Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Financial Integrity Monitor

Lithuania LT

Domains (D1–D6)
1
Sources
12
Role actions
8
Jurisdiction profile
Largely CompliantTier BRisk: StableMixed

Lithuania applies the EU AML/CFT acquis (AMLD transposition, forthcoming AMLR/6AMLD) via the Law on Prevention of Money Laundering and Terrorist Financing, supervised by the Financial Crime Investigation Service (FNTT/FCIS) and the Bank of Lithuania for financial/EMI/crypto obliged entities.

MoreA fast-growing EMI and VASP licensing hub has produced recurring supervisory failures alongside genuine enforcement escalation and EU-funded institutional reform.

Key deficiencies
  • Beneficial ownership register not publicly accessible (legitimate-interest access only, post-2022 CJEU ruling)
  • FATF Recommendations 6, 7 and 28 (targeted financial sanctions for TF/PF; DNFBP supervision) remain rated Partially Compliant
  • No registration framework for accountants and real estate agents as DNFBPs; low STR filing from notaries, CSPs, MVTS and real estate agents
  • Recurring AML/CFT control failures inside licensed EMI and crypto-asset firms despite a fast-expanding fintech sector
Recent developments (18m)
  • OLAF-supported Lithuanian Customs raid (April 2025) on a company rerouting sanctioned EU-origin goods to Russia/Belarus via Central Asia
  • Lithuanian customs disclosed refusal of 28,854 sanctioned-goods export requests exploiting a 'medical exemption' loophole (reported June 2025)
  • Bank of Lithuania fined Pervesk UAB (Bankera-linked) €130,000 for AML/CFT control failures, with heightened supervision imposed (2025)
  • EU broadened the Belarus sanctions regime (December 2025) explicitly citing meteorological-balloon airspace incursions into Lithuania
  • MONEYVAL enhanced follow-up report (December 2024) upgraded Recommendation 2 to Compliant; Recommendations 6, 7, 28 remained Partially Compliant

Law made at European Economic Area level that applies in Lithuania is covered once, on the European Economic Area page. This page covers Lithuania’s own layer: implementation, national authorities, national options and local enforcement.

Brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Lithuania's anti-money-laundering framework illustrates, this cycle, a structural feature of EU-member regimes that is easy to overlook when attention is fixed on domestic legislative calendars: the enhanced due diligence perimeter can expand without any domestic legislative act at all. The Law on the Prevention of Money Laundering and Terrorist Financing (No VIII-275), in its article 14(1)(3), requires enhanced due diligence toward customers and beneficial owners connected to jurisdictions named on the European Commission high-risk third-country list, and because that reference is a live incorporation rather than a fixed schedule, the Commission's own updates propagate directly into Lithuanian obliged-entity obligations. Commission Delegated Regulations 2026/46 and 2026/83 added Russia, Bolivia and the British Virgin Islands to that list, with Russia's listing taking effect from 29 January 2026; the preceding Delegated Regulation 2025/1184 had already reshaped the list's composition, adding ten jurisdictions including Algeria, Kenya, Lebanon and Venezuela while removing eight others, among them Panama, the Philippines and the UAE. Lithuanian obliged entities inherit each of these changes automatically.

The architectural point is sharpened by the fact that Lithuanian law maintains a second, independent EDD trigger. Article 14(1)(4) of the same law requires enhanced due diligence for customers or beneficial owners connected to jurisdictions identified by the Financial Action Task Force as high-risk, a determination that runs on its own track and need not align with the Commission list. A jurisdiction can therefore be high-risk for Lithuanian EDD purposes under one basis and not the other, and firms operating in Lithuania must monitor both lists rather than treating them as a single combined feed.

Other Developments

Remote identification is governed by a closed, exhaustive list of routes. Article 11(1) of the AML Law permits establishing customer and beneficial-owner identity without physical presence only through one of five defined mechanisms: reliance on a third party under article 13, an EU electronic identification scheme at high or substantial assurance level, a qualified electronic signature, live video capturing the original identity document together with an advanced electronic signature or a captured face image, or a first payment from the customer's own account at a qualifying EU or equivalent credit, payment or e-money institution accompanied by a certified paper copy of the identity document. An asynchronous onboarding journey built around document upload plus a selfie check is not independently compliant under Lithuanian law; it must be structurally mapped onto one of these five routes before it can be relied upon. The precise wording of the five limbs rests on an unverified translation, and further local-language confirmation would be needed before this reading is treated as settled in all its particulars.

Low-risk electronic money attracts a bounded customer due diligence derogation. Articles 9(4) and 9(5) of the AML Law permit credit and e-money institutions, where their own risk assessment and management procedures establish low money-laundering or terrorist-financing risk, to depart from the standard identification requirements of articles 10 to 12 for non-reloadable e-money instruments with stored value capped at EUR 150, restricted to goods-and-services use, with no anonymous funding and no cash redemption. Article 9(5) separately permits opening an account on limited data, with full identification completed within one month, subject to ongoing monitoring obligations. Lithuanian law does not carry a separate EUR 50 remote-payment limb that appears in some comparator regimes; the derogation is built around the EUR 150 non-reloadable instrument alone.

Record retention for customer due diligence material runs to eight years. Articles 19(10) and 19(11) require that registration log data, in paper or electronic form, be kept for eight years from the end of the transaction or business relationship, with shorter five-year periods applying to certain correspondence. This retention period sits at the longer end of what comparator jurisdictions apply to equivalent material, with implications for data-minimisation planning by firms operating across multiple EU markets with differing retention floors.

Cross-Monitor Connections

The automatic incorporation mechanism under article 14(1)(3) is the kind of structural finding that routes naturally to other monitors tracking EU-level list governance: any future Commission delegated regulation altering the high-risk third-country list will, by the same mechanism, alter obligations across every EU member state simultaneously, making the Commission's own listing process a more consequential single point of regulatory change than any one member state's domestic legislative calendar. Where other monitors track sanctions-list or conflict-finance exposure tied to jurisdictions newly added to the Commission's high-risk list, the Lithuanian incorporation mechanism demonstrates concretely how such a listing decision converts into binding firm-level EDD obligations across the bloc without further domestic process, a pattern worth cross-referencing wherever a newly-listed jurisdiction's financial exposure through EU-domiciled correspondent or payment channels is being assessed.

Outlook

The most immediate open question for Lithuania is the transposition status of the sixth Anti-Money Laundering Directive and the jurisdiction's alignment timeline with the directly-applicable AML Regulation and the Anti-Money Laundering Authority build-out; this was not established in the present research cycle and remains a gap. Until that timeline is confirmed, Lithuania's AML Law No VIII-275 continues to operate as the operative national instrument, with the Commission high-risk third-country list and FATF findings as its two live external EDD triggers. Firms with Lithuanian exposure should expect the EDD perimeter to continue moving in step with future Commission delegated regulations rather than with any domestic legislative schedule, and should treat the article 11(1) remote-identification list as closed rather than illustrative when designing or auditing onboarding journeys.

weekly_brief_draft · JID LT
Domain intelligence (D1–D6)

D1 Sanctions

Not covered

Sanctions is not yet covered for this jurisdiction in this report.

D2 Beneficial Ownership

Not covered

Beneficial Ownership is not yet covered for this jurisdiction in this report.

D3 Enabler Jurisdictions

Not covered

Enabler Jurisdictions is not yet covered for this jurisdiction in this report.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto / Digital Assets / Financial Innovation

Not covered

Crypto / Digital Assets / Financial Innovation is not yet covered for this jurisdiction in this report.

D6 Compliance Technology & Active Defence

Not covered

Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.

D7 AML/CTF Regime

AML/CTF Regime

Continue reading

Lithuania's AML/CTF regime, built on the Law on the Prevention of Money Laundering and Terrorist Financing (No VIII-275), demonstrates this cycle a structural property that deserves emphasis over any single incident: the enhanced due diligence perimeter under article 14(1)(3) is set not by domestic statute amendment but by dynamic reference to the European Commission's high-risk third-country list. When Commission Delegated Regulations 2026/46 and 2026/83 added Russia to that list, with effect from 29 January 2026, alongside Bolivia and the British Virgin Islands, the Lithuanian EDD obligation toward those jurisdictions arose automatically, without a Seimas vote, a ministerial order, or any other domestic legislative step. This is the architecture-over-incident reading: the Commission's own delegated-regulation process has become, for every EU member state including Lithuania, a more consequential lever over firm-level AML obligations than most domestic legislative calendars, because its effect is instantaneous and uniform across the bloc the moment a new regulation enters into force. The same mechanism had already operated earlier, under Delegated Regulation 2025/1184, which added ten jurisdictions including Algeria, Kenya, Lebanon and Venezuela to the list while removing eight others including Panama, the Philippines and the UAE; each of those additions and removals passed through to Lithuanian EDD obligations on the same automatic basis.

A second, independent trigger operates alongside the Commission list. Article 14(1)(4) requires enhanced due diligence toward customers and beneficial owners connected to jurisdictions that the Financial Action Task Force has separately identified as high-risk. Because the Commission list and the FATF findings are not the same instrument and do not necessarily move in lockstep, a jurisdiction can be high-risk for Lithuanian EDD purposes on one basis without being so on the other, or vice versa. Firms relying on a single combined high-risk feed risk missing obligations that arise under only one of the two tracks; the two triggers must be monitored as distinct inputs into the same due-diligence decision.

The regime's customer-identification architecture carries its own structural rigidity worth foregrounding for an AML/CTF audience specifically. Article 11(1) does not permit remote identification generally subject to a reasonableness standard; it enumerates five closed routes — third-party reliance under article 13, an EU eID scheme at high or substantial assurance, a qualified electronic signature, live video combined with either an advanced e-signature or a captured face image alongside the original document, or a first payment from a qualifying EU or equivalent account plus a certified paper identity copy. A compliance programme that treats this as a flexible principles-based standard, rather than a closed list against which any onboarding flow must be mapped, is building on a misreading of the statute. The translation underlying this reading carries medium confidence and the precise statutory wording would benefit from local-language confirmation before the mapping exercise is finalised for any specific onboarding product.

The low-risk electronic money derogation under articles 9(4) and 9(5) is narrower than some comparator frameworks. It applies to non-reloadable instruments capped at EUR 150 in stored value, restricted to goods-and-services use, with no anonymous funding and no cash redemption, and separately permits account opening on limited data with full identification completed within a month, subject to ongoing monitoring. Lithuania does not carry the EUR 50 remote-payment-instrument limb seen elsewhere, meaning firms calibrating a pan-EU low-risk e-money product cannot assume Lithuanian law mirrors the broadest version of the simplified due diligence permitted under comparable regimes.

Record retention closes the structural picture for this cycle: registration logs, identity document copies, beneficial-owner data and related account documentation must be kept for eight years from the end of the relationship under articles 19(10) and 19(11), a period at the longer end of what comparator EU jurisdictions require, with shorter five-year periods for some correspondence. For firms operating retention schedules across multiple EU markets, Lithuania's eight-year floor is the binding constraint wherever a shorter harmonised schedule would otherwise apply.

What remains unresolved, and should be read as a gap rather than a finding, is Lithuania's transposition status for the sixth Anti-Money Laundering Directive and its alignment timeline with the directly-applicable AML Regulation and the build-out of the Anti-Money Laundering Authority's supervisory perimeter. The present research cycle did not establish a transposition date, and the AML Law No VIII-275 continues to operate as the live national instrument in the interim.

