Bahreïn KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Bahreïn.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Guide d’implémentation portable
Obtenir la checklist PDF
11 domaines de contrôle · 41 contrôles d’implémentation
Dernière revue: 30 September 2026 · Version 1.0
Télécharger la checklistRéponse directe
Que couvre la checklist de conformité pour Bahreïn ?
La checklist pour Bahreïn traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 41 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML law
- Legislative Decree No. 4 of 2001, as amended through 2025
- FIU and reporting
- National Financial Intelligence Centre; CBB licensees use the Online STR system under current rules
- STR timing
- Immediately upon suspicion, including attempted transactions, regardless of value
- CBB occasional-transaction CDD
- Above BHD 6,000, including linked transactions; wire transfers trigger CDD irrespective of amount in banking modules
- AML retention
- At least 5 years; the statutory start event depends on record class
- Commercial-register UBO
- 10% ownership or voting control is one criterion; effective control and other influence tests also apply
- Privacy
- Law No. 30 of 2018 on Personal Data Protection and implementing decisions
- FATF public lists
- Not listed at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Bahreïn
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingClassify the entity, activity and supervisory rulebook before assigning controls.3 éléments+
Determine whether each activity is an institution or otherwise subject to the AML law.
- Action d’implémentation
- Map services, customers and Bahrain nexus to Legislative Decree No. 4 of 2001, current amendments, CBB licensing categories and the applicable DNFBP order.
- Preuves à conserver
- Perimeter memo, service and funds-flow maps, legal analysis and authority confirmation.
- Source primaire
- Legislative Decree No. 4 of 2001, articles 1, 4 and 5; applicable competent-authority rules
Obtain each required CBB or sector licence before activity.
- Action d’implémentation
- Classify banking, investment, insurance, payment, remittance, exchange, crypto-asset and other regulated services and secure approval before launch.
- Preuves à conserver
- Licence matrix, applications, approvals, conditions register and renewal calendar.
- Source primaire
- CBB and Financial Institutions Law 2006; applicable CBB Rulebook volume
Apply the correct Financial Crime module and current version.
- Action d’implémentation
- Identify the CBB volume for the licence category, track module amendments and document any sector-specific departures rather than copying controls across volumes.
- Preuves à conserver
- Rulebook inventory, change log, compliance mapping and governance approval.
- Source primaire
- CBB Rulebook Financial Crime modules, current version
02Governance and ML/TF/PF risk assessmentGovernance must address money laundering, terrorist financing and proliferation-financing risk.4 éléments+
Maintain a documented enterprise risk assessment.
- Action d’implémentation
- Assess customers, countries, products, delivery channels, transactions, technology, sanctions and emerging risks and update for material change and national findings.
- Preuves à conserver
- Methodology, current assessment, data sources, approvals, residual-risk decisions and change log.
- Source primaire
- Legislative Decree No. 4 of 2001, articles 4-5; CBB FC risk-based approach requirements
Maintain proportionate AML/CFT/CPF policies and controls.
- Action d’implémentation
- Document CDD, monitoring, reporting, recordkeeping, sanctions, employee screening, training, group controls, independent review and escalation.
- Preuves à conserver
- Approved framework, control map, procedures, training and issue register.
- Source primaire
- Legislative Decree No. 4 of 2001, article 5; applicable CBB FC module
Appoint an approved and empowered MLRO.
- Action d’implémentation
- Appoint a suitably senior Bahrain-resident MLRO and deputy where the rulebook requires; preserve independence, resources, unrestricted information access and direct board escalation.
- Preuves à conserver
- CBB approval, appointment, fit-and-proper file, authority matrix and board reporting.
- Source primaire
- Applicable CBB FC module, MLRO chapter
Conduct independent compliance review and remediate findings.
- Action d’implémentation
- Test design and operation at the required frequency using an independent and competent function; report results and verify closure.
- Preuves à conserver
- Review plan, independence assessment, report, management response and closure testing.
- Source primaire
- Applicable CBB FC compliance-monitoring and audit requirements
03Natural-person identificationCDD covers the customer, beneficial owner and each authorised representative.5 éléments+
Apply CDD before a relationship and when a statutory or rulebook trigger arises.
- Action d’implémentation
- Identify and verify the customer before establishment, and refresh for material changes, doubts, suspicion, covered occasional transactions and transfers under the applicable module.
