The AMLR is the European Anti-Money Laundering Regulation, Regulation (EU) 2024/1624. It applies from 10 July 2027 and is directly applicable in all Member States. For your KYC this means that the rules on customer due diligence, UBO research and enhanced due diligence will be set out in one European text and become more uniform across the EU. A large part of the current rules in the Dutch Wwft will be absorbed into it. If you start preparing now, the transition will be a small step.
The AMLR affects every organisation that currently falls under the Wwft. Read What is KYC? and What is the Wwft? first if you want to refresh the basics.
What is the AMLR?
The AMLR is part of a European package against money laundering and terrorist financing. The package consists of three parts:
- the AMLR, with the rules for institutions, such as customer due diligence
- a new directive, with rules that Member States work out themselves, such as UBO registers, supervision and the FIU
- the establishment of AMLA, the new European supervisory authority
Until now the EU mainly worked with directives. Each Member State transposed them into its own legislation, in the Netherlands the Wwft. As a result, the rules differed from country to country. A regulation does not need to be transposed. It applies directly, in the same text, in all Member States.
What changes for your KYC?
The core of KYC stays the same. You identify and verify the customer, establish the UBO, understand the purpose of the relationship, screen for PEPs and sanctions, and keep monitoring. What changes is the way the rules are laid down:
- More detail. The AMLR describes more precisely which data you record and how you verify it.
- Uniform rules in the EU. Institutions active in several Member States will work with one set of rules.
- UBO research. The rules for establishing the ultimate beneficial owner are harmonised across the EU. Read more in What is a UBO?
- Enhanced due diligence. The rules for higher-risk customers, such as PEPs and high-risk countries, are also in the regulation. See Enhanced due diligence.
- Detailed rules. Many details are still being worked out in technical standards and guidelines. These will follow in the run-up to 2027.
Because not all details are known yet, it is sensible to keep following publications from AMLA and the European Commission.
The role of AMLA
AMLA is the new European Authority for Anti-Money Laundering and Countering the Financing of Terrorism. It is based in Frankfurt. AMLA has three main tasks:
- making supervision in the Member States more uniform and coordinating it
- drafting detailed rules and guidelines
- directly supervising a limited number of large, cross-border financial institutions
For most organisations, the national supervisor remains the point of contact. In the Netherlands these include DNB, the AFM, the Bureau Financieel Toezicht and the Kansspelautoriteit, the gambling authority. Reports of unusual transactions continue to go to FIU-Nederland.
What can you prepare now?
You do not have to wait until 2027. Much of the preparation can be done now:
- Gap analysis. Compare your current policy and procedures with the AMLR. Where do you fall short, and where are you already doing enough?
- Policy and procedures. Update your KYC policy, your risk assessment and your work instructions. Record who is responsible for what.
- UBO research. Check whether you have properly established and substantiated the UBO for every business customer, including complex structures.
- Existing files. Put old files in order. Missing data or outdated documents are a risk now, and will be later too.
- Data and retention periods. Review which data you record, how long you keep it and when you delete it. Align this with the new rules and with data protection law.
- Systems and training. Make sure your systems can record the new data and that your staff know about the changes.
Preparing yourself or getting help
Many organisations prepare the transition themselves, often led by the compliance function. That requires knowledge of the new rules and time to update policies and files. If you do not have that capacity, you can have specialists carry out the gap analysis or put your files in order. You then remain responsible for the policy and for the choices you make.