Un primo orientamento chiaro e immediato sulle tue esigenze fiscali, societarie e professionali.
Studio Ponchio Academy · 2026 pathway
Twenty-three chapters in three levels to understand why the law requires a chartered accountant to know their client, how customer due diligence actually works, and what obligations remain with the Firm over time — built on Legislative Decree 231/2007 (the Italian AML Decree) and the CNDCEC Technical Rules of 16 January 2025, with a complete guided case at the end.
AML pathway
This pathway does not replace the operational tool the Firm uses to collect and verify client data — that remains a separate application, explained to those who use it when needed. Here the aim is to provide the framework: why the law requires it, how the beneficial owner is identified, when enhanced due diligence applies, what is retained and for how long, and what the real consequences of non-compliance are. The first level is written in a register a client could follow too, if curious about why they are asked for a document or the name of whoever controls their company; the next two levels go into the operational detail and are addressed to the Firm's staff.
The pathway
The legal framework, who is subject to the obligations, the stages of customer due diligence in summary — accessible to a curious client too.
02Identification, the beneficial owner, politically exposed persons, levels of due diligence, reliance on third parties.
03Record-keeping, ongoing monitoring, suspicious transaction reporting, sanctions, a complete guided case.
The legal framework, who is subject to the obligations, the stages of customer due diligence in summary — accessible to a curious client wondering why the Firm asks for certain data.
Level 1 · Chapter 01
Anyone walking into a firm of chartered accountants for a routine matter does not expect to have to produce identification and answer questions about their own business. The most common reaction is not hostility but surprise: what does the accountant have to do with money laundering. The answer lies in the way the European legislator, and behind it the national legislator, chose to tackle the problem. Rather than leaving it solely to the judiciary and law enforcement, who intervene after the fact, the legislator drew in those who see the money pass through beforehand: banks, financial intermediaries, and the professionals who assist businesses and individuals in their economic transactions. D.Lgs. 231/2007 thus builds a network of obliged entities, and within that network the chartered accountant occupies a precise position, named expressly by the law (Article 3, paragraph 4, letter a). Everything else follows from that position: the questions, the documents, the record-keeping, the training of staff. It is not zealousness on the part of the Firm, nor suspicion of the individual client, and it is not even a practice that the professional may adjust at will: it is a statutory obligation, with content that is largely predetermined.
The rule is preventive, not punitive, and this distinction changes the meaning of every question the client is asked. The chartered accountant does not investigate, accuse or judge: they gather and verify information, assess it according to risk-based criteria, and keep a record of what they have done. If a suspicion emerges, that assessment does not turn into an accusation but into a report to an administrative authority, which is a different matter from a criminal complaint. The underlying premise is that money of illicit origin, to become usable, must sooner or later pass through a formally ordinary transaction — a capital contribution, a transfer of business, a property purchase, a shareholder loan — and that at that point a diffuse, documented control is more effective than a subsequent investigation. Hence the choice to trigger the obligation at the moment the engagement is accepted rather than when a monetary threshold is exceeded: what matters is not the value of the engagement, but the fact that the professional enters into a stable relationship with that client.
Certain activities fall outside the scope, and it is worth saying so at once to avoid the impression of an indiscriminate obligation. Customer due diligence does not apply to the mere preparation and filing of tax returns, nor to payroll administration tasks under Law 12/1979 (Article 17, paragraph 7, D.Lgs. 231/2007). This exclusion is narrower than it appears: it covers purely executory activity, not the advisory work that often accompanies it, and it does not cover the professional relationship as a whole when that relationship includes other services too. Even where the exclusion applies, however, the duty of attention is not entirely switched off: a suspicion, should one arise, remains relevant in its own right (Article 17, paragraph 2).
Level 1 · Chapter 02
The three concepts are almost always mentioned together, as though they formed a single block, and this creates confusion. It is worth separating them, because they respond to different logics and demand different attention. Money laundering is a problem of origin: there is a predicate offence that has generated money or assets, and there is a need to erase the trace of that origin. The launderer does not profit from the original offence — they kept out of that — but makes usable what the offence produced. Self-laundering shifts the centre of gravity: the perpetrator of the predicate offence and the person reinvesting the proceeds are one and the same. It is a relatively recent concept in the Italian legal system and it has changed the perception of risk within professional firms, because it has made criminally relevant the reinvestment of resources originating even from tax offences into perfectly normal economic activities. Terrorist financing, finally, reverses the perspective: the money may be clean, and what qualifies the conduct is where it ends up and what it is used for. These are three distinct phenomena that the legislator chose to counter with a single prevention framework, and it is this legislative technique that makes them appear as one and the same thing.
Prevention concerns not only those who move money, but also those who give legal form to transactions. This is the aspect most easily overlooked. A bank sees the financial flow and little else; the chartered accountant sees the structure: who enters a company and with what contribution, how a shareholder loan is justified, why a loss-making business continues to receive funds, what economic rationale underpins a transfer between related parties. The professional, in other words, has access to the rationale behind the transaction, not merely to its amount. This is why European law has progressively extended the obligations to accounting professionals, and why the assessment required is never purely quantitative. The relevant question is not how much the transaction is worth, but whether it makes economic sense consistent with what is known about the client.
One point deserves to be stated explicitly, because it affects how staff experience this work: it is not the Firm's task to establish whether an offence has been committed. It has neither the tools nor the power to do so, and to presume otherwise would be unfair to the client. The task is to gather adequate information, assess its consistency, and keep a documented record of that assessment. However, precisely because the assessment is not a judgement, it cannot be a mere formality either: a file compiled without understanding what the client actually does protects no one, neither the client nor the Firm.
Level 1 · Chapter 03
The risk-based approach is the principle underpinning the entire framework, and at the same time the one clients find hardest to accept, because it appears to introduce unequal treatment. In reality it does the opposite of what it seems: it prevents everyone from being asked for everything, and concentrates scrutiny where there are genuinely more variables to understand. The legislator did not draw up a closed list of documents to collect, applicable to all; it imposed a method, requiring the obliged entity to analyse and assess the risks to which its own activity is exposed, to formalise that assessment and keep it updated over time (Article 15, D.Lgs. 231/2007), and then to adopt procedures consistent with that analysis (Article 16). It follows that the Firm must be able to explain, if asked, not only what it requested from the client, but why it requested those particular things from that particular client. The rationale is part of the compliance obligation, not an afterthought: a risk rating assigned without traceable criteria is just as indefensible as missing information.
Risk is assessed by looking at the client and the transaction together, never at either in isolation. What matters are the client's characteristics — its legal nature, the complexity of its ownership structure, the sector, the geographic area in which it operates — and the characteristics of the service requested, because the same person may approach the Firm for a straightforward routine matter or for an extraordinary transaction that opens up many more questions. A client known for years is not, for that reason alone, a low-risk client in every circumstance: if the nature of the engagement changes, so does the exposure. This is why the profile is not a label fixed to the client record once and for all, but the outcome of a judgement that accompanies the relationship and must be reviewed whenever something occurs that warrants it: a change in the ownership structure, entry into a new market, a transaction out of scale compared with the usual size of the business.
It should be said honestly that this method leaves room for judgement, and that room for judgement means debatable decisions. That is the price of a regime that has abandoned automatic rules. However, the margin is not arbitrary: precisely because the assessment is discretionary, the law requires it to be documented, and documentation is what distinguishes a professional judgement from an omission. In the event of an inspection, the Firm is not required to have guessed correctly, but to be able to show what elements its reasoning was based on.
Level 1 · Chapter 04
Customer due diligence is often described as a form-filling exercise, and this is the surest way to do it badly. Within the structure of the law, it is instead a fact-finding process comprising four distinct elements, listed clearly: identification of the client and verification of their identity, identification of the beneficial owner, obtaining information on the purpose and intended nature of the service, and ongoing monitoring throughout the relationship (Article 18, paragraph 1, D.Lgs. 231/2007). The first three are concentrated at the outset; the fourth runs through the entire relationship and is the part most exposed to being overlooked, because it has no visible deadline and does not, in itself, produce a document to be signed. The overall purpose is to build, at the start, a coherent picture of the client and of what they are asking of the Firm, and then to verify over time that what happens is consistent with that picture. This chapter is confined to the overview: the practical way of gathering each piece of information, the particular cases and the records to be kept are matters for the subsequent levels.
Ongoing monitoring is the stage that distinguishes a genuine compliance exercise from an archive of forms. It is also the stage that explains why, years later, the Firm goes back to ask a client it considers well established for updated information. The professional relationship is not static: shareholders change, the corporate purpose changes, relationships with new counterparties open up, the business grows or contracts. A file that photographs the situation on the day the engagement was accepted, and is never touched again, describes a client who, quite simply, no longer exists in that form. The law expressly requires ongoing monitoring throughout the relationship (Article 18, paragraph 1, letter d), and this entails two things at once: verifying that transactions are consistent with what is known about the client and their activity, and keeping the data and information originally gathered up to date.
One final clarification, useful for preventing a common misunderstanding. The four stages cannot be scaled down on account of trust: personal familiarity with the client, however long-standing and solid, does not substitute for identity verification or for the identification of the beneficial owner. What risk calibrates is the depth of the scrutiny and the frequency of review, not the presence of the four elements. However, it must be acknowledged that the practical application of some of them — in particular, the identification of the beneficial owner in complex ownership structures — presents interpretive issues that are not entirely settled, and the subsequent levels of this course address that point.
Level 1 · Chapter 05
When a client hands over an identity document, states who controls their company and explains where the funds used in a transaction come from, the question that arises — legitimately — is not only why they are being asked, but what will become of that information. It is a question that deserves a precise answer, because AML regulation is, by its nature, a regime that produces a concentration of sensitive data in the hands of the professional. The first safeguard concerns purpose: the information is collected to fulfil a statutory obligation, may be used only for the purposes of that obligation, and cannot be used for other purposes. The second concerns access: within the Firm, not everyone sees everything, and handling is restricted to those working on the engagement. The third concerns the recipient: outside the Firm, the data may be disclosed only to authorities entitled to receive it, in the exercise of their powers, and to no one else. These safeguards apply all the more strictly given how much the professional relationship is, by its nature, a relationship of trust.
Responsibility for compliance rests with the professional, even where the practical work is entrusted to a member of staff. Internal organisation may well provide for the collection of documents, their retention and periodic updating to be handled by dedicated staff — this is normal and, in larger firms, unavoidable — but the assessment that gives meaning to that material remains a professional act that cannot, in substance, be delegated. This has two practical consequences, opposite in direction and equally important. On the one hand, whoever carries out the work in practice must be put in a position to understand what they are doing: hence the obligation to provide ongoing training programmes (Article 16, paragraph 3, D.Lgs. 231/2007), which is not a formal requirement but the condition that makes delegation function. On the other hand, a member of staff who comes across something they cannot place should not try to resolve it themselves: it must be brought to the professional, whose task it is to assess it.
It should be added that this arrangement is not left to the self-discipline of the individual firm. The law assigns to the self-regulatory bodies — the National Council of Chartered Accountants and Accounting Experts (CNDCEC) and the local professional boards — the task of promoting and monitoring compliance with the obligations by their members, together with responsibility for their training and continuing education (Article 11, D.Lgs. 231/2007), as well as the adoption of the Technical Rules to which members must conform (Article 11, paragraph 2). The Technical Rules currently in force, dated 16 January 2025, are the operational reference on which this training course has been built. For the client, the point of all this is simple: the procedures they encounter are not an invention of the Firm, nor are they left to the Firm's discretion.
Level 1 · Chapter 06
The most delicate part of this subject is not technical: it is a matter of communication. The questions a client is asked when a file is opened are perceived as a request from the Firm, and as such as something negotiable — one might ask to skip it, to postpone it, to settle for a verbal answer. It is precisely here that clarity matters, because the legal structure is different from how it appears. The law does not merely impose obligations on the professional: it imposes them on the client too. It is the client who must provide, in writing and on their own responsibility, the information necessary and up to date to allow customer due diligence (Article 22, D.Lgs. 231/2007). The professional, in other words, is not asserting a claim of their own and has no power to waive it: they are asking the client to fulfil a duty the law places directly upon them. Explaining it in these terms, without emphasis and without a defensive tone, is generally enough to defuse resistance, because it moves the conversation from the ground of personal trust to the far simpler ground of the applicable law.
On the beneficial owner, the law has provided for a consequence that touches directly on the life of the company, and not only on the relationship with the Firm. A shareholder who unjustifiably refuses to provide the information necessary to identify the beneficial owner cannot exercise their voting rights, and any resolutions passed with their decisive vote may be challenged (Article 22, paragraph 3, D.Lgs. 231/2007). This is a provision rarely known before it is explained, and it has an immediate clarifying effect: a refusal does not merely create a problem in the relationship with the professional, but a potential flaw in the decisions of the shareholders' meeting, with consequences that fall on the company and on the other shareholders. No one is using it as a threat — that is not the spirit of it — but staying silent about it would leave the client unaware of a consequence that concerns them very directly.
The right way to present these requests, then, is also the most sober one: state what is being asked, why the law requires it, and what will become of the information. No request is arbitrary, none is negotiable out of goodwill, and none serves purposes other than the one for which it is made. However, it must be acknowledged that certain lines of enquiry may, in a specific case, appear disproportionate to the client; when that happens, the right response is not to insist on the form, but to explain the criterion by which that particular piece of information was deemed necessary.
Identifying the natural person and the entity, the beneficial owner, politically exposed persons, the purpose of the engagement, levels of due diligence, reliance on third parties.
Level 2 · Chapter 07
There is an understandable temptation, when beginning to work on AML compliance, to start with the first file on the desk: take the client, identify them, assign a risk profile, file it away. The Decree reasons in the opposite direction. Before even looking at clients one by one, it requires the Firm to look at itself and ask what risks it is exposed to given how it is structured: what services it provides, what type of clientele it habitually works with, through what channels new engagements arrive, in what territorial context it operates (Article 15, D.Lgs. 231/2007). This is an assessment of the organisation, not of individuals. A firm that mainly handles tax returns for employees and small tradespeople known for twenty years has a different exposure profile from one that regularly assists extraordinary transactions, corporate vehicles with articulated ownership chains, or non-resident clients. It is not a question of professional merit: it is a question of where the risk is concentrated. The practical significance of this step is that everything that follows — internal procedures, controls, staff training, the level of scrutiny required to open a file — derives from it, and without this foundation remains arbitrary.
