Skip to content
PARLA CON LO STUDIO

Un primo orientamento chiaro e immediato sulle tue esigenze fiscali, societarie e professionali.

Studio Ponchio Academy · 2026 pathway

AML pathway

Twenty-three chapters in three levels to understand why the law requires a chartered accountant to know their client, how customer due diligence actually works, and what obligations remain with the Firm over time — built on Legislative Decree 231/2007 (the Italian AML Decree) and the CNDCEC Technical Rules of 16 January 2025, with a complete guided case at the end.

Training under Article 16, paragraph 3, D.Lgs. 231/200723 chapters3 levelsAI assistant via OpenAI APISources current as of the date shown

AML pathway

Why the Firm needs to know its clients.

This pathway does not replace the operational tool the Firm uses to collect and verify client data — that remains a separate application, explained to those who use it when needed. Here the aim is to provide the framework: why the law requires it, how the beneficial owner is identified, when enhanced due diligence applies, what is retained and for how long, and what the real consequences of non-compliance are. The first level is written in a register a client could follow too, if curious about why they are asked for a document or the name of whoever controls their company; the next two levels go into the operational detail and are addressed to the Firm's staff.

01

Why and for whom

The legal framework, who is subject to the obligations, the stages of customer due diligence in summary — accessible to a curious client wondering why the Firm asks for certain data.

Level 1 · Chapter 01

Why the law requires the chartered accountant to know the client

Frequently asked questions
Why should a firm of chartered accountants concern itself with anti-money laundering?
Because the law lists it among the obliged entities: the regime covers "persons enrolled on the register of chartered accountants and accounting experts and on the register of employment consultants" (Article 3, paragraph 4, letter a, D.Lgs. 231/2007, the Italian AML Decree). The obligation does not arise from a choice made by the Firm, nor from any contract with the client: it follows directly from enrolment on the register and from the exercise of the profession.
Does the same apply to notaries and lawyers, in the same way?
No, and the difference matters. Notaries and lawyers are obliged entities only when they carry out, in the name or on behalf of the client, transactions specifically listed by the law (Article 3, paragraph 4, letter c, D.Lgs. 231/2007); the chartered accountant, by contrast, is obliged by reason of the professional activity as such. This is one of the reasons why a client who has already signed documents with other professionals may find, at the Firm, that the requests go further.
Is this a rule designed to punish, or to prevent?
To prevent. D.Lgs. 231/2007 does not punish money laundering — that is a matter for the criminal code — but builds a system of safeguards that makes it harder to introduce illicitly obtained money into the legitimate economic circuit: knowing the client, assessing risk, retaining records, reporting suspicious transactions. The logic is one of preventive obstruction, not of establishing whether an offence has been committed, which remains a matter for the judicial authorities.
From what point does the obligation apply — from a certain amount upward?
No. For the professional, the obligation arises when the professional engagement is accepted or when an ongoing relationship is established (Article 17, paragraph 1, letter a, D.Lgs. 231/2007), regardless of the value of the engagement. The €15,000 threshold concerns a different case, that of occasional transactions (Article 17, paragraph 1, letter b). And in any event, where a suspicion arises, customer due diligence (CDD) is required irrespective of any threshold (Article 17, paragraph 2).

Anyone walking into a firm of chartered accountants for a routine matter does not expect to have to produce identification and answer questions about their own business. The most common reaction is not hostility but surprise: what does the accountant have to do with money laundering. The answer lies in the way the European legislator, and behind it the national legislator, chose to tackle the problem. Rather than leaving it solely to the judiciary and law enforcement, who intervene after the fact, the legislator drew in those who see the money pass through beforehand: banks, financial intermediaries, and the professionals who assist businesses and individuals in their economic transactions. D.Lgs. 231/2007 thus builds a network of obliged entities, and within that network the chartered accountant occupies a precise position, named expressly by the law (Article 3, paragraph 4, letter a). Everything else follows from that position: the questions, the documents, the record-keeping, the training of staff. It is not zealousness on the part of the Firm, nor suspicion of the individual client, and it is not even a practice that the professional may adjust at will: it is a statutory obligation, with content that is largely predetermined.

The rule is preventive, not punitive, and this distinction changes the meaning of every question the client is asked. The chartered accountant does not investigate, accuse or judge: they gather and verify information, assess it according to risk-based criteria, and keep a record of what they have done. If a suspicion emerges, that assessment does not turn into an accusation but into a report to an administrative authority, which is a different matter from a criminal complaint. The underlying premise is that money of illicit origin, to become usable, must sooner or later pass through a formally ordinary transaction — a capital contribution, a transfer of business, a property purchase, a shareholder loan — and that at that point a diffuse, documented control is more effective than a subsequent investigation. Hence the choice to trigger the obligation at the moment the engagement is accepted rather than when a monetary threshold is exceeded: what matters is not the value of the engagement, but the fact that the professional enters into a stable relationship with that client.

Certain activities fall outside the scope, and it is worth saying so at once to avoid the impression of an indiscriminate obligation. Customer due diligence does not apply to the mere preparation and filing of tax returns, nor to payroll administration tasks under Law 12/1979 (Article 17, paragraph 7, D.Lgs. 231/2007). This exclusion is narrower than it appears: it covers purely executory activity, not the advisory work that often accompanies it, and it does not cover the professional relationship as a whole when that relationship includes other services too. Even where the exclusion applies, however, the duty of attention is not entirely switched off: a suspicion, should one arise, remains relevant in its own right (Article 17, paragraph 2).

Why this matters

  • The obligation arises from enrolment on the register and from the exercise of the profession, not from any assessment the Firm makes of the individual client: saying so clearly at the first meeting prevents the questions from being read as distrust.
  • The relevant moment is the acceptance of the engagement, not payment and not the crossing of a threshold: information should be gathered at the start of the relationship, not on the eve of a transaction.
  • The exclusions for tax returns and payroll administration (Article 17, paragraph 7) must be read narrowly and checked engagement by engagement, because a genuine professional relationship rarely consists solely of those activities.

Level 1 · Chapter 02

Money laundering, self-laundering and terrorist financing: what they actually are

Frequently asked questions
What, in concrete terms, is meant by money laundering?
The process by which money or assets deriving from a criminal offence are substituted, transferred or otherwise handled so as to make it difficult to trace their origin. The point is not the illicit gain itself, but the subsequent step: making it spendable, apparently ordinary, indistinguishable from a lawful resource. D.Lgs. 231/2007 does not punish that conduct — the criminal code deals with that — but builds the obstacles intended to make it harder.
And how does self-laundering differ?
In classic money laundering, the person who cleans the money is different from the person who committed the predicate offence. Self-laundering, by contrast, concerns a person who reinvests the proceeds of their own offence in economic or financial activities. It is a concept introduced later into Italian criminal law, and it has significantly widened the area of attention for professionals, because it touches situations where the underlying offence is of a tax nature and the downstream use takes the form of an entirely ordinary corporate transaction.
Is terrorist financing the same thing seen from another angle?
No, and this is the most common mistake. In money laundering the money is dirty at the source and is cleaned; in terrorist financing the money may be perfectly lawful in origin — a fundraiser, a genuine commercial activity — and it is the destination that is unlawful. It follows that the useful indicators differ: here what matters less is the origin of the funds and more the beneficiaries, the routes, and the stated purposes of the relationship.
Is a small provincial firm genuinely exposed?
The legislation does not scale the obligation according to the size of the firm: it scales the procedures. D.Lgs. 231/2007 requires every obliged entity to adopt safeguards proportionate to its own nature and size (Article 16), not to consider itself exempt because it is small. The transactions that raise concern are not necessarily large ones: they are often ordinary in form and anomalous in context, and it is precisely a smaller firm, which knows its clients closely, that is best placed to notice.

The three concepts are almost always mentioned together, as though they formed a single block, and this creates confusion. It is worth separating them, because they respond to different logics and demand different attention. Money laundering is a problem of origin: there is a predicate offence that has generated money or assets, and there is a need to erase the trace of that origin. The launderer does not profit from the original offence — they kept out of that — but makes usable what the offence produced. Self-laundering shifts the centre of gravity: the perpetrator of the predicate offence and the person reinvesting the proceeds are one and the same. It is a relatively recent concept in the Italian legal system and it has changed the perception of risk within professional firms, because it has made criminally relevant the reinvestment of resources originating even from tax offences into perfectly normal economic activities. Terrorist financing, finally, reverses the perspective: the money may be clean, and what qualifies the conduct is where it ends up and what it is used for. These are three distinct phenomena that the legislator chose to counter with a single prevention framework, and it is this legislative technique that makes them appear as one and the same thing.

Prevention concerns not only those who move money, but also those who give legal form to transactions. This is the aspect most easily overlooked. A bank sees the financial flow and little else; the chartered accountant sees the structure: who enters a company and with what contribution, how a shareholder loan is justified, why a loss-making business continues to receive funds, what economic rationale underpins a transfer between related parties. The professional, in other words, has access to the rationale behind the transaction, not merely to its amount. This is why European law has progressively extended the obligations to accounting professionals, and why the assessment required is never purely quantitative. The relevant question is not how much the transaction is worth, but whether it makes economic sense consistent with what is known about the client.

One point deserves to be stated explicitly, because it affects how staff experience this work: it is not the Firm's task to establish whether an offence has been committed. It has neither the tools nor the power to do so, and to presume otherwise would be unfair to the client. The task is to gather adequate information, assess its consistency, and keep a documented record of that assessment. However, precisely because the assessment is not a judgement, it cannot be a mere formality either: a file compiled without understanding what the client actually does protects no one, neither the client nor the Firm.

Why this matters

  • Money laundering and terrorist financing call for opposite kinds of attention: in the first case what matters is where the money comes from, in the second where it goes and to whom.
  • Self-laundering has brought the subject closer to the Firm's everyday work, because it makes relevant the reinvestment of proceeds — even of tax origin — into formally regular corporate transactions.
  • The size of the firm affects the procedures, not the existence of the obligation: the law requires proportionate safeguards (Article 16, D.Lgs. 231/2007), not optional ones.

Level 1 · Chapter 03

The risk-based approach: why the same question does not carry the same weight for everyone

Frequently asked questions
Why aren't two different clients asked the same things?
Because the law does not impose a uniform questionnaire for everyone, but a method: assess the risk and calibrate the controls accordingly. The obliged entity must carry out an assessment of the risk inherent in its own activity, documenting it and updating it periodically (Article 15, D.Lgs. 231/2007), and adopt proportionate mitigation measures (Article 16). Asking everyone for exactly the same set of information would not offer greater protection: it would simply be a different way of not assessing anything.
Does a higher risk rating mean the Firm suspects something about the client?
No, and this is the most important clarification to give the client. Risk is a classification of the situation, not a judgement about the person. A business that deals in cash, or with foreign counterparties, or with an articulated corporate structure, objectively presents more variables to check: the consequence is greater scrutiny, not distrust. Many higher-risk situations involve entirely legitimate clients.
What actually changes, in practice, between one profile and another?
The intensity and the frequency change. For the same statutory obligations, a lower-risk profile requires essential information and a less frequent review; a higher-risk profile requires more extensive documentation on the source of funds and the ownership structure, and more frequent updating throughout the relationship. It is the content of the obligation that is calibrated, never its existence.
Is the assessment carried out once only, at the outset?
No. The law refers to an assessment that is documented and periodically updated (Article 15) and, for the individual relationship, to ongoing monitoring throughout its duration (Article 18, paragraph 1, letter d). A risk profile assigned three years ago and never reviewed since is, in practice, a profile that no longer exists: the client's activity changes, and with it the information the Firm needs to hold.

The risk-based approach is the principle underpinning the entire framework, and at the same time the one clients find hardest to accept, because it appears to introduce unequal treatment. In reality it does the opposite of what it seems: it prevents everyone from being asked for everything, and concentrates scrutiny where there are genuinely more variables to understand. The legislator did not draw up a closed list of documents to collect, applicable to all; it imposed a method, requiring the obliged entity to analyse and assess the risks to which its own activity is exposed, to formalise that assessment and keep it updated over time (Article 15, D.Lgs. 231/2007), and then to adopt procedures consistent with that analysis (Article 16). It follows that the Firm must be able to explain, if asked, not only what it requested from the client, but why it requested those particular things from that particular client. The rationale is part of the compliance obligation, not an afterthought: a risk rating assigned without traceable criteria is just as indefensible as missing information.

Risk is assessed by looking at the client and the transaction together, never at either in isolation. What matters are the client's characteristics — its legal nature, the complexity of its ownership structure, the sector, the geographic area in which it operates — and the characteristics of the service requested, because the same person may approach the Firm for a straightforward routine matter or for an extraordinary transaction that opens up many more questions. A client known for years is not, for that reason alone, a low-risk client in every circumstance: if the nature of the engagement changes, so does the exposure. This is why the profile is not a label fixed to the client record once and for all, but the outcome of a judgement that accompanies the relationship and must be reviewed whenever something occurs that warrants it: a change in the ownership structure, entry into a new market, a transaction out of scale compared with the usual size of the business.

It should be said honestly that this method leaves room for judgement, and that room for judgement means debatable decisions. That is the price of a regime that has abandoned automatic rules. However, the margin is not arbitrary: precisely because the assessment is discretionary, the law requires it to be documented, and documentation is what distinguishes a professional judgement from an omission. In the event of an inspection, the Firm is not required to have guessed correctly, but to be able to show what elements its reasoning was based on.

Why this matters

  • The risk level classifies a situation, not a person: explaining it in these terms prevents the client's defensive reaction, who might otherwise read the scrutiny as an implicit accusation.
  • Risk arises from the interplay between the client's profile and the nature of the engagement: the same client may require different levels of scrutiny depending on the service.
  • An undocumented assessment is equivalent to no assessment at all, because the law expressly requires it to be documented and updated over time (Article 15, D.Lgs. 231/2007).

Level 1 · Chapter 04

The stages of customer due diligence: an overview

Frequently asked questions
What exactly does customer due diligence consist of?
Four elements set out by the law: identification of the client and verification of their identity; identification of any beneficial owner; obtaining information on the purpose and intended nature of the ongoing relationship or professional engagement; ongoing monitoring throughout the relationship (Article 18, paragraph 1, letters a, b, c and d, D.Lgs. 231/2007). These are cumulative elements: none of the four can substitute for the others.
Are identifying the client and verifying their identity two different things?
Yes, and it is a distinction the law maintains firmly. Identification means obtaining the data that identify the individual; verifying identity means checking that data against a reliable and independent source — typically a valid identity document. Noting down a name given over the telephone is identification without verification, and does not satisfy the obligation.
Who is the beneficial owner, in plain terms?
The natural person who actually stands behind the client: whoever owns or controls the entity, or on whose behalf the transaction is carried out. Where the client is a natural person acting on their own behalf, client and beneficial owner coincide; where the client is a company, one must trace back to the natural persons involved. This is the step clients perceive as most intrusive, and yet, from a prevention standpoint, it is the most significant: interposed corporate structures are the classic tool for distancing a name from an estate.
Why is it necessary to establish the purpose of the engagement, if the Firm already knows it?
Because implicit knowledge cannot be documented and does not allow for later comparison. Obtaining information on the purpose and intended nature of the relationship (Article 18, paragraph 1, letter c) serves to establish a benchmark: if a transaction later appears that falls outside that scope, the anomaly emerges precisely from the divergence with what was declared at the outset. Without that initial reference point, there is nothing against which to measure the anomaly.

