[codicts-css-switcher id=”346″]

Global Law Experts Logo
vasp aml malaysia

Our Expert in Malaysia

  • GOLD

How to Build an AML & KYC Program for Vasps in Malaysia (2026): Step‑by‑step Compliance Checklist

By Global Law Experts
– posted 43 minutes ago

VASP AML Malaysia compliance has moved from a box-ticking exercise to a supervisory priority, and firms that treat it as an afterthought now face inspection and enforcement risk. This guide sets out a practitioner-level, inspector-ready build for virtual asset service providers (VASPs) operating in Malaysia in 2026, mapping the legal obligations under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA) and the expectations of Bank Negara Malaysia (BNM) and the Securities Commission Malaysia (SC) to concrete operational controls. You will find numbered steps, document checklists, cost and timeline tables, and the evidence that supervisors expect to see.

It is written for founders, compliance officers, legal and risk teams who need to stand up a defensible program quickly.

Who this is for: Founders, compliance officers, legal teams and risk officers at VASPs and digital asset exchanges in Malaysia seeking an actionable, inspector-ready AML and KYC build for 2026.

Outcome: A stepwise checklist and template structure to design policies, processes and evidence required for licensing, supervision and suspicious transaction reporting obligations.

Overview, What a VASP AML & KYC program must achieve

A VASP AML Malaysia program exists to detect, prevent and report money laundering and terrorist financing. It must satisfy the statutory obligations in AMLA 2001, reporting, recordkeeping and customer due diligence, and the supervisory expectations published by the SC for digital asset exchanges and by BNM in its wider AML/CFT framework. Above all, a modern program must be risk-based and fully documented: every control should trace back to an identified risk, and every decision should leave an audit trail.

Regulator expectations in Malaysia (SC vs BNM)

The division of responsibility matters when designing your controls. In Malaysia, digital assets that fall within the prescribed definition are treated as securities, and the SC regulates digital asset exchanges (DAX operators), initial exchange offerings and digital asset custodians under the Capital Markets and Services Act 2007 and the relevant SC guidelines. BNM is a key AML/CFT policy authority and houses the Financial Intelligence and Enforcement Department, which operates Malaysia’s financial intelligence function and receives suspicious transaction reports. A VASP AML Malaysia build should therefore reconcile SC licensing-stage expectations with BNM’s reporting and AML/CFT supervisory framework, rather than treating them as separate silos.

Outcomes inspectors expect

  • Board-approved policies. AML/CFT and KYC policies signed off at board level, with version control.
  • A designated compliance officer. A named, independent compliance officer with reporting responsibilities and clear escalation authority (often described as the Money Laundering Reporting Officer function).
  • A documented risk assessment. A current, methodology-driven assessment covering customers, products, geographies and channels.
  • Operational logs. Onboarding files, transaction monitoring alerts, investigation records and STR filings.
  • Training evidence. Attendance records, test results and refresh schedules.

Eligibility & scope, Which VASPs must comply

Any business that carries on a regulated digital asset activity in Malaysia falls within the AML/CFT net. In practice this covers three broad functions: exchange and trading of digital assets, custody and safekeeping of client assets, and transfer or remittance of virtual assets between parties. If your business touches any of these, assume AMLA obligations apply and build accordingly.

When AMLA and licensing apply

AMLA 2001 imposes reporting institution obligations, including customer due diligence, recordkeeping and suspicious transaction reporting, on designated reporting institutions. The SC’s digital asset framework, together with the relevant SC guidelines, determines when a firm must be registered, recognised or approved to operate a digital asset exchange or related service in Malaysia. The statutory text and the relevant sections of AMLA are published by the Attorney-General’s Chambers of Malaysia, and firms should read the licensing triggers in conjunction with the reporting-institution definitions and the SC’s AML/CFT guidelines applicable to digital asset activities.

Cross-border agents and intermediaries that facilitate access to Malaysian customers should not assume they sit outside scope simply because servers or entities are offshore; operating a digital asset exchange in Malaysia without SC approval may itself be unlawful.

Exemptions & hybrid models

Some firms operate hybrid structures where part of the group is licensed overseas. An overseas licence does not displace Malaysian obligations for activity directed at Malaysian customers. Where a group relies on a parent’s global AML program, the Malaysian entity must still demonstrate local governance, a local compliance function, and controls calibrated to Malaysian risk and reporting channels. The Financial Action Task Force (FATF) standards on VASPs reinforce that the registration or licensing obligation attaches to the jurisdiction where the VASP is created, or where it does business.

Step-by-step VASP AML Malaysia compliance build

This is the operational core. Follow the steps in sequence, each builds on the previous one, and skipping ahead (for example, buying monitoring software before completing a risk assessment) is a common cause of wasted spend and inspection findings.

