EU Regulations

Understanding EU AMLA

AMLA is reshaping European financial crime compliance and operations. SymphonyAI helps compliance teams close the data and readiness gaps that AMLA requires.

The AMLA Package becomes fully applicable on 10 July 2027, comprising the Regulation, the Directive, and a number of the mandates issued under them. 2026 is the year those mandates take shape with AMLA running a rolling programme of consultative public hearings on the regulatory technical standards, implementing technical standards, and guidelines that will translate the Regulation's principles into day-to-day compliance requirements. Institutions that wait for the last piece of guidance before acting will have the least time to close the gaps AMLA has already flagged, including the data gaps its own analysis found in roughly 80% of institutions.
White clock icon with an arrow circling clockwise, representing time update or history.
AMLA is a moving target
Roughly 50 pieces of level 2 and level 3 legislation are still being finalized through 2029
White circle divided into three sections by a vertical line and a horizontal line on the right side, forming a geometric symbol.
Fragmented supervision
27 national regimes are converging into one rulebook, with no room for local interpretation after July 2027
White bell icon with an exclamation mark inside, symbolizing an important notification or alert.
Data gaps must be rectified
AMLA's own analysis found that around 80 percent of institutions lack the data needed to report correctly
Icon with three horizontal white lines on the left and a large white magnifying glass on the right, symbolizing search filter or search options.
Direct scrutiny ahead
40 high-risk institutions face direct AMLA supervision from 2028
2024

AMLA formally established

July 2025

AMLA becomes fully operational

July 2027

AMLR directly applicable

2028

Direct supervision begins

40

Institutions directly supervised

50

Level 2 / 3 measures due by 2029

AMLA
AMLR
RTS
ITS
GL

AMLA is the institution behind the package: the EU's new anti-money laundering supervisor, based in Frankfurt. It sets the common rulebook everyone else in this module works within, and from 2028 it takes direct control of the highest-risk cases itself.

  • Coordinates a common supervisory methodology across all 27 member states, not only the institutions it supervises directly
  • Directly supervises around 40 high-risk cross-border institutions from 2028, selected against a shared risk methodology
  • Works alongside national regulators such as BaFin and the CSSF rather than replacing them
Three men in business attire seated at a desk in a modern office, each working with multiple large monitors displaying financial data, stock charts, and analytics dashboards, with other employees and workstations visible in the background.

AMLR is the law AMLA enforces: Regulation (EU) 2024/1624, directly applicable across every member state with no national transposition and no room for local interpretation once it lands.

  • Becomes directly applicable in all 27 member states on 10 July 2027
  • Replaces fragmented national AML rules with one rulebook for customer due diligence, beneficial ownership, and reporting
  • Extends scope to crypto-asset service providers, crowdfunding platforms, and other newly obliged entities
Four professionals in a control room monitoring multiple large screens displaying various data visualizations, charts, graphs, and analytics dashboards in a dark, high-tech environment.

RTS turn AMLR's principles into binding technical detail. AMLA drafts them, but the European Commission adopts them, and once adopted, they carry the same legal force as the Regulation itself.

  • Set binding detail on substantive requirements, such as customer due diligence data and risk methodologies
  • Become law the moment the European Commission adopts them, with no local flexibility
  • Are being finalized on a rolling basis through 2027, so gap analysis should start against the drafts, not wait for final text
A woman wearing glasses and a navy blazer smiles while working on a computer in an office, with multiple monitors displaying a high-risk alert dashboard and colleagues working in the background.

ITS work the same way as RTS but govern a different layer: the formats, templates, and procedures institutions use to submit information, rather than the substance of what they must do.

  • Standardize the templates and formats used to report to regulators and financial intelligence units
  • Carry the same legal force as RTS once adopted, despite being more procedural in nature
  • Close the door on jurisdictions interpreting submission requirements differently
Man viewed from behind sitting at a desk with multiple computer monitors displaying data analytics, charts, and dashboards in a modern office environment.

Guidelines are AMLA's own supervisory expectations, issued directly rather than adopted by the European Commission. They are not binding law, but ignoring one means answering for it.

  • Operate on a comply-or-explain basis rather than carrying direct legal force
  • Require institutions and national regulators to justify any deviation to their national competent authority
  • Move faster than RTS or ITS, often filling gaps before binding law catches up
Professional business meeting in a modern conference room with five people in suits seated around a wooden table while a man stands pointing at a wall-mounted screen displaying a world map and infographic.
Blue icon depicting a hierarchical tree structure with one top square connected by lines to three lower squares arranged in a T shape.

Structured CDD and beneficial ownership data

Captures place of birth, multiple nationalities, digital identity, and beneficial ownership as structured, reportable data from day one, closing the exact gaps AMLA's Article 28.1 draft standards are targeting.

Simple turquoise eye icon with a circular pupil in the center, symbolizing visibility or view.

One view of group-wide risk

A single, entity-centric view of risk across every legal entity in the group, so the group-level governance body Article 16.4 requires works from one picture instead of reconciling separate local assessments.

Yellow light bulb icon with a circular arrow pointing clockwise around it, symbolizing idea refresh or innovation.

Consistent transaction logic

Define what counts as a business relationship and a linked occasional transaction once, then apply it the same way across jurisdictions and business lines, the consistency Article 19.9 is asking for.

Purple icon of a bar chart with bars of three different heights inside a square frame with rounded corners.

Governed, auditable data lineage

Every decision is traceable to source and defensible to a supervisor, giving compliance teams the evidence trail cross-border information-sharing and reporting under Article 17.3 demands.

Blue shield outline with a checkmark inside symbolizing verified protection or security.

Evidence on demand

Complete due diligence records, defensible risk assessments, and auditable decisions already exist in the platform, so a gap analysis surfaces real gaps rather than missing paperwork.

Checklist icon with three horizontal lines on the left and a large checkmark on the right inside a rounded rectangle.

Built to evolve with AMLA's rulebook

A modular, evergreen platform that absorbs new RTS, ITS, and guidelines as they land through 2029, without a disruptive rebuild every time AMLA issues fresh guidance.

The AMLA and EU publications shaping how institutions must prepare

AMLA's own 3-year roadmap

AMLA's first multi-year work programme, published February 2026, setting out its priorities, rulemaking calendar, and supervisory approach through 2028.

5
strategic goals
Nighttime cityscape with a tall illuminated central tower surrounded by high-rise buildings lit with office and red aviation lights, a highway with bright streetlights and light trails from vehicles stretches in the foreground.
Nighttime cityscape with a tall illuminated central tower surrounded by high-rise buildings lit with office and red aviation lights, a highway with bright streetlights and light trails from vehicles stretches in the foreground.

AMLA's first multi-year work programme, published February 2026, setting out its priorities, rulemaking calendar, and supervisory approach through 2028.

5
strategic goals
The CDD standard driving the data gap

AMLA's most contested draft standard, setting new requirements for identity data, including place of birth, multiple nationalities, and beneficial ownership verification.

80%
institutions currently lacking the required data
Low-angle view of two modern glass skyscrapers reflecting the clear blue sky with sunlight in the upper right corner.
Low-angle view of two modern glass skyscrapers reflecting the clear blue sky with sunlight in the upper right corner.

AMLA's most contested draft standard, setting new requirements for identity data, including place of birth, multiple nationalities, and beneficial ownership verification.

80%
institutions currently lacking the required data
The rulebook for group-wide governance

Sets out the governance body, information-sharing, and third-country impediment requirements that cross-border groups must build into their operating model.

27
member states in scope
Cityscape of London featuring iconic skyscrapers including the Gherkin, the Leadenhall Building, and other modern high-rises under a partly cloudy blue sky during golden hour.
Cityscape of London featuring iconic skyscrapers including the Gherkin, the Leadenhall Building, and other modern high-rises under a partly cloudy blue sky during golden hour.

Sets out the governance body, information-sharing, and third-country impediment requirements that cross-border groups must build into their operating model.

27
member states in scope

Get in touch to find out how prepared your compliance program is for AMLA, and what it takes to close the gap before 2027.

How SymphonyAI helps you get AMLA-ready.

White checkmark inside a spiked circular badge shape, symbolizing verification or approval.
Always-on Compliance™

Combining unified risk intelligence with end-to-end agentic orchestration, our platforms keep compliance programmes current as AMLA's technical standards, guidelines, and supervisory expectations evolve.

White puzzle piece icon with one protruding tab on the right and three inward curves.
Built to cover every AMLR domain

AMLR touches customer due diligence, group governance, transaction definitions, and cross-border data sharing all at once. Build coverage domain by domain, getting you to compliance in a structured manner.

White icon of a rocket ship launching, with flame coming from the bottom.
Works with what you already run

SymphonyAI's AI overlays add detection, screening, and due diligence capability on top of the systems you already run, so you can close AMLA-driven gaps on your own timeline rather than commit to a multi-year replacement programme.

White circular arrow icon rotating clockwise inside a white ring.
Built for FinCrime. Proven at scale.

Our solutions are built on 25 years of proven expertise on a global scale. That’s why we’re trusted by 33% of the world’s largest financial institutions.

Have specific questions? Our solution consultants are happy to answer them and show you exactly how SymphonyAI can help your organization prepare for AMLA.

What is AMLA?

AMLA is the Anti-Money Laundering Authority, the European Union's new financial crime supervisor. It is headquartered in Frankfurt, Germany, became operational on 1 July 2025, and took over the European Banking Authority's AML and CFT mandates on 1 January 2026.

What is the difference between AMLA and AMLR?

AMLA is the institution: the supervisory authority that enforces the rules, writes technical standards, and directly supervises the highest-risk institutions from 2028.

‍

AMLR, the Anti-Money Laundering Regulation (EU 2024/1624), is the law: a single, directly applicable rulebook that replaces fragmented national AML rules across all 27 member states from 10 July 2027.

Which institutions will AMLA supervise directly?

From 2028, AMLA will directly supervise 40 high-risk institutions that operate across at least six EU member states, selected using a common risk methodology finalized in 2026. Most institutions will continue to be supervised by their national regulator, applying AMLA's harmonized standards.

What should institutions do now to prepare for AMLA?

Run a gap analysis against the draft regulatory technical standards, particularly for customer due diligence and beneficial ownership data; review group-wide risk assessment processes; and track AMLA's rolling programme of technical standards, most of which are due for finalization between now and 2027.

Does AMLA replace national regulators such as BaFin or the CSSF?

No. National regulators remain the front-line supervisor for the large majority of institutions. AMLA sets binding technical standards and a common supervisory methodology that national regulators apply, and directly supervises a small group of the highest-risk cross-border institutions from 2028.