AMLA EU

Key takeaways

  • AMLA is the Anti-Money Laundering Authority, the EU’s first supranational AML supervisor.
  • It was established by Regulation (EU) 2024/1620, in force since 26 June 2024, and has been headquartered in Frankfurt am Main since February 2025.
  • It is already operating. It took over the European Banking Authority’s AML/CFT mandates on 1 January 2026, but direct supervision of selected firms starts in 2028.
  • AMLA will directly supervise up to 40 cross-border financial groups, with the first selection made in 2027.
  • The rules AMLA enforces, the AMLR, apply from 10 July 2027 which is the date that matters most for your onboarding and AML screening processes as you select your AMLR provider.

What is AMLA EU?

AMLA is the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, an EU agency created to supervise how firms prevent money laundering and terrorist financing, and to make that supervision consistent across the single market.

It was set up by Regulation (EU) 2024/1620 of 31 May 2024 and in force from 26 June 2024.

AMLA exists because AML enforcement in the EU was fragmented. It’s the EU’s answer to that problem: one authority with the power to supervise the highest-risk cross-border firms directly, to push national supervisors towards a common standard, and to coordinate financial intelligence units.

Where is AMLA based?

AMLA is based in Frankfurt am Main and its staff moved into offices in the MesseTurm in February 2025.

Frankfurt was chosen partly for proximity to the European Central Bank and the European Insurance and Occupational Pensions Authority, and partly because Germany offered to host the authority in a city with an established financial-supervision ecosystem alongside BaFin.

AMLA EU at MesseTurm in Frankfurt

Is AMLA operational yet?

Yes, partly. AMLA has legal existence, a leadership team, premises and a budget, and it has already begun exercising some of its powers. What it does not yet do is directly supervise firms.

AMLA timeline: 2024 to 2028

DateMilestone
31 May 2024Regulation (EU) 2024/1620 adopted
19 June 2024AML package published in the Official Journal
26 June 2024AMLA regulation enters into force
Jan 2025Bruna Szego appointed Chair
Feb 2025Staff move into the MesseTurm, Frankfurt
Mid-2025AMLA begins most of its activities
1 Jan 2026EBA transfers AML/CFT mandates and EuReCA to AMLA
10 July 2027AMLR applies; AMLD6 transposition deadline; first selection of directly supervised entities
2028Direct supervision of selected obliged entities begins

AMLA vs AMLR vs AMLD6: what’s the difference?

The June 2024 AML package contains three separate legal instruments, and they are routinely confused:

  • AMLA is the supervisor
  • The AMLR is the rulebook
  • AMLD6 is the directive that Member States must transpose into national law.
InstrumentWhat it isKey date
AMLA Regulation — (EU) 2024/1620Creates the authority, defines its powers and governanceIn force 26 June 2024
AMLR — (EU) 2024/1624The single rulebook: directly applicable obligations on obliged entities, including customer due diligenceApplies 10 July 2027
AMLD6 — (EU) 2024/1640Rules for Member States: supervisors, FIUs, beneficial ownership registersTransposition by 10 July 2027

For most compliance teams, AMLR is the instrument that changes day-to-day work, because it replaces nationally transposed rules with one directly applicable set of obligations. Our article on what AMLR means for financial services covers those obligations in detail.

What does AMLA do?

AMLA has four functions:

  1. Direct supervision of a small group of high-risk cross-border firms
  2. Indirect supervision of everyone else through national authorities
  3. Coordination and support of financial intelligence units
  4. Development of the technical standards that turn the AMLR into operational rules.

1. Direct supervision of selected obliged entities

From 2028, AMLA will directly supervise a group of firms known in the legislation as selected obliged entities, capped at 40 at any one time.

What AMLA can demand and inspect

AMLA’s investigative powers are broad. It can require an entity to hand over internal documents, books and records, internal audit reports, and access to software, databases and IT tools. Notably, it can also demand records of algorithmic decision-making, meaning automated risk-scoring, screening and monitoring logic must be documented and explainable, not just effective.

It can compel oral or written explanations from staff and management, and carry out on-site inspections. Where national law requires it, inspections need prior judicial authorisation.

Penalties and corrective measures

Where AMLA finds a breach, it can order the entity to comply, restrict or limit its business or network, and require governance changes, including the removal of members of the management body.

It can also impose pecuniary sanctions of up to €2 million or 1% of annual turnover, whichever is higher, and levy periodic penalty payments to force ongoing compliance. Decisions can be challenged before the Administrative Board of Review and then the Court of Justice of the European Union, which has unlimited jurisdiction to annul, reduce or increase a sanction.

2. Indirect supervision and national regulators

Every firm not on the selected list stays with its national supervisor, BaFin in Germany, the ACPR in France, and so on. AMLA’s role here is convergence rather than enforcement.

It carries out assessments of national supervisors, issues guidelines and recommendations, and can require a national authority to answer a request within 10 working days. Where it suspects a systematic failure in how a Member State supervises AML, it can open an investigation with a one-month window for the authority to respond, and ultimately issue a binding decision.

In practice this means firms outside the top 40 will still feel AMLA’s influence through the expectations their own supervisor adopts, and through the technical standards AMLA writes.

3. Coordinating financial intelligence units

AMLA supports Member States’ financial intelligence units, but it is not a European central FIU. It does not receive suspicious transaction reports directly and it cannot instruct an FIU to investigate.

