AMLA ¦ AMLA Consults on Draft Standards for an EU-wide AML/CFT Database

AMLA ¦ AMLA Consults on Draft Standards for an EU-wide AML/CFT Database

AMLA sets out what EU supervisors will feed into its central AML/CFT database

The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has opened a consultation on draft regulatory technical standards (RTS) under Article 11(6) of Regulation (EU) 2024/1620 (AMLAR). The standards define what information national supervisors must transmit to the central AML/CFT database, in what level of detail, in which format and by when. Obliged entities will not report to the database themselves, but a large part of what supervisors know about them – their risk profile, the data points behind it, every administrative measure and sanction imposed on them, and negative fit and proper opinions on their shareholders and managers – will end up there. AMLA will hold a public hearing on the draft on 3 November 2026, from 14:00 to 16:00 CET.

A single supervisory picture for the whole Union

The database is meant to be the single point through which EU supervisors report and retrieve AML/CFT information. It will hold data on individual obliged entities and on the supervisors themselves: their mandates, tasks, powers, staffing, budgets and supervisory activities. AMLA intends to use it to identify risks and trends at sector, country and EU level, to oversee how the supervisory system as a whole functions, and to support targeted supervision of individual entities, including its own direct supervision of selected institutions from 2028.

Until now, the only central AML/CFT database at EU level has been EuReCA, which the European Banking Authority built around material weaknesses and measures concerning financial institutions. The new database goes much further. It covers the financial and non-financial sectors, all categories of obliged entities listed in the AMLR, and supervisory activity in general rather than only its most serious outcomes.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"Firms will never log into this database, but it will hold a fairly complete record of them: their risk scores and the data behind them, every measure and sanction with its remediation status, and negative fit and proper opinions on the people who own and run them. AMLA chose comprehensive reporting over a materiality filter, which means even minor findings travel to Frankfurt.

My practical advice is to treat every answer in a supervisory risk data collection as if it were going to be read in several capitals, because it will be. Closing findings quickly and documenting the remediation has always been good practice; with a central record that follows a firm across borders, it also protects its reputation with every supervisor it meets."

No new reporting for obliged entities, but more exposure

AMLA stresses that the draft RTS impose no new reporting obligations on obliged entities. The standards draw on information that supervisors already hold or will collect anyway under the new framework, in particular the data points gathered for the risk assessment methodology under Article 40(2) of Directive (EU) 2024/1640.

For firms, that is only partly reassuring, because the information they provide to their national supervisor will no longer stay at national level. Once it reaches the central database, it becomes available on a need-to-know and confidential basis to supervisors across the Union and to AMLA. Inconsistent or poorly documented answers in a risk data collection, for example, will be visible to more than one authority and easier to compare with peers in other Member States.

Risk profiles and the data points behind them

For each obliged entity, supervisors will transmit its identification details, including the legal entity identifier where available, its inherent risk profile, the quality of its AML/CFT controls and its residual risk profile, as determined under the methodology of the Article 40(2) RTS. Any manual adjustment of a score must be documented, and adjusted scores must be reported within 30 working days of the adjustment.

AMLA considered limiting the granular data to entities selected for its direct supervision, or to the financial sector, and rejected both options. Supervisors will transmit the full set of underlying data points for all obliged entities. The draft also asks for group affiliation, the name and country of the parent undertaking, central contact points and, where an AML/CFT supervisory college exists, its members and observers.

For the financial sector, the first transmission of this information is due by 31 May 2028. The non-financial sector follows on 31 May 2031.

Every sanction and measure, not only the material ones

On enforcement data, AMLA weighed a model similar to EuReCA, in which only measures responding to serious, repeated or systematic breaches would be reported, against a comprehensive model. It chose the comprehensive one. Supervisors are to report all administrative measures, pecuniary sanctions and periodic penalty payments imposed for breaches of AML/CFT requirements or for weaknesses in internal policies, procedures and controls likely to lead to breaches.

AMLA’s reasoning is that lower-level breaches, analysed together, can reveal systemic weaknesses and emerging trends that a database of serious cases would miss. A single reporting standard also removes uncertainty about where a reporting threshold should lie and reduces divergent practices between supervisors. The gravity of each breach is still recorded, so the database can distinguish minor findings from serious ones.

The level of detail is considerable. Supervisors will record the type of measure, the amounts imposed and, in the case of settlements, the settled amount, the status of any appeal, whether and how the measure was published and why publication was anonymised or delayed. On the breach itself, they will report the area of AML/CFT compliance concerned, a description, the gravity, whether it has been remediated and whether it has cross-border impact. Where a measure is linked to a natural person, the database will hold that person’s name, date of birth, nationality, country of residence and function in the obliged entity. Information must be transmitted within 30 working days of the measure being imposed and updated within 30 working days of any change.

