Saudi AML Compliance: Anti-Money Laundering and CFT 2026

Anti-money laundering, counter-financing of terrorism, and obligated entities in Saudi Arabia.

Saudi Arabia’s anti-money laundering (AML) and counter-financing of terrorism (CFT) framework is set by law and supervised by SAMA and the Anti-Money Laundering Permanent Committee. This guide covers obligated entities, CDD, reporting, and compliance. See sanctions compliance, anti-bribery, fintech, and insurance license.

Overview

Saudi Arabia has a comprehensive AML/CFT legal and regulatory framework aligned with FATF standards. Obligated entities must implement risk-based policies, customer due diligence (CDD), record-keeping, and suspicious activity reporting (SAR). The Saudi Central Bank (SAMA) supervises financial institutions; the Anti-Money Laundering Permanent Committee and the Financial Intelligence Unit play central roles. Non-compliance can result in heavy fines and criminal liability. See ZATCA penalties for tax-related enforcement and corporate governance.

Authority and Law

The Anti-Money Laundering Law and its Implementing Regulations set the obligations. The Anti-Money Laundering Permanent Committee coordinates policy; the Financial Intelligence Unit receives and analyses reports. SAMA supervises banks, insurers, and finance companies; CMA supervises capital market participants. Other sectors (e.g. real estate, dealers in precious metals) are supervised by the relevant authority. Check whether your entity is obligated and which supervisor applies. See fintech for SAMA-regulated activities.

Obligated Entities

Obligated entities include: banks and financial institutions; insurance and reinsurance companies; capital market participants; money changers and remittance providers; real estate brokers and developers (in specified cases); dealers in precious metals and stones; legal and accounting professionals (in specified cases); and trust and company service providers. If you fall within a designated category, you must register or comply with the relevant supervisor and implement AML/CFT measures. See insurance license and professional services.

Customer Due Diligence and KYC

Obligated entities must conduct customer due diligence (CDD): identify and verify the customer and beneficial owners; understand the nature of the business relationship; and conduct ongoing monitoring. Enhanced due diligence applies to higher-risk customers (e.g. PEPs, high-risk jurisdictions). Records must be kept for a specified period. Ensure your KYC/CDD procedures meet the law and your supervisor’s rules. See beneficial ownership and PDPL for data handling.

Reporting and SAR

Obligated entities must report suspicious transactions to the Financial Intelligence Unit without tipping off the customer. Reporting thresholds and timeframes are set by law. Failure to report can result in penalties. You must also comply with sanctions screening and not deal with designated persons or entities. Implement clear internal reporting lines and train staff. See anti-bribery for related controls.

Policies and Training

Obligated entities must have AML/CFT policies and procedures, a designated compliance officer (or MLRO), and training for staff. A risk-based approach is required: assess your exposure and tailor controls. Supervisors may require a compliance function and periodic reporting. Document your risk assessment and keep policies up to date. See corporate compliance checklist and corporate governance.

AML Compliance Checklist

  • Determine whether you are an obligated entity and identify your supervisor (SAMA, CMA, etc.).
  • Adopt AML/CFT policies, CDD/KYC procedures, and a risk-based approach; designate a compliance officer.
  • Implement suspicious transaction reporting and sanctions screening. See sanctions.
  • Train staff and maintain records; conduct periodic reviews. See PDPL for personal data.
  • Cooperate with supervisors and respond to requests. See corporate compliance checklist.

Frequently Asked Questions

Are all companies subject to AML obligations?
No. Only entities that fall within the defined categories (financial institutions, designated non-financial businesses, etc.) are obligated. If you are a general trading company with no designated activity, you may not be obligated, but you should still consider sanctions and anti-bribery. See sanctions and anti-bribery.
Do we need to screen against sanctions lists?
Yes. Obligated entities must screen customers and transactions against applicable sanctions lists. Even non-obligated entities should avoid dealing with designated persons. See sanctions compliance.
What are the penalties for AML breaches?
Penalties can include substantial fines, licence suspension or revocation, and criminal liability for individuals. The exact sanctions are set in the AML Law and implementing rules. Take compliance seriously. See ZATCA penalties for tax enforcement context.
Is a compliance officer mandatory?
For obligated entities, the law and supervisory rules typically require a designated compliance officer (or MLRO) responsible for AML/CFT. The role and seniority may depend on your size and risk. Check your supervisor’s requirements.
How long must we keep AML records?
The AML Law and regulations set minimum retention periods (typically several years after the end of the relationship or transaction). Ensure your record-keeping meets these and that you can respond to supervisor or FIU requests. See PDPL for data retention limits.
Do fintechs have AML obligations?
Yes. Fintechs that perform regulated activities (e.g. payment services, lending) are typically obligated and supervised by SAMA or CMA. See fintech license. AML/CFT is part of the licensing and ongoing compliance requirements.

AML

Need AML/CFT Compliance Support?

We help with policies, CDD, and reporting.

Related guides

What Comes Next