What this covers
You already run a risk-based approach. This is about the parts of it that ICPAC and CySEC actually inspect, the categories that override whatever your matrix produces, and the specific places where firms fail monitoring visits.
ICPAC issued the third edition of its Guidance Paper on the Client Risk Based Approach in April 2026, replacing the July 2024 edition. If your methodology was built against the second edition, the six risk areas and the scoring bands are worth re-reading before your next annual review.
Everything below is client-level. Firm-wide risk assessment is a separate obligation with its own ICPAC guidance paper, and the client paper says so explicitly.
Where the obligation actually comes from
The chain matters when a supervisor asks you to justify a design choice.
| Level | Source | What it requires |
|---|---|---|
| Statute | Article 58 of Law 188(I)/2007 | Adequate policies, controls and procedures, proportionate to the nature and size of the obliged entity |
| Statute | Article 58A | Identify and assess ML/TF risk across clients, countries, products, services, transactions and delivery channels. Document it, keep it updated, make it available to the supervisory authority |
| Statute | Article 58B | An independent internal audit function where the size and nature of activities warrant it. The supervisor can impose one |
| Statute | Articles 58C and 58D | Senior management approve the policies. A named board member is responsible for implementation |
| Supervisor | Article 59(4) | Directives issued by your supervisory authority are binding and mandatory, not guidance |
| Supervisor | ICPAC AML/CFT Directive, ICPAC Sanctions Directive | The binding instruments for ICPAC-licensed firms |
| Guidance | ICPAC Client-RBA Guidance Paper | Not binding in itself. It is what the supervisor will measure your methodology against |
Article 59(1) allocates supervision. ICPAC supervises its members, and partnerships and limited companies where the majority of partners, shareholders and directors are ICPAC members, including their trust and company services. CySEC supervises Cyprus Investment Firms and licensed administrative service providers under the Fiduciaries Law, and runs its Risk Based Supervision Framework across its regulated population. The Council of the Cyprus Bar Association supervises advocates and law firms. The Central Bank of Cyprus supervises credit institutions.
If your firm sits on both sides of that line, and many do, you are answering to two supervisors with two directives and two questionnaire cycles.
The six risk areas
The 2026 paper works on six client-level risk areas. The 2024 edition and much off-the-shelf software still work on four.
| Risk area | The question ICPAC frames it as |
|---|---|
| Client risk | What types of clients does the firm service? |
| Service risk | What services does the client require, and could they be used to launder money or finance terrorism? |
| Geographical risk | What countries does the client operate in, reside in, or hold citizenship of? |
| Delivery channel risk | How and by whom was the client introduced? |
| Transaction risk | What are the client’s transactional methods and behaviour? |
| Counterparty risk | What risks are created by the client’s counterparties? |
Transaction risk and counterparty risk are the two that older matrices omit. Counterparty risk in particular carries a hard rule: a client engaging with counterparties subject to international sanctions or related to designated persons scores 5, the maximum, in the paper’s own risk factor table.
The paper is explicit that the factors it lists are a minimum set and not exhaustive. “Firms are required to identify all relevant risk factors/indicators applicable to each business relationship they maintain and adapt their mitigating measures accordingly.” A methodology that only implements the tables is a methodology that has not been thought about.
Scoring, and the scale problem
ICPAC suggests scoring each risk factor 1 to 5, with 1 the lowest risk and 5 the highest, then averaging within each risk area and summing the area scores.
The paper carries two different total-score scales. One reads 17 to 20 High, 9 to 16 Normal, 4 to 8 Low, which is the range for four risk areas. The other, in the due diligence table, reads 20 to 30 High, 10 to 19 Normal, 6 to 9 Low, which is the range for six. Both worked examples in the paper use the six-area scale: Example 1 totals 19 and is classified Normal, Example 2 totals 11 and would be Normal on score alone.
Use the six-area scale, and record in your AML/CFT manual which scale you have adopted and why. A supervisor asking why your matrix produces a given band will accept a documented choice. It will not accept a matrix whose bands do not correspond to its own inputs.
While you are in there: Example 1 in the paper scores one counterparty sub-factor at 6 on a 1 to 5 scale. Do not replicate it.
