Deddy Rizaldy & Partners Law Firm
×
Regulatory Note

Financial Services   |   2 AUGUST 2026

Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023

Financial-service providers should operate an institution-specific anti-money-laundering and counter-terrorist-financing programme. Controls should be proportionate to customer, product, delivery, geographic, transaction, and proliferation-financing risks.

AuthorDRP Law

Executive Summary

REGULATORY NOTE | FINANCIAL SERVICES | 2 AUGUST 2026 Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023 Risk assessment, customer due diligence, beneficial ownership, monitoring, and governance EXECUTIVE Financial-service providers should operate an institution-specific SUMMARY anti-money-laundering and counter-terrorist-financing programme. Controls should be proportionate to customer, product, delivery, geographic, transaction, and proliferation-financing risks.

Background

Regulatory compliance should be translated into assigned controls, documented evidence, reporting calendars, and
escalation triggers. A licence or filing is most useful when the underlying operation remains consistent with the facts
represented to the authority.
Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023 should be approached as a connected legal,
factual, and decision-making problem. In the financial services context, the quality of the final position depends on
whether the governing instruments, authority records, chronology, correspondence, operational facts, and available
remedies are reviewed together. A conclusion reached from one document or one legal provision may overlook
qualifications, implementing rules, later conduct, or evidence that changes the practical assessment.
This publication therefore focuses on the sequence of analysis rather than offering a universal answer. The first task is
to define the relevant person, company, asset, permit, transaction, or government action. The second is to identify the
legal source and the institution or contractual actor with authority. The third is to test the position against
contemporaneous records and the procedure that governs any filing, objection, response, negotiation, investigation, or
claim.
For regulatory matters, formal approval and continuing compliance must be considered separately. A licence,
registration, certificate, filing, or system status does not by itself prove that the activity continues to satisfy its
conditions. Compliance should be translated into named control owners, source evidence, monitoring intervals,
reporting calendars, change-management triggers, and escalation routes. This makes the regulatory position capable of
being demonstrated during inspection, renewal, financing, transaction due diligence, or enforcement.
The analysis is current as at 2 August 2026. The application of any law, regulation, court decision, administrative
practice, or contractual provision depends on the specific facts and may change after publication.

Key Legal Issues

  • Enterprise and customer risk assessments should drive the intensity of due diligence and monitoring This issue defines the legal scope of the assessment.
  • Beneficial owners The point must be tested against contemporaneous evidence.
  • Politically exposed persons and higher-risk relationships require enhanced controls and approval Procedure and timing are central.
  • Monitoring scenarios The operational consequences should be assessed before a position is implemented.
  • Board and senior-management oversight should receive meaningful risk and control information The position should anticipate how an authority, court, counterparty, shareholder, complainant, or other stakeholder may respond.

Analysis

The principal authorities identified for this topic are listed below. They should be read together with any implementing
measures, sector-specific instruments, later amendments, binding court decisions, official guidance, contractual
provisions, corporate instruments, and transitional rules applicable to the matter. The legal hierarchy and the date on
which an instrument became effective may be decisive.
DEDDY RIZALDY & PARTNERS LAW FIRM 1
l
OJK Regulation No. 8 of 2023
Before relying on an authority, confirm that it applies to the relevant person, entity, activity, asset, transaction, location,
procedural stage, and period. Where an official system or institution maintains the operative record, the record should
be verified rather than inferred from an earlier submission. The scope of any discretion, appeal, objection, cure, or
review mechanism should also be mapped.
DEDDY RIZALDY & PARTNERS LAW FIRM 2

3.1 Enterprise and customer risk assessments should drive the intensity of due diligence and
monitoring
This issue defines the legal scope of the assessment. Counsel should identify who holds the relevant right, duty, power,
or exposure; the instrument from which it arises; and any limits on authority. The review should distinguish legal form
from actual conduct and should record inconsistencies rather than silently choosing one version. Authority can depend
on legislation, implementing rules, constitutional documents, delegations, contracts, licences, resolutions, or an
institution's procedural mandate.
For Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023, this point should be converted into a
compliance control: a responsible owner, required evidence, review frequency, system or filing dependency, approval
threshold, and escalation trigger. Management should be able to demonstrate both the formal regulatory status and the
operational facts supporting that status.
3.2 Beneficial owners
The point must be tested against contemporaneous evidence. Useful material may include executed documents, official
records, system data, correspondence, meeting minutes, reports, financial entries, technical records, witness
knowledge, and proof of delivery or submission. The legal team should identify the source, custodian, date,
completeness, and reliability of each record. Missing records and later-created summaries should be labelled so that
decision-makers understand the evidentiary limits.
For Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023, this point should be converted into a
compliance control: a responsible owner, required evidence, review frequency, system or filing dependency, approval
threshold, and escalation trigger. Management should be able to demonstrate both the formal regulatory status and the
operational facts supporting that status.
3.3 Politically exposed persons and higher-risk relationships require enhanced controls and
approval
Procedure and timing are central. The applicable framework may prescribe a form, authorised signatory, service
method, supporting document, cure opportunity, objection route, hearing sequence, or deadline. A substantively
reasonable position may still be weakened by using the wrong forum or failing to preserve a procedural step. A
calendar should distinguish statutory deadlines, contractual deadlines, internal approval dates, and practical milestones
for collecting evidence and preparing submissions.
For Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023, this point should be converted into a
compliance control: a responsible owner, required evidence, review frequency, system or filing dependency, approval
threshold, and escalation trigger. Management should be able to demonstrate both the formal regulatory status and the
operational facts supporting that status.
3.4 Monitoring scenarios
The operational consequences should be assessed before a position is implemented. Legal exposure can affect cash
flow, licences, financing, contractual performance, insurance, governance, personnel, public statements, and
relationships with authorities or counterparties. Scenario analysis should compare immediate action, conditional action,
negotiated adjustment, and preservation of the status quo. Each scenario should state its assumptions, dependencies,
reversible steps, and indicators that would require escalation.
For Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023, this point should be converted into a
compliance control: a responsible owner, required evidence, review frequency, system or filing dependency, approval
threshold, and escalation trigger. Management should be able to demonstrate both the formal regulatory status and the
operational facts supporting that status.
DEDDY RIZALDY & PARTNERS LAW FIRM 3
3.5 Board and senior-management oversight should receive meaningful risk and control
information
The position should anticipate how an authority, court, counterparty, shareholder, complainant, or other stakeholder
may respond. That includes testing the strongest counterargument, not only confirming the preferred interpretation.
Communications should be accurate, proportionate, and consistent across legal submissions, corporate records,
regulatory filings, and operational instructions. Where uncertainty remains, the decision record should explain the
chosen risk tolerance and the safeguards applied.
For Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023, this point should be converted into a
compliance control: a responsible owner, required evidence, review frequency, system or filing dependency, approval
threshold, and escalation trigger. Management should be able to demonstrate both the formal regulatory status and the
operational facts supporting that status.

