سه‌شنبه 27 مرداد 1405   15:26:12

Amendment date: 14.08.1404 SH
Corresponding to: 05.11.2025

Executive By-Law on

Combating and Preventing Money Laundering and Terrorist Financing Offences

The Council of Ministers, in its session dated 19.10.2025, upon the proposal of the High Council of Preventing and Combating Money Laundering and Terrorist Financing Offences and with the approval of the Head of the Judiciary, pursuant to Article (14) of the Amended AML Act ratified in (2018), adopted the following.

Chapter One – Definitions

Article 1
For the purposes of this By-Law, the following terms shall have the following meanings:
1.Act: The Anti-Money Laundering Act, ratified in (2008) and its subsequent amendments and supplements.
2.Council: The High Council of Preventing and Combating Money Laundering and Terrorist Financing Offences, referred to in Article (4) of the Act.
3.Center: The Financial Intelligence Center, referred to in Article (7) bis of the Act.
4.AML Unit: The Anti-Money Laundering and Counter-Terrorism Financing Unit, which is in charge of combating money laundering and terrorist financing and is established within the internal structure of the obliged persons, and is responsible for performing the obligations set forth in Article (38) of this By-Law.
5.Financial Institution: Obliged persons who conduct as a business or commercial activity, one or more of the following financial operations for or on behalf of a customer:
  1. Acceptance of deposits or other repayable funds from the public;
  2. Lending or offering other banking services or operations;
  3. Financial leasing or related services;
  4. Money or value transfer services or financial services and the payment of a corresponding sum in cash or other forms by means of a communication, message, transfer, or through a clearing network;
  5. Issuing and managing means of payment (e.g., credit and debit cards, cheques, traveler’s cheques, money orders, electronic money);
  6. Financial guarantees and commitments;
  7. Trading in:
  1. Money market instruments (cheques, bills, certificates of deposit, derivatives, etc.);
  2. Foreign exchange (Forex);
  3. Exchange, interest rate and index instruments;
  4. Securities;
  5. Commodity futures trading;
  1. Participation in securities issues and the provision of financial services related to such issues;
  2.  Individual and collective portfolio management;
  3. Safekeeping and administration of cash or liquid securities on behalf of other persons;
  4. Otherwise investing, administering, or managing funds or money on behalf of other persons;
  5. Life insurance-related services and other investment-related insurance services;
  6. Currency exchange operations (including the purchase and sale of foreign currency and coins, foreign-currency remittance operations carried out directly and/or through credit institutions, and the provision of cross-border foreign exchange services through agents, within the framework of foreign exchange laws and regulations) or services related to the exchange of money and currency.
  7. Payment system services and fintech-based services.
  8. Virtual asset services, including:
  1. Exchange between virtual assets and Iranian Rials or other fiat currencies and vice versa.
  2. Exchange between one or more forms of virtual assets;
  3. Transfer of virtual assets;
  4. Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets;
  5. Participation in and provision of financial services related to an issuer’s offer and/or sale of virtual assets.
  1. Without Delay: Within one business day, provided that it does not exceed (48) hours.
  2. Designated Non-Financial Businesses and Professions (DNFBPs):
  1. Real estate agents and brokers;
  2. Car dealers and brokers;
  3. Dealers in gold, silver, and coins;
  4. Dealers in precious metals and stones;
  5. Dealers in antiques, art works, and high-value handicrafts;
  6. Dealers in high-value handmade carpets;
  7. Notaries and their deputies;
  8. Independent accountants, certified auditors, and audit firms;
  9. Lawyers, independent legal professionals, or legal professionals employed in law firms;
  10. Other high-risk businesses and professions designated by the Council in line with paragraph (E) of article (1) of the Act.
  1. Obliged Persons: The persons subject to articles (5) and (6) of the Act.
  2. Supervisory Authorities: The supervisory authorities are as follows:
  1. Financial sector supervisors include:
  • Central Bank of the Islamic Republic of Iran;
  • Central Insurance of the Islamic Republic of Iran;
  • Securities and Exchange Organization.
  1. DNFBPs supervisors include:
  • Ministry of Industry, Mine, and Trade;
  • State Organization for Registration of Deeds and Properties;
  • Bar Associations and the Center for Lawyers, Official Experts, and Family Advisors of the Judiciary;
  • Iranian Association of Certified Public Accountants.
  1. other authorities and bodies designated by the Council, which pursuant to laws and regulations, entrusted with the responsibility to issue licenses for financial institutions and DNFBPs, supervising their compliance with AML/CFT regulations and effective implementation of related obligations, and exercising administrative or disciplinary sanctioning powers in case of non-compliance.
  1. Supervised Obliged Persons: Any obliged person that, under the supervision of a supervisory authority, is responsible for implementing AML/CFT requirements.
  2. Customer: Any natural or legal person (whether principal, attorney, or legal representative) seeking to receive services & benefits, transactions, asset transfers, credit facilities, or any economic and financial activities from obliged persons.
  3. Suspicious Transactions and Activities: Any transaction, receipt, or payment of funds, whether physical or electronic, or attempted transaction, which reasonably raises suspicion of criminal activity based on circumstances such as value, subject, or parties involved, such as:
  1. Financial transactions or operations of a customer that are meaningfully beyond the expected level of his/her activities;
  2. The detection of forgery, false declarations, and/or false statements by the customer, before or after any transaction has occurred, and also at the time of obtaining basic services.
  3. Financial transactions or operations that are revealed, in any way, that are fictitious or nominal, and the beneficial owner is another person.
  4. Financial transactions or operations with one party located in high-risk jurisdictions (as far as AML/CFT is concerned)
  5. Financial transactions and operations above the designated threshold; no matter whether the customer has withdrawn from conducting the transaction or operation before or during its execution, or, after the transaction is completed, cancels the contract with no logical reason.
  1. Designated Threshold: The threshold amount prescribed under the Law on the Holding of Tenders, for conducting micro transactions, in the form of cash (Rial) or its equivalent in other currencies or precious commodities, as approved annually by the Cabinet pursuant to Note (1) to Article (3) of the Law on the Holding of Tenders.
  2. Beneficial Owner: Any natural person(s) who is the ultimate owner or controls a customer, directly or indirectly, or on whose behalf a transaction or operation is being conducted. It also refers to those who exercise ultimate effective control over a legal person. It includes beneficiaries of life or other investment-related insurance, too.
  3. Central Bank Payment Systems: Including CBI systems such as SATNA (Real-Time Gross Settlement System), SHETAB (The Iran National Interchange Card Payment Switch), PAYA (Automated Clearing House), and SHAPARAK (the Electronic Card Payment Network), through which macro and micro electronic payments in the banking system are being conducted.
  4. High-Risk Jurisdictions: Countries and jurisdictions with higher ML/TF risks, as designated by the NRA working group.
  5. Payment Service Provider (PSP): Any company licensed by the Central Bank of the Islamic Republic of Iran to provide payment services.
  6. Watchlist: All persons whose names and particulars are designated by the Center for the purpose of monitoring their possible links to ML/TF activities, and whose names and particulars are communicated by the Center or the supervisory authority to the obliged persons under supervision.
  7. Suspected Persons: Persons whose names and particulars are communicated by the Center to obliged persons due to suspicion of their links to ML/TF activities, so that the provisional measures set out in this By-Law may be applied to them in order to mitigate ML/TF risks.
  8. Virtual Asset: A digital representation of value that can be digitally traded, or transferred, and can be used for payment or investment purposes. Virtual assets do not include digital representations of fiat currencies, securities, or other assets.
  9. Deleted
  10. Deleted
  11. National Risk Assessment (NRA): A report in which, through the examination of existing vulnerabilities and threats across the main sectors, the risks of ML/TF in each sector are assessed, and measures and actions are adopted to control and mitigate the identified risks.
  12. Main Sector: Including but not limited to the banking system, capital market, insurance market, DNFBPs, NPOs, currency exchange bureaus, and any other sector which, as determined by the NRA Working Group, are assessed as presenting high risks of ML/TF.
  13. Business Relationship: Interaction between an obliged person and a customer at a specific geographic location for offering services or conducting transactions.
  14. Customer Risk: The ML/TF risks arising from a customer, to which the obliged person is exposed due to factors such as the customer’s social and occupational position, financial status, type and nature of business, background, and country of origin.
  15. Geographic Risk: The ML/TF risks to which the obliged person is exposed due to the geographical location where the business relationship takes place.
  16. Product/Service Risk: The ML/TF risk to which the obliged person is exposed due to the type or the delivery channel through which a service or transaction is provided to a customer in a business relationship.
  17. Basic Services: Services which, as per the related regulations, constitute prerequisites for providing other services by obliged persons, and then the customer refers to the obliged persons for the purpose of obtaining ongoing and frequent services.
  18. Non-Basic Services: Any service other than those defined as Basic Services in paragraph (29) of this Article.
  19. Cash: Any coin and banknote in circulation, and any type of cheque, whose transfer is undocumented and untraceable, including bearer cheques and other cheques whose holder is not the original beneficiary (such as cheques endorsed by third-party, cashier’s cheques, traveler’s cheques), as well as anonymous payment cards and similar instruments. Cash funds include both Rials and foreign currency.
  20. Property: Every kind of assets, funds or economic resources, whether corporeal or incorporeal, tangible or intangible, movable or immovable, cash or non-cash, legitimate or illegitimate, and any financial interest or benefit and funds whether cash or non-cash, and all legal documents or instruments, both in paper or electronic ones such as commercial documents, shares, or securities, evidencing title to or interest in such assts.
  21. Customer Due Diligence (CDD): The process of obtaining and reviewing customer information for identity verification and assessment of ML/TF risks on an on-going basis. CDD levels are simplified, normal, and enhanced due diligence.
  22. Funds Aggregator: Any legal person engaged in aggregating payments from buyers to sellers, directly or in cooperation with payment service providers (PSPs) or financial institutions within the framework of national laws and regulations. Such entities receive card-not-present payments, including in-app and mobile/virtual infrastructure-based payments, and transmit them to the banking payment systems.
  23. Correspondent Banking: The provision of banking services by one financial institution (correspondent financial institution) to another financial institution (respondent financial institution).
  24. Shell Bank: A bank that has no physical presence in the jurisdiction in which it is licensed and registered and is not affiliated with a regulated financial group subject to effective consolidated supervision, and its mind and management are located in another jurisdiction. A shell bank has no physical presence other than a registered representative office. The agent only affords a place to conduct the legal issues of the bank in the said jurisdiction (countries and regions).
  25. Payment Instrument: Any type of physical or virtual card, or any method or instrument made available by financial institutions to the holder, enabling the holder to receive, make a payment, or transfer of funds to another person.
  26. Acceptance Device: A physical device or an electronic system through which, by using a payment instrument, one may proceed to perform receipt/payment, and/or funds transfer operations.
  27. Acceptor: A person who, by accepting a bank card and by using an acceptance instrument, proceeds to sell goods and/or provide services to cardholders.
  28. Payment Facilitator: A legal person duly registered in accordance with the laws and regulations of the Islamic Republic of Iran that operates, within the framework of the requirements, rules, and executive procedures governing the activities of payment facilitators and supported accepters in the national payment system, on the basis of a contract concluded with the SHAPARAK (the Electronic Card Payment Network).
  29. Foreign Exchange Service Providers: All persons licensed by the Central Bank of the Islamic Republic of Iran to provide services relating to buying, selling, exchanging, and transferring domestic or cross-border funds or values in foreign currencies, such as currency exchange bureaus, banks, and the Iran Currency and Gold Exchange Center.
  30. Deleted
  31. Non-Profit Organizations (NPOs): Non-governmental persons and entities such as social associations, charities, NGOs, groups, associations, institutions, and organizations- regardless of their title- that engages in raising, providing, or disbursing funds or other assets for purposes such as charitable, religious, cultural, educational, scientific, social, medical, or fraternal activities.

