How Crypto and Payment Firms Should Prepare for the EU AML Regulation

Legasset Legal Blog Legal Guides How Crypto and Payment Firms Should Prepare for the EU AML Regulation

EU AML Regulation 2027: Compliance Guide for CASPs, EMIs and Payment Institutions

The European Union’s new anti-money laundering framework enters its main implementation phase on 10 July 2027.

Regulation (EU) 2024/1624, commonly referred to as the EU Anti-Money Laundering Regulation or AMLR, will impose directly applicable requirements on obliged entities across Member States. The affected businesses include crypto-asset service providers, electronic money institutions, payment institutions, banks and other regulated financial firms.

The AMLR does not merely restate the existing AML directives. It creates a more harmonised rulebook covering business-wide risk assessments, internal controls, customer due diligence, beneficial ownership, ongoing monitoring, group-wide compliance and high-risk relationships.

At the same time, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism is preparing technical standards and guidelines that will determine how many of these obligations work in practice. Several important instruments remained under consultation or post-consultation development as of 4 August 2026.

CASPs, EMIs and payment institutions should therefore begin implementation now. Waiting for every technical standard to become final would leave insufficient time to revise systems, remediate customer files, test monitoring models and obtain board approval before July 2027.

This guide distinguishes between:

  • requirements already contained in the final AMLR;
  • technical detail currently being developed by AMLA;
  • and practical implementation measures that regulated firms should consider now.

For readers’ convenience, we have placed the key official sources and regulatory materials at the end of this guide.

Publish Date

08 Aug 2026

Reading Time

16 minutes

Category

Legal Guides

Jurisdiction

EU

What is the EU AML Regulation?

The AMLR is the directly applicable core of the EU’s revised AML/CFT legislative package.

It forms part of a wider framework that also includes:

  • Regulation (EU) 2024/1620, which established AMLA;
  • Directive (EU) 2024/1640, often referred to as AMLD6;
  • and revised rules governing transfers of funds and certain crypto-assets.

The European Commission describes the package as a reform intended to strengthen and harmonise the prevention of money laundering and terrorist financing throughout the EU.

The difference between the AMLR and AMLD6

The AMLR governs many of the obligations imposed directly on private-sector obliged entities.

These include requirements relating to:

  • internal policies and controls;
  • risk assessments;
  • customer due diligence;
  • beneficial ownership;
  • reporting suspicions;
  • record keeping;
  • and group-wide frameworks.

Directive (EU) 2024/1640 focuses more heavily on mechanisms that Member States must establish, including national supervisors, financial intelligence units and beneficial-ownership systems. It requires national transposition rather than operating solely as a directly applicable regulation.

The role of AMLA

AMLA is responsible for developing technical standards, guidelines and supervisory methodologies under the new framework.

It will also coordinate national supervisors and directly supervise selected high-risk cross-border financial institutions from 2028.

For regulated businesses, this means implementation will be shaped by three layers:

  1. the final AMLR text;
  2. AMLA’s technical standards and guidelines;
  3. supervisory expectations applied by AMLA and national authorities.

When does the AMLR apply?

The main AMLR requirements apply from 10 July 2027. The principal exception concerns specified professional football clubs and football agents, for which the rules generally apply from 10 July 2029.

For CASPs, EMIs, payment institutions and most other financial institutions, the relevant date is therefore 10 July 2027.

Key AMLR implementation dates

DevelopmentDate or status
AMLR entered into force9 July 2024
Main AMLR application date10 July 2027
CDD RTS consultation closed8 May 2026
Business relationships and linked transactions RTS consultation closed8 May 2026
Group-wide controls RTS consultation closed15 June 2026
Business-wide risk assessment consultation closed15 July 2026
Ongoing monitoring consultation closes3 September 2026
Main football-sector application date10 July 2029
The consultations do not replace the AMLR’s application date. Businesses must prepare for July 2027 even where technical standards remain in development.

Why the AMLR requires an implementation programme

The move from directives to a directly applicable regulation should reduce major national differences in substantive AML/CFT obligations.

It does not mean that implementation will be automatic.

A regulated business may need to change:

  • its risk methodology;
  • customer-data requirements;
  • onboarding workflows;
  • beneficial-ownership checks;
  • transaction-monitoring rules;
  • customer-review schedules;
  • group reporting;
  • outsourcing arrangements;
  • internal governance;
  • and regulatory documentation.

Existing compliance does not guarantee AMLR readiness

A firm may comply with its current national framework but still face gaps against the AMLR.

Potential reasons include:

  • different national interpretations under earlier directives;
  • incomplete group-wide implementation;
  • legacy customer files;
  • insufficient targeted-financial-sanctions analysis;
  • fragmented customer data;
  • and monitoring systems designed around current national thresholds.

The appropriate question is not whether the firm already has an AML manual. It is whether its actual controls, systems and evidence will satisfy the new EU framework.

Which businesses are affected?

The AMLR applies to a broad category of obliged entities.

For the Legasset audience, the most relevant financial-sector entities include:

  • crypto-asset service providers;
  • credit institutions;
  • electronic money institutions;
  • payment institutions;
  • investment firms;
  • investment and asset-management businesses;
  • insurers and insurance intermediaries in relevant circumstances;
  • lending and credit businesses;
  • and currency-exchange providers.

CASPs

CASPs authorised under Regulation (EU) 2023/1114, or MiCA, remain subject to AML/CFT obligations.

A MiCA authorisation does not replace the AMLR. The two frameworks regulate different aspects of the business.

MiCA addresses matters such as:

  • authorisation;
  • governance;
  • prudential safeguards;
  • custody;
  • conduct;
  • and market integrity.

The AMLR addresses the prevention of money laundering, terrorist financing and related financial-crime risks.

EMIs and payment institutions

EMIs and PIs are already subject to EU AML/CFT requirements.

The AMLR may nevertheless require material changes to:

  • customer classification;
  • merchant and agent oversight;
  • linked-transaction detection;
  • monitoring;
  • source-of-funds controls;
  • and group-wide governance.

Firms operating through passports, branches, agents or distributors should pay particular attention to whether controls are consistently implemented across Member States.

Business-wide risk assessment

The AMLR requires obliged entities to identify and assess the money laundering and terrorist financing risks arising from their business.

The assessment must also address risks connected with the non-implementation and evasion of targeted financial sanctions. AMLA’s draft guidelines explain that this expands the express scope of the business-wide risk assessment beyond the approach set out under the earlier framework.

What the assessment should cover

A business-wide risk assessment should consider exposure arising from:

  • customers;
  • products and services;
  • transactions;
  • delivery channels;
  • geographic markets;
  • new technologies;
  • agents and distributors;
  • intermediaries;
  • outsourcing;
  • and group structures.

It should be documented, maintained and reviewed regularly.

CASP-specific risk factors

For a CASP, relevant risk factors may include:

  • interactions with unhosted wallets;
  • privacy-enhancing technology;
  • mixers or tumblers;
  • cross-chain bridges;
  • rapid asset conversion;
  • high-risk tokens;
  • DeFi protocols;
  • peer-to-peer transfers;
  • sanctions exposure;
  • and blockchain-obfuscation techniques.

The assessment should distinguish between products that create different levels and types of risk. Treating all crypto activity as one uniform category is unlikely to produce a defensible risk methodology.

EMI and PI risk factors

For an EMI or payment institution, relevant factors may include:

  • remote onboarding;
  • cross-border transfers;
  • merchant acquiring;
  • card-not-present activity;
  • agents and distributors;
  • account misuse;
  • high-risk merchants;
  • rapid movement of funds;
  • nested payment relationships;
  • and transactions involving higher-risk jurisdictions.

A firm should explain how each risk factor affects its customer-risk model, onboarding requirements and monitoring controls.

Targeted financial sanctions

The express inclusion of targeted-financial-sanctions risks means firms should review whether their business-wide assessment covers more than sanctions-screening operations.

The analysis may need to address:

  • customer and beneficial-owner screening;
  • ownership and control;
  • asset-freeze exposure;
  • circumvention risks;
  • indirect counterparties;
  • payment-message data;
  • blockchain-address exposure;
  • and escalation procedures.

Policies, procedures and internal controls

The business-wide risk assessment should determine the design of the firm’s policies, procedures and controls.

A firm should be able to demonstrate a clear connection between identified risk and implemented mitigation.

Core policy areas

The internal framework should cover, where relevant:

  • customer due diligence;
  • beneficial ownership;
  • customer-risk classification;
  • enhanced due diligence;
  • ongoing monitoring;
  • sanctions;
  • suspicious-transaction reporting;
  • record keeping;
  • staff screening;
  • training;
  • new-product approval;
  • outsourcing;
  • agents and distributors;
  • group-wide information sharing;
  • and independent testing.

Policies must reflect operations

Generic or group-template policies may be insufficient where they do not reflect the legal entity’s actual products, systems and customers.

For example, a CASP policy should explain how blockchain analytics are used in practice. An EMI policy should address the risks created by agents, distributors, merchants or pooled accounts where those features form part of the business.

Governance and management approval

Senior management should understand and approve the firm’s AML/CFT framework.

The board or equivalent governing body should receive enough information to evaluate:

  • material risks;
  • control performance;
  • monitoring weaknesses;
  • suspicious-activity trends;
  • sanctions exposure;
  • remediation;
  • staffing;
  • and regulatory findings.

Approval should be evidenced through minutes, decisions and follow-up actions rather than an isolated signature page.

Customer due diligence

The AMLR establishes the legal basis for harmonised customer due diligence across the EU.

AMLA’s draft RTS under Article 28(1) is intended to specify the information and documentation that obliged entities should collect for standard, simplified and enhanced due diligence. The consultation opened on 9 February 2026 and closed on 8 May 2026; AMLA had not yet published final consultation results as of 4 August 2026.

Identification and verification

A firm should identify and verify:

  • the customer;
  • persons acting on the customer’s behalf;
  • beneficial owners;
  • and, where relevant, persons exercising control.

Verification should use reliable and independent sources.

AMLA’s draft standards also address the attributes required when electronic identification or qualified trust services are used.

Purpose and intended nature

CDD should not stop at identity documents.

The firm should understand:

  • why the customer requires the product;
  • the expected use of the account or service;
  • anticipated transaction types;
  • expected volumes and values;
  • relevant counterparties;
  • and geographic exposure.

This information forms the baseline against which later activity can be monitored.

Customer information should be proportionate

The risk-based approach permits differences in the extent of information collected.

However, proportionality should not be confused with omission. The firm should retain enough evidence to explain why its measures were suitable for the assessed risk.

Electronic identification

Digital onboarding will remain important for CASPs, EMIs and PIs.

Firms using electronic identification should assess:

  • whether all required attributes are available;
  • whether the source is sufficiently reliable;
  • how liveness and impersonation risks are managed;
  • how fraud indicators are escalated;
  • and what additional checks are required where digital tools do not provide complete information.

The draft CDD RTS recognises that electronic identification may need to be supplemented where it lacks the attributes necessary for proper verification.

Beneficial ownership

Legal-entity customers require more than verification of incorporation.

The obliged entity must identify and take reasonable measures to verify beneficial owners and understand the customer’s ownership and control structure.

Areas requiring particular attention

Higher-risk cases may involve:

  • several corporate layers;
  • trusts or similar arrangements;
  • nominee shareholders or directors;
  • foundations;
  • partnerships;
  • control through contractual rights;
  • ownership chains crossing several jurisdictions;
  • or apparent owners acting for undisclosed persons.

