When is customer due diligence (CDD) required?
The events and euro thresholds that trigger CDD under Cyprus's AML/CFT Law, and the traps exam questions set around them.
By the ExamPass CY editorial teamLast reviewed 5 min read
Topic 1 of 14 · all topics in this chapter
- 1When CDD is required
- 2What CDD involves
- 3When CDD must be completed
- 4Verifying individuals
- 5Verifying companies and organisations
- 6Customer economic profile
- 7Beneficial ownership registers
- 8Simplified due diligence
- 9Enhanced due diligence and PEPs
- 10CDD by sector
- 11Ongoing monitoring
- 12Reliance on third parties
- 13Group-wide AML policies
- 14Prohibited practices and data use
On this page
- Short answer
- CDD triggers at a glance
- What is the difference between a business relationship and an occasional transaction?
- Why are linked transactions added together?
- When is CDD required regardless of the amount?
- What happened to the €10,000 cash threshold for traders in goods?
- How to think about it
- Common mistakes
- Looking ahead: changes from July 2027
- Legal references
- Practise this topic
Short answer
A firm covered by Cyprus's AML/CFT Law must carry out customer due diligence (CDD) whenever it starts a business relationship, whatever the amount. For one-off (occasional) transactions, CDD depends on the amount: €15,000 or more in general, more than €1,000 for transfers of funds and €1,000 or more for crypto-asset services. Gambling providers apply CDD to stakes or winnings of €2,000 or more. Suspicion of money laundering, or doubts about identity data already on file, triggers CDD at any amount.
CDD triggers at a glance
| Situation | CDD applies |
|---|---|
| Starting a business relationship | Always, whatever the amount |
| Occasional transaction (general rule) | €15,000 or more, in one operation or several linked ones |
| Occasional transfer of funds, such as a wire transfer | More than €1,000 |
| Crypto-asset service provider, occasional transaction | €1,000 or more, single or linked |
| Gambling services: stakes, winnings or both | €2,000 or more, single or linked |
| Suspicion of money laundering or terrorist financing | Any amount; no threshold, exemption or derogation applies |
| Doubts about identification data already on file | At any time, for an existing customer |
Source: Law 188(I)/2007 (the AML/CFT Law), Article 60, as amended up to 2025.
What is the difference between a business relationship and an occasional transaction?
The first question is always what kind of contact the firm has with the customer. A business relationship is a professional or commercial relationship that the firm expects, when contact begins, to last for some time: an investment account, a fund subscription, an ongoing mandate. An occasional transaction is a one-off carried out outside any such relationship.
That distinction decides whether amounts matter at all. A business relationship requires CDD from day one, even if the first deposit is small. For an occasional transaction, the amount and the type of business decide.
Terms used in this note
- Obliged entity
- A firm or professional that must apply the AML/CFT Law, including banks and other financial institutions, investment firms, fund managers, auditors, lawyers, administrative service providers, gambling operators and crypto-asset service providers.
- Linked transactions
- Separate operations that appear to belong together, such as one payment split into several smaller ones. Their values are added up when a threshold is checked.
- Transfer of funds
- A payment made electronically through a payment service provider to make money available to a payee, such as a wire transfer.
Why are linked transactions added together?
Splitting a payment is the simplest way to stay under a threshold, so the law looks at the total of operations that appear connected rather than at each payment on its own. A customer who pays €8,000 today and another €8,000 next week for the same purchase has made a €16,000 transaction, which crosses the €15,000 line. The same adding-up applies to the gambling and crypto thresholds, and to the cash limit described below.
When is CDD required regardless of the amount?
Two situations override every figure in the table. The first is suspicion: once a firm suspects money laundering or terrorist financing, it must apply CDD even for a small sum, and no exemption or minimum amount can be used to avoid it. The second is doubt about information the firm already holds, for example when an identity document on file turns out to be expired, inaccurate or inconsistent. That doubt re-opens CDD for an existing customer.
Existing customers are also brought back into CDD at suitable, risk-based moments, such as when their circumstances change. That is covered in When must CDD be completed?
What happened to the €10,000 cash threshold for traders in goods?
Until 31 December 2024, traders in goods had to apply CDD to occasional cash transactions of €10,000 or more, single or linked, and older study material still shows that rule. An amendment in force from that date removed the trigger and replaced it with an outright limit: anyone trading in goods or providing services, including buying and selling property, may now receive or make cash payments of no more than €10,000, whether in one operation or several linked ones.
The limit has narrow exceptions, such as payments between private individuals not acting in a professional capacity, and payments made at the premises of banks, e-money institutions or payment service providers. Breaking it is a criminal offence.
How to think about it
Ask two questions, in this order. First: is this a relationship or a one-off? A relationship means CDD, whatever the amount. Second, for a one-off: who is the firm, and what is moving? The general line is €15,000. Lower lines apply to transfers of funds (above €1,000) and crypto-asset services (€1,000), and gambling providers check stakes and winnings from €2,000. Then check the two overrides, suspicion and doubt, which ignore every threshold.
Common mistakes
Treating a CDD threshold as a trigger for enhanced due diligence. Crossing a threshold means CDD applies. Enhanced due diligence depends on risk, such as a politically exposed person, a high-risk third country or a transaction that is unusually large or complex for that customer.
Mixing up "more than" and "or more". A transfer of funds is caught only above €1,000; the general, crypto and gambling thresholds apply from the figure itself. The cash limit works the other way: a cash payment of exactly €10,000 is allowed, anything above it is not.
Quoting the €10,000 cash threshold for traders in goods as a current CDD trigger. Since 31 December 2024 Cyprus instead limits cash payments for goods and services to €10,000.
Checking each payment separately. Linked operations are added together, so splitting a payment does not avoid CDD.
Assuming CDD is only for new customers. Suspicion, or doubt about data already on file, requires CDD for existing customers too.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), as amended (opens in a new tab)
Article 2B: €10,000 cash limit · Article 60: when CDD applies · Article 61: what CDD involves · Article 62: timing of verification
- CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing, as amended (opens in a new tab)
- Directive (EU) 2015/849 (4th AML Directive), as amended by Directive (EU) 2018/843 (opens in a new tab)
- Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets (opens in a new tab)
- Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation), applying from 10 July 2027 (opens in a new tab)
Practise this topic
Test what you just read
The Chapter 6 pack has 152 exam-style questions, 12 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 18 free Chapter 6 flashcards →