European Union KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in European Union.

Direct answer
What does the European Union compliance checklist cover?
The European Union checklist translates primary KYC, KYB and AML rules into 13 control areas and 67 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Current preventive framework
- Directive (EU) 2015/849, as amended, implemented through each Member State's national law until 10 July 2027
- Future single rulebook
- Regulation (EU) 2024/1624 generally applies from 10 July 2027; football agents and professional football clubs from 10 July 2029
- EU-level authority
- AMLA assumed EU-level AML/CFT tasks on 1 January 2026; national authorities and FIUs retain their statutory roles
- Current general CDD floor
- Business relationships always; occasional transactions EUR 15,000 or more; lower and sector-specific national triggers may apply
- Current sector triggers
- Transfers exceeding EUR 1,000; cash goods transactions EUR 10,000 or more; gambling transactions EUR 2,000 or more
- Suspicious reporting
- No EU monetary threshold; report promptly to the FIU designated by the applicable Member State using its national channel
- Beneficial ownership
- Current national transposition generally uses more than 25% ownership plus control and senior-manager fallback; verify the national act and register
- Core AML retention
- EU baseline five years after the relationship ends or occasional transaction; national extension and deletion rules vary
- Transfers and crypto
- Regulation (EU) 2023/1113 has applied since 30 December 2024 to covered funds and crypto-asset transfers
- Financial sanctions
- EU regulations bind operators, but licensing, reporting, investigation and enforcement are handled by national competent authorities
- Privacy
- GDPR applies across the EU, with national laws, supervisory authorities and permitted Member-State specifications
- FATF public lists
- Bulgaria was the only EU Member State named on the FATF increased-monitoring list reviewed 31 July 2026; no EU Member State was on the call-for-action list
Implementation detail
European Union compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Legal layers, scope and transitionStart with the date, entity, activity and Member State. A directive does not create one identical national operating rule, and a directly applicable regulation does not create one national reporting or enforcement channel.4 items+
Until 10 July 2027, Directive (EU) 2015/849 as amended remains the EU preventive baseline through 27 national transposition regimes.
- Implementation action
- Map every establishment and cross-border service to the current national act, obliged-entity perimeter, exemptions, supervisor and FIU; apply stricter national rules where valid.
- Evidence to retain
- Entity and branch map, national-law inventory, perimeter opinions, supervisory allocation, effective-date register and counsel approvals.
- Primary citation
- Directive (EU) 2015/849, arts. 2, 4-5 and 67; Directive (EU) 2024/1640, art. 77
Regulation (EU) 2024/1624 generally applies from 10 July 2027, with a 10 July 2029 start for football agents and professional football clubs.
- Implementation action
- Keep the AMLR as a dated change programme, not current operative customer law; map new obliged entities, the EUR 10,000 cash cap and harmonized controls to the correct commencement date.
- Evidence to retain
- Transition plan, legal gap assessment, product backlog, training plan, configuration tests and dated launch gates.
- Primary citation
- Regulation (EU) 2024/1624, arts. 80 and 90
Directive (EU) 2024/1640 has staged national transposition deadlines and replaces the current directive from 10 July 2027.
- Implementation action
- Track each Member State's enacted measures rather than assuming identical or timely transposition; preserve earlier deadlines for designated provisions and later timing for single FIU access points.
- Evidence to retain
- 27-state transposition tracker, official-gazette links, legal comparison, dependencies and escalation record.
- Primary citation
- Directive (EU) 2024/1640, arts. 77-78
AMLA has held transferred EU-level AML/CFT responsibilities since 1 January 2026; its first direct supervision of selected high-risk cross-border financial entities begins in 2028.
- Implementation action
- Identify the current national financial, professional or self-regulatory supervisor; do not replace the national supervisor or FIU with AMLA, and do not treat the ECB's prudential mandate as general AML supervision.
- Evidence to retain
- Authority matrix, future direct-supervision assessment, current supervisory correspondence and FIU routing tests.
- Primary citation
- Regulation (EU) 2024/1620, arts. 5, 12-17 and 54; AMLA direct-supervision explainer
02Governance and risk assessmentThe current directives require national risk-based systems; the precise governance allocation, fit-and-proper rules, independent audit and supervisor expectations remain sector- and state-specific.3 items+
Obliged entities must identify and assess ML/TF risk using customer, country, product, transaction and delivery-channel factors and keep the assessment current.
- Implementation action
- Maintain EU group methodology plus entity- and Member-State-specific risk assessments; incorporate national and supranational risk assessments and document divergence.
- Evidence to retain
- Business-wide and local risk assessments, source register, methodology, approval minutes, control mapping and update log.
- Primary citation
- Directive (EU) 2015/849, arts. 6-8
Policies, controls and procedures must be proportionate and include model risk management, CDD, reporting, records, internal control, compliance management and staff screening where appropriate.
- Implementation action
- Assign accountable management, local MLRO or contact roles required by national law, independent assurance and escalation; reconcile group standards with local mandatory rules.
- Evidence to retain
- Governance charter, appointment records, policies, local addenda, training, testing, issues and board reporting.
- Primary citation
- Directive (EU) 2015/849, arts. 8, 45 and 46
Group-wide controls and information sharing do not override GDPR, national secrecy rules or host-state obligations.
- Implementation action
- Map controller/processor roles, permitted AML data flows, host requirements and escalation where third-country law prevents group controls.
- Evidence to retain
- Group policy, data-flow map, legal-basis analysis, transfer mechanism, conflicts register and regulator communications.
- Primary citation
- Directive (EU) 2015/849, arts. 45 and 46; GDPR, arts. 5, 6, 28 and 44-49
03CDD triggers and natural-person KYCThe directive amounts are minimum harmonization points, not a safe universal configuration. Member States may impose lower thresholds and additional event-, sector- or risk-based triggers.4 items+
CDD is required when establishing a business relationship, on suspicion regardless of threshold, and when prior identification data is doubtful.
- Implementation action
- Make relationship creation, suspicion and data-quality failure hard triggers in every Member State; overlay local definitions and sector rules.
- Evidence to retain
- Trigger matrix, onboarding rules, suspicion override, refresh logic, tests, exceptions and approvals.
