← All guides

Jurisdiction guide · EU

EU: the business-wide risk assessment under the AML Regulation and AMLA’s draft guidelines

Article 10 of the AML Regulation, AMLA’s four minimum requirements and what a payments business can prepare before July 2027.

Published

The obligation in the AML Regulation

Regulation (EU) 2024/1624, the AML Regulation or AMLR, applies from 10 July 2027. Article 10 requires obliged entities to take “appropriate measures, proportionate to the nature of their business, including its risks and complexity, and their size, to identify and assess the risks of money laundering and terrorist financing to which they are exposed, as well as the risks of non-implementation and evasion of targeted financial sanctions”. Read the AML Regulation on EUR-Lex

The assessment must take into account the risk variables and factors in the Regulation’s annexes, the EU and national risk assessments, publications by international standard setters, the Commission and AMLA, information from competent authorities, and information on the customer base. New products, services, delivery channels, customer segments and geographical areas must be assessed before launch.

Article 10(2) sets the governance. The business-wide risk assessment “shall be documented, kept up-to-date and regularly reviewed”, made available to supervisors on request, “drawn up by the compliance officer and approved by the management body in its management function”, and communicated to the management body in its supervisory function where one exists. Supervisors may waive individual documented assessments in some sectors, but not for credit institutions or financial institutions, so a payment institution or e-money institution should expect to keep its own.

AMLA’s draft guidelines

Article 10(4) required AMLA to issue guidelines on the minimum content of the business-wide risk assessment and on additional sources of information by 10 July 2026. AMLA opened a public consultation on draft guidelines on 16 April 2026, held a public hearing on 28 May 2026 and closed responses on 15 July 2026. Final guidelines follow the consultation; check AMLA’s site for the published version. Read the consultation

The draft proposes four minimum requirements that apply across all obliged entities:

  1. A business and operational overview of the entity.
  2. Identification, assessment and classification of inherent risks, covering money laundering, terrorist financing and the non-implementation and evasion of targeted financial sanctions.
  3. Assessment of the quality of the controls that mitigate those risks.
  4. Assessment and classification of residual risk.

The draft also stresses proportionality: the assessment should not be “a mere formalistic exercise”, non-complex entities may use a less elaborate and more qualitative assessment, and firms may use third parties to help draw it up provided the proposal and approval stay inside the firm and the firm can explain the methodology and results. A parent undertaking should have branches and subsidiaries assess with a common methodology and consolidate them into a group-wide view.

What a payments business can prepare now

The direction is clear even before the final text. A payments business in the EU can usefully:

  • Write the business and operational overview: entities, licences, products, customer segments, corridors, channels and agents or distributors.
  • Separate targeted financial sanctions risk from money laundering and terrorist financing risk, and assess both the risk of non-implementation and the risk of evasion.
  • Define the methodology and the sources of information used, including the national risk assessment and supervisory publications.
  • Record control quality with evidence, not assertion, and derive residual risk from it.
  • Have the compliance officer draw it up and the management body approve it, and keep the record of that approval.
  • Set the review cycle and the internal and external events that trigger an earlier update.

How to reflect it in EWRA

EWRA follows the same three-phase structure the draft guidelines describe: inherent risk, control effectiveness, residual risk, with the rationale and evidence kept next to each answer and the report building as you work.

  • Use the entity details and domain questionnaires to capture the business and operational overview.
  • Assess sanctions on its own terms, separately from the ML/TF methodology, with its own scoring and governance record.
  • Grade design and operating effectiveness for each control and let residual risk follow.
  • Route the assessment through preparation, review, second-line challenge and approval, so the compliance-officer and management-body steps are time-stamped in the audit trail.
  • Compare year on year to show what changed, and for a group, view entities side by side.

The demonstration environment uses a fictional payments group whose entities include an EU entity, so you can see how the group view and the entity assessments fit together. Try the payments demo Sample data only; no sign-up.

Check the current position

The Regulation and AMLA’s published guidelines are the sources to rely on. Confirm the application date for your entity type, whether your national supervisor has issued a sectoral assessment you may start from, and the final wording of the guidelines once published. AMLA’s announcement

How to do an EWRA

This guide provides general information, not legal advice. Check the current source material and requirements applicable to your firm. Software does not confer regulatory approval.