The mapping to due diligence
| Total score | Risk level | Due diligence | Approval | Suggested review frequency |
|---|---|---|---|---|
| 20 to 30 | High | EDD | Board of Directors | Yearly, with board approval to continue the relationship |
| 10 to 19 | Normal | CDD | MLCO | Every 2 years |
| 6 to 9 | Low | CDD or SDD | MLCO | Every 3 years |
ICPAC marks the monitoring frequencies as suggestions. The due diligence levels are not suggestions once the classification is made, because Articles 63 and 64 of the Law govern simplified and enhanced measures directly.
The four weighting constraints
These are the ones that get tested. When weighting risk factors, the firm must ensure that:
- weighting is not disproportionately influenced by any single factor;
- economic or profit considerations do not influence the risk rating;
- weighting does not produce a matrix in which it is impossible for any business relationship to be classified high risk;
- the provisions of the ICPAC AML/CFT Directive or the Law on situations that always present high risk cannot be overruled by the firm’s weighting.
Constraint three is worth modelling directly. Run your matrix at maximum plausible inputs for a realistic client profile and confirm it can actually reach the high band. A surprising number of matrices cannot.
The categories that override your score
Article 64 of the Law and the ICPAC Directive create classifications that no amount of averaging can displace:
- PEPs, their family members and known close associates. The paper marks a PEP client as “always High Risk, regardless of the overall score”.
- Clients from EU high-risk third countries. The paper attributes this to Article 64, and records that where the country is on the EU list of high-risk jurisdictions the client is always high risk regardless of the overall score.
- Transactions that are complex, unusually large, follow an unusual pattern, or lack apparent economic or lawful purpose.
- Clients for whom a Cyprus Investment Programme application was made, under paragraph 4.5 of the ICPAC AML/CFT Directive. This is ICPAC’s own addition on top of the Law. The Directive extends it: an element of higher client risk should also be allocated where CIP services were provided by another professional, or where citizenship was refused, and where refused the reasons must be documented.
The Directive adds a point on nationality that is easy to get wrong. Where a client holds Cypriot nationality attained through the CIP, it is the origin of the client that goes into the geographical risk assessment, not the acquired nationality.
Note also Article 67(β)(i): you may not rely on third parties established in high-risk third countries for CDD. That is a prohibition, not a risk factor.
Worked example
A client with a low profile on every measurable input, whose beneficial owner is a PEP.
Following ICPAC’s own Example 2:
- Client risk: activity (training centre) 1, beneficial owner (PEP) 5. Average 2.
- Service risk: audit services 2, instructions from the BO directly 2. Average 2.
- Geographical risk: business, place of birth and residence all Cyprus, 1 each. Average 1.
- Delivery channel: no third-party introduction, 1. Average 1.
- Transaction risk: methods 2, complexity 2. Average 2.
- Counterparty risk: status 3, activities 3. Average 3.
- Total: 11. On the six-area scale that is Normal.
The classification is High. The beneficial owner is a PEP, which the Law treats as always high risk, and weighting constraint four means the matrix cannot overrule it. EDD applies, board approval is required, and the relationship is reviewed yearly.
The useful part is what the file has to show: not the score of 11, but the documented reason the score was set aside. A file that records 11 and applies CDD fails. A file that records 11, records the PEP override and applies EDD passes.
Where the compliance officer overrides a manual or automated score in either direction, the paper requires the rationale and the information relied on to be documented and filed.
What the supervisor asks to see
From ICPAC’s Compliance Officers’ Handbook, submissions calendar and reporting rules:
| Obligation | To whom | When |
|---|---|---|
| Consolidated AML/CFT Questionnaire, via the ICPAC RegTek Portal | ICPAC | Annually, 30 June. Mandatory for all firms |
| Annual Compliance Officer’s Report, under paragraph 3.2.1(j) of the AML/CFT Directive | Board or senior management. Not submitted to ICPAC | Annually. Must be readily available at the on-site visit or on request |
| Annual Sanctions Risk Assessment Report, under paragraph 3.2.7 of the Sanctions Directive | Board or senior management. Not submitted | Annually. Same availability requirement |
| Notification of appointment or change of compliance officer | ICPAC | Within 7 days. Failure may attract a predefined penalty of €500 |
| True match report, and sectoral sanctions report | ICPAC | Without delay |
The compliance officer must be a senior management official with the AML/CFT Certification or an equivalent exemption, appointed under ICPAC Regulation 6.700, and must complete at least 10 CPD units annually specialised in compliance, under section 2.700 paragraph 4(9) of the Members Handbook and section 3.1.4 of the AML/CFT Directive.
