Skip to main content
AMLA Myths Compliance Teams Already BelieveInternational Bodies & Standards
5 min readFor MLROs

AMLA Myths Compliance Teams Already Believe

Since the EU decided to establish the Anti-Money Laundering Authority (AMLA), misconceptions have spread faster than the regulation itself. Some teams think they're off the hook because they're not "high-risk." Others assume AMLA is just another coordinating body with no real power.

These myths aren't harmless. They're shaping compliance roadmaps right now, and teams building on false assumptions will face costly corrections when AMLA becomes operational. Let's clear up what AMLA actually does and what it means for your program.

Myth 1: "AMLA only matters if you're one of the 40 riskiest entities"

Reality: While AMLA's direct supervision initially covers up to 40 groups and entities, its influence extends to every obliged entity in the EU financial sector.

Even if you're not selected for direct supervision, you'll still operate under national authorities who coordinate with AMLA. AMLA will maintain a central database of AML/CFT supervisory information, set standards, and conduct assessments that shape how your national supervisor evaluates your program.

For crypto-asset service providers, the stakes are higher. AMLA has direct supervisory powers over this sector regardless of the 40-entity selection. If you operate a crypto exchange or wallet provider across multiple member states, you're not just dealing with your national regulator anymore.

The selection criteria matter too. Entities with operations in at least six member states face designation as high-risk. As you expand cross-border, you move closer to direct AMLA oversight. Your compliance framework needs to scale with that reality, not scramble to catch up after designation.

Myth 2: "Non-financial sectors get a pass under AMLA"

Reality: AMLA plays a supportive role for non-financial sectors, but "supportive" doesn't mean optional.

The regulation gives AMLA authority to assess and investigate potential violations in how non-financial entities implement their AML/CFT frameworks. The Pandora Papers example highlights scrutiny on real estate transactions, legal services, accountants, and other gatekeepers of large-value transfers.

AMLA can issue recommendations to non-financial obliged entities. While not binding like direct supervisory orders, they set expectations that national authorities will enforce. If AMLA identifies a compliance gap in your sector and issues a recommendation, your national regulator will expect you to address it.

For compliance officers in non-financial firms, this means you can't rely solely on your existing relationship with national supervisors. Monitor AMLA's guidance, sector assessments, and recommendations. They'll shape enforcement priorities even if AMLA isn't your direct supervisor.

Myth 3: "AMLA is just coordinating existing supervisors"

Reality: AMLA has its own enforcement powers and leads joint supervisory teams for inspections, assessments, and investigations.

This isn't a coordinating committee. Joint teams led by AMLA will perform on-site inspections at designated high-risk entities. They'll assess your internal policies, test your transaction monitoring rules, and evaluate whether your financial sanctions controls actually work.

The distinction matters for how you prepare. When a national supervisor visits, you know their focus areas and enforcement history. AMLA joint teams bring a pan-European perspective. They'll compare your sanctions screening against practices in other member states and question why your transaction monitoring didn't catch typologies that triggered alerts at peer institutions.

Your documentation needs to withstand this cross-border scrutiny. If your risk assessment justifies lower monitoring thresholds for certain customer segments based on "local market norms," be ready to defend why those norms should override EU-wide risk indicators.

Myth 4: "Whistle-blowing provisions are just HR policy updates"

Reality: AMLA's reinforced whistle-blowing mechanism creates new reporting channels that bypass your internal process.

The regulation establishes channels for reporting breaches, with protections for whistle-blowers. AMLA will handle reports about obliged entities directly, not just funnel them back to your compliance team or national supervisor.

This changes your risk calculus. If a front-line employee spots a sanctions screening failure or suspects your SAR escalation process is suppressing filings, they now have a protected path to report it externally. You won't necessarily know a report was filed until AMLA initiates an inquiry.

The operational implication: your internal controls can't just exist on paper. Staff need to trust that internal reporting channels work, that escalations get investigated, and that compliance concerns don't get buried. If your team believes the whistle-blowing channel is safer than your internal process, you've already lost control of your compliance narrative.

Myth 5: "We'll adapt once AMLA publishes its first guidance"

Reality: AMLA's supervisory approach is already visible in the regulation's structure, and waiting means you're building on outdated assumptions.

The regulation specifies that AMLA will monitor whether obliged entities have established internal policies and procedures for executing targeted financial sanctions asset freezes. That's not a future requirement. It's telling you exactly what AMLA will examine during its first supervisory cycle.

Consider what "established internal policies and procedures" means in practice. AMLA will want to see documented workflows, staff training records, testing results, and evidence that your sanctions controls operate without delay. If you're still screening batch files overnight or relying on manual name-matching for crypto transactions, those gaps are already on AMLA's radar.

The central database AMLA will maintain creates another pressure point. Supervisory findings, enforcement actions, and compliance deficiencies will be visible across the integrated system. If AMLA identifies a control weakness at a peer institution, they'll look for the same issue in your program. Cross-border consistency becomes the standard, not national regulatory interpretation.

What to do instead

Start with your sanctions compliance framework. Map your current asset freeze procedures against the expectation that AMLA will verify they're documented, tested, and executed without delay. If you can't demonstrate automated screening with immediate alerts for designated persons and entities, that's your first gap.

Review your transaction monitoring rules for cross-border consistency. If you operate in multiple member states, can you explain why monitoring thresholds or alert logic differs by jurisdiction? AMLA joint teams will ask, and "local regulatory preference" won't satisfy them unless you can tie it to specific risk factors.

For crypto-asset service providers, assume direct AMLA supervision is coming. Your Travel Rule compliance, wallet screening, and suspicious activity detection need to meet the highest EU standard, not just your current national requirement.

Build internal reporting channels that actually work. Anonymous hotlines aren't enough. Staff need to see that escalations lead to investigations, that compliance concerns get addressed, and that raising issues doesn't derail careers. If your team doesn't trust internal processes, AMLA's whistle-blowing mechanism will become your external audit function.

Finally, monitor AMLA's governance structure as it forms. The executive board will comprise a Chair and five independent members. Their backgrounds, enforcement philosophies, and public statements will signal supervisory priorities before the first inspection. Don't wait for formal guidance to understand where AMLA will focus.

The teams that treat AMLA as a distant future concern will spend the next two years building compliance programs that don't meet the new standard. The regulation is final. The expectations are clear. Your preparation timeline starts now.

You Might Also Like