Malaysia KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Malaysia.
- Last reviewed
- Last reviewed:
- Version
- Version 1.1

Portable implementation guide
Get the PDF checklist
11 control areas · 42 implementation checks
Last reviewed: 25 September 2026 · Version 1.1
Download the checklistDirect answer
What does the Malaysia compliance checklist cover?
The Malaysia checklist translates primary KYC, KYB and AML rules into 11 control areas and 42 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Competent authority and FIU
- Bank Negara Malaysia (BNM), Financial Intelligence and Enforcement Department
- Primary AML law
- AMLA 2001 as amended by Act A1761, effective 1 March 2026
- STR timing
- Promptly; under BNM's financial-institution policy, by the next working day after the compliance officer establishes suspicion
- Cash threshold report
- For covered financial institutions: RM25,000 or more in aggregated qualifying cash transactions in the same account in one day
- AML retention
- At least 6 years from the applicable transaction-completion or relationship-termination event; longer where directed or investigated
- Company-register BO
- Separate SSM criteria include direct or indirect holdings of not less than 20%, plus control-by-other-means tests
- Privacy
- PDPA 2010 as amended; biometric data is sensitive personal data; breach, DPO, transfer and DPIA controls may apply
- FATF public lists
- Not listed at 19 June 2026; 2025 mutual-evaluation roadmap remains relevant
Implementation detail
Malaysia compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingMap the actual activity, regulator and licence before applying a control set.4 items+
Determine whether each activity is carried on by a reporting institution under AMLA.
- Implementation action
- Map every product, service, customer journey, branch and agent to the current First Schedule activity and record the applicable financial-institution or DNFBP/NBFI policy document; include the Act A1761 changes effective 1 March 2026.
- Evidence to retain
- Activity and entity map, First Schedule analysis, policy-document mapping, legal update log and counsel or compliance approval.
- Primary citation
- AMLA 2001, sections 3, 7 and 7A and First Schedule, as amended by Act A1761; BNM AMLA portal
Identify the competent authority and sector supervisor.
- Implementation action
- Route AMLA reporting and competent-authority matters to BNM's Financial Intelligence and Enforcement Department while documenting the relevant regulatory or supervisory authority for the entity and activity.
- Evidence to retain
- Regulatory perimeter memo, supervisor directory, reporting access, escalation tree and correspondence log.
- Primary citation
- AMLA 2001, sections 7, 7A and 8; Act A1761; BNM AMLA portal
Obtain every required sector approval before regulated activity.
- Implementation action
- Confirm licensing or approval under the FSA, IFSA, MSBA, capital-markets framework or other sector law; do not treat AMLA registration or compliance as permission to provide the underlying service.
- Evidence to retain
- Licence or approval, conditions, service inventory, renewal calendar, agent approvals and launch sign-off.
- Primary citation
- Financial Services Act 2013; Islamic Financial Services Act 2013; Money Services Business Act 2011; SC Guidelines on Recognized Markets
Control branches, subsidiaries, agents and outsourced functions.
- Implementation action
- Apply the required group programme, information-sharing safeguards and risk-based oversight; document responsibility and applicable Malaysian or host-country rules for each delivery party.
- Evidence to retain
- Group standard, contracts, due diligence, responsibility matrix, monitoring results and remediation.
- Primary citation
- BNM AML/CFT/CPF and TFS for FIs PD, paragraphs 13 and 18; applicable DNFBP/NBFI PD provisions
02Governance and risk assessmentGovernance must reflect the institution's actual ML/TF/PF exposure, scale and complexity.4 items+
Maintain documented business and relationship risk assessments.
- Implementation action
- Assess customers, countries, products, services, transactions, delivery channels, technology, agents and outsourcing for ML/TF/PF risk and refresh after material change or new national and sector risk information.
- Evidence to retain
- Methodology, current assessments, data sources, approvals, residual-risk decisions and remediation plan.
- Primary citation
- AMLA 2001, sections 16 and 19; BNM FIs PD, paragraph 10; applicable DNFBP/NBFI PD risk provisions
Maintain an effective AML/CFT/CPF compliance programme.
