AMLR 2027: 8 big changes, and where to start.

Download the Executive Summary slides (PDF)
This article is part of our AMLR 2027 series.

-

AMLR, the EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), is coming into force on 10 July 2027. It replaces national AML laws with a single set of rules that will apply directly in every EU member state.

This article offers a plain-language overview of what changes under AMLR 2027, and where to start.

If you're working within AML and compliance in the financial industry, trying to get an understanding of the new legislation and how it'll impact your work, this article is a great first read.

Summary: The 8 big changes that AMLR introduces.

  1. One set of rules will apply across the EU. Instead of national AML laws and regulations, the same AML rules will apply directly in all EU countries from July 2027 onwards.

  2. A new EU supervisor, AMLA, is established in Frankfurt. AMLA will directly supervise around 40 of the largest financial institutions and coordinate national regulators.

  3. More companies included. With AMLR, new sectors come into the scope of "obliged entities", needing to comply with the new regulation.

  4. Accountability moves up and roles become more structured. The management body becomes accountable for compliance. Companies will also need named compliance roles (compliance officer and manager).

  5. Beneficial ownership mapping gets more layers, requiring companies to restructure their current processes for UBO mapping.

  6. Due diligence widens and tightens. Source and destination of funds become standard for every customer, not just high-risk ones. Lighter due diligence checks can no longer be applied by default.

  7. Monitoring becomes prescriptive. Transaction monitoring becomes a legal obligation. ODD gets new hard deadlines, and event-based review requirements are introduced.

  8. Identity verification moves to electronic ID. eIDAS-based verification becomes one of the explicitly permitted verification methods.

While this list isn't exhaustive, it includes the core changes that AMLR introduces. The next section will cover each of these new requirements in a bit more depth.

If you'd like to dive deeper into any of these topics, you can explore our AMLR 2027 info series.

Note: This article reflects AMLR as enacted in Regulation EU 2024/1624. Some operational details sit in AMLA's technical standards that aren't yet fully finalised.

Fundamentals of AMLR: What changes.

AMLR introduces both broad structural changes and highly operational ones. In everyday work, it touches your core workflows: onboarding, UBO mapping, monitoring, and identity checks. These are also the areas requiring the heaviest lift to ensure AMLR compliance.

Our overview starts with the big picture (sections 1-3), then expands to the operational impacts on compliance workflows (sections 4-8), focusing on what they mean for compliance professionals in practice.

1. One rulebook across the EU.

AML and compliance in Europe has historically run on directives, and each country has written them into its own law. Over the years, this has produced 27 versions of roughly the same idea for compliance teams to navigate.

Since the new Anti-Money Laundering Regulation is an EU-wide regulation, not a directive, the same rules will apply everywhere from 10 July 2027.

Why it matters to you:

While the initial lift to comply with AMLR can be tedious, in the long run, the new regulation should simplify compliance work by providing a single rulebook to follow across the EU.

It removes growth and scale hurdles that many companies have historically had to overcome when expanding to new European markets with varying regulations.

2. A new EU-wide supervisor: AMLA.

AMLA, the EU's anti-money-laundering authority, has been established in Frankfurt. AMLA will directly supervise around 40 large financial institutions from 2028 onwards and coordinate national regulators for everyone else.

AMLA is also responsible for the technical standards of AMLR, which include the operational details of the new regulation. AMLA is currently finalising these standards and publishing them throughout the year leading to July 2027.

Why it matters to you:

Since some of AMLA's technical standards are yet to be finalised, preparing for AMLR means preparing against a somewhat moving target.

However, since the big picture is already set, and the workload required to comply will be significant, the best positioned companies are the ones starting the preparation now.

3. A wider scope of companies.

AMLR widens the scope of obliged entities, the companies that must follow AML rules, to include e.g. crypto-asset service providers, crowdfunding platforms, dealers in high-value goods, and professional football clubs and agents (Art. 3). Additionally, anonymous accounts will be forbidden, including anonymous crypto accounts (Art. 79), and cash payments will be capped at €10,000 across the EU (Art. 80).

Why it matters to you:

If you work for a licensed financial company, your company has been one of the obliged entities already before AMLR, so operationally this doesn't change anything. New companies in scope need to build a lot of what's needed from scratch.

