CySEC AML · Chapter 5 · Topic 4 of 6

How do products, services and delivery channels affect ML/TF risk?

The three tests for product, service and transaction risk, the sector examples that raise or lower it, and what firms must check when customers arrive remotely or through introducers.

By the ExamPass CY editorial teamLast reviewed 6 min read

Short answer

Product, service and transaction risk is judged on three tests: transparency (can the customer or beneficial owner stay anonymous?), complexity (how many parties, jurisdictions or layers?) and value or size (cash, size and speed). Delivery channel risk asks how the customer obtains the service: in person or non-face-to-face, directly or through an introducer, intermediary, group entity or tied agent. A firm relying on a third party must be satisfied that it applies CDD to EEA standards, is supervised, hands over identification data on request and is not based in a high-risk third country.

Product and channel risk at a glance

TransparencyHigher where the product allows anonymity: bearer shares, offshore shells, trusts, nominee shareholders, complex structures
ComplexityHigher with many parties or jurisdictions, unrelated third parties, or innovative products whose risk is not fully understood
Value or sizeHigher with cash intensity, high-value transactions and rapid high volumes; caps on values lower it
Funds: higher riskPrivate or single-investor funds, quick redemption at little cost, units traded without the fund being told
Funds: lower riskNo third-party payments; open to small investors only, with capped investments
Delivery channelNon-face-to-face relationships without safeguards such as electronic identification; introducers, intermediaries, group entities or tied agents
Relying on a third partyCDD and record keeping to EEA standards, supervised, identification data provided immediately on request, not established in a high-risk third country (narrow group exception)

Source: Law 188(I)/2007, Articles 58A and 67 and Annexes II and III, as amended up to 2026; EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02); FATF securities-sector guidance (2018).

How is product, service and transaction risk judged?

Part of every risk assessment is reviewing the products, services and transactions a firm offers, new and existing, to see how they could be misused for laundering or terrorist financing. Three questions do most of the work.

Transparency: how far does the product let the customer or beneficial owner stay anonymous, or transact with little oversight by the firm? Bearer shares, offshore shell companies, trusts, nominee shareholders and complex structures all reduce transparency. Complexity: does the transaction involve several parties or jurisdictions, or payments from unrelated or unknown third parties, and does the firm fully understand the risk of an innovative product? Value or size: is the product cash-intensive, does it encourage high-value transactions, are there caps on values or premiums, and can large volumes move quickly?

The law's indicative lists point the same way. Potentially higher-risk factors include private banking, products or transactions that may favour anonymity, payments from unknown or unassociated third parties, new products and delivery mechanisms, and transactions related to oil, arms, precious metals, tobacco, cultural artefacts, ivory and protected species. Lower-risk factors include life policies with low premiums, and pension insurance policies with no early surrender option that cannot be used as collateral.

Terms used in this note

Delivery channel
The way a customer obtains a product or service: in person or remotely, directly or through an introducer, intermediary or agent.
Tied agent
A person who promotes an investment firm's services on behalf of only that firm, under its full responsibility.
Omnibus account
An account held by an intermediary in which the assets of several underlying clients are pooled.

Which products raise or lower risk in investment services?

In wealth management, requests for large amounts of cash or precious metals, very high-value transactions, lending secured on assets abroad whose title is hard to confirm, trusts and private investment vehicles that obscure the beneficial owner, and arrangements spread across several countries or providers raise the risk. In investment firms, transactions that are unusually large for the customer's profile, non-standard settlement arrangements, mirror trades, products that make it hard to identify the customer, and third-party payments do the same.

For investment funds, a fund designed for a few individuals or family offices is riskier, as is one that allows quick redemption without significant cost, or whose units can change hands without the fund knowing. Subscriptions involving several jurisdictions or unexpected third-party payers add risk. A fund that bans third-party payments, or is open only to small investors with capped investments, is lower risk. The FATF's securities-sector guidance adds funding from unexpected third parties, penny or microcap stocks, bearer instruments and omnibus accounts that obscure underlying clients.

What makes a delivery channel risky?

Delivery channel risk is about how the customer obtains the product: how far the relationship is conducted without the customer being physically present, and whether an introducer or intermediary stands between the firm and the customer. It is not about who the customer is, so a politically exposed person is a customer factor, not a channel factor.

For a customer who is not physically present, the firm asks whether it verified identity remotely in a reliable way, for example through electronic identification with proper safeguards. For a customer introduced by another group entity, it asks how far it can rely on that introduction and whether the group entity applies CDD to EEA standards. For a third-party introducer, the firm must be satisfied that the third party applies CDD and keeps records to EEA standards, is supervised for compliance with comparable obligations, and will provide copies of identification and verification data immediately on request; a third party established in a high-risk third country cannot be relied on, except that the supervisor may allow reliance on branches and majority-owned subsidiaries of EU groups that fully apply group-wide policies. CySEC-supervised firms may rely on third parties only at the start of a relationship. For a tied agent, it asks whether the agent gathers enough information for the firm to know its customer and how involved the agent stays over time. Even when it relies on a third party, the firm remains responsible for CDD.

How to think about it

Put each product on three dials: how transparent, how complex, how big and fast. More anonymity, more parties and more value push the risk up; caps, restrictions and simplicity pull it down. For channels, ask only how the customer came to you and who stands in between. Then check what the firm has done to rely safely on that route: reliable remote identification, or an introducer working to EEA standards who hands over data on request.

Common mistakes

  1. Treating geography as a product factor. Where the money comes from or goes to is country risk; products are judged on transparency, complexity and value.

  2. Assuming a small investor fund is as risky as a private fund. A fund built for a few individuals or family offices is riskier than a capped fund for small investors.

  3. Calling PEP status a channel factor. Channel risk is about how the customer is reached; PEP status is about the customer.

  4. Relying on any introducer. The third party must apply CDD and keep records to EEA standards, be supervised, provide data immediately on request and, save a narrow group exception, not be established in a high-risk third country.

Practise this topic

Test what you just read

The Chapter 5 pack has 61 exam-style questions, 7 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 16 free Chapter 5 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error