
AMLA has harmonised the reasoning behind an enforcement decision rather than the price of one, and the provision that will decide most Cyprus files puts a repeated breach at least in category three.
The Final Report published with AMLA's press release of 8 July 2026 carries the draft regulatory technical standards under Article 53(10) of Directive (EU) 2024/1640, on pecuniary sanctions, administrative measures and periodic penalty payments. It is one horizontal text for financial and non-financial supervisors. AMLA sets out consecutive steps: assess the gravity of a breach against common indicators, classify it into one of four categories, then set the sanction or measure. Supervisors apply supervisory judgement throughout, and AMLA states the lists of indicators and criteria are non-exhaustive.
Article 1 fixes what every supervisor must take into account, to the extent it applies: duration, repetition, the conduct of whoever committed, permitted or did not prevent the breach, impact on the entity and on its ML/TF exposure, the nature of the breach, whether it could have facilitated criminal activity, structural failure, financial viability, impact on the financial system or internal market, systematic nature, and any other indicator the supervisor identifies.
Article 2 turns that into four categories. Category one needs minor or no impact, short duration and no repetition together, and is unavailable where the indicators from facilitating criminal activity through to systematic nature are met. Category two is moderate impact with none of those met. A breach is at least category three where the supervisor finds the repetition indicator met, or the systematic-nature indicator, or where significant impact has persisted over a significant period. Category four covers very significant impact, structural failure, facilitating significant criminal activity, or significant impact on viability or on the financial system. Breaches that would not reach category three in isolation could amount to category three or four in combination.
Article 3 is the sharp end. A breach classified as category three or four is deemed serious, repeated or systematic in the meaning of Article 55(1) AMLD — the provision requiring pecuniary sanctions for such breaches of the internal policies, customer due diligence and reporting chapters of Regulation (EU) 2024/1624 and of its record-retention article. Article 55(2) requires the available maximum to be at least twice the benefit derived where that can be determined, or at least EUR 1 000 000, whichever is higher; the larger figures in Article 55(3) reach only credit and financial institutions.
Mitigation is narrower than aggravation. Two criteria reduce the level: cooperation, which AMLA frames as bringing the complete breach to the supervisor quickly and effectively and contributing actively to the investigation, and effective, timely remedial action once it is identified. Six increase it, among them concealment, intent, benefit derived, losses to third parties and previous breaches. Both lists end with any other criteria the supervisor identifies. Category three or four is also the first criterion in each of AMLA's three lists for the most serious administrative measures: restricting business, withdrawing or suspending an authorisation, and requiring a change in governance structure.
The draft goes to the Commission for adoption, then the Official Journal. It applies from 10 July 2027, a date still bracketed in the draft and deferred to 10 July 2029 for football clubs and agents, and not to proceedings begun before then. Until then national law applies — in Cyprus, through supervisors such as the Bar Association, ICPAC and CySEC.
Nothing to file this year. But the two things that pull a sanction down are both evidence: what you disclosed, and how fast you fixed it.
Not legal advice. Verify against the primary source before acting.
FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.
Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