AT A GLANCE
Bank Negara Malaysia’s (BNM) 2025 exposure draft on electronic money (“e-money”) introduces strengthened anti-money laundering and counter financing of terrorism (AML/CFT) obligations for e-money issuers (EMIs). The revised policy document – effective January 31, 2025, significantly raises the bar for AML/CFT compliance across all e-money issuers operating in Malaysia. The policy introduces explicit obligations around customer due diligence, sanctions screening, real-time transaction monitoring, risk-based controls, and governance accountability. A RM600,000 fine against Touch 'n Go eWallet for sanctions screening failures makes clear that BNM is actively enforcing these requirements, and that the cost of non-compliance now far exceeds the investment required to build a compliant program. Malaysian fintechs and e-wallet providers that have not yet aligned their compliance infrastructure with these updated requirements face real licensing and reputational risk.
What Is BNM's 2025 E-Money Policy Document and Who Does It Apply To?
Bank Negara Malaysia's 2025 exposure draft on electronic money is a revised policy document that strengthens AML/CFT obligations for all e-money issuers operating in Malaysia. The policy took effect on January 31, 2025, and is aimed at ensuring the safety and reliability of e-money services while preserving public confidence in digital payment infrastructure.
The policy applies to e-money issuers operating open-loop e-money products, meaning digital wallets and payment products accepted by multiple merchants or across multiple platforms. This includes mainstream e-wallet providers, payment facilitators, and fintech companies that issue or manage electronic money as part of their product offering.
The revised framework reflects BNM's broader commitment to bringing digital payment providers in line with the AML/CFT standards applied to traditional financial institutions. As digital payment volumes grow, BNM has made clear it expects the same rigor in compliance controls regardless of whether the institution is a licensed bank or a fintech startup.
Which E-Money Businesses Are Exempted from BNM's AML/CFT Requirements?
Limited-purpose e-money is exempted from BNM's main e-money AML/CFT guidelines under a separate exemption order. Closed-loop gift cards, merchant loyalty points, and prepaid value usable only at a single merchant or within a single platform fall into this category. Their lower risk profile, restricted usability, and limited exposure to cross-merchant money movement justify the regulatory carve-out.
All other e-money products, particularly open-loop wallets usable across multiple merchants and payment contexts, are subject to the full scope of BNM's AML/CFT requirements. If your product allows customers to send funds to other users, pay across multiple merchants, or interact with external payment networks, it falls within the regulated scope.
Tip: If you are unsure whether your product qualifies as limited-purpose e-money under BNM's exemption order, apply the cross-merchant usability test. If your e-money is accepted at more than one merchant or can be transferred to third parties, assume full AML/CFT obligations apply and build your compliance program accordingly.
What Are the New AML/CFT Requirements for E-Money Issuers Under BNM's 2025 Policy?
BNM's 2025 policy introduces five core AML/CFT obligations that every e-money issuer must address. Each requirement carries direct operational implications for how e-wallet providers design their onboarding flows, transaction monitoring systems, and internal governance structures.
Customer Due Diligence
E-money issuers must perform thorough customer due diligence on all customers at onboarding. This includes verifying customer identity, identifying beneficial owners and beneficiaries where applicable, and understanding the purpose of the account. CDD now explicitly integrates sanctions screening as a mandatory onboarding step, rather than treating it as a separate process. For corporate or high-risk clients, enhanced due diligence applies, requiring additional verification of business ownership and source of funds. All CDD information must be kept current and reviewed periodically, with more frequent reviews required for higher-risk customers.
Sanctions and PEP Watchlist Screening in Malaysia
Sanctions and politically exposed person screening are non-negotiable under BNM's updated policy. Every new customer must be screened against Malaysia's Domestic List and the United Nations Security Council resolutions list before onboarding is completed. Existing customers must be re-screened regularly against both lists as part of ongoing due diligence. Screening must be fully integrated into both initial CDD and ongoing monitoring processes, not treated as a separate periodic exercise. BNM's enforcement record makes clear that failure to screen, even once, constitutes a serious compliance breach with significant financial and reputational consequences.
Ongoing AML Transaction Monitoring in Malaysia
BNM expects e-money issuers to continuously monitor all customer transactions for suspicious patterns and inconsistencies throughout the customer relationship. Real-time transaction monitoring is explicitly stressed as essential, not as a best practice but as a regulatory expectation. Transactions must be assessed against the customer's known risk profile and expected behavior. Unusual or large transactions must trigger alerts and prompt reviews. E-money issuers must maintain systems capable of transaction risk scoring, filing suspicious transaction reports with the Financial Intelligence Unit when suspicion thresholds are met, and documenting investigation decisions comprehensively.
