Forecast Notes

EU Audit Shows Up to €1.9 Trillion Laundering

By Stephanie Cole October 10, 2026
EU Audit Shows Up to €1.9 Trillion Laundering - money laundering
The audit, conducted by supreme audit institutions from Cyprus, Germany, the Netherlands, Spain and Poland, covered 2020–2024.

The joint audit notes that illegal money moving worldwide amounts to roughly 2% to 5% of global GDP, translating to between €715 billion and €1.87 trillion each year. These figures highlight the scale of the challenge confronting European anti-money-laundering efforts.

Scope of the Multinational Audit

Supreme Audit Institutions from Cyprus, Germany, the Netherlands, Spain, and Poland examined the period 2020–2024. Their report identified gaps in the European anti-money-laundering framework and singled out Cyprus for a series of institutional shortcomings.

The audit focused on the efficiency of supervisory bodies, the quality of risk assessments, and the compliance of banks with customer-due-diligence rules. Findings point to delays, data-access disputes, and inadequate documentation that weaken overall oversight.

Institutional Disputes Limit Oversight

In Cyprus, the Auditor General and the Central Bank of Cyprus clashed over the audit’s scope. The bank argued that the audit office could only assess “operational efficiency” and that data linked to the Single Supervisory Mechanism were confidential.

Because of this disagreement, the audit team received internal inspector reports and complaint files late and in incomplete form. The audit office therefore could not confirm whether the central bank fully separates its AML supervisory duties from other monetary functions.

Restrictions on data provision meant the audit could only evaluate the bank’s operational efficiency, not the substantive independence of its supervisory role. This limitation reduced the assurance level required by international standards.

Bank Practices and De-Risking of NGOs

Review of three less-significant institutions revealed gaps in anti-money-laundering legislation compliance. Banks delayed reviews of customer business profiles, often submitting incomplete documentation.

Customer-due-diligence and transaction-monitoring procedures were found lacking, with risk-assessment scenarios not tailored to individual client risk. Critical risk indicators frequently went undetected.

Read Also: OpenAI safety executive resigns over risk concerns

Two banks faced monetary fines, while a third entered enhanced supervision during the audit period. Fear of penalties has driven a de-risking trend, prompting banks to refuse services to entire categories of clients without case-by-case evaluation.

The fifth evaluation of the Council of Europe’s MONEYVAL Committee noted that Cypriot banks treat all non-profit organizations as high-risk by default. This blanket approach has led many charities and NGOs to encounter difficulties opening new accounts, hampering their operations.

Compared with earlier audits in other EU states, the Cypriot case shows how institutional friction can slow risk-assessment updates and erode banking cooperation. When supervisory bodies cannot share data promptly, both regulators and financial institutions lose the ability to spot illicit flows early.

Financial Intelligence Unit Faces Autonomy Issues

The Unit for Combating Money Laundering, known as MOKAS, reports to the Law Office of the Republic, with its head representing the Attorney General. The audit highlighted that lacking a separate budget may compromise its operational independence.

In 2024, MOKAS received 3,870 suspicious transaction reports, up from 1,594 in 2020. The share of bank-originated reports fell from 39% to 17% as crypto-asset cases surged, demanding specialized expertise.

On average, MOKAS forwards 5.5% of bank reports to police for criminal investigation. A sample of 101 reports showed 27% related to money-laundering suspicions, while the remainder involved fraud, cyber fraud, corruption or sanctions breaches.

The audit also found gaps in the quality of bank submissions to MOKAS, especially regarding identification of involved parties, justification of suspicion, supporting documentation, and timely delivery.

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 Business Analystic. All rights reserved.