Vietnam KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Vietnam.
- Last reviewed
- Last reviewed:
- Version
- Version 1.1

Portable implementation guide
Get the PDF checklist
11 control areas · 38 implementation checks
Last reviewed: 27 September 2026 · Version 1.1
Download the checklistDirect answer
What does the Vietnam compliance checklist cover?
The Vietnam checklist translates primary KYC, KYB and AML rules into 11 control areas and 38 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Anti-Money Laundering Department within the State Bank of Vietnam
- Primary AML rules
- Law 14/2022/QH15, Decree 19/2023/ND-CP and Circular 27/2025/TT-NHNN
- STR timing
- Within 3 working days from the transaction or 1 working day from detecting suspicion, whichever is earlier
- Large-value report
- Transactions of VND 400 million or more under the current general threshold rule
- Wire reports
- Domestic transfers from VND 500 million; international transfers from USD 1,000 equivalent
- AML records
- Generally 5 years from the applicable transaction, closure or report trigger
- Privacy framework
- Personal Data Protection Law 91/2025/QH15 and Decree 356/2025/ND-CP apply from 1 January 2026
- FATF public lists
- Under increased monitoring at 19 June 2026
Implementation detail
Vietnam compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the entity, activity and competent supervisor before applying any control or threshold.3 items+
Determine whether each activity is performed by a reporting entity.
- Implementation action
- Map licensed financial activities and the listed non-financial businesses and professions to Article 4, including relevant gaming, real-estate, precious-metal and stone, accounting, notarial, legal and company-service activity; document exclusions and supervisor.
- Evidence to retain
- Entity chart, product and funds-flow inventory, perimeter memorandum, source extracts and counsel sign-off.
- Primary citation
- Law 14/2022/QH15, Article 4
Obtain every sector licence, registration or approval before launch.
- Implementation action
- Confirm State Bank, securities, insurance, gaming, foreign-exchange, payment and other competent-authority requirements for the actual service and delivery model.
- Evidence to retain
- Perimeter analysis, application, licence or registration, conditions, regulator correspondence and renewal calendar.
- Primary citation
- Applicable sector law; Decree 52/2024/ND-CP for non-cash payment services
Maintain current AML reporting access and accountable contacts.
- Implementation action
- Register required contacts and reporting users with the AML Department, test the current electronic route and protect credentials and signing authority.
- Evidence to retain
- Registration, user inventory, access test, delegation, contact-change notice and continuity plan.
- Primary citation
- Law 14/2022/QH15, Articles 24 and 37; Circular 27/2025/TT-NHNN
02Governance and ML/TF/PF risk assessmentThe programme must be risk-based, approved, resourced and independently tested.3 items+
Maintain a documented institutional risk assessment.
- Implementation action
- Assess customers, countries, products, services, transactions, channels, technology, agents and outsourcing; complete the annual update by 31 March for the preceding calendar year and refresh before material change.
- Evidence to retain
- Methodology, data set, assessment, scoring, approval, residual-risk decisions and remediation plan.
- Primary citation
- Law 14/2022/QH15, Articles 15-16; Circular 27/2025/TT-NHNN, Articles 3-4
Maintain approved internal AML rules and accountable governance.
- Implementation action
- Assign senior responsibility and a competent AML function; document CDD, monitoring, reporting, sanctions, records, training and escalation and send current internal rules to the competent authority within the applicable period.
- Evidence to retain
- Approved rules, appointments, submission receipt, committee minutes, training and issue log.
- Primary citation
- Law 14/2022/QH15, Article 24; Circular 27/2025/TT-NHNN, Article 5
Independently test design and operating effectiveness.
- Implementation action
- Use a risk-based audit scope to sample customer files, ownership, reporting clocks, sanctions, data quality and remediation; submit the annual internal-audit report where required.
- Evidence to retain
- Audit plan, independence record, samples, report, submission receipt and closure tests.
- Primary citation
- Law 14/2022/QH15, Article 24; Circular 27/2025/TT-NHNN, Article 5
03Natural-person identificationCDD applies at relationship, relevant occasional-transaction, suspicion and prior-data-doubt triggers.4 items+
Identify and verify natural-person customers.
- Implementation action
- Collect prescribed identity information and verify it from reliable independent documents, data or electronic-identification sources; resolve discrepancies and prohibit anonymous or false-name relationships.
- Evidence to retain
- Customer record, identity evidence, verification source, timestamp and discrepancy resolution.
- Primary citation
- Law 14/2022/QH15, Articles 9-12
Apply the correct CDD trigger and aggregation rule.
- Implementation action
- Configure relationship opening, occasional transactions, suspicion and doubt about existing data. For a customer without an active transactional history, apply the current VND 400 million same-day identification trigger only within its stated scope and exclusions.
- Evidence to retain
- Trigger matrix, linked-transaction logic, tested scenarios, rule version and exceptions.
- Primary citation
- Law 14/2022/QH15, Article 9; Circular 27/2025/TT-NHNN, Article 5
Verify representatives and authority.
- Implementation action
- Identify and verify each person acting for a customer and establish the mandate, legal representative status and limits before accepting instructions or access.
- Evidence to retain
- Representative KYC, authority instrument, verification, scope limits and activity log.
- Primary citation
- Law 14/2022/QH15, Articles 10-12
Control failed CDD and tipping-off risk.
- Implementation action
- When required CDD cannot be completed, refuse, suspend or end the relationship or transaction as the governing rule requires, assess an STR and prevent disclosure that could prejudice reporting or investigation.
- Evidence to retain
- CDD gap, restriction or exit decision, approval, suspicion assessment and filing evidence.
- Primary citation
- Law 14/2022/QH15, Articles 9, 13 and 40
04KYB, registries, and beneficial ownershipVerify legal existence, authorised persons and natural-person ownership or control; registry data supports but does not replace AML analysis.4 items+
Verify every legal person or arrangement.
- Implementation action
- Obtain current National Business Registration Portal or other competent-registry evidence, constitutional documents, purpose, address, legal representatives, controllers and authority information.
- Evidence to retain
- Registry extract, constitutional documents, licences, mandates and discrepancy log.
- Primary citation
- Law 14/2022/QH15, Articles 10-12; Law on Enterprises, as amended by Law 76/2025/QH15
Identify and verify beneficial owners through ownership and control.
- Implementation action
- Trace the chain to natural persons, assess actual ownership and control and document the prescribed fallback analysis; do not treat nominees or a registry filing as conclusive.
- Evidence to retain
- Ownership chart, calculations, registry evidence, control analysis, verified identities and fallback rationale.
- Primary citation
- Law 14/2022/QH15, Articles 3, 10-12; Decree 19/2023/ND-CP
Identify relevant trust and arrangement parties.
- Implementation action
- Identify and verify settlors, trustees or equivalents, protectors where relevant, beneficiaries or classes and every natural person exercising ultimate effective control.
- Evidence to retain
- Trust instrument, party schedule, control powers, entitlement analysis and verified identities.
- Primary citation
- Law 14/2022/QH15, Articles 10-12; Decree 19/2023/ND-CP
Make and maintain corporate beneficial-owner filings.
- Implementation action
- For enterprises subject to the amended Enterprise Law, collect, retain and declare beneficial-owner information from 1 July 2025 and update it through the current business-registration process; reconcile it to AML CDD.
- Evidence to retain
- BO register, filing, portal receipt, change log, reconciliation and discrepancy escalation.
- Primary citation
- Law 76/2025/QH15; Decree 168/2025/ND-CP; Circular 68/2025/TT-BTC
05PEPs, enhanced due diligence, and remote onboardingPolitical exposure, higher risk and non-face-to-face delivery require stronger measures.3 items+
Identify politically exposed persons and relevant relationships.
- Implementation action
- Screen customers and beneficial owners for foreign PEP status and applicable related persons under the current framework; apply risk-sensitive refresh and escalation.
- Evidence to retain
- Screening result, source, relationship map, rationale and refresh history.
- Primary citation
- Law 14/2022/QH15, Article 17
Apply enhanced due diligence to high-risk customers.
- Implementation action
- Obtain approval at least one management level above the ordinary approval level, gather and verify additional income, business, source-of-funds or source-of-assets information and increase monitoring and refresh frequency.
- Evidence to retain
- Risk trigger, approval, additional verification, enhanced plan and periodic reviews.
- Primary citation
- Law 14/2022/QH15, Article 16; Circular 27/2025/TT-NHNN, Article 4
Control remote and electronic identification.
- Implementation action
- Validate identity, document authenticity, liveness, impersonation and device risk; preserve the electronic-identification method, result and exception handling required by the applicable sector rule.
