Nepal's accounting profession is no longer just about ledgers, audits, and tax returns. Under the country's Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) framework, practicing Chartered Accountants and audit firms are formally classified as "reporting entities." That single classification brings a full set of legal obligations — customer due diligence, suspicious transaction reporting, record-keeping, and more — that many small and mid-sized CA practices are still catching up on. The Institute of Chartered Accountants of Nepal (ICAN) recently ran an AML/CFT Compliance Refresher Webinar to close exactly this gap. Here's what every practicing CA and audit firm in Nepal needs to know.
Why Accountants and Auditors Are "Reporting Entities" Under Nepal's AML/CFT Framework
Nepal's Asset (Money) Laundering Prevention Act (ALPA) and its accompanying rules extend AML/CFT obligations beyond banks and financial institutions to a wider list of "designated non-financial businesses and professions" (DNFBPs). Practicing accountants, auditors, and audit firms fall squarely within this category whenever they prepare, execute, or advise on transactions involving the buying/selling of real estate, management of client funds or accounts, formation or management of companies, or buying/selling of business entities on behalf of a client.
This means a CA firm is not just a service provider anymore — in the eyes of the regulator, it is a frontline gatekeeper against money laundering and terrorist financing. The obligations that follow from this status are not optional guidance; they are binding compliance requirements, enforced through Nepal Rastra Bank, the Department of Money Laundering Investigation, and ICAN's own disciplinary mechanisms.
What ICAN's AML/CFT Compliance Refresher Webinar Covered
ICAN's refresher session was aimed squarely at practicing members who handle client engagements that touch on company formation, statutory audit, or advisory work involving fund movement. The session revisited the core pillars of the AML/CFT regime — risk-based customer due diligence, ongoing monitoring, suspicious transaction reporting, and documentation standards — while also flagging areas where ICAN has observed weak compliance during quality-review inspections of member firms.
A recurring theme of the notice was that AML/CFT compliance is not a one-time registration exercise. It is an ongoing operational discipline that has to be embedded into a firm's client-acceptance process, engagement letters, working-paper templates, and staff training calendar. Firms that treat it as a "tick the box once" exercise are the ones most likely to be flagged in future ICAN reviews.
Customer Due Diligence (CDD) Obligations for Practicing CAs
Customer due diligence is the foundation of AML/CFT compliance. Before accepting an engagement, a CA firm is expected to verify the identity of the client, understand the ownership and control structure of the entity (including beneficial ownership beyond the registered shareholders), and assess the purpose and intended nature of the professional relationship.
For higher-risk clients — for example, cash-intensive businesses, politically exposed persons (PEPs), non-resident clients, or entities with opaque ownership structures — firms are expected to apply enhanced due diligence, which typically means collecting additional identification documents, verifying the source of funds, and seeking senior partner sign-off before proceeding. Lower-risk, well-documented domestic clients can generally be handled through simplified, proportionate due diligence.
Suspicious Transaction Reporting — Process and to Whom
If, during the course of an engagement, a CA identifies a transaction or pattern that has no clear economic or lawful purpose, is inconsistent with the client's known profile, or shows signs of structuring to avoid reporting thresholds, the firm is obligated to file a Suspicious Transaction Report (STR). In Nepal, STRs are routed to the Financial Information Unit (FIU Nepal), which sits under Nepal Rastra Bank and acts as the national hub for receiving, analyzing, and disseminating financial intelligence.
Two points are worth emphasizing here. First, the reporting firm and its staff are legally prohibited from informing the client that an STR has been filed — this "tipping-off" prohibition exists to protect the integrity of any subsequent investigation. Second, filing an STR in good faith generally shields the reporting professional from civil or criminal liability for breach of client confidentiality, which is precisely why the law is structured to encourage reporting rather than silence.
Record-Keeping Requirements and Penalties for Non-Compliance
CA firms are required to maintain CDD documentation, transaction records, and correspondence related to an engagement for a prescribed retention period after the relationship ends — commonly five years or more, depending on the specific rule and the nature of the engagement. These records must be readily retrievable if requested by the regulator or investigating authorities, which in practice means firms need a structured, searchable filing system rather than loose paper files.
Non-compliance carries real consequences. Depending on the severity and nature of the breach, penalties can range from monetary fines and mandatory corrective action plans to suspension of the firm's ability to take on certain categories of engagements, and in serious cases, referral for criminal prosecution under ALPA. ICAN can additionally pursue disciplinary action against individual members who fail to meet these obligations, separate from any regulatory penalty.
How This Connects to Nepal's FATF-Related Commitments
Nepal's AML/CFT framework does not exist in isolation — it is shaped substantially by the country's commitments as a member of the Asia/Pacific Group on Money Laundering (APG), a FATF-style regional body. Nepal has previously undergone periods of increased monitoring related to AML/CFT gaps, and strengthening supervision of DNFBPs — including accountants and auditors — has been a consistent theme in Nepal's mutual evaluation and follow-up reporting.
In practical terms, this means the standards ICAN is asking practicing members to meet are not arbitrary local rules; they reflect international benchmarks that Nepal is expected to demonstrate compliance with. Weak implementation at the level of individual CA firms directly affects Nepal's standing in these international assessments, which is part of why ICAN has been proactive about refresher training rather than waiting for a compliance failure to surface.
A Practical AML Checklist for Small CA/Audit Practices
Large firms often have dedicated compliance officers and software to manage AML/CFT obligations, but most Nepali CA practices are small teams juggling audit, tax, and advisory work simultaneously. For these firms, a lightweight but consistently applied checklist is far more valuable than an elaborate policy document that never gets used. The checklist below is a practical starting point that can be adapted to your firm's size and client base.
Start by formally registering your firm as a reporting entity where required, and designate one partner or senior staff member as the point person for AML/CFT matters — even in a two- or three-partner firm, having a named owner for this responsibility prevents it from falling through the cracks. From there, build a simple written CDD policy, screen new clients against publicly available sanctions and PEP information at onboarding, and set a clear internal threshold for when a transaction or client relationship needs a second look from a senior partner.
Finally, treat staff training as a recurring calendar item rather than a one-off session — annual refreshers, ideally timed around ICAN's own webinars and circulars, keep the whole team alert to red flags. Combined with a disciplined record-retention system, this gives even a small practice a defensible, audit-ready AML/CFT compliance posture.
Bringing It Back to Nepal's Broader Fraud Landscape
AML/CFT compliance does not sit in isolation from the wider fraud and financial-crime risks we've covered elsewhere on this blog. The same red flags that show up in QR code payment fraud and SIM-swap fraud cases — unexplained fund movements, mismatched client profiles, urgency and pressure tactics — are often the earliest signals a CA firm encounters during an engagement, long before law enforcement gets involved. Understanding AML/CFT obligations is, in that sense, a natural extension of the fraud-awareness work we've been building through this series, just viewed from the professional gatekeeper's side of the table rather than the consumer's.
If your firm hasn't yet reviewed its AML/CFT posture against ICAN's latest guidance, now is a good time to do so — not because a penalty is imminent, but because a documented, consistently applied process is the single best protection a practicing CA has if a client relationship ever comes under regulatory scrutiny.
Discussion