Back to all articles
SCALESUCCESSCOMPLIANCE

AML/KYC Blueprint 2026: From Risk Assessment to Onboarding and Ongoing Monitoring (EU AMLR & 6AMLD)

·
29 min
AML/KYC Blueprint 2026: From Risk Assessment to Onboarding and Ongoing Monitoring (EU AMLR & 6AMLD)

Author: Nexora Team, NEXORA Unternehmensberatung GmbH Published: January 2026 | Reading time: 16 minutes

This blueprint provides FinTechs, crypto providers, and payments with a complete end-to-end process for AML/KYC under EU AMLR & 6AMLD: Risk Assessment Templates, Onboarding Decision Trees, Monitoring Playbook, and Governance Roles. Includes practical checklists and a download kit.

The 7 most important points:

Risk Assessment every 12 months (Enterprise + Customer/Product/Channel) → Risk Appetite Statement | KPI Target: 100% Documentation Coverage

Onboarding: eKYC + UBO + Source of Funds → Decision Matrix (Auto Approve/EDD/Reject) | Target: under 10 minutes for Low Risk

Monitoring: Behavioral + Transaction Rules → Alert Lifecycle (Triage → Investigate → Report → SAR) | Target: 95% Closure under 48 hours

Screening: Sanctions/PEP/Adverse Media real-time + batch → Hit Rates under 0.5% target | False Positives under 80%

Governance: MLRO + 1st/2nd Line + IT → Board KPI Dashboard | Target: Quarterly Review 100%

KYC Refresh: Low Risk 24 months | High Risk 12 months | PEP 6 months (exemplary cycles based on RBA)

SAR Filing: FIU without undue delay (Practice: ideally on the same day, at the latest within a few working days in accordance with FMA guidelines)

Important note on the application of this blueprint

All thresholds, risk scores, SLAs, and processes mentioned in this blueprint are examples and serve to illustrate a risk-based approach in accordance with AMLR (EU) 2024/1624 and 6AMLD (EU) 2024/1640.

Each institution must:

  • Develop its own methodology based on the company-wide risk assessment
  • Adjust thresholds to its own business model
  • Consider national requirements (e.g. FM-GwG in Austria, GwG in Germany)
  • Document and regularly review the risk-based approach
For corporate groups, the requirements for group-wide risk assessment and group-wide policies according to AMLR Art. 8-9 also apply.

Target: What does "professional AML/KYC" mean?

Professional AML/KYC means an automated, risk-based process with the following flow:

Customer → Risk Score → CDD/EDD → Ongoing Monitoring → Alerts → SARs → FIU

Screening (PEP/Sanctions) and Transaction Monitoring run in parallel, triggering alerts in the event of Behavioral Changes.

The result: A 100% comprehensible audit trail, board-ready KPI, and scalability from 10,000 to 1 million customers.

Blueprint overview: The three main steps

The AML/KYC process consists of three main steps:

STEP 1: RISK ASSESSMENT

  • Enterprise Risk Assessment (annual, AMLR-compliant)
  • Product/Channel/Customer Risk Assessment
  • Group-wide Risk Assessment (for corporate groups)
  • Output: Risk Appetite Statement + Risk Matrix
STEP 2: ONBOARDING / CDD / eKYC
  • 6-step process: Pre-Fill → ID Check → UBO → Purpose → Screening → Decision
  • Decision Matrix: Auto-Approve / CDD / EDD / Reject based on Risk Score
  • Output: Customer File (Immutable Audit Trail)
STEP 3: ONGOING MONITORING
  • Transaction Monitoring Rules (8 examples)
  • Alert Lifecycle: Generation → Triage → Investigation → MLRO → SAR → Closure
  • Screening Stack: Real-Time + Daily Batch + Weekly Deep
  • Output: Alerts → SARs → Board KPI Dashboard
All three steps lead to the MLRO + Reporting, which reports quarterly to the Board and takes over the FIU liaison.

Step 1: Risk Assessment

Frequency and Outputs

How often:

  • Enterprise Risk Assessment: annually (Q4) in accordance with AMLR Art. 8
  • Product/Channel Risk Assessment: at launch or significant change
  • Group-wide Risk Assessment: annually (for groups in accordance with AMLR Art. 9)
  • Ad-hoc Review: in the event of regulatory changes or significant incidents
What will be created:
  • Risk Appetite Statement (Board-approved)
  • Methodology Document (EBA-Guidelines-compliant)
  • Risk Matrix (3×3 or 4×4, institution-specific)
  • Risk Register (Living Document)
  • Group-wide Policies (if applicable)
Risk Matrix: 3×3 Example

IMPORTANT: This matrix is exemplary. Each institution must develop its own matrix based on its business model and company-wide risk assessment.

The risk matrix assesses four criteria:

CRITERION 1: JURISDICTION (40% weighting - example)

  • Low (Score 1): EU Tier 1 (Austria, Germany, Netherlands, France)
  • Medium (Score 2): EU Tier 2, Eastern EU (Poland, Czech Republic, Hungary)
  • High (Score 3): High-Risk 3rd Countries according to FATF lists and EU Delegated Regulation
CRITERION 2: PRODUCT (30% weighting - example)
  • Low (Score 1): SEPA Payments under EUR 15,000
  • Medium (Score 2): FX Trading, Lending over EUR 15,000
  • High (Score 3): Crypto, Cash over EUR 50,000
CRITERION 3: CHANNEL (20% weighting - example)
  • Low (Score 1): App/Website (Authenticated, strong KYC)
  • Medium (Score 2): Agent Network (Semi-Authenticated)
  • High (Score 3): P2P, ATM (higher anonymity risk)
CRITERION 4: CUSTOMER TYPE (10% weighting - example)
  • Low (Score 1): Retail (KYC, Low Velocity)
  • Medium (Score 2): SME, Freelance (Mid Velocity)
  • High (Score 3): HNWI, PEP, Complex Structures
Risk Score Formula

IMPORTANT NOTE: This formula is exemplary and serves to illustrate a risk-based approach. Each institution must develop its own methodology, which is empirically validated (e.g. by historical SAR rate per segment) and corresponds to the company-wide risk assessment in accordance with AMLR.

Exemplary formula:

  • Risk Score (0-100) = (0.40 × Jurisdiction Score × 33.33) + (0.30 × Product Score × 33.33) + (0.20 × Channel Score × 33.33) + (0.10 × Customer Type × 33.33)
  • Where: Score 1 = 0 points | Score 2 = 50 points | Score 3 = 100 points
Example calculation: A customer from Poland (Score 2) + Crypto (Score 3) + Website (Score 1) + Retail (Score 1) results in: (0.40 × 50) + (0.30 × 100) + (0.20 × 0) + (0.10 × 0) = 20 + 30 + 0 + 0 = 50 points (MEDIUM)

The weightings must be justified and documented by your own risk analysis.

RISK APPETITE STATEMENT 2026 – EXAMPLE

1. STRATEGIC GOALS

  • Growth: +30% customers per year (SEPA + Crypto)
  • Compliance: 0 material FMA Findings
  • Efficiency: Alert Closure under 48h in 95% of cases
2. RISK TOLERANCE
  • Alert Closure SLA: 95% under 48h | 100% under 5 days (internal target)
  • False Positive Rate: under 80% (Target: 75%)
  • EDD-Trigger: Risk Score over 70/100 (exemplary threshold)
  • Auto-Reject: Score over 90/100 in combination with confirmed Sanctions hit or serious risk factors
  • SAR Filing: Without undue delay in accordance with FM-GwG (internal SLA: on the same day, at the latest within a few working days)
3. REVIEW & GOVERNANCE
  • Quarterly MLRO Report (Board)
  • Annual Enterprise Risk Assessment (AMLR Art. 8)
  • Group-wide Risk Assessment (if applicable, AMLR Art. 9)
  • Monthly Alert KPI Review (Compliance Committee)
  • Ad-hoc in the event of High-Impact Events (over EUR 500,000 SAR)
  • Independent AML audits in high-risk constellations
4. ESCALATION THRESHOLDS
  • EUR 50,000+ Transaction → 2nd Line Review
  • PEP/Sanctions Hit → MLRO Immediate
  • Crypto over EUR 100,000/day → EDD + Source of Wealth
  • High-Risk 3rd Country → Auto-EDD (no automatic Auto-Approve)
Approved: MLRO | CFO | CEO | Date: 2026-01-01 Review: Q4 2026

Data sources for Risk Assessment

  • FATF Public Statements (High-Risk & Non-Cooperative Jurisdictions)
  • EU High-Risk 3rd Countries (Delegated Regulation in accordance with AMLR)
  • EBA Guidelines on ML/TF Risk Factors (EBA/GL/2021/02)
  • OECD Financial Action Task Force (Mutual Evaluation Reports)
  • National Supervisory Guidelines (FMA Austria, BaFin Germany)
  • Internal Data: SAR History, Alert Volume, False Positive Rates
Step 2: Onboarding / CDD / eKYC

The 6-step onboarding process

STEP 1: PRE-FILL

  • Name, date of birth, nationality (API or Manual)
  • Output: Customer Profile (Draft)
STEP 2: ID CHECK (eKYC)
  • Document Scan (Passport or eID)
  • Liveness Detection (Selfie)
  • OCR + Validation (MRZ)
  • Tools (Examples, no recommendation): Jumio, Onfido, Sumsub, IDnow
  • Note: When using external eKYC providers, DPA, SLA, audit rights, and vendor due diligence are required in accordance with AMLR outsourcing requirements
  • Output: ID Verified ✓ or Failed ✗
STEP 3: UBO IDENTIFICATION (Legal Entities)
  • Company Register Extract (API, access to central BO registers in accordance with AMLR)
  • Over 25% Ownership Chain (AMLR threshold)
  • UBO Declaration (Self-Certification)
  • Output: UBO List + Percent Ownership
STEP 4: PURPOSE & SOURCE OF FUNDS
  • Questionnaire: Purpose of Business Relationship
  • Expected Activity (Volume, Frequency)
  • Source of Funds (Salary/Business/Inheritance)
  • Output: Purpose Statement + SoF Evidence (for EDD)
STEP 5: SCREENING (PEP / SANCTIONS / ADVERSE MEDIA)
  • Real-Time API (Examples: WorldCheck, Dow Jones, Refinitiv – no vendor recommendation; selection according to RFP process with vendor due diligence in accordance with AMLR/GDPR requirements)
  • Fuzzy Match (Name + Date of Birth + Nationality)
  • Hit Review (False Positive Elimination)
  • Output: Clear ✓ or Hit → Manual Review
STEP 6: DECISION (AUTO / EDD / REJECT)
  • Risk Score Calculation
  • Decision Matrix Application
  • MLRO Escalation (if Score over 70 - exemplary threshold)
  • Output: Account Activated | EDD Initiated | Rejected
Decision Matrix: The five risk levels

IMPORTANT NOTE: All thresholds, scores, and SLAs in this decision matrix are exemplary and must be adapted to your own business model, company-wide risk assessment, and national requirements (e.g. FM-GwG in Austria).

RISK SCORE 0-29: AUTO-APPROVE (Example)

  • Documents: eID (Passport/National ID) + Proof of Address (optional) + Screening Clear
  • SLA: under 10 minutes
  • Action: 1st Line Info only (no review necessary)
  • KYC Refresh: 24 months (exemplary cycle based on RBA; AMLR requires risk-based and event-driven refresh, no fixed legal cycles)
RISK SCORE 30-49: STANDARD CDD (Example)
  • Documents: eID + Proof of Address + Source of Funds (Statement) + Purpose of Account + Screening Clear
  • SLA: under 24 hours
  • Action: 1st Line Review (Plausibility Check)
  • KYC Refresh: 12-24 months
RISK SCORE 50-69: ENHANCED CDD (Example)
  • Documents: All CDD documents + Source of Funds (Evidence) + Expected Activity (Detail) + UBO (if Legal Entity)
  • SLA: under 48 hours
  • Action: 2nd Line Review
  • KYC Refresh: 12 months
RISK SCORE 70-89: EDD (ENHANCED DUE DILIGENCE) (Example)
  • Documents: All Enhanced CDD documents + Source of Wealth (Tax Return, Bank Statements over 6 months) + UBO Verification (Legal Register Extract) + Adverse Media Research + Site Visit (optional for High-Risk Business)
  • SLA: under 5 working days (internal SLA)
  • Action: MLRO Approval required
  • KYC Refresh: 6 months (PEP) or 12 months
RISK SCORE 90-100: AUTO-REJECT (Only in combination with serious factors)
  • Trigger: Confirmed Sanctions hit (no False Positive) OR High-Risk 3rd Country without possible Mitigation OR Internal Blacklist Entry OR several serious risk factors
  • Important: PEP in itself triggers EDD, but no general ban or Auto-Reject according to FATF standards
  • Action: Blacklist Entry (after MLRO-Review) + MLRO Notification + SAR Filing (in case of reasonable suspicion)
  • Next: No Appeal (except Sanctions False Positive after Re-Review)
When EDD? The 10 Trigger Criteria

According to AMLR and FATF-Recommendations, EDD is required for:

  • PEP status (Politically Exposed Persons - mandatory EDD, but no automatic business ban)
  • High-Risk 3rd Country according to FATF lists and EU Delegated Regulation
  • Crypto/High-Value (Example: Single transaction over EUR 50,000 or daily limit over EUR 100,000)
  • UBO over 25% unclear (Complex Ownership Structures)
  • Adverse Media Hits (Financial Crime, Corruption, Terrorism)
  • Cash-Intensive Business (Example: Taxi, Gastronomy, Exchange Offices over EUR 10,000/month)
  • Geo-Hopping (3+ countries within 30 days - exemplary threshold)
  • Inconsistent Profile (Low Income + High Transactions)
  • Previous SAR Filed (Historical Red Flag)
  • Complex Corporate Structure (over 3 Layers, Offshore SPVs)
You must adapt the specific thresholds to your risk assessment.

Customer File: What is documented?

Each customer receives an immutable audit trail with the following 10 components in accordance with AMLR documentation obligations:

  • Application Form (Timestamp, IP, User Agent)
  • ID Document Scan (Front, Back, MRZ Data)
  • Liveness Check (Video/Selfie + AI Score)
  • Screening Results (API Response + Manual Review)
  • Risk Score Calculation (Formula + Inputs)
  • Decision Log (Auto/EDD/Reject + Rationale)
  • UBO Declaration (if applicable, access to central BO registers)
  • Source of Funds/Wealth (Evidence, if EDD)
  • MLRO Approval (if Score over 70)
  • KYC Refresh Date (based on Risk-based approach)
Retention period: At least 5 years after termination of the business relationship (AMLR/FM-GwG)

Step 3: Ongoing Monitoring

The three monitoring categories

CATEGORY 1: EVENT-DRIVEN

  • KYC Refresh (risk-based cycles in accordance with AMLR)
  • Behavioral Change (e.g. Velocity +300% MoM)
  • Geo-Change (Login from High-Risk Country)
  • Customer Request (Account Upgrade)
  • Adverse Media Alert (Batch Screening)
CATEGORY 2: TIME-DRIVEN
  • Quarterly Risk Score Review (all customers)
  • Monthly PEP Re-Screening (PEP-Flagged)
  • Annual Enterprise Risk Assessment (AMLR Art. 8)
CATEGORY 3: TRANSACTION-DRIVEN
  • Threshold Breach (Example: over EUR 15,000 SEPA, over EUR 1,000 Crypto in accordance with EU Funds Transfer Regulation/TFR)
  • Rule-Based Alert (Velocity, Structuring)
  • Suspicious Pattern (ML Model Score over 0.8)
  • Sanction Screening Hit (Real-Time)
Transaction Monitoring: 8 concrete Rules (Examples)

IMPORTANT: These rules are exemplary. Thresholds must be adapted to your business model and risk assessment.

TM-01: VELOCITY CHECK

  • Logic: over 10 transactions per 24h OR over EUR 50,000 per 24h
  • Alert Action: L1 Review under 4h
TM-02: GEO-HOPPING
  • Logic: 3+ countries within 7 days (excl. EU Tier 1)
  • Alert Action: EDD + Source of Funds
TM-03: STRUCTURING (SMURFING)
  • Logic: 9× between EUR 9,000-9,900 within 24h (under EUR 10,000 Limit)
  • Alert Action: SAR Preparation
TM-04: CRYPTO FIAT RAMP
  • Logic: over EUR 10,000 per day (Crypto → Fiat)
  • Alert Action: Source of Funds Required
  • Note: Travel Rule for over EUR 1,000 in accordance with AMLR Art. 45-46 for CASPs, EU Funds Transfer Regulation (TFR), IVMS101 format
TM-05: ROUND-TRIPPING
  • Logic: In/Out same amount within 48h
  • Alert Action: L2 Investigation
TM-06: HIGH-RISK COUNTRY EXPOSURE
  • Logic: Transaction FROM/TO FATF Blacklist/Greylist
  • Alert Action: Enhanced Review
TM-07: DORMANT ACCOUNT ACTIVATION
  • Logic: 0 Activity for over 180 days THEN Transaction over EUR 5,000
  • Alert Action: Low Priority + Profile Check
TM-08: INCONSISTENT PROFILE
  • Logic: Income EUR 2,000/Month BUT Spending over EUR 20,000/Month
  • Alert Action: MLRO Escalation
Alert Lifecycle: The 6 Steps in Detail

