AMLA and the European Single Market: From Regulatory Harmonisation to Operational Readiness

Madina Rashid, Senior Advisor
2026-09-14
Abstract
The establishment of the European Anti-Money Laundering Authority (“AMLA”), alongside the new Anti-Money Laundering Regulation (“AMLR”) and Sixth Anti-Money Laundering Directive (“AMLD6”), represents a significant change in the architecture of European financial crime supervision.
Much of the discussion to date has understandably focused on the new regulatory framework itself. For financial institutions, however, the more immediate challenge is practical: what needs to change within existing governance, risk management and operating models?
International banking, asset management and insurance groups rarely operate through a single AML framework in practice. Group policies interact with local requirements, different customer populations, products, distribution models, technology platforms and supervisory expectations. First-line ownership may differ between businesses, while second-line oversight is often distributed across local, regional and group functions.
AMLA therefore raises a broader strategic question. As Europe moves towards greater regulatory and supervisory convergence, are firms themselves sufficiently integrated to respond?
This article considers AMLA from that operational perspective and identifies practical steps firms can take now to prepare for a more harmonised and increasingly group-wide European supervisory environment.
I. What is changing?
The European AML package combines three interconnected reforms: AMLR, AMLD6 and the establishment of AMLA.
One important development is the move of significant AML/CFT requirements into a directly applicable regulation. This should reduce some of the national divergence that has historically characterised areas including customer due diligence. AMLA will meanwhile promote supervisory convergence and directly supervise selected higher-risk financial institutions and groups.
That matters because European financial institutions have historically operated within something of a paradox.
The business may operate regionally or globally. Customers and transactions cross borders. Technology and operational functions may be centralised. Yet AML requirements, regulatory relationships and supervisory expectations have often remained substantially jurisdictional.
AMLA begins to challenge that model.
The practical consequence is that firms should increasingly expect supervisors to look not only at whether an individual legal entity complies, but at whether the wider group can identify, aggregate, govern and respond to financial-crime risk coherently.
For senior management, that changes the question from:
“Are our individual entities compliant?”
to:
“Can we demonstrate that our European AML framework works as an integrated system?”
II. Start with the operating model - not the policy
The instinctive response to significant regulatory change is often to begin with policies.
That is necessary, but it may be the wrong starting point.
For international groups, the first exercise should be an operating-model assessment.
A banking group may have central transaction-monitoring infrastructure but locally owned customer due diligence. An asset manager may have delegated onboarding or transfer-agent arrangements across jurisdictions. Insurance businesses may operate through multiple distribution models, intermediaries and legal entities.
The resulting AML framework can look coherent on paper while responsibilities in practice are distributed across numerous businesses, jurisdictions and functions.
Firms should therefore map:
which AML/CFT responsibilities sit within the first line and which sit within the second;
which controls are group-wide and which remain locally operated;
where material activities are outsourced or delegated;
who owns customer and business-wide risk assessments;
where significant AML decisions are made;
how local issues are escalated to regional or group management; and
what information ultimately reaches senior management and Boards.
This is particularly important because the new framework develops explicit requirements around group-level compliance arrangements and management responsibility.
The outcome should be a clear accountability map — not another policy document.
III. Test whether group-wide risk assessments actually aggregate risk
The business-wide risk assessment should be another immediate priority.
Many international institutions already maintain sophisticated enterprise, business-line and legal-entity financial-crime risk assessments.
The difficulty is often aggregation.
Can management meaningfully compare AML risk between a German banking entity, Luxembourg fund business and French insurance operation?
Are customer, geography, product, distribution and transaction risks assessed using sufficiently consistent methodologies?
And where methodologies differ, is there a documented rationale?
AMLA's group-wide supervisory perspective makes those questions increasingly important.
A practical readiness exercise should therefore identify:
Common methodology → permitted local variation → rationale → escalation threshold → group aggregation.
This is where first- and second-line responsibilities matter.
The first line should be able to articulate the financial-crime risks arising from its customers, products and distribution channels. The second line should be capable of challenging those assessments, identifying inconsistencies and providing senior management with an aggregated view of material exposure.
A risk assessment that produces twenty different jurisdictional documents but no coherent group view may become increasingly difficult to defend.
IV. Revisit first-line and second-line accountability
Greater regulatory harmonisation does not remove the need for clear ownership.
If anything, it increases it.
The AMLR framework places emphasis on management responsibility and defined compliance roles, while the Linklaters analysis identifies requirements for both management-level responsibility and day-to-day AML/CFT compliance functions.
For firms, the practical exercise should be to test where accountability actually sits when something goes wrong.
