AML Compliance Ireland: 7 Actions for Designated Persons in 2026

AML Compliance in Ireland: A Seven-Step Action Plan for Designated Persons

Ireland’s first National AML/CFT/CPF Strategy confirms that the State is moving towards more coordinated, intelligence led and evidence based supervision of financial crime controls. For designated persons, the central question is practical: what should we do now?

The Strategy does not make every planned reform immediately binding. Existing obligations under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, however, continue to apply. The publication gives organisations an opportunity to test whether their current framework is capable of meeting both existing duties and emerging supervisory expectations.

 

Who is a designated person in Ireland?

Section 25 of the 2010 Act identifies the persons and businesses subject to the relevant AML duties when carrying out specified activities. The category includes credit and financial institutions and a wide range of designated non-financial businesses and professions, including certain solicitors, accountants, auditors, tax advisers, trust or company service providers, estate agents, gambling service providers and high-value goods dealers.

The precise application of the legislation depends on the person, the service and the activity being conducted. A professional practice should therefore map which of its services fall within scope rather than assume that every instruction or no instruction is automatically covered.

 

Step 1: Refresh the business-wide risk assessment

The business-wide risk assessment should be a working analysis of the organisation’s actual exposure. It should consider customers, countries and geographic areas, products and services, transactions, delivery channels and other relevant risk factors.

The 2026 National Risk Assessment identifies fraud and drug offending among the leading money-laundering threats and highlights the use of crypto-assets, money-mule networks, complex layering, digital platforms and cross-border structures. Firms should determine which of those risks are genuinely relevant to their work and document the conclusion.

 

Step 2: Map the beneficial owner – and resolve inconsistencies

A company search is evidence, but it is not always the complete beneficial ownership analysis. Layered companies, nominee arrangements, trusts, partnerships, voting rights, contractual control and informal influence may all require further enquiry.

The file should show the ownership and control chain, the reliable sources used to verify it and how inconsistencies were addressed. Where the customer cannot provide a coherent explanation, the issue should be escalated rather than normalised by repetition.

 

Step 3: Distinguish source of funds from source of wealth

Source of funds asks where the money for the particular transaction came from. Source of wealth considers how the customer accumulated their overall wealth. They are related but different enquiries.

The level of evidence should reflect risk. In a higher-risk matter, an uncorroborated statement that funds are ‘savings’, ‘sale proceeds’ or ‘family money’ may not be sufficient. The organisation should establish what documents are normally required, when further corroboration is necessary and who can approve an exception.

 

Step 4: Strengthen sanctions and proliferation-financing controls

The Strategy gives proliferation financing a more visible place in Ireland’s framework. Relevant warning signs can include indirect exposure to sanctioned jurisdictions, opaque intermediaries, unusual trade routes, dual-use goods, complex payment chains and transactions lacking a credible commercial purpose.

Screening software is only one control. Firms should define what is screened, when rescreening occurs, how close or partial matches are resolved and how ownership and control are assessed where sanctions apply to entities connected with listed persons.

 

Step 5: Review crypto and technology related risk

The presence of crypto assets does not automatically make a customer or transaction suspicious. It may, however, change the evidence required. Relevant considerations can include the route by which assets were acquired, the platforms and wallets used, conversion into fiat currency, transaction history, mixing or privacy-enhancing tools and links to higher-risk jurisdictions. Policies should also address the risks created by artificial intelligence, digital impersonation and fabricated documents. Verification processes designed for paper documentation may not adequately identify modern fraud.

 

Step 6: Test escalation and suspicious transaction reporting

Staff should know how to raise an internal suspicion promptly and without tipping off the customer. The MLRO or nominated person should receive enough information to make an informed decision and should record the reasons for reporting or not reporting.

The Strategy’s focus on improved STR data and analysis is a reminder that reports should be timely, accurate and useful. Organisations should test whether reporting lines work during holidays, absences and urgent transactions and whether supporting records can be retrieved quickly.

 

Step 7: Build an inspection ready evidence file

A policy is important, but a supervisor will also look for evidence that the policy works. A central AML governance file should normally contain:

· the current and previous business wide risk assessments;

· approved AML policies, procedures and version history;

· records of governance review and senior-management decisions;

· training materials, attendance and effectiveness testing;

· file-review and monitoring results;

· breaches, incidents, remediation and closure evidence;

· relevant regulatory correspondence and change logs; and

· records showing how sectoral feedback and new risks were incorporated into controls.

 

Common weaknesses to avoid

· A generic risk assessment that could belong to any organisation.

· CDD completed once at onboarding with no trigger-based or ongoing review.

· Beneficial ownership accepted without resolving conflicting information.

· Source of funds evidence collected but not evaluated.

· Training delivered but understanding never tested.

· Internal suspicions discussed informally without an auditable record.

· Remediation actions repeatedly carried forward without ownership or deadlines.

 

The outcome: defensible and effective compliance

Good AML compliance is not measured by the volume of documents collected. It is measured by whether the organisation identifies relevant risk, applies proportionate controls, makes reasoned decisions and creates a reliable record of what it did and why.

Sherwin O’Riordan assists Irish designated persons with AML risk assessments, policies, governance, file audits, training, inspection readiness and remediation.

For advice on reviewing your AML framework, contact us today

Speak with a Solicitor Today – Call 01 663 2000

Contact us today through our online contact form.

For a free initial conversation call