Financial Integrity Monitor

Slovenia SI

Domains (D1–D6)
6
Sources
11
Role actions
8
Horizon <90d
5
Jurisdiction profile
CompliantTier BRisk: StableMixed

Slovenia's AML/CFT regime rests on the Prevention of Money Laundering and Terrorist Financing Act (ZPPDFT-2), transposing EU AMLD, supervised by the FIU (UPPD, Ministry of Finance) and Banka Slovenije for banks.

MoreA free public beneficial-ownership register is maintained via AJPES. MONEYVAL rates Slovenia largely compliant technically (all Recommendations bar R.5 at LC/C) but the country remains in enhanced follow-up, with persistently low money-laundering conviction rates relative to predicate-crime investigations.

Key deficiencies
  • Low ML prosecution/conviction rate relative to volume of predicate-offence investigations (tax evasion, fraud, drug trafficking), a finding carried from the 2017 MER through subsequent follow-up reports
  • VASP oversight rated only Partially Compliant in the 2021 Follow-Up Report due to deficiencies in the definition of virtual asset service providers
  • No comprehensive domestic review of the NPO sector's terrorist-financing risk exposure identified in the 2017 MER
Recent developments (18m)
  • MONEYVAL 5th-round mutual evaluation on-site assessment of Slovenia tentatively scheduled around late September 2025 per the FATF assessment calendar, opening a new evaluation cycle
  • EU AMLA became operational (Frankfurt, mid-2025) creating a new indirect supervisory layer over Slovenian obliged entities
  • EU added Russia, Bolivia and the British Virgin Islands to its high-risk third-country list (December 2025), triggering enhanced due diligence obligations for Slovenian obliged entities
  • Eurojust-coordinated dismantling and Reggio Calabria sentencing (October 2025) of an 'Ndrangheta money-laundering/cocaine-trafficking network in which Slovenian authorities participated as one of nine cooperating jurisdictions
  • MiCA transitional period for legacy-registered crypto-asset service providers, including Slovenia-domiciled exchanges, closed 1 July 2026
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

The financial-integrity profile of Slovenia this cycle is defined by architecture rather than incident: three EU-level shifts have converged onto a jurisdiction whose technical AML and CFT compliance is already rated largely compliant across all forty FATF Recommendations bar Recommendation 5, per the 2023/2024 MONEYVAL Follow-Up Report, while Slovenia remains in enhanced follow-up. The European Commission Delegated Regulations (EU) 2026/46 and (EU) 2026/83, adopted in December 2025, added Russia, Bolivia and the British Virgin Islands to the EU high-risk third-country list, with six delistings, triggering enhanced due diligence obligations for every Slovenian obliged entity transacting with those jurisdictions. At the same time, the EU-wide MiCA transitional window for legacy-registered crypto-asset service providers closed on 1 July 2026, converting the Ljubljana domicile of Bitstamp from a reputational asset into a live regulatory-gatekeeping exposure: continued EU-facing service now depends on full Article 63 authorization rather than legacy national registration. Layered onto both is the Anti-Money Laundering Authority, operational in Frankfurt since mid-2025 under Chair Bruna Szego, which already exercises indirect coordination over Banka Slovenije even though no Slovenian entity has yet been named for direct supervision.

The domestic overlay to this EU-level architecture is an open 5th-round MONEYVAL evaluation cycle for Slovenia, with an on-site assessment tentatively conducted around 29 September 2025 and a plenary discussion tentatively scheduled around 1 May 2026, an outcome that requires reconfirmation. Read together, the picture is one of steadily improving technical form arriving alongside unresolved effectiveness questions, most notably a persistently low money-laundering conviction rate relative to the volume of predicate-offence investigations, a deficiency first identified in the 2017 Mutual Evaluation Report and not resolved through any subsequent follow-up report.

Other Developments

A historical correspondent-banking case retains structural relevance. Nova Ljubljanska Banka, the largest bank in Slovenia, held accounts around 2010 for a shell company moving funds tied to the sanctioned Export Development Bank of Iran; a suspicious transaction report was filed, but the freeze order took nine days to implement, a delay that allowed the funds to move into Russian banks. The episode is retained not as a live case but as the reference precedent for a delayed-freeze vulnerability pattern that could recur for Russia-linked flows given the EU-member exposure of Slovenia to the current sanctions architecture.

A US Kingpin Act designation reached the Slovenian corporate registry directly. In October 2024, an OFAC SDNTK designation named a Ljubljana resident, Uros Slivnik, and linked him to two Slovenian investment vehicles, Velinvestment D.O.O. and Sagax Investment Group, in connection with narcotics-trafficking-linked nominee asset management. The case demonstrates that ordinary Slovenian limited-liability company forms can be layered into US-designated nominee structures independent of any disclosed domestic predicate investigation.

A cross-border company-formation laundering network centred on a Slovenian prime ministerial adviser remains the standing enabler-jurisdiction story. The network used shell companies across six jurisdictions, namely Slovenia, Bosnia, Slovakia, Hungary, Austria and Bulgaria, fabricated invoices to move funds beneath banking-compliance detection thresholds, and relied on lax due diligence at a UK company-formation agent, Formations House, to bury vehicles once they came under investigation.

The beneficial-ownership register of Slovenia continues to outperform regional peers on transparency, even as enforcement outcomes lag. Global Witness rates the AJPES-administered public register in its top green category, alongside Bulgaria, Denmark, Latvia and Luxembourg. Separately, Slovenian police cooperated as one of nine jurisdictions in a Eurojust-coordinated operation against an Ndrangheta cocaine-trafficking and money-laundering network, which the Reggio Calabria court concluded on 21 October 2025 with 76 defendants sentenced to a combined 1,098 years imprisonment and EUR 440,000 in fines.

Sanctions-regime divergence between the EU and the UK continues to create compliance friction for Slovenian-linked entities. The June 2026 Money Laundering Advisory Notice from HM Treasury tracks the 19 June 2026 FATF plenary outcomes, but the UK high-risk third-country list continues to differ in composition and timing from the EU delegated-regulation list; as of this cycle, neither list names Slovenia itself, but Slovenian firms transacting with UK counterparties must reconcile two distinct enhanced-due-diligence perimeters.

Cross-Monitor Connections

The reliance of the cross-border company-formation network on a UK company-formation agent is a direct enabler-jurisdiction signal relevant to the tracking by FCW of professional-facilitator ecosystems that obscure illicit flows across borders. Separately, the historical NLB-Iran correspondent-banking case and the Slivnik Kingpin Act designation both touch a sanctions-evasion and narcotics-finance nexus of relevance to the conflict- and state-linked financial-flow monitoring conducted by SCEM, though this connection is assessed at lower confidence given the single-source nature of both underlying cases. No Slovenia-specific state-capture, conflict-finance or extractive-industry signal was identified this cycle, consistent with the quiet rating carried by the domain tracker for conflict finance.

Outlook

The near-term regulatory horizon for Slovenia is dominated by the convergence of three EU-level shifts rather than by any single domestic event: the AMLA Work Programme and supervisory-methodology build-out expected around the fourth quarter of 2026, the AMLR and 6AMLD both becoming generally applicable and requiring transposition from 10 July 2027, and the first cohort of directly-supervised cross-border obliged entities under AMLA expected around 2028, which would shift the supervisory perimeter of Slovenia from a purely national to a hybrid EU-level regime. Confirmation of the MONEYVAL 5th-round plenary outcome, and confirmation of the post-1 July 2026 MiCA authorization status of Bitstamp and any other Slovenian CASP, are the two most consequential near-term data points still outstanding; both are flagged in the gaps register as requiring re-verification rather than treated as resolved.

weekly_brief_draft · JID SI
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

The D1 exposure of Slovenia this cycle is structuralrather than active: no evidence places the jurisdiction in a current transit or intermediary corridor for Russian sanctions evasion, but two developments bind it firmly into the evolving sanctions architecture of the EU. First, the European Commission Delegated Regulations (EU) 2026/46 and (EU) 2026/83, adopted 3 and 4 December 2025 respectively, added Russia, Bolivia and the British Virgin Islands to the EU high-risk third-country list, alongside six delistings. This is an autonomous Commission action that diverges from the FATF, US OFAC and UK OFSI list mechanisms in both form and timing, and it triggers enhanced due diligence obligations for every Slovenian obliged entity dealing with the newly listed jurisdictions, obligations that apply uniformly across the EU rather than through any Slovenia-specific instrument. Second, the 20th Russia sanctions package of the EU, adopted around May 2026, introduced a sectoral ban on Russia-based crypto service providers and prohibited RUBx and digital-ruble instruments; as an EU member state with no independent national sanctions regime, Slovenia applies this package uniformly, extending the sanctions-architecture perimeter into the crypto-asset domain that already carries elevated significance for Slovenia given the Ljubljana domicile of Bitstamp.

The historical case retained as this cycle structural-vulnerability precedent is the correspondent-banking exposure of Nova Ljubljanska Banka to Iran-linked funds around 2010: accounts were opened for a shell company moving funds for the sanctioned Export Development Bank of Iran, a suspicious transaction report was filed, but the freeze order took nine days to implement, a delay sufficient to allow the funds to move into Russian banks. This is not treated as a live case, it rests on a single tier-two source without independent corroboration this cycle, but it is retained because it demonstrates a delayed-freeze vulnerability pattern in the banking sector of Slovenia that is structurally identical to the risk now attaching to Russia-linked flows under the newly expanded EU sanctions perimeter. The analytical significance is not that Slovenia has an active Russian-evasion nexus today, but that the same institutional pattern, a suspicious transaction report filed, a freeze delayed, funds moved to a third-country banking system, remains a plausible recurrence path.

Compounding this, the divergence between the EU high-risk third-country list and the UK list maintained by HM Treasury continues into this cycle: the June 2026 Money Laundering Advisory Notice tracks the 19 June 2026 FATF plenary outcomes but continues to differ in composition and timing from the EU delegated-regulation list, and as of this cycle neither list names Slovenia itself. For Slovenian obliged entities transacting with UK counterparties, this divergence is a standing compliance-friction cost rather than a resolved harmonisation: two separate high-risk-country perimeters must be reconciled, and the newer sectoral and anti-circumvention crypto tools introduced under the 20th sanctions package of the EU have not yet been mirrored by the entity-by-entity designation approach used by OFAC or OFSI.

The NLB case also carries pillar significance beyond its AML dimension: it is tagged as a counter-proliferation-financing matter given the documented connection of the sanctioned Iranian bank to weapons proliferation financing, illustrating a pattern of under-weighting CPF risk within the overall AML-dominated compliance architecture of Slovenia. Three-pillar balance analysis therefore treats this historical case as more analytically significant than its age alone would suggest: it is the only CPF-flagged finding in the current dataset for Slovenia, and the absence of any newer CPF-specific development this cycle should not be read as reduced CPF exposure, given how rarely CPF-relevant findings surface relative to the volume of AML enforcement activity.

Read together, the D1 posture of Slovenia is best characterised as compliant-by-default rather than actively tested: EU membership supplies the sanctions architecture and Slovenia applies it without independent discretion, while its own historical vulnerability, the NLB-Iran case, and its position inside a still-diverging tri-bloc sanctions landscape spanning the EU, US and UK are the structural features worth monitoring, rather than any newly surfaced Slovenia-specific evasion scheme this cycle.

Outlook

The most consequential near-term D1 development for Slovenia is not a domestic event but the next EU delegated-regulation update cycle to the high-risk third-country list, and whether further EU sanctions packages extend sector-level crypto-CASP measures that UK and US authorities have not yet mirrored. Supervisory guidance in Slovenia will need to keep pace with each EU-level change given the lack of independent sanctions discretion attaching to Slovenia as a member state. Any resurfacing of a Slovenian correspondent-banking nexus in blockchain-analytics or investigative reporting, the pattern that produced the NLB-Iran case, would be the clearest signal of the structural vulnerability becoming active rather than historical.

Cumulative analysis

Sanctions Architecture and Evasion - Cumulative Analysis

This is the baseline cycle for the Sanctions Architecture and Evasion domain as it applies to Slovenia, and the cumulative picture established here should be read as the founding state against which future cycles will be measured. Slovenia enters this tracking arrangement as a jurisdiction whose sanctions exposure is structural rather than active: as an EU member state with no independent national sanctions regime, every EU-level sanctions instrument applies to Slovenia uniformly and without domestic discretion, which means that the sanctions-architecture story for Slovenia is, almost by construction, a story about EU-level policy rather than Slovenia-specific enforcement action.

Two EU-level developments define the current baseline. The European Commission Delegated Regulations (EU) 2026/46 and (EU) 2026/83, adopted in December 2025, added Russia, Bolivia and the British Virgin Islands to the EU high-risk third-country list, with six delistings, an autonomous Commission action that diverges from FATF, OFAC and OFSI list mechanisms in form and timing and that triggers enhanced due diligence obligations for Slovenian obliged entities transacting with those jurisdictions. The 20th Russia sanctions package of the EU, adopted around May 2026, extended this architecture into the crypto-asset domain through a sectoral ban on Russia-based crypto service providers and a prohibition on RUBx and digital-ruble instruments, a development of particular relevance to Slovenia given its outsized crypto-sector footprint through the Ljubljana domicile of the Bitstamp exchange.

Sitting alongside these EU-level developments is a single retained historical case that anchors the structural-vulnerability narrative for Slovenia: the correspondent-banking exposure of Nova Ljubljanska Banka, the largest bank in the country, to Iran-linked funds around 2010. A shell company held accounts used to move funds for the sanctioned Export Development Bank of Iran; a suspicious transaction report was filed but the freeze order took nine days to implement, long enough for the funds to move into Russian banks. This case is sourced from a single tier-two investigative account and lacks independent corroboration this cycle, so it is carried at assessed rather than high confidence, but its structural value is durable: it establishes a delayed-freeze vulnerability pattern in the banking sector of Slovenia that is analytically identical to the risk profile now attaching to Russia-linked flows under the newly expanded EU high-risk third-country and sanctions-package architecture. The case also carries counter-proliferation-financing significance, given the weapons-proliferation nexus of the designated Iranian bank, a pillar dimension that is likely to remain under-represented in Slovenia reporting relative to AML findings simply because CPF-relevant material surfaces far less often than AML enforcement volume.

The final structural layer of the baseline is the position of Slovenia within a diverging tri-bloc sanctions landscape. The EU high-risk third-country list, the UK list maintained by HM Treasury, and the US OFAC SDN architecture do not move in lockstep: the EU list update of December 2025 and the UK June 2026 advisory notice diverge in composition and timing, and neither list currently names Slovenia. This divergence is not itself a Slovenia-specific finding, since it applies to any EU jurisdiction with UK and US counterparty exposure, but for Slovenian obliged entities operating cross-border relationships it is a recurring compliance-friction cost that this tracker will continue to monitor, particularly as the EU introduces sector-level crypto-CASP designation tools that OFAC and OFSI have not yet mirrored.

Taken as a whole, the founding assessment for the Slovenia D1 domain is: compliant-by-default under EU sanctions architecture, with a single retained historical vulnerability precedent rather than any live evasion nexus, and a standing exposure to sanctions-regime divergence via UK and US counterparty relationships. Future cycles should watch for three things in particular: further EU delegated-regulation updates to the high-risk third-country list, any resurfacing of a Slovenian correspondent-banking nexus in blockchain-analytics or investigative reporting, and whether UK or US authorities begin to mirror the sector-level crypto-CASP designation approach introduced by the EU.

Outlook

The baseline outlook for this domain carries forward unchanged into subsequent cycles: watch the next EU high-risk third-country list update, monitor for any active, rather than structural, Russian sanctions-evasion nexus surfacing in Slovenia, and track whether the tri-bloc sanctions-divergence pattern narrows or widens as the EU, US and UK regimes continue to evolve independently.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

Slovenia sits inside the direct perimeter of the EU AML Package, and this cycle D2 picture should be read against that structural backdrop before any Slovenia-specific detail. The EU AML Package is properly understood as three distinct instruments rather than a single reform: the AML Regulation, known as the AMLR (Regulation (EU) 2024/1624), is directly applicable across all Member States and becomes generally applicable on 10 July 2027, harmonising customer due diligence, beneficial-ownership and financial-intelligence-unit powers into a single rulebook; the sixth AML Directive, known as 6AMLD (Directive (EU) 2024/1640), requires per-Member-State transposition, with the transposition deadline for Slovenia not yet due and no Slovenia-specific transposition gap having yet materialised; and the AMLA Regulation (Regulation (EU) 2024/1620) establishes the Anti-Money Laundering Authority itself, which has been operational in Frankfurt since mid-2025 under Chair Bruna Szego. AMLA already exercises an indirect coordination role over Banka Slovenije even though no Slovenian entity has yet been named for direct supervision; that direct-supervision perimeter, expected to select its first cohort of high-risk cross-border obliged entities around 2028, is the mechanism by which supervision shifts from a purely national to a hybrid EU-level regime. This three-instrument architecture is the durable backdrop against which every Slovenia-specific transparency signal this cycle should be read.

Against that backdrop, the technical-compliance position of Slovenia itself is strong: the 2023/2024 MONEYVAL Follow-Up Report rates all forty FATF Recommendations bar Recommendation 5 as Largely Compliant or Compliant, though Slovenia remains in enhanced follow-up pending resolution of that single gap. The beneficial-ownership register of Slovenia, administered via AJPES, is rated in the top green category by Global Witness for public accessibility, alongside Bulgaria, Denmark, Latvia and Luxembourg, placing Slovenia ahead of many larger EU peers on registry transparency in absolute terms.

The structural counterweight to this improving technical picture is a persistent effectiveness gap: the money-laundering conviction rate of Slovenia relative to the volume of predicate-offence investigations has remained low since this deficiency was first identified in the 2017 Mutual Evaluation Report, and it has not been resolved through any subsequent follow-up report. This is the central analytical tension in the D2 posture of Slovenia, a jurisdiction can operate a best-practice public beneficial-ownership register and still fail to convert that transparency into prosecutions, and the case of Slovenia demonstrates this directly. The October 2024 OFAC Kingpin Act designation of Uros Slivnik, a Ljubljana resident linked to two Slovenian investment vehicles, Velinvestment D.O.O. and Sagax Investment Group, tied to narcotics-trafficking-linked nominee asset management, illustrates how an ordinary Slovenian limited-liability company form can be layered into a foreign-designated nominee structure entirely independent of any disclosed domestic predicate investigation, the transparency register did not, on its own, prevent the underlying misuse.

This effectiveness gap is not confined to abstract statistics: it recurs in the most prominent recent case involving Slovenia, the cross-border company-formation laundering network centred on a Slovenian prime ministerial adviser, which used shell companies across six jurisdictions and fabricated invoices to move funds beneath banking-compliance detection thresholds. That network is analysed in full under the D3 enabler-jurisdiction lens, but its D2 relevance is direct: the same beneficial-ownership transparency regime rated green by Global Witness did not, on its own, prevent a network linked to a prime ministerial adviser from obscuring beneficial ownership across borders, reinforcing that the transparency-register strength of Slovenia and its predicate-to-conviction gap are two sides of the same structural finding.

The evaluation calendar of Slovenia adds a further overlay: a new MONEYVAL 5th-round evaluation cycle is open, with an on-site assessment tentatively conducted around 29 September 2025 and a plenary discussion tentatively scheduled around 1 May 2026, though the outcome requires reconfirmation as of this cycle baseline. Adoption of the 5th-round report would reset the compliance and effectiveness ratings of Slovenia under the 2022 FATF Methodology, and is the single most consequential near-term event for the D2 trajectory of Slovenia.

Outlook

The general application date of 10 July 2027 for the AMLR, and the still-open 6AMLD transposition question, are the two clearest forward D2 markers for Slovenia, both of which will compress the discretion currently exercised under the national ZPPDFT-2 transposition of the predecessor AMLD framework. Confirmation of the MONEYVAL 5th-round plenary outcome remains the most consequential unresolved data point, since a reset of the compliance and effectiveness ratings of Slovenia would materially alter the standing narrative independent of any EU-level instrument taking effect. The continuing build-out by AMLA of its direct-supervision selection criteria, expected through the fourth quarter of 2026, should also be watched for any signal of the inclusion of a Slovenian entity in the first directly-supervised cohort.

Cumulative analysis

Beneficial Ownership and Corporate Transparency - Cumulative Analysis

This is the baseline cycle for the Beneficial Ownership and Corporate Transparency domain as it applies to Slovenia, and it should be read as establishing the durable architecture against which every future D2 cycle will be measured. The starting point for that architecture is not Slovenia-specific: it is the EU AML Package, which must be tracked as three distinct instruments rather than a single reform. The AML Regulation, the AMLR under Regulation (EU) 2024/1624, is directly applicable and becomes generally applicable across the EU on 10 July 2027, harmonising customer due diligence, beneficial-ownership and financial-intelligence-unit powers into a single rulebook. The sixth AML Directive, 6AMLD under Directive (EU) 2024/1640, requires transposition on a per-Member-State basis, and the transposition deadline for Slovenia is not yet due. The AMLA Regulation, Regulation (EU) 2024/1620, establishes the Anti-Money Laundering Authority itself, operational in Frankfurt since mid-2025 under Chair Bruna Szego, which already coordinates indirectly with Banka Slovenije and is expected to begin direct supervision of a first cohort of high-risk cross-border obliged entities around 2028. This three-instrument, staged-implementation architecture is the single most durable fact in the D2 domain and will remain the interpretive backdrop for Slovenia regardless of what develops in any individual cycle.

Against this backdrop, the baseline technical-compliance position of Slovenia is strong: MONEYVAL rated all forty FATF Recommendations bar Recommendation 5 as Largely Compliant or Compliant in its 2023/2024 Follow-Up Report, and the public beneficial-ownership register administered through AJPES is independently rated in the top transparency category by Global Witness, alongside Bulgaria, Denmark, Latvia and Luxembourg. On paper, Slovenia is a strong performer on both technical compliance and registry accessibility.

The counterweight that has defined this domain since its earliest assessment, and that this baseline cycle carries forward rather than resolves, is the persistent gap between predicate-offence investigation volume and money-laundering conviction outcomes, a deficiency first identified in the 2017 Mutual Evaluation Report and never closed through any subsequent follow-up cycle. This baseline cycle supplies the clearest illustration yet of why that gap matters in practice: the October 2024 Kingpin Act designation by OFAC of a Ljubljana resident linked to two ordinary Slovenian limited-liability companies, and the cross-border company-formation network centred on a Slovenian prime ministerial adviser using shell structures across six jurisdictions, both demonstrate that a best-practice public registry and improving technical ratings have not, on their own, prevented beneficial ownership from being obscured or misused. The transparency-register strength of Slovenia and its conviction-rate weakness should therefore be read as two faces of a single structural finding, not as independent or offsetting signals.

The final element of the baseline is the open evaluation calendar: a 5th-round MONEYVAL cycle for Slovenia, with an on-site assessment conducted around September 2025 and a plenary discussion tentatively scheduled around May 2026, whose outcome is not yet confirmed. Adoption of that report will reset the compliance and effectiveness ratings of Slovenia and is the most consequential single event on this domain horizon.

