Aug 24
/
Evdokia Pitsillidou
A Practical Guide on AML Risk Assessment and Monitoring Program in 2026
about the author
Evdokia, a partner at SALVUS Funds, is actively advising and working on all matters related to licensing, regulatory compliance, and internal audit for investment firms, funds, Electronic Money Institutions (EMI) & Crypto-Asset Services Providers (CASP).
- Member of the Global Institute of Internal Auditors (IIA)
- Member of the Cyprus Investment Funds Association (CIFA)
- Certified Actuarial Analyst (CAA)
- CySEC Advanced Certified Person
- CySEC certified Anti-Money Laundering Compliance Officer (AMLCO)
As global regulatory expectations surrounding anti-money laundering (AML) and combating the financing of terrorism (CFT) become increasingly stringent, financial institutions face growing pressure to elevate their internal governance and compliance structures. Regulators such as the European Union, CySEC, and other supervisory authorities are continuously updating legislative frameworks to address emerging risks posed by sophisticated financial crime techniques. In this evolving environment, organizations are expected not only to comply with baseline legal requirements but to proactively enhance their ability to detect, prevent, and report activities related to money laundering (ML) and terrorist financing (TF).
The modern AML framework must therefore be dynamic, risk-based, and deeply embedded within an institution's operational and strategic processes. It is no longer sufficient to view AML as a box-ticking exercise; rather, it has become a critical component of enterprise-wide risk management. Institutions must demonstrate that they have the appropriate systems, controls, and cultural commitment to mitigate both current and emerging risks.
In this blog post, Evdokia Pitsillidou, Global Chief Risk & Compliance Officer at SALVUS Funds, introduces the key themes covered in the online course “A Practical Guide on AML Risk Assessment and Monitoring Program in 2026", available through the Institute for Professional Excellence platform.
Understanding the Foundations: Money Laundering and Terrorist Financing
Money laundering involves the concealment of the origins of illegally obtained funds, typically executed through three stages: placement, layering, and integration. Placement introduces illicit funds into the financial system, layering obscures the source through complex transactions, and integration reintroduces the funds into the economy appearing legitimate. In contrast, terrorist financing often involves the use of both lawful and unlawful sources to fund illicit acts, with a focus not on profit but on ideology.
Despite differing motivations, both ML and TF share similarities in methods—such as structuring, wire transfers, and use of financial instruments—and typically occur in jurisdictions with weak AML/CFT enforcement. Regulatory bodies like the Cyprus Securities and Exchange Commission (CySEC) provide oversight by issuing directives, monitoring compliance, and using risk-based supervision approaches.
Conducting an AML Risk Assessment: A Strategic Necessity
The AML risk assessment is the cornerstone of an institution’s ability to allocate resources efficiently and monitor ML/TF risks effectively. This evaluation encompasses several dimensions, including customer profiles, geographic risks, delivery channels, and the complexity or transparency of products and services offered.
To ensure effectiveness, the AML risk assessment must be conducted regularly and consider both internal audits and evolving regulatory developments. Priority levels—low, medium, or high—are assigned based on risk exposure, influencing the frequency and intensity of monitoring activities. High-risk areas demand ongoing surveillance and adaptive controls.
A robust AML risk assessment should also feed directly into a broader Business Risk Assessment (BRA), providing a comprehensive view of potential threats to operations, including regulatory, financial, and reputational risks.
Structuring the AML Function for Compliance and Efficiency
The effectiveness of any AML strategy lies in the strength of the AML function itself. Divided across three levels of control, AML responsibilities include business units (first line), the AML function (second line), and internal audit (third line). The AML function must remain independent, permanent, and well-resourced—both in human and IT terms.
Key responsibilities include:
• Developing and enforcing AML policies and procedures.
• Conducting firm-wide AML risk assessments.
• Ensuring compliance with national and EU AML laws.
• Providing regular staff training and regulatory reporting
• Monitoring internal controls and responding to risks and incidents
Leadership roles such as the AML Compliance Officer (AMLCO) and AML Director must be clearly defined, CySEC-certified, and possess in-depth knowledge of both regulation and business operations. Additionally, firms must designate an Alternate AMLCO to ensure continuity during absences.
Driving Effective AML Monitoring Programs
An effective AML monitoring program must reflect the firm’s risk profile and consider changes such as mergers, IT upgrades, or organizational restructuring. It must extend to remedial actions taken in response to AML-related breaches, ensuring the firm remains compliant under scrutiny.
A risk-based approach is central, enabling tailored monitoring tools, appropriate review scopes, and the efficient deployment of resources. Monitoring activities must also be collaborative, engaging various departments to foster a unified approach to financial crime prevention.
