Source: OJ L, 2024/1624, 19.6.2024

Current language: EN

Article 33 Simplified due diligence measures


Summary What does Article 33 of the Anti-money laundering regulation (AMLR) say?

This article sets out the rules governing simplified due diligence, which is the lighter-touch alternative to the standard customer due diligence measures established elsewhere in the regulation.

Where a business relationship or transaction is assessed as presenting a low degree of risk, obliged entities are permitted to scale back their due diligence obligations in a number of ways — for example, by delaying identity verification, reducing the frequency of monitoring, or collecting less information on the purpose of the relationship.

The article is careful to balance this flexibility with clear guardrails: simplified measures must be proportionate to the risks identified, ongoing monitoring must still be sufficient to detect suspicious activity, and the conditions for applying simplified measures must be reviewed regularly.

Crucially, the article also specifies the circumstances in which simplified due diligence must be abandoned entirely, such as where doubts arise about the accuracy of customer information or where money laundering or terrorist financing is suspected.

Important points:

  • Apply simplified due diligence measures only where risk factors from the relevant annexes support a low-risk determination, and document those decisions in your internal procedures.
  • Even under simplified due diligence, carry out sufficient transaction monitoring to detect unusual or suspicious activity — the reduced regime does not suspend this obligation.
  • Cease applying simplified due diligence immediately if the low-risk conditions no longer hold, inconsistencies in customer information emerge, or any suspicion of money laundering, terrorist financing, or sanctions evasion arises.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Where, taking into account the risk factors set out in Annexes II and III, the business relationship or transaction present a low degree of risk, obliged entities may apply the following simplified due diligence measures:

      1. verifying the identity of the customer and the beneficial owner after the establishment of the business relationship, provided that the specific lower risk identified justified such postponement, but in any case no later than 60 days of the relationship being established;

      2. reducing the frequency of customer identification updates;

      3. reducing the amount of information collected to identify the purpose and intended nature of the business relationship or occasional transaction or inferring it from the type of transactions or business relationship established;

      4. reducing the frequency or degree of scrutiny of transactions carried out by the customer;

      5. applying any other relevant simplified due diligence measure identified by AMLA pursuant to Article 28.

    2. The measures referred to in the first subparagraph shall be proportionate to the nature and size of the business and to the specific elements of lower risk identified. However, obliged entities shall carry out sufficient monitoring of the transactions and business relationship to enable the detection of unusual or suspicious transactions.

    1. Obliged entities shall ensure that the internal procedures established pursuant to Article 9 contain the specific measures of simplified verification that shall be taken in relation to the different types of customers that present a lower risk. Obliged entities shall document decisions to take into account additional factors of lower risk.

    1. For the purpose of applying simplified due diligence measures referred to in paragraph 1, point (a), obliged entities shall adopt risk management procedures with respect to the conditions under which they can provide services or perform transactions for a customer prior to the verification taking place, including by limiting the amount, number or types of transactions that can be performed or by monitoring transactions to ensure that they are in line with the expected norms for the business relationship at hand.

    1. Obliged entities shall verify on a regular basis that the conditions for the application of simplified due diligence measures continue to exist. The frequency of such verifications shall be commensurate with the nature and size of the business and the risks posed by the specific relationship.

    1. Obliged entities shall refrain from applying simplified due diligence measures in any of the following situations:

      1. the obliged entities have doubts as to the veracity of the information provided by the customer or the beneficial owner at the stage of identification, or they detect inconsistencies regarding that information;

      2. the factors indicating a lower risk are no longer present;

      3. the monitoring of the customer’s transactions and the information collected in the context of the business relationship exclude a lower risk scenario;

      4. there is a suspicion of money laundering or terrorist financing;

      5. there is a suspicion that the customer, or the person acting on behalf of the customer, is attempting to circumvent or evade targeted financial sanctions.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod