EU Regulations

AMLA is reshaping European financial crime compliance and operations. SymphonyAI helps compliance teams close the data and readiness gaps that AMLA requires.

The AMLA Package becomes fully applicable on 10 July 2027, comprising the Regulation, the Directive, and a number of the mandates issued under them. 2026 is the year those mandates take shape with AMLA running a rolling programme of consultative public hearings on the regulatory technical standards, implementing technical standards, and guidelines that will translate the Regulation's principles into day-to-day compliance requirements. Institutions that wait for the last piece of guidance before acting will have the least time to close the gaps AMLA has already flagged, including the data gaps its own analysis found in roughly 80% of institutions.
AMLA is a moving target
Roughly 50 pieces of level 2 and level 3 legislation are still being finalized through 2029
Fragmented supervision
27 national regimes are converging into one rulebook, with no room for local interpretation after July 2027
Data gaps must be rectified
AMLA's own analysis found that around 80 percent of institutions lack the data needed to report correctly
Direct scrutiny ahead
40 high-risk institutions face direct AMLA supervision from 2028
2024

AMLA formally established

July 2025

AMLA becomes fully operational

July 2027

AMLR directly applicable

2028

Direct supervision begins

40

Institutions directly supervised

50

Level 2 / 3 measures due by 2029

AMLA
AMLR
RTS
ITS
GL

AMLA is the institution behind the package: the EU's new anti-money laundering supervisor, based in Frankfurt. It sets the common rulebook everyone else in this module works within, and from 2028 it takes direct control of the highest-risk cases itself.

  • Coordinates a common supervisory methodology across all 27 member states, not only the institutions it supervises directly
  • Directly supervises around 40 high-risk cross-border institutions from 2028, selected against a shared risk methodology
  • Works alongside national regulators such as BaFin and the CSSF rather than replacing them

AMLR is the law AMLA enforces: Regulation (EU) 2024/1624, directly applicable across every member state with no national transposition and no room for local interpretation once it lands.

  • Becomes directly applicable in all 27 member states on 10 July 2027
  • Replaces fragmented national AML rules with one rulebook for customer due diligence, beneficial ownership, and reporting
  • Extends scope to crypto-asset service providers, crowdfunding platforms, and other newly obliged entities

RTS turn AMLR's principles into binding technical detail. AMLA drafts them, but the European Commission adopts them, and once adopted, they carry the same legal force as the Regulation itself.

  • Set binding detail on substantive requirements, such as customer due diligence data and risk methodologies
  • Become law the moment the European Commission adopts them, with no local flexibility
  • Are being finalized on a rolling basis through 2027, so gap analysis should start against the drafts, not wait for final text

ITS work the same way as RTS but govern a different layer: the formats, templates, and procedures institutions use to submit information, rather than the substance of what they must do.

  • Standardize the templates and formats used to report to regulators and financial intelligence units
  • Carry the same legal force as RTS once adopted, despite being more procedural in nature
  • Close the door on jurisdictions interpreting submission requirements differently

Guidelines are AMLA's own supervisory expectations, issued directly rather than adopted by the European Commission. They are not binding law, but ignoring one means answering for it.

  • Operate on a comply-or-explain basis rather than carrying direct legal force
  • Require institutions and national regulators to justify any deviation to their national competent authority
  • Move faster than RTS or ITS, often filling gaps before binding law catches up

Structured CDD and beneficial ownership data

Captures place of birth, multiple nationalities, digital identity, and beneficial ownership as structured, reportable data from day one, closing the exact gaps AMLA's Article 28.1 draft standards are targeting.

One view of group-wide risk

A single, entity-centric view of risk across every legal entity in the group, so the group-level governance body Article 16.4 requires works from one picture instead of reconciling separate local assessments.

Consistent transaction logic

Define what counts as a business relationship and a linked occasional transaction once, then apply it the same way across jurisdictions and business lines, the consistency Article 19.9 is asking for.

