Financial Integrity Monitor

Cyprus CY

Domains (D1–D6)
4
Sources
8
Role actions
8
Horizon <90d
3
Jurisdiction profile
CompliantTier BRisk: StableMixed

Cyprus applies the EU AML/CFT acquis via its AML/CFT Law, with MOKAS as FIU, CySEC as securities/CASP supervisor, and CBC as banking supervisor.

MoreAssessed by MONEYVAL under FATF standards, Cyprus remains in enhanced follow-up since its 2019 MER, rated partially compliant on non-profit organisations, correspondent banking, new technologies (crypto), and law-enforcement investigative powers. A national sanctions unit (NSIU/MEK), replacing a 2016 sanctions law, was legislated in 2025 after EU-deadline delays.

Key deficiencies
  • Partially-compliant FATF rating on new technologies/virtual assets (R.15), downgraded from largely compliant
  • Delayed operationalisation of the National Sanctions Implementation Unit past the EU's May 2024 deadline
  • Non-public beneficial ownership and trust registers limiting third-party/journalistic verification
  • Professional-enabler resistance (Bar Association) to sanctions-enforcement reforms affecting lawyer participation
  • Historically weak prosecutorial follow-through on citizenship-by-investment corruption (2026 acquittals)
Recent developments (18m)
  • ICIJ/OCCRP Cyprus Confidential fallout drove a three-pronged sanctions legislative package passed in 2025 criminalising sanctions evasion and creating a National Sanctions Implementation Unit
  • MONEYVAL/FATF published a further follow-up report on Cyprus's AML/CFT progress on 23 March 2026
  • OFAC designated multiple Cyprus-registered companies and Cypriot nationals under Russia-related EO14024 in November and December 2025
  • A Nicosia criminal court acquitted two former senior politicians in a golden-passport corruption case in February 2026, citing insufficient prosecution evidence
  • UK and Cyprus agreed cooperation (Dec 2024) on establishing the NSIU with OFSI/OTSI technical assistance and beneficial-ownership information sharing
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

The most structurally significant development for Cyprus this cycle is the formal close of the Markets in Crypto-Assets Regulation's national grandfathering window for crypto-asset service providers on 1 July 2026, following a 27 February 2026 application deadline. This retires Cyprus's AML-only national crypto registration regime in favour of full Markets in Crypto-Assets Regulation authorisation, with unauthorised providers required to wind down their operations. The finding carries a High confidence rating, anchored by a Tier 1 CySEC press release and corroborated across three independent secondary sources on both the application-deadline and expiry dates. This is treated as a structural regime transition rather than an incremental development, because it closes the last national-registration pathway available to crypto-asset firms operating in Cyprus and materially raises the compliance bar for CY-domiciled providers entering their first full MiCA supervisory cycle. Providers that have not secured full MiCA authorisation by the relevant deadline no longer have a national fallback registration to rely on, which sharpens the operational stakes of the transition considerably relative to prior cycles. The transition also converges with Cyprus's broader efforts to tighten its financial-crime architecture this cycle, discussed below, even as the crypto-specific compliance burden is assessed independently on its own evidentiary merits.

Other Developments

Sanctions enforcement build-out. CySEC's sanctions-breach criminalisation framework, implementing EU Directive 2024/1226, has been in force since 1 August 2025, and a National Sanctions Implementation Unit is now operational within the Ministry of Finance. This finding is assessed with moderate confidence, corroborated across two independent trade-press mirrors describing the same circular, though no Tier 1 CySEC circular text was located directly this cycle to confirm the precise scope of the new criminalisation framework.

AMLA data-collection groundwork. CySEC Circular C748, as amended by Circular C749, set a 12 January 2026 submission deadline for obliged entities to provide AMLA-related data, forming part of the groundwork for the EU AML Regulation becoming directly applicable across the European Union. This is an assessed-confidence finding, drawn from two independent vendor sources; no Tier 1 or Tier 2 anchor was located this cycle for the underlying circular text itself, so the precise scope of the data-collection exercise remains a research gap.

