Anti-Money Laundering (AML/CFT) Services in Romania & Internationally


I provide tailored AML/CFT advisory services to organizations in Romania and internationally, helping them understand regulatory requirements, identify and manage ML/TF risks, and develop effective, proportionate and practical compliance frameworks.

AML/CFT Compliance Services Tailored to Your Business

I provide end-to-end AML/CFT compliance support tailored to each organization’s business model, risk exposure and regulatory obligations. From independent AML/CFT audits and risk assessments to compliance frameworks, policies and procedures, customer due diligence, transaction monitoring, reporting and training, my approach combines regulatory requirements with practical implementation.

Services are designed for regulated businesses in Romania and internationally, with particular attention to compliance with Law no. 129/2019, ONPCSB regulations and guidance, EU AML/CFT legislation and FATF standards.

AML/CFT Program, Policies & Procedures Development

I design and implement AML/CFT compliance frameworks tailored to your organization’s business model, size, customer profile and specific ML/TF risk exposure, in line with applicable Romanian and EU requirements, including Law no. 129/2019, relevant ONPCSB regulations and guidance, EU AML/CFT legislation and FATF standards. I can develop a complete AML/CFT program from the ground up or review and update an existing framework to address regulatory changes, identified gaps or changes in the business.

Depending on your organization’s needs, the engagement may include the development or revision of the business-wide ML/TF risk assessment, AML/CFT policies and procedures, customer acceptance and risk classification methodology, CDD/EDD processes, internal reporting and suspicious transaction escalation procedures, record-keeping requirements, governance and responsibilities, as well as the supporting forms and operational documentation required for effective implementation.

The objective is not simply to produce compliant documentation, but to build an AML/CFT framework that reflects how your organization actually operates and can be applied effectively in day-to-day activity.

Comprehensive Assessment of Your Existing AML/CFT Program

Not every organization needs a formal independent AML/CFT audit, but every regulated business should know whether its compliance framework actually works.

I conduct a comprehensive review of your existing AML/CFT program, assessing its alignment with applicable regulatory requirements and the specific ML/TF risks of your business. The review covers key elements such as the business-wide risk assessment, internal policies and procedures, customer risk classification and CDD/EDD processes, transaction monitoring and reporting arrangements, governance, record-keeping and staff training.

The assessment identifies gaps, inconsistencies and areas where documented controls are not effectively implemented in practice. You receive clear, prioritized recommendations showing what needs to be corrected, strengthened or updated — without the scope and formality of a full independent AML/CFT audit.

AML/CFT Risk Assessment & Risk Methodology

I develop and conduct AML/CFT risk assessments tailored to your organization’s activities, business model and regulatory obligations. The assessment identifies and evaluates the ML/TF risks to which the organization is exposed, taking into account relevant risk factors such as customers, products and services, transactions, delivery channels and geographic exposure, in accordance with the risk-based approach required by Law no. 129/2019 and the applicable Romanian and EU AML/CFT framework.

Depending on your needs, I can develop the underlying risk assessment methodology, including risk factors, indicators, scoring criteria, weighting and risk classification rules, and apply it at both business-wide and customer level.
Existing methodologies and risk assessments can also be reviewed and updated to reflect changes in the business, regulatory requirements or identified risk exposure.

The result is a documented and practical risk-based framework that supports customer risk classification, the application of appropriate CDD/EDD measures and informed AML/CFT decision-making.

Independent AML/CFT Audit

Romanian AML/CFT legislation requires certain reporting entities to ensure an independent audit function for testing the adequacy and effectiveness of their AML/CFT policies, internal rules, controls and risk management procedures. The applicability, scope and frequency of this requirement depend on the nature and size of the organization, as well as on the specific regulations or instructions issued by the competent supervisory authority or self-regulatory body.

I conduct independent AML/CFT audits in accordance with Law no. 129/2019 and the applicable sector-specific regulatory framework, taking into account the requirements and expectations of ONPCSB or, where relevant, other competent supervisory authorities and professional bodies.

The audit assesses both the design and practical implementation of the AML/CFT framework and may cover the business-wide risk assessment, policies and procedures, governance and responsibilities, customer risk assessment and CDD/EDD, transaction monitoring and reporting, record-keeping, training and internal controls. The scope and testing methodology are tailored to the organization’s activity, size, complexity and ML/TF risk exposure.

The engagement results in an independent AML/CFT audit report documenting the findings, identified deficiencies and areas for improvement, together with prioritized remediation recommendations. Where periodic independent audit is required by the applicable sectoral framework, the engagement can be structured accordingly to support ongoing compliance with that obligation.

