AML Compliance Software in Rwanda: A Buyer's Guide for Banks, Microfinance, Payment Firms and DNFBPs (2026)
How to choose AML compliance software in Rwanda under Law N° 001/2025 and the FIC's 2026 Regulations: goAML reporting, the 24-hour STR rule, the five-hour sanctions screening clock, the BNR's monitoring expectations, provider types, evaluation criteria, cost drivers and red flags.

Short answer: Good anti-money laundering (AML) compliance software for a Rwandan reporting person does five jobs well: it screens customers against sanctions and PEP data fast enough for the Financial Intelligence Centre's (FIC's) sanctions clock, which is measured in hours, rates customer risk, monitors transactions across every channel you run, turns alerts into documented cases in time for the 24-hour suspicious transaction report (STR) rule, and gets STRs and threshold reports to the FIC through goAML. Choose on evidence from scripted demos on your own data, and compare three-year costs on the same basis.
This guide is for compliance officers, heads of risk and procurement teams at Rwandan banks, microfinance institutions, payment service providers, e-money issuers, forex bureaus, remittance providers, insurers, capital-market firms, virtual asset service providers and designated non-financial businesses and professions (DNFBPs). Law N° 001/2025 and the FIC's Regulations N° 002/FIC/2026 set the duties, and the clocks are short: 24 hours for a suspicious transaction, two working days for a threshold report, and 24 hours from a sanctions designation to frozen funds.
Creodata offers AML compliance software in Rwanda, so we say plainly where we fit near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal advice: confirm requirements against current law and guidance from the FIC and your supervisory authority.
What AML compliance software does
AML software turns your customer and transaction data into the decisions an AML programme has to make, and keeps the evidence of each one.
| Function | What it does | What matters in Rwanda |
|---|---|---|
| Customer due diligence and risk rating | Scores each customer's money-laundering risk from factors such as geography, product, channel and PEP status | A model your compliance team can change, with every override approved and recorded, foreign PEPs always rated high risk, and beneficial owners captured to the FIC's 25% test |
| Sanctions and PEP screening | Checks names against sanctions lists, PEP data and adverse media, at onboarding and whenever lists change | The UN consolidated list and Rwanda's domestic list, rescreening of the whole customer base within hours of a change, and proof of which list version was used |
| Transaction monitoring | Runs rules and models over transactions to raise alerts on suspicious patterns | Coverage of cash, transfers, cards and mobile money, linked transactions brought together, and checks on the information that travels with wire transfers |
| Case management | Turns alerts into owned cases with deadlines, evidence and approvals | A 24-hour clock on every STR, and a record of the decision whether to report |
| Regulatory reporting | Prepares STRs and cash and wire transfer reports | Files built to the FIC's goAML schema and business rules |
| Audit trail | Records every action and decision | An append-only log, and 10-year records that stand up when the FIC or your supervisory authority examines them |
The complete AML platform guide explains each function in depth.
Who needs AML software in Rwanda
Law N° 001/2025 applies to the reporting persons listed in its Article 8: financial institutions; advocates, notaries, professional bailiffs and other legal professionals for specified client work; auditors, accountants and tax advisers; real estate agents; dealers in precious metals and precious stones; money distribution businesses; casinos and national lottery gaming halls; trust and company service providers; and virtual asset service providers. When we checked on 1 October 2026, the FIC's compliance page listed about 3,500 of them in an undated table: 408 financial institutions and 3,128 DNFBPs.
The National Bank of Rwanda (BNR) supervises banks, microfinance institutions, insurers and pension funds, payment service providers, forex bureaus, non-deposit-taking financial institutions and trust and company service providers. The Capital Market Authority (CMA) supervises capital-market firms and, under Law N° 023/2026, licenses virtual asset businesses. Professional bodies, the Ministry of Justice, the Rwanda Revenue Authority, the Rwanda Mining Board and the Rwanda Development Board supervise the DNFBPs, and the FIC supervises real estate agents directly.
Not every institution needs the same system. The BNR's 2023 AML/CFT guidelines expect a financial institution "that is large, operating in many locations, or has a large volume of higher-risk customers" to use automated monitoring, while a forex bureau, a small microfinance institution or a DNFBP usually needs dependable screening, risk rating and reporting first, at a cost that fits its size.
The Rwandan requirements that shape the choice
Most vendor demos look alike until you test them against the rules you actually work under. Article numbers below are those of the FIC's Regulations N° 002/FIC/2026 unless the Law is named.
