Malaysia (MY)
Lead Signal
Malaysia's Bank Negara Malaysia (BNM) has completed a broad-based tightening of the country's single-regulator payments architecture, moving simultaneously on operational resilience, customer-fund safeguarding and settlement infrastructure. The revised Policy Document on Electronic Money took effect 31 January 2025, replacing the 2022 version and imposing mandatory trust-account or segregated-deposit safeguarding on non-bank e-money issuers, alongside tightened governance, cybersecurity and a three-year exit-strategy requirement; minimum capital now runs from RM100,000 for small schemes to RM5 million or 8% of outstanding e-money liabilities for large schemes. That safeguarding upgrade sits alongside the Risk Management in Technology (RMiT) policy document issued 28 November 2025, which imposes a 120-minute per-incident and four-hour cumulative annual downtime tolerance on critical systems, a one-hour incident-notification window to BNM, and binds banks, insurers, payment system operators and e-money issuers alike; stand-in-processing and capacity obligations become binding by 30 September 2027. At the same time, PayNet's RENTAS+ enhancement, launched October 2025, made Malaysia's real-time gross settlement system the first in ASEAN to offer continuous 24/7 settlement, now clearing DuitNow retail payments on a gross basis. The combined effect is a coordinated compliance-cost escalation for banks and non-banks together, run in parallel with a step-change in settlement-finality infrastructure — though non-bank participants in PayNet's Real-time Retail Payments Platform still have no direct RENTAS access and must settle through settlement banks, leaving a structural tiering between bank and non-bank market participants intact even as the rails around them modernise.
Outlook
Several forward markers will shape Malaysia's payments landscape through 2026 and beyond. The Complaints Handling policy document enters full force 1 April 2026, formalising a consumer-redress escalation pathway through the Financial Markets Ombudsman Service and BNMLINK for all financial service providers including eligible e-money issuers. The Payment Cards Framework's first three-year interchange review falls due in early 2026, with the unverified July 2025 BNM debit-ceiling document a live variable for merchant and acquirer cost structures. RMiT's stand-in-processing and capacity obligations bind by 30 September 2027, extending prescriptive operational-resilience requirements across the sector. Malaysia's 2025 FATF mutual evaluation outcome, expected through 2026, will help determine the intensity of forward AML/CFT supervision on payment institutions. And BNM's Digital Asset Innovation Hub pilot outcomes will be the key signal for whether Malaysia moves toward a finalised payment-stablecoin licensing framework, with reserve expectations already converging on 1:1 fiat backing ahead of any formal rulebook.
Other Developments
Malaysia's card-scheme economics remain governed by the Payment Cards Framework issued 19 August 2022, which caps credit-card interchange at 0.6% and domestic debit interchange at the lesser of 0.1% or RM0.37 plus 0.001%, bans surcharging and minimum-purchase practices, and is subject to review every three years from 1 January 2023 — placing the first review window in early 2026; a BNM document dated 28 July 2025 referencing an "Adjustment to the Debit Card Interchange Fee Ceiling" suggests a revision may already be underway, though its content remains unverified. Enforcement activity has been active and administrative in character rather than litigation-driven: BNM fined Alipay Malaysia (AIMY Merchant Services) RM340,000 in July 2025 for a sanctions-database failure, and imposed more than RM7 million in penalties on Bank Islam, Bank Rakyat and Bank Simpanan Nasional the same month for RMiT and sanctions-screening breaches, following an earlier May 2023 action against TNG Digital. On consumer protection, Malaysia has no statutory mandatory reimbursement scheme for authorised-push-payment fraud victims comparable to the UK model; redress instead runs through a fair-redress expectation on banks, the National Scam Response Centre, and the Financial Markets Ombudsman Service created 1 January 2025 from the merger of the Ombudsman for Financial Services and SIDREC, with a new Complaints Handling policy document entering force 1 April 2026. On digital money, Malaysia still has no finalised payment-stablecoin licensing regime; routing remains activity-dependent between BNM payment-instrument licensing and Securities Commission oversight under the Capital Markets and Services Act, while BNM's Digital Asset Innovation Hub, launched June 2025, is said to be evaluating more than 30 ringgit-stablecoin project submissions. Commercially, the non-bank-dominated e-wallet segment continues to attract capital: Touch 'n Go's TNG Digital, Malaysia's most-funded fintech at roughly USD 168 million cumulative, raised a further USD 75 million from strategic investors targeting first full-year profitability in 2025, while Axiata's Boost is reportedly in talks with a new shareholder for its e-wallet/digital-bank business, a deal still pending BNM regulatory approval. Underlying all of this is a market that processed 18.4 billion e-payment transactions in 2025, up 25% year-on-year, across a base of roughly 47 non-bank e-money issuers against about 6 bank issuers, reshaped further by the five digital-bank licences BNM awarded in 2022 to consortia including Boost-RHB, GXS Bank-Kuok Brothers, Sea-YTL, AEON-MoneyLion and KAF Investment Bank.
Cross-Monitor Connections
Malaysia's anti-money-laundering and counter-financing-of-terrorism regime, supervised by BNM's Financial Intelligence and Enforcement Department under the Anti-Money Laundering Act 2001, was strengthened in December 2024 with counter-proliferation-financing provisions ahead of the country's 2025 FATF mutual evaluation, and requires e-money issuers and payment institutions to screen new and existing customers against domestic and UN sanctions lists. That AML/CFT surface, sourced here from the Sentinel feed, carries payments-context relevance only — the underlying illicit-finance and sanctions-evasion analysis is routed to the Financial Intelligence Monitor rather than assessed independently within this brief.
