Non-financial sector · Art. 3(3)(m)

EU AML rules for Mixed-activity holding companies

Non-financial holding companies with at least one obliged-entity subsidiary must themselves comply with AML rules — ensuring group-level policies flow through complex corporate structures.

In scope from

10 July 2027

345d left

Single Rulebook applies

10 July 2027

Underlying AMLR obligations for most sectors

Scope notes: Where a subsidiary is a credit or financial institution, the holding company may qualify as a financial institution for supervision purposes.

Legal stack — what binds when

Which legal layers govern your AML programme at each stage — national law, EU regulations, EBA legacy instruments, and AMLA Level 2/3 as they are adopted. Not legal advice; national transposition varies.

Sector note: Where a subsidiary is a credit or financial institution, the holding may be treated as a financial institution for supervision — group-policy mandates apply early.

Current era: Today — before AMLR application

You are herePassed

Today — before AMLR application

You are not yet subject to harmonised AMLR obligations for mixed-activity holding companies — prepare using the fixed AMLR text and track AMLA consultations on universal mandates.

What binds (stacked layers)

Binding (limited)National law

National AML rules (where already in place)

Some Member States already supervise this sector under AMLD5 — thresholds, supervisors, and procedures vary. Do not assume harmonisation until your AMLR application date.

Scope & governanceCustomer due diligenceSuspicious reportingSupervision
Prepare onlyEU regulation

AMLR text (anticipatory preparation)

The Single Rulebook text is fixed — obligations under AMLR Art. 3 apply to mixed-activity holding companies from 2027-07-10. Build policies against the regulation now; Level 2 detail will follow.

Scope & governanceCustomer due diligenceSuspicious reportingInternal controls & MLRO
Official source
Prepare onlyIn development

AMLA consultations (universal mandates)

Core CDD, STR, and PEP mandates apply to almost every obliged entity — follow consultations even before you are in scope to avoid surprise when technical standards land.

Customer due diligenceSuspicious reportingInternal controls & MLRO
Official source
Upcoming345d left

From 10 July 2027 — in scope under AMLR

Direct AMLR obligations apply. National supervision and STR channels are transposed under AMLD6. Technical detail fills in as AMLA Level 2 and Level 3 instruments are adopted.

What binds (stacked layers)

BindingEU regulation

AMLR — direct obligations

EU-harmonised CDD, PEP, STR, and internal control duties apply directly — the first time many non-financial sectors operate under a Single Rulebook.

Scope & governanceCustomer due diligenceSuspicious reportingInternal controls & MLRO
Official source
BindingEU directive

AMLD6 national transposition

Supervision, registration, and FIU reporting channels are set nationally under transposed AMLD6 — identify your competent authority before the application date.

SupervisionSuspicious reporting
Official source
Binding (limited)National law

National implementing measures

Member States may set administrative details, supervisor powers, and sanctions — national law fills gaps until AMLA Level 2 is fully adopted.

SupervisionInternal controls & MLRO
Not yet in forceAMLA Level 2

AMLA Level 2 (as adopted)

RTS and ITS will specify CDD information, STR formats, and sector-relevant detail — until adopted, rely on AMLR general provisions and supervisor guidance.

Customer due diligenceSuspicious reporting
Official source
BindingEU regulation

eIDAS 2.0 — EUDI Wallet & remote identification

Remote CDD may use substantial/high eIDAS means under AMLR Art. 22(6)(b) — track wallet availability in your Member States from late 2026.

Customer due diligence
Migration guide
Comply or explainAMLA Level 3

AMLA Level 3 guidelines

Guidelines on risk factors, PEPs, and suspicious indicators will operationalise the rulebook — EBA legacy guidelines do not automatically apply to most NFS sectors.

Customer due diligenceSuspicious reportingInternal controls & MLRO
Not yet in forceAMLA Level 2

Group-wide policy mandates

Art. 16–18 group policies and third-country branch RTS apply where the group includes financial-sector subsidiaries.

Group & cross-borderInternal controls & MLRO

Business-wide risk assessment

AMLR Art. 10 requires a documented BWRA using six mandatory information sources — including Annex I–III risk factors that also feed relationship-level CDD under Art. 20.

BWRA guide for Holdings

First steps before 10 July 2027

  1. 1Identify obliged-entity subsidiaries that pull the holding company into Art. 3(3)(m) scope.
  2. 2Plan group-wide AML policies flowing from parent to subsidiaries before 2027.
  3. 3Coordinate with subsidiary MLROs on reporting and risk assessment at group level.

Who supervises you?

Supervision varies by EU Member State and sector. Under AMLR Art. 62, AMLA will publish a register of national competent authorities; until that is live, use the European Commission's register of supervisors and FIUs to find who covers mixed-activity holding companies in your country.

Priority mandates for your sector

11 instruments
GuidelinesIn developmentPassedAMLR Art. 9

Internal policies, procedures and controls — proportionality

Elements obliged entities should take into account — nature of business, risks, complexity and size — when deciding the extent of their internal policies, procedures and controls.

GuidelinesConsultation closed · draftingPassedAMLR Art. 10(4)

Business-wide risk assessment — minimum content

Minimum requirements for the content of the business-wide risk assessment and the additional information sources to take into account when carrying it out.

Why it matters: Your BWRA will be measured against this baseline from July 2027.

RTSConsultation closed · draftingPassedAMLR Art. 19(9)

Business relationships, occasional and linked transactions

Criteria for identifying business relationships, occasional and linked transactions, and lower thresholds where simplified or enhanced CDD applies.

GuidelinesIn developmentPassedAMLR Art. 20

Risk variables and risk factors for CDD

Risk variables and risk factors obliged entities must weigh when entering business relationships or carrying out occasional transactions.

Why it matters: Successor to the EBA risk factors guidelines — your customer risk model will need to map to this taxonomy.

GuidelinesConsultation openPassedAMLR Art. 26(5)

Ongoing monitoring of business relationships

Expectations for ongoing monitoring of business relationships and of the transactions carried out within them.

RTSConsultation closed · draftingPassedAMLR Art. 28(1)

Customer due diligence — information requirements

The information obliged entities must collect and verify for standard, simplified and enhanced CDD, including sectoral adjustments.

Why it matters: The operational core of the Single Rulebook — defines what every onboarding and KYC file must contain across the EU.

ITSConsultation openPassedAMLR Art. 69

Suspicious transaction reporting format

The format to be used for reporting suspicions and providing transaction records to FIUs.

Why it matters: STR/SAR workflows and transaction-monitoring outputs must produce this harmonised format.

GuidelinesIn development345d leftAMLR Art. 69

Indicators of suspicious activity or behaviour

Indicators of suspicious activity or behaviours, to be periodically updated.

Why it matters: A living reference for transaction-monitoring scenario design and SAR decision-making.

GuidelinesIn development345d leftAMLR Art. 18

Outsourcing of AML/CFT tasks

Establishment and governance of outsourcing relationships (including sub-outsourcing) and procedures for monitoring their implementation.

RTSConsultation closed · draftingPassedAMLR Art. 16(4)

Group-wide policies, procedures and controls

Minimum requirements for group-wide AML/CFT policies, including minimum standards for information sharing within the group.

RTSConsultation closed · draftingPassedAMLR Art. 17(3)

Branches and subsidiaries in third countries

Additional measures groups must take where third-country law prevents branches or subsidiaries from applying group-wide AML/CFT requirements.

All rules for this sectorAMLR Art. 3 on EUR-Lex

This page is an independent orientation guide — not legal advice. National transposition and exemptions may apply. Always verify scope against the official AMLR text and your supervisor.