2025-07-03
Added · Updated
Otoritas Jasa Keuangan mandates Digital Financial Asset Traders to implement effective Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing programs based on a risk-based approach. Traders must actively monitor risks related to customers, geographic jurisdictions, products, and distribution channels, while maintaining internal controls and updating risk assessments regularly. The regulation defines key terms and outlines specific typologies for money laundering, terrorism financing, and proliferation financing to guide compliance efforts.
OJK published 6 documents in the last 30 days — get each new one by email the day it lands.
To:
The Board of Directors of Digital Financial Asset Traders,
ATTACHED
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY OF THE REPUBLIC OF INDONESIA NUMBER 16/SEOJK.07/2025
CONCERNING
THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING, COUNTER-TERRORISM FINANCING, AND COUNTER-PROLIFERATION FINANCING PROGRAMS FOR DIGITAL FINANCIAL ASSET TRADERS
In light of the implementation of Financial Services Authority Regulation Number 27 of 2024 concerning the Conduct of Digital Financial Asset Trading Including Crypto Assets (State Gazette of the Republic of Indonesia Year 2024 Number 38/OJK, Supplement to the State Gazette of the Republic of Indonesia Number 108/OJK) and to implement the provisions of Financial Services Authority Regulation Number 8 of 2023 concerning the Implementation of Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing Programs in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2023 Number 11/OJK, Supplement to the State Gazette of the Republic of Indonesia Number 36/OJK), it is necessary to further regulate the implementation provisions regarding the procedures, reporting, and mechanisms for implementing anti-money laundering, counter-terrorism financing, and counter-proliferation financing programs for Digital Financial Asset Traders in this Financial Services Authority Circular as follows:
I. GENERAL PROVISIONS
In this Financial Services Authority Circular, the following terms are defined as:
a. Digital Financial Asset is a financial asset that is stored or represented digitally, including crypto assets. b. Crypto Asset is a digital representation of value that can be stored and transferred using technology that enables the use of distributed ledgers such as blockchain to verify transactions and ensure the security and validity of stored information, is not guaranteed by a central authority such as a central bank but is issued by private parties, can be traded, stored, and transferred or assigned electronically, and can be in the form of digital coins, tokens, or other asset representations including backed crypto-assets and unbacked crypto-assets.
c. Digital Financial Asset Trader, hereinafter referred to as Trader, is a business entity that conducts trading of Digital Financial Assets, either on its own behalf and/or facilitating consumers.
d. Board of Directors is the Trader's organ authorized and fully responsible for managing the Trader for the interests of the Trader, in accordance with the purpose and objectives of the Trader, and representing the Trader, both inside and outside of court, in accordance with the provisions of the articles of association. e. Board of Commissioners is the Trader's organ tasked with conducting general and/or specific supervision in accordance with the articles of association and providing advice to the Board of Directors. f. Senior Official is an official at the level of division head or section head at the headquarters who has knowledge and/or experience regarding anti-money laundering, counter-terrorism financing, and counter-proliferation financing. g. Consumer is any person who owns and/or utilizes products and/or services provided by the Trader. h. Customer is a Consumer as referred to in letter g.
i. Beneficial Owner is an individual who is entitled to and/or receives certain benefits related to the Customer's account, is the actual owner of funds and/or Digital Financial Assets including Crypto Assets placed with the Trader (ultimately own account), controls the Customer's transactions, grants power of attorney to conduct transactions, controls corporations or other legal arrangements, and/or is the ultimate controller of transactions conducted through a legal entity or based on an agreement.
j. Travel Rule is the obligation to obtain, store, and submit sender and recipient information required regarding digital financial asset transfer or transfer services to identify and report suspicious transactions, freeze, and prohibit transactions. k. Politically Exposed Person, hereinafter abbreviated as PEP, is a person given authority to perform important functions (prominent function), which is not intended for middle-level or lower-level positions.
l. Customer Due Diligence, hereinafter abbreviated as CDD, is an activity consisting of identification, verification, and monitoring conducted by the Trader to ensure transactions are in accordance with the profile, characteristics, and/or transaction patterns of prospective Customers or Customers.
m. Enhanced Due Diligence, hereinafter abbreviated as EDD, is more in-depth CDD actions conducted by the Trader against prospective Customers or Customers with high risk, including PEPs and/or in high-risk areas. n. Money Laundering Crime, hereinafter abbreviated as TPPU, is TPPU as referred to in laws concerning the prevention and eradication of money laundering crimes. o. Terrorism Financing Crime, hereinafter abbreviated as TPPT, is TPPT as referred to in laws concerning the prevention and eradication of terrorism financing crimes. p. Proliferation Financing of Weapons of Mass Destruction, hereinafter abbreviated as PPSPM, is PPSPM as regulated in regulations concerning proliferation financing of weapons of mass destruction. q. Suspicious Financial Transaction is a suspicious financial transaction related to TPPU, TPPT, and/or PPSPM. r. List of Suspected Terrorists and Terrorist Organizations, hereinafter abbreviated as DTTOT, is a list of names of suspected terrorists and terrorist organizations as referred to in legislation concerning the prevention and eradication of TPPT. s. List of Proliferation Financing of Weapons of Mass Destruction, hereinafter abbreviated as DPPSPM, is a list of names of suspected perpetrators of PPSPM as referred to in legislation concerning the prevention and eradication of PPSPM. t. Blocking is blocking as regulated in legislation concerning the prevention and eradication of TPPU, TPPT, and/or PPSPM. u. High-Risk Customer is a Customer who, based on background, identity, history, and/or the results of risk assessments conducted by the Trader, has a high risk of engaging in activities related to TPPU, TPPT, and/or PPSPM.
v. Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing of Weapons of Mass Destruction, hereinafter abbreviated as APU, PPT, and PPPSPM, are efforts to prevent and eradicate TPPU, TPPT, and/or PPSPM.
w. Financial Action Task Force Recommendations, hereinafter referred to as FATF Recommendations, are standards for the prevention and eradication of TPPU, TPPT, and/or PPSPM issued by FATF.
x. Electronic System is a series of electronic devices and procedures that function to prepare, collect, process, analyze, store, display, announce, transmit, and/or disseminate electronic information.
Traders are highly vulnerable to the possibility of being used as a medium for TPPU, TPPT, and PPSPM. Traders may become an entry point for wealth resulting from TPPU, TPPT, and PPSPM into the financial system, which can subsequently be utilized for criminal interests. For example, for TPPU perpetrators, such wealth can be withdrawn as if it were legitimate wealth and no longer traceable to its origin. For TPPT perpetrators, such wealth can be used to finance terrorist activities. For PPSPM perpetrators, such wealth can be used to finance weapons of mass destruction proliferation activities.
The increasing complexity of financial service products and services, including their marketing (multichannel marketing), and the increasing use of information technology in the financial services industry, result in a higher risk of Traders being used as a means for TPPU, TPPT, and PPSPM.
In this regard, there is a need to improve the quality of implementing APU, PPT, and PPPSPM programs based on a risk-based approach in accordance with general principles applicable internationally, as well as in line with the national risk assessment (NRA) and sectoral risk assessment (SRA).
On principle, the TPPU process can be grouped into 3 (three) stages of activities, including:
a. placement, which is the effort to place cash money derived from criminal acts into the financial system; b. layering, which is the effort to obscure the origin of wealth derived from criminal acts (dirty money) involving the Trader; and/or
c. integration, which is the effort to combine or use wealth that appears legitimate, either to enjoy directly, invest in various types of financial products/services, or other material forms, used to finance legitimate business activities, or to re-fund criminal activities.
Some money laundering modus operandi and typologies that may occur through Traders include:
a. structuring, which is the effort to break down transactions into several transactions with relatively small transaction values intended to avoid reporting; b. smurfing, which is the effort to break down transactions with funds derived from criminal proceeds through several accounts under different individuals, whether affiliated or not, for the benefit of one person or a specific Beneficial Owner;
c. mingling, which is a technique of mixing or combining criminal proceeds with legitimate business proceeds to obscure the source of criminal funds;
d. misuse of professional services such as legal consultants, notaries, and accountants including public accountants, with the intention of obscuring the identity of the beneficiary and the source of criminal funds; e. use of other people's names (nominees), family members, and/or third parties by parties within the Customer's management structure who will represent the Customer in the process of establishing a business relationship with the Trader, intended to obscure the identity of those committing crimes by using the legitimate identity of others; f. use of false identities by parties within the Customer's management structure who will represent the Customer in the process of establishing a business relationship with the Trader, intended to obscure the identity of those committing crimes, thereby generating a new identity that appears genuine by using the legitimate identity of others. The forms of false identity use include impersonation identities (mimicking identity) and synthetic identities (combining real and false identities). Impersonation identities are done by stealing another person's identity, while synthetic identities use identity forgery by combining real and false identities to generate a new identity that appears genuine; and g. use or cooperation with companies in tax haven countries/jurisdictions that do not have real business (paper companies), as classified by competent international organizations, including countries/jurisdictions categorized as high-risk and other monitored jurisdictions by FATF.
Unlike TPPU, whose purpose is to disguise the origin of wealth, the purpose of TPPT is to assist terrorist activities, whether with wealth that is the result of a criminal act or with wealth obtained legitimately.
On principle, the TPPT process can be grouped into 3 (three) stages of activities, including:
a. collecting/raising funds, which is the activity of collecting funds conducted by terrorists, terrorist organizations, and/or other parties who are the funders of TPPT, where the funds are obtained in a lawful or unlawful manner. b. moving/storing/transferring funds, which is the activity of providing, giving, and/or lending funds from the fund owner to terrorists and/or terrorist organizations.
c. using, which is the activity of using or utilizing funds that have been collected or received by terrorists and/or terrorist organizations for terrorist criminal activities.
