AMLA Finalises Three New AML/CFT Standards for the EU Private Sector
The European Union’s Anti-Money Laundering Authority (AMLA) has finalised three sets of draft regulatory technical standards designed to establish greater consistency in how companies and professionals apply anti-money laundering and counter-terrorist financing requirements across the private sector.

The standards, announced by AMLA on 1 October 2026, focus on three key areas: identifying business relationships and occasional or linked transactions, customer due diligence, and group-wide AML/CFT arrangements, including situations involving subsidiaries and branches operating in third countries. The final draft standards have now been submitted to the European Commission for adoption. They will not become legally binding simply because AMLA has finalised and published them.
AMLA said the package is intended to provide the private sector with a common framework for implementing the EU's strengthened AML/CFT requirements. The authority developed the standards in cooperation with national supervisors and after considering feedback obtained through written consultations and stakeholder hearings.
The first set of standards, developed under Article 19(9) of the Anti-Money Laundering Regulation, deals with the distinction between an ongoing business relationship and an occasional transaction, as well as the identification of transactions that should be considered linked.
This distinction is important because an established business relationship generally brings customer due diligence and continuing monitoring obligations into operation, while occasional transactions are subject to the applicable regulatory thresholds and exceptions.
The proposed framework also addresses circumstances in which several transactions may be connected. For currency exchange, money remittance and certain crypto-asset services, three or more transactions occurring within a 12-month period are identified as an indicator of repetition when assessing whether a relationship should be treated as ongoing. A one-month period is also relevant when considering whether transactions in these sectors may be linked.
However, these indicators are not intended to operate as automatic tests. AMLA's approach requires the relevant circumstances and the definitions contained in the regulation to be considered as a whole. A transaction falling outside a particular numerical threshold or time period should not automatically be treated as unrelated, nor should the existence of repeated transactions by itself be interpreted as evidence of criminal activity.
The proposed rules envisage a broader assessment of factors that may demonstrate a connection between transactions. These may include a common origin, destination or purpose, as well as other characteristics of the transactions. Information indicating that customers are acting together, using common digital infrastructure or participating in transactions connected with the same purchase may also be relevant.
At the same time, the standards seek to avoid imposing unnecessary additional information-gathering requirements. Entities are expected to rely on information already available to them, or information that they could reasonably be expected to possess. This places greater importance on the quality and consistency of internal customer records, particularly where different business channels use separate customer-reference systems.
Customer Due Diligence Requirements
The second set of standards concerns customer due diligence and has been developed under Article 28(1) of the Anti-Money Laundering Regulation.
It establishes requirements concerning the information that obliged entities must obtain and the means through which customer information is to be verified. The approach incorporates proportionality, particularly for customers presenting lower levels of risk, rather than requiring businesses to collect the maximum possible amount of information in every case.
For natural persons assessed as presenting a lower risk, the proposed reduced information set includes details such as the customer's name, date and place of birth and nationality or relevant status information. Address information does not necessarily have to be collected and verified in such circumstances.
The standards also address beneficial ownership. Information obtained from a central beneficial ownership register is not automatically treated as conclusive evidence. The information must still be verified against information obtained from the customer or another reliable source.
Remote and non-face-to-face identification is another significant element of the draft.
AMLA's framework provides for alternative verification arrangements where an individual cannot reasonably appear in person and does not have access to qualifying electronic identification methods or relevant trust services.
Those alternative arrangements are accompanied by safeguards intended to establish the identity of the individual, protect communications, ensure adequate image or data quality and maintain appropriate records. Entities would also have to document and justify their decision to use an alternative verification method.
The proposed standards also provide flexibility concerning screening for politically exposed persons, their family members and close associates, as well as targeted financial sanctions. Screening may be carried out manually, through automated systems or through a combination of both approaches.
This flexibility means that businesses will retain responsibility for determining how their screening arrangements should operate in practice, taking account of their customer base, activities and risk profile.
Group-Wide AML Controls and Third-Country Operations
The third set of standards combines requirements under Articles 16(4) and 17(3) and concerns AML/CFT arrangements across corporate groups, including subsidiaries and branches located in third countries.
The proposed framework addresses governance, risk management, internal controls, group-wide policies, employee training, information exchange and remediation arrangements. It may also capture certain networks, partnerships and franchise structures where common ownership, management or compliance control exists.
The standards seek to ensure that relevant information concerning customers, beneficial ownership, transactions and risk can be shared effectively within a group. At the same time, information exchange must take place securely, comply with applicable data-protection requirements and be limited according to legitimate business and compliance needs.
Importantly, the framework does not remove the individual responsibility of each obliged entity. A subsidiary or other group entity remains responsible for its own customer due diligence, risk assessment and decisions, even where information is supplied through a central group compliance function.
The standards also contemplate situations in which laws in a third country prevent or restrict the application of group-wide AML/CFT requirements. In such circumstances, the relevant impediment would need to be assessed and supervisory authorities notified where appropriate.
Depending on the resulting risk, additional safeguards could include independent checks, enhanced reviews, restrictions on certain higher-risk activities or management approval requirements. Where risks cannot adequately be controlled, more significant measures could ultimately be considered, including restrictions on relationships or operations.
Standards Still Require European Commission Adoption
Although AMLA has now completed the three draft standards, the regulatory process is not yet finished. The final drafts have been submitted to the European Commission, which must adopt and publish them before they become applicable.
Under AMLA's proposed timetable, the standards would apply six months after their entry into force following adoption and publication in the Official Journal of the European Union. A specific timetable applies to football agents and professional football clubs, for which the proposed application date is 10 July 2029.
The Commission may still review or amend the drafts before adoption. Consequently, businesses can begin assessing the potential impact of the standards, but should distinguish between the current draft requirements and provisions that have become legally definitive.
The three standards are intended to work together rather than operate as isolated compliance requirements. The classification of a customer relationship or transaction can determine when due diligence is required; information obtained during due diligence feeds into the assessment of customer and transaction risk; and relevant information may subsequently need to be communicated to other entities within a corporate group.
AMLA's initiative is therefore designed to bring greater consistency to the practical application of the EU's AML/CFT framework. The authority has said the standards should strengthen prevention and detection of financial crime while maintaining a risk-based and proportionate approach.
For private-sector organisations, the publication of the final drafts provides an opportunity to review existing customer-identification procedures, transaction-monitoring processes, screening arrangements, beneficial-ownership verification and group information-sharing mechanisms before the new requirements formally take effect.
The ultimate impact of the package, however, will depend on the final versions adopted by the European Commission and on how effectively businesses translate the common regulatory expectations into day-to-day compliance decisions.
AMLA's announcement marks another significant step toward a more harmonised EU AML/CFT framework, with the three standards providing greater detail on when customer checks should be triggered, how those checks should be conducted and how AML/CFT controls should operate across corporate groups and borders.
By fLEXI tEAM





Comments