Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Financial Integrity Monitor

Gibraltar GIB

Domains (D1–D6)
4
Sources
8
Role actions
8
Jurisdiction profile
CleanTier BRisk: DecreasingMixed

Gibraltar (British Overseas Territory) runs its own AML/CFT/CPF regime under the Proceeds of Crime Act 2015, Terrorism Act 2018 and Sanctions Act 2019, supervised by the GFSC and GFIU.

MoreIt was removed from FATF increased monitoring in Feb 2024 and the EU high-risk list in June 2025, but retains structural exposure via its offshore-facing insurance, gaming and DLT/crypto sectors and a historically porous Spain frontier.

Key deficiencies
  • Sanctions imposed by supervisors historically assessed as not proportionate or dissuasive across the majority of AML/CFT cases
  • Weak outgoing mutual legal assistance activity relative to Gibraltar's cross-border exposure to complex international ML cases
  • No PF-related targeted financial sanctions asset freezes have ever been executed, alongside low private-sector (especially DNFBP) awareness of proliferation-financing TFS obligations
  • Complex ownership structures and trusts remain a weak spot for beneficial-ownership identification among banks and some other reporting entities
Recent developments (18m)
  • FATF/MONEYVAL removed Gibraltar from the 'Jurisdictions under Increased Monitoring' grey list on 23 February 2024, with MONEYVAL closing further reporting after a follow-up re-rating exercise
  • European Commission delisted Gibraltar from the EU list of high-risk third countries for AML/CFT purposes on 10 June 2025
  • OFSI issued a wind-down General Licence (Feb 2026) for Maritime Mutual Association Limited ('Maritime Mutual Gibraltar'), a Gibraltar-domiciled marine insurer with Russia-sanctions exposure
  • UK-Gibraltar transitional financial-services market access arrangements extended by a further 12 months to 16 December 2026 pending finalisation of the long-term Gibraltar Authorisation Regime (GAR)
Brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Gibraltars anti-money-laundering architecture this cycle resolves into a clearer, more granular picture of how the Proceeds of Crime Act 2015 (POCA) actually constrains customer due diligence at the point where theory meets practice. The headline finding is structural rather than episodic: Gibraltar has no numerical electronic-money purse-limit derogation from simplified due diligence (SDD), and whatever SDD latitude section 16 of POCA otherwise allows is overridden by section 16(5) geographic-risk precedence under the 2025 National Risk Assessment (NRA v1.3). The practical effect is unambiguous. A regulated entity can never treat Spain as a Low Risk country, and no customer with a residency, nationality or economic-activity connection to Spain may be given SDD, regardless of product type or transaction value. Morocco sits under a parallel constraint, with funds from either jurisdiction required to be categorised as high risk and subjected to additional risk-based controls. This is not a blanket prohibition on serving Spain-connected customers, nor does it mandate automatic enhanced due diligence for every such relationship; it is a floor beneath which the risk rating cannot fall, which is a materially different and more precise instrument than either extreme would suggest.

The second pillar of this weeks lead signal is the commencement of the Funds (Transfer) Regulations 2026 (LN 2026/134) on 15 July 2026, which revokes the onshored text of Regulation (EU) 2015/847 and replaces it with a travel-rule regime that, notably, extends to virtual asset transfers. Payment service providers and virtual asset service providers alike must now attach originator and beneficiary information to transfers, verify that information before execution, and retain records for five years; a reduced-information threshold applies to unlinked transfers up to EUR 1,000 equivalent. This is an architecture-over-incident development in the fullest sense: it does not respond to a single enforcement failure but resets the entire information-accompaniment baseline for funds movement through Gibraltar, fiat and virtual alike.

Other Developments

The PEP continuing-obligations regime diverges from UK practice in a way firms applying UK Money Laundering Regulations logic to Gibraltar accounts could easily miss. Under POCA sections 20A, 20B and 20(2), the test for a politically exposed person is the prominent public function itself, with no foreign/domestic distinction, and once a PEP leaves office a Gibraltar relevant financial business must continue risk-sensitive measures for at least twelve months, a duty that extends to family members and known close associates as though they too were PEPs. UK treatment, by contrast, drops the family/associate extension once the PEP exits office. A firm porting UK PEP-exit logic onto a Gibraltar book of business would under-apply continuing obligations precisely where Gibraltar law requires more.

The UK-EU Agreement in respect of Gibraltar, signed 14 July 2026 and provisionally applied from the same date, inserts a non-regression commitment at Article 198(2): the UK, in respect of Gibraltar, must not weaken AML/CFT measures below the levels set out in the EU instruments listed at Annex 17, which include Directive 2015/849 as amended, the AML Regulation (2024/1624), the sixth AML Directive (2024/1640), the AMLA Regulation (2024/1620), and the funds-transfer Regulation (2023/1113). Critically, this commitment creates no EU market access or passporting right; it is a floor obligation without a corresponding single-market benefit, and European Parliament consent remains pending with an indicative plenary vote of 14 December 2026.

Risk ownership and CDD liability under POCA sections 9B, 10, 13, 15, 20 through 20B, 23 and 26 rests squarely with the Gibraltar legal entity providing the account; reliance on a third party for CDD measures does not discharge that liability, which remains with the relying Gibraltar firm under section 23. Where the entity in question is a Gibraltar branch of a UK company, the risk-owning legal person for UK Money Laundering Regulations purposes shifts to the UK parent under regulation 20, a distinction that matters for groups structuring cross-border compliance functions.

Cross-Monitor Connections

The Funds (Transfer) Regulations 2026 sit at a natural junction between this monitors AML/CTF reading and the digital-asset and payments architecture that World Payments Monitor and crypto-focused trackers follow separately: a single instrument now governs both fiat payment-service-provider transfers and virtual-asset-service-provider transfers under one travel-rule standard, with the same five-year retention and restrictive-measures-policy obligations applying across both rails. The UK-EU Agreements AML non-regression clause likewise connects to enabler-jurisdiction analysis elsewhere in the fleet: Gibraltar now carries an externally-imposed floor referencing the EU AML Package without the offsetting benefit of EU market access, a hybrid posture worth tracking alongside any state-capture or conflict-finance signal that touches UK-aligned offshore centres.

Outlook

The near-term question is less whether Gibraltars standing AML/CTF baseline will move and more whether the UK-EU Agreements non-regression commitment survives European Parliament consent as scheduled for 14 December 2026, and if so, how the Annex 17 reference list is monitored and updated as the underlying EU instruments themselves evolve. The Funds (Transfer) Regulations 2026 travel-rule baseline, now in force, positions Gibraltar ahead of many comparable small jurisdictions on VASP-inclusive information-accompaniment requirements; whether GFSC supervisory practice develops a track record of enforcement against that baseline, or whether the regime remains principally a statement of obligation absent observed enforcement activity, is itself an analytically significant question this monitor will continue to track.

weekly_brief_draft · JID GIB
Domain intelligence (D1–D6)

D1 Sanctions

Not covered

Sanctions is not yet covered for this jurisdiction in this report.

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

Gibraltar sits outside the EU AML Package direct perimeter, but a durable structural fact of that Package remains relevant backdrop for reading any beneficial-ownership and corporate-transparency signal touching UK-aligned offshore centres such as Gibraltar. Globally, the EU AML Package now comprises three distinct instruments: the AML Regulation (AMLR, Regulation (EU) 2024/1624), which is directly applicable across EU Member States without transposition; the sixth AML Directive (6AMLD, Directive (EU) 2024/1640), which each Member State transposes into its own domestic law; and the AMLA Regulation (Regulation (EU) 2024/1620), which establishes the Anti-Money Laundering Authority and shifts supervision of higher-risk cross-border obliged entities from purely national competent authorities toward a hybrid EU-level regime combining direct AMLA supervision of designated entities with indirect AMLA oversight of national supervisors generally. Gibraltar, not being an EEA member, has no direct transposition obligation under 6AMLD and no entities subject to direct AMLA supervision; its connection to this architecture runs instead through the UK-EU Agreement in respect of Gibraltar, under which the UK commits, in respect of Gibraltar, not to weaken AML/CFT measures below the levels set by the Annex 17 list of EU instruments, which names the AMLR, 6AMLD, the AMLA Regulation and the funds-transfer Regulation 2023/1113 specifically. This is a floor obligation, not a transposition duty, and it carries no corresponding EU market access or passporting benefit; European Parliament consent to the Agreement remains pending, with an indicative plenary vote of 14 December 2026.

