Guatemala AML Law 2026: Key Changes Under Decree No. 15-2026

Guatemala AML Law 2026: Key Changes Under Decree No. 15-2026

 

Guatemala’s New AML/CFT Law (Decree No. 15-2026): A Comprehensive Guide for Compliance Leaders

Regulation Name: Decree No. 15-2026
Date Of Publish: 17 Jun 2026
Region: Guatemala
Agency: Guatemala Congress (Congreso de la República de Guatemala)

Executive Summary

Guatemala has enacted one of its most significant anti-money laundering (AML) reforms in over two decades with Decree No. 15-2026, the Comprehensive Law for the Prevention and Repression of Money Laundering or Other Assets and the Financing of Terrorism. Published in the Official Gazette on 17 June 2026, the legislation repeals two long-standing AML laws and replaces them with a single, modern legal framework that integrates international standards for combating money laundering (ML), terrorist financing (TF), and proliferation financing (PF).

More than a legislative update, the new law fundamentally reshapes Guatemala’s financial crime compliance landscape. It introduces a mandatory risk-based approach, expands the scope of obligated entities, formally regulates Virtual Asset Service Providers (VASPs), strengthens customer due diligence (CDD) and beneficial ownership requirements, enhances transaction monitoring and suspicious transaction reporting, and establishes a new national coordination body responsible for AML/CFT policy implementation.

For financial institutions, fintech companies, designated non-financial businesses and professions (DNFBPs), cryptocurrency service providers, auditors, legal professionals, and multinational organizations operating in Guatemala, the law represents a substantial compliance transformation.

Why Guatemala Introduced a New AML/CFT Law

Guatemala’s previous AML legislation consisted primarily of two separate laws:

  • Law Against Money Laundering or Other Assets (Decree 67-2001)
  • Law for Preventing and Repressing Terrorist Financing (Decree 58-2005)

While these laws established Guatemala’s basic AML/CFT framework, the country’s financial system has evolved significantly over the last twenty years. Digital financial services, fintech innovation, virtual assets, increasingly sophisticated organized crime networks, and evolving FATF standards exposed regulatory gaps that could no longer be addressed through piecemeal amendments.

Recognizing these challenges, the Guatemalan Congress enacted Decree No. 15-2026 to create a unified legal framework that:

  • consolidates AML and CFT legislation into a single law;
  • strengthens preventive and enforcement mechanisms;
  • aligns domestic regulations with international standards and best practices, particularly the FATF Recommendations;
  • improves transparency in financial and corporate ownership structures;
  • enhances cooperation among national authorities; and
  • equips obligated entities with a modern, risk-based compliance framework.

Importantly, the law also clarifies that its objective is not to criminalize the informal economy, discourage the legitimate use of cash, or serve as a tax enforcement measure. Instead, it focuses specifically on preventing and repressing money laundering, terrorist financing, and proliferation financing while protecting the stability and integrity of Guatemala’s financial system.

At a Glance: Key Changes Introduced by Decree No. 15-2026

Previous Framework

Decree No. 15-2026

Separate AML and Terrorist Financing laws

Single integrated AML/CFT/PF legislation

Limited coverage of regulated entities

Significant expansion of obligated entities

No dedicated regulation for VASPs

Virtual Asset Service Providers formally regulated

Basic customer due diligence

Risk-based CDD and Enhanced Due Diligence requirements

Limited beneficial ownership provisions

Comprehensive beneficial ownership identification and verification

Conventional compliance programs

Mandatory enterprise-wide AML risk management framework

Traditional transaction reporting

Enhanced monitoring, alert generation and suspicious transaction reporting

Separate institutional coordination

Establishment of CONCLAFT for national AML/CFT coordination

Earlier supervisory framework

Strengthened supervisory and enforcement powers for the IVE and Superintendence of Banks

Major Objectives of the New Law

The legislation establishes five overarching policy objectives that collectively modernize Guatemala’s AML ecosystem.

  1. Build a Comprehensive Preventive AML Framework

Rather than focusing solely on criminal prosecution, the law emphasizes prevention. Financial institutions and other obligated entities must proactively identify, assess, mitigate, and monitor ML/TF/PF risks before criminal activity can penetrate the financial system.

  1. Adopt a Risk-Based Compliance Model

One of the law’s most significant reforms is the mandatory adoption of a Risk-Based Approach (RBA).

Organizations must evaluate risks arising from factors such as:

  • customer types;
  • products and services;
  • delivery channels;
  • geographic exposure;
  • transaction characteristics; and
  • emerging threats.

Compliance measures must be proportionate to the level of identified risk rather than applying uniform controls across all customers and transactions.

