INTRODUCTION
The problems of money laundering and terrorist financing are transnational, but supervision has been traditionally fragmented in the European Union. This resulted in inconsistencies in the approach to risk-based obligations, the level of customer due diligence and the level of enforcement. The AML package 2024 addresses the relevant rulebook, which can be applied directly, and to a new directive for the national institutional framework and a central authority for coordination of the regulatory, supervisory and financial intelligence functions. Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), as established by Regulation (EU) 2024/1620, and directly applicable obligations to obliged entities as introduced in Regulation (EU) 2024/1624, as well as the reorganised national supervision and cooperation between national supervisors and the Financial Intelligence Units, as provided in Directive (EU) 2024/1640, all contribute to this. AMLA's first supervisory exercise of up to 40 financial entities directly supervised by the regulator will be in 2027, with direct supervision starting in 2028, while the AML Regulation will come into effect from 10 July 2027 (Authority for Anti-Money Laundering and Countering the Financing of Terrorism, 2026e; European Parliament & Council of the European Union, 2024a,b,c).
The majority will be superviseable under national law, and many of the new sectors or sectors which have been expanded into the EU framework are very different from banking. The customer relationships, transaction types and compliance resources differ among the various types of lawyers, accountants, real estate practitioners, crypto-asset services providers, traders of high-dollar items and businesses in the football industry. Thus, AMLA's guidelines form a delicate basis for the task within the tight constraints of regulation: to ensure union law is consistent, but not to equate two different risks for two different purposes as equivalent based on their similarities.
There are already some markers of what the new authority might be able to achieve and the things it will be unable to do. This is due to Pavlidis (2024), who argues that EU-level supervision is a solution to regulatory fragmentation. Tosza and Voordeckers (2024) define AMLA as a new ‘centre of gravity’ with real enforcement powers but note that its capacity to directly enforce is limited. To understand how to manage money-laundering, Hock (2026) sees it as a collective-action issue with a lack of clarity and credibility. Levi et al. (2018) demonstrate that it is hard to assess the effectiveness of the policies without improved outcome data. Pol (2020) has raised doubts about the effectiveness of compliance activities with respect to its crime control outcomes. Zavoli and King (2021) identify challenges at the interface of implementation requirements and organisational routines, professional judgement and limited resources.
Draft consultations provide the current understanding of AMLA's understanding of proportionality, monitoring and risk assessment, and do not necessarily constitute the wording or impact of the final instruments. It suggests whether the developing design includes the proper safeguards to enable harmonisation as an effective decision-making tool and identifies areas where problems can still be addressed prior to the general roll-out of the AML Regulation.
The research gap is related to the analytical position of the AMLA guidelines in the process of shifting from the design of legislation to its implementation. There is less discussion about the potential for greater regulatory layering, for the standardisation of weak proxies for risk and for greater data processing or for more ‘defensive’ measures. All assessments must make clear the difference between promulgated legislation, valid technical requirements, draft guidelines and future practice.
The objective of this article is to analyse the objective and scope of AMLA guidelines for financial crimes of money laundering and financing of terrorist activities. The main question to be answered is whether these guidelines can enhance the efficiency and uniformity of the EU AML/CFT framework without introducing unnecessary compliance requirements or standardising procedures. The article challenges the idea that meaningful convergence of supervisory practices will be achieved by AMLA guidelines other than in cases where they call for similar, reasoned and auditable decisions, but allow for sector sensitivity in terms of proportionality. It relies on doctrinal legal analysis of the AML package from 2024, functional analysis of the AMLA published regulatory instruments and programming documents as well as a focused comparison of developments in Germany, France, the Netherlands and Latvia. Because some of the instruments are still in draft form, conclusions therefore focus on institutional design and potential risks in implementation over results of enforcement.
