en

Angola Banks : De-Risking and Cyber Risk

Background Reading for this article

The Financial Action Task Force (FATF)


The FATF is an international body that sets the global rules for stopping money laundering and terrorist financing. The G7 created it in 1989. It is based in Paris and has around 40 member countries.

It has no legal power. It cannot fine a country or force it to do anything. Its influence works entirely through reputation.

The FATF publishes 40 recommendations covering what a country's system should include: identity checks on customers, reporting of suspicious transactions, knowing who really owns a company, and the ability to investigate and prosecute financial crime. Countries are then assessed against those standards.

Two lists follow. The grey list names countries with weaknesses that have promised to fix them, on an agreed plan. Around twenty countries are on it. The black list is far more serious and currently holds only Iran, North Korea and Myanmar.

Being grey-listed brings no sanctions. But every bank in the world checks these lists before doing business. A foreign bank dealing with a listed country must do extra checks, which cost money — so it often ends the relationship instead. That is how a body with no enforcement powers can cut a country off from the dollar.

Updates are published three times a year.

Angola and the FATF Grey List: Compliance, De-Risking and Cyber Risk


Losing access to dollars cost Angola more than any regulation did. Getting it back is the story of the last two years.

Angola was placed on the FATF grey list in October 2024 and was still on it at the June 2026 plenary. The government is targeting exit by 2027.

But the more damaging event happened nine years earlier. In late 2015, US regulators pushed American banks to cut direct dollar clearing relationships with Angolan institutions over compliance failures and money laundering concerns. The country lost direct access to the world's settlement currency, and the foreign exchange crisis that followed shaped the next decade of Angolan finance.

The two stories are connected but not the same, and the sequence matters: in late 2025, with Angola firmly on the grey list, two Angolan banks won back direct correspondent relationships with major international institutions. Compliance at bank level can progress while the country's listing stands.

The key facts

  • Grey-listed October 2024, still listed at the June 2026 plenary, targeting exit by 2027
  • Second time listed — Angola was first listed in 2010 and exited in 2016
  • US dollar clearing cut in late 2015, restored to two banks in late 2025
  • The BNA itself was hit by ransomware in January 2024
  • Cybersecurity is now a formal control function under Aviso n.º 03/2026

Angola returned to the FATF grey list in October 2024

The Financial Action Task Force added Angola to its list of jurisdictions under increased monitoring in October 2024, following the mutual evaluation conducted by ESAAMLG, the regional AML body.

The finding was not that Angola lacked laws. It had passed substantial legislation, including its anti-money laundering and terrorist financing framework. The finding was that legal alignment had not translated into operational effectiveness — few investigations, fewer prosecutions, weak supervision of non-bank entities.

This is Angola's second listing. It was first listed in 2010 and removed in 2016.

Grey-listing carries no direct sanctions. Its effect is indirect and works through the compliance departments of other countries' banks, which treat the FATF lists as inputs to country risk. The practical consequences are higher transaction costs, more documentation, slower payments, and pressure on correspondent relationships.


What Angola has to do to get off the list

The FATF action plan, as set out in the June 2026 statement, requires Angola to:

  1. Improve risk-based supervision of non-bank financial entities and of designated non-financial businesses and professions — lawyers, accountants, real estate agents, dealers in precious stones.
  2. Ensure authorities have adequate, accurate and timely access to beneficial ownership information, and that breaches of those obligations are properly addressed.
  3. Demonstrate an increase in money laundering investigations and prosecutions.
  4. Demonstrate the ability to identify, investigate and prosecute terrorist financing.
  5. Show an effective process for implementing targeted financial sanctions without delay.

Angola has been working through this. Legislative amendments to the AML law were completed in 2025, a beneficial ownership bill went to the National Assembly, and a new NGO statute was approved in January 2026 partly in response to FATF observations — though that law drew strong objections from civil society over freedom of association.

The BNA's position, stated publicly by vice-governor Domingos Pedro, is that the financial system side of the action plan is largely complete and the remaining work sits with other government bodies, professional associations and the justice system.

That is the crux. Three of the five items are about prosecutions and enforcement, not banking regulation. The central bank cannot deliver them, and the FATF has been explicit that it wants convictions and investigations rather than further legislation.


Losing dollar access in 2015 hurt more than the grey list

The correspondent banking problem predates the current listing by nine years.

In late 2015, US regulators moved against Angolan exposure, citing compliance failures and suspected money laundering. American banks terminated direct dollar clearing lines with Angolan institutions.

The consequences were severe. Angolan banks had to clear dollars through chains of smaller intermediaries — small US branches and second-tier banks on other continents — or shift international settlement into euros. Transactions became slower, more expensive and more bureaucratic. Combined with falling oil revenue, the loss of direct dollar access contributed directly to the foreign exchange crisis that followed.

This is why de-risking matters more than the listing itself. Grey-listing raises the cost of doing business; losing correspondent banking removes the ability to do it at all.

.






Two banks won back direct correspondent accounts in 2025


In October 2025 the position changed, for the first time in a decade.

Standard Bank Angola obtained formal approval to open US dollar and euro correspondent accounts with J.P. Morgan. The process began in 2023 with detailed due diligence led by Standard Bank Angola's compliance team, supported by the Standard Bank Group's financial institutions team. Approval came in June 2025 and was finalised in October. It made Standard Bank Angola the first Angolan institution to re-establish a direct relationship with a US bank since 2015, and marked J.P. Morgan's re-entry to the Angolan market.

A week later, BFA announced approval for dollar and euro correspondent accounts with Deutsche Bank, which holds a US dollar clearing licence and an A credit rating. BFA has also been in negotiation with J.P. Morgan and Citibank, though those relationships had not been confirmed as established.

