AML/CFT Obligations: Regulated Entities, Due Diligence and Reporting to TRACFIN
The fight against money laundering and terrorist financing (AML/CFT) requires covered professionals to implement a comprehensive framework: risk classification, due diligence at the outset of a business relationship and throughout its duration, and reporting of suspicious transactions to TRACFIN. This guide clarifies who is subject to these obligations and what concrete requirements follow.
Legal Framework for AML/CFT in France
The French AML/CFT framework is codified in Articles L. 561-1 et seq. of the Monetary and Financial Code, transposing the European anti-money laundering directives. It is based on a risk-based approach: each regulated entity must map its risks, adjust the level of its vigilance, and establish internal procedures. Oversight is provided by the ACPR for the banking and insurance sector, while TRACFIN, the French financial intelligence unit, receives and processes reports of suspicious activity. The European anti-money laundering legislative package adopted in 2024, which establishes the European Anti-Money Laundering Authority (AMLA), will strengthen harmonization across the Union as the authority becomes fully operational.
To move from theory to practice, discover the Certyneo electronic signature solution and its offer dedicated to your sector — eIDAS compliant, no installation required.
- Monetary and Financial Code (art. L. 561-1 et seq.): scope of regulated entities and due diligence obligations.
- Risk-based approach: classification, internal procedures and proportionate due diligence.
- TRACFIN: suspicious activity reporting and systematic information disclosure.
- ACPR: supervision and sanctioning powers for the banking and insurance sector; AMLA at EU level.
Components of an AML/CFT Framework
Steps for implementing due diligence
- 1
Risk assessment
Establish a risk map for money laundering and terrorism financing based on clientele, products and channels.
- 2
Due diligence at the outset of a business relationship
Identify and verify the customer (KYC/KYB), understand the purpose of the relationship and calibrate it according to the risk level.
- 3
Ongoing due diligence
Monitor transactions, update customer knowledge and apply enhanced due diligence in case of high risk.
- 4
Reporting and record-keeping
Report any suspicious transaction to TRACFIN, without informing the customer, and retain evidence for five years.
Frequently asked questions
- Who is subject to AML-CFT regulations?
- In particular banks, payment institutions, insurers, asset management companies, but also non-financial professions such as notaries, lawyers, chartered accountants, real estate agents or digital asset service providers, each according to the procedures provided by law.
- What is the risk-based approach?
- It is the principle according to which the intensity of due diligence must be proportionate to the risk. A low-risk customer is subject to simplified due diligence, a high-risk customer (PEP, high-risk country) to enhanced due diligence.
- What is a suspicious transaction report to TRACFIN?
- It is the reporting to the financial intelligence unit of a sum or transaction that is suspected of being related to money laundering or terrorism financing. It is confidential: it is prohibited to inform the customer concerned.
- What is the role of the ACPR?
- The Prudential Supervision and Resolution Authority supervises organizations in the banking-insurance sector, monitors the effectiveness of their AML-CFT framework and may impose sanctions in case of breach.
- What sanctions apply in case of breach?
- Breaches expose organizations to disciplinary and financial sanctions imposed by the ACPR, which can reach substantial amounts, as well as criminal penalties for underlying money laundering offenses.
Related guides and solutions
Explore the related resources from our electronic signature hub.