The European Union's Anti-Money Laundering Authority (AMLA) has set out a common approach for the way supervisors punish breaches of the bloc's financial-crime rules, so that comparable failings draw comparable consequences wherever a firm is based. The proposal takes the form of draft regulatory technical standards on pecuniary sanctions, administrative measures and periodic penalty payments, and AMLA published its common enforcement approach on 8 July 2026.
At the centre of the standards is a single, staged method that every supervisor would apply. Instead of each authority reaching for its own yardstick, the rules fix four gravity tiers into which any breach must be sorted. Which tier a breach falls into is decided against a shared checklist that weighs its persistence over time, any pattern of repeat conduct, and the eventual harm to the financial system. That ranking, applied through common criteria, then points supervisors to the sanction or remedial step that fits.
The regime is designed to reach every business covered by EU anti-money-laundering law, in the non-financial sector as well as the financial one. Because the rules are regulatory technical standards, they would take effect as a delegated act: once the European Commission adopts them, they apply directly in every member state without needing to be transposed into national law. AMLA's public consultation on the draft ran from 9 February to 9 March 2026.
The enforcement standards are one piece of a wider build-out of AMLA's role. In 2028 the authority steps into a hands-on role for the first time, becoming the direct regulator of up to 40 financial groups singled out as the bloc's most complex and highest-risk cross-border operators, and it will steer national authorities toward a consistent supervisory line across the single market.
AMLA is advancing related workstreams in parallel. It is consulting separately on harmonised risk-assessment standards for the non-financial sector, and it is developing joint guidelines with the European Data Protection Board setting out how regulated firms may pool intelligence through information-sharing partnerships to counter illicit finance without falling foul of privacy law.
