EU AML glossary
Plain-language orientation for AML Package terminology. Article references point to the primary legal hook — always verify against the official text on EUR-Lex before relying on a definition.
AMLA
AMLARThe EU Anti-Money Laundering Authority, established by Regulation (EU) 2024/1620 and seated in Frankfurt. Operational since July 2025, it drafts the Level 2 and Level 3 rules under the AML Package, coordinates supervisors and FIUs, and from 2028 directly supervises selected high-risk cross-border obliged entities.
Beneficial owner
AMLR Ch. IVThe natural person who ultimately owns or controls a customer — through a sufficient ownership interest (the AMLR baseline is 25%, with stricter treatment for higher-risk structures) or through control via other means. Obliged entities must identify and verify beneficial owners as part of CDD, and legal entities must hold and file this information in beneficial ownership registers.
Business relationship
AMLR Art. 2(1)A relationship between an obliged entity and a customer connected to the entity's professional activities and expected to have an element of duration — the trigger for full onboarding CDD and ongoing monitoring, as opposed to one-off occasional transactions.
Business-wide risk assessment (BWRA)
AMLR Art. 10The documented assessment each obliged entity must make of its own exposure to money laundering and terrorist financing risk — taking into account the EU supranational risk assessment, national risk assessments, and the risk variables in the AMLR annexes. It drives the entity's policies, controls, and the intensity of CDD it applies.
Correspondent relationship
AMLR Ch. IIIThe provision of banking or payment services by one institution (the correspondent) to another (the respondent), including relationships established for securities transactions or crypto-asset services. Cross-border correspondent relationships with non-EU respondents require specific enhanced due diligence.
Crypto-asset service provider (CASP)
A provider authorised under MiCA (Regulation (EU) 2023/1114) to offer crypto-asset services — exchange, custody, transfer, and related activities. CASPs are obliged entities under the AMLR, with lower occasional-transaction thresholds and specific rules on transfers and self-hosted addresses.
Customer due diligence (CDD)
AMLR Ch. IIIThe core obligation: identify the customer and beneficial owner, verify identity, understand the purpose of the relationship, and monitor it on an ongoing basis. Applied on onboarding, for occasional transactions above thresholds, and when suspicion or doubt arises. The detail of what a compliant file contains is set by AMLA's CDD RTS.
Enhanced due diligence (EDD)
AMLR Ch. IIIAdditional CDD measures required in higher-risk situations — including business with high-risk third countries, correspondent relationships, politically exposed persons, and cases the entity's own risk assessment flags. Typically means more information, senior-management approval, and closer monitoring.
Financial Intelligence Unit (FIU)
AMLD6The national authority that receives and analyses suspicious transaction reports and disseminates intelligence to law enforcement. AMLD6 strengthens FIU powers, cooperation, and joint analysis across Member States, and AMLA hosts the FIU support and coordination mechanism.
Guidelines (Level 3)
Level 3Non-binding instruments published by AMLA (sometimes jointly with the EBA, ESMA, or EIOPA) that operate on a comply-or-explain basis for supervised entities. Until AMLA's own guidelines land, many legacy EBA guidelines remain the operative reference.
High-risk third country
AMLR Ch. IIIA non-EU jurisdiction identified by the European Commission as having strategic deficiencies in its AML/CFT regime (informed by FATF listings). Business relationships and transactions involving these countries trigger mandatory enhanced due diligence and, in some cases, countermeasures.
Implementing technical standards (ITS)
Level 2Binding technical rules adopted by the European Commission as implementing regulations — typically formats, templates, and procedures, such as the standardised STR reporting format. Drafted by AMLA like RTS, but without the delegated-act scrutiny procedure.
Obliged entity
AMLR Art. 3A business or professional that the AMLR places under AML/CFT obligations — from credit institutions and CASPs to estate agents, art dealers, gambling operators, and (from 2029) professional football clubs and agents. If you are an obliged entity, the full CDD, reporting, and internal-controls framework applies to you.
Occasional transaction
AMLR Art. 2(1)A transaction carried out outside a business relationship. CDD is triggered when an occasional transaction meets the AMLR thresholds (EUR 10,000 as the general baseline, with lower sector-specific thresholds — e.g. for CASPs and cash-intensive activities).
Politically exposed person (PEP)
AMLR Art. 2(1)A person entrusted with a prominent public function — heads of state, ministers, parliamentarians, senior judges, senior executives of state-owned enterprises, and similar roles — plus their family members and known close associates. Business with PEPs always requires enhanced due diligence.
Regulatory technical standards (RTS)
Level 2Binding technical rules drafted by AMLA (building on EBA work for early mandates) and adopted by the European Commission as delegated regulations, subject to scrutiny by Parliament and Council. RTS carry the operational detail of the Single Rulebook — e.g. what a CDD file must contain.
Self-regulatory body
AMLD6A professional body — such as a bar association or chamber of notaries or accountants — that Member States may entrust with supervising its members' AML compliance, under the oversight of a public authority as required by AMLD6.
Simplified due diligence (SDD)
AMLR Ch. IIIReduced-intensity CDD measures allowed where the risk of a business relationship or transaction is low — e.g. adjusting the timing or extent of verification and monitoring. SDD is never an exemption: the obliged entity must still identify the customer and be able to demonstrate the low-risk assessment.
Single Rulebook (AMLR)
AMLRRegulation (EU) 2024/1624 — the directly applicable core of the AML Package. Unlike the previous directives, it applies uniformly across the EU without national transposition, from 10 July 2027 for most obliged entities. It sets the harmonised rules on CDD, beneficial ownership, reporting, and internal controls.
SNRA / NRA
The supranational risk assessment (SNRA) is the European Commission's EU-level assessment of ML/TF risks; national risk assessments (NRAs) are each Member State's own. Both are mandatory inputs into an obliged entity's business-wide risk assessment.
Suspicious transaction report (STR)
AMLR Art. 69The report an obliged entity must file with its Financial Intelligence Unit when it knows, suspects, or has reasonable grounds to suspect that funds or activities are linked to money laundering or terrorist financing. AMLA is standardising the reporting format and the indicators of suspicion across the EU.
Targeted financial sanctions
Asset freezes and prohibitions on making funds or economic resources available to designated persons and entities, adopted under UN or EU sanctions regimes. The AMLR requires obliged entities to have internal policies and controls to manage sanctions-evasion risk alongside ML/TF risk.
Transposition
AMLD6The process by which Member States turn an EU directive into binding national law. AMLD6 (Directive (EU) 2024/1640, covering supervision, FIUs, and registers) must be transposed by 10 July 2027 — until then, national law implementing the previous directives continues to apply.