Non-financial sector · Art. 3(3)(m)
EU AML rules for Mixed-activity holding companies
Non-financial holding companies with at least one obliged-entity subsidiary must themselves comply with AML rules — ensuring group-level policies flow through complex corporate structures.
In scope from
10 July 2027
Single Rulebook applies
10 July 2027
Underlying AMLR obligations for most sectors
Scope notes: Where a subsidiary is a credit or financial institution, the holding company may qualify as a financial institution for supervision purposes.
Legal stack — what binds when
Which legal layers govern your AML programme at each stage — national law, EU regulations, EBA legacy instruments, and AMLA Level 2/3 as they are adopted. Not legal advice; national transposition varies.
Sector note: Where a subsidiary is a credit or financial institution, the holding may be treated as a financial institution for supervision — group-policy mandates apply early.
Current era: Today — before AMLR application
Today — before AMLR application
You are not yet subject to harmonised AMLR obligations for mixed-activity holding companies — prepare using the fixed AMLR text and track AMLA consultations on universal mandates.
What binds (stacked layers)
National AML rules (where already in place)
Some Member States already supervise this sector under AMLD5 — thresholds, supervisors, and procedures vary. Do not assume harmonisation until your AMLR application date.
AMLR text (anticipatory preparation)
The Single Rulebook text is fixed — obligations under AMLR Art. 3 apply to mixed-activity holding companies from 2027-07-10. Build policies against the regulation now; Level 2 detail will follow.
AMLA consultations (universal mandates)
Core CDD, STR, and PEP mandates apply to almost every obliged entity — follow consultations even before you are in scope to avoid surprise when technical standards land.
From 10 July 2027 — in scope under AMLR
Direct AMLR obligations apply. National supervision and STR channels are transposed under AMLD6. Technical detail fills in as AMLA Level 2 and Level 3 instruments are adopted.
What binds (stacked layers)
AMLR — direct obligations
EU-harmonised CDD, PEP, STR, and internal control duties apply directly — the first time many non-financial sectors operate under a Single Rulebook.
AMLD6 national transposition
Supervision, registration, and FIU reporting channels are set nationally under transposed AMLD6 — identify your competent authority before the application date.
National implementing measures
Member States may set administrative details, supervisor powers, and sanctions — national law fills gaps until AMLA Level 2 is fully adopted.
AMLA Level 2 (as adopted)
RTS and ITS will specify CDD information, STR formats, and sector-relevant detail — until adopted, rely on AMLR general provisions and supervisor guidance.
eIDAS 2.0 — EUDI Wallet & remote identification
Remote CDD may use substantial/high eIDAS means under AMLR Art. 22(6)(b) — track wallet availability in your Member States from late 2026.
AMLA Level 3 guidelines
Guidelines on risk factors, PEPs, and suspicious indicators will operationalise the rulebook — EBA legacy guidelines do not automatically apply to most NFS sectors.
Group-wide policy mandates
Art. 16–18 group policies and third-country branch RTS apply where the group includes financial-sector subsidiaries.
Business-wide risk assessment
AMLR Art. 10 requires a documented BWRA using six mandatory information sources — including Annex I–III risk factors that also feed relationship-level CDD under Art. 20.
BWRA guide for HoldingsFirst steps before 10 July 2027
- 1Identify obliged-entity subsidiaries that pull the holding company into Art. 3(3)(m) scope.
- 2Plan group-wide AML policies flowing from parent to subsidiaries before 2027.
- 3Coordinate with subsidiary MLROs on reporting and risk assessment at group level.
Who supervises you?
Supervision varies by EU Member State and sector. Under AMLR Art. 62, AMLA will publish a register of national competent authorities; until that is live, use the European Commission's register of supervisors and FIUs to find who covers mixed-activity holding companies in your country.
Priority mandates for your sector
11 instrumentsInternal policies, procedures and controls — proportionality
Elements obliged entities should take into account — nature of business, risks, complexity and size — when deciding the extent of their internal policies, procedures and controls.
Business-wide risk assessment — minimum content
Minimum requirements for the content of the business-wide risk assessment and the additional information sources to take into account when carrying it out.
Why it matters: Your BWRA will be measured against this baseline from July 2027.
Business relationships, occasional and linked transactions
Criteria for identifying business relationships, occasional and linked transactions, and lower thresholds where simplified or enhanced CDD applies.
Risk variables and risk factors for CDD
Risk variables and risk factors obliged entities must weigh when entering business relationships or carrying out occasional transactions.
Why it matters: Successor to the EBA risk factors guidelines — your customer risk model will need to map to this taxonomy.
Ongoing monitoring of business relationships
Expectations for ongoing monitoring of business relationships and of the transactions carried out within them.
Customer due diligence — information requirements
The information obliged entities must collect and verify for standard, simplified and enhanced CDD, including sectoral adjustments.
Why it matters: The operational core of the Single Rulebook — defines what every onboarding and KYC file must contain across the EU.
Suspicious transaction reporting format
The format to be used for reporting suspicions and providing transaction records to FIUs.
Why it matters: STR/SAR workflows and transaction-monitoring outputs must produce this harmonised format.
Indicators of suspicious activity or behaviour
Indicators of suspicious activity or behaviours, to be periodically updated.
Why it matters: A living reference for transaction-monitoring scenario design and SAR decision-making.
Outsourcing of AML/CFT tasks
Establishment and governance of outsourcing relationships (including sub-outsourcing) and procedures for monitoring their implementation.
Group-wide policies, procedures and controls
Minimum requirements for group-wide AML/CFT policies, including minimum standards for information sharing within the group.
Branches and subsidiaries in third countries
Additional measures groups must take where third-country law prevents branches or subsidiaries from applying group-wide AML/CFT requirements.
This page is an independent orientation guide — not legal advice. National transposition and exemptions may apply. Always verify scope against the official AMLR text and your supervisor.