Understanding EU AMLA
AMLA is reshaping European financial crime compliance and operations. SymphonyAI helps compliance teams close the data and readiness gaps that AMLA requires.
2027 is the deadline. 2026 is the year that decides who's ready.
EU AMLA timeline and stats
AMLA formally established
AMLA becomes fully operational
AMLR directly applicable
Direct supervision begins
Institutions directly supervised
Level 2 / 3 measures due by 2029
Understanding AMLA, AMLR and the Mandates (RTS, ITS, and GL)
AMLA is the institution behind the package: the EU's new anti-money laundering supervisor, based in Frankfurt. It sets the common rulebook everyone else in this module works within, and from 2028 it takes direct control of the highest-risk cases itself.
- Coordinates a common supervisory methodology across all 27 member states, not only the institutions it supervises directly
- Directly supervises around 40 high-risk cross-border institutions from 2028, selected against a shared risk methodology
- Works alongside national regulators such as BaFin and the CSSF rather than replacing them

AMLR is the law AMLA enforces: Regulation (EU) 2024/1624, directly applicable across every member state with no national transposition and no room for local interpretation once it lands.
- Becomes directly applicable in all 27 member states on 10 July 2027
- Replaces fragmented national AML rules with one rulebook for customer due diligence, beneficial ownership, and reporting
- Extends scope to crypto-asset service providers, crowdfunding platforms, and other newly obliged entities

RTS turn AMLR's principles into binding technical detail. AMLA drafts them, but the European Commission adopts them, and once adopted, they carry the same legal force as the Regulation itself.
- Set binding detail on substantive requirements, such as customer due diligence data and risk methodologies
- Become law the moment the European Commission adopts them, with no local flexibility
- Are being finalized on a rolling basis through 2027, so gap analysis should start against the drafts, not wait for final text

ITS work the same way as RTS but govern a different layer: the formats, templates, and procedures institutions use to submit information, rather than the substance of what they must do.
- Standardize the templates and formats used to report to regulators and financial intelligence units
- Carry the same legal force as RTS once adopted, despite being more procedural in nature
- Close the door on jurisdictions interpreting submission requirements differently

Guidelines are AMLA's own supervisory expectations, issued directly rather than adopted by the European Commission. They are not binding law, but ignoring one means answering for it.
- Operate on a comply-or-explain basis rather than carrying direct legal force
- Require institutions and national regulators to justify any deviation to their national competent authority
- Move faster than RTS or ITS, often filling gaps before binding law catches up

What SymphonyAI already features
Structured CDD and beneficial ownership data
Captures place of birth, multiple nationalities, digital identity, and beneficial ownership as structured, reportable data from day one, closing the exact gaps AMLA's Article 28.1 draft standards are targeting.
One view of group-wide risk
A single, entity-centric view of risk across every legal entity in the group, so the group-level governance body Article 16.4 requires works from one picture instead of reconciling separate local assessments.
Consistent transaction logic
Define what counts as a business relationship and a linked occasional transaction once, then apply it the same way across jurisdictions and business lines, the consistency Article 19.9 is asking for.
Governed, auditable data lineage
Every decision is traceable to source and defensible to a supervisor, giving compliance teams the evidence trail cross-border information-sharing and reporting under Article 17.3 demands.
Evidence on demand
Complete due diligence records, defensible risk assessments, and auditable decisions already exist in the platform, so a gap analysis surfaces real gaps rather than missing paperwork.
Built to evolve with AMLA's rulebook
A modular, evergreen platform that absorbs new RTS, ITS, and guidelines as they land through 2029, without a disruptive rebuild every time AMLA issues fresh guidance.
Upgrade to AI the easy way
Get in touch to find out how prepared your compliance program is for AMLA, and what it takes to close the gap before 2027.
Build the technology foundations for AMLA readiness
How SymphonyAI helps financial institutions prepare for AMLA
Combining unified risk intelligence with agentic orchestration, SymphonyAI helps institutions continuously assess changing risk and adapt controls, workflows, and decisioning as regulatory requirements and risk evolve.
Capabilities spanning customer due diligence, customer risk, transaction monitoring, screening, investigations, data, governance, and reporting support institutions across key areas affected by the evolving EU AML framework.
SymphonyAI's AI overlays add detection, screening, and due diligence capability on top of the systems you already run, so you can close AMLA-driven gaps on your own timeline rather than commit to a multi-year replacement programme.
Backed by 25+ years of financial crime expertise and trusted by 200+ financial institutions worldwide, SymphonyAI brings deep domain experience to financial crime modernization.

Related resources
Discover more about EU AMLA and how to prepare
EU AMLA FAQs
Have specific questions? Our solution consultants are happy to answer them and show you exactly how SymphonyAI can help your organization prepare for AMLA.
AMLA is the Anti-Money Laundering Authority, the European Union's new financial crime supervisor. It is headquartered in Frankfurt, Germany, became operational on 1 July 2025, and took over the European Banking Authority's AML and CFT mandates on 1 January 2026.
AMLA is the institution: the supervisory authority that enforces the rules, writes technical standards, and directly supervises the highest-risk institutions from 2028.
AMLR, the Anti-Money Laundering Regulation (EU 2024/1624), is the law: a single, directly applicable rulebook that replaces fragmented national AML rules across all 27 member states from 10 July 2027.
From 2028, AMLA will directly supervise 40 high-risk institutions that operate across at least six EU member states, selected using a common risk methodology finalized in 2026. Most institutions will continue to be supervised by their national regulator, applying AMLA's harmonized standards.
Run a gap analysis against the draft regulatory technical standards, particularly for customer due diligence and beneficial ownership data; review group-wide risk assessment processes; and track AMLA's rolling programme of technical standards, most of which are due for finalization between now and 2027.
No. National regulators remain the front-line supervisor for the large majority of institutions. AMLA sets binding technical standards and a common supervisory methodology that national regulators apply, and directly supervises a small group of the highest-risk cross-border institutions from 2028.
How SymphonyAI supports AMLA readiness
SymphonyAI helps financial institutions modernize the technology foundations that support AMLA readiness. Our capabilities span customer due diligence and lifecycle risk management, screening and transaction monitoring, connected customer, transaction and entity intelligence, investigations and regulatory reporting, and transparent governance and auditability. Through AI, advanced analytics and intelligent automation – with human oversight embedded into decision-making – we help institutions apply risk-based controls more consistently, improve operational effectiveness, and adapt as regulatory requirements evolve.


