KYC & AML Compliance in Sierra Leone (2026): Digital Onboarding for Financial Services
Automated onboarding can pass every check and still fail the case file. Here is how Sierra Leonean fintechs keep the relationship explainable under the 2024 AML/CFT Act.
Automated onboarding can pass every check and still fail the case file. Here is how Sierra Leonean financial-services teams keep the relationship explainable.
Sierra Leonean financial-services teams need digital onboarding that produces a risk-based, explainable customer relationship, not only a completed identity check.
The operating answer
A Sierra Leonean financial-services business needs risk-based AML/CFT controls that identify and verify customers, assess the relationship, monitor for changes and unusual activity, and maintain an accountable reporting route to the country's financial intelligence authority. Digital onboarding works when the evidence, review decisions, and later monitoring history remain connected in the customer case.
VOVE ID helps financial-services teams connect identity evidence, screening context, exceptions, and reviewer actions within a single workflow. The failure mode isn't the digital flow itself — it's a customer accepted through it whose risk decision the team can no longer explain once a question comes back later.
Establish the Sierra Leone perimeter
Sierra Leone's AML/CFT framework was rebuilt by the Anti-Money Laundering and Combating of Financing of Terrorism and Financing of Proliferation of Weapons of Mass Destruction Act, 2024, which replaced the 2012 Act and its 2019 amendment. The 2024 Act established the Financial Intelligence Agency (FIA) as an autonomous body with exclusive authority over financial intelligence tied to money laundering, terrorist financing, and proliferation financing, succeeding the former Financial Intelligence Unit that had operated under the 2012 Act. The Bank of Sierra Leone (BSL) remains the AML/CFT supervisor for banks and other licensed financial institutions.
Sierra Leone is a member of the Inter-Governmental Action Group against Money Laundering in West Africa (GIABA), the FATF-style regional body for the region, and the FIA has been engaging with the Egmont Group as it builds out its international-cooperation role. Sierra Leone is not currently on the FATF list of jurisdictions under increased monitoring.
GIABA's mutual evaluation of Sierra Leone identifies where laundering risk actually concentrates: most often in the country's small-scale artisanal diamond mining sector, driven by domestic groups and individuals rather than transnational networks, alongside dealers in diamonds and precious stones, used-vehicle dealers, and foreign-exchange bureaus and remittance providers — all flagged as higher-risk. Banking and mobile-money services sit at medium risk by comparison, but that doesn't remove them from scope: remittances are a material inflow, with personal transfers into Sierra Leone reported at roughly $293 million in 2023, and mobile money — led by Orange Money and Africell Money — is how a large share of that value actually moves once it lands.
For a payment, e-money, mobile-money, remittance, or other regulated financial product, the first operational task is to confirm the authorization and supervisory perimeter under the 2024 Act. The control design needs to follow the actual service, customers, distribution model, and cross-border footprint — including exposure to mining-adjacent cash and precious-stone dealers where a fintech's corridor touches Kono, Kenema, or other mining districts — not a generic fintech checklist.
Onboarding, compliance governance, and product design have to share the same understanding of the relationship being opened — a control built after the product is live tends to miss exactly the cases it was meant to catch.
For the underlying identity-control model, see our KYC requirements framework.
Build the relationship record
Digital onboarding should collect evidence that supports a decision. Teams need enough context to identify and verify the customer, assess the purpose and intended nature of the relationship, apply risk-based measures, and explain exceptions.
For a business customer, that means a connected view of the entity, representatives, beneficial owners where relevant, expected activity, source evidence, screening context, risk rationale, and decision owner. The 2024 Act carries its own provisions on maintaining beneficial ownership information, and the Companies Act provides for sanctions against legal persons that fail to meet information requirements — a completed document capture is only one input to that record.
The useful question for a Sierra Leonean fintech isn't whether the flow is fully automated — it's whether it has an evidence standard and a clear exception path for the mobile-money agents, cross-border remittance corridors, and cash-heavy customer base that define much of the market.
For the broader entity- and beneficial-ownership model, see our KYB requirements framework.
Case note: automation without an accountable exception
A Freetown-based remittance and forex-bureau platform onboards a small trading business whose declared activity is buying and exporting gold and precious stones sourced from dealers around Kono District. The business submits a company record, identity evidence for the authorized representative, a beneficial-ownership declaration, and an expected transaction profile built around inbound diaspora remittances and outbound supplier payments.
Then the inconsistency appears. The representative's identity result is complete, but the ownership declaration and the expected transaction profile sit in different systems, and neither flags that precious-stone dealing is one of the sector's higher-risk categories under GIABA's own assessment. A reviewer sees an alert on an unusually large outbound payment but cannot see the relationship context that explains whether it is material.
The account is approved, then reopened when payment volumes and counterparties diverge sharply from the original profile. This is not a liveness or document-verification failure. It is an ownership, sector-risk, and case-management failure.
Make human judgment traceable
VOVE ID supports identity verification, biometric liveness, face matching, AML screening, KYB, and transaction monitoring, and can help teams surface document-template inconsistencies, invalid MRZ checksums, barcode or QR inconsistencies, and image manipulation across a range of document types and countries.
Manual review may be used when a customer's compliance team has sufficient evidence to approve a verification. That makes the decision record essential: the case should show what the reviewer saw, what was resolved, and who accepted the residual risk.
Connect alerts to the original decision
The 2024 Act places monitoring and reporting obligations within the same preventive-measures framework as risk assessment, customer due diligence, and record-keeping. The customer relationship should therefore be treated as a living record, not a one-time approval.
Reporting entities in Sierra Leone submit suspicious transaction reports to the FIA under a documented internal escalation route. A firm needs that route in place, tested, before a concern reaches the reporting stage.
In practice, teams should define trigger events for changed activity, ownership, document information, risk indicators, or other material context. Each trigger should create a case that retains the original relationship profile, the new evidence, the review outcome, and the responsible owner.
For the broader screening, case-management, and escalation model, see our AML requirements framework.
Make retrieval part of the control design
Digital onboarding concentrates sensitive identity evidence in digital systems. Access controls, retention decisions, vendor governance, and audit trails must therefore be designed around the customer case. The precise legal basis and retention duties depend on the firm's activities and circumstances, so teams should confirm current requirements with qualified Sierra Leonean advisers.
The operational test: can a compliance reviewer retrieve the evidence, risk rationale, exception decision, monitoring history, and escalation path without reconstructing the case from disconnected tools? If not, the workflow has a control gap.
Field checklist
Governance
- Confirm the firm's Sierra Leonean authorization and AML/CFT perimeter under the 2024 Act.
- Flag sector-specific exposure where customers or counterparties touch artisanal diamond mining, precious-stone dealing, used-vehicle trading, or forex-bureau activity — GIABA's own assessment rates these higher-risk.
- Assign accountable owners for risk assessment, exceptions, monitoring, and escalation.
- Keep procedures aligned with current law, BSL guidance, and FIA directives.
Digital onboarding
- Define evidence standards for automated outcomes and manual exceptions.
- Connect identity, authority, ownership, relationship purpose, and risk evidence.
- Record the reason for every approval, rejection, and residual-risk decision.
Monitoring and reporting
- Define triggers for material activity, ownership, and documentation changes.
- Compare new information with the customer relationship profile.
- Maintain a tested internal route for reporting to the FIA.
Records and audit
- Retain source evidence, reviewer actions, and decisions together.
- Restrict sensitive identity and case information by role.
- Test whether a reviewer can reconstruct a customer case without email searches.
Questions teams ask before launch
Which AML rules matter most for Sierra Leonean financial firms?
The Anti-Money Laundering and Combating of Financing of Terrorism and Financing of Proliferation of Weapons of Mass Destruction Act, 2024, is the central reference, alongside Bank of Sierra Leone supervisory guidance. The exact obligations depend on the firm's activity and licensing perimeter.
Can a fully digital flow complete customer due diligence?
It can collect important identity evidence, but a complete process also needs risk assessment, relationship context, exception management, monitoring, and retrievable records.
When should a digital onboarding case be escalated?
Escalate when evidence is inconsistent, authority or ownership cannot be resolved, the relationship purpose is unclear, or the available information falls outside the firm's risk policy.
Where are suspicious activity reports made in Sierra Leone?
Reports are made to the Financial Intelligence Agency, the body established under the 2024 Act. Firms should use their approved internal procedures and current official guidance for the applicable reporting decision.
The operating position
Sierra Leonean AML compliance doesn't come down to how automated the onboarding flow is. It comes down to whether the identity evidence, risk decision, and monitoring history that follow it stay connected in one case as the relationship changes.
Financial-services teams need identity, risk, reviewer judgment, activity, and reporting evidence to stay connected as the relationship changes. Collection, verification, review, and case management are one workflow.
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.