[codicts-css-switcher id=”346″]

Global Law Experts Logo
romania 2026 aml

Romania 2026: AML Compliance for Banks, Ifns and Credit Servicers, What Lenders and Servicers Need to Know

By Global Law Experts
– posted 2 hours ago

Who this is for: compliance officers, in-house legal teams, AML officers at banks and IFNs, credit servicers and external advisers seeking an operational 2026 AML playbook for Romania. This guide delivers the regulatory framework, supervisory expectations, CDD and SARs process, a risk-based compliance program checklist, remediation guidance and practical templates.

Last updated: 2026

AML compliance Romania is under sharper supervisory focus in 2026 than at any point in recent years, with regulators shifting attention decisively toward non-bank lenders, payment service providers and loan servicers. Where banks have long operated mature anti-money laundering frameworks, IFNs (non-bank financial institutions) and credit servicers now face the same expectations on risk-rating, transaction monitoring and the quality of their suspicious activity reports. This article sets out a practical, jurisdiction-specific playbook for lenders and servicers operating in Romania, mapping the legal framework, the supervisory priorities driving inspections, and the operational controls that will keep your institution enforcement-ready. It is written for practitioners who need to act, not just to understand.

Executive summary: key takeaways and 2026 snapshot

The core message for 2026 is that supervisory tolerance for weak controls has narrowed, and non-bank actors are now firmly inside the perimeter. Effective aml compliance Romania in the current environment means demonstrable, documented, risk-based controls, not policies on paper.

  • Immediate (0–30 days). Confirm your customer due diligence (CDD) files are complete for high-risk relationships, verify beneficial ownership records, and check that your reporting pipeline to the ONPCSB is functioning and documented.
  • Near-term (30–60 days). Tune transaction monitoring rules, review alert backlogs, and test the quality of recent suspicious transaction reports against completeness and evidence standards.
  • Structural (60–90 days). Refresh your enterprise risk assessment, validate vendor and outsourcing oversight, and confirm your compliance officer has adequate authority and resourcing.
  • IFNs, payment providers and credit servicers should assume they are a supervisory priority in 2026 and prepare accordingly.
  • Poor report quality and weak vendor oversight are recurring enforcement themes, address both proactively.
  • Reconcile AML recordkeeping with GDPR obligations before an inspector raises the question.
  • Large institutions, including the country’s leading banks such as Banca Transilvania and BCR, set the practical benchmark for the controls smaller lenders are now expected to match on a scaled basis.

Romanian AML legal and supervisory framework

Effective aml compliance Romania begins with understanding the layered architecture of primary law, national regulators and EU standards that shape day-to-day obligations. Romania transposes European directives into national legislation, and the national framework is then supervised by several authorities depending on the type of institution.

Primary legislation and EU law

Romania’s principal anti-money laundering statute is Law No. 129/2019 on preventing and combating money laundering and terrorist financing, which transposes the relevant EU directives and establishes the obligations for reporting entities. The consolidated text is available through the official Romanian legislative portal. At EU level, Directive (EU) 2015/849 (the Fourth Anti-Money Laundering Directive), as amended by Directive (EU) 2018/843 (the Fifth Anti-Money Laundering Directive, or AMLD5), sets the standards Romania is required to meet, including enhanced transparency of beneficial ownership and expanded coverage of obliged entities.

Practitioners should also be aware that the EU has adopted a new AML package, including the Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) and the establishment of the EU Anti-Money Laundering Authority (AMLA), which will progressively reshape the framework in the coming years. Practitioners should treat Law No. 129/2019 as the operative source for national obligations and refer to the EU directives and the incoming EU package to understand the direction of travel.

Key Romanian regulators, ONPCSB, BNR, ASF and the Ministry of Finance

Several authorities share responsibility for anti-money laundering in Romania, and knowing which one supervises your institution, and to whom you report suspicions, is fundamental.

