Practical guide to the AMLR

If you’re using the Muinmos platform you’re already AMLR ready. But if you’re not – here is a guide to understand the EU AML Regulation, its key changes, implementation timeline and practical steps financial institutions should take to prepare

The time to implement is now

The AMLR is not merely a project to replace national references in existing policies. It requires financial institutions to demonstrate that a more detailed, EU-wide rulebook is embedded in customer data, beneficial-ownership analysis, risk decisions, monitoring, governance and audit trails.

In this guide

This guide explains what the AMLR is, why the EU enacted it, what materially changes, which details remain unsettled, how AMLA fits into the new framework and the three practical steps financial institutions should take now.

1. What is the AMLR?

The AMLR is Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering or terrorist financing. It is the principal substantive rulebook for the private sector under the EU’s new AML/CFT package.

It governs, among other matters:

  • business-wide risk assessments and internal policies, procedures and controls;
  • customer due diligence, including identification, verification and understanding the purpose and intended nature of a relationship;
  • beneficial-ownership identification and analysis;
  • simplified and enhanced due diligence;
  • ongoing customer and transaction monitoring;
  • politically exposed persons, high-risk third countries and other higher-risk situations;
  • targeted financial sanctions implementation and circumvention risk;
  • suspicious-transaction reporting, record-keeping and group-wide controls.

The AMLR forms part of a wider legislative package. The package also includes the Sixth Anti-Money Laundering Directive, the Regulation establishing AMLA and the recast Transfer of Funds Regulation. These instruments have different functions:

  • The AMLR sets most of the directly applicable obligations for obliged entities.
  • AMLD6 deals principally with national institutional arrangements, including supervisors, financial intelligence units and registers, and therefore requires national transposition.
  • The AMLA Regulation creates the new EU Anti-Money Laundering Authority and gives it rule-making, coordination and supervisory responsibilities.
  • The Transfer of Funds Regulation contains traceability requirements for transfers of funds and certain crypto-asset transfers.

Direct applicability does not mean that every national difference will disappear. National law will remain relevant for example in areas where national measures are stricter. Nevertheless, the AMLR moves the centre of gravity away from 27 national implementations and towards a common operational rulebook.

2. Why did the EU enact it?

The EU already had an extensive AML/CFT framework. The problem was not the absence of rules. It was that a directive-based framework had produced uneven implementation, uneven supervision and uneven outcomes across a financial system in which customers, payments, corporate structures and risks frequently cross borders.

The AMLR and the wider package respond to four connected problems.

Fragmentation

The existing directives set common principles, but Member States transpose directives into national law. Definitions, thresholds, documentary expectations, supervisory practices and enforcement approaches can therefore diverge. For a cross-border institution, this often means maintaining multiple jurisdictional interpretations of what is intended to be one EU framework.

Insufficiently operational rules

Many current requirements are expressed at a relatively high level. Institutions are told to apply risk-based measures, keep information up to date and conduct enhanced due diligence, but important implementation choices may be left to national rules, supervisors or individual firms. The AMLR retains the risk-based approach while specifying more of the minimum data, processes, triggers and outcomes expected.

Changing risk

The package reflects the growth of crypto-assets, technology-enabled financial services, complex cross-border ownership structures, new payment channels and sanctions-evasion methods. It also expands or clarifies the perimeter for certain sectors that were not treated uniformly under the existing framework.

Weaknesses in supervision and cooperation

Serious failings in one Member State can affect the wider EU financial system. The EU therefore created AMLA to promote a common supervisory methodology, coordinate national authorities and FIUs, and directly supervise a limited group of particularly high-risk cross-border financial institutions.

3. What changes from the current situation?

The comparison below is deliberately practical. It does not suggest that every AMLR requirement is entirely new. Many core obligations already exist under AMLD4, AMLD5, national law and supervisory guidance. The material change is the combination of direct applicability, greater prescription and a stronger expectation that institutions can demonstrate consistent implementation.

01_amlr_comparison

The most important changes in practice

A more prescriptive CDD baseline

The AMLR specifies the constituent parts of customer due diligence more clearly and requires AMLA to develop a detailed CDD regulatory technical standard. Firms will need to compare their existing customer data, documents and verification methods against an EU-wide minimum rather than relying solely on national practice or internal policy.

