How Saudi Arabia’s SAMA AML/CFT Framework Works for Financial Institutions

Saudi Arabia operates one of the most developed AML/CFT regulatory frameworks in the Gulf Cooperation Council, driven by its full membership in the Financial.

AML Guide  ·  August 2026  ·  GCC

Saudi Arabia operates one of the most developed AML/CFT regulatory frameworks in the Gulf Cooperation Council, driven by its full membership in the Financial Action Task Force and its Vision 2030 economic transformation programme.

The Legislative Foundation

The cornerstone of Saudi Arabia’s AML/CFT regime is the Anti-Money Laundering Law, originally enacted under Royal Decree and subsequently updated to reflect evolving international standards. This primary legislation establishes the criminalisation of money laundering and terrorist financing, creates the framework for financial intelligence gathering and sets out the penalties applicable to both legal entities and individuals.

Complementing the AML Law, SAMA issues detailed supervisory regulations and circulars that translate legislative obligations into practical compliance requirements for regulated entities. These include the SAMA AML/CFT Guidelines, which provide detailed instructions on customer due diligence, record-keeping, suspicious transaction reporting and internal controls. SAMA’s regulatory approach aligns closely with the FATF Forty Recommendations as the international standard, though FATF Recommendations are not domestic law and should be understood as context for Saudi Arabia’s implementation choices.

The Capital Market Authority (CMA) maintains parallel supervisory responsibility for capital markets participants, applying equivalent AML/CFT obligations to licensed entities including broker-dealers, investment advisers and fund managers. This dual-supervisor structure requires regulated entities to coordinate compliance programmes across both SAMA and CMA where their activities span banking and capital markets.

The Saudi Awaan Bilaksh Reporting System

The Saudi Awaan Bilaksh serves as the Kingdom’s financial intelligence unit, receiving suspicious transaction reports and suspicious activity reports from reporting entities across the financial sector. SAMA requires all regulated entities to file STRs electronically through the Saudi Awaan Bilaksh platform when they know, suspect or have reasonable grounds to suspect that a transaction involves funds linked to money laundering, terrorist financing or other criminal activity.

The threshold for reporting is intentionally broad. Regulated entities must report any transaction, regardless of amount, where the circumstances give rise to suspicion. There is no minimum reporting threshold. SAMA guidance emphasises that the obligation to report is absolute once suspicion is formed and cannot be discharged by simply declining to proceed with the transaction without reporting.

Failure to report is a serious compliance failure. SAMA has taken enforcement action against institutions for delayed reporting, incomplete reporting and failure to establish adequate suspicious activity monitoring systems. The consequences include financial penalties, regulatory sanctions and potential personal liability for compliance officers.

Customer Due Diligence Requirements

SAMA’s CDD framework requires regulated entities to identify and verify the identity of customers at the point of account opening and on an ongoing basis throughout the business relationship. The framework distinguishes between standard due diligence applied to most customers and enhanced due diligence required for higher-risk relationships.

Standard CDD requires collection of full name, date of birth, nationality, residential address, source of funds and purpose of the relationship. Legal entities must provide documentation of incorporation, articles of association, identification of beneficial owners holding twenty-five percent or greater ownership or control, and identification of authorised signatories.

Enhanced due diligence applies to relationships involving politically exposed persons, non-resident customers, complex ownership structures, correspondent banking relationships and any other relationship assessed as presenting elevated risk. For PEP relationships, SAMA requires senior management approval before establishment, robust source of wealth and source of funds investigation, ongoing enhanced monitoring and documentation of the risk acceptance decision.

Ongoing monitoring is a continuous obligation. Regulated entities must conduct periodic reviews of customer relationships, update customer information when circumstances change and monitor transactions against customer risk profiles throughout the relationship lifecycle.

PEP Screening and Sanctions Compliance

Saudi Arabia maintains robust requirements for screening customers and counterparties against sanctions lists and PEP databases. SAMA requires regulated entities to screen all new customers and beneficial owners against United Nations Security Council sanctions lists, the Saudi Arabian targeted financial sanctions lists and relevant domestic lists.

PEP screening is not a one-time event. Ongoing screening must occur at each interaction point and through periodic batch screening of the existing customer base against updated lists. Regulated entities must maintain documented processes for escalating potential matches, conducting further investigation and determining whether a match represents a true positive requiring escalation or a false positive requiring documented clearance.

SAMA has emphasised that sanctions compliance must extend to the operational systems of regulated entities. Transaction monitoring systems should incorporate sanctions list screening to prevent processing of transactions involving sanctioned entities. Any transaction that would result in a sanctions violation must be blocked and reported to the relevant authorities.

DNFBP Obligations

Designated Non-Financial Businesses and Professions are subject to AML/CFT obligations under Saudi law, though the scope and specific requirements differ from those applicable to financial institutions. DNFBPs include dealers in precious metals and stones, real estate agents, lawyers, accountants, trust and company service providers and dealers in high-value goods.

DNFBPs operating in Saudi Arabia must implement customer identification procedures, maintain records of transactions and report suspicious activities to the Saudi Awaan Bilaksh. SAMA coordinates with the Ministry of Commerce and other relevant authorities to ensure DNFBP compliance through a combination of licensing conditions and supervisory oversight.

The practical implication for financial institutions is that DNFBPs may be customers or counterparties, and their own AML/CFT compliance is a relevant risk factor. Regulated entities should consider the DNFBP status of customers when assessing the overall risk profile of business relationships.

Supervisory Approach and Enforcement

SAMA employs a risk-based supervisory approach, allocating supervisory resources according to the risk profile of regulated entities. Supervisory tools include off-site monitoring through regulatory returns and data submissions, on-site examinations and thematic reviews of specific compliance areas.

SAMA has progressively increased enforcement activity in recent years, reflecting the Kingdom’s commitment to strengthening financial crime controls. Enforcement actions have included financial penalties, requirements for remediation programmes, restrictions on business activities and individual accountability measures against compliance officers.

For enterprise compliance teams, this supervisory trajectory means that AML/CFT programmes must be treated as strategic priorities rather than administrative overhead. Regulators expect to see board-level engagement, adequate resourcing of compliance functions, robust training programmes and continuous programme improvement.

What This Means for Compliance Leaders

Financial institutions operating in Saudi Arabia must build AML/CFT programmes that satisfy SAMA requirements while operating within the broader Kingdom regulatory environment. This requires integration of AML controls into customer onboarding workflows, transaction processing systems and ongoing monitoring frameworks.

The alignment with FATF standards provides a useful reference point for programme design, but the specific Saudi requirements take precedence. Compliance teams should ensure that policies, procedures and systems are configured to address SAMA-specific obligations, not merely the international framework.

For enterprise risk leaders, the SAMA framework reflects a maturing regulatory environment where enforcement risk is real and increasing. Building compliance programmes capable of withstanding supervisory scrutiny requires sustained investment in people, processes and technology.

Saudi Arabia AML Regulations: A Guide for Financial Institutions

A comprehensive guide to Saudi Arabia’s AML/CFT framework under SAMA. Understand CDD requirements, STR reporting to Saudi Awaan Bilaksh, PEP screening and DNFBP obligations.

Speak to our team

This article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.