AMF/ACPRFranceFintech

AML and KYC Compliance for Fintech in France

A detailed guide to AML and KYC compliance for fintech companies in France, covering AMF PSAN registration, ACPR oversight, the French AML framework, and the transition to MiCA.

Introduction to Fintech Compliance in France

Supportive government programmes such as French Tech, paired with a regulatory stance that holds innovation and financial-crime prevention in tension, have made France one of Europe's leading fintech hubs. Two supervisors share the market. The Autorité des marchés financiers (AMF) oversees investment services and digital asset service providers. Credit institutions, payment service providers, and insurance firms sit with the Autorité de contrôle prudentiel et de résolution (ACPR), a division of the Banque de France.

KYC and AML work is not optional for a fintech that wants to launch or grow in France. This guide sets out the legal framework that applies, the practical compliance load it creates, and how the EU's Markets in Crypto-Assets Regulation (MiCA) lands on French fintech firms. Identity verification fundamentals are covered in our guide on what is KYC.

Legislative Foundation

France's AML rules live mainly in the Code monétaire et financier (CMF). Articles L. 561-1 through L. 561-50 transpose the EU's Anti-Money Laundering Directives into national law. Further material sits around that statute:

  • Arrêtés and décrets from the Ministry of Economy and Finance, which supply technical implementation detail.
  • Guidelines and position papers from the AMF and ACPR, including the ACPR's Lignes directrices conjointes (joint guidelines on CDD).
  • TRACFIN guidance: TRACFIN is France's Financial Intelligence Unit, housed in the Ministry of Economy. It publishes annual risk assessments and typology reports that inform how firms meet AML duties.

Entities Subject to AML Obligations

The CMF casts a wide net of obliged entities (personnes assujetties):

  • Credit institutions and banks
  • Payment institutions and e-money institutions
  • Investment firms and portfolio management companies
  • Digital Asset Service Providers (Prestataires de services sur actifs numériques, or PSANs)
  • Insurance and reinsurance undertakings
  • Crowdfunding platforms (under certain conditions)

A complete AML/CFT compliance programme is required of every obliged entity. Risk assessment, customer due diligence, suspicious transaction reporting, and internal controls all form part of it.

Customer Due Diligence (CDD) Under French Law

Standard CDD Requirements

Under Articles L. 561-5 and L. 561-6 of the CMF, obliged entities must:

  1. Identify the customer before a business relationship is opened, or before an occasional transaction above EUR 15,000 is executed. For individuals that means name, date and place of birth, and nationality. For legal entities: company name, registration number, registered office, and the powers of the representatives.
  2. Verify the customer's identity with reliable, independent documents, data, or information. Individuals need a valid government-issued identity document (carte nationale d'identité, passeport, titre de séjour). The ACPR accepts digital verification methods that deliver equivalent assurance.
  3. Identify and verify the beneficial owner(s) — natural persons who ultimately own or control more than 25% of a legal entity's capital or voting rights.
  4. Understand the purpose and intended nature of the business relationship, and collect origin-of-funds information where that is appropriate.

Enhanced Due Diligence (Vigilance renforcée)

French law calls for enhanced measures in several settings:

  • Politically Exposed Persons (PPEs): Senior management approval, establishment of the source of wealth and funds, and enhanced ongoing monitoring are mandatory.
  • High-risk third countries: The European Commission sets the list; France's own risk assessment supplements it.
  • Complex or unusually large transactions: Any transaction that appears to lack economic justification triggers EDD.
  • Remote onboarding: Extra verification is required when the customer is not physically present. France has, over time, accepted video-based and AI-driven identification methods.

Simplified Due Diligence

Relationships judged genuinely low-risk — accounts with strictly limited functionality, or certain regulated financial counterparties — may receive simplified measures. SDD does not drop the identification duty. It allows lighter verification and less frequent monitoring.

AMF and PSAN Registration

The PSAN Framework

France was among the first EU member states to build a dedicated registration regime for Digital Asset Service Providers, through the PACTE Law of 2019. The AMF runs the PSAN process. Covered services include:

  • Custody of digital assets on behalf of third parties
  • Buying and selling digital assets for legal tender
  • Operating a digital asset trading platform
  • Exchange of digital assets for other digital assets

Since 2023, firms that offer these services to French residents have been required to hold PSAN registration. Applicants must demonstrate, among other things:

  • Adequate AML/CFT policies and procedures
  • A compliance officer with sufficient authority and resources
  • Fit and proper assessments for managers and beneficial owners
  • Cybersecurity and internal control arrangements

AML Obligations Specific to PSANs

CDD under the CMF is the same for PSANs as for other obliged entities. The AMF also expects attention to blockchain-specific risks. That means watching transactions that involve unhosted wallets, mixers, and addresses tied to sanctions or illicit activity. Dedicated AMF guidance explains how PSANs should run risk-based transaction monitoring.