Consider a high-risk customer operating across several European jurisdictions.
Who owns the relationship?
Who determines the customer-risk rating?
Who approves enhanced due diligence?
Who challenges that decision?
Who identifies cross-jurisdictional exposure?
Who escalates material concerns?
And who can see the complete picture?
If those questions produce five different answers depending upon legal entity, the issue is not necessarily that the model is wrong. The issue is whether the organisation can explain why responsibilities differ and demonstrate that the resulting framework remains effective.
That is a governance question, not simply an AML procedure question.
V. Treat outsourcing and technology as accountability issues
Another practical area requiring attention is the increasing reliance on centralised operations, external providers and technology.
The new framework clarifies the circumstances in which AML/CFT functions may be outsourced while retaining ultimate responsibility with the obliged entity. Importantly, certain core judgements — including approval of the business-wide risk assessment and key customer-risk decisions — cannot simply be transferred externally.
Firms should therefore inventory material AML dependencies across:
KYC utilities;
screening providers;
transaction-monitoring platforms;
shared-servicecentres;
transfer agents;
outsourced onboarding;
data providers; and
AI or automated decision-support tools.
But an inventory is only the beginning.
The more important questions are:
Who owns the control? Who validates its effectiveness? Who understands its limitations? And who makes the ultimate decision?
This becomes particularly important as firms increase their use of automated tools.
The framework's treatment of automated decision-making and AI-generated information reinforces an increasingly important regulatory principle: technology can support financial-crime judgement, but it does not remove human accountability.
VI. Build a supervisory evidence pack before anyone asks for one
Perhaps the most practical preparation firms can undertake is to look at their framework through the eyes of a supervisor.
AMLA's supervisory toolkit includes information requests, investigations, on-site inspections and the ability to assess policies, procedures and controls at both entity and group-wide level.
Firms should therefore ask:
If AMLA requested evidence tomorrow, could we demonstrate how our European framework actually works?
A supervisory readiness pack might bring together:
group governance and committee structures;
AML accountability maps;
business-wide and entity-level risk assessments;
Board and committee reporting;
material risk-acceptance decisions;
policies and documented local deviations;
control-testing and assurance results;
outsourcing arrangements;
remediation programmes;
significant AML incidents and escalation;
technology governance; and
evidence of first-line ownership and second-line challenge.
The distinction is important.
Documentation demonstrates what the framework is supposed to do. Evidence demonstrates whether it actually does it.
That is where mature regulatory programmes distinguish themselves.
VII. Five actions firms can take now
1. Map the operating model
Practical Action: Map AML ownership across business lines, legal entities, jurisdictions and three lines of defence.
Outcome: Clear accountability and identification of gaps or duplication.
2. Harmonise risk methodology
Practical Action: Compare business-wide and entity-level risk assessments and identify unjustified methodological differences.
Outcome: A credible aggregated European risk view.
3. Challenge local deviations
Practical Action: Catalogue material departures from group AML standards and document their regulatory or risk rationale.
Outcome: Greater consistency without inappropriate standardisation.
4. Test data and outsourcing
Practical Action: Identify critical providers, systems, data dependencies and automated decision points and assign accountable owners.
Outcome: Demonstrable control over outsourced and technology-enabled processes.
5. Run an AMLA readiness review
Practical Action: Conduct a mock group-wide supervisory review using governance, risk controls, MI and remediation evidence.
Outcome: Earlier identification of weaknesses before supervisory scrutiny.
VIII. Strategic Outlook
The emergence of AMLA should not be treated simply as another regulatory implementation programme.
For international financial institutions, it creates an opportunity to reconsider whether European financial-crime frameworks remain appropriate for increasingly integrated businesses.
The objective should not necessarily be complete centralisation.
Banking, asset management and insurance businesses have different customers, products, distribution channels and financial-crime exposures. Member States will continue to present different risks, and local expertise will remain essential.
The more sophisticated model is likely to be common standards with deliberate local variation.
Group governance should establish the minimum standard. Local businesses should retain the ability to respond to jurisdictional and sector-specific risk. First-line management should own the risks arising from the business. Second-line compliance should provide credible challenge and an aggregated view across entities and jurisdictions. Boards should receive information that allows them to understand not simply whether policies exist, but whether the framework is operating effectively.
That is ultimately the practical challenge presented by greater European supervisory convergence.
The question for international firms is no longer simply whether each entity can demonstrate compliance. It is whether the organisation can demonstrate that financial-crime risk is understood, governed and controlled coherently across the group.
That is the test firms should begin preparing for now.
