Bahrain KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Bahrain.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 41 implementation checks
Last reviewed: 30 September 2026 · Version 1.0
Download the checklistDirect answer
What does the Bahrain compliance checklist cover?
The Bahrain checklist translates primary KYC, KYB and AML rules into 11 control areas and 41 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML law
- Legislative Decree No. 4 of 2001, as amended through 2025
- FIU and reporting
- National Financial Intelligence Centre; CBB licensees use the Online STR system under current rules
- STR timing
- Immediately upon suspicion, including attempted transactions, regardless of value
- CBB occasional-transaction CDD
- Above BHD 6,000, including linked transactions; wire transfers trigger CDD irrespective of amount in banking modules
- AML retention
- At least 5 years; the statutory start event depends on record class
- Commercial-register UBO
- 10% ownership or voting control is one criterion; effective control and other influence tests also apply
- Privacy
- Law No. 30 of 2018 on Personal Data Protection and implementing decisions
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Bahrain compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the entity, activity and supervisory rulebook before assigning controls.3 items+
Determine whether each activity is an institution or otherwise subject to the AML law.
- Implementation action
- Map services, customers and Bahrain nexus to Legislative Decree No. 4 of 2001, current amendments, CBB licensing categories and the applicable DNFBP order.
- Evidence to retain
- Perimeter memo, service and funds-flow maps, legal analysis and authority confirmation.
- Primary citation
- Legislative Decree No. 4 of 2001, articles 1, 4 and 5; applicable competent-authority rules
Obtain each required CBB or sector licence before activity.
- Implementation action
- Classify banking, investment, insurance, payment, remittance, exchange, crypto-asset and other regulated services and secure approval before launch.
- Evidence to retain
- Licence matrix, applications, approvals, conditions register and renewal calendar.
- Primary citation
- CBB and Financial Institutions Law 2006; applicable CBB Rulebook volume
Apply the correct Financial Crime module and current version.
- Implementation action
- Identify the CBB volume for the licence category, track module amendments and document any sector-specific departures rather than copying controls across volumes.
- Evidence to retain
- Rulebook inventory, change log, compliance mapping and governance approval.
- Primary citation
- CBB Rulebook Financial Crime modules, current version
02Governance and ML/TF/PF risk assessmentGovernance must address money laundering, terrorist financing and proliferation-financing risk.4 items+
Maintain a documented enterprise risk assessment.
- Implementation action
- Assess customers, countries, products, delivery channels, transactions, technology, sanctions and emerging risks and update for material change and national findings.
- Evidence to retain
- Methodology, current assessment, data sources, approvals, residual-risk decisions and change log.
- Primary citation
- Legislative Decree No. 4 of 2001, articles 4-5; CBB FC risk-based approach requirements
Maintain proportionate AML/CFT/CPF policies and controls.
- Implementation action
- Document CDD, monitoring, reporting, recordkeeping, sanctions, employee screening, training, group controls, independent review and escalation.
- Evidence to retain
- Approved framework, control map, procedures, training and issue register.
- Primary citation
- Legislative Decree No. 4 of 2001, article 5; applicable CBB FC module
Appoint an approved and empowered MLRO.
- Implementation action
- Appoint a suitably senior Bahrain-resident MLRO and deputy where the rulebook requires; preserve independence, resources, unrestricted information access and direct board escalation.
- Evidence to retain
- CBB approval, appointment, fit-and-proper file, authority matrix and board reporting.
- Primary citation
- Applicable CBB FC module, MLRO chapter
Conduct independent compliance review and remediate findings.
- Implementation action
- Test design and operation at the required frequency using an independent and competent function; report results and verify closure.
- Evidence to retain
- Review plan, independence assessment, report, management response and closure testing.
- Primary citation
- Applicable CBB FC compliance-monitoring and audit requirements
03Natural-person identificationCDD covers the customer, beneficial owner and each authorised representative.5 items+
Apply CDD before a relationship and when a statutory or rulebook trigger arises.
- Implementation action
- Identify and verify the customer before establishment, and refresh for material changes, doubts, suspicion, covered occasional transactions and transfers under the applicable module.
- Evidence to retain
- Trigger analysis, identity record, verification result, purpose and completion timestamp.
- Primary citation
- Legislative Decree No. 4 of 2001, articles 4-5; CBB FC-1
Apply the BHD 6,000 CBB occasional-transaction trigger in its proper scope.
- Implementation action
- For banking modules, apply CDD above BHD 6,000 and aggregate linked transactions; apply the exact current module for other licensees and do not treat the amount as a universal threshold report.
- Evidence to retain
- Aggregation logic, transaction samples, module mapping and CDD outcomes.
- Primary citation
- CBB FC-1.1.2 and corresponding current module provisions
Verify identity from reliable, independent evidence.
- Implementation action
- Obtain official identity attributes and validate authenticity, expiry, address where required and person-to-document linkage using risk-sensitive methods.
- Evidence to retain
- Identity attributes, source provenance, validation result, fraud checks and exceptions.
- Primary citation
- CBB FC-1 customer identification and verification requirements
Identify representatives and validate authority.
- Implementation action
- Identify and verify persons acting for the customer and confirm their legal mandate before accepting instructions.
- Evidence to retain
- Representative KYC, mandate, authority checks and instruction limits.
- Primary citation
- CBB FC-1; applicable sector order
Do not proceed when required CDD cannot be completed.
- Implementation action
- Decline or terminate as the applicable rule requires, restrict activity and consider an STR without tipping off.
- Evidence to retain
- CDD failure record, restriction or exit decision, STR assessment and communications review.
- Primary citation
- CBB FC-1 and suspicious-reporting provisions
04KYB, registry, and beneficial ownershipRegistry disclosure and AML beneficial-ownership analysis are related but distinct.5 items+
Verify the legal person or arrangement and its powers.
- Implementation action
- Collect current legal name, form, commercial registration, address, governing documents, directors, partners or trustees and validate against SIJILAT or other reliable sources.
- Evidence to retain
- Registry extract, constitutional documents, officer list and discrepancy resolution.
- Primary citation
- CBB FC-1; Commercial Companies Law; MOIC registry guidance
Identify natural persons with ultimate ownership or effective control.
- Implementation action
- Trace layered, nominee and legal-arrangement structures to natural persons who ultimately own, control or benefit and to persons on whose behalf activity occurs.
- Evidence to retain
- Ownership chart, control analysis, declarations, source documents and verified identities.
- Primary citation
- CBB Rulebook definition of beneficial owner, amended June 2025
Identify trust and legal-arrangement parties.
- Implementation action
- Identify settlors, trustees, protectors, beneficiaries or classes and any other natural person exercising ultimate effective control; look through legal-person trustees.
- Evidence to retain
- Trust deed, party schedule, powers analysis, ownership look-through and verification.
- Primary citation
- CBB Rulebook beneficial-owner definition, June 2025
Apply the MOIC UBO disclosure criteria without reducing them to one percentage.
- Implementation action
- Treat direct or indirect ownership or voting control of at least 10% as one criterion and assess effective control, decision influence, financing, family or contractual relationships and management powers.
- Evidence to retain
- UBO analysis, calculation, control evidence, filing and update receipts.
- Primary citation
- Ministerial Order No. 83 of 2020, article 3
Keep commercial-register UBO information current.
- Implementation action
- File required UBO information at registration and update changes through the current MOIC/SIJILAT process; retain evidence of submissions and discrepancy resolution.
- Evidence to retain
- UBO register, SIJILAT filings, change log, notices and remediation.
- Primary citation
- Ministerial Order No. 83 of 2020; MOIC business-services guidance
05PEPs, EDD, and remote onboardingEnhanced measures attach to specified and higher-risk circumstances.3 items+
Identify PEPs, family members and close associates.
- Implementation action
- Screen customers and beneficial owners for domestic, foreign and international-organisation PEP exposure and apply senior approval, source-of-wealth, source-of-funds and enhanced monitoring controls.
- Evidence to retain
- Screening, relationship map, approval, source corroboration and review history.
- Primary citation
- Applicable CBB FC enhanced-CDD and PEP provisions
Apply enhanced due diligence to higher-risk relationships.
- Implementation action
- Obtain additional information on customer, ownership, purpose, source of wealth and funds; increase monitoring and document acceptance or continuation decisions.
- Evidence to retain
- Risk trigger, additional CDD, source evidence, approval and monitoring plan.
- Primary citation
- CBB FC-1 enhanced CDD; FATF high-risk-country measures
Control non-face-to-face and technology risk.
- Implementation action
- Validate document authenticity and liveness, detect impersonation, test vendors, preserve manual fallback and apply stronger measures when residual risk is elevated.
- Evidence to retain
- Method assessment, vendor diligence, testing, exceptions and fraud cases.
- Primary citation
- CBB FC non-face-to-face and new-technology provisions
06Monitoring and suspicious transaction reportingOngoing scrutiny and immediate escalation support reporting to the NFIC.4 items+
Keep CDD current and monitor activity on a risk basis.
- Implementation action
- Examine transactions against purpose, profile, expected behaviour and risk; investigate significant, abnormal or unexplained activity and document source-of-funds work.
- Evidence to retain
- Monitoring scenarios, alerts, case decisions, refresh records and quality testing.
- Primary citation
- CBB FC-2 ongoing CDD and transaction monitoring
Escalate suspicion without waiting for proof or transaction completion.
- Implementation action
- Assess completed, attempted and proposed activity promptly and record the facts, grounds and timestamp at which suspicion was formed.
- Evidence to retain
- Alert chronology, information reviewed, suspicion decision and decision-maker.
- Primary citation
- Legislative Decree No. 4 of 2001, articles 4-5, as amended in 2020
Report suspicious transactions immediately, regardless of value.
- Implementation action
- The MLRO must submit complete reports through the current Online STR system to the NFIC and follow any parallel CBB notification required by the applicable module.
- Evidence to retain
- Suspicion timestamp, STR, system receipt, CBB notice and correction record.
- Primary citation
- Legislative Decree No. 4 of 2001, article 5(c); CBB FC external-reporting provisions
Prevent tipping off and protect STR information.
- Implementation action
- Restrict report knowledge, control customer and third-party communications and disclose only where legally permitted.
- Evidence to retain
- Access controls, disclosure register, legal review, training and incident log.
- Primary citation
- AML law and applicable CBB FC confidentiality provisions
07Payments, wires, thresholds, and crypto-assetsPayment and crypto services require activity-specific CBB licensing and transfer controls.4 items+
Carry and validate required wire-transfer information.
- Implementation action
- Collect, transmit and retain prescribed originator and beneficiary information and establish risk-based procedures for missing, incomplete or suspect fields.
- Evidence to retain
- Field matrix, message samples, validation rules, repair queue and dispositions.
- Primary citation
- Applicable CBB FC wire-transfer provisions
Apply CDD to wire transfers under the applicable module.
- Implementation action
- For banking modules, apply CDD irrespective of amount; where a specialised-licensee simplified rule refers to transfers below US$1,000, treat it only as a conditional simplification and never where suspicion or higher risk exists.
- Evidence to retain
- Module mapping, transfer samples, risk decisions and CDD result.
- Primary citation
- CBB FC-1 and FC-3, applicable Rulebook volume
Obtain payment-service approval before launch.
- Implementation action
- Classify domestic and cross-border transfer, merchant acquisition, e-money, payment initiation, account information, money changing and crypto-based payment services under the February 2026 PSP Module.
- Evidence to retain
- Product memo, CBB licence, conditions, safeguarding records and tests.
- Primary citation
- CBB Rulebook Volume 5, PSP Module, February 2026
Obtain the correct crypto-asset service licence.
- Implementation action
- Map exchange, brokerage, custody, portfolio, advisory and crypto-based payment features to the CBB CRA and PSP modules; meet category, governance, custody, cybersecurity, market-conduct and AML controls.
- Evidence to retain
- Service and wallet-flow map, CBB licence, category analysis, custody design and monitoring tests.
- Primary citation
- CBB Rulebook Volume 6, CRA Module; Volume 5 PSP Module
08Targeted financial sanctionsSanctions controls operate independently of an STR decision.3 items+
Screen UN and Bahrain designations and ownership or control.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding and upon list updates; test aliases and controlled entities rather than exact names only.
- Evidence to retain
- List versions, update logs, configuration tests, match analysis and dispositions.
