Kuwait KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Kuwait.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 39 implementation checks
Last reviewed: 1 October 2026 · Version 1.0
Download the checklistDirect answer
What does the Kuwait compliance checklist cover?
The Kuwait checklist translates primary KYC, KYB and AML rules into 11 control areas and 39 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML law
- Law No. 106 of 2013, as amended
- FIU
- Kuwait Financial Intelligence Unit
- STR timing
- No later than 2 working days after suspicion; attempts and all values included
- Occasional-transaction CDD
- KWD 3,000 or equivalent, including linked transactions
- Wire-transfer CDD
- Before domestic or international wire transfers
- AML retention
- At least 5 years, with record-specific start events
- Registry beneficial owner
- 25% ownership or voting rights, control by other means, then senior-management fallback
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Kuwait compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the entity, activity and supervisor before assigning controls.3 items+
Determine whether the entity is a financial institution or designated non-financial business or profession.
- Implementation action
- Map services, customers and Kuwait nexus to Law No. 106 of 2013 and the current activity-specific supervisory perimeter.
- Evidence to retain
- Perimeter memo, service and funds-flow maps, legal analysis and authority confirmation.
- Primary citation
- Law No. 106 of 2013, article 1; Executive Regulation article 1
Obtain each required licence or approval before activity.
- Implementation action
- Classify banking, finance, exchange, securities, insurance, payments, real estate, precious-metals, professional and technology features and obtain approval from the competent authority.
- Evidence to retain
- Licence matrix, applications, approvals, conditions and renewal calendar.
- Primary citation
- Law No. 106 of 2013, articles 13-15; applicable CBK, CMA or MOCI law and instructions
Use the current sector instruction and controlling Arabic text.
- Implementation action
- Track amendments and circulars for the exact licence; treat official English translations as informational where the authority states that Arabic controls.
- Evidence to retain
- Source inventory, translation protocol, change log and compliance mapping.
- Primary citation
- Executive Regulation article 17; applicable supervisory instructions
02Governance and ML/TF/PF risk assessmentGovernance must be risk-based, documented and available to the supervisor.3 items+
Maintain a documented and current enterprise risk assessment.
- Implementation action
- Assess customers, countries, products, services, delivery channels, new technology, sanctions and emerging risks; update for material change.
- Evidence to retain
- Methodology, assessment, data sources, approvals, residual-risk decisions and change log.
- Primary citation
- Law No. 106 of 2013, article 4; Executive Regulation articles 2-4 and 11
Maintain proportionate policies, systems and controls.
- Implementation action
- Document CDD, monitoring, reporting, records, sanctions, screening, training, group information sharing and escalation.
- Evidence to retain
- Approved framework, control map, procedures, training and issue register.
- Primary citation
- Law No. 106 of 2013, article 10; Executive Regulation articles 12-14
Designate a senior compliance officer and independent audit function.
- Implementation action
- Appoint an empowered senior compliance officer, preserve access and escalation, and independently test control design and operation.
- Evidence to retain
- Appointment, authority matrix, board reporting, audit plan, findings and closure tests.
- Primary citation
- Law No. 106 of 2013, article 10(c) and (e)
03Natural-person identificationCDD covers the customer, beneficial owner and authorised representative.6 items+
Apply CDD before or during relationship establishment and at every statutory trigger.
- Implementation action
- Identify and verify the customer and beneficial owner, understand purpose and intended nature, and refresh for suspicion, doubt or material change.
- Evidence to retain
- Trigger analysis, identity record, verification result, purpose and completion timestamp.
- Primary citation
- Law No. 106 of 2013, article 5
Apply the KWD 3,000 occasional-transaction threshold correctly.
- Implementation action
- For a customer without an established relationship, complete CDD before a single or linked transaction at the statutory threshold; do not treat it as a universal threshold-reporting rule.
- Evidence to retain
- Aggregation logic, transaction samples and CDD outcomes.
- Primary citation
- Law No. 106 of 2013, article 5(3)(b); Executive Regulation article 6
Apply CDD before domestic and international wire transfers.
- Implementation action
- Do not import the KWD 3,000 occasional-transaction threshold into the separate wire-transfer trigger.
- Evidence to retain
- Transfer samples, CDD result and exception testing.
- Primary citation
- Law No. 106 of 2013, article 5(3)(c)
Verify identity from reliable, independent evidence.
- Implementation action
- Use the civil card for citizens and residents, passport or travel document for non-residents, and current reliable evidence required by the supervisor.
- Evidence to retain
- Identity attributes, source provenance, validation result and fraud checks.
- Primary citation
- Law No. 106 of 2013, article 5; Executive Regulation article 5
Identify representatives and validate authority.
- Implementation action
- Verify persons acting for the customer and obtain the instrument, document or order proving authority before instructions are accepted.
- Evidence to retain
- Representative KYC, mandate, authority checks and instruction limits.
- Primary citation
- Executive Regulation article 5(d)
Do not proceed when required CDD cannot be completed.
- Implementation action
- Decline or terminate the account, relationship or transaction and consider a KFIU report without tipping off.
- Evidence to retain
- CDD failure record, restriction or exit decision, report assessment and communications review.
- Primary citation
- Law No. 106 of 2013, article 5(5)
04KYB, registry, and beneficial ownershipRegistry disclosure and AML beneficial-ownership analysis are related but distinct.5 items+
Verify the legal person and understand its ownership and control structure.
- Implementation action
- Collect the commercial licence, constitutional documents, address, senior managers and reliable registry information; resolve discrepancies.
- Evidence to retain
- Registry extract, constitutional documents, officer list and discrepancy record.
- Primary citation
- Law No. 106 of 2013, article 5; Executive Regulation article 5(c)
Identify natural persons who ultimately own or control the customer.
- Implementation action
- Trace direct, indirect, layered and nominee structures and identify the person on whose behalf the transaction is conducted.
- Evidence to retain
- Ownership chart, control analysis, declarations, source documents and verified identities.
- Primary citation
- Law No. 106 of 2013, articles 1 and 5
Apply the registry 25% test with control and fallback analysis.
- Implementation action
- Identify natural persons with at least 25% ownership or voting rights; if none, identify control by other means; if still none after all reasonable means, identify the senior management official.
- Evidence to retain
- Calculations, control analysis, fallback rationale and identities.
- Primary citation
- MOCI Ministerial Resolution No. 4 of 2023, article 5, as amended in 2025
Maintain and update the actual-beneficiary register.
- Implementation action
- Create and submit required registers within 60 days and record or submit changes within 15 days of awareness or the applicable change event.
- Evidence to retain
- Register, MOCI submission, change log, notices and receipts.
- Primary citation
- MOCI Ministerial Resolution No. 4 of 2023, articles 8, 11 and 14, as amended
Do not reduce AML ownership analysis to the registry percentage.
- Implementation action
- Assess ultimate ownership, effective control and on-behalf-of activity even when no person meets the registry percentage or an exemption applies.
- Evidence to retain
- Separate AML and registry analyses, rationale and approval.
- Primary citation
- Law No. 106 of 2013, articles 1 and 5; Resolution No. 4 of 2023
05PEPs, EDD, and remote onboardingEnhanced measures attach to specified and higher-risk circumstances.3 items+
Identify foreign, domestic and international-organisation PEPs, family members and close associates.
- Implementation action
- For foreign PEPs apply senior approval, source-of-wealth, source-of-funds and enhanced monitoring; apply those measures to domestic and international-organisation PEPs where risk is high.
- Evidence to retain
- Screening, relationship map, approval, source corroboration and review history.
- Primary citation
- Executive Regulation articles 1(4) and 7
Apply enhanced due diligence to higher-risk relationships.
- Implementation action
- Obtain additional customer, purpose, wealth and funds information; increase monitoring and document acceptance or continuation.
- Evidence to retain
- Risk trigger, additional CDD, source evidence, approval and monitoring plan.
- Primary citation
- Law No. 106 of 2013, article 4; Executive Regulation articles 1(3) and 8
Control non-face-to-face and new-technology risk.
- Implementation action
- Assess impersonation and document risk, validate vendors and liveness methods, preserve fallback and strengthen controls where residual risk is elevated.
- Evidence to retain
- Method assessment, vendor diligence, testing, exceptions and fraud cases.
- Primary citation
- Law No. 106 of 2013, articles 4-5; Executive Regulation article 11
06Monitoring and suspicious transaction reportingOngoing scrutiny and prompt escalation support reporting to KFIU.4 items+
Keep CDD current and monitor activity on a risk basis.
- Implementation action
- Examine transactions against purpose, commercial activity, expected behaviour, risk profile and source of funds where required.
- Evidence to retain
- Monitoring scenarios, alerts, case decisions, refresh records and quality tests.
- Primary citation
- Law No. 106 of 2013, article 5(2)(c)
Escalate suspicion without waiting for proof or completion.
- Implementation action
- Assess completed and attempted activity promptly and record the facts, reasonable grounds and formation timestamp.
- Evidence to retain
- Alert chronology, information reviewed, decision and decision-maker.
- Primary citation
- Law No. 106 of 2013, article 12; Executive Regulation article 16
Report to KFIU no later than two working days after suspicion.
- Implementation action
- Submit the report in KFIU's current method and form for transactions and attempts regardless of value; a stricter sector instruction must also be followed.
- Evidence to retain
- Suspicion timestamp, report, submission receipt, corrections and supervisory notice if required.
