Anti-Money Laundering & Counter-Terrorist Financing Policy
Anti-Money Laundering & Counter-Terrorist Financing Policy
AML/CFT Policy — Internal Compliance Document
Document AML/CFT Policy
Version / Date Version 1.0 — January 2025
Approved by Senior Management — Bulgaria For Business
Review frequency Annual — or on legislative change
CONFIDENTIAL — INTERNAL DOCUMENT: This Anti-Money Laundering and Counter-Terrorist Financing Policy is a confidential internal compliance document of Bulgaria For Business. It is intended for use by authorised staff and management, and for disclosure to regulatory authorities where lawfully required. It must not be disclosed to clients or third parties without the written authorisation of senior management.
1. Purpose and scope
This Anti-Money Laundering and Counter-Terrorist Financing Policy (“AML/CFT Policy” or “Policy”) establishes the framework within which Bulgaria For Business identifies, assesses, and manages the risks of money laundering and terrorist financing arising from its professional services activities.
1.1 Purpose
The purpose of this Policy is to:
- set out the legal obligations of Bulgaria For Business under Bulgarian and EU anti-money laundering law;
- define the procedures for customer due diligence, beneficial ownership verification, PEP and sanctions screening, and ongoing monitoring;
- establish the internal escalation and reporting procedures for suspicious transactions;
- define the responsibilities of all staff in relation to AML/CFT compliance;
- ensure that Bulgaria For Business is not used — knowingly or unknowingly — to facilitate money laundering, terrorist financing, or related predicate offences.
1.2 Scope
This Policy applies to all activities of Bulgaria For Business, including:
- company formation and company administration services;
- legal advice in connection with property transactions, business acquisitions, and corporate transactions;
- accounting and financial services;
- trust and company services;
- real estate advisory and transaction support;
- regulatory licensing advisory;
- business acquisition and investment advisory.
This Policy applies to all directors, managers, employees, and contractors of Bulgaria For Business who are involved in the provision of the above services. Compliance is mandatory and non-compliance may result in disciplinary action, regulatory sanction, or criminal liability.
2. Legal and regulatory framework
2.1 Primary Bulgarian legislation
The primary Bulgarian legislation governing AML/CFT compliance for professional services firms is:
- Закон за мерките срещу изпирането на пари (ЗМИП) — the Measures Against Money Laundering Act (MAMLA) — which implements EU AML Directives into Bulgarian law and establishes the obligations for “obliged entities”, including professional services firms.
- Закон за мерките срещу финансирането на тероризма (ЗМФТ) — the Measures Against Financing of Terrorism Act — which establishes the counter-terrorist financing framework.
- Наредба № 1 от 8 октомври 2018 г. — the National Risk Assessment Regulations.
2.2 EU legislative framework
Bulgaria, as an EU member state, is subject to the EU anti-money laundering legislative framework, including:
- EU AML Directives — the Fourth (AMLD4, Directive 2015/849), Fifth (AMLD5, Directive 2018/843), and Sixth (AMLD6, Directive 2018/1673) EU Anti-Money Laundering Directives — all transposed into Bulgarian law.
- EU Sanctions Regulations — directly applicable EU regulations imposing asset freezes and prohibitions related to specific persons, entities, and jurisdictions.
- FATF Recommendations — the 40 Recommendations of the Financial Action Task Force, which set the international standard for AML/CFT compliance and inform Bulgarian and EU law.
2.3 Bulgaria For Business as an obliged entity
Bulgaria For Business qualifies as an “obliged entity” under the ЗМИП in its capacity as a provider of: company formation services; legal services relating to real estate transactions, corporate transactions, and business acquisitions; accounting and financial services; and trust and company services. As an obliged entity, Bulgaria For Business is subject to the full range of AML obligations set out in this Policy.
3. Governance and responsibility
3.1 Senior management responsibility
Senior management of Bulgaria For Business bear ultimate responsibility for the effectiveness of the firm’s AML/CFT compliance framework. Senior management responsibilities include:
- approving this Policy and any material amendments;
- ensuring adequate resources — including staff, training, and systems — are dedicated to AML/CFT compliance;
- approving high-risk client relationships before they are established or continued;
- receiving and considering the annual AML/CFT compliance review prepared by the MLRO;
- setting and maintaining a culture of AML/CFT compliance throughout the firm.
