The Fourthline Team
Your AMLR Checklist: What Has to Be Done and by When
Your AMLR Checklist: What Has to Be Done and by When
If you're a bank or fintech in Europe, you’ve likely been steeped in AMLR preparation for a while now. Which means that you’re all too aware that the July 2027 deadline, when the regulation takes force, is fast approaching.
What you might not know is that 10 July 2027 is not the only date that institutions need to be aware of. Indeed, with so many changes on a micro and macro scale, it’s essential to pay attention to the different rollouts, policy updates, and dependencies tied to the new regulation.
At Fourthline, we’ve spent the last year helping financial institutions prepare their onboarding, auditing, and due diligence infrastructures for compliance. This means we know exactly what the timeline looks like, what’s required and when.
In this article, we’re covering the important deadlines you need to be aware of.
Need a primer on what AMLR requires? Read our guide: How to Prepare for AMLA Compliance: What Financial Institutions Must Do Before 2027
Deadline 1: Today
Before you start implementing any new architecture or compliance systems, two things need to be in place.
A completed gap analysis. While this step is not mandatory from a regulatory perspective, it’s strongly advised. At its core, this step is all about mapping your current AML/CFT policies, procedures, and controls against AMLR's requirements.
Sign-off from top management. AMLR Articles 9 and 11 place explicit responsibility for AML/CFT compliance on the management body.
Not sure if you're prepared for the new regulation? Check out our guide to find out: Are You Actually Ready for AMLR? A Self-Assessment for Compliance Teams
Deadline 2: 10 July 2026
By 10 July 2026, AMLA — Europe’s new Anti-Money Laundering Authority — will publish most of its 23 Level 2 and Level 3 technical standards, as well as its critical regulatory technical standards (RTS), implementing technical standards (ITS), and further guidelines.
This represents a massive shift. The RTS alone will set the standard for how financial institutions should comply with AMLR, including what methods are accepted, what data needs to be collected, and more. And that’s just one of several weighty regulatory standards coming up the pipeline.
However, delays are already expected.
AMLA's own Single Programming Document confirms it plans to deliver just 24 of its 40 mandates in 2026 — and its own consultation papers set Commission submission deadlines as late as 30 September 2026, nearly three months after the statutory July deadline.
This means that the window between final standards and the July 2027 application date may be shorter than institutions are planning for.
What this means in practice
Waiting for the full standards could put your team behind. The good news is that AMLA's consultation drafts, which are already in circulation, are the most accurate available information as to what the final standards will require.
Our advice? Don’t wait for the final published standards. Start building based on the existing drafts and plan to make adjustments once the final texts are published.
Below we’ve listed the tasks we recommend having completed or underway by July 2026, based on our own experience helping institutions prepare. Pay close attention to the first one, which is mandatory, but take the other points as sound advice.
Beneficial ownership register access: By 10 July 2026, EU member states should have updated and connected their central beneficial ownership registers. What does this mean for you? Essentially, the information your company relies on to verify who owns or controls a legal entity should be more accessible and consistent across borders to satisfy regulators.
UBO verification review: AMLR doesn't change the 25% threshold for identifying “ultimate beneficial owners” (UBOs), but it does change how ownership is calculated. Check that your processes account for both direct and indirect ownership, and all other forms of ownership interest listed in the regulation.
CDD framework review: Map your current customer due diligence and enhanced due diligence procedures against the AMLR's requirements and AMLA's draft CDD RTS. These are already publicly available and provide a good roadmap to move forward with.
Group-wide policy review: Are you part of a financial group? If so, check your group-wide AML/CFT policies and information sharing arrangements with AMLR Article 16 and AMLA's April 2026 draft RTS.
Monitor the AMLA consultation page: Throughout the process, it’s worth keeping a close eye on AMLA's public consultations page, where they publish updates regularly.
Deadline 3: January 2027
In an ideal world, most of AMLA’s standards will be published by this date, meaning you’ll know exactly what is required of your business. From October 2026 to January 2027, AMLA's Level 2 standards will be making their way through European Commission adoption and parliament.
This means it’s time to finalise your governance, update your systems, and get your staff trained.
By January 2027, the following should be complete or in final testing:
Updated CDD procedures: these include revised onboarding flows for all levels of due diligence and updated identity verification processes aligned with AMLR's three approved remote onboarding methods.
EDD mandatory categories: Under AMLR Article 34, EDD is mandatory for certain customer categories. Make sure your processes and controls are set up to trigger automatically for Politically Exposed Persons, customers from high-risk third countries, and complex or unusual transactions.
