AMLA Central Contact Point Survey: The 15 September Deadline for PSPs
On 6 August 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) opened a voluntary survey asking electronic money institutions (EMIs) and payment service providers (PSPs) about their experience with the central contact point framework, and the window closes on 15 September 2026. The CSSF relayed the exercise to the Luxembourg market in a communique of 21 August 2026. The AMLA Central Contact Point survey is a voluntary feedback exercise, yet the responses will shape the regulatory technical standards AMLA has to draft under the 2024 anti-money laundering package, so the firms most exposed to a future central contact point requirement are exactly the ones that should read it now.
The survey targets a specific population: EMIs and PSPs that operate in a host Member State through non-branch establishments (which may include qualifying agent or distributor arrangements), while keeping their head office in another Member State. That cross-border model is the whole reason the central contact point exists. A firm running distribution networks across several Member States can already be required to appoint a contact point in some of them, and the criteria that decide when that happens are precisely what AMLA is now reviewing.
Related reading: AMLA home-host supervisory cooperation RTS.
Key dates for the central contact point survey
- 6 August 2026: AMLA published the survey and opened the response window.
- 21 August 2026: the CSSF published its communique relaying the survey to Luxembourg EMIs and PSPs.
- 15 September 2026: the survey closes. Responses are voluntary.
- 30 December 2024: crypto-asset service providers were brought within the Article 45(9) central contact point option by the recast Transfer of Funds Regulation, Regulation (EU) 2023/1113.
- 10 July 2027: Regulation (EU) 2024/1624, the AML single rulebook, becomes applicable, alongside the transposed Directive (EU) 2024/1640.
What AMLA is asking, and what the survey is not
AMLA invites EMIs and PSPs, on a voluntary basis, to provide feedback on their experience with the current central contact point framework, including how the arrangements work in practice, how effective they have been and operational challenges institutions have encountered. In parallel, AMLA is running a separate survey for national competent authorities to capture the supervisory side of the same questions. After the window closes, AMLA has said it will publish a report setting out the main findings.
This is a voluntary feedback exercise that AMLA describes as preparatory work for the forthcoming Article 41(2) RTS, rather than a regulatory reporting return. The survey notice does not itself amend the current central contact point obligations. The value of responding is upstream of any filing: a firm that has lived with the appointment thresholds and the host-state supervision requests can put concrete operational evidence in front of the authority that will write the successor standards. A firm that stays silent lets other respondents define what “workable” looks like.
The population also has a hard edge. Crypto-asset service providers are outside this exercise, even though they now sit within the same primary-law provision, because the technical standards being reviewed never applied to them. More on that boundary below.
The central contact point requirement the survey is testing
The legal anchor is Article 45(9) of Directive (EU) 2015/849, the Fourth Anti-Money Laundering Directive. It gives Member States an option: they may require electronic money issuers, as defined in Article 2, point (3), of Directive 2009/110/EC, and payment service providers, as defined in Article 4, point (11), of Directive (EU) 2015/2366, that are established in their territory in a form other than a branch and whose head office is in another Member State, to appoint a central contact point in that territory. The contact point ensures, on behalf of the cross-border entity, compliance with AML/CFT rules and supports supervision, including by giving supervisors documents and information on request.
Two features of that text do a lot of work. First, it operates as a Member State option rather than a directly applicable duty: whether a contact point is required at all depends on the host state having exercised the power and on the firm crossing the relevant threshold there. Second, current Article 45(9) and Delegated Regulation (EU) 2018/1108 apply where the EMI or PSP is established in the host Member State in a form other than a branch. Agent or distributor arrangements are relevant where they amount to such an establishment; the current RTS expressly excludes services provided without an establishment from its appointment framework. Our overview of the payment-institution and e-money perimeter under PSD3 for payment institutions and electronic money sets out how those distribution structures are defined.
