My bookmarksSign up free

Regulation (EU) 2024/1624 CHAPTER III — CUSTOMER DUE DILIGENCE

Article 19–Article 50 · 32 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

SECTION 1 — General provisions

Application of customer due diligence measures

Article 19

1.   Obliged entities shall apply customer due diligence measures in any of the following circumstances: (a) when establishing a business relationship; (b) when carrying out an occasional transaction of a value of at least EUR 10 000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions, or a lower value laid down pursuant to paragraph 9; (c) when participating in the creation of a legal entity, the setting up of a legal arrangement or, for the obliged entities referred to in Article 3, points (3) (a), (b) or (c), in the transfer of ownership of a legal entity, irrespective of the value of the transaction; (d) when there is a suspicion of money laundering or terrorist financing, regardless of any derogation, exemption or threshold; (e) when there are doubts about the veracity or adequacy of previously obtained customer identification data; (f) when there are doubts as to whether the person they interact with is the customer or person authorised to act on behalf of the customer. 2.   In addition to the circumstances referred to in paragraph 1, credit institutions and financial institutions, with the exception of crypto-asset service providers, shall apply customer due diligence measures when initiating or executing an occasional transaction that constitutes a transfer of funds as defined in Article 3, point (9), of Regulation (EU) 2023/1113, that amounts to a value of at least EUR 1 000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions. 3.   By way of derogation from paragraph 1, point (b), crypto-asset service providers shall: (a) apply customer due diligence measures when carrying out an occasional transaction that amounts to a value of at least EUR 1 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions; (b) apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction where the value is below EUR 1 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions. 4.   By way of derogation from paragraph 1, point (b), obliged entities shall apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction in cash amounting to a value of at least EUR 3 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions. The first subparagraph of this paragraph shall not apply where Member States have in place, pursuant to Article 80(2) and (3), a limit to large cash payments of EUR 3 000 or less, or the equivalent in national currency, except in the cases covered by paragraph 4, point (b) of that Article. 5.   In addition to the circumstances referred to in paragraph 1, providers of gambling services shall apply customer due diligence measures upon the collection of winnings, the wagering of a stake, or both, when carrying out transactions amounting to at least EUR 2 000 or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions. 6.   For the purposes of this Chapter, obliged entities shall consider as their customers the following persons: (a) in the case of obliged entities as referred to in Article 3, points (3) (e), (f) and (i) and persons trading in high value goods as referred to in Article 3, point (3) (j), in addition to their direct customer, the supplier of goods; (b) in the case of notaries, lawyers and other independent legal professionals intermediating a transaction and to the extent that they are the only notary or lawyer or other independent legal professional intermediating that transaction, both parties to the transaction; (c) in the case of real estate agents, both parties to the transaction; (d) in relation to payment initiation services carried out by payment initiation service providers, the merchant; (e) in relation to crowdfunding service providers and crowdfunding intermediaries, the natural or legal person both seeking funding and providing funding through the crowdfunding platform. 7.   Supervisors may, directly or in cooperation with other authorities in that Member State, exempt obliged entities from applying, in full or in part, the customer due diligence measures referred to in Article 20(1), points (a), (b) and (c), with respect to electronic money on the basis of the proven low risk posed by the nature of the product, where all of the following risk-mitigating conditions are met: (a) the payment instrument is not reloadable, and the amount stored electronically does not exceed EUR 150 or the equivalent in national currency; (b) the payment instrument is used exclusively to purchase goods or services provided by the issuer, or within a network of service providers; (c) the payment instrument is not linked to a payment account and it does not permit any stored amount to be exchanged for cash or for crypto-assets; (d) the issuer carries out sufficient monitoring of the transactions or business relationship to enable the detection of unusual or suspicious transactions. 8.   Providers of gambling services may fulfil their obligation to apply customer due diligence measures referred to in Article 20(1), point (a), by identifying the customer and verifying the customer’s identity upon entry to the casino or other physical gambling premises, provided that they have systems in place that enable them to attribute transactions to specific customers. 9.   By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify: (a) the obliged entities, sectors or transactions that are associated with higher money laundering and terrorist financing risk and to which a value lower than the value set out in paragraph 1, point (b), applies; (b) the related occasional transaction values; (c) the criteria to be taken into account for identifying occasional transactions and business relationships; (d) the criteria to identify linked transactions. When developing the draft regulatory technical standards referred to in the first subparagraph, AMLA shall take due account of the inherent levels of risks of the business models of the different types of obliged entities and of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640. 10.   Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 9 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Customer due diligence measures

Article 20

1.   For the purpose of conducting customer due diligence, obliged entities shall apply all of the following measures: (a) identifying the customer and verifying the customer’s identity; (b) identifying the beneficial owners and taking reasonable measures to verify their identity so that the obliged entity is satisfied that it knows who the beneficial owner is and that it understands the ownership and control structure of the customer; (c) assessing and, as appropriate, obtaining information on and understanding the purpose and intended nature of the business relationship or the occasional transactions; (d) verifying whether the customer or the beneficial owners are subject to targeted financial sanctions, and, in the case of a customer or party to a legal arrangement who is a legal entity, whether natural or legal persons subject to targeted financial sanctions control the legal entity or have more than 50 % of the proprietary rights of that legal entity or majority interest in it, whether individually or collectively; (e) assessing and, as appropriate, obtaining information on the nature of the customers’ business, including, in the case of undertakings, whether they carry out activities, or of their employment or occupation; (f) conducting ongoing monitoring of the business relationship including scrutiny of transactions undertaken throughout the course of the business relationship to ensure that the transactions being conducted are consistent with the obliged entity’s knowledge of the customer, the business and risk profile, including where necessary the source of funds; (g) determining whether the customer, the beneficial owner of the customer and, where relevant, the person on whose behalf or for the benefit of whom a transaction or activity is being carried out is a politically exposed person, a family member or person known to be a close associate; (h) where a transaction or activity is being conducted on behalf of or for the benefit of natural persons other than the customer, identifying and verifying the identity of those natural persons; (i) verifying that any person purporting to act on behalf of the customer is so authorised and identify and verify their identity. 2.   Obliged entities shall determine the extent of the measures referred to in paragraph 1 on the basis of an individual analysis of the risks of money laundering and terrorist financing having regard to the specific characteristics of the client and of the business relationship or occasional transaction, and taking into account the business-wide risk assessment by the obliged entity pursuant to Article 10 and the money laundering and terrorist financing variables set out in Annex I as well as the risk factors set out in Annexes II and III. Where obliged entities identify an increased risk of money laundering or terrorist financing they shall apply enhanced due diligence measures pursuant to Section 4 of this Chapter. Where situations of lower risk are identified, obliged entities may apply simplified due diligence measures pursuant to Section 3 of this Chapter. 3.   By 10 July 2026, AMLA shall issue guidelines on the risk variables and risk factors to be taken into account by obliged entities when entering into business relationships or carrying out occasional transactions. 4.   Obliged entities shall at all times be able to demonstrate to their supervisors that the measures taken are appropriate in view of the risks of money laundering and terrorist financing that have been identified.

