France
4 regulators · 3 instruments · 5 obligations · 1 upcoming deadline
France is an international nation which is sovereign and occupies most of Western Europe.
Regulatory pulse · 90 days
Laws & circulars Enforcement NewsOverview
VERIFIED 18 SEP 2026France is an international nation which is sovereign and occupies most of Western Europe. France is one of the leading countries which formed the European Union (EU) and the Eurozone. The economy of France is ranked third largest in Europe and seventh in the whole world. It acts as a critical point of reference for foreign business and industry as well as foreign investments. Being a semi-presidential constitutional republic, France has a complex legal system based on civil laws.
In terms of the macroeconomic situation, France represents a relatively safe environment to operate in thanks to well-established capital markets, modern technological infrastructure, and good credit rating. The risks on the governmental level are small, but businesses need to be prepared for dealing with high corporate tax levels, tough labor market rules, and some sporadic social unrest or strikes. As for the technological risk, the risk of cyber threats is rather high and businesses need to protect themselves from corporate espionage and ransomware attacks on European infrastructure.
French compliance requirements are tough, extensive, and highly linked to EU rules. Companies are required to comply strictly with the GDPR concerning data protection, as well as strict ESG corporate reporting requirements. French compliance requirements are very tough owing to the introduction of the Sapin II law, which imposes one of the most aggressive corruption prevention systems globally. The Sapin II law obligates companies to establish compliance programs, whistleblower policies, and independent third party verification processes, with the initiative led by the French Anti-Corruption Agency (AFA).
The French corporate governance system is marked by the feature of rigid structural transparency and high stakeholder accountability. The company can opt for either the unitary board system or the two-tier system, wherein there are two separate boards called management board (directoire) and supervisory board (conseil de surveillance). The board systems emphasize gender diversity and mandatory inclusion of employees under the statutory laws of France. Additionally, the corporate environment requires deep supply chain transparency as per the Corporate Duty of Vigilance Law (Loi de Vigilance), where the large companies need to formulate vigilance plans to avoid human rights violations, safety hazards, and environmental harm in subsidiaries/supply chains globally.
France is one of the most vital components of the global financial infrastructure and therefore makes sure that all its sanctions are aligned with United Nations Security Council (UNSC) and EU resolutions. Directorate General of the Treasury is the principal regulator in relation to sanctions, financial and economic restrictions and export controls. France has an absolute no-tolerance policy in regard to the bypassing of trade sanctions or trading with blacklisted parties, especially when it comes to military dual-use technologies. In order not to face serious regulatory sanctions and damage to reputation and even criminal prosecution, banks and multinational companies doing business in France must have an automated screening system.
Who regulates what
View all →Key laws & regulations
All Laws & Regulations →| Instrument | Type | Year | Regulator | Source |
|---|---|---|---|---|
| Loi Sapin II | Act | 2016 | — | official |
| Book V, Title VI of the French Monetary and Financial Code | Act | 2009 | TRACFIN | official |
| AMF General Regulation | Regulation | 2004 | AMF | official |
| No instruments match these filters. | ||||
Industry compliance
Essential obligations
All obligations →| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| AML compliance programme and officer | Ongoing | ACPR | source | |
Within the French Monetary and Financial Code and AMF General Regulation, the AML compliance program and officer system is regarded as an obligation on an ongoing basis, one which has a timing value of a continuous nature. The continuous timing value means that the regulated financial institution should have continuous surveillance of its business environment through automated daily screening against sanction lists worldwide, continuous profiling of risks, and automated transaction monitoring. It does not mean a periodic check, but rather it refers to continuous monitoring without any pause during the whole life cycle of each client relationship in order to stop financial crimes. Even though there are secondary elements with other timelines, such as a 5-year period of retention of documents and an annual cycle of training of staff members, the general structural obligation requires the presence of daily compliance. |
||||
| AML record retention | 5 years | TRACFIN | source | |
In the French Monetary and Financial Code, the AML record retention structure is categorized entirely under a retention obligation, with a fixed retention period of 5 years. In other words, the regulatory framework specifies that financial institutions have to secure and store all records related to customers' identification (KYC), risks, and transactions in an immutable medium. The retention period of 5 years serves as a retroactive tool, aimed at law enforcement, since the countdown starts at the moment when the account is closed for customer identity or when the transaction is completed. In this way, the obligation enables the preservation of financial records that can be easily accessed by TRACFIN and judicial bodies regardless of GDPR erasure requests. |
||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | TRACFIN | source | |
The French Monetary and Financial Code and the AMF General Regulation describe the Customer Due Diligence (KYC/CDD) process as an obligation with a continuous, real-time/daily timing requirement. This regulation requires financial institutions subject to it to maintain constant vigilance, conduct daily automated screenings against asset-freezing lists worldwide, and continue monitoring transaction patterns against the customer's socio-economic profile. It is therefore not a static process but is dynamic, as the process will be ongoing through the life of the relationship with the client. There are structured risk-based timings involved in the KYC process, which range from immediate event triggering for high-risk cases to periodic refreshing of data for a period of between 1 and 5 years, depending on the risk rating of the client. |
||||
| Suspicious transaction reporting | Event-based | TRACFIN | source | |
According to the French Monetary and Financial Code, the Suspicious Transaction Reporting regime is considered an event-based obligation subject to a rigid timing requirement of immediate / without delay (sans délai). The legal requirement stipulates that once a compliance officer or TRACFIN correspondent becomes certain about the suspicions surrounding the transactions or funds being associated with money laundering, tax fraud, or terrorist financing, the formal declaration of suspicion (déclaration de soupçon) should be made directly to TRACFIN. Unlike the calendar-based obligations, the trigger for the reporting duty arises exclusively from the emergence of a compliance risk or transaction alert. In practice, the report must be made either before conducting the transaction in order for TRACFIN to use its blocking authority, or right after the transaction has been completed if the blocking was not possible. Regardless of which, the rigid requirement of the “tipping-off” prohibition, under which the client cannot be notified, remains in effect. |
||||
| Personal data breach notification | Event-based | CNIL | official | |
In the case of GDPR and the French Data Protection Act (Loi Informatique et Libertés), the breach notification requirement is considered an event-driven requirement subject to a strict, split timing value of 72 hours and without undue delay [Status]. Such legal requirement states that the moment a financial organization or data controller becomes aware of a security event that causes personal data to be accessed, altered, or lost, the corporate reporting requirement becomes active. In practice, the firm is required to notify the CNIL (French Data Protection Authority) within a maximum period of 72 hours following the security event, providing information about its nature, the categories of personal data compromised, and the measures taken to prevent the issue [Status]. Besides, when such an event poses a high risk to the rights of individuals, such as being prone to identity theft or financial fraud, the firm is obliged to report such a breach to all affected parties without undue delay. |
||||
| No obligations match these filters. | ||||



