EBA → AMLA migration guide

What you comply with under EBA guidelines today, and which AMLA mandates will replace them. EBA instruments remain valid until formally superseded — see the EBA AML/CFT policy page.

Migration planning view. EBA guidelines remain legally in force under AMLA Reg. Art. 54 until AMLA formally replaces them. Use this page to see what you follow today and which AMLA mandates will supersede each instrument.

EBA in force todayEBA/GL/2021/02CDDRisk factorsRisk assessment

Guidelines on ML/TF risk factors (incl. CDD, SDD/EDD, business-wide RA)

EBA official source

Today — EBA guideline

The core EBA risk-based approach guideline — risk factors for customers, geography, products and channels; how to adjust CDD (including simplified and enhanced) and apply mutatis mutandis to business-wide risk assessment. Amended for NPOs (2023) and CASPs (2024). Replaces JC/2017/37.

In practice: Your CDD and business-wide risk assessment follow EBA risk-factor tables — customer, geography, product, and channel indicators with SDD/EDD triggers.

Published 7 October 2021

Next — AMLA successor

In developmentAMLR Art. 20 · GuidelinesPassed
Risk variables and risk factors for CDD

Risk variables and risk factors obliged entities must weigh when entering business relationships or carrying out occasional transactions.

Why it matters: Successor to the EBA risk factors guidelines — your customer risk model will need to map to this taxonomy.

Expected shift: AMLA will replace the guideline with a binding taxonomy under Art. 20. Expect harmonised risk variables across all obliged entities, not just financial firms — NFS sectors must map their models too.

Statutory deadline 10 July 2026

Prepare now

  1. 1Inventory which EBA risk-factor tables you use today in onboarding and periodic review.
  2. 2Identify gaps where NFS-specific customers (e.g. art buyers, property vendors) are not covered.
  3. 3Track the Art. 20 mandate — consultation and adoption dates drive your policy refresh window.
EBA in force todayEBA/GL/2022/15Remote onboardingCDD

Guidelines on the use of remote customer onboarding solutions

EBA official source

Today — EBA guideline

Common EU standards for non-face-to-face identification and verification — pre-implementation assessment of onboarding tools, data reliability, and risk-sensitive policies under the AMLD.

In practice: Non-face-to-face onboarding tools are assessed before deployment; you verify data reliability and apply risk-sensitive CDD under the EBA remote onboarding standard.

Published 22 November 2022

Next — AMLA successor

In developmentAMLR Art. 50 · Guidelines345d left
Reliance on other obliged entities

Acceptable conditions for relying on CDD information collected by another obliged entity — including remote CDD — and the roles and responsibilities involved.

Expected shift: Art. 50 guidelines will govern reliance on another obliged entity's CDD — including remote identification — with clearer allocation of responsibility between relying firm and relied-upon firm.

Statutory deadline 10 July 2027

Prepare now

  1. 1List third-party onboarding vendors and which obliged entity holds the underlying CDD file.
  2. 2Review contracts for data access, audit rights, and liability if relied-upon CDD is deficient.
  3. 3Watch Art. 50 guidelines — they affect banks and any sector using outsourced KYC.
EBA in force todayEBA/GL/2022/03De-risking

Guidelines on ML/TF risk management when providing access to financial services

EBA official source

Today — EBA guideline

Policies and controls to challenge unwarranted de-risking and safeguard access to basic financial products — balancing AML/CFT compliance with financial inclusion.

In practice: Policies challenge unwarranted de-risking and preserve access to basic payment services while meeting AML obligations.

Published 31 March 2023

Next — AMLA successor

In developmentAMLR Art. 21 · Joint Guidelines345d left
AML/CFT compliance and access to basic payment accounts

Joint guidelines with the EBA on measures credit and financial institutions may take to comply with AML/CFT rules when implementing the Payment Accounts Directive (2014/92/EU).

Why it matters: Addresses de-risking — balancing financial inclusion against AML obligations.

Expected shift: Art. 21 joint EBA/AMLA guidelines will update the financial-inclusion vs AML balance under the Payment Accounts Directive — primarily for credit and financial institutions.

Statutory deadline 10 July 2027

Prepare now

  1. 1Review customer off-boarding and account-refusal policies against EBA de-risking guidance.
  2. 2Prepare for Art. 21 guidelines if you refuse or restrict basic payment accounts.
  3. 3Train front-office staff on documenting legitimate reasons for relationship exits.
EBA in force todayEBA/GL/2024/11CryptoSTR

Travel rule guidelines — transfers of funds and crypto-assets (Reg. 2023/1113)

EBA official source

Today — EBA guideline

Steps PSPs, IPSPs, CASPs and ICASPs must take to detect missing payer/payee information, manage deficient transfers, and handle self-hosted address scenarios. Replaces JC/GL/2017/16.

In practice: CASP and PSP travel-rule processes detect missing payer/payee data, manage deficient transfers, and handle self-hosted wallet scenarios per EBA/GL/2024/11.

Published 4 July 2024

Next — AMLA successor

Submitted to CommissionAMLD6 Art. 40(2) · RTSPassed
Risk profile assessment of obliged entities

Harmonised methodology for supervisors to assess and classify the inherent and residual ML/TF risk profile of obliged entities.

Why it matters: Determines how intensively your firm will be supervised — the same scoring logic will apply in every Member State.

Expected shift: Art. 40 AMLA guidelines will set mitigating measures for self-hosted address transfers — identification and verification of originator/beneficiary beyond current travel-rule formats.

Statutory deadline 10 July 2026

Prepare now

  1. 1Map self-hosted wallet flows against current travel-rule and EBA crypto guidance.
  2. 2Engage technology vendors on wallet screening and beneficiary verification upgrades.
  3. 3Track Art. 40 mandate status — CASP-specific and time-sensitive for MiCA firms.
EBA in force todayJC RTS 2017/25Internal controls

RTS on group-wide AML/CFT policies in third countries

EBA official source

Today — EBA guideline

Legally binding standards (Commission Delegated Regulation (EU) 2019/758) on additional measures where third-country law prevents branches or subsidiaries from applying group-wide AML/CFT requirements.

In practice: Group-wide AML/CFT policies apply across branches and subsidiaries; additional measures apply where third-country law blocks implementation.

Published 3 September 2019

Next — AMLA successor

Consultation closed · draftingAMLR Art. 17(3) · RTSPassed
Branches and subsidiaries in third countries

Additional measures groups must take where third-country law prevents branches or subsidiaries from applying group-wide AML/CFT requirements.

Expected shift: Art. 17(3) RTS will codify minimum group requirements and additional measures for blocked jurisdictions — legally binding where the EBA standard was already an RTS but updated for AMLR.

Statutory deadline 10 July 2026

Prepare now

  1. 1Document every jurisdiction where local law limits group-policy application.
  2. 2Review Art. 17(3) consultation materials against your current third-country playbook.
  3. 3Coordinate group compliance and local MLROs before the July 2026 delivery wave.

Supervisory instruments — no AMLA successor mapped yet

These EBA guidelines remain in force but are primarily for supervisors or have no mapped AMLA replacement in our dataset.

EBA/GL/2022/05

Guidelines on the role and responsibilities of the AML/CFT compliance officer

JC/GL/2016/72

Joint guidelines on risk-based AML/CFT supervision

JC/2019/81

Joint guidelines on cooperation and information exchange for AML/CFT supervision

JC RTS 2017/08

RTS on central contact points for AML/CFT (CCP)

Full EBA guideline list