Against that backdrop, the directly relevant beneficial-ownership and customer-transparency signal for Gibraltar this cycle concerns its politically-exposed-person regime, which operates as a proxy for broader beneficial-ownership risk sensitivity in practice. Under POCA sections 20A, 20B and 20(2), the PEP test turns on whether a natural person is or has been entrusted with a prominent public function, explicitly including heads of state, heads of government, ministers, and deputy or assistant ministers, while expressly excluding middle-ranking or more junior officials; there is no foreign-versus-domestic distinction, so EEA residence confers no concession equivalent to the UK domestic-PEP treatment. Once a PEP ceases to hold that prominent public function, a relevant financial business must, for at least twelve months, continue to take into account the continuing risk the person poses and apply appropriate and risk-sensitive measures until satisfied no further PEP-specific risk remains. Section 20(2) extends this entire regime, including the twelve-month continuing-obligation period, to family members and persons known to be close associates of PEPs as though those persons were themselves PEPs. This is a materially stricter position than the UK Money Laundering Regulations, which drop the family/associate extension once the PEP leaves office; a group applying UK PEP-exit logic mechanically to its Gibraltar-regulated entities would under-apply the continuing obligation precisely where Gibraltar law demands more scrutiny, not less.

Outlook

The PEP continuing-obligations divergence from UK practice is likely to remain a live compliance-trap vector for cross-border groups rather than a one-off finding, given how naturally UK and Gibraltar AML policies get drafted from shared templates. On the broader architecture, the open question is whether the UK-EU Agreements Annex 17 non-regression list is read as a static snapshot of the AML Package as it stood at provisional application, or as a dynamic reference that tracks future amendments to the AMLR, 6AMLD and AMLA Regulation as the EU-level supervisory architecture matures; that question will likely sharpen once European Parliament consent is resolved around the indicative December 2026 timeline.

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

Gibraltars standing as a UK-aligned enabler jurisdiction gained a new and somewhat paradoxical external constraint this cycle: an AML/CFT non-regression commitment anchored in EU law, arriving without any accompanying EU market-access benefit. The UK-EU Agreement in respect of Gibraltar was signed on 14 July 2026 and provisionally applied from the same date under Article 336(4). Article 198(2) of that Agreement states the objective plainly: to support and strengthen action by the Union and by the United Kingdom, in respect of Gibraltar, to prevent and combat money laundering and terrorist financing, and specifically commits that the United Kingdom, in respect of Gibraltar, shall not weaken or reduce its anti-money-laundering and terrorist-financing measures below the levels set out in the Union acts listed in Annex 17, in force at the date of entry into force of the Agreement. Annex 17 names Directive (EU) 2015/849 as amended, the AML Regulation (2024/1624), the sixth AML Directive (2024/1640), the AMLA Regulation (2024/1620) establishing the Anti-Money Laundering Authority, and the funds-transfer Regulation (2023/1113).

The architectural significance of this arrangement is that it creates a floor without a ceiling benefit: Gibraltar is bound to maintain AML/CFT standards referencing an EU instrument set it has no vote in amending and no corresponding passporting right to exploit, a position distinct from both full EU membership and from a jurisdiction with no EU-referenced AML commitment at all. This is precisely the kind of structural finding this framework privileges over single-incident analysis: it is not a response to a specific enforcement failure or designation, but a standing treaty-level commitment reshaping the external reference points against which Gibraltars domestic AML drafting will be measured going forward. European Parliament consent to the Agreement remains pending, with an indicative plenary vote scheduled for 14 December 2026, meaning the Agreements full legal status, and by extension the binding force of the Article 198(2) commitment, carries a degree of procedural uncertainty that a reader should track rather than assume resolved.

