From 2028, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) will directly supervise 40 credit and financial institutions and groups with high residual risk profiles operating in at least six Member States.

The first selection process will take place in 2027.

But preparation is already underway: AMLA is developing and testing the risk-assessment methodology that will inform the selection process. Institutions that may be eligible should use the remaining preparation period to examine the consistency, quality, defensibility and traceability of their anti-money laundering evidence.

What does AMLA direct supervision change?

Until now, anti-money laundering and counter-terrorist financing supervision has been conducted mainly by national authorities. This has sometimes resulted in different supervisory approaches across EU Member States.

AMLA will introduce a more integrated EU supervisory system. It will directly supervise selected institutions, support convergence between national supervisors and establish a more consistent approach to assessing money-laundering and terrorist-financing risk.

For groups, this change is particularly significant because the risk assessment underpinning direct-supervision selection is performed at group level. The change is particularly important for financial groups operating across multiple jurisdictions. Customer information, risk classifications and due-diligence decisions across different entities and jurisdictions may need to be sufficiently consistent and explainable when viewed as part of the wider group risk picture.

Which institutions may be selected?

Credit institutions, financial institutions and groups that operate in at least six EU Member States, including through establishments or under the freedom to provide services, may meet the eligibility criteria for direct supervision.

Eligibility does not mean automatic selection. AMLA will assess eligible institutions and select up to 40 institutions or groups presenting a high level of residual money-laundering or terrorist-financing risk.

According to AMLA’s published timeline:

  • National supervisors are expected to provide AMLA with data relating to entities meeting the eligibility criteria by the end of September 2026.
  • Final data will be collected from eligible institutions for direct supervision between January and March 2027.
  • The selection process will be conducted from July to December 2027.
  • The final selection will be communicated by the end of 2027
  • Direct supervision will begin in 2028.

What should cross-border institutions prepare?

You might be interested in our related article: Seven Questions for an AMLA Readiness Review

Establish whether the group may be eligible

Map the countries in which the institution operates through legal entities, branches or the freedom to provide services. Compliance, legal and regulatory-affairs teams should reach a common understanding of the group’s potential eligibility.

Institutions should establish which entities, branches and activities contribute to the group’s overall footprint and identify the data that may be required to demonstrate eligibility.

Reconcile information across jurisdictions

Determine whether different entities within the group apply the same definitions, risk categories and escalation standards.

The same customer should not have materially different risk classifications without a documented reason. Particular attention should be given to customer identities, beneficial ownership, politically exposed person status, jurisdictional risk and other factors that can materially affect the overall customer risk assessment.

Where they are not, the institution should understand whether the difference reflects a legitimate local requirement, different information or a genuine inconsistency.

Test whether high-risk files are defensible

Select a sample of higher-risk customer files and ask:

  • Can the beneficial ownership structure be reconstructed?
  • Is source-of-wealth or source-of-funds information supported by evidence?
  • Are sanctions, political exposure and adverse information findings current?
  • Can a reviewer understand why the customer was accepted or retained?
  • Are sources, dates, decisions and approvals recorded?

A technically complete file may still be difficult to defend if the reasoning behind it is unclear.

The objective is therefore not simply to establish that a KYC or EDD check was performed. It is to demonstrate how the institution moved from information gathered to risk assessment, decision and approval.

Prioritise the remediation backlog

Institutions should avoid treating remediation as a simple volume-reduction exercise. Prioritisation should consider customer risk, outdated information, complex ownership, high-risk jurisdictions, unexplained transactions and previous exceptions.

Institutions should also consider whether the highest-risk cases are receiving the greatest investigative attention. A large number of closed remediation cases is not necessarily evidence of readiness if the most complex or material cases remain unresolved.

Where remediation decisions involve judgement, the rationale for the decision should be retained alongside the supporting evidence rather than captured only as a final status or conclusion.

Preserve the investigation trail

Institutions should retain the sources and reasoning supporting important decisions. This includes original documents, reliable translations, retrieval dates, ownership findings, analyst conclusions and approval records.

Where information has been obtained from external sources, institutions should be able to identify what was reviewed, when it was reviewed and how it contributed to the final assessment.

This distinction may become increasingly important as supervisory scrutiny becomes more consistent across jurisdictions. A file that contains the right documents but does not clearly demonstrate the reasoning behind the decision may still be difficult to defend.

What does this mean for complex cross-border investigations?

Not every remediation case can be resolved through internal records or standardised database checks. Complex cases may require investigation across corporate registers, local-language media, court records, ownership structures and other public sources.

This is particularly relevant where ownership is opaque, corporate structures span multiple jurisdictions, reliable information is available only in local languages, or adverse information needs to be assessed in context.

For these cases, the quality of the research process matters as much as the final conclusion. Institutions should be able to distinguish between an absence of adverse information and an absence of evidence that was sufficient to reach a conclusion.

How can A Data Pro support AMLA preparation?

Some remediation cases can be resolved through internal records and established data providers. Others require investigation across corporate registers, local-language media, court records and less accessible public sources.

A Data Pro supports enhanced due-diligence and remediation programmes where additional investigative research is required, including multilingual research, beneficial ownership analysis, adverse-media investigation and source-of-wealth research.

This can help internal compliance teams resolve complex files while maintaining a clear and auditable evidence trail.

The role of specialist research should not be to replace the institution’s own risk assessment or decision-making. It should be to help the compliance team obtain, assess and document the information needed to make and defend that decision.

AMLA preparation should not be treated as a last-minute exercise.

The immediate priority is to identify where fragmented information, unresolved cases, inconsistent risk classifications or weak documentation could prevent the institution from explaining its risk decisions consistently.

For institutions potentially within scope, the most valuable preparation may therefore be less about predicting AMLA’s final selection and more about asking a straightforward question now: if a supervisor asked us to explain our highest-risk decisions tomorrow, could we do so clearly, consistently and with evidence?

Prepare for scrutiny, not simply selection

The first AMLA selection process will create a clear dividing line for the institutions chosen for direct supervision. But the wider supervisory change affects the market beyond those first 40 institutions.

For cross-border groups, one of the most important preparations is to understand whether their AML/CFT framework tells a coherent story across jurisdictions: whether customer information is reliable, risk classifications are explainable, high-risk decisions are supported by evidence and important investigations can be reconstructed after the event.

Siyana Vacheva, Head of R&C Business Services at A Data Pro says:

The question institutions should be asking now is not simply “Will AMLA select us?” It is “Could we defend our most important AML/CFT decisions if they were examined from a group-wide perspective?”

For institutions that may fall within AMLA’s first selection exercise, 2026 and 2027 provide an opportunity to identify those weaknesses before they become supervisory issues.

Speak to a risk and compliance expert

FAQs

When will AMLA begin directly supervising financial institutions?

AMLA is expected to begin direct supervision in 2028, following the first selection process in 2027.
For the first selection exercise, the relevant preparation period begins well before direct supervision itself. AMLA’s 2026 data-collection and methodology work is already contributing to the process that will inform the selection of institutions in 2027.

Will every institution operating in six EU countries be selected?

No. Operating in at least six Member States can make an institution eligible for assessment, but it does not mean that the institution will automatically be selected. AMLA will select up to 40 eligible institutions or groups based on their residual money-laundering and terrorist-financing risk.

What should institutions review first?

Institutions should begin with their potential eligibility, cross-border data consistency, high-risk customer files, remediation backlog and the auditability of important risk decisions. They should also identify whether important evidence is fragmented between jurisdictions, whether material decisions depend on undocumented analyst judgement and whether historical investigations can still be reconstructed from the available records.

Does AMLA matter to institutions that are not directly supervised?

Yes. AMLA will also promote more consistent standards among national supervisors. Its impact is therefore broader than the institutions selected for direct supervision. Institutions that are not selected may therefore still experience changes in supervisory expectations and risk-assessment practices and the degree of convergence between national supervisory approaches.