AML/CFT Regulatory Inspection & Remediation Support

I support organizations before, during and after AML/CFT inspections or supervisory reviews, helping them understand regulatory expectations, assess their level of preparedness and address identified compliance deficiencies. My previous experience in AML/CFT supervision and control provides me with a practical understanding of how compliance frameworks are assessed by supervisory authorities and where implementation weaknesses may arise.

Before an inspection, support may include a targeted review of the AML/CFT framework and documentation, identification of potential gaps, preparation of relevant records and evidence of implementation, and guidance for management, the designated person and other employees involved in the control process.

Following an inspection or supervisory action, I can assist with the analysis of findings and measures imposed, development of remediation plans, revision of policies, procedures and risk assessments, and implementation of corrective actions within the applicable deadlines.

Support is tailored to the applicable Romanian AML/CFT framework and, where relevant, to the regulations, instructions and supervisory requirements of ONPCSB or other competent sectoral authorities.

Ongoing AML/CFT Advisory & Outsourced Compliance Officer

 AML/CFT compliance is an ongoing process, not a one-time exercise. I provide continuous advisory support to organizations that need specialized AML/CFT expertise without necessarily maintaining a dedicated in-house compliance function or expanding their existing compliance team.

I can act as your outsourced AML/CFT Compliance Officer, giving your organization direct access to senior-level expertise without the costs and administrative burden associated with recruiting and maintaining a permanent in-house position. Whether you need full-time or part-time support, the engagement can be tailored to the size and complexity of your business, its risk profile and the level of involvement required. This provides a flexible and cost-effective alternative for organizations that need experienced AML/CFT leadership without the commitment of a permanent hire.

Depending on the organization’s needs, ongoing support may include regulatory updates and impact assessments, review and update of policies, procedures and risk assessments, complex CDD/EDD cases and customer risk classification, PEP and sanctions matters, analysis of unusual or potentially suspicious activity, reporting obligations, staff training and preparation for regulatory inspections.

The scope of the engagement is tailored to your regulatory obligations, business model and internal resources, whether you need ongoing specialist advice, an outsourced compliance function or a combination of both.

AML/CFT Training & Awareness

I design and deliver AML/CFT training tailored to your organization’s activities, risk profile and the specific responsibilities of your employees. Training is designed to translate regulatory requirements into practical knowledge that staff can apply in their day-to-day work.

Depending on the audience and the organization’s needs, training may cover AML/CFT obligations, customer due diligence, identification of ML/TF risk factors and suspicious activity, internal escalation and reporting procedures, PEPs and sanctions, as well as industry-specific red flags and typologies. Dedicated training can also be provided for management, compliance personnel and the designated person.

Training content is aligned with the applicable requirements of Law no. 129/2019 and relevant ONPCSB regulations and guidance, and can be adapted to address regulatory changes, findings from internal reviews or audits, or specific weaknesses identified within the organization.

Benefits of Collaborating with a Freelance AML Consultant in Romania

  • Tap into proven expertise – With over 25 years of professional experience across regulatory supervision, consulting and in-house roles, I bring extensive AML/CFT knowledge and a practical understanding of regulatory expectations.
  • Gain fresh perspectives – Thanks to my work across multiple industries, I can provide innovative and practical solutions to AML challenges, tailored to your company’s unique risk profile.
  • Ensure thorough compliance – I help you identify and address compliance gaps and strengthen your AML/CFT framework in line with Law no. 129/2019, ONPCSB requirements and guidance, EU AML/CFT legislation and FATF standards.
  • Scalable to your needs – My services can be adapted to your organization’s size, industry, and risk level, with flexible resources and involvement that evolve as your business grows.
  • Cost-effective solution – By working directly with me, you gain top-level AML expertise without the high costs of large consulting firms — a smarter investment in compliance.
  • Build credibility and trust – A well-designed and effectively implemented AML/CFT framework demonstrates a strong commitment to compliance and helps build confidence among regulators, clients, investors and business partners.

FAQ

When is an independent AML/CFT audit mandatory in Romania?

Under Article 24(2) of Law no. 129/2019, reporting entities may be required to ensure an independent audit function for testing their AML/CFT policies, internal rules, controls and risk management procedures, depending on the size and nature of their activity.

