[codicts-css-switcher id=”346″]

Global Law Experts Logo
corporate compliance iraq

How to Build a Corporate Compliance & AML Program in Iraq (2026), Step-by-step Guide

By Global Law Experts
– posted 3 hours ago

Corporate compliance Iraq is now a threshold requirement for doing business, borrowing money and attracting cross-border investment, not an optional overlay. In 2026, three forces converge: intensified beneficial ownership (UBO) disclosure expectations, renewed anti-money laundering scrutiny from international partners and lenders, and rising foreign capital seeking exposure to Iraq’s reconstruction and energy sectors. This guide translates the regulatory framework into a workable, step-by-step programme that in-house counsel, compliance officers, investors and banks can implement without guesswork. It sets out numbered steps, required documents, realistic timelines and cost ranges, together with lender-specific notes at each relevant stage. The emphasis throughout is on proportionality, building controls that match your company’s size and risk profile.

Because regulatory requirements and official procedures change, verify each procedural point against current primary sources before acting.

Overview, Why build a corporate compliance & AML programme in Iraq?

The case for a formal compliance programme in Iraq rests on three drivers. The first is regulatory: Iraq operates an anti-money laundering and counter-financing of terrorism regime built on the Anti-Money Laundering and Counter-Terrorism Financing Law and overseen by the Central Bank of Iraq (CBI) and its associated financial intelligence function, which set reporting obligations, customer due diligence standards and sanctions expectations for regulated entities. International assessments by the Financial Action Task Force (FATF) and its regional body shape how these obligations are enforced and how counterparties abroad view Iraqi risk.

The second driver is commercial. Banks and lenders increasingly gate credit, correspondent relationships and cross-border payments on the borrower’s ability to demonstrate a functioning compliance framework. A company that cannot produce a risk assessment, UBO records and a suspicious-transaction reporting process will struggle to close financing or open the banking lines it needs to operate.

The third driver is consequence. Weak controls expose companies to regulatory penalties, frozen transactions, reputational damage and, for individuals, potential personal liability. A properly built corporate compliance Iraq programme reduces these exposures and turns compliance from a cost centre into a transaction enabler. The World Bank’s country and governance assessments underline that credible institutional controls materially affect Iraq’s investment climate and the confidence of external capital.

Who should read this, companies, in-house counsel and lenders

This guide is written for in-house counsel and compliance officers designing or upgrading a programme, for foreign investors assessing operational risk before entry, and for banks and lenders underwriting Iraqi exposure. Each group needs the same core artefacts, a risk assessment, verified UBO data, documented policies and monitoring evidence, so the steps below serve all of them, with lender expectations flagged where they diverge.

Eligibility, which companies must comply and when to implement a programme

Regulated financial institutions, banks and money service businesses, carry the most prescriptive obligations under CBI supervision and must maintain full AML/CFT programmes. But the practical reach of corporate compliance in Iraq extends well beyond the regulated perimeter. Any company that seeks bank credit, holds correspondent banking access, engages in cross-border trade, or operates in higher-risk sectors (extractives, construction, logistics and government contracting) will be required by its counterparties to evidence equivalent controls even where the statute does not directly bind it.

The practical trigger is therefore rarely the law alone; it is the moment a company needs a bank, a lender or a foreign partner. Prudent companies implement a proportionate programme at incorporation or before their first financing round rather than retrofitting under deal pressure. The right question is not whether you are technically caught, but whether your bank, your lender or your investor will require the programme, and in 2026 the answer is almost always yes.

Foreign investor approvals and registrations

Foreign investors typically need to complete commercial registration through the Companies Registrar within the relevant Iraqi ministry and, depending on sector and structure, obtain approvals coordinated through the responsible ministries and, in some cases, the National Investment Commission or a provincial investment commission. These registration steps produce the very documents, certificate of incorporation, company charter, shareholder register, that a compliance programme depends on. Confirm current approval pathways against official ministry guidance before filing, because sector-specific licensing can add steps. A dedicated guide on AML due diligence & KYC process for foreign investors covers the entry-stage due diligence in detail.

Step-by-step: build your corporate compliance Iraq programme

The following twelve steps take a company from board decision to a tested, self-improving programme. Treat them as sequential but overlapping: governance and risk assessment come first, and several later steps run in parallel. Scale the depth of each step to your risk profile, a small trading company needs less than a bank, but every step should be addressed and documented.

  1. Secure senior management commitment and governance. The programme begins with a board or senior-management resolution approving the compliance framework, allocating budget and setting the tone from the top. Document this in board minutes. A short resolution should record: approval of the AML/CFT policy, appointment of the compliance officer, the reporting line to the board, and a commitment to remediation funding. Lenders routinely ask for these minutes during credit underwriting as evidence that compliance is owned at the highest level rather than delegated informally.