Inability to comply with the requirement to apply customer due diligence measures

Article 21

1.   Where an obliged entity is unable to comply with the requirement to apply customer due diligence measures laid down in Article 20(1), it shall refrain from carrying out a transaction or establishing a business relationship, and shall terminate the business relationship and consider reporting a suspicious transaction to the FIU in relation to the customer in accordance with Article 69. The termination of a business relationship pursuant to the first subparagraph of this paragraph shall not prohibit the receipt of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 due to the obliged entity. Where an obliged entity has a duty to protect its customer’s assets, the termination of the business relationship shall not be understood as requiring the disposal of the assets of the customer. In the case of life insurance contracts, obliged entities shall, where necessary as an alternative measure to terminating the business relationship, refrain from performing transactions for the customer, including payouts to beneficiaries, until the customer due diligence measures laid down in Article 20(1) are complied with. 2.   Paragraph 1 shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors, to the extent that those persons ascertain the legal position of their client, or perform the task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings. The first subparagraph shall not apply when the obliged entities referred to therein: (a) take part in money laundering, its predicate offences or terrorist financing; (b) provide legal advice for the purposes of money laundering, its predicate offences or terrorist financing; or (c) know that the client is seeking legal advice for the purposes of money laundering, its predicate offences or terrorist financing; knowledge or purpose may be inferred from objective factual circumstances. 3.   Obliged entities shall keep record of the actions taken in order to comply with the requirement to apply customer due diligence measures, including records of the decisions taken and the relevant supporting documents and justifications. Documents, data or information held by the obliged entity shall be updated whenever the customer due diligence is reviewed pursuant to Article 26. The obligation to keep records provided for in the first subparagraph of this paragraph shall also apply to situations where obliged entities refuse to enter into a business relationship, terminate a business relationship or apply alternative measures pursuant to paragraph 1. 4.   By 10 July 2027, AMLA shall issue joint guidelines with the European Banking Authority on the measures that may be taken by credit institutions and financial institutions to ensure compliance with AML/CFT rules when implementing the requirements of Directive 2014/92/EU, including in relation to business relationships that are most affected by de-risking practices.

Identification and verification of the identity of customers and beneficial owners

Article 22

1.   With the exception of cases of lower risk to which measures under Section 3 apply and irrespective of the application of additional measures in cases of higher risk under Section 4 obliged entities shall obtain at least the following information in order to identify the customer, any person purporting to act on behalf of the customer, and the natural persons on whose behalf or for the benefit of whom a transaction or activity is being conducted: (a) for a natural person: (i) all names and surnames; (ii) place and full date of birth; (iii) nationalities, or statelessness and refugee or subsidiary protection status where applicable, and the national identification number, where applicable; (iv) the usual place of residence or, if there is no fixed residential address with legitimate residence in the Union, the postal address at which the natural person can be reached and, where available the tax identification number; (b) for a legal entity: (i) legal form and name of the legal entity; (ii) address of the registered or official office and, if different, the principal place of business, and the country of creation; (iii) the names of the legal representatives of the legal entity as well as, where available, the registration number, the tax identification number and the Legal Entity Identifier; (iv) the names of persons holding shares or a directorship position in nominee form, including reference to their status as nominee shareholders or directors. (c) for a trustee of an express trust or a person holding an equivalent position in a similar legal arrangement: (i) basic information on the legal arrangement; however, with regard to the assets held in the legal arrangement or managed through it, only the assets that are to be managed in the context of the business relationship or occasional transaction shall be identified; (ii) the address of residence of the trustees or persons holding an equivalent position in a similar legal arrangement and, if different, the place from where the express trust or similar legal arrangement is administered, the powers that regulate and bind the legal arrangement, as well as, where available, the tax identification number and the Legal Entity Identifier; (d) for other organisations that have legal capacity under national law: (i) name, address of the registered office or equivalent; (ii) names of the persons empowered to represent the organisation as well as, where applicable, legal form, tax identification number, registration number, Legal Entity Identifier and deeds of association or equivalent. 2.   For the purposes of identifying the beneficial owner of a legal entity or of a legal arrangement, obliged entities shall collect the information referred to in Article 62(1), second subparagraph, point (a). Where, after having exhausted all possible means of identification, no natural persons are identified as beneficial owners, or where there are doubts that the persons identified are the beneficial owners, obliged entities shall record that no beneficial owner was identified and identify all the natural persons holding the positions of senior managing officials in the legal entity and shall verify their identity. Where the performance of identity verification referred to in the second subparagraph may tip off the customer that the obliged entity has doubts regarding the beneficial ownership of the legal entity, the obliged entity shall abstain from verifying the senior managing officials’ identity, and shall instead record the steps taken to ascertain the identity of the beneficial owners and senior managing officials. Obliged entities shall keep records of the actions taken as well as of the difficulties encountered during the identification process, which led to resorting to the identification of a senior managing official. 3.   Credit institutions and financial institutions shall obtain information to identify and verify the identity of the natural or legal persons using any virtual IBAN they issue, and the associated bank or payment account. The credit institution or financial institution servicing the bank or payment account to which a virtual IBAN issued by another credit institution or financial institution redirects payments, shall ensure that it can obtain from the institution issuing the virtual IBAN the information identifying and verifying the identity of the natural person using that virtual IBAN without delay and in any case within 5 working days of it requesting that information. 4.   In the case of beneficiaries of trusts or similar legal entities or arrangements that are designated by particular characteristics or class, an obliged entity shall obtain sufficient information concerning the beneficiary so that it will be able to establish the identity of the beneficiary at the time of the payout or at the time of the exercise by the beneficiary of its vested rights. 5.   In the case of discretionary trusts, an obliged entity shall obtain sufficient information concerning the objects of a power and default takers to enable it to establish the identity of the beneficiary at the time of the exercise by the trustees of their power of discretion, or at the time that the default takers become the beneficiaries due to the trustees’ failure to exercise their power of discretion. 6.   Obliged entities shall obtain the information, documents and data necessary for the verification of the identity of the customer and of any person purporting to act on their behalf through either of the following means: (a) the submission of an identity document, passport or equivalent and, where relevant, the acquisition of information from reliable and independent sources, whether accessed directly or provided by the customer; (b) the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels ‘substantial’ or ‘high’ and relevant qualified trust services as set out in that Regulation. 7.   Obliged entities shall verify the identity of the beneficial owner and, where relevant, the persons on whose behalf or for the benefit of whom a transaction or activity is being carried out in either of the following ways: (a) in accordance with paragraph 6; (b) by taking reasonable measures to obtain the necessary information, documents and data from the customer or other reliable sources, including public registers other than the central registers. Obliged entities shall determine the extent of the information to be consulted, having regard to the risks posed by the occasional transaction or the business relationship and the beneficial owner, including risks relating to the ownership structure. In addition to the means of verification set out in the first subparagraph of this paragraph, obliged entities shall verify the information on the beneficial owners by consulting the central registers.

