The EU AML single rulebook: what uniform enforcement means for fintechs

The EU AML single rulebook: what uniform enforcement means for fintechs

The AML Regulation replaces the patchwork of national AML transpositions with a directly applicable EU rulebook. For fintechs that have built compliance programmes around the variation in how member states implemented successive AML directives, the shift to uniform rules and centralised supervision changes the calculus in specific and material ways.

11 min read

This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for advice specific to your situation.

  • Instrument change: Regulation (EU) 2024/1624 replaces directive-based national transpositions with a directly applicable EU rulebook from July 2027.
  • What harmonises: Beneficial ownership threshold (25%), PEP definitions and EBA reference lists, CDD and EDD triggers, and correspondent banking due diligence, identical across all 27 member states.
  • Review direction: Programmes calibrated to national law must be mapped against the regulation’s direct text to identify gaps.
  • Who is most exposed: Fintechs authorised in member states that historically applied AML obligations with less rigour face the most significant upward revision.

The problem with six iterations of the same directive

The EU has been legislating against money laundering since 1991. The First Anti-Money Laundering Directive was followed by a second, a third, a fourth, a fifth, and then a sixth. Each directive tightened and extended the rules. Each also required member states to transpose those rules into national law, and each member state did so differently.

The result, after three decades of directive-based harmonisation, was twenty-seven national AML regimes that shared the same objectives and broad structure but diverged materially in the definitions they used, the thresholds they set, the sectors they brought into scope, and the rigour with which they enforced. That divergence was not incidental to the directive instrument. It was structural. Directives set objectives; they leave implementation to member states.

For fintechs operating across multiple EU jurisdictions, this divergence had real compliance consequences. The beneficial ownership thresholds used to determine when a natural person must be identified as a UBO varied. The definition of politically exposed person was applied differently across member states. Enhanced due diligence triggers were not uniform. Correspondent banking and e-money exemption conditions differed. A compliance programme calibrated for Germany was not necessarily adequate for Ireland, and neither was automatically sufficient for the Netherlands.

The AML Regulation (Regulation (EU) 2024/1624), which takes effect from July 2027, changes the underlying instrument. It is a regulation, not a directive. It is directly applicable across all member states without transposition. The substantive rules it contains will apply identically in every EU member state on the same date. The variation that accumulated across thirty years of directive transpositions does not carry forward into the new framework.

What the AML Regulation actually harmonises

Understanding which elements of the AML framework are now uniform requires distinguishing between the three instruments that together form the new AML package.

The AML Regulation itself is the substantive rulebook for obliged entities. It sets out the customer due diligence requirements, the beneficial ownership rules, the enhanced due diligence triggers, the internal controls and governance obligations, and the rules on business relationships and occasional transactions. These provisions will be the same in every member state from July 2027.

The AMLA Regulation (Regulation (EU) 2024/1620) establishes the Anti-Money Laundering Authority, defines its supervisory mandate, and sets out how it will coordinate with national supervisors and conduct direct supervision of the highest-risk obliged entities from 2028. For a detailed account of AMLA’s institutional position and its relationship to EBA’s former AML mandate, see ESMA, EBA, EIOPA: who does what in EU financial supervision.

The Sixth Anti-Money Laundering Directive (6AMLD, Directive (EU) 2024/1640) addresses the institutional and procedural framework: the organisation of national Financial Intelligence Units, the conditions for access to beneficial ownership registers, supervisory cooperation, and the sanctions framework. As a directive, 6AMLD still requires national transposition, and some variation in implementation will persist in this layer.

The harmonisation that matters most for fintech compliance programmes is in the AML Regulation, because that is where the substantive customer-facing obligations live.

The specific provisions that are now uniform

Several provisions that varied materially across member states under the directive framework are now set at EU level.

Beneficial ownership thresholds. The AML Regulation fixes the threshold for identifying a natural person as a beneficial owner at a 25 percent ownership or control interest in a legal entity. Some member states applied lower thresholds, or required identification of all natural persons in the control chain regardless of percentage. The regulation does not prohibit member states from maintaining lower thresholds in national law for specific purposes, but the baseline obligation for obliged entities is now harmonised.

PEP definitions and lists. The regulation establishes a uniform definition of politically exposed person and requires the European Banking Authority to maintain a reference list of the functions that qualify as PEP-generating positions across member states. This addresses one of the most practically significant divergences under the directive framework, where national PEP lists and the scope of PEP-generating functions varied enough that a person classified as a PEP in one member state was not necessarily so classified in another.

Customer due diligence triggers. The conditions under which standard, simplified, and enhanced due diligence apply are set in the regulation rather than left to member state implementation. The list of enhanced due diligence triggers, including high-risk third countries, complex ownership structures, and specific product types, is now EU-level. NCAs retain some discretion on enhanced due diligence requirements for specific domestic risk factors, but the baseline trigger conditions are uniform.

Correspondent relationships. The specific due diligence requirements for correspondent banking relationships, which generated significant national variation under successive directives, are now directly applicable EU rules. Payment institutions and e-money institutions providing correspondent-like services are brought within the same framework as credit institutions for these purposes.

Beneficial ownership registers. The AML Regulation requires obliged entities to report discrepancies between the information they obtain during customer due diligence and the information held in national beneficial ownership registers. The conditions for this obligation are now uniform, though the registers themselves remain national and the quality and completeness of register data continues to vary.

What this means for fintechs with multi-jurisdiction compliance programmes

Fintechs that hold payment institution or e-money institution authorisations in multiple EU member states have typically built compliance programmes anchored to the national AML law of the home member state, with adjustments for host member state requirements where the passport is used to provide services cross-border. That architecture was appropriate under the directive framework, because the substantive rules were national laws.

