The statutory duty
Section 19 of AMLA obliges reporting institutions to adopt programmes, policies, procedures and controls to prevent money laundering, terrorist financing and proliferation financing. BNM's AML/CFT/CPF and TFS policy document translates that duty into concrete governance expectations — this is not a paper exercise; supervisors test whether the programme actually works.
A compliant programme is built on five pillars:
- Board and senior-management oversight
- A designated, competent compliance officer
- Risk-based policies, procedures and internal controls
- Ongoing employee training and awareness
- Independent testing of the whole framework
Board and senior-management accountability
The board owns the framework
The board of directors approves the AML/CFT policy, sets the risk appetite, and is ultimately accountable for compliance — it cannot delegate that accountability away.
Senior management implements
Senior management operationalises the policy, allocates resources, and ensures the compliance function has the authority and independence to do its job.
A reporting line to the top
The compliance officer must have a direct line to the board or a board committee, so material AML/CFT issues are escalated without being filtered by the business line.
The compliance officer
Every reporting institution must appoint a compliance officer at management level. The role is the operational heart of the programme:
- Assessing internal suspicious-transaction reports and deciding on STR filing
- Maintaining the institutional risk assessment and keeping it current
- Overseeing CDD, screening and record-keeping controls
- Acting as the liaison with BNM and law-enforcement agencies
- Being fit, proper and sufficiently resourced to perform the function independently
Training and awareness
Employees are the front line. AML/CFT training must be ongoing, role-relevant, and documented — with attendance records — so the institution can demonstrate its staff were equipped to recognise and escalate suspicious activity.
- Induction training for new joiners before they handle customers
- Refresher training at regular intervals, updated for new typologies and rules
- Targeted training for higher-risk roles (onboarding, transaction monitoring, senior management)
- Records of content, attendance and assessment kept for the retention period
Independent testing
The final pillar is independent review — either by internal audit or an external party — to test that the programme is designed well and operating effectively. For many Labuan reporting institutions an independent external AML/CFT audit is expressly required by LFSA. Independent testing is where design gaps and operating failures are found before a regulator finds them.
Frequently asked questions
In conclusion
A defensible AML/CFT compliance programme is judged on all five pillars working together. Weakness in any one — an under-resourced compliance officer, undocumented training, or testing that is not truly independent — is where supervisory findings cluster.
Build or benchmark your compliance programme
We design AML/CFT programmes and provide the independent testing pillar for Malaysian and Labuan reporting institutions.