EU AMLR Readiness Checklist: What to Do Before 10 July 2027 (With AMLA's Standards Tracked)

In short

Regulation (EU) 2024/1624, the AMLR, applies from 10 July 2027, and on 1 October 2026 AMLA submitted final draft standards on customer due diligence, linked transactions and group-wide controls to the European Commission, proposed to apply six months after their entry into force. This checklist maps 14 readiness workstreams to AMLR articles, owners and the evidence an examiner will sample, and tracks every AMLA mandate that changes a firm's build.

Download the Excel template

Free, no email needed. Sheets: READ ME, Readiness checklist, AMLA standards tracker, 90-day plan, Changelog. All templates

The EU Anti-Money Laundering Regulation, Regulation (EU) 2024/1624 (the AMLR), applies from 10 July 2027 under its Article 90, and on that day one directly applicable rulebook replaces the national laws that transposed the Fourth AML Directive. On 1 October 2026 the EU's Anti-Money Laundering Authority (AMLA) published final draft standards on customer due diligence (including electronic identification, non-face-to-face verification and PEP screening), on business relationships and linked transactions, and on group-wide controls, and submitted them to the European Commission. AMLA proposes that they apply six months after their entry into force. On 2 October it invited industry representatives to sectoral roundtables on simplified due diligence, which will feed draft guidelines.

Below: what changes against your national rules, a tracker of AMLA's mandates as of 5 October 2026, a checklist of 14 workstreams with the AMLR article, owner, evidence and the AMLA instrument each waits on, a 90-day plan, a one-page board update, and notes for groups with a non-EU parent and for five sectors. Article numbers are AMLR unless stated.

Eight dates set the AMLR timeline, and AMLA's standards may trail the law

The AMLR was published in the Official Journal on 19 June 2024 with two companions: the AMLA Regulation, Regulation (EU) 2024/1620, which created the authority, and the sixth AML Directive (AMLD6), Directive (EU) 2024/1640, which member states transpose. EUR-Lex records corrigenda to some language versions of the AMLR but no amendments, so the text you build against is the 2024 text.

Date What happens Basis
10 Jul 2026 Deadline for AMLA's first AMLR standards and guidelines; member states transpose AMLD6's rules on access to beneficial ownership registers AMLR Arts. 9(4), 10(4), 16(4), 17(3), 19(9), 20(3), 26(5), 28(1), 69(3); AMLD6 Art. 78
1 Oct 2026 AMLA publishes final draft RTS on CDD, linked transactions and group-wide requirements AMLA
31 Dec 2026 Reference date for the data AMLA uses to select entities for direct supervision Draft ITS under AMLA Regulation Art. 15(3), Art. 5
31 Mar 2027 National supervisors finish collecting that data from provisionally eligible entities Same draft ITS, Art. 5(3)
By 1 Jul 2027 AMLA starts its first selection, which must conclude within six months AMLA Regulation Art. 13(4)
10 Jul 2027 AMLR applies; AMLD6 transposition deadline; the Fourth AML Directive is repealed AMLR Art. 90; AMLD6 Arts. 77, 78
2028 AMLA starts direct supervision, six months after publishing its list of selected entities AMLA Regulation Art. 13(4); AMLA timeline
10 Jul 2029 AMLR applies to football agents and professional football clubs; voting and distribution rights on unconverted bearer shares are suspended AMLR Arts. 90, 79(3)

The gap sits between the second and sixth rows. The AMLR gave AMLA until 10 July 2026 to submit the three standards, and each final draft says it applies six months after its entry into force (CDD final report, draft Article 29). The Commission has three months from receipt to decide whether to adopt a draft regulatory technical standard (AMLA Regulation Article 49(1)), and the European Parliament and Council then have three months to object, extendable by three more (Article 51(1)). On those default periods the standards would apply around the end of 2027, after the AMLR itself; faster adoption or an early non-objection would pull that forward. Plan for a window in which the AMLR's CDD articles bind you while the detailed standards are settled in substance but not yet in force. Build to the final drafts, which AMLA's own factsheets say the Commission may still amend.

Eleven things change on 10 July 2027 compared with your national rules

National AML laws differ, so the comparison is against the directive they transpose, Directive (EU) 2015/849 (AMLD4).

Area From 10 July 2027 (AMLR) What changes against AMLD4
Legal form One regulation, binding in its entirety and directly applicable (Art. 90); national add-ons only where the AMLR allows them (Art. 8(3)) AMLD4 Art. 5 let member states adopt stricter provisions generally
Who is in scope Financial institutions include holding companies, central securities depositories, consumer and mortgage creditors and crypto-asset service providers (Art. 2(1)(6)); traders in high-value goods (Art. 3(3)(f)) Holding companies were outside AMLD4's definition; traders in goods were caught only for cash payments of EUR 10,000 or more
CDD triggers and data Occasional transactions from EUR 10,000 (Art. 19(1)(b)); a fixed list of identification data (Art. 22(1)); e-ID at eIDAS "substantial" or "high" (Art. 22(6)) The occasional-transaction threshold falls from EUR 15,000
Business relationship A relationship with "an element of repetition or duration" (Art. 2(1)(19)) AMLD4 looked at duration only
Existing customers Customer information updated at least every year for higher-risk customers and every five years for the rest (Art. 26(2)) AMLD4 Art. 14(5) said "at appropriate times"
Beneficial ownership 25% or more, multiplied through ownership chains, with control via other means assessed in parallel (Arts. 51 to 54); register discrepancies reported within 14 calendar days (Art. 24) AMLD4 treated more than 25% as an indication of ownership
Politically exposed persons Adds heads of regional and local authorities of 50,000 or more inhabitants, and siblings of heads of state, heads of government and ministers (Art. 2(1)(34), (35)) A wider screening population
Governance A compliance manager from the management body and a compliance officer appointed by it, with an annual implementation report (Art. 11) AMLD4 asked for a responsible board member "where applicable" and a compliance officer "where appropriate"
Business-wide risk assessment Covers ML/TF risk and the risk of non-implementation and evasion of targeted financial sanctions; drawn up by the compliance officer, approved by the management body (Art. 10) Sanctions evasion risk joins the assessment
Groups and outsourcing An EU parent undertaking even for groups headed outside the EU (Arts. 2(1)(42), 16); supervisor notified before an AML task is outsourced, and six tasks never outsourced (Art. 18) AMLD4 had no outsourcing article and no EU parent construct for non-EU groups
Reporting, records and cash FIU requests answered within 5 working days (Art. 69(1)); a record of every suspicion assessment kept for 5 years, then deleted (Art. 77); EUR 10,000 cap on cash payments (Art. 80) Fixed EU deadlines and an EU-wide cash cap; lower national cash limits continue

Member states keep some room, such as lower cash limits (Art. 80(2)), extra enhanced due diligence (Art. 34(6)) and their own lists of prominent public functions (Art. 43(1)), and Article 8(3) and (4) decide which state's rules each establishment follows. Enforcement sits in AMLD6: Article 55(3) requires maximum fines for credit and financial institutions that are legal persons of at least EUR 10 million or 10% of total annual turnover, whichever is higher, measured on the ultimate parent's consolidated accounts where those are required.

AMLA has finalized three standards for firms and is still drafting most of the rest

AMLA took over the EBA's AML/CFT mandates on 1 January 2026, and the EBA's existing AML guidelines stay in force until AMLA replaces them (AMLA, 19 January 2026; AMLA Regulation Art. 54(5)). AMLA's own tracker, last updated 30 September 2026, lists none of its standards as adopted by the Commission. The table covers each mandate that changes a firm's build.

Instrument Basis and legal due date Status on 5 Oct 2026 What it means for your build
RTS on customer due diligence Art. 28(1); 10 Jul 2026 Final draft submitted to the Commission (1 Oct 2026); applies six months after entry into force Freeze the CDD data model on it: names and place of birth as on the ID document, structured addresses, a low-risk data set without address, e-ID attributes, alternative non-face-to-face checks, PEP and sanctions screening
RTS on business relationships, occasional and linked transactions Art. 19(9); 10 Jul 2026 Final draft submitted (1 Oct 2026); no lower CDD thresholds beyond the AMLR's own Remitters, bureaux de change and crypto exchange and transfer services: three or more transactions in 12 months indicate a relationship, and a one-month window applies to linking
RTS on group-wide requirements and third-country measures Arts. 16(4), 17(3); 10 Jul 2026 Final draft submitted (1 Oct 2026) Group framework, information-sharing annex, EU parent notification within 28 days and approval within 60; repeals Delegated Regulation (EU) 2019/758 from 10 Jul 2027
Guidelines on the business-wide risk assessment Art. 10(4); 10 Jul 2026 Consultation ran 16 Apr to 15 Jul 2026; final text pending Four minimum requirements: business overview, inherent risk, control quality, residual risk
Guidelines on ongoing monitoring Art. 26(5); 10 Jul 2026 Consultation ran 3 Jun to 3 Sep 2026; final text pending Documented assessment of vendor default settings, human oversight of automated alert closure, effectiveness measured by outcomes
ITS on the format for reporting suspicions Art. 69(3); 10 Jul 2026 Consultation ran 2 Jul to 20 Sep 2026; application date left open in the draft A common core data set with templates by type of obliged entity; firms that automate filing instead of using their FIU's platform must build to them
Guidelines on risk variables and risk factors Art. 20(3); 10 Jul 2026 Not yet consulted on Keep the customer risk model mapped to the EBA's ML/TF Risk Factors Guidelines, which still apply
Guidelines on internal policies and compliance staffing Art. 9(4); 10 Jul 2026 Not yet consulted on; AMLA's work programme plans a consultation in Q1 2027 and a final text in Q2 2027 Size the compliance functions on your own documented analysis for now
Guidelines on simplified due diligence (AMLA's own initiative) Art. 33; no legal due date Roundtables in Frankfurt, 9 Nov to 2 Dec 2026 (expressions of interest by 18 Oct); AMLA says a public consultation will follow Design SDD on Art. 33 and the CDD RTS only
Nine guidelines due by 10 Jul 2027: outsourcing, PEPs, reliance, suspicious activity indicators, self-hosted addresses, CASP correspondents, geographic risk, the EUR 50 million wealth test, de-risking (joint with the EBA) Arts. 18(8), 42(2), 50, 69(5), 40(2), 37(3), 32(1), 34(5), 21(4) None published Build to the AMLR text and diary a re-check for each
Joint guidelines on partnerships for information sharing (AMLA and the EDPB) Art. 75 Consultation planned for the first half of 2027 Partnerships become possible on 10 Jul 2027; plan the supervisor notification and data protection impact assessment Art. 75 requires
RTS on central contact points AMLD6 Art. 41(2); 10 Jul 2026 AMLA surveyed e-money and payment institutions until 22 Sep 2026; no draft yet Payment and e-money firms using agents in other member states: keep current central contact point arrangements