Register data may not be enough

Beneficial-ownership registers can support verification, but firms should not treat a register entry as conclusive in all circumstances.

Where information is inconsistent, incomplete or implausible, the firm should obtain further evidence and resolve the discrepancy.

Ownership and control

A customer may be controlled without a single person holding a straightforward majority shareholding.

The assessment should consider:

  • voting rights;
  • appointment rights;
  • shareholder agreements;
  • financing arrangements;
  • family or personal relationships;
  • and other means of exercising control.

Business relationships, occasional transactions and linked transactions

The AMLR contains definitions and thresholds that determine when customer due diligence is required.

AMLA consulted on draft RTS specifying criteria for identifying:

  • business relationships;
  • occasional transactions;
  • linked transactions;
  • and circumstances in which lower CDD thresholds may apply.

That consultation closed on 8 May 2026.

What is a business relationship?

A business relationship generally involves an element of duration or expected repetition.

Online registration providing ongoing access may be relevant when determining whether such a relationship exists.

A customer should not necessarily be treated as an occasional user merely because each transaction is initiated separately.

What are linked transactions?

Transactions may be linked where they form part of an overall operation or are structured to avoid CDD requirements.

Systems should be capable of identifying connections across:

  • time;
  • accounts;
  • wallets;
  • beneficiaries;
  • payment instruments;
  • devices;
  • counterparties;
  • and group entities.

Why this matters for digital firms

Digital platforms can process high volumes of apparently separate transactions.

A CASP or payment firm should not rely only on transaction-level thresholds. It should assess whether activity is connected by customer, beneficial owner, device, wallet, destination or economic purpose.

Customer-risk classification

The customer-risk assessment translates the business-wide risk framework into individual customer treatment.

A robust model should consider factors relating to:

  • the customer;
  • ownership and control;
  • products;
  • transaction behaviour;
  • jurisdictions;
  • delivery channels;
  • counterparties;
  • and adverse information.

Avoid mechanical scoring

A scoring model can support consistency, but it should not replace judgement.

Firms should test whether:

  • high-risk indicators receive appropriate weight;
  • combinations of factors create escalation;
  • overrides are controlled and documented;
  • data feeds are accurate;
  • and risk ratings change when customer behaviour changes.

Separate inherent and residual considerations

It may be helpful to distinguish between the customer’s underlying risk and the effect of controls or restrictions.

For example, a customer with high-risk geographic exposure does not become inherently low-risk merely because transaction limits have been imposed.

Simplified due diligence

Simplified due diligence may be used only where lower risk has been established.

It does not mean that the firm can avoid understanding the customer or monitoring the relationship.

A defensible SDD decision

The file should explain:

  • why the relationship presents lower risk;
  • which measures were simplified;
  • why the remaining information is sufficient;
  • and what events would trigger reclassification.

The draft CDD RTS indicates that even in lower-risk situations, firms should understand the intended use of the product and, where relevant, expected transaction values.

Enhanced due diligence

Higher-risk relationships require enhanced measures.

The precise response should reflect the nature of the risk rather than applying the same additional document request in every case.

Potential enhanced measures

Depending on the circumstances, a firm may need to obtain:

  • additional identity evidence;
  • more detailed ownership information;
  • source of funds;
  • source of wealth;
  • business rationale;
  • supporting transaction documentation;
  • senior-management approval;
  • more frequent reviews;
  • enhanced monitoring;
  • and restrictions on products or transaction channels.

Source of funds and source of wealth

Source of funds concerns the origin of money or assets used in a transaction or relationship.

Source of wealth concerns how the customer or beneficial owner accumulated their overall wealth.

For crypto customers, the analysis may require both traditional financial evidence and blockchain information.

For payment customers, it may require invoices, contracts, payroll records, banking statements, tax documents or evidence of commercial activity.

Ongoing monitoring

The AMLR requires ongoing monitoring to ensure that transactions and activities remain consistent with the firm’s knowledge of the customer and assessed risk.

