AMLR compliance checklist: what to have in place before 10 July 2027
This checklist follows the framework AMLR Monitor uses: from strategy and governance through the client lifecycle to data and reporting. Each point names the AMLR articles and the AMLA standard that adds detail. Use it as a gap analysis, then track the work in the workspace.
Governance and risk
The foundations the supervisor will ask about first:
- Compliance manager at management-body level appointed and documented, next to the compliance officer (Articles 9 and 11).
- Business-wide risk assessment updated to the AMLR risk factors and the AMLA Guidelines on it (Article 10), approved by the management body.
- Policies, controls and procedures re-mapped from national law to AMLR articles, group-wide where relevant (Articles 9, 16 and 17).
- Outsourcing reviewed: risk assessment, compliance functions and suspicious-transaction decisions stay in-house (Article 18).
Customer due diligence
What changes in onboarding and review:
- Identity data and verification methods aligned with Articles 19 to 22 and the RTS on customer due diligence (Article 28); onboarding forms and systems updated.
- Beneficial ownership determined at the 25 percent threshold and by control through other means, with the ownership and control structure documented (Articles 51 to 67).
- Enhanced due diligence triggers implemented: high-risk third countries, wealth above 50 million euro or assets above 5 million euro, crypto-asset service providers and self-hosted addresses, PEPs (Articles 29 to 47).
- Simplified due diligence only after a documented low-risk assessment (Article 33); review frequencies and event-driven reviews defined (Article 26).
Monitoring, reporting and data
The operational side:
- Transaction monitoring redesigned to detect suspicion, scenarios and thresholds documented (Articles 26 and 69).
- Suspicious transaction reporting on the EU template from the ITS, with the FIU channel and tipping-off rules in the procedure (Articles 69 to 74).
- Record retention of five years with the data-protection balance documented (Articles 77 and 78).
- Training for AML-relevant roles and integrity screening of staff (Articles 12 and 13); whistleblower protection documented (Article 15).
Prove it
A checklist is only useful when you can show it was done. Record every measure with its date, owner and evidence, and keep the printable compliance report ready for the supervisor. AMLR Monitor has a compliance log and a report built for that, next to the readiness tracker and the task list that divides the work.
Frequently asked questions
Is there an official AMLR checklist?
No. Supervisors publish expectations and AMLA publishes Guidelines, but no official checklist exists. This one follows the structure of the regulation and the AMLA work programme.
How long does AMLR implementation take?
Typically four to six quarters for a mid-sized obliged entity: a few weeks for the gap analysis, then policy, data, system and training work in parallel, with the board decisions early.
What is the first thing to do?
A gap analysis per framework block against the AMLR articles, and the appointment of the compliance manager, because most other decisions depend on that role.
Can a small organisation use this checklist?
Yes. The obligations are proportionate to size and risk, but the topics are the same; a notary office or estate agent covers them in less depth than a bank.
See the status of every AMLR rule, then what it means for you
The monitor is free. A workspace adds the AI impact assessment, country-specific points, the readiness tracker and the board report for your organisation.