The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (“AMLA”) has set out its Single Programming Document (“SPD”) for 2026-2028, providing the first detailed roadmap of how the new EU Authority will shape the future Anti-Money Laundering (“AML”) and Countering the Financing of Terrorism (“CFT”) framework. The document confirms that the coming three years will be foundational for building a more centralised, data-driven and harmonised EU system for AML and CFT.
For regulated firms and gatekeepers across the EU, the SPD signals a clear shift: less national divergence, more EU-level methodology, and stronger supervisory convergence.
Completion of the EU AML/CFT Single Rulebook
A core priority for AMLA is finalising and operationalising the EU AML/CFT Single Rulebook, aimed at eliminating inconsistent interpretations of AML obligations across Member States. Between 2026 and 2028, AMLA will develop a significant body of Regulatory Technical Standards (“RTS”), Implementing Technical Standards (“ITS”) and Guidelines, with a strong emphasis on:
- Risk-based customer due diligence (“CDD”);
- Business-wide risk assessments;
- Harmonised supervisory methodologies; and
- Proportionate application of rules where risks are lower.
For cross-border financial groups and internationally active service providers, this should gradually reduce regulatory fragmentation, but in the short to medium term it will require careful monitoring of new EU-level standards and likely updates to internal frameworks.
Roadmap to AMLA Direct Supervision (from 2028)
AMLA confirms that from 2028 it will directly supervise 40 of the EU’s most significant and highest risk financial institutions. The selection process will be prepared in 2026-2027, with AMLA:
- Finalising its risk analysis and selection methodology;
- Designing its Joint Supervisory Team (“JST”) model;
- Developing both on-site and off-site supervisory tools; and
- Establishing procedures for the transfer of supervisory information from national authorities.
Even institutions not ultimately selected for direct supervision will feel the impact, as AMLA’s methodologies and expectations are likely to influence national supervisory approaches across the market.
Stronger Indirect Supervision and Oversight
Beyond direct supervision, AMLA will play a central role in indirect supervision by driving convergence among national competent authorities. This includes:
- Developing common supervisory strategies and methodologies;
- Conducting supervisory convergence reviews and peer reviews;
- Mapping national supervisory capabilities (including in areas such as crypto-asset supervision); and
- Supporting training and exchange of best practices.
In parallel, AMLA will expand its focus to oversight of the non-financial sector (e.g. certain professional service providers and other gatekeepers), including mapping supervisory practices, identifying implementation gaps and supporting more consistent application of AML/CFT requirements across these sectors.
Operationalising the EU FIU Framework
A major pillar of AMLA’s mandate is strengthening cooperation between EU Financial Intelligence Units (“FIUs”). Over 2026-2028, AMLA will:
- Establish structured joint analyses on cross-border and emerging risks;
- Develop harmonised formats and standards for Suspicious Transaction Reporting (“STR”) reporting and FIU-to-FIU exchanges;
- Host and further develop FIU.net; and
- Build a Support and Coordination Framework, including peer reviews and mediation mechanisms.
For obliged entities, this points to a more integrated EU intelligence environment and potentially more consistent expectations around suspicious activity reporting.
Data, Digitalisation and Risk Frameworks
AMLA’s strategy is strongly technology driven. Key initiatives include:
- Development of a central AML/CFT database for supervisory information;
- Creation of a broader AMLA data ecosystem drawing on supervisory, FIU and inter-institutional data sources;
- Use of advanced analytics, AI and machine learning for risk identification and monitoring; and
- A dedicated risk analysis and assessment framework to underpin both supervisory and FIU work.
This reflects a move toward data-led, EU-wide risk assessment, which is likely to translate into more sophisticated supervisory questions and information requests.
What This Means in Practice
For financial institutions, Crypto Asset Service Providers (“CASPs”) and other obliged entities – as well as professional firms operating as AML/CFT gatekeepers, the SPD highlights:
- A progressive shift of AML standard setting and methodology to EU level;
- Increased focus on consistent, risk-based approaches;
- Growing importance of data quality, governance and reporting frameworks; and
- Greater interaction between supervisory expectations and FIU-driven intelligence.
The period 2026-2028 should therefore be seen as a transition phase, during which firms should review whether their AML frameworks are sufficiently scalable and aligned with evolving EU-level standards, rather than solely national interpretations.
AMLA’s programme confirms that EU AML/CFT supervision is moving toward a more centralised, analytical and harmonised model. Early engagement with these developments will be key for firms seeking to remain ahead of regulatory expectations.
