2026-08-17
Added · Updated
Regulated entities must establish and maintain risk-sensitive policies, controls, and procedures covering customer due diligence, reporting, record-keeping, internal control, risk assessment, compliance management, and employee screening. These measures must be proportionate to the nature and size of the business, with an independent audit function required to assess compliance with Section 26(1) of the Proceeds of Crime Act 2015. Entities with branches or subsidiaries must implement group-wide policies meeting Gibraltar standards, including information sharing and confidentiality safeguards. When outsourcing systems and controls, regulated entities retain ultimate responsibility for compliance and must conduct due diligence, risk assessments, and maintain contingency plans.
Get GFSC alerts — same-day email on every new publication.
www.gfsc.gi
8. Policies, Procedures &
Controls
AML/CFT/CPF Guidance Notes
August 2026
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 2
Table of Contents
8.1 Establishment and Maintenance of Policies and Procedures......................................................... 3
8.2 Independent Audit .......................................................................................................................... 4
8.3 Powers to Require Information and Production of Policies and Procedures Documentation ....... 4
8.4 Branches or Subsidiaries.................................................................................................................. 5
8.5 Systems and Controls...................................................................................................................... 5
8.6 Outsourcing Systems and Controls.................................................................................................. 6
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 3
8.1 Establishment and Maintenance of Policies and Procedures
AML/CFT/CPF Requirements
R24 A regulated entity must establish and maintain appropriate and adequate risk-sensitive policies, controls and procedures. Such policies, controls and procedures must be proportionate to the nature and size of the regulated entity’s business. A regulated entity will be responsible for establishing, implementing and maintaining these, including enhancing these where higher risks have been identified. Guidance
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 4
7. Additionally, a regulated entity must establish procedures which help employees determine
whether a customer or a beneficial owner of a customer is a politically exposed person, family member or close associate of a PEP 6 .
8. It is essential that all directors, senior managers, MLROs and employees within a regulated entity
be fully acquainted with and understand the regulated entity’s policies and procedures, particularly when such policies and procedures have been prepared by a third-party.
8.2 Independent Audit
AML/CFT Requirements
R25 A regulated entity is required to undertake an independent audit in order to assess its AML/CFT/CPF policies, procedures and controls in ensuring compliance with the requirements listed under Section 26(1) of POCA. The independent audit must have regard to the size and nature of the business which will determine the frequency and scope of the assessment. Guidance
9. A regulated entity must undertake an independent audit function for the purposes of testing the
policies, controls, and procedures as stated in 8.1, and which has regard to the size and nature of the business 7 .
10. The frequency and scope of the independent audit function is to be determined by the regulated
entity applying a risk-based approach in line with the size and nature of its business. This must be considered on an ongoing basis.
11. The independent audit function must be performed by individual(s) who are operationally
separate from the regulated entity’s compliance function. It is the ultimate responsibility of a regulated entity to ensure the independence of those performing this function. The independent audit may be performed by an individual within the firm or externally, having regard to the independence of the role.
12. It is the responsibility of a regulated entity’s senior management to monitor and review the
effectiveness of its independent audit function and ensure that any outcomes, findings or deficiencies identified are addressed accordingly. The requirement to carry out an independent audit and its scope, including any deficiencies identified from one, must be reported to the board and documented accordingly.
13. A regulated entity may demonstrate that it has tested the effectiveness of its policies, procedures
and controls by producing periodical reports which show that compliance with its policies and procedures is being monitored. The reports should highlight any deficiencies that have been identified in light of the independent review, as well as any details of actions taken by the regulated entity in demonstrating its commitment to address these shortcomings.
8.3 Powers to Require Information and Production of Policies and Procedures
Documentation
14. Each regulated entity has a duty to make its policies and procedures available to the GFSC as and
when required in accordance with Regulation 12(1) of the SBPR.
