Indonesia KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Indonesia.
- Last reviewed
- Last reviewed:
- Version
- Version 1.2

Portable implementation guide
Get the PDF checklist
11 control areas · 39 implementation checks
Last reviewed: 25 September 2026 · Version 1.2
Download the checklistDirect answer
What does the Indonesia compliance checklist cover?
The Indonesia checklist translates primary KYC, KYB and AML rules into 11 control areas and 39 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Pusat Pelaporan dan Analisis Transaksi Keuangan (PPATK / INTRAC)
- Primary AML law
- Law No. 8 of 2010, preventive and reporting provisions as in force
- Suspicious report
- To PPATK as soon as possible, no later than 3 working days after a financial service provider knows the suspicious elements
- Cash report
- Financial-service cash transaction at least IDR 500 million, single or aggregated in 1 working day; generally within 14 working days, subject to exceptions
- CDD trigger
- Business relationship; at least IDR 100 million; suspicion; or doubt, subject to sector rules
- Records
- Generally at least 5 years, with the start event depending on record type
- Privacy breach
- Written notice within 3 x 24 hours to affected subjects and the statutory institution
- FATF public lists
- Not listed at 19 June 2026; FATF member since 2023
Implementation detail
Indonesia compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the entity, service and supervisor before applying a control or threshold.4 items+
Determine whether the entity is a reporting party.
- Implementation action
- Map each financial, payment, goods, professional and digital-asset activity to Law No. 8 of 2010 and Government Regulation No. 43 of 2015 as amended by Government Regulation No. 61 of 2021; record the competent supervisor and PPATK reporting route.
- Evidence to retain
- Legal perimeter memo, product and funds-flow map, reporting-party category, supervisor confirmation and approved scope decision.
- Primary citation
- Law No. 8 of 2010, Article 17; Government Regulation No. 43 of 2015 as amended by Government Regulation No. 61 of 2021
Obtain the correct OJK or Bank Indonesia authority before service.
- Implementation action
- Map regulated financial services to OJK and payment-system, remittance or non-bank money-changing activities to Bank Indonesia. For payment-system activities, apply Bank Indonesia Regulation No. 10 of 2025 and preserved implementing rules, including Regulation No. 23/6/PBI/2021 only to the extent consistent; do not treat an AML registration or reporting account as a business licence.
- Evidence to retain
- Licence inventory, regulatory correspondence, approved activities, conditions, renewals and change-control record.
- Primary citation
- Law No. 21 of 2011 as amended by Law No. 4 of 2023; BI Regulation No. 10 of 2025; BI Regulation No. 23/6/PBI/2021 to the extent preserved by BI Regulation No. 10 of 2025; BI Regulation No. 10 of 2024
Use the current digital-finance and crypto perimeter.
- Implementation action
- For digital financial assets and crypto, assess and license the activity under OJK Regulation No. 27 of 2024 as amended by OJK Regulation No. 23 of 2025. From 1 September 2026, implement the applicable periodic, incident, asset-evaluation and application-related reporting procedures under PADK OJK No. 3 of 2026, while applying the PADK's staged transitional treatment of SEOJK No. 20/SEOJK.07/2024. Do not rely on obsolete Bappebti-only treatment.
- Evidence to retain
- Classification memo, OJK licence or registration, report inventory and submissions, transition analysis, approved asset and activity list and supervisory correspondence.
- Primary citation
- Law No. 4 of 2023; Government Regulation No. 49 of 2024; OJK Regulation No. 27 of 2024 as amended by OJK Regulation No. 23 of 2025; PADK OJK No. 3 of 2026
Apply the sector rule in addition to the national laws.
- Implementation action
- Maintain a control map for OJK Regulation No. 8 of 2023, BI Regulation No. 10 of 2024 or the relevant PPATK/professional rule; resolve conflicts and amendments with Indonesian counsel.
- Evidence to retain
- Obligations register, effective-date log, gap assessment, counsel advice and implementation sign-off.
- Primary citation
- Law No. 8 of 2010, Article 18; OJK Regulation No. 8 of 2023; BI Regulation No. 10 of 2024
02Governance and risk assessmentA risk-based programme must be governed, documented, resourced and tested.3 items+
Maintain an enterprise ML/TF/PF risk assessment.