RESEARCH RESULTS AND DISCUSSION
Legal position and practical authority of AMLA guidelines
AML Regulation and AMLA Regulation are legally binding pieces of legislation. The procedure for the adoption of binding RTS and Implementing Technical Standards (ITS) is provided for by Union law. They are authorised under Article 54 AMLA Regulation, which seeks to ensure consistent, efficient and effective practices for AMLA in both its supervisory and Financial Intelligence Unit (FIU) aspects, and the general application of Union law. Supervisory authorities and Financial Intelligence Units (FINUs) are required to notify AMLA in respect of compliance and/or compliance plans and guidelines for obliged entities, which may include compliance-reporting arrangements (European Parliament & Council of the European Union, 2024a).
This form will allow the guidelines to have the authority of law, yet won't turn AMLA into a body of law. When a national supervisor departs from an AMLA guideline, it has to be able to back up its decision. If the method of inspection used is materially different from one to which the entity is obliged, then the entity will find it difficult to explain why it is different and justify how the alternative method is meeting the legislative intent and is controlling the relevant risk. Guidance can also be considered as evidence in case of the interpretation of the open-ended obligations of the courts, but cannot change the regulation.
The danger is the guidance getting so detailed that it becomes duties which are not attached to the legislation. According to Article 54, all stages of the process of open consultation and a cost-benefit study, proportional to the scope and effects of the instrument, shall be carried out. Where guidelines have an impact on the substantive constraints of these safeguards, particularly on the costly changes of information systems, they should be seen as substantive constraints.
There are AMLA instruments that control supervisory authorities, obligated entities and those that link the two. The overall legal/operational load is thus passed along a chain: AMLA establishes the methodology, the national authorities incorporate it in supervision, the undertakings rework the controls and front-line staff implement the (new) procedures with the customers and the transactions themselves.
While waiting for AMLA to replace the existing EBA guidelines and standards, the current EBA guidelines and standards will remain applicable (European Banking Authority, 2025). A regulatory vacuum is avoided by continuity, but at the same time there is a time overlap between existing guidance, new legislation and draft AMLA instruments and national guidance. AMLA should designate specifically the provisions that are retained, replaced, or eliminated. In the absence of a concord, it can be a challenge to ensure that obliged entities are meeting overlapping documents which may have different terminology or are intended for a smaller number of sectors to whom they apply.
Current regulatory programme and implementation timetable
The draft Guidelines on business-wide risk assessment are published under Article 10(4) of the AML Regulation (Authority for Anti-Money Laundering and Countering the Financing of Terrorism, 2026a). Draft Guidelines on ongoing monitoring' is issued under Article 26(5). Other obligations such as customer due diligence requirements, group-wide obligations, home-host cooperation, reporting formats and methodologies for risk assessment are in the process of being specified in binding technical standards (Authority for Anti-Money Laundering and Countering the Financing of Terrorism, 2026d). To talk about each instrument as an AMLA guideline would make it difficult to understand the hierarchy of the new rulebook, and would give the false impression of how much discretion AMLA might have in any of these areas.
Assessment should include a description of the nature of the undertaking and its operations, an identification and assessment of inherent risks, evaluation of the quality of controls and determination of residual risk. The draft puts on the shoulders of the obliged entity the responsibility of knowing its exposure, and maintaining the assessment in proportion with its size, its nature, its business model, its complexity and its risk profile. Whether or not it is useful will hinge on whether or not final guidance will allow for concise evidence-based assessment in the smaller entities and challenge the generic risk matrices in use by larger institutions.
The ongoing-monitoring consultation was opened on 3 June 2026, and will be open until 3 September 2026. It is designed for both the finance sector and the non-finance sector and allows for manual, automated and hybrid monitoring approaches. Artificial Intelligence (AI) is not a must and advanced analytics does not mean that governance, explainability, testing/human oversight is unnecessary. The draft also clarifies the distinction between periodic review and event driven review and also permits flexibility to accommodate monitoring designs based on the nature of the relationship (Authority for Anti-Money Laundering and Countering the Financing of Terrorism, 2026b).
The adjoining rulebook is undergoing a gradual process of completion, while the AML Regulation will be applicable in July 2027. Depending on the size, organisational models, monitoring, group policies, reporting interfaces and model-validation processes require a great deal of lead time to change the customer data models. The appropriate answer is a published sequence plan stating any dependencies, anticipated completion date, any transfers in place and how any existing EBA/national guidance will be dealt with.
In March 2026, AMLA began a data collection programme to test and calibrate their risk assessment models. The models will facilitate, for up to 40 entities, the selection for direct supervision from 2028 (to be done in 2027) and will also help to standardise national risk assessments (Authority for Anti-Money Laundering and Countering the Financing of Terrorism, 2026c,f). Guidelines should be based on the same evidence behind the calibration of supervisory models, or entities could be directed to gather information that does not meaningfully enhance the risk differentiation.
Expected benefits of supervisory convergence
Groupwide risk assessment requirements that are agreed upon can help enable similar assessments across business units; enhance the quality of the group risk oversight; and provide clarity on the evidence being required for customer risk classification. This can decrease regulatory arbitrage and complicate it for a group to move higher risk operations to a lower supervised jurisdiction. It could also enable the supervisors to make comparisons between entities based on a shared definition rather than incomparable national datasets.
A documented methodology provides documentation for review that outlines what risk factors were addressed, the rationale for the effectiveness of the controls, how residual risk was evaluated, and what action was taken for the monitoring response. Clear guidance can thus help support supervisory challenge and a defence of reasonable, risk-based decision-making.
Consistent data formats and definitions can facilitate analysis of cross-border data. The same infrastructure can enhance the private-sector controls to suspicious transaction reports feedback loop. Reports that are defensive and disorganised or don't align with investigative goals are of limited value when it comes to data volume.
The move from EBA to AMLA also provides a chance to broaden the existing advanced guidance from the financial sector to the entire obliged-entity community and rectify some of the assumptions embedded in the EBA guidance.
AMLA should ensure that a clear feedback statement is created stating what changes in concerns were made to the final instrument, what concerns were rejected and why. This would ensure that the costs and benefits of Article 54 are indeed measurable and would make it easier to see that the rule is not an example of regulatory capture.
Risks and limits of the guideline-based model
AMLA should include the elements of legal basis, objective, addressee and the interaction with other instruments in the introduction to each guideline. A replacement table must be drawn up to show superseded EBA and national material. Clarity can be found by eliminating, in its entirety, guidance which is a restatement of legislation - repetition causes differences in interpretation.
A small art dealer and an accountancy firm with few transactions and a retail bank with millions of transactions might have the same number and broadly the same nature of legal duties, but the evidence, frequency and technology suitable in each case is clearly different. It's acceptable to have minimum outcomes that are consistent, but it might be unhelpful to have minimum workflows that are consistent. Instruments should be more ambitious in the end to clarify what is required from each outcome, and not prescriptive in terms of giving sector-specific examples.
A comprehensive assessment can include all prescribed areas but not be sufficient to conclusively determine the highest priority areas of the institution's exposure. A monitoring model could well have a large volume of governance-keeping logs and produce low-level alerts. Visual conformity of documents should not be a basis for assessing the reasoning and performance of the controls; rather, AMLA should evaluate the reasoning and performance of the controls.
Implementing at a lower tier - sector and firm size - should be included as part of a cost-benefit analysis under Article 54. It must contain ongoing data quality tasks such as training staff, checking data for correctness, data corrections and data supervision reporting, not simply treat the release of a guideline as a low-cost venture.
A large banking organisation may distribute a new control across many customers, and a small professional practice may have a fixed cost of a control, that is high in comparison to its income and actual risk of exposure. Therefore, not the mean entity cost (MEC) alone, but the market structure should be taken into consideration in the impact assessment by AMLA. It should explore whether the proposed requirement can be fulfilled with existing records, and whether there is a simpler approach to satisfying it that fulfils the supervisory purpose, and whether there is a lower level of relevant information in the record that must be given up on the sectors to satisfy the requirement. The consistency element of proportionality also extends to the process being undertaken by an entity; they should not be penalised if they are using a simpler process for a risk assessment that is consistent with this. Examples of acceptable simplified implementation should be given in guidance, and the guidance should train supervisors on assessing those examples on their merits. This is a practical issue and, without it, the legal right to proceed proportionately could have little impact as institutions would opt to go through the most conservative process available to prevent action being brought against them.