AMLR and 6AMLD direct applicability. The EU AML Regulation and the sixth Anti-Money Laundering Directive are moving toward, respectively, direct applicability and per-Member-State transposition, marking the first time EU anti-money-laundering law takes the form of a directly applicable Regulation rather than a directive requiring national transposition alone. This assessment rests on two independent Tier 4 sources only; no Tier 1 or Tier 2 anchor was located this cycle, and it is flagged accordingly as thinner-sourced than the MiCA finding above.

Cross-Monitor Connections

The MiCA transition intersects directly with the World Payments Monitor's own tracking of Cyprus's crypto-asset-service-provider licensing lifecycle, since the same 1 July 2026 grandfathering expiry that closes the AML-only national registration pathway also determines which providers may continue to offer payment-adjacent digital-asset services in Cyprus going forward. Separately, the sanctions-enforcement build-out and the AMLA data-collection groundwork under Circular C748/C749 both feed the same underlying supervisory infrastructure that Cyprus obliged entities will depend on as the EU AML Regulation and the Anti-Money Laundering Authority's direct and indirect supervision architecture come into force across the European Union. Both threads reflect Cyprus obliged entities preparing simultaneously for a new sanctions-enforcement architecture and a new EU-level AML supervisory architecture, on parallel but related timelines.

Outlook

The immediate item to watch is how CySEC applies its new sanctions-enforcement powers in practice now that the National Sanctions Implementation Unit is operational, since the current finding rests on secondary trade-press coverage rather than a located primary circular; a primary-source confirmation next cycle would materially firm up this finding's confidence. On the AMLA side, sources diverge on whether full AMLA direct supervision of high-risk cross-border obliged entities begins in 2027 or 2028; this date discrepancy is flagged for reconciliation and would sharpen the compliance-timeline picture for Cyprus obliged entities once resolved. On crypto, the practical test of the MiCA transition will be how many previously AML-registered Cyprus crypto-asset firms successfully convert to full MiCA authorisation versus wind down their Cyprus operations, a question this cycle's research could not yet answer and which next cycle should target directly. Taken together, these three threads point to a Cyprus financial-integrity posture that is genuinely building out formal architecture across sanctions, AML supervision, and crypto authorisation in parallel, even though the primary-source evidentiary base for two of the three threads remains thinner than ideal this cycle.

weekly_brief_draft · JID CY
Domain intelligence (D1–D6)

D1 Sanctions

Sanctions

Continue reading

Cyprus's sanctions-architecture posture this cycle shows two forces moving in parallel rather than in the same direction. On the enforcement-build-out side, CySEC's sanctions-breach criminalisation framework, implementing EU Directive 2024/1226, has been in force since 1 August 2025, with a National Sanctions Implementation Unit now operational within the Ministry of Finance. This is an assessed-confidence finding, corroborated across two independent trade-press mirrors describing the same circular, though the underlying CySEC circular text itself was not located directly this cycle, which caps confidence below the highest tier pending primary-source confirmation. Read on its own, this finding would suggest a jurisdiction tightening its domestic sanctions-enforcement machinery in a durable, institutional way: a dedicated implementation unit, sitting inside the Ministry of Finance rather than a sector regulator alone, is architecture rather than a single enforcement episode, and it should be weighted accordingly against a lighter, incident-level finding.

On the enablement side, however, Cyprus joined Greece and Malta this cycle in securing a softened maritime and tanker-restriction posture within the European Union's twentieth Russia-sanctions package, which added 120 new listings when adopted on 23 April 2026. This finding rests on a single quality-journalism source, with no corroborating Tier 1 or Tier 2 anchor located this cycle for the specific blocking role attributed to Cyprus, so it is treated as assessed rather than high confidence. The substantive point, however, is architectural rather than evidentiary: a jurisdiction with an economically significant shipping-registry interest lobbying to soften the maritime dimension of a collective EU sanctions package is a different kind of signal than an isolated non-enforcement episode. It sits alongside the criminalisation build-out as the other half of a genuinely mixed picture, in which Cyprus is simultaneously strengthening enforcement architecture that targets designated persons and entities while working to protect a specific economic sector, shipping, from the sharpest edges of the same sanctions regime.

Absence of enforcement action is itself a legitimate analytical signal in a jurisdiction with an economically significant permissive sector, and the maritime-softening finding should be read with that principle in mind rather than dismissed as a mere trade dispute. Neither finding individually determines Cyprus's overall sanctions-architecture trajectory; read together, they describe a jurisdiction building formal criminal-enforcement capacity for sanctions breaches while simultaneously exercising its negotiating leverage within the EU to protect a specific national economic interest from collective sanctions design.

The institutional placement of the National Sanctions Implementation Unit inside the Ministry of Finance, rather than housed within a single financial-sector regulator, is itself an architectural detail worth noting: it suggests a whole-of-government sanctions-implementation function rather than a narrower, sector-specific compliance unit, consistent with the broader EU push under Directive 2024/1226 to harmonise sanctions-breach criminalisation across member states as a matter of general criminal law rather than sector-specific financial regulation alone. On the EU package side, the addition of 120 new listings on 23 April 2026 represents one of the larger tranches within the ongoing sanctions-designation programme, and the negotiating role Cyprus played alongside Greece and Malta in softening its maritime dimension should be read against that scale: the softening applied to a specific sectoral carve-out within a substantially larger package, not to the package's core designations.

Both findings carry CTF-pillar significance under the three-pillar framework this monitor applies: the criminalisation framework and the National Sanctions Implementation Unit represent counter-terrorist-financing-adjacent architecture insofar as sanctions-evasion typologies frequently overlap with the customer-typology categories flagged this cycle, including correspondent-banking relationships and trade-finance structures. The maritime-softening finding likewise touches trade-finance and correspondent-banking customer typologies, given the role those channels play in financing and settling shipping-sector transactions connected to sanctioned trade flows. Firms operating across the cross-sector and banking categories identified in this cycle's affected-firm-type tagging should treat both findings as relevant to their own sanctions-screening and correspondent-relationship risk assessments, even though neither finding rises to the level of a specific enforcement action against a named institution this cycle.

Outlook

The clearest gap to close next cycle is locating a primary CySEC circular text for the sanctions-breach criminalisation framework now in force; the current finding rests entirely on trade-press mirrors, and a primary source would materially firm up confidence in both the scope and the operational reality of the National Sanctions Implementation Unit. On the maritime-softening finding, watch for any follow-through enforcement action, or lack of it, against Cyprus-flagged or Cyprus-linked tanker activity connected to the sanctioned Russian trade, since continued non-enforcement in that specific channel would corroborate the enablement reading rather than leave it as a single-package negotiating episode. More broadly, the coexistence of enforcement build-out and enablement-adjacent lobbying is itself the trend to track across coming cycles: if the pattern persists, it would support treating Cyprus's sanctions posture as structurally bifurcated rather than as a simple trajectory in either direction. Watch also for whether the EU revisits the maritime carve-out in a subsequent package, which would test whether this cycle's softening was a one-off negotiating outcome or the start of a durable pattern.

D2 Beneficial Ownership

Beneficial Ownership

Continue reading

Cyprus's most concrete beneficial-ownership and corporate-transparency development this cycle is procedural rather than substantive in the beneficial-ownership-register sense: CySEC Circular C748, as amended by Circular C749, set a 12 January 2026 deadline for obliged entities to submit data as part of the groundwork for the EU AML Regulation's single rulebook. This is an assessed-confidence finding drawn from two independent vendor sources; no Tier 1 or Tier 2 anchor was located this cycle for the underlying circular text, so the precise scope of what obliged entities were required to submit remains a research gap rather than a settled fact. Separately, the EU AML Regulation and the sixth Anti-Money Laundering Directive are moving toward, respectively, direct applicability and per-member-state transposition, a milestone described in the available sourcing as the first time EU anti-money-laundering law takes the form of a directly applicable Regulation rather than a directive alone. This finding rests on two independent Tier 4 sources only, thinner sourcing than the CySEC circular finding, and is flagged accordingly.

The obligation itself is tagged to a cross-sector firm-type lens and a corporate customer-typology, indicating that CySEC's data-collection exercise was not confined to a single supervised-entity category such as investment firms alone, but reached across the broader population of CySEC-supervised obliged entities. This breadth is itself informative: a cross-sector data call ahead of a supranational supervisory transition is consistent with a regulator preparing its full obliged-entity population for a harmonised reporting baseline, rather than targeting a narrow subset for a specific enforcement purpose.

Standing context for reading both findings is the durable architecture of the EU AML Package itself, which comprises three distinct instruments rather than one: the AML Regulation, or AMLR (Regulation (EU) 2024/1624), which is directly applicable across member states without national transposition; the sixth AML Directive, or 6AMLD, which is transposed individually per member state; and the AMLA Regulation (Regulation (EU) 2024/1620), which establishes the Anti-Money Laundering Authority itself. Together these three instruments shift the EU's AML supervisory perimeter from a purely national-authority model toward a hybrid regime in which the Anti-Money Laundering Authority exercises direct supervision over a first cohort of high-risk, cross-border obliged entities while national authorities continue to supervise the broader population. This is a structural, durable backdrop against which this cycle's Cyprus-specific signal should be read, not a single-cycle development in itself: Cyprus's CySEC Circular C748/C749 data-collection exercise is best understood as one jurisdiction's piece of groundwork for a supervisory architecture being built at EU level over multiple years.

That said, the precise timeline for AMLA's direct-supervision function remains genuinely unresolved in the sourcing available this cycle. One source places the AMLR/6AMLD application date in 2027, while another places the onset of AMLA's direct supervision of selected high-risk obliged entities in 2028; this date discrepancy has not been reconciled against a primary EU or CySEC source this cycle and is carried forward as an open item. Both dates share the same underlying direction, an EU AML supervisory perimeter shifting from purely national to hybrid EU-level oversight, but the exact sequencing and the specific cohort of Cyprus obliged entities that will fall under direct AMLA supervision, versus continued CySEC national supervision, is not yet settled in the evidence base.

For corporate-services providers, fund structures, and high-net-worth-linked corporate vehicles domiciled in Cyprus, the practical significance of this cycle's findings is anticipatory rather than immediate: no new beneficial-ownership disclosure obligation, register-access rule, or verification duty was identified as taking effect this cycle specifically for Cyprus. The signal is instead that the underlying EU-level architecture within which any future Cyprus-specific beneficial-ownership rule will sit is now firming up, with the AMLR's single rulebook and the AMLA Regulation both already adopted instruments moving toward application, rather than proposals still subject to negotiation.

Outlook

The immediate research priority for next cycle is resolving the 2027-versus-2028 date discrepancy for AMLA's direct-supervision onset, since this materially affects the compliance-planning timeline for Cyprus obliged entities that may fall within AMLA's initial cohort. A second priority is locating primary CySEC circular text for C748/C749 to establish precisely what data obliged entities were required to submit and to which authority, since the current finding rests on vendor commentary rather than the regulator's own published text. Watch also for AMLA's first published work programme and supervisory methodology, expected around the fourth quarter of 2026, which should begin to clarify both the direct-supervision cohort and the practical shape of the hybrid EU-national supervisory model described above. Firms that anticipate falling within AMLA's initial direct-supervision cohort should treat the 2027/2028 date uncertainty as a planning risk rather than a settled compliance deadline, and should not assume the later date without independent confirmation. Taken as a whole, this cycle's Cyprus-specific AMLA-adjacent signal is thin in primary-source terms but directionally consistent with the durable EU-level architecture described above, and it should be tracked rather than treated as concluded.

