What are the Board's responsibilities for AML compliance?
What the Board of a CySEC-supervised firm must do on AML, what senior management approves, and the Board member designated to answer for the AML rules.
By the ExamPass CY editorial teamLast reviewed 6 min read
Topic 2 of 5 · all topics in this chapter
Short answer
The Board sets and records the firm's general AML policy principles, appoints the AML compliance officer, an alternate and, where needed, assistants, approves the risk management and procedures manual, makes sure the compliance team has resources and full access to information, sets up a quick internal reporting chain, and assesses and approves the compliance officer's Annual Report, acting on any weaknesses. Senior management approves the ML/TF policies, procedures and controls and keeps them under review. One Board member, executive or non-executive, is designated as responsible for implementing the AML rules.
Board duties at a glance
| Duty | What it involves |
|---|---|
| Policy principles | Determines, records and approves the general principles and passes them to the compliance officer |
| Appointments | Appoints the compliance officer, an alternate to cover absences and, where needed, assistants, and sets their duties in the manual |
| Procedures manual | Approves it and makes sure it reaches the staff who handle customers' transactions |
| Support | Complete and timely access to data, sufficient staff and technology, a clear and quick reporting chain, and all staff told who the compliance officer, the alternate and the assistants are |
| Annual Report | Assesses and approves the compliance officer's Annual Report and decides how to fix the weaknesses it identifies |
| Senior management (Article 58C) | Approves the ML/TF policies, procedures and controls, monitors them and reinforces them where appropriate |
| Designated Board member (Article 58D and paragraph 5A) | Where there is a Board, one member is responsible for implementing the Law and the rules issued under it, including EU acts; CySEC allows an executive or a non-executive member |
Source: Law 188(I)/2007, Articles 58C and 58D, as amended up to 2026; CySEC AML Directive, paragraphs 5, 5A, 6, 8 and 10; CySEC Circulars C315 and C535.
What must the Board do?
A firm's AML compliance starts and ends with its Board. CySEC's AML Directive gives the Board of every CySEC-supervised firm a set of duties. It determines, records and approves the firm's general policy principles on preventing money laundering and terrorist financing, and communicates them to the compliance officer, who turns them into detailed procedures.
The Board appoints the compliance officer, an alternate compliance officer to stand in during absences (the Directive requires one) and, where necessary, assistants, and defines their duties in the firm's risk management and procedures manual. It approves that manual and makes sure it reaches every employee who manages, monitors or controls customers' transactions. It must also make sure that the requirements of the Law, in particular its Article 58, and of the Directive are actually applied, with systems and controls that are adequate and work in practice.
Terms used in this note
- Board of Directors
- The firm's governing body, which sets its AML policy principles, makes the key appointments and oversees how the rules are applied.
- Senior management
- Officers or employees who know the firm's ML/TF risk exposure well and are senior enough to take decisions that change it; they need not sit on the Board.
- Designated Board member
- The director, executive or non-executive, made responsible under Article 58D for implementing the AML/CFT Law and the supervisor's rules.
How does the Board support the compliance function?
The compliance officer, the alternate, the assistants and anyone else working on AML procedures must be able to see, fully and promptly, all customer identification data, transaction documents and other relevant records. The Board must also give the compliance officer and the alternate enough resources, including competent staff and technology.
Staff need to know where to go. The Board makes sure every employee knows who the compliance officer, the alternate and the assistants are, and sets up a clear and quick reporting chain so that information about suspicious transactions reaches the compliance officer without delay, directly or through the assistants. The chain is written into the procedures manual.
Each year the Board assesses and approves the compliance officer's Annual Report and takes whatever action is needed to fix the weaknesses and deficiencies it reveals. It does the same with the internal auditor's findings. CySEC also expects the Board and senior management to approve the compliance officer's annual training programme, to receive information on how it is carried out, and to be adequately trained themselves. The Board oversees; the daily work, the evaluation of internal reports, reporting to MOKAS and acting as its first point of contact stay with the compliance officer.
What do senior management and the designated Board member do?
Under Article 58C of the Law, senior management approves the policies, procedures and controls the firm applies against money laundering and terrorist financing, and then monitors the measures and, where appropriate, reinforces them. Approval is not a one-off signature.
Under Article 58D, a firm that has a Board designates one Board member who is responsible for implementing the Law and the directives, circulars and regulations issued under it, including relevant EU acts. CySEC's Directive adds that this person may be an executive or a non-executive director and, depending on the nature and size of the firm, may take on other duties as well; the Board records how the arrangement works in the procedures manual.
CySEC has also asked the firms it supervises to follow the EBA's 2022 guidelines on AML/CFT compliance management, which describe this Board member as the person ultimately responsible for AML/CFT at management body level and set out the tasks of the compliance officer and, in groups, of a group compliance officer.
How to think about it
Sort each task by level. The Board sets principles, appoints, approves (the manual and the Annual Report), resources and fixes weaknesses. Senior management approves the ML/TF policies, procedures and controls, monitors them and reinforces them where appropriate. Where there is a Board, one designated member answers for implementation. The compliance officer does the daily work and deals with MOKAS. If an option gives the Board a daily or operational task, or has it file reports with MOKAS, it is wrong.
Common mistakes
Giving the Board day-to-day compliance work. The Board oversees and approves; daily oversight, evaluating internal reports, reporting to MOKAS and acting as its first point of contact belong to the compliance officer.
Saying the designated Board member must be an executive director. The Directive allows an executive or a non-executive member, who may also hold other duties.
Having the compliance officer approve the manual or the Annual Report. The compliance officer prepares both; the Board approves them.
Treating approval of policies as a one-off. Article 58C also requires senior management to monitor the measures and reinforce them where needed.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), consolidated Greek text on CyLaw (amendments up to Law 25(I)/2026) (opens in a new tab)
Article 58C: approval by senior management · Article 58D: designated Board member
- CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing, as amended (opens in a new tab)
Paragraph 5: Board of directors' responsibilities · Paragraph 5A: designated Board member · Paragraph 6: Board's decision on internal audit findings · Paragraph 8(2): alternate compliance officer · Paragraph 10: Annual Report
- CySEC Circular C535: EBA Guidelines on compliance management and the role of the AML/CFT compliance officer (EBA/GL/2022/05) (opens in a new tab)
- CySEC Circular C315 (7 May 2019): targeted AML/CFT training for staff (opens in a new tab)
Paragraphs 11 to 17: training content, timing and effectiveness · Paragraph 19: Board and senior management
Practise this topic
Test what you just read
The Chapter 4 pack has 49 exam-style questions, 8 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 12 free Chapter 4 flashcards →