The European Union’s anti-money laundering regime is undergoing its most significant structural overhaul in decades, and at the heart of it sits the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), the Frankfurt-based agency created to close long-standing supervisory gaps.
According to Alessa, AMLA became operational on 1 July 2025, with its mandate set to expand through to 2028, when it begins directly supervising the EU’s highest-risk financial institutions. For compliance officers, BSA officers and risk managers with EU exposure, the agency is far from a distant policy development.
Alessa, a Canadian RegTech firm, recently discussed AMLA, and what the EU’s AML authority means for FIs.
It will set binding technical standards, absorb AML mandates previously held by national regulators and directly examine a select group of cross-border entities.
The authority was established under EU Regulation 2024/1620, part of a 2024 legislative package designed to fix a supervisory model in which enforcement depended on 27 separate national systems, each interpreting the same EU directives differently. Germany won the race to host the agency in February 2024, and on 1 January 2026 the European Banking Authority completed the transfer of all its AML and CFT mandates to AMLA, consolidating powers previously split across multiple bodies.
AMLA’s authority runs on two tracks. Financial sector entities active in at least six member states with a high residual risk profile will face direct supervision, with the selection process beginning by 1 July 2027 and supervision launching in January 2028. The initial cohort is expected to number around 40 institutions, mostly large banking groups alongside payment institutions, e-money firms and crypto-asset service providers.
For everyone else, AMLA will develop a common supervisory methodology, run peer reviews of national supervisors and, in defined circumstances, step in where a national authority fails to act.
Regulators such as Germany’s BaFin and Luxembourg’s CSSF remain front-line supervisors, but they will increasingly apply AMLA’s standards rather than their own. The agency will also manage FIU.net, the information exchange platform connecting financial intelligence units across the bloc, though national FIUs remain the sole recipients of suspicious transaction reports.
AMLA sits alongside the Anti-Money Laundering Regulation (AMLR) and the Sixth Anti-Money Laundering Directive (AMLD6), which together form the EU AML Package. The AMLR applies identically across all member states from 10 July 2027, ending reliance on more permissive national readings of customer due diligence and KYC obligations.
It also pulls all MiCAR-authorised crypto-asset service providers, crowdfunding platforms and non-bank consumer credit providers fully into AML scope.
Compliance teams are being urged to act before 2027 by running gap analyses against the AMLR text, revisiting business-wide risk assessments, embedding sanctions and PEP screening into onboarding, and tracking AMLA’s 23 Level 2 and Level 3 measures, most of which are due by 10 July 2026.
Institutions best positioned for the shift are treating 2026 as a preparation year rather than waiting for direct supervision to begin.
Read the full Alessa post here.
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





