Oman’s AML/CFT Regulatory Framework Under the Central Bank of Oman

Oman has developed its AML/CFT framework under the legislative foundation of Sultan's Decree No.

AML Guide  ·  August 2026  ·  GCC

Oman has developed its AML/CFT framework under the legislative foundation of Sultan’s Decree No.

The Legislative Foundation

Sultan’s Decree No. 79 of 2002 on Anti-Money Laundering and Combating the Financing of Terrorism, as subsequently amended, provides the foundational legislation for Oman’s AML/CFT regime. This decree establishes the criminalisation of money laundering and terrorist financing, creates the architecture for financial intelligence and sets out the penalties applicable to financial crime violations.

The legal framework has been developed further through additional legislation and regulatory measures addressing specific aspects of AML/CFT compliance. FATF Recommendations inform the development of Oman’s framework, but the Recommendations themselves are not directly applicable as domestic law. They provide the international standard against which national measures are measured.

Oman participates in MENAFATF, the FATF-style regional body for the Middle East and North Africa, through which it engages in mutual evaluation and peer review processes.

Central Bank of Oman AML/CFT Regulations

The Central Bank of Oman issues detailed AML/CFT regulations applicable to all financial institutions under its supervisory scope. These regulations translate legislative obligations into practical compliance requirements covering customer due diligence, record-keeping, suspicious transaction reporting, internal controls and training.

The CBO regulatory framework adopts a risk-based approach, consistent with FATF Recommendations, requiring financial institutions to identify, assess and mitigate the money laundering and terrorist financing risks associated with their business activities. The risk-based approach allows institutions flexibility in implementing controls proportionate to their specific risk profiles.

Financial institutions must maintain comprehensive AML/CFT programmes supported by documented policies and procedures, appropriate systems and controls, ongoing employee training and independent audit functions. The CBO expects these elements to function as an integrated whole.

Customer Due Diligence Requirements

CBO regulations establish comprehensive CDD requirements that financial institutions must apply at account opening and on an ongoing basis throughout business relationships. The framework distinguishes between standard CDD for most customers and enhanced due diligence for higher-risk situations.

Standard CDD requires collection and verification of full customer identification, including name, date of birth, nationality, residential address and for legal entities, evidence of incorporation, ownership structure and identification of beneficial owners. Beneficial owners are typically defined as individuals who ultimately own or control a prescribed ownership interest or who exercise significant influence over the entity.

Enhanced due diligence applies to relationships involving politically exposed persons, complex ownership structures, non-resident customers and any other situation assessed as presenting elevated risk. For PEP relationships, CBO regulations require senior management approval, documented source of wealth and source of funds investigation and enhanced ongoing monitoring.

The ongoing CDD obligation requires periodic reviews of customer relationships, updates to customer information when circumstances change and continuous transaction monitoring against established risk profiles.

Beneficial Ownership

The identification and verification of beneficial owners is a key element of the CBO CDD framework. Financial institutions must identify the natural persons who ultimately own or control legal entities with which they do business, going beyond the legal ownership structure to understand the true controlling parties.

For complex corporate structures, this requires tracing through ownership chains to identify the natural persons at the ultimate beneficial ownership level. Where ownership is exercised through multiple layers of entities, financial institutions must document the ownership chain and identify the individuals who exercise effective control.

CBO regulations require verification of beneficial ownership information to the same standard as customer identification. This creates practical challenges for institutions dealing with complex structures, and the CBO expects firms to develop methodologies capable of addressing these challenges effectively.

PEP Screening

Financial institutions must screen customers and beneficial owners against PEP databases at account opening and on an ongoing basis throughout the relationship. The PEP screening obligation extends to identifying whether customers or beneficial owners hold prominent public functions in Oman or abroad.

PEP relationships require senior management approval before establishment, robust source of wealth and source of funds investigation and enhanced ongoing monitoring. The CBO expects these requirements to be documented and subject to periodic review.

Screening for PEP status is not a one-time event. Institutions must rescreen existing customers periodically and screen at each interaction point to identify any change in PEP status that may alter the risk profile of the relationship.