For entities supervised and controlled by ONPCSB, the implementing rules approved by Order no. 37/2021 require an independent AML/CFT audit when, in the last completed financial year, the entity exceeds at least two of the following three criteria:

  • total assets: RON 16,000,000
  • net turnover: RON 32,000,000
  • average number of employees: 50

Sector-specific rules may establish equivalent or additional requirements, including the frequency of the audit. For this reason, the applicable framework should always be checked based on the type of reporting entity and its competent supervisory authority.

Even where a formal independent audit is not mandatory, an AML/CFT compliance review can still be useful for identifying gaps, assessing the effectiveness of the existing framework and preparing for regulatory inspections.

What AML/CFT documents and procedures must a reporting entity have in place in Romania?

Under Law no. 129/2019 and the applicable regulatory framework, reporting entities must establish and implement an AML/CFT framework appropriate to the nature, size and risks of their activity. The exact documentation required may vary depending on the type of reporting entity and the applicable sector-specific requirements.

In practice, the AML/CFT framework should cover the key areas of compliance, including:

  • ML/TF risk management – business-wide risk assessment, risk methodology and customer risk classification;
  • KYC and customer due diligence – customer identification and verification, beneficial ownership, PEPs and simplified, standard and enhanced due diligence;
  • Monitoring and reporting – ongoing monitoring, identification and internal escalation of suspicious activity, suspicious transaction reporting and other mandatory reporting, including cash transactions and external transfers, where applicable;
  • International sanctions – screening and management of sanctions-related risks and obligations;
  • Governance and internal controls – AML/CFT roles and responsibilities, internal controls, record-keeping and confidentiality requirements;
  • Training and implementation – employee training, operational forms, registers and evidence that the AML/CFT framework is effectively applied in practice.

These should not be generic, stand-alone documents. They should form a coherent AML/CFT framework tailored to the organization’s actual business model, customers, products and services, geographic exposure and specific ML/TF risks.

What is the difference between a business-wide AML/CFT risk assessment and a customer risk assessment?

They serve different purposes and should not be confused. A business-wide AML/CFT risk assessment evaluates the overall money laundering and terrorist financing risks to which the organization is exposed, considering factors such as its customers, products and services, transactions, delivery channels and geographic exposure. It provides the foundation for the organization’s risk-based AML/CFT framework and controls.

A customer risk assessment, on the other hand, evaluates the ML/TF risk associated with an individual customer or business relationship. It considers relevant customer-specific risk factors and determines the customer’s risk classification and the level of due diligence and ongoing monitoring that should be applied.

The two are interconnected: the organization’s overall risk assessment should inform the methodology used to assess individual customers, while customer-level risk information contributes to the organization’s understanding of its overall ML/TF exposure. Both must be documented, kept up to date and capable of being demonstrated in practice.

What are the main AML/CFT obligations for a newly established reporting entity in Romania?

For a newly established reporting entity, AML/CFT compliance starts before the first customer is onboarded.
One of the first steps is to ensure that the company’s beneficial ownership information is correctly identified, documented and, where applicable, declared and kept up to date with the Romanian Trade Registry (ONRC) / Register of Beneficial Owners (RBR).

Where the entity falls under the supervision of ONPCSB, the next step is to complete the applicable registration or notification formalities with the Office, within the required timeframe. The organization should then establish its AML/CFT governance structure by appointing the person or persons responsible for compliance, where required, and ensuring that their responsibilities, authority and access to information are clearly defined. Any other notifications required by the competent supervisory authority should also be completed within the applicable deadlines.
With the governance structure in place, the organization needs to understand its own ML/TF exposure and build an AML/CFT program around the risks of its actual business. This means moving from the business-wide risk assessment to practical controls for customer onboarding and KYC, customer risk classification, ongoing monitoring, identification and reporting of suspicious or otherwise reportable transactions, international sanctions compliance, record-keeping and staff training.

The important point is that AML/CFT compliance should be operational from the beginning. Having policies and procedures on file is not sufficient if the organization cannot demonstrate that they are actually reflected in how customers are onboarded, risks are assessed, transactions are monitored and compliance decisions are made.

Related Services: Risk Management and Information Confidentiality


Beyond AML/CFT compliance, I also provide specialized support in:

  • Risk Management Services – Development and implementation of risk management frameworks, risk assessments and risk registers tailored to the organization’s activities, objectives and risk profile.

  • Information Confidentiality Services – Development of information classification and confidentiality frameworks, including classification methodologies, internal policies and practical rules for handling and protecting sensitive information.

Contact Guardian Compass

AML - Risk Advisory & Data Privacy


Phone: +40 733 920 484

Email: ioana@guardiancompass.ro


©2026 Guardian Compass, All right reserved.