NewsSEALSQ takes a majority stake in Wecan Group — a CHF 5M investment to accelerate our AI Compliance Co-Pilot.
Wecan
Back to blog
Insights14 min read· July 24, 2026

The EU AML Package in 2026-2027: AMLR, AMLD6 and the New AMLA a Luxembourg/CSSF Lens

A practical readiness guide to the EU's AMLR, AMLD6 and the new AMLA authority, through a Luxembourg/CSSF lens — for banks, EAMs and fintechs.

by Wecan

The European Union's anti-money-laundering reform is the most consequential rewrite of the bloc's AML architecture in a generation. Three instruments — the directly-applicable Anti-Money Laundering Regulation (AMLR), the sixth Anti-Money Laundering Directive (AMLD6), and the regulation establishing a single Anti-Money Laundering Authority (AMLA) seated in Frankfurt — replace a patchwork of nationally-transposed directives with a single rulebook and, for the first time, a European supervisor with direct powers. For Chief Compliance Officers at EU-facing banks, External Asset Managers (EAMs) and fintechs, the practical question is no longer whether this changes their obligations, but how to be ready before the phased application dates arrive across 2027 and 2028.

This article is a readiness guide with a Luxembourg/CSSF focus — the jurisdiction where a large share of the EU's cross-border fund and private-banking activity is administered, and where many Swiss institutions maintain a presence. It also frames the cross-border reality for Swiss institutions that will run the revised Swiss regime (the Anti-Money Laundering Act, or LBA; the FINMA Anti-Money Laundering Ordinance, or OBA-FINMA; and the LETA transparency law) alongside the EU one.

1. The package at a glance: AMLR, AMLD6 and the AMLA authority

The reform is best understood as three instruments that do three different jobs. Conflating them is the most common source of confusion, because they differ in legal nature, in how they reach an obliged entity, and in the timeline on which they bite.

The AML Regulation (AMLR) is directly applicable. It is a single rulebook that harmonises the substantive obligations — customer due diligence (CDD), enhanced due diligence (EDD), beneficial-ownership identification, treatment of politically exposed persons, and an EU-wide cap on large cash payments — so that the same rules apply in every member state without national transposition. This is the instrument that will most change day-to-day compliance work.

The sixth AML Directive (AMLD6) is transposed into national law. It governs the institutional plumbing: beneficial-ownership registers, financial intelligence units (FIUs), the powers of national supervisors, and the rules on access to and cooperation between them. Because it is a directive, its details will still vary somewhat by member state.

The AMLA authority, established by its own regulation and seated in Frankfurt, is the structural novelty. It combines direct supervision of a limited number of high-risk, cross-border "selected obliged entities" with indirect oversight of national supervisors and FIUs across the Union. For the first time, a European body will examine certain groups itself rather than leaving supervision entirely to national authorities.

Instrument Legal nature What it does Primary effect on obliged entities
AMLR (Regulation) Directly applicable, no transposition Single rulebook: harmonised CDD, EDD, beneficial ownership, PEPs, cash limit Identical substantive rules in every member state
AMLD6 (Directive) Transposed into national law Beneficial-ownership registers, FIUs, national supervisors, access and cooperation National implementation of the institutional and register framework
AMLA (Authority + regulation) EU authority, seated in Frankfurt Direct supervision of selected obliged entities; indirect oversight of national supervisors and FIUs A European supervisor with direct reach into the highest-risk cross-border groups

The phasing matters. The AMLR becomes applicable across the EU in 2027, AMLA is building up its capacity to begin direct supervision of the first cohort of selected obliged entities from 2028, and AMLD6 is transposed nationally on a parallel track. The window to prepare is now, not when the first examination letter arrives.

2. What harmonised CDD, EDD and beneficial-ownership rules change operationally

The AMLR's promise is convergence: less fragmentation, fewer national carve-outs, one interpretation. For a compliance function, convergence cuts both ways. The good news is that a group operating in several member states can, in principle, run one CDD standard instead of reconciling a dozen. The uncomfortable news is that harmonisation tends to level up: the single rulebook sets a demanding floor, and a file that previously satisfied a lighter national reading may now fall short.

Customer due diligence and enhanced due diligence

The AMLR sets out harmonised expectations for identifying and verifying the customer, understanding the purpose and intended nature of the relationship, and conducting ongoing monitoring. Enhanced due diligence triggers — high-risk third countries, correspondent relationships, certain high-value or opaque structures, and politically exposed persons — are defined at EU level rather than left to each supervisor's guidance. The operational consequence is that EDD can no longer be a discretionary local overlay; it becomes a documented, rules-based step that an examiner in any member state expects to see applied consistently.

Beneficial ownership: one definition, applied to the ultimate natural person

Beneficial ownership is where harmonisation has the sharpest operational edge. The AMLR anchors a common definition built around a 25% ownership threshold and control-based tests, and it requires institutions to look through layered structures to the natural person who ultimately owns or controls the customer — irrespective of how many intermediate holding companies, funds or vehicles sit in the chain. This is the same direction of travel as the Swiss reform, and for the same reason: stopping at the first corporate layer is no longer defensible.

For a bank or EAM onboarding a company held through two or three vehicles across several jurisdictions, this is exactly the work that breaks the manual model. Reconstructing an ownership chain by hand — requesting registry extracts, translating them, mapping shareholdings, and re-verifying at each review — is the kind of task that takes 2 to 4 hours per file and stretches complex onboarding toward four to six weeks. Doing it consistently, at volume, against a single EU standard is a data problem before it is a legal one, which is why automating beneficial-ownership verification is now a supervisory expectation rather than an efficiency nicety.

3. The AMLA supervision model and "selected obliged entities"

AMLA is not a replacement for national supervisors; it is a new layer above and alongside them, with two distinct modes.

Direct supervision applies to a small group of selected obliged entities — the credit and financial institutions that operate across multiple member states and meet defined risk criteria. For this cohort, AMLA leads examinations through joint supervisory teams drawn from AMLA and the relevant national authorities. The number directly supervised is deliberately limited at the outset, but the entities in it are precisely the large, cross-border groups for which Luxembourg is a common hub.

Indirect supervision covers everyone else. Here AMLA sets standards, issues guidance, coordinates national supervisors, and steps in where a national authority falls short. The practical effect is convergence: even an institution that will never be directly supervised by AMLA will be examined by a national supervisor applying AMLA-aligned expectations. There is no "we are too small for AMLA" exemption from the substance.

For Chief Compliance Officers, the strategic reading is simple. Whether or not your group is on the selected list, you should assume you will be assessed against the harmonised standard, with the same demand that has already reshaped Swiss supervision: examiners want evidence that controls work, not merely that they exist. A screening tool that is switched on, a review policy that is written, an onboarding checklist that is signed — none of these, on their own, answers the question AMLA-era supervision asks, which is whether the control produced the right outcome, on time, on this specific file.

4. The Luxembourg/CSSF angle

Luxembourg concentrates several of the exact features the EU reform targets: it is a leading investment-fund domicile, a cross-border private-banking centre, and home to a large population of fund administrators, management companies and wealth managers serving clients across the Union and beyond. That combination — cross-border reach plus complex ownership structures — is what makes the jurisdiction central to how the package will be felt in practice.

The CSSF as supervisor

The Commission de Surveillance du Secteur Financier (CSSF) supervises AML/CFT compliance for the bulk of Luxembourg's financial sector, through its regulations, circulars and periodic AML/CFT reporting. Under the new architecture, the CSSF remains the national supervisor and the day-to-day counterparty for most entities, while working within AMLA's convergence framework and, for selected obliged entities headquartered or heavily active in Luxembourg, alongside AMLA in joint supervisory teams. In practice, Luxembourg-based groups should expect CSSF expectations and AMLA standards to move in lockstep.

The RBE beneficial-ownership register

Luxembourg's Registre des Bénéficiaires Effectifs (RBE), maintained by the Luxembourg Business Registers, already obliges entities to declare their beneficial owners. Under AMLD6, beneficial-ownership registers across the Union are being reinforced and better interconnected. For a compliance function this raises the bar rather than lowering it: the register is a second source of truth against which your own KYC conclusion must be reconciled. A mismatch between what the RBE shows and what your file concludes is a discrepancy you are expected to detect, resolve and document — not a private matter. The institutions that cope best are those that can reconstruct an ownership chain, compare it against the RBE, and evidence the comparison in minutes rather than days.

Cross-border activity as a selection factor

Because Luxembourg entities so often passport services across the EU and manage internationally-held structures, they are natural candidates for the multi-state footprint that feeds AMLA's selected-entity criteria. A Luxembourg private bank or fund platform with a genuinely pan-European client base should model now whether it could fall within direct supervision, and prepare its files to a standard that would survive an AMLA-led examination.

5. Switzerland ↔ EU: running two regimes without duplicating work

For Swiss institutions with EU-facing activity — and for groups with both a Swiss and a Luxembourg presence — the reform creates a two-regime reality. Switzerland is not in the EU and will not apply the AMLR, but it is tightening its own rules on a parallel timeline: the revised LBA and OBA-FINMA, and the LETA transparency law introducing a federal beneficial-ownership register from 1 October 2026 (covered in detail in our guide to the Swiss AML changes for 2026). The temptation is to build two compliance stacks. The better answer is to build one and map it to two regimes.

Obligation Switzerland (LBA / OBA-FINMA / LETA) EU (AMLR / AMLD6 / AMLA) Common denominator
Beneficial ownership Ultimate natural person; federal register from 1 Oct 2026 Harmonised 25% threshold and control test; national registers reinforced Resolve to a natural person through all layers; reconcile against a register
Customer due diligence Risk-based, FINMA / SRO expectations Harmonised, directly applicable in the AMLR Documented, risk-based CDD with a clear evidence trail
Enhanced due diligence Required for higher-risk relationships EU-level EDD triggers (high-risk third countries, PEPs, correspondents) Rules-based, documented EDD applied consistently
Supervision FINMA plus self-regulatory bodies National supervisor plus AMLA (direct or indirect) Demonstrable effectiveness, evidenced on demand
Ongoing monitoring Event-driven expectations, periodic reviews Ongoing monitoring under the single rulebook Continuous, event-driven updates rather than calendar-only cycles

The common denominator is striking. Both regimes want the ultimate natural person identified through every layer, both want that conclusion reconciled against a register, both want documented risk-based diligence, and both want evidence produced on demand rather than reassembled for an audit. An institution that builds its KYC around those shared properties satisfies most of both regimes from one data model — and only handles the genuinely jurisdiction-specific differences as exceptions, rather than maintaining two parallel operations. Duplication is the expensive failure mode here, and it is avoidable.

6. A readiness checklist for 2027-2028

The following is a practical checklist for closing the gap before the phased dates arrive. It applies whether your centre of gravity is a Swiss bank, a Luxembourg fund platform, an EAM or a fintech.

Map your footprint. Establish in which member states you operate and whether your cross-border activity could bring you within AMLA's selected-entity criteria. Even if not, assume you will be assessed against the harmonised standard.

Run a gap analysis against the highest floor. Compare your current CDD, EDD and beneficial-ownership procedures against the AMLR's harmonised expectations, treating the most demanding reading as the baseline. Retire national carve-outs your files quietly relied on.

Fix beneficial ownership to the natural person. Ensure every file resolves ownership through layered structures to the ultimate natural person, records the sources behind each link, and reconciles against the relevant register — the RBE in Luxembourg, the federal register in Switzerland, and equivalents elsewhere.

Make monitoring continuous. Move from calendar-driven periodic reviews toward event-driven monitoring, so that ownership changes, sanctions updates and adverse media reach the file when they occur.