The self-assessment is not a document written once and filed away. Article 15 requires it to be documented and periodically updated, and paragraph 4 specifies that it must be made available to the authorities and to the self-regulatory bodies when requested at an inspection. Two practical consequences follow, and it is worth fixing them from the outset. The first is that the document must exist in written, dated and retrievable form: at an inspection, what is discussed is not what was thought, but what was written. The second is that updating must be scheduled and not left to goodwill. When the Firm opens a new area of activity, when the composition of its portfolio changes significantly, when staffing changes or new client-acquisition tools are introduced, the document must be revisited and, if necessary, revised. Even an explicit confirmation that nothing has changed has value, provided it is dated: it shows that the periodic review was actually carried out and not simply omitted.
On the organisational point, the Technical Rules approved by the CNDCEC on 16 January 2025 and circulated with Notice No. 6/2025 clarified an issue that had created uncertainty in the practice of associated firms: the self-assessment may be conducted at the level of a professional partnership (STP) or professional association, with a single document covering the organisation as a whole, where procedures, safeguards and information systems are shared. This is a reasonable simplification, since organisational risk is by definition a matter for the organisation. It remains the case, however, that the professional engagement is accepted by the individual professional and that assessments of the individual client remain theirs. To support this work, the National Council has prepared sample documentation — the AV.0-AV.7 templates, realigned and circulated with Notice No. 57/2026 of 26 March 2026 — in which template AV.0 is dedicated precisely to the Firm's self-assessment. It is worth reminding junior colleagues that these templates are not mandatory: they are a framework for reasoning, and using them without having understood them produces a file that is formally tidy and substantively empty. However, in the absence of an alternative format designed with equal care, adopting them is the more prudent choice.
Level 2 · Chapter 08
Identifying a natural person is the requirement that seems most straightforward and that, at inspection, most often generates findings — almost always for the same reason: the step was taken without fixing the evidence of it. The Decree requires the client to be identified and their identity verified on the basis of documents, data or information obtained from a reliable and independent source (Article 18, paragraph 1, letter a, D.Lgs. 231/2007), and then regulates the methods by which this check may be carried out (Article 19). In the practice of a firm, this means that when a client presents themselves for the first time, the document is examined, its validity is checked, the photograph is compared with the person present, and the details are recorded. New staff tend to consider recording the details superfluous once a copy of the document has been obtained: this is a mistake in approach. The copy proves that a document exists; the record proves that the document was examined, on a given date, by a specific person at the Firm. These are two different pieces of information, and at inspection both are needed.
The minimum data is not a bureaucratic formality: it is what makes the file reconstructible years later. First and last name, place and date of birth, residence or domicile, tax code where assigned, complete document details. The tax code deserves particular attention, because it is the only element that allows two people with the same name to be reliably distinguished and links the file to all other engagements at the Firm. On acceptable documents, the practical rule is that of valid identity documents issued by a public authority, bearing a photograph: identity card, passport, driving licence, and the equivalent documents provided for under the general rules on administrative documentation. One point that is often lost in the rush should be added: the document must be examined, not merely photocopied. If the photograph is not consistent with the person, if the dates are inconsistent, if the document shows obvious anomalies, the file is not opened and the matter is referred to the professional in charge. Identification is not a mechanical step; it is the first point at which the Firm exercises judgement.
Particular cases are those in which staff must slow down. For a minor, the client is the minor and their identifying data must be obtained to the extent available given their age; the person accepting the engagement, however, is the parent exercising parental responsibility or the guardian, who must be identified with a valid document and whose authority to act must be evidenced. For a foreign national, the typical reference is the passport, supplemented by the residence permit or card where it exists and by the tax code issued in Italy; for EU citizens, the identity document issued by their home state may be used, provided it allows for equivalent identification and is currently valid. Where the document is drawn up in characters or a language that do not allow for a reliable reading, it is advisable to obtain a translation and to note this in the file. In every case, the general principle applies: whoever presents themselves in the name and on behalf of another must be personally identified, and their authority to act must be verified against a document, not against their own statement. However, none of these precautions replaces genuine attention to the individual case: the list of recurring scenarios helps, but does not exhaust the situations that arise at the front desk.
Level 2 · Chapter 09
With a corporate client, the compliance work splits in two, and the difficulty almost always arises because the two levels are conflated. On one hand there is the entity, which is the client: its identifying data must be obtained and verified against a reliable and independent source (Article 18, paragraph 1, letter a, D.Lgs. 231/2007). On the other hand there is the natural person who presents themselves at the Firm claiming to act for the entity: that person must be personally identified using the same methods as for a natural-person client (Article 19), and it must also be verified that they genuinely have the power to bind the company. Staff who obtain the register extract and stop there have completed half the work; those who identify the director but do not obtain the extract have completed the other half. The file is in order only when both levels are documented and consistent with each other, that is, when the comparison shows that the person identified is the same as the one the corporate instruments indicate as authorised. It is a check of correspondence, not merely an exercise in document collection.
The company register extract is the ordinary source, but it must be read, not merely filed. An up-to-date ordinary extract states the legal form, registered office, capital, ownership structure where registered, the directors in office and the nature of their appointment, and it reports powers to the extent that they have been registered. It is precisely the grey areas that call for attention: appointments resolved but not yet registered, which must be checked against the minutes of the shareholders' meeting; delegations internal to the board of directors, which appear in the board minutes and not always in the extract; limits on value or subject matter that the articles of association place on a managing director's authority; special powers of attorney granted to employees or third parties, the instrument for which must be obtained. The date of the extract must also be checked: a document extracted two years earlier does not describe the current situation, and in verifying the ownership structure and the governing bodies, the snapshot must be taken as at the moment the relationship is opened. For entities not registered with the Companies Register, the reasoning is identical but the source changes: deed of incorporation, current articles of association, minutes appointing the officers in office and, where it exists, registration in the register held by the competent authority.
The question that in practice decides everything remains: who signs? The correct answer is almost never the first one offered. It happens that the reference shareholder presents themselves without holding any office, or the external adviser who has followed the company for years, or a family member of the director. None of these persons, absent an instrument conferring the authority on them, has standing to accept the engagement. The engagement letter must be signed by whoever holds the power of representation under the articles of association and the corporate instruments, and the file must retain a record of the document evidencing that power. It is worth adding a consideration that goes beyond mere formality: the person who presents themselves and the way authority is organised are already useful pieces of information for assessing the relationship. A structure in which the actual decision-maker never appears in the corporate instruments is a fact the professional needs to be able to read, and for it to be readable, staff must have recorded it. However, the anomaly is to be recorded and passed on, not interpreted independently at the point of intake.
Level 2 · Chapter 10
Remote identification is the point at which AML regulation meets the way firms actually work. The client who lives in another province, the one operating abroad, the one who simply has no time to come in: these are ordinary situations and the law does not ignore them. Article 19 of D.Lgs. 231/2007 indeed allows the identity check to take place even without the client's physical presence, provided identification is carried out through adequate technical safeguards. The wording deserves close reading, because it does not say that less can be done remotely: it says it can be done differently, provided that method offers a guarantee comparable to direct recognition. The underlying reasoning is straightforward. When the client is in front of us, the guarantee lies in the fact that a member of the Firm has simultaneously seen the person and their document and has confirmed the match. Remotely, that confirmation is missing, and it must be replaced by a technical element performing the same function: reliably linking an already-established identity to the transaction being carried out.
The test is not the channel used, but the strength of the evidence that remains. The tools recognised by the legal system as suitable — SPID, electronic identity card, digital signature or qualified electronic signature, and more generally digital identity systems that provide an equivalent level of assurance — all share the same structure: the person's identity has been established upstream by a qualified party, using documented procedures subject to supervision, and use of the tool produces a technical trail attributable to that person and to that moment. It is this combination, not the electronic method as such, that makes the check acceptable. It follows, conversely, that informal exchanges do not satisfy the obligation: a photograph of an identity card sent by email proves only that someone possesses the image of that document. The same applies to a video call conducted with no technical element fixing and allowing subsequent verification of its outcome: once the call ends, nothing demonstrable remains of that recognition. The difference between a correct procedure and an apparent one lies exactly here.
It is worth fixing the right perspective, because it is the one that matters in the months and years that follow. Identification is not carried out for the moment in which it takes place, but for the moment when someone will ask how it was carried out. Whoever reviews the file at an inspection was not present and can only read what the file contains: they must be able to understand which tool was used, when, with what outcome, and must be able to trace the technical elements documenting that outcome. Hence the attention — which may seem excessive to staff — to the completeness of what is retained: date and time of the operation, tool used, technical references of the check, identifying data obtained. The aim is not to accumulate paperwork, but to make the check traceable by a third party. However, however fully permitted remote identification may be, it remains a method that requires greater documentary discipline than in-person recognition: where a case presents elements of uncertainty, requesting a direct meeting remains the more solid choice and should be discussed with the professional in charge.
Level 2 · Chapter 11
The beneficial owner is the natural person on whose behalf the relationship is established or the transaction is carried out, and, in the case of legal entities, the natural person to whom ownership or control is attributable (Article 1, paragraph 2, letter pp, D.Lgs. 231/2007). Identifying this person is a self-standing element of customer due diligence (Article 18, paragraph 1, letter b) and must be carried out as a staged process, in an order that is not optional. The first criterion is ownership-based: the beneficial owner is the natural person holding a shareholding exceeding 25 per cent of the client's capital (Article 20, paragraph 2). Everything turns on the word "exceeding". A shareholding of exactly 25.00 per cent does not meet the criterion, because it does not exceed the threshold: the shareholder at 25.00% is not the beneficial owner on ownership grounds, while the shareholder at 25.01% is. In practice this scenario is far from rare — four shareholders each at 25%, or two at 25% and other fractional holdings — and it is precisely in these cases that misreading the threshold produces the most insidious error: not a wrong name in the file, but an analysis abandoned before it has genuinely begun.
The relevant shareholding may be direct or indirect, and the indirect case is the one requiring more work. The law also takes into account a shareholding exceeding 25 per cent held through controlled companies, fiduciary companies, or through an intermediary (Article 20, paragraph 3). This means that where the shareholder of a company is itself a company, the extract for the client does not conclude the analysis but opens it: the ownership chain must be traced back to the natural persons at the end of it, multiplying the percentages along each branch and adding together the branches that lead to the same person. A junior staff member tends to stop at the first level and, in good faith, records as beneficial owner the director sitting in front of them; but that record skips the two preceding criteria and is not defensible. If, having exhausted the analysis of the ownership structure, no natural person emerges, the Decree requires that control be examined: whoever holds the majority of voting rights exercisable at an ordinary shareholders' meeting, whoever holds voting rights sufficient to exert a dominant influence at an ordinary shareholders' meeting, whoever exerts a dominant influence by virtue of particular contractual arrangements (Article 20, D.Lgs. 231/2007). Control, in other words, may exist even where ownership is fragmented, and the arrangements that establish it do not always appear on the register extract.
Only where neither ownership nor control identifies anyone does the residual criterion apply, which identifies the beneficial owner as the natural person holding powers of legal representation, administration or management of the entity (Article 20, paragraph 5). It is a closing criterion, designed so that no client is left without a beneficial owner, and it must be used for what it is: the last step of a ladder, not a shortcut. Here comes the provision every member of staff should know by heart. Article 20, paragraph 6, requires a record to be kept of the checks carried out and of the reasons that prevented the beneficial owner from being identified under the preceding criteria. This is the system's safeguard provision: at an inspection, the question is not only who the beneficial owner is, but how that conclusion was reached. A file recording a correct name without showing the path — the register extract consulted, the chain reconstructed, the percentages calculated, the finding that no one exceeds the threshold, the examination of the control criteria and their negative outcome — demonstrates nothing and exposes the professional to a fully justified finding. However, the need to document should not be confused with the indiscriminate accumulation of material: what is required is an orderly, legible trail of the reasoning, not an archive of attachments with no connecting thread.
Level 2 · Chapter 12
In day-to-day practice, the beneficial owner is identified without difficulty in two cases out of three: there is a shareholder holding 60% or 80%, the ownership chain is short, and the answer is in the company register extract. The hard cases are the others, and they are worth addressing methodically, because they are exactly the cases on which, during an inspection, one is asked to account for the reasoning. The first is the perfectly equal shareholding: two shareholders at 50%, three at a third each, four at exactly 25%. The most common mistake is to conclude that "there is no beneficial owner" because no one prevails. The structure of Article 20 does not allow this shortcut: the ownership criterion is only the first step, and if it does not produce a clear outcome, one moves up to the control criterion (Article 20, paragraph 3, of Legislative Decree 231/2007), which looks at control of the majority of voting rights exercisable at an ordinary general meeting, sufficient votes to exercise a dominant influence, and contractual constraints allowing a dominant influence to be exercised. Only when this test, too, remains unanswered does the residual criterion of Article 20, paragraph 5, apply, identifying the beneficial owner as whoever holds powers of administration or management of the company.
Equal on paper does not mean equal in fact. Two shareholders at 50% may have a shareholders' agreement giving one of them the power to appoint the sole director; or one of the two may be the director with full powers while the other is a silent shareholder; or the articles of association may set enhanced quorum requirements that make each of them capable of blocking a decision but neither capable of making one. These are different situations and lead to different conclusions. In a case of genuine parity, with no agreements and no asymmetry in management powers, the correct conclusion is generally to identify both shareholders as beneficial owners: the concept is not inherently exclusive, and nothing prevents more than one person from being identified. What is not permitted is to leave the field blank, or to fill it in with the director's name for convenience, when the ownership structure would have given an answer.
Cooperatives deserve separate treatment, because the one-member-one-vote principle breaks the link between capital share and decision-making power: a shareholder with a larger contribution carries no greater weight at the general meeting. The ownership criterion, applied mechanically, would therefore return a meaningless figure. One proceeds to the control test (Article 20, paragraph 3) and, in the great majority of cases, arrives at the residual criterion (Article 20, paragraph 5), identifying the members of the management body. Even here the conclusion should not be taken for granted: in a cooperative with few members, or with financing members, or with significant contractual constraints towards a third party, the control test may return a positive result and must be carried out before falling back on the residual criterion. Trusts and foundations follow a structurally different logic, because there is no capital to apportion: what matters are the figures who govern the assets and derive benefit from them — the settlor, the trustee, any protector, the beneficiaries — while for private legal persons Article 20, paragraph 4, identifies the founder where living, the beneficiaries where identified or readily identifiable, and the holders of powers of representation, management and administration. In all these cases the founding instrument, the articles of association and the by-laws are documents to be read, not merely filed away.