Customer due diligence is often described as a form-filling exercise, and this is the surest way to do it badly. Within the structure of the law, it is instead a fact-finding process comprising four distinct elements, listed clearly: identification of the client and verification of their identity, identification of the beneficial owner, obtaining information on the purpose and intended nature of the service, and ongoing monitoring throughout the relationship (Article 18, paragraph 1, D.Lgs. 231/2007). The first three are concentrated at the outset; the fourth runs through the entire relationship and is the part most exposed to being overlooked, because it has no visible deadline and does not, in itself, produce a document to be signed. The overall purpose is to build, at the start, a coherent picture of the client and of what they are asking of the Firm, and then to verify over time that what happens is consistent with that picture. This chapter is confined to the overview: the practical way of gathering each piece of information, the particular cases and the records to be kept are matters for the subsequent levels.

Ongoing monitoring is the stage that distinguishes a genuine compliance exercise from an archive of forms. It is also the stage that explains why, years later, the Firm goes back to ask a client it considers well established for updated information. The professional relationship is not static: shareholders change, the corporate purpose changes, relationships with new counterparties open up, the business grows or contracts. A file that photographs the situation on the day the engagement was accepted, and is never touched again, describes a client who, quite simply, no longer exists in that form. The law expressly requires ongoing monitoring throughout the relationship (Article 18, paragraph 1, letter d), and this entails two things at once: verifying that transactions are consistent with what is known about the client and their activity, and keeping the data and information originally gathered up to date.

One final clarification, useful for preventing a common misunderstanding. The four stages cannot be scaled down on account of trust: personal familiarity with the client, however long-standing and solid, does not substitute for identity verification or for the identification of the beneficial owner. What risk calibrates is the depth of the scrutiny and the frequency of review, not the presence of the four elements. However, it must be acknowledged that the practical application of some of them — in particular, the identification of the beneficial owner in complex ownership structures — presents interpretive issues that are not entirely settled, and the subsequent levels of this course address that point.

What you need to get started

  • Keep identification and identity verification separate: the first gathers the data, the second checks it against a reliable and independent source.
  • Remember that the beneficial owner is always a natural person: the chain must be traced back to a name, not stopped at the first company.
  • Treat the stated purpose of the relationship as the benchmark for everything that follows: it is against that reference point that the consistency of subsequent transactions is later measured.
  • Treat ongoing monitoring (Article 18, paragraph 1, letter d) as part of the compliance obligation and not as an optional extra: it is the stage that gives meaning to the previous three.

Level 1 · Chapter 05

Who does what within the Firm: the responsible person, delegation, confidentiality

Frequently asked questions
Who, within the Firm, handles the data collected for AML purposes?
The professional holding the engagement and the staff specifically tasked with handling the file, each for the part within their competence. This is not information available indiscriminately to anyone working at the Firm: access is limited to those who need to process it in order to comply with the statutory obligation, and it remains subject to the confidentiality duty binding on all of the Firm's staff, as well as to data protection law.
Can the information collected end up with third parties?
It cannot be disclosed to third parties or used for purposes other than those provided for under AML law. It is retained for the period set by law and may be disclosed only to authorities entitled to request it in the exercise of their supervisory powers. It does not feed into commercial assessments, is not shared with other clients, and does not leave the scope for which it was obtained.
Are staff trained on this subject, or do they simply learn on the job?
Training is a statutory obligation, not an organisational choice. The law requires obliged entities to adopt, among their risk-mitigation procedures, ongoing training programmes proportionate to the nature, size and risk profile of the firm (Article 16, paragraph 3, D.Lgs. 231/2007). The course you are reading is precisely the fulfilment of that obligation.
Does anyone check whether the Firm genuinely provides training?
Yes. The self-regulatory bodies — for chartered accountants, the CNDCEC (the National Council of Chartered Accountants and Accounting Experts) and the local professional board to which the Firm belongs — promote and monitor compliance with the obligations by their members and are responsible for their training and continuing education (Article 11, D.Lgs. 231/2007). The same bodies adopt the Technical Rules to which members must adhere (Article 11, paragraph 2): the rules currently in force were issued on 16 January 2025 (CNDCEC Notice No. 6/2025) and form the basis on which this course has been built.

When a client hands over an identity document, states who controls their company and explains where the funds used in a transaction come from, the question that arises — legitimately — is not only why they are being asked, but what will become of that information. It is a question that deserves a precise answer, because AML regulation is, by its nature, a regime that produces a concentration of sensitive data in the hands of the professional. The first safeguard concerns purpose: the information is collected to fulfil a statutory obligation, may be used only for the purposes of that obligation, and cannot be used for other purposes. The second concerns access: within the Firm, not everyone sees everything, and handling is restricted to those working on the engagement. The third concerns the recipient: outside the Firm, the data may be disclosed only to authorities entitled to receive it, in the exercise of their powers, and to no one else. These safeguards apply all the more strictly given how much the professional relationship is, by its nature, a relationship of trust.

Responsibility for compliance rests with the professional, even where the practical work is entrusted to a member of staff. Internal organisation may well provide for the collection of documents, their retention and periodic updating to be handled by dedicated staff — this is normal and, in larger firms, unavoidable — but the assessment that gives meaning to that material remains a professional act that cannot, in substance, be delegated. This has two practical consequences, opposite in direction and equally important. On the one hand, whoever carries out the work in practice must be put in a position to understand what they are doing: hence the obligation to provide ongoing training programmes (Article 16, paragraph 3, D.Lgs. 231/2007), which is not a formal requirement but the condition that makes delegation function. On the other hand, a member of staff who comes across something they cannot place should not try to resolve it themselves: it must be brought to the professional, whose task it is to assess it.

It should be added that this arrangement is not left to the self-discipline of the individual firm. The law assigns to the self-regulatory bodies — the National Council of Chartered Accountants and Accounting Experts (CNDCEC) and the local professional boards — the task of promoting and monitoring compliance with the obligations by their members, together with responsibility for their training and continuing education (Article 11, D.Lgs. 231/2007), as well as the adoption of the Technical Rules to which members must conform (Article 11, paragraph 2). The Technical Rules currently in force, dated 16 January 2025, are the operational reference on which this training course has been built. For the client, the point of all this is simple: the procedures they encounter are not an invention of the Firm, nor are they left to the Firm's discretion.

Why this matters

  • The data collected has a restricted purpose: it serves AML compliance and nothing else, and cannot be disclosed to anyone other than the entitled authorities.
  • Internal delegation concerns the practical work, not the professional assessment: any doubt must be brought to the professional, not resolved independently.
  • Staff training is a statutory obligation proportionate to the size of the firm (Article 16, paragraph 3, D.Lgs. 231/2007), and compliance with it is supervised by the self-regulatory body (Article 11).
  • The technical reference is not the Firm's own custom but the CNDCEC Technical Rules of 16 January 2025 (CNDCEC Notice No. 6/2025).

Level 1 · Chapter 06

The questions the client is asked, explained

Frequently asked questions
Why is an identity document required if the Firm has known me for years?
Because the law distinguishes identification from identity verification and requires both (Article 18, paragraph 1, letter a, D.Lgs. 231/2007). Verification presupposes a check against a reliable and independent source, and personal acquaintance — however well established — cannot be documented or produced in the event of an inspection. It is not a sign of distrust: it is the only way the obligation can be demonstrated after the fact.
What do a mobile number and an email address have to do with this?
They serve to keep the relationship verifiable and updatable over time, which is precisely what the law requires when it imposes ongoing monitoring throughout the relationship (Article 18, paragraph 1, letter d). A file with contact details that are no longer active makes it impossible to update the information when the client's situation changes, and turns the initial compliance work into an outdated snapshot.
Why must I state my profession and the source of the funds involved?
Because the purpose and nature of the relationship are an express element of customer due diligence (Article 18, paragraph 1, letter c). Knowing what the client does and with what resources they operate is what makes it possible, later on, to distinguish a consistent transaction from one that is not. Without that initial reference point, there is no benchmark, and any subsequent assessment would lack a basis.
Can the client simply answer verbally, or refuse to answer?
The law requires the client to provide, in writing and on their own responsibility, all the information necessary and up to date to allow customer due diligence to be carried out (Article 22, D.Lgs. 231/2007). It is therefore not a discretionary request from the Firm: it is an obligation resting on the client themselves, with its own consequences. On information relating to the beneficial owner, in particular, a shareholder who unjustifiably refuses to provide it cannot exercise their voting rights, and resolutions passed with their decisive vote may be challenged (Article 22, paragraph 3).

The most delicate part of this subject is not technical: it is a matter of communication. The questions a client is asked when a file is opened are perceived as a request from the Firm, and as such as something negotiable — one might ask to skip it, to postpone it, to settle for a verbal answer. It is precisely here that clarity matters, because the legal structure is different from how it appears. The law does not merely impose obligations on the professional: it imposes them on the client too. It is the client who must provide, in writing and on their own responsibility, the information necessary and up to date to allow customer due diligence (Article 22, D.Lgs. 231/2007). The professional, in other words, is not asserting a claim of their own and has no power to waive it: they are asking the client to fulfil a duty the law places directly upon them. Explaining it in these terms, without emphasis and without a defensive tone, is generally enough to defuse resistance, because it moves the conversation from the ground of personal trust to the far simpler ground of the applicable law.

On the beneficial owner, the law has provided for a consequence that touches directly on the life of the company, and not only on the relationship with the Firm. A shareholder who unjustifiably refuses to provide the information necessary to identify the beneficial owner cannot exercise their voting rights, and any resolutions passed with their decisive vote may be challenged (Article 22, paragraph 3, D.Lgs. 231/2007). This is a provision rarely known before it is explained, and it has an immediate clarifying effect: a refusal does not merely create a problem in the relationship with the professional, but a potential flaw in the decisions of the shareholders' meeting, with consequences that fall on the company and on the other shareholders. No one is using it as a threat — that is not the spirit of it — but staying silent about it would leave the client unaware of a consequence that concerns them very directly.

The right way to present these requests, then, is also the most sober one: state what is being asked, why the law requires it, and what will become of the information. No request is arbitrary, none is negotiable out of goodwill, and none serves purposes other than the one for which it is made. However, it must be acknowledged that certain lines of enquiry may, in a specific case, appear disproportionate to the client; when that happens, the right response is not to insist on the form, but to explain the criterion by which that particular piece of information was deemed necessary.

Why this matters

  • The obligation to provide information rests on the client by law, in writing and on their own responsibility (Article 22, D.Lgs. 231/2007): it is not a practice the Firm can relax on request.
  • An unjustified refusal to provide information on the beneficial owner deprives the shareholder of voting rights and renders challengeable any resolutions passed with their decisive vote (Article 22, paragraph 3): this is the consequence that makes clear to the client the seriousness of the request.
  • Every question should be traceable to the statutory content that justifies it — identity, beneficial owner, purpose and nature of the relationship, ongoing monitoring (Article 18, paragraph 1) — because a request that cannot be explained is perceived as excessive.
  • This chapter closes the introductory part of the course: it sets out the general framework for training purposes and does not replace the examination of the individual case, which remains a matter for the assessment of the professional handling the engagement.
02

Customer due diligence, step by step

Identifying the natural person and the entity, the beneficial owner, politically exposed persons, the purpose of the engagement, levels of due diligence, reliance on third parties.

Level 2 · Chapter 07

Before the client: the Firm's own risk assessment

Frequently asked questions
What is the firm-wide risk self-assessment, and why does it come before everything else?
It is the assessment the Firm carries out on itself: on its own portfolio, on the services it offers, on the channels through which it acquires engagements, on the geographic area in which it operates. The law requires it of professionals as a self-standing obligation (Article 15, D.Lgs. 231/2007) and places it upstream of customer due diligence on the individual client, because it is from the Firm's risk map that internal procedures, controls and the level of scrutiny to be applied case by case all follow. Anyone who skips this step ends up assessing clients without a shared yardstick.
Must it be in writing, or is it enough to have it in mind?
It must be documented. Article 15 requires an assessment that is documented and periodically updated, and paragraph 4 of the same article requires it to be made available to the authorities and to the self-regulatory bodies in the event of an inspection. An assessment that exists only in the mind of the principal is, at an inspection, equivalent to no assessment at all: it cannot be produced, it is not dated, it is not verifiable.
Must every professional carry out their own, or can it be done at the level of an associated firm?
The CNDCEC Technical Rules of 16 January 2025, circulated with Notice No. 6/2025, expressly allow the self-assessment to be conducted at the level of a professional partnership or professional association, where the organisation is unitary and the procedures are shared. Individual responsibility for each professional's own engagements remains unaffected: a unitary self-assessment simplifies compliance, it does not transfer responsibility.
Is there a mandatory form to complete?
No. The CNDCEC provides sample documentation (the AV.0-AV.7 templates), realigned and circulated with Notice No. 57/2026 of 26 March 2026, of which template AV.0 is the one dedicated to the Firm's self-assessment. These are supporting tools, not forms imposed by law: a different one may be used, provided the resulting document contains the reasoning, the date and the conclusions.

There is an understandable temptation, when beginning to work on AML compliance, to start with the first file on the desk: take the client, identify them, assign a risk profile, file it away. The Decree reasons in the opposite direction. Before even looking at clients one by one, it requires the Firm to look at itself and ask what risks it is exposed to given how it is structured: what services it provides, what type of clientele it habitually works with, through what channels new engagements arrive, in what territorial context it operates (Article 15, D.Lgs. 231/2007). This is an assessment of the organisation, not of individuals. A firm that mainly handles tax returns for employees and small tradespeople known for twenty years has a different exposure profile from one that regularly assists extraordinary transactions, corporate vehicles with articulated ownership chains, or non-resident clients. It is not a question of professional merit: it is a question of where the risk is concentrated. The practical significance of this step is that everything that follows — internal procedures, controls, staff training, the level of scrutiny required to open a file — derives from it, and without this foundation remains arbitrary.

The self-assessment is not a document written once and filed away. Article 15 requires it to be documented and periodically updated, and paragraph 4 specifies that it must be made available to the authorities and to the self-regulatory bodies when requested at an inspection. Two practical consequences follow, and it is worth fixing them from the outset. The first is that the document must exist in written, dated and retrievable form: at an inspection, what is discussed is not what was thought, but what was written. The second is that updating must be scheduled and not left to goodwill. When the Firm opens a new area of activity, when the composition of its portfolio changes significantly, when staffing changes or new client-acquisition tools are introduced, the document must be revisited and, if necessary, revised. Even an explicit confirmation that nothing has changed has value, provided it is dated: it shows that the periodic review was actually carried out and not simply omitted.

On the organisational point, the Technical Rules approved by the CNDCEC on 16 January 2025 and circulated with Notice No. 6/2025 clarified an issue that had created uncertainty in the practice of associated firms: the self-assessment may be conducted at the level of a professional partnership (STP) or professional association, with a single document covering the organisation as a whole, where procedures, safeguards and information systems are shared. This is a reasonable simplification, since organisational risk is by definition a matter for the organisation. It remains the case, however, that the professional engagement is accepted by the individual professional and that assessments of the individual client remain theirs. To support this work, the National Council has prepared sample documentation — the AV.0-AV.7 templates, realigned and circulated with Notice No. 57/2026 of 26 March 2026 — in which template AV.0 is dedicated precisely to the Firm's self-assessment. It is worth reminding junior colleagues that these templates are not mandatory: they are a framework for reasoning, and using them without having understood them produces a file that is formally tidy and substantively empty. However, in the absence of an alternative format designed with equal care, adopting them is the more prudent choice.

