AML & KYC in Cyprus is governed by a layered framework that combines EU directives, domestic legislation, and sector-specific guidance from multiple supervisory authorities. Cyprus has significantly tightened its compliance infrastructure in recent years, responding to pressure from the European Commission and international bodies. This guide covers the legal foundations, key obligations for businesses, supervisory structure, enforcement trends, and the practical steps that foreign-owned entities operating in Cyprus must take to remain compliant.
The legal framework underpinning AML & KYC in Cyprus
Cyprus implements EU anti-money laundering rules primarily through the Prevention and Suppression of Money Laundering and Terrorist Financing Law (Law 188(I)/2007, as amended). This statute has been updated multiple times to transpose successive EU AML Directives, including the Fourth and Fifth AML Directives. The most recent legislative cycle aligns Cyprus with the requirements of the Sixth AML Directive and the broader EU AML package that entered into force across member states.
The law defines obliged entities broadly. It covers banks, investment firms, payment institutions, crypto-asset service providers, lawyers, accountants, auditors, real estate agents, trust and company service providers (TCSPs), and dealers in high-value goods. Each category faces obligations calibrated to the risk profile of its sector.
Alongside the primary statute, the Central Bank of Cyprus (CBC), the Cyprus Securities and Exchange Commission (CySEC), and the Institute of Certified Public Accountants of Cyprus (ICPAC) each issue binding directives and guidance notes for the sectors they supervise. These sector-level instruments fill in the operational detail that the primary law leaves to regulators.
A non-obvious requirement is that Cyprus law places personal liability on compliance officers and senior management for systemic failures. This is not merely a corporate fine risk - individuals can face criminal prosecution, professional disqualification, and reputational consequences.
Core KYC obligations: what obliged entities must do
KYC in Cyprus requires obliged entities to identify and verify the identity of customers before establishing a business relationship or executing a transaction above applicable thresholds. The process has three interlocking components: customer due diligence (CDD), enhanced due diligence (EDD), and ongoing monitoring.
Standard CDD involves collecting and verifying:
- Full legal name and date of birth for natural persons, or registered name and incorporation documents for legal entities.
- Proof of address, typically a recent utility bill or bank statement.
- Identification of the ultimate beneficial owner (UBO), defined as any natural person holding more than 25% of shares or voting rights, or exercising effective control.
- The purpose and intended nature of the business relationship.
Enhanced due diligence applies automatically in higher-risk situations. These include relationships with politically exposed persons (PEPs), customers from high-risk third countries listed by the European Commission, complex ownership structures, and transactions that appear inconsistent with the customer';s stated business profile. EDD requires additional documentation, senior management approval, and more frequent review cycles.
Ongoing monitoring means that KYC is not a one-time exercise. Obliged entities must periodically refresh customer files, re-screen against sanctions lists, and flag unusual transaction patterns for internal review and, where warranted, for reporting to the Financial Intelligence Unit (MOKAS).
A common mistake made by foreign-owned businesses in Cyprus is treating KYC as a front-end onboarding formality. In practice, regulators examine the quality of ongoing monitoring during inspections, and gaps in periodic review are among the most frequently cited deficiencies.
Supervisory authorities and their roles
Cyprus operates a multi-authority supervisory model. Understanding which body oversees which sector is essential for compliance planning.
The Central Bank of Cyprus supervises banks, payment institutions, and electronic money institutions. It conducts on-site inspections, issues binding directives, and has the power to impose administrative sanctions, revoke licences, and refer cases to prosecutors.
CySEC supervises investment firms, fund managers, crypto-asset service providers (under MiCA and transitional arrangements), and certain other regulated entities. CySEC has been particularly active in recent enforcement cycles, issuing substantial fines for AML control failures and publishing detailed thematic reviews that set de facto compliance benchmarks.
ICPAC supervises accountants and auditors in private practice. The Cyprus Bar Association supervises lawyers. The Department of the Registrar of Companies and Official Receiver supervises TCSPs and company formation agents. Each of these bodies has its own inspection methodology and sanction scale, but all operate under the umbrella of the primary AML law.
