Read Time
Categories
Share
POJK 8/2023 read as a system requirement: CDD and EDD triggers, three verification mechanisms, ten vendor clauses and a 3-working-day deadline.

AML/CFT in Indonesia goes by the acronym APU PPT (anti pencucian uang dan pencegahan pendanaan terorisme), and its official name is now APU, PPT and PPPSPM because it also covers the financing of weapons-of-mass-destruction proliferation. For the financial services sector the rule in force is OJK Regulation (POJK) Number 8 of 2023, enacted and promulgated on 14 June 2023, which revoked POJK 12/POJK.01/2017 and POJK 23/POJK.01/2019 (Article 89). For digital onboarding the core is Article 21 paragraph (2): three verification mechanisms are recognised, and the one with no officer involved requires population data plus at least 2 authenticity factors.

This piece is for heads of AML, internal audit (SKAI) and compliance officers at banks, insurers, securities firms and multifinance companies in Indonesia, and for the regional compliance teams that supervise them from Singapore, Hong Kong or Tokyo. The definition ends with the paragraph above. The rest treats APU PPT as a system requirement: what has to be built, logged, and produced within 3 working days. Quotations are our translation; the Indonesian text governs, and "Article" stands for Pasal throughout.

The rule in force, and the OJK pages that haven't caught up

POJK 8/2023 took effect on promulgation (Article 90) and allowed a 6-month adjustment period (Article 85), which ran out in December 2023. It binds the 18 categories of financial service provider (penyedia jasa keuangan, PJK) listed in Article 2 paragraph (1), among them banks, securities companies, insurance companies, financing companies and technology-based joint funding (P2P lending) operators. The text is in OJK's PDF, in Indonesian; we worked from that text, not from a translation.

One thing we checked on 7 October 2026. OJK's own APU-PPT page sits at organic position 3 for the Indonesian query "apu ppt adalah" and is the first source Google's AI Overview cites for it. That page still lists 39/POJK.05/2015, 22/POJK.04/2014, PBI 14/27/PBI/2012 and PBI 12/20/PBI/2010. A string search of its HTML doesn't find "Tahun 2023" once. The national APU-PPT regime page, the second source in the same AI Overview, still names POJK 12/POJK.01/2017, which Article 89 revoked.

We don't think this is a housekeeping problem on a regulator's website. A head-office summary or an internal policy drafted from those pages, or from an AI answer that cites them, points at rules that are no longer in force. Check your own policy before the examiner does.

When CDD is mandatory, and when it becomes EDD

Article 19 sets five triggers for customer due diligence (CDD), and Article 35 paragraph (3) makes enhanced due diligence (EDD) mandatory once any one of eight high-risk criteria is met. Every reference in the table is to POJK 8/2023.

Customer or transaction situationWhat must be doneArticle
A prospective customer opens a business relationshipCDD: identification, verification, risk classification19 letter a; 20 paragraph (1)
A transaction of at least Rp100,000,000, including several transactions reasonably suspected to be linkedCDD19 letter b and its Elucidation
A funds transferCDD19 letter c
Indication of a suspicious financial transactionCDD, "without regard to any exemption or transaction value limit"19 letter d and its Elucidation
The information supplied is in doubtCDD19 letter e
Low risk. The Elucidation's examples: payroll accounts, companies majority-owned by the government, government agencies, branchless banking for financial inclusion (the scheme known as Laku Pandai)Simplified CDD may be used. Data for an individual drops to items a) to d) of Article 25 paragraph (1) letter a number 1: name, identity number, address, place and date of birth. A list of these customers must be made and kept45 paragraphs (1), (4) letter a, (8) and Elucidation
Any one of eight high-risk criteria: profile, high-risk product, high-risk party or country, transactions outside the profile, PEP status, line of business, suspected criminal actEDD, and entry in a separate list35 paragraphs (2)–(3); 40
Politically exposed person (PEP)A senior officer is appointed and approves opening or continuing the relationship; periodic EDD on source of funds and source of wealth; tighter monitoring37 paragraph (1); family and close associates Article 39
The beneficial owner carries higher risk than the customerCDD or EDD follows the higher risk level32 paragraph (5)
Life insurance beneficiaryCDD on the beneficiary; identity verified at the time of claim payment42 paragraph (1)

Two rows slip past system design more often than the rest. First, simplified CDD switches itself off: Article 45 paragraph (7) says it doesn't apply where money laundering, terrorism financing or proliferation financing is suspected, or where the risk scenario rises. Your rules engine needs an automatic path up from simplified to full. Second, Article 20 paragraph (2) letter g puts "distribution networks (delivery channels)" inside the risk-classification analysis, and Article 14 paragraph (1) letter a has the AML officer analyse them once a year. The app channel is a rating variable, not just a way to fill in a form.

Remote verification: the three mechanisms in Article 21

Article 21 paragraph (2) requires verification through a "direct face-to-face meeting", an "electronic face-to-face meeting", "and/or non-face-to-face electronic means". The conditions differ per mechanism. Note that the text splits remote verification in two: with an officer on a call, and with none.

MechanismCondition in the textArticle
Direct face-to-faceA PJK employee meets the prospective customer physically21 paragraph (3)
Electronic face-to-faceA PJK employee meets the prospective customer "in real time and online"; the Elucidation names video call or video conference21 paragraph (4)
Non-face-to-face electronic (an app or website with no video call)Population data (the civil registry held by Dukcapil), plus at least 2 authenticity factors: something you are and something you have21 paragraph (5) letter c
A third factor, something you know (username, password, PIN)May be added, not required21 paragraph (6)

Three readings we hold, with their limits.

  • The ID card alone isn't the second factor. The Elucidation of Article 21 paragraph (5) letter c number 2 frames something you have as the national identity card (KTP) "which must also be accompanied by something else, such as a one-time password (OTP), a digital signature, or another form that can be treated as equivalent". A KTP photo upload with no OTP or digital signature doesn't yet meet that wording.
  • This POJK reserves no step for a physical meeting. Articles 35 to 41 add approvals, analysis and monitoring for high-risk customers and PEPs. They don't restrict the channel. That is our reading of the text, not a sentence quoted from it. Article 84 also leaves room for a specific POJK on prospective-customer verification to provide otherwise; we haven't mapped which sectoral POJK is meant, so check your sector.
  • A new channel needs a risk assessment before launch. Article 18 paragraph (2) requires a risk assessment "before new products, business practices, distribution mechanisms and technology are launched or used". If the channel uses face matching, Law No. 27 of 2022 on personal data protection (17 October 2022) classes biometric data as specific personal data in Article 4 paragraph (2) letter b, and Article 34 requires an impact assessment. Two documents, two legal bases, one launch date. The detail is in our piece on the data protection impact assessment in Indonesia.

The specimen signature Article 26 paragraph (1) asks for may be replaced with an electronic signature that meets the electronic-signature regulations (Article 26 paragraph (3)). We've already published the step-by-step mapping in KYC in Indonesia: the legal basis for each onboarding step and don't repeat it here.

Verification vendors: the ten minimum clauses of Article 22 paragraph (3)

Where the software or hardware belongs to a third party, a written agreement is mandatory (paragraph 1) and must contain at least:

  1. the name, address and identity of the parties;
  2. the rights and obligations of the parties;
  3. the scope of the cooperation;
  4. "ownership of the verification data rests entirely with the PJK";
  5. protection of customer data;
  6. a mechanism for sharing data in a "seamless" manner (the regulation uses the English word), which the Elucidation defines as "without any switch of the application or device being used";
  7. subcontracting only with the PJK's written consent;
  8. reporting of critical incidents caused by force majeure;
  9. termination of the agreement;
  10. dispute resolution.

The Elucidation of letter b adds four things that rarely reach the contract: the vendor's contingency plan (data centre and disaster recovery centre, BCP and DRP), confidentiality and information security, the prospective customer's authorisation for the data the vendor uses, and access for OJK "no later than 3 (three) working days" from the request. Item 6 has a design consequence, and of the ten it's the one we think gets the least attention. A flow that throws the applicant out to a separate app for the face check doesn't fit that definition. That is an architecture decision, and it belongs before the vendor contract is signed. If the identity vendor is contracted at group level under a global master agreement, read that agreement against items 4, 6 and 7 before assuming it covers the Indonesian entity.

A bank that is also a payment provider: OJK and BI don't meet in one legal entity

The common assumption that a bank offering payment services falls under two AML/CFT rules at once isn't supported by the text. Bank Indonesia Regulation (PBI) Number 10 of 2024, enacted 30 December 2024, applies under Article 4 paragraph (1) to payment system service providers "other than banks", "non-bank" money changers (KUPVA) and other parties "other than banks". A bank follows POJK 8/2023. The two regimes meet at group level, for example a bank with a non-bank e-money or payment gateway subsidiary. The implementing rule is PADG Number 15 of 2025, enacted and effective 30 June 2025.

