AMLA Central Database RTS: Who Reports What, and From When

RegReportingDesk card: AMLA, Anti-Money Laundering Authority, European Union

On 7 October 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) opened its consultation on the draft regulatory technical standards for the central AML/CFT database under Article 11(6) of Regulation (EU) 2024/1620 (AMLAR). The AMLA central database RTS sets out which supervisory information national authorities transmit to AMLA, in how much detail and on what timetable, with the first financial-sector deadline in the draft falling on 15 July 2027. AMLA is taking views through a public hearing on 3 November 2026, from 14:00 to 16:00 CET.

The reporting line runs from supervisors to AMLA. AMLA’s consultation paper states that the draft does not impose new reporting requirements on obliged entities, and the press release says the database adds no new reporting costs for them. Much of what travels down that line is about obliged entities all the same: their identifiers, their risk scores and the underlying data points, every administrative measure, pecuniary sanction and periodic penalty payment imposed on them, and negative ML/TF opinions given in authorisation and fit-and-proper procedures, in some cases with named individuals attached.

Under Article 11(1) AMLAR, AMLA makes database information available to supervisory authorities, to non-AML/CFT authorities, to other national authorities and bodies competent under the sectoral directives the Article lists, and to the EBA, ESMA and EIOPA, on a need-to-know and confidential basis where they need it for their tasks. My reading is that data a firm already gives its own supervisor becomes, once the RTS applies, part of an EU-level record that other authorities can request.

Related reading: EuReCA Reporting: CSSF Names AMLA in Joint Controllership Update

Draft dates from 15 July 2027 to 31 May 2031

The reporting dates below come from the consultation draft, so each one can move after the hearing and during adoption by the Commission under Article 49 AMLAR. The exception is 27 June 2028, which Article 106(1) AMLAR sets in the Level 1 text. Two dates are still blank in the text: the day of entry into force (shown as the “[…]” day following publication in the Official Journal) and the window for the initial submission in draft Article 11 (shown as “[XXX]”).

Date Source What falls due, and for whom
3 November 2026, 14:00 to 16:00 CET AMLA press release; consultation page Public hearing on the draft RTS. The consultation page lists 16:00 CET that day as the deadline.
15 July 2027 Draft Articles 1(2), 3(4), 4(2) First transmission of the register of supervisors, with entity counts as of 31 December 2026 (voluntary for non-financial supervisors until 27 June 2028). Financial sector: measures, sanctions and periodic penalty payments, and ML/TF advice or opinions, provided or imposed after that date.
31 December 2027 Draft Article 5(2) Financial sector: reporting of supervisory activities starting after that date.
31 March 2028 Draft Articles 1(2), 6(3) Counts of entities supervised by self-regulatory bodies, as of 31 December 2027. First staffing and budget return, covering 2027.
31 May 2028 Draft Article 2(5) First entity-level return for the financial sector, covering 1 January to 31 December 2027.
27 June 2028 Article 106(1) AMLAR Until this date Article 11 applies only to financial supervisors, credit institutions and financial institutions. Non-financial supervisors may comply voluntarily before it.
31 December 2029 Draft Articles 3(4), 5(2) Non-financial sector: measures and sanctions, and supervisory activities.
31 May 2031 Draft Article 2(5) First entity-level return for the non-financial sector.

Once running, the draft settles into recurring cycles: register changes within 30 working days, entity counts and the staffing return by 31 March, entity-level data by 31 May, and measures, sanctions and negative opinions within 30 working days of the event.

Article 11 AMLAR and the seven-point mandate behind the AMLA central database RTS

The obligation to feed the database sits in the Level 1 text. Article 11(2) AMLAR says supervisory authorities “shall transmit to the Authority at least” eight categories of information. Read together, they cover the supervisory map of each Member State, the number of supervised entities per category with basic risk information, administrative measures and pecuniary sanctions with their grounds, ML/TF advice given in authorisation, withdrawal and fit-and-proper procedures, the inherent and residual risk profiles of credit and financial institutions that meet the Article 12(1) criteria, thematic review outcomes, the past year’s supervisory activities, and staffing and resources.

Article 11(6) then asks AMLA to draft RTS on seven points: the procedure, formats and timelines for transmission; the scope and level of detail, taking account of risk profile; the scope and detail for the non-financial sector; which information needs the originating supervisor’s prior consent before AMLA discloses it; the level of materiality a breach must reach before a supervisor is obliged to transmit it; the conditions for AMLA’s additional information requests; and the types of additional information. The Article set 27 December 2025 as the date for AMLA to submit the draft to the Commission. The consultation opened on 7 October 2026, and the paper’s next-steps section names the hearing date without giving a revised submission date.

The impact assessment in the consultation paper sets out the baseline without any RTS: the Article 11 reporting obligations would remain applicable, but there would be no common procedures, formats, timelines, scope or materiality thresholds. The RTS therefore works as the operating manual for an obligation Article 11 already imposes, and because it is drafted as a Commission delegated regulation it will be directly applicable from its entry into force after publication in the Official Journal. Our guide to the EU AML package and its 10 July 2027 countdown places AMLAR alongside the AMLR and AMLD6.

One transitional rule shapes the whole timetable. Article 106(1) AMLAR limits Article 11 to financial supervisors, credit institutions and financial institutions until 27 June 2028, which is why the draft gives non-financial supervisors a voluntary period and later first dates.

Supervisors file, obliged entities feed the data

The draft addresses its obligations to supervisory authorities, which recital 4 ties to the definition in Article 2(1), point (46), of Regulation (EU) 2024/1624 (AMLR). Where self-regulatory bodies supervise, recital 3 says their information and that of the entities they supervise reaches the database through the public body that oversees them, and draft Article 9(5) has self-regulatory bodies make their declarations to that public body. AMLA fills the gaps for its own work: the final subparagraph of Article 11(2) AMLAR has AMLA enter information from its direct supervision and the outcomes of its Article 12 risk assessment.

Prudential data is a separate stream. Article 11(4) AMLAR has AMLA enter information from non-AML/CFT authorities and from bodies supervising credit institutions under Directive 2013/36/EU, including the ECB, covering business model assessments, governance assessments, authorisation procedures, qualifying holdings, fit-and-proper assessments and licence withdrawals. The RTS mandate in Article 11(6)(a) covers transmission under paragraphs 2 and 3, and the consultation draft contains no provisions on that prudential feed.

The database is also a poor place to look for suspicious transaction reports. Article 11(2) AMLAR says the information supervisors provide “shall not include references to specific suspicions” reported under Article 69 AMLR. Suspicion reports keep going to the financial intelligence unit; what reaches AMLA is the supervisory record around the entity.

Articles 1 and 6: the register of supervisors and the resources return

Draft Article 1 builds a register of who supervises whom. Each supervisory authority transmits its Member State, its name and contact details, the people it designates to grant database access to its staff, any self-regulatory bodies it oversees, any leading supervisor or coordination-mechanism representative under Article 37(4) AMLD6 (Directive (EU) 2024/1640), its tasks and powers under Article 37(5) to (7) AMLD6, and the categories of obliged entities it supervises with the number in each category. The categorisation follows Annex I of the draft, which splits obliged entities into credit institutions, financial institutions (including crypto-asset service providers and EU branches) and persons acting in the exercise of professional activities, a list that runs to football agents and professional football clubs.

The narrow field to watch is point (j). It asks for the level of risk applicable to each supervised sector according to the most recent national risk assessment under Article 8 AMLD6 (the draft cites paragraph 6, which has Member States share the results with AMLA), with the date and period that assessment covers. For AMLA, the reference is the most recent Union-level risk assessment. A supervisor whose national risk assessment is old will be sending an old sector rating, dated as such.

Updates run on two clocks. Any change to the register goes into the database within 30 working days of taking effect, except the entity counts, which are refreshed by 31 March each year as of 31 December of the previous year. The first transmission is due by 15 July 2027 with counts as of 31 December 2026, while counts for entities supervised by self-regulatory bodies first fall due on 31 March 2028, as of 31 December 2027.

Draft Article 6 is the resources return. Supervisors report AML/CFT specialists in full-time equivalents, within the authority and, where applicable, within the self-regulatory bodies they oversee, split where available into policy and legal work, risk analysis, supervisory activities and enforcement. They also report the annual AML/CFT budget in euros. Figures reflect 31 December of the preceding year and are due by 31 March, with the first return due on 31 March 2028 for 2027.