Some terrorism financing modus operandi and typologies that may occur through Traders include:
a. misuse of investment funds by Customers, where investment funds are provided, collected, given, and/or lent to terrorists and/or terrorist organizations, directly or indirectly, with the intention that they be used wholly or partially to commit terrorist crimes; and b. parties within the Customer's management structure who will represent the Customer and/or parties who are the Beneficial Owners of the Customer are listed in the DTTOT.
PPSPM has a critical point where crime is not limited to the process of creating a weapon of mass destruction such as nuclear, but also covers various other supporting structures, such as the provision of raw material logistics, the use of certain shipping lines to distribute logistics or even other military hardware, up to the formation of front companies to cover transactions used as an effort to support PPSPM.
II. IMPLEMENTATION OF APU, PPT, PPPSPM PROGRAMS BASED ON RISK (RISK BASED APPROACH)
Traders are required to implement APU, PPT, and PPPSPM programs effectively by considering the risks of TPPU, TPPT, and/or PPSPM, as well as the scale, complexity, and/or characteristics of the Trader's business, which include:
a. active supervision by the Board of Directors and Board of Commissioners; b. policies and procedures;
c. internal controls;
d. information management systems; and e. human resources and training.
The implementation of the APU, PPT, and PPPSPM program as referred to in number 1 is conducted by the Trader using a risk-based approach based on the results of the application of APU, PPT, and PPPSPM risks.
In conducting business relationships and transactions with Customers, Traders must implement a risk-based APU, PPT, and PPPSPM program. This program includes, among other things, what is mandated in the FATF Recommendations as an effort to protect Traders from being used as a means for TPPU, TPPT, and/or PPSPM. The FATF Recommendations state that Traders are obligated to identify, assess, and understand TPPU, TPPT, and/or PPSPM risks related to Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels). The implementation of a risk-based APU, PPT, and PPPSPM program supports Traders in implementing preventive and risk mitigation measures commensurate with the identified TPPU, TPPT, and/or PPSPM risks. Traders can subsequently allocate their resources according to their risk profile, manage internal controls, internal structure, and implement policies and procedures to prevent and detect TPPU, TPPT, and/or PPSPM. In implementing a risk-based APU, PPT, and PPPSPM program, Traders must refer to the risks listed in the NRA and SRA. The risks listed in the NRA and SRA can develop and change, so Traders must be responsive and consider these risk changes.
Risk Concept
a. Risk Definition
Risk is defined as the likelihood of an event and its impact. Simply put, risk is seen as a combination of the probability of occurrence and the level of damage or loss that may result from an event.
In the context of TPPU, TPPT, and PPSPM, risk is interpreted as:
b. Risk Management
Risk management is a process widely used in the public and private sectors to assist in decision-making. In relation to TPPU, TPPT, and/or PPSPM, this process includes understanding TPPU, TPPT, and/or PPSPM risks, assessing these risks, and developing methods to manage and mitigate identified risks. In implementing risk management for TPPU, TPPT, and/or PPSPM, Traders can develop risk management methods according to the Trader's needs based on TPPU, TPPT, and/or PPSPM risk assessments, business models, business activities, business scale, business complexity, business characteristics, and/or major events or developments in Trader management and operations, while still referring to legislation regulating APU, PPT, and PPPSPM.
c. Inherent Risk and Residual Risk
In conducting risk assessments, it is important to distinguish between inherent risk and residual risk.
Inherent risk is the risk attached to an event or condition that exists prior to the application of control measures. This inherent risk is related to the TPPU, TPPT, and/or PPSPM risk profile of prospective Customers or Customers, which includes at least 4 (four) risk factors, namely Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels). On the other hand, residual risk is the level of risk remaining after the implementation of risk mitigation steps and controls.
d. Risk-Based Approach
In the context of TPPU, TPPT, and PPSPM, the risk-based approach is a process that includes the following:
Customer Risks Related to Business Specifics
Customer risks related to the specific nature of the Trader's business increase when meeting the following factors:
a) Customer is a Politically Exposed Person (PEP), including family members or close associates of the PEP; b) Customer is detected using a virtual private network intended to mask the IP address when accessing the Trader's website/application; c) The transaction value of the Customer has a nominal amount that is not commensurate with the Customer's profile (exceeding reasonable limits); d) The intensity of transactions by the Customer exceeds reasonable limits, including those outside normal/reasonable policies or habits; e) The Customer acts on behalf of the Beneficial Owner; f) The Customer uses the Trader's products and/or services or conducts Digital Financial Asset transactions, including Crypto Assets, through the Trader in a manner inconsistent with the Customer's needs or not beneficial to the Customer; g) The Customer or Beneficial Owner provides very minimal information or information that is suspected to be fictitious; h) The Customer or Beneficial Owner obscures or fails to disclose their true identity; i) Gatekeepers, such as supporting professions including accountants, legal consultants, appraisers, notaries, or other professions, acting on behalf of the Customer regarding accounts/accounts at the Trader; j) The Customer is a corporation with a complex ownership structure that makes it difficult to identify the Beneficial Owner, ultimate owner, or ultimate controller of the corporation; k) The Customer is an institution supervised by other regulatory/supervisory authorities that has not effectively implemented Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing programs; l) The Customer changes the account number recorded with the Trader; m) Risks of using false identities in the form of identity forgery, namely impersonation identities (impersonating another's identity) and synthetic identities (combining real and fake identities). Impersonation identities are done by stealing another person's identity, while synthetic identities use forgery by combining real identities with fake identities to generate a new identity that appears real; and/or n) There is a discrepancy between the identity or personal data of the Customer held by the Crypto Asset Trader and the identity or personal data of the Customer held by payment service providers and/or fiat storage bank accounts.
Country/Geographic Area/Jurisdiction Risks
In conducting risk assessments, Traders must identify risks related to geographic locations, whether the Trader's geographic location, the Customer's geographic location, or the location where the business relationship occurs, and their impact on overall risk. TPPU, TPPT, and/or PPSPM risks related to countries/geographic areas/jurisdictions increase when meeting the following provisions:
a) Issuers of Digital Financial Assets, including Crypto Assets, from high-risk countries or jurisdictions; b) Funds or Digital Financial Assets, including Crypto Assets, from or sent to high-risk countries or jurisdictions; c) The Customer has significant connections with high-risk countries or jurisdictions; d) The Customer resides in high-risk areas; e) The Customer is detected accessing the Trader's application/website while in high-risk areas or border regions; f) The Customer resides in high-risk international border areas; g) The Customer's original residence area is unknown (using fake IP addresses); and/or h) The Customer is detected conducting transactions with Customers from high-risk countries or transactions connected to Crypto Asset Traders in high-risk countries.
Indicators determining a high-risk country/geographic area/jurisdiction regarding TPPU, TPPT, and/or PPSPM include:
a) Jurisdictions identified by organizations conducting mutual assessments of countries (such as: Financial Action Task Force (FATF) on Money Laundering, Asia Pacific Group on Money Laundering (APG), Caribbean Financial Action Task Force (CFATF), Committee of Experts on the Evaluation of Anti-Money Laundering Measures and the Financing of Terrorism (MONEYVAL), Eastern and Southern Africa Anti Money Laundering Group (ESAAMLG), The Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), Grupo de Accion Financiera de Sudamerica (GAFISUD), Inter Governmental Action Group Against Money Laundering in West Africa (GIABA), or Middle East & North Africa Financial Action Task Force (MENAFATF)) as not adequately implementing FATF Recommendations; b) Countries identified as non-cooperative or tax havens by the Organization for Economic Cooperation and Development (OECD); c) Countries with low levels of good governance as determined by the World Bank; d) Countries with high corruption risk levels as identified in the Transparency International Corruption Perception Index; e) Countries widely known as places of production and trade centers for narcotics; f) Countries subject to sanctions, embargoes, or similar measures by, for example, the United Nations (UN); or g) Countries or jurisdictions identified by trusted institutions as funding or supporting terrorist activities, or allowing terrorist organization activities in their country.
Product/Service/Transaction Risks (Including Transactions)
Overall risk assessments must include determining risks that may occur regarding various products/services (including transactions) offered. Factors that can increase product/transaction risks include:
a) Digital Financial Asset products or services, including Crypto Assets, that enable increased anonymity, reduced transparency, and blurred financial flows, examples: anonymity-enhanced cryptocurrencies (AECs), mixers and tumblers, decentralized platforms and exchanges, privacy wallets; b) Digital Financial Asset products or services, including Crypto Assets, related to illegal activities such as darknet marketplace transactions, ransomware, and hacking; c) Products or services that enable payments, distribution, or management of funds from unknown third parties or parties with no relationship to the Customer; and/or d) Transactions originating from financing and/or wallets owned by suspected parties and/or designated by authorities as affiliated with specific crimes.
Distribution Network Risks (Delivery Channels)
Distribution networks (delivery channels) are media used to obtain a product/service/transaction, or media used to conduct a transaction.
