top of page

The Teeth Behind the Standard: What AMLA Now Means for Cross-Border Firms

  • Writer: Elizabeth Travis
    Elizabeth Travis
  • 34 minutes ago
  • 7 min read

For two decades, the European Union wrote anti-money laundering rules and then watched twenty-seven member states enforce them twenty-seven different ways. Danske Bank, Wirecard and ABLV were not aberrations. They were the predictable output of a system in which supervision was national, ambition was European, and the gap between the two was where laundered money moved. The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) was built to close that gap. As of this year, it is no longer a proposal or a building in Frankfurt. The teeth are being fitted.


The dates matter, because they mark a shift from architecture to authority. AMLA became operational on 1 July 2025, according to its own record and confirmed by the European Banking Authority (EBA). On 1 January 2026, the EBA and AMLA completed the transfer of all anti-money laundering and counter-terrorist financing (AML/CFT) mandates and functions from the EBA to AMLA, ending the stand-alone mandate the EBA had held since 2020. The EBA's own statement described the handover as a milestone and confirmed that key tools, including the EuReCA database of supervisory deficiencies, moved with it. The scaffolding phase is over. What follows is delivery.


None of this means the teeth are closed. AMLA will not directly supervise a single institution until 2028, the single rulebook does not apply until 2027, and the EBA itself held an AML mandate from 2020 while the worst scandals still unfolded. Centralisation has been promised before. The case for acting now does not rest on AMLA already having bite. It rests on something more useful: the preparation is already binding, and the cost of waiting is asymmetric.


Centralisation is the point, not a side effect


The temptation is to read AMLA as another layer of Brussels machinery. That is the wrong lens. The Anti-Money Laundering Regulation (AMLR), which applies uniformly across all twenty-seven member states from 10 July 2027, replaces the directive-based model that allowed national interpretation. A directive invites transposition, and transposition invites divergence. A regulation applies directly, identically, from Lisbon to Helsinki. AMLA is the institution that makes that single rulebook mean the same thing everywhere it lands.


This is the structural change that firms operating across borders should register first. The old compliance calculus rewarded arbitrage: locate the lightest-touch supervisor, satisfy the local interpretation, and let inconsistency do the rest. AMLA is engineered to remove that option. It will directly supervise forty of the most complex, high-risk credit and financial institutions or groups in the EU from 2028, selected on geographical footprint and risk profile.


But direct supervision is the smaller part of the story. The larger part is indirect supervision: for the first time, supervisors across the bloc will use one common methodology to assess money laundering and terrorist financing risk, reinforced by harmonised standards, supervisory colleges and peer reviews. The list of forty determines who AMLA inspects. The methodology determines what every firm is measured against.


Preparation has already begun, and it is not neutral


Firms that treat 2028 as the deadline have misread the calendar. AMLA's Single Programming Document for 2026 to 2028 commits the authority to five interlinked activities, and several are already live. In its own words the priorities begin with the mandates most critical for industry, notably customer due diligence and the business-wide risk assessment.


AMLA published its final report on the risk-assessment methodology for selecting entities for direct supervision in December 2025 and launched a data-collection exercise in 2026 to calibrate that model. According to AMLA's own reporting package, that exercise closes on 15 August 2026, with a provisional list of candidate entities due by the end of September and the formal selection round following in 2027, ahead of direct supervision beginning in 2028. This is not distant preparation. The data firms submit this month trains the model that will later judge them.


The direction of that early attention is worth reading precisely. AMLA's stated first-order focus is customer due diligence, beneficial ownership capture and enterprise-level risk self-assessment, the data points that feed its supervisory models. Beneficial ownership sits at the centre because inconsistent ownership data is the vulnerability that fragmented supervision never fixed.


The Data for Compliance alliance, which includes Moody's, argued in December 2025 that beneficial ownership information should be structured, machine-readable and consistently formatted across member states, and warned that ownership charts uploaded as images create ambiguity and manual re-keying. AMLA's methodology assumes the opposite: that ownership data can be interrogated at scale. The interconnection of national beneficial ownership registers will also make inconsistencies between jurisdictions far more visible than they have ever been. Firms whose ownership records cannot withstand that assumption are exposed before a single inspector arrives.


The crypto perimeter has closed on schedule


The AMLA story did not sit in isolation. It ran in parallel with a second deadline, and the two together now define the compliance environment of the next eighteen months. On 17 April 2026 the European Securities and Markets Authority (ESMA) confirmed that the transitional window under the Markets in Crypto-Assets Regulation (MiCA) would expire across the EU on 1 July 2026, with no extensions. From that date, any entity providing crypto-asset services to EU clients without a MiCA licence has been, in ESMA's words, in breach of EU law.


The scale of the attrition is now measurable rather than projected. Industry tracker Penning recorded 323 crypto-asset service providers holding full MiCA authorisation across twenty-six EEA states as of 21 July 2026, concentrated in Germany, the Netherlands, France, Malta, Cyprus and Ireland. The composition of that survivor list is more revealing than its size: only twenty-six of the 323 authorised firms can operate a trading platform, and just forty-six hold portfolio management authorisation, meaning most of what remains is built from brokers, custodians and transfer providers rather than exchanges. Binance is the highest-profile casualty, having exited EU operations after failing to secure authorisation before the cutoff, as reported by Finance Magnates. Less predictably, the register's July cohort also welcomed traditional institutions, including Standard Chartered and several German cooperative banks, cutting against the pre-deadline narrative that MiCA would push finance out of Europe rather than draw it in.


The three regimes bite on different clocks, and that is precisely what firms miss. The travel rule traceability obligation under the Transfer of Funds Regulation, requiring originator, beneficiary and amount on every crypto transfer, has applied since 30 December 2024. The MiCA authorisation deadline has now passed. The full anti-money laundering obligations under the AMLR follow from 10 July 2027. A MiCA licence was only ever the entry ticket; travel rule compliance and customer due diligence are the ongoing cost, and neither becomes easier once the licence is granted.


There is no anti-money laundering carve-out for crypto at any stage. ESMA has signalled it will scrutinise client-migration strategies to stop unauthorised providers continuing business as usual through white-label or pass-through arrangements, and has warned investors that MiCA protections apply only to specifically authorised EU entities, not to affiliated non-EU operations trading under the same brand. A sector that grew up outside consolidated supervision has now met the perimeter as an operating reality, and the casualty list confirms it was not a bluff.


Enforcement is the variable that changes behaviour


Rules without consequences produce paper compliance. AMLA is being built with the consequences attached, even if they arrive later than the rules. Under the framework, the authority will directly sanction the institutions it supervises, with pecuniary penalties reaching ten million euros or ten percent of total annual turnover, whichever is higher, and the sixth Anti-Money Laundering Directive doubled the ceiling for serious, repeated or systematic breaches to the same level for national supervisors.


AMLA gave that framework its first concrete shape on 22 July 2026, finalising common standards, originally drafted by the EBA in 2025, for how it and national supervisors impose fines and other enforcement measures, according to AML Intelligence. Tellingly, the authority left the calculation methodology itself open. Harmonised enforcement is being assembled in stages, not delivered whole, and that gap is exactly where the next round of regulatory attention will land.


That doubling is not a technicality. Enforcement is not just being centralised; it is being levelled up. AMLA will also publish its enforcement decisions, naming the entity, the nature of the breach and the amount imposed. Reputational exposure is written into the design.


That is the shift compliance leaders should sit with. For twenty years the operative question was whether a control existed and could be evidenced to a national supervisor whose appetite varied by jurisdiction. The question AMLA is constructing is different: whether a control works, consistently, across every market a firm operates in. Because supervisors will apply one common methodology rather than twenty-seven local interpretations, a control calibrated to satisfy the most lenient reviewer becomes the control most exposed to the harmonised one. Control effectiveness, not control existence. The distinction is no longer academic.


What firms should reassess now


Readiness is a data and governance problem before it is a policy problem. Consolidating fragmented local anti-money laundering policies into a single EU-aligned baseline, with controlled local variation, mirrors the harmonisation AMLA will expect and is cheaper to build now than to retrofit under supervision. Beneficial ownership data should be treated as a structured asset, not a folder of PDFs.

Business-wide risk assessments should move to quantitative scoring against a defined set of risk factors, because that is the language AMLA's models read. Governance matters too: the AMLR requires obliged entities to appoint a dedicated compliance manager, distinct from the money laundering reporting function, with responsibility for aligning policies to the firm's risk exposure.


Firms should also assume the technical standards and guidelines scheduled through 2026 and early 2027, most of them due by 10 July 2026, will keep raising the specificity of what evidence looks like. None of this rewards waiting. Even if AMLA underdelivers on its early ambition, the preparation it demands is the same preparation any serious supervisor will eventually require, which is what makes the cost of waiting asymmetric. The institutions that meet the first supervisory cycle cleanly will be those already treating AMLA as an operational transformation rather than a regulatory update. The rest will discover that a harmonised supervisor removes the places inconsistency used to hide.


Conclusion: Sharpen before, not after


For twenty years the weakness in Europe's defences was never the absence of rules. It was the absence of one standard, enforced the same way everywhere, by an authority with the reach to make it bite. That is what is changing. AMLA does not add another interpretation to the twenty-seven that already exist; it collapses them into one, and it is being built with the power to fine, to publish and to select. The crypto sector has already found that out the hard way. The teeth are not yet fully closed. The only question is whether firms sharpen their controls before they are, or after.


Is your firm's beneficial ownership data ready for a supervisor that reads it by machine, not by eye?


At OpusDatum, we help financial institutions translate supervisory change into operational readiness, from beneficial ownership data quality and business-wide risk assessment to control-effectiveness testing that will withstand harmonised EU scrutiny. We work with compliance teams to build the evidence base a single European supervisor will expect.


To find out how OpusDatum can help you prepare for AMLA, contact us.

bottom of page