Anti-Money Laundering & Counter-Terrorist Financing Policy
1. Purpose and Scope
Albania For Business Sh.p.k. (“the Firm,” “we,” “us,” or “our”) provides company formation, legal, tax, accounting, licensing, real estate advisory and recruitment/HR support to international entrepreneurs, investors and companies establishing or operating in Albania. Several of these activities — including company formation, legal services involving the management of client funds or assets, real estate transactions, and the provision of registered office or nominee services — fall within the categories of “obliged entities” under Albanian anti-money laundering legislation and comparable EU and FATF standards.
This Policy sets out the Firm’s framework for the prevention, detection and reporting of money laundering (ML), terrorist financing (TF) and proliferation financing (PF), and establishes the minimum standards that all partners, employees, contractors and outsourced service providers must follow when engaging with clients, transactions and third parties on behalf of the Firm.
This Policy applies to all services offered by the Firm, all client relationships regardless of size or duration, all jurisdictions in which the Firm operates or accepts instructions from, and all individuals acting for or on behalf of the Firm, including subcontracted professionals (e.g. notaries, external accountants, licensed lawyers) engaged to deliver part of a client engagement.
2. Legal and Regulatory Framework
This Policy is built on the following legal and regulatory sources and is reviewed whenever these sources are updated:
- Law No. 9917, dated 19.5.2008 “On the Prevention of Money Laundering and Financing of Terrorism,” as amended, and its implementing sub-legal acts (Council of Ministers decisions and GDPML instructions).
- Guidance and reporting obligations issued by the General Directorate for the Prevention of Money Laundering (GDPML — Drejtoria e Pergjithshme e Parandalimit te Pastrimit te Parave), Albania’s Financial Intelligence Unit (FIU).
- Law No. 44/2015 “Code of Administrative Procedures” and relevant company, notarial and licensing legislation to the extent they intersect with client due diligence.
- Financial Action Task Force (FATF) 40 Recommendations and applicable FATF guidance for professional intermediaries (“gatekeepers”).
- Relevant provisions of EU Anti-Money Laundering Directives (as a matter of best practice, given Albania’s EU accession process and the Firm’s international client base).
- Law No. 9887, dated 10.3.2008 “On Protection of Personal Data,” as amended, governing how client identification data collected for AML purposes is processed and retained.
This section reflects the framework in force as of the effective date above. Albanian AML legislation and GDPML instructions are amended periodically; the Compliance Officer is responsible for confirming the current legal text before this Policy is relied upon, and qualified Albanian legal counsel should be consulted on any point of statutory interpretation.
3. Definitions
3.1 Money Laundering (ML)
The process of disguising the illicit origin of proceeds of crime so that they appear to come from a legitimate source, typically involving placement, layering and integration stages.
3.2 Terrorist Financing (TF)
The provision or collection of funds, by any means, with the intention or knowledge that they will be used to carry out terrorist acts, or by a terrorist organization or individual terrorist, regardless of whether the funds derive from legitimate or illegitimate sources.
3.3 Beneficial Owner
The natural person(s) who ultimately own or control a client, or on whose behalf a transaction or activity is being conducted, including persons who exercise ultimate effective control over a legal person or arrangement, typically evidenced through direct or indirect ownership of 25% or more of shares/voting rights, or control through other means.
3.4 Politically Exposed Person (PEP)
A natural person who is or has been entrusted with a prominent public function (domestically or abroad), together with their immediate family members and known close associates, as defined under Albanian AML legislation.
3.5 Customer Due Diligence (CDD) / Know Your Client (KYC)
The process of identifying a client and, where applicable, its beneficial owners, verifying that identity using reliable and independent documents or data, and understanding the purpose and intended nature of the business relationship.
3.6 Suspicious Transaction Report (STR)
A report submitted to the GDPML where the Firm knows, suspects or has reasonable grounds to suspect that funds or a transaction are connected to money laundering, terrorist financing or proceeds of crime.
4. Risk-Based Approach
The Firm applies a risk-based approach (RBA) to AML/CTF compliance, allocating a proportionate level of due diligence, monitoring and resourcing to the ML/TF risk actually presented by each client, product, delivery channel and jurisdiction, rather than applying a uniform standard to every engagement.
4.1 Risk factors assessed
- Client risk: legal form, ownership and control structure, source of wealth and source of funds, nature of business activity, whether the client or a beneficial owner is a PEP, and whether the client is represented by an intermediary.
- Geographic risk: jurisdictions connected to the client, its beneficial owners or the transaction, with particular attention to jurisdictions subject to FATF statements, EU/UN sanctions or identified as having strategic AML/CTF deficiencies.
