Skip to main content
Should Your Firm Prepare for AMLA Direct Supervision?Compliance Program Governance
5 min readFor MLROs

Should Your Firm Prepare for AMLA Direct Supervision?

The European Commission's proposed Anti-Money Laundering Authority (AMLA) will fundamentally change how certain financial institutions experience AML/CFT oversight. For the first time, an EU-level supervisor will directly oversee some of the riskiest financial institutions that operate in multiple Member States or require immediate action to address imminent risks.

If your institution falls under AMLA's direct supervision, you'll answer to Brussels, not just your national authority. This shift carries operational, resource, and strategic implications you need to assess now.

The Decision You're Facing

You need to determine whether your institution is likely to fall under AMLA's direct supervision and, if so, how to prepare your compliance framework for that transition. This isn't a simple yes/no question. It's a risk assessment that should inform your 2024-2025 compliance roadmap.

The proposed legislation doesn't specify exact thresholds for direct supervision. Instead, it establishes two criteria: cross-border operational scale and immediate risk profile. Your task is to evaluate where you sit on both dimensions.

Key Factors That Affect Your Choice

Cross-border footprint: Count the number of EU member states where you hold licenses, operate branches, or provide cross-border services under passporting arrangements. AMLA will focus on institutions with significant multi-jurisdictional presence.

Risk indicators: Review your most recent SREP outcomes, any enforcement actions in the past three years, correspondent banking relationships, exposure to high-risk third countries on the Grey List or Black List, and the volume of Suspicious Activity Reports your institution files annually.

Sector classification: The proposal specifically mentions crypto-asset service providers as newly obliged entities. If you operate in this sector, expect heightened scrutiny regardless of your current size.

Existing supervisory relationship: If your national supervisor has flagged deficiencies or imposed remediation requirements, you're more visible to potential EU-level oversight.

Path A: You're Likely Subject to AMLA Direct Supervision

Choose this path if:

  • You operate licensed entities in five or more EU member states.
  • You've received formal enforcement actions from multiple national supervisors in the past 24 months.
  • You provide crypto-asset services at scale across the EU.
  • Your institution appears on national risk assessments as a higher-risk entity.

What this means for your compliance program:

You'll need to harmonize your AML/CFT controls across all EU operations to meet a single rulebook standard. If you currently maintain different Customer Due Diligence thresholds, transaction monitoring rules, or risk rating methodologies across jurisdictions, that fragmentation won't survive AMLA oversight.

Start by conducting a gap analysis between your strongest national program and your weakest. AMLA will expect consistency. Your French subsidiary's enhanced due diligence triggers should match your German operation's approach when facing comparable risk scenarios.

Budget for direct examination costs. AMLA will have the authority to issue binding decisions and impose sanctions. Your compliance budget should include line items for on-site examinations, data requests, and potential remediation orders.

Prepare for English-language examinations and reporting. While the legislation doesn't specify AMLA's working language, EU-level supervision typically operates in English. If your compliance documentation, policies, or training materials exist only in national languages, translation becomes a priority project.

Path B: You'll Remain Under National Supervision with AMLA Coordination

Choose this path if:

  • You operate primarily in one or two EU member states.
  • You maintain a clean supervisory record with no recent enforcement actions.
  • Your risk profile sits in the low-to-moderate range based on customer base, products, and geographic exposure.
  • You don't operate in the crypto sector.

What this means for your compliance program:

Your national competent authority remains your primary supervisor, but AMLA will coordinate and monitor their effectiveness. Think of this as indirect supervision. You won't report directly to AMLA, but AMLA will review how your national supervisor assesses your program.

This creates a standardization pressure. Even if AMLA doesn't examine you directly, your national supervisor will need to demonstrate they're applying the single rulebook consistently with other member states. Expect your supervisor to reference AMLA guidance, adopt AMLA-developed risk indicators, and align examination priorities with EU-wide focus areas.

Monitor AMLA's published guidance and supervisory priorities even though you're not directly supervised. When AMLA issues sector-specific guidance on transaction monitoring calibration or beneficial owner identification in complex structures, your national supervisor will likely incorporate those expectations into their next examination cycle.

Invest in systems that can adapt to the unified rulebook. The proposed regulation will harmonize requirements across the EU. If you've built compliance workflows around national regulatory quirks, you'll need flexibility to adjust as those quirks disappear.

Path C: You're Evaluating EU Market Entry

Choose this path if:

  • You're a non-EU institution planning to establish an EU presence.
  • You're a single-market operator considering expansion into additional member states.
  • You're developing crypto-asset services for EU customers.

What this means for your compliance program:

The unified rulebook dramatically changes your market entry calculus. Previously, expanding from one EU country to another meant learning a new national AML/CFT regime. Under the proposed framework, you'll build one compliance program that works across the entire EU.

This reduces complexity but raises the baseline. You can't enter through the jurisdiction with the lightest-touch supervision and then passport across borders. AMLA's coordination role means supervisory arbitrage opportunities will narrow significantly.

For crypto firms, the €10,000 cash payment limit and the prohibition on anonymous crypto-asset wallets represent hard requirements you'll need to engineer into your product design, not just your compliance overlay. Customer due diligence obligations will apply to your entire operation, not just selected services.

Summary Matrix

Factor AMLA Direct Supervision National Supervision (AMLA Coordinated) Market Entry Planning
Operational scope 5+ EU member states 1-2 EU member states Evaluating EU entry
Primary regulator AMLA National competent authority Depends on entity structure
Compliance framework Fully harmonized across EU Aligned with single rulebook Built to single rulebook from day one
Examination frequency Higher; direct AMLA oversight National supervisor schedule Depends on risk profile at launch
Key preparation step Gap analysis across jurisdictions Monitor AMLA guidance publications Design controls to unified requirements
Resource priority Harmonization projects Adaptability and monitoring Product-level compliance integration

The Commission proposed this package on 20 July for discussion by the European Parliament and Council. You won't face AMLA supervision tomorrow. But Commissioner Mairead McGuinness called this a "game changer," and she's right. The shift from coordination to direct supervision, from fragmented national rules to a single rulebook, and from partial crypto coverage to full sector inclusion represents the most significant structural change to EU AML/CFT enforcement in decades.

Start preparing now, regardless of which path you're on.

You Might Also Like