03 October 2026
AMLA ¦ Final Report on Draft RTS on Pecuniary Sanctions, Administrative Measures and Periodic Penalty Payments
AMLA sets a common scale for AML/CFT breaches, fines and periodic penalty payments
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has finalised draft regulatory technical standards (RTS) under Article 53(10) of the Anti-Money Laundering Directive (AMLD), Directive (EU) 2024/1640. They define how supervisors across the EU will rate the gravity of AML/CFT breaches, which factors push a fine up or down, when the most severe administrative measures come into play, and how periodic penalty payments are imposed to end ongoing non-compliance. The standards apply to financial and non-financial sector supervisors alike and are proposed to apply from 10 July 2027.
Why enforcement needs a common scale
The AMLD’s own recitals acknowledge that supervisors have had no common understanding of what makes a violation “serious”, and therefore no shared view of when a pecuniary sanction is warranted. Data from EuReCA, the EU’s central AML/CFT database on serious deficiencies in financial institutions, points the same way: similar breaches by similar institutions currently lead to different supervisory responses depending on the Member State.
The weakness is even more pronounced outside the financial sector. Mutual evaluation reports by the Financial Action Task Force (FATF) and Moneyval have described the supervision of non-financial obliged entities in EU Member States as fragmented and largely ineffective. Uneven enforcement weakens deterrence. Where a lawyer, notary, trust provider or dealer faces little risk of being sanctioned, the controls that are supposed to keep criminal money out tend to be weaker too.
The RTS set up a single, horizontal framework. Once in force, the same breach should be assessed in the same way by every supervisor, and the resulting measure should be proportionate, effective and dissuasive, as Article 53(2) AMLD requires.
Twelve indicators of gravity
The first step is the assessment of the breach against a common list of indicators, which supervisors must consider to the extent they apply. They cover the duration and repetition of the breach and the conduct of the natural or legal person that committed, permitted or failed to prevent it. They also cover the impact on the obliged entity, measured by whether the breach affects the group or has a cross-border dimension, how many products, services and customers are affected, and how far the effectiveness of AML/CFT systems and controls is impaired.
Further indicators address the breach’s effect on the entity’s exposure to money laundering and terrorist financing risk, and its nature, meaning whether it concerns internal policies and controls, customer due diligence, reporting obligations or record retention. Supervisors must also ask whether the breach could have facilitated or led to criminal activity as defined in the Anti-Money Laundering Regulation (AMLR), whether it reflects a structural failure of the AML/CFT framework, whether it affects the financial viability of the entity or its group, and whether it threatens the integrity, transparency and security of the financial system, financial stability or the functioning of the internal market. The systematic nature of the breach is a separate indicator, and supervisors may add others if they justify them.
From a financial crime perspective, the link to criminal activity weighs most. A control failure that actually enabled laundering of criminal proceeds will be rated far more severely than a documentation gap without consequences.
Four categories of severity
In the second step, supervisors classify the breach in one of four categories of increasing severity. The RTS describes typical situations for each category without claiming to be exhaustive.
Category one covers breaches of short duration, committed on a non-repetitive basis, with no or only minor impact on the obliged entity. A breach cannot fall into category one if any of the more serious indicators apply, such as the facilitation of criminal activity, a structural failure, an impact on financial viability or the financial system, or systematic conduct. Category two applies where the impact is moderate and none of those serious indicators is met.
A breach is at least category three where it is repeated or systematic, or where its impact is significant and it has persisted over a significant period. Category four applies where the impact is very significant, where there is a structural failure of the AML/CFT framework, where the breach facilitated significant criminal activity, or where it significantly affected the entity’s financial viability or the wider financial system. Breaches that would not reach category three or four on their own may do so when assessed together.
The legal effect of categories three and four
Any breach in category three or four is deemed serious, repeated or systematic within the meaning of Article 55(1) AMLD, which triggers the higher maximum pecuniary sanctions available under the directive.
Some respondents to the consultation argued that this structured classification exceeded AMLA’s mandate and pre-determined sanctioning outcomes. AMLA disagreed, pointing to the AMLD’s recital on the lack of a common understanding of serious violations, and clarified the link to Article 55(1) in the final text. Once a supervisor finds a structural failure or a repeated breach, the case therefore moves into the most severe sanctioning bracket.
What raises or lowers a fine
To set the amount, supervisors start from the circumstances already listed in Article 53(6) AMLD and then apply the criteria in the RTS.
Fines decrease where the person held responsible quickly and fully brought the breach to the supervisor’s attention, actively contributed to the investigation, and took timely and effective remedial action or voluntary measures to prevent recurrence. They increase where the person failed to cooperate, withheld information the supervisor could reasonably expect, or tried to conceal the breach or mislead the supervisor. Other aggravating factors include the absence of remediation, the degree of responsibility and intent, any financial or competitive benefit derived from the breach or loss avoided, losses caused to third parties, customers or other market users, and previous breaches, sanctions or ignored remediation requests.
