AML compliance software for Uganda's reporting institutions.
Sanctions and PEP screening, transaction monitoring, customer risk rating, case management and reporting to the Financial Intelligence Authority through goAML, in one analyst workspace for accountable persons under Uganda's Anti-Money Laundering Act.
Built for the Anti-Money Laundering Act and the Financial Intelligence Authority.
Uganda's Anti-Money Laundering Act, 2013 (Cap. 118 in the 2024 Revised Edition), its regulations and the FIA's guidelines set out what an accountable person has to do. Each duty maps to a module, so the evidence sits where an examiner will look for it.
Identify customers and rate their risk
Six-factor customer risk rating across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides, plus a beneficial-owner graph for legal-entity customers.
Apply enhanced due diligence to PEPs and higher-risk customers
An EDD workflow inside case management, with periodic reviews scheduled automatically by risk band so a high-risk file does not go stale.
Screen customers against sanctions lists and PEP data
Multi-script, locale-aware matching against lists synced from providers such as Dow Jones and World-Check, plus manual upload for lists you maintain yourself, with versioned lists and freshness dashboards.
Monitor transactions for suspicious activity
A rule engine running in batch and streaming, with typology-aligned starter rules, back-testing and versioned promotion, fed by REST, SFTP, Kafka, CDC or ISO 20022 connectors.
Report suspicious and cash transactions to the FIA
A draft, review, approve and submit lifecycle with acknowledgement handling. The goAML XML is generated and validated by the Creodata goAML Reporting Platform, with a manual download if the portal is down.
Keep records and show supervisors the evidence
An append-only audit log behind every decision, evidence packs for inspections, a read-only regulator portal, and an obligation registry that turns new guidance and amendments into tracked tasks.
This maps software capability to obligations; it is not legal advice. For registration and filing mechanics, see the Uganda FIA goAML reporting guide.
For Uganda's reporting institutions, whichever regulator supervises them.
Each accountable person's supervisory body enforces compliance, and the FIA does so where there is none (section 21A of the 2013 Act). Uganda's 2023 National Risk Assessment allocates the main sectors like this.
Supervised by the Bank of Uganda for prudential and AML/CFT purposes. The Bank of Uganda also licenses payment service providers.
Regulated by the Uganda Microfinance Regulatory Authority; some SACCOs are licensed by the Bank of Uganda instead.
The Insurance Regulatory Authority of Uganda and the Capital Markets Authority.
The National Lotteries and Gaming Regulatory Board supervises casinos and ICPAU supervises accountants. The FIA supervises virtual asset service providers and sectors with no supervisor, such as real estate agents.
Frequently asked questions.
Does the software report to the FIA?
Yes, through goAML. Suspicious and threshold transaction reports move through a draft, review, approve and submit lifecycle in the AML software, with retry, reconciliation and acknowledgement handling. The Creodata goAML Reporting Platform then generates and validates the goAML file for the FIA's portal, and a manual download is available if the portal is down.
How quickly must a Ugandan accountable person file a suspicious transaction report?
Not later than two working days after forming the suspicion, under section 9 of the Anti-Money Laundering Act, 2013 as amended in 2017 (the Act was renumbered as Cap. 118 in the 2024 Revised Edition). The FIA's August 2024 guidelines add earlier clocks: alerts opened within 3 working days of being generated, and investigations completed within 10 working days.
What is Uganda's large cash transaction threshold?
Accountable persons record every cash or monetary transaction, in any currency, exceeding 1,000 currency points, which is UGX 20 million, and multiple transactions by or for one person in one day are aggregated. Records must be kept for at least 10 years.
Can we run the software on-premises in Uganda?
Yes. The on-premises edition runs on your own Kubernetes cluster with Postgres 16, RabbitMQ, MinIO, OpenSearch and Keycloak, and has the same features as the Microsoft Azure edition, so an institution that must keep data in its own data centre is not running a lesser product.
See the AML software run on a Uganda reporting profile.
Screening, monitoring, cases and FIA reporting on a realistic alert queue, in a live demo.