1. Home
  2. ›
  3. Blog
  4. ›
  5. Anti-Money Laundering SOP Examples (APU-PPT)… | Frans Training

Anti-Money Laundering SOP Examples (APU-PPT)… | Frans Training

APU-PPT SOP template: KYC/CDD procedures, transaction monitoring, PPATK reporting, and a customer risk matrix aligned with POJK.

Author: Frans Training — Tim Pelatihan AML & Compliance

Published: 2026-04-12T17:29:16.000Z

Picture this: an OJK audit team arrives unannounced for an APU-PPT compliance examination. They ask for your written SOP, evidence of CDD being performed, and a year's worth of PPATK reporting records. Is every one of those documents available and up to standard?

Practitioner experience suggests that a great many financial services institutions come away with significant findings from their first APU-PPT compliance examination. The main cause is not ignorance but an SOP that is incomplete, out of date, or missing altogether.

This article presents 3 complete APU-PPT SOP examples you can adapt directly for a bank, insurer, fintech, or other financial institution. Each procedure follows POJK 12/2017 and Law 8/2010 — ready for an audit at any time.

Prepared by: the AML & Compliance Training Team

Contents

  • What Is an APU-PPT SOP?
  • Mandatory Components of an APU-PPT SOP
  • SOP Example 1: KYC/CDD Procedure for New Customers
  • SOP Example 2: Transaction Monitoring Procedure
  • SOP Example 3: PPATK Reporting Procedure
  • Customer Risk Matrix Template
  • 5 Fatal Mistakes in an APU-PPT SOP
  • Audit-Ready SOP Checklist
  • FAQ

What Is an APU-PPT SOP?

An APU-PPT SOP (Standard Operating Procedure for Anti-Money Laundering and Counter-Terrorism Financing) is the written document governing how a financial institution runs its APU-PPT programme internally. It is the operational guide for every member of staff — from front-liners to the compliance officer — in discharging the legal obligations around money laundering prevention.

Flow diagram of the KYC and CDD procedure for new customers, split by low, medium, and high risk

The Legal Basis

  • Law No. 8 of 2010 on the Prevention and Eradication of Money Laundering — requiring reporting parties to apply the know-your-customer principle
  • POJK No. 12/POJK.01/2017 (updated by POJK No. 8 of 2023) on implementing the APU-PPT programme across financial services — setting out the written SOP obligation in detail
  • Law No. 9 of 2013 on the Prevention and Eradication of Terrorism Financing
  • PPATK regulations on report submission covering how reports are filed with PPATK

Under POJK 12/2017, every financial services provider must maintain a written SOP approved by the board of directors and updated periodically. It must cover the full customer relationship cycle: onboarding, monitoring, and reporting.

Strengthen Your Team's APU-PPT Competency

The KYC & AML Compliance Professional course covers SOP drafting, OJK audit simulation, and PPATK reporting case studies.

Mandatory Components of an APU-PPT SOP

Under POJK 12/2017 and OJK guidance, a complete APU-PPT SOP must contain at least these 10 components:

NoSOP ComponentDescriptionRegulatory Reference
1General APU-PPT policyA statement of board commitment, the scope of application, and definitions of key termsPOJK 12/2017 Chapter I
2Organisational structureAppointment of the know-your-customer unit, the compliance officer, and the escalation pathPOJK 12/2017 Chapter II
3CDD (Customer Due Diligence) procedureHow individual and corporate customers are identified, verified, and monitoredPOJK 12/2017 Chapter III
4EDD (Enhanced Due Diligence) procedureAdditional procedure for high-risk customers: PEPs, high-risk countries, complex beneficial ownershipPOJK 12/2017 Chapter IV
5Transaction monitoring procedureMonitoring based on thresholds, patterns, and the customer risk profilePOJK 12/2017 Chapter V
6Reporting procedureHow suspicious, cash, and cross-border reports are filed with PPATK through goAMLLaw 8/2010 Article 23; Government Regulation 43/2015
7Customer risk managementRisk categorisation (low/medium/high), the assessment matrix, and management procedurePOJK 12/2017 Articles 11-13
8Document retentionThe obligation to retain records for at least 5 years after the business relationship endsLaw 8/2010 Article 22
9Training programmeMandatory APU-PPT training for all staff, its frequency, and its contentPOJK 12/2017 Chapter VI
10APU-PPT internal auditHow the SOP's effectiveness is reviewed and tested periodicallyPOJK 12/2017 Chapter VII

Each component must be set out as a clear procedure, complete with a flowchart, standard forms, and completion deadlines. Let us look at three principal SOPs in detail.

SOP Example 1: KYC/CDD Procedure for New Customers

The CDD (Customer Due Diligence) or KYC (Know Your Customer) procedure is the first line of defence in an APU-PPT system. This SOP governs how a financial institution identifies, verifies, and risk-assesses a customer before the business relationship begins.

Scope

This SOP applies to new account opening, credit applications, purchase of investment or insurance products, and the start of any business relationship with an individual or corporate customer.

Procedure Steps

  1. Collect identity documents
    • Individual customers: national ID or passport, tax number, proof of address, employment and source of income information
    • Corporate customers: incorporation deed, business identification number or trading licence, corporate tax number, the list of directors and shareholders, and the latest financial statements
    • Beneficial owner: identify beneficial owners holding ≥ 25% or otherwise exercising control over the company
  2. Verify identity
    • Individuals: match the ID photograph to the customer, verify the national ID number against the civil registry (where available), validate the tax number
    • Corporates: check legal entity status with the company registry, verify the business identification number in the licensing system, confirm the current board composition
    • Screening: match the customer and beneficial owner names against the domestic terrorist list (DTTOT), the UN sanctions list, OFAC, the EU sanctions list, and the internal PEP database
  3. Assess customer risk
    • Use the risk matrix (see the Risk Matrix Template) to determine the risk category
    • Assessment factors: customer profile, products used, geographic region, and planned transaction volume
    • Output: a low, medium, or high risk categorisation
  4. Acceptance decision
    • Low risk: Approved by the Customer Service Officer, normal processing
    • Medium risk: Approved by the Branch Manager, periodic monitoring
    • High risk: Escalated to the know-your-customer unit for EDD, approved by the Compliance Director
    • Rejection: Where the customer appears on a sanctions or terrorist list, cannot be verified, or refuses to provide mandatory information
  5. Documentation and archiving
    • All CDD documents are stored in the customer document system
    • The decision and the reasoning for acceptance or rejection are documented
    • Retention: at least 5 years after the business relationship ends
  6. Periodic refresh (ongoing CDD)
    • Low risk: review every 3 years
    • Medium risk: review annually
    • High risk: review every 6 months or whenever there is a material change

SLAs and Accountability

StageAccountableSLA
Document collectionCustomer Service OfficerSame day
Identity verificationBack office / operations1 working day
Sanctions and PEP screeningCompliance unit1 working day
Risk assessmentCompliance Officer1 working day
EDD (if high risk)Know-your-customer unit5 working days
Final approvalBranch Manager / Compliance Director1 working day

SOP Example 2: Transaction Monitoring Procedure

Transaction monitoring is the continuous process of detecting unusual or suspicious financial activity. This SOP governs the automated and manual monitoring a financial institution must apply.

Types of Monitoring

A. Threshold-Based Monitoring

The system automatically flags transactions exceeding set limits:

  • Cash transactions ≥ IDR 500,000,000 (the cash reporting threshold)
  • Cross-border transfers ≥ IDR 100,000,000 (the cross-border reporting threshold)
  • Transactions worth ≥ 50% of the customer's total assets or turnover in a single month
  • Cumulative cash ≥ IDR 1,000,000,000 in one calendar month

B. Pattern-Based Monitoring (Pattern Detection)

The compliance team must detect the following patterns:

  • Structuring (smurfing): Split transactions consistently just below the reporting threshold
  • Layering: Repeated transfers between accounts with no clear business purpose
  • Rapid movement: Funds in and out within a short window (24-48 hours)
  • Round-tripping: Funds transferred abroad then returned through a different route
  • Dormant account activity: An account inactive for ≥ 6 months suddenly receiving a large transaction

C. Risk Profile-Based Monitoring

  • Transactions that deviate significantly from the customer's historical transaction profile
  • A change in transaction pattern for a high risk customer
  • Transactions involving a high-risk country or jurisdiction (the FATF list)

Escalation Procedure

  1. Initial detection (Level 1) — The AML system or operational staff flag a suspicious transaction. An alert is raised in the monitoring system.
  2. Initial analysis (Level 2) — A compliance analyst reviews within 1 working day: checking the customer profile, transaction history, and business plausibility. Outcome: dismiss (false positive) or escalate.
  3. Investigation (Level 3) — A senior compliance officer investigates in depth within 3 working days: contacting the relationship manager, seeking customer clarification (without tipping off), and performing EDD where required.
  4. Decision (Level 4) — The head of the know-your-customer unit decides within 2 working days: close the case (documenting the reasoning), report to PPATK as a suspicious transaction, or take other action (transaction restriction, account closure).

Optimise Your Transaction Monitoring System

On the KYC & AML Compliance Professional course, participants practise analysing suspicious transaction alerts using real case studies from Indonesian banking and fintech.

SOP Example 3: PPATK Reporting Procedure

Reporting to PPATK is the critical final stage of the APU-PPT cycle. Late or inaccurate reporting can bring administrative sanctions from OJK as well as criminal penalties under Law 8/2010.

The Internal Reporting Chain

StageOwnerActionDeadline
1. DetectionFront-line staff / AML systemIdentify the suspicious transaction, complete the internal initial report formSame day (D+0)
2. VerificationCompliance analystVerify the transaction data, complete the customer information, gather supporting documentsD+1
3. AnalysisCompliance officerAnalyse the suspicion, determine the indicators, draft the report narrativeD+1 to D+2
4. ApprovalHead of the know-your-customer unitReview and approve the report, confirming completeness and qualityD+2
5. FilinggoAML reporting officerEnter the report in the PPATK goAML system and attach supporting documentsD+2 to D+3
6. ConfirmationCompliance officerConfirm the report was received (receipt number), archive the filing evidenceD+3

Report Types and Timelines

Report TypeTriggerDeadlineChannel
Suspicious Transaction Report (LTKM)Suspicion indicators met3 working days from identificationgoAML
Cash Transaction Report (LTKT)Cash transaction ≥ IDR 500 million14 working daysgoAML
Cross-Border Transfer Report (LTKL)Transfer ≥ IDR 100 million14 working daysgoAML

Confidentiality (Anti Tipping Off)

Strict rules apply throughout the reporting process:

  • The customer must not be told their transaction is being reported
  • Reporting information is known only to those in the reporting chain
  • Reporting documents are stored separately from ordinary customer files
  • Internal communication about a report uses an internal code, not the customer's name
  • Tipping off carries up to 5 years imprisonment and a fine of IDR 1 billion (Article 14, Law 8/2010)

Mandatory Documentation

  • A copy of the goAML report with its receipt number
  • The internal initial report form
  • Supporting documents (statements, transaction slips, CDD/EDD results)
  • A chronological record of the investigation
  • Evidence of approval by the head of the know-your-customer unit
  • All documents retained for at least 5 years after filing

Customer Risk Matrix Template

The risk matrix categorises customers by money laundering risk. The result determines the level of CDD applied and the monitoring frequency.

Risk FactorLow (Score 1)Medium (Score 2)High (Score 3)
Customer identityIndonesian citizen, identity complete and verifiedIndonesian citizen with incomplete documents; foreign national from a non-FATF-listed countryForeign national from a FATF high-risk country; identity difficult to verify
PEP statusNot a PEPFamily member or close associate of a PEPActive PEP (state official, state-owned enterprise, political party)
Type of businessPermanent employee, civil servant, retireeTrader, contractor, liberal professionCash-intensive business (money changer, car dealer, property)
Product/serviceOrdinary savings, small depositsConsumer credit, premium credit cardPrivate banking, trusts, large international transactions
GeographyMajor Indonesian cities, low-risk countriesBorder regions, ASEAN countriesFATF high-risk countries, tax havens, conflict zones
Transaction volumeConsistent with the income profileOccasionally exceeds the profile (< 2x)Frequently exceeds the profile (≥ 2x) without explanation
Beneficial ownerClear and identifiedLayered ownership structure (2-3 levels)Complex structure, nominees, or an unidentified ultimate beneficial owner

How to Use the Matrix

  1. Score each risk factor 1-3
  2. Total the scores (range: 7-21)
  3. Categorise: 7-11 = low risk, 12-16 = medium risk, 17-21 = high risk
  4. Document the assessment in the customer profile
  5. Apply the level of CDD matching the risk category

5 Fatal Mistakes in an APU-PPT SOP

These are the mistakes OJK auditors find most often during an APU-PPT compliance examination. All five can lead to serious sanctions:

NoFatal MistakeConsequenceRemedy
1An SOP that exists only on paper and is never followedWarnings through to fines; no evidence of execution at auditApply a daily checklist for each procedure; require the performer's signature at every stage
2No periodic SOP updateThe SOP falls out of step with current regulation; material audit findingsSchedule an SOP review at least every 12 months or whenever regulation changes; record the version and revision date
3Sanctions and PEP screening not applied consistentlyHigh-risk customers pass through without EDD; potential terrorism financingAutomate screening through the AML system; re-screen whenever the sanctions lists are updated
4Threshold monitoring relying solely on the automated systemStructuring patterns below the threshold go undetectedCombine automated monitoring with manual review by a compliance analyst; set a secondary threshold for pattern detection
5APU-PPT training inadequate or undocumentedStaff fail to recognise red flags; audit findings on personnelRun training at least annually for all staff; document the attendance list, the material, and the assessment results

Audit-Ready APU-PPT SOP Checklist

Use this checklist to confirm your APU-PPT SOP is ready for an OJK examination or internal audit:

  1. The SOP document exists and is the current version — Check the last revision date; confirm it is under 12 months old or aligned to the latest applicable regulation.
  2. Board approval is documented — The SOP must be signed by at least one board member, with the approving meeting minutes available.
  3. The know-your-customer unit structure is clear — Appointment letters for the unit head, the compliance officer, and the goAML reporting officer are documented and current.
  4. The CDD procedure is complete — Covering individual customers, corporates, walk-in customers, and beneficial owners. Standard CDD forms are available.
  5. An EDD procedure exists for high-risk customers — The triggers for EDD are clear; the senior management approval procedure is documented.
  6. The customer risk matrix is current — Assessment parameters reflect current conditions; low/medium/high categorisation is defined.
  7. Transaction monitoring is operational — Evidence of reviewed alerts and documented dismiss/escalate decisions.
  8. PPATK reporting records are complete — Copies of every report with their receipt numbers are properly filed.
  9. Evidence of staff training — Attendance lists, training materials, and certificates for the last 12 months are available.
  10. Screening databases are up to date — The latest sanctions and terrorist lists from PPATK; the internal PEP list refreshed.
  11. Document retention meets the requirement — Evidence of 5-year retention; a disposal mechanism for documents past the retention period.
  12. Previous APU-PPT internal audit results — The audit report, findings, and remediation follow-up are documented.

Prepare Your Team for the Next OJK Audit

The KYC & AML Compliance Professional course from Frans Training provides practical guidance on drafting an SOP, an OJK examination simulation, and industry-recognised certification. Register now for the next available class.

Adapting the Template by Institution Type

The SOP templates above are written for a banking context. Other financial institutions (insurers, pension funds, fintechs, P2P lenders) need to adjust the approval authority, monitoring thresholds, and risk parameters to their own business characteristics and sectoral regulation. OJK circular letters provide the technical implementation guidance that complements the POJK.

FAQ

Is an APU-PPT SOP mandatory for every financial institution?

Yes. Under POJK 12/2017, every financial services provider registered with OJK must maintain a written APU-PPT SOP. That covers commercial banks, rural banks, insurers, pension funds, securities firms, investment managers, financing companies, and registered or licensed fintechs. Not having a written SOP is a breach that can attract sanctions from a warning through to revocation of the operating licence.

How often must the APU-PPT SOP be updated?

OJK requires a review at least every 12 months. The SOP must also be updated promptly whenever there is: a regulatory change (a new POJK, government regulation, or law), an organisational change, a new product or service, an audit finding requiring a procedural fix, or a change in monitoring system technology. Every revision must record the version number, the revision date, and board approval.

What are the sanctions for not having an APU-PPT SOP?

Sanctions escalate under Law 8/2010 and POJK 12/2017: a written warning as the initial step, an administrative fine (varying by breach), restriction of business activity, and ultimately revocation of the operating licence for repeated or serious breaches. Directors and compliance officers can also face personal sanctions barring them from holding office at a financial institution.

Do fintechs (P2P lending, e-wallets) also need an APU-PPT SOP?

Yes. Fintechs registered or licensed with OJK fall within the financial services provider category and must run an APU-PPT programme. POJK 77/2016 (for P2P lending) and POJK 12/2017 explicitly cover digital financial services. Fintechs face an additional challenge, in that customer onboarding is often entirely digital, so e-KYC procedures have to be tighter still.

How do you train non-compliance staff on APU-PPT?

APU-PPT training must be given to all staff, not only the compliance team. For front-line staff (tellers, customer service), focus on recognising red flags and the escalation procedure. For operations staff, emphasise adherence to verification and documentation procedure. Use real case studies relevant to their role. OJK requires training at least once a year with complete documentation. Consider certified training from a professional body to raise the team's competency further.

Related Training

  • AML/CFT untuk Perbankan Syariah
  • Investigasi Kejahatan Keuangan untuk Compliance Officer
  • Kepatuhan POJK Keamanan Siber untuk Lembaga Keuangan
  • KYC dan Due Diligence Tingkat Lanjut
Home | Schedule | Pricing | Trainers | Consultation | Blog | Locations | Resources | Exam Simulation | AI for Finance | AI for HR | DevOps for Regulated Industries | Software Testing | Automation | Training in Bali | Training in Yogyakarta | Training in Bandung | Training in Batam | Training in Bogor | Training in Lombok | Online Training