You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 11, 2020

Cambodia’s New Law on Anti-Money Laundering

Cambodia’s new Anti-Money Laundering and Combating the Financing of Terrorism Law (the “2020 AML/CFT Law”) came into force in June 2020, abrogating the 2007 law of the same name and the accompanying sub-decree from 2013.

The 2020 AML/CFT Law differs in three major ways from the 2007 law: (1) more specific definitions, (2) a requirement for reporting entities to introduce enhanced due diligence measures, and (3) increased penalties for non-compliance.

Altered Definitions of Legal Terms

The 2020 version of the law has changed several definitions to lend further clarity and increase the scope of the law:

  • “Financing of Terrorism” is expanded by the addition of a list of examples of actions that could qualify as terrorism financing, including traveling or training with the intent to aid terrorists.
  • “Politically Exposed Persons” is broadened to include local officials (in addition to foreign officials) and “international politically exposed persons,” or prominent individuals in an international organization. In practice this means that reporting entities will now be required to monitor these persons’ transactions.
  • “Ultimate Beneficial Owner” is expanded to include any person who exercises ultimate effective control over a legal person through shares or voting rights.

Reporting Entities and Customer Due Diligence

Trustees have been added as a category of reporting entity, in keeping with the Law on Trusts which went into effect in early 2019. Otherwise, the comprehensive list of reporting entities is largely the same as in the 2007 law.

Reporting entities must deploy enhanced customer due diligence (CDD) measures, as more types of transactions and business relationships have been classified as high risk. This also applies retroactively, and must be conducted on existing customers who newly fall into the “high risk” category. Enhanced due diligence measures may include obtaining additional information on:

  • the customers’ identification;
  • the source of funds;
  • the purpose of the transaction; and
  • the intended nature of the business relationship.

Additional ongoing customer monitoring procedures may also be required.

If a reporting entity believes that carrying out these additional CDD measures will result in a particular customer becoming aware of the entity’s suspicions of them, the entity is allowed to cease conducting the measures and must report the customer and the activity that led to the initial suspicions to the Cambodia Financial Intelligence Unit (CAFIU).

The list of activities for which a reporting entity must apply enhanced CDD measures has been expanded to include:

  • business relations and transactions with institutions or persons in jurisdictions that have a high risk of money laundering or financing of terrorism;
  • business relations and transactions with foreign politically exposed persons and their family members and close associates;
  • business relations and transactions with international politically exposed persons, Cambodian politically exposed persons, and their family members and close associates, but only in response to a transaction that is identified as “high risk”; and,
  • all other business relations or transactions that could be identified as having a high risk of being associated with money laundering and/or financing of terrorism.

Penalties

Penalties for legal entities found to be in violation of the 2020 AML/CFT Law include warnings, fines, revocation of business licenses, and the removal of managers or officers from their positions, applied in addition to applicable sanctions under the Criminal Code. In general, the penalties outlined in the new law introduce higher fines and longer prison terms than were previously imposed under the 2007 Law and its subsequent amendments.

Previously, for example, legal entities deemed criminally responsible for money laundering were subject to a maximum fine of KHR 500 million (approx. USD 122,000), in addition to other sanctions under the Criminal Code. The maximum is doubled under the new law, to KHR 1 billion (approx. USD 244,000). Other offenses, such as money laundering by natural persons, various noncompliant activities, breach of confidentiality, and financing of terrorism are similarly expanded.

