01 October 2026
AMLA ¦ AMLA finalises key standards for the private sector
AMLA finalises three core standards for the private sector
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has finalised three sets of regulatory technical standards (RTS) under the Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, and submitted them to the European Commission. They cover the distinction between business relationships and occasional transactions, the content of customer due diligence (CDD), and the minimum requirements for group-wide AML/CFT arrangements. Together they define how obliged entities will identify customers, verify information and organise controls across the EU once the single rulebook applies.
Three mandates, one operating model
Each standard answers a separate empowerment in the AMLR. The first, under Article 19(9), deals with the classification of a customer contact as either a business relationship or an occasional transaction and with the identification of linked transactions. The second, under Article 28(1), specifies the information obliged entities must collect and verify as part of CDD. The third, under Articles 16(4) and 17(3), sets minimum requirements for group-wide policies, procedures and controls, including the treatment of branches and subsidiaries in third countries.
Read together, the three texts describe a single operating model. The first decides whether and when CDD is triggered, the second decides what CDD consists of, and the third decides how a group ensures that the same standards are applied consistently across all its entities. A weakness in one undermines the other two, so compliance functions are better off running them as one implementation project.
The standards were developed with national supervisors and informed by written consultations and public hearings. They build on preparatory work by the European Banking Authority (EBA), which delivered draft texts in response to the Commission’s call for advice in 2025.
Business relationship or occasional transaction
Whether a customer contact constitutes a business relationship or an occasional transaction has direct consequences. A business relationship triggers CDD from the outset and requires ongoing monitoring for its duration. An occasional transaction triggers CDD only when it reaches the relevant threshold, which under the AMLR is generally €10,000.
In practice, the boundary has never been applied consistently across Member States or sectors. A customer who returns repeatedly to the same money service business, a client who instructs a series of one-off transactions through an intermediary, or a user of a payment service who never opens a formal account may be treated very differently from one institution to the next. Those inconsistencies are exactly what criminals exploit when they spread illicit funds across products, branches and providers.
The RTS sets common criteria for drawing that line, so that the same pattern of activity is treated the same way regardless of the obliged entity or the Member State involved. For many firms, this will mean reviewing product classifications and onboarding triggers that have grown out of national practice over many years.
Linked transactions and the threshold problem
Splitting a payment into several smaller amounts below the CDD threshold is one of the oldest placement techniques. It still works wherever an obliged entity has no clear rule for aggregating related operations.
The RTS defines how obliged entities should identify linked transactions, so that a series of operations which together exceed the threshold is treated as a single occasional transaction. This matters particularly for cash-intensive businesses, money remitters, currency exchange offices, dealers in high-value goods and the gambling sector, where structuring by customers or by networks of money mules is a recurring typology.
Detecting linkage requires data. Firms will need to be able to connect operations across time, channels and, where relevant, across customers acting together. This is a monitoring and data architecture task as much as a legal one, and it takes time to build.
What customer due diligence will contain
Of the three, the CDD standard will change the most day-to-day processes. It specifies the information obliged entities must obtain on customers, beneficial owners and persons acting on behalf of a customer, and how that information must be verified.
Harmonised data requirements remove a long-standing source of friction for cross-border groups, which have had to maintain different onboarding forms and verification rules for each jurisdiction. Under a directly applicable regulation and its implementing standards, the content of CDD will no longer depend on national transposition. For Luxembourg obliged entities, this means the detailed CDD expectations currently derived from national law and CSSF regulation will increasingly be replaced by EU-level rules, with national supervisors focusing on how those rules are applied.
The standard keeps a risk-based logic, distinguishing between the information required in every case and the additional information needed where the risk is higher. The EBA’s preparatory drafts pointed in the same direction, with detailed requirements on ownership and control structures, the purpose and intended nature of the relationship, and source of funds and source of wealth in higher-risk situations.