- Product and service risk: services with inherently higher exposure, such as company formation involving nominee arrangements, real estate transactions, and services involving the handling or coordination of client funds.
- Delivery-channel risk: non-face-to-face onboarding, use of powers of attorney, and remote engagements are assessed for additional verification needs.
4.2 Risk classification and response
Each client relationship is classified as standard, low or high risk following an initial risk assessment performed before the business relationship is established, and reassessed on an ongoing basis and whenever a material change in the client’s circumstances is identified.
- Standard risk: standard CDD as described in Section 5 applies.
- Low risk: simplified due diligence (SDD) may be applied only where permitted under Albanian AML law and where no indicators of higher risk are present.
- High risk: enhanced due diligence (EDD) under Section 5.3 is mandatory, together with senior management approval before the relationship is established or continued, and more frequent ongoing monitoring.
5. Customer Due Diligence (CDD)
5.1 When CDD is performed
- Before establishing a new business relationship or providing any regulated service.
- Before carrying out an occasional transaction above the threshold set by Albanian AML legislation.
- Whenever there is a suspicion of money laundering or terrorist financing, regardless of any exemption or threshold.
- Whenever there are doubts about the veracity or adequacy of previously obtained client identification data.
5.2 Standard due diligence measures
- Identifying the client and verifying identity using an official identity document, corporate registry extract or equivalent reliable, independent source.
- Identifying the beneficial owner(s) and taking reasonable measures to verify their identity, including understanding the ownership and control structure of corporate and other legal entity clients.
- Obtaining information on the purpose and intended nature of the business relationship.
- Screening the client and beneficial owners against applicable sanctions lists and PEP databases before onboarding.
- Conducting ongoing monitoring of the business relationship, including scrutiny of transactions to ensure they are consistent with the Firm’s knowledge of the client, its business and risk profile.
5.3 Enhanced Due Diligence (EDD)
EDD is applied to all higher-risk relationships identified under Section 4.2, including PEPs and their family members/close associates, clients or transactions connected to higher-risk jurisdictions, complex or unusually large transactions with no apparent economic or lawful purpose, and any relationship involving unclear or unnecessarily complex ownership structures. EDD measures include:
- Obtaining senior management approval before establishing or continuing the relationship.
- Establishing the source of wealth and source of funds using documentary evidence where possible.
- Conducting more frequent and more intensive ongoing monitoring of the relationship.
- Obtaining additional independent verification of identity and corporate documents (e.g. notarized or apostilled copies, independent registry searches).
5.4 Reliance on third parties and outsourcing
Where the Firm relies on a third party (such as a bank, licensed notary or another regulated professional) to perform elements of CDD, the Firm remains ultimately responsible for compliance with this Policy and will obtain written confirmation that the third party applies equivalent AML/CTF standards and will make underlying documentation available on request.
5.5 Inability to complete CDD
If the Firm cannot complete the required CDD measures, it will not establish the business relationship, will not carry out the transaction, and will consider whether the circumstances require a suspicious transaction report to the GDPML, in accordance with Section 8.
6. Politically Exposed Persons (PEPs)
The Firm screens all clients and beneficial owners against PEP status at onboarding and periodically thereafter. Where a client or beneficial owner is identified as a PEP, a family member of a PEP, or a known close associate of a PEP, EDD under Section 5.3 applies automatically and the relationship requires senior management sign-off before it may proceed, together with an annual re-approval for as long as the relationship continues.
7. Sanctions and Restrictive Measures
Before onboarding and on an ongoing basis, the Firm screens clients, beneficial owners, and (where relevant) counterparties against applicable United Nations, European Union, Albanian and other relevant sanctions and restrictive-measures lists. The Firm will not establish or continue a business relationship, and will not process a transaction, where doing so would breach applicable sanctions, and will report any sanctions-list match in accordance with the escalation procedure in Section 8.
8. Ongoing Monitoring and Reporting of Suspicious Activity
8.1 Ongoing monitoring
Client relationships and transactions are monitored on an ongoing, risk-based basis to identify activity that is inconsistent with the client’s stated business, risk profile or the information previously obtained, including unusual transaction patterns, unexplained urgency, requests to involve unrelated third parties in payments, or reluctance to provide requested identification or source-of-funds information.
8.2 Internal escalation
Any employee, partner or contractor who knows, suspects, or has reasonable grounds to suspect that a client, transaction or instruction may be connected with money laundering, terrorist financing or the proceeds of crime must report this immediately and internally to the Compliance Officer, using the Firm’s internal escalation form. Employees must not discuss the concern with the client or with colleagues who do not need to know (see Section 11, Tipping-Off).
8.3 External reporting to the GDPML
Where the Compliance Officer determines that the internal report gives rise to knowledge or suspicion of money laundering or terrorist financing, the Firm will file a Suspicious Transaction Report (STR) with the General Directorate for the Prevention of Money Laundering (GDPML) without delay, in the form and manner prescribed by Albanian AML legislation, and will cooperate fully with any subsequent GDPML request for information.
8.4 No liability for good-faith reporting
Reports made in good faith under this Policy do not constitute a breach of any contractual, professional or other duty of confidentiality owed to the client, and Albanian AML legislation provides protection to persons who report in good faith.
9. Record-Keeping
The Firm retains the following records for a minimum of five (5) years from the end of the business relationship or the date of an occasional transaction, or for such longer period as may be required by Albanian AML legislation, court order or GDPML instruction:
- Copies or references of the identification and verification documents obtained for clients and beneficial owners.
- Account files, business correspondence and the results of any analysis undertaken in connection with the business relationship (e.g. risk assessments, source-of-funds analysis).
- Records of transactions sufficient to permit reconstruction of individual transactions.
- Internal escalation reports and any STRs filed, together with supporting analysis.
All AML-related records are stored securely, with access restricted to authorized personnel, and are processed in accordance with the Firm’s Data Protection / GDPR Policy and Albanian data protection legislation.
10. Roles and Responsibilities
10.1 Compliance Officer / AML Responsible Person
The Firm designates a Compliance Officer responsible for the day-to-day operation of this Policy, including approving high-risk and PEP relationships, receiving and assessing internal escalations, filing STRs with the GDPML, maintaining AML records, organizing training, and reporting to senior management on the effectiveness of AML/CTF controls at least annually.
10.2 Senior management
Senior management is responsible for approving this Policy, ensuring adequate resources are allocated to AML/CTF compliance, approving high-risk relationships escalated by the Compliance Officer, and ensuring the Firm’s risk assessment and controls remain proportionate to its client base and service offering.
10.3 All personnel
Every employee, partner and contractor is responsible for completing assigned AML/CTF training, applying this Policy to their day-to-day work, and escalating any concern promptly and honestly, regardless of client relationship or commercial pressure.
11. Confidentiality and Prohibition on Tipping-Off
Employees, partners and contractors must not disclose to a client, or to any third party, that a suspicion has been reported internally or externally, that an STR has been or may be filed, or that an investigation is being or may be undertaken, as doing so may constitute the criminal offence of “tipping-off” under Albanian law. Where a client relationship or transaction must be paused or declined for AML reasons, staff should use pre-approved, neutral wording and refer any client query to the Compliance Officer.
12. Client Acceptance, Refusal and Termination
The Firm reserves the right to decline to establish, or to terminate, a business relationship where required CDD or EDD cannot be completed, where a client or beneficial owner appears on an applicable sanctions list, where the source of funds or wealth cannot be satisfactorily established for a higher-risk relationship, or where continuing the relationship would expose the Firm to an unacceptable ML/TF/regulatory risk. Decisions to decline or terminate a relationship on AML grounds are documented and approved by the Compliance Officer.
13. Training and Awareness
All employees, partners and relevant contractors receive AML/CTF induction training before taking on client-facing responsibilities, and refresher training at least annually, covering this Policy, applicable legislation, red flags relevant to the Firm’s services (company formation, legal, accounting, real estate and recruitment), and the internal escalation procedure. Training completion is recorded and monitored by the Compliance Officer.
14. Internal Controls, Testing and Independent Review
The Compliance Officer conducts periodic sample testing of client files for CDD/EDD completeness, and the Firm arranges an independent review of this Policy and its implementation at least every two years, or sooner if triggered by a material regulatory change, a significant incident, or GDPML guidance, with findings reported to senior management and remediation actions tracked to completion.
15. Policy Review and Governance
This Policy is reviewed and, where necessary, updated at least annually by the Compliance Officer and approved by senior management, and additionally whenever there is a material change in Albanian AML/CTF legislation, GDPML guidance, the Firm’s service offering, or its client risk profile. The version history, effective date and next scheduled review date are recorded on the cover page of this document.
16. Contact
Questions about this Policy, or reports relating to a specific client matter, should be directed to the Compliance Officer at compliance@albania-for-business.com. This Policy is published for transparency at albania-for-business.com and forms part of the Firm’s wider compliance framework, alongside its Data Protection (GDPR) Policy, Client Engagement Terms and Conflicts of Interest Policy.
This document is a policy template prepared for Albania For Business Sh.p.k. and reflects a general, good-practice AML/CTF framework aligned with Albanian law and FATF standards as understood at the time of drafting. It is not a substitute for advice from qualified Albanian legal counsel and should be reviewed, adapted and formally adopted by the Firm’s management before publication, with all statutory references verified against the current text of Albanian law.
