Breadcrumb

  • Home
  • EU - EBA, AMLA and the death of KYC.

Search form

Main navigation

  • Home
WMLR Articles masthead

Front Page | All articles

EU - EBA, AMLA and the death of KYC.

Tue, 20/05/2025 - 09:12

The European Banking Authority says it wants a response to a consultation document about the EU's Anti Money Laundering Regulations. But does it, really, or have all the important decisions already been made?

WMLR Articles section banner

Take a look at the EBA's consultation document at https://www.eba.europa.eu/sites/default/files/2025-03/9bc83e61-e9a1-4e9…

It gives the game away by the frequent use of the term "mandate" - which arises because this marks a significant shift in the way that the business of crime is managed in the EU.

Hiding as it does behind financial sector regulation, the Anti Money Laundering Regulation is a centralised activity relating to criminal conduct. But it works around the question of criminal activity by imposing regulatory requirements not criminal obligations.

Breaches of the regulatory regime are unlawful i.e. civil, not illegal i.e. criminal.

It recognises that actions in breach of the regulatory regime imposed under the Regulation is unlawful and not illegal when it talks of " pecuniary sanctions, administrative measures and periodic penalty payments."

EU Regulations: a political weapon. 

To explain how we got here: the political position is that the EU has become a government without a country. It has the institutions of nationhood but it is not a nation. But those who control the EU aim towards a single jurisdiction, removing as far as possible, the rights of individual states which exist under the European federation.

In the dark days of the global financial crisis, EU officials and proponents saw an opportunity: what if they could create a centralised regime that bypassed the legislative process in member states and even bypassed local enforcement. The approach was simple: create a super-regulator and impose it; states could have their own regulators if they wish, but their decisions would always be subject to the EU.

The test case was to protect the financial sector/system against failure. No arguments were heard; there was little if any public dissent. The EU just did it. Box ticked.

But it is a long-established socialist tactic to call the name of organised crime and through that money laundering. The name is prayed in aid of demands for ever-stronger law and regulation and, equally, importantly, when someone powerful wants to divert attention from something. 

Constantly repeating a mantra about organised crime and taking the proceeds out of crime was a fundamental plank of the UK's Labour Party in the 1997 election. Once in power, it reorganised the regulatory regime (without any statutory authority to deviate from the existing regime) and it passed the devastatingly awful Proceeds of Crime Act 2002. 

This is the same tactic that the EU has adopted for many years: government by fear and force.

The EU needed another proof of concept so that Regulations could replace Directives. Work was being done on the 6th Money Laundering Directive. This directive had absolutely no purpose in relation to the very mature regulatory environment except, it has to be said, to undo some things and redo other better in a simpler, cheaper fashion. 

It didn't do that because that is not the EU's way: the EU lives by the motto "bigger, harder, stronger." And so it breezed across legal systems with all the subtlety of a division of Panzer tanks. 

In fact, the MLD6, essentially, wrote itself and its precursors out of history. We just haven't noticed yet.

And it created The Anti Money Laundering Authority (which has nothing to do with the prevention of money laundering (i.e. anti) and everything to do with ex post facto responses (i.e. counter). 

AMLA (as it has styled itself despite that acronym being used for many different purposes around the world, so sewing confusion from day one) is clear about its function: it's to force states to work to an EU interpretation of Regulations which the EU creates. . 

To be fair: under the Directives, national laws (which created the regulatory regimes) were inconsistent and often delayed. In addressing these issues, the EU has a strong point. Those who remember that France said "we don't need it because we've had denouncement laws since the Revolution" ( or words to that effect) and Italy who said, in effect, "sorry: we can't do it. We can't find regulators with big enough boobs" (it was in one of Berlusconi's periods in office when decision-making was on a somewhat ad hoc basis and often at grand parties in the North of Italy). Italy had still not implemented regulations under MLD1 when MLD2 was passed. 

And each member state drafted its own laws and regulations - as intended by the architects of the Directives system, to take account of local laws and customs. 

The centrists in Brussels couldn't have that; coming from a system where laws are codified regardless of how bad they are, they forced their position through, Britain escaped, France and Spain rebelled (but not very effectively) and Italy surrendered. Germany laughed and said "Come to Frankfurt, it's for your own good."

And so the Sixth Directive became the vehicle for the making of the regulatory body which no longer needs Directives with their pesky democratic underpinning. Now, only AMLA can ask the questions: everyone else must just do as they are told. 

Nigel Morris-Cotterill is at linkedin and at countermoneylaundering.com

And AMLA makes its position clear. If you are going to operate in the EU, in relation to money laundering compliance you will operate under AMLA's controls, regardless of where your company is headquartered or, for that matter, regulated for other purposes.

AMLA's website says "The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) is a decentralised EU agency that will coordinate national authorities to ensure the correct and consistent application of EU rules.  

The aim of the EU Authority is to transform the anti-money laundering and countering the financing of terrorism (AML/CFT) supervision in the EU and enhance cooperation among financial intelligence units (FIUs). "

The EBA simplifies that, saying " The intention is to minimise divergence across sectors and Member States to the extent that this is possible."

The EBA also makes something else clear: the EU's not done with its centralisation - it will  "highlight which aspects of the draft RTSs
could also be relevant for the non-financial sector."

It is also clear that the big decisions have been made :

"The EBA’s work on the call for advice is guided by five principles:
• A proportionate, risk-based approach;
• A focus on effective, workable outcomes;
• Technological neutrality;
• Maximum harmonisation across supervisors, Member States and sectors;
• Limiting disruption by building on existing EBA standards where possible, whilst aligning with global AML/CFT benchmarks.

Also, the voices it has taken soundings from are only those who already agree:

"In addition, the EBA engaged with the following stakeholders:

a. The EBA’s Banking Stakeholder Group.
9. The private sector during a roundtable that took place on 24 October 2024 with 120 representatives that had been nominated by EU financial sector trade associations from all EU/EEA Member States. In parallel, seven supervisors hosted similar roundtables at a national level.
b. The FIU Platform.
c. The European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB)"

So, the "consultation" is more by way of a "confirmation", it seems to me, and a confirmation that will only be accepted if it adopts the approved buzzwords and phrases.

Worse, the EBA has fallen into the trap that financial crime risk assessment is a data-processing task.

"The draft RTS introduces a single set of data points that all supervisors would be required to use to establish the aforementioned indicators. An interpretive note will accompany the final version of the draft RTS to ensure that these data points are understood in the same manner in all Member States and by all obliged entities. AMLA would not specify how supervisors collect these data points, because the relevant sources of information may vary from one Member State to another. For instance, in some cases, supervisors may be able to collect part of the information from their prudential counterparts or from the local FIU, while in other cases, they will need to collect all the data from the obliged entities. Supervisors will be free to identify and use all the relevant sources of information they have at their disposal. Lastly, supervisors will still have the option to collect additional information for other purposes, not directly related to the risk assessment methodology, such as conducting offsite
supervision."

Translation: "we will insist on a standardised data collection system which can be fed into a centrally defined algorithm. It might start as fish and chips, paella or pizza but it will all come out the same at the other end. " The question we are not allowed to ask is this: who designs, builds, manages this system and is it the same big data companies and consultants which have a long history of cost over-runs and systems that fail at great expense to the public purse?

The death of KYC

The entire system is designed to kill KYC during the course of dealings.

"When designing the scoring methodology, the EBA tried to favour the use of objective data over subjective assessment to the extent that it was possible. To fulfil this objective, the methodology does not leave any room for self-assessment by obliged entity and instead, relies on objective indicators. In addition, even though some adjustments are possible based on expert judgement, these adjustments need to be duly justified and are subject to certain rules and limits, to ensure that they do not introduce an element of discretion."
 

That "objective data over subjective assessment" bit means "transaction data is a first national team's number 9 while real world Know Your Customer" i.e. the foundation of suspicion based reporting, is relegated bringing on the half-time oranges for a village club team. 

The perpetuation of uncertainty

All those giving effect to totalitarian regimes and revolutions understand that one of the most important tools in forcing compliance is to perpetuate uncertainty. The objective is to make populations expect but fear change and to keep them busy making changes so they don't dissent.

And that's the EU/AMLA/EBA's plan. It says, clearly, 

"Because risks vary and evolve, risk indicators and weights would not be included in the draft RTS. Instead, it would be the role of AMLA, in cooperation with national supervisors, to define the risk indicators and weights for each review cycle and to monitor the effective application of these indicators by supervisors in all Member States.


The draft RTS adjusts the frequency of entity-level risk assessments based on the nature and size of financial institutions. Under this approach, to have an up-to-date understanding of the risks to which obliged entities under their supervision are exposed and in line with most national supervisors’ current practice, supervisors would review the inherent and residual risk profile of obliged entities once per year unless an institution is very small or carries out activities that do not justify a yearly review. In those cases, a review could take place once every three years instead. However, supervisors would be expected to review an entity’s risk profiles and if necessary, obtain risk assessment data more frequently should risks crystallise or new information emerge that suggest that the ML/TF risk profiles may no longer be accurate.

Oh, and those formal - by definition tick-lists - that make sure that financial institutions do as they are told and only as they are told will be used to create "n an automated scoring system" which, if a strong enough argument can be made, could include "a possibility to adjust the scores based on duly justified considerations."

The whole system as it is discussed so far in this paper is to create a bureaucracy: it is not in any way to aid and assist in the detection and prevention of financial crime. 

The document is 91 pages long. We are on page 6. It repeats, over and over again, phrases similar to "ensure that supervisors’ entity-level ML/TF risk assessment methodologies are consistent across Member States."  Read it if you want to know what is being done in your name. 

At last: something for Britons to rejoice over (if Starmer at al don't slip in decisions to surrender the City's independence to Frankfurt, which is what all the socialists want). 

Quis custodiet ipsos custodes?

The answer is simple: The Eurocracy and national regulators might be on boot scrubbing duty, not even important enough to carry the oranges. 

 

Footer menu

  • Weekly Digest (opens in new tab)
  • Images attribution (opens in new tab)
  • Corporate, privacy, intellectual property and access (opens in new tab)
  • Advertising and Recommendations (opens in new tab)
  • Promote your business (opens in new tab)
  • Enquiries (opens in new tab)


 

BOT AND SCRAPER ACCESS DENIED

 


 

Built with Drupal     |     Hosted by Siteground     |     Template by Alaa Haddad     

Design by Vortex Centrum Limited    |     Some services provided by Google Workspace    

Posters and other merch by ProjectLXX   |   Privacy and security services by Surfshark and Firetrust. 


Nothing in this website is intended to be or shall be taken as legal advice. 

You should always seek advice from a practitioner experienced in this area. 


Everything on this website is copyright Nigel Morris-Cotterill and/or Vortex Centrum Limited for itself or one of its business units. No downloading, printing or other means of replicating or reusing is permitted. In particular, all bot access is denied and all scraping of content will result in the legal action set forth in the terms and conditions in this site. For legal, cookies and privacy see vortexcentrum.com.

Copyright 1999- © 2026 Vortex Centrum Limited - All rights reserved. Bot access denied.