Skip to content
Banca d'Italia · Italy

Relazione annuale antiriciclaggio and autovalutazione

Fintech Passport
September 30, 2026 · 11-min read
Relazione annuale antiriciclaggio and autovalutazione

Every payment and e-money institution supervised by Banca d’Italia owes it two AML documents by 30 April: the annual report of the AML function and the self-assessment of money-laundering risk. They travel together, they are built on a fixed schema and a fixed methodology, and since the 2024 reform one number from the self-assessment has to be reported a month earlier, in the 31 March data return. This guide covers who files, the eleven headings of the Allegato 1 report, the four-step autovalutazione method, how branches and group entities handle it, and three worked cases.

Both documents come from the Banca d’Italia Disposizioni in materia di organizzazione, procedure e controlli interni volti a prevenire l’utilizzo degli intermediari a fini di riciclaggio e di finanziamento del terrorismo of 26 March 2019, most recently published in consolidated form in March 2026. Banca d’Italia issues them under Legislative Decree 231/2007: Article 7(1)(a) for organisation, procedures and controls, Article 15 for the criteria and methodology of the risk self-assessment, and Article 16 for group-wide arrangements.

Three passages carry the obligation:

  • Parte Terza, Sezione I, para. 1.2 requires the AML function to present, at least once a year, a report to the strategic supervision, management and control bodies on the initiatives taken, the malfunctions found, the corrective actions to be taken and staff training. The results of the self-assessment are included in it.
  • Parte Terza, Sezione I, para. 1.6 requires recipients to send Banca d’Italia, by 30 April each year, the AML function’s report, including the self-assessment of risks. The same paragraph sets a 20-day deadline for notifying the appointment or removal of the head of the AML function.
  • Parte Settima, Sezione VIII requires the AML function to update the self-assessment every year and send it to Banca d’Italia by 30 April of the year after the reference year.

Communications under the Disposizioni are addressed to Banca d’Italia’s Unità di Supervisione e Normativa Antiriciclaggio. The next cycle covers 2026 and is due on 30 April 2027.

ItemDeadlineSource in the Disposizioni
Segnalazioni periodiche antiriciclaggio, including the residual-risk score (voce 61709)31 MarchParte Ottava + Allegato 2
Annual report of the AML function, including the self-assessment30 AprilParte Terza, Sez. I, para. 1.6(b); Allegato 1
Self-assessment of ML/TF risk (annual update)30 April of the following yearParte Settima, Sez. VIII
Appointment or removal of the head of the AML function20 days from the board resolutionParte Terza, Sez. I, para. 1.6(a)

2. Who has to file

The “destinatari” list covers banks, SIMs, SGRs, SICAVs and SICAFs, Article 106 TUB intermediaries, electronic money institutions, payment institutions, CASPs, Italian branches of banking and financial intermediaries headquartered in another EU country or in a third country, EU banks, PIs and EMIs required to appoint a central contact point in Italy under Article 43(3) of Decree 231/2007, and several other categories.

Two footnotes shape the position of passported firms. For branches, Parte Seconda (the governance bodies) and Parte Settima, Sezione VII (remedial action) apply by reference to the branch’s own managers. For the central-contact-point population, Parte Seconda does not apply at all, but Parte Sesta, Sezione III requires the firm to design the contact point’s organisation, procedures and controls taking into account “the results of the self-assessment conducted by the central contact point under Parte Settima”. A firm operating in Italy through agents with a contact point should therefore expect to run an Italian self-assessment even without a branch.

