Oman KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Oman.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 38 implementation checks
Last reviewed: 2 October 2026 · Version 1.0
Download the checklistDirect answer
What does the Oman compliance checklist cover?
The Oman checklist translates primary KYC, KYB and AML rules into 11 control areas and 38 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML law
- Royal Decree 30/2016
- FIU
- National Centre for Financial Information
- STR timing
- Immediately; CBO outer limit 48 hours, FSA sectors 24 hours
- CBO occasional-transaction CDD
- OMR 5,000 or more, including linked operations
- CBO occasional wire CDD
- OMR 350 or equivalent
- Financial-sector retention
- At least 10 years under applicable instructions
- Beneficial ownership
- 25% is a starting point; control still requires analysis
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Oman compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify activity and supervisor first.3 items+
Determine the reporting-entity category.
- Implementation action
- Map services and Oman nexus to the financial-institution, DNFBP, non-profit and other covered categories.
- Evidence to retain
- Perimeter memo, service map and authority confirmation.
- Primary citation
- Royal Decree 30/2016
Obtain every licence before regulated activity.
- Implementation action
- Classify banking, payments, money services, finance, securities, insurance, fintech and virtual-asset features under current sector law.
- Evidence to retain
- Licence matrix, approvals and conditions.
- Primary citation
- Banking Law 2/2025; National Payment Systems Law 8/2018
Use the current sector instruction and controlling Arabic text.
- Implementation action
- Track BM 1187, FSA decisions and later circulars for the exact licence.
- Evidence to retain
- Source inventory, translations and change log.
- Primary citation
- CBO AML/CFT Guidelines 2022, sections 1.1-1.3
02Governance and risk assessmentGovernance must be risk-based and demonstrably effective.3 items+
Maintain enterprise and customer risk assessments.
- Implementation action
- Assess customers, countries, products, channels, technology, sanctions and emerging risks.
- Evidence to retain
- Methodology, assessment, approvals and updates.
- Primary citation
- Royal Decree 30/2016; CBO Guidelines chapter 2
Maintain proportionate controls.
- Implementation action
- Document CDD, monitoring, reporting, records, sanctions, training and escalation.
- Evidence to retain
- Approved framework, procedures and issue register.
- Primary citation
- CBO BM 1187
Appoint compliance leadership and independent assurance.
- Implementation action
- Preserve authority, resources, senior access and periodic testing.
- Evidence to retain
- Appointment, board reports, audit and remediation.
- Primary citation
- Royal Decree 30/2016; CBO BM 1187
03Natural-person identificationCDD covers customers, beneficial owners and representatives.6 items+
Apply CDD before a relationship and at every trigger.
- Implementation action
- Identify and verify relevant persons, understand purpose, and refresh for suspicion, doubt or change.
- Evidence to retain
- Trigger analysis, identity record and timestamp.
- Primary citation
- Royal Decree 30/2016 article 33
Apply the CBO OMR 5,000 occasional-transaction threshold correctly.
- Implementation action
- For a customer without a relationship, complete CDD for a single or linked operation at or above OMR 5,000; do not treat it as a universal report.
- Evidence to retain
- Aggregation logic and samples.
- Primary citation
- BM 1187 article 6; CBO Guidelines 3.2.2 note 2
Apply the separate CBO occasional-wire threshold.
- Implementation action
- Complete CDD before an occasional wire at OMR 350 or equivalent and apply wire-data controls.
- Evidence to retain
- Transfer samples and message fields.
- Primary citation
- CBO Guidelines 3.2.2 note 3
Use reliable independent identity evidence.
- Implementation action
- Validate current civil, passport, registry or other authoritative evidence.
- Evidence to retain
- Attributes, provenance and fraud checks.
- Primary citation
- Royal Decree 30/2016 article 33
Validate representatives and authority.
- Implementation action
- Verify the person and mandate before accepting instructions.
- Evidence to retain
- Representative KYC and mandate.
- Primary citation
- CBO BM 1187 CDD provisions
Do not proceed when CDD cannot be completed.
- Implementation action
- Decline or end the relationship and consider an NCFI report without tipping off.
- Evidence to retain
- Failure, restriction and report assessment.
- Primary citation
- Royal Decree 30/2016; CBO Guidelines 3.2-3.3
04KYB and beneficial ownershipVerify legal existence, ownership and effective control.4 items+
Verify the legal person and understand its structure.
- Implementation action
- Collect commercial registration, constitutional documents, managers and reliable registry evidence.
- Evidence to retain
- Extract, documents and discrepancy record.
- Primary citation
- Royal Decree 30/2016 article 33
Identify natural persons who ultimately own or control.
- Implementation action
- Trace direct, indirect, layered, nominee and control arrangements.
- Evidence to retain
- Ownership chart, calculations and verified identities.