Build one audit trail. Ensure every decision — a risk rating, a cleared alert, an accepted beneficial owner — is traceable, timestamped and evidence-linked, so a complete file can be produced on demand for either a CSSF/AMLA or a FINMA examiner.

Consolidate onto one data model. Resist building separate Swiss and EU stacks. Structure KYC data once and map it to each regime's specifics.

7. How automation delivers harmonised, demonstrable compliance across jurisdictions

The reason a single data model is realistic — rather than an aspiration — is that speed, traceability and evidence turn out to be the same capability. A system that resolves a beneficial-ownership chain automatically also records how it did so. A system that clears a screening alert contextually also captures why. Demonstrable effectiveness, the property both the EU and Swiss regimes now demand, is a by-product of automation and extremely expensive to manufacture without it.

The mechanics are consistent across jurisdictions. Reconstructing beneficial ownership by hand takes 2 to 4 hours per file; automated resolution reduces it to minutes, a saving of around 95%. Standard onboarding that runs 15 to 21 days manually — up to six weeks for complex structures — compresses to 2 to 3 hours when document collection, extraction, screening and risk scoring are orchestrated rather than sequential. Sanctions and PEP screening run manually produces false-positive rates of 90 to 99%, each costing roughly 30 to 60 minutes of analyst time; contextual AI scoring cuts false positives to 20 to 25% — around 75 points lower — so the audit trail reflects genuine decisions rather than noise. Periodic review per file falls from 2 to 4 hours to 20 to 45 minutes, and continuous, event-driven perpetual KYC removes 70 to 90% of scheduled review work entirely.

Metric Manual Automated (Wecan) Improvement
Ultimate beneficial-owner identification 2–4 hours/file Minutes −95%
Standard onboarding 15–21 days 2–3 hours −97% time
Complex-structure onboarding Up to 6 weeks 1–2 days −85% time
Document collection 5–10 days Under 24h −90% time
Screening false-positive rate 90–99% 20–25% ≈ −75 pts
Periodic review per file 2–4 hours 20–45 minutes −70%
Clients per analyst per month 15–25 80–120 ~4–5×
Cost per onboarded client CHF 300–800 CHF 50–150 ≈ −75%

The capacity effect compounds all of this: a KYC analyst handles 15 to 25 clients per month manually and 80 to 120 with automation — four to five times more — which matters because a loaded analyst is a scarce, expensive, slow-to-hire resource in both Zurich and Luxembourg. The cost per onboarded client falls from CHF 300–800 to CHF 50–150. Typical Year-1 net ROI on this kind of automation runs around 200–260%, with payback in three to four months. But under the EU package, the stronger argument is not cost — it is that harmonised, demonstrable compliance across two regimes is only realistically achievable when the evidence is generated automatically as the work is done.

8. How Wecan Comply helps

Wecan Comply is built around exactly the properties the EU package and the Swiss reform both demand. Beneficial-ownership resolution runs through layered structures automatically and reconciles against register data — the RBE, the Swiss federal register and others — so the ultimate natural person, and the evidence behind that conclusion, is captured rather than reconstructed later. Customer and enhanced due diligence follow a structured, rules-based workflow that maps to the AMLR's harmonised expectations and to FINMA's, from one data model rather than two.

Monitoring is continuous and event-driven, so ownership changes, sanctions updates and adverse media reach the file when they occur — turning a calendar-bound review model into perpetual KYC. And because every action leaves a timestamped, source-linked record, a complete audit trail for any file can be produced on demand, whether the examiner sits with the CSSF, AMLA or FINMA. For banks, EAMs and fintechs facing two regimes at once, that is the practical definition of harmonised, demonstrable compliance — and the ground automation was built to cover. The same logic applies whether you are reading this as a Swiss bank preparing for KYC/AML change or a Luxembourg platform preparing for AMLA.

See Wecan in action. In 30 minutes.

A live walkthrough on real KYC scenarios — no slides, no commitment. Just see if it fits your context.