[codicts-css-switcher id=”346″]

Global Law Experts Logo
aml compliance israel

AML Compliance Israel 2026: STR Filing, Program Requirements & Regulator Expectations

By Global Law Experts
– posted 1 hour ago

Who this guide is for: MLROs, compliance officers and risk or legal leads in banks, fintechs, payment service providers (PSPs) and payment firms operating in Israel.

What you will get: a regulator-aligned STR filing workflow, an AML programme checklist, CDD and EDD rules, transaction monitoring KPIs, record-keeping obligations, and inspection readiness guidance.

Intro, Why 2026 matters for AML in Israel

AML compliance Israel has moved decisively up the risk agenda for 2026, driven by intensified regulatory scrutiny, a surge in compliance hiring across the financial sector, and a wave of programme refreshes at fintechs and payment firms. The Israel Money Laundering and Terror Financing Prohibition Authority (IMPA, הרשות לאיסור הלבנת הון ומימון טרור) continues to sharpen its expectations around suspicious transaction reporting, customer due diligence and enterprise risk assessment, while sector supervisors such as the Bank of Israel and the Israel Securities Authority reinforce those standards through their own instructions. For regulated institutions, the practical challenge is translating a dense statutory and supervisory framework into an operating model that inspectors will recognise as effective.

This guide sets out, step by step, what a defensible AML programme looks like in Israel today, how to file a suspicious transaction report, and how to prepare for the questions regulators are asking in 2026.

The material below is practitioner-focused and organised around action items. It draws on the Prohibition on Money Laundering Law, 5760-2000, published IMPA guidance, Bank of Israel supervisory instructions, Israel Securities Authority requirements, and the Financial Action Task Force (FATF) mutual evaluation of Israel. Where we offer templates, thresholds or workflow suggestions, treat these as practical guidance rather than a substitute for legal advice tailored to your institution.

Who Regulates AML Compliance Israel & Which Entities Are Covered?

AML compliance Israel operates on a two-tier model: a central financial intelligence and enforcement authority, layered with sector-specific supervisors who apply the framework to the institutions they oversee.

At the centre sits IMPA, the Israel Money Laundering and Terror Financing Prohibition Authority. IMPA is the national financial intelligence unit. It receives and analyses suspicious transaction reports, disseminates intelligence to law-enforcement and security bodies, issues guidance to reporting entities, and participates in supervisory and enforcement activity. The statutory foundation for the entire regime is the Prohibition on Money Laundering Law, 5760-2000, which defines money-laundering offences, imposes reporting duties on regulated businesses, and empowers the making of subsidiary orders that spell out obligations sector by sector. Terrorist-financing duties additionally draw on the Prohibition on Terror Financing Law, 5765-2005 and the Counter-Terrorism Law, 5776-2016.

Above the reporting entities themselves, several supervisors apply and enforce AML requirements:

  • Bank of Israel, Supervisor of Banks. Sets and enforces AML/CTF supervisory expectations for banks and credit-card companies, including onboarding, monitoring and reporting standards.
  • Israel Securities Authority (ISA). Applies AML obligations to capital-market participants, investment firms, portfolio managers and other entities within its remit.
  • Capital Market, Insurance and Savings Authority. Supervises insurers, provident and pension funds, and, under its licensing regime for financial-services providers, currency-service and other financial-asset-service businesses.

The scope of covered entities is broad. It includes banks and credit-card companies, insurers and provident funds, portfolio managers and other capital-market participants, money-services and currency-service businesses, payment service providers, financial-asset-service providers dealing in virtual assets, and, for specified categories of activity, lawyers and accountants. The Israel Bar Association provides guidance on where professional duties intersect with AML obligations for lawyers, including how these coexist with client confidentiality. If your institution is unsure whether it falls within a particular order, that threshold question should be resolved before any programme design work begins.

Core AML Programme Requirements, Mandatory Components & Checklist

An AML programme in Israel is not a single document; it is a system of governance, controls, testing and evidence. Inspectors assess whether each component exists, whether it is proportionate to your money-laundering and terrorist-financing (ML/TF) risk, and whether it actually functions in practice. The components below map to the expectations set out under the Prohibition on Money Laundering Law and elaborated by IMPA and the sector supervisors. Treat this section as the backbone of your AML programme requirements for Israel, and keep a checklist alongside your policies so that ownership and evidence are documented for every item.

