From Rulemaking to Supervision: What AMLA Means for Compliance Teams

From Rulemaking to Supervision: What AMLA Means for Compliance Teams

 

AMLA’s first annual report shows that the European Union’s new anti-money laundering and counter-terrorist financing framework is moving from legislative design towards operational implementation. Common supervisory methodologies, data collection exercises and technical standards are beginning to shape expectations for banks, professional services firms and other gatekeepers across Europe. For firms in Cyprus, preparation is increasingly becoming a practical compliance consideration rather than a future policy discussion.

 

Key Takeaways

 – The EU AML/CFT framework is moving from legislative design towards common operational standards.

 – AMLA’s direct supervision is expected to cover up to 40 selected high-risk financial institutions or groups from 2028, although its methodologies are likely to influence the wider market.

 – Data quality, documented risk decisions and evidence of control effectiveness should be priority areas for firms preparing for the new framework.

 – Cyprus-regulated entities are already participating in AMLA-related data collections and preparatory exercises through national supervisors.

 

A European system is taking shape

The Authority for Anti-Money Laundering and Countering the Financing of Terrorism matters not simply because the European Union has created a new agency, but because of the architecture taking shape around it: a directly applicable Anti-Money Laundering Regulation (AMLR), a recast directive governing national systems (AMLD6), a European authority with direct and indirect supervisory powers, and a programme of technical standards intended to create a common supervisory language.

Chair Bruna Szego described that shift when she presented AMLA’s 2025 Consolidated Annual Activity Report to the European Parliament’s ECON and LIBE committees on 15 July 2026. Her overall assessment was that the Authority was on track. AMLA became operational on 1 July 2025, established its governance bodies, completed the transfer of the European Banking Authority’s AML/CFT mandate, signed cooperation arrangements with the European Central Bank and the European Supervisory Authorities, and ended the year with 119 staff from 24 Member States.

By the July 2026 hearing, AMLA’s headcount had reached 157. Szego told the committees that the Authority expected to reach 233 staff by the end of 2026 and approximately 432 by the end of 2027. This rapid growth illustrates the scale of the transition from institutional establishment to regulatory and supervisory delivery.

The more consequential work for industry is the machinery AMLA is building to determine how risk is assessed, how supervisors cooperate, what firms report and which cross-border groups move under direct European supervision. Six draft instruments had reached the European Commission by mid-2026; eleven further mandates were expected during 2026 and fourteen in 2027. AMLA has also requested phased delivery for certain mandates so that proportionality, sectoral differences and stakeholder participation are not sacrificed for speed.

The practical effect is not a single supervisor replacing national authorities. It is the progressive convergence of national interpretations around a common European rulebook, increasingly standardised data and more comparable supervisory judgments across the Union.

 

From Directive to Single Rulebook

The AMLR will apply in the main from 10 July 2027. Unlike a directive, it will be directly applicable in every Member State. Many operational obligations – including customer due diligence, beneficial ownership analysis, internal controls, suspicious transaction reporting and enhanced measures in higher-risk situations – will therefore be governed by one European regulation rather than being reproduced differently in each national legal system.

National law will nevertheless remain relevant. AMLD6 requires transposition, Member States retain certain options, and national supervisors will remain responsible for most obliged entities. The objective is greater convergence, not the disappearance of national institutions or every local rule.

AMLA’s Level 2 and Level 3 instruments will supply much of the operational detail. Its 2026 consultations show where the main implementation questions lie: distinguishing business relationships from occasional transactions; identifying linked or fragmented transactions; specifying the information and documents required for standard, simplified and enhanced due diligence; setting expectations for business-wide risk assessments and group-wide controls; standardising ongoing monitoring; and harmonising suspicious transaction report formats.

None of this makes compliance mechanical. Proportionality and risk remain central. Firms will still have to justify why the depth of due diligence and monitoring is appropriate to the risks associated with a customer, product, channel, geography or transaction. What changes is the evidentiary bar: a risk-based decision that cannot later be reconstructed from reliable data, documented reasoning and governance records will be more difficult to defend under a common rulebook.

 

Key Implementation Milestones

Date

Milestone

3 September 2026

Deadline for AMLA consultation on draft guidelines relating to ongoing monitoring of business relationships

End-2026

Expected completion of validation work on AMLA’s risk-assessment models and readiness for joint FIU analytical activities

10 July 2027

Main AMLR application date; AMLD6 transposition deadline; transfer of FIU.net management to AMLA

July to December 2027

First selection procedure for up to 40 directly supervised financial institutions or groups

End-2027

AMLA projects staffing levels of approximately 432 employees

2028

AMLA begins direct supervision of selected entities

10 July 2029

AMLR obligations become applicable to professional football clubs and football agents within the defined scope of the Regulation


Subject to any subsequent updates published by AMLA.

 

What This Means for Firms Now

Existing obliged entities do not need to discard their current AML/CFT frameworks. Current EU and national requirements remain applicable until the relevant provisions of the new framework become applicable, while existing EBA AML/CFT guidelines remain in effect unless and until replaced by AMLA instruments. The immediate task is to identify where existing systems may not produce the data, consistency or audit trail expected by the emerging European model.

 – Enterprise-wide risk assessment. Can the firm’s taxonomy, methodology and approval records map to AMLA’s common factors and explain both inherent and residual risk?

 – Beneficial-owner data. Is information complete, current and verifiable for complex legal persons, trusts and nominee arrangements, with an effective discrepancy-escalation process?

 – CDD triggers. Can systems distinguish an ongoing relationship from an occasional or connected transaction, including attempts to divide activity below relevant thresholds?

 – Ongoing monitoring. Is customer information sufficiently current, and can alert decisions be linked clearly to the customer’s risk profile and behaviour?

 – Group control. Can policies, information sharing, third-country restrictions and control performance be evidenced consistently across branches and subsidiaries?

 – Suspicion reporting. Can the organisation produce accurate structured data and clear narratives in preparation for a common EU reporting format?

 – Do boards receive reliable management information and a traceable view of risk appetite, exceptions, remediation, resources and control effectiveness?

The population of obliged entities is also expanding or being clarified. It includes crypto-asset service providers, crowdfunding service providers and intermediaries, specified traders and intermediaries in precious metals, precious stones, cultural goods and other designated high-value goods, investment-migration operators, non-financial mixed-activity holding companies and, from 10 July 2029, professional football clubs and football agents within the Regulation’s defined scope. The AMLR also establishes a EUR 10,000 maximum for cash payments for goods or services, while permitting Member States to maintain or adopt lower limits.

 

Direct Supervision: Up to 40 Entities, Wider Influence

AMLA will begin its first selection procedure on 1 July 2027 and assume direct supervision in 2028. The first cycle will cover up to 40 selected financial institutions or groups that are active in at least six Member States and are assessed as presenting a high residual-risk profile under the harmonised methodology.

During 2026, AMLA and national supervisors have been testing the risk-assessment model using real data. National supervisors are also collecting information to identify provisionally eligible entities. CySEC, for example, issued its first AMLA-related data request at the end of 2025 and followed it in June 2026 with the standardised eligibility reporting exercise.

This matters even for firms that do not expect to be selected. Direct supervision is likely to operate as a benchmark rather than an enclave: AMLA’s expectations for governance, data quality, risk assessment and remediation among selected institutions will influence supervisory practice in the wider market. AMLA’s convergence work, thematic reviews, indirect supervision of the financial sector, oversight of non-financial supervision and participation in supervisory colleges are likely to reinforce that influence over time.

 

What the EuReCA Data Shows

AMLA’s first annual report also contains useful supervisory intelligence from EuReCA, the European Reporting System for Material AML/CFT Weaknesses. Responsibility for analysing EuReCA data moved from the EBA to AMLA in October 2025, with the system serving as the EU’s repository for significant AML/CFT deficiencies identified by competent authorities.

During 2025, EuReCA received 1,385 submissions from 45 authorities covering 213 entities. Reported supervisory responses included EUR 39.5 million in fines, mainly imposed on credit institutions. Among the 213 entities covered by EuReCA submissions, customer-related risks affected 69%, high-risk transaction risks 62%, high-risk products and services 53%, and geographical risks approximately 30%. These figures describe the reported EuReCA population; they should not be interpreted as prevalence rates for the entire European market.

