From 2028, the top 40 EU banks will face direct scrutiny under the Anti-Money Laundering Authority (AMLA). This development has been a long time coming. Cross-border flows are accelerating, and financial crime is evolving just as fast. The European Banking Authority found in 2025 that 70% of competent authorities report high or rising money-laundering and terrorist-financing risk in the financial sector.
While the AMLA’s direct supervision will only initially cover 40 banks, the move sends an industry-wide signal. The bar is rising on how banks are judged, how controls are evidenced, and how financial crime frameworks stand up under pressure. These expectations won’t just stop at the largest institutions, but will increasingly shape expectations across the wider market.
For banks relying on translation tools to bridge the gap between legacy infrastructure and new messaging standards, the clock is ticking. Many legacy systems weren’t designed to store structured AML data or provide end-to-end traceability. When regulators come knocking, fragmented records leave banks exposed to fines, remediation, and reputational damage. Those who wait risk reacting under pressure rather than staying ahead of the curve.
From Screening to Structured Evidence
The AMLA was established in 2024 to strengthen and harmonise anti-money laundering and counter-terrorist financing (AML/CFT) supervision across the EU. For years, oversight has been national, creating inconsistencies in assessment and enforcement. AMLA’s mandate is to create greater consistency, convergence and accountability, reducing gaps that financial crime can exploit.
To support this, European authorities developed a first package of Regulatory Technical Standards (RTS). The RTS specifies standardised data points and criteria that national supervisors will use to assess money-laundering and terrorist financing risk. This involves a three-step process: assess inherent risk, evaluate AML/CFT controls, and determine a residual risk score.
The decision to directly supervise 40 of the EU’s highest-risk cross-border banks from 2028 marks the next phase. It signals that this harmonised methodology will not remain theoretical, but will be brought into direct EU-level application. The direction of travel is clear. Scrutiny is becoming more centralised, more consistent and more exacting, with less room for interpretation or inconsistency.
Supervisors will now assess not only the presence of controls but also how effectively those controls are applied and how risk assessments translate into action. Banks must be able to show precisely how decisions were made, who approved them, and what follow-up steps were taken. Without a complete, end-to-end record, it is impossible to demonstrate that controls are effective or that residual risks are properly managed in a defensible way.
Translation Tools Become the Weak Link
Meeting AMLA’s expectations will be challenging for many banks. Translation tools – used to convert payment message formats to meet evolving requirements – were never designed to capture structured AML verification data or link compliance decisions to individual transactions. They can reformat messages, but they do not embed verification records into the core systems. As a result, critical AML information ends up sat across multiple platforms. Some data remains in the originating platform, some in separate AML systems, whilst workflow decisions may be recorded elsewhere entirely.
The result is fragmentation. Data is split across systems, teams, and workflows. Critical AML information is scattered, making it difficult – if not impossible – to create a single, coherent view of a payment and its associated AML checks. Under AMLA’s new standards, this kind of disconnected record-keeping will be a major liability.
Recent enforcement action shows how quickly these weaknesses can translate into real consequences. In July 2025, the Financial Conduct Authority fined Barclays £42 million for weaknesses in financial crime controls, citing failures in customer due diligence and ongoing monitoring. The AMLA can impose similarly strong penalties – up to €10 million or 10% of a company’s annual turnover. Banks that delay upgrading their AML frameworks not only risk steep fines, but lasting damage to client trust should they fall victim to control failures they cannot clearly explain.
Modernising Payments to Meet AML Demands
As regulatory expectations tighten, banks face a choice. They can continue layering temporary fixes onto legacy infrastructure, or rethink how compliance is built into payments altogether. Stop-gap solutions may appear cost-effective in the short-term, but they often add complexity, increase operational risk and make evidencing compliance harder over time.
A more sustainable path is to embed compliance directly into the transaction lifecycle. That means ensuring AML evidence – screening results, verification references and workflow decisions – sits within the payment record itself, creating a clear and defensible audit trail. Payments platforms that integrate seamlessly with AML and sanctions providers can capture responses in real time, reducing delays and manual intervention. They also standardise data across message formats, allowing banks to build transparency into everyday operations. Banks that take this approach will be better placed to meet rising supervisory expectations; those that delay may find short-term workarounds turning into long-term constraints.
The AMLA Wake-Up Call
AMLA’s supervision of 40 institutions is a starting gun for banks. As increased sanctions expand, the ability to evidence compliance at the transaction level will soon become a baseline expectation. Banks need to move now to get their ducks in a row and ensure their systems are fit for purpose. Those that embed verification, real-time monitoring, and structured workflows into their core processes will navigate scrutiny with confidence. Those that delay risk chaos – scrambling to trace transactions, facing fines, and suffering reputational damage when the rules inevitably tighten across the board.
Learn more at aquaglobal.co.uk
- Cybersecurity in FinTech
- Digital Payments