ItemOJK: POJK 8/2023BI: PBI 10/2024 and PADG 15/2025
CDD triggersFive, Article 19Four, PBI Article 17 paragraph (1), same Rp100,000,000 threshold; a funds transfer is not a trigger of its own; BI may require CDD below the threshold (paragraph 2)
Verification with no officerPopulation data and 2 authenticity factors mandatory"Other adequate means", PBI Article 23 paragraph (1) letter b; Elucidation: biometric data or an online real-time photo. No two-factor formula
Video callA mechanism of its ownFalls under "direct meeting", PBI Article 23 paragraph (2) letter b
Reporting use of a remote methodWe found no specific reporting duty in POJK 8/2023Mandatory, in the annual report, with the method and technology (PBI Article 23 paragraph (4) and Elucidation)
Identification exemptionWe found no comparable exemption; what exists is simplified CDD (Article 45)Not required for a limited-value source of funds that makes no funds transfer (PBI Article 24 paragraph (1)); Elucidation: unregistered e-money
CDD by a third partyDoesn't apply to outsourcing and agency relationships (Article 46 paragraph (2))Allowed, including a party representing the provider (PBI Article 49 paragraph (3) letter a); report no later than 10 working days after the cooperation starts
Customer data retention5 years, Article 635 years, PBI Article 48 paragraph (1) letter a
Risk assessment reportUpdate no later than end of June (Article 74 paragraph (1) letter b)No later than the last working day of January (PADG Article 31 paragraph (3) letter a)

The practical consequence: one group onboarding engine can't run on one configuration. A flow that is lawful for the e-money subsidiary doesn't necessarily satisfy Article 21 paragraph (5) letter c at the parent bank, and the two risk-assessment deadlines sit five months apart. We cover BI's side for payment providers in Indonesia payment gateway, BI-FAST and QRIS.

What the examiner asks for, and the deadline

Article 63 paragraph (4) allows "no more than 3 (three) working days" from receipt of OJK's request. What has to come out of the system inside that window:

  • Customer data documents, for at least 5 years from the end of the business relationship, not from onboarding (Article 63 paragraph (1) letter a). That matches Article 21 paragraph (2) of Law No. 8 of 2010 on money laundering (22 October 2010). The scope is identity and supporting documents, transaction information, analysis results and correspondence (paragraph 2). The arithmetic is simple: a customer who stays 12 years means the verification log is kept for at least 17. A group retention schedule that counts from account opening will be short.
  • Three registers: the list of high-risk customers (Article 40), the list of customers given simplified CDD (Article 45 paragraph (8)), and the documentation of rejected applicants and of customers whose relationship was closed (Article 49 paragraph (4)).
  • Periodic reports (Article 74 paragraph (1)): the risk assessment update no later than end of June; the data-updating plan no later than end of December; its realisation no later than end of January. A change to the policy, the procedures or that plan is reported within 7 working days (paragraph 5).
  • A transaction monitoring system that can trace customer identity, the form, date, amount and denomination of the transaction, and the source of funds (Article 52 paragraph (3) letter b).
  • A pre-launch risk assessment for every new channel or technology (Article 18 paragraph (2)).

The price of neglect is written down. A late report: Rp100,000 per working day per report, capped at Rp3,000,000, for commercial banks, securities companies and insurance companies; Rp50,000 and a cap of Rp1,500,000 for financing companies and joint funding operators (Article 78 paragraph (1)). Those are small numbers. The large one is in Article 79 paragraph (1): a fine of up to 1% of the previous year's net profit, capped at Rp100,000,000,000 a year for a PJK and Rp5,000,000,000 a year for an individual.

The limits of WEBARQ's role

WEBARQ doesn't sell identity services. We aren't a biometric verification provider, we hold no access rights to population data, and we don't issue electronic certificates. We build the websites and apps the flow runs on. Our public record on this subject is one item: the CGS International case study, an online registration system that uses a web form with OCR, plus video call and self-verification, connected to banks, CGS-CIMB, KSEI (the central securities depository) and DUKCAPIL (the civil registry). The case study names no regulation, and we don't claim the flow satisfies any particular article. That assessment belongs to the client's compliance unit.

What we haven't read for this piece: the Appendix to POJK 8/2023 (the risk assessment format), the sectoral POJK that Article 84 refers to, and the sanction provisions of PBI 10/2024. We don't cite them.

What this means for the AML unit and internal audit

Four checks you can run this week, each with an article to point at:

  1. Search policies and procedures for "12/POJK.01/2017", including any English summary sent to head office. If it's still there, update it, then report the change within 7 working days (Article 74 paragraph (5)).
  2. Ask the product team to show you the second factor in the no-officer flow. "A photo of the KTP" isn't enough.
  3. Compare the verification vendor contract against the ten clauses of Article 22 paragraph (3), starting with data ownership.
  4. Test the 3-working-day deadline: ask for the onboarding file of one customer who closed their account four years ago, verification result included.

If those checks end in a change to the flow, WEBARQ's mobile app development and website development teams handle the application side. The compliance decisions stay with you.

Back to List