Risk-Based Controls and the EMI Tiered Approach
BNM's 2025 policy introduces a risk-based framework that calibrates compliance obligations to the type and scale of each e-money business. The policy distinguishes between Standard EMI and Eligible EMI categories. Notably, “limited purpose” e-money (such as closed-loop gift cards or loyalty points usable only at a single merchant or platform) has been carved out of the main e-money guidelines. Eligible EMIs are large issuers that exceed defined user or transaction thresholds. These larger operators face heightened regulatory expectations compared to smaller players, including higher capital requirements and more intensive oversight. Higher-risk customers, such as those with high transaction volumes or foreign politically exposed person status, require stronger controls including lower transaction limits, source-of-funds verification, and more frequent account reviews. The principle is proportionality: stricter controls apply where risk is demonstrably higher.
Licensing, Governance, and Personal Liability
AML/CFT compliance is now directly tied to licensing and governance standards. To obtain and retain an EMI license in Malaysia, firms must demonstrate robust governance and a fully operational compliance framework. Boards must have clear accountability for AML compliance, including appointing a qualified compliance officer, setting a documented risk appetite, and reviewing AML reports on a regular schedule. Senior management must ensure effective program implementation, ongoing staff training, and independent internal audits. BNM has also signaled that individual officers, including directors and compliance officers, can be held personally liable for institutional AML failures. This is not a theoretical risk. It is an active enforcement posture.
Tip: Document your board's AML oversight activity explicitly. Board meeting minutes, signed risk appetite statements, and compliance officer reports are the evidence BNM expects to see during an inspection. If your board is not actively engaging with AML compliance on a scheduled basis, that gap is a governance finding waiting to happen.
What Happened When Touch 'n Go eWallet Failed BNM's AML/CFT Requirements?
In May 2023, BNM fined TNG Digital Sdn. Bhd., the operator of Touch 'n Go eWallet, RM600,000 for serious AML/CFT compliance failures. The enforcement action arose from two distinct incidents. In one case, TNG Digital conducted no sanctions screening whatsoever on a new customer during onboarding. In the other, it failed to check a customer's name against both the UN and domestic sanctions lists. In both instances, individuals who should have been barred from opening accounts were able to register successfully.
BNM determined that these failures constituted breaches of its AML/CFT policy for Electronic Money (Sector 4) and the broader AML/CFT and Targeted Financial Sanctions requirements for financial institutions. Even though TNG Digital self-identified the compliance gaps and voluntarily reported them to BNM, the regulator imposed the full administrative monetary penalty. The company paid the fine by the end of May 2023.
The Touch 'n Go case carries several important lessons for Malaysian e-wallet providers. First, self-reporting does not eliminate regulatory consequences. Second, a single missed screening event at onboarding is sufficient to trigger a public enforcement action. Third, the reputational cost of a publicized BNM fine extends well beyond the financial penalty itself, affecting customer trust and partner relationships. Fourth, and most critically, the case demonstrates that manual screening processes are inherently unreliable at scale. A human oversight error in a high-volume onboarding environment is not a question of if, but when.
BNM's willingness to act on even first-time or inadvertent failures signals that regulatory tolerance for AML/CFT lapses in fintech and e-money operations is extremely low. Proactive, automated compliance is now a licensing and reputational necessity.
Tip: Treat every onboarding event as an auditable compliance action. Your system should generate a time-stamped record confirming that sanctions screening was completed for each new customer, what lists were checked, and what the outcome was. If BNM requests evidence that a specific customer was screened, you should be able to produce that record within minutes, not hours.
What Does KYC and AML Screening in Malaysia Require for E-Wallet Providers?
KYC and AML screening in Malaysia for e-wallet providers involves three integrated processes that must function together as a single compliance workflow rather than as separate operational tasks.
Identity verification is the foundation of KYC. E-money issuers must confirm that customers are who they claim to be, using documentation and data verification processes appropriate to the risk level of the account being opened. For individual customers, this typically involves government-issued ID verification and face-matching checks. For corporate customers or higher-risk individuals, additional documentation is required.
