Financial Monitoring and AML/CFT in Simple Terms: What It Is, Who It Applies To, and How It Works

“Financial monitoring,” “AML/CFT,” “115-FZ,” “mandatory control,” and “suspicious transaction” are often blurred together into one vague topic, even though they are distinct concepts with different rules and different consequences for a business. We break each one down separately: what the state actually controls, exactly whom 115-FZ obligates, how the formal mandatory-control threshold differs from the substantive indicators of a suspicious transaction, and what this system looks like inside a company.

Financial monitoring is oversight of transactions involving money and property that the state requires banks and part of the non-bank sector to carry out, in order to detect signs of money laundering and terrorist financing. It works through a combination of Federal Law No. 115-FZ, the powers of Rosfinmonitoring, and the practical AML/CFT and AML procedures that an obligated organization builds into its own processes. What follows is what each of these terms means individually, exactly whom the law requires to carry them out, and what the process itself looks like — from customer identification to filing a report with Rosfinmonitoring.

What Financial Monitoring Is, in Simple Terms

Financial monitoring is oversight of transactions involving funds and other property, carried out by banks and other obligated organizations to catch signs of illegal schemes in time. The legal mechanism covers four areas set out in Article 1 of 115-FZ: combating the legalization (laundering) of criminally obtained proceeds, combating the financing of terrorism, combating the financing of the proliferation of weapons of mass destruction, and combating extremist activity.

Financial monitoring is an activity: the actual oversight is carried out by banks, insurance companies, pawnshops, and other obligated entities as part of their day-to-day work with customers. Rosfinmonitoring is the authorized body and financial intelligence unit: it receives and analyzes information on transactions, maintains lists, and issues regulations within its competence — but it is not the sole source of requirements, since some rules are set by the Government of the Russian Federation and the Bank of Russia. Rosfinmonitoring’s role is covered separately further below, because conflating the activity with the authority that administers it is a common inaccuracy in writing on this topic.

What AML/CFT Is and How It Relates to AML

AML/CFT stands for anti-money laundering and countering the financing of terrorism. It is a collective term for the entire system of measures: 115-FZ, international FATF standards, and departmental regulations issued by the Bank of Russia and Rosfinmonitoring together form the requirements that an obligated organization must meet.

AML (Anti-Money Laundering) is the practical implementation of this system inside a company: technology, processes, and internal regulations. If AML/CFT answers the question of what the state requires, AML answers the question of how that is organized at the level of a specific organization. For more on what AML verification looks like in practice, see the article “AML Checks and KYC: How Modern Systems Work”.

KYC (Know Your Customer) is the first and most visible stage of AML: customer identification, document verification, initial risk assessment. Without KYC, the AML/CFT system cannot begin to function — all further monitoring is built on the data collected at this stage.

ConceptWhat It IsLevel
AML/CFTRegulatory system: 115-FZ, FATF standards, regulations issued by the Bank of Russia and RosfinmonitoringLegal foundation
AMLAnti-Money Laundering — the practical implementation of AML/CFT within a companyTechnology and processes
KYCKnow Your Customer — customer identificationFirst stage of AML
Financial monitoringOversight of transactions involving money and propertyPractical activity

What Rosfinmonitoring Is and What It Is Responsible For

Rosfinmonitoring (the Federal Financial Monitoring Service) is the authorized body and financial intelligence unit of the Russian Federation. Under Article 8 of 115-FZ, it issues regulations within its competence, receives and analyzes information on transactions subject to mandatory control and on suspicious transactions, maintains and updates lists of organizations and individuals involved in terrorism, extremism, and the proliferation of weapons of mass destruction, and forwards materials to law-enforcement authorities. Some AML/CFT requirements are also set by the Government of the Russian Federation and the Bank of Russia. Rosfinmonitoring may suspend transactions on the grounds and within the timeframes provided for in Article 8 of 115-FZ, and exercises direct supervision over compliance with the law in the cases established by law — where no other supervisory authority has been designated for a given obligated entity.

Organizations do not report every single customer transaction to Rosfinmonitoring — what gets sent is information on transactions subject to mandatory control, and reports on suspicious transactions in the form of a formalized electronic message (FES). These two grounds for reporting are different mechanisms, and the rest of this article covers them separately.

Who 115-FZ Applies To

115-FZ applies to a wide range of organizations and professionals — the main categories are listed in Articles 5 and 7.1 of the law:

  • banks and other credit institutions
  • insurance companies, insurance brokers, mutual insurance societies, pawnshops, microfinance organizations, and consumer credit cooperatives
  • leasing and factoring companies
  • professional securities market participants, non-state pension funds
  • operators of gambling and lotteries, payment acceptance operators, operators of financial and investment platforms, operators of information systems used to issue digital financial assets, organizations that exchange digital currencies, and digital depositories
  • certain telecom operators
  • Russian Post (Pochta Rossii)
  • real estate agencies, jewelry organizations when dealing in precious metals and stones, audit organizations, and individual auditors
  • separately under Article 7.1 — notaries, lawyers, and legal and accounting firms when providing certain types of services to clients

These are the main categories, not an exhaustive list — the exact scope of obligated entities should be checked against the current version of Articles 5 and 7.1. For organizations on this list, the law establishes specific obligations: internal control, customer identification, and reporting to Rosfinmonitoring. For guidance on building compliance around these obligations, see the article “Fintech Compliance Under Federal Law 115-FZ”.

Find Out Whether 115-FZ Applies to Your Company

We’ll help determine whether your business falls under the obligations of 115-FZ and how extensive your AML/CFT procedures need to be based on your type of activity

Get a Consultation

Which Transactions Are Subject to Mandatory Control

Mandatory control is automatic oversight based on formal criteria: the amount and type of a transaction match the list set out in Article 6 of 115-FZ. When there’s a match, the obligated organization reports the transaction to Rosfinmonitoring regardless of whether it raises any suspicion — this is a formal obligation, separate from any substantive assessment of the customer’s behavior.

The threshold for the main list of transactions is ₽1 million, in effect since 14 July 2022 (Article 6(1)). An important caveat applies here: this is not a universal rule that “any transaction of ₽1 million or more is subject to control” — the threshold applies only to the transactions expressly listed in Article 6(1): certain cash transactions, transactions involving digital currencies and digital rights, transactions on bank accounts and deposits, transactions involving movable property, and transactions with persons or accounts in states on a list that the Government of the Russian Federation compiles in accordance with the established procedure, taking FATF documents into account (Article 6(1)(2)). Other thresholds apply to some categories, and the table below shows the main examples, not an exhaustive list.

ThresholdType of TransactionLegal Basis
₽1 millionCertain transactions listed in Article 6(1): cash, digital currencies and digital rights, transactions on accounts and deposits, transactions involving movable property, transactions with states on the list under Article 6(1)(2)Article 6(1) of 115-FZ
₽5 million or moreReal estate transactions: the exact amount is set by the authorized body, but no less than ₽5 millionArticle 6(1.1) of 115-FZ
₽100,000Postal money transfersArticle 6 of 115-FZ
No amount threshold*Transactions of non-profit organizationsArticle 6 of 115-FZ

* with exceptions under Article 6(1.2) — for example, for mandatory budget payments and utility services.

The ₽600,000 threshold that still appears in some sources is no longer a universal main threshold and should not be treated as a general rule. But it hasn’t disappeared from the law entirely: special provisions retain ₽600,000 for certain transactions related to state defense procurement (Article 6(1.4)), while the main threshold under Article 6(1) is ₽1 million.

What a Suspicious Transaction Is

A suspicious transaction works on a fundamentally different control mechanism. It is defined not by amount but by substance: by indicators that the transaction may be linked to money laundering or the financing of terrorism (Article 7(3) of 115-FZ). There is no amount threshold here — a ₽10,000 transaction can be flagged as suspicious if its nature raises questions, while a ₽50 million transaction may raise no questions at all if it has a clear economic rationale.

The indicators of an unusual transaction (deal) used to identify suspicious transactions are set out, for credit institutions and branches of foreign banks, in Bank of Russia Regulation No. 860-P dated 18 June 2025 (which replaced the superseded Regulation No. 375-P); other categories of obligated entities are governed by their own regulations, and certain categories are also subject to Rosfinmonitoring Order No. 18 dated 8 February 2022. This is not a closed list that can simply be checked off: under Regulation No. 860-P, a credit institution is entitled to supplement the list of indicators with its own internal rules, and it assesses a transaction based on the totality of information about the customer and the transaction, not on a single matching indicator. Typical indicators include: a confusing transaction structure with no obvious economic purpose, a loan at an interest rate significantly below the Bank of Russia’s key rate, a large cash deposit atypical for the customer’s business, and a customer’s refusal to provide requested documents.

