Ruling [LUX] ¦ Luxembourg Appeal Court Narrows AML Liability for Notary While Confirming Internal-Control Failures

Ruling [LUX] ¦ Luxembourg Appeal Court Narrows AML Liability for Notary While Confirming Internal-Control Failures

A distinction between deficient compliance and criminally punishable conduct

The Luxembourg Court of Appeal has substantially reduced the criminal liability of a notary prosecuted for alleged failures under the Law of 12 November 2004 on combating money laundering and terrorist financing. The court overturned findings relating to risk assessment, customer due diligence and suspicious-transaction reporting, while upholding convictions for inadequate internal AML/CFT policies and insufficient staff training.

The financial penalty was reduced from EUR 100,000 to EUR 15,000, with the court also taking account of the excessive duration of the proceedings.

The ruling is significant for obliged entities, particularly independent legal professionals. It confirms that the AML/CFT regime imposes demanding professional duties, but it also draws a line between imperfect compliance arrangements and a criminal offence committed knowingly.

Predicate-offence indicators remained unproven

Money laundering controls are directed at preventing the concealment, transfer or use of proceeds from predicate offences. In this case, the court found that the available facts did not establish concrete indicators that the transactions were connected to criminal activity or that the notary had good reasons to suspect money laundering.

The transactions concerned Luxembourg companies and Luxembourg residents. The funds passed through Luxembourg banking institutions, and the amounts were regarded as consistent with real-estate transactions. The notary held beneficial-owner information, declarations concerning the origin of funds, banking documentation and corporate records. Searches had also been performed through the Luxembourg Business Registers and the Mémorial.

Crucially, the court found no contemporaneous information directly linking the beneficial owners to a predicate offence, nor any manifest inconsistency in the transaction structure, source of funds or parties involved. Later media disclosures could not retrospectively create a reporting duty that had not arisen at the time of the transactions.

This is an important point for suspicious transaction reporting. A report to the Financial Intelligence Unit is required where the professional knows, suspects, or has good reason to suspect money laundering or terrorist financing. But the threshold cannot be met merely through the accumulation of neutral factors, including the nationality of participants. A criminal reporting failure requires more than an after-the-fact view that additional enquiries might have been possible.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"The Luxembourg Court of Appeal reduced a notary’s fine from EUR 100,000 to EUR 15,000 after acquitting her of several AML/CFT charges, including failures relating to risk assessment, customer due diligence and suspicious-transaction reporting. The court found no concrete indicators at the relevant time that the transactions were linked to a predicate offence or that there were reasonable grounds to suspect money laundering.

The court nevertheless upheld findings that the notary’s internal AML/CFT procedures and staff-training arrangements were inadequate. The ruling confirms that criminal liability for a failure to report requires an objectively supportable suspicion, while compliance policies and training must be genuinely tailored, implemented and documented."

Customer due diligence must be assessed in its historical setting

The appeal court also acquitted the notary of customer due-diligence breaches. It held that the checks performed reached a reasonable level under the law applicable in 2017.

The timing mattered. Luxembourg’s register of beneficial owners did not yet exist, and the court recognised the practical limits on tracing ownership and funds beyond client declarations and documented banking channels. The absence of a bank alert was not treated as decisive, but it formed part of the factual context in which the notary’s conduct had to be assessed.

The court did not suggest that a professional may rely blindly on the banking sector’s controls. A notary has direct contact with clients and remains subject to independent AML/CFT obligations. However, the decision confirms that due diligence must be measured against the information, tools and legal requirements actually available when the transaction was handled.

The appropriate test is not whether a compliance review would appear stronger with hindsight. It is whether the professional collected and assessed sufficient information to identify the client, beneficial owner, purpose of the transaction and source of funds, while responding proportionately to identifiable risks.

A written risk assessment can defeat an allegation of total absence

The court similarly acquitted the notary of failing to conduct an AML/CFT risk assessment. During an inspection, authorities had seized a note on anti-money-laundering duties and several pages of risk-assessment materials. The approach had apparently been adapted from a law firm’s model.

The court considered that the existence of this material, even if imperfect and externally inspired, excluded an allegation of a complete absence of risk assessment. This conclusion was particularly relevant because the relevant criminal offence had been introduced by the 2018 legislative amendment.

