ماليزيا KYC, KYB & AML compliance checklist
قائمة عملية وموثقة بالمصادر لتنفيذ متطلبات KYC وKYB وAML في ماليزيا.
- تاريخ آخر مراجعة
- تاريخ آخر مراجعة:
- الإصدار
- الإصدار 1.1

دليل تنفيذ قابل للتنزيل
الحصول على ملف PDF
11 مجالات رقابية · 42 فحوص تنفيذ
تاريخ آخر مراجعة: 25 September 2026 · الإصدار 1.1
تنزيل قائمة التحققإجابة مباشرة
ما الذي تغطيه قائمة الامتثال الخاصة بـ ماليزيا؟
تحوّل قائمة ماليزيا قواعد KYC وKYB وAML الأساسية إلى 11 مجالات رقابية و42 فحوص تنفيذ، وتشمل الجهات المختصة وواجبات الإبلاغ والأدلة الواجب الاحتفاظ بها.
حقائق تنظيمية أساسية
- Competent authority and FIU
- Bank Negara Malaysia (BNM), Financial Intelligence and Enforcement Department
- Primary AML law
- AMLA 2001 as amended by Act A1761, effective 1 March 2026
- STR timing
- Promptly; under BNM's financial-institution policy, by the next working day after the compliance officer establishes suspicion
- Cash threshold report
- For covered financial institutions: RM25,000 or more in aggregated qualifying cash transactions in the same account in one day
- AML retention
- At least 6 years from the applicable transaction-completion or relationship-termination event; longer where directed or investigated
- Company-register BO
- Separate SSM criteria include direct or indirect holdings of not less than 20%, plus control-by-other-means tests
- Privacy
- PDPA 2010 as amended; biometric data is sensitive personal data; breach, DPO, transfer and DPIA controls may apply
- FATF public lists
- Not listed at 19 June 2026; 2025 mutual-evaluation roadmap remains relevant
تفاصيل التنفيذ
متطلبات وإجراءات الامتثال في ماليزيا
افتح كل مجال لمراجعة المتطلب وإجراء التنفيذ المقترح والأدلة الواجب الاحتفاظ بها والمصدر الأساسي.
01Scope, authorities, and licensingMap the actual activity, regulator and licence before applying a control set.4 عناصر+
Determine whether each activity is carried on by a reporting institution under AMLA.
- إجراء التنفيذ
- Map every product, service, customer journey, branch and agent to the current First Schedule activity and record the applicable financial-institution or DNFBP/NBFI policy document; include the Act A1761 changes effective 1 March 2026.
- الأدلة الواجب الاحتفاظ بها
- Activity and entity map, First Schedule analysis, policy-document mapping, legal update log and counsel or compliance approval.
- المصدر الأساسي
- AMLA 2001, sections 3, 7 and 7A and First Schedule, as amended by Act A1761; BNM AMLA portal
Identify the competent authority and sector supervisor.
- إجراء التنفيذ
- Route AMLA reporting and competent-authority matters to BNM's Financial Intelligence and Enforcement Department while documenting the relevant regulatory or supervisory authority for the entity and activity.
- الأدلة الواجب الاحتفاظ بها
- Regulatory perimeter memo, supervisor directory, reporting access, escalation tree and correspondence log.
- المصدر الأساسي
- AMLA 2001, sections 7, 7A and 8; Act A1761; BNM AMLA portal
Obtain every required sector approval before regulated activity.
- إجراء التنفيذ
- Confirm licensing or approval under the FSA, IFSA, MSBA, capital-markets framework or other sector law; do not treat AMLA registration or compliance as permission to provide the underlying service.
- الأدلة الواجب الاحتفاظ بها
- Licence or approval, conditions, service inventory, renewal calendar, agent approvals and launch sign-off.
- المصدر الأساسي
- Financial Services Act 2013; Islamic Financial Services Act 2013; Money Services Business Act 2011; SC Guidelines on Recognized Markets
Control branches, subsidiaries, agents and outsourced functions.
- إجراء التنفيذ
- Apply the required group programme, information-sharing safeguards and risk-based oversight; document responsibility and applicable Malaysian or host-country rules for each delivery party.
