The European Union’s anti-money laundering framework is undergoing its biggest structural change in decades. At the center of that change sits the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), a Frankfurt-based agency built to close gaps. AMLA became operational on July 1st, 2025, and its mandate will expand through 2028, when it begins direct supervision of the EU’s highest-risk financial institutions.
For compliance officers, BSA officers, and risk managers with EU exposure, AMLA is not a distant policy development. It will set binding technical standards, absorb anti-money laundering (AML) mandates previously held by national regulators, and directly examine a select group of cross-border entities. Here is what AMLA is, how its authority is structured, and what institutions should do now to prepare.
Key Highlights
- AMLA, based in Frankfurt, Germany, became operational on July 1, 2025, and assumed all AML and counter-terrorist financing (CFT) mandates from the European Banking Authority (EBA) on January 1st, 2026.
- Starting in 2028, AMLA will directly supervise up to 40 high-risk financial institutions operating in at least six EU member states, selected through a common risk methodology finalized in 2026.
- The Anti-Money Laundering Regulation (AMLR) applies directly across all 27 member states beginning July 10th, 2027, replacing fragmented national rules with a single rulebook.
- Most obliged entities will fall outside direct supervision, but AMLA still shapes their requirements by setting binding technical standards and coordinating national supervisors.
- AMLA also coordinates the EU’s network of Financial Intelligence Units (FIUs), including managing the FIU.net information-sharing system.
- Institutions should treat 2026 as the year to close compliance gaps, since most of AMLA’s technical standards are due by July 2026, well ahead of the 2027 enforcement deadline.
What Is AMLA and Why Was It Created?
AMLA was established under EU Regulation 2024/1620, part of a 2024 legislative package addressing gaps in Europe’s AML supervisory model. Before AMLA, enforcement depended on 27 separate national systems, each interpreting the same EU directives differently.
Germany secured AMLA’s headquarters in February 2024, and the agency took up operations on July 1st, 2025. On January 1st, 2026, the European Banking Authority completed the transfer of all its AML and CFT mandates to AMLA, consolidating authority that had previously been split across multiple bodies.
How AMLA’s Supervisory Structure Works
AMLA’s authority operates on two tracks: direct supervision of a small number of high-risk institutions, and indirect coordination of everyone else.
Financial sector entities active in at least six member states with a high residual risk profile will be selected for direct supervision based on objective cross-border and risk criteria. AMLA must begin the selection process by July 1st, 2027, and finalize the list within six months, with direct supervision launching in January 2028. The initial group is expected to include around 40 institutions, primarily large banking groups, alongside a smaller number of payment institutions, e-money institutions, and crypto-asset service providers.
For everyone else, AMLA’s influence still matters. It will develop a common supervisory methodology, conduct peer reviews of national supervisors, and in defined circumstances take over supervisory action where a national authority fails to act. Regulators such as Germany’s BaFin and Luxembourg’s CSSF remain front-line supervisors for most institutions, but they will increasingly apply AMLA’s standards rather than their own.
AMLA also supports national FIUs in joint cross-border analyses, though it will not replace them; FIUs remain the sole recipients of suspicious transaction reports. This includes managing FIU.net, the information exchange platform connecting financial intelligence units across the bloc.
The AMLR: A Single Rulebook for 27 Member States
AMLA does not operate alone. It sits alongside the Anti-Money Laundering Regulation (AMLR) and the Sixth Anti-Money Laundering Directive (AMLD6), together forming the EU AML Package. The AMLR’s directly applicable status is its most consequential feature. Unlike a directive, which member states transpose with local variation, a regulation applies identically across the EU. The AMLR and AMLD6 fully apply from July 10th, 2027, after which institutions can no longer rely on more permissive national interpretations of customer due diligence (CDD) or Know Your Customer (KYC) requirements.
The AMLR also widens who must comply. All crypto-asset service providers authorized under MiCAR now fall fully within AML scope, closing a gap where some crypto businesses previously operated under national exemptions, and crowdfunding platforms and non-bank consumer credit providers are newly in scope as well.
What Financial Institutions Should Do Before 2027
Compliance teams do not need to wait for direct supervision to start acting:
- Run a gap analysis against the AMLR text, particularly around enhanced due diligence for politically exposed persons (PEP) and other high-risk customers.
- Revisit the business-wide risk assessment. AMLR documentation and sign-off requirements are more prescriptive than most current national standards.
- Integrate sanctions and PEP screening into onboarding rather than treating it as a separate periodic check performed afterward.
- Track AMLA’s technical standards. AMLA must publish 23 Level 2 and Level 3 measures before 2027, most due by July 10th, 2026.
Institutions with cross-border exposure should also strengthen the fundamentals AMLA’s risk-based methodology will scrutinize most closely. Reliable transaction monitoring and identity verification and KYC processes give compliance teams the documentation trail that a unified EU standard, and the AML compliance officers who oversee it, will increasingly need to defend.
Building a Compliance Program Ready for AMLA
AMLA marks a genuine shift in EU AML supervision, moving from 27 fragmented national approaches toward one harmonized framework. Even institutions that never fall under AMLA’s direct supervision will feel its influence through binding technical standards and national supervisors applying AMLA’s methodology rather than their own.
The institutions best positioned for this transition are treating 2026 as a preparation year, not waiting for the AMLR’s 2027 application date or AMLA’s 2028 supervisory launch. Closing documentation gaps now will matter far more than scrambling once direct supervision begins.