
Your AML manual is a record of what your firm actually does. It is not a statement of what it means to do. ICPAC writes the duty in the past participle: document the procedures implemented and the controls applied. So a manual describing a control nobody performs is not a cautious document. It is an inaccurate one.
Start with where the word comes from, because it does not come from the Law. I searched the whole consolidated Greek text of L.188(I)/2007 for εγχειρίδιο, manual, and the statute never uses it once. The Law is Greek, no official English version was in front of me, and every English rendering here is mine.
What section 58 asks for is a set of things you apply. It does not name a document. An obliged entity applies adequate and appropriate policies, controls and procedures, which are proportionate to its nature and size, so as to mitigate and effectively manage the risks of money laundering and terrorist financing, in relation to the following — and then a lettered list: client due diligence, record keeping, internal reporting and reporting to MOKAS, internal control and risk assessment and management, the thorough examination of transactions that by their nature are especially open to being linked to such offences, the informing of employees, their regular training, risk management practices, compliance management, and the recruitment and assessment of the integrity of staff. Plainly: the Law hands you a list of areas and tells you to run adequate controls across them, sized to your firm. The operative verb in the opening line is «εφαρμόζει». Applies.
Section 58Γ says who signs those off, and the phrase to watch is two words long. «Τα ανώτερα διοικητικά στελέχη υπόχρεης οντότητας εγκρίνουν τις πολιτικές, τις διαδικασίες και τους ελέγχους που εφαρμόζει η υπόχρεη οντότητα σε σχέση με τη νομιμοποίηση εσόδων από παράνομες δραστηριότητες και τη χρηματοδότηση της τρομοκρατίας, παρακολουθούν δε και, όπου ενδείκνυται, ενισχύουν τα μέτρα που έχουν ληφθεί.» My translation: the senior management officials of an obliged entity approve the policies, the procedures and the controls that the obliged entity applies in relation to money laundering and terrorist financing, and they monitor and, where appropriate, strengthen the measures that have been taken. Plainly: what gets approved is not a plan. It is the control set the firm is running — «που εφαρμόζει», that it applies — and the duty does not stop at the signature. It continues into monitoring and strengthening.
The manual as a container is ICPAC's. At 2.1.2 it lists eight areas, lettered (a) to (h), for which obliged entities should have appropriate procedures in place: they are the Directive's own chapter headings, from the appointment of a compliance officer to training and awareness of staff. Then 2.1.3: all firms should document the procedures implemented and the controls applied in relation to (a) to (h) above in a manual, to prevent money laundering and terrorist financing; the manual and procedures adopted must be approved by Senior Management officials of the firm; arrangements should also be made to update the manual in accordance with the latest provisions of the Law and the risk appetite of the management. Plainly: write your procedures and controls into one document, have senior management officials approve it, and keep it in step with the Law and with management's risk appetite.
Read those three sentences for their verbs and their strength. Should document, must be approved, should also be made — the hardest of the three modals sits on the approval, not on the writing. And the writing is described in the past participle twice over: implemented, applied. Not the procedures envisaged. Not the controls planned. ICPAC's own words in the closing paragraph of 4.2.3 do the same thing from the other side: senior management officials must also approve the policies, procedures and controls applied by their firms. Applied is doing the same work there as «που εφαρμόζει» does in 58Γ.
On who approves, neither text ties the approval to a seat on the board. ICPAC defines a Senior Management Official as an officer or employee with sufficient knowledge of the obliged entity's money laundering and terrorist financing risk exposure and sufficient seniority to take decisions affecting that exposure, irrespective of whether the said person is a member of the Board of Directors. Section 2 of the Law defines «ανώτερο διοικητικό στέλεχος» in near-identical terms and ends on the same clause. Neither text says the board approves the manual. ICPAC's separate definition of Senior Management does reach board members of companies and partners of partnerships; 2.1.3 is not the paragraph that uses it.
The rest of the Directive keeps loading the manual with things you do rather than things you would do. Where a firm appoints assistant compliance officers — larger firms may choose to — the assistant's role must be clearly specified and documented in the firm's corresponding manual. Among the steps a firm must follow when implementing a risk based approach to client risk is designing and documenting the procedures and controls in appropriate manuals and policies, with the purpose stated in the same line: to ensure uniform application across the firm. Uniform application. Not uniform intention.
What the Law itself puts in writing, it puts in the same voice. Section 58Α(2): the risk assessments referred to in 58Α(1) «τεκμηριώνονται, επικαιροποιούνται και τίθενται στη διάθεση της αρμόδιας Εποπτικής Αρχής» — are documented, updated and made available to the competent Supervisory Authority. A documented record of risks you have actually assessed. And what gets checked afterwards is the practice, not the binder: where it is appropriate given the size and nature of the entity's activities, section 58Β has an independent internal audit service set up to verify the internal policies, controls and procedures referred to in section 58, while ICPAC's 2.1.4 asks firms to make arrangements to verify, on a regular basis, the compliance with and the effectiveness of policies, procedures and controls.
Here is what neither text says, and I want to be exact about it. Neither the Law nor the Directive states anywhere that a manual which diverges from practice is a breach. That a divergent manual is an inaccurate document rather than a conservative one is my reading of the tenses, not a finding either source publishes.
So, and this part is mine and is not a requirement anywhere: when you review the manual, do not read it for whether it says enough. Read a paragraph, then ask who performed that control last month and what they left behind. If nobody did, the paragraph is not protecting you — it is a sentence your supervisor can hold up against your files. And if somebody did something the manual never mentions, you have a control running without the approval 58Γ puts in senior management's hands.
Two failure modes, and they are not symmetrical. A control you perform but never wrote down is undocumented, and a morning's work fixes it. A control you wrote down but never perform is not a gap in the manual. It is the manual being wrong about your firm, and no amount of further writing repairs that.
Not legal advice. Verify against the primary source before acting.
FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.
Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