+SECTION 4 Enhanced due diligence
---+Article 34 Scope of application of enhanced due diligence measures
---+Article 35 Countermeasures to mitigate money laundering and terrorist financing threats from outside the Union
---+Article 36 Specific enhanced due diligence measures for cross-border correspondent relationships
---+Article 37 Specific enhanced due diligence measures for cross-border correspondent relationships for crypto-asset service providers
---+Article 38 Specific measures for individual third-country respondent institutions
---+Article 39 Prohibition of correspondent relationships with shell institutions
---+Article 40 Measures to mitigate risks in relation to transactions with a self-hosted address
---+Article 41 Specific provisions regarding applicants for residence by investment schemes
---+Article 42 Specific provisions regarding politically exposed persons
---+Article 43 List of prominent public functions
---+Article 44 Politically exposed persons who are beneficiaries of insurance policies
---+Article 45 Measures for persons who cease to be politically exposed persons
---+Article 46 Family members and persons known to be close associates of politically exposed persons

SECTION 4 Enhanced due diligence

SECTION 4 Enhanced due diligence

1. Übersicht

Bezeichnung Regulierung
Article 34 Scope of application of enhanced due diligence measures

Article 34

Scope of application of enhanced due diligence measures

1.   In the cases referred to in Articles 29, 30, 31 and 36 to 46, as well as in other cases of higher risk that are identified by obliged entities pursuant to Article 20(2), second subparagraph, obliged entities shall apply enhanced due diligence measures to manage and mitigate such risks appropriately.

2.   Obliged entities shall examine the origin and destination of funds involved in, and the purpose of, all transactions that fulfil at least one of the following conditions:

(a)

the transaction is of a complex nature;

(b)

the transaction is unusually large;

(c)

the transaction is conducted in an unusual pattern;

(d)

the transaction does not have an apparent economic or lawful purpose.

3.   With the exception of the cases covered by Section 2 of this Chapter, when assessing the risks of money laundering and terrorist financing posed by a business relationship or occasional transaction, obliged entities shall take into account at least the factors of potential higher risk set out in Annex III and the guidelines adopted by AMLA pursuant to Article 32, as well as any other indicators of higher risk such as notifications issued by the FIU and findings of the business-wide risk assessment under Article 10.

4.   With the exception of the cases covered by Section 2 of this Chapter, in cases of higher risk as referred to in paragraph 1 of this Article, obliged entities shall apply enhanced due diligence measures, proportionate to the higher risks identified, which may include the following measures:

(a)

obtaining additional information on the customer and the beneficial owners;

(b)

obtaining additional information on the intended nature of the business relationship;

(c)

obtaining additional information on the source of funds, and source of wealth of the customer and of the beneficial owners;

(d)

obtaining information on the reasons for the intended or performed transactions and their consistency with the business relationship;

(e)

obtaining the approval of senior management for establishing or continuing the business relationship;

(f)

conducting enhanced monitoring of the business relationship by increasing the number and timing of controls applied, and selecting patterns of transactions that need further examination;

(g)

requiring the first payment to be carried out through an account in the customer’s name with a credit institution subject to customer due diligence standards that are not less robust than those laid down in this Regulation.

5.   Where a business relationship that is identified as having a higher risk involves the handling of assets with a value of at least EUR 5 000 000, or the equivalent in national or foreign currency, through personalised services for a customer holding total assets with a value of at least EUR 50 000 000, or the equivalent in national or foreign currency, whether in financial, investable or real estate assets, or a combination thereof, excluding that customer’s private residence, credit institutions, financial institutions and trust or company service providers shall apply the following enhanced due diligence measures, in addition to any enhanced due diligence measure applied pursuant to paragraph 4:

(a)

specific measures including procedures to mitigate risks associated with personalised services and products offered to that customer;

(b)

obtaining additional information on that customer’s source of funds;

(c)

preventing and managing conflicts of interest between the customer and senior management or employees of the obliged entity that undertake tasks related to that obliged entity’s compliance in relation to that customer.

By 10 July 2027, AMLA shall issue guidelines on the measures to be taken by credit institutions, financial institutions and trust or company service providers to establish whether a customer holds total assets with a value of at least EUR 50 000 000, or the equivalent in national or foreign currency, in financial, investable or real estate assets and how to determine that value.

6.   With the exception of the cases covered by Section 2 of this Chapter, where Member States identify cases of higher risks pursuant to Article 8 of Directive (EU) 2024/1640, including as a result of sectoral risk assessments carried out by the Member States, they may require obliged entities to apply enhanced due diligence measures and, where appropriate, specify those measures. Member States shall notify to the Commission and AMLA their decisions imposing enhanced due diligence requirements upon obliged entities established in their territory within 1 month of their adoption, accompanied by a justification of the money laundering and terrorist financing risks underpinning such decision.

Where the risks identified by Member States pursuant to the first subparagraph are likely to stem from outside the Union and may affect the Union’s financial system, AMLA shall, upon a request from the Commission or on its own initiative, consider updating the guidelines adopted pursuant to Article 32.

7.   The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation where it identifies additional cases of higher risk as referred to in paragraph 1 of this Article that affect the Union as a whole and enhanced due diligence measures that obliged entities are to apply in those cases, taking into account the notifications by Member States pursuant to paragraph 6, first subparagraph, of this Article.

8.   Enhanced due diligence measures shall not be invoked automatically with respect to branches or subsidiaries of obliged entities established in the Union which are located in third countries referred to in Articles 29, 30 and 31 where those branches or subsidiaries fully comply with the group-wide policies, procedures and controls in accordance with Article 17.

Article 35 Countermeasures to mitigate money laundering and terrorist financing threats from outside the Union

Article 35

Countermeasures to mitigate money laundering and terrorist financing threats from outside the Union

For the purposes of Articles 29 and 31, the Commission may choose from among the following countermeasures:

(a)

countermeasures that obliged entities are to apply to persons and legal entities involving high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in:

(i)

the application of additional elements of enhanced due diligence;

(ii)

the introduction of enhanced relevant reporting mechanisms or systematic reporting of financial transactions;

(iii)

the limitation of business relationships or transactions with natural persons or legal entities from those third countries;

(b)

countermeasures that Member States are to apply with regard to high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in:

(i)

refusing the establishment of subsidiaries or branches or representative offices of obliged entities from the country concerned, or otherwise taking into account the fact that the relevant obliged entity is from a third country that does not have adequate AML/CFT regimes;

(ii)

prohibiting obliged entities from establishing branches or representative offices in the third country concerned, or otherwise taking into account the fact that the relevant branch or representative office would be in a third country that does not have adequate AML/CFT regimes;

(iii)

requiring increased supervisory examination or increased external audit requirements for branches and subsidiaries of obliged entities located in the third country concerned;

(iv)

requiring increased external audit requirements for financial groups with respect to any of their branches and subsidiaries located in the third country concerned;

(v)

requiring credit institutions and financial institutions to review and amend, or if necessary terminate, correspondent relationships with respondent institutions in the third country concerned.

Article 36 Specific enhanced due diligence measures for cross-border correspondent relationships

Article 36

Specific enhanced due diligence measures for cross-border correspondent relationships

With respect to cross-border correspondent relationships, including relationships established for securities transactions or fund transfers, involving the execution of payments with a third-country respondent institution, in addition to the customer due diligence measures laid down in Article 20, credit institutions and financial institutions shall, when entering into a business relationship, be required to:

(a)

gather sufficient information about the respondent institution to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the institution and the quality of supervision;

(b)

assess the respondent institution’s AML/CFT controls;

(c)

obtain approval from senior management before establishing new correspondent relationships;

(d)

document the respective responsibilities of each institution;

(e)

with respect to payable-through accounts, be satisfied that the respondent institution has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent institution, and that it is able to provide relevant customer due diligence data to the correspondent institution, upon request.

