+38-095-241-7575 Order a consultation

Financial Monitoring System: Why «Rules in a Drawer» Are No Longer Enough

26.09.2026

From Formal Compliance to Infrastructure

Only a few years ago the financial monitoring system of a non-bank financial institution often amounted to a set of internal documents, an order appointing a responsible officer and an Excel spreadsheet for threshold transactions. The regulator checked that the documents existed, the institution received a written warning or a moderate fine, and the matter was considered closed. The practice of 2026 shows that this model has run its course.

In May 2026 the National Bank of Ukraine applied enforcement measures to one bank and nine non-bank financial institutions, with total fines exceeding UAH 320 million. Two non-bank financial institutions - operators of payment terminal networks - received UAH 135.15 million each, that is, a fine in the maximum amount that the Law of Ukraine «On Prevention and Counteraction to Legalisation (Laundering) of Proceeds of Crime, Terrorist Financing and Financing of Proliferation of Weapons of Mass Destruction» of 06.12.2019 No. 361-IX (hereinafter - «Law No. 361-IX») permits for financial institutions at all. An insurance company received UAH 40.7 million in the same package of decisions. The regulator’s claims were formulated identically: improper customer due diligence, in particular with regard to politically exposed persons, and incorrect risk assessment. In June 2026 one of the largest pawnshop chains received a fine of more than UAH 4 million for deficiencies in primary financial monitoring.

The common denominator of these decisions is that none of the institutions breached the requirements for lack of rules. The breaches arose where the rules had not been turned into a process performed every day and without exception on every customer and every transaction. This is precisely where the demand the market already feels comes from: not for yet another version of the AML rules, but for a system in which regulatory documents, organisational structure and software work as a single mechanism.

Who Is Obliged to Build the System

The range of primary financial monitoring entities (reporting entities) is defined by Article 6 of Law No. 361-IX, while state regulation and supervision over them is divided among several regulators. For the financial services market the key one is the National Bank of Ukraine, which supervises finance companies, pawnshops, insurers, credit unions, payment institutions and other non-bank institutions. The basic act for them is the Regulation on Financial Monitoring by Institutions approved by Resolution of the NBU Board of 28.07.2020 No. 107. Item 23 of the Regulation sets out in detail the content of internal documents: from the procedure for identification, verification and establishing ultimate beneficial owners to risk criteria, suspicion indicators and refusal of business relationships.

An equally significant, if less public, segment consists of reporting entities supervised by the National Securities and Stock Market Commission (NSSMC): professional capital market participants (other than banks), professional participants of organised commodity markets, non-state pension funds, managers of construction financing funds and real estate transaction funds, and the Central Securities Depository. They are governed by the Regulation on Financial Monitoring by Primary Financial Monitoring Entities Subject to State Regulation and Supervision by the NSSMC, approved by NSSMC Decision of 11.03.2021 No. 176, while the supervisory procedures were substantially updated in 2025-2026. NSSMC Decision of 22.08.2025 No. 13/21/2796/К03 approved a new procedure for supervising compliance with AML/CFT requirements, and since 01.07.2026 a unified regulation on proceedings in cases of offences, approved by Decision of 09.04.2026 No. 15/21/4154/К03, has been in force. It provides for mandatory digital interaction with the regulator through an integrated information and communication system and for the possibility of concluding a settlement agreement both at the stage when the breach is recorded and during the hearing of the case.

The gambling market deserves separate mention. Business entities conducting lotteries and/or gambling are specially designated reporting entities under sub-item «з» of item 7 of part 2 of Article 6 of Law No. 361-IX, and the threshold from which a financial transaction, where the statutory indicators are present, is treated as a threshold transaction is set for them by part 1 of Article 20 of that Law at UAH 55,000 - considerably below the general threshold of UAH 400,000. At the same time the regulatory environment has changed: the Commission for the Regulation of Gambling and Lotteries (KRAIL) was liquidated by Resolution of the Cabinet of Ministers of Ukraine of 25.03.2025 No. 336, and since 02.06.2025 the State Agency of Ukraine PlayCity has been operating.

The most common mistake in this market is to equate the licensing regulator with the AML supervisor. These functions are separate. PlayCity issues licences, monitors compliance with licence conditions and in April 2026 launched, in pilot mode, the State Online Monitoring System, which records bets, winnings and refunds in real time. Its full roll-out is scheduled for autumn 2026.

