Which Financial and Crypto Groups Could Face Direct AMLA Supervision?

Legasset Legal Blog Legal News Which Financial and Crypto Groups Could Face Direct AMLA Supervision?

AMLA Direct Supervision: Which Financial Groups Enter the 2027 Selection Process?

The Authority for Anti-Money Laundering and Countering the Financing of Terrorism is preparing to identify the first financial institutions and groups that it will supervise directly at EU level.

National financial supervisors must provide the relevant eligibility data to AMLA by 15 August 2026. The Authority expects to finalise a provisional list of eligible entities by the end of September 2026, before conducting the formal selection process in 2027.

From 2028, AMLA is expected to supervise 40 of the EU’s most complex and high-risk financial institutions or groups. The selection may include banks, payment institutions, electronic money institutions, investment firms and crypto-asset service providers where they meet the geographic and risk criteria.

The current exercise does not mean that AMLA has already selected or named the institutions it will supervise. It is an eligibility and data-collection stage that will determine which businesses enter the 2027 risk assessment and selection process.

For readers’ convenience, we have placed the key official sources and regulatory materials at the end of this article.

Publish Date

08 Aug 2026

Reading Time

14 minutes

Category

Legal News

Jurisdiction

EU

What is AMLA’s direct-supervision mandate?

AMLA was established under Regulation (EU) 2024/1620. Its responsibilities include coordinating national AML/CFT supervisors, supporting cooperation between financial intelligence units and directly supervising selected financial-sector obliged entities.

Direct supervision represents a major change to the EU’s anti-money laundering architecture. Cross-border financial groups have historically been supervised principally by national authorities, even where their operations extend across many Member States.

Under the new framework, selected institutions will be supervised directly by an EU authority through arrangements involving AMLA and relevant national supervisors.

Which businesses fall within the financial sector?

For direct-supervision purposes, the framework concerns credit institutions, financial institutions and groups composed of such institutions.

Depending on their regulatory status and activities, the potentially relevant population may include:

  • banks and other credit institutions;
  • payment institutions;
  • electronic money institutions;
  • investment firms;
  • insurance-sector financial institutions;
  • funds and asset-management businesses;
  • credit providers;
  • currency-exchange businesses;
  • and crypto-asset service providers.

A business does not become eligible merely because it belongs to one of these categories. It must also satisfy the cross-border activity test and receive the required risk classification.

Does AMLA supervise non-financial businesses directly?

The routine selection process under Article 12 of Regulation (EU) 2024/1620 concerns the financial sector.

Non-financial obliged entities will remain under national supervision, although they will be affected by AMLA’s technical standards, supervisory convergence work and coordination role.

AMLA also has powers relating to exceptional supervisory circumstances and systemic weaknesses. However, these should be distinguished from the recurring process used to select the 40 financial institutions or groups for direct supervision.

What is happening in August and September 2026?

On 12 May 2026, AMLA published a reporting package for identifying provisionally eligible obliged entities.

The package contains:

  • a standardised reporting template;
  • an interpretative note;
  • data specifications;
  • and instructions for national supervisors and relevant obliged entities.

National financial supervisors organise the data collection from businesses within their supervisory remit. They then transmit the required information to AMLA, which is the ultimate recipient and sets the reporting specifications.

The 15 August 2026 reporting deadline

AMLA has stated that it will collect the eligibility information from national supervisors by 15 August 2026.

An error-correction and alignment phase will follow. During this period, AMLA and home supervisors may address data-quality problems, inconsistencies and differences in how information has been reported.

The deadline applies to transmissions from national supervisors to AMLA. Individual institutions may receive earlier internal deadlines from their national authority.

Businesses should therefore follow the timetable communicated by their competent supervisor rather than assuming they can submit data directly to AMLA on 15 August.

The provisional eligibility list

AMLA expects the provisional list of eligible obliged entities to be finalised by the end of September 2026.

Inclusion on that list will not mean that the entity has been selected for direct supervision.

