AMLA Risk Assessment Data Collection: The 2027 Selection Exercise
From 2028, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) is due to directly supervise a first group of up to 40 credit and financial institutions or groups across the EU; under Article 13(4) of Regulation (EU) 2024/1620, direct supervision starts six months after AMLA publishes the selected-entity list. The exercise that decides which firms land in that group is the AMLA risk assessment data collection, and the data feeding it moves through national supervisors on a fixed 2026 to 2027 calendar. A bank or payment firm operating across several Member States can be pulled into the selection pool on the strength of numbers its own supervisor submits to AMLA, so the quality of that submission matters even though the firm never sends it to AMLA itself.
The legal machinery sits in Regulation (EU) 2024/1620, the AMLA Regulation, supported by Directive (EU) 2024/1640, the sixth Anti-Money Laundering Directive. Together they give AMLA a risk-based method for picking the highest-risk cross-border institutions and a mandate to harmonise how supervisors score money laundering and terrorist financing risk. The data collection is where that method meets real balance sheets and customer books.
One warning colours everything below. AMLA and the European Banking Authority have published the reporting taxonomy that will carry this data in machine-readable form, but the current version is preparation material only and must not be submitted to any authority. Reading that status wrong is the first mistake a reporting team can make here.
Related reading: AMLA Direct Supervision: Which Entities Are Selected
What the AMLA risk assessment data collection is and its legal basis
AMLA is the EU authority created to supervise anti-money laundering and counter-terrorist-financing (AML/CFT) directly and to steer national supervisors. Regulation (EU) 2024/1620 gives it a specific job: from a large field of obliged entities, identify the cross-border credit and financial institutions that pose the highest ML/TF risk and take over their supervision. The risk assessment data collection is the evidence-gathering step that makes that identification possible. It converts each candidate firm into a set of comparable risk numbers so AMLA can rank them on a common scale.
Two instruments carry the mandate. The AMLA Regulation sets the selection mechanism and, in Article 12(7), requires AMLA to develop draft regulatory technical standards on the methodology for assessing and selecting obliged entities for direct supervision. Article 40(2) of Directive (EU) 2024/1640 requires draft regulatory technical standards for the common methodology supervisors will use to assess and classify obliged entities’ inherent and residual ML/TF risk profiles. As at 15 September 2026, AMLA lists both instruments as draft RTS with final reports published; Commission adoption is still required. AMLA states that the two methodologies use aligned data points and criteria, but detailed thresholds and scoring mechanics described below remain subject to the final adopted RTS.
The distinction to hold onto is that the 2027 collection is a targeted supervisory data collection for the first selection cycle, not a standing periodic AML/CFT return. The underlying statutory mechanism is nevertheless recurring: Article 12(1) requires periodic assessment and Article 13(4) requires the selection process to be carried out every three years after the first selection.
Who must report: the cross-border institutions in the selection pool
Scope is narrower than the phrase “AML reporting” suggests. The entities in view are credit institutions and financial institutions, including groups, that operate in at least six Member States, including the home Member State, through establishments or under the freedom to provide services. That cross-border footprint is the gate. A large domestic bank with no meaningful cross-border presence sits outside the pool, however significant it is at home, while a mid-sized payment or e-money firm passporting into several markets can sit inside it.
Firms do not nominate themselves and they do not submit to AMLA. National supervisors are responsible for organising the data collection from obliged entities within their remit, then transmitting the results to AMLA. For the exercise AMLA ran to test and calibrate its models, participation was by notification through the national competent authority, and two groups were involved: entities that may be eligible for direct supervision, and a representative sample of entities expected to remain under national supervision. The sample exists to calibrate the scoring, not because those firms are selection candidates.
The misread to guard against here is simple. Being contacted is not the same as being selected, and being in the calibration sample carries no implication of future direct supervision. The obligation a firm actually faces is to give its national supervisor accurate data to the template and instructions supplied, on the timetable that supervisor sets. Everything downstream, including whether the firm makes the final list, is AMLA’s decision on data it receives from the supervisor.
What the report contains: the template, the data points, and how they score
AMLA distributes the collection as a reporting package made up of several documents. For the calibration exercise the package consisted of an interpretative note, a standardised template in Excel format, and a set of webinar slides explaining the requirements. The interpretative note is the technical instruction document for the 2026 testing and calibration package. It provides field-level explanations and reporting conventions, but it expressly states that it does not create, amend or supersede legally binding requirements and that applicable Union legal acts prevail in the event of inconsistency.
