AML Compliance in Uganda: A 2026 Guide for Fintechs and Regulated Businesses

Uganda exited the FATF grey list in 2024 — here's the enforcement structure fintechs are now held to.

Share
AML Compliance in Uganda: A 2025 Guide for Fintechs and Regulated Businesses

Uganda has made real progress strengthening its AML/CFT framework: the country exited the FATF grey list in February 2024, reflecting stronger supervision and inter-agency coordination. Fintech transaction volume kept growing through 2024, which raised the stakes for getting compliance right, not lower them. VOVE ID helps fintechs and regulated businesses build the KYC, KYB, and AML screening layer that Ugandan regulators now expect as standard.

This guide covers AML obligations for regulated entities in Uganda. For the underlying compliance framework, see our AML Requirements Explained 2026.

Uganda's AML Regulatory Framework

Uganda's AML framework is anchored in the Anti-Money Laundering Act 2013 (Cap. 118), substituted in relevant part by the 2017 amendment and further updated by amendments in 2022 and 2023, alongside the Anti-Money Laundering Regulations 2015 (as amended). It aligns with FATF standards and those of the Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG).

Key regulators:

  • Financial Intelligence Authority (FIA): the national centre for receiving, analyzing, and disseminating financial intelligence, and the body accountable persons register with.
  • Bank of Uganda (BoU): supervises the banking and payments sectors and enforces risk-based compliance.
  • Capital Markets Authority (CMA): regulates securities and investment firms.
  • Uganda Microfinance Regulatory Authority (UMRA): oversees non-bank financial institutions.
  • Uganda Registration Services Bureau (URSB): manages business registration and the beneficial-ownership register.

For customer due diligence requirements for individuals, see our KYC guide for Uganda. For business verification and beneficial ownership requirements, see our KYB guide for Uganda.

Core AML Obligations for Regulated Businesses

"Accountable persons" — banks, fintechs, microfinance institutions, forex bureaus, and designated non-financial businesses and professions (DNFBPs) — must implement:

  • Customer Due Diligence (CDD): verifying identity and beneficial ownership using reliable, independent evidence, with Enhanced Due Diligence for high-risk customers and PEPs.
  • Record-keeping: identification and transaction records retained for at least 10 years from whichever is later — the date identity evidence was obtained, the date of the relevant transaction, or the date the relationship ends.
  • Suspicious Transaction Reporting (STR): filed with FIA without delay and no later than two working days from formation of suspicion.
  • Large cash reporting: cash and monetary transactions of UGX 20,000,000 or more are reported using Form A.
  • Risk-Based Approach (RBA): internal controls calibrated to customer, product, and transaction risk.
  • Annual compliance return: the prior year's compliance report and internal AML/CFT policy are due to FIA by 31 January.

Recent Progress and Reforms

Uganda's February 2024 exit from the FATF grey list followed a series of reforms:

  • Amendments to the AML Act and Regulations, including a January 2025 exclusion of NGOs and churches from the "accountable persons" schedule to reduce compliance burden on those sectors.
  • National Risk Assessment (NRA) updated in 2024 to capture emerging risks, including virtual-asset activity.
  • Stronger inter-agency cooperation between FIA, BoU, and law enforcement.
  • Risk-based supervision, with proposals in 2025 addressing FATF's remaining recommendations.

Challenges That Remain

  • Limited supervisory capacity: FIA's inspector headcount remains small relative to the number of registered accountable persons, per IMF estimates.
  • Automation gaps: manual transaction monitoring is still common among forex bureaus and remittance firms.
  • Inconsistent compliance across DNFBPs and virtual-asset providers.
  • Ongoing training needs and uneven data-sharing between institutions.

How VOVE ID Supports AML Compliance in Uganda

VOVE ID offers a secure, API-driven platform that supports:

  • Digital onboarding: biometric identity verification for customer onboarding.
  • KYC and KYB checks: document verification and sanctions/PEP screening.
  • AML screening: helping businesses identify and manage high-risk customers and entities at onboarding and on an ongoing basis.
  • Audit-ready recordkeeping: structured for FIA and BoU review.

For the complete, sourced requirement-by-requirement checklist, see VOVE ID's Uganda compliance checklist.

Conclusion

Uganda's AML landscape in 2026 reflects real institutional progress — but a grey-list exit is a floor, not a ceiling. For fintechs and regulated businesses, a strong compliance program is still the difference between smooth growth and a costly FIA finding.

Uganda's grey-list exit raised expectations, not lowered them. VOVE ID helps fintechs meet FIA and Bank of Uganda requirements through automated identity verification, screening, and audit-ready records.

Book a call

This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.