It will mean that the institution or group appears to satisfy the geographic criteria and may proceed into the risk-assessment stage that informs the 2027 selection exercise.

How does an institution become eligible for AMLA supervision?

The selection framework involves two principal stages.

Stage one: geographic eligibility

An institution or group must operate in at least six EU Member States, including its home Member State.

Operations may be conducted:

  • through subsidiaries;
  • through branches;
  • through other establishments;
  • or under the freedom to provide services.

The draft selection standards clarify that a notification to provide cross-border services is not necessarily enough. Activities conducted under the freedom to provide services must reach a specified level of materiality.

Stage two: residual ML/TF risk

After identifying geographically eligible institutions and groups, AMLA will classify their money laundering and terrorist financing risk.

The framework considers both:

  • inherent risk, meaning exposure before mitigating controls are considered; and
  • residual risk, meaning the risk remaining after the quality and effectiveness of controls are assessed.

The most relevant institutions for direct supervision will be those combining a significant EU presence with a high residual ML/TF risk profile.

An institution operating in many countries will therefore not be selected automatically. Geographic eligibility creates entry into the selection population; risk determines which eligible entities are prioritised.

How is the six-Member-State threshold calculated?

The home jurisdiction counts toward the six-Member-State requirement.

For example, an institution headquartered in one Member State and conducting qualifying operations in five others may satisfy the geographic test.

A group can meet the requirement through a combination of:

  • locally incorporated subsidiaries;
  • branches;
  • establishments;
  • and material cross-border services.

Establishment-based operations

Where an institution operates through a subsidiary or branch, that presence is generally more straightforward to identify.

National supervisory and regulatory records can show where the group has legally established operations.

However, the analysis can become more complex where different regulated entities within one group hold different permissions or serve different markets.

Freedom-to-provide-services operations

Passport notifications alone may overstate a firm’s real geographic footprint.

An EMI, payment institution or CASP may have notified services across the European Economic Area without developing meaningful customer activity in every notified jurisdiction.

The draft AMLA methodology therefore introduces materiality thresholds based on:

  • the number of customers resident in the Member State; or
  • the euro value of incoming and outgoing transactions generated by those customers.

The thresholds are alternatives. This allows the methodology to capture both high-customer-volume businesses and firms serving fewer customers with substantial transaction activity.

Why the materiality test matters

The test is intended to prevent nominal or dormant passporting from making an institution eligible for EU-level supervision.

At the same time, firms should not assume that a small number of customers makes a jurisdiction irrelevant. A limited customer base may still be material where transaction values are high.

For cross-border fintech and crypto groups, accurate jurisdictional customer and transaction data will therefore be essential.

How will AMLA assess money laundering risk?

The selection methodology is intended to align with the common risk-assessment framework used by national financial supervisors.

This means AMLA and national authorities should work from comparable data points and classification principles rather than applying entirely different models.

Inherent risk

Inherent risk concerns the institution’s exposure before internal controls are taken into account.

Relevant factors may include:

  • customer types;
  • products and services;
  • transaction channels;
  • delivery methods;
  • geographic exposure;
  • use of agents and distributors;
  • cross-border activity;
  • cash intensity;
  • anonymity risks;
  • complex ownership structures;
  • higher-risk counterparties;
  • and exposure to jurisdictions associated with elevated ML/TF risk.

A digital business with no physical cash activity may still have substantial inherent risk due to rapid cross-border transfers, remote onboarding, high-risk customers or complex payment chains.

Quality of controls

The assessment also considers the institution’s systems and controls.

These may include:

  • customer due diligence;
  • beneficial-ownership verification;
  • customer-risk scoring;
  • sanctions screening;
  • transaction monitoring;
  • suspicious-activity reporting;
  • correspondent controls;
  • agent and distributor oversight;
  • crypto blockchain analytics;
  • governance;
  • compliance staffing;
  • internal audit;
  • outsourcing oversight;
  • and remediation history.

Controls must be effective in practice. A detailed policy will carry limited weight if implementation evidence shows weak alerts, poor escalation, inadequate staffing or unresolved supervisory findings.

