Zum Hauptinhalt springen
European AML Compliance

AMLR Readiness: prepare for the EU AML single rulebook by 10 July 2027

A structured view of your current operating model, the gaps that matter and a prioritised roadmap to the application date.

Regulation (EU) 2024/1624 applies directly across the European Union from 10 July 2027 and raises expectations for governance, business-wide risk assessment, customer due diligence, beneficial ownership, ongoing monitoring, screening, transaction monitoring, data quality, technology and evidence. Readiness is therefore not a legal update exercise. It changes how your organisation identifies risk, onboards and reviews customers, handles alerts, uses technology, documents decisions and reports to management, boards and supervisors.

See what readiness covers

What you get

  • Gap matrix by workstream, risk level and maturity
  • Prioritised heatmap and dependency analysis
  • Action plan with owners, milestones and target dates
  • Roadmap to 10 July 2027 with resource estimates
Regulation (EU) 2024/1624 Article 10 AMLR Article 26 AMLR Article 28 AMLR Applies 10 July 2027

Audit-ready for BaFin and external auditors

Division of responsibilities

What S+P delivers

  • Collection and review of documents, data and case files
  • Structured interviews and operational walkthroughs
  • Assessment of maturity, gaps, risks and dependencies
  • Target state, action plan and prioritised roadmap
  • Reporting prepared for senior management, board and group

What remains with the institution

  • Approval of the risk assessment, policies and control framework
  • Decisions on prioritisation, budget and depth of implementation
  • Decisions on suspicious activity reports to the national FIU
  • Decisions on sanctions freezes and termination of relationships
  • Overall responsibility for proper business organisation

A readiness assessment is an evaluation and a decision paper. It does not replace approval of the framework by the responsible bodies, nor independent assurance by internal audit.

Why readiness matters now

AMLR is a directly applicable regulation. From 10 July 2027, core AML and CFT requirements will apply across the Union through a more harmonised rulebook. National supervisory practice, criminal law, financial intelligence unit processes and organisational obligations remain relevant, so readiness work has to cover both layers rather than replace one with the other.

The detail that determines implementation is being written now. AMLA has consulted on draft regulatory technical standards for the information required to perform customer due diligence under Article 28 AMLR, on draft guidelines for the business-wide risk assessment under Article 10(4) AMLR, and on draft guidelines for ongoing monitoring under Article 26(5) AMLR. The monitoring guidance matters most in practice because it covers periodic reviews, transaction and activity monitoring, and how unusual behaviour is detected across the life of a relationship.

The transition period is therefore not spare time. It is the window in which the current framework is assessed, the target operating model is redesigned where needed, policies and procedures are updated, systems and data are strengthened, operational capacity is built and evidence of effective implementation is prepared. Institutions that begin late carry existing backlogs into the new regime under stricter documentation expectations.

What we typically find

Six patterns that recur across readiness assessments.

A risk assessment that drives nothing

The business-wide risk assessment exists as a document but is disconnected from customer risk classification, review cycles, enhanced due diligence, screening scope and monitoring scenarios. It describes exposure without shaping controls.

Unclear decision rights

Responsibilities between head office, EU parent, branch and subsidiary are not documented, escalation routes are informal and it is unclear who may approve exceptions. Gaps then belong to nobody in particular.

Overdue reviews and stale records

Periodic reviews accumulate, trigger events are captured inconsistently and beneficial ownership data is incomplete. Ongoing monitoring cannot work reliably on a customer record that no longer reflects reality.

Parameters nobody can explain

Scenarios and thresholds were inherited from implementation and never revisited, calibrated or tested. The settings may be reasonable, but the rationale cannot be reconstructed under review.

Data that fails under scrutiny

Identification data, ownership information, country attributes and risk classes are incomplete or inconsistent across systems. Every metric built on that base is contestable, including the ones reported upward.

Evidence assembled after the fact

Files are reconstructed when a review is announced rather than produced as work happens. That approach consumes capacity, produces gaps and rarely convinces an experienced examiner.

What AMLR readiness covers

Eight workstreams, assessed individually or as a full programme.

Governance and accountability

Readiness begins with clear responsibility across boards, senior management, the AML function, business units, technology, operations and internal audit.

  • Definition and documentation of the AML governance model
  • Responsibilities between head office, EU parent, branch and subsidiary
  • Position, resourcing and support of the local reporting officer
  • Deputy arrangements and continuity of the function
  • Escalation routes, decision rights and reporting lines
  • Separation of first line, second line and independent assurance
  • Policies, work instructions and delegated authorities
  • Integration of outsourcing and technology providers
  • Training, quality assurance and control model

Business-wide risk assessment

The assessment should drive the framework rather than sit beside it, and it must be updated when material changes occur.

  • Methodology, currency and depth of documentation
  • Customer, product, service, transaction and delivery channel risks
  • Country and geographic exposure
  • Risks of non-implementation and evasion of targeted financial sanctions
  • Group structure, outsourced services and emerging technologies
  • Link to customer risk classification and review cycles
  • Derivation of due diligence, screening and monitoring intensity
  • Control design and residual risk assessment
  • Approval, review and board reporting process

Article 10 AMLR requires obliged entities to identify and assess exposure to money laundering and terrorist financing as well as the risks of non-implementation and evasion of targeted financial sanctions. New products, services, business practices, delivery channels and technologies must be assessed before launch. AMLA is developing guidelines on the minimum content under Article 10(4) AMLR.

Customer due diligence and KYC

Due diligence has to work across the entire customer lifecycle, not only at onboarding.

  • Customer identification and verification
  • Customer risk classification and review logic
  • Purpose and intended nature of the business relationship
  • Source of funds and source of wealth where required
  • Enhanced due diligence for higher-risk relationships
  • Periodic and trigger-based reviews
  • Customer data refresh and evidence management
  • Backlog and overdue-review remediation
  • Quality assurance and operational controls

Beneficial ownership

Complete, current and evidenced ownership and control information remains a central risk area.

  • Data model and documentation rules for ownership and control
  • Direct and indirect ownership structures
  • Voting rights, control rights and other control mechanisms
  • Complex, multi-layered and cross-border structures
  • Review cycles and trigger events
  • Register checks and discrepancy handling
  • Screening of beneficial owners and linkage to customer risk
  • Evidence, data quality and audit trail
  • Escalation of incomplete or opaque structures

Decisions on discrepancy reports to the national transparency register remain with the authorised function of the institution. S+P prepares and documents the case.

Ongoing and transaction monitoring

Customer information, risk profile and transactional behaviour have to stay aligned over the life of the relationship.

  • Periodic and event-driven customer reviews
  • Monitoring scenarios, indicators and thresholds
  • Customer segmentation and risk profiling
  • Comparison of expected against observed activity
  • Alert prioritisation and investigation workflows
  • Case management, escalation and report preparation
  • Rulebook governance and change management
  • Backtesting, calibration and effectiveness analysis
  • Quality assurance and management reporting

Article 26 AMLR requires ongoing monitoring of business relationships and of the transactions and activities carried out within them. Decisions on suspicious activity reports remain with the authorised function of the institution.

Screening and restrictive measures

Screening must be risk-based, timely, documented and operationally workable at the volumes it produces.

  • Screening policy and scope definition
  • Rules for customers, beneficial owners, counterparties and payments
  • Processes for politically exposed persons, family members and close associates
  • Sanctions, embargo and restrictive measures workflows
  • Adverse media categories and investigation standards
  • Matching logic, tuning and false positive management
  • Rescreening and trigger-event processes
  • Case files, audit trail and escalation rules
  • Quality assurance and performance metrics

Technology, data and case management

Systems support compliance only where platforms, data, workflows and governance are aligned.

  • Platforms for due diligence, screening, monitoring and case management
  • Functional requirements and target operating model
  • Quality of customer, ownership, risk and transaction data
  • Data ownership and control rules
  • Workflow configuration, decision rights and evidence requirements
  • Rulebook, scenario and model governance
  • System changes, releases, testing and functional acceptance
  • Access rights, audit trail and retention
  • Management information and regulatory reporting

Audit readiness and remediation

Readiness has to be evidenced. Policies, controls, files, cases, reviews, changes and decisions should be traceable on request.

  • Evidence maps and structured audit repositories
  • Quality of customer, screening and monitoring files
  • Control evidence and quality assurance documentation
  • Findings, action plans and remediation tracking
  • Closing criteria and residual risk documentation
  • Internal audit follow-up and independent testing
  • Coordination of supervisory information requests
  • Board and management reporting
  • Transition of remediated processes into business as usual

What you receive

A management and implementation basis, not a legal summary.

Executive summary

A condensed view for senior management and the board: critical gaps, regulatory risk and the decisions required, in a few pages.

Gap matrix and heatmap

Assessment per workstream by maturity and risk level, visually prioritised across governance, customer processes, screening, monitoring, data and technology.

Action plan and roadmap

Actions with owners, dependencies, milestones and target dates, sequenced towards 10 July 2027 with room for testing and backlog reduction.

Target model and resources

Target operating model across all three lines, an estimate of technology, data and staffing needs, and a proposal for programme governance and reporting.

Four ways to engage

Depending on scope, urgency and organisational size.

Project

Full readiness assessment

A comprehensive assessment across all eight workstreams, including processes, data, systems and evidence, delivering the complete roadmap.

Focused

Single-topic assessment

A deep review of one area — governance, risk assessment, customer due diligence, beneficial ownership, screening, monitoring, technology or audit readiness.

Briefing

Board briefing

Regulatory developments, board and senior management responsibilities, implementation risks, resource requirements and the decision points ahead.

Programme

Transformation office

Coordination of parallel workstreams from governance and policies through technology and data to training, evidence and group reporting.

How we work

  1. 1

    Scope and mobilise

    Regulatory scope, legal entities, countries, business lines, products, systems, data sources and stakeholders are defined and agreed.

  2. 2

    Documents and data

    Review of the framework, risk assessment, policies, work instructions, rulebooks, reports, case files, findings and open actions.

  3. 3

    Interviews and walkthroughs

    Structured discussions with compliance, operations, risk, technology, data and internal audit. Walkthroughs show how processes actually run.

  4. 4

    Findings and readout

    Gaps, risks and dependencies are assessed and translated into a target state, action plan and roadmap, presented in an executive readout.

Readiness across the three lines

AMLR readiness affects every line of defence, not only the compliance function. The assessment therefore examines whether operational delivery, independent oversight and assurance are genuinely separated — mixed roles are among the most common findings.

Where S+P supports implementation afterwards, those lines remain separated through distinct teams, roles, access rights, delegated authorities and reporting lines.

LevelRole under AMLRAssessment perspective
Management body Approves the risk assessment, policies and control framework Quality of decision papers, reporting and steering capability
First line Operates customer, data, alert, case and evidence processes Process and throughput analysis, backlogs and data quality
Second line Sets standards, assesses risk, monitors, challenges and escalates Governance, methodology and control analysis
Third line Provides independent assurance over framework and controls Audit readiness, evidence and follow-up of findings

What you gain

A defensible baseline

Findings come from files and data rather than assumptions, which makes the scope of work credible internally.

Clarity

Risk-based prioritisation

Limited capacity goes first to the gaps carrying the highest regulatory risk, not the easiest ones.

Steering

A workable timeline

Dependencies and lead times become visible before they turn into bottlenecks close to the deadline.

Planning

Evidence of preparation

The assessment, its findings and the action plan are documented and can be shown to supervisors and auditors.

Assurance

A basis for decisions

Senior management and the board receive what they need to decide on budget, resourcing and sequencing.

Governance

A roadmap that can be executed

The output converts directly into projects and operational capacity rather than requiring another round of analysis.

Delivery

Who we support

  • Credit institutions and specialist banks
  • International banks with German branches or subsidiaries
  • Private banks and independent institutions
  • Payment and e-money institutions
  • Investment firms and asset managers
  • Capital management companies
  • Fintechs and embedded finance providers
  • Crypto-asset service providers
  • Financial groups with EU and German regulatory exposure

Related services

European AML Compliance

The overview of our European AML services, from assessment through implementation to managed operations.

Back to the hub

Group AML Governance

Consistent standards across head office, EU parent, branches and subsidiaries, implementable locally.

Explore Group AML Governance

AML Audit & Remediation

Audit readiness, evidence management and closure of supervisory and audit findings.

Explore Audit & Remediation

German AML for International Banks

Local AML governance, reporting officer support and BaFin-ready documentation.

Explore German AML Compliance

Talk to us

Describe your situation — entity type, processes in scope, trigger and timeline — and we will respond with an assessment.

Contact S+P Compliance

Frequently asked questions

When does AMLR apply?

Regulation (EU) 2024/1624 applies directly across the European Union from 10 July 2027 for most obliged entities. No national transposition is required for the regulation itself, while member states transpose Directive (EU) 2024/1640 into national law in parallel.

Why should we start readiness work now?

Because readiness changes governance, policies, the risk assessment, customer processes, beneficial ownership, screening, monitoring, systems, data, operations and evidence. Each of those needs design, implementation, testing, training and a transition into daily business. Data remediation and backlog reduction alone bind capacity over months.

Does AMLR replace all national AML requirements?

No. AMLR harmonises core requirements at EU level. National supervisory practice, criminal law provisions, financial intelligence unit processes, organisational obligations and other local rules remain relevant, so the assessment covers both layers.

Can we assess only one topic?

Yes. Alongside the full assessment we run focused reviews covering governance, the business-wide risk assessment, customer due diligence, beneficial ownership, screening, transaction monitoring, technology and data quality, group governance or audit readiness.

Can S+P support implementation afterwards?

Yes. Findings can be taken into governance work, technology and operations projects, customer file remediation, managed operations, screening operations, audit readiness and regulatory remediation. First line, second line and internal audit responsibilities remain separated throughout.

Can S+P support international groups?

Yes. We support head offices, EU parent undertakings, German branches and local subsidiaries with group governance, local implementation, technology governance, AML operations and reporting in both German and English.

Readiness starts with a clear view of where you stand

S+P Compliance turns European AML requirements into a prioritised, practical and auditable implementation roadmap — based on findings from your own files and data, and sequenced so that the work is finished before the application date rather than starting at it.

AMLR Readiness: prepare for the EU AML single rulebook by 10 July 2027