Bank Negara Malaysia (BNM) has made public the fines it imposed for anti-money laundering (AML) non-compliance. In November 2025, Malaysia’s central bank took enforcement action against several financial institutions for failures that, on paper, should have been avoided: missed suspicious transaction report (STR) filings, delayed submissions, and incomplete enhanced due diligence (EDD) processes.
Compliance teams operating under BNM’s jurisdiction should take these cases as reference points, as they reveal the fine line between detection and reporting, or policy and practice that regulators are actively scrutinizing.
“We as an industry recognize that you’re not going to eliminate all financial crime, so you need a pragmatic approach that is based on your risk appetite.”
– Andrew Davies, Global Head of FCC Strategy, ComplyAdvantage
In this article, we unwrap what the enforcement record demonstrates, who is affected by Malaysia’s AML obligations under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA), and the practical steps firms your compliance team can take to reduce the risk of exposure.
What do BNM’s recent enforcement actions mean for compliance teams?
BNM published enforcement notices for AML failings. Three themes recur across the publicly available record: failure to file STRs, delays in filing them, and inadequate EDD for high-risk customers. The table below summarizes some of the cases:
| Institution type | Date | Breach | Fine (MYR) |
| Bank | Nov 20, 2025 | Failure to submit STR despite meeting internal red flag criteria | RM560,000 |
| Development financial institution | Nov 20, 2025 | Failure to promptly submit STR | RM460,000 |
| Corporate services provider | Nov 17, 2025 | Failure to promptly submit STR; failure to conduct EDD | RM46,000 |
| Corporate services provider | Nov 17, 2025 | Failure to promptly submit STR | RM8,625 |
| Total | RM1,074,625 (~$273,600) | ||
Failure to file STRs
A bank received a penalty of RM560,000 – the largest single penalty in this enforcement round – after failing to submit an STR despite transactions meeting its own internal red flag criteria. Under the BNM’s Islamic Financial Services Act 2013, and the anti-money laundering and countering the financing of terrorism (AML/CFT) and Targeted Financial Sanctions (TFS) for Financial Institutions Policy Document, the financial institution (FI) was required to act on those flags with a filing. It did not.
This case is particularly interesting because while the bank’s systems identified the risk, the failure occurred between detection and reporting: internal criteria were met, but the compliance obligation was not fulfilled. This detection-to-reporting gap is a pattern across markets, driven less by indifference than by volume.
“The technology just creates too many investigations, too many cases, and the analysts just get fatigued with looking at it. An analyst who wants to come in and do a good job and fight financial crime becomes overwhelmed with alerts and cases – rather than a superhero financial crime fighter, they just become someone who’s there to clear an alert.”
– Andrew Davies, Global Head of FCC Strategy, ComplyAdvantage
Delayed STR filing
Another firm – a development FI –, received a monetary penalty of RM460,000 for failing to submit an STR promptly. The FI is obligated under the Development Financial Institutions Act 2002 and the BNM’s AML/CFT Policy Document, which sets the same reporting standard as AMLA for development financial institutions. A smaller firm – a corporate services provider (CSP) – received a similar fine of RM8,625, but both firms have since taken measures so it doesn’t happen again.
These examples reinforce the importance of timeliness in compliance. Regulators and law enforcement have the power to lock bank accounts so criminals can’t touch the funds. However, they can only freeze what is actually there. If the report is late, the account will likely be empty.
Failure to conduct EDD
Another CSP received a compound of RM46,000 for two separate breaches: failure to promptly submit an STR, and failure to conduct EDD in breach of paragraphs 14.11.1 and 14C.2.1 of the AML/CFT and TFS for DNFBPs and NBFIs Policy Document:
“14.11.1 Reporting institutions are required to perform enhanced CDD where the ML/TF/PF risks are assessed as higher risk. An enhanced CDD, shall include at least, the following:
(a) obtaining CDD information under paragraph 14.10; Anti-Money Laundering, Countering Financing of Terrorism, Countering Proliferation Financing and Targeted Financial Sanctions for DNFBPs and NBFIs (AML/CFT/CPF and TFS for DNFBPs and NBFIs) 41 of 140 Issued on: 5 February 2024
(b) obtaining additional information on the customer and beneficial owner (e.g. volume of assets and other information from commercial or public databases);
(c) enquiring on the source of wealth or source of funds. In the case of PEPs, both sources must be obtained;
and (d) obtaining approval from the Senior Management of the reporting institution before establishing (or continuing, for existing customer) such business relationship with the customer. In the case of PEPs, Senior Management refers to Senior Management at the head office.”
“In relation to paragraphs 14C.1.1 and 14C.1.2, where nominee services are provided, such business relations must be subjected to enhanced CDD and enhanced ongoing due diligence.”
Because CSPs hold the keys to creating legal entities, regulators view them as gatekeepers to the financial system. The risk is that bad actors use complex corporate layers and nominee arrangements to hide who owns and profits from the business – the ultimate beneficial owner (UBO). This is why conducting timely EDD is essential to avoid regulatory penalties and reputational damage.
