The Anti-Money Laundering Authority (AMLA) is now staffing up in Frankfurt ahead of its 2028 direct-supervision launch. Selection criteria for the first 40 supervised entities, the Joint Supervisory Team model, AMLA's RTS pipeline, and what obliged entities should be doing in 2026–2027.
The Anti-Money Laundering Authority (AMLA) opened its doors in Frankfurt in mid-2025 and is now in build-out mode. Direct supervision of the first cohort of obliged entities begins in January 2028, but the decisions that will shape that supervision — selection methodology, Joint Supervisory Team composition, the first regulatory technical standards — are being taken now. This article unpacks what AMLA actually is, how it will exercise power, and what compliance teams should be doing in the 18-month run-up.
What AMLA Actually Is
AMLA is an EU agency established under Regulation (EU) 2024/1620, headquartered in Frankfurt am Main, and modelled in part on the European Central Bank's Single Supervisory Mechanism. It has four operating arms:
Direct supervision
Up to 40 of the highest-risk credit and financial institutions operating cross-border in the EU, supervised through Joint Supervisory Teams led from Frankfurt.
Indirect supervision
Coordination, peer reviews, and convergence of national AML supervisors (NCAs) for all other obliged entities — with the power to take over when a national supervisor is judged inadequate.
FIU support & coordination
Hosts a joint analysis hub for cross-border Suspicious Transaction Reports, runs the FIU.net successor, and drives convergence of analytical practice across national FIUs.
Rule-making
Drafts binding Regulatory and Implementing Technical Standards (RTS/ITS) under the AMLR, plus non-binding guidelines and opinions that set supervisory expectations.
Who Gets Picked for Direct Supervision
The first selection round runs in 2027 and will identify up to 40 "selected obliged entities" for direct supervision from January 2028. The methodology weights three factors:
- Cross-border footprint — established or operating under freedom of services in at least six Member States.
- Inherent ML/TF risk — scored against a harmonised AMLA methodology covering customer base, products, geographies, and delivery channels. The threshold sits in the highest risk bracket.
- Size & systemic relevance — total assets, transaction volumes, and crypto-asset service activity.
Crypto-asset service providers (CASPs) get special treatment: at least one CASP per Member State that hosts a significant cross-border operator will be in scope, and AMLA can include additional CASPs irrespective of the six-Member-State threshold where ML/TF risk warrants it.
The Joint Supervisory Team Model
Each directly-supervised entity will have a Joint Supervisory Team (JST) — a permanent, multi-jurisdictional team led by an AMLA coordinator and staffed with experts from the relevant national supervisors. The model borrows heavily from the ECB's SSM:
- Year-round on-site and off-site supervision, not periodic visits.
- A single Supervisory Review and Evaluation (SREP-style) cycle producing an annual decision.
- Direct enforcement powers, including administrative pecuniary sanctions up to 10% of annual turnover or €10 million, whichever is higher.
- Information-gathering powers that bypass national intermediation — JSTs can request data, interview staff, and conduct dawn raids directly.
"JST supervision is a step-change in intensity. Firms that have been comfortable answering one supervisor in one language on one timetable will be answering a multi-national team in English, continuously, with much shorter response windows."
The Real Timeline
- H2 2025 → 2026 — AMLA staffing, governance, and first wave of RTS consultations (CDD, BO, risk methodology).
- 2026 → mid-2027 — Adoption of the final RTS/ITS package; Member States stand up the National AML Supervisors required by AMLD6.
- 10 July 2027 — AMLR and AMLD6 become applicable; AMLA's indirect supervision powers activate.
- 2027 — Selection assessment for the first cohort of directly-supervised entities.
- 1 January 2028 — Direct supervision begins for selected obliged entities.
Indirect Supervision Is Not "Light Touch"
Even firms that never make the direct-supervision list will feel AMLA's gravity. The authority sets the supervisory methodology that NCAs apply, runs thematic reviews, publishes binding guidelines on supervisory practice, and operates a central database of supervisory data shared across the Union. Where a national supervisor is assessed as inadequate, AMLA can request the Commission to transfer supervision of specific entities to AMLA — a backstop expected to be used sparingly but visibly.
The RTS Pipeline to Watch in 2026
- RTS on customer due diligence — harmonised data and document sets for standard, simplified and enhanced CDD.
- RTS on the inherent risk assessment methodology — the formula that decides who is selected for direct supervision.
- RTS on pecuniary sanctions and periodic penalty payments — turnover-based methodology and aggravating/mitigating factors.
- ITS on supervisory reporting — the data points and frequency AMLA expects from directly-supervised firms.
- Guidelines on group-wide AML policies — implementing AMLR Article 16's parent-undertaking obligations.
What to Do in the Next 18 Months
- Run a selection self-assessment. Map your cross-border footprint against the six-Member-State test and benchmark your inherent risk profile against the draft AMLA methodology. Know whether you are in the candidate pool.
- Treat English as your supervisory language. Policies, board packs, internal-audit reports and management-information narratives should all be producible in English on short notice.
- Industrialise evidence. JSTs will ask for granular, machine-readable evidence — alert dispositions, BO refresh cycles, EDD triggers — not PDFs. Audit your ability to produce row-level data from screening, transaction monitoring and case management within hours.
- Stress-test group governance. AMLR Article 16 makes the parent responsible for group-wide AML policies, including third-country branches. Confirm that policies, escalation paths and MI flows actually work end-to-end across the group — not just on paper.
- Rehearse a JST information request. Pick a recent high-risk customer and reconstruct the full file — onboarding, ongoing monitoring, alerts, decisions, BO refreshes — and time how long it takes. Five business days is a reasonable internal benchmark.
The Bottom Line
AMLA is not just another acronym layered onto the existing AML stack. It is a single supervisor with direct powers, a harmonised methodology, and an expectation that obliged entities can evidence their controls with the same rigour as the ECB expects for prudential supervision. The firms that will adapt smoothly are those treating 2026 and 2027 as a controls-evidencing exercise, not a documentation exercise.
Explore how ComplianceSuite.ai aligns to the AMLR/AMLA framework on the platform overview, or read our companion piece on what the AMLR actually changes for compliance teams in 2027.
