Financial sector · Art. 3(3)(h)

EU AML rules for Crowdfunding service providers

Crowdfunding platforms and intermediaries connecting investors with project owners must apply EU-wide AML controls from July 2027, including customer identification and suspicious activity reporting.

In scope from

10 July 2027

345d left

Single Rulebook applies

10 July 2027

Underlying AMLR obligations for most sectors

Scope notes: Covers crowdfunding service providers and crowdfunding intermediaries under Regulation (EU) 2020/1503.

Legal stack — what binds when

Which legal layers govern your AML programme at each stage — national law, EU regulations, EBA legacy instruments, and AMLA Level 2/3 as they are adopted. Not legal advice; national transposition varies.

Current era: Today — transitional period · EBA → AMLA substitution guide

You are herePassed

Today — transitional period

You are already an obliged entity under national AML law and EBA guidance. The AML Package is published; AMLA is drafting the Level 2 detail that will replace much of the EBA rulebook.

What binds (stacked layers)

BindingNational law

National AMLD5/6 transposition

Member State AML laws implementing the AML Directives — customer identification, STR, internal controls, and registration with your national supervisor.

Scope & governanceCustomer due diligenceSuspicious reportingInternal controls & MLROSupervision
Comply or explainEBA legacy

EBA AML guidelines (legacy)

Risk factors (EBA/GL/2021/02), remote onboarding (EBA/GL/2022/15), compliance officer role, and other EBA/joint ESA instruments. Under AMLA Regulation Art. 54, existing EBA AML/CFT guidelines and standards remain valid until AMLA formally replaces them.

Customer due diligenceSuspicious reportingInternal controls & MLROSupervision
Official source
Prepare onlyIn development

AMLA draft RTS / ITS / guidelines

Consultations and drafts from AMLA — not yet binding but signal the technical standards that will supersede EBA guidance. Respond if your systems or policies will need to change.

Customer due diligenceSuspicious reportingInternal controls & MLRO
Official source
Prepare onlyEU regulation

AMLR & AMLD6 (published, preparing)

Primary legislation is in force but core AMLR obligations for obliged entities apply from 10 July 2027 — use the text now to gap-assess policies and programmes.

Scope & governanceCustomer due diligenceSuspicious reportingInternal controls & MLRO
Official source
Upcoming345d left

From 10 July 2027 — Single Rulebook

AMLR applies directly. EBA instruments stay in force until AMLA replaces them instrument-by-instrument. Level 2 and Level 3 adoption continues on a rolling basis.

What binds (stacked layers)

BindingEU regulation

AMLR — Single Rulebook (direct effect)

Harmonised Level 1 obligations on CDD, PEPs, STR, internal controls, and record-keeping apply directly — no national gold-plating on core requirements.

Scope & governanceCustomer due diligenceSuspicious reportingInternal controls & MLRO
Official source
BindingEU directive

AMLD6 — supervision & FIU mechanisms

Member States transpose supervision arrangements, FIU cooperation, and beneficial ownership registers — affects who supervises you and how STRs are handled nationally.

SupervisionSuspicious reporting
Official source
Comply or explainEBA legacy

EBA instruments (until AMLA replaces)

Under AMLA Regulation Art. 54, existing EBA AML/CFT guidelines and standards remain valid until AMLA formally replaces them.

Replaced instrument-by-instrument as AMLA publishes successors

Customer due diligenceInternal controls & MLROSupervision
Migration guide
Not yet in forceAMLA Level 2

AMLA RTS & ITS (as adopted)

Legally binding technical detail on CDD fields, STR formats, supervisory methodologies, and crypto-specific rules — adoption is rolling from the July 2026 delivery wave onward.

Customer due diligenceSuspicious reportingInternal controls & MLROSupervision
Official source
BindingEU regulation

eIDAS 2.0 — EUDI Wallet & remote identification

AMLR Art. 22(6)(b) requires acceptance of substantial/high eIDAS electronic identification — wallets roll out from 2026; Art. 28(1) RTS will specify attributes and reliable sources.

