
Section 58 of the Law lists the things a firm's anti-money-laundering procedures have to cover. Client due diligence is the first item on that list. The last item is your own staff. Neither the Law nor ICPAC then tells you how to assess them, which leaves the how to you.
The section is one sentence with a list hanging off it. From the consolidated Greek text on CyLII, which is the only version of this Law in front of me: «Υπόχρεη οντότητα εφαρμόζει επαρκείς και κατάλληλες πολιτικές, ελέγχους και διαδικασίες, οι οποίες είναι ανάλογες με τη φύση και το μέγεθός της, ώστε να μετριάζει και να διαχειρίζεται αποτελεσματικά τους κινδύνους νομιμοποίησης εσόδων από παράνομες δραστηριότητες και χρηματοδότησης της τρομοκρατίας, σε σχέση με τα ακόλουθα». My translation, as is every English rendering of the statute below: an obliged entity applies adequate and appropriate policies, controls and procedures, which are proportionate to its nature and size, so as to mitigate and effectively manage the risks of money laundering and terrorist financing, in relation to the following.
Plainly: for each thing on the list the firm is to have a policy, a control or a procedure, sized to the firm it actually is, and aimed at the money laundering and terrorist financing risk. The verb is «εφαρμόζει», present indicative, which is the voice Cyprus statutes use for a duty. I have rendered it applies; shall apply carries the same force. It is not may.
Then the list. Identification and customer due diligence, under sections 60 to 66. Record-keeping. Internal reporting and reporting to MOKAS. Internal control, risk assessment and risk management. Thorough examination of transactions that by their nature are particularly susceptible of being connected to money laundering or terrorist financing, in particular complex or unusually large ones. Informing employees about those systems, the legislation, the supervisor's directives, the EU directives and data protection requirements. The regular training of employees. Risk management practices. Compliance management. And then it stops, at (ια): «την πρόσληψη και αξιολόγηση της ακεραιότητας των υπαλλήλων» — the recruitment and assessment of the integrity of employees. The Law does not write among others at the head of that list, and it does not write anything after (ια).
The duty is the statute's, not a supervisor's. Section 58 addresses «υπόχρεη οντότητα», an obliged entity, and draws no distinction between one supervisor's flock and another's. Section 59 names the supervisory authorities and empowers each to issue binding directives to the persons under its supervision. So the item reads the same whoever supervises you; what varies is the directive laid over it. Only one of those directives is in front of me, and it is ICPAC's.
That Directive, issued to ICPAC's members under sections 59(1)(d) and 59(4), reproduces the statutory list in English at paragraph 1.3.3, opening with The Law requires that all firms apply adequate and appropriate policies, controls and procedures. The entry reads Recruitment and assessment of employees' integrity. In ICPAC's ordering it is not the last one; risk management practices and compliance management follow it. Proportionality moves too. The Law carries it in the opening sentence; ICPAC puts it in a closing one, Appropriate controls and procedures established by firms in the areas mentioned above, should be proportional to the nature and size of the firms.
What ICPAC adds is one sentence, at 2.1.6: Firms should take necessary measures to assess their employee's integrity not only on recruitment but also on an ongoing basis. Should, not must, and addressed to ICPAC's own members. The statutory item names recruitment and assessment and says nothing at all about when the assessing happens. The not-only-at-hiring is the supervisor's, and it is a should.
Now the part I established by looking for it and failing to find it. I searched the Greek for ακεραιότητ, πρόσληψ, υπαλλήλ and εργοδοτουμέν, searched the English Directive for integrity, recruit, screen and employee, and read Part VIII of the Law and the Directive end to end. Neither text says how. No criminal-record certificate for staff. No sanctions or PEP list run across your own people. No statement of which roles are in scope. No definition of integrity either: the Law's interpretation section defines neither «ακεραιότητα» nor either of the two different words section 58 uses for the staff themselves, «υπαλλήλων» in the last item and «εργοδοτουμένων» in the ones about informing and training.
The silence is worth weighing, because both texts prescribe method elsewhere when they mean to. At 5.3.5 the same Directive says firms are required to conduct background screening and perform background checks against sanctions lists and PEPs lists — for clients. And the Law does reach criminal records, at 59(6A)(ε), where the competent Supervisory Authority checks, in accordance with national law, the criminal record of the person concerned for a relevant conviction, and at 59(5A), where supervisors take the necessary measures to stop persons convicted of relevant offences, or their accomplices, from holding a management position or being beneficial owners in an obliged entity. Those are the supervisor's mechanisms, addressed to the supervisor. Neither one is your (ια) procedure.
This paragraph is mine and not either text's, and none of it is a legal requirement: since the design is yours, write down what the design is, name the roles it reaches, say what you look at before someone starts, and say what makes you look again — a move into an AML-sensitive seat, a change in someone's circumstances, an interval you choose. Not one of those triggers appears in the Law or in the Directive. You are the one picking them.
The Law put your own people on the same list as your clients and then said nothing about method. That silence is not a gap someone else is going to fill for you. It is the part you write.
Not legal advice. Verify against the primary source before acting.
FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.
Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