Gå til hovedinnholdet Gå til menyen
Book a demo

Europe's AML Reset: What the New Single Rulebook Means in Practice

From July 2027, Europe moves much closer to one AML rulebook. The bigger change may be what that does to compliance operations.

Looking up between two office towers, rows of identical windows converging towards the sky.

On 10 July 2027, the EU's Anti-Money Laundering Regulation — AMLR, Regulation (EU) 2024/1624 — becomes directly applicable across the European Union. For firms that have spent two decades adapting to national transpositions of successive AML directives, this is a structural change, not just an update. Much of the core private-sector AML framework moves out of national law and into a single regulation that applies, largely as written, in every member state. For EEA countries including Norway, the package is expected to follow through the EEA process, although formal incorporation and any EEA-specific adaptations are still being finalised — a reminder that this reset is not confined to EU member states.

It would be easy to treat this as another compliance deadline: read the new text, update the policy manual, confirm the vendor has a plan, move on. That would be a missed opportunity. The more useful way to think about AMLR is as a rare chance to reconsider compliance processes that, in most firms, were never designed as a coherent system — they were built country by country, requirement by requirement, often years apart, on whatever technology happened to be available at the time.

One rulebook does not mean one identical market

Historically, EU anti-money laundering law has worked through directives, which member states transpose into their own national legislation. That has produced a patchwork: broadly similar objectives, but real differences in wording, scope and practical implementation from one market to the next. A firm operating in several EU countries has had to maintain, in effect, several overlapping frameworks that happen to share a common origin.

AMLR changes the mechanism. As a regulation, it applies directly, without national transposition, placing core obligations — customer identification, beneficial ownership, the purpose and intended nature of the relationship, risk assessment and ongoing monitoring — into one directly applicable text. A companion directive, AMLD6 (Directive (EU) 2024/1640), continues to govern the institutional side: how national supervisors, financial intelligence units and registers are organised, with its own transposition timeline running largely to the same date, with a small number of provisions taking effect earlier or later.

None of this makes the EU one uniform compliance environment. National supervisors remain in place and continue to interpret, prioritise and enforce within their own markets, and institutional arrangements and enforcement culture still vary. A more harmonised framework does not mean an identical compliance environment in every country — it means the underlying rulebook every national environment sits on top of is now, largely, the same one.

The EU Anti-Money Laundering Authority, AMLA, sits alongside this shift rather than starting it. Legally established in 2024 and operationalising its mandate since 2025 from its seat in Frankfurt, it is developing the technical standards, methodologies and supervisory convergence work that will underpin the Single Rulebook. Its own direct supervisory role — over a limited number of high-risk, cross-border financial institutions — follows a selection process beginning in 2027, with direct supervision starting in 2028. AMLA matters, but the more immediate change for most firms is the regulation itself, not the authority that will eventually oversee a subset of institutions within it.

The rules are becoming European. The data is still national.

Here is the distinction firms should hold onto through all of this: the rules are becoming more European. The data infrastructure behind them largely is not.

A more harmonised legal text is genuinely useful for compliance technology vendors. Instead of maintaining a separate rules engine for each national transposition, a vendor can increasingly build against one EU regulatory core and adapt at the margins. That should make it easier for compliance technology to expand credibly across European markets, rather than each vendor's coverage stopping at its home country's border.

It does not make Europe one technology market overnight, because the data needed to actually perform KYC and KYB has not been centralised by AMLR at all. Company registries, beneficial ownership sources, identity infrastructure, national identifiers and local document formats remain organised country by country, each with its own access rules and reliability. Harmonisation removes one genuine layer of complexity — the legal one. It does not remove the practical work of accessing and maintaining good data across jurisdictions that still run their own registries and identity systems.

Why harmonisation still matters for firms operating across borders

Even with that caveat, the practical benefit of a common rulebook is real, particularly for smaller and mid-sized firms. Consider a regulated firm in one EU market considering whether to establish activity, or extend its regulated services, into a neighbouring one. Under the old, directive-based model, that decision meant getting comfortable with an unfamiliar national AML regime on top of the licensing, supervisory and local-law questions any expansion already raises — and often concluding that the added compliance uncertainty was not worth the commercial upside. That uncertainty has quietly discouraged cross-border expansion that would otherwise have made sense.