3. What the report must contain: Allegato 1

Allegato 1 sets the schema of the annual report. It is a fixed list, and a supervisor reading the report will look for each heading:

  1. Description and position of the AML function in the organisation (or the group), including changes in the year, human and technical resources, and outsourced processes.
  2. The function’s activity in the period, malfunctions found and corrective actions, in four areas: (a) customer due diligence and profiling, with specific detail on delays in completing CDD, including failures to identify the beneficial owner, and the distribution of customers across risk classes in absolute numbers and as a percentage; (b) record keeping; (c) detection and reporting of suspicious transactions, stating the number of reports sent to the UIF in the year and the number assessed and archived; (d) identification and application of international financial sanctions on terrorism and proliferation.
  3. The self-assessment of ML risks.
  4. Remedial initiatives defined in light of the self-assessment, and their progress.
  5. Training delivered in the period and planned for the next year.
  6. Specific issues of the intermediary and other relevant information.
  7. The AML function’s activity plan for the next year.
  8. The number of customer relationships closed because of AML anomalies.
  9. Malfunctions found by other internal control functions and the corrective measures taken.
  10. Communications with the supervisory authority, including sanctions imposed and corrective actions requested.
  11. The number of information requests received from the UIF, the judicial authority, and investigative and police bodies.

Several headings duplicate figures that also appear in the segnalazioni periodiche: SOS sent and archived, judicial and police requests, training, and the residual-risk score. Banca d’Italia receives both documents within a month of each other, so any difference between them needs an explanation written into the report.

4. The autovalutazione method: four steps, four-point scales

Parte Settima sets a method with four macro-activities: identification of inherent risk, analysis of vulnerabilities in the controls, determination of residual risk, and remedial action.

Lines of business. The exercise is run for each line of business considered relevant. The firm defines the lines by its own nature, organisation and complexity, and must explain in the document why it chose them and what weight each carries in total activity. Less complex firms may segment proportionately.

Inherent risk. For each line, the firm considers at least five risk-factor groups: the volume and value of transactions and typical activity; products and services and their target market; customer types, with attention to high-risk customers; distribution channels for opening and servicing relationships; and geography, covering customers, any branches or group companies in the area, and activity with other countries. The judgment is expressed on a four-value scale and must be supported by the data considered, the analysis performed and the reasons for the choices made. External sources feed in: the Commission’s supranational risk assessment, the national risk assessment of the Comitato di Sicurezza Finanziaria, FATF mutual evaluations, EU and national terrorism-related designations, and the results of supervisory action.

Vulnerability. For each line, the firm rates the vulnerability of its controls, again on a four-value scale, with a short description of the controls in place, the weaknesses found and the reasons for the score. The rating takes account of the views of the internal control functions and of what Banca d’Italia found in its own supervisory checks. An unaddressed inspection finding cannot sit alongside a “low vulnerability” rating.

Residual risk. Inherent risk and vulnerability are combined through the matrix in Sezione VI to give each line a residual-risk band on a four-value scale. The overall residual risk is the weighted combination of the line-level results, using the weights set earlier.

Remedial action. The management body proposes the remedial measures, taking account of the AML function’s annual report, and the strategic supervision body approves them. Management implements them through the AML function, which checks on an ongoing basis whether they work.

When to update outside the cycle. The exercise is updated annually, run for any new line of business when it opens, and updated promptly when significant new risks emerge or when there are significant changes to existing risks, to operations or to the organisational or corporate structure. In a group, the parent coordinates the exercise of each group company and runs a group-level self-assessment.

5. Worked example: a new line of business in June

Facts: An Italian EMI that issues prepaid cards launches a business-account product with SEPA transfers and virtual IBANs in June 2026.

What the rule says: Sezione VIII requires the AML function to run the self-assessment for the new line when it opens, not at the next annual update. Sezione II requires the document to explain why the line is treated separately and what weight it carries.

What the practitioner does: The AML function scores inherent risk and vulnerability for the business-account line before launch, using projected volumes and the planned controls, and records it as an addendum approved through the normal governance route. At year-end it re-scores the line on actual data and sets its weight from real activity rather than projections.

Outcome: The 30 April 2027 document shows a line that was assessed at launch and re-assessed on evidence. The residual-risk score in the 31 March return already reflects it, and the Allegato 1 report explains the change in the overall score under heading 3.

6. Worked example: an EU payment institution’s Italian branch

Facts: A payment institution authorised in another Member State operates an Italian branch. AML operations, transaction monitoring and screening are run by head office.

