Skip to main content

From 2027, the EU’s Anti-Money Laundering Regulation (AMLR, Regulation (EU) 2024/1624) will apply directly across Member States a harmonised set of rules on customer due diligence (CDD), enhanced due diligence (EDD), and risk assessment. Introducing among others changes:

  • An expanded scope of obliged entities
  • Stronger risk-based requirements for due diligence across all business operations (Art. 20, AMLR 2024/1624)
  • A mandatory, non-exhaustive list of risk factors defined in Annexes II–III
  • Enhanced focus on beneficial ownership and opaque corporate structure red flags
  • Strict reporting obligations
  • The broader AML package establishes the new EU AML Authority (AMLA) with direct supervisory role

To inform AMLA’s work, the European Banking Authority (EBA) has also recently issued a series of Regulatory Technical Standards (RTS) and Guidelines, aimed to standardise risk assessment methodologies, definitions and supervisory reporting.

In this new framework, firms able to deploy scalable, data‑driven and AI-powered solutions for AML/CFT will be best placed to meet the new requirements and turn them into a strategic defence against legal, reputational and operational risks.

A Risk Based Approach

Obliged entities are required to perform a documented, up to date assessment of ML/TF risks at business wide level, taking into account at least the risk factors set out in AMLR Annexes, assessed across multiple dimensions: customer, products and services, delivery channels, geography, and structural/behavioural red flags. The presence of Higher risk factors (Annex III) flags a situation requiring EDD (Art. 20(2), AMLR).

Why Crime&tech Tools Are Built for This

Crime&tech’s 20+ risk indicators on legal entities and individuals turn this multi‑dimensional approach into an automated and validated (see below) scoring system – embedded in Crime&tech tools or third‑party platforms – that generates explainable risk ratings that can be broken by risk areas. Our portfolio covers:​

Ownership structure
Territory & sector
Political exposure
Financial anomalies
Negative events
Countermeasures
Other
Ownership structure
Territory & sector
Political exposure
Financial anomalies
Negative events
Countermeasures
Other

Opaque Ownership

In the AMLR, unduly ownership complexity is both a high‑risk factor (Annex III) and an issue to be investigated as part of EDD (Art. 20(1)(b)), reflecting the growing use of multi‑layered cross‑border structures to obscure beneficial ownership. EBA’s Guidelines define ownership as complex when “there are three or more layers between the customer and the beneficial owner” and involves legal arrangements, entities registered in foreign jurisdictions, ownership opacity, nominee shareholders/directors.

Chapter IV of the AMLR refines the definition of Beneficial Owners and how to assess ownership and control. The ownership threshold is set at “25% or more of the shares or voting rights or other ownership interest” (and no more than 15% in case of high-risk for money laundering and terrorist financing: Art. 52(2)). Indirect ownership is calculated by multiplying holdings along each chain and aggregating them. Art. 53 lists other forms of control or influence such as majority voting rights. Specific rules are set for trusts, foundations and other legal arrangements (Arts. 55 et seq.).

Why Crime&tech Tools Are Built for This

Crime&tech tools provide ownership‑focused indicators and network analytics with intuitive visualisations of complex ownership and control structures. The indicators capture anomalous complexity (layers, jurisdictional spread, diversity of vehicles) and opacity (secrecy jurisdictions, opaque entities, BO data gaps) and our tools allow to reconstruct chains upstream and downstream with no thresholds. The indicators also flag ties to opaque corporate vehicles and legal arrangements (e.g. trusts, foundations, nominee structures), anomalous shareholding patterns and changes in ownership or board composition, to capture forms of control “by other means”. All this is supported by risk scores scientifically validated by Transcrime.

Transcrime research projects
TOM – The Ownership Monitor

Geographical and Sectoral Risk

The AMLR requires obliged entities to treat as higher risk those relationships involving high risk third countries (Annex III), jurisdictions with weak AML/CFT controls, high levels of corruption or criminality, sanctions or embargoes, supporting terrorism, or with financial secrecy, triggering EDD procedures. EBA’s Guidelines underline that risk assessment methodologies should be adjusted according to the sector in which an entity operates.

Why Crime&tech Tools Are Built for This

Crime&tech’s indicators quantify geographical and sectoral risk, combining country and municipality‑level metrics with flags for high‑risk sectors based on empirical research and regulatory references. This, across c. 400 million firms in 200+ jurisdictions, based on +20 data sources at a global level. These sources are customisable to each obliged entity’s perimeter and sector. Users can map cross‑border networks of firms and assets, spot hubs and clusters, and zoom down to address‑level information and street view.

