CySEC AML · Chapter 4 · Topic 3 of 5

What does the AML compliance officer do?

Who can be the AML compliance officer, the roles of the alternate and the assistants, the officer's main duties, and the monthly and annual reports sent to CySEC.

By the ExamPass CY editorial teamLast reviewed 7 min read

Short answer

The AML compliance officer is a member of senior management, appointed by the Board, with the skills and authority to run the compliance function day to day. The officer designs the firm's AML procedures, prepares the customer acceptance policy and the procedures manual, monitors how they are applied, evaluates staff's internal reports and decides what to report to MOKAS, advises and trains staff, files the Monthly Prevention Statement and prepares the Annual Report. An alternate stands in during absences; assistants help where volume or geography requires. CySEC must be told of all appointments immediately.

The compliance officer at a glance

WhoA member of senior management with the ability, knowledge and expertise for the role, appointed by the Board
AlternateReplaces the compliance officer temporarily when absent and must meet the same conditions; can be outsourced only to a natural person
AssistantsAppointed where the volume or geographic spread of the business requires, to assist and pass on internal suspicion reports
Notifying CySECNames, positions and contact details of the officer, alternate and assistants sent immediately
Monthly Prevention StatementSubmitted electronically to CySEC within 15 days of each month-end: cash deposits accepted, internal suspicion reports and reports to MOKAS
Annual ReportSubmitted to the Board for approval by the end of February; then, with the Board minutes, to CySEC within 20 days of the meeting and by the end of March at the latest
Risk reviewAt least once a year, identifies, records and assesses the risks from existing and new customers and from new financial instruments and services, then updates the firm's systems

Source: Law 188(I)/2007, Article 69, as amended up to 2026; CySEC AML Directive, paragraphs 5(b), 8, 9, 10 and 11, as amended to R.A.D. 282/2024; CySEC Circulars C535 and C567.

Who is appointed, and who stands in?

Every obliged entity must appoint a compliance officer from its senior management with the skills, knowledge and expertise needed to receive and assess reports of suspected money laundering or terrorist financing. Belonging to senior management gives the officer the authority the role needs. In CySEC-supervised firms the Board makes the appointment and records the officer's duties in the procedures manual; the officer reports to senior management, and to the Board both through the Annual Report and directly whenever the officer considers it necessary. Under the EBA guidelines that CySEC applies, the designated Board member is the officer's main contact on the Board. The officer does not have to be a director.

The firm must also appoint an alternate compliance officer, who replaces the compliance officer temporarily during absences, performs the same duties and must meet the same conditions of appointment. The alternate's function may be outsourced, but only to a natural person, and the firm records the appointment procedure in its manual. Where the volume or geographic spread of the business makes it necessary, assistants are appointed, by district or otherwise, to support the compliance officer and pass internal suspicion reports to them. The firm tells CySEC immediately the names, positions and contact details of everyone appointed to these roles.

Terms used in this note

AML compliance officer
The member of senior management responsible for the firm's AML/CFT compliance function day to day and for reporting suspicions to MOKAS; also called the AMLCO.
Monthly Prevention Statement
The monthly return to CySEC on cash deposits accepted, internal suspicion reports and reports made to MOKAS.
Customer acceptance policy
The policy, drawn up by the compliance officer and approved by the Board, setting the criteria for accepting customers, those the firm will not accept, and the risk categories it uses.

What are the compliance officer's main duties?

The officer turns the Board's policy principles into practice: designing the firm's AML procedures and controls and allocating responsibilities between departments, including controls for online and telephone services, new products and new markets; drawing up the customer acceptance policy, with at least three risk categories, for the Board to approve; and preparing the risk management and procedures manual.

The officer then checks that everything is applied correctly, using tools such as on-site visits to departments, gives guidance to correct weaknesses and informs the Board where needed. At least once a year the officer identifies, records and assesses the risks posed by new and existing customers and by new financial instruments and services, updates the firm's systems accordingly, and keeps up-to-date lists of customers by risk category.

On suspicious activity, the officer receives staff's Internal Suspicion Reports, evaluates each one in an Internal Evaluation Report, reports to MOKAS through goAML where there is knowledge or reasonable suspicion, records full reasons when deciding not to report, and acts as MOKAS's first point of contact. The officer also approves in writing any reliance on a third party for customer due diligence after checking that it is an obliged entity, makes sure that branches and subsidiaries based outside the European Economic Area (EEA) have taken every measure needed to comply fully with the Directive's identification, due diligence and record-keeping requirements, advises staff, keeps their own knowledge current, identifies training needs and runs an annual training programme, answers all requests from MOKAS and CySEC, and keeps a registry of internal reports, evaluations and reports to MOKAS with the related statistics.

Which reports does the compliance officer send to CySEC?

Every month the officer prepares the Monthly Prevention Statement and submits it to CySEC within 15 days of the month-end. It covers the total cash deposits the firm accepted, the internal suspicion reports and the reports made to MOKAS, and gives the firm a regular chance to spot unusual cash activity early. Since May 2023 it has been submitted electronically through CySEC's Transaction Reporting System.

Every year the officer prepares the Annual Report, a significant tool for judging how well the firm complies. It is submitted to the Board for approval within two months of the year-end, so by the end of February. After approval it is sent to CySEC with the minutes of the Board meeting, which must record the corrective measures decided and their timetable, within 20 days of that meeting and no later than three months after the year-end. The report covers, among other things, changes made for new legal requirements, the officer's inspections and the weaknesses found, the numbers of internal reports and reports to MOKAS, cash deposits above €10,000, high-risk customers, monitoring systems, the training given and how its effectiveness was assessed, next year's training plan, and the staffing of the compliance function.

How to think about it

Keep three roles apart: the compliance officer runs the function; the alternate only steps in during absences; assistants exist because of volume or geography and feed reports to the officer. Then split the work: the officer designs, prepares, monitors, evaluates and reports, while the Board sets principles and approves. For deadlines, remember monthly within 15 days, and the Annual Report to the Board by the end of February and to CySEC by the end of March at the latest.

Common mistakes

  1. Saying the compliance officer must sit on the Board. The officer must belong to senior management, which does not require a Board seat.

  2. Confusing the alternate with the assistants. The alternate replaces the officer temporarily; assistants support the officer where volume or geography requires.

  3. Outsourcing the alternate to a company. The alternate's function can be outsourced only to an individual (a natural person), not to a firm.

  4. Having the officer approve the customer acceptance policy. The officer develops it; the Board considers and approves it.

  5. Filing the Annual Report quarterly or sending every internal report to MOKAS. The Annual Report is yearly, and only cases that give rise to knowledge or reasonable suspicion after evaluation are reported to MOKAS.

Practise this topic

Test what you just read

The Chapter 4 pack has 49 exam-style questions, 13 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 12 free Chapter 4 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error