The data points are built to produce two linked measures for each entity: an inherent risk profile and a residual risk profile. Inherent risk captures exposure before controls, drawn from the customer base, products, delivery channels, and geographies a firm deals with. Residual risk reflects what remains once the firm’s AML/CFT controls are taken into account. For a group, AMLA’s methodology aggregates the assessment at group-wide level; the December 2025 draft RTS final report under Article 12(7) proposes a weighted average of entity-level residual risk scores with materiality thresholds applied to freedom-to-provide-services volumes, though these details are subject to Commission adoption of the draft standards.
AMLA’s public 2026 interpretative note contains field-level data-point instructions and reporting conventions, including the reference period, reporting currency, currency-conversion rules and zero-versus-blank treatment. Reporting teams should use the note together with the applicable Union legal acts and the relevant template or taxonomy package, because the note itself states that binding Union law prevails in the event of inconsistency.
Reference dates and deadlines: the 2026 to 2028 selection calendar
The exercise runs in stages, and the dates matter more than any single reference period. AMLA opened the calibration data collection on 16 March 2026 to test and validate its risk assessment models. Participating obliged entities were requested to submit their data to their respective national supervisors by 22 April 2026. A public webinar on 10 June 2026 explained the reporting package for identifying provisionally eligible entities, and supervisors were required to send their identification data to AMLA by 15 August 2026. In parallel, the European Banking Authority released the framework 4.3 taxonomy in July 2026 as preparation material only. AMLA aimed to finalise the provisional list of eligible entities by the end of September 2026, with the updated taxonomy version expected at roughly the same time.
The heavier substantive stage follows in 2027. AMLA’s January 2026 explainer schedules the final data collection from eligible entities for January to March 2027. Under Article 13(4) of Regulation (EU) 2024/1620, AMLA must commence the first selection process by 1 July 2027 and conclude it within six months of the actual commencement date. AMLA must publish the selected-entity list without undue delay after completion, and direct supervision begins six months after publication of that list.
Read the two 2026 collections as distinct steps. The spring exercise tested the models. The summer step identified which entities meet the eligibility gate, feeding the provisional list. The substantive risk-assessment data that drives scoring is gathered from eligible entities in early 2027, close to the selection itself, so the figures reflect the firm’s position close to the decision point.
The calendar reflects two distinct phases: 2026 draws the boundary of the pool, and 2027 is the year that actually scores a firm. That is why the lighter 2026 contact can lull a team into thinking the work is finished; the heavier data request is the one that arrives closer to the selection, and a firm that treats the earlier contact as the whole exercise will be unprepared for it.
Submission and format: national supervisors, the Excel template, and the framework 4.3 taxonomy
The submission channel is the national supervisor, not AMLA. Obliged entities return data to their competent authority, which validates and forwards it. For firms operating in several Member States, this means the same group can be approached by more than one supervisor, and internal coordination across those relationships is part of the job the collection creates.
Two formats coexist. The calibration and identification steps used a standardised Excel template with the interpretative note. In parallel, the machine-readable version is being built inside the EBA reporting framework, using the Data Point Model 2.0 and the XBRL taxonomy that ship with framework release 4.3, and governed for filing mechanics by the EBA filing rules. The taxonomy is what will let supervisors and firms exchange the data structurally instead of as spreadsheets.
The point to watch is timing. AMLA has been explicit that the framework 4.3 components published in July 2026 are intended only to help reporting agents prepare and must not be used for submissions to national competent authorities, the EBA, or AMLA. The right use of the release is preparation and testing only. AMLA states that version 4.4 will revise the modelling of the version 4.3 templates for 2027 submissions, so mappings built on 4.3 should be treated as provisional and re-checked against the final 4.4 package.
Validation rules and the data-quality traps that matter here
Framework 4.3 includes validation rules, the DPM 2.0 data point model, the XBRL taxonomy and EBA Filing Rules v5.9. For the AMLA risk-assessment module, however, those version 4.3 components are preparation material only and must not be treated as the acceptance rules for a live submission. AMLA has not published rejection statistics for this collection, so any claim about the most common rejection cause would be guesswork. What the authorities have flagged is more useful than a rejection league table.
The known data-quality trap is the treatment of missing information. AMLA has said the next taxonomy version will better distinguish unavailable information from zero values and will add two new data points. AMLA distinguishes a reported zero from unavailable or non-applicable information, and the planned version 4.4 revision is intended to capture unavailable information more clearly. Reporting an unavailable value as zero would therefore misstate the dataset used for the risk assessment; the public sources reviewed do not quantify the direction or size of any resulting change in a firm’s residual risk score.
For a reporting team the practical control is to reconcile every blank and every zero against the interpretative note before submission, and to keep an internal record of why each was chosen. Because the taxonomy is still moving, mapping work should be validated against the current published rules and re-checked when the next version lands.
Caveats and interactions: what this data collection is not
The published framework 4.3 taxonomy carries no submission obligation; everything a firm builds against it now is groundwork for a later collection.
The second caveat is scope discipline. This collection is a targeted selection instrument aimed at cross-border credit and financial institutions, run to a project timetable and sitting alongside the reporting a firm already performs, creating no standing periodic AML/CFT return and not extending to every obliged entity. The survey is distinct from suspicious transaction reporting to a financial intelligence unit, and distinct from the ongoing AML/CFT supervisory data a national authority may already collect through a local periodic AML/CFT data request. Our note on the CSSF AML/CFT data collection covers one such national exercise that a Luxembourg firm would run in parallel.
Interactions run in two directions. The selection outcome connects to AMLA’s wider supervisory architecture, including its central AML/CFT database, EuReCA, into which supervisors feed information on material weaknesses and measures; our EuReCA reporting guide sets out that channel. On the framework side, the taxonomy travels with the EBA package that also carries third-country branch reporting, described in our reporting framework 4.3 TCB and AMLA package guide. And because the selection decides who moves from national to EU-level supervision, it feeds into the home-host cooperation arrangements set out in our AMLA home-host supervisory cooperation guide.
Recent and upcoming changes: from the 2026 test run to the next taxonomy version
The exercise has moved quickly through 2026. The model-calibration collection opened in March 2026 with an April deadline. The identification step followed over the summer, with a June webinar and an August submission date from supervisors to AMLA, and a provisional list of eligible entities due to be finalised by the end of September 2026. The framework 4.3 taxonomy arrived in July 2026 as preparation material.
The change a reporting team should watch is the next taxonomy version. AMLA has signalled a revision expected after the framework 4.3 release, refining the templates on the experience of the 2026 data collection, adding two new data points and sharpening the unavailable-versus-zero treatment. The heavier substantive data collection from eligible entities is scheduled for early 2027, ahead of the selection process that starts by 1 July 2027. A firm that maps to the current taxonomy should therefore plan a second pass once the revised version is published.
Frequently Asked Questions
Does a firm that never submits anything directly to AMLA still count as reporting under this exercise?
Yes. The reporting obligation runs to the national supervisor, which organises the collection from obliged entities in its remit and transmits the data to AMLA. A firm meets its obligation by giving its competent authority accurate data on that authority’s timetable; the onward submission to AMLA is the supervisor’s step.
If a group operates in exactly six Member States only through the freedom to provide services, is it in scope?
The eligibility gate is operating in at least six Member States, including the home Member State, through establishments or under the freedom to provide services, so freedom-to-provide-services activity can count. The December 2025 draft RTS final report under Article 12(7) proposes materiality thresholds for freedom-to-provide-services activity, set in the draft at more than 20,000 resident customers or more than EUR 50 million of annual incoming and outgoing customer transactions in a Member State, meaning negligible cross-border volumes may not carry the same weight as a substantive presence under the proposed methodology; those thresholds remain subject to Commission adoption. Whether a specific footprint clears the gate is a determination for the supervisor and AMLA on the data, and a firm should not assume the answer either way.
We were asked to complete the template as part of a representative sample. Does that mean we will be directly supervised?
No. The representative sample exists to calibrate AMLA’s scoring models and is drawn from entities expected to remain under national supervision. Inclusion in the sample carries no implication of selection for direct supervision.
What should we do with the framework 4.3 files we already built?
Keep them as preparation and test material and do not submit them. The published 4.3 components must not be sent to any national competent authority, the EBA, or AMLA. Use the build to validate internal mappings, then plan to re-check against the revised taxonomy version once it is published.
How is this different from the AML/CFT data our national supervisor already collects?
The AMLA collection is a selection instrument tied to a fixed 2026 to 2027 calendar and aimed at identifying the highest-risk cross-border institutions for EU-level supervision. A national periodic AML/CFT data collection is a standing supervisory return set by the local authority. A firm can be subject to both, and the two data sets are not interchangeable.
Can a firm challenge its inclusion in, or exclusion from, the pool?
The AMLA Regulation sets the selection mechanism and the criteria, and selection follows from the risk scores AMLA derives. This article does not state a specific appeal route because the sources reviewed here do not set one out; a firm with a concern about how it has been assessed should raise it with its national supervisor and take legal advice on the remedies available under the Regulation.