Looking forward from this baseline, three markers will define how the domain develops: the AMLR general application date of 10 July 2027 and the parallel 6AMLD transposition deadline, both of which will compress the discretion currently available under the national ZPPDFT-2 framework; confirmation of the 5th-round MONEYVAL outcome; and any signal from the AMLA supervisory build-out that a Slovenian entity may be included in the first directly-supervised cohort. None of these are yet resolved, and this cumulative baseline should be updated, not restated, as each resolves.

Outlook

The outlook carried forward from this baseline is unchanged from the per-cycle assessment: the AMLR application date, the 6AMLD transposition deadline, the MONEYVAL 5th-round outcome, and the AMLA direct-supervision selection process are the four markers against which future D2 cycles for Slovenia should be measured.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The D3 profile of Slovenia this cycle centres on a single, well-evidenced professional-enablement architecture: a cross-border company-formation laundering network centred on a sitting Slovenian prime ministerial adviser and a convicted fraudster, who together used shell companies across six jurisdictions, Slovenia itself, Bosnia, Slovakia, Hungary, Austria and Bulgaria, fabricated invoices to move funds beneath banking-compliance detection thresholds, and relied on lax due diligence at a UK company-formation agent, Formations House, to incorporate and subsequently bury vehicles once creditors or investigators began to take an interest. This is not a single-jurisdiction failure: it is a live illustration of how professional facilitators operating across multiple permissive incorporation regimes allow a beneficial owner to obscure the ultimate ownership chain even where, as in the case of Slovenia itself, the domestic beneficial-ownership register is independently rated as best in class for public accessibility. The persistence of the network and its cross-jurisdictional footprint make it the clearest enabler-jurisdiction filter trigger in the current dataset for Slovenia, and it should be read as an architecture-level finding rather than an isolated fraud case, consistent with the architecture-over-incident principle: the individual fraud conviction is a data point, but the six-jurisdiction shell structure and the UK formation-agent failure are the enabling infrastructure.

The other D3-relevant development for Slovenia this cycle is more limited in scope but analytically distinct: Slovenian police cooperated as one of nine jurisdictions in a Eurojust-coordinated operation against an Ndrangheta cocaine-trafficking and money-laundering network, which the Reggio Calabria court concluded on 21 October 2025, sentencing 76 defendants to a combined 1,098 years imprisonment and EUR 440,000 in fines. The contribution of Slovenia here was limited to police cooperation rather than a domestic prosecution, and this should be read accordingly: it demonstrates constructive participation by Slovenia in multinational enforcement architecture, but it does not by itself establish that Slovenia hosts a domestic Ndrangheta-linked laundering nexus of its own.

Taken together, these two developments illustrate the enforcement-versus-enablement duality that characterises the overall jurisdiction-risk profile of Slovenia: Slovenia is simultaneously a constructive cooperating partner in cross-border organised-crime enforcement and, through the prime ministerial adviser network, a jurisdiction whose own domestic actors have exploited weak third-country company-formation controls, in this case a UK-domiciled formation agent, to launder proceeds. Neither posture cancels the other; both should be weighted in any overall enabler-jurisdiction assessment. It is also notable that the persistent gap between the predicate-offence investigation volume of Slovenia and its money-laundering conviction rate, carried unresolved from the 2017 Mutual Evaluation Report, recurs directly in the prime ministerial adviser case: the underlying conduct, tax evasion and fabricated invoicing, generated significant public reporting and investigative attention from OCCRP, but no confirmed Slovenian money-laundering conviction outcome for the network has been identified in the available reporting window.

The active-scheme inventory associated with this network flags two recurring red-flag indicators of operational relevance to obliged entities: fabricated invoices used to move funds in amounts below banking-compliance detection thresholds, and reliance on lax overseas company-formation-agent due diligence to incorporate and subsequently bury vehicles once investigations begin. Both indicators are observable at the onboarding or trade-document review stage, meaning they are, in principle, detectable at the point of customer onboarding or trade-finance review rather than only after the fact through law-enforcement referral. Separately, the non-profit sector terrorist-financing risk exposure of Slovenia has not been independently reassessed since the 2017 Mutual Evaluation Report finding on this point, a standing coverage gap that sits adjacent to, though analytically distinct from, the proceeds-laundering focus of the company-formation network.

Outlook

The most consequential open question for the D3 profile of Slovenia is whether the prime ministerial adviser-linked company-formation network produces any domestic money-laundering prosecution outcome, which would be the first direct test of whether the persistent conviction gap of Slovenia can be closed by its highest-profile professional-enablement case to date. Separately, any further Eurojust-coordinated multinational operation naming Slovenia as a cooperating jurisdiction would reinforce the enforcement side of the enforcement-versus-enablement balance, while further OCCRP or investigative reporting on the six-jurisdiction shell network would be the clearest signal of whether the underlying architecture remains active or has been fully dismantled.

Cumulative analysis

Enabler Jurisdictions and Professional Facilitators - Cumulative Analysis

This baseline cycle establishes the D3 domain for Slovenia around a single defining architecture: a cross-border company-formation laundering network centred on a sitting prime ministerial adviser, which used shell companies across six jurisdictions, Slovenia, Bosnia, Slovakia, Hungary, Austria and Bulgaria, fabricated invoices to move funds beneath banking-compliance thresholds, and exploited lax due diligence at a UK company-formation agent, Formations House, to bury vehicles once investigations began. This case is the founding reference point for the enabler-jurisdiction assessment of Slovenia and should be read as an architecture-level finding under the architecture-over-incident principle: the underlying individual fraud conviction is a data point, but the durable analytical value lies in the six-jurisdiction shell structure and in the demonstrated capacity of a permissive third-country company-formation regime to absorb and obscure Slovenian-originated proceeds.

Layered onto this founding case is a second, more limited signal: cooperation by Slovenia as one of nine jurisdictions in a Eurojust-coordinated operation against an Ndrangheta cocaine-trafficking and money-laundering network, concluded by the Reggio Calabria court on 21 October 2025 with 76 defendants sentenced to a combined 1,098 years imprisonment. This establishes the enforcement side of the ledger for Slovenia: a jurisdiction that cooperates constructively in multinational organised-crime operations even as its own domestic actors have exploited foreign company-formation weaknesses. This enforcement-versus-enablement duality is likely to remain the defining structural tension of the D3 domain for Slovenia going forward, and future cycles should track both sides of it rather than treating either as the complete picture.

The baseline also establishes a recurring analytical theme that connects D3 to the domain covering beneficial ownership: the persistent gap between predicate-offence investigation volume and money-laundering conviction outcomes, unresolved since the 2017 Mutual Evaluation Report, recurs directly in the prime ministerial adviser case, where extensive investigative and public reporting has not yet produced a confirmed domestic conviction outcome. This is now the single clearest illustrative example available for that structural deficiency, and its resolution, or continued non-resolution, in future cycles will be a meaningful test of whether the enforcement capacity of Slovenia is closing the gap identified nearly a decade ago.

Finally, this baseline records two practical control-relevant red-flag indicators associated with the company-formation network, fabricated invoicing below detection thresholds and reliance on lax overseas formation-agent due diligence, both of which are observable at onboarding or trade-document review stage rather than only after law-enforcement referral. It also records a standing coverage gap: the non-profit sector terrorist-financing risk exposure of Slovenia has not been independently reassessed since 2017, a gap that remains open into this and future cycles.

