EU AMLA’s final RTS: what changes for screening, due diligence, and transaction monitoring

Arnaud Schwartz
CEO and Co-Founder
0 minutes reading
October 6, 2026
Summary

EU AMLA’s final RTS: what changes for screening, due diligence, and transaction monitoring

On 1 October 2026, the EU Anti-Money Laundering Authority (AMLA) published the AMLA final RTS. These are the three regulatory technical standards that turn the EU Anti-Money Laundering Regulation (AMLR) into precise, day-to-day requirements for the private sector, banks and FinTechs.

They cover three areas.

  1. Customer due diligence (CDD), including sanctions and politically exposed person (PEP) screening.
  2. The line between business relationships, occasional transactions, and linked transactions.
  3. Group-wide controls.

They apply to every obliged entity: banks, payment and e-money institutions, crypto-asset service providers (CASPs under MiCA), and many non-financial firms.

Once in force, you have six months to apply them. Here is what each standard says.

Key takeaways: AMLA final RTS at a glance

  • Scope: covers Customer due diligence (CDD), linked transactions, and group-wide AML controls
  • Entities affected: banks, e-money institutions, CASPs, and non-financial obliged entities across the EU
  • Timeline: applies 6 months after entry into force (20 days post-Official Journal publication)
  • Screening rules: sanctions/PEP screening requires original/transliterated names, aliases, and digital wallet addresses

Who is EU AMLA? AMLA is the EU’s anti-money laundering authority, based in Frankfurt. It writes the detailed standards that make the AMLR apply the same way in every member state. For the bigger picture, read our overview of AMLA in 2026.

What AMLA published on 1 October 2026

AMLA finalized three standards and sent them to the European Commission for adoption.

The three AMLA final RTS
Standard AMLR mandate What it settles
RTS on customer due diligence Article 28(1) The information to collect and verify for standard, simplified, and enhanced due diligence – including sanctions and PEP screening
RTS on business relationships, occasional and linked transactions Article 19(9) When a customer engagement is a business relationship, and when separate transactions count as linked
RTS on group-wide requirements Articles 16(4) and 17(3) Minimum group policies, information sharing within groups, and the steps to take when a third country’s law blocks compliance

The standards build on earlier work by the European Banking Authority (EBA). AMLA then ran its own public consultations. The CDD consultation, open from 9 February to 8 May 2026, drew 325 responses. A public hearing on 24 March 2026 brought together more than 1,600 stakeholders. The group-wide consultation ran from 16 April to 15 June 2026.

AMLA’s stated aim throughout was proportionality, a risk-based approach, and simplification wherever the AMLR allows it.

Customer due diligence: what data the RTS require

The CDD standard specifies what you collect, how you verify it, and when you can do less.

Identifying customers and beneficial owners

  • Names: all first names and surnames as they appear on the identity document, passport, or electronic identification
  • Place of birth: at least the country and the city, municipality, town, or village
  • Nationality: take reasonable measures to identify every nationality held, but verifying one is enough
  • Legal entities: the legal name and, where different, the trade name
  • Addresses: country and city are mandatory, with street, postal code, and building number where they exist

Where no beneficial owner can be identified and you record senior managing officials instead, the entity’s registered office address replaces their home address.

Simplified due diligence for low-risk customers

In low-risk situations, you collect and verify a reduced set of data. For individuals, that means names, date and place of birth, and nationality – no address required. You can identify the beneficial owner from the central register, a company register, the customer, or a reliable open source. The central register alone, however, is not enough to verify it.

Remote and electronic identification

Where a customer cannot present identity documents in person and has no access to electronic identification, you can use alternative verification methods – provided they rely on reliable and independent sources and include the safeguards set out in the standard. The aim here is financial inclusion.

Electronic identification means, including European Digital Identity Wallets, must be able to provide the minimum attributes listed in Annex I of the standard.

Purpose of the relationship and source of funds

The standard lists the information that helps you understand the purpose and intended nature of a relationship: expected activity and volumes, source and destination of funds, and the customer’s occupation or business. AMLA is explicit that this is not a checklist. Apply it in proportion to the risk, and use what you already hold – including information from other entities in your group.

For enhanced due diligence, the standard lists the evidence that can establish source of funds and wealth, from tax documents and audited accounts to property registers and reputable commercial data providers.

