ATLAS
← Back to News and Insights

EU AML standards put three control owners on notice

3 min

AMLA’s draft Regulatory Technical Standards would standardise customer checks, transaction classification and group-wide controls after Commission adoption and publication.

LinkedIn Post
EU AML standards put three control owners on notice
European Union · Photo: Najib Samatar / Unsplash

The Cyprus Gaming and Casino Supervision Commission (CGCS) says the European Union Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has submitted three draft Regulatory Technical Standards (RTS) to the European Commission. Compliance owners should now review customer due diligence, transaction classification and group-wide governance against a pending EU adoption process.

The drafts concern obliged entities under the EU AML/CFT framework. They are not binding rules yet and do not announce a Cyprus-specific enforcement measure.

Three draft standards define the control areas

The first draft covers the boundary between business relationships and occasional transactions. It also sets criteria for identifying linked transactions, supporting consistent application of customer due diligence thresholds.

That classification determines which control route an operator follows. A transaction may require a different assessment depending on whether it forms part of an ongoing customer relationship or is connected to other transactions. The CGCS publication does not set out the final technical wording or prescribe a new Cyprus-specific threshold.

The second draft addresses customer due diligence. It covers the information obliged entities must collect and verify, including measures for lower-risk situations, non-face-to-face verification and electronic identification. It also includes screening of politically exposed persons, their family members and close associates.

For casino and gambling operators supervised by the CGCS, the immediate review is whether existing procedures can accommodate the technical detail once the RTS become applicable. That includes onboarding data, evidence used for remote verification and treatment of PEP-related relationships. The publication does not establish that current CGCS controls are deficient or require replacement before adoption.

The third draft addresses group-wide AML/CFT arrangements. It covers minimum requirements for governance, risk management, internal controls and secure information sharing across a group.

This creates a control-ownership question for operators with entities in more than one jurisdiction. Compliance teams can map which policies are set centrally, which controls remain local and how information moves between group entities. The draft status leaves the timing and final wording unresolved.

Commission adoption remains the legal gateway

AMLA has finalised the drafts, but the European Commission must adopt them before they move to the next stage. The CGCS publication separates that submission from the later publication of adopted standards in the Official Journal of the European Union.

The proposed application period is six months after entry into force, following adoption and Official Journal publication. The publication provides no Commission adoption date, Official Journal date or separate timetable for operator implementation.

That sequence limits the present compliance conclusion. Operators can use the three subject areas to identify affected owners and systems, but the drafts cannot yet be treated as operative EU obligations. CGCS supervision remains a separate jurisdictional layer and the publication does not announce a Cyprus enforcement timetable tied to these drafts.

The distinction also matters for group policy design. A central AML/CFT function can compare existing controls with the draft subjects, while local compliance teams determine how any final requirements interact with Cyprus licensing and supervisory expectations. Applicable scope will depend on the final adopted instruments and their terms.

The implementation test will follow publication

The first technical test is classification: whether the operator can identify business relationships, occasional transactions and linked transactions consistently enough to apply the relevant CDD thresholds. The second is evidential: whether customer information and verification records support the final requirements for lower-risk, remote and electronic-identification cases.

The third is organisational. Operators will need to establish whether governance, risk management, internal controls and secure group information-sharing arrangements meet the adopted standard across entities within scope. Those are implementation questions, not findings that a current operator has breached a rule.

The next supervisory milestone is European Commission adoption. If the Commission adopts the drafts and they are published in the Official Journal, the six-month application period described by the CGCS will determine the subsequent compliance timetable. Until then, the final RTS text, entry-into-force date and implementation window remain the tests that will determine which Cyprus-supervised operators must retune their controls and by when.

Official source: Cyprus Gaming and Casino Supervision Commission (CGCS)
GamblingOnboarding CDDAML ProgrammesAML CFT

Permanent link to this Atlas analysis

Continue with coverage connected by market, topic and operating context.

Continue with Atlas

Move from this development into the relevant research, comparison and workflow.