Outlook

Future cycles should track three things against this baseline: whether the prime ministerial adviser-linked network produces a confirmed domestic prosecution outcome, whether further multinational enforcement operations name Slovenia as a cooperating jurisdiction, and whether the non-profit sector terrorist-financing coverage gap is closed through direct reassessment.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance and Extractive-Industry Integrity

Conflict Finance and Extractive-Industry Integrity

Continue reading

No Slovenia-specific conflict-finance or extractive-industry-integrity development was identified in the available reporting window this cycle; the domain tracker carries this row forward as quiet, with no change from the prior baseline. This is consistent with the wider dataset: none of the structured claims produced for Slovenia this cycle touch armed-conflict financing, extractive-sector corruption, or commodity-flow evasion channels of the kind tracked under the conflict finance filter. Absence of signal should not be read as an assessed finding of zero exposure, it reflects the boundaries of the research coverage available this cycle rather than a positive determination that Slovenia carries no conflict-finance risk. The wider financial-integrity profile of Slovenia this cycle is dominated instead by sanctions-architecture, beneficial-ownership, enabler-jurisdiction and crypto-sector developments, none of which carry a conflict-finance or extractive-industry dimension on the evidence available. This quiet rating reflects a genuine absence of findings across the eighteen sources searched and eleven sources with findings this cycle, rather than an inference drawn from limited search depth; the coverage-gaps register for this cycle does not flag D4 as an area of incomplete collection, distinguishing this quiet status from a research gap.

Outlook

No Slovenia-specific development in this domain is currently anticipated on the near-term regulatory horizon. This domain should be re-tested in subsequent cycles as new research coverage becomes available, particularly if any Slovenian financial institution or corporate structure surfaces in reporting connected to conflict-affected extractive supply chains or armed-group financing. Any future Slovenia-linked signal in this domain would most plausibly surface through EU sanctions-designation reporting or through extractive-industry transparency initiatives, neither of which currently names a Slovenian entity.

Cumulative analysis

Conflict Finance and Extractive-Industry Integrity - Cumulative Analysis

This baseline cycle establishes the D4 domain for Slovenia as quiet: no Slovenia-specific conflict-finance or extractive-industry-integrity development has been identified in the research window available at this baseline. This should be understood as a genuine absence of findings rather than a positive determination of zero risk, and rather than a research-depth limitation, since the coverage-gaps register for this cycle does not flag D4 as an area of incomplete collection. The financial-integrity profile of Slovenia established at this baseline is instead concentrated in sanctions architecture, beneficial ownership, enabler-jurisdiction and crypto-sector domains, none of which carry a conflict-finance or extractive-industry dimension on current evidence. The absence of signal in this domain stands in contrast to the material development recorded this cycle across D1, D2, D3, D5 and D6, and this contrast is itself worth preserving in the cumulative record: it demonstrates that the overall financial-integrity risk profile of Slovenia is concentrated in specific structural domains, sanctions architecture, corporate transparency, professional enablement, and crypto-asset infrastructure, rather than distributed evenly across all six controlled domains. This asymmetry should inform how monitoring resources are prioritised for Slovenia going forward, without treating the D4 quiet status as permanent or foreclosed.

Outlook

Because this is a baseline cycle with no D4 findings, no domain-specific trajectory can yet be established. Future cycles should treat this baseline as a starting point to be revised upward from quiet only if a genuine Slovenia-linked conflict-finance or extractive-industry signal surfaces, most plausibly through EU sanctions-designation reporting or extractive-industry transparency channels. Should a Slovenia-specific extractive-industry or conflict-finance signal emerge in a future cycle, this baseline record provides the explicit starting point against which any change would be measured, namely a fully quiet domain with no prior findings, no open investigations, and no identified exposure through either armed-group financing or extractive-sector corruption channels.

domain_sub_briefs · D4 · Cumulative analysis

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

The D5 exposure of Slovenia is structurally disproportionate to its size, and every development this cycle should be read through that lens: Slovenia is the legal domicile of Bitstamp, a globally significant crypto exchange, which means the Slovenia-facing implementation details of MiCA carry weight well beyond what a jurisdiction of this scale would ordinarily generate. The single most consequential D5 event this cycle is the closure, on 1 July 2026, of the EU-wide MiCA transitional window for legacy-registered crypto-asset service providers. Bitstamp and any other Slovenia-domiciled exchange operating under national legacy registration must now hold full Article 63 CASP authorization to continue EU-facing service; there is no further extension mechanism identified in current tracking. As of this cycle baseline, the post-1 July 2026 authorization status of Bitstamp has not been independently confirmed, and this is flagged explicitly in the gaps register as requiring direct confirmation via the authorization register of Banka Slovenije or ESMA, a live confirmation gap rather than a resolved fact.

This regulatory-gatekeeping shift arrives alongside genuine technical-compliance improvement: the 2023/2024 MONEYVAL Follow-Up Report upgraded the Recommendation 15 rating of Slovenia, covering new technologies and virtual-asset service providers, from Partially Compliant in the 2021 Follow-Up Report to Largely Compliant. This closes a definitional VASP-scope deficiency first identified in the 2017 and 2021 assessments, and it is directly relevant given the role of Slovenia as domicile for an internationally active exchange: a jurisdiction hosting a globally significant VASP now has a materially stronger FATF-rated legal framework for supervising it than it did as recently as 2021.

The crypto-sector sanctions dimension also touches Slovenia this cycle. The 20th Russia sanctions package of the EU, adopted around May 2026, introduced a sectoral ban on Russia-based crypto service providers and prohibited RUBx and digital-ruble instruments; as an EU member with no independent sanctions discretion, Slovenia applies this measure uniformly, meaning any Slovenian VASP counterparty relationship with a Russia-based crypto service provider is now a sanctions-architecture matter and not solely an AML due-diligence question. This is a genuinely novel enforcement tool, sector-level rather than entity-by-entity designation, that neither the US OFAC nor the UK OFSI approach currently mirrors, a divergence that Slovenian VASPs with cross-border US and UK counterparty relationships will need to navigate directly.

Read together, the D5 trajectory of Slovenia is improving on the technical-compliance axis, the Recommendation 15 upgrade, while facing a live, unresolved gatekeeping test on the market-access axis, the MiCA authorization question. The two are related but distinct: a strong FATF rating does not itself confirm that Bitstamp or any other Slovenian CASP has completed Article 63 authorization, and the improving trajectory recorded in the domain tracker should not be read as confirmation that the authorization question has been resolved.

The active-scheme inventory tracks this exposure under the heading of MiCA transition exposure for the Ljubljana-domiciled VASP, with customer-typology relevance flagged for both VASP-counterparty and retail-customer segments; no red-flag indicators have yet been populated for this scheme, reflecting that it is a regulatory-transition exposure rather than an observed laundering typology in its own right. The Article 63 authorization obligation is tracked at an in-force citation stage, meaning the authorization requirement itself is not prospective, it already binds Slovenian CASPs as of this cycle baseline, in contrast to the AMLR and 6AMLD, which remain forward-looking instruments not yet generally applicable. This distinction matters analytically: MiCA Article 63 gatekeeping is a live, binding, present-tense control point for the crypto sector of Slovenia today, whereas the AMLR, 6AMLD and AMLA architecture discussed under D2 remains a forward-looking structural shift whose supervisory bite for Slovenia specifically has not yet arrived.

Outlook

Confirmation of the post-1 July 2026 MiCA authorization status of Bitstamp and other Slovenia-domiciled CASPs is the single most consequential near-term D5 data point, and it remains an open item in the gaps register rather than a settled fact. The continuing development by AMLA of its direct-supervision criteria for high-risk CASPs, expected to progress further through its fourth-quarter 2026 work programme, should also be watched for any signal that a Slovenian entity, most plausibly Bitstamp given its scale, could be drawn into the first directly-supervised cohort of AMLA around 2028, which would mark a genuine shift from Banka Slovenije-led national supervision to hybrid EU-level oversight for the most significant VASP in Slovenia.

