Europe's newest financial-crime regulator is running a dozen major rulemaking projects at once this summer, spanning customer due diligence, business-wide risk assessment and the ongoing monitoring of customer relationships. Yet among the core rulebooks that obliged entities will actually build their compliance programmes around, only two had crossed the finish line by the second week of July. AMLA has finalised several more procedural standards separately, including the rules on how financial intelligence units exchange information, but the substantive compliance measures firms are waiting on mostly sit at various points between an open consultation and a closed one still awaiting its final report. That gap is more than a technicality: a firm that builds its compliance programme around a draft still in flux risks building against a text that shifts underneath it.
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), the EU's Frankfurt-based AML/CFT supervisor, is responsible for roughly a dozen Level 2 and Level 3 technical measures required by the Anti-Money Laundering Regulation (AMLR) and its accompanying legislation. The agency's own regulatory-instruments tracker, last refreshed on 3 June 2026, shows where each one stands. Only two carry a published final report: the Regulatory Technical Standards (RTS) governing the inherent and residual risk profile of obliged entities, and the RTS on the methodology AMLA will use to decide which firms fall under its own direct supervision, both of which had their final reports published in December 2025. AMLA has since finalised a set of more procedural standards as well, including the technical rules on information exchange between financial intelligence units and between those units and the European Public Prosecutor's Office, completed on 3 July 2026, along with the RTS on pecuniary sanctions finalised around the same time. The substantive obligations most firms are waiting on, however, remain in motion.
The three in-motion measures that matter most for compliance planning
The draft RTS on customer due diligence, mandated by Article 28(1) of the AMLR, is the text that will pin down precisely which information and documents firms must gather to satisfy their CDD obligations. Its public consultation closed on 8 May 2026, and AMLA is now refining the draft, which is based on a version the European Banking Authority (EBA) prepared in October 2025, before it goes to the European Commission for formal adoption. No final text has been published yet, but of the three measures below this one is closest to the line.
The draft Guidelines on business-wide risk assessment, issued under Article 10(4), set four minimum requirements that obliged entities must meet when gauging their own enterprise-level money-laundering and terrorist-financing risk, along with information sources beyond those already named in Article 10(1). Their consultation ran from 16 April to 15 July 2026, with final guidance expected in the fourth quarter of the year.
The draft Guidelines on the ongoing monitoring of a business relationship, issued under Article 26(5), are the instruments that will actually govern transaction and activity monitoring, arguably the highest-stakes of the three for day-to-day compliance operations. Their consultation opened only on 3 June and runs to 3 September 2026, after a public hearing on 2 July. Nothing here will be settled before the autumn at the earliest.
A further cluster of measures sits in much the same holding pattern as the CDD RTS, with consultations closed but no final report issued: the RTS on group-wide minimum requirements for third-country subsidiaries and branches, and the RTS on identifying business relationships and linked transactions.
Why 10 July mattered less than many expected
Cited repeatedly across the legislation, 10 July 2026 turned out to be more of a statutory marker than an operational cut-off. The AMLR sets it as the target by which AMLA must submit much of its Level 2 and Level 3 rulemaking to the European Commission, but in practice that work has proceeded on a rolling basis. Some standards may have reached final-report stage before the date, yet many of the measures firms are actually waiting on remain at different points in the consultation and adoption pipeline.
AMLA's tracker makes the unevenness plain. The CDD RTS has moved past consultation into finalisation; the business-wide risk assessment guidelines cleared consultation in July, with final text due later in the year; and the ongoing-monitoring guidelines trail further back, their consultation open until September before any final version can be drafted. The upshot is a timetable far more staggered than the legislation alone implies. Rather than a single moment at which firms could switch on implementation, 10 July sits inside a longer programme of rulemaking that runs well past the date itself, and planning against the maturity of each individual instrument is likely to serve compliance teams better than treating the whole package as though it advances in lockstep.
What compliance leaders should do now
The more useful question is not when AMLA hits a legislative milestone but which measures are developed enough to start acting on. The CDD RTS has advanced far enough that firms can begin reviewing their internal procedures against the EBA's October 2025 draft, on the understanding that some adjustment may be needed once AMLA's final version is adopted; waiting for the finished text before doing any planning is unlikely to be the efficient course.
The business-wide risk assessment guidelines occupy a different spot. Because the four minimum requirements are unlikely to shift much between draft and final, they are worth studying now, even if formal sign-off should wait for the fourth-quarter text. The ongoing-monitoring guidelines are the one area where building anything concrete today would be premature: firms with live transaction-monitoring programmes should read the current draft, and its proposed split between keeping customer information up to date and the transaction-and-activity-monitoring framework, as a directional signal rather than a specification to implement against.
Sources
- AMLA, regulatory-instruments tracker (updated 3 June 2026): amla.europa.eu
- AMLA, consultation on the draft RTS on customer due diligence (Article 28(1)): amla.europa.eu
- AMLA, consultation on the draft Guidelines on business-wide risk assessment (Article 10(4)): amla.europa.eu
- AMLA, consultation on the draft Guidelines on ongoing monitoring of a business relationship (Article 26(5)): amla.europa.eu
- Anti-Money Laundering Regulation (EU) 2024/1624 (AMLR): eur-lex.europa.eu
