Key Takeaways
- Foreign-owned companies and their advisers may fall within Cyprus AML and KYC requirements depending on the activities they carry out.
- Customer due diligence, a risk-based assessment and ongoing monitoring of business relationships form the core of AML obligations in Cyprus.
- Suspicious activity must be reported through the MOKAS process, and AML records must be kept in line with the prescribed requirements.
- Non-compliance with AML and KYC rules can lead to penalties, making the registered agent's role central to keeping a Cyprus company compliant.
Understanding AML and KYC Obligations in Cyprus
Anti-money laundering and know-your-customer rules in Cyprus set out how businesses must identify their clients, assess risk, and report suspicious activity to the authorities. These obligations rest on the Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), which transposes successive EU directives and incorporates the standards of the Financial Action Task Force. The framework binds a defined list of regulated businesses, from banks and investment firms to lawyers, accountants, and the corporate service providers that administer foreign-owned structures.
This article explains how the regime operates in practice: the regulators involved, the due diligence and monitoring expected, record-keeping duties, the reporting channel through the national Financial Intelligence Unit, and the penalties for getting it wrong. A useful starting reference for the wider EU position is the Eversheds Sutherland guide. The material is most relevant to non-resident owners of holding companies and to the advisers who manage their compliance from abroad.
The AML Legal Framework and Supervisory Authority
Law 188(I)/2007 is the spine of the system, and it has been reshaped repeatedly to keep pace with EU rules. The Fourth AML Directive entered local law through amending Law 13(I)/2018, and the Fifth followed via Law 61(I)/2021, adopted on 20 April 2021. Parliament made further targeted changes on 23 December 2024.
Supervision is split by sector rather than concentrated in one regulator. The Central Bank of Cyprus oversees banks and credit institutions; CySEC supervises investment firms, crypto-asset service providers, and Trust and Company Service Providers; the Institute of Certified Public Accountants of Cyprus covers accountants and auditors; the Cyprus Bar Association covers lawyers.
For a foreign owner, this matters because your service providers answer to different supervisors with different rulebooks. CySEC tightened its sectoral directive through R.A.D 282/2024, published on 5 August 2024, while the Central Bank issued Directive K.D.P. 120/2025, in force from 2 June 2025, strengthening board accountability and prohibiting the full outsourcing of compliance functions.
Above the supervisors sits MOKAS, the national Financial Intelligence Unit within the Attorney General's department. Staffed by government lawyers, police, and customs officers, it receives reports, analyses them, and pursues investigation and prosecution. An apex committee, the AML Advisory Authority, coordinates the framework and advises the Council of Ministers on reform.
The EU AML Regulation 2024/1624 becomes directly applicable across member states from 10 July 2027, alongside the Sixth AML Directive and a new EU authority, AMLA, based in Frankfurt. Some of its rules, including cash and high-value-goods reporting thresholds, already shape local practice.
Company Incorporation in Cyprus
Set up your company in Cyprus with Expanship handling registration end to end.
Who Is Subject to AML and KYC Requirements
The law names a closed list of obliged entities. It runs across banks, cooperative societies, investment and stockbroking firms, insurers, accountants, advocates, trust and company service providers, money transfer businesses, dealers in precious metals and stones, casinos, and crypto-asset service providers, together with other designated non-financial businesses and professions.
Real estate agents fall in only where rents exceed €10,000. Following amendments in 2025, crypto-asset service providers are classified as financial entities, and they must apply customer due diligence on occasional transactions of €1,000 or more. Casinos and gambling operators apply due diligence at transactions of €2,000 or above.
A point that frequently confuses non-resident investors concerns holding companies. A passive holding entity is not normally an obliged entity, because it does not provide financial or professional services to third parties.
That distinction does not place such a company outside the system. Its service providers, the bank, auditor, and corporate secretary, owe AML duties when dealing with it, and the holding itself must register its beneficial owners, keep accurate records, and produce KYC documentation when asked.
Two thresholds drawn from EU Regulation 2024/1624 are worth flagging. Cash transactions above €10,000 must use traceable methods, and traders in high-value goods must report acquisitions to MOKAS where, for example, a motor vehicle bought for non-commercial use reaches €250,000, whether or not anything looks suspicious.
Customer Due Diligence and KYC Requirements
Customer due diligence, governed by Sections 60 to 66 of Law 188(I)/2007, is the practical core of what a foreign owner experiences. Identity must be verified before any business relationship begins or any transaction is carried out. The exercise extends beyond a name check to building an economic profile and verifying both source of wealth and source of funds.
For an individual, the expected documents are a government-issued photo identification and proof of residential address dated within three months. For a corporate client, the bar is higher.
| Document | Purpose |
|---|---|
| Certificate of Incorporation | Confirms legal existence |
| Certificate of Registered Office | Confirms address |
| Memorandum and Articles of Association | Confirms governing rules |
| Register of shareholders with percentages | Identifies ownership |
| Register of directors and secretary | Identifies control |
| ID for beneficial owners above 25% | Identifies ultimate ownership |
The beneficial ownership trigger is a shareholding of 25% plus one share, or an ownership interest of more than 25%, held by a person or a group acting together. Directors and authorised signatories must also be identified.
Enhanced due diligence is a legal requirement, not an optional step, reinforced by CySEC Directive R.A.D 282/2024. It applies to politically exposed persons, clients from high-risk third countries, and unusually complex or large transactions. In those cases the firm gathers detailed source-of-funds and source-of-wealth information, assesses the purpose of the relationship, and generally needs senior management approval before onboarding.
Remote onboarding is permitted. Section 61 was amended to allow a risk-based approach using EU electronic identification and trust services under Regulation 910/2014, or another secure process recognised by a competent authority. Where the beneficial owner is a senior executive of the entity, the firm must take reasonable steps to verify that person and record both the actions taken and any difficulties met.
Ongoing Compliance in Cyprus
Keep your Cyprus entity compliant with filings, returns, and statutory obligations.
Risk-Based Approach and Customer Risk Assessment
The law expects obliged entities to calibrate their controls to risk rather than apply identical procedures to every client. The depth of an AML programme should reflect the nature, scale, and risk profile of the business. Proportionality, however, is not exemption; lighter risk justifies lighter procedure, not none.
The 2021 National Risk Assessment singled out real estate, professional services, and corporate structures as areas of elevated exposure. That finding directly affects foreign-owned holding companies, which combine professional administration with cross-border ownership.
Certain features push a relationship into enhanced territory automatically. These include:
- Politically exposed persons among shareholders or directors
- Owners from jurisdictions on the EU high-risk third country list
- Offshore ownership layers or third-party payments
- Transaction features that raise a question about the legitimacy of funds
Both the 2024 CySEC directive and the 2025 Central Bank directive treat enhanced checks as mandatory in higher-risk situations. Supervised institutions must screen their customer base against EU and UN sanctions lists, in real time before processing a transaction, and review for adverse media in the press, online, and in commercial databases.
The Central Bank's 2025 directive also pins responsibility on the boardroom. A designated director must own compliance implementation, the board must approve the compliance officer's appointment, senior management must receive regular reporting on control effectiveness, and high-risk relationships need board or senior management sign-off before they begin.
Ongoing Monitoring of Business Relationships
Due diligence does not end at onboarding. Firms must monitor transactions and keep client information current throughout the relationship, refreshing risk profiles when adverse media or other negative information surfaces.
Reassessment is also event-driven. A change in ownership, a director becoming politically exposed, or expansion into a high-risk jurisdiction must prompt an immediate review, irrespective of any scheduled cycle. Enhanced due diligence clients are reviewed more frequently after onboarding, typically at least once a year.
Banks carry an additional reporting layer of their own. Every bank must file a monthly report to the Central Bank covering cash deposits above €10,000 and incoming or outgoing transfers above €500,000 or equivalent.
Cyprus-registered entities must log into the Beneficial Ownership Register between 1 October and 31 December each year to confirm their recorded details, even when nothing has changed. Changes in ownership must be filed within 14 days.
Cyprus Incorporation Pricing
See transparent pricing to incorporate and maintain a company in Cyprus.
AML Record-Keeping Requirements
Records exist to support any future investigation, so the retention rules are firm. Customer identification and transaction records must be kept for five years from completion of the relevant business; where MOKAS opens an investigation, retention continues until it confirms the case is closed.
The same five-year minimum applies to records of suspicious transaction reports and to beneficial ownership information, which must stay available even after the reason for holding it ends. That period can be extended to support criminal or administrative proceedings.
Records may be held electronically or in another form, provided everything can be retrieved without delay. Because this data is personal, it sits under GDPR as well as AML law: it must be stored securely, made accessible to regulators on request, and protected against misuse. A fuller treatment of these duties appears in this record-keeping overview.
Suspicious Activity Reporting and the MOKAS Process
Anyone who, in the course of business, acquires knowledge or reasonable suspicion that another person is laundering money must report it to MOKAS as soon as reasonably practical, under Section 69. Silence is itself a criminal offence, not merely a regulatory lapse.
Obliged entities file Suspicious Transaction Reports where they know, suspect, or have reasonable grounds to suspect a link to money laundering or terrorist financing. No monetary threshold applies; suspicion alone triggers the duty. MOKAS reviews the reports, analyses trends, and forwards verified cases to the police for investigation.
After a disclosure, the reporting entity follows MOKAS instructions, including whether to execute or suspend a transaction. A bank that delays or declines a customer order on those instructions bears no contractual liability for doing so. MOKAS can also apply to court for freezing, confiscation, and disclosure orders that override bank secrecy.
Discretion around an investigation is mandatory. Disclosing to the subject of suspicion, or to a third party, while knowing or suspecting that authorities are investigating, constitutes a "tipping off" offence under the amended Section 48, carrying up to two years' imprisonment or a fine of up to €50,000. A safe harbour protects advisers: an auditor or lawyer who tries to deter a client from illegality does not commit tipping off.
Reporting a potential sanctions breach to the National Sanctions Implementation Unit is independent of reporting suspicion to MOKAS. A single event can trigger duties to both bodies, so do not treat one filing as discharging the other.
The Role of the Registered Agent in AML Compliance
For a non-resident owner, the corporate service provider is the AML relationship that matters most day to day. In local usage, Trust and Company Service Providers are called Administrative Service Providers, and they are obliged entities supervised by CySEC. They must run due diligence, then detect, mitigate, and report suspicion while serving you.
Their regulated activities include forming a company or trust, supplying a registered office, and arranging directors. Each of these brings the provider, and therefore your structure, into scope.
The practical effect is repeated verification. When a holding company opens a bank account, engages a corporate provider, or appoints an auditor, each professional firm must confirm who owns and controls the structure. Expect to disclose the purpose of the arrangement, which for a holding company usually means managing investments, receiving subsidiary dividends, or consolidating group assets.
Accountants and auditors answer to ICPAC, whose mandatory AML directive requires documented screening against politically exposed person, sanctions, and adverse information lists for clients, beneficial owners, significant shareholders, directors, and signatories. Lawyers answer to the Cyprus Bar Association. Bank account opening for a holding structure typically runs from two to six weeks, longer where the ownership chain or the jurisdictions involved are complex.
Penalties for AML and KYC Non-Compliance
Consequences run from administrative fines to imprisonment, and they reach both individuals and companies. The headline criminal exposure under Law 188(I)/2007 is severe.
| Breach | Maximum penalty |
|---|---|
| Knowing money laundering (individual) | 14 years' imprisonment and/or €500,000 fine |
| "Ought to have known" (individual) | 5 years' imprisonment and/or €50,000 fine |
| Tipping off | 2 years' imprisonment and/or €50,000 fine |
| Administrative fine (supervisors) | Up to €1,000,000 |
| Sanctions breach (NSIU Law) | Up to €500,000, plus €500 daily for continuing breach |
Legal persons can be held criminally liable where the offence was committed on their behalf by someone in a leading or controlling position. Supervisory authorities, empowered by Article 59, can fine up to €1,000,000 and cancel licences, and the Registrar can strike off entities that persistently ignore beneficial ownership duties. The Central Bank's 2025 directive raised certain specific penalties from €100,000 to €350,000.
