When fraud becomes money laundering: Why AMLR matters beyond compliance
Europe's payments landscape is changing rapidly. Instant payments are becoming the norm, digital channels continue to grow, and fraudsters are becoming increasingly sophisticated in the way they exploit both. As financial institutions invest in stronger customer authentication and fraud prevention capabilities, criminals are adapting just as quickly. Once funds have been stolen, they can be moved across accounts, jurisdictions, and even asset classes within minutes, making recovery increasingly difficult. This raises an important question: how can regulators tackle financial crime when money moves faster than ever before?
How can regulators tackle financial crime when money moves faster than ever before?
From July 2027, the EU's new Anti-Money Laundering Regulation (AMLR) will form a central part of the answer. By introducing a single anti-money laundering framework across the European Union, the regulation aims to reduce regulatory fragmentation, strengthen transparency, and make it significantly harder for criminals to move and conceal illicit funds.
While AML regulation has traditionally been viewed through the lens of compliance, the AMLR also represents an important development in the fight against payment fraud. Increasingly, regulators recognize that fraud and money laundering are not separate risks. They are different stages of the same criminal process.
For many years, anti-money laundering requirements have been shaped by national implementation of successive EU directives. Although the core principles remained broadly consistent, differences between Member States created operational complexity for firms and opportunities for criminals to exploit inconsistencies across jurisdictions.
The AMLR seeks to address this challenge through a directly applicable rulebook that will establish a common set of requirements across the European Single Market. The regulation introduces greater consistency in areas including:
For financial institutions operating across multiple jurisdictions, this should reduce complexity and create greater certainty. For criminal networks, it should reduce opportunities to exploit gaps between national frameworks.
The importance of the AMLR extends beyond traditional money laundering risks. Payment fraud continues to grow across Europe, particularly as instant payments gain wider adoption. Fraud schemes such as authorised push payment (APP) fraud, account takeover attacks, identity theft, and fraudulent credit transfers generate significant criminal proceeds that must ultimately be moved, layered, and concealed.
Payment fraud continues to grow across Europe, particularly as instant payments gain wider adoption.
The challenge is especially acute in an instant payment environment. For example, a student recruited through social media may unknowingly allow their account to be used as a mule account in exchange for a small payment. Criminals can transfer stolen funds through dozens of such accounts, making it significantly harder for investigators to trace the ultimate beneficiaries. Once a fraudulent transaction has been executed, funds can be distributed through multiple accounts within seconds.
Money mule networks are frequently used to disguise the movement of funds before they can be frozen or recovered. As a result, preventing fraud is only part of the solution. Institutions must also be capable of detecting and disrupting the movement of criminal proceeds after the initial fraud has taken place. This is where the AMLR becomes particularly relevant. The regulation strengthens the controls that support the identification, tracing, and investigation of suspicious financial activity, helping firms target the infrastructure that enables payment fraud to remain profitable.
Preventing fraud is only part of the solution. Institutions must also be capable of detecting and disrupting the movement of criminal proceeds after the initial fraud has taken place.
The AMLR also targets several areas that have historically been used to facilitate the movement and concealment of illicit funds. One significant development is the full integration of Crypto-Asset Service Providers (CASPs) into the EU anti-money laundering framework. As crypto-assets become increasingly interconnected with the traditional financial system, applying comparable AML requirements across both sectors should reduce opportunities for criminals to convert stolen funds into alternative asset classes with limited oversight.
The regulation also introduces a €10,000 limit on cash payments across the EU, while allowing member states to further reduce this cash limit. While cash will continue to play a legitimate role in the economy, the measure is intended to make it more difficult for organised criminal groups to convert large volumes of illicit proceeds into anonymous cash transactions.
The focus is no longer solely on identifying suspicious transactions.
Taken together, these reforms demonstrate a broader shift in regulatory thinking. The focus is no longer solely on identifying suspicious transactions. Increasingly, regulators are seeking to disrupt the wider criminal ecosystem that supports fraud and money laundering.
Many organisations will need to revisit onboarding and customer due diligence processes that have evolved around local regulatory requirements. The move towards harmonisation creates an opportunity to standardise customer risk frameworks across jurisdictions and improve consistency in decision-making.
Beneficial ownership controls are also likely to become an area of increased focus. Institutions will need confidence not only in the quality of ownership data collected during onboarding, but also in their ability to maintain accurate information throughout the customer lifecycle.
At the same time, the continued growth of instant payments means traditional approaches to transaction monitoring may become increasingly ineffective. Retrospective reviews provide limited value when funds can move through multiple accounts in seconds. Firms will therefore need to invest in more sophisticated monitoring capabilities that combine behavioural analytics, customer risk information, and real-time detection techniques. For instance, if a customer who normally makes low-value domestic payments suddenly initiates a large cross-border instant transfer immediately after changing their contact details or device profile, integrated fraud and AML monitoring could identify the activity as requiring immediate investigation.
Leading institutions are already moving towards more integrated financial crime frameworks that combine fraud intelligence, AML monitoring, and customer risk assessments into a single operational view.
Perhaps the most significant challenge, however, lies within organisational structures. Historically, fraud and AML teams have often operated independently, supported by different technologies, processes, and reporting lines. Yet the threats they address are becoming increasingly interconnected. Leading institutions are already moving towards more integrated financial crime frameworks that combine fraud intelligence, AML monitoring, and customer risk assessments into a single operational view. As regulatory expectations evolve, this convergence is likely to accelerate.
The Anti-Money Laundering Regulation represents more than a harmonised rulebook. It reflects a broader shift in how financial crime is understood and managed.
As payments become increasingly real-time, the connection between fraud, money laundering and customer risk is becoming impossible to ignore. Financial institutions can no longer afford to view these risks in isolation.
AMLR provides an opportunity to take a more connected approach. Organisations that bring together fraud prevention, anti-money laundering and customer risk management will be better placed to detect threats, protect customers and respond to an increasingly complex payments landscape.
At Projective Group, we see this shift reflected across the industry. AMLR may act as a catalyst, but the real value lies in bringing together people, data and technology to create more integrated financial crime frameworks that strengthen resilience and improve customer protection.
Established in 2006, Projective Group is a leading financial services consultancy.
We are recognised across the European industry for turning complex challenges and emerging themes into clear, pragmatic solutions. With deep roots and trusted relationships in financial services, we bring hands-on expertise across key domains. We support the full journey of change: shaping strategy, delivering complex transformation or building long‑term capability through managed services, staffing and training. Our purpose is simple: to empower financial services to drive future wellbeing, prosperity and innovation.