Level 2 · Chapter 13
The question about politically exposed person status is, together with the one on the beneficial owner, the one staff members ask with the greatest discomfort, because it seems to insinuate something. It is worth dispelling that at once: it insinuates nothing. Being a PEP is not an indicator of wrongdoing and is entirely compatible with an irreproachable position; it is simply a condition that, owing to exposure to possible attempts at corruption and to asset visibility, European and national legislation has placed in the higher-risk area. The definition in Article 1, paragraph 2, letter dd), of Legislative Decree 231/2007 covers those who hold prominent public functions and those who ceased to hold them less than a year ago, and it extends to family members and to persons known to be closely associated with the individual: this latter extension is the one most often missed, because the client before us may not be a PEP in their own right yet may be one by association. For this reason the question must be framed so as to cover the family and close-associate perimeter too, not only the personal position of the individual concerned.
The question is asked of everyone, without exception and without prior selection. The reason is practical before it is legal. If the question is put only to those who "seem" to have a public profile, the selection criterion is the staff member's subjective perception, which is by definition incomplete: none of us knows the full composition of the governing bodies of entities and investee companies, still less clients' family ties. Making the question a fixed part of the standard forms achieves two results: it eliminates the risk of omission and strips the question of any personal character, because the client sees it as a box like any other. If the client asks why it is being asked, the correct answer is the simplest one: it is a data point the law requires to be collected for every relationship, regardless of the person. It should also be remembered that the client's answer must be checked against the available sources and not simply recorded: a negative declaration does not discharge the obligation if information in our possession points the other way.
When the answer is positive, the relationship does not automatically open or continue. Article 25, paragraph 4, requires a risk-based procedure to determine whether the client is a PEP and, where they are, prior authorisation from the holders of powers of administration or management (or their delegates): within the Firm this means the position must be referred to the professional in charge before the engagement is accepted, and the authorisation must be formalised in writing and dated, since it must predate the establishment or continuation of the relationship. Next comes verification of the origin of the wealth and of the funds involved in the relationship, which is not satisfied by a generic statement but requires documentary evidence consistent with the scale and nature of the transactions. Finally, ongoing enhanced monitoring, which is the most neglected part: it means a tighter review frequency and a lower threshold of attention to unusual transactions, throughout the life of the relationship. And, as Article 24, paragraph 6, specifies, for high-risk clients attention does not switch off when the year since leaving office expires. However, the reverse should be kept in mind: enhanced measures applied mechanically and without review become as formal as their absence, and must be periodically reassessed on their merits.
Level 2 · Chapter 14
The purpose and nature of the engagement are the part of customer due diligence that is filled in worst, because it seems the most obvious: the client comes in for bookkeeping, "bookkeeping services" is written down, and one moves on. In reality, Article 18, paragraph 1, letter c), of Legislative Decree 231/2007 asks for two distinct things — obtaining the information and assessing it — and the assessment presupposes that the information is concrete enough to be compared later with what actually happens. An engagement described in generic terms allows no subsequent comparison, and therefore hollows out ongoing monitoring as well: if what was expected was never written down, nothing can ever appear out of place. For this reason the type of engagement, the expected economic scale, the source of the funds the client operates with and the intended means of payment are all recorded. This is not about interrogating the client: this information emerges naturally from the engagement interview, and it need only be put in writing at the moment it is gathered, not reconstructed from memory months later.
On cash, the rule is strict and admits no relaxed reading. The prohibition in Article 49, paragraph 1, catches the transfer of cash, on any basis, between different parties where the aggregate value transferred is equal to or greater than 5,000 euros (threshold in force since 1 January 2023, paragraph 3-bis); paragraph 2 then sets a separate and lower threshold for money remittance services (1,000 euros), which follows its own rule and must not be confused with the general one. Two points matter more than any other. The first is that the prohibition is triggered on reaching the threshold, not on exceeding it: exactly five thousand euros is already a breach, and the statutory wording "equal to or greater than" leaves no room for interpretation. The second is that the reference is to the aggregate value of the transfer: the provision looks at the transaction as an economic whole, not at the individual cash movement. Our task, when we come across a payment of this kind, is to identify it and report it through the proper procedure; it is not to advise the client on how to structure payments, which would be improper conduct of the engagement and could itself become significant.
The obligation under Article 51 is the one that, in day-to-day practice, generates the most hesitation, because it places the professional in the position of reporting on a client for a matter the client may not consider serious. It must be stated clearly to staff that there is no room here for a discretionary judgement of expediency: whoever becomes aware, in the exercise of their functions, of an infringement of Articles 49 and 50 must report it to the Ministry of Economy and Finance within thirty days, in the manner indicated by the Ministry, and the time limit runs from the moment the information is acquired — typically, the date the document was reviewed in the accounts. The report is not a denunciation and contains no judgement: it sets out the fact and its documentary particulars, and it opens an administrative sanctions procedure that will follow its course before the competent authority. Separate from this remains the suspicious transaction report to the UIF under Article 35, which arises from suspicion and not from an objective breach, with the single point of contact provided for by the law: the report to the MEF is not due where the transaction has already been the subject of a suspicious transaction report (Article 51, paragraph 3). That said, the distinction between the two mechanisms should not be used as a convenient alternative: an irregular cash payment can, depending on the context, be both an infringement to report and an element contributing to a suspicion, and both assessments must be made.
Level 2 · Chapter 15
The three levels of customer due diligence are not three different procedures to choose between as convenient: they are three degrees of intensity of the same procedure, and the degree follows from the outcome of the risk assessment. This is the point that must be fixed before anything else, because the recurring error is to invert the order — deciding how much work to do and then building a risk assessment consistent with that decision. The correct path runs the other way: information is gathered on the client, on the type of engagement, on the geographic area and on the channels used, the risk is assessed, and the level of due diligence follows as a consequence. Article 23 of Legislative Decree 231/2007 allows simplified measures where the risk is found to be low, permitting the extent of the checks and the frequency of updates to be scaled back; Article 24 identifies the high-risk situations requiring enhanced measures; the standard tier is everything in between, and it is the tier into which the large majority of a professional firm's files fall.
Simplified does not mean omitted. This is the costliest misunderstanding, because it produces files lacking identification of the beneficial owner or documentation of the purpose of the engagement, justified after the fact with the formula "it was a low-risk client." Even under the simplified regime, identification must be carried out, the beneficial owner must be identified, the purpose and nature of the engagement must be obtained and assessed, and ongoing monitoring must be exercised: what is scaled back is the depth of the enquiries and the frequency of updates, not the existence of the obligations. It should also be remembered that low risk is a revocable condition: if elements emerge during the relationship that contradict it — transactions inconsistent with the profile, changes in ownership structure, flows towards unexpected jurisdictions — the level must be raised, and the raising must be recorded. And if a suspicion arises, the simplification falls away entirely, because the very premise of low risk no longer holds.
On the opposite side, enhanced due diligence has a mandatory component and a discretionary one, and it is worth keeping them distinct in day-to-day practice. The mandatory component is that of Article 24, which lists situations in which the application of enhanced measures is not a matter for assessment: relationships involving high-risk third countries, cross-border correspondent relationships, relationships with politically exposed persons. In these cases the staff member does not decide, they apply, following the arrangements set out in Article 25. The discretionary component is where the risk assessment, even in the absence of a listed case, returns an elevated profile: opaque corporate structures, activity inconsistent with the declared business, systematic and unjustified recourse to intermediaries. Here the assessment is ours, and precisely for that reason a written justification is essential. Article 17, paragraph 3, reverses the burden: it is not for the authority to prove that the measures were insufficient, it is for the obliged entity to prove that they were adequate to the risk identified. That said, the written justification is not a safe conduct: a stereotyped justification, identical across every file, only shows that the assessment was never really carried out.
