Koweït KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Koweït.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Guide d’implémentation portable
Obtenir la checklist PDF
11 domaines de contrôle · 39 contrôles d’implémentation
Dernière revue: 1 October 2026 · Version 1.0
Télécharger la checklistRéponse directe
Que couvre la checklist de conformité pour Koweït ?
La checklist pour Koweït traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 39 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML law
- Law No. 106 of 2013, as amended
- FIU
- Kuwait Financial Intelligence Unit
- STR timing
- No later than 2 working days after suspicion; attempts and all values included
- Occasional-transaction CDD
- KWD 3,000 or equivalent, including linked transactions
- Wire-transfer CDD
- Before domestic or international wire transfers
- AML retention
- At least 5 years, with record-specific start events
- Registry beneficial owner
- 25% ownership or voting rights, control by other means, then senior-management fallback
- FATF public lists
- Not listed at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Koweït
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingClassify the entity, activity and supervisor before assigning controls.3 éléments+
Determine whether the entity is a financial institution or designated non-financial business or profession.
- Action d’implémentation
- Map services, customers and Kuwait nexus to Law No. 106 of 2013 and the current activity-specific supervisory perimeter.
- Preuves à conserver
- Perimeter memo, service and funds-flow maps, legal analysis and authority confirmation.
- Source primaire
- Law No. 106 of 2013, article 1; Executive Regulation article 1
Obtain each required licence or approval before activity.
- Action d’implémentation
- Classify banking, finance, exchange, securities, insurance, payments, real estate, precious-metals, professional and technology features and obtain approval from the competent authority.
- Preuves à conserver
- Licence matrix, applications, approvals, conditions and renewal calendar.
- Source primaire
- Law No. 106 of 2013, articles 13-15; applicable CBK, CMA or MOCI law and instructions
Use the current sector instruction and controlling Arabic text.
- Action d’implémentation
- Track amendments and circulars for the exact licence; treat official English translations as informational where the authority states that Arabic controls.
- Preuves à conserver
- Source inventory, translation protocol, change log and compliance mapping.
- Source primaire
- Executive Regulation article 17; applicable supervisory instructions
02Governance and ML/TF/PF risk assessmentGovernance must be risk-based, documented and available to the supervisor.3 éléments+
Maintain a documented and current enterprise risk assessment.
- Action d’implémentation
- Assess customers, countries, products, services, delivery channels, new technology, sanctions and emerging risks; update for material change.
- Preuves à conserver
- Methodology, assessment, data sources, approvals, residual-risk decisions and change log.
- Source primaire
- Law No. 106 of 2013, article 4; Executive Regulation articles 2-4 and 11
Maintain proportionate policies, systems and controls.
- Action d’implémentation
- Document CDD, monitoring, reporting, records, sanctions, screening, training, group information sharing and escalation.
- Preuves à conserver
- Approved framework, control map, procedures, training and issue register.
- Source primaire
- Law No. 106 of 2013, article 10; Executive Regulation articles 12-14
Designate a senior compliance officer and independent audit function.
- Action d’implémentation
- Appoint an empowered senior compliance officer, preserve access and escalation, and independently test control design and operation.
- Preuves à conserver
- Appointment, authority matrix, board reporting, audit plan, findings and closure tests.
- Source primaire
- Law No. 106 of 2013, article 10(c) and (e)
03Natural-person identificationCDD covers the customer, beneficial owner and authorised representative.6 éléments+
Apply CDD before or during relationship establishment and at every statutory trigger.
- Action d’implémentation
- Identify and verify the customer and beneficial owner, understand purpose and intended nature, and refresh for suspicion, doubt or material change.
- Preuves à conserver
- Trigger analysis, identity record, verification result, purpose and completion timestamp.
- Source primaire
- Law No. 106 of 2013, article 5
Apply the KWD 3,000 occasional-transaction threshold correctly.
- Action d’implémentation
- For a customer without an established relationship, complete CDD before a single or linked transaction at the statutory threshold; do not treat it as a universal threshold-reporting rule.