Residual risk

Residual risk is determined after inherent exposure and control quality are assessed.

A high-risk business model does not necessarily result in high residual risk where controls are strong and demonstrably effective.

Conversely, a business with moderate inherent exposure may receive an elevated residual-risk classification where its controls are weak, inconsistently implemented or poorly governed.

How will group-wide risk be calculated?

Large financial groups may contain subsidiaries with very different products, customer populations and risk levels.

The draft methodology therefore does not rely on a simple unweighted average across the group.

Instead, the group-wide risk score is based on a weighted average of entity-level residual-risk scores. Higher-risk and more significant entities should receive greater weight, reducing the possibility that numerous lower-risk subsidiaries dilute the effect of a major high-risk business.

Why group structure matters

A multinational group may operate through:

  • a bank in one jurisdiction;
  • an EMI in another;
  • payment institutions in several Member States;
  • and a CASP serving customers across the EU.

The group-wide assessment may therefore require consistent data across entities subject to different sectoral rules and national supervisors.

The highest EU parent that qualifies as a credit or financial institution is particularly important because the methodology aggregates the group’s risk at that level.

Can a low-risk subsidiary reduce the group score?

Lower-risk subsidiaries may influence the aggregated score, but they should not disproportionately offset a high-risk or systemically important entity.

The weighting mechanism is intended to reflect each entity’s:

  • size;
  • operational importance;
  • sectoral risk;
  • and contribution to the group’s total activities.

Groups should therefore test whether their internal aggregation methodology produces results comparable to AMLA’sintended approach.

Are the selection standards already final?

The legal framework establishing the selection process is already contained in Regulation (EU) 2024/1620.

However, the detailed methodology has been developed through draft regulatory and implementing technical standards.

In December 2025, AMLA published final reports containing draft standards on:

  • common financial-sector risk assessment;
  • and risk assessment for the selection of institutions for direct supervision.

These draft standards were submitted for adoption at EU level. AMLA stated that the rules would apply directly across Member States once approved by the European Commission.

The distinction is important:

  • the direct-supervision mandate and statutory selection framework are in force;
  • the final reports on the draft technical standards have been completed by AMLA;
  • but the technical standards still require completion of the applicable EU adoption process.

Articles should therefore avoid saying that every technical rule has already entered into force.

Which firms are most likely to attract attention?

AMLA has not published the names of provisionally eligible or selected institutions.

No business should be described as a likely selected entity without reliable evidence.

However, the structure of the legal framework suggests that the most relevant population will include institutions or groups with:

  • significant operations across at least six Member States;
  • complex cross-border structures;
  • high-risk products or customer populations;
  • substantial transaction volumes;
  • material third-country exposure;
  • weaknesses in AML/CFT controls;
  • or elevated residual-risk classifications.

Banks and large financial groups

Large banking groups are natural candidates because many operate through subsidiaries, branches and passported services across the EU.

Their scale alone will not determine selection, but it can increase the complexity and significance of the supervisory task.

EMIs and payment institutions

Cross-border EMIs and payment institutions may meet the geographic threshold rapidly through passporting.

The most relevant risk areas may include:

  • agent and distributor networks;
  • merchant-acquiring activity;
  • high-volume transfers;
  • correspondent relationships;
  • safeguarding structures;
  • remote onboarding;
  • account misuse;
  • and customers operating in higher-risk sectors.

These institutions should verify whether passported jurisdictions reflect genuine customer activity and whether their country-level data is complete.

Crypto-asset service providers

CASPs are financial institutions under the EU AML framework and may enter the eligible population where their geographic reach and risk profile satisfy the legal criteria.

Relevant risks can include:

  • rapid cross-border transfers;
  • unhosted-wallet interactions;
  • privacy-enhancing technologies;
  • high-risk tokens;
  • exposure to decentralised protocols;
  • sanctions evasion;
  • complex source-of-funds analysis;
  • and dependence on blockchain analytics.

A MiCA licence does not replace the need for robust AML/CFT controls. Licensing status and residual financial-crime risk are separate considerations.

