AMLR 2027: a quick-start guide to RTS group-wide rules (articles 16 (4) and 17 (3))
AMLA’s final draft Regulatory Technical Standards (RTS) set out how AML compliance should operate across an international firm: who is responsible, what information offices must share and what happens when local law prevents them from doing so.
For senior risk teams preparing for AMLR, the group-wide requirements deserve special attention. They cover the evidence behind client decisions, visibility of compliance failures and the authority needed to address them.
The standards remain final drafts, subject to European Commission review and adoption.
Which parts of the firm are covered?
The requirements can extend to networks and partnerships with common ownership, management or compliance control. Separate legal entities may therefore fall within scope because of how they are managed or how compliance is controlled across them. Shared branding or a common technology platform alone generally does not bring an arrangement within scope.
The provisions also differ in their reach. Article 5 covers information sharing with non-EU group entities more broadly. Articles 7–9 address legal impediments affecting non-EU branches and subsidiaries. Those distinctions matter when assessing which requirements apply to a firm’s international operations.
Clear responsibility, supported by information
Article 3 requires the responsible EU parent to document how compliance operates across the group, including responsibilities, reporting lines and sufficient decision-making authority for group compliance leaders.
Leadership, internal control teams and independent auditors must receive the information needed to oversee compliance and act on supervisory decisions. Annex I gives substance to that requirement: relevant information includes audit findings, compliance breaches, remedial action and supervisory inspections.
For an international firm, this means group oversight needs to account for significant findings across its offices. A completed CDD status may provide little insight into unresolved concerns or the reasoning behind a local decision.
The draft also requires firms to identify and manage conflicts between commercial interests and AML or sanctions responsibilities, including within individual entities and branches. Pressure to accept or retain a client is one practical example.
References: Article 3(1)(a)(i)–(iii); Annex I, 3(b), 3(h), 5(c).
Assessing risk across the group
The group risk assessment must reflect the organisation’s complexity and risk profile. It must consider risks across entities and branches, particularly those that could materially affect the wider group, including outsourcing and reliance arrangements. Non-EU operations require particular attention.
Annex I identifies relevant supporting information: business-wide and individual client risk assessments, changes in beneficial ownership or business activity, sanctions exposure and third-party arrangements.
Group compliance must also exchange information regularly with leadership, commercial teams, local compliance functions and auditors. These exchanges must be documented and cover relevant risks, significant compliance problems and the measures taken to address them.
For risk leaders, this requires access to enough local detail to judge its significance across the firm.
References: Article 3(1)(b)–(c); Annex I, 1(j)–(k), 3(a), 3(c)–(f).
Consistent controls across offices
Group policies and controls must fit the organisation, account for individual entities and branches, and be implemented consistently across applicable operations. Compliance and internal control teams must regularly review their effectiveness, communicate findings and address deficiencies.
Annex I supports that oversight through the sharing of audit findings, recommendations, corrective action and information about how group controls are being implemented.
Article 3 also requires:
- Secure whistleblowing and escalation channels, with appropriate protection.
- Defined arrangements for reporting and handling material breaches.
- Minimum training standards, including for leadership and senior management.
- Communication of policies and controls to relevant staff across applicable EU and non-EU operations.
- Group businesses that are not themselves subject to AML rules must not obstruct regulated entities from meeting their obligations.
The EU parent’s governing body approves group policies. Procedures and controls require approval at least from the group compliance manager. All must be written, current and available to supervisors on request.
References: Article 3(1)(d), 3(2)–(3); Annex I, 3(b), 5(a).
What information must be shared?
Article 4 requires sharing of relevant Annex I information for AML and sanctions purposes. This includes supporting evidence and analysis, as well as the outcome of checks.
Information and Annex I inclusions
Client identity and ownership
Identification and verification evidence for clients, beneficial owners and relevant representatives; ownership and control structures.
Purpose and expected activity
The reason for the relationship or transaction, expected business activity, source of funds and source of wealth.
