1. CamFinTech
  2. /
  3. Learn
  4. /
  5. What Are Cambodia's AML Requirements for FinTech?
Learn

What Are Cambodia's AML Requirements for FinTech?

Cambodia's anti-money laundering and counter-terrorist financing (AML/CFT) framework imposes comprehensive compliance obligations on all FinTech operators licensed by the National Bank of Cambodia. Governed by the 2020 Law on Anti-Money Laundering and Combating the Financing of Terrorism and enforced by the Cambodia Financial Intelligence Unit (CAFIU), the regime requires customer due diligence, transaction monitoring, suspicious activity reporting, and ongoing risk assessment. The obligations are statutory and carry criminal penalties, and they are assessed at licensing and in ongoing supervision -- so an AML programme is built at the start of a FinTech's life in Cambodia, not retrofitted to it.

Updated March 2026·6 min read

Money laundering is punishable by imprisonment of two to five years and a fine of KHR 100 million to KHR 400 million, or up to the value of the property laundered. A legal entity faces a fine of KHR 200 million to KHR 1 billion.

— Law on Anti-Money Laundering and Combating the Financing of Terrorism, penalty provisions, 2020

A reporting entity that suspects funds are the proceeds of an offence, or related to terrorist financing, must report to CAFIU promptly and within 24 hours. Cash transactions above USD 10,000, including connected transactions reaching that total, are separately reportable.

— Law on Anti-Money Laundering and Combating the Financing of Terrorism, Article 12, 2020

Cambodia's AML/CFT Legal Framework

Cambodia's AML/CFT regime is anchored by the 2020 Law on Anti-Money Laundering and Combating the Financing of Terrorism, which replaced and strengthened the original 2007 law. The 2020 revision aligned Cambodia's framework with all 40 FATF Recommendations, expanding the scope of covered entities, strengthening penalties, and establishing clearer obligations for digital financial services. The law designates "reporting entities" that must comply with AML/CFT requirements, including all banks, MFIs, payment service providers, e-money issuers, securities firms, casinos, real estate agents, and dealers in precious metals. For FinTech firms, this means that any entity licensed by the NBC is automatically a reporting entity subject to the full AML/CFT compliance framework. The NBC issues supplementary Prakas (regulations) that translate the law's requirements into specific operational mandates for financial technology operators.

Customer Due Diligence Requirements

Customer due diligence (CDD) is the cornerstone of Cambodia's AML framework. All FinTech firms must verify customer identity before establishing a business relationship, opening an account, or processing transactions above prescribed thresholds. Standard CDD requires collecting the customer's full name, date of birth, national ID or passport number, residential address, and source of funds declaration. For individual customers, identity verification must be conducted against a government-issued document. For legal entities, CDD extends to identifying beneficial owners holding 20% or more ownership interest. Enhanced due diligence (EDD) is required for politically exposed persons (PEPs), high-risk jurisdictions, complex transaction patterns, and business relationships involving correspondent banking. FinTech firms must retain CDD records for at least five years after the relationship ends.
CDD and EDD Requirements by Customer Type
Customer TypeStandard CDDEnhanced Due Diligence TriggerDocumentation RequiredReview Frequency
Individual (Low Risk)ID + Address + Source of FundsNot requiredNational ID or PassportEvery 3 years
Individual (High Risk)Full CDD + Enhanced ChecksPEP, high-risk country, unusual activityID + Proof of Address + Source of WealthAnnual
SME / Legal EntityCDD + Beneficial OwnershipComplex structures, foreign ownershipRegistration + Ownership + DirectorsEvery 2 years
Large CorporateFull CDD + UBO IdentificationLayered structures, high-risk sectorsFull corporate chain + UBO declarationsAnnual
Correspondent FIFull CDD + EDD mandatoryAlways requiredLicense + AML policies + management infoAnnual

CamDigiKey Integration for KYC

CamDigiKey, Cambodia's national digital identity platform, has become the most efficient pathway for FinTech firms to meet CDD requirements. The system provides government-verified identity data through secure API integration, enabling electronic Know Your Customer (e-KYC) processes that replace manual document collection and verification. When a customer authenticates via CamDigiKey during onboarding, the FinTech firm receives verified identity attributes including full legal name, date of birth, national ID number, and photograph -- all authenticated by the government's identity database. This removes the need for physical document inspection and materially reduces identity-fraud risk at onboarding. For FinTech firms, CamDigiKey integration also demonstrates regulatory commitment to the NBC, which actively encourages digital identity adoption as part of Cambodia's Government-as-a-Platform strategy.

Transaction Monitoring and Suspicious Activity Reporting

All NBC-licensed FinTech firms must implement automated transaction monitoring systems capable of detecting potentially suspicious activity in real-time. The monitoring system must flag transactions that exceed prescribed thresholds (currently $10,000 or equivalent for currency transaction reports), identify patterns consistent with money laundering typologies, and detect structuring or smurfing behavior. When suspicious activity is identified, the firm must report its suspicions to CAFIU promptly and within 24 hours, under Article 12 of the AML/CFT Law. The report may be transmitted by any expeditious written means; a report made by telephone must be confirmed in writing. FinTech firms must also implement a compliance escalation framework where frontline staff can flag concerns to the designated compliance officer, who evaluates and submits STRs. Importantly, tipping off -- informing the customer that an STR has been filed -- is a criminal offense under Cambodian law.

