Offices: Poland | Lithuania | Latvia | Estonia

Book a Meeting

Call us: +48 732 126 560

Email us: [email protected]

In: AML Compliance
EU AMLR 2027: What Businesses Need to Prepare For

The European Union’s new Anti-Money Laundering Regulation will significantly reshape how AML and counter-terrorist financing rules are applied across the EU.

Regulation (EU) 2024/1624, commonly referred to as the AMLR, will apply directly across EU Member States from 10 July 2027 for most obliged entities. Rather than relying primarily on national implementation of EU directives, AMLR introduces a more harmonised set of directly applicable requirements covering internal AML controls, customer due diligence, beneficial ownership, transaction monitoring, reporting and recordkeeping.

Updated: August 2026Reading time: ~11 minutes
The short answer: businesses should not wait until 2027 to review their AML framework. AMLA is already developing the technical standards and guidelines that will support the new Single Rulebook, including rules covering customer due diligence, business-wide risk assessments, ongoing monitoring, suspicious activity reporting and group-wide controls.
Complium EU
Prepare Your AML Framework for the 2027 Single Rulebook

Complium helps regulated businesses assess existing AML frameworks, identify gaps and implement the governance, CDD, monitoring and operational changes required ahead of AMLR application.

  • AMLR gap assessment
  • AML policies and risk assessment
  • CDD and monitoring framework review
  • AML governance and outsourcing review

Discuss Your AMLR Readiness

In this guide

  1. What AMLR changes
  2. Who will be affected
  3. Internal AML governance and risk assessment
  4. Customer due diligence and monitoring
  5. Beneficial ownership, reporting and recordkeeping
  6. Outsourcing and group-wide compliance
  7. What AMLA is doing in 2026
  8. How businesses should prepare for July 2027
  9. How Complium can support AMLR readiness
Section 01

What Is AMLR and Why Does It Matter?

AMLR is Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering or terrorist financing.

The Regulation was adopted in 2024 and forms part of the EU’s broader AML/CFT reform package, together with the establishment of the new Anti-Money Laundering Authority, AMLA.

For most obliged entities, AMLR will apply from 10 July 2027. Certain provisions relating to football agents and professional football clubs apply later, from 10 July 2029.

The important structural change is that AMLR is a regulation, meaning its core rules are directly applicable in EU Member States.

This is intended to reduce the regulatory divergence that has developed under successive AML directives and create a more consistent EU-wide AML/CFT framework.

That does not mean every national difference disappears. The Regulation still allows Member States discretion in certain areas, and national supervisory structures will remain relevant.

For businesses operating across several EU countries, however, the direction is clear: AML expectations will become increasingly harmonised.

Section 02

Which Businesses Are in Scope?

AMLR applies to a wide range of financial and non-financial obliged entities.

The Regulation includes credit institutions and financial institutions, with the financial-institution definition covering crypto-asset service providers, alongside professional and non-financial sectors.

Other obliged entities include, among others:

  • auditors, external accountants and tax advisers;
  • certain lawyers, notaries and other independent legal professionals;
  • trust and company service providers;
  • estate agents;
  • traders in precious metals and stones;
  • traders in specified high-value goods;
  • gambling service providers;
  • crowdfunding service providers and intermediaries;
  • certain credit intermediaries;
  • investment migration operators;
  • non-financial mixed activity holding companies; and
  • professional football agents and certain professional football club activities under the later application date.

For fintech companies, the Regulation is particularly relevant to:

  • banks and other financial institutions;
  • payment and electronic money businesses;
  • crypto-asset service providers;
  • crowdfunding businesses; and
  • groups operating across several EU jurisdictions.
Section 03

AML Governance Will Need to Be More Structured

AMLR places detailed requirements on the internal policies, procedures and controls of obliged entities.

These must cover areas including:

  • business-wide risk assessment;
  • risk management;
  • customer due diligence;
  • identification of PEPs and related persons;
  • suspicious transaction reporting;
  • outsourcing and reliance on other obliged entities;
  • record retention;
  • monitoring of compliance deficiencies;
  • staff integrity;
  • internal communication; and
  • employee training.

Policies and controls must be documented, kept up to date and proportionate to the nature, size, complexity and risk profile of the business.

Business-Wide Risk Assessment

AMLR requires obliged entities to identify and assess the money laundering and terrorist financing risks to which their business is exposed.

Importantly, this is not intended to be a one-off document.

The business-wide risk assessment must be documented, maintained and reviewed where changes affect the risk profile of the business.

The Regulation also specifically requires risk assessment before launching new products, services, delivery channels or technologies, or before entering new customer segments or geographic markets.

For growing fintech groups, this makes the AML risk assessment much more closely connected to product development and market-entry decisions.

Compliance Manager and Compliance Officer

AMLR distinguishes between a management-level compliance manager and the operational compliance officer.

The compliance manager is a member of the management body responsible for ensuring compliance, while the compliance officer is responsible for the day-to-day AML/CFT policies, procedures and controls and acts as a contact point for competent authorities.

Depending on the nature and size of the entity, the Regulation allows the two functions to be performed by the same person in certain circumstances.

Businesses should therefore review whether their current AML governance, reporting lines and role descriptions will meet the new framework.

Section 04

Customer Due Diligence and Ongoing Monitoring

Customer due diligence remains central to the AMLR framework.

Obliged entities must apply CDD when, among other circumstances:

  • establishing a business relationship;
  • carrying out qualifying occasional transactions;
  • money laundering or terrorist financing is suspected;
  • previously obtained identification information appears unreliable; or
  • there are doubts about whether the person acting is the customer or an authorised representative.

The general occasional-transaction threshold is EUR 10,000, although lower thresholds apply in specified circumstances.

For example:

  • crypto-asset service providers are subject to specific CDD requirements for occasional transactions at EUR 1,000 and additional identification requirements below that threshold;
  • certain cash transactions trigger identification and verification measures from EUR 3,000; and
  • other sector-specific thresholds apply.

Ongoing Monitoring

The obligation does not stop once the customer is onboarded.

Obliged entities must maintain an up-to-date understanding of the customer and monitor transactions and activities throughout the relationship.

This is already a major area of AMLA’s implementation work.

In June 2026, AMLA opened a public consultation on draft guidelines dealing specifically with ongoing monitoring, customer-information updates and transaction and activity monitoring.

For companies preparing for 2027, this is a strong signal that transaction-monitoring design, alert handling and periodic KYC review should form part of the AMLR readiness project.

Section 05

Beneficial Ownership, Reporting and Recordkeeping

Beneficial Ownership

AMLR provides a more harmonised framework for identifying beneficial owners.

As a general rule, ownership of 25% or more of shares, voting rights or other ownership interests can establish beneficial ownership, while control through other means must also be considered.

The Regulation also provides mechanisms that may result in lower ownership thresholds for specified higher-risk categories of legal entities.

Businesses should therefore review not only the percentage threshold used in their procedures, but also how indirect ownership, multi-layer structures and control through other means are assessed.

Suspicious Activity Reporting

Obliged entities must report to the relevant FIU where they know, suspect or have reasonable grounds to suspect that funds or activities are connected to criminal activity or terrorist financing.

The obligation applies regardless of the amount involved and includes attempted transactions.

AMLA is currently developing a harmonised format for the reporting of suspicions and the provision of transaction records. A public consultation on the draft implementing technical standards opened in July 2026.

Record Retention

AMLR requires obliged entities to retain key CDD information, transaction records and relevant suspicious-activity assessment records.

The general retention period is five years from the termination of the business relationship or relevant occasional transaction, subject to specific extensions permitted under the Regulation.