How this applies in practice

  • The Firm's self-assessment document is the first file in the AML system: before opening any client file, staff must know where it is held, in which version and with what date.
  • A record must be kept of periodicity: every review must state the date, who carried it out, and what has changed compared with the previous version, including the case where nothing has changed.
  • If the Firm is organised as an association or as a professional partnership (STP), the self-assessment may be a single document for the whole structure (CNDCEC Technical Rules, 16 January 2025, Notice No. 6/2025), but the file for the individual engagement remains held in the name of the professional who accepts it.
  • Template AV.0 is a sample aid, not an obligation: it should be completed after the reasoning has been carried out, not instead of carrying it out.
  • The document must be retained in a way that allows it to be produced without reconstruction: Article 15, paragraph 4, requires it to be made available in the event of an inspection.

Level 2 · Chapter 08

Identifying the natural person: valid documents, minimum data, particular cases

Frequently asked questions
What is the difference between identifying the client and verifying their identity?
They are two distinct steps that the law holds together within the same provision. Identification consists of obtaining the data that identify the person; verification consists of checking that data against a reliable and independent source, typically a valid identity document (Article 18, paragraph 1, letter a, D.Lgs. 231/2007; Article 19 on the methods). Noting down the name the client states is not verification: verification is the comparison between what the client asserts and what a reliable document shows.
What data must be obtained as a minimum?
First and last name, place and date of birth, residence or domicile, tax code where assigned, and the details of the document used for verification: type of document, number, issuing authority, date of issue and expiry date. These are the details that allow, years later, the exact reconstruction of who the person who presented themselves was, and on what basis they were identified.
Can the document be expired?
No. Verification is carried out on a document that is currently valid: an expired document is no longer a reliable source as to current identity. If the client presents an expired document, a new one must be requested, and the file must retain a copy of the document actually used, not of one presumed to exist.
How should one deal with a minor, or with someone unable to attend in person?
The client remains the minor, but the engagement is accepted by whoever exercises parental responsibility or by the guardian. The minor's identifying data must therefore be obtained, to the extent available given their age, and the person acting in their name and on their behalf must be identified with a valid document, also obtaining the title on which that authority is based. The same approach applies whenever the person presenting themselves at the Firm does not coincide with the client: whoever acts on behalf of another must themselves be identified, and their authority must be verified.

Identifying a natural person is the requirement that seems most straightforward and that, at inspection, most often generates findings — almost always for the same reason: the step was taken without fixing the evidence of it. The Decree requires the client to be identified and their identity verified on the basis of documents, data or information obtained from a reliable and independent source (Article 18, paragraph 1, letter a, D.Lgs. 231/2007), and then regulates the methods by which this check may be carried out (Article 19). In the practice of a firm, this means that when a client presents themselves for the first time, the document is examined, its validity is checked, the photograph is compared with the person present, and the details are recorded. New staff tend to consider recording the details superfluous once a copy of the document has been obtained: this is a mistake in approach. The copy proves that a document exists; the record proves that the document was examined, on a given date, by a specific person at the Firm. These are two different pieces of information, and at inspection both are needed.

The minimum data is not a bureaucratic formality: it is what makes the file reconstructible years later. First and last name, place and date of birth, residence or domicile, tax code where assigned, complete document details. The tax code deserves particular attention, because it is the only element that allows two people with the same name to be reliably distinguished and links the file to all other engagements at the Firm. On acceptable documents, the practical rule is that of valid identity documents issued by a public authority, bearing a photograph: identity card, passport, driving licence, and the equivalent documents provided for under the general rules on administrative documentation. One point that is often lost in the rush should be added: the document must be examined, not merely photocopied. If the photograph is not consistent with the person, if the dates are inconsistent, if the document shows obvious anomalies, the file is not opened and the matter is referred to the professional in charge. Identification is not a mechanical step; it is the first point at which the Firm exercises judgement.

Particular cases are those in which staff must slow down. For a minor, the client is the minor and their identifying data must be obtained to the extent available given their age; the person accepting the engagement, however, is the parent exercising parental responsibility or the guardian, who must be identified with a valid document and whose authority to act must be evidenced. For a foreign national, the typical reference is the passport, supplemented by the residence permit or card where it exists and by the tax code issued in Italy; for EU citizens, the identity document issued by their home state may be used, provided it allows for equivalent identification and is currently valid. Where the document is drawn up in characters or a language that do not allow for a reliable reading, it is advisable to obtain a translation and to note this in the file. In every case, the general principle applies: whoever presents themselves in the name and on behalf of another must be personally identified, and their authority to act must be verified against a document, not against their own statement. However, none of these precautions replaces genuine attention to the individual case: the list of recurring scenarios helps, but does not exhaust the situations that arise at the front desk.

How this applies in practice

  • The file must contain both the copy of the document and the record of its details, with the date on which the check was carried out and the identity of the person who carried it out.
  • Always check the expiry date before accepting the document: an expired document must be replaced, not filed with a reservation.
  • Obtain the tax code where assigned, because it is the element that makes the record unique and linkable to other files.
  • When the person presenting themselves is not the client, open two separate checks: the identity of the person acting and the authority under which they act.
  • Any anomaly found on the document is not resolved at the front desk: it is referred to the professional in charge before proceeding with the engagement.

Level 2 · Chapter 09

Identifying the entity: powers of representation, company register extract, who signs for the company

Frequently asked questions
When the client is a company, what does identifying it actually mean?
It means two things that must be kept separate. The first is obtaining and verifying the entity's identifying data: name, legal form, registered office, tax code and VAT number, registration details with the Companies Register (Article 18, paragraph 1, letter a, D.Lgs. 231/2007). The second is personally identifying, with a valid document, the natural person who presents themselves in the name and on behalf of the company, and verifying their power of representation. The company does not walk into the Firm on its own: someone walks in who claims to be able to act for it, and that person must be identified and their authority verified.
Is the company register extract sufficient on its own?
It is the ordinary starting point and it is a reliable and independent source, but it covers what has been registered and published. When the extract is not sufficient to clarify the powers involved — recent appointments not yet registered, internal delegations within the board, special powers of attorney, statutory limits on amounts — the current articles of association, the minutes of appointment or the power of attorney must also be obtained. The practical rule is that the extract shows who the director is; it is the articles of association and the instruments of appointment that show what that director is authorised to sign.
What about entities not registered with the Companies Register?
For associations, foundations and other entities not registered with the Companies Register, the check is carried out on the deed of incorporation and the articles of association, supplemented by the minutes appointing the current officers and, where it exists, registration in the register held by the competent authority. The logic does not change: a documentary source external to the statement of the person presenting themselves is required.
What should be done if the person signing the engagement letter does not appear to hold that authority?
The file is not opened. An engagement accepted by someone without the relevant authority cannot be attributed to the entity, and the entire due diligence built on that premise is flawed from the outset. Either the instrument granting the authority is requested — resolution, power of attorney, board delegation — or the engagement letter is signed by whoever does hold the authority. The matter is referred to the professional in charge, and the solution adopted must be documented in the file.

With a corporate client, the compliance work splits in two, and the difficulty almost always arises because the two levels are conflated. On one hand there is the entity, which is the client: its identifying data must be obtained and verified against a reliable and independent source (Article 18, paragraph 1, letter a, D.Lgs. 231/2007). On the other hand there is the natural person who presents themselves at the Firm claiming to act for the entity: that person must be personally identified using the same methods as for a natural-person client (Article 19), and it must also be verified that they genuinely have the power to bind the company. Staff who obtain the register extract and stop there have completed half the work; those who identify the director but do not obtain the extract have completed the other half. The file is in order only when both levels are documented and consistent with each other, that is, when the comparison shows that the person identified is the same as the one the corporate instruments indicate as authorised. It is a check of correspondence, not merely an exercise in document collection.

The company register extract is the ordinary source, but it must be read, not merely filed. An up-to-date ordinary extract states the legal form, registered office, capital, ownership structure where registered, the directors in office and the nature of their appointment, and it reports powers to the extent that they have been registered. It is precisely the grey areas that call for attention: appointments resolved but not yet registered, which must be checked against the minutes of the shareholders' meeting; delegations internal to the board of directors, which appear in the board minutes and not always in the extract; limits on value or subject matter that the articles of association place on a managing director's authority; special powers of attorney granted to employees or third parties, the instrument for which must be obtained. The date of the extract must also be checked: a document extracted two years earlier does not describe the current situation, and in verifying the ownership structure and the governing bodies, the snapshot must be taken as at the moment the relationship is opened. For entities not registered with the Companies Register, the reasoning is identical but the source changes: deed of incorporation, current articles of association, minutes appointing the officers in office and, where it exists, registration in the register held by the competent authority.

The question that in practice decides everything remains: who signs? The correct answer is almost never the first one offered. It happens that the reference shareholder presents themselves without holding any office, or the external adviser who has followed the company for years, or a family member of the director. None of these persons, absent an instrument conferring the authority on them, has standing to accept the engagement. The engagement letter must be signed by whoever holds the power of representation under the articles of association and the corporate instruments, and the file must retain a record of the document evidencing that power. It is worth adding a consideration that goes beyond mere formality: the person who presents themselves and the way authority is organised are already useful pieces of information for assessing the relationship. A structure in which the actual decision-maker never appears in the corporate instruments is a fact the professional needs to be able to read, and for it to be readable, staff must have recorded it. However, the anomaly is to be recorded and passed on, not interpreted independently at the point of intake.

How this applies in practice

  • Obtain a company register extract current as at the date the relationship is opened and, where the powers involved are not clear, the current articles of association, minutes of appointment or power of attorney.
  • Personally identify, with a valid document, the person presenting themselves for the entity, and retain the document details, as for any natural person.
  • Verify the correspondence between the person identified and the individual the corporate instruments indicate as authorised: it is this comparison, and not the mere collection of documents, that is the object of the check.
  • For entities not registered with the Companies Register, establish authority on the basis of the deed of incorporation, the articles of association and the minutes of appointment.
  • If signing authority cannot be established, suspend the opening of the file and refer to the professional in charge before any document is signed.

Level 2 · Chapter 10

Remote identification: when it is permitted, the safeguards required

Frequently asked questions
Does identification always require the client's physical presence?
No. Physical presence remains the ordinary method, but Article 19 of D.Lgs. 231/2007 allows identification to take place without the client's physical presence where identity is verified through adequate technical safeguards, meaning digital identity or signature tools that offer a level of security equivalent to direct recognition. This is not a derogation from the obligation to identify: it is a different way of fulfilling it, subject to stricter technical conditions.
Which tools offer these safeguards?
The digital identity and qualified signature tools recognised under Italian law: SPID, electronic identity card, digital signature or qualified electronic signature, and more generally electronic identification systems that provide an equivalent level of assurance. The common feature is that the person's identity has already been established upstream by a qualified party, following verifiable procedures, and that the use of the tool leaves a technical trail attributable to that person.
Are a video call or a photograph of the document sent by email sufficient?
Not on their own. A photograph of a document received by email proves only that someone sent the image of a document, not that the document belongs to the sender or was shown by them. For remote identification to hold up, a technical element must verifiably link the person to the act performed, and that link must remain demonstrable afterwards. The test is not the convenience of the channel, but the strength of the evidence.
What must remain in the file after a remote identification?
Whatever allows a third party, years later, to reconstruct how the identity was established: the tool used, the date and time of the operation, the technical elements documenting the positive outcome of the check, and the identifying data obtained. If the file contains only a statement that the client was identified remotely, the identification cannot be proven and, from an evidentiary standpoint, is equivalent to not having taken place.

Remote identification is the point at which AML regulation meets the way firms actually work. The client who lives in another province, the one operating abroad, the one who simply has no time to come in: these are ordinary situations and the law does not ignore them. Article 19 of D.Lgs. 231/2007 indeed allows the identity check to take place even without the client's physical presence, provided identification is carried out through adequate technical safeguards. The wording deserves close reading, because it does not say that less can be done remotely: it says it can be done differently, provided that method offers a guarantee comparable to direct recognition. The underlying reasoning is straightforward. When the client is in front of us, the guarantee lies in the fact that a member of the Firm has simultaneously seen the person and their document and has confirmed the match. Remotely, that confirmation is missing, and it must be replaced by a technical element performing the same function: reliably linking an already-established identity to the transaction being carried out.

The test is not the channel used, but the strength of the evidence that remains. The tools recognised by the legal system as suitable — SPID, electronic identity card, digital signature or qualified electronic signature, and more generally digital identity systems that provide an equivalent level of assurance — all share the same structure: the person's identity has been established upstream by a qualified party, using documented procedures subject to supervision, and use of the tool produces a technical trail attributable to that person and to that moment. It is this combination, not the electronic method as such, that makes the check acceptable. It follows, conversely, that informal exchanges do not satisfy the obligation: a photograph of an identity card sent by email proves only that someone possesses the image of that document. The same applies to a video call conducted with no technical element fixing and allowing subsequent verification of its outcome: once the call ends, nothing demonstrable remains of that recognition. The difference between a correct procedure and an apparent one lies exactly here.

It is worth fixing the right perspective, because it is the one that matters in the months and years that follow. Identification is not carried out for the moment in which it takes place, but for the moment when someone will ask how it was carried out. Whoever reviews the file at an inspection was not present and can only read what the file contains: they must be able to understand which tool was used, when, with what outcome, and must be able to trace the technical elements documenting that outcome. Hence the attention — which may seem excessive to staff — to the completeness of what is retained: date and time of the operation, tool used, technical references of the check, identifying data obtained. The aim is not to accumulate paperwork, but to make the check traceable by a third party. However, however fully permitted remote identification may be, it remains a method that requires greater documentary discipline than in-person recognition: where a case presents elements of uncertainty, requesting a direct meeting remains the more solid choice and should be discussed with the professional in charge.

How this applies in practice

  • Verify that the tool used falls among those offering adequate technical safeguards under Article 19: digital identity or qualified signature, not a simple exchange of documents by email.
  • Retain in the file the elements that make the check verifiable after the fact: tool, date and time, outcome, identifying data obtained.
  • Do not consider the obligation fulfilled merely by receiving a copy of a document: the copy proves the document exists, not the identity of the person who sent it.
  • Treat a video call as support for the relationship, not as a self-standing method of identification, unless it is embedded in a procedure that fixes and makes verifiable its outcome.
  • If uncertainties emerge about identity or about how the tool works, pause and refer to the professional in charge before completing the opening of the relationship.

