Listen To Our Podcast🎧

What will you learn?
A Kuwait AML/CFT programme has to satisfy more than one audience. The Capital Markets Authority (CMA) supervises licensed securities firms. The Central Bank of Kuwait (CBK) sets instructions for banks and other entities under its remit. The Kuwait Financial Intelligence Unit (KwFIU) receives and analyses suspicious transaction reports. Law No. 106 of 2013 and its executive regulation provide the common legal base, while sector instructions turn that base into operating duties.
For an MLRO or compliance officer, the practical job is to connect those layers. A policy that quotes the law but does not define who owns customer risk, who files an STR, or what evidence goes to the board will fail in operation. The same is true of a control that works in a bank but is copied into a CMA-licensed firm without checking the applicable module and circulars.
This guide explains the control structure a regulated firm should build. It is operational guidance, not legal advice. Confirm the latest Arabic legal text, sector rules, licence conditions and regulator communications with qualified Kuwaiti counsel before changing policy or filing a report.
- Connect Law No. 106, CMA, CBK and KwFIU duties.
- Build a written business-wide risk assessment.
- Link CDD, monitoring and reporting.
- Prepare replayable evidence for human decisions.
Request a Kuwait AML control review

The Map, Translate, Test, Evidence, Escalate framework
Map the rule, translate it into controls, test operation, preserve evidence and escalate to the authorised person.
- Map the entity, licence and rule set.
- Translate requirements into controls and owners.
- Test ordinary, high-risk and failed-data cases.
- Preserve evidence and escalate to the authorised person.
Kuwait AML/CFT compliance connects Law No. 106 of 2013 with sector rules from the CMA or CBK and reporting duties to the KwFIU.
What will you learn?
- How Law No. 106 of 2013, the CMA, the CBK and the KwFIU fit together
- What belongs in a written business-wide risk assessment
- How customer due diligence, enhanced due diligence and monitoring should connect
- What changes when suspicion is formed
- Which records make a decision defensible during inspection
- How to assign work to analysts and AI agents without moving regulated decisions away from accountable people
Review your Kuwait AML control map
Start with one product, one customer type and one reporting path. Map the legal source, regulator instruction, control owner, evidence produced and human approval point. Talk to us about Kuwait AML requirements if you want to review how that evidence can be assembled for an MLRO or compliance officer.
The Map, Translate, Test, Evidence, Escalate model
A workable Kuwait AML/CFT programme can be organised into five stages.
- The source, control, test and evidence are connected before an authorised person decides.
Source context: https://www.kwfiu.gov.kw/en/lawsAndCercuilar; https://www.cma.gov.kw/en/web/cma/cma-board-releases/resolutions-and-regulations/-/cmaboardreleases/detail/1694750; https://www.cbk.gov.kw/en/images/section-16-2751_v70_tcm10-2751.pdf
- Map. Identify the legal entity, licence, regulator and applicable rule set.
- Translate. Convert each requirement into a named policy, workflow, owner and system control.
- Test. Check whether the control works across ordinary, high-risk and failed-data cases.
- Evidence. Preserve the source, inputs, review history, exceptions and approval record.
- Escalate. Route suspicion, control failures and unresolved risk to the authorised person without delay.
The applicable rule set moves into a named control. The control is tested, the test produces an evidence record, and unresolved risk moves to the authorised person.
This is an editorial operating model. It does not replace the text of Kuwaiti law or a regulator's instructions.
Who sets AML/CFT requirements in Kuwait?
Law No. 106 of 2013 is the common statutory base for financial institutions and designated non-financial businesses and professions. The KwFIU legal-reference page identifies the law and its amendments as the primary legal basis, together with Ministerial Resolution No. 37 of 2013 and the decision establishing the Unit.
Law No. 106 defines supervisory authorities to include the CBK and the CMA. Those authorities issue sector rules, inspect regulated firms and can impose measures within their mandates. The law establishes the KwFIU as a separate body and assigns it the role of receiving, requesting, analysing and disseminating information related to suspected proceeds of crime or funds linked to money laundering or terrorist financing. The KwFIU manuals page publishes reporting material for regulated entities.
A firm should therefore maintain a three-layer obligations register:
| Layer | What to record | Control question |
|---|---|---|
| Law and executive regulation | Statutory duty, scope, threshold and record period | What must the regulated entity do? |
| Sector instruction | CMA module, CBK instruction, circular or licence-specific direction | How does the supervisor expect the duty to operate? |
| KwFIU reporting material | Current form, guidance, channel and data fields | How must suspicion be reported and evidenced? |
Do not merge those layers into one vague statement such as "comply with Kuwait AML law." Each layer needs a source, owner, last-review date and implementation record.
The FluxForce jurisdictions library is a useful starting point for the wider jurisdiction map. The primary legal and regulatory materials still control.
What does the CMA expect from licensed persons?
CMA-licensed persons should begin with Module Sixteen of the Executive Bylaws and the circulars that update or explain how the Authority expects controls to operate. The CMA's July 2025 business-risk circular says firms under its supervision must conduct a systematic assessment of money laundering, terrorist financing and proliferation-financing risks connected to their activities, client base, products and services. It also says the assessment will be followed up during inspections.
That makes the business-wide risk assessment an operating document, not a compliance appendix. It should influence customer risk methods, enhanced due diligence, monitoring scenarios, approval levels, staffing, testing and remediation.
The assessment should answer at least these questions:
- Which products can move or hold value, and how could each be abused?
- Which customer types create ownership, agency, nominee or source-of-wealth risk?
- Which countries, corridors and counterparties change the firm's exposure?
- Which delivery channels reduce face-to-face evidence or increase impersonation risk?
- Which transactions are difficult to explain using the customer's stated purpose?
- Which control failures have appeared in quality review, audit, incidents or regulator feedback?
- What residual risk remains after current controls?
- Who accepted that residual risk and when will the decision be revisited?
A score without an explanation is weak evidence. Keep the underlying data, assumptions, weighting changes, meeting record and action plan. If the institution changes products, customer mix, delivery method or geographic exposure, the assessment should be reviewed before the annual cycle if the change is material.
The annual CMA AML/CFT report
CMA Circular No. 16 of 2022 points licensed persons to Article 7-5 of Module Sixteen. It requires the compliance officer to prepare an annual report for the board on implementation of AML/CFT policies, procedures and controls, including proposals to improve effectiveness. A board-approved copy is submitted to the CMA between January 1 and March 1 each year.
Treat that report as the end product of a year-long evidence process. Waiting until January to collect policy approvals, training records, alert statistics, risk-assessment changes, audit findings and overdue actions creates avoidable gaps.
A monthly evidence pack can make the annual report easier to defend:
- changes to laws, circulars and internal policy;
- customer-risk and enhanced-due-diligence volumes;
- alerts, investigations, STR decisions and filing timeliness;
- monitoring-rule changes and validation results;
- sanctions or high-risk-country control changes;
- training completion and competence testing;
- audit, compliance testing and remediation status; and
- material exceptions accepted by senior management or the board.
Recent enforcement also shows that Module Sixteen is active rather than archival. On May 20, 2026, the CMA announced two fines against a securities company for procedural breaches of Articles 3-15 and 6-1 of the module. The announcement does not establish that every breach will produce the same outcome. It does show why firms need article-level control mapping and evidence.
What does the CBK expect from banks?
The CBK's published AML/CFT instructions require board-approved policies, a risk-based programme, customer and beneficial-owner controls, monitoring, reporting, record keeping, training, compliance oversight and independent testing. The English material is provided for information, and the Arabic legal version controls where stated by the CBK.
The board should not receive a policy once and disappear from the process. It needs management information that shows whether the programme is operating, where exceptions are building, and whether remediation is on time.
The CBK instructions place the compliance officer at senior-management level and require ongoing training for staff, directors and management. They also make the bank responsible when it relies on a third party for elements of due diligence.
That last point matters when identity verification, screening, data enrichment or transaction monitoring uses an external provider. Outsourcing a task does not outsource the bank's accountability. The bank should be able to retrieve the information, understand the provider's limitations, test the control and obtain supporting documents without delay under the CBK's third-party due-diligence requirements.
Enforcement information should reach governance bodies
In May 2025, the CBK said it would publish summaries of penalties imposed on supervised entities. The same statement reported 356 penalties under Article 15 of Law No. 106 of 2013 since the law was issued, including 180 written warnings and 176 financial penalties.
That number is a historical total reported by the CBK, not a forecast of enforcement against any particular firm. Its governance lesson is simple: AML/CFT issues need a route to the board as well as the operations queue.
The FluxForce regulations library can help teams organise the wider regulatory inventory. It should not be treated as a substitute for the CBK's own instructions.
What does the KwFIU expect?
The KwFIU publishes laws, circulars and reporting manuals. Its current circular page includes high-risk-country circulars issued in 2025 and 2026, so a static country list copied into a policy will become stale.
A firm needs a controlled update process:
- monitor the official KwFIU circular page;
- record the circular, publication date and affected control;
- assess customer, transaction and correspondent exposure;
- update screening, due diligence or approval rules where required;
- document effective date and testing; and
- report unresolved implementation issues to the control owner.
The KwFIU manuals page also provides an STR completion guide and separate guidance notes for banks and exchange companies. The correct reporting workflow therefore depends on sector as well as the general law.
What belongs in the business-wide risk assessment?
Article 4 of Law No. 106 requires financial institutions and designated non-financial businesses and professions to assess money-laundering and terrorist-financing risk, including risk from new products or technologies. The assessment and its underlying information must be written, current and available to the supervisor.
- The source, control, test and evidence are connected before an authorised person decides.
Source context: https://www.kwfiu.gov.kw/en/lawsAndCercuilar; https://www.cma.gov.kw/en/web/cma/cma-board-releases/resolutions-and-regulations/-/cmaboardreleases/detail/1694750; https://www.cbk.gov.kw/en/images/section-16-2751_v70_tcm10-2751.pdf
The executive regulation breaks the assessment into customers, countries or geographic areas, products and services, and delivery channels. It also says the assessment should be documented, kept current and periodically reviewed.
A useful risk assessment separates inherent risk, control effectiveness and residual risk.
| Component | Evidence | Common failure |
|---|---|---|
| Inherent exposure | Customer mix, products, geography, channels, transaction profile | Scores copied from a generic template |
| Control design | Policy, system rule, approval level, source hierarchy | Control listed without explaining the risk it treats |
| Operating effectiveness | Sample results, alert quality, QA, audit, exceptions | Design assumed to work because a policy exists |
| Residual risk | Reasoned conclusion after controls | One unexplained red, amber or green rating |
| Action plan | Owner, date, dependency and success test | Open action with no measurable closure condition |
Inherent exposure informs control design. Operating effectiveness tests the control, those results support the residual-risk assessment, and the action plan assigns an owner.
Include proliferation-financing exposure where the applicable regulator expects it. The CMA's 2025 supervisory guidance explicitly refers to money laundering, terrorist financing and proliferation financing.
The assessment should also show how risk findings change the control environment. If a customer segment is rated higher risk but receives the same due diligence, monitoring and approval as a lower-risk segment, the risk methodology is not doing useful work.
How should customer due diligence operate?
Law No. 106 requires identification and verification of the customer and beneficial owner using reliable, independent source documents, data or information. It also requires the firm to understand the purpose and intended nature of the relationship and to monitor that relationship on an ongoing basis.
The file should distinguish:
- the customer;
- the natural person who ultimately owns or controls the customer;
- the person acting on the customer's behalf;
- the purpose of the relationship;
- expected activity; and
- the evidence used to verify each material fact.
