D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.
Gibraltar (British Overseas Territory) runs its own AML/CFT/CPF regime under the Proceeds of Crime Act 2015, Terrorism Act 2018 and Sanctions Act 2019, supervised by the GFSC and GFIU.
Sanctions is not yet covered for this jurisdiction in this report.
Gibraltar sits outside the EU AML Package direct perimeter, but a durable structural fact of that Package remains relevant backdrop for reading any beneficial-ownership and corporate-transparency signal touching UK-aligned offshore centres such as Gibraltar. Globally, the EU AML Package now comprises three distinct instruments: the AML Regulation (AMLR, Regulation (EU) 2024/1624), which is directly applicable across EU Member States without transposition; the sixth AML Directive (6AMLD, Directive (EU) 2024/1640), which each Member State transposes into its own domestic law; and the AMLA Regulation (Regulation (EU) 2024/1620), which establishes the Anti-Money Laundering Authority and shifts supervision of higher-risk cross-border obliged entities from purely national competent authorities toward a hybrid EU-level regime combining direct AMLA supervision of designated entities with indirect AMLA oversight of national supervisors generally. Gibraltar, not being an EEA member, has no direct transposition obligation under 6AMLD and no entities subject to direct AMLA supervision; its connection to this architecture runs instead through the UK-EU Agreement in respect of Gibraltar, under which the UK commits, in respect of Gibraltar, not to weaken AML/CFT measures below the levels set by the Annex 17 list of EU instruments, which names the AMLR, 6AMLD, the AMLA Regulation and the funds-transfer Regulation 2023/1113 specifically. This is a floor obligation, not a transposition duty, and it carries no corresponding EU market access or passporting benefit; European Parliament consent to the Agreement remains pending, with an indicative plenary vote of 14 December 2026.
Against that backdrop, the directly relevant beneficial-ownership and customer-transparency signal for Gibraltar this cycle concerns its politically-exposed-person regime, which operates as a proxy for broader beneficial-ownership risk sensitivity in practice. Under POCA sections 20A, 20B and 20(2), the PEP test turns on whether a natural person is or has been entrusted with a prominent public function, explicitly including heads of state, heads of government, ministers, and deputy or assistant ministers, while expressly excluding middle-ranking or more junior officials; there is no foreign-versus-domestic distinction, so EEA residence confers no concession equivalent to the UK domestic-PEP treatment. Once a PEP ceases to hold that prominent public function, a relevant financial business must, for at least twelve months, continue to take into account the continuing risk the person poses and apply appropriate and risk-sensitive measures until satisfied no further PEP-specific risk remains. Section 20(2) extends this entire regime, including the twelve-month continuing-obligation period, to family members and persons known to be close associates of PEPs as though those persons were themselves PEPs. This is a materially stricter position than the UK Money Laundering Regulations, which drop the family/associate extension once the PEP leaves office; a group applying UK PEP-exit logic mechanically to its Gibraltar-regulated entities would under-apply the continuing obligation precisely where Gibraltar law demands more scrutiny, not less.
The PEP continuing-obligations divergence from UK practice is likely to remain a live compliance-trap vector for cross-border groups rather than a one-off finding, given how naturally UK and Gibraltar AML policies get drafted from shared templates. On the broader architecture, the open question is whether the UK-EU Agreements Annex 17 non-regression list is read as a static snapshot of the AML Package as it stood at provisional application, or as a dynamic reference that tracks future amendments to the AMLR, 6AMLD and AMLA Regulation as the EU-level supervisory architecture matures; that question will likely sharpen once European Parliament consent is resolved around the indicative December 2026 timeline.
Gibraltars standing as a UK-aligned enabler jurisdiction gained a new and somewhat paradoxical external constraint this cycle: an AML/CFT non-regression commitment anchored in EU law, arriving without any accompanying EU market-access benefit. The UK-EU Agreement in respect of Gibraltar was signed on 14 July 2026 and provisionally applied from the same date under Article 336(4). Article 198(2) of that Agreement states the objective plainly: to support and strengthen action by the Union and by the United Kingdom, in respect of Gibraltar, to prevent and combat money laundering and terrorist financing, and specifically commits that the United Kingdom, in respect of Gibraltar, shall not weaken or reduce its anti-money-laundering and terrorist-financing measures below the levels set out in the Union acts listed in Annex 17, in force at the date of entry into force of the Agreement. Annex 17 names Directive (EU) 2015/849 as amended, the AML Regulation (2024/1624), the sixth AML Directive (2024/1640), the AMLA Regulation (2024/1620) establishing the Anti-Money Laundering Authority, and the funds-transfer Regulation (2023/1113).
The architectural significance of this arrangement is that it creates a floor without a ceiling benefit: Gibraltar is bound to maintain AML/CFT standards referencing an EU instrument set it has no vote in amending and no corresponding passporting right to exploit, a position distinct from both full EU membership and from a jurisdiction with no EU-referenced AML commitment at all. This is precisely the kind of structural finding this framework privileges over single-incident analysis: it is not a response to a specific enforcement failure or designation, but a standing treaty-level commitment reshaping the external reference points against which Gibraltars domestic AML drafting will be measured going forward. European Parliament consent to the Agreement remains pending, with an indicative plenary vote scheduled for 14 December 2026, meaning the Agreements full legal status, and by extension the binding force of the Article 198(2) commitment, carries a degree of procedural uncertainty that a reader should track rather than assume resolved.
This non-regression commitment should also be read alongside the absence, this cycle, of any new sanctions-architecture or sanctions-divergence development: Gibraltars Sanctions Act 2019, consolidated to 9 September 2026, continues to function as the domestic implementing framework without structural change, meaning the UK-EU Agreements AML-specific non-regression clause is, for now, the dominant enabler-jurisdiction signal rather than one strand among several moving in parallel.
The principal forward-looking question for Gibraltars enabler-jurisdiction profile is whether European Parliament consent to the UK-EU Agreement proceeds on the indicative 14 December 2026 timeline, and if so, how UK domestic implementation translates the Article 198(2) non-regression duty into enforceable Gibraltar-facing supervisory expectations, given that Annex 17 references instruments (the AMLR, 6AMLD and AMLA Regulation) that are themselves still in their early implementation phase across the EU. A jurisdiction bound to a moving external reference point, without a vote in how that reference point moves, is a structural position worth continued attention independent of any single enforcement event.
Conflict Finance is not yet covered for this jurisdiction in this report.
Gibraltars own crypto and virtual-asset AML perimeter was materially reshaped this cycle, directly within Gibraltars own regulatory architecture rather than as a derivative of any global standard-setting exercise. The Funds (Transfer) Regulations 2026 (LN 2026/134) commenced 15 July 2026 and revoke, in full, the onshored text of Regulation (EU) 2015/847 together with the prior Proceeds of Crime Act 2015 (Transfer of Virtual Assets) provisions that had governed virtual-asset transfer information requirements. In their place, the new Regulations establish a single travel-rule baseline covering both fiat payment-service-provider transfers and virtual-asset-service-provider transfers. Regulations 6 and 8 require payer and payee information, including name and payment account number, to accompany transfers and to be verified before execution; regulation 25 requires payment service providers and virtual asset service providers alike to maintain internal policies, procedures and controls to implement restrictive measures when performing transfers of funds and virtual assets; and regulation 28 imposes a five-year record-retention obligation on originator and beneficiary information for virtual-asset-service-provider transfers specifically, mirroring the retention standard applied to fiat transfers. A reduced-information carve-out applies where all payment service providers in a transfer chain are established in Gibraltar and the transfer falls within the unlinked, lower-value category.
The structural significance of this instrument is that it deems fiat-referenced e-money tokens to be virtual assets for its own purposes, closing what might otherwise have been a product-classification gap between e-money regulation and virtual-asset regulation at the travel-rule layer specifically. This positions Gibraltars VASP-inclusive travel-rule coverage ahead of many comparably sized jurisdictions that have not yet extended fiat transfer-regulation architecture to cover virtual-asset transfers on an equivalent informational footing. It is also a clean illustration of architecture over incident: the change responds to no single enforcement failure in the virtual-asset space but instead resets the entire information-accompaniment and record-retention baseline for a product category, fiat-referenced e-money tokens, that sits at the boundary between traditional payments regulation and crypto-asset regulation.
The revocation of the prior Transfer of Virtual Assets provisions under POCA, alongside the onshored EU Funds Transfer Regulation, also simplifies Gibraltars legal architecture in this space: rather than maintaining two parallel instruments for fiat and virtual-asset transfers, Gibraltar now operates a single consolidated regime, which is itself a structural simplification worth noting independent of the substantive obligations it imposes.
