FIRMCY Insights

Would a stranger agree

Practice notes · all insights
Would a stranger agree

Cyprus law names the kinds of transaction you have to examine. Nothing tells you what should actually stop one. You set the thresholds. You write the red flags. You decide whether a second pair of eyes ever sees the file. What is not yours to set is the standard the write-up has to meet.

The statute is the starting point, not the specification. Section 64(4) of L.188(I)/2007 requires an obliged entity to examine, as far as reasonably possible, the background and purpose of transactions of certain kinds, and to intensify the degree and nature of its monitoring to determine whether they appear suspicious. It describes those transactions by category. It gives you no amount, no velocity, no rule that fires.

ICPAC's AML Directive, issued under section 59(4) of that Law, hands the design straight back to the firm. Paragraph 5.9.1: firms should perform a detailed examination of each transaction which by its nature may be considered to be particularly vulnerable to money laundering activity or terrorist financing, and in particular complex or unusually large transactions and all other unusual patterns of transactions which have no apparent economic or visible lawful purpose. The same categories the Law names, then. To do so, firms should design relevant procedures taking into consideration the type of services provided to the client, as well as the level of risk attached to the client and its activities and apply appropriate parameters and factors to identify and target such vulnerable transactions.

Plainly: build something that catches the vulnerable transactions, sized to the client in front of you and the service you sell them. What follows is a menu, not a recipe. Such parameters and factors may include, and then eight bullets, from financial thresholds personalised for each client to the use of red flag indicators. May include.

A lawyer gets the same instruction in the other language. Chapter ΣΤ of the Bar Association's AML Directive of August 2023, which exists in Greek only, opens its ongoing-monitoring section at ΣΤ.1.3 with a worked example rather than a rule: «Φερ' ειπείν, μια Εταιρεία μπορεί να διεξάγει συνεχή παρακολούθηση με:». For instance, a firm may conduct ongoing monitoring by. At ΣΤ.1.4 the factors to weigh when examining a transaction come in the same voice: a firm may consider, for example, the following factors. That list closes «Τονίζεται ότι ο παραπάνω κατάλογος δεν είναι εξαντλητικός» — it is stressed that the above list is not exhaustive. The translations here are ours.

One thing the Bar does put in the imperative sits inside that permissive list. Identifying and examining transactions that are complex, unusually large, unusually patterned or without apparent economic or lawful purpose is to be, in the Greek, «συνοδευόμενη από καταγραφή της διαδικασίας και των αποτελεσμάτων που ανέκυψαν» — accompanied by a record of the process and of the results that arose. And at ΣΤ.1.7, what a firm looks at when it considers re-rating the client is «τα καταγεγραμμένα ευρήματα», the recorded findings. Not the findings. The recorded ones.

For the how, ICPAC's Directive points its members at a separate document: the Guidance to ICPAC Members on Transaction Monitoring, updated August 2022, forty-eight pages. It is written almost entirely as suggestion, and it says so. The aim of this Guidance is not to provide rigid and risk proof solutions but rather to suggest a series of questions and considerations which Members could use to scrutinize transactions involving their clients in their effort to identify wrongdoing. Its longest section is a set of suggested questions. Its annex is titled Detailed Suggested Working Programs.

Setting the parameters is explicitly the firm's job. The Guide's advice on doing it is to avoid extremes, giving very high or very low financial limits as the example, and to be alert and flexible to adjust and update according to cases identified, and national and international typologies. It is essential to place equal weight to pre-transaction checks as well as post-transaction checks. And each firm should ensure that no transaction is processed if it does not pass the test of legality, reasonableness and business rationale.

The second pair of eyes is optional. It is essential for firms, to set up a policy of reviewing transactions — but depending on the size, structure, resources and services offered by the firm, it may choose to set up an additional four-eye review process, in some cases performed only by the compliance officer, in larger firms by a team of experts not involved in the engagements. What goes to that review is not prescribed either. The Guide lists nine indicative characteristics of transactions which ICPAC Members may wish to be dealt with in a four-eye review process: among them, a transaction whose size and nature is outside the known, normal and verified activities of the client; one that is ambiguous, unclear and difficult to understand, whose terms fall outside the industry norm; one that lacks commercial rationale and business justification. The ninth is any other indicator which the engagement team may consider appropriate to refer to the review team. A list of nine that ends by inviting a tenth is not a rule.

The spot check runs in the same voice. Members may also adopt transaction spot-check reviews. Indicatively, in determining the sample, firms may wish to place emphasis on transactions carried out by high-risk clients, high value transactions, repeated transactions or transactions involving high risk jurisdictions — and the Guide adds that there may be other factors which could direct a Member to sample on different criteria. It is advisable that a cold review of smaller case takes place every quarter and a larger scale review is carried out once a year depending on the size of operations. Advisable.

Then the register changes. No matter what process a firm implements, it is of paramount importance to ensure that the reviews are carried out using a specific review program, using the detailed considerations provided in the Guidance, in order to achieve uniformity and consistency. The results of the cold reviews should be recorded, any deviations addressed promptly, and any required amendments to the policies and procedures effected swiftly.

And section L states the standard the record has to reach. All the work carried out when scrutinizing and monitoring transactions carried out by clients should be properly recorded so as to give a full picture of the verification work carried out by the Member. The work recorded should be sufficiently detailed and the transaction documents that need to be maintained should be such as to enable a third party, including the supervisor and MOKAS to arrive at a similar if not the same conclusion, vis-à-vis the transaction, as the ICPAC Member.

In plain terms: the file is not written for you. It is written for someone who was not there — your supervisor, or the financial intelligence unit — and it has to carry enough detail that they get to a similar conclusion, if not the same one, working only from what you left behind. The Guide gives three reasons for that. It would provide members the necessary defence in case of a legal action against them. It would let you give MOKAS necessary and sufficient information in the event of an investigation. And it would let you prove to your Regulator that transactions are properly scrutinized.

So: you designed the trigger. You wrote the questions. You decided who else looks. None of that is the test. The test is whether someone who was not in the room, holding only your file, arrives where you arrived.

Not legal advice. Verify against the primary source before acting.

Sources

Published 8 September 2026 · Practice notes
Drafted with AI assistance. Reviewed, edited and approved before publication by a named person at Ioannou & Sharpe LLC, who takes editorial responsibility for its content. Approved by Harris Sharpe, 8 September 2026.

Screen against the current lists in seconds

FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.

Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗
© 2026 Ioannou & Sharpe LLC · VAT CY60007091D · Griva Digeni, Limassol Center, Block B, 3rd Floor, Office 304, 3095 Limassol, Cyprus · [email protected]
Not legal advice. FIRMCY publishes this analysis for general informational purposes; verify against the primary sources before acting.