AMLA's work programme, published in February 2026, planned the final BWRA, monitoring, risk-factor and reporting-format texts for the fourth quarter of 2026; the risk-factor guidelines have already missed their planned consultation quarter.

A tracker like this goes stale fast: four of its rows changed on 1 and 2 October 2026. RegWatch, my company, monitors the regulators and sources you choose on the schedule you set, so AMLA's pages, the Official Journal and your national supervisors can sit on one watchlist, with each finding scored against your company profile and the source clause cited.

The readiness checklist covers 14 workstreams, each with an owner and evidence

Copy the rows into your tracker, or use the free workbook that comes with this post, and add a status and a last-reviewed date to each. As in our obligations register template, the unit is a row you can assign and evidence. Owners are roles; put a named person against each.

Governance and risk assessment

Workstream AMLR basis What the AMLR requires Do before 10 July 2027 Owner Evidence an examiner will sample Waiting on
1. Governance and roles Arts. 9, 11 Written policies approved by the management body; procedures approved at least by the compliance manager; a compliance manager and a compliance officer; an annual report Appoint the compliance manager by board resolution; confirm the compliance officer's standing and removal process; re-paper approvals; diary the annual report Company secretary with the CCO Board minutes naming both roles; approval trail per document; the annual report and the board's response Compliance staffing guidelines (Art. 9(4)), planned for 2027
2. Business-wide risk assessment Art. 10 A documented assessment of ML/TF and sanctions-evasion risk, drawn up by the compliance officer, approved by the management body, kept up to date; new products assessed before launch Rebuild the methodology on the draft guidelines' four minimum requirements; add sanctions-evasion risk; link each residual risk to controls and remediation; set review triggers Compliance officer (MLRO) Methodology with weighting rationale; dated, approved assessment; sources list; pre-launch product assessments BWRA guidelines (Art. 10(4)), consultation closed
3. Customer risk assessment Art. 20(2), (4); Annexes I to III CDD measures set by an individual risk analysis using the Annex I variables and Annex II and III factors; ability to show the measures fit the risk Map the risk model's factors to Annexes I to III; document weights and overrides; test that ratings drive simplified, standard or enhanced measures Head of financial crime risk (2LOD) Model documentation; factor mapping; override log; files where rating and measures match Risk factor guidelines (Art. 20(3)), not yet consulted on

Customer due diligence

Workstream AMLR basis What the AMLR requires Do before 10 July 2027 Owner Evidence an examiner will sample Waiting on
4. CDD data model and remediation of existing files Arts. 19, 20, 22, 23, 25, 26(2) Fixed identification data; verification by documents, reliable sources or eIDAS e-ID; purpose and intended nature; customer information updated within one year (higher risk) or five Gap the onboarding data model field by field against Art. 22 and the final draft RTS; count the existing book by risk band; plan remediation within the one-year and five-year windows Head of KYC operations (1LOD) Field-level gap analysis; remediation plan with population counts and dates; sampled customer files CDD RTS (Art. 28(1)), final draft with the Commission
5. Beneficial ownership Arts. 20(1)(b), 22(7), 23(4), 24, 51 to 55, 67(4) Owners at 25% or more, multiplied through chains, plus control via other means; verification beyond the central register; discrepancies reported within 14 calendar days Re-run ownership logic for exactly 25% and indirect chains; add control questions; build the 14-day discrepancy workflow; collect proof of registration at onboarding Head of KYC operations Ownership charts with calculations; dated discrepancy reports; records where no owner was found CDD RTS (verification sources)
6. Politically exposed persons Arts. 2(1)(34) to (36), 20(1)(g), 42 to 46 PEP, family member and close associate checks; senior management approval, source of wealth and funds, enhanced monitoring; measures for at least 12 months after office ends Extend lists to regional and local office holders and siblings of top officials; re-screen when the EU list of prominent functions changes; check insurance beneficiaries at payout Screening lead with the MLRO Screening configuration and list coverage; approval records; source-of-wealth files PEP guidelines (Art. 42(2)), due 10 Jul 2027; CDD RTS (screening)
7. Enhanced due diligence and high-risk third countries Arts. 29 to 31, 34 to 39, 41 Enhanced measures in higher-risk cases and for third countries the Commission identifies by delegated act; scrutiny of complex or unusually large transactions Make country lists follow Commission delegated acts; define EDD menus from Art. 34(4); flag higher-risk customers with EUR 50 million or more in assets for Art. 34(5) MLRO EDD files with senior management approval; Art. 34(2) transaction reviews; country list change log Geographic risk (Art. 32) and wealth-test (Art. 34(5)) guidelines, due 10 Jul 2027
8. Ongoing monitoring Art. 26 Monitoring of transactions against the customer profile; current customer data; sanctions checks, for credit and financial institutions on every new designation Map scenarios to the BWRA; assess vendor default settings; validate automated alert closure by sampling; re-screen on new designations; use group data on shared customers Head of transaction monitoring Scenario inventory and tuning records; alert-to-case-to-report outcomes; QA samples of closed alerts Monitoring guidelines (Art. 26(5)), consultation closed

Groups, third parties, reporting and records

Workstream AMLR basis What the AMLR requires Do before 10 July 2027 Owner Evidence an examiner will sample Waiting on
9. Group-wide policies and information sharing Arts. 16, 17, 73(3) A group-wide risk assessment, group policies (including data protection and information sharing) and a group compliance manager; third-country branches and subsidiaries of EU groups meet AMLR standards Identify the parent undertaking; build the group assessment from entity assessments; set sharing rules for customer, ownership and suspicion data; list third-country legal impediments Group CCO Approved group policy set; group-wide risk assessment; sharing protocol and logs; parent notification (non-EU groups) Group-wide RTS (Arts. 16(4), 17(3)), final draft with the Commission
10. Outsourcing and reliance Arts. 18, 48 to 50 Supervisor notified before a provider starts an AML task; six tasks never outsourced; reliance under a written agreement with CDD data supplied within 5 working days Inventory every AML task run by a vendor or group entity; test it against Art. 18(3); prepare notifications; re-paper contracts; test reliance data delivery COO with the MLRO Outsourcing register; supervisor notifications; agreements; provider control testing; reliance test results Outsourcing (Art. 18(8)) and reliance (Art. 50) guidelines, due 10 Jul 2027
11. FIU reporting Arts. 69 to 74, 80(4) Prompt suspicion reports by the compliance officer; FIU requests answered within 5 working days; suspect transactions held until reported; no tipping off; threshold reports where relevant Re-time FIU responses to 5 working days; record every Art. 69(2) assessment, including decisions not to report; map case data to the common reporting format MLRO Report register with timestamps; FIU request log with response times; records of no-report decisions Reporting format ITS (Art. 69(3)), consultation closed; indicator guidelines (Art. 69(5))
12. Record keeping and data protection Arts. 76 to 78 Unredacted CDD records, suspicion assessments and transaction records kept 5 years after the relationship ends, then deleted; systems to answer FIU enquiries; meaningful human intervention in automated decisions Set retention to the AMLR clock with deletion; test retrieval for FIU enquiries; document human review points in automated onboarding and monitoring decisions Head of records with the DPO and MLRO Retention schedule; deletion logs; retrieval test results; data protection impact assessments None: the AMLR text applies
13. Training and staff integrity Arts. 12, 13 Specific, ongoing training appropriate to functions and risks, duly documented; skills and integrity assessments for staff in AML roles before they start and repeated Build role-based curricula from the BWRA's top risks; record results by role; run Art. 13 assessments for staff, agents and distributors MLRO with HR Training needs analysis tied to the BWRA; role-based materials; results by role; Art. 13 assessment records None: the AMLR text applies
14. AMLA selection readiness AMLA Regulation Arts. 12, 13 Credit and financial institutions operating in at least six member states are assessed for direct supervision on data as of 31 Dec 2026 Count member states as AMLA will; if provisionally eligible, name a data owner, reconcile data points with the BWRA and rehearse the submission (collection closes 31 Mar 2027) CCO with the CFO Eligibility calculation; data lineage; submission sign-off Selection RTS (AMLA Regulation Art. 12(7)) and cooperation ITS (Art. 15(3)), final drafts

Three rows need more than a table cell.