- Implementation action
- Translate risks into policies for CDD, beneficial ownership, PEPs, monitoring, reporting, sanctions, records, training, independent audit and regulatory response.
- Evidence to retain
- Board-approved programme, control map, procedures, testing, training and issue closure.
- Primary citation
- AMLA 2001, section 19 as amended by Act A1761; BNM FIs PD, paragraph 11
Appoint accountable compliance leadership.
- Implementation action
- Appoint a management-level compliance officer, notify BNM when the applicable policy requires it, preserve independence and resources, and maintain branch-level responsibility where required.
- Evidence to retain
- Appointment, BNM notification, job description, reporting line, resources, branch designations and minutes.
- Primary citation
- AMLA 2001, section 19(4); BNM FIs PD, paragraphs 11.3 and 11.4; applicable DNFBP/NBFI PD
Test programme effectiveness independently.
- Implementation action
- Set a risk-based audit scope and frequency, give reviewers access to systems and samples, report findings to appropriate governance and verify remediation.
- Evidence to retain
- Audit plan, independence record, workpapers, report, management response and closure testing.
- Primary citation
- BNM FIs PD, paragraph 11.7; applicable DNFBP/NBFI PD independent-audit provisions
03Natural-person identificationCDD triggers and minimum data vary by sector and product; suspicion overrides monetary thresholds.4 items+
Apply CDD at every applicable trigger.
- Implementation action
- Complete CDD when establishing a relationship and at the sector-specific occasional-transaction, cash, wire, e-money or other trigger, and always when suspicion exists or prior information is doubtful.
- Evidence to retain
- Trigger matrix by sector, onboarding record, transaction aggregation, suspicion override and refresh decision.
- Primary citation
- AMLA 2001, section 16 as amended by Act A1761; BNM FIs PD, paragraphs 14A.1, 14B.2, 14C.2 and 14D.2
Identify and verify each individual from reliable independent sources.
- Implementation action
- Collect the applicable name, official identifier, address, birth, nationality, occupation and contact attributes, verify authenticity and resolve discrepancies before proceeding except under an express controlled allowance.
- Evidence to retain
- Identity record, source images and provenance, verification results, fraud checks and discrepancy resolution.
- Primary citation
- AMLA 2001, section 16; BNM FIs PD, paragraphs 14A.9.1, 14B.11.1, 14C.10.1 and 14D.9.1
Verify representatives and their authority.
- Implementation action
- Identify and verify each person acting for a customer and validate written authority, mandate or directors' resolution before accepting instructions.
- Evidence to retain
- Representative KYC, mandate, signatory rules, validity checks and activity log.
- Primary citation
- BNM FIs PD, paragraphs 14A.3(b), 14A.9.5, 14B.3(b), 14C.4(b) and 14D.3(b)
Do not proceed when required CDD cannot be completed.
- Implementation action
- Do not open the account, start the relationship or perform the transaction, or terminate an existing relationship as applicable; document the reason and promptly assess and file an STR without tipping off.
- Evidence to retain
- CDD failure record, restriction or exit action, STR decision, filing receipt and confidentiality controls.
- Primary citation
- BNM FIs PD, paragraphs 14A.16-14A.17, 14B.18-14B.19, 14C.17-14C.18 and 14D.17-14D.18
04KYB, registries, and beneficial ownershipAML beneficial ownership and SSM company-register reporting are related but distinct tests.4 items+
Verify legal existence, powers and business purpose.
- Implementation action
- Obtain current incorporation or registration evidence, legal form, identifiers, registered and principal addresses, governing documents, directors or partners and intended activity from SSM and other reliable sources.
- Evidence to retain
- Registry extract, constitutional documents, identifier checks, officer list, business profile and discrepancies.
- Primary citation
- AMLA 2001, section 16; BNM FIs PD, paragraphs 14A.9, 14B.11, 14C.10 and 14D.9
Identify and verify AML beneficial owners through the prescribed cascade.
- Implementation action
- Trace ownership to natural persons, including at minimum directors, partners and shareholders with more than 25% equity under the BNM FIs PD; then assess control by other means and use the relevant senior-management fallback only when no natural person is identified.
- Evidence to retain
- Ownership chart, share data, control analysis, verified identities, source records and fallback rationale.
