A company may not be legally required to implement a formal anti-money-laundering program and may still need strong compliance controls.
That distinction is particularly important for foreign companies entering Guatemala, government contractors, suppliers to public entities and businesses operating through distributors, agents, local partners or intermediaries.
The first step is not downloading a generic manual or indiscriminately collecting documents. It is determining the company’s actual exposure, its legal obligations and the controls it needs to contract, invest and operate safely.
Guatemala is entering a new AML framework
Decree 15-2026 contains the Comprehensive Law for the Prevention and Suppression of Money Laundering or Other Assets and Terrorist Financing.
It was published on June 17, 2026 and will enter into force on September 17, 2026. The law consolidates the anti-money-laundering and counter-terrorist-financing regimes, expands the categories of Obligated Persons and strengthens the risk-based approach.
As of this publication, Guatemala is in a transition period. The Superintendency of Banks, through the Special Verification Intendency, is developing the implementing regulation, manuals, instructions and other operating mechanisms.
A company should therefore not wait for every implementing rule before analyzing its exposure. Nor should it assume duties that do not legally apply to it. Preparation should begin with an applicability assessment.
The first question: is the company an Obligated Person?
Not every Guatemalan business or foreign company operating in the country is an Obligated Person.
The answer depends on the activity performed, how the service is delivered, the transactions involved and the categories established by law.
In addition to financial institutions and insurers, the new regime covers specified real-estate and construction activities, trade in certain high-value goods, virtual-asset services and certain legal, economic, accounting and auditing services.
For professionals, holding a license or practicing a profession is not enough by itself. The specific service and its connection to the transactions listed in the statute must be examined.
An applicability assessment should consider:
- What activity does the company actually perform?
- For whom does it receive, manage or transfer funds?
- Does it participate in acquiring or managing assets?
- Does it participate in corporate, trust or wealth structures?
- Does it handle client money, accounts or assets?
- Does it conduct real-estate transactions or trade in specially controlled goods?
- Does it provide virtual-asset services?
- Does it act for itself, as an intermediary or on behalf of others?
- Does a related entity perform an activity covered by the law?
An incorrect conclusion creates two opposite risks: failing to meet applicable duties or building an unnecessarily complex and expensive system.
Supplying the government does not automatically make a company an Obligated Person
Contracting with a public institution, or working with a government supplier, is not enough by itself to place a company within the AML regime. Its activity must still fall within a statutory category.
The absence of a specific AML obligation, however, does not eliminate exposure to corruption, conflicts of interest, fraud, collusion, improper payments, irregular intermediation or opaque corporate structures.
For a foreign company, those risks may extend beyond Guatemala. Depending on its nationality, corporate structure, financing and markets, foreign anti-corruption, sanctions, export-control or parent-company liability rules may also apply.
A business connected with public procurement should therefore maintain an integrity file capable of showing:
- The counterparty’s shareholders and ultimate beneficial owners.
- Who has authority to negotiate and sign.
- How the company or contract was selected.
- Which intermediaries, consultants and subcontractors participate.
- How pricing was determined.
- Whether material family, business or political relationships exist.
- Whether Politically Exposed Persons are involved.
- What goods or services were actually delivered.
- How payments were approved and what evidence supports performance.
The purpose is not to turn every commercial relationship into a criminal investigation. It is to explain why the counterparty was selected, who benefits from the transaction and whether the terms have a reasonable commercial basis.
Due diligence should come before the contract
Many companies request compliance documents only after the relationship has begun or when a bank, auditor or investor asks a question. By then, the company may have signed agreements, paid advances, shared confidential information or allowed a third party to act in its name.
Useful due diligence should occur before approval and should be proportionate to risk. At a minimum, it should verify:
- The counterparty’s legal existence and good standing.
- Its shareholders, managers and ultimate beneficial owners.
- The signing authority of the relevant individual.
- Its experience and practical ability to perform.
- Its commercial reputation and material public background.
- Material litigation, sanctions or adverse findings.
- The involvement of Politically Exposed Persons.
- The reasonable source and destination of funds, when relevant.
- The transaction’s economic rationale.
- Consistency among the service, price, payment method and recipient of funds.
The ultimate beneficial owner matters more than the trade name
A company may be validly registered and still be used to conceal those who control or benefit from a transaction. Due diligence should therefore go beyond the legal representative.
The company should identify the natural persons who directly or indirectly:
- Own or control the entity.
- Exercise significant influence over its decisions.
- Receive the principal economic benefit.
- Control another entity within the structure.
- Act through relatives, attorneys-in-fact or interposed companies.
When ownership extends across jurisdictions, the review should continue until the full structure is understood.
The same information will not always be available from every counterparty. Unjustified resistance to disclosing ownership is itself a factor that should be evaluated.
Not every third party presents the same risk
A reasonable program does not treat an ordinary supplies vendor in the same way as an intermediary negotiating with public officials.
Risk classification may consider:
- The countries and territories connected to the transaction.
- The industry and the value and frequency of transactions.
- The use of cash or bank accounts in third countries.
- The involvement of public officials, public entities or intermediaries.
- The complexity of the ownership structure.
- Limited verifiable experience or unusual commissions.
- Unjustified urgency or refusal to provide information.
- Unclear agreements or services that are difficult to verify.
Lower-risk relationships may receive simplified review. Higher-risk relationships require additional information, senior approval, specific contractual protections and periodic monitoring.
Red flags that should not be ignored
No single red flag necessarily proves misconduct. Certain circumstances do, however, require additional review:
- A newly formed company receives a contract clearly beyond its capacity.
- A third party requests payment to another person or jurisdiction.
- The bank account does not belong to the contractual counterparty.
- An intermediary claims special access to public officials.
- The commission is disproportionate or the contract’s purpose is vague.
- There is no verifiable evidence of the work performed.
- Ownership changes during negotiations or beneficial owners are concealed.
- The counterparty requests cash, extraordinary advances or split invoices.
- Relatives or close associates of public officials appear in the transaction.
- The counterparty demands removal of audit, integrity or termination clauses.
The system’s function is not to produce an automatic accusation. It is to pause the transaction, obtain information and allow an authorized decision-maker to reach a documented conclusion.
A minimum program must work in practice
A compliance program is not measured by the number of pages in its manual.
A small or mid-sized company can build a reasonable system with basic, verifiable elements:
- A responsible person and criteria for classifying risk.
- Know-your-customer and third-party forms.
- Identification of ultimate beneficial owners.
- Sanctions, PEP and material-background screening.
- Approval levels and compliance clauses.
- A consultation and escalation channel.
- Orderly recordkeeping.
- Training for personnel who contract, buy, sell or approve payments.
- Periodic review of higher-risk relationships.
- Evidence supporting the decisions made.
Controls must become part of the operation. If procurement, sales, finance and management do not know when to stop a transaction, the manual exists only on paper.
Due diligence does not end when the contract is signed
A counterparty’s circumstances may change. It may add new owners, retain intermediaries, begin dealing with the government, change its bank account or delegate performance to an unknown subcontractor.
Information should therefore be updated according to risk, with defined events triggering renewed review: ownership or management changes, material renewals or increases, public-sector activity, unexpected payment changes, adverse information or new intermediaries.
Due diligence is an ongoing process, not a file archived after the first meeting.
What a company should do during the transition
Before Decree 15-2026 enters into force, a company should:
- Determine whether it will be an Obligated Person under the new regime.
- Identify the duties applicable to its particular activities.
- Monitor the implementing regulation and guidance issued by the SIB and IVE.
- Map higher-risk customers, suppliers, intermediaries and other third parties.
- Identify relationships connected with public officials or government procurement.
- Review existing forms, contracts and files.
- Define responsibilities and approval levels.
- Train the people who will make the relevant decisions.
- Document gaps and establish an implementation plan.
- Create a review mechanism to adapt the system as new rules are issued.
Compliance should protect the business
A good compliance system does not exist to fill out forms. It exists to prevent a company from entering a relationship it does not understand, giving authority to the wrong person or making payments it cannot later explain.
It also enables faster, stronger responses to banks, investors, auditors, international buyers and authorities.
The question is not only whether the law obligates a company. The question is whether it can demonstrate that it knows its business partners, understands the purpose of its transactions and makes decisions consistent with its risk.
That capability is becoming a condition for investing, contracting and growing safely in Guatemala.
Official sources consulted
Information current as of August 18, 2026. This article is provided for informational purposes and does not constitute legal advice or determine whether any person or company is subject to specific obligations.
