Skip to article
HSJGlobal
Secure KYC workspace

PT PMA Bank Application Data Room: Folder Structure, Owners, and Access

A controlled folder, ownership, access, index, and submission model for corporate records, foreign shareholders, beneficial owners, authority, business evidence, and funding.

A PT PMA bank application data room should separate company records, ownership and beneficial owners, directors and authority, business and licenses, funding and transactions, bank forms, and activation evidence. Every folder needs an owner, read and upload permissions, document index, status, effective date, confidentiality class, and bank-submission history. A shared drive full of passports, deeds, and files named ‘final’ is not a controlled data room because the company cannot prove which version is current, who may access it, or what the bank received.

The room should be built around least-privilege access and evidence purpose. Corporate records may be broadly accessible to the core project team, while passports, addresses, ownership, source-of-wealth, and source-of-funds material should be restricted and delivered only through approved bank channels. OJK Regulation No. 8 of 2023 makes customer and beneficial-owner due diligence relevant, but it does not justify uncontrolled collection or copying. The PT PMA should preserve an immutable submission manifest and query log while allowing source owners to refresh evidence through an approved workflow.

In this article

Seven-folder PT PMA bank data room

The folder numbers create a stable navigation model; permissions and evidence indices determine who can use the material and for what purpose.

Folder Core contents Primary owner
01 Company Deed history, Ministry, NIB, NPWP, address Corporate records
02 Ownership Shareholders, chain, UBO, foreign evidence KYC ownership
03 People and authority Directors, IDs, resolutions, powers, signers Corporate and treasury
04 Business and licenses KBLI, activities, locations, licenses, contracts Operating and licensing
05 Funding and transactions Capital, loans, source of funds, expected flows Finance and shareholders
06 Bank submission Forms, manifest, queries, responses, receipts Application coordinator
07 Activation and refresh Accounts, users, tokens, limits, tests, KYC calendar Treasury controls

Design the PT PMA data room

Assign folders, evidence owners, status rules, confidentiality, access roles, and completion definitions before uploading sensitive files.

Key takeaways

  • Structure the data room by evidence purpose and owner, not by whoever supplied the file.
  • Keep personal and source-of-funds material in restricted folders with an approved recipient log.
  • Every document needs a status, effective date, proof purpose, and replacement history.
  • Build bank-specific outgoing packages from approved read-only files and freeze a manifest.
  • Retain activation, access, query, and refresh evidence after account opening instead of archiving only the application.

Assign folder owners and evidence purposes

Each data-room folder should have one accountable owner who verifies the source, status, effective date, and proof purpose of its files. The owner does not need to perform every upload, but no document should be treated as approved because an adviser, shareholder, or employee placed it in a folder. The application coordinator owns package assembly and bank communication, not the truth of every source field.

Published requirements from BNI , Bank Mandiri , and BCA show the range of corporate, management, authority, and identification records commonly requested. The room should make it easy to assemble bank-specific subsets without creating different company facts for each bank.

Record standard

Open the room only after every folder has an owner, approver, upload route, and definition of complete evidence.

  • Name accountable and backup owners for each folder.
  • Define which fact or bank question every document supports.
  • Separate source evidence, working papers, approved files, and outgoing copies.
  • Record unresolved, rejected, expired, superseded, and missing items explicitly.

Use the PT PMA bank requirements guide to define evidence purposes.

Design least-privilege access for KYC material

Access should be granted by role and folder, with stronger restrictions for passports, residential addresses, tax identifiers, signatures, ownership, source of wealth, source of funds, and bank credentials. A notary may need corporate documents, a licensing adviser may need NIB and KBLI data, and a bank may need a controlled KYC package; none automatically needs permanent access to the full room.

The access register should record user, organization, role, folder, permission, purpose, approver, start, expiry, download setting, and revocation. Links should not be forwarded, shared accounts should be prohibited, and former staff or providers should be removed promptly. The company should apply suitable retention and deletion rules while preserving legal and audit evidence.

Decision rule

Grant access only when the purpose and expiry are known, and review privileged folders after every team or transaction change.

  • Separate view, upload, edit, approve, download, and administrator rights.
  • Use named accounts, multi-factor authentication, and access logs.
  • Time-limit adviser, translator, provider, and transaction access.
  • Revoke access and recover local copies when roles or engagements end.

Read the bank KYC mistakes guide before expanding access to solve a query.

Create a document index with evidence lineage

The master index should list the controlled identifier, folder, file name, document title, issuer, person or entity, reference number, issue date, expiry or recency date, effective status, language, certification, authentication, translation, evidence purpose, source owner, confidentiality, and replacement link. The index should allow a reviewer to trace a bank answer back to its source without searching messages.

Evidence lineage is especially important for ownership percentages and beneficial owners. Ministry of Law Regulation No. 2 of 2025 addresses corporate beneficial-owner verification, while banks conduct their own due diligence. The room should store the ownership calculation and supporting records separately and show which natural-person conclusion each source supports.

Evidence rule

A document is bank-ready only when the index states what it proves and the owner has approved its current status.

  • Use stable controlled identifiers instead of relying on editable file names.
  • Link translations and certifications to the exact source document.
  • Link current documents to the superseded version and reason for replacement.
  • Record the ownership calculation version and every source link.

Use the foreign corporate shareholder guide when the chain spans several jurisdictions.

Build a controlled bank submission

Select approved evidence, freeze the manifest, verify the recipient and channel, and preserve every query and replacement.

Build bank-specific packages without copying the whole room

The application coordinator should create a bank-specific outgoing package from approved read-only files and an approved manifest. The package should contain only the evidence required for the current application or query, with restricted files sent through the bank’s verified secure channel. The bank should not receive an open-ended data-room administrator link or unrelated personal records for convenience.

The manifest should record the bank, branch, case, officer or portal, file identifier, version, purpose, confidentiality, delivery date, sender, acknowledgement, query, and later replacement. A response to a bank question should cite the prior package and explain any changed file. Different form layouts are acceptable; inconsistent legal identity, ownership, authority, or business facts are not.

Control point

Release the package only after a second reviewer matches every file to the manifest and approved answer set.

  • Confirm the recipient and secure channel independently.
  • Export read-only outgoing copies without hidden comments or draft metadata as appropriate.
  • Record exactly which sensitive files the bank received.
  • Preserve query, response, acknowledgement, and replacement history.

Use the company bank evidence guide to test package completeness.

Keep the data room active after account approval

The data room should continue through account activation and ongoing KYC. Store the accepted mandate, signers, account details, digital users, tokens or credential custody records, limits, statements, test transactions, bank query log, KYC refresh dates, and later officer or ownership changes. Do not store live passwords, PINs, or one-time codes in the document room.

The quarterly room review should check expired evidence, ownership or director events, unresolved bank queries, access rights, superseded submissions, and facilities that never activated. It should also archive closed applications and revoke external access while preserving the board and audit trail. A room that stops at account number issuance cannot support later signatory changes or bank refresh.

Release test

Close the project phase, not the controlled evidence lifecycle, when the account opens.

  • Transfer ongoing ownership to corporate and treasury control owners.
  • Schedule KYC, identity, power, license, and access refreshes.
  • Retain before-and-after mandate and user reports for changes.
  • Audit access, downloads, external users, and restricted evidence quarterly.

Connect the room with the PT PMA compliance calendar.

Use the Indonesia company registration service scope to coordinate any deed, OSS, licensing, banking, or post-registration dependency revealed by this review.

Official References and Review Basis

Primary materials were checked on July 31, 2026. These links support the regulatory and banking framework used in this article; they do not replace a matter-specific legal, tax, licensing, accounting, security, or bank review.

Regulatory Notes and Limitations

Data-room controls do not determine which documents a bank must accept. Banks can request additional evidence and apply current verification, data, and risk procedures; the PT PMA should also apply applicable privacy, retention, security, and cross-border data rules.

  • Customer and beneficial-owner due diligence does not justify unrestricted access to personal or source-of-funds material.
  • A bank should receive current approved evidence through a verified channel, not an uncontrolled shared folder.
  • The data room should not store live bank passwords, PINs, one-time codes, or shared authentication secrets.
  • Document retention, deletion, legal hold, and cross-border transfer require matter-specific policy and advice.

Open the PT PMA data room only after ownership and access controls are assigned

A useful bank data room is a governed evidence system, not a large folder. Assign source owners, separate sensitive material, create the evidence index, and release bank-specific packages through a frozen manifest and verified channel.

Do not invite the full project team before permissions and expiry are known, and do not stop controlling the room when the account number arrives. The same evidence lineage should support activation, signatory changes, KYC refresh, and future transactions.

Turn the application room into an ongoing control

Retain activation, mandate, user, token, limit, test, refresh, and access evidence after the account opens.

Frequently asked questions

Should the bank receive access to the whole PT PMA data room?
Usually provide a controlled bank-specific package or approved portal submission containing the requested evidence. Avoid open-ended access to unrelated personal, source-of-funds, adviser, or working files.
Who owns the data room?
Assign a business owner for the control environment, an application coordinator for submissions, and accountable source owners for corporate, ownership, people, licensing, finance, and treasury evidence.
Can passports and source-of-wealth documents share the normal corporate folder?
Use restricted folders and least-privilege access. Record the purpose, approver, recipient, secure channel, retention, and revocation for sensitive evidence.
What should never be stored in the data room?
Do not store live passwords, PINs, one-time codes, shared authentication secrets, or uncontrolled token details. Keep credential custody and recovery records without exposing usable secrets.
When can the bank data room be archived?
Archive the application phase after completion, but keep a controlled ongoing record for accepted mandates, KYC refresh, access changes, bank queries, and required retention. Revoke unnecessary external access.
Jaslyn

Hey! I'm Jaslyn

Leave our friendly team a message and we'll be in touch in no time.

We will never share your details with any third party. Please see our Privacy Policy for more details.

Submission Successful!

Thank you for your inquiry. Our expert team will contact you shortly with a customized solution.

On this page
Talk to an Expert