- Preuves à conserver
- Aggregation logic, transaction samples and CDD outcomes.
- Source primaire
- Law No. 106 of 2013, article 5(3)(b); Executive Regulation article 6
Apply CDD before domestic and international wire transfers.
- Action d’implémentation
- Do not import the KWD 3,000 occasional-transaction threshold into the separate wire-transfer trigger.
- Preuves à conserver
- Transfer samples, CDD result and exception testing.
- Source primaire
- Law No. 106 of 2013, article 5(3)(c)
Verify identity from reliable, independent evidence.
- Action d’implémentation
- Use the civil card for citizens and residents, passport or travel document for non-residents, and current reliable evidence required by the supervisor.
- Preuves à conserver
- Identity attributes, source provenance, validation result and fraud checks.
- Source primaire
- Law No. 106 of 2013, article 5; Executive Regulation article 5
Identify representatives and validate authority.
- Action d’implémentation
- Verify persons acting for the customer and obtain the instrument, document or order proving authority before instructions are accepted.
- Preuves à conserver
- Representative KYC, mandate, authority checks and instruction limits.
- Source primaire
- Executive Regulation article 5(d)
Do not proceed when required CDD cannot be completed.
- Action d’implémentation
- Decline or terminate the account, relationship or transaction and consider a KFIU report without tipping off.
- Preuves à conserver
- CDD failure record, restriction or exit decision, report assessment and communications review.
- Source primaire
- Law No. 106 of 2013, article 5(5)
04KYB, registry, and beneficial ownershipRegistry disclosure and AML beneficial-ownership analysis are related but distinct.5 éléments+
Verify the legal person and understand its ownership and control structure.
- Action d’implémentation
- Collect the commercial licence, constitutional documents, address, senior managers and reliable registry information; resolve discrepancies.
- Preuves à conserver
- Registry extract, constitutional documents, officer list and discrepancy record.
- Source primaire
- Law No. 106 of 2013, article 5; Executive Regulation article 5(c)
Identify natural persons who ultimately own or control the customer.
- Action d’implémentation
- Trace direct, indirect, layered and nominee structures and identify the person on whose behalf the transaction is conducted.
- Preuves à conserver
- Ownership chart, control analysis, declarations, source documents and verified identities.
- Source primaire
- Law No. 106 of 2013, articles 1 and 5
Apply the registry 25% test with control and fallback analysis.
- Action d’implémentation
- Identify natural persons with at least 25% ownership or voting rights; if none, identify control by other means; if still none after all reasonable means, identify the senior management official.
- Preuves à conserver
- Calculations, control analysis, fallback rationale and identities.
- Source primaire
- MOCI Ministerial Resolution No. 4 of 2023, article 5, as amended in 2025
Maintain and update the actual-beneficiary register.
- Action d’implémentation
- Create and submit required registers within 60 days and record or submit changes within 15 days of awareness or the applicable change event.
- Preuves à conserver
- Register, MOCI submission, change log, notices and receipts.
- Source primaire
- MOCI Ministerial Resolution No. 4 of 2023, articles 8, 11 and 14, as amended
Do not reduce AML ownership analysis to the registry percentage.
- Action d’implémentation
- Assess ultimate ownership, effective control and on-behalf-of activity even when no person meets the registry percentage or an exemption applies.
- Preuves à conserver
- Separate AML and registry analyses, rationale and approval.
- Source primaire
- Law No. 106 of 2013, articles 1 and 5; Resolution No. 4 of 2023
05PEPs, EDD, and remote onboardingEnhanced measures attach to specified and higher-risk circumstances.3 éléments+
Identify foreign, domestic and international-organisation PEPs, family members and close associates.
- Action d’implémentation
- For foreign PEPs apply senior approval, source-of-wealth, source-of-funds and enhanced monitoring; apply those measures to domestic and international-organisation PEPs where risk is high.
- Preuves à conserver
- Screening, relationship map, approval, source corroboration and review history.
