Our Expert in Romania
No results available
Who this is for: compliance officers, in-house legal teams, AML officers at banks and IFNs, credit servicers and external advisers seeking an operational 2026 AML playbook for Romania. This guide delivers the regulatory framework, supervisory expectations, CDD and SARs process, a risk-based compliance program checklist, remediation guidance and practical templates.
Last updated: 2026
AML compliance Romania is under sharper supervisory focus in 2026 than at any point in recent years, with regulators shifting attention decisively toward non-bank lenders, payment service providers and loan servicers. Where banks have long operated mature anti-money laundering frameworks, IFNs (non-bank financial institutions) and credit servicers now face the same expectations on risk-rating, transaction monitoring and the quality of their suspicious activity reports. This article sets out a practical, jurisdiction-specific playbook for lenders and servicers operating in Romania, mapping the legal framework, the supervisory priorities driving inspections, and the operational controls that will keep your institution enforcement-ready. It is written for practitioners who need to act, not just to understand.
The core message for 2026 is that supervisory tolerance for weak controls has narrowed, and non-bank actors are now firmly inside the perimeter. Effective aml compliance Romania in the current environment means demonstrable, documented, risk-based controls, not policies on paper.
Effective aml compliance Romania begins with understanding the layered architecture of primary law, national regulators and EU standards that shape day-to-day obligations. Romania transposes European directives into national legislation, and the national framework is then supervised by several authorities depending on the type of institution.
Romania’s principal anti-money laundering statute is Law No. 129/2019 on preventing and combating money laundering and terrorist financing, which transposes the relevant EU directives and establishes the obligations for reporting entities. The consolidated text is available through the official Romanian legislative portal. At EU level, Directive (EU) 2015/849 (the Fourth Anti-Money Laundering Directive), as amended by Directive (EU) 2018/843 (the Fifth Anti-Money Laundering Directive, or AMLD5), sets the standards Romania is required to meet, including enhanced transparency of beneficial ownership and expanded coverage of obliged entities.
Practitioners should also be aware that the EU has adopted a new AML package, including the Anti-Money Laundering Regulation (Regulation (EU) 2024/1624) and the establishment of the EU Anti-Money Laundering Authority (AMLA), which will progressively reshape the framework in the coming years. Practitioners should treat Law No. 129/2019 as the operative source for national obligations and refer to the EU directives and the incoming EU package to understand the direction of travel.
Several authorities share responsibility for anti-money laundering in Romania, and knowing which one supervises your institution, and to whom you report suspicions, is fundamental.
Local context: qualifying as a lawyer in Romania is demanding, candidates complete a law degree, pass the bar admission examination and undergo a supervised traineeship before full admission. Practitioners are generally referred to as avocat (attorney), distinct from a magistrat (a judge or prosecutor).
The defining feature of aml compliance Romania in 2026 is the intensified scrutiny of non-bank actors. Supervisory attention has moved toward IFNs, payment service providers and credit servicers, reflecting the growth of these sectors and the recognition that money-laundering risk does not stop at the doors of traditional banks. Inspections are expected to focus on the adequacy of risk-rating methodologies, the calibration of transaction monitoring, and, critically, the quality and timeliness of reports of suspicious transactions. Banks are not exempt: they face renewed expectations on the same three fronts.
The likely practical effect is that institutions with mature but under-maintained frameworks will be judged on execution, while newer entrants will be judged on whether they have built credible controls at all.
For banks, the obligations under aml compliance Romania are well established but continually raised in expectation. The sequence runs from onboarding, through ongoing monitoring, to detection and reporting, and each stage must be documented to a standard that would survive an inspection.
Customer due diligence in Romania requires verified identification of the customer, identification of the beneficial owner, understanding the purpose and intended nature of the relationship, and assigning a risk rating that drives the intensity of ongoing monitoring. Beneficial ownership verification is a particular supervisory focus following the transparency requirements introduced by AMLD5. Politically exposed persons (PEPs) trigger enhanced measures. A defensible CDD file combines identity evidence, ownership structure documentation, source-of-funds understanding where relevant, and a documented risk-rating rationale.
A practical onboarding checklist for a corporate borrower should include:
Enhanced due diligence (EDD) applies where risk is elevated, for example, relationships involving PEPs, customers in higher-risk jurisdictions, complex ownership structures, unusual transaction patterns or products vulnerable to abuse. EDD means obtaining additional information on the source of funds and source of wealth, securing senior management approval for the relationship, and applying more frequent and intensive ongoing monitoring. The trigger for EDD should be explicit in your policies, and the additional steps taken should be recorded so that the escalation is auditable.
