13 October 2025
AMLA ¦ Summary of the 4th Meeting of the General Board in Supervisory Composition
AMLA’s supervisory framework takes shape around risk, data and predicate offences
The European Union’s new Anti-Money Laundering Authority (AMLA) is moving from institutional set-up to operational delivery. Recent supervisory planning has placed three issues at the centre of its work: developing consistent risk methodologies, improving the quality of supervisory data and creating a proportionate framework for both financial and non-financial obliged entities.
The direction of travel matters for compliance professionals because effective anti-money laundering controls depend on more than procedural compliance. They must identify how criminal proceeds are generated, moved and concealed. That requires a clear understanding of predicate offences, sector-specific vulnerabilities and the transactions that connect illicit activity to the legitimate financial system.
A broader supervisory perimeter for non-financial sectors
Responsibility for work relating to the non-financial sector has shifted to the Anti-Money Laundering Authority. Preparatory work is focused on regulatory standards covering risk assessment methodologies, the seriousness of breaches and customer due diligence (CDD).
The non-financial sector cannot simply be regulated through frameworks designed for banks and other financial institutions. Lawyers, accountants, trust and company service providers, real estate professionals, casinos and other designated businesses face different exposure to criminal proceeds. Their role may involve company formation, asset acquisition, escrow arrangements, legal advice, cash-intensive activity or the transfer of ownership. These functions can be exploited to disguise the proceeds of corruption, fraud, tax crime, sanctions evasion, trafficking and organised criminal activity.
A proportionate approach therefore requires more than applying identical controls across all sectors. Risk assessments should reflect the services provided, the customer base, delivery channels, geographic exposure and the types of predicate offence most relevant to each activity. A real estate professional, for example, may face a different risk profile from a company service provider, even where both encounter complex ownership structures and cross-border funds.
The planned use of working groups, expert input and public consultation should help prevent rules from being reduced to a common minimum. Sector knowledge will be essential if the new standards are to distinguish between genuine risk indicators and administrative formalities that produce limited intelligence.
The predicate offence must remain central to risk assessment
Money laundering is not an independent source of wealth. It is the process through which assets connected with a predicate offence are converted, transferred, concealed or integrated into the lawful economy. Supervisory models that focus only on customer identity, transaction volume or geographic exposure may miss the underlying criminal conduct.
A credible risk methodology should therefore connect laundering indicators with the offences that generate proceeds. Fraud may produce large numbers of apparently ordinary payments, while corruption may involve politically exposed persons, intermediaries and opaque corporate vehicles. Drug trafficking can generate cash deposits, trade-based transfers or investments in cash-intensive businesses. Environmental crime, trafficking and cybercrime may involve payment platforms, virtual assets, front companies and rapidly changing cross-border structures.
This connection is particularly important for non-financial businesses. A suspicious property purchase may be linked to corruption or organised crime. A complex corporate arrangement may conceal proceeds from fraud or tax offences. Professional services may be used to create distance between the offender, the asset and the ultimate beneficiary. Controls that identify only formal ownership, without examining control, source of wealth and the commercial rationale for a transaction, may fail to detect the laundering mechanism.
Supervisory expectations are likely to develop towards more granular assessments of how firms identify these links. The quality of a control framework should be judged not only by the number of customer files reviewed, but by whether the framework can detect plausible pathways from a predicate offence to the movement or use of criminal proceeds.
A common risk model, without mechanical compliance
The development of a uniform financial-sector risk model is intended to support supervisory convergence and the selection of institutions for direct supervision. The key challenge will be calibration. Thresholds, weighting and scoring criteria can materially affect which firms are considered high risk and how supervisory resources are allocated.
A model that is too general may fail to distinguish between different business models. A model that is too rigid may encourage firms to treat risk scoring as a mechanical exercise. Effective supervision needs comparable outcomes, but it must also allow for institution-specific circumstances and credible evidence that changes the risk assessment.
The same principle applies to customer due diligence. Requirements should be risk-based and proportionate, while still addressing the circumstances in which standard measures are insufficient. Enhanced due diligence should be directed towards higher-risk situations, including unexplained wealth, complex ownership, high-risk jurisdictions, unusual transaction patterns and links to known or suspected criminal activity.
The objective is not to impose the greatest possible volume of documentation. It is to obtain information that enables an obliged entity to understand the customer, the beneficial owner, the purpose of the relationship, the expected activity and the source of funds or wealth where relevant. Excessive requirements can obscure material information by generating large quantities of low-value records.
