The Anti-Money Laundering Authority (AMLA) isn't waiting for you to be ready. Its first Regulatory Technical Standards (RTSs) landed in early 2026, rules apply from July 2027, and direct supervision starts in 2028. That timeline feels distant until you realize you're already behind if you haven't started mapping gaps.
I've watched compliance teams across the EU respond to AMLA's emergence, and I'm seeing the same missteps repeat. These aren't minor oversights. They're structural errors that will cost you months of rework, create compliance gaps during transition, and leave you exposed when AMLA's enforcement machinery spins up.
Why These Mistakes Keep Happening
AMLA represents something genuinely new: a single rulebook spanning 27 jurisdictions, covering everything from single-person notaries to crypto exchanges. Its goal of harmonization must somehow accommodate jurisdictional nuance. That tension creates ambiguity, and ambiguity breeds mistakes.
Most teams are treating AMLA like just another regulatory update. It's not. It's a fundamental restructuring of how AML/CTF supervision works in Europe. The teams getting this right are the ones treating it like a multi-year operational transformation, not a compliance project.
Mistake 1: Waiting for Final Rules Before Starting Gap Analysis
Why it happens: Your team reasons that analyzing draft standards is wasted effort if the final version changes. Better to wait for certainty.
The real consequence: The RTSs on Customer Due Diligence and Business Relationships are already in consultation. Core requirements are locked in by the EU Commission's regulations, which AMLA cannot change through consultation. If you're waiting for July 2026 approval to start your gap analysis, you'll have 12 months to remediate everything before rules apply in July 2027. That's not enough time for most institutions.
The fix: Start your gap analysis now against the draft RTSs. Flag items that are set in Commission regulations separately from those that might shift during consultation. Build two remediation tracks: one for certainties (begin immediately) and one for probables (prepare to execute). You can adjust the probable track if consultation feedback changes something material. You cannot buy back the months you lose by waiting.
Mistake 2: Assuming Perpetual KYC Satisfies Periodic Review Requirements
Why it happens: Your institution runs ongoing due diligence with continuous monitoring. When a risk trigger fires, you review the customer. You've moved past the old calendar-based refresh model. Surely AMLA's mandatory periodic reviews (one, three, or five years depending on risk rating) are redundant.
The real consequence: AMLA's draft standards require periodic reviews at defined intervals regardless of whether your monitoring system flagged anything. This isn't about whether you're watching the customer. It's about documenting a structured review at prescribed times. If you don't have a process that explicitly satisfies the periodic review requirement, you're non-compliant even if your ongoing monitoring is excellent.
The fix: Layer periodic reviews on top of your perpetual KYC program. Configure your system to trigger a formal review workflow at the appropriate interval (one, three, or five years based on customer risk rating). That workflow should document that you examined the customer relationship, confirmed risk factors, and found no material changes. If your monitoring already caught something, the periodic review documents that fact. If nothing triggered, the periodic review creates the required audit trail showing you looked and found nothing. Yes, it's duplicative. No, you don't have a choice.
Mistake 3: Treating Country-of-Birth and City-of-Birth as Minor Data Points
Why it happens: These fields seem like demographic trivia. You've never collected them before. Surely you can add them to your onboarding form and move on.
The real consequence: For many customers, especially those onboarded years ago, you don't have this information. Obtaining it requires re-contacting customers and requesting additional documentation. That's friction. It's also a Customer Due Diligence gap that needs remediation before July 2027. If you're one of the 40 institutions AMLA selects for direct supervision (announced in 2027), you'll be explaining your remediation plan and timeline in your first supervisory engagement.
The fix: Inventory your customer base by onboarding date and available data. Segment customers by risk rating. Start with high-risk customers and work backward. For new customers, update your onboarding flows to collect country-of-birth and city-of-birth with clear instructions on acceptable documentation. For existing customers, design a phased outreach campaign tied to periodic reviews or relationship events (renewals, product additions). Don't try to remediate your entire book at once. AMLA has acknowledged that risk-based prioritization is acceptable during transition.
Mistake 4: Assuming Harmonization Means Simplification
Why it happens: AMLA's mandate is to create a single rulebook. Your team interprets this as regulatory streamlining. Finally, one set of rules instead of 27.
The real consequence: Harmonization means one rulebook that must work for notaries, football clubs, crypto exchanges, and multinational banks across 27 jurisdictions. That forces high-level language to maintain applicability. High-level language creates interpretive ambiguity. You'll see divergence in how national regulators apply the rules, how AMLA interprets edge cases, and how your peers implement requirements. This is more complex than what you have now, not less.
The fix: Build flexibility into your compliance framework. Where AMLA's RTSs use broad language, document your interpretation and the rationale behind it. Participate in industry working groups to understand how peers are reading ambiguous provisions. When AMLA issues guidance (they've indicated guidance will add nuance where the rules stay simple), update your procedures immediately. Don't assume your current controls map cleanly to AMLA's requirements just because the words sound similar.
Mistake 5: Ignoring AMLA If You're Not One of the 40
Why it happens: AMLA will directly supervise 40 of the largest and riskiest institutions starting in 2028. If you're not in that cohort, your national regulator remains your supervisor. Why prepare for AMLA?
The real consequence: AMLA supervises national regulators and their application of the single rulebook. It can look deeper into entities beyond the 40 in higher-risk circumstances. And every institution, regardless of who supervises it, must comply with AMLA's RTSs starting July 2027. Your national regulator will be applying AMLA's standards, not their old ones. If anything, expect national regulators to be more stringent as they demonstrate to AMLA that they're enforcing the new framework rigorously.
The fix: Prepare for AMLA's requirements regardless of your supervisory status. The RTSs apply to you. The periodic review mandates apply to you. The Customer Due Diligence standards apply to you. The only difference is who shows up for your examination. The rules you must follow are identical.
Mistake 6: Underestimating the Enforcement Shift
Why it happens: The EU has historically been less aggressive than the US in AML enforcement. Your institution has focused compliance investment on satisfying US regulators. AMLA feels like a European problem that won't have teeth for years.
The real consequence: EU enforcement activity increased 776% in 2025 compared to 2024 (when including ongoing regulatory investigations). Direct supervision by AMLA starts in 2028. By late 2029, expect the first enforcement actions. AMLA needs to establish credibility. Early enforcement targets will be institutions with visible gaps in the new framework. If you're one of the 40 directly supervised entities and you're not ready, you're exposed.
The fix: Treat AMLA as a Tier 1 regulatory risk starting now. Allocate budget, assign senior ownership, and build a multi-year roadmap. If you're likely to be in the 40 (large, cross-border, higher-risk business lines), assume you will be and plan accordingly. Even if you're not, assume your national regulator will be under pressure to demonstrate strong enforcement of AMLA's standards. The enforcement landscape is shifting. Your risk assessment should shift with it.
Prevention Checklist
- Gap analysis started against draft RTSs (separate certainties from probables)
- Periodic review process layered on top of ongoing monitoring
- Country-of-birth and city-of-birth collection added to onboarding workflows
- Remediation plan for existing customers prioritized by risk rating
- Interpretation documentation for ambiguous RTS provisions
- Industry working group participation to track peer approaches
- Budget and senior ownership assigned for AMLA readiness (not treated as a project)
- Enforcement risk assessment updated to reflect EU enforcement trends
- Monitoring configured for AMLA guidance releases and RTS updates
- National regulator engagement plan (even if not in the 40)
The institutions that navigate AMLA successfully won't be the ones with the most resources. They'll be the ones that started earliest, planned for ambiguity, and treated this as the operational transformation it actually is. The window for early action is closing. Use it.



