
Introduction
On 9 October 2026, the Cyprus Securities and Exchange Commission (CySEC) issued Circular C805 to inform regulated entities about the Unit for Combating Money Laundering’s (MOKAS) *Annual Sectorial Quantity & Quality Assessment of STRs/SARs for 2025*. This circular is a **clarification and reminder** of existing obligations under AML/CFT laws. It highlights key deficiencies in suspicious transaction reports (STRs) and suspicious activity reports (SARs), emerging risk indicators, and sector-specific trends. While it sets no new submission deadline, you must review the report to align your internal processes with MOKAS’ expectations and improve the quality of future filings.
CySEC Circular C805 – At a Glance
- Issued date: 9 October 2026
- Applies to: CIFs, ASPs, UCITS Management Companies, Internally managed UCITS, AIFMs, Internally managed AIFs, Internally managed AIFLNPs, Companies with sole purpose the management of AIFLNPs, Crypto Asset Service Providers, Small AIFMs under Law 81(I)/2020, Crowdfunding Service Providers
- Key requirement: Study MOKAS’ 2025 assessment report and address identified deficiencies in STR/SAR submissions to improve quality, completeness, and analytical value.
What Does This Circular Require?
What firms must do. You must review MOKAS’ *Annual Sectorial Quantity & Quality Assessment of STRs/SARs for 2025* and use its findings to enhance the quality of your suspicious transaction and activity reports. While no new submission is required, you are expected to correct common deficiencies—such as weak narratives, missing attachments, or incomplete identification details—identified in the report.
Legal basis. Prevention and Suppression of Money Laundering and Terrorist Financing Laws of 2007–2021 (AML/CFT Law) and MOKAS Reporting Guidelines.
Regulatory objective. To improve the effectiveness of financial intelligence analysis by ensuring STRs/SARs are complete, accurate, and analytically valuable. The report also aims to reinforce a risk-based approach, highlight emerging risks, and strengthen cooperation between obliged entities and the FIU.
Who Is in Scope?
The circular applies to all CySEC-regulated entities required to submit STRs/SARs to MOKAS under AML/CFT laws.
- CIFs
- ASPs
- UCITS Management Companies
- Internally managed UCITS
- AIFMs
- Internally managed AIFs
- Internally managed AIFLNPs
- Companies with sole purpose the management of AIFLNPs
- Crypto Asset Service Providers
- Small AIFMs under Law 81(I)/2020
- Crowdfunding Service Providers
The report provides sector-specific insights, including submission volumes, common deficiencies, and risk indicators. Crypto Asset Service Providers (CASPs) were the largest submitters in 2025, followed by investment firms and payment institutions.
Edge cases and exceptions:
- No reporting from Real Estate Agents, Art Traders, or Free Port Operators: Despite legal obligations, these sectors submitted zero STRs/SARs in 2025.
- Cross-border reports: 21,857 of 24,092 reports (91%) were submitted by entities operating under free provision of services, with only 246 having a Cyprus nexus.
Key Requirements Breakdown
Reporting / Submission Requirements
MOKAS assessed 24,092 STRs/SARs submitted in 2025, identifying 185 failed submissions due to incomplete narratives, missing attachments, or insufficient identification details. The report categorises submissions by risk level (Low, Medium, Medium Serious, High) and highlights sector-specific trends, such as CASPs submitting 20,570 reports (85% of total).
Technical / System Requirements
Reports must be submitted via the goAML system. Key technical requirements include: (1) A narrative between 400–4,000 characters; (2) All relevant attachments; (3) Complete identification details for subjects and entities; (4) Accurate selection of ML/TF indicators from the FIU’s predefined list.
Validation or Approval Process
Reports failing to meet technical requirements (e.g., missing attachments, incomplete IDs) are automatically rejected. MOKAS’ assessment found 26% of failed submissions lacked sufficient narrative, while another 26% missed attachments.
Practical Implementation: What Firms Should Do
In practice, you should use the report to benchmark your STR/SAR submissions against sector peers. Focus on high-risk indicators like virtual asset transactions, money mules, and cyber fraud, which dominated 2025 filings. Common mistakes include submitting SARs instead of STRs, late filings, or using risk indicators without clear justification in the narrative.
CySEC expects you to address deficiencies proactively. For example, if your sector underperformed in narrative quality (e.g., banking institutions), revise internal training to ensure analysts provide detailed, evidence-based explanations. CASPs, which submitted the most reports, should prioritise accuracy to avoid overwhelming the FIU with low-value filings.