D3 Enabler Jurisdictions

Cyprus assessed as an enabler jurisdiction combining capacity deficit (partial FATF-compliance ratings, delayed NSIU) and professional-body-driven political constraint (Bar Association resistance); PwC Cyprus/CSP network remains the documented asset-shielding architecture.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto / Digital Assets / Financial Innovation

Crypto / Digital Assets / Financial Innovation

Continue reading

The defining Cyprus finding this cycle is the formal close, on 1 July 2026, of the Markets in Crypto-Assets Regulation's national grandfathering window for crypto-asset service providers, following a 27 February 2026 application deadline. This is a High-confidence finding, anchored by a Tier 1 CySEC press release and corroborated across three independent secondary sources on both the application-deadline and expiry dates, making it the best-sourced single finding for Cyprus this cycle across any domain. Framed through a digital-asset-architecture lens rather than an incident lens, the significance of this finding is structural: it retires Cyprus's prior AML-only national crypto-registration regime entirely, closing what had functioned as a lighter-touch national pathway into crypto-asset activity, and replaces it with full MiCA authorisation as the only route to lawful operation. Providers that did not secure authorisation by the relevant deadline are required to wind down their Cyprus operations rather than continue under any residual national registration.

This is best understood as a jurisdiction-wide regime transition rather than a single enforcement event, and it should be weighted accordingly against episodic findings elsewhere in this cycle's Cyprus coverage. Where a single enforcement action against a named crypto firm would be an incident, a formal close of an entire national registration category, applicable uniformly across the whole population of Cyprus-domiciled crypto-asset service providers, is architecture: it changes the rules that determine market access for an entire category of financial-innovation firm, not the compliance posture of one firm within an unchanged rule set. The compliance-cost implications flow directly from this architectural framing: firms previously operating under the lighter AML-only national registration must now satisfy the full MiCA authorisation bar, a materially higher compliance threshold spanning governance, prudential, custody, and market-conduct requirements that the prior national regime did not impose in the same form.

The obligation itself traces to Regulation (EU) 2023/1114, Article 143(3), the MiCA provision establishing the national transitional-period mechanism that member states could apply to crypto-asset service providers already operating under national law before MiCA's own authorisation regime took full effect. Cyprus's use of the full transitional window, running through the 27 February 2026 application deadline to the 1 July 2026 hard expiry, places it within the standard MiCA transition timeline rather than an accelerated or Cyprus-specific variant; the significance lies not in Cyprus doing anything unusual, but in the transition milestone itself now being crossed for a jurisdiction with an economically meaningful crypto-services sector.

The transition also has second-order relevance for how Cyprus's crypto sector is perceived from a financial-integrity standpoint specifically: a jurisdiction that has fully retired its national AML-only crypto pathway in favour of the harmonised EU MiCA standard removes one channel that a jurisdiction shopping for lighter-touch crypto registration might previously have used Cyprus for. Firms with a customer-typology profile linked to virtual-asset-service-provider counterparties should treat the transition as closing a specific Cyprus-based regulatory-arbitrage channel, rather than as a routine licensing update. For firms weighing Cyprus as a crypto-asset-service-provider base going forward, the practical entry calculus has now fully converged with the MiCA-wide standard: there is no longer a Cyprus-specific lighter registration tier to weigh against full MiCA authorisation, since that tier has been formally retired.

Outlook

The practical question for next cycle is how many previously AML-registered Cyprus crypto-asset firms have successfully converted to full MiCA authorisation versus wound down their Cyprus operations; this cycle's research established the regulatory deadline and its legal basis but could not yet establish the population-level compliance outcome. Watch also for any enforcement action against providers that continued operating in Cyprus without securing MiCA authorisation past the 1 July 2026 deadline, which would be the first test of how the new architecture is actually enforced in practice, as distinct from simply being formally in place. A further open question is whether any Cyprus-specific transitional guidance was issued by CySEC to firms mid-conversion, which this cycle's sourcing did not surface; locating any such guidance would help distinguish firms that wound down voluntarily from those still pursuing authorisation past the formal deadline. Both threads should be prioritised directly with CySEC primary-source material next cycle, given the current finding's strength rests substantially on the Tier 1 press release rather than granular population-level detail.

D6 Compliance Technology & Active Defence

Not covered

Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.

D7 AML/CTF Regime

Not covered

AML/CTF Regime is not yet covered for this jurisdiction in this report.

Regulatory horizon
In Force Pending2026-Q4 · ±half_year

AMLA Work Programme / build-out

AMLA stands up in Frankfurt and publishes its first work programme and supervisory methodology.
source not collected
Adopted2027 · ±year

AMLR / 6AMLD application date

The single AML rulebook (AMLR) becomes directly applicable and 6AMLD transposition deadlines bite across Member States.
Adopted2028 · ±multi_year

AMLA direct supervision of selected obliged entities

AMLA begins direct supervision of a first cohort of high-risk cross-border obliged entities, shifting supervisory perimeter from purely national authorities to a hybrid EU-level regime.
3 dated · 4 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROAssessed

CySEC's sanctions-enforcement build-out and the AMLA data-collection deadline both tighten the compliance-reporting baseline this cycle.

The National Sanctions Implementation Unit's operational status and the CySEC Circular C748/C749 AMLA data-collection deadline both raise the practical reporting and screening burden for obliged entities, even though neither finding is a specific enforcement action against a named institution this cycle.

2 evidence refs
ComplianceHigh

The EU AML Regulation's shift to direct applicability and the MiCA CASP grandfathering expiry both require Cyprus obliged entities to update control frameworks against new binding EU-level standards.

AMLR's direct applicability and 6AMLD transposition change Cyprus's compliance baseline from a purely national-manual approach toward a structured, EU-harmonised standard, while the MiCA transition removes the prior AML-only national crypto-registration option entirely, both requiring control-framework updates.

3 evidence refs
LegalAssessed

CySEC's new sanctions-breach criminalisation framework and Cyprus's role in softening EU maritime-sanctions restrictions both carry distinct legal-exposure implications.

The criminalisation framework in force since August 2025 raises the stakes of sanctions-breach exposure for Cyprus-linked entities, while the maritime-sanctions softening secured alongside Greece and Malta signals a negotiating posture that may affect enforcement intensity against Cyprus-flagged shipping-sector counterparties under the EU's twentieth sanctions package.

2 evidence refs
BoardHigh

The MiCA CASP grandfathering expiry is the most strategically significant Cyprus financial-integrity development this cycle, closing the last national crypto-registration pathway.

Boards overseeing Cyprus-domiciled crypto-asset exposure should note that the national AML-only registration option no longer exists; continued operation now requires full MiCA authorisation, a materially higher compliance bar with reputational and strategic implications for any Cyprus crypto-services relationship.

1 evidence refs
CTOHigh

The MiCA transition changes the technical-compliance architecture required of Cyprus crypto-asset service providers.

Systems supporting Cyprus crypto-asset operations must now meet full MiCA authorisation requirements rather than the retired AML-only national registration standard, which may require architecture-level changes to custody, governance, and market-conduct controls.

1 evidence refs
RiskAssessed

Cyprus's sanctions and crypto-regulatory architecture are both moving simultaneously, a dual-track exposure pattern risk functions should track together.

The sanctions-enforcement build-out, the maritime-sanctions softening, and the MiCA transition together represent three concurrent structural shifts in Cyprus's financial-integrity architecture this cycle, warranting escalation to cross-monitor risk-aggregation processes given the parallel timing.

3 evidence refs
OperationsAssessed

The AMLA data-collection deadline and the MiCA authorisation transition both carry operational workflow implications for Cyprus obliged-entity processes.

Operations teams supporting CySEC-regulated entities should confirm whether their firm was captured by the Circular C748/C749 data-collection exercise, and crypto-facing operations teams should confirm MiCA authorisation status given the national registration route is now closed.

2 evidence refs
AuditAssessed

Audit-trail scope should extend to the new sanctions-enforcement circular and the AMLA data-collection exercise, both of which currently rest on secondary-source rather than primary-regulator documentation.

Neither the sanctions-criminalisation circular nor the CySEC Circular C748/C749 text was independently located as a primary source this cycle; audit functions verifying control adequacy against these obligations should obtain the primary regulator text directly rather than relying on secondary summaries.

2 evidence refs
Decision lens
MLRO

CySEC's sanctions-enforcement build-out and the AMLA data-collection deadline both tighten the compliance-reporting baseline this cycle.

Compliance

The EU AML Regulation's shift to direct applicability and the MiCA CASP grandfathering expiry both require Cyprus obliged entities to update control frameworks against new binding EU-level standards.

Legal

CySEC's new sanctions-breach criminalisation framework and Cyprus's role in softening EU maritime-sanctions restrictions both carry distinct legal-exposure implications.

Board

The MiCA CASP grandfathering expiry is the most strategically significant Cyprus financial-integrity development this cycle, closing the last national crypto-registration pathway.

CTO

The MiCA transition changes the technical-compliance architecture required of Cyprus crypto-asset service providers.

Risk

Cyprus's sanctions and crypto-regulatory architecture are both moving simultaneously, a dual-track exposure pattern risk functions should track together.

Operations

The AMLA data-collection deadline and the MiCA authorisation transition both carry operational workflow implications for Cyprus obliged-entity processes.

Audit

Audit-trail scope should extend to the new sanctions-enforcement circular and the AMLA data-collection exercise, both of which currently rest on secondary-source rather than primary-regulator documentation.

Shared evidence: 4 refs
Scenario sketches

AMLA supervisory transition and cross-border obliged-entity evasion pressure

As AMLA moves from data-collection groundwork toward direct supervision of a first cohort of high-risk cross-border obliged entities, illustratively, entities anticipating inclusion in that cohort could face pressure to restructure ownership or reporting lines to fall outside the initial direct-supervision perimeter, shifting evasion-adjacent behaviour toward the boundary between direct AMLA supervision and continued national CySEC supervision rather than away from supervision altogether. This is an illustrative structural mechanism, not an observed development.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architecturemixed
T2 · EU AML Package / AMLAimproving
T3 · FATF Grey Listno_change
T4 · Beneficial-Ownership Register Statusno_change
T5 · Crypto & Digital-Asset Integritymaterial_change
T6 · Sanctions Regime Divergencemixed
Registers

Enforcement actions

  • OFAC designated Cypriot businessman Demetrios Serghides and Cyprus-registered Hightrail Ltd, alongside linked individuals (Attikouris, Giannakou/Yiannakou, Georgiou, Vakanas) and entities (Windfel Properties, Savoler Development, Miramonte Investments, Almenor Holdings), under Russia-related Executive Order 14024, citing links to sanctioned oligarch Alisher Usmanov. 24 Nov 2025
  • OFAC designated two Nicosia-registered companies, Veles International Limited and Hadlerco Limited, under Russia-related EO14024 for links to Dmitry Bugayenko, as part of a broader package including Iran-related shipping designations. 18 Dec 2025
  • MONEYVAL published a further follow-up report (3rd enhanced FUR successor) on Cyprus's progress addressing technical-compliance deficiencies since its 2020 mutual evaluation, continuing Cyprus's enhanced follow-up status. 23 Mar 2026
  • Criminal prosecution of two senior former politicians for alleged improper intervention in golden-passport citizenship applications, stemming from a 2020 Al Jazeera undercover investigation, concluded with acquittal after key prosecution witnesses failed to appear. 17 Feb 2026
  • Parliament passed a three-pronged legislative package establishing a National Sanctions Implementation Unit with fining powers, criminalising sanctions evasion, and replacing the 2016 sanctions law, after missing the EU's May 2024 transposition deadline amid Bar Association objections. 10 Jul 2025

