Demivolt logo

Start With Risk Assessment: Fix AML Policy Weaknesses in Lithuania

Published 3 September 2026

AML policy for Lithuanian businesses: start with a risk assessment, document UBOs, automate sanctions screening, and name an owner.

Start With Risk Assessment: Fix AML Policy Weaknesses in Lithuania

An effective AML policy must implement a documented, risk-based customer due diligence program, active sanctions screening, clear suspicious transaction reporting procedures, and disciplined recordkeeping. The first action is not writing a policy document. It’s completing a company-level AML risk assessment and naming an accountable owner for the program before a single client is onboarded.


TL;DR:

  • A comprehensive AML program starts with a detailed company-level risk assessment and clear ownership, not just drafting policy documents.
  • Businesses must continuously verify client identities, beneficial owners, and transaction purposes, even when onboarding remotely using qualified electronic signatures.
  • Automated screening against EU, UN, and national sanctions lists must be ongoing, with documented decision-making for any matches or alerts.
  • Strong governance requires regular transaction monitoring, clear escalation procedures, and staff training, focusing on actual operational enforcement.
  • Fixing gaps in UBO documentation, recurring sanctions checks, and documented risk scoring significantly reduces AML enforcement risks.

Table of Contents

AML Politika Verslui: Who Must Comply and Under What Law

Most business owners assume anti-money laundering rules apply only to banks. That assumption gets companies fined. Lithuania’s national framework, the Law on the Prevention of Money Laundering and Terrorist Financing (PPTFPĮ), extends obligations to a wide range of non-financial businesses, and it operates alongside EU directives and European Banking Authority guidelines that set the baseline for supervisory expectations across the bloc.

An “obligated entity” under this framework includes far more than payment institutions. Real estate agents, accountants, tax advisors, and company formation or administration service providers all carry notification and training duties toward tax authorities and other supervisory bodies.

Recent amendments tied to EU Regulation (EU) 2024/1620 have reshaped identity verification rules, expanding where simplified due diligence applies. Watch for:

  • Updated thresholds for when enhanced due diligence becomes mandatory
  • Changes to beneficial ownership registration timelines
  • New guidance on cross-border payment service providers operating under passporting rights

Building a Risk-Based Approach to AML Compliance

The EBA’s risk-based model rests on four factors: your customers, the geographies you touch, the products or services you offer, and the delivery channels you use to reach clients. A business selling digital services to walk-in local customers carries a different risk profile than one processing cross-border payments for clients in high-risk jurisdictions.

Running an actual risk assessment doesn’t require a consultant on retainer. Follow this sequence:

  1. List every customer segment, product line, and geography your business touches.
  2. Score each combination for money laundering and terrorist financing exposure, using low, medium, and high tiers.
  3. Set your risk tolerance and decide which tiers trigger simplified versus enhanced checks.
  4. Document the reasoning behind each score. Undocumented judgment calls are the most common enforcement finding.
  5. Review the assessment at least annually, or immediately after a material business change.

Simplified CDD is acceptable only for genuinely low-risk cases, per EBA guidelines. Enhanced due diligence becomes mandatory the moment a customer touches a sanctioned jurisdiction, operates through complex ownership layers, or shows behavior inconsistent with their stated business purpose.

Pro Tip: Build your risk matrix in a shared spreadsheet before you buy any compliance software. You’ll understand your actual exposure far better than any vendor’s default template will show you, and you’ll ask sharper questions when you do shop for tools.

Customer Due Diligence and Identity Verification Requirements

CDD isn’t a one-time form. It’s an ongoing obligation to know exactly who you’re doing business with and why. At minimum, every obligated business must collect and verify:

  • Full legal identity of the customer, including government-issued ID for individuals
  • Ultimate beneficial ownership (UBO), tracing ownership through any corporate layers to the natural person
  • The stated business purpose and expected nature of the relationship
  • Corroborating documentation, such as incorporation certificates and proof of address

Remote onboarding is legally sound in Lithuania. Under PPTFPĮ, a client’s identity can be established without physical presence when the process uses a qualified electronic signature meeting eIDAS requirements. That single mechanism is what makes fully digital onboarding legally defensible rather than a compliance shortcut. For a full document breakdown, see this KYC document checklist for companies.

Retention matters as much as collection. Store verification records securely, keep them accessible for audit, and retain them for the period your national law requires, even after the relationship ends.