What the rule says: The branch is a destinatario under letter (i). The report and self-assessment are the branch’s, so its perimeter is the Italian customer base and the Italian activity. Heading 1 of Allegato 1 asks for resources and outsourced processes, and Parte Settima, Sezione VII applies by reference to the branch’s managers.

What the practitioner does: The branch’s AML head writes the report on the Italian perimeter and describes the head-office arrangement openly under heading 1. Extracts from the group systems are filtered to Italian customers. Remedial actions are proposed and approved by the branch’s managers, not simply copied from the group plan. Head-office internal audit findings that concern the Italian perimeter go under heading 9.

Outcome: A document Banca d’Italia can read as a branch-level assessment, consistent with the branch’s figures in the segnalazioni periodiche. A group report forwarded with an Italian cover letter would not meet the schema, because it cannot give Italian risk-class distributions or Italian SOS counts.

7. Worked example: an inspection finding and the vulnerability score

Facts: A Banca d’Italia inspection in 2025 found that ongoing monitoring of high-risk business customers was late. The remediation plan runs until mid-2027.

What the rule says: Sezione IV requires the vulnerability rating to take account of what Banca d’Italia found in its supervisory checks. Allegato 1 asks for communications with the supervisor, including corrective actions requested (heading 10), and for the status of remedial initiatives (heading 4).

What the practitioner does: The AML function keeps the vulnerability of the affected line at the higher score until remediation is complete and tested, and links heading 4 to heading 10 so the reader can follow the finding, the plan and its progress. Where the score does fall, the report states which completed actions justify it.

Outcome: A self-assessment that agrees with the supervisor’s own record. A score improvement with no evidenced remediation behind it is the kind of inconsistency that leads to follow-up questions.

8. Building the annual cycle

  • January: freeze year-end data. Risk-class distribution, CDD backlog, beneficial-owner gaps, SOS sent and archived, requests from the UIF and authorities, relationships closed for AML reasons.
  • February: score inherent risk and vulnerability per line. Collect the views of compliance, risk and internal audit in writing, because Sezione IV requires them to be considered.
  • Early March: fix the overall residual-risk score and report it in voce 61709 of the segnalazioni periodiche by 31 March.
  • March to April: draft the Allegato 1 report, table it with the management, strategic supervision and control bodies, and approve the remedial plan.
  • By 30 April: transmit the report with the self-assessment to Banca d’Italia, and keep the evidence file behind each figure.

FAQ

When is the Italian AML function report due?

By 30 April each year, covering the previous year, under Parte Terza, Sezione I, para. 1.6 of the Banca d’Italia AML organisation provisions. The 2026 report is due on 30 April 2027.

Is the autovalutazione a separate filing?

It is a separate document with its own method in Parte Settima, but it is included in the AML function’s report and sent with it by the same 30 April deadline.

How is residual risk calculated?

For each line of business, inherent risk and vulnerability are each rated on a four-value scale and combined through the matrix in Parte Settima, Sezione VI. The overall figure weights the line-level results by the weight of each line.

Do Italian branches of EU payment firms file?

Yes. Branches of intermediaries headquartered in another EU country or a third country are destinatari. Their report and self-assessment cover the Italian perimeter.

What about firms that operate only through agents?

EU PIs and EMIs required to appoint a central contact point are destinatari. Parte Seconda does not apply to them, but Parte Sesta refers to a self-assessment conducted by the central contact point under Parte Settima. Confirm the expected format with Banca d’Italia.

Must the self-assessment be updated during the year?

Yes, when a new line of business opens, and promptly when significant new risks or significant changes in risks, operations or structure arise.

What to do, today

  • Head of AML: map each of the eleven Allegato 1 headings to a data owner and a source.
  • Risk: list the lines of business and their weights now, so the 2026 scoring can close in early March 2027.
  • Branch managers: confirm that remedial actions for the Italian perimeter are approved locally.
  • Reporting: reconcile the SOS, request and training figures between the report and the 31 March return before either is sent.

Related: Segnalazioni periodiche antiriciclaggio — the 31 March return · The business-wide risk assessment under the AMLR · The Italian reporting calendar

Related reads.