Live Updates

AMLA adopts key Regulatory Technical Standards

AI Analysis

CSSF has highlighted AMLA’s submission of three draft Regulatory Technical Standards to the European Commission covering business relationships and occasional transactions, customer due diligence, and group-wide AML/CFT arrangements. The standards are not yet final or applicable, but they are expected to provide materially more operational detail under Regulation (EU) 2024/1624, with AMLA proposing a six-month transition after the final RTS enter into force.

Key dates

2026-02-09
AMLA opened the public consultation on the draft RTS concerning business relationships, occasional and linked transactions, lower thresholds, and customer due diligence.
2026-04-16
AMLA opened the public consultation on the draft RTS concerning group-wide requirements and additional measures for subsidiaries and branches in third countries.
2026-05-08
Public consultation closed for the business-relationship, transaction and customer-due-diligence draft RTS.
2026-06-15
Public consultation closed for the group-wide arrangements and third-country legal-impediment draft RTS.
2026-10-01
AMLA announced that it had finalised the three draft RTS and submitted them to the European Commission for formal adoption.
2026-10-07
CSSF published its communiqué drawing Luxembourg professionals’ attention to the draft RTS and recommending preparatory gap analysis and control work.

Suggested considerations

  • Compliance teams may wish to complete a gap analysis against the AMLA final reports, particularly for customer and beneficial-owner information, verification sources, electronic identification, non-face-to-face onboarding and PEP screening.
  • Firms should consider mapping current customer journeys and transaction-monitoring logic to the proposed distinction between business relationships, occasional transactions and linked transactions.
  • Firms may wish to identify products, sectors and transaction types that could be affected by lower CDD thresholds for higher-risk activities, while avoiding reliance on unfinalised monetary thresholds.
  • Financial groups should consider reviewing group-wide AML/CFT governance, risk assessments, policies, internal controls, training and secure information-sharing arrangements, including structures involving common ownership, management, compliance control, networks or partnerships.
  • Groups with branches or subsidiaries in third countries should consider inventorying legal impediments to applying EU AMLR and group policies and preparing escalation, risk-mitigation and supervisory-response procedures.
  • IT and operations teams may wish to assess changes needed for customer-data fields, linked-transaction detection, identity-verification evidence, electronic identification and intra-group information exchange.
  • Firms should monitor the European Commission’s adoption process and the Official Journal publication because the final text, effective date and any amendments remain unknown; preparatory work should be calibrated to the proposed six-month transition period rather than treated as a current binding deadline.

What changed

The draft RTS under Article 19(9) of Regulation (EU) 2024/1624 would establish criteria for distinguishing business relationships, occasional transactions and linked transactions, and would identify high-risk obliged entities, sectors or transactions for which lower CDD thresholds should apply. The draft RTS under Article 28(1) would specify information and verification requirements for standard, simplified and enhanced CDD, including reliable and independent verification sources, electronic identification means, qualified trust services, non-face-to-face verification, and relevant treatment of certain electronic money instruments. The draft RTS under Articles 16(4) and 17(3) would set minimum group-wide policies, procedures, controls and information-sharing standards, identify the relevan

Compliance impact

The immediate impact is preparatory rather than a current new compliance deadline, because the drafts remain subject to possible Commission amendment and Official Journal publication. The likely impact is significant: firms may need changes to onboarding, CDD, transaction classification and monitoring, identity verification, group governance, data sharing and third-country legal-impediment control

Who is affected

  • EU-authorised banks and credit institutions
  • EU-authorised investment firms and asset managers
  • EU payment institutions and electronic-money institutions
  • EU crypto-asset service providers and other obliged entities subject to Regulation (EU) 2024/1624
  • Regulation (EU) 2024/1624 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing
  • Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism
  • Regulation (EU) 2015/847 on information accompanying transfers of funds and certain crypto-assets

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

No description available.

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankAsset ManagerPayment ProviderAll Firms
View Original on CSSF Back to Feed

Share this update