
EU AML Regulation (AMLR): Requirements and Implementation Guide 2027
The EU Anti-Money Laundering Regulation, commonly referred to as the AMLR, introduces directly applicable anti-money laundering and counter-terrorist financing requirements across the European Union.
Regulation (EU) 2024/1624 applies from 10 July 2027. Football agents and specified activities of professional football clubs fall within the regime from 10 July 2029. Unlike an EU directive, the AMLR does not first have to be transposed into national law before it becomes applicable. It is binding in its entirety and directly applicable in all EU Member States. (EUR-Lex)
The AMLR does not merely restate existing anti-money laundering regulations. It establishes a more harmonised EU framework covering:
- internal AML/CFT governance;
- business-wide risk assessments;
- customer due diligence;
- beneficial ownership;
- simplified and enhanced due diligence;
- politically exposed persons;
- targeted financial sanctions;
- ongoing and transaction monitoring;
- suspicious transaction reporting;
- group-wide AML/CFT controls;
- outsourcing;
- data protection; and
- record retention.
For obliged entities, the central implementation question is therefore no longer whether the AMLR will affect their AML compliance framework. The question is whether their governance, data, procedures, systems and controls will be demonstrably compliant by 10 July 2027.
AMLR key facts
| Question | Answer |
|---|---|
| What is the AMLR? | Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering or terrorist financing |
| When does it apply? | Generally from 10 July 2027 |
| Is national transposition required? | No. The Regulation is directly applicable |
| Who must comply? | Financial institutions and a broad range of designated non-financial businesses and professions |
| What is the main objective? | A more uniform EU AML/CFT Single Rulebook |
| Who develops detailed standards? | AMLA, with certain technical standards subsequently adopted by the European Commission |
| What should obliged entities do now? | Conduct an AMLR gap assessment and implement the resulting legal, organisational, procedural, data and technology changes |
What is the EU AML Regulation?
The AMLR is the core private-sector rulebook within the EU’s new AML/CFT legislative package. It was adopted because obligations previously contained in directives had been implemented differently across Member States. The Regulation transfers many requirements applying directly to obliged entities into a single EU legal instrument intended to reduce national fragmentation. (EUR-Lex)
The wider legislative package comprises four principal instruments:
| Instrument | Main function |
|---|---|
| Regulation (EU) 2024/1624 — AMLR | Direct obligations for obliged entities, including governance, risk assessment, CDD, monitoring, reporting and beneficial ownership |
| Directive (EU) 2024/1640 — AMLD6 | National supervisory systems, Financial Intelligence Units, beneficial ownership registers and institutional arrangements |
| Regulation (EU) 2024/1620 — AMLA Regulation | Establishment, powers and responsibilities of the EU Anti-Money Laundering Authority |
| Regulation (EU) 2023/1113 | Information accompanying transfers of funds and certain crypto-assets |
The AMLR must therefore be read together with AMLD6, the AMLA Regulation, the Transfer of Funds Regulation, applicable delegated and implementing acts, and relevant national provisions. AMLD6 continues to require national implementation because it governs mechanisms that Member States must establish, while the AMLR lays down requirements that apply directly to obliged entities. (EUR-Lex)
Who is subject to the AMLR?
Article 3 AMLR defines the entities that fall within the Regulation’s scope. The regulated population includes credit institutions, financial institutions and numerous categories of designated non-financial businesses and professions.
The scope includes, among others:
- banks and other credit institutions;
- payment institutions;
- electronic money institutions;
- investment firms;
- asset management companies and collective investment undertakings;
- relevant insurance undertakings and intermediaries;
- credit providers and certain credit intermediaries;
- crypto-asset service providers;
- auditors, external accountants and tax advisers;
- lawyers, notaries and other independent legal professionals when conducting specified transactions;
- trust or company service providers;
- real estate professionals;
- providers of gambling services;
- crowdfunding platforms and intermediaries;
- persons trading in precious metals, precious stones and specified high-value goods;
- investment migration operators;
- certain mixed-activity holding companies;
- football agents; and
- professional football clubs in relation to specified transactions.
Professional football clubs and football agents are subject to the later application date of 10 July 2029, with limited possibilities for Member States to exempt certain lower-risk football clubs. (EUR-Lex)
An organisation should not determine its status solely by reference to its corporate label. It must map its actual services, permissions, professional activities, customer relationships and transaction types against Article 3 and the definitions in Article 2 AMLR.