By contrast, item 3 of part 1 of Article 18 of Law No. 361-IX entrusts state regulation and supervision in the AML/CFT sphere over business entities conducting lotteries and/or gambling to the central executive authority that ensures the formation and implementation of state policy on preventing and countering the legalisation (laundering) of proceeds of crime, that is, the Ministry of Finance of Ukraine. Under part 2 of Article 18 of that Law the inspection procedure for this category of reporting entities is established by the Cabinet of Ministers of Ukraine, and that Procedure was approved by Resolution of the Cabinet of Ministers of Ukraine of 16.06.2023 No. 662.

The basic departmental act for gambling operators is the Regulation on Financial Monitoring by Primary Financial Monitoring Entities Subject to State Regulation and Supervision by the Ministry of Finance of Ukraine, approved by Order of the Ministry of Finance of 07.06.2024 No. 282. Unlike most other reporting entities, for which automation is a matter of expediency, item 4 of Section II of that Regulation expressly obliges a business entity conducting gambling to introduce a financial monitoring automation system. It must record every transaction of accepting and refunding a bet, paying out winnings and exchanging funds for gaming substitutes of the hryvnia, broken down by each identified customer; control that the customer uses one and the same account for all settlements with an online gambling operator; prevent transfers between players’ customer accounts and playing on credit; ensure screening of customers against the list of terrorists, the State Register of Sanctions and for politically exposed person status; and maintain a modification-protected log of each user’s activity. Since 01.01.2026 the annual administrative reporting of such reporting entities has been filed exclusively online through the single web portal of the Ministry of Finance.

The two supervisory systems do not exist in isolation. Under item 10 of part 1 of Article 51 of the Law of Ukraine «On State Regulation of Activities Relating to the Organisation and Conduct of Gambling» of 14.07.2020 No. 768-IX, a ground for terminating a licence is a decision of the said central executive authority to apply an enforcement measure in the form of termination of the licence in accordance with Law No. 361-IX.

This corresponds to item 2 of part 3 of Article 32 of Law No. 361-IX, which expressly lists among enforcement measures the revocation of the licence under which a person acquires the status of a reporting entity. Consequently, systemic breaches of AML requirements mean for a gambling company not only a fine but also the risk of losing a licence which, for an online casino, costs more than UAH 30 million. There is also an important nuance regarding fines: gambling operators are not financial institutions but specially designated reporting entities, so where two or more types of breaches are committed, the cap on the aggregate fine for them is determined under item 2 of part 6 of Article 32 of Law No. 361-IX - twice the amount of the benefit obtained as a result of the breach or, if it cannot be determined, 1,590,000 NMDH (UAH 27.03 million).

Why the System Cannot Be Built Without Software

Law No. 361-IX is built on a risk-based approach, and it is precisely this design that makes manual financial monitoring practically impossible. An institution must not only identify a customer but also assign a risk level, review it periodically, screen the customer and its ultimate beneficial owners against sanctions lists and the list of persons linked to terrorist activity, establish politically exposed person status, detect threshold and suspicious transactions on the basis of a combination of indicators, and report to the State Financial Monitoring Service of Ukraine within the set deadlines in the prescribed electronic formats.

For a pawnshop with dozens of branches or a finance company engaged in online lending, this means thousands of customers and transactions every month.

The regulator understands this and increasingly lays down automation requirements expressly. Thus, item 16 of Regulation No. 107 requires payment institutions to have an automation system ensuring, in particular, the freezing of assets linked to terrorism and its financing, ongoing monitoring of customers’ financial transactions and a modification-protected log of each user’s activity.

For the remaining institutions item 18 of the Regulation requires screening customers against the lists of terrorists and freezing assets by means of an automation system or alternative methods involving electronic data processing, documenting the essence of these measures and demonstrating how they work at the NBU’s request. The last element is particularly telling: the regulator checks not only the result but also the audit trail, that is, the ability to establish who took a decision on a customer or transaction, when and on what grounds. Paper workflows and Excel do not provide such a trail. It is also worth bearing in mind that part 2 of Article 18 of Law No. 361-IX gives the NBU the right to carry out verification (test) transactions, including without notifying the reporting entity: what is checked is not the description of the system in documents but how it actually responds to a specific transaction.

This leads to a key point that the market often underestimates. AML software is not an IT product in the pure sense. Its logic - customer questionnaires, risk criteria, scenarios for detecting suspicious transactions, threshold values, approval routes, response times - is the transfer of regulatory requirements and the institution’s internal documents into an algorithm. If the technical specification is drawn up without a lawyer, the system automates errors: it misses indicators expressly named in the law or generates a mass of false positives that the responsible officer physically cannot process. During an inspection both scenarios are qualified as a failure to ensure proper organisation of primary financial monitoring.

