Group-wide AML — what a parent must push down
Article 16 makes the parent undertaking responsible for something more than oversight — it must produce a group-wide risk assessment and a group-wide framework, and ensure both are actually implemented. Regulation (EU) 2024/1624 requires the parent to ensure that the requirements on internal procedures, risk assessment and staff apply in all branches and subsidiaries of the group in the Member States and, for groups headquartered in the Union, in third countries.
1. What the parent must do
Three obligations, and they are cumulative:
- Perform a group-wide risk assessment, taking into account the business-wide risk assessment performed by all branches and subsidiaries. The group assessment is built from the local ones, not instead of them — so every branch and subsidiary still owes its own.
- Establish and implement group-wide policies, procedures and controls, including on data protection and on information sharing within the group for AML/CFT purposes, and to ensure that employees within the group are aware of the requirements arising from the Regulation.
- Ensure obliged entities within the group implement those group-wide policies, procedures and controls — taking into account their specificities and the risks to which they are exposed.
2. Uniform framework, local application
The final clause of the first subparagraph creates the tension that group compliance functions live with: entities must implement the group framework taking into account their specificities and the risks to which they are exposed. That is an instruction to adapt, not to copy — and it means a group framework that leaves no room for local calibration is as non-compliant as one that is ignored locally.
| Approach | Problem |
|---|---|
| Group policy adopted verbatim everywhere | Does not take local specificities and risks into account |
| Each entity writes its own from scratch | No group-wide policies, procedures and controls exist |
| Group framework with documented local adaptations | The shape the article describes |
The workable pattern is a group layer that sets the standard and an adaptation register that records, per entity, what was changed and why — which doubles as the evidence that specificities were taken into account.
3. Third-country branches and subsidiaries
Article 17 handles what happens when local law in a third country does not permit the group standard. It is the provision to read before assuming the group framework travels intact, and it is why a group operating outside the Union needs a documented assessment of local legal constraints rather than an assumption that the parent’s rules apply.
The information-sharing limb of Article 16 connects here too. Group-wide information sharing for AML/CFT purposes is required, and Article 73(3) then permits disclosure between group entities and their third-country branches and subsidiaries provided those branches and subsidiaries fully comply with the group-wide policies and procedures, including information-sharing procedures, in accordance with Article 16 — and that those policies comply with the Regulation.
That is a conditional derogation with a compliance precondition. A group that has not evidenced Article 16 compliance at a third-country subsidiary cannot rely on Article 73(3) to share information with it.
4. Groups spanning several Member States
Article 16(1) continues with specific provision for groups with establishments in more than one Member State, and — for groups headquartered in the Union — in third countries. Multi-state groups should read that subparagraph directly rather than working from the general rule, because it is where the coordination mechanics sit.
FAQ
Does a subsidiary still need its own risk assessment?
Yes. The group-wide assessment is performed taking into account the business-wide risk assessments performed by all branches and subsidiaries, so the local ones are inputs to it.
Can we roll out one group policy unchanged?
Entities must implement the group framework taking into account their specificities and the risks to which they are exposed. A framework with no room for local calibration does not meet that.
Can we share suspicion information within the group?
Article 73(3) permits it between group entities and their third-country branches and subsidiaries, conditional on full compliance by those branches and subsidiaries with the Article 16 group-wide policies and procedures.
Related: The business-wide risk assessment · Policies, procedures and controls · Tipping-off


