Financial Integrity Monitor

Lithuania LT

Domains (D1–D6)
6
Sources
12
Role actions
8
Horizon <90d
5
Jurisdiction profile
Largely CompliantTier BRisk: StableMixed

Lithuania applies the EU AML/CFT acquis (AMLD transposition, forthcoming AMLR/6AMLD) via the Law on Prevention of Money Laundering and Terrorist Financing, supervised by the Financial Crime Investigation Service (FNTT/FCIS) and the Bank of Lithuania for financial/EMI/crypto obliged entities.

MoreA fast-growing EMI and VASP licensing hub has produced recurring supervisory failures alongside genuine enforcement escalation and EU-funded institutional reform.

Key deficiencies
  • Beneficial ownership register not publicly accessible (legitimate-interest access only, post-2022 CJEU ruling)
  • FATF Recommendations 6, 7 and 28 (targeted financial sanctions for TF/PF; DNFBP supervision) remain rated Partially Compliant
  • No registration framework for accountants and real estate agents as DNFBPs; low STR filing from notaries, CSPs, MVTS and real estate agents
  • Recurring AML/CFT control failures inside licensed EMI and crypto-asset firms despite a fast-expanding fintech sector
Recent developments (18m)
  • OLAF-supported Lithuanian Customs raid (April 2025) on a company rerouting sanctioned EU-origin goods to Russia/Belarus via Central Asia
  • Lithuanian customs disclosed refusal of 28,854 sanctioned-goods export requests exploiting a 'medical exemption' loophole (reported June 2025)
  • Bank of Lithuania fined Pervesk UAB (Bankera-linked) €130,000 for AML/CFT control failures, with heightened supervision imposed (2025)
  • EU broadened the Belarus sanctions regime (December 2025) explicitly citing meteorological-balloon airspace incursions into Lithuania
  • MONEYVAL enhanced follow-up report (December 2024) upgraded Recommendation 2 to Compliant; Recommendations 6, 7, 28 remained Partially Compliant
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Lithuania baseline assessment this cycle establishes the country as a frontline transit corridor for Russia and Belarus sanctions evasion, occupying a mixed enabler-enforcer position that resists a single clean label. The Lithuanian Customs Criminal Service, acting on OLAF intelligence, raided a Lithuania-based exporting company allegedly rerouting sanctioned EU-origin goods to Russia and Belarus via Central Asian transshipment, a scheme suspected to extend beyond a single exporter. In parallel, Lithuanian customs authorities disclosed that 28,854 export requests attempting to exploit a medical exemption classification to bypass EU restrictions on Russia- and Belarus-bound goods were rejected, evidencing a persistent and high-volume evasion tactic rather than an isolated incident. Set against the December 2024 MONEYVAL enhanced follow-up report on Lithuania, in which Recommendation 2 was upgraded to Compliant while Recommendations 6, 7 and 28, covering targeted financial sanctions and DNFBP supervision, remain Partially Compliant, the picture is one where enforcement volume is rising even as underlying architectural gaps persist unresolved. This is assessed at high confidence, characterising the role of Lithuania as a mixed enabler-enforcer position: genuine enforcement escalation running structurally parallel to persistent exposure as a frontline transit corridor.

That frontline exposure acquired an explicitly hybrid-threat dimension in December 2025, when the EU Council broadened the Belarus sanctions regime to cover disinformation and foreign information manipulation, critical-infrastructure disruption, migrant instrumentalisation and unauthorised entry, explicitly citing meteorological-balloon airspace incursions into Lithuania. This is assessed as a strategic shift toward treating hybrid destabilisation as sanctionable conduct in its own right rather than as an adjunct to the existing war-related regime, extending the sanctions-architecture perimeter beyond conventional financial and trade measures into the hybrid-warfare domain.

Other Developments

A widening EU sanctions perimeter reaches third-country financial infrastructure. The 19th EU sanctions package targeted Russian energy, third-country banks facilitating circumvention, and crypto-asset providers connected to the Russian financial messaging system, while the 18th package upgraded the SWIFT-only ban to a full transaction ban for listed Belarusian and Russian banks, and the 16th package mirrored Russia trade sanctions into the Belarus regime while prolonging that regime to 28 February 2026. Together these packages extend the sanctions perimeter of the EU further into third-country financial and crypto operators than equivalent measures elsewhere, a divergence tracked as a standing structural watch item.

A beneficial-ownership registry remains closed to general public access. The Lithuania registry exists but access is limited to those demonstrating a legitimate interest, a standard left undefined since the fourth AML Directive and reinforced by the 2022 CJEU Sovim and W.M. ruling striking down mandatory public access. This is assessed as a durable transparency gap that forthcoming EU harmonisation is likely to only partially resolve absent a revised EU-wide legitimate-interest standard.

A structural DNFBP registration and reporting gap persists alongside enforcement escalation. Lithuania has no registration framework for accountants or real estate agents as designated non-financial businesses and professions, and notaries, company-service providers, MVTS providers and real estate agents have historically filed few suspicious transaction reports despite material money-laundering and terrorist-financing risk exposure, a high-confidence finding carried through from the MONEYVAL follow-up assessment.

Recurring control failures mark the licensed EMI and crypto sector. The Bank of Lithuania fined Pervesk UAB, a Bankera-affiliated entity, EUR130,000 and imposed heightened supervision for failing to properly assess high-risk client and institutional risk, for not adapting monitoring scenarios, and for insufficient staff AML training. This sits alongside a pattern of gross, systematic compliance failures across Payeer, Transactive Systems and Payrnet, despite a 2022-2024 EU-funded supervisory-capacity project. Separately, Payeer, a Lithuania-licensed crypto firm, received a record fine for enabling transfers from EU-sanctioned Russian banks into ruble-denominated crypto-wallet transactions.

A forward-loaded regulatory architecture is scheduled through 2028. The EU AML Regulation becomes directly applicable EU-wide from 10 July 2027, replacing the transposed AMLD-based rulebook of Lithuania, while the sixth AML Directive transposition for Lithuania is estimated for a similar window with the transposition vehicle not yet specified. The EU Anti-Money Laundering Authority is planned to begin direct supervision of approximately 40 high-risk cross-border obliged entities from 2028, potentially including Lithuania-domiciled EMI and VASP firms, and the Financial Crime Investigation Service of Lithuania completed a 2022-2024 EU-funded project strengthening risk-based AML/CFT supervision, including a VASP sectoral risk methodology, ahead of that build-out.

Lithuania retains a clean FATF headline status. As of the June 2026 plenary cycle Lithuania is not listed on the FATF grey list or blacklist, even as it remains in MONEYVAL enhanced follow-up on the unresolved Recommendation 6, 7 and 28 deficiencies.

Legacy laundering exposure frames the current enforcement picture. Kaunas-based Ukio Bankas held at least 35 of approximately 75 BVI and Panama shell companies used in the multi-billion-dollar Troika Laundromat before its 2013 closure, and a Lithuania-registered financial institution set up by an Italy-linked organised-crime group allegedly laundered roughly EUR2 billion since 2017 via a global shell-company network before a 2024 Europol and Eurojust dismantling operation.

Cross-Monitor Connections

The sanctioned dual-use and petrochemical goods intercepted in transit through Lithuania toward Russia and Belarus are assessed as a potential conflict-finance channel sustaining inputs to the war economy of Russia, a connection flagged for SCEM commodity-flow data to corroborate volumes and routes. Separately, the broadening of the EU Belarus sanctions regime in response to hybrid destabilisation, the airspace balloon incursions against Lithuania, is flagged as relevant to WDM state-capture and hybrid-threat tracking, situating the exposure of Lithuania within a wider pattern of state-directed destabilisation activity against frontline EU and NATO states.

