What this chapter covers
Every regulated firm in Cyprus must understand its own exposure to money laundering and terrorist financing before it can decide how hard to look at each customer. That is the risk-based approach: identify the risks, assess them, and spend the most effort where the risk is highest.
The rules come from Law 188(I)/2007, CySEC's AML Directive and the EU's risk factor guidelines, now overseen by the EU's new AML authority. They use four groups of risk factors, a small number of risk levels and a few firm rules about what can and cannot change a rating.
Read the notes in order the first time. The first explains the approach and how risks are identified, the next three cover the risk factors, and the last two show how risks are rated, reviewed and recorded.
The 6 topics
Each note starts with a short answer and a table of the facts to remember.
The risk-based approach
Risk factors
- What are the main ML/TF risk factors, and what makes a customer higher risk?The four categories of risk factors, and the activity, reputation and behaviour questions for every customer.4 categories6 min
- How do firms assess country and geographical risk?Three geographical links for each customer and beneficial owner, and what makes a country higher risk.3 links6 min
- How do products, services and delivery channels affect ML/TF risk?Transparency, complexity and value, plus the checks for remote customers and introducers.3 tests6 min
Rating and review
- How are ML/TF risks rated and weighted?Low, normal and high risk, what each triggers, and the rules no weighting may break.3 levels6 min
- How is a risk assessment kept up to date, and how long must AML records be kept?Keeping the assessment current, spotting new risks, and the 5-year record-keeping rules.5 years+5 years5 min
The numbers to know
Every figure in this chapter, with the note that explains it.
| Figure | What it is | Note |
|---|---|---|
| 4 | Categories of ML/TF risk factors: customer, geography, products-services-transactions, delivery channels | Topic 2: What are the main ML/TF risk factors, and what makes a customer higher risk? |
| 3 | Geographical links checked for the customer and the beneficial owner | Topic 3: How do firms assess country and geographical risk? |
| 1 January 2026 | The EU AML Authority (AMLA) took over the EBA's AML/CFT role; the EBA guidelines stay in force until replaced | Topic 1: What is the risk-based approach to AML, and how do firms identify their risks? |
| 3 levels | Usual risk categories: low, medium (normal) and high | Topic 5: How are ML/TF risks rated and weighted? |
| 5 years | Standard retention of CDD and transaction records after the relationship ends or the occasional transaction; personal data is then deleted | Topic 6: How is a risk assessment kept up to date, and how long must AML records be kept? |
| Up to 5 more years | Extra retention where reasonably justified for preventing, detecting or investigating ML/TF | Topic 6: How is a risk assessment kept up to date, and how long must AML records be kept? |