Home › Academy › Library › Opinion and Report on money laundering and…
Synthesis note · Report

Opinion and Report on money laundering and terrorist financing risks affecting the EU's financial sector

European Banking Authority (EBA) · 2025 · Report · 69 pages · Intermediate

This report examines the money laundering and terrorist financing (ML/TF) risks in the EU's financial sector. It highlights the challenges posed by FinTech firms, the use of regulatory technologies, and concerns regarding competent authorities' ability to manage these risks. The report also emphasizes the increasing risks associated with the use of stablecoins and the persistent weaknesses in managing politically…

General Information

Document: Opinion and report of the European Banking Authority (EBA) on money laundering (ML) and terrorist financing (TF) risks affecting the financial sector of the European Union.

Author: European Banking Authority (EBA).

Date: 28 July 2025.

Scope: Analysis of ML/TF risks in the European financial sector, covering 29 Member States and EEA countries, for the period January 2022 to December 2024. The report is based on responses from 52 AML/CFT competent authorities, the EuReCA database, and EBA’s supervisory and coordination work.

Themes: Assessment of transversal and sectoral ML/TF risks, notably FinTech, RegTech, crypto-assets, fraud, restrictive measures, risks related to politically exposed persons (PEPs), tax crimes, environmental crimes, and AML/CFT control effectiveness.

Limitations: Only the first 42 pages of the full report (69 pages) are available for this summary.

Executive Summary

Subject: This fifth biennial EBA Opinion analyses money laundering and terrorist financing risks in the EU financial sector, in a context of rapid technological innovation and regulatory reforms.

Importance: The report informs European legislators and AML/CFT competent authorities to improve risk-based supervision and support the European Commission’s supranational risk assessment.

Main findings:

- The ML/TF landscape is complex and evolving, marked by rapid growth of FinTech, RegTech, crypto-assets, and increasing use of artificial intelligence (AI).

- 70% of competent authorities report high or increasing ML/TF risks in the FinTech sector, often due to prioritizing growth over AML/CFT compliance.

- Inadequate use of RegTech solutions causes compliance failures, with more than half of material weaknesses linked to these technologies.

- The crypto-asset sector sees a 2.5-fold increase in authorized providers, but major AML/CFT control gaps persist.

- Fraud and cybercrime risks, amplified by automation and AI, are rising rapidly, posing major challenges to institutions.

- Risks related to restrictive measures (sanctions) increase due to regime complexity, with weaknesses in filtering systems.

- Progress is noted in reducing risks related to tax crimes and unjustified de-risking.

- Risks related to products and services now exceed those related to clients.

Conclusions:

- The fight against ML/TF must adapt to technological evolution and growing complexity of financial services.

- Consistent and clear application of risk-based approaches is essential.

- Enhanced supervision, notably in FinTech, crypto, payment, and electronic money sectors, is crucial.

Recommendations:

- Continue promoting best practices in AML/CFT technology use.

- Strengthen coordination and enforcement of the new European regulatory framework, notably for crypto-assets and restrictive measures.

- Improve training and skills of sector actors to face AI and sophisticated fraud risks.

- Intensify competent authorities’ actions to close identified gaps, notably in customer due diligence (CDD) and PEP monitoring.

(p. 1-4, 11-12)

Context and Objectives

The Opinion is established pursuant to Article 6(5) of Directive (EU) 2015/849, which requires the EBA to publish every two years an assessment of ML/TF risks affecting the European financial sector. It aims to inform European co-legislators and AML/CFT competent authorities on the application of risk-based approaches in supervision.

The report is based on comprehensive data collection between January 2022 and December 2024, including responses from 52 competent authorities from 29 Member States and EEA countries, EuReCA data, as well as results from supervisory work and peer reviews conducted by the EBA.

The challenges are to adapt AML/CFT supervision to rapid financial technology developments, identify emerging vulnerabilities, and contribute to coherent implementation of the new European regulatory framework.

The scope covers all financial sectors under EBA competence, with particular focus on FinTech, RegTech, crypto-assets, fraud, restrictive measures, PEPs, tax and environmental crimes.

Limitations include absence of public consultation and cost-benefit analysis, exclusion of data after December 2024, and non-inclusion of external stakeholders such as the Banking Stakeholder Group.

(p. 1-3, 12-13)

Summary of Key Points by Theme

FinTech:

- Rapid growth of FinTech and electronic money institutions, with increasing integration by traditional institutions.

- 69% of competent authorities report high or rising ML/TF risk, linked to prioritizing growth over compliance.

- Major vulnerabilities: cybercrime, outsourcing without effective control, insufficient CDD controls and transaction monitoring.

- Lack of expertise and adapted governance in many FinTechs, exposing the sector to increased risks.

White labelling:

- Practice where an unregulated entity offers financial products under the brand of an authorized entity.

- High risks (90% of authorities) related to contract complexity, difficult supervision, and cross-border nature.

- Authorities lack visibility on the extent of these practices, complicating supervision.

Virtual IBANs (vIBANs):

- High risks for payment and credit institutions, notably regarding end-user identification and transaction transparency.

- Risk of vIBAN cascades and regulatory arbitrage due to divergent definitions.

- AMLR regulation planned for July 2027 introduces registration and identification measures.

RegTech:

- Significant potential to improve compliance and reduce manual errors.

- 50% of authorities identify risks linked to inadequate use, notably outsourcing, unsupervised automation, and lack of internal skills.

- Concentration of solutions among few providers, often not tailored to specific needs, creating systemic vulnerabilities.

- More than half of material weaknesses reported to EuReCA relate to RegTech issues.

Crypto-assets:

- 2.5-fold increase in authorized providers between 2022 and 2024, with strong growth in transaction volumes.

- Persistent weaknesses in AML/CFT systems, notably in risk knowledge related to clients and their activities.

- Governance and integrity risks of management in some CASPs.

- Growing interconnection between CASPs and other financial sectors, increasing contagion risks.

- Introduction of MiCA and FTR regulatory framework end 2024, with 14 regulatory instruments to govern the sector.

Terrorism:

- Overall stable TF risk, with variations linked to geopolitical situation and extremism.

- Growing use of stablecoins for terrorist financing, due to their stability and ease of transfer.

- Weaknesses in TF risk management, notably excessive reliance on targeted sanctions lists.

- 62 material TF weaknesses reported to EuReCA between 2022 and 2024, related to risk assessment, transaction monitoring, and filtering tools.

Fraud and cybercrime:

- Rapid expansion of fraud, fueled by automation and AI, with sophisticated techniques such as deepfakes.

- Major payment fraud, with €4.3 billion in 2022 and €2 billion in the first half of 2023.

- Increased difficulties for institutions to detect and counter these attacks.

- Concrete cases of AI use to bypass identity controls during remote onboarding.

Restrictive measures (sanctions):

- Increasing complexity of sanctions regimes, notably sectoral, difficult to manage with standard tools.

- Weaknesses in filtering systems, governance, and record keeping.

- Specific risks related to SEPA instant payments and card payment infrastructures, with fragmentation and lack of transparency.

- Publication in 2024 of two series of EBA guidelines on compliance with restrictive measures, applicable end 2025.

De-risking:

- Unjustified de-risking phenomenon decreasing, with 80% of authorities having taken measures to address it.

- Awareness actions, targeted inspections, and stakeholder exchanges.

Tax crimes:

- ML/TF risks related to tax crimes perceived as decreasing or stable in most Member States.

- Multiple initiatives of enhanced supervision, information exchange, and training.

- 39 material weaknesses reported, mainly in life insurance and money transfer services.

PEPs and corruption:

- Stable risks related to PEPs, with 203 material weaknesses reported, notably in investment firms.

- Growing use of crypto and FinTech for bribery transfers.

- Internal corruption in financial institutions underestimated, requiring better cooperation between AML/CFT, prudential, and anti-corruption authorities.

- Proposed European directive on anti-corruption strengthening corporate criminal liability.

Environmental crimes:

- ML/TF risks rarely identified, but attention paid to waste trafficking and illegal resource exploitation.

- Actions by some authorities to monitor these sectors and train staff.

- Publication in January 2025 of EBA guidelines on ESG risk management.

(p. 14-33)

Main Findings and Lessons Learned

Established facts:

- Strong increase in ML/TF risks in FinTech, crypto, payment, and electronic money sectors.

- Widespread weaknesses in AML/CFT control application, notably in customer due diligence (CDD).

- Growth of sophisticated fraud and cyberattacks, with significant financial impact.

- Improved controls and reduced residual risks in credit institutions, investment funds, and life insurance sectors.

- Decrease in unjustified de-risking phenomenon.

Hypotheses:

- Rapid technological innovation exceeds institutions’ capacity to effectively manage ML/TF risks.

- Growing interconnection between traditional and innovative sectors increases contagion risks.

- Implementation of the new European regulatory framework should improve the situation.

Interpretations:

- The financial sector faces a delicate balance between innovation and compliance.

- Competent authorities must strengthen their capacities to effectively supervise new risks.

- Uncritical use of RegTech technologies can worsen vulnerabilities.

Uncertainties:

- Full impact of new MiCA and AMLR regulations on risk reduction.

- Institutions’ ability to integrate AI responsibly and effectively in AML/CFT processes.

- Evolution of criminal typologies related to emerging technologies.

(p. 14-36)

Conclusions and Author’s Recommendations

The EBA concludes that the ML/TF landscape in the EU financial sector is marked by increased complexity due to technological innovation and diversification of financial services. AML/CFT compliance struggles to keep pace with these developments, exposing the sector to high risks, notably in FinTech, crypto-assets, payment, and electronic money.

The EBA recommends:

- Consistent and strengthened application of risk-based approaches across the EU.

- Strengthening competent authorities’ capacities to effectively supervise new risks, notably through targeted inspections and information exchanges.

- Promoting best practices in RegTech technology use, with particular attention to governance, internal skills, and solution customization.

- Enhanced coordination to ensure effective implementation of the European regulatory framework, notably MiCA, AMLR, and guidelines on restrictive measures.

- Development of specific measures to counter risks related to AI, sophisticated fraud, and new criminal typologies.

- Continued efforts to reduce unjustified de-risking and ensure equitable access to financial services.

- Integration of risks related to tax crimes, corruption, and environmental crimes into AML/CFT strategies.

These recommendations are accompanied by continuous monitoring of sector developments and adaptation of supervisory tools.

(p. 4, 11-12, 36-38)

Key takeaways

References

Year
2025
Type
Report
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2025-07/13ae2f94-dc04-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.