Implications

The matrix is an initial organising tool. It should be replaced or supplemented by a matter-specific chronology,
document index, authority map, issue list, and risk register once the relevant records have been reviewed.
ISSUE KEY EVIDENCE RISK IF UNMANAGED IMMEDIATE CONTROL
Enterprise and customer Licences, registrations, corporate Regulatory status not matching the Confirm scope, authority, and
risk assessments should data, and delegated authority actual activity controlling instruments.
drive the intensity of due
diligence and monitoring
Beneficial owners Source records, system extracts, Inability to demonstrate compliance Issue preservation instructions
technical reports, and submissions during supervision and build an evidence index.
Politically exposed persons Approval dates, reporting Late or defective filing, renewal, Create a procedural map with
and higher-risk calendars, receipts, and regulator objection, or response verified dates and owners.
relationships require notices
enhanced controls and
approval
Monitoring scenarios Operational data, inspection Operational disruption, sanction, Quantify scenarios and assign
findings, incidents, and remediation transaction, or financing exposure continuity safeguards.
logs
Board and Management review, corrective Recurring gaps because ownership Test counterarguments and
senior-management action, and change-control records and escalation are unclear approve a communication
oversight should receive protocol.
meaningful risk and control
information

IMMEDIATE CONTROL Preserve the relevant record, identify the decision-maker and authority, confirm
procedural deadlines, and prevent avoidable escalation while the facts are verified.
LEGAL ASSESSMENT Map the verified facts and documents against the applicable legal framework,
contractual position, regulatory expectations, and realistic exposure scenarios.
STRATEGIC Select a proportionate course of action, define approval and communication protocols,
EXECUTION
document implementation, and revisit the strategy as new evidence or legal
developments emerge.
6.1 Questions for Decision-Makers
l
What precise decision, right, obligation, or exposure is being assessed in relation to financial-sector aml/cft controls
under ojk regulation no. 8 of 2023?
l
Which law, regulation, contract, licence, corporate instrument, or official decision controls the issue?
l
Which facts are verified by contemporaneous evidence, and which remain assumptions or disputed allegations?
l
What procedural step or deadline could determine whether a right, defence, approval, or remedy remains available?
l
What operational, financial, governance, regulatory, and reputation consequences arise under each realistic scenario?
l
Who is authorised to approve the strategy, communicate externally, implement controls, and monitor later
developments?
DEDDY RIZALDY & PARTNERS LAW FIRM 5

Practical Considerations / Next Steps

5.1 Refresh the institution-wide risk assessment and control mapping.
Begin by defining ownership of the task, the decision required, and the documents that must be available. Record any
assumptions and gaps so that later reviewers can distinguish confirmed facts from matters still under investigation. The
output should be a controlled work product with a clear approval path, not an informal collection of opinions.
5.2 Test onboarding, beneficial-ownership, and sanctions-screening files.
The work should reconcile legal requirements with the organisation's actual process and systems. Where records
conflict, identify the source of truth, the person responsible for correction, and whether a notification, amendment,
reservation of rights, or other protective step is required before the inconsistency becomes material.
5.3 Review monitoring scenarios and alert disposition quality.
DEDDY RIZALDY & PARTNERS LAW FIRM 4
Timing should be planned backwards from the external deadline or business decision. Allow time for authority checks,
document collection, technical or financial input, internal review, translation where relevant, authorised signature,
submission, and proof of delivery. Contingency time is important where portals or third parties are involved.
5.4 Assess third-party, correspondent, and digital-channel risks.
Implementation should be proportionate to the assessed exposure. Immediate measures should prevent further harm
and preserve options; longer-term measures should address root cause, ownership, training, monitoring, and recurrence.
Remediation should be accurate and should not overwrite the historical record needed for advice or proceedings.
5.5 Track remediation with accountable owners and board reporting.
The final position should be communicated only through approved channels. Management should know which
developments require board, insurer, lender, regulator, counterparty, employee, or public disclosure. After the decision,
the team should monitor new evidence and legal developments and adjust the plan when its assumptions no longer
hold.

Conclusion

For Financial-Sector AML/CFT Controls under OJK Regulation No. 8 of 2023, compliance should be demonstrable in
both records and operations. The most useful control environment links each obligation to a responsible owner, reliable
source evidence, a review date, an escalation threshold, and a documented response when facts change or an exception
occurs.
Periodic review is important because legislation, system requirements, regulator practice, ownership, business
activities, and operational conditions may change. This note should therefore be used as a starting framework for a
current, fact-specific assessment rather than as a substitute for confirmation with the relevant authority or professional
adviser.