Emtract Ingest

Regulation source

Overview

Source URL
https://publications.europa.eu/resource/celex/32024R1624
Regulation
Anti-Money Laundering Regulation
Regulation crawler
FramesCube Manual Requests
Publish date
-
Updated date
-
Raw content
1.12 MB

Logs

Type Status Started at Finished at
Parse Finished 2026-08-27 22:29:49 UTC 2026-08-28 00:47:16 UTC

[INFO] [AiRegulationParser] asking LLM for regulation metadata (model: gpt-5.6-luna) for regulation_source 6244 https://publications.europa.eu/resource/celex/32024R1624

[INFO] [AiRegulationParser] asking LLM for obligations and penalties (model: gpt-5.6-luna) for regulation_source 6244 https://publications.europa.eu/resource/celex/32024R1624

[INFO] [AiRegulationParser] asking LLM for regulation links (model: gpt-5.6-luna) for regulation_source 6244 https://publications.europa.eu/resource/celex/32024R1624

[INFO] [AiRegulationParser] skipping attribute value assignment for regulation_source 6244 https://publications.europa.eu/resource/celex/32024R1624 - no extracted condition's attribute has attribute value definitions on file

[INFO] [AiRegulationParser] applying parse of regulation_source 6244 https://publications.europa.eu/resource/celex/32024R1624

[INFO] [AiRegulationParser] created regulation 187 (AMLR)

[INFO] [AiRegulationParser] created milestone 1246 (other 2025-01-10)

[INFO] [AiRegulationParser] created milestone 1247 (other 2026-07-10)

[INFO] [AiRegulationParser] created milestone 1248 (other 2027-07-10)

[INFO] [AiRegulationParser] created milestone 1249 (other 2027-10-10)

[INFO] [AiRegulationParser] created milestone 1250 (application_start 2027-07-10)

[INFO] [AiRegulationParser] created milestone 1251 (other 2028-01-10)

[INFO] [AiRegulationParser] created milestone 1252 (other 2029-07-10)

[INFO] [AiRegulationParser] created milestone 1253 (other 2029-07-10)

[INFO] [AiRegulationParser] created milestone 1254 (other 2030-07-10)

[INFO] [AiRegulationParser] created milestone 1255 (other 2030-07-10)

[INFO] [AiRegulationParser] created milestone 1256 (other 2032-07-10)

[INFO] [AiRegulationParser] created rule set 926 (Obliged companies and professional operators)

[INFO] [AiRegulationParser] created condition 2139 (company_role included_in)

[INFO] [AiRegulationParser] created rule set 927 (Football agents and professional football clubs)

[INFO] [AiRegulationParser] created condition 2140 (company_role included_in)

[INFO] [AiRegulationParser] created rule set 928 (Parent companies of obliged groups)

[INFO] [AiRegulationParser] created condition 2141 (is_parent_undertaking is_true)

[INFO] [AiRegulationParser] created rule set 929 (EU legal entities)

[INFO] [AiRegulationParser] created condition 2142 (company_legal_person is_true)

[INFO] [AiRegulationParser] created rule set 930 (Foreign legal entities with Union connections)

[INFO] [AiRegulationParser] created condition 2143 (is_third_country_undertaking is_true)

[INFO] [AiRegulationParser] created condition 2144 (market_or_service_entry included_in)

[INFO] [AiRegulationParser] created rule set 931 (Companies issuing or holding bearer shares)

[INFO] [AiRegulationParser] created condition 2145 (company_role included_in)

[INFO] [AiRegulationParser] created rule set 932 (Companies trading goods or providing services)

[INFO] [AiRegulationParser] created condition 2146 (company_role included_in)

[INFO] [AiRegulationParser] created obligation 2151 (Maintain internal AML/CFT policies and controls)

[INFO] [AiRegulationParser] created obligation 2152 (Perform and document a business-wide risk assessment)

[INFO] [AiRegulationParser] created obligation 2153 (Appoint and resource compliance functions)

[INFO] [AiRegulationParser] created obligation 2154 (Train and assess relevant personnel)

[INFO] [AiRegulationParser] created obligation 2155 (Apply customer due diligence)

[INFO] [AiRegulationParser] created obligation 2156 (Record customer due-diligence decisions and supporting evidence)

[INFO] [AiRegulationParser] created obligation 2157 (Report suspicious activity to the FIU)

[INFO] [AiRegulationParser] created obligation 2158 (Refrain from suspicious transactions pending FIU instructions)

[INFO] [AiRegulationParser] created obligation 2159 (Report beneficial-ownership discrepancies)

[INFO] [AiRegulationParser] created obligation 2160 (Maintain and report beneficial-ownership information)

[INFO] [AiRegulationParser] created obligation 2161 (Apply group-wide AML/CFT requirements)

[INFO] [AiRegulationParser] created obligation 2162 (Control and document outsourcing)

[INFO] [AiRegulationParser] created obligation 2163 (Retain AML/CFT records)

[INFO] [AiRegulationParser] created obligation 2164 (Avoid anonymous instruments and bearer shares)

[INFO] [AiRegulationParser] created obligation 2165 (Observe the large-cash payment limit)

[INFO] [AiRegulationParser] created measure 55 (Approve and publish internal AML/CFT policies)

[INFO] [AiRegulationParser] created measure 56 (Establish a compliance officer function)

[INFO] [AiRegulationParser] created measure 57 (Run customer and beneficial-owner screening)

[INFO] [AiRegulationParser] created measure 58 (Submit a suspicious-transaction report)

[INFO] [AiRegulationParser] created measure 59 (File beneficial-ownership register updates)

[INFO] [AiRegulationParser] created measure 60 (Convert or immobilise bearer shares)

[INFO] [AiRegulationParser] created penalty 295 (Member States must provide effective, proportionate and dissuasive penalties for breaches of the Regulation, with the specific penalty types and liable persons determined under national law.)

[INFO] [AiRegulationParser] created penalty 296 (Professional persons suspected of breaching the EUR 10,000 cash-payment limit, or a lower national limit, are subject to appropriate measures including penalties; the level must be proportionate to the seriousness of the infringement and discourage repetition.)

[INFO] [AiRegulationParser] created penalty 297 (Existing bearer shares that are not converted, immobilised or deposited by 10 July 2030 are automatically cancelled and the corresponding share capital is reduced; voting and distribution rights are suspended from the earlier compliance deadline until conversion, immobilisation or deposit.)

[INFO] [AiRegulationParser] created regulation link 1700 (supersedes Directive (EU) 2015/849)

[INFO] [AiRegulationParser] created regulation link 1701 (cites Directive (EU) 2018/843)

[INFO] [AiRegulationParser] created regulation link 1702 (related Directive (EU) 2024/1640)

[INFO] [AiRegulationParser] created regulation link 1703 (implements Regulation (EU) 2023/1113)

[INFO] [AiRegulationParser] created regulation link 1704 (related Regulation (EU) 2024/1620)

[INFO] [AiRegulationParser] created regulation link 1705 (cites Directive (EU) 2018/1673)

[INFO] [AiRegulationParser] created regulation link 1706 (cites Directive (EU) 2017/1371)

[INFO] [AiRegulationParser] created regulation link 1707 (cites Directive (EU) 2017/541)

[INFO] [AiRegulationParser] created regulation link 1708 (cites Directive (EU) 2016/97)

[INFO] [AiRegulationParser] created regulation link 1709 (cites Directive (EU) 2015/2366)

[INFO] [AiRegulationParser] created regulation link 1710 (cites Regulation (EU) 2023/1114)

[INFO] [AiRegulationParser] created regulation link 1711 (cites Regulation (EU) 2020/1503)

[INFO] [AiRegulationParser] created regulation link 1712 (cites Directive 2009/65/EC)

[INFO] [AiRegulationParser] created regulation link 1713 (cites Directive 2011/61/EU)

[INFO] [AiRegulationParser] created regulation link 1714 (cites Regulation (EU) No 575/2013)

[INFO] [AiRegulationParser] created regulation link 1715 (cites Regulation (EU) No 910/2014)

[INFO] [AiRegulationParser] created regulation link 1716 (cites Directive 2014/92/EU)

[INFO] [AiRegulationParser] created regulation link 1717 (cites Directive 2013/34/EU)

[INFO] [AiRegulationParser] created regulation link 1718 (cites Directive (EU) 2016/2341)

[INFO] [AiRegulationParser] created regulation link 1719 (cites Directive 2004/109/EC)

[INFO] [AiRegulationParser] created regulation link 1720 (cites Regulation (EU) 2016/679)

[INFO] [AiRegulationParser] created regulation link 1721 (cites Regulation (EU) No 182/2011)

[INFO] [AiRegulationParser] created regulation link 1722 (cites Directive 2013/36/EU)

[INFO] [AiRegulationParser] created regulation link 1723 (cites Directive 2009/138/EC)

[INFO] [AiRegulationParser] created regulation link 1724 (cites Directive 2014/65/EU)

[INFO] [AiRegulationParser] created regulation link 1725 (cites Regulation (EU) No 909/2014)

[INFO] [AiRegulationParser] created regulation link 1726 (cites Directive 2014/17/EU)

[INFO] [AiRegulationParser] created regulation link 1727 (cites Directive 2008/48/EC)

[INFO] [AiRegulationParser] created regulation link 1728 (cites Directive 2009/110/EC)

[INFO] [AiRegulationParser] created regulation link 1729 (cites Regulation (EU) 2018/1672)

[INFO] [AiRegulationParser] created regulation link 1730 (cites Council Regulation (EC) No 116/2009)

[INFO] [AiRegulationParser] created regulation link 1731 (implements Whistleblower Protection Directive)

[INFO] [AiRegulationParser] created regulation link 1732 (cites Council Directive 2011/16/EU)

[INFO] [AiRegulationParser] created regulation link 1733 (cites Directive 2014/24/EU)

[INFO] [AiRegulationParser] created regulation link 1734 (cites Directive (EU) 2016/680)

[INFO] [AiRegulationParser] created regulation link 1735 (cites Regulation (EU) 2024/xxx)

[INFO] [AiRegulationParser] created regulation link 1736 (cites Regulation (EU) 2015/751)

[INFO] [AiRegulationParser] created regulation link 1737 (cites Council Decision 98/415/EC)

[INFO] [AiRegulationParser] created regulation link 1738 (cites Regulation (EU) 2017/1939)

[INFO] [AiRegulationParser] created regulation link 1739 (cites Regulation (EU, Euratom) No 883/2013)

[INFO] [AiRegulationParser] created regulation link 1740 (cites Council Decision 2010/413/CFSP)

[INFO] [AiRegulationParser] created regulation link 1741 (cites Council Decision (CFSP) 2016/849)

[INFO] [AiRegulationParser] created regulation link 1742 (cites Council Regulation (EU) No 267/2012)

[INFO] [AiRegulationParser] created regulation link 1743 (cites Council Regulation (EU) 2017/1509)

[INFO] [AiRegulationParser] parsed regulation 187 with 11 milestones, 7 rule sets, 15 obligations, and 3 penalties

Download Finished 2026-08-27 15:39:54 UTC 2026-08-27 22:29:48 UTC

[INFO] [Crawlers::ReverseMarkdownRegulationDownloader] downloading source from https://publications.europa.eu/resource/celex/32024R1624

[INFO] [Crawlers::ReverseMarkdownRegulationDownloader] converted HTML to Markdown (450985 source bytes) from https://publications.europa.eu/resource/celex/32024R1624

[INFO] [Crawlers::EurlexRegulationCrawler] downloaded regulation_source 6244 from https://publications.europa.eu/resource/celex/32024R1624

[INFO] [Crawlers::EurlexRegulationCrawler] parsed 408 norms for https://publications.europa.eu/resource/celex/32024R1624

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 6 norms

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 56 norms

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 52 norms

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 54 norms

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 52 norms

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 63 norms

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 56 norms

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 65 norms

[INFO] [AiMarkdownNormsExtractor] asking LLM to translate 4 norms

[INFO] [AiMarkdownNormsExtractor] translated 408 norms for https://publications.europa.eu/resource/celex/32024R1624

Norms

CHAPTER I — GENERAL PROVISIONS CHAPTER I — GENERAL PROVISIONS CHAPTER I — ALLGEMEINE BESTIMMUNGEN
SECTION 1 — Subject matter and definitions SECTION 1 — Subject matter and definitions SECTION 1 — Gegenstand und Begriffsbestimmungen
Article 1 — Subject matter Article 1 — Subject matter Article 1 — Gegenstand

This Regulation lays down rules concerning:

  • (a) the measures to be applied by obliged entities to prevent money laundering and terrorist financing;
  • (b) beneficial ownership transparency requirements for legal entities, express trusts and similar legal arrangements;
  • (c) measures to limit the misuse of anonymous instruments.

This Regulation lays down rules concerning:

  • (a) the measures to be applied by obliged entities to prevent money laundering and terrorist financing;
  • (b) beneficial ownership transparency requirements for legal entities, express trusts and similar legal arrangements;
  • (c) measures to limit the misuse of anonymous instruments.

Diese Verordnung legt Vorschriften fest über:

  • a) die von Verpflichteten anzuwendenden Maßnahmen zur Verhinderung von Geldwäsche und Terrorismusfinanzierung;
  • b) Transparenzanforderungen hinsichtlich der wirtschaftlichen Eigentümer juristischer Personen, ausdrücklicher Trusts und ähnlicher Rechtsvereinbarungen;
  • c) Maßnahmen zur Begrenzung des Missbrauchs anonymer Instrumente.
Article 2 — Definitions Article 2 — Definitions Article 2 — Begriffsbestimmungen
1 1 1

For the purposes of this Regulation, the following definitions apply:

  • (1) money laundering means the conduct set out in Article 3, paragraphs 1 and 5, of Directive (EU) 2018/1673 including aiding and abetting, inciting and attempting to commit that conduct, whether the activities which generated the property to be laundered were carried out on the territory of a Member State or on that of a third country; knowledge, intent or purpose required as an element of that conduct may be inferred from objective factual circumstances;
  • (2) terrorist financing means the conduct set out in Article 11 of Directive (EU) 2017/541 including aiding and abetting, inciting and attempting to commit that conduct, whether carried out on the territory of a Member State or on that of a third country; knowledge, intent or purpose required as an element of that conduct may be inferred from objective factual circumstances;
  • (3) criminal activity means criminal activity as defined in Article 2, point (1), of Directive (EU) 2018/1673, as well as fraud affecting the Union’s financial interests as defined in Article 3(2) of Directive (EU) 2017/1371, passive and active corruption as defined in Article 4 (2) and misappropriation as defined in Article 4(3), second subparagraph, of that Directive;
  • (4) funds or property means property as defined in Article 2, point (2), of Directive (EU) 2018/1673;
  • (5) credit institution means:

    • (a) a credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013;
    • (b) a branch of a credit institution, as defined in Article 4(1), point (17), of Regulation (EU) No 575/2013, when located in the Union, whether its head office is located in a Member State or in a third country;
  • (6) financial institution means:

    • (a) an undertaking other than a credit institution or an investment firm, which carries out one or more of the activities listed in points (2) to (12), (14) and (15) of Annex I to Directive 2013/36/EU of the European Parliament and of the Council

Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (OJ L 176, 27.6.2013, p. 338).

, including the activities of currency exchange offices (bureaux de change), but excluding the activities referred to in point (8) of Annex I to Directive (EU) 2015/2366, or an undertaking the principal activity of which is to acquire holdings, including a financial holding company, a mixed financial holding company and a financial mixed activity holding company;
- (b) an insurance undertaking as defined in Article 13, point (1), of Directive 2009/138/EC of the European Parliament and of the Council

Directive 2009/138/EC of the European Parliament and of the Council of 25 November 2009 on the taking-up and pursuit of the business of Insurance and Reinsurance (Solvency II) (OJ L 335, 17.12.2009, p. 1).

, insofar as it carries out life or other investment-related assurance activities covered by that Directive, including insurance holding companies and mixed-activity insurance holding companies as defined, respectively, in Article 212(1), points (f) and (g), of Directive 2009/138/EC;
- (c) an insurance intermediary as defined in Article 2(1), point (3), of Directive (EU) 2016/97 where it acts with respect to life insurance and other investment-related insurance services, with the exception of an insurance intermediary that does not collect premiums or amounts intended for the customer and which acts under the responsibility of one or more insurance undertakings or intermediaries for the products which concern them respectively;
- (d) an investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU of the European Parliament and of the Council

Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU (OJ L 173, 12.6.2014, p. 349).

;
- (e) a collective investment undertaking, in particular:

- **(i)** an undertaking for collective investment in transferable securities (UCITS) as defined in Article 1(2) of Directive 2009/65/EC and its management company as defined in Article 2(1), point (b), of that Directive or an investment company authorised in accordance with that Directive and which has not designated a management company, that makes available for purchase units of UCITS in the Union; 
- **(ii)** an alternative investment fund as defined in Article 4(1), point (a), of Directive 2011/61/EU and its alternative investment fund manager as defined in Article 4(1), point (b), of that Directive that fall within the scope set out in Article 2 of that Directive; 
  • (f) a central securities depository as defined in Article 2(1), point (1), of Regulation (EU) No 909/2014 of the European Parliament and of the Council

Regulation (EU) No 909/2014 of the European Parliament and of the Council of 23 July 2014 on improving securities settlement in the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU) No 236/2012 (OJ L 257, 28.8.2014, p. 1).

;
- (g) a creditor as defined in Article 4, point (2), of Directive 2014/17/EU of the European Parliament and of the Council

Directive 2014/17/EU of the European Parliament and of the Council of 4 February 2014 on credit agreements for consumers relating to residential immovable property and amending Directives 2008/48/EC and 2013/36/EU and Regulation (EU) No 1093/2010 (OJ L 60, 28.2.2014, p. 34).

and in Article 3, point (b), of Directive 2008/48/EC of the European Parliament and of the Council

Directive 2008/48/EC of the European Parliament and of the Council of 23 April 2008 on credit agreements for consumers and repealing Council Directive 87/102/EEC (OJ L 133, 22.5.2008, p. 66).

;
- (h) a credit intermediary as defined in Article 4, point (5), of Directive 2014/17/EU and in Article 3, point (f), of Directive 2008/48/EC, when holding the funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 in connection with the credit agreement, with the exception of the credit intermediary carrying out activities under the responsibility of one or more creditors or credit intermediaries;
- (i) a crypto-asset service provider;
- (j) a branch of a financial institution referred to in points (a) to (i), when located in the Union, whether its head office is located in a Member State or in a third country;

  • (7) crypto-asset means a crypto-asset as defined in Article 3(1), point (5), of Regulation (EU) 2023/1114 except when falling under the categories listed in Article 2(4) of that Regulation;
  • (8) crypto-asset services means crypto-asset services as defined in Article 3(1), point (16), of Regulation (EU) 2023/1114, with the exception of providing advice on crypto-assets as referred to in Article 3(1), point (16)(h), of that Regulation;
  • (9) crypto-asset service provider means a crypto-asset service provider as defined in Article 3(1), point (15), of Regulation (EU) 2023/1114 where performing one or more crypto-asset services;
  • (10) financial mixed activity holding company means an undertaking, other than a financial holding company or a mixed financial holding company, which is not the subsidiary of another undertaking, the subsidiaries of which include at least one credit institution or financial institution;
  • (11) trust or company service provider means any natural or legal person that, by way of its business, provides any of the following services to third parties:

    • (a) the formation of companies or other legal persons;
    • (b) acting as, or arranging for another person to act as, a director or secretary of a company, a partner of a partnership, or a similar position in relation to other legal persons;
    • (c) providing a registered office, business address, correspondence address or administrative address, as well as other related services for a company, a partnership or any other legal person or legal arrangement;
    • (d) acting as, or arranging for another person to act as, a trustee of an express trust or performing an equivalent function for a similar legal arrangement;
    • (e) acting as, or arranging for another person to act as, a nominee shareholder for another person;
  • (12) gambling service means a service which involves wagering a stake with monetary value in games of chance, including those with an element of skill, such as lotteries, casino games, poker games and betting transactions that are provided at a physical location, or by any means at a distance, by electronic means or any other technology for facilitating communication, and at the individual request of a recipient of services;

  • (13) non-financial mixed activity holding company means an undertaking, other than a financial holding company or a mixed financial holding company, which is not the subsidiary of another undertaking, the subsidiaries of which include at least one obliged entity as referred to in Article 3, point (3);

  • (14) self-hosted address means a self-hosted address as defined in Article 3, point (20), of Regulation (EU) 2023/1113;

  • (15) crowdfunding service provider means a crowdfunding service provider as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503;

  • (16) crowdfunding intermediary means an undertaking other than a crowdfunding service provider the business of which is to match or facilitate the matching, through an internet-based information system open to the public or to a limited number of funders, of:

    • (a) project owners, which are any natural or legal person seeking funding for projects, consisting of one or a set of predefined operations aiming at a particular objective, including fundraising for a particular cause or event irrespective of whether those projects are proposed to the public or to a limited number of funders; and
    • (b) funders, which are any natural or legal person contributing to the funding of projects, through loans, with or without interest, or donations, including where such donations entitle the donor to a non-material benefit;
  • (17) electronic money means electronic money as defined in Article 2, point (2), of Directive 2009/110/EC of the European Parliament and of the Council

Directive 2009/110/EC of the European Parliament and of the Council of 16 September 2009 on the taking up, pursuit and prudential supervision of the business of electronic money institutions amending Directives 2005/60/EC and 2006/48/EC and repealing Directive 2000/46/EC (OJ L 267, 10.10.2009, p. 7).

, but excluding monetary value as referred to in Article 1(4) and (5) of that Directive;
- (18) establishment means the actual pursuit by an obliged entity of an economic activity covered by Article 3 in a Member State or third country other than the country where its head office is located for an indefinite period and through a stable infrastructure, including:

  • (a) a branch or subsidiary;
  • (b) in the case of credit institutions and financial institutions, an infrastructure qualifying as an establishment under prudential regulation;

    • (19) business relationship means a business, professional or commercial relationship connected with the professional activities of an obliged entity, which is set up between an obliged entity and a customer, including in the absence of a written contract and which is expected to have, at the time when the contact is established, or which subsequently acquires, an element of repetition or duration;
    • (20) linked transactions means two or more transactions with either identical or similar origin, destination and purpose, or other relevant characteristics, over a specific period;
    • (21) third country means any jurisdiction, independent state or autonomous territory that is not part of the Union and that has its own AML/CFT legislation or enforcement regime;
    • (22) correspondent relationship means:
  • (a) the provision of banking services by one credit institution as the correspondent to another credit institution as the respondent, including providing a current or other liability account and related services, such as cash management, international transfers of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366, cheque clearing, payable-through accounts and foreign exchange services;

  • (b) the relationships between and among credit institutions and financial institutions including where similar services are provided by a correspondent institution to a respondent institution, and including relationships established for securities transactions or transfers of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366, transactions in crypto-assets or transfers of crypto-assets;

    • (23) shell institution means:
  • (a) for credit institutions and financial institutions other than crypto-asset service providers: a credit institution or financial institution, or an institution that carries out activities equivalent to those carried out by credit institutions and financial institutions, created in a jurisdiction in which it has no physical presence, involving meaningful mind and management, and which is unaffiliated with a regulated financial group;

  • (b) for crypto-asset service providers: an entity whose name appears in the register established by the European Securities and Markets Authority pursuant to Article 110 of Regulation (EU) 2023/1114 or third country entity providing crypto-asset services without being licensed or registered nor subject to AML/CFT supervision there;

    • (24) crypto-asset account means a crypto-asset account as defined in Article 3, point (19), of Regulation (EU) 2023/1113;
    • (25) anonymity-enhancing coins means crypto-assets that have built-in features designed to make crypto-asset transfer information anonymous, either systematically or optionally;
    • (26) virtual IBAN means an identifier causing payments to be redirected to a payment account identified by an IBAN different from that identifier;
    • (27) Legal Entity Identifier means a unique alphanumeric reference code based on the ISO 17442 standard assigned to a legal entity;
    • (28) beneficial owner means any natural person who ultimately owns or controls a legal entity or an express trust or similar legal arrangement;
    • (29) express trust means a trust intentionally set up by the settlor, inter vivos or on death, usually in a form of written document, to place assets under the control of a trustee for the benefit of a beneficiary or for a specified purpose;
    • (30) objects of a power means the natural or legal persons or class of natural or legal persons among whom trustees may select the beneficiaries in a discretionary trust;
    • (31) default taker means the natural or legal persons or class of natural or legal persons who are the beneficiaries of a discretionary trust should the trustees fail to exercise their discretion;
    • (32) legal arrangement means an express trust or an arrangement which has a similar structure or function to an express trust, including fiducie and certain types of Treuhand and fideicomiso;
    • (33) basic information means:
  • (a) in relation to a legal entity:

    • (i) legal form and name of the legal entity;
    • (ii) instrument of constitution, and the statutes if they are contained in a separate instrument;
    • (iii) address of the registered or official office and, if different, the principal place of business, and the country of creation;
    • (iv) a list of legal representatives;
    • (v) where applicable, a list of shareholders or members, including information on the number of shares held by each shareholder and the categories of those shares and the nature of the associated voting rights;
    • (vi) where available, the registration number, the European Unique identifier, the tax identification number and the Legal Entity Identifier;
    • (vii) in the case of foundations, the assets held by the foundation to pursue its purposes;
  • (b) in relation to a legal arrangement:

    • (i) the name or unique identifier of the legal arrangement;
    • (ii) the trust deed or equivalent;
    • (iii) the purposes of the legal arrangement, if any;
    • (iv) the assets held in the legal arrangement or managed through it;
    • (v) the place of residence of the trustees of the express trust or persons holding equivalent positions in the similar legal arrangement, and, if different, the place from where the express trust or similar legal arrangement is administered;
    • (34) politically exposed person means a natural person who is or has been entrusted with prominent public functions including:
  • (a) in a Member State:

    • (i) heads of State, heads of government, ministers and deputy or assistant ministers;
    • (ii) members of parliament or of similar legislative bodies;
    • (iii) members of the governing bodies of political parties that hold seats in national executive or legislative bodies, or in regional or local executive or legislative bodies representing constituencies of at least 50000 inhabitants;
    • (iv) members of supreme courts, of constitutional courts or of other high-level judicial bodies, the decisions of which are not subject to further appeal, except in exceptional circumstances;
    • (v) members of courts of auditors or of the boards of central banks;
    • (vi) ambassadors, chargés d’affaires and high-ranking officers in the armed forces;
    • (vii) members of the administrative, management or supervisory bodies of enterprises controlled under any of the relationships listed in Article 22 of Directive 2013/34/EU either by the state, or, where those enterprises qualify as medium sized or large undertakings or medium sized or large groups, as defined in Article 3(3), (4), (6) and (7) of that Directive, by regional or local authorities;
    • (viii) heads of regional and local authorities, including groupings of municipalities and metropolitan regions, with at least 50000 inhabitants;
    • (ix) other prominent public functions provided for by Member States;
  • (b) in an international organisation:

    • (i) the highest ranking officials, their deputies and members of the board or equivalent functions of an international organisation;
    • (ii) representatives to a Member State or to the Union;
  • (c) at Union level:

functions at the level of Union institutions and bodies that are equivalent to those listed in points (a) (i), (ii), (iv), (v) and (vi);

  • (d) in a third country:

functions that are equivalent to those listed in point (a);

  • (35) family member means:

    • (a) a spouse, or a person in a registered partnership or civil union or in a similar arrangement;
    • (b) a child and a spouse of, or a person in a registered partnership or civil union or in a similar arrangement with, that child;
    • (c) a parent;
    • (d) for the functions referred to in point (34)(a)(i) and equivalent functions at Union level or in a third country, a sibling;
  • (36) person known to be a close associate means:

    • (a) a natural person who is known to have joint beneficial ownership of legal entities or legal arrangements, or any other close business relations, with a politically exposed person;
    • (b) a natural person who has sole beneficial ownership of a legal entity or legal arrangement which is known to have been set up for the de facto benefit of a politically exposed person;
  • (37) management body means an obliged entity’s body or bodies, which are appointed in accordance with national law, which are empowered to set the obliged entity’s strategy, objectives and overall direction, and which oversee and monitor management decision-making, and include the persons who effectively direct the business of the obliged entity; where no such body exists, the person who effectively directs the business of the obliged entity;

  • (38) management body in its management function means the management body responsible for the day-to-day management of the obliged entity;

  • (39) management body in its supervisory function means the management body acting in its role of overseeing and monitoring management decision-making;

  • (40) senior management means the members of the management body in its management function, as well as officers and employees with sufficient knowledge of the obliged entity’s money laundering and terrorist financing risk exposure and sufficient seniority to take decisions affecting its risk exposure;

  • (41) group means a group of undertakings which consists of a parent undertaking, its subsidiaries, as well as undertakings linked to each other by a relationship within the meaning of Article 22 of Directive 2013/34/EU;

  • (42) parent undertaking means:

    • (a) for groups whose head office is located in the Union, an obliged entity that is a parent undertaking as defined in Article 2, point (9), of Directive 2013/34/EU that is not itself a subsidiary of another undertaking in the Union, provided that at least one subsidiary undertaking is an obliged entity;
    • (b) for groups whose head office is located outside of the Union, where at least two subsidiary undertakings are obliged entities established in the Union, an undertaking within that group established in the Union that:
    • (i) is an obliged entity;
    • (ii) is an undertaking that is not a subsidiary of another undertaking that is an obliged entity established in the Union;
    • (iii) has a sufficient prominence within the group and a sufficient understanding of the operations of the group that are subject to the requirements of this Regulation; and
    • (iv) is given the responsibility of implementing group-wide requirements under Chapter II, Section 2 of this Regulation;
  • (43) cash means cash as defined in Article 2(1), point (a), of Regulation (EU) 2018/1672 of the European Parliament and of the Council

Regulation (EU) 2018/1672 of the European Parliament and of the Council of 23 October 2018 on controls on cash entering or leaving the Union and repealing Regulation (EC) No 1889/2005 (OJ L 284, 12.11.2018, p. 6).

;
- (44) competent authority means:

  • (a) a Financial Intelligence Unit (FIU);
  • (b) a supervisory authority;
  • (c) a public authority that has the function of investigating or prosecuting money laundering, its predicate offences or terrorist financing, or that has the function of tracing, seizing or freezing and confiscating criminal assets;
  • (d) a public authority with designated responsibilities for combating money laundering or terrorist financing;

    • (45) supervisor means the body entrusted with responsibilities aimed at ensuring compliance by obliged entities with the requirements of this Regulation, including AMLA when performing the tasks entrusted to it in Article 5(2) of Regulation (EU) 2024/1620;
    • (46) supervisory authority means a supervisor who is a public body, or the public authority overseeing self-regulatory bodies in their performance of supervisory functions pursuant to Article 37 of Directive (EU) 2024/1640, or AMLA when acting as a supervisor;
    • (47) self-regulatory body means a body that represents members of a profession and has a role in regulating them, in performing certain supervisory or monitoring functions and in ensuring the enforcement of the rules relating to them;
    • (48) funds or other assets means any assets, including, but not limited to, financial assets, economic resources, including oil and other natural resources, property of every kind, whether tangible or intangible, movable or immovable, however acquired, and legal documents or instruments in any form, including electronic or digital, evidencing title to, or interest in, such funds or other assets, including, but not limited to, bank credits, travellers cheques, bank cheques, money orders, shares, securities, bonds, drafts, or letters of credit, and any interest, dividends or other income on or value accruing from or generated by such funds or other assets, and any other assets which potentially may be used to obtain funds, goods or services;
    • (49) targeted financial sanctions means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated persons and entities pursuant to Council Decisions adopted on the basis of Article 29 TEU and Council Regulations adopted on the basis of Article 215 TFEU;
    • (50) UN financial sanctions means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated or listed persons and entities pursuant to:
  • (a) UNSC Resolution 1267 (1999) and its successor resolutions;

  • (b) UNSC Resolution 1373 (2001), including the determination that the relevant sanctions will be applied to the person or entity and the public communication of that determination;

  • (c) UN financial sanctions relating to proliferation financing;

    • (51) UN financial sanctions relating to proliferation financing means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated or listed persons and entities pursuant to:
  • (a) UNSC Resolution 1718 (2006) and any successor resolutions;

  • (b) UNSC Resolution 2231 (2015) and any successor resolutions;

  • (c) any other UNSC resolutions imposing asset freezing and prohibitions to make funds or other assets available in relation to the financing of proliferation of weapons of mass destruction;

    • (52) professional football club means any legal person that is, owns or manages a football club that has been granted a licence and participates in the national football leagues in a Member State and whose players and staff are contractually engaged and are remunerated in exchange for their services;
    • (53) football agent means a natural or legal person who, for a fee, provides intermediary services and represents football players or professional football clubs in negotiations with a view to concluding a contract for a football player or represents professional football clubs in negotiations with a view to concluding an agreement for the transfer of a football player;
    • (54) high-value goods means goods listed in Annex IV;
    • (55) precious metals and stones means metals and stones listed in Annex V;
    • (56) cultural goods means goods listed in Annex I to Council Regulation (EC) No 116/2009

Council Regulation (EC) No 116/2009 of 18 December 2008 on the export of cultural goods (OJ L 39, 10.2.2009, p. 1).

;
- (57) partnership for information sharing means a mechanism that enables the sharing and processing of information between obliged entities and, where applicable, competent authorities referred to in point 44(a), (b) and (c), for the purposes of preventing and combating money laundering, its predicate offences and terrorist financing, whether at national level or on a cross-border basis, and regardless of the form of that partnership.

For the purposes of this Regulation, the following definitions apply:

  • (1) money laundering means the conduct set out in Article 3, paragraphs 1 and 5, of Directive (EU) 2018/1673 including aiding and abetting, inciting and attempting to commit that conduct, whether the activities which generated the property to be laundered were carried out on the territory of a Member State or on that of a third country; knowledge, intent or purpose required as an element of that conduct may be inferred from objective factual circumstances;
  • (2) terrorist financing means the conduct set out in Article 11 of Directive (EU) 2017/541 including aiding and abetting, inciting and attempting to commit that conduct, whether carried out on the territory of a Member State or on that of a third country; knowledge, intent or purpose required as an element of that conduct may be inferred from objective factual circumstances;
  • (3) criminal activity means criminal activity as defined in Article 2, point (1), of Directive (EU) 2018/1673, as well as fraud affecting the Union’s financial interests as defined in Article 3(2) of Directive (EU) 2017/1371, passive and active corruption as defined in Article 4(2) and misappropriation as defined in Article 4(3), second subparagraph, of that Directive;
  • (4) funds or property means property as defined in Article 2, point (2), of Directive (EU) 2018/1673;
  • (5) credit institution means:
    • (a) a credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013;
    • (b) a branch of a credit institution, as defined in Article 4(1), point (17), of Regulation (EU) No 575/2013, when located in the Union, whether its head office is located in a Member State or in a third country;
  • (6) financial institution means:
    • (a) an undertaking other than a credit institution or an investment firm, which carries out one or more of the activities listed in points (2) to (12), (14) and (15) of Annex I to Directive 2013/36/EU of the European Parliament and of the Council, including the activities of currency exchange offices (bureaux de change), but excluding the activities referred to in point (8) of Annex I to Directive (EU) 2015/2366, or an undertaking the principal activity of which is to acquire holdings, including a financial holding company, a mixed financial holding company and a financial mixed activity holding company;
    • (b) an insurance undertaking as defined in Article 13, point (1), of Directive 2009/138/EC of the European Parliament and of the Council, insofar as it carries out life or other investment-related assurance activities covered by that Directive, including insurance holding companies and mixed-activity insurance holding companies as defined, respectively, in Article 212(1), points (f) and (g), of Directive 2009/138/EC;
    • (c) an insurance intermediary as defined in Article 2(1), point (3), of Directive (EU) 2016/97 where it acts with respect to life insurance and other investment-related insurance services, with the exception of an insurance intermediary that does not collect premiums or amounts intended for the customer and which acts under the responsibility of one or more insurance undertakings or intermediaries for the products which concern them respectively;
    • (d) an investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU of the European Parliament and of the Council;
    • (e) a collective investment undertaking, in particular:
    • (i) an undertaking for collective investment in transferable securities (UCITS) as defined in Article 1(2) of Directive 2009/65/EC and its management company as defined in Article 2(1), point (b), of that Directive or an investment company authorised in accordance with that Directive and which has not designated a management company, that makes available for purchase units of UCITS in the Union;
    • (ii) an alternative investment fund as defined in Article 4(1), point (a), of Directive 2011/61/EU and its alternative investment fund manager as defined in Article 4(1), point (b), of that Directive that fall within the scope set out in Article 2 of that Directive;
    • (f) a central securities depository as defined in Article 2(1), point (1), of Regulation (EU) No 909/2014 of the European Parliament and of the Council;
    • (g) a creditor as defined in Article 4, point (2), of Directive 2014/17/EU of the European Parliament and of the Council and in Article 3, point (b), of Directive 2008/48/EC of the European Parliament and of the Council;
    • (h) a credit intermediary as defined in Article 4, point (5), of Directive 2014/17/EU and in Article 3, point (f), of Directive 2008/48/EC, when holding the funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 in connection with the credit agreement, with the exception of the credit intermediary carrying out activities under the responsibility of one or more creditors or credit intermediaries;
    • (i) a crypto-asset service provider;
    • (j) a branch of a financial institution referred to in points (a) to (i), when located in the Union, whether its head office is located in a Member State or in a third country;
  • (7) crypto-asset means a crypto-asset as defined in Article 3(1), point (5), of Regulation (EU) 2023/1114 except when falling under the categories listed in Article 2(4) of that Regulation;
  • (8) crypto-asset services means crypto-asset services as defined in Article 3(1), point (16), of Regulation (EU) 2023/1114, with the exception of providing advice on crypto-assets as referred to in Article 3(1), point (16)(h), of that Regulation;
  • (9) crypto-asset service provider means a crypto-asset service provider as defined in Article 3(1), point (15), of Regulation (EU) 2023/1114 where performing one or more crypto-asset services;
  • (10) financial mixed activity holding company means an undertaking, other than a financial holding company or a mixed financial holding company, which is not the subsidiary of another undertaking, the subsidiaries of which include at least one credit institution or financial institution;
  • (11) trust or company service provider means any natural or legal person that, by way of its business, provides any of the following services to third parties:
    • (a) the formation of companies or other legal persons;
    • (b) acting as, or arranging for another person to act as, a director or secretary of a company, a partner of a partnership, or a similar position in relation to other legal persons;
    • (c) providing a registered office, business address, correspondence address or administrative address, as well as other related services for a company, a partnership or any other legal person or legal arrangement;
    • (d) acting as, or arranging for another person to act as, a trustee of an express trust or performing an equivalent function for a similar legal arrangement;
    • (e) acting as, or arranging for another person to act as, a nominee shareholder for another person;
  • (12) gambling service means a service which involves wagering a stake with monetary value in games of chance, including those with an element of skill, such as lotteries, casino games, poker games and betting transactions that are provided at a physical location, or by any means at a distance, by electronic means or any other technology for facilitating communication, and at the individual request of a recipient of services;
  • (13) non-financial mixed activity holding company means an undertaking, other than a financial holding company or a mixed financial holding company, which is not the subsidiary of another undertaking, the subsidiaries of which include at least one obliged entity as referred to in Article 3, point (3);
  • (14) self-hosted address means a self-hosted address as defined in Article 3, point (20), of Regulation (EU) 2023/1113;
  • (15) crowdfunding service provider means a crowdfunding service provider as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503;
  • (16) crowdfunding intermediary means an undertaking other than a crowdfunding service provider the business of which is to match or facilitate the matching, through an internet-based information system open to the public or to a limited number of funders, of:
    • (a) project owners, which are any natural or legal person seeking funding for projects, consisting of one or a set of predefined operations aiming at a particular objective, including fundraising for a particular cause or event irrespective of whether those projects are proposed to the public or to a limited number of funders; and
    • (b) funders, which are any natural or legal person contributing to the funding of projects, through loans, with or without interest, or donations, including where such donations entitle the donor to a non-material benefit;
  • (17) electronic money means electronic money as defined in Article 2, point (2), of Directive 2009/110/EC of the European Parliament and of the Council, but excluding monetary value as referred to in Article 1(4) and (5) of that Directive;
  • (18) establishment means the actual pursuit by an obliged entity of an economic activity covered by Article 3 in a Member State or third country other than the country where its head office is located for an indefinite period and through a stable infrastructure, including:
    • (a) a branch or subsidiary;
    • (b) in the case of credit institutions and financial institutions, an infrastructure qualifying as an establishment under prudential regulation;
  • (19) business relationship means a business, professional or commercial relationship connected with the professional activities of an obliged entity, which is set up between an obliged entity and a customer, including in the absence of a written contract and which is expected to have, at the time when the contact is established, or which subsequently acquires, an element of repetition or duration;
  • (20) linked transactions means two or more transactions with either identical or similar origin, destination and purpose, or other relevant characteristics, over a specific period;
  • (21) third country means any jurisdiction, independent state or autonomous territory that is not part of the Union and that has its own AML/CFT legislation or enforcement regime;
  • (22) correspondent relationship means:
    • (a) the provision of banking services by one credit institution as the correspondent to another credit institution as the respondent, including providing a current or other liability account and related services, such as cash management, international transfers of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366, cheque clearing, payable-through accounts and foreign exchange services;
    • (b) the relationships between and among credit institutions and financial institutions including where similar services are provided by a correspondent institution to a respondent institution, and including relationships established for securities transactions or transfers of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366, transactions in crypto-assets or transfers of crypto-assets;
  • (23) shell institution means:
    • (a) for credit institutions and financial institutions other than crypto-asset service providers: a credit institution or financial institution, or an institution that carries out activities equivalent to those carried out by credit institutions and financial institutions, created in a jurisdiction in which it has no physical presence, involving meaningful mind and management, and which is unaffiliated with a regulated financial group;
    • (b) for crypto-asset service providers: an entity whose name appears in the register established by the European Securities and Markets Authority pursuant to Article 110 of Regulation (EU) 2023/1114 or third country entity providing crypto-asset services without being licensed or registered nor subject to AML/CFT supervision there;
  • (24) crypto-asset account means a crypto-asset account as defined in Article 3, point (19), of Regulation (EU) 2023/1113;
  • (25) anonymity-enhancing coins means crypto-assets that have built-in features designed to make crypto-asset transfer information anonymous, either systematically or optionally;
  • (26) virtual IBAN means an identifier causing payments to be redirected to a payment account identified by an IBAN different from that identifier;
  • (27) Legal Entity Identifier means a unique alphanumeric reference code based on the ISO 17442 standard assigned to a legal entity;
  • (28) beneficial owner means any natural person who ultimately owns or controls a legal entity or an express trust or similar legal arrangement;
  • (29) express trust means a trust intentionally set up by the settlor, inter vivos or on death, usually in a form of written document, to place assets under the control of a trustee for the benefit of a beneficiary or for a specified purpose;
  • (30) objects of a power means the natural or legal persons or class of natural or legal persons among whom trustees may select the beneficiaries in a discretionary trust;
  • (31) default taker means the natural or legal persons or class of natural or legal persons who are the beneficiaries of a discretionary trust should the trustees fail to exercise their discretion;
  • (32) legal arrangement means an express trust or an arrangement which has a similar structure or function to an express trust, including fiducie and certain types of Treuhand and fideicomiso;
  • (33) basic information means:
    • (a) in relation to a legal entity:
    • (i) legal form and name of the legal entity;
    • (ii) instrument of constitution, and the statutes if they are contained in a separate instrument;
    • (iii) address of the registered or official office and, if different, the principal place of business, and the country of creation;
    • (iv) a list of legal representatives;
    • (v) where applicable, a list of shareholders or members, including information on the number of shares held by each shareholder and the categories of those shares and the nature of the associated voting rights;
    • (vi) where available, the registration number, the European Unique identifier, the tax identification number and the Legal Entity Identifier;
    • (vii) in the case of foundations, the assets held by the foundation to pursue its purposes;
    • (b) in relation to a legal arrangement:
    • (i) the name or unique identifier of the legal arrangement;
    • (ii) the trust deed or equivalent;
    • (iii) the purposes of the legal arrangement, if any;
    • (iv) the assets held in the legal arrangement or managed through it;
    • (v) the place of residence of the trustees of the express trust or persons holding equivalent positions in the similar legal arrangement, and, if different, the place from where the express trust or similar legal arrangement is administered;
  • (34) politically exposed person means a natural person who is or has been entrusted with prominent public functions including:
    • (a) in a Member State:
    • (i) heads of State, heads of government, ministers and deputy or assistant ministers;
    • (ii) members of parliament or of similar legislative bodies;
    • (iii) members of the governing bodies of political parties that hold seats in national executive or legislative bodies, or in regional or local executive or legislative bodies representing constituencies of at least 50000 inhabitants;
    • (iv) members of supreme courts, of constitutional courts or of other high-level judicial bodies, the decisions of which are not subject to further appeal, except in exceptional circumstances;
    • (v) members of courts of auditors or of the boards of central banks;
    • (vi) ambassadors, chargés d’affaires and high-ranking officers in the armed forces;
    • (vii) members of the administrative, management or supervisory bodies of enterprises controlled under any of the relationships listed in Article 22 of Directive 2013/34/EU either by the state, or, where those enterprises qualify as medium sized or large undertakings or medium sized or large groups, as defined in Article 3(3), (4), (6) and (7) of that Directive, by regional or local authorities;
    • (viii) heads of regional and local authorities, including groupings of municipalities and metropolitan regions, with at least 50000 inhabitants;
    • (ix) other prominent public functions provided for by Member States;
    • (b) in an international organisation:
    • (i) the highest ranking officials, their deputies and members of the board or equivalent functions of an international organisation;
    • (ii) representatives to a Member State or to the Union;
    • (c) at Union level: functions at the level of Union institutions and bodies that are equivalent to those listed in points (a)(i), (ii), (iv), (v) and (vi);
    • (d) in a third country: functions that are equivalent to those listed in point (a);
  • (35) family member means:
    • (a) a spouse, or a person in a registered partnership or civil union or in a similar arrangement;
    • (b) a child and a spouse of, or a person in a registered partnership or civil union or in a similar arrangement with, that child;
    • (c) a parent;
    • (d) for the functions referred to in point (34)(a)(i) and equivalent functions at Union level or in a third country, a sibling;
  • (36) person known to be a close associate means:
    • (a) a natural person who is known to have joint beneficial ownership of legal entities or legal arrangements, or any other close business relations, with a politically exposed person;
    • (b) a natural person who has sole beneficial ownership of a legal entity or legal arrangement which is known to have been set up for the de facto benefit of a politically exposed person;
  • (37) management body means an obliged entity’s body or bodies, which are appointed in accordance with national law, which are empowered to set the obliged entity’s strategy, objectives and overall direction, and which oversee and monitor management decision-making, and include the persons who effectively direct the business of the obliged entity; where no such body exists, the person who effectively directs the business of the obliged entity;
  • (38) management body in its management function means the management body responsible for the day-to-day management of the obliged entity;
  • (39) management body in its supervisory function means the management body acting in its role of overseeing and monitoring management decision-making;
  • (40) senior management means the members of the management body in its management function, as well as officers and employees with sufficient knowledge of the obliged entity’s money laundering and terrorist financing risk exposure and sufficient seniority to take decisions affecting its risk exposure;
  • (41) group means a group of undertakings which consists of a parent undertaking, its subsidiaries, as well as undertakings linked to each other by a relationship within the meaning of Article 22 of Directive 2013/34/EU;
  • (42) parent undertaking means:
    • (a) for groups whose head office is located in the Union, an obliged entity that is a parent undertaking as defined in Article 2, point (9), of Directive 2013/34/EU that is not itself a subsidiary of another undertaking in the Union, provided that at least one subsidiary undertaking is an obliged entity;
    • (b) for groups whose head office is located outside of the Union, where at least two subsidiary undertakings are obliged entities established in the Union, an undertaking within that group established in the Union that:
    • (i) is an obliged entity;
    • (ii) is an undertaking that is not a subsidiary of another undertaking that is an obliged entity established in the Union;
    • (iii) has a sufficient prominence within the group and a sufficient understanding of the operations of the group that are subject to the requirements of this Regulation; and
    • (iv) is given the responsibility of implementing group-wide requirements under Chapter II, Section 2 of this Regulation;
  • (43) cash means cash as defined in Article 2(1), point (a), of Regulation (EU) 2018/1672 of the European Parliament and of the Council;
  • (44) competent authority means:
    • (a) a Financial Intelligence Unit (FIU);
    • (b) a supervisory authority;
    • (c) a public authority that has the function of investigating or prosecuting money laundering, its predicate offences or terrorist financing, or that has the function of tracing, seizing or freezing and confiscating criminal assets;
    • (d) a public authority with designated responsibilities for combating money laundering or terrorist financing;
  • (45) supervisor means the body entrusted with responsibilities aimed at ensuring compliance by obliged entities with the requirements of this Regulation, including AMLA when performing the tasks entrusted to it in Article 5(2) of Regulation (EU) 2024/1620;
  • (46) supervisory authority means a supervisor who is a public body, or the public authority overseeing self-regulatory bodies in their performance of supervisory functions pursuant to Article 37 of Directive (EU) 2024/1640, or AMLA when acting as a supervisor;
  • (47) self-regulatory body means a body that represents members of a profession and has a role in regulating them, in performing certain supervisory or monitoring functions and in ensuring the enforcement of the rules relating to them;
  • (48) funds or other assets means any assets, including, but not limited to, financial assets, economic resources, including oil and other natural resources, property of every kind, whether tangible or intangible, movable or immovable, however acquired, and legal documents or instruments in any form, including electronic or digital, evidencing title to, or interest in, such funds or other assets, including, but not limited to, bank credits, travellers cheques, bank cheques, money orders, shares, securities, bonds, drafts, or letters of credit, and any interest, dividends or other income on or value accruing from or generated by such funds or other assets, and any other assets which potentially may be used to obtain funds, goods or services;
  • (49) targeted financial sanctions means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated persons and entities pursuant to Council Decisions adopted on the basis of Article 29 TEU and Council Regulations adopted on the basis of Article 215 TFEU;
  • (50) UN financial sanctions means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated or listed persons and entities pursuant to:
    • (a) UNSC Resolution 1267 (1999) and its successor resolutions;
    • (b) UNSC Resolution 1373 (2001), including the determination that the relevant sanctions will be applied to the person or entity and the public communication of that determination;
    • (c) UN financial sanctions relating to proliferation financing;
  • (51) UN financial sanctions relating to proliferation financing means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated or listed persons and entities pursuant to:
    • (a) UNSC Resolution 1718 (2006) and any successor resolutions;
    • (b) UNSC Resolution 2231 (2015) and any successor resolutions;
    • (c) any other UNSC resolutions imposing asset freezing and prohibitions to make funds or other assets available in relation to the financing of proliferation of weapons of mass destruction;
  • (52) professional football club means any legal person that is, owns or manages a football club that has been granted a licence and participates in the national football leagues in a Member State and whose players and staff are contractually engaged and are remunerated in exchange for their services;
  • (53) football agent means a natural or legal person who, for a fee, provides intermediary services and represents football players or professional football clubs in negotiations with a view to concluding a contract for a football player or represents professional football clubs in negotiations with a view to concluding an agreement for the transfer of a football player;
  • (54) high-value goods means goods listed in Annex IV;
  • (55) precious metals and stones means metals and stones listed in Annex V;
  • (56) cultural goods means goods listed in Annex I to Council Regulation (EC) No 116/2009;
  • (57) partnership for information sharing means a mechanism that enables the sharing and processing of information between obliged entities and, where applicable, competent authorities referred to in point 44(a), (b) and (c), for the purposes of preventing and combating money laundering, its predicate offences and terrorist financing, whether at national level or on a cross-border basis, and regardless of the form of that partnership.

Für die Zwecke dieser Verordnung gelten folgende Begriffsbestimmungen:

  • (1) „Geldwäsche“ bezeichnet das in Artikel 3 Absätze 1 und 5 der Richtlinie (EU) 2018/1673 genannte Verhalten einschließlich Beihilfe, Anstiftung und Versuch, dieses Verhalten zu begehen, unabhängig davon, ob die Tätigkeiten, aus denen die zu waschenden Vermögensgegenstände stammen, im Hoheitsgebiet eines Mitgliedstaats oder eines Drittlands ausgeübt wurden; die Kenntnis, der Vorsatz oder die Zweckbestimmung, die als Tatbestandsmerkmal dieses Verhaltens erforderlich sind, können aus objektiven tatsächlichen Umständen abgeleitet werden;
  • (2) „Terrorismusfinanzierung“ bezeichnet das in Artikel 11 der Richtlinie (EU) 2017/541 genannte Verhalten einschließlich Beihilfe, Anstiftung und Versuch, dieses Verhalten zu begehen, unabhängig davon, ob es im Hoheitsgebiet eines Mitgliedstaats oder eines Drittlands begangen wurde; die Kenntnis, der Vorsatz oder die Zweckbestimmung, die als Tatbestandsmerkmal dieses Verhaltens erforderlich sind, können aus objektiven tatsächlichen Umständen abgeleitet werden;
  • (3) „kriminelle Tätigkeit“ bezeichnet eine kriminelle Tätigkeit im Sinne von Artikel 2 Nummer 1 der Richtlinie (EU) 2018/1673 sowie Betrug zum Nachteil der finanziellen Interessen der Union im Sinne von Artikel 3 Absatz 2 der Richtlinie (EU) 2017/1371, passive und aktive Bestechung im Sinne von Artikel 4 Absatz 2 sowie Veruntreuung im Sinne von Artikel 4 Absatz 3 Unterabsatz 2 jener Richtlinie;
  • (4) „Gelder oder Vermögensgegenstände“ bezeichnet Vermögensgegenstände im Sinne von Artikel 2 Nummer 2 der Richtlinie (EU) 2018/1673;
  • (5) „Kreditinstitut“ bezeichnet:
    • a) ein Kreditinstitut im Sinne von Artikel 4 Absatz 1 Nummer 1 der Verordnung (EU) Nr. 575/2013;
    • b) eine Zweigstelle eines Kreditinstituts im Sinne von Artikel 4 Absatz 1 Nummer 17 der Verordnung (EU) Nr. 575/2013, sofern sie sich in der Union befindet, unabhängig davon, ob sich der Sitz in einem Mitgliedstaat oder einem Drittland befindet;
  • (6) „Finanzinstitut“ bezeichnet:
    • a) ein Unternehmen, das kein Kreditinstitut oder keine Wertpapierfirma ist und eine oder mehrere der in Anhang I Nummern 2 bis 12, 14 und 15 der Richtlinie 2013/36/EU aufgeführten Tätigkeiten ausübt, einschließlich der Tätigkeiten von Wechselstuben, jedoch mit Ausnahme der in Anhang I Nummer 8 der Richtlinie (EU) 2015/2366 genannten Tätigkeiten, oder ein Unternehmen, dessen Haupttätigkeit im Erwerb von Beteiligungen besteht, einschließlich einer Finanzholdinggesellschaft, einer gemischten Finanzholdinggesellschaft und einer Finanzholdinggesellschaft mit gemischter Tätigkeit;
    • b) ein Versicherungsunternehmen im Sinne von Artikel 13 Nummer 1 der Richtlinie 2009/138/EG, soweit es Lebensversicherungs- oder sonstige versicherungsbezogene Anlagetätigkeiten im Anwendungsbereich jener Richtlinie ausübt, einschließlich Versicherungsholdinggesellschaften und gemischten Versicherungsholdinggesellschaften im Sinne von Artikel 212 Absatz 1 Buchstaben f und g der Richtlinie 2009/138/EG;
    • c) ein Versicherungsvermittler im Sinne von Artikel 2 Absatz 1 Nummer 3 der Richtlinie (EU) 2016/97, wenn er im Bereich der Lebensversicherung und sonstiger versicherungsbezogener Anlageleistungen tätig ist, mit Ausnahme eines Versicherungsvermittlers, der keine Prämien oder für den Kunden bestimmte Beträge einzieht und der unter der Verantwortung eines oder mehrerer Versicherungsunternehmen oder Versicherungsvermittler für die sie jeweils betreffenden Produkte tätig ist;
    • d) eine Wertpapierfirma im Sinne von Artikel 4 Absatz 1 Nummer 1 der Richtlinie 2014/65/EU;
    • e) ein Organismus für gemeinsame Anlagen, insbesondere:
    • i) ein Organismus für gemeinsame Anlagen in Wertpapieren (OGAW) im Sinne von Artikel 1 Absatz 2 der Richtlinie 2009/65/EG und dessen Verwaltungsgesellschaft im Sinne von Artikel 2 Absatz 1 Buchstabe b jener Richtlinie oder eine nach jener Richtlinie zugelassene Investmentgesellschaft, die keine Verwaltungsgesellschaft bestellt hat und Anteile von OGAW in der Union zum Kauf anbietet;
    • ii) ein alternativer Investmentfonds im Sinne von Artikel 4 Absatz 1 Buchstabe a der Richtlinie 2011/61/EU und dessen Verwalter alternativer Investmentfonds im Sinne von Artikel 4 Absatz 1 Buchstabe b jener Richtlinie, die in den Anwendungsbereich von Artikel 2 jener Richtlinie fallen;
    • f) eine Zentralverwahrstelle im Sinne von Artikel 2 Absatz 1 Nummer 1 der Verordnung (EU) Nr. 909/2014;
    • g) ein Gläubiger im Sinne von Artikel 4 Nummer 2 der Richtlinie 2014/17/EU und Artikel 3 Buchstabe b der Richtlinie 2008/48/EG;
    • h) ein Kreditvermittler im Sinne von Artikel 4 Nummer 5 der Richtlinie 2014/17/EU und Artikel 3 Buchstabe f der Richtlinie 2008/48/EG, wenn er im Zusammenhang mit dem Kreditvertrag Gelder im Sinne von Artikel 4 Nummer 25 der Richtlinie (EU) 2015/2366 hält, mit Ausnahme eines Kreditvermittlers, der Tätigkeiten unter der Verantwortung eines oder mehrerer Gläubiger oder Kreditvermittler ausübt;
    • i) ein Anbieter von Krypto-Dienstleistungen;
    • j) eine Zweigstelle eines unter den Buchstaben a bis i genannten Finanzinstituts, sofern sie sich in der Union befindet, unabhängig davon, ob sich der Sitz in einem Mitgliedstaat oder einem Drittland befindet;
  • (7) „Kryptowert“ bezeichnet einen Kryptowert im Sinne von Artikel 3 Absatz 1 Nummer 5 der Verordnung (EU) 2023/1114, außer wenn er unter die in Artikel 2 Absatz 4 jener Verordnung aufgeführten Kategorien fällt;
  • (8) „Krypto-Dienstleistungen“ bezeichnet Krypto-Dienstleistungen im Sinne von Artikel 3 Absatz 1 Nummer 16 der Verordnung (EU) 2023/1114, mit Ausnahme der Beratung zu Kryptowerten nach Artikel 3 Absatz 1 Nummer 16 Buchstabe h jener Verordnung;
  • (9) „Anbieter von Krypto-Dienstleistungen“ bezeichnet einen Anbieter von Krypto-Dienstleistungen im Sinne von Artikel 3 Absatz 1 Nummer 15 der Verordnung (EU) 2023/1114, der eine oder mehrere Krypto-Dienstleistungen erbringt;
  • (10) „Finanzholdinggesellschaft mit gemischter Tätigkeit“ bezeichnet ein Unternehmen, das weder Finanzholdinggesellschaft noch gemischte Finanzholdinggesellschaft ist, nicht Tochterunternehmen eines anderen Unternehmens ist und zu dessen Tochterunternehmen mindestens ein Kreditinstitut oder Finanzinstitut gehört;
  • (11) „Anbieter von Trust- oder Gesellschaftsdienstleistungen“ bezeichnet jede natürliche oder juristische Person, die im Rahmen ihrer Geschäftstätigkeit Dritten eine der folgenden Dienstleistungen erbringt:
    • a) Gründung von Gesellschaften oder anderen juristischen Personen;
    • b) Tätigkeit als Direktor oder Sekretär einer Gesellschaft, als Gesellschafter einer Personengesellschaft oder in einer ähnlichen Position bei anderen juristischen Personen oder die Veranlassung einer anderen Person hierzu;
    • c) Bereitstellung eines Sitzes, einer Geschäfts-, Korrespondenz- oder Verwaltungsadresse sowie anderer damit verbundener Dienstleistungen für eine Gesellschaft, eine Personengesellschaft oder eine andere juristische Person oder Rechtsvereinbarung;
    • d) Tätigkeit als Treuhänder eines ausdrücklichen Trusts oder Ausübung einer gleichwertigen Funktion bei einer ähnlichen Rechtsvereinbarung oder die Veranlassung einer anderen Person hierzu;
    • e) Tätigkeit als nomineller Anteilseigner für eine andere Person oder die Veranlassung einer anderen Person hierzu;
  • (12) „Glücksspieldienst“ bezeichnet eine Dienstleistung, bei der ein Einsatz mit Geldwert bei Glücksspielen, einschließlich solcher mit einem Geschicklichkeitselement, wie Lotterien, Kasinospielen, Pokerspielen und Wetten, gesetzt wird, die an einem physischen Ort oder im Fernabsatz, auf elektronischem Weg oder mittels einer anderen kommunikationserleichternden Technologie und auf individuellen Wunsch des Dienstleistungsempfängers angeboten werden;
  • (13) „nichtfinanzielle Finanzholdinggesellschaft mit gemischter Tätigkeit“ bezeichnet ein Unternehmen, das weder Finanzholdinggesellschaft noch gemischte Finanzholdinggesellschaft ist, nicht Tochterunternehmen eines anderen Unternehmens ist und zu dessen Tochterunternehmen mindestens ein Verpflichteter im Sinne von Artikel 3 Nummer 3 gehört;
  • (14) „selbstverwaltete Adresse“ bezeichnet eine selbstverwaltete Adresse im Sinne von Artikel 3 Nummer 20 der Verordnung (EU) 2023/1113;
  • (15) „Anbieter von Crowdfunding-Dienstleistungen“ bezeichnet einen Anbieter von Crowdfunding-Dienstleistungen im Sinne von Artikel 2 Absatz 1 Buchstabe e der Verordnung (EU) 2020/1503;
  • (16) „Crowdfunding-Vermittler“ bezeichnet ein Unternehmen, das kein Anbieter von Crowdfunding-Dienstleistungen ist und dessen Geschäft darin besteht, über ein internetbasiertes Informationssystem, das der Öffentlichkeit oder einer begrenzten Zahl von Geldgebern offensteht, Folgendes zusammenzuführen oder das Zusammenführen zu erleichtern:
    • a) Projektträger, also jede natürliche oder juristische Person, die eine Finanzierung für Projekte sucht, die aus einem oder mehreren vorab festgelegten Vorgängen mit einem bestimmten Ziel bestehen, einschließlich der Mittelbeschaffung für einen bestimmten Zweck oder eine bestimmte Veranstaltung, unabhängig davon, ob diese Projekte der Öffentlichkeit oder einer begrenzten Zahl von Geldgebern angeboten werden; und
    • b) Geldgeber, also jede natürliche oder juristische Person, die durch verzinsliche oder zinslose Darlehen oder durch Spenden zur Finanzierung von Projekten beiträgt, auch wenn die Spende den Spender zu einem nicht materiellen Vorteil berechtigt;
  • (17) „E-Geld“ bezeichnet E-Geld im Sinne von Artikel 2 Nummer 2 der Richtlinie 2009/110/EG, jedoch mit Ausnahme des in Artikel 1 Absätze 4 und 5 jener Richtlinie genannten Geldwerts;
  • (18) „Niederlassung“ bezeichnet die tatsächliche Ausübung einer von Artikel 3 erfassten wirtschaftlichen Tätigkeit durch einen Verpflichteten in einem Mitgliedstaat oder Drittland, das nicht das Land ist, in dem sich sein Sitz befindet, auf unbestimmte Zeit und mittels einer stabilen Infrastruktur, einschließlich:
    • a) einer Zweigstelle oder Tochtergesellschaft;
    • b) im Falle von Kreditinstituten und Finanzinstituten einer Infrastruktur, die nach den aufsichtsrechtlichen Vorschriften als Niederlassung gilt;
  • (19) „Geschäftsbeziehung“ bezeichnet eine geschäftliche, berufliche oder kommerzielle Beziehung im Zusammenhang mit den beruflichen Tätigkeiten eines Verpflichteten, die zwischen einem Verpflichteten und einem Kunden begründet wird, auch ohne schriftlichen Vertrag, und von der bei ihrer Begründung erwartet wird oder die später ein Element der Wiederholung oder Dauer erlangt;
  • (20) „verbundene Transaktionen“ bezeichnet zwei oder mehr Transaktionen mit identischer oder ähnlicher Herkunft, Bestimmung und Zweck oder sonstigen relevanten Merkmalen innerhalb eines bestimmten Zeitraums;
  • (21) „Drittland“ bezeichnet jede Hoheitsgewalt, jeden unabhängigen Staat oder jedes autonome Gebiet, das nicht Teil der Union ist und über eigene Rechtsvorschriften oder ein eigenes Durchsetzungssystem zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung verfügt;
  • (22) „Korrespondenzbeziehung“ bezeichnet:
    • a) die Erbringung von Bankdienstleistungen durch ein Kreditinstitut als Korrespondent für ein anderes Kreditinstitut als Respondenz, einschließlich der Bereitstellung eines laufenden oder sonstigen Verbindlichkeitskontos und damit verbundener Dienstleistungen wie Cash-Management, internationaler Geldtransfers im Sinne von Artikel 4 Nummer 25 der Richtlinie (EU) 2015/2366, Scheckverrechnung, Durchlaufkonten und Devisendienstleistungen;
    • b) Beziehungen zwischen und unter Kreditinstituten und Finanzinstituten, auch wenn ähnliche Dienstleistungen von einem Korrespondenzinstitut für ein Respondenzinstitut erbracht werden, einschließlich Beziehungen für Wertpapiergeschäfte oder Geldtransfers im Sinne von Artikel 4 Nummer 25 der Richtlinie (EU) 2015/2366, Transaktionen mit Kryptowerten oder Übertragungen von Kryptowerten;
  • (23) „Mantelinstitut“ bezeichnet:
    • a) bei Kreditinstituten und Finanzinstituten, die keine Anbieter von Krypto-Dienstleistungen sind: ein Kreditinstitut oder Finanzinstitut oder ein Institut, das Tätigkeiten ausübt, die den von Kreditinstituten und Finanzinstituten ausgeübten Tätigkeiten gleichwertig sind, in einer Hoheitsgewalt errichtet wurde, in der es keine physische Präsenz mit sinnvoller Ausübung von Leitung und Verwaltung hat, und keiner regulierten Finanzgruppe angehört;
    • b) bei Anbietern von Krypto-Dienstleistungen: ein Unternehmen, dessen Name in dem von der Europäischen Wertpapier- und Marktaufsichtsbehörde gemäß Artikel 110 der Verordnung (EU) 2023/1114 eingerichteten Register erscheint, oder ein Unternehmen aus einem Drittland, das Krypto-Dienstleistungen erbringt, ohne dort zugelassen oder registriert zu sein oder der Aufsicht zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung zu unterliegen;
  • (24) „Krypto-Konto“ bezeichnet ein Krypto-Konto im Sinne von Artikel 3 Nummer 19 der Verordnung (EU) 2023/1113;
  • (25) „anonymitätssteigernde Coins“ bezeichnet Kryptowerte mit integrierten Funktionen, die dazu bestimmt sind, Informationen über Übertragungen von Kryptowerten systematisch oder optional zu anonymisieren;
  • (26) „virtuelle IBAN“ bezeichnet eine Kennung, die bewirkt, dass Zahlungen auf ein durch eine von dieser Kennung verschiedene IBAN bezeichnetes Zahlungskonto umgeleitet werden;
  • (27) „Legal Entity Identifier“ bezeichnet einen einer juristischen Person zugewiesenen eindeutigen alphanumerischen Referenzcode auf der Grundlage der Norm ISO 17442;
  • (28) „wirtschaftlicher Eigentümer“ bezeichnet jede natürliche Person, in deren letztendlichem Eigentum oder unter deren letztendlicher Kontrolle eine juristische Person, ein ausdrücklicher Trust oder eine ähnliche Rechtsvereinbarung steht;
  • (29) „ausdrücklicher Trust“ bezeichnet einen vom Errichter unter Lebenden oder von Todes wegen, gewöhnlich durch schriftliche Urkunde, absichtlich errichteten Trust, durch den Vermögenswerte der Kontrolle eines Treuhänders zum Nutzen eines Begünstigten oder für einen bestimmten Zweck unterstellt werden;
  • (30) „Ermessensbegünstigte“ bezeichnet die natürlichen oder juristischen Personen oder Gruppen natürlicher oder juristischer Personen, aus denen die Treuhänder eines Ermessens-Trusts die Begünstigten auswählen können;
  • (31) „Ersatzbegünstigte“ bezeichnet die natürlichen oder juristischen Personen oder Gruppen natürlicher oder juristischer Personen, die Begünstigte eines Ermessens-Trusts sind, falls die Treuhänder ihr Ermessen nicht ausüben;
  • (32) „Rechtsvereinbarung“ bezeichnet einen ausdrücklichen Trust oder eine Vereinbarung mit ähnlicher Struktur oder Funktion wie ein ausdrücklicher Trust, einschließlich Fiducie sowie bestimmter Arten von Treuhand und Fideikommiss;
  • (33) „Grundinformationen“ bezeichnet:
    • a) in Bezug auf eine juristische Person:
    • i) Rechtsform und Name der juristischen Person;
    • ii) Gründungsurkunde sowie die Satzung, sofern sie in einer gesonderten Urkunde enthalten ist;
    • iii) Anschrift des eingetragenen oder amtlichen Sitzes und, falls abweichend, des Hauptgeschäftssitzes sowie das Gründungsland;
    • iv) eine Liste der gesetzlichen Vertreter;
    • v) gegebenenfalls eine Liste der Anteilseigner oder Mitglieder einschließlich Angaben zur Zahl der von jedem Anteilseigner gehaltenen Anteile, zu den Kategorien dieser Anteile und zur Art der damit verbundenen Stimmrechte;
    • vi) soweit verfügbar, die Registrierungsnummer, die europäische einheitliche Kennung, die Steueridentifikationsnummer und der Legal Entity Identifier;
    • vii) bei Stiftungen die von der Stiftung zur Verfolgung ihrer Zwecke gehaltenen Vermögenswerte;
    • b) in Bezug auf eine Rechtsvereinbarung:
    • i) Name oder eindeutige Kennung der Rechtsvereinbarung;
    • ii) Trusturkunde oder gleichwertige Urkunde;
    • iii) gegebenenfalls die Zwecke der Rechtsvereinbarung;
    • iv) die in der Rechtsvereinbarung gehaltenen oder durch sie verwalteten Vermögenswerte;
    • v) der Wohnort der Treuhänder des ausdrücklichen Trusts oder der Personen mit gleichwertigen Positionen in der ähnlichen Rechtsvereinbarung und, falls abweichend, der Ort, von dem aus der ausdrückliche Trust oder die ähnliche Rechtsvereinbarung verwaltet wird;
  • (34) „politisch exponierte Person“ bezeichnet eine natürliche Person, die ein wichtiges öffentliches Amt innehat oder innehatte, einschließlich:
    • a) in einem Mitgliedstaat:
    • i) Staatsoberhäupter, Regierungschefs, Minister sowie stellvertretende Minister und Staatssekretäre;
    • ii) Mitglieder von Parlamenten oder vergleichbaren gesetzgebenden Organen;
    • iii) Mitglieder der Führungsgremien politischer Parteien, die Sitze in nationalen Exekutiv- oder Legislativorganen oder in regionalen oder lokalen Exekutiv- oder Legislativorganen innehaben, die Wahlkreise mit mindestens 50 000 Einwohnern vertreten;
    • iv) Mitglieder oberster Gerichte, Verfassungsgerichte oder sonstiger hochrangiger Justizorgane, deren Entscheidungen außer unter außergewöhnlichen Umständen nicht weiter angefochten werden können;
    • v) Mitglieder von Rechnungshöfen oder Leitungsorganen von Zentralbanken;
    • vi) Botschafter, Geschäftsträger und hochrangige Offiziere der Streitkräfte;
    • vii) Mitglieder der Verwaltungs-, Leitungs- oder Aufsichtsorgane von Unternehmen, die nach einer der in Artikel 22 der Richtlinie 2013/34/EU genannten Beziehungen entweder vom Staat oder, wenn sie als mittlere oder große Unternehmen oder mittlere oder große Gruppen im Sinne von Artikel 3 Absätze 3, 4, 6 und 7 jener Richtlinie gelten, von regionalen oder lokalen Behörden kontrolliert werden;
    • viii) Leiter regionaler und lokaler Behörden einschließlich Gemeindeverbänden und Ballungsräumen mit mindestens 50 000 Einwohnern;
    • ix) sonstige von den Mitgliedstaaten vorgesehene wichtige öffentliche Ämter;
    • b) in einer internationalen Organisation:
    • i) die höchstrangigen Amtsträger, ihre Stellvertreter sowie Mitglieder des Vorstands oder Personen in gleichwertigen Funktionen einer internationalen Organisation;
    • ii) Vertreter bei einem Mitgliedstaat oder bei der Union;
    • c) auf Unionsebene: Funktionen auf der Ebene der Organe und Einrichtungen der Union, die den unter Buchstabe a Ziffern i, ii, iv, v und vi aufgeführten Funktionen gleichwertig sind;
    • d) in einem Drittland: Funktionen, die den unter Buchstabe a aufgeführten Funktionen gleichwertig sind;
  • (35) „Familienangehöriger“ bezeichnet:
    • a) einen Ehegatten oder eine Person in einer eingetragenen Partnerschaft, Lebenspartnerschaft oder ähnlichen Verbindung;
    • b) ein Kind sowie dessen Ehegatten oder eine Person in einer eingetragenen Partnerschaft, Lebenspartnerschaft oder ähnlichen Verbindung;
    • c) einen Elternteil;
    • d) bei den unter Nummer 34 Buchstabe a Ziffer i genannten Funktionen und gleichwertigen Funktionen auf Unionsebene oder in einem Drittland ein Geschwister;
  • (36) „bekanntermaßen nahestehende Person“ bezeichnet:
    • a) eine natürliche Person, von der bekannt ist, dass sie mit einer politisch exponierten Person das wirtschaftliche Eigentum an juristischen Personen oder Rechtsvereinbarungen teilt oder sonstige enge Geschäftsbeziehungen unterhält;
    • b) eine natürliche Person, die alleinige wirtschaftliche Eigentümerin einer juristischen Person oder Rechtsvereinbarung ist, von der bekannt ist, dass sie de facto zugunsten einer politisch exponierten Person errichtet wurde;
  • (37) „Leitungsorgan“ bezeichnet das oder die nach nationalem Recht bestellten Organe eines Verpflichteten, die befugt sind, die Strategie, Ziele und allgemeine Ausrichtung des Verpflichteten festzulegen, die Beschlussfassung der Geschäftsleitung zu beaufsichtigen und zu überwachen, und umfasst die Personen, die das Geschäft des Verpflichteten tatsächlich leiten; besteht kein solches Organ, bezeichnet der Begriff die Person, die das Geschäft des Verpflichteten tatsächlich leitet;
  • (38) „Leitungsorgan in seiner Leitungsfunktion“ bezeichnet das für die laufende Geschäftsführung des Verpflichteten verantwortliche Leitungsorgan;
  • (39) „Leitungsorgan in seiner Überwachungsfunktion“ bezeichnet das Leitungsorgan in seiner Funktion der Beaufsichtigung und Überwachung der Beschlussfassung der Geschäftsleitung;
  • (40) „höhere Führungsebene“ bezeichnet die Mitglieder des Leitungsorgans in seiner Leitungsfunktion sowie Führungskräfte und Beschäftigte mit ausreichenden Kenntnissen über das Geldwäsche- und Terrorismusfinanzierungsrisiko des Verpflichteten und ausreichender Stellung, um Entscheidungen zu treffen, die dessen Risikobelastung beeinflussen;
  • (41) „Gruppe“ bezeichnet eine Gruppe von Unternehmen, die aus einem Mutterunternehmen, seinen Tochterunternehmen sowie durch eine Beziehung im Sinne von Artikel 22 der Richtlinie 2013/34/EU miteinander verbundenen Unternehmen besteht;
  • (42) „Mutterunternehmen“ bezeichnet:
    • a) bei Gruppen mit Sitz in der Union einen Verpflichteten, der ein Mutterunternehmen im Sinne von Artikel 2 Nummer 9 der Richtlinie 2013/34/EU ist, selbst kein Tochterunternehmen eines anderen Unternehmens in der Union ist und bei dem mindestens ein Tochterunternehmen ein Verpflichteter ist;
    • b) bei Gruppen mit Sitz außerhalb der Union, wenn mindestens zwei Tochterunternehmen Verpflichtete mit Niederlassung in der Union sind, ein in der Union niedergelassenes Unternehmen dieser Gruppe, das:
    • i) ein Verpflichteter ist;
    • ii) kein Tochterunternehmen eines anderen in der Union niedergelassenen Unternehmens ist, das ein Verpflichteter ist;
    • iii) innerhalb der Gruppe über ausreichende Bedeutung und ein ausreichendes Verständnis der den Anforderungen dieser Verordnung unterliegenden Tätigkeiten der Gruppe verfügt; und
    • iv) mit der Umsetzung gruppenweiter Anforderungen nach Kapitel II Abschnitt 2 dieser Verordnung betraut ist;
  • (43) „Bargeld“ bezeichnet Bargeld im Sinne von Artikel 2 Absatz 1 Buchstabe a der Verordnung (EU) 2018/1672;
  • (44) „zuständige Behörde“ bezeichnet:
    • a) eine zentrale Meldestelle (FIU);
    • b) eine Aufsichtsbehörde;
    • c) eine öffentliche Behörde, die für die Untersuchung oder Verfolgung von Geldwäsche, deren Vortaten oder Terrorismusfinanzierung oder für die Aufspürung, Beschlagnahme oder das Einfrieren und die Einziehung von Vermögensgegenständen aus Straftaten zuständig ist;
    • d) eine öffentliche Behörde mit ausdrücklich zugewiesenen Zuständigkeiten für die Bekämpfung von Geldwäsche oder Terrorismusfinanzierung;
  • (45) „Aufseher“ bezeichnet das mit der Sicherstellung der Einhaltung der Anforderungen dieser Verordnung durch Verpflichtete betraute Organ, einschließlich der AMLA bei der Wahrnehmung der ihr in Artikel 5 Absatz 2 der Verordnung (EU) 2024/1620 übertragenen Aufgaben;
  • (46) „Aufsichtsbehörde“ bezeichnet einen Aufseher, der eine öffentliche Stelle ist, oder die öffentliche Behörde, die Selbstregulierungsorgane bei der Wahrnehmung von Aufsichtsfunktionen gemäß Artikel 37 der Richtlinie (EU) 2024/1640 beaufsichtigt, oder die AMLA, wenn sie als Aufseher tätig wird;
  • (47) „Selbstregulierungsorgan“ bezeichnet ein Organ, das Angehörige eines Berufs vertritt und an deren Regulierung, an der Wahrnehmung bestimmter Aufsichts- oder Überwachungsfunktionen sowie an der Durchsetzung der für sie geltenden Vorschriften beteiligt ist;
  • (48) „Gelder oder sonstige Vermögenswerte“ bezeichnet Vermögenswerte jeder Art, einschließlich, aber nicht beschränkt auf finanzielle Vermögenswerte, wirtschaftliche Ressourcen einschließlich Erdöl und sonstiger natürlicher Ressourcen, Vermögensgegenstände jeder Art, gleich ob körperlich oder unkörperlich, beweglich oder unbeweglich, unabhängig davon, wie sie erworben wurden, sowie Rechtsdokumente oder Instrumente in jeder Form, auch elektronisch oder digital, die das Eigentum oder ein sonstiges Recht an solchen Geldern oder sonstigen Vermögenswerten belegen, einschließlich, aber nicht beschränkt auf Bankguthaben, Reiseschecks, Bankschecks, Zahlungsanweisungen, Aktien, Wertpapiere, Schuldverschreibungen, Wechsel oder Akkreditive sowie Zinsen, Dividenden oder sonstige Einkünfte aus oder Werte, die aus solchen Geldern oder sonstigen Vermögenswerten entstehen oder durch sie erwirtschaftet werden, und alle sonstigen Vermögenswerte, die möglicherweise zum Erwerb von Geldern, Waren oder Dienstleistungen verwendet werden können;
  • (49) „gezielte finanzielle Sanktionen“ bezeichnet sowohl das Einfrieren von Vermögenswerten als auch Verbote, Gelder oder sonstige Vermögenswerte unmittelbar oder mittelbar zugunsten benannter Personen und Einrichtungen verfügbar zu machen, gemäß den auf der Grundlage von Artikel 29 EUV erlassenen Beschlüssen des Rates und den auf der Grundlage von Artikel 215 AEUV erlassenen Verordnungen des Rates;
  • (50) „finanzielle Sanktionen der Vereinten Nationen“ bezeichnet sowohl das Einfrieren von Vermögenswerten als auch Verbote, Gelder oder sonstige Vermögenswerte unmittelbar oder mittelbar zugunsten benannter oder gelisteter Personen und Einrichtungen verfügbar zu machen, gemäß:
    • a) Resolution 1267 (1999) des VN-Sicherheitsrats und ihren Nachfolgeresolutionen;
    • b) Resolution 1373 (2001) des VN-Sicherheitsrats, einschließlich der Feststellung, dass die betreffenden Sanktionen auf die Person oder Einrichtung angewandt werden, und der öffentlichen Bekanntmachung dieser Feststellung;
    • c) finanziellen Sanktionen der Vereinten Nationen im Zusammenhang mit der Finanzierung der Proliferation;
  • (51) „finanzielle Sanktionen der Vereinten Nationen im Zusammenhang mit der Finanzierung der Proliferation“ bezeichnet sowohl das Einfrieren von Vermögenswerten als auch Verbote, Gelder oder sonstige Vermögenswerte unmittelbar oder mittelbar zugunsten benannter oder gelisteter Personen und Einrichtungen verfügbar zu machen, gemäß:
    • a) Resolution 1718 (2006) des VN-Sicherheitsrats und allen Nachfolgeresolutionen;
    • b) Resolution 2231 (2015) des VN-Sicherheitsrats und allen Nachfolgeresolutionen;
    • c) allen sonstigen Resolutionen des VN-Sicherheitsrats, die im Zusammenhang mit der Finanzierung der Proliferation von Massenvernichtungswaffen das Einfrieren von Vermögenswerten und Verbote der Bereitstellung von Geldern oder sonstigen Vermögenswerten vorsehen;
  • (52) „professioneller Fußballverein“ bezeichnet jede juristische Person, die ein Fußballverein ist, einen solchen besitzt oder verwaltet, dem eine Lizenz erteilt wurde und der an den nationalen Fußballligen eines Mitgliedstaats teilnimmt und dessen Spieler und Personal vertraglich verpflichtet sind und für ihre Dienste vergütet werden;
  • (53) „Fußballagent“ bezeichnet eine natürliche oder juristische Person, die gegen Entgelt Vermittlungsdienste erbringt und Fußballspieler oder professionelle Fußballvereine bei Verhandlungen zum Abschluss eines Vertrags für einen Fußballspieler vertritt oder professionelle Fußballvereine bei Verhandlungen zum Abschluss einer Vereinbarung über den Transfer eines Fußballspielers vertritt;
  • (54) „hochwertige Güter“ bezeichnet die in Anhang IV aufgeführten Güter;
  • (55) „Edelmetalle und Edelsteine“ bezeichnet die in Anhang V aufgeführten Metalle und Steine;
  • (56) „Kulturgüter“ bezeichnet die in Anhang I der Verordnung (EG) Nr. 116/2009 des Rates aufgeführten Güter;
  • (57) „Partnerschaft für den Informationsaustausch“ bezeichnet einen Mechanismus, der den Austausch und die Verarbeitung von Informationen zwischen Verpflichteten und gegebenenfalls den unter Nummer 44 Buchstaben a, b und c genannten zuständigen Behörden zum Zweck der Verhinderung und Bekämpfung von Geldwäsche, deren Vortaten und Terrorismusfinanzierung ermöglicht, unabhängig davon, ob dies auf nationaler Ebene oder grenzüberschreitend und unabhängig von der Form dieser Partnerschaft erfolgt.
2 2 2

Prominent public functions as referred to in paragraph 1, point (34), shall not be understood as covering middle-ranking or more junior officials.

Prominent public functions as referred to in paragraph 1, point (34), shall not be understood as covering middle-ranking or more junior officials.

Wichtige öffentliche Ämter im Sinne des Absatzes 1 Nummer 34 umfassen keine Beamten oder sonstigen Amtsträger der mittleren oder niedrigeren Führungsebene.

3 3 3

Where justified by their administrative organisation and by risk, Member States may set lower thresholds for the designation of the following prominent public functions:

  • (a) members of governing bodies of political parties represented at regional or local level, as referred to in paragraph 1, point (34)(a)(iii);
  • (b) heads of regional and local authorities, as referred to in paragraph 1, point (34)(a)(viii).

Member States shall notify those lower thresholds to the Commission.

Where justified by their administrative organisation and by risk, Member States may set lower thresholds for the designation of the following prominent public functions:

  • (a) members of governing bodies of political parties represented at regional or local level, as referred to in paragraph 1, point (34)(a)(iii);
  • (b) heads of regional and local authorities, as referred to in paragraph 1, point (34)(a)(viii).

Member States shall notify those lower thresholds to the Commission.

Die Mitgliedstaaten können, sofern dies durch ihre Verwaltungsorganisation und das Risiko gerechtfertigt ist, für die Benennung der folgenden wichtigen öffentlichen Ämter niedrigere Schwellenwerte festlegen:

  • a) Mitglieder der Leitungsorgane politischer Parteien, die auf regionaler oder lokaler Ebene vertreten sind, gemäß Absatz 1 Nummer 34 Buchstabe a Ziffer iii;
  • b) Leiter regionaler und lokaler Behörden gemäß Absatz 1 Nummer 34 Buchstabe a Ziffer viii.

Die Mitgliedstaaten teilen der Kommission diese niedrigeren Schwellenwerte mit.

4 4 4

In relation to paragraph 1, point (34)(a)(vii) of this Article, where justified by their administrative organisation and by risk, Member States may set lower thresholds for the identification of enterprises controlled by regional or local authorities than those defined in Article 3(3), (4), (6) and (7) of Directive 2013/34/EU.Member States shall notify those lower thresholds to the Commission.

In relation to paragraph 1, point (34)(a)(vii) of this Article, where justified by their administrative organisation and by risk, Member States may set lower thresholds for the identification of enterprises controlled by regional or local authorities than those defined in Article 3(3), (4), (6) and (7) of Directive 2013/34/EU.Member States shall notify those lower thresholds to the Commission.

In Bezug auf Absatz 1 Nummer 34 Buchstabe a Ziffer vii dieses Artikels können die Mitgliedstaaten, sofern dies durch ihre Verwaltungsorganisation und das Risiko gerechtfertigt ist, für die Identifizierung von Unternehmen, die von regionalen oder lokalen Behörden kontrolliert werden, niedrigere Schwellenwerte festlegen als jene, die in Artikel 3 Absätze 3, 4, 6 und 7 der Richtlinie 2013/34/EU festgelegt sind. Die Mitgliedstaaten teilen der Kommission diese niedrigeren Schwellenwerte mit.

5 5 5

Where justified by their social and cultural structures and by risk, Member States may apply a broader scope for the designation of siblings as family members of politically exposed persons, as referred to in paragraph 1, point (35)(d).Member States shall notify that broader scope to the Commission.

Where justified by their social and cultural structures and by risk, Member States may apply a broader scope for the designation of siblings as family members of politically exposed persons, as referred to in paragraph 1, point (35)(d).Member States shall notify that broader scope to the Commission.

Sofern dies durch ihre sozialen und kulturellen Strukturen und das Risiko gerechtfertigt ist, können die Mitgliedstaaten für die Benennung von Geschwistern als Familienmitglieder politisch exponierter Personen gemäß Absatz 1 Nummer 35 Buchstabe d einen weiteren Anwendungsbereich festlegen. Die Mitgliedstaaten teilen der Kommission diesen weiteren Anwendungsbereich mit.

SECTION 2 — Scope SECTION 2 — Scope SECTION 2 — Geltungsbereich
Article 3 — Obliged entities Article 3 — Obliged entities Article 3 — Verpflichtete Unternehmen

The following entities are to be considered obliged entities for the purposes of this Regulation:

  • (1) credit institutions;
  • (2) financial institutions;
  • (3) the following natural or legal persons acting in the exercise of their professional activities:

    • (a) auditors, external accountants and tax advisors, and any other natural or legal person including independent legal professionals such as lawyers, that undertakes to provide, directly or by means of other persons to which that other person is related, material aid, assistance or advice on tax matters as principal business or professional activity;
    • (b) notaries, lawyers and other independent legal professionals, where they participate, whether by acting on behalf of and for their client in any financial or real estate transaction, or by assisting in the planning or carrying out of transactions for their client concerning any of the following:
    • (i) buying and selling of real property or business entities;
    • (ii) managing of client money, securities or other assets, including crypto-assets;
    • (iii) opening or management of bank, savings, securities or crypto-assets accounts;
    • (iv) organisation of contributions necessary for the creation, operation or management of companies;
    • (v) creation, setting up, operation or management of trusts, companies, foundations, or similar structures;
    • (c) trust or company service providers;
    • (d) estate agents and other real estate professionals to the extent they act as intermediaries in real estate transactions, including in relation to the letting of immovable property for transactions for which the monthly rent amounts to at least EUR 10000 or the equivalent in national currency, irrespective of the means of payment;
    • (e) persons trading, as a regular or principal professional activity, in precious metals and stones;
    • (f) persons trading, as a regular or principal professional activity, in high-value goods;
    • (g) providers of gambling services;
    • (h) crowdfunding service providers and crowdfunding intermediaries;
    • (i) persons trading or acting as intermediaries in the trade of cultural goods, including when this is carried out by art galleries and auction houses, where the value of the transaction or linked transactions amounts to at least EUR 10000 or the equivalent in national currency;
    • (j) persons storing, trading or acting as intermediaries in the trade of cultural goods and high-value goods, when this is carried out within free zones and customs warehouses, where the value of the transaction or linked transactions amounts to at least EUR 10000 or the equivalent in national currency;
    • (k) credit intermediaries for mortgage and consumer credits, other than credit institutions and financial institutions, with the exception of the credit intermediaries carrying out activities under the responsibility of one or more creditors or credit intermediaries;
    • (l) investment migration operators permitted to represent or offer intermediation services to third-country nationals seeking to obtain residence rights in a Member State in exchange for any kind of investment, including capital transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity to the public good and contributions to the state budget;
    • (m) non-financial mixed activity holding companies;
    • (n) football agents;
    • (o) professional football clubs in respect of the following transactions:
    • (i) transactions with an investor;
    • (ii) transactions with a sponsor;
    • (iii) transactions with football agents or other intermediaries;
    • (iv) transactions for the purpose of a football player’s transfer.

The following entities are to be considered obliged entities for the purposes of this Regulation:

  • (1) credit institutions;
  • (2) financial institutions;
  • (3) the following natural or legal persons acting in the exercise of their professional activities:
    • (a) auditors, external accountants and tax advisors, and any other natural or legal person including independent legal professionals such as lawyers, that undertakes to provide, directly or by means of other persons to which that other person is related, material aid, assistance or advice on tax matters as principal business or professional activity;
    • (b) notaries, lawyers and other independent legal professionals, where they participate, whether by acting on behalf of and for their client in any financial or real estate transaction, or by assisting in the planning or carrying out of transactions for their client concerning any of the following:
    • (i) buying and selling of real property or business entities;
    • (ii) managing of client money, securities or other assets, including crypto-assets;
    • (iii) opening or management of bank, savings, securities or crypto-assets accounts;
    • (iv) organisation of contributions necessary for the creation, operation or management of companies;
    • (v) creation, setting up, operation or management of trusts, companies, foundations, or similar structures;
    • (c) trust or company service providers;
    • (d) estate agents and other real estate professionals to the extent they act as intermediaries in real estate transactions, including in relation to the letting of immovable property for transactions for which the monthly rent amounts to at least EUR 10000 or the equivalent in national currency, irrespective of the means of payment;
    • (e) persons trading, as a regular or principal professional activity, in precious metals and stones;
    • (f) persons trading, as a regular or principal professional activity, in high-value goods;
    • (g) providers of gambling services;
    • (h) crowdfunding service providers and crowdfunding intermediaries;
    • (i) persons trading or acting as intermediaries in the trade of cultural goods, including when this is carried out by art galleries and auction houses, where the value of the transaction or linked transactions amounts to at least EUR 10000 or the equivalent in national currency;
    • (j) persons storing, trading or acting as intermediaries in the trade of cultural goods and high-value goods, when this is carried out within free zones and customs warehouses, where the value of the transaction or linked transactions amounts to at least EUR 10000 or the equivalent in national currency;
    • (k) credit intermediaries for mortgage and consumer credits, other than credit institutions and financial institutions, with the exception of the credit intermediaries carrying out activities under the responsibility of one or more creditors or credit intermediaries;
    • (l) investment migration operators permitted to represent or offer intermediation services to third-country nationals seeking to obtain residence rights in a Member State in exchange for any kind of investment, including capital transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity to the public good and contributions to the state budget;
    • (m) non-financial mixed activity holding companies;
    • (n) football agents;
    • (o) professional football clubs in respect of the following transactions:
    • (i) transactions with an investor;
    • (ii) transactions with a sponsor;
    • (iii) transactions with football agents or other intermediaries;
    • (iv) transactions for the purpose of a football player’s transfer.

Für die Zwecke dieser Verordnung gelten die folgenden Unternehmen als verpflichtete Unternehmen:

  • 1. Kreditinstitute;
  • 2. Finanzinstitute;
  • 3. die folgenden natürlichen oder juristischen Personen, die ihre berufliche Tätigkeit ausüben:
    • a) Wirtschaftsprüfer, externe Buchhalter und Steuerberater sowie jede andere natürliche oder juristische Person, einschließlich unabhängiger Angehöriger der Rechtsberufe wie Rechtsanwälte, die als Hauptgeschäft oder Hauptberuf unmittelbar oder durch andere Personen, mit denen sie verbunden ist, wesentliche Hilfe, Unterstützung oder Beratung in Steuerangelegenheiten leistet;
    • b) Notare, Rechtsanwälte und andere unabhängige Angehörige der Rechtsberufe, wenn sie sich entweder im Namen und für ihren Mandanten an Finanz- oder Immobilientransaktionen beteiligen oder ihren Mandanten bei der Planung oder Durchführung von Transaktionen in Bezug auf Folgendes unterstützen:
    • i) Kauf und Verkauf von Immobilien oder Unternehmen;
    • ii) Verwaltung von Geld, Wertpapieren oder sonstigen Vermögenswerten des Mandanten, einschließlich Kryptowerte;
    • iii) Eröffnung oder Verwaltung von Bank-, Spar-, Wertpapier- oder Kryptowertekonten;
    • iv) Organisation der zur Gründung, zum Betrieb oder zur Verwaltung von Gesellschaften erforderlichen Einlagen;
    • v) Gründung, Errichtung, Betrieb oder Verwaltung von Trusts, Gesellschaften, Stiftungen oder ähnlichen Strukturen;
    • c) Dienstleister für Trusts oder Gesellschaften;
    • d) Immobilienmakler und sonstige Immobilienfachleute, soweit sie als Vermittler bei Immobilientransaktionen tätig sind, einschließlich der Vermietung unbeweglicher Sachen bei Transaktionen, bei denen die monatliche Miete mindestens 10 000 EUR oder den Gegenwert in Landeswährung beträgt, unabhängig vom verwendeten Zahlungsmittel;
    • e) Personen, die regelmäßig oder hauptsächlich beruflich mit Edelmetallen und Edelsteinen handeln;
    • f) Personen, die regelmäßig oder hauptsächlich beruflich mit hochwertigen Gütern handeln;
    • g) Anbieter von Glücksspieldienstleistungen;
    • h) Anbieter von Crowdfunding-Dienstleistungen und Crowdfunding-Vermittler;
    • i) Personen, die mit Kulturgütern handeln oder deren Handel vermitteln, auch wenn dies durch Kunstgalerien und Auktionshäuser erfolgt, sofern der Wert der Transaktion oder verbundener Transaktionen mindestens 10 000 EUR oder den Gegenwert in Landeswährung beträgt;
    • j) Personen, die Kulturgüter und hochwertige Güter lagern, mit ihnen handeln oder ihren Handel vermitteln, wenn dies in Freizonen und Zolllagern erfolgt und der Wert der Transaktion oder verbundener Transaktionen mindestens 10 000 EUR oder den Gegenwert in Landeswährung beträgt;
    • k) Kreditvermittler für Hypothekar- und Verbraucherkredite, ausgenommen Kreditinstitute und Finanzinstitute, mit Ausnahme der Kreditvermittler, die Tätigkeiten unter der Verantwortung eines oder mehrerer Kreditgeber oder Kreditvermittler ausüben;
    • l) Betreiber im Bereich der Investitionsmigration, die befugt sind, Drittstaatsangehörige zu vertreten oder Vermittlungsdienste für sie anzubieten, wenn diese im Austausch gegen jegliche Art von Investition Aufenthaltsrechte in einem Mitgliedstaat erwerben wollen, einschließlich Kapitalübertragungen, Kauf oder Miete von Immobilien, Investitionen in Staatsanleihen, Investitionen in Gesellschaften, Spenden oder Ausstattung einer Tätigkeit zum Gemeinwohl sowie Beiträge zum Staatshaushalt;
    • m) nichtfinanzielle Holdinggesellschaften mit gemischter Tätigkeit;
    • n) Fußballvermittler;
    • o) professionelle Fußballvereine in Bezug auf folgende Transaktionen:
    • i) Transaktionen mit einem Investor;
    • ii) Transaktionen mit einem Sponsor;
    • iii) Transaktionen mit Fußballvermittlern oder anderen Vermittlern;
    • iv) Transaktionen zum Zweck des Transfers eines Fußballspielers.
Article 4 — Exemptions for certain providers of gambling services Article 4 — Exemptions for certain providers of gambling services Article 4 — Ausnahmen für bestimmte Anbieter von Glücksspieldienstleistungen
1 1 1

Member States may decide to exempt, in full or in part, providers of gambling services from the requirements set out in this Regulation on the basis of the proven low risk posed by the nature and, where appropriate, the scale of operations of such services.

The exemption referred to in the first subparagraph shall not apply to:

  • (a) casinos;
  • (b) providers of gambling services the principal activity of which is to provide online gambling services or sport betting services, other than:

    • (i) online gambling services operated by the State, whether through a public authority or an enterprise or body controlled by the State;
    • (ii) online gambling services the organisation, operation and administration of which is regulated by the State.

Member States may decide to exempt, in full or in part, providers of gambling services from the requirements set out in this Regulation on the basis of the proven low risk posed by the nature and, where appropriate, the scale of operations of such services.

The exemption referred to in the first subparagraph shall not apply to:

  • (a) casinos;
  • (b) providers of gambling services the principal activity of which is to provide online gambling services or sport betting services, other than:
    • (i) online gambling services operated by the State, whether through a public authority or an enterprise or body controlled by the State;
    • (ii) online gambling services the organisation, operation and administration of which is regulated by the State.

Die Mitgliedstaaten können beschließen, Anbieter von Glücksspieldienstleistungen aufgrund des nachgewiesenen geringen Risikos, das sich aus der Art und gegebenenfalls dem Umfang der Tätigkeiten dieser Dienste ergibt, ganz oder teilweise von den Anforderungen dieser Verordnung auszunehmen.

Die im ersten Unterabsatz genannte Ausnahme gilt nicht für:

  • a) Kasinos;
  • b) Anbieter von Glücksspieldienstleistungen, deren Haupttätigkeit in der Erbringung von Online-Glücksspieldienstleistungen oder Sportwetten besteht, mit Ausnahme von:
    • i) vom Staat betriebenen Online-Glücksspieldienstleistungen, unabhängig davon, ob sie durch eine öffentliche Behörde oder ein vom Staat kontrolliertes Unternehmen oder eine solche Einrichtung betrieben werden;
    • ii) Online-Glücksspieldienstleistungen, deren Organisation, Betrieb und Verwaltung staatlich geregelt sind.
2 2 2

For the purposes of paragraph 1, Member States shall carry out a risk assessment of gambling services assessing:

  • (a) money laundering and terrorist financing threats and vulnerabilities, and mitigating factors of the gambling services;
  • (b) the risks linked to the size of the transactions and payment methods used;
  • (c) the geographical area in which the gambling services are administered, including their cross border dimension and accessibility from other Member States or third countries.

When carrying out the risk assessments referred to in the first subparagraph of this paragraph, Member States shall take into account the findings of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive(EU) 2024/1640.

For the purposes of paragraph 1, Member States shall carry out a risk assessment of gambling services assessing:

  • (a) money laundering and terrorist financing threats and vulnerabilities, and mitigating factors of the gambling services;
  • (b) the risks linked to the size of the transactions and payment methods used;
  • (c) the geographical area in which the gambling services are administered, including their cross border dimension and accessibility from other Member States or third countries.

When carrying out the risk assessments referred to in the first subparagraph of this paragraph, Member States shall take into account the findings of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive(EU) 2024/1640.

Für die Zwecke des Absatzes 1 führen die Mitgliedstaaten eine Risikobewertung von Glücksspieldienstleistungen durch, bei der Folgendes bewertet wird:

  • a) Bedrohungen und Schwachstellen im Zusammenhang mit Geldwäsche und Terrorismusfinanzierung sowie risikomindernde Faktoren der Glücksspieldienstleistungen;
  • b) die mit der Höhe der Transaktionen und den verwendeten Zahlungsmethoden verbundenen Risiken;
  • c) das geografische Gebiet, in dem die Glücksspieldienstleistungen verwaltet werden, einschließlich ihrer grenzüberschreitenden Dimension und ihrer Zugänglichkeit aus anderen Mitgliedstaaten oder Drittländern.

Bei der Durchführung der im ersten Unterabsatz dieses Absatzes genannten Risikobewertungen berücksichtigen die Mitgliedstaaten die Ergebnisse der von der Kommission gemäß Artikel 7 der Richtlinie (EU) 2024/1640 auf Unionsebene durchgeführten Risikobewertung.

3 3 3

Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Die Mitgliedstaaten führen risikobasierte Überwachungstätigkeiten durch oder treffen andere geeignete Maßnahmen, um sicherzustellen, dass die nach diesem Artikel gewährten Ausnahmen nicht missbraucht werden.

Article 5 — Exemptions for certain professional football clubs Article 5 — Exemptions for certain professional football clubs Article 5 — Ausnahmen für bestimmte professionelle Fußballvereine
1 1 1

Member States may decide to exempt, in full or in part, professional football clubs that participate in the highest division of the national football league and that have a total annual turnover of less than EUR 5000000, or the equivalent in national currency, for each of the previous 2 calendar years from the requirements set out in this Regulation on the basis of the proven low risk posed by the nature and the scale of operation of such professional football clubs.Member States may decide to exempt, in full or in part, professional football clubs that participate in a division lower than the highest division of the national football league from the requirements set out in this Regulation on the basis of proven low risk posed by the nature and the scale of operation of such professional football clubs.

Member States may decide to exempt, in full or in part, professional football clubs that participate in the highest division of the national football league and that have a total annual turnover of less than EUR 5000000, or the equivalent in national currency, for each of the previous 2 calendar years from the requirements set out in this Regulation on the basis of the proven low risk posed by the nature and the scale of operation of such professional football clubs.Member States may decide to exempt, in full or in part, professional football clubs that participate in a division lower than the highest division of the national football league from the requirements set out in this Regulation on the basis of proven low risk posed by the nature and the scale of operation of such professional football clubs.

Die Mitgliedstaaten können beschließen, professionelle Fußballvereine, die an der höchsten Spielklasse der nationalen Fußballliga teilnehmen und in jedem der letzten zwei Kalenderjahre einen jährlichen Gesamtumsatz von weniger als 5 000 000 EUR oder den Gegenwert in Landeswährung erzielt haben, aufgrund des nachgewiesenen geringen Risikos, das sich aus der Art und dem Umfang ihrer Tätigkeit ergibt, ganz oder teilweise von den Anforderungen dieser Verordnung auszunehmen. Die Mitgliedstaaten können beschließen, professionelle Fußballvereine, die an einer niedrigeren als der höchsten Spielklasse der nationalen Fußballliga teilnehmen, aufgrund des nachgewiesenen geringen Risikos, das sich aus der Art und dem Umfang ihrer Tätigkeit ergibt, ganz oder teilweise von den Anforderungen dieser Verordnung auszunehmen.

2 2 2

For the purposes of paragraph 1, Member States shall carry out a risk assessment of the professional football clubs assessing:

  • (a) money laundering and terrorist financing threats and vulnerabilities, and mitigating factors of the professional football clubs;
  • (b) the risks linked to the size and cross-border nature of the transactions.

When carrying out the risk assessments referred to in the first subparagraph of this paragraph, Member States shall take into account the findings of the risk assessments at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640.

For the purposes of paragraph 1, Member States shall carry out a risk assessment of the professional football clubs assessing:

  • (a) money laundering and terrorist financing threats and vulnerabilities, and mitigating factors of the professional football clubs;
  • (b) the risks linked to the size and cross-border nature of the transactions.

When carrying out the risk assessments referred to in the first subparagraph of this paragraph, Member States shall take into account the findings of the risk assessments at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640.

Für die Zwecke des Absatzes 1 führen die Mitgliedstaaten eine Risikobewertung der professionellen Fußballvereine durch, bei der Folgendes bewertet wird:

  • a) Bedrohungen und Schwachstellen im Zusammenhang mit Geldwäsche und Terrorismusfinanzierung sowie risikomindernde Faktoren der professionellen Fußballvereine;
  • b) die mit dem Umfang und dem grenzüberschreitenden Charakter der Transaktionen verbundenen Risiken.

Bei der Durchführung der im ersten Unterabsatz dieses Absatzes genannten Risikobewertungen berücksichtigen die Mitgliedstaaten die Ergebnisse der von der Kommission gemäß Artikel 7 der Richtlinie (EU) 2024/1640 auf Unionsebene durchgeführten Risikobewertungen.

3 3 3

Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Die Mitgliedstaaten führen risikobasierte Überwachungstätigkeiten durch oder treffen andere geeignete Maßnahmen, um sicherzustellen, dass die nach diesem Artikel gewährten Ausnahmen nicht missbraucht werden.

Article 6 — Exemptions for certain financial activities Article 6 — Exemptions for certain financial activities Article 6 — Ausnahmen für bestimmte Finanztätigkeiten
1 1 1

With the exception of persons engaged in the activity of money remittance as defined in Article 4, point (22), of Directive (EU) 2015/2366, Member States may decide to exempt legal or natural persons that engage in a financial activity as listed in Annex I, points (2) to (12), (14) and (15), to Directive 2013/36/EU on an occasional or very limited basis where there is little risk of money laundering or terrorist financing from the requirements set out in this Regulation, provided that all of the following criteria are met:

  • (a) the financial activity is limited in absolute terms;
  • (b) the financial activity is limited on a transaction basis;
  • (c) the financial activity is not the main activity of such persons;
  • (d) the financial activity is ancillary and directly related to the main activity of such persons;
  • (e) the main activity of such persons is not an activity referred to in Article 3, point (3)(a) to (d) or (g) of this Regulation;
  • (f) the financial activity is provided only to the customers of the main activity of such persons and is not generally offered to the public.

With the exception of persons engaged in the activity of money remittance as defined in Article 4, point (22), of Directive (EU) 2015/2366, Member States may decide to exempt legal or natural persons that engage in a financial activity as listed in Annex I, points (2) to (12), (14) and (15), to Directive 2013/36/EU on an occasional or very limited basis where there is little risk of money laundering or terrorist financing from the requirements set out in this Regulation, provided that all of the following criteria are met:

  • (a) the financial activity is limited in absolute terms;
  • (b) the financial activity is limited on a transaction basis;
  • (c) the financial activity is not the main activity of such persons;
  • (d) the financial activity is ancillary and directly related to the main activity of such persons;
  • (e) the main activity of such persons is not an activity referred to in Article 3, point (3)(a) to (d) or (g) of this Regulation;
  • (f) the financial activity is provided only to the customers of the main activity of such persons and is not generally offered to the public.

Mit Ausnahme von Personen, die die in Artikel 4 Nummer 22 der Richtlinie (EU) 2015/2366 definierte Geldtransferdienstleistung erbringen, können die Mitgliedstaaten natürliche oder juristische Personen, die gelegentlich oder in sehr begrenztem Umfang eine in Anhang I Nummern 2 bis 12, 14 und 15 der Richtlinie 2013/36/EU aufgeführte Finanztätigkeit ausüben, bei geringem Risiko von Geldwäsche oder Terrorismusfinanzierung von den Anforderungen dieser Verordnung ausnehmen, sofern alle folgenden Kriterien erfüllt sind:

  • a) Die Finanztätigkeit ist ihrem absoluten Umfang nach begrenzt;
  • b) die Finanztätigkeit ist je Transaktion begrenzt;
  • c) die Finanztätigkeit ist nicht die Haupttätigkeit dieser Personen;
  • d) die Finanztätigkeit ist nebensächlich und steht in unmittelbarem Zusammenhang mit der Haupttätigkeit dieser Personen;
  • e) die Haupttätigkeit dieser Personen ist keine in Artikel 3 Nummer 3 Buchstaben a bis d oder g dieser Verordnung genannte Tätigkeit;
  • f) die Finanztätigkeit wird nur den Kunden der Haupttätigkeit dieser Personen angeboten und der Öffentlichkeit nicht allgemein zugänglich gemacht.
2 2 2

For the purposes of paragraph 1, point (a), Member States shall require that the total turnover of the financial activity does not exceed a threshold which shall be sufficiently low. That threshold shall be established at national level, depending on the type of financial activity.

For the purposes of paragraph 1, point (a), Member States shall require that the total turnover of the financial activity does not exceed a threshold which shall be sufficiently low. That threshold shall be established at national level, depending on the type of financial activity.

Für die Zwecke des Absatzes 1 Buchstabe a schreiben die Mitgliedstaaten vor, dass der Gesamtumsatz aus der Finanztätigkeit einen ausreichend niedrigen Schwellenwert nicht überschreitet. Dieser Schwellenwert wird auf nationaler Ebene nach der Art der Finanztätigkeit festgelegt.

3 3 3

For the purposes of paragraph 1, point (b), Member States shall apply a maximum threshold per customer and per single transaction, whether the transaction is carried out in a single operation or through linked transactions. That maximum threshold shall be established at national level, depending on the type of financial activity. It shall be sufficiently low in order to ensure that the types of transactions in question are an impractical and inefficient method for money laundering or terrorist financing, and shall not exceed EUR 1000 or the equivalent in national currency, irrespective of the means of payment.

For the purposes of paragraph 1, point (b), Member States shall apply a maximum threshold per customer and per single transaction, whether the transaction is carried out in a single operation or through linked transactions. That maximum threshold shall be established at national level, depending on the type of financial activity. It shall be sufficiently low in order to ensure that the types of transactions in question are an impractical and inefficient method for money laundering or terrorist financing, and shall not exceed EUR 1000 or the equivalent in national currency, irrespective of the means of payment.

Für die Zwecke des Absatzes 1 Buchstabe b wenden die Mitgliedstaaten einen Höchstschwellenwert je Kunde und je Einzeltransaktion an, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder durch verbundene Transaktionen durchgeführt wird. Dieser Höchstschwellenwert wird auf nationaler Ebene nach der Art der Finanztätigkeit festgelegt. Er muss ausreichend niedrig sein, um sicherzustellen, dass die betreffenden Transaktionsarten eine ungeeignete und ineffiziente Methode zur Geldwäsche oder Terrorismusfinanzierung darstellen, und darf unabhängig vom Zahlungsmittel 1 000 EUR oder den Gegenwert in Landeswährung nicht überschreiten.

