Malaisie KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Malaisie.
- Dernière revue
- Dernière revue:
- Version
- Version 1.1

Guide d’implémentation portable
Obtenir la checklist PDF
11 domaines de contrôle · 42 contrôles d’implémentation
Dernière revue: 25 September 2026 · Version 1.1
Télécharger la checklistRéponse directe
Que couvre la checklist de conformité pour Malaisie ?
La checklist pour Malaisie traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 42 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Competent authority and FIU
- Bank Negara Malaysia (BNM), Financial Intelligence and Enforcement Department
- Primary AML law
- AMLA 2001 as amended by Act A1761, effective 1 March 2026
- STR timing
- Promptly; under BNM's financial-institution policy, by the next working day after the compliance officer establishes suspicion
- Cash threshold report
- For covered financial institutions: RM25,000 or more in aggregated qualifying cash transactions in the same account in one day
- AML retention
- At least 6 years from the applicable transaction-completion or relationship-termination event; longer where directed or investigated
- Company-register BO
- Separate SSM criteria include direct or indirect holdings of not less than 20%, plus control-by-other-means tests
- Privacy
- PDPA 2010 as amended; biometric data is sensitive personal data; breach, DPO, transfer and DPIA controls may apply
- FATF public lists
- Not listed at 19 June 2026; 2025 mutual-evaluation roadmap remains relevant
Détail d’implémentation
Exigences et actions de conformité pour Malaisie
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingMap the actual activity, regulator and licence before applying a control set.4 éléments+
Determine whether each activity is carried on by a reporting institution under AMLA.
- Action d’implémentation
- Map every product, service, customer journey, branch and agent to the current First Schedule activity and record the applicable financial-institution or DNFBP/NBFI policy document; include the Act A1761 changes effective 1 March 2026.
- Preuves à conserver
- Activity and entity map, First Schedule analysis, policy-document mapping, legal update log and counsel or compliance approval.
- Source primaire
- AMLA 2001, sections 3, 7 and 7A and First Schedule, as amended by Act A1761; BNM AMLA portal
Identify the competent authority and sector supervisor.
- Action d’implémentation
- Route AMLA reporting and competent-authority matters to BNM's Financial Intelligence and Enforcement Department while documenting the relevant regulatory or supervisory authority for the entity and activity.
- Preuves à conserver
- Regulatory perimeter memo, supervisor directory, reporting access, escalation tree and correspondence log.
- Source primaire
- AMLA 2001, sections 7, 7A and 8; Act A1761; BNM AMLA portal
Obtain every required sector approval before regulated activity.
- Action d’implémentation
- Confirm licensing or approval under the FSA, IFSA, MSBA, capital-markets framework or other sector law; do not treat AMLA registration or compliance as permission to provide the underlying service.
- Preuves à conserver
- Licence or approval, conditions, service inventory, renewal calendar, agent approvals and launch sign-off.
- Source primaire
- Financial Services Act 2013; Islamic Financial Services Act 2013; Money Services Business Act 2011; SC Guidelines on Recognized Markets
Control branches, subsidiaries, agents and outsourced functions.
- Action d’implémentation
- Apply the required group programme, information-sharing safeguards and risk-based oversight; document responsibility and applicable Malaysian or host-country rules for each delivery party.
- Preuves à conserver
- Group standard, contracts, due diligence, responsibility matrix, monitoring results and remediation.
- Source primaire
- BNM AML/CFT/CPF and TFS for FIs PD, paragraphs 13 and 18; applicable DNFBP/NBFI PD provisions
02Governance and risk assessmentGovernance must reflect the institution's actual ML/TF/PF exposure, scale and complexity.4 éléments+
Maintain documented business and relationship risk assessments.
- Action d’implémentation
- Assess customers, countries, products, services, transactions, delivery channels, technology, agents and outsourcing for ML/TF/PF risk and refresh after material change or new national and sector risk information.
- Preuves à conserver
- Methodology, current assessments, data sources, approvals, residual-risk decisions and remediation plan.
- Source primaire
- AMLA 2001, sections 16 and 19; BNM FIs PD, paragraph 10; applicable DNFBP/NBFI PD risk provisions
Maintain an effective AML/CFT/CPF compliance programme.