Chapter Two – Assessing Risks and Applying a Risk-based Approach

Article 2
The Council shall, within three months of the adoption of this By-Law and for the purpose of assessing ML/TF risks at the national level, establish a National Risk Assessment (NRA) Working Group, comprising supervisory authorities and other competent authorities. The mandate of this Working Group shall be to coordinate activities and arrangements relating to risk assessment in the main sectors.
Note: The National Risk Assessment Working Group shall establish specialized working groups, including threat assessment working group, national vulnerability assessment working group, banking sector vulnerability assessment working group, securities sector vulnerability assessment working group, insurance sector vulnerability assessment working group, vulnerability assessment working group for other financial institutions, and vulnerability assessment working group for designated non-financial businesses and professions (DNFBPs), for the purpose of assessing ML/TF risks. The members of these working groups shall include representatives of the relevant supervisory authorities for each sector, competent authorities, and representatives of supervised obliged persons, whether from the private or public sectors, as designated by the National Risk Assessment Working Group.
Article 3
The National Risk Assessment Working Group shall, within one year of its establishment, prepare the National Risk Assessment (NRA) document in cooperation with the Center and update it at intervals of three to five years.
Note 1: The National Risk Assessment Working Group shall, taking into account the country’s circumstances and through the examination of vulnerabilities and threats in the main sectors, issue the necessary recommendations regarding the application of a risk-based approach to combating money laundering and terrorist financing and the allocation of available resources based on the identified risks, and to promulgate such recommendations to the relevant authorities.
Note 2: The member authorities of the Council and other obliged persons, including Police Command of the Islamic Republic of Iran, the State Organization for Registration of Deeds and Properties, the Department of Environment, the Drug Control Headquarter, the Central Headquarter for Combating Smuggling of Goods and Currency, the Discretionary Punishment Organization, the Organization for Investment & Economic and Technical Assistance of Iran, the Islamic Republic of Iran Customs Administration, and the National Tax Administration, shall provide the statistics, information, and documentation required for the preparation of the National Risk Assessment document within ten (10) days of a request by the Head of the National Risk Assessment Working Group, in compliance with the relevant laws and regulations. The provision of classified intelligence shall be subject to the completion of the applicable investigation procedures.
Note 3: The Head of the Center shall chair the National Risk Assessment Working Group. The secretary of the National Risk Assessment Working Group and the secretaries of the specialized working groups shall be appointed by the Head of the Center and shall be responsible for directing, coordinating, and overseeing meetings and preparing and following up on the minutes of the relevant working group.
Article 4
To mitigate vulnerabilities in the country’s AML/CFT system, the Center shall, within six months after the preparation of the National Risk Assessment document, develop an Action Plan based on the said document and update it at intervals of three to five years. The Action Plan shall include precise and transparent measures for obliged persons, along with a timetable for the implementation of such measures. The Action Plan shall be developed in accordance with international standards, considering the future threat and vulnerabilities scenarios of the national AML/CFT system of the country, as well as the identified risks in various sectors, and shall be proportionate to the available resources and capacities.
Note 1: Supervisory authorities and, in general, obliged persons shall cooperate with the Center, as notified by the Center, for the purpose of determining the necessary AML/CFT measures and assessing the manner of their implementation.
Note 2: The Center shall, within six months following the finalization of the Action Plan, design, implement, and operate a system for managing and controlling the Action Plan and overseeing the implementation of the measures referred to in this Article by the obliged persons, and shall provide supervisory authorities with access to such system.
Note 3: All persons assigned with obligations under the Action Plan shall perform their duties within the specified timeframe and submit reports on the measures taken to the Center in the prescribed format for assessment. Failure to perform assigned obligations within the specified period, failure to submit reports of the measures taken, or the non-acceptability of implemented measures, as the case may be, shall result in the impositions of sanctions stipulated under AML/CFT laws, including Note (3) of Article (4) of the Act, at the discretion of the competent administrative or judicial authorities.
Article 5
The Center shall, in cooperation with supervisory authorities, determine the indicators and documentations required to assess and measure the level of progress in implementing the Action Plan referred to in Article (4) of this By-Law.
Article 6
The Center shall annually prepare a report on existing ML/TF threats and vulnerabilities within the country, as well as on the implementation process of the domestic Action Plan and related challenges and submit it to the Heads of the three branches of the government and the Office of the Supreme Leader. The report shall include recommendations for addressing existing challenges related to the implementation of the National Risk Assessment document.
Article 7
Obliged persons shall develop and implement their internal AML/CFT programs based on a risk-based approach, aligned with the National Risk Assessment document and the Action Plan referred to in Article (4) of this By-Law. Such internal programs shall be updated every three to five years and reported to the Center on a semi-annual basis.
Article 8
To manage ML/TF risks, financial institutions shall, prior to providing any services/products to customers, assess and understand the risk of the business relationship, including customer, geographic, and service risks, and to decide regarding the appropriate measures proportionate to the assessed risk.
Note 1: The provision of non-basic services below the designated threshold shall not require a business relationship risk assessment.
Note 2: For the purpose of business relationship risk assessment, financial institutions shall obtain sufficient information to enable business relationship risk assessment and apply proportionate customer due diligence (CDD) measures. Such information shall include, at a minimum: type of person (natural or legal), nationality, place of residence, activity and legal residence, the origin, destination, expected volume and frequency of transactions and operations, occupation and nature of business, level of income and source of assets, requested or provided services and products, purpose of establishing the business relationship, direct or indirect use of services, and receipt or use of non-face-to-face services.
Note 3: Until the customer’s declared documentation referred to in Note (2) of this Article can be verified through relevant systems in accordance with applicable laws and regulations, responsibility for taking appropriate measures, including validation of those documentations shall rest with the financial institution.
Note 4: Supervisory authorities shall prepare a list of products or services within their respective sectors and assess their ML/TF risks. The list, specifying risk levels, shall be promulgated to financial institutions upon approval by the Center and shall represent the minimum obligatory requirements for financial institutions.
Note 5: Where the Center determines that the risk of a service, product or delivery channel exceeds the acceptable level, obliged persons shall refrain from offering such products or services.
Note 6: Supervisory authorities shall supervise compliance by obliged persons with the requirements of this Article and report their assessment reports to the Center. The Center shall consider such reports in the ranking process referred to in Article (44) of this By-Law.
Note 7: To establish a unified procedure, the Center shall, within six months from the date of adopting this By-Law, issue and promulgate a guidance on the management of business relationship risks.
Article 9
The Center shall, in cooperation with relevant authorities, prepare and update a list of high-risk customers for the purpose of determining customer risk in business relationships with financial institutions and shall make such list available to financial institutions through system-based channels, subject to security considerations. In preparing the list, the Center shall consider, inter alia, the following criteria:
  1. Legal persons with unusual economic activity or complex ownership structures, or whose activities are inconsistent with their stated objectives or subject of activities as stipulated in the articles of association;
  2. Persons whose economic and financial activities are inconsistent with the subject of their activities;
  3. Institutions and companies suspected of operating as shell entities;
  4. Business that are predominantly dealing in cash or quasi-cash instruments such as gold and precious metals as payment instrument;
  5. Persons with prior convictions for ML/TF offenses.
Note 1: Organizations and entities subject to Articles (5) and (6) of the Act, including but not limited to the Organization for Registration of Deeds and Properties, the Administrative and Recruitment Affairs Organization, the Ministry of Interior, the Ministry of Industry, Mine and Trade, the Ministry of Foreign Affairs, the Police Command of the Islamic Republic of Iran, the Central Bank of Iran, the Judiciary’s Statistics and Information Technology Center, the National Organization for Civil Registration, the Iranian National Tax Administration, the Iranian Association of Certified Public Accountants, and security and intelligence bodies, shall provide the Center with access to the information required for the implementation of this Article, in compliance with the National Data and Information Governance Law (2022) and subsequent amendments.
Note 2: Public prosecutors and law enforcement agencies subject of the Act shall notify the Center of high-risk persons for the implementation of the measures referred to in this Article.
Article 9 (bis)
Financial institutions shall, when establishing business relationships with foreign politically exposed persons (PEPs), whether as customers or beneficial owner, in addition to performing normal customer due diligence (CDD) measures, take the following measures:
  1. take reasonable measures to establish the source and origin of funds involved in the business relationship;
  2. Conduct enhanced and ongoing monitoring of transactions and operations to ensure there is consistency between the type and value of transactions and operations conducted with the information obtained under paragraph (a) of this Article;
  3. Obtain senior management approval for establishing or continuing such high-risk business relationships.
Note 1: Financial institutions shall, where appropriate customer due diligence is not possible based on the above measures, refrain from establishing any business relationship.
Note 2: The Center shall, within three months of the adoption of this By-Law, in cooperation with the Ministry of Foreign Affairs, determine and promulgate the criteria for determining whether the customer or beneficial owner is foreign politically exposed persons.
Note 3: The Ministry of Foreign Affairs, in cooperation with the other authorities referred to in Note (2) of Article (21) of this By-Law, shall provide financial institutions with the identity particulars of foreign politically exposed persons through the Integrated Identity Information Database of Foreign Natural and Legal Persons.
Note 4: Financial institutions shall design their software in such a manner as to enable the systematic identification of the persons referred to in this Article.
Note 5: The associates of the persons referred to in this Article and its Notes shall, as the case may be, include the following and shall be subject to the provisions of this Article:
  1. parents, siblings, spouse, children, persons under guardianship or custodianship, children’s spouses, and grandchildren;
  2. legal persons in which more than ten percent (10%) of the shares are owned by the persons referred to in this Article;
  3. legal arrangements in which one of the parties is a person referred to in this Article;
  4. shareholders holding more than ten percent (10%) of commercial companies in which the persons referred to in this Article hold more than ten percent (10%) ownership;
  5. informal partners and persons who directly participate in the commercial or financial activities of the persons referred to in this Article;
  6. contractual representatives of the persons referred to in this Article.
Note 6: The Administrative and Recruitment Affairs Organization shall, in cooperation with the competent law enforcement authorities referred to in the Act, supervisory authorities, the State Organization for Registration of Deeds and Properties, the Ministry of Foreign Affairs, and the National Organization for Civil Registration, establish and update the database relating to this Article and to provide the necessary access to the Center and financial institutions. With respect to financial institutions, access shall be limited in such a manner as to determine only whether a person is subject or not subject to this Article.
Note 7: The persons referred to in this Article shall remain subject to the measures of this Article for two years after the termination of their functions in the relevant positions.
Note 8: The implementation of the measures set out in this Article with respect to the persons subject to Article (71) of the Civil Service Management Act (2007), and its subsequent amendments, shall be mandatory in cases where the business relationship presents a high risk.
Article 10
Obliged persons shall, with respect to business relationships assessed by the Center as high risk, act in accordance with the procedures communicated by the Center.
Article 11
The Center shall compile the list of high-risk geographic areas based on indicators such as the following and, after approval by the National Risk Assessment Working Group, to promulgate them to financial institutions:
  1. geographic areas such as custom zones, free trade zones, and certain border areas exposed to ML/TF risks;
  2. countries identified as not having adequate AML/CFT systems;
  3. countries identified as having high levels of corruption or criminal activity;
  4. countries or areas identified as providing financing or support for terrorist acts, or countries where terrorist organizations operate.
Note 1: The list of high-risk geographic areas shall be updated by the Center at intervals of three to five years.
Note 2: Obliged persons shall, immediately upon receipt of the list of high-risk geographic areas, update the previous lists in such a manner that the names of such geographic areas, together with the latest amendments thereto, are at all times available to the relevant staff.
Article 12
Obliged persons shall design their software in such a manner that services are provided only after the necessary information for determining the risk of business relationships has been recorded. Information relating to high-risk business relationships shall also be recorded in such software and, upon request by the Center, the relevant reports shall be submitted in the manner determined by the Center.
Article 13
Obliged persons shall continuously and systematically monitor high-risk business relationships and shall submit the information related to such relationships to the Center in accordance with the procedures communicated by the Center.
Article 14
Obliged persons shall supervise the implementation of regulations and internal AML/CFT programs, including the proportionality of the measures taken to the level of risk of business relationships, at all their levels (branches, general directorates, etc.), and, upon observing any deviation, to take corrective action and remedy such deviation.
Article 15
Obliged persons shall, when providing services to persons through domestic intermediaries, take into account the manner of implementation of AML/CFT regulations by such intermediaries in assessing the risk level of business relationships.

