You are currently viewing AMLA Finalises Three Key Draft Standards for the EU AML Rulebook: What Financial Institutions Need to Know

AMLA Finalises Three Key Draft Standards for the EU AML Rulebook: What Financial Institutions Need to Know

  • Post category:AML
AMLA Has Finalised Its Three Core Standards for the EU AML Rulebook. Here Is What Financial Institutions Need to Know. | Truth Technologies

On 1 October 2026, the EU's Anti-Money Laundering Authority announced that it had finalised three sets of draft regulatory technical standards covering business relationships and occasional transactions, customer due diligence, and group-wide AML/CFT arrangements. The final drafts have been submitted to the European Commission for adoption and are not yet binding law. They provide important detail for compliance planning, while their definitive requirements and application dates will depend on the adopted texts.

For financial institutions and other obliged entities within the scope of the EU AML framework, these drafts provide important detail on forthcoming compliance requirements. The AMLR generally applies from 10 July 2027; the definitive RTS requirements and application dates will depend on the adopted texts.


What AMLA Is and Why This Announcement Matters

AMLA, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, was established under Regulation (EU) 2024/1620 and is headquartered in Frankfurt. Its responsibilities include directly supervising selected high-risk cross-border financial institutions and groups, promoting supervisory convergence and developing the EU AML/CFT rulebook, and coordinating and supporting financial intelligence units. AMLA became operational on 1 July 2025; its direct supervision of selected institutions is scheduled to begin in 2028.

EU AML/CFT supervision has relied primarily on national authorities, while earlier directives were implemented through national law. This framework left room for differences in requirements and supervisory practices across Member States. AMLA's work, alongside the directly applicable AMLR, aims to strengthen consistency. These three final draft standards mark an important milestone in developing the harmonised rulebook; national supervisors will continue to play a central role.

"AMLA has finalised three sets of regulatory technical standards defining key measures companies and professionals must apply to reduce money laundering and terrorist financing risks."

AMLA Press Release, 1 October 2026

The consultation process was substantial. The CDD consultation received 325 responses, and more than 1,600 stakeholders participated in the public hearing on 24 March 2026. The CDD final report reflects two consultation stages: the EBA's 2025 consultation and AMLA's consultation from 9 February to 8 May 2026.


The Three Standards: What Each One Covers

Standard 1 — Article 19(9) AMLR

Business Relationships and Occasional Transactions

This draft standard clarifies when dealings with a customer constitute a business relationship, when transactions are occasional, and when separate transactions must be treated as linked for applying CDD thresholds. An occasional transaction does not automatically qualify for simplified due diligence; simplified measures depend on the applicable risk-based conditions.

For institutions processing non-account transactions, the draft provides criteria for classifying customer dealings and identifying linked transactions for CDD purposes. It does not introduce additional lower thresholds beyond those already provided by the AMLR.

Standard 2 — Article 28(1) AMLR

Customer Due Diligence

This draft RTS specifies information and measures for customer identification and verification across different customer categories and risk levels. It addresses simplified due diligence in lower-risk situations, non-face-to-face verification and electronic identification, and measures for identifying politically exposed persons (PEPs), their family members and known close associates.

The underlying PEP obligations arise from the AMLR; the draft RTS provides further detail to support their implementation. PEP screening should cover customers, beneficial owners, and persons on whose behalf or for whose benefit a transaction or activity is conducted. Together with the AMLR, the draft is intended to support a more consistent EU-wide approach to CDD.

Standard 3 — Articles 16(4) and 17(3) AMLR

Group-Wide AML/CFT Requirements

The third draft standard addresses group-wide AML/CFT arrangements, including policies, procedures, controls and information sharing. For groups within scope, it provides detail on coordinating compliance across relevant entities rather than relying solely on separate entity-level programmes.

It also addresses additional measures for subsidiaries and branches in third countries, particularly where local legal restrictions prevent implementation of group-wide AML/CFT requirements. This makes the draft relevant to cross-border operations beyond the EU as well as within it.


An Important Nuance: Finalised Does Not Mean In Force

The terminology around these standards requires careful reading. AMLA has finalised the drafts and submitted them to the European Commission. That is a significant milestone but it is not the end of the legislative process. The Commission must formally adopt the standards before they become binding. After adoption and publication in the EU Official Journal, the standards are proposed to apply six months after entry into force. No fixed calendar date has been confirmed for any of these steps.

Where the Standards Stand Now

30 September 2026 — Final drafts completed by AMLA. The 1 October announcement confirms finalisation and submission to the European Commission.

1 October 2026 — AMLA press release confirms submission to the European Commission.

Next step: Commission adoption — No fixed date confirmed. Commission must formally adopt the drafts before they become binding.