  • ONPCSB (National Office for Prevention and Combating Money Laundering). This is Romania’s Financial Intelligence Unit (FIU). It receives reports of suspicious transactions, issues guidance and procedures, and coordinates the national risk assessment.
  • National Bank of Romania (BNR). The BNR supervises credit institutions and non-banking financial institutions entered in its registers, issuing regulations and supervisory expectations that shape how banks and many IFNs build their AML frameworks.
  • Financial Supervisory Authority (ASF). The ASF oversees the non-banking financial markets, insurance, capital markets and private pensions, and its guidance applies where the entity or product falls within its supervisory perimeter.
  • Ministry of Finance. The ministry contributes to national AML policy and the broader legislative framework within which the operational regulators function.

Local context: qualifying as a lawyer in Romania is demanding, candidates complete a law degree, pass the bar admission examination and undergo a supervised traineeship before full admission. Practitioners are generally referred to as avocat (attorney), distinct from a magistrat (a judge or prosecutor).

2026 supervisory priorities

The defining feature of aml compliance Romania in 2026 is the intensified scrutiny of non-bank actors. Supervisory attention has moved toward IFNs, payment service providers and credit servicers, reflecting the growth of these sectors and the recognition that money-laundering risk does not stop at the doors of traditional banks. Inspections are expected to focus on the adequacy of risk-rating methodologies, the calibration of transaction monitoring, and, critically, the quality and timeliness of reports of suspicious transactions. Banks are not exempt: they face renewed expectations on the same three fronts.

The likely practical effect is that institutions with mature but under-maintained frameworks will be judged on execution, while newer entrants will be judged on whether they have built credible controls at all.

Core AML obligations for banks: CDD, monitoring and suspicious transaction reports

For banks, the obligations under aml compliance Romania are well established but continually raised in expectation. The sequence runs from onboarding, through ongoing monitoring, to detection and reporting, and each stage must be documented to a standard that would survive an inspection.

Customer due diligence: ID, beneficial ownership, risk-rating and PEPs

Customer due diligence in Romania requires verified identification of the customer, identification of the beneficial owner, understanding the purpose and intended nature of the relationship, and assigning a risk rating that drives the intensity of ongoing monitoring. Beneficial ownership verification is a particular supervisory focus following the transparency requirements introduced by AMLD5. Politically exposed persons (PEPs) trigger enhanced measures. A defensible CDD file combines identity evidence, ownership structure documentation, source-of-funds understanding where relevant, and a documented risk-rating rationale.

A practical onboarding checklist for a corporate borrower should include:

  • Certified extract from the trade register and constitutional documents.
  • Identification of directors and authorised signatories.
  • Beneficial ownership declaration and independent verification against reliable sources.
  • PEP and sanctions screening of the entity and its controllers.
  • Understanding of the purpose of the facility and expected transaction patterns.
  • Documented risk rating and the reasoning behind it.

Enhanced due diligence and high-risk scenarios

Enhanced due diligence (EDD) applies where risk is elevated, for example, relationships involving PEPs, customers in higher-risk jurisdictions, complex ownership structures, unusual transaction patterns or products vulnerable to abuse. EDD means obtaining additional information on the source of funds and source of wealth, securing senior management approval for the relationship, and applying more frequent and intensive ongoing monitoring. The trigger for EDD should be explicit in your policies, and the additional steps taken should be recorded so that the escalation is auditable.

Transaction monitoring and automated systems, thresholds and tuning

Transaction monitoring in Romania is the engine of detection, and supervisors increasingly assess whether monitoring rules are appropriate to the institution’s actual risk profile rather than left at vendor defaults. Effective monitoring combines rule-based scenarios (thresholds, velocity, structuring patterns) with periodic tuning to reduce false positives while preserving genuine alerts. The European Banking Authority’s guidelines on ML/TF risk factors provide a useful benchmark for what “adequate” looks like. Institutions should document their tuning decisions, retain the rationale for threshold changes, and be able to demonstrate that alerts are worked and closed within reasonable timeframes.

Suspicious transaction reporting: internal escalation, report quality and ONPCSB feedback

When monitoring or staff judgement identifies suspicion, the obligation is to report. The internal process must route suspicions to the designated reporting person, who assesses them and submits qualifying reports to the ONPCSB as Romania’s FIU. Report quality is now a defining metric: a report that lacks supporting evidence, omits KYC context or fails to explain the basis for suspicion is a liability, not a defence. Suspicious transaction reporting Romania should be treated as a discipline in its own right, with quality standards, review and feedback loops. Where the ONPCSB provides feedback, institutions should use it to refine detection and reporting.