  1. Expand Regulatory Coverage

The law substantially increases the number of entities subject to AML obligations.

Historically, Guatemala’s AML regime focused primarily on banks and financial institutions. The new legislation extends AML requirements to a broad range of financial service providers, commercial sectors, professional service providers, and virtual asset businesses.

This expansion reflects FATF’s expectation that high-risk non-financial sectors also maintain effective AML controls.

  1. Strengthen Transparency

Beneficial ownership transparency has become a global AML priority.

The law strengthens:

  • identification of beneficial owners;
  • verification procedures;
  • ownership tracing through indirect structures;
  • ongoing monitoring of ownership information; and
  • obligations relating to corporate records.

These provisions are intended to reduce the misuse of shell companies, nominee arrangements, and complex ownership structures for laundering illicit funds.

  1. Improve National Coordination

Money laundering investigations increasingly require cooperation among regulators, law enforcement, financial intelligence units, prosecutors, customs authorities, and foreign counterparts.

The law therefore establishes a new institutional coordination mechanism to improve national AML policy implementation and international cooperation.

Alignment with FATF Standards

One of the strongest themes throughout Decree No. 15-2026 is alignment with the Financial Action Task Force (FATF) Recommendations.

The legislation incorporates many internationally recognized AML principles, including:

FATF Principle

Reflected in Guatemala’s Law

Risk-Based Approach

Mandatory enterprise-wide ML/TF risk assessments

Customer Due Diligence

Expanded CDD and Enhanced Due Diligence

Beneficial Ownership

Identification and verification requirements

Politically Exposed Persons

Enhanced controls for domestic and foreign PEPs

Suspicious Transaction Reporting

Mandatory reporting to the IVE

Recordkeeping

Minimum record retention requirements

Targeted Financial Sanctions

Implementation of UN Security Council measures

Virtual Assets

AML obligations for VASPs

National Cooperation

Creation of CONCLAFT

International Cooperation

Expanded authority for information sharing

For multinational institutions, this alignment reduces regulatory fragmentation and enables greater consistency between Guatemala’s AML obligations and global compliance programs.

Expanded Scope of Obligated Entities

Perhaps the most operationally significant reform is the expansion of entities subject to AML obligations.

The legislation categorizes obligated entities into several groups.

Financial Institutions

Entities supervised by the Superintendence of Banks remain subject to AML obligations, including:

  • banks;
  • insurers (for specified life insurance products);
  • financial intermediaries;
  • payment service providers;
  • credit providers;
  • leasing companies;
  • factoring businesses;
  • money transfer businesses;
  • foreign exchange providers;
  • investment intermediaries; and
  • cooperatives conducting savings, credit, or transfer activities.
Commercial Businesses

Several commercial sectors are now expressly covered.

Examples include:

  • real estate agencies;
  • vehicle dealers;
  • dealers in precious metals;
  • dealers in precious stones;
  • art dealers;
  • armored transport services;
  • casinos;
  • lotteries;
  • raffles;
  • sports betting operators;
  • pawn shops.
Professional Service Providers

Professionals involved in certain financial or corporate activities become obligated entities when acting on behalf of clients.

These include:

  • lawyers;
  • accountants;
  • auditors;
  • notaries;
  • company formation service providers;
  • trust and corporate service providers.

Activities such as establishing legal entities, managing client assets, opening financial accounts, administering companies, or facilitating the purchase and sale of corporate interests fall within the AML framework.

This represents a major expansion compared with the previous legal framework and aligns Guatemala more closely with FATF’s treatment of Designated Non-Financial Businesses and Professions (DNFBPs).

Virtual Asset Service Providers Enter Guatemala’s AML Regime

Among the most consequential reforms for emerging financial technologies is the explicit regulation of Virtual Asset Service Providers (VASPs).

For the first time, Guatemala’s AML legislation recognizes businesses engaged in virtual asset activities as obligated entities.

The definition is broad and covers persons or entities that, as a business, conduct one or more of the following activities for or on behalf of another person:

  • exchange between virtual assets and fiat currencies;
  • exchange between different virtual assets;
  • transfer of virtual assets;
  • custody or administration of virtual assets or instruments enabling control over them;
  • participation in or provision of financial services related to the issuance, offer, or sale of virtual assets;
  • services facilitating investment, lending, or returns involving virtual assets; and
  • infrastructure or fiduciary services supporting virtual asset transactions.

Why This Matters

The inclusion of VASPs demonstrates Guatemala’s recognition that digital assets present both innovation opportunities and financial crime risks.

Crypto exchanges and other digital asset businesses will now need to implement comprehensive AML programs comparable to those required of traditional financial institutions, including:

  • customer identification;
  • risk assessments;
  • transaction monitoring;
  • suspicious transaction reporting;
  • sanctions screening; and
  • recordkeeping.

This brings Guatemala substantially closer to international expectations under FATF Recommendation 15 and its guidance on virtual assets.

Implementation Timeline

While Decree No. 15-2026 entered into force after publication in the Official Gazette, several implementation measures are phased to provide regulators and obligated entities with time to adapt.

Timeline

Requirement

17 June 2026

Publication of Decree No. 15-2026 in the Official Gazette

Within 3 months of publication

Law enters into force

Within 6 months of entry into force

Superintendence of Banks to prepare and submit implementing regulations

Within 60 days of the law taking effect

Existing obligated entities with pending registrations or information must provide required documentation to the IVE

Within 1 year

Companies required to update shareholder and administrator information in commercial records, where applicable

Within 2 years

Public institutions to establish interoperable information-sharing systems and cooperation mechanisms supporting AML/CFT implementation

These transition periods provide organizations with an opportunity to review governance structures, conduct enterprise-wide risk assessments, modernize AML controls, and prepare for enhanced supervisory expectations.

Implementing the Risk-Based Approach: The Foundation of the New AML Framework

The most transformative aspect of Guatemala’s new AML law is the shift from a rules-driven compliance model to a Risk-Based Approach (RBA). Rather than applying identical controls to every customer and transaction, obligated entities must identify, assess, mitigate, and continuously monitor money laundering (ML), terrorist financing (TF), and proliferation financing (PF) risks based on their specific business model.

The law requires organizations to consider factors including:

  • Customer profiles and risk characteristics
  • Geographic exposure
  • Products and services offered
  • Distribution and onboarding channels
  • Transaction patterns
  • Emerging threats and vulnerabilities

Risk assessments must be documented, periodically updated, approved by senior management, and proportionate to the nature, size, and complexity of the organization. Institutions launching new products, adopting new technologies, or entering new markets must assess associated ML/TF/PF risks before implementation.

Comprehensive AML Programs Become Mandatory

Every obligated entity must establish and maintain a formal AML/CFT compliance program appropriate to its risk profile.

At a minimum, the program should include:

  • Internal AML/CFT policies and procedures
  • Enterprise-wide risk assessment methodology
  • Customer due diligence procedures
  • Transaction monitoring systems
  • Internal reporting mechanisms
  • Employee screening procedures
  • Ongoing staff training
  • Independent testing or audit
  • Governance and oversight mechanisms

The law also requires annual evaluations of the effectiveness of these programs. Financial groups may implement a unified AML program across subsidiaries, provided group-wide controls meet regulatory expectations.

Compliance Officer Requirements

The legislation significantly strengthens governance by requiring obligated entities to appoint a Compliance Officer responsible for overseeing AML/CFT compliance.

The Compliance Officer must have:

  • operational independence;
  • sufficient authority;
  • adequate technological and financial resources;
  • direct communication with senior management; and
  • responsibility for coordinating with the Superintendence of Banks through the Special Verification Intendancy (IVE).

Financial groups may appoint a Group Compliance Officer, allowing centralized oversight while maintaining accountability across member entities.

Customer Due Diligence (CDD): A More Comprehensive Standard

The new law substantially expands Customer Due Diligence obligations.

CDD measures must generally be applied:

  • when establishing a business relationship;
  • when transactions exceed regulatory thresholds;
  • when unusual transactions occur;
  • when customer information becomes unreliable; or
  • when the customer’s risk profile changes.

Core CDD requirements include:

  1. Verifying the customer’s identity using reliable, independent documentation.
  2. Identifying and verifying the beneficial owner.
  3. Understanding the purpose and intended nature of the business relationship.
  4. Establishing a customer risk profile.
  5. Conducting ongoing monitoring throughout the relationship to ensure transactions remain consistent with the customer’s profile and source of funds.

Unlike traditional “one-time” KYC processes, CDD under the new law is continuous and dynamic.

Enhanced Due Diligence (EDD) for High-Risk Relationships

The law requires enhanced due diligence where elevated ML/TF/PF risks exist.

EDD measures apply to situations including:

  • Politically Exposed Persons (PEPs)
  • State contractors and suppliers
  • Non-profit organizations receiving public or foreign funds
  • Trusts and fiduciary arrangements
  • Private banking relationships
  • Correspondent banking
  • High-value accounts
  • Large cash transactions
  • High-value fund transfers
  • Non-face-to-face business relationships
  • Customers linked to high-risk jurisdictions identified by FATF or domestic authorities.