Outlook

The automatic-incorporation mechanism under article 14(1)(3) means that the single most consequential near-term variable for Lithuania's AML/CTF perimeter is not domestic legislative activity but the Commission's own delegated-regulation cadence: any further addition to, or removal from, the EU high-risk third-country list will change Lithuanian firm-level EDD obligations the moment it enters into force, with no intervening domestic process. Firms with Lithuanian exposure should treat the Commission list, rather than the Seimas calendar, as the primary forward-looking signal to monitor for this regime, while separately tracking FATF findings as an independent second trigger. The 6AMLD transposition timeline remains an open question to be resolved in a future cycle once further research establishes Lithuania's position relative to the AMLR/AMLA build-out.

D8 Commercial Activity

Not covered

Commercial Activity is not yet covered for this jurisdiction in this report.

Regulatory horizon
No dated horizon items this cycle. 4 items tracked without a confirmed date.
4 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLRO

Lithuania's EDD perimeter widened automatically when the EU Commission high-risk third-country list added Russia from 29 January 2026, via AML Law article 14(1)(3) incorporation by reference.

Lithuanian obliged entities inherited an expanded enhanced due diligence obligation toward Russia-connected customers and beneficial owners without any domestic legislative change, and must separately track FATF high-risk findings under article 14(1)(4) as an independent trigger that does not necessarily track the Commission list.

2 evidence refs
Compliance

Remote customer identification in Lithuania is governed by a closed list of five permitted routes under AML Law article 11(1), and the low-risk e-money CDD derogation is narrower than some comparator regimes.

Onboarding journeys built on document upload and selfie verification must be mapped onto one of the five enumerated article 11(1) routes rather than assessed under a general reasonableness standard, and any low-risk e-money product design must respect the EUR 150 non-reloadable cap under articles 9(4)-(5) rather than assuming the broader EUR 50 remote-payment limb seen elsewhere.

2 evidence refs
Legal

No material change this cycle.

No material change for this persona this cycle

Board

Lithuania illustrates that EU Commission delegated regulations, not domestic legislation, now drive the pace of AML/CTF obligation change for an EU member state.

The structural dependency of Lithuania's EDD regime on the Commission's high-risk third-country list means that institutional AML exposure can shift on a Commission timetable rather than a Lithuanian legislative one, a dynamic relevant to board-level oversight of regulatory-change monitoring across EU operating entities.

1 evidence refs
CTO

No material change this cycle.

No material change for this persona this cycle

Risk

Lithuania layers two independent high-risk-country EDD triggers (EU Commission list and FATF findings) that do not necessarily align, creating a dual-track monitoring requirement.

Risk functions assessing jurisdictional exposure through Lithuanian entities should treat the Commission list and FATF findings as separate inputs rather than a single combined feed, since a jurisdiction can be high-risk under one basis without being so under the other.

2 evidence refs
Operations

Lithuanian CDD record retention runs to eight years, longer than some comparator EU retention floors.

Operational data-retention and deletion schedules for Lithuanian customer records must accommodate the eight-year floor under AML Law articles 19(10)-(11) rather than a shorter harmonised EU schedule that might apply elsewhere.

1 evidence refs
Audit

Lithuania's 6AMLD transposition status and AMLR/AMLA alignment timeline remain unestablished, a documented gap rather than a confirmed position.

Audit scope should note that Lithuania's AML Law No VIII-275 continues to operate as the live national instrument, with no confirmed transposition date for the sixth AML Directive recorded this cycle; control-testing against a presumed transposition timeline would be premature.

Decision lens
MLRO

Lithuania's EDD perimeter widened automatically when the EU Commission high-risk third-country list added Russia from 29 January 2026, via AML Law article 14(1)(3) incorporation by reference.

Compliance

Remote customer identification in Lithuania is governed by a closed list of five permitted routes under AML Law article 11(1), and the low-risk e-money CDD derogation is narrower than some comparator regimes.

Legal

No material change this cycle.

Board

Lithuania illustrates that EU Commission delegated regulations, not domestic legislation, now drive the pace of AML/CTF obligation change for an EU member state.

