Europe’s AMLA Finalises Rules for Direct Supervision of Cross-Border Financial Groups

The European Union’s Anti-Money Laundering Authority has finalised a set of technical standards governing how it will work with national authorities to select and directly supervise major cross-border financial institutions.
The standards establish procedures for:
- Identifying financial institutions and groups eligible for direct supervision;
- Collecting and validating the data used in the selection process;
- Assessing money laundering and terrorist financing risk;
- Transferring supervisory responsibilities from national authorities to AMLA;
- Managing ongoing investigations during the transition; and
- Establishing joint supervisory teams for selected institutions.
Direct supervision is scheduled to begin in 2028, following the first formal selection exercise in 2027.
Importantly, AMLA has finalised its draft Implementing Technical Standards under Article 15(3) of Regulation (EU) 2024/1620. The standards must still be adopted by the European Commission and published in the Official Journal of the European Union before becoming legally binding.
Which Financial Institutions Can Be Considered?
AMLA’s direct supervision mandate applies to the financial sector.
The potential candidate population includes:
- Credit institutions;
- Financial institutions;
- Groups of credit institutions;
- Groups of financial institutions; and
- Groups combining credit and financial institutions.
Non-financial obliged entities, such as lawyers, accountants, real estate agents and trust or company service providers, are not included in AMLA’s initial direct-supervision framework.
To be eligible for consideration, a financial institution or group must operate in at least six EU Member States, including its home Member State.
Cross-border operations may be conducted through:
- Subsidiaries;
- Branches;
- Other establishments recognised under financial regulation; or
- The freedom to provide services without establishing a physical presence.
However, merely holding a regulatory notification or passport to provide services in another Member State is not necessarily sufficient. Where an institution operates under the freedom to provide services, its activity must meet a materiality threshold.
An institution is treated as having material operations in another Member State where either:
- It had more than 20,000 customers resident in that Member State at the end of the previous year; or
- The annual value of incoming and outgoing transactions generated by those customers exceeded EUR 50 million.
These are alternative thresholds. An institution may therefore meet the test through a large customer base or through a smaller number of customers generating significant transaction volumes.
Where several institutions within the same group provide services in the same Member State, their relevant activities are aggregated for the purpose of applying the thresholds.
Eligibility Does Not Automatically Mean Selection
Operating in six or more Member States only places an institution or group within the population that may be assessed.
AMLA will then evaluate the institution’s money laundering and terrorist financing risk profile.
The selection methodology considers:
- The institution’s inherent ML/TF risk;
- The quality of its AML/CFT controls; and
- The residual risk remaining after those controls are taken into account.
Institutions are classified as having low, medium, substantial or high residual risk.
For groups, AMLA will calculate a group-wide residual risk score using the risk profiles of the relevant group entities. The calculation is weighted to reflect the relative importance of each entity, including factors such as:
- Customer numbers;
- Transaction volumes;
- Assets held or managed; and
- The risk level of individual entities within the group.
This is intended to prevent the risk presented by a significant high-risk entity from being diluted by a larger number of lower-risk subsidiaries.
AMLA expects to select up to 40 financial institutions or groups during the first selection round.
How the Selection Process Will Work
The standards establish a sequential process involving both national financial supervisors and AMLA.
1. National Supervisors Identify Potentially Eligible Institutions
The financial supervisor in the institution’s home Member State is responsible for collecting the information needed to determine eligibility.
For a group, information will generally be collected from the relevant parent undertaking or a designated reporting entity.
National supervisors may exempt an institution from submitting eligibility information where they can establish, using objective and verifiable information, that it clearly does not meet the eligibility criteria.
The basis for the exemption must be documented, and AMLA may review that documentation.
2. Home and Host Supervisors Check the Cross-Border Information
AMLA will prepare a preliminary list of institutions that appear to meet the geographic eligibility criteria.
Supervisors in the Member States where those institutions operate will then review the information relevant to their jurisdictions.
Where a host supervisor identifies an error—for example, an incorrectly reported branch, subsidiary or cross-border service arrangement—it will work with the home supervisor to correct the information.
AMLA may assist where national authorities cannot reach a common position.
3. Eligible Institutions Provide Detailed Risk Data
The process is designed to be proportionate.
Institutions should not be required to provide the complete risk-assessment dataset before their eligibility has been established. Detailed risk data is collected only from institutions identified as provisionally eligible.
National supervisors will organise the collection and communicate the practical submission requirements to the institutions under their supervision.
