You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 11, 2020

Cambodia’s New Law on Anti-Money Laundering

Cambodia’s new Anti-Money Laundering and Combating the Financing of Terrorism Law (the “2020 AML/CFT Law”) came into force in June 2020, abrogating the 2007 law of the same name and the accompanying sub-decree from 2013.

The 2020 AML/CFT Law differs in three major ways from the 2007 law: (1) more specific definitions, (2) a requirement for reporting entities to introduce enhanced due diligence measures, and (3) increased penalties for non-compliance.

Altered Definitions of Legal Terms

The 2020 version of the law has changed several definitions to lend further clarity and increase the scope of the law:

  • “Financing of Terrorism” is expanded by the addition of a list of examples of actions that could qualify as terrorism financing, including traveling or training with the intent to aid terrorists.
  • “Politically Exposed Persons” is broadened to include local officials (in addition to foreign officials) and “international politically exposed persons,” or prominent individuals in an international organization. In practice this means that reporting entities will now be required to monitor these persons’ transactions.
  • “Ultimate Beneficial Owner” is expanded to include any person who exercises ultimate effective control over a legal person through shares or voting rights.

Reporting Entities and Customer Due Diligence

Trustees have been added as a category of reporting entity, in keeping with the Law on Trusts which went into effect in early 2019. Otherwise, the comprehensive list of reporting entities is largely the same as in the 2007 law.

Reporting entities must deploy enhanced customer due diligence (CDD) measures, as more types of transactions and business relationships have been classified as high risk. This also applies retroactively, and must be conducted on existing customers who newly fall into the “high risk” category. Enhanced due diligence measures may include obtaining additional information on:

  • the customers’ identification;
  • the source of funds;
  • the purpose of the transaction; and
  • the intended nature of the business relationship.

Additional ongoing customer monitoring procedures may also be required.

If a reporting entity believes that carrying out these additional CDD measures will result in a particular customer becoming aware of the entity’s suspicions of them, the entity is allowed to cease conducting the measures and must report the customer and the activity that led to the initial suspicions to the Cambodia Financial Intelligence Unit (CAFIU).

The list of activities for which a reporting entity must apply enhanced CDD measures has been expanded to include:

  • business relations and transactions with institutions or persons in jurisdictions that have a high risk of money laundering or financing of terrorism;
  • business relations and transactions with foreign politically exposed persons and their family members and close associates;
  • business relations and transactions with international politically exposed persons, Cambodian politically exposed persons, and their family members and close associates, but only in response to a transaction that is identified as “high risk”; and,
  • all other business relations or transactions that could be identified as having a high risk of being associated with money laundering and/or financing of terrorism.

Penalties

Penalties for legal entities found to be in violation of the 2020 AML/CFT Law include warnings, fines, revocation of business licenses, and the removal of managers or officers from their positions, applied in addition to applicable sanctions under the Criminal Code. In general, the penalties outlined in the new law introduce higher fines and longer prison terms than were previously imposed under the 2007 Law and its subsequent amendments.

Previously, for example, legal entities deemed criminally responsible for money laundering were subject to a maximum fine of KHR 500 million (approx. USD 122,000), in addition to other sanctions under the Criminal Code. The maximum is doubled under the new law, to KHR 1 billion (approx. USD 244,000). Other offenses, such as money laundering by natural persons, various noncompliant activities, breach of confidentiality, and financing of terrorism are similarly expanded.

RELATED INSIGHTS​ 

January 30, 2025
The Thai cabinet has approved a draft amendment of the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes as proposed by the Ministry of Digital Economy and Society to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Following the Council of State’s review, the emergency decree will be become effective immediately upon its enactment and publication in the Government Gazette. While the draft amendment is not yet publicly available, the government recently indicated that the emergency decree aims to empower authorities with decisive measures to combat cybercrime effectively. It underscores the shared responsibility among various sectors, including banking, telecommunications, and online platforms, in safeguarding against technological crimes. Key provisions of the draft amendment of the emergency decree include: Telecommunications provider obligations: Telecommunications service providers must suspend SIM cards associated with criminal activities. The National Broadcasting and Telecommunications Commission and mobile service providers themselves are authorized to temporarily suspend mobile phone numbers if there is reasonable suspicion of involvement in criminal activities. Banking responsibilities: Financial institutions are required to promptly report mule accounts to the Anti-Money Laundering Office to facilitate quick restitution to victims. The Anti-Money Laundering Transaction Committee is empowered to order the return of funds to victims without requiring a final court ruling. Penalties for noncompliance: The amended emergency decree introduces penalties for noncompliance by regulated entities that fail to prevent criminal activities for offenses related to technology crimes in the following cases: Digital asset services: Those engaged in the buying, selling, or exchanging of digital assets, such as cryptocurrencies and digital tokens, as well as digital asset businesses that launder money obtained from online crimes by converting it into digital currency, will be subject to imprisonment for up to one year, a fine of up to THB 100,000,
January 22, 2025
Tasked with implementing the Politburo’s policy outlined in Notice No. 47-TB/TW dated November 15, 2024, the prime minister of Vietnam issued Decision No. 1718/QD-TTg on December 31, 2024, appointing himself as the head of a steering committee dedicated to the establishment of an international financial center in Ho Chi Minh City and a regional financial center in Da Nang by 2025. The Ministry of Planning and Investment has subsequently drafted an outline for the National Assembly’s Resolution on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Resolution”). This Draft Resolution introduces two key policy groups: (i) policies governing the quantity, location, structure, organization, functions, and responsibilities of the financial centers; and (ii) policies applicable to various areas and matters within the financial centers. Notably, under the Draft Resolution, fintech has been identified as a key sector, with a specific focus on the implementation of a “controlled sandbox” policy for business models involving virtual assets and cryptocurrencies. Under this framework, transactions related to virtual assets and cryptocurrencies will be permitted from July 1, 2026, subject to licensing, management, impact assessment, and risk oversight by the financial centers’ Management and Operations Committee. Scope of Application and Key Principles The Draft Resolution applies to a wide range of stakeholders, including investors, regulatory agencies, organizations, and individuals involved in the establishment, organization, and operation of regional and international financial centers in Vietnam. These financial centers will have clearly defined geographical boundaries and specific locations, which will be further specified and detailed by the People’s Committees of Ho Chi Minh City and Da Nang. Companies successfully registered as members of these financial centers will benefit from special investor-friendly policy principles, which may differ from the general legal and regulatory framework applicable in other parts of Vietnam. Most notably, the state will
January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for
January 10, 2025
Project finance specialists from Tilleke & Gibbins’ Bangkok office have once again contributed the Thailand chapter to the latest edition of The Legal 500’s Project Finance guide. Part of The Legal 500’s Country Comparative Guides series, the publication serves as a valuable resource for investors and businesses seeking detailed insights into project finance in key jurisdictions worldwide. Each Q&A-style chapter offers comprehensive guidance on the legal frameworks impacting various aspects of project finance, including: Ownership structures and corporate governance; Security interests, regimes, and enforcement; Regulatory requirements and consents; Foreign exchange considerations; Environmental, social, and governance (ESG) issues; Public-private partnerships; Foreign judgments; Tax considerations; Common funding structures; and Insurance law principles. In addition to the Thailand chapter, Tilleke & Gibbins has contributed the Vietnam chapter to the guide. The Thailand chapter is available as a PDF through the link below. The full guide can also be accessed for free on The Legal 500 website.