The EU’s Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) said on October 1, 2026, that it had finalized three sets of regulatory technical standards (RTS) and submitted them to the European Commission. They apply to obliged entities under the Anti-Money Laundering Regulation, Regulation (EU) 2024/1624 (AMLR), payment and e-money institutions included. The first, under Article 28(1), spells out customer due diligence: the data to collect and verify, lighter checks for low-risk customers, remote verification, electronic identification, and the screening of politically exposed persons (PEPs).
The second, under Article 19(9), separates business relationships from occasional transactions and defines linked transactions, “so that customer due diligence thresholds are applied consistently,” AMLA said. The third, under Articles 16(4) and 17(3), sets minimum requirements for group-wide arrangements. Once adopted and published in the Official Journal, the texts “are proposed to apply six months after their entry into force,” and from July 10, 2029, for football agents and professional football clubs. Under the due diligence standard, existing customer files must be brought into line on a risk-sensitive basis within one year for higher-risk customers and five years for others, counted from entry into force. AMLA refused to extend those periods, which the AMLR sets.
Firms must record every name shown on the identity document or supplied through electronic identification, and the place of birth as the document gives it, whether a country, a state, a city or a village. Verifying one nationality is enough when a customer declares several. A document counts as equivalent to a passport if a designated authority issued it and it shows the holder’s names, place and date of birth, a number and expiry date, a facial image, a signature, and security features. For virtual IBANs, credit and financial institutions must identify and verify whoever uses one, and obtain the number of the underlying account with its opening and, where applicable, closing dates.
Remote onboarding stays open, with five safeguards
The AMLR’s default routes are an identity document or electronic identification under the EU’s eIDAS regulation, European Digital Identity Wallets included. When a customer cannot reasonably present a document in person and has no access to such eID, firms may use alternative solutions. These must check that the person presenting the document is its holder, secure the session, capture images, video and sound clear enough to identify the person unambiguously, stop on technical failures or doubts, and keep time-stamped copies. Firms must be able to justify each use, and they “may continue using existing remote onboarding tools that meet those requirements,” the standard says. An annex lists the attributes an eID must be able to supply, from family_name to nationality.
PEP checks follow risk, sanctions screening does not
Before opening a relationship or carrying out an occasional transaction, firms determine whether the customer or its beneficial owner is a PEP, a family member or a known close associate. They recheck existing customers at a risk-based frequency, and without delay when new information arrives or the list of prominent public functions changes. Sanctions screening covers names in the original alphabet or in Latin script, plus aliases and digital wallet addresses where available, at onboarding, whenever lists or customer data change, and at regular intervals matched to the firm’s exposure to sanctions evasion. AMLA rejected a general risk-based approach to it, saying compliance with targeted financial sanctions “cannot be made dependent on the level of ML/TF risk associated with a customer.”
Nine risk factors frame e-money exemptions
Article 19(7) of the AMLR lets supervisors exempt certain e-money instruments, in full or in part, from some due diligence measures when four conditions are met. The standard gives them a non-exhaustive list of risk factors to set the extent of that exemption. E-money issuers and payment institutions argued that some factors duplicated those conditions. AMLA dropped a criterion on issuance charges and another requiring funding from accounts at EEA-regulated institutions.
| Factor | What supervisors look at |
|---|---|
| Transaction limits | Low limits or thresholds on transaction values |
| Goods and services | What the instrument can buy, and how risky that is |
| Checks downstream | Transactions run through an obliged entity that applies due diligence |
| Duration | Use limited to a specific period |
| Distribution channels | Sale through direct channels, such as the issuer or a network of service providers |
| Geography | Limited geographical distribution |
| Technical safeguards | Geofencing, monitoring, IP tracking and other tools against unauthorized use and access from third countries |
| Merchant monitoring | The issuer’s monitoring of merchants that accept the instrument |
| Bulk purchases | The issuer’s detection of suspicious bulk buying by or for the same person |
Three transactions in 12 months can signal a relationship
The second standard defines an occasional transaction as one carried out outside a business relationship. To judge duration, every firm must at least consider whether the customer has ongoing access to services within the AML/CFT scope, such as an account. A newsletter subscription does not count. AMLA reworded that test after more than 60 respondents, including payment, fintech and crypto firms, objected to treating an online registration as a sign of duration. Money remitters, bureaux de change and certain crypto-asset service providers must at least consider three or more transactions within the last 12 months as a sign of repetition, and at least consider a one-month period when identifying linked transactions. AMLA kept that count over objections from payment institutions and remitters, citing “significant divergence across Member States.”
Linked transactions are identified through an overall assessment. Criteria include the same customer or customers acting in concert, the same IP address or device identifier, a common invoice or booking number, and the same origin and destination spread across agents or distributors. Linked occasional transactions count toward the threshold on their combined value. AMLA added no lower thresholds, a choice about 120 respondents backed. The AMLR’s own thresholds stand, including €10,000 for occasional transactions in general and €3,000 for cash transactions. For transfers of funds, the threshold is €1,000 at credit and financial institutions other than crypto-asset service providers.
Group rules and cooperation between supervisors
The group standard requires the EU parent undertaking to run a framework proportionate to the group’s size, complexity and risk profile, and lets group entities share customer, due diligence and transaction data on a need-to-know basis through secure channels. It also covers networks and franchises under common ownership, management or compliance control. Where a third country’s law blocks group policies, supervisors can go as far as requiring the closure of some or all operations there. The text repeals Delegated Regulation (EU) 2019/758 with effect from July 10, 2027.
AMLA also published on October 1 its final draft standards on cooperation between home and host supervisors of cross-border groups, under Article 46(4) of Directive (EU) 2024/1640. Supervisors may pass information on within the EU supervisory system without the originating supervisor’s prior consent, subject to notification, unless it came from a third-country authority. That text would apply from July 10, 2027.