- الأدلة الواجب الاحتفاظ بها
- Group standard, contracts, due diligence, responsibility matrix, monitoring results and remediation.
- المصدر الأساسي
- BNM AML/CFT/CPF and TFS for FIs PD, paragraphs 13 and 18; applicable DNFBP/NBFI PD provisions
02Governance and risk assessmentGovernance must reflect the institution's actual ML/TF/PF exposure, scale and complexity.4 عناصر+
Maintain documented business and relationship risk assessments.
- إجراء التنفيذ
- Assess customers, countries, products, services, transactions, delivery channels, technology, agents and outsourcing for ML/TF/PF risk and refresh after material change or new national and sector risk information.
- الأدلة الواجب الاحتفاظ بها
- Methodology, current assessments, data sources, approvals, residual-risk decisions and remediation plan.
- المصدر الأساسي
- AMLA 2001, sections 16 and 19; BNM FIs PD, paragraph 10; applicable DNFBP/NBFI PD risk provisions
Maintain an effective AML/CFT/CPF compliance programme.
- إجراء التنفيذ
- Translate risks into policies for CDD, beneficial ownership, PEPs, monitoring, reporting, sanctions, records, training, independent audit and regulatory response.
- الأدلة الواجب الاحتفاظ بها
- Board-approved programme, control map, procedures, testing, training and issue closure.
- المصدر الأساسي
- AMLA 2001, section 19 as amended by Act A1761; BNM FIs PD, paragraph 11
Appoint accountable compliance leadership.
- إجراء التنفيذ
- Appoint a management-level compliance officer, notify BNM when the applicable policy requires it, preserve independence and resources, and maintain branch-level responsibility where required.
- الأدلة الواجب الاحتفاظ بها
- Appointment, BNM notification, job description, reporting line, resources, branch designations and minutes.
- المصدر الأساسي
- AMLA 2001, section 19(4); BNM FIs PD, paragraphs 11.3 and 11.4; applicable DNFBP/NBFI PD
Test programme effectiveness independently.
- إجراء التنفيذ
- Set a risk-based audit scope and frequency, give reviewers access to systems and samples, report findings to appropriate governance and verify remediation.
- الأدلة الواجب الاحتفاظ بها
- Audit plan, independence record, workpapers, report, management response and closure testing.
- المصدر الأساسي
- BNM FIs PD, paragraph 11.7; applicable DNFBP/NBFI PD independent-audit provisions
03Natural-person identificationCDD triggers and minimum data vary by sector and product; suspicion overrides monetary thresholds.4 عناصر+
Apply CDD at every applicable trigger.
- إجراء التنفيذ
- Complete CDD when establishing a relationship and at the sector-specific occasional-transaction, cash, wire, e-money or other trigger, and always when suspicion exists or prior information is doubtful.
- الأدلة الواجب الاحتفاظ بها
- Trigger matrix by sector, onboarding record, transaction aggregation, suspicion override and refresh decision.
- المصدر الأساسي
- AMLA 2001, section 16 as amended by Act A1761; BNM FIs PD, paragraphs 14A.1, 14B.2, 14C.2 and 14D.2
Identify and verify each individual from reliable independent sources.
- إجراء التنفيذ
- Collect the applicable name, official identifier, address, birth, nationality, occupation and contact attributes, verify authenticity and resolve discrepancies before proceeding except under an express controlled allowance.
- الأدلة الواجب الاحتفاظ بها
- Identity record, source images and provenance, verification results, fraud checks and discrepancy resolution.
- المصدر الأساسي
- AMLA 2001, section 16; BNM FIs PD, paragraphs 14A.9.1, 14B.11.1, 14C.10.1 and 14D.9.1
Verify representatives and their authority.
- إجراء التنفيذ
- Identify and verify each person acting for a customer and validate written authority, mandate or directors' resolution before accepting instructions.
- الأدلة الواجب الاحتفاظ بها
- Representative KYC, mandate, signatory rules, validity checks and activity log.
