EU's AMLA Enters Operational Phase: Payment Institutions and CASPs Under a Unified Risk Assessment Framework
From legislative adoption in 2024 to enforcement standardisation in 2026, AMLA is closing the supervisory gaps between Member States. The cost structure of cross-border compliance is undergoing a structural shift.
EU's AMLA Enters Operational Phase: Payment Institutions and CASPs Under a Unified Risk Assessment Framework
Published: July 12, 2026
Category: Regulation / EU AML Framework
Reading Time: 7 minutes
On 19 June 2024, the EU's Anti-Money Laundering Package was published in the Official Journal. Three core legal instruments — the AMLA Regulation (EU 2024/1620), the AML Regulation (EU 2024/1624), and the Sixth Anti-Money Laundering Directive (EU 2024/1640) — now form the most unified AML/CFT supervisory framework in the EU's history.
Two years later, the Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt's MesseTurm, has moved from institutional setup to active rule-making. In the first two weeks of July 2026, AMLA released four major announcements in rapid succession:
- 2 July: Concluded a public hearing on draft guidelines for ongoing monitoring of business relationships
- 3 July: Finalised three sets of common standards for cross-border FIU cooperation and reporting to the European Public Prosecutor's Office (EPPO)
- 6 July: Launched a public consultation on rules for cross-border FIU information exchange
- 8 July: Published the first EU-wide harmonised enforcement standard for AML breaches — the same violation, in the same circumstances, will now lead to the same enforcement outcome across all Member States
These four announcements share a common trajectory: AMLA is using regulatory technical standards (RTS) and guidelines (GL) to close the supervisory gaps between Member States.
Why Payment Institutions and CASPs Are Brought Under Unified Risk Assessment for the First Time
Under the previous AML framework, EU rules took the form of Directives — each Member State transposed them into national law with discretion. A payment institution or a Crypto-Asset Service Provider (CASP) operating in Lithuania, Ireland, or Malta could face materially different supervisory standards.
The AML Regulation (EU 2024/1624) shifts the legal instrument from Directive to Regulation, which applies directly in all Member States without national transposition. This means:
- Unified definition of obliged entities: Payment institutions (PIs), electronic money institutions (EMIs), and CASPs are all explicitly listed as "obliged entities," subject to uniform risk assessment and customer due diligence (CDD) standards
- Harmonised thresholds: A single €1,000 CDD exemption threshold replaces the previous patchwork of national thresholds ranging from €5,000 to €15,000
- Beneficial ownership coverage: Crypto-asset service providers and crypto-asset issuers are brought within the scope of beneficial ownership verification obligations
Before this framework, CASPs' AML obligations existed in the intersection between MiCA and national AML laws — a grey zone that required navigating 27 different national interpretations. The AMLR removes this ambiguity.
AMLA's Supervisory Architecture: A Dual-Track Design
AMLA's supervisory model draws on the Single Supervisory Mechanism (SSM) blueprint but extends across a broader scope:
| Dimension | Direct Supervision | Indirect Supervision | |-----------|-------------------|---------------------| | Scope | Selected cross-border, high-risk entities | All other obliged entities | | Selection criteria | Operating in 6+ Member States, high ML/TF risk exposure | Supervised by national competent authorities (NCAs) to AMLA standards | | Selection timing | ~40 entities selected during 2027 | 2026–2027 transition period | | Full operation | 2028 | 2028 | | AMLA's role | Direct responsibility, direct enforcement | Monitors NCA performance, coordinates convergence |
Critically, the "selected entities" are not limited to banks. Under Article 6 of the AMLA Regulation, selection factors include cross-border operational scale, ML/TF risk exposure, and supervisory history. Large CASPs and pan-European payment firms are natural candidates for the first cohort.
Harmonised Enforcement: From Divergent Outcomes to Consistent Treatment
The harmonised enforcement standard published on 8 July 2026 marks AMLA's transition from rule-making to supervisory practice.
Previously, the same type of AML breach could yield entirely different enforcement outcomes across Member States. A CDD documentation gap might result in a remediation notice in one country and a substantial fine in another. This divergence was widely regarded as "regulatory arbitrage" space.
The new standard establishes a step-by-step assessment methodology:
- Assessment: Supervisors evaluate breach severity against a shared set of indicators (duration, repetition, impact)
- Classification: Breaches are categorised into one of four gravity levels
- Outcome: Common criteria guide supervisors to the appropriate enforcement action
This standard applies to all sectors covered by the AMLR — financial and non-financial alike. Once adopted by the European Commission, it becomes directly binding across all Member States.
For payment institutions and CASPs, the strategic implication is significant: the practice of establishing operations in jurisdictions with lighter supervisory regimes to reduce compliance costs will face a substantially narrowed window of viability.
The Passporting Dividend vs. the Rising Compliance Floor
MiCA already provides CASPs with a passporting mechanism — a single licence, pan-European operation. AMLA's harmonised AML supervision reinforces that passport on the anti-money laundering dimension:
Upside:
- Unified standards eliminate rule fragmentation, reducing the cost of interpreting divergent national requirements for cross-border operations
- Under direct AMLA supervision, large cross-border CASPs engage primarily with a single supervisor, reducing multi-jurisdictional coordination overhead
- Standardised cross-border FIU information exchange (the subject of AMLA's 3 July and 6 July announcements) will shorten the suspicious transaction report processing chain
Cost structure shifts:
- The compliance floor rises: systems built to satisfy a single Member State's standard will require upgrading to the AMLR's unified level
- Increased technical compliance requirements: ongoing monitoring, real-time transaction screening, and beneficial ownership verification systems must meet standardised specifications
- Preparation window for selected entities: for firms potentially included in the first ~40, the 2026–2027 period is the critical readiness window
Timeline and Practical Considerations
| Milestone | Key Event | Institutional Impact | |-----------|-----------|---------------------| | June 2024 | AML Package published in Official Journal | Legal framework established | | Summer 2025 | AMLA begins operations | Rule-making initiated | | 2026 | Intensive IT systems and technical standards output | Rules becoming concrete — close monitoring essential | | 2027 | Selection of ~40 entities for direct supervision | Large cross-border firms must prepare for direct oversight | | 2028 | Direct supervision fully operational | Compliance systems must be fully ready |
For firms serving EU markets or planning to apply for MiCA/CASP licences, 2026 is the observation window. The technical standards and guidelines AMLA is publishing now will determine the actual supervisory benchmark when full direct supervision begins in 2028. Engaging with public consultations early and tracking regulatory texts proactively will be more cost-effective than reactive adaptation.
About UWAY
UWAY is a compliance technology provider focused on delivering automated compliance solutions for financial institutions and regulated entities. We continuously track the evolution of EU and global AML/CFT frameworks and help clients operationalise compliance requirements during regulatory transition periods.
This article is based on publicly available documents from AMLA (amla.europa.eu) and the EU Official Journal. It is intended as industry analysis and does not constitute legal advice.
Tags: #AMLA #AntiMoneyLaundering #EURegulation #CASP #MiCA #Payments #Compliance #RegTech #FinTech #UWAY
UWAY Compliance Team
UWAY Innovation Limited is a Hong Kong-based compliance technology partner specializing in KYC, KYB, and AML infrastructure for Web3 and fintech firms.