Anti-Money Laundering and Counter-Terrorist Financing (AML/CTF) Policy

1. Purpose

This Anti-Money Laundering and Counter-Terrorist Financing Policy (“Policy”) sets out the framework applied by Romania for Business (“the Company”, “we”, “us”) to prevent the use of its services for money laundering, terrorist financing, or any other form of financial crime.

This Policy is issued in accordance with:

  • Law No. 129/2019 on preventing and combating money laundering and terrorist financing, as well as for amending and supplementing certain normative acts, as subsequently amended and supplemented (“Law 129/2019”);
  • Government Emergency Ordinance No. 111/2020 and subsequent amending acts transposing EU Anti-Money Laundering Directives (AMLD) into Romanian law;
  • Regulation (EU) 2015/847 on information accompanying transfers of funds;
  • Directive (EU) 2015/849 (4AMLD) and Directive (EU) 2018/843 (5AMLD), as implemented in Romanian legislation;
  • Guidance and regulations issued by the National Office for Prevention and Control of Money Laundering (Oficiul Național de Prevenire și Combatere a Spălării Banilor — “ONPCSB”), Romania’s Financial Intelligence Unit (FIU);
  • Applicable rules of the professional body under which the Company or its associated professionals operate (e.g., the Romanian Bar Association, if legal services are rendered by licensed attorneys), where relevant.

Where the Company acts as a reporting entity (“entitate raportoare”) within the meaning of Article 5 of Law 129/2019 — for example, by providing company incorporation, registered office, tax, accounting, or business consultancy services — it complies with the obligations described in this Policy as a matter of law, not merely best practice.

2. Scope

This Policy applies to:

  • All employees, partners, associated consultants, and contractors of Romania for Business;
  • All clients, prospective clients, and beneficial owners of clients, regardless of nationality or country of residence;
  • All services provided by the Company, including but not limited to: company formation and registration in Romania, registered agent/registered office services, business consultancy, accounting liaison, tax registration assistance, and related corporate services.

This Policy does not, by itself, constitute legal advice to third parties and does not replace the individualized due diligence required for any specific client relationship.

3. Risk-Based Approach

The Company applies a risk-based approach (RBA) to AML/CTF compliance, calibrating the intensity of due diligence to the level of risk presented by a client, product, service, delivery channel, and geographic exposure.

3.1 Risk factors assessed include:

  • Client risk: legal form, ownership and control structure, nature of business activity, politically exposed person (PEP) status, adverse media, sanctions exposure.
  • Geographic risk: countries identified by the European Commission, FATF, or ONPCSB as high-risk jurisdictions, non-cooperative jurisdictions, or jurisdictions subject to international sanctions.
  • Product/service risk: complexity, opacity, cash-intensity, or use of nominee arrangements.
  • Delivery channel risk: non-face-to-face onboarding, use of intermediaries.

3.2 Risk classification

Clients are classified as Low, Standard, or High risk. Risk ratings are reviewed periodically and upon the occurrence of trigger events (e.g., adverse media, change in ownership, change in business activity).

4. Customer Due Diligence (CDD)

In accordance with Articles 11–23 of Law 129/2019, the Company applies CDD measures before establishing a business relationship or, in limited legally permitted circumstances, during the establishment of the relationship provided that money-laundering/terrorist-financing risk is low and effectively managed.

4.1 Standard CDD includes:

  1. Identification and verification of the client’s identity, based on official identification documents (ID card, passport) or, for legal entities, constitutive/registration documents (e.g., excerpt from the Trade Registry, articles of association).
  2. Identification of the beneficial owner(s) — any natural person(s) who ultimately own or control the client, per the definition in Article 4 of Law 129/2019, and verification of that identity through reasonable measures, including consultation of the Beneficial Ownership Register maintained by the Romanian Trade Registry Office (ONRC), where applicable.
  3. Understanding the purpose and intended nature of the business relationship.
  4. Ongoing monitoring of the business relationship, including scrutiny of transactions to ensure consistency with the Company’s knowledge of the client, its business, and risk profile.

4.2 Enhanced Due Diligence (EDD)

EDD is applied, at minimum, in the following situations (Articles 24–26 of Law 129/2019):

  • Clients or beneficial owners identified as Politically Exposed Persons (PEPs), their family members, or persons known to be close associates;
  • Clients established in or with significant connections to high-risk third countries as designated by the European Commission;
  • Complex or unusually large transactions, or unusual patterns of transactions with no apparent economic or lawful purpose;
  • Correspondent relationships (where applicable) with entities from third countries;
  • Any other circumstance identified by the Company’s internal risk assessment as posing elevated risk.

EDD measures may include: obtaining additional identification documentation, establishing the source of funds/wealth, obtaining senior management approval to establish or continue the relationship, and conducting more frequent and intensive monitoring.

4.3 Simplified Due Diligence (SDD)

SDD may be applied only where a documented risk assessment confirms low risk, and never in a manner that eliminates ongoing monitoring obligations entirely.

