Solutions

Industries

Markets

Partnerships

Resources

Get in touch

The Fourthline Team

AMLR and AMLD6: A practical guide for banks and fintechs

AMLR and AMLD6: A practical guide for banks and fintechs

June 2024 was a monumental moment for Europe’s financial industry. This, of course, is when the EU signed into law its most expansive anti-money laundering framework in a generation.  

Banks and fintechs have since been updating their systems, protocols, and governance to prepare for compliance in July 2027. In this guide, we’ll dive into the architecture of the new AML framework, with special focus on AMLD6 and what it means for your institution’s compliance programme.   

The problem the package was designed to solve 

Before we dive into the framework itself, it’s worth spending a moment to understand what it's replacing. 

For decades, EU AML obligations were all centred around directives. These directives set a kind of “bare minimum” of standards, which left each member state to translate these into their own national laws. What this meant in practice is that the same directive was interpreted differently in each market. This effectively created twenty-seven subtly different compliance regimes, interpretations, and supervisory cultures.  

For financial institutions operating across borders, this fragmentation created administrative and compliance nightmares. It also created genuine gaps that bad actors could (and did) exploit  

The 2024 package is a structural response to these problems. Its goal is harmonisation through a single, unified rulebook that closes gaps and makes the laws clear, straightforward, and broadly applicable. 

The four primary legislative acts of the new EU AML framework 

On a high level, the new AML package comprises four parts, or “instruments,” all published in the Official Journal on 19 June 2024. Let’s take a look. 

  • The Anti-Money Laundering Regulation (AMLR). This is the single rulebook that’s applicable across all 27 member states starting 10 July 2027. AMLR sets out the substantive obligations that financial institutions must meet, including customer due diligence, beneficial ownership identification, internal controls, and suspicious transaction reporting.  

  • The Sixth Anti-Money Laundering Directive (AMLD6). AMLD6 defines the institutional infrastructure around the rulebook: supervisory powers, Financial Intelligence Units, beneficial ownership registers, and sanctions frameworks. More on this below. 

  • The Anti-Money Laundring Authority Regulation (AMLAR) establishes AMLA, the EU's new Anti-Money Laundering Authority, and defines its mandate, governance, and supervisory powers. 

  • The revised Funds Transfer Regulation (rFTR), adopted in May 2023, extends AML data requirements to crypto-asset transfers for the first time. 

Beneath these four primary acts sit two further tiers. The first is the binding regulatory and technical standards (RTS and ITS) that AMLA is developing throughout 2026 and 2027.  

Second are the guidelines that will shape supervisory expectations across the EU. This is where the high-level obligations of the legislation get translated into the granular, operational requirements that institutions will actually implement. 

Understanding AMLD6  

If the AMLR sets out what institutions must do on a broad scale, AMLD6 builds the infrastructure that ensures they do it. In practice, this means it defines the national supervisory authorities, the sanctions frameworks, and the enforcement mechanisms that give the rulebook its might. 

AMLD6 needs to be transposed into national law by each member state by 10 July 2027. This is where some variation can come into play. Here, the EU has decided to allow a certain degree of national variation, reflecting differences in legal traditions and institutional structures across member states. 

Here’s what its core provisions cover: 

  • National supervisory authorities, including their powers, resources, and independence 

  • Financial Intelligence Units (FIUs) — how they're organised, how they cooperate across borders, and what access they have to financial data 

  • Beneficial ownership registers — more detailed information requirements, a broader range of legal entities in scope, and wider access for FIUs, AMLA, and national authorities 

  • Administrative sanctions — the penalties frameworks that will apply when institutions fall short 

  • Cross-border supervisory cooperation — the mechanisms that allow national supervisors to work together on institutions operating across multiple jurisdictions 

For institutions with operations across multiple EU jurisdictions, understanding the difference between AMLD6 and the rest of the framework is a core part of preparing. So, that’s what we’ll discuss next.  

How AMLD6 connects to the larger EU AML framework 

As we discussed above, AMLR and AMLD6 are two components of the same framework. On 10 July 2027, your AMLR obligations will be clear and identical regardless of where in the EU you operate. Your AMLD6 obligations, on the other hand, will depend on choices that 27 national legislatures are still in the process of making.  

This means the frameworks, structures, and regimes that will govern how you're overseen (and what happens if you don’t comply) are still being shaped. 

At the intersection of these two sits AMLA. This supervisory body defines, through its regulatory technical standards, what AMLR compliance looks like in granular detail. It also coordinates the national supervisors responsible for AMLD6 implementation. 

Learn more about AMLA here.  

