About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

EBA Framework 4.3 Maps the Data Behind AMLA’s First Risk Assessment

Subscribe to our newsletter

The European Banking Authority’s Reporting Framework 4.3 gives financial institutions their first machine-readable view of the data that will support the EU’s selection of firms for direct anti-money laundering supervision.

Published earlier this month, the framework marks an intermediate step towards the first formal risk-assessment and selection exercise by the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) in 2027.

The AMLA components of version 4.3 translate its risk-assessment templates into a Data Point Model and XBRL taxonomy. This gives national supervisors, financial institutions and reporting-system providers an early view of the definitions, table structures, data relationships and validation rules being developed for the exercise.

These components remain preparatory. The EBA says they must not be used to submit data to national competent authorities, the EBA or AMLA.

The wider v4.3 package also contains separate reporting requirements for EU branches of non-EU banks under the Capital Requirements Directive VI.

From 2026 Testing to 2027 Submissions

AMLA has conducted two related but distinct data exercises during 2026.

In March and April, sampled institutions supplied data through their national supervisors to test and calibrate AMLA’s risk-assessment models. Participation was limited to institutions notified by their national competent authorities. This was a test of the methodology rather than part of the formal selection process.

A separate exercise launched in May is identifying institutions that fall provisionally within AMLA’s cross-border selection perimeter. National supervisors organise the collection from institutions within their remit and transmit the information to AMLA.

National supervisors are due to provide this information to AMLA by 15 August. An error-correction and alignment phase will follow, with the provisional in-scope population expected to be established by the end of September.

Both exercises use AMLA’s Excel-based reporting packages and national collection arrangements. They allow AMLA and the EBA to test definitions, data availability and validation rules before the formal collection.

AMLA has signalled two changes for v4.4. The revised model will distinguish unavailable information from a reported value of zero and add two data points.

Phase 1 of EBA Reporting Framework 4.4 is due in September 2026. The EBA expects to revise the model using lessons from this year’s data collections before formal submissions begin. The figures submitted in 2027 will show each institution’s position as of 31 December 2026.

National supervisors are expected to finish collecting information from in-scope institutions by 31 March 2027 and send the validated data to AMLA by 31 May. AMLA will assess the institutions during the second half of the year and select those it will supervise directly from 2028.

Firms will provide the requested information through arrangements set by their national supervisors. Those authorities will check and validate the data before submitting it to AMLA.

National supervisors can decide which templates, systems and processes they use to collect the information from firms. Their onward submissions must meet AMLA’s specifications.

The reporting route therefore runs from institutions through national supervisors to AMLA. At this stage, v4.3 gives institutions and reporting-system providers a basis for mapping the required information to data points, tables, validation rules and XBRL concepts.

In-Scope Institutions

A credit institution, financial institution or group falls within AMLA’s cross-border selection perimeter if it operates in at least six EU Member States. Local operations may take the form of branches, subsidiaries or another established presence. Material cross-border services also count where a firm serves a market without establishing a local operation.

Such cross-border activity is material when it involves more than 20,000 customers in a Member State or when the combined annual value of incoming and outgoing transactions exceeds €50 million.

Meeting either threshold places the institution within AMLA’s assessment population. AMLA will assess its exposure to money-laundering and terrorist-financing risk, the quality of its controls and the residual risk left after those controls are taken into account. Up to 40 institutions or groups will move under direct AMLA supervision from 2028.

AMLA Focus Areas

AMLA’s proposed assessment draws on customer types and locations, products, transaction activity and distribution channels. It also examines beneficial ownership, politically exposed persons and business involving higher-risk jurisdictions.

The controls data go further into how compliance functions operate. AMLA is seeking information on overdue customer reviews, unverified beneficial owners, compliance staffing, outsourced controls and reporting to senior management.

For transaction monitoring, the requested measures include alert backlogs, average review times and the proportion of alerts that result in suspicious transaction reports. The model also asks for the time between identifying suspicious activity and filing a report, and between publication of a targeted financial sanction and its implementation in screening systems.

Capital-markets firms face additional data demands covering professional and retail clients, assets under management and custody, fund structures, investor locations and cross-border activity. Depending on the firm, that information may sit across client-onboarding and KYC systems, monitoring and screening tools, case-management platforms, and datasets covering instruments and ownership relationships.

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Sponsored by FundGuard: NAV Resilience Under DORA, A Year of Lessons Learned

The EU’s Digital Operational Resilience Act (DORA) came into force a year ago, and is reshaping how asset managers, asset owners and fund service providers think about operational risk. While DORA’s focus is squarely on ICT resilience and third-party dependencies, its implications extend deep into core operational processes that are critical to market integrity, investor...

BLOG

Introducing RegPass: A New Agentic Paradigm for Regulatory Change Management

After more than a decade shaped by document aggregation, workflow portals, and rule-mapping engines, a third generation of regulatory intelligence platforms is beginning to emerge. These systems move beyond collecting and classifying regulatory updates. Instead, they attempt something more ambitious: to understand, model and reason about a firm’s actual business operations, and to connect regulatory...

EVENT

RegTech Summit London

Now in its 10th year, RegTech Summit London will bring together the RegTech ecosystem to explore how the European capital markets financial industry can leverage technology to innovate the compliance function and response.

GUIDE

AI in Capital Markets Handbook 2026

AI adoption in capital markets has moved into a more disciplined phase. The priority is now controlled deployment: where AI can be used safely, where it can deliver measurable value, and how outputs can be governed, monitored and evidenced. The 2026 edition of the AI in Capital Markets Handbook examines how AI is being applied...