You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 22, 2020

An Analysis of Cambodia’s New Law on Anti-Money Laundering

OneTrust DataGuidance

On 27 June 2020, Cambodia issued the new Law on Anti-Money Laundering and Combating the Financing of Terrorism (‘the 2020 AML/CFT Law’), that abrogates both the 2007 law of the same name and the 2013 sub-decree that accompanied the former law. All other laws relevant to AML will remain in effect. Jay Cohen, Sochanmalisphoung Vannavuth, and Robin Spiess, of Tilleke & Gibbins International Ltd., provide an overview of the 2020 AML/CFT Law, and how it differs from the 2007 in areas such as definitions and penalities.

The 2020 AML/CFT Law, comprised of nine chapters and 47 articles, aims to further prevent and combat money laundering and terrorist financing in Cambodia by increasing both the scope of the law’s reach and general deterrence measures.

In many ways identical to its predecessor, the 2020 AML/CFT Law differs in three major ways from the 2007 law. Firstly, it provides more specific definitions for terms used throughout the law. Secondly, it requires reporting entities to introduce enhanced due diligence measures in order to maintain compliance. And thirdly, it introduces increased penalties for non-compliance with the law. The changes to the 2020 AML/CFT Law are discussed further below.

Altered definitions of legal terms

The 2020 AML/CFT Law has changed several definitions to lend further clarity in the application, and increase the scope, of the law.

Financing of terrorism

The scope of the definition of ‘financing of terrorism’ has been expanded. The first half of the definition remains the same: ‘the willful provision of financial or other services with the intention that such services be used, or in the knowledge that they may be used, in full or in part, for the purpose of supporting terrorism, terrorist acts or terrorist organisations.’ However, the 2020 AML/CFT Law adds a list of examples of actions that could qualify as the financing of terrorism, including traveling or training with the intent to aid terrorists, as well as participating in or carrying out an act of terrorism.

Ultimate beneficial owner

The definition of an ‘ultimate beneficial owner’ has also been expanded. The first half of the definition remains the same: ‘a person who ultimately owns or controls a customer on whose behalf a transaction is being conducted, including those persons who exercise ultimate effective control over a legal person or arrangement.’ Additionally, the AML/CFT Law stipulates that if the ‘customer’ being controlled is a legal entity, then an ultimate beneficial owner also includes any person who exercises ultimate effective control over a legal person, through the holding of shares or voting rights. It is the duty of the reporting entity to determine who the ultimate beneficial owner is in any given situation, in accordance with the Cambodia Financial Intelligence Unit (‘CAFIU’) guidelines.

Further, the 2020 AML/CFT Law notes that, if CAFIU is unable to determine who holds the most shares or exercises the greatest voting rights, CAFIU will employ the use of ‘other means’ to determine who the ultimate beneficial owner is, though these means are not defined. The law does note that, when a reporting entity is required to identify its ultimate beneficial owner, the highest-ranking person in the organisation will qualify as such.

Politically exposed persons

Notably, the definition of ‘politically exposed persons’ has been broadened to include both local and foreign officials. Previously defined as ‘any individual who is or has been entrusted with prominent public functions in a foreign country,’ the scope of the definition has been extended to include those ‘entrusted with prominent public functions in Cambodia’ as well. In keeping with the 2007 law, the AML/CFT Law provides examples of politically exposed persons that include heads of state or government, senior politicians, senior government officials, judicial or military officials, senior executives of state-owned corporations, and important party officials.

So too has the 2020 AML/CFT Law added a third category of politically exposed persons: the ‘international politically exposed person,’ which is defined as any individual who has been entrusted with prominent public functions in an international organisation. Further clarity as to what qualifies as an ‘international organisation’ is not provided in the law. Examples of such prominence within an international organisation include membership of the senior management team, the Board of Directors, or other similar groups within the organisation.

This change ensures that reporting entities, which were previously not required to monitor Cambodian officials’ or international organisation members’ business activities, are now required to ‘pay special attention’ to transactions conducted by these politically exposed persons.

