Saudi Arabia KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Saudi Arabia.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Direct answer
What does the Saudi Arabia compliance checklist cover?
The Saudi Arabia checklist translates primary KYC, KYB and AML rules into 11 control areas and 39 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Saudi Arabia Financial Intelligence Unit (SAFIU), under the Presidency of State Security
- Primary AML rule
- Anti-Money Laundering Law, Royal Decree M/20 dated 5/2/1439H, and Implementing Regulation
- Suspicion reporting
- Promptly and directly, including attempted transactions and regardless of amount
- Universal threshold
- No single universal CDD or transaction-reporting threshold is stated in the core AML Law
- AML retention
- At least 10 years; specified authorities may require longer retention
- Company BO test
- Resolution 99 applies 25% ownership, then control, then management fallback sequentially
- Privacy authority
- Saudi Data & AI Authority (SDAIA)
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Saudi Arabia compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingIdentify the reporting perimeter and every competent supervisor before onboarding or launch.3 items+
Classify each entity and activity under the national AML perimeter.
- Implementation action
- Determine whether the entity is a financial institution, designated non-financial business or profession, or nonprofit organisation and map its AML, CFT and CPF supervisor.
- Evidence to retain
- Entity map, activity analysis, licence inventory, supervisor confirmation and legal opinion.
- Primary citation
- Anti-Money Laundering Law, Articles 1, 24 and 25; Implementing Regulation, Article 1
Obtain required financial and payment permissions before operating.
- Implementation action
- Classify banking, finance, insurance, securities, payment, electronic-money and technical-support activity and secure the applicable SAMA, CMA or other licence, registration or non-objection.
- Evidence to retain
- Perimeter memorandum, application, licence, conditions, regulator correspondence and renewal calendar.
- Primary citation
- Law of Payments and Payment Services, Royal Decree M/26; Implementing Regulations, Articles 4-7
Do not treat a technical role as exempt without analysis.
- Implementation action
- Where the service supports e-commerce payments, document whether it is limited to linkage and technical support or enters regulated payment execution, custody, settlement or customer-funds activity.
- Evidence to retain
- Service diagram, funds-flow map, contracts, technical permit and regulatory analysis.
- Primary citation
- SAMA Rules for Dealing with E-Commerce Payment Service and Support Providers, Circular 46004436
02Governance and risk assessmentControls must be risk-based, senior-approved, independently tested and responsive to new risks.4 items+
Maintain a documented and current ML risk assessment.
- Implementation action
- Assess customer, country, product, service, transaction, delivery-channel and technology risks and provide the assessment to the supervisor on request.
- Evidence to retain
- Methodology, assessment, source inputs, approvals, residual-risk decisions and remediation plan.
- Primary citation
- Anti-Money Laundering Law, Article 5
Assess new products, practices and technologies before use.
- Implementation action
- Complete and approve a documented assessment before launching remote onboarding, biometrics, automation, new channels or materially changed products.
- Evidence to retain
- Pre-launch assessment, model or vendor validation, controls, approval and monitoring plan.
- Primary citation
- Anti-Money Laundering Law, Article 5; SAMA Circular 472039915
Maintain senior-approved AML policies and accountable management.
- Implementation action
- Cover CDD, reporting, sanctions, records, employee screening, training, group controls and an appropriately senior compliance officer.
- Evidence to retain
- Policy suite, board or senior approval, appointment, authority matrix and reporting packs.
- Primary citation
- Anti-Money Laundering Law, Article 14; Implementing Regulation, Articles 14/1-14/3
Independently test programme effectiveness.
- Implementation action
- Operate risk-based monitoring, ongoing training and an independent audit function; track findings to verified closure.
- Evidence to retain
- Training records, audit plan, samples, findings, owners and closure evidence.
- Primary citation
- Implementing Regulation, Article 14/1
03Natural-person identificationIdentify and verify customers, beneficial owners and representatives using reliable independent material.4 items+
Apply CDD at all core statutory triggers.