CTO

No material change this cycle.

Risk

Lithuania layers two independent high-risk-country EDD triggers (EU Commission list and FATF findings) that do not necessarily align, creating a dual-track monitoring requirement.

Operations

Lithuanian CDD record retention runs to eight years, longer than some comparator EU retention floors.

Audit

Lithuania's 6AMLD transposition status and AMLR/AMLA alignment timeline remain unestablished, a documented gap rather than a confirmed position.

Shared evidence: 2 refs
Scenario sketches

Illustrative pathway: AMLA supervisory perimeter extending into automatically-incorporated EDD triggers

As an illustrative orientation only, consider how the shift from purely national AML supervision toward the Anti-Money Laundering Authority's direct and indirect supervision of cross-border obliged entities, operating alongside the directly-applicable AML Regulation (Reg (EU) 2024/1624) and the member-state transposition of the sixth AML Directive, could interact with a mechanism like Lithuania's article 14(1)(3) automatic incorporation of the Commission high-risk third-country list. A hybrid EU-level supervisory layer could, in principle, standardise how obliged entities across member states respond to a Commission list update, reducing the current variation in how swiftly or thoroughly each national regime operationalises a new listing. This is an illustrative structural sketch, not an observed development or a prediction about Lithuania or any other jurisdiction.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Sanctions Regime Architecturestable
T2 · EU AML Package (AMLR/6AMLD/AMLA) Build-OutwatchLithuania's AML Law continues to operate under the pre-AMLR national framework (VIII-275); transposition status for 6AMLD and alignment timeline with AMLR/AMLA not established this cycle.
T3 · Beneficial Ownership Registry Effectivenessstable
T4 · Crypto/VASP Regulatory Frameworkstable
T5 · Compliance Technology and Supervisory Technology Adoptionstable
T6 · Sanctions Regime DivergencewatchEU high-risk third-country list update (Delegated Regulations 2026/46, 2026/83) adding Russia for mandatory EDD takes direct effect in Lithuania via AML Law art. 14(1)(3), illustrating EU-member automatic incorporation of Commission list changes without domestic legislative action.
Registers

Enforcement actions

  • Joint raid on a company allegedly exporting EU-manufactured, sanctioned goods to Russia and Belarus by rerouting them through Central Asian countries to defeat EU export restrictions. 10 Apr 2025
  • Fine and formal warning for failing to properly assess risk from high-risk clients and foreign financial institutions, not adapting monitoring scenarios to ML typologies, and insufficient staff AML training. 29 Aug 2025
  • Lithuanian customs disclosed rejecting 28,854 export requests for goods bound for Russia and Belarus that attempted to exploit a 'medical exemption' classification to bypass EU sanctions. 12 Jun 2025

Sanctions changes

  • EU's 19th sanctions package against Russia targeted Russian energy, third-country banks facilitating circumvention, and crypto-asset providers, extending the transaction ban to third-country financial and crypto operators connected to Russia's financial messaging system. 23 Oct 2025
  • The EU Council broadened the Belarus sanctions regime to cover hybrid activities against EU member states -- disinformation/FIMI, critical-infrastructure disruption, migrant instrumentalisation and unauthorised entry -- a decision explicitly following meteorological-balloon airspace incursions into Lithuania. 15 Dec 2025
  • EU adopted its 16th sanctions package against Russia (three-year invasion anniversary), mirroring trade sanctions in the parallel Belarus regime and adding restrictions on services, software, deposits, crypto-asset wallets and transport; the Belarus sanctions regime was concurrently prolonged to 28 February 2026. 24 Feb 2025
  • EU's 18th sanctions package upgraded the existing SWIFT ban on Belarusian banks (in view of Belarus' complicity in Russia's war) to a full transaction ban, and extended equivalent full transaction bans on other listed Russian/Belarusian banks. 18 Jul 2025

Regulatory horizon (register)