Transaction monitoring in Romania is the engine of detection, and supervisors increasingly assess whether monitoring rules are appropriate to the institution’s actual risk profile rather than left at vendor defaults. Effective monitoring combines rule-based scenarios (thresholds, velocity, structuring patterns) with periodic tuning to reduce false positives while preserving genuine alerts. The European Banking Authority’s guidelines on ML/TF risk factors provide a useful benchmark for what “adequate” looks like. Institutions should document their tuning decisions, retain the rationale for threshold changes, and be able to demonstrate that alerts are worked and closed within reasonable timeframes.
When monitoring or staff judgement identifies suspicion, the obligation is to report. The internal process must route suspicions to the designated reporting person, who assesses them and submits qualifying reports to the ONPCSB as Romania’s FIU. Report quality is now a defining metric: a report that lacks supporting evidence, omits KYC context or fails to explain the basis for suspicion is a liability, not a defence. Suspicious transaction reporting Romania should be treated as a discipline in its own right, with quality standards, review and feedback loops. Where the ONPCSB provides feedback, institutions should use it to refine detection and reporting.
Reporting entities must retain CDD documentation and transaction records for the statutory period set out in Law No. 129/2019, and must be able to produce them on request. Retention obligations sit alongside data-protection duties, so recordkeeping policies must reconcile the need to keep AML records with GDPR principles of data minimisation and storage limitation. This intersection is addressed further below and is a recurring inspection topic.
The most significant shift in aml compliance Romania for 2026 concerns IFNs and credit servicers. These entities are firmly within the AML perimeter, and the expectation is that their controls are proportionate to their risk, not diluted because they are not banks.
IFNs, non-bank financial institutions, include consumer and micro-lenders, leasing companies, and other credit providers that operate outside the deposit-taking banking model. Many fall under BNR oversight through the registers it maintains for non-banking financial institutions, while certain actors and products may engage ASF oversight. Credit servicers, including firms that manage loan portfolios, collect on debts, or acquire and service non-performing loans, are equally obliged entities where they perform functions that bring them within the scope of the AML law. The regime for credit servicers and credit purchasers in the EU has been reshaped by Directive (EU) 2021/2167 on credit servicers and credit purchasers, transposed into Romanian law.
The practical point is that being non-bank is not a basis for lighter obligations; it is a basis for scaled but genuine controls.
Short-tenor, high-volume products such as micro-loans and buy-now-pay-later arrangements present a distinct challenge: the commercial model relies on speed, but AML obligations require verified identity, beneficial ownership where relevant, and a risk-based understanding of the customer. The answer is not to skip CDD but to embed proportionate, automated verification into the customer journey, apply behavioural monitoring across the portfolio, and escalate anomalies for human review. Source-of-funds enquiry should scale with transaction size and risk indicators rather than being applied uniformly or ignored entirely.
Credit servicers face risks that arise from the nature of their business rather than from originating customers directly. Collection activity can obscure the origin of repayment funds; the resale and purchase of non-performing loan (NPL) portfolios can transfer relationships whose underlying CDD is incomplete or stale; and portfolio acquisitions may import money-laundering risk embedded in the acquired book. Mitigation requires due diligence on acquired portfolios, refreshing CDD where files are inadequate, monitoring repayment sources for anomalies, and clear allocation of AML responsibility between originator and servicer in servicing agreements.
Outsourcing does not transfer AML accountability. Institutions remain responsible for the compliance of functions they delegate, so vendor management is a control in its own right. This means conducting KYC-style due diligence on vendors and suppliers, screening them against sanctions lists, embedding audit and information rights in contracts, and monitoring ongoing performance. Weak vendor oversight is a recurring enforcement focus area, particularly where servicing platforms or outsourced monitoring providers sit between the obliged entity and its customers.
2026 supervisory note: the two enforcement themes most likely to feature in inspections of IFNs and servicers are poor report quality and weak oversight of outsourced functions. Address both before an inspector does.
Suspicious transaction reporting Romania is where the entire AML framework is tested. Detection without reporting is worthless, and reporting without quality is a compliance risk. The workflow runs from detection, through internal escalation, to submission to the ONPCSB, followed by retention and, where it arises, regulator engagement.
Before any external submission, a robust internal report captures the essential information so the reporting person can make a sound decision. Minimum fields should include:
Qualifying suspicions are submitted to the ONPCSB, Romania’s FIU, through the channels and using the procedures published by the Office. Institutions should follow ONPCSB guidance on format and content, submit promptly once suspicion is established, and retain a full record of the submission and its supporting file. Timeliness matters: delays between detection and submission are a common inspection criticism, so internal escalation should be swift and the decision to report or not should be documented in every case.