- Action d’implémentation
- Translate risks into policies for CDD, beneficial ownership, PEPs, monitoring, reporting, sanctions, records, training, independent audit and regulatory response.
- Preuves à conserver
- Board-approved programme, control map, procedures, testing, training and issue closure.
- Source primaire
- AMLA 2001, section 19 as amended by Act A1761; BNM FIs PD, paragraph 11
Appoint accountable compliance leadership.
- Action d’implémentation
- Appoint a management-level compliance officer, notify BNM when the applicable policy requires it, preserve independence and resources, and maintain branch-level responsibility where required.
- Preuves à conserver
- Appointment, BNM notification, job description, reporting line, resources, branch designations and minutes.
- Source primaire
- AMLA 2001, section 19(4); BNM FIs PD, paragraphs 11.3 and 11.4; applicable DNFBP/NBFI PD
Test programme effectiveness independently.
- Action d’implémentation
- Set a risk-based audit scope and frequency, give reviewers access to systems and samples, report findings to appropriate governance and verify remediation.
- Preuves à conserver
- Audit plan, independence record, workpapers, report, management response and closure testing.
- Source primaire
- BNM FIs PD, paragraph 11.7; applicable DNFBP/NBFI PD independent-audit provisions
03Natural-person identificationCDD triggers and minimum data vary by sector and product; suspicion overrides monetary thresholds.4 éléments+
Apply CDD at every applicable trigger.
- Action d’implémentation
- Complete CDD when establishing a relationship and at the sector-specific occasional-transaction, cash, wire, e-money or other trigger, and always when suspicion exists or prior information is doubtful.
- Preuves à conserver
- Trigger matrix by sector, onboarding record, transaction aggregation, suspicion override and refresh decision.
- Source primaire
- AMLA 2001, section 16 as amended by Act A1761; BNM FIs PD, paragraphs 14A.1, 14B.2, 14C.2 and 14D.2
Identify and verify each individual from reliable independent sources.
- Action d’implémentation
- Collect the applicable name, official identifier, address, birth, nationality, occupation and contact attributes, verify authenticity and resolve discrepancies before proceeding except under an express controlled allowance.
- Preuves à conserver
- Identity record, source images and provenance, verification results, fraud checks and discrepancy resolution.
- Source primaire
- AMLA 2001, section 16; BNM FIs PD, paragraphs 14A.9.1, 14B.11.1, 14C.10.1 and 14D.9.1
Verify representatives and their authority.
- Action d’implémentation
- Identify and verify each person acting for a customer and validate written authority, mandate or directors' resolution before accepting instructions.
- Preuves à conserver
- Representative KYC, mandate, signatory rules, validity checks and activity log.
- Source primaire
- BNM FIs PD, paragraphs 14A.3(b), 14A.9.5, 14B.3(b), 14C.4(b) and 14D.3(b)
Do not proceed when required CDD cannot be completed.
- Action d’implémentation
- Do not open the account, start the relationship or perform the transaction, or terminate an existing relationship as applicable; document the reason and promptly assess and file an STR without tipping off.
- Preuves à conserver
- CDD failure record, restriction or exit action, STR decision, filing receipt and confidentiality controls.
- Source primaire
- BNM FIs PD, paragraphs 14A.16-14A.17, 14B.18-14B.19, 14C.17-14C.18 and 14D.17-14D.18
04KYB, registries, and beneficial ownershipAML beneficial ownership and SSM company-register reporting are related but distinct tests.4 éléments+
Verify legal existence, powers and business purpose.
- Action d’implémentation
- Obtain current incorporation or registration evidence, legal form, identifiers, registered and principal addresses, governing documents, directors or partners and intended activity from SSM and other reliable sources.
- Preuves à conserver
- Registry extract, constitutional documents, identifier checks, officer list, business profile and discrepancies.
- Source primaire
- AMLA 2001, section 16; BNM FIs PD, paragraphs 14A.9, 14B.11, 14C.10 and 14D.9
Identify and verify AML beneficial owners through the prescribed cascade.
- Action d’implémentation
- Trace ownership to natural persons, including at minimum directors, partners and shareholders with more than 25% equity under the BNM FIs PD; then assess control by other means and use the relevant senior-management fallback only when no natural person is identified.
- Preuves à conserver
- Ownership chart, share data, control analysis, verified identities, source records and fallback rationale.