- المصدر الأساسي
- BNM FIs PD, paragraphs 14A.3(b), 14A.9.5, 14B.3(b), 14C.4(b) and 14D.3(b)
Do not proceed when required CDD cannot be completed.
- إجراء التنفيذ
- Do not open the account, start the relationship or perform the transaction, or terminate an existing relationship as applicable; document the reason and promptly assess and file an STR without tipping off.
- الأدلة الواجب الاحتفاظ بها
- CDD failure record, restriction or exit action, STR decision, filing receipt and confidentiality controls.
- المصدر الأساسي
- BNM FIs PD, paragraphs 14A.16-14A.17, 14B.18-14B.19, 14C.17-14C.18 and 14D.17-14D.18
04KYB, registries, and beneficial ownershipAML beneficial ownership and SSM company-register reporting are related but distinct tests.4 عناصر+
Verify legal existence, powers and business purpose.
- إجراء التنفيذ
- Obtain current incorporation or registration evidence, legal form, identifiers, registered and principal addresses, governing documents, directors or partners and intended activity from SSM and other reliable sources.
- الأدلة الواجب الاحتفاظ بها
- Registry extract, constitutional documents, identifier checks, officer list, business profile and discrepancies.
- المصدر الأساسي
- AMLA 2001, section 16; BNM FIs PD, paragraphs 14A.9, 14B.11, 14C.10 and 14D.9
Identify and verify AML beneficial owners through the prescribed cascade.
- إجراء التنفيذ
- Trace ownership to natural persons, including at minimum directors, partners and shareholders with more than 25% equity under the BNM FIs PD; then assess control by other means and use the relevant senior-management fallback only when no natural person is identified.
- الأدلة الواجب الاحتفاظ بها
- Ownership chart, share data, control analysis, verified identities, source records and fallback rationale.
- المصدر الأساسي
- BNM FIs PD, paragraphs 14A.9.6, 14B.11.12, 14C.10.7 and 14D.9.6
Identify parties to trusts and comparable arrangements.
- إجراء التنفيذ
- Identify and verify settlors, trustees, protectors, beneficiaries or classes, objects of a power and any other natural person exercising ultimate effective control, including through the chain of control or ownership.
- الأدلة الواجب الاحتفاظ بها
- Trust deed, party schedule, control and ownership chain, identity verification and change monitoring.
- المصدر الأساسي
- BNM FIs PD, definition of beneficial owner and paragraphs 14A.9.13, 14B.11.19, 14C.10.14 and 14D.9.13
Keep SSM beneficial-ownership reporting separate from AML CDD.
- إجراء التنفيذ
- Apply the Companies Act and revised SSM guideline criteria, including not-less-than-20% direct or indirect share or voting holdings and control by other means; record and lodge changes within the applicable 14-day stages and continue identification efforts when senior management is recorded as fallback.
- الأدلة الواجب الاحتفاظ بها
- Register of beneficial owners, notices, responses, verification, e-BOS lodgements, annual return and fallback review log.
- المصدر الأساسي
- Companies Act 2016, Division 8A, sections 60A-60D and 68; SSM BO Guideline revised 2025, paragraphs 20-29 and 43-50
05PEPs, enhanced due diligence, and remote onboardingHigher-risk relationships require corroboration, approval and intensified monitoring.4 عناصر+
Identify foreign, domestic and international organisation PEP exposure.
- إجراء التنفيذ
- Screen customers, beneficial owners and relevant connected persons for PEP, family-member and close-associate status and refresh the assessment during the relationship.
- الأدلة الواجب الاحتفاظ بها
- Screening results, data source, relationship map, risk rationale and refresh history.
- المصدر الأساسي
- BNM FIs PD, paragraph 15 and definitions of PEP, family member and close associate
Apply enhanced CDD to higher-risk cases.
- إجراء التنفيذ
- Obtain additional customer and beneficial-owner information, corroborate source of wealth or funds, obtain senior-management approval and increase monitoring; for PEPs, obtain both source of wealth and source of funds as required by the applicable policy.
- الأدلة الواجب الاحتفاظ بها
- EDD trigger, additional sources, corroboration, approval, monitoring plan and review.