- Reporting through goAML. The FIC receives reports on its goAML portal, goweb.fic.gov.rw. Banks file cash and wire transfer reports as XML once the FIC authorises them for production, and the FIC publishes its schema, business rules and an XML validator. Ask each vendor for a file built to the FIC's schema, and how it tracks each report after submission.
- STRs within 24 hours. The duty covers attempted transactions and any amount (Law, Article 32), and the Regulations require the report "within 24 hours from its occurrence" (Article 39). Triage, investigation and the compliance officer's decision all have to fit inside that.
- Threshold reports within two working days. The Regulations set FRW 10 million for an occasional customer, FRW 3 million in a casino, FRW 15 million for dealers in precious metals and stones, and FRW 1 million where a wire transfer is involved, with linked transactions added together (Articles 41 and 42). The FIC's FAQ and bank templates still describe the 2023 rule, under which financial institutions reported cash transactions of FRW 10 million or more for every customer and wires of FRW 1 million or more, so the system needs thresholds you can configure, and you should confirm the current expectation with the FIC. See our Rwanda FIC goAML reporting guide.
- Sanctions screening in hours. The FIC's targeted financial sanctions Regulations require screening against the UN consolidated list and Rwanda's domestic list, before any new business relationship as well as when the lists change, and freezing "without prior notice". The FIC's January 2026 guidance on the "without delay" principle expects every customer screened within 5 hours, a nil report within 2 hours of screening, and on a match a freeze and a report within 6 hours of finishing the screening. Its 2025 guidance adds screening during KYC reviews, when customer information changes and before processing any transaction, using name, date of birth, nationality, address and ID document. A screening engine that only refreshes its lists once a day cannot reliably meet that.
- Wire transfers. Above a FRW 1 million de minimis threshold, cross-border transfers carry the originator's and beneficiary's names and account numbers, the originator's address and date of birth, and identifiers for legal persons. A receiving institution checks the beneficiary's name and account against its own records and treats transfers missing the required information as suspicious (Articles 22 to 30).
- PEPs and beneficial owners. "A foreign politically exposed person is always treated as a high-risk customer" (Article 10), with senior management approval and checks on the source of wealth and funds. Domestic PEPs get the same measures when the relationship is higher risk. The FIC's beneficial ownership guidelines treat more than 25% of the shares, or at least 25% of the voting rights, as controlling ownership.
- Annual risk assessment, audit and compliance report. The institutional risk assessment is documented and redone at least once a year (Article 5). The independent audit runs at least once a year and covers the "reliability, integrity and timeliness of the internal and regulatory reporting and management of information systems" (Article 33). An annual compliance report goes to your supervisory authority with a copy to the FIC (Article 44).
- Ten-year records. Transaction records, due diligence files, sanctions screening records, refused business and training records are kept for at least 10 years (Law, Article 21). The FIC's record-keeping guideline of January 2026 adds internal memos on decisions whether to report, access controls, "user activity logs" and backups on every storage system, and a disposal register.
- The BNR's monitoring expectations. For institutions the BNR supervises, its 2023 guidelines say the monitoring system "shall be able to" aggregate structured transactions and flag unusual ones, that management periodically reviews the filtering criteria and thresholds, and that the system's methodology and effectiveness are "independently validated". Institutions report to the BNR weekly on the number of STRs and cash transaction reports filed with the FIC, and monthly on PEP accounts. BNR Regulation N° 63/2023 fines a failure "to maintain an internal system for detecting and reporting unusual and suspicious activities" at FRW 10 million for a commercial bank, down to FRW 250,000 for the smallest category.
Our guide to Law N° 001/2025 covers the duties in more detail. If your group also operates in Kenya or Uganda, see our buyer's guides for Kenya and Uganda; the rules there differ.