Under the AML Regulation, the substantive rules are EU-level directly applicable provisions. The home member state NCA is no longer interpreting and applying a national AML law that transposes an EU directive. It is supervising compliance with the same EU regulation as every other NCA across the bloc.

The practical implication for compliance programmes is not that they become simpler overnight. It is that the compliance baseline is now the regulation text itself, the implementing and delegated acts that AMLA and the Commission will issue under it, and AMLA’s supervisory guidance, rather than twenty-seven bodies of national law. Firms with existing national-law calibrated programmes need to review them against the regulation’s direct provisions and identify where the national law they were calibrated to diverges from the EU baseline.

Some of that review will find that the national transposition was stricter than the EU baseline, and that the programme already meets the regulation’s requirements. Some will find gaps where national law was more permissive than the regulation requires, and where the programme needs to be updated upward. For fintechs authorised in member states that historically applied AML obligations with less rigour, the update required may be significant.

The AMLA supervisory layer and what it adds

The AML Regulation on its own is a substantive rulebook change. AMLA adds a supervisory architecture change on top of it.

From 1 January 2026, AMLA coordinates national AML supervisors and maintains the EuReCa database of material AML weaknesses identified by national supervisors. This coordination function is already active. For fintechs, the immediate consequence is that material supervisory findings at the national level flow into a shared EU-level database that other NCAs can access. The information asymmetry between national supervisors that historically allowed AML supervisory gaps to persist without cross-border visibility is narrowing.

From 2028, AMLA will directly supervise approximately forty obliged entities assessed as presenting the highest cross-border AML risk. The selection methodology is still being finalised, but it is expected to focus on firms with significant cross-border activity, large customer volumes in high-risk segments, or complex group structures spanning multiple member states. For the fintech sector, the relevant population is likely to include the largest cross-border payment institutions and the largest crypto-asset service providers after MiCA authorisation.

Firms that fall within AMLA’s direct supervision population will be supervised by AMLA rather than their home NCA for AML/CFT purposes. This means the supervisory relationship, the examination process, and the enforcement route all shift. AMLA’s supervisory approach is being developed through 2026 and 2027, and the methodology documents it publishes during this period are the relevant tracking target for firms that may be in scope.

For firms outside AMLA’s direct supervision, national supervisors remain the primary AML authority, but they operate within a coordination framework that AMLA controls and within rules that are now EU-level rather than national.

The enforcement harmonisation that follows from uniform rules

One of the consistent features of the directive-based AML framework was the divergence in enforcement outcomes for equivalent conduct across member states. The largest AML enforcement actions in Europe have been concentrated in a small number of jurisdictions. Several member states have historically had low AML enforcement activity regardless of the AML risk profile of their financial sector.

The move to a directly applicable regulation does not automatically produce uniform enforcement. NCAs still conduct investigations and impose sanctions at the national level, except for AMLA’s direct supervision population. What changes is the legal basis they are applying. When the same regulation applies in every member state, ESMA-style peer review pressure, which AMLA is explicitly mandated to exercise over national AML supervisors, can identify divergences between member states’ enforcement of the same text more precisely than it could when each member state was enforcing its own national transposition of a directive.

The direction is convergence upward. The AML Regulation sets out a sanctions framework that is more detailed than 6AMLD’s minimum requirements, and AMLA’s coordination mandate includes peer review of national supervisory effectiveness. Member states where AML enforcement has historically been light are under more structural pressure than before to demonstrate that their supervisory activity is proportionate to the risk profile of the firms they supervise.

For fintechs, the practical implication is that compliance programmes calibrated to the enforcement culture of a particular home member state, rather than to the substantive requirements of the AML framework, are more exposed than they were under the directive regime. The regulatory floor is now harder, and the mechanisms for identifying and addressing deviations from it are more developed.

What compliance teams need to do before July 2027

The AML Regulation’s application date is July 2027. That is enough time to conduct a structured review, but not enough time to defer the work until the deadline is close.

The review process has three components. First, identify every provision in the current compliance programme that references a national AML law rather than the EU directive it implemented. For each such provision, assess whether the national law differs from the AML Regulation’s direct text, and in which direction. Second, review the implementing and delegated acts that AMLA and the Commission issue under the regulation as they are published. The regulation confers numerous mandates for secondary legislation, and the technical detail of many requirements, particularly around CDD procedures, risk assessment methodology, and group-level compliance, will be set in those instruments rather than in the regulation text itself. Third, track AMLA’s supervisory guidance as it develops, including the supervisory methodology it intends to apply to the firms it directly supervises, which provides a leading indicator of the supervisory expectations that will eventually flow through to national supervisors for the broader population.

For multi-jurisdiction fintechs, the rationalization opportunity is genuine. A compliance programme anchored to a single EU regulation, with jurisdiction-specific adjustments only where the regulation explicitly permits member state variation, is structurally simpler than a programme anchored to twenty-seven national laws. Reaching that position requires the up-front work of the review described above.

Forseti monitors the AML regulatory pipeline continuously, including AMLA supervisory guidance, AML Regulation implementing acts, and national supervisory developments, anchored to verified official sources. Start for free.

For the supervisory architecture that sits behind the AML framework, including AMLA’s relationship to EBA and the national supervisors, see ESMA, EBA, EIOPA: who does what in EU financial supervision. For the cost exposure that AML non-compliance creates, see the cost of regulatory non-compliance in EU financial services.

A regulatory update is not useful until you know what it means for your business. Here is how Verdandi turns a Commission proposal, a guidance document, or a consultation output into personalised analysis of what changed and why it matters to your specific situation.