The status of every RTS, Guideline and ITS under the EU AML package, mapped onto the compliance framework. Click a block for its instruments, summary, impact and source links.
At a glance. 19 of the 19 Level-2/3 instruments are not yet definitive. The AMLR itself is final and applies in 303 days; the detailed rules are still to come. The greatest uncertainty sits in:
Status as of 9 Sept 2026. Sources: EBA, AMLA, EUR-Lex.
Framework
RTS in consultation Guideline in consultation ITS in consultation Consultation closed, being finalised RTS final, unpublished Guideline final, unpublished Published Level-1 text Dutch guidance
Strategy & Risk
Business Wide Risk Assessment / SIRAArt. 9, 10Risk Management and ControlsArt. 9, 16, 79, 80
Identification & Verification of the customerArt. 20, 22, 23, 28Identification and verification of the Beneficial OwnersArt. 20, 22, 23, 24, 28, 51 to 67Assessing the Ownership and control structureArt. 20, 28Purpose & Nature of Business RelationshipArt. 20, 25, 28Transaction profileArt. 20, 25, 28Sanctions ScreeningArt. 27, 28Politically Exposed Persons ScreeningArt. 28, 42, 43, 44, 45, 46Simplified Due DiligenceArt. 28, 33Enhanced Due DiligenceArt. 28, 34 to 41, 47
From the status of the rules to the state of your programme
The monitor above is the public part. Behind it sits a workspace for one organisation: an AI impact assessment, country-specific points, a readiness tracker with heat map, an AI consultant, consultations and a board report.
01 · Know
Know where every rule stands
One monitor for the whole AML package. Every RTS, Guideline and ITS with its status, consultation deadline, expected date, summary, impact and source, mapped onto the compliance framework and filtered for your type of organisation.
Free, no account needed
Article browser with authentic text on EUR-Lex
Daily check of EBA, AMLA, EUR-Lex and national sources
Alerts by e-mail, Slack or Teams
Public dashboard, free
02 · Assess
Understand what it means for your organisation
Describe your organisation once, or let the AI look it up and confirm it with you. You get an AMLR impact assessment: priority blocks, blocks that do not apply, the documents that matter for you, and country-specific points for every country you operate in.
AI impact assessment with document matching
Country-specific points for every EU/EEA country
AI consultant that knows your profile and progress
Follow-ups straight onto your task list
From the "Analyse the impact" plan
03 · Run
Run the programme and report on it
Track readiness per framework block with owners, target dates and notes, see it as a heat map over the framework, plan consultation responses and milestones, and print the board report when the board asks.
Readiness tracker, heat map and analysis
Consultations, roadmap and milestones
Board report, CSV exports and audit log
Team workspace with invitations and roles
From the "Monitor the programme" plan
The workspace with the framework as a readiness heat map. Statuses per block, owners and target dates feed the analysis and the board report.
Three ways to use it
Chosen when the workspace is created; an admin can change it later.
Capability
Stay informedFollow the legislation and the progress at AMLA and the EBA.
Analyse the impactEverything in Stay informed, plus the impact on your organisation and an AI consultant.
Monitor the programmeEverything in Analyse the impact, plus tracking of your whole readiness programme.
Dashboard with regulatory status, consultations and milestones
✓
✓
✓
Daily source check and what changed
✓
✓
✓
Alerts by e-mail, Slack or Teams
✓
✓
✓
Team with invitations, two-factor authentication
✓
✓
✓
Company profile with AI impact assessment
–
✓
✓
Matching documents and additional sources found by AI
–
✓
✓
Country-specific points, with AI research for any country
–
✓
✓
AI consultant and personal task list
–
✓
✓
Readiness tracker, heat map and analysis
–
–
✓
Consultation responses, roadmap and milestones
–
–
✓
Board report, CSV exports and audit log
–
–
✓
Built for
Credit institution
Payment / e-money institution
Investment firm / fund manager
Life insurer / intermediary
Crypto-asset service provider
Trust or company service provider
Football club / agent
Other obliged entity
Start with the monitor, add a workspace when you need one
Free to create. Your data is encrypted field by field, two-factor authentication is built in, and every organisation has its own workspace.
478 days until AMLA direct supervision (1 Jan 2028)
The application date is the start of supervision, not the end of the work. AMLA keeps issuing and revising Guidelines and technical standards, direct supervision starts in 2028, and the AMLR turns compliance into a standing set of recurring obligations.
Now
Prepare
Gap analysis against the AMLR text, redesign of onboarding, monitoring and reporting, and responses to AMLA consultations while the RTS, ITS and Guidelines are still being finalised.
10 Jul 2027
AMLR applies
The AMLR obligations apply directly. National supervisors (in the Netherlands DNB, AFM and BFT) supervise under the AMLD6 implementation act. First supervisory reviews test the new customer due diligence, beneficial-ownership and reporting processes.
2028
AMLA direct supervision
AMLA directly supervises the first group of around 40 cross-border financial institutions selected in 2027, through joint supervisory teams with the national supervisors. AMLA can also take over supervision of other entities in specific cases and coordinates the supervisory colleges.
