2026-06-30 | BM 1231Added · Updated
Financial Institutions in Oman are authorized to digitally onboard legal persons using the National e-KYB Platform (Mala'a) as the primary data source, while explicitly excluding non-profit associations and foreign registered entities from this digital process. Financial Institutions must verify Ultimate Beneficial Owners holding 25% or more of share capital or voting rights through iterative registry lookups and implement Near Field Communication authentication or external smartcard readers for security. The instructions mandate the collection of specific documentation, including commercial registration and board resolutions, and require periodic manual checks and risk assessments to ensure compliance with Anti-Money Laundering regulations.
Get CBO alerts — same-day email on every new publication.
Instructions on Digital Onboarding and
Electronic Know Your Business (e-KYB) for Legal Persons
Contents
Purpose ....................................................................................................................... 3
Regulatory Framework and Scope........................................................................... 3
2.1 Applicability ............................................................................................................... 3
2.2 Non-Permissible Customer Segments ...................................................................... 3
2.3 National e-KYB Platform (Mala'a)............................................................................. 3
2.4 Customer Due Diligence Measures .......................................................................... 4
2.5 Risk Based Approach ................................................................................................ 4
2.6 Ultimate Responsibility............................................................................................... 4
Digital Onboarding Procedures for Legal Persons................................................... 5
3.1 Documentation .......................................................................................................... 5
3.2 Identifying Ultimate Beneficial Owners .................................................................... 6
3.3 Customer Identification and Verification................................................................. 7
3.4 Authorized Signatory.................................................................................................. 8
Risk Assessment and Customer Due Diligence ....................................................... 8
Security and Compliance Requirements ................................................................. 9
Digital Onboarding Limitations and Statutory Restrictions .................................... 10
Digital Signature and Consent ................................................................................ 11
KYB Compliance and Ongoing Monitoring for Legal Persons.............................. 11
8.1 Periodic e-KYB Reviews ........................................................................................... 11
8.2 Transaction Monitoring ............................................................................................ 11
8.3 Updating Legal Person Information ........................................................................ 12
8.4 Other Requirements ................................................................................................. 12
Reliance on Third Parties for Customer Due Diligence.......................................... 13
Implementation and Reporting............................................................................... 13
Purpose
1.1 Central Bank of Oman (CBO), in furtherance of its digital transformation
strategy and in alignment with the instructions issued on June 06, 2023 regarding Digital Onboarding and e-KYC through Circular BM 1191, hereby issues this Circular to provide specific guidelines for the digital onboarding of legal persons. These guidelines aim to enhance efficiency, financial inclusion and customer experience, while ensuring robust compliance with Anti-Money Laundering (AML), Combating Financing of Terrorism (CFT) and Counter Proliferation Financing (CPF) regulations.
Regulatory Framework and Scope
2.1 Applicability
2.1.1 These instructions apply to all Financial Institutions (Banks, Finance and
Leasing Companies, Money Exchange Establishments and Payment Service Providers) undertaking the onboarding of legal persons registered in the Sultanate of Oman (hereinafter also referred as “customers’) (such as General/Limited Partnership, Limited Liability Company, Joint Stock Company, Holding Company, One Person Company and other types of legal persons.) through digital platforms or channels. These instructions allow all Financial Institutions (FIs) to digitally onboard new customers and to update the Know Your Business (KYB) of existing customers through electronic means.
2.2 Non-Permissible Customer Segments
2.2.1 These instructions explicitly exclude the digital onboarding of Non-Profit
Associations and Entities due to their elevated vulnerabilities to Money Laundering, Terrorist Financing, and Proliferation Financing (ML/TF/PF) under FATF’s guidance and shall continue to follow existing physical or specific procedural guidelines for the onboarding process.
2.3 National e-KYB Platform (Mala'a)
2.3.1 Oman Credit and Financial Information Centre (Mala’a) will continue to
act as the National Digital Onboarding Registry (hereinafter also referred to as the ‘Registry’) and Financial Institutions shall use Registry (Mala’a), as the primary national data source for electronic identification and verification of legal persons, and for accessing relevant KYB data during the digital onboarding and KYB update process, where such data or verification services are available through Mala’a or through Government and official sources connected to Mala’a. The Registry will act only as a facilitator in providing information sourced from different authenticated channels.
2.3.2 Financial Institutions shall remain responsible for collecting and verifying
any information or documents not available through the Registry, in accordance with the applicable laws, regulations, and their risk-based approach.
2.4 Customer Due Diligence Measures
2.4.1 In line with CBO’s guidelines (BM 1187/FM 38/ME 37) and
recommendations by FATF, Financial institutions shall undertake customer due diligence (CDD) measures at the time of establishing business relations through:
2.4.1.1 Identifying the customer and verifying that customer’s identity
using reliable, independent source documents, data or information. Where the customer is a legal person, FI shall verify the legal form, proof of existence, constitution and powers that regulate and bind the customer, using reliable, independent source data, documents or information.