    Appoint a compliance officer or designate an accountable person

    Name a compliance officer in Iraq with clear duties: maintaining the risk assessment, overseeing KYC, filing suspicious transaction reports, coordinating training and reporting to the board. The role should have a direct line to senior management and sufficient independence to escalate concerns. In smaller companies, one accountable person may combine this with another senior role, but the responsibility and authority must be documented.

  2. Conduct a risk assessment. Assess risk across five dimensions: country/geography, customer type, product and service, delivery channel, and transaction. This risk-based approach is the foundation of everything that follows and is expected under FATF methodology and CBI supervision. Record findings in a dated risk assessment report and use it to justify where you apply standard versus enhanced measures. Lenders will read this report to understand your residual risk.

    Risk matrix template, including PEP and sanctions screening

    A workable matrix scores each customer or relationship low, medium or high against the five dimensions, then maps a required due-diligence level to each band. Build in explicit flags for politically exposed persons (PEPs) and for sanctions screening against applicable lists, treating any positive match as an automatic escalation to enhanced due diligence and senior review.

  3. Draft policies and procedures. Convert the risk assessment into written policies: an overarching AML/CFT policy, plus procedures for KYC, enhanced due diligence (EDD), transaction monitoring, sanctions screening and record keeping. Policies should state who does what, when, and how exceptions are approved. Keep them concise enough to be used, and version-control every change.

    Policy template essentials

    At minimum the AML/CFT policy should cover: scope and legal basis; the risk-based approach; customer acceptance rules; CDD and EDD triggers; UBO identification standards; sanctions and PEP screening; suspicious transaction reporting; record retention; training obligations; and the compliance officer’s authority. Cross-reference the detailed procedures rather than duplicating them.

  4. Identify and verify beneficial ownership (UBO). Determine the natural persons who ultimately own or control each customer and each of your own corporate shareholders, and verify their identity against reliable documents. UBO transparency is the single fastest-moving area of expectation in Iraq for 2026, and lenders increasingly refuse to proceed without a clean UBO chain. Our step-by-step How To Verify UBO (procedural guide) sets out the mechanics in full.

    Practical steps for verifying UBOs in Iraq

    Collect a signed UBO declaration; obtain the shareholder register, company charter and share certificates to trace ownership through each layer; and verify each ultimate owner’s identity with a national ID or passport plus proof of address. Where control is exercised without majority ownership, through voting rights, agreements or senior appointments, record the basis of control. Retain the evidence, not just the conclusion.

  5. Operate customer due diligence, enhanced due diligence and ongoing monitoring. Apply standard CDD to all customers at onboarding, EDD to high-risk relationships (including PEPs, complex structures and high-risk jurisdictions), and refresh both on a risk-based cycle. Ongoing monitoring means keeping records current and revisiting risk ratings when behaviour or ownership changes.

    KYC forms and red flags for Iraq operations

    A KYC form should capture legal name, registration details, ownership and control, source of funds and wealth for higher-risk cases, expected activity, and screening results. Red flags for Iraq operations include cash-intensive dealings inconsistent with the business, reluctance to disclose UBOs, use of opaque offshore layers, and transactions routed through unrelated jurisdictions without commercial logic.

  6. Build internal controls, segregation of duties and record keeping. Separate the functions that initiate, approve and record transactions so no single person controls a whole chain. Maintain complete, retrievable records of CDD files, risk assessments and reporting decisions.

    Retention periods and data protection considerations

    Retain customer and transaction records for the period required under Iraqi law and by your regulator, confirm the exact retention period against Ministry of Justice and CBI guidance, as it drives how long files, IDs and reporting evidence must be kept accessible. Store personal data securely and limit access on a need-to-know basis.

  7. Monitor transactions and report suspicious activity. Screen transactions against your risk rules and escalate anomalies. Where suspicion of money laundering or terrorist financing arises, file a suspicious transaction report (STR) with Iraq’s financial intelligence unit through the process set by the Central Bank of Iraq.

    How and when to report, procedural checklist

    The reporting sequence is: the staff member escalates internally to the compliance officer; the compliance officer assesses and, if suspicion is confirmed, prepares and submits the STR to the financial intelligence unit via the CBI-designated channel; the company preserves the filing and avoids tipping off the customer; and the decision, whether or not to report, is documented. Confirm the current submission channel and any formatting requirements against CBI guidance before your first filing.

