Skip to content
EU-wide

The EU AML package — AMLR, AMLD6 and AMLA dates, and what changes for payment firms

Fintech Passport
August 15, 2026 · 11-min read
The EU AML package — AMLR, AMLD6 and AMLA dates, and what changes for payment firms

The EU AML package moves the substance of anti-money-laundering law out of a directive and into a regulation — which means that from 10 July 2027 the rules apply to a payment firm directly, in the same words, in every member state. That change is bigger than any individual obligation in it: firms that have spent a decade running a matrix of national transpositions have to rebuild against one text, on a fixed date. Below are the four instruments, the dates that actually bind, and the provisions of Regulation (EU) 2024/1624 that will change how a payment or e-money institution is organised.

1. Four instruments, one framework

The package is not one law. Four instruments operate together, and confusing them is the commonest source of wrong deadlines in project plans.

  • Regulation (EU) 2024/1624 (AMLR) — the single rulebook. Directly applicable obligations for obliged entities: internal policies, governance, customer due diligence, beneficial ownership, reporting, prohibitions.
  • Directive (EU) 2024/1640 (AMLD6) — the mechanisms member states must put in place: registers, FIUs, supervisors, access rules. It amends and repeals Directive (EU) 2015/849 and still needs transposition.
  • Regulation (EU) 2024/1620 — establishes the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, with both direct supervision of selected firms and indirect coordination powers.
  • Regulation (EU) 2023/1113 — the transfer-of-funds and crypto-asset transfer regulation, already in force and cross-referenced throughout the AMLR.

All three 2024 instruments were adopted at Brussels on 31 May 2024 and published in the Official Journal on 19 June 2024. From there the dates diverge sharply.

2. The dates that bind

DateWhat happensSource
1 July 2025Regulation (EU) 2024/1620 applies (Articles 1, 4, 49, 53–55, 57–66, 68–71, 100, 101 and 107 applied from 26 June 2024)Art 108 Reg 2024/1620
10 July 2025Member states transpose Article 74 AMLD6 (amendments to Directive (EU) 2015/849)Art 78(1) AMLD6
31 December 2025Article 103 of Regulation (EU) 2024/1620 appliesArt 108 Reg 2024/1620
10 July 2026Member states transpose Articles 11, 12, 13 and 15 AMLD6 — the beneficial-ownership register access rulesArt 78(1) AMLD6
10 July 2026AMLA guidelines due on the minimum content of the business-wide risk assessment; draft implementing standards on suspicious-transaction reportingArts 10(4), 69(3) AMLR
10 July 2027AMLR applies. AMLD6 transposition deadline for everything elseArt 90 AMLR; Art 78(1) AMLD6
By 1 July 2027AMLA commences its first selection process for direct supervision; concluded within six monthsArt 13(4) Reg 2024/1620
10 July 2029AMLR applies to football agents and professional football clubs; Article 18 AMLD6 (single access point to real estate information) transposedArt 90 AMLR; Art 78(1) AMLD6

3. Two named compliance roles, not one

Article 11 AMLR is the provision most likely to force an organisational chart change. It requires two distinct appointments.

The compliance manager is one member of the management body in its management function, responsible for ensuring compliance with the AMLR, with Regulation (EU) 2023/1113 and with any administrative act issued by a supervisor. That person ensures internal policies are consistent with the firm’s risk exposure and are implemented, ensures sufficient human and material resources are allocated, and is responsible for receiving information on significant or material weaknesses. Where the management body decides collectively, the compliance manager assists, advises and prepares the decisions.

The compliance officer is appointed by the management body in its management function, must have sufficiently high hierarchical standing, owns the policies and controls in day-to-day operation — including implementation of targeted financial sanctions — is the contact point for competent authorities, and is responsible for reporting suspicious transactions to the FIU under Article 69(6).

Three protections sit around the second role. Removal requires prior notification to the management body, and the firm must notify the supervisor of the removal, specifying whether the decision relates to the AMLR tasks; the compliance officer may, on their own initiative or on request, give the supervisor information about the removal. Article 11(4) requires measures to protect the compliance officer against retaliation, discrimination and unfair treatment, and to ensure their decisions are not undermined or unduly influenced by commercial interests. Article 11(5) gives the compliance officer and the audit-function head a direct reporting line to the management body in both its functions.

Article 11(6) then sets a reporting rhythm: the compliance officer draws up a report on implementation of internal policies, procedures and controls, and the compliance manager submits it to the management body at least once a year. Article 11(7) permits the two roles to be held by the same natural person only where the nature, risks, complexity and size of the business justify it. Under Article 13(2), compliance functions must also be established at group level, including a group compliance manager and, where group-level activity justifies it, a group compliance officer.

