Source: OJ L, 2024/1620, 19.6.2024

Current language: EN

Annex I List of the coefficients linked to aggravating and mitigating factors for the application of Article 22


The following coefficients shall be applicable in a cumulative way to the basic amounts referred to in Article 22(4) on the basis of each of the following aggravating and mitigating factors:

  1. Adjustment coefficients linked to aggravating factors:

    1. If the breach has been committed repeatedly, for every time it has been repeated, an additional coefficient of1,1shall apply.

    2. If the breach has been committed for more than six months, a coefficient of1,5shall apply.

    3. If the infringement has revealed systemic weaknesses in the organisation of the selected obliged entity, in particular in its procedures, management systems or internal controls, a coefficient of2,2shall apply.

    4. If the infringement has been committed intentionally, a coefficient of 3 shall apply.

    5. If no remedial action has been taken since the breach has been identified, a coefficient of 1,7shall apply.

    6. If the selected obliged entity’s senior managementmeans the members of the management body in its management function, as well as officers and employees with sufficient knowledge of the obliged entity’s money laundering and terrorist financing risk exposure and sufficient seniority to take decisions affecting its risk exposure; has not cooperated with the Authority in carrying out its investigations, a coefficient of1,5shall apply.

  2. Adjustment coefficients linked to mitigating factors:

    1. If the selected obliged entity’s senior managementmeans the members of the management body in its management function, as well as officers and employees with sufficient knowledge of the obliged entity’s money laundering and terrorist financing risk exposure and sufficient seniority to take decisions affecting its risk exposure; can demonstrate that it has taken all the necessary measures to prevent the breach, a coefficient of0,7shall apply.

    2. If the selected obliged entity has quickly and effectively brought the complete breach to Authority’s attention, a coefficient of0,4shall apply.

    3. If the selected obliged entity has voluntarily taken measures to ensure that similar breaches cannot be committed anymore in the future, a coefficient of0,6shall apply.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod