Preparing for AMLD6: The Next Step in AML Reporting for Subject Persons

Recent developments highlighted by the Financial Intelligence Analysis Unit (“FIAU”) point towards a clear shift in the EU’s anti-money laundering framework under the 6th Anti-Money Laundering Directive (“AMLD6”): reporting is becoming more structured, data-driven, and centralised.

For Subject Persons, this marks more than a routine compliance update. It requires early preparation, system readiness, and stronger internal coordination, particularly in light of emerging reporting frameworks such as Centralised Bank Account Registers (“CBARs”).

AMLD6 expands both the scope of entities subject to anti-money laundering and counter-terrorist financing (“AML/CFT”) obligations and the depth of reporting expectations. Authorities are placing increased emphasis on:

  • Timely access to accurate and standardised data;
  • Enhanced reporting capabilities and audit trails; and
  • Greater interconnectivity between competent authorities.

This reflects a move towards continuous supervisory oversight, rather than reliance solely on suspicious transaction reporting.

What Subject Persons Should Be Doing Now

Subject Persons should begin preparing across three key areas:

  1. Data Readiness
    Firms should ensure that customer and transactional data is:
  • Complete, accurate, and up to date; and
  • Stored in a way that allows for efficient extraction and reporting.
  1. Governance and Controls
    Clear internal ownership of reporting obligations is essential. This includes:
  • Defined roles across Compliance, MLRO, and IT functions; and
  • Robust policies, procedures, and audit trails
  1. Technology and Systems
    Manual processes will be increasingly inadequate. Firms should assess whether they need:
  • Automated reporting solutions; and
  • Better integration between KYC, monitoring, and reporting systems.

A Particular Focus on CASPs

Perhaps the most significant impact of AMLD6 and related EU reforms is on Crypto-Asset Service Providers (“CASPs”). Historically, many CASPs operated outside the full scope of AMLD4-style obligations. This is no longer the case.

Under the evolving framework:

  • CASPs are now fully subject to AML/CFT obligations, including Customer Due Diligence (“CDD”) and transaction monitoring;
  • They must implement comprehensive reporting and record-keeping systems; and
  • They are subject to ongoing reporting, audit, and supervisory requirements at both the Malta Financial Services Authority (“MFSA”) and FIAU level.

Unlike traditional financial institutions, many CASPs:

  • Were not originally designed with regulatory reporting in mind;
  • Operate on technology stacks that prioritise speed and scalability over compliance traceability; and
  • Rely on decentralised or hybrid models, complicating data capture and reporting.

As a result, CASPs now face a dual transformation challenge:

  1. Regulatory alignment (policies, procedures, governance); and
  2. Technology re-engineering (data capture, monitoring, reporting systems).

This is further compounded by parallel regulatory developments such as Markets in Crypto-Assets Regulation (“MiCA”), which introduce additional licensing, governance, and reporting requirements across the EU.

Key Takeaway

The introduction of CBAR-type reporting and AMLD6 obligations represents a broader trend: AML compliance is becoming increasingly data-centric, technology-driven, and supervisory-integrated.

Subject Persons that act early, by investing in data architecture, governance, and systems will be better positioned to meet upcoming obligations and avoid costly remediation.

For CASPs in particular, this is a defining moment. The transition from a lightly regulated environment to a fully supervised AML/CFT regime requires not just compliance, but institutional maturity.

How We Can Help

At Zerafa Advocates, we support Subject Persons, including CASPs, through:

  • Regulatory gap analyses and AML/CFT framework design;
  • Assistance with FIAU and MFSA compliance requirements;
  • Implementation of governance and reporting structures; and
  • Advisory on MiCA and AMLD6 alignment.