CamFinTech
Phnom Penh · Established 2024 · Fee-only
The Royal Government built the rails. Bakong settles at national scale, CamDX carries data between ministries and licensed institutions, and CamInvoice is bringing invoicing into a single system. The standard for connecting to any of them is set by the National Bank of Cambodia, the NBFSA and SERC, the Techo Startup Center and the General Department of Taxation.
Meeting that standard is mostly not an engineering exercise. The requirements are prudential — AML and CFT programme design, governance, capital planning, documentation — assessed by more than one authority and often alongside a sponsoring member bank. Most financial technology firms are engineering organisations and hold no risk or compliance function, so the work falls to people trained for something else.
This practice supplies that function, and hands it over. Our people have worked inside the regulators, and we would rather leave the competence inside a client's team than remain necessary to it. Compliance capability held in Cambodia is worth more to this market than compliance capability flown in.

The firm works across the approvals, the compliance programmes and the client-side integrations that connect a regulated institution or a rail-using enterprise to Cambodia's digital public infrastructure.
SRV-01
Approval to connect to the national data-exchange and digital-identity systems, and the client-side integration that follows.
SRV-02
Payment Service Institution licensing or member-bank sponsorship, and connectivity to the national payment rails.
SRV-03
Gap assessment and a costed plan against the General Department of Taxation's requirements, ahead of the phased business-to-business mandate.
SRV-04
Connection of a client's ERP to the e-invoicing rail, delivered with an accredited Service Provider where platform depth is the better fit.
SRV-05
Identification of the applicable National Bank, NBFSA or SERC licence, gap mapping against its requirements, and preparation of the application.
SRV-06
For foreign institutions establishing in Cambodia — entity formation, licensing strategy, and the sequence of approvals that reaches the rails.
SRV-07
Customer due diligence and enhanced due diligence, transaction monitoring, CAFIU reporting and MLRO support — built to be demonstrated in supervision, not filed.
SRV-08
Cyber-risk advisory and pre-launch review against the National Bank's Technology and Cyber Risk Management Guidelines. Penetration testing is routed to an accredited security firm.
SRV-09
Consent, retention, processor governance and data-protection-officer support, ahead of the Kingdom's Personal Data Protection Law.
SRV-11
Readiness for the SERC regime under Prakas 093, in force since 30 December 2025 — AML and CFT build, governance roster, and sandbox-to-full application preparation. Full specification
SRV-10
Cohort training in digital public infrastructure, cybersecurity and regulatory compliance, so that a client's own team operates the integration and the programme after handover.
Where an accredited Service Provider is the better fit for a build — BanhJi, Innolab and Odoo, MAQSU, SAP and Crimson, KOSIGN, Metfone, GK-Smart — the firm engages them as a disclosed sub-contract and remains accountable for the programme. Their work is never marked up, and the firm does not compete for their clients. Pricing is indicative until validated by quote.
Set out in full, including its boundaries. Several things a client needs belong to a licensed professional, to the operator, or to the regulator, and the firm would rather name them than blur them.
The firm may build a client's integration and prepare its approval on the same engagement, and a reader is entitled to ask about that. The client is always the applicant of record: the licence, the filing and the operator role are the client's. The firm does not influence a regulator's decision and does not claim to; its work is meeting the published bar. Where both scopes are delivered, that is disclosed in the engagement letter and priced separately, so either can be taken elsewhere without penalty.
The firm maintains a public reference on Cambodian financial-technology regulation and the national rails. It is open, it is dated, and it is the most direct way to assess how the practice works before speaking to anyone.
Laws, sub-decrees and Prakas governing Cambodian financial technology. Each entry records the source that was read and the date it was read, and states what the instrument does not cover.
Extended technical and regulatory references on the rails and the approvals that reach them.
Shorter reference pieces on how each rail works and what it requires.
Analysis of the Cambodian market and its digital-infrastructure programme.
Illustrative scoping documents showing how an engagement is structured and where the boundaries fall. Not client engagements.
Definitions of the institutions, rails and instruments referred to throughout.
The firm also publishes The Riel Report, an independent record of Cambodian financial-technology developments.
“…significant progress in its Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) framework, with strengthened laws and better inter-agency coordination. However, it also highlights a critical gap between legislative development and operational implementation across various sectors. Key deficiencies include inconsistent beneficial ownership verification, limited data integration, and uneven quality in suspicious transaction reporting.”
That is the Royal Government's own assessment of where the work lies, and it describes this practice's subject exactly: the distance between a framework that exists and a programme that operates.
NRA II also sets capacity building among its recommended actions — specialised training and a wider understanding of AML and CFT obligations across sectors. That is the part of this practice we care most about, and the reason every engagement is written to end in a handover.