Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Financial Integrity Monitor

Romania RO

Domains (D1–D6)
2
Sources
9
Role actions
8
Horizon <90d
1
Jurisdiction profile
Largely CompliantTier BRisk: StableMixed

Romania's AML/CFT regime rests on Law 129/2019 (transposing EU AMLD4/5), with NOPCML/ONPCSB as FIU, NBR and FSA as prudential AML/CFT supervisors, and ONRC operating the beneficial ownership register.

MoreMONEYVAL's 2023 MER rated regulation/supervision of financial institutions (R.26) non-compliant and beneficial ownership of legal arrangements (R.25) partially compliant, with a March 2026 follow-up noting only partial progress.

Key deficiencies
  • R.26 (regulation and supervision of financial institutions) rated non-compliant in the 2023 MONEYVAL MER
  • NOPCML/FIU chronically understaffed and lacking technical resources to produce operational financial intelligence
  • Beneficial ownership register (ONRC Register of Real Beneficiaries) is fee-gated/legitimate-interest access rather than fully public, with contested data accuracy
  • No overarching national AML/CFT strategy despite numerous sectoral crime strategies
  • NBR AML/CFT supervision described by assessors as ad hoc, lacking a general strategic direction
  • Large cash-based underground economy (~30% of GDP) and shell-company use for ML linked to tax evasion
Recent developments (18m)
  • MONEYVAL published a follow-up report (23 March 2026) finding Romania made progress on some technical compliance deficiencies identified in its MER
  • Romanian anti-corruption prosecutors opened a probe (reported Feb 2026) into a failed EUR 38 million ONRC (Trade Registry/BO register) IT system that blocked 130,000+ business registrations and exposed personal data of 3,000+ individuals
  • DIICOT conducted a sweeping crypto-laundering crackdown (27 March 2025) against an organised crime network that laundered over $14 million in crypto tied to renewable-energy project embezzlement
  • OLAF and EPPO jointly uncovered a EUR 9.5 million EU-funds fraud and money-laundering scheme spanning Romania, Cyprus, Czechia and the UAE (announced 10 April 2025), leading to 12 indictments
  • Romania adopted a new anti-fraud ordinance (published 30 Jan 2026) strengthening EU-funds fraud prevention under the NRRP/PNRR loan agreement

Law made at European Economic Area level that applies in Romania is covered once, on the European Economic Area page. This page covers Romania’s own layer: implementation, national authorities, national options and local enforcement.

Brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Romania this cycle shows two domains moving in opposite directions. On the AML/CFT architecture side, MONEYVAL's July 2026 follow-up report finds Romania compliant with 7 of the 40 FATF Recommendations, largely compliant with 20, and partially compliant with 13, with improvement recorded specifically on Recommendations 6 and 7 covering targeted financial sanctions. Romania nonetheless remains in MONEYVAL's enhanced follow-up process, meaning the incremental improvement has not been sufficient to exit heightened monitoring. Separately, on the digital-asset side, Romania's national MiCA transitional regime closed decisively: the 18-month grandfathering window under GEO 10/2025 for pre-MiCA crypto-asset service providers expired on 1 July 2026, and the Financial Supervisory Authority (ASF) has begun issuing its first coercive sanctioning decisions against digital-asset entities for periodic-reporting failures.

Read together, these signals describe a jurisdiction whose paper compliance architecture is improving gradually while its supervisory posture toward a specific sector, digital assets, has shifted abruptly from permissive to active. The two developments are not contradictory; they describe different clocks. The FATF-recommendation compliance trajectory moves on a multi-year mutual-evaluation cycle, while the MiCA transition was a fixed statutory deadline that simply arrived.

Other Developments

Sanctions screening mechanism unchanged. Romania's exposure to the EU list of high-risk third countries, the 26-country list in force from 29 January 2026, continues to apply via the standard AMLR mechanism, with no Romania-specific autonomous-listing divergence identified this cycle. This is a structural continuity finding rather than a new development, and it confirms Romania has not adopted any national variation from the EU-wide sanctions-screening baseline.