The finding should not be read as approval of generic template-based compliance. A risk assessment must reflect the actual activity of the professional practice, its client base, geographical exposure, transaction types, services and delivery channels. A copied procedure may be evidence that a framework exists, but it will not necessarily satisfy supervisory expectations or protect the professional where the framework is not adapted and implemented in practice.

Internal policies and training remained criminally deficient

The notary was nevertheless found guilty of failures concerning internal organisation and employee training. The court accepted that a written procedure existed, but held that it had not been genuinely tailored to the notarial practice. No structured monitoring or internal-control system had been demonstrated.

The court also found that the compliance officer had attended external training, but that there was no evidence of organised dissemination of AML/CFT knowledge to relevant staff. Training received by one responsible person does not, by itself, prove that employees are capable of identifying suspicious activity, escalating concerns and applying internal procedures.

The distinction is clear. A compliance policy cannot be merely stored in a file or copied from another professional practice. It must be operational, proportionate to the business and supported by documented controls. Staff members who handle client onboarding, transaction files, payment information or corporate documentation must receive training suited to their tasks, with records showing its content, date, attendees and frequency.

General AML concepts do not breach the principle of legality

The defence challenged several provisions of the Luxembourg AML/CFT framework on constitutional and EU-law grounds. It argued that concepts such as “appropriate measures”, “reasonable level of information”, “good reasons to suspect” and risk-based procedures were insufficiently precise to support criminal sanctions.

The court rejected that argument and declined to refer questions to either the Luxembourg Constitutional Court or the Court of Justice of the European Union.

It held that Article 49 of the EU Charter of Fundamental Rights, which protects the legality of offences and penalties, applies because Luxembourg’s AML/CFT legislation implements EU Directive 2015/849. Nevertheless, the use of general legal concepts is permissible where their meaning can be understood through the relevant statutory context, professional standards, regulatory guidance and case law.

For qualified professionals such as notaries, foreseeability is assessed against the knowledge expected from an informed practitioner. The risk-based nature of AML/CFT rules necessarily involves flexible concepts, because legal and financial risks vary according to the client, transaction, jurisdiction, asset and delivery channel.

Intent remains central to criminal AML/CFT enforcement

The court recalled that criminal liability under the Luxembourg AML/CFT regime requires conduct committed knowingly in breach of the law. It added that general intent may result from culpable ignorance of essential professional obligations.

That principle is particularly relevant for internal-control and training failures. An obliged entity cannot avoid responsibility by remaining unfamiliar with core AML/CFT requirements that apply to its professional activity. Where a notary or other regulated professional does not establish a workable compliance structure, does not maintain controls or fails to ensure that staff are trained, that inaction may support an inference of knowing non-compliance.

At the same time, the judgment confirms that criminal enforcement should not convert every compliance imperfection into a money-laundering offence. The lack of a complete risk assessment, more extensive source-of-wealth checks or an additional client enquiry does not automatically establish criminal intent, particularly where the available evidence did not reveal an objectively identifiable risk of predicate offending or laundering.

Practical consequences for notaries and other obliged entities

The decision provides a useful reminder that AML/CFT compliance has two connected but distinct dimensions. The first concerns transaction-level controls: customer due diligence, beneficial-ownership verification, source-of-funds analysis, ongoing monitoring and suspicious-transaction reporting. The second concerns the compliance infrastructure supporting those obligations: risk assessments, written policies, internal controls, training and documented oversight.

A suspicious transaction report should be based on facts known at the relevant time. Professionals should record why concerns arose, what checks were undertaken, what explanations were obtained and why a report was or was not made. Such records are essential where an authority later examines whether there were reasonable grounds for suspicion.

Equally, firms should avoid treating template policies as a complete answer. Their AML/CFT programme should be adapted to their business model and supported by evidence of implementation. For notarial practices, this includes clear procedures for property transactions, corporate formations and restructurings, beneficial-owner verification, funds-flow analysis, escalation to the compliance officer, staff training and periodic review.

The reduced fine does not lessen the broader enforcement message. Luxembourg courts may require proof of a real and identifiable basis for alleging a failure to report suspected laundering, especially where no predicate-offence indicators were apparent. But they will still impose criminal sanctions where a professional’s internal AML/CFT framework and staff-training arrangements are inadequate.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • La Justice Grand Duché de Luxembourg ¦ Décisions intégrales des juridictions judiciaires ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.