CySEC AML · Chapter 4 · Topic 1 of 5

What makes a strong AML compliance culture?

Why compliance must come before profit, the four building blocks of an AML programme, and what the law expects of a firm's policies, controls and procedures.

By the ExamPass CY editorial teamLast reviewed 5 min read

Tested inAML · Ch 4

Short answer

A strong AML culture means that complying with the law always ranks above business targets and profit, and that preventing money laundering is everyone's job, not only the compliance officer's. It rests on four building blocks: risk-based policies, controls and procedures; a designated AML compliance officer who oversees compliance day to day; ongoing staff training; and an independent audit of how well it all works. Policies must be proportionate to the firm's size, nature and risks, approved by senior management and the Board, applied across every business line and reviewed regularly.

Compliance culture at a glance

PriorityCompliance with AML/CFT law comes before business priorities and profit; this is not left to the Board's discretion
Four building blocksRisk-based policies, controls and procedures · a designated AML compliance officer · ongoing training · independent audit
ScaleProportionate to the firm's nature and size (Article 58) and, under the risk-based approach, to the ML/TF risks it faces
ApprovalSenior management approves the ML/TF policies, procedures and controls, monitors them and reinforces them where appropriate (Article 58C); in CySEC-supervised firms the Board approves the policy principles, the customer acceptance policy and the procedures manual
ReachShared across all business lines and communicated to staff who handle customers' transactions
ReviewKept under regular review and updated when the law, the business or its risks change

Source: Law 188(I)/2007, Articles 58, 58A and 58C, as amended up to 2026; CySEC AML Directive, paragraphs 5, 7, 9(1) and 12.

Why must compliance come before profit?

A firm's controls are only as strong as the attitude behind them. If a sales target can override a due diligence check, or a profitable client is waved through despite an unexplained source of funds, the written procedures stop mattering. The rule is therefore absolute: meeting AML/CFT obligations takes precedence over commercial priorities and profit. The Board cannot decide otherwise, and nobody in the firm should feel that it can.

The culture has to be set from the top and shared by everyone. The Board and senior management show through their decisions that compliance matters, and every employee, from the front office to operations, should see spotting and reporting possible money laundering as part of the job rather than as the compliance department's problem.

Terms used in this note

Compliance culture
The shared attitude in a firm that meeting legal and regulatory obligations comes first, shown in how decisions are actually taken.
Risk management and procedures manual
The firm's written AML/CFT manual, prepared by the compliance officer and approved by the Board, setting out its policies, procedures, controls and responsibilities.
Risk appetite
The level and types of risk a firm is prepared to accept; risks outside it are excluded in the firm's policies.

What are the building blocks of an AML programme?

Four elements come up again and again. First, risk-based internal rules: the policies, controls and procedures that turn the law into daily practice. Second, a designated AML compliance officer who oversees the compliance function day to day. Third, an ongoing training programme so that staff know their duties and can recognise suspicious activity. Fourth, an independent audit function that tests, on a continuing basis, whether the policies and controls actually work.

Other duties, such as reporting suspicions to MOKAS or keeping records, are obligations the programme must deliver; they are not extra building blocks. The Law lists the areas the policies must cover: customer due diligence, record keeping, internal reporting and reporting to MOKAS, internal control and risk assessment, close examination of transactions particularly open to money laundering or terrorist financing, especially complex or unusually large ones and unusual patterns with no apparent economic or lawful purpose, informing and training staff, risk management, compliance management, and the recruitment of staff and assessment of their integrity.

What does the law expect of policies, controls and procedures?

They must be adequate and appropriate, and proportionate to the firm's nature and size, so that it can mitigate and manage its money laundering and terrorist financing risks effectively. Designing them starts with the legal framework and the firm's own risk assessment: the stronger the risk, the stronger the control. If the firm decides that some risks are beyond its appetite, for example certain types of customer it will not take on, that decision belongs in its policies, especially the customer acceptance policy, backed by controls that enforce it.

Senior management approves the policies, procedures and controls and then monitors them and, where needed, strengthens them. In CySEC-supervised firms the Board approves the risk management and procedures manual, which records the firm's AML procedures and is communicated to the staff who deal with customers' transactions. Policies are shared across all service lines so that the same standards apply everywhere, and they are reviewed and updated regularly rather than written once and left on a shelf.

How to think about it

When a question asks what a strong compliance culture needs, look for the four building blocks: risk-based policies and controls, a compliance officer, training and independent audit. Any option that lets profit, client value or the Board's preference outrank the law is wrong. For policies, remember three words: proportionate (to size, nature and risk), approved (by senior management, with the principles, customer acceptance policy and manual approved by the Board) and reviewed (regularly, not once).

Common mistakes

  1. Counting reporting to MOKAS as one of the building blocks. It is a legal duty the programme must deliver, not one of the four elements of the programme itself.

  2. Letting the Board rank profit above compliance. Compliance with AML/CFT law always takes precedence; this is not a matter for the Board's discretion.

  3. Choosing the cheapest or a borrowed set of controls. Controls must match the firm's own size, nature and risks, which a copied or minimal set will not do.

  4. Treating policies as a one-off exercise. They must be monitored, reinforced where needed and updated regularly.

Practise this topic

Test what you just read

The Chapter 4 pack has 49 exam-style questions, 7 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 12 free Chapter 4 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error