Reviewing the AML Inspection Areas
The AML inspection framework includes core areas such as corporate governance, client onboarding, customer verification, KYC documentation, and transaction monitoring. Inspectors assess how well the firm identifies, documents, and manages client risk, especially for high-risk clients or complex structures. Particular attention is given to suspicious transaction reporting, the use of third-party service providers, compliance with international sanctions, and handling of cash deposits exceeding regulatory thresholds. Firms are encouraged to adopt a proactive, well-documented approach and ensure that internal processes align with the AML risk profile and CySEC expectations.
What is “A Practical Guide on AML Risk Assessment and Monitoring Program in 2026” course and what does it include?
The course is designed by SALVUS Funds and delivered by their Global Chief Risk & Compliance Officer, Evdokia Pitsillidou. This course is suited for professionals working at Cyprus Investment Firms (CIF), Crypto-Asset Services Providers (CASP), and other entities regulated by the Cyprus Securities and Exchange Commission (CySEC). Including auditors, lawyers, and risk managers seeking to stay compliant with AML regulations.
The syllabus of the course includes:
• ML, TF & the AML Framework
- What is Money Laundering (ML)?
- The phases/stages of Money Laundering (ML) and examples.
- What is Terrorist Financing (TF)?
- Differences and Similarities between ML and TF
- Supervisory Authority – CySEC
- Powers of the Supervisory Authority
- AML Regulatory Framework
• Anti-Money Laundering (AML) Risk Assessment
- Purpose of the AML Risk Assessment
- Objectives of the AML Risk Assessment
- Influence of AML Risk Assessment
• The Anti-Money Laundering (AML) Function
- Levels of Control
- Responsibilities
- Effectiveness, permanence & independence
- Organizational requirements
- Monitoring obligations
- AML Function – Q&As
• Anti-Money Laundering (AML) Monitoring Program features
- AML Monitoring Program
- Aim & Characteristics
- Type and frequency of monitoring activities
- Tools and methodologies
- AML Report
• Anti-Money Laundering (AML) Inspection areas
- Policies and Procedures
- Methodology
- Inspection Areas
• Good and Bad Practices – Circular C656
- CySEC Circular C656 – Key takeaways
- Consolidated Good Practices
- Common Weaknesses/Deficiencies
- CySEC’s Expectation
The course is delivered through online video recordings and downloadable PDF study material, allowing professionals to learn whenever and wherever it suits them best. Participants can progress at their own pace, revisit topics as needed and reinforce their knowledge through accessible and structured learning resources.
Upon successful completion, participants receive a certificate awarding 5 CPD hours, recognised by CySEC, the Central Bank of Cyprus, and other professional supervisory bodies. The course contributes towards the annual CPD requirements of CySEC Advanced, Basic and AML Certification holders, as well as professionals registered with ICPAC and the Cyprus Bar Association.
The modern AML framework must therefore be dynamic, risk-based, and deeply embedded within an institution's operational and strategic processes. It is no longer sufficient to view AML as a box-ticking exercise; rather, it has become a critical component of enterprise-wide risk management. Institutions must demonstrate that they have the appropriate systems, controls, and cultural commitment to mitigate both current and emerging risks.
In this blog post, Evdokia Pitsillidou, Global Chief Risk & Compliance Officer at SALVUS Funds, introduces the key themes covered in the online course “A Practical Guide on AML Risk Assessment and Monitoring Program in 2026", available through the Institute for Professional Excellence platform.
Understanding the Foundations: Money Laundering and Terrorist Financing
Money laundering involves the concealment of the origins of illegally obtained funds, typically executed through three stages: placement, layering, and integration. Placement introduces illicit funds into the financial system, layering obscures the source through complex transactions, and integration reintroduces the funds into the economy appearing legitimate. In contrast, terrorist financing often involves the use of both lawful and unlawful sources to fund illicit acts, with a focus not on profit but on ideology.
Despite differing motivations, both ML and TF share similarities in methods—such as structuring, wire transfers, and use of financial instruments—and typically occur in jurisdictions with weak AML/CFT enforcement. Regulatory bodies like the Cyprus Securities and Exchange Commission (CySEC) provide oversight by issuing directives, monitoring compliance, and using risk-based supervision approaches.
Conducting an AML Risk Assessment: A Strategic Necessity
The AML risk assessment is the cornerstone of an institution’s ability to allocate resources efficiently and monitor ML/TF risks effectively. This evaluation encompasses several dimensions, including customer profiles, geographic risks, delivery channels, and the complexity or transparency of products and services offered.
To ensure effectiveness, the AML risk assessment must be conducted regularly and consider both internal audits and evolving regulatory developments. Priority levels—low, medium, or high—are assigned based on risk exposure, influencing the frequency and intensity of monitoring activities. High-risk areas demand ongoing surveillance and adaptive controls.
A robust AML risk assessment should also feed directly into a broader Business Risk Assessment (BRA), providing a comprehensive view of potential threats to operations, including regulatory, financial, and reputational risks.