Enforcement is active, not theoretical. In 2024, CySEC issued fines totalling €2.7 million after 850 on-site and remote audits, and imposed roughly €2.3 million in fines and settlements in 2025. The harneys analysis of strengthened sanctions obligations sets out the parallel sanctions regime that overlaps with these powers.
Beyond the figures, the commercial fallout bites. A record of AML or sanctions breaches can complicate raising capital, entering new markets, and keeping correspondent banking relationships intact.
Conclusion
The weight of AML and KYC in Cyprus falls less on a passive foreign owner directly and more on the regulated firms that serve the structure, yet that is precisely why preparation pays. Your bank, auditor, and corporate service provider will repeatedly demand clean ownership evidence and a credible account of your source of funds, and any gap stalls onboarding or freezes activity.
The single move that protects you is to assemble and keep current a complete ownership and source-of-wealth file before you need it. Treat every change in ownership or control as a reporting event, and confirm your beneficial ownership entry in the annual window without waiting to be chased.
How Expanship Can Help Your Business in Cyprus
Expanship supports non-resident owners through the AML and KYC demands that surround a Cyprus entity, preparing the ownership and source-of-funds documentation that banks and regulated providers require and keeping it current as your structure evolves. The same team handles the broader compliance needs of a foreign-owned company across its life cycle.
- Company formation and structuring for non-resident owners
- Registered agent and registered office services
- Ongoing compliance monitoring and filing management
- Accounting and bookkeeping support
- Economic-substance and beneficial-ownership assistance
- Introductions to banking partners
To discuss your obligations and next steps, contact Expanship Cyprus.
Frequently Asked Questions
A passive holding company is not normally an obliged entity, because it does not provide financial or professional services to third parties. It still must register its beneficial owners, keep accurate records, and produce KYC documentation on request, while its bank, auditor, and corporate secretary carry the AML duties that apply when dealing with it.
Customer identification and transaction records must be retained for five years from completion of the relevant business, and the same minimum applies to suspicious transaction reports and beneficial ownership information. Where MOKAS opens an investigation, records must be kept until it confirms the case is closed, and the period can be extended to support proceedings.
An individual provides a government-issued photo identification and proof of residential address dated within three months. For a corporate client, expect to supply incorporation and registered office certificates, the memorandum and articles, registers of shareholders and directors, and identification for every beneficial owner holding more than 25%.
Suspicious activity is reported to MOKAS, the national Financial Intelligence Unit, under Section 69 of Law 188(I)/2007. The duty arises on suspicion alone with no monetary threshold, and failing to report when you know or reasonably suspect money laundering is itself a criminal offence.
Knowing money laundering can draw up to 14 years' imprisonment or a fine of up to €500,000, while supervisory authorities can levy administrative fines reaching €1,000,000 and revoke licences. CySEC issued €2.7 million in fines across 850 audits in 2024, which shows the enforcement is real rather than nominal.
Cyprus-registered entities must access the Beneficial Ownership Register between 1 October and 31 December each year to confirm their recorded details, even where nothing has changed. Any change in ownership must be filed within 14 days of it occurring.
Legal Disclaimer
The information provided in this article is for general informational purposes only and does not constitute legal, tax, or professional advice. While we strive to ensure the accuracy and timeliness of the content, laws and regulations are subject to change, and the application of laws can vary widely based on specific facts and circumstances.
Readers should not act upon this information without seeking professional counsel tailored to their individual situation. Expanship and its authors disclaim any liability for actions taken or not taken based on the content of this article.
For specific advice regarding your business setup, compliance requirements, or any legal matters, please consult with qualified legal and tax professionals in the relevant jurisdiction.