Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

AMLA Finalizes Three Standards for Private-Sector Anti-Money Laundering Controls

AMLA Finalizes Three Standards for Private-Sector Anti-Money Laundering Controls

By
Key Takeaways
  • Three Standards Finalized: AMLA has completed regulatory technical standards covering customer due diligence, business relationships and occasional transactions, and group-wide AML/CFT arrangements.
  • Customer Checks Get More Specific: The standards address what firms must collect and verify, including non-face-to-face identification and screening of politically exposed persons, their families and close associates.
  • Group Controls Come Into Focus: Minimum requirements cover governance, risk management, internal controls and secure information sharing across corporate groups.
  • Commission Adoption Comes Next: The drafts have been submitted to the European Commission and are proposed to apply six months after entering into force and publication in the EU Official Journal.
  • Football Gets a Longer Runway: The standards will apply to professional football clubs and football agents from July 10, 2029.
Deep Dive

The EU's Anti-Money Laundering Authority said on October 1 that it has finalized three sets of regulatory technical standards covering customer due diligence, the treatment of business relationships and occasional transactions, and AML/CFT arrangements across corporate groups. The final drafts have been sent to the European Commission, putting them one step closer to becoming part of the rulebook that companies and professionals subject to the EU regime will have to follow.

The standards deal with questions that tend to become difficult only when somebody has to answer them in an actual file. When does a series of transactions stop being a collection of separate events and become linked? What exactly must a firm collect and verify before it can say it knows its customer? What does an effective AML control framework mean when the information, employees and risks are spread across several companies?

Those judgments have consequences. AMLA is trying to make sure they are not answered differently simply because the firm, supervisor or customer happens to sit on the other side of an EU border.

The first standard sets out how companies and professionals should distinguish an ongoing business relationship from an occasional transaction and determine when transactions are linked. The classification matters because it affects when customer due diligence thresholds apply. What can look like a technical definition on paper can therefore decide whether additional scrutiny of a customer is required.

The second goes deeper into the due diligence itself. It specifies the information obliged entities must collect and verify and addresses proportionate measures for situations presenting lower risks. It also covers non-face-to-face verification and electronic identification, where the old assumption that knowing a customer begins with meeting one has long since ceased to fit much of modern financial activity.

Politically exposed persons remain firmly within the frame. The standard addresses screening of PEPs as well as their family members and close associates, setting common expectations around one of the areas of customer due diligence where the consequences of getting the judgment wrong can be particularly serious.

None of this is meant to turn risk-based supervision into a mechanical exercise. AMLA said the standards are intended to strengthen the prevention and detection of money laundering and terrorist financing while keeping the measures proportionate to the risks involved.

When the Customer File Becomes a Group Problem

The third standard moves from the individual relationship to the organization behind it. AMLA has set minimum requirements for group-wide AML/CFT arrangements covering governance, risk management, internal controls and secure information sharing. For a corporate group operating across jurisdictions, that last point is not administrative housekeeping. A control can exist perfectly well on an organizational chart and still fail if the people responsible for acting on risk cannot obtain the information held elsewhere in the group.

The standard is meant to establish a common baseline for those arrangements. Taken with the other two, it gives both obliged entities and their supervisors a more precise view of how the EU’s new AML/CFT requirements are expected to work in practice.

AMLA did not write the standards alone. They were developed in cooperation with national supervisors and informed by written consultations and hearings involving a broad range of stakeholders. That process has now reached the point where the authority’s drafting work gives way to the European Commission.

The Commission must adopt the final draft standards before they can take effect. Once adopted and published in the Official Journal of the European Union, AMLA has proposed that they apply six months after their entry into force.

There is also a separate timetable for professional football. Football agents and professional football clubs will become subject to the standards from July 10, 2029.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong