CySEC Circular C721: Identity-Verification Timing — Requirements & What Firms Must Do
Reviewed by: Xenia Neophytou (Director — Regulatory Licensing & Compliance Governance): Managing Director with extensive credentials in governance advisory and AML/CFT | C721, Published July 07, 2026
Introduction
The Cyprus Securities and Exchange Commission (CySEC) issued Circular C721 to restate a long-standing regulatory principle that obliged entities sometimes apply inconsistently: the identity of the customer and the beneficial owner must, as a general rule, be verified before a business relationship begins.
The circular clarifies the application of section 62(2) of the AML Law—the narrow conditions under which verification may instead be completed during the establishment of the relationship, and the minimum safeguards expected when a firm relies on that derogation. This is a clarification of an obligation already in force, not a new regime: it introduces no new deadline and no reporting or submission obligation. For most firms, the practical question is not whether the rule has changed, but whether their onboarding controls and AML manual can evidence that the conditions are met in every case. Firms looking to evaluate their current frameworks can leverage our specialized Regulatory Compliance Services to ensure full alignment.
CySEC Circular C721 – At a Glance
- Issued date: 9 July 2025 (Circular C721), signed by Dr. George Theocharides, Chairman of CySEC. It replaces Circular C367.
- Applies to: Regulated Entities — Cyprus Investment Firms (CIFs), Administrative Service Providers (ASPs), UCITS Management Companies, internally managed UCITS, Alternative Investment Fund Managers (AIFMs), internally managed AIFs, internally managed AIFLNPs, companies with the sole purpose of managing AIFLNPs, Crypto Asset Service Providers (CASPs) and small AIFMs under Law 81(I)/2020.
- Deadline: Not applicable — clarifies an in-force obligation. The only time limit is the 15-day onboarding window per customer while identity verification is outstanding (see below).
- Key requirement: Verify the identity of the customer and the beneficial owner before the business relationship begins; where verification is completed during onboarding under the section 62(2) derogation, apply and evidence CySEC’s minimum cumulative conditions (EUR 2,000 deposit cap, same-name bank funding, a documented low-risk assessment and the 15-day limit).
- Submission method: Not applicable — this is an AML control requirement, not a submission.
What Does This Circular Require?
What Firms Must Do
The default under section 62(1) of the Law remains unchanged: identification and verification of the customer and the beneficial owner must be completed before the establishment of a business relationship. Section 62(2) permits verification to be completed during establishment only where all of the following criteria are met:
-
This is required in order not to interrupt the smooth conduct of business.
-
The money-laundering and terrorist-financing (ML/TF) risk is assessed as low.
-
Verification is completed as soon as possible after the initial contact.
Where a firm relies on that derogation, CySEC expects it to apply — and be actively able to evidence — the minimum conditions set out in the circular. Our team provides comprehensive AML Compliance Support to help firms build compliant customer economic profiles and structure clear verification timelines.
Legal Basis
The circular clarifies the application of section 62(2) of the Prevention and Suppression of Money Laundering Activities Law of 2007 (L.188(I)/2007), read alongside section 61(1)(a) and (b) (identification and verification) and, for CIFs, sections 26(2) and 26(3) of Law 87(I)/2017 (suitability and appropriateness tests). It also directly references the overarching CySEC Directive for the Prevention and Suppression of Money Laundering, keeping operations aligned with broader cross-border frameworks established by the European Securities and Markets Authority (ESMA).
Regulatory Objective
The circular disciplines an exception that is easy to over-use. It makes clear that verifying identity during onboarding, rather than before it, is a narrow, conditional derogation — not a general convenience — and that the burden of demonstrating the conditions sits entirely with the firm.
Who Is in Scope?
The circular is addressed to Regulated Entities, namely:
- Cyprus Investment Firms (CIFs)
- Administrative Service Providers (ASPs)
- UCITS Management Companies
- Internally managed UCITS
- Alternative Investment Fund Managers (AIFMs)
- Internally managed AIFs
- Internally managed AIFLNPs
- Companies with the sole purpose of managing AIFLNPs
- Crypto Asset Service Providers (CASPs)
- Small AIFMs under Law 81(I)/2020
Edge cases and exceptions:
- Administrative Service Providers (ASPs): The minimum-conditions specification in point (v) of the circular does not apply to the provision of administrative services by ASPs, given the nature of their activities. ASPs must comply with section 62 of the Law at all times. ASPs looking to structurally document their onboarding justifications can rely on our tailored Fiduciary and Corporate Services for direct assistance. Where an ASP intends under section 62(2) to complete verification during the conclusion of the business relationship, it must fully justify and record why pre-conclusion verification would interrupt smooth operations.