The open question for this domain is less about the substance of the new travel-rule baseline, which is now in force and reasonably detailed, and more about how GFSC supervisory practice will evidence compliance with the virtual-asset-specific obligations, particularly the restrictive-measures policy requirement under regulation 25 and the five-year retention duty under regulation 28, given that no enforcement record yet exists against this specific instrument. Whether the deeming of fiat-referenced e-money tokens as virtual assets for travel-rule purposes is extended, by future amendment or guidance, into other areas of Gibraltars financial-services regulatory architecture is also worth tracking as a potential template for how the jurisdiction treats boundary-category digital-asset products more broadly.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
Gibraltars AML/CTF regime rests on the Proceeds of Crime Act 2015 (POCA), as amended, and is supplemented by Gibraltar Financial Services Commission (GFSC) guidance notes covering customer due diligence, customer risk assessment, and ongoing monitoring. The regime places the customer due diligence and enhanced due diligence decision, and the risk attaching to it, on the Gibraltar legal entity itself: under POCA sections 9B, 10, 13, 15, 20 through 20B, 23 and 26, a relevant financial business must appoint a director, senior manager or partner with the duty of ensuring compliance, and where that business relies on a third party to apply customer due diligence measures, section 23 provides that the relying Gibraltar firm remains liable for any failure in those measures notwithstanding the reliance; subsection (1A) confirms this is not to be construed as permitting reliance on a third party of a kind that would defeat this liability rule. Where the Gibraltar entity in question is a branch of a UK company rather than a Gibraltar-incorporated entity in its own right, the risk-owning legal person shifts to the UK parent company under the UK Money Laundering Regulations 2017, regulation 20, a distinction that matters for groups operating both structures.
Simplified due diligence under section 16 and Schedule 6 is available in principle but is structurally constrained by geographic risk factors identified in the 2025 National Risk Assessment (NRA v1.3): a regulated entity can never treat the country risk of Spain as Low Risk, and no customer with a residency, nationality or economic-activity connection to Spain may be given simplified due diligence; funds received from either Spain or Morocco must be categorised as high risk and subjected to additional risk-based controls under each entitys risk-based approach. There is no fixed numerical purse-limit derogation permitting simplified due diligence for products such as certain electronic money by reference to transaction value alone; the geographic-risk constraint takes precedence over any such product-based carve-out. Where a customer has not been physically present for identification purposes, section 18 requires a relevant financial business to take specific and adequate measures to compensate for the higher risk this presents, for example through additional documentary verification, certification of documents by an appropriate person, or requiring the first payment to be carried out through an account opened in the customers name at a credit institution.
Ongoing monitoring obligations under sections 12, 17(3) and 10(ca) require relevant financial businesses to scrutinise transactions throughout a business relationship to ensure consistency with the businesss own knowledge of the customer and the customers risk profile, with particular attention to transactions that are unusually large, conducted in an unusual pattern, or lack an apparent economic or lawful purpose; monitoring obligations are enhanced where the customer is a politically exposed person. A statutory sanctions check obligation sits alongside this monitoring duty at section 10(ca). Tipping-off provisions at sections 5 and 11(5) and (5A) make it an offence for a person to disclose matters that would prejudice an investigation where the information disclosing that matter came to the person in the course of a business or activity covered by the Act. Where a relevant financial business is unable to apply the required customer due diligence measures, it must not carry out a transaction with or for the customer through a bank account and must not establish a business relationship or carry out an occasional transaction with that customer. Records, including copies of customer due diligence documentation and transaction records, must be retained for a period of five years beginning on the date an occasional transaction is completed or the date the business relationship ends, after which personal data must be deleted unless retention is required by another enactment or the Minister has by order provided for its continued retention.
As this is the first cycle in which Gibraltars standing AML/CTF baseline under POCA has been collected and set out in this detail, the immediate point of continuity to track is how this baseline interacts with the newly in-force Funds (Transfer) Regulations 2026 travel-rule regime and with the UK-EU Agreements AML non-regression commitment, both of which layer additional obligations onto the same underlying customer due diligence and ongoing monitoring architecture described above.
Commercial Activity is not yet covered for this jurisdiction in this report.
The geographic-risk precedence barring Low Risk ratings and SDD for Spain-connected customers, and the twelve-month PEP continuing-obligation period extending to family and associates, both bear directly on how an MLRO sets ongoing risk ratings and monitoring intensity for Gibraltar-regulated books.
Compliance functions overseeing payment or VASP operations in Gibraltar now operate under a single consolidated travel-rule instrument with new verification, policy and five-year retention duties in force from 15 July 2026.
Legal counsel advising on Gibraltar-linked structures should note the Agreements Article 198(2) commitment references a specific and evolving EU instrument list (Annex 17) while conferring no passporting right, and its final legal status remains contingent on European Parliament consent indicatively expected 14 December 2026.
Board-level oversight of Gibraltar-linked operations should treat this hybrid posture as a durable characteristic of the jurisdiction rather than a transitional one, given the non-regression commitment is treaty-based rather than discretionary.
Technical teams building or integrating payment and virtual-asset transfer infrastructure for Gibraltar-regulated entities need to account for the single consolidated instrument covering both product categories at the information-accompaniment and verification layer.
Risk functions calibrating country risk models for Gibraltar-regulated entities should treat the Spain/Morocco high-risk categorisation as a fixed input rather than a variable subject to internal risk-based adjustment below the stated floor.
No material change for this persona this cycle
Audit functions testing control adequacy for Gibraltar-regulated entities should confirm retention practice aligns with both POCA section 25(3) and the newer Funds (Transfer) Regulations 2026 regulation 28 retention duty, which apply the same five-year standard across previously separate instruments.
Gibraltars SDD and PEP continuing-obligations rules carry specific divergences from UK practice that affect SAR-relevant risk-rating decisions.
The Funds (Transfer) Regulations 2026 reset Gibraltars travel-rule baseline for both fiat and virtual-asset transfers.
The UK-EU Gibraltar Agreements AML non-regression clause creates a binding external floor without EU market access, pending European Parliament consent.
Gibraltars hybrid compliance posture, UK-aligned drafting plus an EU-referenced AML floor without market access, is now a standing structural feature.
Gibraltars travel-rule regime now deems fiat-referenced e-money tokens to be virtual assets for transfer-regulation purposes.
Geographic risk-rating constraints for Spain and Morocco are structural, not discretionary, under Gibraltars NRA and POCA framework.
No material change for this persona this cycle.
Gibraltars five-year record-retention baseline now applies consistently across fiat CDD records and virtual-asset transfer records.
As the Anti-Money Laundering Authority established under Regulation (EU) 2024/1620 progressively assumes direct supervision of designated cross-border obliged entities and indirect oversight of national supervisors more broadly, the structural shift from a purely national to a hybrid EU-level supervisory model could, in illustration only, alter where cross-border groups choose to locate higher-risk business lines. A group with both EEA and non-EEA (including UK-aligned) touchpoints might, hypothetically, find that activity booked through entities outside the direct AMLA supervisory perimeter faces a different practical supervisory intensity than equivalent activity booked within it, even where both are nominally bound by comparable or non-regression-referenced standards. This is an illustrative structural mechanism only, not an observed development or a prediction of behaviour by any named firm or jurisdiction.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Sanctions Architecture and Evasion Tracker | stable | Gibraltar Sanctions Act 2019 consolidation to 9 Sep 2026 remains the standing instrument; no new developments this cycle. |
| T2 · EU AML Package Transposition Tracker | watch | Gibraltar is not an EEA member, so EU AML Package transposition is not directly applicable; however the UK-EU Gibraltar Agreement (signed 14 Jul 2026) imposes an AML non-regression obligation referencing AMLR/6AMLD/AMLA Regulation/Reg 2023/1113, pending European Parliament consent (indicative 14 Dec 2026). |
| T3 · Beneficial Ownership Registry Effectiveness Tracker | stable | No BO registry developments surfaced this cycle for Gibraltar. |
| T4 · Crypto / VASP Regulatory Framework Tracker | watch | Gibraltar's Funds (Transfer) Regulations 2026 bring VASP-inclusive travel-rule obligations into force from 15 Jul 2026, deeming fiat-referenced e-money tokens virtual assets for travel-rule purposes. |
| T5 · Enforcement Actions and Penalty Trends Tracker | no_change | No new Gibraltar enforcement actions evidenced this cycle. |
| T6 · Sanctions Regime Divergence Tracker | stable | No new sanctions-regime divergence signal for Gibraltar this cycle. |