- Source primaire
- Executive Regulation articles 1(4) and 7
Apply enhanced due diligence to higher-risk relationships.
- Action d’implémentation
- Obtain additional customer, purpose, wealth and funds information; increase monitoring and document acceptance or continuation.
- Preuves à conserver
- Risk trigger, additional CDD, source evidence, approval and monitoring plan.
- Source primaire
- Law No. 106 of 2013, article 4; Executive Regulation articles 1(3) and 8
Control non-face-to-face and new-technology risk.
- Action d’implémentation
- Assess impersonation and document risk, validate vendors and liveness methods, preserve fallback and strengthen controls where residual risk is elevated.
- Preuves à conserver
- Method assessment, vendor diligence, testing, exceptions and fraud cases.
- Source primaire
- Law No. 106 of 2013, articles 4-5; Executive Regulation article 11
06Monitoring and suspicious transaction reportingOngoing scrutiny and prompt escalation support reporting to KFIU.4 éléments+
Keep CDD current and monitor activity on a risk basis.
- Action d’implémentation
- Examine transactions against purpose, commercial activity, expected behaviour, risk profile and source of funds where required.
- Preuves à conserver
- Monitoring scenarios, alerts, case decisions, refresh records and quality tests.
- Source primaire
- Law No. 106 of 2013, article 5(2)(c)
Escalate suspicion without waiting for proof or completion.
- Action d’implémentation
- Assess completed and attempted activity promptly and record the facts, reasonable grounds and formation timestamp.
- Preuves à conserver
- Alert chronology, information reviewed, decision and decision-maker.
- Source primaire
- Law No. 106 of 2013, article 12; Executive Regulation article 16
Report to KFIU no later than two working days after suspicion.
- Action d’implémentation
- Submit the report in KFIU's current method and form for transactions and attempts regardless of value; a stricter sector instruction must also be followed.
- Preuves à conserver
- Suspicion timestamp, report, submission receipt, corrections and supervisory notice if required.
- Source primaire
- Executive Regulation article 16; Law No. 106 of 2013, article 12
Prevent tipping off and protect reporting information.
- Action d’implémentation
- Restrict report knowledge and customer or third-party communications and disclose only where legally permitted.
- Preuves à conserver
- Access controls, disclosure register, legal review, training and incident log.
- Source primaire
- Law No. 106 of 2013, article 13
07Payments, wires, thresholds, and virtual assetsTransfer and technology services require exact activity and licensing analysis.3 éléments+
Carry and validate required wire-transfer information.
- Action d’implémentation
- Collect and transmit prescribed originator and beneficiary information, keep it through the payment chain and do not execute an outgoing transfer when required information cannot be obtained.
- Preuves à conserver
- Field matrix, message samples, validation rules, repair queue and dispositions.
- Source primaire
- Law No. 106 of 2013, article 9; Executive Regulation article 10
Obtain the correct payment or remittance approval before launch.
- Action d’implémentation
- Map money or value transfer, payment instruments, electronic money, exchange and financing functions to CBK law and current instructions.
- Preuves à conserver
- Product memo, licence, conditions, safeguarding design and tests.
- Source primaire
- Law No. 106 of 2013, article 1; Law No. 32 of 1968 and applicable CBK instructions
Do not offer virtual-asset services as a Kuwait business without a lawful current licence path.
- Action d’implémentation
- Apply MOCI's July 2023 circular and parallel regulator notices prohibiting the grant of VASP licences; re-verify current law before any crypto feature and warn customers of external-transaction risks where required.
- Preuves à conserver
- Feature map, prohibition analysis, regulator confirmation, geofencing and customer notices.
- Source primaire
- MOCI Circular No. 80 of 2023; sector circulars dated July 2023
08Targeted financial sanctionsThe 2025 framework must be implemented using current lists and committee procedures.3 éléments+
Screen UN and Kuwait designations and ownership or control.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding and list updates; test aliases and controlled entities.
- Preuves à conserver
- List versions, update logs, configuration tests, match analysis and dispositions.