Joinble's AI-powered identity verification platform helps PSANs meet these onboarding duties by automating French identity document verification, biometric liveness checks, and real-time screening against sanctions and PEP databases — and by producing the audit trail the AMF expects.

ACPR Oversight for Payment and E-Money Institutions

Licensing and Supervision

Payment institutions (établissements de paiement) and e-money institutions (établissements de monnaie électronique) are licensed and supervised by the ACPR. Licensing includes a close review of the applicant's AML programme, governance structure, and capital adequacy.

AML controls at supervised entities are examined on-site and off-site on a regular cycle. Enforcement has produced significant fines where CDD, transaction monitoring, or suspicious transaction reporting was deficient. Fintechs authorised as payment or e-money institutions should expect their automated onboarding flows — and whether their KYC technology is adequate — to be tested.

Suspicious Transaction Reporting to TRACFIN

Suspicious transaction reports (déclarations de soupçon) must go to TRACFIN whenever an obliged entity knows, suspects, or has reasonable grounds to suspect that funds are the proceeds of a criminal offence or are related to terrorist financing. Reports are filed promptly. Tipping off the customer is forbidden (obligation de non-divulgation). TRACFIN processed over 180,000 reports in recent years, which shows the maturity and scale of France's AML reporting system.

The MiCA Transition

What MiCA Means for French Fintech

The Markets in Crypto-Assets Regulation (MiCA) entered full application across the EU in December 2024. National frameworks such as the PSAN regime give way to a harmonized European licensing system. For French fintech, the main effects are:

  • Crypto-Asset Service Provider (CASP) authorization: Firms that were registered as PSANs must obtain CASP authorization under MiCA during the transitional period. France has set a transitional window so existing PSANs can keep operating while they apply for MiCA authorization.
  • Passporting: MiCA-authorized CASPs can offer services across all EU member states without a separate national registration in each one — a real advantage for French fintechs that want to expand.
  • Strengthened AML integration: MiCA sits alongside the EU's AML package (including the upcoming Anti-Money Laundering Authority, AMLA), so CASPs are fully integrated into the European AML supervisory framework.

French fintech firms should plan the MiCA move with care. KYC infrastructure needs to support customer identification, suitability assessments, and ongoing monitoring as the regulation requires. Joinble's verification platform is built to the highest EU standards for identity proofing and gives firms a scalable base through that shift.

Record Keeping and Data Protection

Under French law, AML-related records — copies of identity documents, transaction records, and due diligence files among them — must be kept for five years after the business relationship ends. Firms also answer to the General Data Protection Regulation (GDPR) and France's Loi Informatique et Libertés. The duty to retain AML data has to be balanced with data minimisation and purpose limitation. The CNIL (Commission nationale de l'informatique et des libertés) has issued guidance on how to reconcile those competing requirements.

Penalties for Non-Compliance

The ACPR's sanctions committee (Commission des sanctions) can impose fines of up to EUR 100 million or 10% of annual turnover for AML failings. The AMF can withdraw PSAN registration and impose financial penalties. Criminal sanctions under French law for money laundering offences include up to 10 years imprisonment and fines of up to EUR 750,000 for individuals.

FAQ

Is PSAN registration still required after MiCA entered into force?

During the transitional period, existing PSANs may keep operating under their French registration while they apply for MiCA CASP authorization. New entrants must apply directly for MiCA authorization through the AMF. The French transitional arrangements act as a bridge. Firms should still not delay their MiCA applications. For identity verification basics relevant to this process, see what is KYC.

What identity documents does French law accept for KYC verification?

The CMF and ACPR guidelines accept valid government-issued identity documents, including the French national identity card (CNI), passport, and residence permit (titre de séjour). Digital verification methods — AI-powered document authentication and biometric matching among them — are accepted when they provide equivalent assurance to physical document inspection.

How does TRACFIN differ from other EU Financial Intelligence Units?

TRACFIN sits under the French Ministry of Economy and Finance and is the national FIU. It receives, analyses, and disseminates suspicious transaction reports from obliged entities. A proactive stance is a known feature: sector-specific risk indicators and outreach to obliged entities. It cooperates with EU counterparts through the FIU.net platform and bilateral agreements.

Can a French fintech passport its PSAN registration to other EU countries?

Passporting was not available under the national PSAN regime. Firms needed a separate registration in each member state. Under MiCA, CASP authorization from the AMF allows passporting across all EU and EEA member states, which is one of the principal advantages of moving onto the MiCA framework.

What are the ACPR's priorities in AML examinations of fintech firms?

The ACPR has publicly named several priority areas: the adequacy of automated onboarding and digital KYC solutions; the effectiveness of transaction monitoring systems (especially for novel payment methods); the quality and timeliness of suspicious transaction reports filed with TRACFIN; and the governance and resourcing of the AML compliance function. Firms that use third-party KYC providers should still retain full oversight and accountability.

Automate your compliance with AI Agents

Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.

Book a demo