Compliance Advisory · Bahrain & GCC

Compliance frameworks a supervisor will recognise as real.

SRR designs and embeds AML, CFT, and governance frameworks for CBB licensees and designated non-financial businesses across Bahrain, from customer due diligence and reporting routes to the policies, training, and ownership beneath them.

The short answer

What does compliance and AML advisory in Bahrain cover?

It covers the design and embedding of AML and CFT frameworks under Decree-Law No. 4 of 2001, regulatory compliance reviews, governance structures, and policy development. That means documented customer due diligence, ongoing monitoring, record keeping, staff training, and a defined route for reporting suspicious transactions, built to operate in practice rather than to sit in a manual.

AML obligations extend beyond banks to designated non-financial businesses and professions (DNFBPs), so real estate, dealing, and professional-services businesses can carry the same duties. Supervision sits with the CBB for licensed institutions and the relevant ministry for DNFBPs. SRR is a management and business advisory consultancy; where a formal legal opinion is required, that sits with qualified legal counsel.

AML legal basis
Decree-Law 4/2001
Bahrain’s AML and CFT regime rests on Decree-Law No. 4 of 2001, which sets the legal basis for the obligations that follow.
Who is covered
Beyond banks
Obligations extend to designated non-financial businesses and professions (DNFBPs), not only to CBB-licensed financial institutions.
Core duties
CDD to STR
A compliant business needs documented customer due diligence, ongoing monitoring, record keeping, training, and a route for reporting suspicious transactions.

What We Handle

From the obligation to a framework that works.

One team assesses what applies, builds the AML and governance framework, and trains the people who have to run it, so the controls operate rather than just exist.

  • Regulatory compliance reviews and gap assessments
  • AML and CFT framework design under Decree-Law No. 4 of 2001
  • Customer due diligence and ongoing monitoring procedures
  • Suspicious transaction reporting routes and escalation
  • Policy and procedure development, and periodic refresh
  • Governance frameworks and board and committee structures
  • AML and compliance staff training and awareness

Who It Is For

Where clients come to us on compliance.

You are a DNFBP and only now realising AML applies

A real estate, dealer, or professional-services business that carries customer due diligence and reporting duties under the AML regime, without a framework in place to meet them.

A regulator or bank has asked for your AML policy

A supervisor, a correspondent bank, or a counterparty wants to see documented CDD, monitoring, and reporting procedures, and the current position will not withstand the request.

Your policies exist but nobody follows them

A compliance manual that was written once, never trained on, and does not match what the business actually does day to day.

You are building governance for the first time

A growing business or institution that needs board, committee, and reporting structures, with clear ownership of compliance rather than an informal arrangement.

How It Works

From obligation to an embedded framework.

  1. Assess the obligations

    We establish which regime and which obligations apply to your business, whether as a CBB licensee or a designated non-financial business, and review the current position against them.

  2. Design the framework

    We build the AML, CFT, and governance framework: policies, customer due diligence and monitoring procedures, reporting routes, and the ownership beneath them.

  3. Embed and train

    We put the procedures into practice and train the staff who have to apply them, so the framework operates rather than sitting in a manual.

  4. Keep it current

    We refresh policies and procedures as the rules and the business change, so the framework does not drift out of date between reviews.

What Goes Wrong

The compliance gaps supervisors find.

Assuming AML is only for banks

Designated non-financial businesses and professions carry real customer due diligence and reporting duties. Assuming the regime stops at licensed financial institutions is one of the most common and most exposed compliance gaps.

A policy with no procedure beneath it

A high-level AML policy with no working CDD procedure, no monitoring, and no escalation route is a statement of intent, not a control, and it will not satisfy a supervisor.

No route for suspicious transaction reporting

Without a defined escalation and reporting route, a suspicious transaction has nowhere to go, and the obligation to report is missed at exactly the moment it matters.

Training that never happened

Staff who have never been trained cannot apply the framework. Untrained staff are both a compliance failure in themselves and the reason the rest of the framework does not work.

Common Questions

Compliance and AML advisory, answered.

What is the legal basis for AML compliance in Bahrain?

Bahrain’s anti-money laundering and counter-terrorism-financing regime rests on Decree-Law No. 4 of 2001, which criminalises money laundering and terrorism financing and provides the legal basis for the obligations businesses must meet. Supervision sits with the CBB for licensed institutions and with the relevant ministry for designated non-financial businesses and professions.

Does AML apply to my business if we are not a bank?

Very possibly. AML obligations extend well beyond banks to a range of designated non-financial businesses and professions, including certain real estate, dealing, and professional-services activities. If your business is a DNFBP, it carries real customer due diligence, record keeping, and reporting duties, and assuming otherwise is a common and exposed gap.

What does a compliant AML framework actually require?

Documented customer due diligence, ongoing monitoring of the business relationship, record keeping, staff training, and a defined route for reporting suspicious transactions. Each element has to work in practice, not just exist on paper, because a supervisor tests whether the framework operates, not just whether a policy document exists.

What is a suspicious transaction reporting route, and why does it matter?

It is the defined internal path by which a member of staff escalates a suspicion, through the reporting officer, to the authorities where required. Without it, a suspicious transaction has nowhere to go and the reporting obligation is missed at the moment it matters most. Building and documenting that route is a core part of the framework.

Can you help with governance beyond AML?

Yes. Compliance advisory covers governance frameworks, board and committee structures, and policy development more broadly, alongside AML and CFT. The aim is clear ownership of compliance and a structure that a regulator, a board, or a counterparty can see is real rather than nominal.

Who leads the work, and what is SRR’s role?

Engagements are led by ACA and ACCA qualified practitioners. SRR Consultants is a management and business advisory consultancy: we design and embed the compliance framework and train the staff who run it. We are not a regulator or a law firm, so where a formal legal opinion is required, that sits with qualified legal counsel.

Put a compliance framework in place that holds up.

A short call with a senior practitioner is the quickest way to scope an AML framework, a compliance review, or a governance structure.