- Primary citation
- Directive (EU) 2015/849, art. 11(a), (e) and (f)
The current directive sets CDD floors at EUR 15,000 for occasional transactions, more than EUR 1,000 for covered funds transfers, EUR 10,000 cash for goods traders and EUR 2,000 for gambling transactions.
- Implementation action
- Configure the lower of applicable EU and national triggers, aggregate linked operations, preserve sector scope and never describe these as universal transaction-reporting thresholds.
- Evidence to retain
- Country threshold table, currency-conversion method, linked-transaction logic, sector mapping, test cases and legal sign-off.
- Primary citation
- Directive (EU) 2015/849, art. 11(b)-(d)
Identify the customer and verify identity using reliable independent documents, data or information; understand purpose and intended nature and monitor the relationship.
- Implementation action
- Define risk-based evidence standards, validate authenticity and identity binding, capture purpose and expected activity, and refresh on risk or material change.
- Evidence to retain
- Identity evidence, validation result, customer profile, risk decision, timestamps, monitoring and refresh history.
- Primary citation
- Directive (EU) 2015/849, arts. 13-14
A representative must be authorized and identified and verified; failure to complete required CDD normally prevents the relationship or transaction and requires an STR assessment.
- Implementation action
- Validate mandates and signatory power; block activation or transaction on unresolved CDD, document national exceptions and escalate reporting without tipping off.
- Evidence to retain
- Mandate, representative KYC, restriction, exit record, exception analysis, STR decision and approval.
- Primary citation
- Directive (EU) 2015/849, arts. 13(1), 14 and 39
04KYB, ownership and registersCorporate CDD, the entity's own national filing duty and access to a national beneficial-ownership register are separate controls. Register access and content differ following EU case law and national legislation.4 items+
For legal persons, understand ownership and control and take reasonable measures to verify beneficial owners, using senior-management fallback only after all possible means are exhausted and no suspicion remains.
- Implementation action
- Trace each ownership layer to natural persons, test control through other means, record every unsuccessful step before fallback and apply the operative national definition.
- Evidence to retain
- Registry extracts, constitutional documents, ownership calculations, control analysis, exhaustion log and reviewer approval.
- Primary citation
- Directive (EU) 2015/849, arts. 3(6), 13 and 30
The current directive's indicative corporate ownership threshold is more than 25%, but ownership percentage does not displace control through other means and national law can be stricter.
- Implementation action
- Do not encode 25% as the sole test; identify lower national or sector thresholds and verify direct, indirect, voting, contractual and de facto control.
- Evidence to retain
- Country rule table, cap table, indirect ownership calculation, voting agreements, control memo and sign-off.
- Primary citation
- Directive (EU) 2015/849, art. 3(6)(a)
Member States maintain national central beneficial-ownership registers and BORIS interconnects available national information, but authorization, authentication, fees, covered arrangements and access conditions vary.
- Implementation action
- Use the correct national company and BO register, evidence lawful access, obtain current extracts and corroborate them; do not treat missing public access or an extract as proof of no beneficial owner.
- Evidence to retain
- National register query, BORIS result, access basis, source documents, discrepancy decision and refresh schedule.
- Primary citation
- Directive (EU) 2015/849, arts. 30-31; European e-Justice Portal, BORIS directory
Obliged entities must report discrepancies found between CDD and register information under the applicable national process.
- Implementation action
- Define the national recipient, materiality or scope, filing route and timing; retain comparison and resolution evidence without delaying necessary CDD remediation.
- Evidence to retain
- Register-to-CDD reconciliation, discrepancy classification, report, acknowledgement, correction and closure record.
- Primary citation
- Directive (EU) 2015/849, arts. 30(4) and 31(5)
05PEPs, EDD and remote onboardingEDD is risk- and trigger-based. National PEP lists, domestic treatment, high-risk-country measures and acceptable digital identity evidence must be mapped locally.3 items+
For a PEP, family member or known close associate, obtain senior-management approval, establish source of wealth and source of funds, and conduct enhanced ongoing monitoring.
- Implementation action
- Screen customers, representatives and beneficial owners; adjudicate matches, distinguish the national PEP definition and document relationship-specific approval and evidence.
- Evidence to retain
- Screening results, role and relationship analysis, wealth narrative, funds evidence, approval and monitoring plan.
- Primary citation
- Directive (EU) 2015/849, arts. 20-23
EDD applies to high-risk situations and relationships or transactions involving third countries identified under the EU process, with national additional measures possible.
- Implementation action
- Maintain separate EU, FATF and national lists, record the legal consequence of each and apply proportionate measures rather than automatic blanket rejection.
- Evidence to retain
- List versions, trigger mapping, risk decision, additional evidence, approvals, monitoring and review.
- Primary citation
- Directive (EU) 2015/849, arts. 18a and 18b; FATF public-list statements
Remote or electronic identification must meet the applicable national assurance, reliability and risk requirements; use of a vendor does not transfer the obliged entity's responsibility.
- Implementation action
- Assess eIDAS or notified schemes where relevant, document fraud and impersonation controls, accessibility, fallback, vendor assurance and ongoing performance.
- Evidence to retain
- Digital-identity assessment, assurance evidence, biometric and liveness tests, exceptions, monitoring and vendor governance.
- Primary citation
- Directive (EU) 2015/849, art. 13(1)(a); Regulation (EU) No 910/2014 as amended
06Monitoring, STRs and tipping offThere is no single EU STR portal or monetary suspicion threshold. Each Member State designates its FIU, national channel, form, language, timing formulation and additional reporting regimes.4 items+
Conduct ongoing monitoring, including scrutiny of transactions for consistency with customer knowledge, risk and source of funds where necessary, and keep CDD information current.
- Implementation action
- Set Member-State and sector scenarios, investigate unusual activity, refresh profiles and document disposition, escalation and model performance.
- Evidence to retain
- Monitoring inventory, alert files, customer refresh, source-of-funds evidence, tuning, testing and governance.
- Primary citation
- Directive (EU) 2015/849, art. 13(1)(d) and (4)
Where an obliged entity knows, suspects or has reasonable grounds to suspect ML/TF or criminal proceeds, it must inform the applicable national FIU promptly, including attempted transactions where national law so requires.
