Financial Services Authority Board of Commissioners Regulation Number 4 of 2026 Requires Trustees to Implement a Risk-Based Anti-Money Laundering Program
Introduction
On 7 July 2026, the Financial Services Authority implemented Financial Services Authority Board of Commissioners Regulation Number 4 of 2026 on Guidelines for the Implementation of Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing of Weapons of Mass Destruction Programs for Trustees (“PADK 4/2026”).
PADK 4/2026 is an implementing regulation of Financial Services Authority Regulation Number 8 of 2023 on the Implementation of Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing of Weapons of Mass Destruction Programs in the Financial Services Sector. PADK 4/2026 serves as an operational technical guideline for trustees in implementing Anti-Money Laundering, Counter-Terrorism Financing, and Counter-Proliferation Financing of Weapons of Mass Destruction (“AML, CTF, and CPF-WMD”) programs through a risk-based approach, strengthened reporting mechanisms, and standardized supervision.
The issuance of PADK 4/2026 is driven by the Financial Services Authority’s (“OJK”) need to strengthen the control and risk mitigation framework applicable to trustees acting as representatives of holders of debt securities or sukuk, thereby preventing the misuse of trusteeship activities as a means of money laundering, terrorism financing, or the proliferation financing of weapons of mass destruction.
Key Provisions
Implementation of a Risk-Based Approach
Pursuant to Annex I, Roman Numeral III, trustees are required to implement AML, CTF, and CPF-WMD programs using a risk-based approach.
In implementing this approach, trustees must identify, assess, and understand the level of risk associated with the Customer’s (Issuer’s) profile, geographical area or jurisdiction, product and/or service characteristics, and transaction methods.
The results of such assessment must be documented in an Individual Risk Assessment (IRA) document, which must be reviewed, evaluated, and updated periodically in accordance with changes in the trustee’s risk profile and operational requirements.
Customer Due Diligence (CDD) and Beneficial Owner Identification
Pursuant to Annex I, Roman Numeral V, trustees are required to conduct Customer Due Diligence (CDD) and, where warranted by the level of risk, Enhanced Due Diligence (EDD) when establishing a business relationship with a customer.
Since trustees’ customers generally consist of legal entities or corporate entities, the due diligence process focuses on verifying the identity of the Beneficial Owner to ensure that fictitious identities, shell companies, or other forms of concealed ownership are not being used.
Where beneficial ownership information is publicly available from adequate, reliable, and trustworthy sources, such as disclosures in the capital market, trustees may rely on such information for verification purposes without requesting the same information again from the customer, provided that the information remains relevant and complies with the applicable requirements.
Supervision and Establishment of a Responsible Unit
Pursuant to Annex I, Roman Numeral IV, the board of directors and board of commissioners of a trustee bear full responsibility for the implementation, supervision, and effectiveness of the AML, CTF, and CPF-WMD program.
To support the implementation of the program, trustees are required to appoint a responsible officer or establish an independent AML, CTF, and CPF-WMD work unit.
The responsible officer or work unit must report directly to the board of directors and be granted authority to access all information required from every organizational unit of the trustee in order to effectively perform its supervisory functions.
Periodic and Incidental Reporting Obligations
Pursuant to Annex I, Roman Numeral IX, trustees are required to fulfill a number of administrative reporting obligations as part of the implementation of AML, CTF, and CPF-WMD programs.
|
Type of Report |
Obligation |
Submission Deadline |
Submitted To |
|
IRA Document and AML, CTF, and CPF-WMD Questionnaire Update Report |
Submission of updates to the Institutional Risk Assessment (IRA) document and the AML, CTF, and CPF-WMD Questionnaire. |
Annually, no later than the end of June. |
OJK |
|
Customer Data Updating Plan Report |
Submission of the customer data updating plan for the following reporting period. |
No later than the end of December of the preceding year. |
OJK |
|
Customer Data Updating Implementation Report |
Submission of the realization of customer data updating activities. |
No later than the end of January. |
OJK |
|
Suspicious Financial Transaction Report (LTKM) and Nil Report on DTTOT/DPPSPM |
Submission of Suspicious Financial Transaction Reports (LTKM) and Nil Reports relating to the List of Suspected Terrorists and Terrorist Organizations (DTTOT) and the List of Proliferation Financing of Weapons of Mass Destruction (DPPSPM). |
No later than 3 (three) working days after the reporting obligation arises. |
PPATK and the Indonesian National Police, with a copy to OJK. |
Obligation to Ensure Compliance of Supporting Professionals and Submission of Data
Pursuant to Annex I, Roman Numeral X, PADK 4/2026 establishes additional obligations that trustees must fulfill to support the effective implementation of AML, CTF, and CPF-WMD programs. These obligations include:
- Ensuring the compliance of supporting professionals: Where a trustee appoints or directly engages supporting professionals who qualify as reporting parties under the AML, CTF, and CPF-WMD regime, the trustee must ensure that such professionals have implemented AML, CTF, and CPF-WMD programs and are registered in the AML, CTF, and CPF-WMD reporting information system administered by PPATK.
Such compliance must be evidenced by, among other things:
- an electronic confirmation from PPATK stating that the registration application has been received; and/or
- other forms of evidence in accordance with the applicable laws and regulations governing the AML, CTF, and CPF-WMD reporting information system.
- Obligation to provide data to the authorities: Trustees are also required to provide data, information, and/or documents under their control or administration to OJK and/or other competent authorities immediately upon receiving a request, with a submission deadline of no later than 3 (three) working days from the date the request is received.
PADK 4/2026 emphasizes that the responsibilities of trustees extend beyond implementing AML, CTF, and CPF-WMD programs within their own organizations. Trustees are also responsible for supervising the compliance of the supporting professionals they engage and for supporting supervisory and law enforcement processes through the timely submission of data to OJK and/or other competent authorities.
Transitional Provisions
Pursuant to Article 3, Individual Risk Assessment (IRA) documents that were prepared and submitted by trustees to OJK prior to the entry into force of PADK 4/2026 remain valid and may continue to be used.
However, any updates to IRA documents made after PADK 4/2026 came into effect on 7 July 2026 must follow the standardized format prescribed in the Annex to PADK 4/2026.
Furthermore, Article 4 establishes a transitional provision concerning the submission of the AML, CTF, and CPF-WMD program questionnaire. The obligation to use the new questionnaire format will apply beginning with the 2027 reporting period.
Closing
The enactment of PADK 4/2026 provides more detailed governance and risk management requirements for trustees in preventing money laundering, terrorism financing, and the proliferation financing of weapons of mass destruction.
Through the implementation of a risk-based approach, mandatory Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD), strengthened internal supervisory functions, and comprehensive reporting obligations, OJK emphasizes that trustees play a strategic role in maintaining the integrity of Indonesia’s capital market while supporting the national AML, CTF, and CPF-WMD regime.
Accordingly, trustees should ensure that their internal policies, operational procedures, control systems, IRA documentation, reporting mechanisms, and supervision of supporting professionals are aligned with the requirements of PADK 4/2026. Such adjustments are essential to fulfill regulatory compliance obligations, mitigate legal and compliance risks, and support effective supervision by OJK, PPATK, and other competent authorities.
Related Regulations
Click a regulation to view details.
Log in to comment
Log inWhat is
Veritask is an integrated AI-powered legal platform that helps with regulatory research, document preparation, and compliance management in one dashboard.
Free Subscription
Subscribe to receive a free weekly email with the latest legal analysis.