- Implementation action
- Assess customers, countries, products, services, transactions, delivery channels, technology and distribution partners; update for material change and national or sector risk information.
- Evidence to retain
- Methodology, current assessment, data sources, approvals, residual-risk decisions and remediation plan.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 7-9 and 17; BI Regulation No. 10 of 2024
Operate an approved AML/CFT/CPF programme.
- Implementation action
- Translate risk into written policies for CDD, monitoring, reporting, sanctions, records, employees, training, groups, third parties and regulatory access.
- Evidence to retain
- Board-approved programme, control owners, procedures, training, testing, issues and closure evidence.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 7-17; BI Regulation No. 10 of 2024
Assign accountable leadership and independent assurance.
- Implementation action
- Document board and director oversight, a sufficiently independent compliance function, escalation and risk-based testing; deliver role-appropriate training at the applicable frequency.
- Evidence to retain
- Appointments, committee minutes, reports, independence assessment, test plan, findings and annual training records.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 10-16 and 64-72
03Natural-person identificationCDD identifies the person, any principal and the purpose and funding of the relationship.4 items+
Trigger CDD at the legally required events.
- Implementation action
- Apply CDD on establishing a business relationship, a transaction of at least IDR 100 million or equivalent, suspicion, or doubt about supplied information, then apply the stricter relevant sector rule.
- Evidence to retain
- Trigger matrix, aggregation logic, onboarding record, alert link and exception approval.
- Primary citation
- Law No. 8 of 2010, Article 18(3); OJK Regulation No. 8 of 2023, Articles 24-25
Identify and verify the individual from reliable current evidence.
- Implementation action
- Collect required identity, contact, occupation, source-of-funds and purpose information; verify against reliable independent documents or data and resolve inconsistencies.
- Evidence to retain
- Identity attributes, document/data provenance, verification result, fraud checks and discrepancy resolution.
- Primary citation
- Law No. 8 of 2010, Articles 19-21; OJK Regulation No. 8 of 2023, Articles 25-26 and 30
Identify representatives and underlying principals.
- Implementation action
- Determine whether the person acts for self or another, verify the represented person, verify the representative and establish authority before permitting activity.
- Evidence to retain
- Principal and representative KYC, mandate, signature or electronic authority, scope and activity log.
- Primary citation
- Law No. 8 of 2010, Articles 19-20; OJK Regulation No. 8 of 2023, Article 30(2)
Control delayed verification and failed CDD.
- Implementation action
- Reject the transaction where required identity or supporting documents are incomplete. A financial service provider must terminate the business relationship where the customer refuses the customer-identification principle or the provider doubts the truth of the information, and must report that termination to PPATK as a suspicious financial transaction. Apply any stricter sector rule and document the decision.
- Evidence to retain
- Exception basis, restrictions, completion timestamp, refusal/termination decision, PPATK report and receipt.
- Primary citation
- Law No. 8 of 2010, Articles 20 and 22; OJK Regulation No. 8 of 2023, Articles 23, 30(5)-(7) and 33(12)
04KYB, registries, and beneficial ownershipLegal existence, authority, ultimate ownership and control require separate evidence.4 items+
Verify the corporation or legal arrangement and its authorised persons.
- Implementation action
- Obtain legal name, form, licence, registered address, formation and governance documents, business purpose, officers and reliable AHU or other competent-register evidence.
- Evidence to retain
- Current registry extract, constitutional documents, licence, officer list, authority and discrepancy log.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 27-30
Identify and verify the AML beneficial owner.
- Implementation action
- Follow ownership, benefit and control to natural persons, including persons controlling the account, transaction, corporation or arrangement; do not stop at a nominee, direct shareholder or percentage threshold.
- Evidence to retain
- Layered ownership chart, control analysis, funding trail, independent corroboration and verified natural-person identities.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 30 and 33-34
Apply the separate corporate beneficial-owner duties.
- Implementation action
- For covered corporations, determine the persons meeting the entity-specific more-than-25% and alternative control/benefit tests, report through AHU, report changes within three working days and update information annually.
- Evidence to retain
- BO determination, AHU receipts, change log, annual update and verification questionnaire/result.
- Primary citation
- Presidential Regulation No. 13 of 2018, Articles 3-11 and 18-21; Minister of Law Regulation No. 2 of 2025
Do not treat AHU data as conclusive AML proof.
- Implementation action
- Compare the registry declaration with ownership, voting, benefit, appointment and control evidence; escalate inconsistencies and preserve the functional AML conclusion.
- Evidence to retain
- AHU record, shareholder and governance records, source comparison, customer explanation and escalation outcome.
- Primary citation
- Presidential Regulation No. 13 of 2018, Article 11; OJK Regulation No. 8 of 2023, Article 33
05PEPs, enhanced due diligence, and remote onboardingPEP, high-risk and non-face-to-face exposure require stronger, risk-sensitive measures.3 items+
Identify PEPs, relevant family and close associates.
- Implementation action
- Screen customers, beneficial owners and relevant principals for foreign, domestic and international-organisation PEP status, then extend required treatment to family and close associates.
- Evidence to retain
- Screening source and timestamp, role and relationship map, risk conclusion and refresh history.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 2, 35-40
Apply EDD to high-risk relationships.
- Implementation action
- Obtain the required senior approval, analyse and corroborate source of funds and source of wealth, collect additional information and apply enhanced monitoring; preserve the regulation's risk qualification for domestic and international-organisation PEPs.
- Evidence to retain
- EDD trigger, senior decision, source corroboration, monitoring plan and periodic review.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 35-39
Control electronic and remote verification.
- Implementation action
- Use reliable electronic processes, test impersonation, document and liveness risks, govern third parties and protect identity and biometric data; the regulated institution remains accountable for verification outcomes.
- Evidence to retain
- Method assessment, test results, vendor diligence, privacy basis, human exception route and quality monitoring.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 21-22 and 30; Law No. 27 of 2022, Articles 4 and 34-39
06Monitoring and suspicious reportingOngoing monitoring must support a documented and timely PPATK decision.4 items+
Monitor customer and transaction activity continuously.
- Implementation action
- Compare activity with customer profile, business purpose, source of funds and expected pattern; update CDD and investigate anomalies without tipping off.
- Evidence to retain
- Scenario inventory, alerts, case chronology, customer refresh, explanation and disposition.
- Primary citation
- Law No. 8 of 2010, Article 18(5); OJK Regulation No. 8 of 2023, Articles 51-52
Identify suspicious financial transactions without waiting for proof.
- Implementation action
- Apply the statutory indicators to transactions that deviate from the customer profile or pattern, appear designed to avoid reporting, are conducted or cancelled using assets suspected to derive from crime, or are requested by PPATK; record when the provider knew the suspicious elements. Apply any additional attempted-transaction rule only where a current sector instrument expressly requires it.
- Evidence to retain
- Alert and referral timestamps, facts reviewed, statutory analysis, decision-maker and audit trail.
- Primary citation
- Law No. 8 of 2010, Article 1(5) and Article 23(1)(a)
Report covered suspicion to PPATK on time.
- Implementation action
- Submit through the current PPATK reporting system as soon as possible and no later than three working days after a financial service provider knows the suspicious elements; use the profession or sector-specific clock where different.
- Evidence to retain
- Knowledge timestamp, report payload, submission receipt, corrections and late-report escalation.
- Primary citation
- Law No. 8 of 2010, Article 25(1); Government Regulation No. 43 of 2015 as amended
Protect report confidentiality and prevent tipping off.
- Implementation action
- Restrict access to suspicion and report information, pre-clear external disclosures and train staff not to reveal that a report was or will be made.
- Evidence to retain
- Access log, disclosure decision, confidentiality controls, training and incident record.
- Primary citation
- Law No. 8 of 2010, Article 12
07Cash reports, transfers, and paymentsCash, cross-border transfer and payment controls have different scopes and thresholds.4 items+
Report covered financial-service cash transactions.
- Implementation action
- Aggregate physical-cash transactions within one working day and report at least IDR 500 million or foreign-currency equivalent to PPATK within 14 working days, unless a statutory exception applies; retain the exception list.
- Evidence to retain
- Aggregation output, currency conversion, report and receipt, exception authority and retained exception list.
- Primary citation
- Law No. 8 of 2010, Articles 23-25
Keep other threshold and cross-border reports separate.