How to Apply This Correctly
- Download and review MOKAS’ *Annual Sectorial Quantity & Quality Assessment of STRs/SARs for 2025* (attached to Circular C805).
- Compare your 2025 STR/SAR submissions against the report’s sector-specific findings. Identify gaps in narrative quality, attachments, or identification details.
- Update internal policies and procedures to address common deficiencies. For example, enforce a minimum 400-character narrative and mandate attachment checks before submission.
- Train staff on emerging risk indicators (e.g., virtual assets, money mules) and sector-specific typologies highlighted in the report.
- Monitor goAML system updates for revised ML/TF indicators and ensure your team uses the latest predefined list.
- Conduct a sample review of past submissions to verify compliance with MOKAS’ expectations. Document corrective actions taken.
Compliance Officer Checklist
- Reviewed MOKAS’ 2025 assessment report and identified sector-specific deficiencies.
- Updated internal STR/SAR policies to enforce narrative length, attachment requirements, and identification details.
- Trained staff on high-risk indicators (e.g., virtual assets, cyber fraud) and sector trends.
- Verified goAML system compliance, including use of predefined ML/TF indicators.
- Conducted a sample audit of past submissions to confirm improvements.
- Documented corrective actions and policy updates for supervisory review.
Evidence to Retain
- MOKAS’ *Annual Sectorial Quantity & Quality Assessment of STRs/SARs for 2025* (attached to Circular C805).
- Internal records of STR/SAR submissions, including narratives, attachments, and goAML confirmation receipts.
- Training materials and attendance logs demonstrating staff awareness of report findings.
- Policy documents updated to reflect MOKAS’ expectations (e.g., narrative length, attachment requirements).
- Sample audit reports of past submissions, highlighting corrective actions taken.
Why This Matters
Non-compliance with MOKAS’ expectations risks undermining the effectiveness of Cyprus’ AML/CFT framework. Deficient STRs/SARs delay financial intelligence analysis, hinder criminal investigations, and may trigger supervisory scrutiny. In 2025, MOKAS disseminated 572 intelligence reports to law enforcement—up from 205 in 2024—demonstrating the critical role of high-quality filings. Failure to address deficiencies could result in reputational damage, regulatory action, or enforcement measures under AML/CFT laws.
Frequently Asked Questions
Is this a new obligation or a clarification?
This circular is a **clarification and reminder** of existing obligations under AML/CFT laws. It does not introduce new requirements but highlights deficiencies in 2025 STR/SAR submissions and expects firms to improve future filings.
What are the most common reasons for failed submissions?
In 2025, 185 reports failed due to: (1) Narratives outside 400–4,000 characters (26%); (2) Missing attachments (26%); (3) Incomplete identification details (14%); or (4) Missing entity information (10%).
Which sectors submitted the most STRs/SARs in 2025?
Crypto Asset Service Providers (CASPs) submitted 20,570 reports (85% of total), followed by investment firms (980) and payment institutions (340). Traditional sectors like banking submitted 597 reports.
What were the top risk indicators in 2025?
The most used indicators were: (1) Transactions related to virtual assets; (2) Use of money mules; (3) Transactions between unrelated counterparties; (4) Internet fraud/cyber crime; and (5) Money laundering.
How does MOKAS categorise STRs/SARs?
Reports are prioritised as “Low,” “Medium,” “Medium Serious,” or “High” based on predefined risk criteria. This ensures efficient allocation of analytical resources to high-risk cases.
What happens if my firm ignores this circular?
Ignoring the circular may lead to persistent deficiencies in your STR/SAR filings, increasing the risk of supervisory scrutiny, enforcement action, or reputational harm. MOKAS communicates deficiencies to firms on a case-by-case basis.
How CX Financia Can Support You
At CX Financia, we help firms align with MOKAS’ expectations through our **Regulatory Compliance** and **AML/CFT** services. Our team assists with policy reviews, staff training on STR/SAR quality, and goAML system compliance. We also provide **Risk Management** and **Internal Audit** services to identify gaps in your AML framework. Contact us to ensure your filings meet regulatory standards and support Cyprus’ financial intelligence efforts.
Read the CySEC Circular C805
Read more at Regulatory Updates
Disclaimer
This article provides general information based on CySEC Circular C805 and is not regulatory advice. For specific compliance queries, consult your legal or compliance advisor. CX Financia does not accept liability for actions taken based on this content.