Domains
14 regulatory modules · click to expand the full sub-briefLicensing, Authorisation & Market Access
ConfirmedMalaysia operates a single-regulator payments regime under Bank Negara Malaysia (BNM), with market access governed by the Financial Services Act 2013 (FSA) and its Islamic-finance counterpart, the Islamic Financial Services Act 2013 (IFSA).
Conduct, Safeguarding & Promotions
ConfirmedThe live conduct-and-safeguarding story in Malaysia is the revised Policy Document on Electronic Money, effective 31 January 2025, which replaced the 2022-vintage PD and materially raised the bar for non-bank e-money issuers.
Correspondent Banking, Settlement & Access
ConfirmedThe analytical spine of this module is Malaysia's bank/non-bank settlement-access asymmetry.
Payment Corridor Dynamics
ConfirmedMalaysia's domestic instant-payments rail, DuitNow, runs on PayNet's Real-time Retail Payments Platform (RPP), live since December 2018 and built on ISO 20022 messaging, with DuitNow QR serving as the unified national QR standard.
Stablecoins & Digital Money
AssessedMalaysia has no finalised payment-stablecoin licensing regime in force as of mid-2026.
Operational Resilience & Critical Infra
ConfirmedBNM's Risk Management in Technology (RMiT) policy document, issued 28 November 2025, is a substantial revision of the 2019/2020 framework (as further updated 1 June 2023) and functions as Malaysia's DORA-analogue.
Full per-domain detail — all 14 modules
W1aConfirmedLicensing, Authorisation & Market Access
see this theme across all jurisdictions →5 claimsMalaysia is a single-regulator, non-EMI-regime jurisdiction. Payment activity is authorised by Bank Negara Malaysia under the Financial Services Act 2013 (FSA) and the parallel Islamic Financial Services Act 2013 (IFSA), which repealed and consolidated the former Payment Systems Act 2003. Three principal authorisation routes exist: approval to operate a payment system (PSO) under s.11 FSA, approval to issue a designated payment instrument (e-money/cards) under s.11, and registration to provide merchant acquiring services under s.17. Both bank and non-bank entities may be authorised; physical local incorporation/presence is generally required.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Licensing, Authorisation & Market Access
Malaysia operates a single-regulator payments regime under Bank Negara Malaysia (BNM), with market access governed by the Financial Services Act 2013 (FSA) and its Islamic-finance counterpart, the Islamic Financial Services Act 2013 (IFSA). There is no separate electronic-money-institution licence of the kind seen in the UK or EU; instead, operators route through three FSA mechanisms: payment-system-operator (PSO) approval under section 11, designated payment-instrument approval under section 11 for e-money and card schemes, and merchant-acquiring registration under section 17. The FSA repealed and consolidated the former Payment Systems Act 2003, with deemed continuity preserved for approvals granted under the earlier regime. Both bank and non-bank entities are authorisable under this framework, and local incorporation or presence is generally required for market entry. This single-regulator, non-EMI-regime architecture is the foundational market-access fact for any payments operator assessing entry into Malaysia: rather than a licence taxonomy split by activity type, BNM applies a unified approval process spanning payment-system operation, e-money issuance and merchant acquiring, with prudential and conduct obligations attached to each approval type rather than to a standalone licence class.
Outlook
No near-term change to the core FSA/IFSA market-access architecture is signalled; the framework is treated as an established baseline. Continuity of prior approvals under the repealed Payment Systems Act 2003 remains structurally significant for any entity that entered the market before the FSA consolidation. Market-access conditions should instead be read alongside the parallel tightening documented in conduct/safeguarding (W1b) and operational resilience (W3), which raise the ongoing compliance burden attached to holding a BNM approval without altering the entry route itself.
Malaysia is a single-regulator, non-EMI-regime jurisdiction. Payment activity is authorised by Bank Negara Malaysia under the Financial Services Act 2013 (FSA) and the parallel Islamic Financial Services Act 2013 (IFSA), which repealed and consolidated the former Payment Systems Act 2003. Three principal authorisation routes exist: approval to operate a payment system (PSO) under s.11 FSA, approval to issue a designated payment instrument (e-money/cards) under s.11, and registration to provide merchant acquiring services under s.17. Both bank and non-bank entities may be authorised; physical local incorporation/presence is generally required.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Safeguarding of customer funds is the central conduct mechanism. Non-bank e-money issuers (EMIs) must place collected funds in segregated trust/dedicated deposit accounts with licensed banking institutions, used only to refund users and pay merchants; large-scheme EMIs use a Trustee Act 1949 trust. The regime was tightened by successive BNM e-money policy documents (2022, then a revised version effective 31 January 2025). Conduct is governed alongside Fair Treatment of Financial Consumers and Complaints Handling policy documents. Minimum capital is RM100,000 (small scheme) and RM5 million or 8% of outstanding e-money liabilities (large scheme).