- Primary citation
- Executive Regulation article 16; Law No. 106 of 2013, article 12
Prevent tipping off and protect reporting information.
- Implementation action
- Restrict report knowledge and customer or third-party communications and disclose only where legally permitted.
- Evidence to retain
- Access controls, disclosure register, legal review, training and incident log.
- Primary citation
- Law No. 106 of 2013, article 13
07Payments, wires, thresholds, and virtual assetsTransfer and technology services require exact activity and licensing analysis.3 items+
Carry and validate required wire-transfer information.
- Implementation action
- Collect and transmit prescribed originator and beneficiary information, keep it through the payment chain and do not execute an outgoing transfer when required information cannot be obtained.
- Evidence to retain
- Field matrix, message samples, validation rules, repair queue and dispositions.
- Primary citation
- Law No. 106 of 2013, article 9; Executive Regulation article 10
Obtain the correct payment or remittance approval before launch.
- Implementation action
- Map money or value transfer, payment instruments, electronic money, exchange and financing functions to CBK law and current instructions.
- Evidence to retain
- Product memo, licence, conditions, safeguarding design and tests.
- Primary citation
- Law No. 106 of 2013, article 1; Law No. 32 of 1968 and applicable CBK instructions
Do not offer virtual-asset services as a Kuwait business without a lawful current licence path.
- Implementation action
- Apply MOCI's July 2023 circular and parallel regulator notices prohibiting the grant of VASP licences; re-verify current law before any crypto feature and warn customers of external-transaction risks where required.
- Evidence to retain
- Feature map, prohibition analysis, regulator confirmation, geofencing and customer notices.
- Primary citation
- MOCI Circular No. 80 of 2023; sector circulars dated July 2023
08Targeted financial sanctionsThe 2025 framework must be implemented using current lists and committee procedures.3 items+
Screen UN and Kuwait designations and ownership or control.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding and list updates; test aliases and controlled entities.
- Evidence to retain
- List versions, update logs, configuration tests, match analysis and dispositions.
- Primary citation
- Ministerial Decision No. 8 of 2025 and executive annexes
Freeze without delay when the current framework requires it.
- Implementation action
- Block dealings and prevent direct or indirect asset availability upon a true match, then use the competent notification route without waiting for an STR decision.
- Evidence to retain
- Match analysis, restriction timestamp, notification and authority correspondence.
- Primary citation
- Ministerial Decision No. 8 of 2025; MENAFATF 2026 follow-up, Recommendations 6 and 7
Use exemptions, licences, delisting or release only under written authority.
- Implementation action
- Identify the governing designation, apply through the current Special Committee process and implement every condition and expiry.
- Evidence to retain
- Regime analysis, permission, controls, reporting and release record.
- Primary citation
- Ministerial Decision No. 8 of 2025 and executive annexes
09Records and regulator accessFive years is the baseline, with distinct start events by record class.3 items+
Retain CDD, account and correspondence records for at least five years.
- Implementation action
- Run the period from relationship end or the covered occasional transaction, subject to longer competent-authority directions.
- Evidence to retain
- Retention schedule, trigger date, archive sample, retrieval test and deletion approval.
- Primary citation
- Law No. 106 of 2013, article 11(a)
Retain attempted and executed transaction records for at least five years.
- Implementation action
- Keep sufficient detail to reconstruct each transaction from its attempt or execution date.
- Evidence to retain
- Transaction sample, trigger calculation, legal hold and deletion log.
- Primary citation
- Law No. 106 of 2013, article 11(b)
Retain reports and risk assessments for their statutory periods.
- Implementation action
- Keep KFIU reports and related documents for five years from reporting and each risk assessment for five years from creation or update.
- Evidence to retain
- Report archive, assessment versions, access controls and production log.
- Primary citation
- Law No. 106 of 2013, article 11(c)-(d)
10Privacy, biometrics, breaches, and transfersApply the scope-specific CITRA regime and other confidentiality rules to KYC processing.3 items+
Determine whether CITRA's 2024 Data Privacy Protection Regulation applies.
- Implementation action
- Map the service, provider status, processing location and technology scope before treating the CITRA regulation as a universal economy-wide law.
- Evidence to retain
- Scope memo, data and service maps, regulator analysis and approval.
- Primary citation
- CITRA Decision No. 26 of 2024 and Data Privacy Protection Regulation
Process personal and sensitive data under the applicable conditions.
- Implementation action
- Document purpose and legal basis, transparency, minimisation, accuracy, security, retention and rights; apply heightened controls to biometric or sensitive identity data.
- Evidence to retain
- Data inventory, legal-basis map, notices, impact assessment, access and deletion tests.
- Primary citation
- CITRA Data Privacy Protection Regulation, 2024
Control processors, incidents and cross-border access.