Reports commonly fall short where the basis for suspicion is not clearly articulated, where KYC information is missing, where supporting evidence is absent, or where the narrative is generic. Remediation is straightforward in principle: build a quality-review step into the reporting pipeline, require a clear statement of the grounds for suspicion, attach the evidence, and ensure the customer’s KYC file is complete before the report leaves the building.
A simple report quality scoring rubric helps embed consistency:
A defensible aml compliance Romania program is risk-based, governed from the top, and evidenced throughout. Supervisors expect the intensity of controls to reflect the institution’s assessed risk, and they expect senior management to own the outcome. The following structure translates the legal obligations into an operating model.
Governance is the foundation. Senior management must approve the AML policy, understand the institution’s risk exposure, allocate adequate resources, and receive regular reporting on the effectiveness of controls. A named member of the management body should carry accountability, and the board or equivalent body should be able to demonstrate active oversight rather than passive delegation.
Two layers of risk assessment are required. The enterprise-wide assessment captures the institution’s overall exposure across customers, products, channels and geographies. The product-level assessment drills into the specific risks of each offering, a micro-loan carries a different profile from a corporate facility or a purchased NPL portfolio. A sample risk-rating matrix scores each customer or product across risk factors (customer type, geography, product, channel, transaction behaviour) and translates the aggregate score into a risk tier that drives CDD intensity and monitoring frequency.
The control layer operationalises the framework. It comprises KYC and CDD at onboarding and on an ongoing basis, calibrated transaction monitoring, a disciplined reporting pipeline with quality review, and sanctions screening at onboarding and on a continuing basis against updated lists. Each control should have a documented owner, a defined process, and evidence that it operates as designed. Customer due diligence Romania obligations run through this layer at every point where a relationship is established, changed or reviewed.
The designated compliance officer responsible for AML is the pivot of the program. Under Law No. 129/2019, obliged entities designate one or more persons with responsibility for applying AML measures, whose names are notified to the ONPCSB. The role requires sufficient seniority, independence, direct access to senior management, and adequate staffing to handle alert volumes and reporting workloads. Under-resourcing the function is a false economy: it produces alert backlogs, delayed reports and weak-quality submissions, precisely the failings supervisors target.
People and assurance close the loop. Staff across customer-facing and operational functions need role-appropriate training, refreshed regularly and recorded. Internal audit should test the AML framework on a risk-based cycle, and independent testing, whether internal or external, validates that controls work in practice, not just on paper. Findings should feed a documented remediation process with owners and deadlines.
An AML compliance program checklist covering governance, risk assessment, controls, the compliance officer function and assurance can be maintained as a living document and reviewed against each supervisory update. Templates are for guidance only and do not constitute legal advice.
Enforcement is the point at which aml compliance Romania stops being theoretical. Understanding the range of consequences and the mechanics of remediation allows institutions to prepare rather than react.
Consequences for AML failings range from administrative fines, through supervisory measures and conditions, to licence actions and, in serious cases, criminal referral. Law No. 129/2019 provides for significant administrative sanctions for breaches of AML obligations, with the applicable ceilings set out in the statute; the severity typically reflects the gravity of the breach, whether it was systemic, and how the institution responded. Beyond formal penalties, reputational damage and remediation costs frequently exceed the headline fine.
A credible remediation plan following an inspection identifies the root cause of each finding, assigns an owner and a deadline, sequences fixes by risk, and reports progress to senior management and, where appropriate, the regulator. A structured 30/60/90-day action plan demonstrates control and good faith. Engaging constructively with the supervisor, acknowledging findings, explaining corrective steps, and evidencing progress, generally serves an institution better than defensiveness.
Where an institution identifies a material control failing itself, the practical calculus usually favours proactive engagement and remediation over waiting for an inspection to surface the issue. Self-identification paired with a credible fix signals a functioning compliance culture. The decision is fact-specific and warrants legal advice, but early, documented remediation is generally treated as the lower-risk path.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Cristiana Petropoulos at Tiller Legal, a member of the Global Law Experts network.
posted 34 seconds ago
posted 8 minutes ago
posted 8 minutes ago
posted 16 minutes ago
posted 16 minutes ago
posted 17 minutes ago
posted 25 minutes ago
posted 25 minutes ago
posted 26 minutes ago
posted 34 minutes ago
posted 35 minutes ago
posted 40 minutes ago
No results available
Find the right Legal Expert for your business
Send welcome message