22 min read
The new EU AML package (AMLR, AMLD6, AMLA) applies from 10 July 2027. What Cyprus CIFs, EMIs, trustees and obliged entities must do now to close the gap.

Reviewed by Gregoris Philippou, Managing Partner
Cyprus Bar Association (since 2013)
The new EU AML package is a set of three legal instruments adopted in 2024 that harmonise anti-money-laundering and counter-terrorist-financing rules across all EU member states, including Cyprus. It matters because, for the first time, the core obligations that a Cyprus obliged entity must follow will come directly from an EU regulation rather than from Cyprus law, removing the national variations that firms operating cross-border have relied on for years.
For Cyprus, a jurisdiction with a large regulated financial-services and corporate-services base, the shift is substantial. The rules that Cyprus Investment Firms, Electronic Money Institutions, administrative service providers, trustees, accountants and lawyers apply will be standardised, and the discretion that Cyprus historically exercised when transposing EU directives will largely disappear.
The package rests on three instruments, each with a distinct legal function. The AMLR is the substantive rulebook, AMLD6 governs the institutional framework, and the AMLA Regulation creates the new supervisor.
| Instrument | Legal act | Function |
|---|---|---|
| AMLR | Regulation (EU) 2024/1624 | The single rulebook: customer due diligence, beneficial ownership, cash limits, obliged-entity scope. Directly applicable, no transposition. |
| AMLD6 | Directive (EU) 2024/1640 | Institutional rules: national supervisors, financial intelligence units, beneficial-ownership registers. Must be transposed by member states. |
| AMLA Regulation | Regulation (EU) 2024/1620 | Establishes the Anti-Money Laundering Authority in Frankfurt, with direct and indirect supervisory powers. |
The takeaway for a Cyprus compliance officer is that the AMLR is where day-to-day obligations now live, while AMLD6 reshapes who supervises you and how.
A regulation is directly applicable, meaning the AMLR becomes binding law in Cyprus on 10 July 2027 without any Cyprus statute needing to reproduce it. A directive, by contrast, sets an outcome that each member state must reach through its own national legislation, which is why AMLD6 requires a Cyprus transposing law.
This distinction is the defining feature of the reform. Because the AMLR entered into force on 9 July 2024 and applies from 10 July 2027 as a directly applicable single rulebook, a Cyprus obliged entity can no longer wait for a local law to tell it what customer due diligence to perform. The obligation flows straight from the EU text, and Cyprus courts and supervisors will apply it as written.
The package supersedes the substantive AML obligations currently set out in the Cyprus Prevention and Suppression of Money Laundering Activities Law 188(I)/2007, which transposed the Fourth and Fifth Anti-Money Laundering Directives. When AMLD6 is transposed, the Fourth and Fifth Directives are repealed, and Law 188(I)/2007 will need extensive amendment so that only its institutional and supervisory provisions survive alongside the directly applicable AMLR.
In practice, Cyprus firms should stop treating Law 188(I)/2007 as the primary source of their obligations from 10 July 2027 and treat the AMLR as the controlling text, with the amended Cyprus law filling the institutional gaps that AMLD6 leaves to member states. The supervisory split established under Law 188(I)/2007 is expected to continue: CySEC supervises Cyprus Investment Firms, crypto-asset service providers and funds, the Central Bank of Cyprus supervises banks and payment and electronic-money institutions, ICPAC supervises accountants and auditors, the Cyprus Bar Association supervises lawyers, and MOKAS remains the financial intelligence unit. The Cyprus law transposing AMLD6 and amending Law 188(I)/2007 will confirm each competent authority, and the exact final mapping depends on that legislation.
The single most important date is 10 July 2027, when the AMLR becomes directly applicable and AMLD6 must be transposed. Around that anchor sits a staggered timeline: AMLA became operational on 1 July 2025, its direct supervision begins on 1 January 2028, and a small number of provisions carry earlier or later dates.
Cyprus obliged entities should plan backwards from 10 July 2027, because a credible remediation programme takes twelve months or more and the compliance function cannot be rebuilt in the final quarter.
The AMLR entered into force on 9 July 2024 but applies from 10 July 2027, giving obliged entities a three-year transition. The gap between entry into force and application is the compliance window, not a grace period, and it is closing.
By 10 July 2027 every Cyprus obliged entity must already operate under the AMLR: the beneficial-ownership threshold, the cash cap, the harmonised customer due diligence and the internal-controls requirements all take effect on that single date rather than phasing in.
AMLD6 must be transposed by Cyprus into national law by 10 July 2027, the same date the AMLR applies, at which point the Fourth and Fifth Directives are repealed. Certain beneficial-ownership register and financial-intelligence-unit access provisions are reported to carry earlier deadlines, so parts of the institutional framework may bind Cyprus before the main date.
Directive (EU) 2024/1640 confirms a staggered timetable. The beneficial-ownership register access provisions in Article 74 carried an earlier transposition deadline of 10 July 2025, and Articles 11 to 13 and 15, which govern the beneficial-ownership registers themselves, must be transposed by 10 July 2026, a full year ahead of the main date. Firms with complex ownership structures should not assume the register changes wait until 2027.
AMLA, the European Anti-Money Laundering Authority, is headquartered in Frankfurt and has been operational since 1 July 2025. Its direct supervision of selected obliged entities begins from 1 January 2028, after a selection process that starts on 1 July 2027 and runs for six months.
For most Cyprus entities the practical effect of AMLA before 2028 is indirect: it drafts the technical standards, guidelines and templates that Cyprus supervisors and firms will apply, so the AMLA rulebook shapes remediation well before any Cyprus firm is directly supervised.
Professional football clubs and football agents have a delayed application date of 10 July 2029, two years after the general date. The football sector is the one category the AMLR brings in on a longer runway, reflecting the time needed to build compliance in a newly regulated industry.
This carve-out is narrow. Every other newly in-scope category, including crypto-asset service providers and high-value-goods dealers, must comply from 10 July 2027.
The AMLR changes the substance of what every obliged entity must do, standardising customer due diligence, internal controls, record-keeping and reporting into one directly applicable text. The largest operational changes are a lower occasional-transaction trigger of EUR 10,000, a harmonised beneficial-ownership standard, and a mandatory compliance-function structure.
Because these rules now come from a regulation, a Cyprus firm cannot rely on a lighter national interpretation. The AMLR is the floor and the ceiling.
The AMLR lowers the general customer-due-diligence trigger for occasional transactions from EUR 15,000 to EUR 10,000, so due diligence bites at a lower value. Customer due diligence itself is harmonised, meaning identification, verification and beneficial-ownership checks follow a single EU standard rather than divergent national rules.
For a Cyprus obliged entity this means recalibrating transaction-monitoring thresholds and onboarding logic to the EUR 10,000 figure and ensuring that the identification data collected meets the AMLR standard rather than the older Law 188(I)/2007 approach.
Enhanced due diligence remains mandatory for higher-risk situations, including clients connected to high-risk third countries and high-net-worth individuals, with additional scrutiny of source of wealth and source of funds. The AMLR standardises when enhanced measures are triggered and what they must include.
The AMLR sets a specific high-net-worth trigger: financial and credit institutions must apply enhanced due diligence where they hold custody of at least EUR 5 million in assets for a customer whose total assets are at least EUR 50 million, with AMLA due to issue guidelines by 10 July 2027 on how to determine whether a customer crosses that EUR 50 million threshold. Firms serving international clients, including those using a Cyprus holding company structuring arrangement or advised on establishing economic substance in a Cyprus company, should expect deeper source-of-wealth files.
The AMLR requires every obliged entity to maintain internal policies, controls and procedures proportionate to its size and risk, and to appoint a compliance function with a designated compliance officer at management level. The compliance officer is responsible for implementing the AML framework, and a separate senior manager is accountable at board level.
Cyprus firms already operate an MLRO model under existing law, but the AMLR formalises the two-tier structure, the compliance-function documentation and the group-wide policies, so existing appointments and manuals should be reviewed against the new text rather than assumed compliant.
The AMLR requires obliged entities to retain customer-due-diligence records and transaction data for five years, and to report suspicious transactions to the national financial intelligence unit. In Cyprus, MOKAS, the Unit for Combating Money Laundering, is the financial intelligence unit and mandatory recipient of suspicious and threshold-based reports.
Under Article 77 of the AMLR, obliged entities must retain customer-due-diligence records and transaction data for five years after the end of the business relationship or the date of an occasional transaction, and national law may require or permit retention for up to five further years where that is necessary and proportionate for preventing, detecting or investigating money laundering. Suspicious-transaction-reporting workflows should route to MOKAS and be tested before the 2027 date.
The beneficial-ownership threshold changes from more than 25% to 25% or more of shares, voting rights or ownership interest, so a person holding exactly 25% now qualifies as a beneficial owner. This closes the gap that previously let an exact 25% holder sit outside the definition, and it can be reduced to 15% for higher-risk structures.
For Cyprus, where corporate and trust structures often distribute holdings in even quarters, the change is not cosmetic: a large number of exactly-25% holders move into scope overnight and must be identified, verified and registered.
Under the AMLR, a beneficial owner is any natural person who owns 25% or more of shares, voting rights or ownership interest, directly or indirectly, in the entity. The previous test captured only holdings strictly above 25%, so an equal four-way split of 25% each produced no beneficial owner under the old rule and produces four under the new one.
Cyprus firms should re-run every client and in-house structure against the 25%-or-more test and update their Cyprus UBO register and beneficial ownership compliance filings where new owners now qualify.
For higher-risk categories of entities, the beneficial-ownership threshold can be lowered to as low as 15%, so a smaller holding triggers identification. The reduced threshold targets sectors and structures the AMLR treats as inherently higher risk.
The practical consequence for Cyprus is a two-tier analysis: the default 25%-or-more test for ordinary entities, and a 15% test for higher-risk ones, which compliance teams must map to their client base rather than applying a single number across the board.
The lower threshold expands who must appear on the Cyprus beneficial-ownership register maintained through the Registrar of Companies, and it sharpens discrepancy-reporting duties when an obliged entity's own findings differ from the register. Obliged entities that identify a mismatch must report it, and the register must reflect the 25%-or-more standard.
Because the register data and the AMLR standard must align, Cyprus firms should treat register remediation and internal UBO-file remediation as one project, not two.
Nominee arrangements, trusts and multi-layer holding chains require the obliged entity to look through to the natural persons who ultimately own or control 25% or more, and to record nominee relationships. Trust structures, including a Cyprus international trusts and asset protection vehicle, must identify settlor, trustee, protector, beneficiaries and any other person exercising ultimate control.
These look-through scenarios are where Cyprus corporate service providers carry the most remediation work, because layered structures that previously produced no UBO at 25% may now surface several.
The AMLR introduces a harmonised EUR 10,000 limit on cash payments for goods and services across the EU, including Cyprus, from 10 July 2027. Member states may set a lower national limit, and identity verification is required for occasional cash transactions between EUR 3,000 and EUR 10,000.
For a cash-using economy this is a hard operational rule: any trader in goods or services must decline cash above EUR 10,000 for a single purchase, however it is structured to look like separate payments.
The EUR 10,000 cash cap is an EU-wide ceiling, and member states retain discretion to impose a lower national threshold. Cyprus has not yet fixed its final national figure, so firms should plan for EUR 10,000 while watching for a lower Cyprus limit.
The cap applies to a single operation or linked operations, so splitting a large payment into sub-EUR 10,000 tranches does not escape it.
For occasional cash transactions between EUR 3,000 and EUR 10,000, the AMLR requires identity verification even though the payment is below the cap. This creates an intermediate band where the transaction is lawful but the customer must be identified.
Cyprus traders should build a two-band process: identify and verify between EUR 3,000 and EUR 10,000, and refuse cash above EUR 10,000.
Traders in high-value goods, such as dealers in precious metals, jewellery, art or motor vehicles, must apply the cash cap and, where they are obliged entities, the full customer-due-diligence regime. The AMLR sets tiered monetary triggers: dealers become obliged entities where they trade in precious metals and stones, or in jewellery, watches and similar goods above EUR 10,000, in luxury motor vehicles above EUR 250,000, or in aircraft and boats above EUR 750,000.
High-value-goods dealers should confirm both whether they are obliged entities and which monetary trigger applies before designing their controls.
The AMLR keeps the existing obliged-entity base and adds new categories, so more Cyprus businesses fall inside AML law than before. The expansion brings in crypto-asset service providers, crowdfunding platforms and intermediaries, consumer and mortgage credit intermediaries, investment migration operators, and traders in high-value goods.
Every obliged entity, old or new, must comply from 10 July 2027, except professional football clubs and agents, whose rules apply from 10 July 2029.
Crypto-asset service providers become obliged entities under the AMLR, aligning AML rules with the Markets in Crypto-Assets Regulation, alongside crowdfunding platforms and consumer and mortgage credit intermediaries. These categories must now run full customer due diligence, beneficial-ownership checks and suspicious-transaction reporting.
Cyprus firms licensed as Cyprus crypto-asset service providers (CASPs) should treat the AMLR as an addition to their MiCA obligations, and those advising on cryptocurrency taxation in Cyprus should flag the AML overlay to clients.
Investment migration operators and traders in high-value goods are brought into scope, reflecting the AML risk in residence-and-citizenship-by-investment services and in high-value cash-intensive trades. Investment migration intermediaries must apply customer due diligence to applicants and their source of funds.
For Cyprus, with an active investment-migration and property-advisory market, this widens the obliged-entity base beyond the traditional financial sector into service providers who previously sat outside AML law.
The existing Cyprus obliged-entity base remains fully in scope: banks, Cyprus Investment Firms, Electronic Money Institutions, payment institutions, administrative service providers, trustees, accountants, auditors and lawyers. These entities continue to carry the core AML burden and must migrate their frameworks to the AMLR.
Regulated firms such as those operating under the Cyprus Investment Firms (CIFs) licensing framework should treat the AMLR migration as a licence-critical project, because AML failings threaten authorisation.
AMLA supervises through two channels: direct supervision of a small group of the highest-risk cross-border entities, and indirect oversight of national supervisors for everyone else. Most Cyprus obliged entities remain supervised nationally by CySEC, ICPAC, the Central Bank of Cyprus and MOKAS, while AMLA sets standards and monitors the supervisors themselves.
The Cyprus reality is that direct AMLA supervision will touch very few local entities, but AMLA's indirect influence over Cyprus supervisors will reshape how every firm is examined.
AMLA will directly supervise up to 40 selected obliged entities across the EU, with the selection process starting on 1 July 2027, running six months, and direct supervision transferring to AMLA from 1 January 2028. The selection is reviewed every three years.
Given the small number of directly supervised entities across the whole EU, only the largest cross-border Cyprus financial institutions are realistic candidates, and most Cyprus firms will not be directly supervised.
Direct supervision targets obliged entities that operate in at least six member states and present the highest residual risk, so cross-border footprint plus risk drives selection. An entity active in only Cyprus, or in fewer than six member states, is unlikely to be selected.
This criterion matters for Cyprus groups with a genuinely pan-European presence, which should assess whether their footprint and risk profile could place them in the selected pool.
For entities not directly supervised, national supervisors remain the front line: CySEC for investment firms and CASPs, ICPAC for accountants and auditors, the Central Bank of Cyprus for banks and payment and electronic-money institutions, and MOKAS as the financial intelligence unit. AMLA oversees these supervisors to drive consistency.
This division of labour reflects the supervisory split already operating under Law 188(I)/2007, which the Cyprus legislation transposing AMLD6 is expected to preserve while confirming each entity type's competent supervisor. Firms should map each of their regulated activities to the corresponding supervisor once that legislation is in place.
AMLA holds sanctioning powers over the entities it directly supervises, and MOKAS remains the Cyprus recipient of suspicious and threshold reports and the hub of financial-intelligence cooperation. National supervisors retain enforcement powers over the entities they supervise.
The dual structure means a Cyprus firm answers to its national supervisor and MOKAS in the ordinary course, with AMLA in the background as standard-setter and, for a select few, as direct enforcer.
The compliance gap analysis is a structured comparison of a firm's current AML framework against the AMLR single rulebook, producing a remediation plan. For Cyprus CIFs, EMIs and trustees it centres on four workstreams: policy migration, UBO-data remediation, group-wide policies and technology upgrades.
Starting the gap analysis early is decisive, because remediation of UBO data and transaction-monitoring systems is slow and cannot be compressed into the weeks before 10 July 2027.
The first step is to map each provision of your existing AML manual, built on Law 188(I)/2007, to the corresponding AMLR article and record every gap. Where the AMLR imposes a new or stricter obligation, the manual must be rewritten rather than annotated.
This mapping produces the remediation backlog: each identified gap becomes a task with an owner and a deadline inside the twelve-month window.
UBO data must be re-collected and re-verified against the 25%-or-more standard, and against the 15% standard for higher-risk structures, so that every newly qualifying owner is captured. This is the largest single remediation task for corporate service providers and trustees.
Firms should prioritise structures with exact 25% holdings and layered ownership, and reconcile their files against the Cyprus beneficial-ownership register to resolve discrepancies.
Groups must implement group-wide AML policies, and firms relying on outsourcing or reliance arrangements must confirm those arrangements meet the AMLR standard. The compliance function must retain accountability even where activities are outsourced.
Cyprus firms in international groups should align their local framework with group policy and document the division of responsibility, because the AMLR holds the obliged entity accountable regardless of outsourcing.
Technology for sanctions screening, adverse-media screening and transaction monitoring must be recalibrated to the AMLR thresholds, including the EUR 10,000 occasional-transaction trigger and the cash-band verification rules. Systems that encode the old EUR 15,000 threshold or the more-than-25% test must be reconfigured.
A phased remediation checklist keeps the programme on track:
Non-compliance exposes obliged entities to administrative pecuniary sanctions, national enforcement and licensing risk. AMLA can impose sanctions on directly supervised entities, Cyprus national supervisors enforce against the entities they oversee, and AML failings can jeopardise a firm's authorisation.
The financial-services entities that dominate Cyprus have the most to lose, because an AML breach is not only a fine but a threat to the licence the business depends on.
AMLA can impose administrative pecuniary sanctions on the obliged entities it directly supervises for serious, systematic or repeated breaches. Under Article 22 of the AMLA Regulation (EU) 2024/1620, these sanctions can reach up to EUR 10 million or 10% of the total annual turnover of the entity, whichever is higher, calculated on the last available audited consolidated accounts of the ultimate parent. These ceilings sit alongside the enforcement powers that Cyprus national supervisors retain over the entities they oversee.
Cyprus supervisors, including CySEC, ICPAC and the Central Bank of Cyprus, retain enforcement powers over the entities they supervise, ranging from fines to directions and licence action. National enforcement is the channel most Cyprus firms will actually face.
Because supervision remains largely national, a Cyprus firm's day-to-day enforcement risk sits with its own supervisor rather than with AMLA.
Beyond fines, AML failings carry reputational and licensing consequences, because a regulated entity that cannot demonstrate AMLR compliance risks conditions on, or loss of, its authorisation. For a CIF or EMI, the licence is the business.
Reputational damage compounds the regulatory risk, since counterparties and banks increasingly screen for AML robustness before doing business.
