AMLA Final RTS: CDD Data, Linked Transactions and Group-Wide Rules

RegReportingDesk card: AMLA, Anti-Money Laundering Authority, European Union

On 1 October 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) announced that it had finalised three sets of regulatory technical standards for the private sector and submitted them to the European Commission. The AMLA final RTS cover customer due diligence under Article 28(1) of Regulation (EU) 2024/1624 (the AMLR), the criteria for separating business relationships from occasional and linked transactions under Article 19(9), and group-wide AML/CFT arrangements under Articles 16(4) and 17(3). Each final report is dated 30 September 2026.

These are the Level 2 texts that turn the AMLR’s due diligence chapter and its group-wide Articles 16 and 17 into data fields, classification rules and notification clocks. They decide which address elements a customer record carries, when a third transaction within twelve months at a money remitter counts as a repetition criterion for treating a walk-in customer as being in a business relationship, which entity in a group headed outside the EU notifies its supervisor, and how many calendar days a parent has to report a legal impediment in a third country. Once adopted, each standard applies six months after entry into force. For customers already on the books, the CDD remediation clock is counted from entry into force itself.

None of it is law yet. The factsheets published with each final report say the standards remain subject to review and possible amendment by the Commission and become definitive only on publication in the Official Journal. Article numbers below refer to the final draft texts as submitted.

Related reading: The EU AML Package: The Countdown to 10 July 2027

Dates that drive AMLA final RTS implementation

Only the AMLR’s own dates are certain today; everything keyed to entry into force waits for adoption and publication.

  • 10 July 2026: the date by which Articles 16(4), 17(3), 19(9) and 28(1) AMLR required AMLA to develop these draft RTS and submit them to the Commission.
  • 30 September 2026: date of the three final reports.
  • 1 October 2026: AMLA press release stating that the final drafts have been submitted to the Commission.
  • Entry into force: the twentieth day after publication in the Official Journal. No date exists yet.
  • Application: six months after entry into force, except for football agents and professional football clubs (AMLR Article 3(3)(n) and (o)), for whom all three standards apply from 10 July 2029.
  • 10 July 2027: the AMLR applies (Article 90). The draft group-wide RTS repeal Commission Delegated Regulation (EU) 2019/758 with effect from the same 10 July 2027.
  • Existing customers: CDD records brought into line within the maximum update periods in AMLR Article 26(2), which are 1 year for higher-risk customers subject to enhanced due diligence and 5 years for all others, counted from entry into force of the CDD RTS.
  • Six months after the group-wide RTS apply: the deadline for structures that already exist: the entity identified as head of structure notifies its supervisor of that role, or the obliged entities request permission not to identify a head (Article 19 of that draft).

One pairing in that list deserves a second look. Article 18 of the draft group-wide RTS fixes the repeal of Delegated Regulation (EU) 2019/758, the current third-country standard supplementing Directive (EU) 2015/849, at 10 July 2027. Article 20 ties the new standard’s own application to entry into force plus six months. The final draft contains no provision linking the two dates.

One horizontal rulebook, with narrow sector hooks

All three standards apply to obliged entities in the financial and non-financial sectors alike. AMLA’s CDD impact assessment rejected separate instruments per sector, on the ground that AMLR due diligence requirements do not change by sector and parallel texts would mean parallel policies for firms active in both. The sector-specific provisions that survived are few:

  • Money remitters (money remittance as defined in Article 4(22) of Directive (EU) 2015/2366), bureaux de change, and CASPs providing exchange of crypto-assets for funds, exchange of crypto-assets for other crypto-assets, or transfer services (MiCA Article 3(1)(16)(c), (d) and (j)) get sector-specific repetition and linked-transaction criteria.
  • Service providers under AMLR Article 3(3)(a) to (d) and (l), meaning auditors, accountants and tax advisers, notaries and lawyers, trust or company service providers, estate agents and investment migration operators, get their own duration and repetition criteria.
  • Gambling providers get targeted criteria on voluntary membership and on games offered by the same provider; football agents and clubs get one on conditional transfer obligations.

The group-wide RTS have a different perimeter. They apply to groups as the AMLR defines them, and to structures such as networks, partnerships and franchises where two or more obliged entities share common ownership, common management or common compliance control. AMLA’s factsheet lists customer referral arrangements, shared branding arrangements and shared technical platforms, where they lack common ownership, management or compliance control, as generally outside scope. Branding alone, then, keeps a network out. Branding combined with shared audits, reviews, risk assessments or internal controls tied to that branding is one of the listed forms of common compliance control in Article 14(2)(c)(v), and that brings the network in.

