AML Compliance Obligations for Accountants in Romania (Law 129/2019)
Updated: Sep 16
If you're a chartered accountant, an authorized accountant, or you run an accounting practice in Romania, you're already used to CECCAR's professional oversight. What's easy to underestimate is that Law No. 129/2019 on preventing and combating money laundering and terrorist financing puts you in a second, separate regulatory relationship: as a reporting entity under the direct supervision of Romania's Financial Intelligence Unit, ONPCSB — independent of your tax or audit obligations.

This isn't a theoretical exposure. ONPCSB runs dedicated inspections of accounting practices, and the penalties for non-compliance are real — we cover those separately in AML Fines in Romania – ONPCSB Sanctions for Companies and Reporting Entities. This guide focuses on what you actually need to have in place.
Who's covered: reporting entity status for accounting professionals
Article 5(1)(e) of Law 129/2019 explicitly lists auditors, accountants, and tax consultants among reporting entities. In practice, if you provide accounting, chartered-accounting, or tax advisory services — whether as a sole practitioner, an individual practice, or an accounting firm, with or without staff — the law treats you the same way it treats a bank or a notary for AML purposes: you're expected to know your client, assess risk, and report what looks suspicious.
CECCAR has translated this general framework into practice-specific guidance through its sectoral rules of 12 January 2023 on the application of Law 129/2019 to services provided by accounting professionals — a document that adapts the law's general requirements to how an accounting practice actually operates (typical client types, typical transactions, sector-specific risks). If you're a CECCAR member, this is your primary reference alongside the law itself.
The concrete AML obligations accountants need to meet
1. Designate a person responsible for ONPCSB liaison
Under Article 23(1) of Law 129/2019, every reporting entity with employees must designate one or more people responsible for applying the law and liaising with ONPCSB. This designation is made exclusively online, through the "Person designation and online reporting" section of the ONPCSB website, where you obtain an account in the Electronic Data Transmission System (SETD). Without that account, you have no way to file the reports described below at all.
If you operate as a sole practitioner without staff, check whether you fall under the natural-person exemption from this specific designation requirement — but note that the exemption doesn't waive the rest of your obligations: client due diligence, reporting, and record-keeping still apply.
2. Client due diligence (KYC) and risk assessment
Before starting a business relationship — not after — you need to identify and verify the client and, where relevant, the beneficial owner behind a company. For an accounting practice, that means: collecting identification documents for the client and any beneficial owners, checking ownership structure for corporate clients, and assigning each client a risk rating (low, standard, high) based on their sector, country exposure, ownership complexity, or transaction patterns. High-risk clients — for example, those tied to jurisdictions with elevated AML risk, or with opaque ownership structures — require enhanced due diligence, not a checkbox exercise.
3. Written internal AML procedures, tailored to your practice
The law requires your own written procedures — not a generic template pulled offline and left unsigned. A proper internal procedure should cover: how you identify and classify clients, the criteria you use to flag suspicious transactions or behavior, your internal escalation path (who decides whether to report to ONPCSB, and how quickly), your practice's risk register, and how client files are archived. For a broader look at what such a program should include, see our dedicated guide: How to Implement an AML Program in a Company – Complete Guide.
4. Reporting to ONPCSB
Two reporting obligations apply directly to accounting professionals:
Suspicious transaction reporting — any transaction, or intended transaction, that raises a suspicion of money laundering or terrorist financing must be reported to ONPCSB via SETD, regardless of amount.
Cash transaction reporting for transactions above the equivalent of €10,000, whether or not the transaction looks suspicious on its own — the threshold triggers the filing automatically.
Both are filed electronically, through the account obtained in step 1 — which is why the designation requirement isn't a formality; it's the technical precondition for reporting at all.
5. Record-keeping
Client identification documents, risk assessment files, and records of any reports filed must be kept for at least 5 years from the end of the business relationship or the date of an occasional transaction — a period you need to be able to demonstrate during an ONPCSB inspection, not just comply with on paper.
6. Periodic staff training
If you work with staff or associates who have client contact, they need periodic training on recognizing red flags and understanding how your internal reporting process actually works. A written procedure nobody in the practice has read won't hold up under an inspection.
Why accounting practices are a specific AML target
This isn't an abstract concern — the accounting profession appears repeatedly in AML risk typologies precisely because of the role it plays: company formation, transaction structuring, preparing financial statements that can obscure the origin of funds, or managing accounts on a client's behalf. Typical red flags worth watching for include: clients who push for complex ownership structures with no clear commercial rationale, transactions unrelated to a company's stated business activity, repeated cash payments kept just under the reporting threshold, or clients reluctant to disclose beneficial ownership information. None of these automatically mean money laundering — but each justifies extra scrutiny before you continue the relationship.
Practical AML compliance checklist for accountants
Have you formally, electronically designated a responsible person with ONPCSB (or confirmed you qualify for the exemption)?
Do you have a written, signed, up-to-date internal procedure — not an unsigned generic template?
Are you actually risk-rating every new client, with supporting documentation?
Does your team know the internal escalation path if someone spots a suspicious transaction?
Are client identification and risk assessment files archived for at least 5 years?
Has client-facing staff been trained in the last 12 months?
If you answered "no" to any of these, you already have a concrete priority list.
How AMLExpert can help
If you're not sure your accounting practice fully meets these obligations, you can check quickly, for free, with no registration, using the AML Reporting Entity Checker — one question, a clear answer on what applies to you. Note: the tool itself is currently in Romanian only. You can also subscribe to the AMLExpert newsletter directly from the tool's page for ongoing updates on Romanian AML requirements.
Frequently asked questions
Are all accountants reporting entities, or only accounting firms? The law covers anyone exercising an accounting profession — chartered accountants, authorized accountants, and tax consultants — regardless of legal form (sole practitioner, individual practice, or company). Legal form affects some procedural details (for example, the exemption from designating a responsible person for staff-free sole practitioners), not the underlying duty to know your client and report.
What happens if I don't designate a responsible person with ONPCSB? Without that SETD account, you have no way to file the required reports electronically — a compliance gap that can be sanctioned on its own, separately from any undetected suspicious transactions. See AML Fines in Romania for how sanctions are structured.
Do CECCAR's sectoral rules replace Law 129/2019? No — they complement it. The law sets the general, mandatory framework for all reporting entities; CECCAR's sectoral rules adapt its application to the accounting profession specifically, for its members.
How often should a practice's internal AML procedure be updated? The law doesn't set a fixed interval, but the recommended practice — and the practical expectation during an ONPCSB inspection — is at least an annual review, or sooner if the practice's risk profile changes (new clients in higher-risk sectors, international expansion, etc.).
Conclusion
Reporting-entity status isn't a footnote in an accountant's practice — it's an active legal obligation, with its own procedure, deadlines, and penalties. The realistic starting point is an honest check of what you already have in place against the checklist above, not waiting for an ONPCSB inspection to find out what's missing.




Comments