4 4 4

For the purposes of paragraph 1, point (c), Member States shall require that the turnover of the financial activity does not exceed 5 % of the total turnover of the natural or legal person concerned.

For the purposes of paragraph 1, point (c), Member States shall require that the turnover of the financial activity does not exceed 5 % of the total turnover of the natural or legal person concerned.

Für die Zwecke des Absatzes 1 Buchstabe c schreiben die Mitgliedstaaten vor, dass der Umsatz aus der Finanztätigkeit 5 % des Gesamtumsatzes der betreffenden natürlichen oder juristischen Person nicht überschreitet.

5 5 5

In assessing the risk of money laundering or terrorist financing for the purposes of this Article, Member States shall pay particular attention to any financial activity which is considered to be particularly likely, by its nature, to be used or abused for the purposes of money laundering or terrorist financing.

In assessing the risk of money laundering or terrorist financing for the purposes of this Article, Member States shall pay particular attention to any financial activity which is considered to be particularly likely, by its nature, to be used or abused for the purposes of money laundering or terrorist financing.

Bei der Bewertung des Risikos von Geldwäsche oder Terrorismusfinanzierung für die Zwecke dieses Artikels schenken die Mitgliedstaaten jeder Finanztätigkeit besondere Aufmerksamkeit, die aufgrund ihrer Art als besonders geeignet gilt, für Zwecke der Geldwäsche oder Terrorismusfinanzierung genutzt oder missbraucht zu werden.

6 6 6

Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Die Mitgliedstaaten führen risikobasierte Überwachungstätigkeiten durch oder treffen andere geeignete Maßnahmen, um sicherzustellen, dass die nach diesem Artikel gewährten Ausnahmen nicht missbraucht werden.

Article 7 — Prior notification of exemptions Article 7 — Prior notification of exemptions Article 7 — Vorherige Mitteilung von Ausnahmen
1 1 1

Member States shall notify the Commission of any exemption that they intend to grant in accordance with Articles 4, 5 and 6 without delay. The notification shall include a justification based on the relevant risk assessment carried out by the Member State to sustain the exemption.

Member States shall notify the Commission of any exemption that they intend to grant in accordance with Articles 4, 5 and 6 without delay. The notification shall include a justification based on the relevant risk assessment carried out by the Member State to sustain the exemption.

Die Mitgliedstaaten teilen der Kommission unverzüglich jede Ausnahme mit, die sie gemäß den Artikeln 4, 5 und 6 zu gewähren beabsichtigen. Die Mitteilung enthält eine auf der einschlägigen Risikobewertung des Mitgliedstaats beruhende Begründung für die Ausnahme.

2 2 2

The Commission shall within 2 months of the notification referred to in paragraph 1 take one of the following actions:

  • (a) confirm that the exemption may be granted on the basis of the justification given by the Member State;
  • (b) by reasoned decision, declare that the exemption may not be granted.

For the purposes of the first subparagraph, the Commission may request additional information from the notifying Member State.

The Commission shall within 2 months of the notification referred to in paragraph 1 take one of the following actions:

  • (a) confirm that the exemption may be granted on the basis of the justification given by the Member State;
  • (b) by reasoned decision, declare that the exemption may not be granted.

For the purposes of the first subparagraph, the Commission may request additional information from the notifying Member State.

Die Kommission ergreift innerhalb von zwei Monaten nach der in Absatz 1 genannten Mitteilung eine der folgenden Maßnahmen:

  • a) Sie bestätigt, dass die Ausnahme auf der Grundlage der vom Mitgliedstaat vorgelegten Begründung gewährt werden kann;
  • b) sie erklärt durch begründeten Beschluss, dass die Ausnahme nicht gewährt werden darf.

Für die Zwecke des ersten Unterabsatzes kann die Kommission den mitteilenden Mitgliedstaat um zusätzliche Informationen ersuchen.

3 3 3

Upon receipt of a confirmation by the Commission pursuant to paragraph 2, point (a), of this Article, Member States may adopt a decision granting the exemption. The decision shall state the reasons on which it is based. Member States shall review such decisions regularly, and in any case when they update their national risk assessment pursuant to Article 8 of Directive (EU) 2024/1640.

Upon receipt of a confirmation by the Commission pursuant to paragraph 2, point (a), of this Article, Member States may adopt a decision granting the exemption. The decision shall state the reasons on which it is based. Member States shall review such decisions regularly, and in any case when they update their national risk assessment pursuant to Article 8 of Directive (EU) 2024/1640.

Nach Erhalt einer Bestätigung der Kommission gemäß Absatz 2 Buchstabe a dieses Artikels können die Mitgliedstaaten einen Beschluss über die Gewährung der Ausnahme erlassen. In dem Beschluss sind die Gründe anzugeben, auf denen er beruht. Die Mitgliedstaaten überprüfen solche Beschlüsse regelmäßig und in jedem Fall, wenn sie ihre nationale Risikobewertung gemäß Artikel 8 der Richtlinie (EU) 2024/1640 aktualisieren.

4 4 4

By 10 October 2027, Member States shall notify to the Commission the exemptions granted pursuant to Article 2(2) and (3) of Directive (EU) 2015/849 in place on 10 July 2027.

By 10 October 2027, Member States shall notify to the Commission the exemptions granted pursuant to Article 2(2) and (3) of Directive (EU) 2015/849 in place on 10 July 2027.

Bis zum 10. Oktober 2027 teilen die Mitgliedstaaten der Kommission die gemäß Artikel 2 Absätze 2 und 3 der Richtlinie (EU) 2015/849 gewährten und am 10. Juli 2027 geltenden Ausnahmen mit.

5 5 5

The Commission shall publish every year in the Official Journal of the European Union the list of exemptions granted pursuant to this Article and make that list publicly available on its website.

The Commission shall publish every year in the Official Journal of the European Union the list of exemptions granted pursuant to this Article and make that list publicly available on its website.

Die Kommission veröffentlicht jedes Jahr im Amtsblatt der Europäischen Union die Liste der nach diesem Artikel gewährten Ausnahmen und macht diese Liste auf ihrer Website öffentlich zugänglich.

SECTION 3 — Cross-border operations SECTION 3 — Cross-border operations SECTION 3 — Grenzüberschreitende Tätigkeiten
Article 8 — Notification of cross-border operations and application of national law Article 8 — Notification of cross-border operations and application of national law Article 8 — Mitteilung grenzüberschreitender Tätigkeiten und Anwendung des nationalen Rechts
1 1 1

Obliged entities wishing to carry out activities within the territory of another Member State for the first time shall notify the supervisors of their home Member State of the activities which they intend to carry out in that other Member State. That notification shall be submitted as soon as the obliged entity takes steps to carry out the activities, and, in the case of establishments at least 3 months prior to the commencement of those activities. Obliged entities shall immediately notify the supervisors of their home Member State upon commencement of those activities in that other Member State.The first subparagraph shall not apply to obliged entities subject to specific notification procedures for the exercise of the freedom of establishment and of the freedom to provide services under other Union legal acts or to cases where the obliged entity is subject to specific authorisation requirements in order to operate in the territory of that other Member State.

Obliged entities wishing to carry out activities within the territory of another Member State for the first time shall notify the supervisors of their home Member State of the activities which they intend to carry out in that other Member State. That notification shall be submitted as soon as the obliged entity takes steps to carry out the activities, and, in the case of establishments at least 3 months prior to the commencement of those activities. Obliged entities shall immediately notify the supervisors of their home Member State upon commencement of those activities in that other Member State.The first subparagraph shall not apply to obliged entities subject to specific notification procedures for the exercise of the freedom of establishment and of the freedom to provide services under other Union legal acts or to cases where the obliged entity is subject to specific authorisation requirements in order to operate in the territory of that other Member State.

Verpflichtete Unternehmen, die erstmals Tätigkeiten im Hoheitsgebiet eines anderen Mitgliedstaats ausüben möchten, teilen den Aufsichtsbehörden ihres Herkunftsmitgliedstaats die Tätigkeiten mit, die sie in diesem anderen Mitgliedstaat ausüben wollen. Diese Mitteilung wird übermittelt, sobald das verpflichtete Unternehmen Schritte zur Ausübung der Tätigkeiten unternimmt, und im Falle von Niederlassungen mindestens drei Monate vor Aufnahme dieser Tätigkeiten. Verpflichtete Unternehmen teilen den Aufsichtsbehörden ihres Herkunftsmitgliedstaats die Aufnahme dieser Tätigkeiten in dem anderen Mitgliedstaat unverzüglich mit. Der erste Unterabsatz gilt nicht für verpflichtete Unternehmen, die nach anderen Rechtsakten der Union besonderen Mitteilungsverfahren für die Ausübung der Niederlassungsfreiheit und des freien Dienstleistungsverkehrs unterliegen, oder für Fälle, in denen das verpflichtete Unternehmen für seine Tätigkeit im Hoheitsgebiet dieses anderen Mitgliedstaats einer besonderen Genehmigungspflicht unterliegt.

2 2 2

Any planned change to the information communicated under paragraph 1 shall be communicated by the obliged entity to the supervisor of the home Member State at least 1 month before making the change.

Any planned change to the information communicated under paragraph 1 shall be communicated by the obliged entity to the supervisor of the home Member State at least 1 month before making the change.

Jede geplante Änderung der gemäß Absatz 1 mitgeteilten Informationen wird dem Aufseher des Herkunftsmitgliedstaats vom verpflichteten Unternehmen mindestens einen Monat vor der Änderung mitgeteilt.

3 3 3

Where this Regulation allows Member States to adopt additional rules applicable to obliged entities, obliged entities shall comply with the national rules of the Member State in which they are established.

Where this Regulation allows Member States to adopt additional rules applicable to obliged entities, obliged entities shall comply with the national rules of the Member State in which they are established.

Soweit diese Verordnung den Mitgliedstaaten den Erlass zusätzlicher Vorschriften für verpflichtete Unternehmen gestattet, halten verpflichtete Unternehmen die nationalen Vorschriften des Mitgliedstaats ein, in dem sie niedergelassen sind.

4 4 4

Where obliged entities operate establishments in several Member States, they shall ensure that each establishment applies the rules of the Member State in which it is located.

Where obliged entities operate establishments in several Member States, they shall ensure that each establishment applies the rules of the Member State in which it is located.

Betreiben verpflichtete Unternehmen Niederlassungen in mehreren Mitgliedstaaten, stellen sie sicher, dass jede Niederlassung die Vorschriften des Mitgliedstaats anwendet, in dem sie sich befindet.

5 5 5

Where obliged entities as referred to in Article 38(1) of Directive (EU) 2024/1640 operate, in other Member States than the one where they are established through agents, distributors, or through other types of infrastructure located in those other Member States under the freedom to provide services, they shall apply the rules of the Member States in which they provide services in relation to those activities, unless Article 38(2) of that Directive applies, in which case they shall apply the rules of the Member State where their head office is located.

Where obliged entities as referred to in Article 38(1) of Directive (EU) 2024/1640 operate, in other Member States than the one where they are established through agents, distributors, or through other types of infrastructure located in those other Member States under the freedom to provide services, they shall apply the rules of the Member States in which they provide services in relation to those activities, unless Article 38(2) of that Directive applies, in which case they shall apply the rules of the Member State where their head office is located.

Üben verpflichtete Unternehmen im Sinne des Artikels 38 Absatz 1 der Richtlinie (EU) 2024/1640 in anderen Mitgliedstaaten als demjenigen, in dem sie niedergelassen sind, über Agenten, Vertriebsstellen oder andere Arten von Infrastruktur, die sich in diesen anderen Mitgliedstaaten befinden, im Rahmen des freien Dienstleistungsverkehrs Tätigkeiten aus, wenden sie in Bezug auf diese Tätigkeiten die Vorschriften der Mitgliedstaaten an, in denen sie Dienstleistungen erbringen, es sei denn, Artikel 38 Absatz 2 dieser Richtlinie findet Anwendung; in diesem Fall wenden sie die Vorschriften des Mitgliedstaats an, in dem sich ihr Sitz befindet.

6 6 6

Where obliged entities are required to appoint a central contact point pursuant to Article 41 of Directive (EU) 2024/1640, they shall ensure that the central contact point is able to ensure compliance with applicable law on behalf of the obliged entity.

Where obliged entities are required to appoint a central contact point pursuant to Article 41 of Directive (EU) 2024/1640, they shall ensure that the central contact point is able to ensure compliance with applicable law on behalf of the obliged entity.

Sind verpflichtete Unternehmen gemäß Artikel 41 der Richtlinie (EU) 2024/1640 verpflichtet, eine zentrale Kontaktstelle zu benennen, stellen sie sicher, dass die zentrale Kontaktstelle in der Lage ist, die Einhaltung des geltenden Rechts im Namen des verpflichteten Unternehmens sicherzustellen.

CHAPTER II — INTERNAL POLICIES, PROCEDURES AND CONTROLS OF OBLIGED ENTITIES CHAPTER II — INTERNAL POLICIES, PROCEDURES AND CONTROLS OF OBLIGED ENTITIES CHAPTER II — INTERNE STRATEGIEN, VERFAHREN UND KONTROLLEN VERPFLICHTETER UNTERNEHMEN
SECTION 1 — Internal policies, procedures and controls, risk assessment and staff SECTION 1 — Internal policies, procedures and controls, risk assessment and staff SECTION 1 — Interne Strategien, Verfahren und Kontrollen, Risikobewertung und Personal
Article 9 — Scope of internal policies, procedures and controls Article 9 — Scope of internal policies, procedures and controls Article 9 — Geltungsbereich der internen Strategien, Verfahren und Kontrollen
1 1 1

Obliged entities shall have in place internal policies, procedures and controls in order to ensure compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor and in particular to:

  • (a) mitigate and manage effectively the risks of money laundering and terrorist financing identified at the level of the Union, the Member State and the obliged entity;
  • (b) in addition to the obligation to apply targeted financial sanctions, mitigate and manage the risks of non-implementation and evasion of targeted financial sanctions.

The policies, procedures and controls referred to in the first subparagraph shall be proportionate to the nature of the business, including its risks and complexity, and the size of the obliged entity and shall cover all the activities of the obliged entity that fall under the scope of this Regulation.

Obliged entities shall have in place internal policies, procedures and controls in order to ensure compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor and in particular to:

  • (a) mitigate and manage effectively the risks of money laundering and terrorist financing identified at the level of the Union, the Member State and the obliged entity;
  • (b) in addition to the obligation to apply targeted financial sanctions, mitigate and manage the risks of non-implementation and evasion of targeted financial sanctions.

The policies, procedures and controls referred to in the first subparagraph shall be proportionate to the nature of the business, including its risks and complexity, and the size of the obliged entity and shall cover all the activities of the obliged entity that fall under the scope of this Regulation.

Verpflichtete Unternehmen verfügen über interne Strategien, Verfahren und Kontrollen, um die Einhaltung dieser Verordnung, der Verordnung (EU) 2023/1113 und jedes von einem Aufseher erlassenen Verwaltungsakts sicherzustellen und insbesondere um:

  • a) die auf Unionsebene, auf Ebene des Mitgliedstaats und auf Ebene des verpflichteten Unternehmens ermittelten Risiken der Geldwäsche und Terrorismusfinanzierung wirksam zu mindern und zu steuern;
  • b) zusätzlich zur Pflicht zur Anwendung gezielter finanzieller Sanktionen die Risiken der Nichtumsetzung und Umgehung gezielter finanzieller Sanktionen zu mindern und zu steuern.

Die im ersten Unterabsatz genannten Strategien, Verfahren und Kontrollen müssen der Art der Geschäftstätigkeit, einschließlich ihrer Risiken und Komplexität, sowie der Größe des verpflichteten Unternehmens angemessen sein und sämtliche Tätigkeiten des verpflichteten Unternehmens abdecken, die in den Geltungsbereich dieser Verordnung fallen.

2 2 2

The policies, procedures and controls referred to in paragraph 1 shall include:

  • (a) internal policies and procedures, including in particular:

    • (i) the carrying out and updating of the business-wide risk assessment;
    • (ii) the obliged entity’s risk management framework;
    • (iii) customer due diligence to implement Chapter III of this Regulation, including procedures to determine whether the customer, the beneficial owner, or the person on whose behalf or for the benefit of whom a transaction or activity is being conducted, is a politically exposed person or a family member or person known to be a close associate;
    • (iv) reporting of suspicious transactions;
    • (v) outsourcing and reliance on customer due diligence performed by other obliged entities;
    • (vi) record retention and policies in relation to the processing of personal data pursuant to Articles 76 and 77;
    • (vii) the monitoring and management of compliance with such internal policies and procedures in accordance with point (b) of this paragraph, the identification and management of deficiencies and the implementation of remedial actions;
    • (viii) the verification, proportionate to the risks associated with the tasks and functions to be performed, when recruiting and assigning staff to certain tasks and functions and when appointing agents and distributors, that those persons are of good repute;
    • (ix) the internal communication of the obliged entity’s internal policies, procedures and controls, including to its agents, distributors and service providers involved in the implementation of its AML/CFT policies;
    • (x) a policy on the training of employees and, where relevant, agents and distributors with regard to measures in place in the obliged entity to comply with the requirements of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor;
  • (b) internal controls and an independent audit function to test the internal policies and procedures referred to in point (a) of this paragraph and the controls in place in the obliged entity; in the absence of an independent audit function, obliged entities may have this test carried out by an external expert.

The internal policies, procedures and controls set out in the first subparagraph shall be recorded in writing. Internal policies shall be approved by the management body in its management function. Internal procedures and controls shall be approved at least at the level of the compliance manager.

The policies, procedures and controls referred to in paragraph 1 shall include:

  • (a) internal policies and procedures, including in particular:
    • (i) the carrying out and updating of the business-wide risk assessment;
    • (ii) the obliged entity’s risk management framework;
    • (iii) customer due diligence to implement Chapter III of this Regulation, including procedures to determine whether the customer, the beneficial owner, or the person on whose behalf or for the benefit of whom a transaction or activity is being conducted, is a politically exposed person or a family member or person known to be a close associate;
    • (iv) reporting of suspicious transactions;
    • (v) outsourcing and reliance on customer due diligence performed by other obliged entities;
    • (vi) record retention and policies in relation to the processing of personal data pursuant to Articles 76 and 77;
    • (vii) the monitoring and management of compliance with such internal policies and procedures in accordance with point (b) of this paragraph, the identification and management of deficiencies and the implementation of remedial actions;
    • (viii) the verification, proportionate to the risks associated with the tasks and functions to be performed, when recruiting and assigning staff to certain tasks and functions and when appointing agents and distributors, that those persons are of good repute;
    • (ix) the internal communication of the obliged entity’s internal policies, procedures and controls, including to its agents, distributors and service providers involved in the implementation of its AML/CFT policies;
    • (x) a policy on the training of employees and, where relevant, agents and distributors with regard to measures in place in the obliged entity to comply with the requirements of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor;
  • (b) internal controls and an independent audit function to test the internal policies and procedures referred to in point (a) of this paragraph and the controls in place in the obliged entity; in the absence of an independent audit function, obliged entities may have this test carried out by an external expert.

The internal policies, procedures and controls set out in the first subparagraph shall be recorded in writing. Internal policies shall be approved by the management body in its management function. Internal procedures and controls shall be approved at least at the level of the compliance manager.

Die in Absatz 1 genannten Strategien, Verfahren und Kontrollen umfassen:

  • a) interne Strategien und Verfahren, insbesondere:
    • i) die Durchführung und Aktualisierung der unternehmensweiten Risikobewertung;
    • ii) den Rahmen des Risikomanagements des verpflichteten Unternehmens;
    • iii) die Sorgfaltspflichten gegenüber Kunden zur Umsetzung des Kapitels III dieser Verordnung, einschließlich Verfahren zur Feststellung, ob der Kunde, der wirtschaftliche Eigentümer oder die Person, in deren Namen oder zu deren Gunsten eine Transaktion oder Tätigkeit durchgeführt wird, eine politisch exponierte Person, ein Familienmitglied oder eine bekanntermaßen nahestehende Person ist;
    • iv) die Meldung verdächtiger Transaktionen;
    • v) die Auslagerung und das Vertrauen auf von anderen verpflichteten Unternehmen durchgeführte Sorgfaltspflichten gegenüber Kunden;
    • vi) die Aufbewahrung von Aufzeichnungen und Strategien hinsichtlich der Verarbeitung personenbezogener Daten gemäß den Artikeln 76 und 77;
    • vii) die Überwachung und Steuerung der Einhaltung dieser internen Strategien und Verfahren gemäß Buchstabe b dieses Absatzes, die Ermittlung und Steuerung von Mängeln sowie die Durchführung von Abhilfemaßnahmen;
    • viii) die der mit den wahrzunehmenden Aufgaben und Funktionen verbundenen Risiken angemessene Überprüfung bei der Einstellung und Zuweisung von Personal zu bestimmten Aufgaben und Funktionen sowie bei der Bestellung von Agenten und Vertriebsstellen, dass diese Personen einen guten Leumund haben;
    • ix) die interne Mitteilung der internen Strategien, Verfahren und Kontrollen des verpflichteten Unternehmens, auch an seine Agenten, Vertriebsstellen und Dienstleister, die an der Umsetzung seiner Strategien zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung beteiligt sind;
    • x) eine Strategie für die Schulung von Beschäftigten und gegebenenfalls Agenten und Vertriebsstellen in Bezug auf die Maßnahmen, die das verpflichtete Unternehmen zur Einhaltung der Anforderungen dieser Verordnung, der Verordnung (EU) 2023/1113 und jedes von einem Aufseher erlassenen Verwaltungsakts getroffen hat;
  • b) interne Kontrollen und eine unabhängige Prüfungsfunktion zur Prüfung der in Buchstabe a dieses Absatzes genannten internen Strategien und Verfahren sowie der im verpflichteten Unternehmen bestehenden Kontrollen; fehlt eine unabhängige Prüfungsfunktion, können verpflichtete Unternehmen diese Prüfung durch einen externen Sachverständigen durchführen lassen.

Die im ersten Unterabsatz genannten internen Strategien, Verfahren und Kontrollen werden schriftlich festgehalten. Interne Strategien werden vom Leitungsorgan in seiner Leitungsfunktion genehmigt. Interne Verfahren und Kontrollen werden mindestens auf der Ebene des Compliance-Managers genehmigt.

3 3 3

The obliged entities shall keep the internal policies, procedures and controls up-to-date, and enhance them where weaknesses are identified.

The obliged entities shall keep the internal policies, procedures and controls up-to-date, and enhance them where weaknesses are identified.

Die verpflichteten Unternehmen halten die internen Strategien, Verfahren und Kontrollen auf dem neuesten Stand und verbessern sie, wenn Schwachstellen festgestellt werden.

4 4 4

By 10 July 2026, AMLA shall issue guidelines on the elements that obliged entities should take into account, based on the nature of their business, including its risks and complexity, and their size, when deciding on the extent of their internal policies, procedures and controls, in particular as regards the staff allocated to the compliance functions. Those guidelines shall also identify situations where, due to the nature and size of the obliged entity:

  • (i) internal controls are to be organised at the level of the commercial function, of the compliance function and of the audit function;
  • (ii) the independent audit function can be carried out by an external expert.

By 10 July 2026, AMLA shall issue guidelines on the elements that obliged entities should take into account, based on the nature of their business, including its risks and complexity, and their size, when deciding on the extent of their internal policies, procedures and controls, in particular as regards the staff allocated to the compliance functions. Those guidelines shall also identify situations where, due to the nature and size of the obliged entity:

  • (i) internal controls are to be organised at the level of the commercial function, of the compliance function and of the audit function;
  • (ii) the independent audit function can be carried out by an external expert.

Bis zum 10. Juli 2026 erlässt die AMLA Leitlinien zu den Elementen, die verpflichtete Unternehmen unter Berücksichtigung der Art ihrer Geschäftstätigkeit, einschließlich ihrer Risiken und Komplexität, sowie ihrer Größe bei der Festlegung des Umfangs ihrer internen Strategien, Verfahren und Kontrollen berücksichtigen sollten, insbesondere hinsichtlich des den Compliance-Funktionen zugewiesenen Personals. In den Leitlinien werden außerdem Situationen bestimmt, in denen aufgrund der Art und Größe des verpflichteten Unternehmens:

  • i) interne Kontrollen auf der Ebene der Geschäfts-, Compliance- und Prüfungsfunktion zu organisieren sind;
  • ii) die unabhängige Prüfungsfunktion von einem externen Sachverständigen wahrgenommen werden kann.
Article 10 — Business-wide risk assessment Article 10 — Business-wide risk assessment Article 10 — Unternehmensweite Risikobewertung
1 1 1

Obliged entities shall take appropriate measures, proportionate to the nature of their business, including its risks and complexity, and their size, to identify and assess the risks of money laundering and terrorist financing to which they are exposed, as well as the risks of non-implementation and evasion of targeted financial sanctions, taking into account at least:

  • (a) the risk variables set out in Annex I and the risk factors set out in Annexes II and III;
  • (b) the findings of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640;
  • (c) the findings of the national risk assessments carried out by the Member States pursuant to Article 8 of Directive (EU) 2024/1640, as well as of any relevant sector-specific risk assessment carried out by the Member States;
  • (d) relevant information published by international standard setters in the AML/CFT area or, at the level of the Union, relevant publications by the Commission or by AMLA;
  • (e) information on money laundering and terrorist financing risks provided by competent authorities;
  • (f) information on the customer base.

Prior to the launch of new products, services or business practices, including the use of new delivery channels and new or developing technologies, in conjunction with new or pre-existing products and services or before starting to provide an existing service or product to a new customer segment or in a new geographical area, obliged entities shall identify and assess, in particular, the related money laundering and terrorist financing risks and take appropriate measures to manage and mitigate those risks.

Obliged entities shall take appropriate measures, proportionate to the nature of their business, including its risks and complexity, and their size, to identify and assess the risks of money laundering and terrorist financing to which they are exposed, as well as the risks of non-implementation and evasion of targeted financial sanctions, taking into account at least:

  • (a) the risk variables set out in Annex I and the risk factors set out in Annexes II and III;
  • (b) the findings of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640;
  • (c) the findings of the national risk assessments carried out by the Member States pursuant to Article 8 of Directive (EU) 2024/1640, as well as of any relevant sector-specific risk assessment carried out by the Member States;
  • (d) relevant information published by international standard setters in the AML/CFT area or, at the level of the Union, relevant publications by the Commission or by AMLA;
  • (e) information on money laundering and terrorist financing risks provided by competent authorities;
  • (f) information on the customer base.

Prior to the launch of new products, services or business practices, including the use of new delivery channels and new or developing technologies, in conjunction with new or pre-existing products and services or before starting to provide an existing service or product to a new customer segment or in a new geographical area, obliged entities shall identify and assess, in particular, the related money laundering and terrorist financing risks and take appropriate measures to manage and mitigate those risks.

Verpflichtete Unternehmen treffen geeignete Maßnahmen, die der Art ihrer Geschäftstätigkeit, einschließlich ihrer Risiken und Komplexität, sowie ihrer Größe angemessen sind, um die Risiken von Geldwäsche und Terrorismusfinanzierung, denen sie ausgesetzt sind, sowie die Risiken der Nichtumsetzung und Umgehung gezielter finanzieller Sanktionen zu ermitteln und zu bewerten; dabei berücksichtigen sie mindestens:

  • a) die in Anhang I aufgeführten Risikovariablen und die in den Anhängen II und III aufgeführten Risikofaktoren;
  • b) die Ergebnisse der von der Kommission gemäß Artikel 7 der Richtlinie (EU) 2024/1640 auf Unionsebene durchgeführten Risikobewertung;
  • c) die Ergebnisse der von den Mitgliedstaaten gemäß Artikel 8 der Richtlinie (EU) 2024/1640 durchgeführten nationalen Risikobewertungen sowie jeder einschlägigen sektorspezifischen Risikobewertung der Mitgliedstaaten;
  • d) einschlägige Informationen, die von internationalen Einrichtungen zur Festlegung von Standards im Bereich der Bekämpfung von Geldwäsche und Terrorismusfinanzierung veröffentlicht wurden, oder auf Unionsebene einschlägige Veröffentlichungen der Kommission oder der AMLA;
  • e) von den zuständigen Behörden bereitgestellte Informationen über Risiken von Geldwäsche und Terrorismusfinanzierung;
  • f) Informationen über den Kundenstamm.

Vor der Einführung neuer Produkte, Dienstleistungen oder Geschäftspraktiken, einschließlich der Nutzung neuer Bereitstellungskanäle und neuer oder sich entwickelnder Technologien, in Verbindung mit neuen oder bereits bestehenden Produkten und Dienstleistungen, oder bevor ein bestehender Dienst oder ein bestehendes Produkt einem neuen Kundensegment oder in einem neuen geografischen Gebiet angeboten wird, ermitteln und bewerten verpflichtete Unternehmen insbesondere die damit verbundenen Risiken von Geldwäsche und Terrorismusfinanzierung und treffen geeignete Maßnahmen zur Steuerung und Minderung dieser Risiken.

2 2 2

The business-wide risk assessment drawn up by the obliged entity pursuant to paragraph 1 shall be documented, kept up-to-date and regularly reviewed, including where any internal or external events significantly affect the money laundering and terrorist financing risks associated with the activities, products, transactions, delivery channels, customers or geographical zones of activities of the obliged entity. It shall be made available to supervisors upon request.The business-wide risk assessment shall be drawn up by the compliance officer and approved by the management body in its management function and, where such body exists, communicated to the management body in its supervisory function.

The business-wide risk assessment drawn up by the obliged entity pursuant to paragraph 1 shall be documented, kept up-to-date and regularly reviewed, including where any internal or external events significantly affect the money laundering and terrorist financing risks associated with the activities, products, transactions, delivery channels, customers or geographical zones of activities of the obliged entity. It shall be made available to supervisors upon request.The business-wide risk assessment shall be drawn up by the compliance officer and approved by the management body in its management function and, where such body exists, communicated to the management body in its supervisory function.

Die vom verpflichteten Unternehmen gemäß Absatz 1 erstellte unternehmensweite Risikobewertung wird dokumentiert, auf dem neuesten Stand gehalten und regelmäßig überprüft, auch wenn interne oder externe Ereignisse die mit den Tätigkeiten, Produkten, Transaktionen, Bereitstellungskanälen, Kunden oder geografischen Tätigkeitsgebieten des verpflichteten Unternehmens verbundenen Risiken von Geldwäsche und Terrorismusfinanzierung erheblich beeinflussen. Sie wird den Aufsichtsbehörden auf Verlangen zur Verfügung gestellt. Die unternehmensweite Risikobewertung wird vom Compliance-Beauftragten erstellt und vom Leitungsorgan in seiner Leitungsfunktion genehmigt sowie, sofern ein solches Organ besteht, dem Leitungsorgan in seiner Überwachungsfunktion mitgeteilt.

3 3 3

With the exception of credit institutions, financial institutions, crowdfunding service providers and crowdfunding intermediaries, supervisors may decide that individual documented business-wide risk assessments are not required where the specific risks inherent in the sector are clear and understood.

With the exception of credit institutions, financial institutions, crowdfunding service providers and crowdfunding intermediaries, supervisors may decide that individual documented business-wide risk assessments are not required where the specific risks inherent in the sector are clear and understood.

Mit Ausnahme von Kreditinstituten, Finanzinstituten, Anbietern von Crowdfunding-Dienstleistungen und Crowdfunding-Vermittlern können die Aufsichtsbehörden beschließen, dass keine individuellen dokumentierten unternehmensweiten Risikobewertungen erforderlich sind, wenn die dem Sektor innewohnenden spezifischen Risiken klar und bekannt sind.

4 4 4

By 10 July 2026, AMLA shall issue guidelines on the minimum requirements for the content of the business-wide risk assessment drawn up by the obliged entity pursuant to paragraph 1, and on the additional sources of information to be taken into account when carrying out the business-wide risk assessment.

By 10 July 2026, AMLA shall issue guidelines on the minimum requirements for the content of the business-wide risk assessment drawn up by the obliged entity pursuant to paragraph 1, and on the additional sources of information to be taken into account when carrying out the business-wide risk assessment.

Bis zum 10. Juli 2026 erlässt die AMLA Leitlinien zu den Mindestanforderungen an den Inhalt der vom verpflichteten Unternehmen gemäß Absatz 1 erstellten unternehmensweiten Risikobewertung sowie zu den zusätzlichen Informationsquellen, die bei der Durchführung der unternehmensweiten Risikobewertung zu berücksichtigen sind.

Article 11 — Compliance functions Article 11 — Compliance functions Article 11 — Compliance-Funktionen
1 1 1

Obliged entities shall appoint one member of the management body in its management function who shall be responsible for ensuring compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor (compliance manager).The compliance manager shall ensure that the obliged entity’s internal policies, procedures and controls are consistent with the obliged entity’s risk exposure and that they are implemented. The compliance manager shall also ensure that sufficient human and material resources are allocated to that end. The compliance manager shall be responsible for receiving information on significant or material weaknesses in such policies, procedures and controls.Where the management body in its management function is a body collectively responsible for its decisions, the compliance manager shall be responsible for assisting and advising it and for preparing the decisions referred to in this Article.

Obliged entities shall appoint one member of the management body in its management function who shall be responsible for ensuring compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor (compliance manager).The compliance manager shall ensure that the obliged entity’s internal policies, procedures and controls are consistent with the obliged entity’s risk exposure and that they are implemented. The compliance manager shall also ensure that sufficient human and material resources are allocated to that end. The compliance manager shall be responsible for receiving information on significant or material weaknesses in such policies, procedures and controls.Where the management body in its management function is a body collectively responsible for its decisions, the compliance manager shall be responsible for assisting and advising it and for preparing the decisions referred to in this Article.

Verpflichtete Unternehmen benennen ein Mitglied des Leitungsorgans in seiner Leitungsfunktion, das für die Sicherstellung der Einhaltung dieser Verordnung, der Verordnung (EU) 2023/1113 und jedes von einem Aufseher erlassenen Verwaltungsakts verantwortlich ist (Compliance-Manager). Der Compliance-Manager stellt sicher, dass die internen Strategien, Verfahren und Kontrollen des verpflichteten Unternehmens mit dessen Risikoexposition im Einklang stehen und umgesetzt werden. Er stellt außerdem sicher, dass hierfür ausreichende personelle und materielle Ressourcen bereitgestellt werden. Der Compliance-Manager ist für den Empfang von Informationen über erhebliche oder wesentliche Schwachstellen in diesen Strategien, Verfahren und Kontrollen verantwortlich. Ist das Leitungsorgan in seiner Leitungsfunktion ein Organ, das kollektiv für seine Entscheidungen verantwortlich ist, ist der Compliance-Manager dafür verantwortlich, dieses zu unterstützen und zu beraten sowie die in diesem Artikel genannten Beschlüsse vorzubereiten.

2 2 2

Obliged entities shall have a compliance officer, to be appointed by the management body in its management function and with sufficiently high hierarchical standing, who shall be responsible for the policies, procedures and controls in the day-to-day operation of the obliged entity’s AML/CFT requirements, including in relation to the implementation of targeted financial sanctions, and shall be a contact point for competent authorities. The compliance officer shall also be responsible for reporting suspicious transactions to the FIU in accordance with Article 69(6).In the case of obliged entities subject to checks on their senior management or beneficial owners pursuant to Article 6 of Directive (EU) 2024/1640 or under other Union legal acts, compliance officers shall be subject to verification that they comply with those requirements.Where justified by the size of the obliged entity and the low risk of its activities, an obliged entity that is part of a group may appoint as its compliance officer an individual who performs that function in another entity within that group.The compliance officer may only be removed following prior notification to the management body in its management function. The obliged entity shall notify the supervisor of the removal of the compliance officer, specifying whether the decision relates to the carrying out of the tasks assigned under this Regulation. The compliance officer may, on his or her own initiative or upon request, provide information to the supervisor concerning the removal. The supervisor may use that information to perform its tasks under the second subparagraph of this paragraph and under Article 37(4) of Directive (EU) 2024/1640.

Obliged entities shall have a compliance officer, to be appointed by the management body in its management function and with sufficiently high hierarchical standing, who shall be responsible for the policies, procedures and controls in the day-to-day operation of the obliged entity’s AML/CFT requirements, including in relation to the implementation of targeted financial sanctions, and shall be a contact point for competent authorities. The compliance officer shall also be responsible for reporting suspicious transactions to the FIU in accordance with Article 69(6).In the case of obliged entities subject to checks on their senior management or beneficial owners pursuant to Article 6 of Directive (EU) 2024/1640 or under other Union legal acts, compliance officers shall be subject to verification that they comply with those requirements.Where justified by the size of the obliged entity and the low risk of its activities, an obliged entity that is part of a group may appoint as its compliance officer an individual who performs that function in another entity within that group.The compliance officer may only be removed following prior notification to the management body in its management function. The obliged entity shall notify the supervisor of the removal of the compliance officer, specifying whether the decision relates to the carrying out of the tasks assigned under this Regulation. The compliance officer may, on his or her own initiative or upon request, provide information to the supervisor concerning the removal. The supervisor may use that information to perform its tasks under the second subparagraph of this paragraph and under Article 37(4) of Directive (EU) 2024/1640.

Verpflichtete Unternehmen verfügen über einen Compliance-Beauftragten, der vom Leitungsorgan in seiner Leitungsfunktion bestellt wird und eine ausreichend hohe hierarchische Stellung innehat. Dieser ist für die Strategien, Verfahren und Kontrollen beim täglichen Betrieb der Anforderungen des verpflichteten Unternehmens zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung, einschließlich der Umsetzung gezielter finanzieller Sanktionen, verantwortlich und dient den zuständigen Behörden als Kontaktstelle. Der Compliance-Beauftragte ist außerdem gemäß Artikel 69 Absatz 6 für die Meldung verdächtiger Transaktionen an die FIU verantwortlich. Bei verpflichteten Unternehmen, deren Geschäftsleitung oder wirtschaftliche Eigentümer gemäß Artikel 6 der Richtlinie (EU) 2024/1640 oder nach anderen Rechtsakten der Union überprüft werden, wird überprüft, ob die Compliance-Beauftragten diese Anforderungen erfüllen. Sofern dies durch die Größe des verpflichteten Unternehmens und das geringe Risiko seiner Tätigkeiten gerechtfertigt ist, kann ein zu einer Gruppe gehörendes verpflichtetes Unternehmen eine Person zum Compliance-Beauftragten bestellen, die diese Funktion in einem anderen Unternehmen der Gruppe ausübt. Der Compliance-Beauftragte darf nur nach vorheriger Mitteilung an das Leitungsorgan in seiner Leitungsfunktion abberufen werden. Das verpflichtete Unternehmen teilt dem Aufseher die Abberufung des Compliance-Beauftragten mit und gibt an, ob sich der Beschluss auf die Wahrnehmung der nach dieser Verordnung übertragenen Aufgaben bezieht. Der Compliance-Beauftragte kann dem Aufseher von sich aus oder auf Anfrage Informationen über die Abberufung erteilen. Der Aufseher kann diese Informationen zur Wahrnehmung seiner Aufgaben nach dem zweiten Unterabsatz dieses Absatzes und nach Artikel 37 Absatz 4 der Richtlinie (EU) 2024/1640 verwenden.

3 3 3

Obliged entities shall provide the compliance functions with adequate resources, including staff and technology, in proportion to the size, nature and risks of the obliged entity for effective performance of their tasks, and shall ensure that the persons responsible for those functions are granted the powers to propose any measures necessary to ensure the effectiveness of the obliged entity’s internal policies, procedures and controls.

Obliged entities shall provide the compliance functions with adequate resources, including staff and technology, in proportion to the size, nature and risks of the obliged entity for effective performance of their tasks, and shall ensure that the persons responsible for those functions are granted the powers to propose any measures necessary to ensure the effectiveness of the obliged entity’s internal policies, procedures and controls.

Verpflichtete Unternehmen stellen den Compliance-Funktionen angemessene Ressourcen, einschließlich Personal und Technologie, im Verhältnis zur Größe, Art und den Risiken des verpflichteten Unternehmens zur wirksamen Wahrnehmung ihrer Aufgaben zur Verfügung und stellen sicher, dass die für diese Funktionen verantwortlichen Personen befugt sind, alle Maßnahmen vorzuschlagen, die erforderlich sind, um die Wirksamkeit der internen Strategien, Verfahren und Kontrollen des verpflichteten Unternehmens sicherzustellen.

4 4 4

Obliged entities shall take measures to ensure that the compliance officer is protected against retaliation, discrimination and any other unfair treatment, and that decisions of the compliance officer are not undermined or unduly influenced by commercial interests of the obliged entity.

Obliged entities shall take measures to ensure that the compliance officer is protected against retaliation, discrimination and any other unfair treatment, and that decisions of the compliance officer are not undermined or unduly influenced by commercial interests of the obliged entity.

Verpflichtete Unternehmen treffen Maßnahmen, um sicherzustellen, dass der Compliance-Beauftragte vor Vergeltungsmaßnahmen, Diskriminierung und jeder anderen unfairen Behandlung geschützt ist und dass seine Beschlüsse nicht durch Geschäftsinteressen des verpflichteten Unternehmens untergraben oder unangemessen beeinflusst werden.

5 5 5

Obliged entities shall ensure that the compliance officer and the person responsible for the audit function referred to in Article 9(2), point (b), can report directly to the management body in its management function and, where such a body exists, to the management body in its supervisory function independently, and can raise concerns and warn the management body, where specific risk developments affect or may affect the obliged entity.Obliged entities shall ensure that the persons directly or indirectly participating in implementation of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, have access to all information and data necessary to perform their tasks.

Obliged entities shall ensure that the compliance officer and the person responsible for the audit function referred to in Article 9(2), point (b), can report directly to the management body in its management function and, where such a body exists, to the management body in its supervisory function independently, and can raise concerns and warn the management body, where specific risk developments affect or may affect the obliged entity.Obliged entities shall ensure that the persons directly or indirectly participating in implementation of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, have access to all information and data necessary to perform their tasks.

Verpflichtete Unternehmen stellen sicher, dass der Compliance-Beauftragte und die für die Prüfungsfunktion gemäß Artikel 9 Absatz 2 Buchstabe b verantwortliche Person dem Leitungsorgan in seiner Leitungsfunktion und, sofern ein solches Organ besteht, dem Leitungsorgan in seiner Überwachungsfunktion unabhängig unmittelbar Bericht erstatten sowie Bedenken äußern und das Leitungsorgan warnen können, wenn bestimmte Risikoentwicklungen das verpflichtete Unternehmen beeinträchtigen oder beeinträchtigen können. Verpflichtete Unternehmen stellen sicher, dass Personen, die unmittelbar oder mittelbar an der Umsetzung dieser Verordnung, der Verordnung (EU) 2023/1113 und jedes von einem Aufseher erlassenen Verwaltungsakts beteiligt sind, Zugang zu allen für die Wahrnehmung ihrer Aufgaben erforderlichen Informationen und Daten haben.

6 6 6

The compliance manager shall regularly report on the implementation of the obliged entity’s internal policies, procedures and controls to the management body. In particular, the compliance manager shall submit once a year, or, where appropriate, more frequently, to the management body a report on the implementation of the obliged entity’s internal policies, procedures and controls drawn up by the compliance officer, and shall keep that body informed of the outcome of any reviews. The compliance manager shall take the necessary actions to remedy in a timely manner any deficiencies identified.

The compliance manager shall regularly report on the implementation of the obliged entity’s internal policies, procedures and controls to the management body. In particular, the compliance manager shall submit once a year, or, where appropriate, more frequently, to the management body a report on the implementation of the obliged entity’s internal policies, procedures and controls drawn up by the compliance officer, and shall keep that body informed of the outcome of any reviews. The compliance manager shall take the necessary actions to remedy in a timely manner any deficiencies identified.

Der Compliance-Manager erstattet dem Leitungsorgan regelmäßig Bericht über die Umsetzung der internen Strategien, Verfahren und Kontrollen des verpflichteten Unternehmens. Insbesondere legt der Compliance-Manager dem Leitungsorgan einmal jährlich oder gegebenenfalls häufiger einen vom Compliance-Beauftragten erstellten Bericht über die Umsetzung dieser internen Strategien, Verfahren und Kontrollen vor und hält dieses Organ über die Ergebnisse jeder Überprüfung auf dem Laufenden. Der Compliance-Manager ergreift die erforderlichen Maßnahmen, um festgestellte Mängel rechtzeitig zu beheben.

7 7 7

Where the nature of the business of the obliged entity, including its risks and complexity, and its size justify it, the functions of the compliance manager and the compliance officer may be performed by the same natural person. Those functions may be cumulated with other functions.Where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only, that person shall be responsible for performing the tasks under this Article.

Where the nature of the business of the obliged entity, including its risks and complexity, and its size justify it, the functions of the compliance manager and the compliance officer may be performed by the same natural person. Those functions may be cumulated with other functions.Where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only, that person shall be responsible for performing the tasks under this Article.

Sofern die Art der Geschäftstätigkeit des verpflichteten Unternehmens, einschließlich ihrer Risiken und Komplexität, und seine Größe dies rechtfertigen, können die Funktionen des Compliance-Managers und des Compliance-Beauftragten von derselben natürlichen Person wahrgenommen werden. Diese Funktionen können mit anderen Funktionen verbunden werden. Ist das verpflichtete Unternehmen eine natürliche Person oder eine juristische Person, deren Tätigkeiten ausschließlich von einer natürlichen Person ausgeübt werden, ist diese Person für die Wahrnehmung der Aufgaben nach diesem Artikel verantwortlich.

Article 12 — Awareness of requirements Article 12 — Awareness of requirements Article 12 — Kenntnis der Anforderungen

Obliged entities shall take measures to ensure that their employees or persons in comparable positions whose function so requires, including their agents and distributors are aware of the requirements arising from this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, and of the business-wide risk assessment, internal policies, procedures and controls in place in the obliged entity, including in relation to the processing of personal data for the purposes of this Regulation.The measures referred to in the first paragraph shall include the participation of employees or persons in comparable positions, including agents and distributors, in specific, ongoing training programmes to help them recognise operations which may be related to money laundering or terrorist financing and to instruct them as to how to proceed in such cases. Such training programmes shall be appropriate to their functions or activities and to the risks of money laundering and terrorist financing to which the obliged entity is exposed, and shall be duly documented.

Obliged entities shall take measures to ensure that their employees or persons in comparable positions whose function so requires, including their agents and distributors are aware of the requirements arising from this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, and of the business-wide risk assessment, internal policies, procedures and controls in place in the obliged entity, including in relation to the processing of personal data for the purposes of this Regulation.The measures referred to in the first paragraph shall include the participation of employees or persons in comparable positions, including agents and distributors, in specific, ongoing training programmes to help them recognise operations which may be related to money laundering or terrorist financing and to instruct them as to how to proceed in such cases. Such training programmes shall be appropriate to their functions or activities and to the risks of money laundering and terrorist financing to which the obliged entity is exposed, and shall be duly documented.

Verpflichtete Unternehmen treffen Maßnahmen, um sicherzustellen, dass ihre Beschäftigten oder Personen in vergleichbaren Positionen, deren Funktion dies erfordert, einschließlich ihrer Agenten und Vertriebsstellen, die sich aus dieser Verordnung, der Verordnung (EU) 2023/1113 und jedem von einem Aufseher erlassenen Verwaltungsakt ergebenden Anforderungen sowie die im verpflichteten Unternehmen bestehende unternehmensweite Risikobewertung und die internen Strategien, Verfahren und Kontrollen kennen, einschließlich im Hinblick auf die Verarbeitung personenbezogener Daten für die Zwecke dieser Verordnung. Die im ersten Absatz genannten Maßnahmen umfassen die Teilnahme von Beschäftigten oder Personen in vergleichbaren Positionen, einschließlich Agenten und Vertriebsstellen, an spezifischen fortlaufenden Schulungsprogrammen, die ihnen helfen, Vorgänge zu erkennen, die mit Geldwäsche oder Terrorismusfinanzierung zusammenhängen können, und sie anweisen, wie in solchen Fällen vorzugehen ist. Diese Schulungsprogramme müssen ihren Funktionen oder Tätigkeiten und den Risiken von Geldwäsche und Terrorismusfinanzierung, denen das verpflichtete Unternehmen ausgesetzt ist, angemessen sein und ordnungsgemäß dokumentiert werden.

Article 13 — Integrity of employees Article 13 — Integrity of employees Article 13 — Integrität der Beschäftigten
1 1 1

Any employee, or person in a comparable position, including agents and distributors, directly participating in the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, shall undergo an assessment commensurate with the risks associated with the tasks performed and whose content is approved by the compliance officer of:

  • (a) individual skills, knowledge and expertise to carry out their functions effectively;
  • (b) good repute, honesty and integrity.

The assessment referred to in the first subparagraph shall be performed prior to taking up of activities by the employee or person in a comparable position, including agents and distributors, and shall be regularly repeated. The intensity of the subsequent assessments shall be determined on the basis of the tasks entrusted to the person and risks associated with the function they perform.

Any employee, or person in a comparable position, including agents and distributors, directly participating in the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, shall undergo an assessment commensurate with the risks associated with the tasks performed and whose content is approved by the compliance officer of:

  • (a) individual skills, knowledge and expertise to carry out their functions effectively;
  • (b) good repute, honesty and integrity.

The assessment referred to in the first subparagraph shall be performed prior to taking up of activities by the employee or person in a comparable position, including agents and distributors, and shall be regularly repeated. The intensity of the subsequent assessments shall be determined on the basis of the tasks entrusted to the person and risks associated with the function they perform.

Jeder Mitarbeiter oder jede Person in einer vergleichbaren Position, einschließlich Vertreter und Vertriebshändler, die unmittelbar an der Einhaltung dieser Verordnung, der Verordnung (EU) 2023/1113 und jedes von einer Aufsichtsbehörde erlassenen Verwaltungsakts durch das verpflichtete Unternehmen beteiligt ist, muss einer den mit den ausgeübten Aufgaben verbundenen Risiken entsprechenden und deren Inhalt vom Compliance-Beauftragten genehmigten Bewertung unterzogen werden hinsichtlich:

  • a) der individuellen Fähigkeiten, Kenntnisse und Fachkenntnisse zur wirksamen Wahrnehmung ihrer Aufgaben;
  • b) des guten Leumunds, der Ehrlichkeit und der Integrität.

Die im ersten Unterabsatz genannte Bewertung wird vor Aufnahme der Tätigkeit durch den Mitarbeiter oder die Person in einer vergleichbaren Position, einschließlich Vertreter und Vertriebshändler, durchgeführt und regelmäßig wiederholt. Die Intensität der späteren Bewertungen wird anhand der der Person übertragenen Aufgaben und der mit ihrer Funktion verbundenen Risiken bestimmt.

2 2 2

Employees, or persons in comparable positions, including agents and distributors, entrusted with tasks related to the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, shall inform the compliance officer of any close private or professional relationship established with the obliged entity’s customers or prospective customers and shall be prevented from undertaking any tasks related to the obliged entity’s compliance in relation to those customers.

Employees, or persons in comparable positions, including agents and distributors, entrusted with tasks related to the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, shall inform the compliance officer of any close private or professional relationship established with the obliged entity’s customers or prospective customers and shall be prevented from undertaking any tasks related to the obliged entity’s compliance in relation to those customers.

Mitarbeiter oder Personen in vergleichbaren Positionen, einschließlich Vertreter und Vertriebshändler, denen Aufgaben im Zusammenhang mit der Einhaltung dieser Verordnung, der Verordnung (EU) 2023/1113 und jedes von einer Aufsichtsbehörde erlassenen Verwaltungsakts durch das verpflichtete Unternehmen übertragen wurden, unterrichten den Compliance-Beauftragten über jede enge private oder berufliche Beziehung zu Kunden oder potenziellen Kunden des verpflichteten Unternehmens und dürfen keine Aufgaben im Zusammenhang mit der Einhaltung der Vorschriften durch das verpflichtete Unternehmen in Bezug auf diese Kunden wahrnehmen.

3 3 3

Obliged entities shall have in place procedures to prevent and manage conflicts of interest that may affect the carrying out of tasks related to the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor.

Obliged entities shall have in place procedures to prevent and manage conflicts of interest that may affect the carrying out of tasks related to the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor.

Verpflichtete Unternehmen müssen über Verfahren zur Vermeidung und Bewältigung von Interessenkonflikten verfügen, die die Wahrnehmung von Aufgaben im Zusammenhang mit der Einhaltung dieser Verordnung, der Verordnung (EU) 2023/1113 und jedes von einer Aufsichtsbehörde erlassenen Verwaltungsakts durch das verpflichtete Unternehmen beeinträchtigen können.

4 4 4

This Article shall not apply where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only.

This Article shall not apply where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only.

Dieser Artikel gilt nicht, wenn es sich bei dem verpflichteten Unternehmen um eine natürliche Person oder eine juristische Person handelt, deren Tätigkeiten ausschließlich von einer natürlichen Person ausgeübt werden.

Article 14 — Reporting of breaches and protection of reporting persons Article 14 — Reporting of breaches and protection of reporting persons Article 14 — Meldung von Verstößen und Schutz von Hinweisgebern
1 1 1

Directive (EU) 2019/1937 of the European Parliament and of the Council

Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law (OJ L 305, 26.11.2019, p. 17).

shall apply to the reporting of breaches of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, and to the protection of persons reporting such breaches.

Directive (EU) 2019/1937 of the European Parliament and of the Council

Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law (OJ L 305, 26.11.2019, p. 17).

shall apply to the reporting of breaches of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, and to the protection of persons reporting such breaches.

Die Richtlinie (EU) 2019/1937 des Europäischen Parlaments und des Rates

Die Richtlinie (EU) 2019/1937 des Europäischen Parlaments und des Rates vom 23. Oktober 2019 zum Schutz von Personen, die Verstöße gegen das Unionsrecht melden (ABl. L 305 vom 26.11.2019, S. 17),

gilt für die Meldung von Verstößen gegen diese Verordnung, die Verordnung (EU) 2023/1113 und jeden von einer Aufsichtsbehörde erlassenen Verwaltungsakt sowie für den Schutz von Personen, die solche Verstöße melden.

2 2 2

Obliged entities shall establish internal reporting channels that meet the requirements set out in Directive (EU) 2019/1937.

Obliged entities shall establish internal reporting channels that meet the requirements set out in Directive (EU) 2019/1937.

Verpflichtete Unternehmen richten interne Meldekanäle ein, die den Anforderungen der Richtlinie (EU) 2019/1937 entsprechen.

3 3 3

Paragraph 2 shall not apply where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only.

Paragraph 2 shall not apply where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only.

Absatz 2 gilt nicht, wenn es sich bei dem verpflichteten Unternehmen um eine natürliche Person oder eine juristische Person handelt, deren Tätigkeiten ausschließlich von einer natürlichen Person ausgeübt werden.

Article 15 — Situation of specific employees Article 15 — Situation of specific employees Article 15 — Situation bestimmter Mitarbeiter

Where a natural person falling within any of the categories listed in Article 3, point (3) performs professional activities as an employee of a legal person, the requirements laid down in this Regulation shall apply to that legal person rather than to the natural person.

Where a natural person falling within any of the categories listed in Article 3, point (3) performs professional activities as an employee of a legal person, the requirements laid down in this Regulation shall apply to that legal person rather than to the natural person.

Übt eine natürliche Person, die unter eine der in Artikel 3 Nummer 3 aufgeführten Kategorien fällt, eine berufliche Tätigkeit als Mitarbeiter einer juristischen Person aus, so gelten die Anforderungen dieser Verordnung für die juristische Person und nicht für die natürliche Person.

SECTION 2 — Provisions applying to groups SECTION 2 — Provisions applying to groups SECTION 2 — Für Gruppen geltende Bestimmungen
Article 16 — Group-wide requirements Article 16 — Group-wide requirements Article 16 — Gruppenweite Anforderungen
1 1 1

A parent undertaking shall ensure that the requirements on internal procedures, risk assessment and staff referred to in Section 1 of this Chapter apply in all branches and subsidiaries of the group in the Member States and, for groups whose head office is located in the Union, in third countries. To this end, a parent undertaking shall perform a group-wide risk assessment, taking into account the business-wide risk assessment performed by all branches and subsidiaries of the group, and establish and implement group-wide policies, procedures and controls, including on data protection and on information sharing within the group for AML/CFT purposes and to ensure that employees within the group are aware of the requirements arising from this Regulation. Obliged entities within the group shall implement those group-wide policies, procedures and controls, taking into account their specificities and the risks to which they are exposed.The group-wide policies, procedures and controls and the group-wide risk assessments referred to in the first subparagraph shall include all the elements listed in Articles 9 and 10, respectively.For the purposes of the first subparagraph, where a group has establishments in more than one Member State and, for groups whose head office is located in the Union, in third countries, parent undertakings shall take into account the information published by the authorities of all the Member States or third countries where the group’s establishments are located.

A parent undertaking shall ensure that the requirements on internal procedures, risk assessment and staff referred to in Section 1 of this Chapter apply in all branches and subsidiaries of the group in the Member States and, for groups whose head office is located in the Union, in third countries. To this end, a parent undertaking shall perform a group-wide risk assessment, taking into account the business-wide risk assessment performed by all branches and subsidiaries of the group, and establish and implement group-wide policies, procedures and controls, including on data protection and on information sharing within the group for AML/CFT purposes and to ensure that employees within the group are aware of the requirements arising from this Regulation. Obliged entities within the group shall implement those group-wide policies, procedures and controls, taking into account their specificities and the risks to which they are exposed. The group-wide policies, procedures and controls and the group-wide risk assessments referred to in the first subparagraph shall include all the elements listed in Articles 9 and 10, respectively. For the purposes of the first subparagraph, where a group has establishments in more than one Member State and, for groups whose head office is located in the Union, in third countries, parent undertakings shall take into account the information published by the authorities of all the Member States or third countries where the group’s establishments are located.

Ein Mutterunternehmen stellt sicher, dass die in Abschnitt 1 dieses Kapitels genannten Anforderungen an interne Verfahren, Risikobewertung und Personal in allen Zweigstellen und Tochterunternehmen der Gruppe in den Mitgliedstaaten und bei Gruppen mit Sitz in der Union in Drittländern Anwendung finden. Zu diesem Zweck führt ein Mutterunternehmen eine gruppenweite Risikobewertung durch, bei der die von allen Zweigstellen und Tochterunternehmen der Gruppe durchgeführte unternehmensweite Risikobewertung berücksichtigt wird, und führt gruppenweite Strategien, Verfahren und Kontrollen ein und setzt diese um, einschließlich in Bezug auf den Datenschutz und den Informationsaustausch innerhalb der Gruppe für Zwecke der Bekämpfung von Geldwäsche und Terrorismusfinanzierung sowie um sicherzustellen, dass die Mitarbeiter innerhalb der Gruppe die sich aus dieser Verordnung ergebenden Anforderungen kennen. Verpflichtete Unternehmen innerhalb der Gruppe setzen diese gruppenweiten Strategien, Verfahren und Kontrollen unter Berücksichtigung ihrer Besonderheiten und der Risiken, denen sie ausgesetzt sind, um. Die im ersten Unterabsatz genannten gruppenweiten Strategien, Verfahren und Kontrollen sowie gruppenweiten Risikobewertungen umfassen jeweils alle in den Artikeln 9 beziehungsweise 10 aufgeführten Elemente. Hat eine Gruppe für die Zwecke des ersten Unterabsatzes Niederlassungen in mehr als einem Mitgliedstaat und bei Gruppen mit Sitz in der Union in Drittländern, berücksichtigen die Mutterunternehmen die von den Behörden aller Mitgliedstaaten oder Drittländer veröffentlichten Informationen, in denen sich die Niederlassungen der Gruppe befinden.

2 2 2

Compliance functions shall be established at the level of the group. Those functions shall include a compliance manager at the level of the group and, where justified by the activities carried out at group level, a compliance officer. The decision on the extent of the compliance functions shall be documented.The compliance manager referred to in the first subparagraph shall regularly report to the management body in its management function of the parent undertaking on the implementation of the group-wide policies, procedures and controls. At a minimum, the compliance manager shall submit once a year a report on the implementation of the obliged entity’s internal policies, procedures and controls and shall take the necessary actions to remedy in a timely manner any deficiencies identified. Where the management body in its management function is a body collectively responsible for its decisions, the compliance manager shall assist and advise it, and shall prepare the decisions necessary for the implementation of this Article.

Compliance functions shall be established at the level of the group. Those functions shall include a compliance manager at the level of the group and, where justified by the activities carried out at group level, a compliance officer. The decision on the extent of the compliance functions shall be documented. The compliance manager referred to in the first subparagraph shall regularly report to the management body in its management function of the parent undertaking on the implementation of the group-wide policies, procedures and controls. At a minimum, the compliance manager shall submit once a year a report on the implementation of the obliged entity’s internal policies, procedures and controls and shall take the necessary actions to remedy in a timely manner any deficiencies identified. Where the management body in its management function is a body collectively responsible for its decisions, the compliance manager shall assist and advise it, and shall prepare the decisions necessary for the implementation of this Article.

Auf Gruppenebene werden Compliance-Funktionen eingerichtet. Diese Funktionen umfassen einen Compliance-Manager auf Gruppenebene und, sofern dies durch die auf Gruppenebene ausgeübten Tätigkeiten gerechtfertigt ist, einen Compliance-Beauftragten. Die Entscheidung über den Umfang der Compliance-Funktionen wird dokumentiert. Der im ersten Unterabsatz genannte Compliance-Manager erstattet dem Leitungsorgan in seiner Leitungsfunktion des Mutterunternehmens regelmäßig Bericht über die Umsetzung der gruppenweiten Strategien, Verfahren und Kontrollen. Der Compliance-Manager legt mindestens einmal jährlich einen Bericht über die Umsetzung der internen Strategien, Verfahren und Kontrollen des verpflichteten Unternehmens vor und ergreift die erforderlichen Maßnahmen, um festgestellte Mängel rechtzeitig zu beheben. Ist das Leitungsorgan in seiner Leitungsfunktion ein für seine Entscheidungen kollektiv verantwortliches Organ, unterstützt und berät der Compliance-Manager dieses und bereitet die für die Umsetzung dieses Artikels erforderlichen Entscheidungen vor.

3 3 3

The policies, procedures and controls pertaining to the sharing of information referred to in paragraph 1 shall require obliged entities within the group to exchange information when such sharing is relevant for the purposes of customer due diligence and money laundering and terrorist financing risk management. The sharing of information within the group shall cover in particular the identity and characteristics of the customer, its beneficial owners or the person on behalf of whom the customer acts, the nature and purpose of the business relationship and of the occasional transactions and the suspicions, accompanied by the underlying analyses, that funds are the proceeds of criminal activity or are related to terrorist financing reported to FIU pursuant to Article 69, unless otherwise instructed by the FIU.The group-wide policies, procedures and controls shall not prevent entities within a group which are not obliged entities to provide information to obliged entities within the same group where such sharing is relevant for those obliged entities to comply with requirements set out in this Regulation.Parent undertakings shall put in place group-wide policies, procedures and controls to ensure that the information exchanged pursuant to the first and second subparagraphs is subject to sufficient guarantees in terms of confidentiality, data protection and use of the information, including to prevent its disclosure.

The policies, procedures and controls pertaining to the sharing of information referred to in paragraph 1 shall require obliged entities within the group to exchange information when such sharing is relevant for the purposes of customer due diligence and money laundering and terrorist financing risk management. The sharing of information within the group shall cover in particular the identity and characteristics of the customer, its beneficial owners or the person on behalf of whom the customer acts, the nature and purpose of the business relationship and of the occasional transactions and the suspicions, accompanied by the underlying analyses, that funds are the proceeds of criminal activity or are related to terrorist financing reported to FIU pursuant to Article 69, unless otherwise instructed by the FIU. The group-wide policies, procedures and controls shall not prevent entities within a group which are not obliged entities to provide information to obliged entities within the same group where such sharing is relevant for those obliged entities to comply with requirements set out in this Regulation. Parent undertakings shall put in place group-wide policies, procedures and controls to ensure that the information exchanged pursuant to the first and second subparagraphs is subject to sufficient guarantees in terms of confidentiality, data protection and use of the information, including to prevent its disclosure.

Die in Absatz 1 genannten Strategien, Verfahren und Kontrollen für den Informationsaustausch müssen von den verpflichteten Unternehmen innerhalb der Gruppe verlangen, Informationen auszutauschen, wenn dieser Austausch für Zwecke der Sorgfaltspflichten gegenüber Kunden sowie des Risikomanagements in Bezug auf Geldwäsche und Terrorismusfinanzierung relevant ist. Der Informationsaustausch innerhalb der Gruppe umfasst insbesondere die Identität und Merkmale des Kunden, seiner wirtschaftlichen Eigentümer oder der Person, in deren Namen der Kunde handelt, die Art und den Zweck der Geschäftsbeziehung und der gelegentlichen Transaktionen sowie die nach Artikel 69 an die zentrale Meldestelle gemeldeten Verdachtsmomente, zusammen mit den zugrunde liegenden Analysen, dass Gelder aus kriminellen Tätigkeiten stammen oder mit Terrorismusfinanzierung zusammenhängen, sofern die zentrale Meldestelle nichts anderes anweist. Die gruppenweiten Strategien, Verfahren und Kontrollen dürfen Unternehmen innerhalb einer Gruppe, die keine verpflichteten Unternehmen sind, nicht daran hindern, verpflichteten Unternehmen innerhalb derselben Gruppe Informationen bereitzustellen, wenn dieser Austausch für die verpflichteten Unternehmen zur Einhaltung der Anforderungen dieser Verordnung relevant ist. Mutterunternehmen führen gruppenweite Strategien, Verfahren und Kontrollen ein, um sicherzustellen, dass die gemäß dem ersten und zweiten Unterabsatz ausgetauschten Informationen ausreichenden Garantien hinsichtlich Vertraulichkeit, Datenschutz und Verwendung der Informationen unterliegen, einschließlich zur Verhinderung ihrer Offenlegung.

4 4 4

By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify the minimum requirements of group-wide policies, procedures and controls, including minimum standards for information sharing within the group, the criteria for identifying the parent undertaking in the cases covered by Article 2(1), point (42)(b), and the conditions under which the provisions of this Article apply to entities that are part of structures which share common ownership, management or compliance control, including networks or partnerships, as well as the criteria for identifying the parent undertaking in the Union in those cases.

By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify the minimum requirements of group-wide policies, procedures and controls, including minimum standards for information sharing within the group, the criteria for identifying the parent undertaking in the cases covered by Article 2(1), point (42)(b), and the conditions under which the provisions of this Article apply to entities that are part of structures which share common ownership, management or compliance control, including networks or partnerships, as well as the criteria for identifying the parent undertaking in the Union in those cases.

Bis zum 10. Juli 2026 entwickelt die AMLA Entwürfe technischer Regulierungsstandards und legt sie der Kommission zur Annahme vor. In diesen Entwürfen technischer Regulierungsstandards werden die Mindestanforderungen an gruppenweite Strategien, Verfahren und Kontrollen festgelegt, einschließlich Mindeststandards für den Informationsaustausch innerhalb der Gruppe, der Kriterien zur Bestimmung des Mutterunternehmens in den unter Artikel 2 Absatz 1 Buchstabe b genannten Fällen und der Bedingungen, unter denen die Bestimmungen dieses Artikels auf Unternehmen Anwendung finden, die Teil von Strukturen mit gemeinsamer Eigentümerschaft, Leitung oder Compliance-Kontrolle sind, einschließlich Netzwerken oder Partnerschaften, sowie der Kriterien zur Bestimmung des Mutterunternehmens in der Union in diesen Fällen.

5 5 5

Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 4 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 4 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Der Kommission wird die Befugnis übertragen, diese Verordnung durch den Erlass der in Absatz 4 dieses Artikels genannten technischen Regulierungsstandards gemäß den Artikeln 49 bis 52 der Verordnung (EU) 2024/1620 zu ergänzen.

Article 17 — Branches and subsidiaries in third countries Article 17 — Branches and subsidiaries in third countries Article 17 — Zweigstellen und Tochterunternehmen in Drittländern
1 1 1

Where branches or subsidiaries of obliged entities are located in third countries where the minimum AML/CFT requirements are less strict than those set out in this Regulation, the parent undertaking shall ensure that those branches or subsidiaries comply with the requirements laid down in this Regulation, including requirements concerning data protection, or equivalent.

Where branches or subsidiaries of obliged entities are located in third countries where the minimum AML/CFT requirements are less strict than those set out in this Regulation, the parent undertaking shall ensure that those branches or subsidiaries comply with the requirements laid down in this Regulation, including requirements concerning data protection, or equivalent.

Befinden sich Zweigstellen oder Tochterunternehmen verpflichteter Unternehmen in Drittländern, in denen die Mindestanforderungen zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung weniger streng sind als die in dieser Verordnung festgelegten, so stellt das Mutterunternehmen sicher, dass diese Zweigstellen oder Tochterunternehmen die in dieser Verordnung festgelegten Anforderungen, einschließlich der Anforderungen an den Datenschutz, oder gleichwertige Anforderungen einhalten.

2 2 2

Where the law of a third country does not permit compliance with this Regulation, the parent undertaking shall take additional measures to ensure that branches and subsidiaries in that third country effectively handle the risk of money laundering or terrorist financing, and shall inform the supervisors of its home Member State of those additional measures. Where the supervisors of the home Member State consider that the additional measures are not sufficient, they shall exercise additional supervisory actions, including requiring the group not to enter into any business relationship, to terminate existing ones or not to undertake transactions, or to close down its operations in the third country.

Where the law of a third country does not permit compliance with this Regulation, the parent undertaking shall take additional measures to ensure that branches and subsidiaries in that third country effectively handle the risk of money laundering or terrorist financing, and shall inform the supervisors of its home Member State of those additional measures. Where the supervisors of the home Member State consider that the additional measures are not sufficient, they shall exercise additional supervisory actions, including requiring the group not to enter into any business relationship, to terminate existing ones or not to undertake transactions, or to close down its operations in the third country.

Gestattet das Recht eines Drittlands die Einhaltung dieser Verordnung nicht, so ergreift das Mutterunternehmen zusätzliche Maßnahmen, um sicherzustellen, dass die Zweigstellen und Tochterunternehmen in diesem Drittland das Risiko von Geldwäsche oder Terrorismusfinanzierung wirksam bewältigen, und unterrichtet die Aufsichtsbehörden seines Herkunftsmitgliedstaats über diese zusätzlichen Maßnahmen. Halten die Aufsichtsbehörden des Herkunftsmitgliedstaats die zusätzlichen Maßnahmen für nicht ausreichend, ergreifen sie zusätzliche Aufsichtsmaßnahmen, einschließlich der Anordnung an die Gruppe, keine Geschäftsbeziehungen einzugehen, bestehende Geschäftsbeziehungen zu beenden, keine Transaktionen durchzuführen oder ihre Tätigkeiten in dem Drittland einzustellen.

3 3 3

By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify the type of additional measures referred to in paragraph 2 of this Article, including the minimum action to be taken by obliged entities where the law of a third country does not permit the implementation of the measures required under Article 16 and the additional supervisory actions required in such cases.

By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify the type of additional measures referred to in paragraph 2 of this Article, including the minimum action to be taken by obliged entities where the law of a third country does not permit the implementation of the measures required under Article 16 and the additional supervisory actions required in such cases.

Bis zum 10. Juli 2026 entwickelt die AMLA Entwürfe technischer Regulierungsstandards und legt sie der Kommission zur Annahme vor. In diesen Entwürfen technischer Regulierungsstandards wird die Art der in Absatz 2 dieses Artikels genannten zusätzlichen Maßnahmen festgelegt, einschließlich der Mindestmaßnahmen, die von verpflichteten Unternehmen zu ergreifen sind, wenn das Recht eines Drittlands die Umsetzung der nach Artikel 16 erforderlichen Maßnahmen nicht gestattet, sowie der in solchen Fällen erforderlichen zusätzlichen Aufsichtsmaßnahmen.

4 4 4

Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 3 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 3 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Der Kommission wird die Befugnis übertragen, diese Verordnung durch den Erlass der in Absatz 3 dieses Artikels genannten technischen Regulierungsstandards gemäß den Artikeln 49 bis 52 der Verordnung (EU) 2024/1620 zu ergänzen.

SECTION 3 — Outsourcing SECTION 3 — Outsourcing SECTION 3 — Auslagerung
Article 18 — Outsourcing Article 18 — Outsourcing Article 18 — Auslagerung
1 1 1

Obliged entities may outsource tasks resulting from this Regulation to service providers. The obliged entity shall notify the supervisor of the outsourcing before the service provider starts to carry out the outsourced task.

Obliged entities may outsource tasks resulting from this Regulation to service providers. The obliged entity shall notify the supervisor of the outsourcing before the service provider starts to carry out the outsourced task.

Verpflichtete Unternehmen können sich aus dieser Verordnung ergebende Aufgaben an Dienstleister auslagern. Das verpflichtete Unternehmen unterrichtet die Aufsichtsbehörde über die Auslagerung, bevor der Dienstleister mit der Durchführung der ausgelagerten Aufgabe beginnt.

2 2 2

When performing tasks under this Article, service providers shall be regarded as part of the obliged entity, including where they are required to consult the central registers referred to in Article 10 of Directive (EU) 2024/1640 (central registers) for the purposes of carrying out customer due diligence on behalf of the obliged entity.The obliged entity shall remain fully liable for any action, whether an act of commission or omission, connected to the outsourced tasks that are carried out by service providers.For each outsourced task, the obliged entity shall be able to demonstrate to the supervisor that it understands the rationale behind the activities carried out by the service provider and the approach followed in their implementation, and that such activities mitigate the specific risks to which the obliged entity is exposed.

When performing tasks under this Article, service providers shall be regarded as part of the obliged entity, including where they are required to consult the central registers referred to in Article 10 of Directive (EU) 2024/1640 (central registers) for the purposes of carrying out customer due diligence on behalf of the obliged entity. The obliged entity shall remain fully liable for any action, whether an act of commission or omission, connected to the outsourced tasks that are carried out by service providers. For each outsourced task, the obliged entity shall be able to demonstrate to the supervisor that it understands the rationale behind the activities carried out by the service provider and the approach followed in their implementation, and that such activities mitigate the specific risks to which the obliged entity is exposed.

Bei der Wahrnehmung von Aufgaben nach diesem Artikel gelten Dienstleister als Teil des verpflichteten Unternehmens, auch wenn sie zum Zweck der Durchführung von Sorgfaltspflichten gegenüber Kunden im Namen des verpflichteten Unternehmens die in Artikel 10 der Richtlinie (EU) 2024/1640 genannten zentralen Register (zentrale Register) konsultieren müssen. Das verpflichtete Unternehmen bleibt für jede mit den ausgelagerten und von Dienstleistern durchgeführten Aufgaben verbundene Handlung, sei es ein Tun oder Unterlassen, uneingeschränkt haftbar. Für jede ausgelagerte Aufgabe muss das verpflichtete Unternehmen gegenüber der Aufsichtsbehörde nachweisen können, dass es die Gründe für die vom Dienstleister ausgeübten Tätigkeiten und den bei ihrer Umsetzung verfolgten Ansatz versteht und dass diese Tätigkeiten die spezifischen Risiken, denen das verpflichtete Unternehmen ausgesetzt ist, mindern.

3 3 3

The tasks outsourced pursuant to paragraph 1 of this Article shall not be undertaken in such a way as to impair materially the quality of the obliged entity’s policies and procedures to comply with the requirements of this Regulation and of Regulation (EU) 2023/1113, and of the controls in place to test those policies and procedures. The following tasks shall not be outsourced under any circumstances:

  • (a) the proposal and approval of the obliged entity’s business-wide risk assessment pursuant to Article 10(2);
  • (b) the approval of the obliged entity’s internal policies, procedures and controls pursuant to Article 9;
  • (c) decision on the risk profile to be attributed to the customer;
  • (d) the decision to enter into a business relationship or carry out an occasional transaction with a client;
  • (e) the reporting to FIU of suspicious activities pursuant to Article 69 or threshold-based reports pursuant to Article 74 and 80, except where such activities are outsourced to another obliged entity belonging to the same group and established in the same Member State;
  • (f) the approval of the criteria for the detection of suspicious or unusual transactions and activities.

The tasks outsourced pursuant to paragraph 1 of this Article shall not be undertaken in such a way as to impair materially the quality of the obliged entity’s policies and procedures to comply with the requirements of this Regulation and of Regulation (EU) 2023/1113, and of the controls in place to test those policies and procedures. The following tasks shall not be outsourced under any circumstances:

  • (a) the proposal and approval of the obliged entity’s business-wide risk assessment pursuant to Article 10(2);
  • (b) the approval of the obliged entity’s internal policies, procedures and controls pursuant to Article 9;
  • (c) decision on the risk profile to be attributed to the customer;
  • (d) the decision to enter into a business relationship or carry out an occasional transaction with a client;
  • (e) the reporting to FIU of suspicious activities pursuant to Article 69 or threshold-based reports pursuant to Article 74 and 80, except where such activities are outsourced to another obliged entity belonging to the same group and established in the same Member State;
  • (f) the approval of the criteria for the detection of suspicious or unusual transactions and activities.

Die gemäß Absatz 1 dieses Artikels ausgelagerten Aufgaben dürfen nicht so wahrgenommen werden, dass die Qualität der Strategien und Verfahren des verpflichteten Unternehmens zur Einhaltung der Anforderungen dieser Verordnung und der Verordnung (EU) 2023/1113 sowie der zur Prüfung dieser Strategien und Verfahren eingerichteten Kontrollen wesentlich beeinträchtigt wird. Unter keinen Umständen dürfen folgende Aufgaben ausgelagert werden:

  • a) der Vorschlag und die Genehmigung der unternehmensweiten Risikobewertung des verpflichteten Unternehmens gemäß Artikel 10 Absatz 2;
  • b) die Genehmigung der internen Strategien, Verfahren und Kontrollen des verpflichteten Unternehmens gemäß Artikel 9;
  • c) die Entscheidung über das dem Kunden zuzuordnende Risikoprofil;
  • d) die Entscheidung, eine Geschäftsbeziehung mit einem Kunden einzugehen oder eine gelegentliche Transaktion mit ihm durchzuführen;
  • e) die Meldung verdächtiger Tätigkeiten an die zentrale Meldestelle gemäß Artikel 69 oder schwellenwertbezogener Meldungen gemäß den Artikeln 74 und 80, außer wenn diese Tätigkeiten an ein anderes verpflichtetes Unternehmen ausgelagert werden, das derselben Gruppe angehört und im selben Mitgliedstaat niedergelassen ist;
  • f) die Genehmigung der Kriterien zur Aufdeckung verdächtiger oder ungewöhnlicher Transaktionen und Tätigkeiten.
4 4 4

Before an obliged entity outsources a task pursuant to paragraph 1, it shall assure itself that the service provider is sufficiently qualified to carry out the tasks to be outsourced.Where an obliged entity outsources a task pursuant to paragraph 1, it shall ensure that the service provider, as well as any subsequent sub-outsourcing service provider, applies the policies and procedures adopted by the obliged entity. The conditions for the performance of such tasks shall be laid down in a written agreement between the obliged entity and the service provider. The obliged entity shall perform regular controls to ascertain the effective implementation of such policies and procedures by the service provider. The frequency of such controls shall be determined on the basis of the critical nature of the tasks outsourced.

Before an obliged entity outsources a task pursuant to paragraph 1, it shall assure itself that the service provider is sufficiently qualified to carry out the tasks to be outsourced. Where an obliged entity outsources a task pursuant to paragraph 1, it shall ensure that the service provider, as well as any subsequent sub-outsourcing service provider, applies the policies and procedures adopted by the obliged entity. The conditions for the performance of such tasks shall be laid down in a written agreement between the obliged entity and the service provider. The obliged entity shall perform regular controls to ascertain the effective implementation of such policies and procedures by the service provider. The frequency of such controls shall be determined on the basis of the critical nature of the tasks outsourced.

Bevor ein verpflichtetes Unternehmen eine Aufgabe gemäß Absatz 1 auslagert, vergewissert es sich, dass der Dienstleister hinreichend qualifiziert ist, um die auszulagernden Aufgaben wahrzunehmen. Lagert ein verpflichtetes Unternehmen eine Aufgabe gemäß Absatz 1 aus, so stellt es sicher, dass der Dienstleister sowie jeder nachfolgende Unterauftragnehmer die vom verpflichteten Unternehmen angenommenen Strategien und Verfahren anwendet. Die Bedingungen für die Wahrnehmung dieser Aufgaben werden in einer schriftlichen Vereinbarung zwischen dem verpflichteten Unternehmen und dem Dienstleister festgelegt. Das verpflichtete Unternehmen führt regelmäßige Kontrollen durch, um die wirksame Umsetzung dieser Strategien und Verfahren durch den Dienstleister festzustellen. Die Häufigkeit dieser Kontrollen wird anhand des kritischen Charakters der ausgelagerten Aufgaben bestimmt.

5 5 5

Obliged entities shall ensure that outsourcing is not undertaken in such way as to impair materially the ability of the supervisory authorities to monitor and retrace the obliged entity’s compliance with this Regulation and Regulation (EU) 2023/1113.

Obliged entities shall ensure that outsourcing is not undertaken in such way as to impair materially the ability of the supervisory authorities to monitor and retrace the obliged entity’s compliance with this Regulation and Regulation (EU) 2023/1113.

Verpflichtete Unternehmen stellen sicher, dass Auslagerungen nicht so vorgenommen werden, dass die Fähigkeit der Aufsichtsbehörden, die Einhaltung dieser Verordnung und der Verordnung (EU) 2023/1113 durch das verpflichtete Unternehmen zu überwachen und nachzuverfolgen, wesentlich beeinträchtigt wird.

6 6 6

By way of derogation from paragraph 1, obliged entities shall not outsource tasks deriving from the requirements under this Regulation to service providers residing or established in third countries identified pursuant to Section 2 of Chapter III, unless all of the following conditions are met:

  • (a) the obliged entity outsources tasks solely to a service provider that is part of the same group;
  • (b) the group applies AML/CFT policies and procedures, customer due diligence measures and rules on record-keeping that are fully in compliance with this Regulation, or with equivalent rules in third countries;
  • (c) the effective implementation of the requirements referred to in point (b) of this paragraph is supervised at group level by the supervisory authority of the home Member State in accordance with Chapter IV of Directive (EU) 2024/1640.

By way of derogation from paragraph 1, obliged entities shall not outsource tasks deriving from the requirements under this Regulation to service providers residing or established in third countries identified pursuant to Section 2 of Chapter III, unless all of the following conditions are met:

  • (a) the obliged entity outsources tasks solely to a service provider that is part of the same group;
  • (b) the group applies AML/CFT policies and procedures, customer due diligence measures and rules on record-keeping that are fully in compliance with this Regulation, or with equivalent rules in third countries;
  • (c) the effective implementation of the requirements referred to in point (b) of this paragraph is supervised at group level by the supervisory authority of the home Member State in accordance with Chapter IV of Directive (EU) 2024/1640.

Abweichend von Absatz 1 dürfen verpflichtete Unternehmen sich aus den Anforderungen dieser Verordnung ergebende Aufgaben nicht an Dienstleister auslagern, die in den gemäß Abschnitt 2 des Kapitels III bestimmten Drittländern ansässig oder niedergelassen sind, es sei denn, alle folgenden Bedingungen sind erfüllt:

  • a) Das verpflichtete Unternehmen lagert Aufgaben ausschließlich an einen Dienstleister aus, der derselben Gruppe angehört;
  • b) Die Gruppe wendet Strategien und Verfahren zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung, Sorgfaltspflichten gegenüber Kunden und Vorschriften zur Aufbewahrung von Aufzeichnungen an, die vollständig mit dieser Verordnung oder mit gleichwertigen Vorschriften in Drittländern im Einklang stehen;
  • c) Die wirksame Umsetzung der unter Buchstabe b dieses Absatzes genannten Anforderungen wird auf Gruppenebene von der Aufsichtsbehörde des Herkunftsmitgliedstaats gemäß Kapitel IV der Richtlinie (EU) 2024/1640 beaufsichtigt.
7 7 7

By way of derogation from paragraph 3, where a collective investment undertaking has no legal personality, or has only a board of directors and has delegated the processing of subscriptions and the collection of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 from investors to another entity, it may outsource the task referred to in paragraph 3, points (c), (d) and (e) to one of its service providers.

The outsourcing referred to in the first subparagraph of this paragraph may only take place after the collective investment undertaking has notified its intention to outsource the task to the supervisor pursuant to paragraph 1, and the supervisor has approved such outsourcing taking into consideration:

  • (a) the resources, experience and knowledge of the service provider in relation to the prevention of money laundering and terrorist financing;
  • (b) the knowledge of the service provider of the type of activities or transactions carried out by the collective investment undertaking.

By way of derogation from paragraph 3, where a collective investment undertaking has no legal personality, or has only a board of directors and has delegated the processing of subscriptions and the collection of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 from investors to another entity, it may outsource the task referred to in paragraph 3, points (c), (d) and (e) to one of its service providers.

The outsourcing referred to in the first subparagraph of this paragraph may only take place after the collective investment undertaking has notified its intention to outsource the task to the supervisor pursuant to paragraph 1, and the supervisor has approved such outsourcing taking into consideration:

  • (a) the resources, experience and knowledge of the service provider in relation to the prevention of money laundering and terrorist financing;
  • (b) the knowledge of the service provider of the type of activities or transactions carried out by the collective investment undertaking.

Abweichend von Absatz 3 kann ein Organismus für gemeinsame Anlagen, der keine Rechtspersönlichkeit besitzt oder nur über einen Verwaltungsrat verfügt und die Bearbeitung von Zeichnungen und die Einziehung von Geldern im Sinne des Artikels 4 Nummer 25 der Richtlinie (EU) 2015/2366 von Anlegern an ein anderes Unternehmen delegiert hat, die in Absatz 3 Buchstaben c, d und e genannten Aufgaben an einen seiner Dienstleister auslagern.

Die im ersten Unterabsatz dieses Absatzes genannte Auslagerung darf erst erfolgen, nachdem der Organismus für gemeinsame Anlagen seine Absicht, die Aufgabe auszulagern, der Aufsichtsbehörde gemäß Absatz 1 mitgeteilt hat und die Aufsichtsbehörde diese Auslagerung unter Berücksichtigung folgender Faktoren genehmigt hat:

  • a) die Ressourcen, Erfahrung und Kenntnisse des Dienstleisters im Zusammenhang mit der Verhinderung von Geldwäsche und Terrorismusfinanzierung;
  • b) die Kenntnisse des Dienstleisters über die Art der vom Organismus für gemeinsame Anlagen ausgeübten Tätigkeiten oder durchgeführten Transaktionen.
8 8 8

By 10 July 2027, AMLA shall issue guidelines addressed to obliged entities on:

  • (a) the establishment of outsourcing relationships, including any subsequent outsourcing relationship, in accordance with this Article, their governance and procedures for monitoring the implementation of functions by the service provider and in particular those functions that are to be regarded as critical;
  • (b) the roles and responsibility of the obliged entity and the service provider within an outsourcing agreement;
  • (c) supervisory approaches to outsourcing as well as supervisory expectations regarding the outsourcing of critical functions.

By 10 July 2027, AMLA shall issue guidelines addressed to obliged entities on:

  • (a) the establishment of outsourcing relationships, including any subsequent outsourcing relationship, in accordance with this Article, their governance and procedures for monitoring the implementation of functions by the service provider and in particular those functions that are to be regarded as critical;
  • (b) the roles and responsibility of the obliged entity and the service provider within an outsourcing agreement;
  • (c) supervisory approaches to outsourcing as well as supervisory expectations regarding the outsourcing of critical functions.

Bis zum 10. Juli 2027 erlässt die AMLA Leitlinien für verpflichtete Unternehmen zu:

  • a) der Begründung von Auslagerungsbeziehungen, einschließlich jeder nachfolgenden Auslagerungsbeziehung, gemäß diesem Artikel, ihrer Governance und den Verfahren zur Überwachung der Wahrnehmung von Funktionen durch den Dienstleister, insbesondere der als kritisch anzusehenden Funktionen;
  • b) den Rollen und Verantwortlichkeiten des verpflichteten Unternehmens und des Dienstleisters im Rahmen einer Auslagerungsvereinbarung;
  • c) den Aufsichtsansätzen für Auslagerungen sowie den Erwartungen der Aufsicht hinsichtlich der Auslagerung kritischer Funktionen.
CHAPTER III — CUSTOMER DUE DILIGENCE CHAPTER III — CUSTOMER DUE DILIGENCE CHAPTER III — SORGFALTSPFLICHTEN GEGENÜBER KUNDEN
SECTION 1 — General provisions SECTION 1 — General provisions SECTION 1 — Allgemeine Bestimmungen
Article 19 — Application of customer due diligence measures Article 19 — Application of customer due diligence measures Article 19 — Anwendung von Sorgfaltspflichten gegenüber Kunden
1 1 1

Obliged entities shall apply customer due diligence measures in any of the following circumstances:

  • (a) when establishing a business relationship;
  • (b) when carrying out an occasional transaction of a value of at least EUR 10000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions, or a lower value laid down pursuant to paragraph 9;
  • (c) when participating in the creation of a legal entity, the setting up of a legal arrangement or, for the obliged entities referred to in Article 3, points (3) (a), (b) or (c), in the transfer of ownership of a legal entity, irrespective of the value of the transaction;
  • (d) when there is a suspicion of money laundering or terrorist financing, regardless of any derogation, exemption or threshold;
  • (e) when there are doubts about the veracity or adequacy of previously obtained customer identification data;
  • (f) when there are doubts as to whether the person they interact with is the customer or person authorised to act on behalf of the customer.

Obliged entities shall apply customer due diligence measures in any of the following circumstances:

  • (a) when establishing a business relationship;
  • (b) when carrying out an occasional transaction of a value of at least EUR 10000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions, or a lower value laid down pursuant to paragraph 9;
  • (c) when participating in the creation of a legal entity, the setting up of a legal arrangement or, for the obliged entities referred to in Article 3, points (3) (a), (b) or (c), in the transfer of ownership of a legal entity, irrespective of the value of the transaction;
  • (d) when there is a suspicion of money laundering or terrorist financing, regardless of any derogation, exemption or threshold;
  • (e) when there are doubts about the veracity or adequacy of previously obtained customer identification data;
  • (f) when there are doubts as to whether the person they interact with is the customer or person authorised to act on behalf of the customer.

Verpflichtete Unternehmen wenden Sorgfaltspflichten gegenüber Kunden in jedem der folgenden Fälle an:

  • a) bei Begründung einer Geschäftsbeziehung;
  • b) bei Durchführung einer gelegentlichen Transaktion im Wert von mindestens 10 000 EUR oder dem Gegenwert in Landeswährung, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder durch verbundene Transaktionen durchgeführt wird, oder eines gemäß Absatz 9 festgelegten niedrigeren Werts;
  • c) bei Mitwirkung an der Gründung einer juristischen Person, der Errichtung einer Rechtsvereinbarung oder – bei den in Artikel 3 Nummer 3 Buchstaben a, b oder c genannten verpflichteten Unternehmen – an der Übertragung des Eigentums an einer juristischen Person, unabhängig vom Wert der Transaktion;
  • d) bei Verdacht auf Geldwäsche oder Terrorismusfinanzierung, unabhängig von einer Abweichung, Ausnahme oder Schwelle;
  • e) bei Zweifeln an der Richtigkeit oder Angemessenheit zuvor erhobener Identifikationsdaten des Kunden;
  • f) bei Zweifeln daran, ob die Person, mit der sie interagieren, der Kunde oder eine zum Handeln im Namen des Kunden befugte Person ist.
2 2 2

In addition to the circumstances referred to in paragraph 1, credit institutions and financial institutions, with the exception of crypto-asset service providers, shall apply customer due diligence measures when initiating or executing an occasional transaction that constitutes a transfer of funds as defined in Article 3, point (9), of Regulation (EU) 2023/1113, that amounts to a value of at least EUR 1000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions.

In addition to the circumstances referred to in paragraph 1, credit institutions and financial institutions, with the exception of crypto-asset service providers, shall apply customer due diligence measures when initiating or executing an occasional transaction that constitutes a transfer of funds as defined in Article 3, point (9), of Regulation (EU) 2023/1113, that amounts to a value of at least EUR 1000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions.

Zusätzlich zu den in Absatz 1 genannten Fällen wenden Kreditinstitute und Finanzinstitute, mit Ausnahme von Anbietern von Krypto-Dienstleistungen, Sorgfaltspflichten gegenüber Kunden an, wenn sie eine gelegentliche Transaktion einleiten oder durchführen, die eine Übertragung von Geldbeträgen im Sinne des Artikels 3 Nummer 9 der Verordnung (EU) 2023/1113 darstellt und einen Wert von mindestens 1 000 EUR oder dem Gegenwert in Landeswährung aufweist, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder durch verbundene Transaktionen durchgeführt wird.

3 3 3

By way of derogation from paragraph 1, point (b), crypto-asset service providers shall:

  • (a) apply customer due diligence measures when carrying out an occasional transaction that amounts to a value of at least EUR 1000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions;
  • (b) apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction where the value is below EUR 1000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.

By way of derogation from paragraph 1, point (b), crypto-asset service providers shall:

  • (a) apply customer due diligence measures when carrying out an occasional transaction that amounts to a value of at least EUR 1000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions;
  • (b) apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction where the value is below EUR 1000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.

Abweichend von Absatz 1 Buchstabe b wenden Anbieter von Krypto-Dienstleistungen Folgendes an:

  • a) Sorgfaltspflichten gegenüber Kunden bei Durchführung einer gelegentlichen Transaktion im Wert von mindestens 1 000 EUR oder dem Gegenwert in Landeswährung, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder durch verbundene Transaktionen durchgeführt wird;
  • b) mindestens die in Artikel 20 Absatz 1 Buchstabe a genannten Sorgfaltspflichten gegenüber Kunden bei Durchführung einer gelegentlichen Transaktion mit einem Wert von weniger als 1 000 EUR oder dem Gegenwert in Landeswährung, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder durch verbundene Transaktionen durchgeführt wird.
4 4 4

By way of derogation from paragraph 1, point (b), obliged entities shall apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction in cash amounting to a value of at least EUR 3000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.The first subparagraph of this paragraph shall not apply where Member States have in place, pursuant to Article 80(2) and (3), a limit to large cash payments of EUR 3000 or less, or the equivalent in national currency, except in the cases covered by paragraph 4, point (b) of that Article.

By way of derogation from paragraph 1, point (b), obliged entities shall apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction in cash amounting to a value of at least EUR 3000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions. The first subparagraph of this paragraph shall not apply where Member States have in place, pursuant to Article 80(2) and (3), a limit to large cash payments of EUR 3000 or less, or the equivalent in national currency, except in the cases covered by paragraph 4, point (b) of that Article.

Abweichend von Absatz 1 Buchstabe b wenden verpflichtete Unternehmen mindestens die in Artikel 20 Absatz 1 Buchstabe a genannten Sorgfaltspflichten gegenüber Kunden an, wenn sie eine gelegentliche Bargeldtransaktion im Wert von mindestens 3 000 EUR oder dem Gegenwert in Landeswährung durchführen, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder durch verbundene Transaktionen durchgeführt wird. Der erste Unterabsatz dieses Absatzes gilt nicht, wenn die Mitgliedstaaten gemäß Artikel 80 Absätze 2 und 3 eine Obergrenze für hohe Barzahlungen von höchstens 3 000 EUR oder dem Gegenwert in Landeswährung festgelegt haben, außer in den von Absatz 4 Buchstabe b jenes Artikels erfassten Fällen.

5 5 5

In addition to the circumstances referred to in paragraph 1, providers of gambling services shall apply customer due diligence measures upon the collection of winnings, the wagering of a stake, or both, when carrying out transactions amounting to at least EUR 2000 or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.

In addition to the circumstances referred to in paragraph 1, providers of gambling services shall apply customer due diligence measures upon the collection of winnings, the wagering of a stake, or both, when carrying out transactions amounting to at least EUR 2000 or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.

Zusätzlich zu den in Absatz 1 genannten Fällen wenden Anbieter von Glücksspieldiensten Sorgfaltspflichten gegenüber Kunden bei der Auszahlung von Gewinnen, dem Setzen eines Einsatzes oder beidem an, wenn sie Transaktionen im Wert von mindestens 2 000 EUR oder dem Gegenwert in Landeswährung durchführen, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder durch verbundene Transaktionen durchgeführt wird.

6 6 6

For the purposes of this Chapter, obliged entities shall consider as their customers the following persons:

  • (a) in the case of obliged entities as referred to in Article 3, points (3) (e), (f) and (i) and persons trading in high value goods as referred to in Article 3, point (3) (j), in addition to their direct customer, the supplier of goods;
  • (b) in the case of notaries, lawyers and other independent legal professionals intermediating a transaction and to the extent that they are the only notary or lawyer or other independent legal professional intermediating that transaction, both parties to the transaction;
  • (c) in the case of real estate agents, both parties to the transaction;
  • (d) in relation to payment initiation services carried out by payment initiation service providers, the merchant;
  • (e) in relation to crowdfunding service providers and crowdfunding intermediaries, the natural or legal person both seeking funding and providing funding through the crowdfunding platform.

For the purposes of this Chapter, obliged entities shall consider as their customers the following persons:

  • (a) in the case of obliged entities as referred to in Article 3, points (3) (e), (f) and (i) and persons trading in high value goods as referred to in Article 3, point (3) (j), in addition to their direct customer, the supplier of goods;
  • (b) in the case of notaries, lawyers and other independent legal professionals intermediating a transaction and to the extent that they are the only notary or lawyer or other independent legal professional intermediating that transaction, both parties to the transaction;
  • (c) in the case of real estate agents, both parties to the transaction;
  • (d) in relation to payment initiation services carried out by payment initiation service providers, the merchant;
  • (e) in relation to crowdfunding service providers and crowdfunding intermediaries, the natural or legal person both seeking funding and providing funding through the crowdfunding platform.

Für die Zwecke dieses Kapitels betrachten verpflichtete Unternehmen folgende Personen als ihre Kunden:

  • a) bei den in Artikel 3 Nummer 3 Buchstaben e, f und i genannten verpflichteten Unternehmen und bei Personen, die mit hochwertigen Gütern handeln, im Sinne des Artikels 3 Nummer 3 Buchstabe j, zusätzlich zu ihrem unmittelbaren Kunden den Lieferanten der Güter;
  • b) bei Notaren, Rechtsanwälten und anderen unabhängigen Angehörigen der rechtsberatenden Berufe, die eine Transaktion vermitteln, sofern sie der einzige Notar, Rechtsanwalt oder andere unabhängige Angehörige der rechtsberatenden Berufe sind, der diese Transaktion vermittelt, beide Parteien der Transaktion;
  • c) bei Immobilienmaklern beide Parteien der Transaktion;
  • d) im Zusammenhang mit von Zahlungsauslösedienstleistern erbrachten Zahlungsauslösediensten den Händler;
  • e) im Zusammenhang mit Crowdfunding-Dienstleistern und Crowdfunding-Vermittlern die natürliche oder juristische Person, die sowohl eine Finanzierung sucht als auch über die Crowdfunding-Plattform eine Finanzierung bereitstellt.
7 7 7

Supervisors may, directly or in cooperation with other authorities in that Member State, exempt obliged entities from applying, in full or in part, the customer due diligence measures referred to in Article 20(1), points (a), (b) and (c), with respect to electronic money on the basis of the proven low risk posed by the nature of the product, where all of the following risk-mitigating conditions are met:

  • (a) the payment instrument is not reloadable, and the amount stored electronically does not exceed EUR 150 or the equivalent in national currency;
  • (b) the payment instrument is used exclusively to purchase goods or services provided by the issuer, or within a network of service providers;
  • (c) the payment instrument is not linked to a payment account and it does not permit any stored amount to be exchanged for cash or for crypto-assets;
  • (d) the issuer carries out sufficient monitoring of the transactions or business relationship to enable the detection of unusual or suspicious transactions.

Supervisors may, directly or in cooperation with other authorities in that Member State, exempt obliged entities from applying, in full or in part, the customer due diligence measures referred to in Article 20(1), points (a), (b) and (c), with respect to electronic money on the basis of the proven low risk posed by the nature of the product, where all of the following risk-mitigating conditions are met:

  • (a) the payment instrument is not reloadable, and the amount stored electronically does not exceed EUR 150 or the equivalent in national currency;
  • (b) the payment instrument is used exclusively to purchase goods or services provided by the issuer, or within a network of service providers;
  • (c) the payment instrument is not linked to a payment account and it does not permit any stored amount to be exchanged for cash or for crypto-assets;
  • (d) the issuer carries out sufficient monitoring of the transactions or business relationship to enable the detection of unusual or suspicious transactions.

Die Aufsichtsbehörden können verpflichtete Unternehmen direkt oder in Zusammenarbeit mit anderen Behörden dieses Mitgliedstaats von der vollständigen oder teilweisen Anwendung der in Artikel 20 Absatz 1 Buchstaben a, b und c genannten Sorgfaltspflichten gegenüber Kunden in Bezug auf E-Geld ausnehmen, wenn aufgrund der nachgewiesenen geringen Risiken, die von der Art des Produkts ausgehen, alle folgenden risikomindernden Bedingungen erfüllt sind:

  • a) Das Zahlungsinstrument ist nicht wiederaufladbar und der elektronisch gespeicherte Betrag überschreitet nicht 150 EUR oder den Gegenwert in Landeswährung;
  • b) Das Zahlungsinstrument wird ausschließlich zum Erwerb von Waren oder Dienstleistungen verwendet, die vom Emittenten oder innerhalb eines Netzes von Dienstleistern bereitgestellt werden;
  • c) Das Zahlungsinstrument ist nicht mit einem Zahlungskonto verbunden und erlaubt nicht, gespeicherte Beträge in Bargeld oder Krypto-Vermögenswerte umzutauschen;
  • d) Der Emittent überwacht die Transaktionen oder die Geschäftsbeziehung ausreichend, um die Erkennung ungewöhnlicher oder verdächtiger Transaktionen zu ermöglichen.
8 8 8

Providers of gambling services may fulfil their obligation to apply customer due diligence measures referred to in Article 20(1), point (a), by identifying the customer and verifying the customer’s identity upon entry to the casino or other physical gambling premises, provided that they have systems in place that enable them to attribute transactions to specific customers.

Providers of gambling services may fulfil their obligation to apply customer due diligence measures referred to in Article 20(1), point (a), by identifying the customer and verifying the customer’s identity upon entry to the casino or other physical gambling premises, provided that they have systems in place that enable them to attribute transactions to specific customers.

Anbieter von Glücksspieldiensten können ihrer Verpflichtung zur Anwendung der in Artikel 20 Absatz 1 Buchstabe a genannten Sorgfaltspflichten gegenüber Kunden nachkommen, indem sie den Kunden beim Betreten des Kasinos oder anderer örtlicher Glücksspieleinrichtungen identifizieren und seine Identität überprüfen, sofern sie über Systeme verfügen, die es ihnen ermöglichen, Transaktionen bestimmten Kunden zuzuordnen.

9 9 9

By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify:

  • (a) the obliged entities, sectors or transactions that are associated with higher money laundering and terrorist financing risk and to which a value lower than the value set out in paragraph 1, point (b), applies;
  • (b) the related occasional transaction values;
  • (c) the criteria to be taken into account for identifying occasional transactions and business relationships;
  • (d) the criteria to identify linked transactions.

When developing the draft regulatory technical standards referred to in the first subparagraph, AMLA shall take due account of the inherent levels of risks of the business models of the different types of obliged entities and of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640.

By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify:

  • (a) the obliged entities, sectors or transactions that are associated with higher money laundering and terrorist financing risk and to which a value lower than the value set out in paragraph 1, point (b), applies;
  • (b) the related occasional transaction values;
  • (c) the criteria to be taken into account for identifying occasional transactions and business relationships;
  • (d) the criteria to identify linked transactions.

When developing the draft regulatory technical standards referred to in the first subparagraph, AMLA shall take due account of the inherent levels of risks of the business models of the different types of obliged entities and of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640.

Bis zum 10. Juli 2026 entwickelt die AMLA Entwürfe technischer Regulierungsstandards und legt sie der Kommission zur Annahme vor. In diesen Entwürfen technischer Regulierungsstandards wird Folgendes festgelegt:

  • a) die verpflichteten Unternehmen, Sektoren oder Transaktionen, die mit einem höheren Risiko der Geldwäsche und Terrorismusfinanzierung verbunden sind und für die ein niedrigerer Wert als der in Absatz 1 Buchstabe b festgelegte Wert gilt;
  • b) die entsprechenden Werte gelegentlicher Transaktionen;
  • c) die bei der Identifizierung gelegentlicher Transaktionen und Geschäftsbeziehungen zu berücksichtigenden Kriterien;
  • d) die Kriterien zur Identifizierung verbundener Transaktionen.

Bei der Ausarbeitung der im ersten Unterabsatz genannten Entwürfe technischer Regulierungsstandards trägt die AMLA den inhärenten Risikograden der Geschäftsmodelle der verschiedenen Arten verpflichteter Unternehmen und der von der Kommission gemäß Artikel 7 der Richtlinie (EU) 2024/1640 auf Unionsebene durchgeführten Risikobewertung gebührend Rechnung.

10 10 10

Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 9 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 9 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Der Kommission wird die Befugnis übertragen, diese Verordnung durch den Erlass der in Absatz 9 dieses Artikels genannten technischen Regulierungsstandards gemäß den Artikeln 49 bis 52 der Verordnung (EU) 2024/1620 zu ergänzen.

Article 20 — Customer due diligence measures Article 20 — Customer due diligence measures Article 20 — Sorgfaltspflichten gegenüber Kunden
1 1 1

For the purpose of conducting customer due diligence, obliged entities shall apply all of the following measures:

  • (a) identifying the customer and verifying the customer’s identity;
  • (b) identifying the beneficial owners and taking reasonable measures to verify their identity so that the obliged entity is satisfied that it knows who the beneficial owner is and that it understands the ownership and control structure of the customer;
  • (c) assessing and, as appropriate, obtaining information on and understanding the purpose and intended nature of the business relationship or the occasional transactions;
  • (d) verifying whether the customer or the beneficial owners are subject to targeted financial sanctions, and, in the case of a customer or party to a legal arrangement who is a legal entity, whether natural or legal persons subject to targeted financial sanctions control the legal entity or have more than 50 % of the proprietary rights of that legal entity or majority interest in it, whether individually or collectively;
  • (e) assessing and, as appropriate, obtaining information on the nature of the customers’ business, including, in the case of undertakings, whether they carry out activities, or of their employment or occupation;
  • (f) conducting ongoing monitoring of the business relationship including scrutiny of transactions undertaken throughout the course of the business relationship to ensure that the transactions being conducted are consistent with the obliged entity’s knowledge of the customer, the business and risk profile, including where necessary the source of funds;
  • (g) determining whether the customer, the beneficial owner of the customer and, where relevant, the person on whose behalf or for the benefit of whom a transaction or activity is being carried out is a politically exposed person, a family member or person known to be a close associate;
  • (h) where a transaction or activity is being conducted on behalf of or for the benefit of natural persons other than the customer, identifying and verifying the identity of those natural persons;
  • (i) verifying that any person purporting to act on behalf of the customer is so authorised and identify and verify their identity.

For the purpose of conducting customer due diligence, obliged entities shall apply all of the following measures:

  • (a) identifying the customer and verifying the customer’s identity;
  • (b) identifying the beneficial owners and taking reasonable measures to verify their identity so that the obliged entity is satisfied that it knows who the beneficial owner is and that it understands the ownership and control structure of the customer;
  • (c) assessing and, as appropriate, obtaining information on and understanding the purpose and intended nature of the business relationship or the occasional transactions;
  • (d) verifying whether the customer or the beneficial owners are subject to targeted financial sanctions, and, in the case of a customer or party to a legal arrangement who is a legal entity, whether natural or legal persons subject to targeted financial sanctions control the legal entity or have more than 50 % of the proprietary rights of that legal entity or majority interest in it, whether individually or collectively;
  • (e) assessing and, as appropriate, obtaining information on the nature of the customers’ business, including, in the case of undertakings, whether they carry out activities, or of their employment or occupation;
  • (f) conducting ongoing monitoring of the business relationship including scrutiny of transactions undertaken throughout the course of the business relationship to ensure that the transactions being conducted are consistent with the obliged entity’s knowledge of the customer, the business and risk profile, including where necessary the source of funds;
  • (g) determining whether the customer, the beneficial owner of the customer and, where relevant, the person on whose behalf or for the benefit of whom a transaction or activity is being carried out is a politically exposed person, a family member or person known to be a close associate;
  • (h) where a transaction or activity is being conducted on behalf of or for the benefit of natural persons other than the customer, identifying and verifying the identity of those natural persons;
  • (i) verifying that any person purporting to act on behalf of the customer is so authorised and identify and verify their identity.

Für die Zwecke der Durchführung der Sorgfaltspflichten gegenüber Kunden wenden verpflichtete Unternehmen alle folgenden Maßnahmen an:

  • a) Identifizierung des Kunden und Überprüfung seiner Identität;
  • b) Identifizierung der wirtschaftlichen Eigentümer und Ergreifung angemessener Maßnahmen zur Überprüfung ihrer Identität, sodass das verpflichtete Unternehmen davon überzeugt ist, zu wissen, wer der wirtschaftliche Eigentümer ist, und die Eigentums- und Kontrollstruktur des Kunden versteht;
  • c) Bewertung und gegebenenfalls Einholung von Informationen über sowie Verständnis des Zwecks und der angestrebten Art der Geschäftsbeziehung oder der gelegentlichen Transaktionen;
  • d) Überprüfung, ob der Kunde oder die wirtschaftlichen Eigentümer gezielten finanziellen Sanktionen unterliegen, und – im Falle eines Kunden oder Beteiligten an einer Rechtsvereinbarung, bei dem es sich um eine juristische Person handelt – ob natürliche oder juristische Personen, die gezielten finanziellen Sanktionen unterliegen, die juristische Person kontrollieren oder einzeln oder gemeinsam mehr als 50 % der Eigentumsrechte an der juristischen Person oder eine Mehrheitsbeteiligung daran halten;
  • e) Bewertung und gegebenenfalls Einholung von Informationen über die Art der Geschäftstätigkeit der Kunden, einschließlich – bei Unternehmen – darüber, ob sie Tätigkeiten ausüben, oder über ihre Beschäftigung oder ihren Beruf;
  • f) laufende Überwachung der Geschäftsbeziehung, einschließlich der Prüfung der während der Geschäftsbeziehung durchgeführten Transaktionen, um sicherzustellen, dass die durchgeführten Transaktionen mit den Kenntnissen des verpflichteten Unternehmens über den Kunden, dessen Geschäfts- und Risikoprofil sowie gegebenenfalls der Herkunft der Gelder übereinstimmen;
  • g) Feststellung, ob es sich bei dem Kunden, dem wirtschaftlichen Eigentümer des Kunden und gegebenenfalls der Person, in deren Namen oder zu deren Gunsten eine Transaktion oder Tätigkeit durchgeführt wird, um eine politisch exponierte Person, ein Familienmitglied oder eine bekanntermaßen nahestehende Person handelt;
  • h) Identifizierung und Überprüfung der Identität natürlicher Personen, wenn eine Transaktion oder Tätigkeit im Namen oder zugunsten anderer natürlicher Personen als des Kunden durchgeführt wird;
  • i) Überprüfung, dass jede Person, die vorgibt, im Namen des Kunden zu handeln, hierzu befugt ist, sowie Identifizierung und Überprüfung ihrer Identität.
2 2 2

Obliged entities shall determine the extent of the measures referred to in paragraph 1 on the basis of an individual analysis of the risks of money laundering and terrorist financing having regard to the specific characteristics of the client and of the business relationship or occasional transaction, and taking into account the business-wide risk assessment by the obliged entity pursuant to Article 10 and the money laundering and terrorist financing variables set out in Annex I as well as the risk factors set out in Annexes II and III.Where obliged entities identify an increased risk of money laundering or terrorist financing they shall apply enhanced due diligence measures pursuant to Section 4 of this Chapter. Where situations of lower risk are identified, obliged entities may apply simplified due diligence measures pursuant to Section 3 of this Chapter.

Obliged entities shall determine the extent of the measures referred to in paragraph 1 on the basis of an individual analysis of the risks of money laundering and terrorist financing having regard to the specific characteristics of the client and of the business relationship or occasional transaction, and taking into account the business-wide risk assessment by the obliged entity pursuant to Article 10 and the money laundering and terrorist financing variables set out in Annex I as well as the risk factors set out in Annexes II and III. Where obliged entities identify an increased risk of money laundering or terrorist financing they shall apply enhanced due diligence measures pursuant to Section 4 of this Chapter. Where situations of lower risk are identified, obliged entities may apply simplified due diligence measures pursuant to Section 3 of this Chapter.

Verpflichtete Unternehmen bestimmen den Umfang der in Absatz 1 genannten Maßnahmen auf der Grundlage einer individuellen Analyse der Risiken von Geldwäsche und Terrorismusfinanzierung unter Berücksichtigung der spezifischen Merkmale des Kunden und der Geschäftsbeziehung oder gelegentlichen Transaktion sowie unter Berücksichtigung der unternehmensweiten Risikobewertung des verpflichteten Unternehmens gemäß Artikel 10, der in Anhang I aufgeführten Variablen für Geldwäsche und Terrorismusfinanzierung sowie der in den Anhängen II und III aufgeführten Risikofaktoren. Stellen verpflichtete Unternehmen ein erhöhtes Risiko von Geldwäsche oder Terrorismusfinanzierung fest, wenden sie gemäß Abschnitt 4 dieses Kapitels verstärkte Sorgfaltspflichten an. Werden Situationen mit geringerem Risiko festgestellt, können verpflichtete Unternehmen gemäß Abschnitt 3 dieses Kapitels vereinfachte Sorgfaltspflichten anwenden.

3 3 3

By 10 July 2026, AMLA shall issue guidelines on the risk variables and risk factors to be taken into account by obliged entities when entering into business relationships or carrying out occasional transactions.

By 10 July 2026, AMLA shall issue guidelines on the risk variables and risk factors to be taken into account by obliged entities when entering into business relationships or carrying out occasional transactions.

Bis zum 10. Juli 2026 erlässt die AMLA Leitlinien zu den Risiko-Variablen und Risikofaktoren, die von verpflichteten Unternehmen beim Eingehen von Geschäftsbeziehungen oder bei der Durchführung gelegentlicher Transaktionen zu berücksichtigen sind.

4 4 4

Obliged entities shall at all times be able to demonstrate to their supervisors that the measures taken are appropriate in view of the risks of money laundering and terrorist financing that have been identified.

Obliged entities shall at all times be able to demonstrate to their supervisors that the measures taken are appropriate in view of the risks of money laundering and terrorist financing that have been identified.

Verpflichtete Unternehmen müssen ihren Aufsichtsbehörden jederzeit nachweisen können, dass die getroffenen Maßnahmen angesichts der festgestellten Risiken von Geldwäsche und Terrorismusfinanzierung angemessen sind.

Article 21 — Inability to comply with the requirement to apply customer due diligence measures Article 21 — Inability to comply with the requirement to apply customer due diligence measures Article 21 — Unfähigkeit zur Erfüllung der Pflicht zur Anwendung von Sorgfaltspflichten gegenüber Kunden
1 1 1

Where an obliged entity is unable to comply with the requirement to apply customer due diligence measures laid down in Article 20(1), it shall refrain from carrying out a transaction or establishing a business relationship, and shall terminate the business relationship and consider reporting a suspicious transaction to the FIU in relation to the customer in accordance with Article 69.The termination of a business relationship pursuant to the first subparagraph of this paragraph shall not prohibit the receipt of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 due to the obliged entity.Where an obliged entity has a duty to protect its customer’s assets, the termination of the business relationship shall not be understood as requiring the disposal of the assets of the customer.In the case of life insurance contracts, obliged entities shall, where necessary as an alternative measure to terminating the business relationship, refrain from performing transactions for the customer, including payouts to beneficiaries, until the customer due diligence measures laid down in Article 20(1) are complied with.

Where an obliged entity is unable to comply with the requirement to apply customer due diligence measures laid down in Article 20(1), it shall refrain from carrying out a transaction or establishing a business relationship, and shall terminate the business relationship and consider reporting a suspicious transaction to the FIU in relation to the customer in accordance with Article 69. The termination of a business relationship pursuant to the first subparagraph of this paragraph shall not prohibit the receipt of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 due to the obliged entity. Where an obliged entity has a duty to protect its customer’s assets, the termination of the business relationship shall not be understood as requiring the disposal of the assets of the customer. In the case of life insurance contracts, obliged entities shall, where necessary as an alternative measure to terminating the business relationship, refrain from performing transactions for the customer, including payouts to beneficiaries, until the customer due diligence measures laid down in Article 20(1) are complied with.

Ist ein verpflichtetes Unternehmen nicht in der Lage, der in Artikel 20 Absatz 1 festgelegten Pflicht zur Anwendung von Sorgfaltspflichten gegenüber Kunden nachzukommen, so sieht es von der Durchführung einer Transaktion oder der Begründung einer Geschäftsbeziehung ab, beendet die Geschäftsbeziehung und erwägt, im Zusammenhang mit dem Kunden gemäß Artikel 69 eine verdächtige Transaktion an die zentrale Meldestelle zu melden. Die Beendigung einer Geschäftsbeziehung gemäß dem ersten Unterabsatz dieses Absatzes hindert das verpflichtete Unternehmen nicht am Eingang von Geldbeträgen im Sinne des Artikels 4 Nummer 25 der Richtlinie (EU) 2015/2366. Hat ein verpflichtetes Unternehmen die Pflicht, die Vermögenswerte seines Kunden zu schützen, so ist die Beendigung der Geschäftsbeziehung nicht dahingehend auszulegen, dass sie die Veräußerung der Vermögenswerte des Kunden erfordert. Bei Lebensversicherungsverträgen sehen verpflichtete Unternehmen, soweit erforderlich als alternative Maßnahme zur Beendigung der Geschäftsbeziehung, von der Durchführung von Transaktionen für den Kunden, einschließlich Auszahlungen an Begünstigte, ab, bis die in Artikel 20 Absatz 1 festgelegten Sorgfaltspflichten gegenüber Kunden erfüllt sind.

2 2 2

Paragraph 1 shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors, to the extent that those persons ascertain the legal position of their client, or perform the task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings.

The first subparagraph shall not apply when the obliged entities referred to therein:

  • (a) take part in money laundering, its predicate offences or terrorist financing;
  • (b) provide legal advice for the purposes of money laundering, its predicate offences or terrorist financing; or
  • (c) know that the client is seeking legal advice for the purposes of money laundering, its predicate offences or terrorist financing; knowledge or purpose may be inferred from objective factual circumstances.

Paragraph 1 shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors, to the extent that those persons ascertain the legal position of their client, or perform the task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings.

The first subparagraph shall not apply when the obliged entities referred to therein:

  • (a) take part in money laundering, its predicate offences or terrorist financing;
  • (b) provide legal advice for the purposes of money laundering, its predicate offences or terrorist financing; or
  • (c) know that the client is seeking legal advice for the purposes of money laundering, its predicate offences or terrorist financing; knowledge or purpose may be inferred from objective factual circumstances.

Absatz 1 gilt nicht für Notare, Rechtsanwälte, andere unabhängige Angehörige der rechtsberatenden Berufe, Wirtschaftsprüfer, externe Buchhalter und Steuerberater, soweit diese Personen die Rechtsstellung ihres Mandanten feststellen oder die Aufgabe wahrnehmen, diesen Mandanten in Gerichtsverfahren oder im Zusammenhang mit Gerichtsverfahren zu verteidigen oder zu vertreten, einschließlich der Beratung über die Einleitung oder Vermeidung solcher Verfahren.

Der erste Unterabsatz gilt nicht, wenn die darin genannten verpflichteten Unternehmen:

  • a) an Geldwäsche, deren Vortaten oder Terrorismusfinanzierung beteiligt sind;
  • b) Rechtsberatung zum Zweck der Geldwäsche, ihrer Vortaten oder der Terrorismusfinanzierung leisten; oder
  • c) wissen, dass der Mandant Rechtsberatung zum Zweck der Geldwäsche, ihrer Vortaten oder der Terrorismusfinanzierung sucht; aus objektiven tatsächlichen Umständen kann auf die Kenntnis oder den Zweck geschlossen werden.
3 3 3

Obliged entities shall keep record of the actions taken in order to comply with the requirement to apply customer due diligence measures, including records of the decisions taken and the relevant supporting documents and justifications. Documents, data or information held by the obliged entity shall be updated whenever the customer due diligence is reviewed pursuant to Article 26.The obligation to keep records provided for in the first subparagraph of this paragraph shall also apply to situations where obliged entities refuse to enter into a business relationship, terminate a business relationship or apply alternative measures pursuant to paragraph 1.

Obliged entities shall keep record of the actions taken in order to comply with the requirement to apply customer due diligence measures, including records of the decisions taken and the relevant supporting documents and justifications. Documents, data or information held by the obliged entity shall be updated whenever the customer due diligence is reviewed pursuant to Article 26.The obligation to keep records provided for in the first subparagraph of this paragraph shall also apply to situations where obliged entities refuse to enter into a business relationship, terminate a business relationship or apply alternative measures pursuant to paragraph 1.

Verpflichtete müssen Aufzeichnungen über die Maßnahmen führen, die ergriffen wurden, um der Pflicht zur Anwendung von Sorgfaltspflichten gegenüber Kunden nachzukommen, einschließlich Aufzeichnungen über die getroffenen Entscheidungen sowie der einschlägigen Belege und Begründungen. Die von der verpflichteten Stelle aufbewahrten Dokumente, Daten oder Informationen sind zu aktualisieren, sobald die Sorgfaltspflichten gegenüber Kunden gemäß Artikel 26 überprüft werden. Die im ersten Unterabsatz dieses Absatzes vorgesehene Aufzeichnungspflicht gilt auch für Fälle, in denen verpflichtete Stellen den Abschluss einer Geschäftsbeziehung ablehnen, eine Geschäftsbeziehung beenden oder gemäß Absatz 1 alternative Maßnahmen anwenden.

4 4 4

By 10 July 2027, AMLA shall issue joint guidelines with the European Banking Authority on the measures that may be taken by credit institutions and financial institutions to ensure compliance with AML/CFT rules when implementing the requirements of Directive 2014/92/EU, including in relation to business relationships that are most affected by de-risking practices.

By 10 July 2027, AMLA shall issue joint guidelines with the European Banking Authority on the measures that may be taken by credit institutions and financial institutions to ensure compliance with AML/CFT rules when implementing the requirements of Directive 2014/92/EU, including in relation to business relationships that are most affected by de-risking practices.

Bis zum 10. Juli 2027 erlässt die AMLA gemeinsam mit der Europäischen Bankenaufsichtsbehörde Leitlinien zu den Maßnahmen, die Kreditinstitute und Finanzinstitute ergreifen können, um bei der Umsetzung der Anforderungen der Richtlinie 2014/92/EU die Einhaltung der Vorschriften zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung sicherzustellen, auch in Bezug auf Geschäftsbeziehungen, die am stärksten von De-Risking-Praktiken betroffen sind.

Article 22 — Identification and verification of the identity of customers and beneficial owners Article 22 — Identification and verification of the identity of customers and beneficial owners Article 22 — Identifizierung und Überprüfung der Identität von Kunden und wirtschaftlichen Eigentümern
1 1 1

With the exception of cases of lower risk to which measures under Section 3 apply and irrespective of the application of additional measures in cases of higher risk under Section 4 obliged entities shall obtain at least the following information in order to identify the customer, any person purporting to act on behalf of the customer, and the natural persons on whose behalf or for the benefit of whom a transaction or activity is being conducted:

  • (a) for a natural person:

    • (i) all names and surnames;
    • (ii) place and full date of birth;
    • (iii) nationalities, or statelessness and refugee or subsidiary protection status where applicable, and the national identification number, where applicable;
    • (iv) the usual place of residence or, if there is no fixed residential address with legitimate residence in the Union, the postal address at which the natural person can be reached and, where available the tax identification number;
  • (b) for a legal entity:

    • (i) legal form and name of the legal entity;
    • (ii) address of the registered or official office and, if different, the principal place of business, and the country of creation;
    • (iii) the names of the legal representatives of the legal entity as well as, where available, the registration number, the tax identification number and the Legal Entity Identifier;
    • (iv) the names of persons holding shares or a directorship position in nominee form, including reference to their status as nominee shareholders or directors.
  • (c) for a trustee of an express trust or a person holding an equivalent position in a similar legal arrangement:

    • (i) basic information on the legal arrangement; however, with regard to the assets held in the legal arrangement or managed through it, only the assets that are to be managed in the context of the business relationship or occasional transaction shall be identified;
    • (ii) the address of residence of the trustees or persons holding an equivalent position in a similar legal arrangement and, if different, the place from where the express trust or similar legal arrangement is administered, the powers that regulate and bind the legal arrangement, as well as, where available, the tax identification number and the Legal Entity Identifier;
  • (d) for other organisations that have legal capacity under national law:

    • (i) name, address of the registered office or equivalent;
    • (ii) names of the persons empowered to represent the organisation as well as, where applicable, legal form, tax identification number, registration number, Legal Entity Identifier and deeds of association or equivalent.

With the exception of cases of lower risk to which measures under Section 3 apply and irrespective of the application of additional measures in cases of higher risk under Section 4 obliged entities shall obtain at least the following information in order to identify the customer, any person purporting to act on behalf of the customer, and the natural persons on whose behalf or for the benefit of whom a transaction or activity is being conducted:

  • (a) for a natural person:
    • (i) all names and surnames;
    • (ii) place and full date of birth;
    • (iii) nationalities, or statelessness and refugee or subsidiary protection status where applicable, and the national identification number, where applicable;
    • (iv) the usual place of residence or, if there is no fixed residential address with legitimate residence in the Union, the postal address at which the natural person can be reached and, where available the tax identification number;
  • (b) for a legal entity:
    • (i) legal form and name of the legal entity;
    • (ii) address of the registered or official office and, if different, the principal place of business, and the country of creation;
    • (iii) the names of the legal representatives of the legal entity as well as, where available, the registration number, the tax identification number and the Legal Entity Identifier;
    • (iv) the names of persons holding shares or a directorship position in nominee form, including reference to their status as nominee shareholders or directors.
  • (c) for a trustee of an express trust or a person holding an equivalent position in a similar legal arrangement:
    • (i) basic information on the legal arrangement; however, with regard to the assets held in the legal arrangement or managed through it, only the assets that are to be managed in the context of the business relationship or occasional transaction shall be identified;
    • (ii) the address of residence of the trustees or persons holding an equivalent position in a similar legal arrangement and, if different, the place from where the express trust or similar legal arrangement is administered, the powers that regulate and bind the legal arrangement, as well as, where available, the tax identification number and the Legal Entity Identifier;
  • (d) for other organisations that have legal capacity under national law:
    • (i) name, address of the registered office or equivalent;
    • (ii) names of the persons empowered to represent the organisation as well as, where applicable, legal form, tax identification number, registration number, Legal Entity Identifier and deeds of association or equivalent.

Abgesehen von Fällen geringeren Risikos, auf die die Maßnahmen nach Abschnitt 3 Anwendung finden, und unabhängig von der Anwendung zusätzlicher Maßnahmen bei höherem Risiko nach Abschnitt 4 holen verpflichtete Stellen mindestens die folgenden Informationen ein, um den Kunden, jede Person, die vorgibt, im Namen des Kunden zu handeln, sowie die natürlichen Personen, in deren Namen oder zu deren Gunsten ein Geschäft oder eine Tätigkeit durchgeführt wird, zu identifizieren:

  • (a) bei einer natürlichen Person:
    • (i) alle Vor- und Nachnamen;
    • (ii) Geburtsort und vollständiges Geburtsdatum;
    • (iii) Staatsangehörigkeiten oder gegebenenfalls Staatenlosigkeit sowie Flüchtlingsstatus oder Status des subsidiären Schutzes und gegebenenfalls die nationale Identifikationsnummer;
    • (iv) der gewöhnliche Wohnsitz oder, falls keine feste Wohnanschrift bei rechtmäßigem Aufenthalt in der Union besteht, die Postanschrift, unter der die natürliche Person erreichbar ist, sowie, sofern verfügbar, die Steueridentifikationsnummer;
  • (b) bei einer juristischen Person:
    • (i) Rechtsform und Name der juristischen Person;
    • (ii) Anschrift des eingetragenen oder amtlichen Sitzes und, falls abweichend, des Hauptgeschäftssitzes sowie das Gründungsland;
    • (iii) die Namen der gesetzlichen Vertreter der juristischen Person sowie, sofern verfügbar, die Registernummer, die Steueridentifikationsnummer und der Legal Entity Identifier;
    • (iv) die Namen der Personen, die Anteile oder eine Geschäftsführungsposition treuhänderisch halten, einschließlich eines Hinweises auf ihren Status als nominee-Anteilseigner oder nominee-Geschäftsführer;
  • (c) bei einem Treuhänder eines Express Trusts oder einer Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsgestaltung:
    • (i) grundlegende Informationen über die Rechtsgestaltung; hinsichtlich der in der Rechtsgestaltung gehaltenen oder durch sie verwalteten Vermögenswerte sind jedoch nur die Vermögenswerte zu identifizieren, die im Rahmen der Geschäftsbeziehung oder des gelegentlichen Geschäfts verwaltet werden sollen;
    • (ii) die Wohnanschrift der Treuhänder oder Personen mit einer gleichwertigen Stellung in einer ähnlichen Rechtsgestaltung und, falls abweichend, der Ort, von dem aus der Express Trust oder die ähnliche Rechtsgestaltung verwaltet wird, die Befugnisse, die die Rechtsgestaltung regeln und binden, sowie, sofern verfügbar, die Steueridentifikationsnummer und der Legal Entity Identifier;
  • (d) bei sonstigen Organisationen, die nach nationalem Recht rechtsfähig sind:
    • (i) Name und Anschrift des eingetragenen Sitzes oder eines gleichwertigen Sitzes;
    • (ii) die Namen der zur Vertretung der Organisation befugten Personen sowie gegebenenfalls Rechtsform, Steueridentifikationsnummer, Registernummer, Legal Entity Identifier und Gründungsurkunde oder ein gleichwertiges Dokument.
2 2 2

For the purposes of identifying the beneficial owner of a legal entity or of a legal arrangement, obliged entities shall collect the information referred to in Article 62(1), second subparagraph, point (a).Where, after having exhausted all possible means of identification, no natural persons are identified as beneficial owners, or where there are doubts that the persons identified are the beneficial owners, obliged entities shall record that no beneficial owner was identified and identify all the natural persons holding the positions of senior managing officials in the legal entity and shall verify their identity.Where the performance of identity verification referred to in the second subparagraph may tip off the customer that the obliged entity has doubts regarding the beneficial ownership of the legal entity, the obliged entity shall abstain from verifying the senior managing officials’ identity, and shall instead record the steps taken to ascertain the identity of the beneficial owners and senior managing officials. Obliged entities shall keep records of the actions taken as well as of the difficulties encountered during the identification process, which led to resorting to the identification of a senior managing official.

For the purposes of identifying the beneficial owner of a legal entity or of a legal arrangement, obliged entities shall collect the information referred to in Article 62(1), second subparagraph, point (a).Where, after having exhausted all possible means of identification, no natural persons are identified as beneficial owners, or where there are doubts that the persons identified are the beneficial owners, obliged entities shall record that no beneficial owner was identified and identify all the natural persons holding the positions of senior managing officials in the legal entity and shall verify their identity.Where the performance of identity verification referred to in the second subparagraph may tip off the customer that the obliged entity has doubts regarding the beneficial ownership of the legal entity, the obliged entity shall abstain from verifying the senior managing officials’ identity, and shall instead record the steps taken to ascertain the identity of the beneficial owners and senior managing officials. Obliged entities shall keep records of the actions taken as well as of the difficulties encountered during the identification process, which led to resorting to the identification of a senior managing official.

Zur Identifizierung des wirtschaftlichen Eigentümers einer juristischen Person oder einer Rechtsgestaltung holen verpflichtete Stellen die in Artikel 62 Absatz 1 Unterabsatz 2 Buchstabe a genannten Informationen ein. Werden nach Ausschöpfung aller möglichen Identifizierungsmittel keine natürlichen Personen als wirtschaftliche Eigentümer identifiziert oder bestehen Zweifel daran, dass die identifizierten Personen die wirtschaftlichen Eigentümer sind, vermerken verpflichtete Stellen, dass kein wirtschaftlicher Eigentümer identifiziert wurde, identifizieren alle natürlichen Personen, die in der juristischen Person die Positionen der obersten Führungskräfte innehaben, und überprüfen deren Identität. Könnte die in Unterabsatz 2 genannte Identitätsüberprüfung den Kunden darauf aufmerksam machen, dass die verpflichtete Stelle Zweifel an der wirtschaftlichen Eigentümerschaft der juristischen Person hat, sieht die verpflichtete Stelle von der Überprüfung der Identität der obersten Führungskräfte ab und vermerkt stattdessen die zur Feststellung der Identität der wirtschaftlichen Eigentümer und der obersten Führungskräfte unternommenen Schritte. Verpflichtete Stellen führen Aufzeichnungen über die ergriffenen Maßnahmen sowie die während des Identifizierungsverfahrens aufgetretenen Schwierigkeiten, die zur Identifizierung einer obersten Führungskraft geführt haben.

3 3 3

Credit institutions and financial institutions shall obtain information to identify and verify the identity of the natural or legal persons using any virtual IBAN they issue, and the associated bank or payment account.The credit institution or financial institution servicing the bank or payment account to which a virtual IBAN issued by another credit institution or financial institution redirects payments, shall ensure that it can obtain from the institution issuing the virtual IBAN the information identifying and verifying the identity of the natural person using that virtual IBAN without delay and in any case within 5 working days of it requesting that information.

Credit institutions and financial institutions shall obtain information to identify and verify the identity of the natural or legal persons using any virtual IBAN they issue, and the associated bank or payment account.The credit institution or financial institution servicing the bank or payment account to which a virtual IBAN issued by another credit institution or financial institution redirects payments, shall ensure that it can obtain from the institution issuing the virtual IBAN the information identifying and verifying the identity of the natural person using that virtual IBAN without delay and in any case within 5 working days of it requesting that information.

Kreditinstitute und Finanzinstitute holen Informationen ein, um die natürlichen oder juristischen Personen, die eine von ihnen ausgegebene virtuelle IBAN nutzen, sowie das damit verbundene Bank- oder Zahlungskonto zu identifizieren und deren Identität zu überprüfen. Das Kreditinstitut oder Finanzinstitut, das das Bank- oder Zahlungskonto führt, auf das eine von einem anderen Kreditinstitut oder Finanzinstitut ausgegebene virtuelle IBAN Zahlungen weiterleitet, stellt sicher, dass es von dem Institut, das die virtuelle IBAN ausgestellt hat, unverzüglich und in jedem Fall innerhalb von fünf Arbeitstagen nach Anforderung dieser Informationen die Informationen zur Identifizierung und Überprüfung der Identität der natürlichen Person erhalten kann, die diese virtuelle IBAN nutzt.

4 4 4

In the case of beneficiaries of trusts or similar legal entities or arrangements that are designated by particular characteristics or class, an obliged entity shall obtain sufficient information concerning the beneficiary so that it will be able to establish the identity of the beneficiary at the time of the payout or at the time of the exercise by the beneficiary of its vested rights.

In the case of beneficiaries of trusts or similar legal entities or arrangements that are designated by particular characteristics or class, an obliged entity shall obtain sufficient information concerning the beneficiary so that it will be able to establish the identity of the beneficiary at the time of the payout or at the time of the exercise by the beneficiary of its vested rights.

Bei Begünstigten von Trusts oder ähnlichen juristischen Personen oder Rechtsgestaltungen, die durch bestimmte Merkmale oder eine Klasse bezeichnet werden, holt eine verpflichtete Stelle ausreichende Informationen über den Begünstigten ein, damit sie dessen Identität zum Zeitpunkt der Auszahlung oder zum Zeitpunkt der Ausübung seiner erworbenen Rechte durch den Begünstigten feststellen kann.

5 5 5

In the case of discretionary trusts, an obliged entity shall obtain sufficient information concerning the objects of a power and default takers to enable it to establish the identity of the beneficiary at the time of the exercise by the trustees of their power of discretion, or at the time that the default takers become the beneficiaries due to the trustees’ failure to exercise their power of discretion.

In the case of discretionary trusts, an obliged entity shall obtain sufficient information concerning the objects of a power and default takers to enable it to establish the identity of the beneficiary at the time of the exercise by the trustees of their power of discretion, or at the time that the default takers become the beneficiaries due to the trustees’ failure to exercise their power of discretion.

Bei Ermessens-Trusts holt eine verpflichtete Stelle ausreichende Informationen über die Begünstigten eines Ermessens sowie die Ersatzbegünstigten ein, damit sie die Identität des Begünstigten zum Zeitpunkt der Ausübung des Ermessens durch die Treuhänder oder zu dem Zeitpunkt feststellen kann, zu dem die Ersatzbegünstigten aufgrund der Nichtausübung des Ermessens durch die Treuhänder zu Begünstigten werden.

6 6 6

Obliged entities shall obtain the information, documents and data necessary for the verification of the identity of the customer and of any person purporting to act on their behalf through either of the following means:

  • (a) the submission of an identity document, passport or equivalent and, where relevant, the acquisition of information from reliable and independent sources, whether accessed directly or provided by the customer;
  • (b) the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels substantial or high and relevant qualified trust services as set out in that Regulation.

Obliged entities shall obtain the information, documents and data necessary for the verification of the identity of the customer and of any person purporting to act on their behalf through either of the following means:

  • (a) the submission of an identity document, passport or equivalent and, where relevant, the acquisition of information from reliable and independent sources, whether accessed directly or provided by the customer;
  • (b) the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels substantial or high and relevant qualified trust services as set out in that Regulation.

Verpflichtete Stellen holen die zur Überprüfung der Identität des Kunden und jeder Person, die vorgibt, in seinem Namen zu handeln, erforderlichen Informationen, Dokumente und Daten durch eines der folgenden Mittel ein:

  • (a) Vorlage eines Identitätsdokuments, Reisepasses oder gleichwertigen Dokuments und gegebenenfalls Einholung von Informationen aus zuverlässigen und unabhängigen Quellen, unabhängig davon, ob direkt auf diese zugegriffen wird oder sie vom Kunden bereitgestellt werden;
  • (b) Verwendung elektronischer Identifizierungsmittel, die hinsichtlich der Vertrauensniveaus „substanziell“ oder „hoch“ die Anforderungen der Verordnung (EU) Nr. 910/2014 erfüllen, sowie einschlägiger qualifizierter Vertrauensdienste im Sinne dieser Verordnung.
7 7 7

Obliged entities shall verify the identity of the beneficial owner and, where relevant, the persons on whose behalf or for the benefit of whom a transaction or activity is being carried out in either of the following ways:

  • (a) in accordance with paragraph 6;
  • (b) by taking reasonable measures to obtain the necessary information, documents and data from the customer or other reliable sources, including public registers other than the central registers.

Obliged entities shall determine the extent of the information to be consulted, having regard to the risks posed by the occasional transaction or the business relationship and the beneficial owner, including risks relating to the ownership structure.In addition to the means of verification set out in the first subparagraph of this paragraph, obliged entities shall verify the information on the beneficial owners by consulting the central registers.

Obliged entities shall verify the identity of the beneficial owner and, where relevant, the persons on whose behalf or for the benefit of whom a transaction or activity is being carried out in either of the following ways:

  • (a) in accordance with paragraph 6;
  • (b) by taking reasonable measures to obtain the necessary information, documents and data from the customer or other reliable sources, including public registers other than the central registers.

Obliged entities shall determine the extent of the information to be consulted, having regard to the risks posed by the occasional transaction or the business relationship and the beneficial owner, including risks relating to the ownership structure.In addition to the means of verification set out in the first subparagraph of this paragraph, obliged entities shall verify the information on the beneficial owners by consulting the central registers.

Verpflichtete Stellen überprüfen die Identität des wirtschaftlichen Eigentümers und gegebenenfalls der Personen, in deren Namen oder zu deren Gunsten ein Geschäft oder eine Tätigkeit durchgeführt wird, auf eine der folgenden Arten:

  • (a) gemäß Absatz 6;
  • (b) durch Ergreifung angemessener Maßnahmen, um die erforderlichen Informationen, Dokumente und Daten beim Kunden oder aus anderen zuverlässigen Quellen, einschließlich öffentlicher Register außer den Zentralregistern, einzuholen.

Verpflichtete Stellen bestimmen den Umfang der zu konsultierenden Informationen unter Berücksichtigung der Risiken, die von dem gelegentlichen Geschäft oder der Geschäftsbeziehung und dem wirtschaftlichen Eigentümer ausgehen, einschließlich der Risiken im Zusammenhang mit der Eigentümerstruktur. Zusätzlich zu den im ersten Unterabsatz dieses Absatzes genannten Überprüfungsmitteln überprüfen verpflichtete Stellen die Informationen über die wirtschaftlichen Eigentümer durch Konsultation der Zentralregister.

Article 23 — Timing of the verification of the customer and beneficial owner identity Article 23 — Timing of the verification of the customer and beneficial owner identity Article 23 — Zeitpunkt der Überprüfung der Identität des Kunden und des wirtschaftlichen Eigentümers
1 1 1

Verification of the identity of the customer, the beneficial owner, and of any persons pursuant to Article 20(1), points (h) and (i), shall take place before the establishment of a business relationship or the carrying out of an occasional transaction. Such obligation shall not apply to situations of lower risk under Section 3 of this Chapter, provided that the lower risk justifies postponement of such verification.For real estate agents, the verification referred to in the first subparagraph shall be carried out after an offer is accepted by the seller or lessor, and in all cases before any funds or property are transferred.

Verification of the identity of the customer, the beneficial owner, and of any persons pursuant to Article 20(1), points (h) and (i), shall take place before the establishment of a business relationship or the carrying out of an occasional transaction. Such obligation shall not apply to situations of lower risk under Section 3 of this Chapter, provided that the lower risk justifies postponement of such verification.For real estate agents, the verification referred to in the first subparagraph shall be carried out after an offer is accepted by the seller or lessor, and in all cases before any funds or property are transferred.

Die Überprüfung der Identität des Kunden, des wirtschaftlichen Eigentümers und aller Personen gemäß Artikel 20 Absatz 1 Buchstaben h und i erfolgt vor der Begründung einer Geschäftsbeziehung oder der Durchführung eines gelegentlichen Geschäfts. Diese Pflicht gilt nicht für Fälle geringeren Risikos nach Abschnitt 3 dieses Kapitels, sofern das geringere Risiko eine Verschiebung dieser Überprüfung rechtfertigt. Bei Immobilienmaklern erfolgt die im ersten Unterabsatz genannte Überprüfung, nachdem ein Angebot vom Verkäufer oder Vermieter angenommen wurde, und in jedem Fall bevor Gelder oder Vermögenswerte übertragen werden.

2 2 2

By way of derogation from paragraph 1, verification of the identity of the customer and of the beneficial owner may be completed during the establishment of a business relationship if necessary so as not to interrupt the normal conduct of business and where there is little risk of money laundering or terrorist financing. In such situations, those procedures shall be completed as soon as practicable after initial contact.

By way of derogation from paragraph 1, verification of the identity of the customer and of the beneficial owner may be completed during the establishment of a business relationship if necessary so as not to interrupt the normal conduct of business and where there is little risk of money laundering or terrorist financing. In such situations, those procedures shall be completed as soon as practicable after initial contact.

Abweichend von Absatz 1 kann die Überprüfung der Identität des Kunden und des wirtschaftlichen Eigentümers während der Begründung einer Geschäftsbeziehung abgeschlossen werden, wenn dies erforderlich ist, um den normalen Geschäftsablauf nicht zu unterbrechen, und nur ein geringes Risiko der Geldwäsche oder Terrorismusfinanzierung besteht. In diesen Fällen sind die Verfahren so bald wie möglich nach dem ersten Kontakt abzuschließen.

3 3 3

By way of derogation from paragraph 1 of this Article, a credit institution or financial institution may open an account, including accounts that permit transactions in transferable securities, as may be required by a customer provided that there are adequate safeguards in place to ensure that transactions are not carried out by the customer or on its behalf until full compliance with the customer due diligence measures laid down in Article 20(1), points (a) and (b), is obtained.

By way of derogation from paragraph 1 of this Article, a credit institution or financial institution may open an account, including accounts that permit transactions in transferable securities, as may be required by a customer provided that there are adequate safeguards in place to ensure that transactions are not carried out by the customer or on its behalf until full compliance with the customer due diligence measures laid down in Article 20(1), points (a) and (b), is obtained.

Abweichend von Absatz 1 dieses Artikels kann ein Kreditinstitut oder Finanzinstitut ein Konto, einschließlich eines Kontos, das Geschäfte mit übertragbaren Wertpapieren ermöglicht, auf Wunsch eines Kunden eröffnen, sofern angemessene Schutzvorkehrungen bestehen, die sicherstellen, dass keine Geschäfte vom Kunden oder in seinem Namen durchgeführt werden, bis die vollständige Einhaltung der in Artikel 20 Absatz 1 Buchstaben a und b festgelegten Sorgfaltspflichten gegenüber Kunden gewährleistet ist.

4 4 4

Whenever entering into a new business relationship with a legal entity or the trustee of an express trust or the person holding an equivalent position in a similar legal arrangement referred to in Articles 51, 57, 58, 61 and 67 and subject to the registration of beneficial ownership information pursuant to Article 10 of Directive (EU) 2024/1640, obliged entities shall collect valid proof of registration or a recently issued excerpt of the register confirming validity of registration.

Whenever entering into a new business relationship with a legal entity or the trustee of an express trust or the person holding an equivalent position in a similar legal arrangement referred to in Articles 51, 57, 58, 61 and 67 and subject to the registration of beneficial ownership information pursuant to Article 10 of Directive (EU) 2024/1640, obliged entities shall collect valid proof of registration or a recently issued excerpt of the register confirming validity of registration.

Bei jeder Begründung einer neuen Geschäftsbeziehung mit einer juristischen Person, dem Treuhänder eines Express Trusts oder einer Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsgestaltung im Sinne der Artikel 51, 57, 58, 61 und 67, die der Eintragung von Informationen über die wirtschaftlichen Eigentümer gemäß Artikel 10 der Richtlinie (EU) 2024/1640 unterliegt, holen verpflichtete Stellen einen gültigen Eintragungsnachweis oder einen kürzlich ausgestellten Registerauszug ein, der die Gültigkeit der Eintragung bestätigt.

Article 24 — Reporting of discrepancies with information contained in beneficial ownership registers Article 24 — Reporting of discrepancies with information contained in beneficial ownership registers Article 24 — Meldung von Abweichungen von den in Registern der wirtschaftlichen Eigentümer enthaltenen Informationen
1 1 1

Obliged entities shall report to the central registers any discrepancies they find between the information available in the central registers and the information they collect pursuant to Article 20(1), point (b), and Article 22(7).The discrepancies referred to in the first subparagraph shall be reported without undue delay and, in any case, within 14 calendar days of their detection. When reporting such discrepancies, obliged entities shall accompany their reports with information they have obtained indicating the discrepancy and whom they consider to be the beneficial owners and, where applicable, the nominee shareholders and nominee directors to be and why.

Obliged entities shall report to the central registers any discrepancies they find between the information available in the central registers and the information they collect pursuant to Article 20(1), point (b), and Article 22(7).The discrepancies referred to in the first subparagraph shall be reported without undue delay and, in any case, within 14 calendar days of their detection. When reporting such discrepancies, obliged entities shall accompany their reports with information they have obtained indicating the discrepancy and whom they consider to be the beneficial owners and, where applicable, the nominee shareholders and nominee directors to be and why.

Verpflichtete Stellen melden den Zentralregistern jede Abweichung, die sie zwischen den in den Zentralregistern verfügbaren Informationen und den gemäß Artikel 20 Absatz 1 Buchstabe b und Artikel 22 Absatz 7 erhobenen Informationen feststellen. Die im ersten Unterabsatz genannten Abweichungen sind unverzüglich, spätestens jedoch innerhalb von 14 Kalendertagen nach ihrer Feststellung zu melden. Bei der Meldung solcher Abweichungen fügen verpflichtete Stellen Informationen bei, die sie erhalten haben und aus denen die Abweichung hervorgeht, sowie Angaben dazu, wen sie als wirtschaftliche Eigentümer und gegebenenfalls als nominee-Anteilseigner und nominee-Geschäftsführer ansehen und aus welchem Grund.

2 2 2

By way of derogation from paragraph 1, obliged entities may refrain from reporting discrepancies to the central register and may instead request additional information from the customers where the discrepancies identified:

  • (a) are limited to typographical errors, different ways of transliteration, or minor inaccuracies that do not affect the identification of the beneficial owners or their position; or
  • (b) are a result of outdated data, but the beneficial owners are known to the obliged entity from another reliable source and there are no grounds for suspicion that there is an intention to conceal any information.

Where an obliged entity concludes that the beneficial ownership information in the central register is incorrect, it shall invite the customer to submit the correct information to the central register pursuant to Articles 63, 64 and 67 without undue delay, and, in any case, within 14 calendar days.This paragraph shall not apply to cases of higher risk to which measures under Section 4 of this Chapter apply.

By way of derogation from paragraph 1, obliged entities may refrain from reporting discrepancies to the central register and may instead request additional information from the customers where the discrepancies identified:

  • (a) are limited to typographical errors, different ways of transliteration, or minor inaccuracies that do not affect the identification of the beneficial owners or their position; or
  • (b) are a result of outdated data, but the beneficial owners are known to the obliged entity from another reliable source and there are no grounds for suspicion that there is an intention to conceal any information.

Where an obliged entity concludes that the beneficial ownership information in the central register is incorrect, it shall invite the customer to submit the correct information to the central register pursuant to Articles 63, 64 and 67 without undue delay, and, in any case, within 14 calendar days.This paragraph shall not apply to cases of higher risk to which measures under Section 4 of this Chapter apply.

Abweichend von Absatz 1 können verpflichtete Stellen davon absehen, Abweichungen dem Zentralregister zu melden, und stattdessen zusätzliche Informationen von den Kunden anfordern, wenn die festgestellten Abweichungen:

  • (a) auf Schreibfehler, unterschiedliche Transliterationsweisen oder geringfügige Ungenauigkeiten beschränkt sind, die die Identifizierung der wirtschaftlichen Eigentümer oder deren Stellung nicht beeinträchtigen; oder
  • (b) auf veralteten Daten beruhen, die wirtschaftlichen Eigentümer der verpflichteten Stelle jedoch aus einer anderen zuverlässigen Quelle bekannt sind und keine Anhaltspunkte für die Absicht bestehen, Informationen zu verschleiern.

Kommt eine verpflichtete Stelle zu dem Schluss, dass die Informationen über die wirtschaftlichen Eigentümer im Zentralregister unrichtig sind, fordert sie den Kunden auf, die richtigen Informationen gemäß den Artikeln 63, 64 und 67 unverzüglich, spätestens jedoch innerhalb von 14 Kalendertagen, an das Zentralregister zu übermitteln. Dieser Absatz gilt nicht für Fälle höheren Risikos, auf die die Maßnahmen nach Abschnitt 4 dieses Kapitels Anwendung finden.

3 3 3

Where a customer has not submitted the correct information within the deadline referred to in paragraph 2, second subparagraph, the obliged entity shall report the discrepancy to the central register in accordance with paragraph 1, second subparagraph.

Where a customer has not submitted the correct information within the deadline referred to in paragraph 2, second subparagraph, the obliged entity shall report the discrepancy to the central register in accordance with paragraph 1, second subparagraph.

Hat ein Kunde die richtigen Informationen nicht innerhalb der in Absatz 2 Unterabsatz 2 genannten Frist übermittelt, meldet die verpflichtete Stelle die Abweichung dem Zentralregister gemäß Absatz 1 Unterabsatz 2.

4 4 4

This Article shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors in relation to information they receive from, or obtain on, a client, in the course of ascertaining the legal position of that client, or performing their task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, regardless of whether such information is received or obtained before, during or after such proceedings.However, the requirements of this Article shall apply when the obliged entities referred to in the first subparagraph of this paragraph provide legal advice in any of the situations covered by Article 21(2), second subparagraph.

This Article shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors in relation to information they receive from, or obtain on, a client, in the course of ascertaining the legal position of that client, or performing their task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, regardless of whether such information is received or obtained before, during or after such proceedings.However, the requirements of this Article shall apply when the obliged entities referred to in the first subparagraph of this paragraph provide legal advice in any of the situations covered by Article 21(2), second subparagraph.

Dieser Artikel gilt nicht für Notare, Rechtsanwälte, andere unabhängige Angehörige der Rechtsberufe, Wirtschaftsprüfer, externe Buchhalter und Steuerberater in Bezug auf Informationen, die sie von einem Mandanten erhalten oder über einen Mandanten erlangen, während sie dessen Rechtslage feststellen oder ihre Aufgabe wahrnehmen, diesen Mandanten in Gerichtsverfahren oder im Zusammenhang mit solchen Verfahren zu verteidigen oder zu vertreten, einschließlich der Beratung über die Einleitung oder Vermeidung solcher Verfahren, unabhängig davon, ob die Informationen vor, während oder nach diesen Verfahren erhalten oder erlangt werden. Die Anforderungen dieses Artikels gelten jedoch, wenn die im ersten Unterabsatz dieses Absatzes genannten verpflichteten Stellen in einer der von Artikel 21 Absatz 2 Unterabsatz 2 erfassten Situationen Rechtsberatung leisten.

Article 25 — Identification of the purpose and intended nature of a business relationship or occasional transaction Article 25 — Identification of the purpose and intended nature of a business relationship or occasional transaction Article 25 — Feststellung des Zwecks und der angestrebten Art einer Geschäftsbeziehung oder eines gelegentlichen Geschäfts

Before entering into a business relationship or performing an occasional transaction, an obliged entity shall assure itself that it understands its purpose and intended nature. To that end, the obliged entity shall obtain, where necessary, information on:

  • (a) the purpose and economic rationale of the occasional transaction or business relationship;
  • (b) the estimated amount of the envisaged activities;
  • (c) the source of funds;
  • (d) the destination of funds;
  • (e) the business activity or the occupation of the customer.

For the purposes of the first paragraph, point (a), of this Article, obliged entities covered by Article 74 shall collect information in order to determine whether the intended use of high value goods referred to in that Article is for commercial or non-commercial purposes.

Before entering into a business relationship or performing an occasional transaction, an obliged entity shall assure itself that it understands its purpose and intended nature. To that end, the obliged entity shall obtain, where necessary, information on:

  • (a) the purpose and economic rationale of the occasional transaction or business relationship;
  • (b) the estimated amount of the envisaged activities;
  • (c) the source of funds;
  • (d) the destination of funds;
  • (e) the business activity or the occupation of the customer.

For the purposes of the first paragraph, point (a), of this Article, obliged entities covered by Article 74 shall collect information in order to determine whether the intended use of high value goods referred to in that Article is for commercial or non-commercial purposes.

Vor der Begründung einer Geschäftsbeziehung oder der Durchführung eines gelegentlichen Geschäfts vergewissert sich eine verpflichtete Stelle, dass sie dessen Zweck und angestrebte Art versteht. Zu diesem Zweck holt die verpflichtete Stelle erforderlichenfalls Informationen ein über:

  • (a) den Zweck und die wirtschaftliche Begründung des gelegentlichen Geschäfts oder der Geschäftsbeziehung;
  • (b) den geschätzten Betrag der geplanten Tätigkeiten;
  • (c) die Herkunft der Gelder;
  • (d) die Bestimmung der Gelder;
  • (e) die Geschäftstätigkeit oder den Beruf des Kunden.

Für die Zwecke des Absatzes 1 Buchstabe a dieses Artikels erheben die von Artikel 74 erfassten verpflichteten Stellen Informationen, um festzustellen, ob die beabsichtigte Verwendung der in jenem Artikel genannten hochwertigen Güter kommerziellen oder nichtkommerziellen Zwecken dient.

Article 26 — Ongoing monitoring of the business relationship and monitoring of transactions performed by customers Article 26 — Ongoing monitoring of the business relationship and monitoring of transactions performed by customers Article 26 — Laufende Überwachung der Geschäftsbeziehung und Überwachung der von Kunden durchgeführten Transaktionen
1 1 1

Obliged entities shall conduct ongoing monitoring of business relationships, including transactions undertaken by the customer throughout the course of a business relationship, to ensure that those transactions are consistent with the obliged entity’s knowledge of the customer, the customer’s business activity and risk profile, and where necessary, with the information about the origin and destination of the funds and to detect those transactions that shall be made subject to a more thorough assessment pursuant to Article 69(2).Where business relationships cover more than one product or service, obliged entities shall ensure that the customer due diligence measures cover all those products and services.Where obliged entities belonging to a group have business relationships with customers that are also the customers of other entities within that group, whether obliged entities or undertakings not subject to AML/CFT requirements, they shall take into account information relating to those other business relationships for the purposes of monitoring the business relationship with their customers.

Obliged entities shall conduct ongoing monitoring of business relationships, including transactions undertaken by the customer throughout the course of a business relationship, to ensure that those transactions are consistent with the obliged entity’s knowledge of the customer, the customer’s business activity and risk profile, and where necessary, with the information about the origin and destination of the funds and to detect those transactions that shall be made subject to a more thorough assessment pursuant to Article 69(2).Where business relationships cover more than one product or service, obliged entities shall ensure that the customer due diligence measures cover all those products and services.Where obliged entities belonging to a group have business relationships with customers that are also the customers of other entities within that group, whether obliged entities or undertakings not subject to AML/CFT requirements, they shall take into account information relating to those other business relationships for the purposes of monitoring the business relationship with their customers.

Verpflichtete Stellen überwachen Geschäftsbeziehungen laufend, einschließlich der vom Kunden im Verlauf einer Geschäftsbeziehung vorgenommenen Transaktionen, um sicherzustellen, dass diese Transaktionen mit den Kenntnissen der verpflichteten Stelle über den Kunden, dessen Geschäftstätigkeit und Risikoprofil sowie erforderlichenfalls mit den Informationen über Herkunft und Bestimmung der Gelder übereinstimmen, und um diejenigen Transaktionen zu erkennen, die gemäß Artikel 69 Absatz 2 einer eingehenderen Bewertung zu unterziehen sind. Erstrecken sich Geschäftsbeziehungen auf mehr als ein Produkt oder eine Dienstleistung, stellen verpflichtete Stellen sicher, dass die Sorgfaltspflichten gegenüber Kunden alle diese Produkte und Dienstleistungen abdecken. Unterhalten zu einer Gruppe gehörende verpflichtete Stellen Geschäftsbeziehungen mit Kunden, die zugleich Kunden anderer Unternehmen derselben Gruppe sind, unabhängig davon, ob es sich um verpflichtete Stellen oder nicht den Anforderungen zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung unterliegende Unternehmen handelt, berücksichtigen sie zur Überwachung der Geschäftsbeziehung mit ihren Kunden Informationen über diese anderen Geschäftsbeziehungen.

2 2 2

In the context of the ongoing monitoring referred to in paragraph 1, obliged entities shall ensure that the relevant documents, data or information of the customer are kept up to date.

The period between updates of customer information pursuant to the first subparagraph shall be dependent on the risk posed by the business relationship and shall not in any case exceed:

  • (a) for higher risk customers to which measures under Section 4 of this Chapter apply, 1 year;
  • (b) for all other customers, 5 years.

In the context of the ongoing monitoring referred to in paragraph 1, obliged entities shall ensure that the relevant documents, data or information of the customer are kept up to date.

The period between updates of customer information pursuant to the first subparagraph shall be dependent on the risk posed by the business relationship and shall not in any case exceed:

  • (a) for higher risk customers to which measures under Section 4 of this Chapter apply, 1 year;
  • (b) for all other customers, 5 years.

Im Rahmen der in Absatz 1 genannten laufenden Überwachung stellen verpflichtete Stellen sicher, dass die einschlägigen Dokumente, Daten oder Informationen des Kunden auf dem neuesten Stand gehalten werden.

Der Zeitraum zwischen Aktualisierungen der Kundeninformationen gemäß dem ersten Unterabsatz hängt vom Risiko der Geschäftsbeziehung ab und darf keinesfalls überschreiten:

  • (a) bei Kunden mit höherem Risiko, auf die die Maßnahmen nach Abschnitt 4 dieses Kapitels Anwendung finden, ein Jahr;
  • (b) bei allen anderen Kunden fünf Jahre.
3 3 3

In addition to the requirements set out in paragraph 2, obliged entities shall review and, where relevant, update the customer information where:

  • (a) there is a change in the relevant circumstances of a customer;
  • (b) the obliged entity has a legal obligation in the course of the relevant calendar year to contact the customer for the purpose of reviewing any relevant information relating to the beneficial owners or to comply with Council Directive 2011/16/EU

Council Directive 2011/16/EU of 15 February 2011 on administrative cooperation in the field of taxation and repealing Directive 77/799/EEC (OJ L 64, 11.3.2011, p. 1).

;
- (c) they become aware of a relevant fact which pertains to the customer.

In addition to the requirements set out in paragraph 2, obliged entities shall review and, where relevant, update the customer information where:

  • (a) there is a change in the relevant circumstances of a customer;
  • (b) the obliged entity has a legal obligation in the course of the relevant calendar year to contact the customer for the purpose of reviewing any relevant information relating to the beneficial owners or to comply with Council Directive 2011/16/EU

Council Directive 2011/16/EU of 15 February 2011 on administrative cooperation in the field of taxation and repealing Directive 77/799/EEC (OJ L 64, 11.3.2011, p. 1).

;
- (c) they become aware of a relevant fact which pertains to the customer.

Zusätzlich zu den in Absatz 2 festgelegten Anforderungen überprüfen und aktualisieren verpflichtete Stellen gegebenenfalls die Kundeninformationen, wenn:

  • (a) sich die maßgeblichen Umstände eines Kunden ändern;
  • (b) die verpflichtete Stelle im Laufe des betreffenden Kalenderjahres gesetzlich verpflichtet ist, den Kunden zu kontaktieren, um einschlägige Informationen über die wirtschaftlichen Eigentümer zu überprüfen oder der Richtlinie 2011/16/EU des Rates nachzukommen.

Richtlinie 2011/16/EU des Rates vom 15. Februar 2011 über die Zusammenarbeit der Verwaltungsbehörden im Bereich der Besteuerung und zur Aufhebung der Richtlinie 77/799/EWG (ABl. L 64 vom 11.3.2011, S. 1).

;
- (c) sie von einer maßgeblichen Tatsache Kenntnis erlangen, die den Kunden betrifft.

4 4 4

In addition to the ongoing monitoring referred to in paragraph 1 of this Article, obliged entities shall regularly verify whether the conditions laid down in Article 20(1), point (d), are met. The frequency of that verification shall be commensurate with the exposure of the obliged entity and the business relationship to risks of non-implementation and evasion of targeted financial sanctions.For credit institutions and financial institutions, the verification referred to in the first subparagraph shall also be carried out upon any new designation in relation to targeted financial sanctions.The requirements of this paragraph shall not replace the obligation to apply targeted financial sanctions or stricter requirements under other Union legal acts or under national law on the verification of the client base against lists of targeted financial sanctions.

In addition to the ongoing monitoring referred to in paragraph 1 of this Article, obliged entities shall regularly verify whether the conditions laid down in Article 20(1), point (d), are met. The frequency of that verification shall be commensurate with the exposure of the obliged entity and the business relationship to risks of non-implementation and evasion of targeted financial sanctions.For credit institutions and financial institutions, the verification referred to in the first subparagraph shall also be carried out upon any new designation in relation to targeted financial sanctions.The requirements of this paragraph shall not replace the obligation to apply targeted financial sanctions or stricter requirements under other Union legal acts or under national law on the verification of the client base against lists of targeted financial sanctions.

Zusätzlich zu der in Absatz 1 dieses Artikels genannten laufenden Überwachung überprüfen verpflichtete Stellen regelmäßig, ob die in Artikel 20 Absatz 1 Buchstabe d festgelegten Voraussetzungen erfüllt sind. Die Häufigkeit dieser Überprüfung muss dem Ausmaß entsprechen, in dem die verpflichtete Stelle und die Geschäftsbeziehung dem Risiko der Nichtumsetzung und Umgehung gezielter finanzieller Sanktionen ausgesetzt sind. Bei Kreditinstituten und Finanzinstituten wird die im ersten Unterabsatz genannte Überprüfung außerdem bei jeder neuen Benennung im Zusammenhang mit gezielten finanziellen Sanktionen durchgeführt. Die Anforderungen dieses Absatzes ersetzen nicht die Pflicht zur Anwendung gezielter finanzieller Sanktionen oder strengerer Anforderungen nach anderen Rechtsakten der Union oder nach nationalem Recht zur Überprüfung des Kundenbestands anhand von Listen gezielter finanzieller Sanktionen.

5 5 5

By 10 July 2026, AMLA shall issue guidelines on ongoing monitoring of a business relationship and on the monitoring of the transactions carried out in the context of such relationship.

By 10 July 2026, AMLA shall issue guidelines on ongoing monitoring of a business relationship and on the monitoring of the transactions carried out in the context of such relationship.

Bis zum 10. Juli 2026 erlässt die AMLA Leitlinien zur laufenden Überwachung einer Geschäftsbeziehung und zur Überwachung der im Rahmen einer solchen Geschäftsbeziehung durchgeführten Transaktionen.

Article 27 — Temporary measures for customers subject to UN financial sanctions Article 27 — Temporary measures for customers subject to UN financial sanctions Article 27 — Vorläufige Maßnahmen für Kunden, die Finanzsanktionen der Vereinten Nationen unterliegen
1 1 1

In respect of customers that are subject to UN financial sanctions or that are controlled by natural or legal persons or entities subject to UN financial sanctions, or in which natural or legal persons or entities that are subject to UN financial sanctions have more than 50 % of the proprietary rights or majority interest, whether individually or collectively, obliged entities shall keep records of:

  • (a) the funds or other assets that they manage for the customer at the time when UN financial sanctions are made public;
  • (b) the transactions attempted by the customer;
  • (c) the transactions carried out for the customer.

In respect of customers that are subject to UN financial sanctions or that are controlled by natural or legal persons or entities subject to UN financial sanctions, or in which natural or legal persons or entities that are subject to UN financial sanctions have more than 50 % of the proprietary rights or majority interest, whether individually or collectively, obliged entities shall keep records of:

  • (a) the funds or other assets that they manage for the customer at the time when UN financial sanctions are made public;
  • (b) the transactions attempted by the customer;
  • (c) the transactions carried out for the customer.

In Bezug auf Kunden, die Finanzsanktionen der Vereinten Nationen unterliegen, von natürlichen oder juristischen Personen oder Organisationen kontrolliert werden, die solchen Sanktionen unterliegen, oder bei denen solche natürlichen oder juristischen Personen oder Organisationen einzeln oder gemeinsam mehr als 50 % der Eigentumsrechte oder eine Mehrheitsbeteiligung halten, führen verpflichtete Stellen Aufzeichnungen über:

  • (a) die Gelder oder sonstigen Vermögenswerte, die sie für den Kunden zu dem Zeitpunkt verwalten, zu dem die Finanzsanktionen der Vereinten Nationen öffentlich bekannt gemacht werden;
  • (b) die vom Kunden versuchten Transaktionen;
  • (c) die für den Kunden durchgeführten Transaktionen.
2 2 2

Obliged entities shall apply this Article between the time that UN financial sanctions are made public and the time of application of the relevant targeted financial sanctions in the Union.

Obliged entities shall apply this Article between the time that UN financial sanctions are made public and the time of application of the relevant targeted financial sanctions in the Union.

Verpflichtete Stellen wenden diesen Artikel zwischen dem Zeitpunkt der öffentlichen Bekanntmachung der Finanzsanktionen der Vereinten Nationen und dem Zeitpunkt der Anwendung der einschlägigen gezielten finanziellen Sanktionen in der Union an.

Article 28 — Regulatory technical standards on the information necessary for the performance of customer due diligence Article 28 — Regulatory technical standards on the information necessary for the performance of customer due diligence Article 28 — Technische Regulierungsstandards für die zur Erfüllung der Sorgfaltspflichten gegenüber Kunden erforderlichen Informationen
1 1 1

By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify:

  • (a) the requirements that apply to obliged entities pursuant to Article 20 and the information to be collected for the purpose of performing standard, simplified and enhanced due diligence pursuant to Articles 22 and 25 and Articles 33(1) and 34(4), including minimum requirements in situations of lower risk;
  • (b) the type of simplified due diligence measures which obliged entities may apply in situations of lower risk pursuant to Article 33(1) of this Regulation, including measures applicable to specific categories of obliged entities and products or services, having regard to the results of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640;
  • (c) the risk factors associated with features of electronic money instruments that should be taken into account by supervisors when determining the extent of the exemption under Article 19(7);
  • (d) the reliable and independent sources of information that may be used to verify the identification data of natural or legal persons for the purposes of Article 22(6) and (7);
  • (e) the list of attributes which electronic identification means and relevant qualified trust services referred to in Article 22(6), point (b), must feature in order to fulfil the requirements of Article 20(1), points (a) and (b), in the case of standard, simplified and enhanced due diligence.

By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify:

  • (a) the requirements that apply to obliged entities pursuant to Article 20 and the information to be collected for the purpose of performing standard, simplified and enhanced due diligence pursuant to Articles 22 and 25 and Articles 33(1) and 34(4), including minimum requirements in situations of lower risk;
  • (b) the type of simplified due diligence measures which obliged entities may apply in situations of lower risk pursuant to Article 33(1) of this Regulation, including measures applicable to specific categories of obliged entities and products or services, having regard to the results of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640;
  • (c) the risk factors associated with features of electronic money instruments that should be taken into account by supervisors when determining the extent of the exemption under Article 19(7);
  • (d) the reliable and independent sources of information that may be used to verify the identification data of natural or legal persons for the purposes of Article 22(6) and (7);
  • (e) the list of attributes which electronic identification means and relevant qualified trust services referred to in Article 22(6), point (b), must feature in order to fulfil the requirements of Article 20(1), points (a) and (b), in the case of standard, simplified and enhanced due diligence.

Bis zum 10. Juli 2026 entwickelt die AMLA Entwürfe technischer Regulierungsstandards und legt sie der Kommission zur Annahme vor. Diese Entwürfe technischer Regulierungsstandards legen Folgendes fest:

  • (a) die Anforderungen, die gemäß Artikel 20 für verpflichtete Stellen gelten, sowie die Informationen, die für die Durchführung der standardmäßigen, vereinfachten und verstärkten Sorgfaltspflichten gemäß den Artikeln 22 und 25 sowie Artikel 33 Absatz 1 und Artikel 34 Absatz 4 zu erheben sind, einschließlich der Mindestanforderungen in Fällen geringeren Risikos;
  • (b) die Arten vereinfachter Sorgfaltspflichten, die verpflichtete Stellen in Fällen geringeren Risikos gemäß Artikel 33 Absatz 1 dieser Verordnung anwenden dürfen, einschließlich der für bestimmte Kategorien verpflichteter Stellen sowie bestimmte Produkte oder Dienstleistungen geltenden Maßnahmen, unter Berücksichtigung der Ergebnisse der von der Kommission gemäß Artikel 7 der Richtlinie (EU) 2024/1640 auf Unionsebene durchgeführten Risikobewertung;
  • (c) die mit den Merkmalen von E-Geld-Instrumenten verbundenen Risikofaktoren, die die Aufsichtsbehörden bei der Bestimmung des Umfangs der Ausnahme nach Artikel 19 Absatz 7 berücksichtigen müssen;
  • (d) die zuverlässigen und unabhängigen Informationsquellen, die zur Überprüfung der Identifizierungsdaten natürlicher oder juristischer Personen für die Zwecke des Artikels 22 Absatz 6 und Absatz 7 verwendet werden dürfen;
  • (e) die Liste der Merkmale, die elektronische Identifizierungsmittel und einschlägige qualifizierte Vertrauensdienste im Sinne des Artikels 22 Absatz 6 Buchstabe b aufweisen müssen, um bei standardmäßigen, vereinfachten und verstärkten Sorgfaltspflichten die Anforderungen des Artikels 20 Absatz 1 Buchstaben a und b zu erfüllen.
2 2 2

The requirements and measures referred to in paragraph 1, points (a) and (b), shall be based on the following criteria:

  • (a) the inherent risk involved in the service provided;
  • (b) the risks associated with categories of customers;
  • (c) the nature, amount and recurrence of the transaction;
  • (d) the channels used for conducting the business relationship or the occasional transaction.

The requirements and measures referred to in paragraph 1, points (a) and (b), shall be based on the following criteria:

  • (a) the inherent risk involved in the service provided;
  • (b) the risks associated with categories of customers;
  • (c) the nature, amount and recurrence of the transaction;
  • (d) the channels used for conducting the business relationship or the occasional transaction.

Die in Absatz 1 Buchstaben a und b genannten Anforderungen und Maßnahmen beruhen auf folgenden Kriterien:

  • (a) dem dem erbrachten Dienst innewohnenden Risiko;
  • (b) den mit Kundenkategorien verbundenen Risiken;
  • (c) der Art, dem Umfang und der Häufigkeit der Transaktion;
  • (d) den Kanälen, die für die Durchführung der Geschäftsbeziehung oder des gelegentlichen Geschäfts genutzt werden.
3 3 3

AMLA shall review regularly the regulatory technical standards and, if necessary, prepare and submit to the Commission the draft for updating those standards in order, inter alia, to take account of innovation and technological developments.

AMLA shall review regularly the regulatory technical standards and, if necessary, prepare and submit to the Commission the draft for updating those standards in order, inter alia, to take account of innovation and technological developments.

Die AMLA überprüft die technischen Regulierungsstandards regelmäßig und erstellt und übermittelt der Kommission erforderlichenfalls einen Entwurf zur Aktualisierung dieser Standards, um unter anderem Innovationen und technologische Entwicklungen zu berücksichtigen.

4 4 4

Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraphs 1 and 3 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraphs 1 and 3 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Der Kommission wird die Befugnis übertragen, diese Verordnung durch die Annahme der in den Absätzen 1 und 3 dieses Artikels genannten technischen Regulierungsstandards gemäß den Artikeln 49 bis 52 der Verordnung (EU) 2024/1620 zu ergänzen.

SECTION 2 — Third-country policy and money laundering and terrorist financing threats from outside the Union SECTION 2 — Third-country policy and money laundering and terrorist financing threats from outside the Union SECTION 2 — Politik gegenüber Drittländern und von außerhalb der Union ausgehende Bedrohungen durch Geldwäsche und Terrorismusfinanzierung
Article 29 — Identification of third countries with significant strategic deficiencies in their national AML/CFT regimes Article 29 — Identification of third countries with significant strategic deficiencies in their national AML/CFT regimes Article 29 — Identifizierung von Drittländern mit erheblichen strategischen Mängeln in ihren nationalen Regelungen zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung
1 1 1

Third countries with significant strategic deficiencies in their national AML/CFT regimes shall be identified by the Commission and designated as high-risk third countries.

Third countries with significant strategic deficiencies in their national AML/CFT regimes shall be identified by the Commission and designated as high-risk third countries.

Drittländer mit erheblichen strategischen Mängeln in ihren nationalen Regelungen zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung werden von der Kommission identifiziert und als Hochrisiko-Drittländer eingestuft.

2 2 2

In order to identify third countries as referred to in paragraph 1 of this Article, the Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation, where:

  • (a) significant strategic deficiencies in the legal and institutional AML/CFT framework of the third country have been identified;
  • (b) significant strategic deficiencies in the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks or in its system to assess and mitigate risks of non-implementation or evasion of UN financial sanctions relating to proliferation financing have been identified;
  • (c) the significant strategic deficiencies identified under points (a) and (b) are of a persistent nature and no measures to mitigate them have been taken or are being taken.

Those delegated acts shall be adopted within 20 calendar days of the Commission ascertaining that the criteria in point (a), (b) or (c) of the first subparagraph are met.

In order to identify third countries as referred to in paragraph 1 of this Article, the Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation, where:

  • (a) significant strategic deficiencies in the legal and institutional AML/CFT framework of the third country have been identified;
  • (b) significant strategic deficiencies in the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks or in its system to assess and mitigate risks of non-implementation or evasion of UN financial sanctions relating to proliferation financing have been identified;
  • (c) the significant strategic deficiencies identified under points (a) and (b) are of a persistent nature and no measures to mitigate them have been taken or are being taken.

Those delegated acts shall be adopted within 20 calendar days of the Commission ascertaining that the criteria in point (a), (b) or (c) of the first subparagraph are met.

Um die in Absatz 1 dieses Artikels genannten Drittländer zu identifizieren, wird der Kommission die Befugnis übertragen, gemäß Artikel 85 delegierte Rechtsakte zur Ergänzung dieser Verordnung zu erlassen, wenn:

  • (a) erhebliche strategische Mängel im rechtlichen und institutionellen Rahmen des Drittlands zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung festgestellt wurden;
  • (b) erhebliche strategische Mängel bei der Wirksamkeit des Systems des Drittlands zur Bekämpfung der Risiken von Geldwäsche und Terrorismusfinanzierung oder seines Systems zur Bewertung und Eindämmung der Risiken der Nichtumsetzung oder Umgehung von Finanzsanktionen der Vereinten Nationen im Zusammenhang mit der Finanzierung der Proliferation festgestellt wurden;
  • (c) die unter den Buchstaben a und b festgestellten erheblichen strategischen Mängel dauerhaft bestehen und keine Maßnahmen zu ihrer Eindämmung ergriffen wurden oder ergriffen werden.

Diese delegierten Rechtsakte werden innerhalb von 20 Kalendertagen erlassen, nachdem die Kommission festgestellt hat, dass die Kriterien des ersten Unterabsatzes Buchstabe a, b oder c erfüllt sind.

3 3 3

For the purposes of paragraph 2, the Commission shall take into account calls for the application of enhanced due diligence measures and additional mitigating measures (countermeasures) by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing, as well as relevant evaluations, assessments, reports or public statements drawn up by them.

For the purposes of paragraph 2, the Commission shall take into account calls for the application of enhanced due diligence measures and additional mitigating measures (countermeasures) by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing, as well as relevant evaluations, assessments, reports or public statements drawn up by them.

Für die Zwecke des Absatzes 2 berücksichtigt die Kommission Aufforderungen internationaler Organisationen und Standardsetzungsgremien mit Zuständigkeit im Bereich der Verhinderung von Geldwäsche und der Bekämpfung der Terrorismusfinanzierung zur Anwendung verstärkter Sorgfaltspflichten und zusätzlicher Eindämmungsmaßnahmen (Gegenmaßnahmen) sowie die von ihnen erstellten einschlägigen Bewertungen, Beurteilungen, Berichte oder öffentlichen Erklärungen.

4 4 4

Where a third country is identified in accordance with the criteria referred to in paragraph 2, obliged entities shall apply enhanced due diligence measures listed in Article 34(4) with respect to the business relationships or occasional transactions involving natural or legal persons from that third country.

Where a third country is identified in accordance with the criteria referred to in paragraph 2, obliged entities shall apply enhanced due diligence measures listed in Article 34(4) with respect to the business relationships or occasional transactions involving natural or legal persons from that third country.

Wird ein Drittland gemäß den in Absatz 2 genannten Kriterien identifiziert, wenden verpflichtete Stellen hinsichtlich der Geschäftsbeziehungen oder gelegentlichen Geschäfte mit natürlichen oder juristischen Personen aus diesem Drittland die in Artikel 34 Absatz 4 aufgeführten verstärkten Sorgfaltspflichten an.

5 5 5

The delegated act referred to in paragraph 2 shall identify among the countermeasures listed in Article 35 the specific countermeasures mitigating specific risks stemming from each high-risk third country.

The delegated act referred to in paragraph 2 shall identify among the countermeasures listed in Article 35 the specific countermeasures mitigating specific risks stemming from each high-risk third country.

Der in Absatz 2 genannte delegierte Rechtsakt bestimmt unter den in Artikel 35 aufgeführten Gegenmaßnahmen die spezifischen Gegenmaßnahmen zur Eindämmung der spezifischen Risiken, die von jedem Hochrisiko-Drittland ausgehen.

6 6 6

Where a Member State identifies a specific money laundering or terrorist financing risk posed by a third country that the Commission has identified in accordance with the criteria referred to in paragraph 2 which is not addressed by the countermeasures referred to in paragraph 5, it may require obliged entities established in its territory to apply specific additional countermeasures to mitigate the specific risks stemming from that third country. The risk identified and the corresponding countermeasures shall be notified to the Commission within 5 days of the countermeasures being applied.

Where a Member State identifies a specific money laundering or terrorist financing risk posed by a third country that the Commission has identified in accordance with the criteria referred to in paragraph 2 which is not addressed by the countermeasures referred to in paragraph 5, it may require obliged entities established in its territory to apply specific additional countermeasures to mitigate the specific risks stemming from that third country. The risk identified and the corresponding countermeasures shall be notified to the Commission within 5 days of the countermeasures being applied.

Stellt ein Mitgliedstaat ein spezifisches Geldwäsche- oder Terrorismusfinanzierungsrisiko fest, das von einem Drittland ausgeht, das die Kommission gemäß den in Absatz 2 genannten Kriterien identifiziert hat, und das durch die in Absatz 5 genannten Gegenmaßnahmen nicht abgedeckt wird, kann er die in seinem Hoheitsgebiet niedergelassenen verpflichteten Stellen verpflichten, spezifische zusätzliche Gegenmaßnahmen zur Eindämmung der von diesem Drittland ausgehenden spezifischen Risiken anzuwenden. Das festgestellte Risiko und die entsprechenden Gegenmaßnahmen werden der Kommission innerhalb von fünf Tagen nach Anwendung der Gegenmaßnahmen mitgeteilt.

7 7 7

The Commission shall review the delegated acts referred to in paragraph 2 on a regular basis to ensure that the specific countermeasures identified pursuant to paragraph 5 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.Upon receiving a notification pursuant to paragraph 6, the Commission shall assess the information received to determine whether country-specific risks affect the integrity of the Union’s internal market. Where appropriate, the Commission shall review the delegated acts referred to in paragraph 2, by adding the necessary countermeasures to mitigate those additional risks. Where the Commission considers that the specific additional measures applied by a Member State under paragraph 6 are not necessary to mitigate specific risks stemming from that third country, it may decide, by means of an implementing act, that the Member State shall put an end to the specific additional countermeasure.

The Commission shall review the delegated acts referred to in paragraph 2 on a regular basis to ensure that the specific countermeasures identified pursuant to paragraph 5 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.Upon receiving a notification pursuant to paragraph 6, the Commission shall assess the information received to determine whether country-specific risks affect the integrity of the Union’s internal market. Where appropriate, the Commission shall review the delegated acts referred to in paragraph 2, by adding the necessary countermeasures to mitigate those additional risks. Where the Commission considers that the specific additional measures applied by a Member State under paragraph 6 are not necessary to mitigate specific risks stemming from that third country, it may decide, by means of an implementing act, that the Member State shall put an end to the specific additional countermeasure.

Die Kommission überprüft die in Absatz 2 genannten delegierten Rechtsakte regelmäßig, um sicherzustellen, dass die gemäß Absatz 5 bestimmten spezifischen Gegenmaßnahmen den Änderungen im Rahmen des Drittlands zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung Rechnung tragen und den Risiken angemessen und verhältnismäßig sind. Nach Eingang einer Mitteilung gemäß Absatz 6 bewertet die Kommission die erhaltenen Informationen, um festzustellen, ob länderspezifische Risiken die Integrität des Binnenmarkts der Union beeinträchtigen. Gegebenenfalls überprüft die Kommission die in Absatz 2 genannten delegierten Rechtsakte, indem sie die erforderlichen Gegenmaßnahmen zur Eindämmung dieser zusätzlichen Risiken hinzufügt. Ist die Kommission der Auffassung, dass die von einem Mitgliedstaat gemäß Absatz 6 angewandten spezifischen zusätzlichen Maßnahmen zur Eindämmung spezifischer Risiken dieses Drittlands nicht erforderlich sind, kann sie im Wege eines Durchführungsrechtsakts beschließen, dass der Mitgliedstaat die spezifische zusätzliche Gegenmaßnahme beendet.

Article 30 — Identification of third countries with compliance weaknesses in their national AML/CFT regimes Article 30 — Identification of third countries with compliance weaknesses in their national AML/CFT regimes Article 30 — Identifizierung von Drittländern mit Mängeln bei der Einhaltung ihrer nationalen Regelungen zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung
1 1 1

Third countries with compliance weaknesses in their national AML/CFT regimes shall be identified by the Commission.

Third countries with compliance weaknesses in their national AML/CFT regimes shall be identified by the Commission.

Drittländer mit Mängeln bei der Einhaltung ihrer nationalen Regelungen zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung werden von der Kommission identifiziert.

2 2 2

In order to identify the third countries referred to in paragraph 1, the Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation, where:

  • (a) compliance weaknesses in the legal and institutional AML/CFT framework of the third country have been identified;
  • (b) compliance weaknesses in the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks or in its system to assess and mitigate risks of non-implementation or evasion of UN financial sanctions relating to proliferation financing have been identified.

Those delegated acts shall be adopted within 20 calendar days of the Commission ascertaining that the criteria in point (a) or (b) of the first subparagraph are met.

In order to identify the third countries referred to in paragraph 1, the Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation, where:

  • (a) compliance weaknesses in the legal and institutional AML/CFT framework of the third country have been identified;
  • (b) compliance weaknesses in the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks or in its system to assess and mitigate risks of non-implementation or evasion of UN financial sanctions relating to proliferation financing have been identified.

Those delegated acts shall be adopted within 20 calendar days of the Commission ascertaining that the criteria in point (a) or (b) of the first subparagraph are met.

Um die in Absatz 1 genannten Drittländer zu identifizieren, wird der Kommission die Befugnis übertragen, gemäß Artikel 85 delegierte Rechtsakte zur Ergänzung dieser Verordnung zu erlassen, wenn:

  • (a) Mängel bei der Einhaltung des rechtlichen und institutionellen Rahmens des Drittlands zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung festgestellt wurden;
  • (b) Mängel bei der Einhaltung hinsichtlich der Wirksamkeit des Systems des Drittlands zur Bekämpfung der Risiken von Geldwäsche und Terrorismusfinanzierung oder seines Systems zur Bewertung und Eindämmung der Risiken der Nichtumsetzung oder Umgehung von Finanzsanktionen der Vereinten Nationen im Zusammenhang mit der Finanzierung der Proliferation festgestellt wurden.

Diese delegierten Rechtsakte werden innerhalb von 20 Kalendertagen erlassen, nachdem die Kommission festgestellt hat, dass die Kriterien des ersten Unterabsatzes Buchstabe a oder b erfüllt sind.

3 3 3

The Commission, when drawing up the delegated acts referred to in paragraph 2 shall take into account, as a baseline for its assessment, information on jurisdictions under increased monitoring by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing, as well as relevant evaluations, assessments, reports or public statements drawn up by them.

The Commission, when drawing up the delegated acts referred to in paragraph 2 shall take into account, as a baseline for its assessment, information on jurisdictions under increased monitoring by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing, as well as relevant evaluations, assessments, reports or public statements drawn up by them.

Bei der Ausarbeitung der in Absatz 2 genannten delegierten Rechtsakte berücksichtigt die Kommission als Grundlage ihrer Bewertung Informationen über Rechtsordnungen, die von internationalen Organisationen und Standardsetzungsgremien mit Zuständigkeit im Bereich der Verhinderung von Geldwäsche und der Bekämpfung der Terrorismusfinanzierung verstärkt überwacht werden, sowie die von ihnen erstellten einschlägigen Bewertungen, Beurteilungen, Berichte oder öffentlichen Erklärungen.

4 4 4

The delegated act referred to in paragraph 2 shall identify the specific enhanced due diligence measures among those listed in Article 34(4), that obliged entities shall apply to mitigate risks related to business relationships or occasional transactions involving natural or legal persons from that third country.

The delegated act referred to in paragraph 2 shall identify the specific enhanced due diligence measures among those listed in Article 34(4), that obliged entities shall apply to mitigate risks related to business relationships or occasional transactions involving natural or legal persons from that third country.

Der in Absatz 2 genannte delegierte Rechtsakt bestimmt die spezifischen verstärkten Sorgfaltspflichten aus den in Artikel 34 Absatz 4 aufgeführten Maßnahmen, die verpflichtete Stellen zur Eindämmung der Risiken im Zusammenhang mit Geschäftsbeziehungen oder gelegentlichen Geschäften mit natürlichen oder juristischen Personen aus diesem Drittland anwenden müssen.

5 5 5

The Commission shall review the delegated acts referred to in paragraph 2 on a regular basis to ensure that the specific enhanced due diligence measures identified pursuant to paragraph 4 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.

The Commission shall review the delegated acts referred to in paragraph 2 on a regular basis to ensure that the specific enhanced due diligence measures identified pursuant to paragraph 4 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.

Die Kommission überprüft die in Absatz 2 genannten delegierten Rechtsakte regelmäßig, um sicherzustellen, dass die gemäß Absatz 4 bestimmten spezifischen verstärkten Sorgfaltspflichten den Änderungen im Rahmen des Drittlands zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung Rechnung tragen und den Risiken angemessen und verhältnismäßig sind.

Article 31 — Identification of third countries posing a specific and serious threat to the Union’s financial system Article 31 — Identification of third countries posing a specific and serious threat to the Union’s financial system Article 31 — Identifizierung von Drittländern, die eine spezifische und schwerwiegende Bedrohung für das Finanzsystem der Union darstellen
1 1 1

The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation by identifying third countries where in exceptional cases it considers it indispensable to mitigate a specific and serious threat to the Union’s financial system and the proper functioning of the internal market posed by those third countries, and which cannot be mitigated pursuant to Articles 29 and 30.

The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation by identifying third countries where in exceptional cases it considers it indispensable to mitigate a specific and serious threat to the Union’s financial system and the proper functioning of the internal market posed by those third countries, and which cannot be mitigated pursuant to Articles 29 and 30.

Der Kommission wird die Befugnis übertragen, gemäß Artikel 85 delegierte Rechtsakte zur Ergänzung dieser Verordnung zu erlassen, indem sie in Ausnahmefällen Drittländer identifiziert, bei denen sie es für unerlässlich hält, eine von diesen Drittländern ausgehende spezifische und schwerwiegende Bedrohung des Finanzsystems der Union und des ordnungsgemäßen Funktionierens des Binnenmarkts einzudämmen, die gemäß den Artikeln 29 und 30 nicht eingedämmt werden kann.

2 2 2

The Commission, when drawing up the delegated acts referred to in paragraph 1, shall take into account in particular the following criteria:

  • (a) the legal and institutional AML/CFT framework of the third country, in particular:

    • (i) the criminalisation of money laundering and terrorist financing;
    • (ii) measures relating to customer due diligence;
    • (iii) requirements relating to record-keeping;
    • (iv) requirements to report suspicious transactions;
    • (v) the availability of accurate and timely information of the beneficial ownership of legal persons and arrangements to competent authorities;
  • (b) the powers and procedures of the third country’s competent authorities for the purposes of combating money laundering and terrorist financing including appropriately effective, proportionate and dissuasive sanctions, as well as the third country’s practice in cooperation and exchange of information with Member States’ competent authorities;

  • (c) the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks.

The Commission, when drawing up the delegated acts referred to in paragraph 1, shall take into account in particular the following criteria:

  • (a) the legal and institutional AML/CFT framework of the third country, in particular:
    • (i) the criminalisation of money laundering and terrorist financing;
    • (ii) measures relating to customer due diligence;
    • (iii) requirements relating to record-keeping;
    • (iv) requirements to report suspicious transactions;
    • (v) the availability of accurate and timely information of the beneficial ownership of legal persons and arrangements to competent authorities;
  • (b) the powers and procedures of the third country’s competent authorities for the purposes of combating money laundering and terrorist financing including appropriately effective, proportionate and dissuasive sanctions, as well as the third country’s practice in cooperation and exchange of information with Member States’ competent authorities;
  • (c) the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks.

Bei der Ausarbeitung der in Absatz 1 genannten delegierten Rechtsakte berücksichtigt die Kommission insbesondere folgende Kriterien:

  • (a) den rechtlichen und institutionellen Rahmen des Drittlands zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung, insbesondere:
    • (i) die Strafbarkeit von Geldwäsche und Terrorismusfinanzierung;
    • (ii) Maßnahmen zur Erfüllung der Sorgfaltspflichten gegenüber Kunden;
    • (iii) Anforderungen an die Aufbewahrung von Aufzeichnungen;
    • (iv) Anforderungen zur Meldung verdächtiger Transaktionen;
    • (v) die Verfügbarkeit genauer und zeitnaher Informationen über die wirtschaftlichen Eigentümer juristischer Personen und Rechtsgestaltungen für die zuständigen Behörden;
  • (b) die Befugnisse und Verfahren der zuständigen Behörden des Drittlands zur Bekämpfung von Geldwäsche und Terrorismusfinanzierung, einschließlich angemessen wirksamer, verhältnismäßiger und abschreckender Sanktionen, sowie die Praxis des Drittlands bei der Zusammenarbeit und dem Informationsaustausch mit den zuständigen Behörden der Mitgliedstaaten;
  • (c) die Wirksamkeit des Systems des Drittlands zur Bekämpfung der Risiken von Geldwäsche und Terrorismusfinanzierung.
3 3 3

For the purposes of determining the level of threat referred to in paragraph 1, the Commission may request AMLA to adopt an opinion aimed at assessing the specific impact on the integrity of the Union’s financial system due to the level of threat posed by a third country.

For the purposes of determining the level of threat referred to in paragraph 1, the Commission may request AMLA to adopt an opinion aimed at assessing the specific impact on the integrity of the Union’s financial system due to the level of threat posed by a third country.

Zur Bestimmung des in Absatz 1 genannten Bedrohungsgrads kann die Kommission die AMLA ersuchen, eine Stellungnahme zur Bewertung der spezifischen Auswirkungen des von einem Drittland ausgehenden Bedrohungsgrads auf die Integrität des Finanzsystems der Union abzugeben.

4 4 4

Where AMLA identifies that a third country other than those identified pursuant to Articles 29 and 30 poses a specific and serious threat to the Union’s financial system, it may address an opinion to the Commission setting out the threat it has identified and why it believes that the Commission should identify the third country pursuant to paragraph 1.Where the Commission decides not to identify the third country referred to in the first subparagraph, it shall provide a justification thereof to AMLA.

Where AMLA identifies that a third country other than those identified pursuant to Articles 29 and 30 poses a specific and serious threat to the Union’s financial system, it may address an opinion to the Commission setting out the threat it has identified and why it believes that the Commission should identify the third country pursuant to paragraph 1. Where the Commission decides not to identify the third country referred to in the first subparagraph, it shall provide a justification thereof to AMLA.

Stellt die AMLA fest, dass ein anderes als die gemäß den Artikeln 29 und 30 bestimmte Drittland eine spezifische und erhebliche Bedrohung für das Finanzsystem der Union darstellt, kann sie der Kommission eine Stellungnahme übermitteln, in der sie die festgestellte Bedrohung darlegt und begründet, weshalb die Kommission ihrer Auffassung nach das Drittland gemäß Absatz 1 bestimmen sollte. Beschließt die Kommission, das im ersten Unterabsatz genannte Drittland nicht zu bestimmen, so legt sie der AMLA hierfür eine Begründung vor.

5 5 5

The Commission, when drawing up the delegated acts referred to in paragraph 1, shall take into account in particular relevant evaluations, assessments or reports drawn up by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing.

The Commission, when drawing up the delegated acts referred to in paragraph 1, shall take into account in particular relevant evaluations, assessments or reports drawn up by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing.

Die Kommission berücksichtigt bei der Ausarbeitung der delegierten Rechtsakte nach Absatz 1 insbesondere einschlägige Bewertungen, Beurteilungen oder Berichte internationaler Organisationen und Einrichtungen zur Festlegung von Standards, die im Bereich der Verhinderung von Geldwäsche und der Bekämpfung der Terrorismusfinanzierung zuständig sind.

6 6 6

Where the identified specific and serious threat from the third country concerned amounts to a significant strategic deficiency, Article 29(4) shall apply and the delegated act referred to in paragraph 1 of this Article shall identify specific countermeasures as referred to in Article 29(5).

Where the identified specific and serious threat from the third country concerned amounts to a significant strategic deficiency, Article 29(4) shall apply and the delegated act referred to in paragraph 1 of this Article shall identify specific countermeasures as referred to in Article 29(5).

Betrifft die festgestellte spezifische und erhebliche Bedrohung durch das betreffende Drittland einen erheblichen strategischen Mangel, so gilt Artikel 29 Absatz 4, und im delegierten Rechtsakt nach Absatz 1 dieses Artikels werden spezifische Gegenmaßnahmen im Sinne des Artikels 29 Absatz 5 festgelegt.

7 7 7

Where the identified specific and serious threat from the third country concerned amounts to a compliance weakness, the delegated act referred to in paragraph 1 shall identify specific enhanced due diligence measures among those listed in Article 34(4), that obliged entities shall apply to mitigate risks related to business relationships or occasional transactions involving natural or legal persons from that third country.

Where the identified specific and serious threat from the third country concerned amounts to a compliance weakness, the delegated act referred to in paragraph 1 shall identify specific enhanced due diligence measures among those listed in Article 34(4), that obliged entities shall apply to mitigate risks related to business relationships or occasional transactions involving natural or legal persons from that third country.

Betrifft die festgestellte spezifische und erhebliche Bedrohung durch das betreffende Drittland eine Schwäche bei der Einhaltung der Vorschriften, so werden im delegierten Rechtsakt nach Absatz 1 spezifische verstärkte Sorgfaltspflichten aus den in Artikel 34 Absatz 4 aufgeführten Maßnahmen festgelegt, die die Verpflichteten zur Minderung der mit Geschäftsbeziehungen oder gelegentlichen Transaktionen verbundenen Risiken anwenden müssen, an denen natürliche oder juristische Personen aus diesem Drittland beteiligt sind.

8 8 8

The Commission shall review the delegated acts referred to in paragraph 1 on a regular basis to ensure that the countermeasures referred to in paragraph 6 and enhanced due diligence measures referred to in paragraph 7 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.

The Commission shall review the delegated acts referred to in paragraph 1 on a regular basis to ensure that the countermeasures referred to in paragraph 6 and enhanced due diligence measures referred to in paragraph 7 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.

Die Kommission überprüft die delegierten Rechtsakte nach Absatz 1 regelmäßig, um sicherzustellen, dass die in Absatz 6 genannten Gegenmaßnahmen und die in Absatz 7 genannten verstärkten Sorgfaltspflichten den Änderungen des AML/CFT-Rahmens des Drittlandes Rechnung tragen und den Risiken angemessen und verhältnismäßig sind.

9 9 9

The Commission may adopt, by means of an implementing act, the methodology for the identification of third countries pursuant to this Article. That implementing act shall set out, in particular:

  • (a) how the criteria referred to in paragraph 2 are assessed;
  • (b) the process for interaction with the third country under assessment;
  • (c) the process for involvement of Member States and AMLA in the identification of third countries posing a specific and serious threat to the Union’s financial system.

The implementing act referred to in the first subparagraph of this paragraph shall be adopted in accordance with the examination procedure referred to in Article 86(2).

The Commission may adopt, by means of an implementing act, the methodology for the identification of third countries pursuant to this Article. That implementing act shall set out, in particular:

  • (a) how the criteria referred to in paragraph 2 are assessed;
  • (b) the process for interaction with the third country under assessment;
  • (c) the process for involvement of Member States and AMLA in the identification of third countries posing a specific and serious threat to the Union’s financial system.

The implementing act referred to in the first subparagraph of this paragraph shall be adopted in accordance with the examination procedure referred to in Article 86(2).

Die Kommission kann im Wege eines Durchführungsrechtsakts die Methode zur Bestimmung von Drittländern gemäß diesem Artikel festlegen. In diesem Durchführungsrechtsakt wird insbesondere Folgendes festgelegt:

  • a) wie die in Absatz 2 genannten Kriterien bewertet werden;
  • b) das Verfahren für die Zusammenarbeit mit dem zu bewertenden Drittland;
  • c) das Verfahren für die Einbeziehung der Mitgliedstaaten und der AMLA in die Bestimmung von Drittländern, die eine spezifische und erhebliche Bedrohung für das Finanzsystem der Union darstellen.

Der im ersten Unterabsatz dieses Absatzes genannte Durchführungsrechtsakt wird gemäß dem in Artikel 86 Absatz 2 genannten Prüfverfahren erlassen.

Article 32 — Guidelines on money laundering and terrorist financing risks, trends and methods Article 32 — Guidelines on money laundering and terrorist financing risks, trends and methods Article 32 — Leitlinien zu den Risiken, Trends und Methoden der Geldwäsche und der Terrorismusfinanzierung
1 1 1

By 10 July 2027, AMLA shall issue guidelines defining the money laundering and terrorist financing risks, trends and methods involving any geographical area outside the Union to which obliged entities are exposed. AMLA shall take into account, in particular, the risk factors listed in Annex III. Where situations of higher risk are identified, the guidelines shall include enhanced due diligence measures that obliged entities shall consider applying to mitigate such risks.

By 10 July 2027, AMLA shall issue guidelines defining the money laundering and terrorist financing risks, trends and methods involving any geographical area outside the Union to which obliged entities are exposed. AMLA shall take into account, in particular, the risk factors listed in Annex III. Where situations of higher risk are identified, the guidelines shall include enhanced due diligence measures that obliged entities shall consider applying to mitigate such risks.

Bis zum 10. Juli 2027 gibt die AMLA Leitlinien heraus, in denen die Risiken, Trends und Methoden der Geldwäsche und der Terrorismusfinanzierung im Zusammenhang mit allen geografischen Gebieten außerhalb der Union festgelegt werden, denen die Verpflichteten ausgesetzt sind. Die AMLA berücksichtigt insbesondere die in Anhang III aufgeführten Risikofaktoren. Werden Situationen mit höherem Risiko festgestellt, so enthalten die Leitlinien verstärkte Sorgfaltspflichten, deren Anwendung durch die Verpflichteten zur Minderung dieser Risiken in Betracht zu ziehen ist.

2 2 2

AMLA shall review the guidelines referred to in paragraph 1 at least every 2 years.

AMLA shall review the guidelines referred to in paragraph 1 at least every 2 years.

Die AMLA überprüft die in Absatz 1 genannten Leitlinien mindestens alle zwei Jahre.

3 3 3

When issuing and reviewing the guidelines referred to in paragraph 1, AMLA shall take into account evaluations, assessments or reports of Union institutions, bodies, offices and agencies, international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing.

When issuing and reviewing the guidelines referred to in paragraph 1, AMLA shall take into account evaluations, assessments or reports of Union institutions, bodies, offices and agencies, international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing.

Bei der Herausgabe und Überprüfung der in Absatz 1 genannten Leitlinien berücksichtigt die AMLA die Bewertungen, Beurteilungen oder Berichte der Organe, Einrichtungen, Ämter und Agenturen der Union, internationaler Organisationen und Einrichtungen zur Festlegung von Standards, die im Bereich der Verhinderung von Geldwäsche und der Bekämpfung der Terrorismusfinanzierung zuständig sind.

SECTION 3 — Simplified due diligence SECTION 3 — Simplified due diligence SECTION 3 — Vereinfachte Sorgfaltspflichten
Article 33 — Simplified due diligence measures Article 33 — Simplified due diligence measures Article 33 — Maßnahmen zu vereinfachten Sorgfaltspflichten
1 1 1

Where, taking into account the risk factors set out in Annexes II and III, the business relationship or transaction present a low degree of risk, obliged entities may apply the following simplified due diligence measures:

  • (a) verifying the identity of the customer and the beneficial owner after the establishment of the business relationship, provided that the specific lower risk identified justified such postponement, but in any case no later than 60 days of the relationship being established;
  • (b) reducing the frequency of customer identification updates;
  • (c) reducing the amount of information collected to identify the purpose and intended nature of the business relationship or occasional transaction or inferring it from the type of transactions or business relationship established;
  • (d) reducing the frequency or degree of scrutiny of transactions carried out by the customer;
  • (e) applying any other relevant simplified due diligence measure identified by AMLA pursuant to Article 28.

The measures referred to in the first subparagraph shall be proportionate to the nature and size of the business and to the specific elements of lower risk identified. However, obliged entities shall carry out sufficient monitoring of the transactions and business relationship to enable the detection of unusual or suspicious transactions.

Where, taking into account the risk factors set out in Annexes II and III, the business relationship or transaction present a low degree of risk, obliged entities may apply the following simplified due diligence measures:

  • (a) verifying the identity of the customer and the beneficial owner after the establishment of the business relationship, provided that the specific lower risk identified justified such postponement, but in any case no later than 60 days of the relationship being established;
  • (b) reducing the frequency of customer identification updates;
  • (c) reducing the amount of information collected to identify the purpose and intended nature of the business relationship or occasional transaction or inferring it from the type of transactions or business relationship established;
  • (d) reducing the frequency or degree of scrutiny of transactions carried out by the customer;
  • (e) applying any other relevant simplified due diligence measure identified by AMLA pursuant to Article 28.

The measures referred to in the first subparagraph shall be proportionate to the nature and size of the business and to the specific elements of lower risk identified. However, obliged entities shall carry out sufficient monitoring of the transactions and business relationship to enable the detection of unusual or suspicious transactions.

Weisen die Geschäftsbeziehung oder die Transaktion unter Berücksichtigung der in den Anhängen II und III aufgeführten Risikofaktoren ein geringes Risiko auf, so können die Verpflichteten folgende vereinfachte Sorgfaltspflichten anwenden:

  • a) Überprüfung der Identität des Kunden und des wirtschaftlichen Eigentümers nach Begründung der Geschäftsbeziehung, sofern das festgestellte spezifische geringere Risiko diese Zurückstellung rechtfertigt, jedoch in jedem Fall spätestens 60 Tage nach Begründung der Geschäftsbeziehung;
  • b) Verringerung der Häufigkeit der Aktualisierung der Kundenidentifizierung;
  • c) Verringerung des Umfangs der erhobenen Informationen zur Feststellung des Zwecks und der vorgesehenen Art der Geschäftsbeziehung oder gelegentlichen Transaktion oder Ableitung dieser Angaben aus der Art der durchgeführten Transaktionen oder der begründeten Geschäftsbeziehung;
  • d) Verringerung der Häufigkeit oder des Umfangs der Überprüfung der vom Kunden durchgeführten Transaktionen;
  • e) Anwendung jeder anderen einschlägigen vereinfachten Sorgfaltspflicht, die die AMLA gemäß Artikel 28 festgelegt hat.

Die im ersten Unterabsatz genannten Maßnahmen müssen der Art und Größe des Unternehmens sowie den festgestellten spezifischen Elementen des geringeren Risikos angemessen sein. Die Verpflichteten führen jedoch eine ausreichende Überwachung der Transaktionen und der Geschäftsbeziehung durch, damit ungewöhnliche oder verdächtige Transaktionen erkannt werden können.

2 2 2

Obliged entities shall ensure that the internal procedures established pursuant to Article 9 contain the specific measures of simplified verification that shall be taken in relation to the different types of customers that present a lower risk. Obliged entities shall document decisions to take into account additional factors of lower risk.

Obliged entities shall ensure that the internal procedures established pursuant to Article 9 contain the specific measures of simplified verification that shall be taken in relation to the different types of customers that present a lower risk. Obliged entities shall document decisions to take into account additional factors of lower risk.

Die Verpflichteten stellen sicher, dass die gemäß Artikel 9 eingerichteten internen Verfahren die spezifischen Maßnahmen der vereinfachten Überprüfung enthalten, die bei den verschiedenen Arten von Kunden mit geringerem Risiko zu ergreifen sind. Die Verpflichteten dokumentieren Entscheidungen, mit denen zusätzliche Faktoren eines geringeren Risikos berücksichtigt werden.

3 3 3

For the purpose of applying simplified due diligence measures referred to in paragraph 1, point (a), obliged entities shall adopt risk management procedures with respect to the conditions under which they can provide services or perform transactions for a customer prior to the verification taking place, including by limiting the amount, number or types of transactions that can be performed or by monitoring transactions to ensure that they are in line with the expected norms for the business relationship at hand.

For the purpose of applying simplified due diligence measures referred to in paragraph 1, point (a), obliged entities shall adopt risk management procedures with respect to the conditions under which they can provide services or perform transactions for a customer prior to the verification taking place, including by limiting the amount, number or types of transactions that can be performed or by monitoring transactions to ensure that they are in line with the expected norms for the business relationship at hand.

Für die Anwendung der in Absatz 1 Buchstabe a genannten vereinfachten Sorgfaltspflichten erlassen die Verpflichteten Risikomanagementverfahren hinsichtlich der Bedingungen, unter denen sie für einen Kunden vor Durchführung der Überprüfung Dienstleistungen erbringen oder Transaktionen durchführen können, unter anderem durch Begrenzung des Betrags, der Anzahl oder der Arten der durchführbaren Transaktionen oder durch Überwachung der Transaktionen, um sicherzustellen, dass sie den für die betreffende Geschäftsbeziehung erwarteten üblichen Mustern entsprechen.

4 4 4

Obliged entities shall verify on a regular basis that the conditions for the application of simplified due diligence measures continue to exist. The frequency of such verifications shall be commensurate with the nature and size of the business and the risks posed by the specific relationship.

Obliged entities shall verify on a regular basis that the conditions for the application of simplified due diligence measures continue to exist. The frequency of such verifications shall be commensurate with the nature and size of the business and the risks posed by the specific relationship.

Die Verpflichteten überprüfen regelmäßig, ob die Voraussetzungen für die Anwendung vereinfachter Sorgfaltspflichten weiterhin vorliegen. Die Häufigkeit dieser Überprüfungen muss der Art und Größe des Unternehmens sowie den Risiken der spezifischen Geschäftsbeziehung angemessen sein.

5 5 5

Obliged entities shall refrain from applying simplified due diligence measures in any of the following situations:

  • (a) the obliged entities have doubts as to the veracity of the information provided by the customer or the beneficial owner at the stage of identification, or they detect inconsistencies regarding that information;
  • (b) the factors indicating a lower risk are no longer present;
  • (c) the monitoring of the customer’s transactions and the information collected in the context of the business relationship exclude a lower risk scenario;
  • (d) there is a suspicion of money laundering or terrorist financing;
  • (e) there is a suspicion that the customer, or the person acting on behalf of the customer, is attempting to circumvent or evade targeted financial sanctions.

Obliged entities shall refrain from applying simplified due diligence measures in any of the following situations:

  • (a) the obliged entities have doubts as to the veracity of the information provided by the customer or the beneficial owner at the stage of identification, or they detect inconsistencies regarding that information;
  • (b) the factors indicating a lower risk are no longer present;
  • (c) the monitoring of the customer’s transactions and the information collected in the context of the business relationship exclude a lower risk scenario;
  • (d) there is a suspicion of money laundering or terrorist financing;
  • (e) there is a suspicion that the customer, or the person acting on behalf of the customer, is attempting to circumvent or evade targeted financial sanctions.

Die Verpflichteten sehen von der Anwendung vereinfachter Sorgfaltspflichten in jeder der folgenden Situationen ab:

  • a) Sie haben Zweifel an der Richtigkeit der vom Kunden oder wirtschaftlichen Eigentümer bei der Identifizierung gemachten Angaben oder stellen diesbezüglich Widersprüche fest;
  • b) die auf ein geringeres Risiko hindeutenden Faktoren liegen nicht mehr vor;
  • c) die Überwachung der Transaktionen des Kunden und die im Rahmen der Geschäftsbeziehung erhobenen Informationen schließen ein Szenario mit geringerem Risiko aus;
  • d) es besteht der Verdacht auf Geldwäsche oder Terrorismusfinanzierung;
  • e) es besteht der Verdacht, dass der Kunde oder die im Namen des Kunden handelnde Person versucht, gezielte finanzielle Sanktionen zu umgehen oder sich ihnen zu entziehen.
SECTION 4 — Enhanced due diligence SECTION 4 — Enhanced due diligence SECTION 4 — Verstärkte Sorgfaltspflichten
Article 34 — Scope of application of enhanced due diligence measures Article 34 — Scope of application of enhanced due diligence measures Article 34 — Anwendungsbereich der Maßnahmen zu verstärkten Sorgfaltspflichten
1 1 1

In the cases referred to in Articles 29, 30, 31 and 36 to 46, as well as in other cases of higher risk that are identified by obliged entities pursuant to Article 20(2), second subparagraph, obliged entities shall apply enhanced due diligence measures to manage and mitigate such risks appropriately.

In the cases referred to in Articles 29, 30, 31 and 36 to 46, as well as in other cases of higher risk that are identified by obliged entities pursuant to Article 20(2), second subparagraph, obliged entities shall apply enhanced due diligence measures to manage and mitigate such risks appropriately.

In den in den Artikeln 29, 30, 31 und 36 bis 46 genannten Fällen sowie in anderen Fällen eines höheren Risikos, die von den Verpflichteten gemäß Artikel 20 Absatz 2 Unterabsatz 2 festgestellt werden, wenden die Verpflichteten verstärkte Sorgfaltspflichten an, um diese Risiken angemessen zu steuern und zu mindern.

2 2 2

Obliged entities shall examine the origin and destination of funds involved in, and the purpose of, all transactions that fulfil at least one of the following conditions:

  • (a) the transaction is of a complex nature;
  • (b) the transaction is unusually large;
  • (c) the transaction is conducted in an unusual pattern;
  • (d) the transaction does not have an apparent economic or lawful purpose.

Obliged entities shall examine the origin and destination of funds involved in, and the purpose of, all transactions that fulfil at least one of the following conditions:

  • (a) the transaction is of a complex nature;
  • (b) the transaction is unusually large;
  • (c) the transaction is conducted in an unusual pattern;
  • (d) the transaction does not have an apparent economic or lawful purpose.

Die Verpflichteten prüfen die Herkunft und das Ziel der an einer Transaktion beteiligten Gelder sowie den Zweck aller Transaktionen, die mindestens eine der folgenden Voraussetzungen erfüllen:

  • a) die Transaktion ist komplex;
  • b) die Transaktion ist ungewöhnlich umfangreich;
  • c) die Transaktion weist ein ungewöhnliches Muster auf;
  • d) die Transaktion hat keinen erkennbaren wirtschaftlichen oder rechtmäßigen Zweck.
3 3 3

With the exception of the cases covered by Section 2 of this Chapter, when assessing the risks of money laundering and terrorist financing posed by a business relationship or occasional transaction, obliged entities shall take into account at least the factors of potential higher risk set out in Annex III and the guidelines adopted by AMLA pursuant to Article 32, as well as any other indicators of higher risk such as notifications issued by the FIU and findings of the business-wide risk assessment under Article 10.

With the exception of the cases covered by Section 2 of this Chapter, when assessing the risks of money laundering and terrorist financing posed by a business relationship or occasional transaction, obliged entities shall take into account at least the factors of potential higher risk set out in Annex III and the guidelines adopted by AMLA pursuant to Article 32, as well as any other indicators of higher risk such as notifications issued by the FIU and findings of the business-wide risk assessment under Article 10.

Mit Ausnahme der in Abschnitt 2 dieses Kapitels erfassten Fälle berücksichtigen die Verpflichteten bei der Bewertung der von einer Geschäftsbeziehung oder gelegentlichen Transaktion ausgehenden Risiken der Geldwäsche und der Terrorismusfinanzierung mindestens die in Anhang III aufgeführten Faktoren eines potenziell höheren Risikos und die von der AMLA gemäß Artikel 32 erlassenen Leitlinien sowie alle sonstigen Anzeichen eines höheren Risikos, etwa Mitteilungen der zentralen Meldestelle und die Ergebnisse der unternehmensweiten Risikobewertung nach Artikel 10.

4 4 4

With the exception of the cases covered by Section 2 of this Chapter, in cases of higher risk as referred to in paragraph 1 of this Article, obliged entities shall apply enhanced due diligence measures, proportionate to the higher risks identified, which may include the following measures:

  • (a) obtaining additional information on the customer and the beneficial owners;
  • (b) obtaining additional information on the intended nature of the business relationship;
  • (c) obtaining additional information on the source of funds, and source of wealth of the customer and of the beneficial owners;
  • (d) obtaining information on the reasons for the intended or performed transactions and their consistency with the business relationship;
  • (e) obtaining the approval of senior management for establishing or continuing the business relationship;
  • (f) conducting enhanced monitoring of the business relationship by increasing the number and timing of controls applied, and selecting patterns of transactions that need further examination;
  • (g) requiring the first payment to be carried out through an account in the customer’s name with a credit institution subject to customer due diligence standards that are not less robust than those laid down in this Regulation.

With the exception of the cases covered by Section 2 of this Chapter, in cases of higher risk as referred to in paragraph 1 of this Article, obliged entities shall apply enhanced due diligence measures, proportionate to the higher risks identified, which may include the following measures:

  • (a) obtaining additional information on the customer and the beneficial owners;
  • (b) obtaining additional information on the intended nature of the business relationship;
  • (c) obtaining additional information on the source of funds, and source of wealth of the customer and of the beneficial owners;
  • (d) obtaining information on the reasons for the intended or performed transactions and their consistency with the business relationship;
  • (e) obtaining the approval of senior management for establishing or continuing the business relationship;
  • (f) conducting enhanced monitoring of the business relationship by increasing the number and timing of controls applied, and selecting patterns of transactions that need further examination;
  • (g) requiring the first payment to be carried out through an account in the customer’s name with a credit institution subject to customer due diligence standards that are not less robust than those laid down in this Regulation.

Mit Ausnahme der in Abschnitt 2 dieses Kapitels erfassten Fälle wenden die Verpflichteten in Fällen eines höheren Risikos im Sinne des Absatzes 1 dieses Artikels dem festgestellten höheren Risiko angemessene verstärkte Sorgfaltspflichten an, die unter anderem Folgendes umfassen können:

  • a) Einholung zusätzlicher Informationen über den Kunden und die wirtschaftlichen Eigentümer;
  • b) Einholung zusätzlicher Informationen über die vorgesehene Art der Geschäftsbeziehung;
  • c) Einholung zusätzlicher Informationen über die Herkunft der Gelder und des Vermögens des Kunden und der wirtschaftlichen Eigentümer;
  • d) Einholung von Informationen über die Gründe für die beabsichtigten oder durchgeführten Transaktionen und deren Übereinstimmung mit der Geschäftsbeziehung;
  • e) Einholung der Zustimmung der Führungsebene zur Begründung oder Fortführung der Geschäftsbeziehung;
  • f) verstärkte Überwachung der Geschäftsbeziehung durch Erhöhung der Anzahl und der Zeitabstände der Kontrollen sowie Auswahl von Transaktionsmustern, die einer weiteren Prüfung bedürfen;
  • g) Verlangen, dass die erste Zahlung über ein auf den Namen des Kunden lautendes Konto bei einem Kreditinstitut abgewickelt wird, das Sorgfaltspflichten gegenüber Kunden unterliegt, die nicht weniger streng sind als die in dieser Verordnung festgelegten.
5 5 5

Where a business relationship that is identified as having a higher risk involves the handling of assets with a value of at least EUR 5000000, or the equivalent in national or foreign currency, through personalised services for a customer holding total assets with a value of at least EUR 50000000, or the equivalent in national or foreign currency, whether in financial, investable or real estate assets, or a combination thereof, excluding that customer’s private residence, credit institutions, financial institutions and trust or company service providers shall apply the following enhanced due diligence measures, in addition to any enhanced due diligence measure applied pursuant to paragraph 4:

  • (a) specific measures including procedures to mitigate risks associated with personalised services and products offered to that customer;
  • (b) obtaining additional information on that customer’s source of funds;
  • (c) preventing and managing conflicts of interest between the customer and senior management or employees of the obliged entity that undertake tasks related to that obliged entity’s compliance in relation to that customer.

By 10 July 2027, AMLA shall issue guidelines on the measures to be taken by credit institutions, financial institutions and trust or company service providers to establish whether a customer holds total assets with a value of at least EUR 50000000, or the equivalent in national or foreign currency, in financial, investable or real estate assets and how to determine that value.

Where a business relationship that is identified as having a higher risk involves the handling of assets with a value of at least EUR 5000000, or the equivalent in national or foreign currency, through personalised services for a customer holding total assets with a value of at least EUR 50000000, or the equivalent in national or foreign currency, whether in financial, investable or real estate assets, or a combination thereof, excluding that customer’s private residence, credit institutions, financial institutions and trust or company service providers shall apply the following enhanced due diligence measures, in addition to any enhanced due diligence measure applied pursuant to paragraph 4:

  • (a) specific measures including procedures to mitigate risks associated with personalised services and products offered to that customer;
  • (b) obtaining additional information on that customer’s source of funds;
  • (c) preventing and managing conflicts of interest between the customer and senior management or employees of the obliged entity that undertake tasks related to that obliged entity’s compliance in relation to that customer.

By 10 July 2027, AMLA shall issue guidelines on the measures to be taken by credit institutions, financial institutions and trust or company service providers to establish whether a customer holds total assets with a value of at least EUR 50000000, or the equivalent in national or foreign currency, in financial, investable or real estate assets and how to determine that value.

Betrifft eine als höheres Risiko eingestufte Geschäftsbeziehung die Verwaltung von Vermögenswerten im Wert von mindestens 5 000 000 EUR oder dem Gegenwert in nationaler oder ausländischer Währung durch personalisierte Dienstleistungen für einen Kunden, dessen Gesamtvermögen einen Wert von mindestens 50 000 000 EUR oder dem Gegenwert in nationaler oder ausländischer Währung aufweist, und zwar in Form von Finanzvermögen, Anlagevermögen oder Immobilienvermögen oder einer Kombination daraus, ausgenommen der private Wohnsitz des Kunden, so wenden Kreditinstitute, Finanzinstitute und Trust- oder Gesellschaftsdienstleister zusätzlich zu den gemäß Absatz 4 angewandten verstärkten Sorgfaltspflichten folgende Maßnahmen an:

  • a) spezifische Maßnahmen, einschließlich Verfahren zur Minderung der mit den diesem Kunden angebotenen personalisierten Dienstleistungen und Produkten verbundenen Risiken;
  • b) Einholung zusätzlicher Informationen über die Herkunft der Gelder dieses Kunden;
  • c) Vermeidung und Bewältigung von Interessenkonflikten zwischen dem Kunden und der Führungsebene oder den Mitarbeitern des Verpflichteten, die Aufgaben im Zusammenhang mit der Einhaltung der Vorschriften durch den Verpflichteten in Bezug auf diesen Kunden wahrnehmen.

Bis zum 10. Juli 2027 gibt die AMLA Leitlinien zu den Maßnahmen heraus, die Kreditinstitute, Finanzinstitute und Trust- oder Gesellschaftsdienstleister ergreifen müssen, um festzustellen, ob ein Kunde über ein Gesamtvermögen im Wert von mindestens 50 000 000 EUR oder dem Gegenwert in nationaler oder ausländischer Währung in Form von Finanzvermögen, Anlagevermögen oder Immobilienvermögen verfügt, und wie dieser Wert zu bestimmen ist.

6 6 6

With the exception of the cases covered by Section 2 of this Chapter, where Member States identify cases of higher risks pursuant to Article 8 of Directive (EU) 2024/1640, including as a result of sectoral risk assessments carried out by the Member States, they may require obliged entities to apply enhanced due diligence measures and, where appropriate, specify those measures. Member States shall notify to the Commission and AMLA their decisions imposing enhanced due diligence requirements upon obliged entities established in their territory within 1 month of their adoption, accompanied by a justification of the money laundering and terrorist financing risks underpinning such decision.Where the risks identified by Member States pursuant to the first subparagraph are likely to stem from outside the Union and may affect the Union’s financial system, AMLA shall, upon a request from the Commission or on its own initiative, consider updating the guidelines adopted pursuant to Article 32.

With the exception of the cases covered by Section 2 of this Chapter, where Member States identify cases of higher risks pursuant to Article 8 of Directive (EU) 2024/1640, including as a result of sectoral risk assessments carried out by the Member States, they may require obliged entities to apply enhanced due diligence measures and, where appropriate, specify those measures. Member States shall notify to the Commission and AMLA their decisions imposing enhanced due diligence requirements upon obliged entities established in their territory within 1 month of their adoption, accompanied by a justification of the money laundering and terrorist financing risks underpinning such decision. Where the risks identified by Member States pursuant to the first subparagraph are likely to stem from outside the Union and may affect the Union’s financial system, AMLA shall, upon a request from the Commission or on its own initiative, consider updating the guidelines adopted pursuant to Article 32.

Mit Ausnahme der in Abschnitt 2 dieses Kapitels erfassten Fälle können die Mitgliedstaaten, wenn sie gemäß Artikel 8 der Richtlinie (EU) 2024/1640 Fälle höherer Risiken feststellen, auch infolge von durch die Mitgliedstaaten durchgeführten sektoralen Risikobewertungen, die Verpflichteten verpflichten, verstärkte Sorgfaltspflichten anzuwenden, und gegebenenfalls diese Maßnahmen festlegen. Die Mitgliedstaaten teilen der Kommission und der AMLA ihre Entscheidungen, mit denen sie im Hoheitsgebiet niedergelassene Verpflichtete zur Anwendung verstärkter Sorgfaltspflichten verpflichten, innerhalb eines Monats nach deren Erlass mit und fügen eine Begründung der diesen Entscheidungen zugrunde liegenden Risiken der Geldwäsche und der Terrorismusfinanzierung bei. Wenn die von den Mitgliedstaaten gemäß dem ersten Unterabsatz festgestellten Risiken wahrscheinlich außerhalb der Union entstehen und das Finanzsystem der Union beeinträchtigen können, prüft die AMLA auf Ersuchen der Kommission oder von sich aus eine Aktualisierung der gemäß Artikel 32 erlassenen Leitlinien.

7 7 7

The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation where it identifies additional cases of higher risk as referred to in paragraph 1 of this Article that affect the Union as a whole and enhanced due diligence measures that obliged entities are to apply in those cases, taking into account the notifications by Member States pursuant to paragraph 6, first subparagraph, of this Article.

The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation where it identifies additional cases of higher risk as referred to in paragraph 1 of this Article that affect the Union as a whole and enhanced due diligence measures that obliged entities are to apply in those cases, taking into account the notifications by Member States pursuant to paragraph 6, first subparagraph, of this Article.

Der Kommission wird die Befugnis übertragen, gemäß Artikel 85 delegierte Rechtsakte zur Ergänzung dieser Verordnung zu erlassen, wenn sie zusätzliche Fälle eines höheren Risikos im Sinne des Absatzes 1 dieses Artikels feststellt, die die Union insgesamt betreffen, sowie verstärkte Sorgfaltspflichten festzulegen, die die Verpflichteten in diesen Fällen anzuwenden haben, wobei sie die Mitteilungen der Mitgliedstaaten gemäß Absatz 6 Unterabsatz 1 dieses Artikels berücksichtigt.

8 8 8

Enhanced due diligence measures shall not be invoked automatically with respect to branches or subsidiaries of obliged entities established in the Union which are located in third countries referred to in Articles 29, 30 and 31 where those branches or subsidiaries fully comply with the group-wide policies, procedures and controls in accordance with Article 17.

Enhanced due diligence measures shall not be invoked automatically with respect to branches or subsidiaries of obliged entities established in the Union which are located in third countries referred to in Articles 29, 30 and 31 where those branches or subsidiaries fully comply with the group-wide policies, procedures and controls in accordance with Article 17.

Verstärkte Sorgfaltspflichten werden nicht automatisch gegenüber Zweigniederlassungen oder Tochterunternehmen von in der Union niedergelassenen Verpflichteten geltend gemacht, die sich in den Artikeln 29, 30 und 31 genannten Drittländern befinden, wenn diese Zweigniederlassungen oder Tochterunternehmen die gruppenweiten Strategien, Verfahren und Kontrollen gemäß Artikel 17 vollständig einhalten.

Article 35 — Countermeasures to mitigate money laundering and terrorist financing threats from outside the Union Article 35 — Countermeasures to mitigate money laundering and terrorist financing threats from outside the Union Article 35 — Gegenmaßnahmen zur Minderung von Bedrohungen durch Geldwäsche und Terrorismusfinanzierung von außerhalb der Union

For the purposes of Articles 29 and 31, the Commission may choose from among the following countermeasures:

  • (a) countermeasures that obliged entities are to apply to persons and legal entities involving high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in:

    • (i) the application of additional elements of enhanced due diligence;
    • (ii) the introduction of enhanced relevant reporting mechanisms or systematic reporting of financial transactions;
    • (iii) the limitation of business relationships or transactions with natural persons or legal entities from those third countries;
  • (b) countermeasures that Member States are to apply with regard to high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in:

    • (i) refusing the establishment of subsidiaries or branches or representative offices of obliged entities from the country concerned, or otherwise taking into account the fact that the relevant obliged entity is from a third country that does not have adequate AML/CFT regimes;
    • (ii) prohibiting obliged entities from establishing branches or representative offices in the third country concerned, or otherwise taking into account the fact that the relevant branch or representative office would be in a third country that does not have adequate AML/CFT regimes;
    • (iii) requiring increased supervisory examination or increased external audit requirements for branches and subsidiaries of obliged entities located in the third country concerned;
    • (iv) requiring increased external audit requirements for financial groups with respect to any of their branches and subsidiaries located in the third country concerned;
    • (v) requiring credit institutions and financial institutions to review and amend, or if necessary terminate, correspondent relationships with respondent institutions in the third country concerned.

For the purposes of Articles 29 and 31, the Commission may choose from among the following countermeasures:

  • (a) countermeasures that obliged entities are to apply to persons and legal entities involving high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in:
    • (i) the application of additional elements of enhanced due diligence;
    • (ii) the introduction of enhanced relevant reporting mechanisms or systematic reporting of financial transactions;
    • (iii) the limitation of business relationships or transactions with natural persons or legal entities from those third countries;
  • (b) countermeasures that Member States are to apply with regard to high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in:
    • (i) refusing the establishment of subsidiaries or branches or representative offices of obliged entities from the country concerned, or otherwise taking into account the fact that the relevant obliged entity is from a third country that does not have adequate AML/CFT regimes;
    • (ii) prohibiting obliged entities from establishing branches or representative offices in the third country concerned, or otherwise taking into account the fact that the relevant branch or representative office would be in a third country that does not have adequate AML/CFT regimes;
    • (iii) requiring increased supervisory examination or increased external audit requirements for branches and subsidiaries of obliged entities located in the third country concerned;
    • (iv) requiring increased external audit requirements for financial groups with respect to any of their branches and subsidiaries located in the third country concerned;
    • (v) requiring credit institutions and financial institutions to review and amend, or if necessary terminate, correspondent relationships with respondent institutions in the third country concerned.

Für die Zwecke der Artikel 29 und 31 kann die Kommission aus den folgenden Gegenmaßnahmen auswählen:

  • a) Gegenmaßnahmen, die Verpflichtete gegenüber natürlichen und juristischen Personen im Zusammenhang mit Hochrisiko-Drittländern und gegebenenfalls anderen Ländern, die eine Bedrohung für das Finanzsystem der Union darstellen, anzuwenden haben, darunter:
    • i) Anwendung zusätzlicher Elemente verstärkter Sorgfaltspflichten;
    • ii) Einführung verstärkter einschlägiger Meldemechanismen oder einer systematischen Meldung von Finanztransaktionen;
    • iii) Beschränkung von Geschäftsbeziehungen oder Transaktionen mit natürlichen oder juristischen Personen aus diesen Drittländern;
  • b) Gegenmaßnahmen, die die Mitgliedstaaten gegenüber Hochrisiko-Drittländern und gegebenenfalls anderen Ländern, die eine Bedrohung für das Finanzsystem der Union darstellen, anzuwenden haben, darunter:
    • i) Verweigerung der Errichtung von Tochterunternehmen, Zweigniederlassungen oder Repräsentanzen von Verpflichteten aus dem betreffenden Land oder anderweitige Berücksichtigung der Tatsache, dass der betreffende Verpflichtete aus einem Drittland stammt, das nicht über angemessene AML/CFT-Regelungen verfügt;
    • ii) Verbot der Errichtung von Zweigniederlassungen oder Repräsentanzen durch Verpflichtete in dem betreffenden Drittland oder anderweitige Berücksichtigung der Tatsache, dass sich die betreffende Zweigniederlassung oder Repräsentanz in einem Drittland befinden würde, das nicht über angemessene AML/CFT-Regelungen verfügt;
    • iii) Forderung einer verstärkten aufsichtlichen Prüfung oder verstärkter Anforderungen an die externe Prüfung von Zweigniederlassungen und Tochterunternehmen von Verpflichteten in dem betreffenden Drittland;
    • iv) Forderung verstärkter Anforderungen an die externe Prüfung von Finanzgruppen in Bezug auf deren Zweigniederlassungen und Tochterunternehmen in dem betreffenden Drittland;
    • v) Verpflichtung von Kreditinstituten und Finanzinstituten, Korrespondenzbeziehungen mit Respondenzinstituten in dem betreffenden Drittland zu überprüfen und zu ändern oder erforderlichenfalls zu beenden.
Article 36 — Specific enhanced due diligence measures for cross-border correspondent relationships Article 36 — Specific enhanced due diligence measures for cross-border correspondent relationships Article 36 — Spezifische verstärkte Sorgfaltspflichten für grenzüberschreitende Korrespondenzbeziehungen

With respect to cross-border correspondent relationships, including relationships established for securities transactions or fund transfers, involving the execution of payments with a third-country respondent institution, in addition to the customer due diligence measures laid down in Article 20, credit institutions and financial institutions shall, when entering into a business relationship, be required to:

  • (a) gather sufficient information about the respondent institution to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the institution and the quality of supervision;
  • (b) assess the respondent institution’s AML/CFT controls;
  • (c) obtain approval from senior management before establishing new correspondent relationships;
  • (d) document the respective responsibilities of each institution;
  • (e) with respect to payable-through accounts, be satisfied that the respondent institution has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent institution, and that it is able to provide relevant customer due diligence data to the correspondent institution, upon request.

Where credit institutions and financial institutions decide to terminate cross-border correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision.

With respect to cross-border correspondent relationships, including relationships established for securities transactions or fund transfers, involving the execution of payments with a third-country respondent institution, in addition to the customer due diligence measures laid down in Article 20, credit institutions and financial institutions shall, when entering into a business relationship, be required to:

  • (a) gather sufficient information about the respondent institution to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the institution and the quality of supervision;
  • (b) assess the respondent institution’s AML/CFT controls;
  • (c) obtain approval from senior management before establishing new correspondent relationships;
  • (d) document the respective responsibilities of each institution;
  • (e) with respect to payable-through accounts, be satisfied that the respondent institution has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent institution, and that it is able to provide relevant customer due diligence data to the correspondent institution, upon request.

Where credit institutions and financial institutions decide to terminate cross-border correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision.

Bei grenzüberschreitenden Korrespondenzbeziehungen, einschließlich für Wertpapiertransaktionen oder Geldtransfers eingerichteter Beziehungen, die die Ausführung von Zahlungen mit einem Respondenzinstitut in einem Drittland umfassen, müssen Kreditinstitute und Finanzinstitute zusätzlich zu den in Artikel 20 festgelegten Sorgfaltspflichten gegenüber Kunden bei Begründung einer Geschäftsbeziehung:

  • a) ausreichende Informationen über das Respondenzinstitut einholen, um die Art seiner Geschäftstätigkeit vollständig zu verstehen und anhand öffentlich verfügbarer Informationen seinen Ruf und die Qualität seiner Beaufsichtigung zu beurteilen;
  • b) die AML/CFT-Kontrollen des Respondenzinstituts bewerten;
  • c) vor der Begründung neuer Korrespondenzbeziehungen die Zustimmung der Führungsebene einholen;
  • d) die jeweiligen Verantwortlichkeiten der Institute dokumentieren;
  • e) bei Durchlaufkonten sicherstellen, dass das Respondenzinstitut die Identität der Kunden mit direktem Zugang zu Konten des Korrespondenzinstituts überprüft und ihnen gegenüber eine laufende Sorgfaltspflicht erfüllt hat und dass es dem Korrespondenzinstitut auf Anfrage einschlägige Daten zur Sorgfaltspflicht gegenüber Kunden bereitstellen kann.

Beschließen Kreditinstitute und Finanzinstitute, grenzüberschreitende Korrespondenzbeziehungen aus Gründen im Zusammenhang mit der AML/CFT-Politik zu beenden, so dokumentieren sie ihre Entscheidung.

Article 37 — Specific enhanced due diligence measures for cross-border correspondent relationships for crypto-asset service providers Article 37 — Specific enhanced due diligence measures for cross-border correspondent relationships for crypto-asset service providers Article 37 — Spezifische verstärkte Sorgfaltspflichten für grenzüberschreitende Korrespondenzbeziehungen für Anbieter von Kryptowerte-Dienstleistungen
1 1 1

By way of derogation from Article 36, with respect to cross-border correspondent relationships involving the execution of crypto-asset services, with a respondent entity not established in the Union and providing similar services, including transfers of crypto-assets, crypto-asset service providers shall, in addition to the customer due diligence measures laid down in Article 20, when entering into a business relationship, be required to:

  • (a) determine if the respondent entity is licensed or registered;
  • (b) gather sufficient information about the respondent entity to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the entity and the quality of supervision;
  • (c) assess the respondent entity’s AML/CFT controls;
  • (d) obtain approval from senior management before establishing the new correspondent relationship;
  • (e) document the respective responsibilities of each party to the correspondent relationship;
  • (f) with respect to payable-through crypto-asset accounts, be satisfied that the respondent entity has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent entity, and that it is able to provide relevant customer due diligence data to the correspondent entity, upon request.

Where crypto-asset service providers decide to terminate correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision.Crypto-asset service providers shall update the due diligence information for the correspondent relationship on a regular basis or when new risks emerge in relation to the respondent entity.

By way of derogation from Article 36, with respect to cross-border correspondent relationships involving the execution of crypto-asset services, with a respondent entity not established in the Union and providing similar services, including transfers of crypto-assets, crypto-asset service providers shall, in addition to the customer due diligence measures laid down in Article 20, when entering into a business relationship, be required to:

  • (a) determine if the respondent entity is licensed or registered;
  • (b) gather sufficient information about the respondent entity to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the entity and the quality of supervision;
  • (c) assess the respondent entity’s AML/CFT controls;
  • (d) obtain approval from senior management before establishing the new correspondent relationship;
  • (e) document the respective responsibilities of each party to the correspondent relationship;
  • (f) with respect to payable-through crypto-asset accounts, be satisfied that the respondent entity has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent entity, and that it is able to provide relevant customer due diligence data to the correspondent entity, upon request.

Where crypto-asset service providers decide to terminate correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision. Crypto-asset service providers shall update the due diligence information for the correspondent relationship on a regular basis or when new risks emerge in relation to the respondent entity.

Abweichend von Artikel 36 müssen Anbieter von Kryptowerte-Dienstleistungen bei grenzüberschreitenden Korrespondenzbeziehungen, die die Erbringung von Kryptowerte-Dienstleistungen mit einem nicht in der Union niedergelassenen Respondenzunternehmen umfassen, das ähnliche Dienstleistungen, einschließlich Transfers von Kryptowerten, erbringt, zusätzlich zu den in Artikel 20 festgelegten Sorgfaltspflichten gegenüber Kunden bei Begründung einer Geschäftsbeziehung:

  • a) feststellen, ob das Respondenzunternehmen zugelassen oder registriert ist;
  • b) ausreichende Informationen über das Respondenzunternehmen einholen, um die Art seiner Geschäftstätigkeit vollständig zu verstehen und anhand öffentlich verfügbarer Informationen seinen Ruf und die Qualität seiner Beaufsichtigung zu beurteilen;
  • c) die AML/CFT-Kontrollen des Respondenzunternehmens bewerten;
  • d) vor der Begründung der neuen Korrespondenzbeziehung die Zustimmung der Führungsebene einholen;
  • e) die jeweiligen Verantwortlichkeiten jeder Partei der Korrespondenzbeziehung dokumentieren;
  • f) bei Durchlaufkonten für Kryptowerte sicherstellen, dass das Respondenzunternehmen die Identität der Kunden mit direktem Zugang zu Konten des Korrespondenzunternehmens überprüft und ihnen gegenüber eine laufende Sorgfaltspflicht erfüllt hat und dass es dem Korrespondenzunternehmen auf Anfrage einschlägige Daten zur Sorgfaltspflicht gegenüber Kunden bereitstellen kann.

Beschließen Anbieter von Kryptowerte-Dienstleistungen, Korrespondenzbeziehungen aus Gründen im Zusammenhang mit der AML/CFT-Politik zu beenden, so dokumentieren sie ihre Entscheidung. Anbieter von Kryptowerte-Dienstleistungen aktualisieren die Sorgfaltsinformationen für die Korrespondenzbeziehung regelmäßig oder sobald im Zusammenhang mit dem Respondenzunternehmen neue Risiken entstehen.

2 2 2

Crypto-asset service providers shall take into account the information collected pursuant to paragraph 1 in order to determine, on a risk sensitive basis, the appropriate measures to be taken to mitigate the risks associated with the respondent entity.

Crypto-asset service providers shall take into account the information collected pursuant to paragraph 1 in order to determine, on a risk sensitive basis, the appropriate measures to be taken to mitigate the risks associated with the respondent entity.

Anbieter von Kryptowerte-Dienstleistungen berücksichtigen die gemäß Absatz 1 erhobenen Informationen, um risikosensitiv die geeigneten Maßnahmen zur Minderung der mit dem Respondenzunternehmen verbundenen Risiken zu bestimmen.

3 3 3

By 10 July 2027, AMLA shall issue guidelines to specify the criteria and elements that crypto-asset service providers shall take into account for conducting the assessment referred to in paragraph 1 and the risk mitigating measures referred to in paragraph 2, including the minimum action to be taken by crypto-asset service providers upon identification that the respondent entity is not registered or licensed.

By 10 July 2027, AMLA shall issue guidelines to specify the criteria and elements that crypto-asset service providers shall take into account for conducting the assessment referred to in paragraph 1 and the risk mitigating measures referred to in paragraph 2, including the minimum action to be taken by crypto-asset service providers upon identification that the respondent entity is not registered or licensed.

Bis zum 10. Juli 2027 gibt die AMLA Leitlinien heraus, in denen die Kriterien und Elemente festgelegt werden, die Anbieter von Kryptowerte-Dienstleistungen bei der Durchführung der in Absatz 1 genannten Bewertung und bei den in Absatz 2 genannten risikomindernden Maßnahmen berücksichtigen müssen, einschließlich der Mindestmaßnahmen, die Anbieter von Kryptowerte-Dienstleistungen zu ergreifen haben, wenn sie feststellen, dass das Respondenzunternehmen nicht registriert oder zugelassen ist.

Article 38 — Specific measures for individual third-country respondent institutions Article 38 — Specific measures for individual third-country respondent institutions Article 38 — Spezifische Maßnahmen für einzelne Respondenzinstitute in Drittländern
1 1 1

Credit institutions and financial institutions shall apply the measures laid down in paragraph 6 of this Article in relation to third-country respondent institutions with which they have a correspondent relationship pursuant to Articles 36 or 37 and in respect of which AMLA issues a recommendation pursuant to paragraph 2 of this Article.

Credit institutions and financial institutions shall apply the measures laid down in paragraph 6 of this Article in relation to third-country respondent institutions with which they have a correspondent relationship pursuant to Articles 36 or 37 and in respect of which AMLA issues a recommendation pursuant to paragraph 2 of this Article.

Kreditinstitute und Finanzinstitute wenden gegenüber Respondenzinstituten in Drittländern, mit denen sie gemäß Artikel 36 oder 37 eine Korrespondenzbeziehung unterhalten und zu denen die AMLA gemäß Absatz 2 dieses Artikels eine Empfehlung abgibt, die in Absatz 6 dieses Artikels festgelegten Maßnahmen an.

2 2 2

AMLA shall issue a recommendation addressed to credit institutions and financial institutions where there are concerns that respondent institutions in third countries fall into any of the following situations:

  • (a) they are in serious, repeated or systematic breach of AML/CFT requirements;
  • (b) they have weaknesses in their internal policies, procedures and controls that are likely to result in serious, repeated or systematic breaches of AML/CFT requirements;
  • (c) they have in place internal policies, procedures and controls that are not commensurate with the risks of money laundering, its predicate offences and terrorist financing to which the third-country respondent institution is exposed.

AMLA shall issue a recommendation addressed to credit institutions and financial institutions where there are concerns that respondent institutions in third countries fall into any of the following situations:

  • (a) they are in serious, repeated or systematic breach of AML/CFT requirements;
  • (b) they have weaknesses in their internal policies, procedures and controls that are likely to result in serious, repeated or systematic breaches of AML/CFT requirements;
  • (c) they have in place internal policies, procedures and controls that are not commensurate with the risks of money laundering, its predicate offences and terrorist financing to which the third-country respondent institution is exposed.

Die AMLA gibt eine an Kreditinstitute und Finanzinstitute gerichtete Empfehlung ab, wenn Anlass zu der Annahme besteht, dass Respondenzinstitute in Drittländern eine der folgenden Situationen aufweisen:

  • a) Sie verstoßen schwerwiegend, wiederholt oder systematisch gegen AML/CFT-Anforderungen;
  • b) ihre internen Strategien, Verfahren und Kontrollen weisen Schwächen auf, die wahrscheinlich zu schwerwiegenden, wiederholten oder systematischen Verstößen gegen AML/CFT-Anforderungen führen;
  • c) ihre internen Strategien, Verfahren und Kontrollen stehen nicht im angemessenen Verhältnis zu den Risiken der Geldwäsche, ihrer Vortaten und der Terrorismusfinanzierung, denen das Respondenzinstitut in dem Drittland ausgesetzt ist.
3 3 3

The recommendation referred to in paragraph 2 shall be issued where all of the following conditions are met:

  • (a) on the basis of the information available in the context of its supervisory activities, a financial supervisor, including AMLA when performing its supervisory activities, deems that a third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship;
  • (b) following an assessment of the information available to the financial supervisor referred to in point (a) of this paragraph, there is an agreement among financial supervisors in the Union that the third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship.

The recommendation referred to in paragraph 2 shall be issued where all of the following conditions are met:

  • (a) on the basis of the information available in the context of its supervisory activities, a financial supervisor, including AMLA when performing its supervisory activities, deems that a third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship;
  • (b) following an assessment of the information available to the financial supervisor referred to in point (a) of this paragraph, there is an agreement among financial supervisors in the Union that the third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship.

Die in Absatz 2 genannte Empfehlung wird abgegeben, wenn alle folgenden Voraussetzungen erfüllt sind:

  • a) Ein Finanzaufsichtsbehörde, einschließlich der AMLA bei Wahrnehmung ihrer Aufsichtstätigkeiten, ist auf der Grundlage der im Rahmen ihrer Aufsichtstätigkeiten verfügbaren Informationen der Auffassung, dass ein Respondenzinstitut in einem Drittland eine der in Absatz 2 aufgeführten Situationen aufweist und die Risikoexposition der Korrespondenzbeziehung beeinflussen kann;
  • b) nach Bewertung der der in Buchstabe a dieses Absatzes genannten Finanzaufsichtsbehörde verfügbaren Informationen besteht Einigkeit zwischen den Finanzaufsichtsbehörden in der Union darüber, dass das Respondenzinstitut in dem Drittland eine der in Absatz 2 aufgeführten Situationen aufweist und die Risikoexposition der Korrespondenzbeziehung beeinflussen kann.
4 4 4

Prior to issuing the recommendation referred to in paragraph 2, AMLA shall consult the third-country supervisor in charge of the respondent institution and request that it provides its own as well as the respondent institution’s views on the adequacy of AML/CFT policies, procedures and controls as well as of the customer due diligence measures the respondent institution has in place to mitigate risks of money laundering, its predicate offences and terrorist financing and remedial measures to be put in place. Where no reply is provided within 2 months or where the reply provided does not indicate that the third-country respondent institution can implement satisfactory AML/CFT policies, procedures and controls as well as apply adequate customer due diligence measures to mitigate the risks to which it is exposed that may affect the correspondent relationship, AMLA shall proceed with the recommendation.

Prior to issuing the recommendation referred to in paragraph 2, AMLA shall consult the third-country supervisor in charge of the respondent institution and request that it provides its own as well as the respondent institution’s views on the adequacy of AML/CFT policies, procedures and controls as well as of the customer due diligence measures the respondent institution has in place to mitigate risks of money laundering, its predicate offences and terrorist financing and remedial measures to be put in place. Where no reply is provided within 2 months or where the reply provided does not indicate that the third-country respondent institution can implement satisfactory AML/CFT policies, procedures and controls as well as apply adequate customer due diligence measures to mitigate the risks to which it is exposed that may affect the correspondent relationship, AMLA shall proceed with the recommendation.

Vor Abgabe der in Absatz 2 genannten Empfehlung konsultiert die AMLA die für das Respondenzinstitut zuständige Aufsichtsbehörde des Drittlands und fordert sie auf, sowohl ihre eigene Auffassung als auch die Auffassung des Respondenzinstituts zur Angemessenheit der AML/CFT-Strategien, -Verfahren und -Kontrollen sowie der vom Respondenzinstitut eingerichteten Sorgfaltspflichten gegenüber Kunden zur Minderung der Risiken der Geldwäsche, ihrer Vortaten und der Terrorismusfinanzierung und der zu ergreifenden Abhilfemaßnahmen mitzuteilen. Wird innerhalb von zwei Monaten keine Antwort erteilt oder ergibt sich aus der Antwort nicht, dass das Respondenzinstitut in dem Drittland zufriedenstellende AML/CFT-Strategien, -Verfahren und -Kontrollen umsetzen und angemessene Sorgfaltspflichten gegenüber Kunden anwenden kann, um die Risiken, denen es ausgesetzt ist und die die Korrespondenzbeziehung beeinträchtigen können, zu mindern, so fährt die AMLA mit der Empfehlung fort.

5 5 5

AMLA shall withdraw the recommendation referred to in paragraph 2 as soon as it considers that a third-country respondent institution on which it adopted that recommendation no longer fulfils the conditions laid down in paragraph 3.

AMLA shall withdraw the recommendation referred to in paragraph 2 as soon as it considers that a third-country respondent institution on which it adopted that recommendation no longer fulfils the conditions laid down in paragraph 3.

Die AMLA nimmt die in Absatz 2 genannte Empfehlung zurück, sobald sie der Auffassung ist, dass ein Respondenzinstitut in einem Drittland, für das sie diese Empfehlung abgegeben hat, die in Absatz 3 festgelegten Voraussetzungen nicht mehr erfüllt.

6 6 6

In relation to third-country respondent institutions referred to in paragraph 1, credit institutions and financial institutions shall:

  • (a) abstain from entering into new business relationships with the third-country respondent institution unless they conclude, on the basis of the information collected under Article 36 or 37, that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship;
  • (b) for ongoing business relationships with the third-country respondent institution:

    • (i) review and update the information on the respondent institution pursuant to Articles 36 or 37;
    • (ii) terminate the business relationship unless they conclude, on the basis of the information collected under point (i), that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship;
  • (c) inform the respondent institution of the conclusions they have drawn in relation to the risks posed by the correspondent relationship following the recommendation by AMLA and the measures taken pursuant to points (a) or (b).

Where AMLA has withdrawn a recommendation pursuant to paragraph 5, credit institutions and financial institutions shall review their assessment as to whether the third-country respondent institutions fulfil any of the conditions laid down in paragraph 3.

In relation to third-country respondent institutions referred to in paragraph 1, credit institutions and financial institutions shall:

  • (a) abstain from entering into new business relationships with the third-country respondent institution unless they conclude, on the basis of the information collected under Article 36 or 37, that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship;
  • (b) for ongoing business relationships with the third-country respondent institution:
    • (i) review and update the information on the respondent institution pursuant to Articles 36 or 37;
    • (ii) terminate the business relationship unless they conclude, on the basis of the information collected under point (i), that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship;
  • (c) inform the respondent institution of the conclusions they have drawn in relation to the risks posed by the correspondent relationship following the recommendation by AMLA and the measures taken pursuant to points (a) or (b).

Where AMLA has withdrawn a recommendation pursuant to paragraph 5, credit institutions and financial institutions shall review their assessment as to whether the third-country respondent institutions fulfil any of the conditions laid down in paragraph 3.

In Bezug auf die in Absatz 1 genannten Respondenzinstitute in Drittländern müssen Kreditinstitute und Finanzinstitute:

  • a) davon absehen, neue Geschäftsbeziehungen mit dem Respondenzinstitut in dem Drittland zu begründen, es sei denn, sie gelangen auf der Grundlage der gemäß Artikel 36 oder 37 erhobenen Informationen zu dem Schluss, dass die auf die Geschäftsbeziehung angewandten risikomindernden Maßnahmen und die beim Respondenzinstitut in dem Drittland bestehenden Maßnahmen die mit dieser Geschäftsbeziehung verbundenen Risiken der Geldwäsche und der Terrorismusfinanzierung angemessen mindern können;
  • b) bei bestehenden Geschäftsbeziehungen mit dem Respondenzinstitut in dem Drittland:
    • i) die Informationen über das Respondenzinstitut gemäß Artikel 36 oder 37 überprüfen und aktualisieren;
    • ii) die Geschäftsbeziehung beenden, es sei denn, sie gelangen auf der Grundlage der gemäß Ziffer i erhobenen Informationen zu dem Schluss, dass die auf die Geschäftsbeziehung angewandten risikomindernden Maßnahmen und die beim Respondenzinstitut bestehenden Maßnahmen die damit verbundenen Risiken der Geldwäsche und der Terrorismusfinanzierung angemessen mindern können;
  • c) das Respondenzinstitut über die Schlussfolgerungen zu den Risiken der Korrespondenzbeziehung nach der Empfehlung der AMLA und über die gemäß Buchstabe a oder b ergriffenen Maßnahmen unterrichten.

Hat die AMLA eine Empfehlung gemäß Absatz 5 zurückgenommen, so überprüfen Kreditinstitute und Finanzinstitute ihre Bewertung, ob die Respondenzinstitute in Drittländern eine der in Absatz 3 festgelegten Voraussetzungen erfüllen.

7 7 7

Credit institutions and financial institutions shall document any decision taken pursuant to this Article.

Credit institutions and financial institutions shall document any decision taken pursuant to this Article.

Kreditinstitute und Finanzinstitute dokumentieren jede gemäß diesem Artikel getroffene Entscheidung.

Article 39 — Prohibition of correspondent relationships with shell institutions Article 39 — Prohibition of correspondent relationships with shell institutions Article 39 — Verbot von Korrespondenzbeziehungen mit Mantelinstituten
1 1 1

Credit institutions and financial institutions shall not enter into, or continue, a correspondent relationship with a shell institution. Credit institutions and financial institutions shall take appropriate measures to ensure that they do not engage in or continue correspondent relationships with a credit institution or financial institution that is known to allow its accounts to be used by a shell institution.

Credit institutions and financial institutions shall not enter into, or continue, a correspondent relationship with a shell institution. Credit institutions and financial institutions shall take appropriate measures to ensure that they do not engage in or continue correspondent relationships with a credit institution or financial institution that is known to allow its accounts to be used by a shell institution.

Kreditinstitute und Finanzinstitute dürfen keine Korrespondenzbeziehung mit einem Mantelinstitut begründen oder fortführen. Kreditinstitute und Finanzinstitute ergreifen geeignete Maßnahmen, um sicherzustellen, dass sie keine Korrespondenzbeziehungen mit einem Kreditinstitut oder Finanzinstitut eingehen oder fortführen, von dem bekannt ist, dass es einem Mantelinstitut die Nutzung seiner Konten gestattet.

2 2 2

In addition to the requirement laid down in paragraph 1, crypto-asset service providers shall ensure that their accounts are not used by shell institutions to provide crypto-asset services. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls to detect any attempt to use their accounts for the provision of unregulated crypto-asset services.

In addition to the requirement laid down in paragraph 1, crypto-asset service providers shall ensure that their accounts are not used by shell institutions to provide crypto-asset services. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls to detect any attempt to use their accounts for the provision of unregulated crypto-asset services.

Zusätzlich zu der in Absatz 1 festgelegten Anforderung stellen Anbieter von Kryptowerte-Dienstleistungen sicher, dass ihre Konten nicht von Mantelinstituten zur Erbringung von Kryptowerte-Dienstleistungen genutzt werden. Zu diesem Zweck verfügen Anbieter von Kryptowerte-Dienstleistungen über interne Strategien, Verfahren und Kontrollen, mit denen jeder Versuch erkannt werden kann, ihre Konten zur Erbringung nicht regulierter Kryptowerte-Dienstleistungen zu nutzen.

Article 40 — Measures to mitigate risks in relation to transactions with a self-hosted address Article 40 — Measures to mitigate risks in relation to transactions with a self-hosted address Article 40 — Maßnahmen zur Minderung der Risiken im Zusammenhang mit Transaktionen mit einer selbstverwalteten Adresse
1 1 1

Crypto-asset service providers shall identify and assess the risk of money laundering and financing of terrorism associated with transfers of crypto-assets directed to or originating from a self-hosted address. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls.

Crypto-asset service providers shall apply mitigating measures commensurate with the risks identified. Those mitigating measures shall include one or more of the following:

  • (a) taking risk-based measures to identify, and verify the identity of, the originator or beneficiary of a transfer made from or to a self-hosted address or beneficial owner of such originator or beneficiary, including through reliance on third parties;
  • (b) requiring additional information on the origin and destination of the crypto-assets;
  • (c) conducting enhanced ongoing monitoring of transactions with a self-hosted address;
  • (d) any other measure to mitigate and manage the risks of money laundering and financing of terrorism as well as the risk of non-implementation and evasion of targeted financial sanctions.

Crypto-asset service providers shall identify and assess the risk of money laundering and financing of terrorism associated with transfers of crypto-assets directed to or originating from a self-hosted address. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls.

Crypto-asset service providers shall apply mitigating measures commensurate with the risks identified. Those mitigating measures shall include one or more of the following:

  • (a) taking risk-based measures to identify, and verify the identity of, the originator or beneficiary of a transfer made from or to a self-hosted address or beneficial owner of such originator or beneficiary, including through reliance on third parties;
  • (b) requiring additional information on the origin and destination of the crypto-assets;
  • (c) conducting enhanced ongoing monitoring of transactions with a self-hosted address;
  • (d) any other measure to mitigate and manage the risks of money laundering and financing of terrorism as well as the risk of non-implementation and evasion of targeted financial sanctions.

Anbieter von Kryptowerte-Dienstleistungen ermitteln und bewerten das mit Transfers von Kryptowerten zu oder von einer selbstverwalteten Adresse verbundene Risiko der Geldwäsche und der Terrorismusfinanzierung. Zu diesem Zweck verfügen Anbieter von Kryptowerte-Dienstleistungen über interne Strategien, Verfahren und Kontrollen.

Anbieter von Kryptowerte-Dienstleistungen wenden risikomindernde Maßnahmen an, die den festgestellten Risiken angemessen sind. Diese Maßnahmen umfassen eine oder mehrere der folgenden Maßnahmen:

  • a) Ergreifung risikobasierter Maßnahmen zur Identifizierung und Überprüfung der Identität des Auftraggebers oder Begünstigten eines von einer selbstverwalteten Adresse vorgenommenen oder an diese gerichteten Transfers oder des wirtschaftlichen Eigentümers eines solchen Auftraggebers oder Begünstigten, auch unter Rückgriff auf Dritte;
  • b) Verlangen zusätzlicher Informationen über Herkunft und Ziel der Kryptowerte;
  • c) Durchführung einer verstärkten laufenden Überwachung von Transaktionen mit einer selbstverwalteten Adresse;
  • d) jede andere Maßnahme zur Minderung und Steuerung der Risiken der Geldwäsche und der Terrorismusfinanzierung sowie des Risikos der Nichtumsetzung und Umgehung gezielter finanzieller Sanktionen.
2 2 2

By 10 July 2027, AMLA shall issue guidelines to specify the mitigating measures referred to in paragraph 1, including:

  • (a) the criteria and means for identification and verification of the identity of the originator or beneficiary of a transfer made from or to a self-hosted address, including through reliance on third parties, taking into account the latest technological developments;
  • (b) criteria and means for the verification of whether or not the self-hosted address is owned or controlled by a customer.

By 10 July 2027, AMLA shall issue guidelines to specify the mitigating measures referred to in paragraph 1, including:

  • (a) the criteria and means for identification and verification of the identity of the originator or beneficiary of a transfer made from or to a self-hosted address, including through reliance on third parties, taking into account the latest technological developments;
  • (b) criteria and means for the verification of whether or not the self-hosted address is owned or controlled by a customer.

Bis zum 10. Juli 2027 gibt die AMLA Leitlinien heraus, in denen die in Absatz 1 genannten risikomindernden Maßnahmen festgelegt werden, einschließlich:

  • a) der Kriterien und Mittel zur Identifizierung und Überprüfung der Identität des Auftraggebers oder Begünstigten eines von einer selbstverwalteten Adresse vorgenommenen oder an diese gerichteten Transfers, auch unter Rückgriff auf Dritte, unter Berücksichtigung der neuesten technologischen Entwicklungen;
  • b) der Kriterien und Mittel zur Überprüfung, ob die selbstverwaltete Adresse einem Kunden gehört oder von ihm kontrolliert wird.
Article 41 — Specific provisions regarding applicants for residence by investment schemes Article 41 — Specific provisions regarding applicants for residence by investment schemes Article 41 — Spezifische Bestimmungen für Antragsteller im Rahmen von Aufenthaltsregelungen für Investoren

In addition to the customer due diligence measures laid down in Article 20, with respect to customers who are third-country nationals who are in the process of applying for residence rights in a Member State in exchange for any kind of investment, including transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity contributing to the public good and contributions to the state budget, obliged entities shall, as a minimum, apply enhanced due diligence measures set out in Article 34(4), points (a), (c), (e) and (f).

In addition to the customer due diligence measures laid down in Article 20, with respect to customers who are third-country nationals who are in the process of applying for residence rights in a Member State in exchange for any kind of investment, including transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity contributing to the public good and contributions to the state budget, obliged entities shall, as a minimum, apply enhanced due diligence measures set out in Article 34(4), points (a), (c), (e) and (f).

Zusätzlich zu den in Artikel 20 festgelegten Sorgfaltspflichten gegenüber Kunden wenden die Verpflichteten gegenüber Kunden, die Staatsangehörige eines Drittlands sind und ein Aufenthaltsrecht in einem Mitgliedstaat gegen irgendeine Art von Investition beantragen, einschließlich Transfers, des Kaufs oder der Miete von Immobilien, Investitionen in Staatsanleihen, Investitionen in Unternehmen, der Schenkung oder Ausstattung einer dem Gemeinwohl dienenden Tätigkeit und Beiträgen zum Staatshaushalt, mindestens die in Artikel 34 Absatz 4 Buchstaben a, c, e und f festgelegten verstärkten Sorgfaltspflichten an.

Article 42 — Specific provisions regarding politically exposed persons Article 42 — Specific provisions regarding politically exposed persons Article 42 — Spezifische Bestimmungen für politisch exponierte Personen
1 1 1

In addition to the customer due diligence measures laid down in Article 20, obliged entities shall apply the following measures with respect to occasional transactions or business relationships with politically exposed persons:

  • (a) obtain senior management approval for carrying out occasional transactions or for establishing or continuing business relationships with politically exposed persons;
  • (b) take adequate measures to establish the source of wealth and source of funds that are involved in business relationships or occasional transactions with politically exposed persons;
  • (c) conduct enhanced, ongoing monitoring of those business relationships.

In addition to the customer due diligence measures laid down in Article 20, obliged entities shall apply the following measures with respect to occasional transactions or business relationships with politically exposed persons:

  • (a) obtain senior management approval for carrying out occasional transactions or for establishing or continuing business relationships with politically exposed persons;
  • (b) take adequate measures to establish the source of wealth and source of funds that are involved in business relationships or occasional transactions with politically exposed persons;
  • (c) conduct enhanced, ongoing monitoring of those business relationships.

Zusätzlich zu den in Artikel 20 festgelegten Sorgfaltspflichten gegenüber Kunden wenden die Verpflichteten bei gelegentlichen Transaktionen oder Geschäftsbeziehungen mit politisch exponierten Personen folgende Maßnahmen an:

  • a) Einholung der Zustimmung der Führungsebene zur Durchführung gelegentlicher Transaktionen oder zur Begründung oder Fortführung von Geschäftsbeziehungen mit politisch exponierten Personen;
  • b) Ergreifung angemessener Maßnahmen zur Feststellung der Herkunft des Vermögens und der Gelder, die Gegenstand von Geschäftsbeziehungen oder gelegentlichen Transaktionen mit politisch exponierten Personen sind;
  • c) Durchführung einer verstärkten laufenden Überwachung dieser Geschäftsbeziehungen.
2 2 2

By 10 July 2027, AMLA shall issue guidelines on the following matters:

  • (a) the criteria for the identification of persons known to be close associates;
  • (b) the level of risk associated with a particular category of politically exposed person, family member or person known to be a close associate, including guidance on how such risks are to be assessed where the person is no longer entrusted with a prominent public function for the purposes of Article 45.

By 10 July 2027, AMLA shall issue guidelines on the following matters:

  • (a) the criteria for the identification of persons known to be close associates;
  • (b) the level of risk associated with a particular category of politically exposed person, family member or person known to be a close associate, including guidance on how such risks are to be assessed where the person is no longer entrusted with a prominent public function for the purposes of Article 45.

Bis zum 10. Juli 2027 gibt die AMLA Leitlinien zu folgenden Fragen heraus:

  • a) die Kriterien für die Identifizierung von Personen, die bekanntermaßen enge Vertraute sind;
  • b) das mit einer bestimmten Kategorie politisch exponierter Personen, Familienangehöriger oder bekanntermaßen enger Vertrauter verbundene Risikoniveau, einschließlich Leitlinien dazu, wie diese Risiken zu bewerten sind, wenn die Person für die Zwecke des Artikels 45 nicht mehr mit einem wichtigen öffentlichen Amt betraut ist.
Article 43 — List of prominent public functions Article 43 — List of prominent public functions Article 43 — Liste der wichtigen öffentlichen Ämter
1 1 1

Each Member State shall issue and keep up-to-date a list indicating the exact functions which, in accordance with its national laws, regulations and administrative provisions, qualify as prominent public functions for the purposes of Article 2(1), point (34). Member States shall request each international organisation accredited on their territories to issue and keep up-to-date a list of prominent public functions at that international organisation for the purposes of Article 2(1), point (34). Those lists shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Member State level. Member States shall notify those lists, as well as any change made to them, to the Commission and to AMLA.

Each Member State shall issue and keep up-to-date a list indicating the exact functions which, in accordance with its national laws, regulations and administrative provisions, qualify as prominent public functions for the purposes of Article 2(1), point (34). Member States shall request each international organisation accredited on their territories to issue and keep up-to-date a list of prominent public functions at that international organisation for the purposes of Article 2(1), point (34). Those lists shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Member State level. Member States shall notify those lists, as well as any change made to them, to the Commission and to AMLA.

Jeder Mitgliedstaat erstellt und hält eine Liste auf dem neuesten Stand, in der die genauen Funktionen angegeben sind, die nach seinen nationalen Rechts- und Verwaltungsvorschriften für die Zwecke des Artikels 2 Absatz 1 Nummer 34 als wichtige öffentliche Ämter gelten. Die Mitgliedstaaten fordern jede auf ihrem Hoheitsgebiet akkreditierte internationale Organisation auf, eine Liste der bei dieser internationalen Organisation bestehenden wichtigen öffentlichen Ämter für die Zwecke des Artikels 2 Absatz 1 Nummer 34 zu erstellen und auf dem neuesten Stand zu halten. Diese Listen enthalten auch alle Funktionen, die Vertretern von Drittländern und von auf Ebene der Mitgliedstaaten akkreditierten internationalen Einrichtungen übertragen werden können. Die Mitgliedstaaten teilen diese Listen sowie jede daran vorgenommene Änderung der Kommission und der AMLA mit.

2 2 2

The Commission may set out, by means of an implementing act, the format for the establishment and communication of the Member States’ lists of prominent public functions pursuant to paragraph 1. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

The Commission may set out, by means of an implementing act, the format for the establishment and communication of the Member States’ lists of prominent public functions pursuant to paragraph 1. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

Die Kommission kann im Wege eines Durchführungsrechtsakts das Format für die Erstellung und Übermittlung der Listen der Mitgliedstaaten über wichtige öffentliche Ämter gemäß Absatz 1 festlegen. Dieser Durchführungsrechtsakt wird nach dem in Artikel 86 Absatz 2 genannten Prüfverfahren erlassen.

3 3 3

The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement Article 2(1), point (34), where the lists notified by Member States pursuant to paragraph 1 identify common additional categories of prominent public functions and those categories of prominent public functions are of relevance for the Union as a whole.When drawing up delegated acts pursuant to the first subparagraph, the Commission shall consult AMLA.

The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement Article 2(1), point (34), where the lists notified by Member States pursuant to paragraph 1 identify common additional categories of prominent public functions and those categories of prominent public functions are of relevance for the Union as a whole. When drawing up delegated acts pursuant to the first subparagraph, the Commission shall consult AMLA.

Der Kommission wird die Befugnis übertragen, gemäß Artikel 85 delegierte Rechtsakte zur Ergänzung des Artikels 2 Absatz 1 Nummer 34 zu erlassen, wenn die von den Mitgliedstaaten gemäß Absatz 1 mitgeteilten Listen gemeinsame zusätzliche Kategorien wichtiger öffentlicher Ämter ausweisen und diese Kategorien für die Union insgesamt von Bedeutung sind. Bei der Ausarbeitung delegierter Rechtsakte gemäß Unterabsatz 1 konsultiert die Kommission die AMLA.

4 4 4

The Commission shall draw up and keep up-to-date the list of the exact functions which qualify as prominent public functions at the level of the Union. That list shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Union level.

The Commission shall draw up and keep up-to-date the list of the exact functions which qualify as prominent public functions at the level of the Union. That list shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Union level.

Die Kommission erstellt und hält die Liste der genauen Funktionen, die auf Unionsebene als wichtige öffentliche Ämter gelten, auf dem neuesten Stand. Diese Liste enthält auch alle Funktionen, die Vertretern von Drittländern und von auf Unionsebene akkreditierten internationalen Einrichtungen übertragen werden können.

5 5 5

The Commission shall assemble, based on the lists provided for in paragraphs 1 and 4 of this Article, a single list of all prominent public functions for the purposes of Article 2(1), point (34). The Commission shall publish that single list in the Official Journal of the European Union. AMLA shall make that list publicly available on its website.

The Commission shall assemble, based on the lists provided for in paragraphs 1 and 4 of this Article, a single list of all prominent public functions for the purposes of Article 2(1), point (34). The Commission shall publish that single list in the Official Journal of the European Union. AMLA shall make that list publicly available on its website.

Die Kommission erstellt auf der Grundlage der in den Absätzen 1 und 4 dieses Artikels vorgesehenen Listen eine einheitliche Liste aller wichtigen öffentlichen Ämter für die Zwecke des Artikels 2 Absatz 1 Nummer 34. Die Kommission veröffentlicht diese einheitliche Liste im Amtsblatt der Europäischen Union. Die AMLA macht diese Liste auf ihrer Website öffentlich zugänglich.

Article 44 — Politically exposed persons who are beneficiaries of insurance policies Article 44 — Politically exposed persons who are beneficiaries of insurance policies Article 44 — Politisch exponierte Personen, die Begünstigte von Versicherungspolicen sind

Obliged entities shall take reasonable measures to determine whether the beneficiaries of a life or other investment-related insurance policy or, where relevant, the beneficial owner of the beneficiary are politically exposed persons. Those measures shall be taken no later than at the time of the payout or at the time of the assignment, in whole or in part, of the policy. Where there are higher risks identified, in addition to applying the customer due diligence measures laid down in Article 20, obliged entities shall:

  • (a) inform senior management before payout of policy proceeds;
  • (b) conduct enhanced scrutiny of the entire business relationship with the policyholder.

Obliged entities shall take reasonable measures to determine whether the beneficiaries of a life or other investment-related insurance policy or, where relevant, the beneficial owner of the beneficiary are politically exposed persons. Those measures shall be taken no later than at the time of the payout or at the time of the assignment, in whole or in part, of the policy. Where there are higher risks identified, in addition to applying the customer due diligence measures laid down in Article 20, obliged entities shall:

  • (a) inform senior management before payout of policy proceeds;
  • (b) conduct enhanced scrutiny of the entire business relationship with the policyholder.

Verpflichtete haben angemessene Maßnahmen zu ergreifen, um festzustellen, ob es sich bei den Begünstigten einer Lebensversicherung oder einer anderen Versicherung mit Anlagebezug oder gegebenenfalls beim wirtschaftlichen Eigentümer des Begünstigten um politisch exponierte Personen handelt. Diese Maßnahmen sind spätestens zum Zeitpunkt der Auszahlung oder zum Zeitpunkt der vollständigen oder teilweisen Abtretung der Police zu ergreifen. Werden höhere Risiken festgestellt, haben Verpflichtete zusätzlich zur Anwendung der in Artikel 20 festgelegten Sorgfaltspflichten gegenüber Kunden:

  • (a) die Führungsebene vor der Auszahlung der Versicherungsleistung zu informieren;
  • (b) die gesamte Geschäftsbeziehung mit dem Versicherungsnehmer einer verstärkten Überprüfung zu unterziehen.
Article 45 — Measures for persons who cease to be politically exposed persons Article 45 — Measures for persons who cease to be politically exposed persons Article 45 — Maßnahmen für Personen, die nicht mehr politisch exponiert sind
1 1 1

Where a politically exposed person is no longer entrusted with a prominent public function by the Union, a Member State, third country or an international organisation, obliged entities shall take into account the continuing risk posed by that person, as a result of his or her former function, in their assessment of money laundering and terrorist financing risks in accordance with Article 20.

Where a politically exposed person is no longer entrusted with a prominent public function by the Union, a Member State, third country or an international organisation, obliged entities shall take into account the continuing risk posed by that person, as a result of his or her former function, in their assessment of money laundering and terrorist financing risks in accordance with Article 20.

Ist eine politisch exponierte Person nicht mehr mit einem wichtigen öffentlichen Amt bei der Union, einem Mitgliedstaat, einem Drittland oder einer internationalen Organisation betraut, berücksichtigen Verpflichtete bei ihrer Bewertung der Risiken von Geldwäsche und Terrorismusfinanzierung gemäß Artikel 20 das fortbestehende Risiko, das von dieser Person aufgrund ihres früheren Amtes ausgeht.

2 2 2

Obliged entities shall apply one or more of the measures referred to in Article 34(4) to mitigate the risks posed by the politically exposed person until such time as the risks referred to in paragraph 1 of this Article no longer exist, but in any case for not less than 12 months following the time when the individual ceased to be entrusted with a prominent public function.

Obliged entities shall apply one or more of the measures referred to in Article 34(4) to mitigate the risks posed by the politically exposed person until such time as the risks referred to in paragraph 1 of this Article no longer exist, but in any case for not less than 12 months following the time when the individual ceased to be entrusted with a prominent public function.

Verpflichtete wenden eine oder mehrere der in Artikel 34 Absatz 4 genannten Maßnahmen an, um die von der politisch exponierten Person ausgehenden Risiken zu mindern, bis die in Absatz 1 dieses Artikels genannten Risiken nicht mehr bestehen, in jedem Fall jedoch mindestens zwölf Monate nach dem Zeitpunkt, zu dem die Person nicht mehr mit einem wichtigen öffentlichen Amt betraut war.

3 3 3

The obligation referred to in paragraph 2 shall apply accordingly where an obliged entity carries out an occasional transaction or enters into a business relationship with a person who in the past was entrusted with a prominent public function by the Union, a Member State, third country or an international organisation.

The obligation referred to in paragraph 2 shall apply accordingly where an obliged entity carries out an occasional transaction or enters into a business relationship with a person who in the past was entrusted with a prominent public function by the Union, a Member State, third country or an international organisation.

Die in Absatz 2 genannte Verpflichtung gilt entsprechend, wenn ein Verpflichteter ein gelegentliches Geschäft mit einer Person durchführt oder eine Geschäftsbeziehung mit einer Person aufnimmt, die in der Vergangenheit bei der Union, einem Mitgliedstaat, einem Drittland oder einer internationalen Organisation mit einem wichtigen öffentlichen Amt betraut war.

Article 46 — Family members and persons known to be close associates of politically exposed persons Article 46 — Family members and persons known to be close associates of politically exposed persons Article 46 — Familienangehörige und bekanntermaßen enge Vertraute politisch exponierter Personen

The measures referred to in Articles 42, 44 and 45 shall also apply to family members or persons known to be close associates of politically exposed persons.

The measures referred to in Articles 42, 44 and 45 shall also apply to family members or persons known to be close associates of politically exposed persons.

Die in den Artikeln 42, 44 und 45 genannten Maßnahmen gelten auch für Familienangehörige oder bekanntermaßen enge Vertraute politisch exponierter Personen.

SECTION 5 — Specific customer due diligence provisions SECTION 5 — Specific customer due diligence provisions SECTION 5 — Besondere Bestimmungen über die Sorgfaltspflichten gegenüber Kunden
Article 47 — Specifications for the life and other investment-related insurance sector Article 47 — Specifications for the life and other investment-related insurance sector Article 47 — Besonderheiten des Lebensversicherungssektors und des Sektors der sonstigen Versicherungen mit Anlagebezug

For life or other investment-related insurance business, in addition to the customer due diligence measures required for the customer and the beneficial owner, obliged entities shall apply the following customer due diligence measures on the beneficiaries of life insurance and other investment-related insurance policies, as soon as the beneficiaries are identified or designated:

  • (a) in the case of beneficiaries that are identified as specifically named persons or legal arrangements, recording the name of the person or arrangement;
  • (b) in the case of beneficiaries that are designated by characteristics or by class or by other means, obtaining sufficient information concerning those beneficiaries so that it will be able to establish the identity of the beneficiary at the time of the payout.

For the purposes of the first subparagraph, the verification of the identity of the beneficiaries and, where relevant, their beneficial owners shall take place at the time of the payout. In the case of assignment, in whole or in part, of the life or other investment-related insurance to a third party, obliged entities aware of the assignment shall identify the beneficial owner at the time of the assignment to the natural or legal person or legal arrangement receiving for its own benefit the value of the policy assigned.

For life or other investment-related insurance business, in addition to the customer due diligence measures required for the customer and the beneficial owner, obliged entities shall apply the following customer due diligence measures on the beneficiaries of life insurance and other investment-related insurance policies, as soon as the beneficiaries are identified or designated:

  • (a) in the case of beneficiaries that are identified as specifically named persons or legal arrangements, recording the name of the person or arrangement;
  • (b) in the case of beneficiaries that are designated by characteristics or by class or by other means, obtaining sufficient information concerning those beneficiaries so that it will be able to establish the identity of the beneficiary at the time of the payout.

For the purposes of the first subparagraph, the verification of the identity of the beneficiaries and, where relevant, their beneficial owners shall take place at the time of the payout. In the case of assignment, in whole or in part, of the life or other investment-related insurance to a third party, obliged entities aware of the assignment shall identify the beneficial owner at the time of the assignment to the natural or legal person or legal arrangement receiving for its own benefit the value of the policy assigned.

Bei Lebensversicherungen oder sonstigen Versicherungen mit Anlagebezug wenden Verpflichtete zusätzlich zu den für den Kunden und den wirtschaftlichen Eigentümer erforderlichen Sorgfaltspflichten gegenüber Kunden folgende Sorgfaltspflichten gegenüber den Begünstigten von Lebensversicherungen und sonstigen Versicherungen mit Anlagebezug an, sobald die Begünstigten identifiziert oder bestimmt sind:

  • (a) bei Begünstigten, die als namentlich genannte Personen oder Rechtsvereinbarungen identifiziert sind, die Aufzeichnung des Namens der Person oder der Rechtsvereinbarung;
  • (b) bei Begünstigten, die anhand von Merkmalen oder einer Kategorie oder auf andere Weise bestimmt sind, die Einholung ausreichender Informationen über diese Begünstigten, damit die Identität des Begünstigten zum Zeitpunkt der Auszahlung festgestellt werden kann.

Für die Zwecke des Unterabsatzes 1 erfolgt die Überprüfung der Identität der Begünstigten und gegebenenfalls ihrer wirtschaftlichen Eigentümer zum Zeitpunkt der Auszahlung. Im Fall der vollständigen oder teilweisen Abtretung der Lebensversicherung oder sonstigen Versicherung mit Anlagebezug an einen Dritten identifizieren Verpflichtete, die von der Abtretung Kenntnis haben, zum Zeitpunkt der Abtretung den wirtschaftlichen Eigentümer, der den Wert der abgetretenen Police für eigene Rechnung erhält.

SECTION 6 — Reliance on customer due diligence performed by other obliged entities SECTION 6 — Reliance on customer due diligence performed by other obliged entities SECTION 6 — Rückgriff auf von anderen Verpflichteten vorgenommene Sorgfaltsmaßnahmen gegenüber Kunden
Article 48 — General provisions relating to reliance on other obliged entities Article 48 — General provisions relating to reliance on other obliged entities Article 48 — Allgemeine Bestimmungen über den Rückgriff auf andere Verpflichtete
1 1 1

Obliged entities may rely on other obliged entities, whether located in a Member State or in a third country, to meet the customer due diligence requirements laid down in Article 20(1), points (a), (b) and (c), provided that:

  • (a) the other obliged entities apply customer due diligence requirements and record-keeping requirements laid down in this Regulation, or equivalent when the other obliged entities reside or are established in a third country;
  • (b) compliance with AML/CFT requirements by the other obliged entities is supervised in a manner consistent with Chapter IV of Directive (EU) 2024/1640.

The ultimate responsibility for meeting the customer due diligence requirements shall remain with the obliged entity which relies on another obliged entity.

Obliged entities may rely on other obliged entities, whether located in a Member State or in a third country, to meet the customer due diligence requirements laid down in Article 20(1), points (a), (b) and (c), provided that:

  • (a) the other obliged entities apply customer due diligence requirements and record-keeping requirements laid down in this Regulation, or equivalent when the other obliged entities reside or are established in a third country;
  • (b) compliance with AML/CFT requirements by the other obliged entities is supervised in a manner consistent with Chapter IV of Directive (EU) 2024/1640.

The ultimate responsibility for meeting the customer due diligence requirements shall remain with the obliged entity which relies on another obliged entity.

Verpflichtete dürfen sich zur Erfüllung der in Artikel 20 Absatz 1 Buchstaben a, b und c festgelegten Sorgfaltspflichten gegenüber Kunden auf andere Verpflichtete stützen, unabhängig davon, ob diese in einem Mitgliedstaat oder einem Drittland ansässig sind, sofern:

  • (a) die anderen Verpflichteten die in dieser Verordnung festgelegten Sorgfalts- und Aufzeichnungspflichten oder, wenn sie in einem Drittland ansässig oder niedergelassen sind, gleichwertige Anforderungen anwenden;
  • (b) die Einhaltung der AML/CFT-Anforderungen durch die anderen Verpflichteten in einer mit Kapitel IV der Richtlinie (EU) 2024/1640 im Einklang stehenden Weise beaufsichtigt wird.

Die letztendliche Verantwortung für die Erfüllung der Sorgfaltspflichten gegenüber Kunden verbleibt bei dem Verpflichteten, der sich auf einen anderen Verpflichteten stützt.

2 2 2

When deciding to rely on other obliged entities located in third countries, obliged entities shall take into consideration the geographical risk factors listed in Annexes II and III and any relevant information or guidance provided by the Commission, or by AMLA or other competent authorities.

When deciding to rely on other obliged entities located in third countries, obliged entities shall take into consideration the geographical risk factors listed in Annexes II and III and any relevant information or guidance provided by the Commission, or by AMLA or other competent authorities.

Bei der Entscheidung, sich auf in Drittländern ansässige andere Verpflichtete zu stützen, berücksichtigen Verpflichtete die in den Anhängen II und III aufgeführten geografischen Risikofaktoren sowie alle einschlägigen Informationen oder Leitlinien der Kommission, der AMLA oder anderer zuständiger Behörden.

3 3 3

In the case of obliged entities that are part of a group, compliance with the requirements of this Article and of Article 49 may be ensured through group-wide policies, procedures and controls provided that all the following conditions are met:

  • (a) the obliged entity relies on information provided solely by an obliged entity that is part of the same group;
  • (b) the group applies AML/CFT policies and procedures, customer due diligence measures and rules on record-keeping that are fully in compliance with this Regulation, or with equivalent rules in third countries;
  • (c) the effective implementation of the requirements referred to in point (b) of this paragraph is supervised at group level by the supervisory authority of the home Member State in accordance with Chapter IV of Directive (EU) 2024/1640 or of the third country in accordance with the rules of that third country.

In the case of obliged entities that are part of a group, compliance with the requirements of this Article and of Article 49 may be ensured through group-wide policies, procedures and controls provided that all the following conditions are met:

  • (a) the obliged entity relies on information provided solely by an obliged entity that is part of the same group;
  • (b) the group applies AML/CFT policies and procedures, customer due diligence measures and rules on record-keeping that are fully in compliance with this Regulation, or with equivalent rules in third countries;
  • (c) the effective implementation of the requirements referred to in point (b) of this paragraph is supervised at group level by the supervisory authority of the home Member State in accordance with Chapter IV of Directive (EU) 2024/1640 or of the third country in accordance with the rules of that third country.

Bei Verpflichteten, die Teil einer Gruppe sind, kann die Einhaltung der Anforderungen dieses Artikels und des Artikels 49 durch gruppenweite Strategien, Verfahren und Kontrollen sichergestellt werden, sofern alle folgenden Bedingungen erfüllt sind:

  • (a) der Verpflichtete stützt sich ausschließlich auf Informationen eines Verpflichteten, der derselben Gruppe angehört;
  • (b) die Gruppe wendet AML/CFT-Strategien und -Verfahren, Sorgfaltsmaßnahmen gegenüber Kunden sowie Aufzeichnungsvorschriften an, die vollständig mit dieser Verordnung oder mit gleichwertigen Vorschriften in Drittländern übereinstimmen;
  • (c) die wirksame Umsetzung der in Buchstabe b dieses Absatzes genannten Anforderungen wird auf Gruppenebene von der Aufsichtsbehörde des Herkunftsmitgliedstaats gemäß Kapitel IV der Richtlinie (EU) 2024/1640 oder des Drittlands gemäß dessen Vorschriften beaufsichtigt.
4 4 4

Obliged entities shall not rely on obliged entities established in third countries identified pursuant to Section 2 of this Chapter. However, obliged entities established in the Union whose branches and subsidiaries are established in those third countries may rely on those branches and subsidiaries, where all the conditions laid down in paragraph 3, are met.

Obliged entities shall not rely on obliged entities established in third countries identified pursuant to Section 2 of this Chapter. However, obliged entities established in the Union whose branches and subsidiaries are established in those third countries may rely on those branches and subsidiaries, where all the conditions laid down in paragraph 3, are met.

Verpflichtete dürfen sich nicht auf in Drittländern niedergelassene Verpflichtete stützen, die gemäß Abschnitt 2 dieses Kapitels bestimmt wurden. In der Union niedergelassene Verpflichtete, deren Zweigniederlassungen und Tochterunternehmen in diesen Drittländern niedergelassen sind, dürfen sich jedoch auf diese Zweigniederlassungen und Tochterunternehmen stützen, sofern alle in Absatz 3 festgelegten Bedingungen erfüllt sind.

Article 49 — Process of reliance on another obliged entity Article 49 — Process of reliance on another obliged entity Article 49 — Verfahren für den Rückgriff auf einen anderen Verpflichteten
1 1 1

Obliged entities shall obtain from the obliged entity relied upon all the necessary information concerning the customer due diligence measures laid down in Article 20(1), points (a), (b) and (c), or the business being introduced.

Obliged entities shall obtain from the obliged entity relied upon all the necessary information concerning the customer due diligence measures laid down in Article 20(1), points (a), (b) and (c), or the business being introduced.

Verpflichtete holen von dem Verpflichteten, auf den sie sich stützen, alle erforderlichen Informationen über die in Artikel 20 Absatz 1 Buchstaben a, b und c festgelegten Sorgfaltsmaßnahmen gegenüber Kunden oder über das vermittelte Geschäft ein.

2 2 2

Obliged entities which rely on other obliged entities shall take all necessary steps to ensure that the obliged entity relied upon provides, upon request:

  • (a) copies of the information collected to identify the customer;
  • (b) all supporting documents or trustworthy sources of information that were used to verify the identity of the client, and, where relevant, of the customer’s beneficial owners or persons on whose behalf the customer acts, including data obtained through electronic identification means and relevant trust services as set out in Regulation (EU) No 910/2014; and
  • (c) any information collected on the purpose and intended nature of the business relationship.

Obliged entities which rely on other obliged entities shall take all necessary steps to ensure that the obliged entity relied upon provides, upon request:

  • (a) copies of the information collected to identify the customer;
  • (b) all supporting documents or trustworthy sources of information that were used to verify the identity of the client, and, where relevant, of the customer’s beneficial owners or persons on whose behalf the customer acts, including data obtained through electronic identification means and relevant trust services as set out in Regulation (EU) No 910/2014; and
  • (c) any information collected on the purpose and intended nature of the business relationship.

Verpflichtete, die sich auf andere Verpflichtete stützen, ergreifen alle erforderlichen Maßnahmen, um sicherzustellen, dass der Verpflichtete, auf den sie sich stützen, auf Anfrage Folgendes bereitstellt:

  • (a) Kopien der zur Identifizierung des Kunden erhobenen Informationen;
  • (b) alle Belege oder zuverlässigen Informationsquellen, die zur Überprüfung der Identität des Kunden und gegebenenfalls der wirtschaftlichen Eigentümer des Kunden oder der Personen, in deren Auftrag der Kunde handelt, verwendet wurden, einschließlich der mittels elektronischer Identifizierungsmittel und einschlägiger Vertrauensdienste gemäß der Verordnung (EU) Nr. 910/2014 erlangten Daten; und
  • (c) alle Informationen über den Zweck und die beabsichtigte Art der Geschäftsbeziehung.
3 3 3

The information referred to in paragraphs 1 and 2 shall be provided by the obliged entity relied upon without delay and in any case within 5 working days.

The information referred to in paragraphs 1 and 2 shall be provided by the obliged entity relied upon without delay and in any case within 5 working days.

Die in den Absätzen 1 und 2 genannten Informationen werden von dem Verpflichteten, auf den sich der andere Verpflichtete stützt, unverzüglich und in jedem Fall innerhalb von fünf Arbeitstagen bereitgestellt.

4 4 4

The conditions for the transmission of the information and documents mentioned in paragraphs 1 and 2 shall be specified in a written agreement between the obliged entities.

The conditions for the transmission of the information and documents mentioned in paragraphs 1 and 2 shall be specified in a written agreement between the obliged entities.

Die Bedingungen für die Übermittlung der in den Absätzen 1 und 2 genannten Informationen und Dokumente werden in einer schriftlichen Vereinbarung zwischen den Verpflichteten festgelegt.

5 5 5

Where the obliged entity relies on an obliged entity that is part of its group, the written agreement may be replaced by an internal procedure established at group level, provided that the conditions laid down in Article 48(3) are met.

Where the obliged entity relies on an obliged entity that is part of its group, the written agreement may be replaced by an internal procedure established at group level, provided that the conditions laid down in Article 48(3) are met.

Stützt sich ein Verpflichteter auf einen Verpflichteten, der seiner Gruppe angehört, kann die schriftliche Vereinbarung durch ein auf Gruppenebene eingerichtetes internes Verfahren ersetzt werden, sofern die in Artikel 48 Absatz 3 festgelegten Bedingungen erfüllt sind.

Article 50 — Guidelines on reliance on other obliged entities Article 50 — Guidelines on reliance on other obliged entities Article 50 — Leitlinien zum Rückgriff auf andere Verpflichtete

By 10 July 2027, AMLA shall issue guidelines addressed to obliged entities on:

  • (a) the conditions which are acceptable for obliged entities to rely on information collected by another obliged entity, including in the case of remote customer due diligence;
  • (b) the roles and responsibility of the obliged entities involved in a situation of a reliance on another obliged entity;
  • (c) supervisory approaches to reliance on other obliged entities.

By 10 July 2027, AMLA shall issue guidelines addressed to obliged entities on:

  • (a) the conditions which are acceptable for obliged entities to rely on information collected by another obliged entity, including in the case of remote customer due diligence;
  • (b) the roles and responsibility of the obliged entities involved in a situation of a reliance on another obliged entity;
  • (c) supervisory approaches to reliance on other obliged entities.

Bis zum 10. Juli 2027 erlässt die AMLA an Verpflichtete gerichtete Leitlinien zu:

  • (a) den Bedingungen, unter denen sich Verpflichtete auf von einem anderen Verpflichteten erhobene Informationen stützen können, auch im Fall der Fern-Sorgfaltspflichten gegenüber Kunden;
  • (b) den Aufgaben und der Verantwortung der an einem Rückgriff auf einen anderen Verpflichteten beteiligten Verpflichteten;
  • (c) den Aufsichtsansätzen für den Rückgriff auf andere Verpflichtete.
CHAPTER IV — BENEFICIAL OWNERSHIP TRANSPARENCY CHAPTER IV — BENEFICIAL OWNERSHIP TRANSPARENCY CHAPTER IV — TRANSPARENZ DER WIRTSCHAFTLICHEN EIGENTÜMERSCHAFT
Article 51 — Identification of beneficial owners for legal entities Article 51 — Identification of beneficial owners for legal entities Article 51 — Identifizierung der wirtschaftlichen Eigentümer juristischer Personen

Beneficial owners of legal entities shall be the natural persons who:

  • (a) have, directly or indirectly, an ownership interest in the corporate entity; or
  • (b) control, directly or indirectly, the corporate or other legal entity, through ownership interest or via other means.

Control via other means as referred to in the first paragraph, point (b), shall be identified independently of and in parallel to the existence of an ownership interest or control through ownership interest.

Beneficial owners of legal entities shall be the natural persons who:

  • (a) have, directly or indirectly, an ownership interest in the corporate entity; or
  • (b) control, directly or indirectly, the corporate or other legal entity, through ownership interest or via other means.

Control via other means as referred to in the first paragraph, point (b), shall be identified independently of and in parallel to the existence of an ownership interest or control through ownership interest.

Wirtschaftliche Eigentümer juristischer Personen sind die natürlichen Personen, die:

  • (a) unmittelbar oder mittelbar eine Beteiligung an der Gesellschaft halten; oder
  • (b) die Gesellschaft oder sonstige juristische Person unmittelbar oder mittelbar durch eine Beteiligung oder auf andere Weise kontrollieren.

Die in Absatz 1 Buchstabe b genannte Kontrolle auf andere Weise ist unabhängig vom und parallel zum Bestehen einer Beteiligung oder einer Kontrolle durch eine Beteiligung festzustellen.

Article 52 — Beneficial ownership through ownership interest Article 52 — Beneficial ownership through ownership interest Article 52 — Wirtschaftliche Eigentümerschaft durch Beteiligung
1 1 1

For the purpose of Article 51, first paragraph, point (a), an ownership interest in the corporate entity shall mean direct or indirect ownership of 25 % or more of the shares or voting rights or other ownership interest in the corporate entity, including rights to a share of profits, other internal resources or liquidation balance. The indirect ownership shall be calculated by multiplying the shares or voting rights or other ownership interests held by the intermediate entities in the chain of entities in which the beneficial owner holds shares or voting rights and by adding together the results from those various chains, unless Article 54 applies.For the purposes of assessing whether an ownership interest exists in the corporate entity, all shareholdings on every level of ownership shall be taken into account.

For the purpose of Article 51, first paragraph, point (a), an ownership interest in the corporate entity shall mean direct or indirect ownership of 25 % or more of the shares or voting rights or other ownership interest in the corporate entity, including rights to a share of profits, other internal resources or liquidation balance. The indirect ownership shall be calculated by multiplying the shares or voting rights or other ownership interests held by the intermediate entities in the chain of entities in which the beneficial owner holds shares or voting rights and by adding together the results from those various chains, unless Article 54 applies. For the purposes of assessing whether an ownership interest exists in the corporate entity, all shareholdings on every level of ownership shall be taken into account.

Für die Zwecke des Artikels 51 Absatz 1 Buchstabe a bezeichnet eine Beteiligung an der Gesellschaft das unmittelbare oder mittelbare Eigentum an mindestens 25 % der Anteile oder Stimmrechte oder einer sonstigen Beteiligung an der Gesellschaft, einschließlich der Rechte auf einen Anteil an Gewinnen, sonstigen Innenmitteln oder am Liquidationserlös. Die mittelbare Beteiligung wird berechnet, indem die von den zwischengeschalteten Einheiten in der Kette von Einheiten gehaltenen Anteile, Stimmrechte oder sonstigen Beteiligungen, an denen der wirtschaftliche Eigentümer Anteile oder Stimmrechte hält, miteinander multipliziert und die Ergebnisse der verschiedenen Ketten addiert werden, sofern nicht Artikel 54 Anwendung findet. Bei der Beurteilung, ob eine Beteiligung an der Gesellschaft besteht, sind alle Beteiligungen auf jeder Eigentumsebene zu berücksichtigen.

2 2 2

Where Member States identify pursuant to Article 8(4), point (c), of Directive (EU) 2024/1640 categories of corporate entities that are exposed to higher money laundering and terrorist financing risks, including based on the sectors in which they operate, they shall inform the Commission thereof. By 10 July 2029, the Commission shall assess whether the risks associated with those categories of legal entities are relevant for the internal market and, where it concludes that a lower threshold is appropriate to mitigate those risks, adopt delegated acts in accordance with Article 85 to amend this Regulation by identifying:

  • (a) the categories of corporate entities that are associated with higher money laundering and terrorist financing risks and for which a lower threshold shall apply;
  • (b) the related thresholds.

The lower threshold referred to in the first subparagraph shall be set at a maximum of 15 % of ownership interest in the corporate entity, unless the Commission concludes, on the basis of risk, that a higher threshold would be more proportionate, which shall in any case be set at less than 25 %.

Where Member States identify pursuant to Article 8(4), point (c), of Directive (EU) 2024/1640 categories of corporate entities that are exposed to higher money laundering and terrorist financing risks, including based on the sectors in which they operate, they shall inform the Commission thereof. By 10 July 2029, the Commission shall assess whether the risks associated with those categories of legal entities are relevant for the internal market and, where it concludes that a lower threshold is appropriate to mitigate those risks, adopt delegated acts in accordance with Article 85 to amend this Regulation by identifying:

  • (a) the categories of corporate entities that are associated with higher money laundering and terrorist financing risks and for which a lower threshold shall apply;
  • (b) the related thresholds.

The lower threshold referred to in the first subparagraph shall be set at a maximum of 15 % of ownership interest in the corporate entity, unless the Commission concludes, on the basis of risk, that a higher threshold would be more proportionate, which shall in any case be set at less than 25 %.

Ermitteln die Mitgliedstaaten gemäß Artikel 8 Absatz 4 Buchstabe c der Richtlinie (EU) 2024/1640 Kategorien von Gesellschaften, die höheren Risiken der Geldwäsche und Terrorismusfinanzierung ausgesetzt sind, auch aufgrund der Sektoren, in denen sie tätig sind, so unterrichten sie die Kommission darüber. Bis zum 10. Juli 2029 bewertet die Kommission, ob die mit diesen Kategorien juristischer Personen verbundenen Risiken für den Binnenmarkt von Bedeutung sind, und erlässt, wenn sie zu dem Schluss kommt, dass zur Minderung dieser Risiken ein niedrigerer Schwellenwert angemessen ist, gemäß Artikel 85 delegierte Rechtsakte zur Änderung dieser Verordnung, in denen sie Folgendes festlegt:

  • (a) die Kategorien von Gesellschaften, die mit höheren Risiken der Geldwäsche und Terrorismusfinanzierung verbunden sind und für die ein niedrigerer Schwellenwert gilt;
  • (b) die entsprechenden Schwellenwerte.

Der in Unterabsatz 1 genannte niedrigere Schwellenwert wird auf höchstens 15 % der Beteiligung an der Gesellschaft festgesetzt, es sei denn, die Kommission kommt auf der Grundlage des Risikos zu dem Schluss, dass ein höherer Schwellenwert verhältnismäßiger wäre; dieser muss in jedem Fall unter 25 % liegen.

3 3 3

The Commission shall review the delegated act referred to in paragraph 2 on a regular basis to ensure that it identifies the relevant categories of corporate entities that are associated with higher risks, and that the related thresholds are commensurate with those risks.

The Commission shall review the delegated act referred to in paragraph 2 on a regular basis to ensure that it identifies the relevant categories of corporate entities that are associated with higher risks, and that the related thresholds are commensurate with those risks.

Die Kommission überprüft den in Absatz 2 genannten delegierten Rechtsakt regelmäßig, um sicherzustellen, dass darin die einschlägigen Kategorien von Gesellschaften, die mit höheren Risiken verbunden sind, ermittelt werden und die entsprechenden Schwellenwerte diesen Risiken angemessen sind.

4 4 4

In the case of legal entities other than corporate entities, for which, having regard to their form and structure, it is not appropriate or possible to calculate ownership, the beneficial owners shall be the natural persons who control via other means, directly or indirectly, the legal entity, pursuant to Article 53(3) and (4), except where Article 57 applies.

In the case of legal entities other than corporate entities, for which, having regard to their form and structure, it is not appropriate or possible to calculate ownership, the beneficial owners shall be the natural persons who control via other means, directly or indirectly, the legal entity, pursuant to Article 53(3) and (4), except where Article 57 applies.

Bei anderen juristischen Personen als Gesellschaften, bei denen es aufgrund ihrer Form und Struktur nicht angemessen oder möglich ist, eine Beteiligung zu berechnen, sind die wirtschaftlichen Eigentümer die natürlichen Personen, die die juristische Person gemäß Artikel 53 Absätze 3 und 4 unmittelbar oder mittelbar auf andere Weise kontrollieren, es sei denn, Artikel 57 findet Anwendung.

Article 53 — Beneficial ownership through control Article 53 — Beneficial ownership through control Article 53 — Wirtschaftliche Eigentümerschaft durch Kontrolle
1 1 1

Control over a corporate or other legal entity shall be exercised through ownership interest or via other means.

Control over a corporate or other legal entity shall be exercised through ownership interest or via other means.

Die Kontrolle über eine Gesellschaft oder eine sonstige juristische Person wird durch eine Beteiligung oder auf andere Weise ausgeübt.

2 2 2

For the purposes of this Chapter, the following definitions apply:

  • (a) control of the legal entity means the possibility to exercise, directly or indirectly, significant influence and impose relevant decisions within the legal entity;
  • (b) indirect control of a legal entity means control of intermediate legal entities in the ownership structure or in various chains of the ownership structure, where the direct control is identified on each level of the structure;
  • (c) control through ownership interest of the corporate entity means direct or indirect ownership of 50 % plus one of the shares or voting rights or other ownership interest in the corporate entity.

For the purposes of this Chapter, the following definitions apply:

  • (a) control of the legal entity means the possibility to exercise, directly or indirectly, significant influence and impose relevant decisions within the legal entity;
  • (b) indirect control of a legal entity means control of intermediate legal entities in the ownership structure or in various chains of the ownership structure, where the direct control is identified on each level of the structure;
  • (c) control through ownership interest of the corporate entity means direct or indirect ownership of 50 % plus one of the shares or voting rights or other ownership interest in the corporate entity.

Für die Zwecke dieses Kapitels gelten folgende Begriffsbestimmungen:

  • (a) Kontrolle der juristischen Person bezeichnet die Möglichkeit, unmittelbar oder mittelbar maßgeblichen Einfluss auszuüben und innerhalb der juristischen Person relevante Entscheidungen durchzusetzen;
  • (b) mittelbare Kontrolle einer juristischen Person bezeichnet die Kontrolle über zwischengeschaltete juristische Personen in der Eigentumsstruktur oder in verschiedenen Ketten der Eigentumsstruktur, wobei die unmittelbare Kontrolle auf jeder Ebene der Struktur festgestellt wird;
  • (c) Kontrolle durch eine Beteiligung an der Gesellschaft bezeichnet das unmittelbare oder mittelbare Eigentum an 50 % plus einem der Anteile oder Stimmrechte oder einer sonstigen Beteiligung an der Gesellschaft.
3 3 3

Control of the legal entity via other means shall in any case include the possibility to exercise:

  • (a) in the case of a corporate entity, the majority of the voting rights in the corporate entity, whether or not shared by persons acting in concert;
  • (b) the right to appoint or remove a majority of the members of the board or the administrative, management or supervisory body or similar officers of the legal entity;
  • (c) relevant veto rights or decision rights attached to the share of the corporate entity;
  • (d) decisions regarding distribution of profit of the legal entity or leading to a shift in assets in the legal entity.

Control of the legal entity via other means shall in any case include the possibility to exercise:

  • (a) in the case of a corporate entity, the majority of the voting rights in the corporate entity, whether or not shared by persons acting in concert;
  • (b) the right to appoint or remove a majority of the members of the board or the administrative, management or supervisory body or similar officers of the legal entity;
  • (c) relevant veto rights or decision rights attached to the share of the corporate entity;
  • (d) decisions regarding distribution of profit of the legal entity or leading to a shift in assets in the legal entity.

Die Kontrolle der juristischen Person auf andere Weise umfasst in jedem Fall die Möglichkeit, Folgendes auszuüben:

  • (a) bei einer Gesellschaft die Mehrheit der Stimmrechte an der Gesellschaft, unabhängig davon, ob diese von gemeinsam handelnden Personen geteilt werden;
  • (b) das Recht, die Mehrheit der Mitglieder des Verwaltungs-, Leitungs- oder Aufsichtsorgans oder ähnlicher Funktionsträger der juristischen Person zu bestellen oder abzuberufen;
  • (c) maßgebliche Vetorechte oder Entscheidungsrechte, die mit dem Anteil an der Gesellschaft verbunden sind;
  • (d) Entscheidungen über die Gewinnverteilung der juristischen Person oder Entscheidungen, die zu einer Verschiebung von Vermögenswerten innerhalb der juristischen Person führen.
4 4 4

In addition to paragraph 3, control of the legal entity may be exercised via other means. Depending on the particular situation of the legal entity and its structure, other means of control may include:

  • (a) formal or informal agreements with owners, members or the legal entities, provisions in the articles of association, partnership agreements, syndication agreements, or equivalent documents or agreements depending on the specific characteristics of the legal entity, as well as voting arrangements;
  • (b) relationships between family members;
  • (c) use of formal or informal nominee arrangements.

For the purpose of this paragraph, formal nominee arrangement means a contract or an equivalent arrangement, between a nominator and a nominee, where the nominator is a legal entity or natural person that issues instructions to a nominee to act on their behalf in a certain capacity, including as a director or shareholder or settlor, and the nominee is a legal entity or natural person instructed by the nominator to act on their behalf.

In addition to paragraph 3, control of the legal entity may be exercised via other means. Depending on the particular situation of the legal entity and its structure, other means of control may include:

  • (a) formal or informal agreements with owners, members or the legal entities, provisions in the articles of association, partnership agreements, syndication agreements, or equivalent documents or agreements depending on the specific characteristics of the legal entity, as well as voting arrangements;
  • (b) relationships between family members;
  • (c) use of formal or informal nominee arrangements.

For the purpose of this paragraph, formal nominee arrangement means a contract or an equivalent arrangement, between a nominator and a nominee, where the nominator is a legal entity or natural person that issues instructions to a nominee to act on their behalf in a certain capacity, including as a director or shareholder or settlor, and the nominee is a legal entity or natural person instructed by the nominator to act on their behalf.

Zusätzlich zu Absatz 3 kann die Kontrolle der juristischen Person auf andere Weise ausgeübt werden. Je nach der konkreten Situation und Struktur der juristischen Person können andere Kontrollmittel Folgendes umfassen:

  • (a) förmliche oder informelle Vereinbarungen mit Eigentümern, Mitgliedern oder juristischen Personen, Bestimmungen der Satzung, Gesellschaftsverträge, Syndikatsvereinbarungen oder je nach den besonderen Merkmalen der juristischen Person gleichwertige Dokumente oder Vereinbarungen sowie Stimmrechtsvereinbarungen;
  • (b) Beziehungen zwischen Familienmitgliedern;
  • (c) die Nutzung förmlicher oder informeller Nominee-Vereinbarungen.

Für die Zwecke dieses Absatzes bezeichnet eine förmliche Nominee-Vereinbarung einen Vertrag oder eine gleichwertige Vereinbarung zwischen einem Auftraggeber und einem Nominee, bei der der Auftraggeber eine juristische oder natürliche Person ist, die einem Nominee Weisungen erteilt, in einer bestimmten Eigenschaft in ihrem Namen zu handeln, auch als Direktor, Anteilseigner oder Treugeber, und der Nominee eine juristische oder natürliche Person ist, die vom Auftraggeber angewiesen wird, in dessen Namen zu handeln.

Article 54 — Coexistence of ownership interest and control in the ownership structure Article 54 — Coexistence of ownership interest and control in the ownership structure Article 54 — Nebeneinander von Beteiligung und Kontrolle in der Eigentumsstruktur

Where corporate entities are owned through a multi-layered ownership structure, and in one or more chains of that structure the ownership interest and the control coexist in relation to different layers of the chain, the beneficial owners shall be:

  • (a) the natural persons who control, directly or indirectly, through ownership interest or via other means, legal entities that have a direct ownership interest in the corporate entity, whether individually or cumulatively;
  • (b) the natural persons who, whether individually or cumulatively, directly or indirectly, have an ownership interest in the corporate entity that controls, through ownership interest or via other means, the corporate entity, directly or indirectly.

Where corporate entities are owned through a multi-layered ownership structure, and in one or more chains of that structure the ownership interest and the control coexist in relation to different layers of the chain, the beneficial owners shall be:

  • (a) the natural persons who control, directly or indirectly, through ownership interest or via other means, legal entities that have a direct ownership interest in the corporate entity, whether individually or cumulatively;
  • (b) the natural persons who, whether individually or cumulatively, directly or indirectly, have an ownership interest in the corporate entity that controls, through ownership interest or via other means, the corporate entity, directly or indirectly.

Sind Gesellschaften über eine mehrschichtige Eigentumsstruktur im Eigentum und bestehen in einer oder mehreren Ketten dieser Struktur in Bezug auf verschiedene Ebenen der Kette nebeneinander Beteiligung und Kontrolle, so sind die wirtschaftlichen Eigentümer:

  • (a) die natürlichen Personen, die unmittelbar oder mittelbar durch eine Beteiligung oder auf andere Weise juristische Personen kontrollieren, die unmittelbar an der Gesellschaft beteiligt sind, sei es einzeln oder kumulativ;
  • (b) die natürlichen Personen, die unmittelbar oder mittelbar, sei es einzeln oder kumulativ, an der Gesellschaft beteiligt sind, die die Gesellschaft unmittelbar oder mittelbar durch eine Beteiligung oder auf andere Weise kontrolliert.
Article 55 — Ownership structures involving legal arrangements or similar legal entities Article 55 — Ownership structures involving legal arrangements or similar legal entities Article 55 — Eigentumsstrukturen unter Einbeziehung von Rechtsvereinbarungen oder ähnlichen juristischen Personen

Where legal entities referred to in Article 57 or legal arrangements have an ownership interest in the corporate entity, whether individually or cumulatively, or control, directly or indirectly, the corporate entity, through ownership interest or via other means, the beneficial owners shall be the natural persons who are the beneficial owners of the legal entities referred to in Article 57 or of the legal arrangements.

Where legal entities referred to in Article 57 or legal arrangements have an ownership interest in the corporate entity, whether individually or cumulatively, or control, directly or indirectly, the corporate entity, through ownership interest or via other means, the beneficial owners shall be the natural persons who are the beneficial owners of the legal entities referred to in Article 57 or of the legal arrangements.

Haben die in Artikel 57 genannten juristischen Personen oder Rechtsvereinbarungen, sei es einzeln oder kumulativ, eine Beteiligung an der Gesellschaft oder kontrollieren sie die Gesellschaft unmittelbar oder mittelbar durch eine Beteiligung oder auf andere Weise, so sind die wirtschaftlichen Eigentümer die natürlichen Personen, die wirtschaftliche Eigentümer der in Artikel 57 genannten juristischen Personen oder der Rechtsvereinbarungen sind.

Article 56 — Notifications Article 56 — Notifications Article 56 — Mitteilungen

Each Member State shall notify to the Commission by 10 October 2027 a list of the types of legal entities existing under its national law with beneficial owners identified in accordance with Article 51 and Article 52(4). That notification shall include the specific categories of entities, description of characteristics and, where applicable, legal basis under the national law of the Member State concerned. It shall also include an indication of whether, due to the specific form and structures of legal entities other than corporate entities, the mechanism under Article 63(4) applies, accompanied by a detailed justification of the reasons for that.The Commission shall communicate the notification referred to in the first paragraph to other Member States.

Each Member State shall notify to the Commission by 10 October 2027 a list of the types of legal entities existing under its national law with beneficial owners identified in accordance with Article 51 and Article 52(4). That notification shall include the specific categories of entities, description of characteristics and, where applicable, legal basis under the national law of the Member State concerned. It shall also include an indication of whether, due to the specific form and structures of legal entities other than corporate entities, the mechanism under Article 63(4) applies, accompanied by a detailed justification of the reasons for that. The Commission shall communicate the notification referred to in the first paragraph to other Member States.

Jeder Mitgliedstaat übermittelt der Kommission bis zum 10. Oktober 2027 eine Liste der nach seinem nationalen Recht bestehenden Arten juristischer Personen, deren wirtschaftliche Eigentümer gemäß Artikel 51 und Artikel 52 Absatz 4 identifiziert werden. Diese Mitteilung enthält die spezifischen Kategorien von Einheiten, eine Beschreibung ihrer Merkmale und gegebenenfalls die Rechtsgrundlage im nationalen Recht des betreffenden Mitgliedstaats. Sie enthält ferner die Angabe, ob aufgrund der besonderen Form und Strukturen anderer juristischer Personen als Gesellschaften der Mechanismus nach Artikel 63 Absatz 4 Anwendung findet, zusammen mit einer ausführlichen Begründung. Die Kommission übermittelt die in Absatz 1 genannte Mitteilung den anderen Mitgliedstaaten.

Article 57 — Identification of beneficial owners for legal entities similar to express trust Article 57 — Identification of beneficial owners for legal entities similar to express trust Article 57 — Identifizierung der wirtschaftlichen Eigentümer von Rechtsgebilden, die einem Express Trust ähneln
1 1 1

In the case of legal entities other than those referred to in Article 51, similar to express trust, such as foundations, the beneficial owners shall be all the following natural persons:

  • (a) the founders;
  • (b) the members of the management body in its management function;
  • (c) the members of the management body in its supervisory function;
  • (d) the beneficiaries, unless Article 59 applies;
  • (e) any other natural person, who controls directly or indirectly the legal entity.

In the case of legal entities other than those referred to in Article 51, similar to express trust, such as foundations, the beneficial owners shall be all the following natural persons:

  • (a) the founders;
  • (b) the members of the management body in its management function;
  • (c) the members of the management body in its supervisory function;
  • (d) the beneficiaries, unless Article 59 applies;
  • (e) any other natural person, who controls directly or indirectly the legal entity.

Bei juristischen Personen, die nicht unter Artikel 51 fallen und einem Express Trust ähneln, wie etwa Stiftungen, sind die wirtschaftlichen Eigentümer alle folgenden natürlichen Personen:

  • (a) die Gründer;
  • (b) die Mitglieder des Leitungsorgans in seiner Leitungsfunktion;
  • (c) die Mitglieder des Leitungsorgans in seiner Aufsichtsfunktion;
  • (d) die Begünstigten, sofern Artikel 59 keine Anwendung findet;
  • (e) jede andere natürliche Person, die die juristische Person unmittelbar oder mittelbar kontrolliert.
2 2 2

In cases where legal entities referred to in paragraph 1 belong to multi-layered control structures, where any of the positions listed in paragraph 1 is held by a legal entity, beneficial owners of the legal entity referred to in paragraph 1 shall be:

  • (a) the natural persons listed in paragraph 1; and
  • (b) the beneficial owners of the legal entities that occupy any of the positions listed in paragraph 1.

In cases where legal entities referred to in paragraph 1 belong to multi-layered control structures, where any of the positions listed in paragraph 1 is held by a legal entity, beneficial owners of the legal entity referred to in paragraph 1 shall be:

  • (a) the natural persons listed in paragraph 1; and
  • (b) the beneficial owners of the legal entities that occupy any of the positions listed in paragraph 1.

Gehören die in Absatz 1 genannten juristischen Personen mehrschichtigen Kontrollstrukturen an und wird eine der in Absatz 1 aufgeführten Positionen von einer juristischen Person gehalten, so sind die wirtschaftlichen Eigentümer der in Absatz 1 genannten juristischen Person:

  • (a) die in Absatz 1 aufgeführten natürlichen Personen; und
  • (b) die wirtschaftlichen Eigentümer der juristischen Personen, die eine der in Absatz 1 aufgeführten Positionen innehaben.
3 3 3

Member States shall notify to the Commission by 10 October 2027 a list of types of legal entities, of which the beneficial owners are identified in accordance with paragraph 1.

The notification referred to in the first subparagraph shall be accompanied by a description of:

  • (a) the form and basic features of those legal entities;
  • (b) the process through which they can be set up;
  • (c) the process for accessing basic information and beneficial ownership information on those legal entities;
  • (d) the websites at which the central registers containing information on beneficial owners of those legal entities can be consulted and contact details of the entities in charge of those registers.

Member States shall notify to the Commission by 10 October 2027 a list of types of legal entities, of which the beneficial owners are identified in accordance with paragraph 1.

The notification referred to in the first subparagraph shall be accompanied by a description of:

  • (a) the form and basic features of those legal entities;
  • (b) the process through which they can be set up;
  • (c) the process for accessing basic information and beneficial ownership information on those legal entities;
  • (d) the websites at which the central registers containing information on beneficial owners of those legal entities can be consulted and contact details of the entities in charge of those registers.

Die Mitgliedstaaten übermitteln der Kommission bis zum 10. Oktober 2027 eine Liste der Arten juristischer Personen, deren wirtschaftliche Eigentümer gemäß Absatz 1 identifiziert werden.

Der in Unterabsatz 1 genannten Mitteilung ist eine Beschreibung folgender Punkte beizufügen:

  • (a) Form und grundlegende Merkmale dieser juristischen Personen;
  • (b) Verfahren, nach dem sie errichtet werden können;
  • (c) Verfahren für den Zugang zu den Basisinformationen und den Informationen über die wirtschaftlichen Eigentümer dieser juristischen Personen;
  • (d) Websites, auf denen die zentralen Register mit Informationen über die wirtschaftlichen Eigentümer dieser juristischen Personen eingesehen werden können, sowie Kontaktdaten der für diese Register zuständigen Stellen.
4 4 4

The Commission may adopt, by means of an implementing act, a list of types of legal entities governed by the law of Member States which should be subject to the requirements of this Article. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

The Commission may adopt, by means of an implementing act, a list of types of legal entities governed by the law of Member States which should be subject to the requirements of this Article. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

Die Kommission kann im Wege eines Durchführungsrechtsakts eine Liste der Arten juristischer Personen annehmen, die dem Recht der Mitgliedstaaten unterliegen und den Anforderungen dieses Artikels unterliegen sollten. Dieser Durchführungsrechtsakt wird nach dem in Artikel 86 Absatz 2 genannten Prüfverfahren erlassen.

Article 58 — Identification of beneficial owners for express trusts and similar legal arrangements Article 58 — Identification of beneficial owners for express trusts and similar legal arrangements Article 58 — Identifizierung der wirtschaftlichen Eigentümer von Express Trusts und ähnlichen Rechtsvereinbarungen
1 1 1

The beneficial owners of express trusts shall be all the following natural persons:

  • (a) the settlors;
  • (b) the trustees;
  • (c) the protectors, if any;
  • (d) the beneficiaries, unless Article 59 or 60 applies;
  • (e) any other natural persons exercising ultimate control over the express trust by means of direct or indirect ownership or by other means, including through a chain of control or ownership.

The beneficial owners of express trusts shall be all the following natural persons:

  • (a) the settlors;
  • (b) the trustees;
  • (c) the protectors, if any;
  • (d) the beneficiaries, unless Article 59 or 60 applies;
  • (e) any other natural persons exercising ultimate control over the express trust by means of direct or indirect ownership or by other means, including through a chain of control or ownership.

Die wirtschaftlichen Eigentümer von Express Trusts sind alle folgenden natürlichen Personen:

  • (a) die Treugeber;
  • (b) die Treuhänder;
  • (c) gegebenenfalls die Protektoren;
  • (d) die Begünstigten, sofern Artikel 59 oder 60 keine Anwendung findet;
  • (e) alle anderen natürlichen Personen, die auf unmittelbarem oder mittelbarem Eigentum oder auf andere Weise, auch über eine Kontroll- oder Eigentumskette, die letztendliche Kontrolle über den Express Trust ausüben.
2 2 2

The beneficial owners of other legal arrangements similar to express trusts shall be the natural persons holding equivalent or similar positions to those referred to in paragraph 1.

The beneficial owners of other legal arrangements similar to express trusts shall be the natural persons holding equivalent or similar positions to those referred to in paragraph 1.

Die wirtschaftlichen Eigentümer anderer Rechtsvereinbarungen, die Express Trusts ähneln, sind die natürlichen Personen, die gleichwertige oder ähnliche Positionen wie die in Absatz 1 genannten innehaben.

3 3 3

Where legal arrangements belong to multi-layered control structures and where any of the positions listed in paragraph 1 is held by a legal entity, the beneficial owners of the legal arrangement shall be:

  • (a) the natural persons listed in paragraph 1; and
  • (b) the beneficial owners of the legal entities that occupy any of the positions listed in paragraph 1.

Where legal arrangements belong to multi-layered control structures and where any of the positions listed in paragraph 1 is held by a legal entity, the beneficial owners of the legal arrangement shall be:

  • (a) the natural persons listed in paragraph 1; and
  • (b) the beneficial owners of the legal entities that occupy any of the positions listed in paragraph 1.

Gehören Rechtsvereinbarungen mehrschichtigen Kontrollstrukturen an und wird eine der in Absatz 1 aufgeführten Positionen von einer juristischen Person gehalten, so sind die wirtschaftlichen Eigentümer der Rechtsvereinbarung:

  • (a) die in Absatz 1 aufgeführten natürlichen Personen; und
  • (b) die wirtschaftlichen Eigentümer der juristischen Personen, die eine der in Absatz 1 aufgeführten Positionen innehaben.
4 4 4

Member States shall notify to the Commission by 10 October 2027 a list of types of legal arrangements similar to express trusts which are governed under their law.

The notification shall be accompanied by a description of:

  • (a) the form and basic features of those legal arrangements;
  • (b) the process through which those legal arrangements can be set up;
  • (c) the process for accessing basic information and beneficial ownership information on those legal arrangements;
  • (d) the websites at which the central registers containing information on beneficial owners of those legal arrangements can be consulted and the contact details of the entities in charge of those registers.

The notification shall also be accompanied by a justification detailing the reasons why the Member State considers the notified legal arrangements to be similar to express trusts and why it concluded that other legal arrangements governed under its law are not similar to express trusts.

Member States shall notify to the Commission by 10 October 2027 a list of types of legal arrangements similar to express trusts which are governed under their law.

The notification shall be accompanied by a description of:

  • (a) the form and basic features of those legal arrangements;
  • (b) the process through which those legal arrangements can be set up;
  • (c) the process for accessing basic information and beneficial ownership information on those legal arrangements;
  • (d) the websites at which the central registers containing information on beneficial owners of those legal arrangements can be consulted and the contact details of the entities in charge of those registers.

The notification shall also be accompanied by a justification detailing the reasons why the Member State considers the notified legal arrangements to be similar to express trusts and why it concluded that other legal arrangements governed under its law are not similar to express trusts.

Die Mitgliedstaaten übermitteln der Kommission bis zum 10. Oktober 2027 eine Liste der Arten von Rechtsvereinbarungen, die Express Trusts ähneln und ihrem Recht unterliegen.

Der Mitteilung ist eine Beschreibung folgender Punkte beizufügen:

  • (a) Form und grundlegende Merkmale dieser Rechtsvereinbarungen;
  • (b) Verfahren, nach dem diese Rechtsvereinbarungen errichtet werden können;
  • (c) Verfahren für den Zugang zu den Basisinformationen und den Informationen über die wirtschaftlichen Eigentümer dieser Rechtsvereinbarungen;
  • (d) Websites, auf denen die zentralen Register mit Informationen über die wirtschaftlichen Eigentümer dieser Rechtsvereinbarungen eingesehen werden können, sowie die Kontaktdaten der für diese Register zuständigen Stellen.

Der Mitteilung ist ferner eine Begründung beizufügen, in der ausführlich dargelegt wird, weshalb der Mitgliedstaat die mitgeteilten Rechtsvereinbarungen als Express Trusts ähnlich ansieht und weshalb er zu dem Schluss gelangt ist, dass andere seinem Recht unterliegende Rechtsvereinbarungen Express Trusts nicht ähneln.

5 5 5

The Commission may adopt, by means of an implementing act, a list of types of legal arrangements governed under the law of Member States which should be subject to the same beneficial ownership transparency requirements as express trusts, accompanied by the information referred to in paragraph 4, second subparagraph of this Article. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

The Commission may adopt, by means of an implementing act, a list of types of legal arrangements governed under the law of Member States which should be subject to the same beneficial ownership transparency requirements as express trusts, accompanied by the information referred to in paragraph 4, second subparagraph of this Article. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

Die Kommission kann im Wege eines Durchführungsrechtsakts eine Liste der Arten von Rechtsvereinbarungen annehmen, die dem Recht der Mitgliedstaaten unterliegen und denselben Anforderungen an die Transparenz der wirtschaftlichen Eigentümerschaft wie Express Trusts unterliegen sollten; dieser Liste sind die in Absatz 4 Unterabsatz 2 dieses Artikels genannten Informationen beizufügen. Dieser Durchführungsrechtsakt wird nach dem in Artikel 86 Absatz 2 genannten Prüfverfahren erlassen.

Article 59 — Identification of a class of beneficiaries Article 59 — Identification of a class of beneficiaries Article 59 — Identifizierung einer Kategorie von Begünstigten
1 1 1

In the case of legal entities similar to express trusts under Article 57 or, with the exception of discretionary trusts, express trusts and similar legal arrangements under Article 58, where beneficiaries have yet to be determined, the class of beneficiaries and its general characteristics shall be identified. Beneficiaries within the class shall be beneficial owners as soon as they are identified or designated.

In the case of legal entities similar to express trusts under Article 57 or, with the exception of discretionary trusts, express trusts and similar legal arrangements under Article 58, where beneficiaries have yet to be determined, the class of beneficiaries and its general characteristics shall be identified. Beneficiaries within the class shall be beneficial owners as soon as they are identified or designated.

Bei juristischen Personen, die gemäß Artikel 57 Express Trusts ähneln, oder — mit Ausnahme von Ermessens-Trusts — bei Express Trusts und ähnlichen Rechtsvereinbarungen gemäß Artikel 58 sind, sofern die Begünstigten noch nicht bestimmt wurden, die Kategorie der Begünstigten und ihre allgemeinen Merkmale zu identifizieren. Begünstigte innerhalb der Kategorie sind wirtschaftliche Eigentümer, sobald sie identifiziert oder bestimmt sind.

2 2 2

In the following cases, only the class of beneficiaries and its characteristics shall be identified:

  • (a) pension schemes within the scope of Directive (EU) 2016/2341;
  • (b) employee financial ownership or participation schemes, provided that Member States, following an appropriate risk assessment, have concluded a low risk of misuse for money laundering or terrorist financing;
  • (c) legal entities similar to express trusts under Article 57, express trusts and similar legal arrangements under Article 58, provided that:

    • (i) the legal entity, the express trust or similar legal arrangement is set up for a non-profit or charitable purpose; and
    • (ii) following an appropriate risk assessment, Member States have concluded that the category of legal entity, express trust or similar legal arrangement is at a low risk of misuse for money laundering or terrorist financing.

In the following cases, only the class of beneficiaries and its characteristics shall be identified:

  • (a) pension schemes within the scope of Directive (EU) 2016/2341;
  • (b) employee financial ownership or participation schemes, provided that Member States, following an appropriate risk assessment, have concluded a low risk of misuse for money laundering or terrorist financing;
  • (c) legal entities similar to express trusts under Article 57, express trusts and similar legal arrangements under Article 58, provided that:
    • (i) the legal entity, the express trust or similar legal arrangement is set up for a non-profit or charitable purpose; and
    • (ii) following an appropriate risk assessment, Member States have concluded that the category of legal entity, express trust or similar legal arrangement is at a low risk of misuse for money laundering or terrorist financing.

In den folgenden Fällen sind nur die Kategorie der Begünstigten und ihre Merkmale zu identifizieren:

  • (a) Pensionsfonds im Anwendungsbereich der Richtlinie (EU) 2016/2341;
  • (b) Systeme der finanziellen Beteiligung oder Teilhabe von Arbeitnehmern, sofern die Mitgliedstaaten nach einer angemessenen Risikobewertung zu dem Schluss gelangt sind, dass ein geringes Risiko des Missbrauchs für Geldwäsche oder Terrorismusfinanzierung besteht;
  • (c) juristische Personen, die gemäß Artikel 57 Express Trusts ähneln, sowie Express Trusts und ähnliche Rechtsvereinbarungen gemäß Artikel 58, sofern:
    • (i) die juristische Person, der Express Trust oder die ähnliche Rechtsvereinbarung zu einem nicht gewinnorientierten oder gemeinnützigen Zweck errichtet wurde; und
    • (ii) die Mitgliedstaaten nach einer angemessenen Risikobewertung zu dem Schluss gelangt sind, dass die Kategorie der juristischen Person, des Express Trusts oder der ähnlichen Rechtsvereinbarung einem geringen Risiko des Missbrauchs für Geldwäsche oder Terrorismusfinanzierung ausgesetzt ist.
3 3 3

Member State shall notify to the Commission the categories of legal entities, express trusts or similar legal arrangements under paragraph 2, together with a justification based on the specific risk assessment. The Commission shall communicate that notification to the other Member States.

Member State shall notify to the Commission the categories of legal entities, express trusts or similar legal arrangements under paragraph 2, together with a justification based on the specific risk assessment. The Commission shall communicate that notification to the other Member States.

Der Mitgliedstaat teilt der Kommission die Kategorien juristischer Personen, Express Trusts oder ähnlicher Rechtsvereinbarungen nach Absatz 2 zusammen mit einer auf der spezifischen Risikobewertung beruhenden Begründung mit. Die Kommission übermittelt diese Mitteilung den anderen Mitgliedstaaten.

Article 60 — Identification of objects of a power and default takers in discretionary trusts Article 60 — Identification of objects of a power and default takers in discretionary trusts Article 60 — Identifizierung der Begünstigungsobjekte einer Ermessenbefugnis und der Ersatzbegünstigten bei Ermessens-Trusts

In the case of discretionary trusts, where beneficiaries have yet to be selected, the objects of a power and default takers shall be identified. Beneficiaries among the objects of a power shall be beneficial owners as soon as they are selected. Default takers shall be beneficial owners when the trustees fail to exercise their discretion.Where discretionary trusts meet the conditions laid down in Article 59(2), only the class of objects of a power and default takers shall be identified. Those categories of discretionary trusts shall be notified to the Commission in accordance with paragraph 3 of that Article.

In the case of discretionary trusts, where beneficiaries have yet to be selected, the objects of a power and default takers shall be identified. Beneficiaries among the objects of a power shall be beneficial owners as soon as they are selected. Default takers shall be beneficial owners when the trustees fail to exercise their discretion. Where discretionary trusts meet the conditions laid down in Article 59(2), only the class of objects of a power and default takers shall be identified. Those categories of discretionary trusts shall be notified to the Commission in accordance with paragraph 3 of that Article.

Bei Ermessens-Trusts sind, sofern die Begünstigten noch nicht ausgewählt wurden, die Begünstigungsobjekte einer Ermessenbefugnis und die Ersatzbegünstigten zu identifizieren. Begünstigte unter den Begünstigungsobjekten einer Ermessenbefugnis sind wirtschaftliche Eigentümer, sobald sie ausgewählt wurden. Ersatzbegünstigte sind wirtschaftliche Eigentümer, wenn die Treuhänder ihr Ermessen nicht ausüben. Erfüllen Ermessens-Trusts die in Artikel 59 Absatz 2 festgelegten Bedingungen, ist nur die Kategorie der Begünstigungsobjekte einer Ermessenbefugnis und der Ersatzbegünstigten zu identifizieren. Diese Kategorien von Ermessens-Trusts werden der Kommission gemäß Absatz 3 jenes Artikels mitgeteilt.

Article 61 — Identification of beneficial owners of collective investment undertakings Article 61 — Identification of beneficial owners of collective investment undertakings Article 61 — Identifizierung der wirtschaftlichen Eigentümer von Organismen für gemeinsame Anlagen

By way of derogation from Article 51, first paragraph and Article 58(1), the beneficial owners of collective investment undertakings shall be the natural persons who fulfil one or more of the following conditions:

  • (a) they hold directly or indirectly 25 % or more of the units held in the collective investment undertaking;
  • (b) they have the ability to define or influence the investment policy of the collective investment undertaking;
  • (c) they control the activities of the collective investment undertaking through other means.

By way of derogation from Article 51, first paragraph and Article 58(1), the beneficial owners of collective investment undertakings shall be the natural persons who fulfil one or more of the following conditions:

  • (a) they hold directly or indirectly 25 % or more of the units held in the collective investment undertaking;
  • (b) they have the ability to define or influence the investment policy of the collective investment undertaking;
  • (c) they control the activities of the collective investment undertaking through other means.

Abweichend von Artikel 51 Absatz 1 und Artikel 58 Absatz 1 sind die wirtschaftlichen Eigentümer von Organismen für gemeinsame Anlagen die natürlichen Personen, die eine oder mehrere der folgenden Bedingungen erfüllen:

  • (a) Sie halten unmittelbar oder mittelbar mindestens 25 % der Anteile des Organismus für gemeinsame Anlagen;
  • (b) sie können die Anlagepolitik des Organismus für gemeinsame Anlagen festlegen oder beeinflussen;
  • (c) sie kontrollieren die Tätigkeiten des Organismus für gemeinsame Anlagen auf andere Weise.
Article 62 — Beneficial ownership information Article 62 — Beneficial ownership information Article 62 — Informationen über die wirtschaftlichen Eigentümer
1 1 1

Legal entities and trustees of express trusts or persons holding equivalent positions in similar legal arrangements shall ensure that the beneficial ownership information which they hold, provide to obliged entities in the context of customer due diligence procedures in accordance with Chapter III or submit to central registers is adequate, accurate, and up-to-date.