This non-regression commitment should also be read alongside the absence, this cycle, of any new sanctions-architecture or sanctions-divergence development: Gibraltars Sanctions Act 2019, consolidated to 9 September 2026, continues to function as the domestic implementing framework without structural change, meaning the UK-EU Agreements AML-specific non-regression clause is, for now, the dominant enabler-jurisdiction signal rather than one strand among several moving in parallel.

Outlook

The principal forward-looking question for Gibraltars enabler-jurisdiction profile is whether European Parliament consent to the UK-EU Agreement proceeds on the indicative 14 December 2026 timeline, and if so, how UK domestic implementation translates the Article 198(2) non-regression duty into enforceable Gibraltar-facing supervisory expectations, given that Annex 17 references instruments (the AMLR, 6AMLD and AMLA Regulation) that are themselves still in their early implementation phase across the EU. A jurisdiction bound to a moving external reference point, without a vote in how that reference point moves, is a structural position worth continued attention independent of any single enforcement event.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

Gibraltars own crypto and virtual-asset AML perimeter was materially reshaped this cycle, directly within Gibraltars own regulatory architecture rather than as a derivative of any global standard-setting exercise. The Funds (Transfer) Regulations 2026 (LN 2026/134) commenced 15 July 2026 and revoke, in full, the onshored text of Regulation (EU) 2015/847 together with the prior Proceeds of Crime Act 2015 (Transfer of Virtual Assets) provisions that had governed virtual-asset transfer information requirements. In their place, the new Regulations establish a single travel-rule baseline covering both fiat payment-service-provider transfers and virtual-asset-service-provider transfers. Regulations 6 and 8 require payer and payee information, including name and payment account number, to accompany transfers and to be verified before execution; regulation 25 requires payment service providers and virtual asset service providers alike to maintain internal policies, procedures and controls to implement restrictive measures when performing transfers of funds and virtual assets; and regulation 28 imposes a five-year record-retention obligation on originator and beneficiary information for virtual-asset-service-provider transfers specifically, mirroring the retention standard applied to fiat transfers. A reduced-information carve-out applies where all payment service providers in a transfer chain are established in Gibraltar and the transfer falls within the unlinked, lower-value category.

The structural significance of this instrument is that it deems fiat-referenced e-money tokens to be virtual assets for its own purposes, closing what might otherwise have been a product-classification gap between e-money regulation and virtual-asset regulation at the travel-rule layer specifically. This positions Gibraltars VASP-inclusive travel-rule coverage ahead of many comparably sized jurisdictions that have not yet extended fiat transfer-regulation architecture to cover virtual-asset transfers on an equivalent informational footing. It is also a clean illustration of architecture over incident: the change responds to no single enforcement failure in the virtual-asset space but instead resets the entire information-accompaniment and record-retention baseline for a product category, fiat-referenced e-money tokens, that sits at the boundary between traditional payments regulation and crypto-asset regulation.

The revocation of the prior Transfer of Virtual Assets provisions under POCA, alongside the onshored EU Funds Transfer Regulation, also simplifies Gibraltars legal architecture in this space: rather than maintaining two parallel instruments for fiat and virtual-asset transfers, Gibraltar now operates a single consolidated regime, which is itself a structural simplification worth noting independent of the substantive obligations it imposes.

Outlook

The open question for this domain is less about the substance of the new travel-rule baseline, which is now in force and reasonably detailed, and more about how GFSC supervisory practice will evidence compliance with the virtual-asset-specific obligations, particularly the restrictive-measures policy requirement under regulation 25 and the five-year retention duty under regulation 28, given that no enforcement record yet exists against this specific instrument. Whether the deeming of fiat-referenced e-money tokens as virtual assets for travel-rule purposes is extended, by future amendment or guidance, into other areas of Gibraltars financial-services regulatory architecture is also worth tracking as a potential template for how the jurisdiction treats boundary-category digital-asset products more broadly.

D6 Compliance Technology & Active Defence

Not covered

Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.

