AMLR blog · · 7 min read

Five days left: AMLA's risk-rating RTS for the non-financial sector

AMLA's draft RTS on the risk profile of non-financial obliged entities closes on 27 September 2026. What it proposes, why it matters and how to respond.

Most attention around AMLA's supervisory risk-rating work has gone to the financial sector and the selection of institutions for direct supervision. The non-financial sector has its own instrument in the making, and its consultation is about to close. AMLA's consultation on the draft RTS on the assessment of the inherent and residual risk profile of obliged entities in the non-financial sector opened on 13 July 2026, held its public hearing on 10 September 2026 and closes on Sunday 27 September 2026. Status on the AMLR Monitor list: In consultation. This article explains what the draft does, why it concerns lawyers, notaries, accountants, tax advisers, trust and company service providers, estate agents, dealers in goods and gambling operators even though it is addressed to their supervisors, and what a response should focus on.

Where the mandate comes from

The legal basis is Article 40(2) of AMLD6 (Directive (EU) 2024/1640). Article 40 requires supervisors to apply a risk-based approach and to determine the frequency and intensity of their on-site and off-site supervision on the basis of each obliged entity's inherent and residual ML/TF risk profile. Article 40(2) asks AMLA to draft regulatory technical standards setting out the benchmarks and the methodology for that assessment and classification.

AMLA is delivering the mandate in two instruments under the same article:

  • The RTS for the financial sector, first drafted by the EBA, whose remit did not cover the non-financial sector. AMLA published the final report on 16 December 2025; the Commission's Legal Service asked for clarifications and AMLA aims to finalise it before the end of 2026. Status: Final text, awaiting publication.
  • The RTS for the non-financial sector, the subject of this consultation. Final draft scheduled for Q4 2026. Status: In consultation.

Non-financial obliged entities are supervised by public authorities or, under Article 37 AMLD6, by self-regulatory bodies such as bar associations, notarial chambers and accountancy institutes. The methodology will bind both.

What the draft proposes

According to the press release and the consultation paper, the draft sets out a common methodology that every supervisor in the EU would use to assess and classify the ML/TF risk profile of the entities it supervises. Its main design choices:

  • Two layers: inherent risk (the exposure that comes with the activity, customers, geography, products and channels) and residual risk (what remains after controls). The result is a classification into risk categories that drives supervisory frequency and intensity.
  • Activity-specific data points. A small legal practice, an estate agency and a football club face different risks, so the draft defines separate sets of data points per activity rather than one questionnaire for the whole sector.
  • A reduced set of data points for smaller entities, and an instruction to supervisors to draw on data they already hold where possible, to limit reporting costs.
  • An application date of 31 December 2028, well after the AMLR and AMLD6 apply on 10 July 2027.

AMLA asks about the methodology itself, the relevance and proportionality of the data points, the treatment of small entities, the operational feasibility of the reporting framework and the expected implementation costs. It welcomes further proposals to reduce the burden on small entities and national supervisors. The consultation uses sector-specific surveys: a respondent only completes the survey for its own activity.

Everything above is a proposal. AMLA has not published a final draft, the Commission still has to adopt the standard, and the data points and thresholds may change.

Why an obliged entity should care about a standard aimed at supervisors

Four reasons not to treat this RTS as the supervisor's problem:

  1. It decides how often you see your supervisor. Under Article 40 AMLD6 the risk category determines the frequency and intensity of inspections. An entity that lands in a higher category because its data points are incomplete or unfavourable will receive more supervisory attention.
  2. The data points become your reporting obligation. In practice the methodology means periodic data requests to obliged entities: customer numbers and types, share of non-resident or high-risk-country customers, cash volumes, high-value transactions, staff numbers, training and the state of the controls. Many small firms hold this information, but not in a form that can be extracted reliably every year.
  3. Residual risk is a score of your control framework. The controls the methodology will look at are the ones the AMLR requires anyway: internal policies, procedures and controls proportionate to your size and risk (Article 9 AMLR), the business-wide risk assessment (Article 10 AMLR), the compliance functions (Article 11 AMLR), training and awareness (Article 12 AMLR) and integrity checks on staff (Article 13 AMLR). If these are documented, the residual risk score follows; if they exist only in practice, it does not.
  4. It connects to enforcement. The RTS on pecuniary sanctions, administrative measures and periodic penalty payments (status: Final text, awaiting publication) gives supervisors a harmonised grid for grading breaches; an entity's risk category will inform how a supervisor responds to a finding.

There is also an upside: the same profession will be assessed on the same terms in every Member State, which cross-border accounting networks and law firms have long asked for.

Two points to test in your response

The definition and treatment of small entities. The draft's proportionality rests on a reduced data set for small entities. Check whether the size criterion fits your profession: a two-partner notarial office and a two-person trust and company service provider are both small, but their inherent risk and the data that says something useful about them differ. Say whether the threshold for "small" is measured in a way you can evidence.

Feasibility of the data points for your activity. Mark each data point proposed for your sector as available now, available with effort, or not available. A response that names the missing system field and offers a workable proxy is far more useful to AMLA than a general complaint about burden. Also point out where the supervisor or self-regulatory body already receives the data through membership records or annual returns, since the draft asks supervisors to use existing data first.

Alignment with your own risk assessment

The Guidelines on the business-wide risk assessment (status: Consultation closed, being finalised; final draft scheduled for Q4 2026) set out how obliged entities assess their own inherent risk and controls under Article 10 AMLR. It is reasonable to expect the inherent risk dimensions used by supervisors to mirror those in the entity's own assessment. Building the business-wide risk assessment along the same axes (customers, geography, products and services, delivery channels, plus the sanctions-evasion risk the AMLR adds) means the numbers you report and the numbers in your own assessment come from one source. Discrepancies between the two are the first thing an inspector will ask about.

Timeline

  • 27 September 2026: consultation closes.
  • Q4 2026: final draft scheduled for submission to the Commission.
  • 2027: Commission adoption as a delegated regulation, scrutiny by Parliament and Council, publication in the Official Journal; no dates fixed yet.
  • 10 July 2027: AMLR applies, AMLD6 transposition deadline.
  • 31 December 2028: intended application date of the methodology.

The first harmonised ratings will most likely rest on data from the first full year under the AMLR, so the data-gathering habits an entity forms in 2027 will show up in its first risk category.

What to do now

  • If your firm or professional body has not yet responded, complete the sector-specific survey before 27 September 2026 and concentrate on the two points above: the small-entity treatment and the feasibility of each data point for your activity.
  • Coordinate with your self-regulatory body or professional association; a consolidated response with worked examples carries more weight than a dozen individual ones.
  • Read the financial-sector final report of 16 December 2025 for the direction of travel; the structure is unlikely to differ fundamentally.
  • Start a data inventory: for each likely data point, record where the information sits, who owns it and how it is extracted. Fix the gaps in 2027, not in 2028.
  • Make the controls behind the residual-risk score demonstrable: an approved business-wide risk assessment, written policies, a named compliance officer and compliance manager, training records and integrity checks, each with a date and an owner.
  • Track the final draft in Q4 2026 so that the reporting build in 2027 targets the adopted data points, not the consulted ones.

The AMLR Monitor dashboard tracks this RTS, its financial-sector counterpart, the sanctions RTS and the Guidelines on the business-wide risk assessment, with status changes as AMLA and the Commission publish them.

Written with AI for AMLR Monitor and reviewed against the tracked instruments; not legal advice. Check the source documents linked from the dashboard before acting.

Track every RTS, Guideline and ITS as it moves.
The dashboard shows the status of each instrument mentioned here; the workspace tells your organisation what it means.