Zum Hauptinhalt

New implementing rules under the AMLR: what can you do now?

Much has already been said about the Anti-Money Laundering Regulation (AMLR), including in our series of alerts on customer due diligence, governance, outsourcing and the group-wide approach. But reading the Regulation alone reveals only part of the obligations. In dozens of places, the AMLR sets out broad requirements that will be developed further through technical standards and guidelines. These implementing rules have taken shape over the past six months. Consultations have been published on customer due diligence (CDD), the distinction between business relationships and occasional transactions, the business-wide risk assessment and group-wide requirements. Most recently, a consultation on ongoing monitoring was also published. In this article, we explain what these texts add to the Regulation itself. One important caveat applies: these are still consultation drafts. Their broad direction is becoming clear, but the details may change.

Level 2 rules

The AMLR contains various obligations that will be developed further at European level through regulatory technical standards (RTS) and implementing technical standards (ITS). These standards specify aspects of the AMLR, such as the information institutions must collect, the criteria they must apply and the formats they must use. The European Commission ultimately adopts RTS in the form of delegated regulations and ITS through implementing regulations. Level 2 rules therefore form a binding supplement to the AMLR.

Customer due diligence: from broad requirements to a specified set of information – Article 28(1) AMLR

The draft RTS under Article 28(1) AMLR covers customer due diligence as a whole. It describes the information needed for standard, simplified and enhanced due diligence. It also addresses the purpose and intended nature of a relationship, the identification of politically exposed persons (PEPs), screening against targeted financial sanctions, and the features electronic identification means must have to establish and verify customers’ identities reliably.

The draft RTS does not prescribe a uniform list of documents for every customer file. It does, however, specify the information required, the standards sources must meet and the circumstances in which documentation is needed. Institutions therefore retain room to choose appropriate documents and sources of information. An address, for example, could be established using a reliable register or, where necessary, evidence provided by the customer. AMLA does not add further rules where it considers the AMLR sufficiently clear.

What this means in practice: existing documentation requirements do not necessarily need to be replaced. Institutions must, however, be able to demonstrate that their forms, supporting documents and sources collectively provide the prescribed information and meet the draft RTS requirements for verification, source reliability and, where required, documentation. A practical first step is to map onboarding forms, file requirements and customer acceptance policies against these requirements. This will quickly reveal where information is missing, insufficiently verified or requested more than once.

RTS on business relationships, occasional transactions, linked transactions and lower thresholds for customer due diligence – Article 19(9) AMLR

The draft RTS under Article 19(9) AMLR sets out criteria for three concepts. A business relationship is one that is expected, when established, to have an element of duration. An occasional transaction takes place outside such a continuing relationship. Linked transactions are separate transactions that are connected in practice through their timing, parties, purpose or other characteristics. AMLA aims to harmonise the application of customer due diligence across the EU and prevent thresholds from being circumvented by splitting transactions. Some criteria apply to all institutions; others are sector-specific.

Two points stand out. For now, AMLA has not introduced additional lower thresholds for customer due diligence, although its mandate allows it to do so. The criteria for linked transactions also call for a systematic assessment across relevant transactions. Consider several payments involving the same customer or beneficiary that each fall below the threshold but exceed it when combined. For institutions that process large numbers of occasional transactions, this may have the greatest operational impact.

What this means in practice: first, assess what information the institution has, or can reasonably be expected to have, to link transactions. This could include the customer, beneficiary, payment method, timing and purpose of a transaction. The draft RTS does not require an institution to request additional information from a customer solely for this assessment if it would not otherwise need that information. Then use historical data to test whether existing systems and manual controls identify split transactions. Finally, document the period and characteristics used to determine whether transactions are linked in each relevant sector.

Delegated regulation containing RTS on group-wide AML/CFT requirements and additional measures for third countries – Articles 16(4) and 17(3) AMLR

The draft RTS sets minimum requirements for group-wide policies, procedures and controls, including rules on information sharing within a group. It also contains criteria for identifying the EU parent undertaking and measures for situations in which local law in a third country prevents compliance with the AMLR. AMLA has combined the two mandates in one text because the requirements complement each other.

For groups that already have group-wide policies under the Dutch Money Laundering and Terrorist Financing (Prevention) Act (Wwft), the first part contains little that is new. The second part may have a greater impact. It builds on Delegated Regulation (EU) 2019/758 on additional measures in third countries, but extends further under the AMLR. Consider a subsidiary outside the EU that is prohibited by local privacy law from sharing customer files with its European parent. The group must then establish, with supporting reasons, which information cannot be shared, inform the supervisor and take other risk mitigation measures. If those measures are insufficient, the group may, depending on the circumstances, have to terminate business relationships, refuse occasional transactions or close some or all of its operations in the third country.

What this means in practice: prepare an up-to-date overview of restrictions on information sharing for each jurisdiction. Record the legal basis for each restriction, what information can still be shared, which alternative controls are available and who within the group makes escalation decisions.

Implementing regulation containing ITS on a common format for reports to FIUs – Article 69(3) AMLR

The draft ITS under Article 69(3) AMLR harmonises two separate flows of information. First, it sets out a format for reports of suspected money laundering and terrorist financing submitted by obliged entities to Financial Intelligence Units (FIUs). Second, it provides templates for transaction data supplied by credit and financial institutions at an FIU’s request. The ITS introduces a common core set of data points and templates for each type of institution.