Recordkeeping and data retention

Reporting entities must retain CDD documentation and transaction records for the statutory period set out in Law No. 129/2019, and must be able to produce them on request. Retention obligations sit alongside data-protection duties, so recordkeeping policies must reconcile the need to keep AML records with GDPR principles of data minimisation and storage limitation. This intersection is addressed further below and is a recurring inspection topic.

AML obligations for IFNs and credit servicers: 2026 guidance and practical controls

The most significant shift in aml compliance Romania for 2026 concerns IFNs and credit servicers. These entities are firmly within the AML perimeter, and the expectation is that their controls are proportionate to their risk, not diluted because they are not banks.

Who counts as an IFN and the supervisory perimeter

IFNs, non-bank financial institutions, include consumer and micro-lenders, leasing companies, and other credit providers that operate outside the deposit-taking banking model. Many fall under BNR oversight through the registers it maintains for non-banking financial institutions, while certain actors and products may engage ASF oversight. Credit servicers, including firms that manage loan portfolios, collect on debts, or acquire and service non-performing loans, are equally obliged entities where they perform functions that bring them within the scope of the AML law. The regime for credit servicers and credit purchasers in the EU has been reshaped by Directive (EU) 2021/2167 on credit servicers and credit purchasers, transposed into Romanian law.

The practical point is that being non-bank is not a basis for lighter obligations; it is a basis for scaled but genuine controls.

CDD and source of funds for micro-loans and buy-now-pay-later

Short-tenor, high-volume products such as micro-loans and buy-now-pay-later arrangements present a distinct challenge: the commercial model relies on speed, but AML obligations require verified identity, beneficial ownership where relevant, and a risk-based understanding of the customer. The answer is not to skip CDD but to embed proportionate, automated verification into the customer journey, apply behavioural monitoring across the portfolio, and escalate anomalies for human review. Source-of-funds enquiry should scale with transaction size and risk indicators rather than being applied uniformly or ignored entirely.

Loan servicing-specific risks and mitigation

Credit servicers face risks that arise from the nature of their business rather than from originating customers directly. Collection activity can obscure the origin of repayment funds; the resale and purchase of non-performing loan (NPL) portfolios can transfer relationships whose underlying CDD is incomplete or stale; and portfolio acquisitions may import money-laundering risk embedded in the acquired book. Mitigation requires due diligence on acquired portfolios, refreshing CDD where files are inadequate, monitoring repayment sources for anomalies, and clear allocation of AML responsibility between originator and servicer in servicing agreements.

Vendor management and screening

Outsourcing does not transfer AML accountability. Institutions remain responsible for the compliance of functions they delegate, so vendor management is a control in its own right. This means conducting KYC-style due diligence on vendors and suppliers, screening them against sanctions lists, embedding audit and information rights in contracts, and monitoring ongoing performance. Weak vendor oversight is a recurring enforcement focus area, particularly where servicing platforms or outsourced monitoring providers sit between the obliged entity and its customers.

2026 supervisory note: the two enforcement themes most likely to feature in inspections of IFNs and servicers are poor report quality and weak oversight of outsourced functions. Address both before an inspector does.

Suspicious transaction reporting: process, timelines and quality metrics

Suspicious transaction reporting Romania is where the entire AML framework is tested. Detection without reporting is worthless, and reporting without quality is a compliance risk. The workflow runs from detection, through internal escalation, to submission to the ONPCSB, followed by retention and, where it arises, regulator engagement.

Internal report form: minimum fields

Before any external submission, a robust internal report captures the essential information so the reporting person can make a sound decision. Minimum fields should include:

  • Customer identity and account or relationship reference.
  • Description of the activity or transaction giving rise to suspicion.
  • The specific red flags observed and why they are suspicious.
  • Relevant KYC and risk-rating context.
  • Supporting evidence (transaction data, correspondence, screening hits).
  • The name of the reporting staff member and the date of detection.

Submission process to the ONPCSB

Qualifying suspicions are submitted to the ONPCSB, Romania’s FIU, through the channels and using the procedures published by the Office. Institutions should follow ONPCSB guidance on format and content, submit promptly once suspicion is established, and retain a full record of the submission and its supporting file. Timeliness matters: delays between detection and submission are a common inspection criticism, so internal escalation should be swift and the decision to report or not should be documented in every case.

Common reasons for report rejection and how to remediate

Reports commonly fall short where the basis for suspicion is not clearly articulated, where KYC information is missing, where supporting evidence is absent, or where the narrative is generic. Remediation is straightforward in principle: build a quality-review step into the reporting pipeline, require a clear statement of the grounds for suspicion, attach the evidence, and ensure the customer’s KYC file is complete before the report leaves the building.

A simple report quality scoring rubric helps embed consistency:

  • Completeness. Are all required fields populated and is the KYC context present?
  • Evidence. Is the suspicion supported by transaction data or documentation?
  • Urgency. Has the report been escalated and submitted promptly relative to detection?

Designing a risk-based aml compliance Romania program, operational checklist and templates

A defensible aml compliance Romania program is risk-based, governed from the top, and evidenced throughout. Supervisors expect the intensity of controls to reflect the institution’s assessed risk, and they expect senior management to own the outcome. The following structure translates the legal obligations into an operating model.

Governance and senior management responsibilities

Governance is the foundation. Senior management must approve the AML policy, understand the institution’s risk exposure, allocate adequate resources, and receive regular reporting on the effectiveness of controls. A named member of the management body should carry accountability, and the board or equivalent body should be able to demonstrate active oversight rather than passive delegation.

Risk assessment: enterprise-level and product-level

Two layers of risk assessment are required. The enterprise-wide assessment captures the institution’s overall exposure across customers, products, channels and geographies. The product-level assessment drills into the specific risks of each offering, a micro-loan carries a different profile from a corporate facility or a purchased NPL portfolio. A sample risk-rating matrix scores each customer or product across risk factors (customer type, geography, product, channel, transaction behaviour) and translates the aggregate score into a risk tier that drives CDD intensity and monitoring frequency.

Controls: KYC/CDD, transaction monitoring, reporting pipeline and sanctions screening

The control layer operationalises the framework. It comprises KYC and CDD at onboarding and on an ongoing basis, calibrated transaction monitoring, a disciplined reporting pipeline with quality review, and sanctions screening at onboarding and on a continuing basis against updated lists. Each control should have a documented owner, a defined process, and evidence that it operates as designed. Customer due diligence Romania obligations run through this layer at every point where a relationship is established, changed or reviewed.

Compliance officer role, reporting lines and resourcing

The designated compliance officer responsible for AML is the pivot of the program. Under Law No. 129/2019, obliged entities designate one or more persons with responsibility for applying AML measures, whose names are notified to the ONPCSB. The role requires sufficient seniority, independence, direct access to senior management, and adequate staffing to handle alert volumes and reporting workloads. Under-resourcing the function is a false economy: it produces alert backlogs, delayed reports and weak-quality submissions, precisely the failings supervisors target.

Training, internal audit and independent testing

People and assurance close the loop. Staff across customer-facing and operational functions need role-appropriate training, refreshed regularly and recorded. Internal audit should test the AML framework on a risk-based cycle, and independent testing, whether internal or external, validates that controls work in practice, not just on paper. Findings should feed a documented remediation process with owners and deadlines.

An AML compliance program checklist covering governance, risk assessment, controls, the compliance officer function and assurance can be maintained as a living document and reviewed against each supervisory update. Templates are for guidance only and do not constitute legal advice.

Enforcement, penalties and remediation: what to expect and how to prepare

Enforcement is the point at which aml compliance Romania stops being theoretical. Understanding the range of consequences and the mechanics of remediation allows institutions to prepare rather than react.

Typical penalties and consequences

Consequences for AML failings range from administrative fines, through supervisory measures and conditions, to licence actions and, in serious cases, criminal referral. Law No. 129/2019 provides for significant administrative sanctions for breaches of AML obligations, with the applicable ceilings set out in the statute; the severity typically reflects the gravity of the breach, whether it was systemic, and how the institution responded. Beyond formal penalties, reputational damage and remediation costs frequently exceed the headline fine.