- Implementation action
- Perform CDD before a relationship, an occasional transaction, an occasional wire, whenever suspicion exists regardless of amount, and when prior identity information is doubtful; apply any supervisor-set threshold in addition.
- Evidence to retain
- Trigger matrix, aggregation logic, timestamps, customer file and exception log.
- Primary citation
- Implementing Regulation, Article 7/1
Verify the customer from authentic independent evidence.
- Implementation action
- Obtain and verify identity information proportionate to the customer and risk and prohibit anonymous, obviously fictitious-name or numbered accounts.
- Evidence to retain
- Identity copy, independent verification results, authenticity checks and discrepancy log.
- Primary citation
- Anti-Money Laundering Law, Articles 6-7; Implementing Regulation, Articles 7/2-7/3
Verify representatives and their authority.
- Implementation action
- Identify and verify anyone acting for the customer and establish the authenticity and scope of the authority before permitting instructions or access.
- Evidence to retain
- Representative KYC, power or mandate, verification result, limits and activity log.
- Primary citation
- Implementing Regulation, Article 7/2
Do not proceed when CDD cannot be completed.
- Implementation action
- Do not open the account, establish the relationship or execute the transaction; terminate an existing relationship as required and consider an STR. If CDD would tip off the customer, stop that step and report the reason.
- Evidence to retain
- Restriction, exit decision, suspicion assessment, approval and filing receipt.
- Primary citation
- Implementing Regulation, Articles 7/8-7/9
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and actual control; keep AML verification and company filing duties distinct.4 items+
Verify legal-person identity, purpose and authority.
- Implementation action
- Obtain current constitutional and commercial-register information, principal address, business purpose, directors or managers and binding authority from reliable independent sources.
- Evidence to retain
- Commercial-register extract, constitutional pack, licence, officer list, mandates and discrepancy log.
- Primary citation
- Implementing Regulation, Article 7/2
Identify and verify each AML beneficial owner.
- Implementation action
- Trace the natural person who ultimately owns or controls the customer and take reasonable measures to verify identity; for legal arrangements identify the relevant controlling natural persons.
- Evidence to retain
- Layered ownership chart, control analysis, source documents, verified identities and rationale.
- Primary citation
- Implementing Regulation, Article 7/3; SAMA AML/CTF Guide, section 3.17
Apply the current company-register beneficial-owner cascade.
- Implementation action
- Where Resolution 99 applies, identify natural persons owning directly or indirectly at least 25%; only if none, identify control by other means; only if still none, apply the manager, board-member or chairperson fallback.
- Evidence to retain
- Percentage calculations, control analysis, sequential fallback rationale and filing record.
- Primary citation
- Ministerial Resolution 99 dated 5/6/1447H; Ministry of Commerce announcement, 8 December 2025
Maintain and confirm the company beneficial-owner record.
- Implementation action
- Keep the prescribed identity, contact, qualification and nature-and-extent information accurate; disclose and annually confirm it through the current Ministry process and preserve the internal register.
- Evidence to retain
- BO register, reasonable-measures file, submission, annual confirmation and change log.
- Primary citation
- Ministerial Resolution 99 dated 5/6/1447H
05PEPs, EDD, and relianceDetect prominent public functions and strengthen controls where risk requires.3 items+
Identify customers and beneficial owners with prominent public functions.
- Implementation action
- Use risk systems, declarations and reliable sources to identify domestic or foreign prominent public functions and senior international-organisation roles, including relationships covered by the regulation.
- Evidence to retain
- Declaration, screening result, relationship map, rationale and refresh history.
- Primary citation
- Anti-Money Laundering Law, Article 8; Implementing Regulation, Article 8
Apply enhanced measures proportionate to higher risk.
- Implementation action
- Obtain required senior approval, establish source of wealth and source of funds where applicable, and increase ongoing monitoring for higher-risk customers and relationships.
- Evidence to retain
- Risk assessment, approval, source corroboration, monitoring plan and review record.
- Primary citation
- Anti-Money Laundering Law, Articles 7-8; Implementing Regulation, Articles 7/14 and 8
Retain responsibility when relying on a third party.
- Implementation action
- Obtain required CDD information immediately, ensure underlying documents are available without delay, confirm the relied party is regulated and supervised, assess country risk and keep ultimate responsibility.
- Evidence to retain
- Reliance assessment, agreement, information receipt, document test, supervision check and review.
- Primary citation
- Implementing Regulation, Articles 7/10-7/13
06Monitoring and suspicious reportingSuspicious funds and attempts are reported promptly and directly, regardless of amount.4 items+
Monitor relationships and keep CDD current.
- Implementation action
- Scrutinise transactions against customer information, business activity, risk and source of funds where necessary; refresh higher-risk records more frequently.
- Evidence to retain
- Monitoring scenarios, alerts, investigations, refresh schedule and dispositions.
- Primary citation
- Anti-Money Laundering Law, Article 13; Implementing Regulation, Articles 7/6-7/7
Examine complex, unusually large or purposeless patterns.
- Implementation action
- Document the background and purpose of transactions or patterns with no clear economic or legal objective and escalate unresolved suspicion.
- Evidence to retain
- Alert, customer explanation, corroboration, analysis and disposition.
- Primary citation
- Anti-Money Laundering Law, Article 13
Report suspicion and attempted transactions promptly and directly.
- Implementation action
- When suspicion or reasonable grounds concern funds, proceeds or money laundering, regardless of amount, send SAFIU a detailed report with available information and respond promptly to follow-up requests.
- Evidence to retain
- Suspicion chronology, report, submission receipt, acknowledgement and supplemental responses.
- Primary citation
- Anti-Money Laundering Law, Articles 15 and 18
Prevent tipping off and preserve report confidentiality.
- Implementation action
- Restrict access and do not disclose that a report will be, is being or has been filed or that a criminal investigation is underway, except where lawfully permitted.
- Evidence to retain
- Need-to-know matrix, access logs, communication controls, training and incident review.
- Primary citation
- Anti-Money Laundering Law, Article 16
07Payments, wires, thresholds, and agentsPayment permissions, wire data and agent oversight are product- and supervisor-specific.4 items+
Carry required originator and beneficiary information through the payment chain.
- Implementation action
- Obtain and retain prescribed originator and beneficiary data and do not execute a wire when required information cannot be obtained.
- Evidence to retain
- Field matrix, validation logic, sampled transfers, repair queue and rejection record.
- Primary citation
- Anti-Money Laundering Law, Article 10; Implementing Regulation, Article 10
Use the correct payment or electronic-money permission.
- Implementation action
- Map the product to regulated payment services and secure the SAMA licence, registration or other approval before offering, marketing or arranging it in the Kingdom.
- Evidence to retain
- Product classification, licence, conditions, terms, launch approval and renewal calendar.
- Primary citation
- Payments and Payment Services Implementing Regulations, Articles 4-7
Obtain SAMA non-objection before appointing payment agents.
- Implementation action
- Submit the prescribed business plan and agent information, verify required permissions and maintain annual performance and incident reporting.
- Evidence to retain
- Non-objection, due diligence, contract, agent register, annual report and monitoring.
- Primary citation
- Payments and Payment Services Implementing Regulations, Article 24
Obtain SAMA non-objection before material outsourcing.
- Implementation action
- Assess materiality, risks, audit and access rights, continuity and exit; obtain non-objection before contracting a material payment function.
- Evidence to retain
- Outsourcing assessment, regulator non-objection, contract, oversight and exit test.
- Primary citation
- Payments and Payment Services Implementing Regulations, Article 27
08Targeted financial sanctionsUse the current national, UN and supervisory framework; procedures differ by supervised sector.3 items+
Screen relevant parties against current sanctions designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and when applicable lists change.
- Evidence to retain
- List inventory, update logs, screening configuration, tests and dispositions.
- Primary citation
- SAMA Targeted Financial Sanctions Rules, Circular 472035766 dated 7 December 2025
Freeze covered property without delay when a confirmed designation applies.