  8. Train and communicate. Deliver induction training to all relevant staff and refresher training on a regular cadence, with tailored modules for higher-risk roles such as onboarding, payments and relationship management. Record attendance and test comprehension so you can evidence competence to regulators and lenders.
  9. Commission independent audit and testing. Have the programme independently tested, by internal audit or an external firm, to confirm that policies are followed in practice, not just on paper. Set a defined scope and frequency proportionate to risk, and feed findings into remediation.
  10. Establish remediation and disciplinary procedures. When testing or monitoring reveals gaps, manage them through a documented case-management process with owners, deadlines and sign-off. Link failures of individual staff to clear disciplinary consequences so that accountability is real.
  11. Liaise with banks and lenders. Treat your compliance evidence as a financing asset. Before credit closes, lenders typically request the risk assessment, AML/CFT policy, UBO records, board minutes appointing the compliance officer, and sample CDD files. Assemble a standing due-diligence pack so financing is not delayed by document gathering. Our guide to lender due diligence & documentation requirements for Iraq transactions details what underwriters expect.
  12. Review periodically and improve continuously. Schedule at least an annual review of the whole programme, plus interim reviews when the law changes or the business enters new markets or products. Update the risk assessment first, then cascade changes through policies, monitoring and training.

A recurring decision throughout these steps is whether to staff the compliance function in-house or outsource part of it. The comparison below sets out the trade-offs.

In-house versus outsourced compliance functions

Function In-house Outsourced / shared
Cost Higher fixed salary and overhead Lower fixed cost; pay-as-you-go
Control & integration Greater control; faster internal coordination Specialist expertise; potential latency
Local law depth Dependent on the hire Often broader comparative experience
Confidentiality Full internal control Requires robust NDAs and controls
Recommended for Large corporations, banks, long-term investment SMEs, start-ups, short-term projects, specialised tasks

Required documents and compliance checklist for Iraq

The table below lists the core documents needed to set up the programme, verify UBOs and satisfy lender due diligence. Assembling these into a single, version-controlled corporate compliance checklist for Iraq shortens onboarding and financing timelines and gives you an audit-ready file.

Document Purpose Who provides
Certificate of incorporation / commercial registration Legal existence and entity details Company
Memorandum & articles / company charter Ownership structure and governance Company
Shareholder register & share certificates Identify shareholders and shareholdings Company
Beneficial ownership declaration(s) / UBO form UBO identification and verification Company / beneficial owners
National ID / passport copies for UBOs and key controllers Identity verification (KYC) Beneficial owners
Recent utility bills / proof of address for principals Address verification Beneficial owners
AML/CFT policy & KYC procedures Internal controls evidence Company
Risk assessment report Demonstrates risk-based approach Company / risk team
Customer acceptance & CDD files (sample) Evidence of due diligence Company
Board minutes appointing compliance officer & approving policy Governance evidence Company
Power of attorney / mandates (if a third party verifies) Authority to act Company / agent

The forthcoming Iraq Corporate Compliance & AML Checklist (2026) collects these items into a single working document.

Timeline & deadlines, implementation roadmap

A first-time programme can move from board sign-off to first independent testing in roughly three to four months, with individual workstreams running in parallel. UBO verification and transaction-monitoring set-up are the usual bottlenecks, particularly where ownership is layered across jurisdictions. Where a lender has imposed conditions, remediation must complete before credit closes, so start the document pack early. The durations below are typical spans for a mid-sized company and should be scaled to complexity.

Step Responsible party Typical duration
1. Board sign-off & appoint compliance officer Board / senior management 1–2 weeks
2. Initial risk assessment (company-level) Compliance officer + external consultant 2–4 weeks
3. Draft policies & procedures Compliance officer + counsel 2–6 weeks
4. UBO collection & verification Company / external verification agent 2–8 weeks
5. Implement KYC/CDD processes & forms Compliance officer / operations 1–3 weeks
6. Transaction monitoring tools (selection & set-up) IT + compliance 4–12 weeks
7. Staff training roll-out HR + compliance 1–2 weeks per cohort
8. Independent audit / first testing External auditor or internal audit 2–4 weeks
9. Remediation / corrective action Compliance officer / management 2–12 weeks

Costs & fees

Costs vary widely with company size, risk profile and whether functions are staffed in-house or outsourced, and with location, Baghdad salaries and advisory rates typically run higher than in the provinces. All figures below are broad estimates in US dollars for 2026 planning purposes only; local currency movements and market conditions will affect actual pricing, and multi-year software or advisory commitments can shift the totals materially. Obtain current quotations before budgeting.

