10 December 2025
AMLA ¦ Summary of the 5th Meeting of the General Board in Supervisory Composition
AMLA sets a more data-driven course for EU anti-money laundering supervision
The European Union’s Anti-Money Laundering Authority (AMLA) is moving towards a more harmonised supervisory model, with risk assessment, data quality and cross-border cooperation at its centre.
A key step is the approval of two draft Regulatory Technical Standards for submission to the European Commission. The first concerns a common methodology for assessing risks under Article 40(2) of the applicable framework. The second addresses the methodology for selecting entities and determining materiality thresholds under Article 12(7).
The approach is significant because the quality of supervisory selection depends on the quality and comparability of the underlying data. Differences in national definitions, reporting practices and data structures can distort risk assessments and make cross-border comparisons unreliable. A common European methodology is intended to reduce those inconsistencies.
Some technical elements, including indicator weights and thresholds, will remain outside the standards. This would allow the methodology to be adjusted as evidence accumulates and supervisory experience develops. A dedicated working group is expected to test and calibrate the model during 2026 using sample data from national authorities. The first selection cycle is planned for 2027.
AMLA also intends to publish a common taxonomy, data templates and validation rules. A centralised approach to data collection and data-quality controls should help identify inconsistencies before they affect supervisory decisions.
Predicate offences remain central to effective supervision
A risk-based AML framework cannot be effective if it focuses only on compliance processes. It must also identify the criminal conduct that generates illicit proceeds.
Predicate offences such as fraud, corruption, drug trafficking, tax-related crime, trafficking in human beings and cybercrime produce different transaction patterns and laundering risks. A card-fraud scheme, for example, may involve rapid movement of funds through payment accounts, mule networks and cash-out channels. Crypto-asset activity can introduce additional risks, including the use of mixers, privacy-enhancing tools, unregulated intermediaries and rapid transfers across jurisdictions.
The supervisory cases presented by national authorities illustrate why risk assessment must be connected to actual criminal typologies. Enforcement action in the crypto-asset sector, responses to a major card-fraud scheme and measures addressing systemic reporting weaknesses all point to the same conclusion: institutions need to understand not only whether controls exist, but whether those controls detect and disrupt the proceeds of specific predicate offences.
This requires meaningful transaction monitoring, credible suspicious transaction reporting and timely escalation. A formal policy that does not identify the relevant proceeds, typologies and customer exposure will provide limited protection against money laundering.
Crypto-assets and fraud create immediate supervisory pressure
The inclusion of crypto-asset enforcement and card fraud among the practical cases discussed reflects two areas of continuing concern.
Crypto-asset services can facilitate the rapid movement and layering of criminal proceeds. Risks may arise from customer anonymity, complex ownership structures, cross-border service models and reliance on third-party providers. Supervisors will need to assess whether firms can identify source-of-funds concerns, trace transactions across blockchain networks and respond appropriately to exposure involving high-risk platforms or wallets.
Card fraud presents a different but equally important challenge. Proceeds may be fragmented across numerous accounts, transferred through payment institutions or withdrawn quickly through cash and digital channels. Where fraud networks use money mules, beneficial ownership analysis and customer risk assessment become especially important. Weak reporting can allow the laundering stage to continue even when the original fraud has been detected.
The practical value of case-sharing lies in translating enforcement experience into supervisory expectations. It can also help authorities distinguish isolated control failures from weaknesses that affect an entire business model or sector.
Reporting failures and outsourcing weaknesses remain recurring themes
Systemic deficiencies in suspicious transaction reporting continue to undermine the fight against money laundering. Under-reporting, delayed reporting, poor-quality narratives and weak links between transaction monitoring and investigations can prevent financial intelligence units and law enforcement agencies from identifying wider criminal networks.
Reporting should explain why activity is suspicious, identify the suspected predicate offence where possible and set out the relevant flow of funds. Generic references to unusual activity are unlikely to support effective financial intelligence.
Outsourcing creates a related risk. Firms may delegate monitoring, customer due diligence or other operational functions while retaining full responsibility for compliance. Weak oversight of outsourced providers can result in inconsistent procedures, incomplete data, unclear escalation routes and failures to preserve audit trails.
Supervisors are therefore likely to examine whether institutions understand their outsourced arrangements in practice, rather than relying solely on contractual assurances. Governance, access to data, quality testing and senior management accountability are essential controls.
Direct supervision will receive a common cooperation framework
The General Board approved the publication of a consultation paper and draft Implementing Technical Standard on cooperation arrangements for direct supervision. The consultation will run for six weeks, with a final report expected in the second quarter of 2026.
Effective direct supervision of cross-border institutions depends on clear allocation of responsibilities between AMLA and national authorities. Without agreed procedures for information exchange, supervisory planning, access to records and follow-up action, firms may face fragmented requests while material risks remain insufficiently addressed.
A common cooperation framework should also support more consistent treatment of entities operating across several Member States. This is particularly important where predicate-offence risks and laundering channels extend beyond the jurisdiction in which a transaction is first identified.
Thematic reviews will first focus on comparability
AMLA’s 2026 plan for thematic reviews will prioritise methodology and process. Joint reviews of higher-risk areas may follow from 2027.
A major obstacle is the lack of consistency in how authorities define review subjects and obliged entities. If one jurisdiction assesses a particular business line while another uses a broader sectoral category, the results cannot be compared reliably. Common definitions, scopes, questions and timelines are therefore being treated as prerequisites for meaningful convergence.
Thematic reviews should provide more than a description of technical compliance. Their value will depend on whether they assess how controls perform against real risks, including the laundering of proceeds from identifiable predicate offences. Reviews that examine customer profiles, transaction flows, reporting decisions and investigative outcomes are more likely to reveal weaknesses that matter in practice.
Enforcement capacity is being developed alongside policy work
A working group on enforcement is being established on an accelerated basis. This is an important institutional development because supervisory standards have limited effect without credible follow-up.
Enforcement should address failures that are material, repeated or connected to significant exposure to criminal proceeds. It should also support proportionality. A minor procedural deficiency and a control failure that allows proceeds from organised fraud or corruption to enter the financial system should not be treated as equivalent.
Clear internal procedures, reporting lines and committee arrangements are being put in place to support this work. Questions remain around representation, participation, document circulation and observer involvement, but the overall direction points towards a more structured enforcement function.
The wider implication for obliged entities
The emerging supervisory model will place greater weight on evidence, data quality and the connection between AML controls and criminal risk.
Firms should be prepared to demonstrate how their risk assessments reflect the predicate offences relevant to their customers, products and markets. They should be able to explain how transaction monitoring detects typologies linked to fraud, corruption, cybercrime, drug trafficking and other sources of illicit proceeds. They should also be able to show that suspicious transaction reports are complete, timely and useful to competent authorities.
Institutions operating through outsourced arrangements or across multiple jurisdictions will face particular scrutiny. Governance must provide clear accountability, reliable access to information and consistent escalation practices.
European AML supervision is becoming more coordinated, more data-dependent and more focused on practical outcomes. The central test will not be whether a firm has adopted the required policies, but whether it can identify, report and disrupt the laundering of criminal proceeds before those proceeds are integrated into the legitimate economy.