What are the most important AMLR requirements?
1. Written AML policies, procedures and controls
Article 9 AMLR requires obliged entities to maintain internal policies, procedures and controls that ensure compliance with the AMLR, Regulation (EU) 2023/1113 and applicable supervisory acts.
The framework must be proportionate to the nature, size, risks and complexity of the business and must cover all activities falling within the scope of the AMLR.
The required framework includes, in particular:
- the business-wide risk assessment;
- the AML/CFT risk management framework;
- customer due diligence procedures;
- procedures for identifying PEPs, family members and close associates;
- suspicious transaction reporting;
- outsourcing and reliance arrangements;
- record-retention and data-protection procedures;
- controls for identifying and remediating deficiencies;
- employee integrity measures;
- internal communication;
- employee training;
- compliance monitoring; and
- independent testing of policies, procedures and controls.
The policies, procedures and controls must be documented in writing. Policies require approval by the management body in its management function, while procedures and controls must be approved at least at the level of the compliance manager. They must be updated and improved when weaknesses are identified. (EUR-Lex)
Implementation consequence: A collection of legacy AML policies is not sufficient. Each policy and procedure must be mapped to the AMLR, assigned to an accountable owner, approved at the correct level and supported by operational controls and evidence of implementation.
2. Business-wide risk assessment
Article 10 AMLR requires obliged entities to identify and assess:
- money laundering risks;
- terrorist financing risks; and
- risks of non-implementation or evasion of targeted financial sanctions.
The business-wide risk assessment must consider the risk variables and factors in Annexes I to III AMLR, the EU-level risk assessment, national and sector-specific risk assessments, information from competent authorities, relevant publications and the composition of the entity’s customer base.
The assessment must also cover risks arising before the launch of:
- new products;
- new services;
- new business practices;
- new delivery channels;
- new or developing technologies;
- services offered to new customer segments; and
- activities in new geographical areas.
The business-wide risk assessment must be documented, kept up to date, regularly reviewed and reassessed where internal or external developments materially affect the entity’s exposure. It is drawn up by the compliance officer and approved by the management body in its management function. (EUR-Lex)
Implementation consequence: The assessment should establish a traceable connection between inherent risks, existing controls, control effectiveness, residual risks and the entity’s risk-mitigation programme. A generic sector risk assessment that is not connected to the entity’s products, customers, channels, countries and controls will not meet the underlying requirement.
3. Compliance manager and compliance officer
Article 11 AMLR distinguishes between the compliance manager and the compliance officer.
The compliance manager is a member of the management body in its management function who is responsible for ensuring compliance with the AMLR. The compliance manager must ensure that the organisation’s policies, procedures and controls are aligned with its risk exposure and that sufficient human and material resources are provided.
The compliance officer is responsible for the day-to-day operation of the AML/CFT framework, including targeted financial sanctions and suspicious transaction reporting. The compliance officer must have sufficiently high hierarchical standing and act as a contact point for competent authorities.
The compliance function must receive adequate staff, technology, information, powers and direct reporting access. The compliance officer must also be protected against retaliation, unfair treatment and undue influence from commercial interests. (EUR-Lex)
Implementation consequence: Obliged entities should formally document the division of responsibilities between the management body, compliance manager, compliance officer, business functions, operations, technology, data management and internal audit.
4. Customer due diligence
Article 19 AMLR defines when customer due diligence must be applied. CDD is required, among other circumstances:
- when establishing a business relationship;
- when carrying out an occasional transaction of at least EUR 10,000, whether in one operation or linked operations;
- when participating in the creation of certain legal entities or legal arrangements;
- when there is a suspicion of money laundering or terrorist financing; or
- when there are doubts about previously obtained customer identification data.
For occasional cash transactions of at least EUR 3,000, the obliged entity must apply at least the customer identification and identity-verification measures specified in Article 20(1)(a) AMLR. (EUR-Lex)
Article 20 requires obliged entities to perform a comprehensive set of CDD measures, including:
- identifying and verifying the customer;
- identifying and verifying beneficial owners;
- understanding the ownership and control structure;
- understanding the purpose and intended nature of the relationship or transaction;
- checking whether customers and beneficial owners are subject to targeted financial sanctions;
- identifying relevant ownership or control by sanctioned persons;
- understanding the customer’s business, employment or occupation;
- conducting ongoing monitoring;
- identifying PEPs, family members and close associates;
- identifying persons for whose benefit a transaction is conducted; and
- identifying and verifying authorised representatives.
