16 December 2025
AMLA ¦ Final Report on Draft RTS on the Assessment of the Inherent and Residual Risk Profile of Obliged Entities
AMLA finalises the common methodology for rating the ML/TF risk of financial institutions
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has finalised draft regulatory technical standards (RTS) under Article 40(2) of the Anti-Money Laundering Directive (AMLD), Directive (EU) 2024/1640, on how supervisors assess and classify the inherent and residual money laundering and terrorist financing (ML/TF) risk profile of obliged entities. The RTS covers credit and financial institutions and introduces a single, largely automated scoring model built on common datapoints, with fixed review cycles. It is proposed to apply from 31 December 2027, and supervisors will have to complete their first assessments within nine months of that date.
One methodology instead of 27
Supervisors’ approaches to entity-level ML/TF risk assessment currently diverge across Member States, so their results cannot be compared. The number of datapoints requested varies widely, which imposes disproportionate costs on institutions operating across borders and distorts competition. Divergent assessments also mean that supervisory resources do not consistently go to the institutions that present the highest risk.
The RTS replaces this with a fully harmonised methodology meant to be comparable, effective in steering supervisory strategies and inspection plans toward the highest-risk entities, and proportionate in its data demands. The scores will feed directly into how often and how intensively an institution is inspected. They also matter for AMLA itself, whose selection of institutions for direct supervision relies on a separate but related risk methodology.
A common, limited set of datapoints
The assessment rests on a common set of datapoints listed in an annex. A core set applies to all institutions and is complemented by sector-specific datapoints for credit institutions, life insurers, e-money and payment institutions, bureaux de change, investment firms, asset management companies, crypto-asset service providers and others. According to AMLA, most entities will need to provide no more than 100 to 150 datapoints, significantly fewer than most supervisors request today. Supervisors keep their right to obtain other data for on-site and off-site supervision.
The RTS does not prescribe where the data must come from. Supervisors may collect it from the institutions themselves, from external auditors, from prudential supervisors, from financial intelligence units or from other public bodies, which could reduce the reporting burden. The assessment uses quantitative data where possible and evidence-based supervisory judgement. Institutions’ self-assessments of their own risk play no part.
Inherent risk: customers, products, geography and channels
Inherent risk is the ML/TF risk an institution faces because of its customers, products, services and transactions, the jurisdictions in which it operates and the distribution channels it uses, before any mitigation. The inherent risk indicators are grouped in four categories reflecting those risk factors.
The customer datapoints show what supervisors will look at: customers by country, politically exposed persons and legal entities with PEP beneficial owners, legal entities with complex corporate structures, customers in high-risk activities, legal entities with beneficial owners resident outside the EEA, customers with cross-border transactions involving non-EEA countries, walk-in customers and occasional transactions, and customers subject to requests from the FIU. The products and services category is divided into sub-categories such as payment accounts, virtual IBANs and re-issued IBANs, prepaid cards, lending, private banking, trade finance, crypto-asset activity and investment funds, each with its own volume and value datapoints.
Several of these indicators map directly onto well-known laundering typologies. Virtual IBANs used by non-customers, multiple prepaid cards per customer, real estate loans repaid by third parties, prematurely repaid loans and cash-collateralised lending all appear as datapoints, reflecting their use in placement and layering schemes.
How the scores are calculated
Each inherent risk indicator receives a score from 1 (lowest risk) to 4 (highest risk) based on predetermined thresholds. Indicators are combined into sub-category and category scores by weighted arithmetic average, with weights from 1 to 5 according to risk significance. The categories are then combined into an inherent risk score, with higher-scoring categories carrying more weight, so that one high-risk area is not diluted by low scores elsewhere.
The final score converts into four classes: low (below 1.75), medium (1.75 to below 2.5), substantial (2.5 to below 3.25) and high (3.25 or above). The precise thresholds and weights are deliberately left out of the RTS. AMLA will set and update them for each review cycle so that the model can follow evolving risks, and it will monitor their application across Member States. The sector-specific weights are to take account of the Commission’s supranational risk assessment.
