D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.
Lithuania applies the EU AML/CFT acquis (AMLD transposition, forthcoming AMLR/6AMLD) via the Law on Prevention of Money Laundering and Terrorist Financing, supervised by the Financial Crime Investigation Service (FNTT/FCIS) and the Bank of Lithuania for financial/EMI/crypto obliged entities.
Law made at European Economic Area level that applies in Lithuania is covered once, on the European Economic Area page. This page covers Lithuania’s own layer: implementation, national authorities, national options and local enforcement.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Crypto / Digital Assets / Financial Innovation is not yet covered for this jurisdiction in this report.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
Lithuania's AML/CTF regime, built on the Law on the Prevention of Money Laundering and Terrorist Financing (No VIII-275), demonstrates this cycle a structural property that deserves emphasis over any single incident: the enhanced due diligence perimeter under article 14(1)(3) is set not by domestic statute amendment but by dynamic reference to the European Commission's high-risk third-country list. When Commission Delegated Regulations 2026/46 and 2026/83 added Russia to that list, with effect from 29 January 2026, alongside Bolivia and the British Virgin Islands, the Lithuanian EDD obligation toward those jurisdictions arose automatically, without a Seimas vote, a ministerial order, or any other domestic legislative step. This is the architecture-over-incident reading: the Commission's own delegated-regulation process has become, for every EU member state including Lithuania, a more consequential lever over firm-level AML obligations than most domestic legislative calendars, because its effect is instantaneous and uniform across the bloc the moment a new regulation enters into force. The same mechanism had already operated earlier, under Delegated Regulation 2025/1184, which added ten jurisdictions including Algeria, Kenya, Lebanon and Venezuela to the list while removing eight others including Panama, the Philippines and the UAE; each of those additions and removals passed through to Lithuanian EDD obligations on the same automatic basis.
A second, independent trigger operates alongside the Commission list. Article 14(1)(4) requires enhanced due diligence toward customers and beneficial owners connected to jurisdictions that the Financial Action Task Force has separately identified as high-risk. Because the Commission list and the FATF findings are not the same instrument and do not necessarily move in lockstep, a jurisdiction can be high-risk for Lithuanian EDD purposes on one basis without being so on the other, or vice versa. Firms relying on a single combined high-risk feed risk missing obligations that arise under only one of the two tracks; the two triggers must be monitored as distinct inputs into the same due-diligence decision.
The regime's customer-identification architecture carries its own structural rigidity worth foregrounding for an AML/CTF audience specifically. Article 11(1) does not permit remote identification generally subject to a reasonableness standard; it enumerates five closed routes — third-party reliance under article 13, an EU eID scheme at high or substantial assurance, a qualified electronic signature, live video combined with either an advanced e-signature or a captured face image alongside the original document, or a first payment from a qualifying EU or equivalent account plus a certified paper identity copy. A compliance programme that treats this as a flexible principles-based standard, rather than a closed list against which any onboarding flow must be mapped, is building on a misreading of the statute. The translation underlying this reading carries medium confidence and the precise statutory wording would benefit from local-language confirmation before the mapping exercise is finalised for any specific onboarding product.
The low-risk electronic money derogation under articles 9(4) and 9(5) is narrower than some comparator frameworks. It applies to non-reloadable instruments capped at EUR 150 in stored value, restricted to goods-and-services use, with no anonymous funding and no cash redemption, and separately permits account opening on limited data with full identification completed within a month, subject to ongoing monitoring. Lithuania does not carry the EUR 50 remote-payment-instrument limb seen elsewhere, meaning firms calibrating a pan-EU low-risk e-money product cannot assume Lithuanian law mirrors the broadest version of the simplified due diligence permitted under comparable regimes.
Record retention closes the structural picture for this cycle: registration logs, identity document copies, beneficial-owner data and related account documentation must be kept for eight years from the end of the relationship under articles 19(10) and 19(11), a period at the longer end of what comparator EU jurisdictions require, with shorter five-year periods for some correspondence. For firms operating retention schedules across multiple EU markets, Lithuania's eight-year floor is the binding constraint wherever a shorter harmonised schedule would otherwise apply.
What remains unresolved, and should be read as a gap rather than a finding, is Lithuania's transposition status for the sixth Anti-Money Laundering Directive and its alignment timeline with the directly-applicable AML Regulation and the build-out of the Anti-Money Laundering Authority's supervisory perimeter. The present research cycle did not establish a transposition date, and the AML Law No VIII-275 continues to operate as the live national instrument in the interim.