Structuring the AML Function for Compliance and Efficiency
The effectiveness of any AML strategy lies in the strength of the AML function itself. Divided across three levels of control, AML responsibilities include business units (first line), the AML function (second line), and internal audit (third line). The AML function must remain independent, permanent, and well-resourced—both in human and IT terms.
Key responsibilities include:
• Developing and enforcing AML policies and procedures.
• Conducting firm-wide AML risk assessments.
• Ensuring compliance with national and EU AML laws.
• Providing regular staff training and regulatory reporting
• Monitoring internal controls and responding to risks and incidents
Leadership roles such as the AML Compliance Officer (AMLCO) and AML Director must be clearly defined, CySEC-certified, and possess in-depth knowledge of both regulation and business operations. Additionally, firms must designate an Alternate AMLCO to ensure continuity during absences.
Driving Effective AML Monitoring Programs
An effective AML monitoring program must reflect the firm’s risk profile and consider changes such as mergers, IT upgrades, or organizational restructuring. It must extend to remedial actions taken in response to AML-related breaches, ensuring the firm remains compliant under scrutiny.
A risk-based approach is central, enabling tailored monitoring tools, appropriate review scopes, and the efficient deployment of resources. Monitoring activities must also be collaborative, engaging various departments to foster a unified approach to financial crime prevention.
Reviewing the AML Inspection Areas
The AML inspection framework includes core areas such as corporate governance, client onboarding, customer verification, KYC documentation, and transaction monitoring. Inspectors assess how well the firm identifies, documents, and manages client risk, especially for high-risk clients or complex structures. Particular attention is given to suspicious transaction reporting, the use of third-party service providers, compliance with international sanctions, and handling of cash deposits exceeding regulatory thresholds. Firms are encouraged to adopt a proactive, well-documented approach and ensure that internal processes align with the AML risk profile and CySEC expectations.
What is “A Practical Guide on AML Risk Assessment and Monitoring Program in 2026” course and what does it include?
The course is designed by SALVUS Funds and delivered by their Global Chief Risk & Compliance Officer, Evdokia Pitsillidou. This course is suited for professionals working at Cyprus Investment Firms (CIF), Crypto-Asset Services Providers (CASP), and other entities regulated by the Cyprus Securities and Exchange Commission (CySEC). Including auditors, lawyers, and risk managers seeking to stay compliant with AML regulations.
The syllabus of the course includes:
• ML, TF & the AML Framework
- What is Money Laundering (ML)?
- The phases/stages of Money Laundering (ML) and examples.
- What is Terrorist Financing (TF)?
- Differences and Similarities between ML and TF
- Supervisory Authority – CySEC
- Powers of the Supervisory Authority
- AML Regulatory Framework
• Anti-Money Laundering (AML) Risk Assessment
- Purpose of the AML Risk Assessment
- Objectives of the AML Risk Assessment
- Influence of AML Risk Assessment
• The Anti-Money Laundering (AML) Function
- Levels of Control
- Responsibilities
- Effectiveness, permanence & independence
- Organizational requirements
- Monitoring obligations
- AML Function – Q&As
• Anti-Money Laundering (AML) Monitoring Program features
- AML Monitoring Program
- Aim & Characteristics
- Type and frequency of monitoring activities
- Tools and methodologies
- AML Report
• Anti-Money Laundering (AML) Inspection areas
- Policies and Procedures
- Methodology
- Inspection Areas
• Good and Bad Practices – Circular C656
- CySEC Circular C656 – Key takeaways
- Consolidated Good Practices
- Common Weaknesses/Deficiencies
- CySEC’s Expectation
The course is delivered through online video recordings and downloadable PDF study material, allowing professionals to learn whenever and wherever it suits them best. Participants can progress at their own pace, revisit topics as needed and reinforce their knowledge through accessible and structured learning resources.
Upon successful completion, participants receive a certificate awarding 5 CPD hours, recognised by CySEC, the Central Bank of Cyprus, and other professional supervisory bodies. The course contributes towards the annual CPD requirements of CySEC Advanced, Basic and AML Certification holders, as well as professionals registered with ICPAC and the Cyprus Bar Association.
Get in touch
If you have any questions about Evdokia's course or any other questions related to your training requirements, please contact us; we would love to help.
If you have any questions about Evdokia's course or any other questions related to your training requirements, please contact us; we would love to help.
From all of us at IforPE, the Institute for Professional Excellence,
Ancora Imparo
Ancora Imparo
#1 for CySEC, CBC, ICPAC & CBA CPD education
The Institute for Professional Excellence (IforPE)
Copyright © 2019-2026
The Institute for Professional Excellence (IforPE)
Copyright © 2019-2026
navigate
The Institute for Professional Excellence is protected under a registered European trade mark. The figurative trade mark registration number is 018854840. This trade mark is protected under the European Union's legislation.
