Skip to content Skip to footer

Who oversees your " AML-CFT " program based on your profession?

A compliance officer generally knows what the AML-CFT requires of them. They are less likely to know who will conduct the audit, what scope it will cover, and how detailed it will be. The answer depends on the entity’s status: the same oversight system is reviewed by the ACPR at an insurer, by the AMF at an asset management firm, by the National Gaming Authority at a licensed operator, and by a professional regulatory body at a notary’s office. This article maps out this breakdown and specifies what each authority examines in practice.

 

Why does the supervisor depend on status rather than obligation?

Anti-money laundering and counter-terrorism financing obligations apply to all regulated professions. The basic framework is the same: customer due diligence, risk classification, screening against sanctions lists and politically exposed persons (PEPs), and reporting suspicious activity to Tracfin. What varies is not the rule itself, but the authority responsible for enforcing it.

This breakdown is not random. It stems from the very structure of financial supervision in France, where each sector has a regulator responsible for prudential supervision, consumer protection, and compliance AML-CFT. A banking institution falls under the ACPR’s jurisdiction because the ACPR already oversees its prudential activities. An asset management firm falls under the AMF’s jurisdiction for the same reason.

A Common Set of Obligations

The European Directive on the prevention of the use of the financial system for the purposes of money laundering and terrorist financing establishes a single framework. This framework is transposed into the Monetary and Financial Code. All regulated professions must identify their customers, verify the identity of the beneficial owner, exercise risk-based vigilance, conduct sanctions list screening, and report suspicious transactions.

What differs from one profession to another is the timing of due diligence, the threshold that triggers it, and the format of the evidence. A notary exercises due diligence at the outset of each transaction; a casino triggers it as soon as a customer makes a purchase or cashes out 2,000 euros; a credit institution maintains it continuously across its entire portfolio. The principle, however, remains the same: know your customer, assess the risk, monitor, and report.

 

Map of Government Agencies by Profession

The following table breaks down the regulated professions by supervisory authority. This is not an exhaustive list, but rather an overview of the main sectors.

Occupation or industry Supervisory Authority AML-CFT Foundation
Bank, credit institution ACPR Art. L. 612-1 CMF
Payment Institution, Electronic Money Institution ACPR Art. L. 612-1 CMF
Digital Asset Service Provider (DASP) AMF Art. L. 54-10-5 CMF
Portfolio management firm, financial investment advisor AMF Art. L. 621-9 CMF
Insurer, mutual insurance company, insurance broker ACPR Art. L. 612-1 CMF
Licensed online gaming operator National Gaming Authority Art. L. 561-36 CMF
Notary, attorney, bailiff, judicial officer Professional body (CSN, CNB, CNCEJ) Art. L. 561-36 CMF
Certified Public Accountant, Statutory Auditor Professional Association (CSOEC, H3C) Art. L. 561-36 CMF
Real estate agent, property manager DGCCRF Art. L. 561-36 CMF
Dealer in valuable goods, jeweler, antique dealer General Directorate of Customs and Indirect Taxes

DGCCRF

Art. L. 561-36 CMF
Casino National Gaming Authority Art. L. 561-36 CMF

Banking, Payments, and Electronic Money

Credit institutions, payment institutions, and electronic money issuers are regulated by the Prudential Supervision and Resolution Authority (ACPR). The ACPR supervises not only their financial soundness but also their compliance systems AML-CFT. It has the authority to conduct both off-site and on-site inspections and may impose penalties for any violations, including periodic penalty payments, monetary sanctions, or the revocation of authorization. Its three main missions are prudential supervision, consumer protection, and compliance oversight AML-CFT.

Asset Management and Investment Advisory Services
 

Asset Management and Investment Consulting

Portfolio management firms, financial investment advisors, and digital asset service providers are regulated by the Autorité des marchés financiers (AMF). The AMF oversees their entire compliance framework, including customer due diligence, screening, and the reporting of suspicious activity. Each year, it publishes a summary of its audits related to AML-CFT, which details the most frequently identified areas of concern.

The difference between the AMF and the ACPR lies in the scope of their supervisory activities. The AMF supervises financial market participants and systemically important non-bank financial institutions (PSANs), while the ACPR supervises banks and insurance companies.