For legal entities, the executive regulation requires evidence beyond a commercial licence. The firm still needs to understand ownership, control, authority and expected use. For natural persons, the identification document does not explain source of funds, source of wealth or the purpose of unusual activity.
Do not compress all evidence into a single "KYC complete" flag. Record whether a fact is verified, supported but not independently verified, or unresolved. The reviewer then has a clearer basis for deciding whether to proceed, ask for more information, restrict the relationship or reject it.
When is enhanced due diligence needed?
Enhanced due diligence applies where risk is higher. The executive regulation gives examples such as obtaining more information about the customer, the intended relationship, source of funds or source of wealth, and increasing the degree and nature of monitoring.
For politically exposed persons, the regulation calls for risk-management systems that identify whether the customer or beneficial owner is a PEP. Under the executive regulation, foreign PEP relationships require senior-management approval, reasonable measures to identify source of wealth and funds, and enhanced ongoing monitoring.
A firm should define what enhanced due diligence changes in practice. A label without extra work is not a control.
Possible changes include:
- a higher approval level;
- more independent ownership evidence;
- source-of-wealth and source-of-funds testing;
- a shorter review cycle;
- narrower product access;
- lower manual-review thresholds; or
- more detailed transaction expectations.
The decision record should explain why those measures are proportionate to the risk. It should also state what evidence would allow the relationship to return to ordinary review.
What should ongoing monitoring detect?
Monitoring should compare actual activity with the customer profile and expected purpose. It should also respond to changes in ownership, control, occupation, business model, geography, sanctions exposure and adverse information.
The point is not to generate the largest alert queue. It is to surface activity that needs explanation and give the analyst enough context to test that explanation.
A decision-ready alert should show:
- the relevant customer and account history;
- the event or pattern that triggered review;
- expected activity and the source of that expectation;
- connected parties and counterparties;
- prior alerts, decisions and unresolved issues;
- the analyst's evidence requests and findings; and
- the reason for closure, continued monitoring or escalation.
If a system can only show a rule name and a transaction list, the analyst has to rebuild the case manually. That increases delay and makes similar cases harder to compare.
Customer activity creates alert context. Alert context moves to the analyst investigation. The analyst investigation tests that context, the authorised person makes the suspicion decision, and a report moves to the KwFIU only when that human decision requires filing.
When should a suspicious transaction report be filed?
Article 12 of Law No. 106 requires reporting to the KwFIU without delay when a financial institution or designated non-financial business or profession suspects, or has reasonable grounds to suspect, that a transaction or attempted transaction involves criminal proceeds or funds related to money laundering or terrorist financing. The duty applies regardless of value.
- The source, control, test and evidence are connected before an authorised person decides.
Source context: https://www.kwfiu.gov.kw/en/lawsAndCercuilar; https://www.cma.gov.kw/en/web/cma/cma-board-releases/resolutions-and-regulations/-/cmaboardreleases/detail/1694750; https://www.cbk.gov.kw/en/images/section-16-2751_v70_tcm10-2751.pdf
The CBK instructions for banks state a maximum of two days for reporting a suspicious transaction or attempted transaction to the KwFIU after the relevant suspicion threshold is met. Firms should confirm the applicable sector rule and measure the internal clock from the correct event. Do not wait for certainty or for a criminal case to be proved.
The workflow should preserve two separate judgements:
- whether the alert or referral needs investigation; and
- whether the facts create suspicion or reasonable grounds for suspicion that require reporting.
A closing rationale such as "activity is normal" is too thin. The analyst should identify the evidence reviewed, explain the expected activity, address the red flags and state why the suspicion threshold was or was not met.
Law No. 106 prohibits tipping off, so those controls belong in the same workflow. Access to an STR decision, draft and filing confirmation should be limited to people who need it. Customer communication should follow approved procedures so the institution does not disclose that a report has been or may be filed.
What records must the firm preserve?
Law No. 106 sets a five-year baseline for several record categories. These include customer and beneficial-owner due-diligence records after the relationship ends, attempted and executed transaction records, copies of reports sent to the KwFIU and the underlying business risk assessment.
