AML/KYC Blueprint 2026: From Risk Assessment to Onboarding and Ongoing Monitoring (EU AMLR & 6AMLD)

Author: Nexora Team, NEXORA Unternehmensberatung GmbH Published: January 2026 | Reading time: 16 minutes
This blueprint provides FinTechs, crypto providers, and payments with a complete end-to-end process for AML/KYC under EU AMLR & 6AMLD: Risk Assessment Templates, Onboarding Decision Trees, Monitoring Playbook, and Governance Roles. Includes practical checklists and a download kit.
The 7 most important points:
✅ Risk Assessment every 12 months (Enterprise + Customer/Product/Channel) → Risk Appetite Statement | KPI Target: 100% Documentation Coverage
✅ Onboarding: eKYC + UBO + Source of Funds → Decision Matrix (Auto Approve/EDD/Reject) | Target: under 10 minutes for Low Risk
✅ Monitoring: Behavioral + Transaction Rules → Alert Lifecycle (Triage → Investigate → Report → SAR) | Target: 95% Closure under 48 hours
✅ Screening: Sanctions/PEP/Adverse Media real-time + batch → Hit Rates under 0.5% target | False Positives under 80%
✅ Governance: MLRO + 1st/2nd Line + IT → Board KPI Dashboard | Target: Quarterly Review 100%
✅ KYC Refresh: Low Risk 24 months | High Risk 12 months | PEP 6 months (exemplary cycles based on RBA)
✅ SAR Filing: FIU without undue delay (Practice: ideally on the same day, at the latest within a few working days in accordance with FMA guidelines)
Important note on the application of this blueprint
All thresholds, risk scores, SLAs, and processes mentioned in this blueprint are examples and serve to illustrate a risk-based approach in accordance with AMLR (EU) 2024/1624 and 6AMLD (EU) 2024/1640.
Each institution must:
- Develop its own methodology based on the company-wide risk assessment
- Adjust thresholds to its own business model
- Consider national requirements (e.g. FM-GwG in Austria, GwG in Germany)
- Document and regularly review the risk-based approach
Target: What does "professional AML/KYC" mean?
Professional AML/KYC means an automated, risk-based process with the following flow:
Customer → Risk Score → CDD/EDD → Ongoing Monitoring → Alerts → SARs → FIU
Screening (PEP/Sanctions) and Transaction Monitoring run in parallel, triggering alerts in the event of Behavioral Changes.
The result: A 100% comprehensible audit trail, board-ready KPI, and scalability from 10,000 to 1 million customers.
Blueprint overview: The three main steps
The AML/KYC process consists of three main steps:
STEP 1: RISK ASSESSMENT
- Enterprise Risk Assessment (annual, AMLR-compliant)
- Product/Channel/Customer Risk Assessment
- Group-wide Risk Assessment (for corporate groups)
- Output: Risk Appetite Statement + Risk Matrix
- 6-step process: Pre-Fill → ID Check → UBO → Purpose → Screening → Decision
- Decision Matrix: Auto-Approve / CDD / EDD / Reject based on Risk Score
- Output: Customer File (Immutable Audit Trail)
- Transaction Monitoring Rules (8 examples)
- Alert Lifecycle: Generation → Triage → Investigation → MLRO → SAR → Closure
- Screening Stack: Real-Time + Daily Batch + Weekly Deep
- Output: Alerts → SARs → Board KPI Dashboard
Step 1: Risk Assessment
Frequency and Outputs
How often:
- Enterprise Risk Assessment: annually (Q4) in accordance with AMLR Art. 8
- Product/Channel Risk Assessment: at launch or significant change
- Group-wide Risk Assessment: annually (for groups in accordance with AMLR Art. 9)
- Ad-hoc Review: in the event of regulatory changes or significant incidents
- Risk Appetite Statement (Board-approved)
- Methodology Document (EBA-Guidelines-compliant)
- Risk Matrix (3×3 or 4×4, institution-specific)
- Risk Register (Living Document)
- Group-wide Policies (if applicable)
IMPORTANT: This matrix is exemplary. Each institution must develop its own matrix based on its business model and company-wide risk assessment.