Institutions are expected to collect additional information, increase monitoring frequency, and apply stronger approval and review processes for these relationships.

Beneficial Ownership: Looking Beyond Legal Ownership

The legislation strengthens beneficial ownership transparency by requiring obligated entities to identify the natural person who ultimately owns or controls a customer.

The definition extends beyond direct ownership to include:

  • indirect ownership;
  • ownership chains;
  • control exercised through other means; and
  • decision-making authority over legal entities or structures.

Verification must rely on reliable documentation and continue throughout the business relationship.

For multinational financial institutions, these requirements reinforce the importance of maintaining accurate ownership records across complex corporate structures.

Politically Exposed Persons (PEPs)

The law modernizes Guatemala’s treatment of Politically Exposed Persons.

A PEP includes individuals who currently hold—or have held within the previous year—prominent public positions in Guatemala or abroad, as well as individuals entrusted with prominent functions by international organizations. Immediate family members and close associates are also subject to enhanced scrutiny where applicable.

Enhanced measures include:

  • senior management approval where appropriate;
  • establishing the source of wealth and source of funds;
  • enhanced monitoring; and
  • periodic review of the relationship.

The legislation also requires authorities to maintain and periodically update lists of prominent public positions to assist obligated entities in identifying PEPs.

Continuous Transaction Monitoring

Decree No. 15-2026 places significant emphasis on ongoing transaction monitoring.

Obligated entities must implement systems capable of:

  • monitoring all customer transactions;
  • generating risk-based alerts;
  • identifying unusual activity;
  • analyzing suspicious behaviour; and
  • escalating cases requiring investigation.

Alert scenarios should be updated periodically to reflect evolving money laundering typologies and institutional risk assessments.

For larger organizations, this reinforces the need for automated transaction monitoring systems supported by configurable rules, behavioral analytics, and risk scoring.

Suspicious Transaction Reporting (STR)

Where an unusual transaction lacks an apparent economic or lawful purpose—or gives rise to reasonable grounds for suspicion—it must be reported confidentially to the Special Verification Intendancy (IVE).

Key principles include:

  • prompt reporting;
  • confidentiality;
  • protection of reporting entities;
  • prohibition against tipping off customers.

The law recognizes that reporting should occur even when a transaction is not completed, provided reasonable suspicion exists.

Cash Transaction Reporting

In addition to suspicious transaction reporting, obligated entities must maintain daily records of cash transactions.

Transactions of USD 10,000 or more (or equivalent) must be recorded and periodically reported to the Superintendence of Banks through the IVE.

These reporting requirements support national efforts to detect bulk cash movement and large-value laundering schemes.

Recordkeeping Requirements

Documentation remains a critical element of AML compliance.

The law requires obligated entities to retain records relating to:

  • customer identification;
  • due diligence;
  • business correspondence;
  • transactions;
  • internal analyses;
  • compliance documentation.

Most records must be retained for at least five years, while certain electronic records must remain accessible for extended preservation periods to support investigations and supervisory reviews.

Virtual Asset Service Providers Face Full AML Obligations

The inclusion of Virtual Asset Service Providers (VASPs) is among the most significant reforms.

Crypto exchanges, custodial wallet providers, virtual asset transfer services, issuance platforms, and other qualifying businesses are now expected to implement AML controls comparable to those applied to banks.

Practical obligations include:

  • customer onboarding and verification;
  • beneficial ownership identification;
  • sanctions screening;
  • transaction monitoring;
  • suspicious transaction reporting;
  • record retention;
  • internal governance and training.

For digital asset businesses operating in Guatemala, AML compliance transitions from a best practice to a statutory obligation.

Targeted Financial Sanctions and UN Security Council Resolutions

The law incorporates comprehensive obligations relating to targeted financial sanctions.

Obligated entities must:

  • screen customers against relevant UN Security Council designation lists;
  • identify designated individuals and entities;
  • freeze assets where legally required;
  • restrict financial services to sanctioned persons; and
  • comply with reporting and notification requirements.

This strengthens Guatemala’s implementation of international obligations concerning terrorism and proliferation financing.

Administrative Enforcement

The Superintendence of Banks receives broader supervisory and enforcement authority.

Administrative sanctions may include:

  • written warnings;
  • corrective action requirements;
  • mandatory remediation plans;
  • monetary penalties.

Fines range from US$500 to US$300,000, depending on factors such as:

  • severity of the violation;
  • conduct of the obligated entity;
  • type of reporting entity;
  • aggravating circumstances.

Repeated deficiencies may result in additional supervisory intervention and enhanced oversight.

