EU AML Package: what Swiss Financial Institutions need to know
The EU AML Package introduces a single, directly applicable rulebook (AMLR) and a centralised EU supervisor (AMLA). For Swiss financial institutions, this means that EU‑based counterparties and group entities will increasingly require evidence of harmonised controls, consistent risk scoring, and enhanced due‑diligence practices aligned with EU standards.
33%
Emergence of new technologies
33%
Increased competition
37%
Economic trends (including inflation/cost of living)
Increased competition is also one of the top trends influencing businesses today and one of the highest risers from last year.
28%
Difficulty recruiting skilled workforce
30%
National or international political tension/instability
31%
Energy prices and/or shortages
35%
Increased competition
41%
Economic uncertainty
Increased competition and economic uncertainty are the most important factors limiting growth
Contact
Executive Director, Head Regulatory Compliance & Financial Crime
Olivier Maes
AMLD 6: Effective cooperation and
a harmonised supervisory approach
Contact
Partner - Head Financial Services
Stefan Müller
Contact
Partner - Head Consulting
Ivan Lamorte
Contact our experts
The new European regulatory framework for combating money laundering and terrorist financing (“AML/CFT”) was officially published on 19 June 2024. This “AML Package”, or “Single Rulebook”, comprises three key legislative acts.
Regulation (EU) 2024/1624 of the European Parliament of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing.
AML Package or Single Rulebook
AMLR
AMLD 6
Directive (EU) 2024/1640 of the European Parliament and of the Council of 31 May 2024 on the mechanisms to be put in place by Member States to prevent the use of the financial system for the purposes of money laundering or terrorist financing.
Regulation (EU) 2024/1620 of the European Parliament of the Council of 31 May 2024 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism.
AMLA Regulation: Establishment of a European AML/CFT authority
The AMLA Regulation provides for the establishment of a new European authority responsible for anti-money laundering and counter-terrorist financing: the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA).
AMLA will be responsible for the direct and indirect supervision of the financial sector and for coordinating the activities of Member States’ Financial Intelligence Units. From 1 January 2028, at least 40 entities selected based on their risk profiles will be subject to AMLA’s direct supervision. Based in Frankfurt, the authority will be empowered to impose fines and sanctions on obliged entities that fail to comply with the European AMLR.
AMLR: Towards a harmonised European AML/CFT framework
The Regulation will be directly applicable to obliged entities from 10 July 2027 and will introduce strengthened and harmonised financial crime prevention requirements for both financial and non-financial obliged entities. Its objective is to clarify the rules applicable across the EU and ensure greater cross-border consistency in AML/CFT matters. The main changes relate to:
extending the scope of supervision and clarifying governance and procedural framework requirements;
strengthening customer due diligence obligations and the implementation of due diligence measures;
enhancing beneficial ownership transparency requirements;
reinforcing reporting obligations to Financial Intelligence Units;
enabling information sharing between obliged entities; and
strengthening data protection and record-retention requirements.
Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing will be directly applicable to obliged entities and will have significant practical implications for their control frameworks. These impacts will be particularly significant for institutions’ KYC frameworks, data management and operating models.
Organisation of the compliance governance framework
The AMLR will affect the organisation of the compliance governance framework. Institutions will be required to formally designate the following individuals:
A compliance manager, responsible for ensuring that the obliged entity’s internal policies, procedures and controls are proportionate to its risk exposure and are effectively implemented. This role must be performed by a member of the management body in its management function.
A compliance officer, appointed by the management body and holding a sufficiently senior position, responsible for the day-to-day application of the obliged entity’s AML/CFT policies, procedures and controls, including those relating to the implementation of targeted financial sanctions. The compliance officer will also act as a point of contact for the competent authorities.
Required updates to the policy and procedural framework and strengthened approval requirements
Article 9 of the AMLR specifies the minimum topics that institutions must address in their policies and procedures. Although the current content of these documents is broadly aligned with existing requirements and market practice, updates will be necessary to reflect the new obligations introduced by the Regulation.
These mainly concern:
the implementation of customer due diligence measures, which are set out in greater detail in the AMLR and the related RTS;
outsourcing requirements;
the submission of suspicious transaction reports (STRs); and
the arrangements for exchanging information within information-sharing partnerships.
In addition, internal policies must be approved by the management body in its management function, while internal procedures and controls must be approved at least at the level of the compliance manager.
Policies, procedures and operating instructions will need to be updated to ensure compliance with the requirements of the Regulation.
Significant Impacts on KYC processes and tools
The AMLR focuses extensively on customer due diligence and transparency in the identification of beneficial owners. It clarifies and strengthens know-your-customer (KYC) requirements, with the data collected forming the foundation of an effective financial crime prevention framework.
General Regime — Standard Due Diligence Measures
The general regime defines a list of basic information that must be collected. This will require institutions to review their KYC processes and may also necessitate enhancements to the supporting systems, including adjustments to data fields and document-storage capabilities.
The Regulation also provides further clarification on the implementation of due diligence measures, including:
the conditions for applying standard due diligence measures, including lower application thresholds for occasional transactions under Articles 19 and 20;
the actions to be taken where an institution is unable to comply with customer due diligence requirements, as well as the retention requirements for collected information and decision-making records, for example where a business relationship is declined, under Article 21;
the specific identification and verification information required for different customer types, as well as the approach to be taken where a virtual IBAN is used, under Article 22;
the process for reporting discrepancies against information recorded in beneficial ownership registers, including a maximum reporting deadline of 14 days, which may have a significant impact on KYC teams’ workload, under Article 24; and
the identification of the purpose and intended nature of a business relationship or occasional transaction, including the collection of information such as the estimated volume of anticipated activity and the source and destination of funds, under Article 25.
Consequences for Swiss financial institutions?
Articles 19–25 AMLR impose more granular, prescriptive, and uniformly binding KYC/CDD obligations than the Swiss AMLA/AMLO‑FINMA framework. For Swiss financial institutions, this means material uplift of KYC processes, documentation standards, IT/data architecture, and governance, especially for groups with EU branches/subsidiaries — but also indirectly for purely domestic banks because regulatory arbitrage becomes riskier and FINMA may expect alignment where EU rules are stricter.
One of the main expected impacts of the AMLR concerns the frequency of KYC file reviews, which must be conducted at least annually for high-risk customers and at least every five years for all other customers (Article 26).
The conditions for applying simplified due diligence measures are further specified. At a minimum, institutions will now be required to:
verify the customer’s identity within 60 days of establishing the business relationship; and
understand the purpose and intended nature of the business relationship.
Annex II to the Regulation includes a list of “lower-risk factors” intended to support institutions in conducting their risk assessments and configuring their tools, including customer risk-scoring and transaction-monitoring systems.
The conditions for applying enhanced due diligence measures are more prescriptive than under current Swiss law and provide for:
a specific regime for high-risk customers involving the management of assets of at least EUR 5 million through tailored services, where the customer has total wealth of at least EUR 50 million;
countermeasures that obliged entities must apply to individuals and legal entities linked to high-risk third countries and, where relevant, to other countries posing a threat to the Union’s financial system. These countermeasures will be defined at a later stage by the European Commission;
specific measures for correspondent banking relationships, particularly where these involve respondent institutions located in third countries;
a specific regime for individuals applying for investor residence schemes, including so-called golden passports and golden visas; and
further clarification of the regime applicable to politically exposed persons, including the need to consider risks arising from such functions even after the individual has left office.
In addition, a broader list of politically exposed functions than the one currently applicable in Switzerland is expected to be published. This will require institutions to update the lists used in their screening tools, as well as their processes for identifying and managing politically exposed persons (PEPs).
These developments are also expected to increase the number of customers classified as PEPs and may therefore require additional resources for institutions with significant exposure to this customer category.
Annex III to the Regulation includes a list of “higher-risk factors” intended to support institutions in conducting their risk assessments and configuring their tools, including customer risk-scoring and transaction-monitoring systems.
What this means for Swiss Financial Institutions with EU branches or subsidiaries?
Swiss headquarters may continue applying the Swiss foreign‑PEP‑only model, but EU branches must adopt the full AMLR PEP scope. Because AMLR requires mandatory EDD for domestic, regional, local, and SOE PEPs, Swiss groups will face pressure to harmonise upward to avoid regulatory arbitrage and inconsistent risk treatment. AMLR’s expanded categories (local officials, SOEs, associates) require new data fields, new screening logic, and updated KYC questionnaires. Finally, Swiss financial institutions must ensure group‑wide PEP policies clearly distinguish:
Swiss‑law obligations
AMLR obligations
Group‑wide risk‑based extensions
The rules governing the identification and verification of beneficial owners are further specified and include:
lowering the ownership threshold from 25% to 15% for certain categories of legal entities considered to present a higher level of risk. These categories will be defined at Member State level, and the European Commission may impose lower thresholds where deemed necessary;
defining the concept of “means of control” and the methodology for identifying beneficial owners where both ownership interests and control coexist within the ownership structure. Ownership interests must be assessed both individually and cumulatively; and
setting out the methodology for identifying beneficial owners in complex ownership structures, including legal arrangements, trusts, express trusts and collective investment undertakings.
The provisions of the AMLR and the related RTS will have a significant impact on KYC processes, systems and documentation, all of which will need to be adapted by July 2027.
New requirements for suspicious transaction reporting and exchanges with financial intelligence units
The new Regulation introduces several significant requirements for obliged entities:
They will be required to respond to information requests from the Financial Intelligence Unit (FIU) within five working days. In justified and urgent cases, this deadline may be reduced to less than 24 hours.
The format of suspicious transaction reports (STRs) and transaction records will be standardised at EU level. This will affect reporting processes and potentially the systems from which the required information is extracted. The format will be specified in an RTS to be published no later than 10 July 2026.
Where the activities of an information-sharing partnership result in the preparation of an STR, the obliged entities that identified the suspicion relating to their customers’ activities may designate one entity to submit a single report to the FIU.
A specific reporting regime will apply to credit institutions and financial institutions providing services relating to the purchase or transfer of ownership of high-value goods. These institutions will be required to report to the FIU all transactions executed for customers in connection with such goods. This may have a significant impact on private banking activities.
Information sharing through dedicated partnerships
Article 75 of the AMLR governs information sharing between obliged entities. Such sharing will only be permitted where both of the following conditions are met:
it is strictly necessary to comply with customer due diligence and suspicious transaction reporting obligations, while respecting fundamental rights and applicable judicial safeguards; and
the competent supervisory authorities have been informed in advance and have verified compliance, including the completion of a data protection impact assessment.
Information sharing will be optional and limited to the necessary data specified in the AMLR, including:
information relating to the customer and the customer’s identity;
the nature of the business relationship or transactions carried out;
the source of funds and source of wealth;
the customer’s risk factors and related risk assessments; and
suspicions of money laundering or terrorist financing.
The use of information-sharing arrangements will also require the implementation of appropriate technical and organisational measures to ensure a level of security and confidentiality proportionate to the nature and scope of the information exchanged. Such measures may include pseudonymisation and the use of suitable secure communication channels.
Outsourcing restrictions
Article 18 introduces specific outsourcing requirements, including a list of critical tasks that may not be outsourced:
proposing and approving the entity-wide risk assessment;
approving internal policies, controls and procedures;
deciding on the customer risk profile;
deciding whether to establish a business relationship with a customer or execute an occasional transaction on the customer’s behalf;
submitting suspicious transaction reports; and
approving the criteria used to detect suspicious or unusual transactions and activities.
In addition, the supervisory authority must be informed of the outsourcing arrangement before the service provider begins performing the outsourced activities on behalf of the obliged entity. This will require institutions to review their outsourced activities to ensure that none of the tasks listed above are included and, where necessary, to adapt the existing processes accordingly.
Staff integrity screening and training requirements
Article 13 sets out integrity requirements for personnel, including agents and distributors, who are directly involved in the obliged entity’s compliance activities. Institutions will be required to carry out an assessment proportionate to the risks associated with the tasks to be performed, with the assessment methodology approved by the compliance officer. For this purpose, institutions must define criteria tailored to the individual’s role—such as compliance manager, compliance officer or compliance specialist—to support and evidence the assessment. These criteria should enable the institution to verify the suitability and integrity of the personnel concerned.
Finally, about training requirements, agents and distributors must be included in the relevant training programmes. However, the Regulation does not appear to require obliged entities to deliver this training to their agents and distributors themselves.
Key impacts on Swiss compliance frameworks
AMLR will push Swiss banks toward stricter, more standardised KYC/CDD practices, because EU‑connected groups must align policies, data models, and monitoring thresholds across all entities. EU rules also raise expectations for beneficial‑ownership verification and high‑risk treatment, which affects Swiss banks serving EU clients or intermediaries. Finally, AMLR’s data‑governance, supervisory, and sector‑specific obligations will pressure Swiss institutions to upgrade systems, strengthen oversight, and adapt controls for EU‑facing payment and digital‑asset services.
Recommended actions
Swiss financial institutions should assess gaps between Swiss AML requirements and AMLR/AMLA standards, then align group‑wide policies to ensure consistent KYC, risk scoring, and monitoring across jurisdictions. They must upgrade data governance to meet EU expectations for traceability and interoperability and reinforce cross‑border oversight for EU‑linked business lines and correspondent relationships. Finally, they should prepare supervisory documentation that demonstrates risk‑based governance consistent with AMLA’s emerging supervisory model.
Along this journey, implementation projects could also be audited or strengthened with external advisors who are Subject Matter Experts to secure conformity with the regulatory expectations.
Conclusion
Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing — the AMLR — represents a major development in the European AML/CFT regulatory framework. This has impacts and creates challenges for Swiss financial institutions having branches or subsidiaries in the EU or owned by a EU financial group that may require an alignment of the Swiss operations to the EU AMLR.
Directly applicable from 10 July 2027, it will require obliged entities to undertake a significant transformation of their financial crime prevention frameworks, including updates to policies and procedures, strengthened customer due diligence measures and enhanced information-sharing arrangements. The impact will therefore extend across all components of the financial crime compliance framework.
In addition, AMLA will directly supervise up to 40 entities from 2028. AMLA’s supervisory model and the draft technical standards place a strong emphasis on data, which will become a key consideration in the future supervisory framework and in assessing the quality and effectiveness of AML/CFT arrangements.
These developments require institutions to mobilise quickly and in a coordinated manner to anticipate the necessary adjustments, particularly in relation to KYC, data management and governance, secure critical processes and ensure compliance within the required timelines.
Our dedicated Regulatory Compliance and Financial Crime teams have the relevant expertise to support you in preparing for and implementing the measures introduced by the European AML legislative package.
AMLAR
AMLR Regulatory Timeline
Focus on the practical impacts of the AMLR
Policies, procedures and operating instructions will need to be updated to ensure compliance with the requirements of the Regulation.
Secondary legislation will be published over the next two years to specify the detailed implementation requirements of the Regulation. To date, consultations have been completed or are ongoing regarding the following Regulatory Technical Standards (RTS):
RTS on customer due diligence;
RTS on risk profiling;
RTS on the criteria for selecting entities subject to direct AMLA supervision; and
RTS on sanctions.
Simplified Due Diligence regime
Enhanced Due Diligence regime
Beneficial ownership regime
Where obliged entities rely on other obliged entities, they must take all necessary measures to ensure that the relied-upon entity provides the required information and documentation within five working days of a request.
A highly detailed draft RTS on customer due diligence and beneficial ownership was published by the EBA in March 2025 and was subject to consultation. A second consultation, which is still ongoing, was launched by AMLA in February 2026.
These new provisions move towards a more cooperative and harmonised investigation and reporting framework. They will affect existing arrangements and require coordination among obliged entities.
Reliance on another obliged entity
This new directive amends and supplements the Fifth Anti-Money Laundering Directive (EU) 2015/849 and aims to reshape the institutional framework for anti-money laundering and counter-terrorist financing (AML/CFT). It entered into force on 10 July 2024, and Member States have until 10 July 2027 to transpose it into national law. The main provisions of AMLD6 focus on:
improving cooperation between relevant stakeholders and centralising financial information;
strengthening the framework for the identification, verification and oversight of beneficial owners;
establishing AML/CFT supervisory colleges; and
harmonising supervisory and sanctioning approaches.
Each institution must ensure that individuals are formally appointed to perform these functions and that they have the appropriate reporting lines and level of responsibility.
Head Regulatory Compliance and Financial Crime
Forvis Mazars in Switzerland
Olivier Maes
“AMLR pushes Swiss financial institutions toward more intensive KYC/CDD, stricter beneficial‑ownership verification, fully integrated AML–sanctions controls, and consistent group‑wide policy alignment. EU‑based entities must meet these requirements directly, while Swiss‑booked operations need to elevate their standards to prevent regulatory arbitrage and avoid heightened supervisory scrutiny.”