The reported weaknesses included failures in customer and beneficial-owner identification, inadequate politically exposed person screening, misclassified customer risk, shortcomings in transaction monitoring, repeated small transactions below thresholds, and insufficient controls over correspondent banking, private banking and crypto-asset services. Geographical risks were principally associated with exposure to high-risk third countries and failures to comply with targeted financial sanctions. Full-scope on-site inspections remained the principal means of detecting deficiencies.

AMLA is also developing its Central AML/CFT Database, exploring advanced analytics and secure AI-supporting tools, and preparing to take over FIU.net. The direction is clear: incomplete ownership information, inconsistent identifiers and poorly structured alert outcomes will increasingly affect regulatory reporting and supervisory comparability as well as internal compliance.

 

Implications for Cyprus

Cyprus combines an international banking and investment-services sector with funds, administrative service providers, legal and accounting professions, real-estate activity and an expanding crypto-asset perimeter. These sectors create legitimate cross-border value, but they also require mature controls over complex ownership structures, international customer bases, sanctions exposure, source of wealth and source of funds, and multi-jurisdictional activity.

Cyprus is already connected to AMLA’s governance and implementation. The Central Bank of Cyprus participates in AMLA’s General Board in its supervisory composition on behalf of Cyprus’s public-sector supervisory authorities. AMLA Chair Bruna Szego visited Cyprus on 30 October 2025 and held discussions at the Central Bank of Cyprus with national competent authorities, MOKAS and associations representing obliged entities.

That cooperation has since become operationally visible. CySEC began collecting AMLA-related information from regulated entities through Circular C748 in December 2025, with further information provided through Circular C749. It subsequently issued Circular C783 in June 2026, requiring the specified entities authorised by 31 December 2025 to submit AMLA’s standardised eligibility template by 26 June 2026. Circular C783 expressly warned that failure to comply promptly and properly could attract administrative penalties under the CySEC Law.

National responsibilities remain central: the Central Bank of Cyprus, CySEC and other designated authorities continue to supervise obliged entities within their respective sectors, while MOKAS remains Cyprus’s Financial Intelligence Unit. AMLA reinforces and connects this system; it does not eliminate national supervision. For Cyprus-based firms, waiting until 2027 would therefore be a mistake. European data requests and preparatory exercises are already part of domestic supervisory workflows.

 

Six Actions for Boards and Compliance Teams

 1.Build a legal and policy inventory. Map AMLR, AMLD6 and AMLA requirements against Cyprus legislation, supervisory directives, EBA guidance and internal policies. Distinguish clearly between requirements already in force, adopted requirements not yet applicable and proposals that remain under development.

 2.Test data readiness. Assess whether customer, beneficial ownership, transaction, geographic, product and control-effectiveness data can be extracted accurately and reconciled across systems and entities.

 3.Rehearse the European risk assessment. Compare enterprise-wide and customer-risk methodologies against AMLR risk factors and AMLA’s emerging supervisory approaches. Document expert judgement, overrides and governance decisions.

 4.Review cross-border operating models. Clarify home-host responsibilities, information-sharing arrangements, outsourcing structures, third-country constraints and group-wide control consistency.

 5.Demonstrate effectiveness. Move beyond policy documentation. Use quality assurance testing, thematic reviews, remediation outcomes and management information to demonstrate that controls operate effectively in practice.

 6.Engage while standards are developing. Monitor AMLA and local supervisory consultations, contribute through industry bodies where appropriate and provide evidence on proportionality, feasibility and sector-specific considerations.

 

A Broader Strategic Perspective

AMLA is frequently viewed primarily through the lens of compliance burden. Yet one of the broader objectives of the Single Rulebook is to reduce inefficiencies arising from divergent national interpretations, support greater consistency in cross-border supervision and encourage investment in high-quality data and effective controls.

