How do AML rules apply across a group?
What a group of obliged entities must put in place, how the rules travel to branches and subsidiaries abroad, and what to do when local law gets in the way.
By the ExamPass CY editorial teamLast reviewed 4 min read
Topic 13 of 14 · all topics in this chapter
- 1When CDD is required
- 2What CDD involves
- 3When CDD must be completed
- 4Verifying individuals
- 5Verifying companies and organisations
- 6Customer economic profile
- 7Beneficial ownership registers
- 8Simplified due diligence
- 9Enhanced due diligence and PEPs
- 10CDD by sector
- 11Ongoing monitoring
- 12Reliance on third parties
- 13Group-wide AML policies
- 14Prohibited practices and data use
Short answer
An obliged entity that belongs to a group must implement group-wide AML/CFT policies and procedures, including data protection policies and procedures for sharing information inside the group, and apply them effectively in its branches and majority-owned subsidiaries in the EU and beyond. Establishments in another member state follow that state's AML rules. Where a third country's rules are weaker, branches and subsidiaries there apply the Cyprus standard as far as local law allows; if local law blocks it, the firm takes additional measures and informs its supervisor immediately.
Group rules at a glance
| Situation | Rule |
|---|---|
| Group policies | Group-wide AML/CFT policies and procedures, including data protection and procedures for sharing information inside the group |
| Where they apply | Effectively in all branches and majority-owned subsidiaries, whether in the EU or in third countries |
| Establishment in another EU member state | Complies with that member state's national AML/CFT rules |
| Branch or subsidiary in a third country with weaker rules | Applies the Cyprus requirements, including data protection, as far as the local law allows |
| Local law prevents group policies | Take additional measures to handle the money laundering or terrorist financing risk, and inform the competent supervisor immediately |
| EU group entity in a high-risk third country | EDD is not automatic, and the supervisor may allow reliance on it, if it fully follows group-wide policies |
Source: Law 188(I)/2007, Article 68A; also Articles 64(1)(a) and 67.
What must a group put in place?
Belonging to a group brings a group-level duty. Alongside its own procedures, the obliged entity implements policies and procedures that apply across the group, covering AML/CFT controls, data protection and the sharing of information within the group to prevent money laundering and terrorist financing. Sharing matters because a customer turned away by one member, or a pattern seen in another country, could otherwise stay invisible to the rest of the group.
Every office should be able to meet the head office's minimum standards for identification and for keeping records accessible, although local rules or local risk may require differences in what is collected and how long it is kept.
Terms used in this note
- Branch
- A place of business that is legally part of the firm but operates in another location or country.
- Majority-owned subsidiary
- A company in which the parent holds more than half of the ownership.
- Third country
- A country outside the European Union and the European Economic Area.
Which rules apply to branches and subsidiaries abroad?
It depends on where they are. An establishment in another EU member state follows that member state's national AML/CFT rules, which implement the same EU directive. A branch or majority-owned subsidiary in a third country whose minimum AML/CFT standards are less strict applies the Cyprus requirements, including the directives and circulars of the Cyprus supervisor and data protection rules, to the extent the third country's law allows. In short, outside the EU the Cyprus standard travels with the group wherever local rules are weaker.
What if local law blocks group policies?
Where the law of a third country does not allow the group's policies and procedures to be applied, the obliged entity must take additional measures to deal effectively with the money laundering or terrorist financing risk and inform its competent supervisor immediately. Simply following the weaker local rules is not an option.
Following group-wide policies also brings two concessions. EU group branches and majority-owned subsidiaries based in high-risk third countries do not automatically trigger EDD if they fully comply with the group's policies; the firm applies a risk-based approach instead. And the supervisor can allow such entities to be relied on for CDD, which is otherwise not permitted for third parties in high-risk countries. See Can a firm rely on a third party for CDD?
How to think about it
Group-wide policies apply everywhere the group operates. Inside the EU, each establishment also complies with the host member state's national rules. Outside it, a branch or subsidiary in a country with weaker rules applies the Cyprus standard as far as local law permits; where local law prevents that, the firm adds extra measures and tells its supervisor at once.
Common mistakes
Letting a third-country branch follow weaker local rules. It applies the Cyprus requirements as far as local law allows.
Doing nothing when local law blocks group policies. The firm takes additional measures and informs its supervisor immediately.
Forgetting data protection and information sharing. Group policies must cover both, alongside AML/CFT controls.
Assuming Cyprus law governs an establishment in another EU member state. It complies with that member state's national AML/CFT rules, while still applying the group-wide policies.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), as amended (opens in a new tab)
Article 68A (group-wide policies) · Article 64(1)(a) (group entities in high-risk countries) · Article 67 (reliance within groups)
- Directive (EU) 2015/849 (4th AML Directive), as amended by Directive (EU) 2018/843 (opens in a new tab)
Article 45
- Commission Delegated Regulation (EU) 2019/758 on additional measures where third-country law does not permit group-wide policies (opens in a new tab)
Applies to credit and financial institutions
Practise this topic
Test what you just read
The Chapter 6 pack has 152 exam-style questions, 4 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 18 free Chapter 6 flashcards →