What it does is enable cooperation: it conducts joint analyses of cross-border cases, provides hit/no-hit cross-matching so an FIU can discover that another Member State holds relevant information, hosts delegated FIU staff in Frankfurt, and manages the FIU.net communication network transferred from the Commission.

4. Building the single rulebook

Much of AMLA’s near-term output is technical. It is responsible for drafting more than 80 technical standards, guidelines and opinions that specify how the AMLR’s obligations work in practice, including the detail of customer due diligence, risk assessment methodology and reporting.

Who does AMLA supervise?

Directly, at most 40 credit institutions and financial groups operating across at least six Member States. Indirectly, every obliged entity in the EU through the standards it sets and the national supervisors it oversees.

The AMLR also widens the definition of an obliged entity beyond the traditional financial sector. Newly captured categories include crypto-asset service providers, non-financial mixed-activity holding companies, credit intermediaries, investment migration operators, and professional football clubs and football agents.

Crypto and virtual asset service providers

Crypto-asset service providers are explicitly in scope of the AMLR, and AMLA has signalled that cross-border crypto firms and novel payment channels are a supervisory priority, though which specific entities fall into the first selection has not been decided.

The context is straightforward: illicit crypto flows have grown sharply, with recent estimates putting funds received by laundering-linked addresses at tens of billions of dollars a year, up roughly eightfold over five years. CASPs operating across several Member States should assume they are candidates for AMLA’s attention and prepare accordingly. See our crypto compliance overview for the practical implications.

What AMLA means for customer due diligence and identity verification

This is where AMLA stops being an institutional story and becomes an operational one.

Until now, customer due diligence has been governed by nationally transposed rules, which is why a firm operating in five Member States often runs five subtly different onboarding flows. From 10 July 2027 the AMLR replaces that with one directly applicable standard and AMLA writes the technical detail underneath it.

Three practical consequences follow:

  • Harmonisation cuts both ways. A single standard removes the need for country-by-country variants, but it also removes the option of applying the most permissive interpretation available. Firms report divergent national interpretations as their single biggest CDD-harmonisation challenge, and the levelling will not always be downwards.
  • Existing customers are in scope, eventually. New customers are covered as soon as the rulebook applies. For customers already on the books, a transitional period has been proposed to allow remediation over several years rather than immediately, but the direction is clear: legacy files verified to an older standard will need to be brought up to the new one.
  • Your automation must be auditable. AMLA’s power to inspect records of algorithmic decision-making means the audit trail matters as much as the outcome. If identity verification decisions, risk scores or screening matches are produced by models or rules engines, you need to be able to show what the system decided, on what evidence, and why, years after the fact. Verification evidence, decision logs and model documentation should be treated as regulatory records from now on. Our AML screening solution is built around exactly that requirement.

How should companies prepare for AMLA?

  1. Establish whether you are a candidate for direct supervision. Count the Member States you operate in and assess your ML/TF risk profile in each. If you are close to the six-Member-State threshold, plan for the 2027 selection.
  2. Gap-analyse your CDD against the AMLR, not against your national rules. Read the regulation itself and track AMLA’s technical standards as they are published. Detail you are waiting on will arrive between now and 2027.
  3. Audit your verification and screening evidence trail. Can you reconstruct any individual onboarding decision, including automated ones? Are retention periods aligned to the new rules? See our guide to identification requirements under the AMLR from 2027.
  4. Plan remediation of legacy customer files. Segment your existing base by verification standard and vintage, and build a phased plan rather than a cliff-edge project.
  5. Assign ownership now. Firms that treat July 2027 as a 2027 problem will be competing for the same scarce AML expertise as everyone else — and Frankfurt’s talent market is already tightening as AMLA staffs up.

Further reading: EU AMLR 2027: The Compliance Clock Is Ticking. Here’s What the Next 18 Months Mean for Your Identity Stack


Frequently asked questions about AMLA EU

What does AMLA stand for?

AMLA stands for Authority for Anti-Money Laundering and Countering the Financing of Terrorism.

Is AMLA the same as the AMLR?

No. AMLA is the supervisory authority created by Regulation (EU) 2024/1620. The AMLR, Regulation (EU) 2024/1624, is the rulebook of obligations that applies to firms from 10 July 2027.

Where is AMLA located?

In the MesseTurm in Frankfurt am Main, Germany. The seat was decided in February 2024 and staff moved in in February 2025.

When does AMLA start supervising firms directly?

In 2028. The first list of selected obliged entities is drawn up in 2027.

How many firms will AMLA supervise directly?

Up to 40 at any one time, reviewed every three years.

Can AMLA fine my company?

It can fine entities under its direct supervision, up to €2 million or 1% of annual turnover, whichever is higher, plus periodic penalty payments. Firms under national supervision are fined by their national authority.

Does AMLA replace BaFin or other national regulators?

No. National supervisors keep responsibility for all firms outside the selected list. AMLA oversees and coordinates them, and can intervene where it identifies systematic failures.

What should companies do before July 2027?

Gap-analyse customer due diligence against the AMLR rather than national rules, make automated verification decisions auditable, and plan remediation of existing customer files.

Prepare for AMLR with IDnow

The rules AMLA enforces with the Anti-Money Laundering Regulation (AMLR) apply from July 2027, and the evidence trail they demand has to be built before then, not after. IDnow Trust Platform provides identity verification and AML screening designed for audit with documented decisions and coverage across EU markets.

Get ready for the 2027 AML rulebook.

Talk to our compliance experts about audit-ready identity verification and AML screening.