Zum Hauptinhalt springen
European AML Compliance

AMLR readiness, AMLA standards and financial crime operations

The Anti-Money Laundering Regulation establishes a directly applicable EU single rulebook for core AML and CFT requirements from 10 July 2027.

In parallel, the Anti-Money Laundering Authority is developing technical standards and guidelines covering customer due diligence, the business-wide risk assessment and the ongoing monitoring of business relationships. For banks, payment and e-money institutions, investment firms, asset managers, fintechs and crypto-asset service providers, the task is not to understand new rules but to turn them into working governance, processes, data, technology, controls and audit-ready evidence. S+P Compliance combines German regulatory expertise with European implementation, financial crime technology and managed operations.

Go to our services

What you get

  • Gap assessment against AMLR and evolving AMLA standards
  • Group AML governance that works in local entities
  • Calibrated screening and monitoring with documented rationale
  • Operational capacity for reviews, alerts and remediation
Regulation (EU) 2024/1624 Article 10 AMLR Article 26 AMLR Article 28 AMLR Applies 10 July 2027

Audit-ready for BaFin and external auditors

Division of responsibilities

What S+P delivers

  • Regulatory mapping, gap assessment and implementation roadmap
  • Target operating model, policies and local addenda
  • Functional calibration of scenarios, thresholds and screening logic
  • Test concepts, test cases and support during functional acceptance
  • Operational processing in the first line of defence

What remains with the institution

  • Approval of the risk assessment, policies and control framework
  • Sign-off on material rules, models and changes
  • Decisions on suspicious activity reports to the national FIU
  • Decisions on sanctions freezes and termination of relationships
  • Overall responsibility for proper business organisation

Outsourcing shifts execution, not accountability. Decisions carrying reporting or freezing effect remain with the authorised function of the institution.

Why AMLR matters now

Regulation (EU) 2024/1624 will apply directly across the European Union from 10 July 2027, harmonising central AML and CFT obligations and reducing national variation. This does not mean national requirements disappear. Supervisory practice, criminal law, FIU processes and organisational requirements remain relevant, and the sixth anti-money laundering directive still has to be transposed into national law.

The practical detail is being written now. AMLA has consulted on draft regulatory technical standards specifying the information to be collected for customer due diligence under Article 28(1) AMLR, on draft guidelines for the business-wide risk assessment under Article 10(4) AMLR, and on draft guidelines for the ongoing monitoring of business relationships under Article 26(5) AMLR. This level determines what data must be held, how risk classes are formed, when reviews are triggered and how monitoring outcomes must be documented.

The action plan follows from that: assess the current framework, review group and local governance, strengthen customer due diligence and ongoing monitoring, revisit screening and transaction monitoring controls, improve data quality and evidence, build operational capacity for backlogs and alert volumes, and prepare management, board and supervisory reporting.

What institutions are facing

Six patterns we encounter repeatedly in readiness assessments.

A policy that is compliant on paper

The framework reads well but does not describe how requirements are executed, documented and controlled day to day. Supervisors and auditors do not assess the text, they assess the effect. The gap becomes visible in files, not in policies.

A risk assessment that steers nothing

The business-wide risk assessment exists as a document but is not connected to customer risk classification, review cycles, enhanced due diligence, screening scope or monitoring scenarios. It describes risk without shaping controls.

Customer data that ages faster than it is refreshed

Periodic reviews accumulate, trigger events are not consistently captured and beneficial ownership information is incomplete. Ongoing monitoring cannot work reliably on a stale customer record.

Alert volumes beyond team capacity

Screening and monitoring produce more hits than the function can process within deadlines. Preparation consumes the time needed for assessment and escalation, and case files remain incomplete.

Group standards that do not land locally

Central policies describe principles but leave open how a German branch or subsidiary implements, documents and controls them. Without local addenda and documented deviations, gaps belong to nobody.

Decisions without evidence

It cannot be demonstrated why an alert was closed, a customer was classified, a review was completed or a scenario was adjusted. The decision may have been sound; the record does not show it.

Our European AML services

Six areas, available individually or as one programme.

AMLR readiness

Assess the current framework against AMLR and the evolving AMLA implementation standards, and translate the findings into a prioritised roadmap.

  • Regulatory mapping of AMLR, AMLA standards and national requirements
  • Gap assessment with maturity and risk rating per topic
  • Review of AML policies, procedures and delegated authorities
  • Business-wide risk assessment review
  • Customer due diligence and enhanced due diligence review
  • Beneficial ownership framework review
  • Ongoing monitoring model review
  • Screening, monitoring, technology and data quality assessment
  • Executive summary and board reporting

Group AML governance

A consistent framework across head office, EU parent undertakings, branches and subsidiaries, that remains implementable locally.

  • Group AML policy and binding minimum standards
  • Group target operating model and role allocation
  • Responsibilities between head office, EU parent and local entities
  • Governance for the local money laundering reporting officer and deputy
  • Group-wide and local risk assessment methodology
  • Group standards for customer due diligence, ownership, screening and monitoring
  • Governance for group AML technology
  • Escalation paths and bilingual reporting
  • Local implementation, evidence and audit readiness

AML technology and operations

Turn systems into an effective, auditable and scalable operating model — independently of any software provider.

  • Target architecture for customer due diligence, screening, monitoring and case management
  • Functional data model and interface requirements
  • Screening policy, matching logic and alert triage
  • Monitoring rulebook, scenarios, segmentation and thresholds
  • Case management and escalation workflows
  • Data quality rules, reconciliation and data ownership
  • Test concept, test cases and functional acceptance
  • Backtesting and effectiveness analysis
  • Managed operations for reviews, alerts and screening hits

S+P prepares and calibrates scenarios, indicators and thresholds and documents the rationale. Sign-off on material rules, models and changes takes place within the institution’s own governance and delegated authorities.

Audit readiness and remediation

Prepare for supervisory reviews, external and internal audit, and close findings in a way that holds.

  • Audit readiness assessment and evidence mapping
  • Structured evidence rooms and document sets
  • Review and completion of customer, screening and case files
  • Coordination and response to information requests
  • Findings translated into actions with owners and deadlines
  • Evidence collection and closing documentation
  • Residual risk documentation and exception handling
  • Remediation governance and progress reporting
  • Support for follow-up reviews and closure

Business-wide risk assessment

Turn the assessment from a static document into a management tool that actually drives controls.

  • Documented overview of business and operating model
  • Identification, assessment and classification of inherent risks
  • Assessment of control quality and effectiveness
  • Assessment and classification of residual risks
  • Coverage of customers, products, channels and geographies
  • Consideration of group structure, outsourcing and new technologies
  • Link to customer risk classification and review cycles
  • Derivation of screening scope and monitoring intensity
  • Review, update and board reporting process

Article 10 AMLR requires obliged entities to identify and assess exposure to money laundering and terrorist financing as well as the risks of non-implementation and evasion of targeted financial sanctions. New products, services, business practices, delivery channels and technologies must be assessed before launch. AMLA is developing guidelines on the minimum content under Article 10(4) AMLR.

Ongoing monitoring and customer lifecycle

Due diligence does not end at onboarding. Keeping the customer record current is a control in its own right.

  • Onboarding and customer due diligence
  • Customer risk classification and review cycles
  • Enhanced due diligence for higher-risk relationships
  • Beneficial ownership and control structures
  • Periodic and trigger-event reviews
  • Screening and event-driven rescreening
  • Customer data refresh and backlog reduction
  • Evidence management, deadlines and follow-ups
  • Managed operations for the ongoing workload

Article 26 AMLR requires ongoing monitoring of business relationships and of the transactions and activities carried out within them. AMLA has consulted on draft guidelines under Article 26(5) AMLR covering both the currency of customer information and the transaction and activity monitoring framework.

How we work

Provider independent

We represent no platform and receive no vendor commission. Recommendations follow requirements and risk profile, not product interests.

Functional, not technical

We specify, calibrate, test and operate on the functional side. System administration, development and vendor support stay with your authorised partners.

Evidence led

Every decision on parameters, classifications and case outcomes is documented so that it can be reconstructed under review.

Operationally capable

Design work does not stop at go-live. Where useful, we take on the processing volume so implementation and daily business do not compete.

Your readiness roadmap

Four phases, from transparency to a stable operating model.

Assess

Establish transparency

Regulatory mapping, gap assessment, review of governance, customer processes, screening, monitoring, technology and data, closing with a prioritised roadmap and board briefing.

Design

Define the target model

Target operating model for roles, processes, minimum standards, data, technology and reporting, aligned between group and local entities.

Implement

Build and test

Policies and work instructions, process redesign, rulebook implementation, data remediation, backlog reduction, training, testing and go-live readiness.

Operate

Run and improve

Local compliance support, managed operations, rulebook governance and calibration, quality assurance, audit readiness and bilingual reporting.

How an engagement starts

  1. 1

    Scoping

    Business model, obliged entity status, entities in scope, jurisdictions, products, systems, data sources and stakeholders.

  2. 2

    Documents and data

    Review of the risk assessment, policies, work instructions, control plans, rulebooks, reports, case files, findings and open actions.

  3. 3

    Interviews and walkthroughs

    Structured discussions with compliance, operations, IT, data and audit. Walkthroughs reveal how processes actually run.

  4. 4

    Findings and roadmap

    Maturity, gaps, risks and dependencies are assessed and translated into a target picture, action plan and management readout.

A clear three lines model

S+P can support operational, compliance and audit-related workstreams. These roles must remain separated — particularly when one provider covers more than one of them.

We separate delivery, oversight and assurance through distinct teams, roles, access rights, delegated authorities and reporting lines.

Line of defenceCore roleS+P support
First line Operates processes, handles cases, maintains data, deadlines and evidence Customer due diligence, alert and screening operations, data remediation
Second line Sets standards, assesses risk, monitors, challenges and escalates Money laundering reporting officer, group governance, compliance monitoring
Third line Provides independent assurance over the framework and its controls Internal audit, independent testing and follow-up
Management body Approves the framework and carries overall accountability Decision papers, board briefings and reporting formats

What you gain

A defensible baseline

Findings come from files and data rather than assumptions, which makes the scope of work credible.

Clarity

Risk-based prioritisation

Limited capacity goes first to the gaps carrying the highest regulatory risk.

Steering

Group and local alignment

Central standards and local requirements fit together instead of running in parallel.

Governance

Reliable data

Control rules, error lists and clear ownership make data quality measurable and manageable.

Data

Evidence that holds

Decisions, parameters and case outcomes are documented and can be reconstructed under review.

Assurance

Capacity when it counts

Processing capacity is available when implementation and daily business coincide.

Capacity

Who we support

  • International banks with German branches or subsidiaries
  • EU parent undertakings and cross-border banking groups
  • Private banks and specialist banks
  • Payment and e-money institutions
  • Investment firms and asset managers
  • Capital management companies
  • Fintechs and embedded finance providers
  • Crypto-asset service providers
  • Institutions with backlogs, high alert volumes or audit findings

Explore our European AML services

AMLR Readiness

Gap assessment against AMLR and AMLA standards, with a prioritised roadmap to 10 July 2027.

Explore AMLR Readiness

German AML for International Banks

Local AML governance, reporting officer support and BaFin-ready documentation.

Explore German AML Compliance

Talk to us

Describe your situation — entity type, processes in scope, trigger and timeline — and we will respond with an assessment.

Contact S+P Compliance

Frequently asked questions

When does AMLR apply?

Regulation (EU) 2024/1624 applies directly across the European Union from 10 July 2027 for most obliged entities. No national transposition is required for the regulation itself. In parallel, member states are transposing Directive (EU) 2024/1640 into national law.

Does AMLR replace all local AML requirements?

No. AMLR harmonises central obligations at EU level, while national rules remain relevant in areas such as supervisory practice, criminal law, financial intelligence unit processes and organisational requirements. Readiness work therefore has to cover both layers.

What is AMLA?

AMLA is the EU Anti-Money Laundering Authority, established by Regulation (EU) 2024/1620 and based in Frankfurt am Main. It develops technical standards, guidelines and supervisory approaches, and is expected to directly supervise selected financial sector entities from 2028.

Why should we start readiness work now?

Because the work is operational, not editorial. Governance, risk assessment, customer processes, beneficial ownership, screening, monitoring, technology, data, operations and evidence all need design, implementation, testing and a transition into daily business. Data remediation and backlog reduction alone bind capacity over months.

Can S+P support both transformation and ongoing operations?

Yes. Readiness assessment, governance, technology work, remediation, alert and screening operations, audit readiness and regulatory remediation can be combined. First line, second line and internal audit responsibilities remain separated through distinct teams, roles, access rights and reporting lines.

Does S+P provide technical software support?

No. We provide regulatory, functional and operational support. Technical system operation, software development, configuration by authorised administrators, licensing and vendor support remain with the institution, the software provider or the appointed technical implementation partner.

European rules. Local implementation. Effective AML compliance.

AMLR and AMLA are reshaping European financial crime compliance. Institutions that prepare governance, processes, technology, data and operational capacity now will be in a stronger position from July 2027 onwards. S+P Compliance helps you translate European requirements into practical, scalable and audit-ready operating models.

AMLR readiness, AMLA standards and financial crime operations