The types of AML software provider in Rwanda
A search for AML software or AML solutions in Rwanda returns very different kinds of supplier. Knowing which kind you are talking to tells you what to test.
| Provider type | Typical strengths | Watch for |
|---|---|---|
| Global AML suites | Depth, large-bank references, mature analytics | Cost, long implementations, and whether FIC goAML reporting and Rwandan payment channels work out of the box or through partners |
| AML modules from core banking vendors | Tight integration with the vendor's own core system | Screening and monitoring depth compared with specialist tools, and lock-in to one core platform |
| Local software houses and consultancies | Local presence, regulatory knowledge, help with policies and returns | Whose software it is, who supports it, and whether it is a full system or a tracker for obligations and returns |
| Identity verification and KYC API providers | Fast digital onboarding and identity checks | Onboarding checks are not transaction monitoring, case management or FIC reporting |
| Specialist AML vendors from other African markets | goAML reporting built in, and experience of mobile money and agent channels | Support arrangements in Rwanda, references of similar size, security assurance, and the roadmap behind each module |
| Spreadsheets and in-house builds | Low starting cost, full control | Key-person risk, no audit trail, and the cost of keeping pace with the FIC's regulations and guidance |
The types can be combined, for example an identity verification service at onboarding and an AML system for everything after it, provided they share one record of the customer.
Evaluation criteria
Score every vendor against the same requirements, weighted before the first demo.
| Area | What to test |
|---|---|
| Regulatory fit | goAML files built to the FIC's schema; a 24-hour clock on STRs; configurable cash and wire thresholds, with linked transactions brought together; cash and wire transfer report volumes if you are a bank |
| Risk rating | Compliance can change the model without code; overrides need four eyes; ratings explain themselves; foreign PEPs rated high automatically |
| Screening | Matching quality on your own sample of Rwandan names; the UN consolidated list and the domestic list; rescreening the whole customer base within hours; list freshness you can prove; false-positive control |
| Transaction monitoring | Cash, transfer, card and mobile money coverage; structuring below the thresholds; checks on wire transfer information; back-testing, and rules your institution can have independently validated |
| Case management | The time of the transaction and of the suspicion on every case; the compliance officer's decision inside 24 hours; tipping-off controls; decision memos kept; an append-only audit trail |
| Data and integration | The identity data the Law lists and beneficial owners on customer records; proven integration with your core banking, switching or wallet platform; visible handling of failed feeds |
| Deployment and data | Where data is stored and processed; the same features in cloud and on-premises editions; access controls, user activity logs and backups; security assurance |
| Commercials | Three-year cost; currency of the quote; implementation plan; references; exit terms; regulatory updates included |
How to run the evaluation
- Set priorities with compliance, risk, IT and procurement before meeting vendors.
- Long-list suppliers and drop those that fail your Must-have requirements.
- Issue an RFP with your questions and the evidence you expect. Our free AML vendor RFP checklist and scoring template was written for Kenya, but most requirements carry over once you swap in the FIC, Law N° 001/2025 and your supervisory authority.
- Run scripted demos on your own data: a foreign PEP at onboarding; a near-match against Rwanda's domestic list; a UN list update rescreened across your whole customer base, timed; an incoming cross-border wire missing originator information; cash deposits by one occasional customer that together pass FRW 10 million; and an alert taken to a filed STR with the 24-hour clock visible throughout.
- Call references of similar size and sector, and ask what went wrong.
- Score independently, then calibrate as a panel, and file the scoring sheet with the decision papers.
What AML software costs in Rwanda
Vendors price AML software in very different ways, so ask every shortlisted vendor to itemise the same lines over three years:
- Licence: per module or tier, per customer or account, per transaction, or a flat enterprise fee.
- List data: sanctions, PEP and adverse-media data is often a separate subscription.
- Implementation: data mapping, core-system integration, rule configuration and training, plus travel if the vendor's team is based outside Rwanda.
- Hosting: cloud subscription and consumption, or servers and operations on-premises.
- Support, including whether changes to the FIC's goAML schema, thresholds and templates are covered.
- Currency: US dollars or Rwandan francs, and who carries the exchange-rate risk.
- Internal effort: your analysts' and IT team's time during and after implementation.
A lower licence fee can hide higher data, integration or change-request costs, so compare three-year totals, not first-year quotes.
Red flags
- The vendor cannot show a goAML file built to the FIC's schema, or treats FIC reporting as a future feature.
- The STR workflow has no clock, or starts it at the end of the investigation.
- Sanctions lists update on a fixed daily batch rather than when the UN or the FIC publishes a change, or rescreening your whole customer base takes longer than the FIC's 5 hours.
- Thresholds are fixed in code, or the system ignores linked transactions.
- An administrator can edit or delete audit entries.
- Answers about where your data is stored are vague or change between meetings.
- Must-have requirements are answered with roadmap dates.
Where Creodata fits
Creodata is a Nairobi software company, and our AML compliance software is a regional vendor's answer to the criteria above. It covers sanctions, PEP and adverse-media screening with multi-script matching and a false-positive workflow; customer risk rating across country, industry, product, channel, behaviour and PEP or sanctions exposure, with four-eyes overrides; batch and streaming transaction monitoring with back-testing; case management with enhanced due diligence; and an append-only audit log. Reports move through a draft, review, approve and submit lifecycle, and our separate goAML reporting software for Rwanda generates and validates the file for the FIC's portal, with a manual download if the portal is down.
The cloud edition runs on Microsoft Azure as an Azure Managed Application. Azure has no region in Rwanda, so if data must stay in the country or in your own data centre, choose the on-premises edition, which has the same features. Modules are licensed separately in Starter, Growth and Enterprise tiers, so a forex bureau or DNFBP can start with screening, risk rating and case basics and a bank can run the full suite. Country differences are configuration, not code: see AML compliance software in Rwanda for how each Rwandan duty maps to a module and the AML product overview for every module, or book a demo and bring your own scenarios.
Frequently asked questions
What is the best AML software in Rwanda?
There is no single best system, only the best fit for your institution's size, channels and risks. Shortlist two or three vendors that meet your Must-have requirements, run the same scripted demos on your own data, and score them against one weighted checklist that includes the FIC's 24-hour STR rule and its sanctions screening clock.
How much does AML software cost in Rwanda?
It varies because vendors price differently: by module or tier, by customer or account, by transaction volume, or as an enterprise licence, with list data, implementation and hosting often extra. Ask each shortlisted vendor to itemise licence, data, implementation, hosting and support costs over three years in the same currency, and compare the totals.
Does AML software file reports with the FIC?
Suspicious transaction and threshold reports reach the FIC through its goAML portal. What matters is whether the software produces files built to the FIC's schema and tracks each report after submission. Ask for a validated sample file, and ask how the vendor handles changes to the FIC's schema, thresholds and templates. In Creodata's case, the AML software manages the report lifecycle and the separate Creodata goAML Reporting Platform generates and validates the file.
What are the STR and threshold reporting deadlines in Rwanda?
Suspicious transactions are reported "within 24 hours from its occurrence", whatever the amount (Article 39 of Regulations N° 002/FIC/2026). Cash transactions, wire transfers and value transfers above the FIC's thresholds are reported within two working days of the transaction (Article 42). See our guide to STRs in Rwanda.
Do microfinance institutions, payment firms and DNFBPs in Rwanda need AML software?
Usually, once volumes grow. The core duties do not shrink with size: the 24-hour STR rule, the sanctions screening clock, the annual risk assessment and 10-year record keeping apply to every reporting person. The BNR's guidelines expect automated monitoring at large institutions and those with many higher-risk customers, and its sanctions regulation fines institutions that do not maintain a system for detecting and reporting suspicious activity. A small DNFBP can work manually for a while, but proving that it rescreened every customer within 5 hours of a list change is hard without a system that timestamps each step.
Should AML software be hosted in the cloud or on-premises in Rwanda?
Either can work: cloud is faster to start and easier to scale, while on-premises keeps data in your own data centre. Microsoft has no Azure region in Rwanda: its Azure regions in Africa are in South Africa, so an Azure-hosted system stores data outside the country. The FIC's record-keeping guideline gives "cloud-based platforms with local data residency" as one example of secure storage, alongside internal servers with restricted access and regular backups. Decide with your legal and risk teams what is acceptable, check what your supervisory authority expects of outsourcing, and ask each vendor where data is stored and processed and whether both options have the same features.
How long does it take to implement AML software?
It depends mostly on data and integration, not the software. Screening and risk rating need clean customer data; transaction monitoring also needs reliable feeds from every channel, including mobile money and agents. A phased plan that starts with screening and risk rating and adds monitoring once feeds are proven reduces risk. Ask vendors for a plan with named responsibilities on both sides.
See how Creodata's AML compliance software in Rwanda meets these criteria: book a demo and bring your own scenarios.
More guides for Rwanda
- Rwanda FIC goAML Reporting: A Practical Guide for Banks
- FIC goAML Registration in Rwanda: Step by Step for Reporting Persons (2026)
- Suspicious Transaction Reports in Rwanda: The 24-Hour Rule, goAML Filing and Penalties (2026)
- Rwanda's Anti-Money Laundering Law N° 001/2025 Explained: Reporting Persons, Duties, the FIC and Penalties (2026)


