AML & KYC in Italy is governed by a detailed and actively enforced legal framework that applies to banks, financial intermediaries, professional service providers and a growing range of virtual asset businesses. Italy has transposed the EU';s successive Anti-Money Laundering Directives into national law through Legislative Decree 231/2007, which remains the central statute, and has since layered on further obligations through implementing regulations issued by the Bank of Italy, CONSOB and the Financial Intelligence Unit (UIF). Businesses operating in Italy - whether domestic or foreign-owned - face real compliance costs and meaningful penalties for non-compliance. This guide explains the current rules, the authorities that enforce them, recent changes to the framework, and the practical steps that obliged entities must take.
What the Italian AML framework covers
Italy';s primary AML statute is Legislative Decree 231/2007, commonly called the "AML Decree." It implements the EU';s Fourth and Fifth Anti-Money Laundering Directives and has been amended several times to reflect evolving FATF standards and EU guidance. The decree defines which entities are "obliged subjects," sets out customer due diligence (CDD) requirements, establishes suspicious transaction reporting obligations, and mandates internal controls and record-keeping.
The scope of obliged subjects is broad. It includes credit institutions and banks, insurance companies, investment firms, payment institutions, e-money institutions, accountants, notaries, lawyers when they assist with financial or corporate transactions, real estate agents, and - following recent amendments - virtual asset service providers (VASPs). Each category faces obligations calibrated to its risk profile, but the core duties are consistent: know your customer, monitor transactions, report suspicions, and maintain records.
The UIF, Italy';s Financial Intelligence Unit, sits within the Bank of Italy and is the central body for receiving and analysing suspicious transaction reports (STRs). The Bank of Italy supervises credit and financial institutions for AML compliance. CONSOB oversees investment firms and market intermediaries. The Guardia di Finanza and the Anti-Mafia Investigation Directorate (DIA) handle criminal enforcement. The interplay between these bodies means that a compliance failure can trigger both administrative sanctions and criminal investigation.
Italy is a member of FATF and undergoes mutual evaluation. The country';s most recent FATF evaluation highlighted improvements in financial intelligence and beneficial ownership transparency, while noting areas where technical compliance and effectiveness could be strengthened - particularly in the non-financial professions sector.
Customer due diligence and KYC requirements in Italy
KYC in Italy is structured around three levels of due diligence: simplified, standard and enhanced. The appropriate level depends on the risk classification of the customer, the product or service, and the jurisdiction involved.
Standard CDD requires obliged entities to identify and verify the identity of the customer and, where applicable, the beneficial owner. For legal entities, this means identifying the natural persons who ultimately own or control the entity - those holding more than 25 percent of shares or voting rights, or exercising control by other means. Verification must rely on reliable and independent sources, which in practice means official documents, company registry extracts and, increasingly, electronic identity verification tools.
Enhanced due diligence (EDD) is mandatory in higher-risk situations. These include transactions involving politically exposed persons (PEPs), customers from high-risk third countries as designated by the European Commission, complex or unusually large transactions, and correspondent banking relationships. For PEPs, EDD requires senior management approval, enhanced ongoing monitoring and a clear understanding of the source of wealth and funds.
Simplified due diligence is permitted for lower-risk customers and products, but Italian supervisors have narrowed its application in recent years. Entities cannot rely on simplified measures simply because a customer is a listed company or a public authority - a genuine risk assessment must support the decision.
A common mistake among foreign-founded businesses operating in Italy is treating KYC as a one-time onboarding exercise. Italian law requires ongoing monitoring of the business relationship. Obliged entities must update customer records when circumstances change and must scrutinise transactions for consistency with the customer';s known profile. Failure to maintain current records is one of the most frequently cited deficiencies in Bank of Italy supervisory inspections.
Beneficial ownership identification is a particular focus. Italy maintains a beneficial ownership register (Registro dei titolari effettivi) under the framework established by Legislative Decree 231/2007 as amended. Companies and other legal entities are required to file beneficial ownership information with the Business Register (Registro delle Imprese) held at the local Chamber of Commerce. Obliged entities must cross-reference their own CDD findings against this register, but cannot rely on it exclusively - they must resolve any discrepancies.
Suspicious transaction reporting and the role of the UIF
The obligation to report suspicious transactions to the UIF is one of the most operationally demanding aspects of AML & KYC in Italy. An STR must be filed when an obliged entity knows, suspects or has reasonable grounds to suspect that a transaction or activity is connected to money laundering or terrorist financing. The threshold is suspicion, not certainty.