Facts: a mid-sized EMI has an MLRO reporting to the COO and no board member individually accountable for AML. Rule: Article 11(1) requires a named management-body member as compliance manager, and Article 11(5) requires the compliance officer to be able to report to the management body directly. What the team does: the board designates a compliance manager, the MLRO role is mapped onto the Article 11(2) compliance officer with a direct board line, removal procedures and supervisor notification are written into the terms of reference, and the annual report route is documented. Outcome: a governance change with board minutes and a job-description rewrite — long-lead work that cannot be done in the final quarter before the date.

4. Policies, risk assessment, training and the group

Article 9 requires internal policies, procedures and controls proportionate to the nature, risks, complexity and size of the business, covering all in-scope activities, and directed at two objectives: mitigating ML/TF risk, and — in addition to applying targeted financial sanctions — mitigating the risks of non-implementation and evasion of those sanctions. That second limb makes sanctions-evasion controls an AML deliverable in their own right rather than a screening-vendor question.

Article 10 requires a documented business-wide risk assessment, approved by the management body in its management function and, where one exists, communicated to the supervisory function. Credit institutions, financial institutions, crowdfunding service providers and crowdfunding intermediaries cannot be relieved of the individual documented assessment — the Article 10(3) relief for clear and well-understood sector risk is expressly closed to them.

Article 12 requires awareness measures and specific, ongoing training programmes — and it names the population explicitly: employees or persons in comparable positions including agents and distributors. Firms distributing through third-party networks carry the training obligation into that network.

Article 13 puts group-wide policies, procedures and controls on the parent undertaking, applying across all branches and subsidiaries in the member states and, for groups headquartered in the Union, in third countries, on the basis of a group-wide risk assessment that takes in every entity’s own assessment.

5. Customer due diligence: three thresholds, not one

Article 19 sets when CDD applies, and the thresholds differ by entity type — a point that matters for any firm holding both a payments and a crypto authorisation.

TriggerThresholdWho
Establishing a business relationshipNo thresholdAll obliged entities
Occasional transactionEUR 10,000, single or linkedAll obliged entities (Art 19(1)(b))
Occasional transfer of fundsEUR 1,000, single or linkedCredit and financial institutions, excluding crypto-asset service providers (Art 19(2))
Occasional crypto transactionEUR 1,000; below that, at least identification under Art 20(1)(a)Crypto-asset service providers (Art 19(3))
Suspicion of ML/TFNo threshold, notwithstanding any derogation or exemptionAll obliged entities (Art 19(1)(d))
Doubts about previously obtained data or identityNo thresholdAll obliged entities (Art 19(1)(e), (f))

The structural point is that a crypto-asset service provider is carved out of the transfer-of-funds threshold in Article 19(2) and given its own rule in Article 19(3), which has no zero-floor: below EUR 1,000 the provider still applies at least the identification measures in Article 20(1)(a). There is no de-minimis at which nothing is required.

6. Outright prohibitions

Article 79 turns several risk-based practices into flat bans. Anonymous accounts, anonymous passbooks, anonymous safe-deposit boxes and anonymous crypto-asset accounts are prohibited, as are anonymity-enhancing coins. Existing anonymous accounts, passbooks and boxes must be subjected to customer due diligence before they are used in any way — a remediation duty attached to first use, not to a review cycle.

Article 79(2) reaches acquiring: credit institutions and financial institutions acting as acquirers within the meaning of Article 2(1) of Regulation (EU) 2015/751 shall not accept payments carried out with anonymous prepaid cards issued in third countries, unless regulatory technical standards adopted under Article 28 provide otherwise on the basis of proven low risk. That is a card-scheme-level acceptance rule sitting inside an AML regulation, and it lands on the acquiring rulebook rather than on the onboarding team.

Article 79(3) prohibits companies from issuing bearer shares, with a conversion, immobilisation or deposit deadline of 10 July 2029 — after which voting and distribution rights are automatically suspended — and cancellation of shares still outstanding on 10 July 2030. Article 80 caps cash payments for goods or services at EUR 10,000, single or linked, with member states free to set lower limits and existing lower national limits preserved; payments between natural persons not acting in a professional capacity, and payments or deposits made at the premises of credit institutions, e-money issuers and payment service providers, are outside the cap.

7. Reporting: attempts count, and the clock is five days

Article 69(1) requires prompt reporting to the FIU where the entity knows, suspects or has reasonable grounds to suspect that funds or activities, regardless of the amount involved, are the proceeds of criminal activity or related to terrorist financing or criminal activity. The second subparagraph is explicit that attempted transactions, and suspicions arising from the inability to complete customer due diligence, are reportable on the same footing.