One of the Trader's business characteristics is the distribution network (delivery channels) process conducted without direct meetings (non-face to face). For example, the use of mobile phone applications (mobile apps) and websites, accessible 24 (twenty-four) hours a day, 7 (seven) days a week, and from anywhere. Additionally, Traders must also consider borderless risks as part of what can increase distribution network (delivery channels) risks, where media used for borderless transactions carry higher risks compared to non-borderless transactions. With these specific characteristics, Traders may likely be used to obscure the true identity of the Customer or Beneficial Owner, thereby carrying higher risks. Although some distribution networks (delivery channels) using mobile phone applications or internet websites are common, these must still be considered as part of the factors that can cause TPPU, TPPT, and/or PPSPM risks to become higher. Some indicators causing high-risk distribution networks (delivery channels) include untested online applications regarding reliability and security, particularly concerning Customer data confidentiality.
Other Relevant Risks
Other relevant factors that can impact TPPU, TPPT, and/or PPSPM risks include:
a) developments in TPPU, TPPT, and/or PPSPM risk modes and typologies; b) business models, business scale, and number of employees as inherent risk factors for Traders; c) high total value and intensity of transactions requiring adequate risk mitigation; d) the use of information technology throughout the Trader's entire business process chain; e) data security from cyberattack risks, where Traders heavily rely on the use of open communication networks (internet), thus carrying significant risks against cyberattacks during internet usage; f) personal data protection covering protection against the acquisition, collection, processing, analysis, storage, presentation, announcement, delivery, dissemination, and destruction of personal data in accordance with applicable laws and regulations. The greatest risk for Traders relates to poor personal data protection management; g) transaction and customer acceptance records, where Traders are required to provide transaction and customer acceptance records for all activities within the Trader's Electronic System. Transaction and customer acceptance records are crucial as they are used for supervision, law enforcement, dispute resolution, verification, testing, and other examinations; and/or h) data storage centers (data centers) and disaster recovery centers, where the existence of data centers and disaster recovery centers aims to facilitate personal data protection processes and to restore data, information, and important functions of the Electronic System disrupted or damaged by natural and/or human-caused disasters. Through data storage centers (data centers) and disaster recovery centers, Traders maintain backup data so as not to repeat the data collection process.
Traders must consider that risk factors as referred to in numbers 3) through 8) above may be interrelated between 1 (one) risk factor and other risk factors.
Indicators that can increase risks are not limited to those referred to in numbers 3) through 8). Indicators that can increase risks may develop according to the complexity of the Trader's business activities.
After identifying and documenting inherent risks, Traders must provide assessments regarding the level of each risk for prospective Customers, such as low, medium, and high.
In conducting the inherent risk identification stage, Traders must be able to explain the entire risk identification process conducted by the Trader and the reasons or considerations.
Each risk element identified as high risk must be mitigated and documented. Traders must be able to explain to the Financial Services Authority (OJK) the mitigation steps for high-risk elements, for example, steps in policies and procedures or training programs.
Traders must also be able to demonstrate to the Financial Services Authority (OJK) that risk mitigation steps have been implemented effectively, for example, shown through internal audit results or independent audits.
Traders must provide documented information showing that Traders have specifically considered high-risk indicators in their risk assessments.
In order to identify TPPU, TPPT, and/or PPSPM risks and establish risk scales for prospective Customers when opening business relationships or Customers when conducting transactions, Traders may use regulatory technology such as big data analytics, artificial intelligence, and/or machine learning.
The utilization of regulatory technology in implementing Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing programs by Traders can also be done by Traders during electronic verification, transaction monitoring, and red flag alert determination, while considering Customer data and information security.
b. Establishing Risk Tolerance
c. Implementation of Risk-Based Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing Programs (Risk-Based Approach)
d. Risk Mitigation and Control Steps
e. Evaluation of Residual Risks (Residual Risk)
f. Review and Evaluation of Risk-Based Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing Programs (Risk Based Approach) Implementation https://jdih.ojk.go.id/
The Money Laundering, Terrorism Financing, and Proliferation Financing Risk Assessment held by the Trader must be evaluated based on the need to test the effectiveness of the implementation of the AML, CTF, and CPF programs, which includes:
a) active supervision by the Board of Directors and Board of Commissioners; b) policies and procedures; c) management information systems; d) internal controls; e) human resource needs possessing knowledge and capabilities in the field of information technology and the Trader's business processes; f) human resource training programs for employees, Senior Officials, as well as the Board of Directors and Board of Commissioners regarding the implementation of the AML, CTF, and CPF programs; and/or g) employee profiles including the creation of (profiling) identity data and employee competencies.
In the event of changes in business activity structure, the offering of new products and services, and new technologies, updates to the risk assessment must be conducted for policies and procedures, mitigation steps, and internal controls.
Review of the Money Laundering, Terrorism Financing, and/or Proliferation Financing Risk Assessment must cover all elements including policies and procedures regarding risk assessment, risk mitigation, and more intensive continuous monitoring. The review of the risk assessment can help the Trader in evaluating the improvement of existing policies and procedures or the formation of new policies and procedures. Identified risks may change or develop along with the development of new products or the emergence of new threats to the Trader's business activities. Ultimately, the review procedures for the aforementioned risk assessment will affect the effectiveness of the implementation of the risk-based AML, CTF, and CPF programs in applying the AML, CTF, and CPF programs.
With the review of the implementation of the risk-based AML, CTF, and CPF programs (risk based approach), the Trader must:
a) conduct reviews according to the Trader's needs; b) produce reviews that cover compliance with policies and procedures, risk assessments regarding Money Laundering, Terrorism Financing, and Proliferation Financing, as well as training programs to test the effectiveness of the implementation of the risk-based AML, CTF, and CPF programs (risk based approach); c) conduct accounting of the review process and report to the Senior Official; and d) conduct accounting of the review results and establish corrective steps to be followed up.
III. ACTIVE SUPERVISION BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
Active Supervision by the Board of Commissioners.
In conducting active supervision, the Board of Commissioners must at least:
a. ensure the Trader has policies and procedures for the implementation of the AML, CTF, and CPF programs; b. approve the written policies and procedures for the implementation of the AML, CTF, and CPF programs proposed by the Board of Directors;
c. evaluate the policies and procedures for the implementation of the AML, CTF, and CPF programs;
d. supervise the implementation of the duties and responsibilities of the Board of Directors regarding the implementation of the AML, CTF, and CPF programs; and e. ensure that discussions regarding the implementation of the AML, CTF, and CPF programs take place in Board of Directors and Board of Commissioners meetings. The results of the discussion meetings must be recorded in meeting minutes (minute meeting) signed by the Board of Directors and Board of Commissioners attending the discussion meetings.
In supporting the effectiveness of the implementation of the AML, CTF, and CPF programs, the Board of Directors and Board of Commissioners must:
a. have adequate understanding of the inherent Money Laundering, Terrorism Financing, and/or Proliferation Financing risks associated with all operational activities of the Trader so that the Board of Directors and Board of Commissioners are able to manage and mitigate such risks adequately in accordance with applicable laws and regulations; b. have understanding regarding inherent risks including Customer risk, country/geographic area/jurisdiction risk, product/service/transaction risk, distribution network (delivery channels) risk, and other relevant risks;
c. ensure an adequate organizational structure for the implementation of the AML, CTF, and CPF programs, including ensuring that the AML, CTF, and CPF program responsible party is within the organizational structure; and
d. be responsible for policies and procedures, implementation, and supervision of the implementation of the AML, CTF, and CPF programs, including the management and mitigation of Money Laundering, Terrorism Financing, and/or Proliferation Financing risks in all operational activities of the Trader.
Responsible Party for the Implementation of the AML, CTF, and CPF Programs
a. The Trader must have a responsible party for the implementation of the AML, CTF, and CPF programs. b. The responsible party for the implementation of the AML, CTF, and CPF programs must be within the Trader's organizational structure.
c. The determination and existence of the responsible party for the implementation of the AML, CTF, and CPF programs is based on the needs and complexity of the Trader's business, meaning the Trader can have a special work unit and a responsible official, or only have a special work unit, or only have a responsible official.
d. In the event that the responsible party for the implementation of the AML, CTF, and CPF programs is a special work unit, it must meet the following provisions:
IV. POLICIES AND PROCEDURES
Policies and procedures for the implementation of the AML, CTF, and CPF programs based on a risk-based approach include:
a. identification and verification of prospective Customers or Customers; b. identification and verification of Beneficial Owners;
c. termination of business relationships or rejection of transactions;
d. continuous management of Money Laundering, Terrorism Financing, and Proliferation Financing risks regarding Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels); e. maintenance of accurate data related to transactions, accounting of the CDD process, and accounting of policies and procedures; f. updating and monitoring; g. reporting to Senior Officials, the Board of Directors, and the Board of Commissioners; and h. reporting to the Financial Transaction Reports and Analysis Center (PPATK) and the Police.
The Trader must review policies and procedures once (1) in one (1) year. In accordance with the Trader's needs based on Money Laundering, Terrorism Financing, and/or Proliferation Financing risk assessments, business activities, business scale, business complexity, business characteristics, and/or major events or developments in the management and operations of the Trader, reviews of policies and procedures can be conducted more than once (1) in one (1) year.
If based on the review conducted, the Trader deems it necessary to change the existing policies and procedures, such changes must be formulated within a maximum of 6 (six) months from the review results.
The policies and procedures as referred to in number 1 must observe the principle of knowing the service user (Know Your Customer (KYC)).
PMPJ/KYC as referred to in number 1 consists of CDD and EDD, through CDD or EDD:
a. The Trader can obtain detailed information regarding prospective Customers, Customers, Customer transactions, including Suspicious Financial Transactions; b. The Trader can protect the Trader's reputation and integrity, facilitate compliance with provisions, and protect the Trader from external threats, namely being used as a means of Money Laundering, Terrorism Financing, and/or Proliferation Financing; and
c. The Trader must always be careful in accepting prospective Customers and continue to monitor Customer transactions using the Trader's services. If transactions made are not in accordance with the profile, characteristics, or habitual transaction patterns of the respective Customer, the Trader is obligated to submit a Suspicious Financial Transaction report to PPATK.
