AMLR Takes Effect in 2027 and Establishes Uniform Anti-Money Laundering Law for Institutions
Effective July 10, 2027, the EU Anti-Money Laundering Regulation applies directly and replaces national rules. Institutions must shift their KYC processes to continuous updating.
What changes
Effective July 10, 2027, the EU Anti-Money Laundering Regulation (AMLR) becomes directly applicable law and replaces large parts of the national Money Laundering Act. This creates a uniform rulebook for all obliged entities in the EU, eliminating the patchwork of 27 national implementations. The regulation establishes fixed update cycles for customer data: generally every five years, annually for higher risk, and additionally on an event-driven basis. This brings the concept of perpetual KYC into focus, whereby customer data is continuously maintained rather than only at onboarding or during periodic reviews. Additionally, technical standards mandate a uniform sanctions screening and, for the first time, bind the outsourcing of KYC processes.
The new EU Authority AMLA has been conducting operational work since July 1, 2025 and, starting January 1, 2028, will exercise direct supervision over up to 40 selected cross-border active institutions. The selection will already take place in 2027. For institutions, this means they must keep an eye not only on national supervisory authorities but also on a central EU body. The preparation phase is already underway in 2026, during which institutions should assess the state of their systems using AMLA questionnaires and the data pilot. The goal is early alignment with the technical standards so that the cutoff date of 2027 does not turn into a sprint.
What it costs
The source does not publish concrete figures for the expected costs of implementing the AMLR. Nevertheless, the cost mechanism can be derived: Institutions must adapt their IT systems to enable continuous data updates, automated sanctions screening, and the demonstrability of outsourcing arrangements. This includes licensing costs for monitoring tools, potential database expansions, and potential acquisitions of identification solutions for digital onboarding processes.
Additionally, expenses arise for external consulting in the gap analysis, for calibrating existing systems to the technical standards, and for training staff. Ongoing operations also become more cost-intensive because data stocks must be continuously maintained and quality assurance processes established. These ongoing expenses manifest as higher personnel costs for compliance and IT, as well as increased spending on data quality management.
What breaks
The shift from point-in-time KYC checks to a perpetual model requires migrating existing customer data stocks into systems that support real-time or near-real-time updates. In the process, interfaces to legacy core banking systems or third-party platforms may need to be adapted or replaced, which can lead to temporary outages or reduced performance. In particular, institutions that rely heavily on batch processes must rethink their workflows.
During the transition, existing interfaces to screening providers, identification service providers, or outsourcing partners may be interrupted until the new connections are running stably. This requires careful testing and, if necessary, parallel operation to avoid jeopardizing business operations. Furthermore, staff must be trained to follow new work instructions for continuous data maintenance and handling trigger events, which can temporarily reduce productivity.
What a switch demands
A successful switch first requires a comprehensive gap analysis: the existing KYC and monitoring setup is benchmarked against the AMLR requirements and the AMLA’s technical standards. Based on this analysis, an action plan is created that prioritizes the necessary system adjustments, data quality initiatives, and contract reviews. Planning should begin as early as 2026 to avoid pressure in 2027.
Implementation typically takes several months to over a year, depending on the complexity of the IT landscape and the scope of the necessary changes. Various internal areas are involved: the Chief Data Officer or data manager leads the data quality initiative, the Chief Risk Officer or compliance head oversees the regulatory implementation, the IT department carries out the technical changes, and the executive board or management approves the required budgets and resources. An early decision on the selection of tools and any outsourcing arrangements is crucial to staying on schedule.