4. AMLA Conducts the Risk Assessment
National supervisors will validate the submitted information before sending it to AMLA.
AMLA will then calculate the institution’s:
- Inherent risk profile;
- Quality-of-controls assessment; and
- Residual risk profile.
National supervisors will receive the assessment results and may propose adjustments to the evaluation of the institution’s AML/CFT controls.
Any proposed adjustment must be supported by relevant evidence, such as findings from supervisory reviews, inspections or external audit assessments.
AMLA will make the final assessment and must explain any decision not to accept a proposed adjustment.
5. AMLA Makes and Publishes the Selection Decision
Selected institutions will be notified in writing before the final list is published.
The notification must explain:
- The outcome of the selection;
- How pending supervisory procedures will be handled;
- The process for requesting corrections;
- The institution’s right to request a substantive review;
- The right to be heard;
- Access to the selection file; and
- The right to seek judicial review.
Following the review period, AMLA will publish the list of selected institutions on its website, together with the date on which direct supervision begins.
What Data May Institutions Need to Submit?
The reporting process is divided into two broad stages: eligibility data and risk-assessment data.
Eligibility Data
Information used to establish whether an institution or group operates in at least six Member States may include:
- The identity of the reporting institution;
- The EU parent undertaking;
- The ultimate parent where it is located outside the EU;
- Group structure;
- Subsidiaries and branches in EU Member States;
- The type of regulated activity carried out by each establishment;
- Operations conducted under the freedom to provide services;
- Customer numbers by Member State;
- Incoming and outgoing transaction values by Member State; and
- Relevant agents, distributors or other cross-border arrangements.
For groups, the reporting entity may need to coordinate information across multiple subsidiaries and business lines.
Risk-Assessment Data
Once an institution is confirmed as eligible, the requested information becomes considerably more detailed.
The inherent-risk dataset may cover:
- Total customer numbers;
- Natural-person and legal-entity customers by country;
- Politically exposed persons;
- Customers with complex corporate structures;
- Customers with beneficial owners outside the European Economic Area;
- Cross-border transactions involving non-EEA countries;
- Products and services offered;
- Payment-account activity;
- Correspondent banking;
- Trade finance;
- Electronic money;
- Crypto-asset services;
- Cash transactions;
- Assets under management;
- Incoming and outgoing transactions by country;
- Remote onboarding;
- Reliance on agents or distributors; and
- Other sector-specific activities.
The controls dataset may cover:
- AML/CFT governance;
- The role of the management body;
- Compliance staffing and resources;
- Staff and board training;
- Internal controls;
- Outsourcing arrangements;
- Internal and external audit;
- Business-wide risk assessments;
- Customer risk classification;
- Beneficial ownership identification;
- Customer due diligence;
- Ongoing monitoring;
- Transaction-monitoring systems;
- Suspicious transaction reporting;
- Sanctions screening; and
- Record keeping.
Institutions will not necessarily complete every data field. The applicable information depends on the institution’s sector, products and activities.
Data Quality Will Be a Supervisory Issue
National supervisors are required to apply validation, data-quality and plausibility checks before transmitting information to AMLA.
Submissions containing unexplained inconsistencies may be rejected.
Where an institution uses:
- Estimates;
- Proxies;
- Alternative calculation methods; or
- Incomplete information,
the limitations and methodology should be clearly explained.
This means that institutions potentially falling within the candidate population will need more than the ability to populate a reporting template. They must also be able to demonstrate where the data came from, how it was calculated and whether it is consistent across entities and Member States.
For large groups, this may require coordination between compliance, finance, operations, legal, data management and local subsidiaries.
How Supervision Will Be Transferred to AMLA
Once the final selection list is published, AMLA and the relevant national supervisors must begin organising the transfer of supervisory responsibilities.
The authority transferring supervision must prepare a comprehensive inventory of relevant information.
As a minimum, the inventory should cover the three years preceding publication of the selection list. A longer period may be required where necessary to understand the institution’s risks or supervisory history.
The transferred material may include:
- Previous risk assessments;
- On-site and off-site inspection findings;
- Supervisory correspondence;
- Remediation plans;
- Enforcement history;
- Supervisory decisions;
- Open issues;
- Information on AML/CFT systems and controls; and
- Pending supervisory procedures or investigations.
Where the institution has been supervised for less than three years, the information should cover its entire supervisory history.
The transfer must take place through secure channels with appropriate controls over confidential, personal and commercially sensitive information.
What Happens to Ongoing Investigations?
The change of supervisor should not interrupt an existing investigation or supervisory procedure.
