AMLR blog · · 6 min read

What changes on 10 July 2027: the AMLR in ten obligations

From 10 July 2027 the EU Anti-Money Laundering Regulation applies directly. Ten obligations that change the day-to-day work of obliged entities, with the articles and what to do now.

On 10 July 2027 Regulation (EU) 2024/1624, the Anti-Money Laundering Regulation (AMLR), starts to apply in every Member State. Unlike the directives it replaces, it does not need transposition: the same text binds a bank in Lisbon, a trust office in Amsterdam and a crypto-asset service provider in Vilnius. National law does not disappear, but it shrinks to what the Sixth Anti-Money Laundering Directive (AMLD6) leaves to Member States: supervision, the Financial Intelligence Unit, registers and sanctions.

Most of the detailed rules are still being written. AMLA, the new Authority for Anti-Money Laundering, is drafting the Regulatory Technical Standards (RTS), Implementing Technical Standards (ITS) and Guidelines that fill in the AMLR, and several of them are in or just out of consultation. That is no reason to wait: the obligations below follow from the Level-1 text itself. Here are the ten that change the most for an obliged entity, with the article to read and a first step to take.

1. A compliance manager at board level (Article 11)

The AMLR requires two roles. A compliance manager is a member of the management body responsible for implementing the AMLR; a compliance officer runs the day-to-day programme and reports to the management body at least once a year. Many firms have the second role and not the first. The compliance manager must be identifiable, must have the mandate to act, and supervisors will look for evidence that the management body actually receives and discusses the reports.

First step: name the compliance manager in the governance documents and put an annual AML report on the board calendar.

2. A business-wide risk assessment that lives (Article 10)

The business-wide risk assessment stops being a document you refresh once a year. It must be documented, kept up to date, proportionate to the business and available to the supervisor, and it drives the policies, procedures and controls of Article 9. AMLA is preparing Guidelines on how to do this; the direction is a risk assessment that changes when the business changes: a new product, a new country, a new distribution channel.

First step: map every product, customer type, country and channel to the current assessment and note where it is silent.

3. Customer due diligence with a fixed data set (Articles 19 to 22)

The AMLR spells out which identity data must be collected for natural and legal persons and how it may be verified, including through electronic identification and, in time, the EU Digital Identity Wallet. Occasional transactions trigger due diligence above fixed thresholds. The RTS on customer due diligence under Article 28 will specify the sources and the simplified and enhanced measures; the EBA consulted on the draft in 2025 and AMLA is finalising it.

First step: compare the fields in your onboarding forms and core systems with the Article 22 list.

4. A single beneficial ownership threshold (Articles 51 to 56)

Ownership of 25% or more of the shares or voting rights makes a natural person a beneficial owner, and so does control through other means. Multi-layered structures must be traced through each layer; where no beneficial owner can be found after all reasonable means, the senior managing officials are recorded, with the reason. Article 24 adds the duty to consult the register and report discrepancies.

First step: find the customers where your current threshold or method differs and plan a re-verification wave.

5. Enhanced due diligence for large private wealth (Article 34)

Customers, or beneficial owners, with wealth of at least €50 million or assets under management of at least €5 million bring enhanced measures: source of wealth, senior management approval and closer monitoring. Correspondent relationships with crypto-asset service providers (Article 37), transactions with self-hosted addresses (Article 38) and the high-risk third countries identified by the Commission (Article 29) also carry specific enhanced measures.

First step: flag the customers who meet the wealth and asset thresholds; private-banking and wealth units usually know them but rarely tag them.

6. Politically exposed persons for twelve months after office (Articles 42 to 45)

The AMLR defines the prominent public functions, requires Member States and EU institutions to publish lists of them, and keeps risk-based measures in place for at least twelve months after a person leaves office. Family members and known close associates are covered as before.

First step: check whether your PEP screening can apply a time-boxed off-boarding of PEP status instead of a manual decision.

7. Sanctions screening as part of due diligence (Article 27)

Verifying whether a customer or beneficial owner is subject to EU targeted financial sanctions becomes an explicit customer due diligence measure, at onboarding and when the lists change. For most financial institutions this is existing practice; for professional service providers and dealers in goods it is often new.

First step: confirm that screening covers beneficial owners, not only the contracting party.

8. Reporting on suspicion, on a common template (Article 69 and the ITS)

Obliged entities report to the FIU when they know, suspect or have reasonable grounds to suspect money laundering or terrorist financing. For Dutch institutions this replaces the indicator-driven unusual-transaction model of the Wwft. The ITS on the reporting template will standardise the format; transaction-monitoring scenarios calibrated to indicators will need recalibration to suspicion.

First step: list the scenarios and typologies behind your current reports and ask which of them describe a suspicion.

9. Outsourcing and reliance with hard limits (Articles 18, 48 and 49)

Tasks may be outsourced, but the business-wide risk assessment, the compliance functions and decisions on suspicious transactions may not. Reliance on the due diligence of another obliged entity remains possible, with the relying entity fully responsible. AMLA Guidelines on both are in preparation.

First step: inventory every AML task performed by a group entity or a vendor and mark the ones the AMLR keeps in-house.

10. Cash, records and group-wide rules (Articles 16, 17 and the cash limit)

Cash payments above €10,000 are prohibited for traders in goods and services, with Member States free to set a lower limit. Records must be kept for five years and then deleted, balancing the data-protection rules that apply to KYC data. Parent undertakings must roll out group-wide policies, including information sharing within the group and additional measures where a third country does not allow them.

First step: if you sell goods for cash, decide now how you will refuse cash above the limit; if you are a group, decide which group policies become mandatory for every entity.

What to do now

  • Read the Level-1 text for your entity type; the articles above are directly applicable and will not change in the RTS and Guidelines.
  • Run a gap analysis against a framework, block by block, rather than against a list of articles; the AMLR Monitor dashboard maps every instrument onto the compliance framework for exactly this purpose.
  • Follow the consultations. The RTS on customer due diligence, the RTS on the risk-assessment methodology and the Guidelines on risk factors will settle the details that matter most; responding to a consultation is the last chance to influence them.
  • Plan backwards from 10 July 2027. Data-model changes, re-verification waves and scenario recalibration take quarters, not weeks.

AMLR Monitor tracks the status of each instrument mentioned here, with source links and expected dates, and its workspace turns the framework into a readiness tracker for your organisation.

Written with AI for AMLR Monitor and reviewed against the tracked instruments; not legal advice. Check the source documents linked from the dashboard before acting.

Track every RTS, Guideline and ITS as it moves.
The dashboard shows the status of each instrument mentioned here; the workspace tells your organisation what it means.