The AML Act – what it requires of obliged entities
Act No. 253/2008 Coll. on certain measures against legitimisation of proceeds from crime is the core legal framework for AML compliance in the Czech Republic. This page explains what the law requires and how to meet your obligations more easily.
What is the AML Act?
Act No. 253/2008 Coll. — on certain measures against legitimisation of proceeds from crime and financing of terrorism — is the Czech transposition of the European AML directive. It sets out specific obligations for so-called obliged entities.
The AML Act has undergone a series of amendments and tightening in recent years. A key change comes with the European regulation AMLR (EU) 2024/1624, which will be fully applicable from 2027. The new European authority AMLA started operating in January 2026.
The Act is enforced by the Financial Analytical Office (FAÚ), which has significantly intensified inspections and penalties since 2023.
Key sections
- § 7–9Client identification and customer due diligence (KYC/CDD)
- § 9aEnhanced identification and customer due diligence (EDD)
- § 21aRisk assessment of the obliged entity
- § 21Internal policies and procedures (SVZ)
- § 22Contact person for communication with the FAÚ
- § 22aResponsible person — a member of the statutory body accountable for AML compliance
- § 18Suspicious transaction reporting (STR) to the FAÚ
- § 9 odst. 2 písm. d)Ongoing monitoring of the business relationship
- § 16Archivace dokumentů — min. 10 let
Obligations under the AML Act
The AML Act imposes six core areas of obligation. Each must be actively fulfilled by the obliged entity.
Client identification and verification (KYC)
Before entering a business relationship, the obliged entity must identify the client — a natural or legal person — and verify their identity (§ 7–8).
PEP screening and sanctions checks
Checking whether the client is a politically exposed person (§ 8(8)) or appears on EU, UN sanctions lists (§ 9(2)(c), Act No. 69/2006 Coll.).
Business relationship risk assessment
Every client must be assigned a risk category (§ 9, § 21a). High-risk clients are subject to enhanced due diligence (§ 9a).
Internal AML policy and responsible person
The obliged entity must have a written internal AML policy and designate a responsible person in writing (§ 22a) — a member of the statutory body — and notify the FAÚ of a contact person (§ 22). These are two distinct roles under two different provisions.
Suspicious transaction reporting (STR)
Suspicious transactions or business relationships must be reported to the Financial Analytical Office (§ 18).
Archiving and audit trail
Veškerá AML dokumentace musí být uchována minimálně 10 let pro případ kontroly FAÚ.
Who does the AML Act apply to?
Obliged entities are precisely defined in § 2 of Act No. 253/2008 Coll. If you fall into one of the categories below, the full scope of AML obligations applies to you.
- Credit and financial institutions
- Real estate agents and brokers
- Accounting firms and tax advisors
- Attorneys and notaries
- Virtual asset service providers (cryptocurrencies)
- Leasing and factoring companies
- Casinos and betting shops
- Auctioneers and art dealers
- Insurance intermediaries
- Fund managers and investment advisors
Penalties for non-compliance
Frequently asked questions about the AML Act
Do I have to comply with the AML Act even if I am a small business?
Yes. The AML Act does not distinguish by company size — if you are a defined obliged entity under § 2, you must fulfil all obligations without exception. The FAÚ inspects small businesses as well.
How does KYC differ from AML?
KYC (Know Your Customer) is one component of AML. AML is a broader system of measures covering KYC identification (§ 7–8), PEP screening (§ 8(8)), risk assessment (§ 21a), internal policy (§ 21), the responsible person (§ 22a) and reporting (§ 18).
When is EDD (enhanced due diligence) required?
EDD is mandatory for high-risk business relationships — § 9a(2) defines mandatory triggers: the client is a PEP, the client's country of origin is a high-risk third country, or the transaction relates to a high-risk third country. EDD also applies where risk assessment indicates elevated risk (§ 9a(1)).
How can I comply with the AML Act efficiently?
The most efficient approach is a dedicated cloud AML system that covers all legal requirements. AML PROOF automates KYC, PEP screening, risk assessment, internal documentation and FAÚ reporting in one place — no installation required.