Compliance Hub

eKYC in Malaysia: Bank Negara Malaysia's Requirements for Digital Banks and E-Wallets

Site Logo
Tookitaki
03 Aug 2026
6 min
read

In 2022, Bank Negara Malaysia awarded digital bank licences to five applicants: GXBank, Boost Bank, AEON Bank, KAF Digital, and Zicht. None of these institutions have a branch network. For them, remote identity verification is not a product feature — it is the only way they can onboard a customer at all.

BNM's e-KYC framework sets the standard those institutions, and a much broader group of licensed entities, must meet. The current policy document is BNM/RH/PD 030-16, issued on 15 April 2024. It supersedes the e-KYC policy document issued on 30 June 2020 and is the version BNM examiners assess compliance against today.

This guide covers what the April 2024 policy document requires, how the verification components fit together, what BNM expects from liveness detection, and what the ring fencing requirements mean for product design.

Talk to an Expert

Who the policy document applies to

BNM's e-KYC policy document applies to a range of supervised institutions:

  • Licensed banks and Islamic banks
  • Development financial institutions
  • E-money issuers operating under the Financial Services Act 2013, including major operators such as Touch 'n Go eWallet, GrabPay, and Boost
  • Money service businesses
  • Payment Services Operators licensed under the Payment Systems Act 2003

The overriding standard in the policy document is that e-KYC must achieve the same level of identity assurance as face-to-face verification. That is the benchmark BNM examiners use when reviewing whether a remote onboarding programme is compliant.

The three components of e-KYC identity verification

Section G 8.10 of the policy document sets out how institutions must verify the identity of individual customers remotely. BNM specifies three components that work together:

Document verification. The institution ensures the customer's government-issued identity document — their National Registration Identity Card (NRIC), passport, or other official document — is authentic, using appropriate fraud detection mechanisms.

Biometric matching. The institution verifies the customer against their government-issued ID using biometric technology. In practice, this means comparing a selfie or live image captured during the onboarding session against the photograph on the identity document.

Liveness detection. The institution confirms that the person submitting the identity is a live subject and not an impersonator using a photograph, recorded video, or synthetic face mask. Liveness detection addresses the limitation of biometric matching alone: a static photograph of the document holder held in front of a camera can defeat facial matching without a liveness check.

All three components work together. Document verification confirms the ID is genuine. Biometric matching confirms the customer matches the ID. Liveness detection confirms the customer is present in person. An e-KYC programme that uses biometric matching without liveness detection does not meet BNM's standard.

Authentication factors

Alongside identity verification, Section S 8.7 and G 8.8 set out the authentication factors institutions must apply. BNM recognises three categories:

  • Something the customer possesses: a national identity document, registered mobile number, or, for legal persons, a certificate of incorporation
  • Something the customer knows: a PIN, personal information, or transaction history
  • Something the customer is: biometric characteristics — applicable to individual customers only

For higher-risk products — current accounts, savings accounts, and unrestricted investment accounts — Appendix 4 requires an additional step: a credit transfer to demonstrate that the customer holds an existing account with another licensed financial institution. This step confirms the customer's identity through an established banking relationship and is required in addition to the three verification components above.

The unbanked pathway and ringfencing

Not all customers onboarding through digital banks or e-wallets have an existing bank account. BNM's policy document provides a separate pathway for these customers, with restrictions that reflect the higher identity risk.

Customers who cannot complete the credit transfer step are given access to a ringfenced account. During a period of at least twelve months from account opening, the account must:

  • Not have fund transfer capabilities to accounts held in the same customer's name
  • Not permit cross-border wire transfers
  • Operate with lower account size and fund transfer limits

After twelve months, an institution may remove the ring fencing restrictions if it has observed sufficient account activity and assessed that the account is genuine. Alternatively, the customer may visit a branch for physical identity verification to lift the restrictions earlier.

This means product decisions about account access are also compliance decisions. An institution that grants a customer who completed only the unbanked pathway full account functionality before the twelve-month period ends, or without a branch visit, is operating outside the regulatory framework.

ec1fee7b-906e-47e5-9d6c-ddfc283f9edf

Liveness detection: the FAR standard

BNM's requirements for liveness detection are set out in Section S 8.21 and detailed in Appendix 2. The standard is framed around the False Acceptance Rate (FAR): the rate at which the liveness detection system incorrectly accepts a spoof attempt.

BNM's Appendix 2, Table 1 sets out three performance levels:

997bbfb5-d334-47df-8dea-b8fb503e2c6b

BNM explicitly encourages institutions to strive for a FAR as close to zero as possible. The policy document also states that if a FAR above 5% persists and the Board has not effectively undertaken rectification, enforcement action may follow.

The FAR measurement requirement applies to e-KYC solutions that use AI, machine learning, or predictive algorithms. It does not apply to solutions where verification is fully automated without those techniques.

Minimum sample size for FAR measurement is the higher of: 400 cases per month, or a sample sufficient to achieve a 95% confidence level with a 3% margin of error.

BNM references two international standards for liveness and facial recognition compliance:

  • ISO 19794-5 for facial recognition
  • ISO 30107-3 for presentation attack detection (liveness testing)

Vendors used for liveness detection must be on BNM's approved list. A technically capable vendor that is not on that list does not produce a compliant e-KYC programme.

