Description
The EU AMLR Toolkit is built on the Regulation, not the Directive it replaces
The EU AMLR Toolkit is a complete AML-CFT documentation set for Regulation (EU) 2024/1624, which applies from 10 July 2027. It is a Regulation, not a Directive: it applies directly in all 27 Member States, there is no national transposition to wait for, and the national rules that grew up around the previous Directive do not automatically carry forward.
The EU AMLR Toolkit is 99 editable templates – 81 Microsoft Word documents and 18 Microsoft Excel workbooks – organised into 17 sections that follow the Regulation’s own chapter structure, so a supervisor working through Chapter III can be handed the matching section. The full text of the Regulation is published on EUR-Lex.
What the EU AMLR Toolkit covers, and what it does not
The EU AMLR Toolkit answers 76 of the 80 operative articles. The other 4 are mandates to AMLA or to Member States rather than duties on an obliged entity, and each one is listed with the reason rather than quietly omitted.
Chapter IX – Articles 81 to 89 – is out of scope, because it is addressed to Financial Intelligence Units, the EPPO, OLAF, the Commission and the co-legislators. Article 90 is covered by the EU AMLR Toolkit for its application dates. A pack claiming to cover all ninety articles is claiming to answer obligations that are not yours.
The EU AMLR Toolkit is built on Level 1, and honest about Level 2
The Regulation mandates around two dozen regulatory technical standards, implementing technical standards and guidelines. Most carried a statutory deadline of 10 July 2026 and most were still in draft when this EU AMLR Toolkit was written – and the application date does not move because they are late. You can track their progress on the AMLA website.
So every document rests on the Regulation itself. Where a Level 2 measure will add detail, the document says so, records the position the entity has taken in the meantime, and is structured to receive the final text. A Level 2 Measures Status Tracker lists each mandate, its status, the documents it affects and the action it will require.
That is a deliberate choice. A pack that states draft technical-standard content as though it binds is wrong on the day the final text lands, and wrong in a way that is expensive to unpick.
The two roles the Regulation names
Article 11 requires two appointments, and they are not interchangeable. A compliance manager who is a member of the management body in its management function, accountable for compliance with this Regulation and with Regulation (EU) 2023/1113. And a compliance officer with sufficiently high hierarchical standing who runs the programme day to day, implements targeted financial sanctions, is the contact point for competent authorities and reports suspicions to the FIU under Article 69(6).
The EU AMLR Toolkit gives each role separate terms of reference, and carries the split through every document – including which of the two approvals under Article 9(2) each policy and procedure needs.
Transfers of funds and crypto-assets are inside the EU AMLR Toolkit
Articles 9(1) and 11(1) name Regulation (EU) 2023/1113 expressly: the internal policies must ensure compliance with it, and the compliance manager is accountable for it. So the information that must accompany transfers of funds and transfers of crypto-assets is part of this framework, with the Article 4 and Article 14 field sets set out in full.
It is also the part that is already live, unlike AMLR itself.
Crypto-asset service providers are in the Level 1 text
Not as an afterthought. The Regulation gives them their own provisions, and the EU AMLR Toolkit follows: Article 37 correspondent relationships for crypto-asset services, Article 40 measures for transfers to and from self-hosted addresses, the Article 39(2) duty to detect attempts by shell institutions to use the entity’s accounts, and the anonymity-enhancing coin limb of Article 79. Firms already authorised under the markets regime will want the MiCA Toolkit alongside it.
Registers in the EU AMLR Toolkit arrive already filled in
Three of the EU AMLR Toolkit workbooks ship seeded from the Regulation rather than empty.
The Article-by-Article Compliance Register opens with every one of the 80 operative articles already listed, each with the document that answers it – and the 4 with no obliged-entity duty flagged with the reason.
The Business-Wide Risk Assessment Workbook opens with the Annex I risk variables and the Annex II and Annex III risk factors already entered, group by group.
The Outsourcing Register opens with the six tasks Article 18(3) says may not be outsourced under any circumstances, so the first thing the EU AMLR Toolkit does there is stop you.
Written from the enacting text
The detail in the EU AMLR Toolkit comes from reading the Articles, not a summary of them. A few of the things that produces:
- Indirect ownership under Article 52(1) is calculated by multiplying along each chain and adding across chains. Two chains of 15% and 12% total 27% and cross the threshold; neither reaches it alone.
- Article 26(2) caps the interval between customer information updates at one year for higher-risk customers and five for everyone else – and requires the interval to vary with risk below the ceiling, so a single standard interval does not satisfy it.
