AML Compliance in Tunisia: A 2026 Guide for Fintechs and Regulated Businesses
Tunisia exited the FATF grey list in 2019 and stayed off it — here's the enforcement structure that keeps it that way.
Tunisia has built one of the more mature AML/CFT frameworks in North Africa since adopting Organic Law No. 2015-26, and it shows: the country isn't on the FATF grey list, and hasn't been since 2019. That doesn't lower the bar for fintechs — a sizable informal economy, a role as a regional trade and remittance hub, and rising digital-payment volume all keep AML compliance a real operational requirement. VOVE ID helps regulated businesses meet that bar with customer due diligence and screening tools built for the market.
This guide covers AML obligations for regulated entities in Tunisia. For the underlying compliance framework, see our AML Requirements Explained 2026.
The Regulatory Framework
Tunisia's AML/CFT regime is governed by Organic Law No. 2015-26, as amended by Organic Law No. 2019-9, which criminalizes money laundering and terrorism financing and sets obligations for financial institutions and designated non-financial businesses and professions (DNFBPs).
- CTAF (Commission Tunisienne d'Analyse Financière): Tunisia's Financial Intelligence Unit, established at the Central Bank of Tunisia (BCT), receives and analyzes suspicious transaction reports (STRs).
- BCT (Banque Centrale de Tunisie): supervises banks, payment institutions, exchange offices, and microfinance institutions, and issues the sector-specific AML/CFT circulars (including Circular No. 2017-08, as amended by No. 2025-17) that operationalize the law for each institution type.
- INPDP: Tunisia's data protection authority, whose declaration and authorization requirements apply to KYC and biometric data even when that processing supports an AML obligation.
- MENAFATF: the FATF-style regional body that evaluates Tunisia's framework.
For customer due diligence requirements for individuals, see our KYC guide for Tunisia. For business verification and beneficial ownership requirements, see our KYB guide for Tunisia.
Tunisia and the FATF Grey List
Tunisia was removed from the FATF grey list in October 2019 after demonstrating substantial reforms, including stronger beneficial ownership requirements and a more effective FIU. It remains off the list as of the 19 June 2026 FATF statement — a status that keeps Tunisia distinct from several regional neighbors currently under increased monitoring. That doesn't mean lighter scrutiny disappears: risk-based enhanced controls still apply wherever warranted, particularly for higher-risk countries, sectors, and relationships.
Key AML Requirements for Businesses
- Customer Due Diligence (CDD): verifying identity, beneficial ownership, and the purpose of the business relationship.
- Enhanced Due Diligence (EDD): required for PEPs, high-risk customers, and cross-border relationships.
- Suspicious Transaction Reporting: reported to CTAF without delay once suspicion forms — institutions covered by BCT Circular No. 2025-17 file immediately through goAML. There is no general 10-day filing window; that figure sometimes cited in secondary sources isn't the governing rule.
- Record-Keeping: client and transaction data retained for at least 10 years.
- Risk-Based Approach: internal controls tailored to sector-specific risk, reassessed at least every three years for BCT-covered institutions.
- Sanctions Compliance: screening against UN and national designations, with freezes executed without delay and without prior notice.
Failure to comply can result in regulatory fines, license suspension, or reputational damage.
Compliance Challenges in Tunisia
- Cash-dependent informal economy: estimated at 30–40% of GDP, which complicates transaction traceability.
- De-risking pressure: NGOs and civil society groups risk losing access to financial services as institutions over-apply risk controls.
- Limited digital infrastructure in rural areas, which constrains identity verification.
- Evolving financial crime: trade-based money laundering and illicit cross-border flows remain a persistent risk given Tunisia's position as a trade and remittance corridor.
VOVE ID's biometric onboarding, sanctions screening, and audit-ready logging help close some of these operational gaps without adding friction to onboarding.
Industry Impact
- Fintech and mobile money: expanding digital payment platforms drive financial inclusion but widen the surface area for AML risk.
- Remittances: diaspora inflows represent a significant and closely monitored transaction category.
- Digital assets: regulators are watching the space, though a comprehensive VASP licensing framework is not yet finalized.
- Foreign direct investment: a credible AML framework is part of what makes Tunisia attractive to international investors.
For the complete, sourced requirement-by-requirement checklist, see VOVE ID's Tunisia compliance checklist.
Conclusion
Tunisia's AML framework is more mature than its regional reputation sometimes suggests — and staying off the FATF grey list since 2019 isn't an accident. For fintechs and regulated businesses, the practical requirement is the same as anywhere else: build CDD, screening, and recordkeeping that can survive a CTAF or BCT review, not just a policy document that looks good on paper.
Tunisia's AML framework rewards businesses that treat compliance as infrastructure, not paperwork. VOVE ID helps fintechs and regulated businesses in Tunisia build audit-ready CDD, screening, and monitoring without slowing down onboarding.
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.