Anti - Financial Crime

The EBF supports an effective, proportionate and risk-based approach to preventing and detecting money laundering and terrorist financing, and advocates for clear requirements that appropriately reflect the role, capabilities and responsibilities of banks, while promoting effective cooperation among the different actors involved in the fight against financial crime. 

Why anti-financial crime matters to banks

Banks play a pivotal role in the European Union’s fight against money laundering and terrorist financing. As gatekeepers to the financial system, banks are the first line of defence against financial crime, identifying, mitigating, and reporting risks that threaten financial integrity and citizens’ safety. 

AML competent authorities extensively rely on banks in their fight against financial crime through a series of due diligence, transactions monitoring, detecting and reporting requirements. In addition, banks perform financial sanctions screening. 

European banks are critical allies to public authorities in the collective effort to combat financial crime. They dedicate vast resources – both human and technological – to protecting citizens and society from the threats posed by organised crime, terrorism, and illicit finance. As gatekeepers of the financial system, banks are the first line of defence in safeguarding the integrity of the financial system. By addressing money laundering risks, banks contribute directly to the stability and resilience of the financial sector. 

However, criminal networks are constantly innovating. To stay ahead, banks continue to invest in advanced technologies, analytics, and expertise. But their efforts alone are not enough. To fully unlock the potential of these investments, banks need an enabling environment – one that recognises the banking sector as an integral part of the solution, that supports intelligence-led approaches, and that fosters innovation.

Image
law

(ANTI-)MONEY LAUNDERING

Money laundering is the process of:

  • introducing into the financial system illicit funds and the proceeds of crimes, 

  • disguising, obscuring and concealing the criminal origin of these funds through a series of mechanisms and transactions, and 

  • reintroducing the funds into the legitimate economy to make them usable.

Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) refers to the framework of laws, regulations, procedures, and controls designed to prevent, detect, and report money laundering and related financial crimes, such as terrorist financing.

Image
Valdis Dombrovskis
A credible framework for preventing and fighting money laundering and terrorist financing is essential to maintain the integrity of the European financial system and reduce risks to financial stability.
Valdis Dombrovskis
Former Executive Vice-President of the European Commission; Commissioner (2024-2029) Economy and Productivity, Implementation and Simplification
Image
Wim Mijs
The banking sector sees itself as being at the forefront of the fight against financial crime. It understands that to be effective this fight cannot remain solely in the hands of the public authorities or solely in the hands of the industry
Wim Mijs
EBF CEO
Image
Valdis Dombrovskis
While Europe has some of the world’s toughest rules against money laundering, we need to strengthen supervision and enforcement, including across borders.
Valdis Dombrovskis
Former Executive Vice-President of the European Commission, Commissioner (2024-2029) Economy and Productivity, Implementation and Simplification
Image
Wim Mijs
For the EU AML Authority (AMLA) to effectively contribute to the fight against financial crime, it must make information exchange easier and help detect patterns and cross-border criminal activities. It is important to stress that this objective cannot be achieved by simply introducing another layer of ex-post reporting.
Wim Mijs
EBF CEO
Image
Simonas Krėpšta
We [AMLA] are designing the digital ecosystem to support AMLA’s mission. Technology must empower supervision, collaboration, and secure data exchange across Europe.
Simonas Krėpšta
AMLA Executive Board Member
Image
Rikke-Louise Petersen
Our [AMLA’s] workstreams are defining building blocks for a unified, data-driven and resilient AML framework in Europe's fight against financial crime.
Rikke-Louise Petersen
AMLA Executive Board Member

THE AML COMMUNITY 

The AML community is a global network of professionals, institutions, and authorities engaged in the prevention, detection, investigation, and prosecution of money laundering and related financial crimes. It encompasses both private-sector and public-sector stakeholders.

  • On the public-sector side, the AML community includes standard-setters and lawmakers, and competent authorities responsible for overseeing and enforcing AML requirements, such as financial intelligence units (FIUs), regulatory and supervisory authorities, law enforcement agencies and prosecutors.

  • On the private-sector side, it includes regulated or obliged entities that are subject to AML compliance obligations, such as financial institutions, payment service providers, insurers, investment firms, and other designated non-financial businesses and professions.

Together, these stakeholders form an interconnected ecosystem, working collaboratively to safeguard the integrity of the financial system, prevent its misuse for criminal purposes, and combat illicit financial activity.

As the voice of European banks, the EBF is committed to being at the forefront of the fight against financial crime and to playing a leading and constructive role within the AML Community. By fostering cooperation, facilitating the exchange of expertise, and contributing to effective policy and regulatory frameworks, the EBF seeks to strengthen the collective capacity of the AML Community to address evolving financial crime risks.

Image
agreement

The Financial Action Taskforce (FATF)

The FATF is an intergovernmental organisation that sets global AML/CFT standards, evaluates countries' compliance with those standards, and promotes international cooperation to protect the integrity of the global financial system.

The EBF engages with the FATF’s standard-setting work, bringing the European banking sector’s expertise into the development and review of global AML/CFT standards and guidance, notably through consultations and dialogue with the FATF.

Risk-Based Approach and Risk Assessments

The Risk based approach (RBA)

The Risk based approach (RBA) is a key FATF principle  and an essential enabler for efficient and effective anti-financial crime programmes. Understanding money laundering and terrorist financing risks is an essential aspect of formulating and implementing effective AML/CFT regimes and compliance programmes. The RBA enables countries and financial operators to prioritise resources where most necessary and allocate them efficiently, improving effectiveness and ultimately safeguarding citizens from financial crime risks. According to the RBA countries, competent authorities, and financial institutions are expected to identify, assess, and understand the financial crime risks to which they are exposed. Consequently, these actors can take proportionate action in response, corresponding with the relative level of risks that have been identified. 

The EBF believes that the RBA needs to be fully applied in practice. Through more effective use of data and more efficient reporting, banks would ideally be able to analyse patterns of criminal activities, identifying where financial crime undermines the system. Expanding the use of innovative technologies and advanced tools would allow banks to stay ahead of emerging threats and strengthen their capacity to detect, prevent, and respond to financial crime in real time. The EBF therefore recommends:

  • Continued facilitation and strengthening of a RBA to supervision and compliance, in particular when applying customer due diligence measures and reporting suspicious activities.

  • Continued simplification and standardisation of the AML regulatory environment by ensuring uniform interpretation at national level. Limit Member States’ discretionary powers to instances where national specificities genuinely require differentiation, ensuring greater EU-wide consistency.

  • Increase the ability to leverage new technologies and tools, ensuring that innovation supports the sector’s capacity to detect and prevent financial crime. Facilitate data privacy-conscious information sharing opportunities, including the removal of legal barriers to shared utilities, while respecting GDPR principles.

Risk Assessment

Business-Wide Risk Assessment is undertaken by obliged entities to identify key external and internal risks they faced, testing the controls in place to mitigate these risks and strengthening their overall compliance frameworks. The aim is to determine a measure of the total exposure of an obliged entity, allowing the identification of appropriate mitigation strategies by highlighting key risk areas. 

National Risk Assessment (NRA): A systematic assessment of a country’s money laundering and terrorist financing risks, used to inform national AML/CFT priorities, policies, supervision, and risk-based mitigation measures, as well as obliged entities’ business-wide risk assessments.

EU-wide risk assessment: A systematic assessment by the European Commission of money laundering and terrorist financing risks affecting the EU internal market and cross-border activities, taking into account the opinion of the EU Anti-Money Laundering Authority (AMLA). It informs EU and national AML/CFT priorities and risk-mitigation measures, as well as Member States’ national risk assessments and obliged entities’ business-wide risk assessments.

THE EU AML FRAMEWORK

The EU Anti-Money Laundering (AML) framework is built around a single set of rules applicable across the EU and aligned with FATF standards. The current framework comprises four key legislative instruments:

AMLD6

The Sixth Anti-Money Laundering Directive, which sets out rules on the organisation of national AML/CFT systems. It covers, in particular, the tasks and powers of national supervisors and Financial Intelligence Units (FIUs), cooperation between competent authorities, and access to central beneficial ownership and bank account registers.

AMLR

The Anti-Money Laundering Regulation, which establishes directly applicable AML/CFT rules across the EU, creating a harmonised framework of obligations for the the obliged entities of the private sector. It covers, in particular, customer due diligence, beneficial ownership transparency, reporting obligations and restrictions on large cash payments.

FTR

The revised Funds Transfer Regulation, which extends the “travel rule” to transfers of crypto-assets, enhancing their traceability by imposing information requirements on crypto-asset service providers alongside the existing requirements for transfers of funds, in line with FATF standards (FATF Recommendation 16).

AMLAR

The AMLA Regulation, which establishes the EU Anti-Money Laundering Authority (AMLA) and sets out its mandate, tasks, powers and governance framework.

From the outset, the EBF has been actively engaged in the fundamental reform of the EU’s AML framework undertaken through the EU AML Package. In March 2020, it published its AML Blueprint, identifying key challenges and proposing solutions to strengthen the effectiveness of the EU AML framework. Since then, the EBF has engaged closely with the EU Institutions throughout the legislative process and, with the establishment of AMLA, has continued this dialogue to support the effective implementation of the new framework.

The EBF considers that fragmentation remains an important concern where EU rules are interpreted or applied differently across Member States. A truly harmonised EU regulatory framework, including greater consistency in the interaction between AML/CFT and data protection rules, would provide banks with the legal clarity and operational environment needed to further enhance the effectiveness of the fight against financial crime.
 

THE EU AML AUTHORITY (AMLA)

The Anti-Money Laundering Authority (AMLA) is a decentralised EU agency established to strengthen and harmonise the EU’s anti-money laundering and countering the financing of terrorism (AML/CFT) framework. AMLA coordinates national supervisory authorities to promote the consistent application of EU rules and enhances cooperation among Financial Intelligence Units (FIUs). Its main responsibilities include directly supervising selected high-risk, cross-border financial sector entities, supporting and coordinating FIUs, and developing regulatory and implementing technical standards and guidelines to complement the EU AML/CFT framework.

The establishment of AMLA represents a pivotal opportunity to strengthen coordination in the EU’s fight against financial crime. The EBF believes that this coordination should extend across the entire AML/CFT community, bringing together public authorities and private-sector actors. Building on its mandate to support and coordinate FIUs, AMLA has the potential to develop into a genuine Financial Intelligence Coordination Centre, fostering a more integrated approach to financial intelligence and contributing, together with relevant stakeholders, to a robust EU-wide understanding of financial crime risks.
Public-private cooperation should be an important part of this approach. The EBF supports a strong role for AMLA in fostering public-private partnerships and cross-border cooperation, including through initiatives such as the Europol Financial Intelligence Public Private Partnership (EFIPPP). Strengthening these channels will enable authorities and obliged entities to share expertise, identify emerging risks and improve the collective effectiveness of the EU’s response to financial crime.

The establishment of AMLA also marks an important step towards more consistent, effective and risk-based supervision across the EU. The EBF supports structured engagement between AMLA and the community of supervised entities through an inclusive forum for identifying challenges, sharing best practices and discussing supervisory approaches. Such dialogue would allow AMLA to communicate its expectations and processes clearly, while enabling the banking sector to contribute practical expertise and experience from the implementation of AML/CFT requirements.

The EBF is committed to developing a professional and pragmatic relationship with AMLA, grounded in open dialogue and consultation. It stands ready to facilitate regular, strategic engagement between AMLA and senior AML leaders from the European banking sector, helping to ensure that industry expertise contributes to the effective implementation of the new EU AML/CFT framework.
 

OBLIGED ENTITIES’ COMPLIANCE REQUIREMENTS

Obliged entities, including banks, are at the forefront of the fight against money laundering and terrorist financing. Under the EU AML/CFT framework, they are required to identify, assess and mitigate the risks to which they are exposed and to detect and report suspicious activity.

Their core AML/CFT compliance requirements notably include:

  • Internal policies, procedures and controls, including at group level where applicable;

  • Business-wide risk assessments to identify and assess money laundering and terrorist financing risks;

  • Customer due diligence (CDD/KYC), including the identification and verification of customers and beneficial owners and, where appropriate, enhanced due diligence;

  • Ongoing monitoring, including the scrutiny of transactions and customer relationships;

  • Reporting of suspicious transactions or activities to the relevant Financial Intelligence Unit (FIU).

These obligations form the foundation of banks’ AML/CFT compliance frameworks and enable them to play a central role in detecting and preventing the misuse of the financial system for criminal purposes.

The EBF contributes to the development and implementation of the technical standards and guidance underpinning these requirements, bringing the practical expertise of the European banking sector into the regulatory process. It advocates for rules that are clear, simple, risk-based and proportionate, providing banks with the necessary legal certainty and operational flexibility to focus resources where risks are greatest. Through its engagement with AMLA, the EU Institutions and other relevant authorities, the EBF supports a regulatory framework that is both effective in fighting financial crime and workable in practice.

Key EBF positions on this topic:

CUSTOMER DUE DILIGENCE

Customer Due Diligence (CDD) is a cornerstone of the AML/CFT framework. Its overarching objective is to ensure that obliged entities have sufficient knowledge of their customers to understand who they are dealing with, assess the money laundering and terrorist financing risks associated with a business relationship or occasional transaction, and apply appropriate risk-mitigating measures.

CDD requires obliged entities to identify and verify the identity of their customers, whether natural or legal persons, and to understand the purpose and intended nature of the business relationship. It also extends to beneficial owners (UBOs), the natural persons who ultimately own or control a legal entity or legal arrangement, such as a trust. Obliged entities must therefore identify beneficial owners and take reasonable measures to verify their identity, looking through legal entities and arrangements where necessary to determine the natural persons who ultimately exercise ownership or control. Under the EU framework, a 25% ownership interest generally serves as a threshold for identifying ownership-based beneficial interests, while control must also be assessed through other means.

CDD follows a risk-based approach, meaning that the nature and extent of the measures applied should reflect the level of risk identified. Enhanced Due Diligence (EDD) involves additional measures where higher risks are present, including in relation to politically exposed persons (PEPs) and certain relationships or transactions involving high-risk third countries.

CDD is not a one-off exercise. Ongoing monitoring requires obliged entities to scrutinise business relationships and transactions and to keep customer information and risk profiles up to date, allowing controls and mitigating measures to be adapted as risks evolve.

For the EBF, effective CDD must be driven by risk and focused on outcomes. Clear, proportionate and risk-based requirements are essential to ensuring that CDD delivers effective risk mitigation rather than a predominantly procedural compliance exercise.

TRANSACTION MONITORING AND SUSPICIOUS ACTIVITY REPORTING

Transaction monitoring is a key component of ongoing customer due diligence. It enables obliged entities to identify unusual transactions, behaviours and patterns throughout the business relationship, assess them against the customer’s profile and associated risks, and investigate activity that may give rise to suspicion.

Where an obliged entity knows, suspects or has reasonable grounds to suspect that funds or activities are linked to criminal activity or terrorist financing, suspicious transaction or activity reporting (STR/SAR) provides the mechanism for communicating that financial intelligence to the relevant Financial Intelligence Unit (FIU). 

Over time, increasingly complex compliance requirements and defensive approaches to reporting have contributed to growing volumes of alerts and reports, many of which may provide limited intelligence value. This can absorb significant resources across both obliged entities and public authorities and make it more difficult to focus attention on the transactions, behaviours and networks that present the greatest risks. 

The EBF supports a shift towards more intelligence-led, risk-based and outcomes-focused detection and reporting. Banks should be able to make greater use of advanced technologies and innovative analytical techniques to identify patterns, connections and emerging threats that traditional approaches may not detect. This is increasingly important as financial crime evolves alongside new technologies, forms of communication and methods of transferring value.

Technology alone, however, is not sufficient. Effective detection requires closer cooperation between obliged entities, FIUs, law enforcement and supervisors, supported by appropriate information-sharing frameworks and meaningful feedback. Stronger public-private cooperation can improve the quality of financial intelligence, enhance the detection of criminal networks, reduce unnecessary impacts on legitimate customers and enable both public and private resources to be directed towards the areas of greatest risk.

For the EBF, the effectiveness of the reporting system should be measured by the quality and operational value of the intelligence it generates - not by the volume of reports submitted.
 

INFORMATION SHARING

Effective financial crime prevention requires seamless information sharing and close cooperation between the public and private sectors. Connecting relevant information can be critical to identifying suspicious patterns, networks and emerging threats.

The EBF strongly supports the development and expansion of Public-Private Partnerships (PPPs) that enable banks, Financial Intelligence Units (FIUs), law enforcement and other competent authorities to share relevant information and expertise, contributing directly to the detection and prevention of financial crime.

Article 75 of the AML Regulation provides an important legal framework for information sharing within partnerships. The EBF supports its effective implementation as part of a broader EU-wide approach to information sharing, underpinned by close cooperation between AML/CFT and data protection authorities and clear rules governing the use and exchange of information.

The EBF is also actively engaged in the Europol Financial Intelligence Public Private Partnership (EFIPPP), which has demonstrated the value of structured cooperation between public authorities and the financial sector. The next step should be to build on this experience and strengthen the operational dimension of such partnerships, enabling them to generate actionable intelligence and tangible outcomes in the fight against financial crime.

For the EBF, financial crime cannot be effectively tackled in information silos. Europe should build on initiatives such as EFIPPP to create a trusted information-sharing environment in which relevant intelligence can be connected across institutions and borders, while fully respecting fundamental rights and data protection safeguards.
 

PAYMENT TRANSPARENCY

Payment transparency is essential to ensuring that transfers of funds can be traced and that relevant information is available to detect and investigate financial crime. FATF Recommendation 16 sets the global standard for the information that should accompany payments (so-called “travel rule”) and was revised in 2025 to respond to the evolving payments landscape and further strengthen the transparency of cross-border payments.

In the EU, these principles are reflected in the Funds Transfer Regulation (FTR), which establishes requirements for information accompanying transfers of funds and extends these requirements to transfers of certain crypto-assets.

The EBF supports clear, proportionate and internationally aligned payment transparency requirements that strengthen the fight against financial crime while enabling efficient and innovative payment services, together with the principle of principle of “Same Activity, Same Risk, Same Rule” to be implemented in both regulation and supervision.

Key EBF positions on this topic:

FINANCIAL SANCTIONS

Sanctions and restrictive measures are important foreign policy and security tools used by governments and international organisations to respond to threats to international peace and security and to influence the behaviour of targeted individuals, entities or jurisdictions. They may be imposed by international organisations, such as the United Nations, or by individual jurisdictions, including the European Union, the United States and the United Kingdom. .

Within the European Union, restrictive measures form an important part of the Common Foreign and Security Policy (CFSP) and can be used to respond to international crises and security threats. They cover a wide range of measures, including asset freezes, restrictions on admission or travel, arms embargoes, and restrictions on trade, financial activities and other economic sectors. 
Since February 2022, the most prominent developments in the field are the sanctions packages adopted by the EU against Russia and Belarus following Russia’s military aggression against Ukraine.

The scope of restrictive measures has evolved over time, shifting from being mostly comprehensive – i.e. prohibiting any form of business dealing by a state – to being more targeted in nature. Restrictive measures are now often calibrated to affect those who are the targets of sanctions due to their unwanted behaviour, rather than all civilians of a sanctioned state. Designated persons and entities are generally identified through sanctions lists published by the relevant authorities. Compliance with applicable sanctions is a legal obligation, with non-compliance potentially resulting in enforcement action and penalties.

The increasing use and complexity of targeted sanctions have created significant legal and operational challenges for businesses implementing them. Financial institutions may need to navigate multiple and evolving sanctions regimes, exemptions and derogations, licensing provisions and differences between jurisdictions. This requires them to continuously adapt their policies, procedures, systems and controls to ensure compliance with applicable requirements.

As providers of payment and financial services, banks play a central role in the implementation of sanctions and restrictive measures. They apply due diligence, screening and other controls to identify designated persons and entities and to determine whether transactions or financial services are subject to applicable restrictions. Where required under the relevant legal framework, banks must apply asset freezes and other applicable restrictive measures and prevent or restrict prohibited transactions or the provision of funds, financial services or economic resources to designated persons and entities.
For the EBF, effective sanctions implementation requires clear, consistent and workable rules, supported by timely and sufficiently detailed guidance. Sufficient legal certainty is essential for banks to apply rapidly evolving requirements effectively, while taking into account the operational realities of complex and cross-border financial activities.
 

International stakeholders - useful links

The European Commission’s Directorate-General for Financial Stability, Financial Services and Capital Markets Union (DG FISMA) is responsible for developing and implementing EU policies on financial services, including the EU framework for anti-money laundering and countering the financing of terrorism (AML/CFT). It contributes to shaping EU legislation and policy in this area, supports the effective implementation of the AML/CFT framework across Member States, and works with EU and international partners to strengthen the integrity and resilience of the EU financial system.

Visit the DG FISMA website

The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) is a decentralised EU agency established to strengthen and harmonise the EU’s anti-money laundering and countering the financing of terrorism (AML/CFT) framework. AMLA coordinates national supervisory authorities to ensure the consistent application of EU rules and enhances cooperation among Financial Intelligence Units (FIUs). Its responsibilities include directly supervising selected high-risk, cross-border financial sector entities, supporting and coordinating FIUs, and developing regulatory and implementing technical standards and guidelines to complement the EU AML/CFT framework.

Visit the AMLA website

The European Banking Authority (EBA) is an independent EU Authority founded in 2011, in the aftermath of the Great Financial Crisis. Their main tasks are to establish consistent rules for EU banks, ensure a level playing field, and safeguard consumers of financial services. Our overarching objective is to contribute to financial stability in the EU.  From 1 January 2026, responsibility for all EU level anti money laundering and counter terrorist financing (AML/CFT) tasks has moved from the European Banking Authority (EBA) to the new Anti Money Laundering Authority (AMLA). Although the EBA no longer manages the AML/CFT rulebook, Article 54 of the AMLA Regulation ensures that all existing EBA AML/CFT guidelines and standards remain valid until AMLA replaces them. The EBA continues to contribute to safeguarding the EU financial system from money laundering and terrorist financing risks through its prudential supervisory work, including by:

  • assessing ML/TF risks during authorisations and fit-and-proper assessments;
  • overseeing ongoing supervision across the banking, payments, and crypto asset sectors;
  • promoting consistent supervisory approaches across the EU.

Visit the EBA website

Headquartered in The Hague, the Netherlands, Europol’s mission is to support its Member States in preventing and combating all forms of serious international and organised crime, cybercrime and terrorism. Europol also works with many non-EU partner states and international organisations. The European Financial and Economic Crime Centre (EFECC) at Europol enhances Europol’s operational and strategic support by preventing and combating financial and economic crime in the European Union. EFECC promotes the consistent use of financial investigations and asset forfeiture while forging alliances with public and private entities. EFECC runs the Europol Financial Intelligence Public Private Partnership project (EFIPPP). Created in 2017, EFIPPP tests and increases the possibilities for cross-border cooperation and information exchange between Europol, competent authorities (including Financial Intelligence Units and Law Enforcement Agencies) and regulated financial service entities such as banks. It is the first transnational information sharing mechanism ever established in the field of Anti-Money Laundering and Counter-Terrorist Financing. 

Visit the Europol website

The Financial Action Task Force (FATF) leads global action to tackle money laundering, terrorist and proliferation financing.  The FATF researches how money is laundered and terrorism is funded, promotes global standards to mitigate the risks, and assesses whether countries are taking effective action. The FATF plays a central role in setting global standards for combating money laundering, terrorist financing and the financing of proliferation. FATF Recommendations, ensure a co-ordinated global response to prevent organised crime, corruption and terrorism. They help authorities go after the money of criminals dealing in illegal drugs, human trafficking and other crimes.  The FATF also works to stop funding for weapons of mass destruction. 

Visit the FATF website

EBF members

Questions about this topic?
We are happy to help.

Image
Roger Kaiser

Roger Kaiser

Head of Anti-Financial Crime and Tax Matters

Image
Giulia Verde

Giulia Verde

Policy Advisor/Executive Coordinator, Anti-Financial Crime and Tax Matters

Image
Anna Maria Nowak

Anna Maria Nowak

Policy Advisor - Anti-Financial Crime and Tax Matters

Image
Jairo

Jairo Ferreira

Intern - Anti-Financial Crime and Tax Matters, Sustainable Finance