AML/CFT in Indonesia goes by the acronym APU PPT (anti pencucian uang dan pencegahan pendanaan terorisme), and its official name is now APU, PPT and PPPSPM because it also covers the financing of weapons-of-mass-destruction proliferation. For the financial services sector the rule in force is OJK Regulation (POJK) Number 8 of 2023, enacted and promulgated on 14 June 2023, which revoked POJK 12/POJK.01/2017 and POJK 23/POJK.01/2019 (Article 89). For digital onboarding the core is Article 21 paragraph (2): three verification mechanisms are recognised, and the one with no officer involved requires population data plus at least 2 authenticity factors.
This piece is for heads of AML, internal audit (SKAI) and compliance officers at banks, insurers, securities firms and multifinance companies in Indonesia, and for the regional compliance teams that supervise them from Singapore, Hong Kong or Tokyo. The definition ends with the paragraph above. The rest treats APU PPT as a system requirement: what has to be built, logged, and produced within 3 working days. Quotations are our translation; the Indonesian text governs, and "Article" stands for Pasal throughout.
POJK 8/2023 took effect on promulgation (Article 90) and allowed a 6-month adjustment period (Article 85), which ran out in December 2023. It binds the 18 categories of financial service provider (penyedia jasa keuangan, PJK) listed in Article 2 paragraph (1), among them banks, securities companies, insurance companies, financing companies and technology-based joint funding (P2P lending) operators. The text is in OJK's PDF, in Indonesian; we worked from that text, not from a translation.
One thing we checked on 7 October 2026. OJK's own APU-PPT page sits at organic position 3 for the Indonesian query "apu ppt adalah" and is the first source Google's AI Overview cites for it. That page still lists 39/POJK.05/2015, 22/POJK.04/2014, PBI 14/27/PBI/2012 and PBI 12/20/PBI/2010. A string search of its HTML doesn't find "Tahun 2023" once. The national APU-PPT regime page, the second source in the same AI Overview, still names POJK 12/POJK.01/2017, which Article 89 revoked.
We don't think this is a housekeeping problem on a regulator's website. A head-office summary or an internal policy drafted from those pages, or from an AI answer that cites them, points at rules that are no longer in force. Check your own policy before the examiner does.
Article 19 sets five triggers for customer due diligence (CDD), and Article 35 paragraph (3) makes enhanced due diligence (EDD) mandatory once any one of eight high-risk criteria is met. Every reference in the table is to POJK 8/2023.
| Customer or transaction situation | What must be done | Article |
|---|---|---|
| A prospective customer opens a business relationship | CDD: identification, verification, risk classification | 19 letter a; 20 paragraph (1) |
| A transaction of at least Rp100,000,000, including several transactions reasonably suspected to be linked | CDD | 19 letter b and its Elucidation |
| A funds transfer | CDD | 19 letter c |
| Indication of a suspicious financial transaction | CDD, "without regard to any exemption or transaction value limit" | 19 letter d and its Elucidation |
| The information supplied is in doubt | CDD | 19 letter e |
| Low risk. The Elucidation's examples: payroll accounts, companies majority-owned by the government, government agencies, branchless banking for financial inclusion (the scheme known as Laku Pandai) | Simplified CDD may be used. Data for an individual drops to items a) to d) of Article 25 paragraph (1) letter a number 1: name, identity number, address, place and date of birth. A list of these customers must be made and kept | 45 paragraphs (1), (4) letter a, (8) and Elucidation |
| Any one of eight high-risk criteria: profile, high-risk product, high-risk party or country, transactions outside the profile, PEP status, line of business, suspected criminal act | EDD, and entry in a separate list | 35 paragraphs (2)–(3); 40 |
| Politically exposed person (PEP) | A senior officer is appointed and approves opening or continuing the relationship; periodic EDD on source of funds and source of wealth; tighter monitoring | 37 paragraph (1); family and close associates Article 39 |
| The beneficial owner carries higher risk than the customer | CDD or EDD follows the higher risk level | 32 paragraph (5) |
| Life insurance beneficiary | CDD on the beneficiary; identity verified at the time of claim payment | 42 paragraph (1) |
Two rows slip past system design more often than the rest. First, simplified CDD switches itself off: Article 45 paragraph (7) says it doesn't apply where money laundering, terrorism financing or proliferation financing is suspected, or where the risk scenario rises. Your rules engine needs an automatic path up from simplified to full. Second, Article 20 paragraph (2) letter g puts "distribution networks (delivery channels)" inside the risk-classification analysis, and Article 14 paragraph (1) letter a has the AML officer analyse them once a year. The app channel is a rating variable, not just a way to fill in a form.
Article 21 paragraph (2) requires verification through a "direct face-to-face meeting", an "electronic face-to-face meeting", "and/or non-face-to-face electronic means". The conditions differ per mechanism. Note that the text splits remote verification in two: with an officer on a call, and with none.
| Mechanism | Condition in the text | Article |
|---|---|---|
| Direct face-to-face | A PJK employee meets the prospective customer physically | 21 paragraph (3) |
| Electronic face-to-face | A PJK employee meets the prospective customer "in real time and online"; the Elucidation names video call or video conference | 21 paragraph (4) |
| Non-face-to-face electronic (an app or website with no video call) | Population data (the civil registry held by Dukcapil), plus at least 2 authenticity factors: something you are and something you have | 21 paragraph (5) letter c |
| A third factor, something you know (username, password, PIN) | May be added, not required | 21 paragraph (6) |
Three readings we hold, with their limits.
