Skip to main content

AI Summary of Article 16 Group-wide requirements

Parent undertakings must ensure that internal procedures, risk assessment and staffing requirements apply to all group branches and subsidiaries in Member States and, for groups headquartered in the Union, in third countries. They must perform a group-wide risk assessment informed by business-wide assessments from branches and subsidiaries, and establish and implement group-wide policies, procedures and controls for AML/CFT, including data protection and intra-group information sharing; obliged entities must implement those measures taking account of their specificities and risks. Group-wide policies and risk assessments must include the elements listed in Articles 9 and 10 and take account of information published by authorities where group establishments are located.

Group-level compliance functions are required, including a compliance manager and, where justified, a compliance officer, with the scope documented. The compliance manager must report regularly to the management body in its management function and at minimum submit an annual implementation report and remedy identified deficiencies; they shall assist collectively responsible management bodies and prepare necessary decisions. Group policies must require exchange of customer due diligence and ML/TF risk information — including identity, beneficial ownership, purpose of relationship and suspicions with supporting analyses reported to the FIU under Article 69 — and permit non-obliged entities to provide relevant information to obliged entities. Parents must ensure confidentiality, data protection and appropriate use of exchanged information. AMLA must deliver draft RTS by 10 July 2026 specifying minimum requirements for group policies, information-sharing standards, criteria for identifying parent undertakings in specified cases and conditions applying to entities in structures with common ownership, management or compliance control; the Commission is delegated to adopt those RTS under Articles 49–52 of Regulation (EU) 2024/1620.

Version status: Entered into force | Document consolidation status: No known changes
Version date: 9 July 2024 - 9 July 2027
Version 2 of 3

Article 16 Group-wide requirements

1. A parent undertaking shall ensure that the requirements on internal procedures, risk assessment and staff referred to in Section 1 of this Chapter apply in all branches and subsidiaries of the group in the Member States and, for groups whose head office is located in the Union, in third countries. To this end, a parent undertaking shall perform a group-wide risk assessment, taking into account the business-wide risk assessment performed by all branches and subsidiaries of the group, and establish and implement group-wide policies, procedures and controls, including on data protection and on information sharing within the group for AML/CFT purposes and to ensure that employees within the group are aware of the requirements arising from this Regulation. Obliged entities within the group shall implement those group-wide policies, procedures and controls, taking into account their specificities and the risks to which they are exposed.

 The group-wide policies, procedures and controls and the group-wide risk assessments referred to in the first subparagraph shall include all the elements listed in Articles 9 and 10, respectively.