Reports are submitted through the UIF';s dedicated electronic platform. The UIF analyses incoming reports, enriches them with financial intelligence, and disseminates relevant information to law enforcement and the judiciary. Italy consistently ranks among the higher-volume STR jurisdictions in the EU, reflecting both the size of its financial sector and the breadth of its obliged entity population.
Tipping off is prohibited. An obliged entity that files an STR must not disclose to the customer or any third party that a report has been made or that an investigation is underway. Breach of this prohibition is a criminal offence. In practice, this creates operational tension for relationship managers who must continue dealing with a customer while a report is under review.
The UIF publishes periodic guidance on typologies and red flags. Recent UIF communications have focused on risks in the real estate sector, the use of cash in high-value transactions, and anomalies associated with virtual asset transfers. Obliged entities are expected to incorporate this guidance into their risk assessments and staff training programmes.
Italy also operates a cash transaction reporting system. Transfers of cash above a threshold set by regulation must be reported to the UIF through a separate mechanism (the so-called "aggregate transaction reports" or segnalazioni aggregate). This obligation applies primarily to banks and payment institutions and covers cash deposits, withdrawals and exchanges above the applicable limit.
If your business operates in Italy and you are uncertain whether your current STR procedures meet the UIF';s expectations, contact info@vlolawfirm.com. We can assist with compliance gap assessments and procedure design.
Internal controls, record-keeping and staff training
Legislative Decree 231/2007 requires obliged entities to establish internal AML procedures proportionate to their size, nature and risk exposure. For larger financial institutions, this means a dedicated AML function, a nominated AML officer (responsabile antiriciclaggio), written policies and procedures, and a regular internal audit cycle. For smaller obliged entities such as accountants or notaries, the requirements are lighter but not absent.
Record-keeping obligations are specific. Obliged entities must retain CDD documents and transaction records for at least ten years from the end of the business relationship or the date of the transaction. Records must be stored in a way that allows them to be retrieved promptly in response to a supervisory or judicial request. Many entities underestimate the practical burden of this requirement, particularly when customer relationships span multiple years and involve large volumes of documents.
Staff training is a legal obligation, not merely good practice. Obliged entities must ensure that relevant employees understand AML and KYC requirements, can recognise suspicious activity, and know how to escalate concerns internally. Training must be documented and updated regularly to reflect changes in the law and emerging typologies. A common mistake is delivering training once at onboarding and failing to refresh it as the regulatory framework evolves.
Italy';s AML framework also requires a risk-based approach to internal controls. This means that the intensity of monitoring, the frequency of customer reviews and the depth of due diligence must reflect the actual risk profile of each customer and product. A flat, one-size-fits-all approach is not compliant and will be criticised in supervisory inspections.
The Bank of Italy has issued detailed supervisory expectations for credit institutions and financial intermediaries through its Circular 285 and related provisions. CONSOB has issued parallel guidance for investment firms. Both regulators conduct thematic inspections focused on AML, and findings are increasingly made public, creating reputational as well as financial consequences for non-compliant entities.
Virtual assets and new obliged entities
One of the most significant recent developments in AML & KYC in Italy is the formal inclusion of virtual asset service providers within the obliged entity framework. Italy has implemented the relevant EU requirements, and VASPs - including crypto-asset exchanges, custodian wallet providers and certain token issuers - must now register with the OAM (Organismo Agenti e Mediatori) and comply with the full range of AML obligations under Legislative Decree 231/2007.
The registration requirement with the OAM is a prerequisite for operating legally in Italy. VASPs that fail to register face administrative sanctions and potential prohibition from operating. Registered VASPs must apply CDD to their customers, monitor transactions for suspicious activity, file STRs with the UIF, and maintain records in the same way as traditional financial institutions.
The EU';s Markets in Crypto-Assets Regulation (MiCA) and the accompanying Transfer of Funds Regulation (TFR) - which extends the "travel rule" to crypto-asset transfers - are reshaping the compliance landscape for VASPs across the EU, including Italy. Under the travel rule, VASPs must collect and transmit originator and beneficiary information for virtual asset transfers above the applicable threshold. Italian VASPs are expected to build the technical and operational capacity to comply with these requirements as they take full effect.
In practice, many smaller VASPs operating in Italy have underestimated the compliance infrastructure required. A common mistake is assuming that registration with the OAM is sufficient and that detailed AML procedures can be developed later. Supervisors expect a functioning compliance programme from the outset.
Beyond VASPs, Italy has also tightened obligations for real estate agents, high-value goods dealers and certain professional service providers. The real estate sector in particular has been identified as a higher-risk area, and agents are expected to apply CDD not only to buyers but also to sellers in certain circumstances, and to report suspicious transactions involving property acquisitions.