- Primary citation
- CBO Guidelines 3.2.4
Use 25% as a starting point, not a safe harbour.
- Implementation action
- Identify aggregate interests of 25% or more and assess concert parties, control and lower holdings.
- Evidence to retain
- Calculations and control rationale.
- Primary citation
- CBO Guidelines 3.2.4
Maintain current BO information and filings.
- Implementation action
- Reconcile internal CDD with the commercial register and use the live MOCIIP change procedure.
- Evidence to retain
- BO register, filings, receipts and changes.
- Primary citation
- Commercial Companies Law 18/2019; FATF/MENAFATF MER 2024
05PEPs, EDD, and remote onboardingApply enhanced measures to PEPs and higher risks.3 items+
Identify PEPs, family and close associates.
- Implementation action
- Apply required approval, source-of-wealth, source-of-funds and enhanced monitoring under the sector rule.
- Evidence to retain
- Screening, approval and corroboration.
- Primary citation
- Royal Decree 30/2016 article 36; CBO Guidelines 3.2.7
Apply EDD to higher-risk relationships.
- Implementation action
- Obtain additional customer, purpose, wealth and funds information.
- Evidence to retain
- Risk trigger, additional CDD and approval.
- Primary citation
- CBO Guidelines 3.2.7
Control digital onboarding.
- Implementation action
- CBO licensees must use the National Digital Onboarding Registry as instructed while retaining responsibility for accuracy and EDD.
- Evidence to retain
- Method assessment, registry result and exceptions.
- Primary citation
- CBO BM 1191
06Monitoring and suspicious reportingOngoing scrutiny supports immediate NCFI reporting.4 items+
Monitor and refresh on a risk basis.
- Implementation action
- Compare activity with purpose, expected behaviour, risk and source of funds.
- Evidence to retain
- Scenarios, alerts and refresh records.
- Primary citation
- CBO Guidelines 3.2.6 and 3.3
Escalate suspicion without waiting for proof.
- Implementation action
- Assess transactions and attempts promptly and record grounds and formation time.
- Evidence to retain
- Chronology, information and decision.
- Primary citation
- Royal Decree 30/2016
Notify NCFI immediately and obey the sector outer limit.
- Implementation action
- File immediately; CBO-supervised entities must not exceed 48 hours and FSA capital-markets or insurance sectors must not exceed 24 hours.
- Evidence to retain
- Suspicion timestamp, report and receipt.
- Primary citation
- CBO Guidelines 3.3.4
Prevent tipping off.
- Implementation action
- Restrict report knowledge and customer communications.
- Evidence to retain
- Access controls, training and incidents.
- Primary citation
- Royal Decree 30/2016 article 49
07Payments, wires, thresholds, and virtual assetsApply activity-specific licensing and transfer controls.3 items+
Carry required wire information.
- Implementation action
- Transmit prescribed originator and beneficiary fields and risk-manage missing data.
- Evidence to retain
- Field matrix, samples and repair queue.
- Primary citation
- CBO BM 1187 articles 31-40
Obtain payment or money-service approval.
- Implementation action
- Map wallets, acquiring, remittance, exchange and ancillary activity to current CBO rules.
- Evidence to retain
- Product memo, licence and safeguarding tests.
- Primary citation
- Banking Law 2/2025; BM 1192
Treat virtual-asset exposure as a distinct risk.
- Implementation action
- Apply EDD to elevated exposure and confirm the current VASP registration and licensing path before launch.
- Evidence to retain
- Feature map, perimeter analysis and approval.
- Primary citation
- CBO Circular BDD/AML/CB/2020/4480
08Targeted financial sanctionsUse current UN and Oman directions.3 items+
Screen designations and ownership or control.
- Implementation action
- Screen relevant parties at onboarding, transactions and list updates.
- Evidence to retain
- List versions, tests and decisions.
- Primary citation
- NCCT Decision 1/2022
Freeze without delay and notify.
- Implementation action
- Prevent dealing or asset availability on a true match and notify through the live route.
- Evidence to retain
- Match analysis, restriction time and notification.
- Primary citation
- NCCT Decision 1/2022; MER 2024
Use licences, delisting or release only under written authority.
- Implementation action
- Apply designation-specific procedure and conditions.
- Evidence to retain
- Analysis, permission and release record.
- Primary citation
- NCCT Decision 1/2022
09Records and regulator accessApply the exact sector retention rule.3 items+
Retain CDD and relationship records for at least ten years where CBO rules apply.
- Implementation action
- Run the period from the correct relationship or transaction event and preserve longer holds.
- Evidence to retain
- Schedule, trigger and deletion approval.
- Primary citation
- CBO BM 1187
Retain transaction and wire data for at least ten years under CBO rules.
- Implementation action
- Keep enough information to reconstruct transactions and payment messages.
