2026-07-14

Added · Updated

AML/CFT Instructions for Licensed Banks

The Central Bank of Jordan issues these instructions to regulate anti-money laundering and counter-terrorist financing compliance for licensed banks, their branches, and subsidiaries. The document mandates a risk-based approach requiring annual risk assessments, customer classification, and enhanced due diligence for high-risk entities, including politically exposed persons and shell banks. It establishes specific obligations for verifying beneficial ownership, reporting suspicious transactions, and managing wire transfers, with a threshold of 10,000 Jordanian Dinars triggering due diligence for occasional customers.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

10/ 4/ / /1439 AH / /2018 AD Instructions for Combating Money Laundering and Financing of Terrorism for Licensed Banks Number ( / ) Issued in accordance with the provisions of Paragraph (b) of Article (99) of the Banking Law No. (28) of 2000 and its amendments, and the provisions of Article (14/A/4) and Article (18/B) of the Anti-Money Laundering and Financing of Terrorism Law No. (46) of 2007 in force.

Article (1): Definitions: First: The words and phrases contained in these Instructions shall have the meanings assigned to them in the Anti-Money Laundering and Financing of Terrorism Law and the Banking Law in force, wherever mentioned in these Instructions, unless the context indicates otherwise.

Second: The following words and phrases shall have the meanings assigned to them below wherever they appear in these Instructions, unless the context indicates otherwise:

The Law: The Anti-Money Laundering and Financing of Terrorism Law in force.

Banking Relationship: The relationship arising between the Bank and the Client concerning the activities, products, and services provided by the Bank to its clients.

Occasional Customer: The Client who does not have a bank account with the Bank and is not bound to the Bank by a banking relationship.

Beneficiary of Transfer: The natural or legal person or legal arrangement designated by the originator of the transfer as the recipient of the required financial transfer.

Non-Profit Organization: Any legal person, legal arrangement, or institution established in accordance with relevant laws to collect or spend funds for charitable, religious, cultural, educational, social, or other similar purposes, without its activity aiming to generate profit, distribute it, or achieve personal benefit, including foreign branches of international non-profit organizations and bodies.

Control: The direct or indirect ability to exercise effective influence on the actions and decisions of another person.

Beneficial Owner: The natural person with the actual interest, for whose benefit or on whose behalf the business relationship is conducted, or who has full or effective control over a legal person or legal arrangement, or the right to carry out a legal transaction on behalf of either.

Foreign Politically Exposed Persons: Persons who hold or have held a senior public office in a foreign country, such as: head of state or government, judicial or military officials, or a high-level government position, or a prominent politician or prominent figure in a political party, or senior executives in companies owned by a foreign state. This includes the first-degree relatives of these persons at a minimum, their business partners, or any persons acting on their behalf or holding powers of attorney issued by them.

Local Politically Exposed Persons: Persons who hold or have held a senior public office in the Kingdom, such as: head of government, minister, judicial or military officials, or a high-level government position, or a prominent politician or prominent figure in a political party, or senior executives in state-owned companies. This includes the first-degree relatives of these persons at a minimum, their business partners, or any persons acting on their behalf or holding powers of attorney issued by them.

Persons (foreign or local) who held a prominent position in an international organization: They are senior management members, i.e., directors, deputy directors, board members, or positions equivalent to them in an international organization. This includes the first-degree relatives of these persons at a minimum, their business partners, or any persons acting on their behalf or holding powers of attorney issued by them. This definition does not apply to individuals holding middle or lower positions in the aforementioned categories.

Shell Bank: The Bank that is characterized by any of the following:

  • It has no physical presence in the country where it was established and obtained its license. Physical presence means having a real head office and actual management within a country; merely having a local agent or low-level employees does not constitute physical presence.
  • It does not keep records of its transactions.
  • It is not subject to supervision by a competent regulatory authority, whether in the country where it was established or in any other country. The definition of Shell Bank does not apply to a Bank without a fixed headquarters if it is a subsidiary of a licensed Bank with physical presence and subject to effective supervision.

Shell Company: The Company used as a vehicle through which transactions are passed without holding any assets or conducting operations specific to its activity, even if registered.

Non-resident: The natural or legal person who usually resides or has their headquarters outside the Kingdom, or who has not completed a period of one year of residence within the Kingdom, regardless of the nationality of this person, except for families and individuals who have an economic status or interest and have permanent economic activity and permanent residence within the Kingdom, even if they reside there intermittently.

The Unit: The Anti-Money Laundering and Financing of Terrorism Unit formed in accordance with the provisions of the Law.

Money Laundering Reporting Officer (MLRO): A senior management official (who may be the Compliance Manager) appointed for the purpose of reporting transactions suspected of being related to money laundering or financing of terrorism.

Senior Executive Management: Includes the Bank's General Manager or Regional Director, Deputy General Manager or Deputy Regional Director, Assistant General Manager or Assistant Regional Director, Chief Financial Officer, Operations Manager, Risk Management Director, Internal Audit Director, Treasury (Investment) Director, Compliance Director, and any Bank employee with executive authority equivalent to any of the aforementioned and functionally reporting directly to the General Manager.

Wire Transfer: Any transfer process carried out by a Bank using electronic money transfer means on behalf of the originator of the transfer, such that the funds are sent to another Bank or any other financial company where the beneficiary can receive them, regardless of whether the originator of the transfer is the same person as the beneficiary.

Batch Transfer: A transfer consisting of a number of individual financial transfers sent to the same financial institution, but may or may not be ultimately directed to different persons.

Financial Group: A group consisting of a parent company or any other legal person who holds controlling shares and coordinates functions with the rest of the group members to apply or implement group-wide supervision in accordance with the Basel Committee on Banking Supervision's Principles for Effective Banking Supervision, along with branches and/or subsidiaries subject to group-wide Anti-Money Laundering and Financing of Terrorism policies and procedures.

Financial Institution: The legal person that exercises one or more of the financial activities specified in the Banking Law under its founding document. For the purposes of these Instructions, this includes insurance companies.

Subsidiary Company: The Company in which a person or group of persons united by a common interest owns at least (50%) of its capital, or in which this person or these persons have an influential interest allowing control over its management or general policy.

Straight Through Processing: Payment processes carried out electronically without the need for manual intervention.

Legal Arrangements: The relationship arising under a contract between two or more parties that does not result in the creation of a legal personality, such as direct trusts or similar legal arrangements.

Express Trusts: Legal relationships arising – inter vivos or upon death – by a person or trustee, where assets have been placed under the control of the person or trustee for the benefit of a beneficiary or for a specific purpose, such that the assets are independent funds and not part of the trustee's property, and the right to the trustee's assets remains in the name of the settlor or in the name of another person on behalf of the settlor.

Article (2): Scope of Application: The provisions of these Instructions shall apply to each of the following: First: Banks operating in the Kingdom.

Second: Branches of Jordanian Banks operating and their subsidiaries operating abroad, to the extent permitted by the laws and regulations in force in the countries where they operate, with the application of the strictest standards possible in case of differences in Anti-Money Laundering and Financing of Terrorism requirements in the host country compared to the home country. The Bank must notify the Central Bank of any obstacles or restrictions that may limit or prevent the application of the provisions of these Instructions.

Third: Subsidiaries of Jordanian Banks operating in the Kingdom, unless these companies are subject to the supervision of another regulatory authority in the Kingdom, and that authority has issued specific instructions for combating money laundering and financing of terrorism.

Article (3): Risk-Based Approach: First: Risk Management: Within the framework of the Risk-Based Approach, the scope and intensity of the risk management function must be commensurate with the nature, size, and complexity of the Bank's operations and activities, and its level of money laundering and financing of terrorism risks. The function of money laundering and financing of terrorism risk management in the Bank must be aligned and integrated with the overall risk management framework within it.

Second: Risk Assessment: The Bank must conduct a comprehensive assessment of money laundering and financing of terrorism risks at least annually, or whenever there is a need to conduct this assessment due to a fundamental change in the nature of risks faced by the Bank. Through this assessment, money laundering and financing of terrorism risks regarding clients, countries, geographic regions, products, services, operations, and service delivery channels are identified, assessed, and understood, according to a methodology approved by its Board of Directors or the Regional Management of the foreign Bank. The assessment must include the Bank's branches and its subsidiaries abroad, and the assessment processes must be documented. The assessment must include at least the following:

  • Results of monitoring activities conducted by the Bank, such as the Bank's level of exposure to money laundering and financing of terrorism risks, details of risks by main activities and client categories, trends in suspicious transaction reports and cash transaction reports, and trends in requests received by the Bank from law enforcement agencies.
  • Details of major risk events that occurred internally or externally and their impact on the Bank.
  • Any recent changes in instructions or circulars regulating the combating of money laundering and financing of terrorism and their impact on the Bank. The Bank must provide the Central Bank before the end of April of each year with the following:
  • The approved methodology for assessment and any modifications made to it.
  • The results of the assessment submitted to senior management and the Board of Directors.
  • A report from the Bank's internal auditor or the committee emanating from its Board of Directors, clarifying the recommendations and measures intended to be taken to mitigate high risks identified as a result of the assessment.

Third: Risk Control and Mitigations: The Bank must have the following:

  • Policies, controls, and procedures for managing and reducing identified money laundering and financing of terrorism risks, approved by senior management in the Bank according to their respective jurisdictions.
  • Monitoring the application of these policies, controls, and procedures and strengthening them if necessary.
  • Taking enhanced due diligence measures to manage and reduce risks identified as "high risk."
  • Verification of the application of these policies, controls, and procedures on the ground by internal audit as an independent body.

Fourth: Customers Classification: The Bank must classify its customers according to the nature of their money laundering and financing of terrorism risks, updating this classification periodically in accordance with the nature and level of those risks for each customer, taking into account the following factors:

  • Resident or non-resident.
  • Type of customer (natural person, legal person, non-profit organization, etc.).
  • Occasional customer.
  • Ownership structure of the legal person.
  • Types of politically exposed persons.
  • Types of professions.
  • Geographic location.
  • The country of origin to which the customer belongs.
  • Products, services, operations, or service delivery channels (e.g., cash transactions, direct or indirect dealing, cross-border transactions).
  • Any other information indicating the customer's risk level. The risk mitigation measures applied by the Bank must be commensurate with the nature of the customer's risk.

Fifth: Higher Risk: Cases where the Bank's assessment of money laundering/financing of terrorism risks is high, taking into account the following factors (at a minimum): Factors related to customer risks:

  • Conducting business under unusual circumstances (e.g., unjustified large geographical distance between the Bank and the customer).
  • Non-resident customers.
  • Cases where the legal person or legal arrangements are special purpose entities.
  • Businesses relying heavily on cash.
  • Unjustified complexity in ownership structure compared to the nature of the company's business.
  • Private banking customers (High Net Worth Customers).
  • Customers belonging to areas known for high crime rates (e.g., countries known for drug production, transport, or smuggling).
  • Customers belonging to or present in countries that do not apply Financial Action Task Force (FATF) recommendations or do not apply them sufficiently.
  • Businesses classified by the Financial Action Task Force (FATF) as "high risk" in money laundering and financing of terrorism.
  • Customers who meet the risk indicators specified by the Bank.

Factors related to country and geographic region risks:

  • Countries lacking sufficient systems for combating money laundering and financing of terrorism or not applying FATF recommendations sufficiently.
  • Countries subject to sanctions, embargoes, or other measures issued by the United Nations.
  • Countries suffering from high levels of corruption or other criminal activities.
  • Geographic regions considered to be financing terrorism or supporting terrorist activities.
  • Countries where terrorist organizations are present.
  • Countries suffering from political or security conditions that hinder their compliance with FATF recommendations. When determining factors related to risks for countries and geographic regions, the Bank may refer to credible sources such as mutual evaluation reports, follow-up reports, and any other relevant reports published by international organizations such as the United Nations and the Financial Action Task Force (FATF).

Factors related to product, service, operation, or distribution channel risks:

  • Transactions carried out by anonymous persons (which may involve the use of cash).
  • Business relationships or transactions not conducted face-to-face.
  • Amounts received by the customer from multiple persons or from countries that do not correspond to the nature of their business and risk profile.
  • Amounts received by the customer from unknown sources or from a third party with no clear relationship to the customer.

High-Risk Countries: Countries listed by the Financial Action Task Force (FATF) as high-risk countries regarding money laundering and financing of terrorism, or those with deficiencies in anti-money laundering and financing of terrorism procedures that pose a threat to the global financial system, or for which the Kingdom has information indicating they are high-risk countries in money laundering and financing of terrorism.

Sixth: The Bank must identify and assess money laundering and financing of terrorism risks that may arise regarding the development of products within new business lines, including new means of service delivery, and those that may arise from the use of new technologies within new or developing business lines regarding both new and existing products, and take appropriate measures to manage and reduce those risks, and inform the Central Bank of Jordan of the results.

Seventh: Taking into account all relevant risk factors before determining the overall risk level and the appropriate level of risk mitigation measures to be applied.

Eighth: Providing appropriate mechanisms to supply identified risks to competent authorities upon request.