The beneficial ownership information referred to in the first subparagraph shall include the following:

  • (a) all names and surnames, place and full date of birth, residential address, country of residence and nationality or nationalities of the beneficial owner, number of identity document, such as passport or national identity document, and, where it exists, unique personal identification number assigned to the person by his or her country of usual residence, and general description of the source of such number;
  • (b) the nature and extent of the beneficial interest held in the legal entity or legal arrangement, whether through ownership interest or control via other means, as well as the date as of which the beneficial interest is held;
  • (c) information on the legal entity of which the natural person is the beneficial owner in accordance with Article 22(1), point (b), or, in the case of legal arrangements of which the natural person is the beneficial owner, basic information on the legal arrangement;
  • (d) where the ownership and control structure contains more than one legal entity or legal arrangement, a description of such structure, including names and, where it exists, identification numbers of the individual legal entities or legal arrangements that are part of that structure, and a description of the relationships between them, including the share of the interest held;
  • (e) where a class of beneficiaries is identified under Article 59, general description of the characteristic of the class of beneficiaries;
  • (f) where objects of a power and default takers are identified under Article 60:

    • (i) for natural persons, their names and surnames;
    • (ii) for legal entities and legal arrangements, their names;
    • (iii) for a class of objects of a power or default takers, its description.

Legal entities and trustees of express trusts or persons holding equivalent positions in similar legal arrangements shall ensure that the beneficial ownership information which they hold, provide to obliged entities in the context of customer due diligence procedures in accordance with Chapter III or submit to central registers is adequate, accurate, and up-to-date.

The beneficial ownership information referred to in the first subparagraph shall include the following:

  • (a) all names and surnames, place and full date of birth, residential address, country of residence and nationality or nationalities of the beneficial owner, number of identity document, such as passport or national identity document, and, where it exists, unique personal identification number assigned to the person by his or her country of usual residence, and general description of the source of such number;
  • (b) the nature and extent of the beneficial interest held in the legal entity or legal arrangement, whether through ownership interest or control via other means, as well as the date as of which the beneficial interest is held;
  • (c) information on the legal entity of which the natural person is the beneficial owner in accordance with Article 22(1), point (b), or, in the case of legal arrangements of which the natural person is the beneficial owner, basic information on the legal arrangement;
  • (d) where the ownership and control structure contains more than one legal entity or legal arrangement, a description of such structure, including names and, where it exists, identification numbers of the individual legal entities or legal arrangements that are part of that structure, and a description of the relationships between them, including the share of the interest held;
  • (e) where a class of beneficiaries is identified under Article 59, general description of the characteristic of the class of beneficiaries;
  • (f) where objects of a power and default takers are identified under Article 60:
    • (i) for natural persons, their names and surnames;
    • (ii) for legal entities and legal arrangements, their names;
    • (iii) for a class of objects of a power or default takers, its description.

Juristische Personen und Treuhänder von Express Trusts oder Personen, die in ähnlichen Rechtsvereinbarungen gleichwertige Positionen innehaben, stellen sicher, dass die Informationen über die wirtschaftlichen Eigentümer, über die sie verfügen, die sie Verpflichteten im Rahmen von Sorgfaltspflichten gegenüber Kunden gemäß Kapitel III bereitstellen oder die sie zentralen Registern übermitteln, angemessen, korrekt und aktuell sind.

Die in Unterabsatz 1 genannten Informationen über die wirtschaftlichen Eigentümer umfassen:

  • (a) sämtliche Vor- und Nachnamen, Geburtsort und vollständiges Geburtsdatum, Wohnanschrift, Wohnsitzland und Staatsangehörigkeit oder Staatsangehörigkeiten des wirtschaftlichen Eigentümers, die Nummer des Identitätsdokuments, etwa des Reisepasses oder des Personalausweises, sowie, sofern vorhanden, die eindeutige persönliche Identifikationsnummer, die der Person von ihrem gewöhnlichen Wohnsitzland zugewiesen wurde, und eine allgemeine Beschreibung der Quelle dieser Nummer;
  • (b) Art und Umfang der an der juristischen Person oder Rechtsvereinbarung gehaltenen wirtschaftlichen Beteiligung, unabhängig davon, ob diese durch eine Beteiligung oder durch Kontrolle auf andere Weise besteht, sowie das Datum, ab dem die wirtschaftliche Beteiligung gehalten wird;
  • (c) Informationen über die juristische Person, deren wirtschaftlicher Eigentümer die natürliche Person gemäß Artikel 22 Absatz 1 Buchstabe b ist, oder, im Fall von Rechtsvereinbarungen, deren wirtschaftlicher Eigentümer die natürliche Person ist, grundlegende Informationen über die Rechtsvereinbarung;
  • (d) enthält die Eigentums- und Kontrollstruktur mehr als eine juristische Person oder Rechtsvereinbarung, eine Beschreibung dieser Struktur einschließlich der Namen und, sofern vorhanden, der Identifikationsnummern der einzelnen juristischen Personen oder Rechtsvereinbarungen, die Teil dieser Struktur sind, sowie eine Beschreibung ihrer Beziehungen, einschließlich des Umfangs der gehaltenen Beteiligung;
  • (e) sofern gemäß Artikel 59 eine Kategorie von Begünstigten identifiziert wird, eine allgemeine Beschreibung der Merkmale dieser Kategorie;
  • (f) sofern gemäß Artikel 60 Begünstigungsobjekte einer Ermessenbefugnis und Ersatzbegünstigte identifiziert werden:
    • (i) bei natürlichen Personen deren Vor- und Nachnamen;
    • (ii) bei juristischen Personen und Rechtsvereinbarungen deren Namen;
    • (iii) bei einer Kategorie von Begünstigungsobjekten einer Ermessenbefugnis oder Ersatzbegünstigten deren Beschreibung.
2 2 2

Legal entities and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement shall obtain adequate, accurate, and up-to-date beneficial ownership information within 28 calendar days of the creation of the legal entity or the setting up of the legal arrangement. That information shall be updated promptly, and, in any case, within 28 calendar days of any change thereto, as well as on an annual basis.

Legal entities and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement shall obtain adequate, accurate, and up-to-date beneficial ownership information within 28 calendar days of the creation of the legal entity or the setting up of the legal arrangement. That information shall be updated promptly, and, in any case, within 28 calendar days of any change thereto, as well as on an annual basis.

Juristische Personen und Treuhänder von Express Trusts oder Personen, die in einer ähnlichen Rechtsvereinbarung eine gleichwertige Position innehaben, beschaffen innerhalb von 28 Kalendertagen nach Gründung der juristischen Person oder Errichtung der Rechtsvereinbarung angemessene, korrekte und aktuelle Informationen über die wirtschaftlichen Eigentümer. Diese Informationen werden unverzüglich und in jedem Fall innerhalb von 28 Kalendertagen nach einer Änderung sowie jährlich aktualisiert.

Article 63 — Obligations of legal entities Article 63 — Obligations of legal entities Article 63 — Pflichten juristischer Personen
1 1 1

All legal entities created in the Union shall obtain and hold adequate, accurate and up-to-date beneficial ownership information.Legal entities shall provide, in addition to information about their legal owners, information on the beneficial owners to obliged entities where the obliged entities are applying customer due diligence measures in accordance with Chapter III.

All legal entities created in the Union shall obtain and hold adequate, accurate and up-to-date beneficial ownership information. Legal entities shall provide, in addition to information about their legal owners, information on the beneficial owners to obliged entities where the obliged entities are applying customer due diligence measures in accordance with Chapter III.

Alle in der Union gegründeten juristischen Personen beschaffen und halten angemessene, korrekte und aktuelle Informationen über ihre wirtschaftlichen Eigentümer. Juristische Personen stellen Verpflichteten, sofern diese Sorgfaltspflichten gegenüber Kunden gemäß Kapitel III anwenden, zusätzlich zu Informationen über ihre rechtlichen Eigentümer Informationen über ihre wirtschaftlichen Eigentümer bereit.

2 2 2

A legal entity shall report beneficial ownership information to the central register without undue delay after its creation. Any change to that information shall be reported to the central register without undue delay and, in any case, within 28 calendar days thereof. The legal entity shall regularly verify that it holds up-to-date information on its beneficial ownership. As a minimum, such verification shall be performed annually whether as a self-standing process or as part of other periodical processes, such as the submission of financial statement.The beneficial owners of a legal entity as well as the legal entities and, in the case of legal arrangements, their trustees or persons holding an equivalent position, which are part of the ownership or control structure of a legal entity, shall provide that legal entity with all the information necessary for the legal entity to comply with the requirements of this Chapter or to respond to any request for additional information received pursuant to Article 10(4) of Directive (EU) 2024/1640.

A legal entity shall report beneficial ownership information to the central register without undue delay after its creation. Any change to that information shall be reported to the central register without undue delay and, in any case, within 28 calendar days thereof. The legal entity shall regularly verify that it holds up-to-date information on its beneficial ownership. As a minimum, such verification shall be performed annually whether as a self-standing process or as part of other periodical processes, such as the submission of financial statement. The beneficial owners of a legal entity as well as the legal entities and, in the case of legal arrangements, their trustees or persons holding an equivalent position, which are part of the ownership or control structure of a legal entity, shall provide that legal entity with all the information necessary for the legal entity to comply with the requirements of this Chapter or to respond to any request for additional information received pursuant to Article 10(4) of Directive (EU) 2024/1640.

Eine juristische Person hat Informationen über ihre wirtschaftlichen Eigentümer unverzüglich nach ihrer Errichtung an das zentrale Register zu melden. Jede Änderung dieser Informationen ist dem zentralen Register unverzüglich und in jedem Fall innerhalb von 28 Kalendertagen nach der Änderung zu melden. Die juristische Person überprüft regelmäßig, ob sie über aktuelle Informationen über ihre wirtschaftlichen Eigentümer verfügt. Eine solche Überprüfung ist mindestens einmal jährlich durchzuführen, und zwar entweder als eigenständiger Vorgang oder im Rahmen anderer regelmäßiger Vorgänge, etwa der Einreichung von Jahresabschlüssen. Die wirtschaftlichen Eigentümer einer juristischen Person sowie die juristischen Personen und — im Falle von Rechtsvereinbarungen — deren Treuhänder oder Personen mit einer gleichwertigen Stellung, die Teil der Eigentums- oder Kontrollstruktur einer juristischen Person sind, haben dieser juristischen Person alle Informationen zur Verfügung zu stellen, die erforderlich sind, damit die juristische Person die Anforderungen dieses Kapitels erfüllen oder auf ein Ersuchen um zusätzliche Informationen nach Artikel 10 Absatz 4 der Richtlinie (EU) 2024/1640 antworten kann.

3 3 3

Where, having exhausted all possible means of identification pursuant to Articles 51 to 57, no person is identified as beneficial owner, or where there is substantial and justified uncertainty on the part of the legal entity that the persons identified are the beneficial owners, legal entities shall keep records of the actions taken in order to identify their beneficial owners.

Where, having exhausted all possible means of identification pursuant to Articles 51 to 57, no person is identified as beneficial owner, or where there is substantial and justified uncertainty on the part of the legal entity that the persons identified are the beneficial owners, legal entities shall keep records of the actions taken in order to identify their beneficial owners.

Wenn nach Ausschöpfung aller möglichen Mittel zur Identifizierung gemäß den Artikeln 51 bis 57 keine Person als wirtschaftlicher Eigentümer identifiziert wird oder wenn seitens der juristischen Person erhebliche und begründete Zweifel daran bestehen, dass es sich bei den identifizierten Personen um die wirtschaftlichen Eigentümer handelt, haben juristische Personen Aufzeichnungen über die zur Identifizierung ihrer wirtschaftlichen Eigentümer ergriffenen Maßnahmen aufzubewahren.

4 4 4

In the cases referred to in paragraph 3 of this Article, when providing beneficial ownership information in accordance with Article 20 of this Regulation and Article 10 of Directive (EU) 2024/1640, legal entities shall provide the following:

  • (a) a statement that there is no beneficial owner or that the beneficial owners could not be determined, accompanied by a justification as to why it was not possible to determine the beneficial owner in accordance with Articles 51 to 57 of this Regulation and what constitutes uncertainty about the ascertained information;
  • (b) the details of all natural persons who hold the position of senior managing officials in the legal entity equivalent to the information required under Article 62(1), second subparagraph, point (a) of this Regulation.

For the purpose of this paragraph, senior managing officials means the natural persons who are the executive members of the management body, as well as the natural persons who exercise executive functions within a legal entity and are responsible, and accountable to the management body, for the day-to-day management of the entity.

In the cases referred to in paragraph 3 of this Article, when providing beneficial ownership information in accordance with Article 20 of this Regulation and Article 10 of Directive (EU) 2024/1640, legal entities shall provide the following:

  • (a) a statement that there is no beneficial owner or that the beneficial owners could not be determined, accompanied by a justification as to why it was not possible to determine the beneficial owner in accordance with Articles 51 to 57 of this Regulation and what constitutes uncertainty about the ascertained information;
  • (b) the details of all natural persons who hold the position of senior managing officials in the legal entity equivalent to the information required under Article 62(1), second subparagraph, point (a) of this Regulation.

For the purpose of this paragraph, senior managing officials means the natural persons who are the executive members of the management body, as well as the natural persons who exercise executive functions within a legal entity and are responsible, and accountable to the management body, for the day-to-day management of the entity.

In den in Absatz 3 dieses Artikels genannten Fällen haben juristische Personen bei der Übermittlung von Informationen über die wirtschaftlichen Eigentümer gemäß Artikel 20 dieser Verordnung und Artikel 10 der Richtlinie (EU) 2024/1640 Folgendes anzugeben:

  • (a) eine Erklärung, dass es keinen wirtschaftlichen Eigentümer gibt oder dass die wirtschaftlichen Eigentümer nicht bestimmt werden konnten, zusammen mit einer Begründung, warum es nicht möglich war, den wirtschaftlichen Eigentümer gemäß den Artikeln 51 bis 57 dieser Verordnung zu bestimmen, und worauf die Zweifel an den festgestellten Informationen beruhen;
  • (b) die Angaben zu allen natürlichen Personen, die in der juristischen Person die Stellung eines leitenden Geschäftsführungsmitglieds innehaben, entsprechend den nach Artikel 62 Absatz 1 Unterabsatz 2 Buchstabe a dieser Verordnung erforderlichen Informationen.

Für die Zwecke dieses Absatzes bezeichnet der Ausdruck „leitende Geschäftsführungsmitglieder“ die natürlichen Personen, die geschäftsführende Mitglieder des Leitungsorgans sind, sowie die natürlichen Personen, die innerhalb einer juristischen Person geschäftsführende Aufgaben wahrnehmen und für die tägliche Geschäftsführung der Einrichtung verantwortlich und gegenüber dem Leitungsorgan rechenschaftspflichtig sind.

5 5 5

Legal entities shall make the information collected pursuant to this Article available, upon request and without delay, to competent authorities.

Legal entities shall make the information collected pursuant to this Article available, upon request and without delay, to competent authorities.

Juristische Personen stellen die gemäß diesem Artikel erhobenen Informationen den zuständigen Behörden auf Ersuchen und unverzüglich zur Verfügung.

6 6 6

The information referred to in paragraph 4 shall be maintained for 5 years after the date on which the legal entities are dissolved or otherwise cease to exist, whether by persons designated by the entity to retain the documents, or by administrators or liquidators or other persons involved in the dissolution of the entity. The identity and contact details of the person responsible for retaining the information shall be reported to the central registers.

The information referred to in paragraph 4 shall be maintained for 5 years after the date on which the legal entities are dissolved or otherwise cease to exist, whether by persons designated by the entity to retain the documents, or by administrators or liquidators or other persons involved in the dissolution of the entity. The identity and contact details of the person responsible for retaining the information shall be reported to the central registers.

Die in Absatz 4 genannten Informationen sind fünf Jahre nach dem Tag aufzubewahren, an dem die juristischen Personen aufgelöst werden oder anderweitig zu bestehen aufhören, und zwar entweder durch von der Einrichtung mit der Aufbewahrung der Unterlagen betraute Personen oder durch Verwalter oder Liquidatoren oder andere an der Auflösung der Einrichtung beteiligte Personen. Die Identität und die Kontaktdaten der für die Aufbewahrung der Informationen verantwortlichen Person sind den zentralen Registern zu melden.

Article 64 — Trustee obligations Article 64 — Trustee obligations Article 64 — Pflichten der Treuhänder
1 1 1

In the case of any legal arrangement administered in a Member State or whose trustee or the person holding an equivalent position in a similar legal arrangement resides or is established in a Member State, trustees and persons holding an equivalent position in a similar legal arrangement shall obtain and hold the following information regarding the legal arrangement:

  • (a) basic information on the legal arrangement;
  • (b) adequate, accurate and up-to-date beneficial ownership information as provided under Article 62;
  • (c) where legal entities or legal arrangements are parties to the legal arrangement, basic information and beneficial ownership information on those legal entities and legal arrangements;
  • (d) information on any agent authorised to act on behalf of the legal arrangement or to take any action in relation to it, and on the obliged entities with which the trustee or person holding an equivalent position in a similar legal arrangement enter into a business relationship on behalf of the legal arrangement.

The information referred to in the first subparagraph shall be maintained for 5 years after the involvement of the trustee or the person holding an equivalent position with the express trust or similar legal arrangement ceases to exist.

In the case of any legal arrangement administered in a Member State or whose trustee or the person holding an equivalent position in a similar legal arrangement resides or is established in a Member State, trustees and persons holding an equivalent position in a similar legal arrangement shall obtain and hold the following information regarding the legal arrangement:

  • (a) basic information on the legal arrangement;
  • (b) adequate, accurate and up-to-date beneficial ownership information as provided under Article 62;
  • (c) where legal entities or legal arrangements are parties to the legal arrangement, basic information and beneficial ownership information on those legal entities and legal arrangements;
  • (d) information on any agent authorised to act on behalf of the legal arrangement or to take any action in relation to it, and on the obliged entities with which the trustee or person holding an equivalent position in a similar legal arrangement enter into a business relationship on behalf of the legal arrangement.

The information referred to in the first subparagraph shall be maintained for 5 years after the involvement of the trustee or the person holding an equivalent position with the express trust or similar legal arrangement ceases to exist.

Im Falle einer Rechtsvereinbarung, die in einem Mitgliedstaat verwaltet wird, oder deren Treuhänder oder Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung in einem Mitgliedstaat ansässig oder niedergelassen ist, haben Treuhänder und Personen mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung folgende Informationen über die Rechtsvereinbarung einzuholen und aufzubewahren:

  • (a) grundlegende Informationen über die Rechtsvereinbarung;
  • (b) angemessene, korrekte und aktuelle Informationen über die wirtschaftlichen Eigentümer gemäß Artikel 62;
  • (c) sofern juristische Personen oder Rechtsvereinbarungen Parteien der Rechtsvereinbarung sind, grundlegende Informationen und Informationen über die wirtschaftlichen Eigentümer dieser juristischen Personen und Rechtsvereinbarungen;
  • (d) Informationen über jeden Bevollmächtigten, der befugt ist, im Namen der Rechtsvereinbarung zu handeln oder in Bezug auf sie Maßnahmen zu ergreifen, sowie über die Verpflichteten, mit denen der Treuhänder oder die Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung im Namen der Rechtsvereinbarung eine Geschäftsbeziehung eingeht.

Die in Unterabsatz 1 genannten Informationen sind fünf Jahre lang aufzubewahren, nachdem die Beteiligung des Treuhänders oder der Person mit einer gleichwertigen Stellung an dem Express Trust oder der ähnlichen Rechtsvereinbarung beendet wurde.

2 2 2

The trustee or the person holding an equivalent position in a similar legal arrangement shall obtain and report to the central register beneficial ownership information and basic information on the legal arrangement without undue delay after the setting up of the express trust or similar legal arrangement and, in any case, within 28 calendar days thereof. The trustee or the person holding an equivalent position in a similar legal arrangement shall ensure that any change of beneficial ownership or of the basic information on the legal arrangement is reported to the central register without undue delay, and in any case, within 28 calendar days thereof.The trustee or the person holding an equivalent position in a similar legal arrangement shall regularly verify that the information they hold over the legal arrangement pursuant to paragraph 1, first subparagraph, is updated. Such verification shall be performed at least annually, whether as a self-standing process or as part of other periodical processes.

The trustee or the person holding an equivalent position in a similar legal arrangement shall obtain and report to the central register beneficial ownership information and basic information on the legal arrangement without undue delay after the setting up of the express trust or similar legal arrangement and, in any case, within 28 calendar days thereof. The trustee or the person holding an equivalent position in a similar legal arrangement shall ensure that any change of beneficial ownership or of the basic information on the legal arrangement is reported to the central register without undue delay, and in any case, within 28 calendar days thereof. The trustee or the person holding an equivalent position in a similar legal arrangement shall regularly verify that the information they hold over the legal arrangement pursuant to paragraph 1, first subparagraph, is updated. Such verification shall be performed at least annually, whether as a self-standing process or as part of other periodical processes.

Der Treuhänder oder die Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung holt Informationen über die wirtschaftlichen Eigentümer und grundlegende Informationen über die Rechtsvereinbarung ein und meldet diese unverzüglich nach Errichtung des Express Trusts oder der ähnlichen Rechtsvereinbarung und in jedem Fall innerhalb von 28 Kalendertagen danach an das zentrale Register. Der Treuhänder oder die Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung stellt sicher, dass jede Änderung der Informationen über die wirtschaftlichen Eigentümer oder der grundlegenden Informationen über die Rechtsvereinbarung unverzüglich und in jedem Fall innerhalb von 28 Kalendertagen danach dem zentralen Register gemeldet wird. Der Treuhänder oder die Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung überprüft regelmäßig, ob die Informationen, über die er beziehungsweise sie gemäß Absatz 1 Unterabsatz 1 über die Rechtsvereinbarung verfügt, aktualisiert sind. Eine solche Überprüfung ist mindestens einmal jährlich durchzuführen, und zwar entweder als eigenständiger Vorgang oder im Rahmen anderer regelmäßiger Vorgänge.

3 3 3

The trustees or the persons holding an equivalent position in a similar legal arrangement referred to in paragraph 1 shall disclose their status and provide the information on the beneficial owners and on the assets of the legal arrangements that are to be managed in the context of a business relationship or occasional transaction to obliged entities when the obliged entities are applying customer due diligence measures in accordance with Chapter III.

The trustees or the persons holding an equivalent position in a similar legal arrangement referred to in paragraph 1 shall disclose their status and provide the information on the beneficial owners and on the assets of the legal arrangements that are to be managed in the context of a business relationship or occasional transaction to obliged entities when the obliged entities are applying customer due diligence measures in accordance with Chapter III.

Die in Absatz 1 genannten Treuhänder oder Personen mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung haben ihren Status offenzulegen und den Verpflichteten, wenn diese Sorgfaltspflichten gegenüber Kunden gemäß Kapitel III anwenden, die Informationen über die wirtschaftlichen Eigentümer und die Vermögenswerte der Rechtsvereinbarungen, die im Rahmen einer Geschäftsbeziehung oder eines gelegentlichen Geschäfts verwaltet werden sollen, zur Verfügung zu stellen.

4 4 4

The beneficial owners of a legal arrangement other than the trustees or persons holding an equivalent position, its agents and the obliged entities servicing the legal arrangement, as well as any person and, in the case of legal arrangements, their trustees, who are part of the multi-layered control structure of the legal arrangement, shall provide the trustees or persons holding an equivalent position in a similar legal arrangement with all the information and documentation necessary for the trustees or persons holding an equivalent position to comply with the requirements of this Chapter.

The beneficial owners of a legal arrangement other than the trustees or persons holding an equivalent position, its agents and the obliged entities servicing the legal arrangement, as well as any person and, in the case of legal arrangements, their trustees, who are part of the multi-layered control structure of the legal arrangement, shall provide the trustees or persons holding an equivalent position in a similar legal arrangement with all the information and documentation necessary for the trustees or persons holding an equivalent position to comply with the requirements of this Chapter.

Die wirtschaftlichen Eigentümer einer Rechtsvereinbarung, bei denen es sich nicht um die Treuhänder oder Personen mit einer gleichwertigen Stellung, ihre Bevollmächtigten und die Verpflichteten, die die Rechtsvereinbarung betreuen, handelt, sowie alle Personen und — im Falle von Rechtsvereinbarungen — deren Treuhänder, die Teil der mehrstufigen Kontrollstruktur der Rechtsvereinbarung sind, stellen den Treuhändern oder Personen mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung alle Informationen und Unterlagen zur Verfügung, die erforderlich sind, damit die Treuhänder oder Personen mit einer gleichwertigen Stellung die Anforderungen dieses Kapitels erfüllen können.

5 5 5

Trustees of an express trust and persons holding an equivalent position in a similar legal arrangement shall make the information collected pursuant to this Article available, upon request and without delay, to competent authorities.

Trustees of an express trust and persons holding an equivalent position in a similar legal arrangement shall make the information collected pursuant to this Article available, upon request and without delay, to competent authorities.

Treuhänder eines Express Trusts und Personen mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung stellen die gemäß diesem Artikel erhobenen Informationen den zuständigen Behörden auf Ersuchen und unverzüglich zur Verfügung.

6 6 6

In the case of legal arrangements whose parties are legal entities, where, after having exhausted all possible means of identification pursuant to Articles 51 to 57, no person is identified as beneficial owner of those legal entities, or where there is substantial and justified uncertainty that the persons identified are the beneficial owners, trustees of express trusts or persons in an equivalent position in similar legal arrangements shall keep records of the actions taken in order to identify their beneficial owners.

In the case of legal arrangements whose parties are legal entities, where, after having exhausted all possible means of identification pursuant to Articles 51 to 57, no person is identified as beneficial owner of those legal entities, or where there is substantial and justified uncertainty that the persons identified are the beneficial owners, trustees of express trusts or persons in an equivalent position in similar legal arrangements shall keep records of the actions taken in order to identify their beneficial owners.

Im Falle von Rechtsvereinbarungen, deren Parteien juristische Personen sind, haben die Treuhänder von Express Trusts oder Personen mit einer gleichwertigen Stellung in ähnlichen Rechtsvereinbarungen, wenn nach Ausschöpfung aller möglichen Mittel zur Identifizierung gemäß den Artikeln 51 bis 57 keine Person als wirtschaftlicher Eigentümer dieser juristischen Personen identifiziert wird oder wenn erhebliche und begründete Zweifel daran bestehen, dass es sich bei den identifizierten Personen um die wirtschaftlichen Eigentümer handelt, Aufzeichnungen über die zur Identifizierung ihrer wirtschaftlichen Eigentümer ergriffenen Maßnahmen aufzubewahren.

7 7 7

In the cases referred to in paragraph 6 of this Article, when providing beneficial ownership information in accordance with Article 20 of this Regulation and Article 10 of Directive (EU) 2024/1640, trustees of express trusts or persons in an equivalent position in similar legal arrangements shall provide the following:

  • (a) a statement that there is no beneficial owner or that the beneficial owners could not be determined, accompanied by a justification as to why it was not possible to determine the beneficial owner in accordance with Article 51 to 57 of this Regulation and what constitutes uncertainty about the ascertained information;
  • (b) the details of all natural persons who hold the position of senior managing officials in the legal entity that is party to the legal arrangement equivalent to the information required under Article 62(1), second subparagraph, point (a), of this Regulation.

In the cases referred to in paragraph 6 of this Article, when providing beneficial ownership information in accordance with Article 20 of this Regulation and Article 10 of Directive (EU) 2024/1640, trustees of express trusts or persons in an equivalent position in similar legal arrangements shall provide the following:

  • (a) a statement that there is no beneficial owner or that the beneficial owners could not be determined, accompanied by a justification as to why it was not possible to determine the beneficial owner in accordance with Article 51 to 57 of this Regulation and what constitutes uncertainty about the ascertained information;
  • (b) the details of all natural persons who hold the position of senior managing officials in the legal entity that is party to the legal arrangement equivalent to the information required under Article 62(1), second subparagraph, point (a), of this Regulation.

In den in Absatz 6 dieses Artikels genannten Fällen haben Treuhänder von Express Trusts oder Personen mit einer gleichwertigen Stellung in ähnlichen Rechtsvereinbarungen bei der Übermittlung von Informationen über die wirtschaftlichen Eigentümer gemäß Artikel 20 dieser Verordnung und Artikel 10 der Richtlinie (EU) 2024/1640 Folgendes anzugeben:

  • (a) eine Erklärung, dass es keinen wirtschaftlichen Eigentümer gibt oder dass die wirtschaftlichen Eigentümer nicht bestimmt werden konnten, zusammen mit einer Begründung, warum es nicht möglich war, den wirtschaftlichen Eigentümer gemäß den Artikeln 51 bis 57 dieser Verordnung zu bestimmen, und worauf die Zweifel an den festgestellten Informationen beruhen;
  • (b) die Angaben zu allen natürlichen Personen, die in der juristischen Person, die Partei der Rechtsvereinbarung ist, die Stellung eines leitenden Geschäftsführungsmitglieds innehaben, entsprechend den nach Artikel 62 Absatz 1 Unterabsatz 2 Buchstabe a dieser Verordnung erforderlichen Informationen.
Article 65 — Exceptions to obligations of legal entities and legal arrangements Article 65 — Exceptions to obligations of legal entities and legal arrangements Article 65 — Ausnahmen von den Pflichten juristischer Personen und Rechtsvereinbarungen

Articles 63 and 64 shall not apply to:

  • (a) companies whose securities are admitted to trading on a regulated market, provided that:

    • (i) control over the company is exercised exclusively by the natural person with the voting rights;
    • (ii) no other legal entities or legal arrangements are part of the company’s ownership or control structure; and
    • (iii) for foreign legal entities under Article 67, equivalent requirements to those referred to in subpoints (i) and (ii) of this point exist under international standards;
  • (b) bodies governed by public law as defined in Article 2(1), point (4), of Directive 2014/24/EU of the European Parliament and of the Council

Directive 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC (OJ L 94, 28.3.2014, p. 65).

.

Articles 63 and 64 shall not apply to:

  • (a) companies whose securities are admitted to trading on a regulated market, provided that:
    • (i) control over the company is exercised exclusively by the natural person with the voting rights;
    • (ii) no other legal entities or legal arrangements are part of the company’s ownership or control structure; and
    • (iii) for foreign legal entities under Article 67, equivalent requirements to those referred to in subpoints (i) and (ii) of this point exist under international standards;
  • (b) bodies governed by public law as defined in Article 2(1), point (4), of Directive 2014/24/EU of the European Parliament and of the Council

Directive 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC (OJ L 94, 28.3.2014, p. 65).

Die Artikel 63 und 64 finden keine Anwendung auf:

  • (a) Unternehmen, deren Wertpapiere zum Handel an einem geregelten Markt zugelassen sind, sofern:
    • (i) die Kontrolle über das Unternehmen ausschließlich von der natürlichen Person mit den Stimmrechten ausgeübt wird;
    • (ii) keine anderen juristischen Personen oder Rechtsvereinbarungen Teil der Eigentums- oder Kontrollstruktur des Unternehmens sind; und
    • (iii) für ausländische juristische Personen nach Artikel 67 nach internationalen Standards gleichwertige Anforderungen wie die in den Ziffern (i) und (ii) dieses Buchstabens bestehen;
  • (b) Einrichtungen des öffentlichen Rechts im Sinne des Artikels 2 Absatz 1 Nummer 4 der Richtlinie 2014/24/EU des Europäischen Parlaments und des Rates.

Richtlinie 2014/24/EU des Europäischen Parlaments und des Rates vom 26. Februar 2014 über die öffentliche Auftragsvergabe und zur Aufhebung der Richtlinie 2004/18/EG (ABl. L 94 vom 28.3.2014, S. 65).

Article 66 — Nominee obligations Article 66 — Nominee obligations Article 66 — Pflichten von Nominee-Aktionären und Nominee-Direktoren

Nominee shareholders and nominee directors of a legal entity shall maintain adequate, accurate and up-to-date information on the identity of their nominator and the nominator’s beneficial owners and disclose them, as well as their status, to the legal entity. Legal entities shall report that information to the central register.Legal entities shall also report the information referred to in the first paragraph to obliged entities when the obliged entities are applying customer due diligence measures in accordance with Chapter III.

Nominee shareholders and nominee directors of a legal entity shall maintain adequate, accurate and up-to-date information on the identity of their nominator and the nominator’s beneficial owners and disclose them, as well as their status, to the legal entity. Legal entities shall report that information to the central register. Legal entities shall also report the information referred to in the first paragraph to obliged entities when the obliged entities are applying customer due diligence measures in accordance with Chapter III.

Nominee-Aktionäre und Nominee-Direktoren einer juristischen Person haben angemessene, korrekte und aktuelle Informationen über die Identität ihres Auftraggebers und dessen wirtschaftliche Eigentümer aufzubewahren und diese sowie ihren Status gegenüber der juristischen Person offenzulegen. Juristische Personen melden diese Informationen dem zentralen Register. Juristische Personen melden die in Absatz 1 genannten Informationen auch den Verpflichteten, wenn diese Sorgfaltspflichten gegenüber Kunden gemäß Kapitel III anwenden.

Article 67 — Foreign legal entities and foreign legal arrangements Article 67 — Foreign legal entities and foreign legal arrangements Article 67 — Ausländische juristische Personen und ausländische Rechtsvereinbarungen
1 1 1

Legal entities created outside the Union and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement that are administered outside the Union or that reside or are established outside the Union shall submit beneficial ownership information pursuant to Article 62 to the central register of the Member State where they:

  • (a) enter into a business relationship with an obliged entity;
  • (b) acquire real estate in the Union, whether directly or through intermediaries;
  • (c) acquire, whether directly or through intermediaries, any of the following goods from persons trading as referred to in Article 3, points (3) (f) and (j), in the context of an occasional transaction:

    • (i) motor vehicles for non-commercial purposes for a price of at least EUR 250000 or the equivalent in national currency;
    • (ii) watercraft for non-commercial purposes for a price of at least EUR 7500000 or the equivalent in national currency;
    • (iii) aircraft for non-commercial purposes for a price of at least EUR 7500000 or the equivalent in national currency;
  • (d) are awarded a public contract for goods or services, or concessions by a contracting authority in the Union.

Legal entities created outside the Union and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement that are administered outside the Union or that reside or are established outside the Union shall submit beneficial ownership information pursuant to Article 62 to the central register of the Member State where they:

  • (a) enter into a business relationship with an obliged entity;
  • (b) acquire real estate in the Union, whether directly or through intermediaries;
  • (c) acquire, whether directly or through intermediaries, any of the following goods from persons trading as referred to in Article 3, points (3)(f) and (j), in the context of an occasional transaction:
    • (i) motor vehicles for non-commercial purposes for a price of at least EUR 250000 or the equivalent in national currency;
    • (ii) watercraft for non-commercial purposes for a price of at least EUR 7500000 or the equivalent in national currency;
    • (iii) aircraft for non-commercial purposes for a price of at least EUR 7500000 or the equivalent in national currency;
  • (d) are awarded a public contract for goods or services, or concessions by a contracting authority in the Union.

Juristische Personen, die außerhalb der Union gegründet wurden, sowie Treuhänder von Express Trusts oder Personen mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung, die außerhalb der Union verwaltet werden oder außerhalb der Union ansässig oder niedergelassen sind, übermitteln Informationen über die wirtschaftlichen Eigentümer gemäß Artikel 62 an das zentrale Register des Mitgliedstaats, in dem sie:

  • (a) eine Geschäftsbeziehung mit einem Verpflichteten eingehen;
  • (b) unmittelbar oder über Vermittler Immobilien in der Union erwerben;
  • (c) im Rahmen eines gelegentlichen Geschäfts unmittelbar oder über Vermittler eine der folgenden Waren von Personen erwerben, die im Sinne des Artikels 3 Nummer 3 Buchstaben f und j Handel treiben:
    • (i) Kraftfahrzeuge für nichtgewerbliche Zwecke zu einem Preis von mindestens 250000 EUR oder dem Gegenwert in Landeswährung;
    • (ii) Wasserfahrzeuge für nichtgewerbliche Zwecke zu einem Preis von mindestens 7500000 EUR oder dem Gegenwert in Landeswährung;
    • (iii) Luftfahrzeuge für nichtgewerbliche Zwecke zu einem Preis von mindestens 7500000 EUR oder dem Gegenwert in Landeswährung;
  • (d) von einer öffentlichen Auftraggeberin oder einem öffentlichen Auftraggeber in der Union einen öffentlichen Auftrag über Waren oder Dienstleistungen oder eine Konzession erhalten.
2 2 2

By way of derogation from paragraph 1, point (a), where legal entities created outside the Union enter into a business relationship with an obliged entity, they shall only submit their beneficial ownership information to the central register where:

  • (a) they enter into a business relationship with an obliged entity that is associated with medium-high or high money laundering and terrorist financing risks pursuant to the risk assessment at Union level or the national risk assessment of the Member State concerned referred to in Articles 7 and 8 of Directive (EU) 2024/1640; or
  • (b) the risk assessment at Union level or the national risk assessment of the Member State concerned identifies that the category of legal entity or the sector in which the legal entity created outside the Union operates is associated, where relevant, with medium-high or high money laundering and terrorist financing risks.

By way of derogation from paragraph 1, point (a), where legal entities created outside the Union enter into a business relationship with an obliged entity, they shall only submit their beneficial ownership information to the central register where:

  • (a) they enter into a business relationship with an obliged entity that is associated with medium-high or high money laundering and terrorist financing risks pursuant to the risk assessment at Union level or the national risk assessment of the Member State concerned referred to in Articles 7 and 8 of Directive (EU) 2024/1640; or
  • (b) the risk assessment at Union level or the national risk assessment of the Member State concerned identifies that the category of legal entity or the sector in which the legal entity created outside the Union operates is associated, where relevant, with medium-high or high money laundering and terrorist financing risks.

Abweichend von Absatz 1 Buchstabe a übermitteln außerhalb der Union gegründete juristische Personen, die eine Geschäftsbeziehung mit einem Verpflichteten eingehen, ihre Informationen über die wirtschaftlichen Eigentümer dem zentralen Register nur, wenn:

  • (a) sie eine Geschäftsbeziehung mit einem Verpflichteten eingehen, der gemäß der Risikobewertung auf Unionsebene oder der in den Artikeln 7 und 8 der Richtlinie (EU) 2024/1640 genannten nationalen Risikobewertung des betreffenden Mitgliedstaats mit mittelhohen bis hohen Risiken der Geldwäsche und Terrorismusfinanzierung verbunden ist; oder
  • (b) die Risikobewertung auf Unionsebene oder die nationale Risikobewertung des betreffenden Mitgliedstaats ergibt, dass die Kategorie der juristischen Person oder der Sektor, in dem die außerhalb der Union gegründete juristische Person tätig ist, gegebenenfalls mit mittelhohen bis hohen Risiken der Geldwäsche und Terrorismusfinanzierung verbunden ist.
3 3 3

The beneficial ownership information shall be accompanied by a statement setting out in relation to which of those activities the information is submitted, as well as any relevant document, and shall be submitted:

  • (a) for the cases referred to in paragraph 1, point (a), prior to start of the business relationship;
  • (b) for the cases referred to in paragraph 1, points (b) and (c), before completion of the purchase;
  • (c) for the cases referred to in paragraph 1, point (d), before signature of the contract.

The beneficial ownership information shall be accompanied by a statement setting out in relation to which of those activities the information is submitted, as well as any relevant document, and shall be submitted:

  • (a) for the cases referred to in paragraph 1, point (a), prior to start of the business relationship;
  • (b) for the cases referred to in paragraph 1, points (b) and (c), before completion of the purchase;
  • (c) for the cases referred to in paragraph 1, point (d), before signature of the contract.

Den Informationen über die wirtschaftlichen Eigentümer ist eine Erklärung beizufügen, aus der hervorgeht, auf welche dieser Tätigkeiten sich die Übermittlung der Informationen bezieht, sowie jedes einschlägige Dokument; sie sind zu übermitteln:

  • (a) in den Fällen nach Absatz 1 Buchstabe a vor Beginn der Geschäftsbeziehung;
  • (b) in den Fällen nach Absatz 1 Buchstaben b und c vor Abschluss des Kaufs;
  • (c) in dem Fall nach Absatz 1 Buchstabe d vor Unterzeichnung des Vertrags.
4 4 4

For the purposes of paragraph 1, point (a), obliged entities shall inform the legal entities where the conditions laid down in paragraph 2 are met and require a certificate of proof of registration or an excerpt of the beneficial ownership information held in the central register to proceed with the business relationship or occasional transaction.

For the purposes of paragraph 1, point (a), obliged entities shall inform the legal entities where the conditions laid down in paragraph 2 are met and require a certificate of proof of registration or an excerpt of the beneficial ownership information held in the central register to proceed with the business relationship or occasional transaction.

Für die Zwecke des Absatzes 1 Buchstabe a informieren die Verpflichteten die juristischen Personen, wenn die in Absatz 2 festgelegten Bedingungen erfüllt sind, und verlangen eine Eintragungsbescheinigung oder einen Auszug aus den im zentralen Register gespeicherten Informationen über die wirtschaftlichen Eigentümer, um die Geschäftsbeziehung oder das gelegentliche Geschäft fortzusetzen.

5 5 5

In the cases covered by paragraph 1, legal entities created outside the Union and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement that are administered outside the Union or that reside or are established outside the Union shall report any change to the beneficial ownership information submitted to the central register pursuant to paragraph 1 without undue delay, and in any case, within 28 calendar days thereof.

The first subparagraph shall apply:

  • (a) for the cases referred to in paragraph 1, point (a), for the entire duration of the business relationship with the obliged entity;
  • (b) for the cases referred to in paragraph 1, point (b), for as long as the legal entity or legal arrangement owns the real estate;
  • (c) for the cases referred to in paragraph 1, point (c), for the period between the initial submission of the information to the central register and the completion of the purchase;
  • (d) for the cases referred to in paragraph 1, point (d), for the entire duration of the contract.

In the cases covered by paragraph 1, legal entities created outside the Union and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement that are administered outside the Union or that reside or are established outside the Union shall report any change to the beneficial ownership information submitted to the central register pursuant to paragraph 1 without undue delay, and in any case, within 28 calendar days thereof.

The first subparagraph shall apply:

  • (a) for the cases referred to in paragraph 1, point (a), for the entire duration of the business relationship with the obliged entity;
  • (b) for the cases referred to in paragraph 1, point (b), for as long as the legal entity or legal arrangement owns the real estate;
  • (c) for the cases referred to in paragraph 1, point (c), for the period between the initial submission of the information to the central register and the completion of the purchase;
  • (d) for the cases referred to in paragraph 1, point (d), for the entire duration of the contract.

In den unter Absatz 1 fallenden Fällen melden außerhalb der Union gegründete juristische Personen sowie Treuhänder von Express Trusts oder Personen mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung, die außerhalb der Union verwaltet werden oder außerhalb der Union ansässig oder niedergelassen sind, jede Änderung der gemäß Absatz 1 dem zentralen Register übermittelten Informationen über die wirtschaftlichen Eigentümer unverzüglich und in jedem Fall innerhalb von 28 Kalendertagen danach.

Unterabsatz 1 gilt:

  • (a) in den Fällen nach Absatz 1 Buchstabe a für die gesamte Dauer der Geschäftsbeziehung mit dem Verpflichteten;
  • (b) in dem Fall nach Absatz 1 Buchstabe b so lange, wie die juristische Person oder Rechtsvereinbarung Eigentümerin der Immobilie ist;
  • (c) in dem Fall nach Absatz 1 Buchstabe c für den Zeitraum zwischen der erstmaligen Übermittlung der Informationen an das zentrale Register und dem Abschluss des Kaufs;
  • (d) in dem Fall nach Absatz 1 Buchstabe d für die gesamte Vertragsdauer.
6 6 6

Where the legal entity, the trustee of the express trust or the person holding an equivalent position in a similar legal arrangement meets the conditions laid down in paragraph 1 in different Member States, a certificate of proof of registration of the beneficial ownership information in a central register held by one Member State shall be considered as sufficient proof of registration.

Where the legal entity, the trustee of the express trust or the person holding an equivalent position in a similar legal arrangement meets the conditions laid down in paragraph 1 in different Member States, a certificate of proof of registration of the beneficial ownership information in a central register held by one Member State shall be considered as sufficient proof of registration.

Erfüllt die juristische Person, der Treuhänder des Express Trusts oder die Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung die in Absatz 1 festgelegten Bedingungen in verschiedenen Mitgliedstaaten, gilt eine von einem Mitgliedstaat ausgestellte Bescheinigung über die Eintragung der Informationen über die wirtschaftlichen Eigentümer in einem zentralen Register als ausreichender Nachweis der Eintragung.

7 7 7

Where, on 10 July 2027, legal entities created outside the Union or legal arrangements administered outside the Union or whose trustee or person holding an equivalent position in a similar legal arrangement resides or is established outside the Union own, whether directly or through intermediaries, real estate, the beneficial ownership information of those legal entities and legal arrangements shall be submitted to the central register and accompanied by a justification for that submission by 10 January 2028.However, the first subparagraph shall not apply to legal entities or legal arrangements that have acquired real estate in the Union prior to 1 January 2014.Member States may decide, on the basis of risk, that an earlier date applies and notify the Commission thereof. The Commission shall communicate such decisions to the other Member States.

Where, on 10 July 2027, legal entities created outside the Union or legal arrangements administered outside the Union or whose trustee or person holding an equivalent position in a similar legal arrangement resides or is established outside the Union own, whether directly or through intermediaries, real estate, the beneficial ownership information of those legal entities and legal arrangements shall be submitted to the central register and accompanied by a justification for that submission by 10 January 2028. However, the first subparagraph shall not apply to legal entities or legal arrangements that have acquired real estate in the Union prior to 1 January 2014. Member States may decide, on the basis of risk, that an earlier date applies and notify the Commission thereof. The Commission shall communicate such decisions to the other Member States.

Wenn juristische Personen, die außerhalb der Union gegründet wurden, oder Rechtsvereinbarungen, die außerhalb der Union verwaltet werden oder deren Treuhänder oder Person mit einer gleichwertigen Stellung in einer ähnlichen Rechtsvereinbarung außerhalb der Union ansässig oder niedergelassen ist, am 10. Juli 2027 unmittelbar oder über Vermittler Immobilien besitzen, sind die Informationen über die wirtschaftlichen Eigentümer dieser juristischen Personen und Rechtsvereinbarungen bis zum 10. Januar 2028 dem zentralen Register zu übermitteln und ist dieser Übermittlung eine Begründung beizufügen. Unterabsatz 1 gilt jedoch nicht für juristische Personen oder Rechtsvereinbarungen, die vor dem 1. Januar 2014 Immobilien in der Union erworben haben. Die Mitgliedstaaten können auf der Grundlage einer Risikobewertung beschließen, dass ein früherer Zeitpunkt gilt, und die Kommission davon in Kenntnis setzen. Die Kommission teilt solche Beschlüsse den anderen Mitgliedstaaten mit.

8 8 8

Member States may, on the basis of risk, extend the obligation set out in paragraph 1, point (a), to business relationships with foreign legal entities that are ongoing on 10 July 2027 and notify the Commission thereof. The Commission shall communicate such decisions to the other Member States.

Member States may, on the basis of risk, extend the obligation set out in paragraph 1, point (a), to business relationships with foreign legal entities that are ongoing on 10 July 2027 and notify the Commission thereof. The Commission shall communicate such decisions to the other Member States.

Die Mitgliedstaaten können auf der Grundlage einer Risikobewertung die in Absatz 1 Buchstabe a festgelegte Pflicht auf Geschäftsbeziehungen mit ausländischen juristischen Personen ausdehnen, die am 10. Juli 2027 bestehen, und die Kommission davon in Kenntnis setzen. Die Kommission teilt solche Beschlüsse den anderen Mitgliedstaaten mit.

Article 68 — Penalties Article 68 — Penalties Article 68 — Sanktionen
1 1 1

Member States shall lay down rules on the penalties applicable to breaches of the provisions of this Chapter and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive.Member States shall by 10 January 2025 notify the Commission of those rules on penalties together with their legal basis and shall notify it, without delay, of any subsequent amendment affecting them.

Member States shall lay down rules on the penalties applicable to breaches of the provisions of this Chapter and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive. Member States shall by 10 January 2025 notify the Commission of those rules on penalties together with their legal basis and shall notify it, without delay, of any subsequent amendment affecting them.

Die Mitgliedstaaten legen Vorschriften über die Sanktionen fest, die bei Verstößen gegen die Bestimmungen dieses Kapitels anwendbar sind, und treffen alle erforderlichen Maßnahmen, um deren Umsetzung sicherzustellen. Die vorgesehenen Sanktionen müssen wirksam, verhältnismäßig und abschreckend sein. Die Mitgliedstaaten teilen der Kommission bis zum 10. Januar 2025 diese Sanktionsvorschriften zusammen mit ihrer Rechtsgrundlage mit und setzen sie unverzüglich von späteren Änderungen in Kenntnis, die diese Vorschriften betreffen.

2 2 2

By 10 July 2026, the Commission shall adopt delegated acts in accordance with Article 85 to supplement this Regulation by defining:

  • (a) the categories of breaches that are subject to penalties and the persons liable for such breaches;
  • (b) indicators to classify the level of gravity of breaches that are subject to penalties;
  • (c) the criteria to be taken into account when setting the level of penalties.

The Commission shall regularly review the delegated act referred to in the first subparagraph to ensure that it identifies the relevant categories of breaches and that the related penalties are effective, dissuasive and proportionate.

By 10 July 2026, the Commission shall adopt delegated acts in accordance with Article 85 to supplement this Regulation by defining:

  • (a) the categories of breaches that are subject to penalties and the persons liable for such breaches;
  • (b) indicators to classify the level of gravity of breaches that are subject to penalties;
  • (c) the criteria to be taken into account when setting the level of penalties.

The Commission shall regularly review the delegated act referred to in the first subparagraph to ensure that it identifies the relevant categories of breaches and that the related penalties are effective, dissuasive and proportionate.

Bis zum 10. Juli 2026 erlässt die Kommission gemäß Artikel 85 delegierte Rechtsakte zur Ergänzung dieser Verordnung, in denen Folgendes festgelegt wird:

  • (a) die Kategorien von Verstößen, die mit Sanktionen belegt werden, und die für diese Verstöße verantwortlichen Personen;
  • (b) Indikatoren zur Einstufung des Schweregrads von Verstößen, die mit Sanktionen belegt werden;
  • (c) die Kriterien, die bei der Festsetzung der Höhe der Sanktionen zu berücksichtigen sind.

Die Kommission überprüft den in Unterabsatz 1 genannten delegierten Rechtsakt regelmäßig, um sicherzustellen, dass darin die einschlägigen Kategorien von Verstößen bestimmt werden und die damit verbundenen Sanktionen wirksam, abschreckend und verhältnismäßig sind.

CHAPTER V — REPORTING OBLIGATIONS CHAPTER V — REPORTING OBLIGATIONS CHAPTER V — MELDEPFLICHTEN
Article 69 — Reporting of suspicions Article 69 — Reporting of suspicions Article 69 — Meldung von Verdachtsfällen
1 1 1

Obliged entities, and, where applicable, their directors and employees, shall cooperate fully with the FIU by promptly:

  • (a) reporting to the FIU, on their own initiative, where the obliged entity knows, suspects or has reasonable grounds to suspect that funds or activities, regardless of the amount involved, are the proceeds of criminal activity or are related to terrorist financing or criminal activity and by responding to requests by the FIU for additional information in such cases;
  • (b) providing the FIU, at its request, with all necessary information, including information on transaction records, within the deadlines imposed.

All suspicious transactions, including attempted transactions and suspicions arising from the inability to conduct customer due diligence shall be reported in accordance with the first subparagraph.For the purposes of the first subparagraph, obliged entities shall reply to requests for information by the FIU within 5 working days. In justified and urgent cases, FIUs may shorten that deadline, including to less than 24 hours.By way of derogation from the third subparagraph, the FIU may extend the deadline for a response beyond the 5 working days where it considers it justified and provided that the extension does not undermine the FIU’s analysis.

Obliged entities, and, where applicable, their directors and employees, shall cooperate fully with the FIU by promptly:

  • (a) reporting to the FIU, on their own initiative, where the obliged entity knows, suspects or has reasonable grounds to suspect that funds or activities, regardless of the amount involved, are the proceeds of criminal activity or are related to terrorist financing or criminal activity and by responding to requests by the FIU for additional information in such cases;
  • (b) providing the FIU, at its request, with all necessary information, including information on transaction records, within the deadlines imposed.

All suspicious transactions, including attempted transactions and suspicions arising from the inability to conduct customer due diligence shall be reported in accordance with the first subparagraph. For the purposes of the first subparagraph, obliged entities shall reply to requests for information by the FIU within 5 working days. In justified and urgent cases, FIUs may shorten that deadline, including to less than 24 hours. By way of derogation from the third subparagraph, the FIU may extend the deadline for a response beyond the 5 working days where it considers it justified and provided that the extension does not undermine the FIU’s analysis.

Verpflichtete und gegebenenfalls ihre Mitglieder der Leitungsorgane und Beschäftigten arbeiten uneingeschränkt mit der zentralen Meldestelle (FIU) zusammen, indem sie unverzüglich:

  • (a) der FIU aus eigener Initiative melden, wenn der Verpflichtete weiß, vermutet oder aufgrund von Tatsachen berechtigten Grund zu der Vermutung hat, dass Gelder oder Tätigkeiten unabhängig von ihrer Höhe aus einer kriminellen Tätigkeit stammen oder mit Terrorismusfinanzierung oder kriminellen Tätigkeiten zusammenhängen, und in solchen Fällen auf Ersuchen der FIU zusätzliche Informationen übermitteln;
  • (b) der FIU auf deren Ersuchen innerhalb der gesetzten Fristen alle erforderlichen Informationen, einschließlich Informationen über Transaktionsaufzeichnungen, übermitteln.

Alle verdächtigen Transaktionen, einschließlich versuchter Transaktionen und Verdachtsfälle, die sich aus der Unmöglichkeit ergeben, Sorgfaltspflichten gegenüber Kunden durchzuführen, sind gemäß Unterabsatz 1 zu melden. Für die Zwecke von Unterabsatz 1 antworten die Verpflichteten innerhalb von fünf Arbeitstagen auf Informationsersuchen der FIU. In begründeten und dringenden Fällen können die FIUs diese Frist, auch auf weniger als 24 Stunden, verkürzen. Abweichend von Unterabsatz 3 kann die FIU die Antwortfrist über fünf Arbeitstage hinaus verlängern, wenn sie dies für gerechtfertigt hält und die Verlängerung ihre Analyse nicht beeinträchtigt.

2 2 2

For the purposes of paragraph 1, obliged entities shall assess transactions or activities carried out by their customers on the basis of and against any relevant fact and information known to them or which they are in possession of. Where necessary, obliged entities shall prioritise their assessment taking into consideration the urgency of the transaction or activity and the risks affecting the Member State in which they are established.A suspicion pursuant to paragraph 1, point (a), shall be based on the characteristics of the customer and their counterparts, the size and nature of the transaction or activity or the methods and patterns thereof, the link between several transactions or activities, the origin, destination or use of funds, or any other circumstance known to the obliged entity, including the consistency of the transaction or activity with the information obtained pursuant to Chapter III including the risk profile of the client.

For the purposes of paragraph 1, obliged entities shall assess transactions or activities carried out by their customers on the basis of and against any relevant fact and information known to them or which they are in possession of. Where necessary, obliged entities shall prioritise their assessment taking into consideration the urgency of the transaction or activity and the risks affecting the Member State in which they are established. A suspicion pursuant to paragraph 1, point (a), shall be based on the characteristics of the customer and their counterparts, the size and nature of the transaction or activity or the methods and patterns thereof, the link between several transactions or activities, the origin, destination or use of funds, or any other circumstance known to the obliged entity, including the consistency of the transaction or activity with the information obtained pursuant to Chapter III including the risk profile of the client.

Für die Zwecke des Absatzes 1 bewerten die Verpflichteten die von ihren Kunden durchgeführten Transaktionen oder Tätigkeiten auf der Grundlage aller ihnen bekannten oder vorliegenden einschlägigen Tatsachen und Informationen und unter Berücksichtigung dieser Tatsachen und Informationen. Soweit erforderlich, räumen die Verpflichteten ihrer Bewertung unter Berücksichtigung der Dringlichkeit der Transaktion oder Tätigkeit und der Risiken, die den Mitgliedstaat betreffen, in dem sie niedergelassen sind, Priorität ein. Ein Verdacht gemäß Absatz 1 Buchstabe a muss auf den Merkmalen des Kunden und seiner Geschäftspartner, dem Umfang und der Art der Transaktion oder Tätigkeit oder deren Methoden und Mustern, dem Zusammenhang zwischen mehreren Transaktionen oder Tätigkeiten, dem Ursprung, dem Bestimmungsort oder der Verwendung der Gelder oder jedem anderen dem Verpflichteten bekannten Umstand beruhen, einschließlich der Übereinstimmung der Transaktion oder Tätigkeit mit den gemäß Kapitel III erlangten Informationen, einschließlich des Risikoprofils des Kunden.

3 3 3

By 10 July 2026, AMLA shall develop draft implementing technical standards and submit them to the Commission for adoption. Those draft implementing technical standards shall specify the format to be used for the reporting of suspicions pursuant to paragraph 1, point (a), and for the provision of transaction records pursuant to paragraph 1, point (b).

By 10 July 2026, AMLA shall develop draft implementing technical standards and submit them to the Commission for adoption. Those draft implementing technical standards shall specify the format to be used for the reporting of suspicions pursuant to paragraph 1, point (a), and for the provision of transaction records pursuant to paragraph 1, point (b).

Bis zum 10. Juli 2026 entwickelt die AMLA Entwürfe technischer Durchführungsstandards und legt sie der Kommission zur Annahme vor. In diesen Entwürfen technischer Durchführungsstandards wird das Format festgelegt, das für die Meldung von Verdachtsfällen gemäß Absatz 1 Buchstabe a und für die Übermittlung von Transaktionsaufzeichnungen gemäß Absatz 1 Buchstabe b zu verwenden ist.

4 4 4

Power is conferred on the Commission to adopt the implementing technical standards referred to in paragraph 3 of this Article in accordance with Article 53 of Regulation (EU) 2024/1620.

Power is conferred on the Commission to adopt the implementing technical standards referred to in paragraph 3 of this Article in accordance with Article 53 of Regulation (EU) 2024/1620.

Der Kommission wird die Befugnis übertragen, die in Absatz 3 dieses Artikels genannten technischen Durchführungsstandards gemäß Artikel 53 der Verordnung (EU) 2024/1620 zu erlassen.

5 5 5

By 10 July 2027, AMLA shall issue guidelines on indicators of suspicious activity or behaviours. Those guidelines shall be periodically updated.

By 10 July 2027, AMLA shall issue guidelines on indicators of suspicious activity or behaviours. Those guidelines shall be periodically updated.

Bis zum 10. Juli 2027 erlässt die AMLA Leitlinien zu Indikatoren für verdächtige Tätigkeiten oder Verhaltensweisen. Diese Leitlinien werden regelmäßig aktualisiert.

6 6 6

The compliance officer appointed in accordance with Article 11(2) shall transmit the information referred to in paragraph 1 of this Article to the FIU of the Member State in whose territory the obliged entity transmitting the information is established.

The compliance officer appointed in accordance with Article 11(2) shall transmit the information referred to in paragraph 1 of this Article to the FIU of the Member State in whose territory the obliged entity transmitting the information is established.

Der gemäß Artikel 11 Absatz 2 bestellte Compliance-Beauftragte übermittelt die in Absatz 1 dieses Artikels genannten Informationen der FIU des Mitgliedstaats, in dessen Hoheitsgebiet der die Informationen übermittelnde Verpflichtete niedergelassen ist.

7 7 7

Obliged entities shall ensure that the compliance officer appointed in accordance with Article 11(2), as well as any employee or person in a comparable position, including agents and distributors, involved in the performance of the tasks covered by this Article are protected against retaliation, discrimination and any other unfair treatment for carrying out those tasks.This paragraph shall not affect the protection that the persons referred to in the first subparagraph may be entitled to under Directive (EU) 2019/1937.

Obliged entities shall ensure that the compliance officer appointed in accordance with Article 11(2), as well as any employee or person in a comparable position, including agents and distributors, involved in the performance of the tasks covered by this Article are protected against retaliation, discrimination and any other unfair treatment for carrying out those tasks. This paragraph shall not affect the protection that the persons referred to in the first subparagraph may be entitled to under Directive (EU) 2019/1937.

Die Verpflichteten stellen sicher, dass der gemäß Artikel 11 Absatz 2 bestellte Compliance-Beauftragte sowie alle an der Wahrnehmung der unter diesen Artikel fallenden Aufgaben beteiligten Beschäftigten oder Personen in einer vergleichbaren Stellung, einschließlich Bevollmächtigter und Vertriebshändler, gegen Vergeltungsmaßnahmen, Diskriminierung und jede andere ungerechte Behandlung wegen der Wahrnehmung dieser Aufgaben geschützt sind. Dieser Absatz berührt nicht den Schutz, auf den die in Unterabsatz 1 genannten Personen nach der Richtlinie (EU) 2019/1937 Anspruch haben können.

8 8 8

Where the activities of a partnership for information sharing result in the knowledge, suspicion or reasonable grounds to suspect that funds, regardless of the amount involved, are the proceeds of criminal activity or are related to terrorist financing, obliged entities which identified suspicions in relation to the activities of their customers may designate one among them which shall be tasked with the submission of a report to the FIU pursuant to paragraph 1, point (a). Such submission shall include at least the name and contact details of all the obliged entities that participated in the activities giving rise to the report.Where the obliged entities referred to in the first subparagraph are established in several Member States, the information shall be reported to each relevant FIU. To that end, obliged entities shall ensure that the report is submitted by an obliged entity within the territory of the Member States where the FIU is located.Where the obliged entities decide not to avail themselves of the possibility to submit a single report with the FIU pursuant to the first subparagraph, they shall include a reference in their reports to the fact that the suspicion is the result of the activities of a partnership for information sharing.

Where the activities of a partnership for information sharing result in the knowledge, suspicion or reasonable grounds to suspect that funds, regardless of the amount involved, are the proceeds of criminal activity or are related to terrorist financing, obliged entities which identified suspicions in relation to the activities of their customers may designate one among them which shall be tasked with the submission of a report to the FIU pursuant to paragraph 1, point (a). Such submission shall include at least the name and contact details of all the obliged entities that participated in the activities giving rise to the report. Where the obliged entities referred to in the first subparagraph are established in several Member States, the information shall be reported to each relevant FIU. To that end, obliged entities shall ensure that the report is submitted by an obliged entity within the territory of the Member States where the FIU is located. Where the obliged entities decide not to avail themselves of the possibility to submit a single report with the FIU pursuant to the first subparagraph, they shall include a reference in their reports to the fact that the suspicion is the result of the activities of a partnership for information sharing.

Führen die Tätigkeiten einer Partnerschaft zum Informationsaustausch dazu, dass bekannt ist, dass Gelder unabhängig von ihrer Höhe aus einer kriminellen Tätigkeit stammen oder mit Terrorismusfinanzierung zusammenhängen, oder besteht ein entsprechender Verdacht oder berechtigter Grund zu einem solchen Verdacht, so können Verpflichtete, die im Zusammenhang mit den Tätigkeiten ihrer Kunden Verdachtsmomente festgestellt haben, einen unter ihnen benennen, der mit der Übermittlung einer Meldung an die FIU gemäß Absatz 1 Buchstabe a beauftragt wird. Diese Meldung muss zumindest den Namen und die Kontaktdaten aller Verpflichteten enthalten, die an den Tätigkeiten beteiligt waren, aufgrund deren die Meldung erfolgt. Sind die in Unterabsatz 1 genannten Verpflichteten in mehreren Mitgliedstaaten niedergelassen, so sind die Informationen jeder einschlägigen FIU zu melden. Zu diesem Zweck stellen die Verpflichteten sicher, dass die Meldung von einem Verpflichteten im Hoheitsgebiet des Mitgliedstaats übermittelt wird, in dem sich die FIU befindet. Beschließen die Verpflichteten, die Möglichkeit der Übermittlung einer einzigen Meldung an die FIU gemäß Unterabsatz 1 nicht in Anspruch zu nehmen, so nehmen sie in ihre Meldungen einen Hinweis darauf auf, dass der Verdacht auf die Tätigkeiten einer Partnerschaft zum Informationsaustausch zurückgeht.

9 9 9

The obliged entities referred to in paragraph 8 of this Article shall retain a copy of any reports submitted pursuant to that paragraph in accordance with Article 77.

The obliged entities referred to in paragraph 8 of this Article shall retain a copy of any reports submitted pursuant to that paragraph in accordance with Article 77.

Die in Absatz 8 dieses Artikels genannten Verpflichteten bewahren gemäß Artikel 77 eine Kopie aller nach diesem Absatz übermittelten Meldungen auf.

Article 70 — Specific provisions for reporting of suspicions by certain categories of obliged entities Article 70 — Specific provisions for reporting of suspicions by certain categories of obliged entities Article 70 — Besondere Bestimmungen für die Meldung von Verdachtsfällen durch bestimmte Kategorien von Verpflichteten
1 1 1

By way of derogation from Article 69(1), Member States may allow obliged entities referred to in Article 3, point (3)(a) and (b), to transmit the information referred to in Article 69(1) to a self-regulatory body designated by the Member State.The designated self-regulatory body shall forward the information referred to in the first subparagraph to the FIU promptly and unfiltered.

By way of derogation from Article 69(1), Member States may allow obliged entities referred to in Article 3, point (3)(a) and (b), to transmit the information referred to in Article 69(1) to a self-regulatory body designated by the Member State. The designated self-regulatory body shall forward the information referred to in the first subparagraph to the FIU promptly and unfiltered.

Abweichend von Artikel 69 Absatz 1 können die Mitgliedstaaten den in Artikel 3 Nummer 3 Buchstaben a und b genannten Verpflichteten gestatten, die in Artikel 69 Absatz 1 genannten Informationen an eine von dem Mitgliedstaat benannte Selbstverwaltungseinrichtung zu übermitteln. Die benannte Selbstverwaltungseinrichtung leitet die in Unterabsatz 1 genannten Informationen unverzüglich und ungefiltert an die FIU weiter.

2 2 2

Notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors shall be exempted from the requirements laid down in Article 69(1) to the extent that such exemption relates to information that they receive from, or obtain on a client, in the course of ascertaining the legal position of that client, or performing their task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, regardless of whether such information is received or obtained before, during or after such proceedings.

The exemption set out in the first subparagraph shall not apply when the obliged entities referred to therein:

  • (a) take part in money laundering, its predicate offences or terrorist financing;
  • (b) provide legal advice for the purposes of money laundering, its predicate offences or terrorist financing; or
  • (c) know that the client is seeking legal advice for the purposes of money laundering, its predicate offences or terrorist financing; knowledge or purpose may be inferred from objective factual circumstances.

Notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors shall be exempted from the requirements laid down in Article 69(1) to the extent that such exemption relates to information that they receive from, or obtain on, a client, in the course of ascertaining the legal position of that client, or performing their task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, regardless of whether such information is received or obtained before, during or after such proceedings.

The exemption set out in the first subparagraph shall not apply when the obliged entities referred to therein:

  • (a) take part in money laundering, its predicate offences or terrorist financing;
  • (b) provide legal advice for the purposes of money laundering, its predicate offences or terrorist financing; or
  • (c) know that the client is seeking legal advice for the purposes of money laundering, its predicate offences or terrorist financing; knowledge or purpose may be inferred from objective factual circumstances.

Notare, Rechtsanwälte, andere unabhängige Angehörige rechtsberatender Berufe, Wirtschaftsprüfer, externe Buchhalter und Steuerberater sind von den Anforderungen des Artikels 69 Absatz 1 insoweit ausgenommen, als sich diese Ausnahme auf Informationen bezieht, die sie von einem Mandanten erhalten oder über einen Mandanten erlangen, während sie dessen Rechtsstellung feststellen oder ihre Aufgabe wahrnehmen, den Mandanten in oder im Zusammenhang mit Gerichtsverfahren zu verteidigen oder zu vertreten, einschließlich der Beratung über die Einleitung oder Vermeidung solcher Verfahren, unabhängig davon, ob diese Informationen vor, während oder nach solchen Verfahren erhalten oder erlangt werden.

Die in Unterabsatz 1 genannte Ausnahme gilt nicht, wenn die dort genannten Verpflichteten:

  • (a) an Geldwäsche, deren Vortaten oder Terrorismusfinanzierung beteiligt sind;
  • (b) Rechtsberatung zum Zweck der Geldwäsche, deren Vortaten oder der Terrorismusfinanzierung leisten; oder
  • (c) wissen, dass der Mandant Rechtsberatung zum Zweck der Geldwäsche, deren Vortaten oder der Terrorismusfinanzierung sucht; Kenntnis oder Zweck kann aus objektiven tatsächlichen Umständen abgeleitet werden.
3 3 3

In addition to the situations referred to in paragraph 2, second subparagraph, where justified on the basis of the higher risks of money laundering, its predicate offences or terrorist financing associated with certain types of transactions, Member States may decide that the exemption referred to in paragraph 2, first subparagraph, does not apply to those types of transactions and, as appropriate, impose additional reporting obligations on the obliged entities referred to in that paragraph. Member States shall notify the Commission of any decision taken pursuant to this paragraph. The Commission shall communicate such decisions to the other Member States.

In addition to the situations referred to in paragraph 2, second subparagraph, where justified on the basis of the higher risks of money laundering, its predicate offences or terrorist financing associated with certain types of transactions, Member States may decide that the exemption referred to in paragraph 2, first subparagraph, does not apply to those types of transactions and, as appropriate, impose additional reporting obligations on the obliged entities referred to in that paragraph. Member States shall notify the Commission of any decision taken pursuant to this paragraph. The Commission shall communicate such decisions to the other Member States.

Zusätzlich zu den in Absatz 2 Unterabsatz 2 genannten Fällen können die Mitgliedstaaten, wenn dies aufgrund der mit bestimmten Arten von Transaktionen verbundenen höheren Risiken der Geldwäsche, ihrer Vortaten oder der Terrorismusfinanzierung gerechtfertigt ist, beschließen, dass die in Absatz 2 Unterabsatz 1 genannte Ausnahme für diese Arten von Transaktionen nicht gilt, und gegebenenfalls den in jenem Absatz genannten Verpflichteten zusätzliche Meldepflichten auferlegen. Die Mitgliedstaaten teilen der Kommission jeden gemäß diesem Absatz gefassten Beschluss mit. Die Kommission teilt solche Beschlüsse den anderen Mitgliedstaaten mit.

Article 71 — Refraining from carrying out transactions Article 71 — Refraining from carrying out transactions Article 71 — Unterlassung der Durchführung von Transaktionen
1 1 1

Obliged entities shall refrain from carrying out transactions which they know or suspect to be related to proceeds of criminal activity or to terrorist financing until they have submitted a report in accordance with Article 69(1), first subparagraph, point (a), and have complied with any further specific instructions from the FIU or other competent authority in accordance with the applicable law. Obliged entities may carry out the transaction concerned after having assessed the risks of proceeding with the transaction if they have not received instructions to the contrary from the FIU within 3 working days of submitting the report.

Obliged entities shall refrain from carrying out transactions which they know or suspect to be related to proceeds of criminal activity or to terrorist financing until they have submitted a report in accordance with Article 69(1), first subparagraph, point (a), and have complied with any further specific instructions from the FIU or other competent authority in accordance with the applicable law. Obliged entities may carry out the transaction concerned after having assessed the risks of proceeding with the transaction if they have not received instructions to the contrary from the FIU within 3 working days of submitting the report.

Verpflichtete sehen von der Durchführung von Transaktionen ab, von denen sie wissen oder vermuten, dass sie mit Erträgen aus kriminellen Tätigkeiten oder mit Terrorismusfinanzierung zusammenhängen, bis sie eine Meldung gemäß Artikel 69 Absatz 1 Unterabsatz 1 Buchstabe a übermittelt und etwaige weitere besondere Anweisungen der FIU oder einer anderen zuständigen Behörde nach dem geltenden Recht befolgt haben. Verpflichtete können die betreffende Transaktion nach Bewertung der Risiken ihrer Durchführung ausführen, wenn sie innerhalb von drei Arbeitstagen nach Übermittlung der Meldung keine gegenteiligen Anweisungen der FIU erhalten haben.

2 2 2

Where it is not possible for an obliged entity to refrain from carrying out a transaction as referred to in paragraph 1or where refraining would be likely to frustrate efforts to pursue the beneficiaries of a suspected transaction, the obliged entity shall inform the FIU immediately after carrying out the transaction.

Where it is not possible for an obliged entity to refrain from carrying out a transaction as referred to in paragraph 1 or where refraining would be likely to frustrate efforts to pursue the beneficiaries of a suspected transaction, the obliged entity shall inform the FIU immediately after carrying out the transaction.

Ist es einem Verpflichteten nicht möglich, die Durchführung einer Transaktion gemäß Absatz 1 zu unterlassen, oder würde das Unterlassen wahrscheinlich die Bemühungen vereiteln, die Begünstigten einer verdächtigen Transaktion zu verfolgen, so informiert der Verpflichtete die FIU unmittelbar nach Durchführung der Transaktion.

Article 72 — Disclosure to FIU Article 72 — Disclosure to FIU Article 72 — Offenlegung gegenüber der FIU

Disclosure of information to the FIU in good faith by an obliged entity or by an employee or director of such an obliged entity in accordance with Articles 69 and 70 shall not constitute a breach of any restriction on disclosure of information imposed by contract or by any legislative, regulatory or administrative provision, and shall not involve the obliged entity or its directors or employees in liability of any kind even in circumstances where they were not precisely aware of the underlying criminal activity and regardless of whether illegal activity actually occurred.

Disclosure of information to the FIU in good faith by an obliged entity or by an employee or director of such an obliged entity in accordance with Articles 69 and 70 shall not constitute a breach of any restriction on disclosure of information imposed by contract or by any legislative, regulatory or administrative provision, and shall not involve the obliged entity or its directors or employees in liability of any kind even in circumstances where they were not precisely aware of the underlying criminal activity and regardless of whether illegal activity actually occurred.

Die gutgläubige Offenlegung von Informationen gegenüber der FIU durch einen Verpflichteten oder durch einen Beschäftigten oder ein Mitglied des Leitungsorgans eines solchen Verpflichteten gemäß den Artikeln 69 und 70 stellt keinen Verstoß gegen eine vertraglich oder durch Rechts- oder Verwaltungsvorschriften auferlegte Beschränkung der Offenlegung von Informationen dar und begründet für den Verpflichteten oder seine Mitglieder des Leitungsorgans oder Beschäftigten keinerlei Haftung, selbst wenn sie sich der zugrunde liegenden kriminellen Tätigkeit nicht genau bewusst waren und unabhängig davon, ob tatsächlich eine rechtswidrige Tätigkeit stattgefunden hat.

Article 73 — Prohibition of disclosure Article 73 — Prohibition of disclosure Article 73 — Verbot der Offenlegung
1 1 1

Obliged entities and their directors, employees, or persons in comparable positions, including agents and distributors, shall not disclose to the customer concerned or to other third persons the fact that transactions or activities are being or have been assessed in accordance with Article 69, that information is being, will be or has been transmitted in accordance with Article 69 or 70 or that a money laundering or terrorist financing analysis is being, or may be, carried out.

Obliged entities and their directors, employees, or persons in comparable positions, including agents and distributors, shall not disclose to the customer concerned or to other third persons the fact that transactions or activities are being or have been assessed in accordance with Article 69, that information is being, will be or has been transmitted in accordance with Article 69 or 70 or that a money laundering or terrorist financing analysis is being, or may be, carried out.

Verpflichtete und ihre Mitglieder des Leitungsorgans, Beschäftigten oder Personen in vergleichbaren Stellungen, einschließlich Bevollmächtigter und Vertriebshändler, dürfen dem betreffenden Kunden oder sonstigen Dritten nicht offenlegen, dass Transaktionen oder Tätigkeiten gemäß Artikel 69 geprüft werden oder geprüft wurden, dass Informationen gemäß Artikel 69 oder 70 übermittelt werden, werden sollen oder übermittelt wurden oder dass eine Analyse im Hinblick auf Geldwäsche oder Terrorismusfinanzierung durchgeführt wird oder möglicherweise durchgeführt wird.

2 2 2

Paragraph 1 shall not apply to disclosures to competent authorities and to self-regulatory bodies where they perform supervisory functions, or to disclosure for the purposes of investigating and prosecuting money laundering, terrorist financing and other criminal activity.

Paragraph 1 shall not apply to disclosures to competent authorities and to self-regulatory bodies where they perform supervisory functions, or to disclosure for the purposes of investigating and prosecuting money laundering, terrorist financing and other criminal activity.

Absatz 1 gilt nicht für Offenlegungen gegenüber zuständigen Behörden und Selbstverwaltungseinrichtungen, wenn diese Aufsichtsfunktionen wahrnehmen, oder für Offenlegungen zum Zweck der Untersuchung und strafrechtlichen Verfolgung von Geldwäsche, Terrorismusfinanzierung und anderen kriminellen Tätigkeiten.

3 3 3

By way of derogation from paragraph 1 of this Article, disclosure may take place between obliged entities that belong to the same group, or between such entities and their branches and subsidiaries established in third countries, provided that those branches and subsidiaries fully comply with the group-wide policies and procedures, including procedures for sharing information within the group, in accordance with Article 16, and that the group-wide policies and procedures comply with the requirements set out in this Regulation.

By way of derogation from paragraph 1 of this Article, disclosure may take place between obliged entities that belong to the same group, or between such entities and their branches and subsidiaries established in third countries, provided that those branches and subsidiaries fully comply with the group-wide policies and procedures, including procedures for sharing information within the group, in accordance with Article 16, and that the group-wide policies and procedures comply with the requirements set out in this Regulation.

Abweichend von Absatz 1 dieses Artikels kann eine Offenlegung zwischen Verpflichteten, die derselben Gruppe angehören, oder zwischen solchen Verpflichteten und ihren in Drittländern niedergelassenen Zweigniederlassungen und Tochterunternehmen erfolgen, sofern diese Zweigniederlassungen und Tochterunternehmen die gruppenweiten Strategien und Verfahren einschließlich der Verfahren für den Informationsaustausch innerhalb der Gruppe gemäß Artikel 16 vollständig einhalten und die gruppenweiten Strategien und Verfahren den Anforderungen dieser Verordnung entsprechen.

4 4 4

By way of derogation from paragraph 1 of this Article, disclosure may take place between obliged entities as referred to in Article 3, point (3)(a) and (b), or entities from third countries which impose requirements equivalent to those laid down in this Regulation, who perform their professional activities, whether as employees or not, within the same legal person or a larger structure to which the person belongs and which shares common ownership, management or compliance control, including networks or partnerships.

By way of derogation from paragraph 1 of this Article, disclosure may take place between obliged entities as referred to in Article 3, point (3)(a) and (b), or entities from third countries which impose requirements equivalent to those laid down in this Regulation, who perform their professional activities, whether as employees or not, within the same legal person or a larger structure to which the person belongs and which shares common ownership, management or compliance control, including networks or partnerships.

Abweichend von Absatz 1 dieses Artikels kann eine Offenlegung zwischen den in Artikel 3 Nummer 3 Buchstaben a und b genannten Verpflichteten oder Einrichtungen aus Drittländern, die Anforderungen auferlegen, die den in dieser Verordnung festgelegten Anforderungen gleichwertig sind, erfolgen, wenn diese ihre berufliche Tätigkeit, unabhängig davon, ob sie Beschäftigte sind oder nicht, innerhalb derselben juristischen Person oder einer größeren Struktur ausüben, der die Person angehört und die sich durch gemeinsames Eigentum, eine gemeinsame Leitung oder gemeinsame Compliance-Kontrolle auszeichnet, einschließlich Netzwerken oder Partnerschaften.

5 5 5

For obliged entities referred to in Article 3, points (1), (2), (3)(a) and (b), in cases relating to the same transaction involving two or more obliged entities, and by way of derogation from paragraph 1 of this Article, disclosure may take place between the relevant obliged entities provided that they are located in the Union, or with entities in a third country which imposes requirements equivalent to those laid down in this Regulation, and that they are subject to professional secrecy and personal data protection requirements.

For obliged entities referred to in Article 3, points (1), (2), (3)(a) and (b), in cases relating to the same transaction involving two or more obliged entities, and by way of derogation from paragraph 1 of this Article, disclosure may take place between the relevant obliged entities provided that they are located in the Union, or with entities in a third country which imposes requirements equivalent to those laid down in this Regulation, and that they are subject to professional secrecy and personal data protection requirements.

Für die in Artikel 3 Nummern 1, 2 und 3 Buchstaben a und b genannten Verpflichteten kann in Fällen, die dieselbe Transaktion betreffen, an der zwei oder mehr Verpflichtete beteiligt sind, abweichend von Absatz 1 dieses Artikels eine Offenlegung zwischen den betreffenden Verpflichteten erfolgen, sofern sie in der Union ansässig sind oder mit Einrichtungen in einem Drittland, das Anforderungen auferlegt, die den in dieser Verordnung festgelegten Anforderungen gleichwertig sind, und sofern sie den Anforderungen an das Berufsgeheimnis und den Schutz personenbezogener Daten unterliegen.

6 6 6

Where the obliged entities referred to in Article 3, point (3)(a) and (b), seek to dissuade a client from engaging in illegal activity, that shall not constitute disclosure within the meaning of paragraph 1 of this Article.

Where the obliged entities referred to in Article 3, point (3)(a) and (b), seek to dissuade a client from engaging in illegal activity, that shall not constitute disclosure within the meaning of paragraph 1 of this Article.

Wenn die in Artikel 3 Nummer 3 Buchstaben a und b genannten Verpflichteten versuchen, einen Mandanten von der Ausübung einer rechtswidrigen Tätigkeit abzubringen, gilt dies nicht als Offenlegung im Sinne des Absatzes 1 dieses Artikels.

Article 74 — Threshold-based reports of transactions in certain high-value goods Article 74 — Threshold-based reports of transactions in certain high-value goods Article 74 — Schwellenwertbezogene Meldungen von Transaktionen mit bestimmten hochwertigen Gütern
1 1 1

Persons trading in high-value goods shall report to the FIU all transactions involving the sale of the following high-value goods when those goods are acquired for non-commercial purposes:

  • (a) motor vehicles for a price of at least EUR 250000 or the equivalent in national currency;
  • (b) watercraft for a price of at least EUR 7500000 or the equivalent in national currency;
  • (c) aircraft for a price of at least EUR 7500000 or the equivalent in national currency.

Persons trading in high-value goods shall report to the FIU all transactions involving the sale of the following high-value goods when those goods are acquired for non-commercial purposes:

  • (a) motor vehicles for a price of at least EUR 250000 or the equivalent in national currency;
  • (b) watercraft for a price of at least EUR 7500000 or the equivalent in national currency;
  • (c) aircraft for a price of at least EUR 7500000 or the equivalent in national currency.

Personen, die mit hochwertigen Gütern handeln, melden der FIU alle Transaktionen über den Verkauf der folgenden hochwertigen Güter, wenn diese Güter zu nichtgewerblichen Zwecken erworben werden:

  • (a) Kraftfahrzeuge zu einem Preis von mindestens 250000 EUR oder dem Gegenwert in Landeswährung;
  • (b) Wasserfahrzeuge zu einem Preis von mindestens 7500000 EUR oder dem Gegenwert in Landeswährung;
  • (c) Luftfahrzeuge zu einem Preis von mindestens 7500000 EUR oder dem Gegenwert in Landeswährung.
2 2 2

Credit institutions and financial institutions that provide services in relation to the purchase or transfer of ownership of the goods referred to in paragraph 1 shall also report to the FIU all transactions they carry out for their customers in relation to those goods.

Credit institutions and financial institutions that provide services in relation to the purchase or transfer of ownership of the goods referred to in paragraph 1 shall also report to the FIU all transactions they carry out for their customers in relation to those goods.

Kreditinstitute und Finanzinstitute, die Dienstleistungen im Zusammenhang mit dem Kauf oder der Übertragung des Eigentums an den in Absatz 1 genannten Gütern erbringen, melden der FIU ebenfalls alle Transaktionen, die sie für ihre Kunden im Zusammenhang mit diesen Gütern durchführen.

3 3 3

Reporting pursuant to paragraphs 1 and 2 shall be carried out within the deadlines imposed by the FIU.

Reporting pursuant to paragraphs 1 and 2 shall be carried out within the deadlines imposed by the FIU.

Die Meldung gemäß den Absätzen 1 und 2 erfolgt innerhalb der von der FIU festgelegten Fristen.

CHAPTER VI — INFORMATION SHARING CHAPTER VI — INFORMATION SHARING CHAPTER VI — AUSTAUSCH VON INFORMATIONEN
Article 75 — Exchange of information in the framework of partnerships for information sharing Article 75 — Exchange of information in the framework of partnerships for information sharing Article 75 — Austausch von Informationen im Rahmen von Partnerschaften für den Informationsaustausch
1 1 1

Members of partnerships for information sharing may share information among each other where strictly necessary for the purposes of complying with the obligations under Chapter III and Article 69 and in accordance with fundamental rights and judicial procedural safeguards.

Members of partnerships for information sharing may share information among each other where strictly necessary for the purposes of complying with the obligations under Chapter III and Article 69 and in accordance with fundamental rights and judicial procedural safeguards.

Mitglieder von Partnerschaften für den Informationsaustausch dürfen untereinander Informationen austauschen, soweit dies zur Erfüllung der Pflichten nach Kapitel III und Artikel 69 unbedingt erforderlich ist und im Einklang mit den Grundrechten und den justiziellen Verfahrensgarantien erfolgt.

2 2 2

Obliged entities intending to participate in a partnership for information sharing shall notify their respective supervisory authorities which shall, where relevant in consultation with each other and with the authorities in charge of verifying compliance with Regulation (EU) 2016/679, verify that the partnership for information sharing has mechanisms in place to ensure compliance with this Article and that the data protection impact assessment referred to in paragraph 4, point (h), has been carried out. The verification shall take place prior to the beginning of the activities of the partnership for information sharing. Where relevant, the supervisory authorities shall also consult the FIUs.Responsibility for compliance with requirements under Union or national law shall remain with the participants in the partnership for information sharing.

Obliged entities intending to participate in a partnership for information sharing shall notify their respective supervisory authorities which shall, where relevant in consultation with each other and with the authorities in charge of verifying compliance with Regulation (EU) 2016/679, verify that the partnership for information sharing has mechanisms in place to ensure compliance with this Article and that the data protection impact assessment referred to in paragraph 4, point (h), has been carried out. The verification shall take place prior to the beginning of the activities of the partnership for information sharing. Where relevant, the supervisory authorities shall also consult the FIUs.Responsibility for compliance with requirements under Union or national law shall remain with the participants in the partnership for information sharing.

Verpflichtete Unternehmen, die beabsichtigen, an einer Partnerschaft für den Informationsaustausch teilzunehmen, teilen dies ihren jeweiligen Aufsichtsbehörden mit. Diese überprüfen, gegebenenfalls im gegenseitigen Einvernehmen und im Benehmen mit den für die Überprüfung der Einhaltung der Verordnung (EU) 2016/679 zuständigen Behörden, ob die Partnerschaft über Mechanismen verfügt, die die Einhaltung dieses Artikels gewährleisten, und ob die in Absatz 4 Buchstabe h genannte Datenschutz-Folgenabschätzung durchgeführt wurde. Die Überprüfung erfolgt vor Beginn der Tätigkeiten der Partnerschaft. Gegebenenfalls konsultieren die Aufsichtsbehörden auch die FIUs. Die Verantwortung für die Einhaltung der Anforderungen des Unionsrechts oder des nationalen Rechts verbleibt bei den Teilnehmern der Partnerschaft für den Informationsaustausch.

3 3 3

Information exchanged in the framework of a partnership for information sharing shall be limited to:

  • (a) information on the customer, including any information obtained in the course of identifying and verifying the identity of the customer and, where relevant, the beneficial owner of the customer;
  • (b) information on the purpose and intended nature of the business relationship or occasional transaction between the customer and the obliged entity, as well as, where applicable, the source of wealth and source of funds of the customer;
  • (c) information on customer transactions;
  • (d) information on higher and lower risk factors associated with the customer;
  • (e) the obliged entity’s analysis of the risks associated with the customer pursuant to Article 20(2);
  • (f) information held by the obliged entity pursuant to Article 77(1);
  • (g) information on suspicions pursuant to Article 69.

The information referred to in the first subparagraph shall only be exchanged to the extent that it is necessary for the purposes of carrying out the activities of the partnership for information sharing.

Information exchanged in the framework of a partnership for information sharing shall be limited to:

  • (a) information on the customer, including any information obtained in the course of identifying and verifying the identity of the customer and, where relevant, the beneficial owner of the customer;
  • (b) information on the purpose and intended nature of the business relationship or occasional transaction between the customer and the obliged entity, as well as, where applicable, the source of wealth and source of funds of the customer;
  • (c) information on customer transactions;
  • (d) information on higher and lower risk factors associated with the customer;
  • (e) the obliged entity’s analysis of the risks associated with the customer pursuant to Article 20(2);
  • (f) information held by the obliged entity pursuant to Article 77(1);
  • (g) information on suspicions pursuant to Article 69.

The information referred to in the first subparagraph shall only be exchanged to the extent that it is necessary for the purposes of carrying out the activities of the partnership for information sharing.

Die im Rahmen einer Partnerschaft für den Informationsaustausch ausgetauschten Informationen beschränken sich auf:

  • a) Informationen über den Kunden, einschließlich aller Informationen, die bei der Identifizierung und Überprüfung der Identität des Kunden und gegebenenfalls des wirtschaftlichen Eigentümers des Kunden erlangt wurden;
  • b) Informationen über Zweck und beabsichtigte Art der Geschäftsbeziehung oder gelegentlichen Transaktion zwischen dem Kunden und dem verpflichteten Unternehmen sowie gegebenenfalls über die Herkunft des Vermögens und der Mittel des Kunden;
  • c) Informationen über Transaktionen des Kunden;
  • d) Informationen über höhere und geringere Risikofaktoren im Zusammenhang mit dem Kunden;
  • e) die Analyse der mit dem Kunden verbundenen Risiken durch das verpflichtete Unternehmen gemäß Artikel 20 Absatz 2;
  • f) Informationen, die das verpflichtete Unternehmen gemäß Artikel 77 Absatz 1 besitzt;
  • g) Informationen über Verdachtsmomente gemäß Artikel 69.

Die im ersten Unterabsatz genannten Informationen werden nur insoweit ausgetauscht, als dies für die Durchführung der Tätigkeiten der Partnerschaft für den Informationsaustausch erforderlich ist.

4 4 4

The following conditions shall apply to the sharing of information within the context of a partnership for information sharing:

  • (a) obliged entities shall record all instances of information sharing within the partnership;
  • (b) obliged entities shall not rely solely on the information received in the context of the partnership to comply with the requirements of this Regulation;
  • (c) obliged entities shall not draw conclusions or take decisions that have an impact on the business relationship with the customer or on the performance of occasional transactions for the customer on the basis of information received from other participants in the partnership for information sharing without having assessed that information; any information received in the context of the partnership that is used in an assessment resulting in a decision to refuse or terminate a business relationship or to carry out an occasional transaction shall be included in the records kept pursuant to Article 21(3), and that record shall contain reference to the fact that the information originated from a partnership for information sharing;
  • (d) obliged entities shall carry out their own assessment of transactions involving customers in order to assess which ones may be related to money laundering or terrorist financing or involve proceeds of criminal activity;
  • (e) obliged entities shall implement appropriate technical and organisational measures, including measures to allows pseudonymisation, to ensure a level of security and confidentiality proportionate to the nature and extent of the information exchanged;
  • (f) the sharing of information shall be carried out only in relation to customers:

    • (i) whose behaviour or transaction activities are associated with a higher risk of money laundering, its predicate offences or terrorist financing, as identified pursuant to the risk assessment at Union level and the national risk assessment carried out in accordance with Articles 7 and 8 of Directive (EU) 2024/1640;
    • (ii) who fall under any of the situations referred to in Articles 29, 30, 31 and 36 to 46 of this Regulation; or
    • (iii) for whom the obliged entities need to collect additional information in order to determine whether they are associated with a higher level of risk of money laundering, its predicate offences or terrorist financing;
  • (g) information generated through the use of artificial intelligence, machine learning technologies or algorithms may only be shared where those processes were subject to adequate human oversight;

  • (h) a data protection impact assessment referred to in Article 35 of Regulation (EU) 2016/679 shall be carried out prior to the processing of any personal data;

  • (i) the competent authorities that are members of a partnership for information sharing shall only obtain, provide and exchange information to the extent that this is necessary for the performance of their tasks under relevant Union or national law;

  • (j) where competent authorities referred to in Article 2(1), point (44)(c), of this Regulation participate in a partnership for information sharing, they shall only obtain, provide or exchange personal data and operational information in accordance with national law transposing Directive (EU) 2016/680 of the European Parliament and of the Council

Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89).

and with the applicable provisions of national criminal procedural law, including prior judicial authorisation or any other national procedural safeguard as required;
- (k) the exchange of information on suspicious transactions pursuant to paragraph 3, point (g), of this Article shall only take place where the FIU to which the suspicious transaction report was submitted pursuant to Articles 69 or 70 has agreed with such disclosure.

The following conditions shall apply to the sharing of information within the context of a partnership for information sharing:

  • (a) obliged entities shall record all instances of information sharing within the partnership;
  • (b) obliged entities shall not rely solely on the information received in the context of the partnership to comply with the requirements of this Regulation;
  • (c) obliged entities shall not draw conclusions or take decisions that have an impact on the business relationship with the customer or on the performance of occasional transactions for the customer on the basis of information received from other participants in the partnership for information sharing without having assessed that information; any information received in the context of the partnership that is used in an assessment resulting in a decision to refuse or terminate a business relationship or to carry out an occasional transaction shall be included in the records kept pursuant to Article 21(3), and that record shall contain reference to the fact that the information originated from a partnership for information sharing;
  • (d) obliged entities shall carry out their own assessment of transactions involving customers in order to assess which ones may be related to money laundering or terrorist financing or involve proceeds of criminal activity;
  • (e) obliged entities shall implement appropriate technical and organisational measures, including measures to allow pseudonymisation, to ensure a level of security and confidentiality proportionate to the nature and extent of the information exchanged;
  • (f) the sharing of information shall be carried out only in relation to customers:
    • (i) whose behaviour or transaction activities are associated with a higher risk of money laundering, its predicate offences or terrorist financing;
    • (ii) who fall under any of the situations referred to in Articles 29, 30, 31 and 36 to 46 of this Regulation; or
    • (iii) for whom the obliged entities need to collect additional information in order to determine whether they are associated with a higher level of risk of money laundering, its predicate offences or terrorist financing;
  • (g) information generated through the use of artificial intelligence, machine learning technologies or algorithms may only be shared where those processes were subject to adequate human oversight;
  • (h) a data protection impact assessment referred to in Article 35 of Regulation (EU) 2016/679 shall be carried out prior to the processing of any personal data;
  • (i) competent authorities that are members of a partnership shall only obtain, provide and exchange information to the extent necessary for the performance of their tasks;
  • (j) competent authorities participating in a partnership shall only obtain, provide or exchange personal data and operational information in accordance with applicable national law and procedural safeguards;
  • (k) the exchange of information on suspicious transactions pursuant to paragraph 3, point (g), shall only take place where the FIU to which the report was submitted has agreed to such disclosure.

Für den Austausch von Informationen im Rahmen einer Partnerschaft für den Informationsaustausch gelten folgende Bedingungen:

  • a) Verpflichtete Unternehmen zeichnen sämtliche Fälle des Informationsaustauschs innerhalb der Partnerschaft auf;
  • b) Verpflichtete Unternehmen dürfen sich zur Erfüllung der Anforderungen dieser Verordnung nicht ausschließlich auf die im Rahmen der Partnerschaft erhaltenen Informationen stützen;
  • c) Verpflichtete Unternehmen dürfen auf der Grundlage von Informationen anderer Teilnehmer keine Schlussfolgerungen ziehen oder Entscheidungen treffen, die sich auf die Geschäftsbeziehung mit dem Kunden oder die Durchführung gelegentlicher Transaktionen für den Kunden auswirken, ohne diese Informationen bewertet zu haben; Informationen, die im Rahmen der Partnerschaft erhalten und bei einer Bewertung verwendet wurden, die zur Ablehnung oder Beendigung einer Geschäftsbeziehung oder zur Durchführung einer gelegentlichen Transaktion führt, sind in die gemäß Artikel 21 Absatz 3 geführten Aufzeichnungen aufzunehmen; diese Aufzeichnung enthält einen Hinweis darauf, dass die Informationen aus einer Partnerschaft für den Informationsaustausch stammen;
  • d) Verpflichtete Unternehmen nehmen eine eigene Bewertung der Transaktionen von Kunden vor, um festzustellen, welche möglicherweise mit Geldwäsche oder Terrorismusfinanzierung zusammenhängen oder Erträge aus kriminellen Tätigkeiten umfassen;
  • e) Verpflichtete Unternehmen treffen geeignete technische und organisatorische Maßnahmen, einschließlich Maßnahmen zur Pseudonymisierung, um ein dem Wesen und Umfang der ausgetauschten Informationen angemessenes Maß an Sicherheit und Vertraulichkeit zu gewährleisten;
  • f) der Informationsaustausch erfolgt nur in Bezug auf Kunden:
    • i) deren Verhalten oder Transaktionen mit einem höheren Risiko der Geldwäsche, ihrer Vortaten oder der Terrorismusfinanzierung verbunden sind;
    • ii) auf die eine der in den Artikeln 29, 30, 31 und 36 bis 46 dieser Verordnung genannten Situationen zutrifft; oder
    • iii) bei denen die verpflichteten Unternehmen zusätzliche Informationen erheben müssen, um festzustellen, ob sie mit einem höheren Risiko der Geldwäsche, ihrer Vortaten oder der Terrorismusfinanzierung verbunden sind;
  • g) durch künstliche Intelligenz, Technologien des maschinellen Lernens oder Algorithmen erzeugte Informationen dürfen nur ausgetauscht werden, wenn diese Prozesse einer angemessenen menschlichen Aufsicht unterlagen;
  • h) Vor der Verarbeitung personenbezogener Daten ist eine Datenschutz-Folgenabschätzung gemäß Artikel 35 der Verordnung (EU) 2016/679 durchzuführen;
  • i) zuständige Behörden, die Mitglieder einer Partnerschaft sind, dürfen Informationen nur in dem Umfang erhalten, bereitstellen und austauschen, der zur Erfüllung ihrer Aufgaben erforderlich ist;
  • j) zuständige Behörden, die an einer Partnerschaft teilnehmen, dürfen personenbezogene Daten und operative Informationen nur im Einklang mit dem geltenden nationalen Recht und den Verfahrensgarantien erhalten, bereitstellen oder austauschen;
  • k) der Austausch von Informationen über verdächtige Transaktionen gemäß Absatz 3 Buchstabe g erfolgt nur, wenn die FIU, bei der die Meldung eingereicht wurde, dieser Offenlegung zugestimmt hat.
5 5 5

Information received in the context of a partnership for information sharing shall not be further transmitted, except where:

  • (a) the information is provided to another obliged entity pursuant to Article 49(1);
  • (b) the information is to be included in a report submitted to the FIU or provided in response to a FIU request pursuant to Article 69(1);
  • (c) the information is provided to AMLA pursuant to Article 93 of Regulation (EU) 2024/1620;
  • (d) the information is requested by law enforcement or judicial authorities, subject to any prior authorisations or other procedural guarantees as required under the national law.

Information received in the context of a partnership for information sharing shall not be further transmitted, except where:

  • (a) the information is provided to another obliged entity pursuant to Article 49(1);
  • (b) the information is included in a report submitted to the FIU or provided in response to a FIU request pursuant to Article 69(1);
  • (c) the information is provided to AMLA pursuant to Article 93 of Regulation (EU) 2024/1620; or
  • (d) the information is requested by law enforcement or judicial authorities, subject to any prior authorisations or other procedural guarantees required under national law.

Im Rahmen einer Partnerschaft für den Informationsaustausch erhaltene Informationen dürfen nicht weiter übermittelt werden, außer wenn:

  • a) die Informationen gemäß Artikel 49 Absatz 1 einem anderen verpflichteten Unternehmen bereitgestellt werden;
  • b) die Informationen in eine an die FIU übermittelte Meldung aufgenommen oder gemäß Artikel 69 Absatz 1 als Antwort auf ein Ersuchen der FIU bereitgestellt werden;
  • c) die Informationen gemäß Artikel 93 der Verordnung (EU) 2024/1620 der AMLA bereitgestellt werden; oder
  • d) die Informationen von Strafverfolgungs- oder Justizbehörden angefordert werden, vorbehaltlich der nach nationalem Recht erforderlichen vorherigen Genehmigungen oder sonstigen Verfahrensgarantien.
6 6 6

Obliged entities that participate in partnerships for information sharing shall define policies and procedures for the sharing of information in their internal policies and procedures established pursuant to Article 9. Such policies and procedures shall:

  • (a) specify the assessment to be carried out to determine the extent of information to be shared, and where relevant for the nature of the information or the applicable judicial safeguards, provide for differentiated or limited access to information for members of the partnership;
  • (b) describe the roles and responsibilities of the parties to the partnership for information-sharing;
  • (c) identify the risk assessments that the obliged entity will take into account to determine situations of higher risk in which information can be shared.

The internal policies and procedures referred to in the first subparagraph shall be drawn up prior to the participation in a partnership for information sharing.

Obliged entities that participate in partnerships for information sharing shall define policies and procedures for the sharing of information in their internal policies and procedures established pursuant to Article 9. Such policies and procedures shall:

  • (a) specify the assessment to be carried out to determine the extent of information to be shared and, where relevant, provide for differentiated or limited access;
  • (b) describe the roles and responsibilities of the parties to the partnership;
  • (c) identify the risk assessments that the obliged entity will take into account to determine situations of higher risk in which information can be shared.

The internal policies and procedures referred to in the first subparagraph shall be drawn up prior to participation in a partnership for information sharing.

Verpflichtete Unternehmen, die an Partnerschaften für den Informationsaustausch teilnehmen, legen in ihren gemäß Artikel 9 erstellten internen Regelungen und Verfahren Leitlinien und Verfahren für den Informationsaustausch fest. Diese Leitlinien und Verfahren müssen:

  • a) die durchzuführende Bewertung zur Bestimmung des Umfangs der auszutauschenden Informationen festlegen und gegebenenfalls einen abgestuften oder beschränkten Zugang vorsehen;
  • b) die Rollen und Verantwortlichkeiten der Parteien der Partnerschaft beschreiben;
  • c) die Risikobewertungen bestimmen, die das verpflichtete Unternehmen berücksichtigt, um Situationen mit höherem Risiko festzustellen, in denen Informationen ausgetauscht werden können.

Die im ersten Unterabsatz genannten internen Leitlinien und Verfahren werden vor der Teilnahme an einer Partnerschaft für den Informationsaustausch erstellt.

7 7 7

Where supervisory authorities deem it necessary, obliged entities participating in a partnership for information sharing shall commission an independent audit of the functioning of that partnership and shall share the results with the supervisory authorities.

Where supervisory authorities deem it necessary, obliged entities participating in a partnership for information sharing shall commission an independent audit of the functioning of that partnership and shall share the results with the supervisory authorities.

Halten die Aufsichtsbehörden dies für erforderlich, beauftragen verpflichtete Unternehmen, die an einer Partnerschaft für den Informationsaustausch teilnehmen, eine unabhängige Prüfung der Funktionsweise dieser Partnerschaft und teilen die Ergebnisse den Aufsichtsbehörden mit.

CHAPTER VII — DATA PROTECTION AND RECORD RETENTION CHAPTER VII — DATA PROTECTION AND RECORD RETENTION CHAPTER VII — DATENSCHUTZ UND AUFBEWAHRUNG VON AUFZEICHNUNGEN
Article 76 — Processing of personal data Article 76 — Processing of personal data Article 76 — Verarbeitung personenbezogener Daten
1 1 1

To the extent that it is strictly necessary for the purposes of preventing money laundering and terrorist financing, obliged entities may process special categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679 and personal data relating to criminal convictions and offences referred to in Article 10 of that Regulation subject to the safeguards provided for in paragraphs 2 and 3 of this Article.

To the extent that it is strictly necessary for the purposes of preventing money laundering and terrorist financing, obliged entities may process special categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679 and personal data relating to criminal convictions and offences referred to in Article 10 of that Regulation subject to the safeguards provided for in paragraphs 2 and 3 of this Article.

Soweit dies zur Verhinderung von Geldwäsche und Terrorismusfinanzierung unbedingt erforderlich ist, dürfen verpflichtete Unternehmen vorbehaltlich der in den Absätzen 2 und 3 dieses Artikels vorgesehenen Schutzvorkehrungen besondere Kategorien personenbezogener Daten gemäß Artikel 9 Absatz 1 der Verordnung (EU) 2016/679 sowie personenbezogene Daten über strafrechtliche Verurteilungen und Straftaten gemäß Artikel 10 jener Verordnung verarbeiten.

2 2 2

Obliged entities shall be able to process personal data covered by Article 9 of Regulation (EU) 2016/679 provided that:

  • (a) they inform their customers or prospective customers that such categories of data may be processed for the purpose of complying with the requirements of this Regulation;
  • (b) the data originate from reliable sources, are accurate and up-to-date;
  • (c) they do not take decisions that would lead to biased and discriminatory outcomes on the basis of those data;
  • (d) they adopt measures of a high level of security in accordance with Article 32 of Regulation (EU) 2016/679, in particular in terms of confidentiality.

Obliged entities shall be able to process personal data covered by Article 9 of Regulation (EU) 2016/679 provided that:

  • (a) they inform their customers or prospective customers that such categories of data may be processed for the purpose of complying with this Regulation;
  • (b) the data originate from reliable sources and are accurate and up-to-date;
  • (c) they do not take decisions that would lead to biased and discriminatory outcomes on the basis of those data;
  • (d) they adopt measures of a high level of security in accordance with Article 32 of Regulation (EU) 2016/679, in particular in terms of confidentiality.

Verpflichtete Unternehmen dürfen personenbezogene Daten gemäß Artikel 9 der Verordnung (EU) 2016/679 verarbeiten, sofern:

  • a) sie ihre Kunden oder potenziellen Kunden darüber informieren, dass solche Datenkategorien zur Einhaltung dieser Verordnung verarbeitet werden können;
  • b) die Daten aus zuverlässigen Quellen stammen sowie richtig und aktuell sind;
  • c) sie auf der Grundlage dieser Daten keine Entscheidungen treffen, die zu voreingenommenen oder diskriminierenden Ergebnissen führen würden;
  • d) sie gemäß Artikel 32 der Verordnung (EU) 2016/679 ein hohes Sicherheitsniveau gewährleisten, insbesondere hinsichtlich der Vertraulichkeit.
3 3 3

Obliged entities shall be able to process personal data covered by Article 10 of Regulation (EU) 2016/679 provided that they comply with the conditions laid down in paragraph 2 of this Article and that:

  • (a) such personal data relate to money laundering, its predicate offences or terrorist financing;
  • (b) the obliged entities have procedures in place that allow the distinction, in the processing of such data, between allegations, investigations, proceedings and convictions, taking into account the fundamental right to a fair trial, the right of defence and the presumption of innocence.

Obliged entities shall be able to process personal data covered by Article 10 of Regulation (EU) 2016/679 provided that they comply with the conditions laid down in paragraph 2 of this Article and that:

  • (a) such personal data relate to money laundering, its predicate offences or terrorist financing;
  • (b) the obliged entities have procedures in place that allow the distinction, in the processing of such data, between allegations, investigations, proceedings and convictions, taking into account the fundamental right to a fair trial, the right of defence and the presumption of innocence.

Verpflichtete Unternehmen dürfen personenbezogene Daten gemäß Artikel 10 der Verordnung (EU) 2016/679 verarbeiten, sofern sie die Bedingungen des Absatzes 2 dieses Artikels einhalten und:

  • a) sich diese personenbezogenen Daten auf Geldwäsche, deren Vortaten oder Terrorismusfinanzierung beziehen;
  • b) die verpflichteten Unternehmen über Verfahren verfügen, die bei der Verarbeitung dieser Daten eine Unterscheidung zwischen Anschuldigungen, Ermittlungen, Verfahren und Verurteilungen ermöglichen, wobei das Grundrecht auf ein faires Verfahren, das Verteidigungsrecht und die Unschuldsvermutung berücksichtigt werden.
4 4 4

Personal data shall be processed by obliged entities on the basis of this Regulation only for the purposes of the prevention of money laundering and terrorist financing and shall not be further processed in a way that is incompatible with those purposes. The processing of personal data on the basis of this Regulation for commercial purposes shall be prohibited.

Personal data shall be processed by obliged entities on the basis of this Regulation only for the purposes of the prevention of money laundering and terrorist financing and shall not be further processed in a way that is incompatible with those purposes. The processing of personal data on the basis of this Regulation for commercial purposes shall be prohibited.

Personenbezogene Daten dürfen von verpflichteten Unternehmen auf der Grundlage dieser Verordnung ausschließlich zur Verhinderung von Geldwäsche und Terrorismusfinanzierung verarbeitet und nicht in einer mit diesen Zwecken unvereinbaren Weise weiterverarbeitet werden. Die Verarbeitung personenbezogener Daten auf der Grundlage dieser Verordnung zu kommerziellen Zwecken ist verboten.

5 5 5

Obliged entities may adopt decisions resulting from automated processes, including profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679, or from processes involving AI systems as defined in Article 3, point (1), of Regulation (EU) 2024/xxx of the European Parliament and of the Council

Regulation (EU) 2024/xxx of the European Parliament and of the Council of xxx laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Not yet published in the Official Journal).

, provided that:

  • (a) the data processed by such systems is limited to data obtained pursuant to Chapter III of this Regulation;
  • (b) any decision to enter or refuse to enter into or maintain a business relationship with a customer or to carry out or refuse to carry out an occasional transaction for a customer, or to increase or decrease the extent of the customer due diligence measures applied pursuant to Article 20 of this Regulation, is subject to meaningful human intervention to ensure the accuracy and appropriateness of such a decision; and
  • (c) the customer may obtain an explanation of the decision reached by the obliged entity, and may challenge that decision, except in relation to a report as referred to in Article 69 of this Regulation.

Obliged entities may adopt decisions resulting from automated processes, including profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679, or from processes involving AI systems as defined in Article 3, point (1), of Regulation (EU) 2024/xxx of the European Parliament and of the Council, provided that:

  • (a) the data processed by such systems is limited to data obtained pursuant to Chapter III of this Regulation;
  • (b) any decision to enter into, refuse to enter into or maintain a business relationship with a customer, to carry out or refuse to carry out an occasional transaction, or to increase or decrease the extent of customer due diligence measures, is subject to meaningful human intervention to ensure its accuracy and appropriateness; and
  • (c) the customer may obtain an explanation of the decision and challenge it, except in relation to a report referred to in Article 69.

Verpflichtete Unternehmen dürfen Entscheidungen treffen, die sich aus automatisierten Verfahren, einschließlich Profiling im Sinne des Artikels 4 Nummer 4 der Verordnung (EU) 2016/679, oder aus Verfahren unter Einbeziehung von KI-Systemen im Sinne des Artikels 3 Nummer 1 der Verordnung (EU) 2024/xxx des Europäischen Parlaments und des Rates ergeben, sofern:

  • a) die von diesen Systemen verarbeiteten Daten auf Daten beschränkt sind, die gemäß Kapitel III dieser Verordnung erlangt wurden;
  • b) jede Entscheidung über die Aufnahme, Ablehnung oder Aufrechterhaltung einer Geschäftsbeziehung mit einem Kunden, die Durchführung oder Ablehnung einer gelegentlichen Transaktion oder die Ausweitung oder Einschränkung der nach Artikel 20 angewandten Sorgfaltspflichten einer sinnvollen menschlichen Einflussnahme unterliegt, um ihre Richtigkeit und Angemessenheit sicherzustellen; und
  • c) der Kunde eine Erklärung der getroffenen Entscheidung erhalten und diese anfechten kann, außer im Zusammenhang mit einer Meldung nach Artikel 69.
Article 77 — Record retention Article 77 — Record retention Article 77 — Aufbewahrung von Aufzeichnungen
1 1 1

Obliged entities shall retain the following documents and information:

  • (a) a copy of the documents and information obtained in the performance of customer due diligence pursuant to Chapter III, including information obtained through electronic identification means;
  • (b) a record of the assessment undertaken pursuant to Article 69(2), including the information and circumstances considered and the results of such assessment, whether or not such assessment results in a suspicious transaction report being made to the FIU, and a copy of the suspicion transaction report, if any;
  • (c) the supporting evidence and records of transactions, consisting of the original documents or copies admissible in judicial proceedings under the applicable national law, which are necessary to identify transactions;
  • (d) when they participate in partnerships for information sharing pursuant to Chapter VI, copies of the documents and information obtained in the framework of those partnerships, and records of all instances of information sharing.

Obliged entities shall ensure that documents, information and records kept pursuant to this Article are not redacted.

Obliged entities shall retain the following documents and information:

  • (a) a copy of the documents and information obtained in the performance of customer due diligence pursuant to Chapter III, including information obtained through electronic identification means;
  • (b) a record of the assessment undertaken pursuant to Article 69(2), including the information and circumstances considered and the results of such assessment, whether or not it results in a suspicious transaction report being made to the FIU, and a copy of the suspicious transaction report, if any;
  • (c) the supporting evidence and records of transactions necessary to identify transactions;
  • (d) when participating in partnerships for information sharing pursuant to Chapter VI, copies of documents and information obtained in the framework of those partnerships, and records of all instances of information sharing.

Obliged entities shall ensure that documents, information and records kept pursuant to this Article are not redacted.

Verpflichtete Unternehmen bewahren folgende Dokumente und Informationen auf:

  • a) eine Kopie der bei der Erfüllung der Sorgfaltspflichten gegenüber Kunden gemäß Kapitel III erlangten Dokumente und Informationen, einschließlich der mittels elektronischer Identifizierung erlangten Informationen;
  • b) eine Aufzeichnung der gemäß Artikel 69 Absatz 2 vorgenommenen Bewertung, einschließlich der berücksichtigten Informationen und Umstände sowie der Ergebnisse dieser Bewertung, unabhängig davon, ob eine Meldung über eine verdächtige Transaktion an die FIU erfolgt, und gegebenenfalls eine Kopie dieser Meldung;
  • c) die Belege und Aufzeichnungen über Transaktionen, die für deren Identifizierung erforderlich sind;
  • d) bei Teilnahme an Partnerschaften für den Informationsaustausch gemäß Kapitel VI Kopien der im Rahmen dieser Partnerschaften erlangten Dokumente und Informationen sowie Aufzeichnungen über sämtliche Fälle des Informationsaustauschs.

Verpflichtete Unternehmen stellen sicher, dass die nach diesem Artikel aufbewahrten Dokumente, Informationen und Aufzeichnungen nicht geschwärzt werden.

2 2 2

By way of derogation from paragraph 1, obliged entities may decide to replace the retention of copies of the information by a retention of the references to such information, provided that the nature and method of retention of such information ensure that the obliged entities can provide immediately to competent authorities the information and that the information cannot be modified or altered.Obliged entities making use of the derogation referred to in the first subparagraph shall define in their internal procedures drawn up pursuant to Article 9, the categories of information for which they will retain a reference instead of a copy or original, as well as the procedures for retrieving the information so that it can be provided to competent authorities upon request.

By way of derogation from paragraph 1, obliged entities may decide to replace the retention of copies of the information by retention of references to such information, provided that the nature and method of retention ensure that the information can be provided immediately to competent authorities and cannot be modified or altered. Obliged entities using this derogation shall define in their internal procedures pursuant to Article 9 the categories of information for which they retain a reference instead of a copy or original, and the procedures for retrieving the information.

Abweichend von Absatz 1 dürfen verpflichtete Unternehmen beschließen, die Aufbewahrung von Kopien der Informationen durch die Aufbewahrung von Verweisen auf diese Informationen zu ersetzen, sofern Art und Methode der Aufbewahrung gewährleisten, dass die Informationen den zuständigen Behörden unverzüglich bereitgestellt werden können und nicht geändert oder verfälscht werden können. Verpflichtete Unternehmen, die von dieser Abweichung Gebrauch machen, legen in ihren internen Verfahren gemäß Artikel 9 die Informationskategorien fest, für die sie anstelle einer Kopie oder eines Originals einen Verweis aufbewahren, sowie die Verfahren zum Abruf der Informationen.

3 3 3

The information referred to in paragraphs 1 and 2 shall be retained for a period of 5 years commencing on the date of the termination of the business relationship or on the date of the carrying out of the occasional transaction, or on the date of refusal to enter into a business relationship or carry out an occasional transaction. Without prejudice to retention periods for data collected for the purposes of other Union legal acts or national law complying with Regulation (EU) 2016/679, obliged entities shall delete personal data upon expiry of the five-year period.Competent authorities may require further retention of the information referred to in the first subparagraph on a case-by-case basis, provided that such retention is necessary for the prevention, detection, investigation or prosecution of money laundering or terrorist financing. That further retention period shall not exceed 5 years.

The information referred to in paragraphs 1 and 2 shall be retained for a period of 5 years commencing on the date of termination of the business relationship or the date of carrying out the occasional transaction, or the date of refusal to enter into a business relationship or carry out an occasional transaction. Obliged entities shall delete personal data upon expiry of the five-year period. Competent authorities may require further retention on a case-by-case basis where necessary for the prevention, detection, investigation or prosecution of money laundering or terrorist financing. That further retention period shall not exceed 5 years.

Die in den Absätzen 1 und 2 genannten Informationen werden ab dem Tag der Beendigung der Geschäftsbeziehung, dem Tag der Durchführung der gelegentlichen Transaktion oder dem Tag der Ablehnung der Aufnahme einer Geschäftsbeziehung oder der Durchführung einer gelegentlichen Transaktion fünf Jahre lang aufbewahrt. Nach Ablauf dieses Zeitraums löschen verpflichtete Unternehmen die personenbezogenen Daten. Zuständige Behörden können im Einzelfall eine längere Aufbewahrung verlangen, wenn dies zur Verhinderung, Aufdeckung, Untersuchung oder Verfolgung von Geldwäsche oder Terrorismusfinanzierung erforderlich ist. Dieser weitere Aufbewahrungszeitraum darf fünf Jahre nicht überschreiten.

4 4 4

Where, on 10 July 2027, legal proceedings concerned with the prevention, detection, investigation or prosecution of suspected money laundering or terrorist financing are pending in a Member State, and an obliged entity holds information or documents relating to those pending proceedings, the obliged entity may retain that information or those documents for a period of 5 years from 10 July 2027.Member States may, without prejudice to national criminal law on evidence applicable to ongoing criminal investigations and legal proceedings, allow or require the retention of such information or documents for a further period of 5 years where the necessity and proportionality of such further retention have been established for the prevention, detection, investigation or prosecution of suspected money laundering or terrorist financing.

Where, on 10 July 2027, legal proceedings concerned with the prevention, detection, investigation or prosecution of suspected money laundering or terrorist financing are pending in a Member State, and an obliged entity holds information or documents relating to those proceedings, it may retain them for 5 years from 10 July 2027. Member States may allow or require retention for a further period of 5 years where necessary and proportionate.

Sind am 10. Juli 2027 in einem Mitgliedstaat Gerichtsverfahren zur Verhinderung, Aufdeckung, Untersuchung oder Verfolgung mutmaßlicher Geldwäsche oder Terrorismusfinanzierung anhängig und besitzt ein verpflichtetes Unternehmen Informationen oder Dokumente, die diese Verfahren betreffen, darf es diese ab dem 10. Juli 2027 fünf Jahre lang aufbewahren. Die Mitgliedstaaten können eine weitere Aufbewahrung von fünf Jahren gestatten oder vorschreiben, wenn deren Notwendigkeit und Verhältnismäßigkeit festgestellt wurden.

Article 78 — Provision of records to competent authorities Article 78 — Provision of records to competent authorities Article 78 — Bereitstellung von Aufzeichnungen für die zuständigen Behörden

Obliged entities shall have systems in place that enable them to respond fully and speedily to enquiries from their FIU or from other competent authorities, in accordance with national law, as to whether they are maintaining or have maintained, during a five-year period prior to that enquiry a business relationship with specified persons, and on the nature of that relationship, through secure channels and in a manner that ensures full confidentiality of the enquiries.

Obliged entities shall have systems in place that enable them to respond fully and speedily to enquiries from their FIU or other competent authorities, in accordance with national law, as to whether they are maintaining or have maintained, during a five-year period prior to that enquiry, a business relationship with specified persons, and on the nature of that relationship, through secure channels and in a manner that ensures full confidentiality of the enquiries.

Verpflichtete Unternehmen verfügen über Systeme, die es ihnen ermöglichen, Anfragen ihrer FIU oder anderer zuständiger Behörden nach Maßgabe des nationalen Rechts vollständig und zügig zu beantworten, ob sie in dem der Anfrage vorausgehenden Zeitraum von fünf Jahren Geschäftsbeziehungen zu bestimmten Personen unterhalten oder unterhalten haben und welcher Art diese Beziehung ist. Die Übermittlung erfolgt über sichere Kanäle und in einer Weise, die die vollständige Vertraulichkeit der Anfragen gewährleistet.

CHAPTER VIII — MEASURES TO MITIGATE RISKS DERIVING FROM ANONYMOUS INSTRUMENTS CHAPTER VIII — MEASURES TO MITIGATE RISKS DERIVING FROM ANONYMOUS INSTRUMENTS CHAPTER VIII — MAẞNAHMEN ZUR MINDERUNG DER VON ANONYMEN INSTRUMENTEN AUSGEHENDEN RISIKEN
Article 79 — Anonymous accounts and bearer shares and bearer share warrants Article 79 — Anonymous accounts and bearer shares and bearer share warrants Article 79 — Anonyme Konten sowie Inhaberaktien und Inhaberschuldverschreibungen
1 1 1

Credit institutions, financial institutions and crypto-asset service providers shall be prohibited from keeping anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes or anonymous crypto-asset accounts as well as any account otherwise allowing for the anonymisation of the customer account holder or the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins.Owners and beneficiaries of existing anonymous bank or payment accounts, anonymous passbooks, anonymous safe-deposit boxes held by credit institutions or financial institutions, or crypto-asset accounts shall be subject to customer due diligence measures before those accounts, passbooks, or deposit boxes are used in any way.

Credit institutions, financial institutions and crypto-asset service providers shall be prohibited from keeping anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes or anonymous crypto-asset accounts, or accounts otherwise allowing anonymisation of the customer account holder or transactions, including through anonymity-enhancing coins. Owners and beneficiaries of existing anonymous accounts, passbooks or safe-deposit boxes, or crypto-asset accounts, shall be subject to customer due diligence before those accounts or facilities are used.

Kreditinstitute, Finanzinstitute und Anbieter von Kryptowerte-Dienstleistungen dürfen keine anonymen Bank- und Zahlungskonten, anonymen Sparbücher, anonymen Schließfächer oder anonymen Kryptowertekonten sowie keine Konten führen, die anderweitig eine Anonymisierung des Kontoinhabers oder von Transaktionen ermöglichen, einschließlich durch anonymitätssteigernde Kryptowährungen. Eigentümer und Begünstigte bestehender anonymer Konten, Sparbücher oder Schließfächer sowie von Kryptowertekonten unterliegen vor jeder Nutzung dieser Konten oder Einrichtungen den Sorgfaltspflichten gegenüber Kunden.

2 2 2

Credit institutions and financial institutions acting as acquirers within the meaning of Article 2, point (1), of Regulation (EU) 2015/751 of the European Parliament and of the Council

Regulation (EU) 2015/751 of the European Parliament and of the Council of 29 April 2015 on interchange fees for card-based payment transactions (OJ L 123, 19.5.2015, p. 1).

shall not accept payments carried out with anonymous prepaid cards issued in third countries, unless otherwise provided for in the regulatory technical standards adopted by the Commission in accordance with Article 28 of this Regulation on the basis of a proven low risk.

Credit institutions and financial institutions acting as acquirers within the meaning of Article 2, point (1), of Regulation (EU) 2015/751 shall not accept payments carried out with anonymous prepaid cards issued in third countries, unless otherwise provided for in regulatory technical standards adopted by the Commission on the basis of a proven low risk.

Kreditinstitute und Finanzinstitute, die als Akquisiteure im Sinne des Artikels 2 Nummer 1 der Verordnung (EU) 2015/751 handeln, dürfen keine Zahlungen mit in Drittländern ausgegebenen anonymen vorausbezahlten Karten annehmen, sofern in den von der Kommission auf der Grundlage eines nachgewiesen geringen Risikos erlassenen technischen Regulierungsstandards nichts anderes bestimmt ist.

3 3 3

Companies shall be prohibited from issuing bearer shares, and shall convert all existing bearer shares into registered shares, shall immobilise them within the meaning of Article 2(1), point (3), of Regulation (EU) No 909/2014, or deposit them with a financial institution by 10 July 2029. However, companies with securities listed on a regulated market or whose shares are issued as intermediated securities either through immobilisation within the meaning of Article 2(1), point (3), of that Regulation or through a direct issuance in dematerialised form within the meaning of Article 2(1), point (4), of that Regulation shall be permitted to issue new and maintain existing bearer shares. For existing bearer shares that are not converted, immobilised or deposited by 10 July 2029, all voting rights and rights to distribution attached to those shares shall be automatically suspended until their conversion, immobilisation or deposit. All such shares not converted, immobilised or deposited by 10 July 2030 shall be cancelled, leading to a share capital decrease of the corresponding amount.Companies shall be prohibited from issuing bearer share warrants that are not in intermediated form.

Companies shall be prohibited from issuing bearer shares and shall convert all existing bearer shares into registered shares, immobilise them or deposit them with a financial institution by 10 July 2029. Companies with securities listed on a regulated market or whose shares are issued as intermediated securities may issue new and maintain existing bearer shares. Existing bearer shares not converted, immobilised or deposited by 10 July 2029 shall have all voting and distribution rights suspended until conversion, immobilisation or deposit. Shares not so converted, immobilised or deposited by 10 July 2030 shall be cancelled, resulting in a corresponding reduction of share capital. Companies shall be prohibited from issuing bearer share warrants that are not in intermediated form.

Unternehmen dürfen keine Inhaberaktien ausgeben und müssen alle bestehenden Inhaberaktien bis zum 10. Juli 2029 in Namensaktien umwandeln, immobilisieren oder bei einem Finanzinstitut hinterlegen. Unternehmen mit an einem geregelten Markt notierten Wertpapieren oder mit Aktien, die als zentral verwahrte Wertpapiere ausgegeben werden, dürfen neue Inhaberaktien ausgeben und bestehende Inhaberaktien behalten. Bei bestehenden Inhaberaktien, die bis zum 10. Juli 2029 nicht umgewandelt, immobilisiert oder hinterlegt wurden, werden sämtliche Stimmrechte und Rechte auf Ausschüttungen bis zur Umwandlung, Immobilisierung oder Hinterlegung automatisch ausgesetzt. Alle bis zum 10. Juli 2030 nicht umgewandelten, immobilisierten oder hinterlegten Aktien werden eingezogen, wodurch sich das Aktienkapital entsprechend verringert. Unternehmen dürfen keine Inhaberschuldverschreibungen ausgeben, die nicht in zentral verwahrter Form vorliegen.

Article 80 — Limits to large cash payments in exchange for goods or services Article 80 — Limits to large cash payments in exchange for goods or services Article 80 — Beschränkungen hoher Barzahlungen im Austausch für Waren oder Dienstleistungen
1 1 1

Persons trading in goods or providing services may accept or make a payment in cash only up to an amount of EUR 10000 or the equivalent in national or foreign currency, whether the transaction is carried out in a single operation or in several operations which appear to be linked.

Persons trading in goods or providing services may accept or make a payment in cash only up to an amount of EUR 10000 or the equivalent in national or foreign currency, whether the transaction is carried out in a single operation or in several operations which appear to be linked.

Personen, die mit Waren handeln oder Dienstleistungen erbringen, dürfen Barzahlungen nur bis zu einem Betrag von 10 000 EUR oder dem Gegenwert in nationaler oder ausländischer Währung annehmen oder leisten, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder in mehreren offenbar miteinander verbundenen Vorgängen durchgeführt wird.

2 2 2

Member States may adopt lower limits following consultation of the European Central Bank in accordance with Article 2(1) of Council Decision 98/415/EC

Council Decision 98/415/EC of 29 June 1998 on the consultation of the European Central Bank by national authorities regarding draft legislative provisions (OJ L 189, 3.7.1998, p. 42).

. Those lower limits shall be notified to the Commission within 3 months of the measure being introduced at national level.

Member States may adopt lower limits following consultation of the European Central Bank. Those lower limits shall be notified to the Commission within 3 months of the measure being introduced at national level.

Die Mitgliedstaaten können nach Konsultation der Europäischen Zentralbank niedrigere Grenzen festlegen. Diese niedrigeren Grenzen sind der Kommission innerhalb von drei Monaten nach Einführung der Maßnahme auf nationaler Ebene mitzuteilen.

3 3 3

When limits already exist at national level which are below the limit set out in paragraph 1, they shall continue to apply. Member States shall notify those limits to the Commission by 10 October 2024.

When limits already exist at national level which are below the limit set out in paragraph 1, they shall continue to apply. Member States shall notify those limits to the Commission by 10 October 2024.

Bestehen auf nationaler Ebene bereits Grenzen, die unter der in Absatz 1 festgelegten Grenze liegen, gelten diese weiterhin. Die Mitgliedstaaten teilen der Kommission diese Grenzen bis zum 10. Oktober 2024 mit.

4 4 4

The limit referred to in paragraph 1 shall not apply to:

  • (a) payments between natural persons who are not acting in a professional capacity;
  • (b) payments or deposits made at the premises of credit institutions, electronic money issuers as defined in Article 2, point (3), of Directive 2009/110/EC and payment service providers as defined in Article 4, point (11), of Directive (EU) 2015/2366.

Payments or deposits referred to in the first subparagraph, point (b) above the limit shall be reported to the FIU within the deadlines imposed by the FIU.

The limit referred to in paragraph 1 shall not apply to:

  • (a) payments between natural persons who are not acting in a professional capacity;
  • (b) payments or deposits made at the premises of credit institutions, electronic money issuers and payment service providers.

Payments or deposits referred to in point (b) above the limit shall be reported to the FIU within the deadlines imposed by the FIU.

Die in Absatz 1 genannte Grenze gilt nicht für:

  • a) Zahlungen zwischen natürlichen Personen, die nicht beruflich handeln;
  • b) Zahlungen oder Einlagen in den Räumlichkeiten von Kreditinstituten, E-Geld-Emittenten und Zahlungsdienstleistern.

Zahlungen oder Einlagen nach Buchstabe b, die die Grenze überschreiten, sind der FIU innerhalb der von der FIU festgelegten Fristen zu melden.

5 5 5

Member States shall ensure that appropriate measures, including the imposition of penalties, are taken against natural or legal persons acting in their professional capacity which are suspected of a breach of the limit set out in paragraph 1, or of a lower limit adopted by the Member States.

Member States shall ensure that appropriate measures, including the imposition of penalties, are taken against natural or legal persons acting in their professional capacity which are suspected of a breach of the limit set out in paragraph 1 or of a lower limit adopted by the Member States.

Die Mitgliedstaaten stellen sicher, dass gegen natürliche oder juristische Personen, die beruflich handeln und bei denen der Verdacht eines Verstoßes gegen die in Absatz 1 festgelegte Grenze oder eine von den Mitgliedstaaten festgelegte niedrigere Grenze besteht, geeignete Maßnahmen, einschließlich Sanktionen, ergriffen werden.

6 6 6

The overall level of the penalties shall be calculated, in accordance with the relevant provisions of national law, in such way as to produce results proportionate to the seriousness of the infringement, thereby effectively discouraging further offences of the same kind.

The overall level of the penalties shall be calculated, in accordance with the relevant provisions of national law, in such way as to produce results proportionate to the seriousness of the infringement, thereby effectively discouraging further offences of the same kind.

Die Gesamthöhe der Sanktionen wird nach den einschlägigen Bestimmungen des nationalen Rechts so berechnet, dass sie der Schwere des Verstoßes angemessen ist und dadurch weitere Verstöße gleicher Art wirksam verhindert werden.

7 7 7

Where, by reason of force majeure, means of payment by funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 other than banknotes and coins become unavailable at national level, Member States may temporarily suspend the application of paragraph 1 or, where applicable, of paragraph 2 of this Article and shall inform the Commission thereof without delay. Member States shall also inform the Commission of the expected duration of the unavailability of means of payment by funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 other than banknotes and coins and of the measures taken by Member States to reinstate their availability.Where, on the basis of the information communicated by the Member State, the Commission considers that the suspension of the application of paragraph 1 or, where applicable, of paragraph 2 is not justified by a case of force majeure, it shall adopt a decision addressed to that Member State requesting the immediate lifting of such suspension.

Where, by reason of force majeure, means of payment by funds other than banknotes and coins become unavailable at national level, Member States may temporarily suspend the application of paragraph 1 or, where applicable, paragraph 2 and shall inform the Commission without delay. They shall also inform the Commission of the expected duration of the unavailability and the measures taken to reinstate availability. Where the Commission considers that the suspension is not justified by force majeure, it shall adopt a decision addressed to that Member State requesting its immediate lifting.

Werden auf nationaler Ebene aufgrund höherer Gewalt andere Zahlungsmittel als Banknoten und Münzen nicht verfügbar, können die Mitgliedstaaten die Anwendung des Absatzes 1 oder gegebenenfalls des Absatzes 2 vorübergehend aussetzen und unterrichten die Kommission unverzüglich. Sie informieren die Kommission ferner über die voraussichtliche Dauer der Nichtverfügbarkeit und die zur Wiederherstellung der Verfügbarkeit getroffenen Maßnahmen. Ist die Kommission der Auffassung, dass die Aussetzung nicht durch höhere Gewalt gerechtfertigt ist, erlässt sie einen an den betreffenden Mitgliedstaat gerichteten Beschluss, in dem sie die sofortige Aufhebung der Aussetzung verlangt.

CHAPTER IX — FINAL PROVISIONS CHAPTER IX — FINAL PROVISIONS CHAPTER IX — SCHLUSSBESTIMMUNGEN
SECTION 1 — Cooperation between FIUs and the EPPO SECTION 1 — Cooperation between FIUs and the EPPO SECTION 1 — Zusammenarbeit zwischen den FIUs und der EPPO
Article 81 — Cooperation between FIUs and the EPPO Article 81 — Cooperation between FIUs and the EPPO Article 81 — Zusammenarbeit zwischen den FIUs und der EPPO
1 1 1

Pursuant to Article 24 of Regulation (EU) 2017/1939, each FIU shall without undue delay report to the EPPO the results of its analyses and any additional relevant information where there are reasonable grounds to suspect that money laundering and other criminal activity are being or have been committed in respect of which the EPPO could exercise its competence in accordance with Article 22 and Article 25(2) and (3) of that Regulation.By 10 July 2026, AMLA shall, in consultation with the EPPO, develop draft implementing technical standards and submit them to the Commission for adoption. Those draft implementing technical standards shall specify the format to be used by FIUs for reporting information to the EPPO.Power is conferred on the Commission to adopt the implementing technical standards referred to in the second subparagraph of this paragraph in accordance with Article 53 of Regulation (EU) 2024/1620.

Pursuant to Article 24 of Regulation (EU) 2017/1939, each FIU shall without undue delay report to the EPPO the results of its analyses and any additional relevant information where there are reasonable grounds to suspect that money laundering and other criminal activity are being or have been committed in respect of which the EPPO could exercise its competence. By 10 July 2026, AMLA shall, in consultation with the EPPO, develop draft implementing technical standards and submit them to the Commission for adoption. Those standards shall specify the format to be used by FIUs for reporting information to the EPPO. The Commission is empowered to adopt those standards in accordance with Article 53 of Regulation (EU) 2024/1620.

Gemäß Artikel 24 der Verordnung (EU) 2017/1939 meldet jede FIU der EPPO unverzüglich die Ergebnisse ihrer Analysen und alle zusätzlichen relevanten Informationen, wenn hinreichende Gründe für den Verdacht bestehen, dass Geldwäsche oder sonstige kriminelle Tätigkeiten begangen werden oder wurden, für die die EPPO ihre Zuständigkeit ausüben könnte. Bis zum 10. Juli 2026 entwickelt die AMLA im Benehmen mit der EPPO Entwürfe für technische Durchführungsstandards und legt sie der Kommission zur Annahme vor. Diese Entwürfe legen das von den FIUs für die Meldung von Informationen an die EPPO zu verwendende Format fest. Der Kommission wird die Befugnis übertragen, diese Standards gemäß Artikel 53 der Verordnung (EU) 2024/1620 zu erlassen.

2 2 2

FIUs shall respond in a timely manner to requests for information by the EPPO in relation to money laundering and other criminal activity as referred to in paragraph 1.

FIUs shall respond in a timely manner to requests for information by the EPPO in relation to money laundering and other criminal activity as referred to in paragraph 1.

Die FIUs beantworten Informationsersuchen der EPPO im Zusammenhang mit der in Absatz 1 genannten Geldwäsche und sonstigen kriminellen Tätigkeiten fristgerecht.

3 3 3

FIUs and the EPPO may exchange the results of strategic analyses, including typologies and risk indicators, where such analyses relate to money laundering and other criminal activity as referred to in paragraph 1.

FIUs and the EPPO may exchange the results of strategic analyses, including typologies and risk indicators, where such analyses relate to money laundering and other criminal activity as referred to in paragraph 1.

Die FIUs und die EPPO können die Ergebnisse strategischer Analysen, einschließlich Typologien und Risikoindikatoren, austauschen, wenn sich diese Analysen auf die in Absatz 1 genannte Geldwäsche und sonstige kriminelle Tätigkeiten beziehen.

Article 82 — Requests for information to the EPPO Article 82 — Requests for information to the EPPO Article 82 — Informationsersuchen an die EPPO
1 1 1

The EPPO shall respond without undue delay to reasoned requests for information by an FIU where that information is necessary for the performance of the FIU’s functions under Chapter III of Directive (EU) 2024/1640.

The EPPO shall respond without undue delay to reasoned requests for information by an FIU where that information is necessary for the performance of the FIU’s functions under Chapter III of Directive (EU) 2024/1640.

Die EPPO beantwortet begründete Informationsersuchen einer FIU unverzüglich, wenn die Informationen für die Wahrnehmung der Aufgaben der FIU nach Kapitel III der Richtlinie (EU) 2024/1640 erforderlich sind.

2 2 2

The EPPO may postpone or refuse the provision of the information referred to in paragraph 1 where providing it would be likely to prejudice the proper conduct and confidentiality of an ongoing investigation. The EPPO shall communicate in a timely manner the postponement of or refusal to provide the requested information, including the reasons therefor, to the requesting FIU.

The EPPO may postpone or refuse the provision of the information referred to in paragraph 1 where providing it would be likely to prejudice the proper conduct and confidentiality of an ongoing investigation. The EPPO shall communicate the postponement or refusal, including the reasons therefor, to the requesting FIU in a timely manner.

Die EPPO kann die Bereitstellung der in Absatz 1 genannten Informationen aufschieben oder verweigern, wenn deren Bereitstellung den ordnungsgemäßen Ablauf oder die Vertraulichkeit einer laufenden Untersuchung beeinträchtigen könnte. Die EPPO teilt der ersuchenden FIU den Aufschub oder die Verweigerung einschließlich der Gründe hierfür fristgerecht mit.

SECTION 2 — Cooperation between FIUs and OLAF SECTION 2 — Cooperation between FIUs and OLAF SECTION 2 — Zusammenarbeit zwischen den FIUs und OLAF
Article 83 — Cooperation between FIUs and OLAF Article 83 — Cooperation between FIUs and OLAF Article 83 — Zusammenarbeit zwischen den FIUs und OLAF
1 1 1

Pursuant to Article 8(3) of Regulation (EU, Euratom) No 883/2013 of the European Parliament and of the Council

Regulation (EU, Euratom) No 883/2013 of the European Parliament and of the Council of 11 September 2013 concerning investigations conducted by the European Anti-Fraud Office (OLAF) and repealing Regulation (EC) No 1073/1999 of the European Parliament and of the Council and Council Regulation (Euratom) No 1074/1999 (OJ L 248, 18.9.2013, p. 1).

, each FIU shall transmit without delay the results of its analyses and any additional relevant information to OLAF where there are reasonable grounds to suspect that fraud, corruption or any other illegal activity affecting the Union’s financial interests are being or have been committed in respect of which OLAF could exercise its competence in accordance with Article 8 of that Regulation.

Pursuant to Article 8(3) of Regulation (EU, Euratom) No 883/2013, each FIU shall transmit without delay the results of its analyses and any additional relevant information to OLAF where there are reasonable grounds to suspect that fraud, corruption or any other illegal activity affecting the Union’s financial interests are being or have been committed in respect of which OLAF could exercise its competence.

Gemäß Artikel 8 Absatz 3 der Verordnung (EU, Euratom) Nr. 883/2013 übermittelt jede FIU OLAF unverzüglich die Ergebnisse ihrer Analysen und alle zusätzlichen relevanten Informationen, wenn hinreichende Gründe für den Verdacht bestehen, dass Betrug, Korruption oder eine sonstige rechtswidrige Tätigkeit zum Nachteil der finanziellen Interessen der Union begangen werden oder wurden, für die OLAF seine Zuständigkeit ausüben könnte.

2 2 2

FIUs shall respond in a timely manner to requests for information by OLAF in relation to fraud, corruption or any other illegal activity as referred to in paragraph 1.

FIUs shall respond in a timely manner to requests for information by OLAF in relation to fraud, corruption or any other illegal activity as referred to in paragraph 1.

Die FIUs beantworten Informationsersuchen von OLAF im Zusammenhang mit dem in Absatz 1 genannten Betrug, der dort genannten Korruption oder sonstigen rechtswidrigen Tätigkeit fristgerecht.

3 3 3

FIUs and OLAF may exchange the results of strategic analyses, including typologies and risk indicators, where such analyses relate to fraud, corruption or any other illegal activity as referred to in paragraph 1.

FIUs and OLAF may exchange the results of strategic analyses, including typologies and risk indicators, where such analyses relate to fraud, corruption or any other illegal activity as referred to in paragraph 1.

Die FIUs und OLAF können die Ergebnisse strategischer Analysen, einschließlich Typologien und Risikoindikatoren, austauschen, wenn sich diese Analysen auf den in Absatz 1 genannten Betrug, die dort genannte Korruption oder sonstige rechtswidrige Tätigkeit beziehen.

Article 84 — Requests for information to OLAF Article 84 — Requests for information to OLAF Article 84 — Informationsersuchen an OLAF
1 1 1

OLAF shall respond in a timely manner to reasoned requests for information by an FIU where that information is necessary for the performance of the FIU’s functions under Chapter III of Directive (EU) 2024/1640.

OLAF shall respond in a timely manner to reasoned requests for information by an FIU where that information is necessary for the performance of the FIU’s functions under Chapter III of Directive (EU) 2024/1640.

OLAF beantwortet begründete Informationsersuchen einer FIU fristgerecht, wenn die Informationen für die Wahrnehmung der Aufgaben der FIU nach Kapitel III der Richtlinie (EU) 2024/1640 erforderlich sind.

2 2 2

OLAF may postpone or refuse the provision of the information referred to in paragraph 1 where providing it would be likely to have a negative impact on an ongoing investigation. OLAF shall communicate such postponement or refusal to the requesting FIU in a timely manner, including the reasons therefor.

OLAF may postpone or refuse the provision of the information referred to in paragraph 1 where providing it would be likely to have a negative impact on an ongoing investigation. OLAF shall communicate such postponement or refusal to the requesting FIU in a timely manner, including the reasons therefor.

OLAF kann die Bereitstellung der in Absatz 1 genannten Informationen aufschieben oder verweigern, wenn deren Bereitstellung wahrscheinlich negative Auswirkungen auf eine laufende Untersuchung hätte. OLAF teilt der ersuchenden FIU einen solchen Aufschub oder eine solche Verweigerung einschließlich der Gründe hierfür fristgerecht mit.

SECTION 3 — Other provisions SECTION 3 — Other provisions SECTION 3 — Sonstige Bestimmungen
Article 85 — Exercise of the delegation Article 85 — Exercise of the delegation Article 85 — Ausübung der Befugnisübertragung
1 1 1

The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.

The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.

Die Befugnis zum Erlass delegierter Rechtsakte wird der Kommission unter den Bedingungen dieses Artikels übertragen.

2 2 2

The power to adopt delegated acts referred to in Articles 29, 30, 31, 34, 43, 52 and 68 shall be conferred on the Commission for an indeterminate period of time from 9 July 2024.

The power to adopt delegated acts referred to in Articles 29, 30, 31, 34, 43, 52 and 68 shall be conferred on the Commission for an indeterminate period of time from 9 July 2024.

Die Befugnis zum Erlass delegierter Rechtsakte gemäß den Artikeln 29, 30, 31, 34, 43, 52 und 68 wird der Kommission ab dem 9. Juli 2024 für einen Zeitraum von fünf Jahren übertragen.

3 3 3

The delegation of power referred to in Articles 29, 30, 31, 34, 43, 52 and 68 may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.

The delegation of power referred to in Articles 29, 30, 31, 34, 43, 52 and 68 may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following publication in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of delegated acts already in force.

Die in den Artikeln 29, 30, 31, 34, 43, 52 und 68 genannte Befugnisübertragung kann vom Europäischen Parlament oder vom Rat jederzeit widerrufen werden. Der Widerruf beendet die in dem Beschluss genannte Befugnisübertragung. Er wird am Tag nach der Veröffentlichung des Beschlusses im Amtsblatt der Europäischen Union oder zu einem darin angegebenen späteren Zeitpunkt wirksam. Die Gültigkeit bereits in Kraft befindlicher delegierter Rechtsakte bleibt unberührt.

4 4 4

Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.

Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.

Vor dem Erlass eines delegierten Rechtsakts konsultiert die Kommission die von jedem Mitgliedstaat benannten Sachverständigen im Einklang mit den Grundsätzen der Interinstitutionellen Vereinbarung vom 13. April 2016 über bessere Rechtsetzung.

5 5 5

As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.

As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.

Sobald die Kommission einen delegierten Rechtsakt erlässt, teilt sie ihn gleichzeitig dem Europäischen Parlament und dem Rat mit.

6 6 6

A delegated act adopted pursuant to Article 29, 30, 31 or 34 shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of 1 month of notification of that act to the European Parliament and to the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by 1 month at the initiative of the European Parliament or of the Council.

A delegated act adopted pursuant to Article 29, 30, 31 or 34 shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of 1 month of notification of that act, or if both have informed the Commission before expiry of that period that they will not object. That period shall be extended by 1 month at the initiative of either institution.

Ein gemäß Artikel 29, 30, 31 oder 34 erlassener delegierter Rechtsakt tritt nur in Kraft, wenn weder das Europäische Parlament noch der Rat innerhalb eines Monats nach der Mitteilung dieses Rechtsakts Einwände erhoben hat oder beide der Kommission vor Ablauf dieses Zeitraums mitgeteilt haben, dass sie keine Einwände erheben werden. Dieser Zeitraum wird auf Initiative des Europäischen Parlaments oder des Rates um einen Monat verlängert.

7 7 7

A delegated act adopted pursuant to Article 43, 52 or 68 shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of 3 months of notification of that act to the European Parliament and to the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by 3 months at the initiative of the European Parliament or of the Council.

A delegated act adopted pursuant to Article 43, 52 or 68 shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of 3 months of notification of that act, or if both have informed the Commission before expiry of that period that they will not object. That period shall be extended by 3 months at the initiative of either institution.

Ein gemäß Artikel 43, 52 oder 68 erlassener delegierter Rechtsakt tritt nur in Kraft, wenn weder das Europäische Parlament noch der Rat innerhalb von drei Monaten nach der Mitteilung dieses Rechtsakts Einwände erhoben hat oder beide der Kommission vor Ablauf dieses Zeitraums mitgeteilt haben, dass sie keine Einwände erheben werden. Dieser Zeitraum wird auf Initiative des Europäischen Parlaments oder des Rates um drei Monate verlängert.

Article 86 — Committee procedure Article 86 — Committee procedure Article 86 — Ausschussverfahren
1 1 1

The Commission shall be assisted by the Committee on the Prevention of Money Laundering and Terrorist Financing established by Article 34 of Regulation (EU) 2023/1113. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.

The Commission shall be assisted by the Committee on the Prevention of Money Laundering and Terrorist Financing established by Article 34 of Regulation (EU) 2023/1113. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.

Die Kommission wird von dem durch Artikel 34 der Verordnung (EU) 2023/1113 eingesetzten Ausschuss zur Verhinderung von Geldwäsche und Terrorismusfinanzierung unterstützt. Dieser Ausschuss ist ein Ausschuss im Sinne der Verordnung (EU) Nr. 182/2011.

2 2 2

Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.

Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.

Wird auf diesen Absatz verwiesen, findet Artikel 5 der Verordnung (EU) Nr. 182/2011 Anwendung.

Article 87 — Review Article 87 — Review Article 87 — Überprüfung

By 10 July 2032, and every 3 years thereafter, the Commission shall review the application of this Regulation and submit a report to the European Parliament and to the Council.

The first review shall include an assessment of:

  • (a) the national systems for reporting of suspicions pursuant to Article 69 and obstacles and opportunities to establish a single reporting system at Union level;
  • (b) the adequacy of the beneficial ownership transparency framework to mitigate risks associated with legal entities and legal arrangements.

By 10 July 2032, and every 3 years thereafter, the Commission shall review the application of this Regulation and submit a report to the European Parliament and to the Council.

The first review shall include an assessment of:

  • (a) the national systems for reporting of suspicions pursuant to Article 69 and obstacles and opportunities to establish a single reporting system at Union level;
  • (b) the adequacy of the beneficial ownership transparency framework to mitigate risks associated with legal entities and legal arrangements.

Bis zum 10. Juli 2032 und danach alle drei Jahre überprüft die Kommission die Anwendung dieser Verordnung und legt dem Europäischen Parlament und dem Rat einen Bericht vor.

Die erste Überprüfung umfasst eine Bewertung:

  • a) der nationalen Systeme für die Meldung von Verdachtsfällen gemäß Artikel 69 sowie der Hindernisse und Möglichkeiten für die Einrichtung eines einheitlichen Meldesystems auf Unionsebene;
  • b) der Angemessenheit des Transparenzrahmens für das wirtschaftliche Eigentum zur Minderung der mit juristischen Personen und Rechtsvereinbarungen verbundenen Risiken.
Article 88 — Reports Article 88 — Reports Article 88 — Berichte

By 10 July 2030, the Commission shall submit reports to the European Parliament and to the Council assessing the necessity and proportionality of:

  • (a) lowering the 25 % threshold for the identification of beneficial ownership of legal entities through ownership interest;
  • (b) extending the scope of high-value goods to include high-value garments and accessories;
  • (c) extending the scope of the threshold-based disclosures under Article 74 to cover the sale of other goods, of introducing harmonised formats for the reporting of those transactions based on the usefulness of those reports for FIUs, and of extending the scope of information collected from persons trading in free-trade zones;
  • (d) adjusting the limit for large cash payments.

By 10 July 2030, the Commission shall submit reports to the European Parliament and to the Council assessing the necessity and proportionality of:

  • (a) lowering the 25 % threshold for the identification of beneficial ownership of legal entities through ownership interest;
  • (b) extending the scope of high-value goods to include high-value garments and accessories;
  • (c) extending the scope of the threshold-based disclosures under Article 74 to cover the sale of other goods, of introducing harmonised formats for the reporting of those transactions based on the usefulness of those reports for FIUs, and of extending the scope of information collected from persons trading in free-trade zones;
  • (d) adjusting the limit for large cash payments.

Bis zum 10. Juli 2030 legt die Kommission dem Europäischen Parlament und dem Rat Berichte vor, in denen die Notwendigkeit und Verhältnismäßigkeit folgender Maßnahmen bewertet werden:

  • a) der Herabsetzung des Schwellenwerts von 25 % für die Feststellung des wirtschaftlichen Eigentums an juristischen Personen aufgrund einer Beteiligung am Eigentum;
  • b) der Ausweitung des Anwendungsbereichs von hochwertigen Gütern auf hochwertige Bekleidung und Accessoires;
  • c) der Ausweitung des Anwendungsbereichs der schwellenwertbezogenen Meldungen gemäß Artikel 74 auf den Verkauf anderer Güter, der Einführung harmonisierter Formate für die Meldung dieser Transaktionen auf der Grundlage des Nutzens dieser Meldungen für die FIUs sowie der Ausweitung des Umfangs der von Personen erhobenen Informationen, die in Freizonen Handel treiben;
  • d) der Anpassung des Höchstbetrags für hohe Barzahlungen.
Article 89 — Relation to Directive (EU) 2015/849 Article 89 — Relation to Directive (EU) 2015/849 Article 89 — Verhältnis zur Richtlinie (EU) 2015/849

References to Directive (EU) 2015/849 shall be construed as references to this Regulation and to Directive (EU) 2024/1640 and read in accordance with the correlation table set out in Annex VI to this Regulation.

References to Directive (EU) 2015/849 shall be construed as references to this Regulation and to Directive (EU) 2024/1640 and read in accordance with the correlation table set out in Annex VI to this Regulation.

Bezugnahmen auf die Richtlinie (EU) 2015/849 gelten als Bezugnahmen auf diese Verordnung und auf die Richtlinie (EU) 2024/1640 und sind im Einklang mit der Entsprechungstabelle in Anhang VI dieser Verordnung zu lesen.

Article 90 — Entry into force and application Article 90 — Entry into force and application Article 90 — Inkrafttreten und Anwendung

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.It shall apply from 10 July 2027, except in relation to obliged entities referred to in Article 3, points (3)(n) and (o), to which it shall apply from 10 July 2029.

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.It shall apply from 10 July 2027, except in relation to obliged entities referred to in Article 3, points (3)(n) and (o), to which it shall apply from 10 July 2029.

Diese Verordnung tritt am zwanzigsten Tag nach ihrer Veröffentlichung im Amtsblatt der Europäischen Union in Kraft.Sie gilt ab dem 10. Juli 2027, mit Ausnahme der in Artikel 3 Nummer 3 Buchstaben n und o genannten Verpflichteten, für die sie ab dem 10. Juli 2029 gilt.

Annexes

No annexes extracted yet.

Full text

European flag Official Journal; of the European Union EN; L series


2024/1624 19.6.2024

REGULATION (EU) 2024/1624 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

of 31 May 2024

on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing

(Text with EEA relevance)

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Having regard to the proposal from the European Commission,

After transmission of the draft legislative act to the national parliaments,

Having regard to the opinion of the European Central Bank (1),

Having regard to the opinion of the European Economic and Social Committee (2),

Acting in accordance with the ordinary legislative procedure (3),

Whereas:

(1) Directive (EU) 2015/849 of the European Parliament and of the Council (4) constitutes the main legal instrument for the prevention of the use of the Union’s financial system for the purposes of money laundering and terrorist financing. That Directive sets out a comprehensive legal framework, which Directive (EU) 2018/843 of the European Parliament and the Council (5) further strengthened by addressing emerging money laundering and terrorist financing risks and increasing transparency of beneficial ownership. Notwithstanding the achievements under that legal framework, experience has shown that further improvements should be introduced to adequately mitigate money laundering and terrorist financing risks and to effectively detect criminal attempts to misuse the Union’s financial system for criminal purposes.

(2) The main challenge identified in respect of the application of the provisions of Directive (EU) 2015/849 that lay down obligations for obliged entities, is the lack of direct applicability of the rules set out in those provisions and a fragmented approach along national lines. Although those rules have existed and evolved over three decades, they are still implemented in a manner not fully consistent with the requirements of an integrated internal market. Therefore, it is necessary that rules on matters currently covered in Directive (EU) 2015/849 which could be directly applicable by the obliged entities concerned are addressed in a Regulation in order to achieve the desired uniformity of application.

(3) This new instrument is part of a comprehensive package that aims to strengthen the Union’s framework for anti-money laundering and countering the financing of terrorism (‘AML/CFT’). Together, this Regulation, Directive (EU) 2024/1640 of the European Parliament and of the Council (6) and Regulations (EU) 2023/1113 (7) and (EU) 2024/1620 (8) of the European Parliament and of the Council will form the legal framework governing the AML/CFT requirements to be met by obliged entities and underpinning the Union’s AML/CFT institutional framework, including the establishment of an Authority for anti-money laundering and countering the financing of terrorism (AMLA).

(4) Money laundering and terrorist financing are frequently carried out in an international context. Measures adopted at Union level, without taking into account international coordination and cooperation, would have very limited effect. The measures adopted by the Union in that field should therefore be compatible with, and at least as stringent as, actions undertaken at international level. Union action should continue to take particular account of the Financial Action Task Force (FATF) Recommendations and instruments of other international bodies active in the fight against money laundering and terrorist financing. With a view to reinforcing the efficacy of the fight against money laundering and terrorist financing, the relevant Union legal acts should, where appropriate, be aligned with the International Standards on Combating Money Laundering and the Financing of Terrorism and Proliferation adopted by the FATF in February 2012 (the ‘revised FATF Recommendations’) and the subsequent amendments to such standards.

(5) Since the adoption of Directive (EU) 2015/849, recent developments in the Union’s criminal law framework have contributed to strengthening the prevention of and fight against money laundering, its predicate offences and terrorist financing. Directive (EU) 2018/1673 of the European Parliament and of the Council (9) has led to a common understanding of the money laundering crime and its predicate offences. Directive (EU) 2017/1371 of the European Parliament and of the Council (10) defined financial crimes affecting the Union’s financial interest, which should also be considered predicate offences to money laundering. Directive (EU) 2017/541 of the European Parliament and of the Council (11) has achieved a common understanding of the crime of terrorist financing. As those concepts are now clarified in Union criminal law, it is no longer necessary for the Union’s AML/CFT rules to define money laundering, its predicate offences or terrorist financing. Instead, the Union’s AML/CFT framework should be fully coherent with the Union’s criminal law framework.

(6) Harmonisation in the relevant area of criminal law enables a strong and coherent approach at Union level to the prevention of and fight against money laundering and its predicate offences, including corruption. At the same time, such an approach ensures that Member States that have adopted a broader approach to the definition of criminal activities which constitute predicate offences for money laundering can continue to apply such an approach. For that reason, in line with Directive (EU) 2018/1673, any kind of punishable involvement in the commission of a predicate offence for money laundering as criminalised in accordance with national law should also be considered as a criminal activity for the purposes of that Directive and of this Regulation.

(7) Technology keeps evolving, offering opportunities to the private sector to develop new products and systems to exchange funds or value. While this is a positive phenomenon, it can generate new money laundering and terrorist financing risks, as criminals continuously manage to find ways to exploit vulnerabilities in order to hide and move illicit funds around the world. Crypto-asset service providers and crowdfunding platforms are exposed to the misuse of new channels for the movement of illicit money and are well placed to detect such movement and mitigate risks. The scope of Union legislation should therefore be expanded to cover such entities, in line with FATF standards in relation to crypto-assets. At the same time, advances in innovation, such as the development of the metaverse, provide new avenues for the perpetration of crimes and for the laundering of their proceeds. It is therefore important to exercise vigilance as regards the risks associated with the provision of innovative products or services, whether at Union or national level or at the level of obliged entities.

(8) The institutions and persons covered by this Regulation play a crucial role as gatekeepers of the Union’s financial system and should therefore take all necessary measures to implement the requirements of this Regulation with a view to preventing criminals from laundering the proceeds of their illegal activities or from financing terrorism. Measures should also be put in place to mitigate any risk of non-implementation or evasion of targeted financial sanctions.

(9) The definition of an insurance intermediary under Directive (EU) 2016/97 of the European Parliament and of the Council (12) covers a broad range of natural or legal persons that take up or pursue the activity of insurance distribution. Some insurance intermediaries take up insurance distribution activities under the full responsibility of insurance undertakings or intermediaries and carry out activities subject to their policies and procedures. Where those intermediaries do not collect premia or amounts intended for the customer, the policy holder or the beneficiary of the insurance policy, they are not in a position to conduct meaningful due diligence or to detect and report suspicious transactions. In view of that limited role and of the fact that full application of AML/CFT requirements is ensured by the insurance undertakings or intermediaries under whose responsibility they provide services, intermediaries that do not handle funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 of the European Parliament and of the Council (13) should not be considered obliged entities for the purposes of this Regulation.

(10) Holding companies that carry out mixed activities and have at least one subsidiary that is an obliged entity should themselves be included as obliged entities in the scope of this Regulation. To ensure consistent supervision by financial supervisors, in cases where the subsidiaries of a mixed activity holding company include at least one credit institution or financial institution, the holding company itself should also qualify as a financial institution.

(11) Financial transactions can also take place within the same group as a way of managing group finances. However, such transactions are not undertaken vis-à-vis customers and do not require the application of AML/CFT measures. In order to ensure legal certainty, it is necessary to recognise that this Regulation does not apply to financial activities or other financial services which are provided by members of a group to other members of that group.

(12) Independent legal professionals should be subject to this Regulation when participating in financial or corporate transactions, including when providing tax advice, because there is risk of the services provided by those legal professionals being misused for the purpose of laundering the proceeds of criminal activity or for the purpose of terrorist financing. There should, however, be exemptions from any obligation to report information obtained before, during or after judicial proceedings, or in the course of ascertaining the legal position of a client, as such information is covered by legal privilege. Therefore, legal advice should remain subject to the obligation of professional secrecy, except where the legal professional is taking part in money laundering or terrorist financing, the legal advice is provided for the purposes of money laundering or terrorist financing, or where the legal professional knows that the client is seeking legal advice for the purposes of money laundering or terrorist financing. Such knowledge and purpose can be inferred from objective factual circumstances. As legal advice might already be sought at the stage of perpetrating the proceeds-generating criminal activity, it is important that cases excluded from legal privilege extend to situations where legal advice is provided in the context of the predicate offences. Legal advice sought in relation to ongoing judicial proceedings should not be deemed to constitute legal advice for the purposes of money laundering or terrorist financing.

(13) In order to ensure respect for the rights guaranteed by the Charter of Fundamental Rights of the European Union (the ‘Charter’), in the case of auditors, external accountants and tax advisors who, in some Member States, are entitled to defend or represent a client in the context of judicial proceedings or to ascertain a client’s legal position, the information they obtain in the performance of those tasks should not be subject to reporting obligations. However, the same exceptions that apply to notaries and lawyers should also apply to those professionals where they act in the exercise of the right of defence or when they ascertain the legal position of a client.

(14) Directive (EU) 2018/843 was the first legal instrument to address the risks of money laundering and terrorist financing posed by crypto-assets in the Union. It extended the scope of the AML/CFT framework to two types of crypto-asset service providers: providers engaged in exchange services between virtual currencies and fiat currencies, and custodian wallet providers. Due to rapid technological developments and the advancement in FATF standards, it is necessary to review that approach. A first step to complete and update the Union legal framework has been achieved with Regulation (EU) 2023/1114 of the European Parliament and of the Council (14), which set requirements for crypto-asset service providers wishing to apply for an authorisation to provide their services in the internal market. It also introduced a definition of crypto-assets and crypto-asset service providers encompassing a broader range of activities. In addition, Regulation (EU) 2023/1113 has extended traceability requirements to transfers of crypto-assets carried out by crypto-asset service providers covered by Regulation (EU) 2023/1114, and amended Directive (EU) 2015/849 to require Member States to make those crypto-asset service providers obliged entities. Those crypto-asset service providers should also be covered by this Regulation, to mitigate any risk of misuse of crypto-assets for money laundering or terrorist financing purposes.

(15) The creation of markets in unique and non-fungible crypto-assets is still recent and has not resulted in legislation regulating their functioning. The evolution of those markets is being monitored and it is important that it does not result in new money laundering and terrorist financing risks that would not be properly mitigated. By 30 December 2024, the Commission is to submit a report to the European Parliament and to the Council on the latest developments with respect to crypto-assets, including an assessment of the development of markets in unique and non-fungible crypto-assets, the appropriate regulatory treatment of such crypto-assets, including an assessment of necessity and feasibility of regulating providers of services related to unique and non-fungible crypto-assets. If appropriate, the Commission is to accompany that report with a legislative proposal.

(16) Crowdfunding platforms’ vulnerabilities to money laundering and terrorist financing risks are horizontal and affect the internal market as a whole. To date, diverging approaches have emerged across Member States as to the management of those risks. While Regulation (EU) 2020/1503 of the European Parliament and of the Council (15) harmonises the regulatory approach for business investment and lending-based crowdfunding platforms across the Union and introduces several safeguards to deal with potential money laundering and terrorist financing risks, such as due diligence of crowdfunding platforms in respect of project owners and within authorisation procedures, the lack of a harmonised legal framework with robust AML/CFT obligations for crowdfunding platforms creates gaps and weakens the Union’s AML/CFT safeguards. It is therefore necessary to ensure that all crowdfunding platforms, including those already licensed under Regulation (EU) 2020/1503, are subject to Union AML/CFT legislation.

(17) Crowdfunding intermediaries, which operate a digital platform in order to match or facilitate the matching of funders with projects owners such as associations or individuals that seek funding, are exposed to money laundering and terrorist financing risks. Undertakings that are not licensed under Regulation (EU) 2020/1503 are currently left either unregulated or are subject to diverging regulatory approaches across Member States, including in relation to rules and procedures to tackle money laundering and terrorist financing risks. Such intermediaries should therefore be subject to the obligations of this Regulation, in particular to avoid the diversion of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 or crypto-assets raised for illicit purposes by criminals. In order to mitigate such risks, those obligations apply to a wide range of projects, including, inter alia, educational or cultural projects and the collection of those funds or crypto-assets to support more general causes, for example in the humanitarian field, or to organise or celebrate a family or social event.

(18) Directive (EU) 2015/849 set out to mitigate the money laundering and terrorist financing risks posed by large cash payments by including persons trading in goods among obliged entities where they make or receive payments in cash above EUR 10 000, whilst allowing Member States to introduce stricter measures. Such an approach has shown to be ineffective in light of the poor understanding and application of AML/CFT requirements, lack of supervision and limited number of suspicious transactions reported to the Financial Intelligence Unit (FIU). In order to adequately mitigate risks deriving from the misuse of large cash sums, a Union-wide limit to large cash payments above EUR 10 000 should be laid down. As a consequence, persons trading in goods no longer need to be subject to AML/CFT obligations, with the exception of persons trading in precious metals, precious stones, other high value goods and cultural goods.

(19) Some categories of persons trading in goods are particularly exposed to money laundering and terrorist financing risks due to the high value of the often small, transportable goods they deal with. For that reason, persons dealing in precious metals and precious stones and other high value goods should be subject to AML/CFT requirements where such trading is either a regular or a principal professional activity.

(20) Motor vehicles, watercraft and aircraft in the higher market segments are vulnerable to risks of misuse for money laundering and terrorist financing given their high value and transportability. Therefore, persons trading in such goods should be subject to AML/CFT requirements. The transportable nature of those goods is particularly attractive for the purposes of money laundering and terrorist financing given the ease with which such goods can be moved across or outside Union borders, and the fact that access to information on such goods where registered in third countries might not be easily accessible to competent authorities. To mitigate risks that Union high-value goods may be misused for criminal purposes and to ensure visibility on the ownership of such goods, it is necessary to require persons trading in high-value goods to report transactions concerning the sale of motor vehicles, watercraft and aircraft. Credit institutions and financial institutions provide services that are essential for the conclusion of the sale or transfer of ownership of such goods, and should also be required to report those transactions to the FIU. While goods intended solely for the pursuit of commercial activities should not be subject to such disclosure, sales for private, non-commercial use should not be limited to instances where the customer is a natural person, but should also relate to sales to legal entities and arrangements, in particular where they are set up to administer the wealth of their beneficial owner.

(21) Investment migration operators are private companies, bodies or persons acting or interacting directly with the national authorities competent for granting rights of residence on behalf of third-country nationals or providing intermediary services to third-country nationals seeking to obtain residence rights in a Member State in exchange for any kind of investment, including capital transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity contributing to the public good and contributions to the state budget. Investor residence schemes present risks and vulnerabilities in relation to money laundering, corruption and tax evasion. Such risks are exacerbated by the cross-border rights associated with residence in a Member State. Therefore, it is necessary that investment migration operators are subject to AML/CFT obligations. This Regulation should not apply to investor citizenship schemes, which result in the acquisition of nationality in exchange for such investment, as such schemes must be considered as undermining the fundamental status of Union citizenship and sincere cooperation among Member States.

(22) While creditors for mortgage and consumer credits are typically credit institutions or financial institutions, there are consumer and mortgage credit intermediaries that do not qualify as credit institutions or financial institutions and have not been subject to AML/CFT requirements at Union level, but have been subject to such obligations in certain Member States due to their exposure to money laundering and terrorist financing risks. Depending on their business model, such consumer and mortgage credit intermediaries can be exposed to significant money laundering and terrorist financing risks. It is important to ensure that entities carrying out similar activities that are exposed to such risks are covered by AML/CFT requirements, regardless of whether they qualify as credit institutions or financial institutions. Therefore, it is appropriate to include consumer and mortgage credit intermediaries that are not credit institutions or financial institutions but that are, as a result of their activities, exposed to money laundering and terrorist financing risks. In many cases, however, the credit intermediary is acting on behalf of the credit institution or financial institution that grants and processes the loan. In those cases, AML/CFT requirements should not apply to consumer and mortgage credit intermediaries, but only to the credit institutions or financial institutions.

(23) To ensure a consistent approach, it is necessary to clarify which entities in the investment sector are subject to AML/CFT requirements. Although collective investment undertakings already fall within the scope of Directive (EU) 2015/849, it is necessary to align the relevant terminology with the current Union investment fund legislation, namely Directives 2009/65/EC (16) and 2011/61/EU (17) of the European Parliament and of the Council. Because funds might be constituted without legal personality, the inclusion of their managers in the scope of this Regulation is also necessary. AML/CFT requirements should apply regardless of the form in which units or shares in a fund are made available for purchase in the Union, including where units or shares are directly or indirectly offered to investors established in the Union or placed with such investors at the initiative of the manager or on behalf of the manager. As both funds and fund managers fall within the scope of AML/CFT requirements, it is appropriate to clarify that a duplication of efforts should be avoided. To that end, the AML/CFT measures taken at the level of the fund and at the level of its manager should not be the same, but should reflect the allocation of tasks between the fund and its manager.

(24) The activities of professional football clubs and football agents are exposed to risks of money laundering and its predicate offences due to several factors inherent to the football sector, such as the global popularity of football, the considerable sums, cash flows and financial interests involved, the prevalence of cross-border transactions, and the sometimes opaque ownership structures. All those factors expose football to possible abuse by criminals to legitimise illicit funds and thus make the sport vulnerable to money laundering and its predicate offences. Key areas of risk include, for example, transactions with investors and sponsors, including advertisers, and the transfer of players. Professional football clubs and football agents should therefore put in place robust anti-money laundering measures, including carrying out customer due diligence on investors, sponsors, including advertisers, and other partners and counterparties with whom they transact. In order to avoid any disproportionate burden on smaller clubs that are less exposed to risks of criminal misuse, Member States should be able to, on the basis of a proven lower risk of money laundering, its predicate crimes and terrorist financing, exempt certain professional football clubs from the requirements of this Regulation, whether in full or in part.

(25) The activities of professional football clubs competing in the highest divisions of their national football leagues make them more exposed to higher risks of money laundering and its predicate offences compared to football clubs participating in lower divisions. For example, top-tier football clubs engage in more substantial financial transactions, such as high-value transfers of players and sponsorship deals, might have more complex corporate structures with multiple layers of ownership, and are more likely to engage in cross-border transactions. Those factors make such top-tier clubs more attractive for criminals and provide more opportunities to conceal illicit funds. Therefore, Member States should only be able to exempt professional football clubs participating in the highest division in cases of proven low risk and provided that such clubs have a turnover for each of the previous 2 years of less than EUR 5 000 000 or the equivalent in national currency. Nonetheless, the risk of money laundering is not determined solely by the division in which a football club competes. Lower-division clubs can also be exposed to significant risks of money laundering and its predicate offences. Member States should therefore only be able to exempt from the requirements of this Regulation football clubs in lower divisions that are associated with a proven low risk of money laundering, its predicate offences or terrorist financing.

(26) This Regulation harmonises the measures to be put in place to prevent money laundering, its predicate offences and terrorist financing at Union level. At the same time, in line with the risk-based approach, Member States should be able to impose additional requirements in limited cases where they are confronted with specific risks. To ensure that such risks are adequately mitigated, obliged entities that have their head office located in another Member State should apply such additional requirements, whether they operate in that other Member State through freedom of establishment or under the freedom to provide services, provided they have an infrastructure in that other Member State. Furthermore, in order to clarify the relationship between those internal market freedoms, it is important to clarify what activities amount to an establishment.

(27) Consistent with the case law of the Court of Justice of the European Union, unless specifically set out in sectorial legislation an establishment does not need to take the form of a subsidiary, branch or agency, but can consist of an office managed by an obliged entity’s own staff or by a person who is independent but authorised to act on a permanent basis for the obliged entity. According to that definition, which requires the actual pursuit of an economic activity at the place of establishment of the provider, a mere letter-box does not constitute an establishment. Equally, offices or other infrastructure used for supporting activities, such as mere back-office operations, IT-hubs or data centres operated by obliged entities, do not constitute an establishment. Conversely, activities such as the provision of crypto-asset services through ATMs constitute an establishment having regard to the limited physical equipment needed for operators that mainly service their customers through the internet, as is the case for crypto-asset service providers.

(28) It is important that AML/CFT requirements apply in a proportionate manner and that the imposition of any requirement is proportionate to the role that obliged entities are able to play in the prevention of money laundering and terrorist financing. To that end, it should be possible for Member States, in line with the risk-based approach of this Regulation, to exempt certain operators from AML/CFT requirements where the activities they perform present low money laundering and terrorist financing risks and where the activities are limited in nature. To ensure transparent and consistent application of such exemptions across the Union, a mechanism should be put in place allowing the Commission to verify the necessity of the exemptions to be granted. The Commission should also publish such exemptions on a yearly basis in the Official Journal of the European Union.

(29) A consistent set of rules on internal systems and controls that applies to all obliged entities operating in the internal market will strengthen AML/CFT compliance and make supervision more effective. In order to ensure adequate mitigation of money laundering and terrorist financing risks, as well as of risks of non-implementation or evasion of targeted financial sanctions, obliged entities should have in place an internal control framework consisting of risk–based policies, procedures and controls and a clear division of responsibilities throughout the organisation. In line with the risk-based approach of this Regulation, those policies, procedures and controls should be proportionate to the nature of the business, including its risks and complexity, and the size of the obliged entity and respond to the risks of money laundering and terrorist financing that the entity faces, including, for crypto-asset service providers, transactions with self-hosted wallets.

(30) An appropriate risk-based approach requires obliged entities to identify the inherent risks of money laundering and terrorist financing as well as the risks of non-implementation or evasion of targeted financial sanctions that they face by virtue of their business in order to mitigate them effectively and to ensure that their policies, procedures and internal controls are appropriate to address those inherent risks. In doing so, obliged entities should take into account the characteristics of their customers, the products, services or transactions offered, including, for crypto-asset service providers, transactions with self-hosted addresses, the countries or geographical areas concerned and the distribution channels used. In light of the evolving nature of risks, such risk assessment should be regularly updated.

(31) With a view to supporting a consistent and effective approach to the identification of risks affecting their businesses by obliged entities, AMLA should issue guidelines on minimum requirements for the content of the business-wide risk assessment and additional sources of information to be taken into account. Those sources could include information from international standard setters in the field of AML/CFT, such as FATF mutual evaluation reports, and other credible and reliable sources providing information on typologies, emerging risks and criminal activity, including corruption, such as reports from civil society organisations, media and academia.

(32) It is appropriate to take account of the characteristics and needs of smaller obliged entities, and to ensure treatment which is appropriate to their specific needs, and the nature of the business. That might include exempting certain obliged entities from performing a risk assessment where the risks involved in the sector in which the entity operates are well understood.

(33) The FATF has developed standards for jurisdictions to identify and assess the risks of potential non-implementation or evasion of the targeted financial sanctions related to proliferation financing, and to take action to mitigate those risks. Those new standards introduced by the FATF do not substitute nor undermine the existing strict requirements for countries to implement targeted financial sanctions to comply with the relevant United Nations Security Council (‘UNSC’) resolutions relating to the prevention, suppression and disruption of proliferation of weapons of mass destruction and its financing. Those existing obligations, as implemented at Union level by Council Decisions 2010/413/CFSP (18) and (CFSP) 2016/849 (19) as well as by Council Regulations (EU) No 267/2012 (20) and (EU) 2017/1509 (21), remain binding on all natural and legal persons within the Union. Given the specific risks of non-implementation and evasion of targeted financial sanctions to which the Union is exposed, it is appropriate to expand the assessment of risks to encompass all targeted financial sanctions adopted at Union level. The risk-sensitive nature of AML/CFT measures related to targeted financial sanctions does not remove the rule-based obligation incumbent upon all natural or legal persons in the Union to freeze and not make funds or other assets available, directly or indirectly, to designated persons or entities.

(34) In order to ensure that risks of non-implementation or evasion of targeted financial sanctions are appropriately mitigated, it is important to set out measures that obliged entities are required to implement, including measures to check their customer base against the lists of persons or entities designated under targeted financial sanctions. The requirements incumbent upon obliged entities under this Regulation do not remove the rule-based obligation to freeze and not make funds and other assets available, directly or indirectly, to individuals or entities subject to targeted financial sanctions that apply to all natural or legal persons in the Union. In addition, the requirements of this Regulation are not intended to replace obligations regarding the screening of customers for the implementation of targeted financial sanctions under other Union legal acts or under national law.

(35) In order to reflect the latest developments at international level, a requirement is to be introduced by this Regulation to identify, understand, manage and mitigate risks of potential non-implementation or evasion of targeted financial sanctions at obliged entity level.

(36) Listing or designations of individuals or entities by the UNSC or the UN Sanctions Committee are integrated into Union law by means of decisions and regulations adopted under Article 29 of the Treaty on European Union (TEU) and Article 215 of the Treaty on the Functioning of the European Union (TFEU) respectively that impose targeted financial sanctions on such individuals and entities. The process for adoption of such acts at Union level requires verification of compliance of any designation or listing with fundamental rights granted under the Charter. Between the moment of publication by the UN and the moment of entry into application of the Union acts transposing the UN listings or designations, in order to enable the effective application of targeted financial sanctions, obliged entities should keep records of the funds or other assets they hold for customers listed or designated under UN financial sanctions, or customers owned or controlled by listed or designated individuals or entities, of any attempted transaction and of transactions carried out for the customer, such as for the fulfilment of basic needs of the customer.

(37) In assessing whether a customer who is a legal entity is owned or controlled by individuals designated under targeted financial sanctions, obliged entities should take into account the Council Guidelines on implementation and evaluation of restrictive measures (sanctions) in the framework of the Union common foreign and security policy and the Best Practices for the effective implementation of restrictive measures.

(38) It is important that obliged entities take all measures at the level of their management to implement internal policies, procedures and controls and to implement AML/CFT requirements. While a member of the management body should be identified as being responsible for implementing the obliged entity’s internal policies, procedures and controls, the responsibility for compliance with AML/CFT requirements should rest ultimately with the management body of the entity. That attribution of responsibility should be without prejudice to national provisions on joint civil or criminal liability of management bodies. Tasks pertaining to the day-to-day implementation of the obliged entity’s AML/CFT internal policies, procedures and controls should be entrusted to the compliance officer.

(39) It should be possible for each Member State to lay down in its national law that an obliged entity subject to prudential rules requiring the appointment of a compliance officer or of a head of the internal audit function can entrust those persons with the functions and responsibilities of AML/CFT compliance officer and internal audit function for AML/CFT purposes. In cases of higher risks, or where justified by the size of the obliged entity, it should be possible for the responsibilities of compliance controls and of the day-to-day operation of the obliged entity’s AML/CFT policies and procedures to be entrusted to two different persons.

(40) For effective implementation of AML/CFT measures, it is also vital that the employees of obliged entities, as well as their agents and distributors, who have a role in that implementation understand the requirements and the internal policies, procedures and controls in place in the entity. Obliged entities should put in place measures, including training programmes, to this effect. Where necessary, obliged entities should provide basic training on AML/CFT measures to all those who have a role in implementing such measures. That includes not only the employees of obliged entities but also their agents and distributors.

(41) Individuals entrusted with tasks related to an obliged entity’s compliance with AML/CFT requirements should undergo assessment of their skills, knowledge, expertise, integrity and conduct. Performance by employees of tasks related to the obliged entity’s compliance with the AML/CFT framework in relation to customers with whom they have a close private or professional relationship can lead to conflicts of interests and undermine the integrity of the system. Such relations might exist at the time of the establishment of the business relationship but can also arise thereafter. Therefore, obliged entities should have in place processes to manage and address conflicts of interests. Those processes should ensure that employees are prevented from performing any tasks related to the obliged entity’s compliance with the AML/CFT framework in relation to such customers.

(42) Situations might occur where individuals who would qualify as obliged entities provide their services in-house to businesses whose activities do not fall within the scope of this Regulation. As those businesses do not act as gatekeepers of the Union’s financial system, it is important to clarify that such employees, for example in-house lawyers, are not covered by the requirements of this Regulation. Similarly, individuals carrying out activities that fall within the scope of this Regulation should not be considered obliged entities in their own right where those activities are carried out in the context of their employment with an obliged entity, for example in the case of lawyers or accountants employed with a legal or accounting firm.

(43) The consistent implementation of group-wide AML/CFT policies and procedures is key to the robust and effective management of money laundering and terrorist financing risks within a group. To that end, group-wide policies, procedures and controls should be adopted and implemented by the parent undertaking. Entities within a group should be required to exchange information where such sharing is relevant for preventing money laundering and terrorist financing. Information sharing should be subject to sufficient guarantees in terms of confidentiality, data protection and use of information. AMLA should have the task of drawing up draft regulatory standards specifying the minimum requirements of group-wide procedures and policies, including minimum standards for information sharing within a group and the criteria for identifying parent undertakings for groups whose head office is located outside of the Union.

(44) In order to ensure effective application of AML/CFT requirements where several obliged entities are directly or indirectly linked with each other and constitute, or are a part of, a group of entities, it is necessary to consider the broadest possible definition of a group. For that purpose, obliged entities should follow applicable accounting rules which allow structures with various types of economic links to be considered as groups. While a traditional group includes a parent undertaking and its subsidiaries, other types of group structures are equally relevant, for example group structures of several parent entities owning a single subsidiary, which have been referred to as entities permanently affiliated to a central body in Article 10 of Regulation (EU) No 575/2013 of the European Parliament and of the Council (22), or financial institutions which are members of the same institutional protection scheme referred to in Article 113(7) of that Regulation. Those structures are all groups according to accounting rules and should therefore be considered as groups for the purposes of this Regulation.

(45) In addition to groups, other structures exist, such as networks or partnerships, in which obliged entities might share common ownership, management and compliance controls. To ensure a level playing field across the sectors whilst avoiding overburdening those sectors, AMLA should identify those situations where similar group-wide policies are to apply to those structures, taking into account the principle of proportionality.

(46) There are circumstances where branches and subsidiaries of obliged entities are located in third countries where the minimum AML/CFT requirements, including data protection obligations, are less strict than the Union AML/CFT framework. In such situations, and in order to fully prevent the use of the Union’s financial system for the purposes of money laundering and terrorist financing and to ensure the highest standard of protection for personal data of Union citizens, those branches and subsidiaries should comply with AML/CFT requirements laid down at Union level. Where the law of a third country does not permit compliance with those requirements, for example because of limitations to the group’s ability to access, process or exchange information due to an insufficient level of data protection or banking secrecy law in that third country, obliged entities should take additional measures to ensure that branches and subsidiaries located in that country effectively handle the risks. AMLA should be tasked with developing draft regulatory technical standards specifying the type of such additional measures, taking into account the principle of proportionality.

(47) Obliged entities might outsource tasks relating to the performance of certain AML/CFT requirements to a service provider. In the case of outsourcing relationships on a contractual basis between obliged entities and service providers not covered by AML/CFT requirements, any AML/CFT obligations upon those service providers arise only from the contract between the parties and not from this Regulation. Therefore, the responsibility for complying with AML/CFT requirements should remain entirely with the obliged entity. The obliged entity should in particular ensure that, where a service provider is involved for the purposes of remote customer identification, the risk-based approach is respected. Processes or arrangements that contribute to the performance of a requirement under this Regulation, but where the performance of the requirement itself is not carried out by a service provider, such as the use or acquisition of third-party software or the access to databases or screening services by the obliged entity, are not considered to be outsourcing.

(48) The possibility to outsource tasks to a service provider allows obliged entities to decide on how to allocate their resources to comply with this Regulation, but does not relieve them of their obligation to understand whether the measures they undertake, including those outsourced to service providers, mitigate the money laundering and terrorist financing risks identified, and whether such measures are appropriate. In order to ensure that such understanding is in place, the final decisions on measures that have a bearing on the implementation of policies, procedures and controls should always rest with the obliged entity.

(49) The notification of outsourcing arrangements to the supervisor does not imply an acceptance of the outsourcing arrangement. The information contained in that notification, in particular where critical functions are outsourced or where the obliged entity systematically outsources its functions, might however be taken into consideration by supervisors when assessing the obliged entity’s systems and controls, and when determining the residual risk profile or in preparation for inspections.

(50) In order for outsourcing relationships to function efficiently, further clarity is needed around the conditions according to which outsourcing takes place. AMLA should have the task of developing guidelines on the conditions under which outsourcing can take place, as well as the roles and responsibilities of the respective parties. To ensure that consistent oversight of outsourcing practices is ensured throughout the Union, the guidelines should also provide clarity on how supervisors are to take into account such practices and verify compliance with AML/CFT requirements when obliged entities resort to those practices.

(51) Customer due diligence requirements are essential to ensure that obliged entities identify, verify and monitor their business relationships with their clients, in relation to the money laundering and terrorist financing risks that they pose. Accurate identification and verification of data of prospective and existing customers are essential for understanding the risks of money laundering and terrorist financing associated with clients, whether they are natural or legal persons. Obliged entities should also understand on whose behalf or for the benefit of whom a transaction is carried out, for example in situations where credit institutions or financial institutions provide accounts to legal professionals for the purposes of receiving or holding their client’s funds as defined in Article 4, point (25), of Directive (EU) 2015/2366. In the context of customer due diligence, the person for the benefit of whom a transaction or activity is carried out does not refer to the recipient or beneficiary of a transaction carried out by the obliged entity for their customer.

(52) It is necessary to achieve a uniform and high standard of customer due diligence in the Union, relying on harmonised requirements for the identification of customers and verification of their identity, and reducing national divergences to allow for a level playing field across the internal market and for a consistent application of provisions throughout the Union. At the same time, it is essential that obliged entities apply customer due diligence measures in a risk-based manner. The risk-based approach is not an unduly permissive option for obliged entities. It involves the use of evidence-based decision-making in order to target more effectively the risks of money laundering and terrorist financing facing the Union and those operating within it.

(53) Civil society organisations that conduct charitable or humanitarian work in third countries contribute to the Union’s goals of achieving peace, stability, democracy and prosperity. Credit institutions and financial institutions play an important role in ensuring that such organisations can continue to conduct their work, by providing access to the financial system and important financial services that allow development and humanitarian funding to be channelled to developing or conflict areas. While obliged entities should be aware that activities conducted in certain jurisdictions expose them to a higher risk of money laundering or terrorist financing, the operation of civil society organisations in those jurisdictions should not, alone, result in the refusal to provide financial services or termination of such services, as the risk-based approach requires a holistic assessment of risks posed by individual business relationships, and the application of adequate measures to mitigate the specific risks. While credit institutions and financial institutions remain free to decide with whom they engage in contractual relationships, they should also be mindful of their central role in the functioning of the international financial system, and in enabling the movement of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 or of crypto-assets, for the important development and humanitarian goals that civil society organisations pursue. Such institutions should therefore make use of the flexibility allowed by the risk-based approach to mitigate the risks associated with business relationships in a proportionate manner. Under no circumstances should AML/CFT reasons be invoked to justify commercial decisions as regards prospective or existing clients.

(54) Obliged entities should identify and take reasonable measures to verify the identity of the beneficial owner using reliable documents and sources of information. The consultation of central registers of beneficial ownership information (‘central registers’) allows obliged entities to ensure consistency with information obtained through the verification process and should not be the obliged entity’s primary source for verification. Where obliged entities identify discrepancies between information held in the central registers and the information they obtain from the customer or other reliable sources in the course of customer due diligence, they should report those discrepancies to the entity in charge of the relevant central register so that measures can be taken to resolve inconsistencies. That process contributes to the quality and reliability of information held in those registers, as part of a multi-pronged approach towards ensuring that information contained in central registers is accurate, adequate and up-to-date. In low-risk situations and where the beneficial owners are known to the obliged entity, it should be possible for obliged entities to allow the customer to report discrepancies where minor differences are identified that consist of errors of a typographical or similar technical nature.

(55) The risks posed by foreign legal entities and foreign legal arrangements need to be adequately mitigated. Where a legal entity created outside the Union or an express trust or similar legal arrangement administered outside the Union, or whose trustee or person in an equivalent position resides or is established outside the Union, is about to enter into a business relationship with an obliged entity, the registration of the beneficial ownership information in the central register of a Member State should be a precondition for entering into the business relationship. However, for legal entities created outside the Union, the requirement should only apply in the case of medium-high or high risks of money laundering, its predicate offences or terrorist financing associated with the category of foreign legal entity, the sector in which the foreign legal entity operates, or in the case of medium-high or high risks of money laundering, its predicate offences or terrorist financing associated with the sector in which the obliged entity operates. The registration of the beneficial ownership information should also be a precondition for the continuation of a business relationship with a legal entity created outside the Union in a situation where that relationship becomes associated with such medium-high or high risks after its establishment.

(56) The process of establishing a business relationship or carrying out the steps necessary to conduct an occasional transaction is triggered when the customer expresses an interest in acquiring a product or receiving a service from an obliged entity. The services offered by real estate agents include helping customers to find a property to purchase, sell, rent or lease. Such services start to be relevant for AML/CFT purposes where there is a clear indication that the parties are willing to proceed with the purchase, sale, rental or lease or with taking the necessary preparatory steps. That could be, for instance, the moment when an offer for the purchase or rental of the property is made and accepted by the parties. Prior to that moment, it would not be necessary to conduct due diligence on any prospective customer. Similarly, it would not be proportionate to conduct customer due diligence on persons that have not yet expressed an interest in going forward with the purchase or rental of a specific property.

(57) Real estate transactions are exposed to money laundering and terrorist financing risks. In order to mitigate those risks, real estate operators intermediating the buying, selling and letting of immovable property should be subject to the requirements of this Regulation, regardless of their designation or principal business or profession, including property developers when and to the extent that they intermediate in the buying, selling and letting of immovable property.

(58) The anonymity associated with certain electronic money products exposes them to money laundering and terrorist financing risks. There are however significant differences across the sector, and not all electronic money products bear the same level of risk. For example, certain low value electronic money products, such as prepaid gift cards or prepaid vouchers, might present low risks of money laundering or terrorist financing. In order to ensure that the requirements imposed on the sector are commensurate with its risk and do not effectively hamper its operation, it should be possible, in certain proven low-risk circumstances and under strict risk-mitigating conditions, to exempt those products from certain customer due diligence measures, such as the identification and verification of the customer and of the beneficial owner, but not from the monitoring of transactions or of business relationships. It should only be possible for supervisors to grant such an exemption upon verification of the proven low risk having regard to relevant risk factors to be defined by AMLA and in a way that effectively mitigates any risk of money laundering or terrorist financing and that precludes circumvention of AML/CFT rules. In any case, any exemption should be conditional on strict limits regarding the maximum value of the product, its exclusive use to purchase goods or services, and provided that the amount stored cannot be exchanged for other value.

(59) Obliged entities should not be required to apply due diligence measures on customers carrying out occasional or linked transactions below a certain value, unless there is suspicion of money laundering or terrorist financing. Whereas the EUR 10 000, or the equivalent in national currency, threshold applies to most occasional transactions, obliged entities which operate in sectors or carry out transactions that present a higher risk of money laundering and terrorist financing should be required to apply customer due diligence measures for transactions with lower thresholds. To identify the sectors or transactions as well as the adequate thresholds for those sectors or transactions, AMLA should develop dedicated draft regulatory technical standards.

(60) There are specific situations where, for the purposes of customer due diligence, the customer is not limited to the person transacting with the obliged entity. That is the case, for example, where only one notary is involved in a real estate transaction. In such cases, in order to ensure that adequate checks are carried out on the transaction to detect possible cases of money laundering, its predicate offences or terrorist financing, obliged entities should consider both the buyer and the seller as customers and apply customer due diligence measures on both parties. This Regulation should provide a list of such situations where the customer is not, or is not limited to, the direct customer of the obliged entity. Such a list should complement the understanding of who the customer is in typical situations and should not be understood as encompassing an exhaustive interpretation of the term. Similarly, a business relationship should not always require a contractual relationship or other formal engagement as long as the services are provided repeatedly or over a period of time so as to entail an element of duration. Where national law precludes obliged entities that are public officials from entering into contractual relationships with customers, such national law should not be construed as prohibiting obliged entities from treating a series of transactions as a business relationship for the purposes of AML/CFT.

(61) The introduction of a Union-wide limit to large cash payments mitigates the risks associated with the use of such payments. However, obliged entities that carry out transactions in cash below that limit remain vulnerable to risks of money laundering and terrorist financing as they provide a point of entry into the Union’s financial system. Therefore, it is necessary to require the application of customer due diligence measures to mitigate the risks of misuse of cash. To ensure that the measures are proportionate with the risks posed by transactions of a value lower than EUR 10 000, such measures should be limited to the identification and verification of the customer and the beneficial owner when carrying out occasional transactions in cash of at least EUR 3 000. That limitation does not relieve the obliged entity from applying all customer due diligence measures whenever there is a suspicion of money laundering or terrorist financing, or from reporting suspicious transactions to the FIU.

(62) Some business models are based on the obliged entity having a business relationship with a merchant for offering payment initiation services through which the merchant gets paid for the provision of goods or services, and not with the merchant’s customer, who authorises the payment initiation service to initiate a single or one-off transaction to the merchant. In such a business model, the obliged entity’s customer for the purpose of AML/CFT rules is the merchant, and not the merchant’s customer. Therefore, with respect to payment initiation services, customer due diligence measures should be applied by the obliged entity vis-a-vis the merchant. In relation to other financial services that fall within the scope of this Regulation, including where provided by the same operator, the determination of the customer should be done having regard to the services provided.

(63) Gambling activities vary in nature, geographical scope and associated risks. In order to ensure a proportionate and risk-based application of this Regulation, it should be possible for Member States to identify gambling services associated with low money laundering and terrorist financing risks, such as State or private lotteries or State-administered gambling activities, and to decide not to apply all or some of the requirements of this Regulation to them. Given the potential cross-border effects of national exceptions, it is necessary to ensure a consistent application of a strict risk-based approach across the Union. To that end, the Commission should be enabled to approve Member States’ decisions, or to reject them where the exception is not justified by a proven low risk. In any case, no exception should be granted in relation to activities associated with higher risks. This is the case for activities such as casinos, online gambling and sport betting, but is not the case where online gambling activities are administered by the State, whether through direct provision of those services or through regulation of the way in which those gambling services are organised, operated and administered. In light of the risks for public health or of criminal activities that can be associated with gambling, national measures regulating the organisation, operation and administration of gambling, where genuinely pursuing goals of public policy, public security or public health, can contribute to reducing the risks associated with that activity.

(64) The EUR 2 000, or the equivalent in national currency, threshold applicable to providers of gambling services is met regardless of whether the customer carries out a single transaction of at least that amount or several smaller transactions which add up to that amount. To that effect, providers of gambling services should be able to attribute transactions to a given customer even if they have not yet verified the customer’s identity, to be in a position to determine whether and when that threshold has been met. Thus, providers of gambling services should have systems in place that allow attribution and monitoring of transactions prior to the application of the requirement to conduct customer due diligence. In the case of casinos or other physical gambling premises, it can be impractical to check the customer’s identity upon each transaction. In such cases, it should be possible to identify the customer and verify the customer’s identity upon entry into the gambling premises, provided that systems are in place to attribute transactions carried out at the gambling premises, including the purchase or exchange of gambling chips, to that customer.

(65) Directive (EU) 2015/849, despite having harmonised the rules of Member States in the area of customer identification obligations to a certain degree, did not lay down detailed rules in relation to the procedures to be followed by obliged entities. In view of the crucial importance of that aspect in the prevention of money laundering and terrorist financing, it is appropriate, in accordance with the risk-based approach, to introduce more specific and detailed provisions on the identification of the customer and on the verification of the customer’s identity, whether in relation to natural or legal persons, legal arrangements such as trusts, or entities having legal capacity under national law.

(66) Technological developments and progress in digitalisation enable a secure remote or electronic identification and verification of prospective and existing customers and can facilitate the remote performance of customer due diligence. The identification solutions as set out in Regulation (EU) No 910/2014 of the European Parliament and of the Council (23) enable secure and trusted means of customer identification and verification for both prospective and existing customers and can facilitate the remote performance of customer due diligence. The electronic identification as set out in that Regulation should be taken into account and accepted by obliged entities for the customer identification process. The use of such means of identification can reduce, where appropriate risk mitigation measures are in place, the risk level to standard or even low. Where such electronic identification is not available to a customer, for example due to the nature of their residence status in a given Member State or their residence in a third country, verification should take place through relevant qualified trust services.

(67) To ensure that the AML/CFT framework prevents illicit funds from entering the financial system, obliged entities should carry out customer due diligence before entering into business relationships with prospective clients, in line with the risk-based approach. Nevertheless, in order not to unnecessarily delay the normal conduct of business, obliged entities should be able to collect the information from the prospective customer during the establishment of a business relationship. Credit institutions and financial institutions should be able to obtain the necessary information from the prospective customers once the relationship is established, provided that transactions are not initiated until the customer due diligence process is successfully completed.

(68) The customer due diligence process is not limited to the identification and verification of the customer’s identity. Before entering into business relationships or carrying out occasional transactions, obliged entities should also assess the purpose and nature of a business relationship or occasional transaction. Pre-contractual or other information about the proposed product or service that is communicated to the prospective customer can contribute to the understanding of that purpose. Obliged entities should always be able to assess the purpose and nature of a prospective business relationship or occasional transaction in an unambiguous manner. Where the offered service or product enables customers to carry out various types of transactions or activities, obliged entities should obtain sufficient information on the intention of the customer regarding the use to be made of that relationship.

(69) To ensure the effectiveness of the AML/CFT framework, obliged entities should regularly review the information obtained from their customers, in accordance with the risk-based approach. Business relationships are likely to evolve as the customer’s circumstances and the activities they conduct through the business relationship change over time. In order to maintain a comprehensive understanding of the customer risk profile and conduct meaningful scrutiny of transactions, obliged entities should regularly review the information obtained from their customers, in accordance with the risk-based approach. Such reviews should be done on a periodic basis but should also be triggered by changes in relevant circumstances of the customer, when facts and information point towards a potential change in the risk profile or identification details of the customer. To that end, the obliged entity should consider the need to review the customer file in response to material changes, such as a change in the jurisdictions transacted with, in the value or volume of transactions, upon requests for new products or services that are significantly different in terms of risk, or following changes in beneficial ownership.

(70) In the context of repeated clients for whom customer due diligence measures have recently been conducted, it should be possible for customer due diligence measures to be fulfilled by obtaining a confirmation from the customer that the information and documents held in the records have not changed. Such a method facilitates the application of AML/CFT obligations in situations where the obliged entity is confident that the information pertaining to the customer has not changed, as it is incumbent on obliged entities to ensure that they take adequate customer due diligence measures. In all cases, the confirmation received from the customer, and any changes to the information held on the customer, should be recorded.

(71) Obliged entities might provide more than one product or service in the context of a business relationship. In those circumstances, the requirement to update information, data and documents at regular intervals is not intended to target the individual product or service, but the business relationship in its entirety. It is for the obliged entities to assess, across the range of products or services provided, when the relevant circumstances of the customer change, or when other conditions triggering the updating of the customer due diligence are met, and to proceed to review the customer file in relation to the entirety of the business relationship.

(72) Obliged entities should also set up a monitoring system to detect transactions that might raise money laundering or terrorist financing suspicions. To ensure the effectiveness of the transaction monitoring, obliged entities’ monitoring activity should in principle cover all services and products offered to customers and all transactions which are carried out on behalf of the customer or offered to the customer by the obliged entity. However, not all transactions need to be scrutinised individually. The intensity of the monitoring should respect the risk-based approach and be designed around precise and relevant criteria, taking account, in particular, of the characteristics of the customer and the risk level associated with them, the products and services offered, and the countries or geographical areas concerned. AMLA should develop guidelines to ensure that the intensity of the monitoring of business relationships and of transactions is adequate and proportionate to the level of risk.

(73) Terminating the business relationship where customer due diligence measures cannot be complied with reduces the obliged entity’s exposure to risks posed by possible changes in the customer’s profile. However, there might be situations where the termination should not be pursued due to public interest goals. This is the case, for example, in relation to life insurance contracts, where obliged entities should, where necessary, as an alternative to termination take measures to freeze the business relationship including by prohibiting any further services to that customer and withholding the payout to beneficiaries, until customer due diligence measures can be complied with. Additionally, certain products and services require the obliged entity to continue holding or receiving the customer’s funds as defined in Article 4, point (25), of Directive (EU) 2015/2366, for example in the context of lending, payment accounts or the taking of deposits. That should however not be treated as an impediment to the requirement to terminate the business relationship, which can be achieved by ensuring that no transactions or activities are carried out for the customer.

(74) In order to ensure consistent application of this Regulation, AMLA should have the task of drawing up draft regulatory technical standards on customer due diligence. Those regulatory technical standards should set out the minimum set of information to be obtained by obliged entities in order to enter into new business relationships with customers or assess ongoing ones, according to the level of risk associated with each customer. Furthermore, the draft regulatory technical standards should provide sufficient clarity to allow market players to develop secure, accessible and innovative means of verifying customers’ identity and performing customer due diligence, including remotely, while respecting the principle of technology neutrality. Those specific tasks are in line with the role and responsibilities of AMLA as provided in Regulation (EU) 2024/1620.

(75) The harmonisation of customer due diligence measures will contribute to achieving consistent, and consistently effective, understanding of the risks associated with an existing or prospective customer regardless of where the business relationship is opened in the Union. That harmonisation should also ensure that the information obtained in the performance of customer due diligence is not used by obliged entities to pursue de-risking practices which might result in circumventing other legal obligations, in particular those laid down in Directive 2014/92/EU of the European Parliament and of the Council (24) or Directive (EU) 2015/2366, without achieving the Union’s objectives in the prevention of money laundering and terrorist financing. To enable the proper supervision of compliance with the customer due diligence obligations, it is important that obliged entities keep record of the actions undertaken and the information obtained during the customer due diligence process, irrespective of whether a new business relationship is established with them and of whether they have submitted a suspicious transaction report upon refusing to establish a business relationship. Where the obliged entity takes a decision to not enter into a business relationship with a prospective customer, or to terminate an existing business relationship, to refuse to carry out an occasional transaction, or to apply alternative measures to terminating a business relationship, the customer due diligence records should include the grounds for such a decision. That will enable supervisory authorities to assess whether obliged entities have appropriately calibrated their customer due diligence practices and how the entity’s risk exposure evolves, as well as help to build statistical evidence on the application of customer due diligence rules by obliged entities throughout the Union.

(76) The approach for the review of existing customers in the current AML/CFT framework is already risk-based. However, given the higher risk of money laundering, its predicate offences and terrorist financing associated with certain intermediary structures, that approach might not allow for the timely detection and assessment of risks. It is therefore important to ensure that clearly specified categories of existing customers are also monitored on a regular basis.

(77) Risk itself is variable in nature, and the variables, on their own or in combination, can increase or decrease the potential risk posed, thus having an impact on the appropriate level of preventive measures, such as customer due diligence measures.

(78) In low risk situations, obliged entities should be able to apply simplified due diligence measures. That does not equate to an exemption or absence of customer due diligence measures. It rather consists of a simplified or reduced set of scrutiny measures, which should however address all components of the standard due diligence procedure. In line with the risk-based approach, obliged entities should nevertheless be able to reduce the frequency or intensity of their customer or transaction scrutiny, or rely on adequate assumptions with regard to the purpose of the business relationship or use of simple products. The regulatory technical standards on customer due diligence should set out the specific simplified measures that obliged entities are able to implement in the case of lower risk situations identified in the risk assessment at Union level conducted by the Commission. When developing draft regulatory technical standards, AMLA should have due regard to preserving social and financial inclusion.

(79) It should be recognised that certain situations present a greater risk of money laundering or terrorist financing. Although the identity and business profile of all customers should be established with the regular application of customer due diligence measures, there are cases in which particularly rigorous customer identification and verification procedures are required. Therefore, it is necessary to lay down detailed rules on such enhanced due diligence measures, including specific enhanced due diligence measures for cross-border correspondent relationships.

(80) Cross-border correspondent relationships with a third country’s respondent institution are characterised by their on-going, repetitive nature. Moreover, not all cross-border correspondent banking services present the same level of money laundering and terrorist financing risks. Therefore, the intensity of the enhanced due diligence measures should be determined by application of the principles of the risk-based approach. However, the risk-based approach should not be applied when interacting with a third country’s respondent institutions that have no physical presence where they are created, or with unregistered and unlicensed entities providing crypto-asset services. Given the high risk of money laundering and terrorist financing inherent in shell institutions, credit institutions and financial institutions should refrain from entertaining any correspondent relationship with such shell institutions, as well as with counterparts in third countries that allow their accounts to be used by shell institutions. To avoid misuse of the Union’s financial system to provide unregulated services, crypto-assets service providers should also ensure that their accounts are not used by nested exchanges and should have in place policies and procedures to detect any such attempt.

(81) In the context of the performance of their oversight function, supervisors might identify situations where breaches of AML/CFT requirements by third-country respondent institutions, or weaknesses in their implementation of the AML/CFT requirements, cause risks to the Union’s financial system. In order to mitigate those risks, it should be possible for AMLA to address recommendations to credit institutions and financial institutions in the Union in order to inform them of its views regarding the deficiencies of those third-country respondent institutions. Those recommendations should be issued where AMLA and financial supervisors in the Union agree that the breaches and weaknesses in place in the third-country respondent institutions are likely to affect the risk exposure of correspondent relationships by credit institutions and financial institutions in the Union, and provided that the third-country respondent institution and its supervisor have had the opportunity to provide their views. In order to preserve the good functioning of the Union’s financial system, credit institutions and financial institutions should take adequate measures in response to recommendations by AMLA, including by abstaining from entering into or continuing a correspondent relationship unless they can put in place sufficient mitigating measures to address the risks posed by the correspondent relationship.

(82) In the context of enhanced due diligence measures, obtaining approval from senior management for establishing business relationships does not need to imply, in all cases, obtaining approval from the board of directors. It should be possible for such approval to be granted by someone with sufficient knowledge of the entity’s money laundering and terrorist financing risk exposure and of sufficient seniority to take decisions affecting its risk exposure.

(83) In order to protect the proper functioning of the Union’s financial system from money laundering and terrorist financing, the Commission should be empowered to adopt delegated acts to identify third countries whose shortcomings in their national AML/CFT regimes represent a threat to the integrity of the Union’s internal market. The changing nature of money laundering and terrorist financing threats from outside the Union, facilitated by a constant evolution of technology and of the means at the disposal of criminals, requires that quick and continuous adaptations of the legal framework as regards third countries be made in order to address efficiently existing risks and prevent new ones from arising. The Commission should take into account, as a baseline for its assessment, information from international organisations and standard setters in the field of AML/CFT, such as FATF public statements, mutual evaluation or detailed assessment reports or published follow-up reports, and adapt its assessments to the changes therein, where appropriate. The Commission should act within 20 days of ascertaining shortcomings in a third country’s AML/CFT regime that pose a threat to the integrity of the Union’s internal market.

(84) Third countries which are ‘subject to a call for action’ by the relevant international standard-setter, namely the FATF, present significant strategic deficiencies of a persistent nature in their legal and institutional AML/CFT frameworks and their implementation which are likely to pose a high risk to the Union’s financial system. The persistent nature of those significant strategic deficiencies, reflective of the lack of commitment or continued failure by the third country to tackle them, signal a heightened level of threat emanating from those third countries, which requires an effective, consistent and harmonised mitigating response at Union level. Therefore, obliged entities should be required to apply the whole set of available enhanced due diligence measures to occasional transactions and business relationships involving those high-risk third countries to manage and mitigate the underlying risks. Furthermore, the high level of risk justifies the application of additional specific countermeasures, whether at the level of obliged entities or by the Member States. Such an approach would avoid divergence in the determination of the relevant countermeasures, which would expose the entirety of Union’s financial system to risks. Where Member States identify specific risks that are not mitigated, they should be able to apply additional countermeasures, in which case they should notify the Commission thereof. Where the Commission considers that those risks are of relevance for the internal market, it should be able to update the relevant delegated act to include the necessary additional countermeasures to mitigate those risks. Where the Commission considers that those countermeasures are not necessary and undermine the proper functioning of the Union’s internal market, it should be empowered to decide that the Member State put an end to the specific countermeasure. Prior to triggering the procedure for that decision, the Commission should provide an opportunity to the Member State concerned to submit its views on the consideration of the Commission. Given its technical expertise, AMLA can provide useful input to the Commission in identifying the appropriate countermeasures.

(85) Compliance weaknesses in both the legal and institutional AML/CFT framework and its implementation in third countries which are subject to ‘increased monitoring’ by the FATF are susceptible to be exploited by criminals. This is likely to represent a risk for the Union’s financial system, and that risk needs to be managed and mitigated. The commitment of those third countries to address identified weaknesses, while not eliminating the risk, justifies a mitigating response less severe than that applicable to high-risk third countries. Where such third countries commit to address identified weaknesses, obliged entities should apply enhanced due diligence measures to occasional transactions and business relationships when dealing with natural persons or legal entities established in those third countries that are tailored to the specific weaknesses identified in each third country. Such granular identification of the enhanced due diligence measures to be applied would, in line with the risk-based approach, also ensure that the measures are proportionate to the level of risk. To ensure such consistent and proportionate approach, the Commission should be able to identify which specific enhanced due diligence measures are required in order to mitigate country-specific risks. Given AMLA’s technical expertise, it can provide useful input to the Commission to identify the appropriate enhanced due diligence measures.

(86) Countries that are not publicly identified as subject to calls for actions or increased monitoring by the FATF might still pose a specific and serious threat to the integrity of the Union’s financial system, which could be due either to compliance weaknesses or to significant strategic deficiencies of a persistent nature in their AML/CFT regime. To mitigate those specific risks, that cannot be mitigated through measures applicable to countries with strategic deficiencies or countries with compliance weaknesses, it should be possible for the Commission to take action in exceptional circumstances by identifying such third countries, based on a clear set of criteria and with the support of AMLA. According to the level of risk posed to the Union’s financial system, the Commission should require the application either of all enhanced due diligence measures and country-specific countermeasures, in relation to high-risk third countries, or of country-specific enhanced due diligence measures, in relation to third countries with compliance weaknesses.

(87) In order to ensure a consistent identification of third countries that pose a specific and serious threat to the Union’s financial system, while not being publicly identified as subject to calls for actions or increased monitoring by the FATF, the Commission should be able to set out, by means of an implementing act, the methodology for the identification in exceptional circumstances of such third countries. That methodology should include in particular how the criteria are to be assessed and the process for the interaction with such third countries and for the involvement of Member States and AMLA in the preparatory stages of such identification.

(88) Considering that there could be changes to the AML/CFT frameworks of third countries identified under this Regulation, or in their implementation, for example as result of the country’s commitment to address the identified weaknesses or of the adoption of relevant AML/CFT measures to tackle them, which could change the nature and level of the risks emanating from them, the Commission should regularly review the identification of those specific enhanced due diligence measures in order to ensure that they remain proportionate and adequate.

(89) Potential external threats to the Union’s financial system do not only emanate from third countries, but can also emerge in relation to specific customer risk factors or products, services, transactions or delivery channels which are observed in relation to a specific geographical area outside the Union. There is therefore a need to identify money laundering and terrorist financing trends, risks and methods to which Union’s obliged entities might be exposed. AMLA is best placed to detect any emerging money laundering and terrorist financing typologies from outside the Union, in order to monitor their evolution with a view to providing guidance to the Union’s obliged entities on the need to apply enhanced due diligence measures aimed at mitigating such risks.

(90) Relationships with individuals who hold or who have held important public functions, within the Union or internationally, and in particular individuals from countries where corruption is widespread, could expose the financial sector to significant reputational and legal risks. The international effort to combat corruption also justifies the need to pay particular attention to such persons and to apply appropriate enhanced due diligence measures with respect to persons who are or who have been entrusted with prominent public functions and with respect to senior figures in international organisations. Therefore, it is necessary to specify measures which obliged entities should apply with respect to transactions or business relationships with politically exposed persons. To facilitate the risk-based approach, AMLA should be tasked with issuing guidelines on assessing the level of risks associated with a particular category of politically exposed persons, their family members or persons known to be close associates.

(91) Risks associated with persons who are or who have been entrusted with prominent public functions are not limited to the national level but can also exist at regional or municipal levels. This is particularly true at the local level for densely populated areas, such as cities, which alongside the regional level often manage significant public funds and access to critical services or permits, with a resulting risk of corruption and associated money laundering. Therefore, it is necessary to include in the category of persons who are or who have been entrusted with prominent public functions the heads of regional and local authorities, including groupings of municipalities and metropolitan regions, with at least 50 000 inhabitants. At the same time, it should be acknowledged that the geography and administrative organisation of Member States vary significantly, and Member States should be able, where appropriate, to set a lower threshold to cover the relevant local authorities on the basis of risk. Where Member States decide to set lower thresholds, they should communicate those lower thresholds to the Commission.

(92) Members of the administrative, management or supervisory bodies of enterprises controlled by the state or by regional or local authorities can also be exposed to risks of corruption and associated money laundering. Given the size of the budget of such enterprises and the funds under management, such risks are particularly acute in relation to senior executive members in enterprises controlled by the state. Risks can also arise in relation to enterprises of a significant size controlled by regional and local authorities. As a result, the senior executives in enterprises controlled by regional or local authorities should be considered as politically exposed persons where those enterprises qualify as medium-sized or large undertakings or groups as defined in Article 3 of Directive 2013/34/EU of the European Parliament and of the Council (25). However, recognising the geographical and administrative organisational differences, and the powers and responsibilities associated with those enterprises and their senior executives, Member States should be able to choose to set a lower annual turnover threshold on the basis of risk. In such a case, Member States should notify the Commission of that decision.

(93) In order to identify politically exposed persons in the Union, lists should be issued by Member States indicating the specific functions which, in accordance with national laws, regulations and administrative provisions, qualify as prominent public functions. Member States should request each international organisation accredited on their territories to issue and keep up-to-date a list of prominent public functions at that international organisation. The Commission should be tasked with compiling and issuing a list, which should be valid across the Union, as regards persons entrusted with prominent public functions in Union institutions or bodies. In order to ensure a harmonised approach to the identification and notification of prominent public functions, the Commission should be able to set out, by means of an implementing act, the format to be used for Member States’ notifications, and should be empowered to adopt delegated acts supplementing the categories of prominent public functions identified by this Regulation, where they are common across Member States.

(94) Where customers are no longer entrusted with a prominent public function, they can still pose a higher risk, for example because of the informal influence they could still exercise, or because their previous and current functions are linked. It is essential that obliged entities take into consideration those continuing risks and apply one or more enhanced due diligence measures until such time that the individuals are deemed to pose no further risk, and in any case for not less than 12 months following the time when they cease to be entrusted with a prominent public function.

(95) Insurance companies often do not have client relationships with beneficiaries of the insurance policies. However, they should be able to identify cases of higher risk, such as when the proceeds of the policy benefit a politically exposed person. To determine whether this is the case, the insurance policy should include reasonable measures to identify the beneficiary, as if that person were a new client. It should be possible for such measures to be taken at the time of the payout or at the time of the assignment of the policy, but not later.

(96) Close private and professional relationships might be abused for money laundering and terrorist financing purposes. For that reason, measures concerning politically exposed persons should also apply to their family members and persons known to be close associates. Properly identifying family members and persons known to be close associates might depend on the socio-economic and cultural structure of the country of the politically exposed person. Against that background, AMLA should have the task of issuing guidelines on the criteria to use to identify persons who should be considered as close associates.

(97) Relationships with family members which might be abused by politically exposed persons do not only cover those with parents and descendants but can also include those with siblings. This is particularly the case for categories of politically exposed persons who hold senior central government posts. In recognition, however, of differing socio-economic and cultural structures in existence at national level, which might influence the potential for abuse of sibling relationships, Member States should be able to apply a broader scope for the designation of siblings as family members of politically exposed persons to adequately mitigate the risks of abuse of those relationships. Where Member States decide to apply a broader scope, they should communicate the details of that broader scope to the Commission.

(98) The requirements relating to politically exposed persons, their family members and persons known to be close associates are of a preventive and not criminal nature, and should not be interpreted as implying that politically exposed persons, their family members or close associates are involved in criminal activity. Refusing a business relationship with a person simply on the basis of a determination that they are a politically exposed person or a family member or a person known to be a close associate of a politically exposed person is contrary to the letter and spirit of this Regulation.

(99) Given the vulnerability of residency-by-investment schemes to money laundering, tax crimes, corruption and the evasion of targeted financial sanctions, as well as the potential associated significant security threats for the Union as a whole, it is appropriate that obliged entities carry out, as a minimum, specific enhanced due diligence with respect to customers who are third-country nationals who are in the process of applying for residence rights in a Member State within the framework of those schemes.

(100) The provision of personalised asset management services to individuals with a high level of wealth might expose credit institutions, financial institutions and trust or company service providers to specific risks including those arising from the complex and often personalised nature of such services. It is therefore necessary to specify a set of enhanced due diligence measures that should be applied, as a minimum, where such business relationships are deemed to pose a high risk of money laundering, its predicate offences or terrorist financing. The determination that a customer holds assets with a value of at least EUR 50 000 000, or the equivalent in national or foreign currency, takes into account financial and investable assets including cash and cash equivalents, whether held as deposits or in savings products, as well as investments such as stocks, bonds and mutual funds, even when they are held under long-term agreements with that obliged entity. Furthermore, the value of the customer’s real estate assets, excluding his or her private residence, should be taken into account. For the purposes of making that determination, credit institutions, financial institutions and trust or company service providers need not carry out or request a precise calculation of the customer’s total wealth. Rather, such entities should take measures to establish whether a customer holds assets with a value of at least EUR 50 000 000, or the equivalent in national or foreign currency, in financial, investable or real estate assets.

(101) In order to avoid repeated customer identification procedures, it is appropriate, subject to suitable safeguards, to allow obliged entities to rely on the customer information collected by other obliged entities. Where an obliged entity relies on another obliged entity, the ultimate responsibility for customer due diligence should remain with the obliged entity which chooses to rely on the customer due diligence performed by another obliged entity. The obliged entity relied upon should also retain its own responsibility for compliance with AML/CFT requirements, including the requirement to report suspicious transactions and retain records.

(102) The introduction of harmonised AML/CFT requirements across the Union, including with regard to group-wide policies and procedures, information exchange and reliance allows obliged entities operating within a group to leverage to the maximum the systems in place within that group in situations concerning the same customers. Those rules permit not only consistent and efficient implementation of AML/CFT rules across the group but also benefit from economies of scale at group level, for example by making it possible for obliged entities within the group to rely on the outcomes of processes adopted by other obliged entities within the group to comply with their customer identification and verification requirements.

(103) In order for reliance on measures carried out by a third-party to function efficiently, further clarity is needed around the conditions according to which such reliance takes place. AMLA should have the task of developing guidelines on the conditions under which third-party reliance can take place, as well as the roles and responsibilities of the respective parties. To ensure that consistent oversight of reliance is ensured throughout the Union, those guidelines should also provide clarity on how supervisors should take into account such practices and verify compliance with AML/CFT requirements where obliged entities resort to those practices.

(104) The concept of beneficial ownership was introduced to increase transparency of complex corporate structures. The need to access accurate, up-to-date and adequate information on the beneficial owner is a key factor in tracing criminals who might otherwise be able to hide their identity behind such opaque structures. Member States are currently required to ensure that corporate and other legal entities, as well as express trusts and other similar legal arrangements, obtain and hold adequate, accurate and up-to-date information on their beneficial ownership. However, the degree of transparency imposed by Member States varies. The rules are subject to divergent interpretations, and that results in different methods to identify beneficial owners of a given legal entity or legal arrangement. This is due, inter alia, to inconsistent methods of calculating indirect ownership of a legal entity or legal arrangement, and differences between the legal systems of the Member States. This hampers the transparency that was intended to be achieved. It is therefore necessary to clarify the rules to achieve a consistent definition of beneficial owner and its application across the internal market.

(105) The application of the rules for identifying the beneficial ownership of legal entities, as well as of legal arrangements, can give rise to implementation questions when relevant stakeholders are confronted with concrete cases, especially in instances of complex corporate structures, where the criteria of ownership interest and control coexist, or for the purposes of determining indirect ownership or control. In order to support the application of those rules by legal entities, trustees or persons holding an equivalent position in similar legal arrangements and obliged entities, and consistent with the harmonisation goal of this Regulation, it should be possible for the Commission to adopt guidelines setting out how rules to identify the beneficial owners in different scenarios are to be applied, including through the use of case examples.

(106) A meaningful identification of the beneficial owners requires a determination of whether control is exercised via other means. The determination of the existence of an ownership interest or of control through an ownership interest is necessary but not sufficient and it does not exclude the need for checks to determine the beneficial owners. The test as to whether any natural person exercises control via other means is not a subsequent test to be performed only where it is not possible to determine an ownership interest. The two tests, namely that of existence of an ownership interest or control through an ownership interest and that of control via other means, should be performed in parallel.