AMLA opened a consultation on draft guidelines for ongoing monitoring on 3 June 2026. The consultation remains open until 3 September 2026 at 23:59 CEST.

Monitoring the relationship

Ongoing monitoring includes more than automated transaction alerts.

The firm should consider:

  • whether customer information remains accurate;
  • whether ownership has changed;
  • whether transaction behaviour remains consistent;
  • whether new products have been added;
  • whether geographic exposure has changed;
  • and whether new adverse or sanctions information is available.

Monitoring for CASPs

A CASP may need to combine:

  • customer information;
  • blockchain analytics;
  • wallet-risk data;
  • transaction patterns;
  • sanctions data;
  • and off-chain information.

Blockchain alerts should not be assessed in isolation. The firm should consider whether the explanation is consistent with the customer profile and wider activity.

Monitoring for EMIs and PIs

Payment firms may need scenarios covering:

  • rapid movement of funds;
  • unusual merchant activity;
  • account cycling;
  • multiple cards or accounts;
  • pass-through behaviour;
  • unexpected jurisdictions;
  • third-party funding;
  • and structuring below thresholds.

Monitoring should reflect how the product can be misused, not merely reproduce a generic vendor rule set.

Suspicious-transaction reporting

Where the firm knows, suspects or has reasonable grounds to suspect money laundering or terrorist financing, it must follow the applicable reporting framework.

The AMLR operates alongside the national FIU structures governed principally through Directive (EU) 2024/1640.

Internal escalation

The internal process should specify:

  • who receives alerts;
  • how investigations are documented;
  • who decides whether to report;
  • how urgent cases are escalated;
  • how tipping-off risk is controlled;
  • and how post-reporting monitoring is handled.

Quality matters

A high volume of reports does not necessarily demonstrate effective compliance.

The firm should assess whether reports are:

  • timely;
  • factually clear;
  • supported by relevant transaction information;
  • linked to the suspected typology;
  • and consistent with internal findings.

Group-wide AML/CFT controls

Groups must establish policies, procedures and controls that provide a consolidated view of risk and support consistent compliance across entities.

AMLA consulted on draft RTS under Articles 16(4) and 17(3) of the AMLR. The standards address group-wide minimum requirements and additional measures for branches and subsidiaries in third countries. The consultation closed on 15 June 2026.

Components of a group-wide framework

A cross-border group should consider:

  • common minimum policies;
  • consistent risk methodology;
  • information sharing;
  • consolidated management information;
  • group compliance oversight;
  • internal audit;
  • escalation of material deficiencies;
  • local-law deviations;
  • and remediation tracking.

Local differences

A group policy should establish minimum standards, but local entities may require additional measures.

The group should document:

  • which local rules differ;
  • whether they are stricter or incompatible;
  • what adjustments have been made;
  • and how residual risk is managed.

Third-country operations

Where local law prevents a subsidiary or branch from applying required group controls, the group may need additional measures.

The issue should be escalated and documented. A statement that local law prevents compliance should be supported by a clear legal analysis.

Outsourcing and reliance on third parties

Outsourcing does not transfer regulatory responsibility.

CASPs, EMIs and PIs often rely on third parties for:

  • identity verification;
  • sanctions screening;
  • transaction monitoring;
  • blockchain analytics;
  • case management;
  • cloud hosting;
  • and compliance operations.

Due diligence before appointment

The firm should assess:

  • technical capability;
  • data quality;
  • methodology;
  • security;
  • regulatory experience;
  • subcontracting;
  • resilience;
  • and exit arrangements.

Contractual protections

The agreement should address:

  • service standards;
  • access to data;
  • audit and inspection;
  • incident reporting;
  • confidentiality;
  • business continuity;
  • regulatory access;
  • and termination assistance.

Ongoing oversight

Vendor selection is not enough.

The firm should test:

  • false-positive and false-negative rates;
  • rule performance;
  • screening coverage;
  • data completeness;
  • service incidents;
  • and remediation.

Where a vendor model cannot be explained or validated, the obliged entity may struggle to demonstrate effective control.

Record keeping and audit trail

A regulated firm should retain enough information to reconstruct:

  • the customer relationship;
  • CDD decisions;
  • risk classification;
  • transactions;
  • monitoring alerts;
  • investigations;
  • reports;
  • approvals;
  • and material changes.

Decision records

A file should show why a decision was made.

This is particularly important where the firm:

  • applies simplified due diligence;
  • accepts a high-risk customer;
  • overrides a risk score;
  • closes an alert without reporting;
  • relies on alternative verification;
  • or continues a relationship after adverse information.

Data architecture

Implementation should include a data-mapping exercise identifying:

  • source systems;
  • ownership of data;
  • retention periods;
  • access rights;
  • interfaces;
  • data-quality controls;
  • and reconciliation procedures.

Staff, compliance functions and training

The compliance framework requires sufficient people with appropriate knowledge and authority.

Compliance capacity

Firms should assess whether staffing is adequate for:

  • onboarding volumes;
  • alert volumes;
  • investigations;
  • periodic reviews;
  • sanctions;
  • quality assurance;
  • regulatory reporting;
  • and remediation.

The assessment should reflect forecast growth, not only current activity.

Training

Training should be appropriate to the employee’s role.

Different material may be required for:

  • customer-support teams;
  • onboarding analysts;
  • investigators;
  • product teams;
  • developers;
  • senior management;
  • sales;
  • and board members.

Independent testing

The firm should determine how it will test the effectiveness of its framework.

Independent review may cover:

  • governance;
  • risk methodology;
  • sample customer files;
  • monitoring;
  • suspicious-reporting decisions;
  • outsourcing;
  • and remediation.

AMLR implications for licensing applications

The AMLR will affect new CASP, EMI and PI applications as well as existing institutions.

An applicant should demonstrate that its planned framework can comply with the rules applicable when operations begin.

Application documents

Relevant materials may include:

  • a business-wide risk assessment;
  • AML/CFT policies;
  • customer-risk methodology;
  • onboarding procedures;
  • transaction-monitoring design;
  • sanctions controls;
  • outsourcing arrangements;
  • compliance governance;
  • staffing plans;
  • and financial-crime reporting lines.

Timing

A business applying during 2026 or 2027 should not design its framework only around rules that will soon be replaced or supplemented.

Where AMLA standards remain draft, the applicant should identify this clearly and create an update mechanism.

AMLR implications for regulated-entity acquisitions

The AMLR is also relevant to transactions involving CASPs, EMIs, PIs and other regulated entities.

A buyer should assess whether the target’s framework is likely to be compliant by 10 July 2027.

Due-diligence areas

The review may include:

  • AMLR gap analysis;
  • legacy customer files;
  • customer-risk methodology;
  • transaction-monitoring performance;
  • sanctions;
  • beneficial ownership;
  • suspicious-reporting history;
  • regulator findings;
  • outsourcing;
  • staffing;
  • and open remediation.

Purchase-price and integration implications

Material AMLR deficiencies may affect:

  • valuation;
  • warranties;
  • indemnities;
  • conditions precedent;
  • remediation budgets;
  • integration timing;
  • and regulatory notifications.

A buyer should also assess whether the combined group can share information and produce consolidated risk reporting.

Sensitive transaction materials should be considered only after appropriate KYC, NDA and Proof of Funds procedures where applicable.

A practical AMLR implementation roadmap

Firms should treat AMLR readiness as a structured programme with clear ownership.

Phase 1: Legal and regulatory mapping

Recommended timing: August–October 2026

The firm should:

  • map current requirements against the AMLR;
  • identify applicable AMLA standards and consultations;
  • distinguish mandatory changes from pending technical detail;
  • and create an obligations register.

