On 30 May 2024, the European Union formally adopted one of the most ambitious overhauls of its anti-money laundering and counter-terrorist financing (AML/CFT) framework in decades. The so-called EU AML Package marks a fundamental shift away from a patchwork of national transpositions and toward a directly applicable, harmonized European rulebook.
The central date to mark is 10 July 2027. That is when the core obligations of the new framework become directly enforceable. While one year may feel like ample time, the structural, operational, and cultural changes required make an early start essential.
What the Package Consists Of
The AML Package is composed of four interlocking legislative acts:
1. The AML Regulation (AMLR) – Regulation (EU) 2024/1624
This is the centerpiece of the package and the most consequential instrument for obliged entities. As a directly applicable EU regulation, it replaces the directive-based approach of previous AML legislation and eliminates the implementation gaps that arose from uneven national transposition. In Germany, for instance, the AMLR will effectively supersede large parts of the Geldwäschegesetz (GwG). The Regulation sets out a comprehensive rulebook, i. a. on customer due diligence (CDD), beneficial ownership, internal controls, and reporting obligations. It applies directly from 10 July 2027.
2. The 6th AML Directive (6AMLD) – Directive (EU) 2024/1640
Where the AMLR harmonizes the rules for obliged entities directly, the 6th AML Directive addresses the institutional and supervisory architecture within Member States. It governs national supervision, the role of Financial Intelligence Units (FIUs), access to information, and cooperation mechanisms. Member States are required to transpose this directive into national law.
3. The AMLA Regulation – Regulation (EU) 2024/1620
This regulation establishes the new EU-level supervisory authority, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), and defines its mandate, governance, and powers. More on AMLA below.
4. The Revised Fund Transfer Regulation
In addition, the revised rAMLA: Europe's New AML Watchdogules on the transfer of funds strengthen traceability requirements for payment transactions and extend the “travel rule” to transfers of crypto-assets, in alignment with FATF (Financial Action Taskforce) recommendations.
AMLA: Europe's New AML Watchdog
Perhaps the most structurally significant element of the package is the AMLA. The new authority was established by Regulation (EU) 2024/1620, with the regulation entering into force on 1 July 2025. The AMLA is headquartered in Frankfurt am Main, Germany.
The AMLA operates on two levels: direct supervision and indirect supervision through coordination. Direct supervision will apply from 1 January 2028 to a first selection of approximately 40 of the riskiest and most cross-border-active financial institutions in the EU. These are entities operating in at least six Member States that exhibit high residual AML/CFT risk. The selection process begins on 1 July 2027. Being selected means the AMLA becomes the primary AML supervisor – a significant shift for institutions previously supervised by national authorities.
Indirect supervision covers the broader landscape. The AMLA coordinates and monitors the work of national competent authorities across both the financial and non-financial sectors, issues binding technical standards, and ensures consistent application of EU rules. The AMLA can also intervene if a national supervisor fails to act. Furthermore, the AMLA plays a central role in FIU (Financial Intelligence Unit) coordination, facilitating joint cross-border analysis of suspicious transactions.
Enforcement Powers
The AMLA has an ample toolkit: it can request documents, conduct on-site inspections, interview individuals, and access IT systems and internal audit reports. Its enforcement powers include the imposition of fines of up to 2 million EUR or 1% of the annual turnover for directly supervised entities. For serious infringements, higher penalties may apply.
Who Is Affected?
A key element of the AMLR is the significant expansion of obliged entities. The familiar categories (banks, insurance companies, notaries, lawyers, accountants, real estate agents) remain, but the Regulation adds several new sectors and tightens the definition of existing ones.
Notable additions and clarifications include:
- Crypto-asset service providers (CASPs): Subject to the same CDD standards as financial institutions, with a transaction threshold for occasional transactions of EUR 1,000.
- Crowdfunding service providers and intermediaries: Newly covered by EU-level AML rules.
- Professional football clubs and agents: An acknowledgement by legislators of the well-documented money-laundering risks in professional sports.
- Traders of high-value goods, such as precious metals, gemstones, and luxury goods, as well as auctioneers.
- Non-financial mixed-activity holding companies with certain characteristics.
The AMLR’s Key Requirements Include:
Customer Due Diligence (CDD)
The Regulation distinguishes between standard, simplified (in lower-risk situations), and enhanced CDD (EDD, required in higher-risk situations). As the trigger cases for EDD are now enumerated in the Regulation, a risk-based approach alone is no longer sufficient to determine when enhanced measures apply.
Beneficial Ownership
The definition of a beneficial owner is harmonized EU-wide: any natural person holding (directly or indirectly) at least 25% of ownership, voting rights, or other ownership interest in a legal entity. Obliged entities must take reasonable measures to verify beneficial ownership information, including against the national UBO registers (e.g., in Germany: Transparenzregister).
Harmonized Cash Payment Limit
Another key element of the AMLR is the introduction of an EU-wide cash payment limit of EUR 10,000 (previously EUR 15,000 for occasional transactions). Obliged entities must carry out CDD when processing cash transactions of or higher than EUR 3,000. Member States may set a lower limit.
Internal Policies, Controls, and Procedures
All obliged entities must maintain documented internal AML/CFT policies and procedures tailored to their risk profile, including:
- A written business-wide risk assessment
- Customer risk assessments conducted at onboarding and updated on a risk-sensitive basis
- Policies on CDD, record-keeping, internal reporting, and staff training
- Designation of a compliance officer at management level
- Independent audit function for larger entities
Record-Keeping
Documents and information obtained during CDD must be retained for five years after the end of the business relationship or the date of the transaction. The retention period may be extended by national law.
Practical Outlook: Navigating the Transition
The EU AML Package is an enormous shift in how money-laundering prevention is regulated in Europe. The combination of a directly applicable single rulebook, an independent EU-level supervisor with real enforcement powers, and an expanded scope of obliged entities creates a landscape that will have a significant impact on the compliance function in many organizations.
Adjustment in Germany
The direct applicability of the AMLR means that the Geldwäschegesetz (GwG), Germany's longstanding national AML statute, will ultimately be replaced. German businesses that have built their compliance frameworks around the GwG must re-engineer them around the AMLR, which in several areas goes further.
Interaction with the EU-GDPR
The broad data collection and retention requirements of the AMLR exist in tension with the data minimization and purpose limitation principles of the GDPR. Obliged entities must ensure that personal data collected for AML purposes is documented, proportionate, and subject to appropriate retention and access controls. Regulators on both sides, AML supervisors and data protection authorities, are increasingly attentive to this intersection.
Compliance as a Strategic Asset and Why Businesses Should Act Now
In an environment where the AMLA will benchmark supervisory practices across Member States and publish sector-wide risk assessments, the quality of an organization’s AML program will increasingly be visible and consequential. Organizations with mature, well-documented, and effective programs will be better positioned in supervisory actions, M&A due diligence, and commercial relationships with business partners.
No comments