It’s worth drawing a clear line here, because confusion often arises around this topic: reaching the mandatory-control threshold does not, by itself, make a transaction suspicious, and conversely, a transaction below any threshold can still be flagged as suspicious based on substantive indicators. These are two independent articles of the law with different grounds for control: Article 6 works on a formal match of amount and transaction type, Article 7 works on substance.

How Financial Monitoring Works in Practice

Within an obligated organization, the process breaks down into a clear sequence of steps.

  • Customer identification (KYC) — collecting data, verifying documents, and conducting an initial risk assessment when entering into an agreement or opening an account.
  • Risk assessment — assigning the customer a risk profile based on their type of activity, geography, and the nature of their transactions.
  • Transaction monitoring — ongoing tracking of the customer’s transactions after initial identification.
  • Flagging indicators — a match with the criteria for mandatory control (Article 6) or the indicators of a suspicious transaction (Article 7).
  • Additional verification — requesting documents, clarifying the economic rationale for the transaction.
  • Decision and action — refusing to carry out the transaction on the grounds set out in Article 7(11), suspending the transaction on the special grounds provided by 115-FZ (not every suspicious transaction is automatically suspended), or reporting the information to Rosfinmonitoring.

The final step for the organization is submitting the information to Rosfinmonitoring via an FES: no later than three business days after a transaction subject to mandatory control, and no later than three business days after identifying the indicators of a suspicious transaction. From there, Rosfinmonitoring may suspend transactions on the grounds and within the timeframes established by Article 8 of 115-FZ, and forward materials to law-enforcement authorities.

The AML/CFT System Within an Organization: How Internal Control Works Under 115-FZ

At the organizational level, the AML/CFT system is a continuously maintained loop made up of several elements:

  • internal control rules and a designated responsible officer
  • KYC procedures for onboarding customers — often set out in a separate policy that accounts for the requirements of 115-FZ, 152-FZ, FATF, and GDPR (for more, see “How to Build a KYC Policy”)
  • verification of beneficial owners and ownership structure for legal entities (KYB) — relevant for B2B customers, covered in the article “AML, KYB, and Beneficiary Verification”
  • regular staff training on the indicators of suspicious transactions
  • retention of the documents and information required by Article 7 of 115-FZ, including identification records, for at least five years from the date the relationship with the customer ends (special statutory retention periods apply to certain data)
  • reporting to Rosfinmonitoring

Each of these elements addresses a narrow task on its own, but they only work as a whole: without KYC at the front end, there is no basis for risk assessment; without ongoing transaction monitoring, signs of suspicious behavior won’t be caught in time; without staff training, formal rules remain nothing more than paperwork.

How KYC and AML Help Automate Control

Manually checking every customer and every transaction doesn’t scale well: an organization with thousands of customers simply cannot manually screen each one against sanctions lists and track transaction patterns in time. This is where automation enters the loop: KYC modules verify documents and biometrics during onboarding, AML screening checks a customer against sanctions lists, PEP (politically exposed persons) lists, and terrorist lists — for more on how this screening works, see the article “How Sanctions Screening, PEP Checks, and Risk Profiling Work” — while risk scoring assigns and updates the customer’s risk level as transaction data accumulates.

Further down the loop, transaction monitoring does its work: the system compares every transaction against the customer’s risk profile and against the criteria for mandatory control and suspicious transactions, and only when there’s a match does manual review by a compliance specialist kick in. A loop like this is usually built on a dedicated platform — for example, the NeuroVision AML platform combines KYC identification, AML checks, and risk assessment into a single process, leaving the compliance team to handle decisions that require substantive human judgment.