- Source primaire
- BNM FIs PD, paragraphs 14A.9.6, 14B.11.12, 14C.10.7 and 14D.9.6
Identify parties to trusts and comparable arrangements.
- Action d’implémentation
- Identify and verify settlors, trustees, protectors, beneficiaries or classes, objects of a power and any other natural person exercising ultimate effective control, including through the chain of control or ownership.
- Preuves à conserver
- Trust deed, party schedule, control and ownership chain, identity verification and change monitoring.
- Source primaire
- BNM FIs PD, definition of beneficial owner and paragraphs 14A.9.13, 14B.11.19, 14C.10.14 and 14D.9.13
Keep SSM beneficial-ownership reporting separate from AML CDD.
- Action d’implémentation
- Apply the Companies Act and revised SSM guideline criteria, including not-less-than-20% direct or indirect share or voting holdings and control by other means; record and lodge changes within the applicable 14-day stages and continue identification efforts when senior management is recorded as fallback.
- Preuves à conserver
- Register of beneficial owners, notices, responses, verification, e-BOS lodgements, annual return and fallback review log.
- Source primaire
- Companies Act 2016, Division 8A, sections 60A-60D and 68; SSM BO Guideline revised 2025, paragraphs 20-29 and 43-50
05PEPs, enhanced due diligence, and remote onboardingHigher-risk relationships require corroboration, approval and intensified monitoring.4 éléments+
Identify foreign, domestic and international organisation PEP exposure.
- Action d’implémentation
- Screen customers, beneficial owners and relevant connected persons for PEP, family-member and close-associate status and refresh the assessment during the relationship.
- Preuves à conserver
- Screening results, data source, relationship map, risk rationale and refresh history.
- Source primaire
- BNM FIs PD, paragraph 15 and definitions of PEP, family member and close associate
Apply enhanced CDD to higher-risk cases.
- Action d’implémentation
- Obtain additional customer and beneficial-owner information, corroborate source of wealth or funds, obtain senior-management approval and increase monitoring; for PEPs, obtain both source of wealth and source of funds as required by the applicable policy.
- Preuves à conserver
- EDD trigger, additional sources, corroboration, approval, monitoring plan and review.
- Source primaire
- BNM FIs PD, paragraphs 14A.12, 14B.14, 14C.13 and 14D.13; paragraph 15
Use simplified CDD only on documented low risk.
- Action d’implémentation
- Confirm the sector-specific eligibility and Board or management approval, keep effective monitoring and withdraw simplified treatment when risk increases or suspicion arises.
- Preuves à conserver
- Eligibility assessment, approval, configured limits, monitoring results and withdrawal trigger.
- Source primaire
- BNM FIs PD, paragraphs 14A.10, 14B.12, 14C.11 and 14D.10
Control non-face-to-face identity risk.
- Action d’implémentation
- Apply the current BNM e-KYC and sector requirements to document authenticity, biometric or liveness controls, impersonation, device and channel risk, fallback review and model or vendor governance.
- Preuves à conserver
- Method assessment, test results, exception handling, vendor diligence, monitoring and model-change approvals.
- Source primaire
- BNM Electronic Know-Your-Customer Policy Document, 15 April 2024; BNM FIs PD non-face-to-face provisions
06Monitoring and suspicious transaction reportingSuspicion covers transactions, activities and property under amended AMLA, while the saved BNM policy also captures attempted and proposed transactions.4 éléments+
Conduct ongoing due diligence and transaction monitoring.
- Action d’implémentation
- Scrutinise activity against the customer's business, risk and source-of-funds profile, keep CDD and beneficial ownership current and escalate unusual patterns or new risk promptly.
- Preuves à conserver
- Scenario inventory, alerts, case files, profile refreshes, tuning and dispositions.
- Source primaire
- AMLA 2001, section 16 as amended by Act A1761; BNM FIs PD ongoing-due-diligence provisions
Assess statutory and policy suspicion triggers.
- Action d’implémentation
- Evaluate transactions, activities and property under amended AMLA for links to unlawful activity, ML, TF or restricted-activity financing. For institutions subject to the saved BNM FIs policy, also assess attempted and proposed transactions; record when reasonable grounds arose.
- Preuves à conserver
- Alert chronology, facts reviewed, statutory or policy ground, decision-maker, decision time and escalation.
- Source primaire
- AMLA 2001, section 14 as amended by Act A1761; Act A1761, section 52(5); BNM FIs PD, paragraph 22.1.1
Submit an STR through BNM's prescribed channel on time.
- Action d’implémentation
- Submit promptly through the Financial Intelligence System or current prescribed route. For an institution governed by the BNM FIs PD, file by the next working day after the compliance officer establishes suspicion; verify the sector-specific rule before relying on that deadline.
- Preuves à conserver
- Internal report, confirmation timestamp, STR, FINS receipt, supplemental filing and delay analysis.
- Source primaire
- AMLA 2001, section 14; BNM FIs PD, paragraphs 22.1-22.2, especially 22.2.6
Protect STR and investigation information.
- Action d’implémentation
- Restrict knowledge and disclosure, use need-to-know access, review any customer communication for tipping-off risk and preserve statutory confidentiality and permitted-disclosure analysis.
- Preuves à conserver
- Access logs, disclosure register, legal review, communications approval, training and incident record.
- Source primaire
- AMLA 2001, sections 14A and 20; BNM FIs PD, paragraph 23
07Cash, wire transfers, payments, and digital assetsAmounts and licensing duties attach to specific products and institution types.4 éléments+
Report covered cash transactions at the correct scoped threshold.
- Action d’implémentation
- For institutions subject to the BNM FIs PD cash-reporting rule, aggregate qualifying physical-currency and bearer-instrument deposits and withdrawals in the same account in one day and report RM25,000 or more; do not extend this threshold to every AMLA reporting institution or non-cash activity.
- Preuves à conserver
- Aggregation logic, cash data, exclusions, CTR, FINS receipt and quality review.
- Source primaire
- BNM FIs PD, paragraphs 21.2-21.4
Transmit and retain required wire-transfer information.
- Action d’implémentation
- For cross-border wires of RM3,000 or more, include accurate originator and required beneficiary details; apply the reduced below-threshold dataset, domestic traceability, missing-data controls and beneficiary verification exactly as the policy requires.
- Preuves à conserver
- Field matrix, payment samples, validation rules, exception queue, beneficiary checks and retention.
- Source primaire
- BNM FIs PD, paragraphs 19.1-19.4
Obtain approval before issuing e-money and apply the product's AML limits.
- Action d’implémentation
- Confirm approval under section 11 of the FSA or IFSA unless a current limited-purpose exemption applies, implement the 31 January 2025 e-money policy and map the product to the applicable CDD, account and transaction limits.
- Preuves à conserver
- Approval or exemption analysis, product limits, safeguarding, CDD configuration, testing and reporting.
- Source primaire
- FSA 2013, section 11; IFSA 2013, section 11; BNM Electronic Money Policy Document, revised 31 January 2025; BNM FIs PD, paragraph 14D and Appendix 3
Use licensed MSB providers and registered digital-asset operators.
- Action d’implémentation
- Obtain the appropriate BNM MSB licence for money changing, remittance or wholesale currency business and SC registration for a DAX or other regulated digital-asset role; verify agents and current public registers before reliance.
- Preuves à conserver
- Licence or registration, public-register check, agent certificate, conditions, service map and renewal monitoring.
- Source primaire
- Money Services Business Act 2011; BNM MSB directory; SC Guidelines on Recognized Markets, revised 20 May 2026; SC Digital Assets portal
08Targeted financial sanctionsTerrorism, proliferation and other UN sanctions controls apply independently of ordinary CDD thresholds.3 éléments+
Screen current domestic and UN lists without threshold.
- Action d’implémentation
- Screen customers, beneficial owners, beneficiaries, representatives and transactions against the Domestic List and relevant UNSCR lists at onboarding, ongoing review and immediately after list updates; assess ownership, control and direction, not names alone.
- Preuves à conserver
- List versions, update timestamps, screening scope, configuration tests, match analysis and dispositions.
- Source primaire
- AMLA 2001, Part VIA; BNM FIs PD, paragraphs 27.3-27.5, 28.2-28.4 and 29.2-29.4
Freeze, block or reject immediately and without delay after confirmation.