5. Politically Exposed Persons (PEPs) and Sanctions Screening

The Company screens clients and beneficial owners against:

  • Lists of PEPs, their family members, and close associates;
  • EU, UN, and OFAC sanctions and asset-freeze lists, and any list issued or referenced by Romanian authorities (including the list maintained pursuant to Law No. 535/2004 on preventing and combating terrorism, as amended).

Screening is conducted at onboarding and on an ongoing basis, with escalation procedures for any positive match.

6. Refusal and Termination of Business Relationships

The Company reserves the right to refuse to establish, or to terminate, a business relationship where:

  • The client fails to provide required identification or beneficial ownership information;
  • CDD/EDD cannot be satisfactorily completed;
  • There is reasonable suspicion of money laundering, terrorist financing, or other predicate offences;
  • Continuing the relationship would expose the Company to legal, regulatory, or reputational risk that cannot be adequately mitigated.

Where a suspicious transaction report has been or will be filed, the Company will assess — consistent with Article 7 of Law 129/2019 — whether informing the client of the report or the underlying suspicion (the anti-“tipping-off” rule) is legally prohibited, and will act accordingly.

7. Reporting Obligations

7.1 Suspicious Transaction Reports (STRs)

Where the Company knows, suspects, or has reasonable grounds to suspect that funds or assets are derived from criminal activity, or are related to terrorist financing, it will, through its designated Compliance Officer, promptly submit a Suspicious Transaction Report to ONPCSB, in accordance with Article 6 of Law 129/2019.

7.2 Cash Transaction Reports

Transactions in cash exceeding the statutory threshold (currently EUR 10,000 or its equivalent, whether carried out as a single operation or as linked operations) are reported to ONPCSB in accordance with Article 7 of Law 129/2019.

7.3 Confidentiality (“No Tipping-Off”)

Employees and associated persons are strictly prohibited from disclosing to a client, or to any third party, that a suspicious transaction report has been filed, is being considered, or that an investigation is underway, except as permitted by law.

8. Record-Keeping

In accordance with Article 34 of Law 129/2019, the Company retains, for a minimum of 5 (five) years from the end of the business relationship (or from the date of an occasional transaction):

  • Copies of identification documents and CDD/EDD documentation;
  • Records of transactions and supporting business correspondence;
  • Internal and external reports related to suspicious activity;
  • Risk assessments performed in relation to the client.

Retention periods may be extended upon a reasoned request from a competent authority, up to a maximum of 5 additional years, as permitted by law. All records are retained and processed in compliance with Regulation (EU) 2016/679 (GDPR) and the Company’s Privacy Policy.

9. Governance and Compliance Officer

The Company designates a Compliance Officer (or equivalent responsible person) reporting to senior management, responsible for:

  • Implementing and maintaining this Policy;
  • Serving as the point of contact with ONPCSB and other competent authorities;
  • Reviewing and, where warranted, filing suspicious transaction reports;
  • Overseeing staff training;
  • Conducting periodic internal audits of AML/CTF compliance;
  • Maintaining and updating the Company’s institutional risk assessment.

10. Staff Training

All employees and associated consultants involved in client-facing or compliance-relevant roles receive periodic training covering:

  • Romanian and EU AML/CTF legal requirements;
  • Identification of red flags and typologies of suspicious activity;
  • Internal escalation and reporting procedures;
  • Data protection obligations linked to AML processing.

Training records are maintained by the Compliance Officer.

11. Internal Controls and Review

The Company maintains internal policies, controls, and procedures proportionate to its nature, size, and risk profile, including:

  • A documented institutional risk assessment, reviewed at least annually or upon material change in the Company’s business or the regulatory environment;
  • Independent review/audit function, where proportionate;
  • Escalation procedures for red flags identified by staff.

This Policy is reviewed at least annually, and more frequently if required by legislative change, guidance from ONPCSB, or the Company’s own risk assessment.

12. Cooperation with Authorities

The Company fully cooperates with ONPCSB, the Romanian National Trade Registry Office (ONRC), law enforcement, and any other competent Romanian or EU authority in connection with AML/CTF investigations, requests for information, or inspections, as required by law.

13. Sanctions for Non-Compliance

Failure to comply with this Policy by employees or associated persons may result in disciplinary action, up to and including termination of engagement, without prejudice to any administrative or criminal liability arising under Law 129/2019 or other applicable legislation (which provides for significant administrative fines and, in serious cases, criminal sanctions for money laundering offences under Article 49 and related provisions of Law 129/2019, and Articles 49-52 of the Romanian Criminal Code where applicable).

14. Contact

Questions regarding this Policy may be directed to:

Romania for Business
Email address: info@romania-for-business.com
Website: https://romania-for-business.com/

This Policy is published for the information of clients and prospective clients of Romania for Business and reflects the Company’s internal AML/CTF compliance framework as required under Romanian and EU law. It does not constitute legal advice and may be updated from time to time without prior notice; the version published on our website at any given time is the version in force.