CDD is conducted by the Trader at the time:
a. establishing business relationships with prospective Customers or transactions with Customers; b. there are financial transactions in Indonesian Rupiah and/or foreign currency with a value of at least or equivalent to IDR 100,000,000.00 (one hundred million Rupiah);
c. there are indications of Suspicious Financial Transactions related to Money Laundering, Terrorism Financing, and/or Proliferation Financing; or
d. the Trader doubts the truthfulness of information provided by prospective Customers, Customers, authorized recipients, and/or Beneficial Owners (Beneficial Owner).
Repeated CDD can be conducted by the Trader if the Trader assesses that there are changes in risk levels caused by, among others:
a. significant increase in transaction values; b. significant changes in Customer profiles; and/or
c. information in the Customer profiles available in the integrated Customer profile (single customer identification file) has not been completed with supporting documents for verification purposes.
Before the development of new products/services/services and business practices including transaction methods/distribution networks (delivery channels) and/or the use of new technology or development of technology for existing products/services/services that have been launched or used, the Trader is required to identify and conduct risk assessments regarding Money Laundering, Terrorism Financing, and/or Proliferation Financing, and take adequate actions to manage and mitigate risks.
Identification of Prospective Customers and Customers;
a. The Trader is obligated to identify and classify prospective Customers or Customers into groups of individuals (natural person), corporations (legal person), and other legal arrangements (legal arrangement). b. The Trader must have policies regarding the acceptance and identification of prospective Customers or Customers.
c. The acceptance and identification policies for prospective Customers as referred to in letter b must at least cover the following:
submission of copies of documents as referred to in Article 25, Article 26, Article 27, Article 28, and Article 29 of the Financial Services Authority Regulation regarding the implementation of AML, CFT, and CPF programs in the financial services sector in softcopy format through the Trader's website or application.
g. In addition to copies of documents as referred to in letter f, the Trader may request additional data, documents, and information needed in identifying and verifying prospective Customers or Customers, the submission of which is carried out through the Trader's website or application. Examples of such additional data, documents, and information include:
a. In order to conduct business relationships with prospective Customers or transactions with Customers, the Trader must verify the information provided during identification through supporting documents of the prospective Customers or Customers.
b. In order to ensure the truthfulness of the identity of prospective Customers, verification is carried out by:
c. The completion of the identity verification process for prospective Customers or Customers must be done before opening a business relationship with the prospective Customer or conducting transactions with the Customer.
d. In certain conditions, the verification process may be completed after the business relationship or transaction has been conducted.
Example: Identity documents required are still being processed and cannot be fulfilled at the time of conducting a business relationship with the prospective Customer or Customer.
e. In the event that the verification process is completed after the business relationship or transaction has been conducted as referred to in letter d, the Trader must carry out adequate risk mitigation, for example by doing the following:
Example:
a) for corporate Customers and other legal arrangements, in the form of documents proving the processing of business permits issued by the relevant authority, and/or documents proving the processing of tax identification numbers from the relevant government agency administering tax affairs; or b) for individual Customers, in the form of documents proving that inheritance deeds or sales deeds as source of funds documents are being processed by a notary/land deed official;
2) imposing service and/or transaction restrictions provided by the Trader; and/or
3) the Trader requests the prospective Customer to complete the required documents within a certain period.
f. The Trader may conduct the verification process for prospective Customers or Customers electronically as long as the Electronic System used by the Trader is capable of verifying the truthfulness of the identity of the prospective Customers or Customers.
g. In the event that the Trader carries out the verification process electronically, the Trader must pay attention to the following matters:
Example: Video call features on the Trader's application that are connected directly in real-time and online with the Trader's employees/officials via smartphones, computers, and/or tablets owned by the prospective Customer or Customer;
e) face-to-face verification through electronic facilities owned by a third party is conducted in a form equivalent to real-time and online video banking, electronically connecting the Trader's employees/officials with the prospective Customer or Customer;
f) electronic face-to-face verification owned by the Trader or third parties must not be conducted using providers that generally provide electronic facilities, such as WhatsApp calls, Line calls, and Skype;
g) to provide additional assurance for the Trader in carrying out the face-to-face verification process through electronic facilities owned by the Trader or third parties, the Trader may add the use of motion detection mechanisms and/or technologies to ensure that the prospective Customer or Customer is a living subject and there is no identity fraud attempt.
Example: Motion detection mechanisms in the electronic face-to-face verification process include the Trader's officials/employees requesting the prospective Customer or Customer to move randomly in various directions (e.g., moving the face 45 degrees or 90 degrees left or right), requesting the prospective Customer or Customer to show the area around them during verification, and/or asking questions to confirm the truthfulness of information or identity to the prospective Customer or Customer.
The face-to-face verification process may be exempted with a non-face-to-face verification process (non-face to face verification) with the following provisions:
a) non-face-to-face verification is conducted using software owned by the Trader with hardware owned by the Trader or the Customer or prospective Customer.
Example: Software owned by the Trader and hardware owned by the Customer or prospective Customer used for non-face-to-face verification include but are not limited to:
(1) applications owned by the Trader that can be accessed via mobile devices (mobile devices) such as smartphones and/or tablet computers; and/or (2) the Trader's website that can be accessed via electronic devices of the prospective Customer or Customer such as computers and/or laptops.
The Trader must ensure that the hardware owned by the prospective Customer or Customer is equipped with supporting verification features such as cameras, scanners, recorders, and/or location trackers;
b) non-face-to-face verification is required to utilize population data that meets 2 (two) authentication factors covering:
(1) what you have, namely identity documents owned by the prospective Customer, namely the Electronic Identity Card (KTP Elektronik); and (2) what you are, namely biometric data such as fingerprints, iris data of the prospective Customer, and/or facial recognition technology.
Access to population data can be obtained by referring to legislation regulating the granting of access rights and utilization of population data, which can be accessed via web services, web portals, and card readers.
Examples of population data access via web services and web portals include the Trader cooperating with the Ministry administering population and civil registration affairs to obtain access rights to population data and not storing individual data.
Other examples of population data access are through parties that utilize population administrative data meeting 2 (two) authentication factors as referred to in items (1) and (2), where such parties obtain certification from the Ministry administering communication and information affairs;
c) to provide additional assurance for the Trader in the non-face-to-face verification process as referred to in letter b), the Trader may:
(1) add other authentication factors, namely what you know, which can include personal identification numbers (PIN), passwords, one-time passwords (OTP), verification emails, and/or challenge-response; and/or (2) add the use of motion detection technology to ensure that the prospective Customer or Customer is a living subject and there is no identity fraud attempt;
a. Identification of High-Risk Prospective Customers and Customers or PEPs
In the event that the Trader assesses that a prospective Customer or Customer is High-Risk or a PEP, the Trader is obligated to apply Enhanced Due Diligence (EDD).
The Trader must have policies and procedures for the identification of Customers or High-Risk Customers or PEPs.
The policies and procedures for the identification of Customers or High-Risk Customers or PEPs as referred to in item 2) must at least cover the provisions as referred to in the identification provisions for prospective Customers or Customers as referred to in item 8.
The identification of High-Risk prospective Customers and Customers or PEPs can be conducted electronically, as long as the Trader's Electronic System is capable of identifying the official identity of the High-Risk prospective Customers and Customers or PEPs.
In the event that the identification of High-Risk prospective Customers and Customers or PEPs is conducted electronically, the implementation can be carried out, among others, through the filling out of electronic forms and the submission of copies of documents as referred to in Article 25, Article 26, Article 27, Article 28, and Article 29 of the Financial Services Authority Regulation regarding the implementation of AML, CFT, and CPF programs in the financial services sector electronically (softcopy) through the Trader's website or application.
In addition to copies of documents as referred to in item 5), the Trader may request additional data, documents, and information needed in electronically identifying and verifying prospective Customers, the submission of which is carried out through the Trader's website or application. Examples of such additional data, documents, and information can include data and information as referred to in item 8 letter g regarding the identification of prospective Customers or Customers.
b. Verification of High-Risk Prospective Customers and Customers or PEPs
Verification of High-Risk prospective Customers and Customers or PEPs is carried out by paying attention to the provisions as referred to in item 9 letter a, letter b, letter c, letter d, and letter e.
In addition to paying attention to the provisions as referred to in item 1), the Trader may conduct verification of High-Risk prospective Customers and Customers or PEPs in the implementation of EDD by methods including but not limited to:
a) requesting or seeking additional information regarding the Customer's profile, such as occupation, source of funds, source of wealth; b) updating Customer identity data; c) requesting or seeking additional information regarding the reasons or basis for transactions conducted by the Customer; d) obtaining approval from Senior Officials to initiate and/or continue business relationships and/or transactions; and/or
e) conducting stricter monitoring of transactions conducted by the Customer.
Verification of High-Risk prospective Customers and Customers or PEPs as referred to in item 1) can be conducted electronically.
In the event that the Trader conducts verification of High-Risk prospective Customers and Customers or PEPs electronically, the Trader must pay attention to the provisions as referred to in item 9 letter g.
a. Identification of Beneficial Owners
The Trader must ensure whether the business relationship with prospective Customers or transactions with Customers are conducted for the benefit of:
a) prospective Customers or Customers; or b) other parties or Beneficial Owners.
If prospective Customers represent Beneficial Owners to open business relationships or conduct transactions, the Trader must conduct CDD procedures against Beneficial Owners that are equally strict as CDD procedures for prospective Customers.
In the event that Beneficial Owners are classified as High-Risk Customers or PEPs, the procedure applied is stricter CDD procedures or Enhanced Due Diligence (EDD).
The Trader must examine the truthfulness of information provided by prospective Customers by verifying supporting documents based on documents and/or other independent sources and ensuring the currency of such information.
In identifying corporate prospective Customers, the Trader must determine Beneficial Owners based on data and/or information provided by prospective Customers.
Identification of Beneficial Owners from corporations in the form of limited liability companies can be conducted, among others, through tracing information as follows:
a) individuals who have a majority share ownership percentage. Majority share ownership depends on the ownership structure of the limited liability company, which can be based on a threshold, for example, parties owning shares with a percentage of more than 25% (twenty-five percent).
b) in the event that no majority share ownership is found (shareholders have equal ownership percentages), the identification of the shareholder who most controls the corporation is conducted through other means, for example, individuals who have the ability to determine or appoint members of the Board of Directors.
c) in the event that no shareholder who most controls the corporation is found, for example, decisions are taken collectively by all shareholders of the corporation, the identification of Beneficial Owners is based on members of the Board of Commissioners or Board of Directors who most control the limited liability company.
The steps of tracing information for the identification of Beneficial Owners as referred to in letters a), b), and c) above are not optional alternative steps, but are hierarchical steps that will each be used if the previous steps have been applied by the Trader. However, the Trader has not yet been able to identify Beneficial Owners through these steps.
For Beneficial Owners that are state institutions or government agencies, companies with majority state-owned shares, or public companies or issuers, prospective Customers are not required to submit documents and/or identity documents of ultimate controllers. Nevertheless, the Trader must still conduct identification and verification of Beneficial Owners using data and information available in the public domain.
Exceptions to the requirement to submit documents and/or identity documents of Beneficial Owners as referred to in item 7) must be documented by the Trader.
If the Trader doubts or cannot verify the identity of Beneficial Owners, the Trader is obligated to refuse to conduct business relationships with prospective Customers or transactions with Customers.
Against prospective Customers or Beneficial Owners whose business relationships are rejected, the Trader must obtain at least name, identity number, address, and place and date of birth information in accordance with copies of identity documents obtained by the Trader for the purpose of reporting Suspicious Financial Transactions.
Identification of Beneficial Owners can be conducted electronically as long as the Trader's Electronic System is capable of identifying the official identity of Beneficial Owners.
To determine whether prospective Customers or Customers are acting for the benefit of Beneficial Owners, the implementation can be conducted, among others, by adding questions as to whether prospective Customers or Customers are acting for the benefit of Beneficial Owners in the filling out of electronic forms filled out through the Trader's website or application.
In the event that the identification of Beneficial Owners is conducted electronically, the implementation can be carried out, among others, through the filling out of electronic forms and uploading copies of identity documents in accordance with the provisions regarding the obligation to conduct identification and verification of Beneficial Owners as referred to in the Financial Services Authority Regulation regarding the implementation of AML, CFT, and CPF programs in the financial services sector, electronically (softcopy) through the Trader's website or application.
b. Verification of Beneficial Owners
In order to ensure the truthfulness of the identity of Beneficial Owners, verification can be conducted by:
a) conducting interviews via telephone or video conference with Beneficial Owners if necessary; b) matching the consistency of thumbprints, fingerprints, or facial photos (selfies) with identity documents or other documents containing signatures, electronic signatures, thumbprints, fingerprints, or facial photos (selfies) of Beneficial Owners; c) requesting the provision of more than one identity document of Beneficial Owners issued by the relevant party if there is doubt regarding the existing identity documents; d) In cases where necessary, conducting cross-checks to ensure consistency of various information provided. Cross-checks are carried out by methods including but not limited to:
(1) contacting prospective Customers via landline or office telephone; (2) contacting the human resources official at the prospective Customer's workplace if the prospective Customer is an employee of a company or agency; (3) confirming the prospective Customer's income by requiring bank statements from banks or other financial service providers; or (4) conducting geographic information analysis to view forest conditions through remote sensing technology for prospective Customers who are companies operating in the forestry sector; and/or e) ensuring that prospective Customers do not have a negative track record by verifying the identity of prospective Customers using other independent sources including but not limited to:
(1) DTTOT issued by the National Police of the Republic of Indonesia; (2) DPPSPM; or (3) other data such as the prospective Customer's employer identity, telephone accounts, and electricity accounts.
The completion of the identity verification process for Beneficial Owners must be done before opening a business relationship with prospective Customers or conducting transactions
with Customers acting for and on behalf of the interests of the Beneficial Owner.
a) document completeness cannot be met at the time the business relationship or transaction is to be conducted, for example, because documents are still being processed. In this case, the Beneficial Owner may submit documents after establishing the business relationship, within the timeframe set by the Trader, followed by adequate risk mitigation; and/or
b) the risk level of the individual Beneficial Owner is classified as low.
Verification of the Beneficial Owner may be conducted electronically as long as the Trader's Electronic System is capable of verifying the authenticity of the official identity of the Beneficial Owner.
In the event that the Trader conducts electronic verification of the Beneficial Owner, the Trader must observe the provisions as referred to in item 9 letter g.
a. In the event that the Trader assesses that a prospective Customer or Customer, based on the results of the risk assessment of Money Laundering, Terrorism Financing, and/or Proliferation Financing, has a low risk profile or the transaction conducted by the Customer is low risk and meets the criteria for a prospective Customer or Customer with a simple profile and characteristics, the Trader may apply Simplified CDD.
b. In the event that the Trader implements Simplified CDD, the Trader must at least:
ensure that the information and supporting documents for Simplified CDD contain at least identity, source of funds, and purpose of the transaction;
establish criteria for Customers with simple profiles and characteristics eligible for Simplified CDD, accompanied by clear reasons or basis for the determination that are consistent with the risk assessment conducted by the Trader, for example, High-Risk Customers or PEPs are not included as prospective Customers or Customers eligible for Simplified CDD;
ensure that Simplified CDD requirements are capable of managing and mitigating the threat level of Money Laundering, Terrorism Financing, and/or Proliferation Financing;
ensure that Simplified CDD requirements do not include Customers who are categorized as High-Risk Customers or PEPs based on legislation;
notify the Financial Services Authority (OJK) of the plan to implement Simplified CDD procedures, including the criteria for Customers with simple profiles and characteristics eligible for Simplified CDD and the start date of the implementation of the Simplified CDD procedures. Example: After conducting a customer risk analysis, the Trader decides to apply Simplified CDD to a specific group of Customers by changing the existing AML, CFT, and CPF policies and procedures. Based on the changes to the AML and CFT policies and procedures, if Simplified CDD will be applied starting March 30, the Trader may submit the notification to the Financial Services Authority regarding the plan to implement Simplified CDD before March 30;
document Customers eligible for Simplified CDD in a list that also contains information regarding the reasons for classifying the Customer as low-risk and eligible for Simplified CDD; and
ensure information security measures to maintain the confidentiality of managed data and information.
c. Customers who have received Simplified CDD must be removed from the Simplified CDD Customer list if they meet the following criteria:
identified in connection with suspected Money Laundering, Terrorism Financing, and/or Proliferation Financing;
have an increased risk level; and/or
do not align with the initial purpose at the time of registration as a Customer.
d. The Trader may conduct identification and verification of prospective Customers or Customers for the purpose of Simplified CDD electronically as long as the Trader's Electronic System is capable of identifying the official identity of low-risk prospective Customers or Customers and meeting the criteria for prospective Customers or Customers with simple profiles and characteristics, as well as being capable of verifying the authenticity of the official identity of the prospective Customers or Customers in question.
e. In the event that the Trader conducts identification and verification of prospective Customers or Customers for the purpose of Simplified CDD electronically, the implementation must observe the provisions as referred to in item 8 letter d, letter e, letter f, and letter g, as well as item 9 letter g.
a. The Trader may use the results of CDD conducted by a third party against prospective Customers who have become Customers of that third party.
b. Third-party CDD does not apply to agency relationships or outsourcing. This is because in agency or outsourcing relationships, CDD is conducted for the interests of the Trader in accordance with the Trader's procedures and subject to the control of the Trader who delegates the application of those procedures.
c. In the event that results of CDD conducted by a third party against prospective Customers are available, the Trader may use the results of CDD conducted by the third party against those prospective Customers.
d. In the event that the Trader uses the results of Third-Party CDD:
CDD responsibility remains with the Trader.
The Trader must understand the purpose and intent of the business relationship and identify and verify the Customer and Beneficial Owner.
The Trader must obtain the necessary information related to CDD procedures as soon as possible.
The Trader must have cooperation with the third party in the form of a written agreement, wherein the written agreement must contain clauses confirming that the Trader has the right to obtain information, data, or copies of Customer supporting documents from the third party that has conducted CDD on the Customer, provided that the information, data, or copies of Customer supporting documents are needed solely for the implementation of the AML, CFT, and CPF programs, and not for other interests such as marketing. Example: The interest in implementing the AML, CFT, and CPF programs is the fulfillment of requests for information, data, and copies of Customer supporting documents from the Financial Services Authority, PPATK, or law enforcement officials.