Customer file remediation (row 4). Article 26(2) caps the interval between customer information updates at one year for higher-risk customers and five years for the rest. Draft Article 28 of the CDD standard applies those windows to existing relationships from the standard's entry into force, and AMLA refused requests to extend them (final report, feedback section). The higher-risk window will probably close during the AMLR's first year, so count that population now. The final draft's low-risk data set (names, date and place of birth, nationality, no address) shows which fields you may not need to chase.

Monitoring effectiveness (row 8). AMLA's consultation draft on ongoing monitoring says vendor default settings should not be used without a documented assessment (paragraph 50), automated closure of alerts needs human oversight through sampling (paragraphs 78 and 79), and effectiveness should not be judged solely by alert or reporting volumes (paragraph 84). The evidence that answers those points is the trail from alert to case to report, with the reasons for each closure.

Training (row 13). Article 12 asks for training "appropriate to their functions or activities and to the risks", "duly documented". The evidence that meets it is a curriculum mapped by role to the BWRA's top risks, with assessment results recorded by role.

AMLA's selection for direct supervision runs on data as of 31 December 2026

The AMLA Regulation assesses credit and financial institutions, and groups of them, that operate in at least six member states including their home state, through establishments or the freedom to provide services (Article 12(1)). Under the final draft standard on Article 12(7), freedom-to-provide-services activity counts in a member state where more than 20,000 of the firm's customers reside there at 31 December, or where those customers' incoming and outgoing transactions exceed EUR 50 million in the year, with activity through agents and distributors and across group entities added together (AMLA interpretative note). Each risk profile is classified low, medium, substantial or high, at group level for groups (Article 12(3)), and a high residual risk qualifies (Article 13(1)). AMLA says it will select up to 40 entities in 2027 for direct supervision starting in 2028.

The process has run all year. Sampled entities were asked to send data for a testing exercise by 22 April 2026. National supervisors collected eligibility data as of 31 December 2025 and were due to pass it to AMLA by 15 August 2026, with a provisional list of eligible entities expected by the end of September 2026. Under the final draft implementing standard on cooperation (Article 5), supervisors then collect eligibility information and data points as of 31 December 2026 from provisionally eligible entities, finish by 31 March 2027 and pass them to AMLA by 31 May 2027. The EBA published a public working draft of the data model for the 2027 eligibility collection in August 2026.

If you might be eligible, three things matter before January. Count member states the way AMLA will. Give the data set an owner outside the compliance team's spreadsheets, because the same data points feed the business-wide risk assessment: AMLA's draft BWRA guidelines tell firms to refer to the supervisory data points when assessing inherent risk. And rehearse the extract, since the reference date is 31 December and national collections close three months later.

Groups with a non-EU parent must name an EU parent undertaking

Where a group's head office is outside the EU and at least two of its subsidiaries are obliged entities in the EU, one EU undertaking must carry the parent role: an obliged entity, not a subsidiary of another EU obliged entity, with sufficient prominence in and understanding of the group, and the responsibility for group-wide requirements (Article 2(1)(42)(b)). The final draft group-wide standard sets the tests. Prominence comes first from holding-company status, cross-border establishments, customer numbers and transaction volumes, then turnover, balance sheet and staff (draft Article 10). Understanding comes from deciding strategy, important transactions, internal controls or material outsourcing for most EU entities, then from compliance staff numbers (draft Article 11). The chosen entity notifies its supervisor and the other EU entities within 28 calendar days of the situation arising, or on the standard's date of application for groups already in it, and the supervisor approves within 60 calendar days (draft Article 13).

An illustrative case, with a fictional group: a Canada-headquartered payments group holds an e-money institution in the Netherlands and a payment institution in Portugal through separate Canadian holding companies. Neither is the other's parent, so one must be identified. If the Dutch entity serves most EU customers, runs the shared transaction monitoring for both and employs most of the EU compliance staff, it is the likelier choice under draft Articles 10 and 11.

Three further points for these groups. Group-wide requirements cover the EU entities; Article 16(1) extends them to third-country branches and subsidiaries only for groups headed in the EU. For AMLA's eligibility data, "head office outside the EU" means the ultimate parent, and an EU holding company that becomes an obliged entity only on 10 July 2027 must still be identified, with a subsidiary reporting for the group (AMLA FAQ). And information flowing upward needs a legal view: Article 73(3) allows suspicion-related disclosures between obliged entities in the same group and to their third-country branches and subsidiaries that follow group-wide policies, and it does not name a parent outside the EU.

Sector rules change the checklist for payments, crypto, insurance, banking and car finance

Each of these sectors has AMLR articles that a generic checklist misses.