Groups combining payments and crypto

Groups operating both payment and crypto businesses may face additional complexity.

They may need to aggregate data across:

  • fiat payment accounts;
  • e-money wallets;
  • card or merchant services;
  • crypto custody;
  • exchange activity;
  • stablecoin transfers;
  • and cross-border group companies.

Fragmented compliance systems can make it difficult to identify linked customers, connected transactions and group-wide risk.

What will direct AMLA supervision involve?

Selected entities will move from principally national AML/CFT supervision to direct oversight led by AMLA.

The legal framework provides for a joint supervisory team for each selected obliged entity. The team will include AMLAstaff and personnel from relevant national financial supervisors, coordinated by an AMLA team leader.

Joint supervisory teams

The joint supervisory team may coordinate:

  • supervisory planning;
  • risk assessments;
  • information requests;
  • thematic reviews;
  • on-site inspections;
  • remediation monitoring;
  • and communication with the supervised group.

This model resembles established EU supervisory structures while retaining national expertise.

Direct information and investigation powers

Under its founding regulation, AMLA has supervisory and enforcement powers over selected obliged entities.

The Authority may require information, conduct investigations and coordinate supervisory action. The precise use of those powers will depend on the facts, applicable procedures and the institution’s compliance profile.

Minimum period of direct supervision

A selected entity is expected to remain directly supervised for at least the relevant selection period.

The founding framework is designed to avoid immediate changes in supervisory responsibility where an entity temporarily alters its geographic footprint or risk characteristics after selection.

When does supervision begin?

The first formal selection takes place in 2027, with direct supervision beginning during 2028. AMLA’s current planning documents refer to the selection of 40 institutions and the commencement of direct supervision from 2028.

What happens to firms that are not selected?

Non-selection does not mean that an institution is low-risk or outside AMLA’s influence.

Most financial institutions will continue to be supervised directly by their national competent authorities.

However, AMLA’s methodologies and coordination role are intended to produce more consistent supervision across the EU.

Harmonised national risk assessments

National supervisors will use a common financial-sector methodology to assess inherent and residual ML/TF risk.

Institutions may therefore receive more standardised data requests and risk classifications, even where they are not considered for direct supervision.

Supervisory convergence

AMLA is expected to influence:

  • supervisory priorities;
  • risk-classification practices;
  • information requirements;
  • group-supervision approaches;
  • inspection methods;
  • and responses to serious compliance deficiencies.

A business outside the first group of 40 should not assume that its AML programme can remain unchanged.

Exceptional transfers of supervision

The legal framework also allows a national financial supervisor to submit a reasoned request asking AMLA to assume direct supervision of a non-selected institution in specified circumstances.

This is distinct from routine selection and should not be treated as an automatic mechanism. It nevertheless means that the first list of 40 is not the only possible route to direct involvement by AMLA.

What should potentially eligible groups do now?

The immediate objective should not be to predict whether the group will appear on the final list.

Businesses should ensure that the data used to assess eligibility and risk is complete, consistent and defensible.

1. Verify the EU operating footprint

Groups should identify every Member State in which they operate through:

  • subsidiaries;
  • branches;
  • agents or distributors where relevant;
  • establishments;
  • or the freedom to provide services.

Passport notifications should be compared against actual customer and transaction data.

2. Reconcile customer-location data

Customer residence may be recorded differently across onboarding, compliance, billing and payment systems.

Groups should test whether they can reliably determine:

  • the customer’s country of residence;
  • the contracting entity;
  • the regulated service provided;
  • and the transaction activity attributed to each Member State.

Poor data quality may create incorrect eligibility conclusions or require repeated supervisory clarification.

3. Reconcile transaction volumes

The institution should be able to calculate incoming and outgoing transaction values by relevant customer jurisdiction.

Methodologies should be consistent across entities and products.

Particular attention may be required where the group processes:

  • internal transfers;
  • currency conversions;
  • card payments;
  • merchant settlements;
  • crypto transfers;
  • blockchain transactions;
  • or transactions involving several group entities.