The extent of these measures must be determined through an individual analysis of the customer and relationship risk. Obliged entities must be able to demonstrate to supervisors that the measures applied were appropriate for the risks identified. (EUR-Lex)
5. Consequences of incomplete CDD
Where an obliged entity cannot complete the required CDD measures, Article 21 AMLR generally requires it to:
- refrain from carrying out the transaction;
- refrain from establishing the business relationship;
- terminate an existing business relationship; and
- consider submitting a suspicious transaction report to the FIU.
The entity must document the steps taken, the decision reached, the supporting evidence and the justification. Similar documentation is required where a prospective customer is rejected or an existing relationship is terminated. (EUR-Lex)
Implementation consequence: Customer onboarding and periodic review systems must not merely show that a case is incomplete. They should enforce the required consequence, record the decision and preserve evidence of escalation, rejection, restriction or termination.
6. Beneficial ownership identification
Under Articles 51 and 52 AMLR, a beneficial owner is a natural person who directly or indirectly:
- holds an ownership interest in a legal entity; or
- controls the legal entity through ownership or other means.
An ownership interest generally means 25% or more of the shares, voting rights or another ownership interest. Indirect interests must be calculated through the ownership chain. Control through other means must be analysed independently and in parallel with ownership interests.
Relevant control indicators include majority voting rights, rights to appoint or remove a majority of the management or supervisory body, relevant veto or decision rights, formal or informal agreements, family relationships and nominee arrangements. (EUR-Lex)
When entering into a new business relationship with a legal entity or relevant legal arrangement subject to beneficial ownership registration, the obliged entity must obtain valid proof of registration or a recently issued register excerpt.
Where information collected by the obliged entity conflicts with the beneficial ownership register, discrepancies generally have to be reported without undue delay and no later than 14 calendar days after detection. (EUR-Lex)
Implementation consequence: A register extract alone is not a complete beneficial ownership assessment. The obliged entity must perform its own ownership and control analysis, verify the natural persons identified and address inconsistencies.
7. Simplified and enhanced due diligence
The AMLR retains a risk-based distinction between standard, simplified and enhanced due diligence.
Simplified due diligence may be applied only where a lower-risk situation has been identified and documented. It does not permit the complete omission of customer due diligence. Sufficient monitoring must continue so that unusual or suspicious transactions can be detected.
Simplified measures must not be applied where:
- customer information is doubtful or inconsistent;
- lower-risk factors no longer exist;
- transaction monitoring contradicts the lower-risk classification;
- money laundering or terrorist financing is suspected; or
- targeted financial sanctions may be circumvented.
Enhanced due diligence is required in prescribed circumstances and in other higher-risk situations identified through the individual customer risk assessment.
Depending on the risk, enhanced measures can include:
- additional information about the customer and beneficial owners;
- additional information about the intended nature of the relationship;
- information and evidence concerning source of funds;
- information and evidence concerning source of wealth;
- information about the reasons for transactions;
- senior management approval;
- more frequent or intensive controls; and
- selection of transaction patterns for closer examination.
The AMLR also requires closer examination of transactions that are complex, unusually large, conducted in an unusual pattern or lacking an apparent economic or lawful purpose. (EUR-Lex)
8. Ongoing monitoring and customer information updates
Article 26 AMLR requires continuous monitoring of business relationships and customer transactions. The purpose is to determine whether activities remain consistent with the obliged entity’s knowledge of the customer, business activity, risk profile and, where necessary, the origin and destination of funds.
Customer documents, data and information must be kept up to date. The period between reviews must be risk-sensitive but may not exceed:
- one year for higher-risk customers subject to enhanced due diligence; and
- five years for all other customers.
These are maximum periods, not automatic waiting periods. Customer information must also be reviewed and, where necessary, updated when:
- the customer’s relevant circumstances change;
- another legal obligation requires the entity to contact the customer; or
- the obliged entity becomes aware of a relevant new fact.
