Skip to content
ABC Tech
Book a demo

One rulebook, one authority: what the EU AML package and AMLA ask of a bank

From 10 July 2027, anti-money laundering rules for every EU bank sit in one regulation, read the same way in every member state. A new authority in Frankfurt writes the detail and will supervise the largest cross-border groups itself. For most banks, the hard part is the evidence behind every customer file.

ABC Tech5 min read

What the package requires

The package has three parts. Regulation (EU) 2024/1624 (AMLR) is the single rulebook for obliged entities. Directive (EU) 2024/1640 (AMLD6) sets what member states must build: supervisors, financial intelligence units and registers. Regulation (EU) 2024/1620 creates the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), seated in Frankfurt. For a bank, five things change.

  • One directly applicable rulebook. The AMLR applies as written in every member state. National laws that transposed the old directives, with their local variations, give way to one text and to AMLA's technical standards.
  • Customer due diligence on common terms. The bank identifies and verifies customers when it opens a relationship and for occasional transactions of EUR 10,000 or more. Customer information is kept up to date: at least every year for higher-risk customers and at least every five years for everyone else.
  • Beneficial ownership at 25%. A beneficial owner is anyone holding, directly or indirectly, 25% or more of the shares, voting rights or other ownership interest, with indirect holdings multiplied along the chain. The Commission may set lower thresholds, no lower than 15%, for categories of entity that carry higher risk.
  • A cap on large cash payments. Traders in goods and services may accept or make cash payments only up to EUR 10,000. Member states may set a lower limit after consulting the European Central Bank. The cap does not apply to payments between private individuals or to deposits made at a bank's premises.
  • Group-wide policies. A parent sets AML policies, procedures and controls that apply across the group, including branches and subsidiaries in third countries. That is how the rulebook reaches an EU group's banks in candidate countries.

The dates

MilestoneDate
AMLA established26 June 2024
AMLA Regulation applies; AMLA starts operations1 July 2025
AMLA final draft standards on entity risk assessment and on selection for direct supervision16 December 2025
Legal deadline for AMLA's draft standards on customer due diligence10 July 2026
AMLA starts the first selection for direct supervision1 July 2027
AMLR applies; AMLD6 transposition deadline10 July 2027
AMLA starts direct supervision of selected entities2028, six months after the list is published

AMLA consulted on its draft customer due diligence standards from February to May 2026, and on draft guidelines for ongoing monitoring until September 2026. The final texts were still pending in September 2026. Banks that wait for them will run out of time.

Who AMLA supervises directly

AMLA will select credit and financial institutions, or groups, that operate in at least six member states, including the home state, and whose residual risk is classified as high under its methodology. AMLA expects 40 entities in the first cohort, and where no entity in a member state qualifies, it runs an additional selection there. The selection is repeated every three years.

Every other bank stays with its national supervisor, under the same AMLR and the same technical standards, and AMLA supervises it indirectly through that supervisor. Supervision moves closer to one standard for everyone.

Where banks get stuck

The rules are clear. The gap sits in data and systems built for a national rulebook.

One rulebook replacing national variants

Banks tuned their procedures to local laws and local supervisory habits. Those variations end. Group banks running several national versions of the same process now have to converge on one, and prove it.

Customer data that will not hold up

The standards ask for specific identification data, verified against reliable sources, with a clear record of what was checked. Files opened years ago under older rules often miss fields, hold unverified documents or store data as free text. Remediation of the back book is the largest single task.

Ongoing monitoring that is only periodic

Refresh cycles of one and five years are a minimum. A change in ownership, activity or risk should trigger a review before the calendar does. That needs monitoring connected to the customer record, with every alert and its outcome kept.

Beneficial ownership through the chain

Calculating indirect ownership means walking every layer of a corporate structure and multiplying holdings. Registers help, but the bank remains responsible for its own view, and it has to act when its view and the register disagree.

Evidence for supervisors

Under one rulebook, supervisors compare banks directly. A policy is not enough. The bank has to show, customer by customer, which rule applied, which data it relied on and who decided.

What it takes inside the platform

AML compliance becomes a property of the data model and the transaction flow.

  • One customer record. Identification, verification results, risk score, beneficial owners and review dates live on the master record every module reads from.
  • Screening before execution. Sanctions and AML checks run inside the transaction flow, so a payment is stopped before it leaves the bank.
  • Risk rules as configuration. Thresholds, refresh cycles and escalation rules change on parameters when AMLA's final standards land, without a code release.
  • A decision trail on every case. Each check, alert, approval and override records who acted, under which rule and with what authority.
  • Controls that match the risk. Role-based access and four-eyes approval for high-risk onboarding, overrides and exits.

Where ABC Tech fits

In the ABC Tech core, AML screening runs in every module before a transaction executes, and every action is written to a verification diary showing who acted, the rule applied and the authority behind it, with role-based access down to the record and four-eyes verification where the bank requires it. ABC Tech Digital onboarding opens accounts fully digitally for individual customers, with document and liveness verification plus sanctions, PEP and adverse-media screening on the Sumsub platform, the bank's own risk rules deciding, and one case file holding every check, decision and reviewer before a live account is created in the core; company customers are outside its scope. The Reporting Platform traces every figure to the record behind it.

Sources
  1. Regulation (EU) 2024/1624 (AMLR), Official Journal of the EU
  2. Regulation (EU) 2024/1620 establishing AMLA, Official Journal of the EU
  3. AMLA: About AMLA and timeline
  4. AMLA: Consultation on the draft RTS on customer due diligence
  5. AMLA: Regulatory instruments

Transform your operating model
with ABC Tech

Book a demo