The automatic-incorporation mechanism under article 14(1)(3) means that the single most consequential near-term variable for Lithuania's AML/CTF perimeter is not domestic legislative activity but the Commission's own delegated-regulation cadence: any further addition to, or removal from, the EU high-risk third-country list will change Lithuanian firm-level EDD obligations the moment it enters into force, with no intervening domestic process. Firms with Lithuanian exposure should treat the Commission list, rather than the Seimas calendar, as the primary forward-looking signal to monitor for this regime, while separately tracking FATF findings as an independent second trigger. The 6AMLD transposition timeline remains an open question to be resolved in a future cycle once further research establishes Lithuania's position relative to the AMLR/AMLA build-out.
Commercial Activity is not yet covered for this jurisdiction in this report.
Lithuanian obliged entities inherited an expanded enhanced due diligence obligation toward Russia-connected customers and beneficial owners without any domestic legislative change, and must separately track FATF high-risk findings under article 14(1)(4) as an independent trigger that does not necessarily track the Commission list.
Onboarding journeys built on document upload and selfie verification must be mapped onto one of the five enumerated article 11(1) routes rather than assessed under a general reasonableness standard, and any low-risk e-money product design must respect the EUR 150 non-reloadable cap under articles 9(4)-(5) rather than assuming the broader EUR 50 remote-payment limb seen elsewhere.
No material change for this persona this cycle
The structural dependency of Lithuania's EDD regime on the Commission's high-risk third-country list means that institutional AML exposure can shift on a Commission timetable rather than a Lithuanian legislative one, a dynamic relevant to board-level oversight of regulatory-change monitoring across EU operating entities.
No material change for this persona this cycle
Risk functions assessing jurisdictional exposure through Lithuanian entities should treat the Commission list and FATF findings as separate inputs rather than a single combined feed, since a jurisdiction can be high-risk under one basis without being so under the other.
Operational data-retention and deletion schedules for Lithuanian customer records must accommodate the eight-year floor under AML Law articles 19(10)-(11) rather than a shorter harmonised EU schedule that might apply elsewhere.
Audit scope should note that Lithuania's AML Law No VIII-275 continues to operate as the live national instrument, with no confirmed transposition date for the sixth AML Directive recorded this cycle; control-testing against a presumed transposition timeline would be premature.
Lithuania's EDD perimeter widened automatically when the EU Commission high-risk third-country list added Russia from 29 January 2026, via AML Law article 14(1)(3) incorporation by reference.
Remote customer identification in Lithuania is governed by a closed list of five permitted routes under AML Law article 11(1), and the low-risk e-money CDD derogation is narrower than some comparator regimes.
No material change this cycle.
Lithuania illustrates that EU Commission delegated regulations, not domestic legislation, now drive the pace of AML/CTF obligation change for an EU member state.
No material change this cycle.
Lithuania layers two independent high-risk-country EDD triggers (EU Commission list and FATF findings) that do not necessarily align, creating a dual-track monitoring requirement.
Lithuanian CDD record retention runs to eight years, longer than some comparator EU retention floors.
Lithuania's 6AMLD transposition status and AMLR/AMLA alignment timeline remain unestablished, a documented gap rather than a confirmed position.
As an illustrative orientation only, consider how the shift from purely national AML supervision toward the Anti-Money Laundering Authority's direct and indirect supervision of cross-border obliged entities, operating alongside the directly-applicable AML Regulation (Reg (EU) 2024/1624) and the member-state transposition of the sixth AML Directive, could interact with a mechanism like Lithuania's article 14(1)(3) automatic incorporation of the Commission high-risk third-country list. A hybrid EU-level supervisory layer could, in principle, standardise how obliged entities across member states respond to a Commission list update, reducing the current variation in how swiftly or thoroughly each national regime operationalises a new listing. This is an illustrative structural sketch, not an observed development or a prediction about Lithuania or any other jurisdiction.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Sanctions Regime Architecture | stable | |
| T2 · EU AML Package (AMLR/6AMLD/AMLA) Build-Out | watch | Lithuania's AML Law continues to operate under the pre-AMLR national framework (VIII-275); transposition status for 6AMLD and alignment timeline with AMLR/AMLA not established this cycle. |
| T3 · Beneficial Ownership Registry Effectiveness | stable | |
| T4 · Crypto/VASP Regulatory Framework | stable | |
| T5 · Compliance Technology and Supervisory Technology Adoption | stable | |
| T6 · Sanctions Regime Divergence | watch | EU high-risk third-country list update (Delegated Regulations 2026/46, 2026/83) adding Russia for mandatory EDD takes direct effect in Lithuania via AML Law art. 14(1)(3), illustrating EU-member automatic incorporation of Commission list changes without domestic legislative action. |