Does this collection cover non-financial obliged entities, such as lawyers or trust and company service providers?
The direct supervision selection targets credit and financial institutions with a cross-border footprint. Non-financial obliged entities are supervised through other arrangements in the AML/CFT framework and are not the population this selection exercise is built around.
Related Articles
- AMLA Direct Supervision: Which Entities Are Selected: how the identification and selection of directly supervised obliged entities works.
- AMLA Direct Supervision: Luxembourg Eligible Entities: what the eligibility criteria mean for Luxembourg-based firms.
- EBA Reporting Framework 4.3: TCB and AMLA Package: the release that carries the AMLA taxonomy and third-country branch reporting.
- EuReCA Reporting and AMLA Joint Controllership: how supervisors feed AML/CFT weaknesses into AMLA’s central database.
- AMLA Home-Host Supervisory Cooperation RTS: how home and host supervisors coordinate on cross-border AML/CFT supervision.
- EBA Reporting Framework 4.4 Draft Technical Package: the next framework release firms should track for taxonomy changes.
Key Takeaways
- The 2027 AMLA risk assessment data collection supports the first selection cycle for up to 40 cross-border credit and financial institutions or groups to be directly supervised from 2028; it is not a standing periodic return, but the statutory selection process recurs every three years and direct supervision begins six months after publication of the selected-entity list.
- The scope gate is the six-Member-State threshold: credit and financial institutions, including groups, operating in at least six Member States, including the home Member State, through establishments or the freedom to provide services. Firms report to their national supervisor, which transmits to AMLA; no entity files data to AMLA directly.
- The published framework 4.3 taxonomy is preparation material only and must not be submitted to any national competent authority, the EBA, or AMLA.
- AMLA set 15 August 2026 as the date by which it would collect identification data from national supervisors, and the provisional list of eligible entities is expected by end-September 2026. AMLA’s explainer schedules the final data collection from eligible entities for January to March 2027. The Regulation requires AMLA to commence the first selection process by 1 July 2027 and conclude it within six months of the actual commencement date.
- Keep unavailable values and true zeros distinct in the template. The next taxonomy version sharpens that distinction and adds two new data points. Plan a mapping re-check once the revised version is published.
Sources and References
- Regulation (EU) 2024/1620 of 31 May 2024 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA Regulation), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1620/oj
- Directive (EU) 2024/1640 of 31 May 2024 (sixth Anti-Money Laundering Directive, AMLD6), EUR-Lex: https://eur-lex.europa.eu/eli/dir/2024/1640/oj
- AMLA, “Updated taxonomy for the 2027 risk assessment data collection”: https://www.amla.europa.eu/news-media/news-articles/updated-taxonomy-2027-risk-assessment-data-collection_en
- AMLA, “AMLA takes next step toward 2027 selection of entities for direct supervision”: https://www.amla.europa.eu/amla-takes-next-step-toward-2027-selection-entities-direct-supervision_en
- AMLA, “AMLA launches data collection exercise to test risk assessment models”: https://www.amla.europa.eu/amla-launches-data-collection-exercise-test-risk-assessment-models_en
- AMLA, “Explainer: Towards AMLA’s direct supervision”: Explainer – Direct Supervision by AMLA (PDF)
- European Banking Authority, reporting framework release 4.3 (taxonomy, Data Point Model 2.0, filing rules): https://www.eba.europa.eu/risk-and-data-analysis/reporting-frameworks/reporting-framework-43
- A&L Goodbody, “AML reform progresses with final RTS on risk assessments and direct supervision selection”: https://www.algoodbody.com/insights-publications/aml-reform-progresses-with-final-rts-on-risk-assessments-and-direct-supervision-selection
- AMLA, Final Report, Draft RTS under Article 12(7) AMLAR, 16 December 2025: https://www.amla.europa.eu/system/files/2025-12/2.1_20251216_Final%20report%20-%20RTS%20under%20art.%2012(7)%20AMLAR.pdf
What to have ready before the 2027 collection
The next concrete task is a data-mapping build. Map the firm’s customer, product, channel, and geography data to the framework 4.3 structure now, treating the current taxonomy as a test target and nothing more, then hold that mapping open for the revised version expected after the 4.3 release. Keep a written rationale for every blank and every zero, because the unavailable-versus-zero distinction is where residual risk scores quietly go wrong. When the substantive request reaches eligible entities in early 2027, the firms that treated 2026 as preparation rather than as the finish line will be the ones ready to answer it.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