Sanctions changes

  • The EU's 19th sanctions package added 117 further shadow-fleet vessel listings (total 557), imposed the first-ever EU sanctions on crypto-asset infrastructure supporting Russia, banned LNG imports from 2027, and eliminated remaining Rosneft/Gazprom Neft oil-import exemptions. 23 Oct 2025
  • Commission Delegated Regulation (EU) 2026/46 added Russia to the EU list of high-risk third countries with AML/CFT strategic deficiencies, amending Delegated Regulation (EU) 2016/1675. 3 Dec 2025
  • Commission Delegated Regulation (EU) 2026/83 added Bolivia and the British Virgin Islands to the EU high-risk third-country list while removing Burkina Faso, Mali, Mozambique, Nigeria, South Africa and Tanzania, reflecting FATF grey-list alignment. 4 Dec 2025
  • The EU Council designated nine shadow-fleet enablers (shipping companies based in the UAE, Vietnam and Russia) on 15 December 2025 and a further 41 shadow-fleet vessels on 18 December 2025, bringing total vessel designations to nearly 600. 18 Dec 2025

Regulatory horizon (register)

  • AML Regulation (AMLR) becomes directly applicable across the EU
  • AMLA selects ~40 directly-supervised high-risk cross-border entities
  • National Sanctions Implementation Unit reaches full operational capacity
  • Next MONEYVAL follow-up report on Cyprus AML/CFT progress

Active schemes

  • [CRITICAL] Cypriot professional-enabler network shielding Russian oligarch assets
  • [HIGH] Shadow-fleet oil tanker layering via Cyprus corporate structures
  • EEA VASP-passporting gap in Cyprus crypto supervision
  • [HIGH] Legacy golden-passport beneficial-ownership opacity
Sources
  1. FATF / MONEYVAL
  2. Cyprus Securities and Exchange Commission (CySEC)
  3. US Office of Foreign Assets Control (OFAC)
  4. European Commission (DG FISMA)
  5. International Consortium of Investigative Journalists (ICIJ)
  6. Organized Crime and Corruption Reporting Project (OCCRP)
  7. Council of the European Union
  8. HM Treasury (UK)
Coverage gaps
The seed-referenced authoritative national NRA document (Min…
The seed-referenced authoritative national NRA document (Ministry of Finance Cyprus Concise NRA, mof.gov.cy/assets/modules/wnp/articles/201811/448/docs/cy_concise_nra.pdf) returned a 404 error at execution and could not be directly read or cited verbatim as instructed.
The Cyprus Bar Association's objections (constitutional/lang…
The Cyprus Bar Association's objections (constitutional/language grounds, exclusion from the AML advisory role) delayed the National Sanctions Implementation Unit legislation past the EU's 20 May 2024 deadline, illustrating professional-body capture of reform timelines.
Criminal prosecutions arising from the golden-passport scand…
Criminal prosecutions arising from the golden-passport scandal have largely failed at first instance, with the February 2026 acquittal of two senior former politicians the latest of three first-instance cases to founder, in one instance due to witnesses simply not being summoned.
Cyprus's UBO registry (established 2021) and trust registers…
Cyprus's UBO registry (established 2021) and trust registers remain non-public, limiting third-party and journalistic verification of beneficial ownership; investigators have repeatedly had to rely on leaked corporate-registry data (Cyprus Confidential) rather than official transparency mechanisms.
Cyprus's virtual-asset supervisory framework remains rated p…
Cyprus's virtual-asset supervisory framework remains rated partially compliant on FATF Recommendation 15, with MONEYVAL noting the unresolved question of host-country obligations for foreign-registered VASPs operating remotely into Cyprus, and an initially absent national VASP risk-mitigation action plan.
Cyprus's government has historically linked support for stri…
Cyprus's government has historically linked support for stricter shadow-fleet and shipping-sector sanctions to compensation for lost shipping-industry revenue (a sector worth ~8% of GDP), and its law firms continued servicing dozens of sanctioned oligarchs more than a year after the 2022 sanctions wave.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.