- Implementation action
- Route the report to the establishment's designated FIU through the live national portal, preserve urgency, language and form requirements and document why each state nexus was selected.
- Evidence to retain
- FIU routing matrix, report, timestamps, acknowledgement, attempted-transaction flag, rationale and follow-up correspondence.
- Primary citation
- Directive (EU) 2015/849, arts. 32-35 and 37
Do not execute a suspicious transaction before informing the FIU where national law permits the required restraint; if restraint is impossible or could frustrate pursuit, report immediately afterwards.
- Implementation action
- Implement jurisdiction-specific stop, consent, moratorium and emergency rules; obtain legal escalation before moving funds or disclosing the report.
- Evidence to retain
- Hold decision, FIU instruction, legal advice, transaction timestamp, exception rationale and release approval.
- Primary citation
- Directive (EU) 2015/849, art. 35
Protect FIU reports and related information from prohibited disclosure, subject to defined group, professional and authority exceptions in national law.
- Implementation action
- Restrict access, train staff, control customer communications and document the legal basis for any permitted information sharing.
- Evidence to retain
- Access log, confidentiality labels, scripts, training, sharing assessment and incident record.
- Primary citation
- Directive (EU) 2015/849, arts. 38-39
07Threshold reports, payments and crypto-assetsCDD thresholds, cash-payment limits, declarations and threshold reports are different concepts. National objective or systematic reports must not be inferred from the EU CDD amounts.4 items+
The current EU framework does not create one universal cash-transaction report for all obliged entities.
- Implementation action
- For each Member State, distinguish CDD triggers, legal cash-payment caps, customs cash declarations, sector-specific notifications and automatic or systematic FIU reports from suspicion-based STRs.
- Evidence to retain
- Country reporting matrix, statutory basis, form, portal, frequency, aggregation rule, tests and filing receipts.
- Primary citation
- Directive (EU) 2015/849, arts. 11 and 33; Regulation (EU) 2018/1672
Regulation (EU) 2023/1113 requires prescribed originator and beneficiary information and risk-based handling of missing information for covered funds and crypto-asset transfers.
- Implementation action
- Map payer/payee and originator/beneficiary data by role and transfer type, validate completeness, reject or suspend where required and monitor repeated failures.
- Evidence to retain
- Message schema, transfer samples, missing-data rules, rejections, counterparty monitoring and quality metrics.
- Primary citation
- Regulation (EU) 2023/1113, arts. 4-22
Covered payment service providers and crypto-asset service providers need controls for Union and national restrictive measures when performing transfers.
- Implementation action
- Screen transfer parties and ownership/control using current EU legal acts and national requirements; connect alerts to freeze, reject, licence and reporting workflows.
- Evidence to retain
- Screening configuration, list provenance, alert files, ownership analysis, freeze or rejection, licence and report.
- Primary citation
- Regulation (EU) 2023/1113, art. 23
MiCA's maximum grandfathering period ended on 1 July 2026; an in-scope provider serving EU clients after that date needs MiCA authorization or another valid status.
- Implementation action
- Confirm scope, home-state competent authority, authorization and passport status; stop in-scope service where no valid authorization or exclusion exists.
- Evidence to retain
- Service classification, authorization, ESMA register extract, passport notice, exclusion analysis and launch gate.
- Primary citation
- Regulation (EU) 2023/1114, arts. 59-65 and 143; ESMA, end of MiCA transitional period
08Targeted financial sanctionsEU restrictive-measures regulations are directly applicable, but the operative regulation, ownership/control analysis, licences, reporting and penalties remain programme- and Member-State-specific.3 items+
Operators must comply with asset-freeze, non-availability and other prohibitions in the exact EU restrictive-measures regulation that applies.
- Implementation action
- Screen the current EU consolidated data as an aid, verify matches and obligations against the Official Journal act, assess ownership/control and block prohibited dealings.
- Evidence to retain
- Legal-act version, list snapshot, match decision, ownership analysis, freeze or rejection, approval and audit trail.
- Primary citation
- Applicable Council Decision and Council Regulation; Commission sanctions resources
Licensing, derogations, frozen-asset reporting and suspected-breach routes are administered by the national competent authority or authorities identified for the relevant Member State and programme.
- Implementation action
- Use the Commission national-authority directory to select the correct authority; do not treat the Commission whistleblower tool as a substitute for mandatory national reporting.
- Evidence to retain
- Authority selection, licence application, frozen-asset report, acknowledgement, legal advice and renewal calendar.
- Primary citation
- Commission, Contacts on EU sanctions and national competent-authority directory
Directive (EU) 2024/1226 establishes minimum criminal-law rules for sanctions violations, but national transposition, enforcement bodies and Denmark's treaty position must be checked.
- Implementation action
- Map applicable national offences, attempts, circumvention, liability and penalties; escalate potential violations to the competent national investigative or enforcement authority.
- Evidence to retain
- National transposition, offence analysis, incident file, escalation, report and remediation.
- Primary citation
- Directive (EU) 2024/1226, arts. 3-15 and 20
09Records and authority accessThe five-year EU baseline is implemented through national law and can coexist with longer lawful periods, regulatory holds, sector records and GDPR deletion duties.3 items+
Keep CDD documents and information and transaction records for five years after the business relationship ends or the occasional transaction, subject to national extension within EU limits.
- Implementation action
- Define each record trigger, national extension, legal hold and deletion event; prevent indefinite retention justified only by generic AML need.
- Evidence to retain
- Retention schedule, trigger fields, national-law mapping, deletion jobs, holds, test results and exceptions.
- Primary citation
- Directive (EU) 2015/849, art. 40
Records must allow reconstruction and be available to the competent FIU and authorities in accordance with national law and secure-channel requirements.
- Implementation action
- Index identity, ownership, transaction, monitoring and report evidence; authenticate authority requests and deliver complete records through approved channels.
- Evidence to retain
- Evidence index, request log, authority verification, production record, access controls and chain of custody.
- Primary citation
- Directive (EU) 2015/849, arts. 32, 40 and 44
Regulation (EU) 2023/1113 sets a five-year retention period for required transfer information, with national law able to permit or require a further period not exceeding five years after assessment.
- Implementation action
- Separate transfer-rule records from other AML records, document any national extension and delete personal data when the lawful period expires.
- Evidence to retain
- Transfer record class, national extension assessment, retention controls, deletion log and sampled reconstruction.
- Primary citation
- Regulation (EU) 2023/1113, art. 26
10GDPR, biometrics and transfersAML duties do not displace data-protection principles. KYC processing needs a purpose-specific lawful basis, minimization, security, retention and rights analysis in every operating model.4 items+
Process KYC personal data lawfully, fairly and transparently for specified purposes, minimize it, keep it accurate, limit retention and secure it with demonstrable accountability.
- Implementation action
- Document controller roles and Article 6 bases, notices, purpose limits, data minimization, accuracy, retention and technical and organizational measures.
- Evidence to retain
- Record of processing, lawful-basis assessment, notices, data map, retention schedule, security controls and DPIA decisions.
- Primary citation
- GDPR, arts. 5, 6, 24, 25, 30 and 32
Biometric data used to uniquely identify a person is special-category data and requires both an Article 6 basis and an Article 9 condition, including any national-law condition relied on.
- Implementation action
- Prove necessity and proportionality, document the condition, limit templates and raw media, offer appropriate fallback and assess accuracy and bias.
- Evidence to retain
- Biometric assessment, legal basis and condition, DPIA, vendor tests, fallback records, deletion and incident controls.
- Primary citation
- GDPR, arts. 4(14), 6 and 9
Complete a DPIA before likely high-risk processing; notify the supervisory authority of a qualifying breach without undue delay and, where feasible, within 72 hours.
- Implementation action
- Screen each KYC use case for high risk, consult where residual high risk remains, operate 24-hour incident escalation and apply individual-notification rules.
- Evidence to retain
- DPIA screen and assessment, consultation, breach log, risk analysis, authority notice, individual notice and lessons learned.
- Primary citation
- GDPR, arts. 33-36
Transfers outside the EEA require a valid Chapter V route and, where necessary, supplementary measures; processor and onward-transfer controls remain separate.
- Implementation action
- Map destinations and remote access, select adequacy, SCCs, BCRs or a narrow derogation, assess destination law and control onward transfers.
- Evidence to retain
- Transfer map, mechanism, transfer impact assessment, SCC module, supplementary controls, approvals and reassessment.
- Primary citation
- GDPR, arts. 44-49; Commission Implementing Decision (EU) 2021/914
11National implementation - Austria to IrelandThese state rows identify the implementation route and a material operational distinction. They do not replace the operative national act, sector rule or live authority instruction. Suspicion reporting is threshold-free unless a separate national reporting regime expressly applies.14 items+
Austria - FIU Austria receives goAML reports; FMA is the principal financial AML supervisor, with OeNB involvement; Firmenbuch and WiEReG provide company and BO data; sanctions competence is split among OeNB, FMA and other authorities.
- Implementation action
- Report suspicion without undue delay through goAML. No universal CTR was verified. Reconcile five-year core retention with lawful extension; complete WiEReG annual verification and report or confirm non-exempt entities within four weeks.
- Evidence to retain
- FIU receipt, FMA perimeter, Firmenbuch/WiEReG extracts, annual BO review, national threshold decision and measure-specific sanctions routing.
- Primary citation
- Austrian FM-GwG; BMF WiEReG and sanctions guidance; Commission sanctions NCA directory
Belgium - CTIF-CFI is the FIU; NBB and FSMA supervise financial sectors; BCE/KBO and the FPS Finance UBO Register are distinct sources; FPS Finance Treasury leads financial-sanctions functions.
- Implementation action
- Report immediately, normally before execution. Do not confuse Belgium's generally EUR 3,000 cash-payment restriction with a CTR. Apply ten-year AML retention and the 30-day plus annual UBO filing/confirmation duties where applicable.
- Evidence to retain
- CTIF-CFI report, NBB/FSMA allocation, BCE and UBO extracts, cash-limit control, ten-year schedule and Treasury routing.
- Primary citation
- Belgian AML Law of 18 September 2017; CTIF-CFI, NBB and FPS Finance guidance
Bulgaria - SANS Financial Intelligence Directorate is the FIU; BNB and the Financial Supervision Commission supervise financial sectors; BO information sits in Commercial, non-profit and BULSTAT registers.
- Implementation action
- Report suspicion immediately and before execution where possible through the current SANS route. No universal CTR was verified; treat national cash-payment limits as payment controls, not FIU threshold reports. Route sanctions by measure.
- Evidence to retain
- SANS submission, BNB/FSC perimeter, Registry Agency extract, cash-control analysis, retention decision and sanctions authority selection.
- Primary citation
- Bulgarian Measures Against Money Laundering Act; BNB and Registry Agency official material
Croatia - the Ministry of Finance Anti-Money Laundering Office is the FIU; CNB, HANFA and the Financial Inspectorate divide supervision; FINA maintains the BO Register.
- Implementation action
- Report without delay and before execution, or by the next working day where the statutory post-execution exception applies. Report cash transactions of EUR 10,000 or more and enforce the separate EUR 10,000 cash-payment prohibition; apply ten-year retention.
- Evidence to retain
- AMLO report, timing rationale, cash report, payment block, CNB/HANFA mapping, FINA extract and ten-year schedule.
- Primary citation
- Croatian AML/CFT Law; Ministry of Finance and government BO Register guidance
Cyprus - MOKAS is the FIU; CBC, CySEC and the insurance supervisor divide financial supervision; the corporate BO register and CyTBOR for trusts are separate; NSIU handles sanctions implementation and licensing.
- Implementation action
- Use MOKAS goAML and the May 2026 reporting guidance promptly. No universal CTR was verified. Query the register matching the legal arrangement, apply five-year retention and use NSIU plus the relevant sector authority.
- Evidence to retain
- MOKAS filing, CBC/CySEC perimeter, corporate/CyTBOR extracts, five-year schedule, NSIU licence or report and acknowledgement.