Timing of the verification of the customer and beneficial owner identity

Article 23

1.   Verification of the identity of the customer, the beneficial owner, and of any persons pursuant to Article 20(1), points (h) and (i), shall take place before the establishment of a business relationship or the carrying out of an occasional transaction. Such obligation shall not apply to situations of lower risk under Section 3 of this Chapter, provided that the lower risk justifies postponement of such verification. For real estate agents, the verification referred to in the first subparagraph shall be carried out after an offer is accepted by the seller or lessor, and in all cases before any funds or property are transferred. 2.   By way of derogation from paragraph 1, verification of the identity of the customer and of the beneficial owner may be completed during the establishment of a business relationship if necessary so as not to interrupt the normal conduct of business and where there is little risk of money laundering or terrorist financing. In such situations, those procedures shall be completed as soon as practicable after initial contact. 3.   By way of derogation from paragraph 1 of this Article, a credit institution or financial institution may open an account, including accounts that permit transactions in transferable securities, as may be required by a customer provided that there are adequate safeguards in place to ensure that transactions are not carried out by the customer or on its behalf until full compliance with the customer due diligence measures laid down in Article 20(1), points (a) and (b), is obtained. 4.   Whenever entering into a new business relationship with a legal entity or the trustee of an express trust or the person holding an equivalent position in a similar legal arrangement referred to in Articles 51, 57, 58, 61 and 67 and subject to the registration of beneficial ownership information pursuant to Article 10 of Directive (EU) 2024/1640, obliged entities shall collect valid proof of registration or a recently issued excerpt of the register confirming validity of registration.

Reporting of discrepancies with information contained in beneficial ownership registers

Article 24

1.   Obliged entities shall report to the central registers any discrepancies they find between the information available in the central registers and the information they collect pursuant to Article 20(1), point (b), and Article 22(7). The discrepancies referred to in the first subparagraph shall be reported without undue delay and, in any case, within 14 calendar days of their detection. When reporting such discrepancies, obliged entities shall accompany their reports with information they have obtained indicating the discrepancy and whom they consider to be the beneficial owners and, where applicable, the nominee shareholders and nominee directors to be and why. 2.   By way of derogation from paragraph 1, obliged entities may refrain from reporting discrepancies to the central register and may instead request additional information from the customers where the discrepancies identified: (a) are limited to typographical errors, different ways of transliteration, or minor inaccuracies that do not affect the identification of the beneficial owners or their position; or (b) are a result of outdated data, but the beneficial owners are known to the obliged entity from another reliable source and there are no grounds for suspicion that there is an intention to conceal any information. Where an obliged entity concludes that the beneficial ownership information in the central register is incorrect, it shall invite the customer to submit the correct information to the central register pursuant to Articles 63, 64 and 67 without undue delay, and, in any case, within 14 calendar days. This paragraph shall not apply to cases of higher risk to which measures under Section 4 of this Chapter apply. 3.   Where a customer has not submitted the correct information within the deadline referred to in paragraph 2, second subparagraph, the obliged entity shall report the discrepancy to the central register in accordance with paragraph 1, second subparagraph. 4.   This Article shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors in relation to information they receive from, or obtain on, a client, in the course of ascertaining the legal position of that client, or performing their task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, regardless of whether such information is received or obtained before, during or after such proceedings. However, the requirements of this Article shall apply when the obliged entities referred to in the first subparagraph of this paragraph provide legal advice in any of the situations covered by Article 21(2), second subparagraph.

Identification of the purpose and intended nature of a business relationship or occasional transaction

Article 25

Before entering into a business relationship or performing an occasional transaction, an obliged entity shall assure itself that it understands its purpose and intended nature. To that end, the obliged entity shall obtain, where necessary, information on: (a) the purpose and economic rationale of the occasional transaction or business relationship; (b) the estimated amount of the envisaged activities; (c) the source of funds; (d) the destination of funds; (e) the business activity or the occupation of the customer. For the purposes of the first paragraph, point (a), of this Article, obliged entities covered by Article 74 shall collect information in order to determine whether the intended use of high value goods referred to in that Article is for commercial or non-commercial purposes.

Ongoing monitoring of the business relationship and monitoring of transactions performed by customers

Article 26

1.   Obliged entities shall conduct ongoing monitoring of business relationships, including transactions undertaken by the customer throughout the course of a business relationship, to ensure that those transactions are consistent with the obliged entity’s knowledge of the customer, the customer’s business activity and risk profile, and where necessary, with the information about the origin and destination of the funds and to detect those transactions that shall be made subject to a more thorough assessment pursuant to Article 69(2). Where business relationships cover more than one product or service, obliged entities shall ensure that the customer due diligence measures cover all those products and services. Where obliged entities belonging to a group have business relationships with customers that are also the customers of other entities within that group, whether obliged entities or undertakings not subject to AML/CFT requirements, they shall take into account information relating to those other business relationships for the purposes of monitoring the business relationship with their customers. 2.   In the context of the ongoing monitoring referred to in paragraph 1, obliged entities shall ensure that the relevant documents, data or information of the customer are kept up to date. The period between updates of customer information pursuant to the first subparagraph shall be dependent on the risk posed by the business relationship and shall not in any case exceed: (a) for higher risk customers to which measures under Section 4 of this Chapter apply, 1 year; (b) for all other customers, 5 years. 3.   In addition to the requirements set out in paragraph 2, obliged entities shall review and, where relevant, update the customer information where: (a) there is a change in the relevant circumstances of a customer; (b) the obliged entity has a legal obligation in the course of the relevant calendar year to contact the customer for the purpose of reviewing any relevant information relating to the beneficial owners or to comply with Council Directive 2011/16/EU  ( 42 ) ; (c) they become aware of a relevant fact which pertains to the customer. 4.   In addition to the ongoing monitoring referred to in paragraph 1 of this Article, obliged entities shall regularly verify whether the conditions laid down in Article 20(1), point (d), are met. The frequency of that verification shall be commensurate with the exposure of the obliged entity and the business relationship to risks of non-implementation and evasion of targeted financial sanctions. For credit institutions and financial institutions, the verification referred to in the first subparagraph shall also be carried out upon any new designation in relation to targeted financial sanctions. The requirements of this paragraph shall not replace the obligation to apply targeted financial sanctions or stricter requirements under other Union legal acts or under national law on the verification of the client base against lists of targeted financial sanctions. 5.   By 10 July 2026, AMLA shall issue guidelines on ongoing monitoring of a business relationship and on the monitoring of the transactions carried out in the context of such relationship.