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Conduct, Safeguarding & Promotions
The live conduct-and-safeguarding story in Malaysia is the revised Policy Document on Electronic Money, effective 31 January 2025, which replaced the 2022-vintage PD and materially raised the bar for non-bank e-money issuers. Large-scheme issuers must now hold customer funds in a Trustee Act 1949 trust account maintained with a licensed institution; small-scheme issuers must use a separated or dedicated deposit account managed on trust-like terms; and Shariah-compliant e-money issuers use a qard structure within a Shariah-compliant trust or dedicated deposit account. The revised PD also tightens governance and cybersecurity expectations and introduces a three-year exit-strategy requirement for issuers. Minimum capital is tiered at RM100,000 for small-scheme issuers and RM5 million, or 8% of outstanding e-money liabilities, for large-scheme issuers. Because Malaysia has no FSCS-style deposit-protection scheme extending to non-bank e-money balances, this trust/segregation mechanism is the primary consumer-fund protection in the wallet-dominated Malaysian market — a market where non-bank issuers outnumber bank issuers by roughly eight to one. Confidence in this reading was upgraded to Confirmed following verification that the revised PD is in force via a Bank Negara Malaysia primary source. On the conduct side, BNM issued a Policy Document on Complaints Handling on 28 March 2025, superseding 2009-vintage guidelines. It applies to financial service providers including eligible e-money issuers and establishes an escalation pathway to the Financial Markets Ombudsman Service or BNMLINK. Most of the document enters force on 1 April 2026, though Paragraph 12 took effect immediately on issuance (28 March 2025).
Outlook
The Complaints Handling PD's full entry into force on 1 April 2026 is the near-term marker to track for conduct compliance across all financial service providers, including e-money issuers. Beyond that date, the safeguarding regime established by the 2025 e-money PD is expected to remain the standing baseline; further tightening would most plausibly come via governance or cybersecurity guidance rather than a change to the core trust-account safeguarding mechanism itself.
Safeguarding of customer funds is the central conduct mechanism. Non-bank e-money issuers (EMIs) must place collected funds in segregated trust/dedicated deposit accounts with licensed banking institutions, used only to refund users and pay merchants; large-scheme EMIs use a Trustee Act 1949 trust. The regime was tightened by successive BNM e-money policy documents (2022, then a revised version effective 31 January 2025). Conduct is governed alongside Fair Treatment of Financial Consumers and Complaints Handling policy documents. Minimum capital is RM100,000 (small scheme) and RM5 million or 8% of outstanding e-money liabilities (large scheme).
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W12ConfirmedCorrespondent Banking, Settlement & Access
see this theme across all jurisdictions →4 claimsLarge-value settlement runs through RENTAS (RTGS), Malaysia's only large-value payment system, operated by PayNet since July 1999, settling high-value ringgit interbank funds and scripless securities with finality across BNM books. RENTAS supports PvP (a ringgit–USD link with Hong Kong's USD CHATS since November 2006) and foreign-currency settlement via Onshore Settlement Institutions. Non-bank RPP participants do NOT have direct RTGS access and settle via settlement banks. In October 2025 BNM launched RENTAS+, the first ASEAN RTGS to offer 24/7 round-the-clock gross settlement of DuitNow retail transactions, backed by an automated round-the-clock liquidity facility.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Correspondent Banking, Settlement & Access
The analytical spine of this module is Malaysia's bank/non-bank settlement-access asymmetry. RENTAS, operated by PayNet since July 1999, is Malaysia's only large-value payment system, settling high-value ringgit interbank funds and scripless securities with finality across BNM's books; it supports payment-versus-payment settlement through a ringgit–USD CHATS link with Hong Kong established November 2006, and foreign-currency settlement via Onshore Settlement Institutions. Non-bank participants in PayNet's Real-time Retail Payments Platform have no direct access to RENTAS and must settle through settlement banks — a structural constraint on non-bank market participants that persists even as the settlement rails around them are modernised. That modernisation arrived in October 2025 with the launch of RENTAS+, the first ASEAN RTGS system to offer round-the-clock (24/7) gross settlement, which now settles DuitNow retail transactions on a gross basis with an automated liquidity facility.
Outlook
The tiered non-bank settlement-access model — under which non-bank PSPs settle via settlement banks rather than directly through RENTAS — is the structural dynamic most worth tracking in this module; whether RENTAS+ or future settlement-infrastructure upgrades extend any form of direct or semi-direct access to non-bank participants would be a material change to Malaysia's settlement-access architecture. Absent that, RENTAS+'s 24/7 gross-settlement capability for DuitNow retail flows remains the leading settlement-finality development in the market.
Large-value settlement runs through RENTAS (RTGS), Malaysia's only large-value payment system, operated by PayNet since July 1999, settling high-value ringgit interbank funds and scripless securities with finality across BNM books. RENTAS supports PvP (a ringgit–USD link with Hong Kong's USD CHATS since November 2006) and foreign-currency settlement via Onshore Settlement Institutions. Non-bank RPP participants do NOT have direct RTGS access and settle via settlement banks. In October 2025 BNM launched RENTAS+, the first ASEAN RTGS to offer 24/7 round-the-clock gross settlement of DuitNow retail transactions, backed by an automated round-the-clock liquidity facility.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Malaysia's principal domestic instant rail is DuitNow, operating on PayNet's Real-time Retail Payments Platform (RPP, live December 2018) on ISO 20022, with DuitNow QR providing a unified interoperable national QR standard. Cross-border corridors are built on QR-linkage and real-time-transfer interoperability under the ASEAN Regional Payment Connectivity (RPC) framework signed November 2022 by Indonesia, Malaysia, Philippines, Singapore and Thailand. Live linkages include DuitNow–PromptPay (Thailand), DuitNow–QRIS (Indonesia), DuitNow–NETS / PayNow (Singapore), plus China, Cambodia and others; the PayNow–DuitNow real-time fund-transfer link (Nov 2023) was notable for non-bank participation.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Payment Corridor Dynamics
Malaysia's domestic instant-payments rail, DuitNow, runs on PayNet's Real-time Retail Payments Platform (RPP), live since December 2018 and built on ISO 20022 messaging, with DuitNow QR serving as the unified national QR standard. Malaysia has become one of the more active participants in ASEAN's Regional Payment Connectivity initiative, signed November 2022, with multiple live cross-border QR and real-time transfer linkages: DuitNow–PromptPay with Thailand, DuitNow–QRIS with Indonesia, and a DuitNow–NETS/PayNow real-time transfer link with Singapore established November 2023 that notably includes non-bank participation (subject to transaction limits). Further linkages extend to China and Cambodia, among others. This multi-corridor cross-border QR network is a genuine differentiator for remittance and travel-payment flows and aligns with the G20's cross-border payments roadmap.
