ESMA ¦ Work Programme for 2027

ESMA ¦ Work Programme for 2027

ESMA’s 2027 agenda puts money laundering, fraud and market abuse under closer scrutiny

The European Securities and Markets Authority’s 2027 priorities point to a more connected approach to financial crime risk across securities markets. Supervision will increasingly combine market surveillance, data analysis, operational resilience, crypto-asset oversight and cooperation with the European Anti-Money Laundering Authority (AMLA).

Although ESMA’s mandate is centred on securities markets, the implications for anti-money laundering and fraud controls are significant. Securities firms, fund managers, crypto-asset service providers, market infrastructures and other supervised entities will face stronger expectations around governance, data quality, outsourcing, suspicious activity detection and the prevention of abusive conduct.

The central message: financial crime risks cannot be assessed in isolation from market integrity, technology and the underlying criminal conduct that generates illicit proceeds.

Predicate offences remain central to the financial crime picture

Money laundering is dependent on a predicate offence. Criminal proceeds may originate from investment fraud, insider dealing, market manipulation, corruption, tax offences, cybercrime, sanctions evasion, theft or other forms of organised financial crime. Once those proceeds enter securities, funds or crypto-asset markets, the laundering process may be disguised as ordinary investment activity.

This makes the detection of the underlying offence as important as identifying the movement of funds. A suspicious transaction may represent the laundering of proceeds, but it may also be evidence of the fraud, manipulation or insider dealing that generated those proceeds in the first place.

ESMA’s market integrity priorities are therefore closely linked to anti-money laundering controls. Suspicious Transaction and Order Reports, market surveillance alerts, unusual trading patterns and information from investor complaints can all provide intelligence about the source and purpose of funds. They may reveal not only a potential breach of market abuse rules, but also a wider criminal network or fraud scheme.

Firms should avoid treating market abuse monitoring, fraud prevention and AML transaction monitoring as unrelated control systems. Fragmented processes create blind spots, particularly where a customer’s activity appears legitimate when viewed through one control but suspicious when analysed across several data sets.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"ESMA’s 2027 priorities signal tighter scrutiny of money laundering, fraud and market abuse across securities and crypto-asset markets. Stronger data integration, market surveillance and cooperation with AMLA should help authorities identify illicit proceeds and the predicate offences that generate them.

Financial institutions should connect AML, fraud, sanctions and market abuse controls instead of managing them in isolation. Particular attention is needed for crypto-assets, impersonation scams, outsourced technology, artificial intelligence, beneficial ownership and cross-border transactions."

Fraud using ESMA’s identity is an operational warning

Fraudsters continue to misuse the names, logos and identities of public authorities to make investment scams appear credible. ESMA plans to strengthen public awareness of schemes that falsely claim an association with the authority.

This form of impersonation fraud often supports wider investment fraud, including fake trading platforms, advance-fee schemes, recovery scams and fraudulent offers involving crypto-assets or high-risk financial products. Victims may be directed to transfer money to accounts controlled by mule networks or to wallets operated by criminal groups. Once the payment is made, the funds may be layered through multiple accounts, converted into crypto-assets or transferred across borders.

The response requires more than public warnings. Financial institutions should treat references to regulators, authorisation claims and official-looking documentation as part of their fraud risk assessment. Customer communications, payment instructions, beneficiary details, website information and transaction behaviour should be assessed together.

A firm that identifies a suspected impersonation scheme should consider whether it is dealing with a single fraudulent payment or a broader predicate offence involving multiple victims, accounts and jurisdictions. Escalation, reporting and information sharing may be necessary even where the immediate transaction value is modest.

Crypto-assets remain a high-priority AML risk

The implementation of the Markets in Crypto-Assets (MiCA) framework will remain a major supervisory focus. ESMA intends to promote greater convergence in the supervision of crypto-asset service providers, including their digital operational resilience, outsourcing arrangements, corporate substance, liquidity and asset classification.

The AML implications are substantial. Crypto-asset service providers may be used to receive fraud proceeds, move funds through multiple wallets, obscure ownership, convert criminal proceeds into fiat currency or transfer value outside traditional banking channels. Criminal actors may also exploit weak onboarding controls, inadequate wallet screening, decentralised services and cross-border structures.