Governed, auditable data lineage

Every decision is traceable to source and defensible to a supervisor, giving compliance teams the evidence trail cross-border information-sharing and reporting under Article 17.3 demands.

Evidence on demand

Complete due diligence records, defensible risk assessments, and auditable decisions already exist in the platform, so a gap analysis surfaces real gaps rather than missing paperwork.

Built to evolve with AMLA's rulebook

A modular, evergreen platform that absorbs new RTS, ITS, and guidelines as they land through 2029, without a disruptive rebuild every time AMLA issues fresh guidance.

The AMLA and EU publications shaping how institutions must prepare

AMLA's own 3-year roadmap

AMLA's first multi-year work programme, published February 2026, setting out its priorities, rulemaking calendar, and supervisory approach through 2028.

5
strategic goals

AMLA's first multi-year work programme, published February 2026, setting out its priorities, rulemaking calendar, and supervisory approach through 2028.

5
strategic goals
The CDD standard driving the data gap

AMLA's most contested draft standard, setting new requirements for identity data, including place of birth, multiple nationalities, and beneficial ownership verification.

80%
institutions currently lacking the required data

AMLA's most contested draft standard, setting new requirements for identity data, including place of birth, multiple nationalities, and beneficial ownership verification.

80%
institutions currently lacking the required data
The rulebook for group-wide governance

Sets out the governance body, information-sharing, and third-country impediment requirements that cross-border groups must build into their operating model.

27
member states in scope

Sets out the governance body, information-sharing, and third-country impediment requirements that cross-border groups must build into their operating model.

27
member states in scope

Get in touch to find out how prepared your compliance program is for AMLA, and what it takes to close the gap before 2027.

How SymphonyAI helps you get AMLA-ready.

Always-on Compliance™

Combining unified risk intelligence with end-to-end agentic orchestration, our platforms keep compliance programmes current as AMLA's technical standards, guidelines, and supervisory expectations evolve.

Built to cover every AMLR domain

AMLR touches customer due diligence, group governance, transaction definitions, and cross-border data sharing all at once. Build coverage domain by domain, getting you to compliance in a structured manner.

Works with what you already run

SymphonyAI's AI overlays add detection, screening, and due diligence capability on top of the systems you already run, so you can close AMLA-driven gaps on your own timeline rather than commit to a multi-year replacement programme.

Built for FinCrime. Proven at scale.

Our solutions are built on 25 years of proven expertise on a global scale. That’s why we’re trusted by 33% of the world’s largest financial institutions.

Have specific questions? Our solution consultants are happy to answer them and show you exactly how SymphonyAI can help your organization prepare for AMLA.

What is AMLA?

AMLA is the Anti-Money Laundering Authority, the European Union's new financial crime supervisor. It is headquartered in Frankfurt, Germany, became operational on 1 July 2025, and took over the European Banking Authority's AML and CFT mandates on 1 January 2026.

What is the difference between AMLA and AMLR?

AMLA is the institution: the supervisory authority that enforces the rules, writes technical standards, and directly supervises the highest-risk institutions from 2028.

AMLR, the Anti-Money Laundering Regulation (EU 2024/1624), is the law: a single, directly applicable rulebook that replaces fragmented national AML rules across all 27 member states from 10 July 2027.

Which institutions will AMLA supervise directly?

From 2028, AMLA will directly supervise 40 high-risk institutions that operate across at least six EU member states, selected using a common risk methodology finalized in 2026. Most institutions will continue to be supervised by their national regulator, applying AMLA's harmonized standards.

What should institutions do now to prepare for AMLA?

Run a gap analysis against the draft regulatory technical standards, particularly for customer due diligence and beneficial ownership data; review group-wide risk assessment processes; and track AMLA's rolling programme of technical standards, most of which are due for finalization between now and 2027.

Does AMLA replace national regulators such as BaFin or the CSSF?

No. National regulators remain the front-line supervisor for the large majority of institutions. AMLA sets binding technical standards and a common supervisory methodology that national regulators apply, and directly supervises a small group of the highest-risk cross-border institutions from 2028.