July 28, 2026

Bulgaria strengthens AML governance requirements for banks

The latest amendments to the Credit Institutions Act introduce important changes to the regulatory framework for banks, further integrating anti-money laundering and counter-terrorist financing requirements into prudential supervision

The latest amendments to the Credit Institutions Act, published in State Gazette No. 60 of 24 July 2026, introduce important changes to the regulatory framework for banks, further integrating anti-money laundering (AML) and counter-terrorist financing (CTF) requirements into prudential supervision.

The amendments reflect an increasingly visible European regulatory trend: AML risk is no longer viewed solely as a compliance issue but as a governance and prudential risk capable of affecting the stability and sound management of financial institutions.

Among the key changes are:

  • enhanced AML scrutiny in relation to qualifying holdings, acquisitions and ownership structures;
  • stronger cooperation and information exchange between the Bulgarian National Bank (BNB) and the State Agency for National Security (SANS);
  • explicit recognition of the AML compliance function as part of banks' governance arrangements; and
  • increased supervisory attention to high-risk third countries and complex cross-border structures.

Perhaps the most significant practical development is the new supervisory power allowing the BNB to require changes to the composition of a bank's management body where money laundering or terrorist financing risks affect the institution's sound and prudent management. This demonstrates that shortcomings in AML governance may now have direct consequences at board level.

What does this mean in practice?

The amendments reinforce the expectation that AML compliance should be embedded in the institution's governance framework rather than operate as a standalone control function. Financial institutions should review whether their governance arrangements enable senior management and boards to exercise effective oversight of AML risks.

In particular, banks and other regulated financial institutions should assess:

  • whether governance and reporting lines adequately support the AML compliance function;
  • whether enterprise-wide AML risk assessments properly reflect ownership, group and cross-border risks; and
  • whether management bodies receive sufficient information to identify and address material AML risks before they become supervisory concerns.

The legislative changes confirm that effective AML governance is becoming an essential element of prudential supervision. Institutions that proactively strengthen their governance and risk management frameworks will be better positioned to meet increasing regulatory expectations and reduce supervisory risk.

DPC's Financial Regulatory team advises banks, payment institutions, fintech companies and other obliged entities on AML and sanctions compliance, governance frameworks, regulatory investigations and cross-border compliance matters.

Tsvetelina Koleva
Senior Associate

Having practiced for over ten years in the core of DPC dispute resolution team, Tsvetelina has made herself a name as a dedicated and tenacious litigator who is not afraid of tough cases.

Related insights

Innovative solutions and customer care.
Get in touch