Governance, Policies and MLRO Responsibilities

Effective AML compliance Israel begins with clear accountability. The board or equivalent governing body must approve the AML policy, understand the institution’s residual ML/TF risk, and receive regular reporting on programme performance. A designated Money Laundering Reporting Officer (MLRO), or head of compliance with equivalent authority, must own day-to-day execution.

The MLRO role should be documented in a written mandate covering: authority to file suspicious transaction reports without needing commercial sign-off; a direct reporting line to senior management and the board; ownership of sanctions-screening decisions and escalation; and sufficient resources and seniority to challenge the business. Reporting lines and escalation paths, from front-line analyst to MLRO to board, should be mapped so that any inspector can trace how a red flag becomes a decision.

Enterprise Risk Assessment (ML/TF Risk Assessment)

A documented enterprise-wide ML/TF risk assessment is the analytical core of the programme. It should be refreshed periodically and whenever a material change occurs, a new product, a new market, an acquisition, or a significant regulatory update. The methodology should assess inherent risk, the effectiveness of controls, and the resulting residual risk across four standard risk dimensions:

  • Product and service risk. Cash intensity, cross-border capability, anonymity features and speed of value transfer.
  • Customer risk. Politically exposed persons, complex ownership structures, high-risk sectors and non-resident customers.
  • Channel risk. Face-to-face versus fully remote onboarding, use of intermediaries and third-party agents.
  • Geographic risk. Exposure to jurisdictions identified by FATF and other bodies as higher risk.

A simple scoring matrix, rating each factor and combining them into a residual-risk tier, gives the board a defensible, repeatable view and drives the intensity of due diligence and monitoring downstream.

Customer Due Diligence (CDD), EDD & Onboarding Controls

Customer due diligence in Israel requires identifying and verifying the customer, understanding the nature and purpose of the relationship, and identifying beneficial owners behind legal entities. Standard CDD covers reliable identity data and verification; enhanced due diligence (EDD) applies to higher-risk relationships such as PEPs, complex structures and customers connected to higher-risk jurisdictions.

Key controls include:

  • Collection and verification of identity documents at onboarding, with a defined re-verification cadence.
  • Beneficial-ownership identification for corporate customers, including the steps taken where ownership is opaque.
  • Ongoing monitoring triggers that prompt a CDD refresh, for example, unexpected activity, adverse media, or a change in ownership.
  • Digital KYC controls for fintechs conducting remote onboarding: liveness checks, document authentication and device or behavioural signals to counter impersonation and synthetic identity fraud.

For fintechs, the tension is between low-friction onboarding and robust CDD. The answer is risk-based tiering: light-touch checks for demonstrably low-risk profiles, with automatic step-up to EDD when risk indicators appear.

Transaction Monitoring & Tuning Rules

Transaction monitoring in Israel should detect activity inconsistent with the customer’s expected profile. A mature ruleset combines several detection approaches:

  • Amount-based rules. Large single transactions or aggregated activity crossing defined thresholds.
  • Velocity rules. Rapid movement of funds, structuring patterns, or high transaction frequency over short windows.
  • Behavioural rules. Deviation from a customer’s historical baseline, dormant-then-active patterns, and pass-through behaviour.

Rules must be tuned, not set and forgotten. Track key performance indicators such as the false-positive rate (FPR), alert-to-report conversion, detection rate, and suspicious transaction reports per thousand customers. A very high FPR wastes analyst capacity; a suspiciously low alert volume suggests coverage gaps. Distinguish symptoms (an alert firing) from indicators (a genuine risk pattern) and document tuning decisions so that inspectors can see the monitoring model is actively managed.

STR Policy & Escalation Workflow

The reporting duty under the Prohibition on Money Laundering Law includes both threshold-based reporting of prescribed transactions and reporting based on suspicion. Your policy must make clear that where a reasonable suspicion of money laundering or terrorist financing arises, a report is required regardless of value, in addition to any regular reports required for transactions above prescribed amounts.