- Implementation action
- Block covered funds or assets, prevent funds or services being made available and follow the current competent-authority reporting and release procedure without prior notice to the designated person.
- Evidence to retain
- Match analysis, freeze timestamp, ownership-control analysis, asset inventory, report and system blocks.
- Primary citation
- SAMA Targeted Financial Sanctions Rules, Circular 472035766; Law on Combating Terrorism Crimes and Financing
Scope proliferation-sanctions procedures to the relevant sector.
- Implementation action
- Apply SAMA's in-force rules to supervised financial institutions and the Ministry of Commerce guide to dealers in precious metals and stones; do not generalise a sector filing route without authority.
- Evidence to retain
- Sector analysis, applicable rule version, procedure map, training and test case.
- Primary citation
- SAMA Circular 472035766; Ministry of Commerce Guide for Dealers in Precious Metals and Stones, April 2026
09Records and authority accessRecords must reconstruct transactions and remain available for at least ten years.3 items+
Retain transaction and relationship records for at least ten years.
- Implementation action
- Keep domestic, international, commercial and monetary transaction records from transaction completion or account closure and CDD, account, correspondence and analysis material from the relevant statutory trigger.
- Evidence to retain
- Retention schedule, trigger calculations, archive sample, legal holds and deletion controls.
- Primary citation
- Anti-Money Laundering Law, Article 12
Extend retention when lawfully required.
- Implementation action
- Apply Public Prosecution extensions for criminal investigation or prosecution and preserve relevant material under controlled legal hold.
- Evidence to retain
- Authority request, validation, hold notice, affected records and release approval.
- Primary citation
- Anti-Money Laundering Law, Article 12(3)
Reconstruct and promptly produce records.
- Implementation action
- Organise records to reconstruct individual transactions, authenticate official requests and make responsive material readily available while protecting STR confidentiality.
- Evidence to retain
- Request register, authority validation, production index, delivery log and receipt.
- Primary citation
- Anti-Money Laundering Law, Articles 12(4), 18 and 25
10Privacy, biometrics, and transfersIdentity and monitoring data must follow the PDPL, its Implementing Regulation and Transfer Regulation.4 items+
Map scope, purpose and lawful basis for each processing activity.
- Implementation action
- Document the controller or processor role, purpose, statutory or consent basis, notice, source and recipient for identity, screening, monitoring and biometric data.
- Evidence to retain
- Data inventory, role and lawful-basis analysis, notices, consent records and exception register.
- Primary citation
- Personal Data Protection Law, Articles 2, 5-6 and 10-15
Minimise and secure personal and sensitive data.
- Implementation action
- Collect only necessary data, apply purpose limitation, accuracy, access, security and destruction controls, and give sensitive and biometric data heightened safeguards.
- Evidence to retain
- Field justification, security design, access reviews, retention configuration and tests.
- Primary citation
- PDPL; Implementing Regulation, Articles 8, 19 and 23
Govern processors and breaches.
- Implementation action
- Select processors providing sufficient guarantees, include required contract terms, control subprocessors and operate the applicable authority and data-subject breach-notification process.
- Evidence to retain
- Due diligence, contract, subprocessor register, incident assessment, notices and chronology.
- Primary citation
- PDPL Implementing Regulation, Articles 17 and 24
Use a lawful route for transfers outside the Kingdom.
- Implementation action
- Assess national and vital interests, necessity and minimisation; use adequacy, an approved appropriate safeguard or a permitted exception and complete a transfer risk assessment when required.
- Evidence to retain
- Transfer map, legal route, safeguard, risk assessment, approvals and monitoring.
- Primary citation
- PDPL, Article 29; Regulation on Personal Data Transfer Outside the Kingdom, Articles 2-8
11Practical evidence packsEvidence should reproduce onboarding, monitoring and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, PEP and sanctions screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting Anti-Money Laundering Law, Articles 7-8 and 12
Maintain a reconstructable reporting and sanctions pack.
- Implementation action
- Link transactions, alerts, analysis, timing, report, acknowledgement, supplements, freeze actions, authority communications and access logs.