4. Review inherent-risk classifications

The group should assess whether internal risk ratings adequately reflect:

  • products;
  • customers;
  • channels;
  • geographies;
  • transaction activity;
  • third-party arrangements;
  • and new business lines.

An internal classification that materially understates obvious risk factors may be difficult to defend.

5. Test control effectiveness

Policies should be supported by evidence showing that controls work.

Useful testing areas include:

  • onboarding files;
  • beneficial-ownership verification;
  • sanctions alerts;
  • transaction-monitoring scenarios;
  • suspicious-activity escalation;
  • customer-risk reviews;
  • blockchain analytics;
  • agent oversight;
  • and compliance-quality assurance.

6. Prepare a group-wide risk view

The group should be able to explain how entity-level risks are consolidated.

This includes identifying:

  • the highest relevant EU parent;
  • material subsidiaries;
  • significant business lines;
  • high-risk entities;
  • shared systems;
  • outsourced controls;
  • and dependencies between regulated companies.

7. Review governance and management information

Boards and senior management should receive information that enables them to understand group-wide AML/CFT exposure.

Management information should not be limited to alert counts or filing volumes. It should explain:

  • significant risk trends;
  • control weaknesses;
  • overdue remediation;
  • staffing and capacity;
  • high-risk customer exposure;
  • jurisdictional developments;
  • and major supervisory concerns.

8. Prepare for supervisory challenge

A potentially eligible institution should be ready to explain:

  • its geographic footprint;
  • data methodology;
  • risk classifications;
  • group structure;
  • control environment;
  • and remediation programme.

Different group entities should provide consistent answers. Contradictory explanations from compliance, legal, operations and senior management can undermine confidence in the control framework.

Implications for acquisitions of regulated institutions

The AMLA selection framework is relevant to investors acquiring banks, EMIs, PIs, CASPs and other financial institutions.

A transaction may change:

  • the group’s EU footprint;
  • the identity of the highest EU parent;
  • the number of Member States in which it operates;
  • the group-wide risk score;
  • management and governance arrangements;
  • and the ability to aggregate compliance data.

Eligibility should form part of regulatory due diligence

A buyer should assess whether the target or combined group may meet the six-country test.

This requires more than reviewing regulatory permissions. The buyer may need information on:

  • active customers by jurisdiction;
  • transaction volumes;
  • passport use;
  • branches and subsidiaries;
  • sectoral risks;
  • residual-risk assessments;
  • and supervisory findings.

Control weaknesses can affect the combined group

A high-risk target may influence the group-wide score after completion, particularly where it represents a significant proportion of operations.

Buyers should examine unresolved AML/CFT deficiencies, enforcement history, monitoring backlogs, sanctions controls and dependence on key outsourced providers.

Integration planning matters

Where businesses use different customer-risk systems or transaction-monitoring platforms, post-acquisition integration can become a supervisory issue.

The buyer should establish whether group-wide reporting can be produced consistently and whether senior management can exercise effective oversight after completion.

Sensitive information about regulated-entity transactions should be shared only after appropriate KYC, NDA and Proof of Funds procedures where applicable.

How Legasset can assist

Legasset supports financial and crypto groups preparing for the EU’s new AML/CFT framework.

Our work may include:

  • AMLA eligibility and footprint assessments;
  • group-wide AML/CFT gap analysis;
  • CASP, EMI and payment institution licensing;
  • governance and MLRO support;
  • customer-risk and transaction-monitoring reviews;
  • policy development;
  • regulatory data-readiness analysis;
  • regulated-entity acquisitions;
  • post-acquisition compliance integration;
  • market-entry structuring;
  • and remediation planning.

The objective is not merely to prepare an isolated supervisory response. It is to establish a defensible group-wide framework that can withstand more consistent and data-driven EU supervision.

FAQ About AMLA Direct Supervision

Has AMLA already selected the 40 institutions it will supervise?

No. AMLA is currently collecting eligibility data. The formal selection process will take place in 2027, and direct supervision is expected to begin in 2028.