The risk matrix assesses four criteria:
CRITERION 1: JURISDICTION (40% weighting - example)
- Low (Score 1): EU Tier 1 (Austria, Germany, Netherlands, France)
- Medium (Score 2): EU Tier 2, Eastern EU (Poland, Czech Republic, Hungary)
- High (Score 3): High-Risk 3rd Countries according to FATF lists and EU Delegated Regulation
- Low (Score 1): SEPA Payments under EUR 15,000
- Medium (Score 2): FX Trading, Lending over EUR 15,000
- High (Score 3): Crypto, Cash over EUR 50,000
- Low (Score 1): App/Website (Authenticated, strong KYC)
- Medium (Score 2): Agent Network (Semi-Authenticated)
- High (Score 3): P2P, ATM (higher anonymity risk)
- Low (Score 1): Retail (KYC, Low Velocity)
- Medium (Score 2): SME, Freelance (Mid Velocity)
- High (Score 3): HNWI, PEP, Complex Structures
IMPORTANT NOTE: This formula is exemplary and serves to illustrate a risk-based approach. Each institution must develop its own methodology, which is empirically validated (e.g. by historical SAR rate per segment) and corresponds to the company-wide risk assessment in accordance with AMLR.
Exemplary formula:
- Risk Score (0-100) = (0.40 × Jurisdiction Score × 33.33) + (0.30 × Product Score × 33.33) + (0.20 × Channel Score × 33.33) + (0.10 × Customer Type × 33.33)
- Where: Score 1 = 0 points | Score 2 = 50 points | Score 3 = 100 points
The weightings must be justified and documented by your own risk analysis.
RISK APPETITE STATEMENT 2026 – EXAMPLE
1. STRATEGIC GOALS
- Growth: +30% customers per year (SEPA + Crypto)
- Compliance: 0 material FMA Findings
- Efficiency: Alert Closure under 48h in 95% of cases
- Alert Closure SLA: 95% under 48h | 100% under 5 days (internal target)
- False Positive Rate: under 80% (Target: 75%)
- EDD-Trigger: Risk Score over 70/100 (exemplary threshold)
- Auto-Reject: Score over 90/100 in combination with confirmed Sanctions hit or serious risk factors
- SAR Filing: Without undue delay in accordance with FM-GwG (internal SLA: on the same day, at the latest within a few working days)
- Quarterly MLRO Report (Board)
- Annual Enterprise Risk Assessment (AMLR Art. 8)
- Group-wide Risk Assessment (if applicable, AMLR Art. 9)
- Monthly Alert KPI Review (Compliance Committee)
- Ad-hoc in the event of High-Impact Events (over EUR 500,000 SAR)
- Independent AML audits in high-risk constellations
- EUR 50,000+ Transaction → 2nd Line Review
- PEP/Sanctions Hit → MLRO Immediate
- Crypto over EUR 100,000/day → EDD + Source of Wealth
- High-Risk 3rd Country → Auto-EDD (no automatic Auto-Approve)
Data sources for Risk Assessment
- FATF Public Statements (High-Risk & Non-Cooperative Jurisdictions)
- EU High-Risk 3rd Countries (Delegated Regulation in accordance with AMLR)
- EBA Guidelines on ML/TF Risk Factors (EBA/GL/2021/02)
- OECD Financial Action Task Force (Mutual Evaluation Reports)
- National Supervisory Guidelines (FMA Austria, BaFin Germany)
- Internal Data: SAR History, Alert Volume, False Positive Rates
The 6-step onboarding process
STEP 1: PRE-FILL
- Name, date of birth, nationality (API or Manual)
- Output: Customer Profile (Draft)
- Document Scan (Passport or eID)
- Liveness Detection (Selfie)
- OCR + Validation (MRZ)
- Tools (Examples, no recommendation): Jumio, Onfido, Sumsub, IDnow
- Note: When using external eKYC providers, DPA, SLA, audit rights, and vendor due diligence are required in accordance with AMLR outsourcing requirements
- Output: ID Verified ✓ or Failed ✗
- Company Register Extract (API, access to central BO registers in accordance with AMLR)
- Over 25% Ownership Chain (AMLR threshold)
- UBO Declaration (Self-Certification)
- Output: UBO List + Percent Ownership
- Questionnaire: Purpose of Business Relationship
- Expected Activity (Volume, Frequency)
- Source of Funds (Salary/Business/Inheritance)
- Output: Purpose Statement + SoF Evidence (for EDD)
- Real-Time API (Examples: WorldCheck, Dow Jones, Refinitiv – no vendor recommendation; selection according to RFP process with vendor due diligence in accordance with AMLR/GDPR requirements)
- Fuzzy Match (Name + Date of Birth + Nationality)
- Hit Review (False Positive Elimination)
- Output: Clear ✓ or Hit → Manual Review
- Risk Score Calculation
- Decision Matrix Application
- MLRO Escalation (if Score over 70 - exemplary threshold)
- Output: Account Activated | EDD Initiated | Rejected
IMPORTANT NOTE: All thresholds, scores, and SLAs in this decision matrix are exemplary and must be adapted to your own business model, company-wide risk assessment, and national requirements (e.g. FM-GwG in Austria).
