The EU AML package changes duties and supervisory responsibilities. The AMLR sets directly applicable requirements for obliged entities, while AMLD6 requires national transposition and the AMLA Regulation establishes the European supervisory framework. Institutions need to connect these instruments with their different application dates.
What is the EU AML package and what changes in 2027?
The EU AML package consists of three core legal acts published in the EU Official Journal in 2024. The first and most operationally significant is the AMLR (Anti-Money Laundering Regulation), Regulation (EU) 2024/1624 (EUR-Lex). As an EU regulation, it applies directly in all Member States without any national transposition act. It is the so-called Single Rulebook of AML regulation: uniform obligations on customer due diligence (CDD), the identification of beneficial owners and the internal management of money laundering risk. The AMLR applies from 10 July 2027 (Art. 90 AMLR; for professional football from 10 July 2029); it replaces large parts of the German Anti-Money Laundering Act (GwG) to the extent the GwG previously transposed the relevant EU directives.
The main AMLD6 transposition deadline is 10 July 2027. Articles 11, 12, 13 and 15 had an earlier deadline of 10 July 2026. The 10 July 2029 deadline concerns Article 18 on access to real-estate information, rather than a general deadline for interconnecting bank-account registers. Directive (EU) 2024/1640, Article 78
AMLA plans to begin direct supervision during 2028. Legally, supervision starts six months after publication of the selection list. The first selection process must begin by 1 July 2027 and finish within six months; Article 13 does not set 1 January 2028 as a fixed start. Regulation (EU) 2024/1620, Article 13 AMLA: About AMLA, timeline
Which deadlines apply? (Timeline to 2029)
The table below lists all key deadlines of the EU AML package through 2029 with the legal reference. Deadlines under national law (GwG, GwG-MeldV, goAML) are shown separately.
| Date | Event | Legal basis |
|---|---|---|
| 1 July 2025 | AMLA commences operations in Frankfurt | Regulation (EU) 2024/1620, Art. 108 |
| 1 September 2025 | goAML: two-factor authentication becomes mandatory | FIU/Zoll |
| 1 March 2026 | GwG-MeldV enters into force: reports under Sections 43, 44 GwG must be submitted digitally via goAML only (XML/form fields), with uniform formal and substantive standards | FIU/Zoll |
| 10 July 2026 | AMLD6: transposition of Articles 11, 12, 13 and 15 | Art. 78 AMLD6 |
| 10 July 2027 | AMLR applies; AMLD6 main transposition; GwG displaced in large part | Regulation (EU) 2024/1624, Art. 90 |
| 2028, following selection | AMLA direct supervision: six months after publication of the selection list | Art. 13 VO (EU) 2024/1620 |
| 10 July 2029 | AMLR for professional football; AMLD6 Article 18 on access to real-estate information | Art. 90 AMLR; Art. 78 AMLD6 |
What does the AMLA do in Frankfurt?
The Anti-Money Laundering Authority (AMLA) is based in Frankfurt am Main (Art. 4 AMLA Regulation (EU) 2024/1620, EUR-Lex) and commenced operations on 1 July 2025 (BMF). The AMLA is the first cross-sector EU supervisory authority in the field of anti-money laundering.
AMLA plans to begin direct supervision during 2028. Legally, supervision starts six months after publication of the selection list. The first selection process must begin by 1 July 2027 and finish within six months; Article 13 does not set 1 January 2028 as a fixed start. AMLA plans an initial selection of 40 directly supervised entities. The selection rules in Article 13 must be considered separately; the Regulation does not establish 40 as an absolute maximum. Regulation (EU) 2024/1620, Article 13 AMLA: About AMLA, timeline
Over all other obliged entities the AMLA acts indirectly, coordinating the national supervisory authorities. In Germany these include BaFin and other supervisors depending on the category of obliged entity. The AMLA has wide-ranging powers, including the imposition of fines and periodic penalty payments (Art. 5(2) and Art. 21 to 23 AMLA Regulation, EUR-Lex).
Who is obliged under the AMLR?
