Back Fincrimecentral CBC Fines Banque SBA Cyprus €750000 Over AML Compliance Failures
Banque SBA Cyprus has been fined €750,000 by the Central Bank of Cyprus(CBC) following findings from a 2023 examination. The decision was taken on 29 September 2026 and announced on 30 September. The regulator identified non-compliance with provisions of the national anti-money laundering law and its February 2019 directive for credit institutions. Its short notice establishes a supervisory penalty, without publishing the detailed findings or identifying a criminal money laundering transaction.
Banque SBA Cyprus AML fine follows a 2023 CBC examination
The announcement names the sanctioned institution and gives its legal entity identifier as 213800X5TSY4F7M3X732. That precision matters when assessing an enforcement disclosure: the decision concerns the named Cyprus institution, and should not automatically be attributed to other entities with similar names. The published material provides no breakdown of the amount between individual breaches. It therefore cannot support an assessment of which requirement contributed most to the penalty or how the regulator weighted separate deficiencies when determining the overall sum.
The examination year, decision date and publication date represent different stages. The statement does not define the full period during which the breaches occurred, specify when they were first identified internally, or describe subsequent corrective work. A 2023 examination followed by a decision in 2026 does not establish that the same problems continued throughout that interval. Equally, publication of a financial penalty does not demonstrate that the underlying weaknesses have been resolved. Both conclusions would require further evidence beyond the dates supplied.
The most important evidentiary boundary concerns the nature of the finding. Failure to comply with preventive requirements can justify regulatory action without establishing that the institution or a customer committed a laundering offence. Nothing in the published notice identifies criminal proceeds, a predicate offence, a suspect, an affected account or a transaction route. The sanction should consequently be read as a documented compliance finding. Describing it as proof of illicit transfers, terrorist financing or sanctions evasion would add facts that the regulator has not disclosed.
The legal basis and procedural position
The CBC situates the decision within section 59(6) of the Prevention and Suppression of Money Laundering Activities Law of 2007, as amended. Its explanation concerns non-compliance with Part VIII or relevant supervisory directives. The notice also describes an administrative process that gives the affected institution an opportunity to be heard before the final decision. This is relevant to the legal character of the action, but it supplies no account of the bank’s submissions, disputed issues or the regulator’s response to particular arguments.
The separate official sanctions register records that the 75-day deadline under Article 146 of the Constitution has not yet expired. That entry should not be converted into a statement that an appeal has been filed, nor into a prediction that the decision will be challenged. It identifies the procedural position reported by the authority at publication. An assessment of later developments would need an updated official entry or a court record. The current material also does not establish that the fine has already been paid.
The regulator’s general supervisory framework helps explain why an examination can lead to this type of decision. The CBC describes off-site monitoring supported by institutional returns and reports, alongside on-site inspections that assess the adoption and application of preventive policies, systems and procedures. It distinguishes comprehensive, thematic and special inspections. The SBA notice does not identify which category applied to the 2023 examination. For analytical purposes, the relevant point is that supervision tests implementation as well as the existence of written policies; the actual scope and testing results remain undisclosed.
The historical directive and its replacement
The February 2019 fifth edition is expressly identified in the sanction, making it the appropriate starting point for understanding the historical regulatory context. It covers customer identification, due diligence and risk assessment, together with governance and internal control arrangements. These subjects describe the framework within which the examination findings arose. They are not a list of breaches proved against this institution, because the announcement does not identify the relevant paragraphs or explain which operational processes failed to meet them.
The historical directive connects reliable customer information with the assessment of a relationship’s economic and risk profile. It also addresses data quality, access to information for the compliance function, management reporting and internal audit. These provisions illustrate why preventive controls must operate as an integrated process: information collected at onboarding must remain usable when activity is assessed later. A bank can have extensive documentation while still needing to demonstrate that its information supports decisions. That is a general control issue, not a disclosed weakness at SBA.
A newer directive was published in the Official Gazette on 2 May 2025. Its unofficial English translation includes a transitional provision, paragraph 72, retaining the February 2019 provisions for qualifying procedures, actions or acts already initiated but incomplete when the new directive entered into force. Paragraph 73 provides for repeal of the earlier directive. These provisions supply relevant background to the continued historical reference, although the penalty announcement does not itself explain the application of paragraph 72 to this proceeding.
