Blog
8.20.2026

Quick Summary

AMLA is the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, the European Union's new financial crime supervisor. Headquartered in Frankfurt, Germany, AMLA became operational on 1 July 2025 and took over the European Banking Authority's anti-money laundering and counter-terrorist financing mandates on 1 January 2026. For compliance leaders, AMLA marks a shift away from 27 fragmented national AML regimes toward one harmonized EU-wide supervisory framework, with the highest-risk institutions facing direct AMLA supervision from 2028.

Key facts
Full name: Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA)
Established: June 2024, under Regulation (EU) 2024/1620
Headquarters: Frankfurt, Germany
Operational since: 1 July 2025
Assumed the EU Banking Authority's AML and CFT mandates: 1 January 2026
Core regulation (AMLR): Regulation (EU) 2024/1624, directly applicable from 10 July 2027
Direct supervision begins: 2028, for around 40 high-risk cross-border institutions
Rulemaking program: Roughly 50 pieces of level 2 and level 3 technical standards and guidelines due on a rolling basis through 2029

Why was AMLA created?

Before AMLA, anti-money laundering enforcement across the EU depended on 27 separate national systems, each interpreting the same underlying directives differently. That fragmentation left gaps at exactly the points criminals exploit, such as cross-border groups, uneven beneficial ownership standards, and supervisors with no shared view of risk.

The 2024 EU AML package, comprising AMLA itself, the AML regulation (AMLR), and the sixth AML directive, was designed to close those gaps by replacing inconsistent national interpretation with a single rulebook and a central supervisor with the authority to enforce it consistently across the EU. At the 2026 AMLA Day conference in Frankfurt, AMLA outlined three strategic priorities that shape its work:

  • Developing a deeper understanding of financial crime risk through advanced technology and a new central data infrastructure.
  • Strengthening supervision through a harmonized rulebook and broader supervisory coverage.
  • Enabling faster and more effective financial intelligence sharing between national authorities.

In a subsequent joint webinar, EY's Manuel Delgado Colmenero and SymphonyAI's Charmian Simmons argued that these priorities signal a fundamental shift in Europe's AML framework. They highlighted the move towards a harmonized EU-wide regime, a greater emphasis on demonstrating compliance outcomes rather than processes, direct AMLA supervision of around 40 high-risk cross-border financial groups, a shared digital infrastructure connecting national authorities, and AMLA's ambition to become a global standard setter for financial crime supervision rather than solely a European regulator.

How AMLA's supervision works

AMLA supervises financial institutions and designated non-financial businesses and professions including law firms, gaming, and football clubs. This occurs through two complementary models: direct supervision of the EU's highest-risk cross-border firms and indirect oversight through national competent authorities. This structure is designed to create consistent anti-money laundering supervision across all EU member states while improving cooperation between regulators.

AMLA direct supervision

AMLA will directly supervise around 40 high-risk financial groups operating across at least six EU member states. These institutions will be selected using a common EU risk assessment methodology, and will be announced in 2027, with direct supervision beginning in 2028.

The supervised population is expected to consist primarily of large banking groups, alongside a smaller number of payment institutions, e-money institutions, and crypto-asset service providers that fall within the EU's harmonized AML framework.

AMLA indirect supervision

For all other regulated financial institutions, national competent authorities (NCA’s) will remain the primary supervisors. However, they will apply AMLA's common supervisory methodology rather than relying solely on national interpretations of AML requirements.

AMLA will also oversee supervisory consistency through peer reviews and, where necessary, has the authority to intervene if a national regulator fails to take appropriate supervisory action.

AMLA's role in financial intelligence sharing

Beyond supervision, AMLA coordinates the EU's network of Financial Intelligence Units (FIUs), including FIU.net, the platform used to share financial intelligence across member states. As such, national FIUs will continue to receive and assess suspicious activity reports (SARs), while AMLA supports coordination, information sharing, and supervisory consistency across the EU.

In summary, AMLA's two-tier supervisory model combines direct oversight of the EU's highest-risk financial institutions with coordinated supervision through national authorities. The objective is to deliver a more consistent, technology-enabled, and harmonized approach to AML supervision across the EU.

What is the difference between AMLA, AMLR, and Mandates (RTS, ITS, and GL)?

