Grade B AI-Researched

Malaysia -- AML/CFT Compliance Regulatory Overview

Published: 2026-04-22 Updated: 2026-04-22 Author: SearXNG+LLM Version 1 Sources cited in: English (2)

Methodology

AI-generated synthesis from web search results.

Limitations

  • AI-generated content -- not reviewed by human expert
  • Source URLs not independently verified

Malaysia has robust Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) requirements that extend to cryptocurrency and virtual asset service providers (VASPs). These requirements are primarily driven by the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act (AMLATFPUAA) 2001 and subsequent policy documents issued by Bank Negara Malaysia (BNM).

1. AML/CFT Legislation and Regulatory Framework

The primary legislative and regulatory instruments are:

  • Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act (AMLATFPUAA) 2001: This is the overarching legislation that imposes AML/CFT obligations on designated "reporting institutions," which include VASPs.
  • AML/CFT and Targeted Financial Sanctions for Financial Institutions (AML/CFT TFS for FIs) Policy Document (BNM Policy Document): Issued by Bank Negara Malaysia, this comprehensive policy document provides detailed guidance and requirements for reporting institutions to comply with AMLATFPUAA 2001. This document has specific sections/appendices applicable to "Digital Currencies" or "Virtual Assets."
  • Capital Markets and Services Act 2007 (CMSA): For digital assets that are deemed "securities," the Securities Commission Malaysia (SC) regulates entities like Digital Asset Exchanges (DAX) under this Act and its accompanying guidelines. These entities are also subject to specific AML/CFT requirements imposed by the SC.
  • Guidelines on Recognised Markets (SC Guidelines): Specifically for operators of recognised markets, including DAX, detailing operational, conduct, and AML/CFT requirements.

2. Regulating Authorities

  • Bank Negara Malaysia (BNM):
    • Role: The central bank of Malaysia and the primary regulator for AML/CFT compliance across all reporting institutions, including VASPs, under the AMLATFPUAA 2001. BNM also houses the Financial Intelligence Unit (FIU) responsible for receiving Suspicious Transaction Reports (STRs).
    • URL: https://www.bnm.gov.my/
  • Securities Commission Malaysia (SC):
    • Role: Regulates the capital markets in Malaysia. The SC specifically licenses and oversees Digital Asset Exchanges (DAX) and other entities involved in the offering or trading of digital assets that are classified as securities. SC-regulated entities must comply with both SC-specific AML/CFT requirements and the broader BNM framework.
    • URL: https://www.sc.com.my/

3. Definition of Virtual Asset Service Providers (VASPs)

Malaysia generally aligns with the Financial Action Task Force (FATF) definition. Under the BNM Policy Document, entities dealing with "Digital Currencies" (which include virtual assets) are considered reporting institutions if they perform activities such as:

  • Exchanges between digital currencies and fiat currencies.
  • Exchanges between one or more forms of digital currencies.
  • Transfers of digital currencies.
  • Safekeeping and/or administration of digital currencies or instruments enabling control over digital currencies.
  • Participation in and provision of financial services related to an issuer’s offer and/or sale of a digital currency.

This includes entities like Digital Asset Exchanges, wallet providers, and certain ICO/STO platforms.

4. Customer Due Diligence (CDD) Requirements

VASPs in Malaysia must implement a risk-based approach to CDD, which includes:

  • Customer Identification and Verification:
    • Obtain and verify the identity of individual customers (name, address, date of birth, nationality, identification document details, contact information).
    • For legal entities/corporate customers, obtain and verify: legal name, legal form, proof of existence (e.g., certificate of incorporation), address of registered office, names of directors/partners/trustees, details of shareholders and beneficial owners, and constitution/governing documents.
    • For partnerships and trusts, similar information must be collected for partners, trustees, settlors, and beneficiaries.
  • Beneficial Ownership: Identify and verify the ultimate beneficial owner (UBO) for all corporate and legal arrangements. This involves looking through layers of ownership to identify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.
  • Purpose and Intended Nature of Business Relationship: Understand the rationale behind the customer's request to use the VASP's services and the anticipated level and type of activity.
  • Source of Funds/Wealth: For higher-risk customers or transactions, obtain information on the source of funds or source of wealth.
  • Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure consistency with the VASP's knowledge of the customer, their business, risk profile, and source of funds. Update customer information regularly.
  • Non-Face-to-Face (NFF) Customers: Given the online nature of many VASPs, robust measures for NFF CDD are crucial, including multi-factor authentication, video verification, and cross-referencing with reliable independent sources.
  • Politically Exposed Persons (PEPs): Implement Enhanced Due Diligence (EDD) measures for PEPs, their family members, and close associates, including obtaining senior management approval to establish or continue the relationship and taking reasonable measures to establish the source of wealth and funds.

5. Enhanced Due Diligence (EDD) Requirements

EDD is required in situations deemed higher risk, including but not limited to:

  • High-Risk Customers: PEPs, customers from high-risk jurisdictions (e.g., those identified by FATF), customers involved in cash-intensive businesses.
  • High-Risk Products/Services: Products or services that facilitate anonymity (e.g., privacy coins, mixing services).
  • High-Risk Delivery Channels: Non-face-to-face relationships without sufficient mitigating controls.
  • Large, Complex, or Unusual Transactions: Transactions that have no apparent economic or lawful purpose.
  • Cross-border Correspondent Relationships: If applicable, especially with VASPs in high-risk jurisdictions.

EDD measures may include: collecting additional identification information, verifying information using additional sources, conducting site visits, obtaining senior management approval for the relationship, and intensified ongoing monitoring.

6. Suspicious Transaction Reporting (STR)

  • Obligation: All VASPs, as reporting institutions, are legally obliged to report any transaction (including attempted transactions) that they know or have reason to suspect is related to money laundering, terrorism financing, or proceeds of unlawful activities.
  • Recipient: Reports must be submitted to the Financial Intelligence Unit (FIU) within Bank Negara Malaysia.
  • No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a STR has been or will be made.
  • Reporting Thresholds: While there are no specific monetary thresholds for STRs (suspicion is key), BNM's policy document also outlines Currency Transaction Reports (CTR) for cash transactions exceeding a certain amount. However, for most virtual asset transactions, suspicion drives the reporting.

7. Record-Keeping Obligations

VASPs must maintain comprehensive records to assist in investigations and demonstrate compliance:

  • Customer Identification Data: All records obtained during CDD and EDD (identification documents, verification records, beneficial ownership information) must be kept for at least five (5) years after the business relationship has ended.
  • Transaction Records: Records of all transactions (date, type, amount, parties involved, digital asset addresses, hash IDs) must be kept for at least five (5) years from the date of the transaction.
  • STRs and Internal Reports: Records of all STRs filed and any internal suspicious activity reports or investigations.
  • AML/CFT Policies and Procedures: Records of all policies, procedures, risk assessments, training materials, and audit reports.

8. Other Key AML/CFT Obligations

  • Internal Policies and Procedures: Develop and implement robust internal AML/CFT policies, procedures, and controls commensurate with the VASP's risk profile.
  • Compliance Officer: Appoint a dedicated Compliance Officer (often referred to as an Money Laundering Reporting Officer - MLRO) responsible for overseeing AML/CFT compliance, receiving internal suspicious activity reports, and submitting STRs to the FIU.
  • Employee Training: Provide regular and comprehensive AML/CFT training to all relevant employees to ensure they understand their obligations and can identify suspicious activities.
  • Independent Audit: Periodically review and audit the effectiveness of the VASP's AML/CFT programs.
  • Sanctions Screening: Implement measures to screen customers and transactions against targeted financial sanctions lists issued by the United Nations Security Council (UNSC) and domestic authorities to prevent terrorism financing and proliferation financing.

In summary, VASPs operating in Malaysia are subject to a comprehensive AML/CFT framework, primarily overseen by Bank Negara Malaysia, with specific oversight by the Securities Commission for regulated digital asset exchanges. Compliance with AMLATFPUAA 2001 and the BNM Policy Document is critical for these entities to operate legally and avoid severe penalties.

Source Data

60%

**Capital Markets and Services Act 2007 (CMSA):** For digital assets that are deemed "securities," the Securities Commission Malaysia (SC) regulates entities like Digital Asset Exchanges (DAX) under this Act and its accompanying guidelines. These entities are also subject to specific AML/CFT requirements imposed by the SC.

60%

**Guidelines on Recognised Markets (SC Guidelines):** Specifically for operators of recognised markets, including DAX, detailing operational, conduct, and AML/CFT requirements.

60%

**Role:** The central bank of Malaysia and the primary regulator for AML/CFT compliance across all reporting institutions, including VASPs, under the AMLATFPUAA 2001. BNM also houses the Financial Intelligence Unit (FIU) responsible for receiving Suspicious Transaction Reports (STRs).

60%

**Role:** Regulates the capital markets in Malaysia. The SC specifically licenses and oversees Digital Asset Exchanges (DAX) and other entities involved in the offering or trading of digital assets that are classified as securities. SC-regulated entities must comply with both SC-specific AML/CFT requirements and the broader BNM framework.

60%

Exchanges between digital currencies and fiat currencies.

60%

Exchanges between one or more forms of digital currencies.

60%

Safekeeping and/or administration of digital currencies or instruments enabling control over digital currencies.

60%

Participation in and provision of financial services related to an issuer’s offer and/or sale of a digital currency.

60%

Obtain and verify the identity of individual customers (name, address, date of birth, nationality, identification document details, contact information).

60%

For legal entities/corporate customers, obtain and verify: legal name, legal form, proof of existence (e.g., certificate of incorporation), address of registered office, names of directors/partners/trustees, details of shareholders and beneficial owners, and constitution/governing documents.

60%

For partnerships and trusts, similar information must be collected for partners, trustees, settlors, and beneficiaries.

60%

**Beneficial Ownership:** Identify and verify the ultimate beneficial owner (UBO) for all corporate and legal arrangements. This involves looking through layers of ownership to identify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.

60%

**Purpose and Intended Nature of Business Relationship:** Understand the rationale behind the customer's request to use the VASP's services and the anticipated level and type of activity.

60%

**Source of Funds/Wealth:** For higher-risk customers or transactions, obtain information on the source of funds or source of wealth.

60%

**Ongoing Monitoring:** Continuously monitor the business relationship and transactions to ensure consistency with the VASP's knowledge of the customer, their business, risk profile, and source of funds. Update customer information regularly.

60%

**Non-Face-to-Face (NFF) Customers:** Given the online nature of many VASPs, robust measures for NFF CDD are crucial, including multi-factor authentication, video verification, and cross-referencing with reliable independent sources.

60%

**Politically Exposed Persons (PEPs):** Implement Enhanced Due Diligence (EDD) measures for PEPs, their family members, and close associates, including obtaining senior management approval to establish or continue the relationship and taking reasonable measures to establish the source of wealth and funds.

60%

**High-Risk Customers:** PEPs, customers from high-risk jurisdictions (e.g., those identified by FATF), customers involved in cash-intensive businesses.

60%

**High-Risk Products/Services:** Products or services that facilitate anonymity (e.g., privacy coins, mixing services).

60%

**High-Risk Delivery Channels:** Non-face-to-face relationships without sufficient mitigating controls.

60%

**Large, Complex, or Unusual Transactions:** Transactions that have no apparent economic or lawful purpose.

60%

**Cross-border Correspondent Relationships:** If applicable, especially with VASPs in high-risk jurisdictions.

60%

**Obligation:** All VASPs, as reporting institutions, are legally obliged to report any transaction (including attempted transactions) that they know or have reason to suspect is related to money laundering, terrorism financing, or proceeds of unlawful activities.

60%

**Recipient:** Reports must be submitted to the Financial Intelligence Unit (FIU) within Bank Negara Malaysia.

60%

**No Tipping-Off:** VASPs and their employees are prohibited from disclosing to the customer or any third party that a STR has been or will be made.

60%

**Reporting Thresholds:** While there are no specific monetary thresholds for STRs (suspicion is key), BNM's policy document also outlines Currency Transaction Reports (CTR) for cash transactions exceeding a certain amount. However, for most virtual asset transactions, suspicion drives the reporting.

60%

**Customer Identification Data:** All records obtained during CDD and EDD (identification documents, verification records, beneficial ownership information) must be kept for at least **five (5) years** after the business relationship has ended.

60%

**Transaction Records:** Records of all transactions (date, type, amount, parties involved, digital asset addresses, hash IDs) must be kept for at least **five (5) years** from the date of the transaction.

60%

**STRs and Internal Reports:** Records of all STRs filed and any internal suspicious activity reports or investigations.

60%

**AML/CFT Policies and Procedures:** Records of all policies, procedures, risk assessments, training materials, and audit reports.

60%

**Internal Policies and Procedures:** Develop and implement robust internal AML/CFT policies, procedures, and controls commensurate with the VASP's risk profile.

60%

**Compliance Officer:** Appoint a dedicated Compliance Officer (often referred to as an Money Laundering Reporting Officer - MLRO) responsible for overseeing AML/CFT compliance, receiving internal suspicious activity reports, and submitting STRs to the FIU.

60%

**Employee Training:** Provide regular and comprehensive AML/CFT training to all relevant employees to ensure they understand their obligations and can identify suspicious activities.

60%

**Independent Audit:** Periodically review and audit the effectiveness of the VASP's AML/CFT programs.

60%

**Sanctions Screening:** Implement measures to screen customers and transactions against targeted financial sanctions lists issued by the United Nations Security Council (UNSC) and domestic authorities to prevent terrorism financing and proliferation financing.

60%

**Violation Type:** Operating a Digital Asset Exchange (DAX) without registration/license, which is a violation under the Capital Markets and Services Act 2007. The SC considers digital assets as securities, and operating a platform for trading them requires authorization.

60%

**Penalty Amount:** No explicit monetary fine was announced at the time of the public reprimand. The penalties were operational: a public reprimand, an order to cease all operations in Malaysia, disable access to its website and mobile applications, and cease all media and marketing activities targeting Malaysian investors.

60%

**Outcome:** Binance was forced to shut down its direct operations in Malaysia. Malaysian users were advised to withdraw their funds. The action led Binance to later pursue a compliant pathway to re-enter the Malaysian market by acquiring a stake in and partnering with a licensed local Digital Asset Exchange (DAX), MX Global, demonstrating the effectiveness of the SC's enforcement in driving regulatory compliance.

60%

**Penalty Amount:** Typically no specific monetary penalty is announced publicly for being added to the alert list. The "penalty" is a public warning, which often leads to the platform being unable to operate effectively in Malaysia and subsequent cessation of operations or blocking of access.

60%

**Role:** Primarily responsible for the financial system's stability, payment systems, and Anti-Money Laundering/Counter-Terrorism Financing (AML/CFT). BNM designates "virtual asset service providers" (VASPs) as reporting institutions under the AMLATFPUAA, requiring them to report suspicious transactions and adhere to AML/CFT measures. BNM also monitors the broader implications of digital assets on financial stability, monetary policy, and payment systems, including stablecoins and central bank digital currencies (CBDCs).

9 fact(s) collected but awaiting source verification. View in explorer →

Sources & Attribution

This article was generated by SearXNG+LLM .

Primary Sources

[1] www.bnm.gov.my (government-public)

Based on reporting by

[2] Unknown — www.sc.com.my

Edit History

2026-04-22 — auto-publish-pipeline: published — Auto-published: grade B

This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →