Guidelines on Electronic Know-Your-Customer (e-KYC)

Test Documents

e-KYC Guidelines

PDF · Test Documents 01 Jul 2024

Guidelines on Electronic Know-Your-Customer (e-KYC)

Issuing Authority: Bank Negara Malaysia Document No: BNM/RH/PD 030-10 Effective Date: 1 July 2024 Version: 1.2

Revision Notice: This version supersedes version 1.1 dated 1 April 2024. Please refer to the revision history at the end of this document.

1. Introduction

This document sets out the regulatory expectations for financial institutions implementing electronic Know-Your-Customer (e-KYC) solutions for customer onboarding and ongoing due diligence. These guidelines apply to all licensed banks, Islamic banks, insurers, and prescribed institutions under the purview of Bank Negara Malaysia.

Financial institutions are expected to adopt robust technology solutions that balance customer convenience with the integrity of verification processes. The adoption of e-KYC shall not compromise the quality of customer due diligence conducted by the institution.

2. Scope of Application

These guidelines are applicable to the following categories of financial institutions:

  1. Licensed banks and licensed Islamic banks
  2. Licensed insurers and licensed takaful operators
  3. Prescribed institutions under the Development Financial Institutions Act 2002
  4. Payment system operators and e-money issuers

3. Minimum Requirements for e-KYC Technology

3.1 Identity Verification

All e-KYC solutions must incorporate the following minimum capabilities for identity verification:

Component Requirement Standard
Document Authentication Verify authenticity of identity documents (MyKad, passport) ISO/IEC 19794-5
Facial Recognition Liveness detection with anti-spoofing measures ISO/IEC 30107-3 Level 1
Data Extraction Automated extraction of personal data from identity documents ICAO Doc 9303

3.2 Risk Assessment

Financial institutions shall implement a risk-based approach to e-KYC. Higher-risk customers or transactions must be subjected to enhanced due diligence measures, which may include additional verification steps or manual review by trained personnel.

3.3 Third-Party e-KYC Service Providers

Where financial institutions engage third-party providers to deliver e-KYC functions, they remain fully responsible for compliance with these guidelines. A formal due diligence assessment of the third-party provider must be conducted prior to engagement and reviewed annually thereafter.

4. Data Protection and Privacy

All personal data collected through e-KYC processes must be handled in accordance with the Personal Data Protection Act 2010 (PDPA). Financial institutions must ensure:

  • Explicit customer consent is obtained prior to data collection
  • Data is encrypted both in transit (TLS 1.2 or above) and at rest (AES-256)
  • Biometric data is stored for a maximum period of 4 years from account closure
  • Regular penetration testing is conducted on e-KYC infrastructure

5. Reporting and Compliance

Financial institutions shall submit quarterly reports to the Supervision Department detailing:

Report Item Frequency Submission Deadline
e-KYC onboarding volume and success rates Quarterly 15th of following month
Fraud and false positive rates Quarterly 15th of following month
System downtime and incident reports Monthly 5th of following month

6. Revision History

Version Date Summary of Changes
1.0 1 Jan 2024 Initial issuance
1.1 1 Apr 2024 Added requirements for third-party e-KYC service providers
1.2 1 Jul 2024 Biometric retention reduced from 5 to 4 years

© 2024 Bank Negara Malaysia. All rights reserved. This document is issued pursuant to sections 47(1) and 266 of the Financial Services Act 2013 and sections 57(1) and 277 of the Islamic Financial Services Act 2013.

# Guidelines on Electronic Know-Your-Customer (e-KYC)

**Issuing Authority:** Bank Negara Malaysia
**Document No:** BNM/RH/PD 030-10
**Effective Date:** 1 July 2024
**Version:** 1.2

**Revision Notice:** This version supersedes version 1.1 dated 1 April 2024. Please refer to the revision history at the end of this document.

## 1. Introduction

This document sets out the regulatory expectations for financial institutions implementing electronic Know-Your-Customer (e-KYC) solutions for customer onboarding and ongoing due diligence. These guidelines apply to all licensed banks, Islamic banks, insurers, and prescribed institutions under the purview of Bank Negara Malaysia.