Article (4): Due Diligence Requirements: First: General Rules: The customer due diligence to be taken by the Bank refers to the following:

  • Obtaining information about the identity of customers (permanent or occasional, whether natural or legal persons or legal arrangements) and their legal status, and verifying it using original documents, data, or information from a reliable and independent source.
  • Comparing the customer's name with the names of persons and entities listed on the sanctions lists issued under United Nations Security Council resolutions.
  • Establishing the customer's activity and understanding the purpose and nature of the business relationship with the Bank and obtaining information regarding that.
  • In case a person acts on behalf of the customer, it must be verified that they are authorized to do so, and their identity must be identified and verified.
  • Identifying the beneficial owner and taking reasonable measures to verify their identity using an identification document issued by a government authority, such that the Bank is satisfied that it is aware of the beneficial owner's identity.
  • Verifying the sources of funds and supporting documents for transactions conducted within the banking relationship.
  • Exercising ongoing due diligence regarding business relationships and scrutinizing transactions carried out throughout the duration of the relationship to ensure consistency of these transactions with what the Bank knows about its customer, their activity pattern, and their risk profile, including the source of funds when necessary, and comparing them with peers in the same activity or those within the same risk degree, and recording and retaining all data related thereto in accordance with the provisions of these Instructions.
  • Ensuring that documents, data, or information obtained under due diligence procedures are continuously updated and appropriate by reviewing existing records, especially for high-risk customer categories.
  • Obtaining any other information related to customer risk assessment indicators. The Bank must apply all due diligence measures regarding customers stipulated in Paragraph (1) of Item (First) above in this Article, defining the scope of those measures using the Risk-Based Approach referred to in Article (3) of these Instructions. The Bank must take customer due diligence measures in the following cases:
  • Before or during the banking relationship.
  • When there is doubt about the accuracy or sufficiency of data and information previously obtained regarding customer identification.
  • When conducting transactions for occasional customers where the value of a single transaction or multiple seemingly linked transactions exceeds (10,000) Jordanian Dinars or its equivalent in foreign currencies.
  • If the Bank suspects that the transaction is suspected of being related to money laundering or financing of terrorism, regardless of its value or the applicability of simplified due diligence procedures.
  • Any electronic transfers carried out by an occasional customer, regardless of their value. In case the Bank is unable to fulfill customer due diligence procedures, it must not open an account or enter into any banking relationship with the customer or execute any transaction on their behalf, and must immediately notify the Unit in case of suspicion of connection to money laundering or terrorism financing according to the form or means approved by the Unit for this purpose.

Timing of verifying the identity of the customer and beneficial owner: 1.5 The Bank must verify the identity of the customer and beneficial owner before or during the banking relationship or when executing transactions for occasional customers from reliable and neutral sources. 2.5 The Bank may postpone some customer and beneficial owner identity verification procedures until after establishing a continuous business relationship, provided they are completed within a period not exceeding (10) working days from the date of establishing the relationship; otherwise, the relationship shall be terminated and the Unit immediately notified in case of suspicion of connection to money laundering or terrorism financing according to the form or means approved by the Unit for this purpose, without allowing the customer to withdraw cash upon termination of the relationship, but using one of the other payment methods that enable tracking (Audit trail), and the postponement must be in accordance with the following: 1.2.5 The postponement of verification procedures must be necessary to maintain the completion of ordinary business, without resulting in money laundering or financing of terrorism risks. 2.2.5 The Bank must have taken necessary measures to effectively control money laundering or financing of terrorism risks regarding the case where postponement was applied, including setting limits on the number, type, and amounts of transactions that can be executed before completing verification procedures, and including that in the Bank's approved work procedures. In case the Bank enters into a banking relationship with the customer and indicators appear of a transaction suspected of being related to money laundering or financing of terrorism, the Bank must do the following: 1.6 Complete/re-fulfill due diligence procedures regarding the suspected transactions. 2.6 In case the Bank does not reach satisfaction with the sufficiency of due diligence procedures, and that continuing to demand the customer to complete due diligence procedures may tip off the customer (Tipping off), the Bank in such cases must not continue to complete those procedures and must immediately notify the Unit according to the form or means approved by the Unit for this purpose, without allowing the customer to withdraw cash, and use one of the other payment methods regarding account tracking (Audit trail). The Bank must exercise due diligence towards existing customers based on relative importance and risk, and take necessary due diligence measures regarding its current relationships with them in the cases stated below, and the Bank must be aware whether due diligence procedures were taken previously, when they were taken, and the sufficiency of the data obtained: 1.7 When executing transactions in large amounts or using banking instruments in an unusual manner. 2.7 When a fundamental change occurs in the mechanism of documenting customer information. 3.7 When a noticeable change occurs in the method of account management. 4.7 When the Bank realizes it does not have sufficient information about one of these customers. 8- Updating Data: The Bank must take due diligence measures continuously regarding business relationships, including:

  • Scrutinizing transactions carried out throughout the duration of the relationship to ensure consistency of transactions carried out with what the Bank knows about customers, their activity pattern, and the risks they represent, including the source of funds if necessary.
  • Ensuring that documents, data, or information obtained under due diligence procedures are continuously updated and appropriate by reviewing existing records, especially for high-risk customer categories. The Bank may rely on identity identification and verification procedures previously carried out, unless it has doubts about the validity of that information or in case of suspicion of money laundering or financing of terrorism or a fundamental change in the way the customer's account is operated that does not correspond to the customer's activity. 4.8 In case the customer does not respond to the Bank's request to update their data as the Bank deems appropriate, the Bank may gradually suspend some financial operations and services provided to the non-responsive customer, until the customer updates their data properly, provided that awareness tools and campaigns are activated for customers regarding the consequences of failing to update their data and urging them to update whenever necessary.

Second: Customer Identity Identification Procedures: The Bank must put in place systems capable of identifying the customer's identity in accordance with the requirements stipulated in Item (First) of this Article. The Bank must review the original official documents for customer identification and obtain a copy of these documents signed by the competent employee indicating that it is a true copy. The following shall be observed in customer identity identification procedures for the Natural Person: 1.3 Identification data for the customer must include: full name, date and place of birth, national ID number, and full information related to the identity document for Jordanians, passport number, personal number for non-Jordanians, nationality, annual residence permit issued by the Ministry of Interior or valid work permit issued by the competent authority in case the customer is foreign labor, nature of work, permanent residence address, phone numbers, purpose and nature of the business relationship, and any other information the Bank deems necessary to complete the customer identification process. 2.3 For persons with limited legal capacity, such as minors, documents related to their legal representative in dealing with these accounts must be obtained in accordance with Paragraph (2) above. 3.3 In case a person deals with the Bank as an agent for the customer, it must be ensured that there is a valid judicial power of attorney or Bank-approved authorization, with the necessity of retaining the power of attorney or a certified copy thereof or the authorization, in addition to the necessity of identifying the agent's identity according to the customer identification procedures stipulated in Item (1.3) of this Article. The following shall be observed in customer identity identification procedures for the Legal Person or Legal Arrangement: 1.4 Identification data must include: name of the legal person or legal arrangement, legal form, names and addresses of owners, ownership shares, headquarters address, nature of work and type of activity, amount of capital, registration date and number, tax number, national number of the establishment, names of authorized signatories, purpose and nature of the business relationship, and names of persons holding senior management positions in the legal person or legal arrangement, and any other information the Bank deems necessary to obtain for completing identification and keeping it updated first-hand. 2.4 Obtaining documents indicating authorization from the legal person or legal arrangement for natural persons authorized to deal with the account, in addition to the necessity of identifying the identity of the authorized person dealing according to the identification procedures for natural persons stipulated in Item (1.3) of this Article and verifying the absence of legal obstacles preventing dealing with them and obtaining samples of their signatures. 3.4 Obtaining information about the provisions regulating the work of the legal person or legal arrangement, including ownership structure and controlling management, and provisions regulating the authority to make binding decisions for the legal person or legal arrangement. Public joint stock companies are exempted from the request for data related to owners' names, addresses, and ownership shares for shareholders whose participation percentage is less than (10%) of the company's capital, with obtaining a commitment from the authorized signatories to provide the Bank with data of any shareholders whose participation falls within this percentage. 4.4 The following shall be observed in identifying the identity of Legal Arrangements:

  • The Bank must be aware of the nature of the customer, ownership structure, and board of trustees.
  • The necessity of identifying authorized signatories and controlling persons according to the customer identification procedures stipulated in Item (1.3) of this Article. The following shall be observed in customer identity identification procedures for the Non-Profit Organization: 1.5 Identification data must include: name of the non-profit organization, legal form, national number of the organization (if available), headquarters address, type of activity, date of establishment, names of persons authorized to deal with the account and their nationalities, phone numbers, purpose of dealing, sources of income or funding, names of persons holding senior management positions in the non-profit organization, and any other information the Bank deems necessary to obtain. 2.5 Obtaining documents indicating authorization from the non-profit organization for natural persons authorized to deal with the account, in addition to the necessity of identifying the identity of the authorized person dealing according to the customer identification procedures stipulated in Item (1.3) of this Article. An attached form represents the minimum customer identification data to be fulfilled.

Third: Customer Identification Data Verification Procedures: The Bank must take necessary measures to verify the accuracy of data and information obtained from the customer through neutral and reliable sources, including communication with competent authorities issuing official documents confirming this data, as follows: Verification of the identity of the Natural Person: This is done by referring to the Civil Status, Passports and Residence Department website for Jordanians, and obtaining photocopies of passports...