Only one year left before new AML regime starts
Obliged entities have only one year left to adjust their AML framework to the new rules. This is not only about the regulation itself but also about the technical standards and guidelines that are gradually being prepared by the new European Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA).
We introduced the regulation, directly applicable from 10 July 2027, in our article AML Regulation: uniform rules and stricter supervision in the EU. We covered AMLA, the key European supervisory authority in the AML area, here.
The next step is now the preparation of detailed technical rules, in particular regulatory technical standards (RTS), through which AMLA is tasked with ensuring a uniform interpretation and application of the new AML framework.
AMLA has already published and is preparing final drafts of several key regulations that will have a direct impact on the day-to-day operations of obliged entities. These include in particular:
- RTS on group-wide minimum requirements and additional measures for subsidiaries and branches in third countries (Article 16(4) and Article 17(3) AMLR), which define the shape of the group AML framework in multinational groups,
- RTS on customer identification and customer due diligence (CDD), which specify in more detail what information will be collected from customers as part of standard, simplified and enhanced due diligence,
- RTS on criteria for identifying business relationships, occasional and linked transactions, and lower thresholds, which are intended, among other things, to prevent circumvention of the rules through artificial splitting of transactions.
Consultations are also currently under way on guidelines for the ongoing monitoring of business relationships, i.e. on the setup of transaction monitoring, work with warning signs and documentation depending on the customer’s risk profile, and on guidelines for business-wide risk assessment, which will be one of the cornerstones of the internal AML system.
Obliged entities should therefore not wait until 2027. It already makes sense to carry out a gap analysis and review internal AML policies, risk assessments, KYC/CDD processes, transaction monitoring and related documentation.
The new regime for holding companies deserves separate attention. The AML Regulation expressly provides that a financial or non-financial holding company may also be an obliged entity if one of its subsidiaries is an obliged entity. This may have a significant impact on some corporate groups, as AML obligations will no longer apply only to the specific regulated subsidiary but may also extend to the level of the holding company and the entire group.
In practice, this may mean the need for a group-wide AML risk assessment, uniform group policies, rules for sharing information within the group and a clear determination of who is responsible for AML management at group level.
Technology support may also play an important role in practice. Many companies today use specialised platforms that help manage the KYC lifecycle from end to end by:
- accelerating onboarding,
- allowing automated periodic reviews and event-driven triggers to be set up,
- automating communication with customers and the collection and processing of data, and
- being able to reduce the operating expenses for KYC/CDD.
One example of such a solution is Sapphirus, a platform developed by KPMG that offers end-to-end management of KYC processes, support for various types of obliged entities and scalability for the period when AMLA’s new technical rules begin to apply in full.
If you are considering adjusting your existing AML framework or introducing a new structure of processes and tools before the new regime takes effect in 2027, we can help you set up the processes, documentation and technology solution.