The fourth risk is that of data overgrowth that could lead to a lack of useful information. The types of data that are essential to customer due diligence and continuous monitoring include identity data, beneficial ownership information, transactions, behavioural data and any inferences that might be sensitive. European Data Protection Supervisor (2021) advocated for more coordination of the EU while urging clarity on the roles and tasks, as well as limits and data protection safeguards. AMLA guidance needs to clearly explain what constitutes purpose limitation, access controls, retention logic and responsibilities for data-quality activities and ways to correct inaccurate information. Errors can be as easily propagated throughout a centralised system as can be useful intelligence.
Although automated monitoring can handle volumes too large for manual checking, it can produce false positives or be unable to identify patterns when they are not seen in the past, and may be subject to bias in the labels used in the historical data. The draft for the ongoing monitoring published by AMLA does not prescribe the use of AI - an appropriate move. Final guidance should include documented guidance objectives, reference to relevant typologies, setting up false-positive and false-negative indicators, change control, human escalation/independent challenge.
Customer de-risking and financial exclusion is the fifth risk. In 2025, Financial Action Task Force (FATF) issued an updated recommendation on financial inclusion measures (Recommendation 1) to further strengthen the notion of proportionality, with more clearly identified low risk subjecting to less stringent measures; and an update to the financial inclusion guidance (Financial Action Task Force, 2025a,b) warns against indiscriminate risk avoidance (IR avoidance). The Dutch Central Bank (DNB) has also been calling for narrower targeted restrictions and dispensable exemptions (De Nederlandsche Bank, 2022). AMLA guidelines should include established reasons for case-specific refusal and escalate before termination in the appropriate cases and should involve tracking refusal and exit patterns. Beneath-average departure rates should not be taken solely at face value as evidence of good risk management but instead can be red flags for poor practices.
The sixth Risk is that of poor measurement. Inputs and outputs are commonly reported on AML systems, such as a count of staff, alerts, reports of possible suspicious transactions, inspections, hours of sanctions and training. These measures offer no indication of whether or not any criminal funds were prevented, detected as soon as possible, or recovered more effectively. Levi et al. (2018) outline the challenges in having a weak evaluation without reliable data and counterfactual analysis. So, while Pol (2020) concludes about compliance spend and measured impact differently, his words still ring true. Guidelines should include relevant decisions addressed; and should be evaluated following the implementation with outcome indicators, burden indicators and unintended-consequence indicators.
The seventh risk is that a diverse supervisory response may be conducted. Important differences in the staffing, technology, expertise and enforcement culture of national authorities does not mean there are no common rules. An over-ambitious guidance given by inadequate staff can result in nominal compliance. The peer reviews, indirect supervision and common methodologies by AMLA can enhance this but can also focus attention on scores that could be collected centrally. There is a need for qualitative estimation, especially for non-financial businesses. AMLA should not only undertake quantitative benchmarking but also undertake thematic inspections and analysis of supervisory decisions and undertake deliver targeted file reviews. Convergence should inhere that similar risks are treated similarly instead of all authorities having a similar score distribution.
A final concern is the operational utility vs. Supervisory Tools / Standards (STs). An eighth risk is that of suspicious transaction reporting vs. operational usefulness. There is a place for uniformity in reporting through common language and the use of common reporting formats, but adopting a stick-to-the-rules approach could result in species data being in similar reports in a format that does not offer much investigative value. Without context, FIUs will not be able to determine what to investigate or what to look for, whereas the reason for suspicions, relationship with the customer, known counterparties and anything that the reporting entity has done to investigate the suspicions so far will help the FIU reduce the range of investigations. This is because a system based on volume will promote defensive submission. Within common formats AMLA's work needs to be related to structured feedback in FIU; typology; analyses about the characteristics that facilitate dissemination, investigation, restraint and confiscation of reports. Quality of reporting should not be used to judge the decision to report, as an institution can have a reasonable suspicion and perform poorly when it comes to the quality of the report.
