Bahrain CBB AML Requirements: What Financial Institutions Need to Know

Bahrain's position as a regional financial centre makes its anti-money laundering and counter-terrorist financing framework critical for any organisation.

AML Guide  ·  August 2026

Bahrain’s position as a regional financial centre makes its anti-money laundering and counter-terrorist financing framework critical for any organisation operating in or through the kingdom.

The Legislative Foundation

Bahrain’s AML/CFT regime rests on Law No. 54 of 2018, which replaced earlier legislation and brought the kingdom’s framework closer to the FATF Recommendations. The law establishes the fundamental obligations for financial institutions and designated non-financial businesses and professions (DNFBPs) operating in Bahrain.

The Bahrain Financial Intelligence Unit (BFiu) operates as the central body for receiving, analysing, and disseminating financial intelligence. Financial institutions are required to file suspicious transaction reports (STRs) with the BFiu when they have reasonable grounds to suspect that a transaction involves proceeds of crime or is related to terrorist financing.

The CBB has issued detailed module requirements within its Rulebook that specify how financial institutions must implement their AML/CFT programmes. These include the AML/CFT Module (Module AML) that sets out obligations across the customer lifecycle.

Supervisory Framework

The CBB supervises financial institutions through a risk-based approach, with supervisory intensity calibrated to the risk profile of each licensee. The CBB’s licensing framework categorises financial institutions into different types, each subject to specific requirements.

Licensing categories under the CBB framework include:

Retail banks

Wholesale banks

Investment banks

Insurance companies and agencies

Money exchange houses

Money transfer operators

Securities and investment firms

Finance companies

Each category carries specific capital adequacy, governance, and AML Compliancerequirements. The CBB conducts both off-site surveillance and on-site examinations to assess compliance. The frequency and depth of supervision typically correlate with the institution’s risk rating.

Customer Due Diligence Requirements

The CBB requires financial institutions to implement a risk-based approach to customer due diligence (CDD). This includes:

Standard CDD: For all customers, institutions must identify the customer, verify identity using reliable documents, understand the nature and purpose of the business relationship, and conduct ongoing monitoring.

Enhanced Due Diligence (EDD): Required for higher-risk customers, including politically exposed persons (PEPs), customers from high-risk jurisdictions, and complex ownership structures where beneficial ownership cannot be readily determined.

Simplified Due Diligence: Permitted only in low-risk circumstances, with ongoing monitoring still required.

The CBB’s requirements align broadly with FATF Recommendations on CDD, including the need to identify and verify beneficial owners. For legal entities, this means identifying individuals who ultimately own or control 25 percent or more of the entity, or who exercise significant control over the entity.

Politically Exposed Persons

PEPs represent a distinct risk category under the CBB framework. Financial institutions must have policies and procedures to identify PEPs, both when they are customers and when they are beneficial owners. For Bahrain-resident PEPs, foreign PEPs, and international organisation PEPs, the CBB requires:

Senior management approval before establishing or continuing a business relationship

Enhanced CDD measures throughout the relationship

Ongoing monitoring to detect any changes in beneficial ownership or control

Robust source of wealth and source of funds investigation

DNFBP Obligations

DNFBPs in Bahrain are subject to AML/CFT obligations under the applicable legislation and supervisory frameworks. DNFBP categories typically include:

Real estate agents and developers

Dealers in precious metals and stones

Lawyers and legal practitioners (in certain circumstances)

Accountants and auditors

Trust and company service providers

DNFBPs must apply CDD measures for transactions above specific thresholds and maintain records. The FATF’s 2018 mutual evaluation of Bahrain noted that DNFBPs had a fragmented understanding of money laundering and terrorist financing risks, with the majority not implementing targeted financial sanctions without delay. This remains an area requiring ongoing attention.

Record Keeping and Reporting

Financial institutions must maintain records of all CDD information, including copies of identification documents, for at least five years following the end of the business relationship or the completion of the transaction. These records must be readily available to the CBB and, where applicable, the BFiu.

STR filing obligations require institutions to report suspected money laundering or terrorist financing promptly. The tipping-off prohibition applies: institutions must not disclose to the customer or third parties that an STR has been or may be filed.

The FATF Assessment and Action Plan

Bahrain underwent a FATF-MENAFATF mutual evaluation in 2018, which resulted in an action plan with specific items to be addressed. The FATF subsequently conducted follow-up assessments, with the most recent published in May 2022.

The 2022 follow-up report acknowledged progress in addressing technical compliance deficiencies. However, FATF assessment criteria continue to evolve, and Bahrain’s next on-site evaluation is scheduled for November 2026, with a potential plenary discussion in June 2027.

For compliance leaders, this upcoming evaluation cycle is significant. It suggests heightened supervisory attention and the potential for regulatory change as Bahrain seeks to demonstrate further progress.

Key Compliance Considerations

Organisations operating in Bahrain should consider the following:

Risk assessment: Conduct and maintain an enterprise-wide money laundering and terrorist financing risk assessment that considers the specific threats and vulnerabilities of the Bahrain market.

Policies and procedures: Ensure AML/CFT policies and procedures are current, approved by senior management, and aligned with CBB requirements.

Training: Implement ongoing training programmes appropriate to the roles and responsibilities of staff, with records maintained.

Screening: Screen customers and beneficial owners against relevant lists, including sanctions lists, PEP databases, and other high-risk indicators.

Monitoring: Implement transaction monitoring systems that generate alerts for investigation, with a clear escalation framework.

How Bahrain Fits Within the GCC Compliance Landscape

Bahrain’s AML/CFT framework operates within a broader GCC context where regulatory expectations are converging, largely driven by FATF membership requirements and the desire to attract international financial flows. However, each jurisdiction maintains its own supervisory structure and specific requirements.

The CBB’s approach reflects Bahrain’s positioning as a international financial centre with a regulatory philosophy that balances supervisory rigour with market development objectives. For organisations with multi-jurisdiction footprints, Bahrain operations require dedicated attention to local requirements rather than assumptions of uniformity.

What This Means for Compliance Leaders

The CBB’s AML/CFT framework demands sustained investment in people, processes, and technology. Compliance functions must maintain the capability to identify and respond to financial crime risk, report suspicious activity, and demonstrate to supervisors that the programme is effective.

For those planning operations in Bahrain, early engagement with the regulatory framework is advisable. The licensing process, subsequent ongoing obligations, and the forthcoming FATF evaluation create an environment where compliance credibility matters significantly.

Nexiant supports financial institutions operating in Bahrain and across the GCC with AI-assisted screening, transaction monitoring, and risk management solutions. Contact our team to discuss your compliance requirements.

Bahrain CBB AML Requirements: A Complete Compliance Guide

Understand Bahrain’s AML/CFT obligations under the Central Bank of Bahrain, including Law No. 54 of 2018, CDD requirements, DNFBP obligations, and FATF action plan status.

Speak to our team

This article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.