Oman Financial Intelligence Unit

The Oman Financial Intelligence Unit serves as Oman’s financial intelligence unit, receiving suspicious transaction reports from reporting entities and analysing financial intelligence to support law enforcement investigations. CBO regulations require financial institutions to file STRs with the OFIU when they know, suspect or have reasonable grounds to suspect that a transaction involves proceeds of crime or is linked to terrorist financing.

The reporting obligation applies regardless of transaction amount. Financial institutions must establish clear procedures for identifying potentially suspicious activity, escalating concerns through appropriate governance channels and filing timely reports with the OFIU.

The OFIU plays a central role in Oman’s AML/CFT framework, analysing and disseminating intelligence to law enforcement and supervisory authorities. Effective reporting by financial institutions supports the overall effectiveness of the national framework.

DNFBP Obligations

Designated Non-Financial Businesses and Professions in Oman are subject to AML/CFT obligations under the applicable legal framework. Relevant DNFBP categories include real estate agents, dealers in precious metals and stones, lawyers, accountants and trust and company service providers.

DNFBPs must implement customer identification procedures appropriate to their activities, maintain records of transactions and report suspicious activities to the OFIU. The scope of obligations varies depending on the specific DNFBP category and the nature of activities conducted.

For financial institutions, DNFBP status is a relevant factor in relationship risk assessment, both for DNFBP customers and for correspondent banking and counterparty relationships involving DNFBPs.

2022 FATF Mutual Evaluation

Oman underwent FATF mutual evaluation, with the on-site visit conducted in 2022 and the mutual evaluation report subsequently adopted by the FATF. The MER assessed both technical compliance with FATF Recommendations and the effectiveness of Oman’s AML/CFT framework in practice.

The mutual evaluation identified several areas where Oman’s framework requires improvement. Some FATF Recommendations were rated below the compliant level, indicating deficiencies in technical compliance or effectiveness that Oman has committed to address through an action plan with the FATF.

The FATF action plan for Oman outlines the improvements required and the timeline for addressing identified deficiencies. Regulatory developments in Oman are likely to be influenced by FATF follow-up processes, and financial institutions should monitor for changes to CBO regulations and other requirements.

For compliance teams, the MER provides insight into supervisory expectations and areas where the framework may evolve. Institutions may wish to assess their own programmes against the FATF standards referenced in the MER, even where CBO-specific requirements remain unchanged.

Sanctions Implementation

Oman implements United Nations Security Council targeted financial sanctions through its domestic legal framework. Financial institutions must screen customers and counterparties against UN sanctions lists and any additional lists specified by the CBO.

Implementation of targeted financial sanctions requires integration with operational systems, including transaction monitoring and payment processing. Financial institutions must be capable of identifying potential sanctions violations, blocking prohibited transactions and reporting blocked transactions to the relevant authorities.

The intersection of AML/CFT obligations and sanctions compliance creates operational complexity that requires coordinated systems and governance frameworks.

CBO Supervisory Approach

The CBO employs a risk-based supervisory approach, allocating supervisory resources according to the risk profile of supervised entities. Supervisory tools include off-site monitoring through regulatory returns and data submissions, on-site examinations and thematic reviews of specific compliance areas.

The CBO has indicated continued focus on financial crime compliance as a supervisory priority. Enforcement actions have included financial penalties, remediation requirements and restrictions on activities.

Practical Implications for Compliance Teams

Financial institutions operating in Oman must implement AML/CFT programmes that satisfy CBO requirements while addressing the implications of the FATF mutual evaluation findings and action plan. The dual obligation to comply with existing requirements and anticipate regulatory developments creates a dynamic compliance environment.

Building an effective compliance programme requires investment in screening systems, transaction monitoring capabilities and reporting processes configured to address CBO-specific requirements. Training programmes must ensure that staff understand both their obligations and the practical implementation of controls.

For enterprise risk leaders, the FATF MER provides useful context for understanding supervisory priorities and the direction of regulatory development. Proactive engagement with regulatory changes and continuous programme improvement are essential for maintaining effective compliance.

Oman AML Regulations: CBO Framework and FATF Evaluation

A practical guide to Oman’s AML/CFT framework under the CBO. Understand Sultan’s Decree No. 79/2002, OFIU reporting, DNFBP obligations and FATF MER 2022 findings.

Speak to our team

This article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.