Think of it like driving. The AMLR is the highway code — the rules every driver must follow, the same across every road. AMLD6 establishes the traffic authorities and the penalties for breaking the rules. AMLA writes the detailed guidance that defines exactly how compliance is assessed on the ground. 

Here is a table that breaks down the functions more clearly. 


AMLR

AMLD6

AMLA

What it is 

One regulation applicable across the EU 

Directive requiring national transposition 

EU supervisory authority 

What it covers 

Obligations for obliged entities 

Supervisory infrastructure, FIUs, sanctions 

Drafting technical standards, direct and indirect supervision 

Consistency

Uniform across all 27 member states 

Variable — shaped by national implementation 

Driving convergence across national supervisory authorities 

Key question for leaders

Are we building to the single EU standard? 

Do we know where each of our markets stands with AMLD6 implementation? 

Are we working from AMLA's published consultation drafts, knowing that changes will come when the final standards are published? 

What AMLD6 means for your compliance programme 

July 2027 is when member states must have AMLD6 fully transposed into national law. That means the supervisory frameworks, FIU structures, and sanctions regimes that will govern your institution should all be in place by then. It's worth noting that some provisions have earlier deadlines: beneficial ownership register rules, for example, are required by July 2026. 

What this adds up to is that unlike with AMLR, your compliance exposure under AMLD6 will look different depending on where your organisation operates. The rules in Frankfurt might differ greatly from those in Paris, and so on.  

A few things worth having on your radar: 

  • Know where your markets stand. As of right now, national transposition is still in progress across the EU. Keep an eye on where each of the jurisdictions you operate in is at.  

  • The sanctions are serious. AMLD6 doubles the maximum penalty ceiling to €10 million, or 10% of total annual turnover for credit and financial institutions. This makes the stakes of non-compliance much higher than under the previous framework. 

  • Don't assume uniformity. This point is bears repeating: your AMLR obligations will be identical across every EU market you operate in. Your AMLD6 obligations — how you're supervised, what your local FIU expects, what sanctions apply — will vary.  

Prepare for AMLR6 with Fourthline 

Navigating the EU's new AML framework is complex. And with technical standards still taking shape and national transposition still in progress, the picture is changing quickly. At Fourthline, we work closely with banks and fintechs across the EU to build compliance infrastructure that's ready for July 2027 and beyond. Learn more about how we support companies with AMLR preparation and more here.  

June 2024 was a monumental moment for Europe’s financial industry. This, of course, is when the EU signed into law its most expansive anti-money laundering framework in a generation.  

Banks and fintechs have since been updating their systems, protocols, and governance to prepare for compliance in July 2027. In this guide, we’ll dive into the architecture of the new AML framework, with special focus on AMLD6 and what it means for your institution’s compliance programme.   

The problem the package was designed to solve 

Before we dive into the framework itself, it’s worth spending a moment to understand what it's replacing. 

For decades, EU AML obligations were all centred around directives. These directives set a kind of “bare minimum” of standards, which left each member state to translate these into their own national laws. What this meant in practice is that the same directive was interpreted differently in each market. This effectively created twenty-seven subtly different compliance regimes, interpretations, and supervisory cultures.  

For financial institutions operating across borders, this fragmentation created administrative and compliance nightmares. It also created genuine gaps that bad actors could (and did) exploit  

The 2024 package is a structural response to these problems. Its goal is harmonisation through a single, unified rulebook that closes gaps and makes the laws clear, straightforward, and broadly applicable. 

The four primary legislative acts of the new EU AML framework 

On a high level, the new AML package comprises four parts, or “instruments,” all published in the Official Journal on 19 June 2024. Let’s take a look. 

  • The Anti-Money Laundering Regulation (AMLR). This is the single rulebook that’s applicable across all 27 member states starting 10 July 2027. AMLR sets out the substantive obligations that financial institutions must meet, including customer due diligence, beneficial ownership identification, internal controls, and suspicious transaction reporting.  

  • The Sixth Anti-Money Laundering Directive (AMLD6). AMLD6 defines the institutional infrastructure around the rulebook: supervisory powers, Financial Intelligence Units, beneficial ownership registers, and sanctions frameworks. More on this below. 

  • The Anti-Money Laundring Authority Regulation (AMLAR) establishes AMLA, the EU's new Anti-Money Laundering Authority, and defines its mandate, governance, and supervisory powers. 

  • The revised Funds Transfer Regulation (rFTR), adopted in May 2023, extends AML data requirements to crypto-asset transfers for the first time. 