The specimen signature Article 26 paragraph (1) asks for may be replaced with an electronic signature that meets the electronic-signature regulations (Article 26 paragraph (3)). We've already published the step-by-step mapping in KYC in Indonesia: the legal basis for each onboarding step and don't repeat it here.
Where the software or hardware belongs to a third party, a written agreement is mandatory (paragraph 1) and must contain at least:
The Elucidation of letter b adds four things that rarely reach the contract: the vendor's contingency plan (data centre and disaster recovery centre, BCP and DRP), confidentiality and information security, the prospective customer's authorisation for the data the vendor uses, and access for OJK "no later than 3 (three) working days" from the request. Item 6 has a design consequence, and of the ten it's the one we think gets the least attention. A flow that throws the applicant out to a separate app for the face check doesn't fit that definition. That is an architecture decision, and it belongs before the vendor contract is signed. If the identity vendor is contracted at group level under a global master agreement, read that agreement against items 4, 6 and 7 before assuming it covers the Indonesian entity.
The common assumption that a bank offering payment services falls under two AML/CFT rules at once isn't supported by the text. Bank Indonesia Regulation (PBI) Number 10 of 2024, enacted 30 December 2024, applies under Article 4 paragraph (1) to payment system service providers "other than banks", "non-bank" money changers (KUPVA) and other parties "other than banks". A bank follows POJK 8/2023. The two regimes meet at group level, for example a bank with a non-bank e-money or payment gateway subsidiary. The implementing rule is PADG Number 15 of 2025, enacted and effective 30 June 2025.
| Item | OJK: POJK 8/2023 | BI: PBI 10/2024 and PADG 15/2025 |
|---|---|---|
| CDD triggers | Five, Article 19 | Four, PBI Article 17 paragraph (1), same Rp100,000,000 threshold; a funds transfer is not a trigger of its own; BI may require CDD below the threshold (paragraph 2) |
| Verification with no officer | Population data and 2 authenticity factors mandatory | "Other adequate means", PBI Article 23 paragraph (1) letter b; Elucidation: biometric data or an online real-time photo. No two-factor formula |
| Video call | A mechanism of its own | Falls under "direct meeting", PBI Article 23 paragraph (2) letter b |
| Reporting use of a remote method | We found no specific reporting duty in POJK 8/2023 | Mandatory, in the annual report, with the method and technology (PBI Article 23 paragraph (4) and Elucidation) |
| Identification exemption | We found no comparable exemption; what exists is simplified CDD (Article 45) | Not required for a limited-value source of funds that makes no funds transfer (PBI Article 24 paragraph (1)); Elucidation: unregistered e-money |
| CDD by a third party | Doesn't apply to outsourcing and agency relationships (Article 46 paragraph (2)) | Allowed, including a party representing the provider (PBI Article 49 paragraph (3) letter a); report no later than 10 working days after the cooperation starts |
| Customer data retention | 5 years, Article 63 | 5 years, PBI Article 48 paragraph (1) letter a |
| Risk assessment report | Update no later than end of June (Article 74 paragraph (1) letter b) | No later than the last working day of January (PADG Article 31 paragraph (3) letter a) |
The practical consequence: one group onboarding engine can't run on one configuration. A flow that is lawful for the e-money subsidiary doesn't necessarily satisfy Article 21 paragraph (5) letter c at the parent bank, and the two risk-assessment deadlines sit five months apart. We cover BI's side for payment providers in Indonesia payment gateway, BI-FAST and QRIS.
Article 63 paragraph (4) allows "no more than 3 (three) working days" from receipt of OJK's request. What has to come out of the system inside that window:
The price of neglect is written down. A late report: Rp100,000 per working day per report, capped at Rp3,000,000, for commercial banks, securities companies and insurance companies; Rp50,000 and a cap of Rp1,500,000 for financing companies and joint funding operators (Article 78 paragraph (1)). Those are small numbers. The large one is in Article 79 paragraph (1): a fine of up to 1% of the previous year's net profit, capped at Rp100,000,000,000 a year for a PJK and Rp5,000,000,000 a year for an individual.
WEBARQ doesn't sell identity services. We aren't a biometric verification provider, we hold no access rights to population data, and we don't issue electronic certificates. We build the websites and apps the flow runs on. Our public record on this subject is one item: the CGS International case study, an online registration system that uses a web form with OCR, plus video call and self-verification, connected to banks, CGS-CIMB, KSEI (the central securities depository) and DUKCAPIL (the civil registry). The case study names no regulation, and we don't claim the flow satisfies any particular article. That assessment belongs to the client's compliance unit.
What we haven't read for this piece: the Appendix to POJK 8/2023 (the risk assessment format), the sectoral POJK that Article 84 refers to, and the sanction provisions of PBI 10/2024. We don't cite them.
Four checks you can run this week, each with an article to point at:
If those checks end in a change to the flow, WEBARQ's mobile app development and website development teams handle the application side. The compliance decisions stay with you.