STEP 1: ALERT GENERATION

  • Source: Transaction Rule | Behavioral Model | Screening Hit
  • Priority: High (MLRO under 1h) | Medium (under 4h) | Low (under 24h)
  • Assignment: Auto-Route to 1st Line Queue
STEP 2: TRIAGE (1st Line)
  • SLA: under 4 hours (internal target: 95%)
  • Action: Review Transaction History (30 days)
  • Decision: FALSE POSITIVE → Close | POSSIBLE TRUE POSITIVE → Escalate to 2nd Line | UNCLEAR → Request Additional Info
  • Output: Triage Decision + Notes
STEP 3: INVESTIGATION (2nd Line)
  • SLA: under 24 hours (internal target: 90%)
  • Action: Deep-Dive Transaction Analysis (90 days), Customer Interview (if necessary), External Data (OSINT, Adverse Media), Pattern Analysis
  • Decision: FALSE POSITIVE → Close | TRUE POSITIVE (No SAR) → Enhanced Monitoring | TRUE POSITIVE (SAR) → Escalate to MLRO
  • Output: Investigation Report (2-5 pages)
STEP 4: MLRO REVIEW
  • SLA: under 48 hours (internal target: 100%)
  • Action: Review Investigation Report + Supporting Evidence
  • Decision: NO SAR → Close + Enhanced Monitoring | SAR REQUIRED → Draft SAR | ACCOUNT ACTION → Freeze/Close + SAR
  • Output: MLRO Decision + SAR Trigger
STEP 5: SAR FILING (FIU)
  • Legal Obligation: Without undue delay (cf. FM-GwG §41, GwG §43) – "without undue delay" means immediate notification from the time of knowledge
  • Internal SLA (based on FMA practice): Ideally on the same day, at the latest within a few working days in accordance with FMA guidelines
  • Important: The actual implementation depends on the circumstances of the individual case; the internal SLA serves to control the process, but does not replace the legal obligation to act immediately
  • Content: Customer Profile, Suspicious Activity Description, Transaction Details, Investigation Summary, Supporting Documents
  • Submission: FIU Portal (Encrypted)
  • Tipping-Off Prohibition: § 41 FM-GwG - No information to customers about SAR-Filing (criminal offense if violated)
  • Output: SAR Reference Number + Acknowledgement
STEP 6: CLOSURE & DOCUMENTATION
  • Action: Update Customer Risk Score, Tag Account (Enhanced Monitoring / Closed / SAR Filed), Archive Alert File (Immutable), Update KPI Dashboard
  • Output: Closed Alert + Audit Trail (minimum 5 years retention after termination of the business relationship in accordance with AMLR/FM-GwG)
Screening Stack: The 3-Tier Approach

TIER 1: REAL-TIME SCREENING (under 100ms)

  • Trigger: Onboarding | Login | Transaction over EUR 15,000 (exemplary threshold)
  • Data Sources: UN Consolidated Sanctions List, EU Sanctions List, OFAC SDN List, National PEP Lists, Internal Blacklist
  • Tools (Examples, no recommendation): WorldCheck, Dow Jones, ComplyAdvantage
  • Vendor Due Diligence: When using external screening providers, DPA, SLA, audit rights, review of sub-processors and regular performance assessment are required in accordance with AMLR outsourcing requirements
  • Match Logic: Fuzzy (Levenshtein Distance under 2) + Date of Birth ±2 years
  • Output: CLEAR ✓ or HIT → Manual Review Queue
  • KPI Target: under 100ms Response Time | Hit Rate under 0.5%
TIER 2: DAILY BATCH SCREENING
  • Trigger: Daily 02:00 CET (all active customers)
  • Data Sources: Tier 1 Sources (Updated Lists), Adverse Media, Expanded PEP (RCA = Relatives & Close Associates), Negative News, Court Records
  • Match Logic: Fuzzy + Contextual (Industry, Location)
  • Output: New Hits → 1st Line Review Queue (under 24h SLA)
  • KPI Target: 100% Customer Base Daily | under 1% New Hit Rate
TIER 3: WEEKLY DEEP SCREENING (High-Risk Cohort)
  • Trigger: Weekly (PEP, High-Risk Score over 70, EDD Customers)
  • Data Sources: UBO Network Analysis (Access to central BO registers), Complex Structure Detection, Cross-Border Linkage, Deep Web OSINT, Industry Watchlists
  • Match Logic: Manual Investigation + OSINT Tools
  • Output: Enhanced Profile + Risk Score Update
  • KPI Target: 100% High-Risk Cohort Weekly | under 5% Escalation Rate
TARGET METRICS:
  • Overall Hit Rate: under 0.5% (Tier 1) | under 1% (Tier 2) | under 5% (Tier 3)
  • False Positive Rate: under 80% (internal target: 75%)
  • Time to Resolution: under 24h (Tier 1+2) | under 5 days (Tier 3)
  • Data Freshness: under 24h (Daily Updates from Vendors)
Governance & Role Model

The six main roles:

MLRO (MONEY LAUNDERING REPORTING OFFICER) – 2nd Line

  • SAR-Filing Ownership (FIU Liaison without undue delay)
  • Alert Escalation Review (High-Priority under 1h)
  • Risk Appetite Statement Owner
  • Quarterly Board KPI Reporting
  • FMA Contact Person (Regulatory Inquiries)
  • Independent of 1st Line (Operational)
  • Reporting directly to Board/CEO (no intermediate level)
1ST LINE (CUSTOMER OPERATIONS)
  • Onboarding Execution (Low Risk Auto-Approve)
  • Alert Triage (under 4h SLA, False Positive Elimination)
  • Customer Communication (Document Requests)
  • KYC Refresh Initiation (Time-Driven + Event-Driven)
2ND LINE (COMPLIANCE & RISK)
  • Alert Investigation (Deep Dive, under 24h SLA)
  • EDD Review & Approval (Risk Score over 70 - exemplary)
  • Monitoring Rule Optimization (False Positive Reduction)
  • Policy Development Support
  • Vendor Performance Monitoring (for Outsourcing)
IT & SECURITY
  • Tool Integration (Screening, Case Management, eKYC)
  • Audit Trail Architecture (Immutable Logs)
  • Data Security (Encryption, Access Control, GDPR-Compliance)
  • Performance Monitoring (API Latency, Uptime)
  • Outsourcing Technical Management (SLA-Monitoring)
COMPLIANCE OFFICER (POLICY OWNER)
  • AML/KYC Policy Ownership (Annual Review)
  • Training Delivery (Staff + Management)
  • Regulatory Change Monitoring (AMLR Updates, FMA/BaFin Guidance)
  • Internal Audit Coordination
  • Group-wide Policy Coordination (for Corporate Groups)
BOARD / CEO
  • Risk Appetite Approval (Annual)
  • Quarterly KPI Review (Dashboard)
  • Resource Allocation (Budget, Headcount)
  • Regulatory Relationship (FMA/BaFin Liaison)
  • Group-wide Oversight (for Corporate Groups)
  • Approval of significant outsourcing arrangements
Group-Wide Governance (for Corporate Groups)

According to AMLR Art. 9, additional requirements apply to corporate groups:

1. GROUP-WIDE RISK ASSESSMENT

  • Consolidated risk assessment across all group entities
  • Consideration of cross-border risks
  • Central documentation and reporting
2. GROUP-WIDE POLICIES & PROCEDURES
  • Uniform AML/KYC policies for all group companies
  • Adaptation to local regulatory requirements (higher standard applies)
  • Central policy governance with local adaptation rights
3. CENTRALIZED OVERSIGHT
  • Group MLRO or Group Compliance Officer
  • Central reporting to Group Board
  • Coordination of SAR-Filing across entities
  • Information Sharing within the group (observing Data Protection)
4. GROUP-WIDE CONTROLS
  • Uniform Monitoring Rules and Screening Standards
  • Central Watchlist Management
  • Consolidated KPI Dashboard
  • Group-wide Training & Awareness Programme
5. AUDIT & REVIEW
  • Independent AML audits at Group-Level
  • Coordination of local audits
  • Escalation mechanisms in case of violations
Documentation: Group-wide AML/KYC Framework (Living Document, annual review)

Outsourcing & Reliance

When using external service providers (eKYC, Screening, Case Management), the following requirements must be observed in accordance with AMLR:

1. VENDOR DUE DILIGENCE

  • Technical Evaluation (Proof-of-Concept)
  • Financial Stability (Annual Financial Statements, Ratings)
  • Compliance Posture (ISO 27001, SOC 2, GDPR-Certifications)
  • References and Track Record
2. CONTRACT DESIGN
  • Data Processing Agreement (DPA) according to GDPR Art. 28
  • Service Level Agreement (SLA) with clear Performance Metrics
  • Audit Rights (annual audit right on-site or remote)
  • Exit Clauses and Data Migration Plan
  • Liability Regulations in case of Data Loss or Compliance Violations
3. SUB-PROCESSORS
  • Full Disclosure of all Sub-Processors
  • Review of Sub-Processor Locations (EU vs. Third Country)
  • Contractual Commitment of Sub-Processors to the same Standards
4. DATA LOCALIZATION
  • EU-Hosting for KYC-Data (GDPR-compliant)
  • Clarification of Data Residency Requirements (e.g. FM-GwG)
  • Backup Locations within EU
5. PERFORMANCE MONITORING
  • Regular Review of the False Positive Rate (Screening)
  • API Uptime and Response Time (eKYC under 100ms)
  • Quarterly Business Reviews with Vendor
  • Escalation Process in case of Performance Problems
6. REGULATORY OVERSIGHT
  • Vendor must enable supervisory audits by FMA/BaFin
  • Vendor must provide documentation and logs on request
  • Incident Reporting Obligation (Data Breaches, System Failures)
Documentation: Vendor Due Diligence File (per Vendor), Vendor Register (central)

RACI Matrix – Distribution of Roles and Responsibilities

The RACI matrix is a proven governance tool for the clear assignment of responsibilities in regulatorily sensitive processes (e.g. AML, Compliance, Risk Management, Outsourcing).

Meaning of the Roles (Legend):

  • R – Responsible (Responsible for Implementation)
The role that takes over the operational implementation of the task.
  • A – Accountable (Overall Responsibility)
Bears the final decision-making and results responsibility. Ideally, only one accountable role should be defined per process.
  • C – Consulted (Involved)
Is consulted professionally and provides input before decisions.
  • I – Informed (Informed)
Is informed about results or decisions without actively intervening.
Process / ActivityMLRO1st Line2nd LineITComplianceBoard
Annual Risk AssessmentACRCRI
Group-wide Risk AssessmentGroup MLRO: ALocal MLROs: RGroup Compliance: RGroup Board: I
Onboarding Approval (Low Risk < 30)A (Escalation)RCII
EDD Approval (High Risk > 70)AICIRI
Alert Triage (SLA < 4h)IRA (Escalation)I
SAR Filing (without undue delay)A / RICCI
Vendor Selection (Outsourcing)CICRAA (Approval)
Quarterly KPI Review (Board Reporting)RCCCCA

Interpretation from a Governance and Compliance Perspective:

  • MLRO (Money Laundering Reporting Officer)
Bears the core professional responsibility for risk-relevant processes, especially in SAR reports, EDD cases and escalations.
  • 1st Line of Defense
Responsible for operational implementation (onboarding, alert processing, customer data maintenance).
  • 2nd Line of Defense / Compliance Function
Controls processes, defines methodologies and assumes independent quality assurance.
  • IT Function
Responsible for technical implementation, monitoring systems and outsourcing implementation.
  • Board / Management
Assumes governance responsibility, approvals for critical decisions and strategic KPI monitoring.

