us

216.73.216.229

Back
Blogs

EU AMLA Regulation: A Compliance Preparation Guide For Obliged Entities

EU AMLA Regulation: A Compliance Preparation Guide For Obliged Entities
Amir RizwanAmir Rizwan MAY 24, 2026 13 minutes read

For as long as the European Union has had anti-money laundering rules, the supervisor asking the questions has been a national one. A German bank answered to BaFin, a French one to the ACPR, and a Maltese payment institution to the MFSA, each of them applying a directive that its own parliament had transposed in its own words.

That arrangement ends for a defined group of firms in 2028. On 12 May 2026 the EU Anti-Money Laundering Authority (AMLA) published the reporting package that national supervisors are now using to identify which firms fall inside the eligible pool, with data due back to Frankfurt by 15 August 2026 and a provisional list expected by the end of September.

What is AMLA in the EU?

AMLA is the European Union’s central anti-money laundering supervisor, established by Regulation (EU) 2024/1620 and seated in Frankfurt under Article 4 of that regulation. It is the first body in the bloc’s history with the power to supervise individual financial institutions for money laundering and terrorist financing risk directly, rather than through a national authority acting as an intermediary. The regulation was adopted on 31 May 2024, entered into force on 26 June 2024, and has applied since 1 July 2025, with a small group of articles applying from earlier or later dates set out in Article 108.

Where AMLA sits in the EU AML Package

The EU AML package is the collective name for four instruments that replace the patchwork built up across five successive anti-money laundering directives. Recital 4 of the AMLA regulation names them together, and each one carries a distinct job. Anyone who reads one of them in isolation will form a misleading picture, because the authority created by the first instrument is the body that enforces the rulebook written in the second.

Instrument What it does When it applies
Regulation (EU) 2024/1620 (AMLAR) Creates AMLA, defines its supervisory powers, sanctioning ceilings, and funding In force 26 June 2024, applies from 1 July 2025
Regulation (EU) 2024/1624 (AMLR) The single rulebook. Directly applicable due diligence, beneficial ownership, and reporting obligations 10 July 2027, with football agents and clubs deferred to 10 July 2029
Directive (EU) 2024/1640 (AMLD6) National supervisory architecture, registers, and FIU powers, transposed into member state law Transposition by 10 July 2027, with certain register-access provisions applying from 10 July 2026
Regulation (EU) 2023/1113 Information accompanying transfers of funds and crypto-assets, the EU travel rule 30 December 2024

Since the AMLR is a regulation rather than a directive, it takes effect in identical wording in all 27 member states without transposition. This single change removes the divergence that has allowed a group to run materially different customer due diligence standards in Dublin and in Vilnius while remaining compliant in both.

Shufti’s EU AMLR compliance guide covers the rulebook obligations in detail, and this article stays with the authority that will police them.

Why the EU built a supervisor instead of another directive?

The reasoning is set out in the regulation’s recitals and reflects a decade of enforcement history in which the largest failures were cross-border and the supervision was not. Successive scandals involving Baltic branch networks of Nordic banks turned on the same structural weakness, because a branch supervised lightly in one jurisdiction could carry risk that materialised in another, and no single authority held the whole file. AMLA exists to close that gap by holding the group-level view that no national supervisor could assemble on its own.

What does the EU AMLA regulation cover?

The EU AMLA regulation covers four separate functions which are set out in Article 5 and built out across four sections of Chapter II. Only the first of them involves AMLA supervising a firm directly, which is the distinction most commentary blurs.

Understanding the AMLA supervision scope therefore means separating the population the authority polices itself from the far larger population it reaches through somebody else.

Direct supervision of selected obliged entities

Articles 12 to 29 give AMLA the full supervisory toolkit over a limited group of credit institutions and financial institutions known as selected obligated entities. Under Article 6(1), AMLA holds the powers specified in Articles 17 to 21, which run from requests for information and general investigations through to on-site inspections and administrative measures.

Article 21(3)(e) goes as far as a temporary ban on an individual exercising managerial responsibilities, which means the authority can reach the people running a firm and not only its policies.

Indirect supervision of non-selected financial entities

Articles 30 to 34 cover the far larger population of financial sector firms that AMLA does not supervise directly. Here the authority works through national supervisors by setting standards, running thematic reviews, and requesting action.

Article 32 provides a sort of an escape hatch where indications of serious, repeated or systematic breaches emerge, because AMLA may ask the European Commission for permission to take over supervision of that firm temporarily, for a maximum of three years and extendable once.

Oversight of the non-financial sector

Articles 35 to 38 address the accountants, notaries, lawyers, real estate agents, trust and company service providers, and dealers in high-value goods that make up the non-financial population. AMLA cannot supervise a designated non-financial business or profession directly at all. Its role is limited to peer reviews of the supervisors and self-regulatory bodies that oversee those sectors, together with recommendations and, where a supervisor does not act, a public warning. Firms in this category will feel AMLA through a more demanding national supervisor rather than through a letter from Frankfurt.