Proportionate measures for lower-risk situations
Simplified due diligence has always been permitted, but in practice many institutions have avoided relying on it because the conditions were unclear and the supervisory reaction uncertain. The result has been over-collection of data from low-risk customers and, in some cases, the exclusion of customers who could not provide the documents demanded.
A clearer legal basis for reduced measures should let firms spend their effort on higher-risk relationships. It also supports financial inclusion where conventional documents are not available. Simplified measures still require a documented justification, however, and firms must be able to return to standard measures as soon as the risk picture changes. AMLA is separately preparing guidelines on simplified due diligence and has invited stakeholders to sectoral roundtables on the topic.
Remote onboarding and electronic identification
The CDD standard addresses non-face-to-face verification and electronic identification. Remote onboarding has become the default channel in retail banking, payments and crypto-asset services, yet the safeguards expected of it have varied widely between supervisors.
The standard ties remote verification to the EU’s electronic identification framework under eIDAS and sets conditions for methods that do not rely on it. Obliged entities gain a firmer basis for accepting electronic identity attributes, along with clearer expectations on liveness checks, document authentication, record retention and how to demonstrate compliance after the event. Accounts opened remotely with stolen or synthetic identities, or by money mules, are a standard route for laundering fraud proceeds, so these safeguards matter well beyond onboarding convenience.
PEP screening beyond the individual
The standard specifies how obliged entities must screen for politically exposed persons (PEPs), their family members and persons known to be close associates. That last category has long been the weakest point of many screening programmes, because commercial lists capture it only partially and associations are often revealed only through adverse media or transaction patterns.
Corruption proceeds are rarely held in the name of the official concerned. They are channelled through relatives, business partners, nominees and corporate vehicles, so screening that stops at the individual PEP misses the most common laundering route for bribery and embezzlement. A harmonised standard that covers family members and close associates closes much of that gap.
Group-wide arrangements as a control framework
The third standard sets minimum requirements for effective group-wide AML/CFT arrangements, covering governance, risk management, internal controls and secure information sharing within the group.
Group-wide policies have been required for years, but their quality varies. Some groups operate a genuine common framework with central oversight. Others combine local procedures under a thin group policy that is rarely tested. The RTS raises the floor by defining what parent undertakings must ensure as a minimum, including how information on customers and suspicious activity can be shared within the group subject to data protection safeguards.
Information sharing deserves particular attention. Laundering schemes regularly use several entities of the same group in different jurisdictions, and a suspicion that remains confined to one subsidiary leaves the rest of the group exposed. For Luxembourg, with its high concentration of subsidiaries and branches of international banking, fund and insurance groups, the standard will shape both the expectations placed on local entities and the information they can expect to receive from their parent.
A short runway to application
Once adopted by the Commission and published in the Official Journal, the standards are proposed to apply six months after their entry into force. For football agents and professional football clubs, which become obliged entities under the AMLR at a later date, they will apply from 10 July 2029.
Six months leaves little time for changes to onboarding forms, verification tools, screening logic, monitoring rules and group policies. The Commission may still amend the final drafts, though large changes to their substance would be unusual. Firms that wait for publication in the Official Journal before starting a gap analysis will find the timetable difficult to meet.
What obliged entities should prepare
The practical work starts with a few questions. Does the firm’s classification of business relationships and occasional transactions, and its approach to linked transactions, match the criteria in the RTS? Do onboarding data, verification methods, remote identification safeguards and PEP screening, including family members and close associates, meet the harmonised CDD requirements? And does the group framework satisfy the minimum standards on governance, risk management, controls and information sharing?
The answers should feed a single implementation plan that combines legal analysis with data, technology and training. The standards remove much of the national divergence that has complicated AML/CFT compliance in the EU. They also leave less room for interpretation, and supervisors, including AMLA in its direct supervision of selected institutions, will expect consistent application from the first day.
Dive deeper
- AMLA ¦ Press Release – AMLA finalises key standards for the private sector (pdf) ¦ Link