The escalation workflow should specify how an alert or an employee referral reaches the MLRO, how the internal investigation is documented, who approves the filing decision, and how the confidentiality of the report is protected. “Tipping off” the customer must be prohibited. This subsection cross-references the detailed STR filing workflow below.

Training, Independent Audit & Record Keeping

Staff must receive AML training appropriate to their role, refreshed regularly and updated when obligations change. Front-line, onboarding and monitoring teams need deeper, scenario-based training than general staff. An independent audit, internal or external, should periodically test whether the programme is designed and operating effectively, covering CDD files, alert handling, STR quality and record retention. Records must be retained for the periods required under the framework so that both the institution and the regulator can reconstruct decisions after the fact.

How to File a Suspicious Transaction Report (STR) in Israel, Step by Step

Filing a suspicious transaction report in Israel is a defined workflow. Getting it right protects both the institution and the integrity of the intelligence IMPA relies on. The steps below reflect the process of investigating, deciding, drafting and submitting a report through IMPA’s reporting channel, and the actions that follow.

  1. Trigger and triage. A report originates from a monitoring alert, an employee referral, adverse media, or a law-enforcement request. The MLRO function triages the item to decide whether it warrants investigation.
  2. Internal investigation. Gather the customer profile, transaction history, CDD records and any prior alerts. Document what was reviewed and why. The objective is to establish whether a reasonable suspicion exists.
  3. Decision to file. The MLRO, exercising independent judgement, determines whether the reporting threshold of suspicion is met. The decision, whether to file or not to file, must be recorded with reasons.
  4. Draft the report. Prepare a clear, factual narrative: who, what, when, how much, through which accounts, and precisely why the activity is suspicious. Attach or reference supporting data. Avoid conclusions unsupported by the evidence, and avoid omitting inconvenient facts.
  5. Submit to IMPA. File the report through IMPA’s reporting system. IMPA operates as Israel’s financial intelligence unit and receives suspicious transaction reports from covered entities; consult the official IMPA pages for the current reporting portal and submission format.
  6. Protect confidentiality. The existence and content of the report are confidential. Do not disclose the filing to the customer or to anyone outside the authorised chain. Restrict internal access to the report on a need-to-know basis.
  7. Post-report actions. Depending on the circumstances, consider account restrictions, heightened monitoring of the relationship, and internal remediation of any control gap the case exposed. Preserve all related records.

For urgent matters, institutions should confirm the current expedited channels with IMPA and follow any prescribed procedure for time-critical situations. Cross-border cases may require coordination reflecting international information-sharing arrangements; where a matter involves foreign jurisdictions, factor that into the narrative and your internal escalation. A short STR checklist, narrative complete, supporting data attached, filing decision documented, confidentiality controls applied, post-report actions logged, helps ensure each report is submission-ready and audit-defensible.

A useful discipline in a strong AML compliance Israel programme is to rehearse the STR workflow periodically, walking a test case from alert to submission so that analysts, the MLRO and senior management all understand their roles before a real, time-pressured case arrives.

Sector Focus, Banks vs Fintechs vs PSPs

While the statutory framework is common, supervisory intensity and practical control design differ sharply across sectors. The comparison below highlights where banks, fintechs and PSPs diverge in their AML obligations.

Dimension Banks Fintechs PSPs
Covered activities Deposits, lending, payments, trade finance, wealth Digital accounts, lending, wallets, embedded finance Payment initiation, acquiring, money remittance, e-money
Typical supervisor Bank of Israel (Supervisor of Banks) Relevant financial-services supervisor for the licensed activity Relevant payments/financial-services supervisor
Minimum CDD Full CDD/EDD, mature beneficial-ownership process Risk-tiered digital KYC with step-up to EDD CDD scaled to payment flow and merchant risk
Monitoring complexity High, broad product set, cross-border flows High velocity, real-time, behavioural analytics High volume, merchant and transaction-level focus
STR volume Typically substantial across product lines Variable; rising with scale and product breadth Concentrated around anomalous flows and merchants
Key control focus Governance depth, EDD, cross-border monitoring Digital identity integrity, real-time monitoring tuning Merchant onboarding, flow monitoring, agent oversight

Banks face the deepest governance expectations and the widest product surface, so investment in EDD and cross-border monitoring is critical. Fintechs live or die by digital identity integrity and real-time monitoring; their advantage is data richness, their risk is scaling faster than controls. PSPs must focus on merchant onboarding, transaction-flow monitoring and oversight of any third-party agents in the value chain. Whatever the sector, the AML obligations for banks and non-banks in Israel converge on the same test: can you demonstrate that your programme is risk-based, functioning and evidenced?

