CySEC Circular C805: MOKAS assessment of 2025 suspicious transaction reports
Cyprus Securities and Exchange Commission (CySEC)Circular C805Issued
By the ExamPass CY editorial teamPublished
- AML/CFT
Short answer
On 9 October 2026 CySEC issued Circular C805 to its regulated entities, including CIFs, fund managers, ASPs and CASPs. It passes on MOKAS's annual assessment of the quantity and quality of the suspicious transaction and activity reports (STRs/SARs) filed in 2025. MOKAS saw an overall improvement but still found weak reasons for suspicion, indicators chosen without explanation and SARs filed instead of STRs. The circular sets no new obligation and no deadline: CySEC encourages firms to study the report and keep improving their reports.
At a glance
- What it is
- CySEC Circular C805 of 9 October 2026, which sends regulated entities MOKAS's annual sectorial quantity and quality assessment of the STRs and SARs that obliged entities submitted in 2025.
- Key points
- MOKAS received 24,092 reports in 2025, against 3,870 in 2024, and 185 failed submission. Among the most common quality deficiencies: a weak reason for suspicion, with an insufficient narrative or unclear grounds.
- Who should read it
- AML compliance officers of CIFs, ASPs, UCITS management companies, AIFMs, CASPs, crowdfunding service providers and the other fund entities CySEC addressed.
- Cyprus investment firms (CIFs) and administrative service providers (ASPs)
- UCITS management companies, AIFMs, small AIFMs, companies whose sole purpose is managing AIFLNPs, and internally managed UCITS, AIFs and AIFLNPs
- Crypto-asset service providers (CASPs)
- Crowdfunding service providers
- What to do
- Read the report, check recent STRs and SARs against its list of common deficiencies and MOKAS's quality measures, and update reporting procedures and staff training.
- What happens next
- Since 1 May 2026 MOKAS has assessed submitted reports against predefined quality measures and gives obliged entities and supervisors quality feedback every four months.
What does Circular C805 say?
With Circular C805, dated 9 October 2026, CySEC informs its regulated entities that MOKAS, the Unit for Combating Money Laundering and Cyprus's financial intelligence unit, has published its Annual Sectorial Quantity & Quality Assessment of the STRs and SARs that obliged entities submitted in 2025. The report is attached to the circular. CySEC describes it as a valuable tool that helps obliged entities focus on high-risk areas sector by sector.
The circular lists the five risk indicators most often behind a report in 2025: transactions related to virtual assets, use of money mules, transactions between unrelated counterparties, internet fraud and cyber crime, and money laundering. It notes that, despite a commendable improvement in overall quality, MOKAS found deficiencies in some reports when it checked them against its Reporting Guidelines. CySEC encourages firms to study the report and to keep improving the reports they submit. There is no new obligation and no deadline.
What did MOKAS find in the 2025 reports?
MOKAS received 24,092 reports in 2025, against 3,870 in 2024. Of these, 21,857 came from obliged entities licensed in Cyprus that operate in other EU countries under the freedom to provide services; only 246 of them had a link with Cyprus, and the rest were passed to other EU/EEA financial intelligence units. CASPs alone filed 20,570 reports, of which 172 had a Cyprus link. Investment firms filed 980, up from 347 in 2024, and 26 of these had a link with Cyprus. Banks, payment institutions, gambling providers, lawyers, company service providers, accountants and other obliged entities established in Cyprus, which MOKAS calls traditional obliged entities, filed 1,183, 16% more than in 2024.
For investment firms, most reports rested on suspected fraud, including cyber fraud, activity with no economic rationale, unusual client behaviour, fake documents and insufficient documentation. CASPs most often cited suspected money mules. MOKAS made 572 disseminations of financial intelligence in 2025, against 205 in 2024, most of them to the Police. MOKAS also notes that it received no reports at all from real estate agents or from persons trading in works of art.
Why do reports fail or fall short?
In 2025, 185 reports failed submission. A report fails automatically if the reason for suspicion is not more than 400 and less than 4,000 characters long, if the supporting documents are not attached, or if identification details of a person or an entity are missing or incomplete. The reason for suspicion and missing attachments were the two most common causes, each in 26% of the failure reasons recorded (a report can fail for more than one reason).
Among the reports that went through, MOKAS's most common quality deficiencies were: a weak reason for suspicion, with an insufficient narrative, no supporting documentation or unclear grounds; risk indicators selected without a clear explanation in the reason for suspicion; SARs submitted instead of STRs; and, in rare cases, late submission. MOKAS says it raised these findings with the entities concerned case by case, with guidance on the corrective measures required.
What should AML compliance officers do now?
Read the report, in particular the pages for your sector and the quality measures in its appendix, which cover timeliness, report type, persons, entities, accounts, transactions, indicators, the reason for suspicion and attachments. Check a sample of your own recent reports against them: the reason for suspicion should explain clearly why the activity is suspicious, match the indicators selected and the transactions reported, and refer to the attachments.
Under its new framework, applied since 1 May 2026, MOKAS assesses submitted reports against these measures and gives statistical feedback at regular intervals, including quality feedback every four months. Entities that filed more than 4 reports in 2025 received individual yearly feedback. Act on any feedback your firm receives, and build the findings into reporting procedures and staff training. For the reporting steps themselves, see our study note on reporting to MOKAS.
In the official wording
“CySEC encourages the Regulated Entities to study the Report and continue their efforts of improving STRs/SARs submissions to the Unit.”
When does it apply?
Applies now
- A report to MOKAS fails submission if the reason for suspicion is not more than 400 and less than 4,000 characters long, or if attachments or identification details of the persons or entities involved are missing.
- Since 1 May 2026 MOKAS assesses the quality of submitted reports against predefined quality measures and gives obliged entities feedback at regular intervals.
- Circular C805 sets no new obligation and no deadline; CySEC encourages regulated entities to study the report and keep improving their reports.
Applies later
No later dates announced.
What to do
- Read MOKAS's 2025 assessment attached to Circular C805, including the pages for your sector.No fixed deadline
- Check a sample of recent STRs and SARs against the common deficiencies and the quality measures in the report's appendix.No fixed deadline
- Make sure each reason for suspicion explains why the activity is suspicious, matches the indicators and transactions reported and refers to the attachments.No fixed deadline
- Update reporting procedures and staff training, and act on any feedback MOKAS sends your firm.No fixed deadline
In the exam
Reporting suspicions to MOKAS, the role of the AML compliance officer and suspicious transaction red flags are core topics of the CySEC AML Compliance Officer exam and of the AML material in the Advanced and Basic exams.
Related study notes
Preparing for an exam?
Practise the topics behind this update
Exam-style questions with a hint before you answer and a full explanation after, chapter by chapter.
Sources
Summary prepared by the ExamPass CY editorial team; it is not the official text. Quotations are reproduced from the source for the purpose of reporting and review.