EU Audit Shows Up to €1.9 Trillion Laundering

The joint audit notes that illegal money moving worldwide amounts to roughly 2% to 5% of global GDP, translating to between €715 billion and €1.87 trillion each year. These figures highlight the scale of the challenge confronting European anti-money-laundering efforts.
Scope of the Multinational Audit
Supreme Audit Institutions from Cyprus, Germany, the Netherlands, Spain, and Poland examined the period 2020–2024. Their report identified gaps in the European anti-money-laundering framework and singled out Cyprus for a series of institutional shortcomings.
The audit focused on the efficiency of supervisory bodies, the quality of risk assessments, and the compliance of banks with customer-due-diligence rules. Findings point to delays, data-access disputes, and inadequate documentation that weaken overall oversight.
Institutional Disputes Limit Oversight
In Cyprus, the Auditor General and the Central Bank of Cyprus clashed over the audit’s scope. The bank argued that the audit office could only assess “operational efficiency” and that data linked to the Single Supervisory Mechanism were confidential.
Because of this disagreement, the audit team received internal inspector reports and complaint files late and in incomplete form. The audit office therefore could not confirm whether the central bank fully separates its AML supervisory duties from other monetary functions.
Restrictions on data provision meant the audit could only evaluate the bank’s operational efficiency, not the substantive independence of its supervisory role. This limitation reduced the assurance level required by international standards.
Bank Practices and De-Risking of NGOs
Review of three less-significant institutions revealed gaps in anti-money-laundering legislation compliance. Banks delayed reviews of customer business profiles, often submitting incomplete documentation.
Customer-due-diligence and transaction-monitoring procedures were found lacking, with risk-assessment scenarios not tailored to individual client risk. Critical risk indicators frequently went undetected.
Read Also: OpenAI safety executive resigns over risk concerns
Two banks faced monetary fines, while a third entered enhanced supervision during the audit period. Fear of penalties has driven a de-risking trend, prompting banks to refuse services to entire categories of clients without case-by-case evaluation.
The fifth evaluation of the Council of Europe’s MONEYVAL Committee noted that Cypriot banks treat all non-profit organizations as high-risk by default. This blanket approach has led many charities and NGOs to encounter difficulties opening new accounts, hampering their operations.
Compared with earlier audits in other EU states, the Cypriot case shows how institutional friction can slow risk-assessment updates and erode banking cooperation. When supervisory bodies cannot share data promptly, both regulators and financial institutions lose the ability to spot illicit flows early.
Financial Intelligence Unit Faces Autonomy Issues
The Unit for Combating Money Laundering, known as MOKAS, reports to the Law Office of the Republic, with its head representing the Attorney General. The audit highlighted that lacking a separate budget may compromise its operational independence.
In 2024, MOKAS received 3,870 suspicious transaction reports, up from 1,594 in 2020. The share of bank-originated reports fell from 39% to 17% as crypto-asset cases surged, demanding specialized expertise.
On average, MOKAS forwards 5.5% of bank reports to police for criminal investigation. A sample of 101 reports showed 27% related to money-laundering suspicions, while the remainder involved fraud, cyber fraud, corruption or sanctions breaches.
The audit also found gaps in the quality of bank submissions to MOKAS, especially regarding identification of involved parties, justification of suspicion, supporting documentation, and timely delivery.