What an Inadequate System Costs

Part 5 of Article 32 of Law No. 361-IX sets separate caps on fines for each type of breach. Failure to comply with customer due diligence requirements, breach of the procedure for documenting and retaining records, or of restrictions on information exchange - up to 12,000 tax-free minimum incomes of citizens, NMDH (UAH 204,000). Failure to report or late reporting, failure to detect or late detection of transactions subject to financial monitoring, obstruction of supervision - up to 20,000 NMDH (UAH 340,000). Breaches relating to asset freezing and politically exposed persons, as well as failure to comply with the regulator’s requirements to remedy breaches - up to 100,000 NMDH (UAH 1.7 million).

The most sensitive is the fine for failure to ensure proper organisation and conduct of primary financial monitoring and the absence of a proper risk management system - up to 10% of total annual turnover, but not more than 7,950,000 NMDH, that is, UAH 135.15 million. It is precisely this maximum amount that the payment terminal operators mentioned above received in May 2026. In addition, under part 6 of Article 32 of Law No. 361-IX, where two or more types of breaches are committed, the fines for each type are added together. For financial institutions the total is capped at the same maximum; for other reporting entities - at twice the benefit obtained as a result of the breach or, if it cannot be determined, 1,590,000 NMDH (UAH 27.03 million).

Alongside a fine, the regulator may apply a written warning, require the removal of an officer from work, revoke a licence or conclude a settlement agreement providing for payment of an agreed monetary obligation. Information on enforcement measures applied, stating the name of the institution, the amount of the fine and general details of the breach, is published on the regulator’s website and remains available for at least five years, so for a financial institution the reputational consequences often exceed the financial ones. The time limit for applying an enforcement measure is six months from the date the breach is detected, but not later than three years from the date it was committed. The decision may be challenged in court within one month from the date it takes effect, and if this is not done and the fine is not paid voluntarily, the decision acquires the status of an enforcement document.

Officers bear personal liability as well. Article 166-9 of the Code of Ukraine on Administrative Offences provides for a fine of 300 to 2,000 NMDH (UAH 5,100 to 34,000) for officers of reporting entities.

Moreover, Article 209-1 of the Criminal Code of Ukraine establishes criminal liability for intentional failure to submit, late submission or submission of false information on financial transactions subject to financial monitoring, where this has caused substantial harm to the rights, freedoms or interests of citizens, state or public interests or the interests of legal entities: a fine of 1,000 to 3,000 NMDH (UAH 17,000 to 51,000) or probation supervision for up to three years, with deprivation of the right to hold certain positions or engage in certain activities for up to three years. For disclosure of financial monitoring secrecy, part 2 of Article 209-1 of the Criminal Code of Ukraine provides for a fine of 3,000 to 5,000 NMDH (UAH 51,000 to 85,000) with the same deprivation of rights. For the AML responsible officer or the head of an institution, this means a criminal record and the de facto loss of their profession in the financial services market.

How We Build a Financial Monitoring System

Our law firm has significant and in-depth experience in the field of financial monitoring, gained on projects for finance companies, insurance companies, professional capital market participants and other reporting entities. We provide effective legal assistance in developing a full package of internal documents: financial monitoring rules, programmes for conducting primary financial monitoring and staff training, methodologies for assessing the risks of the institution and its customers, procedures for customer due diligence, detection and reporting of suspicious transactions, and response to sanctions alerts. The documents are developed around the institution’s actual business processes rather than adapted from a template, which directly affects the outcome of an inspection.

A separate area of our work is legal assistance in implementing the system as a whole: a legal audit of the existing system for compliance with Law No. 361-IX and the acts of the NBU and the NSSMC, preparation of the technical specification for a software developer or vendor, formalisation of risk criteria and suspicion indicators in a form suitable for algorithmisation, and acceptance of the system from a legal standpoint. Where necessary, we are able to support clients during on-site and off-site inspections, prepare explanations and objections, and represent their interests during the hearing of cases, the conclusion of settlement agreements and the appeal of decisions on enforcement measures.

If your institution is planning to update its financial monitoring system, introduce new software or is preparing for a regulatory inspection, it is worth starting with an audit of existing documents and processes: it is precisely this audit that shows which gaps may cost the institution UAH 135.15 million and which can be closed within a few weeks of work.

This material is for information purposes only and does not constitute legal advice. Financial monitoring legislation changes frequently, and it is worth verifying that it remains current before taking any decision.

Дякуємо!

Наша команда зв’яжеться з вами найближчим часом