The Central Bank of Tunisia has published Circular No. 2026-10 of 25 September 2026, setting the rules for the activity and operation of payment institutions. It repeals and replaces Circular No. 2018-16 of 31 December 2018 and enters into force three months after its publication (Article 52), which puts it at the end of December 2026. The press has covered the wider list of services and the higher account ceilings. The bigger change for technical teams is elsewhere: remote onboarding, record-keeping, cybersecurity and a fully coded reporting annex.
Key points
- Higher ceilings (Article 17): level 1 accounts at 1,500 dinars, level 2 at 5,000 dinars, level 3 at 20,000 dinars.
- Remote onboarding open at every level (Article 18), on conditions: document checks against official sources where possible, a liveness check, at least two-factor authentication, and an automatically generated KYC record.
- Information system (Article 12): payment operations must be recorded and processed in real time, including across the agent network, with a tested business continuity plan.
- Annual security audit by an independent firm certified by the National Cybersecurity Agency (ANCS), with the report sent to the BCT (Article 13).
- Transaction registers kept for at least ten years (Article 16).
- New reporting: Annex 1 bis added to Circular 2017-6, with XML or PDF returns and fixed deadlines (Article 50).
The ceilings: before and after
| Account | Circular 2018-16 | Circular 2026-10 |
|---|---|---|
| Level 1 (individuals) | balance 500 TND, outflows 250 TND per day | balance 1,500 TND |
| Level 2 | balance 1,000 TND, outflows 500 TND per day | balance 5,000 TND, cash withdrawals 3,000 TND per day |
| Level 3 | balance 5,000 TND, outflows 1,000 TND per day, in-person opening | balance 20,000 TND, cash withdrawals 10,000 TND per day |
The wording matters. The old text capped total outflows from the account; the new one caps cash withdrawals. Article 23 also creates transitional merchant accounts that are exempt from these ceilings and can only be credited with the merchant's own payment receipts. Cash-based transfers stay capped at 3,000 dinars per operation, and funds received from abroad at 20,000 dinars (Article 3).
Remote onboarding: what the process must prove
In 2018, only level 1 and 2 accounts could be opened remotely, with a check on photos of identity documents. Article 18 now allows remote onboarding at any level, but requires identity verification at least equivalent to an in-person check. The process must cover document authenticity, a liveness check (facial recognition, an audiovisual session or an equivalent reliable method), authentication with at least two factors, explicit consent to personal data processing, encryption, and the automatic generation of a traceable KYC record.
Before going live, the process must be tested in pre-production and the results logged in a performance register that tracks, among other things, the false acceptance rate. It then has to pass penetration tests and audits by bodies approved by ANCS, followed by an audit at least every two years and after any technical or regulatory change. For a product team, this is a specification, not a formality.
Reporting: codes, formats and deadlines
Annex 1 bis gives each return a code, a frequency, a deadline and a format. Some examples:
- RCT03 (balance sheet) and RCT04 (income statement): quarterly, XML, within 30 days.
- RAM05 (commercial indicators) and RAM06 (operations by channel, by count and value): monthly, XML, within 15 days.
- RAT07: list of own branches and appointed agents, quarterly, XML.
- RCIA250100: annual information system security audit report, PDF.
- RROI380: immediate report of a serious incident, XML, on the day of the incident.
Returns go through the BCT Data Exchange System (SED). If the SED is down, Article 51 provides a fallback address: reporting.EP@bct.gov.tn. On incidents, Article 13 requires the institution to inform the BCT and ANCS immediately of any attack or intrusion. If a breach also exposes personal data, our breach notification deadline calculator sets out what Tunisia's Organic Law 2004-63 actually requires.
Governance, products and partnerships
The text brings payment institutions closer to other regulated financial firms. It requires an audit and risk committee and notification of senior appointments to the BCT within seven working days. A full file must reach the BCT before any product launch or fee change (Article 44). Every commercial or technical partnership needs prior authorisation (Articles 30 and 48) and strict separation between the institution's information systems and the partner's. Client funds must be placed in a single pooled account at a bank no later than the next working day after receipt (Article 24).
A note on article numbers
The PDF that some outlets circulated on 25 September contained two articles numbered 1. The version now on the BCT website fixes the numbering, with no other change of substance that we found. Article references here follow the BCT version, so an article cited as 17 elsewhere may be our Article 18.
What to watch
Three months is short for an audited remote onboarding flow, real-time registers and an XML reporting pipeline. The useful question before the end of December is not which new services will launch. It is which institutions will have tested their onboarding process and automated their RAM05 and RAM06 returns before the rules take effect.
The circular belongs to the same series as Circular 2026-08 on honour loans, which already required timestamping and SED reporting. We walked through that implementation in Circular 2026-08 in TypeScript, and the same pattern of registers and returns applies here.
At Noqta we build this kind of pipeline: integration with the core system, traceable registers, automatic generation of regulatory returns, and connections to existing systems. See our services in Tunisia.
Source: Central Bank of Tunisia, Circular No. 2026-10 of 25 September 2026