Picture this: an OJK audit team arrives unannounced for an APU-PPT compliance examination. They ask for your written SOP, evidence of CDD being performed, and a year's worth of PPATK reporting records. Is every one of those documents available and up to standard?
Practitioner experience suggests that a great many financial services institutions come away with significant findings from their first APU-PPT compliance examination. The main cause is not ignorance but an SOP that is incomplete, out of date, or missing altogether.
This article presents 3 complete APU-PPT SOP examples you can adapt directly for a bank, insurer, fintech, or other financial institution. Each procedure follows POJK 12/2017 and Law 8/2010 — ready for an audit at any time.
Prepared by: the AML & Compliance Training Team
Contents
- What Is an APU-PPT SOP?
- Mandatory Components of an APU-PPT SOP
- SOP Example 1: KYC/CDD Procedure for New Customers
- SOP Example 2: Transaction Monitoring Procedure
- SOP Example 3: PPATK Reporting Procedure
- Customer Risk Matrix Template
- 5 Fatal Mistakes in an APU-PPT SOP
- Audit-Ready SOP Checklist
- FAQ
What Is an APU-PPT SOP?
An APU-PPT SOP (Standard Operating Procedure for Anti-Money Laundering and Counter-Terrorism Financing) is the written document governing how a financial institution runs its APU-PPT programme internally. It is the operational guide for every member of staff — from front-liners to the compliance officer — in discharging the legal obligations around money laundering prevention.

The Legal Basis
- Law No. 8 of 2010 on the Prevention and Eradication of Money Laundering — requiring reporting parties to apply the know-your-customer principle
- POJK No. 12/POJK.01/2017 (updated by POJK No. 8 of 2023) on implementing the APU-PPT programme across financial services — setting out the written SOP obligation in detail
- Law No. 9 of 2013 on the Prevention and Eradication of Terrorism Financing
- PPATK regulations on report submission covering how reports are filed with PPATK
Under POJK 12/2017, every financial services provider must maintain a written SOP approved by the board of directors and updated periodically. It must cover the full customer relationship cycle: onboarding, monitoring, and reporting.
Strengthen Your Team's APU-PPT Competency
The KYC & AML Compliance Professional course covers SOP drafting, OJK audit simulation, and PPATK reporting case studies.
Mandatory Components of an APU-PPT SOP
Under POJK 12/2017 and OJK guidance, a complete APU-PPT SOP must contain at least these 10 components:
| No | SOP Component | Description | Regulatory Reference |
|---|---|---|---|
| 1 | General APU-PPT policy | A statement of board commitment, the scope of application, and definitions of key terms | POJK 12/2017 Chapter I |
| 2 | Organisational structure | Appointment of the know-your-customer unit, the compliance officer, and the escalation path | POJK 12/2017 Chapter II |
| 3 | CDD (Customer Due Diligence) procedure | How individual and corporate customers are identified, verified, and monitored | POJK 12/2017 Chapter III |
| 4 | EDD (Enhanced Due Diligence) procedure | Additional procedure for high-risk customers: PEPs, high-risk countries, complex beneficial ownership | POJK 12/2017 Chapter IV |
| 5 | Transaction monitoring procedure | Monitoring based on thresholds, patterns, and the customer risk profile | POJK 12/2017 Chapter V |
| 6 | Reporting procedure | How suspicious, cash, and cross-border reports are filed with PPATK through goAML | Law 8/2010 Article 23; Government Regulation 43/2015 |
| 7 | Customer risk management | Risk categorisation (low/medium/high), the assessment matrix, and management procedure | POJK 12/2017 Articles 11-13 |
| 8 | Document retention | The obligation to retain records for at least 5 years after the business relationship ends | Law 8/2010 Article 22 |
| 9 | Training programme | Mandatory APU-PPT training for all staff, its frequency, and its content | POJK 12/2017 Chapter VI |
| 10 | APU-PPT internal audit | How the SOP's effectiveness is reviewed and tested periodically | POJK 12/2017 Chapter VII |
Each component must be set out as a clear procedure, complete with a flowchart, standard forms, and completion deadlines. Let us look at three principal SOPs in detail.
SOP Example 1: KYC/CDD Procedure for New Customers
The CDD (Customer Due Diligence) or KYC (Know Your Customer) procedure is the first line of defence in an APU-PPT system. This SOP governs how a financial institution identifies, verifies, and risk-assesses a customer before the business relationship begins.
Scope
This SOP applies to new account opening, credit applications, purchase of investment or insurance products, and the start of any business relationship with an individual or corporate customer.
Procedure Steps
- Collect identity documents
- Individual customers: national ID or passport, tax number, proof of address, employment and source of income information
- Corporate customers: incorporation deed, business identification number or trading licence, corporate tax number, the list of directors and shareholders, and the latest financial statements
- Beneficial owner: identify beneficial owners holding ≥ 25% or otherwise exercising control over the company
- Verify identity
- Individuals: match the ID photograph to the customer, verify the national ID number against the civil registry (where available), validate the tax number
- Corporates: check legal entity status with the company registry, verify the business identification number in the licensing system, confirm the current board composition
- Screening: match the customer and beneficial owner names against the domestic terrorist list (DTTOT), the UN sanctions list, OFAC, the EU sanctions list, and the internal PEP database
- Assess customer risk
- Use the risk matrix (see the Risk Matrix Template) to determine the risk category
- Assessment factors: customer profile, products used, geographic region, and planned transaction volume
- Output: a low, medium, or high risk categorisation
- Acceptance decision
- Low risk: Approved by the Customer Service Officer, normal processing
- Medium risk: Approved by the Branch Manager, periodic monitoring
- High risk: Escalated to the know-your-customer unit for EDD, approved by the Compliance Director
- Rejection: Where the customer appears on a sanctions or terrorist list, cannot be verified, or refuses to provide mandatory information
- Documentation and archiving
- All CDD documents are stored in the customer document system
- The decision and the reasoning for acceptance or rejection are documented
- Retention: at least 5 years after the business relationship ends
- Periodic refresh (ongoing CDD)
- Low risk: review every 3 years
- Medium risk: review annually
- High risk: review every 6 months or whenever there is a material change
SLAs and Accountability
| Stage | Accountable | SLA |
|---|---|---|
| Document collection | Customer Service Officer | Same day |
| Identity verification | Back office / operations | 1 working day |
| Sanctions and PEP screening | Compliance unit | 1 working day |
| Risk assessment | Compliance Officer | 1 working day |
| EDD (if high risk) | Know-your-customer unit | 5 working days |
| Final approval | Branch Manager / Compliance Director | 1 working day |
SOP Example 2: Transaction Monitoring Procedure
Transaction monitoring is the continuous process of detecting unusual or suspicious financial activity. This SOP governs the automated and manual monitoring a financial institution must apply.
Types of Monitoring
A. Threshold-Based Monitoring
The system automatically flags transactions exceeding set limits:
- Cash transactions ≥ IDR 500,000,000 (the cash reporting threshold)
- Cross-border transfers ≥ IDR 100,000,000 (the cross-border reporting threshold)
- Transactions worth ≥ 50% of the customer's total assets or turnover in a single month
- Cumulative cash ≥ IDR 1,000,000,000 in one calendar month
B. Pattern-Based Monitoring (Pattern Detection)
The compliance team must detect the following patterns:
- Structuring (smurfing): Split transactions consistently just below the reporting threshold
- Layering: Repeated transfers between accounts with no clear business purpose
- Rapid movement: Funds in and out within a short window (24-48 hours)
- Round-tripping: Funds transferred abroad then returned through a different route
- Dormant account activity: An account inactive for ≥ 6 months suddenly receiving a large transaction
C. Risk Profile-Based Monitoring
- Transactions that deviate significantly from the customer's historical transaction profile
- A change in transaction pattern for a high risk customer
- Transactions involving a high-risk country or jurisdiction (the FATF list)
Escalation Procedure
- Initial detection (Level 1) — The AML system or operational staff flag a suspicious transaction. An alert is raised in the monitoring system.
- Initial analysis (Level 2) — A compliance analyst reviews within 1 working day: checking the customer profile, transaction history, and business plausibility. Outcome: dismiss (false positive) or escalate.
- Investigation (Level 3) — A senior compliance officer investigates in depth within 3 working days: contacting the relationship manager, seeking customer clarification (without tipping off), and performing EDD where required.
- Decision (Level 4) — The head of the know-your-customer unit decides within 2 working days: close the case (documenting the reasoning), report to PPATK as a suspicious transaction, or take other action (transaction restriction, account closure).
Optimise Your Transaction Monitoring System
On the KYC & AML Compliance Professional course, participants practise analysing suspicious transaction alerts using real case studies from Indonesian banking and fintech.
SOP Example 3: PPATK Reporting Procedure
Reporting to PPATK is the critical final stage of the APU-PPT cycle. Late or inaccurate reporting can bring administrative sanctions from OJK as well as criminal penalties under Law 8/2010.
The Internal Reporting Chain
| Stage | Owner | Action | Deadline |
|---|---|---|---|
| 1. Detection | Front-line staff / AML system | Identify the suspicious transaction, complete the internal initial report form | Same day (D+0) |
| 2. Verification | Compliance analyst | Verify the transaction data, complete the customer information, gather supporting documents | D+1 |
| 3. Analysis | Compliance officer | Analyse the suspicion, determine the indicators, draft the report narrative | D+1 to D+2 |
| 4. Approval | Head of the know-your-customer unit | Review and approve the report, confirming completeness and quality | D+2 |
| 5. Filing | goAML reporting officer | Enter the report in the PPATK goAML system and attach supporting documents | D+2 to D+3 |
| 6. Confirmation | Compliance officer | Confirm the report was received (receipt number), archive the filing evidence | D+3 |
Report Types and Timelines
| Report Type | Trigger | Deadline | Channel |
|---|---|---|---|
| Suspicious Transaction Report (LTKM) | Suspicion indicators met | 3 working days from identification | goAML |
| Cash Transaction Report (LTKT) | Cash transaction ≥ IDR 500 million | 14 working days | goAML |
| Cross-Border Transfer Report (LTKL) | Transfer ≥ IDR 100 million | 14 working days | goAML |
Confidentiality (Anti Tipping Off)
Strict rules apply throughout the reporting process:
- The customer must not be told their transaction is being reported
- Reporting information is known only to those in the reporting chain
- Reporting documents are stored separately from ordinary customer files
- Internal communication about a report uses an internal code, not the customer's name
- Tipping off carries up to 5 years imprisonment and a fine of IDR 1 billion (Article 14, Law 8/2010)
Mandatory Documentation
- A copy of the goAML report with its receipt number
- The internal initial report form
- Supporting documents (statements, transaction slips, CDD/EDD results)
- A chronological record of the investigation
- Evidence of approval by the head of the know-your-customer unit
- All documents retained for at least 5 years after filing
Customer Risk Matrix Template
The risk matrix categorises customers by money laundering risk. The result determines the level of CDD applied and the monitoring frequency.
| Risk Factor | Low (Score 1) | Medium (Score 2) | High (Score 3) |
|---|---|---|---|
| Customer identity | Indonesian citizen, identity complete and verified | Indonesian citizen with incomplete documents; foreign national from a non-FATF-listed country | Foreign national from a FATF high-risk country; identity difficult to verify |
| PEP status | Not a PEP | Family member or close associate of a PEP | Active PEP (state official, state-owned enterprise, political party) |
| Type of business | Permanent employee, civil servant, retiree | Trader, contractor, liberal profession | Cash-intensive business (money changer, car dealer, property) |
| Product/service | Ordinary savings, small deposits | Consumer credit, premium credit card | Private banking, trusts, large international transactions |
| Geography | Major Indonesian cities, low-risk countries | Border regions, ASEAN countries | FATF high-risk countries, tax havens, conflict zones |
| Transaction volume | Consistent with the income profile | Occasionally exceeds the profile (< 2x) | Frequently exceeds the profile (≥ 2x) without explanation |
| Beneficial owner | Clear and identified | Layered ownership structure (2-3 levels) | Complex structure, nominees, or an unidentified ultimate beneficial owner |
How to Use the Matrix
- Score each risk factor 1-3
- Total the scores (range: 7-21)
- Categorise: 7-11 = low risk, 12-16 = medium risk, 17-21 = high risk
- Document the assessment in the customer profile
- Apply the level of CDD matching the risk category
5 Fatal Mistakes in an APU-PPT SOP
These are the mistakes OJK auditors find most often during an APU-PPT compliance examination. All five can lead to serious sanctions:
| No | Fatal Mistake | Consequence | Remedy |
|---|---|---|---|
| 1 | An SOP that exists only on paper and is never followed | Warnings through to fines; no evidence of execution at audit | Apply a daily checklist for each procedure; require the performer's signature at every stage |
| 2 | No periodic SOP update | The SOP falls out of step with current regulation; material audit findings | Schedule an SOP review at least every 12 months or whenever regulation changes; record the version and revision date |
| 3 | Sanctions and PEP screening not applied consistently | High-risk customers pass through without EDD; potential terrorism financing | Automate screening through the AML system; re-screen whenever the sanctions lists are updated |
| 4 | Threshold monitoring relying solely on the automated system | Structuring patterns below the threshold go undetected | Combine automated monitoring with manual review by a compliance analyst; set a secondary threshold for pattern detection |
| 5 | APU-PPT training inadequate or undocumented | Staff fail to recognise red flags; audit findings on personnel | Run training at least annually for all staff; document the attendance list, the material, and the assessment results |
Audit-Ready APU-PPT SOP Checklist
Use this checklist to confirm your APU-PPT SOP is ready for an OJK examination or internal audit:
- The SOP document exists and is the current version — Check the last revision date; confirm it is under 12 months old or aligned to the latest applicable regulation.
- Board approval is documented — The SOP must be signed by at least one board member, with the approving meeting minutes available.
- The know-your-customer unit structure is clear — Appointment letters for the unit head, the compliance officer, and the goAML reporting officer are documented and current.
- The CDD procedure is complete — Covering individual customers, corporates, walk-in customers, and beneficial owners. Standard CDD forms are available.
- An EDD procedure exists for high-risk customers — The triggers for EDD are clear; the senior management approval procedure is documented.
- The customer risk matrix is current — Assessment parameters reflect current conditions; low/medium/high categorisation is defined.
- Transaction monitoring is operational — Evidence of reviewed alerts and documented dismiss/escalate decisions.
- PPATK reporting records are complete — Copies of every report with their receipt numbers are properly filed.
- Evidence of staff training — Attendance lists, training materials, and certificates for the last 12 months are available.
- Screening databases are up to date — The latest sanctions and terrorist lists from PPATK; the internal PEP list refreshed.
- Document retention meets the requirement — Evidence of 5-year retention; a disposal mechanism for documents past the retention period.
- Previous APU-PPT internal audit results — The audit report, findings, and remediation follow-up are documented.
Prepare Your Team for the Next OJK Audit
The KYC & AML Compliance Professional course from Frans Training provides practical guidance on drafting an SOP, an OJK examination simulation, and industry-recognised certification. Register now for the next available class.
Adapting the Template by Institution Type
The SOP templates above are written for a banking context. Other financial institutions (insurers, pension funds, fintechs, P2P lenders) need to adjust the approval authority, monitoring thresholds, and risk parameters to their own business characteristics and sectoral regulation. OJK circular letters provide the technical implementation guidance that complements the POJK.
FAQ
Is an APU-PPT SOP mandatory for every financial institution?
Yes. Under POJK 12/2017, every financial services provider registered with OJK must maintain a written APU-PPT SOP. That covers commercial banks, rural banks, insurers, pension funds, securities firms, investment managers, financing companies, and registered or licensed fintechs. Not having a written SOP is a breach that can attract sanctions from a warning through to revocation of the operating licence.
How often must the APU-PPT SOP be updated?
OJK requires a review at least every 12 months. The SOP must also be updated promptly whenever there is: a regulatory change (a new POJK, government regulation, or law), an organisational change, a new product or service, an audit finding requiring a procedural fix, or a change in monitoring system technology. Every revision must record the version number, the revision date, and board approval.
What are the sanctions for not having an APU-PPT SOP?
Sanctions escalate under Law 8/2010 and POJK 12/2017: a written warning as the initial step, an administrative fine (varying by breach), restriction of business activity, and ultimately revocation of the operating licence for repeated or serious breaches. Directors and compliance officers can also face personal sanctions barring them from holding office at a financial institution.
Do fintechs (P2P lending, e-wallets) also need an APU-PPT SOP?
Yes. Fintechs registered or licensed with OJK fall within the financial services provider category and must run an APU-PPT programme. POJK 77/2016 (for P2P lending) and POJK 12/2017 explicitly cover digital financial services. Fintechs face an additional challenge, in that customer onboarding is often entirely digital, so e-KYC procedures have to be tighter still.
How do you train non-compliance staff on APU-PPT?
APU-PPT training must be given to all staff, not only the compliance team. For front-line staff (tellers, customer service), focus on recognising red flags and the escalation procedure. For operations staff, emphasise adherence to verification and documentation procedure. Use real case studies relevant to their role. OJK requires training at least once a year with complete documentation. Consider certified training from a professional body to raise the team's competency further.