D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.
Ireland's AML/CFT regime rests on the Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010-2021 (5AMLD-transposing), with the Central Bank of Ireland as lead AML/CFT supervisor for financial institutions and VASPs, the FIU embedded in the Garda National Economic Crime Bureau, and the CRO/RBO handling corporate and beneficial-ownership registration.
Law made at European Economic Area level that applies in Ireland is covered once, on the European Economic Area page. This page covers Ireland’s own layer: implementation, national authorities, national options and local enforcement.
Sanctions is not yet covered for this jurisdiction in this report.
The durable architectural backdrop against which any EU member state's beneficial-ownership regime is read is the three-instrument EU AML Package: the AML Regulation, known as the AMLR (Regulation (EU) 2024/1624), which is directly applicable without domestic transposition; the sixth AML Directive, known as 6AMLD, which each member state transposes into its own law; and the AMLA Regulation (Regulation (EU) 2024/1620), which establishes the Anti-Money Laundering Authority and shifts the supervisory perimeter from a purely national model toward a hybrid regime in which AMLA exercises direct or indirect supervision over certain obliged entities. No AMLA horizon anchors were surfaced in the research this cycle for Ireland specifically, so this paragraph states the architecture from standing context rather than from a fresh Irish development, and the domain sub-brief below is flagged for limited signal accordingly.
Against that backdrop, Ireland's own confirmed beneficial-ownership obligation this cycle sits in CJA 2010 s.35(3A)-(3D): before establishing a business relationship with a customer to which the European Union (Anti-Money Laundering: Beneficial Ownership of Trusts) Regulations 2021 apply, a designated person must ascertain that the beneficial ownership of the relevant trust is entered either in the trust's own beneficial ownership register or in the Central Register of Beneficial Ownership. This is a precondition-to-relationship obligation rather than an ongoing-monitoring one, and it sits squarely within the AMLR/6AMLD/AMLA architecture described above as the kind of national implementing detail that the EU package is designed to harmonise over time.
What is not yet settled is the amendment history behind that obligation. Secondary commentary, specifically from a professional-services source rather than a primary legal instrument, indicates that the Irish trust-register regime may have been amended by S.I. 440/2025 and S.I. 335/2026, but the primary statutory text of those instruments was not retrieved this cycle. That leaves open the practical question of whether the register-check mechanic described above, access to the trust register itself, or the register's relationship to the Central Register of Beneficial Ownership, has changed since the 1 August 2025 consolidation date that the reviewed text carries. Until that is resolved against primary sources, the finding is recorded at Probable confidence rather than Confirmed, and the register-access architecture should be treated as a known gap rather than a stable fact.
The practical next step for closing this gap is retrieval of the primary text of S.I. 440/2025 and S.I. 335/2026 against the CJA 2010 s.35 register-check mechanic, which would allow the current Probable-confidence finding to be either confirmed or revised. Separately, as the AMLA direct/indirect supervision perimeter continues to take shape at the EU level, Ireland's own beneficial-ownership verification architecture is a candidate area to watch for alignment pressure, though no Irish-specific AMLA development was identified this cycle and none should be inferred from the standing architecture alone.
Ireland's third-party reliance regime under CJA 2010 s.40 defines, and limits, who a designated person may rely on to carry out customer due diligence on its behalf, and that boundary is the operative enabler-jurisdiction question this cycle rather than any single enforcement episode. Reliance is restricted to a defined category of relevant third parties, namely qualifying credit or financial institutions and listed professionals; it expressly does not extend to undertakings that qualify as financial institutions solely because they provide foreign-exchange or payment services. That exclusion is structurally significant for payment and e-money sector due diligence chains, since it means a designated person cannot treat a foreign-exchange or payment-services-only counterparty as a reliance-eligible third party in the way it could a credit institution.
The reliance concept, where it does apply, covers the CDD measures under s.33 and the identification measures under s.35(1), but it does not extend to the ongoing monitoring obligation under s.35(3); that monitoring duty remains with the designated person regardless of any reliance arrangement. Documents obtained by the relied-upon third party are to be forwarded to the designated person as soon as practicable after a request is made, which is a timing obligation rather than a standing-access one. Separately, and importantly for outsourcing structures common in the payments and e-money sector, outsourcing providers and agents engaged under s.40(6)-(7) fall entirely outside the reliance concept: the designated person, which can include an electronic-money institution, remains liable for the outsourced function regardless of the arrangement in place with the provider or agent.
This cycle's reading of s.40 carries a research-currency caveat that is itself part of the enabler-jurisdiction picture: no verbatim quoted text was admitted for this section, so the above is recorded as an open finding pending primary-source confirmation rather than a settled statutory reading. The practical implication is that firms relying on cross-border intermediaries or professional facilitators to discharge CDD obligations operate against a reliance boundary that is probable rather than fully confirmed in its current form, and that boundary matters disproportionately for sectors, such as payment institutions and crypto-asset operators, that routinely depend on intermediary or outsourced arrangements to onboard customers.
The open item to track is primary-source confirmation of the s.40 reliance scope, particularly the precise boundary between the professional-facilitator reliance concept and the outsourcing/agency relationship under s.40(6)-(7), since firms in the payment and e-money sector sit close to that boundary by business model. Until that confirmation is obtained, Ireland's enabler-jurisdiction profile on this specific point should be read as probable rather than confirmed, with the underlying liability allocation, namely that the designated person remains liable for outsourced functions, treated as the more load-bearing fact regardless of how the reliance-scope question resolves.
Conflict Finance is not yet covered for this jurisdiction in this report.