AML for Emerging Sectors, Crypto, Marketplaces & Third-Party Agents

Emerging sectors present the sharpest AML compliance Israel questions in 2026. Providers of virtual-asset services, sandboxed fintechs and platforms relying on third-party agents all sit at the frontier of supervisory attention, in line with FATF’s emphasis on virtual assets and new payment technologies.

Businesses providing financial-asset services in virtual assets should assume that the full weight of CDD, monitoring, sanctions screening and STR obligations applies to their activity, and that the interplay between AML duties and licensing under the Israeli financial-services licensing regime will be scrutinised. A practical action plan looks like this:

  • Confirm the licensing and regulatory perimeter for the specific virtual-asset activity conducted.
  • Implement blockchain-analytics tooling to trace on-chain flows and screen counterparties against sanctions and high-risk indicators.
  • Apply travel-rule-style information capture for transfers where required.
  • Build CDD and monitoring around wallet-level and transaction-level risk, not just account opening.

Marketplaces and firms using third-party agents must remember that outsourcing an activity does not outsource the obligation. Agent conduct, onboarding quality and monitoring coverage remain the responsibility of the regulated entity, and should be governed by contracts, oversight and audit rights.

IMPA Inspections & Regulatory Enforcement, What Inspectors Look For

Inspection readiness is the practical test of everything above. Supervisors assess not only whether policies exist but whether they are lived. A pre-inspection checklist should ensure you can readily produce:

  • The current board-approved AML policy and the enterprise ML/TF risk assessment, with dates and version history.
  • The MLRO mandate, organisational chart and evidence of board reporting.
  • A representative sample of CDD/EDD files, including beneficial-ownership records.
  • Alert handling records showing how alerts were investigated, escalated and closed.
  • Filed suspicious transaction reports and the decision records behind both filings and non-filings.
  • Training records, independent-audit reports and evidence that findings were remediated.

Common findings that draw enforcement attention include stale risk assessments, weak beneficial-ownership evidence, untuned monitoring producing either alert floods or coverage gaps, delayed STRs, and remediation plans that are never closed. The framework provides for administrative financial sanctions imposed by the relevant supervisor for reporting and control failures, alongside potential criminal exposure for money-laundering offences. The most effective way to reduce enforcement risk is a demonstrable culture of compliance: timely reporting, an empowered MLRO, senior engagement, and prompt correction of identified weaknesses. Institutions should also maintain a live remediation tracker so that any prior finding can be shown as resolved.

Record Keeping & Data Protection Interplay

Record-keeping is where AML compliance Israel intersects most directly with data-protection obligations. AML rules require the retention of identification records, transaction records and reporting-decision records for the periods prescribed under the framework, so that activity can be reconstructed by the institution and by supervisors. Confirm the exact minimum periods against the applicable orders under the Prohibition on Money Laundering Law for each record type, and document your retention schedule accordingly.

The friction arises against data-minimisation and storage-limitation principles: privacy law, the Protection of Privacy Law, 5741-1981, as amended, pushes towards holding less data for less time, while AML law compels the opposite for defined records. The reconciliation is a documented retention schedule that identifies the lawful basis for each retained data category, applies AML retention only to records genuinely required, and provides for secure deletion once the retention period lapses. Coordinate the schedule with your data-protection officer or privacy team so that AML and privacy positions are aligned rather than contradictory, and so that access to sensitive AML records, particularly STR content, is tightly restricted.

