Ask a compliance officer at a Cyprus broker and one at a German investment firm what documents they need for a corporate client, and you will get two different answers. Both are correct. Both are following the same European directive, transposed into two national laws by two parliaments with different appetites for detail. That divergence is the problem the current reform is built to solve.
For a firm holding or planning to hold a European licence, the sequence of directives is not legal trivia. It explains why the onboarding file looks the way it does, and the changes now working through the system will alter what has to be collected, stored and reported.
AMLD4: the risk-based approach arrives
The fourth directive moved Europe away from a checklist model. Instead of a fixed document list applied to everyone, firms were required to assess risk at the business level and at the customer level, then apply due diligence proportionate to that assessment. Simplified due diligence became something you had to justify rather than something you could assume.
Two other changes have outlived the directive itself. Beneficial ownership registers were mandated, giving supervisors a route to the natural persons behind a corporate structure. And politically exposed person screening was extended to domestic PEPs, which considerably widened the population a broker's screening tool has to flag.
AMLD5 and AMLD6: crypto and criminal liability
The fifth directive brought virtual currency exchange platforms and custodian wallet providers inside the obliged entity perimeter for the first time, which is the origin of the national VASP registration regimes that ran in most member states until the crypto framework matured. It also tightened prepaid card thresholds and pushed for wider access to ownership registers, an element later narrowed by the Court of Justice on privacy grounds.
The sixth directive worked on a different layer. Rather than customer due diligence, it harmonised the list of predicate offences for money laundering across member states and addressed criminal liability, including liability for legal persons. It matters less to a daily onboarding queue and more to the exposure of a firm and its officers when controls fail badly.
| Instrument | Main contribution | Applies as |
|---|---|---|
| AMLD4 | Risk-based approach, UBO registers, domestic PEPs | National transposition |
| AMLD5 | Crypto firms as obliged entities, register access | National transposition |
| AMLD6 | Predicate offences, criminal liability | National transposition |
| AML Regulation (2024) | Single rulebook for due diligence and reporting | Directly, no transposition |
| AMLA Regulation (2024) | Creates the EU-level supervisor | Directly, phased |
The 2024 package and why the instrument type matters
The reform adopted in 2024 has three parts: a directly applicable AML Regulation containing the operative obligations, a new directive covering supervisory architecture and national mechanisms such as financial intelligence units, and a regulation establishing the Anti-Money Laundering Authority, which is based in Frankfurt.
The regulation is the part that changes daily work. Customer due diligence requirements, beneficial ownership definitions, record-keeping periods and reporting triggers will read identically in every member state, and national supervisors lose most of their discretion to gold-plate. An EU-wide limit on large cash payments, set at 10,000 euro, sits in the same instrument, which matters less to a broker taking bank and card deposits and more to the wider obliged entity population.
The obligations bite on a staged timetable running towards the end of the decade rather than overnight. Firms should be reading the regulation text now and mapping gaps against current procedures, because retrofitting a data model after the deadline is far more expensive than designing for it.
What AMLA changes in practice
AMLA is being built to do three things: supervise a selected group of the highest-risk cross-border obliged entities directly, oversee how national supervisors do their jobs, and issue the technical standards that fill in the regulation. Direct supervision covers a limited list rather than every licensed firm, and most brokers and payment firms will stay under their national regulator.
The indirect effect is the one to plan for. When a European authority reviews national supervisors and publishes standards, the tolerance for a supervisor accepting a thin file drops. Firms in jurisdictions that historically ran lighter inspections should expect the inspection to change character before the law does, which is a pattern that has already played out with MiFID II conduct supervision.
What this means for a broker or prop firm
The practical work sits in four places. Customer files need to hold identity evidence, address evidence and a documented risk rating, with the reasoning visible rather than only the outcome. Ongoing monitoring has to be real: a file completed at signup and never touched again fails a modern inspection regardless of the initial quality. Source of funds and source of wealth questions have to be triggered by defined thresholds and behaviours rather than by an agent's instinct. And suspicious activity has to be reportable inside the deadline set by the national financial intelligence unit.
Most of that is a systems question. The firms that struggle are the ones storing verification results in one provider's portal, risk ratings in a spreadsheet and communications in a shared mailbox. Keeping the identity check, the verification level, the screening hits, the deposit history and the case notes on one client record inside the back office is what makes an inspection a one-day exercise rather than a three-week reconstruction.
The last point is jurisdictional honesty. Firms operating from outside the EU and accepting European clients sometimes assume none of this applies to them. Their payment providers, banking partners and any EU entity in the group apply it anyway, through contractual requirements and de-risking decisions. The rulebook reaches further than the licence map suggests, which is the same lesson covered in marketing into the EU from offshore.
"Nobody gets fined for having a slightly imperfect risk model. They get fined because they cannot show what they knew about a client and when they knew it. Keep the evidence trail on one record and most of the exposure disappears."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- AMLD4 introduced the risk-based approach and UBO registers, AMLD5 pulled crypto firms in, AMLD6 addressed criminal liability.
- The 2024 AML Regulation applies directly in every member state, removing most national variation in due diligence rules.
- AMLA will directly supervise only selected high-risk entities, but will reshape how national supervisors inspect everyone else.
- Inspections turn on evidence trails, so identity checks, risk ratings and case notes belong on one client record.
Frequently Asked Questions
What is the difference between an AML directive and the AML Regulation?
A directive sets objectives that each member state writes into its own national law, which is how twenty-seven different rulebooks appeared. A regulation applies directly in every member state without transposition, so the customer due diligence text a firm reads in Cyprus is the same text a firm reads in Germany.
Which AML directive brought crypto firms into scope?
AMLD5 first captured virtual currency exchange platforms and custodian wallet providers as obliged entities. The 2024 package widened this considerably by treating crypto-asset service providers under the same obligations as other financial institutions.
Will AMLA supervise every regulated firm directly?
No. AMLA is expected to directly supervise a limited group of selected obliged entities judged to carry the highest cross-border risk. Everyone else continues to be supervised nationally, with AMLA setting standards and reviewing how national supervisors apply them.