- Primary citation
- Cyprus AML Law and MOKAS guidance; CySEC CyTBOR; NSIU guidance
Czechia - FAU is the FIU and central financial-sanctions authority; CNB supervises financial institutions; the Ministry of Justice system maintains the BO Register.
- Implementation action
- File through MoneyWeb without undue delay; where circumstances require, particularly where delay is dangerous, report immediately after detection. The current Act has no five-calendar-day outer limit. No universal CTR was verified. Apply ten-year retention.
- Evidence to retain
- MoneyWeb receipt, urgency/timing record, CNB allocation, BO extract, ten-year schedule and FAU sanctions decision.
- Primary citation
- Czech AML Act, s. 18(1), current text effective 11 January 2026; FAU and CNB guidance
Denmark - the NSK Money Laundering Secretariat is the FIU; Finanstilsynet and the Danish Business Authority divide supervision; CVR contains company and BO information; sanctions competence is measure-specific.
- Implementation action
- Submit goAML immediately when suspicion cannot be rebutted. No universal CTR was verified; do not treat the business cash-payment ceiling as a report. Apply five-year retention and select the Business Authority, Finanstilsynet or other competent body by measure.
- Evidence to retain
- goAML receipt, suspicion decision, supervisory map, CVR extract, cash-limit analysis, retention and sanctions routing.
- Primary citation
- Danish AML Act; hvidvask.dk, Finanstilsynet and CVR guidance
Estonia - the Financial Intelligence Unit is the FIU and financial-sanctions authority; Finantsinspektsioon supervises licensed finance; the e-Business Register holds BO data under restricted access from 10 July 2026.
- Implementation action
- Report suspicion without delay and no later than two working days. Except for credit institutions, report within that period a cash monetary obligation over EUR 32,000, including linked payments over up to one year. For credit institutions, the category is an occasional cash FX transaction over EUR 32,000 without a business relationship.
- Evidence to retain
- RABIS receipt, two-day clock, entity classification, linked-payment or FX threshold report, lawful BO access and sanctions filing.
- Primary citation
- Estonian AML/CFT Act, ss. 49(3), 49(5) and 49(8), consolidated 16 February 2026
Finland - the National Bureau of Investigation FIU receives reports; FIN-FSA supervises finance; PRH maintains BO data; the Foreign Ministry, Enforcement Authority and sector bodies divide sanctions roles.
- Implementation action
- Report electronically without delay. No universal CTR was verified. Apply five-year retention, obtain PRH data under the applicable purpose/entitlement rules and route licences, freezes and investigations to the correct body.
- Evidence to retain
- FIU submission, FIN-FSA mapping, PRH access and extract, retention record, sanctions licence/freezing route and acknowledgement.
- Primary citation
- Finnish AML Act; Police, FIN-FSA, PRH and Foreign Ministry guidance
France - TRACFIN is the FIU; ACPR and AMF divide financial supervision; INPI operates the national enterprise/BO system; Treasury administers financial sanctions.
- Implementation action
- File through ERMES before execution where required, using the statutory post-execution exceptions only. File COSI independently for covered cash/e-money transfers over EUR 1,000 per operation or EUR 2,000 monthly and cash deposits/withdrawals over EUR 10,000 monthly.
- Evidence to retain
- ERMES report, execution decision, COSI file and receipt, ACPR/AMF allocation, INPI extract, five-year schedule and Treasury sanctions record.
- Primary citation
- French Monetary and Financial Code; TRACFIN declarative-obligations guidance
Germany - the General Customs Directorate FIU receives goAML reports; BaFin supervises most regulated finance; Handelsregister and Transparenzregister are separate; Bundesbank and BAFA split financial and trade sanctions.
- Implementation action
- Register and report in goAML without undue delay. No universal CTR exists; implement fact-pattern real-estate reports and the real-estate cash-payment prohibition where applicable. Retain five years and destroy no later than ten years absent another basis.
- Evidence to retain
- goAML registration/receipt, BaFin mapping, register extracts, real-estate control, retention/deletion record and Bundesbank/BAFA routing.
- Primary citation
- German Money Laundering Act and GwGMeldV; BaFin and FIU guidance
Greece - Unit A of the Hellenic AML Authority is the FIU; Bank of Greece and HCMC divide financial supervision; the Central BO Register is distinct from GEMI; Unit B handles financial sanctions.
- Implementation action
- Report electronically without delay. No universal CTR was verified. File BO data within the national 60-day rule where applicable, apply five-year retention and keep Unit A reporting separate from Unit B sanctions action.
- Evidence to retain
- FIU receipt, BoG/HCMC perimeter, Central BO and GEMI extracts, 60-day filing proof, retention and Unit B record.
- Primary citation
- Greek Law 4557/2018; Hellenic AML Authority and government BO Register guidance
Hungary - the NAV Financial Intelligence Unit receives reports and handles financial sanctions; MNB supervises finance; NAV maintains central BO, bank-account and safe-deposit registers.
- Implementation action
- Report immediately through the protected national route. No universal CTR was verified. Apply the national eight-year retention period and reconcile BO reliability-index or discrepancy results rather than relying on the register alone.
- Evidence to retain
- FIU submission, MNB allocation, BO reliability result, discrepancy action, eight-year schedule and NAV sanctions record.
- Primary citation
- Hungarian Pmt and Afad Acts; NAV FIU/register and MNB guidance
Ireland - FIU Ireland receives goAML reports and the Central Bank supervises finance; company, trust and certain financial-vehicle BO registers are separate; sanctions roles include the Central Bank and government departments.
- Implementation action
- Make both required filings as soon as practicable: goAML to FIU Ireland and ROS to Revenue. No universal CTR was verified. Apply at least five-year retention and select the correct BO register and sanctions authority.
- Evidence to retain
- goAML and ROS receipts, dual-filing reconciliation, Central Bank perimeter, correct BO extract, retention and sanctions report.
- Primary citation
- Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, s. 42; Revenue and Central Bank guidance
12National implementation - Italy to SwedenUse the state-specific FIU, supervisor, register and sanctions authority. Cross-border groups may need more than one filing or supervisory engagement where establishments or services create multiple national nexuses.13 items+
Italy - UIF is the autonomous FIU at Banca d'Italia; Banca d'Italia, IVASS and CONSOB divide supervision; the Business Register hosts the BO filing system; MEF's Financial Security Committee coordinates financial sanctions.
- Implementation action
- File SOS through Infostat-UIF without delay and where possible before execution. Covered firms also send monthly objective communications for aggregate cash activity of at least EUR 10,000, counting individual cash operations of at least EUR 1,000. Apply ten-year retention.
- Evidence to retain
- SOS and objective-report receipts, supervisory map, register result with access caveat, ten-year schedule and CSF routing.
- Primary citation
- Italian Legislative Decree 231/2007; UIF SOS and objective-communications rules
Latvia - FIU Latvia receives goAML reports, supervises major sanctions functions and works with Latvijas Banka and other sector supervisors; the Enterprise Register holds BO data under access rules changed 1 July 2026.
- Implementation action
- Report suspicion and sanctions triggers immediately through goAML. Apply Cabinet Regulation 550 category thresholds rather than one generalized amount, five-year retention and the restricted-access BO model including new nationality/control fields.
- Evidence to retain
- goAML receipt, threshold category and filing, Latvijas Banka allocation, lawful BO extract, retention and sanctions action.
- Primary citation
- Latvian AML/CFT/PF Prevention Law; FIU and Enterprise Register guidance
Lithuania - FCIS is the FIU and a core financial-sanctions authority; Bank of Lithuania supervises finance; JAR and JADIS are distinct company and BO systems.
- Implementation action
- Report suspicion immediately through the FCIS route and report covered cash transactions of EUR 15,000 or more, including linked transactions, under current implementing instructions. Apply the national eight-year period to the correct CDD/transaction record classes.
- Evidence to retain
- FCIS receipts, threshold aggregation, Bank of Lithuania allocation, JAR/JADIS extracts, record-class schedule and sanctions routing.
- Primary citation
- Lithuanian AML/CFT Law; FCIS, Bank of Lithuania and Centre of Registers guidance
Luxembourg - the CRF is the FIU; CSSF and CAA divide financial supervision; LBR operates RCS and RBE; Finance and Foreign Ministries divide sanctions functions.
- Implementation action
- File STR or SAR exclusively through goAML promptly, including attempts. No universal CTR was verified. Apply five-year retention, lawful RBE access after CJEU restrictions and the ministry/sector route matching the sanction.
- Evidence to retain
- goAML receipt, STR/SAR classification, CSSF/CAA allocation, RCS/RBE extracts, retention and sanctions licence/report.
- Primary citation
- Luxembourg Law of 12 November 2004; CRF, CSSF, LBR and Finance Ministry guidance
Malta - FIAU is the FIU and AML supervisor working with MFSA; MBR maintains corporate BO data; the Sanctions Monitoring Board is the central sanctions body.
- Implementation action
- Report through goAML as soon as reasonably practicable and no later than five working days after suspicion first arose unless exceptional circumstances justify otherwise. Do not delay to the outer limit. No universal CTR was verified; apply five-year retention.
- Evidence to retain
- goAML receipt, first-suspicion timestamp, delay exception if any, FIAU/MFSA mapping, MBR extract, retention and SMB record.
- Primary citation
- Malta PMLFTR; FIAU reporting guidance; MBR and SMB guidance
Netherlands - FIU-Nederland receives reports of unusual transactions; DNB, AFM and other designated bodies divide supervision; KVK maintains company and separate UBO registers; sanctions supervision is sector-split.
- Implementation action
- Report an unusual transaction without delay under the applicable objective or subjective indicator; do not wait until FIU declares it suspicious and do not invent one national threshold. Apply five-year retention and current restricted UBO access.
- Evidence to retain
- FIU report, indicator selection, DNB/AFM allocation, KVK/UBO extract, five-year schedule and measure-specific sanctions route.
- Primary citation
- Dutch Wwft and Implementing Decree; FIU-Nederland, DNB and KVK guidance
Poland - GIIF is the FIU; KNF and GIIF/other bodies divide supervision; KRS and CRBR are distinct; sanctions enforcement is divided around the Interior Ministry list and KAS/sector bodies.
- Implementation action
- Apply the two-working-day descriptive suspicion route and immediate transaction-specific route as applicable. Report Article 72 cash and specified transfers above EUR 15,000 generally within seven days. Apply five-year retention and independently verify CRBR data.
- Evidence to retain
- GIIF receipt and clock, threshold report, KNF allocation, KRS/CRBR extracts, retention and national-sanctions-list check.
- Primary citation
- Polish AML Act, arts. 72, 74 and 86; GIIF and CRBR guidance
Portugal - the Polícia Judiciária UIF is the FIU; Banco de Portugal, CMVM and ASF divide financial supervision; RCBE is distinct from the Commercial Register; sanctions roles are distributed.
- Implementation action
- Immediately report through Portal COS to both UIF and DCIAP, regardless of amount. Apply the periodic/systematic Article 45 typologies under Portaria 310/2018 rather than one cash threshold, and retain records for seven years.
- Evidence to retain
- UIF and DCIAP delivery proof, systematic report, supervisory allocation, RCBE extract, seven-year schedule and sanctions routing.
- Primary citation
- Portuguese Law 83/2017 and Portaria 310/2018; Portal BCFT and Banco de Portugal guidance
Romania - ONPCSB is the FIU and supervises specified sectors; NBR and ASF supervise finance; ONRC maintains company BO information; sanctions competence is split by measure.
- Implementation action
- Report suspicion immediately; use the statutory post-execution exception and 24-hour outer wording only where its conditions are met. Report linked cash operations and covered external account transfers at or above EUR 10,000 under the current filing deadline.
- Evidence to retain
- SETD receipt, execution/timing analysis, threshold aggregation/report, NBR/ASF mapping, ONRC extract, five-year schedule and sanctions route.
- Primary citation
- Romanian Law 129/2019; ONPCSB and ONRC guidance
Slovakia - the Police Force FIU receives reports; NBS and the FIU/other bodies divide supervision; the Commercial Register BO record and RPVS public-sector-partner register have different scopes; sanctions competence is measure-specific.
- Implementation action
- Report unusual business transactions without undue delay, including attempts. No universal CTR was verified; do not treat cash ceilings as FIU reports. Apply five-year retention and never substitute RPVS for AML BO work.
- Evidence to retain
- FIU submission, NBS allocation, Commercial Register and RPVS results, five-year schedule, cash-limit analysis and sanctions authority selection.
- Primary citation
- Slovak Act 297/2008, consolidated 15 January 2025; FIU, NBS and Justice Ministry guidance
Slovenia - the Office for Money Laundering Prevention is the FIU; Bank of Slovenia, Securities Market Agency and Insurance Supervision Agency divide finance; AJPES maintains the BO Register.
- Implementation action
- Report before execution and immediately, documenting any statutory impossibility. File reports for cash transactions of EUR 15,000 or more and covered transfers involving designated high-risk countries of EUR 15,000 or more, generally within three working days. Retain ten years.
- Evidence to retain
- FIU receipt, pre-execution decision, threshold reports, supervisory map, lawful AJPES access, ten-year schedule and sanctions route.
- Primary citation
- Slovenian APMLTF-2; OMLP and AJPES guidance
Spain - SEPBLAC is the FIU and specialist AML supervisor, coordinating with Banco de Espana, CNMV and DGSFP; RCTIR is distinct from the Mercantile Registry; Treasury handles financial sanctions.
- Implementation action
- Report suspicion without delay. File monthly DMO systematic reports for applicable categories, including specified physical cash/bearer movements over EUR 30,000, remitter physical movements over EUR 1,500 and designated-country transactions over EUR 30,000; apply ten-year retention.
- Evidence to retain
- SEPBLAC receipt, DMO and nil reports, supervisory map, RCTIR extract, ten-year schedule and Treasury record.
- Primary citation
- Spanish Law 10/2010 and implementing rules; SEPBLAC systematic-reporting guidance
Sweden - the Police Finanspolisen is the FIU; Finansinspektionen supervises most regulated finance; Bolagsverket maintains BO data; sanctions implementation is divided among government, FI, ISP, Customs and enforcement bodies.
- Implementation action
- Report in goAML without delay when reasonable grounds exist. No universal CTR was verified. Apply five-year retention, obtain current Bolagsverket information and separate FI supervisory data collection from transaction reporting.
- Evidence to retain
- goAML receipt, FI perimeter, BO extract, five-year schedule, reporting-classification note and competent sanctions route.
- Primary citation
- Swedish Money Laundering Act; Police, Finansinspektionen and Bolagsverket guidance
13Practical evidence pack and launch gateNo EU-wide checklist row is complete until the directly applicable rule and the relevant national implementation are reconciled for the actual entity, service, customer and transaction.4 items+
Maintain a 27-state authority and rule matrix with effective dates, FIU portals, supervisors, registers, sanctions authorities, reporting regimes, thresholds and retention.
- Implementation action
- Assign local legal owners, recheck live links and forms before launch, record conflicts and version every change.
- Evidence to retain
- Approved matrix, source snapshots, link checks, form samples, owners, effective dates and change tickets.
- Primary citation
- Directive (EU) 2015/849, arts. 5, 32-33, 45 and 48
For every product and country, determine applicable authorization, AML supervision, payment or e-money status, MiCA treatment, passporting and agent or distributor duties.
- Implementation action
- Gate launch on written perimeter analysis and register confirmation in the home and relevant host states.
- Evidence to retain
- Permission matrix, register extracts, passport notifications, agent filings, terms, approvals and launch record.
- Primary citation
- Applicable national law; PSD2; EMD2; MiCA
Test reporting and restraint workflows with the actual national FIU and sanctions-authority routes without sending test personal data to production portals.
- Implementation action
- Use documented dry runs, verify credentials and availability, maintain emergency contacts and capture evidence after each real filing.
- Evidence to retain
- Dry-run results, access validation, contact tree, incident exercise, receipts and post-filing review.
- Primary citation
- Directive (EU) 2015/849, arts. 33-39; applicable sanctions regulation and national law
Each row requires an explicit applicability decision, current source, owner, operating evidence and independent review before launch.
- Implementation action
- Mark applicable, not applicable or pending counsel confirmation; close blockers and obtain compliance, legal, privacy, security and product approval.
- Evidence to retain
- Completed checklist, rationale, source version, control test, gap ticket, reviewer sign-off and launch approval.
- Primary citation
- Directive (EU) 2015/849, arts. 8, 40, 45-46
Primary-source register
56 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Fourth Anti-Money Laundering Directive - current consolidated frameworkEUR-Lex · Primary EU law
- Regulation (EU) 2024/1624 - AML single rulebookEUR-Lex · Primary EU law - future application
- Directive (EU) 2024/1640 - national AML mechanismsEUR-Lex · Primary EU law - staged transposition
- Regulation (EU) 2024/1620 establishing AMLAEUR-Lex · Primary EU law
- AMLA General Board - FIU compositionAMLA · Official current authority directory
- AMLA General Board - supervisory compositionAMLA · Official current authority directory
- AMLA direct supervision timetableAMLA · Official authority explainer
- Commission register of national AML/CFT competent authoritiesEuropean Commission · Official authority directory
- Beneficial Ownership Registers Interconnection System directoryEuropean e-Justice Portal · Official registry directory
- Business registers in EU countriesEuropean e-Justice Portal · Official registry directory
- Regulation (EU) 2023/1113 on information accompanying transfersEUR-Lex · Primary EU law
- Regulation (EU) 2023/1114 on markets in crypto-assetsEUR-Lex · Primary EU law
- End of the MiCA transitional periodEuropean Securities and Markets Authority · Official supervisor statement
- Directive (EU) 2018/1673 on combating money laundering by criminal lawEUR-Lex · Primary EU law
- Directive (EU) 2024/1226 on sanctions violationsEUR-Lex · Primary EU law
- EU sanctions overview and consolidated financial sanctions listEuropean Commission · Official sanctions resource
- Contacts and national competent authorities for EU sanctionsEuropean Commission · Official sanctions authority directory
- National competent authorities for EU sanctionsEuropean Commission · Official sanctions authority directory
- General Data Protection RegulationEUR-Lex · Primary EU law
- Standard contractual clauses for international transfersEUR-Lex · Primary EU implementing decision
- European data-protection supervisory authoritiesEuropean Data Protection Board · Official authority directory
- Regulation (EU) 2018/1672 on cash entering or leaving the UnionEUR-Lex · Primary EU law
- Payment Services DirectiveEUR-Lex · Primary EU law
- Electronic Money DirectiveEUR-Lex · Primary EU law
- eIDAS Regulation - consolidated textEUR-Lex · Primary EU law
- Austria Financial Markets Anti-Money Laundering ActAustrian Legal Information System · Primary national law
- Belgium AML/CFT supervisory informationNational Bank of Belgium · Official national supervisor guidance
- Bulgaria AML/CFT supervisionBulgarian National Bank · Official national supervisor guidance
- Croatia AML/CFT legislation and implementing materialMinistry of Finance of Croatia · Official national authority material
- Cyprus MOKAS reporting portalUnit for Combating Money Laundering · Official national FIU portal
- Czech AML/CFT Act - current English textFinancial Analytical Office · Official national law reproduction
- Denmark suspicious-reporting guidanceDanish Money Laundering Secretariat · Official national FIU guidance
- Estonia AML/CFT Act - consolidated English textRiigi Teataja · Primary national law
- Finland AML/CFT risk and customer-due-diligence regulations and guidelinesFinnish Financial Supervisory Authority · Official national supervisor instrument
- France declarative AML obligationsTRACFIN · Official national FIU guidance
- Germany Money Laundering ActFederal Ministry of Justice · Primary national law
- Greece AML/CFT Law 4557/2018 - English textHellenic Anti-Money Laundering Authority · Official national law reproduction
- Hungary Financial Intelligence UnitNational Tax and Customs Administration · Official national FIU information
- Ireland suspicious-transaction dual reportingRevenue Commissioners · Official national reporting guidance
- Italy suspicious-transaction reportingFinancial Intelligence Unit for Italy · Official national FIU guidance
- Latvia AML/CFT/PF Prevention Law - English textLatvian Legal Acts · Primary national law
- Lithuania money-laundering preventionFinancial Crime Investigation Service · Official national FIU guidance
- Luxembourg goAML reportingFinancial Intelligence Unit of Luxembourg · Official national FIU guidance
- Malta suspicious-transaction reportingFinancial Intelligence Analysis Unit · Official national FIU guidance
- Netherlands unusual-transaction reporting dutyFIU-Nederland · Official national FIU guidance
- Poland above-threshold transaction reportingGeneral Inspector of Financial Information · Official national FIU guidance
- Portugal suspicious-operation reportingPortuguese AML/CFT Portal · Official national reporting guidance
- Romania Law 129/2019 - current consolidated recordRomanian Legislative Portal · Primary national law
- Slovakia AML/CFT Act - English textMinistry of Interior of Slovakia · Official national law reproduction
- Slovenia AML/CFT Act - English textOffice for Money Laundering Prevention · Official national law reproduction
- Spain systematic AML reportingSEPBLAC · Official national FIU guidance
- Sweden Financial Police and suspicious reportingSwedish Police Authority · Official national FIU guidance
- FATF members and assessment arrangementsFinancial Action Task Force · Official international status
- FATF black and grey listsFinancial Action Task Force · Official current-status source
- Outcomes of the FATF Plenary, June 2026Financial Action Task Force · Official current-status source
- MONEYVAL country and territory evaluationsCouncil of Europe MONEYVAL · Official international assessment
Direct answers
European Union KYC, KYB and AML questions
Is there one AML law and one FIU for all 27 EU Member States?+
No. Until 10 July 2027 the principal preventive directive operates through national transposition. AMLA has EU-level roles, but suspicious reports go to the applicable national FIU and national authorities retain major supervisory and enforcement functions.
Does the AMLR already replace national AML laws?+
No. Regulation (EU) 2024/1624 entered into force in 2024 but generally applies from 10 July 2027, with a later 10 July 2029 start for football agents and professional football clubs. Current national law remains essential.
What is the current EU occasional-transaction CDD threshold?+
The current directive sets EUR 15,000 as the general occasional-transaction floor, with more than EUR 1,000 for covered funds transfers, EUR 10,000 cash for goods traders and EUR 2,000 for gambling. Member States and sectors may impose lower or additional triggers.
Is there an EU-wide cash transaction report?+
No universal report follows from the directive's CDD amounts. Some Member States require objective, systematic or threshold reports, and cash-payment caps and external-border cash declarations are separate controls.
Where should a suspicious transaction be reported?+
To the FIU designated by the applicable Member State, using that FIU's live national channel and timing rules. AMLA coordinates FIUs but is not a substitute universal STR portal.
Can a business use 25% as its only beneficial-owner test?+
No. The current directive's indicative ownership threshold is more than 25%, but control through other means must be assessed and national law may be stricter. Senior-management fallback requires documented exhaustion of reasonable means.
Can BORIS or a national register replace KYB verification?+
No. Register information is an important source, but access and content vary and it must be reconciled with independent evidence and the actual ownership and control structure.
Who enforces EU financial sanctions?+
The relevant EU regulations bind operators, while Member States are primarily responsible for implementation and enforcement. Licensing, frozen-asset and breach reporting must go to the correct national competent authority for the programme.
Does AML law permit unlimited KYC retention?+
No. The current EU baseline is five years from the relationship or transaction trigger, subject to lawful national extensions and holds. GDPR purpose limitation, minimization, security and deletion duties continue to apply.
Is every EU Member State off the FATF public lists?+
No. On the public-list page reviewed 31 July 2026, Bulgaria remained under increased monitoring, although FATF had made an initial determination that its action plan was substantially completed subject to an on-site assessment. No EU Member State was subject to a call for action.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, an authorization decision or a substitute for operative national law. Reviewed 31 July 2026. EU directives require national implementation, while directly applicable regulations still use national authorities. Confirm entity, activity, customer, transaction, thresholds, reporting channel, sanctions route, register access, privacy role and later developments with qualified counsel and the relevant authorities.