Outlook
The MY–SG DuitNow–PayNow link's inclusion of non-bank participation is worth continued tracking as a template for how non-bank PSPs might gain broader cross-border settlement access elsewhere in the network. Further corridor expansion — additional ASEAN or extra-regional links — is the most likely next development in this module, building on the RPC framework signed in November 2022.
Malaysia's principal domestic instant rail is DuitNow, operating on PayNet's Real-time Retail Payments Platform (RPP, live December 2018) on ISO 20022, with DuitNow QR providing a unified interoperable national QR standard. Cross-border corridors are built on QR-linkage and real-time-transfer interoperability under the ASEAN Regional Payment Connectivity (RPC) framework signed November 2022 by Indonesia, Malaysia, Philippines, Singapore and Thailand. Live linkages include DuitNow–PromptPay (Thailand), DuitNow–QRIS (Indonesia), DuitNow–NETS / PayNow (Singapore), plus China, Cambodia and others; the PayNow–DuitNow real-time fund-transfer link (Nov 2023) was notable for non-bank participation.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Malaysia has NO finalised payment-stablecoin framework in force as of mid-2026. Crypto/digital assets that exhibit investment characteristics are classified as securities and regulated by the Securities Commission Malaysia (SC) under the Capital Markets and Services Act 2007 and the 2019 Prescription Order; BNM retains monetary/financial-stability and AML oversight, and does not recognise crypto as legal tender. Stablecoins are not yet specifically regulated; routing is activity-dependent (payment-use may trigger BNM payment-instrument licensing, trading/custody falls to SC). BNM launched a Digital Asset Innovation Hub (DAIH) in June 2025 and is evaluating ringgit-pegged stablecoin pilots; reserve expectations are converging on 1:1 fiat backing. A CBDC remains exploratory (Project Dunbar).
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Stablecoins & Digital Money
Malaysia has no finalised payment-stablecoin licensing regime in force as of mid-2026. Regulatory routing is activity-dependent: stablecoin use for payment purposes may trigger BNM payment-instrument licensing, while exchange, custody and trading activity falls to the Securities Commission under the Capital Markets and Services Act 2007 and the 2019 Prescription of Securities (Digital Currency and Digital Token) Order. Reserve expectations are converging on 1:1 fiat backing even in the absence of a codified rulebook. BNM's Digital Asset Innovation Hub, launched June 2025, is evaluating a reported 30-plus ringgit-stablecoin project submissions, and BNM is separately exploring central bank digital currency questions through Project Dunbar. This is an absence-of-framework finding rather than a confirmed negative; no Tier-1 or Tier-2 source has yet announced either a finalised regime or a definitive decision not to regulate, so the Assessed confidence tier reflects genuine calibration rather than under-research. For operators considering a ringgit-pegged stablecoin, the practical consequence is market-access uncertainty pending the outcome of BNM's DAIH pilot programme.
Outlook
The DAIH pilot outcomes are the single clearest forward signal for Malaysia's stablecoin trajectory; a move toward a finalised licensing framework, if it comes, is most likely to be shaped by the pilot's findings on reserve backing, redemption and issuer eligibility. Absent a firm framework, activity-dependent routing between BNM and the Securities Commission will remain the default, and issuers should expect the current uncertainty to persist through 2026.
Malaysia has NO finalised payment-stablecoin framework in force as of mid-2026. Crypto/digital assets that exhibit investment characteristics are classified as securities and regulated by the Securities Commission Malaysia (SC) under the Capital Markets and Services Act 2007 and the 2019 Prescription Order; BNM retains monetary/financial-stability and AML oversight, and does not recognise crypto as legal tender. Stablecoins are not yet specifically regulated; routing is activity-dependent (payment-use may trigger BNM payment-instrument licensing, trading/custody falls to SC). BNM launched a Digital Asset Innovation Hub (DAIH) in June 2025 and is evaluating ringgit-pegged stablecoin pilots; reserve expectations are converging on 1:1 fiat backing. A CBDC remains exploratory (Project Dunbar).
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Operational resilience is governed by BNM's Risk Management in Technology (RMiT) policy document, the Malaysian analogue to DORA/FCA op-res. RMiT was first issued 2019/2020, updated 1 June 2023, and substantially revised effective 28 November 2025. It applies to banks, insurers/takaful, DFIs, payment system operators and approved e-money issuers under the FSA/IFSA/DFIA, covering governance, cybersecurity, third-party/cloud risk, identity controls and incident management. The 2025 revision imposes prescriptive operational-resilience obligations (e.g. critical-system maximum tolerable downtime of 120 minutes per incident / 4 hours cumulative annual) and mandatory rapid incident notification to BNM (within 1 hour of detection).
