- mandatory KYC documents Morocco
- The KYC file contains verified identity details, an address, an occupation or activity, the purpose of the relationship, and supporting documents appropriate to the level of risk.
- Morocco beneficial owner 25%
- A beneficial owner is notably the natural person who directly or indirectly controls more than 25% of the capital or voting rights.
- company KYC documents Morocco
- A company must provide documents proving its existence, its articles of association, details of its officers, the signatory’s authority, its ownership structure, and its beneficial owners.
- politically exposed person Morocco
- A PEP, their family members, and their associates require appropriate approval, inquiries into the source of funds, and enhanced monitoring.
- updating client files
- The client file must be updated according to risk and whenever a significant change affects identity, activity, or ownership.
- 10-year KYC document retention
- KYC documents and transaction records must be retained for ten years under the conditions established by Article 7 of Law No. 43-05.
KYC, meaning Know Your Customer, refers to the customer due diligence measures provided for in Articles 3 et seq. of consolidated Law No. 43-05. Before establishing a business relationship or carrying out an occasional transaction falling within the scope of the framework, the business collects the client’s identity details and verifies them using reliable documents. For a Moroccan natural person, the file generally includes the electronic national identity card, address, occupation, contact details, and information about the purpose of the relationship. For a non-resident, the passport, any residence permit, and tax residence must be examined.
For a company, requesting only Form J or a copy of the articles of association is not sufficient. Its legal existence, officers, the signatory’s authority, address, actual activity, capital structure, and beneficial owner must be verified. Decree No. 2-21-708 of November 3, 2021 on the public register of beneficial owners notably uses the criterion of direct or indirect control of more than 25% of the capital or voting rights. If no holder is identified under this criterion, the analysis seeks to identify the person exercising control by other means and then, failing that, the principal executive in accordance with the applicable rules.
Consulting the register of beneficial owners does not remove the obligation to verify the information provided. A chain involving a foreign holding company, a non-trading company, shares held on behalf of another person, or an agent warrants additional supporting documents. In practical terms, the obliged person must trace ownership back to a natural person and understand why that person controls the transaction. If the person’s identity cannot be satisfactorily established, the relationship must not be opened or continued. Failure to identify the person may also constitute a red flag to be analyzed with a view to submitting a suspicious transaction report, without informing the client of that possibility.
Due diligence continues after the relationship begins. The business compares transactions with the declared profile, updates expired documents, and reassesses the risk level when the client’s ownership, activity, country of operation, or conduct changes. Enhanced due diligence is required in particular for politically exposed persons, their family members and close associates, complex arrangements, transactions with no apparent economic purpose, or links to a high-risk jurisdiction. It requires additional supporting documents, approval at an appropriate management level, and more frequent monitoring.
Identification documents and transaction records are retained for ten years in accordance with Article 7 of consolidated Law No. 43-05. The starting point depends on the nature of the document: the end of the business relationship or the execution of the relevant occasional transaction. Records may be stored electronically if this guarantees their integrity, availability, confidentiality, and prompt retrieval. In practice, an unsecured spreadsheet or personal email account does not meet these requirements. Access must be restricted to authorized employees and must comply with Law No. 09-08 on personal data protection.