KYC & AML Compliance in Eswatini: Fast Reform Meets a Real Mobile-Money Market
Eswatini went from failing most of its AML review to fixing it fast. Here is what that means for KYC and AML today.
Eswatini's 2022 Mutual Evaluation Report was not a flattering document: the country was found non-compliant or only partially compliant on 26 of the FATF's 40 Recommendations, with all 11 effectiveness outcomes assessed as not achieved or achieved to only a negligible extent. What's changed since is the more interesting story. By the time Eswatini's delegation met with ESAAMLG in Kigali, the country had secured re-ratings that brought it to 32 of 40 Recommendations rated compliant or largely compliant — a fast, measurable improvement most small markets don't manage this quickly. For a financial-services business operating there, that trajectory, combined with a mobile-money sector that already reaches the large majority of the adult population, is the real compliance story.
The operating answer
An Eswatini-based financial-services business needs risk-based AML/CFT controls built for a market actively closing a credibility gap with its regulators, on top of a mobile-money ecosystem that already carries most of the country's financial inclusion. Digital onboarding works when identity evidence, risk rationale, and monitoring history stay connected in a case a reviewer can defend — and when the program is built to keep pace with reforms landing faster than in most comparable markets.
Establish the Eswatini perimeter
Eswatini's AML/CFT framework is anchored by the Money Laundering and Financing of Terrorism (Prevention) Act, 2011, substantially amended in 2016 and again in 2024. The 2011 Act established the Eswatini Financial Intelligence Unit (EFIU) under section 38, and the 2024 amendment embedded risk-based obligations directly into law, requiring accountable institutions to obtain senior management approval for higher-risk business relationships rather than applying a uniform standard across the board. The Central Bank of Eswatini (CBE) licenses and supervises banks, building societies, and money or value transfer services including mobile money, while the Financial Services Regulatory Authority (FSRA) covers insurance, securities, and other non-bank financial institutions.
Eswatini is a member of ESAAMLG, and its most recent enhanced follow-up report and technical compliance re-rating, published in August 2025, documented real progress against the deficiencies the 2022 evaluation identified — progress that continued at the subsequent ESAAMLG meeting in Kigali, where the country secured upgrades on four additional Recommendations. The EFIU has also begun its application process for Egmont Group membership. Eswatini is not currently on the FATF list of jurisdictions under increased monitoring.
For a payment, mobile-money, or other regulated financial license, the first operational task is building a compliance program against where the rulebook is heading, not just where it sits today — a market moving this fast toward full compliance will keep tightening requirements for the accountable institutions operating inside it.
For the underlying identity-control model, see our KYC requirements framework.
Build a case around the mobile-money relationship, not just the account holder
Roughly 85% of Swazi adults are financially included, according to ESAAMLG's own assessment, largely due to mobile money services rather than traditional banking. Eswatini's mobile-money sector is led by MTN MoMo and Instacash, alongside four commercial banks — First National Bank Eswatini, Standard Bank Eswatini, Nedbank Eswatini, and Eswatini Bank — and a newly licensed building society. The CBE's Mobile Money Transfer (MMT) Practice Note No.1/2019/NPSS requires mobile money transfer service providers to be licensed or registered with the Bank, and the same registration requirement extends to agents operating on their behalf.
That combination — near-universal mobile-money penetration layered onto a small population of about 1.2 million — means a mobile-money provider's KYB file needs to capture not just the licensing status of the platform itself but the registration status of every agent in its network. An agent operating without proper registration is a gap the CBE's own framework is explicitly designed to catch, and a case built only around the platform-level relationship will miss it.
For the broader entity- and beneficial-ownership model, see our KYB requirements framework.
Case note: an agent registration gap that outlived the original onboarding
A mobile-money provider onboards a new agent in a rural town, verified at the time as properly registered with the CBE under the MMT Practice Note. Over the following year, the agent's registration lapses administratively — a renewal missed, a filing delayed — while the agent continues processing transactions through the provider's platform without interruption.
Because the provider's original onboarding case didn't include a mechanism for revisiting registration status after initial verification, nothing in the workflow flags that the agent's authorization has quietly expired. The transactions themselves look entirely ordinary — small mobile-money transfers consistent with the agent's location and customer base — so nothing about the activity itself would trigger a standard monitoring alert.