Payments and e-money

Account information service providers fall outside the AMLR's definition of financial institution (Article 2(1)(6)(a) excludes point 8 of Annex I to PSD2), and payment initiation providers treat the merchant as their customer (Article 19(6)(d)). Other payment and e-money firms apply CDD to occasional transfers of funds of EUR 1,000 or more (Article 19(2)). Issuers of virtual IBANs must identify their users, and the institution servicing the underlying account must be able to obtain that identity within 5 working days (Article 22(3)). Activity through agents or distributors in other member states generally follows the host state's rules (Article 8(5)), and host states may require a central contact point (AMLD6 Article 41(1)). For remitters, the draft linked-transactions standard sets a one-month linking window and treats three or more transactions in 12 months as a sign of a business relationship (draft Articles 2(4) and 3(2)). See also our payments and fintech page.

Crypto-asset service providers

Crypto-asset service providers are financial institutions for every crypto-asset service except advice (Article 2(1), points (6)(i) and (8)). They apply CDD to occasional transactions from EUR 1,000 and at least identify and verify the customer below that (Article 19(3)). Transfers with self-hosted addresses need a risk assessment and mitigating measures (Article 40), relationships with non-EU counterparts need enhanced checks including whether the respondent is licensed or registered (Article 37), and accounts that allow anonymization, including through anonymity-enhancing coins, are prohibited (Article 79(1)). An entity on ESMA's MiCA Article 110 list of non-compliant entities counts as a shell institution (Article 2(1)(23)(b)). AMLA's advisory note on the end of MiCA's transitional period asks CASPs taking on customers from exiting providers to assess them individually and scale their monitoring. The MiCA side is in our MiCA compliance checklist.

Life insurers

Life and investment-related insurers, insurance holding companies and most life insurance intermediaries are financial institutions (Article 2(1)(6)(b) and (c)). Beneficiaries are recorded by name, or by enough information about a class to identify them at payout, and verified at payout (Article 47). PEP status of beneficiaries is determined no later than payout or assignment, and for higher risks senior management is informed before payout (Article 44). Where CDD cannot be completed, the insurer may refrain from transactions, including payouts, instead of terminating (Article 21(1)).

Banks

Banks run enhanced checks on third-country correspondent relationships (Article 36), must act on any AMLA recommendation about a specific third-country respondent (Article 38) and may not deal with shell institutions (Article 39). Personalized services handling EUR 5 million or more for a higher-risk customer with total assets of at least EUR 50 million trigger extra measures (Article 34(5)), and sanctions screening must run on every new designation (Article 26(4)).

Automotive finance and dealers

A car maker's finance arm that lends or leases without a banking license is still a financial institution: lending and financial leasing are points 2 and 3 of Annex I to the CRD, which Article 2(1)(6)(a) brings in, and Article 2(1)(6)(g) names consumer and mortgage creditors. AMLA's selection methodology has a separate category for credit providers other than credit institutions (AMLA Regulation Article 12(4)(d)), and its April 2026 template correction added credit providers to the entity types. Credit and financial institutions providing services for the purchase of motor vehicles of EUR 250,000 or more for non-commercial purposes must report those transactions to the FIU (Article 74(2)) and collect information on intended use (Article 25). Dealers that trade such vehicles as a regular or principal activity become obliged entities (Article 3(3)(f) and Annex IV), report those sales (Article 74(1)(a)) and treat their supplier as a customer for CDD (Article 19(6)(a)), so a manufacturer's sales company should expect CDD questions from its own dealers. Annex IV says "exceeding EUR 250 000" while Article 74 says "at least", so set the reporting trigger at EUR 250,000 inclusive. See also our financial services page.

The next 90 days run from gap analysis to a board decision before January

Window Actions Owner Output
6 to 18 Oct 2026 Read the three final draft standards; decide on AMLA's SDD roundtables (expressions of interest close 18 Oct); name an owner for each of the 14 workstreams CCO, MLRO Owner list; roundtable decision
19 Oct to 15 Nov 2026 Run the article-level gap analysis for every workstream; compare the CDD data model field by field; inventory outsourced tasks against Art. 18(3); count member states for AMLA eligibility MLRO, KYC operations, COO Gap register with a RAG status per row
16 Nov to 13 Dec 2026 Rebuild the BWRA methodology on the draft guidelines; size remediation by risk band; review monitoring governance against the draft guidelines; groups: identify the EU parent undertaking MLRO, head of monitoring, group CCO Draft methodology; remediation plan; parent decision paper
14 Dec 2026 to 3 Jan 2027 Take the readiness update to the board with decisions and budget; if provisionally eligible, freeze the data set as of 31 Dec 2026; diary a re-check date for every pending AMLA instrument CCO, CFO Board minute; funded 2027 plan