Strengthened Criminal Liability

Beyond preventive compliance, the law significantly strengthens Guatemala’s criminal AML framework.

The legislation updates offences relating to:

  • money laundering;
  • terrorist financing;
  • cross-border cash smuggling;
  • conspiracy;
  • confiscation of criminal assets;
  • corporate criminal liability.

Legal persons may now face substantial financial penalties where criminal conduct results from failures in governance, supervision, or corporate decision-making.

Sector-by-Sector Compliance Impact

Sector

Primary Compliance Priorities

Banks

Enterprise-wide risk assessments, transaction monitoring, sanctions screening, STR reporting

Fintechs

Digital onboarding controls, customer verification, fraud analytics

Virtual Asset Service Providers

AML programs, wallet monitoring, customer risk profiling, sanctions compliance

Insurance Companies

Risk-based CDD for life insurance and investment-linked products

Real Estate Firms

Beneficial ownership verification, source-of-funds reviews

Lawyers & Notaries

Client due diligence for qualifying transactions, recordkeeping

Accountants & Auditors

Risk assessments, beneficial ownership verification, suspicious activity escalation

Dealers in Precious Metals, Stones and Art

Cash controls, customer verification, transaction monitoring

Casinos, Lotteries and Gaming Operators

Enhanced monitoring, cash reporting, suspicious transaction detection

Practical Compliance Roadmap

Organizations should begin implementation immediately by focusing on the following priorities.

Priority

Recommended Action

Governance

Appoint or review Compliance Officer responsibilities

Enterprise Risk Assessment

Update ML/TF/PF risk assessments

Policies

Revise AML manuals to reflect Decree No. 15-2026

Customer Due Diligence

Strengthen KYC, beneficial ownership and EDD procedures

Technology

Upgrade transaction monitoring and sanctions screening capabilities

Virtual Assets

Assess whether VASP obligations apply

Training

Deliver updated AML training across business functions

Independent Review

Schedule annual AML effectiveness assessments

Regulatory Readiness

Prepare documentation for supervisory examinations

How ZIGRAM Supports Compliance with Guatemala’s New AML Framework

The breadth of Decree No. 15-2026 reinforces the need for technology-enabled compliance.

ZIGRAM’s AML ecosystem helps organizations address many of the law’s core requirements:

Regulatory Requirement

ZIGRAM Capability

Customer Screening

PreScreening.io for sanctions, PEP, adverse media and watchlist screening

Beneficial Ownership & Enhanced Due Diligence

Due Diliger for investigative due diligence and corporate intelligence

Transaction Monitoring

Transact Comply for real-time and batch monitoring, rules management and alert generation

Ongoing Risk Intelligence

Dragnet Alpha for adverse media monitoring and emerging risk detection

Regulatory Data

ZIGRAM Data Assets supporting global AML, sanctions and compliance intelligence

These solutions enable institutions to operationalize risk-based compliance while improving efficiency and regulatory preparedness.

Frequently Asked Questions

Does the new law replace Guatemala’s previous AML legislation?

Yes. Decree No. 15-2026 repeals the previous Law Against Money Laundering and the Law for Preventing and Repressing Terrorist Financing, creating a unified AML/CFT framework.

Are cryptocurrency businesses regulated?

Yes. Virtual Asset Service Providers are expressly included as obligated entities and must implement comprehensive AML controls.

Is a risk-based approach mandatory?

Yes. All obligated entities must identify, assess, mitigate, and monitor ML/TF/PF risks based on the nature and complexity of their activities.

What is the cash transaction reporting threshold?

Cash transactions of US$10,000 or more, or the equivalent in national currency or another currency, must be recorded and reported in accordance with the law.

Final Thoughts

Decree No. 15-2026 marks a defining moment in Guatemala’s financial crime compliance landscape. By consolidating AML and CFT legislation into a single framework, embracing FATF-aligned risk-based supervision, extending obligations to VASPs and DNFBPs, strengthening beneficial ownership transparency, and enhancing supervisory powers, Guatemala has established a significantly more robust and future-ready AML regime.

For compliance leaders, the challenge now shifts from understanding the legislation to implementing it effectively. Institutions that proactively modernize governance, technology, customer due diligence, transaction monitoring, and sanctions compliance will be best positioned to meet regulatory expectations while strengthening resilience against evolving financial crime risks.

As Guatemala moves through its phased implementation period, organizations should view this reform not simply as a regulatory obligation, but as an opportunity to build more agile, intelligence-driven, and globally aligned AML compliance programs.

Read about the laws; click here.

Read about the product: Transact Comply

Empower your organization with ZIGRAM’s integrated RegTech solutions – Book a Demo