Targeted financial sanctions status must be checked regularly. For credit institutions and financial institutions, an additional check is required following any new sanctions designation. (EUR-Lex)
Implementation consequence: Obliged entities need both a periodic review mechanism and an event-driven update process. A review calendar without reliable triggers for ownership changes, new PEP status, sanctions events, activity changes or altered geographical exposure is insufficient.
9. Suspicious transaction reporting
Article 69 AMLR requires obliged entities to report promptly to the competent FIU where they know, suspect or have reasonable grounds to suspect that funds or activities:
- are proceeds of criminal activity;
- are connected with criminal activity; or
- are related to terrorist financing.
The obligation applies regardless of the amount involved. It includes attempted transactions and suspicions arising from an inability to complete customer due diligence.
Obliged entities must also provide requested information, including transaction records, within the deadlines imposed by the FIU. The standard AMLR response period is five working days, although FIUs may impose shorter deadlines, including less than 24 hours in justified and urgent cases. (EUR-Lex)
Implementation consequence: Monitoring and case-management processes must preserve the complete path from alert to assessment, decision, report and post-report controls. The entity must also be operationally capable of responding quickly to FIU information requests.
10. Record retention and data protection
Article 77 AMLR requires the retention of:
- CDD information and documentation;
- electronic identification information;
- assessments of unusual or suspicious activity;
- copies of suspicious transaction reports;
- transaction evidence and records; and
- information exchanged within approved information-sharing partnerships.
These records must generally be retained for five years from the end of the business relationship, the occasional transaction or the refusal to establish the relationship or perform the transaction. Personal data must generally be deleted when the retention period expires, although competent authorities may require an additional case-specific period of up to five years. (EUR-Lex)
The AMLR permits the processing of special categories of personal data and data relating to criminal convictions only under specified safeguards. Data must come from reliable sources, be accurate and up to date, and be protected through an appropriately high level of security.
Where automated systems or AI support customer decisions, meaningful human intervention is required for decisions to establish, refuse, continue or terminate relationships and to increase or decrease the extent of CDD. Customers must generally be able to obtain an explanation and challenge the decision, except in relation to suspicious transaction reporting. (EUR-Lex)
11. Group-wide AML/CFT requirements
A parent undertaking must perform a group-wide risk assessment and establish group-wide policies, procedures and controls.
These requirements must extend to branches and subsidiaries in Member States and, for EU-headquartered groups, to relevant establishments in third countries. Group-wide arrangements must address data protection, AML/CFT information sharing, risk assessment, policies, controls and employee awareness. (EUR-Lex)
Implementation consequence: Groups need a consolidated view of their AML/CFT risks. Local risk assessments and policies cannot remain isolated documents without group aggregation, governance and controlled information exchange.
12. Outsourcing
Article 18 AMLR permits outsourcing of certain AML/CFT tasks, but the obliged entity remains fully liable for the service provider’s acts and omissions.
The obliged entity must understand the rationale and methodology used by the provider, monitor performance and ensure that outsourced activities mitigate the entity’s specific risks.
Certain decisions cannot be outsourced, including:
- proposing and approving the business-wide risk assessment;
- approving internal AML/CFT policies, procedures and controls;
- deciding the customer risk profile;
- deciding whether to enter into a business relationship;
- deciding whether to carry out an occasional transaction;
- reporting suspicious activity, subject to limited group exceptions; and
- approving criteria for detecting unusual or suspicious transactions.
The arrangement must be governed by a written agreement, and the service provider must be sufficiently qualified. (EUR-Lex)
Implementation consequence: Vendor contracts alone are not sufficient. Obliged entities need documented pre-outsourcing due diligence, task allocation, data-access arrangements, performance indicators, control rights, escalation procedures, sub-outsourcing rules and exit planning.
13. EU-wide limit on large cash payments
Article 80 AMLR establishes a general EU limit of EUR 10,000 for cash payments made or received by persons trading in goods or providing services. Linked operations are aggregated for this purpose.
Member States may adopt or retain lower national limits. The EU limit does not apply to private payments between natural persons who are not acting professionally or to specified payments and deposits made at credit institutions, electronic money issuers and payment service providers. (EUR-Lex)
What changes under the AMLR?
The most important structural change is the transition from nationally transposed requirements to a more directly applicable EU rulebook.
For obliged entities, the AMLR creates greater consistency but not complete legal uniformity. National provisions remain relevant where the AMLR permits Member States to introduce additional or stricter requirements, and AMLD6 requires national legislation concerning supervision, FIUs, registers and institutional mechanisms.
