risk intelligence Insights

AMLA and the new EU AML regime: Is your data ready?

Priya Nallan

Global Head of Product, LSEG Risk Intelligence

Key takeaways:

  • The EU Anti-Money Laundering Regulation (AMLR) is raising the bar, requiring firms to collect, verify and maintain richer customer and risk data.
  • As organisations move from planning to implementation, data quality, ownership and traceability are emerging as key determinants of compliance readiness.
  • Firms that take a proactive approach to assessing their data foundations today will be better positioned for AMLR implementation tomorrow.

From regulation to reality

Picture a compliance team at a cross-border financial group preparing for the EU’s new anti-money laundering and countering the financing of terrorism (AML/CFT) regime. 

They have briefed senior management on the new EU-level AML/CFT Authority (AMLA) and the accompanying Anti-Money Laundering Regulation (AMLR). The team has also crafted an implementation roadmap leading up to 10 July 2027, when many of the AMLR’s key provisions are expected to begin applying [note1]. On paper, the programme is progressing well. 

But as the team turns from planning to implementation, harder questions surface. Where is the required customer and ownership data held? Who owns it? Can it be traced, kept current and used consistently across the group? The firm understands what is changing. But the real work is only just beginning.

What is changing – and when?

Let’s back up a little. AMLA and the AMLR are both part of a wider EU AML package, but they play different roles. AMLA is the new authority; the AMLR is the regulation containing many of the substantive obligations firms must implement.

AMLA is expected to directly supervise a limited number of higher-risk, cross-border institutions. Its first selection round is planned for 2027, with direct supervision projected to begin in 2028 [note2] and initially covering up to 40 entities or groups [note3].

Most organisations won’t fall under AMLA’s direct supervision – but that’s no reason to relax. National authorities will continue to supervise most firms, while AMLA will promote greater consistency across the EU and closer cooperation between national supervisors.

Crucially, the AMLR applies much more widely than the cohort AMLA will directly supervise. It marks a significant shift from a directive-led framework implemented through national law to a single, directly applicable EU rulebook specifically intended to reduce variation between Member States.

Important technical standards and guidance are still being developed, consulted on and clarified. Even so, the direction of travel is clear, giving firms a strong basis to begin preparing while some implementation details continue to evolve.

Why is data a key challenge for the AMLR?

What makes implementation so demanding? In short, data.

The ability to collect, access, verify and monitor customer and risk data will be central to implementation for “obliged entities” – the organisations and professionals subject to AML/CFT duties under the regulation. 

Many firms are likely to need more detailed data on customers, beneficial owners and other relevant connected persons, supported by appropriate evidence and ongoing review.

New and evolving requirements introduce additional expectations for customer identification and verification, beneficial ownership, politically exposed person (PEP) identification, sanctions screening and enhanced due diligence. Firms must establish not just who a customer is, but who owns or controls an entity and whether connected individuals require additional scrutiny.

The task doesn’t end once the information has been collected. That data must support ongoing monitoring, periodic refreshes and event-driven reviews. Firms will also need appropriate records, supporting their CDD and monitoring activities and decisions, to show where that information came from, when it was checked and how it informed a decision.

For those processes to work, data needs to be reliable, structured and usable by screening, monitoring and reporting systems. It must also be sufficiently consistent across entities for cross-border groups to apply controls effectively and provide clear evidence to supervisors.

That’s where some implementation challenges can emerge. Customer information is often spread across multiple systems and entities, beneficial ownership records use different formats, and some data can’t easily be traced to its source. Local teams may follow different refresh processes, and even where information exists, it isn’t always structured for screening and monitoring systems to use consistently.

PwC’s 2026 EMEA AML Survey illustrates the scale of the gap. Depending on the sector, between 14% and 29% of EU respondents reported having completed both a detailed analysis and an impact assessment, while only approximately one-third believed that they will be ready to comply by 10 July 2027 [note4].

Across the wider EMEA survey, data quality was seen as the leading barrier to scaling technology and AI adoption – cited by 52%-89% of respondents, depending on sector [note5].

Technology may ease some of the pressure, but fragmented, incomplete or outdated data will ultimately constrain what firms can automate.

What should firms do now?

Firms aren’t all starting from the same place. Some have moved from interpretation and gap analysis into detailed implementation; others still have substantial work ahead on data, technology, processes and operating models.

Larger institutions may have more resources but can also have more complex structures to manage. Smaller or newly in-scope firms may have simpler operations, but fewer people and less mature technology. Either way, a completed gap analysis is not the same as being ready to operate.

Answering the opening questions about where data sits, who owns it and whether it is traceable and consistent often reveals gaps in external data, internal records, governance or the connections between systems. The exercise turns a broad regulatory change programme into specific decisions about sourcing, verification, remediation and ongoing monitoring.

With the deadline approaching, a practical next step is for firms to test whether their data and processes will support implementation in practice. Organisations that operate across multiple jurisdictions should consider whether information is sufficiently consistent, traceable and reliable to support a more harmonised AML framework. Once they have identified potential gaps, they can prioritise remediation activities ahead of the implementation deadline.

  • What is the difference between AMLA and AMLR?
    AMLA is the EU's new anti-money laundering authority, while AMLR is the regulation that sets out many of the AML/CFT requirements firms will need to comply with.

    Will AMLA supervise all EU financial institutions?
    No. AMLA is expected to directly supervise a limited number of selected higher-risk, cross-border institutions, while most firms will remain under national supervisory oversight.

    When does the AMLR apply?
    The AMLR's main provisions are due to begin applying on 10 July 2027, although some technical standards and guidance are still being developed.

    Why is customer data important under AMLR?
    The AMLR places greater emphasis on collecting, verifying and monitoring customer and risk data, making reliable, traceable and consistent data critical to effective compliance.

    What should firms do now to prepare?
    Firms should assess whether their data, systems and processes can support AMLR implementation in practice, identify any gaps and begin addressing them before the 2027 deadline.

footnotes

[1] https://eur-lex.europa.eu/eli/reg/2024/1624/oj/ | Back to Note 1

[2] https://www.amla.europa.eu/amla-takes-next-step-toward-2027-selection-entities-direct-supervision_en | Back to Note 2

[3] https://www.amla.europa.eu/amla-launches-data-collection-exercise-test-risk-assessment-models_en | Back to Note 3

[4] https://www.pwc.com/gr/en/publications/emea-aml-survey-2026.html | Back to Note 4

[5] EMEA AML Survey 2026, Mind the gap, Extended executive summary, PwC | Back to Note 5

Legal Disclaimer

Republication or redistribution of LSE Group content is prohibited without our prior written consent. 

The content of this publication is for informational purposes only and has no legal effect, does not form part of any contract, does not, and does not seek to constitute advice of any nature and no reliance should be placed upon statements contained herein. Whilst reasonable efforts have been taken to ensure that the contents of this publication are accurate and reliable, LSE Group does not guarantee that this document is free from errors or omissions; therefore, you may not rely upon the content of this document under any circumstances and you should seek your own independent legal, investment, tax and other advice. Neither We nor our affiliates shall be liable for any errors, inaccuracies or delays in the publication or any other content, or for any actions taken by you in reliance thereon.

Copyright © 2026 London Stock Exchange Group. All rights reserved.