AML & KYC in Israel is governed by a comprehensive legal framework that applies to banks, financial service providers, fintech companies, and a growing range of non-financial businesses. Israel is a member of the Financial Action Task Force (FATF) and has aligned its domestic rules closely with international standards. Businesses operating in Israel - or transacting with Israeli counterparties - face real compliance obligations with meaningful penalties for failure. This guide covers the legal foundations, the key obligations for regulated entities, recent regulatory updates, and the practical steps businesses need to take.
The primary legislation is the Prohibition on Money Laundering Law, 5760-2000 (the "PMLL"). This statute defines money laundering offences, establishes reporting obligations, and sets out the powers of the competent authorities. It has been amended several times to reflect evolving FATF recommendations and to close gaps identified in mutual evaluation reports.
Alongside the PMLL, the Prohibition on Financing of Terrorism Law, 5765-2005 applies to a broad range of entities. This law requires regulated businesses to screen customers and transactions against designated lists and to report suspicious activity connected to terrorism financing. The two statutes work in tandem and are frequently referred to together in regulatory guidance.
Secondary legislation takes the form of orders issued under the PMLL. These orders - covering banks, insurance companies, portfolio managers, currency service providers, and others - specify the detailed customer due diligence (CDD) requirements, record-keeping obligations, and reporting thresholds applicable to each sector. The Bank of Israel, the Israel Securities Authority (ISA), and the Capital Market, Insurance and Savings Authority (CMISA) each issue sector-specific directives that supplement the statutory orders.
The Israel Money Laundering and Terror Financing Prohibition Authority (IMPA) sits at the centre of the system. IMPA is the national financial intelligence unit (FIU). It receives suspicious transaction reports (STRs), analyses financial intelligence, and shares information with law enforcement and foreign FIUs. Regulated entities report directly to IMPA using prescribed electronic forms.
The scope of regulated entities under the PMLL is broad and has expanded in recent years. The following categories are currently subject to full CDD and reporting obligations:
The extension of AML obligations to designated non-financial businesses and professions (DNFBPs) reflects FATF Recommendation 22. Israel has progressively tightened these requirements following its most recent FATF mutual evaluation. Fintech companies and virtual asset service providers (VASPs) are now explicitly covered under amendments to the PMLL and the relevant orders, making Israel one of the more advanced jurisdictions in regulating crypto-related AML compliance.
KYC in Israel requires regulated entities to identify and verify customers before establishing a business relationship or executing a transaction above the applicable threshold. The standard CDD process involves three core elements: identification, verification, and ongoing monitoring.
For individual customers, identification requires collecting full legal name, date of birth, national identity number or passport details, and residential address. Verification must be based on reliable, independent source documents - typically a government-issued identity document. For corporate customers, the entity';s registration documents, ownership structure, and the identity of ultimate beneficial owners (UBOs) holding ten percent or more of shares or voting rights must be established and verified.
Enhanced due diligence (EDD) applies in higher-risk situations. These include transactions involving politically exposed persons (PEPs), customers from high-risk jurisdictions identified by FATF, complex or unusually large transactions, and business relationships with no apparent economic purpose. EDD requires senior management approval, more intensive document collection, and more frequent monitoring of the relationship.
Simplified due diligence (SDD) is permitted in limited circumstances where the risk is demonstrably low - for example, certain publicly listed companies or government entities. However, regulated entities must document their risk assessment and cannot apply SDD as a default.
A non-obvious requirement is that Israeli law imposes a positive obligation to understand the purpose and intended nature of the business relationship. It is not sufficient to collect documents and file them. The regulated entity must form a reasoned view of what the customer does, why they need the product or service, and whether the activity is consistent with their profile. This "know your business" element is frequently underweighted by foreign-owned entities entering the Israeli market.
Regulated entities in Israel are required to file an STR with IMPA whenever they know, suspect, or have reasonable grounds to suspect that a transaction involves proceeds of crime or is connected to terrorism financing. The obligation to report is not contingent on certainty - suspicion alone triggers the duty. Tipping off the customer that a report has been filed is a criminal offence.
In addition to STRs, certain entities must file currency transaction reports (CTRs) for cash transactions above prescribed thresholds. The thresholds vary by sector and are set out in the relevant orders. Regulated entities must also report cross-border cash movements and certain wire transfers that meet the applicable criteria.
Record-keeping requirements are stringent. All CDD documents, transaction records, and reports must be retained for at least seven years from the end of the business relationship or the date of the transaction. Records must be stored in a manner that allows them to be retrieved and provided to IMPA or the relevant supervisor within a reasonable time. Many entities now maintain digital records, but the legal obligation to produce originals or certified copies on request remains.
A common mistake among smaller regulated entities - particularly currency service providers and real estate agents new to the AML regime - is treating record-keeping as a back-office administrative task rather than a core compliance function. Supervisory inspections frequently reveal gaps in document completeness, inadequate version control, and missing beneficial ownership records. These gaps attract regulatory sanctions even where no underlying money laundering has occurred.
If your business is establishing or reviewing its AML compliance programme in Israel, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Israel';s AML framework has undergone significant development in recent periods. The most consequential changes relate to virtual assets, beneficial ownership transparency, and the professionalisation of compliance functions.
The regulation of VASPs has been formalised through amendments to the PMLL and a dedicated order covering virtual asset service providers. VASPs operating in Israel - including crypto exchanges, custodians, and certain DeFi-adjacent businesses - must now register with the relevant authority, implement full CDD procedures, and file STRs on the same basis as traditional financial institutions. The travel rule, requiring VASPs to transmit originator and beneficiary information with virtual asset transfers, has been incorporated into Israeli regulatory expectations in line with FATF Recommendation 16.
Beneficial ownership transparency has been strengthened through amendments to the Companies Law and the relevant AML orders. The Israeli Companies Registrar now maintains a beneficial ownership register for companies. Regulated entities are required to verify UBO information against this register as part of their CDD process. Discrepancies between declared ownership and registered information must be escalated and, where appropriate, reported to IMPA.
The ISA and CMISA have both issued updated supervisory guidance emphasising the need for risk-based compliance programmes rather than tick-box approaches. Regulated entities are expected to conduct and document enterprise-wide money laundering risk assessments, calibrate their controls to the identified risks, and review those assessments at least annually or when material changes occur.
Israel';s FATF mutual evaluation process has also prompted legislative attention to the effectiveness of enforcement. IMPA';s powers to share financial intelligence with foreign FIUs have been clarified, and the penalties for non-compliance with AML obligations have been reviewed to ensure they are proportionate and dissuasive.
Non-compliance with AML and KYC obligations in Israel carries serious consequences. Criminal liability under the PMLL can result in significant custodial sentences for individuals and substantial fines for legal entities. The offence of money laundering itself carries a maximum sentence of ten years'; imprisonment, with higher penalties where the offence involves an organised crime group or a public official.
Administrative sanctions are the more common enforcement tool for compliance failures that do not rise to the level of criminal conduct. The Bank of Israel, ISA, and CMISA each have the power to impose financial penalties, issue public reprimands, restrict business activities, and revoke licences. Recent enforcement actions have targeted failures in CDD documentation, inadequate STR filing, and deficient internal controls.
Supervisory expectations have shifted from a purely rules-based model to a risk-based approach. Regulators now expect regulated entities to demonstrate that they understand their own risk exposure, have designed controls proportionate to that exposure, and can evidence the effectiveness of those controls over time. A compliance programme that looks good on paper but is not embedded in day-to-day operations will not satisfy a supervisory inspection.
In practice, founders and compliance officers should consider that Israeli regulators share information with foreign counterparts. A compliance failure identified by IMPA may be communicated to the FIU of another jurisdiction where the entity or its principals operate. This cross-border dimension makes local compliance a matter of global reputational risk.
Two practical scenarios illustrate the stakes. First, a foreign fintech company establishing an Israeli subsidiary to serve local customers must implement a full AML programme before onboarding any clients - not as a post-launch project. Second, a real estate developer receiving payments from foreign buyers must conduct CDD on those buyers and verify the source of funds, even where the transaction is structured through a corporate vehicle. Failure to do so is a breach of the PMLL regardless of whether the underlying funds are legitimate.
What are the main compliance obligations for a foreign company operating in Israel?
A foreign company that establishes a regulated business in Israel - whether a branch or a subsidiary - must comply with the PMLL and the relevant sector-specific orders from the date it begins operating. This means implementing a written AML compliance programme, appointing a designated compliance officer, conducting CDD on all customers, maintaining records for at least seven years, and filing STRs with IMPA when required. The compliance programme must be risk-based and documented. Foreign companies sometimes assume that group-level policies from their home jurisdiction are sufficient; Israeli law requires a locally adapted programme that addresses the specific risks of the Israeli market and meets the requirements of the applicable orders.
How long does it take to build a compliant AML programme, and what does it cost?
The timeline depends on the size and complexity of the business. A straightforward currency service provider or small investment adviser can typically implement a basic compliant programme within two to three months, assuming management commitment and access to competent legal and compliance advice. Larger or more complex entities - particularly those with diverse product lines or international customer bases - should allow four to six months for a thorough programme build. Professional fees for legal and compliance advisory work vary considerably. Smaller entities typically spend in the low to mid thousands of EUR equivalent; larger institutions with complex risk profiles may spend significantly more. Ongoing costs include staff training, technology for transaction monitoring, and periodic independent reviews.
Does Israel';s AML framework apply to crypto and virtual asset businesses?
Yes. Virtual asset service providers operating in Israel are now explicitly subject to the PMLL and the dedicated VASP order. This covers exchanges, custodians, and other businesses that provide services involving virtual assets. VASPs must register with the relevant authority, conduct full CDD on customers, implement transaction monitoring, apply the travel rule to qualifying transfers, and file STRs with IMPA. The regulatory treatment of VASPs in Israel is broadly aligned with FATF standards, and the authorities have signalled that enforcement in this sector will intensify. Businesses operating in the virtual asset space should not assume that the absence of a traditional banking relationship reduces their AML exposure - the obligations apply regardless of the payment method used.
AML & KYC in Israel is a mature, FATF-aligned framework that applies to a wide range of financial and non-financial businesses. The recent expansion to cover virtual assets, the strengthening of beneficial ownership requirements, and the shift to risk-based supervision all signal that the regulatory environment will continue to evolve. Businesses that treat compliance as a one-time exercise rather than an ongoing programme face real enforcement risk.
VLO Law Firms advises international clients on AML & KYC matters in Israel. We can assist with compliance programme design, CDD policy drafting, regulatory registration, and ongoing advisory support. To request a consultation, contact: info@vlolawfirm.com