- Primary citation
- BNM FIs PD, paragraphs 14A.9.6, 14B.11.12, 14C.10.7 and 14D.9.6
Identify parties to trusts and comparable arrangements.
- Implementation action
- Identify and verify settlors, trustees, protectors, beneficiaries or classes, objects of a power and any other natural person exercising ultimate effective control, including through the chain of control or ownership.
- Evidence to retain
- Trust deed, party schedule, control and ownership chain, identity verification and change monitoring.
- Primary citation
- BNM FIs PD, definition of beneficial owner and paragraphs 14A.9.13, 14B.11.19, 14C.10.14 and 14D.9.13
Keep SSM beneficial-ownership reporting separate from AML CDD.
- Implementation action
- Apply the Companies Act and revised SSM guideline criteria, including not-less-than-20% direct or indirect share or voting holdings and control by other means; record and lodge changes within the applicable 14-day stages and continue identification efforts when senior management is recorded as fallback.
- Evidence to retain
- Register of beneficial owners, notices, responses, verification, e-BOS lodgements, annual return and fallback review log.
- Primary citation
- Companies Act 2016, Division 8A, sections 60A-60D and 68; SSM BO Guideline revised 2025, paragraphs 20-29 and 43-50
05PEPs, enhanced due diligence, and remote onboardingHigher-risk relationships require corroboration, approval and intensified monitoring.4 items+
Identify foreign, domestic and international organisation PEP exposure.
- Implementation action
- Screen customers, beneficial owners and relevant connected persons for PEP, family-member and close-associate status and refresh the assessment during the relationship.
- Evidence to retain
- Screening results, data source, relationship map, risk rationale and refresh history.
- Primary citation
- BNM FIs PD, paragraph 15 and definitions of PEP, family member and close associate
Apply enhanced CDD to higher-risk cases.
- Implementation action
- Obtain additional customer and beneficial-owner information, corroborate source of wealth or funds, obtain senior-management approval and increase monitoring; for PEPs, obtain both source of wealth and source of funds as required by the applicable policy.
- Evidence to retain
- EDD trigger, additional sources, corroboration, approval, monitoring plan and review.
- Primary citation
- BNM FIs PD, paragraphs 14A.12, 14B.14, 14C.13 and 14D.13; paragraph 15
Use simplified CDD only on documented low risk.
- Implementation action
- Confirm the sector-specific eligibility and Board or management approval, keep effective monitoring and withdraw simplified treatment when risk increases or suspicion arises.
- Evidence to retain
- Eligibility assessment, approval, configured limits, monitoring results and withdrawal trigger.
- Primary citation
- BNM FIs PD, paragraphs 14A.10, 14B.12, 14C.11 and 14D.10
Control non-face-to-face identity risk.
- Implementation action
- Apply the current BNM e-KYC and sector requirements to document authenticity, biometric or liveness controls, impersonation, device and channel risk, fallback review and model or vendor governance.
- Evidence to retain
- Method assessment, test results, exception handling, vendor diligence, monitoring and model-change approvals.
- Primary citation
- BNM Electronic Know-Your-Customer Policy Document, 15 April 2024; BNM FIs PD non-face-to-face provisions
06Monitoring and suspicious transaction reportingSuspicion covers transactions, activities and property under amended AMLA, while the saved BNM policy also captures attempted and proposed transactions.4 items+
Conduct ongoing due diligence and transaction monitoring.
- Implementation action
- Scrutinise activity against the customer's business, risk and source-of-funds profile, keep CDD and beneficial ownership current and escalate unusual patterns or new risk promptly.
- Evidence to retain
- Scenario inventory, alerts, case files, profile refreshes, tuning and dispositions.
- Primary citation
- AMLA 2001, section 16 as amended by Act A1761; BNM FIs PD ongoing-due-diligence provisions
Assess statutory and policy suspicion triggers.
- Implementation action
- Evaluate transactions, activities and property under amended AMLA for links to unlawful activity, ML, TF or restricted-activity financing. For institutions subject to the saved BNM FIs policy, also assess attempted and proposed transactions; record when reasonable grounds arose.