- CIFs: Before entering into a business relationship, the suitability test under section 26(2) and/or the appropriateness test under section 26(3) of Law 87(I)/2017 must be carried out where applicable — alongside, not instead of, the AML identification and verification steps. For new entrants navigating these strict operational standards, our Financial Services Licensing desk ensures that your structural governance is compliant from day one.
Key Requirements Breakdown
The Default Rule and the Derogation
As a general rule, in accordance with section 62(1) of the Law, the verification of the identity of the customer and the beneficial owner is completed before entering into a business relationship. By way of derogation, section 62(2) allows verification to be completed during the establishment of the relationship, provided all of the following are met: (a) this is required in order not to interrupt the smooth conduct of business; (b) the risk of money laundering or terrorist financing is low; and (c) verification is completed as soon as possible after the initial contact. CySEC encourages firms to verify before the relationship begins and describes verification during onboarding as being for exceptional cases.
The EUR 2,000 Deposit Cap
For the purposes of point (iv), CySEC considers the risk may be assessed as low provided, among others and as a minimum, that the total deposit amount of the customer/beneficial owner does not exceed EUR 2,000 — regardless of the number of accounts the customer maintains with the obliged entity — while verification of identity has not been completed. The circular is explicit that the EUR 2,000 amount does not automatically classify the business relationship as low risk: the obliged entity must still assess the risk of each customer’s relationship under the Law and the CySEC Directive.
Source of Funds: Same-Name Bank Account Only
The obliged entity accepts deposits only from a bank account — or from another instrument linked to a bank account, e.g. a credit card — which is in the name of the customer with whom it enters into the business relationship.
The 15-Day Limit, Reminders and Termination
The total time during which verification has not been completed must not exceed 15 days from the initial contact. The “initial contact” takes place when either the customer accepts the terms and conditions or the customer’s first deposit is made, whichever occurs first. During the 15-day period the obliged entity must take all reasonably necessary measures — for example, requests and reminders to submit the necessary documents — to ensure that the percentage of customers who do not comply is particularly low. If verification is not completed within 15 days, the business relationship is terminated on the day the period expires and all deposits are returned to the customer/beneficial owner, to the same bank account from which they originated; the refund process begins immediately, whether or not the customer has requested a refund. When refunding deposits, any profits made by the customer are included and any losses incurred are deducted. No amount is withheld and no account is frozen except in cases of suspected money laundering, where the obliged entity must immediately file a complaint with MOKAS in accordance with the Law and the CySEC Directive.
Disclosure and Explicit Consent
Obliged entities must appropriately, adequately and in a timely manner warn clients about the above procedure — including, for example, the policy for handling open positions and the procedure for possible refunds — and obtain their explicit consent regarding that procedure before initiating a business relationship.
No Deposit Without Identification and Economic Profile
No monetary deposit is accepted by an obliged entity unless the customer and the beneficial owner provide the necessary information to complete the identification procedures and to create an economic profile of the customer. The derogation concerns the timing of verification only; it does not relax identification, which — together with the economic profile — must be in place before any deposit is accepted.
AML Manual Requirement
Obliged entities must include in the AML manual the internal practice, measures, procedures and controls for the proper and effective implementation of, and monitoring of compliance with, section 62(2) of the Law.
C721 Practical Implementation: What Firms Should Do
In practice, the recurring issue with a conditional derogation of this kind is rarely understanding the rule; it is the evidence trail behind each use of it. Onboarding teams under commercial pressure may be tempted to let customers fund and trade before verification is complete. C721 makes clear that this is a narrow, conditional exception, and that the firm must be able to show — customer by customer — how the low-risk assessment was made, how the EUR 2,000 cap and same-name funding were enforced, and how the 15-day clock and refund process were operated.
The most common gaps are not in understanding the derogation but in documentation: the low-risk rationale is asserted rather than recorded; deposit-cap aggregation is not evidenced across multiple accounts; third-party funding controls exist on paper but cannot be demonstrated; the 15-day reminder and termination steps are inconsistently logged; and the AML manual is not updated to reflect the section 62(2) practice. A process that routinely defers verification for most new customers is unlikely to sit comfortably with the circular’s framing, which treats verification during onboarding as exceptional. Controls that exist but cannot be evidenced are, for supervisory purposes, difficult to rely on.
Step-by-Step: Applying the Derogation Correctly
- Apply the default rule first. Verify the identity of the customer and the beneficial owner before the business relationship begins. Treat verification during onboarding as the exception, used only in specific circumstances.
- Confirm the section 62(2) conditions are met. Before relying on the derogation, establish and document that (a) completing verification beforehand would interrupt the smooth conduct of business, (b) the ML/TF risk is low, and (c) verification will be completed as soon as possible after initial contact.
- Record a documented low-risk assessment. Assess and record why the specific customer’s relationship is low risk under the Law and the CySEC Directive. The EUR 2,000 figure does not, by itself, make the relationship low risk.
- Enforce the EUR 2,000 deposit cap. While verification is outstanding, ensure total deposits do not exceed EUR 2,000, aggregated across all of the customer’s accounts with the firm, and prevent the cap being breached.
- Enforce same-name bank funding. Accept deposits only from a bank account — or an instrument linked to one, such as a credit card — held in the name of the customer entering the relationship; reject third-party funding during the window.
- Do not accept any deposit without identification. Confirm the customer and beneficial owner have provided the information needed to complete identification and to build the economic profile before any monetary deposit is accepted.
- Disclose and obtain explicit consent. Warn the customer appropriately, adequately and in good time about the procedure — including the handling of open positions and the refund process — and obtain explicit consent before initiating the relationship.
- Run the 15-day clock with reminders. Start the clock at initial contact (the earlier of terms-and-conditions acceptance or first deposit). During the period, issue requests and reminders and take all reasonably necessary measures to keep non-compliance particularly low.
- Terminate and refund on expiry. If verification is not completed within 15 days, terminate the relationship on the day the period expires and return all deposits to the originating bank account — profits included, losses deducted — beginning the refund immediately, whether or not the customer asks. Withhold no amount and freeze no account except on suspicion of money laundering, in which case file a report with MOKAS in line with the Law and the CySEC Directive.
- ASP carve-out. Do not rely on the point (v) minimum conditions for administrative services provided by ASPs. ASPs must comply with section 62 at all times; where an ASP completes verification during the conclusion of the relationship, fully justify and record why pre-conclusion verification would interrupt operations and why the ML/TF risk is low.
- Reflect the practice in the AML manual. Ensure the AML manual describes the internal practice, measures, procedures and controls for implementing and monitoring compliance with section 62(2).
Compliance Officer Checklist
- Confirm the default onboarding rule — verification before the business relationship — and document the specific circumstances in which the section 62(2) derogation is used.
- Implement a control that aggregates deposits across all of a customer’s accounts and prevents the EUR 2,000 cap being exceeded while verification is outstanding.
- Enforce same-name funding — deposits only from a bank account (or linked instrument) in the customer’s name — and reject third-party funding during the window.
- Operate the 15-day clock from initial contact, with documented reminders, and a termination-and-refund process that returns deposits (profits included, losses deducted) to the originating account on expiry.
- Record, for each in-scope customer, the low-risk assessment supporting reliance on the derogation — not merely the EUR 2,000 figure.
- Confirm no deposit is accepted before identification and the customer economic profile are in place.
- Update terms and conditions and onboarding disclosures to warn customers of the procedure (open positions, refunds) and capture explicit consent before the relationship begins.
- Update the AML manual to describe the internal practice, measures, procedures and controls for applying and monitoring section 62(2).
- For ASPs: ensure the point (v) minimum conditions are not relied upon, and that any use of section 62(2) is fully justified and recorded.
- Record that C721 replaces C367 in the firm’s circular register, and note the owner, date and outcome of the review.
Evidence to Retain
- The onboarding policy and the documented rationale for each use of the section 62(2) derogation.
- A dated low-risk assessment in each in-scope customer file supporting reliance on the derogation.
- System configuration and exception reports evidencing the EUR 2,000 cap aggregated across accounts.