Crypto / Digital Assets / Financial Innovation is not yet covered for this jurisdiction in this report.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
Ireland's AML/CTF regime recorded one confirmed, structurally significant movement this cycle and several standing provisions whose currency needs a primary-source refresh. The confirmed movement is the EU Commission's addition of Russia to the high-risk third-country list, with effect from 29 January 2026, alongside Bolivia and the British Virgin Islands, via Delegated Regulations 2026/46 and 2026/83. Because Ireland applies that list directly through CJA 2010 s.38A, the addition is self-executing domestically: Irish designated persons must now apply the additional enhanced due diligence measures under s.38A to customers connected to Russia without any intervening Irish legislative step. In FIM designation terms this is Enhanced due diligence, distinct from the EU's separate list of high-risk third countries used elsewhere and distinct from any FATF grey-list or call-for-action designation, which are tracked and dated independently.
The electronic-money CDD derogation under s.33A continues to set a narrow, cumulative set of conditions before a designated person may dispense with standard due diligence for an e-money instrument: non-reloadable status, or Ireland-only use with a maximum monthly load of one hundred fifty euro; a stored-value cap of one hundred fifty euro; restriction to goods and services; no anonymous funding; ongoing monitoring; and caps of fifty euro on both cash redemption and remote payment. Critically, this derogation does not apply where the customer is connected to a high-risk third country under s.38A or is a politically exposed person under s.37, which means the Russia designation discussed above directly narrows the population of customers for whom the e-money derogation remains available. The text underpinning this reading is consolidated only to 1 August 2025, and later instruments, S.I. 307/2026 and S.I. 335/2026, have not yet been checked against it, so this finding sits at Probable rather than Confirmed confidence.
Record-keeping under s.55 remains a standing, unchanged obligation: a minimum five-year retention period following cessation of service or the last transaction, extendable by further direction of the Garda Siochana. This is a Confirmed, stable finding that bears on any cross-jurisdictional comparison of AML record-retention regimes, including comparison against the UK's own retention framework.
The structurally important fact to carry forward is that Ireland's s.38A mechanism means future EU Commission delegated-regulation activity on the high-risk third-country list will continue to have immediate, automatic domestic effect, making the EU delegated-act calendar itself the thing to monitor rather than any Irish implementing step. In parallel, resolving the post-1 August 2025 amendment picture for s.33A against S.I. 307/2026 and S.I. 335/2026 is the clearest path to moving this cycle's Probable-confidence findings to Confirmed.
Commercial Activity is not yet covered for this jurisdiction in this report.
Any customer relationship connected to Russia, Bolivia, or the British Virgin Islands now falls within the mandatory CJA 2010 s.38A enhanced due diligence regime, and the electronic-money CDD derogation under s.33A is unavailable for those customers regardless of how low-value the instrument otherwise appears.
Policies built on the s.33A e-money derogation, the s.35 beneficial-ownership register check, and the s.40 third-party reliance scope should be reviewed once S.I. 307/2026, S.I. 335/2026, and S.I. 440/2025 are confirmed against primary text, since the current consolidation reviewed predates those instruments.
No material change for this persona this cycle
Board-level risk appetite discussions on Russia-connected or other high-risk-third-country exposure should account for the fact that future EU Commission delegated-regulation changes to the list will take effect in Ireland automatically, with no opportunity for a domestic consultation period.
No material change for this persona this cycle
Risk exposure concentrated in onboarding chains that depend on foreign-exchange or payment-services-only intermediaries should be reassessed, since those intermediaries cannot be treated as reliance-eligible third parties under s.40, and the designated person remains liable for any outsourced due diligence function regardless of arrangement.
No material change for this persona this cycle
Audit trail adequacy reviews can continue to anchor on the confirmed five-year minimum retention period running from cessation of service or last transaction, with awareness that this period may be extended by Garda direction in specific cases.
Russia's addition to the EU high-risk third-country list triggers mandatory enhanced due diligence for connected Irish customers from 29 January 2026.
Several standing CDD and reliance provisions carry a documented research-currency gap pending primary-source confirmation of 2025-2026 amendments.
No material change this cycle.
Ireland's statute-driven uptake of EU high-risk third-country designations means EU-level rulemaking has immediate domestic effect without Irish legislative intervention.
No material change this cycle.
The s.40 third-party reliance boundary excludes foreign-exchange-only and payment-services-only entities from reliance-eligible status.
No material change this cycle.
Record-retention obligations under s.55 remain a stable, confirmed five-year minimum, extendable on Garda direction.
As an illustrative orientation only, consider how the shift from purely national AML supervision toward AMLA direct or indirect supervision of cross-border obliged entities, operating alongside the directly-applicable AMLR and the per-member-state transposition of 6AMLD, could reshape both the supervisory and the evasion landscape over time. A structural move of this kind could, illustratively, concentrate supervisory attention on entities that operate across multiple member states while leaving purely domestic obliged entities under national supervision for longer, creating a temporary two-track system during the transition. Illegitimate actors seeking to exploit supervisory handover periods might, illustratively, be drawn toward jurisdictions or entity structures where the national-to-AMLA transition timeline is least clear, though this is a structural possibility to orient analysis, not an observed pattern in any specific jurisdiction.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Sanctions Architecture and Evasion Tracking | stable | |
| T2 · EU AML Package Implementation Tracker | stable | No new EEA/EU AML Package development surfaced for Ireland this cycle (delta-only DR posture against EEA parent layer). |
| T3 · Enabler Jurisdiction Dynamics | stable | |
| T4 · Crypto / VASP Regulatory Framework | stable | |
| T5 · Compliance Technology and Active Defence | stable | |
| T6 · Sanctions Regime Divergence | stable | EU high-risk third-country list update (Russia added, in force 29 January 2026) applies in Ireland via CJA 2010 s.38A; divergent from UK reg. 33(1)(b) treatment. |