- Implementation action
- Apply the current PPATK form and sector rule to cross-border fund transfers and the separately scoped IDR 500 million goods/service-provider report; do not reuse the cash definition or threshold outside its legal scope.
- Evidence to retain
- Report matrix, PPATK specification version, transaction classification, report and submission receipt.
- Primary citation
- Law No. 8 of 2010, Articles 23(1)(c), 25(3) and 27
Carry complete wire-transfer information.
- Implementation action
- For covered bank transfers, capture and transmit traceable originator and beneficiary identity, account/reference, address or identifier, amount, currency and date; reject, suspend, repair or monitor missing-data transfers under risk-based procedures.
- Evidence to retain
- Field matrix, message samples, validation rules, exception queue and disposition.
- Primary citation
- OJK Regulation No. 8 of 2023, Articles 58-62
Apply BI AML controls to covered non-bank payment activity.
- Implementation action
- For covered payment, transaction-forwarding, remittance and non-bank money-changing activities, implement the BI Regulation No. 10 of 2024 programme and maintain the payment-system authority required by BI Regulation No. 10 of 2025, applying preserved implementing rules only to the extent consistent.
- Evidence to retain
- BI perimeter analysis, licence, board programme, risk assessment, reporting map and supervisory returns.
- Primary citation
- BI Regulation No. 10 of 2024; BI Regulation No. 10 of 2025, including Article 184; BI Regulation No. 23/6/PBI/2021 to the extent preserved
08Targeted financial sanctionsDTTOT and proliferation-financing lists require immediate, list-specific action.3 items+
Maintain and screen the current DTTOT and DPPSPM.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and when competent authorities transmit updated lists; control false positives and false negatives.
- Evidence to retain
- List provenance and version, update log, configuration tests, match analysis and disposition.
- Primary citation
- Law No. 9 of 2013; OJK Regulation No. 8 of 2023, Article 53(1)-(3)
Block a confirmed listed-person match without delay.
- Implementation action
- Without prior notice, block funds owned or controlled directly, indirectly, wholly or jointly by the matched customer or beneficial owner and prevent funds being made available.
- Evidence to retain
- Identity and ownership analysis, decision, blocking timestamp, system blocks and asset inventory.
- Primary citation
- OJK Regulation No. 8 of 2023, Article 53(2)-(5)
Send each sanctions report to the correct recipient.
- Implementation action
- Create the blocking record, report DTTOT blocking to Police and DPPSPM blocking to PPATK, copy OJK where required, submit the related STR, and apply the applicable three-working-day sector clock for blocking or nil reports.
- Evidence to retain
- Blocking record, Police/PPATK/OJK notices, STR, receipts, nil-report decision and deadline calculation.
- Primary citation
- OJK Regulation No. 8 of 2023, Article 53(6)-(10) and Articles 76-77
09Records and regulator accessRetention begins from the record-specific legal event and must preserve reconstruction.3 items+
Retain customer identity and CDD records for the required period.
- Implementation action
- Keep identity and CDD records for at least five years from the applicable end of relationship, transaction or sector trigger; suspend disposal for investigations, orders or legal holds.
- Evidence to retain
- Retention schedule, trigger date, immutable record set, hold register, access log and disposal approval.
- Primary citation
- Law No. 8 of 2010, Article 21(2); OJK Regulation No. 8 of 2023, Article 63
Retain transaction and beneficial-owner evidence under their own rules.
- Implementation action
- Map company-document and transaction retention separately; preserve corporate BO change and update documents for at least five years from the relevant formation/approval or dissolution event.
- Evidence to retain
- Record-class map, transaction trail, BO archive, trigger evidence and reconciliation tests.
- Primary citation
- OJK Regulation No. 8 of 2023, Article 63; Presidential Regulation No. 13 of 2018, Article 22
Make records retrievable for competent authorities.
- Implementation action
- Index records so PPATK, OJK, Bank Indonesia or another competent authority can reconstruct identity, authority, ownership, monitoring, reporting and transaction history within the lawful request scope.
- Evidence to retain
- Retrieval test, request register, approval, production package, chain of custody and response receipt.
