AML Compliance in Jordan: A Guide for Banks and Payment Institutions
Jordan’s anti-money laundering regime has tightened steadily over the past decade, and the operational burden now falls hardest on the institutions doing the most onboarding: banks, payment service providers, exchange houses and the fintechs licensed alongside them. This guide sets out who is covered, what the obligations actually require in practice, and where compliance programmes most often fall short.
This is general information, not legal advice. Requirements change — confirm current obligations against Central Bank of Jordan instructions and AMLU publications before relying on them.
Who has to comply
Jordan’s AML/CFT obligations reach well beyond banks. The regime covers:
- Banks and financial institutions licensed by the Central Bank of Jordan (CBJ)
- Payment service providers and e-wallet operators — a fast-growing category as Jordan’s digital payments market expands
- Exchange houses and money transfer businesses
- Insurance companies and securities firms regulated by the Jordan Securities Commission
- Designated non-financial businesses and professions (DNFBPs) — lawyers, accountants, real estate agents, dealers in precious metals and stones
If your institution establishes customer relationships, moves value, or holds funds on behalf of others, you are almost certainly in scope.
The legal framework
Three layers matter:
1. The primary law
Jordan’s Anti-Money Laundering and Counter-Terrorist Financing Law establishes the criminal offences, the reporting duties and the supervisory architecture. It has been amended several times since its introduction, progressively widening the definition of predicate offences and strengthening beneficial ownership requirements.
2. The AMLU
The Anti-Money Laundering and Counter-Terrorist Financing Unit is Jordan’s financial intelligence unit. It receives suspicious transaction reports, analyses them, and refers cases to prosecutors. Your reporting obligations run to the AMLU.
3. Sector instructions
The Central Bank of Jordan issues binding AML/CFT instructions for the institutions it supervises. These translate the general law into specific operational requirements — what documents to collect, how to risk-rate customers, how long to keep records. For banks, CBJ instructions are the document your examiners will hold you against.
What compliance actually requires
Customer due diligence
Before establishing a relationship you must identify the customer and verify that identity from reliable, independent sources. For individuals in Jordan that ordinarily means the national ID card or passport, checked for authenticity rather than merely collected. For corporate customers, you must identify the beneficial owners behind the legal entity — the natural persons who ultimately own or control it.
This last requirement is where many programmes are weakest. Collecting a commercial registration certificate is not beneficial ownership verification.
Enhanced due diligence
Higher-risk relationships require more. Politically exposed persons, non-resident customers, complex ownership structures, and customers from higher-risk jurisdictions all trigger enhanced measures: source of funds evidence, senior management approval, and closer ongoing scrutiny.
Ongoing monitoring
Verification at onboarding is the beginning, not the end. You must monitor transactions against the customer’s expected profile and keep customer information current throughout the relationship. Regulators increasingly ask not whether you have a monitoring system, but whether it actually detects anything.
Record keeping
Customer identification records and transaction records must be retained for a minimum of five years, and must be retrievable — an archive you cannot search within a reasonable time is not a compliant archive.
Suspicious transaction reporting
When you form a suspicion, you must report it to the AMLU promptly — the framework contemplates reporting within a few business days of detection, not at the end of a review cycle. Tipping off the customer is a criminal offence.
Penalties
Non-compliance carries administrative fines, criminal liability including custodial sentences for serious breaches, and licence revocation. In practice, the licence risk is what concentrates minds: for a payment institution, a suspension is an existential event in a way that a fine is not.
Where programmes fall down
Manual verification that doesn’t scale. A compliance team checking ID documents by eye can handle tens of onboardings a day, not thousands. As volume grows, either throughput collapses or checks get skipped.
Arabic document handling. Jordanian national IDs, commercial registrations and supporting documents are Arabic-language, frequently bilingual, and often submitted as phone photographs. Verification tooling built for Latin-script documents produces high failure rates on exactly the documents you process most.
Screening noise. Arabic names transliterate inconsistently — the same person may appear as Mohammed, Mohamed, Muhammad or Mohammad across lists. Naive matching generates false positives in volume, and analysts drowning in alerts miss the real ones.
Point-in-time thinking. A customer verified at onboarding and never reviewed again is a gap that examiners now probe directly. Sanctions lists change; customer circumstances change.
Building a programme that holds up
A workable Jordanian compliance stack needs four things working together:
- Document capture and authentication that reads Arabic natively and detects tampering, not just extracts text
- Identity verification that binds the document to the person presenting it, through biometric matching and liveness detection
- Screening against sanctions, PEP and adverse media sources, tuned for Arabic name variation
- Ongoing monitoring that re-screens on list changes and behavioural triggers rather than on a calendar
The value is in the integration. When these are four separate vendors, the risk engine never sees the whole customer — and the audit trail is stitched together after the fact.
Frequently asked questions
Is remote onboarding permitted in Jordan?
Digital onboarding is well established in the Jordanian market, subject to the verification standards set by the CBJ for the relevant licence category. The requirement is not physical presence but reliable verification — which is precisely what document authentication and biometric matching are for.
How long must records be kept?
A minimum of five years is the baseline expectation, measured from the end of the relationship or the date of the transaction. Some categories carry longer expectations, so check the instructions for your licence type.
What is the difference between CDD and EDD?
Customer due diligence is the standard set of checks applied to every customer. Enhanced due diligence is the additional layer for higher-risk relationships — PEPs, complex structures, high-risk jurisdictions — and typically adds source of funds evidence and senior approval.
Do we need to screen existing customers, or only new ones?
Both. Sanctions and PEP lists update continuously, and a customer who was clear at onboarding may not be clear today. Periodic or event-driven re-screening of the existing book is an expectation, not an optional extra.
Is Jordan on the FATF grey list?
Jordan is a member of MENAFATF and participates in the regional evaluation process. Grey-list status changes over time following mutual evaluations — check the current FATF statement rather than relying on any published summary, including this one.
How iPass helps
iPass is built for exactly this market. Our Arabic and English OCR reads Jordanian national IDs, commercial registrations and handwritten documents natively. Identity verification binds the document to the person through biometric matching and liveness detection. AML screening and perpetual KYC monitoring checks against sanctions, PEP and adverse media sources with contextual risk scoring built to handle Arabic name variation.
One platform, one audit trail. See pricing or talk to our team.