Name screening against sanctions and PEP lists must occur at onboarding and on an ongoing basis. The Domestic List maintained by BNM and the UNSC sanctions list are both mandatory reference databases. Additional watchlists may be required depending on the institution's risk appetite and the geographic profile of its customer base. The challenge at scale is false positive management. Common Malaysian names frequently generate false matches against watchlist entries. Without intelligent name-matching technology, a high-volume e-wallet operator will generate more false positives than its compliance team can process, creating the operational conditions for genuine matches to be missed.
Ongoing due diligence requires that e-money issuers continue monitoring customer behavior and risk profiles throughout the customer relationship. Changes in transaction patterns, account behavior, or publicly available information about a customer that affects their risk classification must trigger a review. Higher-risk customers require more frequent periodic reviews than standard-risk customers.
What AML Infrastructure Do Malaysian Fintechs Need to Meet BNM's 2025 Standards?
Traditional manual compliance processes are no longer adequate for meeting BNM's 2025 requirements. E-money providers with customer bases in the hundreds of thousands or millions, processing high-volume, low-value transactions, need automated infrastructure that can operate at the speed and scale the regulatory environment demands.
A compliant AML infrastructure for Malaysian e-money issuers must deliver real-time transaction monitoring that flags suspicious activity as it occurs rather than through batch reviews conducted days after the fact. Real-time transaction monitoring and prompt detection of suspicious activities are stressed as essential by BNM. This is operationally impossible without a real-time monitoring engine.
Risk-based scoring must be automatic and dynamic. Every customer and transaction should carry a risk score that updates as new information becomes available. This allows compliance resources to concentrate where risk is highest, which is both operationally efficient and aligned with BNM's risk-based approach.
Comprehensive record-keeping and audit trails are not optional. Every CDD check, every watchlist screening result, every alert generated, and every investigation step must be logged and retrievable. BNM inspections and regulatory inquiries require institutions to produce documented evidence of their risk controls and decision-making. Ad-hoc manual processes cannot reliably produce this evidence under examination conditions.
Intelligent false positive management is essential for operational sustainability. A monitoring system that generates thousands of false positive alerts per day will paralyze a compliance team, creating the same risk of genuine matches being missed as a system with no monitoring at all. AI-driven false positive suppression is now a practical necessity for e-money operators at scale.
How Does Flagright Help Malaysian E-Money Providers Meet BNM's AML/CFT Requirements?
Flagright is a compliance technology platform used by fintechs and financial institutions, including those in Malaysia, to address these operational and regulatory challenges. It provides an AI-native, unified AML compliance solution designed for real-time compliance management across the full scope of BNM's requirements.
Real-Time Transaction Monitoring and Risk Scoring
Flagright enables immediate, rules-based monitoring of all transactions, identifying and responding to risks at the point of transaction. The platform's engine flags or blocks suspicious activities based on configurable scenarios and thresholds aligned with BNM's guidelines. Compliance teams can customize rules to set wallet loading limits, detect rapid successive transactions, or flag transactions inconsistent with a customer's established behavioral profile. Every transaction receives a dynamic risk score that adapts continuously as new data arrives, ensuring that higher-risk patterns are escalated immediately. The monitoring engine operates in sub-second real time, meeting BNM's expectation for proactive oversight across payments and remittances.
Sanctions and PEP Screening for Malaysian E-Wallets
Flagright's AML screening checks individuals against global sanctions lists, PEP databases, and other watchlists through API integrations. For Malaysian e-wallet operators, this includes the BNM Domestic List and the UNSC sanctions list as required under the 2025 policy. What distinguishes Flagright's screening capability is its use of AI Forensics technology to suppress false positives. The platform can automatically clear up to 93% of false positives, dramatically reducing the noise that overwhelms compliance teams at high onboarding volumes. When a new customer shares a common name with a watchlist entry, the AI distinguishes between a genuine match and a benign name coincidence. Genuine matches are immediately flagged for human review. All screening activities and decisions are logged automatically, and the system continuously improves accuracy over time.
Integrated Case Management and Audit Logging
When a transaction alert is triggered or a sanctions hit is identified, Flagright's integrated case management system streamlines the investigation process. Compliance officers can triage alerts, attach supporting notes, access customer KYC information and transaction history, and document investigation outcomes within a single platform. Every action taken in an investigation is automatically recorded, creating a detailed audit trail that is retrievable on demand. If BNM requests evidence of how a specific case was handled, the complete record is available immediately: what was flagged, who reviewed it, what action was taken, and when. Flagright's case management also supports multi-team collaboration, ensuring that no suspicious activity falls through the cracks and that all outcomes, including STR filings, are properly documented.
No-Code Rule Builder for Regulatory Agility
BNM's regulatory requirements evolve continuously, as demonstrated by the 2025 policy update itself. Flagright's no-code rule configuration interface allows compliance teams to create or modify detection rules and risk scoring models through an intuitive dashboard, without requiring engineering support. If BNM issues new guidelines targeting specific transaction types, high-risk geographies, or emerging fraud typologies, a compliance officer can update monitoring rules immediately. Changes can be tested in a shadow rule environment before deployment, ensuring no gap in coverage during transitions. This operational flexibility is particularly valuable for mid-sized fintechs without large engineering teams, who cannot afford to wait weeks for IT-supported rule updates when regulatory requirements change. Flagright also supports Malaysian data residency requirements and provides out-of-the-box rules aligned with BNM's compliance framework, reducing the implementation burden for new EMIs building their compliance programs from the ground up.
Tip: Use shadow rule testing before deploying any new monitoring rule in a live environment. Testing a rule against historical transaction data first shows you what the alert volume and false positive rate will look like, allowing you to calibrate thresholds before compliance analysts are exposed to a flood of new alerts.
Frequently Asked Questions
What is the BNM policy document on electronic money effective January 31, 2025?
Bank Negara Malaysia's policy document on electronic money, effective January 31, 2025, is a revised regulatory framework that strengthens AML/CFT obligations for all e-money issuers in Malaysia. It introduces explicit requirements for customer due diligence, sanctions and PEP screening, real-time transaction monitoring, risk-based controls calibrated to wallet type and customer risk, and board-level governance accountability. It replaces earlier e-money guidelines and applies to all open-loop e-money providers operating in Malaysia.
What is the difference between a Standard EMI and an Eligible EMI under BNM's framework?
BNM's 2025 policy introduces a tiered approach distinguishing Standard EMIs from Eligible EMIs. Eligible EMIs are large e-money issuers that exceed defined user or transaction volume thresholds. They face heightened regulatory expectations including higher capital requirements and more intensive oversight compared to Standard EMIs. Both tiers must comply with the full scope of AML/CFT requirements, but the scale and scrutiny of obligations increases for Eligible EMIs given their systemic significance in Malaysia's digital payments ecosystem.
What AML record retention period does BNM require for e-money issuers in Malaysia?
BNM requires e-money issuers to retain CDD records, transaction records, and documentation of compliance decisions for a minimum period aligned with its AML/CFT policy requirements. These records must be stored in a format that allows them to be retrieved and produced promptly during regulatory inspections or legal proceedings. Compliance teams should ensure their case management and monitoring systems log every CDD check, alert, investigation step, and outcome with time-stamped records that satisfy BNM's auditability expectations.
How do fintechs manage AML compliance operations without large engineering teams?
Fintechs without large engineering resources can meet BNM's AML/CFT requirements by deploying no-code compliance platforms that allow compliance officers to configure monitoring rules, adjust risk thresholds, and manage case workflows independently. Platforms like Flagright provide out-of-the-box rules aligned with Malaysian regulatory requirements, AI-driven false positive suppression that reduces manual review burden, and automated case management that eliminates the need for manual spreadsheet-based tracking. This allows small and mid-sized fintech compliance teams to operate effectively at scale without depending on engineering resources for routine compliance adjustments.
Which line of business is exempted from BNM's AML/CFT requirements for e-money?
Limited-purpose e-money is exempted from BNM's main e-money AML/CFT guidelines. This includes closed-loop gift cards, merchant loyalty points, and prepaid value that can only be used at a single merchant or within a single platform. The exemption reflects the lower financial crime risk profile of these products. All open-loop e-money products, including mainstream digital wallets accepted across multiple merchants or capable of peer-to-peer transfers, are subject to the full scope of BNM's AML/CFT requirements.
What are the KYC and ongoing compliance requirements for e-wallets in Malaysia?
Malaysian e-wallets must complete identity verification and sanctions screening before onboarding any new customer. Ongoing compliance requires continuous transaction monitoring aligned with each customer's risk profile, periodic re-screening of existing customers against the BNM Domestic List and UNSC sanctions list, enhanced due diligence for higher-risk customers, and prompt filing of suspicious transaction reports when money laundering indicators are detected. All compliance actions must be documented with comprehensive audit trails.