Following adoption and Official Journal publication — The draft standards propose application six months after their entry into force. The definitive dates will depend on the adopted texts.

10 July 2027 — The AMLR generally applies from this date. Institutions should prepare for that deadline and monitor the adopted RTS for their definitive application dates. Football agents and professional football clubs have a later AMLR application date of 10 July 2029.

The practical implication is that compliance teams should use the drafts for preparation while distinguishing confirmed AMLR deadlines from the RTS dates still to be established. For most obliged entities, the AMLR's 10 July 2027 application date is the central planning milestone. Teams should monitor Commission adoption and Official Journal publication for the definitive RTS requirements and dates.


What This Means for Financial Institutions

For financial institutions and other obliged entities within the scope of the EU AML framework, the drafts provide a useful basis for gap analysis and implementation planning. Several practical implications stand out.

CDD programmes should be assessed against the AMLR and the forthcoming adopted RTS, not solely against existing national requirements. Institutions should identify gaps in customer and beneficial-owner information, verification methods, simplified due diligence measures and PEP identification. The final draft is a planning reference; the adopted text will establish the definitive technical requirements.

PEP screening configurations should reflect the AMLR's obligations and the identification measures specified in the adopted CDD RTS. Institutions can begin reviewing coverage of customers, beneficial owners, persons on whose behalf or for whose benefit transactions or activities are conducted, and relevant family members and known close associates. The adopted RTS will not require national transposition in the way a directive does.

Group compliance arrangements should be reviewed alongside entity-level programmes. Groups should assess their policies, controls, responsibilities and information-sharing arrangements against the draft and, subsequently, the adopted text. The review should include subsidiaries and branches in third countries, especially where local laws restrict the implementation of group-wide requirements.

The distinction between business relationships and occasional transactions needs a documented decision framework. Compliance teams should review classification criteria, linked-transaction identification and the application of CDD thresholds against the draft RTS, then update their procedures for the adopted text. The resulting approach should be documented and defensible to the relevant AML/CFT supervisor.


Frequently Asked Questions

What is AMLA?
AMLA is the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, established under Regulation (EU) 2024/1620 and headquartered in Frankfurt. It became operational on 1 July 2025. Its responsibilities include developing the AML/CFT rulebook, promoting supervisory convergence, coordinating and supporting financial intelligence units, and preparing for direct supervision of selected high-risk cross-border financial institutions and groups from 2028.
What are the three AMLA standards finalised in October 2026?
AMLA announced three final draft RTS on 1 October 2026: business relationships, occasional transactions and linked transactions under Article 19(9) AMLR; customer due diligence under Article 28(1); and group-wide arrangements, including additional measures for subsidiaries and branches in third countries, under Articles 16(4) and 17(3). The drafts have been submitted to the European Commission for adoption.
Are the AMLA standards already binding?
No. The three standards published on 1 October 2026 are final drafts submitted to the European Commission for adoption. They are not yet binding law. After the Commission formally adopts them and they are published in the EU Official Journal, they are proposed to apply six months after entry into force. No fixed calendar date has been confirmed for Commission adoption.
When does the EU AML Regulation apply?
The EU Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, generally applies from 10 July 2027. Football agents and professional football clubs have a later application date of 10 July 2029. Institutions should prepare for the applicable AMLR deadline and monitor the adopted RTS for their definitive requirements and application dates.
Which institutions are affected by the AMLA standards?
The drafts address obliged entities within the EU AML framework, covering relevant financial and non-financial businesses and professions. Examples include credit institutions, payment institutions, crypto-asset service providers and certain legal, accounting and real-estate activities. Applicability depends on the AMLR's scope and the relevant provisions; the group-wide requirements concern entities within the applicable group arrangements. Being subject to the rulebook does not mean an entity will be directly supervised by AMLA.

The Sentinel Perspective

Sentinel's PEP and sanctions screening, continuous monitoring, match-review workflows and configurable audit logs can support relevant elements of an institution's AML/CFT programme. Institutions should assess these capabilities alongside their wider CDD, transaction-classification and group-governance controls when preparing for the AMLR and the adopted technical standards.

See How Sentinel Supports PEP Screening and AMLR Preparation

Request a demonstration tailored to your institution's EU compliance program and AMLR preparation requirements.

Truth Technologies provides AML, KYC, OFAC, and sanctions screening compliance solutions through the Sentinel platform. This post is published for informational purposes only and does not constitute legal advice. The AMLA regulatory technical standards described in this post are final drafts submitted to the European Commission for adoption and are not yet binding law. Regulatory information is based on the official AMLA and EUR-Lex publications cited. Statements about Sentinel describe Truth Technologies' product capabilities and do not constitute regulatory approval or a guarantee of compliance. All facts are sourced from official AMLA and EUR-Lex publications linked above.