Level 2 · Chapter 16
Recourse to third parties is a facility that simplifies the start-up phase of a relationship and that, read carelessly, produces the most fragile files one can find in a firm: those containing an attestation from a colleague and nothing else. The relevant section comprises Articles 26 to 30 of Legislative Decree 231/2007 and must be read in full, because each article adds a limit to the one before it. Article 26 defines the scope of what is admissible: recourse to third parties is possible only for the obligations under Article 18, paragraph 1, letters a), b) and c), that is, identification and verification of the client's identity, identification of the beneficial owner, and obtaining and assessing information on the purpose and nature of the engagement. Letter d) — ongoing monitoring during the relationship — cannot be delegated, and the reason is clear: ongoing monitoring consists in comparing actual activity against the client's profile, and only whoever manages the relationship can make that comparison. The section closes with Article 30, which keeps outsourcing and agency arrangements distinct from recourse to third parties, as these follow their own logic and do not fall within this regime.
The article to be learned by heart is Article 28. Recourse to third parties transfers an activity, not the responsibility: that remains entirely with the professional who relies on it. Three concrete duties follow from this, which are the operational core of the chapter. The first is to assess whether what has been received is suitable and sufficient for the obligations to be fulfilled: if the attestation is silent on the beneficial owner, or if the documents transmitted have expired, or if the description of the engagement is generic, what has been received is not sufficient and must be supplemented. The second is to verify, with professional diligence, the accuracy and completeness of the documents transmitted: this does not mean conducting an investigation, but applying the ordinary consistency checks that would apply to any document obtained directly. The third is the most important in practice: where there is doubt about the suitability or accuracy of what has been received, the professional proceeds independently with identification, without referring back to the third party and without seeking verbal reassurance. In this area, doubt is not resolved with a phone call: it is resolved by redoing the work.
It is also worth making clear to staff the difference between this arrangement and the simple receipt of documents from a colleague. If another professional sends us the company register extract and identity document of the client because they happen to have them available, we are not within the scope of Article 26: we are simply obtaining documents from a source, and we carry out customer due diligence ourselves in full. Recourse to third parties in the technical sense presupposes that the third party has actually fulfilled the obligations, that they issue the written attestation required by Article 27, and that they transmit the documentation: it is a formal arrangement, to be documented and retained. The prohibition in Article 29 completes the picture by excluding third parties established in high-risk third countries, and this must be verified before the procedure is activated, not afterwards. That said, even where all the conditions are satisfied, the outcome of the operation still falls on us: if, some time later, the file proves incomplete, the fact that the gap originated with the third party does not lessen the Firm's position.
Record-keeping, ongoing monitoring, recognising unusual activity, suspicious transaction reporting, sanctions, a complete guided case.
Level 3 · Chapter 17
Record-keeping is the part of a file that is least visible and that weighs most heavily during an inspection. Article 31 of Legislative Decree 231/2007 sets the term, in paragraph 3, at ten years, but the delicate point is not the duration: it is the starting date. The ten-year period does not run from when the individual document was created, but from the end of the business relationship or professional engagement, and for an occasional transaction, from its execution. In a firm that follows the same client for decades, this means the file never ages while the engagement is live: nothing can be discarded for age, and the archive grows in a straight line. The recurring error runs the other way and is more insidious — closing the relationship and letting the file dissolve among working folders because "the client is no longer with us." It is precisely from that moment that the term begins to run. Article 32 adds the procedural dimension: data and documents must be entered within thirty days, with the date indicated, in systems that guarantee integrity, non-alterability after entry, and complete and timely accessibility to the authorities. Three requirements to be read together, because an archive that is intact but not findable in time does not satisfy the rule any more than one that is accessible but alterable without trace.
The purpose for which the data may be used is not unrestricted. Article 34, paragraph 1, of Legislative Decree 231/2007 establishes that what is retained may also be used for tax purposes, in accordance with applicable provisions: it is an express extension, and precisely because it is express, it defines the boundary. Everything outside it — using the contact details gathered during customer due diligence for a promotional communication from the Firm, feeding a list for commercial initiatives, profiling clients for business development purposes — is processing without a legal basis. It is worth being blunt about this with staff: this is not a "watered-down" anti-money laundering breach, but an offence that sits on its own track, established and sanctioned by the Italian Data Protection Authority, with consequences independent of those provided for under the decree. Article 32 itself, for that matter, refers to compliance with data protection legislation as the framework for record-keeping, not as a parallel obligation.
On the medium, practice has been simplified. For paper archives, CNDCEC clarified in 2025 that it is sufficient to affix the date, with no signature required: a genuine easing, though one that does not touch the substance. A binder in which sheets are added, replaced and reordered without leaving a trace is not a compliant system, however much each sheet bears its own date. That said, the simplification should not be read as an invitation to stay on paper: the timely accessibility required by Article 32 is demonstrated far more easily on a well-organised digital archive, and on inspection the difference between producing a file in a few minutes and reconstructing it over a day falls entirely on whoever holds the records.
Level 3 · Chapter 18
Ongoing monitoring is the part of customer due diligence that lives through time, and precisely for that reason it is the one most easily neglected. Article 18, paragraph 1, letter d), of Legislative Decree 231/2007 places it among the due diligence obligations alongside identification of the client and beneficial owner and the obtaining of information on the purpose and nature of the engagement, but with a different character: it is not an act, it is a professional attitude that lasts as long as the relationship. From this follows a consequence worth fixing firmly for staff, because it connects directly to what was seen in Chapter 16 on the performance of obligations by third parties: the other elements of customer due diligence may, under the conditions set by law, rest on what a third party has already carried out; ongoing monitoring may not, ever. It is the only segment that remains entirely with whoever holds the engagement, and the reason is intuitive — only someone who works the file day by day can see whether the client's reality has shifted. No third party, however qualified, can observe a relationship they do not manage.
Ongoing monitoring is not a monitoring exercise with an expiry date. This is the most widespread misunderstanding in firms: a deadline is set — three years, five years depending on the risk tier — and the obligation is considered discharged by going through the same round of questions when it falls due. A periodic schedule is good organisational practice and helps prevent quiet relationships from being lost track of, but it is not what the rule asks for. Article 17, paragraph 4, of Legislative Decree 231/2007 requires the risk assessment to be renewed for existing clients whenever the actual risk changes: the trigger is the event, not the calendar. A low-risk relationship unchanged for years may reasonably require nothing new; a relationship re-verified three months ago may have to be reopened tomorrow morning if something material has changed in the meantime. That said, one does not exclude the other: the periodic deadline should be kept as a safety net for relationships that give no signals, because the absence of events is not in itself proof that anyone has been looking.
In the practice of a professional firm, the events that justify an early re-verification are few and recurring, and they almost always pass before someone's eyes in the firm before anyone even thinks of anti-money laundering: a change of legal representative or a change in beneficial ownership; an extraordinary transaction — merger, conversion, transfer of a business unit — that redraws the structure or the shareholding; a significant change in the activity actually carried out compared with what was known when the file was opened; the start of a new professional engagement, of a different nature, with a client already followed for other matters. The difficulty, in a firm, is not recognising these events: it is getting them to whoever holds the file. The register extract documenting the change of director comes in for a corporate matter and stops there; the extraordinary transaction is handled by a colleague and never makes its way back to the anti-money laundering file. It is worth surfacing the event immediately, at the moment it is encountered, rather than letting it sit until the periodic re-verification falls due naturally: redoing the assessment a few months early costs little; reconstructing it after the fact in front of an inspection costs a great deal more.