Item Indicative cost range (USD) Notes
Compliance officer (annual salary) Varies with experience and location Baghdad rates typically higher than provinces
External legal / compliance advisory (initial setup) One-off; scope dependent Obtain a scoped quotation
AML/KYC software / monitoring subscription Per year; small providers to enterprise solutions Pricing tiered by volume and features
External UBO / identity verification (per beneficial owner) Per person Depends on checks and registry access
Independent compliance audit / testing Per engagement Frequency and scope vary
Training (per cohort) Per cohort Depends on trainer and modules
Filing / registration fees (where applicable) As set by the relevant agency Confirm current official fees

What changes in 2026, legal & regulatory updates to watch

The direction of travel for corporate compliance in Iraq during 2026 is toward greater transparency and tighter lender gating. Industry observers expect continued intensification of UBO disclosure expectations, closer alignment with FATF recommendations, and evolving Central Bank of Iraq guidance on reporting and sanctions screening. The likely practical effect will be that banks and correspondent partners demand more granular UBO evidence and more robust monitoring before extending credit or clearing cross-border payments. Companies should monitor CBI and FATF publications, confirm any amendments to the anti-money laundering framework through the Ministry of Justice and the Official Gazette (al-Waqa’i al-Iraqiya), and schedule an interim programme review whenever a material change is published rather than waiting for the annual cycle.

Common pitfalls and how to avoid them

  • No genuine board buy-in. A policy signed but not funded or owned at senior level fails under scrutiny. Fix it by recording a real resolution, allocating budget, and giving the compliance officer authority to escalate.
  • Weak UBO checks. Accepting a declaration without tracing ownership through each layer is the most common failing, and the one lenders catch first. Verify against the shareholder register and identity documents, and record the basis of control.
  • Inadequate record keeping. Reaching a correct conclusion but failing to retain the underlying evidence leaves you unable to prove compliance. Keep the files, not just the outcome, for the full statutory retention period.
  • Insufficient or generic training. One-off, untailored training does not change behaviour in higher-risk roles. Run role-specific modules on a regular cadence and test comprehension.
  • Ignoring banks’ due diligence needs. Treating lender requests as an afterthought delays financing. Maintain a standing due-diligence pack so documents are ready before credit closes.
  • Treating the programme as static. A framework that is never reviewed drifts out of line with the law and the business. Schedule annual and event-driven reviews and update the risk assessment first.

Conclusion

Building a corporate compliance Iraq programme in 2026 is no longer a matter of regulatory box-ticking, it is the foundation of bankability, cross-border credibility and access to foreign capital. Work through the twelve steps in sequence, anchor each control in a documented risk assessment, verify UBOs rigorously, and keep the evidence retrievable. Assemble a standing due-diligence pack so financing is never delayed, monitor CBI and FATF developments, and review the whole framework at least annually. A proportionate, well-documented programme protects the company, satisfies lenders and turns corporate compliance in Iraq from a hurdle into a competitive advantage.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Furat Kuba at Al-Nesoor Law Firm, a member of the Global Law Experts network.

Sources

  1. Central Bank of Iraq (CBI)
  2. Financial Action Task Force (FATF)
  3. United Nations Office on Drugs and Crime (UNODC)
  4. Iraq Ministry of Justice
  5. World Bank, Iraq

FAQs

Do all companies in Iraq need an AML programme?
Regulated financial institutions must maintain full AML/CFT programmes under Central Bank of Iraq supervision. In practice, almost any company seeking bank credit, cross-border trade or foreign investment will be required by its counterparties to evidence equivalent controls. See the Eligibility section above for the practical triggers.
Obtain a signed UBO declaration, trace ownership through the shareholder register, company charter and share certificates, and verify each ultimate owner’s identity with a national ID or passport plus proof of address. Record the basis of any control exercised without majority ownership. Our How To Verify UBO guide walks through the full process.
Bring in external help for first-time programme setup, when onboarding high-risk customers or complex ownership structures, and when a bank or lender imposes conditions before financing. Obtain a scoped quotation for initial advisory work, as costs depend heavily on the size and complexity of the engagement.
Keep CDD files, UBO evidence, risk assessments, transaction records and reporting decisions. The precise retention period is set by Iraqi law and your regulator, so confirm it against Ministry of Justice and Central Bank of Iraq guidance and store records securely with need-to-know access.
Staff escalate internally to the compliance officer, who assesses the matter and, if suspicion is confirmed, files a suspicious transaction report with Iraq’s financial intelligence unit through the channel designated by the Central Bank of Iraq. Preserve the filing, avoid tipping off the customer, and document the decision. Confirm the current submission channel against CBI guidance before your first report.
Watch for cash-intensive activity inconsistent with the stated business, reluctance to disclose beneficial owners, opaque offshore layering without commercial logic, transactions routed through unrelated jurisdictions, and rapid movement of funds with no economic purpose. Escalate any red flag to the compliance officer for assessment and possible reporting.
foreign law firms india
By Global Law Experts

posted 24 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Build a Corporate Compliance & AML Program in Iraq (2026), Step-by-step Guide

Send welcome message

Custom Message