One year to the AMLR: where obliged entities should already be
Exactly one year from now, on 10 July 2027, the EU’s AML Regulation becomes directly applicable and replaces a large part of national AML law for obliged entities. AMLA, the new EU authority in Frankfurt, is already operational and will directly supervise selected high-risk financial entities from 2028. A directly applicable regulation means less room for local interpretation — and less time to hide behind it.
What actually changes
- One rulebook. Customer due diligence, beneficial-ownership identification (25% ownership-or-control threshold, with stricter options for high-risk sectors) and group-wide requirements become uniform across the EU.
- A wider net. Crypto-asset service providers are fully in; new categories — from luxury-goods traders to, later, professional football — join the obliged-entity list.
- An EU-wide cash cap. Payments in cash above €10,000 are barred in commercial transactions.
- Harder data expectations. The rulebook assumes your customer data is accurate, current and connectable — from onboarding through monitoring to reporting.
The three workstreams that pay off first
- Re-run the business-wide risk assessment against AMLR categories — most legacy assessments do not map cleanly, and everything downstream inherits their gaps.
- Fix the data model before the deadline fixes you. UBO records, screening match quality and monitoring inputs deserve a data-quality review this year, not next June.
- Reopen vendor contracts. Screening, KYC and monitoring providers should contractually support AMLR-era requirements; renegotiation queues will only grow.
A note for Polish entities
The Polish AML Act continues to apply until the AMLR takes over its ground; national guidance (GIIF) remains binding practice in the transition. Plan the crossover explicitly: one register of obligations, two regimes, one date.
Sources: Regulation (EU) 2024/1624 (AMLR) · Directive (EU) 2024/1640 (AMLD6) · AMLA