2.4.1.2 Identifying the beneficial owner, and taking reasonable
measures to verify the identity of the beneficial owner, such that the financial institution is satisfied that it knows who the beneficial owner is. For legal persons, this should include financial institutions understanding the ownership and control structure of the customer.
2.4.1.3 Understanding and, as appropriate, obtaining information on
the purpose and intended nature of the business relationship.
2.4.1.4 Conducting ongoing due diligence on the business
relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions being conducted are consistent with the institution’s knowledge of the customer, their business and risk profile, including where necessary, sources of funds.
2.4.1.5 FIs shall be required to apply each of the CDD measures
mentioned above, but should determine the extent of such measures on a risk proportionate basis.
2.5 Risk Based Approach
2.5.1 Financial Institutions shall adopt a risk-based approach to ensure that
access to banking services and products are provided using reliable and legally acceptable digital means, maintaining the same level of security and compliance as traditional face-to-face onboarding.
2.6 Ultimate Responsibility
2.6.1 The ultimate responsibility for maintaining the efficacy of AML/CFT/CPF
controls remains with the Financial Institution. This obligation is constant, irrespective of whether customer onboarding is facilitated in person or via digital channels.
3.1.1.12 Signatures of all officers of the legal person with signing
authority on the account.
3.1.1.13 Primary Contact Information (email, phone number etc.).
These documents will be submitted through the financial institution’s platform.
3.2 Identifying Ultimate Beneficial Owners
3.2.1 In line with FATF Recommendation on Transparency and beneficial
ownership of legal persons, CBO issued specific Beneficial Ownership Guidelines via Circular no. AML/CFT/2022/310 to promote a clear understanding among financial institutions regarding the identification and verification of ultimate beneficial owners. The Ultimate Beneficial Owner (UBO) is the individual/ natural person who ultimately owns or controls a legal person, either directly or indirectly, through ownership of 25% or more of the entity’s share capital, voting rights, or control. In line with CBO’s guidelines, if beneficial owner (s) is identified as a PEP, the ownership must be disclosed regardless of the threshold.
3.2.2 Financial Institutions shall identify and verify the UBOs of each legal
person during the onboarding process. This includes:
3.2.2.1 Obtaining and verifying personal information about the UBO(s),
including full name, nationality, date and place of birth, and valid identification numbers.
3.2.2.2 Identifying and verifying the ownership structure and control
mechanisms of the entity to determine UBOs.
3.2.3 Considering the current limitation where the Registry only provides single
level ownership visibility, FIs must enforce repetitive lookup logic to identify and verify multi layered legal persons structures (except complex beneficial ownership). If an onboarding entity’s data reveals a legal person shareholder holding 25% or more, FIs must execute a followup search within the Registry using that parent company’s registration details. This look through search process must be performed iteratively for each subsequent legal person layer identified at 25% or more until the UBO or persons exercising ultimate control over the legal person are fully identified and verified in accordance with the regulatory criteria.
3.2.4 Legal persons shall submit a UBO Declaration/ undertaking, which
includes information on all individuals who directly or indirectly own 25% or more of the entity’s share capital or voting rights.
3.3 Customer Identification and Verification
3.3.1 In line with Articles 7 and 9 of CBO’s guidelines (BM 1187/FM 38/ME 37),
the financial institution is responsible for ensuring the accuracy and validity of all information submitted by the legal person:
Information to be verified with data fetched from the Registry
3.3.1.1 Full Legal Name of the entity.
3.3.1.2 Legal Structure (Joint stock company, partnership, LLC, etc.).
3.3.1.3 Commercial Registration details.
3.3.1.4 Oman Chamber of Commerce and Industry Membership
Certificate.
3.3.1.5 Authenticating the provided business address.
3.3.1.6 Confirming UBO details.
3.3.1.7 Verification of authorized signatories and Ultimate Beneficial
Owners as per instructions contained in BM 1191 including Facial Verification once implemented by the Registry.
3.3.1.8 FIs shall verify the authenticity of digital documents provided
by customers and ensure they align with official Registry records. Information to be collected, but not verified with the Registry
3.3.1.9 Confirming the powers to regulate and bind the legal person
through validating foundational documents such as memorandum or articles of Association, or equivalent documents that outline the entity’s legal structure and governance arrangements.
3.3.1.10 FIs, in addition to carrying out CDD on legal persons, shall
understand and as appropriate, obtain information on the purpose and nature of the business relationship, source of funds and/ or source of wealth and its control structure.
3.3.1.11 Board Resolution (or Owner's authorization) along with request
signed by authorized signatories, explicitly detailing names and powers to open and operate the account.
3.3.1.12 Business phone number/contact details and email address, as
applicable.
3.3.1.13 Ensuring that all key individuals are not on any sanctions’ lists
(Local and Foreign).
3.3.2 FIs shall ensure compliance with Articles 17 and 18 of CBO guidelines (BM
1187/FM 38/ME 37).
