🏆 FlexM is a Finalist — ICA Compliance Awards 2026 & Highly Commended for Team of the Year — Asia Fintech Awards 2026
View Awards ↓
×
Latest Recognition

Award-Recognised Fintech Innovation 2026

FlexM continues to earn industry recognition for its work across compliance AI, RegTech, and fintech innovation.

Asia Fintech Awards 2026 Team of the Year Finalist
Highly Commended

Team of the Year 2026

Asia FinTech Awards 2026

Recognised for the team, collaboration, and execution behind FlexM’s continued work in fintech and RegTech.

Explore Our Solutions →
ICA Compliance Awards 2026 APAC Finalist
● FINALIST

Compliance AI Solution of the Year 2026

ICA Compliance Awards APAC 2026

Shortlisted for FlexComply’s AI-led approach to compliance and financial crime risk management.

Explore FlexComply →
Asia Fintech Awards 2026 Regtech of the Year Finalist
● FINALIST

RegTech of the Year 2026

Asia FinTech Awards 2026

Recognised for FlexComply, FlexM’s 360-degree RegTech platform built to support compliance, risk, monitoring, and reporting workflows.

Explore FlexComply →
×

We're Highly Commended!

FlexM Highly Commended for Team of the Year at the Asia FinTech Awards 2026

See All Our Awards →

What BNM's 2026 Rules Mean for Your EDD Processes in Malaysia?

If your team still treats enhanced due diligence Malaysia 2026 as a quarterly checkbox exercise, you are not simply behind the curve, you are standing precisely where Bank Negara Malaysia's next enforcement action is destined to land.

In January 2026, BNM shifted the compliance landscape for every reporting institution in the country by penalising firms not for systemic negligence, but for isolated oversights. A single customer without adequate EDD (Enhanced Due Diligence). A one-off suspicious transaction report filed a few days late. One nominee account that slipped through without proper scrutiny. These are not penalties against reckless firms. These are penalties against firms that thought they were doing everything right. By targeting these precise, singular gaps, BNM has established a zero-tolerance precedent that renders the traditional playbook of periodic reviews and static name-screening obsolete overnight.

The message could not be louder: firms still operating on manual cycles and quarterly review windows are no longer compliant, they are merely lucky. And in this new era of precision enforcement, luck is not a regulatory strategy.

‍

From Policy to Penalty: How BNM Changed the Game in 2026

‍

For years, the BNM AML/CFT Policy Document was something compliance teams referenced during audits and training sessions but rarely felt the weight of it in daily operations. The 2024 revised policy introduced stricter language around customer due diligence and STR timelines, but many firms treated it as an update to read and revisit later.

2026 has made that approach impossible.

In January alone, BNM moved from guidance to direct enforcement:

  • Boardroom Corporate Services was compounded RM46,000 for failing to conduct EDD on one high-risk customer and two customers receiving nominee services
  • SME Bank faced a RM460,000 Administrative Monetary Penalty for delays in submitting Suspicious Transaction Reports
  • Ilham Secretarial Services was fined RM8,625 for a single failure to report irregular transactions

Combined penalties exceeded RM500,000 in just one month.

What makes this moment different is not the size of the fines. It is the type of firms being targeted and the nature of the failures being penalised. BNM is no longer reserving enforcement for large financial institutions with repeated, documented breakdowns. Every Reporting Institution, regardless of size or sector, is now held to the same standard of continuous regulatory compliance.

‍

The 2026 "Gatekeeper" Warning: In January 2026, BNM issued over RM500,000 in combined penalties against non-bank reporting institutions. The common thread was a failure to perform Enhanced Due Diligence on high-risk profiles and delays in STR submissions. For Malaysia's 20,000+ reporting institutions, including DNFBPs & NBFIs, manual, periodic checks are no longer enough to satisfy BNM's 2026 digital-first mandate.