- Action d’implémentation
- Upon confirming a designated or specified person or related party, freeze covered funds, property or economic resources, block applicable transactions or reject the potential customer, and permit dealings only under verified written authority.
- Preuves à conserver
- Match confirmation, ownership-control analysis, action timestamp, system blocks, authority and release decision.
- Source primaire
- AMLA 2001, sections 66B and 66E; BNM FIs PD, paragraphs 27.6, 28.5 and 29.5
Report positive matches immediately to the required authorities.
- Action d’implémentation
- Use the current prescribed form to report terrorism-related positive matches immediately to BNM and the Inspector-General of Police, and PF or other UN-sanctions actions immediately to BNM; submit related STRs and periodic updates where required.
- Preuves à conserver
- Positive-match report, delivery receipts, STR, periodic report, communications and frozen-asset ledger.
- Source primaire
- BNM FIs PD, paragraphs 27.7-27.8, 28.6-28.7 and 29.6-29.7
09Records and regulator accessRetention must preserve reconstruction and remain extended for investigations or directions.3 éléments+
Retain AML records for at least six years from the correct event.
- Action d’implémentation
- Keep CDD, account, activity and transaction records for at least six years after the transaction is completed or the relationship is terminated, using the later applicable event under the amended section 17 wording.
- Preuves à conserver
- Retention schedule, event mapping, system configuration, sample retrieval and deletion controls.
- Source primaire
- AMLA 2001, section 17 as amended by Act A1761; BNM FIs PD, paragraph 24.3
Extend holds for investigations and competent-authority directions.
- Action d’implémentation
- Suspend deletion when records are under investigation, prosecution, regulatory request or a current extension direction, and document release authority before disposal.
- Preuves à conserver
- Legal-hold notice, affected systems, custodian acknowledgement, extension direction and release approval.
- Source primaire
- AMLA 2001, section 17; BNM FIs PD, paragraph 24.4
Make records reconstructable and promptly accessible.
- Action d’implémentation
- Preserve origin, destination, amount, currency, parties, authority, CDD sources, decisions and timestamps in a form that can reconstruct activity and be supplied to BNM or the relevant supervisor within the specified period.
- Preuves à conserver
- Reconstruction test, indexed archive, access logs, production record and regulator receipt.
- Source primaire
- AMLA 2001, sections 13, 15, 17, 21 and 25 as amended by Act A1761; BNM FIs PD, paragraphs 24-25
10Privacy, biometrics, breaches, and transfersPDPA duties apply to commercial processing within scope and now expressly address processors, biometrics, DPOs and breaches.5 éléments+
Establish PDPA scope, purpose and processing authority.
- Action d’implémentation
- Map controller and processor roles, commercial-transaction coverage, notices, consent or other permitted processing, disclosure, accuracy, retention, access and security; apply sector codes where relevant.
- Preuves à conserver
- Data map, legal basis, notices, consent records, processor terms, retention and rights workflow.
- Source primaire
- Personal Data Protection Act 2010, sections 2, 5-12 and 43-44, as amended by Act A1727
Treat biometric identity data as sensitive personal data.
- Action d’implémentation
- For face, fingerprint, voice or behavioural templates produced by technical processing, apply sensitive-data conditions, minimisation, strict access, security, retention and deletion, and document alternatives and proportionality.
- Preuves à conserver
- Biometric inventory, purpose assessment, consent or authority, access logs, security tests, retention and deletion proof.
- Source primaire
- PDPA 2010, section 4 as amended by Act A1727, section 40; Personal Data Protection Standard 2015
Appoint and notify a DPO when the current criteria apply.
- Action d’implémentation
- Assess the Commissioner's thresholds, including processing over 20,000 data subjects, sensitive or financial data over 10,000 data subjects, or regular and systematic monitoring; appoint a qualified accessible DPO, register the appointment within 21 days and register a replacement within 14 days of the new appointment after the prior DPO leaves or the term ends.
- Preuves à conserver
- Threshold assessment, appointment, qualifications, contact channel, notification receipt, replacement record and deadline log.
- Source primaire
- PDPA 2010, section 12A; Commissioner's Circular No. 1/2025, paragraphs 8(2)-8(3), and DPO Guideline
Assess every personal-data breach and notify when the criteria are met.
- Action d’implémentation
- Assess whether the breach creates significant harm or meets another notification criterion, including sensitive data, identity-fraud-enabling combinations or significant scale above 1,000 affected subjects. If a criterion is met, notify the Commissioner as soon as practicable and no later than 72 hours from occurrence or confirmation under the guideline; explain a delay, complete staged information no later than 30 days, notify affected subjects no later than seven days after the initial Commissioner notification, and retain breach records for at least two years.
- Preuves à conserver
- Incident chronology, notification-criteria assessment, harm and scale assessment, 72-hour filing, seven-day subject notice, delay reasons, staged updates and two-year register.
- Source primaire
- PDPA 2010, section 12B; Commissioner's Circular No. 2/2025; DBN Guideline, paragraphs 5.2, 6.1-6.2 and 9.1
Control cross-border transfers and high-risk processing.
- Action d’implémentation
- Before an overseas transfer, document substantially similar law or adequate protection, or a specific section 129 exception, and apply contracts and transfer due diligence. Conduct a DPIA where the 2026 guideline requires it, including high-risk biometric or large-scale processing.
- Preuves à conserver
- Transfer map, destination assessment, transfer impact assessment, contract, exception record, DPIA and residual-risk approval.
- Source primaire
- PDPA 2010, section 129 as amended by Act A1727; Cross-Border Transfer Guideline 2025; DPIA Guideline 2026
11Practical evidence packsEvidence should let an independent reviewer reconstruct the legal basis and operational decision.3 éléments+
Maintain a customer and beneficial-owner evidence pack.
- Action d’implémentation
- Preserve the trigger, identity and KYB sources, ownership and control cascade, representative authority, risk rating, PEP and sanctions results, EDD, approvals and refresh history.
- Preuves à conserver
- Timestamped case file with source provenance, decision log, approvals and version history.
- Source primaire
- AMLA 2001, sections 13, 16 and 17; BNM FIs PD, paragraphs 14-17 and 24
Maintain reporting and monitoring evidence.
- Action d’implémentation
- Preserve monitoring configuration, alert chronology, analyst reasoning, escalation, STR and CTR submissions, sanctions actions, confidentiality access and feedback-driven tuning.
- Preuves à conserver
- Scenario register, case exports, FINS receipts, frozen-asset ledger, access logs and change approvals.
- Source primaire
- AMLA 2001, sections 14, 14A, 15, 17 and 20; BNM FIs PD, paragraphs 21-25 and 27-29
Maintain licensing, outsourcing and privacy evidence.
- Action d’implémentation
- Keep current licences, conditions, agent and vendor due diligence, contracts, service and data-flow maps, incident records, transfer assessments, DPIAs and closure testing together with named owners.
- Preuves à conserver
- Licence register, contract repository, assurance reports, data map, privacy register, remediation and governance minutes.
- Source primaire
- Applicable sector law; BNM policy documents; PDPA 2010 as amended by Act A1727; Commissioner guidelines
Registre des sources primaires
28 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Malaysia AMLA portal and current amendment noticeBank Negara Malaysia · Official legal portal
- AMLA 2001 Act 613 compilationAttorney General's Chambers of Malaysia · Primary legislation
- AMLA Amendment Act 2025 Act A1761Bank Negara Malaysia · Primary amending legislation
- Act A1761 commencement notification P.U. (B) 76/2026Bank Negara Malaysia · Official gazette instrument
- AML/CFT/CPF and TFS for Financial Institutions Policy DocumentBank Negara Malaysia · Binding supervisory policy
- AML/CFT/CPF and TFS for DNFBPs and NBFIs Policy DocumentBank Negara Malaysia · Binding supervisory policy
- Companies Act 2016 and amendments portalCompanies Commission of Malaysia · Official legal portal
- Companies Amendment Act 2024 resourcesCompanies Commission of Malaysia · Official legal and implementation portal
- Guideline for the Reporting Framework for Beneficial Ownership of Companies, revised 2025Companies Commission of Malaysia · Official registry guideline
- Personal Data Protection Act 2010 portalPersonal Data Protection Commissioner Malaysia · Official legal portal
- Personal Data Protection Amendment Act 2024 Act A1727Personal Data Protection Commissioner Malaysia · Primary amending legislation
- PDPA Amendment Act commencement notification P.U. (B) 522Personal Data Protection Commissioner Malaysia · Official gazette instrument
- Commissioner's Circular No. 2/2025 on data breach notificationPersonal Data Protection Commissioner Malaysia · Official regulatory circular
- Data Breach Notification GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Personal Data Breach Notification SystemPersonal Data Protection Commissioner Malaysia · Official regulatory reporting portal
