What does the AML/CFT Law prohibit outright?
The bans on shell-bank relationships and anonymous accounts, the duty to watch anonymity-friendly products, and the strict limits on using AML data.
By the ExamPass CY editorial teamLast reviewed 5 min read
Topic 14 of 14 · all topics in this chapter
- 1When CDD is required
- 2What CDD involves
- 3When CDD must be completed
- 4Verifying individuals
- 5Verifying companies and organisations
- 6Customer economic profile
- 7Beneficial ownership registers
- 8Simplified due diligence
- 9Enhanced due diligence and PEPs
- 10CDD by sector
- 11Ongoing monitoring
- 12Reliance on third parties
- 13Group-wide AML policies
- 14Prohibited practices and data use
Short answer
Cyprus's AML/CFT Law bans some things outright. Banks and other financial institutions may not enter into or continue a correspondent relationship with a shell bank, and must assess and take measures to avoid such relationships with an institution that lets a shell bank use its accounts. No firm may open or keep anonymous or numbered accounts, accounts in names that differ from official identity documents, or anonymous safe-deposit boxes. Personal data collected under the law may be used only for AML/CFT purposes; commercial use is prohibited.
The prohibitions at a glance
| Area | Rule |
|---|---|
| Shell banks | No correspondent relationship may be started or continued with a shell bank; banks and other financial institutions must assess and take measures to avoid correspondent relationships with an institution that lets a shell bank use its accounts |
| Anonymous accounts | Anonymous or numbered accounts, accounts in names other than those on official identity documents, and anonymous safe-deposit boxes are banned |
| Products that favour anonymity | Particular attention to the risk, with measures to prevent misuse where needed |
| New products, practices and technologies | Identify and assess the ML/TF risks before launching or using them, and take measures to manage and reduce those risks |
| Use of personal data | Only for AML/CFT purposes; commercial or other incompatible use is prohibited |
| New customers | Told, before the relationship or transaction, what data protection law requires and that their data will be processed to prevent money laundering and terrorist financing |
| Right of access to personal data | Can be restricted so AML/CFT duties can be carried out or so investigations are not obstructed |
Source: Law 188(I)/2007, Articles 66 and 70B, as amended up to 2023.
Why are shell banks banned?
A shell bank is a credit or financial institution, or an institution doing equivalent business, incorporated in a jurisdiction where it has no physical presence involving real management, and which is not part of a regulated financial group. With no one on the ground to supervise, it can move money for anyone with little scrutiny.
Banks and other financial institutions may therefore not enter into, or continue, a correspondent relationship with a shell bank. They must also assess, and take the necessary measures to ensure, that they do not enter into or continue correspondent relationships with an institution that lets a shell bank use its accounts, since that would give the shell bank access through the back door. Other correspondent relationships are covered in When is enhanced due diligence required?
Terms used in this note
- Shell bank
- A credit or financial institution, or equivalent institution, incorporated where it has no physical presence involving real management, and not part of a regulated financial group.
- Correspondent relationship
- Banking or similar services, such as accounts, payments or securities transactions, provided by one institution (the correspondent) to another (the respondent).
- Numbered account
- An account identified only by a number or code rather than by the holder's name.
Which accounts and products are off limits?
No firm may open or maintain an anonymous or numbered account, an account in a name that differs from the one in the customer's official identity documents, or an anonymous safe-deposit box. Every account must be traceable to a verified person.
Beyond the outright bans, firms must pay particular attention to products and transactions that could favour anonymity, take measures where needed to stop them being misused, and apply reasonable measures against the risks that new technology and new financial products bring. Before launching new products, business practices or delivery channels, or using new or developing technologies for new or existing products, they identify and assess the money laundering and terrorist financing risks and take measures to manage and reduce them.
How may AML data be used?
Processing personal data under the AML/CFT Law is subject to the GDPR and Cyprus's data protection law, and it counts as a matter of public interest. Firms may process the data only for the purposes the AML/CFT Law sets. Using it for anything else, such as marketing or other commercial purposes, is prohibited.
Before a relationship starts or an occasional transaction is carried out, the firm gives new customers the information the GDPR requires and a notice explaining that it must process their personal data to prevent money laundering and terrorist financing.
A customer's right to see the data held about them can be restricted in two situations: so the firm or the supervisory authorities can carry out their AML/CFT duties properly, and so official inquiries and investigations are not obstructed and the detection of money laundering and terrorist financing is not put at risk. Convenience or cost is not a ground.
How to think about it
Some risks cannot be managed, only avoided: a bank with no real presence where it is incorporated, or an account that cannot be tied to a verified person. Refuse those outright. Everything else that favours anonymity, including new products and technologies, gets extra attention rather than a ban. And AML data has one purpose only: preventing money laundering and terrorist financing.
Common mistakes
Thinking enhanced due diligence can make a shell-bank relationship acceptable. It is prohibited outright, whatever the measures.
Opening an account under a name that differs from the customer's ID. Accounts must be in the name shown on official identity documents.
Banning every product that favours anonymity. The law asks for particular attention and preventive measures, not a blanket ban.
Using KYC data for marketing. AML data may be processed only for AML/CFT purposes.
Refusing access requests for convenience. The right of access can be restricted only to protect AML/CFT duties or investigations.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), as amended (opens in a new tab)
Article 66 (shell banks, anonymous accounts, new technologies) · Article 70B (personal data)
- Regulation (EU) 2016/679 (General Data Protection Regulation) (opens in a new tab)
Articles 13 and 23
- Directive (EU) 2015/849 (4th AML Directive), as amended by Directive (EU) 2018/843 (opens in a new tab)
Articles 10, 24, 41 and 43
- Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation), applying from 10 July 2027 (opens in a new tab)
Article 79
Practise this topic
Test what you just read
The Chapter 6 pack has 152 exam-style questions, 7 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 18 free Chapter 6 flashcards →