Level 2 · Chapter 11

The beneficial owner: threshold, indirect control, residual criterion

Frequently asked questions
Is a shareholder holding exactly 25.00% the beneficial owner?
No, not under the ownership-based criterion. The law requires a shareholding exceeding 25 per cent of the capital (Article 20, paragraph 2, D.Lgs. 231/2007): exactly 25.00% does not exceed the threshold and therefore does not meet the criterion. 25.01% does. This may seem a pedantic point, and it is not: in companies with four shareholders each holding 25%, the ownership-based criterion identifies no one, and it becomes necessary to move to the subsequent criteria. Anyone who reads the threshold as "equal to or greater than" reaches the wrong conclusion and, worse, stops before the work has really begun.
What does indirect shareholding mean?
It means that a shareholding exceeding 25 per cent is not held directly by the natural person, but is held through controlled companies, fiduciary companies, or through an intermediary (Article 20, paragraph 3). In practice, one must trace the ownership chain back to the natural persons at the end of it, multiplying the percentages along the way, rather than stopping at the first corporate shareholder that appears on the register extract. This is the step where most errors concentrate.
If no one exceeds the threshold, is the obligation satisfied?
No, the search continues. Where the ownership structure does not allow the beneficial owner to be identified, one looks to control: whoever holds the majority of voting rights exercisable at an ordinary shareholders' meeting, whoever holds voting rights sufficient to exert a dominant influence at an ordinary shareholders' meeting, whoever exerts a dominant influence by virtue of particular contractual arrangements (Article 20, D.Lgs. 231/2007). Only if this analysis, too, identifies no one does the residual criterion apply, which points to the natural person holding powers of legal representation, administration or management (Article 20, paragraph 5).
Is it enough to record the correct name in the file?
No, and this is the most important point in this chapter. Article 20, paragraph 6, requires a record to be kept of the checks carried out and, where the residual criterion had to be used, of the reasons why the preceding criteria did not allow the beneficial owner to be identified. Reaching the correct result is not sufficient: the path followed to get there must be documented. At inspection, the difference between a robust file and a vulnerable one almost always lies in this trail.

The beneficial owner is the natural person on whose behalf the relationship is established or the transaction is carried out, and, in the case of legal entities, the natural person to whom ownership or control is attributable (Article 1, paragraph 2, letter pp, D.Lgs. 231/2007). Identifying this person is a self-standing element of customer due diligence (Article 18, paragraph 1, letter b) and must be carried out as a staged process, in an order that is not optional. The first criterion is ownership-based: the beneficial owner is the natural person holding a shareholding exceeding 25 per cent of the client's capital (Article 20, paragraph 2). Everything turns on the word "exceeding". A shareholding of exactly 25.00 per cent does not meet the criterion, because it does not exceed the threshold: the shareholder at 25.00% is not the beneficial owner on ownership grounds, while the shareholder at 25.01% is. In practice this scenario is far from rare — four shareholders each at 25%, or two at 25% and other fractional holdings — and it is precisely in these cases that misreading the threshold produces the most insidious error: not a wrong name in the file, but an analysis abandoned before it has genuinely begun.

The relevant shareholding may be direct or indirect, and the indirect case is the one requiring more work. The law also takes into account a shareholding exceeding 25 per cent held through controlled companies, fiduciary companies, or through an intermediary (Article 20, paragraph 3). This means that where the shareholder of a company is itself a company, the extract for the client does not conclude the analysis but opens it: the ownership chain must be traced back to the natural persons at the end of it, multiplying the percentages along each branch and adding together the branches that lead to the same person. A junior staff member tends to stop at the first level and, in good faith, records as beneficial owner the director sitting in front of them; but that record skips the two preceding criteria and is not defensible. If, having exhausted the analysis of the ownership structure, no natural person emerges, the Decree requires that control be examined: whoever holds the majority of voting rights exercisable at an ordinary shareholders' meeting, whoever holds voting rights sufficient to exert a dominant influence at an ordinary shareholders' meeting, whoever exerts a dominant influence by virtue of particular contractual arrangements (Article 20, D.Lgs. 231/2007). Control, in other words, may exist even where ownership is fragmented, and the arrangements that establish it do not always appear on the register extract.

Only where neither ownership nor control identifies anyone does the residual criterion apply, which identifies the beneficial owner as the natural person holding powers of legal representation, administration or management of the entity (Article 20, paragraph 5). It is a closing criterion, designed so that no client is left without a beneficial owner, and it must be used for what it is: the last step of a ladder, not a shortcut. Here comes the provision every member of staff should know by heart. Article 20, paragraph 6, requires a record to be kept of the checks carried out and of the reasons that prevented the beneficial owner from being identified under the preceding criteria. This is the system's safeguard provision: at an inspection, the question is not only who the beneficial owner is, but how that conclusion was reached. A file recording a correct name without showing the path — the register extract consulted, the chain reconstructed, the percentages calculated, the finding that no one exceeds the threshold, the examination of the control criteria and their negative outcome — demonstrates nothing and exposes the professional to a fully justified finding. However, the need to document should not be confused with the indiscriminate accumulation of material: what is required is an orderly, legible trail of the reasoning, not an archive of attachments with no connecting thread.

How this applies in practice

  • Apply the threshold precisely: what counts is a shareholding exceeding 25 per cent (Article 20, paragraph 2). Exactly 25.00% does not meet the ownership-based criterion and requires moving on to the subsequent criteria.
  • Where companies, fiduciaries or persons acting on behalf of others appear among the shareholders, reconstruct the chain back to the natural persons, multiplying the percentages and adding together the branches attributable to the same person (Article 20, paragraph 3).
  • Once the ownership analysis has been exhausted without result, examine control: majority of voting rights at an ordinary shareholders' meeting, voting rights sufficient for a dominant influence, particular contractual arrangements enabling such influence.
  • Resort to the residual criterion of powers of legal representation, administration or management (Article 20, paragraph 5) only after the preceding criteria have genuinely been applied and have produced a negative result.
  • Document the path in the file, not only the outcome: sources consulted with the relevant date, the ownership chain reconstructed, the calculations performed, the outcome of each criterion, and the reasons why the preceding levels did not yield an identification (Article 20, paragraph 6).
  • If the reconstruction does not reach a reasonably certain conclusion, do not complete the record independently: bring the matter to the professional in charge before finalising the file.

Level 2 · Chapter 12

Beneficial owner in hard cases: equal shareholders, cooperatives, trusts and foundations

Frequently asked questions
Two shareholders at 50% each: who is the beneficial owner?
The percentage alone does not answer the question. Neither shareholder exceeds 25% "exclusively" in the sense of evident control, but both comfortably exceed the ownership threshold: both must therefore be assessed, and it must then be verified whether either exercises control within the meaning of Article 20, paragraph 3, of Legislative Decree 231/2007 (decisive voting rights in general meeting, contractual constraints, dominant influence). If the assessment does not produce a clear outcome, the residual criterion of Article 20, paragraph 5, applies, identifying whoever holds powers of representation, administration or management.
How does one proceed in a cooperative with one-member-one-vote?
Capital is not indicative, because weight in the general meeting is per head, not per share. One moves on to the control test (Article 20, paragraph 3) and, failing that, to the residual criterion (Article 20, paragraph 5): the beneficial owner is whoever actually exercises powers of administration or management, typically the members of the management body.
What about foundations and recognised associations?
Article 20, paragraph 4, of Legislative Decree 231/2007 applies, cumulatively identifying the founder, where living, the beneficiaries where identified or readily identifiable, and the holders of powers of legal representation, management and administration.
Do I need to record somewhere how I reached the conclusion?
Yes, always. Article 20, paragraph 6, of Legislative Decree 231/2007 requires a written record of the checks carried out to identify the beneficial owner to be retained. In doubtful cases that record is not a mere formality: years later, it is the only thing that proves an assessment was actually made.

In day-to-day practice, the beneficial owner is identified without difficulty in two cases out of three: there is a shareholder holding 60% or 80%, the ownership chain is short, and the answer is in the company register extract. The hard cases are the others, and they are worth addressing methodically, because they are exactly the cases on which, during an inspection, one is asked to account for the reasoning. The first is the perfectly equal shareholding: two shareholders at 50%, three at a third each, four at exactly 25%. The most common mistake is to conclude that "there is no beneficial owner" because no one prevails. The structure of Article 20 does not allow this shortcut: the ownership criterion is only the first step, and if it does not produce a clear outcome, one moves up to the control criterion (Article 20, paragraph 3, of Legislative Decree 231/2007), which looks at control of the majority of voting rights exercisable at an ordinary general meeting, sufficient votes to exercise a dominant influence, and contractual constraints allowing a dominant influence to be exercised. Only when this test, too, remains unanswered does the residual criterion of Article 20, paragraph 5, apply, identifying the beneficial owner as whoever holds powers of administration or management of the company.

Equal on paper does not mean equal in fact. Two shareholders at 50% may have a shareholders' agreement giving one of them the power to appoint the sole director; or one of the two may be the director with full powers while the other is a silent shareholder; or the articles of association may set enhanced quorum requirements that make each of them capable of blocking a decision but neither capable of making one. These are different situations and lead to different conclusions. In a case of genuine parity, with no agreements and no asymmetry in management powers, the correct conclusion is generally to identify both shareholders as beneficial owners: the concept is not inherently exclusive, and nothing prevents more than one person from being identified. What is not permitted is to leave the field blank, or to fill it in with the director's name for convenience, when the ownership structure would have given an answer.

Cooperatives deserve separate treatment, because the one-member-one-vote principle breaks the link between capital share and decision-making power: a shareholder with a larger contribution carries no greater weight at the general meeting. The ownership criterion, applied mechanically, would therefore return a meaningless figure. One proceeds to the control test (Article 20, paragraph 3) and, in the great majority of cases, arrives at the residual criterion (Article 20, paragraph 5), identifying the members of the management body. Even here the conclusion should not be taken for granted: in a cooperative with few members, or with financing members, or with significant contractual constraints towards a third party, the control test may return a positive result and must be carried out before falling back on the residual criterion. Trusts and foundations follow a structurally different logic, because there is no capital to apportion: what matters are the figures who govern the assets and derive benefit from them — the settlor, the trustee, any protector, the beneficiaries — while for private legal persons Article 20, paragraph 4, identifies the founder where living, the beneficiaries where identified or readily identifiable, and the holders of powers of representation, management and administration. In all these cases the founding instrument, the articles of association and the by-laws are documents to be read, not merely filed away.

What to do in practice

  • Work through the criteria in the order set out by Article 20 and stop at the first one that gives a reasoned answer: ownership, control, residual. If the residual criterion is reached, record why the first two did not produce a conclusion.
  • In equal shareholdings, always ask whether shareholders' agreements, quorum clauses or management delegations exist, and obtain copies: these are the documents that shift the conclusion.
  • For cooperatives, trusts, foundations and recognised associations, obtain the up-to-date articles of association and founding instrument and read the clauses on the appointment of governing bodies, powers and beneficiaries.
  • Draft a brief internal note — even ten lines — accounting for the criterion applied, the documents consulted and the conclusion reached, and keep it in the client file pursuant to Article 20, paragraph 6.
  • Reopen the assessment whenever the shareholding or the management body changes: a conclusion reached three years ago cannot be carried forward without a fresh review.

Level 2 · Chapter 13

Politically exposed persons: who they are, why the question is always asked, enhanced measures

Frequently asked questions
Who falls within the definition of politically exposed person?
Article 1, paragraph 2, letter dd), of Legislative Decree 231/2007 identifies natural persons who hold, or have ceased to hold for less than a year, prominent public functions, together with their family members and persons known to be closely associated with them. It is not a suspect category: it is a higher-risk category, which is a different thing.
Why is the question put to every client and not only to those who "look like a PEP"?
Because verifying the status is part of ordinary customer due diligence and not a reaction to a suspicion. Choosing whom to ask based on personal impression means introducing an arbitrary filter that the law does not provide for, and it inevitably produces omissions. The standard question, put to everyone, is also the easiest to ask: it hints at nothing.
What changes operationally if the client is a PEP?
The measures under Article 25, paragraph 4, of Legislative Decree 231/2007 apply: authorisation from the holders of powers of administration or management (or their delegates) before establishing or continuing the relationship, adequate measures to establish the origin of the wealth and of the funds involved, and ongoing enhanced monitoring of the relationship.
Do the measures automatically lapse a year after the office is vacated?
No. Article 24, paragraph 6, provides that where a high risk is present, enhanced measures continue to apply even to clients who, originally PEPs, ceased to hold office more than a year ago. The passage of the one-year period marks the end of the qualification by definition, not the automatic end of attention.

The question about politically exposed person status is, together with the one on the beneficial owner, the one staff members ask with the greatest discomfort, because it seems to insinuate something. It is worth dispelling that at once: it insinuates nothing. Being a PEP is not an indicator of wrongdoing and is entirely compatible with an irreproachable position; it is simply a condition that, owing to exposure to possible attempts at corruption and to asset visibility, European and national legislation has placed in the higher-risk area. The definition in Article 1, paragraph 2, letter dd), of Legislative Decree 231/2007 covers those who hold prominent public functions and those who ceased to hold them less than a year ago, and it extends to family members and to persons known to be closely associated with the individual: this latter extension is the one most often missed, because the client before us may not be a PEP in their own right yet may be one by association. For this reason the question must be framed so as to cover the family and close-associate perimeter too, not only the personal position of the individual concerned.

The question is asked of everyone, without exception and without prior selection. The reason is practical before it is legal. If the question is put only to those who "seem" to have a public profile, the selection criterion is the staff member's subjective perception, which is by definition incomplete: none of us knows the full composition of the governing bodies of entities and investee companies, still less clients' family ties. Making the question a fixed part of the standard forms achieves two results: it eliminates the risk of omission and strips the question of any personal character, because the client sees it as a box like any other. If the client asks why it is being asked, the correct answer is the simplest one: it is a data point the law requires to be collected for every relationship, regardless of the person. It should also be remembered that the client's answer must be checked against the available sources and not simply recorded: a negative declaration does not discharge the obligation if information in our possession points the other way.

When the answer is positive, the relationship does not automatically open or continue. Article 25, paragraph 4, requires a risk-based procedure to determine whether the client is a PEP and, where they are, prior authorisation from the holders of powers of administration or management (or their delegates): within the Firm this means the position must be referred to the professional in charge before the engagement is accepted, and the authorisation must be formalised in writing and dated, since it must predate the establishment or continuation of the relationship. Next comes verification of the origin of the wealth and of the funds involved in the relationship, which is not satisfied by a generic statement but requires documentary evidence consistent with the scale and nature of the transactions. Finally, ongoing enhanced monitoring, which is the most neglected part: it means a tighter review frequency and a lower threshold of attention to unusual transactions, throughout the life of the relationship. And, as Article 24, paragraph 6, specifies, for high-risk clients attention does not switch off when the year since leaving office expires. However, the reverse should be kept in mind: enhanced measures applied mechanically and without review become as formal as their absence, and must be periodically reassessed on their merits.

What to do in practice

  • Keep the PEP question in the standard forms for every file, worded so as to cover family members and closely associated persons too.
  • Check the answer against the available sources and keep a record of the date and outcome of the check, not merely the client's declaration.
  • If the outcome is positive, suspend acceptance and refer the position to the professional in charge: written authorisation must precede the start or continuation of the relationship (Article 25, paragraph 4).
  • Document the origin of the wealth and of the funds with verifiable evidence consistent with the scale of the expected transactions.
  • Schedule a closer periodic review of the position, and do not close it automatically when the year since leaving office expires if the risk profile is still elevated (Article 24, paragraph 6).