Controls quality and the residual risk profile
The second step assesses the quality of the institution’s AML/CFT controls in seven categories: governance and training, internal controls and reporting, the business-wide risk assessment, customer due diligence and ongoing monitoring, transaction monitoring and suspicious activity reporting, targeted financial sanctions, and group-wide arrangements. Each indicator is scored from 1 (highest quality) to 4 (lowest quality) and combined by weighted average, with weaker categories weighing more. The result is classified as very good (A), good (B), moderate (C) or poor (D).
Automated scoring alone cannot reliably measure the effectiveness of controls. Supervisors may therefore adjust a category score based on their own assessments, such as on-site inspections, thematic reviews and off-site analyses, or on an external auditor’s assessment. Every adjustment must be justified and recorded.
The residual risk score combines both results. Where the controls score is worse than the inherent risk score, the residual score equals the inherent risk score. Where controls are as good or better, the residual score is the average of the two. Strong controls can therefore lower the residual rating, while weak controls leave it at the level of inherent risk. The residual score is classified on the same four-level scale as inherent risk.
Limited room for supervisory adjustment
Supervisors may adjust an inherent risk score where national specificities or other information obtained through supervision show that the automated result does not reflect the institution’s real exposure. The adjustment is limited to one risk level up or down. An upward adjustment sets the score at the minimum of the higher level, a downward adjustment at the maximum of the lower level, and both must be justified and recorded.
The cap protects comparability. Supervisors keep some judgement, yet they cannot override the model wholesale, which makes it harder for a national authority to classify a high-risk institution as low risk, or the reverse, without evidence.
Annual reviews, triennial for the smallest
Risk profiles must be reviewed every year, with each assessment completed by 30 September. A three-year cycle applies to institutions with no more than five full-time equivalent employees in the Member State, to those carrying out only defined lower-risk activities such as certain insurance and credit intermediation, insurance business limited to non-redeemable, credit protection or low-premium life products, restricted investment services or certain lending activities, to branches set up by collective investment undertakings in another Member State, and to institutions whose residual risk was last classified as low.
Major events trigger an ad hoc review within four months of the supervisor becoming aware of them. These include significant changes to the business model, the identification of significant weaknesses in AML/CFT systems and controls, and an institution becoming a significant supervised entity, or part of a significant group, under the Single Supervisory Mechanism, in each case where a material change in the risk profile may follow.
Financial sector first
The mandate covers financial and non-financial obliged entities, but AMLA has chosen a phased approach. This RTS applies only to credit and financial institutions and their supervisors. A separate RTS for the non-financial sector will follow, giving AMLA more time to consult and define suitable datapoints for professions and businesses with very different business models.
The text is based on the EBA’s draft, which was consulted on between March and June 2025 and submitted to the Commission in October 2025. AMLA adopted it as its own with limited amendments to reflect the narrower scope, add an application date and clarify consistent application. Because the substance did not change, AMLA did not consult again.
What institutions should prepare
For Luxembourg’s banks, payment and e-money institutions, investment firms, fund management companies and crypto-asset service providers, the RTS defines the data supervisors will expect to have from the end of 2027. Institutions should check whether they can produce the relevant datapoints reliably and consistently, particularly for complex structures, non-EEA beneficial owners, PEP exposure, virtual IBANs, distributors and cross-border flows.
Because inherent risk is scored automatically from predetermined thresholds, inaccurate or inconsistent reporting directly affects an institution’s classification and therefore the intensity of supervision it attracts. On the controls side, findings from inspections and external audits can move category scores, so open remediation points will carry through into the risk rating. The controls datapoints cover, among other things, the approval date of the business-wide risk assessment, training coverage by staff category, the transaction monitoring system and the time taken to implement new targeted financial sanctions, so weaknesses there will show up in the score.
Dive deeper
- AMLA ¦ Final Report ¦ Draft RTS on the assessment of the inherent and residual risk profile of obliged entities (RTS AMLD 40(2)) (pdf) ¦ Link