Temporary measures for customers subject to UN financial sanctions

Article 27

1.   In respect of customers that are subject to UN financial sanctions or that are controlled by natural or legal persons or entities subject to UN financial sanctions, or in which natural or legal persons or entities that are subject to UN financial sanctions have more than 50 % of the proprietary rights or majority interest, whether individually or collectively, obliged entities shall keep records of: (a) the funds or other assets that they manage for the customer at the time when UN financial sanctions are made public; (b) the transactions attempted by the customer; (c) the transactions carried out for the customer. 2.   Obliged entities shall apply this Article between the time that UN financial sanctions are made public and the time of application of the relevant targeted financial sanctions in the Union.

Regulatory technical standards on the information necessary for the performance of customer due diligence

Article 28

1.   By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify: (a) the requirements that apply to obliged entities pursuant to Article 20 and the information to be collected for the purpose of performing standard, simplified and enhanced due diligence pursuant to Articles 22 and 25 and Articles 33(1) and 34(4), including minimum requirements in situations of lower risk; (b) the type of simplified due diligence measures which obliged entities may apply in situations of lower risk pursuant to Article 33(1) of this Regulation, including measures applicable to specific categories of obliged entities and products or services, having regard to the results of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640; (c) the risk factors associated with features of electronic money instruments that should be taken into account by supervisors when determining the extent of the exemption under Article 19(7); (d) the reliable and independent sources of information that may be used to verify the identification data of natural or legal persons for the purposes of Article 22(6) and (7); (e) the list of attributes which electronic identification means and relevant qualified trust services referred to in Article 22(6), point (b), must feature in order to fulfil the requirements of Article 20(1), points (a) and (b), in the case of standard, simplified and enhanced due diligence. 2.   The requirements and measures referred to in paragraph 1, points (a) and (b), shall be based on the following criteria: (a) the inherent risk involved in the service provided; (b) the risks associated with categories of customers; (c) the nature, amount and recurrence of the transaction; (d) the channels used for conducting the business relationship or the occasional transaction. 3.   AMLA shall review regularly the regulatory technical standards and, if necessary, prepare and submit to the Commission the draft for updating those standards in order, inter alia, to take account of innovation and technological developments. 4.   Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraphs 1 and 3 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

SECTION 2 — Third-country policy and money laundering and terrorist financing threats from outside the Union

Identification of third countries with significant strategic deficiencies in their national AML/CFT regimes

Article 29

1.   Third countries with significant strategic deficiencies in their national AML/CFT regimes shall be identified by the Commission and designated as ‘high-risk third countries’. 2.   In order to identify third countries as referred to in paragraph 1 of this Article, the Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation, where: (a) significant strategic deficiencies in the legal and institutional AML/CFT framework of the third country have been identified; (b) significant strategic deficiencies in the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks or in its system to assess and mitigate risks of non-implementation or evasion of UN financial sanctions relating to proliferation financing have been identified; (c) the significant strategic deficiencies identified under points (a) and (b) are of a persistent nature and no measures to mitigate them have been taken or are being taken. Those delegated acts shall be adopted within 20 calendar days of the Commission ascertaining that the criteria in point (a), (b) or (c) of the first subparagraph are met. 3.   For the purposes of paragraph 2, the Commission shall take into account calls for the application of enhanced due diligence measures and additional mitigating measures (‘countermeasures’) by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing, as well as relevant evaluations, assessments, reports or public statements drawn up by them. 4.   Where a third country is identified in accordance with the criteria referred to in paragraph 2, obliged entities shall apply enhanced due diligence measures listed in Article 34(4) with respect to the business relationships or occasional transactions involving natural or legal persons from that third country. 5.   The delegated act referred to in paragraph 2 shall identify among the countermeasures listed in Article 35 the specific countermeasures mitigating specific risks stemming from each high-risk third country. 6.   Where a Member State identifies a specific money laundering or terrorist financing risk posed by a third country that the Commission has identified in accordance with the criteria referred to in paragraph 2 which is not addressed by the countermeasures referred to in paragraph 5, it may require obliged entities established in its territory to apply specific additional countermeasures to mitigate the specific risks stemming from that third country. The risk identified and the corresponding countermeasures shall be notified to the Commission within 5 days of the countermeasures being applied. 7.   The Commission shall review the delegated acts referred to in paragraph 2 on a regular basis to ensure that the specific countermeasures identified pursuant to paragraph 5 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks. Upon receiving a notification pursuant to paragraph 6, the Commission shall assess the information received to determine whether country-specific risks affect the integrity of the Union’s internal market. Where appropriate, the Commission shall review the delegated acts referred to in paragraph 2, by adding the necessary countermeasures to mitigate those additional risks. Where the Commission considers that the specific additional measures applied by a Member State under paragraph 6 are not necessary to mitigate specific risks stemming from that third country, it may decide, by means of an implementing act, that the Member State shall put an end to the specific additional countermeasure.

Identification of third countries with compliance weaknesses in their national AML/CFT regimes

Article 30

1.   Third countries with compliance weaknesses in their national AML/CFT regimes shall be identified by the Commission. 2.   In order to identify the third countries referred to in paragraph 1, the Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation, where: (a) compliance weaknesses in the legal and institutional AML/CFT framework of the third country have been identified; (b) compliance weaknesses in the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks or in its system to assess and mitigate risks of non-implementation or evasion of UN financial sanctions relating to proliferation financing have been identified. Those delegated acts shall be adopted within 20 calendar days of the Commission ascertaining that the criteria in point (a) or (b) of the first subparagraph are met. 3.   The Commission, when drawing up the delegated acts referred to in paragraph 2 shall take into account, as a baseline for its assessment, information on jurisdictions under increased monitoring by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing, as well as relevant evaluations, assessments, reports or public statements drawn up by them. 4.   The delegated act referred to in paragraph 2 shall identify the specific enhanced due diligence measures among those listed in Article 34(4), that obliged entities shall apply to mitigate risks related to business relationships or occasional transactions involving natural or legal persons from that third country. 5.   The Commission shall review the delegated acts referred to in paragraph 2 on a regular basis to ensure that the specific enhanced due diligence measures identified pursuant to paragraph 4 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.