  1. Governance & policies
  2. AML/CFT risk assessment
  3. Customer Due Diligence (CDD) & KYC procedures
  4. Transaction monitoring & systems
  5. Suspicious transaction reporting & FIU liaison
  6. Ongoing monitoring, recordkeeping & training

Step 1, Governance & policies

Start with governance. Draft an AML/CFT policy and a separate KYC policy, and have both approved by the board, approval at board level is the single most important piece of evidence of accountability. Appoint a compliance officer (often performing the Money Laundering Reporting Officer function) with a written role description that sets out independence, reporting lines and escalation authority. The officer must have genuine standing to halt onboarding, freeze accounts and file reports without commercial interference.

Establish internal audit and reporting lines so that the compliance officer reports periodically to the board or a board committee. Counsel plays a defined role here: a fintech lawyer advises on the statutory interpretation of AMLA obligations, drafts policy language that will withstand supervisory scrutiny, and structures the escalation and tipping-off rules correctly. A directory of advocates and solicitors admitted to practise in Malaysia is maintained by the Malaysian Bar.

Step 2, AML/CFT risk assessment

The risk assessment is the foundation of a VASP AML Malaysia program, every subsequent control should be justified by reference to it. Conduct an enterprise-wide assessment covering four dimensions: customers (retail, corporate, PEPs), products (spot trading, custody, transfers, staking), geographies (customer and counterparty jurisdictions, high-risk and sanctioned territories) and delivery channels (remote onboarding, API access, agents).

Define risk tiers and a scoring matrix so that each customer and product is assigned a residual risk rating. Document the methodology and the review frequency, at minimum annually, plus trigger-based reviews when you launch a new product, enter a new market, or experience a material incident. The sample scoring approach below illustrates how crypto-native factors feed into tiering.

Risk factor Low (1) Medium (2) High (3)
Customer type Verified retail, domestic SME corporate PEP, complex ownership
Geography Domestic / low-risk Standard foreign High-risk / sanctioned jurisdiction
Transaction pattern Low value, stable Moderate velocity High velocity, structuring indicators
Wallet exposure Clean on-chain history Indirect exposure Mixers, darknet, sanctioned addresses

Step 3, Customer Due Diligence (CDD) & KYC procedures

KYC procedures in Malaysia for VASPs must identify and verify every customer before the business relationship begins. The onboarding flow should capture identification data, verify it against reliable independent sources, and establish beneficial ownership for corporate customers. For individuals, collect government-issued identity documents and proof of address; for entities, collect incorporation documents, directors and beneficial owner details.

Remote onboarding is the norm for VASPs, so build digital ID verification with liveness detection, document authentication, and automated screening against politically exposed person (PEP) lists and sanctions lists. Your VASP KYC Malaysia flow should capture the evidence, not just the outcome, so that an inspector can reconstruct how each identity was confirmed.

Apply a tiered intensity of due diligence based on the risk assessment. The following items form a minimum onboarding evidence checklist:

  • Identity record. Verified government-issued ID with document authentication result.
  • Address verification. Proof of address or equivalent reliable source check.
  • Beneficial ownership. Ownership chart and BO identity documents for corporate customers.
  • Screening results. PEP, sanctions and adverse-media screening output with timestamp.
  • Risk rating. Assigned tier and the factors that drove it.

Enhanced Due Diligence (EDD) triggers & steps

EDD applies to higher-risk relationships. Triggers include PEP status, high-value or high-velocity transactions, funds originating from high-risk jurisdictions, and on-chain exposure to mixers or obfuscation services. EDD steps include obtaining and documenting source of funds and source of wealth, enhanced ongoing monitoring, and senior management approval before onboarding or continuing the relationship. For crypto-specific risk, request the rationale for large transfers and corroborate the on-chain origin of funds using blockchain analytics.

Step 4, Transaction monitoring & systems

Transaction monitoring converts your risk assessment into automated detection. Design rules that reflect crypto-native typologies: unusual velocity, structuring just below reporting thresholds, large single deposits or withdrawals, rapid pass-through activity, address clustering, and interaction with mixing services or sanctioned addresses. The FATF’s VASP typologies provide a useful reference set for rule design.

On the technology side, integrate blockchain forensic and chain-analytics vendors alongside your AML screening engine so that both fiat and on-chain activity are covered. Equally important is alert handling: build a triage, investigation and escalation workflow, with clear SLAs for review and strict record retention for every alert, including those closed as false positives. Tuning the ruleset to manage false-positive volume is itself an inspection point, so document each tuning decision.

Step 5, Suspicious transaction reporting (STR) & FIU liaison

Suspicious transaction reporting in Malaysia is directed to the financial intelligence function within BNM (the Financial Intelligence and Enforcement Department). When a staff member or the monitoring system flags activity that cannot be explained, the matter escalates internally to the compliance officer, who decides whether to file an STR. The report should be submitted promptly once suspicion is formed, with a clear narrative, supporting data and the investigation record attached.