Negative fit and proper opinions follow individuals

Supervisors will also report opinions and advice given to other authorities in authorisation procedures, withdrawals of authorisation and fit and proper assessments of shareholders and members of the management body, but only where those opinions raise ML/TF concerns or are negative. The record includes the identity of the natural person concerned and their current or prospective function.

Ownership and control are a familiar entry point for criminal money: buying into a regulated firm, or placing a manager who will look away, gives launderers access to the financial system from the inside. When a shareholder or director has been turned down on ML/TF grounds in one Member State, an authority assessing the same person elsewhere will be able to see that opinion in the database instead of depending on whether someone thought to pass it on.

Supervisory activity becomes measurable

Supervisors will report their own work as well. For each supervisory activity carried out under their annual strategy, or ad hoc in response to specific events or risks, they will transmit the entities involved, the nature and scope of the activity, its dates and the participation of other authorities, and they will upload the report of every thematic review.

The draft differentiates by relevance and sector. In the financial sector, on-site inspections and off-site activities that are thematic reviews or lead to a measure or sanction are reported within set deadlines, and all other activities are reported once a year at entity level. In the non-financial sector, only thematic reviews and activities leading to a measure or sanction are reported individually, and the rest in aggregated form by sector. Supervisors will also report their AML/CFT staff in full-time equivalents, split by policy, risk analysis, supervision and enforcement, together with their annual AML/CFT budget.

AMLA gains a factual basis for comparing how intensively each Member State supervises. The flip side for obliged entities is that how often, and how deeply, they are inspected becomes part of AMLA’s oversight of their national authority.

Confidentiality and onward sharing

Information in the database is confidential and protected by professional secrecy. It may be used within the AML/CFT supervisory system and for AMLA’s tasks without the consent of the authority that supplied it. Disclosure outside that system generally requires prior consent, and information originating from a third-country authority always does.

The draft allows sharing without prior consent where Union law authorises or requires it, including exchanges with financial intelligence units, with authorities in charge of targeted financial sanctions and with certain other supervisory authorities. The originating supervisor must, where practicable, be notified in advance and in any case informed of what was shared, with whom, on what legal basis and why. Personal data remain subject to the GDPR and to Regulation (EU) 2018/1725.

Limits on AMLA’s additional requests

Beyond the standard reporting, AMLA may ask supervisors for additional information, but only where it is necessary for one of its tasks under Article 5 AMLAR and where AMLA states the task, the justification and the intended use. Requests must be proportionate. Supervisors have 30 working days to respond, AMLA can extend the deadline for complex data, and supervisors that lack legal access to the information must say so without undue delay.

The aim is to replace a stream of ad hoc questionnaires with predictable, structured reporting. Obliged entities stand to benefit indirectly if fewer ad hoc data requests travel down from AMLA to the national supervisor and from there to the firms.

A staged timetable

The obligations start at different dates. Supervisors must transmit information about themselves by 15 July 2027. Sanctions and measures imposed in the financial sector after that date are reported from 15 July 2027, and in the non-financial sector from 31 December 2029. Reporting on supervisory activities starts from 31 December 2027 for the financial sector and 31 December 2029 for the non-financial sector. The first staffing and budget data are due by 31 March 2028. For non-financial supervisors and public authorities overseeing self-regulatory bodies, several transmissions remain voluntary until 27 June 2028, and the application date for football clubs and football agents is deferred in line with their entry into the AML/CFT framework on 10 July 2029.

What obliged entities should take from the consultation

The RTS are addressed to supervisors, yet firms will feel them. Answers given in risk data collections will feed an EU-wide dataset, so they deserve the same review and sign-off as regulatory reporting. Because every measure and sanction is recorded centrally together with its remediation status, closing findings quickly and documenting how they were closed now counts beyond the relationship with the national supervisor. Groups active in several Member States should plan on supervisors in each of them seeing the same entity-level data and the same breach history.

Firms, industry associations and other stakeholders who want to influence the final text can register for the public hearing on 3 November 2026. AMLA’s four consultation questions cover the information on supervisors and supervisory activities, the information on obliged entities, the reporting of enforcement measures and opinions, and the rules on additional information, consent, technical specifications and confidentiality.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • AMLA ¦ Press Release - AMLA consults on draft standards for an EU-wide AML/CFT database ¦ Link
  • AMLA ¦ Consultation and public hearing on draft RTS establishing the central AML/CFT database ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.