Act 2010
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010
An tAcht um Cheartas Coiriúil
Issued by Central Bank of Ireland
Effective: 14 Jun 2010
Last amended: 20 Feb 2026
Plain-English summary
The Criminal Justice (Money Laundering and Terrorist Financing) Act of 2010 acts as the key legislation in the compliance regime for anti-money laundering and counter-terrorism financing in Ireland. The current legislation requires customer due diligence and suspicious transaction reporting by designated businesses, with more recent changes extending coverage to digital asset services businesses.
Who it applies to
Banking · NBFC / Non-bank Lending · Asset & Wealth Management · DNFBPs (Lawyers, Accountants, Dealers)
Topics
AML / CFT / Sanctions
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| AML compliance programme and officer | Ongoing | CBI | source | |
The Ireland AML Compliance Programme and Officer Obligations framework is an extremely stringent mandatory statutory framework under which the personal criminal liability of senior executives is imposed to safeguard the jurisdiction's financial system from the threat of illicit capital outflow. Being an ongoing operational responsibility, it is the legal duty of regulated firms to undertake continuous risk assessment and transaction monitoring and customer due diligence on a risk basis under the supervision of the Central Bank of Ireland. Simultaneously, the framework also imposes an event-driven reporting requirement whereby it becomes the legal responsibility of the designated Money Laundering Reporting Officer (MLRO), who has been pre-approved for a PCF-14 controlled function, to immediately submit a STR to FIU Ireland through the goAML portal, in case of any red flags indicating financial crimes, without failing to observe absolute "tipping-off" secrecy restrictions |
||||
| AML record retention | Retention period 5 years | CBI | source | |
The AML Record Retention Obligation in Ireland comprises a strict statutory requirement under Section 55 of the Criminal Justice Act 2010 that mandates all regulated organizations to retain compliance and transaction records for at least five years [revisedacts.lawreform.ie]. Described as a record retention and continuous management requirement, the five-year statutory period begins either on the termination of the business relationship (Customer Due Diligence, passport copies, and corporate profile) or after the precise date of individual transactions [revisedacts.lawreform.ie]. Under the watchful eyes of the Central Bank of Ireland, the record retention obligation supersedes the GDPR right to data deletion ("right to be forgotten") for the active five-year period and requires organizations to store them safely for later destruction. |
||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | CBI | source | |
The Customer Due Diligence (KYC/CDD) Requirement in Ireland entails a rigorous and obligatory statutory process set out in Chapter 4 of the Criminal Justice Act 2010, where financial institutions are required to continuously identify and verify their clients through official documentation. Under a risk-based classification system that is highly sensitive to changing conditions, this continuous and event-driven requirement entails firms being required to conduct identification and verification checks upon onboarding, conducting Enhanced Due Diligence upon identifying Politically Exposed Persons or jurisdictions deemed high risk, and identifying ultimate beneficial owners of greater than 25% ownership. The process is supervised by the Central Bank of Ireland, with failure to meet the KYC/CDD requirements disqualifying the firm from statutory compliance status, thereby leaving both firms and authorized compliance officers open to severe penalties. |
||||
| Suspicious transaction reporting | Deadline Event-based | CBI | source | |
Suspicious Transaction Reporting Requirement in Ireland is an absolute statutory requirement under Section 42 of the Criminal Justice Act 2010 that makes it mandatory for regulated companies, along with the designated Money Laundering Reporting Officers (MLROs), to report suspicion of financial crime to the authorities [revisedacts.lawreform.ie]. Explicitly categorized as a trigger event, the statutory mechanism becomes operative the instant there are grounds of suspicion of the dealings or the property of a client [revisedacts.lawreform.ie]. The obligation requires the company to follow a mandatory double reporting process where the Suspicious Transaction Report (STR) must be electronically forwarded through the goAML portal to both FIU Ireland and the Office of the Revenue Commissioners [fiu-ireland.ie, revisedacts.lawreform.ie]. Stringently supervised by the Central Bank of Ireland, non-compliance with reporting or even breach of stringent "tipping-off" provisions comes at a huge cost for the compliance officer in terms of criminal conviction, a hefty fine, and imprisonment of five years |
||||
| No obligations match these filters. | ||||
Latest news
-
AUSTRAC Examines Western Union AML Controls and Transaction Monitoring
26 Sep 2026
Australia's financial intelligence unit has initiated a formal investigation into Western Union's anti-money laundering framework and compliance infrastructure. The regulatory examination focuses on the company's paymen…
-
RBI penalizes Ola Financial Services for KYC compliance failures
25 Sep 2026
The Reserve Bank of India imposed a monetary penalty of ₹3.10 lakh on Ola Financial Services Private Limited for non-compliance with KYC directions under the Payment and Settlement Systems Act, 2007. Following a statuto…