Practical Annexes & Templates

To operationalise this guide, compliance teams should maintain a small set of reusable artefacts, each named to reflect the institution and year for version control:

  • One-page AML programme checklist. A single sheet listing every mandatory component, its owner and its evidence location, used for self-assessment and inspection prep.
  • STR sample checklist. The submission-readiness list covering narrative completeness, supporting data, decision documentation and confidentiality controls.
  • MLRO job description template. A mandate documenting authority, independence, reporting lines and resourcing.
  • Monitoring KPI dashboard template. Tracking false-positive rate, alert-to-report conversion, detection rate and STRs per thousand customers over time.

For related services and profiles, see the Compliance Lawyer Israel, Essential Guide and the broader Israel compliance lawyer directory. Institutions seeking a bespoke gap assessment, programme refresh or STR review should engage qualified compliance counsel.

Conclusion & Next Steps for Compliance Teams

AML compliance Israel in 2026 rewards institutions that can prove their programme works, not merely that it exists. The framework is anchored in the Prohibition on Money Laundering Law and enforced through IMPA and the sector supervisors, but the burden of demonstrating a risk-based, functioning and well-evidenced system sits squarely with each regulated entity. Three immediate actions will move most teams forward: run a documented gap assessment of your programme against the components in this guide; rehearse the STR workflow end to end so that a real filing is fast and defensible; and secure genuine senior and board buy-in so that the MLRO has the authority and resources to act.

Treat this as a living programme, reassess risk regularly, tune your monitoring, and keep your records inspection-ready, and AML compliance Israel becomes a manageable, repeatable discipline rather than a periodic scramble.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Idan Levy at MITIGATE Compliance & Risk Management, a member of the Global Law Experts network.

Sources

  1. Israel Money Laundering & Terror Financing Prohibition Authority (IMPA)
  2. Prohibition on Money Laundering Law, 5760-2000 and related regulations (gov.il)
  3. Bank of Israel (Supervisor of Banks)
  4. Israel Securities Authority (ISA)
  5. Capital Market, Insurance and Savings Authority
  6. Financial Action Task Force (FATF), Israel
  7. Israel Bar Association (IBA)

FAQs

Who enforces AML compliance Israel rules and which entities must comply?
AML compliance Israel is centred on IMPA, the national financial intelligence and anti-money-laundering authority, working alongside sector supervisors including the Bank of Israel (Supervisor of Banks), the Israel Securities Authority, and the Capital Market, Insurance and Savings Authority. Covered entities include banks, credit-card companies, insurers, capital-market participants, money-services and currency-service businesses, payment service providers, financial-asset-service providers dealing in virtual assets, and, for certain activities, lawyers and accountants.
A report must be filed whenever a reasonable suspicion of money laundering or terrorist financing arises, based on the reporting duty in the Prohibition on Money Laundering Law, 5760-2000. Suspicion-based reporting applies regardless of amount, and this sits alongside separate obligations to file regular reports for prescribed transactions above defined thresholds. The suspicion-based filing decision is made by the MLRO and must be documented.
The core components are board-level governance and a mandated MLRO, an enterprise ML/TF risk assessment, customer due diligence and enhanced due diligence, transaction monitoring, sanctions screening, an STR policy and escalation workflow, role-based training, independent audit, and record keeping, each proportionate to the institution’s assessed risk and supported by evidence.
Identification, transaction and reporting-decision records must be retained for the periods prescribed under the orders made pursuant to the Prohibition on Money Laundering Law. Institutions should confirm the exact minimum period for each record type against the applicable order and regulator guidance, and maintain a documented retention schedule that reconciles AML retention with data-protection principles.
Fintechs should combine amount, velocity and behavioural rules, and continuously tune them against KPIs such as false-positive rate, alert-to-report conversion and STRs per thousand customers. Given remote, high-velocity activity, digital-identity integrity and real-time monitoring are priorities, with automatic step-up to enhanced due diligence when risk indicators appear.
Aspects of AML operations can be outsourced, but the regulated entity retains legal responsibility for compliance and for the quality of any suspicious transaction report. Where third-party agents or vendors are used, the institution must govern them through contracts, oversight and audit rights, and ensure the MLRO retains ultimate control of filing decisions.
qfc company formation qatar
By Jonathon Richards

posted 5 minutes ago

complete due diligence
By Global Law Experts

posted 46 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

AML Compliance Israel 2026: STR Filing, Program Requirements & Regulator Expectations

Send welcome message

Custom Message