Sanctions and PEP screening under the final RTS

The CDD standard sets clear expectations for sanctions screening and PEP checks.

What you screen: customers, beneficial owners, and the persons or entities that control them. You must use at least:

  • all names of individuals in their original alphabet and/or transliterated into the Latin alphabet
  • legal names of companies, plus trade names where they differ
  • other names, aliases, and digital wallet addresses, where available and included in sanctions lists

When you screen: at least

  • when you enter a business relationship or carry out an occasional transaction
  • when a targeted financial sanctions (TFS) list changes
  • when a customer’s due diligence data changes, such as name, residence, nationality, business, or beneficial owner
  • on a regular basis, at a frequency that matches your exposure to sanctions risk

Screening and verification must happen without undue delay once UN sanctions are made public and once updated sanctions apply.

How you screen: automated tools, manual checks, or a combination. The choice is yours, as long as it fits the nature, size, complexity, and risks of your business and the arrangement is effective.

PEP checks: determine PEP status before onboarding. Then, re-check existing customers at a risk-based frequency – and without delay when new information comes in or when the official list of prominent public functions is updated.

Linked transactions and business relationships: what changes for transaction monitoring

The second standard settles a question at the very start of the AML framework: is this customer in a business relationship, or making an occasional transaction? The answer decides whether CDD and ongoing monitoring apply.

Business relationship or occasional transaction?

The two are mutually exclusive.

Every obliged entity must at least consider whether the customer has ongoing access to its services. That, together with the AMLR’s tests of repetition and duration, points to a business relationship. This brings full CDD and ongoing monitoring.

Occasional transactions require CDD at or above the relevant threshold, usually €10,000. Below it, CDD applies only in the cases listed in Article 19 of the AMLR.

The signals that link transactions

Linked transactions are combined to test the threshold – so splitting a payment no longer slips under it. The standard asks for an overall assessment of all facts, with no single criterion decisive. It lists the signals to take into account:

  • transactions performed or received by the same person
  • customers who are family members, business partners, or operating in concert
  • customers who are subsidiaries or beneficial owners of the same parent undertaking
  • use of the same digital infrastructure, such as an IP address, device identifier, or geolocation
  • use of common intermediaries or service providers
  • transactions relating to the same purchase, such as one invoice or booking
  • transactions within a loyalty programme
  • transactions with the same origin and destination spread across branches, agents, or channels
  • transactions that depend on the completion of an earlier one
  • transactions within a short time frame, defined by how fast your business typically operates

Some criteria apply only where you already have the information. You are not required to collect new data solely to identify linked transactions.

Sector-specific rules

For currency exchange offices, money remitters, and crypto-asset service providers, the standard adds two concrete markers:

  • three or more transactions within 12 months indicate repetition, and therefore a business relationship
  • one month is the period to consider when identifying linked transactions

Thresholds stay where they are

AMLA introduced no new lower CDD thresholds. It found no conclusive evidence that they were needed. The thresholds already set in the AMLR remain unchanged.

Is your transaction monitoring engine ready for dynamic linked-transaction rules?
Explore how Marble automates rule changes without coding →

Group-wide AML requirements and third-country impediments

The third standard sets the minimum framework for groups – and extends it to some structures that are not groups at all.

The group framework: the parent undertaking in the EU must maintain a group-wide AML and counter-terrorist financing framework, proportionate to the group’s size, complexity, and risk. At minimum, it covers:

  • governance and compliance oversight with clear responsibilities
  • a group-wide risk assessment covering all entities, activities, and jurisdictions
  • policies and procedures applied consistently across the group
  • information-sharing arrangements
  • staff training and reporting mechanisms
  • processes to identify and fix compliance weaknesses

Information sharing: group entities exchange the information needed to manage money laundering, terrorist financing, and sanctions risks – customer and beneficial ownership data, CDD information, transactions, and risk findings. Every exchange must follow a need-to-know principle, comply with data protection rules, run through secure channels, and be documented.

The EU parent undertaking: where two or more EU entities share a head office outside the EU, without a parent-subsidiary link, one of them must be identified as the EU parent undertaking and notify its supervisor. The factors include EU presence, customer base, decision-making powers, and AML resources.

Networks, partnerships, and franchises: structures with common ownership, management, or compliance control now fall within scope. They must identify a head of the structure in the EU, or obtain a supervisor’s permission not to, under five conditions. First notifications to supervisors are due no later than six months after the standard applies.

Third-country impediments: where a third country’s law prevents a branch or subsidiary from complying with the AMLR, the group must notify the supervisor, seek customer consent where possible, and apply additional measures (such as enhanced monitoring, senior management approval, or limiting activity to lower-risk products). If risks remain, supervisors can require a risk mitigation plan and, ultimately, an end to new relationships or the closure of operations in that country.

What changed since the consultations

The final texts are leaner than the consultation drafts:

  • the third-country section was cut from seven articles to three (it dropped the list of specific impediments and their prescriptive measures)
  • several definitions were removed as unnecessary
  • the categories of information to share within a group moved to an annex
  • AMLA found no room to simplify simplified due diligence further without creating exemptions from the AMLR, which would exceed its mandate
  • no additional lower CDD thresholds were introduced

When do the AMLA final RTS apply?

The European Commission now adopts the standards as delegated regulations. Then the clock starts:

  • Entry into force: 20 days after publication in the Official Journal of the EU (OJEU)
  • Application: six months after entry into force
  • Football agents and professional football clubs: 10 July 2029
  • Existing customers: brought into line on a risk-sensitive basis – within one year for higher-risk customers and within five years for all others, as set out in the AMLR

Until the Commission adopts and publishes them, the texts can still change.

What this means for your screening and monitoring setup

Six months is short for system changes. Four places to start:

  • Map your CDD data model
    against the required data points and Annex I – names, place of birth, nationalities, address fields, trade names
  • Widen your screening inputs and triggers
    Original-alphabet names and transliterations, aliases, wallet addresses, and rescreening on every list update and every change in customer data
  • Turn the linked-transaction signals into detection rules
    Shared devices and IP addresses, customers acting in concert, same-purchase payments, and time windows sized to your own transaction speeds
  • Trace your group data flows
    Need-to-know access, secure channels, and a documented record of every exchange

This is where a rigid tool shows its cracks.

When the rules are set by the regulator but the thresholds and time windows are yours to define, your monitoring needs to adapt to your framework – not the other way around. Marble lets compliance teams build and adjust transaction monitoring rules and real-time sanctions screening themselves, without waiting on engineering.

What happens next

The Commission adopts the three standards, then publishes them in the Official Journal.

More AMLA standards and guidelines are still on the way, all feeding into the EU AMLR, which applies from 10 July 2027.

To check where your program stands today, use our AMLR checklist for banks and our guide to customer risk assessment.

Your rules. Your thresholds. Your timeline. Talk to an expert about adapting your screening and monitoring to the AMLA final RTS.

Frequently asked questions

What are the AMLA final RTS?

They are three regulatory technical standards that AMLA finalized on 1 October 2026 under the EU AMLR. They cover customer due diligence and sanctions screening, the criteria for business relationships and linked transactions, and group-wide AML requirements.

When do the AMLA RTS apply?

Six months after they enter into force. Entry into force follows 20 days after publication in the Official Journal of the EU, once the European Commission adopts them. Football agents and professional clubs apply them from 10 July 2029.

What are linked transactions under the AMLR?

Two or more transactions with an identical or similar origin, destination, and purpose, or other relevant shared characteristics, over a specific period. The RTS list the signals to assess, including the same customer, customers acting in concert, the same device or IP address, and the same purchase.

Do the AMLA RTS require automated sanctions screening?

No. Screening can be automated, manual, or a combination. The approach must be effective and proportionate to the nature, size, complexity, and risks of your business.

Did AMLA introduce new CDD thresholds?

No. AMLA found no conclusive evidence that additional lower thresholds were needed. The general threshold for occasional transactions remains €10,000, and the AMLR’s existing lower thresholds remain in place.

What happens to existing customers?

Their data must be brought into line on a risk-sensitive basis: within one year for higher-risk customers and within five years for all others.

Sources: AMLA press release, 1 October 2026 · Final Report – draft RTS under Article 28(1) AMLR · Final Report – draft RTS under Article 19(9) AMLR · Final Report – draft RTS under Articles 16(4) and 17(3) AMLR

This article summarizes AMLA’s final draft standards as published on 1 October 2026. They remain subject to review by the European Commission and become definitive only once published in the Official Journal of the EU.

‍

Learn more about Marble

Watch a demo