
A client you never meet in person is not, by that fact alone, a higher-risk factor under Cyprus law. The factor is a remote relationship or transaction without certain safeguards, and the safeguards the Law gives as examples are electronic identification, relevant trust services, and secure identification processes that a Cypriot competent authority regulates, recognises, approves or accepts. A scanned passport and a video call are not among them.
The factor is in Annex III of L.188(I)/2007, which the Law heads an indicative list of factors and types of evidence of potentially higher risk. The Law is Greek, no official English text was in front of me, and every English rendering here is mine. Paragraph 2(c) of that Annex, in full: business relationships or transactions without the physical presence of the parties, without certain safeguards, such as electronic identification means, relevant trust services as defined in Regulation (EU) No 910/2014 and in the Cypriot law implementing that Regulation, or any other secure, remote or electronic identification process that is regulated, recognised, approved or accepted by a competent Authority of the Republic.
Plainly: read as written, the factor has two conditions, and it needs both. The client was not physically present. And the relationship or transaction lacks certain safeguards. The Greek stacks them side by side: «χωρίς φυσική παρουσία των μερών, χωρίς ορισμένες διασφαλίσεις» — without the physical presence of the parties, without certain safeguards. The safeguards come with «όπως», such as, so the examples do not close the list. But a scan and a call are not on it.
What the factor does is set by section 64(3). An obliged entity applies enhanced due diligence measures, in addition to those in sections 60, 61 and 62, also in other cases which by their nature present a high risk of money laundering or terrorist financing; and in assessing those risks it takes into account at least the factors of potentially higher-risk situations set out in Annex III. Plainly: the factor is something you take into account, not a switch. Enhanced due diligence under 64(3) turns on the case presenting high risk by its nature, and Annex III is a floor for that assessment.
The safeguards are not new words. Section 61(1)(a), the first due diligence measure, is identifying and verifying the customer's identity on the basis of documents, data or information issued by or obtained from a reliable and independent source, including, where available, electronic identification means, relevant trust services as defined in the same Regulation and Cypriot law, or any other secure remote or electronic identification process regulated, recognised, approved or accepted by a competent Authority of the Republic. Plainly: the routes the Law accepts for verifying identity are the routes whose absence makes a remote relationship a higher-risk factor. The same list appears twice more: in section 67(3), among the copies a third party you rely on forwards to you, and in section 68(1), among the records you keep.
ICPAC's AML Directive, issued under section 59(4), adds a recommendation the Law does not state: meet the client in person where you can. At 5.4.2: as a general note, it is recommended that clients are met face to face whenever possible. Where not possible, mitigating steps, like for example video calling or a future face to face meeting, should be taken to reduce the AML and CTF risk involved. Video calls should be recorded and documented accordingly, and be readily available to MOKAS or ICPAC. Then: a video call is not to be considered equivalent to a face to face meeting, rather as a means to establish direct communication with the client. For legal persons, the meetings should be held with the beneficial owner or the person responsible for the decisions and management of the client's operations. Plainly: meet if you can; if you cannot, a recorded call helps, but it is not a meeting.
One ICPAC sentence is broader than the Law. At 4.3.7, on delivery channels: where clients have not been met face to face, or a third party authorised to represent the client is involved, the delivery channel risk is higher; where higher risk levels are identified, firms should establish mitigating controls; for higher risk factors relating to delivery channels, see Annex II. That sentence carries no safeguards limb. ICPAC's Annex II, which reproduces the Law's factor in English, does: non-face-to-face business relationships or transactions, without certain safeguards, such as electronic identification means. The Directive does not say how the two fit together, and I will not settle it for ICPAC. If you are an ICPAC member, decide how a client verified through one of those routes is scored on delivery channel, and write down why.
Two more ICPAC lines are worth knowing, and worth reading for what they are. At 5.7.4, which says EDD procedures must be customised to respond to areas that pose higher risk, a table of practical examples pairs "Non-resident & non-face to face" with "Additional identity verification". The row joins two conditions, and the table shows how to shape enhanced due diligence, not when it applies. And in the second part of Annex II, a list ICPAC heads "Risk Factors as highlighted by FATF", item 14 says that where interaction with the client takes place on a non-face to face basis, technological measures can be put in place to mitigate the heightened risk of identity fraud or impersonation. Can, not must.
What follows is mine and is not a requirement anywhere. For every client onboarded remotely, the file should say which route verified identity. If it was one of the Law's examples, name it and keep what it produced. If it was a scan and a call, treat paragraph 2(c) as in play, weigh it in the client's risk assessment, and keep the recording ICPAC asks for.
Not being in the room is half the factor. The other half is how you verified who was on the other end, and ICPAC has already said what a video call is: a means of direct communication, not a meeting.
Not legal advice. Verify against the primary source before acting.
FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 3 free full assessments, no card required.
Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