- المصدر الأساسي
- BNM FIs PD, paragraphs 14A.12, 14B.14, 14C.13 and 14D.13; paragraph 15
Use simplified CDD only on documented low risk.
- إجراء التنفيذ
- Confirm the sector-specific eligibility and Board or management approval, keep effective monitoring and withdraw simplified treatment when risk increases or suspicion arises.
- الأدلة الواجب الاحتفاظ بها
- Eligibility assessment, approval, configured limits, monitoring results and withdrawal trigger.
- المصدر الأساسي
- BNM FIs PD, paragraphs 14A.10, 14B.12, 14C.11 and 14D.10
Control non-face-to-face identity risk.
- إجراء التنفيذ
- Apply the current BNM e-KYC and sector requirements to document authenticity, biometric or liveness controls, impersonation, device and channel risk, fallback review and model or vendor governance.
- الأدلة الواجب الاحتفاظ بها
- Method assessment, test results, exception handling, vendor diligence, monitoring and model-change approvals.
- المصدر الأساسي
- BNM Electronic Know-Your-Customer Policy Document, 15 April 2024; BNM FIs PD non-face-to-face provisions
06Monitoring and suspicious transaction reportingSuspicion covers transactions, activities and property under amended AMLA, while the saved BNM policy also captures attempted and proposed transactions.4 عناصر+
Conduct ongoing due diligence and transaction monitoring.
- إجراء التنفيذ
- Scrutinise activity against the customer's business, risk and source-of-funds profile, keep CDD and beneficial ownership current and escalate unusual patterns or new risk promptly.
- الأدلة الواجب الاحتفاظ بها
- Scenario inventory, alerts, case files, profile refreshes, tuning and dispositions.
- المصدر الأساسي
- AMLA 2001, section 16 as amended by Act A1761; BNM FIs PD ongoing-due-diligence provisions
Assess statutory and policy suspicion triggers.
- إجراء التنفيذ
- Evaluate transactions, activities and property under amended AMLA for links to unlawful activity, ML, TF or restricted-activity financing. For institutions subject to the saved BNM FIs policy, also assess attempted and proposed transactions; record when reasonable grounds arose.
- الأدلة الواجب الاحتفاظ بها
- Alert chronology, facts reviewed, statutory or policy ground, decision-maker, decision time and escalation.
- المصدر الأساسي
- AMLA 2001, section 14 as amended by Act A1761; Act A1761, section 52(5); BNM FIs PD, paragraph 22.1.1
Submit an STR through BNM's prescribed channel on time.
- إجراء التنفيذ
- Submit promptly through the Financial Intelligence System or current prescribed route. For an institution governed by the BNM FIs PD, file by the next working day after the compliance officer establishes suspicion; verify the sector-specific rule before relying on that deadline.
- الأدلة الواجب الاحتفاظ بها
- Internal report, confirmation timestamp, STR, FINS receipt, supplemental filing and delay analysis.
- المصدر الأساسي
- AMLA 2001, section 14; BNM FIs PD, paragraphs 22.1-22.2, especially 22.2.6
Protect STR and investigation information.
- إجراء التنفيذ
- Restrict knowledge and disclosure, use need-to-know access, review any customer communication for tipping-off risk and preserve statutory confidentiality and permitted-disclosure analysis.
- الأدلة الواجب الاحتفاظ بها
- Access logs, disclosure register, legal review, communications approval, training and incident record.
- المصدر الأساسي
- AMLA 2001, sections 14A and 20; BNM FIs PD, paragraph 23
07Cash, wire transfers, payments, and digital assetsAmounts and licensing duties attach to specific products and institution types.4 عناصر+
Report covered cash transactions at the correct scoped threshold.
- إجراء التنفيذ
- For institutions subject to the BNM FIs PD cash-reporting rule, aggregate qualifying physical-currency and bearer-instrument deposits and withdrawals in the same account in one day and report RM25,000 or more; do not extend this threshold to every AMLA reporting institution or non-cash activity.
- الأدلة الواجب الاحتفاظ بها
- Aggregation logic, cash data, exclusions, CTR, FINS receipt and quality review.