Identification of third countries posing a specific and serious threat to the Union’s financial system

Article 31

1.   The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation by identifying third countries where in exceptional cases it considers it indispensable to mitigate a specific and serious threat to the Union’s financial system and the proper functioning of the internal market posed by those third countries, and which cannot be mitigated pursuant to Articles 29 and 30. 2.   The Commission, when drawing up the delegated acts referred to in paragraph 1, shall take into account in particular the following criteria: (a) the legal and institutional AML/CFT framework of the third country, in particular: (i) the criminalisation of money laundering and terrorist financing; (ii) measures relating to customer due diligence; (iii) requirements relating to record-keeping; (iv) requirements to report suspicious transactions; (v) the availability of accurate and timely information of the beneficial ownership of legal persons and arrangements to competent authorities; (b) the powers and procedures of the third country’s competent authorities for the purposes of combating money laundering and terrorist financing including appropriately effective, proportionate and dissuasive sanctions, as well as the third country’s practice in cooperation and exchange of information with Member States’ competent authorities; (c) the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks. 3.   For the purposes of determining the level of threat referred to in paragraph 1, the Commission may request AMLA to adopt an opinion aimed at assessing the specific impact on the integrity of the Union’s financial system due to the level of threat posed by a third country. 4.   Where AMLA identifies that a third country other than those identified pursuant to Articles 29 and 30 poses a specific and serious threat to the Union’s financial system, it may address an opinion to the Commission setting out the threat it has identified and why it believes that the Commission should identify the third country pursuant to paragraph 1. Where the Commission decides not to identify the third country referred to in the first subparagraph, it shall provide a justification thereof to AMLA. 5.   The Commission, when drawing up the delegated acts referred to in paragraph 1, shall take into account in particular relevant evaluations, assessments or reports drawn up by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing. 6.   Where the identified specific and serious threat from the third country concerned amounts to a significant strategic deficiency, Article 29(4) shall apply and the delegated act referred to in paragraph 1 of this Article shall identify specific countermeasures as referred to in Article 29(5). 7.   Where the identified specific and serious threat from the third country concerned amounts to a compliance weakness, the delegated act referred to in paragraph 1 shall identify specific enhanced due diligence measures among those listed in Article 34(4), that obliged entities shall apply to mitigate risks related to business relationships or occasional transactions involving natural or legal persons from that third country. 8.   The Commission shall review the delegated acts referred to in paragraph 1 on a regular basis to ensure that the countermeasures referred to in paragraph 6 and enhanced due diligence measures referred to in paragraph 7 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks. 9.   The Commission may adopt, by means of an implementing act, the methodology for the identification of third countries pursuant to this Article. That implementing act shall set out, in particular: (a) how the criteria referred to in paragraph 2 are assessed; (b) the process for interaction with the third country under assessment; (c) the process for involvement of Member States and AMLA in the identification of third countries posing a specific and serious threat to the Union’s financial system. The implementing act referred to in the first subparagraph of this paragraph shall be adopted in accordance with the examination procedure referred to in Article 86(2).

Guidelines on money laundering and terrorist financing risks, trends and methods

Article 32

1.   By 10 July 2027, AMLA shall issue guidelines defining the money laundering and terrorist financing risks, trends and methods involving any geographical area outside the Union to which obliged entities are exposed. AMLA shall take into account, in particular, the risk factors listed in Annex III. Where situations of higher risk are identified, the guidelines shall include enhanced due diligence measures that obliged entities shall consider applying to mitigate such risks. 2.   AMLA shall review the guidelines referred to in paragraph 1 at least every 2 years. 3.   When issuing and reviewing the guidelines referred to in paragraph 1, AMLA shall take into account evaluations, assessments or reports of Union institutions, bodies, offices and agencies, international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing.

SECTION 3 — Simplified due diligence

Simplified due diligence measures

Article 33

1.   Where, taking into account the risk factors set out in Annexes II and III, the business relationship or transaction present a low degree of risk, obliged entities may apply the following simplified due diligence measures: (a) verifying the identity of the customer and the beneficial owner after the establishment of the business relationship, provided that the specific lower risk identified justified such postponement, but in any case no later than 60 days of the relationship being established; (b) reducing the frequency of customer identification updates; (c) reducing the amount of information collected to identify the purpose and intended nature of the business relationship or occasional transaction or inferring it from the type of transactions or business relationship established; (d) reducing the frequency or degree of scrutiny of transactions carried out by the customer; (e) applying any other relevant simplified due diligence measure identified by AMLA pursuant to Article 28. The measures referred to in the first subparagraph shall be proportionate to the nature and size of the business and to the specific elements of lower risk identified. However, obliged entities shall carry out sufficient monitoring of the transactions and business relationship to enable the detection of unusual or suspicious transactions. 2.   Obliged entities shall ensure that the internal procedures established pursuant to Article 9 contain the specific measures of simplified verification that shall be taken in relation to the different types of customers that present a lower risk. Obliged entities shall document decisions to take into account additional factors of lower risk. 3.   For the purpose of applying simplified due diligence measures referred to in paragraph 1, point (a), obliged entities shall adopt risk management procedures with respect to the conditions under which they can provide services or perform transactions for a customer prior to the verification taking place, including by limiting the amount, number or types of transactions that can be performed or by monitoring transactions to ensure that they are in line with the expected norms for the business relationship at hand. 4.   Obliged entities shall verify on a regular basis that the conditions for the application of simplified due diligence measures continue to exist. The frequency of such verifications shall be commensurate with the nature and size of the business and the risks posed by the specific relationship. 5.   Obliged entities shall refrain from applying simplified due diligence measures in any of the following situations: (a) the obliged entities have doubts as to the veracity of the information provided by the customer or the beneficial owner at the stage of identification, or they detect inconsistencies regarding that information; (b) the factors indicating a lower risk are no longer present; (c) the monitoring of the customer’s transactions and the information collected in the context of the business relationship exclude a lower risk scenario; (d) there is a suspicion of money laundering or terrorist financing; (e) there is a suspicion that the customer, or the person acting on behalf of the customer, is attempting to circumvent or evade targeted financial sanctions.

SECTION 4 — Enhanced due diligence

Scope of application of enhanced due diligence measures

Article 34

1.   In the cases referred to in Articles 29, 30, 31 and 36 to 46, as well as in other cases of higher risk that are identified by obliged entities pursuant to Article 20(2), second subparagraph, obliged entities shall apply enhanced due diligence measures to manage and mitigate such risks appropriately. 2.   Obliged entities shall examine the origin and destination of funds involved in, and the purpose of, all transactions that fulfil at least one of the following conditions: (a) the transaction is of a complex nature; (b) the transaction is unusually large; (c) the transaction is conducted in an unusual pattern; (d) the transaction does not have an apparent economic or lawful purpose. 3.   With the exception of the cases covered by Section 2 of this Chapter, when assessing the risks of money laundering and terrorist financing posed by a business relationship or occasional transaction, obliged entities shall take into account at least the factors of potential higher risk set out in Annex III and the guidelines adopted by AMLA pursuant to Article 32, as well as any other indicators of higher risk such as notifications issued by the FIU and findings of the business-wide risk assessment under Article 10. 4.   With the exception of the cases covered by Section 2 of this Chapter, in cases of higher risk as referred to in paragraph 1 of this Article, obliged entities shall apply enhanced due diligence measures, proportionate to the higher risks identified, which may include the following measures: (a) obtaining additional information on the customer and the beneficial owners; (b) obtaining additional information on the intended nature of the business relationship; (c) obtaining additional information on the source of funds, and source of wealth of the customer and of the beneficial owners; (d) obtaining information on the reasons for the intended or performed transactions and their consistency with the business relationship; (e) obtaining the approval of senior management for establishing or continuing the business relationship; (f) conducting enhanced monitoring of the business relationship by increasing the number and timing of controls applied, and selecting patterns of transactions that need further examination; (g) requiring the first payment to be carried out through an account in the customer’s name with a credit institution subject to customer due diligence standards that are not less robust than those laid down in this Regulation. 5.   Where a business relationship that is identified as having a higher risk involves the handling of assets with a value of at least EUR 5 000 000, or the equivalent in national or foreign currency, through personalised services for a customer holding total assets with a value of at least EUR 50 000 000, or the equivalent in national or foreign currency, whether in financial, investable or real estate assets, or a combination thereof, excluding that customer’s private residence, credit institutions, financial institutions and trust or company service providers shall apply the following enhanced due diligence measures, in addition to any enhanced due diligence measure applied pursuant to paragraph 4: (a) specific measures including procedures to mitigate risks associated with personalised services and products offered to that customer; (b) obtaining additional information on that customer’s source of funds; (c) preventing and managing conflicts of interest between the customer and senior management or employees of the obliged entity that undertake tasks related to that obliged entity’s compliance in relation to that customer. By 10 July 2027, AMLA shall issue guidelines on the measures to be taken by credit institutions, financial institutions and trust or company service providers to establish whether a customer holds total assets with a value of at least EUR 50 000 000, or the equivalent in national or foreign currency, in financial, investable or real estate assets and how to determine that value. 6.   With the exception of the cases covered by Section 2 of this Chapter, where Member States identify cases of higher risks pursuant to Article 8 of Directive (EU) 2024/1640, including as a result of sectoral risk assessments carried out by the Member States, they may require obliged entities to apply enhanced due diligence measures and, where appropriate, specify those measures. Member States shall notify to the Commission and AMLA their decisions imposing enhanced due diligence requirements upon obliged entities established in their territory within 1 month of their adoption, accompanied by a justification of the money laundering and terrorist financing risks underpinning such decision. Where the risks identified by Member States pursuant to the first subparagraph are likely to stem from outside the Union and may affect the Union’s financial system, AMLA shall, upon a request from the Commission or on its own initiative, consider updating the guidelines adopted pursuant to Article 32. 7.   The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation where it identifies additional cases of higher risk as referred to in paragraph 1 of this Article that affect the Union as a whole and enhanced due diligence measures that obliged entities are to apply in those cases, taking into account the notifications by Member States pursuant to paragraph 6, first subparagraph, of this Article. 8.   Enhanced due diligence measures shall not be invoked automatically with respect to branches or subsidiaries of obliged entities established in the Union which are located in third countries referred to in Articles 29, 30 and 31 where those branches or subsidiaries fully comply with the group-wide policies, procedures and controls in accordance with Article 17.

Countermeasures to mitigate money laundering and terrorist financing threats from outside the Union

Article 35

For the purposes of Articles 29 and 31, the Commission may choose from among the following countermeasures: (a) countermeasures that obliged entities are to apply to persons and legal entities involving high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in: (i) the application of additional elements of enhanced due diligence; (ii) the introduction of enhanced relevant reporting mechanisms or systematic reporting of financial transactions; (iii) the limitation of business relationships or transactions with natural persons or legal entities from those third countries; (b) countermeasures that Member States are to apply with regard to high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in: (i) refusing the establishment of subsidiaries or branches or representative offices of obliged entities from the country concerned, or otherwise taking into account the fact that the relevant obliged entity is from a third country that does not have adequate AML/CFT regimes; (ii) prohibiting obliged entities from establishing branches or representative offices in the third country concerned, or otherwise taking into account the fact that the relevant branch or representative office would be in a third country that does not have adequate AML/CFT regimes; (iii) requiring increased supervisory examination or increased external audit requirements for branches and subsidiaries of obliged entities located in the third country concerned; (iv) requiring increased external audit requirements for financial groups with respect to any of their branches and subsidiaries located in the third country concerned; (v) requiring credit institutions and financial institutions to review and amend, or if necessary terminate, correspondent relationships with respondent institutions in the third country concerned.

Specific enhanced due diligence measures for cross-border correspondent relationships

Article 36

With respect to cross-border correspondent relationships, including relationships established for securities transactions or fund transfers, involving the execution of payments with a third-country respondent institution, in addition to the customer due diligence measures laid down in Article 20, credit institutions and financial institutions shall, when entering into a business relationship, be required to: (a) gather sufficient information about the respondent institution to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the institution and the quality of supervision; (b) assess the respondent institution’s AML/CFT controls; (c) obtain approval from senior management before establishing new correspondent relationships; (d) document the respective responsibilities of each institution; (e) with respect to payable-through accounts, be satisfied that the respondent institution has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent institution, and that it is able to provide relevant customer due diligence data to the correspondent institution, upon request. Where credit institutions and financial institutions decide to terminate cross-border correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision.

Specific enhanced due diligence measures for cross-border correspondent relationships for crypto-asset service providers

Article 37

1.   By way of derogation from Article 36, with respect to cross-border correspondent relationships involving the execution of crypto-asset services, with a respondent entity not established in the Union and providing similar services, including transfers of crypto-assets, crypto-asset service providers shall, in addition to the customer due diligence measures laid down in Article 20, when entering into a business relationship, be required to: (a) determine if the respondent entity is licensed or registered; (b) gather sufficient information about the respondent entity to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the entity and the quality of supervision; (c) assess the respondent entity’s AML/CFT controls; (d) obtain approval from senior management before establishing the new correspondent relationship; (e) document the respective responsibilities of each party to the correspondent relationship; (f) with respect to payable-through crypto-asset accounts, be satisfied that the respondent entity has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent entity, and that it is able to provide relevant customer due diligence data to the correspondent entity, upon request. Where crypto-asset service providers decide to terminate correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision. Crypto-asset service providers shall update the due diligence information for the correspondent relationship on a regular basis or when new risks emerge in relation to the respondent entity. 2.   Crypto-asset service providers shall take into account the information collected pursuant to paragraph 1 in order to determine, on a risk sensitive basis, the appropriate measures to be taken to mitigate the risks associated with the respondent entity. 3.   By 10 July 2027, AMLA shall issue guidelines to specify the criteria and elements that crypto-asset service providers shall take into account for conducting the assessment referred to in paragraph 1 and the risk mitigating measures referred to in paragraph 2, including the minimum action to be taken by crypto-asset service providers upon identification that the respondent entity is not registered or licensed.

