Skip to main content
Category: Laws and Regulations

Fourth Anti-Money Laundering Directive

Also known as: 4AMLD, Fourth Money Laundering Directive, MLD4, Directive (EU) 2015/849
Simply put

The Fourth Anti-Money Laundering Directive is a European Union law aimed at strengthening the EU's defences against money laundering and terrorist financing. It updated and improved earlier EU rules and placed greater emphasis on making it clearer who really owns and controls companies. Its broad goal was to reduce the ability of money launderers and terrorist financiers to misuse the EU financial system.

Formal definition

The Fourth Anti-Money Laundering Directive (Directive (EU) 2015/849), commonly cited as 4AMLD or MLD4, is an EU instrument designed to strengthen the Union's framework against money laundering and terrorist financing. It amends and builds upon the provisions of the Third Anti-Money Laundering Directive (3AMLD), and places increased emphasis on beneficial ownership transparency for firms. As an EU directive, it sets objectives that member states are required to transpose into national law, meaning the precise implementing requirements, thresholds, and scope of obliged entities may differ across jurisdictions and should be confirmed against the applicable national transposition. Money laundering and terrorist financing are treated as distinct risks addressed by the Directive, and its provisions should not be read as establishing a single uniform rule directly applicable in each member state.

Why it matters

The Fourth Anti-Money Laundering Directive represents a significant step in the evolution of the EU's framework for countering money laundering and terrorist financing. By amending and building upon the Third Anti-Money Laundering Directive (3AMLD), it reflects the Union's ongoing effort to close gaps that criminals and those financing terrorism may seek to exploit within the EU financial system. Its heightened emphasis on beneficial ownership transparency is particularly consequential, as opaque corporate ownership structures have long been recognised as a vulnerability that can obscure who ultimately owns and controls legal entities.

Who it's relevant to

Compliance Officers at Obliged Entities
Compliance officers responsible for AML/CFT programmes need to understand how 4AMLD's objectives were transposed in the jurisdictions where their firm operates. Because implementing requirements and the scope of obliged entities may differ by member state, they should confirm the precise obligations, thresholds, and beneficial ownership requirements against the applicable national law rather than assuming a single EU-wide standard.
Beneficial Ownership and KYC Teams
Teams that identify and verify who ultimately owns and controls corporate customers are directly affected by 4AMLD's increased emphasis on beneficial ownership transparency. This focus supports efforts to see beyond legal ownership to the natural persons who exercise ultimate control, though the specific verification requirements depend on national transposition.
Legal and Regulatory Advisers
Lawyers and regulatory specialists advising firms on cross-border operations must account for the fact that 4AMLD is a directive requiring transposition, meaning obligations can diverge between member states. They play a key role in mapping how Directive (EU) 2015/849 has been implemented in each relevant jurisdiction.
Financial Intelligence and Investigations Professionals
Analysts and investigators benefit from the greater ownership transparency that 4AMLD seeks to promote, as clearer information about who owns and controls firms can support the identification of misuse of the EU financial system. Such information should be treated as an input to analysis, not as evidence of wrongdoing in itself.

Inside 4AMLD

Risk-Based Approach
4AMLD reinforced the requirement for obliged entities and Member States to identify, assess, and understand the money laundering and terrorist financing risks they face, and to apply mitigating measures proportionate to those risks. This includes obligations for supranational, national, and business-level risk assessments. The approach is a framework for allocating resources and calibrating controls, not a guarantee that risk is eliminated.
Beneficial Ownership Registers
The Directive introduced requirements for Member States to hold information on the beneficial ownership of corporate and other legal entities, as well as trusts, in central registers. Beneficial ownership refers to the natural person(s) who ultimately own or control an entity, which is a distinct concept from legal ownership. Implementation details, access rights, and register design varied across Member States as they transposed the Directive into national law.
Customer Due Diligence (CDD)
4AMLD set out CDD obligations, including identifying and verifying customer identity and, where applicable, beneficial owners, understanding the purpose and intended nature of the business relationship, and conducting ongoing monitoring. CDD is broader than the initial identity-gathering step often referred to as KYC and sits alongside enhanced due diligence (EDD) for higher-risk situations.
Politically Exposed Persons (PEPs)
The Directive extended enhanced scrutiny of PEPs and required enhanced due diligence measures where a customer or beneficial owner is identified as a PEP. Notably, 4AMLD's treatment addressed domestic PEPs as well as foreign PEPs. PEP screening is distinct from sanctions screening, which addresses a different category of designated persons and legal consequences.
Enhanced and Simplified Due Diligence
4AMLD moved away from certain automatic exemptions, requiring that simplified due diligence be justified by a demonstrated lower risk rather than applied by default, and requiring enhanced due diligence in higher-risk scenarios. This shift reflects the Directive's overall emphasis on the risk-based approach.
Scope of Obliged Entities
The Directive applied to a defined range of obliged entities, and its scope was broadened in certain respects, including in relation to the gambling sector and cash transaction thresholds for traders in goods. Exact scope and thresholds were subject to transposition by each Member State, and specific values should be confirmed against the applicable national law.
Sanctions and Administrative Measures
4AMLD established a framework for administrative sanctions and measures that Member States were to make available for breaches of AML/CFT obligations, with the aim of ensuring more consistent and dissuasive enforcement across the EU. The precise sanctioning regime depends on national transposition.

Common questions

Answers to the questions practitioners most commonly ask about 4AMLD.

Does the Fourth Anti-Money Laundering Directive apply directly to obliged entities across the EU?
No. As a directive, 4AMLD is not directly applicable in the same way as a regulation. It sets out requirements that EU Member States were obliged to transpose into their own national laws within the applicable implementation period. This means obliged entities are generally bound by the national transposing legislation in their jurisdiction rather than by the directive text itself. Because Member States retained discretion over certain elements and could impose stricter measures, the precise obligations, thresholds, and definitions can differ from one Member State to another. Practitioners should always confirm the requirements against the applicable national law rather than assuming a single uniform EU-wide rule flows directly from 4AMLD.
Did 4AMLD create fully public, open-access beneficial ownership registers accessible to anyone?
Not as originally framed. 4AMLD introduced requirements for Member States to hold beneficial ownership information on corporate and other legal entities in central registers, but the access regime it set out was more restricted than a fully public model. Access under 4AMLD was generally structured around competent authorities and financial intelligence units, obliged entities conducting customer due diligence, and, in some cases, persons who could demonstrate a legitimate interest. Broader public access provisions were associated with subsequent amendments rather than 4AMLD as originally adopted, and the access landscape has since been affected by further legal developments. The exact scope of register access should be confirmed against the applicable national implementation and later amending instruments.
How does 4AMLD's risk-based approach affect how an obliged entity structures its AML programme?
4AMLD reinforced a risk-based approach as a central organising principle, which generally requires obliged entities to identify, assess, and understand the money laundering and terrorist financing risks they face and to calibrate their controls accordingly. In practice, this typically means conducting and documenting a business-wide risk assessment, applying customer due diligence measures proportionate to the assessed risk, and being able to demonstrate to supervisors how control decisions were reached. The risk-based approach allows for simplified measures in lower-risk situations and enhanced measures in higher-risk ones, but it does not remove baseline obligations, and firms should confirm the specific documentation and assessment requirements under their applicable national law.
What changed for enhanced due diligence on politically exposed persons under 4AMLD?
4AMLD is generally understood to have broadened the treatment of politically exposed persons compared with earlier frameworks, including extending relevant scrutiny beyond a strict foreign/domestic distinction that had characterised some prior approaches. Operationally, this typically means obliged entities are expected to have risk-based systems to determine whether a customer or beneficial owner is a PEP, a family member, or a known close associate, and to apply enhanced due diligence measures where relevant. PEP status is a risk indicator triggering heightened scrutiny, not a determination of wrongdoing. The precise definitions, categories, and required measures depend on the applicable national transposition and any supervisory guidance.
What should an obliged entity do about the risk assessment obligations introduced under 4AMLD?
Under frameworks transposing 4AMLD, obliged entities generally need to maintain a documented business-wide risk assessment that considers relevant risk factors such as customers, products and services, delivery channels, and geographic exposure, and to keep it appropriately up to date. This firm-level assessment typically sits alongside supranational and national risk assessments that inform the broader picture. In practical terms, the assessment should be evidenced, approved through appropriate governance, and used to justify the policies, controls, and procedures the firm applies. Because Member States could specify particular requirements, the exact format, frequency, and evidentiary expectations should be confirmed against the applicable national rules and supervisory expectations.
How should firms handle the interaction between 4AMLD and later amendments when designing controls?
4AMLD has been amended and supplemented by subsequent instruments, so firms should not treat the original directive as a standalone or static reference point. In practice, controls should generally be built against the current consolidated national law, taking into account changes introduced by later directives and any relevant regulatory developments in the applicable jurisdiction. This is particularly important for areas such as beneficial ownership register access and the treatment of higher-risk factors, where the position evolved after 4AMLD's original adoption. Compliance teams should confirm which provisions remain in force, which have been modified, and how their national supervisor expects the combined requirements to be applied.

Common misconceptions

4AMLD created a single, uniform set of AML rules that apply identically across all EU Member States.
A directive sets out results that Member States must achieve but leaves the form and method of implementation to national authorities through transposition into domestic law. As a result, matters such as beneficial ownership register access, thresholds, and sanctioning regimes could differ between Member States. Practitioners should consult the applicable national implementing legislation, not the Directive text alone.
The beneficial ownership registers introduced by 4AMLD identify who legally owns a company.
Beneficial ownership refers to the natural person(s) who ultimately own or control an entity, which is a distinct concept from legal ownership recorded in company registries. A registered legal owner may hold an interest on behalf of another person, so the two data points should not be treated as interchangeable.
Applying the customer due diligence measures required by 4AMLD prevents money laundering.
CDD and the broader risk-based framework are measures to detect, deter, and mitigate money laundering and terrorist financing risk; they do not guarantee prevention. Their effectiveness depends on implementation, ongoing monitoring, and calibration to the specific risks faced by the obliged entity.

Best practices

Work from the applicable national transposing legislation rather than the Directive text alone, since implementation of key elements such as beneficial ownership registers, thresholds, and sanctions varied by Member State, and confirm specific figures against the relevant national rules.
Ground CDD and EDD decisions in a documented risk assessment, ensuring that simplified due diligence is justified by demonstrated lower risk rather than applied automatically, in line with the Directive's risk-based approach.
Maintain clear procedures for identifying and verifying beneficial owners as natural persons who ultimately own or control an entity, and do not treat register or legal-ownership data as a substitute for that determination.
Screen for PEPs, including domestic PEPs where required, as a process distinct from sanctions screening, and apply enhanced due diligence to confirmed PEP relationships without treating a match as evidence of wrongdoing.
Align supranational, national, and business-level risk assessments so that the entity's own risk understanding is informed by, and consistent with, the broader assessments the framework contemplates.
Document the basis for CDD, EDD, and monitoring decisions to support consistency and to demonstrate proportionate mitigation should administrative sanctions or supervisory review arise.