EBA guidelines still in force

Legacy EBA and joint ESA instruments remain applicable until AMLA publishes replacements. EBA AML/CFT policy page

EBA → AMLA migration guide

Still in force.Under Article 54 of the AMLA Regulation, all existing EBA AML/CFT guidelines and standards remain valid until AMLA formally replaces them. Continue to follow these while monitoring AMLA's Level 2 and Level 3 work.

EBA → AMLA migration guide — what changes and how to prepare
In forceEBA/GL/2021/02CDDRisk factorsRisk assessmentPEPs

Guidelines on ML/TF risk factors (incl. CDD, SDD/EDD, business-wide RA)

Official source

The core EBA risk-based approach guideline — risk factors for customers, geography, products and channels; how to adjust CDD (including simplified and enhanced) and apply mutatis mutandis to business-wide risk assessment. Amended for NPOs (2023) and CASPs (2024). Replaces JC/2017/37.

Published 7 October 2021

AMLA successor: Art. 20Risk variables and risk factors for CDD

In forceEBA/GL/2022/15Remote onboardingCDD

Guidelines on the use of remote customer onboarding solutions

Official source

Common EU standards for non-face-to-face identification and verification — pre-implementation assessment of onboarding tools, data reliability, and risk-sensitive policies under the AMLD.

Published 22 November 2022

AMLA successor: Art. 50Reliance on other obliged entities

In forceEBA/GL/2022/05Internal controlsSupervision

Guidelines on the role and responsibilities of the AML/CFT compliance officer

Official source

Role, tasks and responsibilities of the AML/CFT compliance function and the management body — independence, resources, group-level compliance officers, and interaction with supervisors.

Published 14 June 2022

In forceEBA/GL/2022/03De-risking

Guidelines on ML/TF risk management when providing access to financial services

Official source

Policies and controls to challenge unwarranted de-risking and safeguard access to basic financial products — balancing AML/CFT compliance with financial inclusion.

Published 31 March 2023

AMLA successor: Art. 21AML/CFT compliance and access to basic payment accounts

In forceEBA/GL/2024/11CryptoSTR

Travel rule guidelines — transfers of funds and crypto-assets (Reg. 2023/1113)

Official source

Steps PSPs, IPSPs, CASPs and ICASPs must take to detect missing payer/payee information, manage deficient transfers, and handle self-hosted address scenarios. Replaces JC/GL/2017/16.

Published 4 July 2024

AMLA successor: Art. 40Risk profile assessment of obliged entities

In forceJC/GL/2016/72SupervisionRisk assessment

Joint guidelines on risk-based AML/CFT supervision

Official source

Characteristics of a risk-based approach to AML/CFT supervision — how competent authorities allocate supervisory resources in line with ML/TF risk (for supervisors; institutions should understand the framework).

Published 23 November 2016

In forceJC/2019/81Supervision

Joint guidelines on cooperation and information exchange for AML/CFT supervision

Official source

Cooperation between prudential and AML/CFT supervisors domestically and cross-border — including establishment and operation of AML/CFT colleges for multi-jurisdiction firms.

Published 16 December 2019

In forceJC RTS 2017/25Internal controls

RTS on group-wide AML/CFT policies in third countries

Official source

Legally binding standards (Commission Delegated Regulation (EU) 2019/758) on additional measures where third-country law prevents branches or subsidiaries from applying group-wide AML/CFT requirements.

Published 3 September 2019

AMLA successor: Art. 17Branches and subsidiaries in third countries

In forceJC RTS 2017/08Supervision

RTS on central contact points for AML/CFT (CCP)

Official source

Criteria for when payment service providers and e-money issuers operating via non-branch establishments must appoint a central contact point, and the functions that CCP must perform.

Published 6 December 2017