Chapter Three – National Cooperation and Coordination

Article 16
The National Organization for Civil Registration shall, within six months after the approval of this By-Law, develop the Integrated Database of Identity Information of Iranian Natural Persons in such a manner that online and unrestricted inquiry into the latest basic identity information and their related persons is always made available to obliged persons.
Note 1: With respect to natural persons, the basic identity information items shall at minimum include the national identification number, first name and surname, father’s name, date of birth, life status, date of death, and the verified residential postal code; and the information items concerning related persons shall at minimum include the basic identity information items of first-degree relatives by blood or marriage, the type of relationship, the commencement date of the relationship, and the duration of its validity. Other required information shall be determined by the Center as deemed necessary.
Note 2: The National Organization for Civil Registration shall provide changes in the basic identity information of persons and the list of cancelled or suspended IDs, together with the date and reason for cancellation or suspension, on a daily basis to the supervised obliged persons.
Note 3: The Ministry of Health and Medical Education and the Legal Medicine Organization of Iran and their subordinate organizations and companies shall provide the necessary information for the implementation of this Article to the National Organization for Civil Registration on an online basis.
Note 4: The procedure for inquiring the address of Iranian natural persons shall be arranged in such a way by the National Organization for Civil Registration that upon submission of the national identification number, the corresponding postal code shall be provided. Furthermore, the National Organization for Civil Registration shall provide all necessary arrangements to require Iranian nationals to update their postal address pursuant to the Note to Article (3) of the Law on Mandatory Allocation of National Identification Number and Postal Code for All Iranian Nationals adopted in (1997).
Article 17
The Ministry of Information and Communications Technology shall, in cooperation with the Ministry of Interior, within one year after the approval of this By-Law, launch the Location-based Address System for natural and legal persons in such a manner that, while standardizing addresses, it enables obliged persons to inquire and display geographic location on a map in order to implement AML/CFT regulations.
Note: The National Organization for Civil Registration and the State Organization for Registration of Deeds and Properties shall provide the national identification number of natural persons and the national identifier of legal persons connected to each postal code, as well as the national cadastral map of properties, to the Ministry of Information and Communications Technology on an online basis.
Article 18
The Ministry of Industry, Mine and Trade shall, in cooperation with the Central Bank of the Islamic Republic of Iran, within one year after the approval of this By-Law, establish the possibility of system-based registration of transactions relating to gold, precious metals, precious stones, and antiques through the Comprehensive Trade System.
Article 19
The Ministry of Industry, Mine and Trade shall, in cooperation with the Ministry of Interior, the Islamic Republic of Iran Customs Administration, and the Iran Chamber of Guilds, within one year after the approval of this By-Law, establish the possibility of system-based registration of vehicle transactions as well as high-value carpets through the Comprehensive Trade System.
Note 1: The Ministry of Industry, Mine and Trade shall, within three months, determine and announce the indicators and criteria for identifying high-value carpets.
Note 2: After the establishment of the possibility of system-based registration in the System referred to in this Article, the allocation or replacement of vehicle license plates by the Law Enforcement Command of the Islamic Republic of Iran shall take place only after inquiry from this System and only if the vehicle transaction has been registered therein.
Note 3: The Islamic Republic of Iran Customs Administration and all domestic manufacturers of vehicles and high-value carpets shall provide all information relating to vehicles and high-value carpets, whether imported or domestically produced, in accordance with the requirements of the Ministry of Industry, Mine and Trade.
Note 4: The Comprehensive Trade System shall be established in such a manner that the chain of transfers of vehicles and the details of their transactions, including the amount and the parties to the transaction, are recorded in the System and that all persons have the possibility to register their transactions therein.
Article 20
The State Organization for Registration of Deeds and Properties shall, within six months after the approval of this By-Law, develop the Integrated Database of Identity Information of Iranian Legal Persons in such a way that online and unrestricted inquiry into the latest basic identity information, address, and related persons of such entities is always available to obliged persons.
Note 1: With respect to legal persons, the basic identity information items shall at minimum include the national identifier, name, type, registering authority, subject of activity, date of establishment, status (including active, dissolved, or liquidation completed), and the date of dissolution or completion of liquidation. Address information shall at minimum include the verified residential postal code of the head office. Information on related persons shall at minimum include the basic identity information items of managerial related persons (members of the board of directors, managing director, deputy managing director, chief financial officer, treasurer, auditor and similar positions) and ownership-related persons (strategic, major, and significant shareholders) of the legal person concerned, the type of relationship, the commencement date of the relationship, and the duration of its validity. Other required information items shall be determined by the Center as deemed necessary.
Note 2: The State Organization for Registration of Deeds and Properties shall provide changes in the basic identity information of legal persons and the list of cancelled ID (including dissolution and completion of liquidation), together with the date and reason for cancellation, to the supervisory authorities on a daily basis.
Note 3: The procedure for inquiring about related persons shall be arranged by the State Organization for Registration of Deeds and Properties in such a manner that, in addition to enabling inquiry into the list of all natural persons related to each legal person, it also enables inquiry into the list of all legal persons related to each natural person.
Note 4: The procedure for inquiring the address of legal persons shall be arranged by the State Organization for Registration of Deeds and Properties in such a manner that upon submission of the national identifier, the corresponding postal code shall be provided.
Article 21
The Ministry of Interior shall develop the Integrated Database of Identity Information of Foreign Natural and Legal Persons in such a manner that online and unrestricted inquiry into the latest basic identity information, address, and related persons is always available to obliged persons.
Note 1: The basic identity information items of foreign natural persons shall, as applicable, include the first name (Persian and Latin), surname (Persian and Latin), father’s name (Persian and Latin), mother’s name (Persian and Latin), grandfather’s name (Persian and Latin), date of birth and death, type of identification document, document number, date of issuance, date of expiry, country of birth, nationality, and gender. For legal persons, the basic identity information items shall include the name (Persian and Latin), nationality, country of registration, registration number, registration date, type of activity, type of ownership, type of company, address, and telephone number.
Note 2: The Ministry of Foreign Affairs, the Ministry of Health and Medical Education, the Ministry of Information and Communications Technology and their subordinate organizations and companies, the Ministry of Education, the Ministry of Cooperatives, Labour and Social Welfare, the Ministry of Economic Affairs and Finance, the Ministry of Industry, Mine and Trade, the Law Enforcement Command of the Islamic Republic of Iran, the Legal Medicine Organization, the National Organization for Civil Registration, the State Organization for Registration of Deeds and Properties, the Organizations of Free Trade-Industrial Zones and Special Economic Zones, and other relevant bodies shall, within six months after the approval of this By-Law and in accordance with the requirements of the law enforcement agencies, provide the Ministry of Interior with the necessary information for the implementation of this Article to the Ministry of Interior on an online and unrestricted basis.
Note 3: The database referred to in this Article shall be established in such a manner that searching is possible based on various IDs contained in valid identification documents.
Note 4: The Ministry of Interior shall provide changes in the basic identity information of foreign persons and the list of cancelled IDs, together with the date and reason for cancellation, to the supervisory authorities on a daily basis.
Note 5: With respect to those foreign nationals who obtained a foreign national number prior to the approval of this By-Law, the Ministry of Interior shall update their identity information within one year after the approval of this By-Law and, in the event that the basic identity information is not provided, shall suspend the foreign national number taking into account security considerations.
Note 6: Obliged persons shall, prior to issuing any valid identification document to foreign persons, submit the necessary information and inquire about the number. Valid identification documents for foreign persons shall be determined and announced by a working group composed of the Ministry of Intelligence, the Ministry of Interior, and the Ministry of Foreign Affairs.
Note 7: The Ministry of Foreign Affairs shall, without delay after issuing visas to foreign persons, provide visa-related information electronically and online to the Ministry of Interior.
Note 8: The Ministry of Interior shall, in cooperation with the Ministry of Intelligence, the Ministry of Foreign Affairs, and the Ministry of Information and Communications Technology, establish the possibility to identify foreign natural persons in person and collect biometric information prior to assigning the number, and shall provide the necessary arrangements for enabling identification of such persons on the basis of biometric information. Until biometric identification possibility is established for foreign persons, identification procedures shall be conducted in accordance with the existing procedures.
Note 9: The assignment of a number to the representations of international organizations, embassies, and other similar legal persons shall be carried out by the Ministry of Interior after approval by the Ministry of Intelligence and the Ministry of Foreign Affairs.
Article 22
The Ministry of Information and Communications Technology shall, within one year after the approval of this By-Law, in addition to establishing the National Mobile Telephone Number System, create the necessary infrastructure for assigning one mobile telephone number to each natural or legal person, whether Iranian or foreign, and provide online and unrestricted inquiry possibility for obliged persons.
Note: Obliged persons shall use the registered mobile telephone number for identifying customers and for establishing communication with persons (natural or legal, Iranian or foreign).
Article 23
The Ministry of Roads and Urban Development shall, in cooperation with the State Organization for Registration of Deeds and Properties, within six months after the approval of this By-Law, implement a Location-Based System for the Registration of Real Estate Transactions in the Country in such a manner that all natural and legal persons are able to register transactions relating to immovable property, whether such property has an official title deed or an unofficial document.
Note: All owners of immovable property with unofficial title deeds shall upload the evidentiary documents relating to their transactions to this system within six months after the system is implemented.
Article 24
The Law Enforcement Command of the Islamic Republic of Iran shall, within six months after the approval of this By-Law, develop the Integrated Database of Entry and Exit Information of Natural Persons at the Country’s Borders in such a manner that the status of individuals’ presence within the country, including the list of foreign nationals whose lawful period of stay in the country has expired, can always be inquired on a daily basis by the Center and law enforcement agencies.
Article 25
The State Organization for Registration of Deeds and Properties shall, within one year, develop the Integrated Database of Official Powers of Attorney in such a manner that online inquiry into their status is always available to obliged persons.
Note 1: The status of a power of attorney refers to the basic identity information items of the attorney and the principal, the type of power of attorney, and its period of validity.
Note 2: After the launch of this database, the provision of any new services and the continuation of previously provided services to customers by obliged persons shall be conditional upon the registration of the power of attorney in the said database.
Note 3: The State Organization for Registration of Deeds and Properties shall provide the list of those powers of attorney that have been cancelled or suspended for reasons other than the expiration of their validity period, together with the date and reason, to obliged persons on a daily basis.
Article 26
The Ministry of Cooperatives, Labour and Social Welfare shall, in cooperation with executive bodies, develop the Integrated Database of Occupational Information of Natural Persons, whether Iranian or Foreign, in such a manner that obliged persons may always inquire into the latest status of their occupational activity.
Note 1: The inquiry capability shall be arranged in such a way that, for each national identification number and for all occupational records of the individual, the information items including employment status (employed, unemployed, or retired), occupational category and title, average monthly income, date of issuance and period of validity of the occupational license, and the date of termination of occupational activity are determined as a result of the inquiry. Other required information items shall be as announced by the Center.
Note 2: The Social Security Organization and other relevant funds (with respect to the employment information of workers), the Administrative and Recruitment Affairs Organization of Iran (with respect to government employees), pension funds (with respect to retirees), the Ministry of Industry, Mine and Trade (with respect to guild business licenses, licenses of industrial, mining and production units, and holders of commercial cards), the Engineering Organization of Iran (with respect to engineers’ professional licenses), the Islamic Republic of Iran Medical Council (with respect to medical practice licenses), and the Securities and Exchange Organization (with respect to trading identifiers of persons), as well as their subordinate organizations and companies, shall provide the necessary information for the implementation of this Article to the Ministry of Cooperatives, Labour and Social Welfare on a monthly basis.
Note 3: The Ministry of Cooperatives, Labour and Social Welfare shall, in cooperation with the National Tax Administration, identify the occupational relationships among persons in such a way that the Center and the Central Bank of the Islamic Republic of Iran are always able to inquire into the occupational related persons of the concerned persons.
Article 27
The National Tax Administration shall provide, on a quarterly basis, all tax returns of natural and legal persons and the latest status of taxpayers’ tax files to obliged persons.
Note 1: The National Tax Administration shall use the information contained in the Integrated Occupational Information Database referred to in Article (26) of this By-Law, within the framework of Clause (e) of Article (169) bis of the Direct Taxes Law, as tax indicators for the assessment of taxpayers’ taxes.
Note 2: The National Tax Administration shall establish the Intelligent and Standardized Database of Persons Committing Tax Crimes, referred to in Article (274) of the Direct Taxes Law, and tax debtors in accordance with the rules announced by the Council and provide online access to this list for the Center, the supervisory authorities, the law enforcement agencies, and the credit rating company referred to in Articles (5) and (8) of the Law on Facilitating the Granting of Bank Facilities and Reducing Project Implementation Costs and Accelerating the Implementation of Production Projects and Increasing Financial Resources and Efficiency of Banks, adopted in (2007). The National Tax Administration shall update the information relating to the list of these persons on a daily basis.
Note 3: The National Tax Administration shall make the issuance of tax clearance certificates for any real estate conditional upon the registration of its transaction in the system referred to in Article (23) of this By-Law.
Article 27 (bis)
The Securities and Exchange Organization shall, within three months from the date of promulgation of this By-Law, provide the Center and the supervisory authorities with online and unrestricted access to information on the stock portfolios and records of assets and transactions of all persons in the capital market, and shall establish access for obliged persons in compliance with Article (35) of this By-Law.
Article 28
For the purpose of facilitating access to customer’s information and verifying the accuracy of documents and information submitted by persons, the supervisory authorities shall undertake the necessary follow-ups and cooperations in order to enable the supervised obliged persons to access the information required for the implementation of the provisions of this By-Law. This provision shall not negate the responsibility of supervised obliged persons to comply with the provisions of the By-Law.
Article 29
The Central Bank of the Islamic Republic of Iran shall, within six months after the approval of this By-Law, establish a System for Identifying Relationships among Persons, in cooperation with obliged persons and in accordance with the request of the Center, and shall provide inquiry possibility to the Center and other supervisory authorities.
Note 1: Identification of relationships among persons refers to the identification of persons who have with each other relationships of guarantee (including facilities and commitments), partnership (including partnership in occupational activities and joint accounts), facilities and commitments (guarantors), agency, and kinship by marriage or blood, or who, according to the declarations of customers, have a relationship with one another.
Note 2: Obliged persons including the National Organization for Civil Registration, the State Organization for Registration of Deeds and Properties, the Securities and Exchange Organization, the National Tax Administration, the Ministry of Intelligence, and the Ministry of Cooperatives, Labour and Social Welfare shall provide the necessary information required by the Central Bank of the Islamic Republic of Iran for the implementation of this Article.
Article 30
The Iranian Association of Certified Public Accountants shall provide obliged persons with online and unrestricted inquiry possibility for audited financial statements and their annexes, audit reports, statutory auditor reports, and other reports attached to financial statements.
Article 31
The Judiciary shall, in cooperation with the Center, within six months after the approval of this By-Law, establish the necessary system-based procedures and solutions for the online exchange of judicial information concerning persons suspected of committing ML/TF in such a way that it enables the Center to submit requests to the relevant judicial authority to obtain the necessary judicial orders, including orders for seizure or lifting the seizure, notification to law enforcement agencies, and the system-based notification of decisions issued by the judicial authority, including judgments and rulings, to the Center and the relevant obliged persons.
Article 32
Judicial authorities shall notify the Center of the outcome of their proceedings in cases brought to the judiciary on the basis of reports submitted by the Center, whether such outcome is in the form of an order or a judgment.
Note 1: Judicial decisions issued by the aforementioned authorities shall be used by the Center for the preparation of appropriate statistics for the development of the National Risk Assessment document, for the standardization of indicators used in identifying suspected cases of ML/TF, and, where appropriate, for providing feedback to obliged persons in order to correct procedures and ensure compliance with laws relating to such offences within their subordinate bodies.
Note 2: The Judiciary shall annually report to the Council the overall statistics of cases filed and concluded in the field of combating ML/TF, in addition to the cases referred by the Center.
Article 33
The Judiciary, in cooperation with the Center, shall establish a mechanism whereby final conviction judgments issued in relation to ML, in accordance with Article (36) of the Islamic Penal Code (adopted on 21 April 2013), in addition to publication in one widely circulated newspaper, are also communicated electronically by the Center to the obliged persons subject to the Law.
Article 34
Obliged persons and supervisory authorities shall, in compliance with the Act and the National Data and Information Management Law adopted in (2022) as amended, while establishing online and unrestricted access for the Center to the systems created pursuant to this By-Law, provide other information and systems required by the Center, upon its request and in accordance with the formats and data items specified by the Center, through web services. The Center shall prepare, every six months, a report on access to data items, measures taken, the manner of cooperation of the said entities, as well as the challenges, vulnerabilities, and necessary proposed measures, and submit it to the Council.
Note: With respect to existing systems, access for the Center shall be provided within three months after the approval of this By-Law.
Article 35
All information provided to obliged persons pursuant to this By-Law shall be delivered solely through the National Information Exchange Center referred to in Note (2) of Clause (e) of Article (67) of the Sixth Development Plan Law and for the purpose of implementing AML/CFT regulations. Obliged persons shall ensure the security of information production and exchange in accordance with the rules issued by the Presidential Strategic Management Center of AFTA (Security of the Information Exchange Space) and obtain the necessary authorizations. Other rules governing the provision of this information, including considerations such as the determination of inquiry fees and the access level of each obliged person, shall be determined by the Center and approved by the Council.
Note: Access to the information referred to in the Articles of this By-Law and the level of access of each obliged person, taking into account the nature of its activities and organizational structure, shall be determined by a directive to be issued by the Center within three months after the approval of this By-Law and approved by the Council.
Article 36
Obliged persons shall, taking into account their organizational structure, the nature of their activities, the complexity associated with such activities, and the relevant risks, utilize adequate, comprehensive, and efficient system-based solutions for the implementation of the provisions of this By-Law.
Note: If supervised obliged persons, due to their particular circumstances, are unable to use information-technology-based methods, they shall select an efficient alternative method and obtain the approval of the relevant supervisory authorities.
 

Chapter Four – Supervisory Structure and Procedures

Article 37
Financial institutions shall, with regard to the type of activity and their organizational structure, introduce a unit in charge of AML/CFT to the Center. The head of AML unit must be selected from among the senior managers of the financial institution. The Center shall, based on the importance of the mentioned unit, examine the professional competence of the head of this unit.
Note 1: The AML unit of the financial institution must be formed under the highest decision‑making authority or CEO of the financial institution in such a manner that it has access to all information and system infrastructures of the financial institution, without limitation or need to obtain permission, and has membership in internal councils, committees or other similar arrangements including the committees in charge of drafting and amending regulations and product development of these institutions, and also possesses the necessary facilities, powers, infrastructures and resources for performing the assigned duties and the programs communicated by the Center.
Note 2: The list of sectors exempted from establishing an AML unit based on the risk level shall be prepared by the Center and the alternative mechanism, and their reporting method shall also be determined and promulgated.
Note 3: Financial institutions shall, in addition to obtaining professional competence approval of the head of AML unit from the Center, make inquiries from relevant authorities to obtain security and general qualification verification, within the framework of the relevant law.
Note 4: In the absence of an AML unit, the duties and responsibilities of the AML unit and the implementation of all AML/CFT policies and procedures rest with the highest executive authority of the financial institution.
Note 5: The duties and responsibilities of the AML units do not negate the responsibilities of the highest executive authority in implementing the Act and this By-Law.
Note 6: The executive directive of this article shall be drafted within one year by the Center in cooperation with supervisory authorities and shall be promulgated by supervisory authorities.
Article 38
The duties of AML units are as follows:
  1. Monitoring customer activities and related financial institutions to identify suspicious transactions.
  2. Reviewing, analyzing, prioritizing, and commenting on reports sent by employees of the related entity.
  3. Immediate submission of the said reports in the form and mechanism specified by the Center without informing the customer.
  4. Preparing necessary software for facilitating rapid access to the required information for implementing the Act and regulations and system‑based identification of suspicious transactions.
  5. Designing mechanisms required for prioritizing, monitoring, and controlling AML/CFT processes (the processes of collecting & analyzing data, recruitment of human resources, training, etc.) and evaluating and auditing their implementation in the related entity.
  6. Providing supplementary information required by the Center and other AML/CFT competent authorities.
  7. Issuing circulars regarding the implementation of AML/CFT Act and regulations for subordinate entities.
  8. Inspecting and monitoring the subordinate units to ensure full implementation of AML/CFT laws and regulations.
  9. Preparing statistics and reports regarding the measures taken by the subordinate entities to implement AML/CFT regulations, as well as the results of such measures.
  10. Referring case files of persons subject to Note (3) of Article (4) of the Act to administrative and judicial authorities and notifying the Center.
  11. Keeping records and reports of the correspondence of the subordinate entity regarding ML/TF cases.
  12. Preparing annual programs for the implementation of AML/CFT regulations and monthly monitoring of their execution.
  13. Preparing training programs based on the type of activity regarding the subject of this Act.
  14. Reviewing and aligning the financial institution’s internal rules with AML/CFT regulations and providing proper feedback and taking necessary measures for correcting deficiencies.
  15. Performing other duties assigned by the Center within the framework of the provisions of the Act.
Article 39
To expedite access to the required information upon the Center request, one AML unit member of the obliged persons with full access authority to all information of the obliged persons shall be located at the Center to meet its primary requirements. The aforementioned individual shall perform duties under the control of the Center and in accordance with the regulations promulgated by the Center.
Article 40
The AML Unit shall continuously review and assess the transactions and operations conducted within the financial institution. In the event of observing any non-compliance with AML/CFT regulations, it shall, as the case may be, submit a report to the Center or to the supervisory authority.
Note: All procedures adopted for the purpose of AML/CFT within financial institutions shall be implemented in coordination with and under the supervision of the institution’s AML Unit. The AML Unit shall incorporate and implement the requirements issued by the Center and the relevant supervisory authority with respect to such procedures and their manner of implementation.
Article 41
Financial sector supervisors shall:
  1. Establish an appropriate organizational structure, at a minimum at the Directorate-General level, by utilizing the existing institutional capacities of the entities, in compliance with Article (105) of the Seventh Five-Year Development Plan of the Islamic Republic of Iran (2024), together with qualified human resources, adequate facilities, powers, budgetary allocations, and sufficient infrastructure necessary to carry out the full range of supervisory measures relating to AML/CFT. Such arrangements shall be revised in accordance with the feedback issued by the Council.
  2. Develop risk-based supervisory programs, including both on-site and off-site methods, for the purpose of ensuring that financial institutions within their authority comply with AML/CFT requirements, and implement such programs following the approval by the Center.
  3. Exercise supervision over financial institutions within their authority with respect to compliance with AML/CFT laws and regulations.
  4. In case of failure of financial institutions to comply with AML/CFT laws and regulations, implement supervisory directives and programs promulgated, or refrain from cooperating to implement the mentioned programs, supervisors shall impose, within their administrative and disciplinary proceedings, the financial sanctions mentioned in Articles (23) and (25) of the Central Bank of the Islamic Republic of Iran Act (2023), the Securities Market of the Islamic Republic of Iran Act (2005), along with its amendments and supplements, Article (14) of the Law for the Development of New Financial Instruments and Institutions to Facilitate the Implementation of the General Policies of Article (44) of the Constitution (2009), along with its amendments and supplements, the Establishment of the Central Insurance of Iran and Insurance Operations Act (1971), along with its amendments and supplements, and other relevant laws, regulations, by-laws, and directives. Where necessary, the supervisory authority shall, within the framework of the aforementioned laws and regulations, revoke, restrict, or suspend the license of the financial institution.
  5. In case of failure to implement AML/CFT regulations, impose restrictions or prohibitions on the supervised financial institution to provide services.
  6. Submit semi-annual reports to the Center containing the implementation status of supervisory programs, statistics on identified non-compliance cases disaggregated by main sectors and statutory obligations, administrative or judicial proceedings undertaken, sanctions imposed, assessments of the effectiveness of measures taken, identified vulnerabilities, together with appropriate recommendations.
Note 1: The Center shall, while overseeing the proper implementation of this Article and providing feedback and corrective requirements, assess and conduct a vulnerability analysis of the measures and reports submitted by the supervisory authorities and submit the results thereof to the Council.
Note 2: Each supervisory authority referred to in this Article shall, within six months from the promulgation of this By-law and within the scope of statutory powers, prepare a directive governing administrative and disciplinary proceedings specific to AML/CFT for financial institutions and, following the approval by the Center, submit it for adoption by its highest competent legal authority. Such directives shall contain detailed specifications regarding the breaches and shall clearly prescribe effective, proportionate, and dissuasive sanctions for each breach. The measures referred to in paragraph (4) of this Article shall not be contingent upon the preparation or adoption of such directive.
Note 3: The Ministry of Industry, Mine and Trade; the State Organization for Registration of Deeds and Properties; the Iranian Association of Certified Public Accountants; the Bar Associations; and the Center for Lawyers, Official Experts and Family Advisors of the Judiciary shall, in the discharge of their supervisory responsibilities over DNFBPs, implement the provisions of this Article through the establishment of appropriate organizational structures and to undertake revisions in accordance with the resolutions of the Council. Furthermore, with respect to paragraph (4) of this Article, they shall, within the scope of their statutory authority, design and apply effective, proportionate, and dissuasive sanctions.
Article 42
Financial institutions shall, within the timeframes specified by the Center, complete the assessment form concerning the implementation of AML/CFT regulations and procedures.
Note 1: Supervisory authorities shall, in cooperation with and subject to the approval of the Center, design the form referred to in this Article for financial institutions and update it at intervals of three to five years.
Note 2: Supervisory authorities shall, in coordination with the Center, verify the accuracy of the information contained in the aforementioned form(s) through targeted inspection methods, including thematic or ad hoc inspections, and submit the results thereof to the Center. Such authorities shall establish effective mechanisms to prevent the submission of inaccurate reports by financial institutions.
Note 3: Auditors shall assess and validate the form(s) referred to in this Article with respect to those legal persons for whom, under applicable regulations, they are obligated to express an opinion regarding compliance with AML/CFT requirements. In this regard, the Center shall, in cooperation with the Audit Organization, the Iranian Association of Certified Public Accountants, and the relevant supervisory authority, design and develop the assessment form(s) referred to in this Note.
Note 4: The Center shall ensure the systemic implementation of the provisions of this Article through the system established pursuant to Article (4) of this By-law.
Article 43
The supervisory authority shall take the necessary measures to ensure that the AML Unit within each financial institution is vested with adequate and sufficient power and access to the information required, and that the analysis and the submission of reports by such units to the Center and other related authorities shall not be subject to approval or endorsement by any other authority.
Article 44
The Center shall, in cooperation with the supervisory authorities and on the basis of the conducted assessments, rank the financial institutions with respect to their implementation of AML/CFT regulations.
Note 1: Within one year from the adoption of this By-law, the Center shall, in cooperation with the supervisory authorities in each respective sector, determine the methodology for the assessment and ranking referred to in this Article and communicate it to financial institutions.
Note 2: Supervisory authorities shall, in accordance with the mechanism announced by the Center, take into account the ranking referred to in this Article when granting facilities, credit lines, privileges, or licenses to financial institutions, in such a manner that proportionate restrictions are imposed on financial institutions whose performance has been assessed as weak.
Note 3: All financial institutions shall apply enhanced measures in their business relationships with those financial institutions that have been rated as weak under the ranking referred to in this Article and shall treat such institutions as high-risk persons.
Article 45
The State Organization for Registration of Deeds and Properties shall be the competent supervisory authority over notaries public and their deputies, the Iranian Association of Certified Public Accountants shall be the competent supervisory authority over independent accountants, certified auditors, and audit firms and the Bar Associations as well as the Center for Lawyers, Official Experts and Family Advisors of the Judiciary shall, as the case may be, serve as the competent supervisory authorities over lawyers and independent legal professionals or legal professional employed in legal firms, with respect to compliance with AML/CFT laws and regulations.
Article 46
The Center shall, in cooperation with the Audit Organization and the Iranian Association of Certified Public Accountants, design and develop procedures governing auditors’ assessment of the implementation of AML/CFT regulations by legal persons, and establish criteria for identifying suspicious transactions and operations. Such procedures and criteria shall be updated every three years.
Note 1: The Audit Organization and the Iranian Association of Certified Public Accountants shall communicate the procedures and criteria referred to in this Article to auditors, provide the necessary training, and ensure the proper implementation of such procedures, as well as the reporting of suspicious transactions and operations by auditors in accordance with applicable regulations through the JAAM System.
Note 2: Auditors shall, in their assessments of the implementation of AML/CFT regulations by legal persons, take into account the completed assessment form referred to in Article (42) of this By-law.
Note 3: The Iranian Association of Certified Public Accountants shall supervise the implementation of this Article by auditors.
Note 4: Executive bodies and financial institutions shall provide auditors with the information necessary for the discharge of their obligations under this Article. The categories of such information shall be determined by the Center in cooperation with the Audit Organization and the Iranian Association of Certified Public Accountants.
Note 5: The Audit Organization and the Iranian Association of Certified Public Accountants shall establish the necessary infrastructure for the implementation of the provisions of this Article.
Article 47
The Ministry of Industry, Mine and Trade shall serve as the competent supervisory authority over the businesses referred to in subparagraphs (a) to (f) of paragraph (7) of Article (1) of this By-law, with respect to compliance with AML/CFT laws and regulations.
Note: The Ministry of Cultural Heritage, Tourism and Handicrafts and the Ministry of Culture and Islamic Guidance shall provide the necessary cooperation to the Ministry of Industry, Mine and Trade in supervising the businesses referred to in subparagraph (e) of paragraph (7) of Article (1) of this By-law.
Article 48
Supervisory authorities shall, at the time of granting and renewing any license, permit, or authorization to financial institutions and DNFBPs, and within the framework of applicable laws and regulations, take the following measures:
  1. Obtain a clean criminal record certificate, a written commitment to comply with AML/CFT requirements, and a valid AML/CFT training certificate for individuals appointed to the positions of Chief Executive Officer, member of the Board of Directors, member of the Executive Board, and Deputy Chief Executive Officer within financial institutions, as well as the owners of DNFBPs.
  2. Ensure that persons with criminal conviction records do not become significant shareholders or controlling shareholders in financial institutions, nor otherwise become beneficial owners of a substantial portion of shares or controlling interest, nor have acquired such position through other persons in any way.
  3. Verify the lawful origin of capital funded through shareholders’ equity contributions for the establishment of a financial institution or for any capital increase.
  4. Confirm the adequacy of the organizational structure, powers, resources, access rights, and facilities allocated to AML/CFT functions within financial institutions.
Article 49
Law enforcement agencies shall, in cooperation with the supervisory authorities and the Center, identify any natural or legal person operating without obtaining license from financial sector supervisors, including but not limited to the Central Bank of the Islamic Republic of Iran, the Securities and Exchange Organization, or the Central Insurance of the Islamic Republic of Iran, who, in the course of business, engage in one or more of the activities or operations referred to in paragraph (5) of Article (1) of this By-law. Such persons shall be referred to the judicial authorities and other competent authorities for the application of legal measures and enforcement of the applicable laws, including but not limited to article (37) of the Central Bank of the Islamic Republic of Iran Act (2023), article 2 (bis), (18), (29), (30), (31) and (32) of the Law on Combating the Smuggling of Goods and Currency (2013) along with its amendments and supplements, article 49 of Securities Market Law of the Islamic Republic of Iran (2005) along with its amendments and supplements, Note to article (69) of the Law on the Establishment of the Central Insurance of Iran and Insurance Business (1971) along with its amendments and supplements, the Law on Punishment of Disruptors of the Economic System of the country (1990) along with its amendments and supplements, and the Law on the Regulating the Unorganized Money Market (2005) along with its amendments and supplements.
Note: The Office of the Prosecutor General shall take the necessary measures to ensure coordinated implementation of this Article and shall submit to the Council, on an annual basis, a report containing statistics on identified cases, prosecutions, and convictions, together with an assessment of the effectiveness of measures taken, identified existing vulnerabilities, and appropriate recommendations.