Financial institutions are expected to adopt robust technology solutions that balance customer convenience with the integrity of verification processes. The adoption of e-KYC shall not compromise the quality of customer due diligence conducted by the institution.

## 2. Scope of Application

These guidelines are applicable to the following categories of financial institutions:

1. Licensed banks and licensed Islamic banks
2. Licensed insurers and licensed takaful operators
3. Prescribed institutions under the Development Financial Institutions Act 2002
4. Payment system operators and e-money issuers

## 3. Minimum Requirements for e-KYC Technology

### 3.1 Identity Verification

All e-KYC solutions must incorporate the following minimum capabilities for identity verification:

| Component | Requirement | Standard |
| :--- | :--- | :--- |
| Document Authentication | Verify authenticity of identity documents (MyKad, passport) | ISO/IEC 19794-5 |
| Facial Recognition | Liveness detection with anti-spoofing measures | ISO/IEC 30107-3 Level 1 |
| Data Extraction | Automated extraction of personal data from identity documents | ICAO Doc 9303 |

### 3.2 Risk Assessment

Financial institutions shall implement a risk-based approach to e-KYC. Higher-risk customers or transactions must be subjected to enhanced due diligence measures, which may include additional verification steps or manual review by trained personnel.

### 3.3 Third-Party e-KYC Service Providers

Where financial institutions engage third-party providers to deliver e-KYC functions, they remain fully responsible for compliance with these guidelines. A formal due diligence assessment of the third-party provider must be conducted prior to engagement and reviewed annually thereafter.

## 4. Data Protection and Privacy

All personal data collected through e-KYC processes must be handled in accordance with the Personal Data Protection Act 2010 (PDPA). Financial institutions must ensure:

* Explicit customer consent is obtained prior to data collection
* Data is encrypted both in transit (TLS 1.2 or above) and at rest (AES-256)
* Biometric data is stored for a maximum period of 4 years from account closure
* Regular penetration testing is conducted on e-KYC infrastructure

## 5. Reporting and Compliance

Financial institutions shall submit quarterly reports to the Supervision Department detailing:

| Report Item | Frequency | Submission Deadline |
| :--- | :--- | :--- |
| e-KYC onboarding volume and success rates | Quarterly | 15th of following month |
| Fraud and false positive rates | Quarterly | 15th of following month |
| System downtime and incident reports | Monthly | 5th of following month |

## 6. Revision History

| Version | Date | Summary of Changes |
| :--- | :--- | :--- |
| 1.0 | 1 Jan 2024 | Initial issuance |
| 1.1 | 1 Apr 2024 | Added requirements for third-party e-KYC service providers |
| 1.2 | 1 Jul 2024 | Biometric retention reduced from 5 to 4 years |

© 2024 Bank Negara Malaysia. All rights reserved.
This document is issued pursuant to sections 47(1) and 266 of the Financial Services Act 2013 and sections 57(1) and 277 of the Islamic Financial Services Act 2013.