The financial strength of the person held responsible must also be considered. For legal persons, that means total annual turnover, financial statements and, where relevant, information from prudential supervisors on capital and liquidity, or any other reliable information, a broadening added for the non-financial sector. For natural persons, it means annual income, fixed and variable, from the obliged entity or its group and, where relevant, other income.
Respondents raised concerns that treating insufficient cooperation as aggravating could clash with professional secrecy and the privilege against self-incrimination. AMLA’s answer is that the provision must be applied in line with the rights of the defence, including the right to silence under Articles 47 and 48 of the Charter of Fundamental Rights.
Senior managers in the frame
The RTS contains specific provisions for natural persons who are not themselves obliged entities, including senior management and members of the management body in its supervisory function. When setting fines for these individuals, supervisors must consider their role and effective responsibilities, the scope of their functions and the extent of their involvement in the breach.
The conduct indicator points the same way. Supervisors are told to pay particular attention to situations where a natural or legal person, including its senior management and supervisory board, appears to have known about the breach and done nothing, or directly contributed to it. Board members and senior managers who receive compliance reports and fail to act should expect that inaction to be assessed against them personally.
Criteria for the heaviest measures
For administrative measures, the RTS focuses on the three most intrusive options in Article 56(2) AMLD: restricting or limiting the business, operations or network, or requiring divestment; withdrawing or suspending an authorisation; and requiring a change in the governance structure.
In each case, a category three or four classification is a relevant criterion. For business restrictions, supervisors also consider whether the measure can mitigate the impact of the breach, how far the business is affected and what harm the measure could cause to customers and stakeholders. For withdrawal or suspension of authorisation, they consider the conduct of the person responsible and whether there is a structural failure of AML/CFT systems and controls. For governance changes, they look at a lack of cooperation, concealment or absent remediation, ineffective internal controls and information from financial intelligence units, prudential supervisors, other authorities or judicial authorities.
Periodic penalty payments to end ongoing breaches
Periodic penalty payments are new to EU AML/CFT enforcement and have so far been used in only a few Member States. Their purpose is to compel compliance with an administrative measure, so the criteria for setting them differ from those for fines.
Before imposing one, the supervisor must send a statement of findings explaining the reasons and the amount used for the calculation, with a time limit of up to four weeks for written submissions. The decision may rely only on facts on which the person concerned could be heard, and it must state the legal basis, the reasons and the amount. That amount reflects the type of measure not complied with, the reasons for non-compliance and, where established when the measure was imposed, losses to third parties, benefits derived and the financial strength of the person concerned.
Payments can be set daily, weekly or monthly and are collected only for the period of non-compliance with measures under Article 56(2), points (b), (d), (e) and (g), AMLD. Collection is subject to a five-year limitation period starting the day after notification of the final accrued amount. Otherwise, national administrative law governs the process. Respondents asked for caps and clearer accrual rules, fearing that penalties could threaten the viability of small firms and sole practitioners, but AMLA kept the approach flexible and relies on the general requirement of proportionality.
Timing and the non-financial sector
The EBA consulted on an earlier version in 2025 and delivered its advice to the Commission in October 2025. AMLA adopted that text as its baseline and consulted again in February and March 2026 specifically to reach the non-financial sector. Of 88 valid responses from more than 20 Member States, 70 % came from non-financial respondents, many of whom argued that the text transposed banking concepts onto lawyers, notaries, auditors and small firms. AMLA amended several provisions and recitals in response, but kept a single framework for all sectors.
The RTS is proposed to apply from 10 July 2027, and from 10 July 2029 for football clubs and football agents. It will not apply to proceedings initiated before 10 July 2027.
Preparing for harmonised enforcement
Enforcement becomes more predictable as a result. A firm can map its own control weaknesses against the indicators and categories and see roughly where a supervisor would place them. Structural failures, repeated findings and breaches that enabled criminal activity sit at the top of the scale and expose the firm to the heaviest sanctions and measures.
Firms can also influence the outcome. Early self-reporting, real cooperation, prompt remediation and documented preventive measures reduce fines, while concealment, delay and ignored remediation requests increase them. Firms should make sure that breaches are escalated quickly, that remediation is tracked to completion and that management body decisions on compliance findings are recorded.
In Luxembourg, where AML/CFT supervision is shared between the CSSF, the Commissariat aux Assurances, the Administration de l’enregistrement, des domaines et de la TVA and several self-regulatory bodies, the standards should bring these supervisors’ sanctioning practice closer together. Combined with the CSSF’s policy of publishing sanctions by name, a higher category classification will increasingly carry reputational as well as financial consequences.
Dive deeper
- AMLA ¦ Final Report ¦ Draft RTS on pecuniary sanctions, administrative measures and periodic penalty payments (RTS AMLD 53(10)) (pdf) ¦ Link