Cumulative analysis

Crypto, Digital Assets, and Financial Innovation - Cumulative Analysis

This baseline cycle establishes the D5 domain for Slovenia around a single structural fact that will likely remain the defining feature of this domain for the foreseeable future: Slovenia is the legal domicile of Bitstamp, a globally significant crypto exchange, which makes the crypto-sector risk profile of the country structurally disproportionate to its size and makes EU-level crypto regulation, principally MiCA, the primary driver of Slovenia-specific D5 developments rather than any purely domestic policy choice.

The most consequential event captured in this baseline is the closure, on 1 July 2026, of the EU-wide MiCA transitional window for legacy-registered crypto-asset service providers. This converts continued EU-facing service for Bitstamp and any other Slovenia-domiciled exchange into a question of full Article 63 authorization rather than legacy national registration, and it is the single largest open confirmation gap in this domain: the post-transition authorization status of Bitstamp has not yet been independently verified, and closing that gap should be the top research priority for the next cycle of this domain.

Running alongside this authorization question is a genuinely positive technical-compliance trajectory: the Recommendation 15 rating of Slovenia, covering new technologies and virtual-asset service providers, was upgraded from Partially Compliant to Largely Compliant in the 2023/2024 MONEYVAL Follow-Up Report, closing a definitional VASP-scope deficiency that had persisted since the 2017 and 2021 assessments. This baseline record treats the technical-compliance improvement and the MiCA authorization question as related but analytically distinct: a strong FATF rating for VASP supervision does not itself confirm that the most significant VASP in Slovenia has completed the separate, EU-wide market-access authorization process.

The baseline also records the extension of the crypto-sector sanctions architecture into Slovenia through the 20th Russia sanctions package of the EU, which introduced a sectoral ban on Russia-based crypto service providers, a genuinely novel sector-level enforcement tool that neither the US nor the UK currently mirrors. Given the crypto-sector footprint of Slovenia, this sector-level tool is of particular relevance and should be tracked closely in future cycles for any sign of enforcement action or further divergence from the entity-by-entity approaches used elsewhere.

Taken together, this baseline establishes the D5 domain of Slovenia as improving on the technical-compliance axis but carrying a live and unresolved authorization-confirmation gap on the market-access axis, with an additional standing exposure to the emerging sector-level crypto-sanctions architecture of the EU. Future cycles should track the resolution of the authorization question above all else, since it is both the most consequential and the most readily confirmable of the open items in this domain.

Outlook

The outlook carried forward from this baseline centres on three markers: confirmation of the post-MiCA-transition authorization status of Bitstamp and any other Slovenia-domiciled CASP, continuing development of the direct-supervision selection criteria of AMLA for high-risk CASPs, and any enforcement or designation activity arising from the sector-level Russia-crypto sanctions tool introduced by the EU 20th package.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

The D6 profile of Slovenia this cycle is narrower than its D1, D2, D3 and D5 counterparts, and it should be read honestly as a watch-status domain rather than one with a dedicated Slovenia-specific RegTech or AI-monitoring development. The material active-defence control point identified this cycle is institutional rather than technological: the emerging supervisory-coordination methodology of AMLA over higher-risk crypto-asset service providers, combined with the AML gatekeeping role of Banka Slovenije now that the MiCA transitional window has closed, together constitute the operative compliance-technology and active-defence mechanism for the crypto-sector laundering and sanctions-evasion exposure of Slovenia. AMLA, operational in Frankfurt since mid-2025 under Chair Bruna Szego, already exercises indirect coordination over Banka Slovenije even though no Slovenian entity has yet been named for direct supervision; this indirect-coordination layer is itself a form of active defence, in the sense that it introduces an EU-level supervisory check on national authorisation and monitoring decisions before any formal direct-supervision mandate exists.

The practical significance of this control point is that the post-1-July-2026 Article 63 authorization decisions of Banka Slovenije for Bitstamp and any other Slovenia-domiciled crypto-asset service provider now function as the primary gatekeeping mechanism determining continued EU-facing service, and the coordination role of AMLA means those decisions are not made in a purely national vacuum. This is a meaningful strengthening of the control architecture relative to the pre-MiCA-transition period, when national legacy registration alone was sufficient for continued operation. At the same time, it should not be overstated: AMLA has not yet named any Slovenian entity for direct supervision, and the current coordination role is exactly that, coordination, not direct oversight authority over its own decisions.

No dedicated Slovenia-specific transaction-monitoring technology, AI-driven screening tool, or RegTech deployment has been identified in the available reporting window this cycle. This is a genuine coverage gap rather than a positive finding of technological stagnation: the native-language annual statistics of the Slovenian financial intelligence unit, UPPD, on suspicious-transaction-report volumes and operational outcomes have not been directly accessed this cycle, meaning any UPPD-specific technology or triage-capability development would not be visible in the current dataset. This gap sits adjacent to, though distinct from, the AMLA and Banka Slovenije control-point finding, and it should be treated as an open research item rather than folded into the watch-status assessment of the domain as a whole.

Three-pillar balance considerations are also relevant here: the Recommendation 32 rating of Slovenia, covering cross-border currency and bearer-negotiable-instrument declaration and disclosure systems, is tracked among the FATF Recommendations most closely tied to active-defence infrastructure, alongside the already-discussed Recommendation 15 and the still-outstanding Recommendation 5 on the terrorist-financing offence. The dataset available this cycle does not surface a CTF-specific technology or active-defence development for Slovenia distinct from the AML and CPF-weighted findings already discussed under D1 and D2, which is itself worth noting given that CTF signals are structurally under-weighted relative to AML enforcement volume across most jurisdictions, including Slovenia.

From an active-defence design perspective, the red-flag indicators populated across the active-scheme inventory for this cycle are instructive as to where compliance-technology investment would have the greatest marginal effect for Slovenian obliged entities: onboarding-stage screening against fabricated-invoice and lax-formation-agent patterns, relevant to the cross-border company-formation network; transaction-monitoring alerts for delayed-freeze-order execution timelines, relevant to the historical NLB-Iran correspondent-banking pattern; and enhanced beneficial-ownership screening for ordinary limited-liability-company forms layered into designated nominee structures, relevant to the Slivnik Kingpin Act case. None of these are new technology deployments confirmed this cycle, they are analytically derived control points based on where the documented cases and schemes of Slovenia indicate exposure concentrates.

Outlook

The clearest forward D6 marker is the further development by AMLA of its supervisory methodology through its work programme expected around the fourth quarter of 2026, and specifically whether that methodology produces concrete direct-supervision selection criteria that could draw a Slovenian entity, most plausibly Bitstamp given its scale, into the first directly-supervised cohort of AMLA around 2028. Direct access to the native-language annual reporting of UPPD would materially improve visibility into any Slovenia-specific compliance-technology development not currently captured in this dataset, and is flagged as a standing collection priority for future cycles. Any future direct evidence of Slovenian obliged entities adopting AI-driven transaction-monitoring or screening technology specifically targeted at these three control points would represent a genuine D6 development rather than the institutional-coordination finding recorded this cycle.

Cumulative analysis

Compliance Technology and Active Defence - Cumulative Analysis

This baseline cycle establishes the D6 domain for Slovenia around an institutional rather than technological control point: the emerging supervisory-coordination role of AMLA over higher-risk crypto-asset service providers, combined with the AML gatekeeping function of Banka Slovenije following the closure of the MiCA transitional window. No dedicated Slovenia-specific RegTech, AI-monitoring, or transaction-screening technology development has been identified at this baseline, and this absence is recorded honestly as a coverage gap rather than folded into an inflated technology narrative: the native-language annual reporting of the Slovenian financial intelligence unit, UPPD, has not been directly accessed this cycle, and closing that gap should be a standing research priority.

The institutional control point established at this baseline has two components. First, AMLA, operational in Frankfurt since mid-2025, already exercises indirect coordination over Banka Slovenije even though no Slovenian entity has yet been named for direct supervision, meaning an EU-level check now exists on national authorisation and monitoring decisions ahead of any formal direct-supervision mandate. Second, the post-MiCA-transition Article 63 authorization decisions of Banka Slovenije for Bitstamp and any other Slovenia-domiciled CASP now function as the primary gatekeeping mechanism determining continued EU-facing crypto-sector service, a materially stronger control architecture than existed under the prior national legacy-registration regime.

This baseline also records a three-pillar balance observation likely to recur across future cycles: CTF-specific technology and active-defence findings are structurally rarer in the available dataset for Slovenia than AML and CPF-weighted findings, and this asymmetry should be corrected for explicitly in future analysis rather than treated as evidence of low CTF risk. The Recommendation 32 rating of Slovenia, covering cross-border currency and bearer-instrument disclosure systems, is the clearest FATF-linked marker of CTF-relevant active-defence infrastructure currently available, and it should be watched alongside Recommendation 5, the sole outstanding FATF gap for Slovenia, for any future rating movement.

Finally, this baseline derives three analytically useful, though not yet confirmed, control points from the documented Slovenian cases surfaced elsewhere in this cycle: onboarding-stage screening for fabricated-invoice and lax-formation-agent patterns, transaction-monitoring alerts for delayed-freeze-order execution timelines, and enhanced beneficial-ownership screening for ordinary limited-liability-company forms layered into designated nominee structures. These are not confirmed technology deployments; they are the logical control-investment priorities implied by where the documented exposure of Slovenia currently concentrates, and future cycles should track whether any Slovenian obliged entity is confirmed to have adopted controls targeting these specific patterns.

Outlook

Future cycles should track three markers against this baseline: whether the supervisory methodology of AMLA, expected to develop further through its fourth-quarter 2026 work programme, produces concrete criteria that could draw a Slovenian entity into its first directly-supervised cohort around 2028; whether direct access to UPPD native-language reporting closes the current visibility gap on Slovenia-specific compliance technology; and whether any Slovenian obliged entity is confirmed to have adopted monitoring or screening technology targeting the three control points identified at this baseline.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
In Force Pending2026-05 · ±quarter

MONEYVAL 5th-round Plenary outcome for Slovenia

Adoption of the 5th-round mutual evaluation report for Slovenia would reset its FATF/MONEYVAL compliance and effectiveness ratings, materially affecting grey-list proximity and standing narrative.
In Force1 Jul 2026 · ±quarter

MiCA transitional period closes for legacy CASPs

Slovenia-domiciled crypto-asset service providers operating under national legacy registration must complete full MiCA Article 63 authorization or cease EU-facing services.
In Force Pending2026-Q4 · ±half_year

AMLA Work Programme / build-out

AMLA, operational in Frankfurt since mid-2025, finalises its first work programme and supervisory methodology.
source not collected
Adopted10 Jul 2027 · ±year

AMLR / 6AMLD application date

The single AML rulebook, the AMLR, becomes directly applicable and 6AMLD transposition deadlines bite across Member States, reducing the discretion previously exercised under the ZPPDFT-2 transposition of AMLD.
Adopted2028 · ±multi_year

AMLA direct supervision of selected obliged entities

AMLA begins direct supervision of a first cohort of high-risk cross-border obliged entities, shifting supervisory perimeter from purely national authorities to a hybrid EU-level regime.
5 dated · 4 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROHigh

EU high-risk third-country expansion and a historical correspondent-banking freeze-delay case sharpen the enhanced due diligence and SAR-timeliness picture for Slovenia this cycle.

The addition of Russia, Bolivia and the British Virgin Islands to the EU high-risk third-country list triggers enhanced due diligence obligations for Slovenian obliged entities transacting with those jurisdictions. The retained NLB correspondent-banking case, where a nine-day delay between a suspicious transaction report and a freeze order allowed funds to move into Russian banks, remains the reference precedent for freeze-timeliness risk. The October 2024 OFAC Kingpin Act designation of a Ljubljana resident tied to two Slovenian investment vehicles is a live screening-relevance data point, and the persistent gap between predicate-offence investigation volume and money-laundering conviction outcomes continues unresolved since the 2017 Mutual Evaluation Report.

4 evidence refs
ComplianceHigh

Three converging EU-level instruments, the high-risk third-country list expansion, the AMLA build-out, and the MiCA authorization deadline, reshape the near-term control-framework agenda for Slovenia.

The EU high-risk third-country list expansion, the operational status of AMLA with its indirect coordination role over Banka Slovenije, the forward AMLR and 6AMLD application timelines, and the closure of the MiCA transitional window all require policy and control-framework attention this cycle. The continuing divergence between the EU and UK high-risk third-country lists creates an additional cross-jurisdictional reconciliation requirement for Slovenian-linked entities with UK counterparties.

6 evidence refs
LegalHigh

The Kingpin Act designation reaching a Slovenian corporate registry and the cross-border company-formation network both carry liability-exposure and enforcement-trajectory relevance.

The October 2024 OFAC Kingpin Act designation of a Ljubljana resident linked to two Slovenian investment vehicles establishes a direct US sanctions nexus with Slovenian corporate structures. The cross-border company-formation laundering network, involving a Slovenian prime ministerial adviser and shell companies across six jurisdictions, represents an active enablement architecture with associated legal and reputational exposure. The historical NLB-Iran correspondent-banking case remains a reference point for institutional liability arising from freeze-order delay.

3 evidence refs
BoardHigh

An open MONEYVAL 5th-round evaluation cycle and a high-profile enabler-jurisdiction case are the two most material governance-level items for Slovenia this cycle.

The strong technical-compliance position of Slovenia, rated largely compliant across all forty FATF Recommendations bar one, sits alongside an unresolved 5th-round MONEYVAL evaluation whose plenary outcome remains unconfirmed. The prime ministerial adviser-linked company-formation network and the Kingpin Act designation both carry reputational exposure at the institutional level, independent of any confirmed domestic prosecution outcome.

4 evidence refs
CTOHigh

Closure of the MiCA transitional window converts the Ljubljana domicile of Bitstamp into a live authorization-gatekeeping exposure for the crypto-asset infrastructure of Slovenia.

With the EU-wide MiCA transitional window for legacy-registered crypto-asset service providers closed as of 1 July 2026, Bitstamp and any other Slovenia-domiciled exchange must complete full Article 63 authorization to continue EU-facing service. This is a direct technical-architecture and platform-continuity question rather than a purely legal one. Separately, the FATF Recommendation 15 rating upgrade to Largely Compliant reflects improved definitional treatment of virtual-asset service providers, relevant to how the crypto exchange infrastructure of Slovenia is technically supervised.

3 evidence refs
RiskHigh

The cross-border company-formation network, the persistent conviction gap, and EU-UK sanctions-list divergence together concentrate exposure in the enabler-jurisdiction and cross-border compliance-friction risk categories.

The six-jurisdiction shell-company network centred on a Slovenian prime ministerial adviser is the clearest concentration-of-exposure signal this cycle. The persistent gap between predicate-offence investigation volume and money-laundering conviction outcomes, unresolved since 2017, is a structural risk-model input rather than a single-cycle event. Divergence between the EU and UK high-risk third-country lists adds a cross-jurisdictional escalation dimension for risk functions monitoring Slovenian-linked counterparty exposure.

3 evidence refs
OperationsHigh

The EU high-risk third-country list expansion and the MiCA authorization deadline require operational screening and monitoring-threshold updates.

The addition of Russia, Bolivia and the British Virgin Islands to the EU high-risk third-country list requires updated enhanced due diligence workflows for Slovenian obliged entities. The closure of the MiCA transitional window requires operational confirmation of authorization status for any Slovenia-domiciled crypto-asset service provider relationship. The continuing divergence between the EU and UK high-risk third-country lists requires dual-list screening workflows for cross-border transactions.

3 evidence refs
AuditHigh

The green-rated beneficial-ownership register and the unresolved conviction gap present a documentation-versus-outcome audit tension for Slovenia this cycle.

