Our Expert in Malaysia
No results available
VASP AML Malaysia compliance has moved from a box-ticking exercise to a supervisory priority, and firms that treat it as an afterthought now face inspection and enforcement risk. This guide sets out a practitioner-level, inspector-ready build for virtual asset service providers (VASPs) operating in Malaysia in 2026, mapping the legal obligations under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA) and the expectations of Bank Negara Malaysia (BNM) and the Securities Commission Malaysia (SC) to concrete operational controls. You will find numbered steps, document checklists, cost and timeline tables, and the evidence that supervisors expect to see.
It is written for founders, compliance officers, legal and risk teams who need to stand up a defensible program quickly.
Who this is for: Founders, compliance officers, legal teams and risk officers at VASPs and digital asset exchanges in Malaysia seeking an actionable, inspector-ready AML and KYC build for 2026.
Outcome: A stepwise checklist and template structure to design policies, processes and evidence required for licensing, supervision and suspicious transaction reporting obligations.
A VASP AML Malaysia program exists to detect, prevent and report money laundering and terrorist financing. It must satisfy the statutory obligations in AMLA 2001, reporting, recordkeeping and customer due diligence, and the supervisory expectations published by the SC for digital asset exchanges and by BNM in its wider AML/CFT framework. Above all, a modern program must be risk-based and fully documented: every control should trace back to an identified risk, and every decision should leave an audit trail.
The division of responsibility matters when designing your controls. In Malaysia, digital assets that fall within the prescribed definition are treated as securities, and the SC regulates digital asset exchanges (DAX operators), initial exchange offerings and digital asset custodians under the Capital Markets and Services Act 2007 and the relevant SC guidelines. BNM is a key AML/CFT policy authority and houses the Financial Intelligence and Enforcement Department, which operates Malaysia’s financial intelligence function and receives suspicious transaction reports. A VASP AML Malaysia build should therefore reconcile SC licensing-stage expectations with BNM’s reporting and AML/CFT supervisory framework, rather than treating them as separate silos.
Any business that carries on a regulated digital asset activity in Malaysia falls within the AML/CFT net. In practice this covers three broad functions: exchange and trading of digital assets, custody and safekeeping of client assets, and transfer or remittance of virtual assets between parties. If your business touches any of these, assume AMLA obligations apply and build accordingly.
AMLA 2001 imposes reporting institution obligations, including customer due diligence, recordkeeping and suspicious transaction reporting, on designated reporting institutions. The SC’s digital asset framework, together with the relevant SC guidelines, determines when a firm must be registered, recognised or approved to operate a digital asset exchange or related service in Malaysia. The statutory text and the relevant sections of AMLA are published by the Attorney-General’s Chambers of Malaysia, and firms should read the licensing triggers in conjunction with the reporting-institution definitions and the SC’s AML/CFT guidelines applicable to digital asset activities.
Cross-border agents and intermediaries that facilitate access to Malaysian customers should not assume they sit outside scope simply because servers or entities are offshore; operating a digital asset exchange in Malaysia without SC approval may itself be unlawful.
Some firms operate hybrid structures where part of the group is licensed overseas. An overseas licence does not displace Malaysian obligations for activity directed at Malaysian customers. Where a group relies on a parent’s global AML program, the Malaysian entity must still demonstrate local governance, a local compliance function, and controls calibrated to Malaysian risk and reporting channels. The Financial Action Task Force (FATF) standards on VASPs reinforce that the registration or licensing obligation attaches to the jurisdiction where the VASP is created, or where it does business.
This is the operational core. Follow the steps in sequence, each builds on the previous one, and skipping ahead (for example, buying monitoring software before completing a risk assessment) is a common cause of wasted spend and inspection findings.
Start with governance. Draft an AML/CFT policy and a separate KYC policy, and have both approved by the board, approval at board level is the single most important piece of evidence of accountability. Appoint a compliance officer (often performing the Money Laundering Reporting Officer function) with a written role description that sets out independence, reporting lines and escalation authority. The officer must have genuine standing to halt onboarding, freeze accounts and file reports without commercial interference.
Establish internal audit and reporting lines so that the compliance officer reports periodically to the board or a board committee. Counsel plays a defined role here: a fintech lawyer advises on the statutory interpretation of AMLA obligations, drafts policy language that will withstand supervisory scrutiny, and structures the escalation and tipping-off rules correctly. A directory of advocates and solicitors admitted to practise in Malaysia is maintained by the Malaysian Bar.
The risk assessment is the foundation of a VASP AML Malaysia program, every subsequent control should be justified by reference to it. Conduct an enterprise-wide assessment covering four dimensions: customers (retail, corporate, PEPs), products (spot trading, custody, transfers, staking), geographies (customer and counterparty jurisdictions, high-risk and sanctioned territories) and delivery channels (remote onboarding, API access, agents).
Define risk tiers and a scoring matrix so that each customer and product is assigned a residual risk rating. Document the methodology and the review frequency, at minimum annually, plus trigger-based reviews when you launch a new product, enter a new market, or experience a material incident. The sample scoring approach below illustrates how crypto-native factors feed into tiering.
| Risk factor | Low (1) | Medium (2) | High (3) |
|---|---|---|---|
| Customer type | Verified retail, domestic | SME corporate | PEP, complex ownership |
| Geography | Domestic / low-risk | Standard foreign | High-risk / sanctioned jurisdiction |
| Transaction pattern | Low value, stable | Moderate velocity | High velocity, structuring indicators |
| Wallet exposure | Clean on-chain history | Indirect exposure | Mixers, darknet, sanctioned addresses |
KYC procedures in Malaysia for VASPs must identify and verify every customer before the business relationship begins. The onboarding flow should capture identification data, verify it against reliable independent sources, and establish beneficial ownership for corporate customers. For individuals, collect government-issued identity documents and proof of address; for entities, collect incorporation documents, directors and beneficial owner details.
Remote onboarding is the norm for VASPs, so build digital ID verification with liveness detection, document authentication, and automated screening against politically exposed person (PEP) lists and sanctions lists. Your VASP KYC Malaysia flow should capture the evidence, not just the outcome, so that an inspector can reconstruct how each identity was confirmed.
Apply a tiered intensity of due diligence based on the risk assessment. The following items form a minimum onboarding evidence checklist:
EDD applies to higher-risk relationships. Triggers include PEP status, high-value or high-velocity transactions, funds originating from high-risk jurisdictions, and on-chain exposure to mixers or obfuscation services. EDD steps include obtaining and documenting source of funds and source of wealth, enhanced ongoing monitoring, and senior management approval before onboarding or continuing the relationship. For crypto-specific risk, request the rationale for large transfers and corroborate the on-chain origin of funds using blockchain analytics.
Transaction monitoring converts your risk assessment into automated detection. Design rules that reflect crypto-native typologies: unusual velocity, structuring just below reporting thresholds, large single deposits or withdrawals, rapid pass-through activity, address clustering, and interaction with mixing services or sanctioned addresses. The FATF’s VASP typologies provide a useful reference set for rule design.
On the technology side, integrate blockchain forensic and chain-analytics vendors alongside your AML screening engine so that both fiat and on-chain activity are covered. Equally important is alert handling: build a triage, investigation and escalation workflow, with clear SLAs for review and strict record retention for every alert, including those closed as false positives. Tuning the ruleset to manage false-positive volume is itself an inspection point, so document each tuning decision.
Suspicious transaction reporting in Malaysia is directed to the financial intelligence function within BNM (the Financial Intelligence and Enforcement Department). When a staff member or the monitoring system flags activity that cannot be explained, the matter escalates internally to the compliance officer, who decides whether to file an STR. The report should be submitted promptly once suspicion is formed, with a clear narrative, supporting data and the investigation record attached.
Observe the tipping-off prohibition strictly: do not disclose to the customer that a report has been made or is contemplated. Preserve all evidence, maintain the confidentiality of the filing, and keep a liaison channel open with the authorities. Filing mechanisms and supervisory notices are published by Bank Negara Malaysia.
A VASP AML Malaysia program is not static. Build periodic customer review cycles, more frequent for high-risk customers, and schedule regular retuning of transaction monitoring rules against emerging typologies. Run an employee training program covering AML/CFT obligations, red-flag recognition and reporting procedures, and keep attendance and test records as evidence of competency.
Recordkeeping is a statutory obligation under AMLA. Retain KYC records and transaction records for at least the period specified under AMLA and BNM guidance, commonly cited as at least six years after the account is closed or the business relationship or transaction ends. Confirm the applicable retention period against the current legislation and guidance. Maintain a written retention and deletion policy and conduct independent audit and testing to confirm controls operate as designed.
| Procedure | When to use | Key steps | Evidence required |
|---|---|---|---|
| Simplified Due Diligence (SDD) | Lower-risk scenarios only, where permitted by the applicable guidance | Basic ID, reduced verification | ID type, basic contact details |
| Standard CDD | Most customers | ID + verification + AML screening | ID, proof of address, risk score |
| Enhanced Due Diligence (EDD) | High-risk customers / transactions | Source of funds, enhanced monitoring, senior approval | BO documents, wealth evidence, transaction rationale |
| Step | Responsible (Who) | Typical duration |
|---|---|---|
| Governance & policy drafting | Compliance officer + legal counsel | 2–4 weeks |
| AML risk assessment | Compliance team + external consultant (if needed) | 2–6 weeks |
| KYC onboarding flow design & tooling | Product + Compliance + IT | 4–8 weeks |
| Transaction monitoring rules build | Compliance + AML vendor + IT | 3–6 weeks |
| STR procedure & reporting set-up | Compliance + Legal + FIU liaison | 1–2 weeks |
| Training & dry-runs | HR + Compliance | 1–2 weeks (ongoing refresh) |
Supervisors assess a program by its artefacts. Assemble and version-control the following documents so that any one of them can be produced on request during a supervisory visit. This is the backbone of an AML compliance checklist for a VASP.
| Document / Record | Why required / Use |
|---|---|
| Board-approved AML/CFT policy | Demonstrates governance and accountability |
| KYC policy & onboarding checklist | Inspector-ready onboarding evidence |
| Customer identification records (ID, address) | Proof of verification for CDD |
| Beneficial ownership documentation | Required for corporate customers |
| AML risk assessment report & scoring matrix | Demonstrates risk-based approach |
| Transaction monitoring rules & alert logs | Evidence of monitoring & tuning |
| STR filings & investigation files | Proof of reporting and internal handling |
| Training records & attendance logs | Demonstrates staff competency |
| Audit reports & remediation plans | Evidence of oversight & continuous improvement |
| Third-party vendor contracts (AML vendors) | Due diligence on outsourcing |
| Retention & deletion policy | Compliance with recordkeeping rules |
Keep these records indexed and retrievable. A disorganised but technically complete evidence set still produces findings, because an inspector who cannot locate a sample KYC file quickly will question the reliability of the whole control environment.
For most VASPs, a full program build runs across a three-to-six-month window. A realistic sequence is: weeks 1–4 for governance and policy drafting and appointment of the compliance officer; weeks 2–8 for the risk assessment (overlapping with policy work); weeks 4–12 for KYC tooling and transaction monitoring integration; weeks 10–14 for STR procedures and FIU liaison set-up; and weeks 12–16 for training, dry-runs and an independent readiness test. Align this build with any SC registration or approval windows, since the regulator will expect your AML controls to be operational, not merely designed, at the point of assessment.
The figures below are indicative planning ranges only and will vary significantly by firm size, scope and vendor. Obtain current quotations before budgeting.
| Item | Indicative cost (MYR) | Notes |
|---|---|---|
| Legal & compliance consultancy (initial program) | Varies by scope | Depends on scope and external counsel rates |
| AML software + integrations (one-off) | Varies by vendor and scale | Based on vendor, scale and analytics |
| Ongoing AML tooling subscription | Recurring, scale dependent | Monthly or annual licence |
| Digital ID / KYC vendor fees | Per-check or tiered | Variable by vendor and verification complexity |
| Training & internal rollout | Initial + refresh | Initial program and materials |
| External audit / independent testing | Annual engagement | For readiness and attestation |
Budget for both the one-off build and the recurring run cost. The most common budgeting error is under-provisioning for ongoing tuning, alert investigation headcount and annual independent testing, all of which are necessary to keep a VASP AML Malaysia program credible over time.
The direction of travel in 2025–26 has been towards heightened AML/CFT scrutiny of digital asset businesses. The SC has signalled ongoing review and consultation around its digital asset framework, including proposals to refine how digital asset exchanges and tokens are regulated. The practical emphasis for 2026 falls on three areas: stronger, more granular KYC expectations; more consistent reporting; and technology-specific scrutiny, including how VASPs use chain analysis to evidence source of funds. The SC and BNM have signalled greater supervisory engagement, which makes inspection-readiness the priority rather than a theoretical exercise.
Firms should expect supervisory attention on the alert-to-STR workflow and the quality of beneficial ownership evidence. The likely practical effect is that firms should prioritise their risk assessment refresh, strengthen EDD for crypto-native risks such as mixer exposure, and upgrade transaction monitoring to reduce both missed alerts and excessive false positives. Confirm the current position directly against the latest guidelines and consultation papers published by the Securities Commission Malaysia and Bank Negara Malaysia, as the framework continues to evolve.
Across readiness reviews, the same weaknesses recur. Address them before a supervisor finds them.
Building a VASP AML Malaysia program in 2026 is a sequenced project, not a single purchase. Start with the risk assessment, draft and board-approve your AML/CFT and KYC policies, appoint a properly empowered compliance officer, procure and tune your tooling, train your staff, and keep the evidence organised for inspection. Done well, this produces a defensible, risk-based program that satisfies AMLA, SC and BNM expectations and withstands supervisory scrutiny. Firms seeking a tailored readiness review and template pack can contact Global Law Experts to scope a build or remediation plan calibrated to their activities and risk profile.
This article provides general information and process guidance only and does not constitute legal advice. Readers should obtain tailored advice from an advocate and solicitor qualified in Malaysia before designing or relying on an AML/CFT program.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Sabir Alijev at LegalBison, a member of the Global Law Experts network.
posted 4 minutes ago
posted 37 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 6 hours ago
posted 6 hours ago
posted 6 hours ago
posted 7 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message