- Primary citation
- Applicable Bahrain targeted-financial-sanctions framework and CBB FC requirements
Freeze or restrain without delay when a true designation match exists.
- Implementation action
- Stop dealings, prevent direct or indirect availability of assets and notify through the current competent route without waiting for an STR decision or customer notice.
- Evidence to retain
- Match analysis, restriction timestamp, notification, authority correspondence and release approval.
- Primary citation
- Applicable UN implementation orders; CBB FC sanctions provisions
Use licences, exemptions or releases only under written authority.
- Implementation action
- Identify the governing regime, obtain permission before activity, implement conditions and document expiry and release decisions.
- Evidence to retain
- Regime analysis, licence or permission, controls, reporting and release record.
- Primary citation
- Applicable designation and competent-authority procedure
09Records and regulator accessFive years is the baseline, with distinct start events by record class.3 items+
Retain customer and relationship records for at least five years.
- Implementation action
- Keep identity and business-relationship records for at least five years after the relationship ceases, subject to longer legal holds or authority directions.
- Evidence to retain
- Retention schedule, relationship-end date, archive sample, retrieval test and deletion approval.
- Primary citation
- Legislative Decree No. 4 of 2001, article 5(a); CBB FC recordkeeping
Retain transaction and attempted-transaction records for at least five years.
- Implementation action
- Keep records sufficient to reconstruct each transaction or attempt for at least five years after completion or attempt.
- Evidence to retain
- Transaction sample, trigger calculation, legal hold and deletion log.
- Primary citation
- Legislative Decree No. 4 of 2001, article 5(b); CBB FC-7 or corresponding chapter
Preserve STR, monitoring, training and compliance evidence.
- Implementation action
- Keep internal and external reports, dispositions, annual review and training records for the required period and make them promptly accessible to authorised authorities.
- Evidence to retain
- Record-class matrix, access controls, retrieval tests and production log.
- Primary citation
- Applicable CBB FC recordkeeping requirements
10Privacy, biometrics, breaches, and transfersAML processing must also comply with Bahrain's personal-data framework.4 items+
Process personal data on a lawful basis and transparently.
- Implementation action
- Map each KYC data element to a lawful basis and specific purpose, provide required notices, minimise collection, maintain accuracy and support data-subject rights.
- Evidence to retain
- Data inventory, lawful-basis map, notices, request log and accuracy controls.
- Primary citation
- Law No. 30 of 2018 on Personal Data Protection
Apply special controls to sensitive and biometric data.
- Implementation action
- Classify biometric and other sensitive data, identify the applicable statutory condition or permission, document necessity and proportionality and apply heightened access and deletion controls.
- Evidence to retain
- Classification, legal assessment, privacy impact assessment, permissions and deletion tests.
- Primary citation
- Law No. 30 of 2018 and implementing decisions
Manage processors and personal-data breaches.
- Implementation action
- Contract for instructions, confidentiality, security, incident escalation, return and deletion; investigate and notify the Authority or affected people where current law and decisions require.
- Evidence to retain
- Processor contract, security review, incident chronology, notifications and remediation.
- Primary citation
- Law No. 30 of 2018; Personal Data Protection Authority executive decisions
Control transfers outside Bahrain.
- Implementation action
- Determine whether the destination is adequate or another statutory route, authority permission or safeguard is required before transfer or remote access.
- Evidence to retain
- Transfer map, adequacy analysis, permission or safeguard, contract and monitoring.
- Primary citation
- Law No. 30 of 2018, articles 12-13; Order No. 42 of 2022
11Practical evidence packsEvidence should reconstruct onboarding, reporting and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, PEP, sanctions, purpose, risk, privacy, approvals and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting AML law and CBB FC-1
Maintain a reconstructable NFIC and sanctions case pack.
- Implementation action
- Link activity, alert, suspicion chronology, STR, receipt, CBB notice, confidentiality, asset restrictions and authority communications.
- Evidence to retain
- Complete sampled case pack, timeline and controlled-access record.
- Primary citation
- Operational control supporting AML law articles 4-5 and CBB FC reporting rules
Maintain a launch and change pack.
- Implementation action
- Record perimeter, licences, approved programme, reporting connectivity, sanctions, privacy, vendors, tests and controlled uncertainties before launch or material change.
