
Saudi Arabia’s Council of Ministers approved amendments to its AML Law in April 2026, touching five articles and adding one new one. Key changes include immigration consequences for convicted non-Saudi nationals, expanded asset confiscation powers, a formalised national risk policy function under the Permanent Committee, and a recalibrated approach to NPO oversight. No grace period has been signaled. Firms should update governance documentation now rather than waiting for the implementing regulations that follow.
On 17 April 2026, Saudi Arabia’s Council of Ministers approved amendments to the Kingdom’s Anti-Money Laundering Law — the statute issued under Royal Decree No. (M/20) in 1439H in the Islamic calendar (2017) that has anchored the country’s financial crime framework ever since. The changes mark a clear shift toward a more assertive, risk-based compliance posture, which includes stricter border controls for convicted individuals, broader confiscation and seizure powers, and heightened transparency expectations for both legal entities and financial institutions. The law itself isn’t being replaced, but its character is changing.
This analysis is aimed at compliance officers, MLROs, and financial crime leaders at financial institutions and corporates operating in or with exposure to Saudi Arabia and the wider Gulf Cooperation Council (GCC). The changes are modest in word count but meaningful in direction. Here’s what changed, what it means in practice, and what FIs and corporates should be doing about it now.
The amendments touch five articles and add one new one.
Underneath the legal language, the broader direction reported alongside the amendments is unmistakable: tighter border controls for convicted individuals and an expanded confiscation and seizure regime, including exposure for unexplained assets disproportionate to lawful income where linked to criminal conduct.
This is less about adding new regulated activities and more about recalibrating who bears direct statutory weight and how aggressively the state can act once a conviction is secured.
There is currently no published phased compliance timetable, grace period, or remediation window attached to these amendments. The changes took legal effect through publication of the Royal Decree, and regulated entities are expected to reflect the updated scope and structure of the law in their AML policies, procedures, and training materials going forward.
What that means practically:
Technology and System Changes Required for Saudi AML Compliance Because the amendments are currently institutional and definitional rather than technical, the immediate build list is shorter than a full regulatory overhaul would demand, but it still touches core control infrastructure:
It’s tempting to read this alongside the EU’s AMLA harmonization programme, where the AML Regulation is now being layered with Regulatory and Implementing Technical Standards and Guidelines through 2026 and beyond, and there is a genuine echo: both reflect a pattern of hardening enforcement and institutional mandate ahead of the granular technical detail, which arrives later through a separate rule making track. However, the resemblance stops there. AMLA is building new supranational supervisory infrastructure across 27 member states, while Saudi Arabia’s amendments tighten and clarify an existing single-jurisdiction law without creating any equivalent new layer of binding technical standards.
These amendments are a calibration, not a rebuild. The direction is consistent with where Saudi Arabia has been heading since joining FATF in 2019: more assertive enforcement, sharper individual accountability, and an increasingly formalised risk-based policy apparatus. Saudi Arabia’s 2018 FATF Mutual Evaluation, conducted ahead of its full membership, which identified deficiencies in beneficial ownership transparency and financial institution supervision, has been the engine driving successive rounds of AML reform, including these amendments. The technical detail that will determine real operational uplift (the updated Implementing Regulations, Permanent Committee risk guidance) hasn’t landed yet. The entities that move now to align governance and documentation, rather than waiting for that next layer, will be the ones with the shortest gap to close when it does.
SymphonyAI helps financial institutions operating across EMEA and the GCC build the AML controls, risk-rating infrastructure, and governance frameworks that regulators increasingly expect. Explore how Symphony Risk Intelligence supports financial crime compliance across jurisdictions.
UAE AML/CFT 2026: What financial institutions need to know
The UK’s New Fraud Strategy 2026-2029: What it means for financial crime and compliance
Webinar Replay: From Regulation to Action: Getting EU AMLA-ready
Agentic AI & Embedded Risk Intelligence – Leader’s Guide
FCA Insurance Financial Crime Review 2026: Six Findings Insurers Needs to Act On
Find out more about Symphony Risk Intelligence and Always-on Compliance, and how it can improve your approach to transaction monitoring, KYC/CDD, fraud, and screening.