- Commissioner's Circular No. 1/2025 on data protection officersPersonal Data Protection Commissioner Malaysia · Official regulatory circular
- Data Protection Officer GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Cross-Border Transfer of Personal Data GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Data Protection Impact Assessment GuidelinePersonal Data Protection Commissioner Malaysia · Official regulatory guideline
- Electronic Know-Your-Customer Policy Document, 15 April 2024Bank Negara Malaysia · Binding supervisory policy
- Electronic Money Policy Document, revised 31 January 2025Bank Negara Malaysia · Binding supervisory policy
- Money Services Business frameworkBank Negara Malaysia · Official licensing guidance
- Guidelines on Recognized Markets, revised 20 May 2026Securities Commission Malaysia · Official capital-markets guideline portal
- Malaysia digital-assets regulatory portalSecurities Commission Malaysia · Official regulatory guidance
- Malaysia country profileFinancial Action Task Force · Authoritative international assessment
- FATF/APG Mutual Evaluation Report of Malaysia 2025Financial Action Task Force · Authoritative international assessment
- Jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Current public-list statement
- High-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Current public-list statement
Réponses directes
Questions KYC, KYB et AML pour Malaisie
Who receives suspicious transaction reports in Malaysia?+
The Financial Intelligence and Enforcement Department of Bank Negara Malaysia receives STRs through FINS or the current prescribed route. Confirm access and sector instructions before filing.
What is the STR deadline?+
AMLA requires reporting of covered suspicion and BNM policy requires prompt filing. For institutions governed by the FIs Policy Document, the compliance officer must submit by the next working day after establishing suspicion. Other sectors must verify their applicable policy and directions.
Is RM25,000 a universal CDD or reporting threshold?+
No. Under the BNM FIs Policy Document it is the scoped cash-threshold-report level for qualifying aggregated cash activity and is also a banking occasional-transaction CDD trigger. Other products and sectors have different triggers, and suspicion applies regardless of amount.
Which beneficial-ownership threshold should be used?+
Do not merge the tests. The BNM FIs Policy Document cascade includes shareholders with more than 25% equity, control by other means and a senior-management fallback. The SSM company-reporting guideline separately uses not less than 20% share or voting criteria plus control tests.
How long must AML records be kept?+
At least six years from the applicable completion or termination event, with longer retention where an investigation, prosecution or competent-authority direction requires it.
Do digital-asset businesses need approval?+
Yes where the activity falls within Malaysia's regulated digital-asset perimeter. A DAX must be registered as a recognized market operator with the Securities Commission, and other digital-asset roles have their own SC requirements.
What happens after a sanctions match?+
After a true match is confirmed, the institution must take the applicable freeze, block or rejection action immediately and without delay, report immediately to the required authorities, file related STRs and retain evidence. The exact route differs among TF, PF and other UN regimes.
How does Malaysia regulate biometric KYC data?+
Act A1727 added biometric data to sensitive personal data. Controllers and processors must apply the PDPA security and processing requirements, and high-risk biometric processing may require a DPIA under the 2026 guideline.
When must a personal-data breach be reported?+
Assess every breach. Commissioner notification is required when a guideline criterion is met, including significant harm, sensitive data, identity-fraud-enabling combinations or significant scale above 1,000 affected subjects. Notify as soon as practicable and no later than 72 hours from occurrence or confirmation under the guideline; affected subjects must be notified no later than seven days after the initial Commissioner notification.
Is Malaysia on a FATF public list?+
No. Malaysia was absent from both FATF public lists dated 19 June 2026, but its 2025 mutual evaluation includes a three-year roadmap and absence from a public list is not a low-risk rating.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 September 2026. Confirm the current First Schedule activity, applicable BNM or sector-supervisor policy document, post-Act A1761 directions, Labuan or other sector overlays, licensing, reporting forms, sanctions lists, privacy coverage and implementation facts with the competent authority and qualified Malaysian counsel before launch.