D7 AML/CTF Regime

AML/CTF Regime

Continue reading

Gibraltars AML/CTF regime rests on the Proceeds of Crime Act 2015 (POCA), as amended, and is supplemented by Gibraltar Financial Services Commission (GFSC) guidance notes covering customer due diligence, customer risk assessment, and ongoing monitoring. The regime places the customer due diligence and enhanced due diligence decision, and the risk attaching to it, on the Gibraltar legal entity itself: under POCA sections 9B, 10, 13, 15, 20 through 20B, 23 and 26, a relevant financial business must appoint a director, senior manager or partner with the duty of ensuring compliance, and where that business relies on a third party to apply customer due diligence measures, section 23 provides that the relying Gibraltar firm remains liable for any failure in those measures notwithstanding the reliance; subsection (1A) confirms this is not to be construed as permitting reliance on a third party of a kind that would defeat this liability rule. Where the Gibraltar entity in question is a branch of a UK company rather than a Gibraltar-incorporated entity in its own right, the risk-owning legal person shifts to the UK parent company under the UK Money Laundering Regulations 2017, regulation 20, a distinction that matters for groups operating both structures.

Simplified due diligence under section 16 and Schedule 6 is available in principle but is structurally constrained by geographic risk factors identified in the 2025 National Risk Assessment (NRA v1.3): a regulated entity can never treat the country risk of Spain as Low Risk, and no customer with a residency, nationality or economic-activity connection to Spain may be given simplified due diligence; funds received from either Spain or Morocco must be categorised as high risk and subjected to additional risk-based controls under each entitys risk-based approach. There is no fixed numerical purse-limit derogation permitting simplified due diligence for products such as certain electronic money by reference to transaction value alone; the geographic-risk constraint takes precedence over any such product-based carve-out. Where a customer has not been physically present for identification purposes, section 18 requires a relevant financial business to take specific and adequate measures to compensate for the higher risk this presents, for example through additional documentary verification, certification of documents by an appropriate person, or requiring the first payment to be carried out through an account opened in the customers name at a credit institution.

Ongoing monitoring obligations under sections 12, 17(3) and 10(ca) require relevant financial businesses to scrutinise transactions throughout a business relationship to ensure consistency with the businesss own knowledge of the customer and the customers risk profile, with particular attention to transactions that are unusually large, conducted in an unusual pattern, or lack an apparent economic or lawful purpose; monitoring obligations are enhanced where the customer is a politically exposed person. A statutory sanctions check obligation sits alongside this monitoring duty at section 10(ca). Tipping-off provisions at sections 5 and 11(5) and (5A) make it an offence for a person to disclose matters that would prejudice an investigation where the information disclosing that matter came to the person in the course of a business or activity covered by the Act. Where a relevant financial business is unable to apply the required customer due diligence measures, it must not carry out a transaction with or for the customer through a bank account and must not establish a business relationship or carry out an occasional transaction with that customer. Records, including copies of customer due diligence documentation and transaction records, must be retained for a period of five years beginning on the date an occasional transaction is completed or the date the business relationship ends, after which personal data must be deleted unless retention is required by another enactment or the Minister has by order provided for its continued retention.

Outlook

As this is the first cycle in which Gibraltars standing AML/CTF baseline under POCA has been collected and set out in this detail, the immediate point of continuity to track is how this baseline interacts with the newly in-force Funds (Transfer) Regulations 2026 travel-rule regime and with the UK-EU Agreements AML non-regression commitment, both of which layer additional obligations onto the same underlying customer due diligence and ongoing monitoring architecture described above.

D8 Commercial Activity

Not covered

Commercial Activity is not yet covered for this jurisdiction in this report.

Regulatory horizon
No dated horizon items this cycle. 3 items tracked without a confirmed date.
3 pending date · baseline fim-2026-07-05
Role action cards
MLRO

Gibraltars SDD and PEP continuing-obligations rules carry specific divergences from UK practice that affect SAR-relevant risk-rating decisions.

The geographic-risk precedence barring Low Risk ratings and SDD for Spain-connected customers, and the twelve-month PEP continuing-obligation period extending to family and associates, both bear directly on how an MLRO sets ongoing risk ratings and monitoring intensity for Gibraltar-regulated books.

3 evidence refs
Compliance

The Funds (Transfer) Regulations 2026 reset Gibraltars travel-rule baseline for both fiat and virtual-asset transfers.

Compliance functions overseeing payment or VASP operations in Gibraltar now operate under a single consolidated travel-rule instrument with new verification, policy and five-year retention duties in force from 15 July 2026.

1 evidence refs
Legal

The UK-EU Gibraltar Agreements AML non-regression clause creates a binding external floor without EU market access, pending European Parliament consent.

Legal counsel advising on Gibraltar-linked structures should note the Agreements Article 198(2) commitment references a specific and evolving EU instrument list (Annex 17) while conferring no passporting right, and its final legal status remains contingent on European Parliament consent indicatively expected 14 December 2026.

1 evidence refs
Board

Gibraltars hybrid compliance posture, UK-aligned drafting plus an EU-referenced AML floor without market access, is now a standing structural feature.

Board-level oversight of Gibraltar-linked operations should treat this hybrid posture as a durable characteristic of the jurisdiction rather than a transitional one, given the non-regression commitment is treaty-based rather than discretionary.

1 evidence refs
CTO

Gibraltars travel-rule regime now deems fiat-referenced e-money tokens to be virtual assets for transfer-regulation purposes.

Technical teams building or integrating payment and virtual-asset transfer infrastructure for Gibraltar-regulated entities need to account for the single consolidated instrument covering both product categories at the information-accompaniment and verification layer.

1 evidence refs
Risk

Geographic risk-rating constraints for Spain and Morocco are structural, not discretionary, under Gibraltars NRA and POCA framework.

Risk functions calibrating country risk models for Gibraltar-regulated entities should treat the Spain/Morocco high-risk categorisation as a fixed input rather than a variable subject to internal risk-based adjustment below the stated floor.

1 evidence refs
Operations

No material change for this persona this cycle.

No material change for this persona this cycle

Audit

Gibraltars five-year record-retention baseline now applies consistently across fiat CDD records and virtual-asset transfer records.

Audit functions testing control adequacy for Gibraltar-regulated entities should confirm retention practice aligns with both POCA section 25(3) and the newer Funds (Transfer) Regulations 2026 regulation 28 retention duty, which apply the same five-year standard across previously separate instruments.

2 evidence refs
Decision lens
MLRO

Gibraltars SDD and PEP continuing-obligations rules carry specific divergences from UK practice that affect SAR-relevant risk-rating decisions.

Compliance

The Funds (Transfer) Regulations 2026 reset Gibraltars travel-rule baseline for both fiat and virtual-asset transfers.

Legal

The UK-EU Gibraltar Agreements AML non-regression clause creates a binding external floor without EU market access, pending European Parliament consent.

Board

Gibraltars hybrid compliance posture, UK-aligned drafting plus an EU-referenced AML floor without market access, is now a standing structural feature.

CTO

Gibraltars travel-rule regime now deems fiat-referenced e-money tokens to be virtual assets for transfer-regulation purposes.

Risk

Geographic risk-rating constraints for Spain and Morocco are structural, not discretionary, under Gibraltars NRA and POCA framework.

Operations

No material change for this persona this cycle.

Audit

Gibraltars five-year record-retention baseline now applies consistently across fiat CDD records and virtual-asset transfer records.

Shared evidence: 2 refs
Scenario sketches

Illustrative AMLA transition and cross-border supervisory arbitrage

As the Anti-Money Laundering Authority established under Regulation (EU) 2024/1620 progressively assumes direct supervision of designated cross-border obliged entities and indirect oversight of national supervisors more broadly, the structural shift from a purely national to a hybrid EU-level supervisory model could, in illustration only, alter where cross-border groups choose to locate higher-risk business lines. A group with both EEA and non-EEA (including UK-aligned) touchpoints might, hypothetically, find that activity booked through entities outside the direct AMLA supervisory perimeter faces a different practical supervisory intensity than equivalent activity booked within it, even where both are nominally bound by comparable or non-regression-referenced standards. This is an illustrative structural mechanism only, not an observed development or a prediction of behaviour by any named firm or jurisdiction.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Sanctions Architecture and Evasion TrackerstableGibraltar Sanctions Act 2019 consolidation to 9 Sep 2026 remains the standing instrument; no new developments this cycle.
T2 · EU AML Package Transposition TrackerwatchGibraltar is not an EEA member, so EU AML Package transposition is not directly applicable; however the UK-EU Gibraltar Agreement (signed 14 Jul 2026) imposes an AML non-regression obligation referencing AMLR/6AMLD/AMLA Regulation/Reg 2023/1113, pending European Parliament consent (indicative 14 Dec 2026).
T3 · Beneficial Ownership Registry Effectiveness TrackerstableNo BO registry developments surfaced this cycle for Gibraltar.
T4 · Crypto / VASP Regulatory Framework TrackerwatchGibraltar's Funds (Transfer) Regulations 2026 bring VASP-inclusive travel-rule obligations into force from 15 Jul 2026, deeming fiat-referenced e-money tokens virtual assets for travel-rule purposes.
T5 · Enforcement Actions and Penalty Trends Trackerno_changeNo new Gibraltar enforcement actions evidenced this cycle.
T6 · Sanctions Regime Divergence TrackerstableNo new sanctions-regime divergence signal for Gibraltar this cycle.
Registers