Observe the tipping-off prohibition strictly: do not disclose to the customer that a report has been made or is contemplated. Preserve all evidence, maintain the confidentiality of the filing, and keep a liaison channel open with the authorities. Filing mechanisms and supervisory notices are published by Bank Negara Malaysia.

Step 6, Ongoing monitoring, recordkeeping & staff training

A VASP AML Malaysia program is not static. Build periodic customer review cycles, more frequent for high-risk customers, and schedule regular retuning of transaction monitoring rules against emerging typologies. Run an employee training program covering AML/CFT obligations, red-flag recognition and reporting procedures, and keep attendance and test records as evidence of competency.

Recordkeeping is a statutory obligation under AMLA. Retain KYC records and transaction records for at least the period specified under AMLA and BNM guidance, commonly cited as at least six years after the account is closed or the business relationship or transaction ends. Confirm the applicable retention period against the current legislation and guidance. Maintain a written retention and deletion policy and conduct independent audit and testing to confirm controls operate as designed.

Comparison: SDD vs CDD vs EDD for VASPs

Procedure When to use Key steps Evidence required
Simplified Due Diligence (SDD) Lower-risk scenarios only, where permitted by the applicable guidance Basic ID, reduced verification ID type, basic contact details
Standard CDD Most customers ID + verification + AML screening ID, proof of address, risk score
Enhanced Due Diligence (EDD) High-risk customers / transactions Source of funds, enhanced monitoring, senior approval BO documents, wealth evidence, transaction rationale

Build timeline, step, owner and duration

Step Responsible (Who) Typical duration
Governance & policy drafting Compliance officer + legal counsel 2–4 weeks
AML risk assessment Compliance team + external consultant (if needed) 2–6 weeks
KYC onboarding flow design & tooling Product + Compliance + IT 4–8 weeks
Transaction monitoring rules build Compliance + AML vendor + IT 3–6 weeks
STR procedure & reporting set-up Compliance + Legal + FIU liaison 1–2 weeks
Training & dry-runs HR + Compliance 1–2 weeks (ongoing refresh)

Required documents, your inspection-ready evidence pack

Supervisors assess a program by its artefacts. Assemble and version-control the following documents so that any one of them can be produced on request during a supervisory visit. This is the backbone of an AML compliance checklist for a VASP.

Document / Record Why required / Use
Board-approved AML/CFT policy Demonstrates governance and accountability
KYC policy & onboarding checklist Inspector-ready onboarding evidence
Customer identification records (ID, address) Proof of verification for CDD
Beneficial ownership documentation Required for corporate customers
AML risk assessment report & scoring matrix Demonstrates risk-based approach
Transaction monitoring rules & alert logs Evidence of monitoring & tuning
STR filings & investigation files Proof of reporting and internal handling
Training records & attendance logs Demonstrates staff competency
Audit reports & remediation plans Evidence of oversight & continuous improvement
Third-party vendor contracts (AML vendors) Due diligence on outsourcing
Retention & deletion policy Compliance with recordkeeping rules

Keep these records indexed and retrievable. A disorganised but technically complete evidence set still produces findings, because an inspector who cannot locate a sample KYC file quickly will question the reliability of the whole control environment.

Timeline & deadlines, practical milestones

For most VASPs, a full program build runs across a three-to-six-month window. A realistic sequence is: weeks 1–4 for governance and policy drafting and appointment of the compliance officer; weeks 2–8 for the risk assessment (overlapping with policy work); weeks 4–12 for KYC tooling and transaction monitoring integration; weeks 10–14 for STR procedures and FIU liaison set-up; and weeks 12–16 for training, dry-runs and an independent readiness test. Align this build with any SC registration or approval windows, since the regulator will expect your AML controls to be operational, not merely designed, at the point of assessment.

Costs & fees, budgeting the build

The figures below are indicative planning ranges only and will vary significantly by firm size, scope and vendor. Obtain current quotations before budgeting.

Item Indicative cost (MYR) Notes
Legal & compliance consultancy (initial program) Varies by scope Depends on scope and external counsel rates
AML software + integrations (one-off) Varies by vendor and scale Based on vendor, scale and analytics
Ongoing AML tooling subscription Recurring, scale dependent Monthly or annual licence
Digital ID / KYC vendor fees Per-check or tiered Variable by vendor and verification complexity
Training & internal rollout Initial + refresh Initial program and materials
External audit / independent testing Annual engagement For readiness and attestation

Budget for both the one-off build and the recurring run cost. The most common budgeting error is under-provisioning for ongoing tuning, alert investigation headcount and annual independent testing, all of which are necessary to keep a VASP AML Malaysia program credible over time.

