BNM Fined Setel and Standard Chartered Over Sanctions Screening: What Businesses Should Learn

About this guide: This explainer uses an incident reported on 2026-04-15 as a starting point. The legal rules below are general; they do not decide anyone's guilt, liability or individual case.
On 26 August 2026, Bank Negara Malaysia announced concluded administrative penalties tied to targeted-financial-sanctions screening. Setel Ventures was penalised RM637,500, while Standard Chartered Bank Malaysia and Standard Chartered Saadiq were each penalised RM132,000. The failures involved delays in updating sanctions data, incomplete or outdated customer screening and, for Setel, failure to resolve whether potential matches were true matches. All three penalties were paid and remediation was reported. The decisions apply to regulated reporting institutions, not automatically to every Malaysian business, but they show what a regulator expects a real screening control to prove.
Document pack and control checklist
Sanctions-screening control evidence pack
- List-update log: record when the Domestic List or other required list changed, when your screening database received it and who verified completion.
- Coverage record: prove which existing, potential and new customers were screened, what data fields were used and whether the full required population completed.
- Match file: keep the alert, investigation steps, evidence, true-or-false-match decision, approver and any account or transaction action.
- Exception trail: document failed jobs, delayed feeds, backlogs and manual workarounds, with escalation owners and closure times.
- Remediation proof: connect the incident review to updated procedures, system changes, staff testing and independent assurance rather than closing it with an email alone.
What happened
Bank Negara Malaysia published two enforcement notices on 26 August 2026. The first concerned Setel Ventures Sdn Bhd, a regulated non-bank electronic-money issuer. BNM said it imposed an administrative monetary penalty of RM637,500 on 15 April after Setel failed to update its sanctions database without delay, screen customers across its database and determine whether potential matches were true matches. Setel paid the penalty on 6 May.
The second notice concerned Standard Chartered Bank Malaysia Berhad and Standard Chartered Saadiq Berhad. BNM imposed RM132,000 on each entity on 10 June, and both paid on 15 June. An on-site examination found delayed Domestic List updates and screening against an outdated database. BNM expressly said no specified entities were onboarded and no transactions involving such entities were facilitated by the two banks.
New Straits Times independently reported the three penalties and the control failures on 26 August. Scoop followed on 27 August with Petronas Dagangan’s response concerning Setel. The parent company said the matters arose from Setel’s internal reviews in late 2023, did not involve customer transactions or affect customer funds, and had led to remediation embedded in current operations.
These are concluded regulatory outcomes, not allegations of a criminal conviction. The official notices say all penalties were paid. They also record remediation: Setel updated its procedures and systems, while the Standard Chartered entities strengthened oversight and the timeliness of sanctions-screening controls.
The legal insight: what law applies
Targeted financial sanctions controls are designed to stop a reporting institution and the wider financial system being used for terrorism financing. The BNM notices connect the duties to the Financial Services Act 2013, the Islamic Financial Services Act 2013 for the Islamic banking entity, and BNM’s applicable anti-money-laundering and targeted-financial-sanctions policy requirements.
The Domestic List is not just a reference document to check during onboarding. BNM described it as the list of specified entities declared by the Home Affairs Minister under subsidiary legislation made under section 66B(1) of the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001. When it changes, regulated institutions must update the relevant screening data without delay and perform the screening required for their customer population.
For Setel, the enforcement notice identified three connected failures: the database update was not immediate, the customer database was not screened as required, and potential matches were not resolved as true or false matches. That last step matters. A system that produces alerts but leaves them uninvestigated does not complete the control.
For the Standard Chartered entities, the outdated database meant screening was performed against stale data. The notice also described screening duties covering existing, potential or new customers against the Domestic List and the United Nations Security Council Resolutions List as part of customer due diligence. The absence of an onboarded specified entity did not erase the control breach.
BNM said it considered aggravating and mitigating factors, including severity, lack of reasonable care, past compliance record and post-misconduct behaviour such as effective remediation. That explains why a compliance response needs two tracks: contain and fix the technical problem, then preserve evidence showing that management addressed the cause and reduced recurrence risk.
The exact statutory perimeter is important. These notices concern regulated reporting institutions and duties applicable to them. An ordinary retailer, software vendor or unregulated SME should not copy the penalty provisions into its own policy and assume they apply identically. Its obligations may instead come from a different law, licence, banking relationship or contract. Perimeter advice should precede control design.
How does this impact me?
For a compliance or operations team, a successful screen is not enough if nobody can prove which list version was used. Keep timestamps for the regulator or list publication, data ingestion, quality checks, screening job, exception handling and completion. A dashboard showing ‘green’ without that chain may not answer an examiner’s question.
For technology teams, list updates and batch screening are production processes. Monitor failed feeds, partial jobs, record-count mismatches, queue delays and stale caches. Define who can authorise a manual workaround and how the complete population will be rerun after recovery. The Standard Chartered notice shows why using an outdated database can itself be a breach even when no prohibited customer or transaction is found.
For match investigators, write down the basis for a true or false match. Similar names, aliases, dates of birth, identification numbers, nationality and entity details may require careful comparison under the institution’s approved procedure. Do not clear an alert merely to remove a backlog, and do not freeze or reject a person solely because a weak name similarity appears without following the lawful process.
For customers, the notices do not report that the three institutions lost customer money. The Standard Chartered notice says no specified entities were onboarded or involved in transactions, and Petronas Dagangan said the Setel matter involved no customer transactions or impact on customer funds. A compliance penalty therefore should not be turned into an unsupported claim that an account was hacked or deposits were unsafe.
What this incident teaches us
The common failure was timeliness. Screening logic can be sophisticated, but it is only as current as the list data entering it. The phrase ‘without delay’ turns feed monitoring, deployment ownership and exception escalation into legal-control issues rather than background IT maintenance.
