The AMLA Countdown: Transformation, Pressure, and a 30% Readiness Problem
The AMLA Countdown: Transformation, Pressure, and a 30% Readiness Problem
The AMLA Countdown: Transformation, Pressure, and a 30% Readiness Problem
July 2027 is thirteen months away. For the European financial industry, it represents the most significant structural shift in anti-money laundering regulation in a generation: the activation of the EU Anti-Money Laundering Authority, a single rulebook replacing the patchwork of national transpositions that has governed the sector for decades, and the prospect - long discussed, frequently deferred - of genuine regulatory harmonisation across all 27 member states.
A recent PwC analysis, cited at Transform Finance's Amsterdam summit, estimates that only 30% of financial institutions will be ready to meet AMLA's requirements by the deadline. The other 70% are already behind.
The response in the room was something more layered over panic: a mixture of determination, institutional humility, and the seasoned recognition that the industry has been here before.
"We've been here before," said one veteran practitioner, who described the introduction of the first post-9/11 AML regulations - when calling a client to ask for a copy of their passport was considered a remarkable imposition - as a moment that felt equally overwhelming at the time. The industry adapted then. It will adapt again.
But the nature of this adaptation is meaningfully different from previous regulatory cycles. AMLA does not simply introduce new rules. It changes the architecture of supervision, the granularity of data requirements, and the legal basis for information sharing in ways that will require many institutions to rethink processes, systems and organisational structures that have been in place for years.
The Data Problem
If the summit produced a single dominant theme, it was data; its quality, its structure, its availability, and the degree to which most institutions do not yet have it in the condition that AMLA will require.
The regulation demands a level of data precision and completeness that exposes long-standing inadequacies in how customer information has been collected, stored and updated. One institution described going to retrieve a list of all UBOs and their country of residence for an AMLA questionnaire and discovering that the field simply did not exist in their systems. The information had been collected in the regulatory sense - KYC had been conducted, beneficial owners had been identified - but in a form that could not be interrogated by a data query. It existed in documents, not in structured data.
This is not an unusual situation. Legacy banking systems were not built for the data architecture that modern regulatory reporting demands. They were built for transaction processing. Information collected during KYC frequently lives in document stores, scanned files and offline records that require manual extraction before they can be used for any analytical purpose. For institutions that have completed remediation programmes, there is a silver lining - the enforced discipline of remediation has, at least, produced a relatively clean baseline. For those that have not, the gap to AMLA readiness is substantially wider.
The funds industry has its own variant of this problem, and one that the regulation appears not to have fully anticipated. Asset managers operating through third-party transfer agents - common in the Luxembourg and Irish fund structures that dominate European distribution - do not hold all of their own KYC data directly. They depend on outsourced partners whose systems may not be compatible, whose data fields may not match, and whose readiness for AMLA compliance is an additional variable outside the asset manager's direct control. One participant described going to six different third-party administrators to assemble the data required for a single regulatory questionnaire - a process that revealed the extent to which the regulation had been conceived with a retail branch banking model in mind, rather than the intermediated structures that characterise institutional fund distribution.
The One-Size Problem
The AMLA Regulation’s prescriptiveness was a source of genuine concern throughout the session, particularly its shift away from the risk-based flexibility that has characterised EU AML frameworks to date.
The most pointed example involved Article 12's treatment of complex corporate structures. Under the new framework, any client relationship involving multiple layers of legal entities is classified as high risk by default, regardless of whether those entities are regulated financial institutions operating in fully transparent, well-supervised markets. In the funds industry, this single provision would automatically reclassify approximately 80% of the client base as high risk. This concern does not stem from the risk profile of those clients, most of whom are regulated intermediaries, custodians and private banks operating in mainstream European markets. Rather, it reflects the fact that the regulatory text was not drafted with their business model in mind.
The concern is not abstract. Risk classification has resource consequences. If 80% of clients must be treated as high risk, the enhanced due diligence obligations that flow from that classification consume capacity that is no longer available for the clients that genuinely warrant heightened scrutiny: the direct investors, the complex private structures, the foundation relationships that require source-of-wealth analysis and human judgement.
"Our real risk is not through regulated channels," one practitioner said. "Our real risk is foundations, trusts, BVI structures - legal, but requiring scrutiny. We need to focus resources there. The regulation, as drafted, makes that harder."
The Opportunity Within the Obligation
The summit was not, however, a parade of grievances. Running through the discussion of AMLA's challenges was a persistent argument that the regulation, if implemented intelligently, represents a genuine opportunity.
Article 75 - the provision enabling cross-border public-private information sharing partnerships - was cited repeatedly as potentially the most significant tool the industry has been given. The legal framework for structured intelligence sharing between financial institutions and law enforcement agencies, across borders, in a GDPR-compliant manner, does not currently exist at European scale. Article 75 creates it. The practitioners who have spent years trying to share intelligence about criminal networks that routinely cross five borders in a single transaction were not without enthusiasm on this point.
The standardisation of SAR and STR reporting was also welcomed, particularly the introduction of a minimum dataset that will be specified in a regulatory technical standard expected this summer. The current divergence between member states is extraordinary: in some jurisdictions, suspicion reports number in the millions annually; in others, hundreds of thousands. The threshold for reporting, the format of the report, the information required and the platform through which it is filed all differ. Criminal networks, which operate as single entities across these different systems, benefit from every gap.
"The criminals are working cross-border," one practitioner observed. "We need to do the same." The harmonisation that AMLA promises, if its implementation matches its ambition, closes exactly the gaps that sophisticated criminal operations currently exploit.
What the Next Twelve Months Require
The practical consensus that emerged from the session was modest but clear. Institutions that are behind on AMLA readiness should not attempt to solve everything simultaneously. Gap assessments against the new requirements are the necessary starting point, helping firms understand where the distance between their current state and the required state is greatest. Data quality investment, often deferred in favour of more visible compliance projects, must be treated as foundational rather than incremental.
Critically, AMLA readiness should not be treated as a compliance project owned by the second line. The data changes, system upgrades and process redesigns required will touch core banking infrastructure, client-facing operations and technology roadmaps. It is, as several speakers argued, a whole-institution transformation - one that requires executive ownership and board-level sponsorship to deliver on time.
The 30% readiness figure is a sector-wide problem. But it is also a competitive reality. By July 2027, the institutions best positioned to succeed will be those with clean data, upgraded systems and the ability to operationalise Article 75 partnerships from day one. Their advantage will extend well beyond compliance. They will be better positioned to detect financial crime, better placed to share intelligence, and better equipped to demonstrate to supervisors the kind of operational effectiveness that the new regulatory environment will reward.
The road to Rome, as one speaker put it, is not the same for every institution. But Rome is not moving.
This article is part of Transform Finance's coverage of the 4th Annual FinCrime Leaders Summit Europe, Amsterdam 2026. This article reflects a session held under Chatham House rules. To respect those conditions, comments have not been attributed to individual speakers or organisations.