- المصدر الأساسي
- BNM FIs PD, paragraphs 21.2-21.4
Transmit and retain required wire-transfer information.
- إجراء التنفيذ
- For cross-border wires of RM3,000 or more, include accurate originator and required beneficiary details; apply the reduced below-threshold dataset, domestic traceability, missing-data controls and beneficiary verification exactly as the policy requires.
- الأدلة الواجب الاحتفاظ بها
- Field matrix, payment samples, validation rules, exception queue, beneficiary checks and retention.
- المصدر الأساسي
- BNM FIs PD, paragraphs 19.1-19.4
Obtain approval before issuing e-money and apply the product's AML limits.
- إجراء التنفيذ
- Confirm approval under section 11 of the FSA or IFSA unless a current limited-purpose exemption applies, implement the 31 January 2025 e-money policy and map the product to the applicable CDD, account and transaction limits.
- الأدلة الواجب الاحتفاظ بها
- Approval or exemption analysis, product limits, safeguarding, CDD configuration, testing and reporting.
- المصدر الأساسي
- FSA 2013, section 11; IFSA 2013, section 11; BNM Electronic Money Policy Document, revised 31 January 2025; BNM FIs PD, paragraph 14D and Appendix 3
Use licensed MSB providers and registered digital-asset operators.
- إجراء التنفيذ
- Obtain the appropriate BNM MSB licence for money changing, remittance or wholesale currency business and SC registration for a DAX or other regulated digital-asset role; verify agents and current public registers before reliance.
- الأدلة الواجب الاحتفاظ بها
- Licence or registration, public-register check, agent certificate, conditions, service map and renewal monitoring.
- المصدر الأساسي
- Money Services Business Act 2011; BNM MSB directory; SC Guidelines on Recognized Markets, revised 20 May 2026; SC Digital Assets portal
08Targeted financial sanctionsTerrorism, proliferation and other UN sanctions controls apply independently of ordinary CDD thresholds.3 عناصر+
Screen current domestic and UN lists without threshold.
- إجراء التنفيذ
- Screen customers, beneficial owners, beneficiaries, representatives and transactions against the Domestic List and relevant UNSCR lists at onboarding, ongoing review and immediately after list updates; assess ownership, control and direction, not names alone.
- الأدلة الواجب الاحتفاظ بها
- List versions, update timestamps, screening scope, configuration tests, match analysis and dispositions.
- المصدر الأساسي
- AMLA 2001, Part VIA; BNM FIs PD, paragraphs 27.3-27.5, 28.2-28.4 and 29.2-29.4
Freeze, block or reject immediately and without delay after confirmation.
- إجراء التنفيذ
- Upon confirming a designated or specified person or related party, freeze covered funds, property or economic resources, block applicable transactions or reject the potential customer, and permit dealings only under verified written authority.
- الأدلة الواجب الاحتفاظ بها
- Match confirmation, ownership-control analysis, action timestamp, system blocks, authority and release decision.
- المصدر الأساسي
- AMLA 2001, sections 66B and 66E; BNM FIs PD, paragraphs 27.6, 28.5 and 29.5
Report positive matches immediately to the required authorities.
- إجراء التنفيذ
- Use the current prescribed form to report terrorism-related positive matches immediately to BNM and the Inspector-General of Police, and PF or other UN-sanctions actions immediately to BNM; submit related STRs and periodic updates where required.
- الأدلة الواجب الاحتفاظ بها
- Positive-match report, delivery receipts, STR, periodic report, communications and frozen-asset ledger.
- المصدر الأساسي
- BNM FIs PD, paragraphs 27.7-27.8, 28.6-28.7 and 29.6-29.7
09Records and regulator accessRetention must preserve reconstruction and remain extended for investigations or directions.3 عناصر+
Retain AML records for at least six years from the correct event.
- إجراء التنفيذ
- Keep CDD, account, activity and transaction records for at least six years after the transaction is completed or the relationship is terminated, using the later applicable event under the amended section 17 wording.
- الأدلة الواجب الاحتفاظ بها
- Retention schedule, event mapping, system configuration, sample retrieval and deletion controls.
