D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.
Tunisia's AML/CFT regime rests on Organic Law No.26 (2015) and CTAF (Commission Tunisienne des Analyses Financieres) as FIU.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Crypto / Digital Assets / Financial Innovation is not yet covered for this jurisdiction in this report.
Banque Centrale de Tunisie Circular 2026-10, published 25 September 2026 and confirmed on the regulator's own site, is the active-defence story of the cycle for Tunisia's payment sector. The circular repeals and replaces Circular 2018-16 and, on corroborating Tunisian press reporting, mandates an annual cybersecurity audit certified by the national cybersecurity agency ANCS for all licensed payment institutions. It further requires a board-level audit-and-risk committee, embedding technical compliance oversight at governance level rather than leaving it to operational teams alone. These requirements sit alongside a tightening of digital-KYC identification procedures, read together as a package that raises the baseline technical-control expectation for the sector rather than responding to a single incident.
The architecture-over-incident framing matters here: there is no disclosed breach or enforcement action driving this circular as reported. Instead, the BCT is acting ahead of any incident to formalise cyber-audit cadence and governance accountability, which is the kind of structural move that this monitor treats as more analytically significant than a reactive enforcement step in an already well-regulated centre. The content of the obligation -- a recurring certified audit tied to a national technical authority, plus a standing board committee -- is confirmed to exist via the T1 regulator source, though the granular detail of the audit and committee requirements rests on T3 Tunisian press corroboration rather than a retrieved primary circular text, which keeps those specifics at a probable rather than confirmed tier.
The three-month transition window, running from the 25 September 2026 publication date to approximately 25 December 2026, is the operative compliance clock. Payment institutions have that period to stand up the audit-and-risk committee and arrange the first ANCS-certified cyber audit cycle, alongside whatever digital-onboarding and identification-technology changes the circular requires. No enforcement posture for non-compliance after that date has been sourced this cycle.
The near-term marker is the compliance deadline itself, around 25 December 2026. Confirmation of the primary circular text directly from the BCT would resolve the current gap between the confirmed fact of the circular's existence and date, and the probable-tier detail of its specific audit and governance requirements. Analysts should watch for whether ANCS publishes implementing guidance on the certification standard referenced by the circular, which would be the next concrete milestone in this compliance-technology track.
Tunisia's standing AML/CTF architecture is governed by Organic Law No. 2015-26 of 7 August 2015, as amended by Organic Law No. 2019-9, with CTAF -- housed at the Banque Centrale de Tunisie -- operating as the designated financial intelligence unit. BCT Circular No. 2017-08, as amended by Circular No. 2025-17, operationalises sector controls including goAML filing and a ten-year record-retention standard. This standing record is corroborated by third-party commentary rather than a primary text retrieved this cycle, which keeps the governing-law citation at a probable tier even though the underlying facts are well established.
Two developments this cycle sit inside this frame. First, BCT Circular 2026-10, published 25 September 2026 and confirmed directly on the BCT's own site, repeals and replaces Circular 2018-16, tightening digital-KYC identification protocols for payment institutions alongside the governance and cyber-audit measures addressed under compliance technology. This is a confirmed, structural tightening of the identification layer that underpins AML controls for the payment-institution sector specifically, with a three-month transition to roughly 25 December 2026. Second, a joint order of the Ministers of Tourism, the Interior and Finance, dated 29 January 2026, placed licensed casinos under the full Organic Law 2015-26 regime -- risk assessment, a compliance officer, staff training, independent audit, ten-year record retention and immediate suspicious-transaction reporting to CTAF -- repealing a narrower 2018 casino-specific order. This casino-sector extension rests on a single trade-press source without a retrieved primary gazette text, capping it at a probable tier, and falls outside this cycle's immediate recency window as a January dated development surfaced now.
On the international-standing axis, Tunisia is confirmed not to be among the jurisdictions on the FATF's list of jurisdictions under increased monitoring as of the 19 June 2026 Plenary statement, consistent with a 2019 follow-up mutual evaluation report that rated the country compliant or largely compliant on the substantial majority of the FATF's forty recommendations. This is independently corroborated against FATF's own published list and is the strongest-sourced finding in this domain this cycle.