The Mutual Evaluation Cycle and What It Assesses

Cambodia's AML/CFT framework is assessed by the Asia/Pacific Group on Money Laundering (APG), the FATF-style regional body for the Asia-Pacific. Cambodia's mutual evaluation report was adopted in July 2017. The country has since been in enhanced follow-up, submitting progress reports and receiving technical-compliance re-ratings where sufficient progress has been demonstrated -- the second such follow-up report was published in August 2019. Under the APG's published fifth-round schedule, Cambodia's next mutual evaluation falls in the 2029 plenary year, with technical-compliance submissions due ahead of it. A mutual evaluation assesses two distinct things, and the distinction matters for how a FinTech should prepare. Technical compliance asks whether the legal and institutional framework meets the 40 FATF Recommendations. Effectiveness asks whether the framework produces results in practice, measured against eleven Immediate Outcomes. A jurisdiction can rate well on the first and less well on the second, and the second is where a supervised institution's own programme quality is visible: the standard of its customer due diligence, the usefulness of the suspicious transaction reports it files, and whether its risk assessment reflects the business it actually writes. For a FinTech, the practical implication is that an AML programme is assessed on what it produces, not on whether the policy document exists. That is the same test the NBC applies at licensing and in ongoing supervision, and it is the reason a programme built to be demonstrated -- with documented decisions, escalation records, and a risk assessment that is revisited -- is worth more than one built to be filed.
Key FATF Recommendations Applicable to FinTech
FATF Rec.TopicCambodia ImplementationFinTech Impact
R.10Customer Due DiligenceNBC Prakas on CDD, CamDigiKey integrationMandatory e-KYC for all customers
R.15New TechnologiesRegulatory sandbox, FinTech-specific guidanceRisk assessments for digital products
R.16Wire TransfersBakong originator/beneficiary data requirementsTransaction data completeness mandates
R.20Suspicious Transaction ReportingCAFIU STR filing requirements3-day STR filing deadline
R.35SanctionsUNSC sanctions list screeningReal-time screening of all transactions

Penalties for Non-Compliance

Cambodia's AML/CFT penalties are severe and have been strengthened under the 2020 law. Criminal penalties for money laundering offenses include imprisonment of 5-10 years and fines up to $2.5 million for individuals, with higher penalties for organized criminal involvement. Legal entities can face fines of up to five times the laundered amount, forced dissolution, and asset confiscation. For FinTech firms, regulatory penalties short of criminal prosecution can be equally devastating. The NBC can impose administrative fines, require immediate remediation of compliance deficiencies, restrict business activities, suspend processing capabilities, or revoke licenses entirely. CAFIU can impose sanctions for failure to file STRs, late filing, or inadequate record keeping. In practice, the most common enforcement actions against FinTech firms involve inadequate transaction monitoring systems and incomplete CDD documentation -- operational deficiencies rather than intentional violations, but penalized nonetheless.

Building an AML Compliance Program

An effective AML compliance program for a Cambodian FinTech firm requires five core components. First, a documented AML/CFT policy approved by the board of directors and reviewed annually. Second, a designated compliance officer with sufficient authority, resources, and direct board reporting. Third, automated CDD and transaction monitoring systems integrated with CamDigiKey and Bakong data feeds. Fourth, regular staff training covering money laundering typologies, reporting obligations, and sanctions screening. Fifth, independent audit of the AML program at least annually. The compliance program must be risk-based, meaning the intensity of monitoring and due diligence scales with assessed risk. Higher-risk products (cross-border transfers, anonymous prepaid instruments), higher-risk customers (PEPs, cash-intensive businesses), and higher-risk jurisdictions require proportionally more intensive controls. An AML compliance architecture has to meet NBC and CAFIU requirements without becoming operationally unworkable.

Failure to file a required cash or suspicious transaction report carries imprisonment of one month to one year and a fine of KHR 50 million to KHR 200 million; a legal entity faces KHR 200 million to KHR 500 million.

— Law on Anti-Money Laundering and Combating the Financing of Terrorism, penalty provisions, 2020

Cambodia's mutual evaluation report was adopted by the Asia/Pacific Group on Money Laundering in July 2017, and the country has since been in enhanced follow-up with technical-compliance re-ratings. Its fifth-round mutual evaluation is scheduled for the 2029 plenary year.

— APG, 2nd Enhanced Follow-Up Report and Global Fifth Round Mutual Evaluation Schedule, 2019

Frequently Asked Questions

Related Reading

  • What is the National Bank of Cambodia?Glossary
  • What is CamDigiKey?Glossary
  • What is the General Department of Taxation (Cambodia)?Glossary

How CamFinTech Can Help

Core Rail Integrations

  • CamDX / eKYC Enablement
  • Bakong / KHQR Integration
  • CamInvoice Readiness
  • CamInvoice SP-Enablement

Strategic Services

  • Licensing-Readiness
  • Market-Entry Consulting

Risk & Security

  • AML-Programme Design
  • Security / Pentesting
  • Data-Protection Protocols
  • DASP Approval-Readiness· flagship

Enablement

  • Professional Training & Knowledge Transfer

Fee-only. We build the client-side integration ourselves, or bring in an accredited Service Provider as a disclosed sub-contract. We never hold client funds and never operate a rail.

Book a Consultation
← All Learn articles