Article 2: entity-level risk data, down to the data points

The draft asks for the risk score and the data points behind it. For each obliged entity it supervises, or that a self-regulatory body it oversees supervises, a supervisory authority transmits:

  • identification: for legal persons, name, address, national registration number and, where available, the LEI; for natural persons in the financial sector, name, surname and address;
  • where available, the inherent risk profile and the quality of AML/CFT controls, each with documentation of any adjustment made where the score did not adequately reflect the entity’s risk or controls, and the residual risk profile;
  • where available, the data points from which the inherent risk and controls scores were derived;
  • whether there are central contact points under Article 41 AMLD6, identified by the host supervisor, with their Member State.

Group and college information comes on top. Where the entity belongs to a group within the meaning of Article 2(1), point (41), AMLR, the supervisor of the parent undertaking adds the parent’s name and country of establishment; Annex II also lists the parent’s LEI. Where an AML/CFT supervisory college exists under Article 49 or 50 AMLD6, the lead supervisor adds the name, role and country of permanent members and observers. Our coverage of the AMLA central contact point survey for PSPs and EMIs explains where those contact points come from.

The data-point requirement is the policy choice that matters most here. Article 11(2) AMLAR asks for “basic information about the risk profile” of supervised entities and full risk-profile outcomes only for credit and financial institutions meeting the Article 12(1) criteria, which cover credit and financial institutions, and groups of them, operating in at least six Member States including the home Member State. The impact assessment weighed three options: basic scores for all with full data points only for directly supervised entities, full data points for the financial sector only, or full data points for all obliged entities. AMLA chose the third. Draft Article 2(2) tells supervisors to refer to Annex I, Sections A and B, of the RTS under Article 40(2) AMLD6 “by directly transmitting the data points related to the obliged entity.”

Timing has two layers. The entity return is due by 31 May each year for the previous calendar year, first by 31 May 2028 for the financial sector and 31 May 2031 for the non-financial sector. Risk scores and data points, though, go in within 10 working days after the date set in Article 5 of the Article 40(2) RTS, following the review frequency that delegated regulation sets, and any in-year adjustment to an inherent risk or controls score goes in with its supporting documentation within 30 working days of the adjustment. Our piece on the AMLA risk assessment data collection for the 2027 selection exercise covers the separate collection behind AMLA’s Article 12 selection model, a methodology that recital 21 AMLAR asks AMLA to align, where appropriate, with the Article 40(2) RTS.

The cross-references are still placeholders. The draft cites “Commission Delegated Regulation (EU) 202../xxx” and “Article [XX]” for the risk methodology, so the Article 2 timetable depends on an instrument that has no Official Journal number in the consultation text. The EBA’s supervisory convergence report for 2025 records that the EBA published its response to the Commission’s call for advice on 30 October 2025, including two draft RTS on entity-level risk assessment, one of them the AMLD6 methodology. AMLA has since published its final report on the draft Article 40(2) RTS for supervisors of financial-sector obliged entities, for submission to the Commission, and consulted from 13 July to 27 September 2026 on a separate draft RTS for the non-financial sector, which fits the “[RTS 40(2) FS and NFS]” reference in draft Article 2(6).

Article 3: every measure and sanction, and the materiality question

Draft Article 3 covers administrative measures, pecuniary sanctions and periodic penalty payments imposed in response to breaches of AML/CFT requirements and to weaknesses in internal policies, procedures and controls that are likely to result in breaches. The weakness limb widens the scope beyond proven breaches; Annex II includes a field indicating whether a weakness is likely to result in a breach.

For each measure the supervisor reports the entity, the date of imposition, the type of measure, any link to a natural person (with the person’s function, the reasons for the link, and name, surname, date of birth, nationality and country of residence), the status including any appeal or settlement, compliance, payment and end dates, the amount, and whether and how the measure was published, including reasons for anonymous, delayed or non-publication. Article 3(3) adds the breach itself: the supervisory activity that detected it, the compliance area, a description, the level of gravity, whether it has been remediated, whether it has a cross-border impact beyond local branches, agents or distributors, and any planned follow-up. Annex II ties the gravity field to Article 2(1) of the separate RTS under Article 53(10) AMLD6.

Transmission happens without undue delay and no later than 30 working days after imposition, with updates within 30 working days of any change. Financial-sector supervisors start with measures imposed after 15 July 2027; the non-financial date is 31 December 2029.