The operational change is the response clock. Obliged entities must reply to FIU requests for information within five working days; in justified and urgent cases the FIU may shorten that, including to less than 24 hours. The FIU may extend it where justified. A sub-24-hour turnaround on transaction records is a staffing and data-access design constraint, not a policy statement.

Article 69(2) also codifies how suspicion is to be formed: on the basis of any relevant fact known to the entity, with prioritisation by urgency and by the risks affecting the member state of establishment, and grounded in the characteristics of the customer and counterparts, the size, nature, methods and patterns of the transaction, links between transactions, the origin, destination or use of funds, and consistency with the customer’s risk profile.

8. Who AMLA will supervise directly

Direct supervision is narrow, but the assessment population is not. Article 12 of Regulation (EU) 2024/1620 requires AMLA, with financial supervisors, to carry out a periodic assessment of credit and financial institutions and their groups where they operate in at least six member states including the home member state — whether through establishments or under the freedom to provide services, and regardless of whether the activity is carried out through local infrastructure or remotely. Inherent and residual risk profiles are classified as low, medium, substantial or high, at group level where the entity is part of a group.

Article 13(1) then makes entities whose residual risk profile is classified high the selected obliged entities. If more than 40 qualify, AMLA may agree a higher specific number, prioritising those operating in the most member states; Article 13(3) adds a per-member-state top-up so that no member state is left without a selected entity where a high-risk institution exists there.

The timetable in Article 13(4) is precise: the first selection process commences by 1 July 2027 and concludes within six months; the list is published without undue delay; and AMLA commences direct supervision six months after publication. Selection then repeats every three years.

Facts: an EMI licensed in one member state passports into eleven others, almost all under the freedom to provide services with no local establishment. Rule: Article 12(1) counts freedom-of-services activity, so the firm sits inside the assessment population even though it has no branches. What the team does: it prepares to supply the information AMLA requires under Article 12(2), and treats the residual-risk classification — not the inherent one — as the variable it can influence, since Article 13(1) selects on residual risk. Outcome: control effectiveness evidence becomes a supervisory-perimeter question, and passporting breadth becomes a compliance-resourcing input rather than only a commercial one.

9. Questions we get asked

When does the AMLR actually apply?

From 10 July 2027, per Article 90, except for football agents and professional football clubs — Article 3, points (3)(n) and (o) — for whom it applies from 10 July 2029.

Do we still need to watch national law?

Yes. AMLD6 must be transposed by 10 July 2027, with earlier deadlines for Article 74 (10 July 2025) and Articles 11, 12, 13 and 15 (10 July 2026), and a later one for Article 18 (10 July 2029). Member states may also set cash limits below the EUR 10,000 in Article 80 AMLR.

Is the compliance officer the same as an MLRO?

Functionally close, but the AMLR names two roles: a compliance manager who is a member of the management body, and a compliance officer who runs day-to-day AML/CFT and files suspicious transaction reports under Article 69(6). One person may hold both only where size, nature, risks and complexity justify it.

Does the EUR 1,000 transfer-of-funds threshold apply to our crypto arm?

No. Article 19(2) expressly excludes crypto-asset service providers, which are instead covered by Article 19(3): CDD at EUR 1,000 for occasional transactions, and at least the Article 20(1)(a) identification measures below it.

Will AMLA supervise us directly?

Only if you are classified as high residual risk and operate in at least six member states, including through freedom of services. The first selection commences by 1 July 2027, concludes within six months, and direct supervision begins six months after the list is published.

How fast do we have to answer the FIU?

Five working days under Article 69(1), which the FIU may shorten in justified and urgent cases, including to under 24 hours.

10. What to do, today

  • Fix the governance split first. Appointing a compliance manager from the management body and re-papering the compliance officer role takes board time, not project time.
  • Rebuild policies against the AMLR text, not against national transpositions — and add the sanctions non-implementation and evasion limb from Article 9(1)(b).
  • Re-baseline CDD triggers on the three thresholds in Article 19, keeping the crypto carve-out separate in the rules engine.
  • Audit for anonymity. Article 79 requires CDD before any further use of an existing anonymous product, and closes anonymity-enhancing coins outright.
  • Check the acquiring rulebook against Article 79(2) on anonymous third-country prepaid cards.
  • Test the FIU response path against a sub-24-hour request, including out-of-hours data access.
  • Extend training coverage to agents and distributors, which Article 12 names expressly.
  • Count your passported member states. Six or more, including freedom of services, puts you in the AMLA assessment population under Article 12 of Regulation (EU) 2024/1620.

Related: The AMLA harmonised STR format · AMLA entity risk-scoring methodology · Payer and payee information on transfers of funds

Related reads.