Central contact points: AMLA's RTS for PSPs, EMIs and CASPs takes shape
AMLA has surveyed EMIs and PSPs on central contact points ahead of its RTS under Article 41 AMLD6. What the current rules say, what changes, and how to prepare.
Among the quieter items on AMLA's news page this quarter is a survey. In August AMLA invited electronic money institutions and payment service providers to describe their experience with the central contact point (CCP) framework that host Member States have used since 2018 to keep an eye on agents and distributors of institutions headquartered elsewhere in the EU (AMLA news item). The survey has now closed. It fed directly into a regulatory technical standard that AMLA owes under Article 41(2) AMLD6 and that, unusually, will matter more to the host country compliance set-up of payment and crypto firms than to their head offices. This article sets out where the CCP regime stands, what AMLA has to decide, and what a cross-border PSP, EMI or CASP should do before the draft arrives.
Where the regime comes from
Under Article 45(9) of the fourth Anti-Money Laundering Directive (Directive (EU) 2015/849), a Member State may require electronic money issuers and payment service providers that operate on its territory through establishments other than a branch, typically agents and e-money distributors, and whose head office is in another Member State, to appoint a central contact point. The contact point ensures, on behalf of the appointing institution, that the local network complies with the host country's AML/CFT rules and acts as a counterpart for the host supervisor and FIU.
Commission Delegated Regulation (EU) 2018/1108, drafted by the ESAs, fills in the two things the directive left open: when a host Member State may impose a contact point, and what the contact point has to do. In summary:
- Appointment criteria. A host Member State may require a CCP where an institution has ten or more establishments on its territory, where the e-money distributed and redeemed or the payment transactions executed through those establishments are expected to exceed EUR 3 million in a financial year (or did so in the previous year), or where the institution fails to provide the information needed to assess those criteria in time. The delegated regulation also leaves room for a host Member State to require a contact point where it considers the risk of the local operations to be high.
- Functions. The CCP must ensure that the establishments comply with host AML/CFT rules and must facilitate supervision, including by providing documents and information on request and by supporting on-site inspections. Host Member States may in addition require the CCP to fulfil the reporting obligations towards the host FIU on behalf of the establishments, and may attach further functions listed in the regulation.
The rules have been applied unevenly. Some Member States have never used the option, others make the CCP a fixed feature of the local payments market, and a few have effectively turned the contact point into a local compliance function with staff, systems and its own reporting to the FIU. That divergence is exactly what AMLA's survey was designed to capture, alongside a parallel survey among national competent authorities.
What AMLD6 changes
Directive (EU) 2024/1640 carries the option forward in Article 41 AMLD6, with two important adjustments.
First, the scope is extended to crypto-asset service providers. A CASP with an authorisation under MiCAR that serves customers in another Member State through establishments other than a branch may be required to appoint a contact point in that Member State. AMLA's survey did not cover CASPs, because the previous framework did not apply to them, so the crypto sector's practical input will have to come through the public consultation.
Second, the mandate for the technical standard moves from the ESAs to AMLA. Article 41(2) AMLD6 asks AMLA to develop draft RTS on the criteria for determining when the appointment of a central contact point is appropriate and on the functions of that contact point. The statutory deadline was 10 July 2026. AMLA's programming document scheduled the consultation for Q3 2026 and the final draft for Q4 2026; as of our last check no consultation paper had appeared, so some slippage into the fourth quarter is likely.
The status on the AMLR Monitor list is therefore: EBA guideline in force, AMLA successor pending. In practice this means that Delegated Regulation (EU) 2018/1108 continues to apply until the new RTS is adopted by the Commission and enters into force. An EBA amendment to the 2018 regulation still awaits adoption by the Commission, and it is not yet clear whether that amendment will be adopted at all now that AMLA is preparing the replacement.
The CCP regime sits in the directive rather than in the AMLR because it is a supervisory arrangement, not a customer-facing obligation. The obliged entity's own duties, including customer due diligence under Chapter III AMLR, the reporting of suspicions under Article 69 AMLR and the group-wide requirements of Article 16 AMLR, apply directly to the institution wherever its agents operate. The contact point is the mechanism by which the host country checks that those duties are actually performed on its territory.
The questions AMLA has to answer
The survey questions and the mandate together point to a handful of design choices obliged entities should watch for in the consultation paper.
- Thresholds. The 2018 criteria (ten establishments, EUR 3 million) predate the growth of large agent networks in remittances and the arrival of CASPs. AMLA may keep quantitative thresholds, replace them with risk indicators, or combine both. For CASPs a transaction-value threshold designed for e-money distribution does not translate well.
- Risk-based override. Whether and how a host supervisor may require a contact point below the thresholds on risk grounds, and what evidence it needs.
- Functions and reporting lines. The most contentious question in the existing regime is whether the contact point files suspicious transaction reports with the host FIU on behalf of the institution. With AMLA's draft ITS on the format for reporting suspicions (consultation closed, being finalised) moving towards a uniform EU template, and the draft RTS on cross-border information exchange between FIUs (in consultation, closing 6 October 2026) defining when a report concerns another Member State, the allocation of reporting between home and host FIU is being redrawn at the same time. Expect the CCP RTS to be aligned with those instruments rather than to decide the question alone.
- Interaction with home-host supervision. The RTS on the duties of home and host supervisors and the modalities of their cooperation (consultation closed, being finalised) will govern how supervisors share information about cross-border institutions. The CCP is a host tool; the RTS will need to say how it fits with the home supervisor's lead role.
- Proportionality for small networks. Whether an institution with a handful of agents in a Member State can meet the requirement with a designated person at head office rather than a local office.
None of these points has been settled. Until the consultation paper is published, the only firm reference remains the 2018 delegated regulation.
What it means for obliged entities
For a PSP or EMI already running contact points, the immediate effect is continuity: current appointments and host country requirements stand. The risk is in the medium term. If AMLA harmonises the criteria, institutions may find that a Member State which has never required a CCP starts doing so, or that the functions expand to include local reporting. Budget and staffing for 2027 should not assume the current footprint is final.
For CASPs the situation is new. A CASP that passports into other Member States purely through online services without local establishments will generally fall outside Article 41 AMLD6. A CASP that uses local partners, kiosks, ATMs operated by third parties or other physical distribution may be within scope, and should begin mapping those arrangements now.
For groups, the contact point also has a governance dimension. Under Article 16 AMLR the parent must ensure that group-wide policies, procedures and controls are applied across all establishments, and the compliance manager appointed under Article 9 AMLR carries responsibility for that. A contact point that reports to the host supervisor but not clearly into the group compliance function is a weakness supervisors on both sides will notice.
What to do now
- Inventory every Member State in which you operate through agents, distributors or other non-branch establishments, with the number of establishments and the annual volume per country, tested against the 2018 criteria.
- Record which host Member States currently require a contact point, what functions they have attached (in particular local FIU reporting) and how the contact point is embedded in your compliance organisation.
- For CASPs, map physical or third-party distribution in other Member States and flag arrangements that could qualify as establishments.
- Assign someone to respond to AMLA's consultation when it opens; the survey shows AMLA is actively looking for operational evidence, and the thresholds and functions are where a well-documented response can make a difference.
- Read the CCP consultation together with the draft ITS on reporting suspicions and the draft RTS on FIU information exchange, since your host country reporting lines will be shaped by all three.
- Do not dismantle or downsize existing contact points in anticipation of the new RTS. The 2018 delegated regulation applies until the successor enters into force.
The AMLR Monitor dashboard tracks the RTS on central contact points alongside the other supervisory cooperation instruments mentioned here, and will be updated when AMLA publishes the consultation paper.