I provide tailored AML/CFT advisory services to organizations in Romania and internationally, helping them understand regulatory requirements, identify and manage ML/TF risks, and develop effective, proportionate and practical compliance frameworks.
I provide end-to-end AML/CFT compliance support tailored to each organization’s business model, risk exposure and regulatory obligations. From independent AML/CFT audits and risk assessments to compliance frameworks, policies and procedures, customer due diligence, transaction monitoring, reporting and training, my approach combines regulatory requirements with practical implementation.
Services are designed for regulated businesses in Romania and internationally, with particular attention to compliance with Law no. 129/2019, ONPCSB regulations and guidance, EU AML/CFT legislation and FATF standards.
I design and implement AML/CFT compliance frameworks tailored to your organization’s business model, size, customer profile and specific ML/TF risk exposure, in line with applicable Romanian and EU requirements, including Law no. 129/2019, relevant ONPCSB regulations and guidance, EU AML/CFT legislation and FATF standards. I can develop a complete AML/CFT program from the ground up or review and update an existing framework to address regulatory changes, identified gaps or changes in the business.
Depending on your organization’s needs, the engagement may include the development or revision of the business-wide ML/TF risk assessment, AML/CFT policies and procedures, customer acceptance and risk classification methodology, CDD/EDD processes, internal reporting and suspicious transaction escalation procedures, record-keeping requirements, governance and responsibilities, as well as the supporting forms and operational documentation required for effective implementation.
The objective is not simply to produce compliant documentation, but to build an AML/CFT framework that reflects how your organization actually operates and can be applied effectively in day-to-day activity.
Not every organization needs a formal independent AML/CFT audit, but every regulated business should know whether its compliance framework actually works.
I conduct a comprehensive review of your existing AML/CFT program, assessing its alignment with applicable regulatory requirements and the specific ML/TF risks of your business. The review covers key elements such as the business-wide risk assessment, internal policies and procedures, customer risk classification and CDD/EDD processes, transaction monitoring and reporting arrangements, governance, record-keeping and staff training.
The assessment identifies gaps, inconsistencies and areas where documented controls are not effectively implemented in practice. You receive clear, prioritized recommendations showing what needs to be corrected, strengthened or updated — without the scope and formality of a full independent AML/CFT audit.
I develop and conduct AML/CFT risk assessments tailored to your organization’s activities, business model and regulatory obligations. The assessment identifies and evaluates the ML/TF risks to which the organization is exposed, taking into account relevant risk factors such as customers, products and services, transactions, delivery channels and geographic exposure, in accordance with the risk-based approach required by Law no. 129/2019 and the applicable Romanian and EU AML/CFT framework.
Depending on your needs, I can develop the underlying risk assessment methodology, including risk factors, indicators, scoring criteria, weighting and risk classification rules, and apply it at both business-wide and customer level.
Existing methodologies and risk assessments can also be reviewed and updated to reflect changes in the business, regulatory requirements or identified risk exposure.
The result is a documented and practical risk-based framework that supports customer risk classification, the application of appropriate CDD/EDD measures and informed AML/CFT decision-making.
Romanian AML/CFT legislation requires certain reporting entities to ensure an independent audit function for testing the adequacy and effectiveness of their AML/CFT policies, internal rules, controls and risk management procedures. The applicability, scope and frequency of this requirement depend on the nature and size of the organization, as well as on the specific regulations or instructions issued by the competent supervisory authority or self-regulatory body.
I conduct independent AML/CFT audits in accordance with Law no. 129/2019 and the applicable sector-specific regulatory framework, taking into account the requirements and expectations of ONPCSB or, where relevant, other competent supervisory authorities and professional bodies.
The audit assesses both the design and practical implementation of the AML/CFT framework and may cover the business-wide risk assessment, policies and procedures, governance and responsibilities, customer risk assessment and CDD/EDD, transaction monitoring and reporting, record-keeping, training and internal controls. The scope and testing methodology are tailored to the organization’s activity, size, complexity and ML/TF risk exposure.
The engagement results in an independent AML/CFT audit report documenting the findings, identified deficiencies and areas for improvement, together with prioritized remediation recommendations. Where periodic independent audit is required by the applicable sectoral framework, the engagement can be structured accordingly to support ongoing compliance with that obligation.
I support organizations before, during and after AML/CFT inspections or supervisory reviews, helping them understand regulatory expectations, assess their level of preparedness and address identified compliance deficiencies. My previous experience in AML/CFT supervision and control provides me with a practical understanding of how compliance frameworks are assessed by supervisory authorities and where implementation weaknesses may arise.
Before an inspection, support may include a targeted review of the AML/CFT framework and documentation, identification of potential gaps, preparation of relevant records and evidence of implementation, and guidance for management, the designated person and other employees involved in the control process.
Following an inspection or supervisory action, I can assist with the analysis of findings and measures imposed, development of remediation plans, revision of policies, procedures and risk assessments, and implementation of corrective actions within the applicable deadlines.
Support is tailored to the applicable Romanian AML/CFT framework and, where relevant, to the regulations, instructions and supervisory requirements of ONPCSB or other competent sectoral authorities.
AML/CFT compliance is an ongoing process, not a one-time exercise. I provide continuous advisory support to organizations that need specialized AML/CFT expertise without necessarily maintaining a dedicated in-house compliance function or expanding their existing compliance team.
I can act as your outsourced AML/CFT Compliance Officer, giving your organization direct access to senior-level expertise without the costs and administrative burden associated with recruiting and maintaining a permanent in-house position. Whether you need full-time or part-time support, the engagement can be tailored to the size and complexity of your business, its risk profile and the level of involvement required. This provides a flexible and cost-effective alternative for organizations that need experienced AML/CFT leadership without the commitment of a permanent hire.
Depending on the organization’s needs, ongoing support may include regulatory updates and impact assessments, review and update of policies, procedures and risk assessments, complex CDD/EDD cases and customer risk classification, PEP and sanctions matters, analysis of unusual or potentially suspicious activity, reporting obligations, staff training and preparation for regulatory inspections.
The scope of the engagement is tailored to your regulatory obligations, business model and internal resources, whether you need ongoing specialist advice, an outsourced compliance function or a combination of both.
I design and deliver AML/CFT training tailored to your organization’s activities, risk profile and the specific responsibilities of your employees. Training is designed to translate regulatory requirements into practical knowledge that staff can apply in their day-to-day work.
Depending on the audience and the organization’s needs, training may cover AML/CFT obligations, customer due diligence, identification of ML/TF risk factors and suspicious activity, internal escalation and reporting procedures, PEPs and sanctions, as well as industry-specific red flags and typologies. Dedicated training can also be provided for management, compliance personnel and the designated person.
Training content is aligned with the applicable requirements of Law no. 129/2019 and relevant ONPCSB regulations and guidance, and can be adapted to address regulatory changes, findings from internal reviews or audits, or specific weaknesses identified within the organization.


Under Article 24(2) of Law no. 129/2019, reporting entities may be required to ensure an independent audit function for testing their AML/CFT policies, internal rules, controls and risk management procedures, depending on the size and nature of their activity.
For entities supervised and controlled by ONPCSB, the implementing rules approved by Order no. 37/2021 require an independent AML/CFT audit when, in the last completed financial year, the entity exceeds at least two of the following three criteria:
Sector-specific rules may establish equivalent or additional requirements, including the frequency of the audit. For this reason, the applicable framework should always be checked based on the type of reporting entity and its competent supervisory authority.
Even where a formal independent audit is not mandatory, an AML/CFT compliance review can still be useful for identifying gaps, assessing the effectiveness of the existing framework and preparing for regulatory inspections.
Under Law no. 129/2019 and the applicable regulatory framework, reporting entities must establish and implement an AML/CFT framework appropriate to the nature, size and risks of their activity. The exact documentation required may vary depending on the type of reporting entity and the applicable sector-specific requirements.
In practice, the AML/CFT framework should cover the key areas of compliance, including:
These should not be generic, stand-alone documents. They should form a coherent AML/CFT framework tailored to the organization’s actual business model, customers, products and services, geographic exposure and specific ML/TF risks.
They serve different purposes and should not be confused. A business-wide AML/CFT risk assessment evaluates the overall money laundering and terrorist financing risks to which the organization is exposed, considering factors such as its customers, products and services, transactions, delivery channels and geographic exposure. It provides the foundation for the organization’s risk-based AML/CFT framework and controls.
A customer risk assessment, on the other hand, evaluates the ML/TF risk associated with an individual customer or business relationship. It considers relevant customer-specific risk factors and determines the customer’s risk classification and the level of due diligence and ongoing monitoring that should be applied.
The two are interconnected: the organization’s overall risk assessment should inform the methodology used to assess individual customers, while customer-level risk information contributes to the organization’s understanding of its overall ML/TF exposure. Both must be documented, kept up to date and capable of being demonstrated in practice.
For a newly established reporting entity, AML/CFT compliance starts before the first customer is onboarded.
One of the first steps is to ensure that the company’s beneficial ownership information is correctly identified, documented and, where applicable, declared and kept up to date with the Romanian Trade Registry (ONRC) / Register of Beneficial Owners (RBR).
Where the entity falls under the supervision of ONPCSB, the next step is to complete the applicable registration or notification formalities with the Office, within the required timeframe. The organization should then establish its AML/CFT governance structure by appointing the person or persons responsible for compliance, where required, and ensuring that their responsibilities, authority and access to information are clearly defined. Any other notifications required by the competent supervisory authority should also be completed within the applicable deadlines.
With the governance structure in place, the organization needs to understand its own ML/TF exposure and build an AML/CFT program around the risks of its actual business. This means moving from the business-wide risk assessment to practical controls for customer onboarding and KYC, customer risk classification, ongoing monitoring, identification and reporting of suspicious or otherwise reportable transactions, international sanctions compliance, record-keeping and staff training.
The important point is that AML/CFT compliance should be operational from the beginning. Having policies and procedures on file is not sufficient if the organization cannot demonstrate that they are actually reflected in how customers are onboarded, risks are assessed, transactions are monitored and compliance decisions are made.
Beyond AML/CFT compliance, I also provide specialized support in:
Phone: +40 733 920 484
Email: ioana@guardiancompass.ro
©2026 Guardian Compass, All right reserved.