Article 45(10) required the European Supervisory Authorities to develop draft technical standards on the criteria for the appointment and the functions of the contact point, and Article 45(11) delegated power to the Commission to adopt them. That is the chain the current survey sits on top of.
When a host Member State can require a contact point
The criteria live in Commission Delegated Regulation (EU) 2018/1108 of 7 May 2018, the regulatory technical standards supplementing Directive (EU) 2015/849. Article 3 sets out when a host Member State may require a firm to appoint a contact point. The two headline triggers are quantitative. A host state may impose the requirement where the number of a firm’s establishments in its territory is 10 or more, or where the cumulative amount of electronic money distributed and redeemed, or the cumulative value of payment transactions executed by those establishments, is expected to exceed EUR 3 million in a financial year or exceeded EUR 3 million in the previous financial year.
Those are not the only routes. Article 3(1)(c) also covers failure to make the information needed to assess the quantitative criteria available to the host competent authority on request and in a timely manner. Separately, Article 3(2) permits a host Member State to require categories of EMIs or PSPs to appoint a contact point where that is commensurate with the ML/TF risk associated with their establishments. Article 3(4) permits an individual institution to be required to appoint one in exceptional cases where the host Member State has reasonable grounds to believe that its establishments present a high ML/TF risk. The quantitative criteria are therefore not a safe harbour.
This arrangement is a patchwork by design. Because appointment is a host-state option applied against host-state activity, the same firm can face a contact point requirement in one Member State and none in the next, with the EUR 3 million count and the 10-establishment count measured state by state. A group AML function that treats “central contact point” as a single yes-or-no answer for the whole EU footprint will misread its own obligations. The honest map is a country-by-country grid of establishment counts and transaction values.
What the contact point actually has to do
Appointment is only the start; the functions are where the operational load sits. Delegated Regulation (EU) 2018/1108 splits them across three articles. Article 4 covers ensuring compliance: the contact point supports the development and implementation of AML/CFT policies at the establishments, monitors their compliance, keeps the head office informed of breaches, ensures corrective action is taken, and represents the firm before the host authorities. Article 5 covers supporting supervision: representing the firm, giving competent authorities access to information held at the establishments, responding to their requests, and helping with on-site inspections.
Article 6 is the one that changes the job description. A host Member State may, in addition, require the contact point, on behalf of the appointing EMI or PSP, to file reports pursuant to Article 33(1), respond to FIU requests concerning the activity of the covered establishments and provide relevant information, and scrutinise transactions to identify suspicious transactions. Whether the additional Article 6 functions apply is a host-state choice. However, Article 4(f) already requires an appointed contact point to represent the EMI or PSP in communications with the host-state competent authorities and FIU. Article 6 may add three further functions: filing reports under Article 33(1), responding to FIU requests and providing relevant information, and scrutinising transactions to identify suspicious transactions. In Luxembourg, suspicious-operation reporting to the CRF is carried out through goAML. The Article 6 functions therefore add reporting and transaction-scrutiny responsibilities; they do not create the contact point’s FIU communication role.
Supervision does not stop at the contact point either. Article 48(4) of Directive (EU) 2015/849 lets the host-state authority, when supervising establishments of the kind covered by Article 45(9), take appropriate and proportionate measures to address serious failings that need immediate remedy. Those measures are temporary and must be terminated when the identified failings are addressed, including with the assistance of or in cooperation with the competent authorities of the home Member State. Article 48(4) provides for assistance or cooperation with the competent authorities of the home Member State; it does not state that this authority-to-authority cooperation must run through the central contact point.
The crypto boundary that keeps CASPs out of this survey
Crypto-asset service providers are now inside the Article 45(9) universe. Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation, replaced Article 45(9) so that it also covers crypto-asset service providers established in a host territory other than as a branch with a head office in another Member State, with Member States applying that change from 30 December 2024. On the face of the primary law, a cross-border CASP can therefore be required to appoint a contact point on the same logic as an EMI or PSP.
So why does AMLA leave CASPs out of this survey? Because the instrument under review, Delegated Regulation (EU) 2018/1108, predates crypto in this context and never set criteria or functions for CASPs. AMLA’s own statement is that crypto-asset service providers are not included in the exercise as the previous framework did not apply to them. The exclusion concerns this EMI and PSP evidence-gathering exercise; it does not create a separate successor-RTS track for CASPs. Article 41(1) of Directive (EU) 2024/1640 expressly includes electronic money issuers, payment service providers and crypto-asset service providers, and Article 41(2) mandates the RTS setting the criteria for appointment and the functions of central contact points under that paragraph. A CASP should therefore not treat this particular survey as its feedback exercise, but it remains within the scope of the Article 41 successor framework.
Central contact points: how the AML framework and PSD2 regime differ
There is a separate central contact point regime in EU payment-services law. Article 29(4) of Directive (EU) 2015/2366 (PSD2) allows a host Member State to require a payment institution operating through agents under the right of establishment to appoint a central contact point, and Article 29(5) mandated the EBA to develop the criteria and functions. Those standards were adopted as Commission Delegated Regulation (EU) 2020/1423, which is the binding current RTS. For electronic money institutions, the PSD2 supervisory provisions apply mutatis mutandis under Article 3 of Directive 2009/110/EC, but Article 3(4) expressly excludes PSD2 Article 29(4) and (5) when an EMI distributes or redeems electronic money through persons acting on its behalf; an EMI may separately provide payment services through agents under Article 3(5). The PSD2 contact point concerns payment-services supervision rather than the AML/CFT functions governed by Delegated Regulation (EU) 2018/1108.
The AML and PSD2 central contact point regimes have distinct legal bases and functions. A firm may be subject to both regimes, but the EU provisions reviewed here do not state that the two roles must be performed by different persons or entities. A firm should therefore test each host state’s implementation and ensure that any arrangement satisfies each applicable regime separately; it should not assume either that an AML appointment automatically satisfies PSD2 or that separate staffing is mandatory. AMLA’s current survey concerns the AML central contact point framework. Our note on Wolfsberg guidance for non-bank PSPs covers the wider AML governance expectations that sit around this role for payment firms.
Where this is heading under the 2024 AML package
The survey is backward-looking in its evidence and forward-looking in its purpose. AMLA has framed it as preparatory work for the regulatory technical standard under Article 41(2) of Directive (EU) 2024/1640. Article 41(2) required AMLA to develop and submit the draft RTS to the Commission by 10 July 2026. That Level 1 date has passed: AMLA’s current 2026 planning schedules the consultation phase for Q3 2026 and the final draft for Q4 2026, while its 6 August survey notice still describes the RTS as upcoming.
That matters because the whole AML rulebook is being rebuilt around it. Regulation (EU) 2024/1624, the directly applicable AML regulation, becomes applicable on 10 July 2027, and AMLA itself was established by Regulation (EU) 2024/1620. The central contact point standards drafted off the back of this survey will land inside that new architecture. Our explainer on what the AMLR changes traces how the single rulebook reshapes obliged-entity obligations more broadly, and our coverage of AMLA direct supervision of obliged entities explains how AMLA’s supervisory reach is being built alongside its standard-setting role.
No successor RTS under Article 41(2) has been adopted yet. As of publication, Delegated Regulation (EU) 2018/1108 remains in force and its Article 3 criteria remain the current criteria for EMIs and PSPs. The survey should therefore be read as preparatory work for the future framework, not as an amendment of the rules currently in force.
What to do before the window closes
For current-law mapping, build a host-state grid covering non-branch establishments, the Article 3 criteria under Delegated Regulation (EU) 2018/1108, and whether a central contact point is already required or appointed. Separately capture agent, distributor and other infrastructure models because Article 41(1) of Directive (EU) 2024/1640 expressly brings those models into the future framework in specified circumstances. Do not assume that the successor RTS will retain the current 10-establishment or EUR 3 million criteria: those successor criteria have not yet been adopted.