                                                                                          Discover exactly how automation replaces your manual EDD process

What Does the 2026 Regulatory Compliance Landscape Actually Look Like?

Understanding why BNM has tightened its enforcement posture requires looking at the bigger picture. Malaysia's financial crime environment has deteriorated rapidly, and the regulatory infrastructure is evolving to match.

E-financial fraud cases in Malaysia saw a 185% increase in a single year while the losses from these incidents reached RM458 million. These are not projections or global benchmarks. These are Malaysian numbers, from Malaysian institutions, reported by Malaysia's own National Cyber Security Agency.

Three major regulatory shifts define the 2026 landscape:

  • Basel III Malaysia implementation 2026 is now actively shaping how reporting institutions calculate and report operational risk. Compliance is no longer siloed within AML teams; it intersects with capital adequacy, liquidity management, and enterprise-wide risk governance
  • Operational Risk Reporting (ORR) BNM 2026 has introduced a new submission framework requiring system-level data feeds, not manually compiled spreadsheets. For many DNFBPs (Designated Non-Financial Businesses and Professions) and smaller NBFIs (Non-Bank Financial Institutions), this alone represents a fundamental infrastructure upgrade
  • The Data and Compliance Report (DCR) 2026 remains BNM's primary supervisory tool, but the bar for acceptable submissions has risen sharply. BNM is now cross-referencing DCR data against enforcement findings, meaning inconsistencies between what you report and what BNM observes during inspections will trigger deeper scrutiny and potentially penalties under Section 92 of AMLA

The picture is clear: BNM is building a compliance ecosystem that runs on real-time data, digital infrastructure, and continuous monitoring. Firms still operating on periodic cycles are not just at risk of falling behind, they are at risk of falling foul of a system designed to catch exactly that kind of gap.

‍

What Has Actually Changed in EDD Processes This Year?

‍

The BNM EDD requirements for DNFBPs and reporting institutions across the board have shifted significantly in 2026. These are not incremental updates to existing expectations. They are specific operational changes that affect every reporting institution, whether a bank, MSB, fintech, insurance firm, or professional services provider.
‍

Mandatory Source of Wealth Verification for Foreign PEPs

Reporting institutions must now verify both Source of Funds and Source of Wealth for any customer identified as a foreign Politically Exposed Person (PEP). This is not a recommendation. It is a mandatory requirement. The distinction matters because many firms have historically verified where the money for a specific transaction came from without investigating how the customer accumulated their overall wealth. In 2026, doing one without the other is a gap that BNM has explicitly stated it will penalise.
‍

Beneficial Ownership Reporting Malaysia: The "Look Through" Principle

BNM now expects reporting institutions to go beyond the first layer of corporate structure and identify the natural persons who ultimately own or control a customer entity. For firms dealing with:

  • Complex multi-layered corporate structures
  • Nominee arrangements
  • Trust-based ownership models

This requirement demands investigative depth that static document collection cannot provide. The Institutional Risk Assessment (IRA) BNM framework now factors beneficial ownership transparency directly into a firm's overall risk rating, meaning gaps in BO verification do not just expose you to penalties, they elevate your entire institutional risk profile.

Targeted Financial Sanctions (TFS) Malaysia Screening

Screening obligations have tightened considerably. BNM now requires:

  • Real-time screening against domestic lists maintained by the Ministry of Home Affairs
  • Screening against international lists including UNSCR sanctions
  • Continuous, event-triggered screening that captures changes in designations as they happen, not weeks or months after the fact

The expectation is no longer that firms screen customers at onboarding and periodically thereafter. It is ongoing, automated, and immediate.

Ongoing KYC Verification and Monitoring

The traditional approach to anti-money laundering Malaysia 2026 updates relied on officers manually reviewing transactions against static red flag lists. That model simply cannot handle the volume and speed of today's transaction flows.

BNM now expects automated systems that perform ongoing due diligence, learn customer behaviour and flag genuine anomalies, freeing compliance officers to focus on real risks rather than drowning in false positives.