Outlook

The forward trajectory of Lithuania is dominated by the AMLR, 6AMLD and AMLA triad reaching successive milestones between 2026 and 2028: AMLA work programme and institutional build-out through 2026, the AMLR direct-applicability date of 10 July 2027, the still-unconfirmed 6AMLD transposition for Lithuania around the same window, and the first AMLA direct-supervision cohort from 2028, layered against a near-term MONEYVAL follow-up report expected within 2026 that will test whether the Recommendation 6, 7 and 28 deficiencies have been resolved. Both vectors point toward improving structural oversight, but on a multi-year horizon that leaves the current enforcement-versus-architecture gap in place for the interim. The fintech and VASP licensing growth of Lithuania is assessed as continuing to outpace supervisory capacity despite EU-funded reform, indicating a structural rather than purely episodic control gap in the EMI and crypto sector that the AMLA transition is designed to, but has not yet, resolve.

weekly_brief_draft · JID LT
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

The position of Lithuania in the Russia and Belarus sanctions-evasion architecture is best read through the lens of a frontline transit state whose enforcement capacity is escalating in direct proportion to the scale of the evasion attempts it faces. OLAF intelligence supported a raid by the Lithuanian Customs Criminal Service on a Lithuania-based exporting company allegedly rerouting EU-origin sanctioned goods to Russia and Belarus via Central Asian transshipment, with the firm suspected of facilitating similar schemes for other exporters, a structural finding rather than an isolated seizure, since it points to an organised rerouting capability rather than a single opportunistic actor. That structural reading is reinforced by the disclosure from Lithuanian customs that 28,854 export requests attempting to exploit a medical exemption classification to bypass EU sanctions on Russia- and Belarus-bound goods were rejected: a volume of that scale evidences a systemic evasion tactic operating at industrial scale against the export-control perimeter, not a marginal compliance failure. The active-scheme inventory records this trade-evasion architecture through two concrete red-flag indicators: the use of a medical exemption customs classification to bypass EU export restrictions on sanctioned goods, and the rerouting of EU-origin goods through Central Asian third countries before final delivery into Russia or Belarus. Both indicators are trade-document observable, meaning they fall within existing trade-finance and export-control compliance workflows rather than requiring novel detection capability; the gap is one of enforcement intensity and document-level scrutiny rather than a capability gap in what firms can observe.

This transit exposure was formally recognised at the EU architectural level in December 2025, when the Council broadened the Belarus sanctions regime to add hybrid-activity listing grounds, disinformation and foreign information manipulation, critical-infrastructure disruption, migrant instrumentalisation and unauthorised entry, explicitly citing meteorological-balloon airspace incursions into Lithuania. This is assessed as a strategic shift in EU sanctions design: hybrid destabilisation is now treated as sanctionable conduct in its own right, expanding the perimeter of the sanctions architecture beyond financial and trade measures into a hybrid-warfare register that directly concerns a frontline state such as Lithuania. The broadening sits within a wider sequence of EU escalation: the 16th package mirroring Russia trade sanctions into the Belarus regime and prolonging it to 28 February 2026, the 18th package upgrading the SWIFT-only ban to a full transaction ban for listed Belarusian and Russian banks, and the 19th package extending measures to Russian energy, third-country banks facilitating circumvention, and crypto-asset providers connected to the Russian financial messaging system. Each successive package widens the compliance perimeter that Lithuania-domiciled and Lithuania-transiting entities must navigate, and each also widens the divergence between the third-country reach of the EU and equivalent US and UK secondary-sanctions tools, a divergence itself tracked as a standing architectural watch item given the arbitrage surface it creates for evasion intermediaries.

The regulatory-compliance baseline of Lithuania complicates a simple frontline-enforcer reading. The December 2024 MONEYVAL enhanced follow-up report upgraded Recommendation 2 to Compliant but left Recommendations 6, 7 and 28, covering targeted financial sanctions implementation and DNFBP supervision, rated Partially Compliant. This is a high-confidence, primary-sourced finding that anchors the assessment that the sanctions-evasion posture of Lithuania is best characterised as mixed: genuine, escalating enforcement activity running structurally parallel to persistent implementation gaps in the targeted-financial-sanctions freezing mechanism itself. That said, Lithuania is not listed on the FATF grey list or blacklist as of the June 2026 plenary cycle, a clean headline status that coexists with the enhanced-follow-up findings rather than superseding them, a distinction the architecture-over-incident principle requires holding onto rather than collapsing into a single risk label.

Outlook

The next MONEYVAL enhanced follow-up report on Lithuania, expected within 2026, is the most immediate forward-watch item for the sanctions-architecture domain: it will assess whether the Recommendation 6, 7 and 28 deficiencies identified in December 2024 have been resolved, and the outcome will materially affect whether the mixed enabler-enforcer characterisation of Lithuania shifts toward the enforcement end of the spectrum. Layered against this is the multi-year AMLR, 6AMLD and AMLA transition, which is assessed as improving structural oversight in aggregate but does not itself target the targeted-financial-sanctions implementation gap directly, since that gap sits within Recommendation 6 and 7 territory rather than the CDD and beneficial-ownership perimeter the AML Package chiefly addresses. Absent confirmation that the freezing-mechanism deficiencies have been closed, the frontline transit exposure of Lithuania to Russia and Belarus sanctions evasion is likely to remain a persistent structural feature of the domain rather than a resolved one, even as enforcement volume against individual schemes continues to escalate.

Cumulative analysis

This is the first cumulative synthesis for the sanctions architecture and evasion domain in Lithuania, establishing a baseline state-of-the-domain reading for a reader encountering this tracker for the first time. Lithuania functions as a frontline transit state in the Russia and Belarus sanctions-evasion architecture, and its position is defined by two trends moving in parallel rather than trading off against each other: escalating enforcement and persistent structural exposure. OLAF intelligence supported a raid by the Lithuanian Customs Criminal Service on a Lithuania-based exporting company allegedly rerouting EU-origin sanctioned goods to Russia and Belarus via Central Asian transshipment, with the firm suspected of facilitating similar schemes for other exporters, a structural finding rather than an isolated seizure since it points to an organised rerouting capability. That reading is reinforced by the disclosure from Lithuanian customs that 28,854 export requests attempting to exploit a medical exemption classification to bypass EU sanctions on Russia- and Belarus-bound goods were rejected, a volume evidencing a systemic evasion tactic operating at industrial scale rather than a marginal compliance failure. The active-scheme inventory records this trade-evasion architecture through two concrete, document-observable red-flag indicators: the medical exemption customs classification and the rerouting of goods through Central Asian third countries, both of which fall within existing trade-finance and export-control compliance workflows rather than requiring novel detection capability, indicating the gap is one of enforcement intensity rather than observational capacity.

This transit exposure acquired formal recognition at the EU architectural level in December 2025, when the Council broadened the Belarus sanctions regime to add hybrid-activity listing grounds, disinformation and foreign information manipulation, critical-infrastructure disruption, migrant instrumentalisation and unauthorised entry, explicitly citing meteorological-balloon airspace incursions into Lithuania. This is assessed as a strategic shift in EU sanctions design, treating hybrid destabilisation as sanctionable conduct in its own right rather than an adjunct to the existing war-related regime. That broadening sits within a wider sequence of escalation across the 16th package, which mirrored Russia trade sanctions into the Belarus regime and prolonged it to 28 February 2026, the 18th package, which upgraded the SWIFT-only ban to a full transaction ban for listed Belarusian and Russian banks, and the 19th package, which extended measures to Russian energy, third-country banks facilitating circumvention, and crypto-asset providers connected to the Russian financial messaging system. Each package widens the compliance perimeter Lithuania-domiciled and Lithuania-transiting entities must navigate, and widens the divergence between EU third-country reach and equivalent US and UK secondary-sanctions tools, tracked as a standing architectural watch item given the arbitrage surface it creates.

The regulatory-compliance baseline complicates a simple frontline-enforcer reading of Lithuania. The December 2024 MONEYVAL enhanced follow-up report upgraded Recommendation 2 to Compliant but left Recommendations 6, 7 and 28, covering targeted financial sanctions implementation and DNFBP supervision, rated Partially Compliant, a high-confidence, primary-sourced finding anchoring the assessment that the sanctions-evasion posture of Lithuania is best characterised as mixed: genuine, escalating enforcement running structurally parallel to persistent implementation gaps in the targeted-financial-sanctions freezing mechanism. Lithuania nonetheless retains a clean FATF headline status, not listed on the grey list or blacklist as of the June 2026 plenary cycle, a status that coexists with the enhanced-follow-up findings rather than superseding them.

The hybrid-threat broadening of the Belarus regime also carries cross-monitor significance: the explicit citation of airspace balloon incursions against Lithuania situates this sanctions-architecture development within a wider pattern of state-directed destabilisation activity against frontline EU and NATO states, a connection relevant to WDM state-capture and hybrid-threat tracking. Similarly, the sanctioned dual-use and petrochemical goods transiting Lithuania toward Russia and Belarus are read as a potential conflict-finance channel sustaining inputs to the war economy of Russia, a connection flagged for SCEM commodity-flow corroboration of volumes and routes. These cross-references indicate that the sanctions-architecture posture of Lithuania cannot be fully assessed in isolation from adjacent state-capture and conflict-finance monitoring domains, reinforcing the baseline judgment that this is a structural, multi-domain exposure rather than a self-contained enforcement story.