FATF grey-list status confirmed absent. Romania is not on the FATF grey list and continues to be assessed instead through the MONEYVAL fifth-round mutual evaluation process, a status distinct from, and independently confirmed alongside, the enhanced follow-up finding above. This T1-sourced confirmation should not be conflated with the enhanced follow-up status: grey-listing and enhanced follow-up are separate mechanisms, and Romania's exposure runs only through the latter.

Cross-Monitor Connections

The MiCA transitional closure and ASF's new enforcement posture connect directly to the crypto monitor's licensing coverage of the same underlying event, and to the world-payments monitor's structural coverage of BNR's role as banking and payments supervisor outside the MiCA-authorisation perimeter. The enhanced-follow-up AML/CFT finding is architecture-level and has no direct payment-corridor or crypto-licensing analogue this cycle, but it forms part of the same national supervisory backdrop against which both the crypto and payments monitors' Romania coverage should be read.

Outlook

The MiCA transition closure is recent enough that the scale and substance of ASF's coercive sanctioning practice remain unestablished; whether this becomes a sustained enforcement programme or a narrow set of reporting-failure actions will be the key data point to watch. On the AML/CFT side, the improvement on Recommendations 6 and 7 is a positive but partial signal; Romania's continued presence in enhanced follow-up means the compliance architecture is still under active MONEYVAL scrutiny, and the next follow-up report will be the natural checkpoint for whether the partial-compliance items narrow further.

weekly_brief_draft · JID RO
Domain intelligence (D1–D6)

D1 Sanctions

Not covered

Sanctions is not yet covered for this jurisdiction in this report.

D2 Beneficial Ownership

Not covered

Beneficial Ownership is not yet covered for this jurisdiction in this report.

D3 Enabler Jurisdictions

Not covered

Enabler Jurisdictions is not yet covered for this jurisdiction in this report.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto / Digital Assets / Financial Innovation

Crypto / Digital Assets / Financial Innovation

Continue reading

Romania's digital-asset supervisory perimeter tightened decisively this cycle. The 18-month transitional grandfathering window established under GEO 10/2025 for pre-MiCA crypto-asset service providers expired on 1 July 2026. From that date, no crypto-asset service provider may serve Romanian or EU clients without full MiCA authorisation from the Financial Supervisory Authority (ASF); the prior national ONPCSB-registration route that had allowed continued operation during the transition is now closed. This is a structural finding, not an incident: it marks the end of a permissive posture that had persisted since MiCA's phased rollout began, and it converts Romania's digital-asset market overnight from a transitional regime into a fully MiCA-governed one.

The practical consequence is already visible in supervisory behaviour. ASF has begun issuing its first coercive sanctioning decisions against digital-asset entities, specifically for periodic-reporting failures. The scale and substance of these actions have not yet been established in the evidence available this cycle, and the confidence on this specific enforcement-pattern claim is accordingly held at the uncertain tier pending further detail. What can be said with more confidence is the structural fact of the deadline itself and its binding effect on market access from 1 July 2026 onward.

This development should be read architecture-over-incident: the significant fact is not any single sanctioning decision but the transition from a permissive to an active supervisory posture. A regulator that has spent eighteen months administering a grandfathering window and then begins issuing coercive sanctions in the same quarter the window closes is signalling a change in enforcement philosophy, not merely processing a backlog. For institutions with correspondent or counterparty exposure to Romanian digital-asset entities, the relevant question going into the next cycle is whether ASF's enforcement activity remains confined to reporting-failure cases or expands to substantive licensing-perimeter violations.

The absence of a comparable finding on Romania's beneficial-ownership registry mechanics, sanctions-evasion architecture, or enabler-jurisdiction exposure this cycle should not be read as reassurance; it reflects the scope of what was researched, not a finding of clean status in those domains.

Outlook

The immediate watch item is whether ASF's coercive sanctioning activity broadens beyond reporting-failure cases into substantive MiCA-authorisation enforcement, and whether the still-pending national MiCA-implementing draft ordinance (allocating supervisory powers between ASF and the National Bank of Romania) reaches final adoption. Until that ordinance is adopted, some ambiguity in the dual-authority supervisory model persists even as the core authorisation deadline has already taken effect.