AMLA, AMLR and Mandates (Regulatory Technical Standards (RTS), Implementing Technical Standards (ITS), and Guidelines [GL]) each play a different role in the EU's anti-money laundering framework, forming its foundation. AMLA is the supervisory authority, AMLR is the regulation that creates a single EU AML rulebook, and the RTS define how institutions must implement many of the regulation's requirements in practice.

Term What it is What it means for financial institutions
AMLA The EU Anti-Money Laundering Authority, based in Frankfurt AMLA sets binding standards, coordinates national regulators, and will directly supervise around 40 high-risk institutions from 2028
AMLR Regulation (EU) 2024/1624, the EU’s directly applicable Anti-Money Laundering Regulation in all 27 member states from 10 July 2027 AMLR replaces many national AML rules with a single harmonized rulebook covering CDD, beneficial ownership, internal controls, and reporting obligations across all EU member states.
RTS Regulatory Technical Standards are level 2 measures drafted by AMLA and adopted by the European Commission. RTS provide the legally binding detailed technical requirements for implementing AMLR, including identity verification, customer due diligence processes, data standards, reporting formats, and other operational requirements. These standards will be introduced on a phased basis through 2027.
ITS Implementing Technical Standards are level 2 measures drafted by AMLA and adopted by the European Commission. ITS provide the legally binding standards focused on uniform formats, technical specifications, reporting templates, and concrete processes like standard data submission or STR formats. Following its draft consultation window, AMLA submitted the finalised text to the European Commission in July 2026.
GL Guidelines are level 3 measures issued directly by AMLA, not adopted by the Commission. Not directly legally binding, but national regulators and institutions must comply or explain any deviation to their national authority.

It's easiest, then, to think of the framework in three layers:

  • AMLR defines what financial institutions must do
  • AMLA oversees how those rules are supervised and enforced
  • The Mandates (RTS, ITS, and GL) explain how many of those requirements must be implemented, how they are to be implemented, and a suggestion of good practice when following the measures.

AMLA timeline: Key dates from 2024 to 2029

The implementation of the European Anti-Money Laundering Authority and the wider EU AML package is taking place over several years. The timeline below highlights the key milestones that financial institutions should prepare for.

Date AMLA Milestone Why it matters
2024 AMLA is formally established. The new EU AML framework is created.
July 2025 AMLA becomes operational in Frankfurt. The authority begins building its supervisory and regulatory functions.
January 2026 AMLA assumes the European Banking Authority's AML/CFT responsibilities. Responsibility for EU AML coordination transfers to AMLA.
2026–2029

By mid-2029, over 50 pieces of secondary and tertiary legislation – encompassing Guidelines, Regulatory Technical Standards (RTS), and Implementing Technical Standards (ITS) – are expected to be delivered under the new EU AML regulatory package.

AMLA publishes around 50 Level 2 and Level 3 measures, including RTS, Implementing Technical Standards (ITS), guidelines, and other technical guidance.

These measures define how AMLR & AMLD requirements will operate in practice and will continue to shape compliance obligations over several years.
10 July 2027 The AMLR, AMLD and several mandates becomes directly applicable across all EU member states. A single AML rulebook replaces many national requirements.
2028 AMLA begins direct supervision of roughly 40 high-risk cross-border financial groups. The new supervisory model becomes operational.
2029 AMLA's initial rulemaking programme is expected to conclude. By this stage, most of the technical standards, guidance, and supervisory framework underpinning the EU AML regime should be in place.

What financial institutions should do now

Although several AMLA milestones are still ahead, financial institutions should already be assessing the operational impact of the new EU AML framework, monitoring forthcoming technical standards, and preparing for a harmonized supervisory approach across the EU.

AMLA's own analysis, presented at the 2026 AMLA Days conference, found that around 80% of institutions currently lack the data needed to meet future AMLA reporting requirements. As such, it isn’t simply about implementing new controls, but demonstrating that existing controls are supported by complete, consistent, explainable, and auditable data.

Compliance leaders should therefore prioritize ahead of AMLR and specific mandates becoming applicable in July 2027. The regulation contains hundreds of requirements across enterprise-wide risk assessment, governance, customer due diligence, transaction monitoring, and reporting, so the four areas below are not exhaustive. However, they are likely to require the greatest operational change for many financial institutions and therefore warrant early attention.

