This article covers the background and context. If you are looking for a breakdown of what each sector needs to provide and when, that is covered in our companion guide: The Central Bank's REQ by Sector: What to Prepare and When.
The REQ sits within the supervisory framework established by the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 to 2021, commonly referred to as the CJA 2010. This legislation obliges credit and financial institutions to have effective, risk-based AML/CFT frameworks in place covering customer due diligence, suspicious transaction reporting, governance, training, record keeping, and related processes. There is a separate but parallel obligation to comply with EU Council Regulations on financial sanctions measures.
The Central Bank's authority to require firms to submit the REQ comes from Section 22 of the Central Bank (Supervision and Enforcement) Act 2013, which gives it the power to require information from regulated entities for the purposes of performing its supervisory functions. This is not a voluntary disclosure process. A firm selected to submit a REQ is legally required to do so, and the Central Bank has been explicit in its guidance that follow-up action will be taken where submission deadlines are not met.
The REQ is built around three interconnected questions about a firm's AML/CFT/FS position.
The first is about the firm's business profile and the inherent risk it carries: the nature of the products and services it offers, the customer types it serves, the geographies it operates in or connects to, and the distribution channels it uses. These factors shape the baseline money laundering and terrorist financing risk the firm presents, regardless of what controls it has in place.
The second is about how the firm itself has assessed those risks. Does it have a formal, board-approved risk assessment? How does it categorise and rate its inherent risks? Has it identified the specific vulnerabilities in its own business model? The Central Bank is interested not only in the firm's conclusions but in whether it has genuinely engaged with this analysis.
The third is about the framework the firm actually has in place to manage those risks: its policies and procedures, its customer due diligence processes, its transaction monitoring approach, its training programme, its suspicious transaction reporting activity, and how it governs and tests all of the above.
These three elements together give the Central Bank a picture of both the risks a firm faces and how well-equipped it is to manage them. A firm with a high inherent risk profile but a correspondingly sophisticated control framework is in a different supervisory position from one where the risk profile and control framework are mismatched.
Understanding why the REQ matters requires understanding how the Central Bank approaches AML/CFT supervision more broadly. Rather than applying the same level of scrutiny uniformly to every regulated firm, the Central Bank takes a risk-based approach, directing its supervisory resources toward the firms and sectors that present the greatest risk of money laundering, terrorist financing, or financial sanctions breaches.
The REQ is one of the key data-gathering tools that makes this approach operational. By collecting structured information from firms about their risk profiles and their control frameworks, the Central Bank can identify where significant risks are inadequately managed, where a particular sector has vulnerabilities that warrant thematic attention, and which firms should be prioritised for deeper supervisory engagement.
The Central Bank has been clear in its public communications that it intends to use REQ data for three purposes: to identify firm-specific and sector-wide issues, to guide its supervisory strategy, and increasingly, to contribute to the new EU-level data requirements being established by the Anti-Money Laundering Authority (AMLA). This last point is worth noting, because it means REQ submissions are feeding into a supervisory architecture that extends beyond Ireland.
For much of the REQ's history, a single general questionnaire was used across all regulated firms, adapted at the margins for different firm types but largely consistent in structure and scope. This general REQ covered governance, risk assessment, policies and procedures, customer risk profiles, and suspicious transaction reporting activity.
The Central Bank has now begun moving to more detailed, sector-specific REQs, questionnaires designed for the specific products, services, and risk profiles relevant to particular types of regulated entity, rather than a one-size-fits-all format. As the Central Bank's own guidance notes, this change is driven by a desire to capture "more detailed and pertinent risk data" than the general format allows.
The first sector-specific REQ has been published for Payment Institutions and Electronic Money Institutions. Further sector-specific versions are being developed for other firm types, including trading firms and Crypto-Asset Service Providers, which are expected to receive enhanced REQs in the second half of 2026.
For firms currently operating under the general REQ format, the transition to a sector-specific version represents a significant increase in the depth and granularity of information being requested. The sector-specific questionnaires go considerably further into the detail of a firm's business model and its specific risk exposures than the general version.
The REQ does not sit in isolation. It is one component of the Central Bank's broader AML/CFT supervisory toolkit, which also includes thematic reviews, firm-specific inspections, and engagement with individual firms on specific issues raised by their supervisory profile.
The relationship between REQ submissions and other supervisory activity is worth understanding. A REQ is not a full inspection, and submitting a completed REQ does not mean a firm has been examined or cleared. What it does is provide the Central Bank with structured information that can inform where inspections and deeper supervisory engagement are directed. A firm whose REQ indicates a mismatch between its risk profile and its control framework is more likely to receive further supervisory attention than one where the picture is coherent and proportionate.
It also follows from this that the REQ is not a routine administrative exercise to be processed and filed away. The quality and accuracy of a firm's submission matters, both because the Central Bank will use it as a supervisory tool and because it reflects, in a documented form, how seriously the firm takes its AML/CFT obligations. Inconsistencies between what a REQ describes and what is actually found during an inspection can create significant problems.
The Central Bank's published guidance is clear that follow-up action is taken where deadlines are missed. It is equally clear about the standard expected in the substance of submissions. Firms are expected to have genuinely engaged with their AML/CFT risk assessment, not simply to have a document with a date and a signature on it, but to have identified the specific vulnerabilities relevant to their business model and to have a framework in place that genuinely addresses those vulnerabilities.
Policies and procedures are expected to be sufficiently detailed to be operationally meaningful. A generic policy statement about the importance of AML compliance is not what the REQ is designed to surface, it is looking for evidence that the firm's staff know what they are required to do and how to do it, that training is happening, that suspicious activity is being identified and reported correctly, and that the board or senior management is receiving meaningful information about the firm's AML/CFT risk position on an ongoing basis.
For firms with strong, well-maintained compliance frameworks, a REQ is a relatively straightforward opportunity to present an accurate picture of a genuinely functioning system. For firms where AML/CFT governance is less developed, the REQ can expose gaps that prompt urgent remediation, which is, in one sense, exactly what it is designed to do.
Whether your firm is completing a general REQ or preparing for one of the new sector-specific versions, the most useful starting position is to treat the process as a reflection of your actual AML/CFT/FS risk position rather than primarily as a documentation exercise.
That means starting with an honest review of whether the firm's risk assessment is genuinely current, board-approved, and reflective of its actual business model. It means confirming that policies and procedures are not only documented but operationally embedded and genuinely understood by the staff who need to apply them. And it means having reliable data to hand on the firm's customer risk profile, suspicious transaction reporting activity, and ongoing transaction monitoring, since the REQ will ask for this in specific, structured terms.
Getting organised well before the submission deadline, rather than assembling the picture under time pressure, consistently produces better outcomes. It also avoids the risk of discovering, close to the deadline, that data or documentation that the REQ requires simply does not exist in an accessible, current form.
For a detailed breakdown of what each type of regulated firm needs to prepare for its REQ submission, including the specific sections and deadlines that apply by sector, see our companion guide.
Read more: The Central Bank's REQ by Sector: What to Prepare and When