Building an enforcement-ready remediation plan

A credible remediation plan following an inspection identifies the root cause of each finding, assigns an owner and a deadline, sequences fixes by risk, and reports progress to senior management and, where appropriate, the regulator. A structured 30/60/90-day action plan demonstrates control and good faith. Engaging constructively with the supervisor, acknowledging findings, explaining corrective steps, and evidencing progress, generally serves an institution better than defensiveness.

When to self-report versus wait for inspection

Where an institution identifies a material control failing itself, the practical calculus usually favours proactive engagement and remediation over waiting for an inspection to surface the issue. Self-identification paired with a credible fix signals a functioning compliance culture. The decision is fact-specific and warrants legal advice, but early, documented remediation is generally treated as the lower-risk path.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Cristiana Petropoulos at Tiller Legal, a member of the Global Law Experts network.

Sources

  1. National Office for Prevention and Combating Money Laundering (ONPCSB)
  2. National Bank of Romania (BNR)
  3. Financial Supervisory Authority (ASF) Romania
  4. EUR-Lex, Directive (EU) 2015/849 (4th AMLD)
  5. EUR-Lex, Directive (EU) 2018/843 (5th AMLD)
  6. European Banking Authority (EBA), AML guidelines and opinions
  7. General Data Protection Regulation (Regulation (EU) 2016/679)
  8. Financial Action Task Force (FATF), Guidance and country reports
  9. Portalul legislativ / Romanian legislative portal (Law No. 129/2019)

FAQs

Banks, IFNs and credit servicers compared Issue Banks IFNs Credit servicers Licensing / supervision Credit institutions supervised by BNR Non-banking financial institutions registered with and supervised by BNR; ASF where applicable Obliged entities where servicing brings them within the AML law; authorisation and oversight regime for credit servicers per applicable EU-derived rules CDD baseline Full CDD including beneficial ownership and risk-rating Full CDD, proportionate to product and risk CDD on serviced relationships; refresh where acquired files are inadequate EDD triggers PEPs, high-risk jurisdictions, complex structures, unusual activity Same triggers, scaled to portfolio profile High-risk NPL portfolios, opaque repayment sources Report submission route To ONPCSB via internal escalation and designated compliance officer To ONPCSB via internal escalation and designated compliance officer To ONPCSB via internal escalation and designated compliance officer Sanctions screening At onboarding and ongoing against updated lists At onboarding and ongoing On serviced customers and counterparties, including vendors Recordkeeping Statutory retention of CDD and transaction records Statutory retention, reconciled with GDPR Statutory retention across acquired and serviced books Outsourcing / vendor oversight Accountability retained; vendor due diligence required Accountability retained; a 2026 focus area Critical, servicing platforms and collection vendors must be screened and monitored Frequently asked questions on aml compliance Romania
What are the main AML obligations for banks in Romania? Banks must perform customer due diligence including beneficial ownership verification, apply risk-based ongoing monitoring, screen against sanctions lists, submit reports of suspicious transactions to the ONPCSB, and retain CDD and transaction records for the statutory period, all under Law No. 129/2019.
Strong aml compliance Romania in 2026 is built on execution: complete CDD files, calibrated monitoring, high-quality reports of suspicious transactions, disciplined vendor oversight and demonstrable senior accountability. Use the 30/60/90-day priorities in the executive summary to sequence remediation, and treat report quality and outsourcing oversight as the areas most likely to attract supervisory attention. Institutions that can evidence a functioning, risk-based program, and that engage constructively when findings arise, are best placed to withstand the heightened scrutiny now directed at banks, IFNs and credit servicers alike. For institution-specific guidance, seek qualified legal advice from a Banking & Finance practitioner familiar with Romanian AML supervision.
enforcing insurance awards england
By Global Law Experts

posted 3 minutes ago

macau gaming tax compliance
By Global Law Experts

posted 26 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Romania 2026: AML Compliance for Banks, Ifns and Credit Servicers, What Lenders and Servicers Need to Know

Send welcome message

Custom Message