- Preuves à conserver
- Trigger analysis, identity record, verification result, purpose and completion timestamp.
- Source primaire
- Legislative Decree No. 4 of 2001, articles 4-5; CBB FC-1
Apply the BHD 6,000 CBB occasional-transaction trigger in its proper scope.
- Action d’implémentation
- For banking modules, apply CDD above BHD 6,000 and aggregate linked transactions; apply the exact current module for other licensees and do not treat the amount as a universal threshold report.
- Preuves à conserver
- Aggregation logic, transaction samples, module mapping and CDD outcomes.
- Source primaire
- CBB FC-1.1.2 and corresponding current module provisions
Verify identity from reliable, independent evidence.
- Action d’implémentation
- Obtain official identity attributes and validate authenticity, expiry, address where required and person-to-document linkage using risk-sensitive methods.
- Preuves à conserver
- Identity attributes, source provenance, validation result, fraud checks and exceptions.
- Source primaire
- CBB FC-1 customer identification and verification requirements
Identify representatives and validate authority.
- Action d’implémentation
- Identify and verify persons acting for the customer and confirm their legal mandate before accepting instructions.
- Preuves à conserver
- Representative KYC, mandate, authority checks and instruction limits.
- Source primaire
- CBB FC-1; applicable sector order
Do not proceed when required CDD cannot be completed.
- Action d’implémentation
- Decline or terminate as the applicable rule requires, restrict activity and consider an STR without tipping off.
- Preuves à conserver
- CDD failure record, restriction or exit decision, STR assessment and communications review.
- Source primaire
- CBB FC-1 and suspicious-reporting provisions
04KYB, registry, and beneficial ownershipRegistry disclosure and AML beneficial-ownership analysis are related but distinct.5 éléments+
Verify the legal person or arrangement and its powers.
- Action d’implémentation
- Collect current legal name, form, commercial registration, address, governing documents, directors, partners or trustees and validate against SIJILAT or other reliable sources.
- Preuves à conserver
- Registry extract, constitutional documents, officer list and discrepancy resolution.
- Source primaire
- CBB FC-1; Commercial Companies Law; MOIC registry guidance
Identify natural persons with ultimate ownership or effective control.
- Action d’implémentation
- Trace layered, nominee and legal-arrangement structures to natural persons who ultimately own, control or benefit and to persons on whose behalf activity occurs.
- Preuves à conserver
- Ownership chart, control analysis, declarations, source documents and verified identities.
- Source primaire
- CBB Rulebook definition of beneficial owner, amended June 2025
Identify trust and legal-arrangement parties.
- Action d’implémentation
- Identify settlors, trustees, protectors, beneficiaries or classes and any other natural person exercising ultimate effective control; look through legal-person trustees.
- Preuves à conserver
- Trust deed, party schedule, powers analysis, ownership look-through and verification.
- Source primaire
- CBB Rulebook beneficial-owner definition, June 2025
Apply the MOIC UBO disclosure criteria without reducing them to one percentage.
- Action d’implémentation
- Treat direct or indirect ownership or voting control of at least 10% as one criterion and assess effective control, decision influence, financing, family or contractual relationships and management powers.
- Preuves à conserver
- UBO analysis, calculation, control evidence, filing and update receipts.
- Source primaire
- Ministerial Order No. 83 of 2020, article 3
Keep commercial-register UBO information current.
- Action d’implémentation
- File required UBO information at registration and update changes through the current MOIC/SIJILAT process; retain evidence of submissions and discrepancy resolution.
- Preuves à conserver
- UBO register, SIJILAT filings, change log, notices and remediation.
- Source primaire
- Ministerial Order No. 83 of 2020; MOIC business-services guidance
05PEPs, EDD, and remote onboardingEnhanced measures attach to specified and higher-risk circumstances.3 éléments+
Identify PEPs, family members and close associates.
- Action d’implémentation
- Screen customers and beneficial owners for domestic, foreign and international-organisation PEP exposure and apply senior approval, source-of-wealth, source-of-funds and enhanced monitoring controls.
- Preuves à conserver
- Screening, relationship map, approval, source corroboration and review history.
- Source primaire
- Applicable CBB FC enhanced-CDD and PEP provisions
Apply enhanced due diligence to higher-risk relationships.
- Action d’implémentation
- Obtain additional information on customer, ownership, purpose, source of wealth and funds; increase monitoring and document acceptance or continuation decisions.
