Blog · Automation

AML-CFT: obligations, regulated entities and required framework

Aug 11, 20268 min readby Scroll
AML-CFT: obligations, regulated entities and required framework
On this page

AML-CFT imposes a comprehensive framework on banks, insurers, brokers, financial advisors, and many other professions: risk classification, customer due diligence, Tracfin reports, and internal controls. An overview of the obligations.

AML-CFT stands for anti-money laundering and counter-terrorism financing. Behind the acronym lies a precise legal framework: professions exposed to money laundering risks must know their customers, monitor transactions, report suspicions, and implement internal controls. The framework is defined by EU anti-money laundering directives, transposed into Articles L561-1 et seq. of the French Monetary and Financial Code.

This framework is not limited to major banks. A five-person brokerage firm, an independent financial advisor, or a startup fintech must comply as soon as their activity falls within its scope.

Who is subject to these obligations?

Article L561-2 of the French Monetary and Financial Code lists the concerned professions. The main ones include:

Financial sector. Banks and credit institutions, payment and electronic money institutions, investment firms, asset management companies, insurance companies and mutuals, insurance brokers, banking intermediaries (IOBSP), financial investment advisors and financial advisors, digital asset service providers.

Accounting and legal professions. Chartered accountants and statutory auditors, notaries, enforcement officers, lawyers for certain transactions, court-appointed administrators and liquidators.

Other exposed sectors. Real estate agents, gambling professionals, art dealers, precious metals and high-value goods dealers, company formation agents.

The pillars of the framework

Risk classification

Each regulated entity must map its risks: client types, products, distribution channels, and geographic areas. This classification is not a decorative document. It determines the level of due diligence applied to each client and the frequency of file updates.

Customer due diligence

This is the KYC component: identifying the client and their ultimate beneficial owners, understanding the business relationship, and updating information. Due diligence is tiered into three levels: simplified for low risk, standard for general cases, and enhanced for high risk. Politically exposed persons are subject to additional due diligence measures as required by law.

Suspicious activity reporting to Tracfin

When a professional knows, suspects, or has reasonable grounds to suspect that a transaction involves funds from criminal activity or terrorism financing, they must file a suspicious activity report with Tracfin, France’s financial intelligence unit. A lesser-known point: it is prohibited to inform the client that a report has been filed.

Asset freezing

Regulated entities must promptly detect individuals and entities listed in the national freezing register and block their assets. This requires screening clients upon onboarding and monitoring updates to the register.

Training, procedures and internal controls

The system must be documented in internal procedures, known to teams through regular training, and audited: continuous monitoring first, then periodic reviews for entities required to do so. An undocumented or unaudited system risks being deemed deficient during an inspection, even if practices are correct.

Who audits, and what are the risks?

Supervision depends on the profession: the ACPR for banking and insurance, the AMF for asset management firms and investment advisors, and professional bodies for accountancy and legal services. Audits cover the entire system: risk classification, client files, declarations, and governance.

Non-compliance may result in disciplinary and financial penalties imposed by sanction committees, which are usually published by name. Fines often reach several hundred thousand euros, and far more for major institutions. The reputational cost of a published sanction often exceeds the fine amount.

Maintaining the system over time

The hardest part is not writing the procedure—it’s keeping it alive: updating files, monitoring lists, tracing controls, and producing reports. This recurring workload is well-suited to automation, provided that decisions remain human and every action is logged.

This is the approach we detail on our KYC and AML-CFT automation page: automate data collection, reminders, document extraction, and monitoring, while leaving compliance teams to make the final decisions. For the IT resilience aspect of the financial sector, see also our article on the DORA regulation.

What is a suspicious activity report?

It is the report submitted to Tracfin when a regulated professional suspects that a transaction involves illicit funds or terrorism financing. It is filed via the Ermes platform without notifying the client: disclosure is prohibited by law.

What is a politically exposed person (PEP)?

A person who currently holds or has held, within the past year, a prominent public function (e.g., government member, parliamentarian, ambassador, or head of a public company), as well as their close associates. PEPs are subject to enhanced due diligence measures in addition to standard checks.

What is the difference between KYC and AML-CFT?

KYC (Know Your Customer) involves identifying, verifying, and updating client information. AML-CFT (Anti-Money Laundering and Counter-Terrorism Financing) is the full framework, of which KYC is one pillar, alongside risk classification, Tracfin reporting, asset freezing, and internal controls.

Are small firms really audited?

Yes. Supervisors also audit brokerage firms, financial advisors, and small entities, often through thematic campaigns. Size affects the expected depth of the system, not its existence: this is the principle of proportionality.