You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 11, 2020

Cambodia’s New Law on Anti-Money Laundering

Cambodia’s new Anti-Money Laundering and Combating the Financing of Terrorism Law (the “2020 AML/CFT Law”) came into force in June 2020, abrogating the 2007 law of the same name and the accompanying sub-decree from 2013.

The 2020 AML/CFT Law differs in three major ways from the 2007 law: (1) more specific definitions, (2) a requirement for reporting entities to introduce enhanced due diligence measures, and (3) increased penalties for non-compliance.

Altered Definitions of Legal Terms

The 2020 version of the law has changed several definitions to lend further clarity and increase the scope of the law:

  • “Financing of Terrorism” is expanded by the addition of a list of examples of actions that could qualify as terrorism financing, including traveling or training with the intent to aid terrorists.
  • “Politically Exposed Persons” is broadened to include local officials (in addition to foreign officials) and “international politically exposed persons,” or prominent individuals in an international organization. In practice this means that reporting entities will now be required to monitor these persons’ transactions.
  • “Ultimate Beneficial Owner” is expanded to include any person who exercises ultimate effective control over a legal person through shares or voting rights.

Reporting Entities and Customer Due Diligence

Trustees have been added as a category of reporting entity, in keeping with the Law on Trusts which went into effect in early 2019. Otherwise, the comprehensive list of reporting entities is largely the same as in the 2007 law.

Reporting entities must deploy enhanced customer due diligence (CDD) measures, as more types of transactions and business relationships have been classified as high risk. This also applies retroactively, and must be conducted on existing customers who newly fall into the “high risk” category. Enhanced due diligence measures may include obtaining additional information on:

  • the customers’ identification;
  • the source of funds;
  • the purpose of the transaction; and
  • the intended nature of the business relationship.

Additional ongoing customer monitoring procedures may also be required.

If a reporting entity believes that carrying out these additional CDD measures will result in a particular customer becoming aware of the entity’s suspicions of them, the entity is allowed to cease conducting the measures and must report the customer and the activity that led to the initial suspicions to the Cambodia Financial Intelligence Unit (CAFIU).

The list of activities for which a reporting entity must apply enhanced CDD measures has been expanded to include:

  • business relations and transactions with institutions or persons in jurisdictions that have a high risk of money laundering or financing of terrorism;
  • business relations and transactions with foreign politically exposed persons and their family members and close associates;
  • business relations and transactions with international politically exposed persons, Cambodian politically exposed persons, and their family members and close associates, but only in response to a transaction that is identified as “high risk”; and,
  • all other business relations or transactions that could be identified as having a high risk of being associated with money laundering and/or financing of terrorism.

Penalties

Penalties for legal entities found to be in violation of the 2020 AML/CFT Law include warnings, fines, revocation of business licenses, and the removal of managers or officers from their positions, applied in addition to applicable sanctions under the Criminal Code. In general, the penalties outlined in the new law introduce higher fines and longer prison terms than were previously imposed under the 2007 Law and its subsequent amendments.

Previously, for example, legal entities deemed criminally responsible for money laundering were subject to a maximum fine of KHR 500 million (approx. USD 122,000), in addition to other sanctions under the Criminal Code. The maximum is doubled under the new law, to KHR 1 billion (approx. USD 244,000). Other offenses, such as money laundering by natural persons, various noncompliant activities, breach of confidentiality, and financing of terrorism are similarly expanded.

RELATED INSIGHTS​ 

December 3, 2025
Recent high-profile corporate fraud and accounting scandals have brought increased scrutiny to governance, compliance, and enforcement practices in Thailand, highlighting the legal and practical challenges facing companies operating in the country. As regulators and law enforcement authorities sharpen their focus on financial misconduct, cybercrime, and corruption, businesses must navigate a complex and evolving investigative landscape. Tilleke & Gibbins’ investigations and compliance team examines these issues in the Thailand chapter of The Practitioner’s Guide to Global Investigations – Tenth Edition, published by Global Investigations Review (GIR). The chapter provides a detailed overview of Thailand’s legal framework for corporate investigations, offering practical guidance for companies and counsel responding to regulatory and criminal scrutiny. The Thailand chapter covers key topics including corporate criminal liability, enforcement priorities, internal investigations, data protection considerations, dawn raids, whistleblowing, cyber-related investigations, and cross-border cooperation. It also addresses emerging issues such as cybersecurity enforcement, economic sanctions compliance, and anticipated developments affecting investigations in Thailand. The chapter is authored by John Frangos, Chitchai Punsan, Alongkorn Tongmee, Michael Ramirez, Piyawat Vitooraporn, and Michelle McLeod. The Thailand chapter is available as a PDF below, and the full guide can be accessed on the GIR website.
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.