Skip to content
EBA · EU-wide

AMLA’s draft rules for cross-border suspicious-transaction reports

Fintech Passport
July 28, 2026 · 7-min read
AMLA’s draft rules for cross-border suspicious-transaction reports

A suspicious-transaction report filed in one member state often concerns people, accounts or assets in another — and today there is no common EU rulebook for how that report gets to the FIU that actually needs it. On 6 July 2026, the EU’s new Anti-Money Laundering Authority (AMLA) opened a consultation on draft regulatory technical standards that would fix exactly that: when a report “concerns” another member state, how it should be classified, and how it moves between Financial Intelligence Units. This piece explains what AMLA proposed, how it differs from the harmonised-format work already under way, and what it means for a firm operating across borders.

1. What AMLA published

The Anti-Money Laundering Authority (AMLA) — established by Regulation (EU) 2024/1620 and seated in Frankfurt — launched a public consultation on 6 July 2026 on a draft regulatory technical standard (RTS) governing the cross-border exchange of information between Financial Intelligence Units (FIUs). The mandate sits in Article 31(3) of Directive (EU) 2024/1640 — the sixth Anti-Money Laundering Directive (AMLD6) — which requires AMLA to specify how FIUs identify, classify and share reports that touch more than one member state. The consultation runs until 6 October 2026.

This is a distinct workstream from the harmonised suspicious-transaction report format AMLA consulted on earlier in July 2026. That RTS standardises what a report looks like when an obliged entity files it under Article 69(1) of Regulation (EU) 2024/1624 (the AML Regulation, AMLR). This draft RTS governs what happens next: how the receiving FIU decides whether the report also concerns another country, and how it gets there.

2. Two mechanisms: cross-border reports and disseminations

Under the current patchwork, FIUs handle cross-border relevance inconsistently — some forward a full copy, others summarise informally, and the criteria for even recognising foreign relevance vary. The draft RTS sets:

  • Criteria for identifying the affected member state(s) — for a report on a natural person, based on habitual residence; for a legal person, based on where it operates or is established; more broadly, any objective link between the underlying facts and another member state’s territory, subjects or assets.
  • A choice between the two transmission modes — full cross-border report where the receiving FIU needs the complete picture, or a cross-border dissemination where a targeted data set is enough.
  • Reliance on structured data within FIU.net — the secure decentralised network FIUs already use to exchange information, so the new criteria plug into existing technical infrastructure rather than requiring a new channel.

3. Coordination when several member states are involved

A single suspicious-activity case can legitimately concern three or four member states at once — a payment corridor touching several banking relationships, or a group structure spanning jurisdictions. Left unmanaged, that produces duplicated follow-up requests landing on the same obliged entity from multiple FIUs, each unaware of the others’ inquiry.

The draft RTS addresses this with a coordination principle: once a report has been shared with one or more FIUs, follow-up requests for further information go only to the FIU that originally received the report — not directly back to the obliged entity through parallel channels, and not duplicated across every FIU that received a copy. This keeps a single coordination point for the case and is designed to stop the fragmentation that comes from multiple parallel threads on the same underlying facts.

4. A risk-based relevance filter for the receiving FIU

Not every report that technically “concerns” another member state deserves the same priority once it lands there. The draft RTS is expected to give the receiving FIU a risk-based mechanism to assess the relevance of what it receives — so a national FIU is not obliged to treat every incoming cross-border item as equally urgent, and can triage based on objective criteria drawn from the structured data it receives, rather than working purely reactively through an undifferentiated inbox.

5. Timeline and what happens next

The consultation is open for comment until 6 October 2026. As with AMLA’s other AMLD6/AMLR technical-standards work, expect the authority to weigh the responses, finalise the draft, and submit it to the European Commission for adoption — a process that, on the pattern of AMLA’s other 2026 consultations, typically runs several months past the consultation close. Firms with a live cross-border STR/SAR footprint should treat this as a live-but-not-yet-binding proposal: worth tracking, not yet something to build against.