The materiality point deserves a careful read. Article 11(6)(e) AMLAR asks the RTS to specify the level of materiality a breach must reach before a supervisor is obliged to transmit it, and AMLA’s press release says the standards set “the materiality threshold above which a breach must be reported.” The draft articles state no separate threshold. Article 3(5) applies to “all administrative measures, pecuniary sanctions and periodic penalty payments imposed”, and the impact assessment’s preferred option is reporting of all measures; it says reporting all breaches would “eliminate uncertainty regarding reporting thresholds.”

My reading is that the operative trigger in the draft is the imposition of a measure, sanction or penalty payment, with gravity recorded as an attribute of each breach. The gap between the press release wording and the article text is a fair question for the hearing.

The contrast with EuReCA, the database the EBA built under Article 9a of Regulation (EU) No 1093/2010 and which AMLA now manages, is sharp:

Point EuReCA Draft Article 11(6) RTS
Legal basis Article 9a of Regulation (EU) No 1093/2010 (deleted by Article 103 AMLAR with effect from 31 December 2025) and Commission Delegated Regulation (EU) 2024/595; run by AMLA under the Article 106(1) AMLAR arrangement with the EBA Article 11 AMLAR; draft RTS under Article 11(6)
Reporting population Financial sector supervisors and other reporting authorities defined in Delegated Regulation (EU) 2024/595 All AML/CFT supervisory authorities, with later first dates for the non-financial sector
What triggers a report Material weaknesses and the related measures All administrative measures, pecuniary sanctions and periodic penalty payments for breaches and weaknesses

In the impact assessment, the rejected option, reporting only measures for serious, repeated or systematic breaches, is the one AMLA describes as similar to the EuReCA model under Delegated Regulation (EU) 2024/595, which limits reporting to material weaknesses and related measures.

Articles 4 and 5: negative opinions and supervisory activity logs

Article 11(2)(d) AMLAR speaks of “any advice or opinion” on ML/TF risks given to other authorities in authorisation, withdrawal and fit-and-proper procedures. Draft Article 4 narrows that to advice or opinions that raise ML/TF concerns or constitute a negative assessment, whether the supervisor issued them on its own initiative or on request. For those, it transmits a summary of the request, a summary of the ML/TF aspects including outcome and concerns, the type of opinion, the receiving authority and its country, the date, the related entity and, where an individual is concerned, name, surname, date of birth, country of residence, nationality and current or prospective function. The deadline is 30 working days after the opinion; financial-sector reporting covers opinions given after 15 July 2027, and non-financial supervisors and public authorities overseeing self-regulatory bodies report on a voluntary basis until 27 June 2028.

An opinion that raises no ML/TF concern stays out of the database under this draft. One that raises a concern, or is negative, carries the identity of any individual it concerns.

Draft Article 5 covers supervisory activities. Under Article 5(7), an activity is reported when it reflects use of a supervisory tool as part of the supervisor’s annual strategy or plan, or ad hoc use in response to specific events, emerging risks or concerns. The fields are the entities involved, the nature and scope of the activity, start and end dates, whether it is ongoing, the thematic review report where there is one (in any official EU language), and the participation of other authorities. Reporting is differentiated by sector and outcome:

Reporting route Financial sector Non-financial sector
Reported activity by activity On-site activities, and off-site activities that are thematic reviews or end in a measure, sanction or penalty payment Thematic reviews, and activities on-site or off-site that end in a measure, sanction or penalty payment
Deadlines for activity-level data Start data within 30 days of the start; end data within 30 working days of the end; off-site activities report everything after the end Start data for thematic reviews within 30 working days of the start; end data within 30 working days of the end
Everything else Points (a) to (e) per activity, by 31 January of the following year Nature of the activity only, aggregated by sector, by 31 January of the following year
First reporting Activities starting after 31 December 2027 Activities starting after 31 December 2029

The first row follows the impact assessment’s description of the preferred option; the derogation in Article 5(5) is worded more loosely, applying where an activity “is conducted off-site, is not part of a thematic review or does not result in” a measure, and Article 5(6) uses the same “or” for the non-financial sector, where an activity “is not part of a thematic review, or does not result in” a measure. There is also a small inconsistency in units: Article 5(3) gives financial-sector start data “within 30 days”, while Article 5(4) gives the non-financial equivalent “within 30 working days”. For a supervisor building a workflow, that difference sets the alert.

