AML Compliance in Jordan (2026): A Guide for Payment Institutions

AML compliance in Jordan isn't a one-time identity check — it's a connected system of evidence, risk decisions, and reviewer actions under CBJ supervision. Here's how payment institutions build it.

Share
AML Compliance in Jordan (2026): A Guide for Payment Institutions
AML Compliance in Jordan (2026): A Guide for Payment Institutions

What Jordanian payment institutions need to turn AML/CFT obligations into a controlled onboarding and review workflow.

VOVE ID helps payment institutions verify customers and structure AML evidence in markets where reviewers need to connect fast onboarding with accountable decisions. In Jordan, that work sits inside the Central Bank of Jordan's payment-sector supervision and the AML/CFT instructions that apply to electronic payment and money-transfer companies.

This guide is current as of 5 August 2026 and is informational, not legal advice. The legally authoritative text may be Arabic; the Central Bank's English translation of the relevant payment-sector instructions states that it is supplied for knowledge purposes.

That's the difference between payment onboarding as a document-collection step and payment onboarding as a compliance operating system.

Regulatory context: the national law, CBJ supervision, and payment rules

Jordan's overarching framework is the Anti-Money Laundering and Counter Terrorist Financing Law No. (20) of 2021, enacted to repeal and replace the earlier Law No. 46 of 2007. It establishes the National AML/CFT Committee and the Anti-Money Laundering and Counter Terrorist Financing Unit (AMLU), Jordan's financial intelligence unit, and sets out the reporting and enforcement framework that CBJ instructions operate under.

The Central Bank of Jordan's payment-systems legislation library publishes the payment-sector materials that teams should keep in their source register. It includes the Instructions of Anti Money Laundering and Counter Terrorist Financing for Electronic Payments and Money Transfer Companies No. (12/2018).

The CBJ's AML and terrorism-financing supervision department states that its remit covers regulated financial institutions, including payment and electronic-money-transfer companies, and monitors compliance with CBJ instructions and requirements.

This means one thing: a payment institution needs a traceable control system, not a generic global policy. It should keep the applicable statutes, instructions, circulars, license conditions, and internal procedures together, with a named owner who checks for changes.

For a full breakdown of the underlying framework, see our AML requirements explained: the compliance operating system for regulated institutions.

Customer due diligence: make each payment relationship identifiable

The published CBJ payment-sector AML/CFT instructions define payment service providers and payment-system operators within their scope. The CBJ's customer-due-diligence guidance explains that the instructions cover CDD for permanent and occasional customers, natural and legal persons, legal arrangements, and non-profit organizations; it also refers to identity verification using official documents, data, or information from neutral and reliable sources.

For a payment institution, the operational question is not simply whether an image was submitted. The reviewer needs a record of the customer identity evidence, the checks performed, the result, the risk classification, and the reason for any exception or escalation.

VOVE ID supports identity verification, biometric liveness, face matching, AML screening, KYB, and transaction monitoring across a broad range of document types and countries, and can flag document-template inconsistencies, invalid MRZ checksums, barcode or QR inconsistencies, and image manipulation. Teams should apply these signals under their own approved customer-due-diligence and escalation rules.

For the underlying identity-verification framework, see our KYC requirements explained: identity verification framework for fintech and regulated platforms.

Risk-based controls: connect risk ratings to actions

The Central Bank's published guidance refers to simplified and enhanced due diligence according to risk situations and levels, as well as ongoing due diligence through the business relationship. A risk rating therefore needs an operational consequence.

Define which combinations of product, customer, geography, channel, ownership structure, or behavioral signals trigger additional evidence, senior review, or monitoring. Then test whether the case-management flow actually enforces those choices.

The FATF Recommendations, as amended in June 2026, are useful for the international control model. They do not replace Jordanian requirements; use the CBJ's current materials and qualified local advice for binding interpretation.

Screening, suspicious concerns, and reviewer evidence

Screening is a way to surface potential matches, not an automated clearance decision. A name similarity, PEP indicator, sanctions-related alert, or unusual behavior requires a defined review path and a documented disposition.