- Evidence to retain
- Method assessment, fraud tests, vendor diligence, verification result and exception log.
- Primary citation
- Law 14/2022/QH15, Articles 11-12; applicable State Bank electronic-KYC rules
06Monitoring and suspicious transaction reportingMonitor expected activity and report suspicion to the State Bank AML Department without waiting for a monetary threshold.4 items+
Conduct ongoing due diligence and transaction monitoring.
- Implementation action
- Keep identity, ownership and risk information current and scrutinise activity against purpose, profile, capacity and source of funds; investigate deviations promptly.
- Evidence to retain
- Monitoring scenarios, alerts, case analysis, refresh history and dispositions.
- Primary citation
- Law 14/2022/QH15, Articles 13, 16 and 20
Detect suspicious transactions and attempts regardless of amount.
- Implementation action
- Map statutory suspicion indicators and attempted or incomplete activity, record when suspicion was detected and escalate immediately to the authorised decision-maker.
- Evidence to retain
- Alert chronology, indicator mapping, analysis, decision and supporting records.
- Primary citation
- Law 14/2022/QH15, Articles 26-36
File STRs within the statutory earlier-of clock.
- Implementation action
- Submit through the current authorised route within three working days from the transaction or one working day from detecting suspicion, whichever is earlier; report suspected criminal activity promptly to the competent state authority as required.
- Evidence to retain
- Transaction time, detection time, decision, report, acknowledgement and supplement log.
- Primary citation
- Law 14/2022/QH15, Article 37; Circular 27/2025/TT-NHNN, Article 7
Protect reporting confidentiality.
- Implementation action
- Restrict STR and authority-request information to authorised need-to-know access and legally review disclosures and customer communications.
- Evidence to retain
- Access matrix, disclosure log, legal review, training and incident record.
- Primary citation
- Law 14/2022/QH15, Article 40
07Threshold reports, wires, payments, and virtual assetsReporting thresholds, transfer data and licensing must be kept distinct.4 items+
Report large-value transactions at the current threshold.
- Implementation action
- Identify and report transactions at or above VND 400 million under the current general rule, apply aggregation and exclusions correctly and send electronic reports before 16:00 on the next working day.
- Evidence to retain
- Threshold matrix, transaction data, aggregation tests, report and acknowledgement.
- Primary citation
- Law 14/2022/QH15, Article 25; Decision 11/2023/QD-TTg; Circular 27/2025/TT-NHNN, Articles 6 and 10
Report qualifying electronic transfers and preserve required data.
- Implementation action
- Report domestic electronic transfers from VND 500 million and international electronic transfers from USD 1,000 equivalent; retain required originator, beneficiary, institution and transaction fields and handle incomplete data under the risk procedure.
- Evidence to retain
- Transfer-field matrix, messages, screening, report, exception decision and acknowledgement.
- Primary citation
- Law 14/2022/QH15, Article 34; Circular 27/2025/TT-NHNN, Articles 8-10
Obtain permission for regulated payment activity.
- Implementation action
- Map account, wallet, switching, clearing, collection, payment-support and other non-cash payment functions to Decree 52 and current State Bank rules; launch only after the required licence or approval.
- Evidence to retain
- Service map, legal analysis, application, licence, conditions and agent inventory.
- Primary citation
- Decree 52/2024/ND-CP and current State Bank implementing rules
Do not assume virtual-asset activity is licensed or AML-covered.
- Implementation action
- Obtain current Vietnamese advice before offering exchange, custody, transfer, brokerage or issuance. Treat FATF's June 2026 finding that Vietnam still needs effective VASP regulation as a launch and risk-control warning.
- Evidence to retain
- Activity analysis, legal opinion, regulator correspondence, product restriction and change-monitoring record.
- Primary citation
- FATF Vietnam action plan, 19 June 2026; APG Vietnam follow-up reports
08Targeted financial sanctionsControls must detect listed persons, ownership and control and support immediate legally required action.3 items+
Screen relevant persons and transactions against current lists.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and when UN or Vietnamese lists change; assess indirect ownership and control.
- Evidence to retain
- List inventory, update log, configuration test, match analysis and disposition.
- Primary citation
- Law on Prevention and Combat of Terrorism; Decree 122/2013/ND-CP; applicable PF rules
Apply freezing, suspension and reporting measures through the verified route.
- Implementation action
- On a true match, prevent prohibited dealing or availability, preserve property and follow the competent authority's current suspension, freezing, reporting, exemption and release direction without delay.
- Evidence to retain
- Match analysis, action timestamp, report, system blocks and authority correspondence.
- Primary citation
- Law 14/2022/QH15, Articles 44-46; Law on Prevention and Combat of Terrorism
Maintain distinct TF and PF procedures.
- Implementation action
- Map designation, screening, action, reporting, exemption, delisting and release routes for terrorism and proliferation financing and test ownership/control and evasion scenarios.
- Evidence to retain
- Legal map, procedures, list-update record, scenario tests and escalation log.
- Primary citation
- Law 14/2022/QH15; Law on Prevention and Combat of Terrorism; FATF Vietnam action plan
09Records and regulator accessRecords must reconstruct identity, ownership, transactions, reports and decisions from the correct trigger.3 items+
Retain AML records for the applicable five-year period.
- Implementation action
- Apply the five-year minimum from transaction completion, account closure, relationship termination or report date as applicable, and preserve longer for an active authority request, investigation or legal hold.
- Evidence to retain
- Retention schedule, trigger calculations, archive samples, holds and deletion approvals.
- Primary citation
- Law 14/2022/QH15, Article 38
Preserve reconstructable and secure evidence.
- Implementation action
- Link identity, ownership, risk, instructions, transaction data, alerts, reports, sanctions actions, approvals and communications under stable identifiers with controlled access.
- Evidence to retain
- Sample case pack, lineage report, retrieval test and access log.
- Primary citation
- Law 14/2022/QH15, Articles 38-40
Provide information securely to authenticated authorities.
- Implementation action
- Validate the requesting authority, preserve confidentiality and record the scope, approval, material produced and delivery route.
- Evidence to retain
- Request register, authority validation, production index, approval and receipt.
- Primary citation
- Law 14/2022/QH15, Articles 39-40 and Chapter III
10Personal data, biometrics, and transfersAML processing remains subject to Vietnam's current personal-data and cybersecurity framework.4 items+
Document the legal basis, notice and proportionality of KYC processing.
- Implementation action
- Map identity, biometric, screening and monitoring fields to a valid processing ground, give required notices, minimise collection and maintain accuracy, purpose and data-subject-rights controls.
- Evidence to retain
- Data inventory, legal-basis map, notices, consent where relied upon, field justification and rights procedure.
- Primary citation
- Personal Data Protection Law 91/2025/QH15; Decree 356/2025/ND-CP
Apply enhanced controls to sensitive personal data.
- Implementation action
- Classify biometric, financial and other sensitive KYC data under the current law; assign responsibility and apply risk-appropriate access, security, processor and accountability controls.
- Evidence to retain
- Classification, responsibility map, access review, security tests, vendor terms and training.
- Primary citation
- Personal Data Protection Law 91/2025/QH15; Decree 356/2025/ND-CP
Maintain the required personal-data risk and impact records.
- Implementation action
- Assess processing and transfer risks before deployment and keep the current dossiers, supporting evidence and competent-authority submissions required for the entity's processing scale and role.
- Evidence to retain
- Processing map, risk and impact records, submission analysis, receipts, approvals and review log.
- Primary citation
- Personal Data Protection Law 91/2025/QH15, Articles 21-23 and 33; Decree 356/2025/ND-CP
Control incidents, processors and cross-border transfers.
- Implementation action
- Maintain detection, containment, evidence, notification and remediation procedures using the current statutory triggers and routes; contractually control processors and document cross-border recipients, purpose, safeguards and onward transfers.
- Evidence to retain
- Incident procedure, chronology, notices where required, vendor contracts, transfer map and monitoring.
- Primary citation
- Personal Data Protection Law 91/2025/QH15; Decree 356/2025/ND-CP
11Practical evidence packsEvidence should reproduce onboarding, reporting, sanctions and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, representative authority, KYB, ownership and control, PEP and sanctions screening, risk, approvals, privacy records and exceptions.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting Law 14/2022/QH15, Articles 9-24
Maintain a reconstructable reporting and sanctions pack.
- Implementation action
- Link transactions, alerts, detection and decision times, report, acknowledgement, supplements, suspension or freeze actions, authority communications and access logs.
- Evidence to retain
- Complete sampled case pack, timeline and controlled access log.
- Primary citation
- Operational control supporting Law 14/2022/QH15, Articles 25-46
Maintain a regulator-scoped launch pack.
- Implementation action
- Record perimeter, permissions, current sources, reporting readiness, ownership analysis, sanctions, privacy transfers, outsourcing, virtual-asset restrictions and validation before launch or material change.
- Evidence to retain
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Primary citation
- Official sources listed below
Primary-source register
18 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law No. 14/2022/QH15 on Anti-Money LaunderingNational Legal Database / State Bank of Vietnam · Primary legislation
- Decree No. 19/2023/ND-CP implementing the AML LawNational Legal Database · Primary regulation
- Circular No. 27/2025/TT-NHNN implementing the AML LawState Bank of Vietnam / National Legal Database · Official regulation
- Circular No. 27/2025/TT-NHNN operative textState Bank of Vietnam / National Legal Database · Official regulation
- Decision No. 11/2023/QD-TTg on the large-value transaction thresholdGovernment of Vietnam / National Legal Database · Primary regulation
- Law on Prevention and Combat of TerrorismNational Legal Database / State Bank of Vietnam · Primary legislation
- Personal Data Protection Law No. 91/2025/QH15Government Gazette of Vietnam · Primary legislation
- Decree No. 356/2025/ND-CP implementing the Personal Data Protection LawNational Legal Database · Primary regulation
- Law No. 76/2025/QH15 amending the Law on EnterprisesNational Business Registration Portal · Primary legislation
- Official 2026 implementation guidance on enterprise beneficial ownersNational Business Registration Portal · Official registry guidance
- Decree No. 52/2024/ND-CP on non-cash paymentsState Bank of Vietnam · Primary regulation
- Vietnam 2022 mutual evaluation reportAsia/Pacific Group on Money Laundering · Authoritative assessment
- Vietnam first follow-up reportAsia/Pacific Group on Money Laundering · Authoritative assessment
- Vietnam second follow-up reportAsia/Pacific Group on Money Laundering · Authoritative assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- FATF Vietnam country profileFATF · Authoritative country status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Vietnam KYC, KYB and AML questions
Who receives AML transaction reports?+
The State Bank of Vietnam's Anti-Money Laundering Department through the current authorised reporting route.
When must an STR be filed?+
Within three working days from the suspicious transaction or one working day from detecting suspicion, whichever is earlier. Preserve both timestamps and escalate suspected criminal activity as required.
What is the general large-value transaction threshold?+
VND 400 million under the current general threshold rule. Apply aggregation, exclusions and any sector-specific requirements separately.
What electronic transfers are reported?+
Under Circular 27/2025, domestic electronic transfers from VND 500 million and international electronic transfers from USD 1,000 equivalent are reportable, subject to stated exclusions.
Is there one universal CDD threshold?+
No. Relationship opening, suspicion and doubt about prior information can trigger CDD without an amount; occasional-transaction rules and sector requirements must be applied in their exact scope.
How is beneficial ownership determined?+
Trace actual ownership and control to natural persons and document the prescribed fallback analysis. Enterprise-register disclosure from July 2025 supports but does not replace AML CDD.
How long are AML records retained?+
Generally five years, but the clock starts from the applicable transaction, account closure, relationship termination or report date. Active matters may require longer preservation.
Can a payment service launch without State Bank permission?+
No. Map the exact service to Decree 52/2024 and current implementing rules and obtain the required licence or approval before launch.
Can a virtual-asset service assume it has a Vietnamese licence route?+
No. FATF still identified effective VASP regulation as an outstanding action in June 2026. Obtain current Vietnamese advice and competent-authority confirmation before offering a service.
What happens on a sanctions match?+
Confirm identifiers and ownership or control, prevent prohibited dealing, apply the competent authority's suspension or freezing direction without delay and report through the verified route.
Is Vietnam on a FATF public list?+
Yes. Vietnam remained under increased monitoring on 19 June 2026, and FATF strongly urged swift completion of its overdue action plan. This calls for proportionate risk measures, not automatic de-risking.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 27 September 2026. Vietnamese-language instruments control. Confirm the reporting-entity perimeter, current AML Department filing specifications, sector permissions, sanctions directions, virtual-asset regime and personal-data requirements with the competent authority and qualified Vietnamese counsel before launch.