- Evidence to retain
- Signed launch pack, source register, tests, approvals and uncertainty log.
- Primary citation
- Official sources listed below
Primary-source register
19 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Legislative Decree No. 4 of 2001 - AML/CFT frameworkLegislation and Legal Opinion Commission · Primary legislation
- Legislative Decree No. 29 of 2020 - AML/CFT amendmentsLegislation and Legal Opinion Commission · Primary amending legislation
- Legislative Decree No. 36 of 2025 - AML/CFT amendmentsLegislation and Legal Opinion Commission · Primary amending legislation
- CBB Rulebook Volume 1 Financial Crime moduleCentral Bank of Bahrain · Official supervisor rules
- CBB Rulebook Volume 5 Financial Crime moduleCentral Bank of Bahrain · Official supervisor rules
- CBB Online STR system and authority contactsCentral Bank of Bahrain · Official reporting rules
- CBB recordkeeping requirementsCentral Bank of Bahrain · Official supervisor rules
- CBB beneficial-owner definitionCentral Bank of Bahrain · Official supervisor rules
- CBB Rulebook Volume 6 Crypto-asset moduleCentral Bank of Bahrain · Official licensing rules
- CBB Rulebook Volume 5 Payment Service Provider module, February 2026Central Bank of Bahrain · Official licensing rules
- National Financial Intelligence CentreMinistry of Interior · Official FIU information
- NFIC suspicious-activity indicatorsNational Financial Intelligence Centre · Official FIU guidance
- Ministerial Order No. 83 of 2020 on UBO disclosureMinistry of Industry and Commerce · Primary registry order
- Business services and Ultimate Beneficial OwnerMinistry of Industry and Commerce · Official registry guidance
- Law No. 30 of 2018 on Personal Data ProtectionPersonal Data Protection Authority · Primary legislation
- Personal-data executive decisions and breach/transfer requirementsPersonal Data Protection Authority · Official privacy guidance
- MENAFATF third enhanced follow-up report for BahrainMENAFATF · Authoritative assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
Direct answers
Bahrain KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The National Financial Intelligence Centre is Bahrain's FIU. CBB licensees submit through the current Online STR system and follow any CBB notification required by their Rulebook module.
When must an STR be filed?+
Immediately when suspicion arises, including attempted transactions and regardless of value. Record the suspicion timestamp and use the current electronic reporting specification.
What is the CBB occasional-transaction CDD threshold?+
Banking modules require CDD for one-off or linked occasional transactions above BHD 6,000, while wire transfers can trigger CDD irrespective of amount. Confirm the exact rule in the entity's current CBB volume.
Is BHD 6,000 a universal threshold-reporting rule?+
No. It is used in specific CBB CDD and monitoring provisions. Suspicious transactions are reportable regardless of value and no universal cash-threshold report should be inferred.
How is beneficial ownership determined?+
AML analysis identifies natural persons who ultimately own or control the customer, benefit from the arrangement or act behind a transaction. MOIC's UBO order treats 10% ownership or voting control as one criterion and also captures effective control and other influence.
How long are AML records kept?+
At least five years. Identity and relationship records run from relationship end; transaction records run from completion or the attempted transaction, subject to longer holds or authority directions.
Do payment providers need a CBB licence?+
Yes where the service falls within the regulated PSP perimeter. The February 2026 module covers domestic and cross-border transfers, acquiring, e-money, payment initiation, account information, money changing and crypto-based payment services.
Are crypto-asset services regulated?+
Yes. The CBB CRA and PSP modules regulate different crypto-asset and crypto-based payment activities. Determine the correct category and obtain approval before launch.
What privacy rules apply to biometric identity checks?+
Law No. 30 of 2018 and its implementing decisions apply. Classify biometric data, establish a lawful condition or permission, document necessity and proportionality, and control transfers, processors, security and deletion.
Is Bahrain on a FATF public list?+
No. Bahrain was absent from both FATF public lists dated 19 June 2026. It remains within MENAFATF follow-up, and public-list absence is not a low-risk conclusion.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 30 September 2026. Confirm the regulated perimeter, current CBB volume and module, NFIC reporting specifications, sanctions designation, data-protection permissions and sector orders with the competent authority and qualified Bahrain counsel before launch.