Kuwait’s AML/CFT Regulatory Framework Under the Central Bank of Kuwait

Kuwait's AML/CFT framework is anchored by Law No.

AML Guide  ·  August 2026  ·  GCC

Kuwait’s AML/CFT framework is anchored by Law No.

The Legislative Foundation

Law No. 35 of 2002 on Anti-Money Laundering, as amended, provides the primary legislative foundation for Kuwait’s AML/CFT regime. This law establishes the criminalisation of money laundering and terrorist financing, creates the framework for financial intelligence gathering and sets out the penalties applicable to financial crime violations.

The law has been amended over time to reflect evolving international standards and Kuwait’s obligations as a member of the MENAFATF regional body. FATF Recommendations inform the development of Kuwait’s framework, but the FATF Recommendations themselves are not directly applicable as domestic law. They provide the international benchmark against which national measures are assessed.

Complementing the primary AML law, Kuwait has enacted additional legislation addressing specific aspects of financial crime, including legislation implementing United Nations Security Council targeted financial sanctions. The intersection of AML/CFT obligations and sanctions compliance is a key consideration for financial institutions operating in Kuwait.

Central Bank of Kuwait AML Instructions

The Central Bank of Kuwait issues detailed AML/CFT instructions applicable to all financial institutions under its supervisory scope. These instructions translate legislative obligations into practical compliance requirements, covering customer due diligence, record-keeping, suspicious transaction reporting, internal controls, training and audit functions.

The CBK instructions adopt a risk-based approach, requiring financial institutions to assess the money laundering and terrorist financing risks associated with their customers, products, channels and geographies and to implement controls proportionate to those risks. The risk-based approach is consistent with FATF Recommendations and allows institutions flexibility in implementing controls appropriate to their specific risk profiles.

Financial institutions must implement comprehensive AML/CFT programmes that are documented in policies and procedures, supported by appropriate systems and controls, subject to ongoing training and subject to independent audit. The CBK expects these elements to function as an integrated programme rather than isolated compliance activities.

Customer Due Diligence Requirements

CBK instructions establish a comprehensive CDD framework requiring financial institutions to identify and verify customers at account opening and on an ongoing basis throughout the business relationship. The framework requires standard CDD for most customers and enhanced due diligence for higher-risk situations.

Standard CDD requires collection and verification of full identification information, including name, date of birth, nationality, address and for legal entities, evidence of incorporation, ownership structure and identification of beneficial owners. Beneficial owners are defined as individuals who ultimately own or control a prescribed ownership interest or who exercise significant control over the entity.

Enhanced due diligence applies to relationships involving politically exposed persons, complex ownership structures, non-resident customers and any other situation assessed as presenting elevated money laundering or terrorist financing risk. For PEP relationships, CBK instructions require senior management approval, documented source of wealth and source of funds analysis and enhanced ongoing monitoring.

The ongoing CDD obligation requires periodic reviews of customer relationships, updates to customer information when circumstances change and continuous transaction monitoring against established risk profiles.

Kuwait Financial Intelligence Unit

The Kuwait Financial Intelligence Unit serves as Kuwait’s financial intelligence unit, receiving suspicious transaction reports from reporting entities and analysing financial intelligence to support law enforcement investigations. CBK instructions require financial institutions to file STRs with the KFIU when they know, suspect or have reasonable grounds to suspect that a transaction involves proceeds of crime or is linked to terrorist financing.

The reporting obligation applies regardless of transaction amount. Financial institutions must establish clear procedures for identifying potentially suspicious activity, escalating concerns through appropriate governance channels and filing timely reports with the KFIU.

The KFIU analyses reported information and disseminates intelligence to relevant authorities, including law enforcement agencies and supervisory bodies. Compliance with reporting obligations supports the effectiveness of Kuwait’s overall financial crime framework.

Terrorist Financing Provisions

Combating the financing of terrorism is a significant priority within Kuwait’s AML/CFT framework. CBK instructions include specific provisions addressing terrorist financing risks, including enhanced scrutiny of transactions involving jurisdictions of concern, non-profit organisations and any activity linked to designated entities.

Financial institutions must screen customers and counterparties against relevant lists, including UN Security Council sanctions lists as implemented in Kuwait and any additional lists specified by the CBK. Screening must occur at account opening, on an ongoing basis and in real-time for transaction processing.

Any potential match must be investigated, escalated appropriately and reported to the KFIU where required. Financial institutions must maintain documented procedures for sanctions-related decision-making.

DNFBP Obligations

Designated Non-Financial Businesses and Professions in Kuwait are subject to AML/CFT obligations under the applicable legal framework. Relevant DNFBP categories include real estate agents, dealers in precious metals and stones, lawyers, accountants and trust and company service providers.

DNFBPs must implement customer identification procedures appropriate to their activities, maintain records of transactions and report suspicious activities to the KFIU. The scope of obligations varies depending on the specific DNFBP category and the nature of activities conducted.

Financial institutions should consider DNFBP status when assessing the overall risk profile of business relationships, both as a customer risk factor and as a consideration in correspondent banking and other counterparty relationships.

UN Security Council Sanctions

Kuwait implements United Nations Security Council targeted financial sanctions through its domestic legal framework. Financial institutions must screen against UN sanctions lists and any additional lists specified by the CBK.

Implementation of targeted financial sanctions requires integration with operational systems, including transaction monitoring and payment processing systems. Financial institutions must be capable of identifying potential sanctions violations, blocking prohibited transactions and reporting blocked transactions to the relevant authorities.

The intersection of AML/CFT obligations and sanctions compliance creates operational complexity that requires coordinated systems and governance.

FATF Evaluation Context

Kuwait has undergone FATF mutual evaluation, with the resulting report providing insight into the state of Kuwait’s AML/CFT framework against international standards. The evaluation assessed both technical compliance with FATF Recommendations and the effectiveness of Kuwait’s framework in practice.

Certain FATF Recommendations were rated below the compliant level in Kuwait’s mutual evaluation, identifying areas where improvements are needed in technical compliance or effectiveness. These findings inform the direction of regulatory development in Kuwait and provide insight for financial institutions assessing their compliance programmes.

Firms operating in Kuwait should monitor regulatory developments arising from mutual evaluation findings and FATF follow-up processes.

Supervisory Approach and Enforcement

The CBK employs a risk-based supervisory approach, allocating supervisory resources according to the risk profile of supervised entities. Supervisory tools include off-site monitoring through regulatory returns, on-site examinations and thematic reviews of specific compliance areas.

Enforcement actions for AML/CFT failures have included financial penalties, requirements for remediation programmes, restrictions on activities and personal accountability measures. The CBK has indicated continued focus on financial crime compliance as a supervisory priority.

Practical Implications for Compliance Teams

Financial institutions operating in Kuwait must implement AML/CFT programmes that address CBK instructions while navigating the broader legal framework including Law No. 35 of 2002 and UN sanctions obligations.

Building an effective compliance programme requires investment in people, processes and technology. Screening systems, transaction monitoring capabilities and STR reporting processes must all be configured to address CBK-specific requirements.

For enterprise risk leaders, understanding Kuwait’s FATF evaluation findings provides context for supervisory expectations and insight into areas where the framework may evolve.

Kuwait AML Regulations: CBK Framework Requirements

A practical guide to Kuwait’s AML/CFT framework under the CBK. Understand Law No. 35 of 2002, KFIU reporting, DNFBP obligations and UN sanctions implementation.

Speak to our team

This article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.