Record-keeping requirements

BNM requires all e-KYC sessions to be recorded and retained for a minimum of six years. Records must include:

  • Raw images or video from the verification session
  • Facial match confidence scores
  • Liveness detection scores
  • Verification timestamps
  • The outcome of the verification: approved, rejected, or referred for manual review

During AML/CFT examinations, BNM examiners review e-KYC session logs. An institution that can demonstrate a successful biometric match but cannot produce the underlying scores and timestamps for that session has a documentation failure, not a technical one. This is one of the more consistent findings in Malaysian e-KYC examinations.

e-KYC within the broader AML/CFT programme

A compliant e-KYC onboarding process does not discharge an institution's AML/CFT obligations for the full customer lifecycle. BNM's AML/CFT Policy Document — separate from the e-KYC Policy Document — requires continuous risk-based customer due diligence.

Two areas create friction in e-KYC-based operations:

High-risk customers require Enhanced Due Diligence that e-KYC cannot complete. A customer who is a Politically Exposed Person, operates in a high-risk jurisdiction, or presents unusual transaction patterns requires EDD. Source of funds verification for these customers cannot be completed through biometric verification alone. Institutions must document when an e-KYC-onboarded customer triggers the EDD workflow and must enforce those rules in practice.

Dormant account reactivation is a re-verification trigger. BNM expects institutions to treat the reactivation of an account dormant for twelve months or more as an event requiring re-verification. Many institutions have onboarding e-KYC workflows but no corresponding process for dormant accounts. This is a recurring examination gap.

Integrating e-KYC assurance levels into transaction monitoring calibration is also good practice. A ringfenced account that begins transacting at volumes exceeding its intended product tier is exactly the pattern that should generate an alert. See our transaction monitoring software buyer's guide for what to look for in a system capable of handling this kind of integrated logic.

Common implementation gaps

Four gaps appear most frequently in Malaysian e-KYC examinations:

1. Incomplete verification — missing one of the three required components. Institutions that deploy biometric matching without liveness detection, or document verification without biometric matching, do not meet the Section G 8.10 standard. All three components are required for individual customer onboarding.

2. No FAR measurement or documentation. An institution that has deployed a liveness detection system but cannot demonstrate to BNM that it measures and monitors FAR — with documented figures and sample sizes meeting the Appendix 2 requirements — does not have a defensible liveness programme. The technology alone is not sufficient.

3. Liveness detection vendor not on BNM's approved list. BNM maintains an approved vendor list. An institution using a vendor not on that list, regardless of the vendor's global credentials, needs to remediate.

4. No re-verification trigger for dormant account reactivation. Institutions that built their e-KYC programme around the onboarding workflow and never implemented re-verification logic for dormant accounts have a gap that BNM examiners will find.

What a compliant e-KYC programme in Malaysia includes

A programme compliant with BNM/RH/PD 030-16 has the following elements working together:

  1. All three verification components — document verification, biometric matching, and liveness detection — implemented with a BNM-approved vendor
  2. The credit transfer step for higher-risk product accounts (current, savings, unrestricted investment)
  3. Ringfencing controls for customers who cannot complete the credit transfer, enforced for a minimum of twelve months
  4. FAR monitoring at or above BNM's minimum sample requirements, with documented performance against the three-level threshold in Appendix 2
  5. Complete session records — images, scores, timestamps, and outcomes — retained for the full six-year period
  6. EDD triggers documented and enforced for high-risk customer categories
  7. Re-verification workflows for dormant accounts reactivating after twelve months of inactivity

Meeting all seven is not a one-time project. BNM expects periodic vendor performance validation, regular review of FAR calibration, and documented sign-off from a named senior officer on the state of the e-KYC programme.

For Malaysian institutions building or reviewing their e-KYC programme, FinCense combines e-KYC verification with transaction monitoring and ongoing customer risk assessment in an integrated environment designed for the requirements BNM examiners actually check. For broader AML/CFT obligations for BNM-licensed fintechs and PSPs, see our AML compliance guide for Malaysian fintechs. Book a demo to see how it works in a Malaysian digital bank or e-money context.

Talk to an Expert

Ready to Streamline Your Anti-Financial Crime Compliance?

Our Thought Leadership Guides

Blogs
31 Aug 2026
5 min
read

From Telegram Chats to Money Trails: The AML Risk Behind Penang’s Love-Scam Bust

Explore AML lessons from Penang’s love-scam bust, where Telegram-enabled deception exposed mule account, cross-border and money trail risks.

From Telegram Chats to Money Trails: The AML Risk Behind Penang’s Love-Scam Bust
Blogs
31 Aug 2026
5 min
read

Fraud Prevention in New Zealand: What Banks and Financial Institutions Need to Know in 2026

New Zealand banks reported NZD 194 million in scam losses in 2023-24. Investment fraud drove over NZD 100 million of those losses. This guide covers the regulatory framework, the new Banking Code scam protections, and what a fraud programme needs to address in the current environment.

Fraud Prevention in New Zealand: What Banks and Financial Institutions Need to Know in 2026
Blogs
28 Aug 2026
5 min
read

Fraud Prevention for Philippine Banks: AFASA, BSP Requirements and What They Mean in Practice

Understand how AFASA and BSP Circulars 1213-1215 reshape fraud prevention for Philippine banks, including real-time monitoring, stronger authentication, customer controls, disputed-fund holds and coordinated verification.

Fraud Prevention for Philippine Banks: AFASA, BSP Requirements and What They Mean in Practice