- Implementation action
- Contract for instructions, confidentiality, security, escalation, return and deletion; assess transfer and breach duties under the exact applicable regime.
- Evidence to retain
- Processor contract, security review, transfer assessment, incident record and notifications.
- Primary citation
- CITRA Data Privacy Protection Regulation, 2024; applicable sector confidentiality rules
11Practical evidence packsEvidence should reconstruct onboarding, reporting and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, PEP, sanctions, purpose, risk, privacy, approvals and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting Law No. 106 of 2013, articles 4-5 and 11
Maintain a reconstructable KFIU and sanctions case pack.
- Implementation action
- Link activity, alert, suspicion chronology, report, receipt, confidentiality, asset restrictions and authority communications.
- Evidence to retain
- Complete sampled case pack, timeline and controlled-access record.
- Primary citation
- Operational control supporting Law No. 106 of 2013, articles 11-13
Maintain a launch and change pack.
- Implementation action
- Record perimeter, licences, programme, reporting connectivity, sanctions, privacy, vendors, tests and controlled uncertainties before launch or material change.
- Evidence to retain
- Signed launch pack, source register, tests, approvals and uncertainty log.
- Primary citation
- Official sources listed below
Primary-source register
15 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 106 of 2013 on AML/CFT and amendmentsKuwait Financial Intelligence Unit · Primary legislation - official English translation
- Ministerial Decision No. 37 of 2013 Executive Regulation and amendmentsKuwait Financial Intelligence Unit · Primary regulation - official English translation
- KFIU laws and decisions registerKuwait Financial Intelligence Unit · Official legal register
- Kuwait Financial Intelligence UnitKuwait Financial Intelligence Unit · Official FIU information
- CBK AML/CFT instructions for local banksCentral Bank of Kuwait · Official supervisor instructions
- CBK AML/CFT instructions for exchange companiesCentral Bank of Kuwait · Official supervisor instructions
- Ministerial Resolution No. 4 of 2023 on actual beneficiariesMinistry of Commerce and Industry · Primary registry regulation
- Ministerial Resolution No. 16 of 2025 amending beneficial-owner proceduresMinistry of Commerce and Industry · Primary amending regulation
- MOCI 2023 virtual-asset circular and beneficial-owner summaryMinistry of Commerce and Industry · Official regulatory notice
- CITRA Decision No. 26 of 2024 issuing the privacy regulationCommunication and Information Technology Regulatory Authority · Primary regulatory decision
- CITRA Data Privacy Protection RegulationCommunication and Information Technology Regulatory Authority · Official privacy regulation
- Kuwait Mutual Evaluation Report 2024FATF / MENAFATF · Authoritative assessment
- Kuwait second enhanced follow-up report 2026FATF / MENAFATF · Authoritative current follow-up
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
Direct answers
Kuwait KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Kuwait Financial Intelligence Unit receives reports using its current prescribed method and form.
When must a suspicious transaction report be filed?+
The Executive Regulation requires reporting no later than two working days after suspicion or reasonable grounds arise. Attempts and transactions of every value are covered; follow any stricter current sector instruction.
What is the occasional-transaction CDD threshold?+
KWD 3,000 or equivalent for a customer without an established relationship, including linked transactions. This is a CDD trigger, not a universal threshold-reporting rule.
Do wire transfers use the KWD 3,000 threshold?+
No. Law No. 106 of 2013 separately requires CDD before domestic or international wire transfers.
How is beneficial ownership determined?+
AML analysis identifies ultimate ownership, control and the person behind the transaction. The MOCI registry rule uses at least 25% ownership or voting rights, then control by other means, then a senior-management fallback after all reasonable means are exhausted.
How quickly must registry beneficial-owner data be updated?+
The 2023 resolution generally uses 15-day change and notification periods. Apply the exact trigger and the 2025 amendments to the event at issue.
How long are AML records kept?+
At least five years. CDD records run from relationship end or the relevant occasional transaction, transaction records from attempt or execution, reports from submission, and risk assessments from creation or update.
Can a business offer virtual-asset services in Kuwait?+
The July 2023 multi-regulator position prohibited issuing VASP licences and stated none had been issued. Re-confirm current law and regulator position before offering any virtual-asset feature.
Does Kuwait have a universal data-protection law?+
The CITRA 2024 regulation has a defined communications and IT scope. Determine its application and any sector confidentiality rules for the specific service rather than assuming universal coverage.
Is Kuwait on a FATF public list?+
No. Kuwait was absent from both FATF public lists dated 19 June 2026, but remains in MENAFATF enhanced follow-up and public-list absence is not a low-risk conclusion.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 1 October 2026. Confirm the regulated perimeter, current Arabic legal text, supervisory instructions, KFIU reporting specifications, sanctions designation, privacy scope and sector permissions with the competent authority and qualified Kuwait counsel before launch.