Customer due diligence
Migration guide
Comply or explainAMLA Level 3

AMLA guidelines (as published)

Level 3 guidelines shape supervisory expectations — comply or explain for supervised entities.

Customer due diligenceSuspicious reportingInternal controls & MLRO
Official source

Business-wide risk assessment

AMLR Art. 10 requires a documented BWRA using six mandatory information sources — including Annex I–III risk factors that also feed relationship-level CDD under Art. 20.

BWRA guide for Crowdfunding

First steps before 10 July 2027

  1. 1Confirm you are a crowdfunding service provider or intermediary under Regulation (EU) 2020/1503.
  2. 2Design onboarding flows that capture investor and project-owner identity before funds move.
  3. 3Monitor AMLA CDD and STR mandates — reporting channels must be ready before July 2027.

Who supervises you?

Supervision varies by EU Member State and sector. Under AMLR Art. 62, AMLA will publish a register of national competent authorities; until that is live, use the European Commission's register of supervisors and FIUs to find who covers crowdfunding service providers in your country.

Priority mandates for your sector

11 instruments
GuidelinesIn developmentPassedAMLR Art. 9

Internal policies, procedures and controls — proportionality

Elements obliged entities should take into account — nature of business, risks, complexity and size — when deciding the extent of their internal policies, procedures and controls.

GuidelinesConsultation closed · draftingPassedAMLR Art. 10(4)

Business-wide risk assessment — minimum content

Minimum requirements for the content of the business-wide risk assessment and the additional information sources to take into account when carrying it out.

Why it matters: Your BWRA will be measured against this baseline from July 2027.

RTSConsultation closed · draftingPassedAMLR Art. 19(9)

Business relationships, occasional and linked transactions

Criteria for identifying business relationships, occasional and linked transactions, and lower thresholds where simplified or enhanced CDD applies.

GuidelinesIn developmentPassedAMLR Art. 20

Risk variables and risk factors for CDD

Risk variables and risk factors obliged entities must weigh when entering business relationships or carrying out occasional transactions.

Why it matters: Successor to the EBA risk factors guidelines — your customer risk model will need to map to this taxonomy.

GuidelinesConsultation openPassedAMLR Art. 26(5)

Ongoing monitoring of business relationships

Expectations for ongoing monitoring of business relationships and of the transactions carried out within them.

RTSConsultation closed · draftingPassedAMLR Art. 28(1)

Customer due diligence — information requirements

The information obliged entities must collect and verify for standard, simplified and enhanced CDD, including sectoral adjustments.

Why it matters: The operational core of the Single Rulebook — defines what every onboarding and KYC file must contain across the EU.

ITSConsultation openPassedAMLR Art. 69

Suspicious transaction reporting format

The format to be used for reporting suspicions and providing transaction records to FIUs.

Why it matters: STR/SAR workflows and transaction-monitoring outputs must produce this harmonised format.

GuidelinesIn development345d leftAMLR Art. 69

Indicators of suspicious activity or behaviour

Indicators of suspicious activity or behaviours, to be periodically updated.

Why it matters: A living reference for transaction-monitoring scenario design and SAR decision-making.

GuidelinesIn development345d leftAMLR Art. 18

Outsourcing of AML/CFT tasks

Establishment and governance of outsourcing relationships (including sub-outsourcing) and procedures for monitoring their implementation.

GuidelinesIn development345d leftAMLR Art. 42

Politically exposed persons

Criteria for identifying close associates and the level of risk associated with particular categories of PEPs, family members and close associates.

GuidelinesIn development345d leftAMLR Art. 50

Reliance on other obliged entities

Acceptable conditions for relying on CDD information collected by another obliged entity — including remote CDD — and the roles and responsibilities involved.

All rules for this sectorAMLR Art. 3 on EUR-Lex

This page is an independent orientation guide — not legal advice. National transposition and exemptions may apply. Always verify scope against the official AMLR text and your supervisor.