# AMLR 2027 readiness for payment service providers

**In short:** from 10 July 2027, the EU Anti-Money Laundering Regulation — Regulation (EU) 2024/1624, the AMLR — applies directly to payment institutions and electronic money institutions in every Member State, and the national laws that transposed the Fourth Anti-Money Laundering Directive stop being the source of their obligations. For a payment service provider, the practical changes are a minimum list of customer information, a "25 % or more" beneficial-ownership test, a 14-day deadline to report register discrepancies, maximum intervals for refreshing customer files, and explicit conditions for automated and AI-assisted decisions. Much of the operational detail comes from AMLA's technical standards, some of which are still being finalised.

## Key takeaways

- The AMLR applies from **10 July 2027** (Art. 90). It is a regulation: no national transposition is needed.
- Payment institutions and e-money institutions are **obliged entities** (Art. 3(2) with Art. 2(1)(6)(a)).
- Two named roles: a **compliance manager** on the management body and a **compliance officer** (Art. 11).
- A beneficial owner holds **25 % or more**, or controls the entity by other means; both tests run in parallel (Arts. 51 to 53).
- Register discrepancies must be reported **within 14 calendar days** (Art. 24).
- Customer files must be refreshed at least **every year** for higher-risk customers and **every five years** for others (Art. 26(2)).
- Automated and AI-assisted decisions need **meaningful human intervention** (Art. 76(5)); the decision to onboard cannot be outsourced (Art. 18(3)).
- Records are kept **five years**, including refusals and assessments that did not lead to a report (Arts. 21(3) and 77).

## The timeline

| Date | What happens | Source |
|---|---|---|
| 26 June 2024 | AMLA Regulation enters into force | Regulation (EU) 2024/1620, Art. 108 |
| 9 July 2024 | AMLR and AMLD6 enter into force | AMLR Art. 90; AMLD6 Art. 79 |
| 1 July 2025 | AMLA Regulation applies | Regulation (EU) 2024/1620, Art. 108 |
| 10 July 2026 | Deadline for many AMLA drafts and guidelines, e.g. customer due diligence standards (Art. 28), risk factors (Art. 20(3)), ongoing monitoring (Art. 26(5)) | AMLR |
| 2 August 2026 | AI Act general date of application, including transparency duties (Art. 50) | Regulation (EU) 2024/1689, Art. 113 |
| By 1 July 2027 | AMLA starts its first selection of directly supervised entities | Regulation (EU) 2024/1620, Art. 13(4) |
| **10 July 2027** | **AMLR applies; AMLD6 transposition deadline; Directive (EU) 2015/849 repealed** | AMLR Art. 90; AMLD6 Arts. 77 and 78 |
| 2 December 2027 | AI Act high-risk requirements apply to Annex III systems | Regulation (EU) 2026/1744 |
| 10 July 2029 | AMLR applies to football agents and clubs; Commission assessment of lower beneficial-ownership thresholds due | AMLR Arts. 90 and 52(2) |

## Are payment and e-money institutions in scope?

Yes. The AMLR applies to "financial institutions" (Art. 3(2)). Art. 2(1)(6)(a) defines these by reference to the activities in Annex I to Directive 2013/36/EU, which include payment services (point 4) and issuing electronic money (point 15). Account information services are excluded.

Two provisions are specific to this sector. For payment initiation services, the merchant is treated as the customer (Art. 19(6)(d)). For certain low-value e-money products, supervisors may grant exemptions from some due diligence measures if strict conditions are met, including a non-reloadable instrument holding no more than EUR 150 (Art. 19(7)).

## What changes in practice

### Governance: two named roles

Art. 11(1) requires a **compliance manager**: a member of the management body in its management function, responsible for compliance with the AMLR. Art. 11(2) requires a **compliance officer** with sufficient standing, responsible for day-to-day controls, targeted financial sanctions and reporting suspicious transactions to the financial intelligence unit (FIU). The officer is protected against retaliation (Art. 11(4)), reports directly to the management body (Art. 11(5)), and the supervisor must be notified if the officer is removed (Art. 11(2)).

### A business-wide risk assessment owned by the compliance officer

Art. 10 requires a documented business-wide risk assessment covering money laundering, terrorist financing and the risk of sanctions evasion. The compliance officer drafts it; the management body approves it (Art. 10(2)). New products, channels and technologies need their own assessment before launch (Art. 10(1)).

### Customer due diligence with a minimum information list

Art. 20(1) lists the due diligence measures; Art. 22(1) lists the minimum information to collect for natural persons and legal entities; Art. 25 covers the purpose and intended nature of the relationship, including, where necessary, the source and destination of funds. AMLA's regulatory technical standards under Art. 28(1) will specify the information for standard, simplified and enhanced due diligence and the reliable and independent sources that may be used.

### Beneficial ownership: a new threshold, a parallel control test, and the register

A beneficial owner is anyone with an ownership interest of **25 % or more** (Art. 52(1)) — the current directive's default indicator is "more than 25 %" — or who controls the entity by other means, identified in parallel (Arts. 51 and 53). If no beneficial owner can be identified after exhausting all means, the firm records that fact and identifies the senior managing officials (Art. 22(2)). Firms must consult the central register (Art. 22(7)), collect proof of registration at onboarding (Art. 23(4)) and report discrepancies within 14 calendar days (Art. 24).

### Refresh cycles with hard maximums

Art. 26(2) caps the interval between customer information updates at one year for higher-risk customers and five years for all others. Art. 26(3) adds event-driven reviews when circumstances change.

### Sanctions checks on every new designation

Art. 20(1)(d) requires a check of targeted financial sanctions at onboarding, including control by, or more than 50 % ownership by, sanctioned persons. For credit and financial institutions, Art. 26(4) requires the check again upon any new designation.

### Automated and AI-assisted decisions

Art. 76(5) allows decisions resulting from automated processes or AI systems only if the data used are limited to due diligence data, any decision to accept, refuse or end a relationship (or to change the level of due diligence) is subject to meaningful human intervention, and the customer can obtain an explanation and challenge it — except in relation to a suspicious transaction report.

### Outsourcing: what stays in-house

Art. 18 allows outsourcing, with prior notification to the supervisor and full liability remaining with the firm. Some tasks can never be outsourced, including the decision on a customer's risk profile and the decision to enter into a relationship (Art. 18(3)(c) and (d)).

### Records: five years, including refusals

Art. 21(3) requires records of due diligence actions and decisions, including refusals. Art. 77 requires five-year retention, including the assessment of potentially suspicious activity whether or not a report was filed (Art. 77(1)(b)), and deletion afterwards unless other law requires otherwise.

## Direct supervision by AMLA: who is affected

AMLA periodically assesses credit and financial institutions operating in at least six Member States, including payment and e-money institutions (Regulation (EU) 2024/1620, Art. 12). Those whose residual risk is classified as high become "selected obliged entities" (Art. 13(1)). The first selection starts by 1 July 2027; direct supervision begins six months after the list is published (Art. 13(4)). For the first selection, AMLA takes the 40 entities or groups operating in the most Member States (Art. 106(2)). Other payment institutions normally stay with their national supervisor — in Belgium, the National Bank of Belgium (Law of 18 September 2017, Art. 85 §1, 3°) — although, in exceptional circumstances, a national supervisor may ask AMLA to take over a particular institution (Art. 14).

## A readiness checklist

1. Name the compliance manager and the compliance officer, and document their mandates and reporting lines.
2. Refresh the business-wide risk assessment against AMLR Art. 10 and Annexes I to III.
3. Map your onboarding data fields against AMLR Art. 22(1) and Art. 25, and plan for AMLA's Art. 28 standards.
4. Re-test beneficial-ownership logic for "25 % or more", multi-layer multiplication and control by other means.
5. Build a discrepancy workflow with a 14-day clock and an audit trail.
6. Set refresh schedules no longer than one year (higher risk) and five years (others).
7. Confirm sanctions re-screening upon every new designation.
8. Inventory every automated or AI-assisted step and document the human decision behind it.
9. Review outsourcing agreements against AMLR Art. 18, including the non-outsourceable decisions.
10. Check that records cover refusals and non-reported assessments, with five-year retention and deletion.

## Frequently asked questions

### Does the AMLR need to be transposed into national law?

No. It is "binding in its entirety and directly applicable in all Member States" (Art. 90). AMLD6, however, is a directive and must be transposed by 10 July 2027; national law will continue to organise supervisors, the FIU and registers, and to use the options the AMLR leaves to Member States, such as additional enhanced due diligence cases (Art. 34(6)) or lower cash limits (Art. 80(2)).

### Which rules apply until 10 July 2027?

National law transposing Directive (EU) 2015/849, as amended (notably by Directive (EU) 2018/843), together with supervisory regulations and EBA guidelines. In Belgium, that is the Law of 18 September 2017.

### Will AMLA supervise our payment institution directly?

Normally only if you operate in at least six Member States and AMLA classifies your residual risk as high (Arts. 12 and 13). In exceptional circumstances, your national supervisor may also ask AMLA to take over (Art. 14). Otherwise your national supervisor remains responsible.

### When will AMLA's technical standards be final?

AMLA consulted on draft standards on customer due diligence from 9 February to 8 May 2026. On AMLA's overview of 28 September 2026 that consultation was closed and the standards were not yet final. They become law only once adopted by the Commission as delegated regulations (AMLR Art. 28(4); Regulation (EU) 2024/1620, Art. 49).

### Can we let AI decide on onboarding?

Not on its own. AMLR Art. 76(5) requires meaningful human intervention in onboarding decisions, and Art. 18(3) keeps them inside the firm. The AI Act adds its own duties; see [What an auditor asks about AI in compliance](/guides/auditor-questions-ai-in-compliance/).

## Where ProofVolt fits

ProofVolt supports the AMLR's customer due diligence (Chapter III); beneficial ownership, including detecting and documenting register discrepancies and tracking their 14-day reporting deadline (Chapter IV); preparing suspicious transaction reports and holding customer contact until a reportability assessment is made (Chapter V); and record-keeping (Chapter VII). It investigates first — registers, sanctions and adverse media — and asks the customer only for what public sources cannot prove. Every conclusion carries its source on the case's receipt, every source, step and decision is kept in an append-only trail, and approvals can require a second pair of eyes where the risk requires it. The decision stays with your officer.

## Related

- [AMLR](/glossary/amlr/)
- [AMLA](/glossary/amla/)
- [Customer due diligence](/glossary/customer-due-diligence/)
- [Beneficial owner](/glossary/beneficial-owner/)
- [Ongoing monitoring](/glossary/ongoing-monitoring/)

Canonical: https://proofvolt.eu/guides/amlr-2027-readiness-payment-service-providers/