- Source primaire
- Ministerial Decision No. 8 of 2025 and executive annexes
Freeze without delay when the current framework requires it.
- Action d’implémentation
- Block dealings and prevent direct or indirect asset availability upon a true match, then use the competent notification route without waiting for an STR decision.
- Preuves à conserver
- Match analysis, restriction timestamp, notification and authority correspondence.
- Source primaire
- Ministerial Decision No. 8 of 2025; MENAFATF 2026 follow-up, Recommendations 6 and 7
Use exemptions, licences, delisting or release only under written authority.
- Action d’implémentation
- Identify the governing designation, apply through the current Special Committee process and implement every condition and expiry.
- Preuves à conserver
- Regime analysis, permission, controls, reporting and release record.
- Source primaire
- Ministerial Decision No. 8 of 2025 and executive annexes
09Records and regulator accessFive years is the baseline, with distinct start events by record class.3 éléments+
Retain CDD, account and correspondence records for at least five years.
- Action d’implémentation
- Run the period from relationship end or the covered occasional transaction, subject to longer competent-authority directions.
- Preuves à conserver
- Retention schedule, trigger date, archive sample, retrieval test and deletion approval.
- Source primaire
- Law No. 106 of 2013, article 11(a)
Retain attempted and executed transaction records for at least five years.
- Action d’implémentation
- Keep sufficient detail to reconstruct each transaction from its attempt or execution date.
- Preuves à conserver
- Transaction sample, trigger calculation, legal hold and deletion log.
- Source primaire
- Law No. 106 of 2013, article 11(b)
Retain reports and risk assessments for their statutory periods.
- Action d’implémentation
- Keep KFIU reports and related documents for five years from reporting and each risk assessment for five years from creation or update.
- Preuves à conserver
- Report archive, assessment versions, access controls and production log.
- Source primaire
- Law No. 106 of 2013, article 11(c)-(d)
10Privacy, biometrics, breaches, and transfersApply the scope-specific CITRA regime and other confidentiality rules to KYC processing.3 éléments+
Determine whether CITRA's 2024 Data Privacy Protection Regulation applies.
- Action d’implémentation
- Map the service, provider status, processing location and technology scope before treating the CITRA regulation as a universal economy-wide law.
- Preuves à conserver
- Scope memo, data and service maps, regulator analysis and approval.
- Source primaire
- CITRA Decision No. 26 of 2024 and Data Privacy Protection Regulation
Process personal and sensitive data under the applicable conditions.
- Action d’implémentation
- Document purpose and legal basis, transparency, minimisation, accuracy, security, retention and rights; apply heightened controls to biometric or sensitive identity data.
- Preuves à conserver
- Data inventory, legal-basis map, notices, impact assessment, access and deletion tests.
- Source primaire
- CITRA Data Privacy Protection Regulation, 2024
Control processors, incidents and cross-border access.
- Action d’implémentation
- Contract for instructions, confidentiality, security, escalation, return and deletion; assess transfer and breach duties under the exact applicable regime.
- Preuves à conserver
- Processor contract, security review, transfer assessment, incident record and notifications.
- Source primaire
- CITRA Data Privacy Protection Regulation, 2024; applicable sector confidentiality rules
11Practical evidence packsEvidence should reconstruct onboarding, reporting and launch decisions end to end.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, authority, KYB, beneficial ownership, PEP, sanctions, purpose, risk, privacy, approvals and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack and retrieval result.
- Source primaire
- Operational control supporting Law No. 106 of 2013, articles 4-5 and 11
Maintain a reconstructable KFIU and sanctions case pack.
- Action d’implémentation
- Link activity, alert, suspicion chronology, report, receipt, confidentiality, asset restrictions and authority communications.
- Preuves à conserver
- Complete sampled case pack, timeline and controlled-access record.
- Source primaire
- Operational control supporting Law No. 106 of 2013, articles 11-13
Maintain a launch and change pack.