Looking across the multi-year horizon, the AMLR, 6AMLD and AMLA transition running through 2027 and 2028 is assessed as improving structural oversight in aggregate but does not itself target the targeted-financial-sanctions implementation gap directly, since that gap sits within Recommendation 6 and 7 territory rather than the customer-due-diligence and beneficial-ownership perimeter the AML Package chiefly addresses. Absent confirmation that the freezing-mechanism deficiencies have been closed, the frontline transit exposure of Lithuania to Russia and Belarus sanctions evasion is assessed as likely to remain a persistent structural feature of this domain through the 2026 review cycle and beyond, even as enforcement volume against individual schemes continues to escalate. This baseline synthesis will be updated in subsequent cycles as the MONEYVAL follow-up outcome, further EU sanctions-package activity, and any additional enforcement actions against the transit-corridor architecture become available.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

The beneficial-ownership registry of Lithuania exists as a matter of law but functions, in practice, as a semi-closed system: access is restricted to parties demonstrating a legitimate interest, a standard that has remained undefined since the fourth EU AML Directive and was reinforced rather than clarified by the 2022 ruling of the Court of Justice of the European Union in the joined Sovim and W.M. cases, which struck down mandatory general public access to beneficial-ownership data across the bloc. Journalists and researchers report being able to obtain access by citing public interest, but the absence of a defined, enforceable legitimate-interest standard leaves the practical accessibility of ownership data dependent on administrative discretion rather than a codified right, a structural condition assessed at moderate-to-high confidence as a durable transparency gap rather than a transitional one.

That gap is not merely theoretical. Kaunas-based Ukio Bankas held at least 35 of approximately 75 BVI and Panama shell companies used in the multi-billion-dollar Troika Laundromat scheme before its 2013 closure by the Bank of Lithuania, a legacy episode that demonstrates how opaque corporate-ownership structures, once embedded in a licensed EU credit institution, can sustain laundering architecture at scale for years before detection. More recently, a Lithuania-registered financial institution established in 2016 by an Italy-linked organised-crime group allegedly laundered approximately EUR2 billion since 2017 through a global shell-company network, before a 2024 Europol and Eurojust joint operation dismantled it, though the precise date of that dismantling has not been independently confirmed this cycle. Read together, these two episodes, a decade apart, indicate that the corporate and beneficial-ownership transparency architecture of Lithuania has a recurring, rather than one-off, vulnerability to shell-company layering conducted through licensed domestic financial institutions.

The durable structural backdrop against which the beneficial-ownership signal of Lithuania should be read is the standing EU AML Package architecture, which comprises three legally distinct instruments rather than a single reform. The AML Regulation, Regulation (EU) 2024/1624, is directly applicable across the EU without national transposition and is confirmed to take effect from 10 July 2027, replacing the current AMLD-based transposed rulebook of Lithuania with a single harmonised customer-due-diligence, beneficial-ownership and crypto-asset-service-provider framework. The sixth AML Directive is a separate instrument requiring Member State transposition of national-level provisions, financial-intelligence-unit powers, national supervisory architecture, and register-coordination duties, on a broadly parallel timeline; the specific transposition vehicle and confirmed date for Lithuania have not yet been published, a gap honestly recorded rather than assumed away. The third instrument, the AMLA Regulation, Regulation (EU) 2024/1620, establishes the EU Anti-Money Laundering Authority, which is planned to begin direct supervision of approximately 40 high-risk cross-border obliged entities from 2028, potentially including Lithuania-domiciled EMI and VASP firms, shifting the supervisory perimeter for the largest cross-border groups from purely national oversight by the Bank of Lithuania and the Financial Crime Investigation Service toward a hybrid EU-level regime. This three-instrument architecture is the structural context, not a resolved outcome: it establishes a harmonisation trajectory rather than an immediate fix to the current legitimate-interest access standard of Lithuania, which the AMLR is expected to only partially address absent a revised EU-wide public-access standard responsive to the Sovim and W.M. ruling.

Outlook

The forward trajectory for the beneficial-ownership and corporate-transparency posture of Lithuania runs through the 10 July 2027 application date of the AMLR and the still-unconfirmed 6AMLD national transposition, both expected in the same window. Because the access-standard question turns on the balancing by the CJEU of privacy rights against transparency objectives rather than solely on the harmonised CDD baseline of the AMLR, resolution of the legitimate-interest ambiguity is not guaranteed by the entry into force of the AMLR alone, and this is assessed as the single most consequential open question for the D2 posture of Lithuania through the 2027-2028 window. The 2028 direct-supervision start of AMLA, while primarily a supervisory-perimeter change, will also determine whether the largest Lithuania-domiciled cross-border EMI and VASP groups face harmonised beneficial-ownership verification standards ahead of, or only upon, wider national implementation. This durable AMLA-era backdrop frames every subsequent read of the transparency posture of Lithuania across future cycles.

Cumulative analysis

This is the first cumulative synthesis for the beneficial ownership and corporate transparency domain in Lithuania, integrating the baseline evidence into a single state-of-the-domain reading. The beneficial-ownership registry of Lithuania exists as a matter of law but functions, in practice, as a semi-closed system: access is restricted to parties demonstrating a legitimate interest, a standard left undefined since the fourth EU AML Directive and reinforced rather than clarified by the 2022 ruling of the Court of Justice of the European Union in the joined Sovim and W.M. cases, which struck down mandatory general public access to beneficial-ownership data across the bloc. Journalists and researchers report being able to obtain access by citing public interest, but the absence of a defined, enforceable legitimate-interest standard leaves practical accessibility dependent on administrative discretion rather than a codified right, assessed at moderate-to-high confidence as a durable transparency gap rather than a transitional one.

This gap is illustrated by two historical episodes that together establish the pattern rather than the exception. Kaunas-based Ukio Bankas held at least 35 of approximately 75 BVI and Panama shell companies used in the multi-billion-dollar Troika Laundromat scheme before its 2013 closure by the Bank of Lithuania, demonstrating how opaque corporate-ownership structures embedded in a licensed EU credit institution sustained laundering architecture at scale for years before detection. More recently, a Lithuania-registered financial institution established in 2016 by an Italy-linked organised-crime group allegedly laundered approximately EUR2 billion since 2017 through a global shell-company network, before a 2024 Europol and Eurojust joint operation dismantled it, though the precise dismantling date has not been independently confirmed. Read together across a decade, these episodes indicate a recurring, rather than one-off, vulnerability to shell-company layering conducted through licensed domestic financial institutions in Lithuania, a pattern this baseline synthesis treats as structural rather than episodic.

The durable structural backdrop against which this domain must be read, in Lithuania and across the EU generally, is the standing AML Package architecture, comprising three legally distinct instruments. The AML Regulation, Regulation (EU) 2024/1624, is directly applicable across the EU without national transposition and takes effect from 10 July 2027, replacing the current AMLD-based transposed rulebook of Lithuania with a harmonised customer-due-diligence, beneficial-ownership and crypto-asset-service-provider framework. The sixth AML Directive is a separate instrument requiring Member State transposition of national-level provisions, financial-intelligence-unit powers, national supervisory architecture and register-coordination duties, on a broadly parallel timeline; the specific transposition vehicle and confirmed date for Lithuania have not yet been published, a gap this synthesis records honestly rather than assumes away. The third instrument, the AMLA Regulation, Regulation (EU) 2024/1620, establishes the EU Anti-Money Laundering Authority, planned to begin direct supervision of approximately 40 high-risk cross-border obliged entities from 2028, potentially including Lithuania-domiciled EMI and VASP firms, shifting the supervisory perimeter for the largest cross-border groups from purely national oversight by the Bank of Lithuania and the Financial Crime Investigation Service toward a hybrid EU-level regime. This three-instrument architecture is structural context rather than a resolved outcome for the current cycle: it establishes a harmonisation trajectory, not an immediate fix to the current legitimate-interest access standard, which the AMLR is expected only to partially address absent a revised EU-wide public-access standard responsive to the Sovim and W.M. ruling.

This beneficial-ownership opacity is not confined to the D2 domain in isolation: the same Ukio Bankas and EUR2 billion laundering episodes recur in the enabler-jurisdiction and professional-facilitator reading of Lithuania, since both cases involved a single licensed domestic institution functioning as critical facilitation infrastructure rather than an unregulated intermediary. This overlap is treated, across domains, as the same underlying structural fact viewed through different analytical lenses rather than as two separate risks, consistent with the same-facts-different-lens principle governing this synthesis. From an audit and evidentiary perspective, the absence of independent, non-OCCRP corroboration for elements of the historic enforcement record, and the absence of current data confirming the precise 2024 dismantling date, are recorded as open evidentiary gaps rather than resolved facts, a distinction that matters for any control-testing exercise relying on this baseline.