D6 Compliance Technology & Active Defence

Not covered

Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.

D7 AML/CTF Regime

AML/CTF Regime

Continue reading

MONEYVAL's follow-up report, published 6 July 2026, assessed Romania as compliant with 7 of the FATF 40 Recommendations, largely compliant with 20, and partially compliant with 13, recording specific improvement on Recommendations 6 and 7, which cover targeted financial sanctions, since the prior June 2025 report. Despite this incremental improvement, Romania remains under MONEYVAL's enhanced follow-up process. This is the architecture-level finding for the cycle: Romania's AML/CTF technical-compliance position is moving in the right direction on a subset of recommendations without yet reaching the threshold that would remove it from heightened monitoring.

This finding sits separately from Romania's FATF grey-list status. Romania is not on the FATF grey list; it is assessed instead through the MONEYVAL fifth-round mutual evaluation mechanism, a Council of Europe process rather than the FATF's own International Co-operation Review Group process that produces grey-listing. The two mechanisms should not be conflated: enhanced follow-up under MONEYVAL is a form of continued technical-compliance monitoring, while grey-listing carries its own distinct international signalling and correspondent-banking consequences. Romania's exposure runs only through the former.

On sanctions-list mechanics, Romania's exposure to the EU list of high-risk third countries, the 26-country list in force from 29 January 2026, continues to apply through the standard AMLR mechanism, with no Romania-specific autonomous divergence identified. This is a continuity finding confirming Romania has not diverged from the EU-wide baseline on high-risk-country screening obligations.

No Romania-specific finding on beneficial-ownership registry mechanics beyond MONEYVAL's general transparency commentary, sanctions-evasion architecture, enabler-jurisdiction exposure, or conflict-finance nexus was located this cycle. These gaps reflect the scope of research conducted, not a finding of clean status.

Outlook

The next MONEYVAL follow-up report will be the natural checkpoint for whether Romania's partial-compliance items on the remaining 13 Recommendations narrow further, and whether continued improvement is sufficient to support eventual exit from enhanced follow-up. In the interim, the improvement on Recommendations 6 and 7 specifically reinforces the targeted-financial-sanctions screening infrastructure that also underpins Romania's EU high-risk-third-country list application noted above.

D8 Commercial Activity

Not covered

Commercial Activity is not yet covered for this jurisdiction in this report.

Regulatory horizon
In Force2026-Q3 · ±quarter

National MiCA implementing Government Emergency Ordinance (dual ASF/BNR authority model)

From 1 July 2026, crypto-asset service providers without MiCA authorisation may no longer operate for Romanian/EU clients; ASF and BNR are designated competent authorities under GEO 10/2025.
1 dated · 4 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLRO

Romania remains under MONEYVAL enhanced follow-up despite improved Recommendation 6/7 compliance.

The July 2026 MONEYVAL follow-up shows partial compliance on 13 of 40 Recommendations, which may affect correspondent due-diligence posture toward Romanian counterparties even as targeted-sanctions screening compliance improves.

1 evidence refs
Compliance

Romania's MiCA transitional deadline closed 1 July 2026, ending the national grandfathering route for crypto-asset service providers.

Any Romanian counterparty relationship premised on transitional national registration rather than full MiCA authorisation is no longer compliant as of 1 July 2026.

1 evidence refs
Legal

ASF has begun issuing first coercive sanctions against digital-asset entities for reporting failures.

This signals a new enforcement posture from ASF; the scale and legal substance of these decisions is not yet established, warranting monitoring of enforcement precedent as it develops.

1 evidence refs
Board

Romania's AML/CTF and digital-asset postures are diverging: gradual architecture-level improvement alongside abrupt sectoral enforcement tightening.

Board-level risk assessment of Romanian exposure should distinguish between the slow-moving mutual-evaluation trajectory and the fast-moving digital-asset supervisory shift, as they carry different risk horizons.

2 evidence refs
CTO

MiCA authorisation is now the sole legal basis for serving Romanian crypto clients; the transitional national registration pathway no longer exists.

