July 10, 2027, may seem like a distant date. From a business perspective, it still means almost a year to prepare for the new AML regulations. The problem is that for many organizations, adapting to the new regulations won't involve changing a few points of internal procedure.
The new EU AML system changes the way of identifying customers, assessing risk, determining beneficial owners, monitoring economic relations, organizing compliance functions, applying financial sanctions and supervising obligated institutions.
The most important change is systemic: the fundamental obligations of obligated institutions will be regulated directly in Regulation (EU) 2024/1624 of the European Parliament and of the Council – AMLR. The regulation will generally apply from 10 July 2027 and – unlike the directive – does not require implementation into national law. It is intended to create a uniform European set of AML rules, the so-called Single Rulebook.
Therefore, entrepreneurs who plan to start preparations only after the adoption of the next amendment to the Polish AML Act may start them much too late.
AMLR – why is the change different this time?
Until now, the European AML system has been largely based on directives implemented by individual member states. As a result, detailed solutions regarding KYC, beneficial ownership, risk assessment, and supervision may have differed between countries.
AMLR aims to change this model.
Many of the most important obligations of obligated institutions will stem directly from the regulation applicable throughout the European Union. It will be accompanied by Directive (EU) 2024/1640, which primarily regulates institutional and supervisory arrangements and the operation of national AML systems.
At the same time, a new European body was established – AMLA, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism.
This is not an office that will only begin operating in 2027. The AMLA is developing standards, guidelines, and methodologies to guide the application of the new regulations as early as 2026. According to its 2026–2028 work program, the office plans to implement 24 of its 40 regulatory mandates in 2026 alone.
The new AML system is being developed now.
KYC will no longer be a one-time "customer check"
One of the most practical changes will be an even greater emphasis on KYC being an ongoing process throughout the entire customer relationship.
The obligated institution must not only determine the client's identity and beneficial owner at the time of initiation of the relationship. It must also monitor the business relationship and update the information if circumstances relevant to the risk level change.
The direction in which supervisory practice will go is well illustrated by the draft guidelines on ongoing monitoring of economic relations published by AMLA on 3 June 2026.
AMLA indicates two parallel mechanisms:
- periodic reviews of customer data,
- updates triggered by specific events or changes in circumstances.
Monitoring should not be limited solely to cash flows. It should also encompass client activity, behavior, and events that may indicate a change in their risk profile. The draft also allows for the use of manual, automated, or semi-automated monitoring, provided that the adopted solution is proportionate, properly documented, and explainable to the supervisory authority. The AMLA plans to issue final guidelines in this regard in the fourth quarter of 2026.
In practice, this means that in many organizations it is not enough to correct the KYC form.
The question will need to be answered whether the organization has a mechanism to determine that the data collected a year earlier no longer reflects reality.
Beneficial Owner – 25% means 25%
The changes also concern the identification of the beneficial owner.
The current Polish model uses a threshold exceeding 25% of shares or voting rights in certain situations. However, the AMLR covers a threshold of at least 25%, including an individual owning exactly 25%.
Even more important, however, may be a clear separation of ownership and control. Simply determining who owns the appropriate percentage of shares will not conclude the analysis. The obligated institution should also verify whether another party exercises de facto control through other mechanisms, such as voting rights, the ability to appoint bodies, veto rights, or other corporate solutions.
For simple ownership structures the change may be minor.
In the case of holding companies, funds, international structures, investment agreements or multi-level shareholding, the difference can be fundamental.
Therefore, before 2027, it is worth not only changing the definition of the beneficial owner in the procedure, but also checking the logic used in the KYC forms and IT systems used to determine UBO.
AML risk assessment will need to cover more than money laundering
Risk assessment remains the foundation of the AML system. However, the scope of what an institution should analyze within it is changing.
AMLR requires consideration not only of money laundering and terrorist financing risks, but also of the risks of non-compliance and circumvention of targeted financial sanctions.
This is an important practical change.
In many organizations, sanctions compliance and AML currently operate as two partially separate areas. However, the new model increasingly connects them.
AMLA launched a consultation on guidelines for organization-wide risk assessment in April 2026. These guidelines will establish minimum requirements for identifying and assessing an organization's risk exposure, while maintaining proportionality based on the organization's size, business model, and risk profile.
In practice, an entrepreneur should ask himself the following question:
Does our current risk assessment actually describe the company's operations, or is it a document updated every two years mainly to be kept in a binder in case of an audit?
In the new model, such a difference may be particularly significant.
The management board will not be able to say: "AML is handled by the compliance officer"
AMLR strongly emphasizes responsibility at the organizational management level.
The regulation stipulates that a member of the management body be responsible for implementing internal AML/CFT policies, procedures, and controls. Ultimate responsibility for the organization's compliance with AML requirements should remain with the management body, while day-to-day duties may be delegated to a compliance officer.
This is an important difference from a corporate governance perspective.
The AML procedure cannot be a document known only to the compliance officer or the person responsible for KYC.
