From target process to a prioritised gap list.
Reference process (target state)
The blueprint lays out the documented target process across its modules — every step anchored to the article or clause it derives from.
Map your current state
Map your existing processes module by module against the reference — system of record, owner, last review.
See the gaps
Each module yields a gap status (absent · partial · met) with a severity, a concrete remediation action and a target date.
Evidence, not opinion
The deterministic scanner grades the controls; the specialist advisor assists with the mapping — grounded in the regulation, ready for the auditor.
12 modules, each control covered exactly once.
The reference process groups all 41 AMLR controls into 12 modules — from governance to the cash limit.
Governance & internal controls
Approved policies, an AML officer with an independent reporting line, group-wide rollout and an outsourcing register.
Business-wide risk assessment (BWRA)
Identify and assess inherent ML/TF risk across customers, products, channels and geographies; sign-off by the management body.
Training & staff integrity
Role-based AML/CFT training with tracked completion and integrity screening for risk-exposed staff.
Onboarding & customer due diligence (CDD)
Trigger CDD, identify the customer and beneficial owner, record purpose, and branch to simplified or enhanced measures by risk.
Identity verification (KYC)
Verify identity from reliable independent sources before the relationship; stop and consider an STR where CDD cannot be completed.
Beneficial ownership (UBO)
Identify the natural-person owner via the 25% ownership and control tests; reconcile against the central BO register.
Enhanced due diligence (EDD)
EDD for PEPs, high-risk-country nexus and correspondent relationships; reject shell institutions; mitigate self-hosted crypto.
Ongoing monitoring
Scrutinise transactions against the risk profile, keep CDD current, and escalate qualifying alerts to reporting.
Sanctions — UN measures
Screen against UN financial-sanctions lists and apply temporary restrictive measures pending EU transposition.
Suspicious activity reporting (STR/SAR)
Report suspicion to the FIU promptly, refrain from executing, and observe the anti-tipping-off rule.
Record retention & data protection
Retain CDD and transaction records for five years within GDPR safeguards; provide them to authorities on request.
Anonymous instruments & cash limit
Prohibit anonymous accounts and bearer instruments; block cash payments over EUR 10,000 in trade of goods or services.
A draft standard, honestly labelled.
Several Level-2 standards (RTS/ITS) from AMLA and the EBA are still in consultation, so a blueprint generated today is a draft, not a final standard. Controls that depend on them are marked as pending, and every control and process step carries its real AMLR article reference and source. The legal text is never conflated with our process opinion.
Set up your AML blueprint together.
30 minutes with our team: we walk the target process, map it against your current state and show the path to a prioritised gap list — no sales loop.