Level 2 · Chapter 14

Purpose and nature of the engagement: amount, method of payment, use of cash and reporting to the MEF

Frequently asked questions
Why is the type of engagement and the intended method of payment asked about?
Because Article 18, paragraph 1, letter c), of Legislative Decree 231/2007 includes among the customer due diligence obligations obtaining and assessing information on the purpose and intended nature of the business relationship or professional engagement. Amount, source of funds and means of payment are elements of that picture, not administrative curiosities.
Is a cash payment of exactly 5,000 euros permitted?
No. Article 49, paragraph 1, of Legislative Decree 231/2007 prohibits the transfer of cash between different parties where the value transferred is, in aggregate, equal to or greater than 5,000 euros. The threshold does not need to be exceeded for the prohibition to apply: reaching it is already sufficient.
If I find in the accounts an invoice paid in cash for an amount not permitted, what must I do?
Report it. Article 51 of Legislative Decree 231/2007 places on anyone who becomes aware, in the exercise of their functions, of an infringement of Articles 49 and 50 the obligation to report it to the Ministry of Economy and Finance within thirty days. It is an obligation triggered by knowledge of the infringement, not by an assessment of its seriousness.
Does the report to the MEF replace the suspicious transaction report?
No: they are two separate mechanisms, with different preconditions, recipients and purposes. The report under Article 51 goes to the Ministry and concerns the objective breach of the limit; the report under Article 35 goes to the UIF and concerns suspicion. The law does, however, provide that the report to the MEF is not due where the transaction has already been the subject of a suspicious transaction report.

The purpose and nature of the engagement are the part of customer due diligence that is filled in worst, because it seems the most obvious: the client comes in for bookkeeping, "bookkeeping services" is written down, and one moves on. In reality, Article 18, paragraph 1, letter c), of Legislative Decree 231/2007 asks for two distinct things — obtaining the information and assessing it — and the assessment presupposes that the information is concrete enough to be compared later with what actually happens. An engagement described in generic terms allows no subsequent comparison, and therefore hollows out ongoing monitoring as well: if what was expected was never written down, nothing can ever appear out of place. For this reason the type of engagement, the expected economic scale, the source of the funds the client operates with and the intended means of payment are all recorded. This is not about interrogating the client: this information emerges naturally from the engagement interview, and it need only be put in writing at the moment it is gathered, not reconstructed from memory months later.

On cash, the rule is strict and admits no relaxed reading. The prohibition in Article 49, paragraph 1, catches the transfer of cash, on any basis, between different parties where the aggregate value transferred is equal to or greater than 5,000 euros (threshold in force since 1 January 2023, paragraph 3-bis); paragraph 2 then sets a separate and lower threshold for money remittance services (1,000 euros), which follows its own rule and must not be confused with the general one. Two points matter more than any other. The first is that the prohibition is triggered on reaching the threshold, not on exceeding it: exactly five thousand euros is already a breach, and the statutory wording "equal to or greater than" leaves no room for interpretation. The second is that the reference is to the aggregate value of the transfer: the provision looks at the transaction as an economic whole, not at the individual cash movement. Our task, when we come across a payment of this kind, is to identify it and report it through the proper procedure; it is not to advise the client on how to structure payments, which would be improper conduct of the engagement and could itself become significant.

The obligation under Article 51 is the one that, in day-to-day practice, generates the most hesitation, because it places the professional in the position of reporting on a client for a matter the client may not consider serious. It must be stated clearly to staff that there is no room here for a discretionary judgement of expediency: whoever becomes aware, in the exercise of their functions, of an infringement of Articles 49 and 50 must report it to the Ministry of Economy and Finance within thirty days, in the manner indicated by the Ministry, and the time limit runs from the moment the information is acquired — typically, the date the document was reviewed in the accounts. The report is not a denunciation and contains no judgement: it sets out the fact and its documentary particulars, and it opens an administrative sanctions procedure that will follow its course before the competent authority. Separate from this remains the suspicious transaction report to the UIF under Article 35, which arises from suspicion and not from an objective breach, with the single point of contact provided for by the law: the report to the MEF is not due where the transaction has already been the subject of a suspicious transaction report (Article 51, paragraph 3). That said, the distinction between the two mechanisms should not be used as a convenient alternative: an irregular cash payment can, depending on the context, be both an infringement to report and an element contributing to a suspicion, and both assessments must be made.

What to do in practice

  • Complete the section on the purpose and nature of the engagement with verifiable information — type of engagement, expected economic scale, source of funds, intended means of payment — and date it at the time it is gathered.
  • Report to the professional in charge, as soon as it is identified, every cash payment equal to or greater than the threshold found in documents received, noting the date of the finding: the thirty days under Article 51 run from there.
  • Prepare the report to the MEF with the documentary particulars of the fact (document, amount, date, parties), without further evaluation, and keep a copy together with proof of submission.
  • Assess separately, not as an alternative, whether the requirements for a suspicious transaction report under Article 35 are met; if a report has already been made on the same transaction, record this in the file.
  • Do not give the client any guidance on how to structure payments: the Firm's role in this matter is to identify, document and report.

Level 2 · Chapter 15

Simplified, standard and enhanced due diligence: how the level is chosen

Frequently asked questions
When can simplified due diligence be applied?
When the risk analysis, carried out on the factors set out in Article 23 of Legislative Decree 231/2007, returns a low risk. The simplification concerns the extent and frequency of checks, not their existence: all the obligations remain, applied in proportionate form.
Is suspicion compatible with simplified due diligence?
No. Where there is suspicion of money laundering or terrorist financing, customer due diligence is due regardless of any derogation, exemption or applicable threshold (Article 17, paragraph 2): low risk presupposes, by definition, the absence of elements that cast doubt on the regularity of the transaction or the relationship.
In which cases is enhanced due diligence mandatory rather than discretionary?
Article 24 of Legislative Decree 231/2007 identifies the high-risk cases in which enhanced measures must be applied, including relationships involving high-risk third countries, cross-border correspondent relationships and relationships with politically exposed persons. The manner of applying the measures is then governed by Article 25.
Must the choice of level be justified in writing?
Yes. Article 17, paragraph 3, of Legislative Decree 231/2007 places on the obliged entity the burden of demonstrating to the competent authorities that the measures adopted are adequate to the risk identified. An undocumented choice amounts, on inspection, to a choice never made.

The three levels of customer due diligence are not three different procedures to choose between as convenient: they are three degrees of intensity of the same procedure, and the degree follows from the outcome of the risk assessment. This is the point that must be fixed before anything else, because the recurring error is to invert the order — deciding how much work to do and then building a risk assessment consistent with that decision. The correct path runs the other way: information is gathered on the client, on the type of engagement, on the geographic area and on the channels used, the risk is assessed, and the level of due diligence follows as a consequence. Article 23 of Legislative Decree 231/2007 allows simplified measures where the risk is found to be low, permitting the extent of the checks and the frequency of updates to be scaled back; Article 24 identifies the high-risk situations requiring enhanced measures; the standard tier is everything in between, and it is the tier into which the large majority of a professional firm's files fall.

Simplified does not mean omitted. This is the costliest misunderstanding, because it produces files lacking identification of the beneficial owner or documentation of the purpose of the engagement, justified after the fact with the formula "it was a low-risk client." Even under the simplified regime, identification must be carried out, the beneficial owner must be identified, the purpose and nature of the engagement must be obtained and assessed, and ongoing monitoring must be exercised: what is scaled back is the depth of the enquiries and the frequency of updates, not the existence of the obligations. It should also be remembered that low risk is a revocable condition: if elements emerge during the relationship that contradict it — transactions inconsistent with the profile, changes in ownership structure, flows towards unexpected jurisdictions — the level must be raised, and the raising must be recorded. And if a suspicion arises, the simplification falls away entirely, because the very premise of low risk no longer holds.

On the opposite side, enhanced due diligence has a mandatory component and a discretionary one, and it is worth keeping them distinct in day-to-day practice. The mandatory component is that of Article 24, which lists situations in which the application of enhanced measures is not a matter for assessment: relationships involving high-risk third countries, cross-border correspondent relationships, relationships with politically exposed persons. In these cases the staff member does not decide, they apply, following the arrangements set out in Article 25. The discretionary component is where the risk assessment, even in the absence of a listed case, returns an elevated profile: opaque corporate structures, activity inconsistent with the declared business, systematic and unjustified recourse to intermediaries. Here the assessment is ours, and precisely for that reason a written justification is essential. Article 17, paragraph 3, reverses the burden: it is not for the authority to prove that the measures were insufficient, it is for the obliged entity to prove that they were adequate to the risk identified. That said, the written justification is not a safe conduct: a stereotyped justification, identical across every file, only shows that the assessment was never really carried out.

What to do in practice

  • Complete the risk assessment before setting the level of due diligence, not after: the level is the outcome, not the starting premise.
  • Under the simplified regime, still carry out all the customer due diligence obligations, reducing the depth and frequency of the checks and recording in writing the factors that led to classifying the risk as low.
  • For every file, check whether one of the high-risk cases under Article 24 applies — high-risk third countries, cross-border correspondence, PEP — in which enhanced measures are due without any discretionary assessment.
  • Keep the risk-assessment record in the file, dated and attributable to whoever completed it, with the specific justification for the level adopted: it is the document that discharges the burden under Article 17, paragraph 3.
  • Update the assessment when new elements emerge and record the move from one level to another, indicating the circumstance that triggered it.

Level 2 · Chapter 16

Relying on third parties: when another professional has already carried out customer due diligence

Frequently asked questions
What can be entrusted to a third party and what cannot?
Article 26 of Legislative Decree 231/2007 permits recourse to third parties for the fulfilment of the obligations under Article 18, paragraph 1, letters a), b) and c): identification of the client and verification of identity, identification of the beneficial owner, and obtaining and assessing information on the purpose and nature of the relationship. Ongoing monitoring under letter d) is excluded and remains with the professional.
What must the third party deliver?
Article 27 requires the third party to issue a written attestation that the obligations have been fulfilled and to transmit the data and documents obtained. An attestation without the supporting documentation does not put the professional in a position to carry out the assessment the law requires of them.
If the third party made a mistake, is the responsibility theirs?
No. Article 28 establishes that ultimate responsibility for fulfilling the obligations remains with the obliged entity that has recourse to the third party. It is the decisive article of the whole section and the one most often overlooked.
Can recourse be had to a third party established in a high-risk third country?
No. Article 29 prohibits relying, for the purposes of customer due diligence, on third parties established in high-risk third countries. The prohibition is objective and cannot be overcome by a particularly thorough attestation.

Recourse to third parties is a facility that simplifies the start-up phase of a relationship and that, read carelessly, produces the most fragile files one can find in a firm: those containing an attestation from a colleague and nothing else. The relevant section comprises Articles 26 to 30 of Legislative Decree 231/2007 and must be read in full, because each article adds a limit to the one before it. Article 26 defines the scope of what is admissible: recourse to third parties is possible only for the obligations under Article 18, paragraph 1, letters a), b) and c), that is, identification and verification of the client's identity, identification of the beneficial owner, and obtaining and assessing information on the purpose and nature of the engagement. Letter d) — ongoing monitoring during the relationship — cannot be delegated, and the reason is clear: ongoing monitoring consists in comparing actual activity against the client's profile, and only whoever manages the relationship can make that comparison. The section closes with Article 30, which keeps outsourcing and agency arrangements distinct from recourse to third parties, as these follow their own logic and do not fall within this regime.

The article to be learned by heart is Article 28. Recourse to third parties transfers an activity, not the responsibility: that remains entirely with the professional who relies on it. Three concrete duties follow from this, which are the operational core of the chapter. The first is to assess whether what has been received is suitable and sufficient for the obligations to be fulfilled: if the attestation is silent on the beneficial owner, or if the documents transmitted have expired, or if the description of the engagement is generic, what has been received is not sufficient and must be supplemented. The second is to verify, with professional diligence, the accuracy and completeness of the documents transmitted: this does not mean conducting an investigation, but applying the ordinary consistency checks that would apply to any document obtained directly. The third is the most important in practice: where there is doubt about the suitability or accuracy of what has been received, the professional proceeds independently with identification, without referring back to the third party and without seeking verbal reassurance. In this area, doubt is not resolved with a phone call: it is resolved by redoing the work.

It is also worth making clear to staff the difference between this arrangement and the simple receipt of documents from a colleague. If another professional sends us the company register extract and identity document of the client because they happen to have them available, we are not within the scope of Article 26: we are simply obtaining documents from a source, and we carry out customer due diligence ourselves in full. Recourse to third parties in the technical sense presupposes that the third party has actually fulfilled the obligations, that they issue the written attestation required by Article 27, and that they transmit the documentation: it is a formal arrangement, to be documented and retained. The prohibition in Article 29 completes the picture by excluding third parties established in high-risk third countries, and this must be verified before the procedure is activated, not afterwards. That said, even where all the conditions are satisfied, the outcome of the operation still falls on us: if, some time later, the file proves incomplete, the fact that the gap originated with the third party does not lessen the Firm's position.

What to do in practice

  • Before activating the procedure, verify that the third party falls among the permitted entities and is not established in a high-risk third country (Article 29).
  • Always request the written attestation required by Article 27 together with the data and documents obtained: the attestation alone is not enough to constitute the file.
  • Subject what has been received to a documented assessment of suitability and sufficiency — coverage of all three delegable obligations, validity and consistency of the documents — and record the outcome.
  • Where doubts arise, proceed directly with identification and verification of identity, recording this in the file (Article 28).
  • In every case, retain in-house ongoing monitoring of the relationship (Article 18, paragraph 1, letter d), which cannot be entrusted to the third party and must be planned from the moment the engagement is accepted.
03

The file over time

Record-keeping, ongoing monitoring, recognising unusual activity, suspicious transaction reporting, sanctions, a complete guided case.

Level 3 · Chapter 17

Record-keeping: what is retained, for how long, in what form

Frequently asked questions
From when do the ten years of retention run?
Not from the date of the document, but from the end of the business relationship or professional engagement, or from execution of the occasional transaction (Article 31, paragraph 3, Legislative Decree 231/2007). For a client followed for twenty years, the file opened at the outset must be retained for ten years after the engagement closes, not ten years from when it opened.
Within what period must the data be entered into the record-keeping system?
Within thirty days, with the date indicated (Article 32, paragraph 2, letter b, Legislative Decree 231/2007). This is a time limit for entry, not for retention: lateness is a separate irregularity even if the data later turns out to be present and correct.
Does the paper file still need to be signed?
No. CNDCEC guidance from 2025 has clarified that for paper-based retention it is sufficient to affix the date, with no need for a signature. What remains fully required is the integrity and non-alterability requirement demanded by Article 32.
Can the data collected for customer due diligence be used for other purposes of the Firm?
No. It may be used for the purposes of the decree and, by express provision, also for tax purposes (Article 34, paragraph 1, Legislative Decree 231/2007). Any other use — starting with commercial or promotional use — is a separate offence in the field of personal data protection, punishable by the Italian Data Protection Authority and entirely distinct from the anti-money laundering sanctions.

Record-keeping is the part of a file that is least visible and that weighs most heavily during an inspection. Article 31 of Legislative Decree 231/2007 sets the term, in paragraph 3, at ten years, but the delicate point is not the duration: it is the starting date. The ten-year period does not run from when the individual document was created, but from the end of the business relationship or professional engagement, and for an occasional transaction, from its execution. In a firm that follows the same client for decades, this means the file never ages while the engagement is live: nothing can be discarded for age, and the archive grows in a straight line. The recurring error runs the other way and is more insidious — closing the relationship and letting the file dissolve among working folders because "the client is no longer with us." It is precisely from that moment that the term begins to run. Article 32 adds the procedural dimension: data and documents must be entered within thirty days, with the date indicated, in systems that guarantee integrity, non-alterability after entry, and complete and timely accessibility to the authorities. Three requirements to be read together, because an archive that is intact but not findable in time does not satisfy the rule any more than one that is accessible but alterable without trace.

The purpose for which the data may be used is not unrestricted. Article 34, paragraph 1, of Legislative Decree 231/2007 establishes that what is retained may also be used for tax purposes, in accordance with applicable provisions: it is an express extension, and precisely because it is express, it defines the boundary. Everything outside it — using the contact details gathered during customer due diligence for a promotional communication from the Firm, feeding a list for commercial initiatives, profiling clients for business development purposes — is processing without a legal basis. It is worth being blunt about this with staff: this is not a "watered-down" anti-money laundering breach, but an offence that sits on its own track, established and sanctioned by the Italian Data Protection Authority, with consequences independent of those provided for under the decree. Article 32 itself, for that matter, refers to compliance with data protection legislation as the framework for record-keeping, not as a parallel obligation.

On the medium, practice has been simplified. For paper archives, CNDCEC clarified in 2025 that it is sufficient to affix the date, with no signature required: a genuine easing, though one that does not touch the substance. A binder in which sheets are added, replaced and reordered without leaving a trace is not a compliant system, however much each sheet bears its own date. That said, the simplification should not be read as an invitation to stay on paper: the timely accessibility required by Article 32 is demonstrated far more easily on a well-organised digital archive, and on inspection the difference between producing a file in a few minutes and reconstructing it over a day falls entirely on whoever holds the records.

In practice, in the firm's file

  • Record the date the engagement ended in the file, explicitly: it is the data point from which the ten years of Article 31 are counted, and without it there is no way to know when the obligation ends.
  • Enter the data into the system within thirty days, with the date, and not at year-end: the window under Article 32 closes quietly and is discovered too late.
  • Verify that the system used — paper or digital — makes any subsequent modification visible; if a document is replaced, keep the previous version as well rather than overwriting it.
  • Keep customer due diligence data separate from archives used for the Firm's communications, and do not feed the latter from the former.
  • On closure of the relationship, close the file as a formal act rather than letting it dissolve among current working folders.

Level 3 · Chapter 18

Ongoing monitoring: when and why the check is repeated, the events that bring it forward

Frequently asked questions
Can ongoing monitoring be entrusted to third parties?
No. It is the only element of customer due diligence entirely excluded from performance by third parties: ongoing monitoring during the business relationship or professional engagement (Article 18, paragraph 1, letter d, Legislative Decree 231/2007) always remains with the professional in charge, even where the other obligations have been fulfilled through third parties as seen in Chapter 16.
How often is the check redone?
The question is wrongly framed. The law does not set a fixed interval: it requires the risk assessment to be renewed for existing clients whenever the actual risk changes (Article 17, paragraph 4, Legislative Decree 231/2007). A periodic deadline is a useful organisational practice, not the obligation itself.
Does a new engagement for a long-standing client require a fresh assessment?
Yes, when the new engagement has different characteristics from the one already in progress. The risk profile is built on the engagement requested too, not only on the client's particulars: once the engagement changes, the assessment must be redone, not inherited.
What is retained from an early re-verification?
The event that triggered it, the date, the information obtained and the outcome in terms of risk level. Without the record of the trigger, all that remains is an update to the particulars; with the record, it becomes proof that ongoing monitoring was actually exercised.

Ongoing monitoring is the part of customer due diligence that lives through time, and precisely for that reason it is the one most easily neglected. Article 18, paragraph 1, letter d), of Legislative Decree 231/2007 places it among the due diligence obligations alongside identification of the client and beneficial owner and the obtaining of information on the purpose and nature of the engagement, but with a different character: it is not an act, it is a professional attitude that lasts as long as the relationship. From this follows a consequence worth fixing firmly for staff, because it connects directly to what was seen in Chapter 16 on the performance of obligations by third parties: the other elements of customer due diligence may, under the conditions set by law, rest on what a third party has already carried out; ongoing monitoring may not, ever. It is the only segment that remains entirely with whoever holds the engagement, and the reason is intuitive — only someone who works the file day by day can see whether the client's reality has shifted. No third party, however qualified, can observe a relationship they do not manage.

Ongoing monitoring is not a monitoring exercise with an expiry date. This is the most widespread misunderstanding in firms: a deadline is set — three years, five years depending on the risk tier — and the obligation is considered discharged by going through the same round of questions when it falls due. A periodic schedule is good organisational practice and helps prevent quiet relationships from being lost track of, but it is not what the rule asks for. Article 17, paragraph 4, of Legislative Decree 231/2007 requires the risk assessment to be renewed for existing clients whenever the actual risk changes: the trigger is the event, not the calendar. A low-risk relationship unchanged for years may reasonably require nothing new; a relationship re-verified three months ago may have to be reopened tomorrow morning if something material has changed in the meantime. That said, one does not exclude the other: the periodic deadline should be kept as a safety net for relationships that give no signals, because the absence of events is not in itself proof that anyone has been looking.

In the practice of a professional firm, the events that justify an early re-verification are few and recurring, and they almost always pass before someone's eyes in the firm before anyone even thinks of anti-money laundering: a change of legal representative or a change in beneficial ownership; an extraordinary transaction — merger, conversion, transfer of a business unit — that redraws the structure or the shareholding; a significant change in the activity actually carried out compared with what was known when the file was opened; the start of a new professional engagement, of a different nature, with a client already followed for other matters. The difficulty, in a firm, is not recognising these events: it is getting them to whoever holds the file. The register extract documenting the change of director comes in for a corporate matter and stops there; the extraordinary transaction is handled by a colleague and never makes its way back to the anti-money laundering file. It is worth surfacing the event immediately, at the moment it is encountered, rather than letting it sit until the periodic re-verification falls due naturally: redoing the assessment a few months early costs little; reconstructing it after the fact in front of an inspection costs a great deal more.

Keeping ongoing monitoring alive

  • Treat the typical events — change of legal representative or beneficial owner, extraordinary transaction, significant change in activity, new engagement of a different nature — as an immediate trigger for re-verification, regardless of the periodic deadline in progress.
  • Establish that whoever encounters the event while working on another matter must report it to whoever holds the file: the internal flow is the real weak point, not the rule.
  • Still maintain a periodic deadline by risk tier, as a safeguard for relationships that give no signals, without confusing it with the requirement of Article 17, paragraph 4.
  • Never let ongoing monitoring rest on what a third party has done: check that the firm's arrangements do not implicitly treat it as discharged together with the other elements of customer due diligence.
  • Record in the file the event that triggered the re-verification, the date and the outcome for the risk level, even when the outcome is confirmation of the previous profile.

Level 3 · Chapter 19

Recognising an unusual transaction: the indicators, without mechanical thresholds

Frequently asked questions
Does exceeding a quantitative threshold require a report?
No. Article 35, paragraph 1, of Legislative Decree 231/2007 requires a report when one knows, suspects, or has reasonable grounds to suspect — regardless of the amount of the funds involved. The UIF instructions of 18 December 2025, in force from 1 July 2026 in place of the 4 May 2011 measure, reaffirm that suspicion is formed through a comprehensive, unified assessment of the client, their profile and the context of the transaction, not through automatic triggering by an amount alone.
Is reporting out of caution, when the doubt is vague, a prudent choice?
No, it is the second form of the same error. The 2025 UIF instructions take a clear position against "reflex" reports, made defensively without an actual assessment: they degrade the informational quality of the reporting flow and do not remedy the omission of the reports that are genuinely needed.
Are the anomaly indicators a checklist to tick off?
They are a reading tool, not an exhaustive checklist. The anomaly indicators published by the UIF (Article 6, paragraph 4, letter e, Legislative Decree 231/2007) and the typologies of unusual conduct (Article 6, paragraph 7, letter b) help bring a doubt into focus; they neither replace it nor exhaust it.
What really matters in forming a suspicion?
The consistency between the transaction and what is known of the client: the activity actually carried out, the economic scale, the stated reasons, the context in which the transaction sits. It is an overall judgement, and it must be formed before asking whether the amount is high or low. Frequent or unjustified recourse to cash transactions, even where it does not exceed the cash threshold, is in itself a ground for suspicion (Article 35, paragraph 1).

This is the hardest topic to teach, because it cannot be resolved with a rule. The guiding principle of the UIF instructions of 18 December 2025 — adopted on 18 December 2025 and effective from 1 July 2026, replacing the measure of 4 May 2011 — is that suspicion is formed through a comprehensive, unified assessment: the client, their profile, the engagement requested and the context in which the transaction sits must be read together, as a whole picture, not as separate items to be checked against parameters. It is a way of saying that suspicion is not a data point, it is a judgement. From this follows a firm rejection of two opposite temptations. The first is quantitative automatism: setting an amount and treating everything above it as suspicious and everything below it as safe — an approach Article 35, paragraph 1, of the decree already excludes at its root, providing for the reporting obligation regardless of the amount of funds involved. The second is the "reflex" report, made out of defensive caution whenever something is not immediately clear, in the belief that over-reporting can never do harm. The instructions place value on the informational quality of the report precisely because the system depends on it: a well-reasoned, detailed report is useful; an empty report consumes analytical capacity that is needed elsewhere.

The mechanical approach and the permissive one fail in the same way. Whoever looks only at amounts is reassured by activity perfectly consistent with the thresholds yet completely inconsistent with the client's economic profile, and is equally alarmed by a large transaction that is fully explained by the activity carried out. Whoever reports to offload responsibility, by contrast, gives up doing the very thing they were engaged for: applying to the specific case a knowledge that no automated system possesses. Both failings share the same root — the idea that professional judgement is a risk to be neutralised — and produce the same effect: the system receives no information. That said, it must be said honestly to staff that a unified assessment does not offer the psychological protection of a numerical rule, and that this makes it demanding: one is left with a judgement to justify, not a box to tick. This is exactly why the written justification, concise but not generic, must be drawn up at the moment of assessment and not reconstructed afterwards.

The tools exist and should be neither ignored nor treated as gospel. The anomaly indicators (Article 6, paragraph 4, letter e, Legislative Decree 231/2007) and the typologies of unusual conduct (Article 6, paragraph 7, letter b), which the decree assigns to the UIF, remain the reference point for interpretation even under the new arrangements, and we look at them more closely in the next chapter. They should be used as a lens: they help bring into focus what has already been half-glimpsed and give a name to a vague sense of unease. They are not an exhaustive list, and consulting them is not the moment suspicion is born — it is the moment it is articulated. Suspicion is born earlier, from the knowledge of the client built up over time, which is precisely the structural advantage a professional firm has over someone who observes only flows.

How to frame the assessment, in practice

  • Start from the profile: what does the client actually do, at what economic scale, for what stated reasons for the transaction. Only afterwards, look at the amount.
  • Frame the question in terms of consistency — is the transaction explicable given what I know of the client? — not in terms of exceeding a limit.
  • When the answer is "I don't know," seek clarification before deciding: the absence of an explanation is itself an element of the assessment, but it must be sought, not presumed.
  • Use UIF indicators and typologies to articulate and test the doubt, never as a checklist substituting for judgement.
  • Bring the case to the internal contact person when the assessment remains uncertain, avoiding both silent filing and a defensive report lacking justification.

Level 3 · Chapter 20

UIF typologies and communications: from general recognition to typical cases

Frequently asked questions
What is the difference between anomaly indicators and typologies of unusual conduct?
The indicators isolate single points of attention (Article 6, paragraph 4, letter e, Legislative Decree 231/2007); the typologies describe recurring configurations, that is, how several elements combine into a typical pattern of conduct (Article 6, paragraph 7, letter b). Both are tools published by the UIF in the exercise of the functions assigned to it by the decree.
Does matching a typology require a report to be made?
No. A match with a typology is one element of the comprehensive, unified assessment required by the UIF instructions of 18 December 2025, not a fact that in itself constitutes suspicion. A pattern may recur for entirely ordinary economic reasons, which the professional is often in a position to know.
Why does a chartered accountant read the typologies differently from a bank?
Because they have information the intermediary lacks: they know the actual activity, the financial statements, the corporate structure, the stated reasons for the choices made. The same pattern that remains an unexplained anomaly for a bank may, for the firm, be fully explained — or, conversely, far more significant.
Is an internal contact person needed even in a small firm?
The 2025 UIF instructions place value on the reporting contact person and the internal procedure as an organisational safeguard. Even where it is not structurally required, identifying a single point of collection within the firm and a written procedure is the good practice that makes the assessment process demonstrable.

Having established that suspicion arises from judgement and not from a checklist, the practical problem remains of giving that judgement a communicable form. This is where the tools published by the UIF genuinely become useful. The anomaly indicators (Article 6, paragraph 4, letter e, Legislative Decree 231/2007) and the typologies of unusual conduct (Article 6, paragraph 7, letter b) — which the decree places among the Unit's functions — are not theoretical material to know for training purposes: they are the distillation of what the system has actually seen recur. The level at which they should be used is that of categories, not the specific case: activity inconsistent with the client's economic profile; frequent recourse to cash unjustified by the activity carried out; complex corporate structures with no apparent economic rationale; interposition of parties with no recognisable role in the transaction. These are deliberately general descriptions, and the generality is not a limitation of the tool: it is its function, because too precise a list would be both easy to circumvent and useless. Whoever consults it looking for a literal match to their own case gets little out of it; whoever uses it to interrogate the case gets a great deal.

The typology is a lens, not a substitute for professional judgement. It is worth insisting on the difference in position between a firm and a banking intermediary, because it is the point at which the chartered accountant's contribution is most distinctive. The bank observes flows and compares them against a declared profile: it reads the pattern, and in many cases has no way of knowing whether an explanation exists. The firm knows the activity actually carried out, has seen the financial statements of previous years, has followed the incorporation or reorganisation of the structure, has heard from the client the reasons for the choices made. The same configuration, read with this knowledge, may resolve into an anomaly that is only apparent — in which case there is nothing to report, but there is something to note — or take on a significance an outside observer would not perceive. That said, direct knowledge of the client is also the factor most likely to lead to underestimation: familiarity with the person makes it natural to find an explanation, and it is worth being aware of this when the explanation arrives too quickly.

The third element is organisational, and the UIF instructions of 18 December 2025, effective from 1 July 2026, expressly value it: the internal contact person for suspicious transaction reports and the internal procedure leading to them. This is not formalism. In a firm where several staff members follow the same client for different matters, doubt almost always arises at the periphery — in whoever keeps the accounts, whoever prepares the return, whoever handles payroll — and needs a channel to reach whoever decides. If that channel does not exist, the doubt stops where it arose, and on inspection no trace remains of either the assessment or its absence. A written procedure, even a brief one, indicating to whom the case is brought, within what time, with what minimum information, and how the outcome is recorded — report or justified filing — is what turns individual awareness into a firm-wide safeguard.

Using typologies and the internal set-up

  • Read UIF indicators and typologies by category, integrating them with what the firm already knows of the client: they are a reading lens, not a checklist to tick off.
  • Verify the economic explanation for the activity before concluding it is anomalous, and be wary of an explanation found too easily out of familiarity with the client.
  • Designate a single contact person in the firm for reports and make them known to all staff, including those who do not directly manage the anti-money laundering file.
  • Put the internal procedure in writing: who receives the case, within what time limit, with what information, and how the outcome is documented.
  • Document filed decisions too: an assessment concluded without a report, if justified and dated, is a safeguard; if not put on record, it is indistinguishable from an omission on inspection.

