If you are responsible for compliance at a CySEC-regulated entity, two developments from the last year have quietly raised the bar for how your sanctions screening must work — and, just as importantly, how you evidence that it works. This note explains what changed and what a supervisor now expects to see.

Two instruments, one direction of travel

Directive R.A.D. 282/2024, published on 5 August 2024, amended the CySEC Directive for the Prevention and Combating of Money Laundering and Terrorist Financing. Among other changes, it tightened the definition of an “identification document”, replaced the video-call onboarding derogation with a maximum annual deposit threshold, and expressly aligned client due diligence with the economic sanctions imposed by the United Nations and the European Union.

Then, on 27 February 2025, CySEC issued Circular C685 — a practical guide to effective and efficient sanctions screening systems. Unlike a directive, the circular does not create new legal obligations; it tells you how the regulator will judge whether you are meeting the ones you already have. It is the more revealing of the two documents, because it is built directly on what CySEC found when it looked.

What the thematic inspections found

Between April and November 2024, CySEC conducted thematic inspections across Cyprus Investment Firms (CIFs), Administrative Service Providers (ASPs), funds and fund managers, and crypto-asset service providers (CASPs), testing screening against UN, EU, US and UK measures. The recurring weaknesses it reported should be read as a checklist of what to fix:

  • Weak fuzzy matching. Systems failed to catch manipulated or misspelled sanctioned names — the single most-cited deficiency.
  • Settings left untouched. Many entities did not realise their screening thresholds could be adjusted to improve accuracy at all.
  • False-positive overload. Excessive alerts overwhelmed review teams and obscured the matches that mattered.
  • Gaps in automation. Some entities relied on manual checks, inviting human error and missed hits.
  • Inadequate testing and calibration. Firms rarely tested or re-tuned their tools, so configurations drifted out of date.

What CySEC now expects

The circular sets out supervisory expectations that map onto those findings. In practice, a well-run screening function should be able to demonstrate each of the following:

  • Real-time, ongoing screening against updated sanctions lists — not periodic or ad-hoc reviews. A client cleared at onboarding must be re-checked as the lists change.
  • Detection of name variations — misspellings, transposed or missing words, altered dates of birth, and transliteration differences — not merely exact matches.
  • Regular testing and calibration of the tool, tuned for both effectiveness (catching true hits) and efficiency (containing false positives).
  • Clear governance — documented sanctions-compliance policies, senior-management oversight and an identifiable team responsible for screening.
  • Defined regulatory scope — screening that addresses UN Security Council Resolutions and EU Council Decisions and Regulations, at minimum.

The thread running through C685 is evidence. It is no longer enough for screening to happen; you must be able to show, on demand, that it happens well and that you test whether it does.

A practical checklist

Ahead of your next inspection, it is worth being able to answer, with documentation:

  1. Which lists do we screen against, and how quickly do updates to those lists reach our screening?
  2. Can our tool catch a deliberately misspelled or transliterated sanctioned name? When did we last test that?
  3. How are our matching thresholds set, who set them, and on what basis?
  4. Who reviews alerts, and how do we record the outcome of each one?
  5. Where is the dated, auditable record for each screening decision kept?

The last point is where most remediation effort ends up. Real-time screening and fuzzy matching are capabilities of the tool; the audit trail is a discipline of the process — and it is the first thing a supervisor asks to see.

Where a purpose-built tool helps

Much of what C685 asks for is difficult to satisfy with a spreadsheet or an occasional manual check. It is the reason our firm built FIRMCY, an AML screening platform designed around exactly these expectations: screening against the consolidated UN, EU, OFAC and UK sanctions lists and a worldwide PEP database, fuzzy matching that survives misspellings and transliteration, ongoing monitoring that re-screens as the lists change, and an audit-ready report for every check.

You can run a free PEP and sanctions check to see the full result without a card, and there is a maintained reference page for the current FATF high-risk and grey-list countries and the EU high-risk third countries, updated after each FATF plenary.

Run a free PEP & sanctions check →

This note is a general summary of R.A.D. 282/2024 and CySEC Circular C685 and is not legal advice. For how these requirements apply to your entity, please get in touch.

TheCyprusLawyer - Business Law Publications

Subscribe

I believe that you are too busy to keep on visiting my site every now and again but at the same time, you might be interested to hear from me directly to your email. Subscribe in order to get the latest news and updates direct to email. The collection, use, and retention of your personal information is subject to the terms and conditions of the privacy policy

 

You have Successfully Subscribed!