EU AML standards put three control owners on notice
AMLA’s draft Regulatory Technical Standards would standardise customer checks, transaction classification and group-wide controls after Commission adoption and publication.
The Cyprus Gaming and Casino Supervision Commission (CGCS) says the European Union Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has submitted three draft Regulatory Technical Standards (RTS) to the European Commission. Compliance owners should now review customer due diligence, transaction classification and group-wide governance against a pending EU adoption process.
The drafts concern obliged entities under the EU AML/CFT framework. They are not binding rules yet and do not announce a Cyprus-specific enforcement measure.
Three draft standards define the control areas
The first draft covers the boundary between business relationships and occasional transactions. It also sets criteria for identifying linked transactions, supporting consistent application of customer due diligence thresholds.
That classification determines which control route an operator follows. A transaction may require a different assessment depending on whether it forms part of an ongoing customer relationship or is connected to other transactions. The CGCS publication does not set out the final technical wording or prescribe a new Cyprus-specific threshold.
The second draft addresses customer due diligence. It covers the information obliged entities must collect and verify, including measures for lower-risk situations, non-face-to-face verification and electronic identification. It also includes screening of politically exposed persons, their family members and close associates.
For casino and gambling operators supervised by the CGCS, the immediate review is whether existing procedures can accommodate the technical detail once the RTS become applicable. That includes onboarding data, evidence used for remote verification and treatment of PEP-related relationships. The publication does not establish that current CGCS controls are deficient or require replacement before adoption.
The third draft addresses group-wide AML/CFT arrangements. It covers minimum requirements for governance, risk management, internal controls and secure information sharing across a group.
This creates a control-ownership question for operators with entities in more than one jurisdiction. Compliance teams can map which policies are set centrally, which controls remain local and how information moves between group entities. The draft status leaves the timing and final wording unresolved.
Commission adoption remains the legal gateway
AMLA has finalised the drafts, but the European Commission must adopt them before they move to the next stage. The CGCS publication separates that submission from the later publication of adopted standards in the Official Journal of the European Union.
The proposed application period is six months after entry into force, following adoption and Official Journal publication. The publication provides no Commission adoption date, Official Journal date or separate timetable for operator implementation.
That sequence limits the present compliance conclusion. Operators can use the three subject areas to identify affected owners and systems, but the drafts cannot yet be treated as operative EU obligations. CGCS supervision remains a separate jurisdictional layer and the publication does not announce a Cyprus enforcement timetable tied to these drafts.
The distinction also matters for group policy design. A central AML/CFT function can compare existing controls with the draft subjects, while local compliance teams determine how any final requirements interact with Cyprus licensing and supervisory expectations. Applicable scope will depend on the final adopted instruments and their terms.
The implementation test will follow publication
The first technical test is classification: whether the operator can identify business relationships, occasional transactions and linked transactions consistently enough to apply the relevant CDD thresholds. The second is evidential: whether customer information and verification records support the final requirements for lower-risk, remote and electronic-identification cases.
The third is organisational. Operators will need to establish whether governance, risk management, internal controls and secure group information-sharing arrangements meet the adopted standard across entities within scope. Those are implementation questions, not findings that a current operator has breached a rule.
The next supervisory milestone is European Commission adoption. If the Commission adopts the drafts and they are published in the Official Journal, the six-month application period described by the CGCS will determine the subsequent compliance timetable. Until then, the final RTS text, entry-into-force date and implementation window remain the tests that will determine which Cyprus-supervised operators must retune their controls and by when.
Permanent link to this Atlas analysis
Related Atlas analysis
Continue with coverage connected by market, topic and operating context.
- CuraçaoCuraçao sets May 2027 deadline for remote-onboarding controlsCuraçao’s Gaming Authority has imposed mandatory NOIS controls for remote identification, giving existing onboarding systems until 1 May 2027 to comply.
- SingaporeMAS proposes new governance rules for banks and insurersMAS is seeking views on draft rules that would reshape director independence, board structures and senior appointment requirements across specified financial institutions.
- BrazilBrazil's Central Bank blocks boleto betting transactionsBrazil’s Central Bank has amended its boleto payment rules, requiring participating institutions to block transactions intended for fixed-odds betting lotteries.
Continue with Atlas
Move from this development into the relevant research, comparison and workflow.
- Gambling compliance software guideSee the research, monitoring, ownership and evidence a useful platform should connect.
- Atlas vs VixioCompare gambling research, change monitoring, workflow, technical work and evidence.
- Monitoring and alertsFollow a relevant change from detection through accountable implementation.