KYC & AML Compliance in Portugal (2026): A Guide for Regulated Fintechs
A Portuguese customer can pass onboarding and still leave the relationship, risk logic, and next action unexplained.
Passing a first identity check tells a Portuguese fintech very little about whether it can actually defend that customer relationship six months later. The evidence that matters — beneficial ownership, relationship purpose, the risk logic behind the acceptance — tends to scatter across tools the moment onboarding is "done," which is exactly when a compliance reviewer needs it most. VOVE ID helps payment and BaaS teams keep that evidence, along with the review actions built on top of it, in one case rather than several.
Regulated fintechs in Portugal need a risk-based AML/CFT program that performs customer due diligence, understands the relationship, identifies beneficial owners where relevant, applies monitoring, and has a controlled route for suspicious-operation reporting.
Portugal's Regulatory Map: Identify the Firm, Supervisor, and Reporting Path
Portugal's anti-money-laundering framework is anchored in Law No. 83/2017, which establishes preventive and repressive measures against money laundering and terrorist financing and implements elements of the EU AML framework. Banco de Portugal's English version of Notice No. 1/2022 is a useful operational reference for institutions within its supervision.
The competent supervisory perimeter depends on the activity. A payment or electronic-money business should determine its own authorization and supervisory obligations before designing the operating workflow. Banco de Portugal is also the authority responsible for registering certain virtual-asset service providers and checking their AML/CFT obligations — that registration scope doesn't automatically answer every prudential or conduct question.
Portugal's Financial Information Unit (UIF), within the Polícia Judiciária, has functions to collect, centralize, process, and disseminate information concerning money-laundering, terrorist-financing, and tax-crime prevention and investigation. The UIF's official description links that role directly to entities covered by Law No. 83/2017.
For the identity-control framework beneath country-specific requirements, see our KYC requirements framework.
Customer Due Diligence: Establish the Relationship, Not Just the Account Holder
An effective CDD file needs to show more than a name and a document. It should establish who the customer is, whether someone acts on the customer's behalf, who ultimately owns or controls a business relationship where relevant, why the relationship exists, and how that expected use informs risk.
This is particularly important for payment and BaaS models. The commercial product can involve an individual user, a platform, a merchant, a corporate customer, a director, or a beneficial owner. Each additional party adds evidence that needs to align before the team treats the relationship as understood.
On paper, a customer journey can look complete once a document is captured. In practice, the case remains incomplete when authority, ownership, purpose, or risk rationale is stored separately from the identity evidence.
Remote Onboarding and Exception Handling: Keep the Accountable Decision Visible
Remote onboarding should state what evidence is sufficient, what requires more evidence, who can review a discrepancy, and where the rationale is recorded. A generic "manual review" queue isn't enough when the reviewer can't see the relationship context or when the final approval leaves no clear explanation.
That's the layer VOVE ID is built for: identity verification, biometric liveness, face matching, AML screening, and KYB across a wide range of document types and countries, with document-template inconsistencies, invalid MRZ checksums, barcode or QR inconsistencies, and image manipulation flagged automatically rather than left for a reviewer to spot manually.
It doesn't decide whether a Portuguese firm falls in scope, whether a specific case should be accepted, or whether a report must be filed — those calls stay with the team. It just makes sure the evidence behind those calls is collected, connected, and still there when someone needs to look back at it.

Monitoring and Reporting: Build the Decision Path Before a Concern Becomes Urgent
Ongoing monitoring turns the onboarding understanding into a live control. A team should define which activity, ownership, document, or risk changes create a review case, what information reviewers need, and which outcomes require escalation.
The UIF states that it's the national central unit competent to receive, analyze, and disseminate suspicious money-laundering and terrorist-financing information. Its suspicious-operation reporting page says the dedicated reporting route is for entities subject to Law No. 83/2017. Firms should validate the applicable procedure, confidentiality obligations, and decision path with current professional advice.
A screening hit or unusual activity is not a completed control — it needs a case owner, preserved evidence, an explainable decision, and an escalation route that doesn't depend on informal messages.
For the operating framework behind screening, review, and escalation, see our AML requirements framework.
Privacy and Records: Design for Retrievability and Constrained Access
Identity, ownership, and activity records require careful access and retention controls. The specific periods, legal bases, and transfer arrangements depend on the firm's business, sector, and applicable law. Teams should obtain current legal advice for their own processing model rather than adopt a generic retention rule.
The operational standard is still useful: a reviewer should be able to reconstruct what was collected, why a relationship was accepted or escalated, what changed, which evidence was reviewed, and who acted. If that reconstruction needs a search across vendor portals, ticketing tools, and email, the customer file isn't yet audit ready.
Practical Portugal KYC and AML Checklist
Governance
- Confirm the firm's authorization, AML/CFT perimeter, supervisor, and accountable owner.
- Map third-party and delegated onboarding activities to evidence and decision records.
- Review policies against the current Law No. 83/2017 and applicable supervisory materials.
Customer due diligence
- Verify the customer and record any representative authority.
- Connect beneficial-owner, relationship-purpose, and risk evidence where relevant.
- Define the evidence threshold and documented reviewer path for exceptions.
Monitoring and reporting
- Set triggers for changes in activity, ownership, expected use, and customer evidence.
- Route potentially suspicious cases through an accountable internal review process.
- Maintain and test the relevant UIF reporting and escalation path.
Records and privacy
- Preserve source evidence, review actions, and decision rationale in one case record.
- Limit sensitive information to staff with an operational need to access it.
- Test whether a case can be reconstructed without manual evidence gathering.
FAQ
Which law anchors AML/CFT obligations in Portugal? Law No. 83/2017 is a central Portuguese AML/CFT law. The precise duties that apply depend on the entity's activity, authorization, and supervisory perimeter.
Does a digital identity check complete CDD for a Portuguese fintech? No. It can be part of the evidence base, but the team still needs risk assessment, relationship understanding, beneficial-owner handling where relevant, monitoring, and a retrievable decision record.
What should cause an onboarding or monitoring escalation? Examples include inconsistent identity or ownership evidence, unclear relationship purpose, unusual activity against the customer profile, screening concerns, or missing information that can't be resolved under policy.
Who receives suspicious-operation information in Portugal? The UIF describes itself as the national central unit that receives, analyzes, and disseminates suspicious money-laundering and terrorist-financing information. Covered firms should verify the current reporting procedure and their own obligations.
Final Thoughts
The front-end identity step was never really the compliance question in Portugal — it's whether the relationship stays explainable as ownership, activity, and risk shift over time. That only happens when identity, context, review, and reporting evidence are treated as one connected record from the start, not reassembled after the fact.
See how VOVE ID supports a country-aware identity and compliance workflow.
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.