- Article 77 requires records to be retained for five years and then deleted. Deletion is an obligation. The clock also starts at a refusal to enter into a relationship, which creates a retention duty on a file with no customer behind it.
- Article 71 lets you proceed three working days after a report if the FIU has not said otherwise – but only after assessing the risks of proceeding. A timer expiring is not a decision.
- Article 74 threshold reporting covers motor vehicles, watercraft and aircraft acquired for non-commercial purposes. That is a narrower list than the high-value goods in Annex IV, and the EU AMLR Toolkit keeps the two apart.
Where the EU AMLR Toolkit sits beside the rest of the catalogue
Financial-sector obliged entities rarely carry one obligation at a time. The EU AMLR Toolkit is built to sit alongside the DORA Toolkit for digital operational resilience, the NIS2 Toolkit where the entity is also an essential or important entity, and the Basel III Toolkit for prudential risk. Personal data processed under Articles 76 and 77 is handled with the GDPR Toolkit.
Honest about the boundaries
- The Regulation applies from 10 July 2027. The only exception is Article 3(3)(n) football agents and Article 3(3)(o) professional football clubs, for whom it applies from 10 July 2029. Every other obliged entity works to the earlier date.
- Most Level 2 measures were still draft when this EU AMLR Toolkit was written. It is built on the Level 1 text and says where detail is pending. Expect to revisit those areas.
- AMLA will not supervise you directly unless you are one of the selected obliged entities – credit and financial institutions operating in at least six Member States whose residual risk profile AMLA classifies as high, capped at 40 in the first selection. Everyone else stays with their national supervisor.
- The EU AMLR Toolkit is not legal advice, and national requirements sitting alongside the Regulation – a lower cash limit under Article 80, for instance – still need local input.
- Sector-specific provisions are included where the Regulation creates them. Documents that apply only to certain obliged entities are marked, and the implementation guide lists them.
What you get in the EU AMLR Toolkit
| Section | Documents | Basis in the Regulation |
|---|---|---|
| S01 Programme foundation and scope | 5 | AMLR Chapter I, Articles 1-8 |
| S02 Internal policies and controls | 19 | AMLR Chapter II Section 1, Articles 9-15 |
| S03 Group-wide requirements | 3 | AMLR Chapter II Section 2, Articles 16-17 |
| S04 Outsourcing | 2 | AMLR Chapter II Section 3, Article 18 |
| S05 Customer due diligence – general | 12 | AMLR Chapter III Section 1, Articles 19-28 |
| S06 Third-country policy | 3 | AMLR Chapter III Section 2, Articles 29-32, 35 |
| S07 Simplified due diligence | 2 | AMLR Chapter III Section 3, Article 33 |
| S08 Enhanced due diligence | 11 | AMLR Chapter III Section 4, Articles 34-46 |
| S09 Sector specifics and reliance | 4 | AMLR Chapter III Sections 5-6, Articles 47-50 |
| S10 Beneficial ownership transparency | 10 | AMLR Chapter IV, Articles 51-67 |
| S11 Reporting obligations | 7 | AMLR Chapter V, Articles 69-74 |
| S12 Information sharing partnerships | 2 | AMLR Chapter VI, Article 75 |
| S13 Data protection and record retention | 4 | AMLR Chapter VII, Articles 76-78 |
| S14 Anonymous instruments and cash limits | 2 | AMLR Chapter VIII, Articles 79-80 |
| S15 Transfers of funds and crypto-assets | 4 | Regulation (EU) 2023/1113, required by AMLR Articles 9(1) and 11(1) |
| S16 Supervision readiness | 3 | Regulation (EU) 2024/1620 (AMLAR) and Directive (EU) 2024/1640 |
| S17 Implementation and transition | 6 | AMLR Article 90 – application from 10 July 2027 |
S01 Programme foundation and scope
- AML-CFT Compliance Programme Manual
- Obliged Entity Scope Determination
- Exemption Assessment and Notification Procedure
- Cross-Border Operations Notification Procedure
- AMLR Definitions and Terminology Register
S02 Internal policies and controls
- Internal Policies, Procedures and Controls Framework
- Business-Wide Risk Assessment Procedure
- Business-Wide Risk Assessment Workbook (Excel)
- Pre-Launch Risk Assessment Procedure
- AML-CFT Risk Management Framework
- Compliance Manager Terms of Reference
- Compliance Officer Terms of Reference
- Compliance Resourcing and Proportionality Assessment
- AML-CFT Training Policy