This isn't a transaction-monitoring failure. It's a case-design failure: in a regulatory environment that explicitly requires agent-level registration, a KYB process that verifies status once at onboarding and never again will drift out of compliance exactly the way this one did, without any single transaction ever looking suspicious.
Connect monitoring to a supervisory system that's actively tightening
Reporting entities submit suspicious transaction reports to the EFIU. With the 2024 amendment embedding risk-based obligations into law and the EFIU only recently beginning to roll out AML supervision for sectors like securities, insurance, and mobile money, firms should expect supervisory expectations to keep rising rather than plateau — the trajectory from 26-of-40 to 32-of-40 compliant Recommendations in a few years is not a one-time correction.
In practice, that means defining trigger events for agent registration status, risk-tier reassessment under the new senior-management-approval requirement for higher-risk relationships, and periodic re-verification rather than one-time checks — and ensuring each trigger produces a case that retains the original onboarding rationale alongside the new evidence.
For the broader screening, case-management, and escalation model, see our AML requirements framework.
Design onboarding for where the payment system is heading
The CBE is actively building payment-system interoperability across all major players — banks and mobile-money operators alike — from the start, under the National Payment Systems (NPS) Act of 2023, with detailed implementing regulations still being finalized. For a financial-services business, that means the compliance program built today needs room to extend into interoperable rails that don't fully exist yet, rather than being scoped narrowly around today's mobile-money and banking silos.
The operational test: if a mobile-money agent's registration lapses, or a customer relationship is reclassified as higher-risk under the 2024 amendment's senior-management-approval requirement, does the case surface that automatically — or does it depend on someone remembering to re-check a status that was only verified once?
Field checklist
Governance
- Confirm CBE or FSRA licensing category and current obligations under the 2011 MLFTP Act, as amended in 2016 and 2024.
- Track ESAAMLG follow-up reports for further technical compliance re-ratings and resulting obligation changes.
- Assign accountable owners for risk assessment, exceptions, monitoring, and EFIU reporting.
Onboarding
- Verify mobile-money agent registration status under the CBE's MMT Practice Note at onboarding, and schedule periodic re-verification.
- Apply senior-management approval for higher-risk business relationships as required by the 2024 amendment.
- Record the original risk rationale for every business relationship in a retrievable form.
Monitoring
- Define triggers for agent registration lapses, risk-tier changes, and activity inconsistent with an agent's or customer's established profile.
- Build monitoring workflows that can extend into interoperable payment rails as the NPS Act's implementing regulations take effect.
- Maintain a tested internal escalation route into the EFIU.
Records
- Retain source evidence, risk ratings, and reviewer decisions together.
- Restrict access to sensitive identity and case data by role.
- Test whether a reviewer can identify a lapsed agent registration without a scheduled re-verification catching it first.
Questions teams ask before launch
Which law governs AML/CFT in Eswatini right now?
The Money Laundering and Financing of Terrorism (Prevention) Act, 2011, amended in 2016 and again in 2024 to embed risk-based obligations directly into law.
Is Eswatini on the FATF grey list?
No. Eswatini is not currently on the FATF list of jurisdictions under increased monitoring, and has been steadily improving its technical compliance ratings since its 2022 Mutual Evaluation, reaching 32 of 40 Recommendations rated compliant or largely compliant by its most recent ESAAMLG re-ratings.
Why does mobile money matter so much for compliance design in Eswatini?
Because roughly 85% of Swazi adults are financially included largely through mobile money rather than traditional banking, a compliance program that treats mobile-money agents as a secondary concern will miss where most customer-facing risk actually sits.
Where are suspicious transaction reports filed in Eswatini?
Reports go to the Eswatini Financial Intelligence Unit (EFIU). Firms should follow their approved internal escalation procedures and current CBE or FSRA guidance for the applicable reporting decision.
The operating position
Eswatini's compliance story isn't a static rulebook or a country stuck in place — it's a market that started from a weak position in 2022 and has been closing that gap faster than most. A case file built only to today's minimum will fall behind a regulatory environment moving this quickly; one built to track agent status, risk-tier changes, and mobile-money relationships as they evolve will keep pace with where Eswatini's AML/CFT regime is clearly headed.
Want to see how VOVE ID can fit into a case that tracks agent registration and risk-tier changes automatically, instead of relying on someone remembering to re-check? Walk through the workflow with your team before you scale mobile-money onboarding in Eswatini.
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.