- Primary citation
- Law No. 8 of 2010, Articles 41-44; OJK Regulation No. 8 of 2023, Article 63
10Privacy, biometrics, and transfersIdentity processing must satisfy AML duties and Indonesia's separate personal-data rules.4 items+
Establish and document a lawful basis for each processing purpose.
- Implementation action
- Map collection, verification, screening, monitoring, reporting, retention and deletion to a lawful basis; provide required information and separate optional consent from legally required AML processing.
- Evidence to retain
- Processing record, purpose/basis map, notice version, consent record where used and retention decision.
- Primary citation
- Law No. 27 of 2022, Articles 20-25 and 47
Treat biometric and high-risk identity processing as specifically protected.
- Implementation action
- Classify biometrics as specific personal data, conduct a DPIA for high-risk processing including specified automated, large-scale or innovative uses, minimise data and implement access, security and vendor controls.
- Evidence to retain
- Data inventory, DPIA, necessity assessment, architecture, access tests, vendor terms and incident plan.
- Primary citation
- Law No. 27 of 2022, Articles 4 and 34-39
Notify a personal-data protection failure within 3 x 24 hours.
- Implementation action
- Notify affected data subjects and the statutory institution in writing within 3 x 24 hours, stating the exposed data, when and how exposure occurred and remediation; verify the current institutional channel and any public-notice duty.
- Evidence to retain
- Incident timeline, assessment, notice content, delivery receipts, authority-channel verification and recovery record.
- Primary citation
- Law No. 27 of 2022, Article 46
Control cross-border transfers and the privacy function.
- Implementation action
- For overseas transfers, document equivalent-or-higher protection, otherwise binding adequate safeguards, otherwise data-subject consent; appoint a privacy officer/function when an Article 53 trigger applies, read with Constitutional Court Decision 151/PUU-XXII/2024.
- Evidence to retain
- Transfer assessment, safeguards or consent, recipient diligence, appointment, role description and monitoring.
- Primary citation
- Law No. 27 of 2022, Articles 53-56; Constitutional Court Decision No. 151/PUU-XXII/2024
11Practical evidence packsPackage evidence so a reviewer can reconstruct each decision without oral context.3 items+
Maintain a customer and ownership evidence pack.
- Implementation action
- Bundle identity, authority, AHU and other registry evidence, ownership/control analysis, beneficial-owner verification, PEP/sanctions results, risk rating and approvals with provenance and timestamps.
- Evidence to retain
- Versioned case pack and completeness control signed by the responsible owner.
- Primary citation
- Law No. 8 of 2010, Articles 18-21; OJK Regulation No. 8 of 2023, Articles 25-40 and 63
Maintain monitoring, reporting and sanctions evidence.
- Implementation action
- Link alerts and list versions to investigations, STR/threshold/blocking decisions, recipients, deadline calculations, receipts and remediation while segregating restricted report information.
- Evidence to retain
- Case export, decision log, submission receipts, access controls and quality review.
- Primary citation
- Law No. 8 of 2010, Articles 12 and 23-27; OJK Regulation No. 8 of 2023, Articles 51-53 and 74-77
Maintain licence, privacy and change evidence.
- Implementation action
- Keep current licences, regulatory perimeter decisions, legal updates, DPIAs, transfer assessments, incident notices, vendor assurance and tested change approvals together.
- Evidence to retain
- Licence file, obligations register, privacy pack, vendor pack, change tickets and management attestations.
