Solutions

The EU AML rulebook is being replaced. The AMLR applies 10 July 2027, AMLA direct supervision from 2028.

AML / KYC & Financial-Crime Programs

The controls regulators check first — built for the rulebook that applies now, and the one arriving in 2027.

The first thing every reviewer opens

Whatever brings a regulator, bank or partner to your firm, the financial-crime programme is the first file they open. A licence application — EMI, PI, or CASP under MiCA — is assessed on it before anything else. A banking relationship is underwritten on it. An acquirer's onboarding questionnaire is mostly it. "We'll build AML properly once we're licensed" fails for a structural reason: the programme is part of the application, and reviewers grade what exists, not what's promised.

And right now this file matters twice over, because the entire EU AML rulebook is being replaced — the largest overhaul in two decades, already in motion:

The new architecture, and where it stands

Four instruments now define the landscape:

LIVE

The Travel Rule — already live. Regulation (EU) 2023/1113 has applied since 30 December 2024: crypto-asset transfers must carry originator and beneficiary information, with the EBA's Guidelines setting the operational detail. Unlike the wire-transfer regime, there is no minimum threshold for crypto transfers — the information duties apply from the first euro — and transfers involving self-hosted addresses carry their own verification steps.

OPERATING

AMLA — already operating. The EU's new Anti-Money Laundering Authority (Regulation (EU) 2024/1620) has been operational in Frankfurt since July 2025. It has already delivered its first package of technical standards and guidelines, and its selection machinery for direct supervision is running now: from 2028, AMLA will directly supervise a first cohort of around forty high-risk, cross-border financial entities — the statutory criteria look at operations across at least six member states and risk profile, and CASPs are squarely within the frame.

10 JUL 2027

The AMLR — the single rulebook, applying 10 July 2027. Regulation (EU) 2024/1624 replaces the directive-based patchwork with directly applicable, EU-wide obligations. No national transposition, no gold-plating divergence: one rulebook, same text everywhere, from day one.

TO JUL 2027

AMLD6 — the national layer. Directive (EU) 2024/1640 rebuilds the institutional side — supervisors, FIUs, beneficial-ownership registers — with staggered transposition deadlines, the bulk aligning with July 2027.

  1. 30 Dec 2024LIVETravel Rule applies to crypto-asset transfers
  2. Jul 2025LIVEAMLA operational in Frankfurt
  3. 2026DONEAMLA's first package of technical standards and guidelines delivered
  4. NowNOWSelection machinery for AMLA direct supervision running
  5. 10 Jul 2027AHEADAMLR applies, one rulebook across the EU, with AMLD6 transposition deadlines the bulk of which align with July 2027
  6. 2028AHEADAMLA directly supervises a first cohort of around forty high-risk, cross-border financial entities

The practical consequence: a programme built today has to satisfy the current national rules and be structured so the 2027 switch is an update, not a rebuild. That's how we build them.

What actually changes under the AMLR

The deltas that matter for fintech and digital-asset firms, from the regulation's own text:

  • CASPs are fully obliged entities. Every MiCA-authorised crypto-asset service provider is inside the AML regime, EU-wide, with no national carve-outs.
  • Customer due diligence for occasional transactions from €1,000 — including crypto transactions, pulling one-off flows into KYC that national regimes treated differently.
  • A €10,000 EU-wide cash cap for traders in goods and services.
  • Anonymous accounts and anonymity-enhancing instruments are prohibited — for CASPs that means no anonymous accounts and no servicing of anonymity-enhancing coins.
  • A harmonised beneficial-ownership standard — the 25%-or-more ownership-and-control test applied the same way everywhere, ending the register-by-register divergence.
  • Harmonised PEP treatment and EDD triggers, plus explicit outsourcing rules for compliance functions.
  • Governance split made explicit: a compliance manager at management-body level who owns the risk, and a compliance officer (the AMLCO) who runs the day-to-day — the structure regulators will expect to see named in your organogram.

None of this waits until 2027 for planning purposes: the technical standards defining the operational detail are already published, and reviewers increasingly read applications with the incoming rulebook in mind.

What we build: the programme, component by component

A financial-crime programme is a set of named documents and working procedures. Ours contains what the reviewer's checklist contains:

  • Business-wide risk assessment — your actual products, customers, geographies, channels and transaction types, scored and reasoned. The document every other document cites.
  • AML/CFT policy framework — the policy, matched to the risk assessment, not a template with your logo.
  • KYC / CDD onboarding flows — identification, verification, beneficial-ownership resolution to the 25% standard, purpose-and-nature capture — engineered around your real funnel so compliance doesn't kill conversion.
  • EDD triggers and procedures — high-risk third countries, PEPs, complex or unusual transactions, and the crypto-specific triggers, with what "enhanced" concretely means in each case.
  • Ongoing monitoring — transaction-monitoring logic and thresholds fitted to your volumes, alert handling, and periodic review cycles.
  • Travel Rule operations — originator/beneficiary data capture, counterparty CASP due diligence, self-hosted-address handling, and the messaging workflow, aligned with the EBA Guidelines.
  • Sanctions screening — lists, matching, escalation, and freeze procedures.
  • SAR/STR procedures — recognition, internal escalation, FIU reporting, and tipping-off controls.
  • Governance pack — MLRO / compliance-officer role documentation, management-body accountability (the AMLR's compliance-manager structure), and the reporting lines a reviewer maps first.
  • Training and records — role-based training materials and the record-keeping framework that makes the whole programme evidenceable.

Every component is written to be operated by your actual team at your actual stage — a two-person startup and a scaling EMI do not get the same monitoring calibration, and pretending otherwise is how programmes fail their first review.

The crypto lane

Digital-asset firms carry all of the above plus their own layer: the Travel Rule from the first euro, counterparty due diligence on other CASPs, self-hosted wallet procedures, the anonymity-instrument prohibitions, and an AML programme that MiCA authorisation itself depends on. And with AMLA's direct-supervision cohort being selected on cross-border footprint and risk profile, larger CASPs should assume they are being looked at, not just looked after. We build the crypto layer as part of the programme, not an appendix — and we plan it together with the CASP authorisation workstream where there is one.

Our approach

  1. 1Risk assessment firstThe business-wide risk assessment, built from your real products, markets and flows — because every other document has to trace back to it.
  2. 2Policy and procedure buildThe full component set above, drafted to the current rules of your licensing jurisdiction with the AMLR's requirements designed in.
  3. 3KYC/CDD flow engineeringOnboarding, EDD and monitoring designed around your product funnel and vendor stack — the controls regulators accept, at conversion costs you can live with.
  4. 4Travel Rule and crypto operationsFor firms moving digital assets: the data, counterparty and wallet procedures the EBA Guidelines expect, wired into how transfers actually move.
  5. 5Governance and the MLRORole documentation, management accountability, escalation and SAR/STR procedures, training — the human layer reviewers interrogate in interviews.
  6. 6Transition and review supportA gap map from your current programme to the AMLR single rulebook, and support through licence review, bank onboarding, or a supervisor's questions.

Who it's for

  • Payments and fintech firmspreparing an EMI/PI application — where the AML programme is a core dossier component, not an add-on.
  • CASPs and digital-asset businesseswhose MiCA authorisation and banking depend on a credible programme, Travel Rule operations included.
  • Licensed firms facing the 2027 switchthat need a gap analysis from their current national-rule programme to the AMLR.
  • Firms with cross-border scalemodelling whether AMLA's direct-supervision perimeter could reach them.
  • Founders who inherited a template— a policy PDF from a consultant that no one operates, and a review coming.

FAQ

Do we need a full AML program before we apply for a licence?

Usually yes — the AML framework is a core part of the application, not something you add later. Regulators want to see it in place, not promised, and they grade whether the documents describe controls your team actually operates.

Who can act as our MLRO?

A suitably senior, fit-and-proper person — and under the incoming AMLR the governance expectation is explicit: a compliance manager at management-body level owning the risk, and a compliance officer running the function. Some firms appoint internally, others outsource; we document the structure that fits your stage and defend it in review.

Does the Travel Rule apply to us?

If you transfer crypto-assets on behalf of customers — very likely, and already: it has applied since 30 December 2024, with no minimum threshold for crypto transfers and specific procedures for self-hosted addresses. We set up the originator/beneficiary information handling and counterparty due diligence it requires.

What changes under the new AMLR?

From 10 July 2027, one directly applicable rulebook replaces the national patchwork: CDD for occasional transactions from €1,000, a harmonised 25% beneficial-ownership standard, prohibitions on anonymous accounts and anonymity-enhancing instruments, harmonised PEP and EDD treatment, and an explicit compliance-governance structure. Programmes built now should have these designed in.

Could AMLA supervise us directly?

The first direct-supervision cohort — around forty entities from 2028 — is selected on risk profile and cross-border footprint, with operations across at least six member states in the statutory criteria. Most firms will stay with national supervisors operating under AMLA's coordination and the same standards. If you're at cross-border scale, we model your position against the published selection criteria.

What is a business-wide risk assessment?

The foundational document: your products, customer types, geographies, delivery channels and transaction profiles, each assessed for money-laundering and terrorist-financing risk, with the reasoning shown. Every policy choice, EDD trigger and monitoring threshold should trace back to it — which is exactly how reviewers test whether a programme is real.

Should we build to today's rules or wait for 2027?

Build now, transition-ready. Licences, banks and partners require the programme today under current rules — and the AMLR's requirements are published, so designing them in costs little now and saves a rebuild later. We deliver the programme with a 2027 gap map included.

Where this fits. This engagement builds the financial-crime programme itself. Payment & E-Money Licensing is the engagement it sits inside when the programme is a dossier component of an EMI or PI application, and Digital Asset Licensing carries the MiCA and CASP side of the same file. The AMLR's technical standards are still landing, so Horizon watches the official sources and tells you when one lands.

Build a programme that passes review

Tell us your model, markets and licensing plans. You'll get a financial-crime programme your team can actually operate — current-rules ready, single-rulebook proof.

Book a Consultation

General information about anti-money-laundering and counter-terrorist-financing requirements, not legal advice. The dates and thresholds above are those set out in the enacted EU texts, and the detail beneath them is still being filled in by technical standards. Nothing here is a prediction of how any supervisor or reviewer will decide a particular case.