Read together, the picture is of a regime enforcing and extending existing AML/CFT architecture into new sectors (casinos) and new identification technology (digital-KYC for payment institutions), rather than one undergoing legal-base reform. No change to Organic Law 2015-26 itself, nor to CTAF's institutional role, was identified this cycle.
The casino order's absence of a retrieved primary gazette text and the payment-circular's reliance on secondary corroboration for granular detail are the two live gaps in this domain. Resolving either would move the relevant finding from probable to confirmed. Tunisia's grey-list-absent status is stable and was reaffirmed independently this cycle; no near-term FATF review affecting that status has been sourced.
Commercial Activity is not yet covered for this jurisdiction in this report.
Suspicious-transaction reporting obligations to CTAF now explicitly cover licensed casinos under the full Organic Law 2015-26 regime, and payment-institution digital-KYC identification standards are being tightened with a compliance deadline around 25 December 2026.
A board-level audit-and-risk committee and an annual ANCS-certified cybersecurity audit become compliance obligations, alongside tightened digital identification procedures, with full compliance expected by approximately 25 December 2026.
No material change for this persona this cycle
The direction of regulatory travel in Tunisia is toward stricter governance and technical-control standards for payment institutions, a structural signal for any institution with exposure there, set against a stable, non-grey-listed AML/CFT standing.
Technical infrastructure supporting onboarding identification and periodic security certification will need to meet a new, named-standard audit cadence within the three-month transition window.
Crypto exposure risk in Tunisia remains governed by the existing prohibition pending a legislative change that has not progressed past committee hearings through at least June 2026.
Onboarding and identification workflows for payment institutions will need updating to the tightened digital-KYC standard introduced by the new circular within the transition period.
Internal audit scoping for Tunisia-exposed obligations should note that neither the casino order nor the granular payment-circular requirements have been verified against a retrieved primary gazette or circular text this cycle.
BCT Circular 2026-10 tightens payment-institution KYC identification and a January 2026 order brought casinos fully inside the AML/CFT reporting perimeter.
Payment institutions face a three-month transition to new governance, cyber-audit and digital-KYC requirements under BCT Circular 2026-10.
No material change for this persona this cycle.
Tunisia's regulator tightened, rather than relaxed, payment-sector oversight, while the country remains outside the FATF grey list.
Circular 2026-10 mandates an annual ANCS-certified cybersecurity audit and tightened digital-identification technology for Tunisian payment institutions.
A draft Foreign Exchange Code reform (Bill 115/2025) that would permit limited BCT-authorised crypto activity remains stalled in committee.
New branch and client-facing identification procedures under Circular 2026-10 will require operational workflow updates ahead of the roughly 25 December 2026 deadline.
The casino sector's extension into the full AML/CFT regime and the payment-circular overhaul both currently rest on secondary rather than primary-text corroboration.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | no_change | No TN nexus identified in continuing OFAC Ansarallah/Houthi-network designations this cycle. |
| T2 · EU AML Package / AMLA | no_change | Tunisia is outside the EEA and not bound by AMLR/6AMLD/AMLA; no transposition-delta applies. |
| T3 · FATF Grey List | no_change | Tunisia is not among the 22 jurisdictions on the FATF grey list as of the 19 June 2026 Plenary statement. |
| T4 · Beneficial-Ownership Register Status | no_change | No TN beneficial-ownership registry development identified this cycle; awaiting primary-source confirmation. |
| T5 · Crypto & Digital-Asset Integrity | watch | Draft Foreign Exchange Code (Bill 115/2025) and a separate decriminalisation/licensing bill remain in parliamentary committee review; crypto remains fully prohibited under the 2018 BCT directive meanwhile. |
| T6 · Sanctions Regime Divergence | no_change | No TN-specific sanctions-regime divergence development this cycle. |