- Training Plan and Attendance Register (Excel)
- Employee Integrity and Good Repute Screening Procedure
- Staff Screening Record Register (Excel)
- Breach Reporting and Reporting Person Protection
- Specific Employees Situation Procedure
- Internal Communication Procedure
- Compliance Monitoring and Remedial Action Procedure
- Independent Audit Function Charter
- Independent Audit Test Programme Workbook (Excel)
- Policy Approval and Version Control Record
S03 Group-wide requirements
- Group-Wide AML-CFT Policy
- Third-Country Branch and Subsidiary Additional Measures Procedure
- Group Structure and Coverage Register (Excel)
S04 Outsourcing
- AML-CFT Outsourcing Policy and Procedure
- Outsourcing Register and Non-Delegable Tasks Checklist (Excel)
S05 Customer due diligence – general
- Customer Due Diligence Policy
- CDD Trigger and Occasional Transaction Procedure
- Identification and Verification Procedure
- Verification Timing Procedure
- Register Discrepancy Reporting Procedure
- Purpose and Intended Nature Assessment Procedure
- Ongoing Monitoring and Transaction Monitoring Procedure
- Refusal, Termination and Exit Procedure
- UN Financial Sanctions Temporary Measures Procedure
- Customer Risk Assessment Methodology and Scoring Model (Excel)
- Customer Due Diligence File Template
- CDD Level 2 Measures Watch List
S06 Third-country policy
- High-Risk Third Country Policy
- Countermeasures Implementation Procedure
- Third-Country Exposure Register (Excel)
S07 Simplified due diligence
- Simplified Due Diligence Policy and Procedure
- SDD Eligibility Assessment Record
S08 Enhanced due diligence
- Enhanced Due Diligence Policy
- Cross-Border Correspondent Relationships Procedure
- Crypto-Asset Correspondent Relationships Procedure
- Third-Country Respondent Institution Measures Procedure
- Shell Institution Prohibition Standard
- Self-Hosted Address Transaction Mitigation Procedure
- Residence by Investment Applicant EDD Procedure
- Politically Exposed Persons Policy
- PEP Determination and Review Register (Excel)
- Enhanced Due Diligence Case File Template
- Higher-Risk Factor Assessment Checklist
S09 Sector specifics and reliance
- Life and Investment-Related Insurance CDD Procedure
- Reliance on Other Obliged Entities Policy
- Reliance Process and Agreement Template
- Reliance Register (Excel)
S10 Beneficial ownership transparency
- Beneficial Ownership Identification Policy
- Complex and Layered Structures Determination Procedure
- Trusts and Similar Legal Arrangements Procedure
- Collective Investment Undertaking Procedure
- Beneficial Ownership Information Record
- Obligations of Legal Entities Procedure
- Trustee Obligations Procedure
- Nominee Disclosure Procedure
- Foreign Legal Entity and Arrangement Procedure
- Beneficial Ownership Register (Excel)
S11 Reporting obligations
- Suspicious Transaction Reporting Policy and Procedure
- Suspicion Assessment and Decision Record
- Refraining from Transactions Procedure
- Tipping-Off Prohibition Standard
- FIU Disclosure Protection Note
- High-Value Goods Threshold Reporting Procedure
- Suspicion Report Log and FIU Correspondence Register (Excel)
S12 Information sharing partnerships
- Information Sharing Partnership Policy and Safeguards
- Partnership Participation Record
S13 Data protection and record retention
- AML-CFT Personal Data Processing Policy
- Record Retention and Deletion Schedule
- Provision of Records to Competent Authorities
- Retention and Deletion Log (Excel)
S14 Anonymous instruments and cash limits
- Anonymous Instruments Prohibition Standard
- Large Cash Payment Limit Procedure
S15 Transfers of funds and crypto-assets
- Transfers of Funds and Crypto-Assets Policy
- Originator and Beneficiary Information Procedure
- Missing Information Handling and Escalation Procedure
- Transfer Information Data Field Register (Excel)
S16 Supervision readiness
- Supervisory Engagement and Information Request Procedure
- AMLA Direct Supervision Exposure Assessment
- Supervisory Correspondence Register (Excel)
S17 Implementation and transition
- AMLR Implementation Plan and Roadmap
- AMLD Baseline to AMLR Gap Analysis Workbook (Excel)
- AMLR Article-by-Article Compliance Register (Excel)
- Level 2 Measures Status Tracker (Excel)
- Management Body Approval and Attestation Pack
- AMLR Toolkit Implementation Guide



































Reviews
There are no reviews yet