The support and coordination mechanism for FIUs

Articles 39 to 48 establish AMLA as the hub for the bloc’s financial intelligence units, including joint analyses of cross-border cases and the hosting of the FIU communication system. This matters to reporting firms indirectly, because a suspicious transaction report filed in one member state becomes far more likely to be read alongside related reports filed elsewhere.

Four AMLA functions: direct, indirect, non-financial, and FIU support.

Which Firms will AMLA Supervise Directly?

AMLA will directly supervise credit institutions and financial institutions, or groups of them, that operate in at least six member states and carry a high residual risk classification. Article 12(1) sets the first test in precise terms, it also covers entities that operate “whether through establishments or under the freedom to provide services, in at least six member states, including the home Member State, regardless of whether the activities are carried out through infrastructure on the territory concerned or remotely.”

That last clause deserves attention from any payment institution, e-money institution, or crypto-asset service provider passporting across the bloc from a single licence. A firm with one office and 25 passported markets sits inside the eligibility pool just as squarely as a bank with its branches spread across six countries.

The second test is where most published summaries go wrong. A widely repeated claim holds that an entity must be assessed as high risk in a specified number of member states, and no such test exists in the final text.

Article 12(3) requires supervisors to classify inherent and residual risk profiles as low, medium, substantial or high, assessed at group-wide level where the entity belongs to a group. Article 13(1) then provides that entities

“whose residual risk profile has been classified as high pursuant to Article 12 shall qualify as selected obliged entities.”

One group-wide high residual classification is the trigger, and residual rather than inherent risk is what counts, which places the quality of a firm’s controls at the centre of whether it is captured.

The cap of 40 entities is also misplaced in most accounts. Article 13(2) actually permits AMLA to agree to a number greater than 40 in later cycles. The hard ceiling applies only to the first round, through the transitional provision at Article 106(2), which directs the authority to take “the 40 obliged entities or groups operating in the highest number of Member States” where more than 40 would otherwise qualify. Firms should therefore treat the first list as a floor rather than a permanent boundary, since selection repeats every three years and the population is expected to widen.

AMLA timeline from June 2024 to the 2029 football deadline

When does AMLA begin direct supervision? The AMLA implementation timeline

AMLA begins direct supervision of selected obliged entities in 2028, six months after it publishes the first selection list. Article 13(4) sets the sequence, requiring the authority to commence the first selection process by 1 July 2027, conclude it within six months, publish the list without undue delay, and then begin direct supervision six months after publication. The AMLA implementation timeline that follows from the legal texts and the authority’s own announcements runs as follows.

  1. 26th June 2024-AMLAR entered into force, establishing AMLA.
  2. On 1 July 2025- AMLA officially began its operation in Frankfurt.
  3. 2025 to 2026- AMLA further develops its technical standards, which also includes methodologies as well as supervisory processes for its future mandates..
  4. 2026- 2027- national supervisors and AMLA identify entities eligible for AMLA direct supervision.
  5. 10th July 2027- AMLR applies; which means that all Member States must have transposed AMLD6.
  6. End of September 2026-The provisional list of eligible obliged entities is expected to be finalised.
  7. 2028- AMLA begins direct supervision of selected high-risk cross border obliged entities.
  8. 10th July 2029- AMLR obligations extend to professional football clubs and agents.

The end of September 2026 is when a firm learns whether it sits in the eligible pool, which gives roughly fifteen months of warning before the selection decision and around two years before supervision changes hands. Firms that treat that provisional list as the real starting gun will have time to remediate. Those that wait for the 2027 selection announcement will be remediating under observation.

How is AMLA different from national AML supervisors?

The difference is one of legal instrument, reach, and consequence rather than intensity of scrutiny. National supervisors apply national law that transposes an EU directive, so their interpretive discretion is genuine, and their penalties are set by their own legislature. AMLA applies a directly effective EU regulation with sanctioning ceilings written into the AMLR itself.

# National AML supervisor AMLA
Legal basis National law transposing AMLD6 Regulation (EU) 2024/1620, directly applicable
Population covered All obliged entities in one member state Up to 40 high-risk cross-border financial groups selected for AMLA direct supervision in the first cycle.
Interpretive discretion Applies national transposition and guidance Applies the single rulebook uniformly
Sanction ceiling Set by national legislature Up to 10% of total annual turnover or €10 million depending on the infringement and applicable sanctions rules.
Appeal route National courts and tribunals AMLA Administrative Board of Review, then the Court of Justice of the EU
Who funds it The national budget or a domestic levy EU budget contribution and supervisory fees under Article 77

The penalty figures deserve care, because they are usually quoted as one rule, a fine of up to 10% of turnover or EUR 10 million, whichever is higher. The regulation does not work that way. Which ceiling applies depends on which duty a firm has breached. Serious, repeated or systematic failures in customer due diligence, group-wide policies, or reporting carry a cap of 10% of total annual turnover.