Taken as a whole, the baseline assessment of this domain is that Lithuania beneficial-ownership transparency sits on a known and durable gap, legally consistent with binding CJEU precedent but not thereby resolved, layered against a multi-year EU harmonisation process whose effect on the specific access-standard question remains uncertain. This is the single most consequential open question carried forward into future cycles of this synthesis: whether the AMLR, 6AMLD and AMLA transition through 2027 and 2028 produces a revised, EU-wide legitimate-interest standard, or whether the current administrative-discretion model persists in modified form. This cumulative synthesis will be revisited and integrated, rather than appended to, in each subsequent cycle as new beneficial-ownership and corporate-transparency evidence for Lithuania becomes available.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The enabler-jurisdiction profile of Lithuania centres on a specific and well-evidenced structural gap: the absence of a registration framework for accountants and real estate agents as designated non-financial businesses and professions, combined with historically low suspicious-transaction-report filing from notaries, company-service providers, MVTS providers and real estate agents. This is a high-confidence, MONEYVAL-sourced finding, and it is significant because it identifies a design gap in the legal framework itself rather than merely a supervisory-capacity or enforcement-intensity problem: professionals who structurally intermediate corporate formation, property transactions and cash-intensive value transfer are not brought within a registration perimeter that would allow supervisors to monitor their compliance in the first place. Under the four-dimension test of the enabler-jurisdiction filter, legal framework, enforcement, capacity versus choice, and systemic significance, this reads as a legal-framework-level gap that predates and is somewhat independent of the otherwise escalating enforcement activity of Lithuania against sanctions evasion and licensed-sector AML failures.

The professional-facilitator dimension of the enabler profile of Lithuania is also visible in its legacy banking history. Kaunas-based Ukio Bankas served as a structural node in the multi-billion-dollar Troika Laundromat, holding at least 35 of approximately 75 BVI and Panama shell companies used in the scheme before the Bank of Lithuania closed it in 2013, illustrating how a single licensed domestic institution, rather than an unregulated intermediary, can function as critical facilitation infrastructure for offshore layering at scale. The more recent case of a Lithuania-registered institution established in 2016 by an Italy-linked organised-crime group, which allegedly laundered approximately EUR2 billion since 2017 via a global shell-company network before a 2024 Europol and Eurojust dismantling operation, indicates this facilitation risk is not confined to a single historical episode but recurs across licensed Lithuanian financial infrastructure over more than a decade. The active-scheme inventory frames this facilitation risk in observable terms: the red-flag indicator of layering offshore proceeds through a large network of BVI and Panama shell companies domiciled via a single licensed EU bank is captured as an onboarding-stage observable, meaning the vulnerability is, in principle, detectable through enhanced corporate-structure due diligence at the point of client onboarding rather than only through ex-post investigation of already-established shell networks.

Set against this, the enforcement trajectory of Lithuania shows genuine escalation: the OLAF-backed customs raid on a sanctions-evasion export scheme and the disclosure of 28,854 rejected medical exemption export requests demonstrate active, resourced enforcement against trade-based facilitation of Russia and Belarus sanctions evasion, and the EU-funded 2022-2024 Financial Crime Investigation Service supervisory-capacity project specifically targeted risk-based AML/CFT supervision, including a VASP sectoral risk methodology. The enabler-jurisdiction assessment is therefore one of genuine capacity investment coexisting with an unaddressed legal-framework gap in the DNFBP perimeter, a pattern the architecture-over-incident principle treats as more analytically significant than either fact read in isolation, because it indicates the professional-facilitator vulnerability is a matter of unclosed legal design rather than mere resource constraint.

Outlook

Resolution of the DNFBP registration and STR-filing gap is not currently scheduled to a specific date in the available regulatory horizon; the next MONEYVAL enhanced follow-up report, expected within 2026, is the nearest forward-watch item likely to record whether Recommendation 28, which covers DNFBP supervision, has moved from its December 2024 Partially Compliant rating. The 2027 transposition window of the AMLR and 6AMLD is also relevant, since 6AMLD national-level provisions extend to supervisory architecture and could, depending on the as-yet-unspecified transposition vehicle for Lithuania, address the DNFBP registration gap as part of broader national implementation, though this is not yet confirmed and should not be assumed. Absent that confirmation, the professional-facilitator gap identified in the DNFBP perimeter is assessed as likely to persist as a structural vulnerability through at least the 2026 MONEYVAL review cycle.

Cumulative analysis

This is the first cumulative synthesis for the enabler jurisdictions and professional facilitators domain in Lithuania, integrating the baseline evidence into a single state-of-the-domain reading. The enabler-jurisdiction profile of Lithuania centres on a specific and well-evidenced structural gap: the absence of a registration framework for accountants and real estate agents as designated non-financial businesses and professions, combined with historically low suspicious-transaction-report filing from notaries, company-service providers, MVTS providers and real estate agents. This is a high-confidence, MONEYVAL-sourced finding, significant because it identifies a design gap in the legal framework itself rather than merely a supervisory-capacity or enforcement-intensity problem: professionals who structurally intermediate corporate formation, property transactions and cash-intensive value transfer are not brought within a registration perimeter that would allow supervisors to monitor compliance in the first place. Applied against the four-dimension enabler-jurisdiction test, legal framework, enforcement, capacity versus choice, and systemic significance, this reads as a legal-framework-level gap that predates and is somewhat independent of the otherwise escalating enforcement activity of Lithuania against sanctions evasion and licensed-sector AML failures.

The professional-facilitator dimension is also visible in the legacy banking history of Lithuania. Kaunas-based Ukio Bankas served as a structural node in the multi-billion-dollar Troika Laundromat, holding at least 35 of approximately 75 BVI and Panama shell companies used in the scheme before the Bank of Lithuania closed it in 2013, illustrating how a single licensed domestic institution, rather than an unregulated intermediary, functioned as critical facilitation infrastructure for offshore layering at scale. The more recent case of a Lithuania-registered institution established in 2016 by an Italy-linked organised-crime group, which allegedly laundered approximately EUR2 billion since 2017 via a global shell-company network before a 2024 Europol and Eurojust dismantling operation, indicates this facilitation risk recurs across licensed Lithuanian financial infrastructure over more than a decade rather than being confined to a single historical episode. The active-scheme inventory frames this facilitation risk in observable terms: the red-flag indicator of layering offshore proceeds through a large network of BVI and Panama shell companies domiciled via a single licensed EU bank is captured as an onboarding-stage observable, meaning the vulnerability is, in principle, detectable through enhanced corporate-structure due diligence at the point of client onboarding rather than only through ex-post investigation of already-established shell networks.

Set against this structural gap, the enforcement trajectory of Lithuania shows genuine escalation: the OLAF-backed customs raid on a sanctions-evasion export scheme and the disclosure of 28,854 rejected medical exemption export requests demonstrate active, resourced enforcement against trade-based facilitation of Russia and Belarus sanctions evasion, and the EU-funded 2022-2024 Financial Crime Investigation Service supervisory-capacity project specifically targeted risk-based AML/CFT supervision, including a VASP sectoral risk methodology. This baseline synthesis treats the coexistence of genuine capacity investment with an unaddressed legal-framework gap in the DNFBP perimeter as more analytically significant, under the architecture-over-incident principle, than either fact read in isolation, since it indicates the professional-facilitator vulnerability is a matter of unclosed legal design rather than mere resource constraint.

A capacity-versus-choice reading of this gap favours a capacity interpretation over a deliberate-permissiveness one: the EU-funded FCIS project and the customs enforcement escalation both indicate genuine investment in supervisory and enforcement capability, suggesting the unresolved DNFBP registration gap is better read as an unclosed legislative task than as a policy choice to leave professional-services intermediaries unsupervised. This distinction matters for the systemic-significance dimension of the enabler-jurisdiction test, since it implies the gap is addressable through the pending 6AMLD transposition rather than requiring a change in political will.

