2026-08-17
Added
Regulated entities must implement effective measures to identify and report suspected money laundering, terrorist financing, or proliferation financing internally to a Money Laundering Reporting Officer and externally to the Gibraltar Financial Intelligence Unit via the Themis portal. Staff members are required to report suspicions immediately, while the MLRO must assess reports and submit Suspicious Activity Reports to the GFIU without delay if grounds for suspicion exist. The guidance mandates that all records of suspicions and investigations be retained for a minimum of five years and prohibits tipping off subjects of reports, with specific exemptions for intra-group communications and disclosures to supervisory bodies.
Get GFSC alerts — same-day email on every new publication.
www.gfsc.gi
11. Suspicious Activity
Reporting
AML/CFT/CPF Guidance Notes
August 2026
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 1
Table of Contents
11.1 Identification of Suspicion.................................................................................................................... 2
11.2 Internal Reporting ................................................................................................................................ 2
11.3 External Reporting................................................................................................................................ 3
11.4 Failure to Disclose................................................................................................................................. 4
11.5 Tipping-off ............................................................................................................................................ 4
11.6 Data Subjects, Access Rights, Suspicious Activity Reports and the Data Protection Act ..................... 5
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 2
11.1 Identification of Suspicion
AML/CFT/CPF Requirements
R30 A regulated entity must have effective measures in place to be able to identify and report any suspicious activity both internally and externally whenever money laundering, terrorist financing or proliferation financing is suspected. Guidance
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 3
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 4
10. A regulated entity must ensure its disclosures to the GFIU contain sufficient information about the
suspicious activity, along with the grounds for suspicion, to facilitate the GFIU’s assessment and potential investigation. The report should clearly document and state the suspected criminal activity which will allow for dissemination to the appropriate authority.
11. In cases where additional relevant evidence is available, it should be included in the disclosure. The
Themis reporting system provides a platform for uploading any supplementary information/evidence in various formats.
12. Upon receipt of all disclosures, the GFIU will acknowledge receipt and in some instances, written
consent may be granted in cases where it is deemed appropriate for a regulated entity to continue providing services to the relevant parties. However, under exceptional circumstances (such as when a beneficial owner or a related party faces imminent arrest or asset restraint), consent may not be granted. In such cases, the regulated entity will be informed of the situation and must comply with any direction provided by the GFIU or another authority.
13. Where a regulated entity has submitted a SAR to the GFIU, or in the instance where the regulated
entity is aware that a client or transaction is under investigation, it should not destroy any relevant records without the agreement of the authorities, even if the five-year retention period has expired.
11.4 Failure to Disclose
14. A person may be found guilty of an offence if there is knowledge, suspicion or other reasonable
grounds to suspect that a customer may be engaging in money laundering, terrorist financing or proliferation financing and it is not reported.
11.5 Tipping-off
15. A regulated entity must ensure that staff members are aware of their obligations in respect of the
tipping off provisions defined under Section 5(1) of POCA.
16. A person is guilty of an offence if after the disclosure of a SAR, they share information which would
prejudice the investigation or inform the subject that a disclosure has been made to the GFIU or law enforcement agency 4 .
17. A person shall not incur any liability under this section where the disclosure is made between
regulated entities to which this Act applies, and which are members of the same group. This also applies to situations between a regulated entity and its branches and majority-owned subsidiaries located in third countries, provided that those branches and majority-owned subsidiaries fully comply with the group-wide policies and procedures, including procedures for sharing information within the group.
18. Under the provisions of POCA 5
, it is not deemed a tipping-off offence for an individual to disclose or provide information to the GFIU, a police or customs officer or a supervisory body. A regulated 4
Section 5(2) – Proceeds of Crime Act 2015.
5
Section 5(2A) – Proceeds of Crime Act 2015.
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 5 entity is able to disclose information to supervisory bodies concerning both internal and external SARs.
11.6 Data Subjects, Access Rights, Suspicious Activity Reports and the Data
Protection Act
19. A regulated entity may receive a request for access to personal data held by a regulated entity as a
data controller under Section 14(38) of the Data Protection Act, some of which data may be relevant to an investigation or a suspicious activity report received by the GFIU in relation to money laundering/terrorist financing/proliferation financing.
20. Under the Data Protection Act, an individual can request access to their personal data, including
any information about its source. However, the Data Protection Act exempts personal data from being disclosed if doing so could prejudice crime prevention or detection, or the apprehension and prosecution of offenders. This exemption generally includes the requirement to furnish information about any suspicious activity reports, or other relevant data relating to an investigation.
21. If a regulated entity relies on this exemption, data controllers should provide all other relevant data
held on file relating to the subject - the exemption only relates to any information which could tip off or prejudice an ongoing investigation. If a regulated entity decides to withhold information under this exemption, it is not obligated to inform the individual about the withheld data. The information can be omitted from the response to the data request without any reference to it. Example – Branches, Subsidiaries & Passporting
22. When a regulated entity operates in multiple jurisdictions, it is the entity's responsibility to
determine if dual reporting is necessary according to the applicable laws and regulations of each jurisdiction.
23. Where a regulated entity is passporting from another jurisdictions or is operating as a branch or
subsidiary of another regulated entity within Gibraltar, it is mandatory to report all suspicious activities related to the activities of the Gibraltar branch or subsidiary to the GFIU.
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 6 Published by:
Gibraltar Financial Services Commission
PO Box 940
Suite 3, Ground Floor
Atlantic Suites
Europort Avenue
Gibraltar www.gfsc.gi
© 2017 Gibraltar Financial Services Commission
Read the rest free
Source: Gibraltar Financial Services Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from GFSC
We email you every new GFSC publication the day it's published.