Enforcement actions

  • FATF announced that Gibraltar, alongside Barbados, Uganda and the UAE, was no longer subject to increased monitoring, reflecting completion of its post-2019 MER action plan on technical compliance and effectiveness improvements. 23 Feb 2024
  • MONEYVAL's enhanced follow-up report re-rated Gibraltar's technical compliance on Recommendation 36 from Partially Compliant to Largely Compliant, confirming all 40 FATF Recommendations at LC/C level (22 Compliant, 18 Largely Compliant) and closing the jurisdiction's obligation to report further under the current evaluation round. 1 Dec 2024
  • The European Commission updated its delegated regulation listing AML/CFT high-risk third countries, delisting Gibraltar (together with Barbados, Jamaica, Panama, the Philippines, Senegal, Uganda and the UAE) following a technical assessment incorporating FATF findings and bilateral dialogue. 10 Jun 2025
  • OFSI issued General Licence INT/2026/8893924 permitting the orderly wind-down of insurance policies written by Maritime Mutual Gibraltar and its subsidiaries under the Russia (Sanctions) (EU Exit) Regulations 2019, addressing designated-person exposure in the Gibraltar-domiciled marine insurer's book. 24 Feb 2026

Sanctions changes

  • OFSI General Licence INT/2026/8893924 authorised wind-down of Maritime Mutual Gibraltar insurance policies affected by Russia sanctions designations, permitting an orderly unwind rather than abrupt policy termination. 24 Feb 2026
  • European Commission delegated regulation removed Gibraltar from the EU list of AML/CFT high-risk third countries requiring mandatory enhanced due diligence by EU obliged entities. 10 Jun 2025
  • Structural point confirmed via UK secondary legislation: all British Overseas Territories except Bermuda and Gibraltar have UK Russia sanctions extended to them via the Russia (Sanctions) (Overseas Territories) Order 2020; Gibraltar and Bermuda instead implement sanctions under their own domestic legislative arrangements (Gibraltar's Sanctions Act 2019), meaning designation timing, licensing and enforcement in Gibraltar run on a jurisdiction-specific track rather than automatic extension of UK statutory instruments. 17 Apr 2024

Regulatory horizon (register)

  • Next MONEYVAL/FATF mutual evaluation of Gibraltar (5th round)
  • Expiry of UK-Gibraltar transitional financial-services market access arrangements
  • GFSC alignment with new FATF offshore-VASP and stablecoin guidance