The client risk assessment policy itself has to be covered in the Annual Compliance Officer’s Report and be available for inspection during on-site monitoring visits. ICPAC runs quality assurance on AML compliance under Regulation 4.602, Quality Assurance for Compliance with AML/CFT and Sanctions.
What non-compliance costs
Article 59(6) of the Law gives supervisory authorities the power to impose an administrative fine of up to €1,000,000 after giving the supervised person the opportunity to be heard. Where the benefit obtained from the breach exceeds that, the fine may be up to twice the benefit. A continuing breach attracts a further fine of up to €1,000 per day.
Automated systems
If you use a scoring engine, the paper is specific about what the supervisor will ask:
- The compliance officer must have sufficient knowledge of the variables and weights built into the system.
- Those variables and weights must be documented in the firm’s AML/CFT manual.
- The compliance officer must have the flexibility to alter pre-set weights.
- A demonstration of this will be requested during the ICPAC monitoring visit.
A vendor matrix whose weights the compliance officer cannot explain or change is a finding waiting to happen. So is a manual that describes a methodology the software does not implement.
ICPAC’s own steer on when automation is needed: manual matrices are acceptable where the firm offers relatively simple services to relatively few clients with similar non-complex characteristics. Automation is expected where there are more clients, particularly non-local ones, and a range of services that may be complex.
What commonly goes wrong
A four-area matrix. Transaction risk and counterparty risk are in the 2026 paper and in Table 2’s client risk assessment template. Matrices built against the 2024 edition are missing two of six inputs and produce totals that do not map to the published bands.
Scoring bands that cannot reach high. Weighting constraint three exists because this happens. Test it before the supervisor does.
Overrides applied but not documented. The classification being right is only half of it. Article 58A requires the assessment to be documented, and the paper requires an override rationale on file. An undocumented correct answer looks the same as a wrong one.
Treating the guidance list of risk factors as exhaustive. The paper says it is a minimum set. A firm with a distinctive client base and no firm-specific factors has not done the work.
Static risk assessments. The paper is blunt that risk assessment is “not a static event of a limited duration”. Periodic review, plus review on material internal or external change, plus reassessment when the client’s pattern of activity changes. Subscribing to sanctions list alerts and screening at regular intervals are named controls, not optional extras.
Confusing the client-level and firm-wide obligations. They are separate assessments with separate cycles. Client-level runs at onboarding and at each review. Firm-wide runs annually and on material change, and consumes the client-level results.
Missing the second limb of the high-risk third country definition. Article 2 of the Law defines a high-risk third country as one identified by the Commission by delegated act and one that the obliged entity itself classifies as high risk under its Article 58A assessment. Your geographical risk methodology has to be capable of producing the second category. If it only reads the EU list, it does not implement the definition.
Letting commercial pressure into the rating. Weighting constraint two is explicit that economic or profit considerations must not influence the risk rating. This is the constraint most likely to be tested by looking at the ratings of your largest clients.
Where to check
Start with the ICPAC Client-RBA guidance paper itself and check the edition date on the cover: first edition March 2019, second July 2024, third April 2026. Then the ICPAC AML/CFT Directive, which is the binding instrument, and the Compliance Officers’ Handbook for the reporting calendar.
ICPAC publishes compliance circulars, specialised technical materials and guidance papers through its Monitoring and Compliance section, and consolidated high-risk country tables through its circulars. Treat the country tables as orientation only. They are accurate on the date of issue and not afterwards.
For the statutory position, read Law 188(I)/2007 in its consolidated form rather than the 2007 text. CyLaw’s amendment history for the Law records more than twenty amending laws and corrections between 2010 and 2026, the most recent being Law 25(I)/2026. Article numbering and lettering in older commentary does not always survive, so check the article you are relying on against the consolidated text rather than a citation.