  • KYC verification must be refreshed at frequencies determined by the customer's risk profile
  • High-risk customers require substantially more frequent reviews
  • Transaction monitoring must be continuous and behavioural, flagging deviations from a customer's established patterns rather than just transactions crossing a static threshold

The shift from rule-based to behaviour-based monitoring is one of the most significant operational changes facing compliance teams this year.
‍

Technology Is No Longer Optional for EDD Compliance

BNM's 2026 framework is built on the assumption that firms will use technology to meet these obligations. Manual processes simply cannot keep pace with what is now required.

MyDigital ID: The Infrastructure Shift Nobody Can Ignore

2026 is the year MyDigital ID moves from pilot to implementation across Malaysia's financial sector:

  • 18 banks completed Phase 2 sandbox testing for e-verification
  • 15 banks and fintechs, including Maybank, CIMB, Public Bank, and RHB, signed integration agreements
  • E-verification now links directly to the National Registration Department database as a single source of truth

For EDD, this means KYC (Know Your Customer) checks and identity verification are shifting to real-time, government-database-linked authentication. MyDigital ID verifies identities against the National Registration Department database, providing a single source of truth for customer identity.
‍

Your 2026 Enhanced Due Diligence Compliance Checklist
  1. Update your Institutional Risk Assessment to reflect 2026 regulatory changes, customer base, and geographic exposure
  2. Implement real-time PEP checks and sanctions screening with event-triggered rescreening against domestic and international lists
  3. Verify both Source of Wealth and Source of Funds for all foreign PEPs and high-risk customers
  4. Apply the "Look Through" principle to identify ultimate beneficial owners behind layered structures and nominee arrangements
  5. Deploy behavioural transaction monitoring that flags pattern deviations, not just threshold breaches
  6. Automate STR workflows to eliminate the filing delays BNM penalised in January 2026
  7. Prepare for MyDigital ID integration in your onboarding and verification workflows
  8. Cross-verify your DCR 2026 submission against internal records before filing
    ‍
Preparing for What Comes Next

BNM's 2026 enforcement actions are the starting point, not the finish line. Malaysia is preparing for its next Financial Action Task Force (FATF) mutual evaluation, and the country's performance will directly shape regulatory expectations for years ahead.

For reporting institutions looking to bridge the gap between where their compliance operations stand today and where BNM expects them to be, FlexM, the leading global fintech conglomerate, offers FlexComply, a 360-degree compliance platform built for exactly this regulatory environment. With automated KYC verification, real-time PEP checks, and enhanced due diligence capabilities aligned to BNM's 2026 framework, FlexComply enables firms to move from reactive compliance to continuous, confident oversight.

                                                                                       Most firms fail 3 of these 8 checks. Find out which ones

‍

Frequently Asked Questions

Who needs to perform EDD in Malaysia?

Every reporting institution under AMLA, including banks, money service businesses, fintechs, insurance companies, securities firms, and professional services firms like company secretaries, law firms, and accountants. If BNM classifies you as a reporting institution, EDD obligations apply to you.

When is EDD triggered for a customer?

EDD is triggered when a customer is assessed as high-risk, is identified as a foreign PEP, operates from a high-risk jurisdiction, uses nominee services, or when a transaction raises suspicion of money laundering or terrorism financing.

BNM can impose compounds under Section 92 of AMLA or Administrative Monetary Penalties under the Financial Services Act 2013.

Do I need technology to comply with BNM's 2026 EDD requirements?

Practically, yes. The requirements around real-time screening, behavioural monitoring, ORR digital submissions, and MyDigital ID integration are designed around automated systems. Manual processes alone cannot meet the speed and depth BNM now expects.

Thank you! We have received your inquiry.
We have received your message. We’ll reach you out immediately!
Ok, great
Connect with Us
Our team is happy to answer your sales questions. Fill out the form and we’ll be in touch as soon as possible.