Phase 2: Gap assessment

Recommended timing: September–December 2026

The assessment should cover:

  • governance;
  • risk methodology;
  • CDD;
  • beneficial ownership;
  • monitoring;
  • group controls;
  • sanctions;
  • outsourcing;
  • data;
  • staffing;
  • and documentation.

Each gap should have an owner, risk rating and target date.

Phase 3: Design and approval

Recommended timing: November 2026–February 2027

The firm should revise:

  • policies;
  • procedures;
  • risk models;
  • data requirements;
  • monitoring scenarios;
  • governance;
  • and outsourcing arrangements.

Material changes should receive senior-management or board approval.

Phase 4: Systems and remediation

Recommended timing: January–May 2027

This phase may involve:

  • software changes;
  • data migration;
  • customer-file remediation;
  • new verification requirements;
  • scenario tuning;
  • group integration;
  • and vendor changes.

Phase 5: Testing and training

Recommended timing: April–June 2027

Testing should examine whether the redesigned framework works in practice.

The firm should complete:

  • sample testing;
  • monitoring validation;
  • customer-file quality assurance;
  • staff training;
  • management reporting;
  • and implementation sign-off.

Phase 6: Post-application monitoring

From 10 July 2027

The firm should track:

  • technical-standard updates;
  • supervisory guidance;
  • control performance;
  • incidents;
  • regulatory feedback;
  • and unresolved implementation risks.

AMLR implementation checklist

Governance

  • Board-approved AMLR implementation plan
  • Named executive sponsor
  • Clear compliance ownership
  • Adequate staffing and budget
  • Regular implementation reporting
  • Independent assurance arrangements

Risk assessment

  • Updated business-wide risk assessment
  • Targeted-financial-sanctions risk included
  • Product and jurisdictional risks documented
  • CASP, EMI or PI-specific typologies covered
  • Review frequency defined
  •  

Customer due diligence

  • Customer-data requirements mapped
  • Digital identification assessed
  • Beneficial-ownership verification revised
  • Purpose and intended nature documented
  • Simplified and enhanced measures defined
  • Legacy-file remediation planned

Monitoring

  • Customer-review triggers revised
  • Transaction scenarios mapped to risk
  • Crypto and fiat data integrated where relevant
  • Linked transactions addressed
  • Monitoring models tested
  • Alert governance documented

Group-wide controls

  • Group policy updated
  • Local deviations identified
  • Information-sharing arrangements reviewed
  • Third-country restrictions assessed
  • Consolidated management information available
  •  

Outsourcing and data

  • Vendor due diligence completed
  • Contracts reviewed
  • Audit and access rights confirmed
  • Data lineage documented
  • Record-retention framework updated
  • Exit and continuity plans tested
  •  

How Legasset can assist

Legasset supports crypto, payments and financial institutions preparing for the AMLR.

Our work may include:

  • AMLR gap analysis;
  • business-wide risk assessments;
  • CASP, EMI and PI licensing;
  • AML/CFT policy development;
  • beneficial-ownership procedures;
  • customer-risk methodology;
  • governance and MLRO support;
  • transaction-monitoring reviews;
  • outsourcing assessments;
  • regulated-entity due diligence;
  • post-acquisition integration;
  • remediation planning;
  • and cross-border market-entry structuring.

The appropriate implementation approach depends on the firm’s activities, customers, geographic footprint, systems and regulatory status.

EU AMLR 2027 FAQ

When does the EU AML Regulation apply?

The main AMLR provisions apply from 10 July 2027.

Specified football clubs and agents generally become subject to the rules from 10 July 2029.

Yes. Regulation (EU) 2024/1624 has been adopted and published.

However, several AMLA technical standards and guidelines that specify how particular obligations operate were still being finalised as of 4 August 2026.

The AMLR is an EU regulation and is directly applicable.

Directive (EU) 2024/1640 requires national transposition for the matters it covers.

Yes. CASPs are financial-sector obliged entities under the EU AML/CFT framework.

A MiCA authorisation does not replace AMLR compliance.

Yes. Electronic money institutions and payment institutions fall within the regulated financial sector and must prepare for the AMLR requirements.

Some existing material may remain usable, but firms should conduct a formal gap analysis.

Policies may require changes to reflect the AMLR, AMLA standards and the firm’s current business model.

The AMLR requires the assessment to address ML/TF risks and risks related to the non-implementation and evasion of targeted financial sanctions.

Not yet, based on the status available on 4 August 2026.

The consultation closed on 8 May 2026, and AMLA’s regulatory-instruments page continued to classify the CDD RTS as a closed consultation rather than a published final report.

The consultation closes on 3 September 2026 at 23:59 CEST.

Not automatically.

The firm must establish lower risk and retain sufficient information to understand the customer and intended use of the service.

Linked transactions are transactions connected in a way that requires them to be considered together, including where activity may be structured to avoid CDD thresholds.

A firm should assess whether legacy customer files contain the information and evidence required under the new framework.

Where they do not, a risk-based remediation programme may be necessary.

No.

The obliged entity remains responsible for compliance and must oversee the outsourced provider.

No.

The AMLR is final and the July 2027 application date is fixed. Businesses can begin governance, data, risk and systems work while tracking pending technical detail.

Buyers should assess whether the target can comply by July 2027 and whether remediation costs or control weaknesses affect valuation, integration or regulatory risk.

Topic-Specific Official Resources and Regulatory Materials

I. EUR-Lex — Regulation (EU) 2024/1624 on preventing money laundering and terrorist financing
This is the official legal text of the AMLR and the primary source for the obligations applying directly to obliged entities from July 2027.

II. EUR-Lex — Directive (EU) 2024/1640 on national AML/CFT mechanisms
The directive governs matters including national supervisors, financial intelligence units and beneficial-ownership mechanisms.

III. EUR-Lex — Regulation (EU) 2024/1620 establishing AMLA
This regulation establishes AMLA’s mandate, regulatory powers and direct-supervision responsibilities.

IV. AMLA — Regulatory instruments and current development status
This page tracks AMLA’s technical standards, guidelines, open consultations, closed consultations and published final reports.

V. AMLA — Draft RTS on customer due diligence
The consultation addresses the information, documents and verification requirements for standard, simplified and enhanced customer due diligence.

VI. AMLA — Draft RTS on business relationships, occasional transactions and linked transactions
The draft standards explain criteria used to identify CDD-triggering relationships and transactions, including connected activity and lower thresholds.

VII. AMLA — Draft guidelines on business-wide risk assessment
The guidelines describe the proposed minimum content of an obliged entity’s business-wide ML/TF and targeted-financial-sanctions risk assessment.

VIII. AMLA — Draft RTS on group-wide AML/CFT requirements
The consultation covers group-wide policies, cross-border implementation and additional measures for third-country subsidiaries and branches.

IX. AMLA — Draft guidelines on ongoing monitoring
The open consultation addresses customer monitoring, transaction and activity monitoring, risk-based systems and the updating of customer information.

X. European Commission — EU anti-money laundering and counter-terrorist-financing framework
The Commission’s overview explains the development and structure of the EU AML/CFT framework.

Check Our Available Ready-Made Licenses

Below are all the off-the-shelf license options available for purchase. Browse through the list of licenses and read the details to choose the option that is right for your business:

How do I get other licenses?

other articles and news:

Accelerate Your Business with These Offers

Before you leave, take a moment to explore our complete list of ready-made licenses, carefully curated to meet your business needs. These licenses are your fast track to launching or expanding operations without the usual delays. Secure yours today to ensure your business is compliant and ready to thrive from day one.
Scroll to Top

Let’s Discuss Your Request

Your submission has been sent. Be in touch!
Legasset Law Company
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.