3.2 Money Laundering Reporting Officer (MLRO)
Bulgaria For Business designates a Money Laundering Reporting Officer (MLRO) who is responsible for:
- receiving internal suspicious activity reports from staff;
- assessing whether an internal report constitutes grounds for an external suspicious activity report (SAR) to the Bulgarian Financial Intelligence Directorate (Дирекция “Финансово разузнаване” — ДФР);
- submitting SARs to the ДФР where required;
- maintaining SAR records in accordance with legal requirements;
- liaising with the ДФР and other regulatory authorities on AML matters;
- overseeing the implementation of this Policy and AML/CFT procedures;
- delivering AML/CFT training to all relevant staff;
- preparing an annual AML/CFT compliance review for senior management.
All staff must report suspicions of money laundering or terrorist financing to the MLRO — not directly to any external authority (except in circumstances where the MLRO is themselves suspected of involvement). The MLRO’s contact details are communicated to all staff internally.
3.3 Staff responsibilities
All staff involved in client-facing activities or service delivery are responsible for:
- understanding and applying this Policy in their day-to-day work;
- completing AML/CFT training as provided by the MLRO;
- identifying and reporting to the MLRO any suspicious activity or transactions;
- not tipping off clients or third parties that a suspicious activity report has been made or is being considered;
- maintaining confidentiality of all AML-related information;
- completing CDD procedures before establishing or continuing a client relationship.
4. Business-wide and client risk assessment
4.1 Business-wide risk assessment
Bulgaria For Business maintains a documented business-wide risk assessment of the money laundering and terrorist financing risks it faces in the course of its professional activities. This assessment considers:
- the nature and complexity of the services provided;
- the geographic footprint of the client base — including the proportion of clients from higher-risk jurisdictions;
- the sectors in which clients operate;
- the volume and value of transactions conducted;
- delivery channels and the extent of face-to-face vs. remote client relationships;
- internal vulnerabilities — including staff turnover, supervision quality, and system capabilities.
The business-wide risk assessment is reviewed and updated at least annually, or following significant changes to the business or regulatory environment. It informs the calibration of all CDD procedures and monitoring activity.
4.2 Client risk assessment
Every client relationship is assigned a risk rating — Low, Medium, or High — based on the client-specific risk factors identified during onboarding and updated during ongoing monitoring. The risk rating determines the level of customer due diligence applied and the frequency of periodic review.
| Risk factor / scenario | Risk level | Required action |
|---|---|---|
| Client nationality / residence in a high-risk jurisdiction (FATF blacklist / greylist country) | HIGH | Enhanced due diligence mandatory. Senior approval required. Transaction monitoring heightened. |
| Politically Exposed Person (PEP) or close associate / family member | HIGH | Enhanced due diligence mandatory. Senior management sign-off required. Ongoing monitoring at enhanced frequency. |
| Complex or unusual corporate structure (multiple layers, nominee directors, bearer shares) | HIGH / MEDIUM | Establish rationale for structure. Verify all beneficial owners ≥25% stake. Enhanced scrutiny of source of funds. |
| Cash-intensive business or significant cash transaction elements | HIGH / MEDIUM | Source of funds verification required. Transaction monitoring. Consider whether business relationship is appropriate. |
| Business in a high-risk sector (gambling, cryptocurrency, arms, luxury goods, real estate) | MEDIUM / HIGH | Enhanced due diligence. Specific sector risk factors assessed. Source of wealth documentation. |
| Company incorporation or trust / company services | MEDIUM | Standard CDD plus verification of all beneficial owners and purpose of the structure. |
| Established domestic client with transparent corporate structure | LOW | Standard CDD. Periodic review at reasonable intervals. |
| Instructions inconsistent with stated business purpose | HIGH | Suspend transaction pending clarification. Escalate to MLRO. Consider SAR filing. |
5. Customer due diligence (CDD)
Customer due diligence (CDD) — also known as Know Your Customer (KYC) — is the process by which we verify the identity of clients and beneficial owners, understand the nature of the business relationship, and assess the associated money laundering and terrorist financing risks. CDD must be completed before a business relationship is established or, in exceptional circumstances, immediately after.