It is the date by which AMLA expects to receive relevant eligibility data from national financial supervisors.

An individual institution may have an earlier deadline set by its national supervisor.

AMLA expects the provisional list of eligible obliged entities to be finalised by the end of September 2026.

No. Inclusion means that the institution or group appears to meet the geographic eligibility criteria.

It must still undergo the risk-assessment and selection process.

The institution or group must operate in at least six EU Member States, including its home Member State, to satisfy the geographic eligibility test.

Not necessarily.

Cross-border services must meet materiality criteria. A notification to provide services may not count where the institution has no meaningful activity in the jurisdiction.

The draft methodology uses alternative thresholds based on the number of resident customers or the value of incoming and outgoing transactions generated by those customers.

AMLA’s published materials refer to the direct supervision of 40 financial institutions or groups from 2028.

The final identities will be determined through the selection process.

Yes, potentially.

A CASP may enter the eligible population where it is a financial-sector obliged entity operating in at least six Member States and receives the required high residual-risk classification.

Yes.

Cross-border EMIs and payment institutions may satisfy the geographic test through establishments and material passported activities.

No.

The institution must first meet the geographic eligibility criteria. Selection then focuses on eligible entities with high residual ML/TF risk.

Inherent risk is the exposure before controls are considered.

Residual risk is the risk remaining after the quality and effectiveness of the institution’s controls have been assessed.

No.

AMLA will directly supervise selected institutions. National supervisors will continue to supervise most obliged entities and will participate in the wider EU supervisory system.

It will normally remain directly supervised by its national competent authority.

It will still be affected by AMLA’s common methodologies, standards and supervisory-convergence work.

In specified circumstances, a national supervisor may ask AMLA to assume direct supervision of a non-selected institution.

This is an exceptional process and differs from the regular selection of 40 entities.

No.

Groups should already be validating geographic data, risk methodologies, group-wide governance and control effectiveness.

Topic-Specific Official Resources and Regulatory Materials

I. AMLA — Next step toward the 2027 selection of directly supervised entities
This announcement confirms the reporting package, the 15 August 2026 data deadline and the expected end-September provisional eligibility list.

II. AMLA — Preparations for harmonised EU AML/CFT supervision
This resource explains the common risk-assessment methodology, the selection framework and AMLA’s plan to supervise 40 high-risk institutions or groups from 2028.

III. AMLA — Final report on the draft RTS for direct-supervision selection
The report explains the six-Member-State eligibility requirement, freedom-to-provide-services materiality tests and the methodology for assessing individual and group-wide residual risk.

IV. EUR-Lex — Regulation (EU) 2024/1620 establishing AMLA
This is the founding regulation establishing AMLA’s mandate, powers, selection framework and direct-supervision responsibilities.

V. AMLA — Preparations for the 2027 selection exercise
This update covers the data taxonomy and testing work used to support the first selection process.

VI. AMLA — Data collection and calibration of risk-assessment models
The announcement explains AMLA’s testing exercise and its connection to selecting institutions for direct supervision from 2028.

VII. AMLA — Single Programming Document 2026–2028
The programming document sets out AMLA’s operational priorities, staffing plans and preparations for directly supervising 40 financial institutions.

VIII. EUR-Lex — Regulation (EU) 2024/1624 on AML/CFT obligations
The AML Regulation establishes the directly applicable substantive requirements that financial institutions and other obliged entities must follow from 2027.

Check Our Available Ready-Made Licenses

Below are all the off-the-shelf license options available for purchase. Browse through the list of licenses and read the details to choose the option that is right for your business:

How do I get other licenses?

other articles and news:

Accelerate Your Business with These Offers

Before you leave, take a moment to explore our complete list of ready-made licenses, carefully curated to meet your business needs. These licenses are your fast track to launching or expanding operations without the usual delays. Secure yours today to ensure your business is compliant and ready to thrive from day one.
Scroll to Top

Let’s Discuss Your Request

Your submission has been sent. Be in touch!
Legasset Law Company
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.