How is a risk assessment kept up to date, and how long must AML records be kept?
Why risk management is a continuous process, the controls that help spot new risks, and the record-keeping rules: what to keep, for how long, and what happens at the end.
By the ExamPass CY editorial teamLast reviewed 5 min read
Topic 6 of 6 · all topics in this chapter
Short answer
A risk assessment is never finished: firms must keep it under review, check that their controls still work, and update individual customer ratings as monitoring brings new information. Records of CDD, transactions and correspondence must be kept for 5 years after the business relationship ends or the occasional transaction is carried out, and for up to 5 more years where that is reasonably justified for preventing, detecting or investigating money laundering or terrorist financing. Firms must be able to answer MOKAS or their supervisor quickly about any relationship in the previous 5 years.
Review and record keeping at a glance
| Point | Rule |
|---|---|
| Risk assessment | Kept up to date and under continuous review; changes are recorded |
| Records to keep | CDD documents and information, transaction evidence and records, relevant correspondence |
| Retention period | 5 years after the business relationship ends or after the occasional transaction |
| Extension | Up to 5 more years where reasonably justified for preventing, detecting or investigating ML/TF |
| At the end of the period | Personal data is deleted, unless another law provides otherwise |
| Ongoing investigations (CySEC firms) | Relevant records kept until MOKAS confirms the case is closed |
| Enquiries from MOKAS or the supervisor | Systems able to say quickly whether there was a relationship with a named person in the previous 5 years |
Source: Law 188(I)/2007, Articles 58A, 61(1)(d), 68 and 68B, as amended up to 2026; CySEC AML Directive, paragraphs 15, 16, 31 and 32.
Why must a risk assessment be kept under review?
Risk management is a continuous process, not a one-off exercise. Customers' activities change, the firm's services and instruments change, and so do the methods criminals use. The firm must therefore keep checking whether its measures and procedures are working and still suit the level of risk it has assessed, and keep its business-wide and individual risk assessments current.
Information from monitoring feeds back into the assessment. When a customer's transactions or circumstances change, the firm considers whether the customer's risk rating and the CDD measures that go with it should change too, proportionately to the risk. Transaction monitoring itself, and the events that trigger a fresh review of customer data, are part of ongoing CDD.
Changes to risk assessments are documented, so that the firm can show its supervisor that its assessments and the resulting controls are adequate.
Terms used in this note
- Dynamic risk management
- Treating risk assessment as a continuous process that is updated as customers, products and criminal methods change.
- Occasional transaction
- A transaction carried out outside a business relationship, such as a one-off transfer.
- MOKAS
- The Unit for Combating Money Laundering, Cyprus's financial intelligence unit.
How does a firm spot new or emerging risks?
Firms need systems and controls that pick up emerging risks quickly, so that both the firm-wide assessment and individual customer ratings can be updated in good time. Useful controls include alerts on changes to sanctions lists, screening customers against a reputable database at regular intervals, reviewing media reports relevant to the firm's sectors and jurisdictions, following publications by the authorities, and attending relevant seminars and training.
Alerts and typology reports from MOKAS or the supervisor are a good example. They are new risk information: the firm builds them into its own controls and customer ratings, for example with targeted checks where the pattern fits, and reports when it has an actual suspicion.
What records must be kept, and for how long?
An obliged entity keeps a copy of the documents and information needed for CDD, including information obtained through electronic identification, the evidence and records needed to identify transactions, and relevant correspondence with customers and others it has a business relationship with. They are kept for 5 years after the business relationship ends or after the date of the occasional transaction.
At the end of that period personal data is deleted, unless another law provides otherwise. Where further retention is reasonably justified for preventing, detecting or investigating money laundering or terrorist financing, the records are kept for up to 5 more years. CySEC's Directive adds that records relevant to an ongoing investigation are kept until MOKAS confirms that the case has been closed.
Records may be held electronically, other than originals or certified copies kept on paper, provided they can be retrieved without undue delay. They must be made available to MOKAS and the supervisor promptly and without delay on request. Firms also need systems that let them answer, fully and quickly, enquiries from MOKAS or their supervisor about whether they have had a business relationship with specified persons during the previous 5 years, and what kind of relationship it was.
How to think about it
Anchor on five. Records: 5 years after the relationship ends or the occasional transaction, up to 5 more if justified, then deletion. Enquiries: the previous 5 years. For review questions, treat anything new, whether a sanctions list change, a media report or a MOKAS alert, as risk information that updates the firm's controls and ratings, not as an automatic report.
Common mistakes
Counting the 5 years from account opening. The period runs from the end of the business relationship, or from the date of the occasional transaction.
Keeping records forever just in case. Personal data is deleted at the end of the period unless an extension of up to 5 years is justified or another law requires otherwise.
Treating the risk assessment as a one-off exercise. It must be kept up to date and reviewed as customers, products and risks change.
Forgetting to record changes to risk assessments. Updates are documented so that the firm can show its supervisor that its assessments and controls are adequate.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), consolidated Greek text on CyLaw (amendments up to Law 25(I)/2026) (opens in a new tab)
Article 58A(2): risk assessments documented and updated · Article 61(1)(d): ongoing monitoring · Article 68: record keeping and retention · Article 68B: answering enquiries about the previous 5 years
- CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing, as amended (opens in a new tab)
Paragraph 15: monitoring the measures · Paragraph 16: dynamic risk management · Paragraphs 31 and 32: record keeping and format of records
- EBA Guidelines on ML/TF risk factors (EBA/GL/2021/02), as amended (opens in a new tab)
Practise this topic
Test what you just read
The Chapter 5 pack has 61 exam-style questions, 11 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 16 free Chapter 5 flashcards →