Compliance programme for a company in Kazakhstan: a practical checklist
A checklist for a compliance programme in Kazakhstan: AML/CFT and KYC, anti-corruption measures, personal data under Law No. 94-V, HR and migration compliance, and what banks and regulators ask for.
A compliance programme for a company in Kazakhstan covers four areas that regulators, banks and partners actually test: anti-money laundering and know-your-customer procedures, anti-corruption measures, personal data protection and HR compliance, including migration rules for foreign staff. A foreign-owned LLP or an AIFC company does not need a large department to cover them, but it does need documented policies, named responsible people and evidence that the policies are applied. This checklist walks through each area, states the legal basis and lists what a company should have on file.
Use it as a diagnostic: tick what exists, mark what is missing, and prioritize by the consequence of a gap.
Block 1. Governance and structure
Before the four substantive areas, three foundations.
- Corporate documents in order. Charter, current register of participants, decisions appointing the director, and a valid power of attorney chain for anyone who signs. Regulators and banks start here.
- Beneficial ownership file. An ownership chart down to individuals holding more than 25 percent or controlling the company, with supporting documents. The AML/CFT Law's register of beneficial owners requires Kazakhstan legal entities to hold and update this information.
- Named owners of each compliance area. One person may hold several roles in a small company, but each area needs a name, a job description and a management decision behind it.
Block 2. AML/CFT and KYC
Legal basis: Law No. 191-IV of 28 August 2009 (AML/CFT Law); Article 214 of the Code of Administrative Offences; for AIFC participants, the AIFC Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Rules.
Checklist:
- Written analysis of whether the company is a subject of financial monitoring under Article 3 of the AML/CFT Law. If yes, registration in the AFM's cabinet for subjects of financial monitoring.
- Internal control rules adopted by the management body, containing the programmes required by Article 11: organization of internal control, risk management, client identification, transaction monitoring, staff training.
- Appointed responsible officer from senior management, with documented qualifications and business reputation.
- Client onboarding questionnaire and file structure that capture the identification data required by Article 5, including beneficial owners.
- Screening procedure against the AFM lists of persons connected with terrorism financing and proliferation financing, with a 24-hour freeze protocol.
- Commercial sanctions screening policy naming the lists applied and the record kept for each check.
- Reporting procedure for threshold and suspicious transactions with the statutory deadlines and a named submitter.
- Record retention rules for client files and transaction records.
- Training log with dates, attendees and materials.
- For AIFC participants: MLRO appointment, AML policies as filed with AFSA, and the annual AML return calendar.
Even where the company is not a subject of financial monitoring, items on questionnaires, ownership and screening pay for themselves at the first bank inquiry.
Block 3. Anti-corruption
Legal basis: Law No. 410-V of 18 November 2015 on combating corruption, in particular Article 16 on measures in the business sector; the Criminal Code and the Code of Administrative Offences for liability.
Article 16 states that business entities take measures to prevent corruption, including organizational mechanisms ensuring accountability and transparency of decision-making, fair competition, prevention of conflicts of interest, business ethics and an anti-corruption culture. A dedicated anti-corruption compliance function is mandatory for the quasi-public sector; for private companies the law describes measures rather than a prescribed structure. Foreign groups typically also carry obligations under their home jurisdiction's anti-bribery laws, which apply to the Kazakhstan subsidiary.
Checklist:
- Anti-corruption policy adopted by the company, in Russian or Kazakh, aligned with the group policy.
- Conflict of interest procedure: declarations by managers, a register and a decision process.
- Gifts and hospitality rules with thresholds and approval.
- Third-party due diligence for agents, distributors and consultants who interact with state bodies on the company's behalf, with contract clauses on compliance.
- Procurement and payment controls: segregation of duties, approval limits, documented rationale for single-source purchases.
- Reporting channel for employees and a non-retaliation rule.
- Training records.
- Internal analysis of corruption risks performed and documented periodically.
Block 4. Personal data
Legal basis: Law No. 94-V of 21 May 2013 on personal data and their protection; Article 79 of the Code of Administrative Offences.
The law requires consent for collection and processing unless a statutory exception applies (Articles 7 to 9), imposes duties on the owner and operator (Articles 22 and 25), regulates cross-border transfer (Article 16) and requires notification of the authorized body before processing starts, with an exemption for small and medium operators (Article 10-1). Fines under Article 79 rise with the size of the business and are highest where a failure of protection leads to loss or unlawful processing of data. A register of personal data security breaches maintained by the authorized body was added to the law in 2026.
Every employer processes personal data of employees; most companies also process data of clients and counterparties. Checklist:
- Approved list of personal data collected, limited to what the company's tasks require.
- Personal data policy approved by the company, as Article 25 requires.
- Consent forms for employees, clients and website users, containing the elements listed in Article 8, in Kazakh or Russian with an English version where needed.