Regulatory Added Value of the RACI Structure

A clearly defined RACI matrix supports:

  • clear supervisory audits (FMA, BaFin, ECB)
  • Proof of functional separation (Segregation of Duties)
  • Fulfillment of requirements from AMLD, MiCA, DORA and ISO 37301 Compliance Management Systems
  • Reduction of operational risks and liability risks for management and MLRO
6AMLD & Criminal Liability

The 6th EU Money Laundering Directive (6AMLD, 2024/1640) significantly expands criminal liability:

1. EXPANDED UNDERSTANDING OF MONEY LAUNDERING

  • 22 predicate offenses (instead of previously variable national lists)
  • Including Tax Crimes
  • Self-Laundering (perpetrator launders own proceeds) is punishable
  • Aiding and Abetting and Attempt are punishable
2. LIABILITY OF LEGAL ENTITIES
  • Companies can be prosecuted
  • Sanctions: Fines, Business Bans, License Revocation
  • Requirement: Act was committed by a manager OR lack of supervision enabled the act
3. PERSONAL LIABILITY OF EXECUTIVES
  • Management Liability in case of intentional or grossly negligent breach of duty
  • Directors & Officers can be personally prosecuted
  • Relevant Positions: Board, CEO, CFO, MLRO, Compliance Officer
4. MINIMUM PENALTIES
  • At least 4 years imprisonment for serious money laundering
  • In aggravating circumstances (organized crime): up to 8 years
  • Fines: up to 10% of worldwide annual turnover or EUR 5 million
5. TIPPING-OFF & OBSTRUCTION
  • Warning the customer about SAR-Filing: Criminal Offense (§ 41 FM-GwG)
  • Obstruction of Investigations: Criminal Offense
  • Destruction of Evidence: Criminal Offense
6. PROTECTION THROUGH COMPLIANCE
  • Well-documented CDD/EDD Processes
  • Traceable Risk Assessments
  • Timely SAR-Filing (without undue delay)
  • Complete Audit Trails
  • Regular Employee Training
  • Independent AML Audits
These measures are the best protection against personal and corporate liability.

KPI Dashboard – The 10 Most Important AML and Compliance Metrics

Note: The following KPIs serve as best-practice examples for internal control. The specific design depends on the business model, risk profile, product scope and regulatory status of the institution.

Operational KPI Overview

KPICurrentPrevious PeriodTarget ValueStatus
Alert Volume (Monthly Average)1.2471.113< 1,500
Alert Closure Rate (SLA < 48h)96 %94 %≥ 95%
False Positive Rate82 %85 %< 80% (optimal: 75%)
SARs Filed (FIU Reports)1714Trend Monitoring
SAR Filing Timeliness100 %100 %Legally: 100%
EDD Coverage (% Customer Base)14 %13 %10–15%
Average Risk Score42 / 10041 / 100< 50
KYC Refresh On-Time98 %96 %> 95%
Screening Hit Rate0,43 %0,48 %< 0.5%
Onboarding Reject Rate2,1 %1,9 %< 3%

Regulatory Classification of Selected KPIs

SAR Filing Timeliness:

  • Legal Obligation: immediate notification without undue delay
  • Best Practice according to Supervisory Practice (e.g. FMA):
→ Ideally on the same working day, at the latest within a few working days
  • KPI Target: 100% Compliance without exception
KYC Refresh Cycles:
  • Typical Intervals (Example):
  • Low Risk: 24 months
  • Medium Risk: 12 Months
  • High Risk: 6 Months
  • AMLR requires: risk-based approach, no rigid deadline logic.
Trend Analysis – Management Summary:
  • Alert Volume: +12% MoM
→ Rule Review recommended (e.g. TM-01, TM-02)
  • False Positives: 82%
→ Target 75% → Rule Optimization planned (Q2 2026)
  • SARs Filed: +3 compared to previous quarter
→ Within the expected range (~0.3% of the alert base)
  • EDD Coverage stable at 14%
→ High-risk cohort is adequately monitored

Management Action Items

  • Reduce False Positive Rate
→ Velocity Rule TM-01: Threshold test +20%
  • Continue to monitor Alert Volume
→ Capacity planning: Evaluate +1 FTE in Q2
  • Ensure SAR Timeliness
→ Current process shows stable performance

Common Errors: The 15 Biggest Risks

1. Risk Appetite Missing → Arbitrary decisions, no governance, AMLR violation

2. Manual Screening → Does not scale, high false positive rate, inefficient

3. No UBO Data → FIU-SAR rejection, incomplete due diligence, AMLR violation

4. Event-Driven Monitoring Missing → Sleeping Risks (Behavioral Changes undetected)

5. Alert Backlog over 7 Days → FMA criticism, compliance risk, potential sanctions

6. No Audit Trail → Untraceable, audit findings guaranteed, AMLR violation

7. PEP Name-Screening Only → Incomplete (RCA = Relatives & Close Associates missing), FATF non-compliance

8. Source of Funds Ignored → High-Risk Customers accepted without plausibility, ML risk

9. Staff Training Missing → Liability (employees do not recognize SAR-worthy cases), 6AMLD risk

10. No Escalation Processes → MLRO Blindspot (alerts get stuck in 1st line), SAR delay

11. KPI Only Internal → Board not informed, no strategic control, governance gap

12. False Positive over 90% → Inefficiency, high operational costs, staff burnout, missed true positives

13. Crypto without Travel Rule → TFR non-compliance (VASP-to-VASP Transfers over EUR 1,000)

14. Onboarding SLA over 5 Days → Customer Churn, Competitive Disadvantage

15. No Vendor Due Diligence for Outsourcing → AMLR violation, GDPR risk, potential data breaches

"What to do next?" – The 3-Stage Rollout

STAGE 1: BLUEPRINT ASSESSMENT (1 week)

