The EU AML regulation and AMLA: what changes in 2027
By Arturo Navarro · 25 September 2026
On 19 June 2024 the Official Journal of the European Union published the three pieces of the new European framework against money laundering and terrorist financing. The one that changes an obliged entity's daily work most is Regulation (EU) 2024/1624, which its Article 90 declares «binding in its entirety and directly applicable in all Member States» from 10 July 2027. Until now a Spanish entity read its obligations in a national law that transposed directives; from that date, customer due diligence, beneficial ownership and record retention are read, above all, in a European regulation.
Three acts and one timetable
The package splits the work between a regulation of obligations, a directive of institutional architecture and a regulation that creates a European supervisor:
| Act | What it governs | From when |
|---|---|---|
| Regulation (EU) 2024/1624 | The obligations of obliged entities: customer due diligence, beneficial ownership, reporting to the FIU, record retention, the cash limit | 10 July 2027 (Article 90); for football agents and professional football clubs, 10 July 2029 |
| Directive (EU) 2024/1640 | Beneficial ownership and bank account registers, the tasks of financial intelligence units (FIUs) and of supervisors, and cooperation between authorities (Article 1) | Transposition by 10 July 2027 (Article 78), with some articles earlier and Article 18 in 2029 |
| Regulation (EU) 2024/1620 | The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), seated in Frankfurt am Main (Article 4) | First selection of entities for direct supervision from 1 July 2027 (Article 13(4)) |
Directive (EU) 2024/1640 repeals Directive (EU) 2015/849 with effect from 10 July 2027. In Spain, SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC is the Financial Intelligence Unit and also the Supervisory Authority for the prevention of money laundering; the Regulation does not change that dual role, but it does change the text it applies to the entities it supervises.
The figures that change
A directly applicable regulation leaves less room for transposition, and many of its obligations are expressed as thresholds. These are the ones that reach a KYC (Know Your Customer) is the sector name for customer due diligence under Directive (EU) 2015/849: identifying and verifying the customer, identifying the beneficial owner, assessing the relationship's purpose and monitoring it over time. It is completed before the relationship opens, with exceptions (Article 14).Read more → KYC and monitoring system:
| Obligation | What Regulation (EU) 2024/1624 says |
|---|---|
| Due diligence on occasional transactions | From a value of at least EUR 10,000, in one operation or in linked operations (Article 19(1)(b)) |
| Occasional transactions of crypto-asset service providers | Due diligence from EUR 1,000 (Article 19(3)(a)); below that, at least identifying the customer and verifying their identity |
| Occasional cash transactions | At least identifying the customer and verifying their identity (Article 20(1)(a)) from EUR 3,000 (Article 19(4)) |
| Limit on cash payments for goods or services | Up to EUR 10,000 (Article 80(1)), unless national limits are lower |
| Beneficial ownership through ownership interest | Direct or indirect ownership of 25% or more (Article 52(1)); for higher-risk categories, a lower threshold of at most 15% (Article 52(2)) |
| Record retention | Five years from the end of the business relationship or the occasional transaction, extendable case by case for at most five more (Article 77(3)) |
In Spain the cash limit remains lower than the European one
Article 80(3) of the Regulation keeps national limits that are already below the European one. In Spain, Law 7/2012, Article 7 prohibits paying in cash for transactions of 1,000 euros or more when either party acts as a business or professional. A monitoring rule that applies in Spain the European limit of Article 80(1), EUR 10,000, lets through what national law already prohibits.
Who moves under AMLA supervision
AMLA will not directly supervise every entity. Article 12(1) of Regulation (EU) 2024/1620 limits the periodic assessment to credit and financial institutions, and their groups, operating in at least six Member States, including the home Member State, whether through establishments or under the freedom to provide services. Of those, Article 13(1) selects the ones whose residual risk profile is classified as high; if there are more than forty, Article 13(2) allows the selection to be limited to a number above forty.
Article 13(4) sets the timetable: the Authority commences the first selection process by 1 July 2027, concludes it within six months, publishes the list and starts direct supervision six months after publishing it. For the vast majority of Spanish obliged entities the supervisor remains national; what changes is the law it applies and the supervisory convergence the Authority drives.
What it means for the compliance architecture
The change of law shows less in manuals than in systems. Three articles of Regulation (EU) 2024/1624 are enough to measure the gap:
- The decision not to report is also retained. Article 77(1)(b) requires a record of the assessment carried out, including the information and circumstances considered and its results, «whether or not such assessment results in a suspicious transaction report being made to the FIU». Every dismissed alert needs a trail a supervisor can reproduce years later.
- Records are not redacted. The same article requires that documents, information and records «are not redacted», and Article 77(2) only allows keeping references instead of copies if the method guarantees the information can be provided immediately and «cannot be modified or altered».
- Thresholds depend on the jurisdiction and the sector. The Regulation sets one for general due diligence, another for crypto-assets and another for cash; Article 19(9) provides for lower thresholds through regulatory technical standards, and the Spanish cash limit sits below the European one. A rule hard-coded in the system does not survive the first change.
It is the same traceability requirement raised by triaging alerts with an AI agent and by reporting to SEPBLAC: the system has to be able to explain why it decided, not only what it decided.
Auditability is designed before the inspection
An assessment record written afterwards, by hand, proves nothing. What holds up in an inspection is an immutable trail generated at the moment of deciding, with the data the decision had in front of it.
Common mistakes before the 2027 deadline
- Waiting for the Spanish law. The Directive has to be transposed, but the Regulation applies directly from 10 July 2027, with or without a reform of national law.
- Reading the European cash limit as a rise. In Spain the limit of 1,000 euros for businesses and professionals remains in force (Article 7 of Law 7/2012, which Article 80(3) of the Regulation keeps).
- Treating a dismissed alert as a non-event. Article 77(1)(b) turns it into a mandatory record.
- Assuming AMLA will supervise everyone. Its direct supervision only reaches entities operating in at least six Member States with a high residual risk profile.
Conclusion: the same obligation, a stricter law on proof
Regulation (EU) 2024/1624 does not invent the prevention of money laundering; it unifies it and makes it verifiable. The thresholds change little for a Spanish entity, but the duty to retain the assessment of every alert, unredacted and unalterable, turns traceability into a requirement rather than a good practice.
BlueUPALM addresses that requirement with an immutable audit trail of compliance actions and decisions and special examination for SEPBLAC. The first step is to check where the assessment of a dismissed alert is kept today.
Related reading
- Anatomy of agentic AI AML triage: what the machine decides — The assessment record, alert by alert.
- SEPBLAC software: automate AML reporting without losing traceability — Reporting to the FIU downstream.
- AML automation with AI: from manual screening to intelligent triage — The starting point of monitoring.
Want to see how a dismissed alert is traced?
We show you the assessment record, the special examination and the BlueUPALM audit trail with a scenario from your sector.