Blog · Automation
AML-CFT: obligations, regulated entities and required framework

On this page
AML-CFT imposes a comprehensive framework on banks, insurers, brokers, financial advisors, and many other professions: risk classification, customer due diligence, Tracfin reports, and internal controls. An overview of the obligations.
AML-CFT stands for anti-money laundering and counter-terrorism financing. Behind the acronym lies a precise legal framework: professions exposed to money laundering risks must know their customers, monitor transactions, report suspicions, and implement internal controls. The framework is defined by EU anti-money laundering directives, transposed into Articles L561-1 et seq. of the French Monetary and Financial Code.
This framework is not limited to major banks. A five-person brokerage firm, an independent financial advisor, or a startup fintech must comply as soon as their activity falls within its scope.
Who is subject to these obligations?
Article L561-2 of the French Monetary and Financial Code lists the concerned professions. The main ones include:
Financial sector. Banks and credit institutions, payment and electronic money institutions, investment firms, asset management companies, insurance companies and mutuals, insurance brokers, banking intermediaries (IOBSP), financial investment advisors and financial advisors, digital asset service providers.
Accounting and legal professions. Chartered accountants and statutory auditors, notaries, enforcement officers, lawyers for certain transactions, court-appointed administrators and liquidators.
Other exposed sectors. Real estate agents, gambling professionals, art dealers, precious metals and high-value goods dealers, company formation agents.
The pillars of the framework
Risk classification
Each regulated entity must map its risks: client types, products, distribution channels, and geographic areas. This classification is not a decorative document. It determines the level of due diligence applied to each client and the frequency of file updates.
Customer due diligence
This is the KYC component: identifying the client and their ultimate beneficial owners, understanding the business relationship, and updating information. Due diligence is tiered into three levels: simplified for low risk, standard for general cases, and enhanced for high risk. Politically exposed persons are subject to additional due diligence measures as required by law.
Suspicious activity reporting to Tracfin
When a professional knows, suspects, or has reasonable grounds to suspect that a transaction involves funds from criminal activity or terrorism financing, they must file a suspicious activity report with Tracfin, France’s financial intelligence unit. A lesser-known point: it is prohibited to inform the client that a report has been filed.
Asset freezing
Regulated entities must promptly detect individuals and entities listed in the national freezing register and block their assets. This requires screening clients upon onboarding and monitoring updates to the register.
Training, procedures and internal controls
The system must be documented in internal procedures, known to teams through regular training, and audited: continuous monitoring first, then periodic reviews for entities required to do so. An undocumented or unaudited system risks being deemed deficient during an inspection, even if practices are correct.
Who audits, and what are the risks?
Supervision depends on the profession: the ACPR for banking and insurance, the AMF for asset management firms and investment advisors, and professional bodies for accountancy and legal services. Audits cover the entire system: risk classification, client files, declarations, and governance.
Non-compliance may result in disciplinary and financial penalties imposed by sanction committees, which are usually published by name. Fines often reach several hundred thousand euros, and far more for major institutions. The reputational cost of a published sanction often exceeds the fine amount.
Maintaining the system over time
The hardest part is not writing the procedure—it’s keeping it alive: updating files, monitoring lists, tracing controls, and producing reports. This recurring workload is well-suited to automation, provided that decisions remain human and every action is logged.
This is the approach we detail on our KYC and AML-CFT automation page: automate data collection, reminders, document extraction, and monitoring, while leaving compliance teams to make the final decisions. For the IT resilience aspect of the financial sector, see also our article on the DORA regulation.
What is a suspicious activity report?
It is the report submitted to Tracfin when a regulated professional suspects that a transaction involves illicit funds or terrorism financing. It is filed via the Ermes platform without notifying the client: disclosure is prohibited by law.
What is a politically exposed person (PEP)?
A person who currently holds or has held, within the past year, a prominent public function (e.g., government member, parliamentarian, ambassador, or head of a public company), as well as their close associates. PEPs are subject to enhanced due diligence measures in addition to standard checks.
What is the difference between KYC and AML-CFT?
KYC (Know Your Customer) involves identifying, verifying, and updating client information. AML-CFT (Anti-Money Laundering and Counter-Terrorism Financing) is the full framework, of which KYC is one pillar, alongside risk classification, Tracfin reporting, asset freezing, and internal controls.
Are small firms really audited?
Yes. Supervisors also audit brokerage firms, financial advisors, and small entities, often through thematic campaigns. Size affects the expected depth of the system, not its existence: this is the principle of proportionality.
Related articles
Aug 11, 2026
DORA Regulation: Who is affected and what are the obligations
The European DORA regulation has applied since January 2025 to financial entities. IT risk management, incidents, resilience testing, provider oversight: what it mandates, and how it changes your contracts.
Aug 11, 2026
KYC: definition, obligations, and practical verification
KYC (Know Your Customer) refers to the identity and status verification of clients, mandated by the AML-CFT framework. Who is affected, which documents to collect, how often to update files: a comprehensive overview.
Jun 11, 2026
n8n vs Make vs Zapier: which tool to automate your processes?
Zapier for quick starts, Make for complex visual scenarios, n8n for sovereignty and control. An honest comparison to help you choose.