- Primary citation
- BI Regulation No. 10 of 2024; OJK Regulation No. 27 of 2024 as amended; Law No. 27 of 2022
Primary-source register
26 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 8 of 2010 on Prevention and Eradication of Money LaunderingAudit Board of Indonesia legal database (JDIH BPK) · Primary legislation
- Government Regulation No. 43 of 2015 on Reporting PartiesJDIH BPK · Primary regulation
- Government Regulation No. 61 of 2021 amending reporting-party scopeJDIH BPK · Primary regulation
- Law No. 9 of 2013 on Prevention and Eradication of Terrorism FinancingJDIH BPK · Primary legislation
- OJK Regulation No. 8 of 2023 on AML, CFT and CPF programmesFinancial Services Authority (OJK) · Primary sector regulation
- Bank Indonesia Regulation No. 10 of 2024 on AML, CFT and CPF programmesBank Indonesia · Primary sector regulation
- Bank Indonesia Regulation No. 10 of 2025 on the payment industryBank Indonesia · Primary sector regulation
- Bank Indonesia payment-system licensingBank Indonesia · Official licensing guidance
- Presidential Regulation No. 13 of 2018 on corporate beneficial ownershipJDIH BPK · Primary regulation
- Minister of Law Regulation No. 2 of 2025 on BO verification and supervisionDirectorate General of General Legal Administration (AHU) · Primary regulation
- AHU Online corporate servicesMinistry of Law · Official registry service
- Law No. 27 of 2022 on Personal Data ProtectionJDIH BPK · Primary legislation
- Constitutional Court Decision No. 151/PUU-XXII/2024Constitutional Court via JDIH BPK · Authoritative court decision
- OJK Regulation No. 27 of 2024 on digital financial asset and crypto tradingFinancial Services Authority (OJK) · Primary sector regulation
- OJK Regulation No. 23 of 2025 amending the digital-financial-asset and crypto trading frameworkFinancial Services Authority (OJK) · Primary sector regulation
- PADK OJK No. 3 of 2026 implementing digital financial asset and crypto reportingFinancial Services Authority (OJK) · Primary implementing regulation
- OJK digital financial asset and crypto publicationsFinancial Services Authority (OJK) · Official current guidance
- OJK and Bappebti end digital-asset supervision transitionFinancial Services Authority (OJK) · Official transition statement
- PPATK profile and FIU mandatePPATK · Official authority profile
- PPATK goAML reporting portalPPATK · Official reporting service
- FATF Indonesia country profileFATF · Authoritative current assessment
- Indonesia third enhanced follow-up report - 3 June 2026FATF · Authoritative current assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- Law No. 24 of 2009 on the State FlagJDIH BPK · Primary national-symbol legislation
- Secretariat of State guidance on Sang Merah PutihMinistry of State Secretariat · Official national-symbol guidance
Direct answers
Indonesia KYC, KYB and AML questions
Who receives suspicious financial transaction reports?+
PPATK, Indonesia's Financial Transaction Reports and Analysis Centre, through the current PPATK reporting system.
When is a suspicious financial transaction report due?+
For a financial service provider under Law No. 8 of 2010, as soon as possible and no later than three working days after it knows the suspicious elements. Profession- and sector-specific rules must also be checked.
What cash transaction is threshold-reportable?+
A financial-service cash transaction of at least IDR 500 million or equivalent, in one transaction or aggregated within one working day, is generally reportable to PPATK within 14 working days, subject to statutory exceptions.
Is IDR 100 million the universal reporting threshold?+
No. It is a statutory KYC trigger, not the general cash-report threshold. Cash, cross-border transfer, goods/service-provider and sector rules have separate scope and mechanics.
How is beneficial ownership determined?+
For AML CDD, follow ultimate ownership, benefit and control to natural persons. Corporate AHU disclosure separately uses entity-specific tests, including more than 25% for specified interests plus alternative control and benefit tests.
How long are AML records retained?+
Generally at least five years, but the start event differs by customer, transaction, corporate document and beneficial-owner record. Record the trigger for each class.
What happens on a DTTOT or DPPSPM match?+
A confirmed match requires blocking without delay and without prior notice, list-specific reports to Police or PPATK with required copies, and a suspicious transaction report. Apply current sector instructions and deadlines.
What privacy rules apply to biometric onboarding?+
Biometrics are specific personal data under Law No. 27 of 2022. Establish a lawful basis, conduct a DPIA where processing is high-risk, apply security and oversight, and verify current implementing and authority-channel requirements.
Who supervises crypto activity?+
OJK supervises digital financial assets including crypto under the current framework. The OJK/Bappebti transition ended in January 2026; confirm the current amended licence class before service.
Is Indonesia on a FATF public list?+
No. Indonesia was absent from both FATF public lists dated 19 June 2026 and has been a FATF member since 2023. That does not make every Indonesian customer or transaction low risk.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 September 2026. Confirm the reporting-party perimeter, current PPATK reporting schema, OJK or Bank Indonesia licence, professional overlay, sanctions lists, PDP implementing position and digital-asset classification with the competent authority and qualified Indonesian counsel before launch.