Draft Article 7 conditions AMLA’s additional requests under Article 11(3) AMLAR. Each request must be necessary for one or more AMLA tasks listed in Article 5 AMLAR, and AMLA must state the task, the justification and the intended use. Requests must be proportionate. Supervisors answer within 30 working days, which AMLA can extend for complex data; a supervisor that cannot meet the deadline gives reasons and proposes a new one, and a supervisor without legal access to the information says so without undue delay.

Draft Article 8 sets the consent rules that Article 11(6)(d) asked for. Information submitted under Article 11(2) and (3) is confidential. Use for AMLA’s Article 5 tasks or within the AML/CFT supervisory system needs no prior consent from the originating supervisor; disclosure to third parties outside the system does. Exceptions allow sharing without consent where Union law authorises or requires it, including with financial intelligence units, with the authorities in Article 2(1), point (44)(c) and (d), AMLR, and with authorities implementing targeted financial sanctions under Article 66 AMLD6.

The draft says consent should always be required where information originated with a third-country authority, and the originating supervisor is told the scope, recipient, legal basis and rationale of any no-consent disclosure. Statistical, aggregated or anonymised data falls outside the consent requirement.

Draft Article 9 leaves the technical specifications to AMLA, which communicates them to supervisors. Submission is electronic and automated where appropriate. Each supervisor names a person of appropriate seniority to deal with AMLA and designates contact points whose access is limited to the data and functions their tasks require, and supervisors remain responsible for data that is complete, accurate and up to date. Draft Article 10 applies the professional secrecy rules in Articles 67 and 68 AMLD6 to everything submitted.

The draft contains no file format. Recital 2 says the RTS should not prescribe detailed technical provisions on the means of transmission, and section 3.1 of the paper describes the draft as technology neutral, with the technical solution “developed separately and progressively”. Annex II lists the data points per article, and that list is the closest thing to a data dictionary in the package; field formats and validation rules will have to come through the Article 9(1) specifications.

Blanks and inconsistencies worth raising on 3 November

The consultation paper asks four questions. Question 1 covers Articles 1, 5 and 6; Question 2 covers Article 2; Question 3 covers Articles 3 and 4; Question 4 covers Articles 7, 8 and 9 on additional information, prior consent, technical specifications, data quality and confidentiality. Several points in the text fit those questions directly:

  • the initial submission window in draft Article 11 is “[XXX]”, draft Article 11(2) ties the snapshot to the entry-into-force date, which is itself blank, and the initial submission sits alongside the fixed first dates in Articles 1 to 6;
  • Article 2 depends on a risk-methodology delegated regulation cited by placeholder, including the Article 5 date that triggers the 10-working-day clock;
  • the press release describes a breach materiality threshold that the article text does not state;
  • Article 5(3) uses calendar days where neighbouring provisions use working days;
  • recital 15 says the regulation provides a deferred application date for football clubs and football agents, because the AMLR applies to them from 10 July 2029, but the articles in the consultation text do not set out that date.

AMLR Article 90 confirms the football timing: the AMLR applies from 10 July 2027, and from 10 July 2029 for the obliged entities in Article 3, points (3)(n) and (o).

Reading the draft from the obliged entity side

The draft creates no return for firms to file, so the useful question for a firm’s AML/CFT and regulatory reporting teams is which existing outputs end up in the database. Four stand out on the text.

Identifiers come first. The Article 2 identifiers, together with the parent undertaking’s LEI listed in Annex II, are the fields that tie each record to an entity. My working assumption is that, for a group with entities supervised in several Member States, these identifiers are what will link records sent by different supervisors, so a mismatch between registers would show up at EU level.

Risk-assessment submissions come second. The data points a firm supplies to its supervisor for the Article 40(2) AMLD6 risk assessment are, on the draft text, what the supervisor forwards where they are available, by reference to Annex I, Sections A and B, of that RTS.

Enforcement history comes third. Every measure, sanction and penalty payment imposed after the start date goes in with its breach description and gravity level, and individuals linked to a measure are named.

Governance files come fourth. A negative ML/TF opinion in an authorisation or fit-and-proper procedure carries the individual’s identity and function into the database, and recital 18 AMLAR explains the purpose: letting authorities consider shortcomings of entities and individuals that materialised in other Member States. Article 11(1) AMLAR lets AMLA share the results of its analysis with obliged entities “where relevant”; the draft RTS adds no route for an obliged entity to view its own records.