Chapter Five – Customer Due Diligence

Article 50
Financial institutions shall, before establishing a business relationship, perform appropriate CDD measures, and where a financial institution is unable to comply with relevant CDD measures, commencing any business relations shall be prohibited and shall constitute a breach.
Note 1: The provision of services to a customer shall be deemed to constitute a guarantee of compliance with appropriate CDD measures by the employees of financial institutions, and responsibility for any breach in this regard shall rest with the financial institution and the relevant employees.
Note 2: Financial institutions shall be prohibited from keeping anonymous accounts and continuing the provision of basic services on an anonymous basis or under an unknown or fictitious name, as well as the conduct of any anonymous or non-traceable electronic financial transaction.
Note 3: Financial institutions shall refrain from providing services to persons lacking legal identity or persons whose unique identity identifier has, for reasons including death, etc., been invalidated by the competent authorities.
Article 51
Financial institutions shall, for the purpose of performing CDD measures, classify the risk of customers’ business relationships on the basis of AML/CFT regulations and perform CDD measures commensurate with such risk at three levels, namely simplified, normal, and enhanced CDD. Furthermore, CDD policies and procedures shall be risk-based so as to give rise to ongoing and targeted monitoring of the customer’s business relationship, and so that the level of information obtained from the customer, including information relating to the beneficial owner of legal persons, is determined, maintained, and updated commensurate with such risk.
Article 52
Financial institutions shall, in performing CDD measures, establish appropriate CDD processes and procedures (including simplified, normal, and enhanced due diligence) in such a manner that, while obtaining sufficient information at the time of commencing the business relationship (as well as throughout the business relationship), the possibility of assessing the risk of establishing a business relationship with the customer and adopting risk-commensurate due diligence procedures is provided.
Article 53
Financial institutions may, following the comprehensive risk analysis, and where lower business relationship risk has been identified, perform simplified CDD measures. In other cases, the implementation of normal and/or enhanced due diligence measures in accordance with the provisions of this By-law shall be mandatory.
Note: Financial institutions shall obtain the approval of the competent supervisory authorities with respect to the instances of business relationships in relation to which simplified CDD measures are implemented.
Article 54
For the purpose of performing simplified CDD measures, financial institutions shall perform simplified CDD measures commensurate with the level of the customer’s risk. Such measures shall not violate other AML/CFT regulations. Some of these measures include:
  1. Reducing the frequency of updating customer identification information,
  2. Reducing the degree of ongoing monitoring and scrutinizing transactions based on the customer’s expected level of activity,
  3. Not collecting precise and detailed information, or undertaking specific measures to understand the purpose and intended nature of business relationships, in cases where the purpose and nature of transactions are inferable from the type of transactions or the established business relationships.
Article 55
Deleted.
Article 56
Deleted.
Article 57
With respect to legal persons in the process of incorporation, financial institutions may proceed to open an account without obtaining a national identifier, provided that an official letter of introduction issued by the State Organization for Registration of Deeds and Properties is obtained and that the said account is blocked for withdrawals until such time as the national identifier is received.
Note 1: In the event of withdrawal by legal persons in the process of incorporation from formal registration, financial institutions may, solely upon notification by the State Organization for Registration of Deeds and Properties, proceed to close the account and refund the deposit. The deposit shall be repaid exclusively to the natural person who opened the account or to the authorized representative introduced by the State Organization for Registration of Deeds and Properties.
Note 2: The Central Bank of the Islamic Republic of Iran shall, in cooperation with the State Organization for Registration of Deeds and Properties, within three months following the approval of this By-law, provide the necessary systematic infrastructure for the implementation of this Article and for the exchange of information concerning legal persons in the process of incorporation.
Article 58
Financial institutions shall perform or update CDD measures when:
  1. Providing basic services (including account opening, etc.),
  2. Providing non-basic services and establishing business relations with occasional customers for transactions above the applicable designated threshold, including situations where the transaction is carried out in a single operation or in several operations that appear to be linked,
  3. Carrying out cross-border wire transfers,
  4. There is suspicion of ML/TF,
  5. There are doubts about the veracity or adequacy of previously obtained customer identification data,
  6. There are grounds indicating a change in the customer’s status and information during the course of monitoring procedures.
Note: For the purpose of performing normal CDD measures, the intervals for updating customer information shall not exceed one year; with respect to high-risk customers, such updating shall be carried out at shorter intervals.
Article 59
Financial institutions shall, for the purpose of performing normal CDD measures, adopt appropriate measures to ensure the conduct of the following actions in respect of customers:
  1. Verifying the identity of the customer solely on the basis of reliable and independent source documents and obtaining valid identification documents,
  2. Ensuring the identification of the beneficial owner based on reliable information and documentation,
  3. Understanding the nature, purpose, and level of the customer’s activity in the course of establishing a business relationship,
  4. Examining the supporting documents of persons who, under any title (including guardian, executor, custodian, attorney, and representative of a legal person), have approached financial institutions on behalf of other persons, in addition to conducting identification and verification procedures in respect of such persons,
  5. Conducting ongoing due diligence by undertaking appropriate measures such as ensuring that data or information collected under the CDD measures are kept up to date, conducting ongoing monitoring of the customer based on the customer’s expected level of activity, and ensuring that the transactions conducted are consistent with the information obtained from the customer,
  6. Collecting and keeping information relating to the assessment of the risk of business relationships.
Note 1: The implementation of the measures set out in paragraph (1) of this Article shall be mandatory under all circumstances, including in cases of provision of non-basic services, establishment of a business relationship with occasional customers, or transactions below the applicable designated threshold.
Note 2: Payment of government bills and public utility services below the applicable designated threshold shall not require identification and verification.
Note 3: In cases where a person acts on behalf of a principal under any title (including guardian, executor, custodian, attorney, and representative of a legal person), financial institutions shall, in implementing the provisions of paragraphs (1) and (2) of this Article, in addition to identifying and verifying the representative, obtain documents evidencing the authority of representation and to verify their authenticity and validity.
Note 4: With respect to electronic and non-face-to-face services (such as internet-based services), acceptance of a payment instrument, receipt of related information (such as receipt of the password and card expiry date), and matching thereof shall be deemed to constitute identification and verification.
Note 5: Valid identification documents in respect of Iranian natural and legal persons shall be determined and announced by the Center.
Article 60
Financial institutions shall, for the purpose of performing normal CDD measures in respect of natural persons, observe the following minimum measures and obtain three general categories of identity, economic and beneficial ownership information referred to in this Article, together with valid documents and records, as appropriate, from the customer or the relevant entities, and after ensuring the accuracy and authenticity of the information, keep such information in a systematic manner within their customers’ profile.
Note 1: The minimum identity, economic, and beneficial ownership information in respect of Iranian natural persons shall be as follows:
  1. Identifying and verifying the identity of the customer and obtaining identity information, including first name and surname, year of birth, national identification number, father’s name, life status, and, if deceased, the date thereof, residential postal code, by obtaining valid identification documents and records,
  2. Undertaking appropriate measures (such as obtaining a written declaration and commitment as to the accuracy of statements) to determine whether the customer is acting on his or her own behalf or on behalf of another beneficial owner, and where a beneficial owner exists, obtaining the identity information of the beneficial owner in accordance with the provisions of this Article,
  3. Economic information including occupational information (such as employer/organization/institution details in respect of employees and workers and the title of occupational activity and business license number in respect of self-employed persons), an estimate of annual income, an estimate of the aggregate annual amounts of deposits and withdrawals from the account, an estimate of the maximum amount of each transaction, information on other sources of income (such as securities exchange trading code, real estate lease tracking code), the report of the inspector and certified auditor (where the customer is required to have an inspector or certified auditor), tax return and economic code (where available).
Note 2: Identity, economic, and beneficial ownership information in respect of foreign natural persons shall be as follows:
  1. Identifying and verifying the identity of the customer and obtaining identity information including first name and surname, father’s name, grandfather’s name, specific identification number, date and place of birth, life status and date of death, residency status and date of entry into the country, residential postal code, type of identification document, validity period of identification documents, nationality, by obtaining valid identification documents and records,
  2. Undertaking appropriate measures (such as obtaining a written declaration and commitment as to the accuracy of statements) to determine whether the customer is acting on his or her own behalf or on behalf of another beneficial owner, and where a beneficial owner exists, obtaining the identity information of the beneficial owner in accordance with the provisions of this Article,
  3. Economic information including occupational information and work permit obtained from the Ministry of Cooperatives, Labour and Social Welfare (such as employer/organization/institution details in respect of employees and workers and the title of occupational activity and business license number in respect of self-employed persons), an estimate of annual income, an estimate of the aggregate annual amounts of deposits and withdrawals from the account, an estimate of the maximum amount of each transaction, information on other sources of income (such as securities exchange trading code, real estate lease tracking code), the report of the inspector and certified auditor (where the customer is required to have an inspector or certified auditor), tax return and economic code (where available).
Article 61
Financial institutions shall, for the purpose of performing normal CDD measures in respect of legal persons, take the following minimum measures and obtain the three general categories of identity, economic and beneficial ownership information as set out in this Article, together with valid documents and records, as appropriate, from the customer or the relevant entities, and after ensuring the accuracy and authenticity of the information, keep such information together with the relevant documents in a systematic manner within their customers’ profile:
  1. Identifying and verifying the identity of the customer and obtaining the following identity information by receiving documents and records:
  1. national identifier, name of the legal person, legal form (commercial or non-commercial/for-profit or non-profit/governmental or non-governmental/in the case of commercial companies, the type thereof including limited liability, public joint stock, private joint stock, and etc.), registering authority (including Companies and Non-commercial Institutions Registration office, Ministry of Interior, and the like), date of establishment, current existence (including active, dissolved and liquidated) and date of dissolution/liquidation, based on valid documents and records proving the current existence of the legal person such as the articles of association and partnership agreement;
  2. ownership structure and control structure of the customer, including information on major shareholders, members of the board of directors, senior executive managers, and, as applicable, inspectors or auditors, based on the regulations governing the legal person and pursuant to which they are regulated and supervised (such as the articles of association);
  3. verified address and postal code of the registered office and principal place of business, based on valid documents and records evidencing the existence of the legal person.
  1. Identifying and verifying the identity of the beneficial owner of legal persons based on the obtained identity information of the following persons:
  1. natural persons or that group of legal persons who directly or indirectly own at least twenty-five (25) percent of the legal person or hold one managerial seat on the board of directors of the legal person shall be recognized as the beneficial owner;
  2. persons who exercise control over legal person through other means, such as a power of attorney, in cases of doubt as to paragraph (a) or where no natural person is identified who exerts control over legal persons through ownership interests;
  3. persons who hold the position of senior managing officials of the legal person where paragraphs (a) and (b) are not fulfilled.
  1. Understanding the subject matter, nature and level of the customer’s activity by obtaining information such as field of activity (such as manufacturing and trading), estimates of sources of income such as income derived from investment and sale of products, estimates of sales, costs and income, estimates of exports and imports, estimates of expected annual account turnover and expected annual number of transactions, based on valid documents and records including but not limited to the legal person’s business license (certificate of incorporation, business license, operation permit, commercial card and Electronic Trust Symbol License), the latest tax return and/or one of the reports annexed to the financial statements that can be inquired from the Iranian Association of Certified Public Accountants.
Note 1: The Central Bank of the Islamic Republic of Iran shall provide the necessary information concerning the implementation of this Article to financial institutions through the system referred to in Article (29) of this By-law.
Note 2: Insurance service providers shall, in addition to CDD measures (simplified, normal, or enhanced), including identification of the beneficial owner, conduct measures relating to the identification of beneficiaries of life and/or other investment-related insurance policies as follows:
  1. Identifying beneficiaries who are specifically named in the insurance policy (whether natural or legal persons);
  2. Identifying beneficiaries whose names are designated by characteristics or by class (such as spouse or children at the time that the insured event occurs) or by other legal means (such as a will), sufficient information concerning the beneficiary must be obtained so that the insurance company is satisfied that, it will be able to establish the identity of the beneficiary at the time of payout.
Note 3: With respect to governmental and municipal institutions and entities (subject to Article (587) of the Commercial Code) which acquire legal personality upon establishment and without the need for registration, appropriate CDD measures shall be carried out in accordance with the mechanism announced by the Center.
Article 62
Financial institutions shall, in cases where they form a suspicion of ML/TF, and where performing normal CDD process will tip-off the customer, manage the due diligence process and undertake appropriate measures to obtain the customer’s confidence, and immediately file an STR to the Center and act in accordance with the Center’s instructions.
Article 63
Supervisory authorities shall, in cooperation with the Center, within three months after the approval of this By-law, develop and promulgate standard rules relating to the collection of identity, economic and beneficial ownership information for each of the main sectors in accordance with AML/CFT regulations. Financial institutions shall, following the promulgation of these rules, incorporate them into the design of forms for collecting identity, economic and beneficial ownership information from customers.
Article 64
Financial institutions shall, for the purpose of documenting and verifying customer information, inquire into and record the accuracy and authenticity of the information and documents obtained from the customer from the relevant competent authorities.
Note 1: Until the relevant systems and databases are established and in cases where the necessary infrastructure does not exist, copies of the related documents and records obtained from the customer shall be certified as true copies by the authorized signatory within the financial institution.
Note 2: The term relevant competent authorities shall mean the systems and databases set out in Chapter (3) of this By-law. Any change in the list of such databases, as well as the manner and items of information to be inquired into, shall be determined and announced by the Center.
Note 3: Financial institutions shall, in the event of any discrepancy between the identity information (including name, surname, postal code, etc.) provided by the customer and the result of conducted inquiries, refrain from providing any service until the discrepancy is removed.
Note 4: All financial institutions shall, no later than one year after the approval of this By-law, for the purpose of sending any message or establishing any non-face-to-face communication with customers, use exclusively the mobile phone-based infrastructure referred to in the system of Article (22) of this By-law.
Article 65
Financial institutions shall make the provision of any service to persons acting on behalf of a principal under any title (including guardian, executor, custodian, and attorney) conditional upon carrying out the identification and verification process of the representative and obtaining valid official documents evidencing the authority of representation (such as a power of attorney executed before notary public offices and judicial orders establishing guardianship or custodianship).
Note: Financial institutions shall, for the purpose of performing CDD measures, prior to providing any service to the representative of a principal, inquire into the accuracy and authenticity of the representative’s valid identification documents and official documents evidencing representation through the relevant systems, and record the verified information of the representative in the customer’s profile.
Article 66
Basic service providers shall adopt procedures enabling them, within a period of less than one month, to ascertain changes resulting in the revocation or suspension of the ID of a natural or legal person (such as death, legal incapacity, dissolution, or prohibition from transactions) and systematically suspend the continuation of service provision. Where, following the revocation or suspension of the ID, a transaction exceeding the designated threshold has been carried out by the customer, financial institutions shall report the case to the Center.
Note 1: The Civil Registration Organization, the State Organization for Registration of Deeds and Properties, and the Ministry of Intelligence shall provide the necessary information for the implementation of this Article to financial institutions.
Note 2: Basic service providers shall, immediately upon removal of the cause of account blocking and with urgency, lift the restriction on service provision.
Article 67
Financial institutions shall, for the purpose of ongoing monitoring of customers in the normal CDD process and for assessing the risk of establishing business relationships with them, determine the customer’s level of activity in accordance with this By-law and other requirements established by supervisory authorities in cooperation with the Center.
Note 1: Supervisory authorities shall, through the system referred to in Article (26) of this By-law, validate the information and assess the appropriateness of the activity level. In the event of non-confirmation, financial institutions shall immediately re-determine the customer’s level and submit the relevant supporting documents to the supervisory authority.
Note 2: In the event of inconsistency between the customer’s financial behavior and the determined expected level of activity, financial institutions shall invite the customer and provide the discrepancy-with-activity-level form thereto and, after completion, review the said form. Where the financial institution determines the accuracy of the customer’s claim, it shall update the expected activity level accordingly.
Note 3: The mechanism for resolving discrepancies shall be determined within the framework of the requirements referred to in this Article. In the event of inconsistency in the customer’s financial behavior, financial institutions shall, until the discrepancy is resolved, be required to apply the following restrictions:
  1. Imposing restrictions on the provision of services in respect of all payment devices of the customer;
  2. Making the execution of all banking transactions and operations conditional upon the customer’s in-person appearance before the financial institution, stating the purpose in the relevant forms, and providing supporting documentation.
Note 4: The supervisory authority shall, in coordination with and subject to the approval of the Center, prepare the form referred to in Note (3) of this Article within three months after the approval of this By-law and make it available to financial institutions.
Note 5: With respect to persons who refrain from providing economic information in accordance with the requirements of this By-law, the expected activity level shall be determined at a minimum level in accordance with the requirements announced by the Center.
Article 68
Financial institutions shall take the following measures with respect to the provision of safe deposit box and post office box services:
  1. Conducting normal CDD measures prior to providing safe deposit box and post office box services;
  2. Establishing an integrated system for collecting information of safe deposit box customers (including identification information of the renter(s) and information relating to powers of attorney and representation), in such a manner that the said system can promptly provide the information required by competent authorities within the framework of relevant laws and regulations;
  3. Recording the time of all customer visits for the use of the safe deposit box, in such a manner that visits relating to each customer can be systematically noticeable and reportable;
  4. Where there is strong ML/TF suspicion of the customer and the keeping of proceeds thereof in the safe deposit box, the financial institution shall report the case without delay to the Center and refrain from providing the said service to the customer until receipt of the Center’s instruction, for a maximum period of twenty-four (24) hours.
Article 69
Customer identification officers shall, where there is doubt as to the authenticity or accuracy of identification documents provided by the customer (whether natural or legal), remove such doubt by means of inquiry from other systems and databases or from informed competent legal authorities. Provision of service shall be suspended until the doubt is resolved.
Note: Where, at any stage of performing CDD measures (simplified, normal, or enhanced), it is determined that a customer has provided information lacking authenticity or accuracy, financial institutions shall, in accordance with the regulations, make an STR to the Center.
Article 70
The provision of any services whose use is justified solely in commercial activities and which create obligations for the person (such as opening letters of credit, issuing any type of guarantee, granting any acceptance device, and providing cheque books) to legally incapacitated persons is prohibited. The provision of other services to legally incapacitated persons, within the framework of national regulations and subject to compliance with AML/CFT regulations and the risk assessment, shall be permitted.
Article 71
Financial institutions may, in their internal directives, in addition to the documents mentioned in this By-law, request supplementary documents that assist them in implementing more precise CDD processes.
Article 72
PSPs shall be required to refrain from granting any acceptance device, whether physical or virtual, to persons who, based on inquiry from the Integrated Occupational Information database referred to in the system of Article (26) of this By-law, lack an occupational license or who, based on inquiry from the tax information database, lack a tax file.
Note: The Central Bank of the Islamic Republic of Iran shall suspend the activity of all acceptance devices granted without meeting the aforementioned conditions.
Article 73
Financial institutions may provide services solely to foreign persons holding the specific identification number for foreign nationals. The provision of services to foreign persons shall be proportionate to the risk of such persons, the executive rules of which shall, within three months after the approval of this By-law, be determined by the Ministry of Intelligence in cooperation with the competent authorities such as the Ministry of Interior, the Ministry of Foreign Affairs, and the Central Bank of the Islamic Republic of Iran in each main sector, and shall be promulgated after approval by the Council.
Note 1: Financial institutions shall identify foreign persons on the basis of identification documents determined by the working group referred to in Note (6) of Article (21) of the By-law and after inquiry from the system referred to in the said Article.
Note 2: Provision of services to foreign legal persons and representative offices of foreign commercial companies (except representative offices of international organizations, embassies, and similar legal persons), where identification and verification in accordance with the executive rules subject of this Article is feasible, shall be permitted; otherwise, they shall be permitted to receive services only after registration of the representative office and obtaining the national identifier referred to in Article (20) of this By-law.
Article 74
Financial institutions shall manage their internal procedures in such a manner that only senior managers and duly authorized personnel designated by them may be eligible to make changes to the customer’s profile.
Article 75
Financial institutions shall, when providing basic services to customers, obtain the necessary commitments in the following cases:
  1. That customers shall provide the information requested by financial institutions as specified in this By-law and shall cooperate with financial institutions in obtaining and updating the information subject to the Act and this By-law;
  2. That customers shall not permit other persons, other than themselves, to use the received basic services and, if they become aware of such use by other persons, shall immediately notify the financial institution; statutory cases (including guardianship, executorship, custodianship, power of attorney, and representation of a legal person), provided that the representative’s details are recorded and appropriate due diligence procedures are carried out, shall not be subject to this paragraph;
  3. That necessary undertakings shall be obtained regarding compliance with AML/CFT regulations and non-use of the received services for ML/TF purposes.
Note 1: Financial institutions, for the purpose of mitigating the risk of ML/TF and conducting monitoring and controlling procedures over financial institutions, when providing basic services to other financial institutions, DNFBPs, and NPOs, shall, in addition to obtaining due diligence documentation (whether simplified, normal, or enhanced), obtain the necessary undertakings regarding compliance with the requirements announced by the Center and implementation of AML/CFT laws and regulations; in the event of refusal by the said persons to provide such undertakings or to act in accordance therewith, the financial institution shall refrain from providing services to them.
Note 2: The aforementioned undertakings must be expressly and precisely explained to the customer. In the event of refusal by the customer or disregard of his or her undertakings, provision of services shall be terminated.
Article 76
Financial institutions shall, within six months after the promulgation of this By-law, apply appropriate due diligence measures in respect of existing customers. Where financial institutions are unable to implement this requirement, they shall refrain from providing new basic services to existing customers and, in accordance with procedures announced by supervisory authorities, terminate the provision of all basic services. Furthermore, financial institutions shall report to the Center the cases of existing customers lacking essential information.
Article 77
Financial institutions shall, in cases where the risk of business relationships is assessed as higher, perform Enhanced Due Diligence (EDD).
Article 78
Deleted.
Article 79
Financial institutions shall perform EDD measures in such a manner that at least the following measures are undertaken:
  1. Obtaining additional information on the customer, such as economic activity and volume of assets, and updating the customer’s profile information, including beneficial ownership information, at shorter intervals;
  2. Obtaining additional information on the intended nature of the business relationship;
  3. Obtaining information on the source of funds or source of wealth of the customer;
  4. Obtaining information on the reasons for transactions with high amounts;
  5. Obtaining the approval of senior management to commence or continue the business relationship;
  6. Conducting inquiries from required information systems and/or comprehensive databases;
  7. Increasing the degree of control and monitoring by increasing control checkpoints, increasing the number of obtaining and reviewing business relationship information, and determining and identifying patterns of transactions requiring further examination;
  8. Commencing service provision to a newly opened account only after receipt of funds from an account in the customer’s name with a bank subject to acceptable CDD standards.
Article 80
EDD measures for service provision shall consist of completion of the EDD form by the customer and submission of the necessary supporting documentation to substantiate the statements made therein to the financial institution, and review and approval of the customer’s statements and documentation by the AML unit within the financial institution.
Note 1: With respect to services designated by the Center, the AML unit of the financial institution shall, by submitting the customer’s statements and documentation, make service provision conditional upon obtaining authorization from the Center.
Note 2: Supervisory authorities shall determine the executive directive of this Article, including the information items of the aforementioned forms, within one year, and after approval by the Center, promulgate them.
Note 3: Financial institutions shall, where EDD measures cannot be carried out, refrain from providing services to such persons.
Article 81
Financial institutions and the Central Bank of the Islamic Republic of Iran shall, within two years after the approval of this By-law, for the purpose of establishing an automated monitoring process for identifying financial operations or transactions suspected of ML/TF, deploy fraud detection software on all their systems based on data mining methods and in accordance with the financial behavior pattern standard.
Article 82
Financial institutions shall, when providing services, undertake ongoing and enhanced monitoring of the watchlist as notified to them by the Center.
Note: Financial institutions shall treat the names and particulars of the watchlist as confidential and, immediately upon receipt thereof, update the previous list in such a manner that the watchlist, together with its latest amendments, is always available to authorized employees. In the event of disclosure or any unauthorized use of the said information, preparators shall be punished in accordance with the law.
Article 83
The Center shall develop rules, criteria, and procedures for identifying suspected persons and submit them for approval by the Council.
Note 1: The Center shall inform financial institutions of changes to the list of suspected persons in the shortest possible time.
Note 2: Financial institutions shall provide the information and documentation required within the format and timeframe determined to the Center and make documentation available for persons who are under review.
Article 84
Persons whose names are included in the list of suspected persons may, by approaching financial institutions and submitting the necessary documentation, request removal from the said list. Upon review and confirmation of such documentation, the Center shall remove the person’s name from the list of suspected persons and notify financial institutions accordingly.
Article 85
Financial institutions shall, upon notification of the list of suspected persons, immediately refrain from providing new basic services to such persons and apply the restrictions announced by the Center in respect thereof.
Note: The imposed restrictions shall apply from the date of inclusion of the person in the list of suspected persons and shall be lifted only upon confirmation by the Center of the documentation submitted by the suspected person; such persons shall remain on the watchlist for a period of one year.
Article 86
Financial institutions shall, where notified by the Center and in the manner specified by the Center, provide the Center with the information obtained during EDD process.
Article 87
Financial institutions shall, in cooperation with supervisory authorities and the Center, prior to establishing any branch or subsidiary in high-risk countries in terms of ML/TF, adopt appropriate measures for risk control.
Article 88
Supervisory authorities shall, prior to granting a license to foreign financial institutions to establish a branch or representative office in the country, inquire from the Center regarding the status of the home country in terms of AML/CFT. Supervisory authorities shall, in cooperation with the Center, adopt appropriate measures in respect of branches or representative offices of financial institutions from high-risk countries for the purpose of risk control.
Article 89
Supervisory authorities shall, while conducting ongoing supervision and monitoring of relationships between domestic financial institutions and financial institutions of high-risk countries, where the risk of such relationships is assessed as higher, take appropriate measures and, if necessary, prevent the continuation of such relationships.
Article 90
Financial institutions shall draft all contracts concluded with customers in such a manner that implementation of AML/CFT regulations, including enhanced, normal, and simplified due diligence procedures, is enabled and the necessary undertakings are obtained from customers in that regard.
Article 91
All financial institutions shall, for the purpose of conducting appropriate due diligence procedures in respect of non-face-to-face services, act in accordance with non-face-to-face CDD regulations and procedures.
Note 1: The Ministry of Industry, Mine and Trade shall, in cooperation with the Ministry of Communications and Information Technology and the Center, develop non-face-to-face customer identification rules and procedures in the country, commensurate with the level of risk of business relationships and taking into account existing tools and infrastructures such as the National Iranian Inbox, digital signature certificate, and national mobile phone system, within six months after approval of this By-law, and make their implementation possible for financial institutions.
Note 2: All financial institutions shall provide the necessary cooperation with the Ministry of Industry, Mine, and Trade for the implementation of this Article.
Note 3: Provision of basic services to customers by financial institutions in a non-face-to-face manner shall be subject to compliance with a directive approved by the Council.