Supervisory data will influence enforcement and risk prioritisation
The central AML/CFT database is expected to become an important part of the supervisory system. Work is continuing on the transfer of reporting tools, systems and supporting documentation, as well as on technical requirements that will allow national authorities to automate data submissions.
Members have called for more detailed reporting on sanctions and breaches. That request has direct implications for enforcement. Aggregate figures may show how many breaches have been identified, but they do not necessarily reveal whether failures concern customer due diligence, suspicious transaction reporting, beneficial ownership, internal controls, governance or the handling of predicate offence risks.
Greater granularity can help identify recurring weaknesses across sectors and jurisdictions. It may also allow supervisors to distinguish isolated procedural failures from systemic deficiencies that enable criminal proceeds to enter or circulate through the financial system. Data protection safeguards will remain necessary, particularly where supervisory information includes personal data, intelligence on suspected criminal conduct or information concerning enforcement actions.
Data quality will be as important as data quantity. Inconsistent definitions, incompatible reporting formats or incomplete information can undermine comparisons and distort supervisory priorities. Clear technical specifications and common reporting standards will be needed if the database is to support reliable risk analysis.
Thresholds for linked transactions remain a practical fault line
Differences in national interpretation concerning thresholds and criteria for business relationships, occasional transactions and linked transactions illustrate the difficulty of achieving consistent application across the EU.
The issue is operationally significant. Customers may structure transactions below an apparent threshold, divide payments among related parties or use several entities and service providers to avoid detection. If authorities apply different approaches to identifying connected activity, similar conduct may trigger different due diligence or reporting obligations depending on the jurisdiction involved.
The solution should combine clear criteria with a risk-based assessment. Formal thresholds can provide a useful starting point, but they should not prevent firms from considering transactions that are connected by customer, beneficiary, purpose, timing, funding source or economic rationale. A series of apparently separate payments may form part of a single laundering operation even where no individual transaction appears suspicious in isolation.
This is also where predicate offence analysis becomes practical. Linked transactions may reflect the layering of fraud proceeds, the movement of bribery payments through intermediaries or the fragmentation of funds generated by trafficking and organised crime. Supervisory guidance should help firms identify these patterns without turning every unusual transaction into an automatic suspicion.
Thematic reviews will test how controls work in practice
Authorities are preparing a consolidated overview of thematic reviews planned for 2026. Thematic supervision can provide a more focused assessment than routine inspections because it allows authorities to compare how multiple firms address the same risk.
Potentially significant themes include the detection of proceeds from fraud and cybercrime, the use of professional intermediaries, beneficial ownership transparency, source-of-wealth controls, transaction monitoring and the quality of suspicious transaction reports. A well-designed review can identify not only whether a policy exists, but whether staff apply it consistently and whether escalation decisions are supported by evidence.
The results may also clarify what supervisors consider an effective response to predicate offence risk. For example, firms may need to demonstrate how they incorporate law enforcement information, typologies and adverse media into customer risk assessments, how they update profiles when a customer’s activity changes and how they decide whether to exit a relationship or file a report.
Internal committees will support the next phase of implementation
Two internal committees have been approved: one focused on private-sector standards and another on the functioning of the supervisory system. Their planned launch at the beginning of 2026 is intended to support strategic coordination without duplicating existing working groups.
The structure should help bring together expertise from financial and non-financial supervision. That is important because laundering schemes frequently cross institutional boundaries. A company may be established through a professional intermediary, funded through a bank, used to acquire property and connected to an overseas entity. Effective oversight must follow the flow of funds and control, rather than stopping at the boundary of a particular sector.
The committees will also need to prioritise deliverables. The breadth of the regulatory programme creates a risk that important technical work becomes fragmented. Clear sequencing, consultation and communication with national authorities and industry will be necessary to ensure that firms can prepare for new requirements and that supervisors apply them consistently.
What firms should be watching
The emerging framework points towards closer scrutiny of the connection between risk assessment, customer due diligence, reporting and enforcement. Firms should expect greater attention to the quality of their methodology, the reasons supporting customer risk classifications and the extent to which controls address actual laundering scenarios.
Businesses operating in the non-financial sector should review whether their frameworks reflect the predicate offences most relevant to their services. Financial institutions should assess whether transaction monitoring and customer due diligence can identify connected activity across accounts, entities and jurisdictions. All obliged entities should also consider whether their data can be reported in a consistent, auditable format and whether breaches are recorded with enough detail to support meaningful supervisory analysis.
A robust AML/CFT framework must explain how illicit wealth could enter a business, how it could be moved or disguised and which controls would detect the activity. The success of the new supervisory model will depend on whether it turns that principle into consistent, sector-sensitive practice across the European Union.