Level 3 · Chapter 21

The suspicious transaction report: the duty to refrain, the prohibition on informing the client

Frequently asked questions
Are refraining from the transaction and reporting it the same decision?
No, and confusing them is the most common error. Article 42, paragraph 1, requires refraining from establishing the relationship, carrying out the transaction, or continuing the relationship where customer due diligence cannot be completed; the same provision adds that the obliged entity assesses separately whether to make a report to the UIF under Article 35. These are two distinct assessments: one may have to refrain without reporting, and one may have to report even after having already carried out the transaction.
Is there an amount threshold below which no report is required?
No. Article 35 contains no threshold: a report is due when one knows, suspects, or has reasonable grounds to suspect that money laundering or terrorist financing transactions are being carried out, have been carried out or have been attempted, regardless of the amount of the funds involved. The thresholds covered elsewhere in the course (cash, the customer due diligence obligation for occasional transactions) serve an entirely different purpose and play no part in this judgement.
Can I tell the client I am not carrying out the transaction?
Yes, and in many cases it is proper to tell them. Article 39, paragraph 6, clarifies that a professional's attempt to dissuade the client from carrying out an unlawful activity does not constitute a breach of the prohibition on disclosure. What can never be done, in any form, even indirectly, is to let it be understood that a report has been made or is under consideration (Article 39, paragraph 1).
Does the prohibition also apply to requests coming from the UIF?
Yes. The prohibition covers the fact that a report has been made, the transmission of further information requested by the UIF, and the existence or likelihood of investigations or enquiries (Article 39, paragraph 1), and it expressly extends to information flowing back from the UIF (Article 41, paragraph 3). A request for data from the Unit must not be commented on with the client, nor explained to them in any way.

It is worth starting from the distinction that underpins the whole chapter. Refraining from acting is a consequence of the inability to comply: when customer due diligence cannot be completed — the client does not provide the data, the beneficial owner remains unidentifiable, the person executing the transaction does not justify their own powers — the Firm cannot establish the business relationship, cannot carry out the transaction and, if the relationship is already under way, must bring it to an end (Article 42, paragraph 1). It is a rule of professional conduct, not a judgement on the client as a person. The report, by contrast, arises from a different judgement: it concerns suspicion, which may exist even when customer due diligence has been completed perfectly well, and may be absent even when customer due diligence has failed for trivial reasons. The legislator says this expressly in Article 42, paragraph 1 itself, which requires a separate assessment of whether to make a report under Article 35. It is worth adding that Article 42, paragraph 2, governs a further case of mandatory refraining, relating to situations where the client is a fiduciary company, a trust or a similar structure established in high-risk third countries and it proves impossible to identify the beneficial owner: there, refraining does not allow for the discretionary balancing that tends to be applied in other cases.

The report must be made without delay and, as a rule, before the transaction is carried out. Article 35 is clear on both points, and the second is the one most often neglected in firm practice: a late report, submitted once the transaction has already been executed and the funds have already moved, retains very limited informational value. The moment for the decision is when the element of suspicion emerges, not when the file is closed. And it is worth recalling that the requirement under Article 35 is neither proof nor certainty: reasonable grounds for suspicion suffice, assessed also on the basis of the client's subjective characteristics, the activity carried out and the economic consistency of the transaction with the known profile. The staff member who identifies the unusual element does not decide alone: they bring it to the contact person designated by the Firm, with a dated written note, and the decision — to report, or to justify in writing why no report is made — is in any event recorded in the file.

The third pillar is the prohibition on disclosure, known internationally as tipping-off. Article 39, paragraph 1, prohibits disclosing to the client concerned or to third parties that a report has been made, the transmission of further information requested by the UIF, and the existence or likelihood of investigations or enquiries concerning money laundering or terrorist financing. The prohibition is not a recommendation of confidentiality: it is criminally sanctioned, as will be seen in the next chapter, and the offence is constructed so as to catch carelessness as well, not only the intention to warn the client. In firm practice the greatest risk is almost never explicit disclosure: it is the remark made on the phone to justify a delay, the email referring to "anti-money laundering checks under way," the staff member who, pressed by the client, tries to shift responsibility onto some unspecified requirement. These are all indirect forms of disclosure, and all are prohibited.

Here comes the decisive clarification, which needs to be properly understood because it is counter-intuitive. Article 39, paragraph 6, establishes that a professional's attempt to dissuade the client from carrying out an unlawful activity does not constitute a breach of the prohibition on disclosure. In other words: the professional is not required to stay silent about the transaction, only about the report. They can — and generally should — tell the client that a given transaction will not be carried out, that the engagement cannot continue on those terms, that the proposed course of action is not viable. What they cannot do is link that refusal, even by allusion, to a report made or under consideration. The dividing line is sharp and should be kept in mind in these terms: one speaks about the transaction, never about the reporting flow.

What to say, and what not to say

  • Correct wording, usable in writing as well: "I am unable to proceed with the transaction as requested. The professional obligations to which the Firm is subject do not permit me to carry it out or to continue the engagement on this basis. If you wish to proceed differently, I am available to consider a compliant solution with you." It communicates the refusal and its professional grounds, without revealing anything about a report.
  • An equally correct variant, for when the client presses for a reason: "I can confirm that the constraint is not organisational or a matter of timing: it is a compliance constraint concerning the transaction as structured. I have nothing further to add." The close is firm and leaves no room to be filled with allusions.
  • Wording to be avoided absolutely: "we have some anti-money laundering checks under way"; "we were asked for clarification about you"; "we had to make a report"; "look, if I were you I'd leave that account alone for a while"; "a request has come in and I can't tell you from whom." Even the last, seemingly evasive, reveals exactly what Article 39 is meant to keep confidential.
  • No written explanation should be sent to a client without first being reviewed by the Firm's contact person: the text handed to the client is the point at which the prohibition is most easily breached.

The engagement-letter clause, to be inserted beforehand, not afterwards

  • The engagement letter should provide, from the moment of signature, that the effectiveness of the engagement is conditional on the completion of customer due diligence and on the continuation of the conditions allowing it to proceed.
  • Termination should be regulated: form, timing, the fate of matters falling due, return of documentation, fees accrued. Without this provision, refraining translates into an interruption of the engagement with no contractual basis.
  • The practical reason is precise: in the event of a complaint from the client, the Firm will not be able to defend itself by explaining the true reason for the interruption, because Article 39 prevents it. The clause is the only defensible justification and must be drafted before it is needed.
  • A copy of the signed clause should be kept in the file together with the customer due diligence forms, so that the sequence engagement–verification–refraining remains legible years later.

Level 3 · Chapter 22

Sanctions and controls: what the Firm risks, what the professional risks, who supervises

Frequently asked questions
Is failing to carry out customer due diligence a criminal offence?
No. Since 2017, mere non-compliance with the customer due diligence and record-keeping obligations is no longer a criminal offence: it remains an administrative offence (Articles 56 and 57). The criminal offences under Article 55 concern different conduct — falsifying data and information, obtaining or retaining false data, breaching the prohibition on disclosure — and not negligence in performance.
Who imposes administrative sanctions on a chartered accountant?
The Ministry of Economy and Finance (Article 65, paragraph 1), for obliged entities not subject to sector-specific supervision. Not the UIF, which receives reports and carries out their financial analysis, and not the professional board, which operates on a separate disciplinary track. The two paths may proceed in parallel, or only one of them may be activated.
If the Firm has no written internal procedures, is it sanctioned for that?
Not with a standalone pecuniary sanction: the provision on organisational safeguards (Article 62) concerns supervised entities — banks, financial intermediaries, auditors with engagements at public-interest entities — and not non-supervised professionals. The absence of adequate procedures does, however, count as a criterion of seriousness (Article 67, paragraph 1, letter g) and can shift the sanction from the fixed amount to the higher range.
What weighs more heavily than the monetary sanction?
The ancillary measures under Article 66: notification to the self-regulatory body, disqualification from carrying out the function or engagement for between two months and five years, and publication of the sanctioning decree on the Ministry's website for five years. For a professional firm, publication and disqualification have an impact that no monetary amount alone can capture.

The subject of sanctions must be read by separating two levels that common perception tends to conflate. On the criminal level, Article 55 punishes active and specific conduct: paragraph 1 targets anyone who, being required to observe the customer due diligence obligations, falsifies data and information relating to the client, the person executing the transaction, the beneficial owner, or the purpose and nature of the relationship, with imprisonment from six months to three years and a fine from 10,000 to 30,000 euros; paragraph 2 punishes with the same penalty anyone who, being required to observe the record-keeping obligations, obtains or retains false data or untrue information, or uses fraudulent means to undermine proper record-keeping; paragraph 3 extends the same penalty to anyone who, being required to provide the data and information necessary for customer due diligence, provides false data or untrue information — this is the provision that catches the client who lies. These are criminal offences and presuppose intent. Paragraph 4, by contrast, concerns breach of the prohibition on disclosure discussed in the previous chapter and is constructed differently: detention from six months to a year and a fine from 5,000 to 30,000 euros. Being a summary offence, it is also punishable for negligence — carelessness, thoughtlessness, a remark let slip to please someone are enough to satisfy it, without any intention to warn the client being required.

On the administrative level the structure runs on two speeds. Non-compliance with the customer due diligence obligations, including breach of the duty to refrain, is punished with a fixed sanction of 2,000 euros, rising to a range from 2,500 to 50,000 euros where the breach is serious, repeated, systematic or multiple (Article 56). The same structure applies to non-compliance with the record-keeping obligations (Article 57). Failure to make a suspicious transaction report is instead punished with a fixed sanction of 3,000 euros, which in cases of serious, repeated, systematic or multiple breach falls within a range from 30,000 to 300,000 euros; for breaches yielding an economic advantage, an aggravation is provided for, up to twice the amount of the advantage with a minimum of 450,000 euros, or up to one million euros where the advantage cannot be determined (Article 58). Article 63 finally covers breaches concerning the use of cash and failure to report to the Ministry the infringements identified. The gap between the fixed measure and the higher range is the real subject of disputes in this area: it turns entirely on the criteria for setting the sanction under Article 67, which include the seriousness and duration of the breach, the degree of responsibility, the level of cooperation given and — a point of direct relevance to the Firm — the adoption of adequate risk assessment and mitigation procedures.

From this follows a clarification that should be fixed firmly, because it is commonly misunderstood. There is no standalone pecuniary administrative sanction, for a non-supervised professional, for a lack of organisational safeguards: the provision in Article 62, headed precisely "specific sanctioning provisions for supervised obliged entities," is addressed to banking and financial intermediaries and cannot be extended to professionals. It should not, however, be inferred that internal organisation is irrelevant. Self-assessment of risk, written procedures, correctly completed forms, the designation of a contact person for the assessment of reports, and documented staff training are exactly the elements that, when a matter is contested, distinguish an isolated error from a systematic breach: Article 67, paragraph 1, letter g, expressly names the adoption of adequate risk assessment and mitigation procedures as a criterion for setting the sanction. In the first case one is discussing 2,000 or 3,000 euros; in the second, one enters the ranges, and the jump is of one or two orders of magnitude. Procedures, in other words, do not avoid the sanction: they govern its measure, and that is sufficient operational reason to keep them in order.

The disciplinary track runs in parallel and does not depend on the first. Article 66, paragraph 1, provides that, in the case of serious, repeated or systematic breaches, or multiple ones, the Ministry informs the self-regulatory bodies for the purposes of the measures provided for under Article 11, and that the same breaches constitute grounds for the application of disciplinary sanctions under the relevant sector rules; Article 11 assigns to the self-regulatory bodies tasks of promoting and monitoring compliance with the obligations, and the Technical Rules adopted by the CNDCEC (Italy's National Council of Chartered Accountants and Accounting Experts) bind the registered member as such. The practical consequence is that a breach of the Technical Rules can found disciplinary proceedings even in the absence of any administrative sanction from the Ministry: the two paths have separate preconditions, competent authorities and outcomes, and the closing of one does not prejudice the other. Finally, a point should be kept in mind that concerns several members of the Firm's staff personally: whoever sits on a board of statutory auditors or another supervisory body of a client company is subject to their own separate reporting obligations (Article 46), non-compliance with which is punished with a sanction from 5,000 to 30,000 euros applicable to each member (Article 59). That position is not covered by the Firm's overall compliance: the individual board member answers for their own conduct.

What to do in practice

  • Keep the Firm's risk self-assessment updated and dated, and retain successive versions: it is the first document requested in an inspection and the one that places a contested matter in the fixed measure rather than the higher range (Article 67).
  • Keep an internal training log, with dates, content and attendees. Training that is not documented is, for the purposes of an inspection, equivalent to training not given.
  • Check that every file contains the written justification for the level of customer due diligence adopted: the absence of a justification is the gap through which a single omission is classified as systematic.
  • Anyone holding a position on a supervisory body should keep their own schedule and their own record of communications made (Article 46), separate from the Firm's client file.
  • Submit to the contact person, before it is sent, every written communication to a client concerning a transaction not carried out: this is where the offence under Article 55, paragraph 4, is most at risk of being committed.

Level 3 · Chapter 23

A complete worked case: from opening the file to the periodic re-verification

Frequently asked questions
Is the case that follows real?
No. It is a wholly invented textbook case, built for teaching purposes. Names, shareholdings and events are fictional and cannot be attributed to any client of the Firm, either directly or in disguised form. The names are deliberately conventional precisely to make the hypothetical nature of the example clear.
Why an ownership structure with an intermediate holding company?
Because it is the situation in which the search for the beneficial owner stops being mechanical. The shareholding must also be calculated indirectly and, when no natural person exceeds the relevant threshold or exercises control by other means, the residual criterion of powers of administration or management comes into play (Article 20, paragraph 5).
What triggers a re-verification before the ordinary deadline?
Any event that changes the elements on which the assessment was based: in the case proposed, the replacement of the management body, which directly affects the identification of the beneficial owner identified under the residual criterion. Ongoing monitoring is not a fixed-date task, it is a permanent condition of the relationship (Article 18, paragraph 1, letter d).
From when do the ten years of record-keeping run?
From the end of the business relationship, not from the date the file was opened nor from the date of the individual document (Article 31, paragraph 3). This is why the date the engagement closes must be recorded precisely: without that date, the retention period cannot be calculated.

The case that follows is expressly invented and serves only to show, in sequence, mechanisms that the previous chapters treated separately. Alfa Servizi S.r.l. is a small-to-medium-sized business services company that approaches the Firm for ongoing bookkeeping and tax assistance. The shareholding structure is as follows: Gamma Holding S.r.l. holds 80% of the capital, Tizio holds 10%, Caio holds 10%. Gamma Holding, in turn, is held by four natural persons — Mevio, Sempronio, Filano and Caia — each holding 25%. Tizio is the sole director of Alfa Servizi. No shareholders' agreement is declared, no shareholding is held through a fiduciary, no party resides in a high-risk third country. It is an ordinary structure, not an opaque one, and precisely for this reason it is useful, because it shows that applying the residual criterion is not a sign of anomaly, but the normal outcome of an articulated ownership chain.

