EU AML Framework

AML Compliance Intelligence for AMLA 2027 & AMLR

The EU’s anti-money-laundering regime is being rebuilt around a single rulebook and a new central supervisor. This guide summarises what AMLA, AMLR, AMLD6 and the Travel Rule require — and how ReguShield turns those obligations into audit-ready decisions.

The reformed EU AML framework

The EU’s earlier AML directives left rules to differ from one member state to the next. The 2024 AML package replaces much of that fragmentation with a directly-applicable rulebook and a European supervisor. In practice it means the same core customer-due-diligence, reporting and beneficial-ownership standards apply across the Union, backed by stronger, more coordinated enforcement.

AMLA 2027

EU Anti-Money Laundering Authority

A new EU-level supervisor with power to directly supervise the highest-risk cross-border financial entities and to coordinate national Financial Intelligence Units. It shifts AML oversight from a purely national model toward centralised European supervision.

AMLR

Single AML Rulebook

A directly-applicable regulation that harmonises customer due diligence, beneficial-ownership transparency and suspicious-transaction obligations into one set of rules across the Union, reducing the divergence left by earlier directives.

AMLD6

Sixth AML Directive

The directive layer that member states transpose into national law — covering supervisory architecture, FIU powers and access to beneficial-ownership and bank-account registers.

Travel Rule

FATF originator / beneficiary data

For crypto-asset transfers, originator and beneficiary information must travel with the transaction. In the EU this applies from a EUR 1,000 threshold, bringing CASPs in line with the FATF standard.

Core obligations

Customer due diligence

Identify and verify customers and beneficial owners, apply a risk-based approach, and escalate to enhanced due diligence for higher-risk relationships such as PEPs, high-risk third countries and complex cross-border activity.

Suspicious transaction reporting

File a Suspicious Transaction Report with the national FIU when suspicion arises. Under the reformed framework the expectation is prompt reporting — commonly within 15 days of a triggering event under national practice — with supporting rationale preserved.

Beneficial ownership

Maintain accurate, current beneficial-ownership information and reconcile it against national registers, with a lower ownership-threshold focus on transparency for complex structures.

Travel Rule data

For qualifying crypto-asset transfers at or above EUR 1,000, transmit and receive originator and beneficiary data, and screen it before making funds available.

Thresholds and timelines vary by activity and by national implementation. Treat the figures above as orientation, not a substitute for the applicable legal text and your supervisor’s guidance.

How ReguShield helps

ReguShield is a compliance intelligence layer that sits beneath the compliance function. It maps operational and transaction data against the AML obligations in scope and produces decisions a compliance officer can stand behind:

  • Obligation mapping. Each AMLA, AMLR and Travel Rule obligation in scope is mapped to your activity, so coverage and gaps are explicit.
  • Inherent & residual risk scoring. Deterministic ML/TF risk scores before and after controls, so residual exposure is visible.
  • Control-effectiveness assessment. How well existing controls reduce inherent risk, surfaced as a measurable input, not a guess.
  • Evidence lifecycle & audit lineage. Evidence is tracked against each obligation with a complete trail of the reasoning behind every decision.
  • Explainable decision support. Every conclusion traces back to the signal and the rule that produced it — deterministic and explainable, never a black box.
  • Board-ready executive reporting. Audit-ready reports with risk decisions, regulatory basis and recommended actions, built for supervisory scrutiny.

Analysis runs on demand over the data you provide. ReguShield does not claim a live regulator feed or any regulatory certification — it is a decision-support tool.

Frequently asked

What is AMLA and when does it start operating?

AMLA is the EU’s Anti-Money Laundering Authority, established to provide direct EU-level supervision of selected high-risk cross-border entities and to coordinate national supervisors and Financial Intelligence Units. It is being stood up ahead of assuming direct supervisory tasks in 2027, which is why firms describe readiness in terms of 'AMLA 2027'.

How is AMLR different from the earlier AML directives?

AMLR is a regulation — directly applicable in every member state without national transposition — so it harmonises customer due diligence, beneficial-ownership and reporting rules into a single rulebook. AMLD6 remains a directive for the supervisory and institutional architecture that member states adapt into national law. Together they replace much of the fragmented directive-only approach.

What is the Travel Rule threshold in the EU?

For crypto-asset transfers, originator and beneficiary information must accompany the transfer from a EUR 1,000 threshold under the EU transfer-of-funds regime, aligning CASPs with the FATF Travel Rule standard. There is no de minimis exemption below that threshold for the identification data that must still be collected.

Who has to comply with the EU AML framework?

Obliged entities include banks and payment institutions, crypto-asset service providers, many FinTechs, and a range of non-financial businesses. Any firm offering regulated financial or crypto services to EU customers is generally in scope for customer due diligence, suspicious-transaction reporting and beneficial-ownership obligations.

How does ReguShield support AML compliance?

ReguShield maps operational and transaction data against AMLA, AMLR and Travel Rule obligations on demand, scores inherent and residual ML/TF risk, assesses control effectiveness, tracks evidence against each obligation, and produces explainable, board-ready reporting. It is deterministic decision-support — the reasoning behind every conclusion is preserved for review, and final decisions stay with a qualified compliance officer.

ReguShield provides compliance decision-support — not legal advice; final decisions require human review and sign-off.

View the guided demoTrust CenterBack to Resources