us

216.73.217.98

Back
News

BNM Issues New Policy For Remote Corporate Customer Onboarding

BNM Issues New Policy For Remote Corporate Customer Onboarding
Richard M. JULY 12, 2021 1 minute read

BNM has issued a new policy document that permits MSBs to onboard customers remotely in the corporate sector. 

The Central Bank of Malaysia, also known as Bank Negara Malaysia (BNM), recently published a new policy document permitting Money Service Businesses to use non-face-to-face verification processes while onboarding new clients. 

E-KYC verification procedures were introduced for individual remittance customers in 2017, while the scope of e-KYC was expanded to money-changing businesses in 2019. 

E-KYC verification processes are implemented by money service businesses to ensure compliance with AML/CFT regulations and to safeguard the safety and integrity of money services. BNM’s policy document sets out the minimum requirements that licensed MSBs must fulfil during remote customer onboarding. 

The document states that Money Service Businesses must first obtain approval from their Board of Directors and Central Bank of Malaysia prior to the implementation of e-KYC verification in corporate customer onboarding.

It also states that corporations need to ensure proper identification and verification procedures of customer identities on a continuing basis in a remote setting in the same way as implemented during in-person verification. Money laundering risks and suspicious transaction reports must also be filed to prevent ML/CFT activities. 

MSBs must also implement at least one additional verification method on top of the mandatory verification procedure, BNM says. Video calls to the customers must be made to ensure they are actually who they claim to be, requiring them to show proof of their business. However, an unannounced introductory phone call must be made prior to the video call. 

During the video call, MSBs may request the person to show proof of business existence. This can include the use of consent notes or inventories.

“Reporting institutions must ensure the systems and technologies developed and used for the purpose of establishing business relationships using non-face-to-face channels (including verification of identification documents) have capabilities to support an effective AML/CFT compliance programme,” the document says.

BNM adds that the companies that fail to comply with the new rules will be facing appropriate enforcement action, including licence suspension or direct action against MSB directors, managerial staff, and other employees. 

Suggested Read: What is Biometric Consent Authentication?

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.