EU AML Regulation
AMLR 2027: Who Actually Falls Within Scope and Why “You Have a Year to Prepare” Is Misleading
The EU Anti-Money Laundering Regulation will apply from 10 July 2027, but the real question for businesses is not simply when it starts. It is whether they fall within its scope, what obligations apply to them, and which compliance work should begin before 2027.

Reviewed by Oleksandr Sobovyi, Founder & CEO of CORVUS AI — editorial responsibility statement below.
Regulation (EU) 2024/1624 (the Anti-Money Laundering Regulation, or AMLR) has already been adopted and entered into force. The bulk of its requirements will start applying across all EU Member States on 10 July 2027. As a Regulation, it has direct effect — no national implementation is required for it to apply.
The common phrase “entrepreneurs have a year to prepare” is imprecise. AMLR does not automatically turn every EU entrepreneur into a full AML-compliance subject. That is the right place to start any discussion.
1. The most important question: scope analysis
A serious analysis never begins with a list of obligations. It begins with one question:
Is the business an “obliged entity” under Article 3 AMLR?
Only if the answer is yes does it make sense to build a full AML framework.
Article 3 covers banks and other financial institutions, CASPs and crypto-asset service providers, auditors, accountants, tax advisers, certain activities of lawyers and notaries, trust and company service providers, specific real-estate market participants, gambling operators, and a number of other categories.
An ordinary IT company, manufacturer, consulting firm or retailer does not become an obliged entity merely because it does business in the EU. This is the first and most important correction to most public commentary on the topic.
2. Even if you are not an obliged entity, AMLR can still affect you
Indirect effects are already visible and will intensify.
The most obvious is the EU-wide limit on large cash payments. Member States may set lower national thresholds. At the same time, beneficial-ownership transparency rules are being strengthened.
For most ordinary B2B companies, however, the more significant impact will be indirect. Their banks, accountants, certain lawyers and payment providers (themselves obliged entities) will be required to understand far more systematically:
who you are,
who your ultimate beneficial owner is,
where the money comes from,
who the counterparty is,
what the purpose of the transaction is,
and whether the transaction fits the client’s profile.
An entrepreneur may feel the effects of AMLR not because the Regulation itself forced them to create an AML department, but because their bank starts asking many more questions and requesting more documentation. This is already happening and will only increase.
3. What changes if the company does fall under Article 3
Here the picture is fundamentally different. AMLR builds a full risk-based compliance architecture. In practice it can be broken down as follows:
Business-wide risk assessment The company must understand its own exposure to money-laundering and terrorist-financing risk: clients, countries, products, delivery channels and types of transactions.
Customer Due Diligence / KYC Identification of the client and verification of identity. For legal entities this is not enough: the chain company → shareholders → ownership/control → ultimate beneficial owner must be followed. The UBO becomes a central element of the system.
Risk classification Not all clients are equal. A public EU university sits at one risk level. A complex holding structure sits at another. A PEP combined with a high-risk jurisdiction and an unusual payment structure sits at a third. The depth of due diligence follows the classification.
Enhanced Due Diligence Higher risk triggers additional checks on ownership structure, source of funds / source of wealth (where applicable), the nature of the transaction and PEP exposure.
Ongoing monitoring This is the critical point. AML compliance is not “check once and forget”. It is a cycle: onboard → assess → monitor → reassess → document.
Suspicious transaction reporting Where the legal grounds exist, a report must be filed with the relevant FIU.
4. Why 2026–2027 really matter
Waiting until July 2027 is a poor strategy. The new EU Anti-Money Laundering Authority (AMLA) is currently developing a substantial body of RTS, ITS, Guidelines and Recommendations that will flesh out the practical application of the new regime. Work is already under way on standards for assessing the inherent and residual risk of obliged entities.
We know the Level 1 architecture, but the Level 2/3 operational detail is still being built. This is normal for EU regulation, yet it means those who fall within scope are better off starting preparation earlier rather than at the last moment.
5. What to do now
Do not start by buying AML software or drafting a 50-page policy.
Start with a short AMLR Applicability Assessment:
What exactly does the company do?
Does the activity fall under Article 3 AMLR?
If yes — under which category?
Which clients and counterparties create AML exposure?
Are there complex UBO structures?
Is there PEP or high-risk-country exposure?
Are crypto, cash or third-party payments used?
What AML controls already exist?
What needs to be built by 10 July 2027?
The result should be short and clear:
Not in scope — monitor only the indirect requirements and the changing behaviour of banks and other obliged entities.
In scope — perform a gap assessment and build an implementation roadmap.
Practical takeaway
For most ordinary businesses AMLR will not turn life into a compliance nightmare. It will, however, raise the cost of opacity — both for those who themselves fall under Article 3 and for those who deal with banks, payment providers and professional advisers.
The right first step is not “implement AML”. It is to understand whether, and to what extent, the new regime applies to you at all. Everything else follows from that answer.
Official text: Regulation (EU) 2024/1624 (EUR-Lex). Main application date: 10 July 2027. For certain categories listed in Article 3(3)(n)–(o) the date is 10 July 2029.
What matters. What’s next.
Disclaimer
This article has been prepared by CORVUS AI for general informational and educational purposes only. It is intended to make complex legal and regulatory developments easier to understand.
It does not constitute legal advice and does not create a professional adviser–client relationship. The information should not be relied upon as a substitute for advice based on the specific facts, circumstances and applicable law relevant to your organisation or project.
The article reflects our understanding of the law and regulatory framework as of the date of publication. Legislation, case law, regulatory guidance and administrative practice may subsequently change. While reasonable care has been taken in preparing this article, CORVUS AI does not warrant that the information is complete or remains current after the date of publication. We do not undertake to update this content.
To the fullest extent permitted by applicable law, CORVUS AI excludes liability for loss arising from reliance on this article. Nothing in this article constitutes an offer or solicitation to provide regulated legal services in any jurisdiction where doing so would be unlawful.
AI-assisted preparation: This article was prepared with the assistance of AI tools. Its legal analysis, conclusions and final text were subject to human review and editorial control and were reviewed and approved prior to publication by Oleksandr Sobovyi, Founder & CEO of CORVUS AI. CORVUS AI retains editorial responsibility for the published content.
For advice tailored to your organisation, project or specific circumstances, please contact CORVUS AI.
