Skip to content
EU-wide

AMLA’s entity risk-scoring method — how supervisors will rate your inherent, controls and residual risk

Fintech Passport
August 3, 2026 · 10-min read
AMLA’s entity risk-scoring method — how supervisors will rate your inherent, controls and residual risk

From the next supervisory cycle your AML/CFT supervisor will not form an impression of your firm — it will compute a number between 1 and 4, and the arithmetic is now public. AMLA’s final report on the draft regulatory technical standards under Article 40(2) of Directive (EU) 2024/1640 sets out a single EU-wide method for assessing an obliged entity’s inherent risk, the quality of its AML/CFT controls, and the residual risk that remains. It applies to financial-sector entities and their supervisors, which puts payment institutions, e-money institutions and crypto-asset service providers squarely inside it. The useful part is that the scoring structure, the bands and the combination rule are written down — so you can score yourself before somebody else does.

1. Why this is live now, not in 2029

The mandate reached AMLA through the Commission’s 2024 call for advice to the European Banking Authority, which consulted publicly between 6 March and 6 June 2025 and responded on 30 October 2025. AMLA adopted those proposals as its own and published its final report on 16 December 2025. The draft RTS now goes to the Commission for adoption, so the text is settled in substance while the application date is not.

Running alongside it is the reason to care this year. AMLA’s parallel RTS under Article 12(7) of Regulation (EU) 2024/1620 governs how credit and financial institutions are picked for AMLA’s own direct supervision, and it reuses this same methodology as its scoring engine. That process is already collecting data: national supervisors identify entities meeting the selection criteria on a standardised template, with a 15 August 2026 deadline for the data and a provisional list of eligible entities expected by the end of September 2026. AMLA opens the first selection in 2027 and takes up direct supervision from 2028 — up to forty entities or groups, with discretion to go further in agreement with national supervisors. Eligibility turns on cross-border footprint: activity in at least six member states.

2. The three steps, in order

The methodology is deliberately sequential: supervisors classify the inherent risk profile, then the quality of AML/CFT controls, and only then derive the residual risk profile — the risk remaining once controls are taken into account.

Two design choices shape everything downstream. Inherent scores are computed automatically from reported datapoints, while controls scores come in two stages — an automated score, complemented by evidence-based professional judgement where the supervisor has it. And the assessment explicitly does not rely on an entity’s own self-assessment of the ML/TF risk it faces: your business-wide risk assessment is a controls artefact, not the input that sets your inherent score.

3. Inherent risk: four categories, scores of 1 to 4

Inherent risk indicators are grouped into four categories: customers, products and services and transaction types, distribution channels, and geographies. Within products and services, indicators on the same topic form sub-categories, and a sub-category applies only if at least one of its indicators applies to the firm.

Each indicator scores as a whole number from 1 (lowest risk) to 4 (highest risk) against pre-determined thresholds. Sub-category and category scores are weighted arithmetic averages to two decimal places, each indicator weighted by significance on a 1-to-5 scale. The entity score converts to a class:

ScoreInherent risk classControls quality class
Below 1.75Low (1)Very good (A)
1.75 to below 2.5Medium (2)Good (B)
2.5 to below 3.25Substantial (3)Moderate (C)
3.25 and aboveHigh (4)Poor (D)

A supervisor may adjust a score that does not reflect actual exposure — to capture a national risk, or where supervisory information suggests the automated score is unreliable — but only by one risk class, justified and recorded, and only on the basis of a supervisory assessment or an external auditor’s assessment available to it. Critically, the thresholds and weights are not in the RTS: AMLA sets them for each review cycle. You can model the structure of your score but not reverse-engineer the cut-offs, and a change of cycle can move your class without anything changing in your business.

4. The datapoints — and what they ask a payments firm

The RTS builds on a core set of datapoints applying to every entity, complemented by sector-specific ones, with the stated expectation that most entities will not provide more than 100 to 150 datapoints. The RTS does not fix the source, so supervisors may draw on information they already hold — from the FIU or from external auditors — rather than asking the firm again.

The sector columns in the annex are where a payments or e-money firm should stop skimming. Alongside universal customer counts — customers by legal form and country, PEPs and legal entities with PEP beneficial owners, complex ownership structures, beneficial owners resident outside the EEA, customers transacting with non-EEA countries, walk-in customers — the annex reaches features only fintech balance sheets have:

  • Virtual IBANs — master accounts with linked vIBANs, and the count and value of incoming and outgoing vIBAN transactions in the previous year.
  • Re-issued IBANs — the total, and separately the number where the end-user is not a customer of the institution.
  • Prepaid cards — cards issued and their turnover, outstanding value, customers using them, and customers holding more than three.
  • Distribution reach — agents by country, and white-labelling arrangements.
  • Cash and geography — cash aggregates including counts of natural persons whose annual cash activity exceeds a stated figure, and transaction counts and values by country in both directions.

5. Controls quality: seven categories, and the direction of the scale

Controls indicators fall into seven categories: governance, culture and the compliance function; internal controls and outsourcing; risk assessment, covering the business-wide assessment and customer risk profiling; customer due diligence and ongoing monitoring; transaction monitoring and suspicious activity reporting; targeted financial sanctions and compliance with the Transfer of Funds Regulation; and the group-wide framework.

Watch the direction of travel. An individual controls indicator scores from 1, the highest quality, to 4, the lowest, while the combined category and entity scores are expressed on the risk scale — so a high controls score means poor controls. Category weights are score-dependent: categories scoring worse carry greater weight, so a single badly failing area is not diluted by six good ones.

The indicators are concrete enough to audit yourself against. The CDD category counts customers whose beneficial owners have not been identified, and separately those identified but not verified; customers with no identification documentation; customers whose CDD data is not yet aligned with Article 20 of Regulation (EU) 2024/1624; customers with no ML/TF risk profile; and the gap between customer reviews due last year and those completed. The sanctions and funds-transfer category asks for the maximum hours between publication of a listing and its implementation in your screening tools, and the share of outbound transfers returned by a counterparty for missing or malformed information.

6. The residual formula, and its asymmetry

The combination rule is two lines long and repays reading closely. Where the controls quality score is greater than the inherent risk score, residual equals inherent. Where the controls score is lower than or equal to inherent, residual is the arithmetic average of the two. It then converts using the same four bands.

InherentControlsResidualResidual class
3.40 (High)1.20 (Very good)2.30Medium (2)
3.40 (High)3.80 (Poor)3.40High (4)
2.00 (Medium)3.60 (Poor)2.00Medium (2)
2.00 (Medium)1.00 (Very good)1.50Low (1)

Two consequences follow. Poor controls cannot inflate residual risk above inherent risk — the inherent score is a ceiling. And excellent controls cannot do better than pull residual risk halfway towards the controls score, because the best outcome available is an average. If your inherent profile is structurally high — cross-border, vIBAN-heavy, agent-distributed — the realistic objective is to move one class and reduce supervisory intensity, not to be reclassified as low risk.

7. How often, and who gets the three-year cycle

The first assessment is due no later than nine months after the date of application of the Regulation. Subsequent assessments are carried out by 30 September of the year in which they take place — an annual rhythm matching what most national supervisors already do.

There is a derogation to at least once every three years, and it is narrower than “small firm”. It applies where the entity meets any one of the stated criteria: either full-time-equivalent employees in the relevant member state number five or fewer, or the entity carries out only certain defined limited activities — insurance and credit intermediation, defined low-risk insurance undertakings, some investment firms and creditors. Payment institutions, e-money institutions and crypto-asset service providers are not on that activity list, so for a licensed payments firm the headcount limb is the only route in, and most miss it. Ad hoc assessments are separately expected where risks crystallise or material new information emerges — a change of ownership or business model, or controls failures suggesting inherent risk has moved.

8. Two scenarios

Facts: an EU e-money institution runs 900 master accounts with linked virtual IBANs for platform clients, and has re-issued IBANs where the end-user is a platform’s customer rather than its own.

What the rule says: both are named datapoints in the products-and-services category, and the re-issued-IBAN field is split precisely to isolate the case where the end-user is not a customer of the institution. Those counts feed the automated inherent score, and no argument about the platform’s onboarding changes them.

What the practitioner does: stops treating the vIBAN book as a commercial fact and starts treating it as a scored exposure. Since inherent risk here cannot be argued down, the achievable move is on the controls side — evidencing who the end-user is, how the chain is monitored, how fast a listing propagates.

Facts: a payment institution models itself at inherent 3.30 and controls 1.30, and expects a Low classification on the strength of its controls investment.

What the rule says: the controls score is lower than inherent, so residual is the arithmetic average — 2.30, which is Medium. The one-class supervisory adjustment could move it, but not to Low, and only on documented supervisory or audit evidence.

What the practitioner does: resets the internal narrative before the board hears it from the supervisor. The budget case for controls is not “we will be rated low risk”; it is “we will sit one class lower than a peer with the same book and weaker controls”.

9. FAQ

Does this RTS apply to payment institutions and EMIs?

Yes — it applies to financial-sector obliged entities and their supervisors. AMLA took a phased approach and is developing a separate RTS for the non-financial sector, with its consultation open until 27 September 2026 and a public hearing on 10 September 2026.

Can good controls make us a low-risk firm?

Only if your inherent score is already near the boundary. Because residual risk is the average of inherent and controls scores when controls are better, excellent controls move you at most halfway towards the controls score.

Will our own risk assessment set our score?

No. The methodology explicitly does not rely on entities’ self-assessments of the ML/TF risk they face. Your business-wide risk assessment is scored as a control, not as the measure of inherent risk.

How often will we be assessed?

Annually, by 30 September, with the first assessment due within nine months of the Regulation applying. A three-year cycle is available where an entity has five or fewer full-time-equivalent employees in the member state, or carries out only certain defined limited activities.

What is the link to AMLA’s direct supervision?

The selection RTS under Article 12(7) of Regulation (EU) 2024/1620 uses the same entity-level methodology to decide which cross-border institutions AMLA supervises directly, with group-level scores built as weighted averages of entity residual scores.

10. What to do, today

  • Build a shadow scorecard against the four inherent and seven controls categories, populated with real numbers even where you must estimate — a first pass tells you which category will drag your entity score.
  • Check you can actually produce the fintech-specific datapoints: vIBAN master accounts and flows, re-issued IBANs split by whether the end-user is your customer, prepaid cards per customer, agents by country.
  • Instrument the two controls metrics firms most often lack — sanctions-list-to-screening-tool latency in hours, and the share of outbound transfers returned for missing or malformed information.
  • Close the CDD counts that score directly against you: beneficial owners identified but not verified, customers with no ML/TF risk profile, and reviews due but not completed last year.
  • Tell the board the realistic target now — one residual class lower, not a low-risk badge.

Related: The AMLA harmonised suspicious-transaction report format · Cross-border STR routing between EU FIUs · DNB’s SIRA integrity risk analysis

Related reads.