The clock is ticking on AMLA and AMLR readiness. AMLR applies from 10 July 2027, and AMLA continues to publish the standards and guidance that will shape how the regime works in practice. With less than a year remaining, you are now into delivery time.
If the new regime applies to your organisation, the coming months will be absorbed by interpreting regulations, technical standards and guidance; identifying and remediating compliance gaps; and running technology change and testing. Time lost now narrows your implementation choices later.
Over recent weeks I have discussed these issues in client meetings, at a BeyondFS roundtable with Nordic banking leaders in Copenhagen, at our breakfast with senior FinCrime leaders in London, during our webinar with my colleague Clarinda Woodford, and while following the discussions closely at AMLA's inaugural conference in Frankfurt.
Across every forum, the same questions came up: How much can I act on now? How far should I have progressed? What will count as a credible position when the deadline arrives?
AMLR creates a directly applicable European rulebook. AMLA will directly supervise up to 40 of the EU's most significant financial institutions or groups from 2028, with selection taking place in 2027. If you sit outside that "top 40," your national competent authority continues to play the leading role.
AMLA's work is moving quickly through the practical detail. Consultations to date have covered customer due diligence, ongoing monitoring, suspicious activity reporting, and, more recently, the business-wide risk assessment (BWRA) methodology under Article 26(5). These consultations matter more than their technical framing suggests: they start to fix how firms will be expected to evidence risk appetite and control effectiveness at an entity level, which has knock-on implications for governance and MI.
The continuing flow of draft material is not a reason to hold back. The direction is clear enough to begin meaningful work across CDD information, beneficial ownership, review cycles, monitoring, reporting, governance, data and technology. If you work in a large, well-resourced institution, the expectation is simple: by 10 July 2027, you will either be able to explain how you comply, or explain clearly why you don't. Waiting for every last piece of guidance will not be viewed as a credible justification.
National regulators are also still working through the detail, so some questions will remain genuinely open. That makes your internal record more important, not less. Capture assumptions, decisions, deferred matters, owners and review points as the position develops. You will need to reproduce that trail for your board, internal audit and, eventually, your supervisor.
Readiness varies considerably. Some banks have mobilised programmes, mapped requirements and started assessing affected customer populations. Others are still deciding what AMLR means for their footprint and operating model.
Some firms believe existing risk-based review cycles can absorb the required CDD work. Others have concluded a dedicated remediation programme is unavoidable. A third group is leaning more heavily on perpetual KYC or event-driven review.
There is no single "right" answer. It depends on customer volumes, current standards, data quality, systems, operating model and local variation across the group. The question I would ask is whether your chosen approach is evidenced and defensible. Event-driven models depend on reliable data, comprehensive triggers, connected systems and clear governance; none of which can be assumed. Dormant relationships need particular attention here: under the emerging AMLR obligations, you should be able to explain why those accounts remain open and whether review, restriction or exit is the right call, rather than letting them sit outside the active review cycle by default.
By now, I would expect clear senior ownership for AMLR readiness, an agreed governance approach, and a defined scope. You should know what is affected and where responsibility sits across the first and second lines.
I would also expect an initial obligations and impact assessment to be well underway, ideally complete. It should identify likely changes across policy, controls, processes, data, technology, training and testing, and separate requirements into three buckets: those clear enough to act on now, those awaiting further detail, and those dependent on future guidance.
CDD deserves your early attention because it is likely to make up much of the workload. In our webinar poll it was the leading concern for 61% of attendees, followed by the business-wide risk assessment obligations. You should already be quantifying affected populations and assessing whether scheduled reviews, targeted remediation, event-driven activity, or a combined approach will be sufficient.
Your board should also understand the position. I would want to give them a realistic account of known requirements, material gaps, open interpretations, capacity constraints and decisions requiring senior support. Where compliance remains uncertain, the board needs to understand why, and when the position will be revisited. This is also consistent with the direction FATF signalled during its UK Presidency webinar. The expectation is demonstrable, risk-based judgement, not perfect certainty.
Start by confirming scope, assessing likely AMLA exposure, and identifying where current controls diverge from emerging requirements.
Then build a controlled decision record. Document interpretations, owners, approvals and review dates so you can maintain a consistent account across operations, compliance, internal audit, the board and supervisors.
Finally, protect delivery capacity. AMLR work will compete with remediation, audit actions, technology change and business-as-usual priorities. The bottleneck is more likely to be specialist expertise than overall headcount.
The regulatory picture will keep developing. Your task is to absorb new information without losing momentum. The organisations in the strongest position will be the ones that can explain what they know, what they have decided, what remains open, and what happens next. With less than a year to go, that is the position I would expect every senior FinCrime leader to be working towards.