Screening for International Sanctions Before You Onboard

Sanctions screening isn’t optional, and it isn’t a one-time check at signup. Businesses need to screen against EU consolidated sanctions lists, UN Security Council designations, and national watchlists, ideally through automated tools that re-screen your existing client base as lists update, not just new applicants.

Consolidated guidance from the AML Center and FNTT on sanctions implementation walks through common evasion schemes businesses should watch for:

  • Layered ownership structures designed to obscure a sanctioned individual’s control
  • Use of intermediaries or shell entities in jurisdictions adjacent to sanctioned territory
  • Sudden changes in transaction patterns after a sanctions list update
  • Requests to route payments through third-party accounts with no clear business rationale

When a screening hit occurs, escalate it immediately to your compliance owner rather than letting front-line staff decide. Document the decision to permit, block, or report the relationship, including the specific data points that drove the call. Sanctions-evasion tactics evolve constantly, which is why automated screening paired with human review catches what a list match alone misses.

Pro Tip: Treat every sanctions decision like it will be audited in twelve months, because it might be. A one-line note (“cleared, no match”) is not documentation. Write down what you checked and why the outcome was safe.

Turning Policy Into Practice: Monitoring, Reporting, and Governance

A written AML policy that never touches daily operations is worthless in an audit. Operationalizing it requires:

  1. Transaction monitoring rules with thresholds calibrated to your actual customer risk tiers, reviewed at least twice a year as behavior patterns shift.
  2. A clear internal escalation path so any employee who spots suspicious activity knows exactly who to notify and how fast.
  3. Suspicious transaction report (STR) filing procedures that meet your national deadlines, with an audit trail showing what was reviewed and when.
  4. A staff training cadence, at minimum annual, covering red flags relevant to your specific industry.
  5. A policy review schedule tied to regulatory changes, not just a fixed calendar date.

Weak governance here is exactly where enforcement actions concentrate.

What Enforcement Data Reveals About Common AML Failures

Lithuanian companies filed more than 98,500 suspicious transaction reports in 2023, and total fines for AML and terrorist financing violations that year were substantial. The volume shows the reporting system is active. The fines show many businesses still get the fundamentals wrong.

The recurring failures aren’t exotic. They’re weak UBO documentation, sanctions checks run once at onboarding and never again, and risk assessments that exist in name only, with no evidence anyone actually scored anything. Fix those three gaps first: document every UBO chain to the natural person, automate recurring sanctions re-screening, and write down the reasoning behind every risk score you assign.

Three AML failures and corresponding fixes

How Regulated Banking Infrastructure Supports Your AML Program

A policy document is only as strong as the systems enforcing it. This is where regulated banking infrastructure earns its place in your compliance stack rather than sitting beside it.

Demivolt operates as a regulated European fintech platform, which means client funds sit in segregated accounts and onboarding follows EU compliance standards by default. In practice, that translates to:

  • Dedicated IBAN accounts with built-in payment screening at the banking layer, reducing manual sanctions checks
  • Multi-account structures that segregate client funds and transactions, simplifying audit trails during a review
  • Role-based user management, so only accountable staff can approve or release payments above set thresholds
  • Secure, centralized recordkeeping that supports the documentation your risk assessments and STR files require

Compliance teams building or refining onboarding workflows can review this compliance-first guide to digital banking onboarding and the B2B banking checklist for cross-border compliance for practical implementation steps.

Regulator Guidance Worth Bookmarking

Primary sources beat secondary summaries every time a rule changes. Keep these on hand:

For businesses layering AI-driven monitoring into their compliance stack, this analysis of what the EU AI Act requires from financial institutions is worth reading before you automate screening decisions.

Why Most AML Policies Fail Before They’re Tested

The conventional advice on AML compliance treats it as a documentation exercise: write the policy, file it, move on. That’s backwards. The AML Center’s own position is that a check-the-box mentality is the failure mode itself, not a shortcut around it. Every enforcement pattern in Lithuania’s 2023 fine data traces back to policies that existed on paper but never touched actual operations.

Why Most AML Policies Fail Before They're Tested — overview diagram

What gets underestimated is how much of this comes down to ownership, not paperwork. A risk assessment nobody is accountable for updating decays within a year. A sanctions list nobody re-screens against becomes stale the week a new designation drops. The businesses that avoid fines aren’t the ones with the longest policy documents. They’re the ones where one named person answers for the program and where the banking infrastructure underneath does some of the verification work automatically, rather than leaving every check to a spreadsheet and good intentions.

Start with the risk assessment, not the policy template. Everything else follows from an honest answer to “where is our actual exposure?”

— dd

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Sources