The EU’s new Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), passed by the European Parliament in 2024, is designed to centralise how financial institutions across the bloc handle AML/CFT compliance, customer due diligence and Know Your Customer checks.
According to AscentAI, from 10 July 2027, AMLA becomes the bloc’s central AML/CFT supervisor and rule-maker, with the European Banking Authority having already handed over its standalone AML/CFT mandate.
Centralisation implies simplicity, and dealing with one regulator is preferable to juggling several.
However, AMLA is already shaping up to introduce its own layer of complexity. As the primary authority, it will touch every part of EU AML enforcement, from Financial Intelligence Units (FIUs) to national supervisors. AMLA has finalised standards to help FIUs share information faster and more consistently, and has issued draft technical standards defining how it will work with national supervisors.
AMLA will also directly supervise around 40 large financial institutions, selected alongside national supervisors based on cross-border activity and inherent financial crime risk. Direct supervision is due to begin in January 2028, and how these firms are treated is likely to set the tone for regulatory expectations across the wider market.
Despite the push for uniformity, room for local interpretation remains. Under existing AML rules, each member state must designate an authority or mechanism to coordinate its national response to money laundering risks, and notify the European Commission accordingly. With 27 member states each potentially applying their own variant of this requirement, firms will still face a patchwork of practices even under AMLA’s more harmonised rulebook.
AMLA’s Single Programming Document for 2026-2028 lays out its priorities, including criteria for direct supervision selection, risk classification methodology, cooperation frameworks with national supervisors, and standards for assessing breaches and penalties.
To prepare, EY recommends firms conduct a gap analysis against forthcoming technical standards, invest in AI-driven transaction monitoring and eIDAS-compliant onboarding, update governance structures for new compliance roles, integrate with centralised beneficial ownership registers, and embed a stronger compliance culture across operations.
With a new regulator, new authorities and new sources of guidance to track, firms will increasingly need automated tools to monitor, categorise and contextualise regulatory change in near real time.
Read the full AscentAI post here.
Copyright © 2026 FinTech Global









