Supervisory Convergence is Changing Compliance Expectations
The creation of a common supervisory architecture is also changing how firms will need to demonstrate the effectiveness of their anti money laundering controls. The objective is not simply to move selected institutions from national supervision to EU level supervision. It is to establish more consistent approaches to risk assessment, supervisory methodology and enforcement across the financial sector. This makes AMLA supervision increasingly relevant to firms that may remain under national authorities as well as those expected to come under direct EU oversight.
A key part of this transition is the common risk assessment methodology. AMLA states that supervisors across the EU will use a common methodology for assessing money laundering and terrorist financing risks for the first time. The methodology considers both inherent and residual risk, meaning that supervisory assessment will take account of the risks associated with an institution’s activities as well as the effectiveness of its existing controls.
Risk Assessment is Becoming More Data Driven
The transition is already requiring firms and supervisors to work with more structured information. AMLA launched a data collection exercise in March 2026 to test and calibrate the models that will inform the selection of up to 40 entities for direct supervision from 2028. The exercise also includes a representative sample of institutions expected to remain under national supervision, allowing AMLA to test whether the methodology can support consistent assessments across different supervisory populations.
The selection process is becoming increasingly formalised. National supervisors are responsible for collecting eligibility information and submitting it to AMLA using standardised reporting requirements. AMLA’s May 2026 reporting package includes a common template and interpretative instructions for identifying provisionally eligible entities. The authority expects the provisional list of eligible entities to be finalised by the end of September 2026, ahead of the formal selection process in 2027.
This has implications for compliance functions. Risk assessments will increasingly need to be supported by consistent, explainable and comparable data rather than relying primarily on institution-specific methodologies. Firms may therefore face greater pressure to demonstrate how risk classifications are calculated, how controls reduce residual risk and how changes in those indicators are documented over time.
Direct and Indirect Supervision are Becoming Connected
The new framework is also designed to create a closer relationship between direct EU supervision and oversight performed through national authorities. AMLA’s 2026–2028 programme identifies advancing direct supervision and laying the foundations for indirect supervision of the wider financial sector as separate but interconnected priorities. The authority’s strategic objectives also include supervisory convergence, alongside completion of the Single Rulebook and stronger cooperation among Financial Intelligence Units.
This means firms should not view direct supervision as the only material change. Even institutions outside the first group of directly supervised entities will operate within a framework increasingly shaped by common methodologies, supervisory expectations and regulatory standards.
The distinction matters because up to 40 entities will be directly supervised initially, while the wider financial sector will continue to interact primarily with national supervisors. AMLA’s model therefore relies on both central oversight and convergence among national authorities rather than replacing national supervision entirely.
For firms, the practical effect is likely to be greater consistency in what supervisors expect to see: documented risk assessments, evidence that controls address identified risks, clear governance and information that can support supervisory conclusions. AMLA supervision is therefore influencing compliance expectations before direct supervision formally begins.
The transition also creates an implementation challenge. AMLA is simultaneously developing its supervisory model, building its risk frameworks and preparing the infrastructure required to oversee selected institutions. Its 2026–2028 programme describes these activities as part of a move from foundation to delivery, making the period before 2028 particularly important for testing methodologies and aligning supervisory practices.
The wider significance for financial institutions is that AMLA supervision is beginning to influence compliance design before the first direct supervisory relationships are established. As common risk methodologies become operational and supervisory convergence becomes a strategic priority, firms will increasingly need to demonstrate not only that AML controls exist, but that their effectiveness can be evidenced consistently through reliable risk data, documented governance and measurable outcomes.
AMLA Supervision is Moving Toward Greater Supervisory Convergence
The creation of a common EU level supervisory framework is changing how AML compliance effectiveness will be assessed across the financial sector. The transition is not limited to the institutions selected for direct supervision. Common risk assessment methodologies, standardised reporting requirements and closer coordination with national authorities are intended to produce greater consistency in how risks and control weaknesses are identified.
The move toward direct supervision of up to 40 high risk financial entities from 2028 provides a defined starting point, while the wider supervisory framework is expected to influence institutions that remain under national oversight. AMLA has identified supervisory convergence as one of its core strategic priorities for 2026 to 2028, alongside completing the Single Rulebook and strengthening Financial Intelligence Unit cooperation.
For financial institutions, the implication is a stronger focus on demonstrating control effectiveness through comparable and reliable evidence. Risk assessments, governance arrangements, customer due diligence and monitoring frameworks will increasingly need to show not only that requirements are being met, but that their effectiveness can be demonstrated through structured information and clear supervisory evidence.
AMLA supervision is therefore becoming part of a broader shift toward a more harmonised compliance environment. As the new framework moves from design into implementation, firms will face greater expectations around consistency, transparency and the ability to demonstrate how AML risks are identified, managed and reduced.