BUSINESS

AMLR Regulation: what changes on July 10, 2027

September 15, 2026
Blog Image

The AMLR is not a directive but a directly applicable regulation: as of July 10, 2027, it will replace the French transposition of the 4th and 5th directives. Scope, due diligence, beneficial owners, deadlines, sanctions — here is what is really changing.

People often refer to the AMLR as "the new anti-money laundering directive." This is the most common misconception about this text, and it is not a trivial one: the AMLR is not a directive, it is a regulation. A directive must be transposed — each Member State adapts it to its own law, at its own pace, and with its own room for interpretation. A regulation applies directly, as is, in all twenty-seven Member States, without the need for national legislation to implement it.

This is precisely why July 10, 2027 marks a reset rather than a simple update. On that date, Articles L. 561-1 et seq. of the Monetary and Financial Code — the French transposition of the 4th and 5th directives — will give way to the European text itself. Your internal procedures are not just changing in content: they are changing their legal basis.

This guide provides an overview of the AML package, its actual timeline, and what the regulation concretely changes for a French obligated entity.

The AML package: four texts, not just one

The AMLR does not stand alone. Published in the Official Journal of the European Union on June 19, 2024, and having entered into force on July 9, 2024, it forms a set with three other texts:

  • Regulation (EU) 2024/1624 — the AMLR. The "single rulebook" (single rulebook): it contains all the obligations for obligated entities — due diligence, beneficial owners, reporting, and record-keeping. Applicable from July 10, 2027, except for football agents and professional clubs, which are covered as of July 10, 2029.
  • Directive (EU) 2024/1640 — AMLD6. It covers areas that remain under national jurisdiction: the organization of supervisory authorities and financial intelligence units, beneficial ownership registers, access to information, and sanction regimes. Transposition required by July 10, 2027, with earlier deadlines for certain articles.
  • Regulation (EU) 2024/1620 — AMLA. It establishes the European Anti-Money Laundering Authority, headquartered in Frankfurt am Main. Applicable since July 1, 2025.
  • Regulation (EU) 2023/1113 — the TFR. Predating the package, it extends the information requirements that accompany fund transfers to crypto-asset transfers. Applicable since December 30, 2024.

AMLD6 repeals Directive (EU) 2015/849. Article 89 of the AMLR specifies that references to that directive are now to be construed as references to the regulation and AMLD6, in accordance with a correlation table set out in Annex VI. In practice, this is the most useful transition tool for a compliance team: it allows for mapping an existing framework article by article.

Why "regulation" instead of "directive" changes everything

Article 90 of the AMLR is unambiguous: the text is "binding in its entirety and directly applicable in all Member States." This has three practical consequences.

National discretion disappears. Regulations are not transposed: the provisions of the Monetary and Financial Code that replicate the content of the AMLR are no longer necessary. Only those elements that AMLD6 expressly leaves to the national level will remain in French law—the organization of the ACPR, the AMF, and Tracfin, the beneficial ownership register, the sanction regime, and the few explicitly provided national options.

The internal framework is changing its foundation. Any procedure, compliance note, risk map, or control matrix that cites "Article L. 561-5" or "Article R. 561-5-1" must be rewritten to reference the AMLR articles. This is not just a matter of form: these article numbers appear throughout control plans, audit reports, and responses to client questionnaires.

Comparability is now the rule. Until now, a group operating in several Member States applied different transpositions of the same text. From 2027, the standard will be identical everywhere—which simplifies group structures but also eliminates the ability to choose between jurisdictions.

The actual timeline, from 2024 to 2029

  • June 19, 2024 — publication of the package in the OJEU.
  • July 9, 2024 — entry into force of the AMLR and AMLD6.
  • December 30, 2024 — application of the TFR (transfer of funds and crypto-assets).
  • July 1, 2025 — the AMLA regulation becomes applicable; the Authority ramps up operations in Frankfurt.
  • July 10, 2026 — early transposition deadline for several articles of the AMLD6, particularly those relating to access to beneficial ownership registers, and the deadline for Commission delegated acts on categories of offenses and sanction criteria related to beneficial owners.
  • July 1, 2027 at the latest — the AMLA begins its first selection process for entities it will supervise directly; the selection process lasts a maximum of six months.
  • July 10, 2027application of the AMLR and the transposition deadline for AMLD6.
  • During 2028 — start of direct supervision by AMLA. The regulation does not set a specific calendar date: it stipulates that supervision begins six months after the publication of the list of selected entities. January 1, 2028, which is often cited, represents the earliest possible scenario.
  • July 10, 2029 — application of the AMLR to football agents and professional clubs; deadline for the Commission's assessment of a potential lower beneficial ownership threshold for certain sectors.

Who will fall under direct AMLA supervision?

AMLA will evaluate credit and financial institutions — and groups — active in at least six Member States, and will select those with a high residual risk profile. The regulation indicatively caps the first wave at around forty entities.

