Saudi Arabia’s anti-money laundering (AML) and counter-financing of terrorism (CFT) framework is set by law and supervised by SAMA and the Anti-Money Laundering Permanent Committee. This guide covers obligated entities, CDD, reporting, and compliance. See sanctions compliance, anti-bribery, fintech, and insurance license.
Overview
Saudi Arabia has a comprehensive AML/CFT legal and regulatory framework aligned with FATF standards. Obligated entities must implement risk-based policies, customer due diligence (CDD), record-keeping, and suspicious activity reporting (SAR). The Saudi Central Bank (SAMA) supervises financial institutions; the Anti-Money Laundering Permanent Committee and the Financial Intelligence Unit play central roles. Non-compliance can result in heavy fines and criminal liability. See ZATCA penalties for tax-related enforcement and corporate governance.
Obligated Entities
Obligated entities include: banks and financial institutions; insurance and reinsurance companies; capital market participants; money changers and remittance providers; real estate brokers and developers (in specified cases); dealers in precious metals and stones; legal and accounting professionals (in specified cases); and trust and company service providers. If you fall within a designated category, you must register or comply with the relevant supervisor and implement AML/CFT measures. See insurance license and professional services.
Customer Due Diligence and KYC
Obligated entities must conduct customer due diligence (CDD): identify and verify the customer and beneficial owners; understand the nature of the business relationship; and conduct ongoing monitoring. Enhanced due diligence applies to higher-risk customers (e.g. PEPs, high-risk jurisdictions). Records must be kept for a specified period. Ensure your KYC/CDD procedures meet the law and your supervisor’s rules. See beneficial ownership and PDPL for data handling.
Reporting and SAR
Obligated entities must report suspicious transactions to the Financial Intelligence Unit without tipping off the customer. Reporting thresholds and timeframes are set by law. Failure to report can result in penalties. You must also comply with sanctions screening and not deal with designated persons or entities. Implement clear internal reporting lines and train staff. See anti-bribery for related controls.
Policies and Training
Obligated entities must have AML/CFT policies and procedures, a designated compliance officer (or MLRO), and training for staff. A risk-based approach is required: assess your exposure and tailor controls. Supervisors may require a compliance function and periodic reporting. Document your risk assessment and keep policies up to date. See corporate compliance checklist and corporate governance.
AML Compliance Checklist
- Determine whether you are an obligated entity and identify your supervisor (SAMA, CMA, etc.).
- Adopt AML/CFT policies, CDD/KYC procedures, and a risk-based approach; designate a compliance officer.
- Implement suspicious transaction reporting and sanctions screening. See sanctions.
- Train staff and maintain records; conduct periodic reviews. See PDPL for personal data.
- Cooperate with supervisors and respond to requests. See corporate compliance checklist.