Adding to the list of reporting entities

In large part, the comprehensive list of ‘reporting entities’ outlined in the 2007 law remain the same in the 2020 AML/CFT Law: banks, financial institutions, brokerage firms, insurance companies, micro-finance institutions, credit cooperatives, leasing companies, investment funds and companies, exchange offices, money remittance services, real estate agents, dealers in precious metals and gems, post offices dealing in transactions, lawyers, notaries, accountants, auditors, investment advisors, asset managers, casinos and gambling institutions, non-government organisations, and foundations engaging in business activities and fundraising are all classified as reporting entities. Additionally, the catch-all provision that ‘any other institutions or professions designated by the CAFIU to fall within the scope of the law’ is included in both the 2020 AML/CFT Law and the 2007 version.

In keeping with the Law on Trusts, which went into effect on 2 January 2019 and provided the first legal means by which trusts could be established in Cambodia, the 2020 AML/CFT Law has added ‘trustees’ as a new category of reporting entities.

Customer due diligence measures

Reporting entities have long been required by law, both under the 2020 AML/CFT Law and the 2007 version, to exercise due diligence in their activities, including requesting and retaining specific information about customers. Under the 2020 AML/CFT Law, the burden on reporting entities has been increased, as more types of transactions and business relationships have been classified as ‘high risk.’ Reporting entities must thus deploy enhanced customer due diligence (‘CDD’) measures in a broader range of situations than was previously necessary. The provisions outlined in the 2020 AML/CFT Law apply to new and existing customers alike and reporting entities are expected to retroactively conduct enhanced due diligence on those customers who newly fall into the ‘high risk’ category.

Generally, where the risk of money laundering and terrorism of financing is deemed ‘high,’ reporting entities must take enhanced CDD measures in keeping with CAFIU guidelines. These enhanced CDD measures may include:

  • obtaining additional information on the customers’ identification;
  • obtaining information on the source of funds;
  • obtaining information on the transaction purpose;
  • obtaining information on the intended nature of the business relationship; and
  • carrying out additional ongoing monitoring procedures on customers’ activities.

Under the 2020 AML/CFT Law, if a reporting entity believes that carrying out these additional CDD measures will result in a particular customer becoming aware of the entity’s suspicions of him or her, the entity is allowed to cease conducting these enhanced measures. However, the entity must report the customer and any activity that led to its initial suspicions to the CAFIU.

Under both the 2020 AML/CFT Law, as well as the 2007 law, a reporting entity must apply enhanced CDD measures when handling:

  • any complex, unusual, or large transactions;
  • any transactions that follow unusual patterns and/or are not obviously driven by an economic or lawful purpose;
  • business relations and transactions with institutions or persons in jurisdictions that have insufficient systems to prevent or deter money laundering or financing of terrorism;
  • wire transfers that do not contain the originator’s information;
  • business relations and transactions with persons with whom the reporting entity has had no face-to-face contact during the implementation of identification procedure;
  • business relations and transactions with politically exposed persons; and
  • business relations and transactions conducted by means of cross-border correspondent banking or other similar relationships.

However, this list has been expanded upon in the 2020 AML/CFT Law. In addition to the above relations and transactions, the 2020 AML/CFT Law requires the reporting entity to additionally conduct enhanced CDD measures on:

  • business relations and transactions with institutions or persons in jurisdictions that have a high risk of money laundering and/or financing terrorism;
  • all business relations and transactions with ‘foreign politically exposed persons,’ as well as the family members and close associates of these exposed persons;
  • business relations and transactions with international politically exposed persons and Cambodian politically exposed persons, as well as the family members and close associates of these exposed persons, but only in response to a transaction that is identified as high risk; and
  • any and all other business relations or transactions that could be identified as having a high risk of being associated with money laundering and/or financing of terrorism.