  1. Step 1 — Acceptance of the engagementThe file opens with the written engagement letter, signed before any activity begins. The engagement letter contains the clause seen in the chapter on refraining: the effectiveness of the engagement is conditional on the completion of customer due diligence, and the form and effects of termination are set out. At this stage no check has yet been carried out: only the contractual basis has been established that will allow the relationship to be terminated, if necessary, without having to explain to the client reasons that Article 39 prohibits disclosing.
  2. Step 2 — Identification of the client and of the person executing the transactionThe client is the company; the natural person who comes to the Firm is Tizio, in his capacity as sole director, and is therefore the person executing the transaction. Both are identified: for the company, name, registered office, tax code and VAT number, object and legal form, taken from the company register extract obtained in copy; for the person executing the transaction, personal details and a valid identity document, in person, with verification of the powers of representation (Articles 18 and 19). Had the engagement been given by a delegate, verification of the powers would have concerned the instrument of delegation, not merely the verbal statement of the person presenting themselves. A copy of the document and of the register extract goes into the file, with the date of acquisition.
  3. Step 3 — Purpose and nature of the relationshipInformation is gathered on the purpose and intended nature of the business relationship (Article 18): type of assistance requested, expected turnover, reference markets, usual settlement methods, presence of dealings with foreign counterparties. This is not a questionnaire to be filed away unread: it is the yardstick against which, in later years, the consistency of observed transactions will be judged. A profile recorded in generic terms makes ongoing monitoring impracticable, because it removes the point of comparison.
  4. Step 4 — Identification of the beneficial ownerHere the case shows its interest. The chain is traced back: each shareholder of Gamma Holding holds an indirect shareholding in Alfa Servizi equal to 80% multiplied by 25%, that is, 20% each; the direct shareholdings of Tizio and Caio stop at 10% each. No natural person therefore exceeds the relevant 25% threshold of the capital, either directly or indirectly (Article 20). One then moves to the criterion of control exercised by other means: shareholders' agreements, special rights, contractual constraints ensuring a dominant influence are checked, and in the case proposed none emerge. With this check, too, exhausted without a clear outcome, the residual criterion applies: the beneficial owner coincides with the natural person holding powers of administration or management (Article 20, paragraph 5), that is, Tizio, the sole director. The operational point, as seen in the chapter on the beneficial owner, is that the outcome must be justified in writing, retracing the three steps in order: the file must show not only who the beneficial owner is, but why they are, and which criteria were excluded first.
  5. Step 5 — Verification of the beneficial owner's identityHaving identified Tizio as beneficial owner under the residual criterion, the Firm must verify his identity as such, and not simply carried over from the identification already carried out in his capacity as the person executing the transaction. In the file the two positions remain distinct, because they can diverge over time: this is exactly what will happen at Step 8. The client's declaration on beneficial ownership is also obtained, without prejudice to the Firm's responsibility not to rely on it alone when the documents tell a different story.
  6. Step 6 — Choice and justification of the level of customer due diligenceThe assessment takes account of the type of client, the geographic area, the activity carried out and the manner in which the relationship is conducted (Article 17). In the case proposed: a resident corporate client, an ordinary services activity, domestic counterparties, traceable settlements, an articulated but transparent ownership structure, no politically exposed person, no connection to high-risk third countries. The outcome is standard customer due diligence, with a note recording the presence of the intermediate holding company as a point of attention — not of elevated risk — to be reconsidered at every update. The justification takes up only a few lines, but it is what, on inspection, distinguishes a choice actually made from a choice merely undergone.
  7. Step 7 — Record-keepingThe file is closed and retained with the completed and signed customer due diligence forms, the register extract, the identity documents, the note on the beneficial owner, the justification for the level adopted and the date of each item obtained. Record-keeping must make it possible to reconstruct afterwards the date, the parties and the content of the activity carried out (Articles 31 and 32), and the ten-year period will run from the end of the relationship. If the Firm adopts digital record-keeping, the digital file must guarantee the same integrity and retrievability requirements as the paper file: the convenience of the archive is not a criterion, retrievability is.
  8. Step 8 — The event that triggers early re-verificationTwo years later, the client reports that Tizio has left office and that management has been entrusted to a board of directors made up of three members, two of whom are outside the shareholding structure. The event is not neutral: since the beneficial owner had been identified under the residual criterion precisely by reason of the powers of administration, the change in the management body changes the outcome under Article 20, paragraph 5. The assessment is therefore reopened without waiting for the ordinary deadline: an updated register extract is obtained, a check is made as to whether the shareholding has also changed in the meantime, the direct and indirect calculation is redone, and, having confirmed the absence of parties above the threshold and of control by other means, the members of the management body are identified as beneficial owners. Each must be identified and their identity verified; the justification note is rewritten and dated, without deleting the previous one, which remains on file to document the reasoning at the time it was made.
  9. Step 9 — Ongoing monitoring in day-to-day managementOngoing monitoring does not end with updating the particulars: it consists in examining the consistency of transactions with the known profile (Article 18, paragraph 1, letter d). If, say, during the third year, movements appeared with no economic justification relative to the declared activity, the correct response is not to update the record: it is to assess the unusual element. If the anomaly prevents customer due diligence from being completed or maintained — for example, because the client does not provide the clarification requested — the duty to refrain applies (Article 42, paragraph 1) and, separately, a report must be assessed (Article 35). If, on the other hand, customer due diligence remains complete but the suspicion persists, a report must still be assessed: as seen in the previous chapter, these are two independent judgements. In both cases, the client is told about the transaction, and never about the report (Article 39).
  10. Step 10 — Closing the cycleThe business relationship ends, whether through termination by one of the parties or the natural conclusion of the engagement. The date of termination is recorded, the return of documentation to the client is noted, and the point from which the ten-year retention period runs is recorded in the file (Article 31, paragraph 3). From that day the file is no longer a live matter, but it remains a document the Firm must be able to retrieve and produce in legible form: this, and not tidiness on the shelf, is the reason the closing date must be recorded with the same care as the opening date.

Key takeaways from this case

  • The residual criterion does not flag a problematic client: it is the ordinary outcome of an ownership chain in which no one exceeds the threshold. What the file must show is the sequence of criteria examined and excluded, not just the final name.
  • Beneficial owner and person executing the transaction are distinct positions even when they coincide in the same person: keeping them separate in the file is what makes re-verification manageable when one of the two changes.
  • Re-verification is not only periodic: it is triggered by events. A change in the management body, in a structure like the one described, is the typical trigger.
  • Every assessment must be dated and retained in the version in which it was made: superseded notes are not replaced, they are kept alongside the new ones.
  • Closing the relationship is a formal act, not a simple discontinuation: without the date of termination, the ten-year retention period has no starting point.

Reference · Glossary

The terms of the course, in one place.

Each entry is also defined in its own chapter; this glossary brings them all together, for anyone looking for a precise definition without having to find the right chapter.

Customer due diligence (CDD)
The set of obligations covering identification of the client and of the person executing the transaction, verification of their identity, identification of the beneficial owner, obtaining information on the purpose and nature of the relationship, and ongoing monitoring during the relationship (Article 18). The intensity with which these must be fulfilled is scaled according to the risk-based approach (Article 17).
Risk-based approach
The principle whereby the extent and depth of compliance activities are commensurate with the risk of money laundering and terrorist financing associated with the individual client, assessed on the basis of client type, geographic area, activity carried out and the manner in which the relationship is conducted (Article 17).
Simplified due diligence (SDD)
A reduced way of fulfilling the obligations, permitted in cases of demonstrated low risk (Article 23): it reduces the extent and frequency of checks, but eliminates neither identification nor ongoing monitoring.
Standard due diligence
The default level of applying the obligations under Article 18, adopted where the risk assessment shows neither the grounds for simplification nor those for enhancement. It is the most frequent level in firm practice and must nonetheless be justified in writing.
Enhanced due diligence (EDD)
An intensified approach, required where risk is elevated (Article 24): obtaining additional information on the client, the beneficial owner and the origin of the funds, involvement of a higher decision-making level, closer monitoring of the relationship (Article 25).
Customer due diligence performed by third parties
The option of relying on due diligence already carried out by another qualified obliged entity (Articles 26-27), obtaining the related documentation. It does not transfer responsibility: the obliged entity relying on the third party remains responsible for the proper fulfilment of the obligations (Article 28).
Remote identification
Identification carried out without the contemporaneous physical presence of the client or the person executing the transaction, permitted only with adequate technical safeguards — digital identity or qualified signature (Article 19).
Person executing the transaction
A natural person delegated to act in the name and on behalf of the client, or to whom powers of representation are attributed. They must be identified and their powers verified on the basis of documentation, not on the declaration alone (Article 18, paragraph 1, letter a).
Beneficial owner
The natural person on whose behalf a transaction is carried out or to whom, ultimately, ownership or control of the entity is attributable (Article 1, paragraph 2, letter pp). Identified according to the criteria of Article 20, applied in order: ownership, control exercised by other means, residual criterion.
Residual criterion
The closing rule for identifying the beneficial owner: where the other criteria do not allow unambiguous identification, the beneficial owner coincides with the natural person or persons holding powers of legal representation, administration or management (Article 20, paragraph 5). The outcome must be justified, recording which criteria were excluded (Article 20, paragraph 6).
Indirect shareholding
A share of an entity's capital held through controlled companies, fiduciaries or an interposed party (Article 20, paragraph 3), calculated by multiplying the percentages along the ownership chain. It must always be computed together with the direct shareholding when checking whether the relevant threshold is exceeded.
Politically exposed person (PEP)
A natural person who holds, or has held for less than a year, prominent public functions, together with their family members and persons known to be closely associated with them (Article 1, paragraph 2, letter dd). The status implies no negative judgement: it triggers the application of enhanced measures (Article 25, paragraph 4).
Obliged entity
An entity subject to the anti-money laundering obligations. Within the category of professionals, this includes chartered accountants and accounting experts (Article 3, paragraph 4, letter a), who operate as non-supervised entities and are therefore subject to the sanctioning powers of the Ministry of Economy and Finance (Article 65, paragraph 1).
Ongoing monitoring
The continuous examination of transactions carried out during the relationship, to verify their consistency with the obliged entity's knowledge of the client, their activity and their risk profile, with updating of the data held (Article 18, paragraph 1, letter d). Cannot be delegated to third parties.
Duty to refrain
The obligation not to establish the relationship, not to carry out the transaction, or to end an existing relationship where customer due diligence cannot be completed; a separate assessment must at the same time be made as to whether to file a report (Article 42, paragraph 1). Paragraph 2 provides for further cases of mandatory refraining.
Suspicious transaction report (STR)
A communication sent to the UIF without delay and, as a rule, before the transaction is carried out, where one knows, suspects, or has reasonable grounds to suspect that money laundering or terrorist financing transactions are being carried out, have been carried out or have been attempted (Article 35). No amount threshold excludes or triggers it.
Tipping-off (prohibition on disclosure)
The prohibition on disclosing to the client or to third parties that a report has been made, related information, requests for further detail from the UIF, and the existence of investigations or enquiries under way (Article 39, paragraph 1), extended to information flowing back from the UIF (Article 41, paragraph 3). It does not prevent attempting to dissuade the client from carrying out an unlawful activity (Article 39, paragraph 6).
Reporting contact person
The person designated within the Firm to receive anomalies identified by staff, assess them and decide on reporting. Their documented designation contributes to the adequacy of safeguards relevant under Article 67.
UIF — Italy's Financial Intelligence Unit
The authority established within the Bank of Italy (Article 6), the recipient of suspicious transaction reports, responsible for their financial analysis. It does not impose administrative sanctions on professionals: that power belongs to the Ministry of Economy and Finance (Article 65, paragraph 1).
Anomaly indicators
Lists of symptomatic elements that the UIF issues and periodically updates to facilitate the identification of suspicious transactions (Article 6, paragraph 4, letter e). They are aids: their presence does not require a report and their absence does not exempt from the obligation, which remains grounded in the overall assessment of the case.
Typologies of unusual conduct
Models developed and circulated by the UIF describing recurring configurations that may relate to possible money laundering or terrorist financing activity (Article 6, paragraph 7, letter b), distinct from individual anomaly indicators.
Risk self-assessment
A periodic, formalised and dated analysis with which the Firm identifies and examines the money laundering and terrorist financing risk to which it is exposed, in relation to its clientele, the services provided and its operating methods, defining the resulting safeguards (Article 15).
Ten-year retention
The obligation to retain documents, data and information obtained for ten years from the end of the business relationship or from execution of the occasional transaction, in a manner allowing the date, parties and content of the activity carried out to be reconstructed (Article 31, paragraph 3, and Article 32).
Report to the MEF
The obligation to report to the Ministry of Economy and Finance, within thirty days, infringements of the restrictions on the use of cash identified in the course of the activity (Article 51). Breach of the obligation, like breaches concerning cash, is subject to administrative sanction (Article 63).
Self-regulatory body
The representative body of the professional category to which the law assigns tasks of promoting and monitoring compliance with the obligations by its members (Article 11). For chartered accountants and accounting experts, this is the National Council of the category and the local professional boards.
CNDCEC Technical Rules
Implementing provisions adopted by the self-regulatory body (Article 11, paragraph 2), binding on registered members as such. In force since 16 January 2025 (CNDCEC Notice No. 6/2025). Their breach can found disciplinary proceedings even in the absence of an administrative sanction from the Ministry.
AV.0-AV.7 forms
A series of templates prepared to accompany the Technical Rules (realigned and communicated by CNDCEC Notice No. 57/2026 of 26 March 2026) to document the stages of customer due diligence — from assessing client risk to identifying the beneficial owner, through to justifying the level adopted. Illustrative, not mandatory.
Money laundering
Conduct consisting of the conversion, transfer, concealment or use of property derived from criminal activity, for the purpose of disguising its unlawful origin, as well as participation in such conduct.
Self-laundering
The use, substitution or transfer into economic, financial or business activities of money or property derived from an offence committed by the same person who reinvests it, in a manner apt to disguise its origin.
Terrorist financing
The provision or collection of funds, by any means, intended to be used to carry out acts for terrorist purposes, regardless of whether the origin of the funds is lawful or unlawful. The lawfulness of the origin does not exclude the relevance of the conduct.
Administrative sanction (professionals)
A pecuniary sanction imposed by the Ministry of Economy and Finance: a fixed 2,000 euros for failure to carry out customer due diligence or breach of the duty to refrain, rising to a range from 2,500 to 50,000 euros in serious cases (Article 56); an analogous structure applies to record-keeping (Article 57); a fixed 3,000 euros for failure to report, rising to a range from 30,000 to 300,000 euros in serious cases (Article 58).
Ancillary measures
Consequences accompanying the sanctioning decree: notification to the self-regulatory body, disqualification from carrying out the function or engagement for between two months and five years, publication of the sanctioning decree on the Ministry's website for five years (Article 66).
Obligations of supervisory bodies
Separate and autonomous reporting duties borne by members of boards of statutory auditors and other supervisory bodies of client companies (Article 46), non-compliance with which is punished with a sanction from 5,000 to 30,000 euros applicable to each member (Article 59). These are not absorbed by the Firm's overall compliance.

AI utility on this page

Ask a question about the pathway.

The chat can help you understand a chapter, a cited article, or a glossary term. It does not access client files, does not replace the professional's judgement, and never provides guidance on how to avoid a control or a report.

Do not enter client names, tax codes, VAT numbers, identifying data, or details of a real case. Keep data to the minimum necessary and consult the privacy notice for this automated service.

Notice. Content checked against sources current as of the date shown, with the text as published on Normattiva verified directly. This pathway is for internal training purposes and does not constitute professional advice, nor does it exhaust the examination of an individual case, which always remains a matter for the professional in charge. This area of law is subject to frequent updates — Regulation (EU) 2024/1624 will apply from 10 July 2027 and will amend, among other things, the criteria for identifying the beneficial owner and the cash-use thresholds: where in doubt, or before a decision is taken, always check the most recent version with the Firm.

Deadline calendar Install the app