EU AML glossary

Plain-language orientation for AML Package terminology. Article references point to the primary legal hook — always verify against the official text on EUR-Lex before relying on a definition.

AMLA

AMLAR

The EU Anti-Money Laundering Authority, established by Regulation (EU) 2024/1620 and seated in Frankfurt. Operational since July 2025, it drafts the Level 2 and Level 3 rules under the AML Package, coordinates supervisors and FIUs, and from 2028 directly supervises selected high-risk cross-border obliged entities.

Rules AMLA must deliver

Beneficial owner

AMLR Ch. IV

The natural person who ultimately owns or controls a customer — through a sufficient ownership interest (the AMLR baseline is 25%, with stricter treatment for higher-risk structures) or through control via other means. Obliged entities must identify and verify beneficial owners as part of CDD, and legal entities must hold and file this information in beneficial ownership registers.

Business relationship

AMLR Art. 2(1)

A relationship between an obliged entity and a customer connected to the entity's professional activities and expected to have an element of duration — the trigger for full onboarding CDD and ongoing monitoring, as opposed to one-off occasional transactions.

Business-wide risk assessment (BWRA)

AMLR Art. 10

The documented assessment each obliged entity must make of its own exposure to money laundering and terrorist financing risk — taking into account the EU supranational risk assessment, national risk assessments, and the risk variables in the AMLR annexes. It drives the entity's policies, controls, and the intensity of CDD it applies.

BWRA deep dive

Correspondent relationship

AMLR Ch. III

The provision of banking or payment services by one institution (the correspondent) to another (the respondent), including relationships established for securities transactions or crypto-asset services. Cross-border correspondent relationships with non-EU respondents require specific enhanced due diligence.

Crypto-asset service provider (CASP)

A provider authorised under MiCA (Regulation (EU) 2023/1114) to offer crypto-asset services — exchange, custody, transfer, and related activities. CASPs are obliged entities under the AMLR, with lower occasional-transaction thresholds and specific rules on transfers and self-hosted addresses.

CASP sector guide

Customer due diligence (CDD)

AMLR Ch. III

The core obligation: identify the customer and beneficial owner, verify identity, understand the purpose of the relationship, and monitor it on an ongoing basis. Applied on onboarding, for occasional transactions above thresholds, and when suspicion or doubt arises. The detail of what a compliant file contains is set by AMLA's CDD RTS.

CDD information RTS (Art. 28(1))

Enhanced due diligence (EDD)

AMLR Ch. III

Additional CDD measures required in higher-risk situations — including business with high-risk third countries, correspondent relationships, politically exposed persons, and cases the entity's own risk assessment flags. Typically means more information, senior-management approval, and closer monitoring.

Financial Intelligence Unit (FIU)

AMLD6

The national authority that receives and analyses suspicious transaction reports and disseminates intelligence to law enforcement. AMLD6 strengthens FIU powers, cooperation, and joint analysis across Member States, and AMLA hosts the FIU support and coordination mechanism.

Guidelines (Level 3)

Level 3

Non-binding instruments published by AMLA (sometimes jointly with the EBA, ESMA, or EIOPA) that operate on a comply-or-explain basis for supervised entities. Until AMLA's own guidelines land, many legacy EBA guidelines remain the operative reference.

EBA legacy instrumentsEBA → AMLA migration

High-risk third country

AMLR Ch. III

A non-EU jurisdiction identified by the European Commission as having strategic deficiencies in its AML/CFT regime (informed by FATF listings). Business relationships and transactions involving these countries trigger mandatory enhanced due diligence and, in some cases, countermeasures.

Implementing technical standards (ITS)

Level 2

Binding technical rules adopted by the European Commission as implementing regulations — typically formats, templates, and procedures, such as the standardised STR reporting format. Drafted by AMLA like RTS, but without the delegated-act scrutiny procedure.

All mandates

Obliged entity

AMLR Art. 3

A business or professional that the AMLR places under AML/CFT obligations — from credit institutions and CASPs to estate agents, art dealers, gambling operators, and (from 2029) professional football clubs and agents. If you are an obliged entity, the full CDD, reporting, and internal-controls framework applies to you.

All sectorsAm I in scope?

Occasional transaction

AMLR Art. 2(1)

A transaction carried out outside a business relationship. CDD is triggered when an occasional transaction meets the AMLR thresholds (EUR 10,000 as the general baseline, with lower sector-specific thresholds — e.g. for CASPs and cash-intensive activities).

Politically exposed person (PEP)

AMLR Art. 2(1)

A person entrusted with a prominent public function — heads of state, ministers, parliamentarians, senior judges, senior executives of state-owned enterprises, and similar roles — plus their family members and known close associates. Business with PEPs always requires enhanced due diligence.

Regulatory technical standards (RTS)

Level 2

Binding technical rules drafted by AMLA (building on EBA work for early mandates) and adopted by the European Commission as delegated regulations, subject to scrutiny by Parliament and Council. RTS carry the operational detail of the Single Rulebook — e.g. what a CDD file must contain.

All mandates

Self-regulatory body

AMLD6

A professional body — such as a bar association or chamber of notaries or accountants — that Member States may entrust with supervising its members' AML compliance, under the oversight of a public authority as required by AMLD6.

Notaries & lawyers sector

Simplified due diligence (SDD)

AMLR Ch. III

Reduced-intensity CDD measures allowed where the risk of a business relationship or transaction is low — e.g. adjusting the timing or extent of verification and monitoring. SDD is never an exemption: the obliged entity must still identify the customer and be able to demonstrate the low-risk assessment.

Single Rulebook (AMLR)

AMLR

Regulation (EU) 2024/1624 — the directly applicable core of the AML Package. Unlike the previous directives, it applies uniformly across the EU without national transposition, from 10 July 2027 for most obliged entities. It sets the harmonised rules on CDD, beneficial ownership, reporting, and internal controls.

SNRA / NRA

The supranational risk assessment (SNRA) is the European Commission's EU-level assessment of ML/TF risks; national risk assessments (NRAs) are each Member State's own. Both are mandatory inputs into an obliged entity's business-wide risk assessment.

BWRA sources registry

Suspicious transaction report (STR)

AMLR Art. 69

The report an obliged entity must file with its Financial Intelligence Unit when it knows, suspects, or has reasonable grounds to suspect that funds or activities are linked to money laundering or terrorist financing. AMLA is standardising the reporting format and the indicators of suspicion across the EU.

All mandates

Targeted financial sanctions

Asset freezes and prohibitions on making funds or economic resources available to designated persons and entities, adopted under UN or EU sanctions regimes. The AMLR requires obliged entities to have internal policies and controls to manage sanctions-evasion risk alongside ML/TF risk.

Transposition

AMLD6

The process by which Member States turn an EU directive into binding national law. AMLD6 (Directive (EU) 2024/1640, covering supervision, FIUs, and registers) must be transposed by 10 July 2027 — until then, national law implementing the previous directives continues to apply.