AMLR in plain English: Draft RTS for group-wide standards. Articles 16(4) and 17(3)
AMLA’s draft group-wide standards are dense reading. This page puts Articles 3–6 and Annex I into plain English. It is a reading aid, not a substitute for the legal text. The RTS remain subject to European Commission review and adoption.
Article 3. Minimum group-wide requirements
The EU parent undertaking must ensure that the following organisational, risk-assessment, compliance and control requirements are met.
Article 3(1)(a)(i) - Clear responsibilities and decision-making authority
Establish, implement and maintain a documented framework for organising and coordinating compliance across the group. Allocate functions, responsibilities and reporting lines clearly. Give the group compliance manager, and the group compliance officer appointed where justified by group activities under AMLR Article 16(2), sufficient decision-making authority.
Article 3(1)(a)(ii); Annex I, 3(b), 3(h), 5(c) - Information for oversight
Ensure the governing body, internal control functions and independent audit function have the group-level information needed to perform their responsibilities and implement supervisory decisions affecting EU and non-EU group entities and branches.
Relevant information includes audit findings, compliance breaches, remedial action and interactions with supervisors, including inspections.
Article 3(1)(a)(iii) - Conflicts with commercial interests
Identify and mitigate conflicts between commercial functions and the prevention and management of money laundering, terrorist financing and targeted financial sanctions risks. Include conflicts at entity and branch level, where applicable, within the risk-management framework.
Article 3(1)(b)(i); Annex I, 3(a) - Group risk assessment
Ensure the group-wide risk assessment is appropriate to the group’s complexity and risk profile. Relevant information available for sharing includes business-wide assessments and the risk patterns and indicators identified by individual entities.
Article 3(1)(b)(ii); Annex I, 1(j)–(k), 3(a), 3(c)–(f) - Risks across entities and branches
Assess risks across group entities and branches, focusing on those that could significantly affect the group’s overall exposure. Include outsourcing, reliance on other regulated entities and other third-party arrangements. Pay particular attention to non-EU operations.
Relevant information includes individual customer and occasional-transaction assessments, material changes in customer risk, PEP information, sanctions risk assessments and CDD outsourcing or reliance arrangements.
Article 3(1)(c)(i); Annex I, 3–5 - Regular, documented information exchanges
Ensure group compliance functions regularly exchange information with the parent’s governing body, commercial functions, local compliance functions, other internal control functions, independent audit functions and external auditors. Document these exchanges.
Relevant information can include risk assessments, control reviews, compliance breaches, reported suspicions and information about implementation of group controls, subject to the applicable sharing safeguards.
Article 3(1)(c)(ii); Annex I, 3(b), 3(h)–(j), 4(a)–(b) - Minimum content of those exchanges
The exchanges must cover, at a minimum, relevant information about identified risks, significant compliance issues and measures taken to address them.
This can include audit findings, remedial action, clients rejected or exited and the reasons, refused transactions, adverse information and its analysis, and reported suspicions, subject to applicable restrictions.
Article 3(1)(d)(i); Annex I, 3(a), 5(a) - Policies and controls suited to the group
Ensure group policies, procedures and controls fit the group’s actual organisation, composition and operations. Account for the individual circumstances of entities and branches and include all elements required by AMLR Articles 9 and 10.
Relevant information for sharing includes business-wide risk assessments and information about how group controls are implemented, including outsourcing and reliance arrangements.
Article 3(1)(d)(ii); Annex I, 3(a)–(b), 3(h) - Group-specific risks and non-compliance
Account for group-specific risks when designing and applying policies, procedures and controls. Include group-wide measures to address non-compliance.
Relevant shared information includes risk assessments, compliance breaches, audit findings and remedial or corrective action.
Article 3(1)(d)(iii)(1)–(3); Annex I, 3(b) - Reviewing effectiveness and addressing deficiencies
Ensure compliance and internal control functions regularly review whether group policies, procedures and controls are effective, inform relevant stakeholders and address deficiencies.
Relevant information includes internal-control and audit reviews, findings, recommendations, results and corrective action at group and entity level.
Article 3(1)(d)(iv); Annex I, 5(a) - Consistent implementation
Ensure group policies, procedures, controls and risk assessments are implemented consistently across all applicable entities and branches, including subsidiaries and branches outside the EU.
Share relevant information about their implementation, including outsourcing, reliance on other regulated entities and other third-party arrangements.
Article 3(1)(d)(v) - Whistleblowing
Establish, implement and maintain group-wide whistleblowing policies, procedures and controls within the risk-management framework. Include secure reporting and escalation channels and appropriate safeguards for whistleblowers.
Article 3(1)(d)(vi); Annex I, 3(h), 5(b) - Incident reporting and notification
Establish, implement and maintain group-wide arrangements for reporting and notifying incidents. Clearly define how material breaches are handled, with communication procedures and tools that adequately protect relevant information.
Relevant information covered by Annex I includes AML/CFT and sanctions-related breaches and incidents.
Article 3(1)(d)(vii); Annex I, 5(b) - Training
Establish, implement and maintain group-wide training policies, procedures and controls. Set adequate minimum standards for training frequency, categories and delivery, including for the governing body and senior management.
Relevant training information is covered by Annex I. It does not prescribe particular training metrics or reporting formats.
Article 3(1)(d)(viii) - Group entities outside the AML-regulated perimeter
Design and implement group policies, procedures and controls so that entities which are not themselves subject to AMLR do not prevent the parent and regulated group entities from complying.
Article 3(1)(d)(ix) - Communication to staff
Communicate group policies, procedures and controls to relevant staff, including staff in subsidiaries and branches in EU and non-EU countries, as applicable.
Article 3(2) - Approval of policies, procedures and controls
The EU parent’s governing body, acting in its management role, must approve group-wide internal policies. Group-wide procedures and controls must be approved at least by the group compliance manager referred to in AMLR Article 16(2).
Article 3(3) - Written and current records
Record group policies, procedures and controls in writing, keep them up to date and make them available to supervisors on request.
Article 4. Information sharing within a group
Article 4(1); Annex I, 1–5 - Purpose and scope
The parent and regulated group entities must enable sharing of Annex I information when relevant to preventing money laundering, terrorist financing and the failure to implement or evasion of targeted financial sanctions.
This covers CDD information, ongoing monitoring, risk assessments, compliance findings, reported suspicions and other relevant compliance information.
Article 4(2); Annex I, 1–5 - Availability and quality
Provide for sharing Annex I information with any regulated entity within the group, taking account of its availability and quality. The need-to-know, security and other safeguards in Article 4(4) apply.
Article 4(3); Annex I, 1–5 - Sharing arrangements and approval
The parent must define and maintain group information-sharing policies and procedures. Group requirements must not make sharing Annex I information with a regulated group entity conditional on approval from the parent or another regulated entity.
Regulated group entities must establish suitable technical and organisational arrangements for sharing, taking account of their size, complexity and risks.
Article 4(4); applies across Annex I - Information quality, access and security
Information must be up to date, readily accessible and presented in an adequate, understandable form. Share it on a need-to-know basis, in accordance with applicable data protection legislation and fundamental rights, through secure channels that preserve security, integrity and confidentiality.
Maintain appropriate records of information exchanges to support traceability, accountability and effective supervision.
Article 4(5); Annex I, 1(j), 3(c)–(d), 5(a) - Individual entity responsibility
Sharing information does not change each regulated entity’s responsibility to comply with AML/CFT requirements and prevent targeted financial sanctions risks.
Each entity remains fully responsible for its own due diligence, risk assessments and decisions, including when using shared information. Applicable outsourcing, reliance and other third-party arrangements must also be taken into account.
Article 5. Information sharing with non-EU group operations
Article 5(1); Article 4; Annex I, 1–5 - Sharing information outside the EU
Regulated entities established in the EU, or whose head office is in the EU, must be able to share Article 4 information with group entities or branches established outside the EU or whose head office is outside the EU.
Sharing remains subject to restrictions or prohibitions in EU or Member State law. The separate measures in Section 4 of the RTS continue to apply.
Article 5(2); Article 4; Annex I, 1–5 - Receiving information from outside the EU
Regulated entities established or located in the EU must be able to receive Article 4 information from group entities established outside the EU or from their non-EU head office.
Sharing remains subject to restrictions or prohibitions under the relevant non-EU country’s law. The separate measures in Section 4 continue to apply.
Article 5(3) - Assessing legal restrictions
Where law restricts or prohibits sharing in either direction, the parent and EU regulated entities must assess the reasons and take appropriate measures to address the restriction.
The parent must provide the assessment to relevant regulated entities within the group whenever needed.
Applies to restricted information covered by Article 4 and Annex I
Article 5(4) - Notifying supervisors
Notify the appropriate supervisor of the assessment and, where appropriate, alternative methods for addressing the restriction or prohibition. Notify without undue delay and no later than 28 calendar days after identifying it.
For groups, the parent submits the notification. Where a single notification is inappropriate, the parent may allow regulated entities to notify their respective supervisors.
A single notification at group or entity level may also cover cases falling under Section 4.
Article 5(5) - Coordination between supervisors
The supervisor must immediately inform the supervisors of the group’s other EU regulated entities about the restrictions or prohibitions.
Where the supervisor is a self-regulatory body, it must also inform the public authority overseeing it.
Article 6. Exemption for certain client information
Information excluded from these sharing requirements
The information-sharing obligations in Section 3 do not apply to information covered by AMLR Article 70(2).
That provision concerns information obtained by notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisers when establishing a client’s legal position or defending or representing a client in, or concerning, judicial proceedings. It includes advice on starting or avoiding proceedings and information obtained before, during or after them.
The Article 70(2) exemption does not apply where the professional:
- Participates in money laundering, its predicate offences or terrorist financing.
- Provides legal advice for those purposes.
- Knows the client is seeking legal advice for those purposes.
- Knowledge or purpose can be inferred from objective factual circumstances.
About First AML
First AML comes from the perspective of both a technology provider, but also as compliance professionals. Prior to releasing, First AML’s all-in-one AML workflow platform, we processed over 2,000,000 AML cases ourselves. Understanding the acute problem that faces firms these days as they try to scale their own AML, is in our DNA.
That's why First AML now powers thousands of compliance experts around the globe to reduce the time and cost burden of complex and international entity KYC. First AML stands out as a leading solution for organisations with complex or international onboarding needs. It provides streamlined collaboration and ensures uniformity in all AML practices.
Keen to find out more? Book a demo today!