- Name-match checks and rejected-payment records evidencing same-name funding.
- Reminder logs, termination records and the refund audit trail for the 15-day process.
- Onboarding control evidence that no deposit was accepted before identification and the economic profile.
- Consent records and versions of the disclosures/terms and conditions capturing explicit consent.
- The dated AML manual update and approval reflecting the section 62(2) practice.
- For ASPs: the documented justification for completing verification during the conclusion of the relationship.
- The compliance-monitoring record noting the review and that C721 replaces C367 in the circular register.
Why This Matters
C721 clarifies an AML obligation already in force rather than creating a new one, but the practical stakes are real. Verifying identity during onboarding is a narrow, conditional derogation, and the burden of demonstrating each condition — the EUR 2,000 cap, same-name funding, the documented low-risk assessment and the 15-day clock — sits with the firm. Supervisory concern tends to arise less from misunderstanding the rule than from the evidence trail: a firm should be able to show, for any given customer, how the derogation was applied and monitored. It also reinforces that identification and the customer’s economic profile must precede any deposit, and that the AML manual must describe the section 62(2) practice. For CIFs, suitability and appropriateness testing under Law 87(I)/2017 sits alongside, not instead of, these AML steps.
Frequently Asked Questions
Does CySEC Circular C721 introduce a new obligation or deadline?
No. C721, dated 9 July 2025, clarifies and restates how to apply section 62(2) of L.188(I)/2007, and replaces Circular C367. It introduces no new reporting obligation, no submission and no new deadline; the obligations derive from the Law and the CySEC Directive already in force. The only time limit it describes is the 15-day onboarding window per customer while verification is outstanding.
What is the EUR 2,000 threshold in C721?
It is a ceiling on total customer deposits, across all of the customer’s accounts, while identity verification is outstanding and a firm relies on the derogation to verify during onboarding. The circular is explicit that EUR 2,000 does not automatically make a relationship low risk — the firm must still assess the risk of each customer under the Law and the CySEC Directive.
How long can verification remain outstanding?
No more than 15 days from the initial contact, which is the earlier of the customer accepting the terms and conditions or making a first deposit. If verification is not completed within 15 days, the relationship is terminated on the day the period expires and deposits are returned to the originating bank account, with the refund beginning immediately.
Can a customer fund the account from someone else’s card or account during this window?
No. During the verification window, deposits may be accepted only from a bank account, or an instrument linked to one (such as a credit card), held in the name of the customer entering the business relationship.
Does the derogation apply to Administrative Service Providers?
The minimum-conditions specification in point (v) does not apply to administrative services provided by ASPs. ASPs must comply with section 62 at all times; if an ASP completes verification during the conclusion of the relationship, it must fully justify and record why pre-conclusion verification would interrupt its operations and why the ML/TF risk is low.
What should we be able to evidence in response to C721?
That the default is verification before onboarding; that any use of the derogation is supported by a documented low-risk assessment; that the EUR 2,000 cap and same-name funding are enforced and aggregated across accounts; that the 15-day clock, reminders, termination and refund process operate as described; that identification and the economic profile precede any deposit; that customers gave explicit informed consent; and that the AML manual reflects the section 62(2) practice.
How CX Financia Can Support You
For regulated firms, the priority is to demonstrate a structured review: where the derogation is used, how the conditions are enforced, what the customer-level risk assessment shows, and what evidence has been retained.
CX Financia supports firms through Regulatory Compliance and AML/CFT advisory — targeted reviews and gap assessments, AML manual and procedure updates, onboarding-control and governance enhancements, and compliance-monitoring — helping align onboarding controls with section 62(2) and the CySEC Directive, and documenting the review trail.
Ensure Your Onboarding Framework Withstands Scrutiny
CySEC’s clarification places the burden of proof entirely on your firm. A generic verification process that treats the 15-day window as a default—rather than a strict exception—is a major regulatory risk.
Don’t wait for a CySEC inspection to discover gaps in your evidence trail.
C721: Schedule a Targeted Gap Assessment
Our team can review your current onboarding workflows, system-enforced deposit caps, and AML manuals to ensure total compliance with Section 62(2).
Book a Consultation with Our Compliance Team
Disclaimer
General information, not regulatory advice. Firms should refer to the text of Circular C721 and seek tailored advice on their specific circumstances.