Where credit institutions and financial institutions decide to terminate cross-border correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision.

Article 37 Specific enhanced due diligence measures for cross-border correspondent relationships for crypto-asset service providers

Article 37

Specific enhanced due diligence measures for cross-border correspondent relationships for crypto-asset service providers

1.   By way of derogation from Article 36, with respect to cross-border correspondent relationships involving the execution of crypto-asset services, with a respondent entity not established in the Union and providing similar services, including transfers of crypto-assets, crypto-asset service providers shall, in addition to the customer due diligence measures laid down in Article 20, when entering into a business relationship, be required to:

(a)

determine if the respondent entity is licensed or registered;

(b)

gather sufficient information about the respondent entity to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the entity and the quality of supervision;

(c)

assess the respondent entity’s AML/CFT controls;

(d)

obtain approval from senior management before establishing the new correspondent relationship;

(e)

document the respective responsibilities of each party to the correspondent relationship;

(f)

with respect to payable-through crypto-asset accounts, be satisfied that the respondent entity has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent entity, and that it is able to provide relevant customer due diligence data to the correspondent entity, upon request.

Where crypto-asset service providers decide to terminate correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision.

Crypto-asset service providers shall update the due diligence information for the correspondent relationship on a regular basis or when new risks emerge in relation to the respondent entity.

2.   Crypto-asset service providers shall take into account the information collected pursuant to paragraph 1 in order to determine, on a risk sensitive basis, the appropriate measures to be taken to mitigate the risks associated with the respondent entity.

3.   By 10 July 2027, AMLA shall issue guidelines to specify the criteria and elements that crypto-asset service providers shall take into account for conducting the assessment referred to in paragraph 1 and the risk mitigating measures referred to in paragraph 2, including the minimum action to be taken by crypto-asset service providers upon identification that the respondent entity is not registered or licensed.

Article 38 Specific measures for individual third-country respondent institutions

Article 38

Specific measures for individual third-country respondent institutions

1.   Credit institutions and financial institutions shall apply the measures laid down in paragraph 6 of this Article in relation to third-country respondent institutions with which they have a correspondent relationship pursuant to Articles 36 or 37 and in respect of which AMLA issues a recommendation pursuant to paragraph 2 of this Article.

2.   AMLA shall issue a recommendation addressed to credit institutions and financial institutions where there are concerns that respondent institutions in third countries fall into any of the following situations:

(a)

they are in serious, repeated or systematic breach of AML/CFT requirements;

(b)

they have weaknesses in their internal policies, procedures and controls that are likely to result in serious, repeated or systematic breaches of AML/CFT requirements;

(c)

they have in place internal policies, procedures and controls that are not commensurate with the risks of money laundering, its predicate offences and terrorist financing to which the third-country respondent institution is exposed.

3.   The recommendation referred to in paragraph 2 shall be issued where all of the following conditions are met:

(a)

on the basis of the information available in the context of its supervisory activities, a financial supervisor, including AMLA when performing its supervisory activities, deems that a third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship;

(b)

following an assessment of the information available to the financial supervisor referred to in point (a) of this paragraph, there is an agreement among financial supervisors in the Union that the third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship.

4.   Prior to issuing the recommendation referred to in paragraph 2, AMLA shall consult the third-country supervisor in charge of the respondent institution and request that it provides its own as well as the respondent institution’s views on the adequacy of AML/CFT policies, procedures and controls as well as of the customer due diligence measures the respondent institution has in place to mitigate risks of money laundering, its predicate offences and terrorist financing and remedial measures to be put in place. Where no reply is provided within 2 months or where the reply provided does not indicate that the third-country respondent institution can implement satisfactory AML/CFT policies, procedures and controls as well as apply adequate customer due diligence measures to mitigate the risks to which it is exposed that may affect the correspondent relationship, AMLA shall proceed with the recommendation.

5.   AMLA shall withdraw the recommendation referred to in paragraph 2 as soon as it considers that a third-country respondent institution on which it adopted that recommendation no longer fulfils the conditions laid down in paragraph 3.

6.   In relation to third-country respondent institutions referred to in paragraph 1, credit institutions and financial institutions shall:

(a)

abstain from entering into new business relationships with the third-country respondent institution unless they conclude, on the basis of the information collected under Article 36 or 37, that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship;

(b)

for ongoing business relationships with the third-country respondent institution:

(i)

review and update the information on the respondent institution pursuant to Articles 36 or 37;

(ii)

terminate the business relationship unless they conclude, on the basis of the information collected under point (i), that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship;

(c)

inform the respondent institution of the conclusions they have drawn in relation to the risks posed by the correspondent relationship following the recommendation by AMLA and the measures taken pursuant to points (a) or (b).

Where AMLA has withdrawn a recommendation pursuant to paragraph 5, credit institutions and financial institutions shall review their assessment as to whether the third-country respondent institutions fulfil any of the conditions laid down in paragraph 3.

7.   Credit institutions and financial institutions shall document any decision taken pursuant to this Article.

Article 39 Prohibition of correspondent relationships with shell institutions

Article 39

Prohibition of correspondent relationships with shell institutions

1.   Credit institutions and financial institutions shall not enter into, or continue, a correspondent relationship with a shell institution. Credit institutions and financial institutions shall take appropriate measures to ensure that they do not engage in or continue correspondent relationships with a credit institution or financial institution that is known to allow its accounts to be used by a shell institution.

2.   In addition to the requirement laid down in paragraph 1, crypto-asset service providers shall ensure that their accounts are not used by shell institutions to provide crypto-asset services. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls to detect any attempt to use their accounts for the provision of unregulated crypto-asset services.

Article 40 Measures to mitigate risks in relation to transactions with a self-hosted address

Article 40

Measures to mitigate risks in relation to transactions with a self-hosted address

1.   Crypto-asset service providers shall identify and assess the risk of money laundering and financing of terrorism associated with transfers of crypto-assets directed to or originating from a self-hosted address. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls.

Crypto-asset service providers shall apply mitigating measures commensurate with the risks identified. Those mitigating measures shall include one or more of the following:

(a)

taking risk-based measures to identify, and verify the identity of, the originator or beneficiary of a transfer made from or to a self-hosted address or beneficial owner of such originator or beneficiary, including through reliance on third parties;

(b)

requiring additional information on the origin and destination of the crypto-assets;

(c)

conducting enhanced ongoing monitoring of transactions with a self-hosted address;

(d)

any other measure to mitigate and manage the risks of money laundering and financing of terrorism as well as the risk of non-implementation and evasion of targeted financial sanctions.

2.   By 10 July 2027, AMLA shall issue guidelines to specify the mitigating measures referred to in paragraph 1, including:

(a)

the criteria and means for identification and verification of the identity of the originator or beneficiary of a transfer made from or to a self-hosted address, including through reliance on third parties, taking into account the latest technological developments;

(b)

criteria and means for the verification of whether or not the self-hosted address is owned or controlled by a customer.

Article 41 Specific provisions regarding applicants for residence by investment schemes

Article 41

Specific provisions regarding applicants for residence by investment schemes

In addition to the customer due diligence measures laid down in Article 20, with respect to customers who are third-country nationals who are in the process of applying for residence rights in a Member State in exchange for any kind of investment, including transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity contributing to the public good and contributions to the state budget, obliged entities shall, as a minimum, apply enhanced due diligence measures set out in Article 34(4), points (a), (c), (e) and (f).

Article 42 Specific provisions regarding politically exposed persons

Article 42

Specific provisions regarding politically exposed persons

1.   In addition to the customer due diligence measures laid down in Article 20, obliged entities shall apply the following measures with respect to occasional transactions or business relationships with politically exposed persons:

(a)

obtain senior management approval for carrying out occasional transactions or for establishing or continuing business relationships with politically exposed persons;

(b)

take adequate measures to establish the source of wealth and source of funds that are involved in business relationships or occasional transactions with politically exposed persons;

(c)

conduct enhanced, ongoing monitoring of those business relationships.

2.   By 10 July 2027, AMLA shall issue guidelines on the following matters:

(a)

the criteria for the identification of persons known to be close associates;

(b)

the level of risk associated with a particular category of politically exposed person, family member or person known to be a close associate, including guidance on how such risks are to be assessed where the person is no longer entrusted with a prominent public function for the purposes of Article 45.

Article 43 List of prominent public functions

Article 43

List of prominent public functions

1.   Each Member State shall issue and keep up-to-date a list indicating the exact functions which, in accordance with its national laws, regulations and administrative provisions, qualify as prominent public functions for the purposes of Article 2(1), point (34). Member States shall request each international organisation accredited on their territories to issue and keep up-to-date a list of prominent public functions at that international organisation for the purposes of Article 2(1), point (34). Those lists shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Member State level. Member States shall notify those lists, as well as any change made to them, to the Commission and to AMLA.

2.   The Commission may set out, by means of an implementing act, the format for the establishment and communication of the Member States’ lists of prominent public functions pursuant to paragraph 1. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

3.   The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement Article 2(1), point (34), where the lists notified by Member States pursuant to paragraph 1 identify common additional categories of prominent public functions and those categories of prominent public functions are of relevance for the Union as a whole.

When drawing up delegated acts pursuant to the first subparagraph, the Commission shall consult AMLA.

4.   The Commission shall draw up and keep up-to-date the list of the exact functions which qualify as prominent public functions at the level of the Union. That list shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Union level.

5.   The Commission shall assemble, based on the lists provided for in paragraphs 1 and 4 of this Article, a single list of all prominent public functions for the purposes of Article 2(1), point (34). The Commission shall publish that single list in the Official Journal of the European Union. AMLA shall make that list publicly available on its website.

Article 44 Politically exposed persons who are beneficiaries of insurance policies

Article 44

Politically exposed persons who are beneficiaries of insurance policies

Obliged entities shall take reasonable measures to determine whether the beneficiaries of a life or other investment-related insurance policy or, where relevant, the beneficial owner of the beneficiary are politically exposed persons. Those measures shall be taken no later than at the time of the payout or at the time of the assignment, in whole or in part, of the policy. Where there are higher risks identified, in addition to applying the customer due diligence measures laid down in Article 20, obliged entities shall:

(a)

inform senior management before payout of policy proceeds;

(b)

conduct enhanced scrutiny of the entire business relationship with the policyholder.

Article 45 Measures for persons who cease to be politically exposed persons

Article 45

Measures for persons who cease to be politically exposed persons

1.   Where a politically exposed person is no longer entrusted with a prominent public function by the Union, a Member State, third country or an international organisation, obliged entities shall take into account the continuing risk posed by that person, as a result of his or her former function, in their assessment of money laundering and terrorist financing risks in accordance with Article 20.

2.   Obliged entities shall apply one or more of the measures referred to in Article 34(4) to mitigate the risks posed by the politically exposed person until such time as the risks referred to in paragraph 1 of this Article no longer exist, but in any case for not less than 12 months following the time when the individual ceased to be entrusted with a prominent public function.

3.   The obligation referred to in paragraph 2 shall apply accordingly where an obliged entity carries out an occasional transaction or enters into a business relationship with a person who in the past was entrusted with a prominent public function by the Union, a Member State, third country or an international organisation.

Article 46 Family members and persons known to be close associates of politically exposed persons

Article 46

Family members and persons known to be close associates of politically exposed persons

The measures referred to in Articles 42, 44 and 45 shall also apply to family members or persons known to be close associates of politically exposed persons.

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Standards

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Standards

Standards
Source Anforderung
Impressum Deutsch Englisch