Study notes · 6 topics · Free

AML Risk Assessment: CySEC AML study notes

How a regulated firm in Cyprus finds, rates and keeps track of its money laundering and terrorist financing risks, explained in 6 short notes.

By the ExamPass CY editorial teamLast reviewed About 35 minutes to read all 6

CySEC AML exam

Chapter 5 · about 6 of 40 questions (15%)

Exam weight and practice packs →

CySEC Advanced exam

Part of Chapter 7, AML & Terrorist Financing (risk-based approach)

Chapter 7 overview →

CySEC Basic exam

Part of Chapter 8, AML & Terrorist Financing

Chapter 8 overview →

What this chapter covers

Every regulated firm in Cyprus must understand its own exposure to money laundering and terrorist financing before it can decide how hard to look at each customer. That is the risk-based approach: identify the risks, assess them, and spend the most effort where the risk is highest.

The rules come from Law 188(I)/2007, CySEC's AML Directive and the EU's risk factor guidelines, now overseen by the EU's new AML authority. They use four groups of risk factors, a small number of risk levels and a few firm rules about what can and cannot change a rating.

Read the notes in order the first time. The first explains the approach and how risks are identified, the next three cover the risk factors, and the last two show how risks are rated, reviewed and recorded.

The 6 topics

Each note starts with a short answer and a table of the facts to remember.

The numbers to know

Every figure in this chapter, with the note that explains it.

FigureWhat it isNote
4Categories of ML/TF risk factors: customer, geography, products-services-transactions, delivery channelsTopic 2: What are the main ML/TF risk factors, and what makes a customer higher risk?
3Geographical links checked for the customer and the beneficial ownerTopic 3: How do firms assess country and geographical risk?
1 January 2026The EU AML Authority (AMLA) took over the EBA's AML/CFT role; the EBA guidelines stay in force until replacedTopic 1: What is the risk-based approach to AML, and how do firms identify their risks?
3 levelsUsual risk categories: low, medium (normal) and highTopic 5: How are ML/TF risks rated and weighted?
5 yearsStandard retention of CDD and transaction records after the relationship ends or the occasional transaction; personal data is then deletedTopic 6: How is a risk assessment kept up to date, and how long must AML records be kept?
Up to 5 more yearsExtra retention where reasonably justified for preventing, detecting or investigating ML/TFTopic 6: How is a risk assessment kept up to date, and how long must AML records be kept?