The second lesson is end-to-end coverage. Updating a list, screening the right population and resolving potential matches are separate control points. Passing one does not cure failure at another. A sound audit sample should trace a real list change through all three stages and into management reporting.
The third lesson is proportional reporting. BNM published the breaches and penalties, but also the mitigating facts and remediation. Accurate public discussion should keep those together. The enforcement record supports a lesson about control gaps; it does not support accusations of criminal conduct, deliberate sanctions evasion or customer loss.
The verdict
The BNM actions show that sanctions screening is a live operational control, not a yearly policy document. Regulated institutions need evidence that required lists were updated promptly, the correct customer population was screened, potential matches were resolved and failures were escalated. The firms paid the penalties and reported fixes. Other businesses should first confirm whether they fall inside the same regulatory perimeter, then test the controls that actually apply to them.
What can I do if this happens to me?
- Map every sanctions list and customer population your institution is legally required to screen, with a named owner for each data feed and job.
- Record list-publication, ingestion, validation and screening timestamps so ‘without delay’ can be assessed from evidence rather than memory.
- Reconcile expected and completed customer counts after each screening run, and alert on failed, partial or stale-data jobs.
- Require documented investigation and approval for each potential match, following the current lawful process for true matches and false positives.
- Escalate outages and backlogs under a written procedure that identifies interim controls, rerun requirements and senior accountability.
- Test remediation after an incident with sample records and management evidence; do not treat a revised policy as proof that the system now works.
- Confirm the current statutory and regulatory perimeter with qualified Malaysian compliance or legal advisers before applying banking rules to a different business model.
FAQ
Were these criminal fines?
The BNM notices describe administrative monetary penalties imposed under the financial-services legislation. They do not describe criminal convictions. The institutions paid the penalties and BNM recorded remedial action.
Did the breaches cause customer losses?
The Standard Chartered notice says no specified entities were onboarded and no transactions involving them were facilitated. Petronas Dagangan said the Setel matters did not involve customer transactions or affect customer funds. That does not remove the control breaches, but it is an important limit on what should be claimed.
What did Setel’s screening process fail to do?
BNM said Setel did not update its sanctions database without delay, did not conduct the required screening across its customer database and did not determine whether potential matches were true matches. BNM attributed the breaches to gaps in procedures and the screening system.
Why were the Standard Chartered entities penalised if no specified entity was onboarded?
BNM found that delayed list updates led to screening against an outdated database. The control requirement concerns timely and correct screening, not only whether a prohibited customer is ultimately found.
Must every Malaysian SME run the same sanctions-screening system?
Not automatically. These notices address regulated reporting institutions under specific legislation and BNM policy documents. Another business may have different statutory, licence, contractual or bank-imposed duties. Confirm the perimeter before copying a regulated institution’s process.
This article is general legal information, not legal advice, and reading it does not create a lawyer–client relationship.
This is general Malaysian legal and compliance information based on BNM enforcement notices and reporting checked on 31 August 2026. It does not determine whether a business is a reporting institution, prescribe a screening decision, or replace current BNM policy documents, licence conditions and professional advice. List sources, technical requirements and legal duties can change; use the current official materials for a live control.
Spot something outdated or wrong? Tell us — we’ll verify and correct it.
Key sources (6) — how this was verified
- Bank Negara Malaysia, 2026-08-26, “Imposition of Administrative Monetary Penalty on Setel Ventures Sdn. Bhd. for Targeted Financial Sanctions Breaches” — Primary enforcement notice for the RM637,500 penalty, the database-update, population-screening and true-match failures, the statutory basis, payment date and Setel’s remediation.: https://www.bnm.gov.my/-/eapn152026
- Bank Negara Malaysia, 2026-08-26, “Imposition of Administrative Monetary Penalties on Standard Chartered Bank Malaysia Berhad and Standard Chartered Saadiq Berhad for Targeted Financial Sanctions Breaches” — Primary enforcement notice for each RM132,000 penalty, delayed Domestic List updates, outdated screening, the absence of specified-entity onboarding or transactions, statutory basis, payment and remediation.: https://www.bnm.gov.my/-/eapn162026
- New Straits Times, 2026-08-26, “BNM fines Setel, Standard Chartered Bank and Standard Chartered Saadiq for non-compliance” — Independent report confirming all three penalties, the list-update and screening failures, payment dates, absence of specified-entity transactions at the banks and the reported remediation.: https://www.nst.com.my/business/corporate/2026/08/1519477/bnm-fines-setel-standard-chartered-bank-and-standard-chartered
- Scoop, 2026-08-27, “Setel takes remediation measures following BNM findings: Petronas Dagangan” — Independent follow-up reporting Petronas Dagangan’s response, Setel’s remediation, its regulated non-bank e-money status, and the statement that the matter did not involve customer transactions or affect customer funds.: https://www.scoop.my/news/297044/setel-takes-remediation-measures-following-bnm-findings-petronas-dagangan/
- Bank Negara Malaysia, 2013-03-22, “Financial Services Act 2013” — Official full legislative text for the Financial Services Act 2013, including section 48 on compliance with standards and Part XV provisions on BNM’s administrative actions cited in the enforcement notices.: https://bnm.gov.my/?ac=221&ch=en_legislation&full=1&lang=en&pg=en_legislation_act
- Bank Negara Malaysia, 2013-03-22, “Islamic Financial Services Act 2013” — Official full legislative text for the Islamic Financial Services Act 2013, including section 58 on compliance with standards and the administrative-action provisions cited for Standard Chartered Saadiq.: https://bnm.gov.my/?ac=222&ch=en_legislation&full=1&lang=en&pg=en_legislation_act