The public beneficial-ownership register of Slovenia is independently rated in the top transparency category by Global Witness, indicating strong documentary control-framework performance. However, the persistent gap between predicate-offence investigation volume and money-laundering conviction outcomes, carried unresolved since the 2017 Mutual Evaluation Report, indicates that documentary adequacy has not translated into enforcement effectiveness, a distinction relevant to control-testing scope. The open MONEYVAL 5th-round evaluation cycle is also a relevant audit-calendar item.

4 evidence refs
Decision lens
MLRO

EU high-risk third-country expansion and a historical correspondent-banking freeze-delay case sharpen the enhanced due diligence and SAR-timeliness picture for Slovenia this cycle.

Compliance

Three converging EU-level instruments, the high-risk third-country list expansion, the AMLA build-out, and the MiCA authorization deadline, reshape the near-term control-framework agenda for Slovenia.

Legal

The Kingpin Act designation reaching a Slovenian corporate registry and the cross-border company-formation network both carry liability-exposure and enforcement-trajectory relevance.

Board

An open MONEYVAL 5th-round evaluation cycle and a high-profile enabler-jurisdiction case are the two most material governance-level items for Slovenia this cycle.

CTO

Closure of the MiCA transitional window converts the Ljubljana domicile of Bitstamp into a live authorization-gatekeeping exposure for the crypto-asset infrastructure of Slovenia.

Risk

The cross-border company-formation network, the persistent conviction gap, and EU-UK sanctions-list divergence together concentrate exposure in the enabler-jurisdiction and cross-border compliance-friction risk categories.

Operations

The EU high-risk third-country list expansion and the MiCA authorization deadline require operational screening and monitoring-threshold updates.

Audit

The green-rated beneficial-ownership register and the unresolved conviction gap present a documentation-versus-outcome audit tension for Slovenia this cycle.

Shared evidence: 10 refs
Scenario sketches

AMLA Direct-Supervision Perimeter Expansion and the EU AML Package Transition

Illustrative orientation only: as AMLA continues to build out its supervisory methodology beyond its current indirect-coordination role over national authorities such as Banka Slovenije, a plausible structural trajectory is one in which AMLA direct supervision, layered onto the directly-applicable AMLR and the per-Member-State transposition of 6AMLD, gradually narrows the space in which purely national supervisory discretion can be exercised over cross-border obliged entities. In such a trajectory, evasion architectures that previously relied on exploiting divergent national transposition timelines or supervisory priorities across Member States could face a more harmonised detection surface, while new arbitrage opportunities could emerge at the boundary between directly-supervised and indirectly-coordinated entities. This is an illustrative structural sketch, not a forecast of any specific outcome for Slovenia or any other Member State.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Illustrative Authorization-Gap Window for a Legacy-Registered CASP Post-MiCA Transition

Illustrative orientation only: a legacy-registered crypto-asset service provider that has not completed full Article 63 authorization by the close of the MiCA transitional window could, in principle, face a period of regulatory ambiguity in which continued client-facing activity is neither clearly authorized nor definitively prohibited pending a formal supervisory determination. Such a window, if it were to arise for any Slovenia-domiciled CASP, could in theory be exploited by counterparties seeking to route activity through an entity whose authorization status is unresolved. This is an illustrative structural sketch describing a possible mechanism, not an assertion that any specific Slovenia-domiciled CASP is currently in such a position.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architecturestable
T2 · EU AML Package / AMLAimproving
T3 · FATF Grey Liststable
T4 · Beneficial-Ownership Register Statusstable
T5 · Crypto and Digital-Asset Integrityimproving
T6 · Sanctions Regime Divergencestable
Registers

Enforcement actions

  • Following a May 2023 multinational operation involving Belgium, Germany, Portugal, France, Spain, Romania, Slovenia, Brazil and Panama that saw over 2,700 officers conduct raids and arrest 132 network members, the Reggio Calabria court issued its first judicial decision against 76 defendants who requested a shortened procedure. 21 Oct 2025
  • Per FATF's assessment calendar, Slovenia's next MONEYVAL mutual evaluation on-site assessment was scheduled around late September 2025, opening the 5th-round evaluation cycle against the 2022 FATF Methodology, with plenary discussion of results indicatively scheduled around May 2026. 29 Sep 2025
  • MONEYVAL's most recent adopted Follow-Up Report (published 7 May 2024, at the outer edge of the enforcement window but the most recent adopted decision still governing Slovenia's current standing) re-rated Recommendation 15 (new technologies/VASPs) and Recommendation 32 (cash couriers) from Partially Compliant to Largely Compliant. 7 May 2024

Sanctions changes

  • Commission Delegated Regulation (EU) 2026/46 (adopted 3 December 2025) added Russia to the EU's list of high-risk third countries with strategic AML/CFT deficiencies under Directive (EU) 2015/849, requiring Slovenian obliged entities to apply enhanced due diligence to Russia-linked transactions and customers. 3 Dec 2025
  • Commission Delegated Regulation (EU) 2026/83 (adopted 4 December 2025) added Bolivia and the British Virgin Islands to the EU high-risk third-country list and delisted Burkina Faso, Mali, Mozambique, Nigeria, South Africa and Tanzania, altering the enhanced-due-diligence perimeter applicable to Slovenian obliged entities. 4 Dec 2025
  • HM Treasury's June 2026 Money Laundering Advisory Notice updated the UK's High-Risk Third Country list (MLR reg.33) to track the FATF's 19 June 2026 plenary outcomes; the UK list continues to differ in composition and timing from both the EU delegated-regulation list and the underlying FATF lists, creating cross-jurisdiction compliance friction for firms with both EU and UK nexus, including Slovenian-linked entities transacting with UK counterparties. 22 Jun 2026

Regulatory horizon (register)

  • MiCA transitional period closes for legacy CASPs
  • EU AMLR direct-application date across Slovenia
  • AMLA direct-supervision perimeter build-out
  • MONEYVAL 5th-round Plenary outcome for Slovenia

Active schemes

  • [HIGH] Cross-border company-formation laundering network
  • Correspondent-banking channel used for Iran-linked funds
  • Kingpin Act shell-entity designation reaching Slovenia
  • MiCA transition exposure for Ljubljana-domiciled VASP
Sources
  1. FATF/MONEYVAL
  2. Ministry of Finance, Republic of Slovenia (UPPD)
  3. U.S. Department of the Treasury, OFAC
  4. European Commission (DG FISMA)
  5. HM Treasury
  6. Global Witness
  7. OCCRP
  8. OCCRP
  9. Elliptic
  10. Council of the European Union
  11. FATF
Coverage gaps
Money-laundering prosecutions and convictions in Slovenia re…
Money-laundering prosecutions and convictions in Slovenia remain disproportionately low relative to the volume of investigations into proceeds-generating predicate crimes such as tax evasion, fraud and drug trafficking, a finding first identified in the 2017 MER and not resolved through subsequent follow-up reports.
MONEYVAL's 2021 Follow-Up Report found Slovenia's VASP-relat…
MONEYVAL's 2021 Follow-Up Report found Slovenia's VASP-related measures only Partially Compliant with Recommendation 15 due to deficiencies in the definition of virtual asset service providers, a gap only partially closed (upgraded to Largely Compliant) by the 2023/2024 Follow-Up Report.
The 2017 MER found Slovenia had not undertaken a domestic re…
The 2017 MER found Slovenia had not undertaken a domestic review of the non-profit sector to identify which parts might be at particular risk of terrorist-financing misuse, and no risk-based supervision framework for NPOs was in place at that time.
This baseline could not directly access UPPD's (national FIU…
This baseline could not directly access UPPD's (national FIU) own Slovenian-language annual STR/operational statistics publication within the research window; findings on FIU output rely on multilateral (MONEYVAL/FATF) and investigative secondary sourcing rather than the primary national FIU report itself.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.