Skip to content
ProofVoltSend us a company

Four-eyes principle

Checked against the official texts on .

The four-eyes principle is a control under which a decision — for example approving a high-risk customer — takes effect only after a second, independent and authorised person has reviewed and confirmed it. EU anti-money-laundering law does not use the phrase, but several of its provisions require senior-management approval for higher-risk relationships.

Also called: two-person rule, dual control, maker-checker.

Why it matters for PSPs and EMIs

A single analyst approving a high-risk merchant is a single point of failure: one mistake, one conflict of interest or one pressure from sales, and the decision stands. A second approval makes the decision more robust and, just as important, makes it visible who approved what and on which evidence.

What the law says

  • Senior management approval for higher risk. AMLR Art. 34(4)(e): obtaining the approval of senior management to establish or continue the relationship is one of the enhanced due diligence measures.

  • Politically exposed persons. AMLR Art. 42(1)(a): senior management approval is required for occasional transactions or for establishing or continuing relationships with PEPs, and (Art. 46) with their family members and close associates.

  • Correspondent relationships. AMLR Art. 36: senior management approval before establishing new cross-border correspondent relationships involving the execution of payments with a third-country respondent institution.

  • Who counts as senior management. AMLR Art. 2(1)(40): members of the management body in its management function, and officers and employees with sufficient knowledge of the firm's ML/TF risk exposure and sufficient seniority to take decisions affecting it.

  • Human intervention for automated decisions. AMLR Art. 76(5)(b): decisions resulting from automated processes or AI systems on entering, refusing or maintaining a relationship must be subject to meaningful human intervention.

  • In the AI Act. AI Act Art. 14(5) requires verification by at least two natural persons, but only for remote biometric identification systems (Annex III point 1(a)); it is not a general rule for compliance tools.

How ProofVolt handles it

ProofVolt supports role-based access and four-eyes approvals: approvals can require a second pair of eyes where the risk requires it. The case record shows every source, step and decision in an append-only trail.

Sources

Informational only, not legal advice.