AML & KYC in the European Union is governed by one of the most comprehensive regulatory frameworks in the world, and it is currently in the middle of a structural transformation. The EU has replaced its patchwork of national transpositions with a directly applicable supranational rulebook, creating new obligations for thousands of businesses across all member states. This guide covers the core legal framework, the new EU-level supervisory authority, customer due diligence requirements, beneficial ownership rules, and the practical steps businesses must take to remain compliant.
The EU';s anti-money laundering framework rests on a series of directives that have been progressively tightened since the early 1990s. The Sixth Anti-Money Laundering Directive (AMLD6) extended criminal liability for money laundering to legal persons and expanded the list of predicate offences to include cybercrime and environmental crime. However, the directive model - which required each member state to transpose rules into national law - produced significant inconsistencies across the single market.
The EU responded by adopting a new legislative package that fundamentally changes the architecture of AML supervision. The package consists of a directly applicable AML Regulation (AMLR), which replaces large portions of the directive framework with uniform rules, and a revised directive (AMLD6 successor) that governs institutional arrangements and national competent authorities. The AMLR applies directly in all member states without transposition, eliminating the divergence that previously allowed regulatory arbitrage between jurisdictions.
Obliged entities under the framework include credit institutions, payment institutions, crypto-asset service providers, investment firms, insurance companies, real estate agents, lawyers, notaries, accountants, trust and company service providers, and high-value goods dealers. Each category faces specific due diligence obligations calibrated to its risk profile.
Know Your Customer (KYC) is the process by which obliged entities verify the identity of their clients, understand the nature of the business relationship, and assess the associated money laundering and terrorist financing risk. Under the AMLR, KYC is not a one-time onboarding exercise but a continuous obligation that must be updated whenever circumstances change or at risk-based intervals.
Standard customer due diligence requires obliged entities to:
Simplified due diligence is permitted where the customer, product or transaction presents a demonstrably lower risk, as assessed against the criteria set out in the AMLR. Conversely, enhanced due diligence (EDD) is mandatory for high-risk situations, including relationships with customers from third countries identified as high-risk by the European Commission, politically exposed persons (PEPs), and correspondent banking relationships.
The AMLR introduces stricter rules on PEPs. The definition is harmonised across all member states, and the enhanced measures must remain in place for at least 12 months after a person ceases to hold a prominent public function. Family members and close associates of PEPs are subject to the same enhanced scrutiny.
A common mistake among foreign businesses entering the EU market is treating KYC as a documentation exercise rather than a risk assessment process. Regulators increasingly expect firms to demonstrate that their due diligence conclusions are supported by substantive analysis, not merely by the collection of identity documents.
The most structurally significant development in recent EU AML policy is the creation of the Anti-Money Laundering Authority, known as AMLA. AMLA is a new EU-level supervisory body with direct supervisory powers over the highest-risk obliged entities operating across borders. It is headquartered in Frankfurt.
AMLA';s direct supervision covers selected obliged entities in the financial sector that operate in at least six member states and are assessed as presenting the highest risk. For entities not under direct AMLA supervision, AMLA acts as a coordination and oversight body, setting binding technical standards, issuing guidelines, and resolving disputes between national competent authorities.
AMLA has the power to conduct on-site inspections, request information, impose administrative measures, and, in cases of serious, systematic or repeated breaches, impose pecuniary sanctions directly on obliged entities. The introduction of a single EU-level supervisor removes the ability of firms to exploit supervisory gaps between member states.
For businesses, AMLA';s establishment means that the standard of compliance expected across the EU is converging upward toward the most demanding national practices. Firms that previously benefited from lighter-touch supervision in certain member states should expect that gap to close as AMLA';s technical standards become binding.
In practice, founders and compliance officers should consider reviewing their group-wide AML policies now to ensure they are aligned with AMLR requirements and AMLA';s published guidelines, rather than waiting for a supervisory review to identify deficiencies.
If your business operates across multiple EU member states and you are uncertain whether your current AML programme meets the new standards, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Beneficial ownership transparency is a cornerstone of the EU';s AML strategy. The AMLR and the accompanying directive require all member states to maintain central registers of the beneficial owners of corporate and other legal entities, as well as of trusts and similar legal arrangements.
A beneficial owner is defined as any natural person who ultimately owns or controls a legal entity, typically through a threshold of more than 25% of shares or voting rights, or through other means of control. Where no natural person can be identified above the threshold, the senior managing official must be recorded as the beneficial owner.
The registers must be interconnected through the Business Registers Interconnection System (BRIS) and the system for interconnection of registers on beneficial ownership (BORIS), allowing competent authorities and obliged entities across the EU to access information efficiently. Access rules have been refined following the Court of Justice of the EU';s ruling in Joined Cases C-37/20 and C-601/20, which restricted unrestricted public access to beneficial ownership data. Under the current framework, access is available to competent authorities, financial intelligence units, obliged entities performing due diligence, and persons or organisations that can demonstrate a legitimate interest.
A non-obvious requirement for many foreign investors is that the beneficial ownership registration obligation applies not only to EU-incorporated entities but also to foreign entities that own real estate or conduct business in the EU through certain structures. Failure to register or to keep information current can result in administrative sanctions at the national level, and the information gap will be visible to any obliged entity conducting due diligence on the structure.
The EU has extended its AML framework comprehensively to the crypto-asset sector through the Markets in Crypto-Assets Regulation (MiCA) and through specific provisions in the AMLR and the Transfer of Funds Regulation (TFR). Crypto-asset service providers (CASPs) are now fully within the scope of obliged entities and must apply the complete KYC and transaction monitoring framework.
The travel rule, which requires that information about the originator and beneficiary of a transfer accompanies the transfer throughout the payment chain, now applies to crypto-asset transfers without a minimum threshold. This is a stricter standard than the EUR 1,000 threshold that applies to traditional wire transfers. CASPs must collect, verify and transmit originator and beneficiary information for every transfer, including transfers to or from unhosted wallets, where enhanced due diligence measures apply.
For businesses operating in the crypto sector, the practical burden is significant. Compliance requires investment in technical infrastructure capable of handling travel rule data, as well as policies for managing transfers where the counterparty CASP does not yet have the technical capacity to receive or transmit the required information.
A common mistake is assuming that registration or licensing under MiCA satisfies AML obligations. MiCA governs market conduct and prudential requirements; the AMLR governs AML and KYC. Both frameworks apply simultaneously, and a CASP must maintain separate compliance programmes for each.
The risk-based approach (RBA) is the organising principle of the EU';s AML framework. Rather than applying uniform measures to all customers and transactions, obliged entities must calibrate the intensity of their due diligence to the level of risk they have identified. This requires a documented, systematic methodology.
An effective AML compliance programme under the AMLR must include:
The AMLR introduces specific requirements for group-wide compliance programmes. A parent entity in the EU must ensure that its subsidiaries and branches in third countries apply AML measures equivalent to those required under EU law. Where the law of a third country does not permit the application of equivalent measures, the group must apply enhanced measures and notify the competent authority in the home member state.
Many underestimate the documentation burden associated with the risk-based approach. Regulators do not simply ask whether a firm has a policy; they ask for evidence that the policy was applied consistently, that exceptions were escalated appropriately, and that the firm';s risk assessments were updated in response to changes in the business or the external environment.
Consider two practical scenarios. A payment institution onboarding a corporate customer from a FATF-listed high-risk jurisdiction must apply enhanced due diligence, obtain senior management approval for the relationship, and document the specific measures taken. A law firm advising on a real estate transaction must verify the beneficial ownership of the purchasing entity and file a suspicious transaction report if the source of funds cannot be satisfactorily explained - even if the transaction ultimately does not proceed.
To discuss how the AMLR';s requirements apply to your specific business model, reach out to info@vlolawfirm.com. We can assist with documents, policy drafting and filings.
What is the difference between the AMLR and the AMLD6 successor directive, and which applies to my business?
The AMLR is a directly applicable EU regulation that sets out the substantive obligations for obliged entities - customer due diligence, beneficial ownership, internal controls, and so on. It applies automatically in all member states without any national implementing legislation. The accompanying directive governs the institutional framework: the powers and organisation of national financial intelligence units, national supervisory authorities, and their cooperation with AMLA. Both instruments apply simultaneously. If your business is an obliged entity, the AMLR';s substantive rules bind you directly. The directive shapes how national authorities supervise and enforce those rules in your member state.
How long does it take to build a compliant AML programme, and what does it cost?
The timeline depends heavily on the size and complexity of the business. A small payment institution or CASP with a straightforward product range can typically build a baseline-compliant programme within three to six months, assuming it has access to qualified legal and compliance expertise. Larger, multi-jurisdictional financial groups may require 12 to 18 months to align group-wide policies with AMLR requirements. Professional fees for programme design, policy drafting and staff training generally start from the low thousands of EUR for smaller firms and scale significantly for complex organisations. Ongoing costs include the MLRO function, transaction monitoring technology, and periodic independent audits.
Does the EU AML framework apply to non-EU businesses that serve EU customers?
The territorial scope of the AMLR focuses primarily on obliged entities established or operating in the EU. However, non-EU businesses are not entirely outside the framework. A non-EU CASP that seeks authorisation under MiCA to serve EU customers becomes an obliged entity subject to the AMLR. A non-EU law firm or accountancy practice with a branch or representative office in the EU must comply for activities conducted through that presence. Additionally, EU-based obliged entities conducting due diligence on non-EU counterparties or customers will apply the AMLR';s standards to those relationships, meaning that non-EU businesses interacting with EU financial institutions will face KYC requests aligned with AMLR requirements regardless of their own regulatory status.
The EU';s AML and KYC framework has moved from a directive-based, nationally fragmented system to a directly applicable, centrally supervised regime. The AMLR, AMLA, and the extended scope covering crypto-assets represent a step change in the compliance burden for businesses operating in or with the EU. Firms that treat compliance as a documentation exercise rather than a genuine risk management function face increasing supervisory and reputational exposure.
VLO Law Firms advises international clients on AML & KYC matters in the European Union. We can assist with compliance programme design, beneficial ownership analysis, MLRO support, and regulatory filings across EU member states. To request a consultation, contact: info@vlolawfirm.com