Audit trail infrastructure: You’ll need record-keeping systems that meet AMLR Article 77's five-year record retention requirement across every step of the customer journey.
STR reporting formats: Update suspicious transaction reporting processes to be aligned with AMLA's ITS on reporting formats.
Internal governance: AMLR requires a member of your management to take responsibility for AML/CFT compliance. Alongside this, you'll need a dedicated compliance manager with clear, documented reporting lines to that person.
Deadline 4: 10 April 2027
One recommendation that comes up again and again across independent analyses is the concept of being "ready to audit" at least three months before the July 2027 application date.
This means being able to demonstrate compliance not just on paper, but operationally, with evidence packs ready for supervisory inspection.
By April 2027, the following should be in place:
End-to-end testing of all updated AML/CFT processes
Independent internal audit or external review of the compliance programme
Documented remediation of any deficiencies identified in testing
Board attestation of AMLR readiness with supporting evidence
Deadline 5: 10 July 2027
From this date, it’s go time. AMLR now applies across all 27 EU member states.
Two things to note from this day forward:
First, AMLA will begin the selection process for direct supervision of up to 40 high-risk financial institutions by the end of 2027, with direct supervision commencing from January 2028.
Even institutions not selected for direct supervision will be supervised to AMLA standards by their national competent authorities.
Second, existing customer files do not all need to be fully remediated by July 2027. AMLR Article 26 establishes that updates to existing customer files should follow a risk-based approach, prioritising high-risk customers first, with others updated within the applicable timeframe.
This is meaningful breathing room for institutions with large existing portfolios, but it requires a documented remediation plan to be defensible.
The bottom line
The July 2027 deadline is significant but it's also achievable. The framework is complex, the standards are still taking shape, and the timeline is tighter than it looks on paper. That's a lot to hold at once.
But the building blocks are there. AMLA's consultation drafts are publicly available. The regulatory direction of travel has been clear for some time. And the institutions we work with are making real, meaningful progress, one milestone at a time.
Prepare for AMLR with Fourthline
Fourthline is an identity verification and compliance platform for regulated financial institutions, supervised by the Dutch Central Bank. Our infrastructure supports AMLR's approved remote onboarding methods, generates a complete, unified audit trail across every step of the customer journey, and is built to meet the requirements of the single rulebook that applies from July 2027. If your organisation is working through what AMLR means for your compliance infrastructure, we’d be happy to help.
If you're a bank or fintech in Europe, you’ve likely been steeped in AMLR preparation for a while now. Which means that you’re all too aware that the July 2027 deadline, when the regulation takes force, is fast approaching.
What you might not know is that 10 July 2027 is not the only date that institutions need to be aware of. Indeed, with so many changes on a micro and macro scale, it’s essential to pay attention to the different rollouts, policy updates, and dependencies tied to the new regulation.
At Fourthline, we’ve spent the last year helping financial institutions prepare their onboarding, auditing, and due diligence infrastructures for compliance. This means we know exactly what the timeline looks like, what’s required and when.
In this article, we’re covering the important deadlines you need to be aware of.
Need a primer on what AMLR requires? Read our guide: How to Prepare for AMLA Compliance: What Financial Institutions Must Do Before 2027
Deadline 1: Today
Before you start implementing any new architecture or compliance systems, two things need to be in place.
A completed gap analysis. While this step is not mandatory from a regulatory perspective, it’s strongly advised. At its core, this step is all about mapping your current AML/CFT policies, procedures, and controls against AMLR's requirements.
Sign-off from top management. AMLR Articles 9 and 11 place explicit responsibility for AML/CFT compliance on the management body.
Not sure if you're prepared for the new regulation? Check out our guide to find out: Are You Actually Ready for AMLR? A Self-Assessment for Compliance Teams
Deadline 2: 10 July 2026
By 10 July 2026, AMLA — Europe’s new Anti-Money Laundering Authority — will publish most of its 23 Level 2 and Level 3 technical standards, as well as its critical regulatory technical standards (RTS), implementing technical standards (ITS), and further guidelines.
This represents a massive shift. The RTS alone will set the standard for how financial institutions should comply with AMLR, including what methods are accepted, what data needs to be collected, and more. And that’s just one of several weighty regulatory standards coming up the pipeline.
However, delays are already expected.
AMLA's own Single Programming Document confirms it plans to deliver just 24 of its 40 mandates in 2026 — and its own consultation papers set Commission submission deadlines as late as 30 September 2026, nearly three months after the statutory July deadline.
This means that the window between final standards and the July 2027 application date may be shorter than institutions are planning for.
