AML/CFT Obligations for Company Secretaries and What It Means for Your Sdn Bhd

If your company secretary has ever asked you to sign a source of funds declaration, provide identification documents you thought you’d already submitted, or answer questions about who’s really behind a transaction, it can feel like unnecessary friction. It isn’t. Your company secretary is legally required to ask these questions, and if they don’t, the consequences fall on them personally, not just on your company.

Company secretaries in Malaysia are classified as reporting institutions under the country’s anti-money laundering framework. That status comes with real obligations: verifying who they’re dealing with, watching for red flags, and reporting suspicious activity, even when it involves their own paying clients. Understanding this relationship helps explain why your cosec asks the questions they do, and what it means for how your Sdn Bhd is run day to day.

Why Company Secretaries Are Covered by AML/CFT Law

The Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001, commonly referred to as AMLA, is Malaysia’s primary legislation governing money laundering and terrorism financing controls. AMLA doesn’t just apply to banks. It extends to a defined list of reporting institutions, including trust companies, lawyers, accountants, and company secretaries, when they carry out relevant activities on behalf of clients.

This places licensed company secretaries in the same regulatory category as Designated Non-Financial Businesses and Professions, alongside real estate agents and dealers in precious metals. The reasoning is straightforward. Company secretaries sit close to the formation and structure of companies, which makes them a natural checkpoint for spotting attempts to misuse a corporate vehicle for illicit purposes.

What This Actually Requires From Your Company Secretary

Customer Due Diligence (CDD)

Before establishing a business relationship, and at various points afterward, your company secretary is required to verify who they’re actually dealing with. This is why you’ll be asked for identification documents, information about your company’s ownership and control structure, and sometimes documentation around the source of funds involved in a transaction.

This obligation is triggered whenever a business relationship is established or a transaction is carried out, when a transaction exceeds a specified threshold, when there’s reasonable suspicion of money laundering or terrorism financing, or when there’s reasonable doubt about the accuracy of information already on file. In practice, this overlaps directly with the identification work your cosec already does for beneficial ownership reporting, since both frameworks require knowing exactly who stands behind your company.

Enhanced Due Diligence for Higher-Risk Clients

Where a client presents higher risk, such as a politically exposed person, or a structure involving multiple jurisdictions, a company secretary is expected to apply enhanced due diligence rather than standard checks. This can mean requesting additional documentation or asking more detailed questions about the nature and purpose of the business relationship.

Ongoing Monitoring, Not a One-Time Check

AML obligations don’t end once a client is onboarded. Company secretaries are expected to monitor relationships on an ongoing basis and revisit due diligence when something changes, such as a shift in ownership, an unusual transaction pattern, or new information that raises doubt about details previously provided.

Record Keeping

Documentation gathered through the due diligence process needs to be retained for a defined minimum period under AMLA, so it’s available if regulators or investigators need to review it later. This is part of why your cosec may hold onto identification documents and declarations well beyond the point where you assumed they were no longer needed.

Suspicious Transaction Reporting

If a company secretary forms a reasonable suspicion that a transaction or activity may be connected to money laundering or terrorism financing, they are legally required to report it, through a Suspicious Transaction Report submitted to Bank Negara Malaysia’s Financial Intelligence Unit. This obligation exists regardless of the professional relationship involved. A company secretary cannot decline to report simply because the client is paying them or has been a client for years.

Why Confidentiality Doesn’t Override This

A common misunderstanding among SME owners is that professional confidentiality protects them from these disclosures. It doesn’t. AMLA’s reporting provisions are designed to override other confidentiality obligations, including the general duty of confidence that would otherwise apply between a company secretary and their client. Where a reporting obligation applies, the company secretary is legally required to comply with it, and separately, the law provides them protection from civil or disciplinary liability for making a report in good faith.

This is precisely why the forms your company secretary asks you to sign, whether that’s a beneficial ownership declaration, a source of funds form, or a politically exposed person declaration, aren’t bureaucratic box-ticking. They’re the documented evidence that proper due diligence was carried out, and they protect both you and your company secretary if questions ever arise later.

What Happens If a Company Secretary Doesn’t Comply

The consequences for non-compliance are not minor. Failure to meet AML/CFT obligations under AMLA, including failing to carry out proper due diligence or failing to file a required suspicious transaction report, can result in significant fines and, in serious cases, imprisonment. Beyond the statutory penalties, SSM has taken enforcement action against company secretaries who failed to meet their gatekeeper obligations, including cases resulting in substantial fines and revocation of the individual’s practising certificate, effectively ending their ability to work in the profession.

This is exactly why a properly licensed and compliance-conscious company secretary treats AML/CFT obligations seriously rather than as an afterthought. We’ve covered this alongside other regulatory training our team engages with in our note on the AML Workshop for DCR 2026.

What This Means for Your Sdn Bhd Day to Day

For most compliant business owners, AML/CFT obligations translate into a handful of practical touchpoints rather than any real burden:

  • Expect to provide clear identification and ownership documentation when you first engage a company secretary, and again if your structure changes
  • Be prepared to explain the source of funds for unusual or large transactions if asked
  • Understand that your company secretary may decline to proceed with a transaction, or may need to pause and ask questions, if something doesn’t add up
  • Recognise that these checks exist to protect legitimate businesses as much as to catch illegitimate ones. A cosec that takes AML seriously is generally a strong signal they take the rest of their compliance obligations seriously too

If you’re evaluating whether your current company secretary is handling this properly, our guide on how to find the best company secretary in Malaysia covers the broader markers of a diligent, properly licensed provider, of which AML compliance is one important piece.

Frequently Asked Questions

Are company secretaries in Malaysia legally required to comply with AML/CFT rules? Yes. Company secretaries are classified as reporting institutions under AMLA and are subject to the same core obligations as other Designated Non-Financial Businesses and Professions, including customer due diligence and suspicious transaction reporting.

Can my company secretary refuse to disclose information about me to authorities due to confidentiality? No. AMLA’s reporting provisions override other confidentiality obligations. Where a reporting obligation is triggered, the company secretary is legally required to comply, regardless of the professional relationship.

Why does my company secretary keep asking for identification and source of funds documents? This is a legal requirement under AMLA’s customer due diligence provisions, not an optional administrative step. It applies when a business relationship is established, when certain transactions occur, or when there’s reasonable doubt about information already held.

What happens if a company secretary fails to file a required suspicious transaction report? Non-compliance with AML/CFT obligations can result in significant fines and, in serious cases, imprisonment. SSM has also taken disciplinary action against company secretaries in such cases, including revoking practising certificates.

Does AML/CFT compliance affect how quickly my company secretary can process a transaction? It can. If a transaction raises questions that require additional verification or enhanced due diligence, your company secretary may need extra time before proceeding, particularly for higher-risk clients or unusual transaction patterns.

Conclusion

AML/CFT obligations aren’t a formality your company secretary layers on top of their real work. They’re a core part of what it means to be a licensed reporting institution in Malaysia, and they exist to protect legitimate businesses from being unknowingly caught up in illicit activity. When your cosec asks detailed questions or requests documentation, it’s a sign they’re taking their gatekeeper role seriously, which is exactly what you want from the person managing your company’s statutory obligations.

iComSec’s company secretary services in Malaysia are built around full compliance with AML/CFT and beneficial ownership requirements, so your Sdn Bhd is properly protected from day one. Contact our team to find out how we manage this as part of our standard cosec service.