Section 06

Outsourcing Does Not Transfer Compliance Responsibility

AMLR permits obliged entities to outsource certain AML tasks to service providers.

However, outsourcing does not transfer regulatory responsibility.

The obliged entity remains fully liable for the outsourced activity and must be able to demonstrate that it understands how the service provider performs the task and how the arrangement mitigates the relevant risks.

The Regulation also prohibits the outsourcing of certain decisions and responsibilities.

These include, among others:

  • approval of the business-wide risk assessment;
  • approval of internal AML policies and controls;
  • decisions on customer risk profiles;
  • decisions to enter into business relationships or carry out occasional transactions;
  • certain suspicious activity reporting decisions; and
  • approval of criteria used to identify suspicious or unusual activity.

This will be particularly important for fintechs that rely heavily on external KYC, transaction-monitoring, compliance or managed-service providers.

Existing outsourcing arrangements should be reviewed before 2027.

Section 07

Cross-Border Groups Face Group-Wide AML Requirements

AMLR strengthens the connection between group governance and local AML compliance.

A parent undertaking must establish group-wide policies, procedures, controls and risk assessments covering relevant branches and subsidiaries.

For EU-headquartered groups, this can extend to branches and subsidiaries in third countries.

Where third-country law is less strict, the parent undertaking must seek to apply the AMLR requirements or equivalent standards. Where local law prevents this, additional measures and supervisory engagement may be required.

For international fintech groups, preparation should therefore look beyond individual EU entities.

The project should consider:

  • group governance;
  • information sharing;
  • customer and transaction data;
  • local and central compliance responsibilities;
  • group risk assessment;
  • third-country operations; and
  • outsourcing arrangements.
Section 08

The EUR 10,000 EU Cash Limit

AMLR also introduces an EU-wide limit on large cash payments.

Persons trading in goods or providing services may generally make or accept cash payments only up to EUR 10,000, including linked transactions.

Member States remain able to impose lower limits.

This is particularly relevant for sectors dealing with high-value goods and other cash-intensive activities.

Section 09

What Is Happening Now, in 2026?

Businesses do not yet have every implementation detail.

AMLA is currently developing the Level 2 and Level 3 instruments that will clarify how important parts of AMLR should work in practice.

As of August 2026, AMLA’s regulatory programme includes work on:

  • customer due diligence;
  • criteria for business relationships and occasional transactions;
  • business-wide risk assessments;
  • group-wide AML requirements;
  • ongoing monitoring;
  • suspicious activity reporting formats;
  • supervisory risk methodologies; and
  • cross-border supervisory cooperation.

Some consultations have already closed, while others remain active.

For example, AMLA’s business-wide risk assessment consultation closed in July 2026, while its ongoing-monitoring consultation is open until September 2026.

This is one reason businesses should treat 2026 as a preparation and gap-analysis year, rather than waiting until the final months before application.

AMLA Direct Supervision

AMLA will also change the supervisory landscape.

The Authority plans to select up to 40 significant cross-border financial institutions or groups during 2027 for direct EU-level AML supervision beginning in 2028.

The majority of obliged entities will continue to be supervised nationally, but AMLA’s standards and methodologies are intended to drive greater consistency across national supervisors as well.

Section 10

What Should Companies Do Before July 2027?

The exact work required will depend on the company’s current AML framework, sector, licences, jurisdictions and operating model.

A practical AMLR readiness project can include the following.

1. Complete an AMLR Gap Assessment

Map the existing AML framework against Regulation (EU) 2024/1624 and identify areas where policies, processes or governance will need to change.

2. Review the Business-Wide Risk Assessment

Check whether the current risk assessment adequately covers customers, products, services, transaction types, delivery channels, technology and geographic exposure.

3. Review AML Governance

Assess the roles of the management body, compliance manager, compliance officer and internal audit or assurance functions.

4. Update CDD and KYC Procedures

Review identification, verification, beneficial ownership, PEP, source-of-funds and enhanced due diligence procedures against the new framework and emerging AMLA standards.