Insurance, Mutual Insurance, and Distribution

Insurance companies, mutual insurance companies, pension funds, and insurance brokers are subject to ACPR oversight. Supervision AML-CFT covers the entire distribution chain, from the insurer to the intermediary. Insurance brokers are subject to the same regulations as direct insurers. The oversight focuses on due diligence during underwriting, risk classification, and the handling of alerts.

Legal and Accounting Professions

Notaries, attorneys, judicial officers, certified public accountants, and public auditors are subject to the oversight of their respective professional bodies. The High Council of Notaries, the National Bar Council, the National Chamber of Judicial Officers, the High Council of the Order of Certified Public Accountants, and the High Council of Auditors exercise o AML-CFT e oversight within their respective jurisdictions. These bodies submit an annual activity report to Tracfin.

Real Estate, Gaming, and Trading in Valuable Goods

Real estate agents and property managers are subject to oversight by the General Directorate for Competition, Consumer Affairs, and Fraud Control (DGCCRF) regarding compliance with their obligations under the “ AML-CFT ” law. Online gaming operators and casinos are subject to oversight by the National Gaming Authority. Dealers in high-value goods, jewelers, and antique dealers fall under the jurisdiction of the General Directorate of Customs and Indirect Taxes as well as the DGCCRF. Each authority carries out its oversight in accordance with the procedures specific to its sector.

 

What an Audit Actually Examines

The areas examined are consistent across regulatory agencies. An auditor verifies that the system exists, is being implemented, and that its operation can be reconstructed. The review aims, in particular, to determine whether the regulated entity has its risks under control, is effectively implementing its system, and is able to justify its decisions.

Risk Classification and Its Rationale

The first issue examined is risk mapping. The regulated entity must have classified its clients, products, and relevant geographic areas according to their risk level. The method may be manual or automated, but it must be based on explicit criteria. The auditor will request to review the criteria, the classification grid, and the breakdown of the portfolio by risk level.

Consistency between the classification and the monitoring measures is subject to careful review. A customer classified as high-risk must be subject to enhanced monitoring measures. If the classification does not result in any differentiated action, the system is incomplete.

Traceability of Due Diligence

The second point concerns traceability. For each case reviewed, the auditor must be able to reconstruct the steps taken: who performed the screening, on what date, using which database, and with what result. Documented manual processing remains acceptable. However, reconstructing a decision made several months earlier requires locating the relevant document and the person involved.

A specialized system time-stamps the screenings, records the reasons for triggering alerts, and updates the lists automatically. Traceability does not guarantee compliance, but it does demonstrate that due diligence was exercised and clarifies the basis for such diligence.

Reconstructing a Decision

The third point concerns the justification for decisions. Why was an alert lifted without a statement? Why was a client classified as low risk despite exposure related to a “ PEP ”? The auditor may request access to the audit trail—that is, all the information needed to trace the checks performed, the reasons for the decision, and the identity of the person who approved it.

What is being examined is not the tool itself, but the audit trail it generates. A sophisticated tool that does not document its decisions does not meet this requirement. Conversely, a simple tool that allows each step to be reconstructed does meet it.

Alert Handling and Response Time

The fourth point concerns the handling of alerts. A screening process that generates alerts without analyzing them within a reasonable time frame indicates a failure. The auditor will note the number of pending alerts, the average processing time, and the most common reasons for clearing them.

An effective system reduces false positives and speeds up the processing of relevant alerts. The false-positive reduction engine is based on fuzzy logic and precise configuration. More than 90 configuration criteria allow the screening process to be tailored to the entity’s risk profile.

 

The Expected Evidence: What You Need to Be Able to Show

The regulator expects documentation that is proportionate to the circumstances. For a client posing a standard risk, the file may include, among other things, an up-to-date client profile, the required identification information, and the supporting documents necessary given the circumstances. For a high-risk client, the file must also include information regarding the source of funds, the beneficial ownership structure, and the reasons for the classification.

With regard to politically exposed persons, the regulated entity must be able to demonstrate that it has verified the status of the customer and his or her close associates, identified the source of the funds, and obtained approval from a senior manager. Without this approval, the enhanced due diligence is incomplete.

With regard to international sanctions, the entity must be able to demonstrate that it conducted a screening against the lists in effect at the time the business relationship was established. It must also demonstrate that its system takes into account changes to the applicable lists and ensures appropriate monitoring of the portfolio. A one-time screening at the outset is not sufficient if the system does not provide for ongoing monitoring.

 

What a Well-Equipped System Changes

A tool-based system does not replace the obligation to exercise due diligence. It changes the nature of the evidence and reduces the workload. What used to take several hours per case when processed manually can be reduced to just a few minutes using automation, provided the settings are configured correctly.

the traceable audit trail
 

The Reconstructable Audit Trail

A well-documented manual process can meet the auditor’s requirements. However, reconstructing a decision made several months earlier requires locating the document, verifying which version of the sanctions list was used at that time, and justifying why the alert was lifted. A system with the right tools time-stamps each screening, retains the version of the list used, and records the reason for lifting the alert. The audit trail can thus be reconstructed without manual intervention.

Explainability to the controller

Augmented Intelligence differs from black-box engines in terms of traceability. A black-box engine can provide a risk score without explaining the criteria on which it is based. A glass-box engine documents every criterion, every weighting, and every rule applied. The auditor can then verify that the settings correspond to the regulated entity’s risk profile.

The AP Scan, AP Scoring, AP Monitoring, and AP Filter solutions are based on this explainable AI logic. Each decision can be justified criterion by criterion. While this does not guarantee compliance, it does make it possible to demonstrate compliance.

 

How do you determine which agency you fall under?

In most cases, the regulatory status is sufficient to identify the supervisory authority. An authorized credit institution falls under the jurisdiction of the ACPR, a portfolio management company falls under the jurisdiction of the AMF, and a notary falls under the jurisdiction of the High Council of Notaries. The table in Section 2 summarizes this breakdown.

Three Questions to Ask Yourself

Three questions can help clear up most doubts. The first concerns the exact regulatory status of the entity. A crowdfunding intermediary falls under the jurisdiction of the ACPR, while a crowdfunding investment advisor falls under the jurisdiction of the AMF. The nature of the business matters, but the entity’s registration or licensing status determines which authority has jurisdiction.

The second question is whether the organization has been accredited or is listed in a professional registry. If so, the authority that issued the accreditation or maintains the registry is generally the one responsible for ensuring compliance AML-CFT. Otherwise, the organization may fall under the jurisdiction of a professional body or the tax authority.

The third question concerns the business line. A single group may have several subsidiaries that fall under the jurisdiction of different regulatory authorities. A banking holding company is regulated by the ACPR for its lending activities, but its asset management subsidiary is regulated by the AMF. The scope of supervision follows that of the regulated business.

 

Frequently Asked Questions

Who oversees a company's " AML-CFT " program in France?

The supervisory authority depends on the status of the regulated entity. Banks, payment institutions, and the insurance sector fall under the jurisdiction of the ACPR; portfolio management firms fall under the jurisdiction of the AMF; licensed online gaming operators fall under the jurisdiction of the National Gaming Authority; and legal and accounting professionals fall under the jurisdiction of their respective professional bodies. While the due diligence obligations are the same for all, their oversight is not.

Are the requirements under the “ AML-CFT ” the same for all professions?

The basic framework is the same: identify the customer and the beneficial owner, classify the risk, exercise proportionate due diligence, screen against sanctions lists and politically exposed persons lists, and then report any suspicions. What varies is the point at which due diligence is exercised, the threshold that triggers it, and the format of evidence expected by the relevant regulatory authority.

What does an inspector look for first during an inspection of AML-CFT ?

The issues examined are consistent across regulatory agencies. They include risk classification and the rationale for its criteria, the traceability of due diligence performed, the ability to reconstruct a past decision, and the turnaround time for handling alerts. In particular, the auditor will seek to determine why an alert was resolved and what factors underpinned that decision. A consistent but undocumented system remains difficult to defend.

How can I find out which authority oversees my organization?

Three questions are usually sufficient: What is the organization’s exact regulatory status? Does it hold a license or is it listed in a professional registry? And which sector of activity is involved? The status determines which authority has jurisdiction, not the nature of the activity. The same service may fall under the jurisdiction of different regulatory bodies depending on the legal structure chosen.

Does having the right tools make a difference when it comes to monitoring?

It changes the nature of the evidence. Documented manual processing remains admissible, but reconstructing a decision made several months earlier requires locating the relevant document and the person involved. A system equipped with the necessary tools time-stamps the screenings, retains the reasons for clearing alerts, and updates the lists automatically. What is examined is not the tool itself, but the audit trail it generates.

Would you like to take stock of your AML-CFT compliance program? Our teams analyze your risk profile and identify priority areas for attention based on your status and the regulatory authority to which you report.