Frequently Asked Questions

Our group will be directly supervised by AMLA from 2028. Does our national supervisor still report us to the database?

Article 11(2) AMLAR has AMLA enter the information stemming from its own direct supervision that corresponds to the Article 11(2) categories, together with the outcomes of its Article 12 risk assessment. The draft RTS places the Article 2 duty on supervisory authorities for each obliged entity “under their supervision”, and recital 4 takes that term from Article 2(1), point (46), AMLR, which covers AMLA when acting as a supervisor. The consultation text does not spell out how reporting splits between AMLA and national supervisors for a selected entity, so the boundary is a point the final text or AMLA’s technical specifications will have to settle.

A pecuniary sanction against us is under appeal, and we may settle. What would the record show?

Draft Article 3(2)(f) requires the status of the measure, including whether an appeal has been brought and whether a settlement has been reached. Under Article 3(2)(h), for settlements the supervisor reports the imposed amount when first reporting the sanction and the settled amount once known, so both figures sit in the record. Each change triggers an update within 30 working days.

Can a host-state supervisor see what our home supervisor transmits?

Draft Article 8(2) allows use of the information within the AML/CFT supervisory system, as defined in Article 2(1), point (3), AMLAR, without prior consent of the originating supervisor. Authorities outside AMLA can also send AMLA a reasoned request under Article 11(5) AMLAR; AMLA then tells the authority that provided the information who asked, which entity is concerned, why, and whether the information was given.

How long does personal data about named individuals stay in the database?

Article 11(7) AMLAR allows personal data collected under Article 11 to be kept in identifiable form for up to 10 years after AMLA collects it, then deleted. AMLA can delete earlier on a case-by-case basis after a regular necessity assessment. Recitals 10 and 11 of the draft confirm that Regulation (EU) 2016/679 and Regulation (EU) 2018/1725 apply to the personal data processed.

We report material weaknesses through EuReCA today. Does the draft say what happens to those records?

The consultation paper does not describe a migration of existing EuReCA records. Article 106(1) AMLAR provides for an AMLA and EBA arrangement on the existing database for a mutually agreed period, extendable until no later than 30 June 2027, and EuReCA reporting rests on Delegated Regulation (EU) 2024/595, which the new RTS does not amend in its consultation text.

We are a professional football club. When would our data reach the database?

Annex I lists professional football clubs and football agents as obliged entity sub-categories, so supervisors would count them in the Article 1 register. Recital 15 signals a deferred application date for them, matching the AMLR’s 10 July 2029 start for these entities. Because the articles in the consultation text do not set that date, the only dates the text currently gives for these entities are the general non-financial sector ones, with the football-specific date still to appear.

Does the database replace national AML/CFT data collections from firms?

No provision in the draft removes national collections. Recital 4 describes the Article 2 data points as data “collected from obliged entities” by supervisors for the risk classification under Article 40(2) AMLD6, so gathering that data from firms stays with the national supervisor, and the database receives it second-hand.

Key Takeaways

  • Financial-sector firms: reconcile the LEI, national registration number and address each supervisor holds before the first entity-level return on 31 May 2028.
  • A supervisory adjustment to an entity’s inherent risk or controls score reaches AMLA, with its supporting documentation, within 30 working days of the adjustment.
  • Unpublished and anonymously published sanctions are still transmitted, together with the reasons for anonymity, delay or non-publication.
  • Supervisors get 30 working days to answer an AMLA ad hoc request, extendable by AMLA, and the draft requires them to say without undue delay when they have no legal access to the information.
  • IT budgets for supervisors belong against AMLA’s Article 9(1) technical specifications; the RTS lists data points and sets no file format.

Sources and References

  • AMLA, Press Release: AMLA consults on draft standards for an EU-wide AML/CFT database (7 October 2026): amla.europa.eu
  • AMLA, Consultation via a public hearing on the draft RTS for establishing a central AML/CFT database: amla.europa.eu
  • AMLA, Consultation Paper: Draft Regulatory Technical Standards on the AML/CFT Central Database under Article 11(6) of Regulation (EU) 2024/1620 (PDF): amla.europa.eu
  • Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLAR), Articles 2, 5, 11, 12, 49 and 106 and recitals 18 and 21: EUR-Lex
  • Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing (AMLR), Articles 2, 3, 69 and 90: EUR-Lex
  • Directive (EU) 2024/1640 (AMLD6), Articles 8, 37, 40, 41, 49, 50, 53, 66, 67 and 68: EUR-Lex
  • Commission Delegated Regulation (EU) 2024/595 of 9 November 2023 on the AML/CFT central database referred to in Article 9a(2) of Regulation (EU) No 1093/2010: EUR-Lex
  • Regulation (EU) No 1093/2010 establishing the European Banking Authority, Article 9a (deleted by Article 103 of Regulation (EU) 2024/1620 with effect from 31 December 2025): EUR-Lex
  • Regulation (EU) 2016/679 (GDPR): EUR-Lex
  • Regulation (EU) 2018/1725 on data protection by Union institutions, bodies, offices and agencies: EUR-Lex
  • CSSF, Update of the statement on the joint controllership arrangement for the EuReCA central database: cssf.lu
  • EBA, Report on Supervisory Convergence 2025 (section 5.4 on entity-level ML/TF risk assessments): eba.europa.eu
  • AMLA, Final Report: Draft Regulatory Technical Standards on the assessment of the inherent and residual risk profile of obliged entities under Article 40(2) of Directive (EU) 2024/1640 (PDF): amla.europa.eu
  • AMLA, Consultation on the draft RTS on the assessment of the inherent and residual risk profile of obliged entities in the non-financial sector: amla.europa.eu

The 3 November hearing and the blanks AMLA still has to fill

The draft already fixes the shape of the database: a register of supervisors, an annual entity return with risk data points, event-driven reports on measures and negative opinions, an activity log and a resources return. What it leaves open is when the first snapshot is taken, which risk-methodology regulation drives the Article 2 clock, and whether a breach materiality threshold will qualify the “all measures” rule. Registration for the hearing on 3 November 2026, 14:00 to 16:00 CET, runs through the AMLA consultation page, and comments mapped to Questions 1 to 4 are the artifact to have ready before that date.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • Commodity Derivatives Position Reporting: ESMA’s 3 September Go-Live

    On 14 August 2026 ESMA confirmed that the reworked weekly commodity derivatives position reporting framework goes live on 3 September 2026. From that date, an investment firm or market operator operating an EU trading venue whose relevant contract is subject to the Article 58 weekly-reporting obligation must submit the weekly report to ESMA using the…

  • AMLA Final RTS: CDD Data, Linked Transactions and Group-Wide Rules

    On 1 October 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) announced that it had finalised three sets of regulatory technical standards for the private sector and submitted them to the European Commission. The AMLA final RTS cover customer due diligence under Article 28(1) of Regulation (EU) 2024/1624 (the AMLR),…

  • MiCA Review: The EBA’s Priorities for Token Issuers and CASPs

    On 24 September 2026 the European Banking Authority published its response to the European Commission’s targeted consultation on the MiCA review, an exercise feeding into the review framework under Article 140 of Regulation (EU) 2023/1114. The EBA asks the Commission to prioritise five things: a dedicated regime for third-country multi-issuer stablecoin schemes, a fresh look…

  • CSSF B 2.5 B and B 2.5 E Reporting: Luxembourg Staff Costs and Taxes

    Report Library › Prudential ReportingOnce a year, credit institutions within scope report the CSSF’s B 2.5 national return. The survey uses sub-template B 2.5 B for staff expenses and sub-template B 2.5 E for taxes, with B 2.5 E populated only in accounting version L. The CSSF calls the pair its Survey on staff expenses…

  • FATF on Hawala and Underground Banking: AML Red Flags

    Updated September 2026In this guideWhat FATF actually published on 3 September 2026How hawala and underground banking move valueWhy professional launderers reach for these channelsWhere the formal system meets the informal oneThe obligations that already apply, and how they translateRed flags a reporting team can put to workTurning a suspicion into a filingFrequently Asked QuestionsRelated ArticlesKey…

  • EBA Revised SREP Guidelines: What EU Banks Must Review in ICAAP, ILAAP and Pillar 2 Capital

    Updated July 2026In this guideWhat actually changed on 26 June 2026The new capital stack and where Pillar 2 sitsPillar 2 and the output floor: the change that matters mostWhat the revised SREP guidelines expect from your ICAAPILAAP and the merged liquidity assessmentP2G, stress testing and the every-second-year optionDORA, ESG and operational resilience folded into the…