The deciding is whether to answer. A firm with real friction to report, thresholds that produce odd results, host-state Article 6 functions that duplicate home-state controls, or supervision requests that arrive through unclear channels, has a direct interest in putting that on record before AMLA drafts the successor standard. Responses go to AMLA on a voluntary basis through the survey published on its website, and the window shuts on 15 September 2026.
Frequently Asked Questions
Does responding to the AMLA survey create any obligation for our firm?
No. Participation is voluntary, and the survey gathers feedback without creating a reporting return. It does not register your firm, trigger an appointment, or create a filing duty. The substantive obligations remain those in Article 45(9) of Directive (EU) 2015/849 and Delegated Regulation (EU) 2018/1108, unchanged by the survey.
Our head office and our agents are in the same Member State. Are we in scope of the contact point requirement?
The Article 45(9) contact point is a cross-border mechanism. It applies to firms established in a host territory other than as a branch while their head office is in another Member State. A purely domestic footprint, where head office and establishments sit in one Member State, does not engage it.
We operate in the host state through a branch. Does the contact point apply?
Article 45(9) is written for establishments in forms other than a branch. A branch therefore falls outside this central contact point provision. Agent or distributor arrangements fall within the current framework only where the activity amounts to an establishment in the host Member State; services provided without an establishment are outside the current 2018 RTS perimeter.
We are below 10 establishments and under EUR 3 million in the host state. Can a contact point still be required there?
Yes. Article 3 of Delegated Regulation (EU) 2018/1108 also allows a host state to require appointment where information is not provided to competent authorities on time, and on a risk-sensitive basis where higher ML/TF risk is demonstrated. The quantitative thresholds are one route among several, and clearing them is no safe harbour.
If we are required to appoint contact points in several host states, is it one appointment or one per state?
The requirement is territorial. Each host Member State that exercises the option requires a contact point in its own territory, measured against activity in that territory. A firm active through agents in several states can face several separate appointments, and the functions attached to each can differ depending on whether the host state has switched on the Article 6 tasks.
Does the contact point have to file suspicious transaction reports?
Only where the host Member State requires it. Filing STRs, responding to FIU requests, and scrutinising transactions are the optional functions in Article 6 of Delegated Regulation (EU) 2018/1108. Where a host state adopts them, the contact point performs those functions on behalf of the appointing EMI or PSP. Even without those additional functions, Article 4(f) requires the contact point to represent the appointing EMI or PSP in communications with the host-state FIU and competent authorities.
We are a crypto-asset service provider operating cross-border. Should we respond to this survey?
This particular survey covers EMIs and PSPs, not CASPs, because the reviewed standards did not apply to crypto-asset service providers. CASPs were brought into the Article 45(9) option by Regulation (EU) 2023/1113 from 30 December 2024, but the criteria and functions for a CASP contact point are being developed separately from this exercise.
Related Articles
- AMLA Home-Host Supervisory Cooperation RTS: how AMLA is standardising cooperation between home and host AML supervisors for cross-border groups.
- AMLR: What Changes for Luxembourg: the single rulebook and how directly applicable AML obligations reshape obliged-entity duties.
- AMLA Direct Supervision of Obliged Entities: how AMLA’s direct supervisory role interacts with national competent authorities such as the CSSF.
- PSD3 for Payment Institutions and Electronic Money: the changing perimeter for PSPs and EMIs and how agent and distributor networks are defined.
- Wolfsberg Guidance for Non-Bank PSPs: AML governance expectations for payment firms operating across borders.
Key Takeaways
- The AMLA Central Contact Point survey is voluntary, aimed at EMIs and PSPs, and closes on 15 September 2026; it gathers feedback and creates no reporting obligation.
- The framework under review is Article 45(9) of Directive (EU) 2015/849 and Commission Delegated Regulation (EU) 2018/1108, covering firms that reach a host market through non-branch establishments (which may include qualifying agent or distributor arrangements).
