AMLA ¦ Summary of the 7th Meeting of the General Board in Supervisory Composition

AMLA ¦ Summary of the 7th Meeting of the General Board in Supervisory Composition

AMLA sharpens the EU’s response to money laundering and predicate crime

The European Anti-Money Laundering Authority (AMLA) is moving from institutional build-up to operational delivery. Its supervisory agenda for 2026 places particular emphasis on the non-financial sector, customer due diligence, enforcement consistency, risk assessment, and coordinated thematic supervision.

The underlying policy objective is to improve the ability of supervisors and obliged entities to identify, prevent and disrupt the laundering of proceeds generated by predicate offenses. That requires more than formal compliance. It requires reliable customer information, proportionate but effective controls, consistent sanctions and better-quality supervisory data across the European Union.

The non-financial sector remains a major supervisory challenge

The non-financial sector covers fifteen categories of obliged entities and more than two million entities across the Union. It includes professions and businesses with very different operating models, levels of AML/CFT maturity and access to compliance expertise. National supervision is also fragmented, involving several hundred authorities and professional or self-regulatory bodies.

This scale and diversity create vulnerabilities for the concealment and movement of criminal proceeds. Lawyers, accountants, trust and company service providers, real estate professionals, gambling operators, dealers in high-value goods and other non-financial businesses may be used to create legal structures, purchase assets, move cash or give illicit funds an appearance of legitimacy.

Supervisory effectiveness in these sectors remains uneven. Awareness of obligations is limited in some areas, while national approaches differ significantly. The result is a risk of regulatory gaps and inconsistent responses to the same laundering typologies.

AMLA’s planned response combines capacity building, coordinated outreach and greater supervisory convergence. The approach is intended to remain proportionate, particularly for smaller entities and sectors that are newly subject to the harmonised framework. Proportionality, however, is not meant to preserve weak controls or delay implementation. The central test will be whether measures are capable of identifying and addressing the risks arising from predicate offenses.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"AMLA’s 2026 agenda strengthens the EU’s response to money laundering by targeting material control failures, improving customer due diligence and promoting consistent supervision across financial and non-financial sectors. Particular attention is being given to the predicate offenses that generate illicit proceeds, including fraud, corruption, tax crimes and organised crime.

The planned consultations and risk assessment exercise will shape enforcement expectations for obliged entities and national authorities. Effective implementation will depend on reliable data, proportionate controls and the ability to identify linked transactions, beneficial ownership structures and cross-border laundering patterns."

Enforcement standards will focus on material failures

AMLA supported the launch of a public consultation on regulatory technical standards for enforcement in the non-financial sector. The proposed standards would create common indicators for assessing the seriousness of breaches, criteria for pecuniary sanctions and administrative measures, and a methodology for periodic penalty payments.

The framework is expected to use a four-level scale for breach gravity while preserving supervisory discretion. This is important because AML/CFT failures do not all carry the same risk. A technical defect with no meaningful effect on risk management should not automatically attract the same response as a failure that enables the concealment of proceeds from fraud, corruption, drug trafficking, trafficking in human beings or other predicate crimes.

The draft was amended to clarify that failures in AML/CFT systems, controls or policies must be material for the relevant indicator to apply. That clarification should help prevent automatic or purely formal enforcement. At the same time, firms should not interpret materiality as a narrow safe harbour. A control failure may be material where it affects customer identification, beneficial ownership information, transaction monitoring, suspicious transaction reporting or the escalation of high-risk relationships.

The standards will also address responsible natural persons, including senior management. This reflects a broader enforcement principle: responsibility should not stop at the legal entity where management decisions, insufficient resources or a tolerance of control weaknesses contribute to exposure to money laundering.

A one-month public consultation targeting the non-financial sector is planned, with adoption of the final standard intended by the end of June 2026 and submission to the European Commission by 10 July 2026.

Customer due diligence is not a procedural formality

AMLA also supported a three-month consultation on regulatory technical standards for customer due diligence under Article 28 of the Anti-Money Laundering Regulation. The proposed requirements cover standard, simplified and enhanced due diligence, electronic identification, remote onboarding, e-money exemptions and reliable sources for verification.

The most important point is that simplified due diligence is not an exemption from standard due diligence. Any reduction in measures must remain risk-based. Firms must therefore be able to explain why a lower-intensity approach is justified and identify the circumstances that would require a return to standard or enhanced measures.

This distinction matters in the context of predicate offenses. Criminal proceeds may be introduced through apparently low-value products, pooled accounts, retail services or remote relationships that appear limited in isolation but become significant when linked to other accounts, transactions or customers. A simplified process that prevents the institution from recognising those links can weaken the entire detection framework.

The proposed approach to collective investment undertakings has attracted particular attention. It seeks to avoid systematic look-through obligations while preserving the ability of the fund manager to obtain information where the risk warrants it. The frequency and scope of information requests would therefore depend on the specific risk being addressed.

That balance is relevant to both operational efficiency and crime prevention. A blanket requirement to examine every underlying investor may be disproportionate in some structures. Yet a fund arrangement must not become a barrier that prevents access to information when there are indicators of laundering, sanctions evasion, fraud or the use of complex ownership structures.

AMLA also intends to provide clearer expectations for alternative means of remote identification. As digital onboarding expands, weaknesses in identity verification can facilitate account opening under false identities, the use of stolen credentials and the rapid movement of criminal proceeds across borders.

Transaction thresholds and linked activity remain under review

A separate consultation will address the criteria for identifying business relationships, occasional transactions and linked transactions. The proposed standards do not introduce additional lower thresholds at this stage.

The distinction between an occasional transaction and a business relationship is central to effective AML controls. Criminals may deliberately divide activity into separate payments or use multiple counterparties to remain below internal or legal thresholds. If firms assess transactions in isolation, they may miss a connected pattern that points to money laundering or the underlying predicate offense.

High-risk cash activities received specific attention. Cash-intensive businesses can be exposed to the placement of proceeds from tax crimes, drug trafficking, corruption, illegal gambling and other offenses. The absence of a new lower threshold does not remove the need for firms to establish internal policies capable of detecting linked transactions and identifying when repeated activity amounts to a business relationship.

AMLA is also expected to clarify that internal procedures may include identifying and verifying the customer when firms assess whether transactions are linked or whether a business relationship exists. This would support more consistent treatment across sectors and jurisdictions.

Risk assessment will depend on better data

The 2026 testing and fine-tuning exercise for risk assessment methodologies will proceed in three phases. Preparatory work runs through February, data collection is planned from March to May, and calibration, sensitivity testing and benchmarking will continue from June to October.

For the first cycle, the exercise will cover financial holdings within the existing AMLD5 scope. National authorities will collect and validate data before transmission to AMLA, while AMLA will monitor completeness and quality at Union level.

Risk assessment is directly connected to the identification of predicate offenses. If data is incomplete or inconsistent, supervisors may underestimate exposure to fraud, corruption, tax offenses, organised crime, cybercrime or other sources of illicit proceeds. Poor data can also produce the opposite problem – excessive controls imposed on low-risk customers while sophisticated criminal activity remains undetected.

The exercise will therefore need to reflect different business models, cross-border groups and the position of smaller entities. Data requests must be proportionate, but proportionality cannot result in gaps that make comparisons unreliable. Strong validation, common definitions and transparent feedback will be essential.

AMLA plans to report on progress and initial findings in June and November 2026.

De-risking must not replace risk management

Joint AMLA and European Banking Authority (EBA) guidelines on de-risking are being prepared under Article 21(4) of the Anti-Money Laundering Regulation (AMLR). Technical work is expected to begin in the second quarter of 2026, with a public consultation planned for late 2026 or early 2027 and finalisation by July 2027.

De-risking occurs when institutions terminate or refuse relationships with entire categories of customers, countries or sectors instead of assessing individual risk. While institutions must protect themselves from money laundering exposure, blanket exclusions can prevent legitimate customers from accessing financial services and may push activity into less transparent channels.

A sound risk-based approach (RBA) requires institutions to distinguish between elevated risk and unacceptable risk. It should also consider whether enhanced due diligence, transaction limits, additional information or closer monitoring can manage the relationship. Closing an account may be justified in some cases, but it should not become a substitute for proper assessment.

This issue is particularly important for customers operating in sectors or jurisdictions associated with predicate offenses. Risk indicators should trigger a more careful assessment, not an automatic conclusion that every customer is connected to criminal activity.

Supervisory coordination will shape enforcement outcomes

No joint thematic reviews are planned for 2026. Instead, AMLA will focus on stronger engagement with national authorities, earlier planning and better coordination of reviews conducted at national level.

The planned approach includes comparing the scope, risk focus and timing of national reviews and considering dedicated coordination arrangements. A methodology for planning joint thematic reviews is expected in the fourth quarter of 2026, with potential joint reviews to be identified by September.

This is significant because money laundering networks operate across borders, while supervision has often remained nationally segmented. A real estate structure, payment chain or corporate arrangement may involve several Member States, yet supervisory findings can remain isolated if authorities do not share information or align their priorities.

Common survey concepts, standardised templates and better-quality information should help identify recurring weaknesses. They may also reveal where national authorities apply different interpretations to beneficial ownership, customer due diligence, suspicious transaction reporting or the treatment of linked transactions.

The next phase will test whether convergence produces results

The 2026 programme sets out a substantial implementation agenda. Consultations on enforcement, customer due diligence and thresholds will shape the technical framework. Risk assessment testing will generate data for supervisory calibration. Work on de-risking will address the boundary between prudent controls and unjustified exclusion. Coordination with national authorities will determine whether Union-level supervision can identify cross-border patterns more effectively.

For obliged entities, the direction of travel is clear. Policies and procedures will need to demonstrate how they address actual money laundering risks and the predicate offenses that generate illicit proceeds. Formal completion of customer files will not be enough if firms cannot obtain reliable information, connect transactions, identify beneficial owners or explain their risk decisions.

For supervisors, the challenge is to apply common standards without losing sight of proportionality and sector-specific realities. The credibility of the new framework will depend on whether it produces consistent, evidence-based action against material weaknesses while avoiding enforcement driven solely by technical defects.

The effectiveness of the European AML regime will ultimately be measured by its ability to make criminal proceeds harder to place, layer and integrate into the legitimate economy. The decisions and consultations scheduled for 2026 are intended to move that objective from policy design towards measurable supervisory practice.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • AMLA ¦ Document library ¦ Link
  • EUR-Lex ¦ Regulation (EU) 2024/1624 Anti-Money Laundering Regulation (AMLR) ¦ Link
  • EUR-Lex ¦ Directive (EU) 2024/1640 6th Anti-Money Laundering Directive (AMLD6) ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.