No results found
In 2021, the European Commission set out to bolster the EU’s defences against financial crime with an ambitious package of legislative proposals. This package aimed at strengthening the EU's anti-money laundering and countering terrorism financing (AML/CFT) rules and bridge legislative gaps across Member States. A key element of this package was the proposal for a new EU authority - the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) - a central authority coordinating national competent authorities acting in the AML/CFT ecosystem, such as supervisors and Financial Intelligence Units (FIUs).
The EU Council’s adoption of the AML/CFT Package in May and June 2024, and its subsequent publication in the Official EU journal, mark a turning point for both public and private entities across the EU. This package introduces a wave of upcoming milestones, with nearly 100 due dates over the next 8 years, concentrated particularly in July 2026, 2027, and 2029. These deadlines encompass a range of requirements, including AMLA guidelines, regulatory and implementing technical standards, member state notification, and reports, introducing additional obligations and interpretations for obliged entities and other stakeholders.
What’s in the AML Package?
The AML Package comprises four key legal acts:
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) stands as a pivotal institution in the EU’s reformed AML/CTF framework.
⚙️ Operational since July 2025
📍 Based in Frankfurt, Germany
👤 Chaired by Bruna Szego
📈 Expected to grow to 400+ staff by 2027
Its core responsibilities include:
· A more data-driven, comparable, and consistent supervisory model.
Importantly, AMLA will not replace national supervisors or FIUs. Instead, it will act as a central coordinating body to ensure the effective and consistent application of AML/CFT rules throughout the EU.
Effective from July 2024, the Anti-Money Laundering Regulation (AMLR) marks a significant evolution in the EU's fight against financial crime. Replacing the previous directive-led approach, the AMLR is a directly applicable regulation, ensuring consistency across all EU member states.
Key impacts of the AMLR include:
By harmonizing rules on beneficial ownership and enhancing scrutiny of high-risk third countries, the AMLR, along with AMLA’s supervisory role, underscores the EU’s commitment to a robust and unified AML/CTF regime and emphasizes the importance of transparency and compliance in safeguarding the EU’s financial system.
While the AMLR introduces directly applicable rules, AMLD6 focuses on the institutional AML/CFT framework, requiring transposition into national law. by 10 July 2027. Whilst the Directive's provisions have varying transposition deadlines depending on the specific issue, generally Member States must implement the Directive by 10 July 2027, at which point AMLD 4, as amended by AMLD 5, will be repealed.
Key aspects of AMLD6 include:
Overall, AMLD6 aims to reinforce the EU's AML/CFT infrastructure by implementing harmonized mechanisms and enhancing cooperation among member states.
On 9 June 2023, the EU published the recast Wire Transfer Regulation II (WTR II), which came into effect on 30 December 2024. This regulation repeals the existing revised Wire Transfer Regulation and extends the travel rule to include transfers of crypto assets alongside traditional funds, ensuring comprehensive regulatory alignment across the EU.
In essence, WTR II mandates that information about the sender and receiver must accompany all transfers, whether they involve traditional funds or crypto assets. Crypto-Asset Service Providers (CASPs) must provide this information to national authorities to support Anti-Money Laundering (AML) and Counter the Financing of Terrorism (CFT) investigations. Exclusions apply for person-to-person transfers that don't involve a CASP and transfers between CASPs acting on their own behalf.
The regulation also imposes obligations on CASPs regarding self-hosted wallets and mandates compliance with Know Your Customer (KYC) processes, particularly for transactions exceeding EUR 1,000. The European Banking Authority (EBA) will provide guidance on implementation, including data retention requirements.
While WTR II enhances oversight of financial transactions, challenges may arise in cross-border transactions when EU CASPs engage with non-EU entities lacking comparable AML/CFT measures.
What does this mean for your organization?
What exactly does this mean?
A fundamental shift of the AML-Framework: EU-wide, uniform AML rules as of 10 July 2027.
Until now: Directives, national laws, and significant room for national interpretation.
Going forward: One AML Regulation with direct applicability – a true EU Single Rulebook.
How the new framework works:
The objective is clear: More consistency. More comparability. More harmonized requirements.
🚨 From banks to businesses: AML expands itsreach.
With the new EU AML Regulation, the regulatory spotlight is clearly widening. More and more sectors are moving onto the AML radar, and many are underestimating what this really means in practice.
💡 What does this mean for affected sectors?
🔔 Why this matters:
For many non-financial sectors, this is not just a compliance update - it is a fundamental operational transformation challenge.
🚀 Now is the time to act.
🚨 AMLA is moving from concept to execution.
In March 2026, the new Anti-Money Laundering Authority (AMLA) launched a data collection exercise to determine which institutions may fall under direct AMLA supervision.
➡️ This is far more than a regulatory survey. It marks the beginning of a data-driven supervisory model that will shape how AML risks are assessed and supervised across the EU.
