France
4 regulators · 3 instruments · 5 obligations · 1 upcoming deadline
| Obligation | Timing | Regulator | Arises from | Source | Detail |
|---|---|---|---|---|---|
| Banking | |||||
| AML compliance programme and officer | Ongoing | ACPR | Book V, Title VI of the French Monetary and Financial Code | source | |
Within the French Monetary and Financial Code and AMF General Regulation, the AML compliance program and officer system is regarded as an obligation on an ongoing basis, one which has a timing value of a continuous nature. The continuous timing value means that the regulated financial institution should have continuous surveillance of its business environment through automated daily screening against sanction lists worldwide, continuous profiling of risks, and automated transaction monitoring. It does not mean a periodic check, but rather it refers to continuous monitoring without any pause during the whole life cycle of each client relationship in order to stop financial crimes. Even though there are secondary elements with other timelines, such as a 5-year period of retention of documents and an annual cycle of training of staff members, the general structural obligation requires the presence of daily compliance. |
|||||
| AML record retention | Retention period 5 years | TRACFIN | Book V, Title VI of the French Monetary and Financial Code | source | |
In the French Monetary and Financial Code, the AML record retention structure is categorized entirely under a retention obligation, with a fixed retention period of 5 years. In other words, the regulatory framework specifies that financial institutions have to secure and store all records related to customers' identification (KYC), risks, and transactions in an immutable medium. The retention period of 5 years serves as a retroactive tool, aimed at law enforcement, since the countdown starts at the moment when the account is closed for customer identity or when the transaction is completed. In this way, the obligation enables the preservation of financial records that can be easily accessed by TRACFIN and judicial bodies regardless of GDPR erasure requests. |
|||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | TRACFIN | Book V, Title VI of the French Monetary and Financial Code | source | |
The French Monetary and Financial Code and the AMF General Regulation describe the Customer Due Diligence (KYC/CDD) process as an obligation with a continuous, real-time/daily timing requirement. This regulation requires financial institutions subject to it to maintain constant vigilance, conduct daily automated screenings against asset-freezing lists worldwide, and continue monitoring transaction patterns against the customer's socio-economic profile. It is therefore not a static process but is dynamic, as the process will be ongoing through the life of the relationship with the client. There are structured risk-based timings involved in the KYC process, which range from immediate event triggering for high-risk cases to periodic refreshing of data for a period of between 1 and 5 years, depending on the risk rating of the client. |
|||||
| Suspicious transaction reporting | Deadline Event-based | TRACFIN | Book V, Title VI of the French Monetary and Financial Code | source | |
According to the French Monetary and Financial Code, the Suspicious Transaction Reporting regime is considered an event-based obligation subject to a rigid timing requirement of immediate / without delay (sans délai). The legal requirement stipulates that once a compliance officer or TRACFIN correspondent becomes certain about the suspicions surrounding the transactions or funds being associated with money laundering, tax fraud, or terrorist financing, the formal declaration of suspicion (déclaration de soupçon) should be made directly to TRACFIN. Unlike the calendar-based obligations, the trigger for the reporting duty arises exclusively from the emergence of a compliance risk or transaction alert. In practice, the report must be made either before conducting the transaction in order for TRACFIN to use its blocking authority, or right after the transaction has been completed if the blocking was not possible. Regardless of which, the rigid requirement of the “tipping-off” prohibition, under which the client cannot be notified, remains in effect. |
|||||
| Telecom & Tech | |||||
| Personal data breach notification | Deadline Event-based | CNIL | — | official | |
In the case of GDPR and the French Data Protection Act (Loi Informatique et Libertés), the breach notification requirement is considered an event-driven requirement subject to a strict, split timing value of 72 hours and without undue delay [Status]. Such legal requirement states that the moment a financial organization or data controller becomes aware of a security event that causes personal data to be accessed, altered, or lost, the corporate reporting requirement becomes active. In practice, the firm is required to notify the CNIL (French Data Protection Authority) within a maximum period of 72 hours following the security event, providing information about its nature, the categories of personal data compromised, and the measures taken to prevent the issue [Status]. Besides, when such an event poses a high risk to the rights of individuals, such as being prone to identity theft or financial fraud, the firm is obliged to report such a breach to all affected parties without undue delay. |
|||||
| No obligations match these filters. | |||||