Beneath these four primary acts sit two further tiers. The first is the binding regulatory and technical standards (RTS and ITS) that AMLA is developing throughout 2026 and 2027.  

Second are the guidelines that will shape supervisory expectations across the EU. This is where the high-level obligations of the legislation get translated into the granular, operational requirements that institutions will actually implement. 

Understanding AMLD6  

If the AMLR sets out what institutions must do on a broad scale, AMLD6 builds the infrastructure that ensures they do it. In practice, this means it defines the national supervisory authorities, the sanctions frameworks, and the enforcement mechanisms that give the rulebook its might. 

AMLD6 needs to be transposed into national law by each member state by 10 July 2027. This is where some variation can come into play. Here, the EU has decided to allow a certain degree of national variation, reflecting differences in legal traditions and institutional structures across member states. 

Here’s what its core provisions cover: 

  • National supervisory authorities, including their powers, resources, and independence 

  • Financial Intelligence Units (FIUs) — how they're organised, how they cooperate across borders, and what access they have to financial data 

  • Beneficial ownership registers — more detailed information requirements, a broader range of legal entities in scope, and wider access for FIUs, AMLA, and national authorities 

  • Administrative sanctions — the penalties frameworks that will apply when institutions fall short 

  • Cross-border supervisory cooperation — the mechanisms that allow national supervisors to work together on institutions operating across multiple jurisdictions 

For institutions with operations across multiple EU jurisdictions, understanding the difference between AMLD6 and the rest of the framework is a core part of preparing. So, that’s what we’ll discuss next.  

How AMLD6 connects to the larger EU AML framework 

As we discussed above, AMLR and AMLD6 are two components of the same framework. On 10 July 2027, your AMLR obligations will be clear and identical regardless of where in the EU you operate. Your AMLD6 obligations, on the other hand, will depend on choices that 27 national legislatures are still in the process of making.  

This means the frameworks, structures, and regimes that will govern how you're overseen (and what happens if you don’t comply) are still being shaped. 

At the intersection of these two sits AMLA. This supervisory body defines, through its regulatory technical standards, what AMLR compliance looks like in granular detail. It also coordinates the national supervisors responsible for AMLD6 implementation. 

Learn more about AMLA here.  

Think of it like driving. The AMLR is the highway code — the rules every driver must follow, the same across every road. AMLD6 establishes the traffic authorities and the penalties for breaking the rules. AMLA writes the detailed guidance that defines exactly how compliance is assessed on the ground. 

Here is a table that breaks down the functions more clearly. 


AMLR

AMLD6

AMLA

What it is 

One regulation applicable across the EU 

Directive requiring national transposition 

EU supervisory authority 

What it covers 

Obligations for obliged entities 

Supervisory infrastructure, FIUs, sanctions 

Drafting technical standards, direct and indirect supervision 

Consistency

Uniform across all 27 member states 

Variable — shaped by national implementation 

Driving convergence across national supervisory authorities 

Key question for leaders

Are we building to the single EU standard? 

Do we know where each of our markets stands with AMLD6 implementation? 

Are we working from AMLA's published consultation drafts, knowing that changes will come when the final standards are published? 

What AMLD6 means for your compliance programme 

July 2027 is when member states must have AMLD6 fully transposed into national law. That means the supervisory frameworks, FIU structures, and sanctions regimes that will govern your institution should all be in place by then. It's worth noting that some provisions have earlier deadlines: beneficial ownership register rules, for example, are required by July 2026. 

What this adds up to is that unlike with AMLR, your compliance exposure under AMLD6 will look different depending on where your organisation operates. The rules in Frankfurt might differ greatly from those in Paris, and so on.  

A few things worth having on your radar: 

  • Know where your markets stand. As of right now, national transposition is still in progress across the EU. Keep an eye on where each of the jurisdictions you operate in is at.  

  • The sanctions are serious. AMLD6 doubles the maximum penalty ceiling to €10 million, or 10% of total annual turnover for credit and financial institutions. This makes the stakes of non-compliance much higher than under the previous framework. 

  • Don't assume uniformity. This point is bears repeating: your AMLR obligations will be identical across every EU market you operate in. Your AMLD6 obligations — how you're supervised, what your local FIU expects, what sanctions apply — will vary.  

Prepare for AMLR6 with Fourthline 

Navigating the EU's new AML framework is complex. And with technical standards still taking shape and national transposition still in progress, the picture is changing quickly. At Fourthline, we work closely with banks and fintechs across the EU to build compliance infrastructure that's ready for July 2027 and beyond. Learn more about how we support companies with AMLR preparation and more here.  

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.