
Cyprus AML law asks a firm for two different things about what its own staff know, and it is easy to do one of them and count it as both. Telling people the rules is one item. Training them to recognise a suspicious transaction is a separate item, with a separate object. A circular does the first one.
The list is section 58 of L.188(I)/2007: one sentence saying an obliged entity applies adequate and appropriate policies, controls and procedures, proportionate to its nature and size, in relation to the following, and then a list. Three of the items on it are about your staff. One, the last, is recruitment and the assessment of integrity, a different subject. The other two are about what your people know and can do, and they are the two this card is about. Everything I quote from the Law is Greek and translated by me; the consolidated Greek text on CyLII is the only version I had.
The first is (στ): «την ενημέρωση των εργοδοτουμένων του σχετικά με» — the informing of its employees regarding — and then five things. The systems and procedures under paragraphs (α) to (ε). This legislation. The competent Supervisory Authority's directives under section 59(4). The EU's directives from time to time on preventing use of the financial system for money laundering and terrorist financing. And the relevant personal-data protection requirements.
The second is (η): «την τακτική εκπαίδευση των εργοδοτουμένων του πάνω σε θέματα αναγνώρισης και χειρισμού συναλλαγών και δραστηριοτήτων οι οποίες πιθανόν να συνδέονται με αδικήματα νομιμοποίησης εσόδων από παράνομες δραστηριότητες ή χρηματοδότησης της τρομοκρατίας» — the regular training of its employees on matters of recognising and handling transactions and activities which may possibly be connected with money laundering or terrorist financing offences.
Plainly: one item is about rules, the other about transactions. The object of (στ) is a body of rules, the firm's own systems and procedures and then four sets of texts. The object of (η) is what walks through your door, and the verbs attached to it are recognising and handling.
The Law nowhere says that a circular is not training. I am reading that off the structure: two separately lettered items with different objects, so doing the first does not do the second. Note too what (η) does not carry: «τακτική» is regular, not annual, not quarterly. I searched the statute for εκπαίδευση, εκπαιδ, κατάρτιση, ενημέρωση and εργοδοτουμένων: this is the only training duty it puts on an obliged entity, and no interval is attached to it anywhere.
The detail comes from your supervisor. Section 59(4) says a Supervisory Authority issues directives to those under its supervision, binding and obligatory as to their application, which specify the details and the manner of applying this Part. Section 58 addresses «υπόχρεη οντότητα», an obliged entity, without distinguishing between supervisors. Only one of those directives is in front of me: ICPAC's.
ICPAC keeps the split. At 10.1.1, firms should take appropriate measures to inform staff of the Law, the ICPAC Directive and all EU AML/CFT Directives, and should also ensure staff are aware of and familiarised with the policies and procedures in its section 2.1 and the relevant provisions of the personal data law; it is good practice that all staff have read the AML manual and confirm they understand it. Separately, at 10.1.2, firms should ensure staff are provided ongoing training enabling them to recognise and handle transactions and activities which may be related to money laundering and terrorist financing. At 10.3.4 it adds that awareness can also be raised via emails, newsletters and team meetings, among other means — awareness, in a chapter that keeps the two in separate paragraphs.
Role differentiation is ICPAC's contribution, not the Law's, and the modals move. Timing, content and methods should be tailored to the firm (10.3.1); the staff categories at 10.4.1 could be considered, and each firm may adjust them. Within them: new professional staff who will deal with clients or their affairs, whatever their seniority, must obtain a general appreciation of the background, CDD and reporting procedures; front line staff, the firm's eyes and ears, should be trained on what may give rise to suspicion and on what to do when something is deemed suspicious; staff who can accept clients must receive that front line training, and training should be given on the firm's client verification procedures; top level management should get a higher level of instruction, from a list ICPAC itself calls non exhaustive; the Compliance Officer must receive in-depth training and carries an annual requirement for 10 specialised CPD units. That number is the only one in the chapter. For everyone else, 10.3.2 leaves frequency to key factors like legal changes and the firm's risk profile, and 10.3.3 asks for refresher trainings at regular intervals while allowing that repeating a complete programme may not be necessary.
Now the evidence, which is mostly an absence. I searched the Directive for attendance, register, record and test, and read its record-keeping chapter through. Neither text requires you to keep a training log. What the Directive does want written down is the procedure: at 2.1.3, all firms should document, in a manual, the procedures and controls for the areas listed at 2.1.2, and training and awareness of staff is one of them. The chapter 8 five-year retention list is CDD material, transaction records, client correspondence and suspicious reports; training is not on it. The documentation duty at 4.9 is about the risk-based approach framework and the risk assessments, not training. What the Directive does ask is at 10.3.4: a system of tests, or some other method obtaining assurance on the effectiveness of the trainings, should also be considered. Plus 10.1.1's read-and-confirm, and 3.2.1(g), where the Compliance Officer determines whether employees need further training.
So the texts ask for assurance that the training worked, not proof that it happened. What follows is mine and is not a legal requirement: keep the record anyway, because assurance you cannot show is assurance nobody can check — and file the test result, not the signature on the attendance sheet.
Send the circular. It discharges an item. The other item is a person who can look at a payment and feel that something is off, and that is not something you can send.
Not legal advice. Verify against the primary source before acting.
FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.
Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