For Cyprus, where financial and professional services depend heavily on international confidence, effective implementation may ultimately strengthen competitiveness as well as compliance outcomes.

AMLA’s 2025 Annual Report should therefore be viewed as more than an account of the Authority’s first year of operation. It signals an ongoing transition from institutional establishment towards supervisory implementation. Over the coming years, firms are likely to face increasing expectations regarding data quality, risk governance and demonstrable control effectiveness.

The organisations best positioned for 2027 and beyond are unlikely to be those that simply undertake late-stage policy revisions. Rather, they will be the firms capable of explaining their risks, producing reliable data and demonstrating, through evidence, that their AML/CFT controls work effectively in practice.

Explore EIMF’s AML self paced training and CPD programmes or Live online and in person CPD and training programmes for practical guidance on preparing for the European Union’s evolving AML/CFT framework.

 

Sources and further reading

AMLA, 2025 Consolidated Annual Activity Report

Bruna Szego, Opening Statement to the ECON and LIBE Committees, 15 July 2026

AMLA, Single Programming Document 2026-2028

AMLA, Regulatory Instruments register

Regulation (EU) 2024/1624 – AMLR

Directive (EU) 2024/1640 – AMLD6

Regulation (EU) 2024/1620 establishing AMLA

CyprusMail, AMLA Chair visits Cyprus, 31 October 2025

CySEC Circular C783 – AMLA eligibility information

CySEC AML/CFT circulars index

Note: This article reflects the published AMLA programme and legal and regulatory materials reviewed as of August 2026. Draft technical standards and guidelines may change before final adoption. It provides general information and does not constitute legal or regulatory advice.



Days
Hours
Minutes
Seconds

Early bird discount

13 November 2025

Navigating Conflict for Collaborative Teams: Leading with Confidence

Join us to gain insights from Alana Hill, learn practical strategies for turning conflict into opportunity, and discover how challenges can drive growth and stronger team performance.

Days
Hours
Minutes
Seconds

Limited Time

30% Discount

On All Self-Paced eLearning CPD Courses in Financial Regulation

Days
Hours
Minutes
Seconds

Limited Availability

05 June 2025

Corporate Governance Today: Trends and Challenges

Hosted by the EIMF and the Chartered Governance Institute

Engage with 20+ leading experts and earn 6 CPD units in Financial Regulation.

Get Inspired by Our Head of Accounting

Think. Choose. Grow.

Not sure if it’s right for you? Let’s talk.

Days
Hours
Minutes
Seconds

limited time

PAIR UP AND SAVE

BUY ONE, GET ONE FREE

Short Self-Paced Online Courses

Days
Hours
Minutes
Seconds

Limited time

New Year, new you

10% discount on All Courses

Discount Coupon: NYNY10

Valid until 31 Jan 2025 23:59

EIMF's Christmas Advent Calendar

Unwrap the Gift of Knowledge this Festive Season!

Register now to receive a valuable educational resource each day and be automatically entered into our Grand Christmas Draw on 24th December – Don’t miss out!

Days
Hours
Minutes
Seconds

Limited time

black friday has arrived

up to 40% discount

On Self-Paced eLearning Courses

Days
Hours
Minutes
Seconds

Limited Availability

17 October 2024

Regulatory & AFC Compliance Conference

Hosted by the ACAMS Cyprus Chapter and the EIMF.

Engage with 17 leading experts, explore 12 critical areas, earn 6 CPD units in Financial Regulation, gain 4 ACAMS credits, and receive a Certificate of Participation.

Celebrate 9 Years with EIMF

EIMF Has Assisted 6,000+ Professionals Get Certified

 

Ready for your next professional certification? Choose from 9 self-paced eLearning courses and enjoy a 30% discount!

*complete your purchase before 21 April 2024

Starts 20 February 2024

Master in Governance,
Risk & Compliance

Accredited by the CyQAA, our GRC programme empowers you to navigate complex regulations, manage risks, and fortify governance structures. Dive into a dynamic learning experience that ensures ethical operations, regulatory compliance, and risk reduction.

✅ Explore Scholarships & Financial Aid ✅ Discover the Match Funding Scheme