- Action d’implémentation
- Record perimeter, licences, programme, reporting connectivity, sanctions, privacy, vendors, tests and controlled uncertainties before launch or material change.
- Preuves à conserver
- Signed launch pack, source register, tests, approvals and uncertainty log.
- Source primaire
- Official sources listed below
Registre des sources primaires
15 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law No. 106 of 2013 on AML/CFT and amendmentsKuwait Financial Intelligence Unit · Primary legislation - official English translation
- Ministerial Decision No. 37 of 2013 Executive Regulation and amendmentsKuwait Financial Intelligence Unit · Primary regulation - official English translation
- KFIU laws and decisions registerKuwait Financial Intelligence Unit · Official legal register
- Kuwait Financial Intelligence UnitKuwait Financial Intelligence Unit · Official FIU information
- CBK AML/CFT instructions for local banksCentral Bank of Kuwait · Official supervisor instructions
- CBK AML/CFT instructions for exchange companiesCentral Bank of Kuwait · Official supervisor instructions
- Ministerial Resolution No. 4 of 2023 on actual beneficiariesMinistry of Commerce and Industry · Primary registry regulation
- Ministerial Resolution No. 16 of 2025 amending beneficial-owner proceduresMinistry of Commerce and Industry · Primary amending regulation
- MOCI 2023 virtual-asset circular and beneficial-owner summaryMinistry of Commerce and Industry · Official regulatory notice
- CITRA Decision No. 26 of 2024 issuing the privacy regulationCommunication and Information Technology Regulatory Authority · Primary regulatory decision
- CITRA Data Privacy Protection RegulationCommunication and Information Technology Regulatory Authority · Official privacy regulation
- Kuwait Mutual Evaluation Report 2024FATF / MENAFATF · Authoritative assessment
- Kuwait second enhanced follow-up report 2026FATF / MENAFATF · Authoritative current follow-up
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
Réponses directes
Questions KYC, KYB et AML pour Koweït
Who receives suspicious transaction reports?+
The Kuwait Financial Intelligence Unit receives reports using its current prescribed method and form.
When must a suspicious transaction report be filed?+
The Executive Regulation requires reporting no later than two working days after suspicion or reasonable grounds arise. Attempts and transactions of every value are covered; follow any stricter current sector instruction.
What is the occasional-transaction CDD threshold?+
KWD 3,000 or equivalent for a customer without an established relationship, including linked transactions. This is a CDD trigger, not a universal threshold-reporting rule.
Do wire transfers use the KWD 3,000 threshold?+
No. Law No. 106 of 2013 separately requires CDD before domestic or international wire transfers.
How is beneficial ownership determined?+
AML analysis identifies ultimate ownership, control and the person behind the transaction. The MOCI registry rule uses at least 25% ownership or voting rights, then control by other means, then a senior-management fallback after all reasonable means are exhausted.
How quickly must registry beneficial-owner data be updated?+
The 2023 resolution generally uses 15-day change and notification periods. Apply the exact trigger and the 2025 amendments to the event at issue.
How long are AML records kept?+
At least five years. CDD records run from relationship end or the relevant occasional transaction, transaction records from attempt or execution, reports from submission, and risk assessments from creation or update.
Can a business offer virtual-asset services in Kuwait?+
The July 2023 multi-regulator position prohibited issuing VASP licences and stated none had been issued. Re-confirm current law and regulator position before offering any virtual-asset feature.
Does Kuwait have a universal data-protection law?+
The CITRA 2024 regulation has a defined communications and IT scope. Determine its application and any sector confidentiality rules for the specific service rather than assuming universal coverage.
Is Kuwait on a FATF public list?+
No. Kuwait was absent from both FATF public lists dated 19 June 2026, but remains in MENAFATF enhanced follow-up and public-list absence is not a low-risk conclusion.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 1 October 2026. Confirm the regulated perimeter, current Arabic legal text, supervisory instructions, KFIU reporting specifications, sanctions designation, privacy scope and sector permissions with the competent authority and qualified Kuwait counsel before launch.