CySEC AML · Chapter 6 · Topic 13 of 14

How do AML rules apply across a group?

What a group of obliged entities must put in place, how the rules travel to branches and subsidiaries abroad, and what to do when local law gets in the way.

By the ExamPass CY editorial teamLast reviewed 4 min read

Tested inAML · Ch 6

Short answer

An obliged entity that belongs to a group must implement group-wide AML/CFT policies and procedures, including data protection policies and procedures for sharing information inside the group, and apply them effectively in its branches and majority-owned subsidiaries in the EU and beyond. Establishments in another member state follow that state's AML rules. Where a third country's rules are weaker, branches and subsidiaries there apply the Cyprus standard as far as local law allows; if local law blocks it, the firm takes additional measures and informs its supervisor immediately.

Group rules at a glance

Group policiesGroup-wide AML/CFT policies and procedures, including data protection and procedures for sharing information inside the group
Where they applyEffectively in all branches and majority-owned subsidiaries, whether in the EU or in third countries
Establishment in another EU member stateComplies with that member state's national AML/CFT rules
Branch or subsidiary in a third country with weaker rulesApplies the Cyprus requirements, including data protection, as far as the local law allows
Local law prevents group policiesTake additional measures to handle the money laundering or terrorist financing risk, and inform the competent supervisor immediately
EU group entity in a high-risk third countryEDD is not automatic, and the supervisor may allow reliance on it, if it fully follows group-wide policies

Source: Law 188(I)/2007, Article 68A; also Articles 64(1)(a) and 67.

What must a group put in place?

Belonging to a group brings a group-level duty. Alongside its own procedures, the obliged entity implements policies and procedures that apply across the group, covering AML/CFT controls, data protection and the sharing of information within the group to prevent money laundering and terrorist financing. Sharing matters because a customer turned away by one member, or a pattern seen in another country, could otherwise stay invisible to the rest of the group.

Every office should be able to meet the head office's minimum standards for identification and for keeping records accessible, although local rules or local risk may require differences in what is collected and how long it is kept.

Terms used in this note

Branch
A place of business that is legally part of the firm but operates in another location or country.
Majority-owned subsidiary
A company in which the parent holds more than half of the ownership.
Third country
A country outside the European Union and the European Economic Area.

Which rules apply to branches and subsidiaries abroad?

It depends on where they are. An establishment in another EU member state follows that member state's national AML/CFT rules, which implement the same EU directive. A branch or majority-owned subsidiary in a third country whose minimum AML/CFT standards are less strict applies the Cyprus requirements, including the directives and circulars of the Cyprus supervisor and data protection rules, to the extent the third country's law allows. In short, outside the EU the Cyprus standard travels with the group wherever local rules are weaker.

What if local law blocks group policies?

Where the law of a third country does not allow the group's policies and procedures to be applied, the obliged entity must take additional measures to deal effectively with the money laundering or terrorist financing risk and inform its competent supervisor immediately. Simply following the weaker local rules is not an option.

Following group-wide policies also brings two concessions. EU group branches and majority-owned subsidiaries based in high-risk third countries do not automatically trigger EDD if they fully comply with the group's policies; the firm applies a risk-based approach instead. And the supervisor can allow such entities to be relied on for CDD, which is otherwise not permitted for third parties in high-risk countries. See Can a firm rely on a third party for CDD?

How to think about it

Group-wide policies apply everywhere the group operates. Inside the EU, each establishment also complies with the host member state's national rules. Outside it, a branch or subsidiary in a country with weaker rules applies the Cyprus standard as far as local law permits; where local law prevents that, the firm adds extra measures and tells its supervisor at once.

Common mistakes

  1. Letting a third-country branch follow weaker local rules. It applies the Cyprus requirements as far as local law allows.

  2. Doing nothing when local law blocks group policies. The firm takes additional measures and informs its supervisor immediately.

  3. Forgetting data protection and information sharing. Group policies must cover both, alongside AML/CFT controls.

  4. Assuming Cyprus law governs an establishment in another EU member state. It complies with that member state's national AML/CFT rules, while still applying the group-wide policies.

Practise this topic

Test what you just read

The Chapter 6 pack has 152 exam-style questions, 4 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 18 free Chapter 6 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error