The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), the EU's new AML/CFT supervisor based in Frankfurt, is working through roughly a dozen Level 2 and Level 3 technical measures mandated by the Anti-Money Laundering Regulation (AMLR) and related legislation. AMLA's own regulatory-instruments tracker, last updated 3 June 2026, shows the real state of play: two measures — the Regulatory Technical Standards (RTS) on the inherent and residual risk profile of obliged entities, and the RTS on the risk assessment used to select firms for direct AMLA supervision — have final reports published. Everything else is still moving.
The three in-motion measures that matter most for compliance planning right now.
The draft RTS on customer due diligence (CDD), issued under Article 28(1) of the AMLR, is the instrument that will specify exactly what information and documents firms must collect to meet CDD obligations. Its public consultation closed on 8 May 2026; AMLA is now finalising the text — built on a version the European Banking Authority (EBA) originally drafted in October 2025 — before submitting it to the European Commission for formal adoption. No final text exists yet, but this is the closest of the three to completion.
The draft Guidelines on Business-Wide Risk Assessment (BWRA), issued under Article 10(4), set out four minimum requirements obliged entities must meet when assessing their own enterprise-level ML/TF risk, plus additional information sources beyond those already listed in Article 10(1) of the AMLR. This consultation opened 16 April and closed 15 July 2026. Final guidance is expected in the fourth quarter of 2026.
The draft Guidelines on ongoing monitoring of a business relationship, issued under Article 26(5), are the instruments that will actually govern transaction and activity monitoring — arguably the highest-stakes text of the three for day-to-day compliance operations. This consultation opened only on 3 June and runs until 3 September 2026, following a public hearing held on 2 July. Nothing here will be finalised before autumn at the earliest.
Several other measures — RTS on group-wide minimum requirements for third-country subsidiaries and branches, RTS on identifying business relationships and linked transactions, RTS on pecuniary sanctions, and technical standards on FIU-to-FIU and FIU-to-EPPO information exchange — have closed consultations but no final report yet, putting them in a similar holding pattern to the CDD RTS.
Why 10 July mattered less than many expected
Referenced repeatedly across the legislation, 10 July 2026 proved to be more significant as a legislative milestone than an operational one. The AMLR identifies the date as the target for AMLA to deliver much of its Level 2 and Level 3 rulemaking. In practice, the work has continued on a rolling basis. Some technical standards may have reached final-report stage ahead of the deadline, but many of the measures firms are waiting on remain at different points in the consultation and adoption process.
AMLA's own tracker illustrates the difference. The CDD RTS has progressed beyond consultation and into finalisation. The BWRA guidelines moved through consultation in July, with final guidance expected later in the year. The ongoing-monitoring guidelines remain further behind, with consultation running until September before any final text can be prepared.
The result is a timetable considerably more staggered than the legislation alone might suggest. Rather than marking a single point at which firms could begin implementation, 10 July sits within a longer programme of rulemaking that extends well beyond the date itself. For compliance teams, that distinction is more than procedural: planning against the maturity of each individual instrument is likely to produce better outcomes than treating the legislative timetable as though every measure progresses at the same pace.
For compliance leaders
The practical question is less when AMLA reaches a legislative milestone than which measures are sufficiently developed to begin implementing.
The CDD RTS has progressed far enough that firms can start reviewing internal procedures against the EBA's October 2025 draft, recognising that some adjustments may be needed once AMLA's final version is adopted. Waiting for the final text before beginning any planning is unlikely to be the most efficient approach.
The BWRA guidelines sit in a different position. Because the four minimum requirements are unlikely to change substantially between draft and final, they are worth reading now — though formal sign-off should wait for the Q4 text.
The ongoing-monitoring guidelines are the one area where building anything concrete right now would be premature. Firms with live transaction-monitoring programmes should treat the current draft only as a directional signal — the "keeping customer information up to date" and "transaction and activity monitoring framework" split it proposes — rather than a specification to implement against.
Reference:
AMLA Regulatory Instruments tracker (last updated 3 June 2026) — https://www.amla.europa.eu/policy/regulatory-instruments_en
Consultation on draft Guidelines on business-wide risk assessment (Article 10(4)) — https://www.amla.europa.eu/policy/public-consultations/consultation-draft-guidelines-business-wide-risk-assessment_en
Consultation on draft Guidelines on ongoing monitoring of a business relationship (Article 26(5)) — https://www.amla.europa.eu/policy/public-consultations/consultation-draft-guidelines-ongoing-monitoring-business-relationship_en ·
Consultation on draft RTS on Customer Due Diligence (Article 28(1)) — https://www.amla.europa.eu/policy/public-consultations/consultation-draft-rts-customer-due-diligence_en