An AML Guide in 2026: Assessing Risks, KYC, CDD, Duties & Responsibilities

An AML Guide in 2026: Assessing Risks, KYC, CDD, Duties & Responsibilities

Financial crime is about far more than financial loss. Its consequences extend to the trust, integrity, and stability that underpin the financial system and the wider economy. By exploiting financial institutions, markets, and payment channels for unlawful purposes, including money laundering, tax evasion, and terrorist financing, criminal actors can weaken economic resilience, distort legitimate competition, and undermine confidence in both public and private institutions. 

These risks are becoming increasingly complex as financial systems grow more interconnected across borders, digital platforms, and emerging technologies. Criminal networks and extremist groups are continually adapting their methods, using increasingly sophisticated techniques to move, conceal, and disguise illicit funds. This makes the detection and disruption of financial crime more challenging and places greater pressure on institutions to remain vigilant. 

In this article, the SALVUS Regulatory Compliance Team provides essential guidance for financial institutions navigating the complex landscape of AML, as we break down as follows:

1. What is Money Laundering and Terrorist Financing
2. Key Roles Responsible for AML/KYC in CIFs
3. CDD, KYC, and the Risk-Based Approach 
4. How can SALVUS assist?


We regularly share bite-sized insights on LinkedIn such as those found in this article

1. What is Money Laundering and Terrorist Financing 

 Money laundering and terrorist financing pose serious risks to global security, economic stability, and the integrity of the financial system. Money laundering involves disguising the source of funds generated through criminal activity so that they appear legitimate and can be used without attracting suspicion. Terrorist financing, on the other hand, refers to the provision or collection of funds to support terrorist acts or organisations, and these funds may come from either illegal or legitimate sources. 

Both activities take advantage of weaknesses within financial systems, often involve transactions across multiple jurisdictions, and continue to evolve alongside new technologies and payment methods. Understanding how these crimes operate is essential to identifying suspicious activity, disrupting illicit financial flows, and preventing funds from being used to support criminal or terrorist objectives. 

The Three Stages of Money Laundering:

  1. Placement – The illicit funds are introduced into the financial system. This might involve depositing cash into banks, purchasing high-value items, or using shell companies to mask the source. 
  2. Layering – The money is moved through a complex series of transactions to obscure its origin. This can include wire transfers, offshore accounts, cryptocurrency exchanges, or converting funds into assets like art or real estate. 
  3. Integration – The laundered money is reintroduced into the economy as seemingly legitimate income. It may be invested in businesses, used to buy property, or spent on luxury goods. 

Money Laundering is about cleaning “dirty” money from past crimes, while Terrorist financing is about raising or moving money to commit future crimes, regardless of how the money was obtained. 

In Cyprus, the key government bodies responsible for overseeing Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) are the Central Bank of Cyprus (CBC), Cyprus Securities and Exchange Commission (CySEC), the Cyprus Bar Association, the Institute of Certified Public Accountants of Cyprus (ICPAC), and the Unit for Combating Money Laundering (MOKAS). 

2. Key Roles Responsible for AML/KYC in CIFs 

CySEC-regulated entities, including CIFs, must implement robust Anti-Money Laundering (AML) and Know Your Customer (KYC) procedures. Here’s who holds responsibility: 

  1. Board of Directors 
    • Ultimate accountability for AML/KYC compliance.
    • Must ensure the firm has adequate resources, policies, and systems in place. 
    • Approves the AML Manual and reviews the Annual AMLCO Report.
  2.  AML Compliance Officer (AMLCO), AML Director, and Alternate AMLCO 
    • Appointed by the Board and approved by CySEC. 
    • Designs and oversees the implementation of AML policies and procedures. 
    • Submits AMLCO reports to CySEC. 
    • Ensures staff training and monitors suspicious activity reporting.
  3.  Compliance and Risk Teams 
    • Conduct Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD).
    • Monitor transactions and flag suspicious behavior. 
    • Maintain records and ensure timely reporting. 

3. CDD, KYC, and the Risk-Based Approach 

Customer Due Diligence (CDD) and Know Your Customer (KYC) refer to the process of identifying and verifying a customer’s identity and evaluating the level of risk associated with the customer.  

Key Components of CDD and KYC 

  • Identification and Verification, it is the collection of official documents (e.g., passports, utility bills) to confirm the customer’s identity. 
  • Understanding the Business Relationship, it is determining the purpose and intended nature of the relationship, why the customer is opening an account or conducting certain transactions. 
  • Beneficial Ownership Identification, it is knowing who ultimately owns or controls the customer, especially in corporate structures. 
  • Screening, checking whether customers are listed at global sanctions lists, identified to be politically exposed persons (PEPs), and any adverse media. 
  • Periodic Reviews, reviewing transactions to ensure they align with the customer’s profile and expected behavior and to any changes. 

CDD and KYC helps institutions detect red flags early, such as unusual transaction patterns or inconsistencies in customer information. 

A Risk-Based Approach requires institutions to apply a level of due diligence that is proportionate to the customer’s assessed risk. The following components illustrate how this approach is applied: 

  • Risk Assessment, it is the process of evaluating customer based on the risks that they pose based on the following factors 
    • Customer Risk, whether they are PEP, complexity of the entity structure, or entity type. 
    • Geographical Risk, whether they are located or doing business to high-risk countries 
    • Products, services and transactions, whether their products or services are among the prohibited or high-risk business activities. 
    • Delivery Channels, whether establishing business relationship is non-face-to-face or through third parties. 
  •  Risk Categorization, based on the risk they pose as per above categories, customers can be classifying as low, medium, or high risk. 
  • Due Diligence, foundation for reviewing and collecting customer information 
    • Simplified Due Diligence (SDD) for low-risk customers. 
    • Standard Due Diligence (SDD) for medium-risk customers. 
    • Enhanced Due Diligence (EDD) for high-risk customers. 

4. How can SALVUS assist you?

The SALVUS Regulatory Compliance team supports firms in developing risk-based compliance frameworks, performing gap analyses, strengthening Customer Due Diligence (CDD) procedures, and preparing for CySEC inspections and audits. Our solutions are tailored to each firm’s business model and regulatory obligations.

Whether you are newly licensed or an established institution seeking to strengthen your compliance framework, we provide practical tools, targeted training, and strategic guidance to help you keep pace with evolving AML/CFT requirements. 

In partnership with the Institute for Professional Excellence (IforPE), SALVUS proudly presents a self-paced CPD course titled An AML Guide in 2026: Assessing Risks, KYC, CDD, Duties & Responsibilities, designed to provide knowledge on the AML duties, responsibilities, risks, and concepts such as KYC and CDD. Suited and recommended for the required annual Continuous Professional Development (CPD).  

Please contact us at compliance@salvusfunds.com if you require support with your AML/CFT regulatory compliance obligations or are interested in our IforPE courses.

#StayAhead

The information provided in this article is for general information purposes only. You should always seek professional advice suitable to your needs.

Share this post