Resources & Glossary
Precision starts with vocabulary. Below are the working definitions we use across briefings and engagements — aligned, where they exist, with official EU terminology. Downloadable checklists and self-assessments will appear here as they are released; the first set accompanies our launch briefings.
Glossary
AML / CFT
Anti-money laundering and countering the financing of terrorism: the framework of laws, controls and reporting duties aimed at preventing the financial system from being used for laundering criminal proceeds or financing terrorism.
AMLR
Regulation (EU) 2024/1624 — the directly applicable EU “single rulebook” for AML/CFT. Applies from 10 July 2027, replacing large parts of national AML law for obliged entities.
AMLA
The EU Anti-Money Laundering Authority, seated in Frankfurt. Coordinates supervision, will directly supervise selected high-risk financial entities from 2028.
Beneficial owner (UBO)
The natural person who ultimately owns or controls an entity. Under the AMLR, ownership or control at 25% or more triggers identification duties, with stricter thresholds possible for high-risk sectors.
CDD / EDD
Customer due diligence — identifying and verifying customers and understanding the relationship. Enhanced due diligence applies deeper measures to higher-risk customers and situations.
Chain of title
The documented sequence of rights transfers proving that a company actually owns its code, content, data and other work products — from every creator to the current owner.
Control (in a framework)
A defined mechanism — a check, approval, limit, reconciliation or system rule — that reduces a specific risk and leaves evidence of execution.
Deployer (AI Act)
The organisation using an AI system under its own authority in a professional context. Deployers carry duties such as using systems per instructions, human oversight and monitoring.
DORA
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector — ICT risk management, incident reporting, resilience testing and third-party (including cloud) oversight. Applies since 17 January 2025.
Due diligence (transactional)
The structured examination of a company before an investment or acquisition — legal, financial and, increasingly decisive, technological: IP, data, AI, security and compliance.
GPAI
General-purpose AI — models usable across many tasks (e.g. large language models). The AI Act imposes transparency, documentation and copyright-related duties on their providers, applicable since 2 August 2025.
High-risk AI system
An AI system in areas listed by the AI Act (e.g. employment, credit, essential services) or embedded in regulated products, subject to the Act’s strictest requirements. Application dates were rescheduled by the 2026 digital omnibus agreement.
MiCA
Regulation (EU) 2023/1114 on markets in crypto-assets — authorisation and conduct rules for crypto-asset service providers and issuers. Fully applicable since 30 December 2024; national transition periods for existing providers ended by 1 July 2026.
MLRO
Money laundering reporting officer — the senior person responsible for an institution’s AML programme and for deciding on and filing suspicious-activity reports.
NIS2
Directive (EU) 2022/2555 on cybersecurity of network and information systems — risk management, incident reporting and management accountability for essential and important entities. In Poland implemented through the amended National Cybersecurity System Act.
Operational resilience
An organisation’s ability to keep delivering critical services through disruption — combining continuity, incident response, third-party management and testing.
Provider (AI Act)
The entity that develops an AI system or model and places it on the EU market under its own name. Providers bear the fullest set of AI Act obligations.
Risk appetite
The amount and type of risk an organisation consciously accepts to pursue its objectives — approved by governance and usable as a day-to-day decision boundary.
SAR / STR
Suspicious activity / transaction report — the filing an obliged entity makes to the financial intelligence unit when it suspects money laundering or terrorist financing.
Three lines model
A way of organising accountability: management owns risk (first line), specialist functions set frameworks and monitor (second line), internal audit provides independent assurance (third line).