| CDD measure | Description and application |
|---|---|
| Standard CDD (all clients) | Verification of client identity (individual: passport or national ID + selfie or certified copy; corporate: Commercial Register extract + Articles of Association). Verification of beneficial owner(s) with 25%+ ownership or effective control. Confirmation of purpose and nature of business relationship. Ongoing monitoring proportionate to risk. |
| Simplified CDD (low-risk clients) | Applied where a client is assessed as low risk and the circumstances justify simplified measures — e.g. listed companies, public authorities, or clients whose identity has already been verified through a reliable third party. Simplified CDD must still confirm identity; it reduces the depth of additional verification required. Cannot be applied where any high-risk factor is present. |
| Enhanced CDD (high-risk clients) | Mandatory for: PEPs, clients in or from high-risk jurisdictions, complex/unusual corporate structures, and any relationship where higher risk has been identified. Measures include: verification of source of funds and source of wealth; senior management approval before establishing or continuing the relationship; enhanced ongoing monitoring; more frequent periodic reviews. |
| Beneficial owner verification | We are required to identify and verify all individuals who own or control 25% or more of a corporate client, or who otherwise exercise effective control. If no individual holds 25%+, the senior managing official(s) are treated as beneficial owners. We use the Bulgarian Commercial Register as a primary source and cross-check against other sources where needed. |
| PEP screening | All clients are screened at onboarding against PEP databases to identify politically exposed persons — foreign or domestic government officials, senior public officials, and their close associates and family members. PEPs are automatically classified as high risk and subject to enhanced CDD. Screening is repeated periodically and on risk triggers. |
| Sanctions screening | All clients are screened against EU sanctions lists, UN sanctions lists, OFAC (US), HMT (UK), and other applicable sanctions databases at onboarding and on an ongoing basis. Any match triggers an immediate freeze of the relationship and reporting to the competent authority as required. |
6. CDD documentation requirements
6.1 Individual clients
For individual clients, the following documentation is required as a minimum:
- Government-issued photo identification — passport, national identity card (for EU/EEA nationals), or equivalent. The document must be current (not expired).
- Proof of residential address — utility bill, bank statement, or official government correspondence dated within the last 3 months.
- Confirmation of source of funds for transactions above applicable thresholds or where heightened risk is identified.
- For enhanced CDD — source of wealth documentation (e.g. evidence of business ownership, inheritance, employment history) in addition to source of funds.
6.2 Corporate clients
For corporate clients, the following documentation is required as a minimum:
- Current extract from the relevant commercial or companies register — confirming the company’s name, registration number, registered address, directors, and shareholders.
- Articles of Association or equivalent constitutional document.
- Identification and verification of all beneficial owners holding 25% or more of shares or voting rights, or who otherwise exercise effective control — using the same documentation requirements as for individual clients.
- Where beneficial ownership cannot be determined from public registers — a written statement from a director or authorised officer confirming the beneficial ownership structure.
- For enhanced CDD — additional information about the company’s business activities, source of funds, and corporate structure rationale.
6.3 Document certification
For remote clients (those not verified face-to-face), copies of identity documents must be:
- certified as true copies by a qualified professional (notary, lawyer, accountant, or police officer) in the client’s country of residence; or
- verified through an approved electronic identity verification service; or
- accompanied by a clear, colour selfie photograph of the client holding the identity document.
6.4 Ongoing monitoring and periodic review
CDD is not a one-time exercise. All client relationships are subject to ongoing monitoring — reviewing transactions for consistency with the client’s known profile and risk rating — and periodic review of the CDD documentation. Review frequency:
- Low-risk clients: review at least every 3 years, or on risk trigger.