Failures against the remaining requirements carry a flat cap of EUR 10 million instead. The two figures are never weighed against each other, so no firm should assume the larger number is the one that counts. AMLA can also run a daily charge alongside the fine for as long as a breach continues, worth up to 3% of average daily turnover, applied for six months at a time and extendable once.

What are the AMLA compliance requirements obliged entities face?

The AMLA compliance requirements land in two layers, because the substantive obligations come from the AMLR while AMLA supplies the supervisory pressure that tests them. Four consequences follow for firms in or near the eligibility pool.

The single rulebook removes the gold-plating defence

Under the AMLR, customer due diligence obligations, the 25% ownership or voting rights threshold for identifying beneficial owners, and the EUR 10,000 ceiling on cash payments for goods and services all apply in the same words everywhere. A group that has historically justified a weaker standard in one market by pointing to a permissive local transposition will no longer have that argument available. Therefore, the practical work for most groups is upward harmonisation of the weakest entity in the chain rather than fresh policy drafting.

Data you must be able to produce on demand

Article 17 lets AMLA request information directly from a selected obliged entity, and Articles 18 and 19 allow general investigations and on-site inspections without a national supervisor as intermediary. This is because the authority is designed to form its own view rather than inherit one.

The practical requirement is a group-wide, queryable record of customer risk ratings, screening outcomes, escalation decisions, and the evidence behind each of them, retrievable across every entity in the group on a common definition. Groups that hold that data in eleven local systems with eleven different risk taxonomies will spend the first inspection reconciling rather than answering.

The Article 77 levy, which is rarely Budgeted for

Article 77 is the provision that surprises many finance teams. AMLA levies an annual supervisory fee not only on selected obliged entities but also on “the non-selected obliged entities that meet the criteria set out in Article 12(1)”, which is to say the entire six-member-state eligibility pool. A firm can therefore pay the AMLA levy for years without ever being selected. The methodology sits in a Commission delegated act due by 1 January 2027, and the regulation already caps the non-selected contribution at 20% of the fee charged to a selected entity with the same level of income or turnover.

The failure mode, 27 local interpretations inside one group

The pattern that will surface most often in early inspections is not an absent control but an inconsistent one. A group whose Irish subsidiary treats a customer as standard risk while its Cypriot subsidiary treats an identical profile as high risk has, from AMLA’s group-wide vantage point, an unexplained divergence in its risk methodology. Because Article 12(3) requires classification at group-wide level where the entity is part of a group, that divergence feeds directly into the residual risk score that decides selection.

What should firms do now to prepare for AMLA?

Preparation should be sequenced against the dated milestones above rather than against the 2028 supervision date, since the decisions that matter are taken well before it. Six steps carry most of the value.

  1. Run the six-member-state test honestly: Count establishments and passported services together, including markets served remotely, and confirm whether the group crosses the Article 12(1) threshold. Many payment and crypto-asset firms discover they do.
  2. Ask your national supervisor where you stand: Supervisors organised the identification data collection through August 2026 and know which of their firms were reported. A direct question is faster than inference.
  3. Reconcile risk methodology across the group: Residual risk at group-wide level decides selection, so a single risk taxonomy and a single set of rating definitions is the highest-leverage change available before 2027.
  4. Close the evidence gap before the rulebook date: Rebuild files so that every risk decision, screening hit, and escalation can be produced with its supporting evidence and its timestamp, on demand, from one place.
  5. Budget for the Article 77 fee: Model it into 2027 and 2028 planning even if selection looks unlikely, because eligibility rather than selection triggers the charge.
  6. Map the AMLR gap by 10 July 2027: Compare current group standards against the single rulebook rather than against the strictest national transposition you currently follow, and remediate the weakest entity first.

How Shufti helps EU obliged entities evidence AML controls

If your group runs onboarding across six or more EU markets, the hard part of AMLA preparation is rarely the policy document. It is producing one defensible record when eleven local systems each hold part of the answer, and none of them agree on what high risk means.

Shufti ongoing monitoring layer keeps every customer under continuous sanctions, PEP, and adverse media rescreening against a single decisioning model, and it writes each rescreening event, match decision, and escalation to one timestamped audit record across every entity in the group. Because the screening models are Shufti’s own, the reasoning behind a match decision can be explained to an examiner rather than attributed to a third-party black box. For groups with data residency obligations, the same platform deploys through Local Cloud or on-premises options rather than a single shared region.

See your own AML evidence trail the way an AMLA inspection would read it, then book a 20-minute demo.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.