Technical infrastructure and client-onboarding systems referencing the prior ONPCSB-registration route need review against the current MiCA-only authorisation requirement.

1 evidence refs
Risk

Divergent trajectories across AML/CTF architecture and digital-asset supervision in Romania this cycle.

Risk concentration models should treat Romanian digital-asset counterparty exposure as a distinct, more acute risk vector than general AML/CTF country risk, which is improving incrementally.

3 evidence refs
Operations

No material change this cycle.

No material change for this persona this cycle

Audit

EU high-risk third-country list screening mechanism for Romania confirmed unchanged via standard AMLR application.

Audit testing of high-risk-country screening controls for Romanian exposure can continue against the existing 26-country EU list baseline with no divergent national variant to test for.

1 evidence refs
Decision lens
MLRO

Romania remains under MONEYVAL enhanced follow-up despite improved Recommendation 6/7 compliance.

Compliance

Romania's MiCA transitional deadline closed 1 July 2026, ending the national grandfathering route for crypto-asset service providers.

Legal

ASF has begun issuing first coercive sanctions against digital-asset entities for reporting failures.

Board

Romania's AML/CTF and digital-asset postures are diverging: gradual architecture-level improvement alongside abrupt sectoral enforcement tightening.

CTO

MiCA authorisation is now the sole legal basis for serving Romanian crypto clients; the transitional national registration pathway no longer exists.

Risk

Divergent trajectories across AML/CTF architecture and digital-asset supervision in Romania this cycle.

Operations

No material change this cycle.

Audit

EU high-risk third-country list screening mechanism for Romania confirmed unchanged via standard AMLR application.

Shared evidence: 2 refs
Scenario sketches

AMLA direct/indirect supervision transition and cross-border obliged-entity evasion pathways

Illustrative orientation only: as the AMLA Regulation (Reg (EU) 2024/1620) moves toward operational supervisory capacity alongside the directly-applicable AMLR (Reg (EU) 2024/1624) and per-Member-State 6AMLD transposition, the structural move from purely national supervision toward a hybrid EU-level supervisory perimeter could reshape how cross-border obliged entities are monitored. For a jurisdiction such as Romania, still navigating enhanced follow-up under MONEYVAL, this architecture shift could eventually alter which layer, national or EU-level, carries primary supervisory weight for cross-border-active obliged entities. This is illustrative structural orientation, not an observed development or a prediction of Romania-specific outcome.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architecturestable
T2 · EU AML Package / AMLAwatch
T3 · FATF Grey Liststable
T4 · Beneficial-Ownership Register Statuswatch
T5 · Crypto & Digital-Asset Integritymaterial_change
T6 · Sanctions Regime Divergencestable
Registers

Enforcement actions

  • DIICOT conducted 66 searches nationwide and detained 15 suspects, including legal representatives of several companies, accused of embezzlement, misuse of company assets and laundering over $14 million in cryptocurrency tied to a renewable-energy project, including false claims of crypto-trading profits. 27 Mar 2025
  • Following on-the-spot checks in Cyprus and Czechia and analysis of seized IT servers, OLAF and EPPO uncovered a EUR 9.5 million fraud and money-laundering scheme involving EU Regional Development Fund resources for an IT platform, with funds diverted through fictitious contracts. 10 Apr 2025
  • EPPO's Romania office indicted 10 individuals and 4 companies for orchestrating a EUR 1.6 million fraud scheme exploiting subsidies meant to help unemployed people gain job skills, using close to 200 false claims via a network of fictitious companies operating 2019-2021. 25 Jan 2025
  • Prosecutors opened an investigation into the ONRC's failed IT platform (launched summer 2024), which blocked over 130,000 business registrations for weeks, exposed personal data of 3,000+ individuals, and was signed off nine months before launch without adequate testing per draft audits. 17 Feb 2026