AMLR does not grant a passport to provide regulated services anywhere in the EU, and it removes nothing from licensing regimes, supervisory approval or other national law that continues to apply to that expansion. What it does is narrower and still meaningful: it removes one specific source of friction — not knowing whether the underlying AML obligations in the new market are recognisably the same as the ones a firm already meets at home. For firms weighing whether an adjacent market is worth entering, that is one fewer unknown, even though the other regulatory questions remain.

The same logic extends to people. As the underlying rules converge, AML expertise should become more portable across EU markets — a compliance professional trained under one country's implementation should need to spend less time relearning a substantially different underlying AML framework to be useful in another. That should not be overstated into "compliance judgement becomes universal": local supervisory expectations, business models and risk appetite still differ and still require judgement specific to the market a firm actually operates in. Harmonisation can make specialist AML knowledge more transferable without making compliance decisions interchangeable.

KYC cannot live on a review calendar alone

One of the most consequential operational implications of AMLR, though, has little to do with cross-border expansion. It concerns how firms are expected to keep customer information current once a relationship is already open.

Ongoing monitoring is not a new obligation — firms have been required to monitor business relationships for years. What AMLR does is make the operating model behind that obligation considerably more explicit and harmonised. The regulation requires firms to keep customer information current, sets maximum intervals for reviewing and updating it — up to one year for higher-risk relationships and up to five years for others, subject to the exact provisions — and, separately, requires information to be reviewed or updated when there is a relevant change in a customer's circumstances, or when the firm becomes aware of a relevant fact, regardless of where that falls in the review cycle.

That second requirement is the one worth pausing on, because it does not fit neatly into how many firms still operate. A common working pattern is: onboard, screen, assign a risk rating, schedule a future review date, and revisit the file when that date arrives. It satisfies the periodic-review half of the obligation well enough. It is a weaker fit for the change-driven half, because it structurally treats everything that happens between review dates as something to be picked up later rather than noticed now.

The operating model the regulation points toward looks more like: onboard, monitor on an ongoing basis, identify a relevant change, assess it, act where necessary, evidence what was done, and still carry out the periodic review on schedule — an operational illustration, not statutory wording. Put simply, the new framework makes it increasingly difficult to treat KYC as onboarding followed by a diary reminder. That is likely to be one of the more consequential shifts to come out of this reset — not because the obligation to monitor is new, but because a purely scheduled-review model is a poor match for a framework that also expects firms to identify and respond to relevant changes between scheduled reviews.

A detected change is the beginning of a process, not an output

It is worth being precise about why that distinction matters operationally.

A scheduled check tells the firm something at a point in time. A relevant change between checks is different: it can require the firm to reconsider whether its previous understanding, risk assessment or actions still hold. An update to a company register, a shift in ownership, a new adverse finding, an expiring document — none of these is, on its own, a conclusion. Each is the start of a set of questions someone still has to answer: what changed, whether it is material here, who needs to review it, whether the risk assessment still holds, whether more information is needed, whether the customer needs contacting, whether approval is required, what decision was made, and what evidence records the response.

That sequence — change detected, routed into a governed workflow, reviewed by a person with the authority to decide, and recorded as it happens — is where monitoring and workflow meet. None of this implies software should make the underlying compliance decision; routing a change into a governed workflow exists to make sure a person with the right authority makes that decision, with the right information in front of them, on a reasonable timeline. What changes is not who decides, but how reliably a change reaches the person who should decide, and how completely the response gets recorded.

This is also where vendor architecture starts to matter more than vendor marketing suggests. Some AML products were built primarily around onboarding, initial screening, storing a KYC file, assigning a risk score and scheduling periodic refresh — useful, but not inherently change-aware. For a product designed mainly around that model, becoming genuinely change-aware or event-driven can be a more substantial architectural challenge than a rules update. None of this means a particular vendor cannot comply, and AMLR does not mandate a specific technical architecture or "event engine" — the obligation sits with the regulated firm, not its software. But the intelligent buyer question is no longer simply "is our vendor AMLR compliant." It is closer to: can your current technology support the operating model this framework expects your firm to run.

What to ask before July 2027

The practical response is not to wait for 10 July 2027 and see what happens. Firms that treat the date as their starting point will spend the second half of 2027 doing under pressure what could have been done calmly over the preceding year. Leading advisers are already telling firms to look beyond policy updates and examine data, operating processes and technology readiness. KPMG, for instance, has publicly advised firms preparing for the new framework to run a gap analysis of current AML practices against the incoming rulebook, identify what additional customer and counterparty data they may need to collect or maintain, assess the effect on existing AML and KYC processes, and start planning technology changes early — because upgrades to IT systems can have long lead times.

That framing points to two different questions, and it matters which one a firm actually asks. The first is narrow: will our current vendor support AMLR? For many regulated firms, where AML is not the core business, the natural response is to put that question to the existing vendor, receive confirmation, and carry on much as before. There is nothing wrong with that as a first step, but stopping there turns a genuine architectural reset into a policy-and-software update, and forecloses the second, more strategically useful question: if we were designing our AML operating model today, from scratch, would we choose the one we currently have? Answering that means looking at whether client numbers, geographical footprint or risk profiles have shifted since the current systems were chosen, whether staff are still doing manual work the technology should have absorbed, whether pricing and licensing still fit the organisation, whether disconnected tools could be consolidated, and whether the technology genuinely supports both the periodic and the change-triggered side of the obligation.

None of this argues that every firm needs new software. Plenty of existing systems, used well, will support this operating model adequately. The point is that a reset of this size is a rational moment to test that assumption rather than simply assume it.

Some firms will reasonably bring in outside expertise or managed services to help answer that question and run parts of the operational work. That is legitimate: a regulated firm can outsource work — expertise, technology, monitoring, administrative execution — but not its regulatory accountability. AMLR limits what can be delegated away: a firm's own risk assessment, its determination of a customer's risk profile, its decision to enter into a business relationship, and its judgement on whether to report suspicious activity to the relevant authority stay with the obliged entity, subject to the exact provisions and exceptions. External providers can improve how the work gets done. They cannot become the answer to who is responsible for it.

Human judgement does not disappear

None of this should be read as an argument that better technology or a more harmonised rulebook reduces the need for professional judgement. If anything it does the opposite: it removes some of the administrative noise that has crowded out judgement, so judgement can be applied to the cases that actually need it.

A common rulebook does not produce identical decisions across firms, and it should not. Firms still interpret that rulebook through the lens of their own customers, products, business model and risk appetite. What a more harmonised framework, supported by better technology, changes is the quality of the information judgement is applied to and how consistently it gets recorded — not who is exercising it, or whether it is still needed.

What this means for compliance technology

This is the environment IQON is built for. Rather than adding another screening database or a single-purpose KYC tool, IQON is built around the coordination problem AMLR makes explicit: connecting the regulated relationship, its workflow, and the systems a firm already relies on, so a relevant change becomes a governed process — change, workflow, review, decision, evidence — rather than an alert someone has to notice and chase manually. Different firms can configure that process differently, according to their own policy and risk appetite. It does not resolve the data fragmentation described earlier, and it does not make the underlying decisions — humans keep the judgement and the accountability. The aim is simply that execution and coordination stop depending on someone remembering.

Where this leads

July 2027 should not be treated simply as a compliance deadline. It is a reasonable moment to ask whether the operating model built around the old framework — accumulated country by country, system by system, over a decade or more — is still the one a firm would choose today, given a clean sheet of paper.

The Single Rulebook will harmonise a great deal of the underlying law. It will not automatically modernise the processes firms use to meet it. That part is still up to the firms themselves — and it is a considerably better use of the months ahead than waiting to find out what the deadline actually requires.

Book a demo

Protected by reCAPTCHA
Privacy - Terms

Thank you

Why IQON

  • Modular platform for onboarding, KYC/AML and reporting

  • Digital onboarding and document signing with eID

  • Continuous AML monitoring

  • Simple, intuitive client reporting across web and mobile

  • Fully white-labelled apps and portals

  • Digitalized processes that improve speed and accuracy

  • Easy, vendor-agnostic integrations