How do platforms monitor and report suspicious transactions under BNM's requirements?
Compliant platforms monitor suspicious transactions by applying real-time rules-based and AI-driven detection engines that evaluate each transaction against the customer's behavioral profile, known risk indicators, and predefined typology scenarios. When a transaction triggers an alert, it enters an investigation workflow where compliance officers assess the evidence, document their findings, and determine whether a suspicious transaction report should be filed with BNM's Financial Intelligence Unit. The entire process, from initial alert to final disposition, must be logged with a complete audit trail.
What are the AML software requirements for e-wallet companies in Malaysia?
E-wallet companies in Malaysia need AML software that provides real-time transaction monitoring, integrated sanctions and PEP screening against Malaysian and UN watchlists, AI-driven false positive suppression, dynamic risk scoring, AML case management with full audit logging, no-code rule configuration for regulatory agility, and data residency compliance with Malaysian data protection requirements. The software must be capable of generating audit-ready reports that satisfy BNM inspection requirements without manual data reconstruction.
Practical Tips for Malaysian E-Money Compliance Teams
Automate your screening process end to end. The Touch 'n Go enforcement case demonstrates that a single manual screening failure during onboarding is sufficient to trigger a regulatory action. Automated screening that checks 100% of new and existing customers against the BNM Domestic List and UNSC list consistently is the only reliable safeguard at scale.
Implement real-time monitoring before batch monitoring. BNM explicitly requires real-time monitoring. If your current system reviews transactions in batches at the end of the day or week, you are already out of alignment with the 2025 policy expectations. Upgrading to a real-time engine should be a priority action.
Build your audit trail into your operational workflow, not retrospectively. Every CDD check, watchlist screening, alert, and investigation decision should be logged automatically by your compliance system as part of normal operations. Reconstructing audit trails manually for regulatory inspections is both resource-intensive and unreliable.
Establish a board-level AML reporting cycle. BNM expects boards to actively oversee AML compliance, not just delegate it to the compliance function. Establish a regular reporting cycle that brings key compliance metrics, significant cases, and regulatory developments to board attention. Document this oversight in board minutes.
Test your rule set against current transaction data quarterly. Monitoring rules that were well-calibrated six months ago may generate excessive false positives or miss new financial crime typologies today. Regular backtesting of your rule set against current transaction data ensures your controls remain effective as customer behavior and criminal methods evolve.
Designate a qualified compliance officer before you need one. BNM's personal liability provisions mean that the compliance officer role carries real regulatory exposure. Ensure the individual in this role has appropriate qualifications, sufficient authority, and adequate resources to fulfill their responsibilities effectively. Regulatory inspections assess the compliance function directly.
Conclusion: Proactive AML Compliance Is Now a Licensing Requirement for Malaysian E-Wallet Providers
BNM's 2025 e-money policy document makes one thing unambiguous: AML/CFT compliance is no longer a back-office function for Malaysia's digital payment providers and payment processors. It is a core licensing requirement, a board-level accountability, and an operational priority that must be embedded in product design and daily operations from the start.
The Touch 'n Go enforcement action demonstrates that BNM is actively monitoring compliance, willing to impose significant penalties for first-time or inadvertent failures, and prepared to make those actions public. For an industry where customer trust is a foundational asset, the reputational consequences of a publicized compliance failure can outlast the financial penalty many times over.
The good news is that the compliance infrastructure required to meet BNM's 2025 standards is available and deployable within practical timelines. Platforms like Flagright provide Malaysian e-money issuers with real-time transaction monitoring, AI-driven sanctions and PEP screening, integrated case management with full audit logging, and no-code rule configuration that allows compliance teams to respond to regulatory changes without engineering dependency. This is not a theoretical capability. It is an operational reality for fintechs that have already deployed it.
E-money executives in Malaysia face a clear choice. Invest in the compliance infrastructure that BNM requires now, build the audit trails and governance structures that protect your license, and position compliance as a strategic advantage in a market where regulatory trust is a competitive differentiator. Or absorb the compounding cost of reactive compliance: fines, enforcement actions, license risk, and the reputational damage that follows.
The cost of a compliant program is predictable and manageable. The cost of non-compliance is not.
Book a demo with Flagright to see how its AML platform can be tailored for e-money providers in Malaysia and help your team stay ahead of BNM's requirements.