Transactions and services
Relevant counterparties, people benefiting from activity, origin and destination, payment methods and accounts.
Risk assessments and changes
Client risk assessments, relevant PEP and sanctions information, adverse reports and analysis, and material changes in ownership or risk classification.
Restrictions and refusals
AML- or sanctions-related blocked accounts, rejected clients, terminated relationships and refused transactions, including the reasons.
Compliance findings
Breaches, audit findings, remedial action, implementation of controls and relevant supervisory interactions.
Reported suspicions
Suspicions reported to the FIU and supporting analysis, unless the FIU instructs otherwise, plus reporting volumes and typologies.
The reasons behind a refusal or exit are particularly useful to another office considering the same client. They allow the receiving team to assess the concern rather than work from an unexplained status.
The scope also extends beyond shared clients. Information about control weaknesses or emerging risks in one entity may be relevant to oversight elsewhere in the group.
Sharing remains subject to relevance, need-to-know access, legal restrictions and the exemption for certain protected legal information.
References: Article 4(1)–(2); Annex I, 1–5.
Sharing without an internal approval barrier
The parent must establish information-sharing rules. Those rules cannot require approval from the parent or another group entity before Annex I information is shared with a regulated entity within the group.
Suitable technical and organisational arrangements must make sharing possible. Information must be current, readily accessible and understandable, with secure channels, appropriate access restrictions and compliance with data protection requirements. Exchanges must be recorded so they can be traced and reviewed.
For firms using separate intake, AML and matter-management systems, the practical issue is whether authorised users can find the relevant evidence and understand its source, age and significance.
Each regulated entity remains responsible for its own CDD, risk assessment and decisions, even when using information from elsewhere in the group. Another office’s approval does not automatically satisfy those obligations.
References: Article 4(3)–(5).
When local law prevents sharing
Restrictions on sharing in either direction must be assessed and addressed. Under Article 5, the supervisor must be notified without undue delay and within 28 calendar days of identification.
For branches and subsidiaries covered by Article 7, the minimum response includes seeking consent from clients (and beneficial owners where applicable) to overcome the restriction, insofar as this is compatible with local law and AMLR. Consent cannot override a statutory prohibition.
Where consent is not feasible, additional measures are required. Options include fresh CDD by the receiving group entity instead of reliance on the restricted office, enhanced reviews or audits, senior approval for higher-risk relationships and additional monitoring. Underlying facts supporting a suspicious transaction report may be shared to the extent local law permits.
The measures must reflect the risk, and the supervisor must be informed of them and their adequacy. If risks remain unmanaged, escalation can include restrictions on business or closure of operations. Closure is not an automatic consequence of a blocked transfer.
References: Articles 5, 7–9.
The exemption for protected legal information
Article 6 excludes information covered by AMLR Article 70(2) from these sharing obligations. Broadly, this concerns information obtained by specified legal and accounting professionals while establishing a client’s legal position or advising on, defending or representing them in judicial proceedings.
The exemption depends on the circumstances in which the information was obtained. It does not cover every record held by a law firm. Article 70(2) also contains exceptions involving participation in money laundering, its underlying offences or terrorist financing, and advice provided or knowingly sought for those purposes.
References: Article 6; AMLR Article 70(2).
For senior risk managers, the implementation work will involve establishing which entities are covered, making relevant evidence available across them and recording where legal restrictions prevent access. Group oversight will need to show how significant findings are communicated, assessed and addressed.
About First AML
First AML comes from the perspective of both a technology provider, but also as compliance professionals. Prior to releasing First AML’s all-in-one AML workflow platform, we processed over 2,000,000 AML cases ourselves. Understanding the acute problem that faces firms these days as they try to scale their own AML, is in our DNA.
That's why First AML now powers thousands of compliance experts around the globe to reduce the time and cost burden of complex and international entity KYC. Source stands out as a leading solution for organisations with complex or international onboarding needs. It provides streamlined collaboration and ensures uniformity in all AML practices.
Keen to find out more? Book a demo today!