Changes to French AML regulations key points for businesses

April 17, 2023
Blog Image

French businesses that are obligated to follow French anti-money laundering (AML) regulations and report to the Financial Markets Authority (AMF) and the Prudential Supervision and Resolution Authority (ACPR) are facing new changes in 2023. The regulations have been updated to simplify remote verification requirements and expand the list of qualified providers, allowing French companies to onboard clients online without additional diligence measures.

‍

Who's affected by the changes?

‍

The changes impact French businesses obligated to follow French AML regulations and report to the AMF and the ACPR, which includes a wide range of entities such as banks and credit institutions, payment and e-money institutions, investment companies, insurance companies, crowdfunding intermediaries, crypto businesses, and ICO issuers. The new rules also apply to foreign firms onboarding French clients if they are established in the EU/EEA and operate in France through a branch or an agent.

‍

Which parties will be impacted by the alterations?

‍

The modifications will affect French companies that are bound to adhere to French AML regulations and report to the AMF and the ACPR, as well as foreign firms that cater to French clients and are established within the EU/EEA and operate in France through a branch or an agent.

‍

What's changed?

‍

Updates to French Monetary and Financial Code: Remote Verification Now AcceptedRecent changes to the French Monetary and Financial Code now allow remote verification to be considered as reliable as face-to-face verification. This shift mirrors the principles of the Fifth AML Directive, which encourages businesses to use remote verification. The French Monetary and Financial Code amendments simplify the requirements for remote verification and expand the list of qualified providers.

‍

These changes have several benefits, including:

‍

  • French businesses can now onboard clients online without additional diligence measures, such as requesting supporting documents
  • There is a wider selection of remote verification solutions available to French businesses
  • Providers that follow Regulation (EU) N°910/2014 (eIDAS Regulation) are now subject to more flexible security requirements, even when used as a single method of verification
  • French businesses are now able to use providers certified by the National Cybersecurity Agency of France (ANSSI) under the same regulation

‍

Tips for maintaining compliance

‍

To establish a business relationship with a client, companies must identify the nature and purpose of the relationship. If the client is an individual, the company must obtain their first and last name, as well as their date and place of birth. For a legal entity, companies must obtain the legal form, name, registration number, head office address, and the actual activity location if it differs from the legal address. Additionally, companies must identify the beneficial owner of the legal entity, which can be done by collecting the same information required from individuals. A beneficial owner is someone who directly or indirectly owns over 25% of a company's capital or voting rights or exercises ultimate control over it.

‍

Requirements for online onboarding

‍

To get started with online onboarding, natural persons will need to provide one of the following official documents: national identity card, passport, driver's license, residence permit, or a receipt for a residence permit/residence card/asylum application in progress. The document copy must be valid and feature the owner's photograph. As of February 2020, clients are no longer required to submit a second supporting document to confirm their identity.

‍

For legal entities, the company can obtain an act or extract from the official register (such as K-bis) that is less than three months old, or an extract from the official Journal.

‍

Exclusive verification solutions for French businesses

‍

French companies have access to three verified solutions that are approved by French regulators and can be easily integrated into their business operations. The first solution is called "FranceConnect," which is a digital identity verification system that allows French citizens to securely access online public services offered by the government and other approved service providers. This system relies on a user's French social security number and a unique login, making it a reliable and convenient way for businesses to verify the identities of their customers or employees.

‍

The second solution is known as "Chorus Pro," which is an electronic invoicing platform that is mandatory for businesses with more than 10 employees in France. Chorus Pro ensures secure and reliable invoicing by requiring digital signatures and compliance with strict formatting standards. This solution helps businesses save time and reduce errors by streamlining their invoicing processes.

‍

The third and final solution is called "eIDAS," which is a set of regulations that aim to create a secure and trustworthy electronic identification and trust services market in the European Union. eIDAS provides a framework for the mutual recognition of electronic identities across EU member states, making it easier for businesses to operate across borders while maintaining high levels of security.

‍

In addition to these solutions, French businesses also have access to a range of third-party verification providers that offer a variety of services to help businesses comply with regulatory requirements and prevent fraud. These providers can help with tasks such as identity verification, background checks, and document authentication, among others.

‍

Overall, the availability of these exclusive verification solutions and third-party providers make it easier for French businesses to comply with regulations, protect against fraud, and streamline their operations. By utilizing these solutions, French companies can stay ahead of the curve and ensure that they are operating securely and efficiently in today's rapidly evolving business landscape.

‍

‍

‍

Auteur

Autres blogs connexes

Questions fréquemment posées

Dataleon propose-t-il une assistance ?
Oui. Chaque client bénéficie d'un accompagnement dédié : support technique par e-mail et visioconférence, documentation complète et exemples de code pour intégrer nos API. Nos ingénieurs vous aident à cadrer vos parcours KYC et KYB, à réaliser l'intégration puis à passer en production sans interruption de service. Un interlocuteur unique reste ensuite disponible pour suivre vos volumes, ajuster vos règles de contrôle et répondre à vos questions métier comme techniques.
Mes fichiers sont-ils supprimés après traitement ?
Oui. Vos documents sont chiffrés en transit comme au repos, traités puis supprimés automatiquement à l'issue de la durée de conservation que vous définissez. Vous restez seul propriétaire des données transmises : elles ne sont ni revendues ni utilisées à d'autres fins que la réalisation de vos contrôles. Vous pouvez aussi déclencher la suppression immédiate d'un dossier depuis l'interface ou via l'API, et ne conserver que les résultats d'analyse nécessaires à vos obligations de conformité.
Peut-on intégrer Dataleon à nos outils via API ?
Oui. Dataleon se connecte à votre système d'information via une API REST documentée, des webhooks temps réel et des connecteurs vers vos outils existants : CRM, core banking, GED ou solutions de signature électronique. Les parcours de vérification, les règles de scoring, les seuils de risque et les workflows de validation sont entièrement paramétrables afin de coller à vos procédures internes. Nos équipes peuvent également développer des traitements sur mesure lorsque votre cas d'usage l'exige.
Puis-je tester Dataleon avant de m'engager ?
Oui. Vous bénéficiez d'un essai gratuit de 15 jours, sans engagement, pour vérifier vos propres pièces d'identité, justificatifs et documents d'entreprise et mesurer la qualité de l'extraction et des contrôles KYC/KYB. Pendant ces 15 jours, vous accédez à l'interface ainsi qu'à des clés d'API de test afin de valider votre intégration technique de bout en bout. Nous proposons également une démonstration personnalisée avec un expert pour construire ensemble le parcours adapté à votre activité.
Êtes-vous conforme au RGPD avec des serveurs en France ?
Oui. Dataleon est conforme au RGPD et l'ensemble des traitements ainsi que le stockage des données sont réalisés en France, sur l'infrastructure de Scaleway, hébergeur souverain français. Nous appliquons le chiffrement des données en transit et au repos, la minimisation des informations collectées, une gestion fine des droits d'accès et une traçabilité complète des opérations. Un accord de traitement des données (DPA) et notre documentation de sécurité vous sont fournis pour faciliter vos audits internes et réglementaires.

L'automatisation qui rend la conformité invisible.

Dataleon, le chaînon manquant entre votre conformité et votre croissance. KYC, KYB, LCB-FT, enfin réunis au même endroit.