
AMLA is the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, the European Union's new financial crime supervisor. Headquartered in Frankfurt, Germany, AMLA became operational on 1 July 2025 and took over the European Banking Authority's anti-money laundering and counter-terrorist financing mandates on 1 January 2026. For compliance leaders, AMLA marks a shift away from 27 fragmented national AML regimes toward one harmonized EU-wide supervisory framework, with the highest-risk institutions facing direct AMLA supervision from 2028.
Before AMLA, anti-money laundering enforcement across the EU depended on 27 separate national systems, each interpreting the same underlying directives differently. That fragmentation left gaps at exactly the points criminals exploit, such as cross-border groups, uneven beneficial ownership standards, and supervisors with no shared view of risk.
The 2024 EU AML package, comprising AMLA itself, the AML regulation (AMLR), and the sixth AML directive, was designed to close those gaps by replacing inconsistent national interpretation with a single rulebook and a central supervisor with the authority to enforce it consistently across the EU. At the 2026 AMLA Day conference in Frankfurt, AMLA outlined three strategic priorities that shape its work:
In a subsequent joint webinar, EY's Manuel Delgado Colmenero and SymphonyAI's Charmian Simmons argued that these priorities signal a fundamental shift in Europe's AML framework. They highlighted the move towards a harmonized EU-wide regime, a greater emphasis on demonstrating compliance outcomes rather than processes, direct AMLA supervision of around 40 high-risk cross-border financial groups, a shared digital infrastructure connecting national authorities, and AMLA's ambition to become a global standard setter for financial crime supervision rather than solely a European regulator.
AMLA supervises financial institutions and designated non-financial businesses and professions including law firms, gaming, and football clubs. This occurs through two complementary models: direct supervision of the EU's highest-risk cross-border firms and indirect oversight through national competent authorities. This structure is designed to create consistent anti-money laundering supervision across all EU member states while improving cooperation between regulators.
AMLA will directly supervise around 40 high-risk financial groups operating across at least six EU member states. These institutions will be selected using a common EU risk assessment methodology, and will be announced in 2027, with direct supervision beginning in 2028.
The supervised population is expected to consist primarily of large banking groups, alongside a smaller number of payment institutions, e-money institutions, and crypto-asset service providers that fall within the EU's harmonized AML framework.
For all other regulated financial institutions, national competent authorities (NCA’s) will remain the primary supervisors. However, they will apply AMLA's common supervisory methodology rather than relying solely on national interpretations of AML requirements.
AMLA will also oversee supervisory consistency through peer reviews and, where necessary, has the authority to intervene if a national regulator fails to take appropriate supervisory action.
Beyond supervision, AMLA coordinates the EU's network of Financial Intelligence Units (FIUs), including FIU.net, the platform used to share financial intelligence across member states. As such, national FIUs will continue to receive and assess suspicious activity reports (SARs), while AMLA supports coordination, information sharing, and supervisory consistency across the EU.
In summary, AMLA's two-tier supervisory model combines direct oversight of the EU's highest-risk financial institutions with coordinated supervision through national authorities. The objective is to deliver a more consistent, technology-enabled, and harmonized approach to AML supervision across the EU.
AMLA, AMLR and Mandates (Regulatory Technical Standards (RTS), Implementing Technical Standards (ITS), and Guidelines [GL]) each play a different role in the EU's anti-money laundering framework, forming its foundation. AMLA is the supervisory authority, AMLR is the regulation that creates a single EU AML rulebook, and the RTS define how institutions must implement many of the regulation's requirements in practice.
It's easiest, then, to think of the framework in three layers:
The implementation of the European Anti-Money Laundering Authority and the wider EU AML package is taking place over several years. The timeline below highlights the key milestones that financial institutions should prepare for.
Although several AMLA milestones are still ahead, financial institutions should already be assessing the operational impact of the new EU AML framework, monitoring forthcoming technical standards, and preparing for a harmonized supervisory approach across the EU.