Section 26(2)(c), Proceeds of Crime 2015
Section 26(1A), Proceeds of Crime Act 2015
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 5
8.4 Branches or Subsidiaries
15. If a regulated entity has branches or subsidiaries, it is required to implement group-wide policies
and procedures that apply to all its branches and majority-owned subsidiaries within its group which must, as a minimum, meet Gibraltar standards and requirements. These should include the following 8 :
a. Policies, controls and procedures, as those mentioned in 8.1; b. Policies and procedures for sharing information required for the purposes of satisfying the customer due diligence requirements within the group;
c. The provision, at group-level functions, of customer, account and transaction information
from branches and subsidiaries, where necessary, for the purposes of AML, CFT and CPF, which shall include, to the extent permitted under the Data Protection Act 2004 –
i. Information about transactions or activities which appear unusual; and
ii. Any analysis carried out in respect of transaction or activities which appear
suspicious, including the content of any report made to the GFIU or the underlying information where such disclosure is made in confidence and would not cause tipping-off of the customer. d. Adequate safeguards on the confidentiality and use of the information exchanged under customer due diligence requirements, including safeguards to prevent tipping-off; and e. The provision of information from group-level functions to branches and subsidiaries where relevant and appropriate to the management of the risks of ML, TF and PF.
16. The “group-level” functions referred to above, relate to any functions concerning compliance,
audit or AML/CFT/CPF controls 9
.
8.5 Systems and Controls
17. A regulated entity must have systems and controls in place to be able to identify, assess, monitor
and manage ML, TF, and PF risks. These controls must be proportionate to the nature, size and complexity of the regulated entity’s business and activities.
18. A Regulated entity is required to regularly assess its systems and controls in order to ensure that
it continues to comply with the requirements under POCA.
19. When implementing systems and controls to detect and prevent financial crime, a regulated
entity needs to identify the ML, TF, and PF risks which it may be exposed to by considering its customers, distribution channels and the volume and complexity of its transactions. A regulated entity must therefore ensure that it has systems and controls in place which covers all these areas, including those mentioned under Section 26 of POCA.
20. In order for a regulated entity to establish and maintain appropriate and effective systems and
controls, it must:
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 6
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 7 ultimately liable for all systems and controls implemented, regardless of the outsourcing arrangement in place 11 .
24. It is the responsibility of a regulated entity to ensure that any third-party provider maintains
appropriate and satisfactory AML, CFT and CPF systems and controls on its behalf. The regulated entity must also ensure that the relevant policies, controls and procedures remain up-to-date and align with any changes to domestic legislation, as well as any appropriate guidance issued.
25. If a regulated entity has decided to outsource its systems and controls, wholly or partly, its
policies, procedures, systems, and controls should include when outsourcing will be permitted, and under what conditions.
26. The GFSC expects regulated entities to conduct appropriate due diligence on the potential service
provider before entering into an outsourcing arrangement. The regulated entity should properly determine whether the service provider has the relevant expertise and has the appropriate authorisation or registration required to perform the service.
27. Regulated entities are advised to carry out a risk assessment before entering into an outsourcing
agreement with a service provider. In a proportionate manner, a regulated entity must assess the potential risks of all third-party arrangements, including outsourcing arrangements, regardless of materiality. As part of the risk assessment, the GFSC expects firms to also consider operational and financial risks.
28. Regulated entities should have contingency plans in place in the event of an outsourcing
agreement being suddenly terminated, failure of the outsourced provider to perform, or the insolvency of the outsourced provider.
29. Regulated entities are still expected to implement appropriate systems, processes and controls
so that their board, senior management and regulated function holders have sufficient oversight in respect of all outsourcing arrangements and are satisfied that any risks arising from these arrangements are appropriately mitigated. A regulated entity is required to ensure compliance with its outsourcing obligations under POCA and these Guidance Notes. For further guidance on outsourcing arrangements, please refer to the various GFSC Outsourcing Guidance Notes available on our website. . Sector-specific Guidance – Virtual Asset Service Providers (“VASPs”)
30. A regulated entity operating as a VASP (either as an authorised DLT Provider or registered VASP)
must implement virtual asset screening controls in order to identify any association between its customer wallet addresses and potential illicit activity.
31. Virtual asset wallet addresses may be subject to financial sanctions in the same way as individuals
and legal entities. When engaging with the wallet address of a customer, a regulated entity must therefore ensure to screen the respective wallet address to ensure that it is not subject to any relevant designations. 11 Section 23(4), Proceeds of Crime Act 2015
Published by:
Gibraltar Financial Services Commission
PO Box 940
Suite 3, Ground Floor
Atlantic Suites
Europort Avenue
Gibraltar www.gfsc.gi
© 2017 Gibraltar Financial Services Commission
Read the rest free
Source: Gibraltar Financial Services Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from GFSC
We email you every new GFSC publication the day it's published.