CySEC AML · Chapter 6 · Topic 14 of 14

What does the AML/CFT Law prohibit outright?

The bans on shell-bank relationships and anonymous accounts, the duty to watch anonymity-friendly products, and the strict limits on using AML data.

By the ExamPass CY editorial teamLast reviewed 5 min read

Tested inAML · Ch 6

Short answer

Cyprus's AML/CFT Law bans some things outright. Banks and other financial institutions may not enter into or continue a correspondent relationship with a shell bank, and must assess and take measures to avoid such relationships with an institution that lets a shell bank use its accounts. No firm may open or keep anonymous or numbered accounts, accounts in names that differ from official identity documents, or anonymous safe-deposit boxes. Personal data collected under the law may be used only for AML/CFT purposes; commercial use is prohibited.

The prohibitions at a glance

Shell banksNo correspondent relationship may be started or continued with a shell bank; banks and other financial institutions must assess and take measures to avoid correspondent relationships with an institution that lets a shell bank use its accounts
Anonymous accountsAnonymous or numbered accounts, accounts in names other than those on official identity documents, and anonymous safe-deposit boxes are banned
Products that favour anonymityParticular attention to the risk, with measures to prevent misuse where needed
New products, practices and technologiesIdentify and assess the ML/TF risks before launching or using them, and take measures to manage and reduce those risks
Use of personal dataOnly for AML/CFT purposes; commercial or other incompatible use is prohibited
New customersTold, before the relationship or transaction, what data protection law requires and that their data will be processed to prevent money laundering and terrorist financing
Right of access to personal dataCan be restricted so AML/CFT duties can be carried out or so investigations are not obstructed

Source: Law 188(I)/2007, Articles 66 and 70B, as amended up to 2023.

Why are shell banks banned?

A shell bank is a credit or financial institution, or an institution doing equivalent business, incorporated in a jurisdiction where it has no physical presence involving real management, and which is not part of a regulated financial group. With no one on the ground to supervise, it can move money for anyone with little scrutiny.

Banks and other financial institutions may therefore not enter into, or continue, a correspondent relationship with a shell bank. They must also assess, and take the necessary measures to ensure, that they do not enter into or continue correspondent relationships with an institution that lets a shell bank use its accounts, since that would give the shell bank access through the back door. Other correspondent relationships are covered in When is enhanced due diligence required?

Terms used in this note

Shell bank
A credit or financial institution, or equivalent institution, incorporated where it has no physical presence involving real management, and not part of a regulated financial group.
Correspondent relationship
Banking or similar services, such as accounts, payments or securities transactions, provided by one institution (the correspondent) to another (the respondent).
Numbered account
An account identified only by a number or code rather than by the holder's name.

Which accounts and products are off limits?

No firm may open or maintain an anonymous or numbered account, an account in a name that differs from the one in the customer's official identity documents, or an anonymous safe-deposit box. Every account must be traceable to a verified person.

Beyond the outright bans, firms must pay particular attention to products and transactions that could favour anonymity, take measures where needed to stop them being misused, and apply reasonable measures against the risks that new technology and new financial products bring. Before launching new products, business practices or delivery channels, or using new or developing technologies for new or existing products, they identify and assess the money laundering and terrorist financing risks and take measures to manage and reduce them.

How may AML data be used?

Processing personal data under the AML/CFT Law is subject to the GDPR and Cyprus's data protection law, and it counts as a matter of public interest. Firms may process the data only for the purposes the AML/CFT Law sets. Using it for anything else, such as marketing or other commercial purposes, is prohibited.

Before a relationship starts or an occasional transaction is carried out, the firm gives new customers the information the GDPR requires and a notice explaining that it must process their personal data to prevent money laundering and terrorist financing.

A customer's right to see the data held about them can be restricted in two situations: so the firm or the supervisory authorities can carry out their AML/CFT duties properly, and so official inquiries and investigations are not obstructed and the detection of money laundering and terrorist financing is not put at risk. Convenience or cost is not a ground.

How to think about it

Some risks cannot be managed, only avoided: a bank with no real presence where it is incorporated, or an account that cannot be tied to a verified person. Refuse those outright. Everything else that favours anonymity, including new products and technologies, gets extra attention rather than a ban. And AML data has one purpose only: preventing money laundering and terrorist financing.

Common mistakes

  1. Thinking enhanced due diligence can make a shell-bank relationship acceptable. It is prohibited outright, whatever the measures.

  2. Opening an account under a name that differs from the customer's ID. Accounts must be in the name shown on official identity documents.

  3. Banning every product that favours anonymity. The law asks for particular attention and preventive measures, not a blanket ban.

  4. Using KYC data for marketing. AML data may be processed only for AML/CFT purposes.

  5. Refusing access requests for convenience. The right of access can be restricted only to protect AML/CFT duties or investigations.

Practise this topic

Test what you just read

The Chapter 6 pack has 152 exam-style questions, 7 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 18 free Chapter 6 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error