The records must be detailed enough to reconstruct the decision. A screenshot without source metadata is weaker than a record that includes the source, retrieval time, search terms, result, analyst action and approval.
Keep version history for:
- customer and beneficial-owner data;
- policy and risk-method changes;
- alert rules and thresholds;
- analyst notes and evidence;
- escalation and STR decisions;
- regulator submissions;
- board and committee review; and
- remediation testing.
Retention is not the same as usability. Test whether an independent reviewer can retrieve a case and understand what happened without asking the original analyst to explain it.
Illustrative scenario: a Kuwaiti investment firm reviews cross-border activity
Illustrative example, not a customer result or an allegation about a real firm.
- The source, control, test and evidence are connected before an authorised person decides.
Source context: https://www.kwfiu.gov.kw/en/lawsAndCercuilar; https://www.cma.gov.kw/en/web/cma/cma-board-releases/resolutions-and-regulations/-/cmaboardreleases/detail/1694750; https://www.cbk.gov.kw/en/images/section-16-2751_v70_tcm10-2751.pdf
A CMA-licensed investment firm accepts a corporate customer with regional shareholders. The expected profile records periodic investment subscriptions funded from the customer's operating account.
Several months later, the firm sees multiple third-party payments from entities in different jurisdictions, followed by quick redemptions to another account. The transaction value alone does not decide the case. The pattern conflicts with the recorded purpose and funding route.
An analyst reviews the ownership file, payment narrative, counterparties, prior activity and country risk. The file contains an old ownership chart and does not explain two of the remitters. The analyst requests current ownership and commercial evidence, records the customer's response and tests whether the transactions have a clear lawful purpose.
Cross-border payments lead the analyst to ownership evidence. An AI agent may organise those approved records into a case chronology for the compliance officer. The compliance officer makes the filing decision under the institution's authorised process.
The compliance officer applies the institution's escalation standard. If the facts meet the reporting threshold, the authorised person files through the approved KwFIU process. The case preserves the reason, evidence, filing record, access restrictions and any decision about the future relationship.
Who owns each part of the control architecture?
| Component | Responsibility | Boundary |
|---|---|---|
| Board | Approves policy and risk appetite; reviews programme performance | Does not replace daily compliance decisions |
| Senior management | Funds the programme and closes material weaknesses | Cannot treat unresolved risk as an operations issue only |
| MLRO or compliance officer | Owns escalation, reporting governance and regulator engagement | Must retain independent access and authority |
| Business and operations | Collect customer facts and follow approved procedures | Cannot close compliance concerns by commercial preference |
| Investigators | Test alerts, gather evidence and document rationale | Do not change policy thresholds case by case |
| Internal audit or independent testing | Tests design and operating effectiveness | Does not own remediation |
| Technology and data teams | Maintain data lineage, access, rules and change controls | Do not decide regulatory suspicion |
| External or AI provider | Performs contracted evidence or workflow tasks | The regulated firm keeps accountability |
Human control needs to be explicit. The authorised MLRO, compliance officer or delegated reviewer decides whether to escalate, file, restrict or close. The institution should be able to override recommendations, pause automated work and disable the workflow.
How FluxForce fits Kuwait AML operations
FluxForce connects this problem to Policy and Compliance Management. The agent extracts candidate requirements and control statements from an approved policy. The compliance team reviews the interpretation and decides which controls are implemented. Each approved control links back to the policy text and its review history.
AI agents that investigate AML, sanctions, fraud and KYC alerts and prepare the case. Your analyst makes the call, with evidence an examiner can replay. You decide how much each agent does on its own, and every one has a kill switch.
For a Kuwait programme, the institution can configure where the workflow stops for review, what evidence accompanies each candidate control and which changes need approval. The MLRO or compliance officer approves the interpretation and control change. Separate authorised processes govern investigation escalation and STR filing.
FluxForce does not provide Kuwaiti legal advice, determine that a policy is legally sufficient, guarantee regulator acceptance or file an STR without the institution's authorised human process. Source access, Arabic-text review, system integration and sector fit must be confirmed during assessment.