The board needs one page: status, decisions, dependencies and dates

The one page I would send has eight lines:

  1. Headline: overall RAG status and the date the AMLR applies, 10 July 2027.
  2. Workstreams: the 14 rows with RAG status, owner and next milestone.
  3. Decisions needed now: the compliance manager appointment (Article 11(1)), remediation funding, outsourcing changes, and for groups the EU parent undertaking.
  4. External dependencies: AMLA instruments still pending, with AMLA's own planned dates.
  5. AMLA selection: eligibility status, and the 31 March 2027 data deadline if it applies.
  6. Top three risks: for example the CDD data model, vendor contracts and staffing, each with its mitigation.
  7. Evidence readiness: what an examiner could sample today, row by row.
  8. Next update: the date, and what will have changed by then.

Keep the plan current by treating every AMLA publication as a change event

The checklist is accurate on 5 October 2026 and will drift. Still to come before or around July 2027: final guidelines on the business-wide risk assessment and ongoing monitoring, the final reporting format, guidelines on risk factors, the simplified due diligence guidelines, nine more guideline mandates, the Commission's adoption of the three standards and their publication in the Official Journal, Commission delegated acts identifying high-risk third countries under Article 29, 27 national laws transposing AMLD6, and whatever guidance your national supervisors add.

Handle each as a change: log it, run a short impact assessment, update the affected checklist rows and date them. Our regulatory change impact assessment template fits each AMLA instrument, the horizon scanning template holds the ones still in consultation, and the obligations register takes the rows once they apply. A regulatory change management policy sets who signs off, and how compliance teams track regulatory changes covers the feed. Outsourced KYC and screening vendors belong in your third-party risk process as well as in row 10.

This is the loop RegWatch, my company, is built for. A watchlist covers the regulators and sources you choose (AMLA, the EBA, the Official Journal, your national supervisors and FIUs, and any other jurisdiction that publishes its rules online), and monitoring runs on the schedule you set. Triage scores each finding against your company profile and writes why it matters with the source clause cited, and an accepted alert converts to an obligation with an owner, a deadline and evidence. Lifecycle stages from Consultation to Adopted and In force keep the tracker's status column current, the tamper-evident, append-only audit log records who decided what and when, and board-ready reports feed the one-page update above. If you want to see it on your own regulators, book a demo and we will run the session on the AMLA and national sources you name. More of this regime lives in the financial services hub.


This article is general information, not legal advice.

Download the Excel template

Free, no email needed. Sheets: READ ME, Readiness checklist, AMLA standards tracker, 90-day plan, Changelog. All templates

Questions

When does the AMLR apply?

Regulation (EU) 2024/1624 applies from 10 July 2027 to every obliged entity, except football agents and professional football clubs, which follow on 10 July 2029 (Article 90). It is directly applicable, so it replaces the national laws that transposed the Fourth AML Directive, which is repealed on the same day. AMLA's standards run on a separate clock: the three final drafts published on 1 October 2026 each apply six months after their own entry into force.

What is the difference between the AMLR and AMLD6?

The AMLR is the rulebook for obliged entities: internal controls, customer due diligence, beneficial ownership, reporting and record retention, applying directly from 10 July 2027. AMLD6, Directive (EU) 2024/1640, is transposed by member states, mostly by 10 July 2027, and governs the authorities: supervisors, FIUs, beneficial ownership and bank account registers, and sanctions. Its Article 55 requires maximum fines for credit and financial institutions of at least EUR 10 million or 10% of turnover.

Who will AMLA supervise directly?

AMLA assesses credit and financial institutions, and groups, operating in at least six member states, counting freedom-to-provide-services activity above draft thresholds of 20,000 resident customers or EUR 50 million of transactions per state. Those whose residual risk is classified high qualify (AMLA Regulation Articles 12 and 13). AMLA says it will select up to 40 in 2027, using data as of 31 December 2026, and start direct supervision in 2028.

Does the AMLR apply to crypto firms?

Yes. Crypto-asset service providers are financial institutions under the AMLR for every crypto-asset service except advice (Article 2(1), points (6) and (8)). They apply customer due diligence to occasional transactions from EUR 1,000 and at least identify and verify customers below that (Article 19(3)), mitigate risks of transfers with self-hosted addresses (Article 40), run enhanced checks on non-EU correspondents (Article 37) and may not keep accounts that allow anonymization (Article 79).

When do AMLA's customer due diligence standards apply?

Not automatically on 10 July 2027. The final draft RTS under Article 28(1) AMLR, published on 1 October 2026, applies six months after its entry into force (draft Article 29). The Commission has three months to decide on adoption, and Parliament and Council three months to object, extendable by three. Existing customer files must then be brought in line within one year for higher-risk customers and five years for the rest (draft Article 28).

What should firms do before July 2027?

