CySEC AML · Chapter 3 · Topic 2 of 7

Who supervises firms for AML in Cyprus, and what fines can CySEC impose?

The supervisory authorities named in Article 59, what CySEC supervises and what it does not, and the administrative measures and fines available for AML breaches.

By the ExamPass CY editorial teamLast reviewed 5 min read

Short answer

Article 59 of Law 188(I)/2007 names the AML supervisory authorities. CySEC supervises investment firms, investment funds and fund managers, administrative service providers and crypto-asset service providers; the Central Bank of Cyprus supervises banks, e-money and payment institutions. For breaches, a supervisor can order remedial action and impose fines of up to €1,000,000, up to twice the benefit where the benefit exceeds that, and up to €1,000 a day while a breach continues. Credit and financial institutions, including investment firms, funds and crypto firms, face up to €5,000,000 or 10% of turnover.

Supervision and fines at a glance

CySEC supervises (Article 59(1)(b))Cyprus investment firms, investment funds and their managers, administrative service providers it licenses, crypto-asset service providers and their Cyprus branches, and other persons assigned to it by law
Central Bank of Cyprus supervisesCredit institutions, e-money institutions and payment institutions
Standard maximum fine€1,000,000, after giving the firm a hearing
Benefit larger than €1,000,000Up to twice the benefit gained from the breach
Continuing breachUp to €1,000 for each day it continues
Credit or financial institution (including investment firms, investment funds and crypto-asset service providers)Legal person: up to €5,000,000 or 10% of total annual turnover; natural person: up to €5,000,000
Other measuresRemedial orders, licence amendment, suspension or withdrawal, temporary management bans, public statements

Source: Law 188(I)/2007, Article 59, as amended up to 2026.

Which authorities supervise obliged entities?

Each type of obliged entity has an AML supervisor. The Central Bank of Cyprus covers credit institutions, e-money institutions and payment institutions. CySEC covers Cyprus investment firms, investment funds that market their own units and the firms that manage them, the administrative service providers it licenses, crypto-asset service providers, and the Cyprus branches of these, as well as other persons assigned to it by law. Other authorities cover insurance, accountants (ICPAC), lawyers (the Cyprus Bar Association), estate agents, betting, casinos and dealers in works of art.

So a question about a bank's AML failings points to the Central Bank, not CySEC, and casinos or charities fall outside CySEC's remit. MOKAS, the financial intelligence unit, is not a supervisor at all.

Terms used in this note

Supervisory authority
The body named in Article 59 that monitors a category of obliged entities for compliance with AML/CFT rules and can impose measures and fines.
Administrative fine
A monetary penalty imposed by a supervisor, as opposed to a criminal fine imposed by a court.
Obliged entity
A firm or professional that must apply the AML/CFT Law, such as a bank, investment firm, fund manager, lawyer, accountant or crypto-asset service provider.

What does a supervisor do?

A supervisor issues directives to the firms it supervises, which are binding on them; CySEC's AML Directive is the main example. It monitors, evaluates and supervises compliance with the law and its directives, on site and off site.

When it supervises on a risk basis, it must have a clear understanding of the money laundering and terrorist financing risks in Cyprus, have access on site and off site to the information it needs about firms' customers, products and services, and set the frequency and intensity of its inspections according to each firm's risk profile and the national risks. Supervisors must also stop people convicted of relevant crimes, or their associates, from holding management functions in or owning obliged entities.

What measures and fines can follow an AML breach?

If a supervised person fails to comply with the law or the supervisor's directives, the supervisor can require it to put things right within a set time. It can impose an administrative fine of up to €1,000,000 after giving the person a chance to be heard; up to twice the benefit gained where that benefit exceeds the €1,000,000 fine; and up to €1,000 for every day a breach continues. It can amend, suspend or withdraw a licence, temporarily ban people with management duties who are responsible, fine individuals whose fault, deliberate omission or negligence caused the breach, publish a statement naming the person and the breach, and order the conduct to stop. The same measures apply to repeated failures to send the required payer and payee information with transfers of funds or crypto-assets.

For credit institutions and financial institutions the ceilings are higher: a legal person can be fined up to €5,000,000 or 10% of its total annual turnover, or consolidated turnover for a group, and a natural person up to €5,000,000. Financial institutions in the law include Cyprus investment firms, investment funds that market their own units, crypto-asset service providers and life insurers, so this higher tier covers most CySEC-supervised firms, not only banks.

A company can be held liable for breaches committed for its benefit by a person in a leading position with powers of representation, decision-making or control, and also where poor supervision by such a person made the breach possible. In setting a fine, the supervisor considers the gravity and duration of the breach, the degree of responsibility, the person's financial strength, the profit gained, harm to third parties, cooperation and past breaches. Decisions are published on the supervisor's website once notified, but publication can be postponed, made anonymous or, in some cases, dropped where naming the person would be disproportionate or would threaten market stability or an investigation.

How to think about it

First match the firm to its supervisor: investment and fund business, administrative services and crypto to CySEC; banks, e-money and payments to the Central Bank. Then match each fine to its trigger: €1 million as the general ceiling, twice the benefit when that exceeds €1 million, €1,000 a day while the breach goes on, and €5 million or 10% of turnover for credit and financial institutions, a group that includes investment firms, funds and crypto firms. Supervisors impose administrative measures; prison sentences come only from the criminal courts.

Common mistakes

  1. Naming CySEC as the AML supervisor of banks. Credit institutions are supervised by the Central Bank of Cyprus.

  2. Assuming the €5,000,000 tier is only for banks. It applies to credit and financial institutions, and financial institutions include investment firms, investment funds and crypto-asset service providers.

  3. Treating the daily fine as a one-off amount. Up to €1,000 can be imposed for each day the breach continues.

  4. Thinking supervisors can imprison people. Supervisory measures are administrative; criminal penalties are for the courts.

Practise this topic

Test what you just read

The Chapter 3 pack has 84 exam-style questions, 16 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 15 free Chapter 3 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error