Level 3 · Chapter 19
This is the hardest topic to teach, because it cannot be resolved with a rule. The guiding principle of the UIF instructions of 18 December 2025 — adopted on 18 December 2025 and effective from 1 July 2026, replacing the measure of 4 May 2011 — is that suspicion is formed through a comprehensive, unified assessment: the client, their profile, the engagement requested and the context in which the transaction sits must be read together, as a whole picture, not as separate items to be checked against parameters. It is a way of saying that suspicion is not a data point, it is a judgement. From this follows a firm rejection of two opposite temptations. The first is quantitative automatism: setting an amount and treating everything above it as suspicious and everything below it as safe — an approach Article 35, paragraph 1, of the decree already excludes at its root, providing for the reporting obligation regardless of the amount of funds involved. The second is the "reflex" report, made out of defensive caution whenever something is not immediately clear, in the belief that over-reporting can never do harm. The instructions place value on the informational quality of the report precisely because the system depends on it: a well-reasoned, detailed report is useful; an empty report consumes analytical capacity that is needed elsewhere.
The mechanical approach and the permissive one fail in the same way. Whoever looks only at amounts is reassured by activity perfectly consistent with the thresholds yet completely inconsistent with the client's economic profile, and is equally alarmed by a large transaction that is fully explained by the activity carried out. Whoever reports to offload responsibility, by contrast, gives up doing the very thing they were engaged for: applying to the specific case a knowledge that no automated system possesses. Both failings share the same root — the idea that professional judgement is a risk to be neutralised — and produce the same effect: the system receives no information. That said, it must be said honestly to staff that a unified assessment does not offer the psychological protection of a numerical rule, and that this makes it demanding: one is left with a judgement to justify, not a box to tick. This is exactly why the written justification, concise but not generic, must be drawn up at the moment of assessment and not reconstructed afterwards.
The tools exist and should be neither ignored nor treated as gospel. The anomaly indicators (Article 6, paragraph 4, letter e, Legislative Decree 231/2007) and the typologies of unusual conduct (Article 6, paragraph 7, letter b), which the decree assigns to the UIF, remain the reference point for interpretation even under the new arrangements, and we look at them more closely in the next chapter. They should be used as a lens: they help bring into focus what has already been half-glimpsed and give a name to a vague sense of unease. They are not an exhaustive list, and consulting them is not the moment suspicion is born — it is the moment it is articulated. Suspicion is born earlier, from the knowledge of the client built up over time, which is precisely the structural advantage a professional firm has over someone who observes only flows.
Level 3 · Chapter 20
Having established that suspicion arises from judgement and not from a checklist, the practical problem remains of giving that judgement a communicable form. This is where the tools published by the UIF genuinely become useful. The anomaly indicators (Article 6, paragraph 4, letter e, Legislative Decree 231/2007) and the typologies of unusual conduct (Article 6, paragraph 7, letter b) — which the decree places among the Unit's functions — are not theoretical material to know for training purposes: they are the distillation of what the system has actually seen recur. The level at which they should be used is that of categories, not the specific case: activity inconsistent with the client's economic profile; frequent recourse to cash unjustified by the activity carried out; complex corporate structures with no apparent economic rationale; interposition of parties with no recognisable role in the transaction. These are deliberately general descriptions, and the generality is not a limitation of the tool: it is its function, because too precise a list would be both easy to circumvent and useless. Whoever consults it looking for a literal match to their own case gets little out of it; whoever uses it to interrogate the case gets a great deal.
The typology is a lens, not a substitute for professional judgement. It is worth insisting on the difference in position between a firm and a banking intermediary, because it is the point at which the chartered accountant's contribution is most distinctive. The bank observes flows and compares them against a declared profile: it reads the pattern, and in many cases has no way of knowing whether an explanation exists. The firm knows the activity actually carried out, has seen the financial statements of previous years, has followed the incorporation or reorganisation of the structure, has heard from the client the reasons for the choices made. The same configuration, read with this knowledge, may resolve into an anomaly that is only apparent — in which case there is nothing to report, but there is something to note — or take on a significance an outside observer would not perceive. That said, direct knowledge of the client is also the factor most likely to lead to underestimation: familiarity with the person makes it natural to find an explanation, and it is worth being aware of this when the explanation arrives too quickly.
The third element is organisational, and the UIF instructions of 18 December 2025, effective from 1 July 2026, expressly value it: the internal contact person for suspicious transaction reports and the internal procedure leading to them. This is not formalism. In a firm where several staff members follow the same client for different matters, doubt almost always arises at the periphery — in whoever keeps the accounts, whoever prepares the return, whoever handles payroll — and needs a channel to reach whoever decides. If that channel does not exist, the doubt stops where it arose, and on inspection no trace remains of either the assessment or its absence. A written procedure, even a brief one, indicating to whom the case is brought, within what time, with what minimum information, and how the outcome is recorded — report or justified filing — is what turns individual awareness into a firm-wide safeguard.
Level 3 · Chapter 21
It is worth starting from the distinction that underpins the whole chapter. Refraining from acting is a consequence of the inability to comply: when customer due diligence cannot be completed — the client does not provide the data, the beneficial owner remains unidentifiable, the person executing the transaction does not justify their own powers — the Firm cannot establish the business relationship, cannot carry out the transaction and, if the relationship is already under way, must bring it to an end (Article 42, paragraph 1). It is a rule of professional conduct, not a judgement on the client as a person. The report, by contrast, arises from a different judgement: it concerns suspicion, which may exist even when customer due diligence has been completed perfectly well, and may be absent even when customer due diligence has failed for trivial reasons. The legislator says this expressly in Article 42, paragraph 1 itself, which requires a separate assessment of whether to make a report under Article 35. It is worth adding that Article 42, paragraph 2, governs a further case of mandatory refraining, relating to situations where the client is a fiduciary company, a trust or a similar structure established in high-risk third countries and it proves impossible to identify the beneficial owner: there, refraining does not allow for the discretionary balancing that tends to be applied in other cases.
The report must be made without delay and, as a rule, before the transaction is carried out. Article 35 is clear on both points, and the second is the one most often neglected in firm practice: a late report, submitted once the transaction has already been executed and the funds have already moved, retains very limited informational value. The moment for the decision is when the element of suspicion emerges, not when the file is closed. And it is worth recalling that the requirement under Article 35 is neither proof nor certainty: reasonable grounds for suspicion suffice, assessed also on the basis of the client's subjective characteristics, the activity carried out and the economic consistency of the transaction with the known profile. The staff member who identifies the unusual element does not decide alone: they bring it to the contact person designated by the Firm, with a dated written note, and the decision — to report, or to justify in writing why no report is made — is in any event recorded in the file.
The third pillar is the prohibition on disclosure, known internationally as tipping-off. Article 39, paragraph 1, prohibits disclosing to the client concerned or to third parties that a report has been made, the transmission of further information requested by the UIF, and the existence or likelihood of investigations or enquiries concerning money laundering or terrorist financing. The prohibition is not a recommendation of confidentiality: it is criminally sanctioned, as will be seen in the next chapter, and the offence is constructed so as to catch carelessness as well, not only the intention to warn the client. In firm practice the greatest risk is almost never explicit disclosure: it is the remark made on the phone to justify a delay, the email referring to "anti-money laundering checks under way," the staff member who, pressed by the client, tries to shift responsibility onto some unspecified requirement. These are all indirect forms of disclosure, and all are prohibited.