5. Review Ongoing and Transaction Monitoring

Assess whether customer information remains current and whether monitoring rules, alerts, investigations and escalation processes reflect the company’s risk assessment.

6. Review Suspicious Activity Reporting

Ensure internal investigation and FIU reporting procedures are aligned with the new requirements and can adapt to the harmonised AMLA reporting standards.

7. Review Outsourcing

Map outsourced AML functions and identify arrangements that need new governance, documentation, supervisory notification or internal responsibility.

8. Review Group-Wide Controls

International groups should compare group policies against local procedures and identify any differences affecting EU and non-EU subsidiaries and branches.

9. Prepare Training and Implementation

Employees, management and compliance teams should understand what is changing before the new framework becomes applicable.

Section 11

How Complium Can Support AMLR Readiness

AMLR implementation should not be treated as a policy-update exercise alone.

Changes may affect governance, customer onboarding, transaction monitoring, outsourcing, group structures, reporting and the underlying systems used to deliver compliance.

Complium can support businesses with:

  • AMLR gap assessments: compare the current framework against Regulation (EU) 2024/1624 and emerging AMLA standards;
  • business-wide risk assessments: review or redesign the AML risk methodology and documentation;
  • AML policies and procedures: update internal frameworks to reflect the new requirements;
  • CDD and EDD frameworks: review customer identification, verification, beneficial ownership and higher-risk procedures;
  • governance and Compliance Officer support: assess roles, reporting lines and accountable functions;
  • ongoing monitoring: review KYC refresh and transaction-monitoring processes;
  • outsourcing reviews: assess third-party AML arrangements and retained responsibilities;
  • group-wide AML frameworks: align policies and controls across EU and non-EU entities;
  • AML training: prepare management and operational teams for the new framework; and
  • implementation roadmaps: prioritise regulatory changes ahead of July 2027.

For regulated fintech companies, the readiness project can also be coordinated with MiCA, payment services, electronic money and other regulatory obligations to avoid building separate compliance frameworks for overlapping requirements.

Frequently Asked Questions

Frequently Asked Questions

When does AMLR apply?

For most obliged entities, Regulation (EU) 2024/1624 applies from 10 July 2027. Certain provisions applying to football agents and professional football clubs take effect from 10 July 2029.

Is AMLR a directive?

No. AMLR is an EU regulation and is directly applicable across Member States.

Does AMLR replace all national AML rules?

It creates a much more harmonised EU-wide rulebook, but it does not remove every national requirement or supervisory difference. Member States retain discretion in specified areas and national competent authorities will continue supervising most obliged entities.

Does AMLR apply to crypto companies?

Crypto-asset service providers fall within the financial-institution framework used by AMLR and are subject to specific requirements, including particular CDD thresholds.

Will every obliged entity be supervised directly by AMLA?

No. AMLA plans to directly supervise up to 40 significant cross-border financial institutions or groups from 2028. Most obliged entities will remain under national supervision, although AMLA will play a broader role in supervisory convergence.

Can AML functions still be outsourced under AMLR?

Yes, certain tasks can be outsourced, but the obliged entity remains responsible and some core decisions cannot be outsourced.

Should businesses wait for all AMLA standards before starting preparation?

No. Many of AMLR’s core requirements are already established in the Regulation. Businesses can start with a gap assessment now and update their implementation as final AMLA technical standards and guidelines develop.

Prepare for AMLR Before 2027

The transition to the EU AML Single Rulebook will affect more than AML documentation.

Businesses should review governance, customer due diligence, risk assessment, transaction monitoring, outsourcing, reporting and group-wide controls well before July 2027.

Complium can assess your existing AML framework, identify the changes required and build a practical implementation roadmap ahead of AMLR application.

Discuss Your AMLR Readiness

This article is intended for general informational purposes and does not constitute legal advice.