Automate KYC and AML Control

We’ll show you how to combine customer identification, AML screening, and transaction monitoring into a single process built around the requirements of 115-FZ

Learn More

Checklist: What a Business Needs

  1. Check whether you’re an obligated entity — whether your organization falls under the list in Article 5 or Article 7.1 of 115-FZ.
  2. Appoint a responsible officer — and approve the internal control rules.
  3. Implement a KYC procedure — customer identification when entering into an agreement or opening an account.
  4. Set up detection of transactions subject to mandatory control — based on the thresholds and transaction types in Article 6.
  5. Set up monitoring for suspicious transactions — based on the indicators of an unusual transaction from the regulation that applies to your organization (Bank of Russia Regulation No. 860-P for credit institutions, Rosfinmonitoring Order No. 18 for certain other entities), supplementing the list with your own internal rules.
  6. Define the procedure for when indicators are identified — ranging from requesting documents to refusing the transaction.
  7. Set up the submission of information to Rosfinmonitoring — via a formalized electronic message (FES).
  8. Ensure data retention — of the documents and information required under Article 7 of 115-FZ, including identification records, for at least five years from the date the relationship with the customer ends, subject to special retention periods for certain data.
  9. Regularly train employees — on the indicators of suspicious transactions and common social-engineering schemes.
Conclusion
Conclusion

Financial monitoring is oversight of transactions for AML/CFT purposes, established by 115-FZ for a broad range of organizations and administered by Rosfinmonitoring within its competence. Mandatory control and a suspicious transaction are different mechanisms: the first is triggered by a formal match of amount and transaction type, the second by substantive indicators with no amount threshold. AML is the practical label for the set of AML/CFT processes, while KYC is customer identification and due diligence, a significant part of which is directly required by Article 7 of 115-FZ. Automated transaction monitoring is a separate element of the same AML loop that kicks in after the customer has been identified. None of these requirements are addressed to business in general — they apply to the organizations listed in Articles 5 and 7.1 of 115-FZ, and are implemented through internal control rules, KYC procedures, and reporting to Rosfinmonitoring that each organization builds for itself.

FAQ

Question author
What is financial monitoring, in simple terms?
Financial monitoring is oversight of transactions involving money and property, carried out by banks and other obligated organizations to detect signs of money laundering, terrorist financing, financing of the proliferation of weapons of mass destruction, and extremist activity (Article 1 of 115-FZ).
NeuroVision
Question author
What is AML/CFT?
AML/CFT stands for anti-money laundering and countering the financing of terrorism. It’s a system of rules and measures — from 115-FZ down to a specific organization’s internal rules — not a single standalone procedure.
NeuroVision
Question author
Who does 115-FZ apply to?
The main categories, under Articles 5 and 7.1, are: banks and non-bank financial organizations, insurance companies and insurance brokers, pawnshops, microfinance organizations, leasing and factoring companies, gambling and financial-platform operators, certain telecom operators, real estate agencies, jewelers, auditors, and also notaries, lawyers, and accounting firms when providing certain services. The exact scope of obligated entities should be checked against the current version of the law.
NeuroVision
Question author
Which transactions are subject to mandatory control?
Transactions expressly listed in Article 6 of 115-FZ, once they reach the established threshold: ₽1 million for certain transactions under Article 6(1) (for example, cash, digital currencies and digital rights, transactions on accounts and deposits), ₽5 million or more for real estate transactions, ₽100,000 for postal money transfers. For non-profit organizations and a number of other transactions, the law provides separate rules and exceptions.
NeuroVision
Question author
How is mandatory control different from a suspicious transaction?
Mandatory control is triggered automatically by formal criteria — the amount and type of the transaction (Article 6). A suspicious transaction is determined by substance, with no amount threshold, based on indicators of an unusual transaction — drawn from Bank of Russia Regulation No. 860-P for credit institutions, and from Rosfinmonitoring Order No. 18 for certain other entities — assessed on the totality of information about the transaction and the customer (Article 7(3)).
NeuroVision
Question author
From what amount do transactions become subject to financial monitoring?
There’s no single amount. The threshold depends on the type of transaction: for most transactions under Article 6(1), the threshold is ₽1 million, but 115-FZ sets other, special thresholds for different categories of transactions subject to mandatory control. A suspicious transaction can be identified with no amount involved at all.
NeuroVision
Question author
What is Rosfinmonitoring?
The authorized body and financial intelligence unit (Article 8 of 115-FZ). It receives and analyzes information on transactions, maintains lists of persons involved in terrorism and the proliferation of weapons of mass destruction, issues regulations within its competence, and suspends transactions on the grounds and within the timeframes established by law. It exercises direct supervision over obligated entities wherever no other supervisory authority has been designated.
NeuroVision
Question author
How does an organization build its AML/CFT system?
Through a loop made up of several elements: internal control rules, KYC at customer identification, AML screening against lists and the risk profile, ongoing transaction monitoring, staff training, and reporting to Rosfinmonitoring.
NeuroVision