Identical to its predecessor, the 2020 AML/CFT law requires reporting entities to report large cash transactions and other suspicious transactions that exceed the threshold established by the CAFIU. If a reporting entity has reasonable grounds to believe that these large transactions are the proceeds of some offence or are connected to the financing of terrorism, the entity must report the transaction within 24 hours.

New penalties

Penalties for legal entities found to be in violation of the 2020 AML/CFT Law include warnings, fines, revocation of business licenses, and the removal of managers or officers from their positions. In general, the penalties outlined in the new law introduce higher fines and longer prison terms than were previously imposed under the 2007 law and its subsequent amendments.

Previously, for example, legal entities deemed criminally responsible for money laundering were subject to a maximum of KHR 500,000,000 (approx. $122,700) in fines, in addition to other sanctions under the Criminal Code of the Kingdom of Cambodia (‘the Criminal Code’). The penalty has now been doubled under the 2020 AML/CFT Law, with legal entities committing money-laundering crimes subject to up to KHR 1,000,000,000 (approx. $245,500) in fines. While natural persons who committed money-laundering crimes were previously subject to imprisonment of at most one year, these individuals are now subject to imprisonment from two to five years and an increased fine of between KHR 100,000,000 and KHR 500,000,000 (approx. $24,500 to $122,700).

A summary of the penalties prescribed in the 2020 AML/CFT Law are outlined below:

This article was originally published on the OneTrust DataGuidance website, and is republished here with permission and thanks.

RELATED INSIGHTS​ 

March 5, 2026
Amid increasing financial globalization, Vietnam’s establishment of an International Financial Center (IFC) represents a strategic initiative to attract high-quality foreign investment and enhance the country’s position in the global financial system. In support of this objective, a Specialized Court was introduced under Resolution No. 222/2025/QH15 as a dedicated dispute resolution mechanism within the IFC framework. The Specialized Court at the IFC was subsequently operationalized by Law on the Specialized Court No. 150/2025/QH15, effective from January 1, 2026. Organizational Structure of the Specialized Court The Specialized Court at the IFC is a court within the system of the People’s Courts, organized and operating in accordance with the Law on the Specialized Court, and vested with jurisdiction to adjudicate and resolve cases at the IFC. The Specialized Court is located in Ho Chi Minh City and comprises (i) a Court of First Instance; (ii) a Court of Appeal, and (iii) a supporting apparatus. Jurisdiction of the Specialized Court The jurisdiction of the Specialized Court at the IFC is strictly defined based on both (i) the subject matter of the cases and (ii) the membership status of the parties involved. Specifically, the Specialized Court has jurisdiction over (except for cases involving public interests or the interests of the state) the following: Disputes arising from investment and business activities. Requests for recognition and enforcement in Vietnam of judgments and decisions of foreign courts and foreign arbitral awards. Requests related to dispute resolution by arbitration. Other disputes directly related to investment and business activities (to be specified by the Supreme People’s Court). Additionally, at least one party in the case must be a member of the IFC. The IFC’s membership status is established through registration, recognition as a member, or the grant of a license for establishment and operation within the IFC. In the
February 27, 2026
The Bank of Thailand (BOT) has officially implemented a new regulatory framework supervising systemically important retail payment systems (SIRPS), effective February 21, 2026, with PromptPay being the first payment system designated as a SIRPS. Under this new set of regulations, the BOT may designate payment systems under the Payment Systems Act B.E. 2560 (2017) as SIRPSs based on quantitative and qualitative assessments. Once a system is designated as a SIRPS, the operator becomes subject to expanded supervisory obligations beyond the general requirements of the Payment Systems Act. Enhanced Supervisory Requirements SIRPS operators must comply with a heightened supervisory regime across three key areas, outlined below. 1. Governance SIRPS operators must maintain robust and transparent governance structures, including: Balanced board composition, with at least one-third of the board comprising independent directors who represent stakeholders in the system (such as payment service providers, consumers, and experts). Independent directors may serve for no more than two consecutive terms. Subcommittees to assist the board in overseeing compliance, policy implementation, and operational strategy. Clear separation between executives responsible for risk and information security and those overseeing day-to-day business operations. Risk Management and System SecuritySIRPS operators must implement comprehensive risk management frameworks, including: Clear service agreements between the SIRPS operator and its direct participants (payment service providers who connect directly to the SIRPS), defining roles and responsibilities among stakeholders. These agreements must include obligations for direct SIRPS participants to supervise any indirect participants they onboard to ensure compliance with service agreements and business rules. A business continuity plan covering both IT and non-IT aspects, with annual review. The SIRPS must target service availability comparable to international payment infrastructures, including the ability to recover operations within two hours of a disruption and to maintain scalable operational capacity. Tools and controls to monitor and manage material or
February 9, 2026
When unauthorized credit card transactions occur, who bears responsibility—the cardholder or the issuing bank? In Thailand, a landmark 2025 ruling by the country’s Supreme Court has clarified this question, establishing a stricter standard for banks in fraud disputes and significantly strengthening consumer protections. The case centered on disputed charges where a customer claimed their credit card had been used without authorization. The bank sued to recover the amount, and both the court of first instance and the Court of Appeal ruled in favor of the bank. However, the Supreme Court overruled their judgments and decided that the customer did not need to pay for the unauthorized transactions, placing liability squarely on the bank. This ruling was based on three key findings, which are outlined below. Finding 1: Insufficient Expert Testimony In this case, the bank bore the burden of proving matters related to the credit card system’s manufacture, design, security, and operation, as required under the Consumer Case Procedure Act B.E. 2551 (2008). To meet this requirement, the bank presented testimony from two employees in its credit card department regarding ’security measures and issuance procedures. However, the Supreme Court found these witnesses unqualified as experts, as they did not present technical or academic evidence and did not possess specialized expertise in credit card technology. As a result, their testimony failed to establish that the bank’s credit card technology was sufficiently secure against fraudulent misuse. Finding 2: Contradictory Terms and Conditions The bank’s own credit card terms and conditions included a provision acknowledging that despite the card’s EMV security standards, cardholders must still exercise caution to prevent unauthorized access. The Supreme Court interpreted this clause as an explicit admission that credit card systems remain vulnerable to hacking and fraud, even with high-level security measures in place. This acknowledgment undermined the
February 4, 2026
On November 18, 2025, Vietnam’s Ministry of Finance released for public consultation a draft decree on administrative sanctions in the field of crypto assets and crypto asset markets (the “Draft Decree”), intended to implement Resolution No. 05/2025/NQ-CP dated September 9, 2025, on the pilot crypto asset market in Vietnam (“Resolution 05”). While Resolution 05 sets out who may participate and under what conditions, the Draft Decree addresses a more practical question for market participants, i.e., what happens if those conditions are not met. In doing so, the Draft Decree offers important insight into how Vietnamese regulators intend to supervise, discipline, and ultimately shape the crypto market during the pilot phase. Regulatory Scope and Overall Sanctions Architecture The Draft Decree applies to both domestic and foreign organizations and individuals engaging in crypto-related activities in Vietnam’s market. Covered entities include: (i) crypto asset issuers; (ii) crypto asset service providers, including trading platforms and market operators; (iii) Vietnamese and foreign investors participating in the pilot market; and (iv) other organizations involved in the offering, issuance, or provision of crypto-related services in Vietnam. The breadth of this scope is deliberate. It appears to reflect a regulatory view that cross-border structures, offshore platforms, and indirect participation may not necessarily insulate market actors from compliance obligations once they operate within the pilot framework. For the crypto industry, this may mark a shift from regulatory ambiguity toward a more explicit articulation of jurisdictional reach. At first glance, the Draft Decree’s monetary penalties appear restrained. The maximum fine per administrative violation is capped at VND 200 million (approx. USD 7,700) for organizations and VND 100 million (approx. USD 3,800) for individuals. However, focusing solely on fine levels risks missing the point. The Draft Decree also places great regulatory weight on supplementary sanctions and corrective measures, including: (i)