Group-wide policies and third-country branches: managing conflicting laws under the AMLR
Articles 16 and 17 AMLR require parent undertakings to implement group-wide policies, including information sharing, and to manage branches in third countries whose law is less strict or forbids the group policy.
Cet article n'est pas encore disponible dans cette langue ; l'original anglais est affiché. La traduction suit automatiquement.
A group with entities in several countries has always had to reconcile one AML policy with many national laws. The AMLR makes the group dimension explicit: Article 16 requires the parent undertaking to implement group-wide policies, procedures and controls, and Article 17 sets what to do where a branch or subsidiary in a third country cannot apply them. AMLA's Guidelines on group-wide policies are in final draft.
What group-wide means
- One set of policies covering the risk assessment, customer due diligence, monitoring, reporting and record keeping, applied by every entity in the group that is an obliged entity.
- Information sharing within the group for AML purposes, including on suspicious transactions where the AMLR allows it, with safeguards for confidentiality and data protection.
- A group compliance function that coordinates the entity-level functions, with a group compliance manager.
Third-country branches and subsidiaries
Where the law of a third country is less strict than the AMLR, the entity in that country applies the group policy anyway. Where the third country does not permit the group policy, the parent must inform the home supervisor and apply additional measures to manage the risk, up to closing or restricting the business. The Guidelines describe what additional measures look like: enhanced monitoring from the parent, limits on products, independent reviews.
Data protection
Information sharing within a group across borders meets the GDPR and, for third countries, the transfer rules. The AMLR provides the legal basis for sharing for AML purposes but does not remove the need for transfer mechanisms and access controls.
What to do now
- Map the group: which entities are obliged entities, under which law, with which supervisor.
- Decide which policies are mandatory group-wide and which allow local variations, and document the reasoning.
- For each third-country entity, test the group policy against local law and record the outcome; that record is what the home supervisor will ask for.
The dashboard tracks the group Guidelines under Governance; the readiness tracker has blocks for governance and group-wide policies.