- Preuves à conserver
- Risk trigger, additional CDD, source evidence, approval and monitoring plan.
- Source primaire
- CBB FC-1 enhanced CDD; FATF high-risk-country measures
Control non-face-to-face and technology risk.
- Action d’implémentation
- Validate document authenticity and liveness, detect impersonation, test vendors, preserve manual fallback and apply stronger measures when residual risk is elevated.
- Preuves à conserver
- Method assessment, vendor diligence, testing, exceptions and fraud cases.
- Source primaire
- CBB FC non-face-to-face and new-technology provisions
06Monitoring and suspicious transaction reportingOngoing scrutiny and immediate escalation support reporting to the NFIC.4 éléments+
Keep CDD current and monitor activity on a risk basis.
- Action d’implémentation
- Examine transactions against purpose, profile, expected behaviour and risk; investigate significant, abnormal or unexplained activity and document source-of-funds work.
- Preuves à conserver
- Monitoring scenarios, alerts, case decisions, refresh records and quality testing.
- Source primaire
- CBB FC-2 ongoing CDD and transaction monitoring
Escalate suspicion without waiting for proof or transaction completion.
- Action d’implémentation
- Assess completed, attempted and proposed activity promptly and record the facts, grounds and timestamp at which suspicion was formed.
- Preuves à conserver
- Alert chronology, information reviewed, suspicion decision and decision-maker.
- Source primaire
- Legislative Decree No. 4 of 2001, articles 4-5, as amended in 2020
Report suspicious transactions immediately, regardless of value.
- Action d’implémentation
- The MLRO must submit complete reports through the current Online STR system to the NFIC and follow any parallel CBB notification required by the applicable module.
- Preuves à conserver
- Suspicion timestamp, STR, system receipt, CBB notice and correction record.
- Source primaire
- Legislative Decree No. 4 of 2001, article 5(c); CBB FC external-reporting provisions
Prevent tipping off and protect STR information.
- Action d’implémentation
- Restrict report knowledge, control customer and third-party communications and disclose only where legally permitted.
- Preuves à conserver
- Access controls, disclosure register, legal review, training and incident log.
- Source primaire
- AML law and applicable CBB FC confidentiality provisions
07Payments, wires, thresholds, and crypto-assetsPayment and crypto services require activity-specific CBB licensing and transfer controls.4 éléments+
Carry and validate required wire-transfer information.
- Action d’implémentation
- Collect, transmit and retain prescribed originator and beneficiary information and establish risk-based procedures for missing, incomplete or suspect fields.
- Preuves à conserver
- Field matrix, message samples, validation rules, repair queue and dispositions.
- Source primaire
- Applicable CBB FC wire-transfer provisions
Apply CDD to wire transfers under the applicable module.
- Action d’implémentation
- For banking modules, apply CDD irrespective of amount; where a specialised-licensee simplified rule refers to transfers below US$1,000, treat it only as a conditional simplification and never where suspicion or higher risk exists.
- Preuves à conserver
- Module mapping, transfer samples, risk decisions and CDD result.
- Source primaire
- CBB FC-1 and FC-3, applicable Rulebook volume
Obtain payment-service approval before launch.
- Action d’implémentation
- Classify domestic and cross-border transfer, merchant acquisition, e-money, payment initiation, account information, money changing and crypto-based payment services under the February 2026 PSP Module.
- Preuves à conserver
- Product memo, CBB licence, conditions, safeguarding records and tests.
- Source primaire
- CBB Rulebook Volume 5, PSP Module, February 2026
Obtain the correct crypto-asset service licence.
- Action d’implémentation
- Map exchange, brokerage, custody, portfolio, advisory and crypto-based payment features to the CBB CRA and PSP modules; meet category, governance, custody, cybersecurity, market-conduct and AML controls.
- Preuves à conserver
- Service and wallet-flow map, CBB licence, category analysis, custody design and monitoring tests.
- Source primaire
- CBB Rulebook Volume 6, CRA Module; Volume 5 PSP Module
08Targeted financial sanctionsSanctions controls operate independently of an STR decision.3 éléments+
Screen UN and Bahrain designations and ownership or control.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding and upon list updates; test aliases and controlled entities rather than exact names only.
- Preuves à conserver
- List versions, update logs, configuration tests, match analysis and dispositions.
- Source primaire
- Applicable Bahrain targeted-financial-sanctions framework and CBB FC requirements
Freeze or restrain without delay when a true designation match exists.
- Action d’implémentation
- Stop dealings, prevent direct or indirect availability of assets and notify through the current competent route without waiting for an STR decision or customer notice.
- Preuves à conserver
- Match analysis, restriction timestamp, notification, authority correspondence and release approval.
- Source primaire
- Applicable UN implementation orders; CBB FC sanctions provisions
Use licences, exemptions or releases only under written authority.
- Action d’implémentation
- Identify the governing regime, obtain permission before activity, implement conditions and document expiry and release decisions.
- Preuves à conserver
- Regime analysis, licence or permission, controls, reporting and release record.
- Source primaire
- Applicable designation and competent-authority procedure
09Records and regulator accessFive years is the baseline, with distinct start events by record class.3 éléments+
Retain customer and relationship records for at least five years.
- Action d’implémentation
- Keep identity and business-relationship records for at least five years after the relationship ceases, subject to longer legal holds or authority directions.
- Preuves à conserver
- Retention schedule, relationship-end date, archive sample, retrieval test and deletion approval.
- Source primaire
- Legislative Decree No. 4 of 2001, article 5(a); CBB FC recordkeeping
Retain transaction and attempted-transaction records for at least five years.
- Action d’implémentation
- Keep records sufficient to reconstruct each transaction or attempt for at least five years after completion or attempt.
- Preuves à conserver
- Transaction sample, trigger calculation, legal hold and deletion log.
- Source primaire
- Legislative Decree No. 4 of 2001, article 5(b); CBB FC-7 or corresponding chapter
Preserve STR, monitoring, training and compliance evidence.
- Action d’implémentation
- Keep internal and external reports, dispositions, annual review and training records for the required period and make them promptly accessible to authorised authorities.
- Preuves à conserver
- Record-class matrix, access controls, retrieval tests and production log.
- Source primaire
- Applicable CBB FC recordkeeping requirements
10Privacy, biometrics, breaches, and transfersAML processing must also comply with Bahrain's personal-data framework.4 éléments+
Process personal data on a lawful basis and transparently.
- Action d’implémentation
- Map each KYC data element to a lawful basis and specific purpose, provide required notices, minimise collection, maintain accuracy and support data-subject rights.
- Preuves à conserver
- Data inventory, lawful-basis map, notices, request log and accuracy controls.
- Source primaire
- Law No. 30 of 2018 on Personal Data Protection
Apply special controls to sensitive and biometric data.
- Action d’implémentation
- Classify biometric and other sensitive data, identify the applicable statutory condition or permission, document necessity and proportionality and apply heightened access and deletion controls.
- Preuves à conserver
- Classification, legal assessment, privacy impact assessment, permissions and deletion tests.
- Source primaire
- Law No. 30 of 2018 and implementing decisions
Manage processors and personal-data breaches.
- Action d’implémentation
- Contract for instructions, confidentiality, security, incident escalation, return and deletion; investigate and notify the Authority or affected people where current law and decisions require.
- Preuves à conserver
- Processor contract, security review, incident chronology, notifications and remediation.
- Source primaire
- Law No. 30 of 2018; Personal Data Protection Authority executive decisions
Control transfers outside Bahrain.
- Action d’implémentation
- Determine whether the destination is adequate or another statutory route, authority permission or safeguard is required before transfer or remote access.
- Preuves à conserver
- Transfer map, adequacy analysis, permission or safeguard, contract and monitoring.
- Source primaire
- Law No. 30 of 2018, articles 12-13; Order No. 42 of 2022
11Practical evidence packsEvidence should reconstruct onboarding, reporting and launch decisions end to end.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, authority, KYB, beneficial ownership, PEP, sanctions, purpose, risk, privacy, approvals and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack and retrieval result.
- Source primaire
- Operational control supporting AML law and CBB FC-1
Maintain a reconstructable NFIC and sanctions case pack.
- Action d’implémentation
- Link activity, alert, suspicion chronology, STR, receipt, CBB notice, confidentiality, asset restrictions and authority communications.
- Preuves à conserver
- Complete sampled case pack, timeline and controlled-access record.
- Source primaire
- Operational control supporting AML law articles 4-5 and CBB FC reporting rules
Maintain a launch and change pack.
- Action d’implémentation
- Record perimeter, licences, approved programme, reporting connectivity, sanctions, privacy, vendors, tests and controlled uncertainties before launch or material change.
- Preuves à conserver
- Signed launch pack, source register, tests, approvals and uncertainty log.
- Source primaire
- Official sources listed below
Registre des sources primaires
19 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Legislative Decree No. 4 of 2001 - AML/CFT frameworkLegislation and Legal Opinion Commission · Primary legislation
- Legislative Decree No. 29 of 2020 - AML/CFT amendmentsLegislation and Legal Opinion Commission · Primary amending legislation
- Legislative Decree No. 36 of 2025 - AML/CFT amendmentsLegislation and Legal Opinion Commission · Primary amending legislation
- CBB Rulebook Volume 1 Financial Crime moduleCentral Bank of Bahrain · Official supervisor rules
- CBB Rulebook Volume 5 Financial Crime moduleCentral Bank of Bahrain · Official supervisor rules
- CBB Online STR system and authority contactsCentral Bank of Bahrain · Official reporting rules
- CBB recordkeeping requirementsCentral Bank of Bahrain · Official supervisor rules
- CBB beneficial-owner definitionCentral Bank of Bahrain · Official supervisor rules
- CBB Rulebook Volume 6 Crypto-asset moduleCentral Bank of Bahrain · Official licensing rules
- CBB Rulebook Volume 5 Payment Service Provider module, February 2026Central Bank of Bahrain · Official licensing rules
- National Financial Intelligence CentreMinistry of Interior · Official FIU information
- NFIC suspicious-activity indicatorsNational Financial Intelligence Centre · Official FIU guidance
- Ministerial Order No. 83 of 2020 on UBO disclosureMinistry of Industry and Commerce · Primary registry order
- Business services and Ultimate Beneficial OwnerMinistry of Industry and Commerce · Official registry guidance
- Law No. 30 of 2018 on Personal Data ProtectionPersonal Data Protection Authority · Primary legislation
- Personal-data executive decisions and breach/transfer requirementsPersonal Data Protection Authority · Official privacy guidance
- MENAFATF third enhanced follow-up report for BahrainMENAFATF · Authoritative assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
Réponses directes
Questions KYC, KYB et AML pour Bahreïn
Who receives suspicious transaction reports?+
The National Financial Intelligence Centre is Bahrain's FIU. CBB licensees submit through the current Online STR system and follow any CBB notification required by their Rulebook module.
When must an STR be filed?+
Immediately when suspicion arises, including attempted transactions and regardless of value. Record the suspicion timestamp and use the current electronic reporting specification.
What is the CBB occasional-transaction CDD threshold?+
Banking modules require CDD for one-off or linked occasional transactions above BHD 6,000, while wire transfers can trigger CDD irrespective of amount. Confirm the exact rule in the entity's current CBB volume.
Is BHD 6,000 a universal threshold-reporting rule?+
No. It is used in specific CBB CDD and monitoring provisions. Suspicious transactions are reportable regardless of value and no universal cash-threshold report should be inferred.
How is beneficial ownership determined?+
AML analysis identifies natural persons who ultimately own or control the customer, benefit from the arrangement or act behind a transaction. MOIC's UBO order treats 10% ownership or voting control as one criterion and also captures effective control and other influence.
How long are AML records kept?+
At least five years. Identity and relationship records run from relationship end; transaction records run from completion or the attempted transaction, subject to longer holds or authority directions.
Do payment providers need a CBB licence?+
Yes where the service falls within the regulated PSP perimeter. The February 2026 module covers domestic and cross-border transfers, acquiring, e-money, payment initiation, account information, money changing and crypto-based payment services.
Are crypto-asset services regulated?+
Yes. The CBB CRA and PSP modules regulate different crypto-asset and crypto-based payment activities. Determine the correct category and obtain approval before launch.
What privacy rules apply to biometric identity checks?+
Law No. 30 of 2018 and its implementing decisions apply. Classify biometric data, establish a lawful condition or permission, document necessity and proportionality, and control transfers, processors, security and deletion.
Is Bahrain on a FATF public list?+
No. Bahrain was absent from both FATF public lists dated 19 June 2026. It remains within MENAFATF follow-up, and public-list absence is not a low-risk conclusion.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 30 September 2026. Confirm the regulated perimeter, current CBB volume and module, NFIC reporting specifications, sanctions designation, data-protection permissions and sector orders with the competent authority and qualified Bahrain counsel before launch.