Specific measures for individual third-country respondent institutions

Article 38

1.   Credit institutions and financial institutions shall apply the measures laid down in paragraph 6 of this Article in relation to third-country respondent institutions with which they have a correspondent relationship pursuant to Articles 36 or 37 and in respect of which AMLA issues a recommendation pursuant to paragraph 2 of this Article. 2.   AMLA shall issue a recommendation addressed to credit institutions and financial institutions where there are concerns that respondent institutions in third countries fall into any of the following situations: (a) they are in serious, repeated or systematic breach of AML/CFT requirements; (b) they have weaknesses in their internal policies, procedures and controls that are likely to result in serious, repeated or systematic breaches of AML/CFT requirements; (c) they have in place internal policies, procedures and controls that are not commensurate with the risks of money laundering, its predicate offences and terrorist financing to which the third-country respondent institution is exposed. 3.   The recommendation referred to in paragraph 2 shall be issued where all of the following conditions are met: (a) on the basis of the information available in the context of its supervisory activities, a financial supervisor, including AMLA when performing its supervisory activities, deems that a third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship; (b) following an assessment of the information available to the financial supervisor referred to in point (a) of this paragraph, there is an agreement among financial supervisors in the Union that the third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship. 4.   Prior to issuing the recommendation referred to in paragraph 2, AMLA shall consult the third-country supervisor in charge of the respondent institution and request that it provides its own as well as the respondent institution’s views on the adequacy of AML/CFT policies, procedures and controls as well as of the customer due diligence measures the respondent institution has in place to mitigate risks of money laundering, its predicate offences and terrorist financing and remedial measures to be put in place. Where no reply is provided within 2 months or where the reply provided does not indicate that the third-country respondent institution can implement satisfactory AML/CFT policies, procedures and controls as well as apply adequate customer due diligence measures to mitigate the risks to which it is exposed that may affect the correspondent relationship, AMLA shall proceed with the recommendation. 5.   AMLA shall withdraw the recommendation referred to in paragraph 2 as soon as it considers that a third-country respondent institution on which it adopted that recommendation no longer fulfils the conditions laid down in paragraph 3. 6.   In relation to third-country respondent institutions referred to in paragraph 1, credit institutions and financial institutions shall: (a) abstain from entering into new business relationships with the third-country respondent institution unless they conclude, on the basis of the information collected under Article 36 or 37, that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship; (b) for ongoing business relationships with the third-country respondent institution: (i) review and update the information on the respondent institution pursuant to Articles 36 or 37; (ii) terminate the business relationship unless they conclude, on the basis of the information collected under point (i), that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship; (c) inform the respondent institution of the conclusions they have drawn in relation to the risks posed by the correspondent relationship following the recommendation by AMLA and the measures taken pursuant to points (a) or (b). Where AMLA has withdrawn a recommendation pursuant to paragraph 5, credit institutions and financial institutions shall review their assessment as to whether the third-country respondent institutions fulfil any of the conditions laid down in paragraph 3. 7.   Credit institutions and financial institutions shall document any decision taken pursuant to this Article.

Prohibition of correspondent relationships with shell institutions

Article 39

1.   Credit institutions and financial institutions shall not enter into, or continue, a correspondent relationship with a shell institution. Credit institutions and financial institutions shall take appropriate measures to ensure that they do not engage in or continue correspondent relationships with a credit institution or financial institution that is known to allow its accounts to be used by a shell institution. 2.   In addition to the requirement laid down in paragraph 1, crypto-asset service providers shall ensure that their accounts are not used by shell institutions to provide crypto-asset services. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls to detect any attempt to use their accounts for the provision of unregulated crypto-asset services.

Measures to mitigate risks in relation to transactions with a self-hosted address

Article 40

1.   Crypto-asset service providers shall identify and assess the risk of money laundering and financing of terrorism associated with transfers of crypto-assets directed to or originating from a self-hosted address. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls. Crypto-asset service providers shall apply mitigating measures commensurate with the risks identified. Those mitigating measures shall include one or more of the following: (a) taking risk-based measures to identify, and verify the identity of, the originator or beneficiary of a transfer made from or to a self-hosted address or beneficial owner of such originator or beneficiary, including through reliance on third parties; (b) requiring additional information on the origin and destination of the crypto-assets; (c) conducting enhanced ongoing monitoring of transactions with a self-hosted address; (d) any other measure to mitigate and manage the risks of money laundering and financing of terrorism as well as the risk of non-implementation and evasion of targeted financial sanctions. 2.   By 10 July 2027, AMLA shall issue guidelines to specify the mitigating measures referred to in paragraph 1, including: (a) the criteria and means for identification and verification of the identity of the originator or beneficiary of a transfer made from or to a self-hosted address, including through reliance on third parties, taking into account the latest technological developments; (b) criteria and means for the verification of whether or not the self-hosted address is owned or controlled by a customer.

Specific provisions regarding applicants for residence by investment schemes

Article 41

In addition to the customer due diligence measures laid down in Article 20, with respect to customers who are third-country nationals who are in the process of applying for residence rights in a Member State in exchange for any kind of investment, including transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity contributing to the public good and contributions to the state budget, obliged entities shall, as a minimum, apply enhanced due diligence measures set out in Article 34(4), points (a), (c), (e) and (f).

Specific provisions regarding politically exposed persons

Article 42

1.   In addition to the customer due diligence measures laid down in Article 20, obliged entities shall apply the following measures with respect to occasional transactions or business relationships with politically exposed persons: (a) obtain senior management approval for carrying out occasional transactions or for establishing or continuing business relationships with politically exposed persons; (b) take adequate measures to establish the source of wealth and source of funds that are involved in business relationships or occasional transactions with politically exposed persons; (c) conduct enhanced, ongoing monitoring of those business relationships. 2.   By 10 July 2027, AMLA shall issue guidelines on the following matters: (a) the criteria for the identification of persons known to be close associates; (b) the level of risk associated with a particular category of politically exposed person, family member or person known to be a close associate, including guidance on how such risks are to be assessed where the person is no longer entrusted with a prominent public function for the purposes of Article 45.

