Answers to the questions practitioners most commonly ask about 4AMLD.
Does the Fourth Anti-Money Laundering Directive apply directly to obliged entities across the EU?
No. As a directive, 4AMLD is not directly applicable in the same way as a regulation. It sets out requirements that EU Member States were obliged to transpose into their own national laws within the applicable implementation period. This means obliged entities are generally bound by the national transposing legislation in their jurisdiction rather than by the directive text itself. Because Member States retained discretion over certain elements and could impose stricter measures, the precise obligations, thresholds, and definitions can differ from one Member State to another. Practitioners should always confirm the requirements against the applicable national law rather than assuming a single uniform EU-wide rule flows directly from 4AMLD.
Did 4AMLD create fully public, open-access beneficial ownership registers accessible to anyone?
Not as originally framed. 4AMLD introduced requirements for Member States to hold beneficial ownership information on corporate and other legal entities in central registers, but the access regime it set out was more restricted than a fully public model. Access under 4AMLD was generally structured around competent authorities and financial intelligence units, obliged entities conducting customer due diligence, and, in some cases, persons who could demonstrate a legitimate interest. Broader public access provisions were associated with subsequent amendments rather than 4AMLD as originally adopted, and the access landscape has since been affected by further legal developments. The exact scope of register access should be confirmed against the applicable national implementation and later amending instruments.
How does 4AMLD's risk-based approach affect how an obliged entity structures its AML programme?
4AMLD reinforced a risk-based approach as a central organising principle, which generally requires obliged entities to identify, assess, and understand the money laundering and terrorist financing risks they face and to calibrate their controls accordingly. In practice, this typically means conducting and documenting a business-wide risk assessment, applying customer due diligence measures proportionate to the assessed risk, and being able to demonstrate to supervisors how control decisions were reached. The risk-based approach allows for simplified measures in lower-risk situations and enhanced measures in higher-risk ones, but it does not remove baseline obligations, and firms should confirm the specific documentation and assessment requirements under their applicable national law.
What changed for enhanced due diligence on politically exposed persons under 4AMLD?
4AMLD is generally understood to have broadened the treatment of politically exposed persons compared with earlier frameworks, including extending relevant scrutiny beyond a strict foreign/domestic distinction that had characterised some prior approaches. Operationally, this typically means obliged entities are expected to have risk-based systems to determine whether a customer or beneficial owner is a PEP, a family member, or a known close associate, and to apply enhanced due diligence measures where relevant. PEP status is a risk indicator triggering heightened scrutiny, not a determination of wrongdoing. The precise definitions, categories, and required measures depend on the applicable national transposition and any supervisory guidance.
What should an obliged entity do about the risk assessment obligations introduced under 4AMLD?
Under frameworks transposing 4AMLD, obliged entities generally need to maintain a documented business-wide risk assessment that considers relevant risk factors such as customers, products and services, delivery channels, and geographic exposure, and to keep it appropriately up to date. This firm-level assessment typically sits alongside supranational and national risk assessments that inform the broader picture. In practical terms, the assessment should be evidenced, approved through appropriate governance, and used to justify the policies, controls, and procedures the firm applies. Because Member States could specify particular requirements, the exact format, frequency, and evidentiary expectations should be confirmed against the applicable national rules and supervisory expectations.
How should firms handle the interaction between 4AMLD and later amendments when designing controls?
4AMLD has been amended and supplemented by subsequent instruments, so firms should not treat the original directive as a standalone or static reference point. In practice, controls should generally be built against the current consolidated national law, taking into account changes introduced by later directives and any relevant regulatory developments in the applicable jurisdiction. This is particularly important for areas such as beneficial ownership register access and the treatment of higher-risk factors, where the position evolved after 4AMLD's original adoption. Compliance teams should confirm which provisions remain in force, which have been modified, and how their national supervisor expects the combined requirements to be applied.