Here comes the decisive clarification, which needs to be properly understood because it is counter-intuitive. Article 39, paragraph 6, establishes that a professional's attempt to dissuade the client from carrying out an unlawful activity does not constitute a breach of the prohibition on disclosure. In other words: the professional is not required to stay silent about the transaction, only about the report. They can — and generally should — tell the client that a given transaction will not be carried out, that the engagement cannot continue on those terms, that the proposed course of action is not viable. What they cannot do is link that refusal, even by allusion, to a report made or under consideration. The dividing line is sharp and should be kept in mind in these terms: one speaks about the transaction, never about the reporting flow.
Level 3 · Chapter 22
The subject of sanctions must be read by separating two levels that common perception tends to conflate. On the criminal level, Article 55 punishes active and specific conduct: paragraph 1 targets anyone who, being required to observe the customer due diligence obligations, falsifies data and information relating to the client, the person executing the transaction, the beneficial owner, or the purpose and nature of the relationship, with imprisonment from six months to three years and a fine from 10,000 to 30,000 euros; paragraph 2 punishes with the same penalty anyone who, being required to observe the record-keeping obligations, obtains or retains false data or untrue information, or uses fraudulent means to undermine proper record-keeping; paragraph 3 extends the same penalty to anyone who, being required to provide the data and information necessary for customer due diligence, provides false data or untrue information — this is the provision that catches the client who lies. These are criminal offences and presuppose intent. Paragraph 4, by contrast, concerns breach of the prohibition on disclosure discussed in the previous chapter and is constructed differently: detention from six months to a year and a fine from 5,000 to 30,000 euros. Being a summary offence, it is also punishable for negligence — carelessness, thoughtlessness, a remark let slip to please someone are enough to satisfy it, without any intention to warn the client being required.
On the administrative level the structure runs on two speeds. Non-compliance with the customer due diligence obligations, including breach of the duty to refrain, is punished with a fixed sanction of 2,000 euros, rising to a range from 2,500 to 50,000 euros where the breach is serious, repeated, systematic or multiple (Article 56). The same structure applies to non-compliance with the record-keeping obligations (Article 57). Failure to make a suspicious transaction report is instead punished with a fixed sanction of 3,000 euros, which in cases of serious, repeated, systematic or multiple breach falls within a range from 30,000 to 300,000 euros; for breaches yielding an economic advantage, an aggravation is provided for, up to twice the amount of the advantage with a minimum of 450,000 euros, or up to one million euros where the advantage cannot be determined (Article 58). Article 63 finally covers breaches concerning the use of cash and failure to report to the Ministry the infringements identified. The gap between the fixed measure and the higher range is the real subject of disputes in this area: it turns entirely on the criteria for setting the sanction under Article 67, which include the seriousness and duration of the breach, the degree of responsibility, the level of cooperation given and — a point of direct relevance to the Firm — the adoption of adequate risk assessment and mitigation procedures.
From this follows a clarification that should be fixed firmly, because it is commonly misunderstood. There is no standalone pecuniary administrative sanction, for a non-supervised professional, for a lack of organisational safeguards: the provision in Article 62, headed precisely "specific sanctioning provisions for supervised obliged entities," is addressed to banking and financial intermediaries and cannot be extended to professionals. It should not, however, be inferred that internal organisation is irrelevant. Self-assessment of risk, written procedures, correctly completed forms, the designation of a contact person for the assessment of reports, and documented staff training are exactly the elements that, when a matter is contested, distinguish an isolated error from a systematic breach: Article 67, paragraph 1, letter g, expressly names the adoption of adequate risk assessment and mitigation procedures as a criterion for setting the sanction. In the first case one is discussing 2,000 or 3,000 euros; in the second, one enters the ranges, and the jump is of one or two orders of magnitude. Procedures, in other words, do not avoid the sanction: they govern its measure, and that is sufficient operational reason to keep them in order.
The disciplinary track runs in parallel and does not depend on the first. Article 66, paragraph 1, provides that, in the case of serious, repeated or systematic breaches, or multiple ones, the Ministry informs the self-regulatory bodies for the purposes of the measures provided for under Article 11, and that the same breaches constitute grounds for the application of disciplinary sanctions under the relevant sector rules; Article 11 assigns to the self-regulatory bodies tasks of promoting and monitoring compliance with the obligations, and the Technical Rules adopted by the CNDCEC (Italy's National Council of Chartered Accountants and Accounting Experts) bind the registered member as such. The practical consequence is that a breach of the Technical Rules can found disciplinary proceedings even in the absence of any administrative sanction from the Ministry: the two paths have separate preconditions, competent authorities and outcomes, and the closing of one does not prejudice the other. Finally, a point should be kept in mind that concerns several members of the Firm's staff personally: whoever sits on a board of statutory auditors or another supervisory body of a client company is subject to their own separate reporting obligations (Article 46), non-compliance with which is punished with a sanction from 5,000 to 30,000 euros applicable to each member (Article 59). That position is not covered by the Firm's overall compliance: the individual board member answers for their own conduct.
Level 3 · Chapter 23
The case that follows is expressly invented and serves only to show, in sequence, mechanisms that the previous chapters treated separately. Alfa Servizi S.r.l. is a small-to-medium-sized business services company that approaches the Firm for ongoing bookkeeping and tax assistance. The shareholding structure is as follows: Gamma Holding S.r.l. holds 80% of the capital, Tizio holds 10%, Caio holds 10%. Gamma Holding, in turn, is held by four natural persons — Mevio, Sempronio, Filano and Caia — each holding 25%. Tizio is the sole director of Alfa Servizi. No shareholders' agreement is declared, no shareholding is held through a fiduciary, no party resides in a high-risk third country. It is an ordinary structure, not an opaque one, and precisely for this reason it is useful, because it shows that applying the residual criterion is not a sign of anomaly, but the normal outcome of an articulated ownership chain.
Reference · Glossary
Each entry is also defined in its own chapter; this glossary brings them all together, for anyone looking for a precise definition without having to find the right chapter.
AI utility on this page
The chat can help you understand a chapter, a cited article, or a glossary term. It does not access client files, does not replace the professional's judgement, and never provides guidance on how to avoid a control or a report.
Do not enter client names, tax codes, VAT numbers, identifying data, or details of a real case. Keep data to the minimum necessary and consult the privacy notice for this automated service.
Notice. Content checked against sources current as of the date shown, with the text as published on Normattiva verified directly. This pathway is for internal training purposes and does not constitute professional advice, nor does it exhaust the examination of an individual case, which always remains a matter for the professional in charge. This area of law is subject to frequent updates — Regulation (EU) 2024/1624 will apply from 10 July 2027 and will amend, among other things, the criteria for identifying the beneficial owner and the cash-use thresholds: where in doubt, or before a decision is taken, always check the most recent version with the Firm.
Sources
Last editorial check: 30 August 2026 · Version 1.0 · Every article cited in this pathway has been checked against the text published by Normattiva as of the date shown.
Academy Studio Ponchio · 2026
Utility for accounting offices: 27 modules and an AI assistant to structure the entries.
Educational content: your specific case still requires a professional review.
Open pathway and utility