The RTS on sanctions is final: how supervisors will grade and price breaches
AMLA's final draft RTS under Article 53(10) AMLD6 gives supervisors a four-step method to grade breaches and set fines. What it means for obliged entities.
On 8 July 2026 AMLA published its final draft Regulatory Technical Standards on pecuniary sanctions, administrative measures and periodic penalty payments, the instrument mandated by Article 53(10) AMLD6. The press release frames it as the first harmonised, step-by-step enforcement method for AML/CFT supervisors across the EU, and the final report sets out the text and the feedback statement. The draft has gone to the Commission for adoption as a delegated regulation. It is not binding yet, and the Commission may still amend it, but the design is now stable enough for compliance functions to work with. This article explains what the RTS does, how it fits the AMLD6 sanctioning regime, and why an instrument addressed to supervisors matters for the people who run AML programmes.
Where the RTS comes from
The mandate in Article 53(10) AMLD6 is narrow and exhaustive. AMLA had to specify three things by 10 July 2026: indicators to classify the level of gravity of breaches, the criteria to take into account when setting the level of pecuniary sanctions or applying administrative measures, and a methodology for imposing periodic penalty payments, including their frequency.
The drafting history explains why the text looks familiar. The EBA consulted on a first version between 6 March and 6 June 2025 under the Commission's call for advice and delivered its response on 30 October 2025. AMLA then reviewed the EBA text, took input from the Commission's expert group of non-financial supervisors, and ran a second public consultation from 9 February to 9 March 2026. That second round existed mainly to reach the non-financial sector, which had little visibility of the EBA process. Firms that responded to the EBA in 2025 will therefore recognise most of the structure; the changes since then are refinements rather than a new approach.
The four-step method
The RTS turns enforcement into a sequence that every supervisor must follow, whether it supervises a bank, a notary, a casino or a real estate agent. According to the final report the steps are:
- Step 1: assess gravity using a common list of indicators. The indicators include the duration of the breach, whether it was repeated or systemic, the degree of responsibility of the entity and its management, the benefit obtained, the losses caused to third parties, the level of cooperation with the supervisor, and the impact of the breach on the financial viability of the obliged entity or its group. Supervisors cannot pick and choose; the list is what all of them must consider.
- Step 2: classify the breach in one of four gravity categories, ranked by severity. The RTS describes how the indicators map to each category. The classification is the hinge of the whole system, because AMLD6 reserves pecuniary sanctions for breaches that are serious, repeated or systematic. The categories give a common answer to a question national supervisors have answered very differently: when does a shortcoming become serious enough to fine?
- Step 3: choose the response. Pecuniary sanctions, administrative measures and periodic penalty payments may be imposed separately or in combination. The RTS sets out the criteria for deciding whether a measure, a fine or both is the proportionate answer, and how the gravity category feeds into the amount.
- Step 4: set the amount and, where relevant, the periodic penalty. The RTS provides a methodology for periodic penalty payments, including their frequency, and requires the supervisor to give the party a statement of findings that justifies the payments before they start.
The RTS also contains specific provisions for natural persons who are not themselves obliged entities, notably senior management and members of the management body in its supervisory function. That matters for the compliance manager designated under Article 9 AMLR and for the compliance officer under Article 11 AMLR: personal exposure to sanctions is part of the design, and the RTS gives supervisors a common way to assess it.
What the RTS does not change
The RTS does not set the fine levels. Those remain in AMLD6 itself. The Directive sets floors for the maximum fines that Member States must make available: for legal persons at least twice the benefit derived from the breach or at least EUR 1 million, and for credit and financial institutions at least EUR 10 million or 10 percent of total annual turnover, with a separate floor for natural persons. Periodic penalty payments are capped at a percentage of average daily turnover or income and may run for a limited period only. Member States remain free to go higher, and national law will continue to define procedure, appeal and the interaction with criminal law.
What the RTS does is standardise how a supervisor moves from a finding to a number within those limits. The press release's own phrase is that "the same breach in the same circumstances leads to the same enforcement outcome, wherever it happens". For groups operating in several Member States, that convergence is the real change: a control weakness found in Lisbon and the same weakness found in Vilnius should be graded on the same indicators and land in the same gravity category.
Two further points of context. First, the RTS applies to all sectors covered by the AMLR, financial and non-financial, which is why AMLA insisted on the second consultation. Second, AMLA's own direct enforcement powers over selected obliged entities from 2028 are governed by the AMLAR rather than by this RTS, although AMLA has every incentive to apply the same logic when it becomes a supervisor itself.
Why an instrument for supervisors matters to obliged entities
It is tempting to file this RTS under "supervisor business". That would be a mistake, for four reasons.
- The indicators are a description of what makes a breach worse. Duration, repetition, systemic character, cooperation, management responsibility: each of these is something an obliged entity controls. A weakness identified by internal audit and remediated within a quarter sits in a different place on the gravity scale than the same weakness left open for two years and discovered by the supervisor.
- Publication follows sanctions. Article 58 AMLD6 requires supervisors to publish decisions imposing pecuniary sanctions, administrative measures and periodic penalty payments on their websites. Once the gravity category is a formal part of the decision, it will be visible to counterparties, correspondents and clients.
- Cooperation is scored. How a firm responds to a finding, how quickly it self-reports and how completely it remediates are indicators in step 1. Enforcement response is no longer only a legal matter but an operational one that needs a playbook.
- Management is in scope. The specific provisions for natural persons mean that the compliance manager's documented oversight, the escalation records and the board minutes are the evidence that will decide personal responsibility.
Interaction with the rest of the framework
The RTS on sanctions is the enforcement end of a chain that starts with the RTS on business-wide and customer risk assessment and the Guidelines on internal policies, procedures and controls. A supervisor grading a breach of Article 10 AMLR (the business-wide risk assessment) or Article 26 AMLR (ongoing monitoring) will look at the same documents the other instruments require you to produce. The gravity indicators will also reinforce the direct-supervision selection methodology under Article 12 AMLAR and Article 40 AMLD6, where the history of breaches is part of the residual risk picture. Separately, AMLA opened a consultation on 13 July 2026 on the risk assessment methodology for supervisors of the non-financial sector, with a public hearing on 10 September 2026 and application intended from 31 December 2028; that instrument will determine how intensively non-financial firms are supervised, and therefore how often the sanctions RTS is used on them.
What to do now
- Read the final report, not only the press release. The indicator list and the four categories are the operative content. Map them against your issue-management taxonomy so that internal findings are already described in the language the supervisor will use.
- Update the enforcement response playbook. Define who speaks to the supervisor, how a statement of findings is handled, how remediation is evidenced and how cooperation is documented. Duration and repetition are scored, so remediation timelines are now a sanctions variable.
- Close aged findings before 10 July 2027. Anything that is open at application date and later found by a supervisor will carry a duration indicator from day one of the new regime.
- Brief the management body. Explain the personal provisions for senior management and the compliance manager, and check that oversight of AML/CFT is minuted with enough detail to demonstrate responsibility was exercised.
- Check group consistency. For multi-country groups, align internal severity ratings across entities so that a breach classified as moderate in one jurisdiction is not routinely classified as serious in another by your own second line.
- Watch for Commission adoption. The delegated regulation may still change. Treat the July 2026 text as the working assumption and record where your playbook depends on it.
The AMLR Monitor dashboard tracks the RTS on pecuniary sanctions, administrative measures and periodic penalty payments, together with the AMLD6 provisions and the non-financial sector supervision RTS mentioned here, and will update their status when the Commission acts.