- Evidence to retain
- Alert chronology, facts reviewed, statutory or policy ground, decision-maker, decision time and escalation.
- Primary citation
- AMLA 2001, section 14 as amended by Act A1761; Act A1761, section 52(5); BNM FIs PD, paragraph 22.1.1
Submit an STR through BNM's prescribed channel on time.
- Implementation action
- Submit promptly through the Financial Intelligence System or current prescribed route. For an institution governed by the BNM FIs PD, file by the next working day after the compliance officer establishes suspicion; verify the sector-specific rule before relying on that deadline.
- Evidence to retain
- Internal report, confirmation timestamp, STR, FINS receipt, supplemental filing and delay analysis.
- Primary citation
- AMLA 2001, section 14; BNM FIs PD, paragraphs 22.1-22.2, especially 22.2.6
Protect STR and investigation information.
- Implementation action
- Restrict knowledge and disclosure, use need-to-know access, review any customer communication for tipping-off risk and preserve statutory confidentiality and permitted-disclosure analysis.
- Evidence to retain
- Access logs, disclosure register, legal review, communications approval, training and incident record.
- Primary citation
- AMLA 2001, sections 14A and 20; BNM FIs PD, paragraph 23
07Cash, wire transfers, payments, and digital assetsAmounts and licensing duties attach to specific products and institution types.4 items+
Report covered cash transactions at the correct scoped threshold.
- Implementation action
- For institutions subject to the BNM FIs PD cash-reporting rule, aggregate qualifying physical-currency and bearer-instrument deposits and withdrawals in the same account in one day and report RM25,000 or more; do not extend this threshold to every AMLA reporting institution or non-cash activity.
- Evidence to retain
- Aggregation logic, cash data, exclusions, CTR, FINS receipt and quality review.
- Primary citation
- BNM FIs PD, paragraphs 21.2-21.4
Transmit and retain required wire-transfer information.
- Implementation action
- For cross-border wires of RM3,000 or more, include accurate originator and required beneficiary details; apply the reduced below-threshold dataset, domestic traceability, missing-data controls and beneficiary verification exactly as the policy requires.
- Evidence to retain
- Field matrix, payment samples, validation rules, exception queue, beneficiary checks and retention.
- Primary citation
- BNM FIs PD, paragraphs 19.1-19.4
Obtain approval before issuing e-money and apply the product's AML limits.
- Implementation action
- Confirm approval under section 11 of the FSA or IFSA unless a current limited-purpose exemption applies, implement the 31 January 2025 e-money policy and map the product to the applicable CDD, account and transaction limits.
- Evidence to retain
- Approval or exemption analysis, product limits, safeguarding, CDD configuration, testing and reporting.
- Primary citation
- FSA 2013, section 11; IFSA 2013, section 11; BNM Electronic Money Policy Document, revised 31 January 2025; BNM FIs PD, paragraph 14D and Appendix 3
Use licensed MSB providers and registered digital-asset operators.
- Implementation action
- Obtain the appropriate BNM MSB licence for money changing, remittance or wholesale currency business and SC registration for a DAX or other regulated digital-asset role; verify agents and current public registers before reliance.
- Evidence to retain
- Licence or registration, public-register check, agent certificate, conditions, service map and renewal monitoring.
- Primary citation
- Money Services Business Act 2011; BNM MSB directory; SC Guidelines on Recognized Markets, revised 20 May 2026; SC Digital Assets portal
08Targeted financial sanctionsTerrorism, proliferation and other UN sanctions controls apply independently of ordinary CDD thresholds.3 items+
Screen current domestic and UN lists without threshold.
- Implementation action
- Screen customers, beneficial owners, beneficiaries, representatives and transactions against the Domestic List and relevant UNSCR lists at onboarding, ongoing review and immediately after list updates; assess ownership, control and direction, not names alone.
- Evidence to retain
- List versions, update timestamps, screening scope, configuration tests, match analysis and dispositions.
- Primary citation
- AMLA 2001, Part VIA; BNM FIs PD, paragraphs 27.3-27.5, 28.2-28.4 and 29.2-29.4
Freeze, block or reject immediately and without delay after confirmation.