For a broader operating view, see the AML compliance guide.
Which controls should be tested before rollout?
A policy-management or monitoring change should be tested against more than a clean case.
- The source, control, test and evidence are connected before an authorised person decides.
Source context: https://www.kwfiu.gov.kw/en/lawsAndCercuilar; https://www.cma.gov.kw/en/web/cma/cma-board-releases/resolutions-and-regulations/-/cmaboardreleases/detail/1694750; https://www.cbk.gov.kw/en/images/section-16-2751_v70_tcm10-2751.pdf
- Use an ordinary customer with complete data.
- Use a customer with conflicting ownership records.
- Use a higher-risk country or PEP case.
- Use activity that is unusual but has a credible explanation.
- Use a case that crosses the suspicion threshold.
- Remove a required data field and confirm that the workflow stops.
- Change a source document and check whether the previous version remains available.
- Test a denied permission and a privileged override.
- Reconstruct the case from the audit record.
- Confirm that the authorised human can pause, return and reject the recommendation.
Observation mode is useful before operational reliance. Compare the workflow's prepared evidence with the work of experienced analysts, record gaps and adjust the process. Do not infer effectiveness from lower handling time alone.
Which metrics should management review?
| Metric | Definition | Guardrail |
|---|---|---|
| Risk-assessment action closure | Material actions closed by their approved date | Closure needs evidence and retesting |
| Customer-file defect rate | Sampled files missing a required material fact or source | Segment by customer and risk class |
| Alert evidence completeness | Cases containing the required customer, transaction and rationale evidence | Do not reward longer notes |
| Escalation age | Time from material red flag to authorised review | Measure paused time separately |
| STR decision timeliness | Time from formed suspicion to decision and filing | Use the correct sector deadline |
| Repeat-control failure rate | Findings that recur after remediation | Reopen actions that fail testing |
| Policy-to-control coverage | Applicable requirements mapped to an active control and owner | Sample the quality of the mapping |
| Board action ageing | Overdue AML/CFT actions assigned by the board or committee | Show risk, dependency and elapsed days |
Pair volume with quality. A fall in alerts may mean better targeting, missing data or a broken rule. A rise in STR filings may reflect better detection, a changed customer base or poor onboarding. Management needs the explanation alongside the number.
What should an MLRO ask a compliance-technology provider?
Ask the provider to show one requirement from source to final decision.
Useful questions include:
- Can the system separate law, regulator instructions and KwFIU guidance?
- Does every requirement retain its source, date and version?
- How are 2026 high-risk-country circulars detected and reviewed?
- Can the firm map one requirement to several controls and owners?
- What happens when an official source is unavailable or only the Arabic text is authoritative?
- Can analysts see why a case was escalated?
- Does the audit trail preserve edits, overrides and previous evidence?
- Which tasks require human approval?
- Can the institution set different workflows for CMA- and CBK-supervised entities?
- Can an authorised person stop the workflow immediately?
A provider should be candid about source coverage, translation, data latency and implementation work. Those limitations belong in the design review.
Illustrative Kuwait cross-border review workflow
Illustrative scenario, not a customer result.
A CMA-licensed firm investigates third-party payments that do not fit the recorded customer purpose.
- Review ownership and activity.
- Prepare a chronology.
- Route evidence to the compliance officer.
Who owns each part of the control architecture?
Governance, investigation, technology and decision authority are separated.
| Component | Responsibility | Boundary |
|---|---|---|
| Board | Approves policy and reviews programme performance. | Does not replace daily compliance decisions. |
| MLRO or compliance officer | Owns escalation and reporting governance. | Retains regulated decision authority. |
| AI or external provider | Prepares approved evidence and workflow tasks. | Does not decide suspicion or filing. |
The authorised MLRO, compliance officer or delegated reviewer decides whether to escalate, file, restrict or close.
Which sources support the Kuwait control design?
Common statutory and executive framework.
