AML in Armenia: How KYC, Risk and Monitoring Fit Together
A practical map of Armenian AML controls: customer and beneficial-owner checks, PEPs, remote onboarding, monitoring, reporting and evidence.
A customer can present a valid passport, pass a face comparison and still fail Armenia’s AML requirements. The missing evidence may concern the person represented by the applicant, the natural person who ultimately controls a company, the purpose of the relationship or activity that no longer matches the declared profile.
So a status of identity verified should never turn into customer approved on its own. Identity verification covers part of the evidence about the presenter. Approval is a separate risk decision on authority, beneficial ownership, screening, discrepancies and the institution’s own policy. Remote onboarding is where this gap bites hardest, because the Armenian framework treats the customer’s physical absence as a risk factor in its own right.
In brief
Article 16 of Armenia’s AML/CFT Law triggers customer due diligence (CDD) when a relationship is established, in specified occasional transactions, when earlier identity data is doubtful and when ML/TF is suspected.
The customer is one subject of the check. The representative, their authority to act and the beneficial owner each need to be resolved separately.
The seven-day identity-verification allowance comes with conditions. Do not treat it as a standard onboarding grace period.
Non-face-to-face relationships follow a specific high-risk and documented-mitigation route.
If mandatory CDD cannot be completed, the workflow must support refusal or termination and an assessment of suspicion.
Identity verification is one component of CDD
Under Armenia’s Law on Combating Money Laundering and Terrorism Financing, Article 16 requires a reporting entity to obtain prescribed customer information and verify identity using reliable, valid documents or information from competent public authorities. The entity must also establish whether the customer acts for another person, identify and verify the representative and authority to act, identify the beneficial owner and take reasonable measures to verify that person.
For a legal entity, a registry extract is where the work starts. Follow the control chain until you reach the natural person who ultimately owns or controls the entity. If customer declarations, registry data and corporate documents point in different directions, automated approval should stop until the discrepancy is resolved and documented.
Four events trigger CDD
Article 16(2) specifies CDD when:
a business relationship is established;
an occasional transaction or linked occasional transactions are performed, including a domestic or international transfer at or above 400 times the minimum salary unless a stricter rule applies;
the reliability or completeness of previously obtained identity information is in doubt;
money laundering or terrorist financing is suspected.
Transactions below the monetary threshold still need attention. A new relationship, doubt about data and suspicion each trigger CDD independently of the amount. Specific sectors also have additional rules: for example, the law applies a one-million-dram transaction threshold to covered gaming activity, while suspicion overrides the amount.
The law permits identity verification during or after the start of a relationship within a reasonable period of no more than seven days only where risk is effectively managed and delay is necessary not to interrupt normal business. Build that state with explicit controls: restricted functionality, an unresolved-verification status, a deadline and automatic escalation. The customer should not get seven days of unrestricted access.
Risk changes the depth of review, not the minimum evidence
CDD should answer four distinct questions: who the customer is, who can act for the customer, who ultimately controls or benefits from the structure, and why the relationship exists. Article 17 adds ongoing due diligence. Transactions must be examined against the institution’s knowledge of the customer, business profile and risk level; where necessary, the legitimacy of income and assets must also be examined.
Simplified due diligence is allowed only in a lower-risk case, and never where there is suspicion or a high-risk condition. Enhanced due diligence adds evidence, review frequency and decision authority. For a politically exposed person, attaching a PEP label is the first step. The workflow then resolves the person, obtains the required approval, establishes the source of wealth and funds where applicable, and tightens monitoring.
A risk record you can defend stores the reasons, sources, policy version, date and accountable decision-maker alongside the score. Without them, nobody at the institution can explain why one candidate match was dismissed and another escalated.
Remote onboarding has its own decision branch
The Central Bank of Armenia’s official AML/CFT FAQ explains how Clauses 27(6), 22.1 and 40 of the minimum-requirements regulation interact. A non-face-to-face transaction or relationship is a high-risk criterion and therefore calls for enhanced measures. Clause 40 generally requires the first payment to come from an account in the customer’s name at a qualifying financial institution.
The CBA also describes a risk-based exception. Clause 40 need not apply where the reporting entity conducts the Clause 22.1 assessment, places effective mitigations in its internal rules (transaction limits, restricted eligible groups or CDD data from a partner financial institution, for example), reasonably rates the product as medium risk, and sends the assessment results to the Financial Monitoring Center under Chapter 4.

Face Match and liveness alone do not justify a lower AML risk rating. They answer two narrow questions: is a live person present, and does that face resemble the portrait in the identity document? The purpose of the relationship, beneficial ownership, source of funds and suspicious behavior remain open. Still, a remote channel without them has weaker evidence that the presenter and the document belong together. Treat biometrics as one evidence layer inside CDD.
The audit trail must reproduce the decision
Article 22 requires the retention of CDD information and documents, identification data, account and transaction information, business correspondence, material on suspicious cases and cases reviewed but not reported as suspicious, and risk-assessment results. The minimum period is five years after the relationship ends or the transaction is performed, unless a longer period applies.
A reproducible case file should connect:
submitted data and images to their source and timestamp;
document, liveness and face-comparison results;
the customer, representative, authority and beneficial owner;
sanctions and PEP screening to the list version used;
risk factors and mitigations;
manual review, reasoning and final authority;
monitoring events and subsequent profile changes.
Where the required CDD cannot be completed before a relationship begins, Article 27 requires refusal of the transaction or relationship and consideration of whether the case is suspicious. If the necessary checks later become impossible, termination and the same suspicion assessment follow. The customer must not learn about a suspicious report, so case-management access and the wording of refusal messages each need their own controls.
Build a decision chain, not a magic verdict
Keep the automated evidence apart from the institution’s legal decision:
validate the document, capture and data consistency;
bind the presenter to the document with liveness and Face Match;
resolve representatives, authority and beneficial owners;
screen against sanctions, PEP and other applicable sources;
assess purpose, product, channel, geography and other risk factors;
route the case through standard, simplified or enhanced review;
retain evidence, reasoning and the next review date;
monitor activity and route exceptions to an authorized reviewer.
Biometric.Vision AML Screening checks individuals and legal entities against the stated sanctions, PEP and other lists, supports recurring monitoring and records the result history. You can run it together with document, face and liveness checks in one eKYC flow. The customer organization still owns the applicable-law analysis, risk policy, escalation rules and final decision.
Test an Armenian onboarding design with four cases before launch: a normal customer, a possible list match, an opaque beneficial owner and incomplete remote CDD. Each case shows whether the system keeps an explainable path from evidence to decision. A clean API response from every check does not answer that.
Ready to strengthen your customer checks?
500 checks free every month · no card · no contract · no sales call.