Chapter Six – Wire Transfer and Correspondent Banking Relationship

Article 92
Financial institutions shall, in relation to cross-border correspondent banking and other similar relationships, conduct an appropriate ML/TF risk assessment associated with correspondent banking activities and, subsequently, perform the necessary CDD measures (the respondent bank). Accordingly, correspondent banks shall, prior to establishing a business relationship and on an ongoing basis thereafter, collect sufficient information regarding respondent banks in order to fully understand the nature of that bank’s business and appropriately and continuously assess the ML/TF risks. At a minimum, the factors or measures that the financial institution shall consider in relation to the respondent bank are as follows:
  1. The country or jurisdiction in which the respondent bank is located;
  2. Gathering sufficient information about the respondent bank to fully understand the nature of the respondent’s business and its target market, and determining the bank’s reputation from publicly available information;
  3. The quality of supervision over the bank, including whether it has been subject to ML/TF investigation or other regulatory action;
  4. The financial group to which the respondent bank belongs and the country and jurisdiction in which the branches and subsidiaries of the group are located;
  5. Information regarding the management and ownership of the respondent bank (particularly the existence of beneficial owners or politically exposed persons (PEPs));
  6. The purpose of the services to be provided to the respondent bank;
  7. The situation and quality of banking regulation and supervision in the country of the respondent bank (particularly AML/CFT laws);
  8. The policies and procedures for the prevention and detection of ML/TF in the respondent bank, including that bank’s CDD measures;
  9. The ability to verify the identity of third parties that are authorized to use the services of the financial institution as a correspondent bank;
  10. An assessment of the respondent bank’s AML/CFT controls.
Note 1: The Central Bank of the Islamic Republic of Iran shall draft and promulgate, within six months, the minimum requirements and executive procedures for the implementation of this Article.
Note 2: Financial institutions shall obtain and review the required information regarding the AML/CFT policies and procedures of the correspondent bank through a questionnaire completed by the respondent bank or on the basis of publicly available information provided by it.
Note 3: The decision to establish or continue a correspondent banking relationship shall be subject to the approval of the senior management of the financial institution, and senior management shall be regularly informed of high-risk correspondent banking relationships and the way they are monitored.
Article 93
Financial institutions shall be prohibited from entering into a correspondent banking relationship with shell banks.
Note: Financial institutions shall, upon becoming aware of a correspondent banking relationship with shell banks, notify the Central Bank and act in accordance with its announced procedures.
Article 94
With respect to “payable-through accounts” (customers of the respondent bank), the financial institution shall be satisfied that the respondent bank:
  1. Conduct CDD on the customers having direct access to accounts of the correspondent bank;
  2. Is able to provide the institution with the customer information obtained in the course of the CDD process upon request of the financial institution.
Article 95
Financial institutions shall conduct all cross-border wire transfers exclusively through messaging systems approved by, and channels supervised by, the Central Bank of the Islamic Republic of Iran, and, when sending such transfers, shall obtain the following information:
  1. Originator information including first name and surname, national identification number/national identifier/specific identification number for foreign nationals, SHAHAB number (Card-based Electronic Fund Transfer System), date and place of birth, address, and the account number through which the wire transfer is conducted;
  2. 2Beneficiary information including first name and surname/company name, name of the bank, and the account number (destination account).
Note 1: The outgoing wire transfer shall contain a unique transaction reference number in such a manner that the transaction is traceable.
Note 2: The permitted instances of cross-border wire transfers and the persons authorized to conduct such operations shall be determined by the Central Bank of the Islamic Republic of Iran.
Article 96
Financial institutions shall conduct all domestic interbank wire transfers exclusively through the national payment infrastructures of the Central Bank of the Islamic Republic of Iran, including SATNA (Real-Time Gross Settlement System), PAYA (Automated Clearing House), and SHETAB (The Iran National Interchange Card Payment Switch) and, when sending such wire transfers, shall record the following information in the relevant systems of the Central Bank of the Islamic Republic of Iran:
  1. Originator information including first name and surname, national identification number/national identifier/specific identification number for foreign nationals, SHAHAB number, address, and the account number/IBAN of the account through which the transaction is conducted;
  2. Beneficiary information including first name and surname, account number/IBAN (destination account).
Note: The Central Bank of the Islamic Republic of Iran shall, within one year of the approval of this By-Law, provide the necessary infrastructure for the implementation of this Article.
Article 97
Financial institutions shall, when conducting all intrabank wire transfers, record the following information in the relevant systems of the financial institution:
  1. Originator information including first name and surname, national identification number/national identifier/specific identification number for foreign nationals, SHAHAB number, date and place of birth, address, and account number (the account through which the transaction is conducted);
  2. Beneficiary information including first name and surname, national identification number/national identifier/specific identification number for foreign nationals, SHAHAB number, date and place of birth, address, and account number (destination account).
Note 1: The executive directive of this Article with respect to financial institutions providing virtual asset services shall be drafted and promulgated by the competent supervisory authority in coordination with the Center.
Note 2: The Central Bank of the Islamic Republic of Iran shall, within six months from the date of promulgation of this By-Law, establish an integrated database of virtual asset transactions by obtaining the necessary information from supervised VASPs and provide the Center with online and unrestricted access thereto.
Article 98
Financial institutions shall, where they act as intermediaries in cross-border or domestic wire transfers, retain the received information of the originator and the beneficiary, as well as the required transaction information, throughout the payment chain and in the wire transfer process and related messages.
Note: The policies relating to the above subject shall be prepared by the Central Bank of the Islamic Republic of Iran, approved by the Council, and banks shall comply with the circulars issued by the Central Bank of the Islamic Republic of Iran in respect of the aforementioned wire transfers.
Article 99
Financial institutions shall, when conducting wire transfers (directly or through intermediaries), take the necessary measures, such as real-time monitoring or post-event monitoring, to detect those wire transfers that lack required transaction information, including originator/ beneficiary information, and shall also develop the necessary risk-based policies and procedures regarding the manner of handling such transfers.
Note: Financial institutions shall design their systems in such a manner as to automatically identify wire transfers that lack the required information of the parties to the transaction and prevent the execution of such transactions.
Article 100
PSPs shall obtain the necessary undertakings from acceptors regarding the non-misuse of acceptance devices and compliance with AML/CFT regulations. In the event of a breach by the acceptor, action shall be taken in accordance with the requirements of the Central Bank of the Islamic Republic of Iran.
Note 1: Instances of unauthorized use- such as transferring an acceptance device to another person, using it outside the approved access point, or using it to provide cash- shall be determined by the Central Bank of the Islamic Republic of Iran in cooperation with the Center.
Note 2: The contract between the PSP and the acceptor must explicitly stipulate that, in the event of unauthorized use of the acceptance device, the PSP may permanently terminate services to the acceptor without prior notice.
Note 3: Where an applicant requests multiple physical or virtual acceptance devices- including cases in which a legal entity applies for such devices for its head office, representatives, or branches- all obligations set forth in this By-Law must be fulfilled with respect to each individual device.
Note 4: Issuance of an acceptance device to persons under eighteen (18) years of age is prohibited.
Article 101
Financial institutions shall refrain from issuing gift cards, pre-paid cards, or similar payment cards to customers who do not maintain an account with the respective institution. They must also establish and record the linkage between such payment cards and the customer’s account within their systems.
Note: These cards shall be subject to regulations applicable to cash. Additional rules governing the issuance of such cards, aimed at mitigating the risks of ML/TF, shall be promulgated to financial institutions by the Central Bank of the Islamic Republic of Iran in cooperation with the Center.
Article 102
Prior to providing any physical acceptance device, PSPs shall, in addition to conducting normal CDD, obtain the following information from the acceptor and, after verification with the relevant authorities, record it in the customer profile:
  1. A copy of the economic activity license (e.g., business permit) evidencing authorization to conduct the relevant business activity, and, in the case of a legal entity, its registration documents, after verification against the original documents and licenses.
  2. The full address and postal code corresponding to the documents referred to in paragraph (1) of this Article, which must match the installation location of the acceptance device;
  3. The authorized account number linked to the acceptance device, whose holder’s details must correspond to those of the acceptor;
  4. Any additional information as required by the Central Bank of the Islamic Republic of Iran.
Article 103
Prior to providing any virtual acceptance device, PSPs shall, in addition to conducting normal CDD, obtain the following information from the acceptors and, after verification with the relevant authorities, record it in the customer profile:
  1. Information relating to the acceptor’s Electronic Trust Symbol (e-Namad) license or the business permit, subject to Article (87) of the Law on the Guild System of the Country (enacted in 2003) and its subsequent amendments;
  2. The full address and postal code of the acceptor’s place of business and presence (office or location where virtual processing equipment or systems are installed in accordance with the business license or legal entity registration documents), which must correspond to the address declared in the Electronic Trust Symbol and shall be field-verified by virtual PSPs;
  3. The acceptor’s precise website address and identification details, as well as the identity and address of the website host;
  4. The authorized account number linked to the acceptance device, whose holder’s details must correspond to those of the acceptor;
  5. Any additional information as required by the Central Bank of the Islamic Republic of Iran.
Note 1: The Ministry of Industry, Mine and Trade shall provide system-based and online inquiry access to the Electronic Trust Symbol for PSPs and the Central Bank of the Islamic Republic of Iran.
Note 2: The Ministry of Industry, Mine and Trade shall provide the Central Bank of the Islamic Republic of Iran with system-based information regarding any changes in the status of such symbols (including suspension, expiration, or revocation). The said Bank shall prevent the continued provision of services to the relevant virtual acceptance device.
Article 104
Prior to the installation and activation of any acceptance device, whether physical or virtual, the PSP shall obtain the following information in accordance with the acceptor’s declaration and record it in the acceptor’s data records:
  1. The individual threshold for each financial transaction.
  2. The monthly threshold for each acceptance device.
Note 1: Where the declared level of activity is inconsistent with the acceptor’s identity and economic information, the PSP shall determine the individual transaction threshold based on such information and in accordance with a method approved by the Center.
Note 2: The PSP shall report transactions exceeding the designated threshold for the acceptance device to the Center in accordance with the reporting structure announced by it.
Article 105
Any change in the acceptor’s information and data, including changes in physical or virtual location, changes in the nature of activity, and similar matters, must be communicated as soon as possible by the acceptor to the PSP that installed the acceptance device. The relevant PSP shall update such information and data in its information systems within one week. This obligation must be clearly stipulated in the acceptance device installation contracts.
Article 106
The use of an acceptance device in any guild other than that declared by the acceptor, or at any address other than the access point specified in the contract with the acceptor, without obtaining approval from the Comprehensive Acceptor System, is prohibited. In the event of such action by the acceptor, PSPs shall cease providing services to the acceptor and report the matter to the Center as a suspicious transaction. Provision of services to acceptance devices outside the borders of the Islamic Republic of Iran shall only be permitted with the approval of the Central Bank of the Islamic Republic of Iran.
Note 1: PSPs shall define an access point for each acceptance device so that, in the event of a change in the device’s address without coordination with the PSP, service provision shall not be possible.
Note 2: The access point for a physical acceptance device must be defined such that, where the device is connected to a fixed telephone line or fixed internet connection, its location corresponds to the registered location of the telephone line or fixed internet connection. In the case of the device connected to a mobile telephone line or mobile internet connection, ownership of the mobile line or internet connection must correspond to the identity registered with the PSP and to the owner of the bank account linked to the acceptance device.
Note 3: When granting a physical acceptance device connected to a mobile telephone or mobile internet connection, PSPs shall specify in the contract the authorized geographical area for the acceptor’s activity. If the device is used outside the specified area, an STR shall be submitted to the Center. Such areas must be defined proportionate to the size of the region, the level of ML/TF risk therein, and the available facilities.
Note 4: The access point for a virtual acceptance device must be defined in such a way that its use is possible solely through the specifications and website address registered with the PSP and the Electronic Trust Symbol.
Note 5: The Ministry of Communications and Information Technology, as well as operating companies and infrastructure providers, shall make available all facilities and services required for the implementation of this Article to the Central Bank of the Islamic Republic of Iran and PSPs.
Article 107
The Central Bank of the Islamic Republic of Iran shall establish the Comprehensive Acceptor System in a manner accessible to the Center, with a view to facilitating the process and supervising the implementation of the provisions of this Chapter. The system shall enable the ranking of PSPs in accordance with the procedures set forth in Article (40), as well as judicial prosecution of violations committed by acceptors and PSPs.

