AMLA and EU regulations: the direct supervision framework
AMLA, the European Union's authority for anti-money laundering and countering the financing of terrorism, was established by Regulation (EU) 2024/1620 and applies from 1 July 2025. Its most significant shift is the introduction of direct supervision: AMLA directly oversees selected obliged parties in the financial sector, including crypto-asset service providers.
AMLA is the European Union's authority for anti-money laundering and countering the financing of terrorism. Established by Regulation (EU) 2024/1620, it was adopted on 31 May 2024 and has been applicable since 1 July 2025. The fundamental change it introduces lies in the nature of its authority: AMLA directly supervises selected obliged parties, bypassing national authorities.
Which texts form the framework?
Regulation (EU) 2024/1620, which establishes AMLA, does not stand alone. It defines its scope in conjunction with Regulation (EU) 2023/1113, Directive (EU) 2024/1640, and Regulation (EU) 2024/1624.
| Text | What it regulates |
|---|---|
| Regulation (EU) 2024/1620 | Establishment, tasks, and direct supervisory powers of AMLA |
| Regulation (EU) 2024/1624 | Directly applicable rules for obliged parties |
| Directive (EU) 2024/1640 | The framework to be transposed into national regulations by member states |
| Regulation (EU) 2023/1113 | Information accompanying transfers of funds and certain crypto-assets |
The Regulation applies from 1 July 2025; certain articles have been in force since 26 June 2024, and one article will apply from 31 December 2025.
Who does AMLA supervise directly?
AMLA's mandate is defined in the Regulation as follows: direct supervision of selected obliged parties in the financial sector, including crypto-asset service providers; monitoring, analysis, and information sharing regarding money laundering and terrorism financing risks affecting the internal market; coordination and oversight of financial sector supervisory authorities; and coordination and oversight of non-financial sector supervisory authorities, including self-regulatory bodies.
The practical implication for an institution is clear: compliance and supervision are no longer relationships maintained solely with national authorities.
Are crypto-asset service providers in scope?
Yes, explicitly. The Regulation's definition of direct supervision specifically includes crypto-asset service providers. This means that screening, monitoring, and case management on the crypto side are expected to meet the exact same standards as other financial institutions. The sectoral framework can be found on the crypto and VASPs page.
Can different rule sets be established for different countries?
Yes, they can. Customer risk assessment, transaction monitoring, sanctions and PEP screening, post-onboarding monitoring, and case management run on the same platform. Different countries or business units are defined as separate data sources; rule and data isolation is managed through this separation, meaning a single deployment can support different rule sets for different jurisdictions. The structure of rules is detailed on the rule and scenario engine page.
What does direct supervision require from record-keeping?
Direct supervision means that the reasoning behind every decision must be auditable. The rationale for a decision, along with its supporting evidence, is linked directly to the case; details on who made the decision, under what authority, using which data, and when, are written to an immutable audit trail. Approval policies, multi-signature decisions, and documented delegation of authority can be configured. Details are available on the maker-checker, authorization, and audit trail page.
Rule executions are also recorded: which rule was triggered by which event, and the exact rule configuration in effect on that day can be reviewed retrospectively. The reporting aspect is covered on the regulatory reporting page.
Is a separate system required for crypto?
No. In the screening workflow, a wallet address is treated as an entity alongside the individual's name; on-chain and off-chain data merge into a single customer view. Details are on the crypto wallet screening page.
The data protection aspect is on the GDPR page, and the Turkish framework is on the MASAK obligations page.
Source
Regulation (EU) 2024/1620 of the European Parliament and of the Council; related framework Regulation (EU) 2023/1113, Directive (EU) 2024/1640, and Regulation (EU) 2024/1624.
This page does not constitute legal or regulatory advice. Rules, thresholds, and actions are configured according to the institution's own risk policy and obligations.
Common questions
- What is AMLA?
- It is the European Union's authority for anti-money laundering and countering the financing of terrorism, established by Regulation (EU) 2024/1620.
- When did AMLA start to apply?
- The Regulation was adopted on 31 May 2024 and has been applicable since 1 July 2025. Certain articles have been in force since 26 June 2024, and one article will apply from 31 December 2025.
- Who does AMLA supervise directly?
- Selected obliged parties in the financial sector, including crypto-asset service providers. It also coordinates and oversees financial and non-financial sector supervisory authorities.
- Which texts form the framework?
- Regulation (EU) 2024/1620, Regulation (EU) 2024/1624, Directive (EU) 2024/1640, and Regulation (EU) 2023/1113, which regulates information accompanying transfers of funds and certain crypto-assets.
- What does direct supervision change?
- Supervision is no longer a relationship maintained solely with national authorities; selected obliged parties are directly supervised by AMLA.
- Can we establish different rule sets for different countries?
- Yes. Countries and business units are defined as separate data sources; rule and data isolation is managed through this separation, allowing a single deployment to support the rule sets of different jurisdictions.
- Is a separate system required for crypto?
- No. In the screening workflow, a wallet address is treated as an entity alongside the individual's name; on-chain and off-chain data merge into a single customer view.
- What is expected from the audit trail?
- The reasoning behind every decision must be auditable. Details on who made the decision, under what authority, using which data, and when, are written to an immutable audit trail; which rule was triggered by which event is also recorded.