- Implementation action
- Upon confirming a designated or specified person or related party, freeze covered funds, property or economic resources, block applicable transactions or reject the potential customer, and permit dealings only under verified written authority.
- Evidence to retain
- Match confirmation, ownership-control analysis, action timestamp, system blocks, authority and release decision.
- Primary citation
- AMLA 2001, sections 66B and 66E; BNM FIs PD, paragraphs 27.6, 28.5 and 29.5
Report positive matches immediately to the required authorities.
- Implementation action
- Use the current prescribed form to report terrorism-related positive matches immediately to BNM and the Inspector-General of Police, and PF or other UN-sanctions actions immediately to BNM; submit related STRs and periodic updates where required.
- Evidence to retain
- Positive-match report, delivery receipts, STR, periodic report, communications and frozen-asset ledger.
- Primary citation
- BNM FIs PD, paragraphs 27.7-27.8, 28.6-28.7 and 29.6-29.7
09Records and regulator accessRetention must preserve reconstruction and remain extended for investigations or directions.3 items+
Retain AML records for at least six years from the correct event.
- Implementation action
- Keep CDD, account, activity and transaction records for at least six years after the transaction is completed or the relationship is terminated, using the later applicable event under the amended section 17 wording.
- Evidence to retain
- Retention schedule, event mapping, system configuration, sample retrieval and deletion controls.
- Primary citation
- AMLA 2001, section 17 as amended by Act A1761; BNM FIs PD, paragraph 24.3
Extend holds for investigations and competent-authority directions.
- Implementation action
- Suspend deletion when records are under investigation, prosecution, regulatory request or a current extension direction, and document release authority before disposal.
- Evidence to retain
- Legal-hold notice, affected systems, custodian acknowledgement, extension direction and release approval.
- Primary citation
- AMLA 2001, section 17; BNM FIs PD, paragraph 24.4
Make records reconstructable and promptly accessible.
- Implementation action
- Preserve origin, destination, amount, currency, parties, authority, CDD sources, decisions and timestamps in a form that can reconstruct activity and be supplied to BNM or the relevant supervisor within the specified period.
- Evidence to retain
- Reconstruction test, indexed archive, access logs, production record and regulator receipt.
- Primary citation
- AMLA 2001, sections 13, 15, 17, 21 and 25 as amended by Act A1761; BNM FIs PD, paragraphs 24-25
10Privacy, biometrics, breaches, and transfersPDPA duties apply to commercial processing within scope and now expressly address processors, biometrics, DPOs and breaches.5 items+
Establish PDPA scope, purpose and processing authority.
- Implementation action
- Map controller and processor roles, commercial-transaction coverage, notices, consent or other permitted processing, disclosure, accuracy, retention, access and security; apply sector codes where relevant.
- Evidence to retain
- Data map, legal basis, notices, consent records, processor terms, retention and rights workflow.
- Primary citation
- Personal Data Protection Act 2010, sections 2, 5-12 and 43-44, as amended by Act A1727
Treat biometric identity data as sensitive personal data.
- Implementation action
- For face, fingerprint, voice or behavioural templates produced by technical processing, apply sensitive-data conditions, minimisation, strict access, security, retention and deletion, and document alternatives and proportionality.
- Evidence to retain
- Biometric inventory, purpose assessment, consent or authority, access logs, security tests, retention and deletion proof.
- Primary citation
- PDPA 2010, section 4 as amended by Act A1727, section 40; Personal Data Protection Standard 2015
Appoint and notify a DPO when the current criteria apply.
- Implementation action
- Assess the Commissioner's thresholds, including processing over 20,000 data subjects, sensitive or financial data over 10,000 data subjects, or regular and systematic monitoring; appoint a qualified accessible DPO, register the appointment within 21 days and register a replacement within 14 days of the new appointment after the prior DPO leaves or the term ends.
- Evidence to retain
- Threshold assessment, appointment, qualifications, contact channel, notification receipt, replacement record and deadline log.
- Primary citation
- PDPA 2010, section 12A; Commissioner's Circular No. 1/2025, paragraphs 8(2)-8(3), and DPO Guideline
Assess every personal-data breach and notify when the criteria are met.
- Implementation action
- Assess whether the breach creates significant harm or meets another notification criterion, including sensitive data, identity-fraud-enabling combinations or significant scale above 1,000 affected subjects. If a criterion is met, notify the Commissioner as soon as practicable and no later than 72 hours from occurrence or confirmation under the guideline; explain a delay, complete staged information no later than 30 days, notify affected subjects no later than seven days after the initial Commissioner notification, and retain breach records for at least two years.
- Evidence to retain
- Incident chronology, notification-criteria assessment, harm and scale assessment, 72-hour filing, seven-day subject notice, delay reasons, staged updates and two-year register.
- Primary citation
- PDPA 2010, section 12B; Commissioner's Circular No. 2/2025; DBN Guideline, paragraphs 5.2, 6.1-6.2 and 9.1
Control cross-border transfers and high-risk processing.
- Implementation action
- Before an overseas transfer, document substantially similar law or adequate protection, or a specific section 129 exception, and apply contracts and transfer due diligence. Conduct a DPIA where the 2026 guideline requires it, including high-risk biometric or large-scale processing.
- Evidence to retain
- Transfer map, destination assessment, transfer impact assessment, contract, exception record, DPIA and residual-risk approval.
- Primary citation
- PDPA 2010, section 129 as amended by Act A1727; Cross-Border Transfer Guideline 2025; DPIA Guideline 2026
11Practical evidence packsEvidence should let an independent reviewer reconstruct the legal basis and operational decision.3 items+
Maintain a customer and beneficial-owner evidence pack.
- Implementation action
- Preserve the trigger, identity and KYB sources, ownership and control cascade, representative authority, risk rating, PEP and sanctions results, EDD, approvals and refresh history.
- Evidence to retain
- Timestamped case file with source provenance, decision log, approvals and version history.
- Primary citation
- AMLA 2001, sections 13, 16 and 17; BNM FIs PD, paragraphs 14-17 and 24
Maintain reporting and monitoring evidence.
- Implementation action
- Preserve monitoring configuration, alert chronology, analyst reasoning, escalation, STR and CTR submissions, sanctions actions, confidentiality access and feedback-driven tuning.
- Evidence to retain
- Scenario register, case exports, FINS receipts, frozen-asset ledger, access logs and change approvals.
- Primary citation
- AMLA 2001, sections 14, 14A, 15, 17 and 20; BNM FIs PD, paragraphs 21-25 and 27-29
Maintain licensing, outsourcing and privacy evidence.
- Implementation action
- Keep current licences, conditions, agent and vendor due diligence, contracts, service and data-flow maps, incident records, transfer assessments, DPIAs and closure testing together with named owners.
- Evidence to retain
- Licence register, contract repository, assurance reports, data map, privacy register, remediation and governance minutes.
- Primary citation
- Applicable sector law; BNM policy documents; PDPA 2010 as amended by Act A1727; Commissioner guidelines
Primary-source register
28 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Malaysia AMLA portal and current amendment noticeBank Negara Malaysia · Official legal portal
- AMLA 2001 Act 613 compilationAttorney General's Chambers of Malaysia · Primary legislation
- AMLA Amendment Act 2025 Act A1761Bank Negara Malaysia · Primary amending legislation
- Act A1761 commencement notification P.U. (B) 76/2026Bank Negara Malaysia · Official gazette instrument
- AML/CFT/CPF and TFS for Financial Institutions Policy DocumentBank Negara Malaysia · Binding supervisory policy
- AML/CFT/CPF and TFS for DNFBPs and NBFIs Policy DocumentBank Negara Malaysia · Binding supervisory policy
- Companies Act 2016 and amendments portalCompanies Commission of Malaysia · Official legal portal
- Companies Amendment Act 2024 resourcesCompanies Commission of Malaysia · Official legal and implementation portal
- Guideline for the Reporting Framework for Beneficial Ownership of Companies, revised 2025Companies Commission of Malaysia · Official registry guideline
- Personal Data Protection Act 2010 portalPersonal Data Protection Commissioner Malaysia · Official legal portal
- Personal Data Protection Amendment Act 2024 Act A1727Personal Data Protection Commissioner Malaysia · Primary amending legislation
- PDPA Amendment Act commencement notification P.U. (B) 522Personal Data Protection Commissioner Malaysia · Official gazette instrument
- Commissioner's Circular No. 2/2025 on data breach notificationPersonal Data Protection Commissioner Malaysia · Official regulatory circular
- Data Breach Notification GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Personal Data Breach Notification SystemPersonal Data Protection Commissioner Malaysia · Official regulatory reporting portal
