AMLA in 2026: what's happened, and what it means for banks, FinTechs, and payment firms

Arnaud Schwartz
CEO and Co-Founder
0 minutes reading
September 22, 2026
Summary

The EU's Anti-Money Laundering Authority (AMLA) spent 2026 writing the rules your compliance team will work under. Not the law (that was set in 2024), but the technical detail that turns it into practice.

By September 2026, a lot has moved: several standards finalised over the summer, a survey for payment firms, and the biggest rule for onboarding still in draft.

Here's what happened, in order, and what it means for you – with an outlook to 2027 which will be a major milestone for FRAML and compliance in the EU.

Key Takeaways
  • 2026 regulatory progress: AMLA finalized draft standards for FIU reporting, enforcement, and supervisory cooperation in mid-2026. However, the critical Customer Due Diligence (CDD) rulebook remains in draft form.
  • Enforcement timelines: the “single rulebook” (AMLR) takes direct effect across all EU member states on 10 July 2027. AMLA will start its direct oversight of selected high-risk entities in 2028.
  • Operational impact: banks, FinTechs, and PSPs must upgrade to adaptable FRAML compliance software now to handle shifting technical standards without re-engineering their core architecture.

The framework behind the noise: AMLR, AMLD6, and AMLAR

Three instruments make up the EU's new anti-money laundering regime:

  • The Anti-Money Laundering Regulation (AMLR) is the single rulebook, and it applies directly across the EU from 10 July 2027.
  • The sixth Anti-Money Laundering Directive (AMLD6) covers the parts left to national law.
  • The AMLA Regulation (AMLAR) created the authority itself.

AMLA's job is to write the technical standards that underpin all three, to turn principles into clear, concrete obligations.

If you want the full picture of what changes in 2027, our guide to the EU AMLR covers it. This piece is about what AMLA actually did this year.

AMLA 2026 timeline: technical standards & updates

AMLA started the year by putting its first standards on the table.

In February, it opened consultations on the draft rules for customer due diligence, for business relationships and linked transactions, and for enforcement.

Public hearings and the consultation window ran through the spring, with the customer due diligence and linked-transaction consultations closing on 8 May.

Then came a busy summer:

One detail matters here: these are final drafts submitted to the European Commission. Each becomes binding only once the Commission adopts it.

  • In August, the focus shifted to payment firms: AMLA launched a survey on Central Contact Points aimed squarely at electronic money institutions (EMIs) and payment service providers (PSPs), with responses due 15 September 2026.

And the one that isn't done: the customer due diligence rulebook. That consultation is closed, but no final standard has been published yet: at the time of this overview, the page still display "results will follow." This rulebook will contain the rules that will shape how you onboard and re-check customers.

What it means for your FRAML department and compliance teams

The pattern across 2026 is consistent: less room for national interpretation, more precise standards, and a supervisor that will read them the same way everywhere across Europe.

For banks, the enforcement and supervisory-cooperation standards signal how consistently breaches will be judged from 2028. The practical work is readiness now, not just in 2027: our AMLR readiness checklist for banks sets out the capabilities that matter (there's a Nordic-specific view for teams there – that may still be helpful for teams from elsewhere in Europe).

For FinTechs and neobanks, the draft customer due diligence standard is the one to track. It gets prescriptive on identity data, remote onboarding, and re-verification triggers – exactly the flows a digital-first team runs at volume.

For payment providers and e-money institutions, through its Central Contact Points survey, AMLA is currently reviewing how the framework works in practice.

For BaaS providers, all of the above will arrive at the same time, across every partner you serve. So consistent controls stop being a nice-to-have, and become obligatory.

Build for change, not for a fixed rulebook

The uncomfortable part for anyone waiting for "final" rules: they arrive in pieces, over years, and some are still in draft.

So a compliance stack that has to be re-engineered every time a standard lands will always be behind.

The teams that stay ahead treat regulatory change as the normal state, not the exception. That means rules you can reconfigure. Customers can change risk tiers as circumstances change. Records trace every decision cleanly – so your controls evolve without breaking the continuity.

This is the idea behind Marble: the FRAML compliance platform that adapts to your framework, not the other way around. Built to be the FRAML compliance software that allows risk teams to automate reporting without re-engineering the stack. One platform, end to end, no gaps or cracks.

What to watch before July 2027

Three things.

  1. The customer due diligence standard, once AMLA publishes the final version.
  2. The next wave of guidelines on monitoring and risk.
  3. And the countdown itself: the AMLR applies from 10 July 2027, with AMLA selecting its first directly supervised firms that year and supervision beginning in 2028.

The direction is set. The work ahead of you: making your controls ready to meet it – and to keep meeting it as the details keep arriving from AMLA’s HQ in Frankfurt.

Frequently asked questions

What is the difference between AMLA and AMLR? AMLA is the authority. The AMLR is the regulation it helps implement through technical standards.

Is AMLA the same as the US Anti-Money Laundering Act? No. AMLA here is the EU's Anti-Money Laundering Authority, the new supervisor based in Frankfurt. The US Anti-Money Laundering Act is separate legislation.

When is the EU AMLR enforcement deadline? The EU Anti-Money Laundering Regulation (AMLR) applies directly across all EU member states on 10 July 2027. Following this enforcement deadline, AMLA will select its first cohort of obligors and begin direct supervisory activities in 2028.

What did AMLA finalise in 2026? Standards for FIU cooperation and EPPO reporting, a common approach to enforcement, and supervisory cooperation – all as final drafts awaiting Commission adoption. The customer due diligence standard is still in progress.

Learn more about Marble

Watch a demo