10 Jul 2029
Football sector
Professional football clubs and agents become obliged entities. Institutions serving them adjust their risk assessment and due diligence.
Ongoing
Maintain
AMLA keeps issuing and revising Guidelines, Q&As and technical standards; the Commission updates the high-risk third-country list and runs the supranational risk assessment. Compliance shifts from a project to a standing register of obligations, reviews and findings.
Recurring obligations after go-live
Obligation
What it involves
Cadence
Framework blocks
Business-wide risk assessment (SIRA)
Review and update the business-wide risk assessment and the resulting policies; approve at management-body level.
At least yearly, and after material change
Business Wide Risk Assessment / SIRARisk AppetitePolicies & procedures
Periodic customer reviews
Refresh due diligence per risk class within the maximum review periods set in the RTS and Guidelines.
Per risk class (high risk yearly)
Periodic reviewClient Risk Assessment resulting in new/updated/confirmed AML/CFT risk classification
Compliance reporting to the management body
The compliance officer reports on the effectiveness of internal policies, findings and remediation; the compliance manager owns follow-up.
At least yearly
Compliance functionGovernanceManagement information & reporting
Suspicious transaction reporting
Report suspicions to the FIU in the ITS template, respond to FIU requests and suspension orders, and keep the tipping-off controls in place.
Continuous
FIU ReportingAlert handling
Training and awareness
Train staff on the AMLR obligations, typologies and internal procedures; keep records of who was trained on what.
Yearly and at onboarding
Employee Training & Awareness
Regulatory watch
Track new and revised AMLA Guidelines, Q&As, RTS/ITS revisions and Commission delegated acts, and map them to the framework blocks they change.
Continuous (this site checks sources daily)
Policies & proceduresRisk Management and Controls
Supervisory data and AMLA selection
Deliver the data used for AMLA's periodic selection of directly supervised entities and answer supervisory information requests.
Selection rounds every three years
Management information & reportingData & analytics
Record retention and data protection
Keep due-diligence and transaction records for five years after the end of the relationship, then delete them, within national data-protection practice.
Continuous
Record RetentionData & analytics
Frequently asked questions
What is the AMLR?
The AMLR is Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation. It is the "single rulebook" of the EU AML package: directly applicable customer due diligence, beneficial ownership, internal control and reporting obligations for obliged entities across the EU. It applies from 10 July 2027.
When does the AMLR apply?
The AMLR applies from 10 July 2027 (Article 90). Football clubs and agents follow from 10 July 2029. The same date, 10 July 2027, is the transposition deadline of the Sixth Anti-Money Laundering Directive (AMLD6, Directive (EU) 2024/1640).
What is the difference between an RTS, an ITS and a Guideline?
A Regulatory Technical Standard (RTS) is a binding delegated act that specifies how an AMLR article must be applied; AMLA drafts it and the European Commission adopts it. An Implementing Technical Standard (ITS) is a binding act that sets formats and templates, such as the template for reporting suspicious transactions. Guidelines are issued by AMLA on a comply-or-explain basis and set supervisory expectations without being directly binding law.
Who is AMLA?
AMLA is the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, established by Regulation (EU) 2024/1620 and based in Frankfurt. It became operational in 2025, develops the RTS, ITS and Guidelines under the AML package, and will directly supervise a first group of around 40 cross-border financial institutions from 2028.
What does "RTS in consultation" mean?
A draft RTS has been published for public consultation. Obliged entities and industry bodies can respond until the consultation closes. After that the draft is finalised, submitted to the European Commission and adopted as a delegated regulation, then published in the Official Journal of the EU.
What changes for Dutch institutions compared with the Wwft?
Most Wwft obligations are replaced by the directly applicable AMLR; the Dutch implementation act keeps national elements such as supervision by DNB, AFM and BFT, FIU-Netherlands reporting and possibly lower cash limits. Key changes include suspicion-based reporting instead of "unusual transaction" indicators, an EU-wide beneficial ownership threshold, a board-level compliance manager and harmonised enhanced due diligence.
What happens after 10 July 2027?
From 10 July 2027 the AMLR obligations apply and national supervisors review compliance under the AMLD6 implementation act. From 2028 AMLA directly supervises a first group of around 40 cross-border financial institutions selected in 2027, with new selection rounds every three years. From 10 July 2029 football clubs and agents are covered. AMLA keeps issuing and revising Guidelines, Q&As and technical standards, so compliance becomes a standing cycle of risk assessments, periodic customer reviews, reporting and training rather than a one-off project.
What can I do with AMLR Monitor?
The public dashboard shows the status of every RTS, Guideline and ITS under the AMLR, filtered by type of obliged entity, mapped onto a compliance framework with article links and "what changes" notes. The workspace (free account per organisation) adds a company profile with an AI impact assessment, a readiness tracker shown as a heat map, country-specific points for every EU country, an AI consultant that knows your organisation, consultation tracking, daily source alerts, tasks, a team, exports and a board report.
How often is this dashboard updated?
Regulatory statuses are reviewed manually and dated on the page. In addition, an automated check fetches the EBA, AMLA, EUR-Lex and DNB source pages every day and lists any new AML-related publication for signed-in users in the workspace.