6. Three worked examples

  • Payment corridor with a foreign beneficiary. A payments firm files a suspicious-transaction report with its home FIU on a customer whose transactions repeatedly route funds to a beneficiary resident in another member state. Rule: habitual residence of the counterparty is one of the criteria for identifying an “affected” member state under the draft RTS. Action: the home FIU classifies the case as cross-border and chooses between a full report or a targeted dissemination to the beneficiary’s home FIU. Outcome: the beneficiary’s FIU receives only what it needs to assess relevance, rather than the entire underlying file, unless the case calls for the full report.
  • Group entity spanning three countries. A firm’s compliance team files an STR concerning a corporate customer with subsidiaries in three member states. Rule: for legal persons, the criteria look to where the entity operates or is established, which can trigger multiple affected states at once. Action: the home FIU disseminates to each affected FIU, but under the coordination principle, any follow-up questions from those FIUs route back through the home FIU rather than each contacting the firm independently. Outcome: the firm deals with one coordination point instead of three parallel information requests on the same case.
  • Low-priority technical cross-border touch. A report has a marginal, incidental cross-border element — a single historical transaction with a counterparty in another state, with no ongoing pattern. Rule: the receiving FIU’s risk-based relevance assessment lets it de-prioritise or file the incoming dissemination without immediate escalation. Action: the receiving FIU logs the item for monitoring rather than opening a full investigation. Outcome: resources concentrate on cases with a genuine cross-border risk signal, not every technical touchpoint.

7. How this fits the wider AMLR reporting picture

WorkstreamWhat it governsLegal basisConsultation status
STR/SAR formatWhat a report looks like when filed by an obliged entityArt. 69(3) Reg. (EU) 2024/1624Open to 20 Sep 2026
Cross-border FIU exchange (this piece)How a report moves between FIUs once filedArt. 31(3) Dir. (EU) 2024/1640Open to 6 Oct 2026
National filing (today)Existing per-country SAR/STR channelsNational transpositionUnaffected until AMLR applies, 10 Jul 2027

Both RTS workstreams sit on top of the existing national channels — see our guides to filing a SAR in Spain, §43 GwG reports in Germany, TRACFIN in France, UTRs to FIU-Nederland and the CRF in Luxembourg. None of those national filing routes disappears; what changes is what the receiving FIU does with a report once it recognises a cross-border element.

8. FAQ

Is this RTS in force yet?

No. It is a draft out for public consultation until 6 October 2026. AMLA will finalise it and submit it to the European Commission for adoption afterwards; there is no binding text yet.

What is the legal basis?

Article 31(3) of Directive (EU) 2024/1640 (AMLD6) mandates AMLA to specify the criteria and process for cross-border exchange of information between FIUs.

How is this different from the AMLA suspicious-transaction report format RTS?

The format RTS (Article 69(3) AMLR) standardises what an obliged entity sends to its own national FIU. This RTS (Article 31(3) AMLD6) governs what the FIU does next — whether the report concerns another member state, and how it is shared onward.

What is a “cross-border dissemination” as opposed to a “cross-border report”?

A cross-border report passes the full report to another FIU. A cross-border dissemination passes only a focused set of key data — used where the receiving FIU needs enough to assess relevance without the entire file.

Does my firm need to do anything differently today?

No immediate action is required — the national filing channels are unaffected while this remains a draft. Firms with material cross-border STR/SAR exposure should track the consultation and the eventual final RTS as part of their AMLR-readiness planning ahead of the Regulation’s 10 July 2027 application date.

Does FIU.net change as a result?

The draft builds on the existing FIU.net secure network rather than replacing it — the new element is the structured criteria and coordination rules for how that network is used, not a new channel.

9. What to do, today

  • Track this consultation alongside the STR-format RTS — they are two halves of the same AMLR/AMLD6 reporting-modernisation programme, and both feed into the 10 July 2027 AMLR application date.
  • If your group has genuine multi-country STR/SAR exposure, note that the draft’s coordination principle means future follow-up requests should route through a single FIU per case — worth flagging to your MLRO/compliance function now, ahead of any binding text.
  • Do not change your national filing process yet — the existing SAR/STR channels in each jurisdiction remain the operative route until AMLA finalises and the Commission adopts the RTS.
  • If the proposal affects your operating model, consider responding to the consultation before 6 October 2026.

Related: AMLA’s harmonised STR format · Filing a SAR in Spain · AML representative across the EU

Related reads.