AMLA's own analysis, presented at the 2026 AMLA Days conference, found that around 80% of institutions currently lack the data needed to meet future AMLA reporting requirements. As such, it isn’t simply about implementing new controls, but demonstrating that existing controls are supported by complete, consistent, explainable, and auditable data.
Compliance leaders should therefore prioritize ahead of AMLR and specific mandates becoming applicable in July 2027. The regulation contains hundreds of requirements across enterprise-wide risk assessment, governance, customer due diligence, transaction monitoring, and reporting, so the four areas below are not exhaustive. However, they are likely to require the greatest operational change for many financial institutions and therefore warrant early attention.
Draft guidance under Article 28(1) of AMLR introduces additional expectations around customer identity data, including place of birth, multiple nationalities, digital identity, and beneficial ownership verification. Many institutions do not currently capture this information in a structured, reportable format.
Article 16(4) of AMLR requires stronger governance across financial groups. This includes a group-level decision-making body, consistent information sharing across CDD, transaction monitoring, and suspicious activity reporting, and clear identification of the EU parent entity.
Article 19(9) of AMLR requires institutions to apply consistent definitions of when a business relationship begins and which occasional transactions should be treated as linked. These definitions directly affect customer due diligence, transaction monitoring, alert generation, and case management.
Article 17.3 of AMLR requires financial groups with operations outside the EU to identify legal barriers to information sharing, including local privacy laws, SAR tipping-off restrictions, and cross-border data transfer requirements that could affect group-wide compliance. https://www.edpb.europa.eu/news/edpb-and-amla-to-develop-joint-guidelines-on-partnerships-for-information-sharing_en supports this by providing the legal benchmark for how data should safely cross boundaries.
Many of the supporting technical standards are still being finalized, so institutions should not wait for every RTS, ITS and guideline to be finalized before acting. The most effective first step is to conduct a gap analysis that compares existing data, governance arrangements, and technology against the draft requirements. This allows remediation work to begin early while the remaining technical standards are finalized.
AMLA represents a fundamental shift in how financial crime compliance will be supervised across the EU. With a single rulebook, harmonized supervision, and greater expectations around data, governance, and demonstrable outcomes, institutions cannot afford to wait until AMLR applies in July 2027.
The priority now is to understand where gaps exist and begin remediation early. Those that act now will be better positioned not only to meet AMLA’s requirements, but to build a more consistent, agile, and effective compliance operation for the future.
Discover the Symphony Risk Intelligence platform and begin your journey towards Always-on Compliance.
AMLA stands for the Authority for Anti-Money Laundering and Countering the Financing of Terrorism. It is the European Union's new financial crime supervisor, headquartered in Frankfurt, Germany.
No. AMLA is the supervisory institution. AMLR, the Anti-Money Laundering Regulation (EU 2024/1624), is the law AMLA enforces. AMLR becomes directly applicable across all 27 EU member states on 10 July 2027.
From 2028, AMLA will directly supervise around 40 high-risk institutions operating across at least six EU member states, selected using a common risk methodology finalized in 2026. This group is expected to be led by large banking groups, alongside a smaller number of payment institutions, e-money institutions, and crypto-asset service providers. Every other obliged entity continues to be supervised by its national regulator, which applies AMLA's harmonized standards.
The core provisions of the AML regulation become directly applicable on 10 July 2027. Most of AMLA's regulatory technical standards and guidelines are due to be finalized on a rolling basis before that date, so institutions should treat 2026 as the year to close data and process gaps rather than waiting for the deadline itself.
National regulators remain the front-line supervisor for the large majority of institutions and are not replaced by AMLA. AMLA's role is to set binding technical standards and a common supervisory methodology that national regulators apply consistently, to coordinate peer reviews between them, and to directly supervise a small group of the highest-risk cross-border institutions from 2028 onward.