Passed by the EU Parliament in 2024, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) aims to centralize how EU financial institutions manage legal compliance, customer due diligence (CDD) and Know Your Customer (KYC) requirements. As of July 10, 2027, AMLA will become the central anti-money laundering/countering the financing of terrorism (AML/CFT) supervisor and rule maker for EU states. The European Banking Authority has already transferred all AML/CFT mandates to AMLA, concluding the EBA’s standalone AML/CFT mandate.
The goal of centralization suggests simplification, and while complying with one regulatory authority beats chasing three or four, it’s already clear that AMLA will introduce new levels of complexity of its own.
As primary authority, AMLA will impact every touchpoint for EU AML enforcement, from Financial Intelligence Units (FIUs) to national supervisors. The organization recently finalized standards to help Financial Intelligence Units (FIUs) share information more quickly and consistently. It also provided draft technical standards to codify the relationship between AMLA and national supervisors.
Another critical aspect of AMLA is its direct supervision of an estimated 40 large financial institutions. The 40 will be selected in cooperation with national supervisors. Their selection will be based on factors including cross-border activity and inherent risk to financial crime. Direct supervision is expected to start in January 2028. This is important to watch because the direct supervision of these large institutions will signal the regulatory posture toward all others.
Local Interpretation
While AMLA becomes the central supervisor and rule maker for EU AML/KYC/CFT enforcement, the door for local interpretation remains open. For instance, one AML directive defines the mechanisms member states must put in place to prevent the financial system from being used for money laundering or financing terror.
Each Member State shall designate an authority or establish a mechanism to coordinate the national response to the risks referred to (above). The identity of that authority or the description of the mechanism shall be notified to the Commission.1
The potential variants in these mandated “authorities,” and their respective policies, multiplied across 27 EU member states, illustrate the complexity financial organizations will have to navigate even within a more uniform rule set imposed by AMLA.
How to prepare
AMLA has published its Single Programming Document for 2026-2028 that sets priorities and timelines, providing a roadmap for the market. Its 2026 mandates include:
- Direct supervision selection process: minimum activities for determining when a credit or financial institution operates in a Member State other than where it is established and the methodology for classifying risk profiles.
- Benchmarks and methodology for assessing and classifying the risk profile of obliged entities and the frequency of reviews of that risk profile (financial sector).
- Cooperation for the purposes of direct supervision including conditions under which financial supervisors assist AMLA, the periodic risk assessment process and the respective roles of supervisors and AMLA, working arrangements for the transfer of supervisory tasks, procedures for preparation and adoption of decisions and rules and arrangements for joint supervisory teams.
- Indicators to classify the level and gravity of breaches of AML/CFT obligations, criteria to be taken into account when determining pecuniary sanctions or administrative measures, and a methodology for the application of periodic penalty payments.
As AMLA moves forward, there are proactive steps financial institutions can take to prepare for the transition to the new framework. EY provides the following recommendations.
- Conduct a comprehensive gap analysis: Map current AML policies and procedures against the forthcoming RTS to identify any areas where legal compliance gaps exist.
- Assess technology readiness: Invest in advanced, AI-driven transaction monitoring systems, real-time sanctions screening and eIDAS-compliant onboarding solutions.
- Update governance structures: Prepare for new compliance roles and promote the harmonization of AML frameworks across all group entities.
- Integrate with EU registers: Enable systems to connect to centralized beneficial ownership and account registers, as required by the new regulations.
- Build a strong compliance culture…compliance into daily operations fosters a culture of vigilance and accountability.2
A new EU regulator, new authorities to monitor, new sources of guidance to consider… these all require automated tools that continuously track, categorize, and contextualize regulatory developments. AscentAI provides the AI tools trained on regulatory data supported by human oversight that helps ensure accuracy. You’ll not only have near real-time access to regulatory developments, but also the tools and context required to seamlessly operationalize compliance throughout the organization.
HAVE QUESTIONS? Learn more about orchestrating regulatory change throughout your organization with AscentAI.


