Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

EDCA-P08 · Governed by EDCA-STD-09

AML/CFT Programme Certification

An assessment of the quality of an anti-money-laundering and counter-terrorist-financing programme — and, where the organisation supplies screening tooling to others, of the methodology behind that tooling. It asks whether the risk methodology is defensible, whether the lists are current, and whether alerts are worked rather than merely raised.

What this certification is not

This certification is an assessment of a programme, not a regulatory status. It is not registration or authorisation as an obliged entity, not supervision by a national competent authority or by the Anti-Money Laundering Authority, and not a substitute for the organisation's own obligations under Regulation (EU) 2024/1624, Regulation (EU) 2023/1113 or national law. Where the certified organisation supplies screening tooling to others, the certificate concerns that tooling and transfers no obligation from the user of the tooling to its supplier.

Scope of assessment

The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.

  • The AML/CFT programme as applied to named business lines
  • The risk assessment methodology and its calibration
  • Screening against sanctions and other lists, and the currency of those lists
  • Alert handling, escalation and closure
  • Records required to be kept, their retention and their retrievability
  • Where tooling is supplied to others, the methodology behind its output

What is examined

Each area below is assessed against the requirements of EDCA-STD-09, Anti-Money-Laundering and Counter-Terrorist-Financing Programmes, version 1.0.

  • Business-wide risk assessment and the evidence supporting it
  • Customer due diligence proportionate to assessed risk
  • Sanctions and list screening, including provenance and update frequency
  • Management of false positives and of missed matches
  • Transaction monitoring rules and their tuning
  • Information accompanying transfers of funds and crypto-asset transfers
  • Escalation, internal reporting and record retention
  • Independence and competence of the compliance function

Programme particulars

Programme code
EDCA-P08
Governing standard
EDCA-STD-09 — Anti-Money-Laundering and Counter-Terrorist-Financing Programmes, version 1.0, issued 28 July 2026
Levels available
Level II — EDCA Security Verified
Level III — EDCA Advanced Compliance
Level IV — EDCA Trusted Technology
Typical duration
Ten to sixteen weeks from application to decision.
Surveillance
As required by the level held. See level requirements.

Evidence normally requested

The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.

  1. Business-wide risk assessment
  2. Screening list inventory with sources and update timestamps
  3. Alert volumes, closure reasons and ageing
  4. Tuning records and testing of monitoring rules
  5. Sample case files showing the rationale for each decision
  6. Retention schedule and a demonstration of retrieval
  7. For tooling suppliers: the scoring methodology and its validation

Apply for AML/CFT Programme Certification

Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.