Articles 7 to 9 of the same draft, on legal impediments in third countries, apply only where a parent undertaking in the Union or an obliged entity has branches or subsidiaries in third countries. A group operating only inside the EU has nothing to do under that section.

Business relationship or occasional transaction: the Article 19(9) tests

The AMLR defines a business relationship as one expected to have, or that later acquires, an element of repetition or duration (Article 2(1), point (19)). The draft RTS under Article 19(9) define an occasional transaction negatively in Article 1: a transaction, or the provision of services connected to a transaction, not carried out as part of a business relationship. Everything inside AML/CFT scope therefore lands in one box or the other. Recital 5 adds that activities outside that scope are neither, and AMLA’s consultation response gives the example of an obliged entity dealing with its own utility provider, where the obliged entity is the customer.

The horizontal criterion in Article 2(1) asks whether the customer has been granted ongoing access to services within AML/CFT scope; recital 7 adds that this includes access through a customer account. The consultation draft used online registration as the indicator, and more than sixty respondents questioned it, arguing that registration is often a technical step with no in-scope service behind it. The final text moved to ongoing access, and recital 7 says subscriptions to purely informational communications such as newsletters should not count. My reading is that a funded account with no activity still meets the duration criterion, because the test is access and the text attaches no activity condition to it.

For service providers, Article 2(2) adds a duration criterion (whether the service requires multiple actions over a substantial period) and Article 2(3) adds two repetition criteria (services at different intervals, and different services). AMLA’s response to consultation states that the two paragraphs are not cumulative.

Article 2(4) is the hard-edged one. Money remitters, bureaux de change and CASPs providing the three services listed above take into account three or more transactions within the last 12 months as a repetition criterion. Payment institutions, remittance providers and CASPs asked for value, purpose or risk qualifiers. AMLA declined, citing divergence between Member States in how these sectors identify business relationships and the elevated risks the supranational risk assessment attributes to them, and made no change to the paragraph.

Gambling providers operating from physical premises consider engagement through a voluntary membership scheme (Article 2(5)); the word “voluntary” was added after consultation. Football agents and clubs involved in a player transfer consider conditional obligations attached to the transfer (Article 2(6)).

Recital 4 cuts both ways. Meeting a criterion does not in itself establish a business relationship, and the absence of every criterion does not rule one out; the AMLR definition stays the reference.

Recital 6 settles threshold valuation for service providers. It says obliged entities that provide services connected to transactions should consider the value of the relevant transaction, excluding transaction or service fees, when applying CDD thresholds. An estate agent’s fee below EUR 10 000 does not keep the engagement below the threshold when the property price is above it.

Linked transactions and the one-month window

Linked transactions are defined in AMLR Article 2(1), point (20), as two or more transactions with identical or similar origin, destination and purpose, or other relevant characteristics, over a specific period. Article 3(1) of the draft RTS requires an overall assessment of all relevant facts and circumstances, taking into account at least a set of criteria. The ones that change system design are these:

  • Transactions performed or received by the same natural or legal person; this criterion carries no information-availability qualifier.
  • Connected customers, assessed on the basis of information available to the obliged entity: family members, business partners, customers operating in concert, subsidiaries or beneficial owners of the same parent, use of the same digital infrastructure, and common intermediaries or service providers. Recital 11 names IP address, device identifier and geolocation as examples of shared digital infrastructure.
  • Transactions relating to the same purchase; recital 12 points to a common invoice, booking number or order.
  • Transactions with identical or similar origin and destination carried out at different establishments, including through agents or remotely, and transactions within a loyalty programme.
  • Transactions performed within a short time frame, judged against the nature of the business, the speed and frequency of typical transactions and the size of the obliged entity.

Article 3(2) replaces the flexible time frame with a floor for the same three sectors: money remitters, bureaux de change and CASPs providing the listed services take into account a period of one month. Other sectors asked for fixed windows of their own during consultation, one day for gambling and twelve months for real estate among them. AMLA refused, leaving the short-time-frame judgment to each obliged entity, and kept the one-month rule unchanged. Article 3(3) adds one sector point: gambling providers take into account games provided by the same provider when assessing similar purpose.

Recital 10 limits the data burden. Obliged entities take into account information they have, or should have, access to, but are not required to obtain information solely to identify linked transactions. A notary with no view of a client’s family ties does not have to build one for this purpose.

AMLA also flagged a confusion running through the consultation responses. Linked-transaction logic decides whether occasional transactions add up to a CDD threshold. Scrutiny of transactions inside an established business relationship runs under AMLR Article 20(1)(f), on its own terms. Several comments treated the two as one exercise.

On thresholds, the final draft sets no additional lower values. The AMLR thresholds therefore remain the full list: EUR 10 000 for occasional transactions generally; EUR 1 000 for transfers of funds by credit and financial institutions other than CASPs; EUR 1 000 for CASP occasional transactions, with at least identification and verification below that value; at least identification and verification for occasional cash transactions from EUR 3 000, a rule that does not apply where a Member State caps large cash payments at EUR 3 000 or less, except for payments or deposits made at the premises of credit institutions, electronic money issuers and payment service providers (AMLR Article 19(4), referring to Article 80(4), point (b)); and EUR 2 000 for gambling winnings and stakes. AMLA says it will keep monitoring supervisory experience and developments in ML/TF risks and may reassess the issue should new evidence emerge.

What the CDD RTS fix in the customer data model

Section 2 of the Article 28(1) draft (Articles 2 to 15) sets the field-level content of a customer record. Several provisions loosened after consultation because identity documents across the EU present the same data in different ways.

Names, addresses, place of birth and nationality

  • Names (Article 2): all names, including given names and surnames, as they appear on the identity document or come through the electronic identification means. For legal entities, the legal name and, where it differs, the trade name. Recital 3 asks for trade names even where they cannot be verified against reliable sources, because they matter for screening.
  • Address (Article 3(1)): the country, as full name or ISO 3166 code; the city, municipality, town or village, with postal code where one has been issued and the state where relevant; and street name, building number, apartment number and post-box number where such information exists. For senior managing officials identified because no beneficial owner can be found, Article 3(2) allows the registered office address of the legal entity instead of a residential address.
  • Place of birth (Article 4): at least the country, state, city, municipality, town or village as it features on the document. Recital 2 asks firms that hold only a city to consider whether they need the country, for example where the city name is not unique.
  • Nationality (Article 5): reasonable measures to establish whether a person holds more than one nationality, recording every nationality declared and verifying at least one.

Article 6(1) sets the test for a document “equivalent” to an identity document or passport: it must be issued by a designated authority in accordance with the applicable law and contain names, place and date of birth, document number and expiry date, facial image and signature, and security features. Article 6(2) keeps the designated-authority condition and relaxes the data list to names, date of birth and facial image where a person cannot provide a standard document for a legitimate reason such as statelessness or refugee or subsidiary protection status. Where the document such a person provides lacks any of those three items and there are no grounds for suspicion, Article 6(2) requires the firm to obtain and verify the missing information through additional reliable and independent means.

Recital 4 deals with the passport problem directly: passports do not typically include a residential address. Where address verification is required, firms verify it from another reliable and independent source, and need not request further documents for data already verified through the passport or other identity document.

Two further provisions add structured fields. Article 9 requires credit and financial institutions to obtain and verify, for a virtual IBAN, the identity of the person using it and the virtual IBAN itself, and to ensure the information on the associated account includes its number and its opening and, where applicable, closing dates. Article 11(2), which applies to all obliged entities, lists the information to collect on each intermediate entity between a customer and its beneficial owners: legal form, any nominee directors or shareholders, jurisdiction of incorporation, governing law for trusts, shareholdings by class, and listing details where an intermediate entity is listed on a regulated market.

Ownership complexity saw one of the larger changes after consultation. The consultation draft defined complex structures and attached mandatory measures to that definition. Notaries and others objected that multi-layered structures often exist for commercial, regulatory or tax reasons. AMLA merged the two former articles into Article 11, which now lists factors that may increase complexity (number of layers, legal arrangements in the chain, registration in high-risk jurisdictions, nominees) and leaves the risk judgment to the obliged entity.

Remote onboarding: eID first, alternative solutions as a recorded fallback

AMLR Article 22(6) gives two verification routes: submission of an identity document, passport or equivalent, and electronic identification means or relevant qualified trust services under Regulation (EU) No 910/2014 (eIDAS). Recital 11 of the draft RTS reads that second route broadly: electronic identification means at assurance level “substantial” or “high” under Commission Implementing Regulation (EU) 2015/1502, whether or not notified under Article 9 eIDAS, including European Digital Identity Wallets. Article 6(4) allows these means face-to-face as well.

Article 7 covers the customer who fits neither route: someone who cannot reasonably be expected to present a document in person and has no access to compliant eID. For that case, alternative solutions are allowed if they use reliable and independent information sources and meet five safeguards: controls that the person presenting the document is its holder; confidential, integrity-protected communication; images, video, sound and data of a quality that identifies the person unambiguously; a process that stops on technical failures, interruptions or doubts; and verified information, documents and data that are valid and up to date, with copies kept time-stamped, secure and available for ex post checks. Article 7(3) requires the firm to be able to justify why the customer could not be verified through the Article 22(6) routes, and to demonstrate compliance to its supervisor.

Respondents to the consultation worried that the draft could be read as an “eIDAS-first” approach that insufficiently recognised alternative verification and onboarding methods. The final text keeps existing remote onboarding tools usable where they meet those requirements, and treats them as the exception: recital 11 says firms should be required to justify instances of verification through such tools. I read that, with Article 7(3), as a reason recorded for each customer routed to the fallback; a blanket policy statement would not show why that particular customer could not use eID.

Article 27 and Annex I list the attributes an eID means or qualified trust service must be able to deliver, mapped to the person identification data in Commission Implementing Regulation (EU) 2024/2977. The capability requirement sits with the eID means and does not oblige firms to collect every listed attribute in every case. Where an eID means lacks an attribute the AMLR requires, Article 27(2) requires the firm to obtain and verify it by other means.

Low-risk minimums, EDD content and the checklist misreading

The first issue in AMLA’s summary of CDD consultation feedback was that lists in the draft could be read as mandatory checklists. AMLA’s answer was to strengthen Article 1, which now says the extent and nature of information and measures must be proportionate to the type and level of risk, including through simplified due diligence in low-risk situations. The CDD factsheet adds that the purpose-and-nature examples should not be treated as a prescriptive checklist.

Section 5 then sets floors for low-risk situations:

  • Article 18: for natural persons, all names, place and date of birth, and nationalities (or statelessness, refugee or subsidiary protection status). Address is not part of the low-risk minimum. For legal entities, legal form, legal name and any differing trade name, registered office address, and where available a registration number, tax identification number or LEI.
  • Article 19: beneficial owners or senior managing officials may be identified from one of four sources (the central register, a business or company register, information from the customer, or a reliable independent open source) and verified using a different source from the last three.
  • Article 20: the purpose and intended nature may rest on the intended use of the product, the estimated transaction value where applicable, and the customer’s business or occupation, and may be inferred from the product or service.

Article 19 holds a trap for teams that rely on the central beneficial ownership register. In a low-risk file, the register can identify the beneficial owner. The verification route in Article 19(2) then points to a different source among those in Article 19(1)(b) to (d): a business register, the customer, or an open source. Recital 12 states the general point: central registers are a source for identification and are not sufficient on their own for verification.

AMLA did not add automatic simplified treatment for particular sectors, products or customer categories, on the ground that it would bypass the individual risk assessment in AMLR Article 20(2). The consultation draft’s simplified measures for pooled accounts left the RTS altogether; AMLA said that diversity of business models would be better handled in guidelines.

For enhanced due diligence, Articles 21 to 24 list what additional information “may include” under points (a) to (d) of AMLR Article 34(4). AMLA amended the provisions to make the obliged entity’s discretion explicit. Article 23 states the standard for source of funds and wealth, information that enables the firm to be satisfied the source is lawful, and gives examples running from tax declarations and payslips to audited accounts, property deeds and inheritance documents. Article 21(d) allows, where high risk stems from a structure’s complexity or the absence of an apparent legitimate purpose, an analysis or expert opinion on the rationale behind the structure.

PEP and targeted financial sanctions screening

Article 17 governs PEP identification. Before establishing a business relationship or carrying out an occasional transaction, the firm determines whether the customer, its beneficial owner and, where relevant, the person on whose behalf or for whose benefit a transaction or activity is carried out is a PEP, a family member or a known close associate. Article 17(1)(a) excepts the cases in AMLR Article 44: for beneficiaries of a life or other investment-related insurance policy, that check runs no later than payout or assignment of the policy. Existing customers are re-checked at a risk-sensitive frequency, and without delay when CDD information changes in a way that could affect PEP status or when the list of prominent public functions published under AMLR Article 43(5) is updated.