➡️ For financial institutions, the message is clear: AML supervision in Europe is becoming analytical, model-based and data-driven.
🚨 The biggest reform of Europe’s anti-money laundering framework in decades?
With the new EU AML package, the European Union is fundamentally reshaping the fight against money laundering and terrorist financing.
➡️ These changes go far beyond mere adjustments to existing anti-money laundering rules.
New institutions, more harmonized rules and expanded obligations for obliged entities aim to create a far more integrated European AML framework.
➡️ For financial institutions, the message is clear:
For financial institutions, companies and supervisors alike, this will bring significant changes in governance, compliance and cooperation. They must completely overhaul their anti-money laundering measures – as soon as possible!
The most significant changes are listed below:
Change #1 – Unified updating intervals with applicability from 10 July 2027
Medium/Low risk: every 5 years
High risk: annually (to be completed by 10 July 2028)
Change #2 – Harmonization of Beneficial Ownership (BO)
Threshold of 25% (max 15%) including new look-through-methodology
Expansion of Central BO-registers with 14 days reporting deadline of incorrect entries
Change #3 – Redefinition of Politically Exposed Persons (PEPs)
Future PEP-definition to include local public officials (50000+ inhabitants) and siblings (family members)
Enhanced due diligence on occasional transaction with PEPs
Harmonization of PEP classification permitting national extensions
Change #4 – Integration of targeted financial sanctions into the EU-AML-Framework
Mandatory sanction risks in risk assessments and their end-to-end consideration across AML processes
Internal governance strengthened through clearer responsibilities and reporting lines
Change #5 – New Governance Requirements
Clear accountability of the “Compliance Manager” (= designated board member)
Fit & proper assessments for AML-relevant staff
Robust processes to prevent, identify and manage conflicts of interest
Change #6 – Cross-border cooperation of FIUs
AMLA support in joint analyses of cross-border suspicious activity reports (SARs)
Mandatory FIU response in 3 working days n reported transactions
FIU.net (central EU system for operational data exchange) managed by AMLA
Change #7 – New thresholds
Identification requirement on occasional ≥ EUR 3 000 cash transactions
Ban on commercial > EUR 10 000 cash payments
Mandatory transaction reporting to FIU on
Luxury vehicles ≥ EUR 250 000
Watercraft or aircraft ≥ EUR 7.5 million
Change #8 – AMLAs data collection exercise
AMLA calibration exercises (March-April 2026) across ~5000 institutions
250+ quantitative data points for risk assessments
Comparable EU-wide AML/CFT risk assessment framework
Change #9 – EU Single Rulebook = EU AML Regulation and increased focus on data
Less fragmentation, clearer requirements, strong harmonization of due diligence obligations, narrower national options
Increase focus on data availability and analysis to manage AML risks
Change #10 – Direct AMLA supervision of high-risk entities
AMLA to directly supervise 40 high-risk cross-border entities, local authorities to oversight all other entities
Publications of uniform inspection, sanction and oversight standards
🚨 Risk-based supervision is becoming reality.
A core element of the new EU AML framework is the consistent expansion of the risk-based approach and with it a fundamental evolution of the supervisory oversight of obliged entities.
➡️ The basis of supervision?
The risk assessment of institutions pursuant to Article 40 AMLD, further defined by harmonized Regulatory Technical Standards (RTS).
➡️ The objective?
An EU-wide consistent methodology for assessing inherent and residual ML/TF risks.
➡️ The main changes?
➡️ What this means for obliged entities:
Risk models, data quality, and governance will become decisive factors in supervisory classification.
🚨 Lower reporting thresholds. Higher expectations.
With the EU AML Package, the framework for suspicious activity reporting is fundamentally reshaped across Europe. The objective is greater harmonization and earlier identification of risks.
➡️ What are the key changes?
➡️ What does this mean for obliged entities?
Suspicious activity reports are becoming an even more central risk and supervisory management instrument. Processes, data quality, decision logic, and training move further into focus, while reporting thresholds are lowered at the same time.
🚨 You wonder what ‘s at stake and why preparation matters?
From MiCAR, the Transfer of Funds Regulation, and AMLR, the following should be on your dashboard:
👉 Crypto-asset service providers are being regulated like banks.
➡️ Why is crypto moving into the spotlight?
➡️ What is really new under the EU AML framework?
➡️ What does this mean for crypto-asset service providers?
Every CASP will see increasing AML expectations under the EU AML Regulation, driven by AMLA and national supervisors.
👉 Compliance = long-term market viability.
Deloitte is here to guide your organization through this complex regulatory landscape. Our team of experienced professionals offers deep market knowledge and extensive operational transformation expertise to guide your organization through a seamless transition to the new AML/CFT requirements.
Ready to embark on your compliance journey with confidence? Contact us for tailored assistance and guidance.
Did you find this useful?
To tell us what you think, please update your settings to accept analytics and performance cookies.