top of page

AML Basics

Obliged institutions - who must comply with AML and how?

The main categories of entities covered by the AML Act, customer due diligence measures, KYC and CDD procedures, PEP and sanctions screening, notifications to GIIF and the consequences of non-compliance.

WHO IS COVERED

Which institutions are obliged entities?

The AML Act covers far more than banks. Whether a business qualifies as an obliged entity depends primarily on the type of activity it conducts, the services it provides or the transactions it carries out. In some cases, the value of the transaction is also relevant.

free-bank-icon-1071-thumb.png

Banks and credit unions

images.png

Real estate agents

18274908.png

Payment service providers

1__284_29.png

Lending institutions

318-3183849_vector-free-download-accounts-icon-business-finance-accounting-and-finance-ico

Accounting firms

120569051-hierarchical-structure-icon-vector-isolated-on-white-background-logo-concept-of-

Casinos and gambling operators

46ac2aa4-8221-4259-ac45-442f633dd162.png

Insurance companies

sllmnhx-bitcoin-icon-6219384_1920.png

Cryptocurrency exchanges

1026130.png

Tax advisers

2710127.png

Notaries and lawyers

istockphoto-1213726716-612x612.png

Currency exchange offices

mona-lisa.png

Art dealers

These are the most common categories of obliged entities. The Act also covers other businesses and professionals, while in some professions AML obligations apply only when carrying out specific activities.

The size of a business does not determine its status. An obliged entity may be either a large organisation or a sole trader, provided that it performs activities covered by the AML Act.

AML IN PRACTICE

Key obligations of obliged entities

Every obliged entity must implement AML measures appropriate to the nature, type and scale of its activities. The Act specifies the required elements of the system, while the scope and intensity of the measures applied depend on the identified level of risk.

KYC and client identification

Identifying the client and verifying their identity using documents, data or information obtained from a reliable and independent source. For legal entities, this also includes verifying the individuals authorised to act on their behalf.

Risk assessment (CDD)

Identifying and documenting the money laundering and terrorist financing risks associated with a specific business relationship or transaction. The assessment considers factors such as the type of client, jurisdiction, products, transaction value and purpose of the relationship.

Transaction monitoring

Reviewing transactions and the business relationship to ensure that they are consistent with the obliged entity’s knowledge of the client’s activities and risk profile, keeping client information up to date and, where justified, examining the source of funds or other assets.

PEP and sanctions screening

Establishing whether the client or their ultimate beneficial owner is a PEP, a family member or a known close associate of a PEP, and applying the measures required by law. This also includes sanctions screening and the application of relevant restrictive measures.

Notifications to GIIF

Submitting notifications to GIIF about circumstances that may indicate suspected money laundering or terrorist financing, and taking the actions required by law in relation to suspicious transactions or assets.

Procedures, documentation and training

Implementing an internal AML procedure, documenting the measures applied and the results of analyses, training employees responsible for AML tasks and appointing individuals responsible for ensuring that these obligations are properly performed.

You can find detailed definitions of AML, CFT and related concepts in our AML glossary.

VERIFICATION PROCEDURES

KYC and CDD - how is a client verified?

Know Your Customer (KYC) refers in practice to identifying the client and obtaining basic information about their activities. Customer Due Diligence (CDD), is broader: it also includes identifying the UBO, understanding the purpose of the relationship, assessing risk and continuously monitoring the relationship.

Stages of KYC

1

Identifying an individual or legal entity

Collecting the required information and verifying identity against a reliable source - using an identity card or passport and, for legal entities, registration details and corporate documents.

2

Identifying the ultimate beneficial owner (UBO)

Determining which individuals directly or indirectly control the client and understanding the client’s ownership and control structure. An extract from a public register alone may not always be sufficient to meet this obligation.

3

Understanding the purpose of the business relationship

Establishing why the client uses the service, the nature of their activities and the types of transactions that can reasonably be expected during the relationship. Where justified, the source of wealth or funds must also be examined.

4

Screening against external databases

Checking PEP and sanctions status, confirming registration details and analysing other information relevant to risk. It is important not only to identify a result, but also to determine whether it relates to the correct individual or entity.

Due diligence measures according to risk

Lower risk - SDD

Simplified due diligence measures may be applied only where a documented assessment confirms a lower level of risk. Simplification does not mean that the client or ultimate beneficial owner does not need to be identified.

Standard measures - CDD

Standard due diligence measures include identifying and verifying the client, establishing the UBO, understanding the purpose of the relationship, assessing risk and conducting ongoing monitoring. 

Higher risk - EDD

Enhanced due diligence measures are applied where the risk is higher and in situations specified by law, including relationships involving PEPs or high-risk third countries. They may require additional information and more intensive monitoring.

Inability to complete verification

Where an obliged entity cannot apply one of the required due diligence measures, it should generally not establish the relationship, carry out an occasional transaction or continue an existing relationship. It must also consider whether GIIF should be notified.

Risk assessment is not a one-off exercise. Documents, data and information about the client must be kept up to date, while the measures applied must be adjusted to changes in the client’s activities, structure, transactions and other risk factors.

In practice, verifying a client  (whether an individual or a legal entity) requires establishing their identity, ultimate beneficial owner and risk factors associated with PEP status, sanctions and relevant connections. CheckLists FinAP by FinObserve brings this information together in one place and supports the documentation of the analysis

LIABILITY

Consequences of failing to meet AML obligations

Breaches of AML requirements may result in serious legal, financial and organisational consequences — both for the obliged entity and for the individuals responsible for performing its obligations.

Financial penalties

The amount of the penalty depends on the type of entity, the nature of the breach and its consequences. In the most serious cases, penalties may reach millions, while a separate fine may also be imposed on the responsible individual.

Criminal liability

Failure to submit a required notification to GIIF, providing false information or unlawfully disclosing protected information may result in criminal liability, including imprisonment.

Administrative measures

Possible measures include publishing information about the breach, ordering the entity to cease specific activities, prohibiting an individual from holding a managerial position and requiring the implementation of post-inspection recommendations.

Loss of authorisation or licence

Serious breaches may result in the withdrawal of a licence or authorisation, or removal from a register of regulated activities, preventing the entity from continuing the relevant business activity.

A penalty does not require proof that money was actually laundered through the obliged entity. Liability may arise solely from a failure to perform statutory obligations, such as assessing risk, applying due diligence measures, documenting activities, providing training or submitting a required notification.

Where does AML law come from and who enforces it?

Learn what money laundering is, how the global AML system works and how it translates into obligations for specific businesses and professionals.

How do obliged entities implement AML in practice?

Regulations define the obligations. Carrying them out every day — for every client, using current data and maintaining complete documentation and an audit trail - requires appropriate processes and tools.

This is why obliged entities increasingly use solutions that organise data, standardise the verification process and guide users through its individual stages.

One such solution is CheckLists FinAP by FinObserve - a tool supporting the identification and analysis of clients, both individuals and legal entities, for AML, KYC and KYB purposes.

ChatGPT Image Apr 10, 2026, 05_41_04 PM.jpg
bottom of page