Platform
Solutions
Resources
Company
Resources
Solutions

The Balkans: Compliance infrastructure in Montenegro and Serbia

Montenegro and Serbia are among the jurisdictions evaluated by the Council of Europe's MONEYVAL committee. Both are aligning with the EU acquis, meaning the EU's new AML package sets their direction. In TruvaLI, each country is a separate data source: the same deployment hosts different rule sets.

Montenegro and Serbia are jurisdictions evaluated by the Council of Europe's MONEYVAL committee, and both are in the process of aligning with the EU acquis. For an institution operating in both countries, this does not require deploying two separate systems, but it does require managing two distinct rule sets.

Where is the common ground, and where do they diverge?

The common ground between the two countries is their MONEYVAL evaluation and their alignment with the EU acquis. This means both are moving toward the same framework regarding risk-based approach, customer identification, ultimate beneficial owner (UBO) identification, and suspicious transaction report filing.

TopicCommonCountry-specific
Risk-based approachYesDefinition of risk classes
Customer identificationYesRequired documents and verification methods
Ultimate beneficial owner (UBO) identificationYesThreshold ratio and registry access
Suspicious transaction reportYesReporting threshold, format, and timeline
RetentionYesPeriod and storage format

The divergence lies in implementation: reporting thresholds, reporting formats, retention periods, and national authority expectations vary from country to country.

Why does the EU package matter to these countries?

The European Union's new AML framework includes AMLA, established by Regulation (EU) 2024/1620, Regulation (EU) 2024/1624, and Directive (EU) 2024/1640. AMLA applies from 1 July 2025 and directly supervises selected obliged parties in the financial sector, including crypto-asset service providers.

For candidate countries, this means the compliance target is moving: a structure built today must also fit tomorrow's framework. Details are on the AMLA and EU regulations page.

Being in the region

Bitrelic has a team in Podgorica. Having a physical presence in the region is very different from tracking regulatory changes and authority expectations from afar.

Single deployment, country-specific rule sets

Different countries are defined as separate data sources, and rule and data isolation is managed through this separation. The same deployment hosts different rule sets for different jurisdictions: one country's threshold does not affect another, and each data source has its own credentials.

The common elements remain in a single place: customer records, screening infrastructure, case management, audit trail, and report drafting. A separate system is not deployed for each country.

What happens when a country-specific obligation is introduced?

The rule engine handles this: nested logic, named aggregation definitions, and callbacks from rules. A rule can be described in your own language, the draft approved, and tested on historical traffic in simulation before going live. Details are on the rule and scenario engine, writing rules with prompts, and rule simulation pages.

Audit-ready records

The decision is linked to the case with its justification and evidence: information on who decided, with what authority, using which data, and when is written to an immutable audit trail. Approval policies, multi-signature decisions, and documented delegation of authority can be defined. Details are on the maker/checker, authorization, and audit trail page.

Where does the data reside?

In an on-premise deployment, the software runs on the institution's own infrastructure, data remains within the institution's information systems, and keys and the audit trail are under the institution's control. Since data residency rules vary from country to country, this is often a decisive factor in regional deployments. Details are on the on-premise deployment page.

The data protection side is on the GDPR page, and the regional comparison is on the Middle East and North Africa page.

Common questions

Which evaluation are Montenegro and Serbia subject to?
The Council of Europe's MONEYVAL committee evaluation on anti-money laundering and combating the financing of terrorism.
Is it necessary to deploy two separate systems for the two countries?
No. Each country is defined as a separate data source: the same deployment hosts different rule sets, and one country's threshold does not affect another.
What is common and what is different between the two countries?
The risk-based approach, customer identification, ultimate beneficial owner (UBO) identification, and suspicious transaction reports share a common framework. Reporting thresholds, reporting formats, retention periods, and authority expectations vary.
Does the EU's new AML package affect these countries?
Yes. Since both are in the process of aligning with the EU acquis, the framework established by (EU) 2024/1620, (EU) 2024/1624, and (EU) 2024/1640 sets their compliance target.
When did AMLA start to apply?
From 1 July 2025. It directly supervises selected obliged parties in the financial sector, including crypto-asset service providers.
What do we do when a country-specific obligation is introduced?
It is written into the rule engine: nested logic, named aggregation definitions, and callbacks from rules are supported. The rule can be described in your own language and tested on historical traffic before going live.
Is there a local team in the region?
Bitrelic has a team in Podgorica: we track regulatory changes and authority expectations by having a physical presence in the region.
Where does the data reside?
In an on-premise deployment, within the institution's own information systems: keys and the audit trail are under the institution's control. Since data residency rules vary from country to country, this is a decisive factor in regional deployments.

Related