Building an AML/CFT Compliance Programme in Malaysia — CWC & ENG PLT
Articles & Resources
AMLA 8 min read·23 July 2026

Building an AML/CFT Compliance Programme in Malaysia

Section 19 of AMLA requires every reporting institution to run a compliance programme. Here is what BNM expects — board and senior-management accountability, a competent compliance officer, training, and independent testing.

01

The statutory duty

Section 19 of AMLA obliges reporting institutions to adopt programmes, policies, procedures and controls to prevent money laundering, terrorist financing and proliferation financing. BNM's AML/CFT/CPF and TFS policy document translates that duty into concrete governance expectations — this is not a paper exercise; supervisors test whether the programme actually works.

A compliant programme is built on five pillars:

  • Board and senior-management oversight
  • A designated, competent compliance officer
  • Risk-based policies, procedures and internal controls
  • Ongoing employee training and awareness
  • Independent testing of the whole framework
02

Board and senior-management accountability

1

The board owns the framework

The board of directors approves the AML/CFT policy, sets the risk appetite, and is ultimately accountable for compliance — it cannot delegate that accountability away.

2

Senior management implements

Senior management operationalises the policy, allocates resources, and ensures the compliance function has the authority and independence to do its job.

3

A reporting line to the top

The compliance officer must have a direct line to the board or a board committee, so material AML/CFT issues are escalated without being filtered by the business line.

03

The compliance officer

Every reporting institution must appoint a compliance officer at management level. The role is the operational heart of the programme:

  • Assessing internal suspicious-transaction reports and deciding on STR filing
  • Maintaining the institutional risk assessment and keeping it current
  • Overseeing CDD, screening and record-keeping controls
  • Acting as the liaison with BNM and law-enforcement agencies
  • Being fit, proper and sufficiently resourced to perform the function independently
Competence and independence are testedAppointing a compliance officer in name only — without authority, resources, or independence from the revenue-generating business — is a recurring supervisory finding. The role must be able to say no.
04

Training and awareness

Employees are the front line. AML/CFT training must be ongoing, role-relevant, and documented — with attendance records — so the institution can demonstrate its staff were equipped to recognise and escalate suspicious activity.

  • Induction training for new joiners before they handle customers
  • Refresher training at regular intervals, updated for new typologies and rules
  • Targeted training for higher-risk roles (onboarding, transaction monitoring, senior management)
  • Records of content, attendance and assessment kept for the retention period
05

Independent testing

The final pillar is independent review — either by internal audit or an external party — to test that the programme is designed well and operating effectively. For many Labuan reporting institutions an independent external AML/CFT audit is expressly required by LFSA. Independent testing is where design gaps and operating failures are found before a regulator finds them.

Independence is the pointThe reviewer must be independent of the functions being tested. A compliance officer cannot audit their own programme — that defeats the purpose of the pillar.
FAQ

Frequently asked questions

Yes. Section 19 of AMLA requires every reporting institution to establish and maintain a compliance programme, and BNM's policy document sets out the detailed expectations.
The board of directors is ultimately accountable and approves the policy; senior management implements it; the compliance officer runs it day to day. Accountability cannot be delegated away from the board.
Training should be ongoing — induction for new staff plus regular refreshers — and documented with attendance records, updated for new typologies and regulatory changes.
No. Independent testing must be carried out by internal audit or an external party independent of the functions being tested — the compliance officer cannot audit their own programme.

In conclusion

A defensible AML/CFT compliance programme is judged on all five pillars working together. Weakness in any one — an under-resourced compliance officer, undocumented training, or testing that is not truly independent — is where supervisory findings cluster.

AMLA · AML/CFT Advisory

Build or benchmark your compliance programme

We design AML/CFT programmes and provide the independent testing pillar for Malaysian and Labuan reporting institutions.

Request a consultation