4. Accountability moves up and new roles are introduced.

Obliged entities need to appoint two roles: A compliance officer and a compliance manager. In smaller companies, one person can hold both roles. Additionally, the management body (your senior management) becomes responsible for compliance.

A compliance officer is responsible for day-to-day AML/CFT compliance and sanctions. They function as the contact point for authorities (Art. 11(2)), own the business-wide risk assessment, getting it signed off by the management body (Art. 9, 10) and file suspicious-transaction reports to the FIU (Art. 69(6)).

A compliance manager is a member of the management body who owns compliance at senior level (Art. 11(1)). The management body itself becomes accountable, approving internal policies and the business-wide risk assessment (Art. 9, 10).

In addition, training and employee-integrity checks become explicit obligations (Art. 12, 13).

Why it matters to you:

With the management body now accountable for compliance, the importance of the work will be elevated. Additionally, if you are the one appointed as a compliance officer, your role will become more defined: you'll receive both protection and a direct line to management.

5. Beneficial ownership mapping gets more layers and requirements.

When it comes to UBO mapping, five key things change:

  1. Ownership will be calculated using the accumulation method instead of direct ownership. (Art. 52)

  2. Ownership threshold changes to 25% or more. (Art. 52)

  3. Beneficial owner registers can no longer be used as a standalone verification source. Ownership needs to be verified through your own means first. (Art. 22(7))

  4. Control needs to be assessed alongside ownership. (Art. 51-54)

  5. If no beneficial owner can be identified, all senior managing officials need to be identified and verified. (Art. 22, 63)

Why it matters to you:

More named individuals per company means more identity verification, screening, and monitoring. In short, the UBO changes require your systems to work off the same customer record: every identified person should flow into screening and ongoing monitoring automatically.

For more specifics, see how beneficial ownership identification changes in 2027.

6. Due diligence widens and tightens.

Source and destination of funds become standard information to be collected for every customer, not only the high-risk cases (Art. 25). Additionally, sanctions screening becomes part of the core process instead of treating it as a separate step.

Enhanced due diligence stays mandatory for higher-risk situations such as politically exposed persons (Art. 42) and customers connected to high-risk third countries (Art. 29, 34).

At the other end of the scale, simplified due diligence is reserved for genuinely low-risk cases. Lighter checks can no longer be applied by default (Art. 33).

Why it matters to you:

Onboarding questionnaires that ask about funds only for high-risk customers need a redesign. The onboarding answers need to feed the rest of your process, rather than sit in a form nothing else can see.

AMLR also puts more weight on your risk classification. It now decides who gets simplified versus enhanced checks, and there is less room to default to the lighter option.

7. Monitoring becomes prescriptive and transaction monitoring a legal obligation.

With AMLR, ongoing due diligence gets hard limits on how long you can go without refreshing customer information: 1 year for higher-risk customers, 5 years for everyone else (Art. 26(2)).

Reviews need to also fire on events, such as a change in circumstances or facts about the customer (Art. 26(3)). This only works if your systems and their data are connected.

Transaction monitoring, on the other hand, becomes a legal obligation (Art. 20(1)(f)).

Additionally, with AMLR, transaction monitoring needs to be context-aware, as in, the workflow needs to weigh each transaction against what you know about the customer instead of scoring it in isolation (Art. 26(1)).

Why it matters to you:

Monitoring and reviewing windows are no longer a free choice. With fixed review windows, an alert or a change in circumstances has to open a review on its own.

Arguably, these changes will introduce a lot of operational headaches, especially around how connected your data is and how your compliance data architecture is set up overall.

Go deeper on this topic: Why AMLR 2027 is a data architecture problem, and what compliance teams need to do about it.

8. Identity verification moves to electronic ID.

Identity verification and electronic ID that meets the eIDAS standard becomes an explicitly permitted method for verifying identity (Art. 22(6)). The supporting technical standards are still being finalised.

Why it matters to you:

For Nordic teams, the change isn't drastic. Swedish and Norwegian BankID, Danish MitID and the Finnish Trust Network (e.g. Mobiilivarmenne) already do most of the work required. The important point to check is cross-border coverage: what method to use in the other markets you serve.

In Germany, for example, the dominant verification method today is Video-Ident. How much weight German supervisors place on eID vs. video-based identification is still taking shape. If you operate there, it's worth checking with your regulator to prepare accordingly.

Where to start?

While AMLR comes with a multitude of requirements, these checks get you started.

  1. Check how you work with beneficial owners. How does your UBO mapping work today? For most compliance teams, restructuring the UBO mapping according to AMLR will require a significant amount of work, so this is a good place to start.

  2. Check that monitoring understands the customer context. Can your monitoring rules read a customer's risk profile and declared activity, or only the transaction? What are your current review intervals?

  3. Check your funds questions. Do you capture the source and destination of funds for every customer, or only high-risk ones?

  4. Check how you verify identity. Is electronic identification your primary route, or does your onboarding use something else? How do you work with identity verification across borders?

  5. Check your data infrastructure. This is a fundamental need relating to all of the points above. Are your compliance workflows run in silos, in separate systems, or do the systems and their data talk to each other?

Preparing for AMLR means building a data infrastructure where onboarding, monitoring, and case management operate on the same customer record. See more on why AMLR 2027 is a data architecture problem.

FAQ

What is AMLR?

AMLR is the EU's Anti-Money Laundering Regulation, Regulation (EU) 2024/1624. It is a single, directly applicable rulebook that replaces the harmonised core of national AML law across all EU member states. It applies from 10 July 2027.

When does AMLR apply?

10 July 2027, in every EU member state. AMLR doesn't have a national transposition period, because it is a regulation rather than a directive.

Who does AMLR apply to?

AMLR applies to obliged entities (Art. 3): licensed credit and financial institutions, and as new categories, crypto-asset service providers, crowdfunding platforms, dealers in high-value goods, and professional football clubs and agents.

What is AMLA?

AMLA is the EU's new Anti-Money Laundering Authority, based in Frankfurt. It's been operational since 2025. It will directly supervise around 40 large institutions (from 2028) and coordinate national supervisors for each country. AMLA is responsible for the detailed technical standards that sit under AMLR, currently being drafted.

I am already an obliged entity. Do I need to do something?

Yes. Being an obliged entity (i.e. licensed credit or financial institution) does not mean your compliance setup is ready for AMLR. The regulation raises the standard in beneficial ownership mapping, monitoring, source and destination of funds and identity verification, to name a few. AMLR also formalises accountability and team structure, with named compliance roles and management body sign-off.

How do I prepare for AMLR 2027?

Start where the heaviest lift is: how you map beneficial owners, whether you monitor transactions and collect source and destination of funds for every customer, whether your monitoring can read customer context, and how you verify identity. Make sure your compliance systems share one customer record rather than having key information in disconnected silos.

Who is responsible for AML compliance under AMLR?

AMLR requires two named roles: a compliance officer for day-to-day AML/CFT compliance and sanctions (Art. 11(2)), and a compliance manager who sits on the management body and owns compliance at senior level (Art. 11(1)). In smaller companies, one person can hold both roles. The senior management body becomes accountable, approving internal policies and the business-wide risk assessment (Art. 9, 10).

What is the AMLR cash limit?

AMLR sets an EU-wide limit of €10,000 on cash payments for goods or services, whether in one payment or several linked ones (Art. 80). Individual member states have the option to set lower limits.

Does AMLR replace national AML law?

AMLR replaces the harmonised core of national AML law with one directly applicable rulebook. Some things stay national: the parallel directive AMLD6 (Directive (EU) 2024/1640) still has to be transposed by each country, covering areas such as supervisory setup, beneficial ownership registers, and financial intelligence units.

What is the difference between AMLR and AMLD6?

AMLR (Regulation 2024/1624) is the directly applicable single rulebook. AMLD6 (Directive 2024/1640) is the accompanying directive, which each country still transposes into national law, covering areas such as supervisory setup, beneficial ownership registers, and financial intelligence units.

If you want to discuss what AMLR means for your own compliance setup, we're happy to help. Reach out to the Bits team.

Published: 13 August, 2026

This article is published by Bits Technology, a compliance infrastructure platform for regulated financial companies in Europe.