For institutions assessing their own exposure, the distinction between historical requirements and the current framework deserves explicit documentation. A review should identify which rules governed the conduct being examined and which rules govern present operations. Updating a policy to reflect a new directive would not, by itself, answer questions earlier implementation. Conversely, a historical penalty should not be presented as an exhaustive assessment of present compliance. The chronology makes version control useful, while leaving the bank’s actual remediation and current operating position open.
What the decision means for control assurance
The practical lesson from a notice this brief is to distinguish a confirmed supervisory outcome from assumptions its causes. The €750,000 amount demonstrates that the regulator imposed a substantial financial consequence. It does not quantify criminal proceeds, customer exposure, the number of defective files or losses to third parties. Without those denominators, comparisons with penalties imposed elsewhere can be misleading. Differences in legal frameworks, breach populations and decision criteria would need to be understood before treating a larger or smaller amount as a comparable measure of institutional risk.
An institution learning from the case could ask whether its own control assessments produce evidence that another reviewer can follow. Useful evidence might connect a requirement to a tested process, the population examined, identified exceptions and the decision to accept or correct them. Those are analytical suggestions for assessing effectiveness, rather than additional duties or corrective instructions announced in the SBA case. The regulator has not published an action plan, a remediation deadline or an independent review requirement for this bank in the cited notice.
Board oversight should likewise be assessed through the quality of decisions and follow-through, rather than the volume of reporting alone. A meaningful review would ask whether outstanding issues have accountable owners, whether completion claims are independently tested where appropriate, and whether recurring exceptions receive timely attention. These questions are consistent with evaluating a preventive control environment, but they do not imply that SBA’s board ignored warnings or that its audit function failed. The public record contains no findings named individuals or specific governance decisions.
Further official disclosure could clarify the breached provisions, any judicial challenge and the status of corrective work. Until then, the defensible assessment remains bounded: the CBC has imposed a financial penalty after an examination, and the published explanation leaves the operational detail unresolved. This case is useful as a reminder that regulatory findings deserve close attention without being expanded into a criminal narrative. For AML practitioners, the response is to examine demonstrable control performance and preserve the distinction between established facts, relevant background and professional analysis.
The CBC imposed a €750,000 fine following a 2023 examination.
The decision was taken on 29 September and published on 30 September 2026.
The notice cites the AML law and the February 2019 directive without detailing individual breaches.
No criminal laundering transaction or completed remediation is identified.
The judicial-review deadline had not expired at publication.
Frequently Asked Questions
How much was Banque SBA Cyprus fined?
The CBC imposed a €750,000 administrative fine. The published notice does not state that it has been paid.
When was the decision announced?
The announcement was published on 30 September 2026. The decision was taken on 29 September 2026.
What examination led to the sanction?
The decision followed findings from an examination conducted during 2023. The notice does not give its detailed scope or the full breach period.
Which requirements does the announcement identify?
It identifies provisions of the national AML law and the February 2019 fifth edition of the CBC directive for credit institutions. It does not specify the individual provisions breached.
Does the fine establish a criminal laundering offence?
The notice establishes non-compliance with preventive requirements. It does not identify a criminal offence or a particular illicit transaction.
Has a judicial challenge been reported?
The official sanctions entry says the 75-day deadline under Article 146 has not yet expired. That statement does not establish that a challenge has been filed.
Why is the 2019 directive relevant after its replacement?
It is the edition expressly cited in this decision. The 2025 directive also retains the earlier provisions for qualifying pending procedures, without the case notice explaining that provision’s application here.
What remediation has the bank been ordered to complete?
The cited announcement does not publish a remediation programme or deadline. Any assessment of corrective work would require further documented information.
CBC: AML/CFT legal framework and supervisory approach
CBC: February 2019 directive for credit institutions (historical edition)
CBC: Publication of the 2025 AML/CFT directive
CBC: 2025 AML/CFT directive (unofficial English translation)
FATF: International AML/CFT Recommendations
Other FinCrime Central Articles on Bank AML Oversight
Banca Ifis Discloses AML Findings in Bank of Italy Inspection
BaFin Fines Volksbank Düsseldorf Neuss €210,000 Over AML Failures
Julius Baer Monaco Fined €1.5m for Serious AML Failings
Source: Central Bank of Cyprus, announcement of 30 September 2026
Some of FinCrime Central’s articles may have been enriched or edited with the help of AI tools. It may contain unintentional errors.
Want to promote your brand, or need some help selecting the right solution or the right advisory firm? Email us at [email protected]; we probably have the right for you.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