Looking forward, resolution of the DNFBP registration and STR-filing gap is not currently scheduled to a specific date in the available regulatory horizon; the next MONEYVAL enhanced follow-up report, expected within 2026, is the nearest forward-watch item likely to record whether Recommendation 28, covering DNFBP supervision, has moved from its December 2024 Partially Compliant rating. The 2027 transposition window of the AMLR and 6AMLD is also relevant, since 6AMLD national-level provisions extend to supervisory architecture and could, depending on the as-yet-unspecified transposition vehicle for Lithuania, address the DNFBP registration gap as part of broader national implementation, though this is not yet confirmed and should not be assumed. This baseline synthesis carries forward the professional-facilitator gap identified in the DNFBP perimeter as a structural vulnerability likely to persist through at least the 2026 MONEYVAL review cycle, and future cycles of this synthesis will track whether the 6AMLD transposition vehicle for Lithuania, once identified, incorporates DNFBP registration reform directly.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance and Extractive-Industry Integrity

Conflict Finance and Extractive-Industry Integrity

Continue reading

The conflict-finance exposure of Lithuania this cycle is indirect and watch-level rather than direct: no Lithuania-domiciled war-financing flow or extractive-industry corruption channel was identified in the evidence gathered. The relevant signal is the sanctioned dual-use and petrochemical goods, fertilizers, petrochemicals and dual-use items, intercepted in transit through Lithuania toward Russia and Belarus as part of the broader sanctioned-goods evasion scheme uncovered by the OLAF-backed customs raid and the disclosure of 28,854 rejected medical exemption export requests. Under the architecture-over-incident principle, this transit exposure is treated as a potential conflict-finance channel because it concerns inputs that materially sustain the war economy of Russia, even though the flow is one of goods rather than direct financial transfers, and even though no Lithuania-based entity has been identified as a direct financier of conflict activity. This connection has been flagged for SCEM, whose commodity-flow data could corroborate the volumes and routes involved and thereby convert this currently assessed, indirect signal into a more precisely quantified one.

Outlook

Because the D4 signal for Lithuania this cycle is limited to an indirect transit-goods channel rather than a direct financing flow, the forward-watch item is less a specific regulatory horizon date than the outcome of the SCEM cross-referral: confirmation of volumes and routing patterns would materially strengthen or narrow the conflict-finance characterisation. No dedicated conflict-finance regulatory instrument specific to Lithuania was identified in the horizon scan for this cycle, and this domain is assessed as remaining at watch status pending either further trade-flow corroboration or a direct Lithuania-domiciled financing nexus emerging in a future cycle.

Cumulative analysis

This is the first cumulative synthesis for the conflict finance and extractive-industry integrity domain in Lithuania. The baseline signal is indirect and watch-level: no Lithuania-domiciled war-financing flow or extractive-industry corruption channel has been identified. The relevant evidence is the sanctioned dual-use and petrochemical goods, fertilizers, petrochemicals and dual-use items, intercepted in transit through Lithuania toward Russia and Belarus as part of the broader sanctioned-goods evasion scheme uncovered by the OLAF-backed customs raid and the disclosure of 28,854 rejected medical exemption export requests. Under the architecture-over-incident principle, this transit exposure is treated as a potential conflict-finance channel because it concerns inputs that materially sustain the war economy of Russia, even though the flow is one of goods rather than direct financial transfers, and even though no Lithuania-based entity has been identified as a direct financier of conflict activity. This connection has been flagged for SCEM, whose commodity-flow data could corroborate the volumes and routes involved and thereby convert this currently assessed, indirect signal into a more precisely quantified one in a future cycle.

Because this is a baseline, watch-level assessment rather than an established direct-financing finding, this synthesis records the domain honestly as thin rather than inflating it with inference beyond the evidence available. No dedicated conflict-finance regulatory instrument specific to Lithuania was identified in the regulatory horizon scan this cycle. The forward-watch item for this domain is the outcome of the SCEM cross-referral rather than a specific regulatory date: confirmation of volumes and routing patterns for the sanctioned-goods transit would materially strengthen, or alternatively narrow, the conflict-finance characterisation carried forward into subsequent cycles of this synthesis. Absent that corroboration, or a direct Lithuania-domiciled financing nexus emerging in future research, this domain will remain assessed at watch status. This baseline also notes that the frontline transit exposure of Lithuania situates it within a broader pattern of EU sanctioned-goods interdiction relevant to Russia war-economy financing generally, a pattern this synthesis will continue to track for any escalation from indirect goods transit toward direct financial-flow evidence.

domain_sub_briefs · D4 · Cumulative analysis

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

The licensed electronic-money-institution and crypto-asset sector of Lithuania is the locus of this cycle clearest financial-innovation signal, and it is a mixed one: recurring supervisory enforcement against genuine control failures, running alongside a structural pattern of repeated failure across multiple licensed firms. The Bank of Lithuania fined Pervesk UAB, a Bankera-affiliated entity, EUR130,000 and imposed heightened supervision after finding the firm had failed to properly assess high-risk client and institutional risk, had not adapted its transaction-monitoring scenarios to its actual risk profile, and had provided insufficient AML training to staff. This sits within a wider pattern described as gross, systematic compliance failures recurring across Payeer, Transactive Systems and Payrnet, a pattern that persisted despite a 2022-2024 EU-funded Technical Support Instrument project specifically intended to strengthen the risk-based AML/CFT supervisory capacity of Lithuania, including development of a VASP sectoral risk methodology. This is assessed at moderate confidence as evidence that the fintech and VASP licensing growth of Lithuania continues to outpace supervisory capacity despite genuine reform investment, a structural rather than merely episodic control gap.

The sanctions-evasion dimension of this sector is separately significant. Payeer, a Lithuania-licensed crypto firm, received a record fine in 2024 for enabling transfers from EU-sanctioned Russian banks to be converted into ruble-denominated crypto-wallet transactions, a scheme the active-scheme inventory captures through an on-chain-observable red-flag indicator: transfers from EU-sanctioned Russian banks converted into ruble-denominated crypto-wallet transactions. This finding sits at the intersection of the licensed-sector supervisory strain of Lithuania and the broader EU sanctions-architecture perimeter, since the 19th EU sanctions package specifically extended measures to crypto-asset providers connected to the Russian financial messaging system, meaning Lithuania-licensed VASPs sit squarely within an expanding compliance perimeter that both EU sanctions design and domestic AML supervision are converging on simultaneously.

Structural mitigants are in motion but not yet realised. The EU Anti-Money Laundering Authority is planned to begin direct supervision of approximately 40 high-risk cross-border obliged entities from 2028, a cohort assessed as potentially including Lithuania-domiciled EMI and VASP firms given their cross-border footprint, which would shift the supervisory perimeter for the largest firms from purely national Bank of Lithuania oversight toward a hybrid EU-level regime. Ahead of that transition, the Financial Crime Investigation Service of Lithuania has already completed its own EU-funded capacity-building project, indicating domestic supervisory investment is running in parallel with, rather than waiting for, the EU-level build-out. This period also brackets the point at which the EU Markets in Crypto-Assets Regulation reached full application from January 2025, reshaping licensing expectations for crypto-asset service providers ahead of the crypto-priority supervisory plans of AMLA; for Lithuania-domiciled CASPs, the MiCA licensing baseline and the forthcoming direct-supervision perimeter of AMLA are converging obligations rather than sequential ones, meaning firms already navigating MiCA authorisation should not treat the 2028 horizon of AMLA as a separate, later compliance event.

An open evidentiary question remains: independent corroboration, beyond the single OCCRP source, of the Pervesk and Bankera enforcement narrative and its current remediation status has not been obtained this cycle, and this gap is recorded rather than resolved by assumption, a caveat that matters because it determines whether the heightened-supervision order of the Bank of Lithuania should be read as an ongoing containment measure or a closed matter. The recurrence of enforcement action across four separate licensed entities, Pervesk and Bankera, Payeer, Transactive Systems, and Payrnet, over a period spanning the very years the EU-funded supervisory-capacity project was active, is itself a data point about the pace at which reform can outstrip a rapidly growing licensing population, rather than a simple indictment of the reform effort.

Outlook

The near-term forward-watch items for the digital-asset sector of Lithuania are the continued institutional build-out of AMLA, including a July 2026 public hearing on ongoing-monitoring guidelines directly relevant to VASP and EMI supervisory expectations, and the 2028 direct-supervision start date, whose entity-selection methodology has not yet been published. Until that methodology clarifies which Lithuania-domiciled firms fall within the initial cohort of approximately forty entities, the domestic enforcement pattern of repeated fines against individual licensed firms is assessed as likely to continue as the primary visible signal of control weakness in this sector, even as the structural AMLA transition proceeds in parallel.

Cumulative analysis

This is the first cumulative synthesis for the crypto, digital assets and financial innovation domain in Lithuania, integrating the baseline evidence into a single state-of-the-domain reading. The licensed electronic-money-institution and crypto-asset sector of Lithuania is the clearest financial-innovation signal in this baseline, and it is a mixed one: recurring supervisory enforcement against genuine control failures, running alongside a structural pattern of repeated failure across multiple licensed firms. The Bank of Lithuania fined Pervesk UAB, a Bankera-affiliated entity, EUR130,000 and imposed heightened supervision after finding the firm had failed to properly assess high-risk client and institutional risk, had not adapted its transaction-monitoring scenarios to its actual risk profile, and had provided insufficient AML training to staff. This sits within a wider pattern described as gross, systematic compliance failures recurring across Payeer, Transactive Systems and Payrnet, a pattern that persisted despite a 2022-2024 EU-funded Technical Support Instrument project specifically intended to strengthen the risk-based AML/CFT supervisory capacity of Lithuania, including development of a VASP sectoral risk methodology. This baseline synthesis assesses, at moderate confidence, that the fintech and VASP licensing growth of Lithuania continues to outpace supervisory capacity despite genuine reform investment, treating this as a structural rather than merely episodic control gap.