  • Day 1-2: Download Kit Review (Checklist, Templates)
  • Day 3-4: Gap Analysis (Actual vs. AMLR/6AMLD/FM-GwG)
  • Day 5: Prioritization (Quick Wins vs. Long-Term)
  • Output: Gap Report + Prioritized Backlog
STAGE 2: PILOT (4 weeks)
  • Week 1: Scope Definition (1 Product, e.g., SEPA Payments)
  • Week 2: Process Design (Onboarding Flow + Decision Matrix)
  • Week 3: Tool Selection with Vendor Due Diligence (eKYC, Screening, Case Management)
  • Week 4: Full Process Test (10 Onboardings + 5 Alerts)
  • Output: Pilot Report + Lessons Learned + Go/No-Go Decision
STAGE 3: ENTERPRISE ROLLOUT (12 weeks)
  • Week 1-4: Tool Integration (API, Webhooks, Audit Logs) + Outsourcing Agreements
  • Week 5-8: Process Automation (Rules, Workflows, Thresholds)
  • Week 9-10: Staff Training (1st Line, 2nd Line, MLRO) incl. 6AMLD Liability
  • Week 11: Soft Launch (20% Customer Base)
  • Week 12: Full Rollout + KPI Dashboard Go-Live
  • Output: Production-Ready System + Board KPI Report + Group-wide Rollout (if applicable)
FAQ: 12 Frequently Asked Questions

Q1: When do I have to implement AMLR? A: Directly applicable from 2027-07-10. No transposition necessary (EU regulation).

IMPORTANT: Preparation in 2026 is strongly recommended!

  • Q1 2026: Gap Assessment (2 weeks)
  • Q2-Q3 2026: Tool Selection + Process Design (8-12 weeks)
  • Q4 2026: Pilot + Staff Training (4-8 weeks)
  • Q1 2027: Full Rollout + FMA Readiness
Risk of starting later: Implementation pressure, higher consulting costs (vendor capacities fully booked), potential go-live delays, FMA scrutiny for non-compliance from 2027-07-10.

Q2: Which tools are mandatory? A: No specific tools are prescribed. AMLR and MiCA do not require vendor selection. Tool selection is risk-based based on the business model and risk profile.

Examples (no recommendation):

  • eKYC: e.g., Jumio, Onfido, Sumsub, IDnow
  • Screening: e.g., WorldCheck (Refinitiv), Dow Jones Risk & Compliance, ComplyAdvantage
  • Case Management: e.g., Actimize (NICE), SAS AML, FICO
⚠️ Important: Vendor Selection should go through a structured RFP process with Proof-of-Concept, Cost-Benefit Analysis and Vendor Due Diligence. Review of: DPA (GDPR Art. 28), SLA, Audit Rights, Sub-Processors, Data Localization (EU-Hosting), Performance Metrics. NEXORA supports neutral tool selection (no vendor kickbacks).

Q3: How often KYC Refresh? A: Exemplary cycles based on RBA and market standard:

  • Low Risk: 24 months
  • Medium-High Risk: 12 months
  • PEP: 6 months
Important: AMLR requires a risk-based and event-driven refresh, no fixed legal cycles. Event-Driven additionally for Behavioral Changes (e.g., Velocity +300%, Geo-Change, Transaction Volume Spike).

You must define and document the specific cycles based on your company-wide risk assessment.

Q4: SAR Deadline FIU? A: Legal obligation: Without undue delay (cf. FM-GwG §41, GwG §43). "Without undue delay" means immediate reporting from the time of knowledge by MLRO.

FMA practice (indicative): Ideally on the same day, at the latest within a few working days according to FMA guidelines.

Internal SLA: 5 working days from MLRO decision can serve as an internal control benchmark, but does not replace the legal immediate obligation.

Target: 100% Compliance with legal reporting deadline.

Q5: Who is MLRO? A: Designated Person according to AMLR requirements:

  • Independent of 1st Line (Customer Operations)
  • Board access and direct reporting line to CEO/Board
  • FIU-Liaison
  • No dual role with operational business activities
  • Adequate resources and powers
  • Reporting not to COO/CFO, but directly to the Board
Q6: Cloud OK for KYC data? A: Yes, if the following conditions are met:
  • EU-Hosting (GDPR Art. 44-50) or adequate level of protection in third country
  • Data Processing Agreement (DPA) according to GDPR Art. 28
  • Audit rights contractually secured (on-site or remote)
  • Sub-Processors fully declared and verified
  • Backup & Disaster Recovery documented and tested
  • Exit strategy and data migration plan available
  • FM-GwG/GwG Data Residency Requirements observed
Q7: Crypto-specific? A: Travel Rule (TFR) for transfers over EUR 1,000 (VASP-to-VASP) according to AMLR Art. 45-46 for CASPs and EU Money Transfer Regulation (TFR). IVMS101 format for Originator/Beneficiary Data.

Additionally:

  • Wallet Screening (Mixing Services, High-Risk Exchanges, Tornado Cash)
  • MiCA Compliance from 2024-12-30
  • Enhanced Monitoring for Crypto-Ramps (Example: over EUR 10,000/day → Source of Funds)
  • EDD for High-Value Crypto (Example: over EUR 50,000 single transaction)
Q8: Costs Pilot? A: 2 weeks Gap Assessment (Fixed Scope: EUR 4,950 plus VAT) includes:
  • Actual analysis against AMLR/6AMLD/FM-GwG
  • Identification of compliance gaps
  • Prioritized Roadmap with Quick Wins
Pilot 4 weeks (Time & Material or Fixed: EUR 12,500-18,000 plus VAT, depending on scope) includes:
  • Process Design for 1 product line
  • Tool Evaluation and Vendor Due Diligence
  • Full Process Test (10 Onboardings + 5 Alerts)
  • Go/No-Go Recommendation
Q9: False Positive Rate realistic? A: 75-85% is the industry standard for Transaction Monitoring.
  • Below 75% = excellent (requires ML models + continuous rule-tuning)
  • Over 90% = inefficient (rule optimization urgently needed, high costs, staff burnout)
False positives are unavoidable (balance between catch rate and efficiency), but can be reduced through continuous optimization.