- المصدر الأساسي
- AMLA 2001, section 17 as amended by Act A1761; BNM FIs PD, paragraph 24.3
Extend holds for investigations and competent-authority directions.
- إجراء التنفيذ
- Suspend deletion when records are under investigation, prosecution, regulatory request or a current extension direction, and document release authority before disposal.
- الأدلة الواجب الاحتفاظ بها
- Legal-hold notice, affected systems, custodian acknowledgement, extension direction and release approval.
- المصدر الأساسي
- AMLA 2001, section 17; BNM FIs PD, paragraph 24.4
Make records reconstructable and promptly accessible.
- إجراء التنفيذ
- Preserve origin, destination, amount, currency, parties, authority, CDD sources, decisions and timestamps in a form that can reconstruct activity and be supplied to BNM or the relevant supervisor within the specified period.
- الأدلة الواجب الاحتفاظ بها
- Reconstruction test, indexed archive, access logs, production record and regulator receipt.
- المصدر الأساسي
- AMLA 2001, sections 13, 15, 17, 21 and 25 as amended by Act A1761; BNM FIs PD, paragraphs 24-25
10Privacy, biometrics, breaches, and transfersPDPA duties apply to commercial processing within scope and now expressly address processors, biometrics, DPOs and breaches.5 عناصر+
Establish PDPA scope, purpose and processing authority.
- إجراء التنفيذ
- Map controller and processor roles, commercial-transaction coverage, notices, consent or other permitted processing, disclosure, accuracy, retention, access and security; apply sector codes where relevant.
- الأدلة الواجب الاحتفاظ بها
- Data map, legal basis, notices, consent records, processor terms, retention and rights workflow.
- المصدر الأساسي
- Personal Data Protection Act 2010, sections 2, 5-12 and 43-44, as amended by Act A1727
Treat biometric identity data as sensitive personal data.
- إجراء التنفيذ
- For face, fingerprint, voice or behavioural templates produced by technical processing, apply sensitive-data conditions, minimisation, strict access, security, retention and deletion, and document alternatives and proportionality.
- الأدلة الواجب الاحتفاظ بها
- Biometric inventory, purpose assessment, consent or authority, access logs, security tests, retention and deletion proof.
- المصدر الأساسي
- PDPA 2010, section 4 as amended by Act A1727, section 40; Personal Data Protection Standard 2015
Appoint and notify a DPO when the current criteria apply.
- إجراء التنفيذ
- Assess the Commissioner's thresholds, including processing over 20,000 data subjects, sensitive or financial data over 10,000 data subjects, or regular and systematic monitoring; appoint a qualified accessible DPO, register the appointment within 21 days and register a replacement within 14 days of the new appointment after the prior DPO leaves or the term ends.
- الأدلة الواجب الاحتفاظ بها
- Threshold assessment, appointment, qualifications, contact channel, notification receipt, replacement record and deadline log.
- المصدر الأساسي
- PDPA 2010, section 12A; Commissioner's Circular No. 1/2025, paragraphs 8(2)-8(3), and DPO Guideline
Assess every personal-data breach and notify when the criteria are met.
- إجراء التنفيذ
- Assess whether the breach creates significant harm or meets another notification criterion, including sensitive data, identity-fraud-enabling combinations or significant scale above 1,000 affected subjects. If a criterion is met, notify the Commissioner as soon as practicable and no later than 72 hours from occurrence or confirmation under the guideline; explain a delay, complete staged information no later than 30 days, notify affected subjects no later than seven days after the initial Commissioner notification, and retain breach records for at least two years.
- الأدلة الواجب الاحتفاظ بها
- Incident chronology, notification-criteria assessment, harm and scale assessment, 72-hour filing, seven-day subject notice, delay reasons, staged updates and two-year register.
- المصدر الأساسي
- PDPA 2010, section 12B; Commissioner's Circular No. 2/2025; DBN Guideline, paragraphs 5.2, 6.1-6.2 and 9.1
Control cross-border transfers and high-risk processing.