- Commissioner's Circular No. 1/2025 on data protection officersPersonal Data Protection Commissioner Malaysia · Official regulatory circular
- Data Protection Officer GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Cross-Border Transfer of Personal Data GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Data Protection Impact Assessment GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Electronic Know-Your-Customer Policy Document, 15 April 2024Bank Negara Malaysia · Binding supervisory policy
- Electronic Money Policy Document, revised 31 January 2025Bank Negara Malaysia · Binding supervisory policy
- Money Services Business frameworkBank Negara Malaysia · Official licensing guidance
- Guidelines on Recognized Markets, revised 20 May 2026Securities Commission Malaysia · Official capital-markets guideline portal
- Malaysia digital-assets regulatory portalSecurities Commission Malaysia · Official regulatory guidance
- Malaysia country profileFinancial Action Task Force · Authoritative international assessment
- FATF/APG Mutual Evaluation Report of Malaysia 2025Financial Action Task Force · Authoritative international assessment
- Jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Current public-list statement
- High-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Current public-list statement
Direct answers
Malaysia KYC, KYB and AML questions
Who receives suspicious transaction reports in Malaysia?+
The Financial Intelligence and Enforcement Department of Bank Negara Malaysia receives STRs through FINS or the current prescribed route. Confirm access and sector instructions before filing.
What is the STR deadline?+
AMLA requires reporting of covered suspicion and BNM policy requires prompt filing. For institutions governed by the FIs Policy Document, the compliance officer must submit by the next working day after establishing suspicion. Other sectors must verify their applicable policy and directions.
Is RM25,000 a universal CDD or reporting threshold?+
No. Under the BNM FIs Policy Document it is the scoped cash-threshold-report level for qualifying aggregated cash activity and is also a banking occasional-transaction CDD trigger. Other products and sectors have different triggers, and suspicion applies regardless of amount.
Which beneficial-ownership threshold should be used?+
Do not merge the tests. The BNM FIs Policy Document cascade includes shareholders with more than 25% equity, control by other means and a senior-management fallback. The SSM company-reporting guideline separately uses not less than 20% share or voting criteria plus control tests.
How long must AML records be kept?+
At least six years from the applicable completion or termination event, with longer retention where an investigation, prosecution or competent-authority direction requires it.
Do digital-asset businesses need approval?+
Yes where the activity falls within Malaysia's regulated digital-asset perimeter. A DAX must be registered as a recognized market operator with the Securities Commission, and other digital-asset roles have their own SC requirements.
What happens after a sanctions match?+
After a true match is confirmed, the institution must take the applicable freeze, block or rejection action immediately and without delay, report immediately to the required authorities, file related STRs and retain evidence. The exact route differs among TF, PF and other UN regimes.
How does Malaysia regulate biometric KYC data?+
Act A1727 added biometric data to sensitive personal data. Controllers and processors must apply the PDPA security and processing requirements, and high-risk biometric processing may require a DPIA under the 2026 guideline.
When must a personal-data breach be reported?+
Assess every breach. Commissioner notification is required when a guideline criterion is met, including significant harm, sensitive data, identity-fraud-enabling combinations or significant scale above 1,000 affected subjects. Notify as soon as practicable and no later than 72 hours from occurrence or confirmation under the guideline; affected subjects must be notified no later than seven days after the initial Commissioner notification.
Is Malaysia on a FATF public list?+
No. Malaysia was absent from both FATF public lists dated 19 June 2026, but its 2025 mutual evaluation includes a three-year roadmap and absence from a public list is not a low-risk rating.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 September 2026. Confirm the current First Schedule activity, applicable BNM or sector-supervisor policy document, post-Act A1761 directions, Labuan or other sector overlays, licensing, reporting forms, sanctions lists, privacy coverage and implementation facts with the competent authority and qualified Malaysian counsel before launch.