CySEC AML · Chapter 4 · Topic 5 of 5

What must employees do about AML, and how must they be trained?

Staff's personal duty to report even a slight suspicion, who designs the training programme, who must be trained and when, and how firms show that training works.

By the ExamPass CY editorial teamLast reviewed 6 min read

Short answer

Employees must report to the AML compliance officer, without delay, anything about the firm's transactions or business relationships that gives them even a slight suspicion of money laundering or terrorist financing, and they can be personally liable if they fail to report. Once they have reported internally, their legal duty is met. Firms must run a complete education and training programme, designed by the compliance officer and tailored to each role, with the Board trained too. Training is given before new staff start work and at least annually, and its effectiveness is tested.

Employees and training at a glance

Duty to reportAnything about the firm's transactions or business relationships giving even a slight suspicion, reported without delay to the compliance officer, not to MOKAS or the customer
LiabilityEmployees can be personally liable for failing to report information or a suspicion
Duty metBy reporting internally to the compliance officer (Article 26 of the Law)
ProgrammeDesigned by the compliance officer and tailored to roles and departments; the Board and senior management approve it and are trained too
TimingBefore new staff start work, then at least annually, with prompt updates on new risks and legal changes (CySEC Circular C315)
EffectivenessMeasured, for example with tests and minimum pass marks, and reported in the compliance officer's Annual Report

Source: Law 188(I)/2007, Articles 26 and 58, as amended up to 2026; CySEC AML Directive, paragraphs 9(1)(o), 10(4), 34 and 35; CySEC Circular C315, paragraphs 11 to 19.

What are employees' own AML obligations?

Employees are the firm's first line of defence and carry personal duties. They must cooperate with the compliance officer and report to them, without delay, anything that comes to their attention about transactions or business relationships where there is even a slight suspicion of money laundering or terrorist financing. It does not matter whether the information came up in the office or outside it, so long as it concerns the firm's customers or their transactions.

Employees can be held personally liable if they fail to report information or a suspicion. They report to the compliance officer, not straight to MOKAS, and never warn the customer. Under Article 26 of the Law, reporting internally in line with the firm's procedures is how an employee meets the legal duty to disclose; the compliance officer then decides what goes to MOKAS. Firms must also have procedures for recruiting staff and assessing their integrity.

Terms used in this note

Slight suspicion
The low threshold at which an employee must report internally; certainty or proof is not required.
Training programme
The firm's planned AML/CFT education for staff and the Board, designed by the compliance officer, tailored by role and reviewed each year.
Tick-the-box training
Training delivered only to show that it happened, without checking that staff understood it or can apply it.

Who designs the training, and what must it achieve?

The Law requires firms to keep employees informed about the firm's systems and procedures, the AML/CFT legislation, the supervisor's directives, the relevant EU rules and data protection requirements, and to train them regularly to recognise and handle suspicious transactions and activity. CySEC's Directive adds that every firm needs a complete education and training programme so that staff fully understand their legal obligations.

The compliance officer designs the programme's structure and content, identifies which departments and people need further training, prepares and applies an annual training plan, and assesses whether the training was adequate. The results, including how effectiveness was measured, go into the Annual Report. Good training uses real cases, including how a pattern was first spotted and what happened next, so that staff learn to recognise typologies that are otherwise hard to see.

Who should be trained, when and how?

Everyone, including senior management and the Board, but not in the same way. The programme is structured differently for new and existing staff and for each department, according to the services it provides and the risks it faces. The Board and senior management must be adequately trained too, and CySEC expects them to approve the compliance officer's annual training programme; a programme designed for the Board, focused on its responsibilities and on why the AML programme matters, is the recommended way to do this. The timing, frequency and content are set to fit each firm and change with new legal requirements, staff duties and wider developments.

CySEC's training circular requires firms to train staff before they start working for the firm and at least once a year after that, with prompt updates in between on new risks, typologies, legislation and internal procedures. Because the requirement is tied to working for the firm, training received at a previous employer does not replace it. Formats can include classroom seminars, online courses, conferences and forums, internal meetings on AML issues, and guidance notes or newsletters.

To avoid a tick-the-box exercise, firms measure whether training works, for example with tests after each course and minimum pass marks, and adapt the material and delivery to the results. A typical programme covers the basics of money laundering and terrorist financing, the legal framework and the firm's own procedures, offences and penalties including disciplinary action, customer due diligence and the economic profile, ongoing monitoring, recognising and reporting suspicion, handling difficult customers, record keeping and data protection, sanctions screening, and case studies.

How to think about it

For reporting, apply the lowest threshold: even a slight suspicion about the firm's customers or transactions, wherever it came up, goes to the compliance officer without delay, and staying silent can make the employee personally liable. For training, think tailored (by role, department and experience, with the Board included), timely (before starting, then at least yearly, plus updates) and tested (with measured results). The compliance officer designs it; the Board approves it and is trained too.

Common mistakes

  1. Waiting until a suspicion is certain. Even a slight suspicion must be reported to the compliance officer without delay.

  2. Ignoring information because it came up outside the office. If it concerns the firm's customers or transactions, it is reported to the compliance officer wherever the employee learned it.

  3. Reporting straight to MOKAS or telling the customer. Employees report internally to the compliance officer and must not alert the customer.

  4. Relying on training from a previous job. New staff are trained by the firm before they start work.

  5. Giving everyone the same course, or leaving out the Board. Training is tailored to roles and departments, and the Board and senior management must be trained too.

Practise this topic

Test what you just read

The Chapter 4 pack has 49 exam-style questions, 15 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 12 free Chapter 4 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error