Article 3 AMLR defines obliged entities. They include credit and financial institutions and specified professional activities. Each institution needs to map its duties to the relevant category and the applicable future EU and national provisions. Regulation (EU) 2024/1624, AMLR
Important for the practical transition: existing references to the previous Fourth Anti-Money Laundering Directive (Directive (EU) 2015/849) in contracts, articles of association or internal policies are treated, from 10 July 2027, as references to the AMLR or AMLD6 respectively, where the correspondence table in Annex VI to the AMLR (Art. 89 AMLR) indicates a mapping. Reviewing existing internal regulations for outdated directive references is therefore part of the preparation work.
Who is a beneficial owner – today and from 2027?
Under Section 3 of the current GwG (gesetze-im-internet.de), the beneficial owner is the natural person who directly or indirectly holds more than 25 per cent of the shares or voting rights, or exercises control in a comparable manner. If no beneficial owner can be identified, the legal representative is treated as the notional beneficial owner.
From 10 July 2027, the AMLR definition applies directly. Art. 52(1) AMLR defines the relevant ownership interest as direct or indirect ownership of 25 per cent or more in the legal entity. Art. 53(2)(c) AMLR defines "control through ownership interest" as holding more than 50 per cent of the shares. For categories of legal entities classified as high-risk by the Member States, the Commission may set a lower threshold by delegated act, up to a maximum of 15 per cent (Art. 52(2) AMLR).
In practice, the AMLR means that identifying and verifying the beneficial owner cannot rely solely on the beneficial ownership register. Compare register entries with other information and investigate discrepancies. This summary does not replace assessment of the individual due diligence requirements.
When must a suspicious transaction report be filed with the FIU?
The obligation to file a suspicious transaction report arises from Section 43(1) of the GwG (gesetze-im-internet.de). Suspicious matters must be reported without delay to the FIU (Financial Intelligence Unit, based at German Customs). The reporting channel is goAML; two-factor authentication for goAML has been mandatory since 1 September 2025 (FIU/Zoll, technical note).
Since 1 March 2026, suspicious transaction reports must account for the reporting ordinance and FIU technical instructions. Successful formal transmission and substantive fulfilment of the reporting duty require separate checks. FIU: technischer Hinweis zur GwG-Meldeverordnung
How often must customer data be updated (KYC)?
BaFin's interpretive and application guidance (AuA) on the GwG was revised at the beginning of 2025 (valid from 02/2025, supplemented 03/2025 with the inclusion, among other things, of crypto-asset service providers; BaFin announcement of 6 March 2025). The AuA provides for a risk-based update obligation: for standard or medium risk, customer data must be updated at the latest every 5 years; for enhanced risk, the obligation is to update at least annually. The retention period for documents is 5 years (Section 8 GwG, gesetze-im-internet.de).
For identification by video identification procedure, BaFin Circular 3/2017 (GW) applies.
Does an EU-wide cash payment limit apply?
Yes. The AMLR introduces a uniform EU-wide cash payment limit for the first time. Art. 80(1) of Regulation (EU) 2024/1624 reads in the official German text (unofficial working translation below):
Original (DE): „Personen, die mit Gütern handeln oder Dienstleistungen erbringen, dürfen Barzahlungen nur in Höhe von maximal 10 000 EUR oder dem entsprechenden Gegenwert in der nationalen oder einer Fremdwährung entgegennehmen oder vornehmen, unabhängig davon, ob die Transaktion in einem einzigen Vorgang oder in mehreren Vorgängen, zwischen denen eine Verbindung zu bestehen scheint, getätigt wird."
Unofficial working translation: "Persons trading in goods or providing services may only accept or make cash payments of a maximum of EUR 10,000 or the equivalent value in a national or foreign currency, regardless of whether the transaction is carried out in a single operation or in several operations which appear to be linked."
Member States may set lower national limits (Art. 80(2) AMLR); existing lower limits remain valid (Art. 80(3) AMLR). Exempted from the EUR 10,000 limit are, among other things, payments between private individuals not acting in a professional capacity, and payments and deposits made on the premises of credit institutions, e-money institutions or payment institutions (Art. 80(4) AMLR).
What remains of the German GwG?
The AMLR generally applies directly from 10 July 2027. National provisions remain relevant where EU law leaves matters to national regulation. Existing processes therefore need to be mapped duty by duty against the EU framework and German implementing provisions. Regulation (EU) 2024/1624, AMLR Directive (EU) 2024/1640, Article 78
The institutional level – the FIU, national supervisory authorities and beneficial ownership registers – is not governed by the AMLR but by AMLD6 (EUR-Lex). AMLD6 requires national transposition and thus continues to leave room for national law.
What does this mean for implementation at the institution?
Operational preparation for the AMLR can be structured around four workstreams that derive directly from the regulation:
01Risk assessment and internal strategy
Art. 9 and 10 AMLR require the preparation and ongoing updating of a risk assessment and the establishment of internal policies, procedures and controls. These documents are the foundation for all downstream obligations and must meet the AMLR requirements from 10 July 2027.
02Map the CDD chain systematically
Customer due diligence is governed by Art. 19, 20, 22, 23, 25 and 26 AMLR. The due diligence obligations must be embedded in processes: from identification through verification to the ongoing monitoring of the business relationship (Art. 26 AMLR). The AMLR definition of beneficial owner supersedes Section 3 GwG.
03Align sanctions list screening
EU sanctions regulations apply directly; screening is carried out against the consolidated EU sanctions list (data.europa.eu). In Germany, the Deutsche Bundesbank is the competent authority for financial sanctions (bundesbank.de). Screening is to be controlled separately from the GwG process but must be organisationally embedded.
04Review organisational embedding
The organisational obligations remain anchored in national law: the money laundering officer under Section 7 GwG and the internal security measures under Section 25h KWG remain authoritative until the national adaptation of the GwG. Responsibilities should be documented and aligned with the AMLR obligations that will apply directly from 2027.
Related topics
- Banking regulation roadmap: all banking regulation deadlines 2026 to 2028+ in annual tables, including AMLR/AMLA.
- DORA Regulation (EU) 2022/2554: parallel EU regulation for digital operational resilience, applicable since 17 January 2025.
- MaRisk: current version Circular 06/2026: MaRisk AT 9 delineation from DORA; MaRisk and GwG obligations in interaction.
Frequently asked questions about the EU AML package
Sources & further reading
- German Anti-Money Laundering Act (GwG), including Sections 3, 7, 8, 43, 44gesetze-im-internet.de
- Regulation (EU) 2024/1624 (AMLR): official full text on EUR-Lexeur-lex.europa.eu
- Directive (EU) 2024/1640 (AMLD6): official full text on EUR-Lexeur-lex.europa.eu
- Regulation (EU) 2024/1620 (AMLA Regulation): official full text on EUR-Lexeur-lex.europa.eu
- BMF: „Anti-Geldwäschebehörde AMLA nimmt ihre Arbeit auf" (1 July 2025)bundesfinanzministerium.de
- BaFin: announcement of 6 March 2025 on the updated interpretive guidance (AuA) on the GwGbafin.de
- FIU/Zoll: technical note on the GwG Reporting Ordinance (GwG-MeldV) (1 March 2026)zoll.de
- FIU/Zoll: technical note on two-factor authentication in goAML (1 September 2025, PDF)zoll.de
- BaFin/FIU: joint guidance note on suspicious transaction reporting under Section 43 GwG (PDF)bafin.de
- Section 25h KWG (internal security measures): gesetze-im-internet.degesetze-im-internet.de
- BaFin: Circular 3/2017 (GW) on the video identification procedurebafin.de
- Deutsche Bundesbank: financial sanctions (competent authority in Germany)bundesbank.de
- Consolidated EU list of persons, groups and entities subject to EU financial sanctionsdata.europa.eu
- Regulation (EU) 2024/1624, AMLReur-lex.europa.eu
- AMLA: About AMLA, timelineamla.europa.eu
- Directive (EU) 2024/1640, Article 78eur-lex.europa.eu
- Regulation (EU) 2024/1620, Article 13eur-lex.europa.eu
An offer from T-NEX GmbH
Discuss the project with T-NEX
Implementing new AML requirements combines requirements management, professional review and suitable operational tools. T-NEX Compliance supports requirements analysis; Fraud Detection groups transaction alerts into reviewable cases. The actual monitoring and reporting scope is agreed separately.
Management: Andreas Unruh and Christoph Gembruch.
Published by T-NEX GmbH.