Active schemes

  • [HIGH] Gibraltar-domiciled marine insurance wind-down for Russia-exposed vessels
  • Cross-frontier tobacco smuggling and cash-intensive laundering
  • Gibraltar DLT/virtual-asset licensing as light-touch crypto hub
  • Trust and complex-ownership structuring via Gibraltar TCSPs
Sources
  1. HM Government of Gibraltar
  2. FATF/MONEYVAL
  3. FATF
  4. European Commission
  5. OFSI / HM Treasury
  6. UK Government (legislation.gov.uk)
  7. Elliptic
  8. UK Government (legislation.gov.uk)
Coverage gaps
MONEYVAL's assessment found that in the majority of cases, s…
MONEYVAL's assessment found that in the majority of cases, sanctions imposed by Gibraltar's supervisory authorities for AML/CFT breaches were not proportionate or dissuasive, undermining the deterrent effect of an otherwise technically-compliant framework.
Assessors found no evidence that Gibraltar has ever frozen a…
Assessors found no evidence that Gibraltar has ever frozen assets or transactions as a result of proliferation-financing targeted financial sanctions, and private-sector (particularly DNFBP) awareness of PF-TFS obligations was assessed as low compared to terrorist-financing TFS awareness.
Gibraltar authorities were found to make a low number of out…
Gibraltar authorities were found to make a low number of outgoing mutual legal assistance requests relative to the cross-border, complex nature of the proceeds of crime affecting the jurisdiction, raising doubts about proactive pursuit of foreign-predicate asset recovery.
Publicly surfaced material on GFSC-specific enforcement acti…
Publicly surfaced material on GFSC-specific enforcement actions (fines, licence revocations) against individual regulated firms within the last 18 months is thin in open-source reporting; the GFSC does not appear to maintain as visible a public enforcement-notices archive as comparator regulators (e.g. Guernsey FSC), limiting independent verification of granular supervisory outcomes for this baseline.

Evidence

Confidence-tiered claims

No numerical e-money derogation exists; SDD under s.16 is constrained by s.16(5) NRA geographic precedence, barring SDD for customers connected to Spain. SRC-financial-integrity-GI-MDR-001
Confirmed · 1 source
Spain can never be rated Low and no Spain-connected customer may receive SDD; Morocco may not be rated Low; funds from Spain or Morocco must be categorised as high risk subject to additional risk-based controls. SRC-financial-integrity-GI-MDR-002
Confirmed · 1 source
Compensating measures mandatory where customer not physically present, e.g. additional documents, certification, or first payment through an account in the customer's name at a credit institution. SRC-financial-integrity-GI-MDR-004
Probable · 1 source
Five years record retention covering CDD copies including eID data and transaction records. SRC-financial-integrity-GI-MDR-005
Probable · 1 source
The Gibraltar legal entity providing an account owns the AML risk and CDD/EDD decision; reliance on a third party leaves the Gibraltar firm liable (s.23). A Gibraltar branch of a UK company has the UK company as the risk-owning legal person under UK MLRs reg 20. SRC-financial-integrity-GI-MDR-012
Probable · 1 source
The PEP test is the prominent public function, not residence; no foreign/domestic distinction; middle-ranking and junior officials excluded; every PEP relationship treated as higher risk regardless of EEA residence. SRC-financial-integrity-GI-MDR-016
Probable · 1 source
Commencing 15 Jul 2026, revokes onshored Regulation (EU) 2015/847; regs 6/8 require payer/payee details, verification before execution; unlinked transfers up to EUR 1,000 equivalent carry reduced info; reg 25 requires policies for restrictive measures; reg 28 requires 5-year record retention. SRC-financial-integrity-GI-MDR-019
Confirmed · 1 source
Art 198(2): UK, in respect of Gibraltar, must not weaken AML/CFT measures below Annex 17 Union acts in force at entry into force (provisional application date under art 336(4)). Annex 17 lists Directive 2015/849 as amended, AMLR 2024/1624, AMLD6 2024/1640, AMLA Regulation 2024/1620, Regulation 2023/1113. No EU market access/passport created. European Parliament consent pending (indicative plenary 14 Dec 2026). SRC-financial-integrity-GI-MDR-025
Probable · 1 source
Where a PEP leaves office, firm must for at least 12 months apply risk-sensitive measures until deemed no further PEP risk; s.20(2) extends s.20B to family members and known close associates as though themselves PEPs (unlike UK, which drops family/associates when the PEP leaves office). SRC-financial-integrity-GI-MDR-035
Probable · 1 source
Ongoing monitoring requires scrutiny of transactions against knowledge of customer, business and risk profile; PEP monitoring enhanced (s.20(1)(c)); s.17(3) requires examination of complex/unusually large/unusual-pattern/no-apparent-purpose transactions; statutory sanctions check at s.10(ca); tipping-off duties at ss.5 and 11(5)/(5A). SRC-financial-integrity-GI-MDR-039
Probable · 1 source