More explicit beneficial-ownership analysis

The AMLR requires ownership and control to be assessed in parallel. The ownership threshold is framed as 25% or more, and the Regulation contains rules for calculating indirect ownership through corporate chains. A register entry remains relevant evidence, but it is not a substitute for understanding how a natural person ultimately owns or controls the customer. Material discrepancies identified against a beneficial-ownership register generally have to be reported without undue delay and, in any event, within 14 calendar days.

Defined outer limits for customer-data refresh

Customer information must be updated when relevant circumstances change. In addition, the AMLR sets maximum intervals: no more than one year for higher-risk customers and no more than five years for other customers. These are maximum periods, not default service levels. A firm’s risk methodology may require more frequent review, and material events should trigger review before the periodic date.

Sanctions risk embedded in the AML framework

The AMLR does not replace EU sanctions legislation. It does, however, expressly require obliged entities to assess and mitigate the risk of non-implementation and circumvention of targeted financial sanctions. Sanctions checks therefore need to connect with customer and beneficial-owner identification, ownership and control analysis, institutional risk assessment and ongoing monitoring, rather than operating as a detached name-screening exercise.

More prescribed treatment of higher-risk cases

The AMLR retains risk-based enhanced due diligence but provides more specific triggers and measures for certain relationships. One example is the additional regime for particular high-risk relationships involving personalised wealth-management services, assets under management of at least EUR 5 million and customers whose total assets are at least EUR 50 million. More broadly, institutions should expect less freedom to define enhanced due diligence through generic policy language.

Governance and evidence

Policies and controls must be written, approved at the appropriate management level and subject to independent testing. The practical question will increasingly be not only whether a policy exists, but whether the institution can retrieve the data, reasoning, approvals and monitoring evidence showing that the policy worked in the case concerned.

4. What is still to be set?

The Level 1 Regulation is final. The implementation detail is not. The AMLR contains numerous mandates for AMLA to prepare regulatory technical standards, implementing technical standards and guidelines. Some will be adopted by the European Commission and become binding technical rules; others will guide consistent application and supervision.

02_amlr_still_to_be_set

WHAT THE UNCERTAINTY MEANS FOR IMPLEMENTATION

Do not wait for the final line of every standard before starting. Separate the programme into: (1) requirements already fixed in the AMLR; (2) design assumptions based on published drafts; and (3) configurable elements that will be updated when final Level 2 text is issued. Every assumption should have an owner and a formal change-control trigger.

5. AMLR timeline: in force is not the same as applicable

The AMLR has already entered into force. Most of its operative requirements are subject to a deferred application date. This distinction is important: 10 July 2027 is the date by which the framework is expected to operate in production, not the date on which firms should begin analysing it.

AMLR timeline

WHAT THE UNCERTAINTY MEANS FOR IMPLEMENTATION

Do not wait for the final line of every standard before starting. Separate the programme into: (1) requirements already fixed in the AMLR; (2) design assumptions based on published drafts; and (3) configurable elements that will be updated when final Level 2 text is issued. Every assumption should have an owner and a formal change-control trigger.

6. What is AMLA?

AMLA is the European Union Authority for Anti-Money Laundering and Countering the Financing of Terrorism. It is based in Frankfurt and is intended to become the central coordinating institution of the EU AML/CFT supervisory system.

AMLA has four roles that matter particularly to financial institutions:

Rule-maker

AMLA drafts many of the technical standards and guidelines that will turn the AMLR’s Level 1 requirements into a more detailed operating framework. Even institutions that are never directly supervised by AMLA will therefore be affected by its work.

Direct supervisor

AMLA will directly supervise a selected group of high-risk cross-border credit and financial institutions or groups. AMLA’s current operational plan envisages direct supervision beginning in 2028 for up to 40 selected institutions or groups. Selection work is expected to run through 2026 and 2027.

Supervisory convergence and oversight

Most obliged entities will continue to be supervised by their national competent authorities. AMLA will nevertheless influence those relationships through common methodologies, peer reviews, coordination, information exchange and oversight of national supervisory systems. The practical effect should be greater consistency in what supervisors ask for and how control effectiveness is assessed.