Article 25, which merges two articles from the consultation draft, governs targeted financial sanctions. The screened population is the customer, the beneficial owners and any persons or entities that control the customer or meet the ownership conditions in AMLR Article 20(1)(d). The data screened is names in the original alphabet and/or transliterated into the Latin alphabet, legal and differing trade names for legal persons, and where available any other names, aliases and digital wallet addresses where those appear in the sanctions lists. Screening runs at onboarding, on any change to existing targeted financial sanctions, on a new designation for credit and financial institutions, on a change in due diligence data such as name, residence, nationality, business operations or beneficial owner, and on a regular cycle whose frequency is commensurate with the exposure of the firm and of the business relationship to the risks of non-implementation and evasion of targeted financial sanctions. Screening against UN financial sanctions runs without undue delay from the moment they are made public.

Two limits matter for scoping the screening engine. AMLA did not accept proposals for a general risk-based approach to targeted financial sanctions screening, stating that compliance with targeted financial sanctions obligations cannot be made dependent on the level of ML/TF risk associated with a customer. And recital 23 places trade and economic sanctions, such as arms embargoes, trade restrictions and travel bans, outside the AMLR and the RTS. For the list-maintenance side of the same engine, see our note on EU sanctions screening and the July 2026 list refresh.

On tooling, both Article 17 and Article 25 allow automated tools, manual checks or a combination. The consultation draft was read as preferring automation; AMLA’s response says manual checks are one of the available approaches where they suit the firm’s size and business, and are not a lower standard. The firm remains responsible for ensuring that whichever method it uses detects PEP or sanctions matches in a timely and effective manner.

Existing customers: the remediation clock starts at entry into force

Article 28 of the CDD draft requires documents, data and information on business relationships established before entry into force to be brought into line with the RTS and the AMLR on a risk-sensitive basis within the periods in AMLR Article 26(2). Recital 26 says those 1-year and 5-year periods start on the date the delegated regulation enters into force. The consultation draft referred to publication in one place and application in another; respondents flagged the inconsistency, and the final text settled on entry into force.

The arithmetic matters for planning: entry into force comes six months before application, so half of the one-year window for an existing higher-risk customer passes before the RTS apply to new onboarding.

AMLA refused requests to lengthen the one-year and five-year periods, noting they are fixed in the AMLR and cannot be changed by an RTS. It also deleted the consultation draft’s separate article on updating customer information, because it largely repeated Article 26(2) AMLR without adding value.

Group-wide minimums, information sharing and third-country impediments

Article 3 of the draft under Articles 16(4) and 17(3) sets what the parent undertaking in the Union must have in place. The list covers a coordination framework giving the group compliance manager sufficient decision-making powers; group-level information for the management body, internal control and audit; conflict-of-interest controls between AML/CFT and commercial functions; a proportionate group-wide risk assessment; documented exchanges between compliance functions, management body and auditors; and group-wide whistle-blowing, incident-reporting and training policies. Article 3(2) assigns approval: group-wide policies by the management body of the EU parent in its management function, procedures and controls at least by the group compliance manager. Article 3(3) requires them in writing, up to date and available to supervisors on request.

Two consultation changes shape these minimums. The group-wide risk assessment now takes a holistic group-level view and focuses on risks with a significant impact on group exposure, including outsourcing and reliance, without a detailed assessment of every individual entity. Provisions that could have been read as imposing direct obligations on non-obliged group entities were removed.

Information sharing (Article 4) now refers to Annex I, which lists categories such as customer and beneficial owner identity data, expected transactional behaviour, sanctions verification results and material changes in risk profile. Sharing happens where relevant and on a need-to-know basis, through secure channels, with records kept so that exchanges can be traced. Article 4(3) prevents group policies from requiring parent approval before an obliged entity shares Annex I information with another, and Article 4(5) keeps each entity responsible for its own CDD and risk decisions. Article 6 disapplies the section for information referred to in AMLR Article 70(2), which AMLA’s response describes as setting the limits on information sharing for certain categories of obliged entities; the reference answers legal professional privilege concerns raised in consultation.