Political Exposure and Negative Events

Political Exposure and Negative Events (sanctions listings, enforcement actions and reputational risks) are higher risk factors requiring EDD (Annex III). The AMLR (Art. 2(34)) expands the definition of Politically Exposed Persons (PEPs) to include heads of regional and local authorities and extends controls to a wider group of family members and close associates (Art. 46). These individuals are treated as higher risk customers requiring ongoing monitoring (Art. 42).

The EBA’s Draft RTS emphasise “obliged entities shall put in place automated screening tools and measure” to properly comply depending on size, business model, complexity or nature of the business (Art.19). The Guidelines underlines that the customer’s reputation may be assessed through “adverse media screening or similar means, information on criminal investigations, proceedings and convictions or any other relevant information”, provided that such information is accurate and reliable.

Why Crime&tech Tools Are Built for This

Crime&tech’s indicators ensure that political exposure links are captured across the full ownership and governance chain, not only at customer level. The platform integrates matching against adverse media, sanctions, enforcement actions, PEP lists and offshore leaks. For name screening, the solution combines fuzzy matching with AI‑powered open source screening and entity resolution, reducing false positives.

See below for the New AI Screening Module

Reporting and Ongoing Monitoring

AMLR’s Chapter V sets out strict reporting obligations, including short deadlines to respond to requests from competent authorities, which presuppose fast access to, and management of, structured and reliable customer and risk data. Also, The AMLR and EBA Guidelines make clear that risk assessment and CDD/EDD are not one off events. AMLR’s Art. 26 requires obliged entities to conduct ongoing monitoring and to review and update customer information whenever risk or circumstances change, with risk‑based maximum review intervals.

Why Crime&tech Tools Are Built for This

Crime&Tech’s tools generate customisable reports that break down risk by dimension, flag adverse media, and map ownership and control structures. By aggregating data from multiple heterogeneous sources, they cut through information overload and deliver clear assessments, backed by documented methodology that explains why a third party receives a given risk rating and which factors drove it. Risk Master also enables continuous monitoring, alerting users whenever a third party’s ownership changes, control shifts, or new risk events emerge.

Technologies & Ethical AI

The AMLR allows the use of automated and AI based systems to strengthen AML/CFT controls (Art. 76(5)), and EBA consistently promotes models where risk is “first assessed in an automated manner based on objective criteria and then manually adjusted based on professional judgement”. This, provided that data quality, explainability, and human oversight are ensured (e.g. Arts. 76 and 75(4)(g) AMLR). Supervisors increasingly expect organisations using advanced tools to be able to explain their methodology, evidence validation and justify outputs in a way that authorities and stakeholders can understand and challenge.

Crime&tech Risk Assessment Models

Crime&tech’s risk indicators are:

  • Grounded in pioneering research conducted within +300 international projects by Transcrime.
  • Developed using advanced machine learning techniques and scientifically validated in international publications (read more).
  • Institutionally tested and employed by European and national authorities (LEAs, FIUs, anti‑corruption and competition authorities) in real investigations.

Crime&tech AI Screening Module

Open source screening moving beyond traditional approaches:

  • Web Intelligence: Large-scale web crawling and open-source screening to detect links between legal entities, individuals, addresses and adverse information.
  • Entity Resolution: AI-assisted entity reconciliation combining matching criteria and contextual analysis to reduce ambiguity and homonymy.
  • Classification: Automated interpretation and categorisation of results by crime type, with a structured synthesis of the results.
  • Fully integrated into Crime&tech’s platforms or available via API for seamless integration into third-party systems.

Ethical AI and Data Protection

All modules comply with EU requirements:

  • White-box: risk scores are broken down into identifiable drivers, with documented logic and traceable underlying data. All outputs are explainable with access to sources
  • Human-centric: the analyst remains ultimately responsible for final evaluation
  • Data Protection Impact Assessments ensures compliance with GDPR principles (privacy by design and by default, data minimisation, non-discrimination, relevance, accountability).
  • Technical safeguards: anonymisation and pseudonymisation, role-based access controls, encryption at rest and in transit, audit logging.

To discover more on our tools

Receive Transcrime and Crime&tech's bi-monthly bulletin, with our latest research, news, and events.