Who is subject to BNM’s AML obligations under AMLA?
AMLA imposes AML/CFT obligations on a broad class of reporting institutions operating in Malaysia. These include commercial and Islamic banks, insurance and takaful operators, money service businesses (MSBs), securities firms, futures brokers, and certain designated non-financial businesses and professions (DNFBPs) – such as accountants, lawyers, corporate secretaries, and real estate agents – where they carry out specific transaction types.
BNM’s recent regulatory actions show that non-bank entities (NBEs) and development financial institutions face the same strict reporting and due diligence requirements as commercial banks. The regulator aims to maintain equal oversight across all financial sectors.
If your business operates in Malaysia as a branch or subsidiary of a global company, you cannot rely solely on your headquarters’ global compliance policy. BNM evaluates your business solely under Malaysian laws, meaning local regulations override any international group-level frameworks.
What are the steps to mitigate your AML enforcement risk?
Firms looking to reduce their enforcement exposure should focus on closing the gaps between detection, reporting, and ongoing monitoring that regulators are directly targeting. Here’s how to achieve this, in a few steps:
1. Submit STRs faster
Don’t let alerts sit around. The gap between detecting suspicious activity and reporting it creates massive regulatory risk for your firm. Auditing your workflow from the moment an alert is generated to when the STR is submitted, with strict, timestamped deadlines at every step, helps prevent cases from stalling.
Alert volume matters too. Flat, one-size-fits-all thresholds tend to generate high volumes of low-value alerts, driving resourcing and process failures that led to the recent BNM’s enforcement cases. Segmenting customers by shared characteristics – industry, job type, or location – and measuring deviations from each group’s baseline can help reduce that noise, leaving only alerts worth an analyst’s time.
“The first time I implemented that was with […] PwC, for a financial institution we were working with. That project led to an 85% reduction in false positives, getting rid of all of that alert noise where you get alert fatigue.”
– Andrew Davies, Global Head of FCC Strategy, ComplyAdvantage
2. Treat system alerts as legal obligations
When your monitoring system flags a transaction, it becomes a legal obligation. Merely detecting a red flag isn’t enough; the compliance process isn’t complete until the STR is filed. Make sure your system automatically pushes flagged alerts directly into the reporting workflow. A case left sitting in a review queue without a clear next step can be a massive liability during an audit.
3. Automate deeper background checks (EDD)
EDD should never be left to an employee’s personal judgment, but instead should be done automatically. Firms are legally required to run deep background checks on high-risk clients, including:
- PEPs and their immediate family members and close associates.
- Clients from high-risk countries as flagged by FATF.
- Companies with complex, heavily layered ownership structures.
- Clients whose transactions don’t match their stated business profile.
Firms should map their onboarding and ongoing monitoring workflows against these categories and verify that EDD is applied systematically, not selectively, with documented outcomes at each stage. Segmentation can help implement that systematic approach in practice.
4. Keep customer risk profiles updated in real time
A customer’s risk level changes if they alter their company ownership, receive bad news coverage, or change how they move money. Because BNM expects dynamic tracking over time, you would need to update your system so it automatically triggers a risk profile update whenever a major change occurs.
5. Train staff to act on suspicion
A common issue in compliance is employees waiting for absolute proof of a crime before raising a red flag. In Malaysia, the legal standard for filing an STR is simply having reasonable suspicion. Teams need thorough training to recognize those red flags and escalate them immediately without waiting for certainty. In short, training programs should cover:
- The next-working-day filing window and how it is calculated.
- The specific red flags associated with the institution’s customer base and transaction types.
- The escalation pathway from alert to STR, including who is responsible at each stage.
- The difference between suspicion and certainty, and why the former is sufficient to trigger a filing obligation.
The cost of non-compliance in Malaysia
Because BNM publishes all penalties, compliance failures are now a matter of public record. For businesses operating across multiple countries, this public exposure may create severe reputational damage that far outweighs the immediate financial cost. Beyond standard fines, penalized businesses face increased regulatory scrutiny, operational restrictions, and potential prosecution and multi-million-ringgit fines under AMLA in some extreme cases.
Consequently, BNM is actively pivoting from coaching businesses to strictly enforcing its regulatory requirements. Organizations that view these actions as isolated incidents underestimate the permanent regulatory shift that may pose long-term risk to their operations.
Meet BNM’s AML compliance requirements with ComplyAdvantage Mesh
A cloud-based compliance platform, ComplyAdvantage Mesh, combines industry-leading AML risk intelligence with actionable risk signals to screen customers and monitor their behavior in near real time.
Get a demoOriginally published 28 July 2026, updated 28 July 2026
Disclaimer: This is for general information only. The information presented does not constitute legal advice. ComplyAdvantage accepts no responsibility for any information contained herein and disclaims and excludes any liability in respect of the contents or for action taken based on this information.
Copyright © 2026 IVXS UK Limited (trading as ComplyAdvantage).