Where the law of a third country prevents or restricts the application of the AMLR, Article 7 sets minimum actions: inform the supervisor without undue delay and no later than 28 calendar days after identifying the impediment, naming the country and how its law restricts compliance; and ensure the branch or subsidiary requires customers and, where applicable, their beneficial owners to provide consent that overcomes the restriction, to the extent the third-country law and the AMLR allow. If consent is not feasible, the branch or subsidiary applies additional measures from Article 8, chosen on a risk basis and reported to the supervisor with an assessment of their adequacy. The Article 8 menu runs from restricting the branch to low-risk products, through refusing intra-group reliance on its CDD, enhanced reviews or audits, senior management approval for higher-risk business and enhanced monitoring, up to terminating relationships and closing or divesting operations.

Article 8(j) is a reporting line in its own right. As one of the additional measures, the parent or obliged entity requires the third-country branch or subsidiary to provide regular information to senior management, such as the number of high-risk customers with aggregated reasons for that classification, and the number of suspicious transactions identified and reported with aggregated circumstances. If the supervisor finds the measures insufficient, it requires under Article 9(1) a risk mitigation plan approved by the relevant management body, or corrective measures, within a specified timeframe. Where it determines that the risks cannot be effectively managed, or that those actions were not complied with in time, Article 9(2) requires it to exercise one or more of the actions in the last sentence of AMLR Article 17(2), which include stopping new business, terminating relationships or closing the third-country operation.

The final Section 4 is shorter than the consultation version, down from seven articles to three, and no longer lists specific impediment scenarios with a prescribed measure for each.

Parent undertakings and heads of structure: who notifies, and when

Section 5 of the group-wide draft covers groups headed outside the EU that have two or more obliged entities in the Union not in a parent-subsidiary relationship. Those entities identify one of them as the parent undertaking in the Union. Article 10 measures “sufficient prominence” by holding-company status at the highest level of consolidation under Union accounting law, the number of cross-border establishments, the average number of customers on 31 December of the two preceding years (high-risk customers in particular) and the average value of transactions, with turnover, balance sheet and headcount as tie-breakers. Article 11 measures “sufficient understanding of operations” by control over strategy, important transactions, management or internal control, and material outsourcing, with compliance-function headcount in the Union as the fallback. AMLA rejected requests to allow more than one EU parent.

Article 13 sets the procedure. The identified entity notifies its supervisor and the group’s other EU obliged entities no later than 28 calendar days after the situation arises, with a group chart, shareholdings and reasons for meeting both tests. The supervisor approves within 60 calendar days of a complete notification, or may determine that a different entity should be the parent and pass the file to that entity’s supervisor. Material changes are notified at least 28 calendar days before implementation or, in objective and extraordinary circumstances, no later than 28 calendar days after the change.

The transition is asymmetric. Under Article 13(1), obliged entities already in this situation on the day the RTS apply notify the supervisor on that date. Structures get six months under Article 19. A third-country-headed group with sister entities in two Member States therefore needs its parent-undertaking analysis finished before the application date.

For structures, Article 14(2) requires at least one of three conditions (common ownership, common management, common compliance control), and AMLA’s response confirms they operate as alternatives. Article 15 sets tiered criteria for the head of the structure: decision-making, coordination, network management and the power to exclude members first; essential services, compliance control and cost management second; size factors last. Article 16 sets the same 28-day and 60-day mechanics as for parents. Where the head is not an obliged entity, or the law prevents appointing one, Article 17 allows a supervisor to permit the structure to operate without one, provided it runs common risk-monitoring systems, minimum common policies, information sharing, and accepts supervisory monitoring, with a coordinating obliged entity as the contact point. Where an entity sits in both a group and a structure, Article 14(3) gives the group requirements priority.

One drafting point is worth checking in internal summaries written during consultation. The feedback section of the final report describes respondents’ concern about a “28-working-day” notification period. The operative articles of the final draft use 28 calendar days throughout.

The reporting footprint of the AMLA final RTS

The reporting load in the three drafts is event-driven, with no periodic return or template: the legal-impediment notifications under Article 7 of the group-wide draft, the notification of restrictions on information sharing with third-country group entities under its Article 5(4) (without undue delay and no later than 28 calendar days after identifying the restriction), and the parent-undertaking, head-of-structure and permission filings under its Articles 13, 16 and 17.

Alongside the notifications sit records a supervisor can ask to see: the justification for each instance of alternative remote verification (CDD RTS Article 7(3) and recital 11), a collective investment undertaking’s evidence that it may rely on its distributor (Article 15(2)), the written group-wide policies (group-wide RTS Article 3(3)) and the logs of intra-group information exchanges (Article 4(4)).

The classification rules also reach supervisory data. The Article 19(9) impact assessment says the criteria support the integrity and comparability of supervisory data that obliged entities report under the separate draft RTS made pursuant to Article 40(2) of Directive (EU) 2024/1640 and Article 12(7) of Regulation (EU) 2024/1620, including the number of customers and occasional transactions, and that comparable data is needed for AMLA to identify entities eligible for direct supervision. My reading is that a firm which reclassifies walk-in remittance customers as business relationships under the three-in-twelve-months criterion will see its customer counts move in those submissions. For the data collection itself, see our guide to AMLA risk assessment data collection for the 2027 selection exercise.

A build sequence that follows the final text

Because the Commission can still change details, the work most likely to survive amendment is a mapping that ties each system change to an article number. The order below is my reading of the dependencies; AMLA has published no implementation sequence.

  1. Customer data model against Articles 2 to 5 and 9 to 11 of the CDD draft, the low-risk floors in Articles 18 to 20, and Annex I.
  2. Classification and aggregation rules against Articles 2 and 3 of the Article 19(9) draft, set per business line.
  3. Screening configuration against Articles 17 and 25, including the change-driven triggers.
  4. Remote onboarding routing against Article 7, with a reason code captured for every fallback case.
  5. A group inventory: third-country branches and subsidiaries with known legal impediments, any structure meeting an Article 14(2) condition, and the Articles 10 to 12 analysis for groups headed outside the EU.

For cross-border groups, the supervisory side of the same picture is covered in our guide to the AMLA home-host cooperation RTS.

Frequently Asked Questions

Does the one-month linked-transaction window apply to a CASP’s custody business?

A custody-only CASP falls outside Article 3(2), which applies to obliged entities providing the services in MiCA Article 3(1)(16)(c), (d) and (j): exchange of crypto-assets for funds, exchange for other crypto-assets, and transfer services. Custody and administration is point (a) and is not listed, so that CASP falls back on the general short-time-frame criterion in Article 3(1)(e). For a CASP that also offers exchange or transfers, Article 3(2) attaches the one-month floor to the obliged entity providing those services and does not confine it to those service lines.

Do we screen the person acting on behalf of a customer against targeted financial sanctions lists?

Article 25(1) requires it only where there is a suspicion of circumvention or evasion of targeted financial sanctions. The standing screening population is the customer, the beneficial owners and those who control or meet the ownership conditions in AMLR Article 20(1)(d). Respondents had asked whether the consultation text went beyond the AMLR on this point; AMLA kept the provision unchanged as consistent with Level 1.

Can a fund rely on its distributor instead of identifying the final investors?

Article 15 allows a collective investment undertaking that distributes through a credit or financial institution acting in its own name to meet AMLR Article 20(1)(h) through that institution if four conditions hold: the institution is subject to EU or equivalent AML/CFT rules, it is effectively supervised, the relationship is not high risk, and the fund is satisfied the institution applies risk-sensitive controls to its own customers. The fund must be able to demonstrate this on request. The consultation draft also required the intermediary to hand over final-investor identification data without undue delay; AMLA removed that requirement to avoid an implied look-through obligation.

Can an e-money issuer use the Article 26 risk factors to grant itself a CDD exemption?

No. The exemption in AMLR Article 19(7) is a supervisor’s decision, and only where all four statutory conditions are met, including a non-reloadable instrument storing no more than EUR 150. Article 26 of the CDD draft lists the factors supervisors consider when deciding how far that exemption extends, such as transaction limits, limited duration, geographic reach, geofencing and IP controls, merchant monitoring and detection of bulk purchases. AMLA dropped two factors after consultation: issuance charges, and funding from accounts held with EEA-regulated institutions.

What happens if two supervisors disagree on which entity is our parent undertaking in the Union?

Article 13(3) of the group-wide draft lets the supervisors refer the matter to AMLA and request its assistance under Article 33 of Regulation (EU) 2024/1620 for the financial sector or Article 38 for the non-financial sector. That route does not apply where the identified entity is a selected obliged entity under AMLA’s direct supervision.

A customer onboarded by video identification years ago: does the file need re-verification once the RTS apply?

