Skip to main content

AML, as a reference process you can map against.

Regulation (EU) 2024/1624 turned into a documented target process across 12 modules and 41 grounded controls — so your bank can map its own processes against it and close the gaps before 10 July 2027.

41
grounded controls
12
process modules
2027
AMLR application · 10 Jul
Regulation (EU) 2024/1624 (AMLR)
Application date
10 July 2027
Controls
41 (1:1 to articles)
Process modules
12
Chapters covered
9
Grounding
Article + source on every step
Map & Gap

From target process to a prioritised gap list.

01

Reference process (target state)

The blueprint lays out the documented target process across its modules — every step anchored to the article or clause it derives from.

02

Map your current state

Map your existing processes module by module against the reference — system of record, owner, last review.

03

See the gaps

Each module yields a gap status (absent · partial · met) with a severity, a concrete remediation action and a target date.

04

Evidence, not opinion

The deterministic scanner grades the controls; the specialist advisor assists with the mapping — grounded in the regulation, ready for the auditor.

Target process

12 modules, each control covered exactly once.

The reference process groups all 41 AMLR controls into 12 modules — from governance to the cash limit.

Art. 9–18

Governance & internal controls

Approved policies, an AML officer with an independent reporting line, group-wide rollout and an outsourcing register.

Art. 10

Business-wide risk assessment (BWRA)

Identify and assess inherent ML/TF risk across customers, products, channels and geographies; sign-off by the management body.

Art. 12–13

Training & staff integrity

Role-based AML/CFT training with tracked completion and integrity screening for risk-exposed staff.

Art. 19–28

Onboarding & customer due diligence (CDD)

Trigger CDD, identify the customer and beneficial owner, record purpose, and branch to simplified or enhanced measures by risk.

Art. 21–23

Identity verification (KYC)

Verify identity from reliable independent sources before the relationship; stop and consider an STR where CDD cannot be completed.

Art. 24, 51–53, 62–63

Beneficial ownership (UBO)

Identify the natural-person owner via the 25% ownership and control tests; reconcile against the central BO register.

Art. 29–42

Enhanced due diligence (EDD)

EDD for PEPs, high-risk-country nexus and correspondent relationships; reject shell institutions; mitigate self-hosted crypto.

Art. 26

Ongoing monitoring

Scrutinise transactions against the risk profile, keep CDD current, and escalate qualifying alerts to reporting.

Art. 27

Sanctions — UN measures

Screen against UN financial-sanctions lists and apply temporary restrictive measures pending EU transposition.

Art. 69–74

Suspicious activity reporting (STR/SAR)

Report suspicion to the FIU promptly, refrain from executing, and observe the anti-tipping-off rule.

Art. 76–78

Record retention & data protection

Retain CDD and transaction records for five years within GDPR safeguards; provide them to authorities on request.

Art. 79–80

Anonymous instruments & cash limit

Prohibit anonymous accounts and bearer instruments; block cash payments over EUR 10,000 in trade of goods or services.

Accuracy first

A draft standard, honestly labelled.

Several Level-2 standards (RTS/ITS) from AMLA and the EBA are still in consultation, so a blueprint generated today is a draft, not a final standard. Controls that depend on them are marked as pending, and every control and process step carries its real AMLR article reference and source. The legal text is never conflated with our process opinion.

Book a demo

Set up your AML blueprint together.

30 minutes with our team: we walk the target process, map it against your current state and show the path to a prioritised gap list — no sales loop.