The European Union’s new anti money laundering framework is placing greater emphasis on how financial groups organise and apply compliance controls across different entities and jurisdictions. Rather than relying on separate approaches at subsidiary level, the framework establishes stronger expectations for common policies, risk assessment procedures, information sharing and compliance oversight across the wider organisation.
This is making AML compliance frameworks increasingly important to the way financial groups manage regulatory risk. Under the new framework, parent undertakings are expected to establish group-level policies, procedures and controls covering money laundering and terrorist financing risks. Branches and subsidiaries must then implement those arrangements while taking account of their own activities, exposure and operating environment.
Group-Level Controls are Becoming More Structured
The regulatory shift extends beyond the creation of common policies. The framework calls for a more consolidated approach to identifying and managing financial crime risks across organisational structures. This includes group-level risk assessments, information-sharing mechanisms and compliance functions capable of identifying weaknesses across different parts of the organisation.
AMLA is developing additional regulatory technical standards to define minimum requirements for these arrangements. The standards cover how groups should organise their AML/CFT frameworks, establish internal information flows and maintain appropriate controls across subsidiaries and branches. This is significant because it moves the regulatory framework toward greater consistency in how financial groups structure and oversee their compliance operations.
AML compliance frameworks are also becoming more closely connected to group-level governance. The new rules provide for group compliance functions, including responsibility for overseeing implementation of group policies and reporting deficiencies to the management body of the parent undertaking. This creates a clearer line of accountability between individual operating entities and the wider organisation.
Managing Different Jurisdictions Within One Framework
The challenge becomes more complex where subsidiaries or branches operate outside the European Union. EU-based groups are expected to apply relevant group-level AML requirements across third-country operations while taking local legal conditions into account. Where local law prevents full application of EU requirements, additional measures may be required to manage the resulting money laundering and terrorist financing risks.
This creates a balance between consistency and local implementation. A central framework can establish minimum standards, but its application may need to be adapted to different regulatory environments, business models and operational structures. AML compliance frameworks therefore need to provide common controls while allowing institutions to address jurisdiction-specific constraints.
As the new requirements move toward implementation, financial groups will need to assess whether existing structures can provide consistent oversight across increasingly complex organisational networks. The direction of regulation is toward stronger group-level governance, clearer accountability and more integrated control arrangements, making AML compliance frameworks a more central part of how institutions manage financial crime risk across their operations.
AML Compliance Frameworks are Adapting to Complex Regulatory Environments
The move toward stronger group-level controls is creating more detailed expectations for how financial institutions manage compliance across different entities and jurisdictions. The new European framework is not limited to requiring a common AML policy. It also addresses information sharing, governance, risk assessment and the measures needed when local legal requirements differ from European standards.
This makes AML compliance frameworks increasingly dependent on clear responsibilities between parent undertakings, subsidiaries and branches. Group-level oversight can provide a consolidated view of money laundering and terrorist financing risks, while individual entities remain responsible for applying controls that reflect their own business activities and exposure.
Information Sharing is Becoming a Core Control
One of the most important developments concerns the movement of AML information within financial groups. Group-level policies are expected to support information sharing for AML/CFT purposes while maintaining appropriate safeguards around confidentiality and data protection. This creates a more structured relationship between individual compliance functions and the wider group.
The change is particularly relevant where risk information is distributed across multiple markets or business lines. A customer relationship, transaction pattern or geographic exposure identified by one entity may have implications elsewhere within the organisation. More consistent internal information flows can therefore help group compliance teams develop a broader assessment of risk rather than treating each entity as an isolated operation.
AMLA’s draft technical standards are intended to provide greater detail around these arrangements. The regulatory direction is toward common minimum requirements while recognising that subsidiaries and branches can face different operational and legal conditions. AML compliance frameworks therefore need to balance central oversight with appropriate local implementation.
Third-Country Operations Add Further Complexity
The challenge becomes more pronounced when financial groups operate in jurisdictions where local AML requirements differ from those applied within the European Union. Under the new framework, EU-based groups must take measures to ensure that third-country branches and subsidiaries remain subject to appropriate AML/CFT controls.
Where local legislation prevents the full application of EU requirements, additional measures may be needed to manage the resulting money laundering and terrorist financing risks. This means compliance teams need to assess not only whether a control exists, but whether it can operate effectively within the legal environment of the relevant jurisdiction.
The framework also strengthens group-level accountability. A group compliance manager is expected to oversee implementation of group policies and report to the management body of the parent undertaking, including on deficiencies requiring corrective action. This creates a clearer connection between operational compliance activity and senior-level governance.

Key Takeaway: Strong participation in AMLA’s technical-standard process highlights the practical importance of translating the new AML framework into workable compliance requirements.
The wider direction is toward a more coordinated control environment in which policies, risk assessments, information flows and compliance oversight are connected at group level. AML compliance frameworks will therefore need to demonstrate not only that individual controls exist, but also that they operate consistently across complex organisational structures.
AML Compliance Frameworks are Moving Toward Greater Consistency
The European Union’s new AML framework is pushing financial groups toward more consistent compliance arrangements across subsidiaries, branches and other entities. The emphasis is shifting from separate jurisdictional processes toward common policies, information-sharing mechanisms, group-level oversight and consolidated risk assessment.
This makes AML compliance frameworks increasingly important to regulatory readiness. Groups will need to demonstrate that their controls operate effectively across different organisational and legal environments, while still accounting for local requirements and specific risk exposures.
The challenge will be maintaining consistency without creating rigid controls that fail to reflect local circumstances. As AMLA develops the detailed technical framework, institutions will need stronger governance, clearer accountability and more reliable information flows across their operations. AML compliance frameworks are therefore becoming a central mechanism for connecting group-level strategy with the practical management of financial crime risk.