Change History

file_content 2 days ago
91f281b21ed2bb18... 4c194f04c846841c...
file_content 3 days ago
18b2874ed175b858... 91f281b21ed2bb18...
file_content 4 days ago
dacf34148b67ff96... 18b2874ed175b858...
file_content 5 days ago
b80984bb6574daf3... dacf34148b67ff96...
file_content 6 days ago
5a83c74bee6508a0... b80984bb6574daf3...
file_content 1 week ago
f820340543d5b94a... 5a83c74bee6508a0...
file_content 1 week ago
a7c00673ba9d008b... f820340543d5b94a...
file_content 1 week ago
0648df45c08f22d2... a7c00673ba9d008b...
file_content 1 week ago
3d9ced28edff1ac3... 0648df45c08f22d2...
file_content 1 week ago
b683f0d42ee9aa59... 3d9ced28edff1ac3...
file_content 1 week ago
67cae8496748f1c6... b683f0d42ee9aa59...
file_content 1 week ago
cb0492ff1996c6f2... 67cae8496748f1c6...
file_content 2 weeks ago
ec25a4b831df850e... cb0492ff1996c6f2...
file_content 2 weeks ago
7e1fd32c589bde04... ec25a4b831df850e...
file_content 2 weeks ago
b6693707649237e7... 7e1fd32c589bde04...
file_content 2 weeks ago
f3ec8daf9cab090a... b6693707649237e7...
file_content 2 weeks ago
ef3eb65e4f45e119... f3ec8daf9cab090a...
file_content 2 weeks ago
9382c010f3542292... ef3eb65e4f45e119...
file_content 2 weeks ago
96dbb327fa298b47... 9382c010f3542292...
file_content 3 weeks ago
443e51e4d96ac1b4... 96dbb327fa298b47...
file_content 3 weeks ago
790f7fc017e62415... 443e51e4d96ac1b4...
file_content 3 weeks ago
5621c180753888f1... 790f7fc017e62415...
file_content 3 weeks ago
870328592e1154b9... 5621c180753888f1...
file_content 3 weeks ago
1c9731692ef15760... 870328592e1154b9...
file_content 3 weeks ago
7544c1c0b5e567da... 1c9731692ef15760...
file_content 3 weeks ago
8a3dbbaa6089f57c... 7544c1c0b5e567da...
file_content 4 weeks ago
5cecc58ade2fdb27... 8a3dbbaa6089f57c...
file_content 4 weeks ago
766ca55b46f0872e... 5cecc58ade2fdb27...
file_content 4 weeks ago
4106102abbcb1107... 766ca55b46f0872e...
file_content 1 month ago
22cc1bb15db799d3... 4106102abbcb1107...
file_content 1 month ago
827a16456ec5140b... 22cc1bb15db799d3...
file_content 1 month ago
3500cb5aae4221ae... 827a16456ec5140b...
file_content 1 month ago
091cf38d8ba4977d... 3500cb5aae4221ae...
file_content 1 month ago
6bf6e05f419e0b7a... 091cf38d8ba4977d...
file_content 1 month ago
772df72ec0c532ec... 6bf6e05f419e0b7a...
file_content 1 month ago
e45b184d2ffcf87a... 772df72ec0c532ec...
file_content 1 month ago
023c9856e4ee6478... e45b184d2ffcf87a...
file_content 1 month ago
41c5fac20448b034... 023c9856e4ee6478...
file_content 1 month ago
6e58dd22c14d577e... 41c5fac20448b034...
file_content 1 month ago
191c47de151e4e01... 6e58dd22c14d577e...
file_content 1 month ago
c0a7bf60ecac1e90... 191c47de151e4e01...
file_content 1 month ago
0fe10558d7f6f3bc... c0a7bf60ecac1e90...
file_content 1 month ago
3100fc8fe82918b3... 0fe10558d7f6f3bc...
file_content 1 month ago
c2cb631512b08f60... 3100fc8fe82918b3...
file_content 1 month ago
5116c3d28e608636... c2cb631512b08f60...
file_content 1 month ago
45262793bf80f742... 5116c3d28e608636...
file_content 1 month ago
d50ca25f7236dee7... 45262793bf80f742...
file_content 1 month ago
fdfbee2e539550f7... d50ca25f7236dee7...
file_content 1 month ago
8a0105ed9be2804c... fdfbee2e539550f7...
file_content 1 month ago
cb7a574728b53119... 8a0105ed9be2804c...
file_content 1 month ago
6daf61cab219b982... cb7a574728b53119...
file_content 1 month ago
5460248abdc6fc39... 6daf61cab219b982...
file_content 1 month ago