A Cyprus obliged entity should run a phased twelve-month remediation programme, assign board-level accountability, and use specialist legal support for the gap analysis and policy rebuild. Preparation should begin well before 2027, because UBO remediation and system reconfiguration are slow.
The firms that start early convert a compliance obligation into a competitive signal of reliability; those that wait risk a rushed, incomplete migration.
A realistic remediation programme runs twelve months or more, moving from gap analysis, through policy rebuild and UBO remediation, to system upgrades, training and sign-off. Each phase has dependencies, so the sequence matters as much as the deadline.
| Phase | Core tasks | Indicative timing |
|---|---|---|
| Assess | Gap analysis, business-wide risk assessment | Months 1 to 3 |
| Rebuild | Policies, procedures, compliance-function structure | Months 3 to 6 |
| Remediate | UBO data to 25%/15%, register reconciliation | Months 4 to 9 |
| Upgrade | Screening and transaction-monitoring systems | Months 6 to 10 |
| Embed | Staff training, testing, board sign-off | Months 9 to 12 |
The takeaway is that a firm starting the programme in 2026 has adequate runway to 10 July 2027, while one starting in 2027 does not.
The board and senior management are accountable for the AML framework, and the AMLR expects a named senior manager to own AML compliance alongside the compliance officer. Accountability cannot be delegated to the compliance function alone.
Boards should receive the gap-analysis findings, approve the remediation budget, and monitor progress against the twelve-month plan, documenting their oversight for the supervisor.
A Cyprus law firm adds value by mapping the AMLR to the specific Cyprus obliged-entity type and its actual supervisor, drafting compliant policies, and advising on UBO, trust and Cyprus controlled foreign company (CFC) rules and structuring questions that intersect with AML. Legal input is decisive where the analysis turns on statutory interpretation and the pending Cyprus transposing law.
Firms should also align AML remediation with wider compliance obligations, including an overview of taxes in Cyprus and substance requirements, so that structures remain both AML-compliant and tax-efficient.
Philippou Law Firm advises Cyprus obliged entities across the full obliged-entity base, from CIFs, EMIs and payment institutions to administrative service providers, trustees, accountants and crypto-asset service providers, on preparing for the new EU AML package. Our team runs AMLR gap analyses mapped to your specific supervisor (CySEC, ICPAC, the Central Bank of Cyprus or MOKAS), rebuilds AML policies and the compliance-function structure, remediates UBO data to the 25%-or-more standard, and guides your board through a realistic twelve-month roadmap to 10 July 2027. Contact us to scope your gap analysis and remediation programme before the deadline narrows your options.
This article is general information, not legal advice. For advice on your specific circumstances, contact a qualified Cyprus advocate.
Book a free 30-minute consultation with a partner.
Book free consultation
Managing Partner
Managing Partner with a distinguished career in corporate and commercial law, trust law, tax law, property law, litigation, and immigration law. First-Class LL.B. from the University of Leicester and LL.M. from the University of Cambridge.
View profile
VideoCorporate nominee services in Cyprus place a regulated local professional on the public company register in your place, as nominee director, nominee shareholder or company secretary, and provide the registered office address that every Cyprus company must have by law.

Cyprus MiCA transition ended 1 July 2026. Check if your CASP is authorised, pending, or must wind down after the 27 Feb 2026 CySEC deadline.

How to set up a family office in Cyprus in 2026: single vs multi-family thresholds, trust, PTC, foundation and holdco structures, real costs and tax treatment.
Related Services
“Fabulous service from everyone at Philippou Law. We moved here in July and had our immigration sorted with Nikolas and Laura, our tax residency, non-dom and the opening of our business was seamlessly done by Cleo, and we are also buying our house with them, where Maria and Elpida have been wonderful. Honestly I would not go anywhere else. Many thanks all.”
Free Consultation
Book a free, no-obligation consultation with one of our experienced lawyers. As one of the most established law firms in Paphos, we're here to help you navigate the legal landscape of Cyprus with confidence.
No fees. No obligations. Speak with a qualified lawyer today.