The sanctions-evasion dimension of this sector is separately significant and carried forward as a distinct thread of this synthesis. Payeer, a Lithuania-licensed crypto firm, received a record fine in 2024 for enabling transfers from EU-sanctioned Russian banks to be converted into ruble-denominated crypto-wallet transactions, a scheme the active-scheme inventory captures through an on-chain-observable red-flag indicator. This finding sits at the intersection of the licensed-sector supervisory strain of Lithuania and the broader EU sanctions-architecture perimeter, since the 19th EU sanctions package specifically extended measures to crypto-asset providers connected to the Russian financial messaging system, meaning Lithuania-licensed VASPs sit within an expanding compliance perimeter that both EU sanctions design and domestic AML supervision are converging on simultaneously.

Structural mitigants are in motion but not yet realised, and this baseline records both sides honestly. The EU Anti-Money Laundering Authority is planned to begin direct supervision of approximately 40 high-risk cross-border obliged entities from 2028, a cohort assessed as potentially including Lithuania-domiciled EMI and VASP firms given their cross-border footprint, which would shift the supervisory perimeter for the largest firms from purely national Bank of Lithuania oversight toward a hybrid EU-level regime. Ahead of that transition, the Financial Crime Investigation Service of Lithuania has already completed its own EU-funded capacity-building project, indicating domestic supervisory investment running in parallel with, rather than waiting for, the EU-level build-out. This period also brackets the point at which the EU Markets in Crypto-Assets Regulation reached full application from January 2025, reshaping licensing expectations for crypto-asset service providers ahead of the crypto-priority supervisory plans of AMLA, meaning firms already navigating MiCA authorisation face converging rather than sequential obligations as the AMLA horizon approaches.

An open evidentiary question is carried forward in this synthesis: independent corroboration, beyond the single OCCRP source, of the Pervesk and Bankera enforcement narrative and its current remediation status has not been obtained this cycle, a caveat that matters because it determines whether the heightened-supervision order of the Bank of Lithuania should be read as an ongoing containment measure or a closed matter. The recurrence of enforcement action across four separate licensed entities, Pervesk and Bankera, Payeer, Transactive Systems, and Payrnet, over a period spanning the very years the EU-funded supervisory-capacity project was active, is itself a data point about the pace at which reform can outstrip a rapidly growing licensing population, rather than a simple indictment of the reform effort.

Looking forward, the near-term watch items for this domain are the continued institutional build-out of AMLA, including a July 2026 public hearing on ongoing-monitoring guidelines directly relevant to VASP and EMI supervisory expectations, and the 2028 direct-supervision start date, whose entity-selection methodology has not yet been published. Until that methodology clarifies which Lithuania-domiciled firms fall within the initial cohort of approximately forty entities, the domestic enforcement pattern of repeated fines against individual licensed firms is assessed as likely to remain the primary visible signal of control weakness in this sector, even as the structural AMLA transition proceeds in parallel. This synthesis will integrate, rather than append, any further enforcement actions, remediation confirmations, or AMLA selection-methodology developments in subsequent cycles.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

The compliance-technology and active-defence posture of Lithuania this cycle is the most structurally clear of the six domains: a completed domestic capacity-building project sits directly ahead of an EU-level supervisory build-out that will eventually reach the same firms. The Financial Crime Investigation Service completed a 2022-2024 EU-funded Technical Support Instrument project that strengthened risk-based AML/CFT supervision domestically, including the development of a VASP sectoral risk methodology, a concrete deliverable directly relevant to the recurring EMI and crypto control failures identified elsewhere in the evidence for this cycle, since a sectoral risk methodology is precisely the kind of supervisory tool that could, if applied consistently, have identified the risk-assessment and monitoring-scenario deficiencies later found at Pervesk UAB.

At the EU level, the Anti-Money Laundering Authority continues its institutional build-out, including a scheduled July 2026 public hearing on ongoing-monitoring guidelines, a near-term signal on supervisory expectations that will directly affect Lithuania-domiciled obliged entities once finalised. This sits ahead of the planned 2028 direct-supervision start of AMLA for approximately 40 high-risk cross-border obliged entities, a cohort assessed as potentially including Lithuania-domiciled EMI and VASP firms given their cross-border footprint. The structural significance here is that the domestic supervisory-capacity investment of Lithuania, the completed FCIS project, and the EU-level build-out of AMLA are proceeding as parallel, complementary tracks rather than a single national reform sequence, meaning the compliance-technology posture of Lithuania is currently strengthening on two fronts simultaneously, national and supranational, even though neither track has yet fully closed the control gaps visible in the enforcement record.

This dual-track build-out should be read against the backdrop of the three-instrument EU AML Package: the directly applicable AML Regulation, Regulation (EU) 2024/1624, effective 10 July 2027, the sixth AML Directive requiring national transposition, with the transposition vehicle and date for Lithuania not yet specified, and the AMLA Regulation, Regulation (EU) 2024/1620, establishing the Authority itself. The supervisory perimeter of AMLA is a hybrid one by design: it will not replace national supervision by the Bank of Lithuania and the Financial Crime Investigation Service wholesale, but will instead directly supervise a defined high-risk cross-border cohort while national authorities retain supervision of the remainder, a structural bifurcation that active-defence and compliance-technology functions at Lithuania-domiciled firms will need to navigate as a dual-reporting-line reality rather than a simple handover.

Whether this domestic and supranational investment translates into resolved MONEYVAL ratings will become visible at the next enhanced follow-up report, expected within 2026, which will test whether the Recommendation 6, 7 and 28 deficiencies, covering targeted financial sanctions and DNFBP supervision, have been addressed by the supervisory tools the FCIS has developed. A sectoral risk methodology built for VASPs does not, on its own, extend to the DNFBP registration gap for accountants and real estate agents identified elsewhere in the evidence for this cycle; closing that separate gap would require either an extension of the FCIS methodology to a currently unregistered population of obliged entities, or a distinct legislative fix delivered through the still-unspecified 6AMLD transposition vehicle. This combination of national technical capacity-building and supranational institutional design is, at this stage, better characterised as promising infrastructure than as a resolved control environment: the enforcement record from the EMI and crypto sector this cycle demonstrates that risk-based supervisory tools existed in principle before the most recent failures were identified, indicating implementation and enforcement follow-through remain the binding constraint rather than tool availability alone.

Outlook

The nearest forward-watch item is the July 2026 public hearing of AMLA on ongoing-monitoring guidelines, which will provide the first concrete signal of how AMLA supervisory expectations will interact with the already-completed sectoral risk methodology of the FCIS. The more consequential horizon item is the entity-selection methodology for the initial cohort of approximately forty entities under AMLA direct supervision, not yet published but expected ahead of the 2028 start date; until it is published, Lithuania-domiciled EMI and VASP firms cannot determine with confidence whether they will fall within the direct-supervision perimeter of AMLA or remain under purely national oversight, a genuine planning uncertainty for compliance-technology investment decisions at the firm level.

Cumulative analysis

This is the first cumulative synthesis for the compliance technology and active defence domain in Lithuania, integrating the baseline evidence into a single state-of-the-domain reading. The compliance-technology and active-defence posture of Lithuania is, at this baseline, the most structurally clear of the six domains: a completed domestic capacity-building project sits directly ahead of an EU-level supervisory build-out that will eventually reach the same firms. The Financial Crime Investigation Service completed a 2022-2024 EU-funded Technical Support Instrument project that strengthened risk-based AML/CFT supervision domestically, including the development of a VASP sectoral risk methodology, a concrete deliverable directly relevant to the recurring EMI and crypto control failures identified elsewhere in this baseline evidence, since a sectoral risk methodology is precisely the kind of supervisory tool that could, if applied consistently, have identified the risk-assessment and monitoring-scenario deficiencies later found at Pervesk UAB.

At the EU level, the Anti-Money Laundering Authority continues its institutional build-out, including a scheduled July 2026 public hearing on ongoing-monitoring guidelines, a near-term signal on supervisory expectations that will directly affect Lithuania-domiciled obliged entities once finalised. This sits ahead of the planned 2028 direct-supervision start of AMLA for approximately 40 high-risk cross-border obliged entities, a cohort assessed as potentially including Lithuania-domiciled EMI and VASP firms given their cross-border footprint. This baseline synthesis treats the domestic supervisory-capacity investment of Lithuania and the EU-level build-out of AMLA as parallel, complementary tracks rather than a single national reform sequence, meaning the compliance-technology posture of Lithuania is currently strengthening on two fronts simultaneously, national and supranational, even though neither track has yet fully closed the control gaps visible in the enforcement record.