- Medium-risk clients: review at least every 2 years, or on risk trigger.
- High-risk clients: review at least annually, or on risk trigger.
Risk triggers that require an immediate CDD review include: a change in beneficial ownership; a significant change in the nature or volume of the client’s transactions; a change in the client’s country of residence or operations; receipt of adverse media or law enforcement information; or any other circumstances suggesting the risk rating should be reassessed.
7. Politically Exposed Persons (PEPs)
7.1 Definition
A Politically Exposed Person (PEP) is an individual who is, or has been, entrusted with a prominent public function — domestically or in a foreign country. The ЗМИП definition includes:
- Heads of State, heads of government, ministers, and deputy ministers;
- Members of parliament or similar legislative bodies;
- Members of governing bodies of political parties;
- Members of supreme courts, constitutional courts, or other high-level judicial bodies;
- Members of courts of auditors or boards of central banks;
- Ambassadors, chargés d’affaires, and high-ranking officers in the armed forces;
- Members of administrative, management, or supervisory bodies of state-owned enterprises;
- Directors, deputy directors, and members of boards of directors of international organisations.
Close associates and immediate family members of PEPs (spouses, partners, parents, children, siblings, and their spouses or partners) are subject to the same enhanced due diligence as PEPs themselves.
A person who has ceased to hold a prominent public function must continue to be treated as a PEP for a minimum of 12 months after leaving office — or longer where the risk profile warrants it.
7.2 Enhanced CDD for PEPs
Where a client or beneficial owner is identified as a PEP, the following measures are mandatory:
- Senior management approval — written approval from senior management is required before establishing or continuing a business relationship with a PEP.
- Enhanced CDD — verification of source of wealth (not just source of funds) is required for PEPs. The explanation of how the PEP accumulated their wealth must be plausible given their public role and history.
- Enhanced ongoing monitoring — PEP relationships are subject to increased scrutiny and more frequent review.
- Annual senior management sign-off — for all continuing PEP relationships, senior management must annually confirm that the relationship remains appropriate.
8. Sanctions screening and compliance
8.1 Obligations
Bulgaria For Business is subject to EU, UN, and other applicable sanctions regimes. It is prohibited to provide services to, or engage in transactions involving, any person or entity that is:
- listed on the EU Consolidated Sanctions List;
- listed on the UN Security Council Consolidated List;
- listed on OFAC (US Treasury) SDN List;
- subject to any other applicable sanctions regime where Bulgaria For Business has identified a connection to the relevant jurisdiction.
8.2 Screening procedure
All prospective and existing clients, beneficial owners, and — where applicable — counterparties in transactions are screened against the relevant sanctions lists:
- at initial onboarding;
- at each periodic CDD review;
- immediately upon receiving information of a potential sanctions connection;
- on an ongoing basis through automated screening tools where available.
8.3 Sanctions match procedure
Where a screening match is identified:
- The relevant service or transaction is immediately suspended.
- The MLRO is notified immediately.
- No funds or assets are transferred, and no services are provided, pending assessment.
- Where the match is confirmed, the MLRO reports to the competent Bulgarian authority (the State Agency for National Security — ДАНС or other competent body as applicable) as required by law.
- Under no circumstances is the client informed that a sanctions match has been identified — tipping off is a criminal offence.
9. Suspicious activity reporting (SAR) procedure
9.1 Obligation to report
All staff have a legal obligation under the ЗМИП to report to the MLRO any knowledge or suspicion that a client is engaged in money laundering or terrorist financing, or that a transaction or instruction may be connected to the proceeds of crime or to the financing of terrorism. Suspicion does not require certainty — a reasonable suspicion based on available information is sufficient to trigger the reporting obligation.
9.2 Internal reporting to MLRO
Internal suspicious activity reports must be made to the MLRO:
- promptly — as soon as the suspicion arises, and before any further action is taken on the relevant transaction or instruction;
- in writing — using the internal SAR form or by secure written communication;
- with all relevant supporting information — client details, the nature of the suspicion, the transaction or instruction concerned, and any documents or communications that support the report.