- Under Article 3(1), a host Member State may require a contact point where the relevant establishments number 10 or more, where the specified cumulative electronic-money or payment-transaction amount is expected to exceed EUR 3 million in the financial year or exceeded EUR 3 million in the previous financial year, or where requested information needed to assess those criteria is not supplied in a timely manner. Articles 3(2) and 3(4) provide separate risk-based routes.
- The contact point’s functions run from compliance oversight and supervision liaison to, where a host state requires it under Article 6, filing STRs and answering the FIU. Article 4(f) requires FIU communication even without the Article 6 additions.
- Crypto-asset service providers entered the Article 45(9) option via Regulation (EU) 2023/1113 from 30 December 2024, but are excluded from this survey because the reviewed standards did not cover them.
- The AML and PSD2 central contact point regimes have different legal bases and functions. Where both apply, the firm must satisfy each regime; the EU provisions reviewed here do not themselves require the roles to be performed by different persons or entities.
- Responses feed AMLA’s work on the Article 41(2) successor RTS. Article 41(2) set 10 July 2026 as the deadline for AMLA to develop and submit the draft RTS, while the new Directive’s wider framework is generally transposed for application from July 2027. Delegated Regulation (EU) 2018/1108 remains in force today; the successor criteria have not yet been adopted.
- For current-law compliance, maintain a host-state grid against the criteria in Delegated Regulation (EU) 2018/1108. For future readiness, separately capture the wider operating models described in Article 41(1) of Directive (EU) 2024/1640; the successor RTS criteria are not yet adopted.
Sources and References
- CSSF, “Survey launched by AMLA on Central Contact Points” (communique, 21 August 2026): cssf.lu
- AMLA, “AMLA launches survey on Central Contact Points” (news article, 6 August 2026): amla.europa.eu
- Directive (EU) 2015/849 (Fourth Anti-Money Laundering Directive), Article 45(9) to (11) and Article 48(4): EUR-Lex
- Commission Delegated Regulation (EU) 2018/1108 of 7 May 2018 (RTS on central contact points): EUR-Lex
- Regulation (EU) 2023/1113 (recast Transfer of Funds Regulation, amending Article 45(9)): EUR-Lex
- Directive (EU) 2024/1640 (AMLD6), Article 41: EUR-Lex
- Regulation (EU) 2024/1624 (AML single rulebook, AMLR): EUR-Lex
- Regulation (EU) 2024/1620 (establishing AMLA): EUR-Lex
- Directive (EU) 2015/2366 (PSD2), Article 29(4) and (5): EUR-Lex
- Directive 2009/110/EC (Second Electronic Money Directive), consolidated text, Article 3(1), (4) and (5): EUR-Lex
- Commission Delegated Regulation (EU) 2020/1423 of 14 March 2019 (RTS on central contact points under PSD2; published OJ 9 October 2020): EUR-Lex
- AMLA, Single Programming Document 2026-2028, Annex XI, “Planning on RTS/ITS/GL” (Article 41(2) central contact point RTS, consultation Q3 2026, final draft Q4 2026): AMLA.
- Luxembourg Justice/CRF, “goAML – le nouveau mode de transmission exclusif des dĂ©clarations d’opĂ©rations suspectes” (12 December 2016): justice.public.lu.
Before the survey window closes
The central contact point framework is one of the quieter corners of cross-border AML supervision, which is exactly why the population it touches often discovers the appointment thresholds only when a host authority raises them. AMLA is now writing the rulebook that will replace the 2018 standards, and it is asking the firms that live with the current ones to explain what works and what does not. If your non-branch establishment footprint reaches into other Member States, the two artifacts to have in hand before 15 September 2026 are a host-state grid of establishment counts and transaction values against the Article 3 criteria, and a decision on whether your operational experience is worth putting on the record.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