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Operational Resilience & Critical Infrastructure
BNM's Risk Management in Technology (RMiT) policy document, issued 28 November 2025, is a substantial revision of the 2019/2020 framework (as further updated 1 June 2023) and functions as Malaysia's DORA-analogue. It applies to banks, insurers and takaful operators, development financial institutions, payment system operators and approved e-money issuers. The policy sets prescriptive tolerances: critical systems face a maximum tolerable downtime of 120 minutes per incident and four hours cumulative annually; incidents must be notified to BNM within one hour of detection, with a full report due within 14 days and a post-incident review within 30 days. Stand-in-processing and capacity obligations do not bind immediately — firms have until 30 September 2027 to comply. The regime also requires dual reporting to the National Cyber Security Agency under the Cyber Security Act 2024. A November 2024 exposure draft signalled BNM's intent to extend equivalent resilience standards to non-bank merchant acquirers, a scope expansion that would bring RMiT-style obligations to a wider non-bank population than the current in-force text covers.
Outlook
The binding date for stand-in-processing and capacity obligations, 30 September 2027, is the key compliance deadline institutions across the sector — banks, PSOs and e-money issuers alike — need to plan against. Separately, the fate of the November 2024 exposure draft extending RMiT-equivalent resilience duties to non-bank merchant acquirers is worth tracking, as its finalisation would materially widen the population of non-bank entities subject to prescriptive downtime and incident-notification rules.
Operational resilience is governed by BNM's Risk Management in Technology (RMiT) policy document, the Malaysian analogue to DORA/FCA op-res. RMiT was first issued 2019/2020, updated 1 June 2023, and substantially revised effective 28 November 2025. It applies to banks, insurers/takaful, DFIs, payment system operators and approved e-money issuers under the FSA/IFSA/DFIA, covering governance, cybersecurity, third-party/cloud risk, identity controls and incident management. The 2025 revision imposes prescriptive operational-resilience obligations (e.g. critical-system maximum tolerable downtime of 120 minutes per incident / 4 hours cumulative annual) and mandatory rapid incident notification to BNM (within 1 hour of detection).
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Card-scheme economics are regulated domestically by BNM's Payment Cards Framework (PCF) policy document (issued 19 August 2022, interchange ceilings effective 1 January 2023), which superseded the 2014 Payment Card Reform Framework (PCRF). The PCF lowered interchange ceilings (credit capped at 0.6%; domestic debit at the lesser of 0.1% or RM0.37 + 0.001%), subject to review every three years from 1 January 2023. Surcharging and minimum-purchase-amount practices on debit/credit card transactions are prohibited, with a cardholder complaint mechanism. Visa/Mastercard/JCB operate as international schemes; the domestic debit scheme MyDebit is operated by PayNet.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Scheme & Network Compliance
Card-scheme economics in Malaysia are set by BNM's Payment Cards Framework (PCF), issued 19 August 2022 and superseding the 2014 Payment Card Reform Framework. Interchange ceilings took effect 1 January 2023: credit-card interchange is capped at 0.6%, and domestic debit interchange at the lesser of 0.1% or RM0.37 plus 0.001%. The PCF also prohibits surcharging and minimum-purchase practices and requires a cardholder complaint mechanism. International schemes Visa, Mastercard and JCB operate alongside MyDebit, the domestic debit scheme operated by PayNet. The interchange ceilings are subject to review every three years from 1 January 2023, placing the first scheduled review window in early 2026. A BNM document dated 28 July 2025 and titled "Adjustment to the Debit Card Interchange Fee Ceiling" suggests this review may already have produced a change to the debit ceiling, but its content was not accessible during this research cycle and the adjustment remains unverified — the current standing position therefore still cites the original 2023 ceilings pending confirmation.
Outlook
Verification of the 28 July 2025 BNM debit-interchange document is the immediate priority for this module; until confirmed, the three-yearly review cycle should be treated as a live variable for merchant and acquirer cost structures rather than a settled matter. If the ceiling has moved, downstream effects on acquirer and merchant economics would be the first material scheme-compliance change recorded for Malaysia since the 2023 ceilings took effect.
Card-scheme economics are regulated domestically by BNM's Payment Cards Framework (PCF) policy document (issued 19 August 2022, interchange ceilings effective 1 January 2023), which superseded the 2014 Payment Card Reform Framework (PCRF). The PCF lowered interchange ceilings (credit capped at 0.6%; domestic debit at the lesser of 0.1% or RM0.37 + 0.001%), subject to review every three years from 1 January 2023. Surcharging and minimum-purchase-amount practices on debit/credit card transactions are prohibited, with a cardholder complaint mechanism. Visa/Mastercard/JCB operate as international schemes; the domestic debit scheme MyDebit is operated by PayNet.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Malaysia's payments market is a bank/non-bank hybrid centred on PayNet (national payments utility, BNM the single largest shareholder alongside 11 financial institutions). The e-wallet segment is led by TNG Digital (Touch 'n Go), Boost, ShopeePay, GrabPay and BigPay; the regulatee population shows non-bank EMIs far outnumbering bank EMIs (~47–48 non-bank vs ~6 bank). The market is rapidly growing (18.4 billion e-payment transactions in 2025, +25% YoY) and is being reshaped by five digital banks licensed by BNM in 2022 (Boost-RHB, GXBank, SeaMoney-YTL, AEON, KAF). Digital payments hold roughly half the fintech market by service proposition.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Industry Structure & Commercial Dynamics
Malaysia's payments market is a bank/non-bank hybrid centred on PayNet, in which BNM is the single largest shareholder alongside eleven financial institutions. The e-wallet segment is led by TNG Digital, Boost, ShopeePay, GrabPay and BigPay, and non-bank e-money issuers (approximately 47) far outnumber bank e-money issuers (approximately 6). The market processed 18.4 billion e-payment transactions in 2025, up 25% year-on-year, with retail e-payment value of RM831 billion and a 17% compound annual growth rate since 2022. BNM awarded five digital-bank licences in 2022: on the conventional (FSA) side, to Boost-RHB, GXS Bank-Kuok Brothers, and Sea-YTL; on the Islamic (IFSA) side, to AEON-MoneyLion and KAF Investment Bank. (An earlier characterisation of one conventional licensee as a "Grab-Singtel-Kuok consortium" has been corrected: GXS Bank is the Grab-Singtel entity, and its licence was awarded jointly with Kuok Brothers.) Digital payments account for roughly 50.7% of Malaysia's fintech market in 2025. Taken together, this is a non-bank-dominated, rapidly growing market being reshaped by the 2022 digital-bank cohort.