9.3 MLRO assessment and external reporting
On receipt of an internal SAR, the MLRO:
- reviews the report and all supporting information;
- determines whether there are reasonable grounds to suspect money laundering or terrorist financing;
- where grounds exist — files an external Suspicious Activity Report (SAR) with the Bulgarian Financial Intelligence Directorate (Дирекция “Финансово разузнаване” — ДФР) through the prescribed channel without undue delay;
- where grounds do not exist — documents the reasons for not filing and retains the internal report on file;
- maintains a register of all internal SARs received and all external SARs filed.
9.4 Consent requests
Where Bulgaria For Business wishes to proceed with a transaction that has been the subject of a SAR, the MLRO may seek consent from the ДФР before proceeding. Bulgaria For Business must not proceed with the relevant transaction until consent is received, or until the applicable waiting period has elapsed without the ДФР refusing consent.
Staff are protected from civil liability for making a suspicious activity report in good faith, even if the suspicion subsequently proves to be unfounded.
10. Record keeping
Bulgaria For Business maintains comprehensive records of all AML/CFT measures taken in connection with every client relationship. The ЗМИП requires the following records to be retained for 5 years from the end of the business relationship:
- Customer due diligence documentation — copies of all identity documents, beneficial ownership information, source of funds/wealth documentation, and risk assessments.
- Business relationship records — records of the purpose and intended nature of the relationship, transaction history, and correspondence.
- Supporting evidence for CDD decisions — including decisions to apply simplified CDD (with rationale) and decisions to apply enhanced CDD (with rationale and senior management approvals).
- Internal suspicious activity reports — received by the MLRO, together with the MLRO’s decision and supporting reasoning.
- External suspicious activity reports — filed with the ДФР, with confirmation of filing.
- Training records — records of AML/CFT training completed by each member of staff.
Records must be stored securely — with access restricted to the MLRO, senior management, and staff with a legitimate need to access them. Records must be capable of being provided to the competent Bulgarian authorities (ДАНС, ДФР, NRA, regulatory bodies) on request.
11. AML/CFT training
All staff who are involved in providing regulated professional services, or who are involved in client onboarding, transaction processing, or any other activity that may expose them to money laundering or terrorist financing risk, are required to:
- complete initial AML/CFT induction training before engaging in any client-facing activity;
- complete refresher training at least annually;
- receive additional training when significant legislative changes or regulatory guidance require updated understanding;
- familiarise themselves with this Policy and any updates.
Training covers: the nature of money laundering and terrorist financing; the legal obligations of Bulgaria For Business and individual staff; how to identify suspicious activity; the internal reporting procedure; the tipping off prohibition; the consequences of non-compliance.
Training records are maintained by the MLRO and are available for review by regulatory authorities.
12. High-risk jurisdictions
Bulgaria For Business applies enhanced customer due diligence to all clients and transactions connected to jurisdictions identified as high risk for money laundering or terrorist financing. These include:
- Jurisdictions on the FATF list of “High-Risk Jurisdictions Subject to a Call for Action” (the FATF blacklist) — currently including: Iran, North Korea, Myanmar, and other countries as updated by FATF. Business relationships with clients from these jurisdictions require senior management approval and enhanced CDD.
- Jurisdictions on the FATF list of “Jurisdictions Under Increased Monitoring” (the FATF greylist) — currently including countries under enhanced FATF monitoring. Enhanced due diligence is applied, with additional scrutiny of source of funds and the rationale for the Bulgarian connection.
- Jurisdictions identified in the EU’s list of high-risk third countries for AML purposes (Commission Delegated Regulation under AMLD4).
- Any jurisdiction that, in the professional judgement of the MLRO, presents an elevated risk of money laundering based on available intelligence, reputational factors, or the specific circumstances of a transaction.
The MLRO maintains a current list of designated high-risk jurisdictions and reviews it at least quarterly against published FATF and EU updates.
13. Indicators of suspicious activity
The following are examples of indicators that may give rise to a suspicion of money laundering or terrorist financing. This list is not exhaustive. Any indicator, alone or in combination, may justify an internal report to the MLRO.