Operationally, the AMLR introduces or strengthens several areas that require particular attention:
| Area | Implementation impact |
|---|---|
| Governance | Formal allocation of responsibility to a compliance manager and compliance officer |
| Risk assessment | Explicit inclusion of targeted financial sanctions implementation and evasion risks |
| Customer risk | Individual risk analysis linked to the business-wide risk assessment |
| CDD data | More harmonised information and verification expectations |
| Beneficial ownership | Parallel analysis of ownership and control through other means |
| Monitoring | Defined maximum customer information refresh periods |
| Sanctions | Integration of targeted financial sanctions into governance, CDD and monitoring |
| Evidence | Stronger requirement to demonstrate that measures are proportionate to identified risk |
| Technology | Increased importance of data quality, workflow controls, audit trails and human oversight |
| Group governance | Consolidated group-wide risks, policies and information sharing |
| Outsourcing | Explicit restrictions on outsourcing core AML/CFT decisions |
AMLR implementation roadmap for 2027
A compliant implementation programme should not be limited to updating policy wording. It should convert the Regulation into an operational target state supported by governance, processes, systems, data and control evidence.
Phase 1: Determine scope and establish governance
The organisation should:
- confirm its status as an obliged entity;
- identify all in-scope legal entities, branches and services;
- appoint the executive-level compliance manager;
- confirm or appoint the compliance officer;
- establish a formal AMLR implementation steering structure;
- define workstream owners and reporting lines;
- allocate budget, staff and technology resources; and
- establish a complete inventory of applicable AMLR requirements.
Required evidence: scope assessment, governance resolution, role descriptions, responsibility matrix, programme charter and implementation plan.
Phase 2: Conduct an article-by-article gap assessment
Each relevant AMLR obligation should be mapped against:
- existing policies;
- existing procedures;
- systems and data fields;
- manual controls;
- automated controls;
- control owners;
- evidence produced;
- existing legal or operational gaps; and
- required remediation.
The assessment should distinguish between:
- missing requirements;
- insufficiently designed controls;
- controls that are appropriately designed but not implemented;
- controls that operate inconsistently; and
- controls for which operating effectiveness has not been demonstrated.
Required evidence: legal requirements inventory, control matrix, gap register, remediation plan and management-approved prioritisation.
Phase 3: Redesign the risk framework
The business-wide risk assessment should be aligned with Article 10 AMLR and connected to:
- customer risk classification;
- product and service risk;
- geographical risk;
- delivery-channel risk;
- transaction risk;
- targeted financial sanctions risk;
- new-product approval;
- risk appetite;
- enhanced controls; and
- management reporting.
Required evidence: BWRA methodology, risk taxonomy, scoring model, data sources, control assessment, residual-risk methodology and management approval.
Phase 4: Redesign CDD and customer-risk processes
The organisation should determine whether its systems and procedures can capture, validate and evidence all required CDD information.
Particular attention should be paid to:
- customer identification attributes;
- authorised representatives;
- beneficial ownership and control structures;
- purposes and intended nature of relationships;
- business, occupation and employment data;
- PEP, family member and close-associate status;
- targeted financial sanctions;
- source of funds and source of wealth;
- persons on whose behalf transactions are conducted;
- individual customer risk assessments;
- reasons for applying SDD, CDD or EDD; and
- consequences of incomplete CDD.
Required evidence: data dictionary, onboarding forms, verification standards, process maps, decision rules, workflow specifications and sample customer files.
Phase 5: Implement ongoing and transaction monitoring
Monitoring arrangements should combine:
- customer information updates;
- periodic review schedules;
- event-driven review triggers;
- transaction and activity monitoring;
- sanctions rescreening;
- PEP rescreening;
- unusual activity detection;
- alert investigation;
- escalation;
- suspicious transaction reporting; and
- post-report account controls.
The process must be proportionate to risk while remaining capable of detecting unexpected or suspicious activity.
Required evidence: monitoring framework, scenario inventory, threshold rationale, customer segmentation, review calendar, event triggers, alert procedures, case records and performance reporting.
Phase 6: Update policies, procedures and training
The organisation should revise all relevant AML/CFT documents and ensure consistent terminology, roles, risk classifications, thresholds, controls and escalation requirements.
Training should be role-specific rather than limited to one general AML course. Separate content may be required for:
- management bodies;
- AML compliance;
- customer onboarding;
- operations;
- transaction monitoring;
- sanctions teams;
- relationship managers;
- information technology;
- data management;
- internal audit; and
- outsourced service providers.
Required evidence: approved policies, operating procedures, communication records, training materials, attendance evidence and competence assessments.
Phase 7: Test implementation and remediate weaknesses
Before 10 July 2027, obliged entities should test both:
- design effectiveness: whether the control is capable of preventing, detecting or correcting the relevant AML/CFT risk; and
- operating effectiveness: whether the control has been implemented and operated consistently over an appropriate period.
Testing should cover governance, risk assessment, CDD, beneficial ownership, PEPs, sanctions, SDD, EDD, monitoring, reporting, record retention, outsourcing and group-wide requirements.
Required evidence: test plans, samples, test results, deficiencies, root-cause analyses, remediation evidence and management sign-off.
AMLR implementation checklist
| Workstream | Minimum implementation action |
|---|---|
| Scope | Confirm all legal entities, branches, services and professional activities covered by Article 3 |
| Governance | Appoint and document the compliance manager and compliance officer |
| Resources | Demonstrate adequate personnel, technology, data and budget |
| Policies | Map and update all internal policies against Article 9 |
| BWRA | Implement a documented Article 10 business-wide risk assessment |
| Customer risk | Establish an individual customer risk assessment under Article 20(2) |
| CDD | Capture and verify all required customer, representative and beneficiary data |
| Beneficial ownership | Analyse ownership and control through other means |
| Register checks | Obtain proof of registration and implement discrepancy reporting |
| PEPs | Identify customers, beneficial owners, family members and close associates |
| Sanctions | Integrate targeted financial sanctions into risk assessment, CDD and monitoring |
| SDD | Define lower-risk eligibility, measures, monitoring and exit triggers |
| EDD | Define higher-risk triggers, evidence, approvals and enhanced monitoring |
| Monitoring | Establish periodic and event-driven customer review processes |
| Transactions | Calibrate transaction and activity monitoring to customer risk |
| Reporting | Implement FIU reporting, response and tipping-off controls |
| Records | Retain required evidence for the prescribed period and delete it when required |
| Data protection | Establish lawful processing, accuracy, security and access controls |
| Automation | Provide meaningful human intervention and explainability |
| Outsourcing | Review contracts, retained responsibility and non-outsourcable decisions |
| Group-wide controls | Establish consolidated risk assessment, policies and information sharing |
| Staff | Implement integrity screening and role-specific training |
| Assurance | Test design and operating effectiveness before July 2027 |
AMLA technical standards and guidelines
The AMLR is supplemented by Regulatory Technical Standards, Implementing Technical Standards and AMLA guidelines.
During 2026, AMLA consulted on several implementation instruments, including:
- criteria for identifying business relationships, occasional transactions and linked transactions;
- customer due diligence information and documents;
- business-wide risk assessment;
- group-wide AML/CFT requirements;
- ongoing monitoring and transaction monitoring; and
- harmonised formats for suspicious transaction reporting and transaction records.
As of 5 August 2026, the consultation on AMLA’s draft ongoing-monitoring guidelines remains open until 3 September 2026, while the consultation on the common format for reporting suspicions remains open until 20 September 2026. Several earlier consultations, including CDD, business relationships, BWRA and group-wide requirements, have closed and are progressing through the finalisation process. (Finanzkontrolle AML/CFT)
The transfer of AML/CFT mandates from the EBA to AMLA was completed on 1 January 2026. Existing EBA AML/CFT guidelines and standards remain in force until they are replaced by AMLA, supporting regulatory continuity during the transition. (Finanzkontrolle AML/CFT)
Obliged entities should therefore distinguish carefully between:
- the binding text of the AMLR;
- adopted delegated and implementing acts;
- final AMLA guidelines;
- existing EBA instruments that remain applicable; and
- consultation drafts that may still change.
Common AMLR implementation mistakes
Treating implementation as a policy-only project
Updating written policies without changing systems, workflows, data fields, controls and evidence will not establish compliance.
Starting with CDD before completing the risk framework
Customer due diligence must be calibrated to the entity’s business-wide risks and the individual customer risk analysis. CDD cannot be redesigned reliably without first establishing those foundations.
Relying exclusively on beneficial ownership registers
The AMLR requires the obliged entity to understand ownership and control. Register information is a source of information, not a substitute for the entity’s own assessment.
Confusing periodic reviews with event-driven reviews
The one-year and five-year periods are maximum review intervals. Relevant changes and new facts require earlier reassessment.
Outsourcing accountability
Technology vendors and service providers may perform tasks, but the obliged entity remains responsible. Core risk and customer decisions cannot simply be transferred to an external provider.
Failing to preserve decision evidence
A compliant outcome without supporting evidence may not be demonstrable to a supervisor. Risk classifications, CDD decisions, SDD and EDD pathways, monitoring dispositions and reporting decisions require an auditable rationale.
Waiting for every technical standard to become final
The core AMLR obligations are already known. Entities should implement the binding baseline now and manage later technical changes through a controlled regulatory-change process.
Frequently asked questions
When does the EU AML Regulation apply?
The AMLR generally applies from 10 July 2027. It applies to football agents and the specified activities of professional football clubs from 10 July 2029. (EUR-Lex)
Is the AMLR directly applicable?
Yes. Regulation (EU) 2024/1624 is binding in its entirety and directly applicable in all EU Member States. National transposition is not required for the Regulation itself. (EUR-Lex)
Does the AMLR replace all national AML laws?
No. The AMLR harmonises many obligations applying to obliged entities, but national legislation remains relevant. AMLD6 requires Member States to establish national supervisory, FIU, registration and institutional mechanisms, and the AMLR permits national rules in specified areas.
What is the difference between AMLR, AMLD6 and AMLA?
The AMLR establishes directly applicable requirements for obliged entities. AMLD6 governs mechanisms that Member States must establish. AMLA is the EU authority responsible for completing the Single Rulebook, promoting supervisory convergence, coordinating FIUs and directly supervising selected financial-sector entities under the separate AMLA Regulation. (EUR-Lex)
What is a business-wide risk assessment?
The business-wide risk assessment identifies and evaluates the money laundering, terrorist financing and targeted-financial-sanctions risks to which an obliged entity is exposed. It must reflect the entity’s customers, services, products, transactions, delivery channels, geographical exposure and relevant internal and external risk information. (EUR-Lex)
How often must customer information be updated?
The maximum period is one year for higher-risk customers and five years for other customers. Relevant changes, legal review obligations and new facts can require an earlier update. (EUR-Lex)
Is the beneficial ownership threshold still 25%?
The AMLR generally defines an ownership interest as direct or indirect ownership of 25% or more of shares, voting rights or another ownership interest. However, ownership is only one part of the assessment. Control through other means must be analysed independently and in parallel. (EUR-Lex)
What should obliged entities complete before July 2027?
At minimum, they should complete:
- an AMLR scope assessment;
- an article-by-article gap analysis;
- a revised business-wide risk assessment;
- an updated customer-risk methodology;
- redesigned CDD, SDD and EDD processes;
- revised ongoing and transaction monitoring;
- updated policies and procedures;
- required system and data changes;
- staff training; and
- independent readiness testing.
AMLR implementation must now become operational
The EU AML Regulation creates a common legal baseline for AML compliance across the European Union. Its direct application from 10 July 2027 means that obliged entities must be able to demonstrate more than formal policy alignment.
A credible AMLR implementation programme must connect:
- legal requirements;
- governance and accountability;
- business-wide and customer risk assessments;
- CDD data and evidence;
- beneficial ownership;
- sanctions and PEP controls;
- ongoing and transaction monitoring;
- FIU reporting;
- systems and data;
- group-wide controls; and
- independent effectiveness testing.
The organisations best prepared for 2027 will be those that treat the AMLR as an enterprise-wide operating-model transformation rather than a narrow compliance-documentation exercise.
Is your AML/CFT framework ready for the AMLR?
An AMLR readiness assessment identifies legal, procedural, organisational, data and technology gaps before the Regulation becomes applicable on 10 July 2027.
The assessment should cover the business-wide risk assessment, governance, CDD, beneficial ownership, customer risk classification, SDD, EDD, PEP and sanctions controls, ongoing monitoring, transaction monitoring, reporting, outsourcing and group-wide requirements.