Confirm current Arabic legal text.
2026-10-05
Bank governance, CDD, monitoring and reporting controls.
Confirm applicable entity and Arabic legal text.
2026-10-05
How FluxForce fits Kuwait AML operations
Policy and Compliance Management extracts candidate requirements and control statements from an approved policy. The compliance team reviews the interpretation and decides which controls are implemented. Each approved control links back to the policy text and its review history.
AI agents that investigate AML, sanctions, fraud and KYC alerts and prepare the case. Your analyst makes the call, with evidence an examiner can replay. You decide how much each agent does on its own, and every one has a kill switch.
Review Kuwait AML requirementsFluxForce does not provide Kuwaiti legal advice, determine legal sufficiency, guarantee regulator acceptance or replace authorised human interpretation, escalation or filing decisions.
Kuwait AML/CFT rollout test checklist
- Test ordinary, high-risk and failed-data cases.
- Preserve source and version history.
- Confirm human pause, return and rejection controls.
| Metric | Definition | Decision guardrail |
|---|---|---|
| Policy-to-control coverage | Applicable requirements mapped to an active control and owner. | Sample mapping quality. |
| STR decision timeliness | Time from formed suspicion to decision and filing. | Use the correct sector deadline. |
- Map the exact regulator and rule set to each legal entity.
- Use the business-wide risk assessment to change controls.
- Preserve evidence from source through human decision.
- Keep escalation and filing authority with the authorised person.
Conclusion
Kuwait AML/CFT compliance is a connected control system. Law No. 106 creates the common duties. The CMA and CBK turn them into sector expectations. The KwFIU owns the reporting channel and publishes current circulars and guidance.
The practical standard is evidence. The official source supports a mapped control. The test result goes to human approval, and the board receives the resulting evidence and unresolved exceptions. A firm should be able to show which rule applies, how it changed the control, who reviewed the result, what exceptions remain and why an authorised person made the final decision.
Start with the business-wide risk assessment and one reporting path. If those cannot be reconstructed from source to board or STR decision, adding more alerts will not fix the programme.
Request a Kuwait AML control review

Frequently Asked Questions
No. The applicable supervisor depends on the entity and activity. CMA-licensed securities firms should follow the CMA framework, while banks and other entities under CBK supervision must follow the relevant CBK instructions. Law No. 106 and KwFIU reporting duties form part of the common framework.
The main statute is Law No. 106 of 2013 on anti-money laundering and combating the financing of terrorism, with amendments and an executive regulation issued under Ministerial Resolution No. 37 of 2013.
The CMA's 2025 circular says supervised units must conduct a systematic assessment of money-laundering, terrorist-financing and proliferation-financing risks associated with their activities, client base, products and services.
Law No. 106 says suspicious transactions and attempts should be reported to the KwFIU without delay when the suspicion threshold is met. The CBK instructions for banks state a maximum of two days.
Law No. 106 sets a five-year baseline for due-diligence records, transaction records, submitted reports and risk-assessment material, with different starting points for each category. A competent authority may require longer retention in a specific case.
No. The KwFIU circular page lists multiple 2025 and 2026 high-risk-country circulars. Firms need a controlled process to monitor changes and update affected controls.
An AI agent can prepare relevant evidence and the case for review. The authorised MLRO, compliance officer or delegated human applies the institution's legal and policy threshold and makes the filing decision.
About the author

Sahil Kataria
Founder and CEO of FluxForce
Sahil works on secure AI and financial technology for regulated industries. His engineering background spans identity verification, payment security and compliance automation. He has led teams across Africa, the United States, Europe and India.
At FluxForce.ai, his focus is on explainable AI and auditable financial workflows. He writes for banking and compliance teams about the practical decisions behind these systems: how to assess risk, keep controls visible and introduce automation without losing accountability.
View Sahil Kataria's author profile →Related articles
Jurisdiction overview.
Regulatory inventory.
Wider AML operating guidance.












Share this article