RELATED INSIGHTS​ 

April 28, 2026
Thailand’s Anti-Corruption Cooperation Committee has issued a major update to the anticorruption standards required for private entities engaging in high-value state projects. The update, titled “Announcement re: Procurement Limits and Minimum Anticorruption Standards (No. 2),” replaces and amends key provisions of the original announcement dated September 25, 2024. Published in the Government Gazette on April 10, 2026, the new rules take effect on May 10, 2026, and apply to projects valued at more than THB 300 million (approximately USD 9.3 million). The key amendments to the anticorruption standards are detailed below. Expanded Definition of Conflict of Interest The 2026 regulation significantly broadens the scope of what constitutes a conflict of interest compared to the 2024 version, which focused primarily on basic kinship and business ties. Under the new rules, a conflict of interest includes using one’s position or authority to seek benefits for oneself, a group, close associates, or business, including through business relationships, kinship ties, or relationships with spouses or individuals living together as partners without marriage registration. The 2026 announcement also introduces specific examples that were largely absent from the 2024 text, such as holding shares in similar businesses that submit proposals for the same project, or submitting proposals for projects in which a relative, spouse, or unregistered partner is an “involved party” in that procurement. Continuous Compliance: The “Final Payment” Rule Under the 2024 rules, the coverage period for anticorruption policies was less strictly defined. The new regulation mandates a continuous timeline: policies or certifications must remain effective from the date of bid submission until the contractor receives the final payment installment under the contract. If a certification or policy is set to expire before the final payment, the contractor must submit a new self-audit form and supporting evidence to the state agency before the original
March 5, 2026
Amid increasing financial globalization, Vietnam’s establishment of an International Financial Center (IFC) represents a strategic initiative to attract high-quality foreign investment and enhance the country’s position in the global financial system. In support of this objective, a Specialized Court was introduced under Resolution No. 222/2025/QH15 as a dedicated dispute resolution mechanism within the IFC framework. The Specialized Court at the IFC was subsequently operationalized by Law on the Specialized Court No. 150/2025/QH15, effective from January 1, 2026. Organizational Structure of the Specialized Court The Specialized Court at the IFC is a court within the system of the People’s Courts, organized and operating in accordance with the Law on the Specialized Court, and vested with jurisdiction to adjudicate and resolve cases at the IFC. The Specialized Court is located in Ho Chi Minh City and comprises (i) a Court of First Instance; (ii) a Court of Appeal, and (iii) a supporting apparatus. Jurisdiction of the Specialized Court The jurisdiction of the Specialized Court at the IFC is strictly defined based on both (i) the subject matter of the cases and (ii) the membership status of the parties involved. Specifically, the Specialized Court has jurisdiction over (except for cases involving public interests or the interests of the state) the following: Disputes arising from investment and business activities. Requests for recognition and enforcement in Vietnam of judgments and decisions of foreign courts and foreign arbitral awards. Requests related to dispute resolution by arbitration. Other disputes directly related to investment and business activities (to be specified by the Supreme People’s Court). Additionally, at least one party in the case must be a member of the IFC. The IFC’s membership status is established through registration, recognition as a member, or the grant of a license for establishment and operation within the IFC. In the
February 27, 2026
The Bank of Thailand (BOT) has officially implemented a new regulatory framework supervising systemically important retail payment systems (SIRPS), effective February 21, 2026, with PromptPay being the first payment system designated as a SIRPS. Under this new set of regulations, the BOT may designate payment systems under the Payment Systems Act B.E. 2560 (2017) as SIRPSs based on quantitative and qualitative assessments. Once a system is designated as a SIRPS, the operator becomes subject to expanded supervisory obligations beyond the general requirements of the Payment Systems Act. Enhanced Supervisory Requirements SIRPS operators must comply with a heightened supervisory regime across three key areas, outlined below. 1. Governance SIRPS operators must maintain robust and transparent governance structures, including: Balanced board composition, with at least one-third of the board comprising independent directors who represent stakeholders in the system (such as payment service providers, consumers, and experts). Independent directors may serve for no more than two consecutive terms. Subcommittees to assist the board in overseeing compliance, policy implementation, and operational strategy. Clear separation between executives responsible for risk and information security and those overseeing day-to-day business operations. Risk Management and System SecuritySIRPS operators must implement comprehensive risk management frameworks, including: Clear service agreements between the SIRPS operator and its direct participants (payment service providers who connect directly to the SIRPS), defining roles and responsibilities among stakeholders. These agreements must include obligations for direct SIRPS participants to supervise any indirect participants they onboard to ensure compliance with service agreements and business rules. A business continuity plan covering both IT and non-IT aspects, with annual review. The SIRPS must target service availability comparable to international payment infrastructures, including the ability to recover operations within two hours of a disruption and to maintain scalable operational capacity. Tools and controls to monitor and manage material or
February 9, 2026
When unauthorized credit card transactions occur, who bears responsibility—the cardholder or the issuing bank? In Thailand, a landmark 2025 ruling by the country’s Supreme Court has clarified this question, establishing a stricter standard for banks in fraud disputes and significantly strengthening consumer protections. The case centered on disputed charges where a customer claimed their credit card had been used without authorization. The bank sued to recover the amount, and both the court of first instance and the Court of Appeal ruled in favor of the bank. However, the Supreme Court overruled their judgments and decided that the customer did not need to pay for the unauthorized transactions, placing liability squarely on the bank. This ruling was based on three key findings, which are outlined below. Finding 1: Insufficient Expert Testimony In this case, the bank bore the burden of proving matters related to the credit card system’s manufacture, design, security, and operation, as required under the Consumer Case Procedure Act B.E. 2551 (2008). To meet this requirement, the bank presented testimony from two employees in its credit card department regarding ’security measures and issuance procedures. However, the Supreme Court found these witnesses unqualified as experts, as they did not present technical or academic evidence and did not possess specialized expertise in credit card technology. As a result, their testimony failed to establish that the bank’s credit card technology was sufficiently secure against fraudulent misuse. Finding 2: Contradictory Terms and Conditions The bank’s own credit card terms and conditions included a provision acknowledging that despite the card’s EMV security standards, cardholders must still exercise caution to prevent unauthorized access. The Supreme Court interpreted this clause as an explicit admission that credit card systems remain vulnerable to hacking and fraud, even with high-level security measures in place. This acknowledgment undermined the