List of prominent public functions

Article 43

1.   Each Member State shall issue and keep up-to-date a list indicating the exact functions which, in accordance with its national laws, regulations and administrative provisions, qualify as prominent public functions for the purposes of Article 2(1), point (34). Member States shall request each international organisation accredited on their territories to issue and keep up-to-date a list of prominent public functions at that international organisation for the purposes of Article 2(1), point (34). Those lists shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Member State level. Member States shall notify those lists, as well as any change made to them, to the Commission and to AMLA. 2.   The Commission may set out, by means of an implementing act, the format for the establishment and communication of the Member States’ lists of prominent public functions pursuant to paragraph 1. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2). 3.   The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement Article 2(1), point (34), where the lists notified by Member States pursuant to paragraph 1 identify common additional categories of prominent public functions and those categories of prominent public functions are of relevance for the Union as a whole. When drawing up delegated acts pursuant to the first subparagraph, the Commission shall consult AMLA. 4.   The Commission shall draw up and keep up-to-date the list of the exact functions which qualify as prominent public functions at the level of the Union. That list shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Union level. 5.   The Commission shall assemble, based on the lists provided for in paragraphs 1 and 4 of this Article, a single list of all prominent public functions for the purposes of Article 2(1), point (34). The Commission shall publish that single list in the Official Journal of the European Union. AMLA shall make that list publicly available on its website.

Politically exposed persons who are beneficiaries of insurance policies

Article 44

Obliged entities shall take reasonable measures to determine whether the beneficiaries of a life or other investment-related insurance policy or, where relevant, the beneficial owner of the beneficiary are politically exposed persons. Those measures shall be taken no later than at the time of the payout or at the time of the assignment, in whole or in part, of the policy. Where there are higher risks identified, in addition to applying the customer due diligence measures laid down in Article 20, obliged entities shall: (a) inform senior management before payout of policy proceeds; (b) conduct enhanced scrutiny of the entire business relationship with the policyholder.

Measures for persons who cease to be politically exposed persons

Article 45

1.   Where a politically exposed person is no longer entrusted with a prominent public function by the Union, a Member State, third country or an international organisation, obliged entities shall take into account the continuing risk posed by that person, as a result of his or her former function, in their assessment of money laundering and terrorist financing risks in accordance with Article 20. 2.   Obliged entities shall apply one or more of the measures referred to in Article 34(4) to mitigate the risks posed by the politically exposed person until such time as the risks referred to in paragraph 1 of this Article no longer exist, but in any case for not less than 12 months following the time when the individual ceased to be entrusted with a prominent public function. 3.   The obligation referred to in paragraph 2 shall apply accordingly where an obliged entity carries out an occasional transaction or enters into a business relationship with a person who in the past was entrusted with a prominent public function by the Union, a Member State, third country or an international organisation.

Family members and persons known to be close associates of politically exposed persons

Article 46

The measures referred to in Articles 42, 44 and 45 shall also apply to family members or persons known to be close associates of politically exposed persons.

SECTION 5 — Specific customer due diligence provisions

Specifications for the life and other investment-related insurance sector

Article 47

For life or other investment-related insurance business, in addition to the customer due diligence measures required for the customer and the beneficial owner, obliged entities shall apply the following customer due diligence measures on the beneficiaries of life insurance and other investment-related insurance policies, as soon as the beneficiaries are identified or designated: (a) in the case of beneficiaries that are identified as specifically named persons or legal arrangements, recording the name of the person or arrangement; (b) in the case of beneficiaries that are designated by characteristics or by class or by other means, obtaining sufficient information concerning those beneficiaries so that it will be able to establish the identity of the beneficiary at the time of the payout. For the purposes of the first subparagraph, the verification of the identity of the beneficiaries and, where relevant, their beneficial owners shall take place at the time of the payout. In the case of assignment, in whole or in part, of the life or other investment-related insurance to a third party, obliged entities aware of the assignment shall identify the beneficial owner at the time of the assignment to the natural or legal person or legal arrangement receiving for its own benefit the value of the policy assigned.

SECTION 6 — Reliance on customer due diligence performed by other obliged entities

General provisions relating to reliance on other obliged entities

Article 48

1.   Obliged entities may rely on other obliged entities, whether located in a Member State or in a third country, to meet the customer due diligence requirements laid down in Article 20(1), points (a), (b) and (c), provided that: (a) the other obliged entities apply customer due diligence requirements and record-keeping requirements laid down in this Regulation, or equivalent when the other obliged entities reside or are established in a third country; (b) compliance with AML/CFT requirements by the other obliged entities is supervised in a manner consistent with Chapter IV of Directive (EU) 2024/1640. The ultimate responsibility for meeting the customer due diligence requirements shall remain with the obliged entity which relies on another obliged entity. 2.   When deciding to rely on other obliged entities located in third countries, obliged entities shall take into consideration the geographical risk factors listed in Annexes II and III and any relevant information or guidance provided by the Commission, or by AMLA or other competent authorities. 3.   In the case of obliged entities that are part of a group, compliance with the requirements of this Article and of Article 49 may be ensured through group-wide policies, procedures and controls provided that all the following conditions are met: (a) the obliged entity relies on information provided solely by an obliged entity that is part of the same group; (b) the group applies AML/CFT policies and procedures, customer due diligence measures and rules on record-keeping that are fully in compliance with this Regulation, or with equivalent rules in third countries; (c) the effective implementation of the requirements referred to in point (b) of this paragraph is supervised at group level by the supervisory authority of the home Member State in accordance with Chapter IV of Directive (EU) 2024/1640 or of the third country in accordance with the rules of that third country. 4.   Obliged entities shall not rely on obliged entities established in third countries identified pursuant to Section 2 of this Chapter. However, obliged entities established in the Union whose branches and subsidiaries are established in those third countries may rely on those branches and subsidiaries, where all the conditions laid down in paragraph 3, are met.

Process of reliance on another obliged entity

Article 49

1.   Obliged entities shall obtain from the obliged entity relied upon all the necessary information concerning the customer due diligence measures laid down in Article 20(1), points (a), (b) and (c), or the business being introduced. 2.   Obliged entities which rely on other obliged entities shall take all necessary steps to ensure that the obliged entity relied upon provides, upon request: (a) copies of the information collected to identify the customer; (b) all supporting documents or trustworthy sources of information that were used to verify the identity of the client, and, where relevant, of the customer’s beneficial owners or persons on whose behalf the customer acts, including data obtained through electronic identification means and relevant trust services as set out in Regulation (EU) No 910/2014; and (c) any information collected on the purpose and intended nature of the business relationship. 3.   The information referred to in paragraphs 1 and 2 shall be provided by the obliged entity relied upon without delay and in any case within 5 working days. 4.   The conditions for the transmission of the information and documents mentioned in paragraphs 1 and 2 shall be specified in a written agreement between the obliged entities. 5.   Where the obliged entity relies on an obliged entity that is part of its group, the written agreement may be replaced by an internal procedure established at group level, provided that the conditions laid down in Article 48(3) are met.

Guidelines on reliance on other obliged entities

Article 50

By 10 July 2027, AMLA shall issue guidelines addressed to obliged entities on: (a) the conditions which are acceptable for obliged entities to rely on information collected by another obliged entity, including in the case of remote customer due diligence; (b) the roles and responsibility of the obliged entities involved in a situation of a reliance on another obliged entity; (c) supervisory approaches to reliance on other obliged entities.

Back to Regulation (EU) 2024/1624 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next