The timing is the interesting part. Both approvals came a year after Angola was grey-listed. What they demonstrate is that correspondent relationships are granted bank by bank, on the strength of an individual institution's compliance function, rather than country by country. A well-run Angolan bank can satisfy J.P. Morgan's due diligence while its home jurisdiction remains under FATF monitoring.

Two banks is not a banking system. But it is a route, and the other large institutions now have a template.


What de-risking does to trade finance

The damage shows up most clearly in the instruments importers rely on.

Letters of credit became slower and more expensive. Foreign issuing banks demanded full cash collateral or additional compliance guarantees before confirming credits for Angolan counterparties, which ties up working capital for the length of a shipment.

Many businesses stopped using them. Faced with unpredictable execution, importers moved to direct outward transfers instead — paying a worse spot cost in exchange for certainty that the shipment moves. That is a rational response to an unreliable system and a poor outcome for everyone: it strips the payment protection that documentary credit exists to provide.

Three developments are easing the pressure from other directions. The kwanza's integration into SADC-RTGS in July 2026 allows regional trade to settle in kwanza without touching a foreign currency at all. BAI has an agreement with the Bank of China to facilitate renminbi trade settlement. And the BNA has approved the renminbi as an eligible currency for meeting banks' foreign currency reserve requirements.

None of these replaces dollar access. All of them reduce dependence on it.

The BNA itself was hit by ransomware in January 2024

The central bank of Angola - Historic pink building with red dome, trees in foreground, and city skyline under clear blue sky.
The central bank of Angola

The central bank was attacked and it was not a minor incident.

The ransomware encrypted central databases, disrupted shared network folders and institutional email, and forced a roughly 24-hour interruption of the SPTR real-time settlement system — the backbone through which every high-value payment in Angola moves.

If the supervisor can be taken offline for a day, the supervised institutions are not in a stronger position. The attack is the clearest available argument for the regulation that followed.


Banks face hundreds of attack attempts every day

The BNA reports an average of 250 to 350 attempted cyberattacks per day against central bank and interbank infrastructure. Angolan bank executives describe the country as among the most heavily targeted in Africa for financial cybercrime.

The attacks that succeed against customers, though, are rarely technical. The dominant vectors are social engineering: fake SMS messages, phishing, WhatsApp account cloning and credential harvesting. Someone persuades a customer to hand over a PIN or a validation code, and no amount of infrastructure spending prevents it.

That is why the consumer-facing rule is so simple and so heavily repeated: neither your bank nor EMIS will ever ask you for a PIN or a validation code.


What the BNA now requires on cybersecurity

The regulatory response has come in stages. In October 2025, vice-governor Domingos Pedro announced that a dedicated cybersecurity framework for the financial sector was being finalised. Governor Manuel Tiago Dias confirmed its approval at the Angola Banking Conference.

Aviso n.º 03/2026 made the structural change. It revoked the 2022 corporate governance code and elevated cybersecurity from an IT responsibility to a formal control function, placing it in the second line of defence alongside risk and compliance. Institutions must formally designate an administrator responsible for it. Payment service providers were given a twelve-month window to comply.

That reclassification matters more than it sounds. A control function reports independently, has defined authority, and is examined by the supervisor. Moving cybersecurity there takes it out of the technology budget and into board accountability.

The operational requirements across the framework and its supporting regulation cover:

Continuous monitoring. Security operations centres running 24/7 threat detection and log monitoring. The BNA operates its own, and EMIS has established one for the payment network.

Access controls. Multi-factor authentication on critical systems, privileged session management, network access control and web application firewalls.

Testing. Periodic vulnerability scanning, penetration testing and code review before new digital services go live.

Incident reporting. Mandatory notification to the BNA of significant breaches, ransomware incidents and outages.

Third-party risk. Due diligence on vendors, fintech partners, core banking providers and cloud platforms — an area that grows in importance as banks integrate with wallets and payment startups.

Four things to watch next

Prosecutions. The FATF wants investigations and convictions, not statutes. This is the binding constraint on exit, and it sits outside the financial sector.

Whether more banks win correspondent relationships. Two in 2025. If BAI, BIC and Millennium Atlântico follow, the constraint genuinely lifts. If not, the benefit stays concentrated in two institutions.

The beneficial ownership register. Operationalising it is the most concrete of the FATF items and the most measurable.

Concentration risk in payments. One national switch and one dominant app, in a country recording hundreds of attack attempts daily. The infrastructure has held, but there is no fallback at national scale.

Frequently asked questions

Is Angola on the FATF grey list? Yes. Angola was added in October 2024 and remained listed at the June 2026 plenary. The government is targeting exit by 2027.

What does grey-listing mean for Angola? It carries no direct sanctions. It signals higher country risk to foreign banks and investors, which raises transaction costs, increases documentation requirements and puts pressure on correspondent banking relationships.

What does Angola have to do to leave the grey list? Improve supervision of non-bank entities and designated professions, make beneficial ownership information accessible, increase money laundering investigations and prosecutions, prosecute terrorist financing, and implement targeted financial sanctions promptly.

Can Angolan banks clear US dollars? Increasingly, yes. Direct relationships were cut in 2015. Standard Bank Angola re-established a direct correspondent account with J.P. Morgan in October 2025, and BFA with Deutsche Bank shortly afterwards.

Was the Angolan central bank hacked? Yes. The BNA suffered a ransomware attack in January 2024 that encrypted databases and interrupted the SPTR settlement system for around 24 hours.

What is Aviso n.º 03/2026? A BNA regulation that elevated cybersecurity to a formal control function within the second line of defence, requiring institutions to designate a responsible administrator. Payment service providers have twelve months to comply.

FATF publishes updated statements three times a year, in February, June and October. Check the current statement before relying on the listing status described here.

.