People talk about “the new AML law” as if it were one thing. It is really three — a Regulation that applies directly, a Directive implemented through national law, and an EU authority. National law still matters where AMLR permits Member State options and for the implementation of AMLD6.
The three parts
Because it is a Regulation, AMLR applies directly without national transposition. Its core rules apply from 10 July 2027 and cover day-to-day obligations including customer due diligence, beneficial ownership, sanctions and PEP controls, record-keeping and an EU-wide maximum of €10,000 for large cash payments. National law still matters where AMLR allows Member States to adopt options or stricter rules, including lower cash-payment limits.
Because it is a Directive, Member States implement it through national law. The main transposition deadline is 10 July 2027, although selected provisions have earlier 2025 and 2026 deadlines and Article 18 has a 2029 deadline. AMLD6 shapes the supervisory and enforcement environment: supervisors, Financial Intelligence Units, beneficial-ownership registers, sanctions and administrative measures. Check your Member State’s implementing law as well as the EU text.
The Anti-Money Laundering Authority in Frankfurt coordinates and supports national AML/CFT supervision and develops much of the technical detail behind the Single Rulebook. Its first direct-supervision selection takes place in 2027 and concerns high-risk cross-border credit and financial institutions or groups. Direct supervision of the first selected population starts in 2028.
What’s at stake: accountability reaches the firm — and its people
Getting AML wrong under the new regime is not only a paperwork problem. Under AMLD6, Member States must ensure that obliged entities can face pecuniary sanctions for serious, repeated or systematic breaches of core AMLR requirements, including internal policies, procedures and controls, customer due diligence, reporting obligations and record retention.
Responsibility can also reach individuals. National law must allow sanctions and administrative measures to apply, where relevant, to members of senior management and other natural persons held responsible for a breach.
Supervisors can act before a weakness becomes a systemic failure. They must be able to intervene where weaknesses in a firm’s internal policies, procedures or controls are likely to result in breaches, or where those controls are not commensurate with the firm’s money-laundering or terrorist-financing risks.
A firm should be able to show how its controls operated in an individual case — what was identified, what its policy required, what was escalated, who decided and why. A complete, contemporaneous record helps demonstrate that history without reconstructing it later from files, emails and memory. The record is evidence of how the control framework operated; it does not itself determine legal liability.
The dates that matter
| 26 June 2024 | AMLA is legally established. |
| 1 July 2025 | AMLA becomes operational in Frankfurt. |
| 10 July 2027 | AMLR’s core rules apply; this is also the main AMLD6 transposition deadline. Selected AMLD6 provisions have earlier or later deadlines. |
| 2027 | AMLA carries out its first selection of high-risk cross-border financial institutions or groups for direct supervision. |
| 2028 | AMLA starts direct supervision of the first selected population. |
| 10 July 2029 | AMLR begins to apply to the professional-football categories covered by Article 3(3)(n) and (o). |
The preparation checklist
Group by group, the steps a regulated business is expected to have in place. You will work on several at once rather than in order. Tick items as you go — your progress is saved on this device only.
1. Confirm whether the rules apply to you
The scope of regulated businesses has widened. Many firms are covered for the first time.
2. Put the right people and governance in place
The rules expect clear accountability, not just good intentions.
3. Write your risk assessment and policies
Everything downstream is meant to flow from an honest view of your own risk.
4. Know your customers
The core of day-to-day compliance, now with harmonised, specific requirements.
5. Screen — and keep screening
Screening is not a one-time gate at onboarding.
6. Understand ownership and beneficial owners
Registers are being strengthened, with verification and discrepancy reporting.
7. Monitor, report and keep records
Being able to show your working is now part of the obligation.
8. Mind the EU-wide specifics
A few rules are new, uniform, and easy to miss.
9. Bring existing customers up to standard
The rules don’t only apply to new customers.
References & official sources
The primary legislation and guidance behind this page. Links open on official sites.
European Union
Operating in the UK too? See the sibling guide: JUSTE AML UK.
Before you rely on this
- AMLA finalised and submitted key draft regulatory technical standards to the European Commission in October 2026. They are not yet definitive law: they become binding only after Commission adoption and publication in the Official Journal. AMLA has proposed a six-month application period after entry into force for the relevant standards, but final timing depends on adoption.
- AMLD6 is written into each country’s own law, so exact dates and some specifics vary by member state. Always check your national implementing legislation.
- This is a plain-language overview to help you prepare — not legal advice. For your firm’s specific obligations, speak to a qualified AML professional.
Most of this list is work you can carry without a bank-sized compliance team. JUSTE is an AI-assisted, human-supervised AML platform that helps regulated SMEs put much of it into practice — sanctions and PEP screening, policy-governed due diligence, beneficial-ownership checks, staff controls and training, and an inspection report that shows how each decision was reached. AI recommends. Policy governs. Humans sign off. Evidence survives. Talk to us at hello@juste.ai.