ESMA will cooperate with AMLA on the AML and know-your-customer obligations applicable to crypto-asset service providers. This signals a closer relationship between securities supervision and the EU’s developing AML supervisory framework. Firms should expect more consistent scrutiny of customer identification, beneficial ownership, source of funds, transaction monitoring, sanctions screening and controls over outsourcing.

The planned development of MIDAS, ESMA’s centralised system for crypto-asset market surveillance, may also improve the ability of authorities to identify market abuse and suspicious trading activity. Its value will extend beyond traditional manipulation risks. Patterns such as coordinated trading, rapid transfers between linked wallets, wash trading and activity around fraudulent token promotions may provide indicators of both market abuse and laundering.

Data quality will determine the effectiveness of controls

ESMA’s data strategy places strong emphasis on integrated reporting, common identifiers, machine-readable information and the use of supervisory technology. These priorities are directly relevant to financial crime prevention.

AML and fraud controls are only as reliable as the data on which they operate. Incomplete legal entity identifiers, inconsistent transaction records, poor instrument classification and fragmented customer information can prevent firms and authorities from linking activity across markets, entities and jurisdictions.

The planned development of integrated reporting frameworks for transactions and investment funds should improve the ability to compare information from different sources. A more connected data environment can help identify nominee arrangements, circular transactions, unexplained transfers, related-party activity and trading patterns that would not be visible within a single reporting system.

However, increased data availability does not automatically produce effective detection. Firms will need clear data ownership, documented data-quality controls, reliable customer and counterparty identifiers, and governance over automated surveillance tools. False positives must be managed, but the drive for efficiency should not result in rules that exclude unusual activity without proper risk-based analysis.

Artificial intelligence creates both detection opportunities and new risks

ESMA plans to expand the use of artificial intelligence and supervisory technology in market monitoring and other supervisory processes. Financial institutions are also using AI for transaction monitoring, fraud detection, customer risk scoring, identity verification and market surveillance.

These tools may improve the identification of complex patterns, particularly across large volumes of trading and payment data. They may help detect coordinated fraud, unusual account behaviour, hidden relationships and rapid changes in transaction patterns.

At the same time, AI introduces risks that require close governance. Criminals may use generative AI to create convincing investment materials, impersonate executives or regulators, automate social engineering and produce false identity documents. AI-generated content can make fraudulent investment opportunities appear more credible and can increase the scale of scams.

Firms using AI in AML or fraud controls should be able to explain how the system reaches risk decisions, identify material limitations and monitor changes in performance. Human review remains essential for high-risk cases, particularly where the system identifies possible links to organised fraud, market abuse or sanctions evasion.

Governance should also address data quality, model validation, bias, access controls, third-party dependencies and the risk that an automated system may fail to detect a new criminal method.

Outsourcing and third-party risk can weaken AML controls

Across several sectors, ESMA identifies outsourcing, intra-group arrangements, third-party dependencies and operational resilience as supervisory concerns. These risks are particularly relevant to AML and fraud prevention because financial crime controls are often distributed across service providers.

Customer screening, transaction monitoring, payment processing, cloud hosting, trade surveillance and identity verification may be outsourced to different providers. If responsibilities are unclear, alerts may not be investigated promptly, important information may not be shared, or suspicious activity may be lost between systems.

Outsourcing does not transfer regulatory responsibility. Firms must understand which controls are performed externally, how the service provider makes decisions, what data it uses, how alerts are escalated and whether records can be accessed quickly by the firm and competent authorities.

Contractual arrangements should support audit rights, access to information, incident notification, data retention, business continuity and regulatory cooperation. The same principles apply to intra-group services. A centralised group function cannot be treated as an unexplained black box.

Market abuse controls should connect with AML investigations

ESMA’s 2027 market integrity work includes continued attention to suspicious transaction and order reporting, social media, artificial intelligence in trading, crypto-asset market abuse and cross-border cooperation.

These areas also generate important AML intelligence. Insider dealing and market manipulation can produce illicit profits that later enter investment accounts, funds, companies or crypto-asset wallets. Fraudulent investment promotions may be accompanied by artificially inflated trading volumes, coordinated orders or misleading social media campaigns.

A strong control framework should allow information to move between market surveillance, fraud, AML, compliance and investigations teams. For example, a market surveillance alert involving unusual trading before a corporate announcement may need to be assessed alongside the trader’s source of wealth, related accounts, communications and transfers after the transaction.

The purpose is not to merge every control function into one process. It is to ensure that relevant indicators are not isolated in separate systems or handled without considering the wider financial crime context.

Investment funds require closer attention to risk management and transparency

ESMA’s planned work on investment management includes a common supervisory action on the risk management functions of alternative investment fund managers and UCITS management companies. The authority will also examine leverage, liquidity, stress testing and the interconnectedness of funds with the wider financial system.

These issues have a direct financial crime dimension. Complex fund structures, layered ownership, delegated portfolio management and cross-border distribution can make it difficult to identify the true source of capital or the beneficial owner of an investment. Illiquid assets and valuation uncertainty may also be exploited to conceal losses, manipulate performance or move value between related parties.

Fund managers should ensure that AML and fraud risk assessments reflect the full operating model, including distributors, delegates, administrators, custodians, investment advisers and underlying investors. Particular care is needed where the fund receives capital through multiple intermediaries or from jurisdictions presenting elevated corruption, fraud or tax crime risks.

Improved integrated reporting may help authorities compare fund information more effectively. It should also encourage firms to maintain consistent data about investors, counterparties, assets, transactions and delegated activities.

Retail investment fraud is becoming more sophisticated

Retail investor protection remains a prominent priority, particularly in relation to digital distribution channels, social media, artificial intelligence, crowdfunding and innovative products.

Retail investment fraud increasingly combines persuasive online marketing with fake endorsements, fabricated performance data and pressure to transfer funds quickly. Fraudsters may use legitimate brand names, cloned websites, false regulatory references and manipulated testimonials. Crypto-assets and leveraged products can increase both the speed and the irreversibility of losses.

Firms should monitor the channels through which products are marketed, not only the formal onboarding process. Risks may arise from affiliates, influencers, lead generators, unauthorised introducers and online advertising networks. Where a product is promoted through misleading claims, the issue may involve consumer harm, fraud, market abuse and potential laundering of proceeds.

Customer complaints should be treated as a source of intelligence rather than merely a service issue. A pattern of complaints involving the same website, beneficiary account, phone number, wallet or intermediary may indicate a wider criminal operation.

Cooperation with AMLA will reshape supervisory expectations

ESMA intends to continue cooperating with AMLA through relevant governance and coordination structures. This reflects the broader move towards a more integrated EU approach to financial crime supervision.

For securities firms and crypto-asset businesses, closer cooperation between securities authorities and AML supervisors may lead to more consistent expectations about risk assessments, customer due diligence, suspicious transaction reporting and enforcement. Information previously held within separate supervisory channels may be assessed together.

The practical consequence is that firms should be prepared to demonstrate not only that AML policies exist, but that they operate effectively across the business. Supervisors are likely to focus on the quality of outcomes, the handling of higher-risk customers, the speed and quality of investigations, the escalation of fraud indicators and the ability to identify the source and destination of funds.

What firms should prioritise in 2027

Firms within ESMA’s supervisory perimeter should review whether their financial crime framework can connect AML, fraud, market abuse, sanctions and cyber risks. Risk assessments should identify the predicate offences most relevant to the firm’s products, customers, markets and distribution channels.

Particular attention should be given to crypto-asset exposure, impersonation scams, social media activity, outsourced controls, AI use, beneficial ownership, source of funds, cross-border activity and the quality of transaction and trading data.

Governance should support timely escalation between compliance, fraud, market surveillance, cybersecurity, legal and senior management teams. Testing should examine whether the firm can identify linked activity across accounts, products and jurisdictions, preserve evidence and submit high-quality reports to the appropriate authorities.

The broader supervisory direction is toward more data-driven, risk-based and coordinated enforcement. Firms that treat AML as a narrow onboarding obligation will struggle to meet that standard. Effective prevention will depend on understanding the criminal conduct that generates illicit proceeds, recognising how those proceeds move through financial markets and ensuring that fraud and market abuse indicators are acted on before losses and laundering expand.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • ESMA ¦ ESMA sets 2027 priorities for stronger, simpler and more integrated EU capital markets ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.