One point deserves attention: when no institution from a given Member State is selected, AMLA conducts an additional selection procedure in that state. In other words, at least one French entity is expected to fall within the scope of direct supervision. For all others, the ACPR remains the supervisor — but under the coordination of AMLA.

What the AMLR changes in practice

An expanded scope of obligated entities

Article 3 adds several categories to the list of obligated entities: crowdfunding service providers and intermediaries, non-bank mortgage and consumer credit intermediaries , traders and intermediaries in cultural goods and high-value goods from €10,000, warehouse operators in free zones, providers of investment-based immigration services, non-financial mixed holding companies, and real estate agents, including for rentals with a monthly rent of €10,000 or more.

A point often misreported: crypto-asset service providers do not constitute a new category under Article 3. They are obligated because the definition of "financial institution" encompasses them. The regulation then specifically targets them on several points—enhanced due diligence for crypto-asset correspondent relationships, exclusion from the €1,000 threshold applicable to occasional fund transfers, and the prohibition of anonymous accounts.

Harmonized — and timed — customer due diligence

Articles 19 to 28 establish an identical due diligence procedure throughout the Union. Two structural changes:

The content of the identification process is no longer negotiable. Article 22 provides an exhaustive list of the data to be collected: all first names and surnames, the place and full date of birth, nationalities, national identification number where applicable, and place of residence. More flexible — or more stringent — national practices will have to converge.

Sanctions screening is now part of the due diligence process itself. Article 20 requires verifying whether the client or their beneficial owners are subject to targeted financial sanctions, just as with identification. It is no longer a parallel check; it is a step in the due diligence process.

Added to this are specific timeframes to be integrated into systems:

  • client file updates: one year maximum for high-risk clients, five years for others (art. 26);
  • for simplified due diligence, identity verification no later than sixty days after the start of the business relationship (Art. 33);
  • reporting a discrepancy with the register of beneficial owners within fourteen calendar days of its detection (Art. 24);
  • triggering due diligence for any occasional transaction of €10,000 or more (Art. 19), lowered to €1,000 for occasional fund transfers by credit and financial institutions.

Beneficial owners: the threshold remains at 25%, but the method is changing

This is the point about which the most misinformation is circulating. As of July 10, 2027, the threshold remains set at 25% of capital ownership or voting rights (Art. 52). The much-discussed "drop to 15%" does not exist at this date: the regulation provides that by no later than July 10, 2029, the Commission may, via delegated acts and for high-risk categories of companies only, set a lower threshold—a floor of 15% and a ceiling strictly below 25%.

What is actually changing is the method. Article 51 states that control by other means is assessed "independently and in parallel" to capital participation: the two criteria are cumulative, not alternative. Indirect holdings are calculated by multiplying along each chain, then adding the chains together, taking into account all levels of ownership.

Two new obligations are worth noting:

  • Foreign legal entities — established outside the Union — must declare their beneficial owners in a central European register when they enter into a business relationship with an obligated entity, acquire real estate in the Union, or certain high-value goods (Art. 67).
  • Union entities must keep their information "adequate, accurate, and up-to-date," register any changes within twenty-eight days and verify it at least once a year (Art. 63).

Enhanced due diligence: third countries, PEPs, high-net-worth individuals

The regime for third countries is overhauled into three categories — significant strategic deficiencies, compliance deficiencies, and specific and serious threats — identified by the Commission through delegated acts (Arts. 29 to 31).

The regime for politically exposed persons is specified: authorization from a high-level member of the hierarchy, establishment of the source of wealth and the source of funds, and ongoing enhanced monitoring. Each Member State and the Commission shall publish a list of prominent public functions (Art. 42 and 43). The regulation also governs the exit from PEP status, which was long left to individual discretion (Art. 45).

A significant new development for private banking and wealth management: Article 34 imposes specific measures when a high-risk relationship involves the processing of assets of at least 5 million euros by bespoke services, for a client whose total wealth reaches 50 million euros — excluding primary residence. Added to this are additional details on the source of funds and a mechanism for preventing conflicts of interest.

Data retention: five years, then deletion

Article 77 sets a retention period of five years, calculated from the end of the business relationship, the execution of the occasional transaction, or the date of refusal to enter into a relationship. At the end of this period, the regulation mandates theerasure of personal data.

This is a fundamental shift. Where directives previously allowed states the option of extending retention, the regulation imposes an active obligation to delete—making this a matter of system architecture, not just retention policy. The text also specifies that retained documents must not be redacted.

Outsourcing: prior notification to the supervisor

Article 18 permits the outsourcing of certain tasks but sets clear boundaries: the obligated entity must inform its supervisor before the service provider begins performing the tasks. Service providers are considered part of the entity, and the entity "remains fully responsible" for any acts or omissions related to the outsourced tasks.

For any fintech or institution that relies on identity verification or document analysis providers, this is a new formality to incorporate into your timeline—and a reason to rigorously document your processing chain.

The €10,000 cash limit changes nothing in France

Article 80 establishes a European ceiling of €10,000 for cash payments. Many interpreted this as a relaxation of the French €1,000 limit: it is the opposite. The same article expressly provides that lower national limits already in force continue to apply. The French ceiling, set by the Monetary and Financial Code, therefore remains at €1,000 for a debtor with a tax domicile in France or acting in a professional capacity.

Risks for non-compliant entities

The sanctions regime is not in the AMLR but in AMLD6, which delegates it to Member States while setting minimum thresholds.

For serious, repeated, or systematic breaches for internal control, due diligence, reporting, or record-keeping obligations, the maximum financial penalty must reach at least twice the benefit derived from the breach, or one million euros if that amount is higher.

For a credit or financial institution, the floor rises to 10 million euros or 10% of total annual turnover — whichever is higher — for a legal entity, and to 5 million euros for a natural person.

Getting ready: what remains to be done before July 2027

The deadline may seem far off. It is not for those who need to overhaul a framework, reclassify a customer database, and adapt systems. A reasonable roadmap:

  1. Map the gap. Use the correspondence table in Annex VI to remap existing procedures article by article and identify what is being removed, what is becoming stricter, and what is new.
  2. Verify the scope. Confirm whether the activity falls into a newly subject category under Article 3 — this is the starting point, and it affects more players than you might think.
  3. Align identity collection with the harmonized list in Article 22, including fields that are currently optional in your forms.
  4. Operationalize deadlines. One-year and five-year reviews, sixty days for simplified due diligence, fourteen days for beneficial ownership discrepancies: these are engine rules, not procedural guidelines.
  5. Integrate sanctions screening into the due diligence workflow rather than as a separate check.
  6. Revise the beneficial ownership calculation method — dual ownership/control test, multi-level chains, foreign entities.
  7. Review the retention policy to shift from a minimum duration approach to an expiration-based deletion model.
  8. Inventory subcontractors subject to Article 18 and prepare for supervisor notification.
  9. Assess AMLA exposure : if you operate in six or more Member States, direct supervision is a scenario to address now.

Automate what is now time-bound

The AMLR reveals a constant: the regulation transforms principles into deadlines and mandatory fields. Annual or five-year reviews, sixty-day verification, fourteen-day reporting, five-year deletion, closed lists of identification data, and screening integrated into due diligence. These are requirements that manual systems struggle to scale, and which supervisors will be able to audit line by line.

Dataleon automates this chain: collection and analysis of identity and corporate documents, structured extraction, forgery detection, beneficial owner identification, screening, and timestamped retention of audit trails — in France, Europe, and the OHADA region.

Request a demo →

Auteur

Autres blogs connexes

No items found.

Frequently Asked Questions

Does Dataleon provide support?
Yes. Every client receives dedicated support, including technical assistance via email and video conferencing, comprehensive documentation, and code samples for integrating our APIs. Our engineers help you define your KYC and KYB workflows, complete the integration, and go live without service interruption. A dedicated point of contact remains available afterward to monitor your volumes, adjust your control rules, and answer your business and technical questions.
Are my files deleted after processing?
Yes. Your documents are encrypted in transit and at rest, processed, and then automatically deleted after the retention period you define. You remain the sole owner of the data transmitted: it is neither resold nor used for any purpose other than performing your checks. You can also trigger the immediate deletion of a file from the interface or via the API, keeping only the analysis results necessary for your compliance obligations.
Can Dataleon be integrated into our tools via API?
Yes. Dataleon connects to your information system via a documented REST API, real-time webhooks, and connectors for your existing tools, such as CRM, core banking, DMS, or electronic signature solutions. Verification flows, scoring rules, risk thresholds, and validation workflows are fully customizable to align with your internal procedures. Our teams can also develop custom processes if your specific use case requires it.
Can I test Dataleon before committing?
Yes. You can enjoy a 15-day free trial, with no obligation, to verify your own identity documents, proof of address, and business documents, and to evaluate the quality of our extraction and KYC/KYB checks. During these 15 days, you will have access to the interface and test API keys to validate your end-to-end technical integration. We also offer a personalized demo with an expert to help you build a workflow tailored to your business.
Are you GDPR compliant with servers located in France?
Yes. Dataleon is GDPR compliant, and all data processing and storage are carried out in France on the infrastructure of Scaleway, a sovereign French hosting provider. We implement encryption for data in transit and at rest, data minimization, granular access control, and full audit trails for all operations. A Data Processing Agreement (DPA) and our security documentation are provided to facilitate your internal and regulatory audits.

Automation that makes compliance invisible.

Dataleon, the missing link between your compliance and your growth. KYC, KYB, and AML-CFT, finally all in one place.