AML compliance software for Rwanda's reporting institutions.
Sanctions and PEP screening, transaction monitoring, customer risk rating, case management and reporting to the Financial Intelligence Centre through goAML, in one analyst workspace for reporting persons under Rwanda's 2025 AML/CFT law.
Built for Rwanda's AML/CFT law and the Financial Intelligence Centre.
Law N° 001/2025 on the prevention and punishment of money laundering, terrorist financing and proliferation financing, and the FIC's Regulations N° 002/FIC/2026, set out what a reporting person has to do. Each duty maps to a module, so the evidence sits where an examiner will look for it.
Identify customers and rate their risk
Six-factor customer risk rating across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides, plus a beneficial-owner graph for legal-entity customers.
Apply enhanced due diligence to PEPs and higher-risk customers
An EDD workflow inside case management, with periodic reviews scheduled automatically by risk band so a high-risk file does not go stale.
Screen customers against sanctions lists and PEP data
Multi-script, locale-aware matching against lists synced from providers such as Dow Jones and World-Check, plus manual upload for lists you maintain yourself, with versioned lists and freshness dashboards.
Monitor transactions for suspicious activity
A rule engine running in batch and streaming, with typology-aligned starter rules, back-testing and versioned promotion, fed by REST, SFTP, Kafka, CDC or ISO 20022 connectors.
Report suspicious and cash transactions to the FIC
A draft, review, approve and submit lifecycle with acknowledgement handling. The goAML XML is generated and validated by the Creodata goAML Reporting Platform, with a manual download if the portal is down.
Keep records and show supervisors the evidence
An append-only audit log behind every decision, evidence packs for inspections, a read-only regulator portal, and an obligation registry that turns new guidance and amendments into tracked tasks.
This maps software capability to obligations; it is not legal advice. Thresholds and deadlines change, so confirm the current position with the Financial Intelligence Centre.
For Rwanda's reporting institutions, whichever regulator supervises them.
The FIC publishes which authority supervises each category of reporting person.
The National Bank of Rwanda, which also supervises insurers, pension funds, forex bureaus and non-deposit-taking financial institutions.
The Capital Market Authority, which is also the regulatory authority under the May 2026 law on virtual asset business.
The Rwanda Development Board supervises casinos, and the Rwanda Mining Board supervises dealers in precious metals and stones.
The Rwanda Bar Association, the Institute of Certified Public Accountants of Rwanda and the Ministry of Justice for notaries; the FIC supervises real estate agents directly.
Frequently asked questions.
Does the software report to the FIC?
Yes, through goAML. Suspicious and threshold transaction reports move through a draft, review, approve and submit lifecycle in the AML software, with retry, reconciliation and acknowledgement handling. The Creodata goAML Reporting Platform then generates and validates the goAML file for the FIC's portal, and a manual download is available if the portal is down.
How quickly must a Rwandan reporting person file a suspicious transaction report?
Law N° 001/2025 requires reports to be made promptly, including attempted transactions and regardless of amount, and leaves the time limit to the FIC. The FIC's Regulations N° 002/FIC/2026 set it at 24 hours from the occurrence of the transaction or activity.
What are Rwanda's cash and transfer reporting thresholds?
Under the FIC's 2026 Regulations, reporting persons report cash transactions or value transfers of FRW 10 million or more for an occasional customer, FRW 3 million or more in a casino and FRW 15 million or more by a dealer in precious metals and stones, and FRW 1 million or more where a wire transfer is involved, including linked transactions, within two working days. The 2026 text no longer has a separate line for financial institutions' account holders, so confirm with the FIC how it applies to your institution.
Can we run the software on-premises in Rwanda?
Yes. The on-premises edition runs on your own Kubernetes cluster with Postgres 16, RabbitMQ, MinIO, OpenSearch and Keycloak, and has the same features as the Microsoft Azure edition, so an institution that must keep data in its own data centre is not running a lesser product.
See the AML software run on a Rwanda reporting profile.
Screening, monitoring, cases and FIC reporting on a realistic alert queue, in a live demo.