(107) An ownership of 25 % or more of the shares or voting rights or other ownership interest in general establishes the beneficial ownership of a corporate entity. Ownership interest should encompass both control rights and rights that are significant in terms of receiving a benefit, such as a right to a share of profits or other internal resources or liquidation balance. There might, however, be situations where the risk of certain categories of corporate entities being misused for money laundering or terrorist financing purposes is higher, for example due to the specific higher risk sectors in which those corporate entities operate. In such situations, enhanced transparency measures are necessary to dissuade criminals from setting up or infiltrating those entities, either through direct or indirect ownership or control. In order to ensure that the Union is able to adequately mitigate such varying levels of risk, it is necessary to empower the Commission to identify those categories of corporate entities that should be subject to lower beneficial transparency thresholds. To that end, Member States should inform the Commission where they identify categories of corporate entities that are exposed to higher money laundering and terrorist financing risks. In those notifications, it should be possible for Member States to indicate a lower ownership threshold that they consider would mitigate those risks. Such identification should be ongoing and should rely on the results of the risk assessment at Union level and of the national risk assessment as well as on relevant analyses and reports produced by AMLA, Europol or other Union bodies that have a role in the prevention, investigation and prosecution of money laundering and terrorist financing. That lower threshold should be of a sufficiently low level to mitigate the higher risks that corporate entities be misused for criminal purposes. To that end, that lower threshold should in general not be set at more than 15 % of the shares or voting rights or other ownership interest. However, there might be cases in which, on the basis of a risk-sensitive assessment, a higher threshold would be more proportionate to address the identified risks. In those cases, it should be possible for the Commission to set the threshold between 15 % and 25 % of the ownership interest.

(108) By their complex nature, multi-layered ownership and control structures make the identification of beneficial owners more difficult. The concept of ‘ownership or control structure’ is intended to describe the way in which a legal entity is indirectly owned or controlled, or in which a legal arrangement is indirectly controlled, as a result of the relationships that exist between legal entities or arrangements across multiple layers. In order to ensure a consistent approach throughout the internal market, it is necessary to clarify the rules that apply to those situations. For that purpose, it is necessary to assess simultaneously whether any natural person has a direct or indirect shareholding with 25 % or more of the shares or voting rights or other ownership interest, and whether any natural person controls the direct shareholder with 25 % or more of the shares or voting rights or other ownership interest in the corporate entity. In the case of indirect shareholding, the beneficial owners should be identified by multiplying the shares in the ownership chain. To that end, all shares directly or indirectly owned by the same natural person should be added together. That requires the shareholding on every level of ownership to be taken into account. Where 25 % of the shares or voting rights or other ownership interest in the corporate entity are owned by a shareholder that is a legal entity other than a corporate entity, the beneficial ownership should be determined having regard to the specific structure of the shareholder, including whether any natural person exercises control through other means over a shareholder.

(109) The determination of the beneficial owner of a corporate entity in situations where the shares of the corporate entity are held in a legal arrangement, or where they are held by a foundation or similar legal entity, might be more difficult in view of the different nature and identification criteria of beneficial ownership between legal entities and legal arrangements. It is therefore necessary to set out clear rules to deal with those situations of multi-layered structure. In such cases, all beneficial owners of the legal arrangement, or of a similar legal entity such as a foundation, should be the beneficial owners of the corporate entity whose shares are held in the legal arrangement or held by the foundation.

(110) A common understanding of the concept of control and a more precise definition of the means of control are necessary to ensure consistent application of the rules across the internal market. Control should be understood as the effective ability to impose one’s will on the corporate entity’s decision-making on substantive issues. The usual means of control is a majority share of voting rights. The position of beneficial owner can also be established by control via other means without having significant, or any, ownership interest. For that reason, in order to ascertain all individuals that are beneficial owners of a legal entity, control should be identified independently of ownership interest. Control can generally be exercised by any means, including legal and non-legal means. Those means might be taken into account for assessing whether control via other means is exercised, depending on the specific situation of each legal entity.

(111) Indirect ownership or control might be determined by multiple links in a chain or by multiple individual or interlinked chains. A link in a chain could be any natural or legal person or a legal arrangement. The relationships between the links might consist of ownership interest or voting rights or other means of control. In such cases, where ownership interest and control coexist in the ownership structure, specific and detailed rules on the identification of the beneficial ownership are needed to support a harmonised approach to the identification of beneficial owners.

(112) In order to ensure effective transparency, the widest possible range of legal entities and legal arrangements created or set up in the territory of Member States should be covered by beneficial ownership rules. That includes corporate entities, which are characterised by the possibility to hold ownership interest in them, as well as other legal entities and legal arrangements similar to express trusts. Due to differences in the legal systems of Member States, those broad categories encompass a variety of different organisational structures. Member States should notify to the Commission a list of the types of legal entities where the beneficial owners are identified in line with the rules for the identification of beneficial owners for both corporate and other legal entities.

(113) The specific nature of certain legal entities, such as associations, trade unions, political parties or churches, does not result in a meaningful identification of beneficial owners based on ownership interests or membership. In those cases, however, it can be the case that the senior managing officials exercise control over the legal entity by other means. In those cases, such officials should be reported as the beneficial owners.

(114) To ensure the consistent identification of beneficial owners of express trusts and similar legal entities, such as foundations, or similar legal arrangements, it is necessary to lay down harmonised beneficial ownership rules. Member States should be required to notify to the Commission a list of the types of legal entities and legal arrangements similar to express trusts where the beneficial owners are identified according to the identification of beneficial owners for express trusts and similar legal entities or arrangements. The Commission should be able to adopt, by means of an implementing act, a list of legal arrangements and legal entities governed by the law of Member States, which have a structure or function similar to express trusts.

(115) Discretionary trusts allow their trustees discretion on the allocation of the trust assets or benefits derived from them. As such, no beneficiaries or class of beneficiaries is determined from the outset, but rather a pool of persons from among which the trustees can choose the beneficiaries, or persons who will become beneficiaries should the trustees not exercise their discretion. As recognised by the recent revision of FATF standards regarding legal arrangements, such discretion can be misused and allow for the obfuscation of beneficial owners if a minimum level of transparency is not imposed for discretionary trusts, as transparency on beneficiaries would only be achieved upon the exercise of the trustees’ discretion. Therefore, in order to ensure an adequate and consistent transparency for all types of legal arrangements, it is important that, in the case of discretionary trusts, information is also collected on the objects of a trustee’s power and on the default takers who would receive the assets or benefits if the trustees fail to exercise their discretion. There are situations where objects of a power or default takers might not be identified individually, but as a class. In those cases, information on the class should be collected, as well as information on the individual persons who are selected from the class.

(116) The characteristics of express trusts and similar legal arrangements in Member States vary. In order to ensure a harmonised approach, it is appropriate to set out common principles for the identification of such arrangements. Express trusts are trusts set up at the initiative of the settlor. Trusts set up by law or that do not result from the explicit intent of the settlor to set them up should be excluded from the scope of this Regulation. Express trusts are usually set up in the form of a document such as a written deed or written instrument of trust, and usually fulfil a business or personal need. Legal arrangements similar to express trusts are arrangements without legal personality which are similar in structure or functions. The determining factor is not the designation of the type of legal arrangement, but the fulfilment of the basic features of the definition of an express trust, namely the settlor’s intention to place the assets under the administration and control of a certain person for specified purpose, usually of a business or personal nature, such as the benefit of the beneficiaries. To ensure the consistent identification of the beneficial owners of legal arrangements similar to express trusts, Member States should notify to the Commission a list of the types of legal arrangements similar to express trusts. Such notification should be accompanied by an assessment justifying the identification of certain legal arrangements as similar to express trusts as well as explaining why other legal arrangements have been considered to be dissimilar in structure or function from express trusts. In performing such assessment, Member States should take into consideration all legal arrangements that are governed under their law.

(117) In relation to some types of legal entities, such as foundations, express trusts and similar legal arrangements, it is not possible to identify individual beneficiaries because they have yet to be determined. In such cases, beneficial ownership information should include instead a description of the class of beneficiaries and its characteristics. As soon as beneficiaries within the class are designated, they will be beneficial owners. Furthermore, there are specific types of legal persons and legal arrangements where beneficiaries exist, but where their identification is not proportionate in respect of the money laundering and terrorist financing risks associated with those legal persons or legal arrangements. That is the case in relation to regulated products such as pension schemes within the scope of Directive (EU) 2016/2341 of the European Parliament and of the Council (26), and it could be the case, for example, in relation to employee financial ownership or participation schemes, or legal entities or legal arrangements with a non-profit or charitable purpose, provided the risks associated with such legal persons and legal arrangements are low. In those cases, an identification of the class of beneficiaries should be sufficient.

(118) Pension schemes regulated by Directive (EU) 2016/2341 are regulated products which are subject to stringent supervisory standards and present low risks of money laundering and terrorist financing. Where such pension schemes are set up in the form of a legal arrangement, its beneficiaries are employees and workers who rely on those products, linked to their employment contracts, for the management of their retirement benefits. Due the specific nature of the retirement benefit, which carries a low risk of money laundering and terrorist financing, it would not be proportionate to require the identification of each of those beneficiaries, and the identification of the class and its characteristic should be sufficient to fulfil transparency obligations.

(119) To ensure the consistent identification of beneficial owners of collective investment undertakings, it is necessary to lay down harmonised beneficial ownership rules. Regardless of whether the collective investment undertakings exist in the Member State in the form of a legal entity with legal personality, as a legal arrangement without legal personality, or in any other form, the approach to the identification of the beneficial owner should be consistent with their purpose and function.

(120) A consistent approach to the beneficial ownership transparency regime also requires ensuring that the same information is collected on beneficial owners across the internal market. It is appropriate to introduce precise requirements concerning the information that should be collected in each case. That information includes a minimum set of personal data regarding the beneficial owner, information on the nature and extent of the beneficial interest held in the legal entity or legal arrangement, and information on the legal entity or legal arrangement, necessary to ensure the appropriate identification of the natural person who is the beneficial owner and the reasons why that natural person has been identified as the beneficial owner.

(121) An effective framework of beneficial ownership transparency requires information to be collected through various channels. Such a multi-pronged approach includes the information held by the legal entity or trustee of an express trust or persons holding an equivalent position in a similar legal arrangement themselves, the information obtained by obliged entities in the context of customer due diligence, and the information held in central registers. Cross-checking of information among those pillars contributes to ensuring that each pillar holds adequate, accurate and up-to-date information. To that end, and in order to avoid discrepancies caused by different approaches, it is important to identify those categories of data that should always be collected in order to ensure the beneficial ownership information is adequate. That includes basic information on the legal entity and legal arrangement, which is the precondition allowing the entity or arrangement itself to understand its structure, whether through ownership or through control.

(122) Where legal entities and legal arrangements are part of a complex structure, clarity on their ownership or control structure is critical in order to ascertain who their beneficial owners are. To that end, it is important that legal entities and legal arrangements clearly understand the relationships by which they are indirectly owned or controlled, including all intermediary steps between the beneficial owners and the legal entity or legal arrangement itself, whether those relationships are in the form of other legal entities and legal arrangements or of nominee relationships. Identification of the ownership and control structure allows identification of the ways by which ownership is established or control can be exercised over a legal entity and is therefore essential for a comprehensive understanding of the position of the beneficial owner. The beneficial owner information should therefore always include a description of the relationship structure.

(123) Underpinning an effective framework on beneficial ownership transparency is the knowledge by legal entities of the natural persons who are their beneficial owners. Thus, all legal entities in the Union should obtain and hold adequate, accurate and up-to-date beneficial ownership information. That information should be retained for 5 years and the identity of the person responsible for retaining the information should be reported to the central registers. That retention period is equivalent to the period for retention of information obtained through the application of AML/CFT requirements, such as customer due diligence measures. In order to ensure the possibility to cross-check and verify information, for instance through the mechanism of discrepancy reporting, it is justified to ensure that the relevant data retention periods are aligned.

(124) To ensure that beneficial ownership information is up-to-date, the legal entity should update such information immediately after any change and should periodically verify it, for example at the time of submission of the financial statements, or on the occasion of other repetitive interactions with public authorities. The deadline for updating the information should be reasonable in view of possible complex situations.

(125) Legal entities should take all necessary measures to identify their beneficial owners. There might however be cases where no natural person is identifiable who ultimately owns or exerts control over an entity. In such exceptional cases, provided that all means of identification are exhausted, it should be possible for senior managing officials to be reported instead of the beneficial owners when providing beneficial ownership information to obliged entities in the course of the customer due diligence process or when submitting the information to the central register. Although they are identified in those situations, the senior managing officials are not the beneficial owners. Legal entities should keep records of the actions taken in order to identify their beneficial owners, especially when they rely on this last resort measure, which should be duly justified and documented.

(126) Difficulties in obtaining the information should not be a valid reason to avoid the identification effort and resort to reporting the senior management instead. Therefore, legal entities should always be able to substantiate their doubts as to the veracity of the information collected. Such justification should be proportionate to the risk of the legal entity and the complexity of its ownership structure. In particular, the record of the actions taken should be promptly provided to competent authorities where required and, on a risk-sensitive basis, it should be possible for that record to include resolutions of the board of directors and minutes of their meetings, partnership agreements, trust deeds, informal arrangements determining powers equivalent to powers of attorney or other contractual agreements and documentation. In cases where the absence of beneficial owners is evident with respect to the specific form and structure of legal entity, the justification should be understood as a reference to that fact, namely that the legal entity does not have a beneficial owner due to its specific form and structure. Such absence of beneficial owners could arise, where, for example, there are no ownership interests in the legal entity or where the legal entity cannot be ultimately controlled by other means.

(127) In view of the purpose of determining beneficial ownership, which is to ensure effective transparency of legal entities, it is proportionate to exempt certain entities from the obligation to identify their beneficial owner. Such a regime can only be applied to entities for which the identification and registration of their beneficial owners is not useful and where the similar level of transparency is achieved by means other than beneficial ownership. In that respect, bodies governed by public law of the Member States should not be obliged to determine their beneficial owner. Directive 2004/109/EC of the European Parliament and of the Council (27) introduced strict transparency requirements for companies whose securities are admitted to trading on a regulated market. In certain circumstances, those transparency requirements can achieve an equivalent transparency regime to the beneficial ownership transparency rules set out in this Regulation. That is the case where control over the company is exercised through voting rights, and the ownership or control structure of the company only includes natural persons. In those circumstances, there is no need to apply beneficial ownership requirements to those listed companies. The exemption for legal entities from the obligation to determine their own beneficial owner and to register it should not affect the obligation of obliged entities to identify the beneficial owner of a customer when performing customer due diligence.

(128) There is a need to ensure a level playing field among the different types of legal forms and to avoid the misuse of express trusts and legal arrangements, which are often layered in complex structures to further obscure beneficial ownership. Trustees of any express trust administered in a Member State, or established or residing in a Member State should thus be responsible for obtaining and holding adequate, accurate and up-to-date beneficial ownership information regarding the express trust, and for disclosing their status and providing that information to obliged entities carrying out customer due diligence. Any other beneficial owner of the express trust should assist the trustee in obtaining such information.

(129) The nature of legal arrangements and the lack of publicity about their structures and purpose places a particular onus on the trustees, or persons in equivalent positions in similar legal arrangements, to obtain and hold all relevant information on the legal arrangement. Such information should enable an identification of the legal arrangement, the assets placed therein or administered through it, and any agent or service provider to the trust. In order to facilitate the activities of competent authorities in the prevention, detection and investigation of money laundering, its predicate offences and terrorist financing, it is important that trustees keep that information up-to-date and that they hold it for a sufficient amount of time after they cease their role as trustees or equivalent. The provision of a basic amount of information on the legal arrangement to obliged entities is also necessary to enable them to fully ascertain the purpose of the business relationship or occasional transaction involving the legal arrangement, adequately assess the associated risks, and implement commensurate measures to mitigate those risks.

(130) In view of the specific structure of certain legal arrangements, and the need to ensure sufficient transparency about their beneficial ownership, such legal arrangements similar to express trusts should be subject to equivalent beneficial ownership requirements as those that apply to express trusts.

(131) Nominee arrangements can allow the concealment of the identity of the beneficial owners, because a nominee might act as the director or shareholder of a legal entity while the nominator is not always disclosed. Those arrangements might obscure the beneficial ownership and control structure if beneficial owners do not wish to disclose their identity or role within them. There is thus a need to introduce transparency requirements in order to avoid such arrangements being misused and to prevent criminals from hiding behind persons acting on their behalf. The relationship between nominee and nominator is not determined by whether it has an effect on the public or third parties. Although nominee shareholders whose names appear in public or official records would formally have independent control over the company, it should be required to disclose whether they are acting on the instructions of someone else on the basis of a private agreement. Nominee shareholders and nominee directors of legal entities should maintain sufficient information on the identity of their nominator as well as of any beneficial owner of the nominator and disclose them as well as their status to the legal entities. The same information should also be reported by legal entities to obliged entities when customer due diligence measures are applied and to the central registers.

(132) The risks posed by foreign legal entities and foreign legal arrangements which are misused to channel proceeds of funds into the Union’s financial system need to be mitigated. Since beneficial ownership standards in place in third countries might not be sufficient to allow for the same level of transparency and timely availability of beneficial ownership information as in the Union, there is a need to ensure adequate means to identify the beneficial owners of foreign legal entities or foreign legal arrangements in specific circumstances. Therefore, legal entities created outside the Union and express trusts or similar legal arrangements administered outside the Union or whose trustees or persons holding an equivalent position reside or are established outside the Union should be required to disclose their beneficial owners where they operate in the Union by entering into a business relationship with a Union’s obliged entity, by acquiring real estate in the Union or certain high value goods from obliged entities located in the Union, or by being awarded a contract following a public procurement procedure for goods or services, or concessions. There might be variations in the risk exposure across Member States, including depending on the category or type of activities carried out by obliged entities and on the attractiveness for criminals of real estate properties in their territory. Therefore, where Member States identify cases of higher risk, they should be able to take additional mitigating measures to address those risks.

(133) The registration requirements for foreign legal entities and foreign legal arrangements should be proportionate to the risks associated with their operations in the Union. Given the open nature of the Union internal market, and the use made by foreign legal entities of the services offered by obliged entities established in the Union, many of which are associated with lower risks of money laundering, its predicate offences or terrorist financing, it is appropriate to limit the registration requirement to legal entities that belong to high-risk sectors or that operate in higher risk categories or that obtain services from obliged entities operating in sectors associated with higher risks. The private nature of legal arrangements, and the obstacles in accessing beneficial ownership information in the case of foreign legal arrangements, justify the application of a registration requirement irrespective of the level of risk associated with the obliged entity providing services to the legal arrangement, or, where relevant, with the sector in which the legal arrangement operates. Reference to the risk assessment at Union level under Article 7 of Directive (EU) 2024/1640 should be understood to refer to the risk assessment issued by the Commission pursuant to Article 6 of Directive (EU) 2015/849 until the first issuance of the report under Article 7 of Directive (EU) 2024/1640.

(134) In order to encourage compliance and ensure an effective beneficial ownership transparency, beneficial ownership requirements need to be enforced. To that end, Member States should apply penalties for breaches of those requirements. Those penalties should be effective, proportionate and dissuasive, and should not go beyond what is required to encourage compliance. Penalties introduced by Member States should have an equivalent deterrent effect across the Union on the breaches of beneficial ownership requirements. It should be possible for penalties to include, for example, fines for legal entities and on trustees or persons holding an equivalent position in a similar legal arrangement imposed for failure to hold accurate, adequate or up-to-date beneficial ownership information, the striking-off of legal entities that fail to comply with the obligation to hold beneficial ownership information or to submit beneficial ownership information within a given deadline, fines for beneficial owners and other persons who fail to cooperate with a legal entity or trustee of an express trust or person holding an equivalent position in a similar legal arrangement, fines for nominee shareholders and nominee directors who fail to comply with the obligation of disclosure, or private law consequences for undisclosed beneficial owners as prohibition of the payment of profits or prohibition of the exercise of voting rights.

(135) With a view to ensuring a consistent approach to the enforcement of beneficial ownership requirements across the internal market, the Commission should be empowered to adopt delegated acts to define the categories of breaches subject to penalties and the persons liable for such breaches, as well as indicators on the level of gravity and criteria to determine the level of penalties. Furthermore, in order to support the determination of that level, and consistent with the harmonisation goal of this Regulation, it should be possible for the Commission to adopt guidelines setting out the base amounts to apply to each category of breach.

(136) Suspicious transactions, including attempted transactions, and other information relevant to money laundering, its predicate offences and terrorist financing, should be reported to the FIU, which should serve as a single central national unit for receiving and analysing reported suspicions and for disseminating to the competent authorities the results of its analyses. All suspicious transactions, including attempted transactions, should be reported, regardless of the amount of the transaction, and the reference to suspicions should be interpreted as including suspicious transactions, activities, behaviour and patterns of transactions. Reported information could also include threshold-based information. In order to support obliged entities’ detection of suspicions, AMLA should issue guidance on indicators of suspicious activity or behaviour. Given the evolving risk environment, that guidance should be reviewed regularly, and should not prejudge the issuance by FIUs of guidance or indicators on money laundering and terrorist financing risks and methods identified at national level. The disclosure of information to the FIU in good faith by an obliged entity or by an employee or director of such an entity should not constitute a breach of any restriction on disclosure of information and should not involve the obliged entity or its directors or employees in liability of any kind.

(137) Obliged entities should establish comprehensive reporting regimes encompassing all suspicions, regardless of the value or perceived severity of the associated criminal activity. They should be aware of the expectations of FIUs and should, as far as possible, tailor their detection systems and analytical processes to the key risks affecting the Member State in which they are established and, where necessary, prioritise their analysis towards addressing those key risks.

(138) Transactions should be assessed on the basis of information known or which should be known to the obliged entity. That includes relevant information from agents, distributors and service providers. Where the underlying predicate offence is not known or apparent to the obliged entity, the role of identifying and reporting suspicious transactions is fulfilled more efficiently by focusing on detecting suspicions and submitting reports promptly. In those cases, the predicate offence need not be specified by the obliged entity when reporting a suspicious transaction to the FIU, if it is not known to them. Where that information is available, it should be included in the report. As gatekeepers of the Union’s financial system, obliged entities should also be able to submit a report where they know or suspect that funds have been or will be used to carry out criminal activities, such as the purchase of illicit goods, even if the information available to them does not indicate that the funds used originate from illicit sources.

(139) Differences in suspicious transaction reporting obligations between Member States could exacerbate the difficulties in AML/CFT compliance experienced by obliged entities that have a cross-border presence or operations. Moreover, the structure and content of the suspicious transaction reports have an impact on the FIU’s capacity to carry out analysis and on the nature of that analysis, and also affect the FIU’s abilities to cooperate and to exchange information. In order to facilitate obliged entities’ compliance with their reporting obligations and allow for a more effective functioning of the FIU’s analytical activities and cooperation, AMLA should develop draft implementing technical standards specifying a common template for the reporting of suspicious transactions to be used as a uniform basis throughout the Union.

(140) FIUs should be able to obtain swiftly from any obliged entity all the necessary information relating to their functions. Their unfettered and swift access to information is essential to ensure that flows of money can be properly traced and illicit networks and flows detected at an early stage. The need for FIUs to obtain additional information from obliged entities based on a suspicion of money laundering or financing of terrorism might be triggered by a prior suspicious transaction report reported to the FIU, but might also be triggered through other means such as the FIU’s own analysis, intelligence provided by competent authorities or information held by another FIU. FIUs should therefore be able, in the context of their functions, to obtain information from any obliged entity, even without a prior report being made. In particular, records of financial transactions and transfers carried out through a bank, payment or crypto-asset account are critical for the analytical work of FIUs. However, due to the lack of harmonisation, at present credit institutions and financial institutions provide FIUs with transaction records in different formats, which are not readily useable for analysis. Considering the cross-border nature of FIUs’ analytical activities, the disparity of formats and difficulties of processing transaction records hamper the exchange of information among FIUs and the development of cross-border financial analyses. AMLA should therefore develop draft implementing technical standards specifying a common template for the provision of transaction records by credit institutions and financial institutions to FIUs to be used as a uniform basis throughout the Union.

(141) Obliged entities should reply to a request for information by the FIU as soon as possible and, in any case, within 5 working days of receipt of the request or any other shorter or longer deadline imposed by the FIU. In justified and urgent cases, the obliged entity should reply to the FIU’s request within 24 hours. Those deadlines should apply to information requests that are based on sufficiently defined conditions. An FIU should also be able to obtain information from obliged entities upon request made by another FIU and to exchange the information with the requesting FIU. Requests to obliged entities vary in nature. For example, complex requests might necessitate more time and warrant an extended deadline for response. To that end, FIUs should be able to grant extended deadlines to obliged entities, provided that does not have a negative impact on the FIU’s analysis.

(142) For certain obliged entities, Member States should have the possibility to designate an appropriate self-regulatory body to be informed in the first instance instead of the FIU. In accordance with the case-law of the European Court of Human Rights, a system of first instance reporting to a self-regulatory body constitutes an important safeguard for upholding the protection of fundamental rights as concerns the reporting obligations applicable to lawyers. Member States should provide for the means and manner by which to achieve the protection of professional secrecy, confidentiality and privacy.

(143) Notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors should not be obliged to transmit to the FIU or to a self-regulatory body any information received from, or obtained in relation to, one of their clients in the course of ascertaining the legal position of that client, or in performing the task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, whether such information is received or obtained before, during or after such proceedings. However, such an exception should not apply where the legal professional, auditor, external accountant or tax advisor is taking part in money laundering or terrorist financing, the legal advice is provided for the purposes of money laundering or terrorist financing, or where the legal professional, auditor, external accountant or tax advisor knows that the client is seeking legal advice for the purposes of money laundering or terrorist financing. Such knowledge and purpose can be inferred from objective, factual circumstances. Legal advice sought in relation to ongoing judicial proceedings should not be deemed to constitute legal advice for the purposes of money laundering of terrorist financing. In line with the risk-based approach, Member States should be able to identify additional situations where, having regard to the high risk of money laundering, its predicate offences or terrorist financing associated with certain types of transactions, the exemption from the reporting requirement does not apply. When identifying such additional situations, Member States are to ensure compliance in particular with Articles 7 and 47 of the Charter.

(144) Obliged entities should exceptionally be able to carry out suspicious transactions before informing the FIU where refraining from doing so is impossible or likely to frustrate efforts to pursue the beneficiaries of a suspected money laundering or terrorist financing operation. However, that exception should not be invoked in relation to transactions concerned by any international obligations accepted by the Member State of the FIU to freeze without delay funds or other assets of terrorists, terrorist organisations or those who finance terrorism, in accordance with the relevant UNSC resolutions.

(145) Confidentiality in relation to the reporting of suspicious transactions and to the provision of other relevant information to FIUs is essential in order to enable the competent authorities to freeze and seize assets potentially linked to money laundering, its predicate offences or terrorist financing. A suspicious transaction is not an indication of criminal activity. Disclosing that a suspicion has been reported might tarnish the reputation of the persons involved in the transaction and jeopardise the performance of analyses and investigations. Therefore, obliged entities and their directors and employees, or persons in comparable positions, including agents and distributors, should not inform the customer concerned or a third party that information is being, will be or has been submitted to the FIU, whether directly or through the self-regulatory body, or that a money laundering or terrorist financing analysis is being, or might be, carried out. The prohibition of disclosure should not apply in specific circumstances concerning, for example, disclosures to competent authorities and self-regulatory bodies when performing supervisory functions, or disclosures for law enforcement purposes or where the disclosures take place between obliged entities that belong to the same group.

(146) Criminals move illicit proceeds through numerous intermediaries to avoid detection. Therefore it is important to allow obliged entities to exchange information not only between group members, but also in certain cases between credit institutions and financial institutions and other entities that operate within networks, with due regard to data protection rules. Outside of a partnership for information sharing, the disclosure permitted among certain categories of obliged entities in cases involving the same transaction should only take place with regard to the specific transaction that is carried out between or facilitated by those obliged entities, and not with regard to connected previous or subsequent transactions.

(147) The exchange of information among obliged entities and, where applicable, competent authorities, might increase the possibilities for detecting illicit financial flows concerning money laundering, the financing of terrorism and proceeds of crime. For that reason, obliged entities and competent authorities should be able to exchange information in the framework of an information sharing partnership where they deem such sharing to be necessary for compliance with their AML/CFT obligations and tasks. Information sharing should be subject to robust safeguards relating to confidentiality, data protection, use of information and criminal procedure. Obliged entities should not rely solely on information received through the exchange of information to draw conclusions on the money laundering and terrorist financing risk of the customer or transaction or to take decisions regarding the establishment or termination of a business relationship or the carrying out of a transaction. As recognised in Directive 2014/92/EU, the smooth functioning of the internal market and the development of a modern, socially inclusive economy increasingly depends on the universal provision of payment services. Therefore, access to basic financial services should not be denied on the basis of information exchanged among obliged entities or between obliged entities and competent authorities or AMLA.

(148) Compliance with the requirements of this Regulation is subject to checks by supervisors. Where obliged entities exchange information in the framework of a partnership for information sharing, those checks should also include compliance with the conditions laid down in this Regulation for those exchanges of information. While supervisory checks should be risk-based, they should be performed in any event prior to the commencement of the activities of the partnership for information sharing. Partnerships for information sharing that involve the processing of personal data might result in a high risk to the rights and freedoms of natural persons. Therefore, a data protection impact assessment pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (28) should be carried out prior to the start of the activities of the partnership. In the context of supervisory checks, supervisors should consult, where relevant, data protection authorities, which alone are competent for assessing the data protection impact assessment. The data protection provisions and all requirements concerning the confidentiality of information on suspicious transactions contained in this Regulation apply to information shared in the framework of a partnership. Consistent with Regulation (EU) 2016/679, Member States should be able to maintain or introduce more specific provisions to adapt the application of that Regulation to provide more specific requirements in relation to the processing of personal data exchanged in the framework of a partnership for information sharing.

(149) While partnerships for information sharing enable the exchange of operational information and personal data under strict safeguards, those exchanges should not replace the requirements under this Regulation to report any suspicion to the competent FIU. Therefore, when obliged entities identify suspicious activities on the basis of information obtained in the context of a partnership for information sharing, they should report that suspicion to the FIU in the Member State where they are established. Information that indicates suspicious activity is subject to stricter rules that prohibit its disclosure and should only be shared where necessary for the purposes of preventing and combating money laundering, its predicate offences and terrorist financing and subject to safeguards protecting fundamental rights, the confidentiality of FIU work and the integrity of law enforcement investigations.

(150) Regulation (EU) 2016/679 applies to the processing of personal data for the purposes of this Regulation. The fight against money laundering and terrorist financing is recognised as an important public interest ground by all Member States. Obliged entities should pay particular attention to the principles requiring that the personal data processed in the course of compliance with their AML/CFT obligations be accurate, reliable and up-to-date. For the purposes of complying with this Regulation, obliged entities should be able to adopt processes that enable automated individual decision-making, including profiling, as set out under Article 22 of Regulation (EU) 2016/679. When doing so, the requirements set out in this Regulation to safeguard the rights of persons subject to such processes should apply in addition to any other relevant requirements set out in Union law concerning the protection of personal data.

(151) It is essential that the alignment of the AML/CFT framework with the revised FATF Recommendations is carried out in full compliance with Union law, in particular as regards Union data protection law and the protection of fundamental rights as enshrined in the Charter. Certain aspects of the implementation of the AML/CFT framework involve the collection, analysis, storage and sharing of data. Such processing of personal data should be permitted, while fully respecting fundamental rights, only for the purposes laid down in this Regulation, and for carrying out customer due diligence, ongoing monitoring, analysis and reporting of suspicious transactions, identification of the beneficial owner of a legal person or legal arrangement, identification of a politically exposed person and sharing of information by credit institutions and financial institutions and other obliged entities. The collection and subsequent processing of personal data by obliged entities should be limited to what is necessary for the purpose of complying with AML/CFT requirements and personal data should not be further processed in a way that is incompatible with that purpose. In particular, further processing of personal data for commercial purposes should be strictly prohibited.

(152) The processing of certain categories of sensitive data as defined under Article 9 of Regulation (EU) 2016/679 could give rise to risks to the fundamental rights and freedoms of the subjects of those data. To minimise the risks that the processing of such data by obliged entities results in discriminatory or biased outcomes that adversely impact the customer, such as the termination or refusal to enter into a business relationship, obliged entities should not take decisions solely on the basis of information in their possession concerning special categories of personal data within the meaning of Regulation (EU) 2016/679 where that information bears no relevance to the money laundering and terrorist financing risks posed by a transaction or relationship. Similarly, in order to ensure that the intensity of customer due diligence is based on a holistic understanding of the risks associated with the customer, obliged entities should not base the application of a higher or lower level of customer due diligence measures solely on the basis of sensitive data that they possess on the customer.

(153) The revised FATF Recommendations demonstrate that, in order to be able to cooperate fully and comply swiftly with information requests from competent authorities for the purposes of the prevention, detection or investigation of money laundering and terrorist financing, obliged entities should maintain, for at least 5 years, the necessary information obtained through customer due diligence measures and the records on transactions. In order to avoid different approaches and in order to fulfil the requirements relating to the protection of personal data and legal certainty, that retention period should be fixed at 5 years after the end of a business relationship or an occasional transaction. There might be situations where the functions of competent authorities cannot be effectively carried out if the relevant information held by obliged entities is deleted pursuant to the lapse of the retention period. In such cases, competent authorities should be able to request obliged entities to retain information on a case-by-case basis for a longer period, which should not exceed 5 years.

(154) Where the notion of competent authorities refers to investigating and prosecuting authorities, it should be interpreted as including the European Public Prosecutor’s Office (EPPO) with regard to the Member States that participate in the enhanced cooperation on the establishment of the EPPO.

(155) Disseminations by FIUs play a crucial role in detecting possible criminal activities under the competence of the EPPO or the European Anti-Fraud Office (OLAF), or in relation to which Europol and Eurojust are able to provide operational support at an early stage in accordance with their respective mandates, and to support prompt and effective investigations and prosecutions. Information shared with the EPPO and OLAF by FIUs should include grounds for the suspicion that a crime under the EPPO’s and OLAF’s respective competencies might be or has been perpetrated, and be accompanied by all relevant information that the FIU holds and which can support action, including relevant financial and administrative information. Where the EPPO and OLAF request information from FIUs, it is equally important that FIUs are able to share all the information they hold in relation to the case. In accordance with the applicable provisions in their founding legal instruments, the EPPO and OLAF should inform FIUs about the steps taken in relation to the information that was disseminated and any relevant outcomes.

(156) For the purpose of ensuring the appropriate and efficient administration of justice during the period between the entry into force and application of this Regulation, and in order to allow for its smooth interaction with national procedural law, information and documents pertinent to ongoing legal proceedings for the purpose of the prevention, detection or investigation of possible money laundering or terrorist financing, where those proceedings are pending in the Member States on the date of entry into force of this Regulation, should be retained for a period of 5 years after that date, and it should be possible to extend that period for a further 5 years.

(157) The rights of access to data by the data subject are applicable to the personal data processed for the purpose of this Regulation. However, access by the data subject to any information related to a suspicious transaction report would seriously undermine the effectiveness of the fight against money laundering and terrorist financing. Exceptions to and restrictions of that right in accordance with Article 23 of Regulation (EU) 2016/679 might therefore be justified. The data subject has the right to request that an authority referred to in Article 51 of Regulation (EU) 2016/679 check the lawfulness of the processing and has the right to seek a judicial remedy referred to in Article 79 of that Regulation. That authority is also able to act on an ex officio basis where provided for under Regulation (EU) 2016/679. Without prejudice to the restrictions to the right to access, the supervisory authority should be able to inform the data subject that all necessary verifications by the supervisory authority have taken place, and of the result as regards the lawfulness of the processing in question.

(158) Obliged entities might resort to the services of other private operators. However, the AML/CFT framework should apply to obliged entities only, and obliged entities should retain full responsibility for compliance with AML/CFT requirements. In order to ensure legal certainty and to avoid that some services are inadvertently brought into the scope of this Regulation, it is necessary to clarify that persons that merely convert paper documents into electronic data and are acting under a contract with an obliged entity, and persons that provide credit institutions or financial institutions solely with messaging or other support systems for transmitting funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 or with clearing and settlement systems, do not fall within the scope of this Regulation.

(159) Obliged entities should obtain and hold adequate and accurate information on the beneficial ownership and control of legal persons. As bearer shares accord ownership to the person who possesses the bearer share certificate, they allow the beneficial owner to remain anonymous. To ensure that such shares are not misused for money laundering or terrorist financing purposes, companies — other than those with listed securities on a regulated market or whose shares are issued as intermediated securities — should convert all existing bearer shares into registered shares, immobilise them, or deposit them with a financial institution. In addition, bearer share warrants should only be permitted in intermediated form.

(160) The anonymity of crypto-assets exposes them to risks of misuse for criminal purposes. Anonymous crypto-asset accounts, as well as other anonymising instruments, do not allow the traceability of crypto-asset transfers, and make it difficult to identify linked transactions that might raise suspicion or to apply an adequate level of customer due diligence. In order to ensure effective application of AML/CFT requirements to crypto-assets, it is necessary to prohibit the provision and the custody of anonymous crypto-asset accounts or accounts allowing for the anonymisation or the increased obfuscation of transactions by crypto-asset service providers, including through anonymity-enhancing coins. That prohibition does not apply to providers of hardware and software or providers of self-hosted wallets insofar as they do not possess access to or control over those crypto-asset wallets.

(161) The use of large cash payments is highly vulnerable to money laundering and terrorist financing, and that vulnerability has not been sufficiently mitigated by the requirement for persons trading in goods to be subject to anti-money laundering rules when making or receiving cash payments of EUR 10 000 or more. At the same time, differences in approaches among Member States have undermined the level playing field within the internal market to the detriment of businesses located in Member States with stricter controls. It is therefore necessary to introduce a Union-wide limit to large cash payments of EUR 10 000. Member States should be able to adopt lower thresholds and further stricter provisions to the extent that they pursue legitimate objectives in the public interest. Given that the AML/CFT framework is based on the regulation of the business economy, the limit should not apply to payments between natural persons who are not acting in a professional capacity. In addition, in order to ensure that the Union-wide limit does not unintentionally create barriers for persons who do not use or do not have access to banking services to make payments, or for business to deposit the income from their activities in their accounts, payments or deposits made at the premises of credit institutions, payment institutions or electronic money institutions should also be exempted from the application of the limit.

(162) Cash payments or deposits made at the premises of credit institutions, payment service providers and electronic money providers that exceed the threshold for large cash payments should not, by default, be considered an indicator for suspicion of money laundering, its predicate offences or terrorist financing. The reporting of such transactions enables the FIU to assess and identify patterns concerning the movement of cash and, while such information contributes to the FIU’s operational or strategic analyses, the nature of threshold-based disclosures makes them distinct from suspicious transaction reports. To that effect, threshold-based disclosures do not replace the requirement to report suspicious transactions or to apply enhanced due diligence measures in cases of higher risk. It should be possible for FIUs to require the reports to be made within a specific deadline, which could include the periodic submission on an aggregated basis.

(163) There might be cases where reasons of force majeure, such as those caused by natural catastrophes, result in a widespread loss of access to payment mechanisms other than cash. In such cases, Member States should be able to suspend the application of the limit on large cash payments. Such a suspension is an extraordinary measure and should only be applied where necessary as a response to exceptional, duly justified, situations. An impossibility to access financial services does not constitute a valid ground for the suspension of the limit where it is attributable to a Member State’s failure to guarantee that consumers have access to financial infrastructure across the entirety of its territory.

(164) The Commission should assess the costs, benefits and impacts of adjusting the limit for large cash payments at Union level with a view to levelling further the playing field for businesses and reducing opportunities for criminals to use cash for money laundering. That assessment should consider in particular the most appropriate level for a harmonised limit to cash payments at Union level considering the current existing limits to cash payments in place in a large number of Member States, the enforceability of such a limit at Union level and the effects of such a limit on the legal tender status of the euro.

(165) The Commission should also assess the costs, benefits and impacts of lowering the 25 % threshold for the identification of beneficial owners where control is exercised through ownership interest. That assessment should consider in particular the lessons learned from Member States or third countries having introduced lower thresholds.

(166) Risks associated with high-value goods might also extend to other goods that are highly portable, such as garments and clothing accessories. The Commission should therefore assess the need to extend the scope of obliged entities to include persons trading in such high-value goods. In addition, given that this Regulation introduces for the first time at Union level mandatory threshold-based disclosures in relation to certain high-value goods, the Commission should assess, based on the experience gathered in relation to implementation of this Regulation, the need to extend the scope of goods subject to threshold-based disclosures and to harmonise the format for such disclosures in light of the use of threshold-based disclosures made by FIUs. Finally, given the risks associated with high-value goods in free trade zones, the Commission should assess the need to expand the scope of information to be reported by operators trading and storing high-value goods in such free trade zones.

(167) In order to ensure consistent application of AML/CFT requirements, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission in respect of identifying high-risk third countries, third countries with compliance weaknesses and third countries posing a specific and serious threat to the Union’s financial system as well as countermeasures or specific enhanced due diligence measures mitigating risks stemming from such third countries; identifying additional cases of higher risk affecting Union and associated enhanced due diligence measures; identifying common additional categories of prominent public functions; identifying the categories of corporate entities associated with higher risks and the associated lower thresholds for the purpose of identifying beneficial ownership through ownership interest; defining the categories of breaches of beneficial ownership transparency requirements that are subject to penalties and the persons liable for them, the indicators to classify the level of gravity of those breaches and the criteria to be taken into account when setting the level of penalties. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (29). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

(168) The Commission should be empowered to adopt the regulatory technical standards developed by AMLA specifying the minimum requirements of group-wide policies, procedures and controls, including minimum standards for information sharing, the criteria for identifying the parent undertaking and the conditions under which structures which share common ownership, management or compliance controls are required to apply group-wide policies, procedures and controls; specifying the type of additional measures, including the minimum action to be taken by groups where the law of third countries do not permit the implementation of group-wide policies, procedures and controls and additional supervisory actions; specifying the obliged entities, sectors and transactions associated with higher risk and carrying out low value occasional transactions, the related values, the criteria for identifying occasional transactions and business relationship and the criteria to identify linked transaction for the purpose of performance of customer due diligence; and specifying the information necessary for the performance of customer due diligence. The Commission should adopt those regulatory technical standards by means of delegated acts pursuant to Article 290 TFEU and in accordance with Article 49 of Regulation (EU) 2024/1620.

(169) In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission in order to set out the methodology for the identification of third countries posing a specific and serious threat to the Union’s financial system; set out the format for the establishment and communication of the Member States’ lists of prominent public functions; and identify types of legal entities and types of legal arrangements similar to express trusts governed by the law of Member States. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council (30). Implementing powers should also be conferred on the Commission in order to decide on putting an end to specific additional national countermeasures.

(170) The Commission should be empowered to adopt implementing technical standards developed by AMLA specifying the format to be used for the reporting of suspicions and for the provision of transaction records, and the format to be used by FIUs for reporting information to the EPPO. The Commission should adopt those implementing technical standards by means of implementing acts pursuant to Article 291 TFEU and in accordance with Article 53 of Regulation (EU) 2024/1620.

(171) This Regulation respects the fundamental rights and observes the principles recognised by the Charter, in particular the right to respect for private and family life, the right to the protection of personal data and the freedom to conduct a business.

(172) In accordance with Article 21 of the Charter, which prohibits discrimination based on any grounds, obliged entities should perform risk assessments in the context of customer due diligence without discrimination.

(173) When drawing up a report evaluating the implementation of this Regulation, the Commission should give due consideration to the respect of the fundamental rights and principles recognised by the Charter.

(174) Since the objective of this Regulation, namely to prevent the use of the Union’s financial system for the purposes of money laundering and terrorist financing, cannot be sufficiently achieved by the Member States and can rather, by reason of the scale or effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 TEU. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.

(175) The European Data Protection Supervisor has been consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 and delivered an opinion on 22 September 2021 (31),

HAVE ADOPTED THIS REGULATION:

CHAPTER I

GENERAL PROVISIONS

SECTION 1

Subject matter and definitions

Article 1

Subject matter

This Regulation lays down rules concerning:

(a) the measures to be applied by obliged entities to prevent money laundering and terrorist financing;

(b) beneficial ownership transparency requirements for legal entities, express trusts and similar legal arrangements;

(c) measures to limit the misuse of anonymous instruments.

Article 2

Definitions

1.   For the purposes of this Regulation, the following definitions apply:

(1) ‘money laundering’ means the conduct set out in Article 3, paragraphs 1 and 5, of Directive (EU) 2018/1673 including aiding and abetting, inciting and attempting to commit that conduct, whether the activities which generated the property to be laundered were carried out on the territory of a Member State or on that of a third country; knowledge, intent or purpose required as an element of that conduct may be inferred from objective factual circumstances;

(2) ‘terrorist financing’ means the conduct set out in Article 11 of Directive (EU) 2017/541 including aiding and abetting, inciting and attempting to commit that conduct, whether carried out on the territory of a Member State or on that of a third country; knowledge, intent or purpose required as an element of that conduct may be inferred from objective factual circumstances;

(3) ‘criminal activity’ means criminal activity as defined in Article 2, point (1), of Directive (EU) 2018/1673, as well as fraud affecting the Union’s financial interests as defined in Article 3(2) of Directive (EU) 2017/1371, passive and active corruption as defined in Article 4 (2) and misappropriation as defined in Article 4(3), second subparagraph, of that Directive;

(4) ‘funds’ or ‘property’ means property as defined in Article 2, point (2), of Directive (EU) 2018/1673;

(5) ‘credit institution’ means:; (a) a credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013;; (b) a branch of a credit institution, as defined in Article 4(1), point (17), of Regulation (EU) No 575/2013, when located in the Union, whether its head office is located in a Member State or in a third country;

(6) ‘financial institution’ means:; (a) an undertaking other than a credit institution or an investment firm, which carries out one or more of the activities listed in points (2) to (12), (14) and (15) of Annex I to Directive 2013/36/EU of the European Parliament and of the Council (32), including the activities of currency exchange offices (bureaux de change), but excluding the activities referred to in point (8) of Annex I to Directive (EU) 2015/2366, or an undertaking the principal activity of which is to acquire holdings, including a financial holding company, a mixed financial holding company and a financial mixed activity holding company;; (b) an insurance undertaking as defined in Article 13, point (1), of Directive 2009/138/EC of the European Parliament and of the Council (33), insofar as it carries out life or other investment-related assurance activities covered by that Directive, including insurance holding companies and mixed-activity insurance holding companies as defined, respectively, in Article 212(1), points (f) and (g), of Directive 2009/138/EC;; (c) an insurance intermediary as defined in Article 2(1), point (3), of Directive (EU) 2016/97 where it acts with respect to life insurance and other investment-related insurance services, with the exception of an insurance intermediary that does not collect premiums or amounts intended for the customer and which acts under the responsibility of one or more insurance undertakings or intermediaries for the products which concern them respectively;; (d) an investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU of the European Parliament and of the Council (34);; (e) a collective investment undertaking, in particular:; (i) an undertaking for collective investment in transferable securities (UCITS) as defined in Article 1(2) of Directive 2009/65/EC and its management company as defined in Article 2(1), point (b), of that Directive or an investment company authorised in accordance with that Directive and which has not designated a management company, that makes available for purchase units of UCITS in the Union;; (ii) an alternative investment fund as defined in Article 4(1), point (a), of Directive 2011/61/EU and its alternative investment fund manager as defined in Article 4(1), point (b), of that Directive that fall within the scope set out in Article 2 of that Directive;; (f) a central securities depository as defined in Article 2(1), point (1), of Regulation (EU) No 909/2014 of the European Parliament and of the Council (35);; (g) a creditor as defined in Article 4, point (2), of Directive 2014/17/EU of the European Parliament and of the Council (36) and in Article 3, point (b), of Directive 2008/48/EC of the European Parliament and of the Council (37);; (h) a credit intermediary as defined in Article 4, point (5), of Directive 2014/17/EU and in Article 3, point (f), of Directive 2008/48/EC, when holding the funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 in connection with the credit agreement, with the exception of the credit intermediary carrying out activities under the responsibility of one or more creditors or credit intermediaries;; (i) a crypto-asset service provider;; (j) a branch of a financial institution referred to in points (a) to (i), when located in the Union, whether its head office is located in a Member State or in a third country;

(7) ‘crypto-asset’ means a crypto-asset as defined in Article 3(1), point (5), of Regulation (EU) 2023/1114 except when falling under the categories listed in Article 2(4) of that Regulation;

(8) ‘crypto-asset services’ means crypto-asset services as defined in Article 3(1), point (16), of Regulation (EU) 2023/1114, with the exception of providing advice on crypto-assets as referred to in Article 3(1), point (16)(h), of that Regulation;

(9) ‘crypto-asset service provider’ means a crypto-asset service provider as defined in Article 3(1), point (15), of Regulation (EU) 2023/1114 where performing one or more crypto-asset services;

(10) ‘financial mixed activity holding company’ means an undertaking, other than a financial holding company or a mixed financial holding company, which is not the subsidiary of another undertaking, the subsidiaries of which include at least one credit institution or financial institution;

(11) ‘trust or company service provider’ means any natural or legal person that, by way of its business, provides any of the following services to third parties:; (a) the formation of companies or other legal persons;; (b) acting as, or arranging for another person to act as, a director or secretary of a company, a partner of a partnership, or a similar position in relation to other legal persons;; (c) providing a registered office, business address, correspondence address or administrative address, as well as other related services for a company, a partnership or any other legal person or legal arrangement;; (d) acting as, or arranging for another person to act as, a trustee of an express trust or performing an equivalent function for a similar legal arrangement;; (e) acting as, or arranging for another person to act as, a nominee shareholder for another person;

(12) ‘gambling service’ means a service which involves wagering a stake with monetary value in games of chance, including those with an element of skill, such as lotteries, casino games, poker games and betting transactions that are provided at a physical location, or by any means at a distance, by electronic means or any other technology for facilitating communication, and at the individual request of a recipient of services;

(13) ‘non-financial mixed activity holding company’ means an undertaking, other than a financial holding company or a mixed financial holding company, which is not the subsidiary of another undertaking, the subsidiaries of which include at least one obliged entity as referred to in Article 3, point (3);

(14) ‘self-hosted address’ means a self-hosted address as defined in Article 3, point (20), of Regulation (EU) 2023/1113;

(15) ‘crowdfunding service provider’ means a crowdfunding service provider as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503;

(16) ‘crowdfunding intermediary’ means an undertaking other than a crowdfunding service provider the business of which is to match or facilitate the matching, through an internet-based information system open to the public or to a limited number of funders, of:; (a) project owners, which are any natural or legal person seeking funding for projects, consisting of one or a set of predefined operations aiming at a particular objective, including fundraising for a particular cause or event irrespective of whether those projects are proposed to the public or to a limited number of funders; and; (b) funders, which are any natural or legal person contributing to the funding of projects, through loans, with or without interest, or donations, including where such donations entitle the donor to a non-material benefit;

(17) ‘electronic money’ means electronic money as defined in Article 2, point (2), of Directive 2009/110/EC of the European Parliament and of the Council (38), but excluding monetary value as referred to in Article 1(4) and (5) of that Directive;

(18) ‘establishment’ means the actual pursuit by an obliged entity of an economic activity covered by Article 3 in a Member State or third country other than the country where its head office is located for an indefinite period and through a stable infrastructure, including:; (a) a branch or subsidiary;; (b) in the case of credit institutions and financial institutions, an infrastructure qualifying as an establishment under prudential regulation;

(19) ‘business relationship’ means a business, professional or commercial relationship connected with the professional activities of an obliged entity, which is set up between an obliged entity and a customer, including in the absence of a written contract and which is expected to have, at the time when the contact is established, or which subsequently acquires, an element of repetition or duration;

(20) ‘linked transactions’ means two or more transactions with either identical or similar origin, destination and purpose, or other relevant characteristics, over a specific period;

(21) ‘third country’ means any jurisdiction, independent state or autonomous territory that is not part of the Union and that has its own AML/CFT legislation or enforcement regime;

(22) ‘correspondent relationship’ means:; (a) the provision of banking services by one credit institution as the correspondent to another credit institution as the respondent, including providing a current or other liability account and related services, such as cash management, international transfers of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366, cheque clearing, payable-through accounts and foreign exchange services;; (b) the relationships between and among credit institutions and financial institutions including where similar services are provided by a correspondent institution to a respondent institution, and including relationships established for securities transactions or transfers of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366, transactions in crypto-assets or transfers of crypto-assets;

(23) ‘shell institution’ means:; (a) for credit institutions and financial institutions other than crypto-asset service providers: a credit institution or financial institution, or an institution that carries out activities equivalent to those carried out by credit institutions and financial institutions, created in a jurisdiction in which it has no physical presence, involving meaningful mind and management, and which is unaffiliated with a regulated financial group;; (b) for crypto-asset service providers: an entity whose name appears in the register established by the European Securities and Markets Authority pursuant to Article 110 of Regulation (EU) 2023/1114 or third country entity providing crypto-asset services without being licensed or registered nor subject to AML/CFT supervision there;

(24) ‘crypto-asset account’ means a crypto-asset account as defined in Article 3, point (19), of Regulation (EU) 2023/1113;

(25) ‘anonymity-enhancing coins’ means crypto-assets that have built-in features designed to make crypto-asset transfer information anonymous, either systematically or optionally;

(26) ‘virtual IBAN’ means an identifier causing payments to be redirected to a payment account identified by an IBAN different from that identifier;

(27) ‘Legal Entity Identifier’ means a unique alphanumeric reference code based on the ISO 17442 standard assigned to a legal entity;

(28) ‘beneficial owner’ means any natural person who ultimately owns or controls a legal entity or an express trust or similar legal arrangement;

(29) ‘express trust’ means a trust intentionally set up by the settlor, inter vivos or on death, usually in a form of written document, to place assets under the control of a trustee for the benefit of a beneficiary or for a specified purpose;

(30) ‘objects of a power’ means the natural or legal persons or class of natural or legal persons among whom trustees may select the beneficiaries in a discretionary trust;

(31) ‘default taker’ means the natural or legal persons or class of natural or legal persons who are the beneficiaries of a discretionary trust should the trustees fail to exercise their discretion;

(32) ‘legal arrangement’ means an express trust or an arrangement which has a similar structure or function to an express trust, including fiducie and certain types of Treuhand and fideicomiso;

(33) ‘basic information’ means:; (a) in relation to a legal entity:; (i) legal form and name of the legal entity;; (ii) instrument of constitution, and the statutes if they are contained in a separate instrument;; (iii) address of the registered or official office and, if different, the principal place of business, and the country of creation;; (iv) a list of legal representatives;; (v) where applicable, a list of shareholders or members, including information on the number of shares held by each shareholder and the categories of those shares and the nature of the associated voting rights;; (vi) where available, the registration number, the European Unique identifier, the tax identification number and the Legal Entity Identifier;; (vii) in the case of foundations, the assets held by the foundation to pursue its purposes;; (b) in relation to a legal arrangement:; (i) the name or unique identifier of the legal arrangement;; (ii) the trust deed or equivalent;; (iii) the purposes of the legal arrangement, if any;; (iv) the assets held in the legal arrangement or managed through it;; (v) the place of residence of the trustees of the express trust or persons holding equivalent positions in the similar legal arrangement, and, if different, the place from where the express trust or similar legal arrangement is administered;

(34) ‘politically exposed person’ means a natural person who is or has been entrusted with prominent public functions including:; (a) in a Member State:; (i) heads of State, heads of government, ministers and deputy or assistant ministers;; (ii) members of parliament or of similar legislative bodies;; (iii) members of the governing bodies of political parties that hold seats in national executive or legislative bodies, or in regional or local executive or legislative bodies representing constituencies of at least 50 000 inhabitants;; (iv) members of supreme courts, of constitutional courts or of other high-level judicial bodies, the decisions of which are not subject to further appeal, except in exceptional circumstances;; (v) members of courts of auditors or of the boards of central banks;; (vi) ambassadors, chargés d’affaires and high-ranking officers in the armed forces;; (vii) members of the administrative, management or supervisory bodies of enterprises controlled under any of the relationships listed in Article 22 of Directive 2013/34/EU either by the state, or, where those enterprises qualify as medium sized or large undertakings or medium sized or large groups, as defined in Article 3(3), (4), (6) and (7) of that Directive, by regional or local authorities;; (viii) heads of regional and local authorities, including groupings of municipalities and metropolitan regions, with at least 50 000 inhabitants;; (ix) other prominent public functions provided for by Member States;; (b) in an international organisation:; (i) the highest ranking officials, their deputies and members of the board or equivalent functions of an international organisation;; (ii) representatives to a Member State or to the Union;; (c) at Union level:; functions at the level of Union institutions and bodies that are equivalent to those listed in points (a) (i), (ii), (iv), (v) and (vi);; (d) in a third country:; functions that are equivalent to those listed in point (a);

(35) ‘family member’ means:; (a) a spouse, or a person in a registered partnership or civil union or in a similar arrangement;; (b) a child and a spouse of, or a person in a registered partnership or civil union or in a similar arrangement with, that child;; (c) a parent;; (d) for the functions referred to in point (34)(a)(i) and equivalent functions at Union level or in a third country, a sibling;

(36) ‘person known to be a close associate’ means:; (a) a natural person who is known to have joint beneficial ownership of legal entities or legal arrangements, or any other close business relations, with a politically exposed person;; (b) a natural person who has sole beneficial ownership of a legal entity or legal arrangement which is known to have been set up for the de facto benefit of a politically exposed person;

(37) ‘management body’ means an obliged entity’s body or bodies, which are appointed in accordance with national law, which are empowered to set the obliged entity’s strategy, objectives and overall direction, and which oversee and monitor management decision-making, and include the persons who effectively direct the business of the obliged entity; where no such body exists, the person who effectively directs the business of the obliged entity;

(38) ‘management body in its management function’ means the management body responsible for the day-to-day management of the obliged entity;

(39) ‘management body in its supervisory function’ means the management body acting in its role of overseeing and monitoring management decision-making;

(40) ‘senior management’ means the members of the management body in its management function, as well as officers and employees with sufficient knowledge of the obliged entity’s money laundering and terrorist financing risk exposure and sufficient seniority to take decisions affecting its risk exposure;

(41) ‘group’ means a group of undertakings which consists of a parent undertaking, its subsidiaries, as well as undertakings linked to each other by a relationship within the meaning of Article 22 of Directive 2013/34/EU;

(42) ‘parent undertaking’ means:; (a) for groups whose head office is located in the Union, an obliged entity that is a parent undertaking as defined in Article 2, point (9), of Directive 2013/34/EU that is not itself a subsidiary of another undertaking in the Union, provided that at least one subsidiary undertaking is an obliged entity;; (b) for groups whose head office is located outside of the Union, where at least two subsidiary undertakings are obliged entities established in the Union, an undertaking within that group established in the Union that:; (i) is an obliged entity;; (ii) is an undertaking that is not a subsidiary of another undertaking that is an obliged entity established in the Union;; (iii) has a sufficient prominence within the group and a sufficient understanding of the operations of the group that are subject to the requirements of this Regulation; and; (iv) is given the responsibility of implementing group-wide requirements under Chapter II, Section 2 of this Regulation;

(43) ‘cash’ means cash as defined in Article 2(1), point (a), of Regulation (EU) 2018/1672 of the European Parliament and of the Council (39);

(44) ‘competent authority’ means:; (a) a Financial Intelligence Unit (FIU);; (b) a supervisory authority;; (c) a public authority that has the function of investigating or prosecuting money laundering, its predicate offences or terrorist financing, or that has the function of tracing, seizing or freezing and confiscating criminal assets;; (d) a public authority with designated responsibilities for combating money laundering or terrorist financing;

(45) ‘supervisor’ means the body entrusted with responsibilities aimed at ensuring compliance by obliged entities with the requirements of this Regulation, including AMLA when performing the tasks entrusted to it in Article 5(2) of Regulation (EU) 2024/1620;

(46) ‘supervisory authority’ means a supervisor who is a public body, or the public authority overseeing self-regulatory bodies in their performance of supervisory functions pursuant to Article 37 of Directive (EU) 2024/1640, or AMLA when acting as a supervisor;

(47) ‘self-regulatory body’ means a body that represents members of a profession and has a role in regulating them, in performing certain supervisory or monitoring functions and in ensuring the enforcement of the rules relating to them;

(48) ‘funds or other assets’ means any assets, including, but not limited to, financial assets, economic resources, including oil and other natural resources, property of every kind, whether tangible or intangible, movable or immovable, however acquired, and legal documents or instruments in any form, including electronic or digital, evidencing title to, or interest in, such funds or other assets, including, but not limited to, bank credits, travellers cheques, bank cheques, money orders, shares, securities, bonds, drafts, or letters of credit, and any interest, dividends or other income on or value accruing from or generated by such funds or other assets, and any other assets which potentially may be used to obtain funds, goods or services;

(49) ‘targeted financial sanctions’ means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated persons and entities pursuant to Council Decisions adopted on the basis of Article 29 TEU and Council Regulations adopted on the basis of Article 215 TFEU;

(50) ‘UN financial sanctions’ means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated or listed persons and entities pursuant to:; (a) UNSC Resolution 1267 (1999) and its successor resolutions;; (b) UNSC Resolution 1373 (2001), including the determination that the relevant sanctions will be applied to the person or entity and the public communication of that determination;; (c) UN financial sanctions relating to proliferation financing;

(51) ‘UN financial sanctions relating to proliferation financing’ means both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated or listed persons and entities pursuant to:; (a) UNSC Resolution 1718 (2006) and any successor resolutions;; (b) UNSC Resolution 2231 (2015) and any successor resolutions;; (c) any other UNSC resolutions imposing asset freezing and prohibitions to make funds or other assets available in relation to the financing of proliferation of weapons of mass destruction;

(52) ‘professional football club’ means any legal person that is, owns or manages a football club that has been granted a licence and participates in the national football leagues in a Member State and whose players and staff are contractually engaged and are remunerated in exchange for their services;

(53) ‘football agent’ means a natural or legal person who, for a fee, provides intermediary services and represents football players or professional football clubs in negotiations with a view to concluding a contract for a football player or represents professional football clubs in negotiations with a view to concluding an agreement for the transfer of a football player;

(54) ‘high-value goods’ means goods listed in Annex IV;

(55) ‘precious metals and stones’ means metals and stones listed in Annex V;

(56) ‘cultural goods’ means goods listed in Annex I to Council Regulation (EC) No 116/2009 (40);

(57) ‘partnership for information sharing’ means a mechanism that enables the sharing and processing of information between obliged entities and, where applicable, competent authorities referred to in point 44(a), (b) and (c), for the purposes of preventing and combating money laundering, its predicate offences and terrorist financing, whether at national level or on a cross-border basis, and regardless of the form of that partnership.

2.   Prominent public functions as referred to in paragraph 1, point (34), shall not be understood as covering middle-ranking or more junior officials.

3.   Where justified by their administrative organisation and by risk, Member States may set lower thresholds for the designation of the following prominent public functions:

(a) members of governing bodies of political parties represented at regional or local level, as referred to in paragraph 1, point (34)(a)(iii);

(b) heads of regional and local authorities, as referred to in paragraph 1, point (34)(a)(viii).

Member States shall notify those lower thresholds to the Commission.

4.   In relation to paragraph 1, point (34)(a)(vii) of this Article, where justified by their administrative organisation and by risk, Member States may set lower thresholds for the identification of enterprises controlled by regional or local authorities than those defined in Article 3(3), (4), (6) and (7) of Directive 2013/34/EU.

Member States shall notify those lower thresholds to the Commission.

5.   Where justified by their social and cultural structures and by risk, Member States may apply a broader scope for the designation of siblings as family members of politically exposed persons, as referred to in paragraph 1, point (35)(d).

Member States shall notify that broader scope to the Commission.

SECTION 2

Scope

Article 3

Obliged entities

The following entities are to be considered obliged entities for the purposes of this Regulation:

(1) credit institutions;

(2) financial institutions;

(3) the following natural or legal persons acting in the exercise of their professional activities:; (a) auditors, external accountants and tax advisors, and any other natural or legal person including independent legal professionals such as lawyers, that undertakes to provide, directly or by means of other persons to which that other person is related, material aid, assistance or advice on tax matters as principal business or professional activity;; (b) notaries, lawyers and other independent legal professionals, where they participate, whether by acting on behalf of and for their client in any financial or real estate transaction, or by assisting in the planning or carrying out of transactions for their client concerning any of the following:; (i) buying and selling of real property or business entities;; (ii) managing of client money, securities or other assets, including crypto-assets;; (iii) opening or management of bank, savings, securities or crypto-assets accounts;; (iv) organisation of contributions necessary for the creation, operation or management of companies;; (v) creation, setting up, operation or management of trusts, companies, foundations, or similar structures;; (c) trust or company service providers;; (d) estate agents and other real estate professionals to the extent they act as intermediaries in real estate transactions, including in relation to the letting of immovable property for transactions for which the monthly rent amounts to at least EUR 10 000 or the equivalent in national currency, irrespective of the means of payment;; (e) persons trading, as a regular or principal professional activity, in precious metals and stones;; (f) persons trading, as a regular or principal professional activity, in high-value goods;; (g) providers of gambling services;; (h) crowdfunding service providers and crowdfunding intermediaries;; (i) persons trading or acting as intermediaries in the trade of cultural goods, including when this is carried out by art galleries and auction houses, where the value of the transaction or linked transactions amounts to at least EUR 10 000 or the equivalent in national currency;; (j) persons storing, trading or acting as intermediaries in the trade of cultural goods and high-value goods, when this is carried out within free zones and customs warehouses, where the value of the transaction or linked transactions amounts to at least EUR 10 000 or the equivalent in national currency;; (k) credit intermediaries for mortgage and consumer credits, other than credit institutions and financial institutions, with the exception of the credit intermediaries carrying out activities under the responsibility of one or more creditors or credit intermediaries;; (l) investment migration operators permitted to represent or offer intermediation services to third-country nationals seeking to obtain residence rights in a Member State in exchange for any kind of investment, including capital transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity to the public good and contributions to the state budget;; (m) non-financial mixed activity holding companies;; (n) football agents;; (o) professional football clubs in respect of the following transactions:; (i) transactions with an investor;; (ii) transactions with a sponsor;; (iii) transactions with football agents or other intermediaries;; (iv) transactions for the purpose of a football player’s transfer.

Article 4

Exemptions for certain providers of gambling services

1.   Member States may decide to exempt, in full or in part, providers of gambling services from the requirements set out in this Regulation on the basis of the proven low risk posed by the nature and, where appropriate, the scale of operations of such services.

The exemption referred to in the first subparagraph shall not apply to:

(a) casinos;

(b) providers of gambling services the principal activity of which is to provide online gambling services or sport betting services, other than:; (i) online gambling services operated by the State, whether through a public authority or an enterprise or body controlled by the State;; (ii) online gambling services the organisation, operation and administration of which is regulated by the State.

2.   For the purposes of paragraph 1, Member States shall carry out a risk assessment of gambling services assessing:

(a) money laundering and terrorist financing threats and vulnerabilities, and mitigating factors of the gambling services;

(b) the risks linked to the size of the transactions and payment methods used;

(c) the geographical area in which the gambling services are administered, including their cross border dimension and accessibility from other Member States or third countries.

When carrying out the risk assessments referred to in the first subparagraph of this paragraph, Member States shall take into account the findings of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive(EU) 2024/1640.

3.   Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Article 5

Exemptions for certain professional football clubs

1.   Member States may decide to exempt, in full or in part, professional football clubs that participate in the highest division of the national football league and that have a total annual turnover of less than EUR 5 000 000, or the equivalent in national currency, for each of the previous 2 calendar years from the requirements set out in this Regulation on the basis of the proven low risk posed by the nature and the scale of operation of such professional football clubs.

Member States may decide to exempt, in full or in part, professional football clubs that participate in a division lower than the highest division of the national football league from the requirements set out in this Regulation on the basis of proven low risk posed by the nature and the scale of operation of such professional football clubs.

2.   For the purposes of paragraph 1, Member States shall carry out a risk assessment of the professional football clubs assessing:

(a) money laundering and terrorist financing threats and vulnerabilities, and mitigating factors of the professional football clubs;

(b) the risks linked to the size and cross-border nature of the transactions.

When carrying out the risk assessments referred to in the first subparagraph of this paragraph, Member States shall take into account the findings of the risk assessments at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640.

3.   Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Article 6

Exemptions for certain financial activities

1.   With the exception of persons engaged in the activity of money remittance as defined in Article 4, point (22), of Directive (EU) 2015/2366, Member States may decide to exempt legal or natural persons that engage in a financial activity as listed in Annex I, points (2) to (12), (14) and (15), to Directive 2013/36/EU on an occasional or very limited basis where there is little risk of money laundering or terrorist financing from the requirements set out in this Regulation, provided that all of the following criteria are met:

(a) the financial activity is limited in absolute terms;

(b) the financial activity is limited on a transaction basis;

(c) the financial activity is not the main activity of such persons;

(d) the financial activity is ancillary and directly related to the main activity of such persons;

(e) the main activity of such persons is not an activity referred to in Article 3, point (3)(a) to (d) or (g) of this Regulation;

(f) the financial activity is provided only to the customers of the main activity of such persons and is not generally offered to the public.

2.   For the purposes of paragraph 1, point (a), Member States shall require that the total turnover of the financial activity does not exceed a threshold which shall be sufficiently low. That threshold shall be established at national level, depending on the type of financial activity.

3.   For the purposes of paragraph 1, point (b), Member States shall apply a maximum threshold per customer and per single transaction, whether the transaction is carried out in a single operation or through linked transactions. That maximum threshold shall be established at national level, depending on the type of financial activity. It shall be sufficiently low in order to ensure that the types of transactions in question are an impractical and inefficient method for money laundering or terrorist financing, and shall not exceed EUR 1 000 or the equivalent in national currency, irrespective of the means of payment.

4.   For the purposes of paragraph 1, point (c), Member States shall require that the turnover of the financial activity does not exceed 5 % of the total turnover of the natural or legal person concerned.

5.   In assessing the risk of money laundering or terrorist financing for the purposes of this Article, Member States shall pay particular attention to any financial activity which is considered to be particularly likely, by its nature, to be used or abused for the purposes of money laundering or terrorist financing.

6.   Member States shall establish risk-based monitoring activities or take other adequate measures to ensure that the exemptions granted pursuant to this Article are not abused.

Article 7

Prior notification of exemptions

1.   Member States shall notify the Commission of any exemption that they intend to grant in accordance with Articles 4, 5 and 6 without delay. The notification shall include a justification based on the relevant risk assessment carried out by the Member State to sustain the exemption.

2.   The Commission shall within 2 months of the notification referred to in paragraph 1 take one of the following actions:

(a) confirm that the exemption may be granted on the basis of the justification given by the Member State;

(b) by reasoned decision, declare that the exemption may not be granted.

For the purposes of the first subparagraph, the Commission may request additional information from the notifying Member State.

3.   Upon receipt of a confirmation by the Commission pursuant to paragraph 2, point (a), of this Article, Member States may adopt a decision granting the exemption. The decision shall state the reasons on which it is based. Member States shall review such decisions regularly, and in any case when they update their national risk assessment pursuant to Article 8 of Directive (EU) 2024/1640.

4.   By 10 October 2027, Member States shall notify to the Commission the exemptions granted pursuant to Article 2(2) and (3) of Directive (EU) 2015/849 in place on 10 July 2027.

5.   The Commission shall publish every year in the Official Journal of the European Union the list of exemptions granted pursuant to this Article and make that list publicly available on its website.

SECTION 3

Cross-border operations

Article 8

Notification of cross-border operations and application of national law

1.   Obliged entities wishing to carry out activities within the territory of another Member State for the first time shall notify the supervisors of their home Member State of the activities which they intend to carry out in that other Member State. That notification shall be submitted as soon as the obliged entity takes steps to carry out the activities, and, in the case of establishments at least 3 months prior to the commencement of those activities. Obliged entities shall immediately notify the supervisors of their home Member State upon commencement of those activities in that other Member State.

The first subparagraph shall not apply to obliged entities subject to specific notification procedures for the exercise of the freedom of establishment and of the freedom to provide services under other Union legal acts or to cases where the obliged entity is subject to specific authorisation requirements in order to operate in the territory of that other Member State.

2.   Any planned change to the information communicated under paragraph 1 shall be communicated by the obliged entity to the supervisor of the home Member State at least 1 month before making the change.

3.   Where this Regulation allows Member States to adopt additional rules applicable to obliged entities, obliged entities shall comply with the national rules of the Member State in which they are established.

4.   Where obliged entities operate establishments in several Member States, they shall ensure that each establishment applies the rules of the Member State in which it is located.

5.   Where obliged entities as referred to in Article 38(1) of Directive (EU) 2024/1640 operate, in other Member States than the one where they are established through agents, distributors, or through other types of infrastructure located in those other Member States under the freedom to provide services, they shall apply the rules of the Member States in which they provide services in relation to those activities, unless Article 38(2) of that Directive applies, in which case they shall apply the rules of the Member State where their head office is located.

6.   Where obliged entities are required to appoint a central contact point pursuant to Article 41 of Directive (EU) 2024/1640, they shall ensure that the central contact point is able to ensure compliance with applicable law on behalf of the obliged entity.

CHAPTER II

INTERNAL POLICIES, PROCEDURES AND CONTROLS OF OBLIGED ENTITIES

SECTION 1

Internal policies, procedures and controls, risk assessment and staff

Article 9

Scope of internal policies, procedures and controls

1.   Obliged entities shall have in place internal policies, procedures and controls in order to ensure compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor and in particular to:

(a) mitigate and manage effectively the risks of money laundering and terrorist financing identified at the level of the Union, the Member State and the obliged entity;

(b) in addition to the obligation to apply targeted financial sanctions, mitigate and manage the risks of non-implementation and evasion of targeted financial sanctions.

The policies, procedures and controls referred to in the first subparagraph shall be proportionate to the nature of the business, including its risks and complexity, and the size of the obliged entity and shall cover all the activities of the obliged entity that fall under the scope of this Regulation.

2.   The policies, procedures and controls referred to in paragraph 1 shall include:

(a) internal policies and procedures, including in particular:; (i) the carrying out and updating of the business-wide risk assessment;; (ii) the obliged entity’s risk management framework;; (iii) customer due diligence to implement Chapter III of this Regulation, including procedures to determine whether the customer, the beneficial owner, or the person on whose behalf or for the benefit of whom a transaction or activity is being conducted, is a politically exposed person or a family member or person known to be a close associate;; (iv) reporting of suspicious transactions;; (v) outsourcing and reliance on customer due diligence performed by other obliged entities;; (vi) record retention and policies in relation to the processing of personal data pursuant to Articles 76 and 77;; (vii) the monitoring and management of compliance with such internal policies and procedures in accordance with point (b) of this paragraph, the identification and management of deficiencies and the implementation of remedial actions;; (viii) the verification, proportionate to the risks associated with the tasks and functions to be performed, when recruiting and assigning staff to certain tasks and functions and when appointing agents and distributors, that those persons are of good repute;; (ix) the internal communication of the obliged entity’s internal policies, procedures and controls, including to its agents, distributors and service providers involved in the implementation of its AML/CFT policies;; (x) a policy on the training of employees and, where relevant, agents and distributors with regard to measures in place in the obliged entity to comply with the requirements of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor;

(b) internal controls and an independent audit function to test the internal policies and procedures referred to in point (a) of this paragraph and the controls in place in the obliged entity; in the absence of an independent audit function, obliged entities may have this test carried out by an external expert.

The internal policies, procedures and controls set out in the first subparagraph shall be recorded in writing. Internal policies shall be approved by the management body in its management function. Internal procedures and controls shall be approved at least at the level of the compliance manager.

3.   The obliged entities shall keep the internal policies, procedures and controls up-to-date, and enhance them where weaknesses are identified.

4.   By 10 July 2026, AMLA shall issue guidelines on the elements that obliged entities should take into account, based on the nature of their business, including its risks and complexity, and their size, when deciding on the extent of their internal policies, procedures and controls, in particular as regards the staff allocated to the compliance functions. Those guidelines shall also identify situations where, due to the nature and size of the obliged entity:

(i) internal controls are to be organised at the level of the commercial function, of the compliance function and of the audit function;

(ii) the independent audit function can be carried out by an external expert.

Article 10

Business-wide risk assessment

1.   Obliged entities shall take appropriate measures, proportionate to the nature of their business, including its risks and complexity, and their size, to identify and assess the risks of money laundering and terrorist financing to which they are exposed, as well as the risks of non-implementation and evasion of targeted financial sanctions, taking into account at least:

(a) the risk variables set out in Annex I and the risk factors set out in Annexes II and III;

(b) the findings of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640;

(c) the findings of the national risk assessments carried out by the Member States pursuant to Article 8 of Directive (EU) 2024/1640, as well as of any relevant sector-specific risk assessment carried out by the Member States;

(d) relevant information published by international standard setters in the AML/CFT area or, at the level of the Union, relevant publications by the Commission or by AMLA;

(e) information on money laundering and terrorist financing risks provided by competent authorities;

(f) information on the customer base.

Prior to the launch of new products, services or business practices, including the use of new delivery channels and new or developing technologies, in conjunction with new or pre-existing products and services or before starting to provide an existing service or product to a new customer segment or in a new geographical area, obliged entities shall identify and assess, in particular, the related money laundering and terrorist financing risks and take appropriate measures to manage and mitigate those risks.

2.   The business-wide risk assessment drawn up by the obliged entity pursuant to paragraph 1 shall be documented, kept up-to-date and regularly reviewed, including where any internal or external events significantly affect the money laundering and terrorist financing risks associated with the activities, products, transactions, delivery channels, customers or geographical zones of activities of the obliged entity. It shall be made available to supervisors upon request.

The business-wide risk assessment shall be drawn up by the compliance officer and approved by the management body in its management function and, where such body exists, communicated to the management body in its supervisory function.

3.   With the exception of credit institutions, financial institutions, crowdfunding service providers and crowdfunding intermediaries, supervisors may decide that individual documented business-wide risk assessments are not required where the specific risks inherent in the sector are clear and understood.

4.   By 10 July 2026, AMLA shall issue guidelines on the minimum requirements for the content of the business-wide risk assessment drawn up by the obliged entity pursuant to paragraph 1, and on the additional sources of information to be taken into account when carrying out the business-wide risk assessment.

Article 11

Compliance functions

1.   Obliged entities shall appoint one member of the management body in its management function who shall be responsible for ensuring compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor (‘compliance manager’).

The compliance manager shall ensure that the obliged entity’s internal policies, procedures and controls are consistent with the obliged entity’s risk exposure and that they are implemented. The compliance manager shall also ensure that sufficient human and material resources are allocated to that end. The compliance manager shall be responsible for receiving information on significant or material weaknesses in such policies, procedures and controls.

Where the management body in its management function is a body collectively responsible for its decisions, the compliance manager shall be responsible for assisting and advising it and for preparing the decisions referred to in this Article.

2.   Obliged entities shall have a compliance officer, to be appointed by the management body in its management function and with sufficiently high hierarchical standing, who shall be responsible for the policies, procedures and controls in the day-to-day operation of the obliged entity’s AML/CFT requirements, including in relation to the implementation of targeted financial sanctions, and shall be a contact point for competent authorities. The compliance officer shall also be responsible for reporting suspicious transactions to the FIU in accordance with Article 69(6).

In the case of obliged entities subject to checks on their senior management or beneficial owners pursuant to Article 6 of Directive (EU) 2024/1640 or under other Union legal acts, compliance officers shall be subject to verification that they comply with those requirements.

Where justified by the size of the obliged entity and the low risk of its activities, an obliged entity that is part of a group may appoint as its compliance officer an individual who performs that function in another entity within that group.

The compliance officer may only be removed following prior notification to the management body in its management function. The obliged entity shall notify the supervisor of the removal of the compliance officer, specifying whether the decision relates to the carrying out of the tasks assigned under this Regulation. The compliance officer may, on his or her own initiative or upon request, provide information to the supervisor concerning the removal. The supervisor may use that information to perform its tasks under the second subparagraph of this paragraph and under Article 37(4) of Directive (EU) 2024/1640.

3.   Obliged entities shall provide the compliance functions with adequate resources, including staff and technology, in proportion to the size, nature and risks of the obliged entity for effective performance of their tasks, and shall ensure that the persons responsible for those functions are granted the powers to propose any measures necessary to ensure the effectiveness of the obliged entity’s internal policies, procedures and controls.

4.   Obliged entities shall take measures to ensure that the compliance officer is protected against retaliation, discrimination and any other unfair treatment, and that decisions of the compliance officer are not undermined or unduly influenced by commercial interests of the obliged entity.

5.   Obliged entities shall ensure that the compliance officer and the person responsible for the audit function referred to in Article 9(2), point (b), can report directly to the management body in its management function and, where such a body exists, to the management body in its supervisory function independently, and can raise concerns and warn the management body, where specific risk developments affect or may affect the obliged entity.

Obliged entities shall ensure that the persons directly or indirectly participating in implementation of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, have access to all information and data necessary to perform their tasks.

6.   The compliance manager shall regularly report on the implementation of the obliged entity’s internal policies, procedures and controls to the management body. In particular, the compliance manager shall submit once a year, or, where appropriate, more frequently, to the management body a report on the implementation of the obliged entity’s internal policies, procedures and controls drawn up by the compliance officer, and shall keep that body informed of the outcome of any reviews. The compliance manager shall take the necessary actions to remedy in a timely manner any deficiencies identified.

7.   Where the nature of the business of the obliged entity, including its risks and complexity, and its size justify it, the functions of the compliance manager and the compliance officer may be performed by the same natural person. Those functions may be cumulated with other functions.

Where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only, that person shall be responsible for performing the tasks under this Article.

Article 12

Awareness of requirements

Obliged entities shall take measures to ensure that their employees or persons in comparable positions whose function so requires, including their agents and distributors are aware of the requirements arising from this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, and of the business-wide risk assessment, internal policies, procedures and controls in place in the obliged entity, including in relation to the processing of personal data for the purposes of this Regulation.

The measures referred to in the first paragraph shall include the participation of employees or persons in comparable positions, including agents and distributors, in specific, ongoing training programmes to help them recognise operations which may be related to money laundering or terrorist financing and to instruct them as to how to proceed in such cases. Such training programmes shall be appropriate to their functions or activities and to the risks of money laundering and terrorist financing to which the obliged entity is exposed, and shall be duly documented.

Article 13

Integrity of employees

1.   Any employee, or person in a comparable position, including agents and distributors, directly participating in the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, shall undergo an assessment commensurate with the risks associated with the tasks performed and whose content is approved by the compliance officer of:

(a) individual skills, knowledge and expertise to carry out their functions effectively;

(b) good repute, honesty and integrity.

The assessment referred to in the first subparagraph shall be performed prior to taking up of activities by the employee or person in a comparable position, including agents and distributors, and shall be regularly repeated. The intensity of the subsequent assessments shall be determined on the basis of the tasks entrusted to the person and risks associated with the function they perform.

2.   Employees, or persons in comparable positions, including agents and distributors, entrusted with tasks related to the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, shall inform the compliance officer of any close private or professional relationship established with the obliged entity’s customers or prospective customers and shall be prevented from undertaking any tasks related to the obliged entity’s compliance in relation to those customers.

3.   Obliged entities shall have in place procedures to prevent and manage conflicts of interest that may affect the carrying out of tasks related to the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor.

4.   This Article shall not apply where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only.

Article 14

Reporting of breaches and protection of reporting persons

1.   Directive (EU) 2019/1937 of the European Parliament and of the Council (41) shall apply to the reporting of breaches of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, and to the protection of persons reporting such breaches.

2.   Obliged entities shall establish internal reporting channels that meet the requirements set out in Directive (EU) 2019/1937.

3.   Paragraph 2 shall not apply where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only.

Article 15

Situation of specific employees

Where a natural person falling within any of the categories listed in Article 3, point (3) performs professional activities as an employee of a legal person, the requirements laid down in this Regulation shall apply to that legal person rather than to the natural person.

SECTION 2

Provisions applying to groups

Article 16

Group-wide requirements

1.   A parent undertaking shall ensure that the requirements on internal procedures, risk assessment and staff referred to in Section 1 of this Chapter apply in all branches and subsidiaries of the group in the Member States and, for groups whose head office is located in the Union, in third countries. To this end, a parent undertaking shall perform a group-wide risk assessment, taking into account the business-wide risk assessment performed by all branches and subsidiaries of the group, and establish and implement group-wide policies, procedures and controls, including on data protection and on information sharing within the group for AML/CFT purposes and to ensure that employees within the group are aware of the requirements arising from this Regulation. Obliged entities within the group shall implement those group-wide policies, procedures and controls, taking into account their specificities and the risks to which they are exposed.

The group-wide policies, procedures and controls and the group-wide risk assessments referred to in the first subparagraph shall include all the elements listed in Articles 9 and 10, respectively.

For the purposes of the first subparagraph, where a group has establishments in more than one Member State and, for groups whose head office is located in the Union, in third countries, parent undertakings shall take into account the information published by the authorities of all the Member States or third countries where the group’s establishments are located.

2.   Compliance functions shall be established at the level of the group. Those functions shall include a compliance manager at the level of the group and, where justified by the activities carried out at group level, a compliance officer. The decision on the extent of the compliance functions shall be documented.

The compliance manager referred to in the first subparagraph shall regularly report to the management body in its management function of the parent undertaking on the implementation of the group-wide policies, procedures and controls. At a minimum, the compliance manager shall submit once a year a report on the implementation of the obliged entity’s internal policies, procedures and controls and shall take the necessary actions to remedy in a timely manner any deficiencies identified. Where the management body in its management function is a body collectively responsible for its decisions, the compliance manager shall assist and advise it, and shall prepare the decisions necessary for the implementation of this Article.

3.   The policies, procedures and controls pertaining to the sharing of information referred to in paragraph 1 shall require obliged entities within the group to exchange information when such sharing is relevant for the purposes of customer due diligence and money laundering and terrorist financing risk management. The sharing of information within the group shall cover in particular the identity and characteristics of the customer, its beneficial owners or the person on behalf of whom the customer acts, the nature and purpose of the business relationship and of the occasional transactions and the suspicions, accompanied by the underlying analyses, that funds are the proceeds of criminal activity or are related to terrorist financing reported to FIU pursuant to Article 69, unless otherwise instructed by the FIU.

The group-wide policies, procedures and controls shall not prevent entities within a group which are not obliged entities to provide information to obliged entities within the same group where such sharing is relevant for those obliged entities to comply with requirements set out in this Regulation.

Parent undertakings shall put in place group-wide policies, procedures and controls to ensure that the information exchanged pursuant to the first and second subparagraphs is subject to sufficient guarantees in terms of confidentiality, data protection and use of the information, including to prevent its disclosure.

4.   By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify the minimum requirements of group-wide policies, procedures and controls, including minimum standards for information sharing within the group, the criteria for identifying the parent undertaking in the cases covered by Article 2(1), point (42)(b), and the conditions under which the provisions of this Article apply to entities that are part of structures which share common ownership, management or compliance control, including networks or partnerships, as well as the criteria for identifying the parent undertaking in the Union in those cases.

5.   Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 4 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Article 17

Branches and subsidiaries in third countries

1.   Where branches or subsidiaries of obliged entities are located in third countries where the minimum AML/CFT requirements are less strict than those set out in this Regulation, the parent undertaking shall ensure that those branches or subsidiaries comply with the requirements laid down in this Regulation, including requirements concerning data protection, or equivalent.

2.   Where the law of a third country does not permit compliance with this Regulation, the parent undertaking shall take additional measures to ensure that branches and subsidiaries in that third country effectively handle the risk of money laundering or terrorist financing, and shall inform the supervisors of its home Member State of those additional measures. Where the supervisors of the home Member State consider that the additional measures are not sufficient, they shall exercise additional supervisory actions, including requiring the group not to enter into any business relationship, to terminate existing ones or not to undertake transactions, or to close down its operations in the third country.

3.   By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify the type of additional measures referred to in paragraph 2 of this Article, including the minimum action to be taken by obliged entities where the law of a third country does not permit the implementation of the measures required under Article 16 and the additional supervisory actions required in such cases.

4.   Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 3 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

SECTION 3

Outsourcing

Article 18

Outsourcing

1.   Obliged entities may outsource tasks resulting from this Regulation to service providers. The obliged entity shall notify the supervisor of the outsourcing before the service provider starts to carry out the outsourced task.

2.   When performing tasks under this Article, service providers shall be regarded as part of the obliged entity, including where they are required to consult the central registers referred to in Article 10 of Directive (EU) 2024/1640 (‘central registers’) for the purposes of carrying out customer due diligence on behalf of the obliged entity.

The obliged entity shall remain fully liable for any action, whether an act of commission or omission, connected to the outsourced tasks that are carried out by service providers.

For each outsourced task, the obliged entity shall be able to demonstrate to the supervisor that it understands the rationale behind the activities carried out by the service provider and the approach followed in their implementation, and that such activities mitigate the specific risks to which the obliged entity is exposed.

3.   The tasks outsourced pursuant to paragraph 1 of this Article shall not be undertaken in such a way as to impair materially the quality of the obliged entity’s policies and procedures to comply with the requirements of this Regulation and of Regulation (EU) 2023/1113, and of the controls in place to test those policies and procedures. The following tasks shall not be outsourced under any circumstances:

(a) the proposal and approval of the obliged entity’s business-wide risk assessment pursuant to Article 10(2);

(b) the approval of the obliged entity’s internal policies, procedures and controls pursuant to Article 9;

(c) decision on the risk profile to be attributed to the customer;

(d) the decision to enter into a business relationship or carry out an occasional transaction with a client;

(e) the reporting to FIU of suspicious activities pursuant to Article 69 or threshold-based reports pursuant to Article 74 and 80, except where such activities are outsourced to another obliged entity belonging to the same group and established in the same Member State;

(f) the approval of the criteria for the detection of suspicious or unusual transactions and activities.

4.   Before an obliged entity outsources a task pursuant to paragraph 1, it shall assure itself that the service provider is sufficiently qualified to carry out the tasks to be outsourced.

Where an obliged entity outsources a task pursuant to paragraph 1, it shall ensure that the service provider, as well as any subsequent sub-outsourcing service provider, applies the policies and procedures adopted by the obliged entity. The conditions for the performance of such tasks shall be laid down in a written agreement between the obliged entity and the service provider. The obliged entity shall perform regular controls to ascertain the effective implementation of such policies and procedures by the service provider. The frequency of such controls shall be determined on the basis of the critical nature of the tasks outsourced.

5.   Obliged entities shall ensure that outsourcing is not undertaken in such way as to impair materially the ability of the supervisory authorities to monitor and retrace the obliged entity’s compliance with this Regulation and Regulation (EU) 2023/1113.

6.   By way of derogation from paragraph 1, obliged entities shall not outsource tasks deriving from the requirements under this Regulation to service providers residing or established in third countries identified pursuant to Section 2 of Chapter III, unless all of the following conditions are met:

(a) the obliged entity outsources tasks solely to a service provider that is part of the same group;

(b) the group applies AML/CFT policies and procedures, customer due diligence measures and rules on record-keeping that are fully in compliance with this Regulation, or with equivalent rules in third countries;

(c) the effective implementation of the requirements referred to in point (b) of this paragraph is supervised at group level by the supervisory authority of the home Member State in accordance with Chapter IV of Directive (EU) 2024/1640.

7.   By way of derogation from paragraph 3, where a collective investment undertaking has no legal personality, or has only a board of directors and has delegated the processing of subscriptions and the collection of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 from investors to another entity, it may outsource the task referred to in paragraph 3, points (c), (d) and (e) to one of its service providers.

The outsourcing referred to in the first subparagraph of this paragraph may only take place after the collective investment undertaking has notified its intention to outsource the task to the supervisor pursuant to paragraph 1, and the supervisor has approved such outsourcing taking into consideration:

(a) the resources, experience and knowledge of the service provider in relation to the prevention of money laundering and terrorist financing;

(b) the knowledge of the service provider of the type of activities or transactions carried out by the collective investment undertaking.

8.   By 10 July 2027, AMLA shall issue guidelines addressed to obliged entities on:

(a) the establishment of outsourcing relationships, including any subsequent outsourcing relationship, in accordance with this Article, their governance and procedures for monitoring the implementation of functions by the service provider and in particular those functions that are to be regarded as critical;

(b) the roles and responsibility of the obliged entity and the service provider within an outsourcing agreement;

(c) supervisory approaches to outsourcing as well as supervisory expectations regarding the outsourcing of critical functions.

CHAPTER III

CUSTOMER DUE DILIGENCE

SECTION 1

General provisions

Article 19

Application of customer due diligence measures

1.   Obliged entities shall apply customer due diligence measures in any of the following circumstances:

(a) when establishing a business relationship;

(b) when carrying out an occasional transaction of a value of at least EUR 10 000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions, or a lower value laid down pursuant to paragraph 9;

(c) when participating in the creation of a legal entity, the setting up of a legal arrangement or, for the obliged entities referred to in Article 3, points (3) (a), (b) or (c), in the transfer of ownership of a legal entity, irrespective of the value of the transaction;

(d) when there is a suspicion of money laundering or terrorist financing, regardless of any derogation, exemption or threshold;

(e) when there are doubts about the veracity or adequacy of previously obtained customer identification data;

(f) when there are doubts as to whether the person they interact with is the customer or person authorised to act on behalf of the customer.

2.   In addition to the circumstances referred to in paragraph 1, credit institutions and financial institutions, with the exception of crypto-asset service providers, shall apply customer due diligence measures when initiating or executing an occasional transaction that constitutes a transfer of funds as defined in Article 3, point (9), of Regulation (EU) 2023/1113, that amounts to a value of at least EUR 1 000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions.

3.   By way of derogation from paragraph 1, point (b), crypto-asset service providers shall:

(a) apply customer due diligence measures when carrying out an occasional transaction that amounts to a value of at least EUR 1 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions;

(b) apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction where the value is below EUR 1 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.

4.   By way of derogation from paragraph 1, point (b), obliged entities shall apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction in cash amounting to a value of at least EUR 3 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.

The first subparagraph of this paragraph shall not apply where Member States have in place, pursuant to Article 80(2) and (3), a limit to large cash payments of EUR 3 000 or less, or the equivalent in national currency, except in the cases covered by paragraph 4, point (b) of that Article.

5.   In addition to the circumstances referred to in paragraph 1, providers of gambling services shall apply customer due diligence measures upon the collection of winnings, the wagering of a stake, or both, when carrying out transactions amounting to at least EUR 2 000 or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.

6.   For the purposes of this Chapter, obliged entities shall consider as their customers the following persons:

(a) in the case of obliged entities as referred to in Article 3, points (3) (e), (f) and (i) and persons trading in high value goods as referred to in Article 3, point (3) (j), in addition to their direct customer, the supplier of goods;

(b) in the case of notaries, lawyers and other independent legal professionals intermediating a transaction and to the extent that they are the only notary or lawyer or other independent legal professional intermediating that transaction, both parties to the transaction;

(c) in the case of real estate agents, both parties to the transaction;

(d) in relation to payment initiation services carried out by payment initiation service providers, the merchant;

(e) in relation to crowdfunding service providers and crowdfunding intermediaries, the natural or legal person both seeking funding and providing funding through the crowdfunding platform.

7.   Supervisors may, directly or in cooperation with other authorities in that Member State, exempt obliged entities from applying, in full or in part, the customer due diligence measures referred to in Article 20(1), points (a), (b) and (c), with respect to electronic money on the basis of the proven low risk posed by the nature of the product, where all of the following risk-mitigating conditions are met:

(a) the payment instrument is not reloadable, and the amount stored electronically does not exceed EUR 150 or the equivalent in national currency;

(b) the payment instrument is used exclusively to purchase goods or services provided by the issuer, or within a network of service providers;

(c) the payment instrument is not linked to a payment account and it does not permit any stored amount to be exchanged for cash or for crypto-assets;

(d) the issuer carries out sufficient monitoring of the transactions or business relationship to enable the detection of unusual or suspicious transactions.

8.   Providers of gambling services may fulfil their obligation to apply customer due diligence measures referred to in Article 20(1), point (a), by identifying the customer and verifying the customer’s identity upon entry to the casino or other physical gambling premises, provided that they have systems in place that enable them to attribute transactions to specific customers.

9.   By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify:

(a) the obliged entities, sectors or transactions that are associated with higher money laundering and terrorist financing risk and to which a value lower than the value set out in paragraph 1, point (b), applies;

(b) the related occasional transaction values;

(c) the criteria to be taken into account for identifying occasional transactions and business relationships;

(d) the criteria to identify linked transactions.

When developing the draft regulatory technical standards referred to in the first subparagraph, AMLA shall take due account of the inherent levels of risks of the business models of the different types of obliged entities and of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640.

10.   Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 9 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

Article 20

Customer due diligence measures

1.   For the purpose of conducting customer due diligence, obliged entities shall apply all of the following measures:

(a) identifying the customer and verifying the customer’s identity;

(b) identifying the beneficial owners and taking reasonable measures to verify their identity so that the obliged entity is satisfied that it knows who the beneficial owner is and that it understands the ownership and control structure of the customer;

(c) assessing and, as appropriate, obtaining information on and understanding the purpose and intended nature of the business relationship or the occasional transactions;

(d) verifying whether the customer or the beneficial owners are subject to targeted financial sanctions, and, in the case of a customer or party to a legal arrangement who is a legal entity, whether natural or legal persons subject to targeted financial sanctions control the legal entity or have more than 50 % of the proprietary rights of that legal entity or majority interest in it, whether individually or collectively;

(e) assessing and, as appropriate, obtaining information on the nature of the customers’ business, including, in the case of undertakings, whether they carry out activities, or of their employment or occupation;

(f) conducting ongoing monitoring of the business relationship including scrutiny of transactions undertaken throughout the course of the business relationship to ensure that the transactions being conducted are consistent with the obliged entity’s knowledge of the customer, the business and risk profile, including where necessary the source of funds;

(g) determining whether the customer, the beneficial owner of the customer and, where relevant, the person on whose behalf or for the benefit of whom a transaction or activity is being carried out is a politically exposed person, a family member or person known to be a close associate;

(h) where a transaction or activity is being conducted on behalf of or for the benefit of natural persons other than the customer, identifying and verifying the identity of those natural persons;

(i) verifying that any person purporting to act on behalf of the customer is so authorised and identify and verify their identity.

2.   Obliged entities shall determine the extent of the measures referred to in paragraph 1 on the basis of an individual analysis of the risks of money laundering and terrorist financing having regard to the specific characteristics of the client and of the business relationship or occasional transaction, and taking into account the business-wide risk assessment by the obliged entity pursuant to Article 10 and the money laundering and terrorist financing variables set out in Annex I as well as the risk factors set out in Annexes II and III.

Where obliged entities identify an increased risk of money laundering or terrorist financing they shall apply enhanced due diligence measures pursuant to Section 4 of this Chapter. Where situations of lower risk are identified, obliged entities may apply simplified due diligence measures pursuant to Section 3 of this Chapter.

3.   By 10 July 2026, AMLA shall issue guidelines on the risk variables and risk factors to be taken into account by obliged entities when entering into business relationships or carrying out occasional transactions.

4.   Obliged entities shall at all times be able to demonstrate to their supervisors that the measures taken are appropriate in view of the risks of money laundering and terrorist financing that have been identified.

Article 21

Inability to comply with the requirement to apply customer due diligence measures

1.   Where an obliged entity is unable to comply with the requirement to apply customer due diligence measures laid down in Article 20(1), it shall refrain from carrying out a transaction or establishing a business relationship, and shall terminate the business relationship and consider reporting a suspicious transaction to the FIU in relation to the customer in accordance with Article 69.

The termination of a business relationship pursuant to the first subparagraph of this paragraph shall not prohibit the receipt of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 due to the obliged entity.

Where an obliged entity has a duty to protect its customer’s assets, the termination of the business relationship shall not be understood as requiring the disposal of the assets of the customer.

In the case of life insurance contracts, obliged entities shall, where necessary as an alternative measure to terminating the business relationship, refrain from performing transactions for the customer, including payouts to beneficiaries, until the customer due diligence measures laid down in Article 20(1) are complied with.

2.   Paragraph 1 shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors, to the extent that those persons ascertain the legal position of their client, or perform the task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings.

The first subparagraph shall not apply when the obliged entities referred to therein:

(a) take part in money laundering, its predicate offences or terrorist financing;

(b) provide legal advice for the purposes of money laundering, its predicate offences or terrorist financing; or

(c) know that the client is seeking legal advice for the purposes of money laundering, its predicate offences or terrorist financing; knowledge or purpose may be inferred from objective factual circumstances.

3.   Obliged entities shall keep record of the actions taken in order to comply with the requirement to apply customer due diligence measures, including records of the decisions taken and the relevant supporting documents and justifications. Documents, data or information held by the obliged entity shall be updated whenever the customer due diligence is reviewed pursuant to Article 26.

The obligation to keep records provided for in the first subparagraph of this paragraph shall also apply to situations where obliged entities refuse to enter into a business relationship, terminate a business relationship or apply alternative measures pursuant to paragraph 1.

4.   By 10 July 2027, AMLA shall issue joint guidelines with the European Banking Authority on the measures that may be taken by credit institutions and financial institutions to ensure compliance with AML/CFT rules when implementing the requirements of Directive 2014/92/EU, including in relation to business relationships that are most affected by de-risking practices.

Article 22

Identification and verification of the identity of customers and beneficial owners

1.   With the exception of cases of lower risk to which measures under Section 3 apply and irrespective of the application of additional measures in cases of higher risk under Section 4 obliged entities shall obtain at least the following information in order to identify the customer, any person purporting to act on behalf of the customer, and the natural persons on whose behalf or for the benefit of whom a transaction or activity is being conducted:

(a) for a natural person:; (i) all names and surnames;; (ii) place and full date of birth;; (iii) nationalities, or statelessness and refugee or subsidiary protection status where applicable, and the national identification number, where applicable;; (iv) the usual place of residence or, if there is no fixed residential address with legitimate residence in the Union, the postal address at which the natural person can be reached and, where available the tax identification number;

(b) for a legal entity:; (i) legal form and name of the legal entity;; (ii) address of the registered or official office and, if different, the principal place of business, and the country of creation;; (iii) the names of the legal representatives of the legal entity as well as, where available, the registration number, the tax identification number and the Legal Entity Identifier;; (iv) the names of persons holding shares or a directorship position in nominee form, including reference to their status as nominee shareholders or directors.

(c) for a trustee of an express trust or a person holding an equivalent position in a similar legal arrangement:; (i) basic information on the legal arrangement; however, with regard to the assets held in the legal arrangement or managed through it, only the assets that are to be managed in the context of the business relationship or occasional transaction shall be identified;; (ii) the address of residence of the trustees or persons holding an equivalent position in a similar legal arrangement and, if different, the place from where the express trust or similar legal arrangement is administered, the powers that regulate and bind the legal arrangement, as well as, where available, the tax identification number and the Legal Entity Identifier;

(d) for other organisations that have legal capacity under national law:; (i) name, address of the registered office or equivalent;; (ii) names of the persons empowered to represent the organisation as well as, where applicable, legal form, tax identification number, registration number, Legal Entity Identifier and deeds of association or equivalent.

2.   For the purposes of identifying the beneficial owner of a legal entity or of a legal arrangement, obliged entities shall collect the information referred to in Article 62(1), second subparagraph, point (a).

Where, after having exhausted all possible means of identification, no natural persons are identified as beneficial owners, or where there are doubts that the persons identified are the beneficial owners, obliged entities shall record that no beneficial owner was identified and identify all the natural persons holding the positions of senior managing officials in the legal entity and shall verify their identity.

Where the performance of identity verification referred to in the second subparagraph may tip off the customer that the obliged entity has doubts regarding the beneficial ownership of the legal entity, the obliged entity shall abstain from verifying the senior managing officials’ identity, and shall instead record the steps taken to ascertain the identity of the beneficial owners and senior managing officials. Obliged entities shall keep records of the actions taken as well as of the difficulties encountered during the identification process, which led to resorting to the identification of a senior managing official.

3.   Credit institutions and financial institutions shall obtain information to identify and verify the identity of the natural or legal persons using any virtual IBAN they issue, and the associated bank or payment account.

The credit institution or financial institution servicing the bank or payment account to which a virtual IBAN issued by another credit institution or financial institution redirects payments, shall ensure that it can obtain from the institution issuing the virtual IBAN the information identifying and verifying the identity of the natural person using that virtual IBAN without delay and in any case within 5 working days of it requesting that information.

4.   In the case of beneficiaries of trusts or similar legal entities or arrangements that are designated by particular characteristics or class, an obliged entity shall obtain sufficient information concerning the beneficiary so that it will be able to establish the identity of the beneficiary at the time of the payout or at the time of the exercise by the beneficiary of its vested rights.

5.   In the case of discretionary trusts, an obliged entity shall obtain sufficient information concerning the objects of a power and default takers to enable it to establish the identity of the beneficiary at the time of the exercise by the trustees of their power of discretion, or at the time that the default takers become the beneficiaries due to the trustees’ failure to exercise their power of discretion.

6.   Obliged entities shall obtain the information, documents and data necessary for the verification of the identity of the customer and of any person purporting to act on their behalf through either of the following means:

(a) the submission of an identity document, passport or equivalent and, where relevant, the acquisition of information from reliable and independent sources, whether accessed directly or provided by the customer;

(b) the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels ‘substantial’ or ‘high’ and relevant qualified trust services as set out in that Regulation.

7.   Obliged entities shall verify the identity of the beneficial owner and, where relevant, the persons on whose behalf or for the benefit of whom a transaction or activity is being carried out in either of the following ways:

(a) in accordance with paragraph 6;

(b) by taking reasonable measures to obtain the necessary information, documents and data from the customer or other reliable sources, including public registers other than the central registers.

Obliged entities shall determine the extent of the information to be consulted, having regard to the risks posed by the occasional transaction or the business relationship and the beneficial owner, including risks relating to the ownership structure.

In addition to the means of verification set out in the first subparagraph of this paragraph, obliged entities shall verify the information on the beneficial owners by consulting the central registers.

Article 23

Timing of the verification of the customer and beneficial owner identity

1.   Verification of the identity of the customer, the beneficial owner, and of any persons pursuant to Article 20(1), points (h) and (i), shall take place before the establishment of a business relationship or the carrying out of an occasional transaction. Such obligation shall not apply to situations of lower risk under Section 3 of this Chapter, provided that the lower risk justifies postponement of such verification.

For real estate agents, the verification referred to in the first subparagraph shall be carried out after an offer is accepted by the seller or lessor, and in all cases before any funds or property are transferred.

2.   By way of derogation from paragraph 1, verification of the identity of the customer and of the beneficial owner may be completed during the establishment of a business relationship if necessary so as not to interrupt the normal conduct of business and where there is little risk of money laundering or terrorist financing. In such situations, those procedures shall be completed as soon as practicable after initial contact.

3.   By way of derogation from paragraph 1 of this Article, a credit institution or financial institution may open an account, including accounts that permit transactions in transferable securities, as may be required by a customer provided that there are adequate safeguards in place to ensure that transactions are not carried out by the customer or on its behalf until full compliance with the customer due diligence measures laid down in Article 20(1), points (a) and (b), is obtained.

4.   Whenever entering into a new business relationship with a legal entity or the trustee of an express trust or the person holding an equivalent position in a similar legal arrangement referred to in Articles 51, 57, 58, 61 and 67 and subject to the registration of beneficial ownership information pursuant to Article 10 of Directive (EU) 2024/1640, obliged entities shall collect valid proof of registration or a recently issued excerpt of the register confirming validity of registration.

Article 24

Reporting of discrepancies with information contained in beneficial ownership registers

1.   Obliged entities shall report to the central registers any discrepancies they find between the information available in the central registers and the information they collect pursuant to Article 20(1), point (b), and Article 22(7).

The discrepancies referred to in the first subparagraph shall be reported without undue delay and, in any case, within 14 calendar days of their detection. When reporting such discrepancies, obliged entities shall accompany their reports with information they have obtained indicating the discrepancy and whom they consider to be the beneficial owners and, where applicable, the nominee shareholders and nominee directors to be and why.

2.   By way of derogation from paragraph 1, obliged entities may refrain from reporting discrepancies to the central register and may instead request additional information from the customers where the discrepancies identified:

(a) are limited to typographical errors, different ways of transliteration, or minor inaccuracies that do not affect the identification of the beneficial owners or their position; or

(b) are a result of outdated data, but the beneficial owners are known to the obliged entity from another reliable source and there are no grounds for suspicion that there is an intention to conceal any information.

Where an obliged entity concludes that the beneficial ownership information in the central register is incorrect, it shall invite the customer to submit the correct information to the central register pursuant to Articles 63, 64 and 67 without undue delay, and, in any case, within 14 calendar days.

This paragraph shall not apply to cases of higher risk to which measures under Section 4 of this Chapter apply.

3.   Where a customer has not submitted the correct information within the deadline referred to in paragraph 2, second subparagraph, the obliged entity shall report the discrepancy to the central register in accordance with paragraph 1, second subparagraph.

4.   This Article shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors in relation to information they receive from, or obtain on, a client, in the course of ascertaining the legal position of that client, or performing their task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, regardless of whether such information is received or obtained before, during or after such proceedings.

However, the requirements of this Article shall apply when the obliged entities referred to in the first subparagraph of this paragraph provide legal advice in any of the situations covered by Article 21(2), second subparagraph.

Article 25

Identification of the purpose and intended nature of a business relationship or occasional transaction

Before entering into a business relationship or performing an occasional transaction, an obliged entity shall assure itself that it understands its purpose and intended nature. To that end, the obliged entity shall obtain, where necessary, information on:

(a) the purpose and economic rationale of the occasional transaction or business relationship;

(b) the estimated amount of the envisaged activities;

(c) the source of funds;

(d) the destination of funds;

(e) the business activity or the occupation of the customer.

For the purposes of the first paragraph, point (a), of this Article, obliged entities covered by Article 74 shall collect information in order to determine whether the intended use of high value goods referred to in that Article is for commercial or non-commercial purposes.

Article 26

Ongoing monitoring of the business relationship and monitoring of transactions performed by customers

1.   Obliged entities shall conduct ongoing monitoring of business relationships, including transactions undertaken by the customer throughout the course of a business relationship, to ensure that those transactions are consistent with the obliged entity’s knowledge of the customer, the customer’s business activity and risk profile, and where necessary, with the information about the origin and destination of the funds and to detect those transactions that shall be made subject to a more thorough assessment pursuant to Article 69(2).

Where business relationships cover more than one product or service, obliged entities shall ensure that the customer due diligence measures cover all those products and services.

Where obliged entities belonging to a group have business relationships with customers that are also the customers of other entities within that group, whether obliged entities or undertakings not subject to AML/CFT requirements, they shall take into account information relating to those other business relationships for the purposes of monitoring the business relationship with their customers.

2.   In the context of the ongoing monitoring referred to in paragraph 1, obliged entities shall ensure that the relevant documents, data or information of the customer are kept up to date.

The period between updates of customer information pursuant to the first subparagraph shall be dependent on the risk posed by the business relationship and shall not in any case exceed:

(a) for higher risk customers to which measures under Section 4 of this Chapter apply, 1 year;

(b) for all other customers, 5 years.

3.   In addition to the requirements set out in paragraph 2, obliged entities shall review and, where relevant, update the customer information where:

(a) there is a change in the relevant circumstances of a customer;

(b) the obliged entity has a legal obligation in the course of the relevant calendar year to contact the customer for the purpose of reviewing any relevant information relating to the beneficial owners or to comply with Council Directive 2011/16/EU (42);

(c) they become aware of a relevant fact which pertains to the customer.

4.   In addition to the ongoing monitoring referred to in paragraph 1 of this Article, obliged entities shall regularly verify whether the conditions laid down in Article 20(1), point (d), are met. The frequency of that verification shall be commensurate with the exposure of the obliged entity and the business relationship to risks of non-implementation and evasion of targeted financial sanctions.

For credit institutions and financial institutions, the verification referred to in the first subparagraph shall also be carried out upon any new designation in relation to targeted financial sanctions.