What changes in 2026, regulatory highlights

The direction of travel in 2025–26 has been towards heightened AML/CFT scrutiny of digital asset businesses. The SC has signalled ongoing review and consultation around its digital asset framework, including proposals to refine how digital asset exchanges and tokens are regulated. The practical emphasis for 2026 falls on three areas: stronger, more granular KYC expectations; more consistent reporting; and technology-specific scrutiny, including how VASPs use chain analysis to evidence source of funds. The SC and BNM have signalled greater supervisory engagement, which makes inspection-readiness the priority rather than a theoretical exercise.

Firms should expect supervisory attention on the alert-to-STR workflow and the quality of beneficial ownership evidence. The likely practical effect is that firms should prioritise their risk assessment refresh, strengthen EDD for crypto-native risks such as mixer exposure, and upgrade transaction monitoring to reduce both missed alerts and excessive false positives. Confirm the current position directly against the latest guidelines and consultation papers published by the Securities Commission Malaysia and Bank Negara Malaysia, as the framework continues to evolve.

Common pitfalls & remediation

Across readiness reviews, the same weaknesses recur. Address them before a supervisor finds them.

  • Poor documentation. Controls exist in practice but are not written down or version-controlled. Remediation: formalise policies, date and approve them at board level, and index the evidence pack.
  • Weak beneficial ownership checks. Corporate customers onboarded without a verified ownership chart. Remediation: require BO documentation and screening before activation, and back-fill existing high-risk accounts.
  • No digital ID verification. Reliance on manual document review without liveness or authentication. Remediation: integrate a digital ID vendor with authentication and liveness.
  • Under-resourced compliance function. A nominal appointment without authority or support. Remediation: give the compliance officer independence, escalation power and adequate investigation headcount.
  • Untuned monitoring. High false-positive volumes that bury genuine alerts. Remediation: tune rules iteratively, document each change, and track alert-to-STR conversion.

Conclusion

Building a VASP AML Malaysia program in 2026 is a sequenced project, not a single purchase. Start with the risk assessment, draft and board-approve your AML/CFT and KYC policies, appoint a properly empowered compliance officer, procure and tune your tooling, train your staff, and keep the evidence organised for inspection. Done well, this produces a defensible, risk-based program that satisfies AMLA, SC and BNM expectations and withstands supervisory scrutiny. Firms seeking a tailored readiness review and template pack can contact Global Law Experts to scope a build or remediation plan calibrated to their activities and risk profile.

This article provides general information and process guidance only and does not constitute legal advice. Readers should obtain tailored advice from an advocate and solicitor qualified in Malaysia before designing or relying on an AML/CFT program.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Sabir Alijev at LegalBison, a member of the Global Law Experts network.

Sources

  1. Bank Negara Malaysia (BNM)
  2. Securities Commission Malaysia (SC)
  3. Attorney-General’s Chambers of Malaysia
  4. Financial Action Task Force (FATF)
  5. United Nations Office on Drugs and Crime (UNODC)
  6. Malaysian Bar
  7. Judiciary of Malaysia

FAQs

Do all VASPs in Malaysia need an AML program?
Yes. Any VASP engaged in the exchange, custody or transfer of digital assets should implement an AML/CFT program consistent with AMLA 2001 and the guidance of BNM and the SC. A VASP AML Malaysia program is a baseline expectation for registration and ongoing supervision, not an optional enhancement.
High-risk indicators trigger EDD: politically exposed person (PEP) status, high-value or high-velocity transactions, funds originating from high-risk jurisdictions, and on-chain exposure to mixers or obfuscation services. In those cases, document beneficial ownership and source of funds and obtain senior approval.
Suspicious activity escalates internally to the compliance officer, who files a suspicious transaction report with the financial intelligence function at BNM. Maintain the investigation file, follow the timelines and format in BNM guidance, and observe the tipping-off prohibition throughout.
Retention follows AMLA and BNM guidance, commonly cited as at least six years after the end of the business relationship or the transaction. Confirm the applicable period against AMLA as published by the Attorney-General’s Chambers and against current BNM guidance.
Yes, but outsourcing does not transfer responsibility. Conduct vendor due diligence, contractually require data protection and service levels, and retain oversight records. The VASP remains accountable for the quality of KYC and monitoring outcomes.
Expect requests for board minutes and approved policies, the compliance officer designation, the risk assessment and scoring matrix, sample KYC files, transaction monitoring rules and alert logs, the alert-to-STR workflow, and training records. A well-organised evidence pack is central to any VASP AML Malaysia readiness position.
m-and-a due diligence malawi
By Global Law Experts

posted 6 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Build an AML & KYC Program for Vasps in Malaysia (2026): Step‑by‑step Compliance Checklist

Send welcome message

Custom Message