Iraq -- AML/CFT Compliance Regulatory Overview
Methodology
AI-generated synthesis from web search results.
Limitations
- AI-generated content -- not reviewed by human expert
- Source URLs not independently verified
It's crucial to understand that Iraq has largely banned the use, trading, and advertising of cryptocurrencies. This significantly impacts the concept of "AML/KYC requirements for cryptocurrency/virtual asset service providers (VASPs)" because, legally, such providers are not permitted to operate in Iraq.
Therefore, the AML/KYC framework doesn't exist to regulate legal VASPs, but rather to combat money laundering and terrorist financing that may involve the illegal use of virtual assets.
Here's a breakdown of the situation:
Central Bank of Iraq (CBI) Ban on Cryptocurrencies
- Decree: In February 2022 (and reiterated earlier), the Central Bank of Iraq (CBI) issued directives prohibiting the use, trading, and advertising of cryptocurrencies within Iraq. The CBI considers cryptocurrencies to be highly volatile, prone to fraud, and lacking proper regulatory oversight, posing risks to the financial system and national security.
- Implication: This ban means that there are no legally operating cryptocurrency exchanges or virtual asset service providers in Iraq. Any entity engaging in such activities within Iraq would be doing so illegally.
AML/CFT Legislation in Iraq (General Application)
While there are no specific VASP AML/KYC regulations due to the ban, Iraq does have a general AML/CFT framework that would apply to illegal activities involving virtual assets.
AML/CFT Legislation:
- Law No. 39 of 2015 – Anti-Money Laundering and Combating the Financing of Terrorism Law: This is the primary legislation. It establishes the legal framework for combating money laundering and terrorist financing across all sectors of the Iraqi financial system. It aligns with international standards set by the Financial Action Task Force (FATF).
- CBI Regulations: The Central Bank of Iraq issues various regulations and instructions to implement Law No. 39, applicable to banks and financial institutions under its supervision.
Customer Due Diligence (CDD) Requirements (Applicable to Traditional FIs and for Investigative Purposes): If virtual assets were legal, or if traditional financial institutions encounter transactions that might be linked to illegal virtual asset activities, the following general CDD principles derived from Law No. 39 and FATF standards would apply:
- Identification and Verification: Financial institutions (banks, money transfer services) are required to identify and verify the identity of their customers, whether natural persons or legal entities, using reliable, independent source documents, data, or information.
- Beneficial Ownership: Identification of the beneficial owner(s) and taking reasonable measures to verify their identity.
- Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship.
- Ongoing Due Diligence: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the institution's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
- Enhanced Due Diligence (EDD): For higher-risk customers, politically exposed persons (PEPs), or complex transactions, EDD measures would be required (e.g., source of wealth/funds, senior management approval).
Suspicious Transaction Reporting (STR):
- Obligation: All financial institutions and designated non-financial businesses and professions (DNFBPs) are obligated to report suspicious transactions to the Financial Intelligence Unit (FIU) if they suspect or have reasonable grounds to suspect that funds are the proceeds of a criminal activity or are related to terrorist financing.
- Relevance to Crypto: Even with the ban, if a traditional financial institution (e.g., a bank) observes transactions that appear to be attempts to convert illegal cryptocurrency proceeds into fiat currency, or vice-versa, or if they identify transactions linked to entities known to be involved in illegal crypto activities, they would be obligated to file an STR.
Record-Keeping Obligations:
- Duration: Financial institutions must maintain records of all customer identification data, account files, business correspondence, and records of transactions for a minimum period (typically five to ten years) after the business relationship has ended or after the date of the transaction.
- Purpose: These records must be sufficient to permit reconstruction of individual transactions and to provide evidence for prosecution of criminal activity.
Authority Overseeing Compliance
- Iraqi Anti-Money Laundering and Counter-Terrorist Financing Office (AML/CFT Office): This office functions as Iraq's Financial Intelligence Unit (FIU). It is the central national authority responsible for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies. It is instrumental in investigating money laundering and terrorist financing cases, including those potentially involving virtual assets acquired or used illegally.
- Central Bank of Iraq (CBI): The CBI is the primary regulator and supervisor for banks and other financial institutions in Iraq. It issues directives and guidelines related to AML/CFT for entities under its supervision and enforces compliance. It also issued the direct ban on cryptocurrencies.
Specific Legislation Names and Regulatory Body URLs
Primary AML/CFT Legislation:
- Law No. 39 of 2015 – Anti-Money Laundering and Combating the Financing of Terrorism Law. (Finding an official, reliable English translation URL directly from the Iraqi government might be challenging, as these often exist as internal legal documents or are published by international bodies like the UN or FATF. The existence of the law is well-documented by FATF mutual evaluation reports for Iraq.)
Regulatory Bodies:
- Central Bank of Iraq (CBI):
- URL: https://www.cbi.iq/
- Iraqi Anti-Money Laundering and Counter-Terrorist Financing Office: This office operates under the framework of the Central Bank of Iraq or the Ministry of Finance. It doesn't typically have a standalone public-facing website. Its functions and existence are defined by Law No. 39 of 2015 and overseen by the CBI. Information about its activities would generally be found on the CBI's website or in official Iraqi government reports related to AML/CFT.
- Central Bank of Iraq (CBI):
Conclusion
In summary, due to the outright ban on cryptocurrencies by the Central Bank of Iraq, there are no specific AML/KYC requirements for legal cryptocurrency/virtual asset service providers in Iraq, as such entities are not permitted to operate. However, Iraq possesses a robust general AML/CFT framework (Law No. 39 of 2015) enforced by the CBI and the AML/CFT Office. This framework would be applied to investigate and prosecute any money laundering or terrorist financing activities that illegally utilize virtual assets within Iraqi jurisdiction.
Source Data
Decree: In February 2022 (and reiterated earlier), the Central Bank of Iraq (CBI) issued directives prohibiting the use, trading, and advertising of cryptocurrencies within Iraq. The CBI considers cryptocurrencies to be highly volatile, prone to fraud, and lacking proper regulatory oversight, posing risks to the financial system and national security.
Implication: This ban means that there are no legally operating cryptocurrency exchanges or virtual asset service providers in Iraq. Any entity engaging in such activities within Iraq would be doing so illegally.
Law No. 39 of 2015 – Anti-Money Laundering and Combating the Financing of Terrorism Law: This is the primary legislation. It establishes the legal framework for combating money laundering and terrorist financing across all sectors of the Iraqi financial system. It aligns with international standards set by the Financial Action Task Force (FATF).
CBI Regulations: The Central Bank of Iraq issues various regulations and instructions to implement Law No. 39, applicable to banks and financial institutions under its supervision.
Identification and Verification: Financial institutions (banks, money transfer services) are required to identify and verify the identity of their customers, whether natural persons or legal entities, using reliable, independent source documents, data, or information.
Beneficial Ownership: Identification of the beneficial owner(s) and taking reasonable measures to verify their identity.
Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship.
Ongoing Due Diligence: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the institution's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
Enhanced Due Diligence (EDD): For higher-risk customers, politically exposed persons (PEPs), or complex transactions, EDD measures would be required (e.g., source of wealth/funds, senior management approval).
Obligation: All financial institutions and designated non-financial businesses and professions (DNFBPs) are obligated to report suspicious transactions to the Financial Intelligence Unit (FIU) if they suspect or have reasonable grounds to suspect that funds are the proceeds of a criminal activity or are related to terrorist financing.
Relevance to Crypto: Even with the ban, if a traditional financial institution (e.g., a bank) observes transactions that appear to be attempts to convert illegal cryptocurrency proceeds into fiat currency, or vice-versa, or if they identify transactions linked to entities known to be involved in illegal crypto activities, they would be obligated to file an STR.
Duration: Financial institutions must maintain records of all customer identification data, account files, business correspondence, and records of transactions for a minimum period (typically five to ten years) after the business relationship has ended or after the date of the transaction.
Purpose: These records must be sufficient to permit reconstruction of individual transactions and to provide evidence for prosecution of criminal activity.
Iraqi Anti-Money Laundering and Counter-Terrorist Financing Office (AML/CFT Office): This office functions as Iraq's Financial Intelligence Unit (FIU). It is the central national authority responsible for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies. It is instrumental in investigating money laundering and terrorist financing cases, including those potentially involving virtual assets acquired or used illegally.
Central Bank of Iraq (CBI): The CBI is the primary regulator and supervisor for banks and other financial institutions in Iraq. It issues directives and guidelines related to AML/CFT for entities under its supervision and enforces compliance. It also issued the direct ban on cryptocurrencies.
References
This article was generated by SearXNG+LLM .
Primary Sources
isc.gov.iq. (n.d.). isc.gov.iq. Retrieved August 18, 2026, from https://isc.gov.iq
gov.uk — Iraq Child Abduction. (n.d.). gov.uk — Iraq Child Abduction. Retrieved August 18, 2026, from https://www.gov.uk/government/publications/iraq-child-abduction/iraq-child-abduction
isc.gov.iq. (n.d.). isc.gov.iq. Retrieved August 18, 2026, from https://isc.gov.iq/en/pages/263
Secondary Sources
cbi.iq. (n.d.). cbi.iq. Retrieved April 22, 2026, from https://www.cbi.iq/
Edit History
This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →