The EU AML package is a set of 2024 laws that overhaul anti-money laundering rules across the European Union. Its core is AMLR (Regulation (EU) 2024/1624), a single rulebook that applies directly in all 27 Member States from 10 July 2027. Alongside it sit AMLD6 (Directive (EU) 2024/1640), which Member States transpose into national law, and the AMLA Regulation, which created the EU Anti-Money Laundering Authority in Frankfurt, operational since 1 July 2025. To be ready, obliged entities need their customer due diligence, beneficial ownership data and entity identification in order before the 2027 application date.
The problem: a fixed deadline against fragmented data
Most compliance teams already know the EU rewrote its AML framework in 2024. Fewer have mapped what it means for the entity data they hold, and that is where the work sits. AMLR does not ask for a new form to be filed. It raises the standard for how obliged entities identify customers, verify beneficial owners, and keep that information current, and it makes those rules identical across the bloc. The deadline is fixed at 10 July 2027. The data clean-up that makes compliance straightforward is the part that takes time, so the firms that start early carry the least risk.
This piece sets out the three instruments, what changes for obliged entities, and a readiness checklist you can act on now.
The three instruments of the AML package
A common error in AML coverage is to treat “AMLA”, “AMLR” and “AMLD6” as interchangeable. Each does a distinct job.
AMLR, the regulation. Regulation (EU) 2024/1624 is the single rulebook. Because it is a regulation, it is directly applicable: no national transposition, the same text binding a bank in Dublin and a payments firm in Tallinn. It entered into force on 9 July 2024 and applies from 10 July 2027. It covers customer due diligence, beneficial ownership, and reporting.
AMLD6, the directive. Directive (EU) 2024/1640 handles what is better left to national systems: beneficial ownership registers, the powers of financial intelligence units, and how national supervisors operate. Member States must transpose it by 10 July 2027, with some registry-access provisions phased to 2029.
The AMLA Regulation. Regulation (EU) 2024/1620 created the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, AMLA, seated in Frankfurt and operational since 1 July 2025. AMLA will directly supervise a small group of the highest-risk, most cross-border institutions, and will coordinate national supervisors for everyone else.
What changes
A single rulebook replaces 27 interpretations. The shift from directive to regulation is the structural change. Divergence between national AML regimes, long a source of cost and arbitrage, narrows sharply. If you operate in more than one Member State, you move toward one set of obligations rather than several.
More entities are in scope. AMLR widens the obliged-entity population. New additions include crypto-asset service providers (CASPs), crowdfunding service providers and intermediaries, and traders in high-value goods such as precious metals and stones. Professional football clubs and agents come into scope, with their provisions applying from 10 July 2029.
Beneficial ownership rules tighten. From 10 July 2027 a beneficial owner is identified at 25% or more of ownership interest, held directly or indirectly. A lower threshold can apply in higher-risk sectors, but it is not a level Member States set at will: Member States notify higher-risk categories to the European Commission, which may, following an assessment due by 10 July 2029, set a lower threshold by delegated act, capped at 15%. Obliged entities must identify and verify beneficial owners and consult the central registers maintained under AMLD6.
A Union-wide cash limit. AMLR sets an EU-wide limit of EUR 10,000 on cash payments for goods and services, with Member States free to set lower national limits.
Direct EU supervision arrives. From 1 January 2028, AMLA directly supervises a first group of selected obliged entities, capped at around 40, each operating in at least six Member States and assessed as high risk. The selection process runs through the second half of 2027. Most firms will not be directly supervised by AMLA, but every obliged entity is bound by AMLR’s rules regardless of who supervises them.
Where entity identification and the LEI fit
AMLR is specific about the information an obliged entity must collect to identify a legal-entity customer. Under Article 22, that information includes, “where available”, the entity’s registration number, tax identification number, and Legal Entity Identifier (LEI). The LEI is the 20-character ISO 17442 code that identifies a legal entity uniquely and globally.
The characterisation matters, and it is easy to get wrong. AMLR does not require any company to obtain an LEI. The duty is on the obliged entity to collect a customer’s LEI where the customer has one. The customer still benefits directly: an entity that already holds a valid, active LEI hands its counterparties the precise, machine-readable identifier the regulation points to, which makes their due diligence faster and cleaner. For a group managing many entities, funds or subsidiaries, holding active LEIs across the structure removes a recurring point of friction from every counterparty’s onboarding.
Two further points worth tracking. AMLR allows identity verification using electronic identification means that meet the eIDAS “substantial” or “high” assurance levels, which is the direction the vLEI (the verifiable, cryptographically signed form of the LEI) is built for. The vLEI is not referenced in AMLR and is not a requirement; it is the emerging next step in digital entity verification. Separately, the recast Transfer of Funds Regulation already asks that fund and crypto transfers carry originator and beneficiary data, including the LEI where available.
A readiness checklist for 10 July 2027
You do not need to wait for AMLA’s technical standards to start. The data work is independent of the detail.
- Inventory your own entities. List every legal entity you control: parent, subsidiaries, funds, SPVs, branches. Confirm which hold an LEI and which do not.
- Check LEI status and lapse dates. A lapsed LEI is publicly visible in the Global LEI Index. Identify anything lapsed or due to lapse before 2027 and bring it current.
- Consolidate issuance and renewal. If LEIs are tracked on a spreadsheet or spread across several issuers, move to a single managed view so nothing renews late.
- Review beneficial ownership data against the 25% threshold. Confirm your records identify beneficial owners on the AMLR basis, and track whether any sector in which you operate becomes subject to a lower threshold (capped at 15%) under the Commission delegated-act process due by 10 July 2029.
- Map your obliged-entity status. If you are newly in scope (for example a CASP or crowdfunding platform), start building the CDD and monitoring capability now.
- Brief the board. Frame AMLR as a data-quality and operational-resilience programme to complete ahead of the 2027 deadline.
The case for starting now
AMLR is not yet in force. The obligations apply from 10 July 2027, which gives compliance teams a defined runway to get entity identification and beneficial ownership data in order before the standard rises. Clean, current LEIs across your entity structure are one of the simplest pieces of that readiness to put in place, and one of the most visible if neglected.
Next step: check and consolidate the LEIs across your entities. Register or renew an LEI, or if you manage entities at scale, talk to us about managing LEI Numbers in bulk.