Priya Nallan
Key takeaways:
- The EU Anti-Money Laundering Regulation (AMLR) is raising the bar, requiring firms to collect, verify and maintain richer customer and risk data.
- As organisations move from planning to implementation, data quality, ownership and traceability are emerging as key determinants of compliance readiness.
- Firms that take a proactive approach to assessing their data foundations today will be better positioned for AMLR implementation tomorrow.
From regulation to reality
Picture a compliance team at a cross-border financial group preparing for the EU’s new anti-money laundering and countering the financing of terrorism (AML/CFT) regime.
They have briefed senior management on the new EU-level AML/CFT Authority (AMLA) and the accompanying Anti-Money Laundering Regulation (AMLR). The team has also crafted an implementation roadmap leading up to 10 July 2027, when many of the AMLR’s key provisions are expected to begin applying [note1]. On paper, the programme is progressing well.
But as the team turns from planning to implementation, harder questions surface. Where is the required customer and ownership data held? Who owns it? Can it be traced, kept current and used consistently across the group? The firm understands what is changing. But the real work is only just beginning.
What is changing – and when?
Let’s back up a little. AMLA and the AMLR are both part of a wider EU AML package, but they play different roles. AMLA is the new authority; the AMLR is the regulation containing many of the substantive obligations firms must implement.
AMLA is expected to directly supervise a limited number of higher-risk, cross-border institutions. Its first selection round is planned for 2027, with direct supervision projected to begin in 2028 [note2] and initially covering up to 40 entities or groups [note3].
Most organisations won’t fall under AMLA’s direct supervision – but that’s no reason to relax. National authorities will continue to supervise most firms, while AMLA will promote greater consistency across the EU and closer cooperation between national supervisors.
Crucially, the AMLR applies much more widely than the cohort AMLA will directly supervise. It marks a significant shift from a directive-led framework implemented through national law to a single, directly applicable EU rulebook specifically intended to reduce variation between Member States.
Important technical standards and guidance are still being developed, consulted on and clarified. Even so, the direction of travel is clear, giving firms a strong basis to begin preparing while some implementation details continue to evolve.
Why is data a key challenge for the AMLR?
What makes implementation so demanding? In short, data.
The ability to collect, access, verify and monitor customer and risk data will be central to implementation for “obliged entities” – the organisations and professionals subject to AML/CFT duties under the regulation.
Many firms are likely to need more detailed data on customers, beneficial owners and other relevant connected persons, supported by appropriate evidence and ongoing review.
New and evolving requirements introduce additional expectations for customer identification and verification, beneficial ownership, politically exposed person (PEP) identification, sanctions screening and enhanced due diligence. Firms must establish not just who a customer is, but who owns or controls an entity and whether connected individuals require additional scrutiny.
The task doesn’t end once the information has been collected. That data must support ongoing monitoring, periodic refreshes and event-driven reviews. Firms will also need appropriate records, supporting their CDD and monitoring activities and decisions, to show where that information came from, when it was checked and how it informed a decision.
For those processes to work, data needs to be reliable, structured and usable by screening, monitoring and reporting systems. It must also be sufficiently consistent across entities for cross-border groups to apply controls effectively and provide clear evidence to supervisors.
That’s where some implementation challenges can emerge. Customer information is often spread across multiple systems and entities, beneficial ownership records use different formats, and some data can’t easily be traced to its source. Local teams may follow different refresh processes, and even where information exists, it isn’t always structured for screening and monitoring systems to use consistently.
PwC’s 2026 EMEA AML Survey illustrates the scale of the gap. Depending on the sector, between 14% and 29% of EU respondents reported having completed both a detailed analysis and an impact assessment, while only approximately one-third believed that they will be ready to comply by 10 July 2027 [note4].
Across the wider EMEA survey, data quality was seen as the leading barrier to scaling technology and AI adoption – cited by 52%-89% of respondents, depending on sector [note5].
Technology may ease some of the pressure, but fragmented, incomplete or outdated data will ultimately constrain what firms can automate.
What should firms do now?
Firms aren’t all starting from the same place. Some have moved from interpretation and gap analysis into detailed implementation; others still have substantial work ahead on data, technology, processes and operating models.
Larger institutions may have more resources but can also have more complex structures to manage. Smaller or newly in-scope firms may have simpler operations, but fewer people and less mature technology. Either way, a completed gap analysis is not the same as being ready to operate.
Answering the opening questions about where data sits, who owns it and whether it is traceable and consistent often reveals gaps in external data, internal records, governance or the connections between systems. The exercise turns a broad regulatory change programme into specific decisions about sourcing, verification, remediation and ongoing monitoring.
With the deadline approaching, a practical next step is for firms to test whether their data and processes will support implementation in practice. Organisations that operate across multiple jurisdictions should consider whether information is sufficiently consistent, traceable and reliable to support a more harmonised AML framework. Once they have identified potential gaps, they can prioritise remediation activities ahead of the implementation deadline.
footnotes
[1] https://eur-lex.europa.eu/eli/reg/2024/1624/oj/ | Back to Note 1
[2] https://www.amla.europa.eu/amla-takes-next-step-toward-2027-selection-entities-direct-supervision_en | Back to Note 2
[3] https://www.amla.europa.eu/amla-launches-data-collection-exercise-test-risk-assessment-models_en | Back to Note 3
[4] https://www.pwc.com/gr/en/publications/emea-aml-survey-2026.html | Back to Note 4
[5] EMEA AML Survey 2026, Mind the gap, Extended executive summary, PwC | Back to Note 5
Read more about
Legal Disclaimer
Republication or redistribution of LSE Group content is prohibited without our prior written consent.
The content of this publication is for informational purposes only and has no legal effect, does not form part of any contract, does not, and does not seek to constitute advice of any nature and no reliance should be placed upon statements contained herein. Whilst reasonable efforts have been taken to ensure that the contents of this publication are accurate and reliable, LSE Group does not guarantee that this document is free from errors or omissions; therefore, you may not rely upon the content of this document under any circumstances and you should seek your own independent legal, investment, tax and other advice. Neither We nor our affiliates shall be liable for any errors, inaccuracies or delays in the publication or any other content, or for any actions taken by you in reliance thereon.
Copyright © 2026 London Stock Exchange Group. All rights reserved.
The content of this publication is provided by London Stock Exchange Group plc, its applicable group undertakings and/or its affiliates or licensors (the “LSE Group” or “We”) exclusively.
Neither We nor our affiliates guarantee the accuracy of or endorse the views or opinions given by any third party content provider, advertiser, sponsor or other user. We may link to, reference, or promote websites, applications and/or services from third parties. You agree that We are not responsible for, and do not control such non-LSE Group websites, applications or services.
The content of this publication is for informational purposes only. All information and data contained in this publication is obtained by LSE Group from sources believed by it to be accurate and reliable. Because of the possibility of human and mechanical error as well as other factors, however, such information and data are provided "as is" without warranty of any kind. You understand and agree that this publication does not, and does not seek to, constitute advice of any nature. You may not rely upon the content of this document under any circumstances and should seek your own independent legal, tax or investment advice or opinion regarding the suitability, value or profitability of any particular security, portfolio or investment strategy. Neither We nor our affiliates shall be liable for any errors, inaccuracies or delays in the publication or any other content, or for any actions taken by you in reliance thereon. You expressly agree that your use of the publication and its content is at your sole risk.
To the fullest extent permitted by applicable law, LSE Group, expressly disclaims any representation or warranties, express or implied, including, without limitation, any representations or warranties of performance, merchantability, fitness for a particular purpose, accuracy, completeness, reliability and non-infringement. LSE Group, its subsidiaries, its affiliates and their respective shareholders, directors, officers employees, agents, advertisers, content providers and licensors (collectively referred to as the “LSE Group Parties”) disclaim all responsibility for any loss, liability or damage of any kind resulting from or related to access, use or the unavailability of the publication (or any part of it); and none of the LSE Group Parties will be liable (jointly or severally) to you for any direct, indirect, consequential, special, incidental, punitive or exemplary damages, howsoever arising, even if any member of the LSE Group Parties are advised in advance of the possibility of such damages or could have foreseen any such damages arising or resulting from the use of, or inability to use, the information contained in the publication. For the avoidance of doubt, the LSE Group Parties shall have no liability for any losses, claims, demands, actions, proceedings, damages, costs or expenses arising out of, or in any way connected with, the information contained in this document.
LSE Group is the owner of various intellectual property rights ("IPR”), including but not limited to, numerous trademarks that are used to identify, advertise, and promote LSE Group products, services and activities. Nothing contained herein should be construed as granting any licence or right to use any of the trademarks or any other LSE Group IPR for any purpose whatsoever without the written permission or applicable licence terms.