Run an article-level gap analysis, appoint a compliance manager from the management body (Article 11), rebuild the business-wide risk assessment on AMLA's draft guidelines, size the remediation of existing customer files, inventory outsourced AML tasks for notification to the supervisor (Article 18) and, for groups, identify the EU parent undertaking. Then track AMLA's pending instruments, several of which are planned for the months before the deadline.

Terms in this guide

Sources

  1. Regulation (EU) 2024/1624 (AMLR), EUR-Lex accessed 6 Oct 2026
  2. Regulation (EU) 2024/1624, EUR-Lex document information (corrigenda, no amendments) accessed 6 Oct 2026
  3. Directive (EU) 2024/1640 (AMLD6), EUR-Lex accessed 6 Oct 2026
  4. Regulation (EU) 2024/1620 (AMLA Regulation), EUR-Lex accessed 6 Oct 2026
  5. Directive (EU) 2015/849 (Fourth AML Directive), EUR-Lex accessed 6 Oct 2026
  6. Directive 2013/36/EU (CRD), Annex I list of activities, EUR-Lex accessed 6 Oct 2026
  7. Directive (EU) 2015/2366 (PSD2), Annex I payment services, EUR-Lex accessed 6 Oct 2026
  8. Regulation (EU) 2023/1114 (MiCA), Article 110 register of non-compliant entities, EUR-Lex accessed 6 Oct 2026
  9. AMLA: Press release, AMLA finalises key standards for the private sector (1 October 2026) accessed 6 Oct 2026
  10. AMLA: Final report, draft RTS under Article 28(1) AMLR on customer due diligence accessed 6 Oct 2026
  11. AMLA: Factsheet on the RTS on customer due diligence under Article 28(1) AMLR accessed 6 Oct 2026
  12. AMLA: Final report, draft RTS under Article 19(9) AMLR on business relationships, occasional and linked transactions accessed 6 Oct 2026
  13. AMLA: Final report, draft RTS under Articles 16(4) and 17(3) AMLR on group-wide requirements accessed 6 Oct 2026
  14. AMLA: Factsheet on group-wide minimum requirements accessed 6 Oct 2026
  15. AMLA: Regulatory instruments overview (last updated 30 September 2026) accessed 6 Oct 2026
  16. AMLA: Public consultations accessed 6 Oct 2026
  17. AMLA: Consultation on draft Guidelines on business-wide risk assessment (16 April to 15 July 2026) accessed 6 Oct 2026
  18. AMLA: Consultation paper, draft Guidelines under Article 10(4) AMLR accessed 6 Oct 2026
  19. AMLA: Consultation on draft Guidelines on ongoing monitoring of a business relationship (3 June to 3 September 2026) accessed 6 Oct 2026
  20. AMLA: Consultation paper, draft Guidelines under Article 26(5) AMLR accessed 6 Oct 2026
  21. AMLA: Consultation on draft ITS on the format for reporting suspicions and providing transaction records (2 July to 20 September 2026) accessed 6 Oct 2026
  22. AMLA: Sectoral roundtables on simplified customer due diligence (2 October 2026) accessed 6 Oct 2026
  23. AMLA: Single Programming Document 2026 to 2028, Annex XI planning on RTS, ITS and guidelines accessed 6 Oct 2026
  24. AMLA: EBA and AMLA complete handover of AML/CFT mandates (19 January 2026) accessed 6 Oct 2026
  25. AMLA: About AMLA, timeline accessed 6 Oct 2026
  26. AMLA: Data collection exercise to test risk assessment models (26 January 2026) accessed 6 Oct 2026
  27. AMLA: Advances preparations for the 2027 selection exercise (17 April 2026) accessed 6 Oct 2026
  28. AMLA: Next step toward 2027 selection of entities for direct supervision (12 May 2026) accessed 6 Oct 2026
  29. AMLA: Interpretative note on the identification of provisionally eligible obliged entities (2026) accessed 6 Oct 2026
  30. AMLA: FAQ on the data collection for identifying provisionally eligible obliged entities accessed 6 Oct 2026
  31. AMLA: Final report, draft ITS under Article 15(3) AMLAR on cooperation for direct supervision accessed 6 Oct 2026
  32. AMLA: EBA publishes draft reporting framework for the 2027 eligibility data collection (4 August 2026) accessed 6 Oct 2026
  33. AMLA: Advisory note on ML/TF risks at the end of the MiCAR transitional period (June 2026) accessed 6 Oct 2026
  34. AMLA: Survey on central contact points for EMIs and PSPs (6 August 2026) accessed 6 Oct 2026
  35. AMLA: AMLA and EDPB to develop joint guidelines on partnerships for information sharing (1 July 2026) accessed 6 Oct 2026

See which of this month’s changes apply to you.

Book a session on the regulators and markets you name.

Book a demo