Outlook
The performance of the five 2022 digital-bank licensees, and the extent to which they draw volume away from incumbent e-wallets, is the key structural variable to track in this module. Continued high transaction-volume growth (25% YoY in 2025) suggests the non-bank-dominated structure of the market is unlikely to reverse in the near term, though further consolidation among e-wallets (see W13) could shift the competitive balance among non-bank players.
Malaysia's payments market is a bank/non-bank hybrid centred on PayNet (national payments utility, BNM the single largest shareholder alongside 11 financial institutions). The e-wallet segment is led by TNG Digital (Touch 'n Go), Boost, ShopeePay, GrabPay and BigPay; the regulatee population shows non-bank EMIs far outnumbering bank EMIs (~47–48 non-bank vs ~6 bank). The market is rapidly growing (18.4 billion e-payment transactions in 2025, +25% YoY) and is being reshaped by five digital banks licensed by BNM in 2022 (Boost-RHB, GXBank, SeaMoney-YTL, AEON, KAF). Digital payments hold roughly half the fintech market by service proposition.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Payments-relevant legal action in Malaysia is dominated by BNM administrative enforcement (compound/monetary penalties) rather than landmark civil litigation, focused on AML/CFT/sanctions-screening and operational-resilience (RMiT) breaches. Notable actions include the May 2023 penalty on TNG Digital (sanctions-screening lapse), the July 2025 RM340,000 fine on Alipay Malaysia (AIMY Merchant Services) for failing to update its sanctions database, and July 2025 penalties totalling over RM7 million on Bank Islam, Bank Rakyat and BSN for RMiT/availability and sanctions-screening breaches. The AMLA was amended in December 2024 to strengthen supervision and enforcement.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Legal & Litigation
Malaysia's payments-enforcement landscape is dominated by BNM administrative penalties rather than landmark civil litigation, with recent actions concentrated on sanctions-screening and RMiT-related operational-resilience breaches. TNG Digital was penalised in May 2023 over sanctions-screening failures. In July 2025, BNM fined Alipay Malaysia (operating as AIMY Merchant Services) RM340,000 for a sanctions-database failure, and in the same month imposed penalties totalling more than RM7 million on three banks — Bank Islam (RM3.445 million), Bank Rakyat (RM2.85 million) and Bank Simpanan Nasional (RM995,000) — for RMiT and sanctions-screening breaches. The Anti-Money Laundering Act was amended in December 2024. Enforcement activity spans both bank and non-bank PSPs, indicating BNM's administrative posture is applied consistently across the industry rather than concentrated on one segment.
Outlook
The consistency of BNM's July 2025 enforcement wave — hitting both a non-bank PSP (Alipay/AIMY) and three banks within the same month — suggests sanctions-screening and RMiT compliance will remain the two leading enforcement themes through 2026. Any further administrative penalties are likely to continue this dual focus rather than shift toward new enforcement categories.
Payments-relevant legal action in Malaysia is dominated by BNM administrative enforcement (compound/monetary penalties) rather than landmark civil litigation, focused on AML/CFT/sanctions-screening and operational-resilience (RMiT) breaches. Notable actions include the May 2023 penalty on TNG Digital (sanctions-screening lapse), the July 2025 RM340,000 fine on Alipay Malaysia (AIMY Merchant Services) for failing to update its sanctions database, and July 2025 penalties totalling over RM7 million on Bank Islam, Bank Rakyat and BSN for RMiT/availability and sanctions-screening breaches. The AMLA was amended in December 2024 to strengthen supervision and enforcement.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Merchant acquiring is a registered (not licensed) activity under section 17 FSA 2013, with BNM's Policy Document on Merchant Acquiring Services (issued 15 September 2021) setting governance, operational-risk, IT-management, minimum-capital (non-bank) and merchant-onboarding/recruitment requirements. The PD took effect for bank acquirers from 15 March 2022 and for non-bank acquirers (minimum capital) from 15 September 2023. The registered acquirer base is broad — including TNG Digital, GHL, ShopeePay, Razer Merchant Services, Stripe and FIS Worldpay — and the November 2024 RMiT exposure draft would extend resilience standards to non-bank merchant acquirers.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Merchant Acquiring & Risk
Merchant acquiring in Malaysia is a registered, not licensed, activity under section 17 of the FSA 2013. BNM's Policy Document on Merchant Acquiring Services, issued 15 September 2021, sets governance, operational-risk, IT and merchant-onboarding requirements, alongside minimum-capital requirements for non-bank acquirers; the requirements became effective for bank acquirers from 15 March 2022 and for non-bank capital requirements from 15 September 2023. The registered base is broad, including TNG Digital, GHL, ShopeePay, Razer, Stripe and FIS Worldpay among more than 40 registered acquirers. A November 2024 RMiT exposure draft would extend operational-resilience standards to non-bank merchant acquirers, which are not currently within RMiT's in-force scope.