- Cross-border transfer analysis: where data goes (group HR system, cloud, payroll provider), whether the destination state ensures protection, and consent or another lawful ground where it does not.
- Notification to the authorized body before processing, unless the company qualifies for the small and medium operator exemption; documented reasoning either way.
- Security measures under Article 22: access control, logging, protection of databases, an incident response step.
- A person responsible for organizing data processing.
- Data retention and deletion rules tied to the purpose of collection.
- Contracts with processors and third parties that receive data.
Block 5. HR and migration compliance
Legal basis: Labour Code; Law on migration of population; Constitutional Law No. 438-V on the AIFC (Article 8); rules on employer permits to attract foreign labour approved by Order No. 279 of 30 June 2023; Government Decree No. 1041 of 24 November 2023 on persons for whom no permit is required; Articles 518 and 519 of the Code of Administrative Offences.
For a company with foreign staff this block is where inspections most often find something. Checklist:
- Employment contracts for every employee, registered in the unified system of labour contracts, with the foreign employee's position matching the permit or exemption.
- Hiring basis for each foreigner: a labour permit from the local executive body, an exemption under Decree No. 1041 (for example, EAEU citizens or staff hired by AIFC participants under Article 8 of the AIFC Constitutional Law), or a document confirming an exemption.
- For AIFC participants: documents confirming each foreign employee's high qualification, which Article 8 requires the participant to hold and store.
- Visa or temporary residence permit for each foreign employee, matching the purpose of stay.
- Stay notification filed by the company as host party within three working days of each arrival.
- A deadline calendar for permits, visas, TRPs and passports, with reminders well before expiry.
- Offboarding procedure: visa cancellation or exit formalities when a foreigner leaves the company.
- Internal labour rules, safety instructions and mandatory HR records in the form the Labour Code requires.
- A register of powers of attorney issued to staff who file documents with state bodies.
Liability for a missed stay notification or for hiring without a permit is imposed on the company and its officer under Articles 518 and 519, not on the employee, and the fine for a large business under Article 519 reaches several hundred MCI per case.
Block 6. Regulatory and bank readiness
Finally, a set of items that cut across all areas and that banks, auditors and regulators ask for on short notice.
- A single "compliance folder": policies, appointments, ownership chart, training log, latest screening records.
- English translations of key policies for the foreign parent and for foreign banks.
- A named contact for bank inquiries and a standard response pack for held payments.
- An annual review date for each policy against legislative changes.
- For AIFC participants: annual return and AML return calendar, and evidence of the compliance function required at licensing.
| Area | Key law | Responsible person | Typical trigger for a check |
|---|---|---|---|
| AML/CFT and KYC | Law No. 191-IV | Responsible officer / MLRO | Bank inquiry, AFM request, AFSA review |
| Anti-corruption | Law No. 410-V | Compliance lead or director | Group audit, tender, investigation |
| Personal data | Law No. 94-V | Person responsible for data processing | Complaint, incident, authorized body inspection |
| HR and migration | Labour Code, migration rules | HR lead | Labour or migration inspection, visa filing |
Questions and answers
We are a small company. Do we need all of this?
The volume scales with the business, but the four areas do not disappear. A ten-person consulting LLP with foreign staff and foreign clients needs a short AML analysis, a data policy with consent forms, a conflict of interest rule and a migration calendar. Each can be a few pages; the point is that they exist and are applied.
Where do we start?
With a rapid diagnostic: what applies, what exists, what is missing, and the consequence of each gap. Then close the gaps in order of risk. For most foreign-owned companies the first two items are the beneficial ownership file and the migration calendar, because those are checked most often.
Can our group policies be adopted as they are?
They can be the parent documents. Kazakhstan-specific rules are still needed where the law prescribes content: internal control rules under the AML/CFT Law, consent forms and the data policy under Law No. 94-V, HR documents in the form the Labour Code requires.
What language should the documents be in?
Documents intended for state bodies and employees are in Kazakh or Russian. We prepare bilingual versions so that the foreign parent can read and approve them.
How often should the programme be reviewed?
At least annually, and whenever the business changes: a new line of activity, a new country of counterparties, a new category of staff. Sanctions lists and migration rules change more often than that, so screening and the deadline calendar run continuously.
How SHANYRAQ Legal can help
Our compliance services start with a rapid diagnostic and result in a document set tailored to the company: AML/CFT internal control rules and KYC procedures, sanctions screening policy, anti-corruption and corporate policies, personal data documents under Law No. 94-V, staff training and support during inspections. HR documents for foreign employees, permits, visas and the deadline calendar are handled through employer support; contracts and corporate governance through corporate law. Ready-made document lists are in our document checklists.
Current as of 28.09.2026. This material is for general information; requirements and fees are set by the competent authorities and are confirmed on the date of engagement.
Need this applied to your situation?
Send a request — a lawyer will reply within one business day and tell you exactly what you will need.