Skip to main content
Certyneo
AML/CFT

AML/CFT Obligations: Regulated Entities, Due Diligence and Reporting to TRACFIN

The fight against money laundering and terrorist financing (AML/CFT) requires covered professionals to implement a comprehensive framework: risk classification, due diligence at the outset of a business relationship and throughout its duration, and reporting of suspicious transactions to TRACFIN. This guide clarifies who is subject to these obligations and what concrete requirements follow.

Updated on

Legal Framework for AML/CFT in France

The French AML/CFT framework is codified in Articles L. 561-1 et seq. of the Monetary and Financial Code, transposing the European anti-money laundering directives. It is based on a risk-based approach: each regulated entity must map its risks, adjust the level of its vigilance, and establish internal procedures. Oversight is provided by the ACPR for the banking and insurance sector, while TRACFIN, the French financial intelligence unit, receives and processes reports of suspicious activity. The European anti-money laundering legislative package adopted in 2024, which establishes the European Anti-Money Laundering Authority (AMLA), will strengthen harmonization across the Union as the authority becomes fully operational.

To move from theory to practice, discover the Certyneo electronic signature solution and its offer dedicated to your sector — eIDAS compliant, no installation required.

  • Monetary and Financial Code (art. L. 561-1 et seq.): scope of regulated entities and due diligence obligations.
  • Risk-based approach: classification, internal procedures and proportionate due diligence.
  • TRACFIN: suspicious activity reporting and systematic information disclosure.
  • ACPR: supervision and sanctioning powers for the banking and insurance sector; AMLA at EU level.

Components of an AML/CFT Framework

Risk classification (mapping) specific to the business and clientele.
Written internal procedures and designation of an AML/CFT officer and a TRACFIN reporting officer.
Client knowledge file (KYC/KYB) documented and kept up to date.
Transaction monitoring system and anomaly detection mechanism.
Register of suspicious activity reports and TRACFIN requests.
Employee training and awareness program.

Steps for implementing due diligence

  1. 1

    Risk assessment

    Establish a risk map for money laundering and terrorism financing based on clientele, products and channels.

  2. 2

    Due diligence at the outset of a business relationship

    Identify and verify the customer (KYC/KYB), understand the purpose of the relationship and calibrate it according to the risk level.

  3. 3

    Ongoing due diligence

    Monitor transactions, update customer knowledge and apply enhanced due diligence in case of high risk.

  4. 4

    Reporting and record-keeping

    Report any suspicious transaction to TRACFIN, without informing the customer, and retain evidence for five years.

Frequently asked questions

Who is subject to AML-CFT regulations?
In particular banks, payment institutions, insurers, asset management companies, but also non-financial professions such as notaries, lawyers, chartered accountants, real estate agents or digital asset service providers, each according to the procedures provided by law.
What is the risk-based approach?
It is the principle according to which the intensity of due diligence must be proportionate to the risk. A low-risk customer is subject to simplified due diligence, a high-risk customer (PEP, high-risk country) to enhanced due diligence.
What is a suspicious transaction report to TRACFIN?
It is the reporting to the financial intelligence unit of a sum or transaction that is suspected of being related to money laundering or terrorism financing. It is confidential: it is prohibited to inform the customer concerned.
What is the role of the ACPR?
The Prudential Supervision and Resolution Authority supervises organizations in the banking-insurance sector, monitors the effectiveness of their AML-CFT framework and may impose sanctions in case of breach.
What sanctions apply in case of breach?
Breaches expose organizations to disciplinary and financial sanctions imposed by the ACPR, which can reach substantial amounts, as well as criminal penalties for underlying money laundering offenses.
Electronic signature guide · Banking & insurance solutions · Understanding the eIDAS regulation

Related guides and solutions

Explore the related resources from our electronic signature hub.

Equip your AML/CFT compliance

Document customer knowledge, trace your controls and electronically sign your relationship initiation files.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.