1. Home
  2. ›
  3. Blog
  4. ›
  5. AML/CFT for Islamic Banking: Compliance Guide… | Frans Training

AML/CFT for Islamic Banking: Compliance Guide… | Frans Training

AML/CFT compliance guide specifically for Islamic banking institutions. Sharia-compliant monitoring, reporting obligations, and regulatory requirements.

Author: Lead AML/CFT Compliance Trainer — Mantan Penyidik Keuangan Bank Sentral

Published: 2026-04-04T07:43:11.000Z

AML/CFT for Islamic Banking: A Comprehensive Guide from a Financial Investigation Practitioner

Islamic banking in Indonesia is growing rapidly, with assets exceeding IDR 800 trillion in 2025. That growth brings a serious challenge: money laundering through Sharia products has its own typologies, and conventional AML systems frequently fail to detect them. As a former central bank financial investigator with more than a decade spent on cross-border money laundering cases across the Asia-Pacific region, I have seen at first hand how financial criminals exploit the specific gaps in Islamic banking products.

This article examines money laundering typologies in Sharia products in depth, the dual compliance framework institutions must satisfy, and how Islamic banks can build a robust AML/CFT programme without compromising Sharia principles.

Why Is Islamic Banking AML Different from Conventional AML?

The fundamental difference between AML in Islamic and conventional banking is not simply a matter of products. It is a matter of dual compliance architecture that has to operate simultaneously: compliance with anti-money-laundering regulation (Indonesia's Anti-Money Laundering Law, OJK regulations, and PPATK rules — PPATK being Indonesia's financial intelligence unit) alongside compliance with Sharia principles set by the National Sharia Board of the Indonesian Ulema Council (DSN-MUI).

In investigative practice within a financial intelligence unit, we found that many Islamic banks still apply a "copy-paste" approach from their conventional parent bank's AML programme. That creates a significant blind spot. Products such as murabahah, mudharabah, musyarakah, and sukuk have transaction flows fundamentally different from conventional lending — and it is precisely those flows that launderers exploit.

A lesson from the field: In one case I handled while serving in a Southeast Asian financial intelligence unit, a laundering network used repeated murabahah transactions with varying mark-ups to move tens of billions of rupiah in corruption proceeds. The bank's transaction monitoring system flagged anomalies only on transaction volume, not on the irregular mark-up pattern — because the monitoring parameters had been designed for conventional products.

Money Laundering Typologies in Islamic Banking Products

This material is covered in depth in Module 2: Money Laundering Typologies in Sharia Products of our AML/CFT for Islamic Banking course. These are the principal typologies every Islamic bank compliance officer needs to understand:

1. Murabahah Over-Invoicing

Murabahah is a sale contract in which the bank buys goods at the customer's request and resells them at an agreed profit margin. The laundering typology built on murabahah involves over-invoicing — inflating the price of the goods that are the subject of the transaction.

How the scheme works:

  1. The perpetrator sets up a shell company acting as the goods supplier
  2. That company applies to the Islamic bank for murabahah financing to purchase certain goods
  3. The invoice from the supplier (also controlled by the perpetrator) shows a price far above the market rate
  4. The bank finances the transaction on the basis of that invoice
  5. The gap between the real price and the invoiced price becomes "clean money" returning to the perpetrator via the supplier
  6. The perpetrator makes the murabahah instalments punctually to avoid suspicion

Red flags to watch for:

  • Goods prices on murabahah invoices consistently more than 30% above average market rates
  • The supplier is a new company with a limited track record
  • The customer does not negotiate the bank's margin at all — accepting it immediately
  • A repeating transaction pattern with the same supplier in rising amounts
  • The goods purchased do not fit the customer's business profile

2. Mudharabah Layering

Mudharabah is a profit-sharing contract in which the bank acts as shahibul maal (capital provider) and the customer as mudharib (manager). Layering through mudharabah involves creating layers of fictitious business transactions to obscure the origin of funds.

A typical scenario, based on investigative experience:

  • The perpetrator applies for mudharabah financing for a commodity trading business
  • The financing is disbursed to several "business partners" that are in fact related entities
  • Each entity creates an additional transaction layer, every one with documentation that looks legitimate
  • The "profits" from this fictitious business are used to return funds to the bank as profit share, while most of the money has already moved on to its final destination
  • Financial reporting shows an active, profitable business, when in reality there is no real economic activity

The complexity of mudharabah layering lies in the fact that the bank has limited visibility into how the mudharib manages the funds. Unlike a conventional loan, where the bank can monitor the use of funds closely, Sharia principles grant the manager latitude — and perpetrators exploit that.

3. Sukuk Integration

Sukuk, or Islamic bonds, are an increasingly attractive instrument for launderers because of their large transaction volumes and an active secondary market. Integration through sukuk means buying sukuk with illicit funds, collecting "clean" coupons (profit share), and selling the sukuk on the secondary market to obtain funds fully integrated into the legitimate financial system.

Variations we have encountered in the field:

  • Direct purchase: Buying retail sukuk in large volumes using cash through multiple accounts
  • SPV exploitation: Using a Special Purpose Vehicle in a corporate sukuk issuance to conceal the true beneficial owner
  • Cross-border sukuk: Buying sukuk in one jurisdiction and selling in another, exploiting differences in AML regulation between countries

4. Zakat and Waqf as Laundering Channels

This is a highly sensitive typology, but it has to be discussed. Several cases show the zakat and waqf channels managed by Islamic banks being used to move funds. The perpetrator "pays zakat" or "endows waqf" in a large amount, and those funds are then channelled through the receiving institution to entities the perpetrator controls, under the guise of a social programme. Module 6: Islamic Banking AML Case Studies covers this scenario in detail with anonymised real cases.

The Dual Compliance Framework: PPATK + DSN-MUI

This is the core material of Module 5: DSN-MUI Fatwas and Dual Compliance. Islamic banks in Indonesia operate under two regulatory frameworks that must be satisfied simultaneously:

The AML/CFT Regulatory Framework

  • Law No. 8/2010 on Money Laundering — The legal basis for reporting and preventing money laundering
  • POJK No. 12/POJK.01/2017 — The APU-PPT (AML/CFT) programme across financial services
  • PPATK regulations — Guidance on filing LTKM (suspicious transaction reports)
  • FATF Recommendations — The 40 Recommendations that set the global standard

The Sharia Compliance Framework

  • DSN-MUI fatwas — The body of fatwas governing Sharia products and contracts
  • Bank Indonesia regulations on Islamic banking — Governing Islamic bank operations
  • The Sharia Supervisory Board (DPS) — Internal oversight of Sharia compliance

The main challenge arises when the two frameworks potentially conflict. For instance, the principle of ta'awun (mutual assistance) in Sharia, which encourages easy access to finance, can sit awkwardly against the prudential KYC/CDD principle requiring rigorous verification. A practitioner with investigative experience in a regional financial intelligence unit understands that this balance is not about choosing one over the other, but about designing a process that satisfies both.

Comparison: Indonesia vs Malaysia on Islamic Banking AML

As someone who has served with the Malaysian financial authority (Bank Negara Malaysia) and subsequently handled cross-border cases involving financial institutions in both countries, this comparison is highly relevant — and it is covered in our ASEAN AML Regulations course.

Malaysia has the advantage on regulatory integration. Bank Negara Malaysia (BNM) issues a Policy Document on AML/CFT that explicitly covers Islamic Financial Institutions with specific guidance. There is also a Shariah Governance Policy Document requiring an Islamic bank's AML programme to be approved by its Shariah Committee.

Indonesia is still refining AML regulation specific to Islamic banking. The POJK on APU-PPT applies universally to conventional and Islamic banks alike, without adequate differentiation for the distinct typologies of Sharia products.

Lessons from the Malaysian experience that Indonesia could adopt:

  • Integrating a Shariah advisor into the AML compliance team
  • Transaction monitoring parameters specific to each type of Sharia contract
  • Mandatory AML training that covers Sharia products
  • Regular coordination between the Sharia Supervisory Board and the compliance unit

KYC/CDD for Islamic Bank Customers: The Distinct Challenges

Module 3: KYC/CDD for Islamic Bank Customers addresses challenges specifically not found in conventional banking:

  • Corporate customers built on Sharia contracts: Ownership structures using musyarakah (partnership) can be highly complex and multi-layered, making beneficial owner identification difficult
  • Zakat and waqf institutions: KYC for non-profit bodies channelling funds through an Islamic bank needs a different approach from commercial corporate customers
  • Cross-border customers: Investors from Gulf (GCC) states drawn to Indonesian Sharia products require Enhanced Due Diligence informed by the geopolitical context and AML regulation of their home country
  • Islamic fintech: Sharia peer-to-peer lending platforms and Sharia payment gateways create a new layer in the transaction chain that has to be monitored

For a broader grounding in KYC, our KYC AML Compliance Professional course provides a solid foundation before moving on to Sharia specifics.

Writing Effective STRs for an Islamic Bank

Module 4: STRs for Islamic Banks is one of the most practical modules in the course. Suspicious Transaction Reports (STRs, or LTKM in Indonesia) from Islamic banks are often ineffective because the analyst does not understand the Sharia transaction context.

From experience as an investigator: I received hundreds of STRs from Islamic banks while working in a report intake unit. More than 60% did not state the type of contract used in the suspicious transaction. Without that information, analysts at the Financial Intelligence Unit struggle to determine whether a transaction pattern is genuinely anomalous or simply a normal characteristic of that contract.

What a good Islamic bank STR must contain:

  1. Identification of the contract type: Murabahah, mudharabah, musyarakah, ijarah, or another
  2. Explanation of the deviation from the contract's normal pattern: Why this transaction is irregular in the context of the contract used
  3. Transaction timeline: A full chronology including the contract stages (offer and acceptance, disbursement, payment)
  4. Beneficial ownership analysis: Who actually benefits from the transaction
  5. Business context: Whether the transaction fits the customer's business profile and capacity

What the Course Covers

The AML/CFT for Islamic Banking course is designed by a practitioner with direct experience investigating and prosecuting financial crime in the Islamic banking sector. The module map:

  • Module 1 — Introduction to AML/CFT in an Islamic Banking Context: Regulatory foundations, the fundamental differences between Sharia and conventional AML, the roles of PPATK and OJK
  • Module 2 — Money Laundering Typologies in Sharia Products: Murabahah over-invoicing, mudharabah layering, sukuk integration, and other emerging typologies
  • Module 3 — KYC/CDD for Islamic Bank Customers: Identifying beneficial owners within Sharia structures, EDD for high-risk customers, CDD for non-profit institutions
  • Module 4 — STRs for Islamic Banks: Writing high-quality STRs, transaction monitoring parameters per contract type, integration with PPATK reporting systems
  • Module 5 — DSN-MUI Fatwas and Dual Compliance: Navigating between AML regulation and Sharia principles, the Sharia Supervisory Board's role in the AML programme, compliance conflict case studies
  • Module 6 — Islamic Banking AML Case Studies: Analysis of anonymised real cases, red flag identification exercises, decision-making simulations

Every module comes with case studies drawn from direct field experience. Participants do not merely learn theory; they practise analysing suspicious Sharia transactions using data that mirrors real conditions.

Related Courses That Reinforce These Skills

  • AML/CFT Anti Money Laundering — A comprehensive AML foundation for every type of financial institution
  • Financial Crime Investigation — Investigative methodology for handling detected cases
  • PDP Law Compliance for the Financial Industry — Protecting customer personal data in a KYC/CDD context

FAQ: AML/CFT for Islamic Banking

Are Islamic banks more vulnerable to money laundering than conventional banks?

Not inherently. However, Sharia products carry distinct laundering typologies that AML systems designed for conventional products often fail to detect. Islamic banks need monitoring parameters tuned to the characteristics of each contract type. The problem is not product vulnerability but detection-system readiness.

How do you balance Sharia principles against strict AML requirements?

The two are not opposed in principle. Islam itself forbids risywah (bribery) and ghulul (betrayal of trust), which aligns with the aims of AML. The challenge is technical implementation — for example, how to conduct rigorous CDD without violating the principle of ease of transaction. The answer is to design a process satisfying both frameworks simultaneously, rather than choosing one.

Does an Islamic bank's STR use a different format from a conventional bank's?

The base STR format submitted to PPATK is the same for every type of bank. But a good Islamic bank STR must include additional information: the contract type, the stage of the contract at which the anomaly was detected, and an explanation of why the transaction departs from the normal pattern for that contract. Without that context, FIU analysts struggle to evaluate the report.

Is Indonesian AML regulation adequate for Islamic banking?

The basic regulation exists through the POJK on APU-PPT, but there is still no adequate specific guidance for Sharia product typologies. Malaysia, through BNM, is further ahead with a policy document explicitly covering Islamic Financial Institutions. Indonesia needs to develop comparable guidance, and PPATK and OJK have begun moving in that direction.

Who should take the AML/CFT for Islamic Banking course?

It is designed for Islamic bank compliance officers, AML analysts, internal auditors, Sharia Supervisory Board members, risk management staff, and regulators supervising Islamic banking. As the Islamic finance industry grows, AML understanding specific to Sharia products becomes a required competency — no longer merely "nice to have".

What about Islamic fintech? Does that need AML too?

Absolutely. Islamic fintech, including Sharia peer-to-peer lending platforms and payment gateways built on Sharia contracts, is equally required to run an APU-PPT programme under the POJK. If anything, laundering risk in fintech can be higher, because transactions are faster, volumes larger, and digital onboarding is open to exploitation. Our course modules cover this emerging risk.

Related Training

AML/CFT untuk Perbankan Syariah

  • Investigasi Kejahatan Keuangan untuk Compliance Officer
  • Kepatuhan POJK Keamanan Siber untuk Lembaga Keuangan
  • KYC dan Due Diligence Tingkat Lanjut
  • Regulasi AML ASEAN: Perbandingan Indonesia, Malaysia & Singapura
Home | Schedule | Pricing | Trainers | Consultation | Blog | Locations | Resources | Exam Simulation | AI for Finance | AI for HR | DevOps for Regulated Industries | Software Testing | Automation | Training in Bali | Training in Yogyakarta | Training in Bandung | Training in Batam | Training in Bogor | Training in Lombok | Online Training