Chapter Seven – Money or Value Transfer Services

Article 108
Deleted
Article 109
Foreign exchange service providers shall implement all AML/CFT obligations, including CDD, record-keeping, and STRs, in all of their interactions and exchanges, and shall ensure compliance with the aforementioned requirements by their representatives and agents as well. The Central Bank of the Islamic Republic of Iran shall conduct continuous monitoring of license holders authorized by the Central Bank of the Islamic Republic of Iran, supervise the proper implementation of AML/CFT regulations by foreign exchange service providers, and, in cases of non-compliance, develop and impose effective, proportionate, and dissuasive disciplinary sanctions.
Note 1: The use of new delivery channels for the provision of foreign exchange services shall be permitted solely upon approval and licensing by the Central Bank of the Islamic Republic of Iran.
Note 2: Foreign exchange service providers shall submit to the Central Bank of the Islamic Republic of Iran, in accordance with the criteria it determines, the particulars of their representatives or agents through whom foreign exchange transactions and currency transfer services are conducted. With respect to foreign exchange service providers located outside the country that are not subject to the supervision of the Central Bank of the Islamic Republic of Iran, their representatives and agents operating domestically must obtain a license to conduct exchange operations from the Central Bank of the Islamic Republic of Iran. Failure to submit the required particulars or to obtain the required license in the aforementioned cases shall render the financial operations of such representatives or agents unauthorized, and violators shall be punished in accordance with the relevant laws, including the Law on Combating the Smuggling of Goods and Currency and the Sixth Five-Year Development Plan Law.
Article 110
The Central Bank of the Islamic Republic of Iran shall, through continuous supervision and system-based monitoring of foreign exchange service providers, identify their transactions with persons engaged in unauthorized foreign exchange activities and, while preventing such transactions, impose the appropriate legal restrictions and sanctions against them.
Note 1: The Central Bank of the Islamic Republic of Iran shall design, upgrade, and implement its mechanisms for conducting foreign exchange transactions and services in such a manner that all formal exchanges and interactions in the field of foreign exchange are carried out under the supervision of the Central Bank and, while ensuring transparency of exchanges, enable financial traceability and the detection of violations in the foreign exchange domain. The mechanism in question shall be designed in such a way as to enable the Central Bank of the Islamic Republic of Iran to supervise the performance of foreign exchange service providers in recording transaction and financial operation data.
Note 2: The Central Bank of the Islamic Republic of Iran shall, through methods such as reconciliation with account turnover levels, identify those foreign exchange service providers that register inaccurate information in the systems relating to the recording of transactions and financial operations and, where necessary, report the matter to the competent judicial authority.
Note 3: The Central Bank of the Islamic Republic of Iran shall design and implement an effective system-based mechanism to establish correspondence between Rial and foreign exchange transactions on authorized exchange platforms and, on that basis, detect violations and adopt enforceable measures.
Note 4: The Central Bank of the Islamic Republic of Iran shall, through continuous supervision and monitoring, ensure that the conduct of foreign exchange activities and the deployment of acceptance devices by foreign exchange service providers are based solely on official and declared Rial and foreign exchange accounts. Furthermore, in order to enhance transparency of exchanges, the Central Bank of the Islamic Republic of Iran shall design and implement the necessary infrastructure to maximize the conduct of foreign exchange transactions and exchanges through foreign exchange accounts.
Note 5: Foreign exchange service providers shall, in the event of suspicion regarding the unauthorized status of counterparties, including persons engaged in unauthorized foreign exchange activities, submit the particulars of such persons together with the records of the exchanges conducted to the Central Bank of the Islamic Republic of Iran and report the matter to the Center in the form of an STR.
Article 111
Money or value transfer service (MVTS) providers shall, when conducting transfers of money or value, take reasonable and logical measures to detect those transfers that lack required information relating to the originator or the beneficiary and, with respect to such transfers, act in accordance with a risk-based approach. Furthermore, such providers shall, where they act as an intermediary in a transfer, ensure that the required information accompanies the transfer of money or value.
Note: The required information referred to in this Article shall be determined and announced by the Central Bank of the Islamic Republic of Iran in cooperation with the Center.
Article 112
The provision of money transfer services, including the provision of electronic wallets, payment facilitation services, fund aggregation, payment processing, and account facilitation, without compliance with AML/CFT regulations, including CDD, record-keeping, maintaining the information throughout the payment chain, and STR, is prohibited.
Note 1: The Central Bank of the Islamic Republic of Iran shall, in order to mitigate the ML/TF risk in the provision of money transfer services, adopt appropriate measures, including the determination of a maximum threshold for service provision and a permissible daily transaction number for each customer, commensurate with the risk level of the business relationship.
Note 2: Responsibility for the proper implementation of AML/CFT regulations by money transfer service providers rests with those financial institutions or PSPs that make their infrastructure available to them.
Note 3: The rules and criteria for the implementation of this Article, taking into account the level of risk and the scope of provision of such services, shall be prepared by the Central Bank of the Islamic Republic of Iran, in coordination with and subject to the approval of the Center, and promulgated accordingly.

Chapter Eight – Cash Couriers (Physical Cross-Border Transportation of Currency, Bank Instruments, and Bearer Negotiable Instruments)

Article 113
The incoming cross-border transportation of currency, bank instruments, and bearer negotiable instruments through points of entry shall be permitted solely within the framework of the “Directive on Regulations Governing Currency/Bank Instruments and Bearer Negotiable Instruments Accompanying Travelers” (promulgated by the Central Bank of the Islamic Republic of Iran), and the Islamic Republic of Iran Customs Administration shall, in cooperation with the Center, Bank Melli Iran, and the Law Enforcement Command of the Islamic Republic of Iran, establish the necessary system-based mechanism for the implementation of the aforementioned Directive.
Note: Where there is suspicion of ML/TF, predicate offences, or the truthfulness of the traveler’s declarations, the Islamic Republic of Iran Customs Administration shall, within the framework of the said Directive, while retaining the currency, bank instruments, and bearer negotiable instruments with Bank Melli Iran, report the matter without delay to the Center for further action. Where the origin of the currency or instruments in question is not confirmed, the Center shall, while submitting a report to the competent judicial authority, notify the Islamic Republic of Iran Customs Administration so as to refrain from returning the said currency or instruments to the traveler pending determination. Where the origin of the said currency or instruments is confirmed, the Center shall notify the Islamic Republic of Iran Customs Administration without delay that there is no impediment to their return.
Article 114
Foreign exchange service providers that, within the framework of the foreign exchange regulations of the Central Bank of the Islamic Republic of Iran, engage in foreign currency exchange shall, in addition to conducting appropriate CDD measures and obtaining information from the applicant regarding the purpose of receiving the service (including the place and manner of expenditure of the requested cash currency), obtain the necessary documents and evidence relating thereto from the customer and record the information referred to in this Article in the relevant systems. Agent banks shall issue a bank declaration evidencing the sale of foreign currency in banknote form for the purpose of its cross-border transportation out of the country by the traveler for submission to the Islamic Republic of Iran Customs Administration.
Note1: In order to mitigate the risk of cross-border transportation of currency in cash, the Central Bank of the Islamic Republic of Iran shall adopt the necessary measures to reduce demand for foreign currency in cash and to provide non-cash alternatives to travelers departing abroad.
Note 2: The permissible threshold for the amount of foreign currency in cash that may be provided to customers by foreign exchange service providers shall be determined and announced periodically by the Central Bank of the Islamic Republic of Iran, depending on prevailing conditions.
Article 115
The cross-border transportation of currency, bank instruments, and bearer negotiable instruments through points of exit shall be permitted solely within the framework of foreign exchange rules and regulations and the directive referred to in Article (113), and the Islamic Republic of Iran Customs Administration shall, in cooperation with Bank Melli Iran, the Center, and the Law Enforcement Command of the Islamic Republic of Iran, establish the necessary system-based mechanism for the implementation of the said Directive.
Note 1: In the absence of the required documentation (a declaration form and a bank declaration evidencing the sale of foreign currency in banknote form within the framework of the rules and regulations of the Central Bank of the Islamic Republic of Iran), the cross-border transportation of currency out of the country by a traveler shall be prohibited.
Note 2: For the purpose of fulfilling the obligations set forth in this Article, the Central Bank of the Islamic Republic of Iran shall, in cooperation with the Islamic Republic of Iran Customs Administration, establish a mechanism that, while enabling the determination of the legality or illegality of the manner of purchase of foreign currency, provides electronic access for the country’s border entry (gate) points to the relevant information.
Note 3: Where there is suspicion of ML/TF, predicate offences, or the authenticity of the documents and evidence submitted, the law enforcement agencies are required, while retaining the currency, bank instruments, and bearer negotiable instruments with Bank Melli Iran, report the matter without delay to the Center for further action. Where the origin of the said currency or instruments is not confirmed, the Center shall, while submitting a report to the competent judicial authority, notify the relevant law enforcement agencies so as to refrain from returning the said currency or instruments to the traveler pending determination. Where the origin of the said currency or instruments is confirmed, the Center shall notify the relevant law enforcement agencies without delay that there is no impediment to their return.
Article 116
The payment of Rial cash on any given day by financial institutions under the supervision of the Central Bank of the Islamic Republic of Iran shall be permitted up to the designated threshold announced by the Central Bank, and the payment of Rial cash by other financial institutions and DNFBPs shall be permitted solely up to the threshold designated by the Council.
Note 1: Financial institutions shall upgrade their software systems relating to cash payments so as to include information concerning the type and denomination composition of the cash provided to the customer together with the amount of each, in such a manner as to ensure that payment of cash exceeding the designated daily threshold for each customer does not occur.
Note 2: Financial institutions are required to upgrade their software systems in such a way that the daily payment of cash exceeding the designated threshold to a customer becomes systemically (electronically) impossible and that compliance with the necessary obligations by employees is ensured.

Chapter Nine – Confiscation and Provisional Measures

Articles 117 to 134
Deleted

Chapter Ten – Reporting

Article 135
Financial institutions shall, upon observing transactions and operations suspected of ML/TF, or other predicate offences, following preliminary review and where there exists suspicion of the commission of a crime, promptly and without notifying the customer, submit a report to the Center in accordance with the format and mechanism announced by the Center.
Note 1: Where an AML unit has been established within a financial institution, the said unit shall, following preliminary review and where there exists suspicion of the commission of a crime, submit the STR through the system established by the Center for the purpose of collecting STRs, no later than the end of the same working day. Where access to the said system has not been provided by the Center to the obliged person, the AML units shall submit the report in the manner which will be specified by the Center.
Note 2: Financial institutions shall, by conducting daily review of the system for the collection of STRs, respond to inquiries recorded therein within a maximum of one day and submit the required information in the prescribed format and through the system.
Article 136
The discernment by employees of financial institutions that an operation is suspicious, in addition to the criteria stated and the rules announced by the Center, may itself constitute a criterion for the identification of suspicious operations.
Note 1: STRs and other reports which financial institutions are obligated to submit shall not give rise to any liability for good-faith reporters acting in implementation of the Act and this By-Law and shall not imply any accusation against the persons who are the subject of the report, and submission thereof to the Center shall not be deemed a breach of personal confidentiality.
Note 2: The Center shall, at the time of reviewing and drafting the said rules, examine and standardize newly announced criteria proposed by financial institutions. In any event, the submission of STRs shall not be contingent upon the announcement of standardized rules and criteria.
Note 3: A financial institution shall develop appropriate criteria for the identification of suspicious transactions for its various structural levels (branch, supervisory unit, etc.) and, following approval by the Center, communicate them accordingly; the said criteria shall not be inconsistent with the standardized rules and criteria announced by the Center.
Note 4: Financial institutions shall provide the Center with all information necessary for the drafting of the announced rules.
Article 137
Financial institutions shall submit reports of transactions exceeding the thresholds designated by the Center, in the format and through the mechanism announced, to the Center.
Article 138
The Center shall, by adopting appropriate measures, conduct evaluation and preliminary analysis of STRs based on transparent and clear procedures, criteria, and indicators approved by the Council.
Article 139
Employees of financial institutions shall record all business relationships involving cash exceeding 10,000 Euros (or its equivalent in other currencies) or 1,000,000,000 Rials (single or aggregated), including transactions, transfers, and transactions for which the customer pays the amount daily in cash, and notify the AML units thereof together with the customer’s explanations confirmed by the customer. The said units shall submit a summary of the relevant forms at the end of each week in the manner specified by the Center and keep the originals in a fully secure manner.
Note: The amount of Rial and foreign currency cash referred to in this Article shall, where necessary, be updated by the Council and submitted to the Council of Ministers for approval.
Article 140
Financial institutions shall, upon notification by the Center, provide it with a summary list of information relating to recipients of basic services at the intervals announced and, in the manner, specified by the Center.
Article 141
All natural and legal persons, in cases where they observe suspicion of the commission of the crime of ML/TF, may report the matter directly to the Center.
Note 1: Reports in which the identity of the reporter is not specified, or which contain incomplete or incorrect information, shall not be processed unless accompanied by indications that, in the opinion of the Center, are sufficient to initiate analysis.
Note 2: The Center shall, in order to enable direct and confidential reporting by persons, establish the appropriate mechanism and provide notification thereof.