Client behaviour indicators
- Reluctance to provide identity documentation or information about beneficial ownership without plausible explanation
- Provision of inconsistent information about identity, business activities, or source of funds
- Unusual nervousness, evasiveness, or apparent knowledge of AML procedures that is not consistent with stated background
- Client instructs us to not record certain information or to conduct transactions in an unusual manner
- Client appears to be acting on behalf of an undisclosed third party
Transaction / instruction indicators
- Transactions that appear inconsistent with the client’s known business profile, financial position, or the stated purpose of the relationship
- Instructions to transfer funds to or from an unrelated third party without clear business justification
- Requests to structure transactions in a way that appears designed to avoid reporting thresholds
- Multiple transactions just below reporting thresholds (structuring)
- Transactions involving jurisdictions with no apparent business connection to the client’s declared activities
Corporate structure indicators
- Unnecessarily complex corporate structure that does not appear to have a legitimate commercial purpose
- Presence of bearer shares, nominee directors, or nominee shareholders without clear business rationale
- Beneficial ownership that cannot be verified or that appears deliberately obscured
- Corporate vehicles registered in high-secrecy jurisdictions or jurisdictions with weak AML frameworks
- Frequent changes of directors, beneficial owners, or registered address without explanation
Source of funds / wealth indicators
- Client is unable or unwilling to explain the origin of the funds involved in the transaction
- Source of funds claimed appears inconsistent with the client’s known financial profile or declared income
- Funds originate from an unexpected jurisdiction or from an unrelated third party without clear explanation
- Sudden significant increase in client activity or transaction values inconsistent with declared business
- Cash transactions or requests for cash payments outside normal commercial practice
14. Consequences of non-compliance
Non-compliance with this Policy and with the underlying legal obligations may result in severe consequences for both Bulgaria For Business as a firm and for individual staff members:
14.1 For Bulgaria For Business
- Administrative fines — the Bulgarian Financial Intelligence Directorate and other competent authorities may impose significant administrative fines for AML/CFT non-compliance.
- Prohibition orders — in serious cases, the firm may be prohibited from carrying on certain activities.
- Reputational damage — regulatory findings against a professional services firm are typically published and cause lasting reputational harm.
- Criminal prosecution of the firm — in the most serious cases, the firm itself may face criminal liability.
14.2 For individual staff members
- Disciplinary action — up to and including dismissal.
- Personal criminal liability — individuals who knowingly facilitate money laundering or terrorist financing, or who knowingly fail to report a known offence, may be prosecuted under the Bulgarian Penal Code and the ЗМИП.
- Imprisonment — Bulgarian criminal law provides for custodial sentences for money laundering offences.
- Personal financial penalties — courts may impose personal fines on individuals found guilty of AML/CFT violations.
15. Policy review and approval
This Policy is reviewed at least annually by the MLRO and senior management, and updated when:
- there are material changes to Bulgarian or EU AML/CFT legislation or regulatory guidance;
- FATF or EU risk assessments identify changes to the risk landscape;
- internal experience, regulatory feedback, or audit findings indicate that updates are required;
- there are significant changes to Bulgaria For Business’s business model, client base, or service offering.
All amendments to this Policy require senior management approval. Material amendments are communicated to all relevant staff. Training is updated as necessary to reflect Policy changes.
| Policy version | 1.0 |
| Effective date | January 2025 |
| Next scheduled review | January 2026 |
| MLRO | Designated — contact details held internally |
| Approved by | Senior Management — Bulgaria For Business |
CONFIDENTIAL — INTERNAL DOCUMENT: This Anti-Money Laundering and Counter-Terrorist Financing Policy is a confidential internal compliance document. It is not to be disclosed to clients, third parties, or any external party except where required by law or compelled by a competent regulatory authority. Unauthorised disclosure may constitute a tipping-off offence under the ЗМИП.
This Policy is issued under the authority of senior management of Bulgaria For Business and is binding on all directors, managers, employees, and contractors. Questions regarding this Policy or its application should be directed to the MLRO.