The board should know at least:
- what are the most important AML risks in the organization,
- how many clients were classified as high-risk,
- what are the most important problems detected during onboarding,
- whether there are any backlogs in KYC updates,
- how monitoring works,
- what reports are escalated,
- whether compliance has adequate resources.
In other words: AML is increasingly becoming an element of business management, not just the responsibility of the legal department.
Outsourcing KYC does not mean outsourcing liability
More and more companies use external systems for customer identification, sanction screening, PEP verification, document control and transaction monitoring.
Technology can significantly facilitate compliance. However, it does not transfer responsibility for compliance to the system provider.
The AMLR is clearly based on the principle that an obligated institution remains responsible for the performance of its obligations even when specific activities have been outsourced to an external entity.
Therefore, before 2027, it is worth reviewing not only the procedures but also the contracts with AML/KYC providers.
It will be crucial to determine, among other things:
- what data does the system verify,
- what sources does it use,
- how often are sanctions and PEP lists updated,
- whether it is possible to reproduce the result of historical verification,
- how alerts are documented,
- whether the organization is able to explain to the regulator how the solution used works.
This last element may be particularly important. In its draft monitoring guidelines, AMLA indicates that if advanced analytical tools are used, the organization should have appropriate governance mechanisms in place and be able to explain the role and results of these tools to the supervisory authority – even if it uses an external provider.
Capital groups will have to look at risk globally
The new system is of particular importance for groups operating in several countries.
The AMLR establishes policies, procedures, and controls at the group level, and the AMLA is already working on minimum standards for such arrangements, including in cross-border situations and for entities operating outside the European Union. The goal is to provide a consolidated view of AML/CFT risks across the group.
For capital groups, this means the need to check whether individual companies do not function in practice as separate "islands of compliance".
If each company has a different KYC form, a different scoring method, different high-risk client acceptance rules and different escalation mechanisms, preparing for AMLR may require a group-wide project.
Supervision is also changing – and sooner than 2027.
AMLA is not intended to be solely a guideline-making body.
From 2028, it is to begin direct supervision of the 40 most significant financial institutions operating cross-border, and the first selection process will take place in 2027. In parallel, the AMLA is building a model of indirect supervision and convergence of the practices of national authorities.
Importantly, on July 8, 2026, the AMLA announced the completion of work on a common European approach to enforcing AML violations. The standard is intended to ensure that comparable violations are assessed according to a common methodology, regardless of the country in which the obligated institution operates.
This is another signal that European AML is intended not only to harmonise regulations, but also to harmonise the way they are enforced.
What's happening in Poland?
At the same time, work is underway to change Polish regulations.
Draft UC75 amending the Act on Combating Money Laundering and Terrorist Financing provides, among other things, for the implementation of Directive (EU) 2024/1640. According to the Government Legislation Centre, as of August 12, 2026, the draft remains open and at the Legal Committee stage; it has not yet been submitted to the Sejm.
This does not mean, however, that entrepreneurs should wait for the Polish legislative process to be completed.
A significant part of the new obligations will result directly from the AMLR.
Is it necessary to prescribe the AML procedure now?
Not necessarily.
In many cases, it will be more rational to start with a gap analysis, i.e. a comparison of the current AML system with the model resulting from the AMLR and emerging AMLA standards.
First of all, it is worth verifying five areas:
1. KYC and Beneficial Ownership
Do the forms, systems and instructions allow for the correct identification of the ownership and control structure?
2. Risk Assessment
Does it truly reflect the business model, customers, products, distribution channels, geographic risks and financial sanctions risks?
3. Ongoing monitoring
Can the organization detect changes in the customer profile during cooperation, or does KYC end at the time of onboarding?
4. Governance
Is the responsibility of the management board, compliance officer and operational staff clearly defined?
5. Systems and data
Do AML tools allow not only to carry out checks, but also to later demonstrate what was checked, when, with what results and how the alert was responded to?
Only after such a review can you rationally decide which procedures, systems, contracts and processes require change.
Why is 2026 the best time to prepare?
The seemingly simplest solution is: let's wait until 2027, when all the guidelines will be known.
However, in larger organizations, this approach may prove risky.
Changing a procedure takes a few weeks. Changing the way an entire organization operates can take many months.
If adapting to AMLR means changing onboarding forms, rebuilding the risk matrix, changing the KYC system, integrating with data providers, defining new monitoring rules, amending outsourcing agreements, training employees and implementing new escalation paths, starting the project a few weeks before July 10, 2027 may be far too late.
Therefore, 2026 should be the year of diagnosis and design, and the first half of 2027 – the period of implementation and testing of new solutions.
Summary
July 10, 2027 will not be simply another effective date for new AML obligations.
The very architecture of the European system is changing: the directly applicable AMLR, a uniform Single Rulebook, a new European AMLA authority, common supervisory standards and increasingly precise requirements for KYC, monitoring, risk assessment and compliance management.
For obligated institutions, the most important conclusion is simple:
You should not start with the question "how to change our AML procedure?", but with the question "will our current AML system work in accordance with the new rules?".
In many organizations the answer to these two questions will be completely different.
This article is for informational purposes only and does not constitute legal advice
Legal status as of August 12 , 2026
Author / Editor of the series:
