Skip to content
EU-wide

AMLA’s harmonised STR format under the AMLR

Fintech Passport
July 13, 2026 · 9-min read
AMLA’s harmonised STR format under the AMLR

AMLA wants one suspicious-transaction report format for the whole EU — and the draft technical standards that would create it closed for comment on 20 September 2026. Today a firm operating across borders files into a different national FIU system in each country, each with its own structure, field set and validation quirks. Under Article 69(3) of the AML Regulation, a common data catalogue and adapted templates will replace that patchwork. This piece sets out what the draft implementing technical standards actually specify, how the five data-point treatments work, what the transaction-record templates cover, and the two-phase timetable that decides when any of it lands on your systems.

1. What AMLA published

The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) — established by Regulation (EU) 2024/1620 and seated in Frankfurt — opened an eleven-week public consultation on 2 July 2026 on draft implementing technical standards (ITS) specifying the format to be used for the reporting of suspicions and for the provision of transaction records. A public hearing was held on 9 September 2026, the consultation closed on 20 September 2026, and AMLA will take the responses into account in the submission it must make to the European Commission by 30 November 2026. The Commission then adopts the final implementing regulation.

The mandate comes from Article 69(3) of Regulation (EU) 2024/1624 — the AML Regulation, the single rulebook applicable across the EU from 10 July 2027. AMLA’s diagnosis is straightforward: reporting practices across the EU differ so much in structure and content that FIUs struggle to exchange information with each other, and cross-border obliged entities carry the cost of maintaining a different report for every market.

2. What the AMLR already requires

Article 69(1) obliges entities to report, on their own initiative, any knowledge or suspicion that funds or activities — including transactions and any type of behaviour, regardless of the amount involved — are the proceeds of criminal activity or are related to terrorist financing or criminal activity, and separately to provide the FIU, on request, with all necessary information including transaction records. The ITS does not create either duty. It standardises how each is discharged, so that a report filed in one member state carries the same structured data as one filed in another.

3. What “format” means in the draft

The draft defines format as two things: the content — the data points, with a definition common to all FIUs — and the technical specifications, meaning the attributes and values under which those data points are supplied, together with the data structure governing transmission. The data points and their treatment sit in the annexes; the attributes, values, validation rules and filling guidance sit in a separate interpretative note published by AMLA, so that they can be revised without reopening the regulation.

Two consequences follow for a firm building its own reporting layer. Identity, contact details, authentication and signature of the submitting entity are expressly outside the ITS — they remain national technical reporting requirements. And reports must be filled in the language used or requested by the receiving FIU, so harmonised structure does not mean a single narrative language.

4. The five treatments — the part that drives your data model

The draft rejects a minimum common denominator in favour of an exhaustive list of the data points EU FIUs use, each carrying a treatment. That treatment, not the field list, is what determines whether a gap in your records blocks a filing.

TreatmentWhat it means in practice
MandatoryRequired by FIUs and supplied systematically
Technically requiredA subset of mandatory: its absence breaks the FIU’s validation rules and prevents submission altogether
Mandatory if availableSupplied where the information is available to the entity at the time of reporting
OptionalSupplied voluntarily where it better substantiates the suspicion
DependentRequired only where a parent data point or circumstance is present; the treatment then applies
FIU-requiredApplied only where national law or national circumstances require it; FIUs not using it need not implement it

Templates are then adapted to the activity of the reporting entity and to the type of suspicion, with irrelevant data points removed — the non-financial sector in particular gets simplified, tailored formats. The draft is explicit that platforms should request only the necessary and relevant data points, and only where they support the reported suspicion: data minimisation is written into the design, and obliged entities and FIUs remain bound by their data-protection regimes throughout. Article 9 adds a data-quality duty: submissions must be complete and must satisfy the FIU’s validation, consistency and plausibility checks.

5. Transaction records — the second, stricter half

Where reports of suspicion get flexibility, transaction records get prescription. Credit and financial institutions responding to an FIU request use the template matching the activity concerned, and the draft names four: banking and payment activities, money remittance flows, crypto-asset accounts, and correspondent services. Records are transmitted electronically in a machine-readable format specified by the FIU, and must cover all transactions to or from the account over the requested period.

The definition of a transaction record is wider than a statement. It covers operations carried out over a defined period through a payment account or an IBAN-identified bank account, transfers of crypto-assets within the meaning of Regulation (EU) 2023/1113, or operations through a money or value transfer service provider. At the FIU’s request or voluntarily, those operations may include not only completed transactions but scheduled, attempted, rejected, cancelled, suspended, refrained and frozen ones. A firm that can only reproduce settled postings will not be able to answer the request as drafted.

6. The phased rollout, and what it means for planning

Nothing switches over on adoption. Article 10 sets a two-phase adaptation period for the reporting of suspicions. In the first phase, running two years from publication, FIUs assess the completeness and accuracy of the annexes, run a gap analysis against the data points they already use, and assess the impact on their platforms; AMLA then reviews the annexes with them and submits the revised version to the Commission. The second phase is technical implementation into FIU and obliged-entity systems — and its duration is still blank in the draft, to be settled after the consultation. The timeframe for the transaction-record formats is likewise open.

Two further dates are worth carrying. The annexes are subject to periodic review every four years once technical implementation is complete, coordinated by AMLA through a standing working group of FIU representatives, with changes approved by AMLA’s General Board before going to the Commission; an emergency mechanism lets an FIU add a data point ahead of the cycle where a security threat, an emerging trend or new legislation cannot wait. And under Article 87(a) of the AMLR, national reporting systems are to be assessed by 10 July 2032, an assessment that may identify the obstacles to a single Union-level reporting system.

7. What this changes for three kinds of firm

A payment institution passporting into five markets. Today it maintains five report layouts. Under the ITS the content converges, but the submission wrapper does not — authentication, contact data and signature stay national, as does the language. The winning position is a canonical internal case record mapped once to the AMLR data catalogue, with thin per-country adapters for transport and language, rather than five parallel report builders.

A firm that has never had to produce attempted or refrained transactions. The transaction-record template contemplates rejected, cancelled, suspended, refrained and frozen operations. Many monitoring stacks retain only settled postings at the depth an FIU would ask for. Finding that out when an FIU request arrives with a deadline is expensive; testing an extract now against the four activity templates is not.

A crypto-asset service provider or a remittance business. Both get their own transaction-record template, which is good news operationally — but it means the reference data that identifies a transfer under Regulation (EU) 2023/1113 has to reconcile to what the template expects. The customer due diligence data collected under Chapter III of the AMLR is explicitly taken into account in designing the data points, so gaps in onboarding records propagate directly into unfileable reports.

8. FAQ

Is the AMLA format in force yet?

No. It is a draft ITS whose consultation closed on 20 September 2026. AMLA submits its proposal to the European Commission by 30 November 2026; the Commission then adopts the final implementing regulation, after which the two-phase adaptation period begins.

What is the legal basis?

Article 69(3) of Regulation (EU) 2024/1624 mandates AMLA to specify the format for the reporting of suspicions under Article 69(1)(a) and for the provision of transaction records under Article 69(1)(b).

Will there be one EU-wide file format or schema?

Not under this draft. It requires a machine-readable format transmitted through the FIU’s reporting platform but deliberately does not prescribe a technical language or file format, so that existing national platforms can implement the data points their own way. AMLA may publish further data-model and exchange specifications that FIUs may use.

Does this replace the national FIUs?

No. National FIUs remain the recipients and keep their own platforms, validation rules and languages. What converges is the content and structure of what is reported into them.

Do we have to send every field in the catalogue?

No. The annexes set out every data point that could be submitted in any case. Each carries a treatment — mandatory, technically required, mandatory if available, optional, dependent or FIU-required — and platforms are to request only the subset relevant to the activity and the suspicion reported.

Can we attach supporting documents?

Yes. Article 6 requires attachments where the FIU requests them or issues a general instruction to that effect, and permits them spontaneously where the entity identifies documents in its possession that may support the report.

9. What to do, today

  • Map your current national STR fields against the draft catalogue and record which of your gaps sit against mandatory or technically required points — those are the ones that will block a filing, not merely degrade it.
  • Test whether you can extract attempted, rejected, cancelled, suspended, refrained and frozen transactions for a single account over a period, in a machine-readable form.
  • Separate the case record from the submission wrapper in your architecture, so that national authentication, contact and language requirements do not force a per-country report builder.
  • Check that onboarding data quality is good enough to populate the catalogue — the data points are designed around the CDD information the AMLR already requires you to hold.
  • Keep 10 July 2027 on the roadmap as the AMLR application date, and treat the ITS timetable as a separate, later track that starts on publication.

Related: Reporting suspicions under AMLR Article 69 · AMLA cross-border STR routing · Filing a SAR in Spain · §43 GwG SARs in Germany · UTRs to FIU-Nederland · Reporting to TRACFIN · The EU AML package — AMLR, AMLD6 and AMLA

Related reads.