Skip to content

From the FinCrime Agent course

Want to do this for a living?

This is the kind of story financial-crime professionals act on every day. Learn the craft in Marco’s AML & Financial Crime course.

AML & Financial Crime course →
Back to Issue №19

AMLA finalises three core standards for the EU AML rulebook

The EU Anti-Money Laundering Authority sent final draft standards on business relationships, customer due diligence, and group-wide arrangements to the Commission for adoption.

Review AML KYC Governance EU

What happened

On 1 October 2026, the EU Anti-Money Laundering Authority, or AMLA, finalised three sets of regulatory technical standards, known as RTS. They sit under the EU Anti-Money Laundering Regulation, or AMLR.

RTS 1 covers business relationships and occasional transactions under AMLR Article 19(9). It sets criteria for distinguishing a business relationship from an occasional transaction, identifying linked transactions, and applying customer due diligence, or CDD, thresholds consistently.

RTS 2 covers CDD under Article 28(1). It addresses the information to be collected and verified. That includes proportionate measures for lower risk situations, non-face-to-face verification, electronic identification, and screening of politically exposed persons, or PEPs, their family members, and close associates.

RTS 3 covers group-wide arrangements under Article 16(4) and Article 17(3). It sets minimum requirements for group-wide governance, risk management, internal controls, and information sharing for anti-money laundering and countering the financing of terrorism, or AML/CFT.

AMLA submitted the final draft standards to the European Commission for adoption and publication in the Official Journal of the EU. Application follows six months after entry into force. The press release gives a specific date of 10 July 2029 for football agents and professional football clubs. It does not say when the Commission will adopt the standards or when they enter into force.

Why it matters

This section is analysis. The three standards cover points where a firm’s own definitions and thresholds drive onboarding and monitoring outcomes. This suggests AMLA is narrowing the room for local interpretation on the business relationship line, linked transactions, and CDD thresholds. The stated scope of RTS 1 includes consistent threshold application, which points the same way.

Timing is the open variable. Application runs six months after entry into force, and AMLA has not said when the Commission will act. The likely effect is a short build window for firms that wait for publication in the Official Journal before starting. Teams can still scope the work now, because the press release already sets out what each standard covers.

RTS 3 deserves attention from groups with several EU entities. The likely effect is that group policy and local entity practice get tested against one common minimum.

Practitioner angle

Treat the checks below as a scoping exercise. They are things to verify in your own processes, not findings about any firm.

  • Run a gap analysis of current CDD procedures. Map each procedure against the scope of the three standards: business relationships and occasional transactions, CDD information and verification, PEP screening, and group-wide arrangements. Record owners and gaps, then re-test against the final text.
  • Check the business relationship line. Find the field or rule in your onboarding and monitoring systems that decides whether a customer is in a business relationship or an occasional transaction. Confirm both systems use the same definition, across every product and channel.
  • Check linked transactions. Identify what your rules use to link transactions, and whether CDD threshold logic applies the same linking at onboarding and in monitoring. Document the logic.
  • Inventory non-face-to-face and electronic identification journeys. List what each journey collects, what it verifies, and which vendor or tool does the verifying. Confirm that any reduced measures for lower risk situations are tied to a documented risk assessment.
  • Test PEP screening coverage. Check that screening reaches PEPs, their family members, and close associates, not only the principal. Confirm how relatives and associates are sourced, linked to customer records, and rescreened after onboarding.
  • Review group-wide arrangements across EU entities. Check that AML/CFT governance, risk management, internal controls, and information sharing are written down at group level. Identify who owns them and what currently limits information flowing between entities.

The most important step is to start the gap analysis now. Assign an owner to each standard this month, log gaps against the published scope, and re-test when the Commission adopts the final text.

Share:

Want to do this for a living?

Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.

AML & Financial Crime course →