Comply-or-explain: how AMLA guidelines bind supervisors and obliged entities
AMLA guidelines are not law, but they are not optional either. What Article 54 AMLAR means for supervisors and firms, and how to handle the 'final, unpublished' pipeline.
Cet article n'est pas encore disponible dans cette langue ; l'original anglais est affiché. La traduction suit automatiquement.
More than a dozen AMLA guidelines now sit in the status 'final, unpublished' on the AMLR Monitor dashboard, two more are in or just out of consultation (business-wide risk assessment, and ongoing monitoring under Article 26(5) AMLR), and the first tranche of RTS is with the Commission. A question we hear every week from MLROs and legal counsel is deceptively simple: what is the legal force of an AMLA guideline? Can a supervisor fine us for not following one? Can we deviate if we document why? This article sets out the mechanism in Article 54 of the AMLA Regulation (Regulation (EU) 2024/1620, AMLAR), how it differs from the RTS and ITS, and what it means for the way you build your AMLR programme between now and 10 July 2027.
Three layers, three degrees of bindingness
The AML package uses the familiar EU financial-services hierarchy, and it pays to keep the layers apart:
- Level 1: the AMLR itself. Directly applicable in every Member State from 10 July 2027, no transposition. Breaches are breaches of law and are sanctionable under AMLD6 as transposed nationally.
- Level 2: regulatory technical standards (RTS) and implementing technical standards (ITS). AMLA drafts them under Article 49 and Article 53 AMLAR, the Commission adopts them as delegated or implementing regulations, and once published in the Official Journal they are binding law in exactly the same way as the AMLR. The RTS on CDD under Article 28 AMLR, the RTS on risk assessment, and the ITS on the common STR template all belong here.
- Level 3: guidelines and recommendations under Article 54 AMLAR. These are not adopted by the Commission and are not published as regulations. They are adopted by AMLA's General Board and published on amla.europa.eu. Their force comes from the comply-or-explain mechanism described below, not from direct legal effect.
The practical consequence: a firm can be sanctioned for breaching Article 26 AMLR (ongoing monitoring). It cannot, strictly, be sanctioned for 'breaching' the guidelines on ongoing monitoring. But it can be found in breach of Article 26 because it failed to do what the guidelines describe as the way to meet Article 26, and it will have to explain why its alternative approach was equally effective.
What Article 54 AMLAR actually says
Article 54 AMLAR gives AMLA the power to issue guidelines addressed to all supervisory authorities, all FIUs or all obliged entities, and recommendations addressed to one or more of them, with the aim of establishing consistent supervisory and FIU practices and ensuring uniform application of Union law. Three features matter for obliged entities.
First, the 'every effort' duty. Supervisory authorities, FIUs and obliged entities 'shall make every effort to comply' with guidelines and recommendations. This is the same wording used for the EBA, ESMA and EIOPA since 2011, and it has a settled meaning in supervisory practice: the guideline is the default; you are not forbidden from doing something else, but the burden of showing that your alternative is at least as effective is on you.
Second, the supervisor-level comply-or-explain. Within two months of the issuance of a guideline, each supervisory authority and FIU must confirm to AMLA whether it complies or intends to comply. If it does not, it must state its reasons, and AMLA publishes the fact of non-compliance and may publish the reasons. In EBA practice this produced public compliance tables showing, per Member State, 'complies', 'intends to comply' or 'does not comply'. We expect AMLA to follow the same approach; it has not yet published a compliance table for any guideline, so treat this as expectation rather than fact for now.
Third, the entity-level reporting hook. Where a guideline so provides, obliged entities may be required to report, in a clear and detailed way, whether they comply with it. The EBA rarely activated this clause. Whether AMLA will use it, for example for directly supervised entities from 2028, is not yet known.
Article 54 also requires AMLA, where appropriate, to run public consultations and analyse costs and benefits before issuing guidelines, which is why the BWRA and ongoing monitoring texts went through consultation papers and public hearings this year (see the ongoing monitoring consultation page).
How a guideline reaches you in practice
The route from AMLA's General Board to your procedures manual usually has three steps, and each adds a degree of bindingness.
- AMLA publication. The guideline is adopted in English, then translated into all official EU languages. In EBA practice the two-month comply-or-explain clock started on publication of the translations, and the application date stated in the guideline was set with that in mind. Most AMLR guidelines in the current pipeline are expected to apply from 10 July 2027, in step with the Regulation.
- National supervisor adoption. Your supervisor confirms compliance and typically incorporates the guideline into its own supervisory expectations: DNB's guidance in the Netherlands, BaFin's Auslegungs- und Anwendungshinweise in Germany, the CBI's AML guidelines in Ireland, and so on. Some Member States go further and give guidelines quasi-legal status by reference in national regulations or circulars. Once that happens, the guideline is, for you, indistinguishable from a national rule.
- Supervisory examination. Inspection programmes, questionnaires and on-site reviews are built around the guidelines. The 'every effort' standard becomes, in practice: show us where your framework follows the guideline, and for every deviation show us the analysis and approval that supports it.
For the roughly 40 entities that AMLA will directly supervise from 2028, step 2 falls away. AMLA will apply its own guidelines directly, and the joint supervisory teams will use them as their examination baseline.
The EBA legacy and the 'final, unpublished' pipeline
Two points of transition need care.
The existing EBA AML/CFT guidelines (risk factors EBA/GL/2021/02, policies and procedures EBA/GL/2022/05, remote onboarding, de-risking, compliance officer, and others) did not lapse when the EBA's AML mandates transferred to AMLA in January 2026. They continue to apply under the current AMLD4/AMLD5-based national laws until they are repealed or replaced. Several of the AMLA guidelines listed as 'final, unpublished' are explicit successors, and their publication will normally include a repeal or replacement clause with a date. Until that date you are still assessed against the EBA text.
'Final, unpublished' is a status we use for guidelines that have completed consultation and, as far as we can tell, internal adoption, but for which the final text and translations are not yet on the AMLA website. Do not treat consultation-paper drafts as the final word. Content did move between consultation and final in the EBA era, sometimes materially (thresholds, examples, transitional relief). Build your gap analysis on the draft, flag every requirement as 'draft', and plan a re-baseline when the final text lands.
Deviating from a guideline: how to do it defensibly
Deviation is lawful. Unexplained deviation is where firms get hurt. If you conclude that a guideline provision does not fit your business model, or that you have a more effective way of meeting the underlying AMLR article, the file should contain:
- the AMLR article the guideline elaborates (for example Article 10 for the BWRA, Article 26 for ongoing monitoring), and a statement of how your approach meets that article;
- the specific paragraph of the guideline you deviate from, and why (proportionality, sector specifics, technology, group structure);
- evidence that your alternative is at least as effective: testing results, back-testing, peer benchmarks;
- approval by the compliance manager at management body level under Article 11 AMLR, and a review date;
- where your supervisor has published its own position on the point, a note of how your deviation squares with it.
This is also where proportionality lives. Several guidelines in the pipeline include lighter expectations for smaller or lower-risk obliged entities. Proportionality is not a general licence to do less; it is a documented judgement that a specific measure is not warranted given a specific risk profile, and the BWRA is where that judgement must be visible.
What to do now
- Maintain a single register of Level 3 instruments relevant to your entity, with status (consultation, final unpublished, published, applicable), the AMLR article each elaborates, the expected application date, and the EBA guideline it replaces.
- Map every guideline paragraph to a control or procedure. Where the mapping is 'not applied', record the deviation rationale in the format above now, not when an inspector asks.
- Watch two things after each publication: the application date in the final text, and your national supervisor's comply-or-explain response and any accompanying circular. The second often adds national colour that the AMLA text does not have.
- Keep the EBA guidelines in your control framework until the replacement clause in the corresponding AMLA guideline takes effect.
- If you responded to the BWRA or ongoing monitoring consultations, compare the final text against your response when it appears; where AMLA did not take your point, your deviation file should acknowledge that the issue was considered and rejected at EU level.
- For cross-border groups, note that Article 54 comply-or-explain is per supervisor. A guideline your home supervisor complies with may be one that a host supervisor has declined; your group-wide policies under Article 16 AMLR should be built on the guideline text, with host-country deviations documented separately.
The AMLR Monitor dashboard tracks each guideline discussed here through consultation, adoption, publication and application date, alongside the RTS and ITS they sit next to.