Q10: Can KYC Refresh be automated? A: Yes, largely automatable:

  • Time-Driven Trigger (24M/12M/6M - exemplary cycles)
  • Automatic e-mail with update link (eKYC Re-Verification)
  • Customer Self-Service Portal for Document Upload
  • Workflow-Engine for Status-Tracking
Manual only for:
  • EDD cases (MLRO review required)
  • Screening Hits (PEP/Sanctions)
  • Complex Corporate Structures (UBO Updates)
Q11: What sanctions for non-compliance? A: AMLR: Up to 10% of worldwide annual turnover or EUR 5 million (whichever is higher).

6AMLD (criminal law):

  • At least 4 years imprisonment for serious money laundering
  • In aggravating circumstances: up to 8 years
  • Management Liability (personal liability of Board, CEO, CFO, MLRO, Compliance Officer)
  • Liability of legal entities (company as a whole)
  • Tipping-Off: Criminal offense (warning the customer about SAR)
Additionally:
  • License withdrawal possible (FMA/BaFin)
  • Reputational Damage
  • Business prohibitions
Q12: Do I need external advice? A: Recommended for:
  • First-time implementation (AMLR/6AMLD compliance)
  • Complex business models (Crypto, Cross-Border, Group)
  • FMA/BaFin-Audit Preparation
  • Tool Selection (RFP Management with Vendor Due Diligence)
  • Group-wide Harmonization (multiple entities)
  • Outsourcing Arrangements (Contract Review, SLA Design)
DIY possible with Blueprint + Templates for:
  • Standard models (SEPA Payments, Low-Risk)
  • Small customer base (under 10,000 customers)
  • No group structure
  • Available internal compliance resources
Hybrid approach: Gap Assessment external + Implementation internal (with templates)

BONUS DOCUMENTS (NEW):

About NEXORA:

NEXORA Unternehmensberatung GmbH, Vienna: Specialized in compliance, RegTech and digital processes for FinTechs, CASPs and Payments in the DACH region. From Risk Assessment to Go-Live – with practical Blueprints, Templates and Hands-On Support.

Our Expertise:

  • AML/KYC Compliance (AMLR, 6AMLD, FM-GwG, GwG)
  • MiCA & DORA Implementation
  • RegTech Tool Selection & Integration
  • Process Optimization & Automation
  • Group-wide Compliance Harmonization
  • Vendor Due Diligence & Outsourcing Management
Our Methodology:
  • Risk-based Approach (AMLR/EBA-compliant)
  • Practice-oriented Templates (immediately usable)
  • No Vendor-Kickbacks (neutral advice)
  • Fixed-Scope Offers (Cost Transparency)
This blueprint does not constitute legal advice. The contents are of a general nature and do not replace an individual legal assessment under FM-GwG (Austria), GwG (Germany) and applicable national law (e.g. Gewerbeordnung, Bankwesengesetz, Zahlungsdienstegesetz).

Requirements vary depending on:

  • Business model (Payments, Lending, Crypto, FX)
  • Jurisdiction (Austria, Germany, other EU countries)
  • Risk profile (customer segment, transaction volume, product portfolio)
  • Group structure (standalone vs. multi-entity)
  • Outsourcing arrangements (inhouse vs. external service providers)
All thresholds, risk scores, SLAs and processes mentioned in the blueprint are examples and must be adapted to your own company-wide risk assessment in accordance with AMLR (EU) 2024/1624 Art. 8-9. The risk-based approach must be documented and regularly reviewed.

Individual advice from qualified lawyers or compliance experts is recommended, especially for:

  • First-time licensing (FMA/BaFin, incl. PSD2/EMI/MiCA licensing)
  • Complex cross-border structures
  • Group-wide compliance frameworks
  • Supervisory audits (FMA/BaFin audits)
The contents were created to the best of our knowledge (as of January 2026), but no guarantee is given for completeness, topicality and correctness. Regulatory requirements are constantly changing (FMA/BaFin Guidance, EBA Updates, FATF Recommendations).

Sources & Links

EU Legal Acts:

  • AMLR (EU) 2024/1624 – Directly applicable from 2027-07-10
  • 6AMLD (EU) 2024/1640 – Transposition by 2027-07-10
  • EU Money Transfer Regulation (TFR) – Travel Rule for Crypto
  • MiCA (EU) 2023/1114 – Markets in Crypto-Assets Regulation
  • EBA Guidelines on ML/TF Risk Factors (EBA/GL/2021/02)
  • EBA Guidelines on Customer Due Diligence (EBA/GL/2022/XX)
  • FATF Recommendations (40 Recommendations + Interpretive Notes)
  • FATF Public Statements (High-Risk & Non-Cooperative Jurisdictions, quarterly updates)
  • FMA Hinweise zu AML (Austrian Financial Market Authority)
  • BaFin Merkblätter zu GwG (German Federal Financial Supervisory Authority)
  • FM-GwG (Austrian Financial Market Money Laundering Act)
  • GwG (German Money Laundering Act)
  • EU High-Risk 3rd Countries (Delegated Regulation Updates) 14. GDPR (EU) 2016/679 – Data Protection Regulation
© 2026 NEXORA Unternehmensberatung GmbH. All rights reserved.

Need a consultation?

Book a free initial consultation with the NEXORA team.

Free Consultation
AML/KYC Blueprint 2026: From Risk Assessment to Onboarding and Ongoing Monitoring (EU AMLR & 6AMLD) | NEXORA