This dual-track build-out must be read against the standing backdrop of the three-instrument EU AML Package, a durable structural fact rather than a single-cycle development: the directly applicable AML Regulation, Regulation (EU) 2024/1624, effective 10 July 2027, the sixth AML Directive requiring national transposition, with the transposition vehicle and date for Lithuania not yet specified, and the AMLA Regulation, Regulation (EU) 2024/1620, establishing the Authority itself. The supervisory perimeter of AMLA is a hybrid one by design: it will not replace national supervision by the Bank of Lithuania and the Financial Crime Investigation Service wholesale, but will instead directly supervise a defined high-risk cross-border cohort while national authorities retain supervision of the remainder, a structural bifurcation this synthesis will continue to track as it affects Lithuania-domiciled firms directly.

Whether this domestic and supranational investment translates into resolved MONEYVAL ratings will become visible at the next enhanced follow-up report, expected within 2026, which will test whether the Recommendation 6, 7 and 28 deficiencies, covering targeted financial sanctions and DNFBP supervision, have been addressed by the supervisory tools the FCIS has developed. This baseline notes explicitly that a sectoral risk methodology built for VASPs does not, on its own, extend to the DNFBP registration gap for accountants and real estate agents identified in the enabler-jurisdiction domain; closing that separate gap would require either an extension of the FCIS methodology to a currently unregistered population of obliged entities, or a distinct legislative fix delivered through the still-unspecified 6AMLD transposition vehicle. This combination of national technical capacity-building and supranational institutional design is, at this baseline stage, better characterised as promising infrastructure than as a resolved control environment: the enforcement record from the EMI and crypto sector this cycle demonstrates that risk-based supervisory tools existed in principle before the most recent failures were identified, indicating implementation and enforcement follow-through remain the binding constraint rather than tool availability alone.

Looking forward, the nearest forward-watch item is the July 2026 public hearing of AMLA on ongoing-monitoring guidelines, which will provide the first concrete signal of how AMLA supervisory expectations will interact with the already-completed sectoral risk methodology of the FCIS. The more consequential horizon item is the entity-selection methodology for the initial cohort of approximately forty entities under AMLA direct supervision, not yet published but expected ahead of the 2028 start date; until it is published, Lithuania-domiciled EMI and VASP firms cannot determine with confidence whether they will fall within the direct-supervision perimeter of AMLA or remain under purely national oversight. This synthesis will integrate, rather than append, further developments in AMLA institutional build-out and any confirmed entity-selection methodology in subsequent cycles.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
Proposed1 Dec 2026 · ±half_year

Next MONEYVAL enhanced follow-up report on Lithuania (R.6/7/28)

MONEYVAL next enhanced follow-up report will assess whether Lithuania targeted-financial-sanctions freezing mechanisms (R.6/7) and DNFBP supervision (R.28) deficiencies have been resolved since the December 2024 Partially Compliant ratings.
In Force Pending31 Dec 2026 · ±half_year

AMLA Work Programme and institutional build-out

AMLA continues standing up in Frankfurt, publishing its work programme, supervisory methodology, and holding public hearings (e.g. ongoing-monitoring guidelines, July 2026) ahead of direct supervision.
In Force Pending2027-07 · ±quarter

Lithuania 6AMLD national transposition deadline

Lithuania must transpose 6AMLD national-level provisions (FIU powers, national supervisory architecture, register coordination) alongside the AMLR application date.
Adopted10 Jul 2027 · ±year

AMLR and 6AMLD application date (EU-wide)

The single AML rulebook (AMLR) becomes directly applicable EU-wide and 6AMLD transposition deadlines bite across Member States, ending divergent national AMLD-based implementation.
Adopted2028 · ±multi_year

AMLA direct supervision of selected high-risk obliged entities begins

AMLA begins direct supervision of a first cohort (approximately 40) of high-risk cross-border obliged entities, potentially including Lithuania-domiciled cross-border EMI/VASP firms, shifting supervisory perimeter from purely national FNTT/Bank of Lithuania oversight to a hybrid EU-level regime.
5 dated · 4 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROHigh

Lithuania enforcement action against sanctions-evasion trade and licensed-sector AML failures generated concrete SAR-relevant red flags this cycle.

The medical exemption export-classification abuse and the ruble-denominated crypto conversions processed for EU-sanctioned Russian bank clients are both observable, document- or chain-level red flags rather than abstract risk categories, and the persistent DNFBP STR-filing gap indicates under-reporting risk in adjacent professional-services channels that may warrant independent monitoring attention.

5 evidence refs
ComplianceHigh

Recurring control failures across licensed Lithuania EMI and crypto firms coincide with a widening EU regulatory perimeter culminating in the 2027 AMLR and 6AMLD application date.

The Pervesk fine and the broader pattern of gross, systematic failures across several licensed entities indicate current control frameworks have not kept pace with sector growth, while the unresolved MONEYVAL Recommendation 6, 7 and 28 ratings and the DNFBP registration gap mark specific policy areas that the forthcoming AMLR and 6AMLD transposition may or may not directly remediate.

6 evidence refs
LegalHigh

Successive EU sanctions packages and a hybrid-threat broadening of the Belarus regime materially expand the sanctions-nexus liability perimeter touching Lithuania-connected entities.

The 16th, 18th and 19th sanctions packages and the December 2025 hybrid-activity broadening extend enforcement and listing grounds beyond conventional financial measures, while the Payeer and OLAF-linked enforcement actions demonstrate that both crypto-sector and trade-finance intermediaries face direct sanctions-nexus exposure for facilitation conduct.

6 evidence refs
BoardHigh

Lithuania frontline exposure to Russia and Belarus sanctions evasion, combined with an unresolved MONEYVAL rating and a forthcoming AMLA supervisory transition, represents a multi-year strategic risk trajectory rather than a single incident.

The customs raid, the hybrid-threat sanctions broadening, and the persistent Partially Compliant MONEYVAL ratings on targeted financial sanctions and DNFBP supervision together indicate structural exposure that enforcement escalation alone has not resolved, while the 2028 AMLA direct-supervision start signals a coming shift in the supervisory relationship for the largest cross-border obliged entities.

4 evidence refs
CTOHigh

Repeated AML control failures across licensed Lithuania crypto and EMI platforms, alongside a sanctions-evasion crypto conversion scheme, mark this cycle clearest digital-asset architecture risk.

The Pervesk monitoring-scenario deficiencies and the ruble-denominated crypto conversion scheme at Payeer both point to gaps in transaction-monitoring and screening technology at the platform level, gaps the forthcoming AMLA crypto-priority direct-supervision cohort is designed to address but has not yet reached.

4 evidence refs
RiskHigh

Lithuania combines a worsening sanctions-evasion transit trajectory with a recurring licensed-sector control-failure pattern, both flagged for cross-monitor escalation.

The customs enforcement volume and the hybrid-threat sanctions broadening are cross-referred to SCEM and WDM respectively for conflict-finance and state-capture corroboration, while the recurring EMI and crypto failure pattern and the historic EUR2 billion laundering dismantling indicate concentration risk in specific licensed-sector segments that merits monitoring independent of individual enforcement actions.

4 evidence refs
OperationsHigh

The medical exemption export-abuse pattern and the crypto sanctions-evasion scheme this cycle translate into concrete screening and monitoring red flags for trade-finance and VASP-facing workflows.

The volume of rejected exemption-classification export requests and the onchain-observable ruble-conversion indicator are both document- or transaction-level signals that existing screening workflows can incorporate, while the DNFBP registration gap and the completed FCIS sectoral risk methodology point to process-level changes in scope and monitoring calibration ahead of the AMLA transition.

4 evidence refs
AuditHigh

Persistent evidentiary gaps around the Lithuania beneficial-ownership registry, DNFBP reporting, and prior enforcement remediation status limit the current audit trail available for control-testing purposes.

The non-public beneficial-ownership registry, the absence of current STR-filing volume data for DNFBP populations, and the unconfirmed remediation status following the Pervesk enforcement action and the historic Troika Laundromat and EUR2 billion dismantling cases each represent documented gaps in the evidence base rather than confirmed control adequacy, and are recorded as open items rather than resolved findings.

5 evidence refs
Decision lens
MLRO

Lithuania enforcement action against sanctions-evasion trade and licensed-sector AML failures generated concrete SAR-relevant red flags this cycle.

Compliance

Recurring control failures across licensed Lithuania EMI and crypto firms coincide with a widening EU regulatory perimeter culminating in the 2027 AMLR and 6AMLD application date.

Legal

Successive EU sanctions packages and a hybrid-threat broadening of the Belarus regime materially expand the sanctions-nexus liability perimeter touching Lithuania-connected entities.

Board

Lithuania frontline exposure to Russia and Belarus sanctions evasion, combined with an unresolved MONEYVAL rating and a forthcoming AMLA supervisory transition, represents a multi-year strategic risk trajectory rather than a single incident.

CTO

Repeated AML control failures across licensed Lithuania crypto and EMI platforms, alongside a sanctions-evasion crypto conversion scheme, mark this cycle clearest digital-asset architecture risk.

Risk

Lithuania combines a worsening sanctions-evasion transit trajectory with a recurring licensed-sector control-failure pattern, both flagged for cross-monitor escalation.

Operations

The medical exemption export-abuse pattern and the crypto sanctions-evasion scheme this cycle translate into concrete screening and monitoring red flags for trade-finance and VASP-facing workflows.

Audit

Persistent evidentiary gaps around the Lithuania beneficial-ownership registry, DNFBP reporting, and prior enforcement remediation status limit the current audit trail available for control-testing purposes.

Shared evidence: 10 refs
Scenario sketches

AMLA Direct-Supervision Transition and the Reshaping of Cross-Border AML Oversight

Illustrative orientation only: as the EU Anti-Money Laundering Authority moves from institutional build-out toward its planned 2028 direct-supervision start for a first cohort of high-risk cross-border obliged entities, a possible structural dynamic worth watching is how cross-border EMI and VASP groups might adjust their corporate footprint, licensing structure, or cross-border transaction volume in anticipation of, or in response to, entity-selection methodology once published. A hybrid supervisory perimeter, national authorities retaining oversight of the majority of obliged entities while AMLA directly supervises a defined high-risk cohort, could in principle create an incentive structure where firms near the selection threshold manage their cross-border footprint deliberately, or where supervisory arbitrage opportunities emerge at the boundary between AMLA-supervised and nationally supervised peers. This is illustration of a possible structural dynamic under the emerging AMLR, 6AMLD and AMLA architecture, not a description of observed conduct by any named entity.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Adaptive Rerouting in Response to Heightened Lithuania Customs Scrutiny

Illustrative orientation only: given the scale of enforcement now visible in the Lithuania trade-evasion architecture, the OLAF-backed customs raid and the volume of rejected medical-exemption export requests, a possible structural adaptation worth monitoring is a shift of transshipment routing away from the specific Central Asian corridor already identified toward alternative third-country jurisdictions with less-developed export-control scrutiny. Such a shift, if it occurred, would represent a displacement of the same underlying evasion architecture rather than its resolution, illustrating how architecture-over-incident enforcement gains in one transit corridor can, in principle, generate compensating exposure elsewhere. This is an illustrative structural possibility, not an observed development or a prediction about any specific jurisdiction or entity.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion ArchitectureworseningLithuania remains a key transit/interdiction point for Russia/Belarus evasion trade; enforcement (raids, mass exemption rejections) has escalated alongside persistent evasion tactics and EU regime broadening to hybrid-threat grounds.
T2 · EU AML Package / AMLAimprovingFNTT completed an EU-funded TSI supervisory-capacity project (2022-2024); AMLA build-out (IT systems, guidance, July 2026 public hearing) continues ahead of the AMLR application date (10 July 2027) and AMLA direct supervision (2028).
T3 · FATF Grey ListstableLithuania is not on the FATF grey/black list; remains in MONEYVAL enhanced follow-up with R.2 upgraded to Compliant (Dec 2024) while R.6, R.7 and R.28 remain Partially Compliant.
T4 · Beneficial-Ownership Register StatusstableUBO registry remains non-public, legitimate-interest access only, consistent with the post-2022 CJEU ruling; AMLR harmonisation of the access standard is the forward watch item.
T5 · Crypto & Digital-Asset IntegrityimprovingRepeated large enforcement actions (Pervesk/Bankera, Payeer, prior Transactive/Payrnet revocations) expose recurring supervisory strain, partially offset by MiCA's full effect and AMLA's crypto-priority direct-supervision plans.
T6 · Sanctions Regime DivergenceworseningEU full-transaction-ban measures (18th/19th packages) extend further into third-country financial/crypto operators than equivalent US/UK secondary-sanctions tools, creating cross-border compliance friction for Lithuania-domiciled EMIs/VASPs.
Registers

Enforcement actions

  • Joint raid on a company allegedly exporting EU-manufactured, sanctioned goods to Russia and Belarus by rerouting them through Central Asian countries to defeat EU export restrictions. 10 Apr 2025
  • Fine and formal warning for failing to properly assess risk from high-risk clients and foreign financial institutions, not adapting monitoring scenarios to ML typologies, and insufficient staff AML training. 29 Aug 2025
  • Lithuanian customs disclosed rejecting 28,854 export requests for goods bound for Russia and Belarus that attempted to exploit a 'medical exemption' classification to bypass EU sanctions. 12 Jun 2025

Sanctions changes

  • EU's 19th sanctions package against Russia targeted Russian energy, third-country banks facilitating circumvention, and crypto-asset providers, extending the transaction ban to third-country financial and crypto operators connected to Russia's financial messaging system. 23 Oct 2025
  • The EU Council broadened the Belarus sanctions regime to cover hybrid activities against EU member states -- disinformation/FIMI, critical-infrastructure disruption, migrant instrumentalisation and unauthorised entry -- a decision explicitly following meteorological-balloon airspace incursions into Lithuania. 15 Dec 2025
  • EU adopted its 16th sanctions package against Russia (three-year invasion anniversary), mirroring trade sanctions in the parallel Belarus regime and adding restrictions on services, software, deposits, crypto-asset wallets and transport; the Belarus sanctions regime was concurrently prolonged to 28 February 2026. 24 Feb 2025
  • EU's 18th sanctions package upgraded the existing SWIFT ban on Belarusian banks (in view of Belarus' complicity in Russia's war) to a full transaction ban, and extended equivalent full transaction bans on other listed Russian/Belarusian banks. 18 Jul 2025

Regulatory horizon (register)

  • AML Regulation (AMLR) becomes directly applicable EU-wide
  • AMLA begins direct supervision of ~40 high-risk entities
  • 6AMLD transposition deadline for Lithuania
  • Next MONEYVAL follow-up report on Lithuania's R.6/7/28 gaps

Active schemes

  • [HIGH] Belarus/Russia sanctioned-goods transit and exemption abuse
  • [HIGH] Lithuania-licensed crypto firms servicing sanctioned Russian clients
  • Non-public UBO register shielding ownership links
  • [HIGH] Licensed EMI/bank layering for offshore proceeds (legacy and current)
Sources
  1. FATF / MONEYVAL
  2. FATF / MONEYVAL
  3. Council of the European Union (Consilium)
  4. European Anti-Fraud Office (OLAF)
  5. European Commission (DG REFORM / Council of Europe project)
  6. OCCRP
  7. Bloomberg
  8. OCCRP
  9. Bloomberg
  10. OCCRP
  11. European Commission / AMLA
  12. Elliptic
Coverage gaps
Lithuania's beneficial ownership registry is not publicly ac…
Lithuania's beneficial ownership registry is not publicly accessible; access is restricted to parties demonstrating 'legitimate interest,' a standard that remains ill-defined since the 2022 CJEU Sovim/W.M. ruling invalidated mandatory EU-wide public access.
FATF Recommendations 6 (TF targeted financial sanctions), 7 …
FATF Recommendations 6 (TF targeted financial sanctions), 7 (PF targeted financial sanctions) and 28 (DNFBP regulation/supervision) remain rated Partially Compliant in Lithuania's December 2024 MONEYVAL follow-up report, reflecting unclear freezing/de-listing procedures and incomplete DNFBP oversight.
No registration framework exists for accountants and real es…
No registration framework exists for accountants and real estate agents as DNFBPs, and MVTS providers, real estate agents, notaries and CSPs have historically filed few or no suspicious transaction reports despite facing material ML/TF risk exposure.
Recurring AML/CFT control failures across Lithuania's licens…
Recurring AML/CFT control failures across Lithuania's licensed EMI and crypto-asset sector (Pervesk/Bankera, Payeer, Transactive Systems, Payrnet) indicate persistent supervisory capacity strain relative to the scale and speed of fintech-sector growth, despite an EU-funded 2022-2024 project to strengthen FCIS risk-based supervision.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.