What this means in practice
Waiting for the full standards could put your team behind. The good news is that AMLA's consultation drafts, which are already in circulation, are the most accurate available information as to what the final standards will require.
Our advice? Don’t wait for the final published standards. Start building based on the existing drafts and plan to make adjustments once the final texts are published.
Below we’ve listed the tasks we recommend having completed or underway by July 2026, based on our own experience helping institutions prepare. Pay close attention to the first one, which is mandatory, but take the other points as sound advice.
Beneficial ownership register access: By 10 July 2026, EU member states should have updated and connected their central beneficial ownership registers. What does this mean for you? Essentially, the information your company relies on to verify who owns or controls a legal entity should be more accessible and consistent across borders to satisfy regulators.
UBO verification review: AMLR doesn't change the 25% threshold for identifying “ultimate beneficial owners” (UBOs), but it does change how ownership is calculated. Check that your processes account for both direct and indirect ownership, and all other forms of ownership interest listed in the regulation.
CDD framework review: Map your current customer due diligence and enhanced due diligence procedures against the AMLR's requirements and AMLA's draft CDD RTS. These are already publicly available and provide a good roadmap to move forward with.
Group-wide policy review: Are you part of a financial group? If so, check your group-wide AML/CFT policies and information sharing arrangements with AMLR Article 16 and AMLA's April 2026 draft RTS.
Monitor the AMLA consultation page: Throughout the process, it’s worth keeping a close eye on AMLA's public consultations page, where they publish updates regularly.
Deadline 3: January 2027
In an ideal world, most of AMLA’s standards will be published by this date, meaning you’ll know exactly what is required of your business. From October 2026 to January 2027, AMLA's Level 2 standards will be making their way through European Commission adoption and parliament.
This means it’s time to finalise your governance, update your systems, and get your staff trained.
By January 2027, the following should be complete or in final testing:
Updated CDD procedures: these include revised onboarding flows for all levels of due diligence and updated identity verification processes aligned with AMLR's three approved remote onboarding methods.
EDD mandatory categories: Under AMLR Article 34, EDD is mandatory for certain customer categories. Make sure your processes and controls are set up to trigger automatically for Politically Exposed Persons, customers from high-risk third countries, and complex or unusual transactions.
Audit trail infrastructure: You’ll need record-keeping systems that meet AMLR Article 77's five-year record retention requirement across every step of the customer journey.
STR reporting formats: Update suspicious transaction reporting processes to be aligned with AMLA's ITS on reporting formats.
Internal governance: AMLR requires a member of your management to take responsibility for AML/CFT compliance. Alongside this, you'll need a dedicated compliance manager with clear, documented reporting lines to that person.
Deadline 4: 10 April 2027
One recommendation that comes up again and again across independent analyses is the concept of being "ready to audit" at least three months before the July 2027 application date.
This means being able to demonstrate compliance not just on paper, but operationally, with evidence packs ready for supervisory inspection.
By April 2027, the following should be in place:
End-to-end testing of all updated AML/CFT processes
Independent internal audit or external review of the compliance programme
Documented remediation of any deficiencies identified in testing
Board attestation of AMLR readiness with supporting evidence
Deadline 5: 10 July 2027
From this date, it’s go time. AMLR now applies across all 27 EU member states.
Two things to note from this day forward:
First, AMLA will begin the selection process for direct supervision of up to 40 high-risk financial institutions by the end of 2027, with direct supervision commencing from January 2028.
Even institutions not selected for direct supervision will be supervised to AMLA standards by their national competent authorities.
Second, existing customer files do not all need to be fully remediated by July 2027. AMLR Article 26 establishes that updates to existing customer files should follow a risk-based approach, prioritising high-risk customers first, with others updated within the applicable timeframe.
This is meaningful breathing room for institutions with large existing portfolios, but it requires a documented remediation plan to be defensible.
The bottom line
The July 2027 deadline is significant but it's also achievable. The framework is complex, the standards are still taking shape, and the timeline is tighter than it looks on paper. That's a lot to hold at once.
But the building blocks are there. AMLA's consultation drafts are publicly available. The regulatory direction of travel has been clear for some time. And the institutions we work with are making real, meaningful progress, one milestone at a time.
Prepare for AMLR with Fourthline
Fourthline is an identity verification and compliance platform for regulated financial institutions, supervised by the Dutch Central Bank. Our infrastructure supports AMLR's approved remote onboarding methods, generates a complete, unified audit trail across every step of the customer journey, and is built to meet the requirements of the single rulebook that applies from July 2027. If your organisation is working through what AMLR means for your compliance infrastructure, we’d be happy to help.
Solutions
Solutions
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.