- إجراء التنفيذ
- Before an overseas transfer, document substantially similar law or adequate protection, or a specific section 129 exception, and apply contracts and transfer due diligence. Conduct a DPIA where the 2026 guideline requires it, including high-risk biometric or large-scale processing.
- الأدلة الواجب الاحتفاظ بها
- Transfer map, destination assessment, transfer impact assessment, contract, exception record, DPIA and residual-risk approval.
- المصدر الأساسي
- PDPA 2010, section 129 as amended by Act A1727; Cross-Border Transfer Guideline 2025; DPIA Guideline 2026
11Practical evidence packsEvidence should let an independent reviewer reconstruct the legal basis and operational decision.3 عناصر+
Maintain a customer and beneficial-owner evidence pack.
- إجراء التنفيذ
- Preserve the trigger, identity and KYB sources, ownership and control cascade, representative authority, risk rating, PEP and sanctions results, EDD, approvals and refresh history.
- الأدلة الواجب الاحتفاظ بها
- Timestamped case file with source provenance, decision log, approvals and version history.
- المصدر الأساسي
- AMLA 2001, sections 13, 16 and 17; BNM FIs PD, paragraphs 14-17 and 24
Maintain reporting and monitoring evidence.
- إجراء التنفيذ
- Preserve monitoring configuration, alert chronology, analyst reasoning, escalation, STR and CTR submissions, sanctions actions, confidentiality access and feedback-driven tuning.
- الأدلة الواجب الاحتفاظ بها
- Scenario register, case exports, FINS receipts, frozen-asset ledger, access logs and change approvals.
- المصدر الأساسي
- AMLA 2001, sections 14, 14A, 15, 17 and 20; BNM FIs PD, paragraphs 21-25 and 27-29
Maintain licensing, outsourcing and privacy evidence.
- إجراء التنفيذ
- Keep current licences, conditions, agent and vendor due diligence, contracts, service and data-flow maps, incident records, transfer assessments, DPIAs and closure testing together with named owners.
- الأدلة الواجب الاحتفاظ بها
- Licence register, contract repository, assurance reports, data map, privacy register, remediation and governance minutes.
- المصدر الأساسي
- Applicable sector law; BNM policy documents; PDPA 2010 as amended by Act A1727; Commissioner guidelines
سجل المصادر الأساسية
28 مصدرًا مستخدمًا في هذه القائمة
استخدم هذه الروابط للتحقق من التشريعات وإرشادات الجهات الرقابية وإجراءات الإبلاغ والبيانات الدولية.
- Malaysia AMLA portal and current amendment noticeBank Negara Malaysia · Official legal portal
- AMLA 2001 Act 613 compilationAttorney General's Chambers of Malaysia · Primary legislation
- AMLA Amendment Act 2025 Act A1761Bank Negara Malaysia · Primary amending legislation
- Act A1761 commencement notification P.U. (B) 76/2026Bank Negara Malaysia · Official gazette instrument
- AML/CFT/CPF and TFS for Financial Institutions Policy DocumentBank Negara Malaysia · Binding supervisory policy
- AML/CFT/CPF and TFS for DNFBPs and NBFIs Policy DocumentBank Negara Malaysia · Binding supervisory policy
- Companies Act 2016 and amendments portalCompanies Commission of Malaysia · Official legal portal
- Companies Amendment Act 2024 resourcesCompanies Commission of Malaysia · Official legal and implementation portal
- Guideline for the Reporting Framework for Beneficial Ownership of Companies, revised 2025Companies Commission of Malaysia · Official registry guideline
- Personal Data Protection Act 2010 portalPersonal Data Protection Commissioner Malaysia · Official legal portal
- Personal Data Protection Amendment Act 2024 Act A1727Personal Data Protection Commissioner Malaysia · Primary amending legislation
- PDPA Amendment Act commencement notification P.U. (B) 522Personal Data Protection Commissioner Malaysia · Official gazette instrument
- Commissioner's Circular No. 2/2025 on data breach notificationPersonal Data Protection Commissioner Malaysia · Official regulatory circular
- Data Breach Notification GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Personal Data Breach Notification SystemPersonal Data Protection Commissioner Malaysia · Official regulatory reporting portal
- Commissioner's Circular No. 1/2025 on data protection officersPersonal Data Protection Commissioner Malaysia · Official regulatory circular
- Data Protection Officer GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Cross-Border Transfer of Personal Data GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Data Protection Impact Assessment GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Electronic Know-Your-Customer Policy Document, 15 April 2024Bank Negara Malaysia · Binding supervisory policy