The national authority transferring supervision must inform AMLA about relevant pending matters.
Where possible, the transferring authority should complete an existing procedure before AMLA assumes responsibility.
Where this is not possible, AMLA and the national supervisor must agree how the matter will continue. Their arrangements may address:
- Which authority completes particular stages;
- Whether AMLA will take over the case;
- How the case file will be transferred;
- How confidentiality will be protected; and
- What information will be provided to the institution and other participants.
This framework is intended to prevent a change in supervisory responsibility from delaying remediation or enforcement action.
Direct Supervision Will Still Involve National Authorities
AMLA’s direct supervision does not remove national supervisors from the process.
A Joint Supervisory Team, or JST, will be established for each selected institution or group.
Each team will include:
- AMLA staff; and
- Staff from the relevant national financial supervisors.
The team will be coordinated by an AMLA staff member.
The standards require timely information sharing and equal access to relevant meetings, discussions and supervisory platforms for JST members. Restrictions on access must be justified and recorded.
The AMLA coordinator will also be subject to a rotation principle, although the appointment may be extended or shortened where necessary to manage conflicts, organisational changes or supervisory continuity.
Where several national authorities supervise different parts of the same group, they must coordinate their participation in the JST.
The resulting model is therefore not a complete replacement of national supervision with centralised EU supervision. It is an integrated structure in which AMLA holds direct supervisory responsibility while continuing to rely on national knowledge, local access and supervisory resources.
The Timeline to Direct Supervision
| Period | Main development |
|---|---|
| 2026 | AMLA and national supervisors identify the provisional population of eligible institutions and test the risk-assessment methodology. |
| 15 August 2026 | Home supervisors submit initial eligibility information to AMLA under the first identification exercise. |
| End of September 2026 | The provisional population expected to enter the detailed 2027 data collection is finalised. |
| January–March 2027 | National supervisors collect final eligibility and risk data from provisionally eligible institutions. |
| 31 May 2027 | National supervisors submit the relevant data to AMLA under the draft ITS timetable. |
| From July 2027 | AMLA conducts the formal assessment and selection exercise. |
| By 31 July 2027 | AMLA communicates initial risk-assessment outcomes to national supervisors. |
| By 30 September 2027 | National supervisors may propose supported adjustments to the assessment of AML/CFT controls. |
| By the end of 2027 | AMLA communicates and publishes the final selection, following the applicable review process. |
| 2028 | AMLA begins directly supervising the selected institutions and groups. |
Individual institutions may face earlier submission deadlines because data will first be collected by their national supervisors before being transmitted to AMLA.
What Potential Candidate Groups Should Do Now
Groups with substantial EU operations should first determine whether they could meet the six-Member-State test.
This assessment should cover both physical establishments and material services provided cross-border without an establishment.
Potential candidates should also review whether they can produce consistent group-wide data on:
- Legal and regulatory structure;
- Customer locations;
- Customer types and risk classifications;
- Transaction values and volumes;
- Product and service exposure;
- Geographic risk;
- AML/CFT controls; and
- Open supervisory findings.
The immediate objective is not to predict whether the group will ultimately be selected. It is to ensure that eligibility and risk data can be produced accurately, reconciled across the group and explained to national supervisors.
Groups should also prepare for the possibility that AML/CFT supervision will be assessed increasingly at EU group level rather than through separate national views of individual subsidiaries.
The Compliance Significance
AMLA’s finalised standards provide the operational link between national supervision and the EU’s new direct-supervision regime.
The framework separates the process into clear stages:
- Identify institutions with a sufficiently significant cross-border presence;
- Collect detailed information only from eligible institutions;
- Assess inherent risk and the quality of AML/CFT controls;
- Select the highest-risk and most significant institutions;
- Transfer supervisory history without interrupting ongoing work; and
- Supervise selected groups through joint teams involving AMLA and national authorities.
For financial groups operating across the EU, the key issue is no longer simply whether each subsidiary complies with its local regulatory requirements.
The new framework requires institutions to demonstrate that their cross-border structure, risk exposure, data and AML/CFT controls can be understood consistently at group level.
Main Sources
AMLA — Finalises Standards for Supervisory Cooperation in Direct Supervision
AMLA — Final Report: Draft Implementing Technical Standards Under Article 15(3) of Regulation (EU) 2024/1620
AMLA — Final Report: Regulatory Technical Standards on Risk Assessment for Direct-Supervision Selection
AMLA — Explainer: Towards AMLA’s Direct Supervision