One last risk is the development of incentives tied to the central risk scores. Data collection & calibration activities by AMLA are required in the direct supervision selection and convergence of supervision. A numerical model can, however, be a target. Institutions can do this by rewriting their home-grown classifications in order to make reported measures more accurate; and national supervisors may be hesitant to question a turf-and-farm common model even if local intelligence suggests otherwise. AMLA needs to explain the general logic, the data quality restrictions and governance of its models and document how the models can be overridden by experts and to verify stability of model outcomes across sectors and Member States. Transparency in challenging a score adds credibility to a centrally generated score, not institutional status!
The 10th risk is regarding sanctions and remediation. While harmonised sanction methodology can minimise the differences between the various countries, deterrence will not strictly take place on the basis of the highest possible level. Supervisors must know the difference between isolated items of control failure, failures in system or assault in system, deliberate hiding or weakness identified and corrected by the institution itself. As each deficiency is seen as a sign that there is serious non-compliance, companies will cover up defects and will not conduct honest internal tests. AMLA guidance should help support early remedial actions, root cause analysis and ensure that serious consequences (sanctions) are retained for recurrent, repeated, systematic and intentional breaches. The balance would also boost commandability of the institutions - they would be incentivised to seek out and address their shortcomings but also have consequences to face if their governance is not up to scratch.
The limitations of the framework do not only include the institutional and formal one, but also the substantive one as AML scope does not cover all aspects of criminal investigation, prosecution, predicate offence and confiscation. Even though the various registry systems share a common goal, the implementation of this goal could still be hindered by differences in beneficial ownership verification, access to evidence and judicial capacity of companies in the different registries, which could yet further obstruct cross-border cases. AMLA can increase information entering the system and make information more comparable, but the impact of this depends on institutions beyond its reach. Effectiveness claims should then be broken down into compliance outcomes, supervisory outcomes, intelligence outcomes and criminal-justice outcomes. This separation of the issues would mean that AMLA would not be deemed responsible or liable for any consequences that occur further down in the enforcement chain.
To conclude, the last institutional risk has, as they say, expectations. AMLA has also been presented as a ‘panacea’ to ‘disjointed enforcement’. A smaller number of high-risk financial entities will be supervised directly by it. A majority of obliged entities will continue to be supervisees by the national authorities, and criminal investigation will stay mainly national. In arguing these points, Tosza and Voordeckers (2024) emphasise the actual capacity of AMLA as well as the constraints on its powers. The support provided by AMLA, national supervisors, FIUs, police, prosecutors and data-protection authorities will make the difference between success and failure in implementing common guidance in practice as far as criminal finance is concerned. The fact is that a good enough guideline can only be used if investigators have been able to conduct these investigations on time as well as secure the asset back or make sure good feedback to the reporting entities is available.
Different national starting points
The process of implementation will start from various institutional levels in the Member States. AMLA is hosted by Germany in Frankfurt, and there is a developed federal supervisory and law enforcement system in place. The site can help to enable the exchange of experience between institutions; however, it does not alleviate co-ordinating problems between federal and regional institutions or between financial and non-financial institutions. The tricky part for the Germans will be to square out their developed national practice in line with the EU procedure without continuing to include duplication of requirements because of their AMLA-related pre-eminence.
France has also a well-established system of enforcement to transition. The Autorité de contrôle prudentiel et de résolution highlighted areas where risk-based AML/CFT - Countering the Financing of Terrorism supervision is needed, as well as the contribution to AMLA's operational implementation in its 2026 work programme. The French authorities have also collated data for the identification of entities possibly subject to direct supervision by AMLA (Autorité de contrôle prudentiel et de résolution, 2026a,b). France has a lot to offer in terms of supervisory experience. The analytical issue is transferability: what works for larger banks and/or insurers and what does not needs to be deliberately adapted so that it works for smaller professions, unless acting on the initiative of the AMLA and the national authorities, respectively.
The Netherlands offers a good counterbalancing force to the growth of compliance. DNB's policy guidance has highlighted a need for a more target-oriented approach to govern AMLs and minimisation of de-risking activities that are not necessary. This status is awarded on the reality of the high intensity of transaction monitoring and wide-spread customer review programmes. The notion that a more stringent framework equates to a more effective framework is one of the core themes of this article, and this was evident in Dutch experience. AMLA is able to leverage common data and compare to its provided supervision to detect an area where controls create excessive effort for little benefit in investigations.
There is a very detailed national methodology in Latvia, and considerable experience in the country with financial-sector risk reform. The AML Handbook of Latvijas Banka (March 2026) encourages the adoption of a risk-based approach and provides guidelines and best practices on governance, crypto-asset service providers and sanctions controls. The national strategy guided by the Financial Intelligence Unit is a result of the national risk assessment of 2023 and outlines an action plan for the year 2024–2026 (Financial Intelligence Unit Latvia, 2024). AMLA guidelines will, therefore, not be placed in a blank document, but rather into an existing system. The key challenge for Latvia to address will be to establish a national level mapping of the needs compared to the EU instruments, eliminate duplication and maintain local risk expertise that can be missed in a typical EU template.
Also, a sequencing issue comes out of the comparison. There can't be a ‘wait and see’ for National authorities for the completion of all the instruments by AMLA, as end-nodes need to be budgeting, contracting and making arrangements for system changeovers before July 2027. Meanwhile, the premature national guidance can set up another layer which need to be further lifted later. A coordinated transition should be based on the presence of common questions for implementation, and on mutual communication of supervision, coordinated by clearly articulating the sunset clauses for exceptionary national measures. Existing guidance to the EU outcome should be determined by national authorities as to whether more or less change is required or whether there are other points of focus that would benefit from being integrated into the country's existing planning. This would mean that writing, which could be performed without, would not be performed and that focus would be placed on real needs of the children.
From the following four examples it can be seen why a mere formal transposition of implementation is not sufficient to assess it. Germany and France have good institutional capacity; the Netherlands have examples of proportionality; and Latvia shows how difficult it is to have alignment once there is considerable national reform. A common rulebook should reduce the discrepancies of expectations across boundaries and enable a nation to target threats that don't match that of another nation. AMLA should include implementation reviews to give clarity on justified variation in the national level and justify the presence of the variation due to poor supervision.
Five tests for effective AMLA guidelines
The analysis is used for the formulation of five tests for future AMLA guidelines. There are two major aspects: Firstly, legal clarity. All guidelines should clearly state their legal requirements, the target groups, the connection to Regulatory Technical Standards/Implementing Technical Standards (RTS/ITS) and impact on the current European Banking Authority (EBA) or national guidance. Definitions should be consistent with the legislative acts. Examples should be used in an illustrative context. A guideline should not lead to the setting of a sanctionable obligation which may not be deduced from the regulation or directive. This test ensures the principle of the primacy of EU law is respected and is meaningful to consultation.
Proportionate risk differentiation is the second test. The minimum target outcome that must be met by all obliged entities should be defined by AMLA and various means to achieve the minimum target outcome be allowed. Identifies the outcomes relevant for reoccurring financial relationships, occasional transactions and professional services for sector annexes. The emphasis should be on home-made, using proportionality as an example, but not suggesting it as a rule of thumb in the introduction. The final text needs to clarify when and how there are simplifying actions that make sense.
Operational Feasibility testing is the third test. AMLA should assign each of the requirements to the data, staff, systems and governance required to support the implementation. As well as large financial service groups and associations, small and new to the market entities are involved and should be consulted. Realistic application dates, move on from legacy relationships and dependency to other standards should be included in final instruments. If a requirement is to be met via a reporting requirement or database that is not in place, the guideline shall outline a short-term solution.
The fourth test is the accountability for data and technology. Purposes for all required data should be stated. AMLA should include restrictions on data access, procedures for data quality control, and procedures for data corrections, retention decisions, and documented. Evaluating automated tools should be based on their performance, governance and explainability, not on their respective vendors or on the size and the complexity of the models. Institutions should have the ability to provide details on how an alert, score or decision on customer risk was reached, and how it was modified or confirmed through the human review process.
The fifth test is the outcome-based assessment. AMLA should articulate in the draft timeline for an adoption whether there will be any indicators to be used for reviewing a guideline. The review should look at supervisory consistency, quality of risk decisions, usefulness of reports to FIUs, the cost of implementation, false-positive burden and customer exits and evidence of displaced activity. These indicators should be compared with each other by sex, sectors and Member States, in a post-implementation review. If a Guideline makes documentation more for its own sake, then it should be revised. Whether this decreases burden and does not impact, or improves, the quality of detection should be used as information to inform the later instrument(s).
The tests should also influence processes of AMLA's internal governance. Before the adoption of each instrument, consideration be given to the opinions of legal, supervisory, FIU, data-protection and technology experts, as well as those related to the respective sector. There should be a record of the review that lists the areas of unresolved trade-offs (e.g., trade-off between detection sensitivity and burden of false-positive). A changing chain is not only technically accurate, but it may also be operationally inadequate, and an effective monitoring plan may not sufficiently address the legal concerns. If the main assumptions to create an instrument will be published, the basis for the delivery of the instrument and subsequent assessment will be stable for the national authorities and obliged entities.
When used in combination, convergence takes on new meaning when discussed in the context of the five tests. The goal is now similar thinking, standards of evidence and results that are subject to review. Does not mandate that all institutions adopt the same matrix or software or participate in the same review cycle. In this model supervisors will have to make judgements, so it is a more demanding model for supervisors. It's also more consistent to the risk-based approach. The success of AMLA's institutions should be viewed as its extent to influence the quality of this judgement in the Union.
CONCLUSION
The AMLA guidelines aim to spread the implementation of the EU AML/CFT package to supervisory and operational practice in a harmonised way. They can help with reduced ambiguity regarding risk assessment, similar supervisory ambitions, better cross-border joint action, and better-accessible data. Even though they are guidelines, their impact will be quite significant in practice as their observation and compliance will be expected from supervisors, FIUs and obliged entities.
Material risks are the same as above. Detailed guidance can turn into an extra layer of regulations, leading to checklist compliance; be heavy to implement and acquire, introduce additional data processing and promote defensive customer exits. Some of these impacts are particularly significant for the beginning of July 2027 as some standards and guidelines are in development. The direct supervision of AMLA will be very constrained and will also leave national capacity and cooperation as pivotal.
This research question is thus qualified with a very important qualification. The EU framework could be enhanced by the AMLA guidelines, meaning that convergence equals comparable reasoned and auditable decision making. The uniformity of procedures for various sectors would have downplayed the risk approach. Final rules should pass five tests: being legible, proportionately distinguishing risk, a feasible operational mechanism, data accountability and outcomes assessment. This would help AMLA to limit fragmentation without formal uniformity or the curtailment of professional judgement.
The final guidelines on a risk assessment and continuous monitoring (issue 25) adopted by businesses after should be examined in further research, and the cost of implementing these guidelines, the findings and their impact on the right of customers to access the services should be compared, across Member States. The ability to do that should be made possible by AMLA publishing equal data on outcomes and unwanted side effects. The long-term value to the authority of the volumes of instruments created will come down to the quality of the instruments and their ability to enable better decisions on criminal finance in the areas of prevention, detection and investigation.