FIU coordination

AMLA will support cooperation and joint analysis among national financial intelligence units and will host FIU.net. This is intended to improve the analysis of cross-border suspicious activity and the flow of intelligence across the Union.

DOES AMLA DIRECTLY SUPERVISE EVERY FINANCIAL INSTITUTION?

No. Direct supervision is reserved for a selected group of high-risk cross-border institutions. Most firms will remain under national supervision. However, AMLA’s standards, methodologies and convergence work will shape the expectations applied by national supervisors across the EU.

AMLA timeline

  • 1 July 2025: AMLA assumed most of its statutory tasks.
  • Q3 2026: provisional eligibility work for the first direct-supervision selection cycle.
  • 2027: data collection, risk assessment and selection process.
  • Q4 2027: selected entities are expected to be identified under AMLA’s current planning.
  • 2028: AMLA plans to begin direct supervision.

For institutions potentially within scope, preparation should include a dedicated direct-supervision workstream. For everyone else, the priority is to understand how AMLA’s Level 2 measures and supervisory methodologies will be reflected by the national authority.

7. How to prepare: three practical steps

A useful AMLR programme should move through three stages: map, design, and remediate.

STEP 1

MAP: convert law into a control and data matrix

Break the AMLR down requirement by requirement. For each obligation, identify the current policy, operational process, data fields, system, control owner, and retained evidence. Record whether the requirement is fixed in Level 1, dependent on Level 2 detail or subject to a national rule.

Practical deliverable: A single AMLR control matrix, prioritised gap assessment and implementation plan.

The matrix should not ask only, “Do we have a policy?” It should ask, “Where is the required information captured? Which rule makes the decision? What happens when the data is missing? Who approves the exception? What evidence can be shown to an auditor or supervisor?”

STEP 2

DESIGN: build the target operating model

Design the future-state process before configuring individual systems. Align the business-wide risk assessment, customer-risk methodology, CDD requirements, beneficial-ownership logic, sanctions controls, approval levels, ongoing-monitoring triggers and review cycles.

For users of the Muinmos platform, this is an easy exercise - similar to the configuring of the CRA and Orchestration agents.

Practical deliverable (for non-Muinmos users): An approved target operating model, data dictionary, and decision logic with controlled assumptions for pending Level 2 rules.

Particular design questions include:

  • Can the firm identify all required persons and explain the ownership and control chain?
  • Does the customer risk result change the information collected, approval level, monitoring intensity and review frequency?
  • Can a change in ownership, activity, geography, sanctions exposure or adverse information trigger a review?
  • Can the workflow distinguish a legal minimum from the institution’s stricter risk appetite or national requirement?

STEP 3

REMEDIATE: fix the customer book and control environment

Profile the existing customer population against the target data model. Identify missing or stale information, unresolved ownership structures, unverified representatives, inconsistent risk ratings, insufficient purpose or expected-activity information and weak sanctions ownership/control analysis. Prioritise by risk and operational dependency.

For users of the Muinmos platform, this is an easy step as well - simply re-run assessments according to any new parameters added. 

Non users can also migrate their clients to the platform and run them there at bulk. Note, that this stage should also cover vendor and system readiness. Contracts, data licences, APIs, screening configurations, identity-verification methods and audit logs must support the intended control (of course, on the Muinmos platform they already do).

8. Conclusion: the deadline is a go-live date

The AMLR is often described as the measure that creates a single EU AML rulebook. That is correct, but incomplete. For financial institutions, its more important effect is to make the framework more prescriptive, more operational and more dependent on structured data, connected controls and demonstrable outcomes.

The Regulation is already final and in force. The main application date is 10 July 2027. Some important implementation details are still moving through AMLA’s Level 2 process. That is not a reason to delay. The core requirements are sufficiently clear to begin mapping, design and remediation now, provided that assumptions are documented and the framework remains configurable.

The institutions best prepared for July 2027 will not be those with the longest new policy. They will be those that can show, customer by customer and decision by decision, that the AMLR is embedded in their data, workflows, monitoring, governance and evidence.

Start getting ready now