The Trader must take adequate steps to ensure that the third party is willing to fulfill requests for information and copies of supporting documents immediately at the first opportunity when needed by the Trader in the implementation of the AML, CFT, and CPF programs.
The Trader must ensure that the third party is a financial institution and/or provider of goods and/or services and specific professions that have CDD procedures and are subject to supervision by the competent authority in accordance with applicable regulations. For example, the Trader may use the results of CDD conducted by:
a) financial service providers in the banking, capital market, and/or non-bank financial industry sectors, where the financial service provider has CDD procedures established by the competent supervisory authority, namely the Financial Services Authority; or
b) commodity futures brokerage companies, where the commodity futures brokerage company has CDD procedures established by the competent supervisory authority, namely the Commodity Futures Trading Regulatory Agency (BAPPEBTI).
The Trader must pay attention to information regarding the country risk where the third party originates.
In the event that the Trader intends to use the results of third-party CDD from a third party located in a high-risk country, this may be done if:
a) the third party is in the same financial group as the Trader;
b) the financial group has effectively implemented CDD, document management, and AML, CFT, and CPF programs in accordance with FATF Recommendations;
c) adequate risk mitigation has been conducted by the AML, CFT, and CPF unit against the high-risk country based on the AML, CFT, and CPF program policies at the financial group level; and
d) the financial group is supervised by a competent authority.
In providing digital financial asset transfer or transfer services, the Trader is required to apply the Travel Rule principle as follows:
a. in the transfer or transfer of Digital Financial Assets with a value in Rupiah equivalent to or greater than USD 1,000.00 (one thousand US dollars), the following details and/or information must be obtained:
a) sender's name, sender's Wallet address, and sender's address;
b) ID card is mandatory for Indonesian citizens; and
c) passport, identity card issued by the Customer's country of origin, permanent residence permit card, or limited residence permit card for foreign citizens, if possible to obtain;
a) recipient's name;
b) recipient's wallet address; and
c) recipient's address; and
b. in the transfer or transfer of Digital Financial Assets with a value in Rupiah equivalent to less than USD 1,000.00 (one thousand US dollars), the following details and/or information must be obtained:
a) sender's name; and
b) sender's wallet address; and
a) recipient's name; and
b) recipient's wallet address.
a. The Trader is obligated to have a system for recognizing and monitoring Digital Financial Asset transactions, using a regulatory technology-based system, to monitor and review current transaction recognition and monitoring and past records to determine if there are any suspicious transactions involving Digital Financial Assets. Example: Blockchain analytic tools are applications that can collect, process, and analyze data from the blockchain, whether paid or publicly provided (open source).
b. The Digital Financial Asset transaction recognition and monitoring system as referred to in letter a must be capable of detecting at least the following:
Digital Financial Asset transactions indicated to be conducted by High-Risk Customers;
Digital Financial Asset transactions related to Money Laundering, Terrorism Financing, and/or Proliferation Financing;
red flag transaction indicators based on FATF Recommendations; and
Digital Financial Asset transactions indicated to use methods, techniques, or efforts to enhance anonymity, reduce transparency, and obscure financial flows, for example: anonymity-enhanced cryptocurrencies (AECs), mixers and tumblers, decentralized platforms and exchanges, privacy wallets.
c. In the event that the monitoring system as referred to in letter a indicates the presence of Suspicious Financial Transactions, the Trader must:
reject the transfer of the Customer's Digital Financial Assets from the Trader's wallet to a recipient wallet indicated to be involved in Money Laundering, Terrorism Financing, and/or Proliferation Financing;
freeze the account of the Customer receiving the transfer of Digital Financial Assets from a wallet indicated to be involved in Money Laundering, Terrorism Financing, and/or Proliferation Financing; and/or
close/terminate the business relationship with the Customer.
d. The Trader is prohibited from opening or maintaining anonymous accounts or accounts using fictitious names.
e. The Trader must reject the business relationship or transaction or close/terminate the business relationship with a prospective Customer or Customer in the event that:
they are unwilling to provide information and/or complete documents required by the Trader;
the Trader cannot verify the authenticity of the identity and completeness of documents;
incoming transfers to the Customer's account occur, but after the Customer receives and conducts re-CDD, and based on the sender, it is known that the recipient Customer's account is an account for harboring criminal proceeds as referred to in legislation governing the prevention and eradication of Money Laundering;
providing information and/or documents that are inconsistent or reasonably suspected to be fake documents or information whose authenticity is doubtful;
the source of transaction funds is known and/or reasonably suspected to originate from criminal proceeds;
they are recorded in the DTTOT; and/or
they are recorded in the DPPSPM.
f. The Trader is obligated to notify the Customer in writing regarding the closure of the business relationship.
g. Written notification may be conducted by sending a letter addressed to the Customer according to the address recorded in the Trader's database or announced through print media, electronic media, or other media.
h. In the event that the Trader rejects the business relationship with a prospective Customer or rejects a transaction or closes/terminates the business relationship with a Customer, the Trader is obligated to report this to PPATK regarding the action of rejecting the business relationship or transaction or closing/terminating the business relationship as a Suspicious Financial Transaction.
i. In the event that written notification has been conducted and the Customer does not withdraw the remaining funds stored with the Trader, the settlement of the Customer's remaining funds is conducted in accordance with applicable legislation, including by handing over the remaining funds to the Estate Management Office (Balai Harta Peninggalan).
j. The Trader must document prospective Customers or Customers affected by transaction rejection or business relationship closure as referred to in letter c and letter e in a separate list.
a. The Trader must have policies and procedures to manage continuous risks related to Money Laundering, Terrorism Financing, and/or Proliferation Financing risks, where risk management is not only conducted when the Trader establishes a business relationship with a prospective Customer or conducts transactions with a Customer.
b. Policies and procedures for continuously managing Money Laundering, Terrorism Financing, and/or Proliferation Financing risks include:
In conducting risk identification, the Trader must assess Money Laundering, Terrorism Financing, and/or Proliferation Financing risks inherent in its business by considering inherent risks such as Customer risk, country/area/geographical/jurisdiction risk, product/service/transaction risk, and distribution network (delivery channels).
Risk control and mitigation that can be applied include:
a) identifying and verifying prospective Customers and monitoring Customer transactions;
b) increasing the frequency of supervision and conducting continuous review of business relationships;
c) upgrading CDD to Enhanced Due Diligence (EDD) conducted by the Trader in response to increased Money Laundering, Terrorism Financing, and/or Proliferation Financing risks present in the Customer, the source of funds used to purchase products/services/transactions, and the Customer's transaction patterns in purchasing products and services; and
d) escalation or hierarchical approval for establishing business relationships or transactions through Senior Official approval.
a. Maintenance of accurate data related to Customers and Customer transactions is not only useful for the Trader in risk management and business development, but is also necessary as an effort to assist competent authorities in conducting compliance supervision, examinations of suspected Money Laundering, Terrorism Financing, and/or Proliferation Financing, as well as investigations and inquiries into funds indicated to originate from crime, so that documents stored by the Trader must be sufficient to be used as evidence (if necessary) by law enforcement officials.
b. The Trader must manage or document Customer data, including data obtained from the identification and verification process of prospective Customers or monitoring of Customer transactions, including those with high risks or PEPs in the context of EDD, Beneficial Owners, or those classified as low-risk and meeting the criteria for prospective Customers or Customers with simple profiles and characteristics in the context of Simplified CDD.
c. The Trader must have policies and procedures for document management timeframes covering:
a) the end of the business relationship with the Customer; and/or
b) the discovery of transaction inconsistencies with economic purposes and/or business purposes.
documents related to Customer financial transactions must be managed for the period as regulated in legislation regarding corporate documents.
managed documents must include at least:
a) Customer identity and supporting documents;
b) transaction information conducted;
c) results of analysis conducted;
d) correspondence with Customers; and
e) other documents related to the reporting of Suspicious Financial Transactions.
d. Documents as mentioned in letter b and letter c may be stored through electronic data or document formats in the Trader's database while still observing data or electronic document security systems.
e. In the event that documents as mentioned in letter b and letter c are stored through electronic data or document formats in the Trader's database, the Trader must be capable of displaying the electronic data or documents in full in accordance with legislation, when requested by the Financial Services Authority and/or other competent authorities such as PPATK and/or law enforcement officials.
a. The Trader must update Customer data in accordance with the provisions as referred to in the Financial Services Authority Regulation regarding the implementation of AML, CFT, and CPF programs in the financial services sector continuously and ensure that data, information, and/or documents collected through the CDD and/or EDD process are the most recent data intended to identify the consistency between Customer transactions and the Customer's profile.
b. Data, information, and/or Customer supporting document updating activities are based on the Money Laundering, Terrorism Financing, and/or Proliferation Financing risk level of the Customer and are focused on higher-risk Customers first.
c. Data updating based on Customer risk level as referred to in letter b is obtained from the results of Customer risk assessment manifested in Customer classification based on risk level, taking into account business capacity, business complexity, business characteristics, and/or significant events or developments in Trader management and operations, for example:
Traders with automated data updating capacity capable of reporting all risk levels in real time are updated annually.