- Evidence to retain
- Samples, archive and retrieval test.
- Primary citation
- CBO Guidelines 3.2.5
Produce records promptly to authorities.
- Implementation action
- Preserve controlled access, legal holds and production audit trails.
- Evidence to retain
- Access matrix, retrieval and production log.
- Primary citation
- Royal Decree 30/2016
10Privacy, biometrics, breaches, and transfersApply the 2022 law and 2024 regulation subject to scope and exemptions.3 items+
Map processing conditions and transparency.
- Implementation action
- Inventory processing, provide notices, support rights and maintain the processing record and policy.
- Evidence to retain
- Data map, notices, rights and record.
- Primary citation
- Royal Decree 6/2022; Decision 34/2024
Obtain the Article 5 permit when required.
- Implementation action
- Before biometric, genetic, health and other listed sensitive processing, complete the MTCIT permit process unless exempt.
- Evidence to retain
- Classification, permit and conditions.
- Primary citation
- Royal Decree 6/2022 article 5
Control processors, breaches and transfers.
- Implementation action
- Appoint a DPO, contract processors, assess recipient protection and make required notifications.
- Evidence to retain
- Appointment, contracts, assessment and incident record.
- Primary citation
- Decision 34/2024; MTCIT guidance
11Practical evidence packsEvidence must reconstruct decisions end to end.3 items+
Maintain an onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, BO, PEP, sanctions, purpose, risk, privacy and approvals.
- Evidence to retain
- Complete sample and retrieval result.
- Primary citation
- Operational control supporting Royal Decree 30/2016
Maintain NCFI and sanctions case packs.
- Implementation action
- Link activity, suspicion time, report, receipt, confidentiality, restrictions and communications.
- Evidence to retain
- Case pack, timeline and access record.
- Primary citation
- Royal Decree 30/2016; NCCT Decision 1/2022
Maintain a launch and change pack.
- Implementation action
- Record perimeter, licences, reporting, sanctions, privacy, vendors, tests and uncertainties.
- Evidence to retain
- Signed pack, source register and approvals.
- Primary citation
- Official sources listed below
Primary-source register
14 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- AML/CFT Law - Royal Decree 30/2016Central Bank of Oman · Primary legislation and official register
- CBO Instructions implementing Royal Decree 30/2016 - BM 1187Central Bank of Oman · Binding instructions
- AML/CFT Guidelines for Financial InstitutionsCentral Bank of Oman · Official guidance
- Digital Onboarding and e-KYC - BM 1191Central Bank of Oman · Official instructions
- Payment Service Providers Policy - BM 1192Central Bank of Oman · Official licensing policy
- Banking Law 2/2025 and current perimeterCentral Bank of Oman · Primary legislation and official summary
- Virtual Assets and VASPs circularCentral Bank of Oman · Official circular
- AML/CFT portal, NCCT Decision 1/2022 and sanctions guidanceCentral Bank of Oman · Official register
- Personal Data Protection Law - Royal Decree 6/2022MTCIT · Primary legislation
- Personal Data Protection Executive Regulation - Decision 34/2024MTCIT · Primary regulation
- Personal Data Protection guidance and formsMTCIT · Official guidance
- Oman Mutual Evaluation Report 2024FATF / MENAFATF · Authoritative assessment
- FATF increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF call for action - 19 June 2026FATF · Authoritative current status
Direct answers
Oman KYC, KYB and AML questions
Who receives STRs?+
The National Centre for Financial Information receives reports through its current prescribed system.
When must an STR be filed?+
Immediately after suspicion arises. CBO entities must not exceed 48 hours; applicable FSA sectors use 24 hours.
What is the CBO occasional-transaction threshold?+
OMR 5,000 or more, including linked operations. It is a CDD trigger, not a universal report.
What threshold applies to an occasional wire?+
OMR 350 or equivalent under CBO rules, plus required wire information.
How is beneficial ownership determined?+
Identify aggregate interests of 25% or more, then assess control, concert parties and lower holdings; 25% is not a safe harbour.
How long are AML records kept?+
Applicable CBO rules use at least ten years. Confirm the trigger and any longer direction.
Can onboarding be digital?+
Eligible CBO licensees may use BM 1191 and the National Digital Onboarding Registry but remain responsible for accuracy and EDD.
Does biometric KYC need a permit?+
Article 5 data including biometrics requires the MTCIT permit process unless exempt.
Can payment or virtual-asset services be offered?+
Only after confirming the current activity-specific licence or registration path.
Is Oman on a FATF public list?+
No at 19 June 2026, but absence is not a low-risk conclusion.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General information, not legal advice. Reviewed 2 October 2026. Confirm controlling Arabic text, current sector instructions, NCFI filing specifications, beneficial-owner procedure, sanctions directions, privacy permits and licensing with the competent authority and qualified Oman counsel.