- Electronic Money Policy Document, revised 31 January 2025Bank Negara Malaysia · Binding supervisory policy
- Money Services Business frameworkBank Negara Malaysia · Official licensing guidance
- Guidelines on Recognized Markets, revised 20 May 2026Securities Commission Malaysia · Official capital-markets guideline portal
- Malaysia digital-assets regulatory portalSecurities Commission Malaysia · Official regulatory guidance
- Malaysia country profileFinancial Action Task Force · Authoritative international assessment
- FATF/APG Mutual Evaluation Report of Malaysia 2025Financial Action Task Force · Authoritative international assessment
- Jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Current public-list statement
- High-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Current public-list statement
إجابات مباشرة
أسئلة KYC وKYB وAML في ماليزيا
Who receives suspicious transaction reports in Malaysia?+
The Financial Intelligence and Enforcement Department of Bank Negara Malaysia receives STRs through FINS or the current prescribed route. Confirm access and sector instructions before filing.
What is the STR deadline?+
AMLA requires reporting of covered suspicion and BNM policy requires prompt filing. For institutions governed by the FIs Policy Document, the compliance officer must submit by the next working day after establishing suspicion. Other sectors must verify their applicable policy and directions.
Is RM25,000 a universal CDD or reporting threshold?+
No. Under the BNM FIs Policy Document it is the scoped cash-threshold-report level for qualifying aggregated cash activity and is also a banking occasional-transaction CDD trigger. Other products and sectors have different triggers, and suspicion applies regardless of amount.
Which beneficial-ownership threshold should be used?+
Do not merge the tests. The BNM FIs Policy Document cascade includes shareholders with more than 25% equity, control by other means and a senior-management fallback. The SSM company-reporting guideline separately uses not less than 20% share or voting criteria plus control tests.
How long must AML records be kept?+
At least six years from the applicable completion or termination event, with longer retention where an investigation, prosecution or competent-authority direction requires it.
Do digital-asset businesses need approval?+
Yes where the activity falls within Malaysia's regulated digital-asset perimeter. A DAX must be registered as a recognized market operator with the Securities Commission, and other digital-asset roles have their own SC requirements.
What happens after a sanctions match?+
After a true match is confirmed, the institution must take the applicable freeze, block or rejection action immediately and without delay, report immediately to the required authorities, file related STRs and retain evidence. The exact route differs among TF, PF and other UN regimes.
How does Malaysia regulate biometric KYC data?+
Act A1727 added biometric data to sensitive personal data. Controllers and processors must apply the PDPA security and processing requirements, and high-risk biometric processing may require a DPIA under the 2026 guideline.
When must a personal-data breach be reported?+
Assess every breach. Commissioner notification is required when a guideline criterion is met, including significant harm, sensitive data, identity-fraud-enabling combinations or significant scale above 1,000 affected subjects. Notify as soon as practicable and no later than 72 hours from occurrence or confirmation under the guideline; affected subjects must be notified no later than seven days after the initial Commissioner notification.
Is Malaysia on a FATF public list?+
No. Malaysia was absent from both FATF public lists dated 19 June 2026, but its 2025 mutual evaluation includes a three-year roadmap and absence from a public list is not a low-risk rating.
منهجية البحث والمراجعة
تحدد VOVE ID Compliance Research النطاق التنظيمي، وتحول الالتزامات إلى ضوابط تشغيلية، وتربط الادعاءات الجوهرية بالمصادر، وتسجل تاريخ وإصدار كل مراجعة.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 September 2026. Confirm the current First Schedule activity, applicable BNM or sector-supervisor policy document, post-Act A1761 directions, Labuan or other sector overlays, licensing, reporting forms, sanctions lists, privacy coverage and implementation facts with the competent authority and qualified Malaysian counsel before launch.