3.4 Authorized Signatory
3.4.1 During digital onboarding, the signatories (single and joint) need to be
verified as per e-KYC guidelines. They must have financial authority and single and joint signatories should get One Time Password (OTP) at the mobile number registered under their Civil/Resident Identity card with Royal Oman Police (ROP). FIs will also notify the Board or owner in line with their internal procedures accordingly. Financial Institutions shall ensure that the designated signatory has the required authority to open, operate, and digitally authorize the account relationship.
3.4.2 In case, board resolution (or owner's authorization) appoints
non-shareholder or person not mentioned in CR as an authorized signatory, the eKYB process is deemed insufficient to mitigate the risk of financial crime. Therefore, FIs need to ensure physical face-to-face interaction at a branch, and manually verify the resolution’s validity and the signatory's identity.
4. Risk Assessment and Customer Due Diligence
4.1 FIs shall conduct an AML/CFT risk assessment, by their control function
(Compliance/Risk Management etc.) prior to the launch of the e-KYB technology solution. The risk assessment shall be approved by the Head of Compliance.
4.2 A comprehensive customer risk profile must be established based on the
business's nature, location, ownership structure, and intended use of the financial products/services.
4.3 FIs shall be ensured to risk classify the customers in accordance with
Article 2 of Circular guidelines (BM 1187/FM 38/ME 37).
4.4 FIs shall conduct due diligence on business relationships and review
existing records on an ongoing basis to ensure that documents, data or information collected under due diligence are kept up-to-date and relevant. For high-risk customers, such review shall be conducted more frequently as compared to other customers.
5.10 To ensure the robustness of digital onboarding, FIs shall perform periodic
manual checks on a random sample of accounts opened via e-KYB to identify and remediate any process gaps.
5.11 FIs shall ensure that electronic records must be maintained in
accordance with Article 44 of Royal Decree 30/2016 so that all data can be retrieved accurately, efficiently, and in a timely manner.
5.12 In line with Article 39 of the AML/CFT Law, where the FI is unable to
comply with the required identification and verification measures, it shall refrain from opening the account or commencing a business relationship or carrying out the transaction.
6. Digital Onboarding Limitations and Statutory Restrictions
6.1 FIs shall not rely solely on digital verification if mandatory information is
missing or inconsistent with the Registry records. In such instances, FIs are required to perform additional due diligence, such as inspecting original physical documentation, to ensure the authenticity of the information provided.
6.2 In the event that digital onboarding efforts are unsuccessful on multiple
occasions due to technical complications, FIs are required to finalize the customer due diligence process via an in-person arrangement.
6.3 FIs are prohibited from establishing business relationships or conducting
transactions if they cannot fulfill the outlined obligations or the requirements specified in the AML/CFT Law and related supervisory instructions.
6.4 Foreign Registered Legal Persons (Non-resident Legal Persons) and
Foreign Professional Investors that are not residents in the Sultanate of Oman, will continue the account opening process and CDD refresher through physical submission of documents as these entities present heightened ML/TF/PF risks associated with cross-border structures.
6.5 Government entities require Ministry of Finance (MOF) approval before
the onboarding process. Accordingly, supplementary regulatory requirements for the digital onboarding of such entities will be issued in due course, subject to the Registry's ongoing data assessment and the associated risk profile.
6.6 Any legal person without CR or ownership details will not be allowed for
e-KYB.
6.7 Joint Stock Companies (SAOG and SAOC) will continue under the
manual onboarding and KYB process until the ongoing system integration between the Registry and relevant authorities, allows for digital onboarding and electronic KYB process.
8.3 Updating Legal Person Information
8.3.1 Legal persons must notify the financial institution of any significant
changes, such as modifications to their ownership, control, management, authorized signatories, main/ licensed business activity or operational structure. Updated information will be verified by FIs in line with section 3.
8.3.2 Where a Financial Institution identifies during onboarding, periodic
review or trigger event that there has been a change in the ownership structure, controlling interests or ultimate beneficial ownership of the legal person, FIs shall undertake appropriate due diligence measures to verify the legitimacy of such change and to accurately identify and verify the new ultimate beneficial owner(s).
8.3.3 In such cases, the FI shall not rely solely on updated CR records, registry
information or electronically submitted documents, but shall obtain such additional information, documentation, confirmations, or evidence as may be necessary, commensurate with the nature and risk profile of the customer, in order to satisfy itself regarding the validity of the ownership change and the identity of the new ultimate beneficial owner(s).
8.3.4 The FI shall also ensure that its records are updated without undue delay
and that all applicable customer due diligence and beneficial ownership requirements are complied with prior to permitting the continued operation of the account under the revised ownership structure.
8.4 Other Requirements
8.4.1 Financial institutions have ongoing duties such as verifying customers
including UBO information from reliable sources, assessing customer risk and applying appropriate levels of due diligence, maintaining accurate customers records, and continuously monitoring and updating ownership data. They are also required to follow guidelines for monitoring transactions and reporting suspicious activity.
Read the rest free
Source: Central Bank of Oman — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works