Penalties, enforcement and recent supervisory trends
Non-compliance with AML & KYC obligations in Italy can result in significant administrative sanctions and, in serious cases, criminal liability. Legislative Decree 231/2007 sets out a tiered penalty structure. Administrative fines for procedural violations - such as failures in record-keeping or training - can reach substantial amounts. Fines for more serious failures, including failure to report suspicious transactions or systematic CDD deficiencies, are considerably higher and can be calculated as a multiple of the benefit obtained or the amount involved.
The Bank of Italy and CONSOB publish enforcement decisions, and the reputational impact of a public sanction can be severe. In recent years, Italian supervisors have increased the frequency and depth of AML inspections, with a particular focus on beneficial ownership verification, the quality of STRs, and the adequacy of internal controls at smaller intermediaries.
Criminal liability under Italian law can arise where AML failures are connected to underlying money laundering offences. The crime of money laundering (riciclaggio) under Article 648-bis of the Italian Penal Code, and the related offence of self-laundering (autoriciclaggio) under Article 648-ter.1, carry custodial sentences. Corporate liability under Legislative Decree 231/2001 - a separate statute that governs corporate criminal responsibility - can also be engaged where AML failures benefit the legal entity.
A non-obvious requirement that catches many foreign-owned entities is the interaction between Legislative Decree 231/2001 (corporate liability) and Legislative Decree 231/2007 (AML). Both statutes share a numbering coincidence but serve different purposes. An entity that has adopted a compliance model under the corporate liability statute must ensure that its AML procedures are integrated into that model, not treated as a separate silo.
Recent supervisory trends point to increased scrutiny of outsourced compliance functions. Where an obliged entity delegates CDD or monitoring tasks to a third party, it remains fully responsible for the quality of that work. Supervisors have found cases where outsourcing arrangements lacked adequate oversight, leading to systemic gaps in customer files.
If your organisation needs to review its AML compliance programme or respond to a supervisory inquiry in Italy, contact info@vlolawfirm.com. We can assist with regulatory analysis, internal procedure drafting and liaison with supervisory authorities.
Frequently asked questions
What is the beneficial ownership threshold for KYC purposes in Italy?
Under Legislative Decree 231/2007, the beneficial owner of a legal entity is generally the natural person who ultimately owns or controls more than 25 percent of the shares or voting rights. Where no individual meets this threshold, or where ownership is exercised through other means of control, obliged entities must identify the person who exercises effective control through other mechanisms. If no such person can be identified, the senior managing official may be recorded as the beneficial owner as a last resort. Obliged entities must document their analysis and cannot simply accept a customer';s self-declaration without independent verification. Discrepancies between CDD findings and the information in the Business Register must be reported to the competent authority.
How long does it take to build a compliant AML programme for a new business in Italy?
The timeline depends heavily on the size and complexity of the business. A smaller obliged entity - such as an accountancy firm or a payment institution with a limited product range - can typically develop core policies, procedures and training materials within two to three months if it has access to competent legal and compliance advice. Larger financial institutions or VASPs with complex product offerings should allow considerably longer, often six months or more, to design, test and embed a risk-based programme. The OAM registration process for VASPs adds a further procedural step with its own timeline. Attempting to compress this process creates the risk of launching with inadequate controls, which supervisors will identify during their initial review.
Can a foreign company rely on CDD carried out by a group entity outside Italy?
Italian law permits reliance on third-party CDD in certain circumstances, including where the third party is a group entity subject to equivalent AML requirements. However, the relying entity remains fully responsible for the adequacy of the CDD and must be able to obtain the underlying documentation on request. Reliance on entities based in high-risk third countries is not permitted. In practice, group-wide CDD frameworks must be carefully designed to meet Italian requirements, which in some respects are more detailed than the minimum standards set by EU directives. A common mistake is assuming that a group KYC process designed for another EU jurisdiction will automatically satisfy Italian supervisors without adaptation.
Conclusion
Italy';s AML and KYC framework is comprehensive, actively enforced and continuing to evolve in line with EU and FATF standards. Obliged entities - from banks and investment firms to accountants, real estate agents and virtual asset providers - face detailed obligations that require genuine investment in compliance infrastructure. The consequences of non-compliance range from administrative fines and reputational damage to criminal liability.
VLO Law Firms advises international clients on AML & KYC matters in Italy. We can assist with compliance programme design, beneficial ownership analysis, STR procedure development, regulatory gap assessments and engagement with Italian supervisory authorities. To request a consultation, contact: info@vlolawfirm.com