Chapter Eleven – Record-Keeping

Article 142
Financial institutions shall maintain documents, records, and information relating to business relationships for a period of (10) years in such a manner that, upon request by competent authorities, the said items may be provided swiftly. The documents, records, and information referred to in this Article include, inter alia, the following:
  1. Documents, records, and information obtained through the CDD measure, whether simplified, normal, or enhanced, including copies of documents evidencing the identity of the customer and the beneficial owner;
  2. Documents, records, and information relating to account files and business correspondence;
  3. Documents, records, and information relating to transactions and financial operations, whether domestic or international, in such a manner that such records contain sufficient information on assets (including the amounts and, where applicable, the types of currency involved in each transaction) and enable the reconstruction of individual transaction process and the provision of sufficient information, documents, and evidence for the prosecution of criminal activity.
Note 1: In the event of dissolution of obliged legal persons, as applicable, the relevant administrator or liquidation board shall also keep the information and documents for (10) years following dissolution.
Note 2: This Article shall not prejudice other regulations requiring keeping of documents for a period exceeding the aforementioned duration.
Article 143
Financial institutions shall record and keep information, records, and documents in such a manner that, upon request by the Center or competent authorities, including law enforcement agencies, the information contained in such documents is accessible within two working days. Furthermore, the original documents and records, upon request by the Center and other competent authorities, shall be provided within one week.
Note 1: Responsibility for providing information and documents with respect to natural persons rests with the financial institution itself and, with respect to legal persons, with the highest-ranking official of the financial institution.
Note 2: The said information and documents must enable, where necessary, the reconstruction of the transaction chain process.
Note 3: Specific documents, records, and information announced by the Center shall be kept electronically in such a manner that, while preserving their confidentiality, they are accessible within one working day upon request by competent authorities and without the need to obtain them from branches and representatives.

Chapter Twelve – Guidance and Training

Article 144
Supervisory authorities shall, in coordination with and subject to the approval of the Center, draft and promulgate to financial institutions the necessary feedback, guidelines, and requirements for the proper implementation of AML/CFT regulations.
Article 145
Financial institutions shall, in coordination with the Center, conduct needs assessments and design, implement, and evaluate continuous programs for the training and capacity-building of their employees in combating ML/TF.
Note 1: Supervisory authorities shall, while evaluating and supervising the training courses conducted, submit reports thereof to the Center on a quarterly basis.
Note 2: The minimum required training for assuming each of the relevant positions in financial institutions shall, as applicable, be announced by the Center.
Note 3: The training courses referred to in this Article, with respect to directors and employees of executive bodies subject to Article (5) of the Civil Service Management Law, shall be eligible for the benefits provided in Chapter Nine of that Law.
Article 146
The Judiciary, while observing Article (30) of the Criminal Procedure Code and its subsequent notes, shall, in cooperation with the Center, undertake continuous training of judicial authorities, judicial staff and employees, and law enforcement agencies with respect to ML/TF and their legal dimensions as independent offences.
Note: The executive regulations of this Article shall, within six months, be drafted by the Judiciary in cooperation with the Center.

Chapter Thirteen – New Technologies

Article 147
Financial institutions and DNFBPs shall, at all times prior to launch of any new product, service, or delivery channel, undertake a risk assessment and ensure that the mechanisms for the provision thereof are aligned with AML/CFT regulations, and submit the relevant report to their respective supervisory authority.
Note: Supervisory authorities shall, regardless of the assessments conducted by the financial institutions under their supervision, identify and assess the ML/FT risks associated with launching new products, services, and delivery channels within their respective supervisory authority. For this purpose, supervisory authorities shall, in addition to examining the use of new or developing technologies in relation to both new and pre-existing products, take into consideration issues such as new business practices and new mechanisms for the transfer and delivery of goods. Ultimately, these authorities shall adopt appropriate measures to manage and mitigate such risks and shall promulgate them to the relevant financial institutions for implementation.

Chapter Fourteen – DNFBPs & NPOs

Article 148
The Ministry of Interior shall take the necessary measures to prevent the abuse of NPOs, or the possibility of operating under the cover of such organizations for ML/TF. It shall also prevent terrorist individuals and groups from exploiting legitimate institutions for the purpose of escaping asset-freezing measures.
Note: The Ministry of Interior and the Ministry of Justice shall, in coordination with the Center and other relevant authorities, submit, within six months from the date of promulgation of this By-Law, the relevant directive on the “Organization and Regulation of the Activities of NPOs” to the Council for approval.
Article 149
The obligations and regulations relating to risk assessment, supervisory procedures, CDD, record-keeping, STRs, and training set out in Chapters Two, Four, Five, Ten, Eleven, Twelve, and Thirteen of this By-Law shall apply, in the following situations and within the framework determined in the procedure announced by the Center, to DNFBPs and their relevant supervisory authority:
  1. Real estate agents and brokers- when they are involved in transactions for their clients concerning the buying, selling or leasing of real estate;
  2. Dealers in cars, gold, silver, coins, precious metals, precious stones, antiques, art works and high-value handicrafts, and high-value handmade carpets- when they engage in any transaction with a customer in cash or by barter, exceeding the designated threshold;
  3. Notaries and their deputies, independent accountants and certified auditors and audit firms, lawyers, independent legal professionals or legal professionals employed in legal firms- when they prepare for or carry out transactions for their client concerning the following activities:
  1. buying and selling of real estate;
  2. managing of client money or other assets;
  3. management of bank and savings or securities accounts;
  4. organization of contributions for the creation, operation, or management of civil and commercial companies;
  5. creation, operation, or management of legal persons or arrangements, and buying and selling of companies, institutions, and business entities.
Article 150
Any raising and provision of funds or other assets from the public and disbursing thereof by NPOs shall be subject to obtaining a license or establishment permit from the competent authority. The Ministry of Interior shall identify persons, groups and associations engaged in unauthorized activities and take necessary measures in accordance with applicable regulations to prevent the continuation of the activities of such organizations and associations and take enforcement action against them.
Article 150 (bis)
The Ministry of Interior shall, for the purpose of transparency, supervision, and integration of the issues related to NPOs, establish and operationalize, within six months after the approval of this By-Law, a Comprehensive Social Participation System with the following capabilities:
  1. Electronic processing of the creation procedure of NPOs;
  2. Uploading of the articles of association and activity licenses of NPOs;
  3. Risk assessment of NPOs;
  4. Recording of identity, economic, and geo-referenced information of donors and beneficiaries;
  5. Retention and public disclosure of financial statements;
  6. Recording and public disclosure of bank accounts information of NPOs;
  7. Recording of data related to international assistance and corresponding commitments;
  8. Receipt of public reports regarding breaches by NPOs;
  9. Creation of NPOs profiles;
  10. Recording of data concerning founders and directors of NPOs, including members of boards of trustees, boards of directors, managing directors, and other managers;
  11. Recording and public disclosure of all revenues and expenditures, disaggregated by revenue and expenditure categories;
  12. Recording of all properties and assets of NPOs;
  13. Exchange of information between supervisory authorities and NPOs.
Note 1: The Ministry of Interior shall, within six months after the launch of the system referred to in this Article, complete its information in cooperation with other relevant authorities and provide the necessary access to the Center and law enforcement agencies.
Note 2: NPOs shall, after the launch of the Comprehensive Social Participation System, complete their information in accordance with the procedures announced by the Ministry of Interior.
Note 3: The implementation of paragraphs (4), (5), (9), and (11) of this Article shall be mandatory only for those NPOs as announced by the Ministry of Interior commensurate with their level of risk and following approval by the Center.
Note 4: The State Organization for Registration of Deeds and Properties, the National Organization for Civil Registration, the National Tax Administration, the Central Bank of the Islamic Republic of Iran, and authorities issuing licenses or permits or providing assistance to NPOs, including the Judiciary, the Vice Presidency for Women and Family Affairs, the Department of Environment, the Ministries of Culture and Islamic Guidance, Sports and Youth, Foreign Affairs, Cooperatives, Labour and Social Welfare, Education, Justice, Agriculture, Science, Research and Technology, Health and Medical Education, Cultural Heritage, Tourism and Handicrafts, the Law Enforcement Command of the Islamic Republic of Iran, and the Islamic Propagation Organization, the Hajj and Pilgrimage Organization, the Endowments and Charity Affairs Organization, the Basij Organization, the State Welfare Organization, the Imam Khomeini Relief Committee, the Headquarters for Executing the Order of the Imam, the Foundation of the Oppressed of the Islamic Revolution, municipalities, and the Red Crescent Society of the Islamic Republic of Iran, shall provide the information required by the Comprehensive Social Participation System in accordance with the procedures and timelines announced by the Ministry of Interior. The Ministry of Interior shall report the performance of the aforementioned authorities to the Council.
Note 5: Financial institutions shall, commensurate with the level of risk of NPOs as determined by the Comprehensive Social Participation System, decide on the manner of provision of services thereto.
Article 151
The Ministry of Interior shall supervise the proper implementation of the obligations of NPOs as set forth in AML/CFT laws and regulations and, in cases of breach, apply the following sanctions in accordance with relevant regulations:
  1. Written warning with entry in the file;
  2. Temporary suspension of the permit or license until fulfillment of the relevant obligations;
  3. Prohibition from receiving assistance and services provided by governmental bodies and authorities;
  4. Non-renewal of the permit or license;
  5. Revocation of the permit or license.
Note 1: Other licensing or permitting authorities shall apply the above sanctions upon request of the Ministry of Interior.
Note 2: In cases where the permit or license of NPOs is suspended, the tax exemptions provided under Articles (139) and (172) of the Direct Taxes Law shall not apply to the said NPOs, as notified by the Ministry of Interior.
Article 152
Authorities referred to in Article (29) of the Sixth Five-Year Economic, Social and Cultural Development Plan of the Islamic Republic of Iran shall register their assistance to NPOs in the Iranian Welfare System.
Note: The Ministry of Cooperatives, Labour and Social Welfare shall provide the relevant information in the Iranian Welfare System to the Ministry of Interior on an online basis.
Article 152 (bis)
The issuance of commercial cards and the granting of major facilities and commitments to all persons financially supported by an NPO shall be prohibited during the period of such support.
Note 1: The granting and provision of the privileges and services referred to in this Article to persons previously financially supported by an NPO shall be subject to risk assessment by the granting authority.
Note 2: The Ministry of Interior shall submit the information of the persons referred to in this Article on a monthly basis to the Central Bank of the Islamic Republic of Iran and the Ministry of Industry, Mine and Trade.
Note 3: Persons financially supported by an NPO may submit a request for reconsideration concerning the issuance of a commercial card and the granting of major facilities and commitments to the Ministry of Interior. Where the request is approved, the Ministry of Interior shall remove the applicant’s name from the list referred to in this Article and announce the same.

Chapter Fifteen – Miscellaneous

Article 153
The manner of international cooperation in relation to combating ML/TF, pursuant to paragraph (d) of Article (7) bis of the Act and in compliance with other relevant laws and regulations, shall be in accordance with a By-Law prepared by the Council and approved by the Supreme National Security Council.
Article 154
Obliged persons shall, while keeping customer information, adopt the necessary protective and security measures in the collection, keeping, and exchange of information and documents subject to the Act and this By-Law and to prevent any unauthorized disclosure and use thereof.
Note: The manner of cooperation of obliged persons with foreign counterparts shall be within the framework of the rules announced by the Council and in accordance with relevant regulations.
Article 155
All obliged persons shall provide the information requested by designated law enforcement agencies pursuant to a judicial order related to combating ML/TF, within the framework of the rules announced by the Center in cooperation with such officers.
Article 156
The Council shall prepare the necessary directives to ensure the proper implementation of this By-Law and, following approval, communicate them to obliged persons. Compliance with such directives by these persons shall be mandatory.
Note: Supervisory authorities shall also, as needed, prepare draft directives necessary for the implementation of this By-Law and submit them to the Center for approval. These directives, after approval by the Council, shall be communicated to obliged persons.
Article 157
The Center shall be accountable solely within the scope of reports submitted to judicial authorities, and responsibility for tracing and other investigations necessary to establish the offence shall rest with law enforcement agencies.
Article 158
The provisions of this By-Law and other regulations and executive procedures based thereon, whether pertaining to AML or CFT, shall be binding and enforceable upon all natural and legal persons, and breaches thereof shall be subject to the administrative-disciplinary proceedings set forth in Article (41) of this By-Law. Supervisory authorities and other relevant bodies shall, where the breach constitutes a criminal offence, in addition to administrative-disciplinary proceedings, refer the competent judicial authority for the imposition of the sanctions provided in Note (3) of Article (4) and the Note to Article (7) of the Act and Note (1) of Article (14) of the CFT Act approved in 2016, as amended and supplemented.
Article 159
All educational and research institutions affiliated with or under the supervision of executive bodies, including the Economic Research Institute of the Ministry of Economic Affairs and Finance and the Monetary and Banking Research Institute of the Central Bank of the Islamic Republic of Iran, shall, either on their own initiative or at the request of the Center, conduct training courses on AML/CFT and carry out research and studies in this field.
Article 160
The Islamic Republic of Iran Broadcasting (IRIB) and the Ministry of Culture and Islamic Guidance shall, in coordination with the Center, produce and broadcast multimedia products and contents aimed at enhancing public awareness, explaining the harmful effects of ML/TF and the risks arising from abuse of personal identification documents, and promoting the obligations and duties of obliged persons.
Article 161
Financial institutions and supervisory authorities shall, in furtherance of social prevention and awareness-raising, allocate two percent (2%) of their total credits related to training, media production, and corporate social responsibility to the promotion and training of AML/CFT in the manner announced by the Center and report the measures taken annually to the Center.
Article 162
The Council shall, for the purpose of coherence and coordination in matters of AML/CFT, establish specialized commissions in furtherance of the Council’s missions. The members, manner of administration and decision-making, manner of holding meetings, and the duties and powers of the said commissions shall be prepared by the Secretariat of the Council within one month after approval of this By-Law and submitted for approval to the Council.
Article 163
The Ministry of Interior, the Islamic Republic of Iran Customs Administration, and the National Tax Administration shall, subject to compliance with relevant legal formalities, allocate appropriate structure, resources, and authorities for the implementation of the obligations assigned to them under AML/CFT laws and regulations and take action to amend the same in accordance with the resolutions of the Council.
Article 164
In view of the revocation of the Executive By-Law of AML Act, approved in (2009), the Council shall, within six months from the date of promulgation of this By-Law, repeal or amend the regulations based on the said By-Law and the directives of the Council adopted prior to the amendment of the AML Law.