1. Improve CDD data quality

Draft guidance under Article 28(1) of AMLR introduces additional expectations around customer identity data, including place of birth, multiple nationalities, digital identity, and beneficial ownership verification. Many institutions do not currently capture this information in a structured, reportable format.

2. Strengthen group-wide AML governance

Article 16(4) of AMLR requires stronger governance across financial groups. This includes a group-level decision-making body, consistent information sharing across CDD, transaction monitoring, and suspicious activity reporting, and clear identification of the EU parent entity.

3. Review business relationship and transaction definitions

Article 19(9) of AMLR requires institutions to apply consistent definitions of when a business relationship begins and which occasional transactions should be treated as linked. These definitions directly affect customer due diligence, transaction monitoring, alert generation, and case management.

4. Assess cross-border information-sharing risks

Article 17.3 of AMLR requires financial groups with operations outside the EU to identify legal barriers to information sharing, including local privacy laws, SAR tipping-off restrictions, and cross-border data transfer requirements that could affect group-wide compliance. https://www.edpb.europa.eu/news/edpb-and-amla-to-develop-joint-guidelines-on-partnerships-for-information-sharing_en supports this by providing the legal benchmark for how data should safely cross boundaries.

Start with a gap analysis

Many of the supporting technical standards are still being finalized, so institutions should not wait for every RTS, ITS and guideline to be finalized before acting. The most effective first step is to conduct a gap analysis that compares existing data, governance arrangements, and technology against the draft requirements. This allows remediation work to begin early while the remaining technical standards are finalized.

Conclusion

AMLA represents a fundamental shift in how financial crime compliance will be supervised across the EU. With a single rulebook, harmonized supervision, and greater expectations around data, governance, and demonstrable outcomes, institutions cannot afford to wait until AMLR applies in July 2027.  

The priority now is to understand where gaps exist and begin remediation early. Those that act now will be better positioned not only to meet AMLA’s requirements, but to build a more consistent, agile, and effective compliance operation for the future.

Related resources

Sources and further reading

Learn more about Symphony Risk Intelligence

Discover the Symphony Risk Intelligence platform and begin your journey towards Always-on Compliance.

EU AMLA FAQs
What does AMLA stand for?

AMLA stands for the Authority for Anti-Money Laundering and Countering the Financing of Terrorism. It is the European Union's new financial crime supervisor, headquartered in Frankfurt, Germany.

Is AMLA the same as AMLR?

No. AMLA is the supervisory institution. AMLR, the Anti-Money Laundering Regulation (EU 2024/1624), is the law AMLA enforces. AMLR becomes directly applicable across all 27 EU member states on 10 July 2027.

Which companies will AMLA regulate directly?

From 2028, AMLA will directly supervise around 40 high-risk institutions operating across at least six EU member states, selected using a common risk methodology finalized in 2026. This group is expected to be led by large banking groups, alongside a smaller number of payment institutions, e-money institutions, and crypto-asset service providers. Every other obliged entity continues to be supervised by its national regulator, which applies AMLA's harmonized standards.

What is the deadline for AMLA compliance?

The core provisions of the AML regulation become directly applicable on 10 July 2027. Most of AMLA's regulatory technical standards and guidelines are due to be finalized on a rolling basis before that date, so institutions should treat 2026 as the year to close data and process gaps rather than waiting for the deadline itself.

How is AMLA different from national regulators such as BaFin or the FCA?

National regulators remain the front-line supervisor for the large majority of institutions and are not replaced by AMLA. AMLA's role is to set binding technical standards and a common supervisory methodology that national regulators apply consistently, to coordinate peer reviews between them, and to directly supervise a small group of the highest-risk cross-border institutions from 2028 onward.

about the author
Henry Fosdike
Content Manager

Henry Fosdike is Content Manager at SymphonyAI’s financial services division, bringing 10+ years of expertise in crafting compelling B2B, B2C, and D2C content to the world of AI-driven financial crime prevention technology. With a rich background, Henry excels at translating complex AI, finance, and SaaS concepts into clear, engaging narratives. His insightful articles and whitepapers demystify cutting-edge anti-financial crime solutions, providing readers with valuable knowledge and offering readers a deeper understanding of this rapidly evolving field.

Learn more about the author >