The requirements of this paragraph shall not replace the obligation to apply targeted financial sanctions or stricter requirements under other Union legal acts or under national law on the verification of the client base against lists of targeted financial sanctions.

5.   By 10 July 2026, AMLA shall issue guidelines on ongoing monitoring of a business relationship and on the monitoring of the transactions carried out in the context of such relationship.

Article 27

Temporary measures for customers subject to UN financial sanctions

1.   In respect of customers that are subject to UN financial sanctions or that are controlled by natural or legal persons or entities subject to UN financial sanctions, or in which natural or legal persons or entities that are subject to UN financial sanctions have more than 50 % of the proprietary rights or majority interest, whether individually or collectively, obliged entities shall keep records of:

(a) the funds or other assets that they manage for the customer at the time when UN financial sanctions are made public;

(b) the transactions attempted by the customer;

(c) the transactions carried out for the customer.

2.   Obliged entities shall apply this Article between the time that UN financial sanctions are made public and the time of application of the relevant targeted financial sanctions in the Union.

Article 28

Regulatory technical standards on the information necessary for the performance of customer due diligence

1.   By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify:

(a) the requirements that apply to obliged entities pursuant to Article 20 and the information to be collected for the purpose of performing standard, simplified and enhanced due diligence pursuant to Articles 22 and 25 and Articles 33(1) and 34(4), including minimum requirements in situations of lower risk;

(b) the type of simplified due diligence measures which obliged entities may apply in situations of lower risk pursuant to Article 33(1) of this Regulation, including measures applicable to specific categories of obliged entities and products or services, having regard to the results of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640;

(c) the risk factors associated with features of electronic money instruments that should be taken into account by supervisors when determining the extent of the exemption under Article 19(7);

(d) the reliable and independent sources of information that may be used to verify the identification data of natural or legal persons for the purposes of Article 22(6) and (7);

(e) the list of attributes which electronic identification means and relevant qualified trust services referred to in Article 22(6), point (b), must feature in order to fulfil the requirements of Article 20(1), points (a) and (b), in the case of standard, simplified and enhanced due diligence.

2.   The requirements and measures referred to in paragraph 1, points (a) and (b), shall be based on the following criteria:

(a) the inherent risk involved in the service provided;

(b) the risks associated with categories of customers;

(c) the nature, amount and recurrence of the transaction;

(d) the channels used for conducting the business relationship or the occasional transaction.

3.   AMLA shall review regularly the regulatory technical standards and, if necessary, prepare and submit to the Commission the draft for updating those standards in order, inter alia, to take account of innovation and technological developments.

4.   Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraphs 1 and 3 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.

SECTION 2

Third-country policy and money laundering and terrorist financing threats from outside the Union

Article 29

Identification of third countries with significant strategic deficiencies in their national AML/CFT regimes

1.   Third countries with significant strategic deficiencies in their national AML/CFT regimes shall be identified by the Commission and designated as ‘high-risk third countries’.

2.   In order to identify third countries as referred to in paragraph 1 of this Article, the Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation, where:

(a) significant strategic deficiencies in the legal and institutional AML/CFT framework of the third country have been identified;

(b) significant strategic deficiencies in the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks or in its system to assess and mitigate risks of non-implementation or evasion of UN financial sanctions relating to proliferation financing have been identified;

(c) the significant strategic deficiencies identified under points (a) and (b) are of a persistent nature and no measures to mitigate them have been taken or are being taken.

Those delegated acts shall be adopted within 20 calendar days of the Commission ascertaining that the criteria in point (a), (b) or (c) of the first subparagraph are met.

3.   For the purposes of paragraph 2, the Commission shall take into account calls for the application of enhanced due diligence measures and additional mitigating measures (‘countermeasures’) by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing, as well as relevant evaluations, assessments, reports or public statements drawn up by them.

4.   Where a third country is identified in accordance with the criteria referred to in paragraph 2, obliged entities shall apply enhanced due diligence measures listed in Article 34(4) with respect to the business relationships or occasional transactions involving natural or legal persons from that third country.

5.   The delegated act referred to in paragraph 2 shall identify among the countermeasures listed in Article 35 the specific countermeasures mitigating specific risks stemming from each high-risk third country.

6.   Where a Member State identifies a specific money laundering or terrorist financing risk posed by a third country that the Commission has identified in accordance with the criteria referred to in paragraph 2 which is not addressed by the countermeasures referred to in paragraph 5, it may require obliged entities established in its territory to apply specific additional countermeasures to mitigate the specific risks stemming from that third country. The risk identified and the corresponding countermeasures shall be notified to the Commission within 5 days of the countermeasures being applied.

7.   The Commission shall review the delegated acts referred to in paragraph 2 on a regular basis to ensure that the specific countermeasures identified pursuant to paragraph 5 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.

Upon receiving a notification pursuant to paragraph 6, the Commission shall assess the information received to determine whether country-specific risks affect the integrity of the Union’s internal market. Where appropriate, the Commission shall review the delegated acts referred to in paragraph 2, by adding the necessary countermeasures to mitigate those additional risks. Where the Commission considers that the specific additional measures applied by a Member State under paragraph 6 are not necessary to mitigate specific risks stemming from that third country, it may decide, by means of an implementing act, that the Member State shall put an end to the specific additional countermeasure.

Article 30

Identification of third countries with compliance weaknesses in their national AML/CFT regimes

1.   Third countries with compliance weaknesses in their national AML/CFT regimes shall be identified by the Commission.

2.   In order to identify the third countries referred to in paragraph 1, the Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation, where:

(a) compliance weaknesses in the legal and institutional AML/CFT framework of the third country have been identified;

(b) compliance weaknesses in the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks or in its system to assess and mitigate risks of non-implementation or evasion of UN financial sanctions relating to proliferation financing have been identified.

Those delegated acts shall be adopted within 20 calendar days of the Commission ascertaining that the criteria in point (a) or (b) of the first subparagraph are met.

3.   The Commission, when drawing up the delegated acts referred to in paragraph 2 shall take into account, as a baseline for its assessment, information on jurisdictions under increased monitoring by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing, as well as relevant evaluations, assessments, reports or public statements drawn up by them.

4.   The delegated act referred to in paragraph 2 shall identify the specific enhanced due diligence measures among those listed in Article 34(4), that obliged entities shall apply to mitigate risks related to business relationships or occasional transactions involving natural or legal persons from that third country.

5.   The Commission shall review the delegated acts referred to in paragraph 2 on a regular basis to ensure that the specific enhanced due diligence measures identified pursuant to paragraph 4 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.

Article 31

Identification of third countries posing a specific and serious threat to the Union’s financial system

1.   The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation by identifying third countries where in exceptional cases it considers it indispensable to mitigate a specific and serious threat to the Union’s financial system and the proper functioning of the internal market posed by those third countries, and which cannot be mitigated pursuant to Articles 29 and 30.

2.   The Commission, when drawing up the delegated acts referred to in paragraph 1, shall take into account in particular the following criteria:

(a) the legal and institutional AML/CFT framework of the third country, in particular:; (i) the criminalisation of money laundering and terrorist financing;; (ii) measures relating to customer due diligence;; (iii) requirements relating to record-keeping;; (iv) requirements to report suspicious transactions;; (v) the availability of accurate and timely information of the beneficial ownership of legal persons and arrangements to competent authorities;

(b) the powers and procedures of the third country’s competent authorities for the purposes of combating money laundering and terrorist financing including appropriately effective, proportionate and dissuasive sanctions, as well as the third country’s practice in cooperation and exchange of information with Member States’ competent authorities;

(c) the effectiveness of the third country’s AML/CFT system in addressing money laundering and terrorist financing risks.

3.   For the purposes of determining the level of threat referred to in paragraph 1, the Commission may request AMLA to adopt an opinion aimed at assessing the specific impact on the integrity of the Union’s financial system due to the level of threat posed by a third country.

4.   Where AMLA identifies that a third country other than those identified pursuant to Articles 29 and 30 poses a specific and serious threat to the Union’s financial system, it may address an opinion to the Commission setting out the threat it has identified and why it believes that the Commission should identify the third country pursuant to paragraph 1.

Where the Commission decides not to identify the third country referred to in the first subparagraph, it shall provide a justification thereof to AMLA.

5.   The Commission, when drawing up the delegated acts referred to in paragraph 1, shall take into account in particular relevant evaluations, assessments or reports drawn up by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing.

6.   Where the identified specific and serious threat from the third country concerned amounts to a significant strategic deficiency, Article 29(4) shall apply and the delegated act referred to in paragraph 1 of this Article shall identify specific countermeasures as referred to in Article 29(5).

7.   Where the identified specific and serious threat from the third country concerned amounts to a compliance weakness, the delegated act referred to in paragraph 1 shall identify specific enhanced due diligence measures among those listed in Article 34(4), that obliged entities shall apply to mitigate risks related to business relationships or occasional transactions involving natural or legal persons from that third country.

8.   The Commission shall review the delegated acts referred to in paragraph 1 on a regular basis to ensure that the countermeasures referred to in paragraph 6 and enhanced due diligence measures referred to in paragraph 7 take account of the changes in the AML/CFT framework of the third country and are proportionate and adequate to the risks.

9.   The Commission may adopt, by means of an implementing act, the methodology for the identification of third countries pursuant to this Article. That implementing act shall set out, in particular:

(a) how the criteria referred to in paragraph 2 are assessed;

(b) the process for interaction with the third country under assessment;

(c) the process for involvement of Member States and AMLA in the identification of third countries posing a specific and serious threat to the Union’s financial system.

The implementing act referred to in the first subparagraph of this paragraph shall be adopted in accordance with the examination procedure referred to in Article 86(2).

Article 32

Guidelines on money laundering and terrorist financing risks, trends and methods

1.   By 10 July 2027, AMLA shall issue guidelines defining the money laundering and terrorist financing risks, trends and methods involving any geographical area outside the Union to which obliged entities are exposed. AMLA shall take into account, in particular, the risk factors listed in Annex III. Where situations of higher risk are identified, the guidelines shall include enhanced due diligence measures that obliged entities shall consider applying to mitigate such risks.

2.   AMLA shall review the guidelines referred to in paragraph 1 at least every 2 years.

3.   When issuing and reviewing the guidelines referred to in paragraph 1, AMLA shall take into account evaluations, assessments or reports of Union institutions, bodies, offices and agencies, international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing.

SECTION 3

Simplified due diligence

Article 33

Simplified due diligence measures

1.   Where, taking into account the risk factors set out in Annexes II and III, the business relationship or transaction present a low degree of risk, obliged entities may apply the following simplified due diligence measures:

(a) verifying the identity of the customer and the beneficial owner after the establishment of the business relationship, provided that the specific lower risk identified justified such postponement, but in any case no later than 60 days of the relationship being established;

(b) reducing the frequency of customer identification updates;

(c) reducing the amount of information collected to identify the purpose and intended nature of the business relationship or occasional transaction or inferring it from the type of transactions or business relationship established;

(d) reducing the frequency or degree of scrutiny of transactions carried out by the customer;

(e) applying any other relevant simplified due diligence measure identified by AMLA pursuant to Article 28.

The measures referred to in the first subparagraph shall be proportionate to the nature and size of the business and to the specific elements of lower risk identified. However, obliged entities shall carry out sufficient monitoring of the transactions and business relationship to enable the detection of unusual or suspicious transactions.

2.   Obliged entities shall ensure that the internal procedures established pursuant to Article 9 contain the specific measures of simplified verification that shall be taken in relation to the different types of customers that present a lower risk. Obliged entities shall document decisions to take into account additional factors of lower risk.

3.   For the purpose of applying simplified due diligence measures referred to in paragraph 1, point (a), obliged entities shall adopt risk management procedures with respect to the conditions under which they can provide services or perform transactions for a customer prior to the verification taking place, including by limiting the amount, number or types of transactions that can be performed or by monitoring transactions to ensure that they are in line with the expected norms for the business relationship at hand.

4.   Obliged entities shall verify on a regular basis that the conditions for the application of simplified due diligence measures continue to exist. The frequency of such verifications shall be commensurate with the nature and size of the business and the risks posed by the specific relationship.

5.   Obliged entities shall refrain from applying simplified due diligence measures in any of the following situations:

(a) the obliged entities have doubts as to the veracity of the information provided by the customer or the beneficial owner at the stage of identification, or they detect inconsistencies regarding that information;

(b) the factors indicating a lower risk are no longer present;

(c) the monitoring of the customer’s transactions and the information collected in the context of the business relationship exclude a lower risk scenario;

(d) there is a suspicion of money laundering or terrorist financing;

(e) there is a suspicion that the customer, or the person acting on behalf of the customer, is attempting to circumvent or evade targeted financial sanctions.

SECTION 4

Enhanced due diligence

Article 34

Scope of application of enhanced due diligence measures

1.   In the cases referred to in Articles 29, 30, 31 and 36 to 46, as well as in other cases of higher risk that are identified by obliged entities pursuant to Article 20(2), second subparagraph, obliged entities shall apply enhanced due diligence measures to manage and mitigate such risks appropriately.

2.   Obliged entities shall examine the origin and destination of funds involved in, and the purpose of, all transactions that fulfil at least one of the following conditions:

(a) the transaction is of a complex nature;

(b) the transaction is unusually large;

(c) the transaction is conducted in an unusual pattern;

(d) the transaction does not have an apparent economic or lawful purpose.

3.   With the exception of the cases covered by Section 2 of this Chapter, when assessing the risks of money laundering and terrorist financing posed by a business relationship or occasional transaction, obliged entities shall take into account at least the factors of potential higher risk set out in Annex III and the guidelines adopted by AMLA pursuant to Article 32, as well as any other indicators of higher risk such as notifications issued by the FIU and findings of the business-wide risk assessment under Article 10.

4.   With the exception of the cases covered by Section 2 of this Chapter, in cases of higher risk as referred to in paragraph 1 of this Article, obliged entities shall apply enhanced due diligence measures, proportionate to the higher risks identified, which may include the following measures:

(a) obtaining additional information on the customer and the beneficial owners;

(b) obtaining additional information on the intended nature of the business relationship;

(c) obtaining additional information on the source of funds, and source of wealth of the customer and of the beneficial owners;

(d) obtaining information on the reasons for the intended or performed transactions and their consistency with the business relationship;

(e) obtaining the approval of senior management for establishing or continuing the business relationship;

(f) conducting enhanced monitoring of the business relationship by increasing the number and timing of controls applied, and selecting patterns of transactions that need further examination;

(g) requiring the first payment to be carried out through an account in the customer’s name with a credit institution subject to customer due diligence standards that are not less robust than those laid down in this Regulation.

5.   Where a business relationship that is identified as having a higher risk involves the handling of assets with a value of at least EUR 5 000 000, or the equivalent in national or foreign currency, through personalised services for a customer holding total assets with a value of at least EUR 50 000 000, or the equivalent in national or foreign currency, whether in financial, investable or real estate assets, or a combination thereof, excluding that customer’s private residence, credit institutions, financial institutions and trust or company service providers shall apply the following enhanced due diligence measures, in addition to any enhanced due diligence measure applied pursuant to paragraph 4:

(a) specific measures including procedures to mitigate risks associated with personalised services and products offered to that customer;

(b) obtaining additional information on that customer’s source of funds;

(c) preventing and managing conflicts of interest between the customer and senior management or employees of the obliged entity that undertake tasks related to that obliged entity’s compliance in relation to that customer.

By 10 July 2027, AMLA shall issue guidelines on the measures to be taken by credit institutions, financial institutions and trust or company service providers to establish whether a customer holds total assets with a value of at least EUR 50 000 000, or the equivalent in national or foreign currency, in financial, investable or real estate assets and how to determine that value.

6.   With the exception of the cases covered by Section 2 of this Chapter, where Member States identify cases of higher risks pursuant to Article 8 of Directive (EU) 2024/1640, including as a result of sectoral risk assessments carried out by the Member States, they may require obliged entities to apply enhanced due diligence measures and, where appropriate, specify those measures. Member States shall notify to the Commission and AMLA their decisions imposing enhanced due diligence requirements upon obliged entities established in their territory within 1 month of their adoption, accompanied by a justification of the money laundering and terrorist financing risks underpinning such decision.

Where the risks identified by Member States pursuant to the first subparagraph are likely to stem from outside the Union and may affect the Union’s financial system, AMLA shall, upon a request from the Commission or on its own initiative, consider updating the guidelines adopted pursuant to Article 32.

7.   The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement this Regulation where it identifies additional cases of higher risk as referred to in paragraph 1 of this Article that affect the Union as a whole and enhanced due diligence measures that obliged entities are to apply in those cases, taking into account the notifications by Member States pursuant to paragraph 6, first subparagraph, of this Article.

8.   Enhanced due diligence measures shall not be invoked automatically with respect to branches or subsidiaries of obliged entities established in the Union which are located in third countries referred to in Articles 29, 30 and 31 where those branches or subsidiaries fully comply with the group-wide policies, procedures and controls in accordance with Article 17.

Article 35

Countermeasures to mitigate money laundering and terrorist financing threats from outside the Union

For the purposes of Articles 29 and 31, the Commission may choose from among the following countermeasures:

(a) countermeasures that obliged entities are to apply to persons and legal entities involving high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in:; (i) the application of additional elements of enhanced due diligence;; (ii) the introduction of enhanced relevant reporting mechanisms or systematic reporting of financial transactions;; (iii) the limitation of business relationships or transactions with natural persons or legal entities from those third countries;

(b) countermeasures that Member States are to apply with regard to high-risk third countries and, where relevant, other countries posing a threat to the Union’s financial system consisting in:; (i) refusing the establishment of subsidiaries or branches or representative offices of obliged entities from the country concerned, or otherwise taking into account the fact that the relevant obliged entity is from a third country that does not have adequate AML/CFT regimes;; (ii) prohibiting obliged entities from establishing branches or representative offices in the third country concerned, or otherwise taking into account the fact that the relevant branch or representative office would be in a third country that does not have adequate AML/CFT regimes;; (iii) requiring increased supervisory examination or increased external audit requirements for branches and subsidiaries of obliged entities located in the third country concerned;; (iv) requiring increased external audit requirements for financial groups with respect to any of their branches and subsidiaries located in the third country concerned;; (v) requiring credit institutions and financial institutions to review and amend, or if necessary terminate, correspondent relationships with respondent institutions in the third country concerned.

Article 36

Specific enhanced due diligence measures for cross-border correspondent relationships

With respect to cross-border correspondent relationships, including relationships established for securities transactions or fund transfers, involving the execution of payments with a third-country respondent institution, in addition to the customer due diligence measures laid down in Article 20, credit institutions and financial institutions shall, when entering into a business relationship, be required to:

(a) gather sufficient information about the respondent institution to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the institution and the quality of supervision;

(b) assess the respondent institution’s AML/CFT controls;

(c) obtain approval from senior management before establishing new correspondent relationships;

(d) document the respective responsibilities of each institution;

(e) with respect to payable-through accounts, be satisfied that the respondent institution has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent institution, and that it is able to provide relevant customer due diligence data to the correspondent institution, upon request.

Where credit institutions and financial institutions decide to terminate cross-border correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision.

Article 37

Specific enhanced due diligence measures for cross-border correspondent relationships for crypto-asset service providers

1.   By way of derogation from Article 36, with respect to cross-border correspondent relationships involving the execution of crypto-asset services, with a respondent entity not established in the Union and providing similar services, including transfers of crypto-assets, crypto-asset service providers shall, in addition to the customer due diligence measures laid down in Article 20, when entering into a business relationship, be required to:

(a) determine if the respondent entity is licensed or registered;

(b) gather sufficient information about the respondent entity to understand fully the nature of the respondent’s business and to determine from publicly available information the reputation of the entity and the quality of supervision;

(c) assess the respondent entity’s AML/CFT controls;

(d) obtain approval from senior management before establishing the new correspondent relationship;

(e) document the respective responsibilities of each party to the correspondent relationship;

(f) with respect to payable-through crypto-asset accounts, be satisfied that the respondent entity has verified the identity of, and performed ongoing due diligence on, the customers having direct access to accounts of the correspondent entity, and that it is able to provide relevant customer due diligence data to the correspondent entity, upon request.

Where crypto-asset service providers decide to terminate correspondent relationships for reasons relating to AML/CFT policy, they shall document their decision.

Crypto-asset service providers shall update the due diligence information for the correspondent relationship on a regular basis or when new risks emerge in relation to the respondent entity.

2.   Crypto-asset service providers shall take into account the information collected pursuant to paragraph 1 in order to determine, on a risk sensitive basis, the appropriate measures to be taken to mitigate the risks associated with the respondent entity.

3.   By 10 July 2027, AMLA shall issue guidelines to specify the criteria and elements that crypto-asset service providers shall take into account for conducting the assessment referred to in paragraph 1 and the risk mitigating measures referred to in paragraph 2, including the minimum action to be taken by crypto-asset service providers upon identification that the respondent entity is not registered or licensed.

Article 38

Specific measures for individual third-country respondent institutions

1.   Credit institutions and financial institutions shall apply the measures laid down in paragraph 6 of this Article in relation to third-country respondent institutions with which they have a correspondent relationship pursuant to Articles 36 or 37 and in respect of which AMLA issues a recommendation pursuant to paragraph 2 of this Article.

2.   AMLA shall issue a recommendation addressed to credit institutions and financial institutions where there are concerns that respondent institutions in third countries fall into any of the following situations:

(a) they are in serious, repeated or systematic breach of AML/CFT requirements;

(b) they have weaknesses in their internal policies, procedures and controls that are likely to result in serious, repeated or systematic breaches of AML/CFT requirements;

(c) they have in place internal policies, procedures and controls that are not commensurate with the risks of money laundering, its predicate offences and terrorist financing to which the third-country respondent institution is exposed.

3.   The recommendation referred to in paragraph 2 shall be issued where all of the following conditions are met:

(a) on the basis of the information available in the context of its supervisory activities, a financial supervisor, including AMLA when performing its supervisory activities, deems that a third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship;

(b) following an assessment of the information available to the financial supervisor referred to in point (a) of this paragraph, there is an agreement among financial supervisors in the Union that the third-country respondent institution falls into any of the situations listed in paragraph 2 and may affect the risk exposure of the correspondent relationship.

4.   Prior to issuing the recommendation referred to in paragraph 2, AMLA shall consult the third-country supervisor in charge of the respondent institution and request that it provides its own as well as the respondent institution’s views on the adequacy of AML/CFT policies, procedures and controls as well as of the customer due diligence measures the respondent institution has in place to mitigate risks of money laundering, its predicate offences and terrorist financing and remedial measures to be put in place. Where no reply is provided within 2 months or where the reply provided does not indicate that the third-country respondent institution can implement satisfactory AML/CFT policies, procedures and controls as well as apply adequate customer due diligence measures to mitigate the risks to which it is exposed that may affect the correspondent relationship, AMLA shall proceed with the recommendation.

5.   AMLA shall withdraw the recommendation referred to in paragraph 2 as soon as it considers that a third-country respondent institution on which it adopted that recommendation no longer fulfils the conditions laid down in paragraph 3.

6.   In relation to third-country respondent institutions referred to in paragraph 1, credit institutions and financial institutions shall:

(a) abstain from entering into new business relationships with the third-country respondent institution unless they conclude, on the basis of the information collected under Article 36 or 37, that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship;

(b) for ongoing business relationships with the third-country respondent institution:; (i) review and update the information on the respondent institution pursuant to Articles 36 or 37;; (ii) terminate the business relationship unless they conclude, on the basis of the information collected under point (i), that the mitigating measures applied to the business relationship with the third-country respondent institution and the measures in place in the third-country respondent institution can adequately mitigate the money laundering and terrorist financing risks associated with that business relationship;

(c) inform the respondent institution of the conclusions they have drawn in relation to the risks posed by the correspondent relationship following the recommendation by AMLA and the measures taken pursuant to points (a) or (b).

Where AMLA has withdrawn a recommendation pursuant to paragraph 5, credit institutions and financial institutions shall review their assessment as to whether the third-country respondent institutions fulfil any of the conditions laid down in paragraph 3.

7.   Credit institutions and financial institutions shall document any decision taken pursuant to this Article.

Article 39

Prohibition of correspondent relationships with shell institutions

1.   Credit institutions and financial institutions shall not enter into, or continue, a correspondent relationship with a shell institution. Credit institutions and financial institutions shall take appropriate measures to ensure that they do not engage in or continue correspondent relationships with a credit institution or financial institution that is known to allow its accounts to be used by a shell institution.

2.   In addition to the requirement laid down in paragraph 1, crypto-asset service providers shall ensure that their accounts are not used by shell institutions to provide crypto-asset services. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls to detect any attempt to use their accounts for the provision of unregulated crypto-asset services.

Article 40

Measures to mitigate risks in relation to transactions with a self-hosted address

1.   Crypto-asset service providers shall identify and assess the risk of money laundering and financing of terrorism associated with transfers of crypto-assets directed to or originating from a self-hosted address. To that end, crypto-asset service providers shall have in place internal policies, procedures and controls.

Crypto-asset service providers shall apply mitigating measures commensurate with the risks identified. Those mitigating measures shall include one or more of the following:

(a) taking risk-based measures to identify, and verify the identity of, the originator or beneficiary of a transfer made from or to a self-hosted address or beneficial owner of such originator or beneficiary, including through reliance on third parties;

(b) requiring additional information on the origin and destination of the crypto-assets;

(c) conducting enhanced ongoing monitoring of transactions with a self-hosted address;

(d) any other measure to mitigate and manage the risks of money laundering and financing of terrorism as well as the risk of non-implementation and evasion of targeted financial sanctions.

2.   By 10 July 2027, AMLA shall issue guidelines to specify the mitigating measures referred to in paragraph 1, including:

(a) the criteria and means for identification and verification of the identity of the originator or beneficiary of a transfer made from or to a self-hosted address, including through reliance on third parties, taking into account the latest technological developments;

(b) criteria and means for the verification of whether or not the self-hosted address is owned or controlled by a customer.

Article 41

Specific provisions regarding applicants for residence by investment schemes

In addition to the customer due diligence measures laid down in Article 20, with respect to customers who are third-country nationals who are in the process of applying for residence rights in a Member State in exchange for any kind of investment, including transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity contributing to the public good and contributions to the state budget, obliged entities shall, as a minimum, apply enhanced due diligence measures set out in Article 34(4), points (a), (c), (e) and (f).

Article 42

Specific provisions regarding politically exposed persons

1.   In addition to the customer due diligence measures laid down in Article 20, obliged entities shall apply the following measures with respect to occasional transactions or business relationships with politically exposed persons:

(a) obtain senior management approval for carrying out occasional transactions or for establishing or continuing business relationships with politically exposed persons;

(b) take adequate measures to establish the source of wealth and source of funds that are involved in business relationships or occasional transactions with politically exposed persons;

(c) conduct enhanced, ongoing monitoring of those business relationships.

2.   By 10 July 2027, AMLA shall issue guidelines on the following matters:

(a) the criteria for the identification of persons known to be close associates;

(b) the level of risk associated with a particular category of politically exposed person, family member or person known to be a close associate, including guidance on how such risks are to be assessed where the person is no longer entrusted with a prominent public function for the purposes of Article 45.

Article 43

List of prominent public functions

1.   Each Member State shall issue and keep up-to-date a list indicating the exact functions which, in accordance with its national laws, regulations and administrative provisions, qualify as prominent public functions for the purposes of Article 2(1), point (34). Member States shall request each international organisation accredited on their territories to issue and keep up-to-date a list of prominent public functions at that international organisation for the purposes of Article 2(1), point (34). Those lists shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Member State level. Member States shall notify those lists, as well as any change made to them, to the Commission and to AMLA.

2.   The Commission may set out, by means of an implementing act, the format for the establishment and communication of the Member States’ lists of prominent public functions pursuant to paragraph 1. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

3.   The Commission is empowered to adopt delegated acts in accordance with Article 85 to supplement Article 2(1), point (34), where the lists notified by Member States pursuant to paragraph 1 identify common additional categories of prominent public functions and those categories of prominent public functions are of relevance for the Union as a whole.

When drawing up delegated acts pursuant to the first subparagraph, the Commission shall consult AMLA.

4.   The Commission shall draw up and keep up-to-date the list of the exact functions which qualify as prominent public functions at the level of the Union. That list shall also include any function which may be entrusted to representatives of third countries and of international bodies accredited at Union level.

5.   The Commission shall assemble, based on the lists provided for in paragraphs 1 and 4 of this Article, a single list of all prominent public functions for the purposes of Article 2(1), point (34). The Commission shall publish that single list in the Official Journal of the European Union. AMLA shall make that list publicly available on its website.

Article 44

Politically exposed persons who are beneficiaries of insurance policies

Obliged entities shall take reasonable measures to determine whether the beneficiaries of a life or other investment-related insurance policy or, where relevant, the beneficial owner of the beneficiary are politically exposed persons. Those measures shall be taken no later than at the time of the payout or at the time of the assignment, in whole or in part, of the policy. Where there are higher risks identified, in addition to applying the customer due diligence measures laid down in Article 20, obliged entities shall:

(a) inform senior management before payout of policy proceeds;

(b) conduct enhanced scrutiny of the entire business relationship with the policyholder.

Article 45

Measures for persons who cease to be politically exposed persons

1.   Where a politically exposed person is no longer entrusted with a prominent public function by the Union, a Member State, third country or an international organisation, obliged entities shall take into account the continuing risk posed by that person, as a result of his or her former function, in their assessment of money laundering and terrorist financing risks in accordance with Article 20.

2.   Obliged entities shall apply one or more of the measures referred to in Article 34(4) to mitigate the risks posed by the politically exposed person until such time as the risks referred to in paragraph 1 of this Article no longer exist, but in any case for not less than 12 months following the time when the individual ceased to be entrusted with a prominent public function.

3.   The obligation referred to in paragraph 2 shall apply accordingly where an obliged entity carries out an occasional transaction or enters into a business relationship with a person who in the past was entrusted with a prominent public function by the Union, a Member State, third country or an international organisation.

Article 46

Family members and persons known to be close associates of politically exposed persons

The measures referred to in Articles 42, 44 and 45 shall also apply to family members or persons known to be close associates of politically exposed persons.

SECTION 5

Specific customer due diligence provisions

Article 47

Specifications for the life and other investment-related insurance sector

For life or other investment-related insurance business, in addition to the customer due diligence measures required for the customer and the beneficial owner, obliged entities shall apply the following customer due diligence measures on the beneficiaries of life insurance and other investment-related insurance policies, as soon as the beneficiaries are identified or designated:

(a) in the case of beneficiaries that are identified as specifically named persons or legal arrangements, recording the name of the person or arrangement;

(b) in the case of beneficiaries that are designated by characteristics or by class or by other means, obtaining sufficient information concerning those beneficiaries so that it will be able to establish the identity of the beneficiary at the time of the payout.

For the purposes of the first subparagraph, the verification of the identity of the beneficiaries and, where relevant, their beneficial owners shall take place at the time of the payout. In the case of assignment, in whole or in part, of the life or other investment-related insurance to a third party, obliged entities aware of the assignment shall identify the beneficial owner at the time of the assignment to the natural or legal person or legal arrangement receiving for its own benefit the value of the policy assigned.

SECTION 6

Reliance on customer due diligence performed by other obliged entities

Article 48

General provisions relating to reliance on other obliged entities

1.   Obliged entities may rely on other obliged entities, whether located in a Member State or in a third country, to meet the customer due diligence requirements laid down in Article 20(1), points (a), (b) and (c), provided that:

(a) the other obliged entities apply customer due diligence requirements and record-keeping requirements laid down in this Regulation, or equivalent when the other obliged entities reside or are established in a third country;

(b) compliance with AML/CFT requirements by the other obliged entities is supervised in a manner consistent with Chapter IV of Directive (EU) 2024/1640.

The ultimate responsibility for meeting the customer due diligence requirements shall remain with the obliged entity which relies on another obliged entity.

2.   When deciding to rely on other obliged entities located in third countries, obliged entities shall take into consideration the geographical risk factors listed in Annexes II and III and any relevant information or guidance provided by the Commission, or by AMLA or other competent authorities.

3.   In the case of obliged entities that are part of a group, compliance with the requirements of this Article and of Article 49 may be ensured through group-wide policies, procedures and controls provided that all the following conditions are met:

(a) the obliged entity relies on information provided solely by an obliged entity that is part of the same group;

(b) the group applies AML/CFT policies and procedures, customer due diligence measures and rules on record-keeping that are fully in compliance with this Regulation, or with equivalent rules in third countries;

(c) the effective implementation of the requirements referred to in point (b) of this paragraph is supervised at group level by the supervisory authority of the home Member State in accordance with Chapter IV of Directive (EU) 2024/1640 or of the third country in accordance with the rules of that third country.

4.   Obliged entities shall not rely on obliged entities established in third countries identified pursuant to Section 2 of this Chapter. However, obliged entities established in the Union whose branches and subsidiaries are established in those third countries may rely on those branches and subsidiaries, where all the conditions laid down in paragraph 3, are met.

Article 49

Process of reliance on another obliged entity

1.   Obliged entities shall obtain from the obliged entity relied upon all the necessary information concerning the customer due diligence measures laid down in Article 20(1), points (a), (b) and (c), or the business being introduced.

2.   Obliged entities which rely on other obliged entities shall take all necessary steps to ensure that the obliged entity relied upon provides, upon request:

(a) copies of the information collected to identify the customer;

(b) all supporting documents or trustworthy sources of information that were used to verify the identity of the client, and, where relevant, of the customer’s beneficial owners or persons on whose behalf the customer acts, including data obtained through electronic identification means and relevant trust services as set out in Regulation (EU) No 910/2014; and

(c) any information collected on the purpose and intended nature of the business relationship.

3.   The information referred to in paragraphs 1 and 2 shall be provided by the obliged entity relied upon without delay and in any case within 5 working days.

4.   The conditions for the transmission of the information and documents mentioned in paragraphs 1 and 2 shall be specified in a written agreement between the obliged entities.

5.   Where the obliged entity relies on an obliged entity that is part of its group, the written agreement may be replaced by an internal procedure established at group level, provided that the conditions laid down in Article 48(3) are met.

Article 50

Guidelines on reliance on other obliged entities

By 10 July 2027, AMLA shall issue guidelines addressed to obliged entities on:

(a) the conditions which are acceptable for obliged entities to rely on information collected by another obliged entity, including in the case of remote customer due diligence;

(b) the roles and responsibility of the obliged entities involved in a situation of a reliance on another obliged entity;

(c) supervisory approaches to reliance on other obliged entities.

CHAPTER IV

BENEFICIAL OWNERSHIP TRANSPARENCY

Article 51

Identification of beneficial owners for legal entities

Beneficial owners of legal entities shall be the natural persons who:

(a) have, directly or indirectly, an ownership interest in the corporate entity; or

(b) control, directly or indirectly, the corporate or other legal entity, through ownership interest or via other means.

Control via other means as referred to in the first paragraph, point (b), shall be identified independently of and in parallel to the existence of an ownership interest or control through ownership interest.

Article 52

Beneficial ownership through ownership interest

1.   For the purpose of Article 51, first paragraph, point (a), ‘an ownership interest in the corporate entity’ shall mean direct or indirect ownership of 25 % or more of the shares or voting rights or other ownership interest in the corporate entity, including rights to a share of profits, other internal resources or liquidation balance. The indirect ownership shall be calculated by multiplying the shares or voting rights or other ownership interests held by the intermediate entities in the chain of entities in which the beneficial owner holds shares or voting rights and by adding together the results from those various chains, unless Article 54 applies.

For the purposes of assessing whether an ownership interest exists in the corporate entity, all shareholdings on every level of ownership shall be taken into account.

2.   Where Member States identify pursuant to Article 8(4), point (c), of Directive (EU) 2024/1640 categories of corporate entities that are exposed to higher money laundering and terrorist financing risks, including based on the sectors in which they operate, they shall inform the Commission thereof. By 10 July 2029, the Commission shall assess whether the risks associated with those categories of legal entities are relevant for the internal market and, where it concludes that a lower threshold is appropriate to mitigate those risks, adopt delegated acts in accordance with Article 85 to amend this Regulation by identifying:

(a) the categories of corporate entities that are associated with higher money laundering and terrorist financing risks and for which a lower threshold shall apply;

(b) the related thresholds.

The lower threshold referred to in the first subparagraph shall be set at a maximum of 15 % of ownership interest in the corporate entity, unless the Commission concludes, on the basis of risk, that a higher threshold would be more proportionate, which shall in any case be set at less than 25 %.

3.   The Commission shall review the delegated act referred to in paragraph 2 on a regular basis to ensure that it identifies the relevant categories of corporate entities that are associated with higher risks, and that the related thresholds are commensurate with those risks.

4.   In the case of legal entities other than corporate entities, for which, having regard to their form and structure, it is not appropriate or possible to calculate ownership, the beneficial owners shall be the natural persons who control via other means, directly or indirectly, the legal entity, pursuant to Article 53(3) and (4), except where Article 57 applies.

Article 53

Beneficial ownership through control

1.   Control over a corporate or other legal entity shall be exercised through ownership interest or via other means.

2.   For the purposes of this Chapter, the following definitions apply:

(a) ‘control of the legal entity’ means the possibility to exercise, directly or indirectly, significant influence and impose relevant decisions within the legal entity;

(b) ‘indirect control of a legal entity’ means control of intermediate legal entities in the ownership structure or in various chains of the ownership structure, where the direct control is identified on each level of the structure;

(c) ‘control through ownership interest of the corporate entity’ means direct or indirect ownership of 50 % plus one of the shares or voting rights or other ownership interest in the corporate entity.

3.   Control of the legal entity via other means shall in any case include the possibility to exercise:

(a) in the case of a corporate entity, the majority of the voting rights in the corporate entity, whether or not shared by persons acting in concert;

(b) the right to appoint or remove a majority of the members of the board or the administrative, management or supervisory body or similar officers of the legal entity;

(c) relevant veto rights or decision rights attached to the share of the corporate entity;

(d) decisions regarding distribution of profit of the legal entity or leading to a shift in assets in the legal entity.

4.   In addition to paragraph 3, control of the legal entity may be exercised via other means. Depending on the particular situation of the legal entity and its structure, other means of control may include:

(a) formal or informal agreements with owners, members or the legal entities, provisions in the articles of association, partnership agreements, syndication agreements, or equivalent documents or agreements depending on the specific characteristics of the legal entity, as well as voting arrangements;

(b) relationships between family members;

(c) use of formal or informal nominee arrangements.

For the purpose of this paragraph, ‘formal nominee arrangement’ means a contract or an equivalent arrangement, between a nominator and a nominee, where the nominator is a legal entity or natural person that issues instructions to a nominee to act on their behalf in a certain capacity, including as a director or shareholder or settlor, and the nominee is a legal entity or natural person instructed by the nominator to act on their behalf.

Article 54

Coexistence of ownership interest and control in the ownership structure

Where corporate entities are owned through a multi-layered ownership structure, and in one or more chains of that structure the ownership interest and the control coexist in relation to different layers of the chain, the beneficial owners shall be:

(a) the natural persons who control, directly or indirectly, through ownership interest or via other means, legal entities that have a direct ownership interest in the corporate entity, whether individually or cumulatively;

(b) the natural persons who, whether individually or cumulatively, directly or indirectly, have an ownership interest in the corporate entity that controls, through ownership interest or via other means, the corporate entity, directly or indirectly.

Article 55

Ownership structures involving legal arrangements or similar legal entities

Where legal entities referred to in Article 57 or legal arrangements have an ownership interest in the corporate entity, whether individually or cumulatively, or control, directly or indirectly, the corporate entity, through ownership interest or via other means, the beneficial owners shall be the natural persons who are the beneficial owners of the legal entities referred to in Article 57 or of the legal arrangements.

Article 56

Notifications

Each Member State shall notify to the Commission by 10 October 2027 a list of the types of legal entities existing under its national law with beneficial owners identified in accordance with Article 51 and Article 52(4). That notification shall include the specific categories of entities, description of characteristics and, where applicable, legal basis under the national law of the Member State concerned. It shall also include an indication of whether, due to the specific form and structures of legal entities other than corporate entities, the mechanism under Article 63(4) applies, accompanied by a detailed justification of the reasons for that.

The Commission shall communicate the notification referred to in the first paragraph to other Member States.

Article 57

Identification of beneficial owners for legal entities similar to express trust

1.   In the case of legal entities other than those referred to in Article 51, similar to express trust, such as foundations, the beneficial owners shall be all the following natural persons:

(a) the founders;

(b) the members of the management body in its management function;

(c) the members of the management body in its supervisory function;

(d) the beneficiaries, unless Article 59 applies;

(e) any other natural person, who controls directly or indirectly the legal entity.

2.   In cases where legal entities referred to in paragraph 1 belong to multi-layered control structures, where any of the positions listed in paragraph 1 is held by a legal entity, beneficial owners of the legal entity referred to in paragraph 1 shall be:

(a) the natural persons listed in paragraph 1; and

(b) the beneficial owners of the legal entities that occupy any of the positions listed in paragraph 1.

3.   Member States shall notify to the Commission by 10 October 2027 a list of types of legal entities, of which the beneficial owners are identified in accordance with paragraph 1.

The notification referred to in the first subparagraph shall be accompanied by a description of:

(a) the form and basic features of those legal entities;

(b) the process through which they can be set up;

(c) the process for accessing basic information and beneficial ownership information on those legal entities;

(d) the websites at which the central registers containing information on beneficial owners of those legal entities can be consulted and contact details of the entities in charge of those registers.

4.   The Commission may adopt, by means of an implementing act, a list of types of legal entities governed by the law of Member States which should be subject to the requirements of this Article. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

Article 58

Identification of beneficial owners for express trusts and similar legal arrangements

1.   The beneficial owners of express trusts shall be all the following natural persons:

(a) the settlors;

(b) the trustees;

(c) the protectors, if any;

(d) the beneficiaries, unless Article 59 or 60 applies;

(e) any other natural persons exercising ultimate control over the express trust by means of direct or indirect ownership or by other means, including through a chain of control or ownership.

2.   The beneficial owners of other legal arrangements similar to express trusts shall be the natural persons holding equivalent or similar positions to those referred to in paragraph 1.

3.   Where legal arrangements belong to multi-layered control structures and where any of the positions listed in paragraph 1 is held by a legal entity, the beneficial owners of the legal arrangement shall be:

(a) the natural persons listed in paragraph 1; and

(b) the beneficial owners of the legal entities that occupy any of the positions listed in paragraph 1.

4.   Member States shall notify to the Commission by 10 October 2027 a list of types of legal arrangements similar to express trusts which are governed under their law.

The notification shall be accompanied by a description of:

(a) the form and basic features of those legal arrangements;

(b) the process through which those legal arrangements can be set up;

(c) the process for accessing basic information and beneficial ownership information on those legal arrangements;

(d) the websites at which the central registers containing information on beneficial owners of those legal arrangements can be consulted and the contact details of the entities in charge of those registers.

The notification shall also be accompanied by a justification detailing the reasons why the Member State considers the notified legal arrangements to be similar to express trusts and why it concluded that other legal arrangements governed under its law are not similar to express trusts.

5.   The Commission may adopt, by means of an implementing act, a list of types of legal arrangements governed under the law of Member States which should be subject to the same beneficial ownership transparency requirements as express trusts, accompanied by the information referred to in paragraph 4, second subparagraph of this Article. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 86(2).

Article 59

Identification of a class of beneficiaries

1.   In the case of legal entities similar to express trusts under Article 57 or, with the exception of discretionary trusts, express trusts and similar legal arrangements under Article 58, where beneficiaries have yet to be determined, the class of beneficiaries and its general characteristics shall be identified. Beneficiaries within the class shall be beneficial owners as soon as they are identified or designated.

2.   In the following cases, only the class of beneficiaries and its characteristics shall be identified:

(a) pension schemes within the scope of Directive (EU) 2016/2341;

(b) employee financial ownership or participation schemes, provided that Member States, following an appropriate risk assessment, have concluded a low risk of misuse for money laundering or terrorist financing;

(c) legal entities similar to express trusts under Article 57, express trusts and similar legal arrangements under Article 58, provided that:; (i) the legal entity, the express trust or similar legal arrangement is set up for a non-profit or charitable purpose; and; (ii) following an appropriate risk assessment, Member States have concluded that the category of legal entity, express trust or similar legal arrangement is at a low risk of misuse for money laundering or terrorist financing.

3.   Member State shall notify to the Commission the categories of legal entities, express trusts or similar legal arrangements under paragraph 2, together with a justification based on the specific risk assessment. The Commission shall communicate that notification to the other Member States.

Article 60

Identification of objects of a power and default takers in discretionary trusts

In the case of discretionary trusts, where beneficiaries have yet to be selected, the objects of a power and default takers shall be identified. Beneficiaries among the objects of a power shall be beneficial owners as soon as they are selected. Default takers shall be beneficial owners when the trustees fail to exercise their discretion.

Where discretionary trusts meet the conditions laid down in Article 59(2), only the class of objects of a power and default takers shall be identified. Those categories of discretionary trusts shall be notified to the Commission in accordance with paragraph 3 of that Article.

Article 61

Identification of beneficial owners of collective investment undertakings

By way of derogation from Article 51, first paragraph and Article 58(1), the beneficial owners of collective investment undertakings shall be the natural persons who fulfil one or more of the following conditions:

(a) they hold directly or indirectly 25 % or more of the units held in the collective investment undertaking;

(b) they have the ability to define or influence the investment policy of the collective investment undertaking;

(c) they control the activities of the collective investment undertaking through other means.

Article 62

Beneficial ownership information

1.   Legal entities and trustees of express trusts or persons holding equivalent positions in similar legal arrangements shall ensure that the beneficial ownership information which they hold, provide to obliged entities in the context of customer due diligence procedures in accordance with Chapter III or submit to central registers is adequate, accurate, and up-to-date.

The beneficial ownership information referred to in the first subparagraph shall include the following:

(a) all names and surnames, place and full date of birth, residential address, country of residence and nationality or nationalities of the beneficial owner, number of identity document, such as passport or national identity document, and, where it exists, unique personal identification number assigned to the person by his or her country of usual residence, and general description of the source of such number;

(b) the nature and extent of the beneficial interest held in the legal entity or legal arrangement, whether through ownership interest or control via other means, as well as the date as of which the beneficial interest is held;

(c) information on the legal entity of which the natural person is the beneficial owner in accordance with Article 22(1), point (b), or, in the case of legal arrangements of which the natural person is the beneficial owner, basic information on the legal arrangement;

(d) where the ownership and control structure contains more than one legal entity or legal arrangement, a description of such structure, including names and, where it exists, identification numbers of the individual legal entities or legal arrangements that are part of that structure, and a description of the relationships between them, including the share of the interest held;

(e) where a class of beneficiaries is identified under Article 59, general description of the characteristic of the class of beneficiaries;

(f) where objects of a power and default takers are identified under Article 60:; (i) for natural persons, their names and surnames;; (ii) for legal entities and legal arrangements, their names;; (iii) for a class of objects of a power or default takers, its description.

2.   Legal entities and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement shall obtain adequate, accurate, and up-to-date beneficial ownership information within 28 calendar days of the creation of the legal entity or the setting up of the legal arrangement. That information shall be updated promptly, and, in any case, within 28 calendar days of any change thereto, as well as on an annual basis.

Article 63

Obligations of legal entities

1.   All legal entities created in the Union shall obtain and hold adequate, accurate and up-to-date beneficial ownership information.

Legal entities shall provide, in addition to information about their legal owners, information on the beneficial owners to obliged entities where the obliged entities are applying customer due diligence measures in accordance with Chapter III.

2.   A legal entity shall report beneficial ownership information to the central register without undue delay after its creation. Any change to that information shall be reported to the central register without undue delay and, in any case, within 28 calendar days thereof. The legal entity shall regularly verify that it holds up-to-date information on its beneficial ownership. As a minimum, such verification shall be performed annually whether as a self-standing process or as part of other periodical processes, such as the submission of financial statement.

The beneficial owners of a legal entity as well as the legal entities and, in the case of legal arrangements, their trustees or persons holding an equivalent position, which are part of the ownership or control structure of a legal entity, shall provide that legal entity with all the information necessary for the legal entity to comply with the requirements of this Chapter or to respond to any request for additional information received pursuant to Article 10(4) of Directive (EU) 2024/1640.

3.   Where, having exhausted all possible means of identification pursuant to Articles 51 to 57, no person is identified as beneficial owner, or where there is substantial and justified uncertainty on the part of the legal entity that the persons identified are the beneficial owners, legal entities shall keep records of the actions taken in order to identify their beneficial owners.

4.   In the cases referred to in paragraph 3 of this Article, when providing beneficial ownership information in accordance with Article 20 of this Regulation and Article 10 of Directive (EU) 2024/1640, legal entities shall provide the following:

(a) a statement that there is no beneficial owner or that the beneficial owners could not be determined, accompanied by a justification as to why it was not possible to determine the beneficial owner in accordance with Articles 51 to 57 of this Regulation and what constitutes uncertainty about the ascertained information;

(b) the details of all natural persons who hold the position of senior managing officials in the legal entity equivalent to the information required under Article 62(1), second subparagraph, point (a) of this Regulation.

For the purpose of this paragraph, ‘senior managing officials’ means the natural persons who are the executive members of the management body, as well as the natural persons who exercise executive functions within a legal entity and are responsible, and accountable to the management body, for the day-to-day management of the entity.

5.   Legal entities shall make the information collected pursuant to this Article available, upon request and without delay, to competent authorities.

6.   The information referred to in paragraph 4 shall be maintained for 5 years after the date on which the legal entities are dissolved or otherwise cease to exist, whether by persons designated by the entity to retain the documents, or by administrators or liquidators or other persons involved in the dissolution of the entity. The identity and contact details of the person responsible for retaining the information shall be reported to the central registers.

Article 64

Trustee obligations

1.   In the case of any legal arrangement administered in a Member State or whose trustee or the person holding an equivalent position in a similar legal arrangement resides or is established in a Member State, trustees and persons holding an equivalent position in a similar legal arrangement shall obtain and hold the following information regarding the legal arrangement:

(a) basic information on the legal arrangement;

(b) adequate, accurate and up-to-date beneficial ownership information as provided under Article 62;

(c) where legal entities or legal arrangements are parties to the legal arrangement, basic information and beneficial ownership information on those legal entities and legal arrangements;

(d) information on any agent authorised to act on behalf of the legal arrangement or to take any action in relation to it, and on the obliged entities with which the trustee or person holding an equivalent position in a similar legal arrangement enter into a business relationship on behalf of the legal arrangement.

The information referred to in the first subparagraph shall be maintained for 5 years after the involvement of the trustee or the person holding an equivalent position with the express trust or similar legal arrangement ceases to exist.

2.   The trustee or the person holding an equivalent position in a similar legal arrangement shall obtain and report to the central register beneficial ownership information and basic information on the legal arrangement without undue delay after the setting up of the express trust or similar legal arrangement and, in any case, within 28 calendar days thereof. The trustee or the person holding an equivalent position in a similar legal arrangement shall ensure that any change of beneficial ownership or of the basic information on the legal arrangement is reported to the central register without undue delay, and in any case, within 28 calendar days thereof.

The trustee or the person holding an equivalent position in a similar legal arrangement shall regularly verify that the information they hold over the legal arrangement pursuant to paragraph 1, first subparagraph, is updated. Such verification shall be performed at least annually, whether as a self-standing process or as part of other periodical processes.

3.   The trustees or the persons holding an equivalent position in a similar legal arrangement referred to in paragraph 1 shall disclose their status and provide the information on the beneficial owners and on the assets of the legal arrangements that are to be managed in the context of a business relationship or occasional transaction to obliged entities when the obliged entities are applying customer due diligence measures in accordance with Chapter III.

4.   The beneficial owners of a legal arrangement other than the trustees or persons holding an equivalent position, its agents and the obliged entities servicing the legal arrangement, as well as any person and, in the case of legal arrangements, their trustees, who are part of the multi-layered control structure of the legal arrangement, shall provide the trustees or persons holding an equivalent position in a similar legal arrangement with all the information and documentation necessary for the trustees or persons holding an equivalent position to comply with the requirements of this Chapter.

5.   Trustees of an express trust and persons holding an equivalent position in a similar legal arrangement shall make the information collected pursuant to this Article available, upon request and without delay, to competent authorities.

6.   In the case of legal arrangements whose parties are legal entities, where, after having exhausted all possible means of identification pursuant to Articles 51 to 57, no person is identified as beneficial owner of those legal entities, or where there is substantial and justified uncertainty that the persons identified are the beneficial owners, trustees of express trusts or persons in an equivalent position in similar legal arrangements shall keep records of the actions taken in order to identify their beneficial owners.

7.   In the cases referred to in paragraph 6 of this Article, when providing beneficial ownership information in accordance with Article 20 of this Regulation and Article 10 of Directive (EU) 2024/1640, trustees of express trusts or persons in an equivalent position in similar legal arrangements shall provide the following:

(a) a statement that there is no beneficial owner or that the beneficial owners could not be determined, accompanied by a justification as to why it was not possible to determine the beneficial owner in accordance with Article 51 to 57 of this Regulation and what constitutes uncertainty about the ascertained information;

(b) the details of all natural persons who hold the position of senior managing officials in the legal entity that is party to the legal arrangement equivalent to the information required under Article 62(1), second subparagraph, point (a), of this Regulation.

Article 65

Exceptions to obligations of legal entities and legal arrangements

Articles 63 and 64 shall not apply to:

(a) companies whose securities are admitted to trading on a regulated market, provided that:; (i) control over the company is exercised exclusively by the natural person with the voting rights;; (ii) no other legal entities or legal arrangements are part of the company’s ownership or control structure; and; (iii) for foreign legal entities under Article 67, equivalent requirements to those referred to in subpoints (i) and (ii) of this point exist under international standards;

(b) bodies governed by public law as defined in Article 2(1), point (4), of Directive 2014/24/EU of the European Parliament and of the Council (43).

Article 66

Nominee obligations

Nominee shareholders and nominee directors of a legal entity shall maintain adequate, accurate and up-to-date information on the identity of their nominator and the nominator’s beneficial owners and disclose them, as well as their status, to the legal entity. Legal entities shall report that information to the central register.

Legal entities shall also report the information referred to in the first paragraph to obliged entities when the obliged entities are applying customer due diligence measures in accordance with Chapter III.

Article 67

Foreign legal entities and foreign legal arrangements

1.   Legal entities created outside the Union and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement that are administered outside the Union or that reside or are established outside the Union shall submit beneficial ownership information pursuant to Article 62 to the central register of the Member State where they:

(a) enter into a business relationship with an obliged entity;

(b) acquire real estate in the Union, whether directly or through intermediaries;

(c) acquire, whether directly or through intermediaries, any of the following goods from persons trading as referred to in Article 3, points (3) (f) and (j), in the context of an occasional transaction:; (i) motor vehicles for non-commercial purposes for a price of at least EUR 250 000 or the equivalent in national currency;; (ii) watercraft for non-commercial purposes for a price of at least EUR 7 500 000 or the equivalent in national currency;; (iii) aircraft for non-commercial purposes for a price of at least EUR 7 500 000 or the equivalent in national currency;

(d) are awarded a public contract for goods or services, or concessions by a contracting authority in the Union.

2.   By way of derogation from paragraph 1, point (a), where legal entities created outside the Union enter into a business relationship with an obliged entity, they shall only submit their beneficial ownership information to the central register where:

(a) they enter into a business relationship with an obliged entity that is associated with medium-high or high money laundering and terrorist financing risks pursuant to the risk assessment at Union level or the national risk assessment of the Member State concerned referred to in Articles 7 and 8 of Directive (EU) 2024/1640; or

(b) the risk assessment at Union level or the national risk assessment of the Member State concerned identifies that the category of legal entity or the sector in which the legal entity created outside the Union operates is associated, where relevant, with medium-high or high money laundering and terrorist financing risks.

3.   The beneficial ownership information shall be accompanied by a statement setting out in relation to which of those activities the information is submitted, as well as any relevant document, and shall be submitted:

(a) for the cases referred to in paragraph 1, point (a), prior to start of the business relationship;

(b) for the cases referred to in paragraph 1, points (b) and (c), before completion of the purchase;

(c) for the cases referred to in paragraph 1, point (d), before signature of the contract.

4.   For the purposes of paragraph 1, point (a), obliged entities shall inform the legal entities where the conditions laid down in paragraph 2 are met and require a certificate of proof of registration or an excerpt of the beneficial ownership information held in the central register to proceed with the business relationship or occasional transaction.

5.   In the cases covered by paragraph 1, legal entities created outside the Union and trustees of express trusts or persons holding an equivalent position in a similar legal arrangement that are administered outside the Union or that reside or are established outside the Union shall report any change to the beneficial ownership information submitted to the central register pursuant to paragraph 1 without undue delay, and in any case, within 28 calendar days thereof.

The first subparagraph shall apply:

(a) for the cases referred to in paragraph 1, point (a), for the entire duration of the business relationship with the obliged entity;

(b) for the cases referred to in paragraph 1, point (b), for as long as the legal entity or legal arrangement owns the real estate;

(c) for the cases referred to in paragraph 1, point (c), for the period between the initial submission of the information to the central register and the completion of the purchase;

(d) for the cases referred to in paragraph 1, point (d), for the entire duration of the contract.

6.   Where the legal entity, the trustee of the express trust or the person holding an equivalent position in a similar legal arrangement meets the conditions laid down in paragraph 1 in different Member States, a certificate of proof of registration of the beneficial ownership information in a central register held by one Member State shall be considered as sufficient proof of registration.

7.   Where, on 10 July 2027, legal entities created outside the Union or legal arrangements administered outside the Union or whose trustee or person holding an equivalent position in a similar legal arrangement resides or is established outside the Union own, whether directly or through intermediaries, real estate, the beneficial ownership information of those legal entities and legal arrangements shall be submitted to the central register and accompanied by a justification for that submission by 10 January 2028.

However, the first subparagraph shall not apply to legal entities or legal arrangements that have acquired real estate in the Union prior to 1 January 2014.

Member States may decide, on the basis of risk, that an earlier date applies and notify the Commission thereof. The Commission shall communicate such decisions to the other Member States.

8.   Member States may, on the basis of risk, extend the obligation set out in paragraph 1, point (a), to business relationships with foreign legal entities that are ongoing on 10 July 2027 and notify the Commission thereof. The Commission shall communicate such decisions to the other Member States.

Article 68

Penalties

1.   Member States shall lay down rules on the penalties applicable to breaches of the provisions of this Chapter and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive.

Member States shall by 10 January 2025 notify the Commission of those rules on penalties together with their legal basis and shall notify it, without delay, of any subsequent amendment affecting them.

2.   By 10 July 2026, the Commission shall adopt delegated acts in accordance with Article 85 to supplement this Regulation by defining:

(a) the categories of breaches that are subject to penalties and the persons liable for such breaches;

(b) indicators to classify the level of gravity of breaches that are subject to penalties;

(c) the criteria to be taken into account when setting the level of penalties.

The Commission shall regularly review the delegated act referred to in the first subparagraph to ensure that it identifies the relevant categories of breaches and that the related penalties are effective, dissuasive and proportionate.

CHAPTER V

REPORTING OBLIGATIONS

Article 69

Reporting of suspicions

1.   Obliged entities, and, where applicable, their directors and employees, shall cooperate fully with the FIU by promptly:

(a) reporting to the FIU, on their own initiative, where the obliged entity knows, suspects or has reasonable grounds to suspect that funds or activities, regardless of the amount involved, are the proceeds of criminal activity or are related to terrorist financing or criminal activity and by responding to requests by the FIU for additional information in such cases;

(b) providing the FIU, at its request, with all necessary information, including information on transaction records, within the deadlines imposed.

All suspicious transactions, including attempted transactions and suspicions arising from the inability to conduct customer due diligence shall be reported in accordance with the first subparagraph.

For the purposes of the first subparagraph, obliged entities shall reply to requests for information by the FIU within 5 working days. In justified and urgent cases, FIUs may shorten that deadline, including to less than 24 hours.

By way of derogation from the third subparagraph, the FIU may extend the deadline for a response beyond the 5 working days where it considers it justified and provided that the extension does not undermine the FIU’s analysis.

2.   For the purposes of paragraph 1, obliged entities shall assess transactions or activities carried out by their customers on the basis of and against any relevant fact and information known to them or which they are in possession of. Where necessary, obliged entities shall prioritise their assessment taking into consideration the urgency of the transaction or activity and the risks affecting the Member State in which they are established.

A suspicion pursuant to paragraph 1, point (a), shall be based on the characteristics of the customer and their counterparts, the size and nature of the transaction or activity or the methods and patterns thereof, the link between several transactions or activities, the origin, destination or use of funds, or any other circumstance known to the obliged entity, including the consistency of the transaction or activity with the information obtained pursuant to Chapter III including the risk profile of the client.

3.   By 10 July 2026, AMLA shall develop draft implementing technical standards and submit them to the Commission for adoption. Those draft implementing technical standards shall specify the format to be used for the reporting of suspicions pursuant to paragraph 1, point (a), and for the provision of transaction records pursuant to paragraph 1, point (b).

4.   Power is conferred on the Commission to adopt the implementing technical standards referred to in paragraph 3 of this Article in accordance with Article 53 of Regulation (EU) 2024/1620.

5.   By 10 July 2027, AMLA shall issue guidelines on indicators of suspicious activity or behaviours. Those guidelines shall be periodically updated.

6.   The compliance officer appointed in accordance with Article 11(2) shall transmit the information referred to in paragraph 1 of this Article to the FIU of the Member State in whose territory the obliged entity transmitting the information is established.

7.   Obliged entities shall ensure that the compliance officer appointed in accordance with Article 11(2), as well as any employee or person in a comparable position, including agents and distributors, involved in the performance of the tasks covered by this Article are protected against retaliation, discrimination and any other unfair treatment for carrying out those tasks.

This paragraph shall not affect the protection that the persons referred to in the first subparagraph may be entitled to under Directive (EU) 2019/1937.

8.   Where the activities of a partnership for information sharing result in the knowledge, suspicion or reasonable grounds to suspect that funds, regardless of the amount involved, are the proceeds of criminal activity or are related to terrorist financing, obliged entities which identified suspicions in relation to the activities of their customers may designate one among them which shall be tasked with the submission of a report to the FIU pursuant to paragraph 1, point (a). Such submission shall include at least the name and contact details of all the obliged entities that participated in the activities giving rise to the report.

Where the obliged entities referred to in the first subparagraph are established in several Member States, the information shall be reported to each relevant FIU. To that end, obliged entities shall ensure that the report is submitted by an obliged entity within the territory of the Member States where the FIU is located.

Where the obliged entities decide not to avail themselves of the possibility to submit a single report with the FIU pursuant to the first subparagraph, they shall include a reference in their reports to the fact that the suspicion is the result of the activities of a partnership for information sharing.

9.   The obliged entities referred to in paragraph 8 of this Article shall retain a copy of any reports submitted pursuant to that paragraph in accordance with Article 77.

Article 70

Specific provisions for reporting of suspicions by certain categories of obliged entities

1.   By way of derogation from Article 69(1), Member States may allow obliged entities referred to in Article 3, point (3)(a) and (b), to transmit the information referred to in Article 69(1) to a self-regulatory body designated by the Member State.

The designated self-regulatory body shall forward the information referred to in the first subparagraph to the FIU promptly and unfiltered.

2.   Notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors shall be exempted from the requirements laid down in Article 69(1) to the extent that such exemption relates to information that they receive from, or obtain on a client, in the course of ascertaining the legal position of that client, or performing their task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, regardless of whether such information is received or obtained before, during or after such proceedings.

The exemption set out in the first subparagraph shall not apply when the obliged entities referred to therein:

(a) take part in money laundering, its predicate offences or terrorist financing;

(b) provide legal advice for the purposes of money laundering, its predicate offences or terrorist financing; or

(c) know that the client is seeking legal advice for the purposes of money laundering, its predicate offences or terrorist financing; knowledge or purpose may be inferred from objective factual circumstances.

3.   In addition to the situations referred to in paragraph 2, second subparagraph, where justified on the basis of the higher risks of money laundering, its predicate offences or terrorist financing associated with certain types of transactions, Member States may decide that the exemption referred to in paragraph 2, first subparagraph, does not apply to those types of transactions and, as appropriate, impose additional reporting obligations on the obliged entities referred to in that paragraph. Member States shall notify the Commission of any decision taken pursuant to this paragraph. The Commission shall communicate such decisions to the other Member States.

Article 71

Refraining from carrying out transactions

1.   Obliged entities shall refrain from carrying out transactions which they know or suspect to be related to proceeds of criminal activity or to terrorist financing until they have submitted a report in accordance with Article 69(1), first subparagraph, point (a), and have complied with any further specific instructions from the FIU or other competent authority in accordance with the applicable law. Obliged entities may carry out the transaction concerned after having assessed the risks of proceeding with the transaction if they have not received instructions to the contrary from the FIU within 3 working days of submitting the report.

2.   Where it is not possible for an obliged entity to refrain from carrying out a transaction as referred to in paragraph 1or where refraining would be likely to frustrate efforts to pursue the beneficiaries of a suspected transaction, the obliged entity shall inform the FIU immediately after carrying out the transaction.

Article 72

Disclosure to FIU

Disclosure of information to the FIU in good faith by an obliged entity or by an employee or director of such an obliged entity in accordance with Articles 69 and 70 shall not constitute a breach of any restriction on disclosure of information imposed by contract or by any legislative, regulatory or administrative provision, and shall not involve the obliged entity or its directors or employees in liability of any kind even in circumstances where they were not precisely aware of the underlying criminal activity and regardless of whether illegal activity actually occurred.

Article 73

Prohibition of disclosure

1.   Obliged entities and their directors, employees, or persons in comparable positions, including agents and distributors, shall not disclose to the customer concerned or to other third persons the fact that transactions or activities are being or have been assessed in accordance with Article 69, that information is being, will be or has been transmitted in accordance with Article 69 or 70 or that a money laundering or terrorist financing analysis is being, or may be, carried out.

2.   Paragraph 1 shall not apply to disclosures to competent authorities and to self-regulatory bodies where they perform supervisory functions, or to disclosure for the purposes of investigating and prosecuting money laundering, terrorist financing and other criminal activity.

3.   By way of derogation from paragraph 1 of this Article, disclosure may take place between obliged entities that belong to the same group, or between such entities and their branches and subsidiaries established in third countries, provided that those branches and subsidiaries fully comply with the group-wide policies and procedures, including procedures for sharing information within the group, in accordance with Article 16, and that the group-wide policies and procedures comply with the requirements set out in this Regulation.

4.   By way of derogation from paragraph 1 of this Article, disclosure may take place between obliged entities as referred to in Article 3, point (3)(a) and (b), or entities from third countries which impose requirements equivalent to those laid down in this Regulation, who perform their professional activities, whether as employees or not, within the same legal person or a larger structure to which the person belongs and which shares common ownership, management or compliance control, including networks or partnerships.

5.   For obliged entities referred to in Article 3, points (1), (2), (3)(a) and (b), in cases relating to the same transaction involving two or more obliged entities, and by way of derogation from paragraph 1 of this Article, disclosure may take place between the relevant obliged entities provided that they are located in the Union, or with entities in a third country which imposes requirements equivalent to those laid down in this Regulation, and that they are subject to professional secrecy and personal data protection requirements.

6.   Where the obliged entities referred to in Article 3, point (3)(a) and (b), seek to dissuade a client from engaging in illegal activity, that shall not constitute disclosure within the meaning of paragraph 1 of this Article.

Article 74

Threshold-based reports of transactions in certain high-value goods

1.   Persons trading in high-value goods shall report to the FIU all transactions involving the sale of the following high-value goods when those goods are acquired for non-commercial purposes:

(a) motor vehicles for a price of at least EUR 250 000 or the equivalent in national currency;

(b) watercraft for a price of at least EUR 7 500 000 or the equivalent in national currency;

(c) aircraft for a price of at least EUR 7 500 000 or the equivalent in national currency.

2.   Credit institutions and financial institutions that provide services in relation to the purchase or transfer of ownership of the goods referred to in paragraph 1 shall also report to the FIU all transactions they carry out for their customers in relation to those goods.

3.   Reporting pursuant to paragraphs 1 and 2 shall be carried out within the deadlines imposed by the FIU.

CHAPTER VI

INFORMATION SHARING

Article 75

Exchange of information in the framework of partnerships for information sharing

1.   Members of partnerships for information sharing may share information among each other where strictly necessary for the purposes of complying with the obligations under Chapter III and Article 69 and in accordance with fundamental rights and judicial procedural safeguards.

2.   Obliged entities intending to participate in a partnership for information sharing shall notify their respective supervisory authorities which shall, where relevant in consultation with each other and with the authorities in charge of verifying compliance with Regulation (EU) 2016/679, verify that the partnership for information sharing has mechanisms in place to ensure compliance with this Article and that the data protection impact assessment referred to in paragraph 4, point (h), has been carried out. The verification shall take place prior to the beginning of the activities of the partnership for information sharing. Where relevant, the supervisory authorities shall also consult the FIUs.

Responsibility for compliance with requirements under Union or national law shall remain with the participants in the partnership for information sharing.

3.   Information exchanged in the framework of a partnership for information sharing shall be limited to:

(a) information on the customer, including any information obtained in the course of identifying and verifying the identity of the customer and, where relevant, the beneficial owner of the customer;

(b) information on the purpose and intended nature of the business relationship or occasional transaction between the customer and the obliged entity, as well as, where applicable, the source of wealth and source of funds of the customer;

(c) information on customer transactions;

(d) information on higher and lower risk factors associated with the customer;

(e) the obliged entity’s analysis of the risks associated with the customer pursuant to Article 20(2);

(f) information held by the obliged entity pursuant to Article 77(1);

(g) information on suspicions pursuant to Article 69.

The information referred to in the first subparagraph shall only be exchanged to the extent that it is necessary for the purposes of carrying out the activities of the partnership for information sharing.

4.   The following conditions shall apply to the sharing of information within the context of a partnership for information sharing:

(a) obliged entities shall record all instances of information sharing within the partnership;

(b) obliged entities shall not rely solely on the information received in the context of the partnership to comply with the requirements of this Regulation;

(c) obliged entities shall not draw conclusions or take decisions that have an impact on the business relationship with the customer or on the performance of occasional transactions for the customer on the basis of information received from other participants in the partnership for information sharing without having assessed that information; any information received in the context of the partnership that is used in an assessment resulting in a decision to refuse or terminate a business relationship or to carry out an occasional transaction shall be included in the records kept pursuant to Article 21(3), and that record shall contain reference to the fact that the information originated from a partnership for information sharing;

(d) obliged entities shall carry out their own assessment of transactions involving customers in order to assess which ones may be related to money laundering or terrorist financing or involve proceeds of criminal activity;

(e) obliged entities shall implement appropriate technical and organisational measures, including measures to allows pseudonymisation, to ensure a level of security and confidentiality proportionate to the nature and extent of the information exchanged;

(f) the sharing of information shall be carried out only in relation to customers:; (i) whose behaviour or transaction activities are associated with a higher risk of money laundering, its predicate offences or terrorist financing, as identified pursuant to the risk assessment at Union level and the national risk assessment carried out in accordance with Articles 7 and 8 of Directive (EU) 2024/1640;; (ii) who fall under any of the situations referred to in Articles 29, 30, 31 and 36 to 46 of this Regulation; or; (iii) for whom the obliged entities need to collect additional information in order to determine whether they are associated with a higher level of risk of money laundering, its predicate offences or terrorist financing;

(g) information generated through the use of artificial intelligence, machine learning technologies or algorithms may only be shared where those processes were subject to adequate human oversight;

(h) a data protection impact assessment referred to in Article 35 of Regulation (EU) 2016/679 shall be carried out prior to the processing of any personal data;

(i) the competent authorities that are members of a partnership for information sharing shall only obtain, provide and exchange information to the extent that this is necessary for the performance of their tasks under relevant Union or national law;

(j) where competent authorities referred to in Article 2(1), point (44)(c), of this Regulation participate in a partnership for information sharing, they shall only obtain, provide or exchange personal data and operational information in accordance with national law transposing Directive (EU) 2016/680 of the European Parliament and of the Council (44) and with the applicable provisions of national criminal procedural law, including prior judicial authorisation or any other national procedural safeguard as required;

(k) the exchange of information on suspicious transactions pursuant to paragraph 3, point (g), of this Article shall only take place where the FIU to which the suspicious transaction report was submitted pursuant to Articles 69 or 70 has agreed with such disclosure.

5.   Information received in the context of a partnership for information sharing shall not be further transmitted, except where:

(a) the information is provided to another obliged entity pursuant to Article 49(1);

(b) the information is to be included in a report submitted to the FIU or provided in response to a FIU request pursuant to Article 69(1);

(c) the information is provided to AMLA pursuant to Article 93 of Regulation (EU) 2024/1620;

(d) the information is requested by law enforcement or judicial authorities, subject to any prior authorisations or other procedural guarantees as required under the national law.

6.   Obliged entities that participate in partnerships for information sharing shall define policies and procedures for the sharing of information in their internal policies and procedures established pursuant to Article 9. Such policies and procedures shall:

(a) specify the assessment to be carried out to determine the extent of information to be shared, and where relevant for the nature of the information or the applicable judicial safeguards, provide for differentiated or limited access to information for members of the partnership;

(b) describe the roles and responsibilities of the parties to the partnership for information-sharing;

(c) identify the risk assessments that the obliged entity will take into account to determine situations of higher risk in which information can be shared.

The internal policies and procedures referred to in the first subparagraph shall be drawn up prior to the participation in a partnership for information sharing.

7.   Where supervisory authorities deem it necessary, obliged entities participating in a partnership for information sharing shall commission an independent audit of the functioning of that partnership and shall share the results with the supervisory authorities.

CHAPTER VII

DATA PROTECTION AND RECORD RETENTION

Article 76

Processing of personal data

1.   To the extent that it is strictly necessary for the purposes of preventing money laundering and terrorist financing, obliged entities may process special categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679 and personal data relating to criminal convictions and offences referred to in Article 10 of that Regulation subject to the safeguards provided for in paragraphs 2 and 3 of this Article.

2.   Obliged entities shall be able to process personal data covered by Article 9 of Regulation (EU) 2016/679 provided that:

(a) they inform their customers or prospective customers that such categories of data may be processed for the purpose of complying with the requirements of this Regulation;

(b) the data originate from reliable sources, are accurate and up-to-date;

(c) they do not take decisions that would lead to biased and discriminatory outcomes on the basis of those data;

(d) they adopt measures of a high level of security in accordance with Article 32 of Regulation (EU) 2016/679, in particular in terms of confidentiality.

3.   Obliged entities shall be able to process personal data covered by Article 10 of Regulation (EU) 2016/679 provided that they comply with the conditions laid down in paragraph 2 of this Article and that:

(a) such personal data relate to money laundering, its predicate offences or terrorist financing;

(b) the obliged entities have procedures in place that allow the distinction, in the processing of such data, between allegations, investigations, proceedings and convictions, taking into account the fundamental right to a fair trial, the right of defence and the presumption of innocence.

4.   Personal data shall be processed by obliged entities on the basis of this Regulation only for the purposes of the prevention of money laundering and terrorist financing and shall not be further processed in a way that is incompatible with those purposes. The processing of personal data on the basis of this Regulation for commercial purposes shall be prohibited.

5.   Obliged entities may adopt decisions resulting from automated processes, including profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679, or from processes involving AI systems as defined in Article 3, point (1), of Regulation (EU) 2024/xxx of the European Parliament and of the Council (45), provided that:

(a) the data processed by such systems is limited to data obtained pursuant to Chapter III of this Regulation;

(b) any decision to enter or refuse to enter into or maintain a business relationship with a customer or to carry out or refuse to carry out an occasional transaction for a customer, or to increase or decrease the extent of the customer due diligence measures applied pursuant to Article 20 of this Regulation, is subject to meaningful human intervention to ensure the accuracy and appropriateness of such a decision; and

(c) the customer may obtain an explanation of the decision reached by the obliged entity, and may challenge that decision, except in relation to a report as referred to in Article 69 of this Regulation.

Article 77

Record retention

1.   Obliged entities shall retain the following documents and information:

(a) a copy of the documents and information obtained in the performance of customer due diligence pursuant to Chapter III, including information obtained through electronic identification means;

(b) a record of the assessment undertaken pursuant to Article 69(2), including the information and circumstances considered and the results of such assessment, whether or not such assessment results in a suspicious transaction report being made to the FIU, and a copy of the suspicion transaction report, if any;

(c) the supporting evidence and records of transactions, consisting of the original documents or copies admissible in judicial proceedings under the applicable national law, which are necessary to identify transactions;

(d) when they participate in partnerships for information sharing pursuant to Chapter VI, copies of the documents and information obtained in the framework of those partnerships, and records of all instances of information sharing.

Obliged entities shall ensure that documents, information and records kept pursuant to this Article are not redacted.

2.   By way of derogation from paragraph 1, obliged entities may decide to replace the retention of copies of the information by a retention of the references to such information, provided that the nature and method of retention of such information ensure that the obliged entities can provide immediately to competent authorities the information and that the information cannot be modified or altered.

Obliged entities making use of the derogation referred to in the first subparagraph shall define in their internal procedures drawn up pursuant to Article 9, the categories of information for which they will retain a reference instead of a copy or original, as well as the procedures for retrieving the information so that it can be provided to competent authorities upon request.

3.   The information referred to in paragraphs 1 and 2 shall be retained for a period of 5 years commencing on the date of the termination of the business relationship or on the date of the carrying out of the occasional transaction, or on the date of refusal to enter into a business relationship or carry out an occasional transaction. Without prejudice to retention periods for data collected for the purposes of other Union legal acts or national law complying with Regulation (EU) 2016/679, obliged entities shall delete personal data upon expiry of the five-year period.

Competent authorities may require further retention of the information referred to in the first subparagraph on a case-by-case basis, provided that such retention is necessary for the prevention, detection, investigation or prosecution of money laundering or terrorist financing. That further retention period shall not exceed 5 years.

4.   Where, on 10 July 2027, legal proceedings concerned with the prevention, detection, investigation or prosecution of suspected money laundering or terrorist financing are pending in a Member State, and an obliged entity holds information or documents relating to those pending proceedings, the obliged entity may retain that information or those documents for a period of 5 years from 10 July 2027.

Member States may, without prejudice to national criminal law on evidence applicable to ongoing criminal investigations and legal proceedings, allow or require the retention of such information or documents for a further period of 5 years where the necessity and proportionality of such further retention have been established for the prevention, detection, investigation or prosecution of suspected money laundering or terrorist financing.

Article 78

Provision of records to competent authorities

Obliged entities shall have systems in place that enable them to respond fully and speedily to enquiries from their FIU or from other competent authorities, in accordance with national law, as to whether they are maintaining or have maintained, during a five-year period prior to that enquiry a business relationship with specified persons, and on the nature of that relationship, through secure channels and in a manner that ensures full confidentiality of the enquiries.

CHAPTER VIII

MEASURES TO MITIGATE RISKS DERIVING FROM ANONYMOUS INSTRUMENTS

Article 79

Anonymous accounts and bearer shares and bearer share warrants

1.   Credit institutions, financial institutions and crypto-asset service providers shall be prohibited from keeping anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes or anonymous crypto-asset accounts as well as any account otherwise allowing for the anonymisation of the customer account holder or the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins.

Owners and beneficiaries of existing anonymous bank or payment accounts, anonymous passbooks, anonymous safe-deposit boxes held by credit institutions or financial institutions, or crypto-asset accounts shall be subject to customer due diligence measures before those accounts, passbooks, or deposit boxes are used in any way.

2.   Credit institutions and financial institutions acting as acquirers within the meaning of Article 2, point (1), of Regulation (EU) 2015/751 of the European Parliament and of the Council (46) shall not accept payments carried out with anonymous prepaid cards issued in third countries, unless otherwise provided for in the regulatory technical standards adopted by the Commission in accordance with Article 28 of this Regulation on the basis of a proven low risk.

3.   Companies shall be prohibited from issuing bearer shares, and shall convert all existing bearer shares into registered shares, shall immobilise them within the meaning of Article 2(1), point (3), of Regulation (EU) No 909/2014, or deposit them with a financial institution by 10 July 2029. However, companies with securities listed on a regulated market or whose shares are issued as intermediated securities either through immobilisation within the meaning of Article 2(1), point (3), of that Regulation or through a direct issuance in dematerialised form within the meaning of Article 2(1), point (4), of that Regulation shall be permitted to issue new and maintain existing bearer shares. For existing bearer shares that are not converted, immobilised or deposited by 10 July 2029, all voting rights and rights to distribution attached to those shares shall be automatically suspended until their conversion, immobilisation or deposit. All such shares not converted, immobilised or deposited by 10 July 2030 shall be cancelled, leading to a share capital decrease of the corresponding amount.

Companies shall be prohibited from issuing bearer share warrants that are not in intermediated form.

Article 80

Limits to large cash payments in exchange for goods or services

1.   Persons trading in goods or providing services may accept or make a payment in cash only up to an amount of EUR 10 000 or the equivalent in national or foreign currency, whether the transaction is carried out in a single operation or in several operations which appear to be linked.

2.   Member States may adopt lower limits following consultation of the European Central Bank in accordance with Article 2(1) of Council Decision 98/415/EC (47). Those lower limits shall be notified to the Commission within 3 months of the measure being introduced at national level.

3.   When limits already exist at national level which are below the limit set out in paragraph 1, they shall continue to apply. Member States shall notify those limits to the Commission by 10 October 2024.

4.   The limit referred to in paragraph 1 shall not apply to:

(a) payments between natural persons who are not acting in a professional capacity;

(b) payments or deposits made at the premises of credit institutions, electronic money issuers as defined in Article 2, point (3), of Directive 2009/110/EC and payment service providers as defined in Article 4, point (11), of Directive (EU) 2015/2366.

Payments or deposits referred to in the first subparagraph, point (b) above the limit shall be reported to the FIU within the deadlines imposed by the FIU.

5.   Member States shall ensure that appropriate measures, including the imposition of penalties, are taken against natural or legal persons acting in their professional capacity which are suspected of a breach of the limit set out in paragraph 1, or of a lower limit adopted by the Member States.

6.   The overall level of the penalties shall be calculated, in accordance with the relevant provisions of national law, in such way as to produce results proportionate to the seriousness of the infringement, thereby effectively discouraging further offences of the same kind.

7.   Where, by reason of force majeure, means of payment by funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 other than banknotes and coins become unavailable at national level, Member States may temporarily suspend the application of paragraph 1 or, where applicable, of paragraph 2 of this Article and shall inform the Commission thereof without delay. Member States shall also inform the Commission of the expected duration of the unavailability of means of payment by funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 other than banknotes and coins and of the measures taken by Member States to reinstate their availability.

Where, on the basis of the information communicated by the Member State, the Commission considers that the suspension of the application of paragraph 1 or, where applicable, of paragraph 2 is not justified by a case of force majeure, it shall adopt a decision addressed to that Member State requesting the immediate lifting of such suspension.

CHAPTER IX

FINAL PROVISIONS

SECTION 1

Cooperation between FIUs and the EPPO

Article 81

Cooperation between FIUs and the EPPO

1.   Pursuant to Article 24 of Regulation (EU) 2017/1939, each FIU shall without undue delay report to the EPPO the results of its analyses and any additional relevant information where there are reasonable grounds to suspect that money laundering and other criminal activity are being or have been committed in respect of which the EPPO could exercise its competence in accordance with Article 22 and Article 25(2) and (3) of that Regulation.

By 10 July 2026, AMLA shall, in consultation with the EPPO, develop draft implementing technical standards and submit them to the Commission for adoption. Those draft implementing technical standards shall specify the format to be used by FIUs for reporting information to the EPPO.

Power is conferred on the Commission to adopt the implementing technical standards referred to in the second subparagraph of this paragraph in accordance with Article 53 of Regulation (EU) 2024/1620.

2.   FIUs shall respond in a timely manner to requests for information by the EPPO in relation to money laundering and other criminal activity as referred to in paragraph 1.

3.   FIUs and the EPPO may exchange the results of strategic analyses, including typologies and risk indicators, where such analyses relate to money laundering and other criminal activity as referred to in paragraph 1.

Article 82

Requests for information to the EPPO

1.   The EPPO shall respond without undue delay to reasoned requests for information by an FIU where that information is necessary for the performance of the FIU’s functions under Chapter III of Directive (EU) 2024/1640.

2.   The EPPO may postpone or refuse the provision of the information referred to in paragraph 1 where providing it would be likely to prejudice the proper conduct and confidentiality of an ongoing investigation. The EPPO shall communicate in a timely manner the postponement of or refusal to provide the requested information, including the reasons therefor, to the requesting FIU.

SECTION 2

Cooperation between FIUs and OLAF

Article 83

Cooperation between FIUs and OLAF

1.   Pursuant to Article 8(3) of Regulation (EU, Euratom) No 883/2013 of the European Parliament and of the Council (48), each FIU shall transmit without delay the results of its analyses and any additional relevant information to OLAF where there are reasonable grounds to suspect that fraud, corruption or any other illegal activity affecting the Union’s financial interests are being or have been committed in respect of which OLAF could exercise its competence in accordance with Article 8 of that Regulation.

2.   FIUs shall respond in a timely manner to requests for information by OLAF in relation to fraud, corruption or any other illegal activity as referred to in paragraph 1.

3.   FIUs and OLAF may exchange the results of strategic analyses, including typologies and risk indicators, where such analyses relate to fraud, corruption or any other illegal activity as referred to in paragraph 1.

Article 84

Requests for information to OLAF

1.   OLAF shall respond in a timely manner to reasoned requests for information by an FIU where that information is necessary for the performance of the FIU’s functions under Chapter III of Directive (EU) 2024/1640.

2.   OLAF may postpone or refuse the provision of the information referred to in paragraph 1 where providing it would be likely to have a negative impact on an ongoing investigation. OLAF shall communicate such postponement or refusal to the requesting FIU in a timely manner, including the reasons therefor.

SECTION 3

Other provisions

Article 85

Exercise of the delegation

1.   The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.

2.   The power to adopt delegated acts referred to in Articles 29, 30, 31, 34, 43, 52 and 68 shall be conferred on the Commission for an indeterminate period of time from 9 July 2024.

3.   The delegation of power referred to in Articles 29, 30, 31, 34, 43, 52 and 68 may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.

4.   Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.

5.   As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.

6.   A delegated act adopted pursuant to Article 29, 30, 31 or 34 shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of 1 month of notification of that act to the European Parliament and to the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by 1 month at the initiative of the European Parliament or of the Council.

7.   A delegated act adopted pursuant to Article 43, 52 or 68 shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of 3 months of notification of that act to the European Parliament and to the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by 3 months at the initiative of the European Parliament or of the Council.

Article 86

Committee procedure

1.   The Commission shall be assisted by the Committee on the Prevention of Money Laundering and Terrorist Financing established by Article 34 of Regulation (EU) 2023/1113. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.

2.   Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.

Article 87

Review

By 10 July 2032, and every 3 years thereafter, the Commission shall review the application of this Regulation and submit a report to the European Parliament and to the Council.

The first review shall include an assessment of:

(a) the national systems for reporting of suspicions pursuant to Article 69 and obstacles and opportunities to establish a single reporting system at Union level;

(b) the adequacy of the beneficial ownership transparency framework to mitigate risks associated with legal entities and legal arrangements.

Article 88

Reports

By 10 July 2030, the Commission shall submit reports to the European Parliament and to the Council assessing the necessity and proportionality of:

(a) lowering the 25 % threshold for the identification of beneficial ownership of legal entities through ownership interest;

(b) extending the scope of high-value goods to include high-value garments and accessories;

(c) extending the scope of the threshold-based disclosures under Article 74 to cover the sale of other goods, of introducing harmonised formats for the reporting of those transactions based on the usefulness of those reports for FIUs, and of extending the scope of information collected from persons trading in free-trade zones;

(d) adjusting the limit for large cash payments.

Article 89

Relation to Directive (EU) 2015/849

References to Directive (EU) 2015/849 shall be construed as references to this Regulation and to Directive (EU) 2024/1640 and read in accordance with the correlation table set out in Annex VI to this Regulation.

Article 90

Entry into force and application

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

It shall apply from 10 July 2027, except in relation to obliged entities referred to in Article 3, points (3)(n) and (o), to which it shall apply from 10 July 2029.

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 31 May 2024.

For the European Parliament

The President

R. METSOLA

For the Council

The President

H. LAHBIB


(1)   OJ C 210, 25.5.2022, p. 5.

(2)   OJ C 152, 6.4.2022, p. 89.

(3)  Position of the European Parliament of 24 April 2024 (not yet published in the Official Journal) and decision of the Council of 30 May 2024.

(4)  Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, amending Regulation (EU) No 648/2012 of the European Parliament and of the Council, and repealing Directive 2005/60/EC of the European Parliament and of the Council and Commission Directive 2006/70/EC (OJ L 141, 5.6.2015, p. 73).

(5)  Directive (EU) 2018/843 of the European Parliament and of the Council of 30 May 2018 amending Directive (EU) 2015/849 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, and amending Directives 2009/138/EC and 2013/36/EU (OJ L 156, 19.6.2018, p. 43).

(6)  Directive (EU) 2024/1640 of the European Parliament and of the Council of 31 May 2024 on the mechanisms to be put in place by the Member States for the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, amending Directive (EU) 2019/1937, and amending and repealing Directive (EU) 2015/849 (OJ L, 2024/1640, 19.6.2024, ELI: http://data.europa.eu/eli/dir/2024/1640/oj).

(7)  Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/849 (OJ L 150, 9.6.2023, p. 1).

(8)  Regulation (EU) 2024/1620 of the European Parliament and of the Council of 31 May 2024 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010 (OJ L, 2024/1620, 19.6.2024, http://data.europa.eu/eli/reg/2024/1620/oj).

(9)  Directive (EU) 2018/1673 of the European Parliament and of the Council of 23 October 2018 on combating money laundering by criminal law (OJ L 284, 12.11.2018, p. 22).

(10)  Directive (EU) 2017/1371 of the European Parliament and of the Council of 5 July 2017 on the fight against fraud to the Union’s financial interests by means of criminal law (OJ L 198, 28.7.2017, p. 29).

(11)  Directive (EU) 2017/541 of the European Parliament and of the Council of 15 March 2017 on combating terrorism and replacing Council Framework Decision 2002/475/JHA and amending Council Decision 2005/671/JHA (OJ L 88, 31.3.2017, p. 6).

(12)  Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (OJ L 26, 2.2.2016, p. 19).

(13)  Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (OJ L 337, 23.12.2015, p. 35).

(14)  Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 (OJ L 150, 9.6.2023, p. 40).

(15)  Regulation (EU) 2020/1503 of the European Parliament and of the Council of 7 October 2020 on European crowdfunding service providers for business, and amending Regulation (EU) 2017/1129 and Directive (EU) 2019/1937 (OJ L 347, 20.10.2020, p. 1).

(16)  Directive 2009/65/EC of the European Parliament and of the Council of 13 July 2009 on the coordination of laws, regulations and administrative provisions relating to undertakings for collective investment in transferable securities (UCITS) (OJ L 302, 17.11.2009, p. 32).

(17)  Directive 2011/61/EU of the European Parliament and of the Council of 8 June 2011 on Alternative Investment Fund Managers and amending Directives 2003/41/EC and 2009/65/EC and Regulations (EC) No 1060/2009 and (EU) No 1095/2010 (OJ L 174, 1.7.2011, p. 1).

(18)  Council Decision 2010/413/CFSP of 26 July 2010 concerning restrictive measures against Iran and repealing Common Position 2007/140/CFSP (OJ L 195, 27.7.2010, p. 39).

(19)  Council Decision (CFSP) 2016/849 of 27 May 2016 concerning restrictive measures against the Democratic People’s Republic of Korea and repealing Decision 2013/183/CFSP (OJ L 141, 28.5.2016, p. 79).

(20)  Council Regulation (EU) No 267/2012 of 23 March 2012 concerning restrictive measures against Iran and repealing Regulation (EU) No 961/2010 (OJ L 88, 24.3.2012, p. 1).

(21)  Council Regulation (EU) 2017/1509 of 30 August 2017 concerning restrictive measures against the Democratic People’s Republic of Korea and repealing Regulation (EC) No 329/2007 (OJ L 224, 31.8.2017, p. 1).

(22)  Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1).

(23)  Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (OJ L 257, 28.8.2014, p. 73).

(24)  Directive 2014/92/EU of the European Parliament and of the Council of 23 July 2014 on the comparability of fees related to payment accounts, payment account switching and access to payment accounts with basic features (OJ L 257, 28.8.2014, p. 214).

(25)  Directive 2013/34/EU of the European Parliament and of the Council of 26 June 2013 on the annual financial statements, consolidated financial statements and related reports of certain types of undertakings, amending Directive 2006/43/EC of the European Parliament and of the Council and repealing Council Directives 78/660/EEC and 83/349/EEC (OJ L 182, 29.6.2013, p. 19).

(26)  Directive (EU) 2016/2341 of the European Parliament and of the Council of 14 December 2016 on the activities and supervision of institutions for occupational retirement provision (IORPs) (OJ L 354, 23.12.2016, p. 37).

(27)  Directive 2004/109/EC of the European Parliament and of the Council of 15 December 2004 on the harmonisation of transparency requirements in relation to information about issuers whose securities are admitted to trading on a regulated market and amending Directive 2001/34/EC (OJ L 390, 31.12.2004, p. 38).

(28)  Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1).

(29)   OJ L 123, 12.5.2016, p. 1.

(30)  Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission’s exercise of implementing powers (OJ L 55, 28.2.2011, p. 13).

(31)   OJ C 524, 29.12.2021, p. 10.

(32)  Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (OJ L 176, 27.6.2013, p. 338).

(33)  Directive 2009/138/EC of the European Parliament and of the Council of 25 November 2009 on the taking-up and pursuit of the business of Insurance and Reinsurance (Solvency II) (OJ L 335, 17.12.2009, p. 1).

(34)  Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU (OJ L 173, 12.6.2014, p. 349).

(35)  Regulation (EU) No 909/2014 of the European Parliament and of the Council of 23 July 2014 on improving securities settlement in the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU) No 236/2012 (OJ L 257, 28.8.2014, p. 1).

(36)  Directive 2014/17/EU of the European Parliament and of the Council of 4 February 2014 on credit agreements for consumers relating to residential immovable property and amending Directives 2008/48/EC and 2013/36/EU and Regulation (EU) No 1093/2010 (OJ L 60, 28.2.2014, p. 34).

(37)  Directive 2008/48/EC of the European Parliament and of the Council of 23 April 2008 on credit agreements for consumers and repealing Council Directive 87/102/EEC (OJ L 133, 22.5.2008, p. 66).

(38)  Directive 2009/110/EC of the European Parliament and of the Council of 16 September 2009 on the taking up, pursuit and prudential supervision of the business of electronic money institutions amending Directives 2005/60/EC and 2006/48/EC and repealing Directive 2000/46/EC (OJ L 267, 10.10.2009, p. 7).

(39)  Regulation (EU) 2018/1672 of the European Parliament and of the Council of 23 October 2018 on controls on cash entering or leaving the Union and repealing Regulation (EC) No 1889/2005 (OJ L 284, 12.11.2018, p. 6).

(40)  Council Regulation (EC) No 116/2009 of 18 December 2008 on the export of cultural goods (OJ L 39, 10.2.2009, p. 1).

(41)  Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law (OJ L 305, 26.11.2019, p. 17).

(42)  Council Directive 2011/16/EU of 15 February 2011 on administrative cooperation in the field of taxation and repealing Directive 77/799/EEC (OJ L 64, 11.3.2011, p. 1).

(43)  Directive 2014/24/EU of the European Parliament and of the Council of 26 February 2014 on public procurement and repealing Directive 2004/18/EC (OJ L 94, 28.3.2014, p. 65).

(44)  Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89).

(45)  Regulation (EU) 2024/xxx of the European Parliament and of the Council of xxx laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Not yet published in the Official Journal).

(46)  Regulation (EU) 2015/751 of the European Parliament and of the Council of 29 April 2015 on interchange fees for card-based payment transactions (OJ L 123, 19.5.2015, p. 1).

(47)  Council Decision 98/415/EC of 29 June 1998 on the consultation of the European Central Bank by national authorities regarding draft legislative provisions (OJ L 189, 3.7.1998, p. 42).

(48)  Regulation (EU, Euratom) No 883/2013 of the European Parliament and of the Council of 11 September 2013 concerning investigations conducted by the European Anti-Fraud Office (OLAF) and repealing Regulation (EC) No 1073/1999 of the European Parliament and of the Council and Council Regulation (Euratom) No 1074/1999 (OJ L 248, 18.9.2013, p. 1).


ANNEX I

Indicative list of risk variables

The following is a non-exhaustive list of risk variables that obliged entities shall take into account when drawing up their risk assessment in accordance with Article 10 and when determining to what extent to apply customer due diligence measures in accordance with Article 20:

(a) Customer risk variables:; (i) the customer’s and the customer’s beneficial owner’s business or professional activity;; (ii) the customer’s and the customer’s beneficial owner’s reputation;; (iii) the customer’s and the customer’s beneficial owner’s nature and behaviour;; (iv) the jurisdictions in which the customer and the customer’s beneficial owner are based;; (v) the jurisdictions that are the customer’s and the customer’s beneficial owner’s main places of business;; (vi) the jurisdictions to which the customer and the customer’s beneficial owner have relevant personal links;

(b) Product, service or transaction risk variables:; (i) the purpose of an account or relationship;; (ii) the regularity or duration of the business relationship;; (iii) the level of assets to be deposited by a customer or the size of transactions undertaken;; (iv) the level of transparency, or opaqueness, the product, service or transaction affords;; (v) the complexity of the product, service or transaction;; (vi) the value or size of the product, service or transaction;

(c) Delivery channel risk variables:; (i) the extent to which the business relationship is conducted on a non-face-to-face basis;; (ii) the presence of any introducers or intermediaries that the customer might use and the nature of their relationship with the customer;

(d) Risk variable for life and other investment-related insurance:; (i) the risk level presented by the beneficiary of the insurance policy.


ANNEX II

Lower risk factors

The following is a non-exhaustive list of factors and types of evidence of potentially lower risk referred to in Article 20:

(1) Customer risk factors:; (a) public companies listed on a stock exchange and subject to disclosure requirements (either by stock exchange rules or through law or enforceable means), which impose requirements to ensure adequate transparency of beneficial ownership;; (b) public administrations or enterprises;; (c) customers that are resident in geographical areas of lower risk as set out in point (3);

(2) Product, service, transaction or delivery channel risk factors:; (a) life insurance policies for which the premium is low;; (b) insurance policies for pension schemes if there is no early surrender option and the policy cannot be used as collateral;; (c) a pension, superannuation or similar scheme that provides retirement benefits to employees, where contributions are made by way of deduction from wages, and the scheme rules do not permit the assignment of a member’s interest under the scheme;; (d) financial products or services that provide appropriately defined and limited services to certain types of customers, so as to increase access for financial inclusion purposes;; (e) products where the risks of money laundering and terrorist financing are managed by other factors such as purse limits or transparency of ownership (e.g. certain types of electronic money);

(3) Geographical risk factors — registration, establishment, residence in:; (a) Member States;; (b) third countries having effective AML/CFT systems;; (c) third countries identified by credible sources as having a low level of corruption or other criminal activity;; (d) third countries which, on the basis of credible sources such as mutual evaluations, detailed assessment reports or published follow-up reports, have requirements to combat money laundering and terrorist financing consistent with the revised FATF Recommendations and effectively implement those requirements.


ANNEX III

Higher risk factors

The following is a non-exhaustive list of factors and types of evidence of potentially higher risk referred to in Article 20:

(1) Customer risk factors:; (a) the business relationship or occasional transaction is conducted in unusual circumstances;; (b) customers that are resident in geographical areas of higher risk as set out in point (3);; (c) legal persons or legal arrangements that are personal asset-holding vehicles;; (d) corporate entities that have nominee shareholders or shares in bearer form;; (e) businesses that are cash-intensive;; (f) the ownership structure of the company appears unusual or excessively complex given the nature of the company’s business;; (g) customer is a third-country national who applies for residence rights in a Member State in exchange of any kind of investment, including capital transfers, purchase or renting of property, investment in government bonds, investment in corporate entities, donation or endowment of an activity contributing to the public good and contributions to the state budget;; (h) customer is a legal entity or arrangement created or set up in a jurisdiction in which it has no real economic activity, substantial economic presence or apparent economic rationale;; (i) customer is directly or indirectly owned by one or several entities or arrangements under point (h);

(2) Product, service, transaction or delivery channel risk factors:; (a) private banking;; (b) products or transactions that might favour anonymity;; (c) payment received from unknown or unassociated third parties;; (d) new products and new business practices, including new delivery mechanism, and the use of new or developing technologies for both new and pre-existing products;; (e) transactions related to oil, arms, precious metals or stones, tobacco products, cultural artefacts and other items of archaeological, historical, cultural and religious importance, or of rare scientific value, as well as ivory and protected species;

(3) Geographical risk factors:; (a) third countries subject to increased monitoring or otherwise identified by the FATF due to the compliance weaknesses in their AML/CFT systems;; (b) third countries identified by credible sources / acknowledged processes, such as mutual evaluations, detailed assessment reports or published follow-up reports, as not having effective AML/CFT systems;; (c) third countries identified by credible sources / acknowledged processes as having significant levels of corruption or other criminal activity;; (d) third countries subject to sanctions, embargos or similar measures issued by, for example, the Union or the UN;; (e) third countries providing funding or support for terrorist activities, or that have designated terrorist organisations operating within their country;; (f) third countries identified by credible sources or pursuant to acknowledged processes as enabling financial secrecy by:; (i) posing barriers to the cooperation and exchange of information with other jurisdictions;; (ii) having strict corporate or banking secrecy laws which prevent institutions and their employees from providing customer information to competent authorities, including through fines and penalties;; (iii) having weak controls for the creation of legal entities or setting up of legal arrangements; or; (iv) not requiring beneficial ownership information to be recorded or held in a central database or register.


ANNEX IV

List of high value goods referred to in Article 2(1), point (54):

(1) Jewellery, gold- or silversmith articles of a value exceeding EUR 10 000 or the equivalent in national currency;

(2) Clocks and watches of a value exceeding EUR 10 000 or the equivalent in national currency;

(3) Motor vehicles of a price exceeding EUR 250 000 or the equivalent in national currency;

(4) Aircraft of a price exceeding EUR 7 500 000 or the equivalent in national currency;

(5) Watercraft of a price exceeding EUR 7 500 000 or the equivalent in national currency.


ANNEX V

Precious metals referred to in Article 2(1), point (55):

(a) Gold

(b) Silver

(c) Platinium

(d) Iridium

(e) Osmium

(f) Palladium

(g) Rhodium

(h) Rhutenium.

Precious stones referred to in Article 2(1), point (55):

(a) Diamond

(b) Ruby

(c) Sapphire

(d) Emerald.


ANNEX VI

Correlation table

Directive (EU) 2015/849 Directive (EU) 2024/1640 This Regulation
Article 1(1)
Article 1(2)
Article 1(3) Article 2(1), point (1)
Article 1(4) Article 2(1), point (1)
Article 1(5) Article 2(1), point (2)
Article 1(6) Article 2(1), points (1) and (2)
Article 2(1) Article 3
Article 2(2) Article 4
Article 2(3) Article 6(1)
Article 2(4) Article 6(2)
Article 2(5) Article 6(3)
Article 2(6) Article 6(4)
Article 2(7) Article 6(5)
Article 2(8) Article 7
Article 2(9) Article 4(3) and Article 6(6)
Article 3, point (1) Article 2(1), point (5)
Article 3, point (2) Article 2(1), point (6)
Article 3, point (3) Article 2(1), point (4)
Article 3, point (4) Article 2(1), point (3)
Article 3, point (5) Article 2(1), point (47)
Article 3, point (6) Article 2(1), point (28)
Article 3, point (6) (a) Articles 51 to 55
Article 3, point (6) (b) Article 58
Article 3, point (6) (c) Article 57
Article 3, point (7) Article 2(1), point (11)
Article 3, point (8) Article 2(1), point (22)
Article 3, point (9) Article 2(1), point (34) and Article 2(2)
Article 3, point (10) Article 2(1), point (35) and Article 2(5)
Article 3, point (11) Article 2(1), point (36)
Article 3, point (12) Article 2(1), point (40)
Article 3, point (13) Article 2(1), point (19)
Article 3, point (14) Article 2(1), point (12)
Article 3, point (15) Article 2(1), point (41)
Article 3, point (16) Article 2(1), point (17)
Article 3, point (17) Article 2(1), point (23)
Article 3, point (18) Article 2(1), point (7)
Article 3, point (19)
Article 4 Article 3
Article 5
Article 6 Article 7
Article 7 Article 8
Article 8(1) Article 10(1)
Article 8(2) Article 10(2) and (3)
Article 8(3) Article 9(1)
Article 8(4) Article 9(2)
Article 8(5) Article 9(2) and (3)
Article 9 Article 29
Article 10(1) Article 79(1)
Article 10(2) Article 79(3)
Article 11 Article 19(1), (2) and (5)
Article 12 Article 19(7) and Article 79(2)
Article 13(1) Article 20(1)
Article 13(2) Article 20(2)
Article 13(3) Article 20(2)
Article 13(4) Article 20(4)
Article 13(5) Article 47
Article 13(6) Article 22(4)
Article 14(1) Article 23(1) and (4)
Article 14(2) Article 23(2)
Article 14(3) Article 23(3)
Article 14(4) Article 21(1) and (2)
Article 14(5) Article 26(2) and (3)
Article 15 Article 20(2), second subparagraph and Article 33
Article 16 Article 33(1)
Article 17
Article 18(1) Article 34(1) and (8)
Article 18(2) Article 34(2)
Article 18(3) Article 34(3)
Article 18(4)
Article 18a(1) Article 29(4)
Article 18a(2) Article 29(5) and (6) and Article 35, point (a)
Article 18a(3) Article 29(5) and (6) and Article 35, point (b)
Article 18a(4)
Article 18a(5) Article 29(6)
Article 19 Article 36
Article 20 Article 9(2), Article 20(1) and Article 42(1)
Article 20, point (a) Article 9(2), point (a)(iii) and Article 20(1), point (g)
Article 20, point (b) Article 42(1)
Article 20a Article 43
Article 21 Article 44
Article 22 Article 45
Article 23 Article 46
Article 24 Article 39
Article 25 Article 48(1)
Article 26 Article 48
Article 27 Article 49
Article 28 Article 48(3)
Article 29
Article 30(1) Article 63(1), (2), second subparagraph and (4) and Article 68
Article 30(2) Article 63(5)
Article 30(3) Article 10(1)
Article 30(4) Article 10(7) and (10) Article 24
Article 30(5), first subparagraph Article 11 and Article 12(2)
Article 30(5), second subparagraph Article 12(1)
Article 30(5), third subparagraph
Article 30(5a) Article 11(4) and Article 13(12)
Article 30(6) Article 11(1), (2) and (3)
Article 30(7) Article 61(2)
Article 30(8) Article 22(7)
Article 30(9) Article 15
Article 30(10) Article 10(19) and (20)
Article 31(1) Articles 58, Article 64(1) and Article 68
Article 31(2) Article 64(3)
Article 31(3) Article 64(5)
Article 31(3a) Article 10(1), (2) and (3) Article 67
Article 31(4), first subparagraph Article 11 and Article 12(2)
Article 31(4), second subparagraph Article 12(1)
Article 31(4), third subparagraph
Article 31(4), fourth subparagraph Article 11(2)
Article 31(4a) Article 11(4) and Article 13(12)
Article 31(5) Article 10(7) and (10) Article 24
Article 31(6) Article 22(7)
Article 31(7) Article 61(2)
Article 31(7a) Article 15
Article 31(9) Article 10(19) and (20)
Article 31(10) Article 58(4)
Article 31a Article 17(1)
Article 32(1) Article 19(1)
Article 32(2) Article 62(1)
Article 32(3) Article 19(2), (3), first subparagraph, (4) and (5)
Article 32(4) Articles 21(1) and Article 22(1), first subparagraph
Article 32(5) Article 22(1), second subparagraph
Article 32(6) Article 22(2)
Article 32(7) Article 24(1)
Article 32(8) Article 19(3), second subparagraph
Article 32(9) Article 21(4)
Article 32a(1) Article 16(1)
Article 32a(2) Article 16(2)
Article 32a(3) Article 16(3)
Article 32a(4) Article 16(5)
Article 32b Article 18
Article 33(1) Article 69(1)
Article 33(2) Article 69(6)
Article 34(1) Article 70(1)
Article 34(2) Article 70(2)
Article 34(3) Article 40(5)
Article 35 Article 71
Article 36 Article 42
Article 37 Article 72
Article 38 Article 60 Article 11(2), fourth subparagraph, and (4), Article 14 and Article 69(7)
Article 39 Article 73
Article 40 Article 77
Article 41 Article 70 Article 76
Article 42 Article 78
Article 43
Article 44(1) Article 9(1)
Article 44(2) Article 9(2)
Article 44(3)
Article 44(4) Article 9(3) and (6)
Article 45(1) Article 16(1)
Article 45(2) Article 8(3), (4) and (5)
Article 45(3) Article 17(1)
Article 45(4) Article 48
Article 45(5) Article 17(2)
Article 45(6) Article 17(3)
Article 45(7) Article 17(4)
Article 45(8) Article 16(3)
Article 45(9) Article 41(1)
Article 45(10) Article 41(2)
Article 45(11) Article 41(3)
Article 46(1) Articles 12 and 15
Article 46(2) Article 39(2)
Article 46(3) Article 28(1)
Article 46(4) Article 11(1)
Article 47(1) Article 4(1) and (2)
Article 47(2) Article 6(1)
Article 47(3) Article 6(2)
Article 48(1) Article 37(1)
Article 48(1a) Article 37(5) and Article 62(1)
Article 48(2) Article 37(2) and (6)
Article 48(3) Article 37(7)
Article 48(4) Article 37(1), first subparagraph, Article 46 and Article 54(4)
Article 48(5) Article 46(2) and (3) and Article 47
Article 48(6) Article 40(1)
Article 48(7) Article 40(2)
Article 48(8) Article 40(4)
Article 48(9) Article 37(3)
Article 48(10) Article 40(3)
Article 49 Article 61(1)
Article 50 Article 63
Article 50a Article 61(3)
Article 51
Article 52 Article 29
Article 53 Article 31
Article 54 Article 33
Article 55 Article 34
Article 56 Article 30(2) and (3)
Article 57 Article 35
Article 57a(1) Article 67(1)
Article 57a(2) Article 67(2)
Article 57a(3) Article 67(3)
Article 57a(4) Article 44, Article 46(1) and Article 47(1)
Article 57a(5) Article 51
Article 57b Article 68
Article 58(1) Article 53(1)
Article 58(2) Article 53(2) and (3)
Article 58(3) Article 53(4)
Article 58(4)
Article 58(5) Article 53(5)
Article 59(1) Article 55(1)
Article 59(2) Article 55(2) and Article 56(2) and (3)
Article 59(3) Article 55(3)
Article 59(4) Article 55(4)
Article 60(1) Article 58(1), (2), first subparagraph and (3)
Article 60(2) Article 58(2), third subparagraph
Article 60(3) Article 58(4)
Article 60(4) Article 53(6)
Article 60(5) Article 53(7)
Article 60(6) Article 53(8)
Article 61 Article 60
Article 62(1) Article 59(1)
Article 62(2) Article 6(6)
Article 62(3) Article 59(2)
Article 63
Article 64 Article 85
Article 64a Article 72 Article 86
Article 65
Article 66
Article 67
Article 68
Article 69
Annex I Annex I
Annex II Annex II
Annex III Annex III
Annex IV

ELI: http://data.europa.eu/eli/reg/2024/1624/oj

ISSN 1977-0677 (electronic edition)