VOVE ID offers customer-configurable AML screening. The compliance team must set the relevant scope, assess potential matches, decide whether enhanced review is required, and follow the applicable process for escalation or reporting.

The same principle applies to transaction monitoring. An alert should retain the underlying event, customer context, reviewer rationale, action taken, and any handoff to the institution's responsible AML function. This is where teams lose control over risk when queues and case evidence sit in different systems.

A realistic payment-institution failure: a verified customer without a defensible decision

A Jordanian electronic-payment company onboards a merchant that expects to receive frequent cross-border customer payments.

The file contains:

  • A business registration document
  • Director and ownership information
  • Identity documents for the authorized signatory
  • A stated purpose for the account

Then the inconsistency appears. The stated business activity does not explain the expected payment pattern, and the ownership information changes after the first review. The team collects a new document, but the prior risk decision and the reason for the follow-up sit in separate spreadsheets.

The next reviewer cannot see the full rationale. This is not a document failure. It is a case-control failure.

How VOVE ID supports the workflow: evidence before a decision

VOVE ID can provide identity, liveness, face-matching, KYB, and AML-screening inputs inside the institution's workflow. It gives reviewers structured evidence to assess against a risk policy rather than asking them to reconstruct the onboarding record across tools.

Manual review may be used where the customer's compliance team has sufficient evidence to approve a verification. That keeps the decision with the accountable team while allowing the workflow to preserve the supporting signals and reviewer outcome.

Practical AML checklist for Jordan payment institutions

Source and governance

  • Maintain a register of the AML/CFT Law, applicable CBJ instructions, circulars, and license conditions.
  • Check the authoritative Arabic text and obtain qualified advice for binding interpretation.
  • Assign owners for policy updates, control testing, and regulatory-change review.

Onboarding and risk

  • Identify the customer type, purpose, ownership, and expected payment activity.
  • Verify identity evidence using the institution's approved controls and reliable sources.
  • Link each risk rating to a defined due-diligence, approval, and review action.

Screening and records

  • Review potential screening matches with documented rationale.
  • Preserve alert context, reviewer actions, and escalation records in one case file.
  • Test that records remain retrievable for the applicable retention period.

Q&A

Which authority supervises AML/CFT compliance for Jordanian payment institutions?

The Central Bank of Jordan describes its AML and terrorism-financing supervision department as covering payment and electronic-money-transfer companies under CBJ supervision, operating within the framework of the national AML/CFT Law. The exact obligations depend on the institution's license, services, and applicable rules.

Do the 2018 payment-sector AML/CFT instructions still matter in 2026?

They remain published in the CBJ's payment-systems legislation library. Teams should check the current library, circulars, and authoritative legal texts for amendments or superseding requirements.

Is customer identification enough for a payment-institution AML program?

No. Teams also need risk assessment, appropriate due diligence, screening and review processes, ongoing controls, escalation, and records that support the decisions made.

Can an automated AML tool make the final decision?

Tools can provide signals and workflow support. The regulated institution's accountable compliance function must apply its policy, assess exceptions, and make the required decisions.

FAQ

Where should a Jordan payment institution check for current source material?

Start with the national AML/CFT Law, the Central Bank of Jordan's payment-systems legislation library, and relevant CBJ supervisory materials. Check for current circulars and obtain qualified advice before relying on an English translation for binding interpretation.

What should trigger a control review?

Review the workflow when the institution changes a product, channel, customer segment, or risk exposure, and when a new CBJ instruction, circular, or material case finding changes the control rationale.

Conclusion

AML compliance for a Jordan payment institution is not a one-time identity check. It is a connected system of evidence, risk decisions, reviewer actions, and ongoing control.

Teams should start with the national law and the CBJ's current sources, translate obligations into named workflow steps, and test whether a completed case tells the whole story. Collection, verification, screening, and case management are one workflow.

Ready to put identity and AML evidence inside a payment-compliance workflow? VOVE ID can help.

Book a demo

This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.