In Italy, financing companies that produce anti-personnel mines and cluster munitions has been prohibited since 2022, but the operating instructions for intermediaries only arrived on July 26, 2024. Since then, weapons and controversial business screening has moved out of the realm of voluntary policies and become a safeguard to be formalized, documented and demonstrated during inspections. For many banks, asset management companies, insurers and fintechs, however, it remains the last missing piece of the customer due diligence file.
What counts as a controversial business
There is no single list that applies to everyone. The scope is built in layers, combining legal bans and internal policy choices:
- Controversial weapons: anti-personnel mines, cluster munitions and submunitions, chemical and biological weapons. They are the only category for which Italy has an explicit financing ban.
- Military equipment: export, import and transit are subject to authorization under Law No. 185 of July 9, 1990.
- Dual-use items: civilian products with possible military applications, governed by Regulation (EU) 2021/821.
- Sectors with high reputational sensitivity: thermal coal, tobacco, gambling, extractive industries. Here there is no ban, only the exclusions set by investment and lending policies.
Weapons and controversial business screening: what the regulations require
The Italian reference is Law No. 220 of December 9, 2021, which prohibits any form of financial support to companies that produce or trade anti-personnel mines and cluster munitions, including their components. Article 3 tasks the supervisory authorities with issuing the implementing instructions: they were published jointly by the Bank of Italy, COVIP, IVASS and the Ministry of Economy and Finance (MEF) on July 26, 2024, with a six-month compliance period from their entry into force.
The instructions require authorized intermediaries to adopt proportionate procedural safeguards, calibrate them with a risk-based approach and formalize them in their internal rules, integrating them into the system of controls already required by sector regulations. In other words: not wanting to do it is not enough, you must be able to demonstrate how you check.
On top of this there is the sustainable finance front. Regulation (EU) 2019/2088 (SFDR) and Delegated Regulation (EU) 2022/1288 include exposure to controversial weapons among the mandatory indicators of principal adverse impacts, with the same substantive definition: anti-personnel mines, cluster munitions, chemical and biological weapons. The same data point therefore serves two different functions within the company, compliance and sustainability, and it pays to produce it only once with a shared methodology.
Why a list of names is not enough
The limitation of manual checks against an exclusion file is structural, not a matter of diligence. The manufacturer is almost never the counterparty in front of you:
- The financed company is a holding company, a foreign subsidiary or a joint venture vehicle, and production sits two or three levels further down the chain of control.
- Similar names, namesakes and transliterations generate false positives that eat up time and false negatives that weigh far more.
- The scope shifts: acquisitions, divestments and reorganizations change the map while the exclusion file grows stale.
- A one-time check at onboarding will not catch a company that enters the prohibited scope three years later.
What to do to become compliant
- Define the scope in writing: distinguish the legal ban from voluntary exclusions and specify which activities trigger it.
- Integrate the check into customer due diligence instead of running it as a parallel process: same file, same audit trail.
- Trace the corporate chain all the way to the beneficial owners and the operating subsidiaries, without stopping at the counterparty’s company name.
- Move from one-off checks to ongoing monitoring, with alerts on changes in ownership structure and activities.
- Record decisions: who decided, based on which sources, with what outcome. It is the part supervisors look at first.
- Train front-line staff, because the warning sign often comes from the relationship manager before it comes from a system.
How AegisX helps you
Our Clusterwatch was built precisely for this: identifying companies involved in the production of controversial weapons and returning a documented result, usable both for the safeguard required by Law 220/2021 and for sustainability reporting. When the risk depends on the group structure rather than the name, Lensis reconstructs the chain of control and the beneficial owner, so screening works on the right entity.
This is how we interpret AI-native RegTech: turning compliance into a strategic advantage, reducing manual work and raising the quality of evidence. Let’s talk: request a Clusterwatch demo and let’s assess the scope of your exposure together.
This article is for informational purposes only and does not constitute legal or compliance advice.