The data points to be completed depend on the activity and the nature of the suspicion. Where an unusual payment pattern is suspected, for example, relevant information may include the parties involved, accounts, amounts, currencies, transaction times and the grounds for suspicion. AMLA distinguishes between mandatory fields, fields that are mandatory if the information is available, optional fields and fields that depend on earlier answers or additional FIU requirements.

What this means in practice: compare the proposed data points with the information held in source systems and determine where missing information will come from. Internal escalation forms are not covered by the ITS, but they must provide compliance teams with the information needed for an external report. The FIU will also help determine the technical arrangements. An institution does not need its own automated reporting system if it reports through the FIU’s platform. Bear in mind that the list of data points may still change following review by the FIUs.

Level 3 guidance

Level 3 consists of AMLA guidelines. These do not amend the AMLR or the technical standards, but clarify how AMLA expects them to be applied consistently and on a risk-based basis.

Guidelines on the business-wide risk assessment (BWRA) – Article 10(4) AMLR

The draft guidelines under Article 10(4) AMLR address the business-wide risk assessment. This obligation is not new, but the AMLR extends it to include the risk that targeted financial sanctions are not implemented or are circumvented. The assessment should help institutions identify that risk and put appropriate controls in place.

The assessment has four components: an overview of the institution and its activities, an assessment of inherent risks, an assessment of controls and a determination of residual risk. Institutions must use relevant internal and external sources of information.

The guidelines do not prescribe a fixed methodology. The depth of the assessment can be tailored to the nature, size and complexity of the institution. The chosen approach, sources used and judgements made must, however, be clearly documented and capable of explanation.

What this means in practice: check whether the current BWRA clearly covers all four components and explicitly includes sanctions risks. Also document how its findings inform the institution’s policies, procedures, controls and priorities.

Guidelines on monitoring business relationships – Article 26(5) AMLR

The draft guidelines under Article 26(5) AMLR comprise three connected parts: general principles, keeping customer information up to date, and the framework for transaction and activity monitoring.

The first substantive part explains how documents, data and information about customers should be kept current. AMLA distinguishes between periodic reviews and reviews prompted by an event. Both are carried out on a risk-based basis. An event could be a change in ownership, management, activities, geographical exposure or transaction behaviour. AMLA provides a non-exhaustive list of internal and external sources that can be used to update information.

For existing files, the consequences may be less extensive than is often assumed. There is no general obligation to onboard the entire existing customer base again before 10 July 2027. Nevertheless, existing files cannot always be left untouched until the deadline for their periodic review. An event, increased risk or doubts about the accuracy or adequacy of information may require an earlier review. The timeframes for periodic reviews are set out in Article 26(2) AMLR. The draft RTS on customer due diligence also contains proposed transitional arrangements for existing customers. Which files should be reviewed first? Start with the existing risk classification and consider the age and completeness of each file. Take account of relevant changes, geographical exposure, sanctions risk and signals from transaction or activity monitoring.

The second substantive part concerns the monitoring framework. For institutions that process payments continuously, transaction monitoring will be a significant focus. For other institutions, activity monitoring may carry more weight. Consider a service provider that notices, during a long-standing relationship, a sudden change in a customer’s ownership structure, source of funding or geographical focus. Changes like these, as well as transactions, may prompt a review or further investigation.

What this means in practice: create a single implementation overview covering, at a minimum, review frequencies, trigger events, data sources, scenarios or indicators, responsibilities, escalation routes and how outcomes are recorded. Then test a sample of customer files to establish whether the policy can be applied in practice.

Where are the implementing rules in the legislative process?

AMLA tracks progress in its overview of regulatory instruments. The consultations on the draft RTS under Articles 28(1) and 19(9) closed on 8 May 2026. The consultation on the combined draft RTS under Articles 16(4) and 17(3) ran until 15 June 2026, while the consultation on the monitoring guidelines closed more recently, on 3 September 2026. The consultations on the business-wide risk assessment guidelines and the ITS under Article 69(3) have also closed.

The next steps are as follows. AMLA intends to submit the combined RTS on group-wide requirements to the European Commission by 30 September 2026 and the ITS on the reporting format by 30 November 2026. The final guidelines on the business-wide risk assessment and ongoing monitoring are both expected in the fourth quarter of 2026. The RTS must also be adopted by the Commission as a delegated regulation, after which the European Parliament and the Council have a period in which they may object. Publication in the Official Journal will therefore take some time.

What does this mean for your preparations?

The consultation drafts are not yet final, but they now provide enough direction to begin preparing. Map where your current policies, processes and systems differ from the proposed requirements. Pay particular attention to the information customer due diligence must produce, the identification of linked transactions, group-wide information sharing, the business-wide risk assessment and the monitoring framework. Then prioritise the changes with the greatest operational impact and document your decisions and assumptions, so you can make targeted adjustments once the final texts are published.

If you need support with these preparations, whether through a gap analysis, translating the requirements into policies and procedures, or developing an implementation plan, Projective Group can help.

We're ready to get started! Are you?