- Evidence to retain
- Complete sampled case pack and controlled access log.
- Primary citation
- Operational control supporting Anti-Money Laundering Law, Articles 15-18 and applicable TFS rules
Maintain a regulator-scoped launch pack.
- Implementation action
- Record activity classification, licences, current legal sources, filing readiness, ownership duties, sanctions procedure, privacy analysis, vendor controls and validation before launch and material change.
- Evidence to retain
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Primary citation
- Official sources listed below
Primary-source register
17 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering Law and Implementing RegulationSaudi Central Bank Rulebook · Primary legislation and official regulation
- Law on Combating Terrorism Crimes and Financing and Implementing RegulationsSaudi Central Bank Rulebook · Primary legislation and official regulation
- AML/CTF Guide for SAMA-supervised financial institutionsSaudi Central Bank Rulebook · Official supervisory guidance
- Guidance on assessing ML, TF and PF business risksSaudi Central Bank Rulebook · Official in-force circular
- Targeted Financial Sanctions Rules, Circular 472035766Saudi Central Bank Rulebook · Official in-force rules
- Targeted-financial-sanctions guide for dealers in precious metals and stonesMinistry of Commerce · Official sector guidance
- Beneficial Ownership Rules approved by Resolution 99Ministry of Commerce · Official binding rules
- Ministry announcement of Resolution 99 and sequential BO criteriaMinistry of Commerce · Official explanatory announcement
- Ministry guidance on BO confirmation and register accessMinistry of Commerce · Official explanatory announcement
- Implementing Regulations of Payments and Payment Services LawSaudi Central Bank Rulebook · Official in-force regulation
- Rules for e-commerce payment service and support providersSaudi Central Bank Rulebook · Official in-force rules
- Personal Data Protection LawSaudi Data & AI Authority · Primary legislation
- PDPL Implementing Regulation and Transfer RegulationSaudi Data & AI Authority · Official regulations
- Saudi Arabia mutual evaluationFATF · Authoritative assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Saudi Arabia KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Saudi Arabia Financial Intelligence Unit (SAFIU), the national central agency under the Presidency of State Security. Use the current authorised reporting channel for the entity's sector.
When must suspicion be reported?+
Promptly and directly when suspicion or reasonable grounds concern criminal proceeds or money laundering, including attempted transactions and regardless of amount. Do not wait for proof or a monetary threshold.
Is there one universal CDD threshold?+
No single universal monetary threshold is stated in the core AML Law for all sectors. CDD applies at statutory triggers, and sector supervisors may prescribe additional thresholds or rules.
How is beneficial ownership determined?+
For AML CDD, identify and verify the natural person who ultimately owns or controls the customer. Separately, Resolution 99 applies a sequential company-register test: at least 25% ownership, then control by other means, then a management fallback.
How long are AML records retained?+
At least ten years under Article 12 of the AML Law. The Public Prosecution may require longer retention for an investigation or prosecution.
What happens on a sanctions match?+
Apply the current list and sector rule, confirm identifiers, freeze covered property without delay where required, prevent prohibited availability, report through the competent route and release only under verified authority.
Does a payment business need SAMA permission?+
Regulated payment services and payment-system operation require the applicable SAMA licence or approval. Agents and material outsourcing also trigger prior non-objection requirements under the implementing regulations.
Is Saudi Arabia on a FATF public list?+
No. Saudi Arabia was absent from both FATF public lists dated 19 June 2026. That does not make a customer, product or transaction low risk.
What privacy rules apply to KYC data?+
The PDPL, its Implementing Regulation and Transfer Regulation govern scope, lawful processing, security, processors, breaches, destruction and overseas transfers, subject to any applicable sector rule.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 16 September 2026. Confirm the controlling Arabic text, later amendments, sector circulars, SAFIU filing mechanics, sanctions-list procedures, Ministry of Commerce filing workflow and product-specific SAMA or CMA requirements with the competent authority and qualified Saudi counsel before launch.