  • AML Regulation (AMLR) becomes directly applicable EU-wide
  • AMLA begins direct supervision of ~40 high-risk entities
  • 6AMLD transposition deadline for Lithuania
  • Next MONEYVAL follow-up report on Lithuania's R.6/7/28 gaps

Active schemes

  • [HIGH] Belarus/Russia sanctioned-goods transit and exemption abuse
  • [HIGH] Lithuania-licensed crypto firms servicing sanctioned Russian clients
  • Non-public UBO register shielding ownership links
  • [HIGH] Licensed EMI/bank layering for offshore proceeds (legacy and current)
Sources
  1. FATF / MONEYVAL
  2. FATF / MONEYVAL
  3. Council of the European Union (Consilium)
  4. European Anti-Fraud Office (OLAF)
  5. European Commission (DG REFORM / Council of Europe project)
  6. OCCRP
  7. Bloomberg
  8. OCCRP
  9. Bloomberg
  10. OCCRP
  11. European Commission / AMLA
  12. Elliptic
Coverage gaps
Lithuania's beneficial ownership registry is not publicly ac…
Lithuania's beneficial ownership registry is not publicly accessible; access is restricted to parties demonstrating 'legitimate interest,' a standard that remains ill-defined since the 2022 CJEU Sovim/W.M. ruling invalidated mandatory EU-wide public access.
FATF Recommendations 6 (TF targeted financial sanctions), 7 …
FATF Recommendations 6 (TF targeted financial sanctions), 7 (PF targeted financial sanctions) and 28 (DNFBP regulation/supervision) remain rated Partially Compliant in Lithuania's December 2024 MONEYVAL follow-up report, reflecting unclear freezing/de-listing procedures and incomplete DNFBP oversight.
No registration framework exists for accountants and real es…
No registration framework exists for accountants and real estate agents as DNFBPs, and MVTS providers, real estate agents, notaries and CSPs have historically filed few or no suspicious transaction reports despite facing material ML/TF risk exposure.
Recurring AML/CFT control failures across Lithuania's licens…
Recurring AML/CFT control failures across Lithuania's licensed EMI and crypto-asset sector (Pervesk/Bankera, Payeer, Transactive Systems, Payrnet) indicate persistent supervisory capacity strain relative to the scale and speed of fintech-sector growth, despite an EU-funded 2022-2024 project to strengthen FCIS risk-based supervision.

Evidence

Confidence-tiered claims

EU Commission high-risk third-country list (Delegated Regulations 2026/46 and 2026/83, in force from 29 January 2026, adding Russia, Bolivia and BVI) for mandatory enhanced due diligence SRC-financial-integrity-LT-MDR-003
Probable · 1 source
Enhanced due diligence for customers/beneficial owners connected to FATF-identified high-risk third countries, separate from the EU Commission list trigger SRC-financial-integrity-LT-MDR-003
Probable · 1 source
Where low ML/TF risk is established, credit/e-money institutions may depart from arts 10-12 CDD requirements for non-reloadable e-money instruments (or EUR 150/month domestic-use limit) with stored value capped at EUR 150, goods/services-only use, no anonymous funding, no cash redemption; art. 9(5) permits account opening on limited data with identification finalised within one month, subject to ongoing monitoring under art. 9(16) and art. 17 scrutiny. SRC-financial-integrity-LT-MDR-004
Probable · 1 source
Remote customer/beneficial-owner identification permitted only via: (1) third-party reliance under art. 13; (2) EU eID at high/substantial assurance; (3) qualified electronic signature; (4) live video capturing the original document plus advanced e-signature, or capturing face plus original document; (5) a first payment from the customer's own account at a qualifying EU/equivalent credit, payment or e-money institution plus a certified paper copy of the identity document. SRC-financial-integrity-LT-MDR-006
Probable · 1 source
Eight years for registration logs, identity document copies, beneficial-owner data, live-video recordings and account/contract documents; shorter five-year periods apply to some correspondence. SRC-financial-integrity-LT-MDR-008
Probable · 1 source