b82f5df82b15b9e1... 5460248abdc6fc39...
file_content 1 month ago
e8aee097c4c5dc25... b82f5df82b15b9e1...
file_content 1 month ago
c486768bf4b77ee8... e8aee097c4c5dc25...
file_content 1 month ago
b5e78a76dc23cea8... c486768bf4b77ee8...
file_content 1 month ago
48df104421666877... b5e78a76dc23cea8...
file_content 1 month ago
0b5b220c9364efe3... 48df104421666877...
file_content 1 month ago
2063d888b52b008c... 0b5b220c9364efe3...
file_content 2 months ago
20cd532507fb1228... 2063d888b52b008c...
file_content 2 months ago
3ebd09b5786a679b... 20cd532507fb1228...
file_content 2 months ago
efa15b06393c0f82... 3ebd09b5786a679b...
file_content 2 months ago
a0c348651b116f5a... efa15b06393c0f82...
file_content 2 months ago
ff65e82a8e566578... a0c348651b116f5a...
file_content 2 months ago
54bca26b6721efe9... ff65e82a8e566578...
file_content 2 months ago
6be5c622d1e4c82a... 54bca26b6721efe9...
file_content 2 months ago
6aafd814b2724d51... 6be5c622d1e4c82a...
file_content 2 months ago
ee7cdf13c451bfbb... 6aafd814b2724d51...
file_content 2 months ago
65bff86116062a24... ee7cdf13c451bfbb...
file_content 2 months ago
c93c94237f424cb1... 65bff86116062a24...
file_content 2 months ago
ae91521a67c235f0... c93c94237f424cb1...
file_content 2 months ago
600d0fc76b40b26b... ae91521a67c235f0...
file_content 2 months ago
5460c00c7ff15c38... 600d0fc76b40b26b...
file_content 2 months ago
d2656f564bd430b7... 5460c00c7ff15c38...
file_content 2 months ago
00900d67d5a6a56f... d2656f564bd430b7...
file_content 2 months ago
ecff9322eb878f66... 00900d67d5a6a56f...
file_content 2 months ago
0c2c3571eae884bc... ecff9322eb878f66...
file_content 2 months ago
e2acab6ed546227c... 0c2c3571eae884bc...
file_content 2 months ago
f177e1167dc4ad65... e2acab6ed546227c...
file_content 2 months ago
69bab6be6c7809f3... f177e1167dc4ad65...
file_content 2 months ago
b07956138806a718... 69bab6be6c7809f3...
file_content 2 months ago
da63d07fa10afa2b... b07956138806a718...
file_content 2 months ago
f0ec84cace521e6a... da63d07fa10afa2b...
file_content 2 months ago
fbd52875eb1e8ae2... f0ec84cace521e6a...
file_content 2 months ago
5a47e31ed193a687... fbd52875eb1e8ae2...
file_content 2 months ago
dd72bfaa59c28665... 5a47e31ed193a687...
file_content 2 months ago
9c2f5bf45beee95f... dd72bfaa59c28665...
file_content 2 months ago
e1f81154e2e478a1... 9c2f5bf45beee95f...
file_content 2 months ago
b7cc0cc420954333... e1f81154e2e478a1...
file_content 2 months ago
65881b26d5faf3e8... b7cc0cc420954333...
markdown_content 2 months ago
78c571c1b0b4a0c96ce128ab295b96... 413cd9cc864ea98a1bf71a8c904a0d...
file_content 2 months ago
d3032df975ff33a1... 65881b26d5faf3e8...
published_date 2 months ago
2024-04-01 2024-07-01
markdown_content 2 months ago
413cd9cc864ea98a1bf71a8c904a0d... 78c571c1b0b4a0c96ce128ab295b96...
published_date 2 months ago
2025-07-01 2024-04-01
file_content 2 months ago
3b05d04e4edbdbb4... d3032df975ff33a1...
markdown_content 2 months ago
78c571c1b0b4a0c96ce128ab295b96... 413cd9cc864ea98a1bf71a8c904a0d...
file_content 2 months ago
a1326f78b7cbc1ed... 3b05d04e4edbdbb4...
markdown_content 2 months ago
69f85972db359307c812a52cf768a3... 78c571c1b0b4a0c96ce128ab295b96...
file_content 2 months ago
7a2a83908f1b010a... a1326f78b7cbc1ed...
published_date 2 months ago
2024-01-01 2025-07-01
published_date 2 months ago
2025-07-01 2024-01-01
file_content 3 months ago
d10ec2172773ba22... 7a2a83908f1b010a...