The AMLR, or Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), is the European Union's single anti-money laundering rulebook, directly applicable in every member state from 10 July 2027. It is the centrepiece of the EU's new anti-money laundering package, and for financial institutions it marks a shift from years of nationally implemented directives to one uniform set of rules. Yet when we polled compliance professionals in our webinar, nearly 70 percent said they were not, or probably not, ready for it.
This article explains what the AMLR changes, and draws on that webinar to show why it will test your compliance architecture, not your team.
The AMLR harmonises anti-money laundering and know-your-customer obligations across every member state, standardising how KYC, AML and CDD obligations are applied rather than leaving them to diverge from one country to the next. For financial institutions, the AMLR marks a shift from years of nationally implemented directives to one directly applicable set of rules.
A directive sets objectives that each member state must transpose into national law, which is why AML requirements have historically varied from one country to the next. A regulation is different: it is directly applicable, taking legal effect in the same form across all member states without national transposition. By replacing the patchwork of national rules with one uniform text, the AMLR removes the divergence that left obliged entities operating in several countries facing inconsistent requirements.
It sits alongside two other instruments in the EU AML package:
The regulation was adopted in 2024 as part of the wider AML/CFT legislative package. Its main substantive provisions apply from 10 July 2027, giving obliged entities a defined runway to adapt their processes, data models, and systems before the rules take effect. This is not an indefinite horizon: the preparation window is finite, and the operational changes the AMLR requires take time to design and embed.
Two intermediate deadlines matter more than the 2027 date itself. The first has already passed: the first package of regulatory technical standards, including the RTS on customer due diligence measures under Article 28(1) AMLR, was due to the European Commission on 10 July 2026, so the binding shape of the standard is now largely visible in the drafts publicly consulted in the first half of 2026. The second concerns digital identity: Regulation (EU) 2024/1183, eIDAS 2.0, requires Member States to make the European Digital Identity Wallet available by 24 December 2026, with an acceptance obligation for listed private actors, including banks, from 24 December 2027. These timelines overlap: an identification architecture built in 2026 has to work under the AMLR, absorb the EUDI Wallet at an uneven pace across countries, and stay explainable for the entire retention period of the files.
The AMLR introduces several concrete changes that reshape day-to-day compliance operations.
Customer due diligence becomes far more prescriptive. The regulation clarifies and standardises how obliged entities perform customer identification, verification, beneficial-ownership checks, and ongoing monitoring, with more measurable requirements on identity verification. The risk-based approach remains, but it becomes more demanding: every decision must be documented and defensible, showing how, why, and on what basis it was reached, rather than a general assertion that risk was assessed. Our deep dive on what the AMLR changes for customer due diligence walks through this in detail.
The AMLR sets a harmonised threshold for identifying a beneficial owner at 25 percent ownership or control, applied consistently across the EU. It also expands the data set that must be collected and held for each beneficial owner, including full legal names, all nationalities, national identification numbers, dates of birth, residential addresses, and detailed ownership percentages across the ownership chain. Meeting this at scale is where automated UBO verification and register integration earns its place.
The regulation introduces an EU-wide limit of 10,000 euro on large cash payments for goods and services, and requires customer identification for cash payments from 3,000 euro. This restricts the anonymity that high-value cash transactions can provide and gives supervisors a common baseline rather than differing national ceilings.
The population of obliged entities widens. The AMLR brings additional sectors into scope, extending AML obligations beyond the institutions traditionally covered so that a broader range of businesses must apply due diligence and reporting duties.
These are the changes with the broadest operational impact, not the whole regulation. The AMLR goes further, from enhanced due diligence to reporting obligations, and the full text on EUR-Lex remains the definitive reference.
The Anti-Money Laundering Authority (AMLA) is the new EU-level body created to give the single rulebook consistent teeth. AMLA will directly supervise a selection of the highest-risk cross-border financial institutions and will coordinate national supervisors to ensure the AMLR is applied uniformly rather than interpreted differently from one country to the next. We looked at how it will operate in our note on the AMLA regulation and technical standardisation. For obliged entities, this means integrated European supervision with less local flexibility, and a higher premium on standardised, defensible processes.
Understanding the AMLR is the first step; translating it into an operating model that can withstand integrated European supervision is the harder one.
Three articles of the AMLR make this concrete rather than aspirational.
A simple test cuts through the abstraction. Take a file accepted eighteen months ago and check whether these six questions can be answered without reconstruction:
If answering means reopening several tools and rebuilding a timeline by hand, the framework is documented, not demonstrable. That gap, between documented and demonstrable, is what the rest of this piece is really about.
The conversations we have with compliance managers across Europe share a common thread. The effort is there. The talent is there. And yet the system keeps getting more expensive, more manual, more fragile. Alert volumes rise. Onboarding timelines stretch. Audit preparation feels like a crisis every time.
Frank Verhaest, Partnership Director at Harmoney, opened the webinar with a reframe that resonated throughout the session:
"They work hard. They do their job well. The problem is not the effort. The problem is the architecture."
Most compliance frameworks were not designed. They were accumulated. A system added after an audit. A new layer after a regulation. Another tool after a fine. Each decision made sense at the time. The result is an architecture built in layers, never designed as a whole.
AMLR will not break your team. It will expose the architecture.
The webinar introduced the FAILS framework, five structural bottlenecks that prevent sustainable compliance progress:
Each one is real. Together, they form a cycle that local fixes cannot break. More rules generate more alerts. More alerts drive more manual processing. More manual processing creates fatigue. Fatigue increases the risk of missing real threats. Real threats prompt more rules. And the loop continues. Adding another tool or another rule does not break this cycle. It adds weight to a system that is already bending.
The real question compliance leaders need to ask is not "are we AMLR compliant today?" Most organisations are, at least partially.
The question is: can our model survive tomorrow?
Financially. Operationally. Structurally. AMLR raises the bar on traceability, risk-based decision-making, and consistent documentation in ways that a fragmented architecture will struggle to meet. Not because of a lack of will, but because of how the system was built.
Regulation (EU) 2024/1624 is directly applicable across all Member States from 10 July 2027, with no national transposition needed. AMLA's direct supervision of a selection of entities begins in 2028.
Yes. Article 22(6) accepts electronic identification meeting eIDAS assurance levels, "substantial" or "high", alongside traditional documents, provided the reliability is equivalent and demonstrated.
No. Article 24 treats register information as a starting point for verification, not sufficient proof on its own. The obligated entity remains responsible for verifying that it matches the actual control structure.
It rests on four properties: being able to reconstruct why an identity was judged trustworthy years later, explicit proportionality so a given level of vigilance can be justified against a given risk profile, consistency between written policy and day-to-day practice, and continuity, since identification does not stop at onboarding.
No specific technology is prescribed. The regulation sets an outcome: reliable, risk-proportionate, demonstrable identification. The useful question isn't which tools to replace, but whether the tools already in place produce a traceable, explainable decision.
AMLR asks whether an identity can be demonstrated as reliable, and kept reliable. Our white paper, written with ShareID, Trustfull and ID Protect, shows what that takes in practice. Download From document verification to mastering identity entities free for the full analysis, including worked cases in insurance and in auto credit and leasing. ⬇️