Traders with limited data updating capacity are updated as follows:
a) High-Risk Customers are updated at least once a year;
b) Medium-Risk Customers are updated at least once every 2 (two) years; and
c) Low-Risk Customers are updated at least once every 3 (three) years.
d. In conducting data, information, and/or Customer supporting document updating (Customer data updating), the Trader must document Customer updating efforts in the form of worksheets containing the Customer's name, Customer updating date, Customer updating method (for example, via email, phone, letter, news in print and electronic media including the internet or other trusted sources), Customer data updating results, and follow-up on updating results, specifically regarding Customer data that could not be successfully updated.
e. In the event that the Trader's resources are limited, Customer updating activities are conducted on a priority scale, based on:
Customer risk level classified as High-Risk Customer;
transactions with significant amounts and/or deviating from transaction profiles or Customer profiles;
significant changes in balance values; and
information in the integrated Customer profile (single customer identification file) is inconsistent with the Customer profile.
f. High-Risk Customer criteria can be seen from:
background or profile of High-Risk Customers;
high-risk financial services sector products used as a means for Money Laundering, Terrorism Financing, and/or Proliferation Financing;
transactions with parties from high-risk countries or Customers having significant relationships with high-risk countries;
transactions inconsistent with Customer profiles;
inclusion in the PEP category;
business field included in high-risk business;
g. The implementation of customer data updates as outlined in the data update plan can be carried out, among others, at the following times:
h. Traders must ensure that documents, data, or information gathered during the Customer Due Diligence (CDD) process are always updated and remain relevant by re-examining existing data, particularly regarding High-Risk Customers or Politically Exposed Persons (PEP).
i. Regarding the updating of DTTOT and DPPSPM, Traders:
j. Traders may update customer data electronically. In the event that Traders perform data updates electronically, then:
k. Traders must account for and document the customer data update process.
l. The accounting and documentation of customer data updates can be done manually in written form through formal documents such as memos, notes, or records, which can also be stored in electronic data or document formats in the Trader's database.
b. Traders are prohibited from providing, giving, or lending funds to or for the benefit of persons or corporations whose identities are listed in the DTTOT and/or DPPSPM. The term "funds" refers to all assets or tangible or intangible movable or immovable property, whether tangible or intangible, obtained by any means and in any form, including in digital or electronic formats, proof of ownership, or connection to all such assets or property, including but not limited to bank credits, traveler's checks, bank-issued checks, money transfer orders, shares, securities, bonds, bank drafts, debt acknowledgments, and Digital Financial Assets.
c. Traders must:
The term "false positive" refers to errors in the immediate blocking implementation carried out by the Trader due to the Trader's customer information system finding partial consistency between Customer information in the Trader's database and the identity of individuals or corporations listed in the DTTOT and/or DPPSPM.
The term "false negative" refers to errors in not implementing immediate blocking by the Trader due to the Trader's customer information system finding partial consistency between Customer information in the Trader's database and the identity of individuals or corporations listed in the DTTOT and/or DPPSPM, while failing to pay sufficient attention to the consistency of all information.
d. In the event that there is consistency of identities and other information regarding Customers or Beneficial Owners with identities and other information listed in the DTTOT and/or DPPSPM, Traders must implement immediate blocking without delay and without prior notification to the Customer or Beneficial Owner, while also referring to other applicable laws and regulations.
In the event that immediate blocking without delay is implemented, the rights of blocked Customers remain provided according to the applicable regulations of the Trader, but these rights remain subject to the blocking.
e. Blocking is implemented against funds owned or controlled, directly or indirectly, obtained by any means and in any manner, by Customers or Beneficial Owners, either fully or jointly with other parties.
f. In the event that there is consistency of identities and other information regarding prospective customers, Customers, and/or Beneficial Owners with identities and other information listed in the DTTOT and/or DPPSPM, Traders must report this as a Suspicious Transaction Report to PPATK.
g. Traders who implement immediate blocking without delay regarding DTTOT must:
h. Traders who implement immediate blocking without delay regarding DPPSPM must:
i. In the event that no consistency of identities and other information regarding Customers with identities and other information listed in the DTTOT is found, Traders must create and submit a null report to the Indonesian National Police (Polri) with a copy to the Financial Services Authority (OJK).
j. In the event that no consistency of identities and other information regarding Customers with identities and other information listed in the DPPSPM is found, Traders must create and submit a null report to PPATK with a copy to the Financial Services Authority (OJK).
k. Traders must identify, assess, understand, and mitigate the risk of sanction evasion regarding DTTOT and/or DPPSPM conducted by prospective customers, Customers, and/or Beneficial Owners.
l. The term "sanction evasion" refers to efforts to evade sanctions by parties whose identities are listed in the DTTOT and/or DPPSPM who conduct business relationships and/or financial transactions with or on behalf of other parties to avoid the detection of Suspicious Transactions.
Examples include prospective customers, Customers, and/or Beneficial Owners conducting business relationships and/or transactions through the following modes:
b. Monitoring conducted by Traders as referred to in letter a must observe the following:
c. Customer profile and transaction monitoring activities are conducted continuously and include:
d. Information sources that can be used to monitor Customers designated as suspects or defendants can be obtained, among others, from:
e. Traders must classify transactions and Customers requiring special monitoring. Monitoring of Customer transactions must be stricter if there are High-Risk Customers.
f. In the event that Traders monitor Customer profiles and transactions electronically, Traders must ensure that the Electronic Systems used can:
g. Traders may monitor profiles and transactions electronically using regulatory technology, including by utilizing algorithms, specific parameters, artificial intelligence, and machine learning.
h. Traders must account for and document the process of monitoring Customer profiles and transactions.
i. The accounting and documentation of monitoring Customer profiles and transactions can be done manually in written form through formal documents such as memos, notes, or records, or through electronic data or document formats in the Trader's database.
b. The trail of transaction activities and customer reception is used for supervision, law enforcement, dispute resolution, verification, testing, and other examinations.
c. The implementation of transaction and customer reception trails includes at minimum:
d. Transaction and customer reception trail processes can be conducted electronically, including:
b. Reports on the progress of approval and supervision regarding these special conditions are reported hierarchically from Senior Officials, the Board of Directors, and the Board of Commissioners.
c. Reporting policies and procedures to Senior Officials, the Board of Directors, and the Board of Commissioners include:
b. Reporting policies and procedures as referred to in letter a include at minimum policies and procedures for reporting Suspicious Transactions, reports related to DPPSPM, and other reports related to the implementation of APU, PPT, and PPPSPM programs in the event of information requests from PPATK.
V. INTERNAL CONTROL
b. Traders are required to have effective and independent internal control systems. The aforementioned systems aim to ensure Trader compliance in effectively implementing APU, PPT, and PPPSPM programs and to minimize the TPPU, TPPT, and/or PPSPM risks faced by Traders.
c. In internal control, Traders must observe the following:
d. Traders must have effective and independent internal control systems to ensure that all functions implementing APU, PPT, and PPPSPM programs run according to established policies and procedures. Effective and independent control systems can be demonstrated by:
reporting submitted to the competent authorities;
11) compliance with legal regulations, reporting requirements, and recommendations regarding the implementation of AML, CFT, and CPF programs, and updating changes in legal regulations;
12) implementation of policies, procedures, and controls regarding CDD and EDD;
13) adequate supervision regarding high-risk customers, transactions, and products, such as transaction limits or management approval;
14) adequate supervision of Trader employees who prepare reports, receive grants, monitor suspicious activities, or are involved in other activities that are part of the implementation of AML, CFT, and CPF programs;
15) integration of compliance with the implementation of AML, CFT, and CPF programs into appropriate job descriptions and performance evaluations;
16) appropriate and relevant training regarding the implementation of AML, CFT, and CPF programs for all employees;
17) testing of the effectiveness of the implementation of AML, CFT, and CPF programs through random sampling and documenting the tests conducted; and
18) independent examination to ensure compliance and effectiveness of AML, CFT, and CPF implementation, carried out in accordance with the needs and complexity of the Trader's business.
e. In conducting internal controls, Traders may use regulatory technology such as algorithms, artificial intelligence technology, and/or machine learning. f. In the event that Traders conduct internal controls using regulatory technology as referred to in letter e, Traders must ensure that the regulatory technology used in the internal control system:
For example, for customer data updates carried out during the period from January to December 2026, Traders must submit reports on the realization of customer data updates no later than January 31, 2027. d) Reports on the realization of customer data updates are submitted online through the electronic system managed by the Financial Services Authority (OJK). In the event that the electronic system is not yet available or experiences technical difficulties, the report on the realization of customer data updates is submitted physically or via electronic mail to the OJK addressed to the head of the supervisory work unit. In the event that the reporting date for the realization of customer data updates falls on a holiday, the report submission is carried out on the next working day.
East Banteng Field Street 2-4
Jakarta 10710, Indonesia, in the event that the OJK Reporting System is not yet available; or
2) Head of the International Department and Anti-Money Laundering and Counter-Terrorism Financing Department
Soemitro Djojohadikusumo Building
East Banteng Field Street 2-4
Jakarta 10710, Indonesia, with a copy to:
Head of the Department of Supervision of Financial Sector Technology Innovation, Digital Financial Assets and Crypto Assets in the event that the OJK Reporting System experiences technical difficulties. f. Traders are deemed to have submitted reports with the following provisions:
Financial Services Authority (OJK) physically as referred to in item 2 letter e. f. Traders must ensure that they are registered as users (user) of SIGAP by accessing https://sigap.ojk.go.id. g. For Traders who have never registered on SIGAP, they can choose the Register button to register. In the registration process, information regarding the SIPO account (OJK Reception Information System) is required, to ensure that only Traders licensed under the authority of the Financial Services Authority (OJK) can access the SIGAP system. h. In more detail, the SIGAP registration procedure and the mechanism for submitting copies of Immediate Blocking reports related to DTTOT and/or DPPSPM through SIGAP, can refer to the Circular Letter of the Financial Services Authority (OJK) regarding guidelines for Immediate Blocking of Customer funds whose identities are listed in DTTOT or DPPSPM.
licensed under the authority of the Financial Services Authority (OJK) can access the SIGAP system. g. In more detail, the SIGAP registration procedure and the mechanism for submitting copies of nil reports related to DTTOT and/or DPPSPM through SIGAP, can refer to the Circular Letter of the Financial Services Authority (OJK) regarding guidelines for Immediate Blocking of Customer funds whose identities are listed in DTTOT or DPPSPM.
c. Nil DPPSPM Reports;
IX. Action Plan and Policies and Procedures
Submission of Action Plans and Policies and Procedures for the Implementation of AML, CFT, and CCPF Programs and Their Amendments
X. OTHER PROVISIONS
This copy is consistent with the original
Head of the Legal Development Directorate
Legal Department signed
Aat Windradi
XI. CLOSING
This Circular Letter of the Financial Services Authority (OJK) takes effect on the date of establishment.
Established in Jakarta on July 3, 2025
EXECUTIVE HEAD OF SUPERVISION OF FINANCIAL SECTOR TECHNOLOGY INNOVATION, DIGITAL FINANCIAL ASSETS AND CRYPTO ASSETS FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA,
HASAN FAWZI signed https://jdih.ojk.go.id/
APPENDIX
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY (OJK) NUMBER 16/SEOJK.07/2025 REGARDING IMPLEMENTATION OF ANTI-MONEY LAUNDERING, COUNTER-TERRORISM FINANCING, AND COUNTER-PROLIFERATION FINANCING PROGRAMS FOR DIGITAL FINANCIAL ASSET TRADERS
A. LIKELIHOOD AND IMPACT MATRIX
In conducting risk identification, one of the tools that can be used by Traders is the likelihood and impact matrix. This matrix helps Traders determine the extent of efforts or monitoring that need to be carried out to identify inherent risks. It should be noted that this matrix is only an example. Traders can use other tools or other forms of matrices that are appropriate to the scale of business, needs, characteristics, and complexity of the Traders' business activities so that it truly reflects the risks faced by the Traders.
Likelihood
Likelihood refers to the potential for money laundering and terrorism financing risks to occur for each specific risk assessed.
In this regard, Traders can use commonly used risk scales, namely:
Risk Rating for TPPU, TPPT, and PPPSPM Likelihood High High probability of TPPU, TPPT, and PPPSPM risks occurring Medium Probability of risk occurrence is acceptable Low No probability of risk occurrence
Impact
Impact in this context refers to the level of seriousness or consequences of damage or loss that occurs if a risk occurs.
The emergence of impact depends on the internal conditions of the Traders. The impact of TPPU, TPPT, and PPPSPM risks can be viewed from various perspectives, including:
a. reputational risk and its impact on the Traders' business activities; b. regulatory impact;
c. financial losses for the Traders; and/or
d. legal risk.
The impact of TPPU, TPPT, and PPPSPM risks will be very specific for each Trader, making it difficult to calculate the impact. Therefore, only the Traders can determine the impact of the risks that occur.
The scale used to calculate impact is not much different from the scale in calculating likelihood.
Consequence Rating for TPPU, TPPT, and PPSPM Risks High Risks have heavy consequences Medium Risks have moderate consequences Low Risks have small or insignificant consequences.
The likelihood and impact matrix will help Traders decide what needs to be done by considering the overall risk. As mentioned earlier, the risk-based approach is a process that allows Traders to implement steps commensurate with identified risks as part of risk assessment.
Likelihood and Impact Matrix
Each box in the matrix indicates the resources needed to perform:
B. EXAMPLES OF RISK LEVELS ASSOCIATED WITH TRADER ACTIVITIES a. As an example, the following table presents several examples of risk factors that Traders may face as part of the risk assessment related to Trader business activities. The table also outlines the rational reasons that can help Traders differentiate each risk level. b. Traders may decide on the risk scale used by the Trader. This Guideline does not require Traders to determine high, medium, and low risk scales. Traders may use only high and low scales according to the business activity, needs, and complexity of the Trader.
EXAMPLE RISK LEVEL TABLE
FACTOR
RISK LEVEL
LOW MEDIUM HIGH
Customer Profile
Identified and verified customer profile has low potential for engaging in ML/TF/CPF Customer requires further verification to ensure the customer is not involved in ML/TF/CPF Customer meets criteria associated with engaging in ML/TF/CPF
Digital Financial Asset Distribution Network
Digital Financial Asset distribution network is conducted via electronic medium meeting at least: cybersecurity maturity test showing level 5, transparent, traceable, cybersecurity in accordance with best practices, data encryption, personal data protection, consumer protection, and licensed according to statutory regulations. Digital Financial Asset distribution network is conducted via electronic medium that is still transparent and traceable, but cybersecurity maturity test shows level 4 or below. Digital Financial Asset distribution network allows increased anonymity and obscures traceability, thereby complicating the identification of ML/TF/CPF.
Digital Financial Asset Products or Services
Digital Financial Asset Products or Services are in accordance with the crypto asset list and have product/activity/service licenses.
Digital Financial Asset Products or Services have characteristics that have the potential to be exploited by ML/TF/CPF perpetrators.
Digital Financial Asset Products or Services allow increased anonymity, reduced transparency, and obscure financial flows.
Geography of High-Risk Countries
Trader does not have business relations with high-risk country customers.
Customer or Trader partner is located in a geographic area/border area that has the potential for ML/TF/CPF.
Trader has high-frequency business relations and significant transaction values with high-risk countries.
C. EXAMPLE FORMAT FOR CUSTOMER DATA UPDATE PLAN REPORT
CUSTOMER DATA UPDATE PLAN REPORT
(TRADER NAME)
YEAR ……
No.
Customer Type and Risk Level
Number of Single Customer Identification Files Information to be Updated Method or Strategy Target Fulfillment Percentage Single Customer Identification Files to be Updated in a Specific Period Single Customer Identification Files to be Updated % of Total Single Customer Identification Files
(a) (b) (c) (d) (e) (f) (g)
State Institutions, Government Agencies, International Institutions, and Foreign State Representatives
a. High Risk b. Medium Risk
c. Low Risk
Column Notes:
(a) Filled with number.
(b) According to column.
(c) Filled with the planned number to be updated for the next 1 (one) year.
(d) Filled in percentage.
(e) Information can be filled with more than one, such as updating residential address or work address.
(f) Method or strategy can be filled with more than one, such as correspondence via mail or email.
(g) Filled with the target fulfillment percentage of single customer identification file updates in a specific period. The period is determined by adjusting to the ability and conditions of each Trader, for example, quarterly. Example: Quarter I = 30%, Quarter II = 60%, Quarter III = 90%, Quarter IV = 100%.
The number of risk levels can be adjusted according to policies established by the Trader.
D. EXAMPLE FORMAT FOR CUSTOMER DATA UPDATE REALIZATION REPORT
CUSTOMER DATA UPDATE REALIZATION REPORT
(TRADER NAME)
YEAR ……
No.
Customer Type and Risk Level
Development
Obstacles
Efforts to be Made
Target
Realization
Deviation (%)
(a) (b) (c) (d) (e) (f) (g)
State Institutions, Government Agencies, International Institutions, and Foreign State Representatives
a. High Risk b. Medium Risk
c. Low Risk
Column Notes:
(a) Filled with number.
(b) According to column.
(c) Filled with the target number of single customer identification files to be updated.
(d) Filled with the realized number of single customer identification files to be updated.
(e) Filled with the percentage difference between the target single customer identification files to be updated (c) and (d) realized single customer identification files to be updated.
(f) Obstacles can be filled with more than one.
(g) Filled with efforts to overcome obstacles and can be filled with more than one.
The number of risk levels can be adjusted according to policies established by the Trader.
E. EXAMPLE CRITERIA FOR SUSPICIOUS FINANCIAL TRANSACTIONS
A. GENERAL
B. CRITERIA FOR SUSPICIOUS DIGITAL FINANCIAL ASSET TRANSACTIONS
F. EXAMPLE FORMAT FOR ACTION PLAN AND POLICIES AND PROCEDURES
ACTION PLAN AND POLICIES AND PROCEDURES
(TRADER NAME)
DATE : ……
TRADER AML/CFT/CPF PROGRAM ACTION PLAN
Item
Action
Things to be Done
Required Resources
Person in Charge
Start Date
Deadline
Expected Performance Results
Supervisory Issues
Board of Directors and Board of Commissioners
Internal control
Information systems
Human resource management and training
POLICIES AND PROCEDURES
Policies and Procedures
Things to be Done
Required Resources
Person in Charge
Start Date
Deadline
Expected Performance Results
Supervisory Issues
Identification and verification of prospective Customers or Customers Identification and verification of Beneficial Owners - Closure of business relations or rejection of transactions Travel Rule Sustainable ML, TF, and CPF risk management related to Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels); Maintenance of accurate data related to transactions, documentation of the CDD process, and documentation of policies and procedures for updating and monitoring Reporting to senior officials, Board of Directors, and Board of Commissioners regarding the implementation of AML, CFT, and CPF program policies and procedures
This copy is in accordance with the original
Head of Legal Development Directorate
Legal Department signed
Aat Windradi
Issued in Jakarta on July 3, 2025
EXECUTIVE HEAD OF THE FINANCIAL SECTOR TECHNOLOGY INNOVATION SUPERVISOR, DIGITAL FINANCIAL ASSETS AND CRYPTO ASSETS FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA,
HASAN FAWZI signed
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works