Sanctions changes

  • The EU's 20th sanctions package (adopted 23 April 2026) added 46 shadow-fleet vessels (total 632 listed), 36 Russian energy-sector designations, a first-ever activation of the EU anti-circumvention tool against a third country, and new tanker-sale/scrapping safeguards. As an EU member and Black Sea port state, Romania directly applies and enforces these measures at Constanta and other national ports. 23 Apr 2026
  • The EU's 19th sanctions package (23 October 2025) introduced sanctions on the developer of the Russian state-linked stablecoin A7A5, its Kyrgyz issuer, and a platform operator, plus a ban on reinsuring shadow-fleet vessels and further shadow-fleet vessel listings (bringing the total to 557 at the time). These crypto and maritime-insurance measures are directly applicable in Romania as an EU member state with a materially large VASP/crypto sector. 23 Oct 2025

Regulatory horizon (register)

  • AMLR (Reg 2024/1624) direct application in Romania
  • 6AMLD transposition deadline for Romania
  • AMLA supervisory perimeter and standards build-out affecting Romania
  • MONEYVAL next enhanced follow-up report on Romania

Active schemes

  • [HIGH] EU-funds fraud layered through Romania-Cyprus-Czechia-UAE network
  • Crypto-ATM cash-out pipeline for embezzled renewable-energy funds
  • Black Sea shadow-fleet transit exposure via Constanta corridor
  • [HIGH] Restricted, low-integrity beneficial ownership register exploitation
Sources
  1. MONEYVAL / FATF
  2. Romania's Parliament / UNODC hosted
  3. OCCRP
  4. European Anti-Fraud Office (OLAF)
  5. Council of the European Union
  6. Global Witness
  7. European e-Justice Portal / Romanian Ministry of Justice submission
  8. OCCRP / Public Record
  9. FATF
Coverage gaps
MONEYVAL's 2023 MER rated Romania non-compliant (NC) on R.26…
MONEYVAL's 2023 MER rated Romania non-compliant (NC) on R.26 (regulation and supervision of financial institutions), the only Recommendation to receive the lowest rating; the March 2026 follow-up confirmed only partial progress on such technical compliance deficiencies.
MONEYVAL assessors found that a lack of technical and human …
MONEYVAL assessors found that a lack of technical and human resources at NOPCML (the FIU) hampers the quantity and quality of financial intelligence it can provide to law enforcement and other partners, compounded by a shortage of financial investigators more broadly.
The ONRC's beneficial-ownership register infrastructure suff…
The ONRC's beneficial-ownership register infrastructure suffered a EUR 38 million IT-platform failure (launched summer 2024) that blocked over 130,000 registrations and exposed personal data of more than 3,000 individuals; auditors found the system was signed off nine months before launch without adequate testing.
MONEYVAL found no overarching AML/CFT strategy exists in Rom…
MONEYVAL found no overarching AML/CFT strategy exists in Romania; while numerous sector-specific strategies address corruption, trafficking and organised crime, information on the level of risk mitigation actually achieved is not comprehensive.

Evidence

Confidence-tiered claims

Romania rated compliant on 7, largely compliant on 18, partially compliant on 15 of the 40 FATF Recommendations per MONEYVAL's 6 July 2026 follow-up report; under 5th-round enhanced follow-up procedure SRC-fim-RO-002
Probable · 1 source
RBR remains publicly searchable; draft 2025 legislation may restrict access to parties demonstrating a legitimate interest, mirroring post-2022 CJEU trend; new ONRC filing fees (RON 200) took effect 1 January 2026 SRC-fim-RO-005
Uncertain · 1 source
18-month Article 143(3) grandfathering window for legacy crypto-asset providers ended 1 July 2026; unauthorised crypto-asset service provision after that date is unlawful SRC-fim-RO-007
Probable · 1 source
Romania directly bound by AMLR (Reg (EU) 2024/1624) from 10 July 2027 as an EU-27 member; harmonised 25% BO threshold (15% for higher-risk sectors) and EUR 10,000 cash-payment limit become directly applicable SRC-fim-RO-008
Probable · 1 source
Targeted-financial-sanctions technical compliance remains only partially compliant per MONEYVAL's 6 July 2026 follow-up report, an architecture-level gap SRC-fim-RO-002
Probable · 1 source