Preparing for AMLR: what financial institutions need to know now
The EU Anti-Money Laundering Regulation (AMLR) applies from July 10, 2027. It replaces today’s patchwork of national AML directives with a single rulebook applied the same way across all 27 EU member states, overseen by a new pan-European supervisor, the Anti-Money Laundering Authority (AMLA), based in Frankfurt.
At a recent Encompass webinar, a panel of compliance and financial crime practitioners discussed what this shift means in practice. Additionally, what leaders of financial crime and compliance functions should be doing now, to prepare. The panel included Marielle Fernaine, partner at KYC Consulting; Lucile Delanoe, Head of Financial Security Office for Operations at BNP Paribas; and Jeeva Moni, an EY consulting partner specializing in data, analytics, and AI for financial crime transformation. Here’s what they had to say.
What do AMLR and AMLA actually change?
AMLR replaces local interpretation of AML rules with one detailed, harmonized standard, and shifts the focus from having policies to proving decisions. Institutions must be able to show, on demand, how the data they hold supports every client decision they make.
Until now, AML directives have been transposed and interpreted nationally, creating inconsistencies in how obligations are applied across Europe. Under AMLR, client due diligence, risk assessment, and the identification of ultimate beneficial owners (UBOs) are defined in detail. Regulatory and implementing technical standards (RTS and ITS) spell out exactly what data to collect, when enhanced due diligence applies, and which risk factors to consider.
The panel agreed that the most significant change is not the rules themselves, but what institutions must be able to prove. Strong policies and procedures on paper are no longer enough. Institutions need to demonstrate, quickly and on demand, the link between their data and every decision, from onboarding through to ongoing monitoring.
AMLA will directly supervise around 40 of the largest institutions, with national supervisors overseeing the rest under the same harmonized standard.
What is the biggest risk ahead of the AMLR deadline?
The biggest risk is data, not new rules. Most institutions hold large volumes of client records that must be reviewed, enriched, or corrected before July 2027, and few have started. A live poll during the webinar found that only around a third of attendees felt their data was in place and their reviews up to date. Roughly 65 percent had not yet started the work.
As Jeeva Moni put it, the feature and functionality changes in AMLR are the easy part. The real risk is data debt: the backlog of client records that fall short of the new standard, at a scale institutions cannot solve simply by hiring more staff. Institutions that have already invested in workflow orchestration and modern data infrastructure will find the transition considerably more manageable than those starting from a lower base. One way institutions are tackling data debt is with a corporate digital identity (CDI): a single, continuously updated profile of a legal entity that combines verified data and documents from authoritative sources, so each client record is complete, current, and traceable.
The panel also flagged a client experience issue that is easy to underestimate. Many corporate clients are multi-banked, so they will be asked for the same UBO documents by several banks at once, across multiple entities. The panel saw this as one of the more difficult, and more overlooked, practical implications of the new rules.
What does AMLR readiness look like in practice?
Readiness means dedicated governance, industrialized data collection, early change management, and preparing clients for what they will be asked. BNP Paribas offers a working example.
The bank has been preparing since mid-2025, when group compliance set up a dedicated governance structure and program team to coordinate the response across business lines and countries. Lucile Delanoe described three main challenges the bank is managing:
- Collecting additional data at quality. The bank is industrializing collection wherever possible, using public sources, data already held internally, or external providers, rather than defaulting to client outreach.
- Managing change at scale. Due diligence, relationship management, and compliance teams all need to adapt within a tightening timeline.
- Preparing clients. Many clients remain unaware of what will be asked of them.
The panel’s shared view was that institutions should resist the instinct to simply layer new requirements onto existing frameworks. Rethinking the framework for efficiency and explainability by design is the more durable path.
Does AMLR create opportunities as well as obligations?
Yes. A harmonized rulebook makes it easier for institutions to share information and detect cross-border financial crime, and further alignment may reduce complexity over time. Financial crime rarely respects institutional or national borders. Common standards make it easier to build a fuller picture of complex, cross-border schemes. The panel also noted that UK requirements, already stricter than the EU baseline in some areas, appear to be influencing AMLA’s direction. Further alignment may reduce operational complexity over time, even where it initially adds requirements.
Full alignment has limits, however. The panel highlighted a growing divergence between the EU and the US on UBO requirements, with Europe reinforcing its standards as the US moves to simplify them. That creates a specific challenge for global institutions operating across both.
What should financial institutions do now to prepare for AMLR?
Start now. The panel’s closing advice was consistent, and it came down to five steps:
- Assess data quality and exposure across your client base before deadline pressure compounds the problem.
- Industrialize data collection wherever possible, using public and internal sources before defaulting to client outreach.
- Build traceability so you can explain every decision, not just document the policy behind it.
- Coordinate change management early across due diligence, relationship management, and compliance teams.
- Rethink the framework for efficiency and explainability, not just compliance.
How does EC360 help institutions prepare for AMLR?
EC360 builds a corporate digital identity (CDI) profile for every client, giving compliance teams complete, auditable KYC data and a clear link between data and decisions. EC360 brings together real-time data and documents from authoritative public sources and private client information into a single CDI profile. By structuring KYC data and maintaining an auditable link between data and decisions, EC360 helps institutions meet AMLR’s explainability requirements without adding manual workload. It also gives compliance teams a foundation to industrialize data collection ahead of the July 2027 deadline.
Frequently asked questions about AMLR
The EU Anti-Money Laundering Regulation (AMLR) applies from July 10, 2027. It replaces national AML directives with a single rulebook applied directly in all 27 EU member states.
The Anti-Money Laundering Authority (AMLA) is the new EU-level AML supervisor, based in Frankfurt. It will directly supervise selected high-risk, cross-border institutions and coordinate national supervisors to apply AMLR consistently.
AMLA will directly supervise around 40 of the largest, highest-risk financial institutions operating across borders. National supervisors will oversee all other institutions under the same harmonized standard.
AMLR defines in detail how institutions identify and verify ultimate beneficial owners (UBOs), supported by technical standards on what data to collect. Corporate clients that bank with several institutions may face repeated requests for the same UBO documents.
Data debt is the backlog of client records that are incomplete, outdated, or inconsistent with current requirements. Under AMLR, these records must be reviewed, enriched, or corrected, often at a scale manual teams cannot absorb.
A corporate digital identity (CDI) is a single, continuously updated profile of a legal entity, built from verified data and documents from authoritative sources. It gives institutions a complete, traceable view of each corporate client for KYC and AML.
Discover corporate digital identity from Encompass