MOKAS - the Unit for Combating Money Laundering - is Cyprus';s financial intelligence unit. It receives suspicious transaction reports (STRs) and suspicious activity reports (SARs), analyses them, and disseminates intelligence to law enforcement. MOKAS also cooperates with Europol, Egmont Group members, and other FIUs internationally.
In practice, founders should consider that a single Cyprus-based group structure may be subject to oversight by two or three different supervisors simultaneously - for example, a holding company using a TCSP, holding a CySEC-licensed subsidiary, and banking with a CBC-regulated institution.
Beneficial ownership registration and transparency requirements
Cyprus maintains a beneficial ownership register for companies and other legal entities, administered by the Registrar of Companies. This register was established to comply with the Fifth AML Directive and has been progressively expanded in scope and accessibility.
All Cyprus-registered companies, partnerships, and certain other legal arrangements must file accurate UBO information with the register. The information required includes the UBO';s full name, nationality, country of residence, date of birth, and the nature and extent of the beneficial interest held. Updates must be filed within a defined period whenever the underlying ownership structure changes.
Trustees of express trusts with a connection to Cyprus - whether through trustee residence, trust assets, or business relationships - must register trust beneficial ownership information in a separate register maintained by the Tax Department. This obligation extends to foreign trusts that establish a business relationship with a Cyprus obliged entity.
Many underestimate the practical complexity of UBO registration for multi-layered international structures. Where a Cyprus company is owned through a chain of holding entities across multiple jurisdictions, each intermediate layer must be traced until a natural person is identified. Nominee arrangements do not extinguish the UBO obligation - the underlying beneficial owner must still be disclosed.
Non-compliance with UBO registration obligations carries administrative fines and can trigger enhanced scrutiny from supervisors and banks. In practice, banks in Cyprus routinely cross-check their own KYC files against the register and flag discrepancies as a red flag requiring explanation.
Recent enforcement trends and what they mean for businesses
Enforcement of AML & KYC rules in Cyprus has intensified markedly in recent years. CySEC has issued a series of high-profile fines against investment firms and crypto-asset businesses for failures including inadequate CDD, poor transaction monitoring systems, and failure to file STRs in a timely manner. The CBC has similarly sanctioned payment institutions for systemic KYC gaps.
Several themes emerge from published enforcement decisions:
- Overreliance on automated screening tools without adequate human review of alerts.
- Failure to apply EDD to customers who were subsequently identified as PEPs or connected to high-risk jurisdictions.
- Inadequate documentation of the rationale for risk classifications, making it impossible to demonstrate a risk-based approach during inspections.
- Delays in filing STRs after internal red flags were identified.
The EU';s new AML Authority (AMLA), which is being established to directly supervise the highest-risk obliged entities across the EU, will have jurisdiction over certain Cyprus-based entities once it becomes fully operational. This adds a supranational layer of oversight that businesses should factor into their compliance planning now.
For foreign founders operating in Cyprus, a practical scenario worth considering is this: a non-EU parent company establishes a Cyprus subsidiary to access EU markets. The subsidiary uses a local TCSP for registered office services and opens a bank account with a Cyprus bank. In this scenario, the subsidiary is subject to KYC from the bank, the TCSP, and potentially CySEC if it holds a licence. Each obliged entity will conduct its own independent KYC, and inconsistencies between the information provided to each can trigger STR filings.
A second scenario involves a Cyprus-based law firm or accountancy practice acting as a TCSP for multiple international clients. Under current rules, the firm must apply a risk-based approach to each client relationship, maintain a written AML policy, appoint a compliance officer, and train staff annually. Failure to do so exposes the firm to sanctions from ICPAC or the Bar Association, as well as potential criminal liability for the compliance officer personally.
If your business operates in Cyprus and you are uncertain whether your current AML and KYC framework meets regulatory expectations, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Practical compliance steps for foreign-owned businesses in Cyprus
Foreign founders and international businesses operating through Cyprus entities face a specific set of practical challenges. The following steps reflect current regulatory expectations and common inspection findings.
Appoint a qualified compliance officer. Cyprus law requires obliged entities to designate a natural person as the AML compliance officer. This person must have adequate seniority, independence, and access to resources. For smaller entities, the role may be combined with other functions, but the individual must be identifiable and reachable by the supervisor.
Adopt a written AML policy and risk assessment. The policy must be tailored to the entity';s specific business model, customer base, and geographic exposure. A generic template downloaded from the internet will not satisfy an inspector. The risk assessment must be reviewed and updated periodically, and whenever there is a material change in the business.
Implement a risk-based CDD process. Not all customers require the same level of scrutiny. The risk-based approach means applying lighter-touch CDD to demonstrably low-risk relationships and concentrating resources on higher-risk ones. The rationale for each risk classification must be documented and retained.
Train staff regularly. Annual AML training is a minimum expectation. Training records must be maintained and available for inspection. Supervisors have cited inadequate training as an aggravating factor in sanction decisions.
Establish a clear STR filing process. Staff must know how to escalate internal suspicions, and the compliance officer must have a documented process for evaluating and filing STRs with MOKAS. Delays between internal identification of a red flag and the filing of an STR are a recurring enforcement issue.
Maintain records for the required retention period. Cyprus law requires KYC documents and transaction records to be retained for a minimum of five years after the end of the business relationship or the completion of the transaction. Records must be retrievable promptly if requested by a supervisor or law enforcement.
FAQ
What triggers enhanced due diligence for a Cyprus business relationship?
Enhanced due diligence is triggered automatically in several situations under Cyprus AML law. These include relationships with politically exposed persons or their close associates, customers or counterparties from countries designated as high-risk by the European Commission, complex or unusual transaction structures that lack an obvious economic rationale, and situations where standard CDD cannot be completed satisfactorily. In practice, EDD means collecting additional documentation, obtaining senior management sign-off before the relationship proceeds, and conducting more frequent periodic reviews. Obliged entities must document why EDD was applied and what additional steps were taken. Failing to apply EDD when it is required is one of the most common findings in CySEC and CBC inspections.
How long does it typically take to set up a compliant AML framework for a new Cyprus entity?
The timeline depends on the complexity of the business and the sector. For a straightforward Cyprus company using a TCSP and a single bank account, a basic compliant framework - written policy, risk assessment, compliance officer appointment, and staff training - can be put in place within four to eight weeks if approached systematically. For a CySEC-licensed entity, the framework must be submitted as part of the licence application and reviewed by CySEC before authorisation is granted, which adds to the overall timeline. The cost of building a compliant framework varies widely depending on whether the business uses external legal or compliance advisers, the complexity of the customer base, and the technology deployed for transaction monitoring. Professional fees for initial framework development typically start from the low thousands of EUR for simpler structures.
Can a Cyprus company rely on KYC conducted by another EU-regulated entity?
Yes, within defined limits. Cyprus law permits obliged entities to rely on CDD performed by another obliged entity that is subject to equivalent AML requirements, provided certain conditions are met. The relying entity must obtain confirmation that CDD has been performed, be able to obtain the underlying documentation on request, and satisfy itself that the third party is subject to supervision and compliant with applicable rules. Critically, the relying entity retains full legal responsibility for the adequacy of the CDD. If the third party';s KYC turns out to be deficient, the relying entity cannot use reliance as a defence. In practice, reliance arrangements must be documented in a written agreement and reviewed periodically.
Conclusion
AML & KYC compliance in Cyprus is a substantive, ongoing obligation that touches every sector of the economy. The framework is sophisticated, enforcement is active, and the consequences of non-compliance - fines, licence revocation, and personal liability - are real. Foreign-owned businesses and international founders using Cyprus as a base for EU market access must treat compliance as a core operational function, not an administrative afterthought.
VLO Law Firms advises international clients on AML & KYC matters in Cyprus. We can assist with compliance framework design, UBO registration, regulatory correspondence, and ongoing compliance support. To request a consultation, contact: info@vlolawfirm.com