Saudi Arabia has built one of the most comprehensive anti-money laundering and know-your-customer frameworks in the Gulf region. The Kingdom';s AML & KYC regime applies to banks, fintechs, insurance companies, real estate brokers, lawyers, accountants and a growing range of designated non-financial businesses. Non-compliance carries criminal liability, licence revocation and reputational damage that can close a business permanently. This guide covers the legal foundations, the competent authorities, customer due diligence requirements, recent regulatory updates, enforcement trends and what foreign-owned businesses operating in Saudi Arabia must do to remain compliant.
The legal framework governing AML & KYC in Saudi Arabia
The primary statute is the Anti-Money Laundering Law, issued by Royal Decree M/20 and most recently amended to align with the Financial Action Task Force recommendations. The law criminalises money laundering, terrorist financing and proliferation financing, and imposes obligations on a broad category of reporting entities. Alongside it, the Combating Terrorism Crimes and Financing Law extends obligations to the detection and reporting of terrorism-related financial flows.
The Implementing Regulations issued under the AML Law provide granular rules on customer due diligence, record-keeping, suspicious transaction reporting and internal controls. These regulations are the operational backbone of the compliance framework and are updated periodically by the Saudi Central Bank, known as SAMA, and the Capital Market Authority, known as CMA. Businesses must track both the primary law and the implementing regulations, because the regulations often impose stricter or more specific obligations than the statute itself.
Saudi Arabia is a member of the FATF and the Middle East and North Africa Financial Action Task Force, known as MENAFATF. The Kingdom underwent a mutual evaluation that assessed its technical compliance and effectiveness. The results of that evaluation have driven a sustained programme of legislative and supervisory reform, and the current framework reflects those recommendations directly.
Competent authorities and their roles
Several regulators share responsibility for AML & KYC supervision in Saudi Arabia, each covering a distinct sector.
- SAMA supervises banks, exchange houses, insurance companies, finance companies and payment service providers.
- The CMA supervises broker-dealers, investment managers, securities firms and listed companies.
- The Financial Intelligence Unit, known as the FIU or Safwa, receives and analyses suspicious transaction reports and financial intelligence from all reporting entities.
- The Ministry of Commerce oversees designated non-financial businesses and professions, including real estate agents, dealers in precious metals and stones, and company service providers.
- The General Authority for Zakat and Tax, known as GAZT, has a role in monitoring financial flows relevant to tax compliance that intersects with AML obligations.
In practice, SAMA is the dominant AML supervisor for most financial institutions. It conducts on-site inspections, issues guidance circulars and imposes administrative sanctions. The FIU acts as the national centre for financial intelligence and cooperates with international counterparts through the Egmont Group.
Customer due diligence: what businesses must do
Customer due diligence, or CDD, is the operational core of any AML & KYC programme in Saudi Arabia. The Implementing Regulations require reporting entities to identify and verify the identity of customers before establishing a business relationship or conducting an occasional transaction above the applicable threshold.
For individual customers, verification requires a valid national identity card for Saudi nationals or a residency permit and passport for foreign nationals. For legal entities, businesses must obtain the commercial registration, articles of association, and information on the beneficial owners who ultimately own or control the entity. The beneficial ownership threshold under current Saudi rules is set at ownership or control of twenty-five percent or more, though entities must also identify any person exercising effective control regardless of percentage.
Enhanced due diligence, known as EDD, is mandatory in higher-risk situations. These include:
- Customers who are politically exposed persons, or PEPs, whether domestic or foreign.
- Correspondent banking relationships with foreign financial institutions.
- Transactions involving jurisdictions identified as high-risk by FATF or by SAMA.
- Complex or unusually large transactions with no apparent economic purpose.
Simplified due diligence is permitted for lower-risk customers, but only where the reporting entity has documented its risk assessment and obtained supervisory acceptance of its risk-based approach. A common mistake among foreign-owned businesses entering Saudi Arabia is assuming that simplified CDD applies broadly. In practice, SAMA expects robust documentation of the rationale for any simplified measures.
Ongoing monitoring is a continuous obligation. Reporting entities must review customer files at intervals proportionate to risk, update beneficial ownership information when it changes, and screen customers against sanctions lists maintained by the United Nations, OFAC and Saudi domestic lists on an ongoing basis.
Suspicious transaction reporting and record-keeping
Reporting entities in Saudi Arabia are required to file a suspicious transaction report, known as an STR, with the FIU whenever they know, suspect or have reasonable grounds to suspect that a transaction or attempted transaction involves proceeds of crime or is connected to terrorist financing. There is no minimum threshold for STR filing. The obligation applies regardless of the amount involved.
The tipping-off prohibition is strict. A reporting entity that files an STR must not disclose to the customer or any third party that a report has been made. Violation of this prohibition is itself a criminal offence under the AML Law.
Record-keeping requirements mandate that reporting entities retain all customer identification documents, transaction records and correspondence for a minimum of ten years from the end of the business relationship or the date of the transaction. Records must be stored in a format that allows them to be retrieved promptly in response to a regulatory or law enforcement request.
In practice, many businesses underestimate the operational burden of record-keeping. A non-obvious requirement is that records must be maintained in a way that allows reconstruction of individual transactions, not merely aggregated data. Foreign businesses operating through Saudi subsidiaries should ensure that their group-level document management systems meet this granular standard.
If your business is establishing or reviewing its AML & KYC programme in Saudi Arabia, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Recent updates and current enforcement trends
Saudi Arabia';s AML & KYC framework has evolved significantly in recent years, driven by the FATF mutual evaluation findings and the Kingdom';s Vision 2030 financial sector development agenda.
SAMA has issued updated guidance on the risk-based approach to AML supervision, requiring financial institutions to document their enterprise-wide risk assessments more rigorously and to demonstrate that their compliance resources are allocated proportionately to risk. The guidance places particular emphasis on the quality of suspicious transaction reporting, not just the volume. Regulators have signalled that they will scrutinise whether STRs contain actionable intelligence, not merely defensive filings.
The CMA has strengthened its AML rules for the capital markets sector, introducing requirements for investment firms to conduct AML risk assessments specific to their product lines and distribution channels. Firms offering digital asset services face additional scrutiny, as the regulatory perimeter for virtual asset service providers has been extended.
Real estate has emerged as a priority sector. The Ministry of Commerce has increased inspections of real estate brokers and developers, reflecting FATF guidance that real estate is a high-risk channel for money laundering. Businesses in this sector that have not yet implemented formal CDD and STR procedures face significant exposure.
Enforcement has become more active. SAMA has publicly announced administrative penalties against financial institutions for AML control failures, including fines and requirements to remediate specific deficiencies within defined timeframes. Criminal referrals to the Public Prosecution for serious AML failures are no longer rare. The trend is toward higher penalties and faster enforcement timelines, which makes proactive compliance more cost-effective than reactive remediation.
AML & KYC obligations for foreign-owned businesses in Saudi Arabia
Foreign investors and multinational groups operating in Saudi Arabia through a wholly foreign-owned company, a joint venture or a branch face the same AML & KYC obligations as domestic entities. There is no exemption based on foreign ownership, and group-level compliance programmes designed for other jurisdictions do not automatically satisfy Saudi requirements.
A practical scenario: a European financial services group establishes a Saudi subsidiary to offer investment products. The subsidiary must implement a standalone AML programme that meets SAMA and CMA requirements, appoint a dedicated compliance officer resident in Saudi Arabia, and file STRs directly with the FIU. The group';s home-country programme can inform the design, but it cannot substitute for local compliance.
A second scenario: a multinational real estate developer enters the Saudi market through a joint venture with a local partner. The joint venture entity is a reporting entity for AML purposes. Both partners bear responsibility for ensuring the joint venture has adequate CDD procedures, even if day-to-day compliance is delegated to the local partner. Foreign partners who assume that local partners will handle compliance without formal documentation of responsibilities frequently find themselves exposed when regulators investigate.
Foreign businesses should also be aware that SAMA and the CMA conduct group-wide assessments when a Saudi entity is part of an international group. Regulators may request information about the group';s global AML programme, its beneficial ownership structure and any adverse regulatory findings in other jurisdictions. Transparency with Saudi regulators about group-level matters is strongly advisable.
FAQ
What are the consequences of failing to file a suspicious transaction report in Saudi Arabia?
Failure to file an STR when required is a criminal offence under the Anti-Money Laundering Law. Penalties can include imprisonment and substantial fines for responsible individuals, as well as administrative sanctions against the reporting entity itself, including licence suspension or revocation. Regulators treat STR failures as evidence of systemic control weakness, which typically triggers a broader supervisory investigation. In practice, the reputational consequences of a public enforcement action often exceed the direct financial penalties.
How long does it take to build a compliant AML programme for a new Saudi entity, and what does it cost?
The timeline depends on the entity type and the complexity of its business. A straightforward financial institution can expect to spend several months designing, documenting and testing its AML programme before it is ready for regulatory scrutiny. Professional fees for legal and compliance advisory work typically start from the low thousands of USD for basic programme documentation and rise significantly for complex or multi-product businesses. Ongoing costs include the salary of a dedicated compliance officer, technology for transaction monitoring and sanctions screening, and periodic external audits. Many businesses underestimate the recurring cost relative to the one-time setup investment.
Does Saudi Arabia';s AML framework apply to digital assets and cryptocurrency businesses?
Saudi Arabia has extended its AML perimeter to cover virtual asset service providers operating in the Kingdom. Businesses offering exchange, transfer, custody or other services involving digital assets are subject to CDD, STR and record-keeping obligations equivalent to those applying to traditional financial institutions. The regulatory framework for digital assets is still developing, and businesses in this sector should monitor guidance from SAMA and the CMA closely. Operating a digital asset business without a clear regulatory authorisation and a documented AML programme carries significant legal risk.
Conclusion
Saudi Arabia';s AML & KYC framework is rigorous, actively enforced and continuing to evolve. Businesses operating in the Kingdom - whether in finance, real estate, professional services or digital assets - must treat compliance as an operational priority, not a back-office function. The cost of getting it right is manageable; the cost of getting it wrong is not.
VLO Law Firms advises international clients on AML & KYC matters in Saudi Arabia. We can assist with programme design, regulatory gap analysis, beneficial ownership documentation, STR procedures and engagement with SAMA, the CMA and the FIU. To request a consultation, contact: info@vlolawfirm.com