Home › Academy › Library › EBA response to the European Commission's Call…
Synthesis note · Report

EBA response to the European Commission's Call for Advice on six AMLA mandates

European Banking Authority (EBA) · 2025 · Report · 202 pages · Intermediate

This document presents the EBA's response to the European Commission regarding six mandates related to anti-money laundering (AML). It includes proposals on the risk assessment of obliged entities, customer due diligence, and pecuniary sanctions. The EBA also provides technical advice on group-wide policies and procedures to ensure compliance in both the financial and non-financial sectors.

General Information

This 2025 report, titled "EBA response to the European Commission's Call for Advice on six AMLA mandates," was drafted by the European Banking Authority (EBA). It responds to a request for advice from the European Commission dated 12 March 2024, concerning six mandates related to the European anti-money laundering and counter-terrorist financing (AML/CFT) framework. The scope covers draft regulatory technical standards (RTS) on the assessment of inherent and residual risks of obliged entities, the selection of financial institutions for direct supervision by the AML Authority (AMLA), customer due diligence (CDD), pecuniary sanctions, as well as technical advice on base fine amounts and group policies. The report mainly relies on the financial sector and, to a lesser extent, the non-financial sector, for the period following the entry into force of AMLD6 directives and AMLAR and AMLR regulations in 2024.

Executive Summary

The report responds to the European Commission's call for advice on six AMLA mandates, aiming to strengthen harmonization and effectiveness of the European AML/CFT framework. It proposes regulatory technical standards (RTS) for:

- The assessment and classification of inherent and residual risk profiles of obliged entities, with a common methodology based on a scoring grid combining risk exposure and quality of AML/CFT controls (p. 5-11).

- The selection of financial institutions operating in at least six Member States for direct supervision by AMLA, defining materiality thresholds for cross-border activity via freedom to provide services (p. 11-15).

- The harmonization of customer due diligence (CDD) requirements, adopting a principles- and risk-based approach, with a five-year transition period for updating existing client information (p. 15-17).

- The classification of pecuniary sanctions, administrative measures, and periodic payments, establishing common criteria and indicators to ensure proportionate, effective, and deterrent application, including specific provisions for natural persons (p. 17-22).

Additionally, the report provides technical advice on base fine amounts and on information-sharing policies and procedures within groups, emphasizing the need for a harmonized framework protecting personal data while facilitating consolidated supervision (p. 21-23).

The adopted approach is proportionate, risk-based, technologically neutral, and aims for maximum harmonization to limit compliance costs. The report recommends that AMLA continue this work, notably by adapting certain aspects to non-financial entities and ensuring a smooth transition to the new framework. These proposals constitute a solid basis for a resilient and coherent European AML/CFT system (p. 5-23).

Context and Objectives

The report was prepared in response to a call for advice from the European Commission dated 12 March 2024, within the framework of implementing the new European AML/CFT framework, notably the AMLD6 directives and AMLAR and AMLR regulations adopted in 2024. The objective is to provide proposals for regulatory technical standards (RTS) and technical advice to support the AML Authority (AMLA) in its supervisory and harmonization missions.

The document addresses six mandates concerning risk assessment of obliged entities, selection of financial institutions for direct supervision, customer due diligence requirements, sanctions and administrative measures, as well as advice on base fine amounts and group policies.

The scope mainly covers the financial sector, with recommendations for adaptation to the non-financial sector. Limitations include partial data availability for the non-financial sector and the need for a phased transition for concerned entities.

The report aims to ensure a harmonized, proportionate, and risk-based approach, facilitating cooperation between national and European authorities, and limiting compliance costs for obliged entities (p. 6-7).

Summary of Key Points by Theme

Assessment of inherent and residual risks (Article 40(2) AMLD6):

- Proposal of a common methodology based on a scoring grid combining inherent risk exposure (categories 1 to 4) and AML/CFT control quality (categories A to D), leading to residual risk classification (p. 7-11, 24-33).

- Use of a unique set of harmonized data points, with limited adjustments possible by supervisors based on specific evidence (p. 9-10).

- Recommended annual review frequency, with the possibility of triennial review for small or low-risk entities, and ad hoc reviews in case of major events (p. 10-11, 31-33).

- Need to adapt the methodology for the non-financial sector, with a recommendation to develop separate RTS (p. 10-11, 25).

Selection for direct supervision (Article 12(7) AMLAR):

- Eligibility criteria based on operation in at least six Member States via establishments or freedom to provide services, with materiality thresholds (20,000 clients or €50 million in transactions) to qualify activity under freedom to provide services (p. 11-14).

- Selection methodology based on weighted aggregation of residual risk scores of group entities, to avoid dilution of the overall score by low-risk entities (p. 13-14).

- Transition measures to ensure consistency between RTS on risk assessment and selection, notably for the first selection planned in July 2027 (p. 14-15).

- No application to the non-financial sector (p. 15).

Customer due diligence (CDD) (Article 28(1) AMLR):

- Harmonization of CDD, simplified due diligence (SDD), and enhanced due diligence (EDD) requirements via RTS, with a principles- and risk-based approach, avoiding a prescriptive list of documents (p. 15-17).

- Consideration of risk factors related to electronic money instruments and electronic identification means (p. 15-17).

- Five-year transition period for updating existing client information, prioritizing high-risk relationships (p. 16-17).

- Recommendation to assess the need for separate RTS for the non-financial sector, considering entity diversity and AML/CFT maturity (p. 16-17).

Pecuniary sanctions, administrative measures, and periodic payments (PePPs) (Article 53(10) AMLD6):

- Establishment of common indicators and criteria to classify breach severity and determine sanctions, aiming for proportionate, effective, and deterrent application (p. 17-22).

- Inclusion of specific provisions for natural persons, notably executives (p. 18-20).

- Alignment of PePP procedures with national and European practices, with guaranteed rights of defense (p. 20).

- Planned transition with RTS application from 10 July 2027 (p. 20-21).

- Applicability to the non-financial sector with adaptations considering sector-specific features (p. 20-21).

Technical advice on base fine amounts (Article 53(11) AMLD6):

- Proposal of options for AMLA to harmonize base sanction amounts according to breach type and entity category, including natural and legal persons (p. 21-22).

- Application planned from 10 July 2027 (p. 21-22).

- Need to adapt to non-financial sector specificities, notably size, business model, and sanction thresholds (p. 22).

Technical advice on group policies and procedures (Article 16(4) AMLR):

- Recommendation to establish minimum standards for information sharing within groups, including personal data and suspicious activity information, with strict data protection safeguards (p. 22-23).

- Definition of acceptable uses of shared information, related to ML/TF risk assessments and group operations (p. 22-23).

- Importance of the parent company’s role and specific provisions for sharing with entities located outside the EU (p. 22-23).

- Applicability to the non-financial sector (p. 23).

Main Findings and Lessons Learned

Findings:

- National AML/CFT risk assessment approaches vary significantly, hindering supervision and creating costs for entities operating internationally (p. 8, 14).

- Data collected via the EuReCA database show divergences in sanction application and a lack of harmonized internal policies among supervisors (p. 18-19).

- Freedom to provide services is widely used but often without material activity in the concerned Member States (p. 12-13).

Assumptions:

- A harmonized and automated risk assessment methodology will enable better comparability and supervisory effectiveness (p. 9-10).

- Adoption of materiality thresholds to qualify activity under freedom to provide services will prevent irrelevant inclusions in direct supervision (p. 13).

Interpretations:

- The matrix approach combining inherent risk and control quality allows better targeting of supervisory efforts (p. 9).

- A phased transition with adapted compliance periods is necessary to limit risks related to new framework implementation (p. 16, 22).

Uncertainties:

- Adaptation of RTS to the non-financial sector remains to be defined, given entity diversity and lack of specific data (p. 10, 16, 22).

- Operational impact and costs for entities, notably regarding data collection and reporting, require monitoring during implementation (p. 9, 14).

- The effectiveness of harmonized sanction mechanisms will depend on their consistent application by national authorities and AMLA (p. 19-20).

Conclusions and Author’s Recommendations

The EBA concludes that the proposed regulatory technical standards (RTS) provide a solid foundation for a harmonized, proportionate, and effective European AML/CFT system, aligned with AMLA’s statutory objectives (p. 5).

It recommends that:

- AMLA continue the development and implementation of the proposed RTS, ensuring maximum coherence between mandates and a smooth transition, notably for the first direct supervision selection scheduled for July 2027 (p. 14, 42).

- Separate RTS be developed for the non-financial sector to adapt requirements to this sector’s specificities and ensure proportionate application (p. 10, 25, 57).

- AMLA establish guidelines on base fine amounts, covering all entity categories and breach types, with an entry into force aligned with RTS on sanctions (p. 21, 79).

- A harmonized framework for information sharing within groups be implemented, guaranteeing personal data protection while facilitating consolidated supervision (p. 22-23).

- Particular attention be paid to training and cooperation between national and European authorities to ensure consistent application of sanctions and measures (p. 73).

- AMLA regularly assess the operational impact of RTS and adjust methodologies and thresholds according to evolving ML/TF risks (p. 21, 22).

These measures aim to strengthen the resilience of the European AML/CFT system while limiting compliance costs for obliged entities.

Key takeaways

References

Year
2025
Type
Report
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2025-10/b5a9a9aa-ce4f-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.