CySEC AML · Chapter 5 · Topic 6 of 6

How is a risk assessment kept up to date, and how long must AML records be kept?

Why risk management is a continuous process, the controls that help spot new risks, and the record-keeping rules: what to keep, for how long, and what happens at the end.

By the ExamPass CY editorial teamLast reviewed 5 min read

Short answer

A risk assessment is never finished: firms must keep it under review, check that their controls still work, and update individual customer ratings as monitoring brings new information. Records of CDD, transactions and correspondence must be kept for 5 years after the business relationship ends or the occasional transaction is carried out, and for up to 5 more years where that is reasonably justified for preventing, detecting or investigating money laundering or terrorist financing. Firms must be able to answer MOKAS or their supervisor quickly about any relationship in the previous 5 years.

Review and record keeping at a glance

Risk assessmentKept up to date and under continuous review; changes are recorded
Records to keepCDD documents and information, transaction evidence and records, relevant correspondence
Retention period5 years after the business relationship ends or after the occasional transaction
ExtensionUp to 5 more years where reasonably justified for preventing, detecting or investigating ML/TF
At the end of the periodPersonal data is deleted, unless another law provides otherwise
Ongoing investigations (CySEC firms)Relevant records kept until MOKAS confirms the case is closed
Enquiries from MOKAS or the supervisorSystems able to say quickly whether there was a relationship with a named person in the previous 5 years

Source: Law 188(I)/2007, Articles 58A, 61(1)(d), 68 and 68B, as amended up to 2026; CySEC AML Directive, paragraphs 15, 16, 31 and 32.

Why must a risk assessment be kept under review?

Risk management is a continuous process, not a one-off exercise. Customers' activities change, the firm's services and instruments change, and so do the methods criminals use. The firm must therefore keep checking whether its measures and procedures are working and still suit the level of risk it has assessed, and keep its business-wide and individual risk assessments current.

Information from monitoring feeds back into the assessment. When a customer's transactions or circumstances change, the firm considers whether the customer's risk rating and the CDD measures that go with it should change too, proportionately to the risk. Transaction monitoring itself, and the events that trigger a fresh review of customer data, are part of ongoing CDD.

Changes to risk assessments are documented, so that the firm can show its supervisor that its assessments and the resulting controls are adequate.

Terms used in this note

Dynamic risk management
Treating risk assessment as a continuous process that is updated as customers, products and criminal methods change.
Occasional transaction
A transaction carried out outside a business relationship, such as a one-off transfer.
MOKAS
The Unit for Combating Money Laundering, Cyprus's financial intelligence unit.

How does a firm spot new or emerging risks?

Firms need systems and controls that pick up emerging risks quickly, so that both the firm-wide assessment and individual customer ratings can be updated in good time. Useful controls include alerts on changes to sanctions lists, screening customers against a reputable database at regular intervals, reviewing media reports relevant to the firm's sectors and jurisdictions, following publications by the authorities, and attending relevant seminars and training.

Alerts and typology reports from MOKAS or the supervisor are a good example. They are new risk information: the firm builds them into its own controls and customer ratings, for example with targeted checks where the pattern fits, and reports when it has an actual suspicion.

What records must be kept, and for how long?

An obliged entity keeps a copy of the documents and information needed for CDD, including information obtained through electronic identification, the evidence and records needed to identify transactions, and relevant correspondence with customers and others it has a business relationship with. They are kept for 5 years after the business relationship ends or after the date of the occasional transaction.

At the end of that period personal data is deleted, unless another law provides otherwise. Where further retention is reasonably justified for preventing, detecting or investigating money laundering or terrorist financing, the records are kept for up to 5 more years. CySEC's Directive adds that records relevant to an ongoing investigation are kept until MOKAS confirms that the case has been closed.

Records may be held electronically, other than originals or certified copies kept on paper, provided they can be retrieved without undue delay. They must be made available to MOKAS and the supervisor promptly and without delay on request. Firms also need systems that let them answer, fully and quickly, enquiries from MOKAS or their supervisor about whether they have had a business relationship with specified persons during the previous 5 years, and what kind of relationship it was.

How to think about it

Anchor on five. Records: 5 years after the relationship ends or the occasional transaction, up to 5 more if justified, then deletion. Enquiries: the previous 5 years. For review questions, treat anything new, whether a sanctions list change, a media report or a MOKAS alert, as risk information that updates the firm's controls and ratings, not as an automatic report.

Common mistakes

  1. Counting the 5 years from account opening. The period runs from the end of the business relationship, or from the date of the occasional transaction.

  2. Keeping records forever just in case. Personal data is deleted at the end of the period unless an extension of up to 5 years is justified or another law requires otherwise.

  3. Treating the risk assessment as a one-off exercise. It must be kept up to date and reviewed as customers, products and risks change.

  4. Forgetting to record changes to risk assessments. Updates are documented so that the firm can show its supervisor that its assessments and controls are adequate.

Practise this topic

Test what you just read

The Chapter 5 pack has 61 exam-style questions, 11 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 16 free Chapter 5 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error