The final draft contains no specific re-verification trigger for files opened with remote tools. Article 28 brings existing files into line on a risk-sensitive basis within the AMLR Article 26(2) periods counted from entry into force, and recital 11 lets firms keep using existing remote onboarding tools that meet the Article 7 safeguards, case by case, where the customer cannot be verified through either Article 22(6) route. My reading is that the existing file is reviewed within the normal update cycle, and that a fresh verification is needed where the original method or the data captured falls short of the final requirements.

Key Takeaways

  • Anchor the existing-customer plan to entry into force of the CDD delegated regulation, twenty days after Official Journal publication; the application date six months later is the wrong anchor.
  • Money remitters, bureaux de change and CASPs providing exchange or transfer services can set stricter classification and aggregation parameters than the Article 19(9) draft, and none looser than its stated floors.
  • A natural-person customer in a low-risk file can be onboarded without an address; the beneficial owner in that file still needs two different sources.
  • Remote verification through an alternative solution, for a customer who cannot reasonably be expected to present an identity document in person and has no compliant eID, must be justifiable under Article 7(3); recording the reason for each customer routed to the fallback is my reading of how to evidence that.
  • AMLA rejected a general risk-based approach to targeted financial sanctions screening, so a customer’s ML/TF risk level does not decide whether it is screened. Under Article 25(2), the choice of automated tools, manual checks or both follows the nature of the firm’s business, its risks and complexity, and its size; the regular re-screening frequency follows the exposure of both the firm and the business relationship to the risks of non-implementation and evasion of targeted financial sanctions. Scope the match data for original scripts, aliases and wallet addresses accordingly.
  • Groups headed outside the EU with two or more obliged entities in the Union that are not in a parent-subsidiary relationship have no grace period for the parent-undertaking notification.

Sources and References

What to have ready before the Commission adopts the AMLA RTS

The Commission now holds the three drafts, and the only fixed dates around them are 10 July 2027, when the AMLR applies and the draft group-wide RTS would repeal Delegated Regulation (EU) 2019/758, and 10 July 2029 for football agents and clubs. The date that will start the existing-customer remediation clock is the entry into force of the CDD delegated regulation, twenty days after Official Journal publication. The artefact to have ready by then is a field-by-field gap list against Articles 2 to 5, 9 to 11 and 18 to 20 of the CDD draft and its Annex I, with the higher-risk customer population already identified for the one-year window.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • SRB Resolution Reporting: RESOL 1 and RESOL 2 Under the New ITS

    Report Library › Prudential ReportingFor the 2026 collection cycle, the Single Resolution Board is retiring the resolution templates that banks have filed for the best part of a decade. From this cycle, the SRB’s annual resolution-planning collection uses two reporting modules, RESOL 1 and RESOL 2, built on the revised Implementing Technical Standards in Commission…

  • FATF Terrorist Financing on Social Media: What AML Teams Should Check

    On 26 June 2026 the Financial Action Task Force published a report on terrorist financing through social media, instant messaging applications and streaming platforms, and it lands with an uncomfortable number attached. Fewer than 30% of jurisdictions contributing to the FATF report said that this risk was covered in their national risk assessments. That national-level…

  • AMLA Direct Supervision: How Luxembourg Entities Are Identified for the 2027 Selection

    Updated July 2026In this guideWhat the CSSF announced, and what it did notThe eligibility gate: a cross-border footprint, not sizeHow risk classification turns eligibility into selectionEligible, selected, and under AMLA direct supervisionThe timeline that drives the data workFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesWhere the next decision really sitsIf a Luxembourg credit institution or financial…

  • EPC Delays SEPA Structured Address Migration: Revised Timeline

    On 9 September 2026 the European Payments Council (EPC) removed the fixed end date it had set for unstructured customer addresses in SEPA payments. Its Payment Scheme Management Board (PSMB) decided to delay the 15 November 2026 sunset of the unstructured address format across all five EPC payment scheme rulebooks, and support for unstructured addresses…

  • AMLA Home-Host Supervisory Cooperation: Final RTS and Group Data Flows

    AMLA home-host supervisory cooperation moved from consultation to final draft on 1 October 2026, when the Authority for Anti-Money Laundering and Countering the Financing of Terrorism published its final report on the regulatory technical standards (RTS) mandated by Article 46(4) of Directive (EU) 2024/1640 (AMLD). The draft delegated regulation fixes what the AML/CFT supervisor of…