July 10, 2026 is a date to mark in the calendar for anyone working in anti-money laundering. It is the deadline by which AMLA, the new European Authority for Countering Money Laundering and the Financing of Terrorism based in Frankfurt, must submit a broad package of technical standards and guidelines to the European Commission. These are the so-called Level 2 and Level 3 measures: the piece that turns the principles of the new Anti-Money Laundering Regulation (AMLR) into concrete, operational rules for obliged entities.
Levels 1, 2 and 3: what they mean
EU financial legislation follows a multi-level architecture. Level 1 is the basic legislation adopted by Parliament and Council: in the case of anti-money laundering, the AMLR Regulation and the Sixth Directive (AMLD6). Level 2 consists of regulatory and implementing technical standards (RTS and ITS), delegated acts that set out the obligations in technical, binding detail. Level 3 covers the guidelines and recommendations that guide the practical application of the rules. Together, these levels make up the anti-money laundering Single Rulebook, the set of harmonized rules that applies to all obliged entities in the Union.
AMLA Level 2: what is due by July 10, 2026
The AMLA Level 2 mandate is demanding: the Authority must draft and submit to the Commission a significant number of RTS, ITS and guidelines, most of them due by July 10, 2026. During the first part of 2026, AMLA ran a series of public consultations on the drafts of these standards, gathering input from the financial and non-financial sectors before finalizing the texts.
The priority workstreams include in particular:
- Customer due diligence (CDD): what information to collect, which identification sources and methods to consider reliable, how to document checks.
- Risk factors: the criteria that determine when to apply simplified or enhanced due diligence, consistent with the risk-based approach.
- Internal controls and governance: minimum requirements for the policies, procedures and compliance function of obliged entities.
- Groups and third countries: group-wide measures and additional obligations for subsidiaries and branches established outside the EU.
Note a point that is often misunderstood: July 10, 2026 is the deadline by which AMLA must deliver the drafts to the Commission, not the date on which the rules become applicable. After submission, the Commission adopts them as delegated or implementing acts. The AMLR, the Level 1 Regulation, applies instead from July 10, 2027: that is the horizon by which obliged entities will need to be fully compliant.
What changes for your company
Even if 2027 may seem far off, the technical details emerging now already define how processes and systems will need to be configured. Here are the concrete steps to take:
- Monitor the final texts of the RTS on customer due diligence and risk factors, to understand where internal procedures need updating.
- Review the risk model in light of the new criteria for simplified and enhanced due diligence.
- Check the quality of KYC data and the traceability of controls, in view of stricter documentation and record-keeping requirements.
- Prepare the audit trail: AMLA supervision will favor explainable, documented processes.
How AegisX helps you
Adapting to an evolving regulatory framework requires flexible tools that make customer due diligence and monitoring faster and more reliable. Monitus, the AegisX AML screening and monitoring solution, applies a risk-based approach, reducing false positives and keeping a clear, explainable audit trail: exactly what AMLA supervision will require. For an overview of the new European framework, you can also read our article on what changes with AMLA and AMLR.
Want to find out how to prepare your processes and systems for the 2027 deadline? Contact the AegisX team for a dedicated assessment: we turn compliance into a strategic advantage.
This article is for informational purposes only and does not constitute legal or compliance advice.





