KYC & AML Compliance in Latvia (2026): A Guide for Cross-Border Fintechs
A technically verified customer isn't the same as an explainable one — here's what Latvian due diligence actually requires to connect.
A customer can pass every identity check a Latvian fintech runs and still leave the compliance team unable to say why they were accepted. That gap — between a technically verified customer and an explainable one — is where cross-border due diligence in Latvia tends to break down, not at the point of collecting documents. VOVE ID helps cross-border fintech and payments teams close that gap by keeping identity evidence, review actions, and the resulting case record in one place.
Latvian obliged entities need risk-based customer due diligence before a business relationship, including customer and beneficial-owner identification, an understanding of purpose and intended activity, ongoing supervision, and retrievable records. Cross-border products need a controlled exception path, because a completed remote journey doesn't remove the obligation to assess risk.
Regulatory Map: Establish the Latvian Perimeter Before Configuring a Flow
Latvia's core AML/CFT framework is the Law on the Prevention of Money Laundering and Terrorism and Proliferation Financing. It requires a subject of the law to document its own risk assessment and establish an internal control system that fits its activities and customers.
The same law frames customer due diligence as more than identification: identifying and verifying the customer, establishing and risk-assessing the beneficial owner, understanding the purpose and intended nature of the relationship, supervising the relationship, and keeping information current. Firms that offer payments, electronic money, or cross-border financial services should confirm their own license, supervision, and outsourcing perimeter before treating a vendor flow as the control framework.
For the underlying identity workflow, see the KYC requirements framework.
Customer Due Diligence: Build the Relationship File, Not an Upload Queue
The Latvian law requires customer due diligence before a business relationship is established. It also specifies transaction situations that trigger due diligence, including certain occasional transactions and transfers, while requiring due diligence whenever there's suspicion or doubt about previously obtained data.
For a digital product, the operational question is whether the team can bring the inputs together. An identity document, a liveness result, a company ownership record, the expected use of the product, and an analyst's exception decision should point to one accountable relationship file. A remote onboarding journey can collect evidence quickly, but it can't make the risk decision disappear — a reviewer still needs enough connected information to approve, restrict, escalate, or decline the relationship.
Beneficial Ownership and Cross-Border Risk
For legal persons and legal arrangements, the law requires firms to ascertain the beneficial owner and, based on risk, verify that person. It also requires an understanding of ownership structure and how control is exercised. A complex ownership structure that doesn't fit the customer's economic activity is a listed risk-increasing factor.
Cross-border onboarding adds a practical layer: the firm must determine which evidence is reliable for the customer's jurisdiction, how foreign-language or unfamiliar documents will be reviewed, and which discrepancies block automation. The answer isn't a longer checklist — it's a defined evidence, escalation, and decision path.

Ongoing Supervision and Reporting
Latvian due diligence continues after onboarding. The law requires supervision of the relationship and regular assessment and updating of records according to risk, including when material customer circumstances change. Teams should translate this into concrete triggers: changed ownership, a mismatch with the stated business purpose, a higher-risk jurisdiction connection, or evidence that's no longer current.
The Financial Intelligence Unit of Latvia states that obliged entities can submit suspicious-transaction or activity reports and threshold declarations through goAML. The reporting route shouldn't be the first time an operations team decides who owns an escalation — a signal needs an assigned reviewer, evidence request, documented rationale, and a route to the accountable reporting decision.
For the operating framework behind escalation and screening, see the AML requirements framework.
Records and Privacy
The record should show what the firm knew when it made its decision, where information came from, what changed, and how the case was resolved — that matters when a relationship is reviewed months later by a compliance lead, an internal auditor, or the relevant authority.
The law also places boundaries around use of personal data obtained for AML/CFT purposes. Teams should align access, retention, deletion, and legal-hold decisions with their legal obligations and data-protection advice. A system that stores files without preserving review actions still leaves the firm unable to reconstruct the decision.
Where VOVE ID Fits Into This
The risk decision itself — whether to accept, restrict, or decline a cross-border customer — stays with the firm. What a Latvian fintech typically struggles with operationally is everything feeding into that decision: verifying identity documents from unfamiliar jurisdictions, running biometric liveness and face-matching checks consistently, screening against AML watchlists, and pulling KYB evidence together in a form a reviewer can actually use. VOVE ID handles that layer across a wide range of document types and countries, catching document-template inconsistencies, invalid MRZ checksums, barcode or QR inconsistencies, and image manipulation along the way — so the evidence a reviewer sees is already vetted, not just collected.
Practical Latvia KYC and AML Checklist
Governance
- Confirm the firm's AML/CFT perimeter, supervisor, and accountable decision owner.
- Document the risk assessment for customers, products, delivery channels, and jurisdictions.
- Define approval rights for complex ownership, remote-verification exceptions, and elevated-risk cases.
Customer due diligence
- Connect identity, beneficial-owner, purpose, and risk evidence in one relationship file.
- Set evidence standards for foreign documents and resolve discrepancies before acceptance.
- Record why the depth of due diligence matches the risk profile.
Monitoring and reporting
- Set review triggers for material customer, ownership, and activity changes.
- Assign case ownership before a signal becomes a reporting decision.
- Maintain a tested goAML reporting procedure for cases that require escalation.
Records and privacy
- Preserve facts, review actions, and decision rationale together.
- Restrict access to identity and ownership evidence by role.
- Test whether a completed case can be reconstructed without manual searching.
FAQ
What should a Latvian digital-finance CDD file contain? It should connect customer and beneficial-owner evidence, the purpose and intended nature of the relationship, the risk assessment, review actions, monitoring triggers, and the final decision.
Does remote verification complete Latvian due diligence? No. Remote verification is an evidence-collection method. The firm still needs risk-based assessment, controlled exceptions, ongoing supervision, and a retrievable relationship file.
When should Latvian customer information be updated? The timing should reflect risk and the quality of the last due-diligence review. Information should also be updated without delay when significant customer-related circumstances change.
How are suspicious reports submitted to FIU Latvia? FIU Latvia identifies goAML as the electronic reporting system for suspicious transaction or activity reports and threshold declarations. Firms should validate their applicable procedure and governance with current requirements.
Final Thoughts
More files rarely fix a Latvian CDD gap — a connected explanation does. A cross-border team that can show identity, ownership, purpose, review, and monitoring evidence as one coherent record is in a fundamentally different position than one that merely collected all the same information across five different tools.
KYC and AML compliance in Latvia isn't a task of collecting more files — it's the discipline of maintaining an explainable customer relationship. Cross-border teams need identity, ownership, purpose, review, monitoring, and audit evidence to remain connected as the relationship changes.
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.