Between October 2025 and August 2026, the sanctions committee of Monaco's financial intelligence and supervisory authority (Autorité monégasque de sécurité financière, AMSF) issued ten decisions. They concern two banks, an asset manager, three corporate service providers, two real estate professionals, a yacht broker and a precious metals dealer, with sanctions ranging from EUR 7,000 to EUR 6 million. Read together, they set out a consistent reading of customer due diligence obligations. This reading concerns every regulated professional, and every business that enters into a relationship with one.
The framework
Law No. 1.362 of 3 August 2009 requires, before any business relationship, identifying the customer, any agent and the beneficial owners, verifying that information and understanding the ownership and control structure of a legal entity (Art. 4-1).
Information on the purpose of the relationship is proportionate to the risk, but information on the source of the customer's wealth must be "supported by reliable documents, data or sources of information" (Art. 4-3).
Ongoing monitoring follows, which also covers the source of funds where necessary (Art. 5). Where these identification and due diligence obligations cannot be met, the relationship may be neither established nor continued (Art. 7).
The intensity of these measures varies with the risk. They may be simplified for a low-risk relationship, after a satisfactory risk analysis and in the absence of suspicion (Art. 11). They are enhanced where the risk is high, in particular for a politically exposed person, for whom both the source of wealth and the source of funds must be established (Arts. 12-2 and 17). The AMSF's guidelines add that the consistency between the source of wealth and the source of funds "must be analysed and recorded in the customer file".
The decisions create no new obligation. They show what is sufficient and, above all, what is not.
1. Risk sets the depth of due diligence, not whether it is done
A corporate service provider argued that only high-risk files required supporting documents, a customer's statement being enough for the others. The argument was rejected: collecting documents on the customer's socio-economic background applies to the whole customer base, "regardless of its risk level, which can only be assessed once that information has been collected" (decision of 22 December 2025, No. 2025/3199).
A decision issued the same day faulted another provider for assigning a risk level to prospects before obtaining the essential identification and corroborating information (No. 2025/3171).
The risk-based approach also works the other way. Applying the same measures to all customers is not a risk-based approach, even when those measures are strict: identical alert thresholds for every customer ignore the profile of each relationship, because "a uniformly prudent threshold remains an undifferentiated threshold" (decision of 25 August 2026, No. 2026/0537).
The same decision noted risk-scoring sheets kept on a spreadsheet, with no date and no formal approval. A risk level whose date and author cannot be established demonstrates nothing.
For the most exposed relationships, the standard of proof rises. In a file rated high risk, no document corroborated the profession or the income declared by the customer; the committee held that the institution "was required to carry out enhanced due diligence to establish the source of wealth and of funds" (decision of 28 April 2026, No. 2025/3827).
Likewise, a customer's mere statement about their politically exposed status, without analysis or a screening tool, does not amount to a compliant system (decision of 22 December 2025, No. 2025/3196).
2. An ownership chain must be proven, not drawn
The committee recalled that regulated entities must verify "not only the existence but also the ownership and control arrangements" of each entity in a complex structure. This does not require systematically collecting the articles of every intermediate company, but it is not met without documentary evidence establishing the chain of ownership and control "reliably and exhaustively" (No. 2025/3827).
A register extract or a certificate showing that a company exists therefore does not establish the ownership links between entities, and the organisation charts produced were found to be "declaratory and not probative". The same decision found a breach for lack of proof of address for a beneficial owner: identification also covers the address.
Another decision noted the absence of identification documents for four persons involved in a complex structure (No. 2026/0537).
3. A customer's statement proves nothing on its own
What the customer asserts must be corroborated.
- Bank confirmation letters and reference letters do not establish the socio-economic background and source of wealth "through figures that are reliable, up to date and usable"; a beneficial owner's tax return remains "a mere declaratory document" (No. 2025/3199).
- Neither internal know-your-customer notes, nor information from public sources, nor essentially declaratory documents are sufficient "on their own" (decision of 30 June 2026, No. 2026/0458).
- Informal checks, bank reference letters or internet searches are not enough to justify the source of a tenant's funds (decision of 18 November 2025, No. 2025/2147). Websites are not, in any event, among the reliable sources (No. 2025/3827).
- For regular cash withdrawals by a high-risk customer, a bare reference to funding their lifestyle does not show that the consistency of those withdrawals was assessed (No. 2026/0537).
The AMSF's 2025 annual report identifies the same weakness in a transaction settled in cryptocurrency: the beneficial owner's wealth rested on "purely declaratory" information.
4. Relying on another professional does not transfer responsibility
A real estate agency relied solely on the notary's checks for the source of funds (No. 2025/3196).
A yacht broker had independent brokers collect its customers' socio-economic background (decision of 18 November 2025, No. 2025/2145).
An asset manager entrusted the due diligence on its high-risk customers to a bank within its group, with no contractual means of overseeing how it was carried out (No. 2026/0537).
The law allows reliance on a third party under certain conditions, but it leaves "ultimate responsibility for compliance with the obligations" with the professional who relies on it (Art. 8). A check carried out by someone else does not replace one's own.
5. When due diligence is done matters as much as what it contains
The committee assesses due diligence "in the light of the measures actually carried out and documented on the date on which they were required" (No. 2026/0458).
Know-your-customer notes written two to five years after onboarding (No. 2026/0458), a certified copy obtained after onboarding (No. 2025/3827), a tax notice dated eight years after the start of the relationship (No. 2025/3199): none of these cures the file.
The finding runs through most of the decisions: training completed, procedures rewritten or files remediated after the inspection cure nothing.
The committee even noted that the cost of remedying a breach, raised in defence, "confirms its existence and its extent" (No. 2025/3171). Long-standing knowledge of a customer does not replace the formal checks required at onboarding either (No. 2025/2147).
6. What this means in practice
For a regulated professional, the decisions outline a method:
- collect and corroborate the socio-economic background before rating the risk, and rate the risk before accepting the relationship;
- date and approve the rating, then derive genuinely differentiated measures from it;
- document the ownership chain entity by entity, up to the natural persons;
- corroborate every statement with a document from a reliable source and, where the risk is high, establish the source of funds;
- carry out one's own checks, even where a notary, a bank or an intermediary has already been involved.
For a client company, the law already provides the essentials: registered companies must obtain and keep "adequate, accurate and current" information on their beneficial owners, with the corresponding supporting documents (Art. 21). In practice, a complete file includes:
- a recent extract from the Trade and Industry Register and the up-to-date articles of association (Sovereign Order No. 2.318 refers, for identification in the presence of the representative, to documents less than three months old, Art. 5);
- the extract from the register of beneficial owners;
- for each intermediate entity, a document establishing ownership (register of members, share certificate, deed of transfer), not merely an organisation chart;
- a recent identity document and proof of address for each beneficial owner;
- quantified evidence of the source of wealth and, where the relationship presents a high risk, of the source of the funds involved: deed of sale, inheritance, tax notice, annual accounts.
Where the relationship is established remotely, the requirements are stricter: copies of two official documents bearing a photograph, and a first transaction through an account opened with a regulated institution, unless an electronic identification means with a substantial or high assurance level is used (Law, Art. 13; Sovereign Order No. 2.318, Arts. 5 and 25).
Conclusion
The ten decisions do not concern obscure obligations. They sanction the gap between a file that describes and a file that proves, and between a stated risk level and genuinely adapted due diligence. For professionals and their clients alike, the useful question is no longer "is the information in the file?" but "where does it come from, when does it date from, and what was done with it?".
Anthony Raymond · September 2026
General information, not legal advice. Quotations from the decisions and guidelines are our translation of the French originals. For a question about your situation: contact form.
Sources
- Law No. 1.362 of 3 August 2009, Arts. 4-1, 4-3, 5, 7, 8, 11, 12-2, 13, 17 and 21; Sovereign Order No. 2.318 of 3 August 2009, Arts. 5 and 25 (Legimonaco).
- AMSF, generic guidelines (Lignes directrices génériques), version 2 of 21 April 2026, § 1.5.2 and Annex A.
- AMSF, 2025 annual report.
- Decisions of the AMSF sanctions committee (amsf.mc/sanction): No. 2025/2144 of 29 October 2025; Nos. 2025/2145 and 2025/2147 of 18 November 2025; Nos. 2025/3171, 2025/3196 and 2025/3199 of 22 December 2025; No. 2025/3827 of 28 April 2026; No. 2026/0458 of 30 June 2026; No. 2026/0438 of 8 July 2026; No. 2026/0537 of 25 August 2026.