CDD & Beneficial Ownership: What Reporting Institutions Get Wrong — CWC & ENG PLT
Articles & Resources
AMLA 9 min read·16 July 2026

CDD & Beneficial Ownership: What Reporting Institutions Get Wrong

Risk-based customer due diligence, beneficial-owner verification, PEP requirements, e-KYC, and sanctions screening — and the compliance failures that recent enforcement actions keep exposing.

01

When CDD is required

Customer due diligence applies whenever a reporting institution establishes a business relationship — and to occasional one-off transactions. The core requirement, set out in Section 16 of AMLA and the supervisory policy documents, is simple to state: know who your customer is, verify that identity from reliable sources, and understand the purpose and intended nature of the relationship.

The harder part is beneficial ownership. Where the customer is a company, trust, or other structure, the institution must identify the natural persons who ultimately own or control it — and take reasonable measures to verify them. Criminals rely on layered structures precisely because institutions stop at the legal-entity level.

The most-cited failureWeak beneficial-ownership identification is the recurring theme in enforcement. In 2025, BNM publicly announced penalties totalling nearly RM5 million on four institutions — with HSBC Malaysia entities fined RM3.26 million and Bank Pembangunan RM493,500, in both cases citing weaknesses in CDD and identifying beneficial ownership.
02

The risk-based approach in practice

CDD is not one-size-fits-all. The depth of information collected and verified should scale with the risk of the customer, their geography, the product, and the delivery channel. A practical risk-based CDD programme means:

  • A documented customer risk assessment at onboarding — who they are, where they operate, what they need
  • Monitoring frequency and depth tied to the risk rating
  • Graduated sign-off: higher-risk customers escalated to senior management
  • Refreshing CDD for existing customers on materiality and risk — triggered by new products, unusual activity, or stale information
03

Enhanced due diligence: PEPs and non-face-to-face

1

Politically exposed persons

For PEPs, enhanced due diligence is mandatory: establish both source of wealth and source of funds, and obtain senior management approval — at head-office level — before establishing or continuing the relationship.

2

Non-face-to-face onboarding

Digital onboarding is permitted but Board-approved and subject to BNM's e-KYC policy document (updated April 2024). Institutions must demonstrate on a continuing basis that remote identification is secure and effective.

3

e-KYC controls

Robust e-KYC typically combines document verification (fraud-detection on government IDs), biometric matching against the ID, and liveness detection to defeat photos, videos, and synthetic masks — with multi-factor authentication proportionate to risk.

04

Sanctions screening is part of CDD

Every customer — regardless of any CDD threshold — must be screened against the Domestic List and the UN Security Council Resolutions List, both at onboarding and as part of ongoing due diligence. When a list is updated, the entire customer database, including dormant accounts, must be re-screened without delay.

Minimum data points to enable screening:

  • Full name
  • NRIC, passport, or other official reference number
  • Date of birth
Screening gaps attract penaltiesIn September 2024, BNM imposed an administrative monetary penalty of RM660,000 on Agrobank for failing to conduct timely sanctions screening of customers and beneficial owners — even though no sanctioned party was actually onboarded. The gap itself is the breach.
05

Lessons from enforcement

Stopping at the declared beneficial owner
Regulators expect institutions to probe when documents or behaviour contradict the declared ownership and control structure.
Onboarding before CDD is complete
Establishing business relations first and finishing due diligence later is a breach in itself.
Taking source-of-wealth claims at face value
Higher-risk customers' wealth must be corroborated, not just recorded from the customer's own representation.
Stale risk ratings
If risk ratings are never refreshed, enhanced due diligence is never triggered — a compounding failure.
Screening only new customers
List updates require prompt re-screening of the full existing book, including dormant accounts.
FAQ

Frequently asked questions

The natural person(s) who ultimately owns or controls the customer, or on whose behalf a transaction is conducted — including control exercised through a chain of ownership rather than directly.
Yes, on the basis of materiality and risk — for example when a significant transaction occurs, the relationship changes materially, or the information held is insufficient or outdated.
Yes. BNM's e-KYC policy document permits digital onboarding of individuals and legal persons, subject to Board approval, effective identification and verification measures, and controls proportionate to risk.
Without delay upon publication — the Domestic List upon gazettal, and the UNSCR List upon UN publication — across the entire customer database.

In conclusion

Enforcement actions in Malaysia and the region keep pointing at the same weaknesses: beneficial ownership, source-of-wealth corroboration, and screening discipline. An independent review of your CDD framework — before the regulator's on-site examination finds the gap — is the cheapest fix available.

AMLA · AML/CFT Advisory

Get your CDD framework independently reviewed

We test onboarding files, beneficial-ownership verification, and screening controls against current requirements.

Request a consultation