Outlook
The registration (rather than licensing) model keeps entry friction relatively low for global acquirers such as Stripe and Worldpay, but the pending RMiT exposure draft is the key variable that would raise ongoing resilience-compliance costs specifically for non-bank acquirers if finalised. Its progress should be tracked alongside the main RMiT stand-in-processing deadline of 30 September 2027 (W3).
Merchant acquiring is a registered (not licensed) activity under section 17 FSA 2013, with BNM's Policy Document on Merchant Acquiring Services (issued 15 September 2021) setting governance, operational-risk, IT-management, minimum-capital (non-bank) and merchant-onboarding/recruitment requirements. The PD took effect for bank acquirers from 15 March 2022 and for non-bank acquirers (minimum capital) from 15 September 2023. The registered acquirer base is broad — including TNG Digital, GHL, ShopeePay, Razer Merchant Services, Stripe and FIS Worldpay — and the November 2024 RMiT exposure draft would extend resilience standards to non-bank merchant acquirers.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Product development is steered by BNM's Financial Sector Blueprint 2022–2026 and PayNet's multi-year RPP modernisation, plus the Interoperable Credit Transfer Framework (ICTF) giving banks and eligible non-bank EMIs fair, open access to shared infrastructure. Live build-out includes DuitNow QR, Request-to-Pay, e-mandates/AutoDebit, cross-border QR, and tap-to-phone (Soft Space). Sandboxes operate at both BNM (Digital Asset Innovation Hub, June 2025) and the SC (digital-asset/tokenisation sandbox, 2025). CBDC work remains exploratory (Project Dunbar; tokenised-deposit pilots in BNM's 2022–2026 blueprint).
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Product Innovation & Market Development
BNM's product-development agenda runs through the Financial Sector Blueprint 2022–2026, PayNet's RPP modernisation programme, and the Interoperable Credit Transfer Framework (ICTF), which gives banks and eligible non-bank e-money issuers fair, open access to shared payments infrastructure. Live build-out includes DuitNow QR, Request-to-Pay, e-mandates/AutoDebit, cross-border QR expansion and tap-to-phone acceptance (via Soft Space). Sandbox activity is running at both BNM (the Digital Asset Innovation Hub, launched June 2025) and the Securities Commission (a digital-asset/tokenisation sandbox, 2025), alongside CBDC-exploratory work through Project Dunbar and tokenised-deposit pilots. The ICTF's open-access mandate is a distinct market-access lever for non-bank EMIs, separate from the specific product launches tracked in W13.
Outlook
Continued build-out of Request-to-Pay and e-mandate functionality on the RPP rail is the most concrete near-term product development to track, alongside further cross-border QR expansion beyond the current Thailand, Indonesia and Singapore linkages. The BNM and Securities Commission sandbox programmes are the mechanisms most likely to produce the next generation of regulated product innovation, including any eventual stablecoin or tokenised-deposit pilots.
Product development is steered by BNM's Financial Sector Blueprint 2022–2026 and PayNet's multi-year RPP modernisation, plus the Interoperable Credit Transfer Framework (ICTF) giving banks and eligible non-bank EMIs fair, open access to shared infrastructure. Live build-out includes DuitNow QR, Request-to-Pay, e-mandates/AutoDebit, cross-border QR, and tap-to-phone (Soft Space). Sandboxes operate at both BNM (Digital Asset Innovation Hub, June 2025) and the SC (digital-asset/tokenisation sandbox, 2025). CBDC work remains exploratory (Project Dunbar; tokenised-deposit pilots in BNM's 2022–2026 blueprint).
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Consumer protection rests on BNM's conduct framework (Fair Treatment of Financial Consumers; Complaints Handling PD of March 2025, effective April 2026) with redress via the Financial Markets Ombudsman Service (FMOS) — created 1 January 2025 by merging the Ombudsman for Financial Services (OFS) and SIDREC — and BNMLINK. Malaysia has NO statutory mandatory APP-fraud reimbursement scheme equivalent to the UK PSR model; instead BNM requires banks to ensure fair redress for unauthorised-transaction victims who took protective steps and did not act fraudulently, coordinated via the National Scam Response Centre / PDRM / MCMC anti-scam framework.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Consumer Protection & APP Fraud
Malaysia has no statutory mandatory reimbursement scheme for authorised-push-payment fraud victims equivalent to the UK's PSR-mandated model. Instead, BNM requires banks to ensure fair redress for victims of unauthorised transactions who took reasonable protective steps and did not act fraudulently, with case coordination running through the National Scam Response Centre alongside the police (PDRM) and the communications regulator (MCMC). Redress channels were consolidated on 1 January 2025 with the creation of the Financial Markets Ombudsman Service (FMOS) from the merger of the Ombudsman for Financial Services and SIDREC, alongside the BNMLINK channel. The Complaints Handling policy document, issued 28 March 2025, enters full force 1 April 2026 and formalises the FMOS/BNMLINK escalation pathway for financial service providers. The absence of a mandatory APP-reimbursement liability model materially lowers PSP consumer-fraud liability exposure in Malaysia relative to jurisdictions with statutory reimbursement mandates.
Outlook
The Complaints Handling PD's 1 April 2026 full entry into force is the near-term marker for this module. Beyond that, whether BNM moves toward a more UK-style mandatory reimbursement liability model — rather than the current fair-redress expectation — is the key open question, though no such proposal is currently signalled in the available record.
Consumer protection rests on BNM's conduct framework (Fair Treatment of Financial Consumers; Complaints Handling PD of March 2025, effective April 2026) with redress via the Financial Markets Ombudsman Service (FMOS) — created 1 January 2025 by merging the Ombudsman for Financial Services (OFS) and SIDREC — and BNMLINK. Malaysia has NO statutory mandatory APP-fraud reimbursement scheme equivalent to the UK PSR model; instead BNM requires banks to ensure fair redress for unauthorised-transaction victims who took protective steps and did not act fraudulently, coordinated via the National Scam Response Centre / PDRM / MCMC anti-scam framework.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W11AssessedAML/CFT & Financial Crime (Sentinel.gi-fed)
Sentinelsee this theme across all jurisdictions →4 claims[SENTINEL-FED] Sentinel.gi payments-context position: Malaysia's AML/CFT regime rests on the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA), supervised by BNM's Financial Intelligence & Enforcement Department (FIED). Payments-context posture: stringent sanctions/PEP screening and CDD obligations on EMIs and payment institutions, active administrative enforcement (TNG Digital 2023; Alipay/AIMY 2025), AMLA strengthened December 2024 ahead of the 2025 FATF mutual evaluation, with CPF (counter-proliferation-financing) provisions added. No original FIM analysis performed here.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
AML/CFT & Financial Crime
[Sentinel-sourced] Malaysia's AML/CFT regime rests on the Anti-Money Laundering Act 2001, supervised by BNM's Financial Intelligence and Enforcement Department (FIED). In the payments context, this translates into stringent sanctions and PEP-screening and customer-due-diligence obligations on e-money issuers and payment institutions: reporting institutions, including e-money issuers, must screen both new and existing customers against the Domestic List and UN sanctions lists. The AMLA was strengthened in December 2024 with counter-proliferation-financing provisions, timed ahead of Malaysia's 2025 FATF mutual evaluation. This intelligence is attributed to the Sentinel.gi feed; the payments-context sanctions-screening and CDD posture described here is carried as the relevant EMI/PSP compliance-cost signal, and readers seeking the underlying illicit-finance and sanctions-evasion analysis should refer to the Financial Intelligence Monitor, to which this material has been cross-referenced.
Outlook
Malaysia's 2025 FATF mutual evaluation outcome, expected through 2026, is the principal forward variable shaping AML/CFT supervisory intensity on EMIs and PSPs. Continued sanctions-screening enforcement (see W7) suggests BNM is treating this as an active compliance priority ahead of the evaluation result.
[SENTINEL-FED] Sentinel.gi payments-context position: Malaysia's AML/CFT regime rests on the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA), supervised by BNM's Financial Intelligence & Enforcement Department (FIED). Payments-context posture: stringent sanctions/PEP screening and CDD obligations on EMIs and payment institutions, active administrative enforcement (TNG Digital 2023; Alipay/AIMY 2025), AMLA strengthened December 2024 ahead of the 2025 FATF mutual evaluation, with CPF (counter-proliferation-financing) provisions added. No original FIM analysis performed here.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- True
Event Findings
W13AssessedCommercial Intelligence (M&A, Investment & Product)
see this theme across all jurisdictions →5 claimsTrailing-12-month commercial activity (run date 2026-06-24) centres on capital injections into e-wallet/digital-banking players and merchant-acquiring/cross-border product expansion. TNG Digital secured ~USD 75 million from strategic investors and targeted first full-year profitability in 2025; Axiata's Boost was reportedly in talks with a potential new shareholder (regulatory approval pending). Funding leaders include TNG Digital (~USD 168m cumulative), BigPay (~RM475m) and Boost (~RM308m). RENTAS+ (Oct 2025) and continued cross-border QR linkages are the principal product releases.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Commercial Intelligence (M&A, Investment & Product)
Three discrete commercial events are recorded for Malaysia this cycle. TNG Digital (Touch 'n Go) raised USD 75 million from strategic investors in 2025, targeting first full-year profitability the same year; the round brings TNG Digital's cumulative funding to roughly USD 168 million, making it Malaysia's most-funded fintech as of October 2025. Axiata's Boost Holdings is reportedly in talks with a potential new shareholder; the amount involved is not publicly disclosed, and the investment still requires regulatory approval. Separately, PayNet launched RENTAS+ in October 2025 — an in-house, cloud-based enhancement enabling continuous 24/7 interbank settlement and the first such round-the-clock RTGS capability in ASEAN, now settling DuitNow retail paymentson a gross basis (also recorded as a structural settlement development under W12).
Outlook
The completion status of the Boost/Axiata shareholder talks — currently rumoured and pending regulatory approval — is the clearest near-term event to track in this module. TNG Digital's stated target of first full-year profitability in 2025 is a second marker worth monitoring for confirmation in subsequent reporting.
Trailing-12-month commercial activity (run date 2026-06-24) centres on capital injections into e-wallet/digital-banking players and merchant-acquiring/cross-border product expansion. TNG Digital secured ~USD 75 million from strategic investors and targeted first full-year profitability in 2025; Axiata's Boost was reportedly in talks with a potential new shareholder (regulatory approval pending). Funding leaders include TNG Digital (~USD 168m cumulative), BigPay (~RM475m) and Boost (~RM308m). RENTAS+ (Oct 2025) and continued cross-border QR linkages are the principal product releases.
Evidence — 5 structured claims
Key facts
- Content Tier
- D
- Sentinel Feed
- False