RISK SCORE 0-29: AUTO-APPROVE (Example)
- Documents: eID (Passport/National ID) + Proof of Address (optional) + Screening Clear
- SLA: under 10 minutes
- Action: 1st Line Info only (no review necessary)
- KYC Refresh: 24 months (exemplary cycle based on RBA; AMLR requires risk-based and event-driven refresh, no fixed legal cycles)
- Documents: eID + Proof of Address + Source of Funds (Statement) + Purpose of Account + Screening Clear
- SLA: under 24 hours
- Action: 1st Line Review (Plausibility Check)
- KYC Refresh: 12-24 months
- Documents: All CDD documents + Source of Funds (Evidence) + Expected Activity (Detail) + UBO (if Legal Entity)
- SLA: under 48 hours
- Action: 2nd Line Review
- KYC Refresh: 12 months
- Documents: All Enhanced CDD documents + Source of Wealth (Tax Return, Bank Statements over 6 months) + UBO Verification (Legal Register Extract) + Adverse Media Research + Site Visit (optional for High-Risk Business)
- SLA: under 5 working days (internal SLA)
- Action: MLRO Approval required
- KYC Refresh: 6 months (PEP) or 12 months
- Trigger: Confirmed Sanctions hit (no False Positive) OR High-Risk 3rd Country without possible Mitigation OR Internal Blacklist Entry OR several serious risk factors
- Important: PEP in itself triggers EDD, but no general ban or Auto-Reject according to FATF standards
- Action: Blacklist Entry (after MLRO-Review) + MLRO Notification + SAR Filing (in case of reasonable suspicion)
- Next: No Appeal (except Sanctions False Positive after Re-Review)
According to AMLR and FATF-Recommendations, EDD is required for:
- PEP status (Politically Exposed Persons - mandatory EDD, but no automatic business ban)
- High-Risk 3rd Country according to FATF lists and EU Delegated Regulation
- Crypto/High-Value (Example: Single transaction over EUR 50,000 or daily limit over EUR 100,000)
- UBO over 25% unclear (Complex Ownership Structures)
- Adverse Media Hits (Financial Crime, Corruption, Terrorism)
- Cash-Intensive Business (Example: Taxi, Gastronomy, Exchange Offices over EUR 10,000/month)
- Geo-Hopping (3+ countries within 30 days - exemplary threshold)
- Inconsistent Profile (Low Income + High Transactions)
- Previous SAR Filed (Historical Red Flag)
- Complex Corporate Structure (over 3 Layers, Offshore SPVs)
Customer File: What is documented?
Each customer receives an immutable audit trail with the following 10 components in accordance with AMLR documentation obligations:
- Application Form (Timestamp, IP, User Agent)
- ID Document Scan (Front, Back, MRZ Data)
- Liveness Check (Video/Selfie + AI Score)
- Screening Results (API Response + Manual Review)
- Risk Score Calculation (Formula + Inputs)
- Decision Log (Auto/EDD/Reject + Rationale)
- UBO Declaration (if applicable, access to central BO registers)
- Source of Funds/Wealth (Evidence, if EDD)
- MLRO Approval (if Score over 70)
- KYC Refresh Date (based on Risk-based approach)
Step 3: Ongoing Monitoring
The three monitoring categories
CATEGORY 1: EVENT-DRIVEN
- KYC Refresh (risk-based cycles in accordance with AMLR)
- Behavioral Change (e.g. Velocity +300% MoM)
- Geo-Change (Login from High-Risk Country)
- Customer Request (Account Upgrade)
- Adverse Media Alert (Batch Screening)
- Quarterly Risk Score Review (all customers)
- Monthly PEP Re-Screening (PEP-Flagged)
- Annual Enterprise Risk Assessment (AMLR Art. 8)
- Threshold Breach (Example: over EUR 15,000 SEPA, over EUR 1,000 Crypto in accordance with EU Funds Transfer Regulation/TFR)
- Rule-Based Alert (Velocity, Structuring)
- Suspicious Pattern (ML Model Score over 0.8)
- Sanction Screening Hit (Real-Time)
IMPORTANT: These rules are exemplary. Thresholds must be adapted to your business model and risk assessment.
TM-01: VELOCITY CHECK
- Logic: over 10 transactions per 24h OR over EUR 50,000 per 24h
- Alert Action: L1 Review under 4h
- Logic: 3+ countries within 7 days (excl. EU Tier 1)
- Alert Action: EDD + Source of Funds
- Logic: 9× between EUR 9,000-9,900 within 24h (under EUR 10,000 Limit)
- Alert Action: SAR Preparation
- Logic: over EUR 10,000 per day (Crypto → Fiat)
- Alert Action: Source of Funds Required
- Note: Travel Rule for over EUR 1,000 in accordance with AMLR Art. 45-46 for CASPs, EU Funds Transfer Regulation (TFR), IVMS101 format
- Logic: In/Out same amount within 48h
- Alert Action: L2 Investigation
- Logic: Transaction FROM/TO FATF Blacklist/Greylist
- Alert Action: Enhanced Review
- Logic: 0 Activity for over 180 days THEN Transaction over EUR 5,000
- Alert Action: Low Priority + Profile Check
- Logic: Income EUR 2,000/Month BUT Spending over EUR 20,000/Month
- Alert Action: MLRO Escalation
STEP 1: ALERT GENERATION
- Source: Transaction Rule | Behavioral Model | Screening Hit
- Priority: High (MLRO under 1h) | Medium (under 4h) | Low (under 24h)
- Assignment: Auto-Route to 1st Line Queue
- SLA: under 4 hours (internal target: 95%)
- Action: Review Transaction History (30 days)
- Decision: FALSE POSITIVE → Close | POSSIBLE TRUE POSITIVE → Escalate to 2nd Line | UNCLEAR → Request Additional Info
- Output: Triage Decision + Notes
- SLA: under 24 hours (internal target: 90%)
- Action: Deep-Dive Transaction Analysis (90 days), Customer Interview (if necessary), External Data (OSINT, Adverse Media), Pattern Analysis
- Decision: FALSE POSITIVE → Close | TRUE POSITIVE (No SAR) → Enhanced Monitoring | TRUE POSITIVE (SAR) → Escalate to MLRO
- Output: Investigation Report (2-5 pages)
- SLA: under 48 hours (internal target: 100%)
- Action: Review Investigation Report + Supporting Evidence
- Decision: NO SAR → Close + Enhanced Monitoring | SAR REQUIRED → Draft SAR | ACCOUNT ACTION → Freeze/Close + SAR
- Output: MLRO Decision + SAR Trigger
- Legal Obligation: Without undue delay (cf. FM-GwG §41, GwG §43) – "without undue delay" means immediate notification from the time of knowledge
- Internal SLA (based on FMA practice): Ideally on the same day, at the latest within a few working days in accordance with FMA guidelines
- Important: The actual implementation depends on the circumstances of the individual case; the internal SLA serves to control the process, but does not replace the legal obligation to act immediately
- Content: Customer Profile, Suspicious Activity Description, Transaction Details, Investigation Summary, Supporting Documents
- Submission: FIU Portal (Encrypted)
- Tipping-Off Prohibition: § 41 FM-GwG - No information to customers about SAR-Filing (criminal offense if violated)
- Output: SAR Reference Number + Acknowledgement
- Action: Update Customer Risk Score, Tag Account (Enhanced Monitoring / Closed / SAR Filed), Archive Alert File (Immutable), Update KPI Dashboard
- Output: Closed Alert + Audit Trail (minimum 5 years retention after termination of the business relationship in accordance with AMLR/FM-GwG)
TIER 1: REAL-TIME SCREENING (under 100ms)
- Trigger: Onboarding | Login | Transaction over EUR 15,000 (exemplary threshold)
- Data Sources: UN Consolidated Sanctions List, EU Sanctions List, OFAC SDN List, National PEP Lists, Internal Blacklist
- Tools (Examples, no recommendation): WorldCheck, Dow Jones, ComplyAdvantage
- Vendor Due Diligence: When using external screening providers, DPA, SLA, audit rights, review of sub-processors and regular performance assessment are required in accordance with AMLR outsourcing requirements
- Match Logic: Fuzzy (Levenshtein Distance under 2) + Date of Birth ±2 years
- Output: CLEAR ✓ or HIT → Manual Review Queue
- KPI Target: under 100ms Response Time | Hit Rate under 0.5%
- Trigger: Daily 02:00 CET (all active customers)
- Data Sources: Tier 1 Sources (Updated Lists), Adverse Media, Expanded PEP (RCA = Relatives & Close Associates), Negative News, Court Records
- Match Logic: Fuzzy + Contextual (Industry, Location)
- Output: New Hits → 1st Line Review Queue (under 24h SLA)
- KPI Target: 100% Customer Base Daily | under 1% New Hit Rate
- Trigger: Weekly (PEP, High-Risk Score over 70, EDD Customers)
- Data Sources: UBO Network Analysis (Access to central BO registers), Complex Structure Detection, Cross-Border Linkage, Deep Web OSINT, Industry Watchlists
- Match Logic: Manual Investigation + OSINT Tools
- Output: Enhanced Profile + Risk Score Update
- KPI Target: 100% High-Risk Cohort Weekly | under 5% Escalation Rate
- Overall Hit Rate: under 0.5% (Tier 1) | under 1% (Tier 2) | under 5% (Tier 3)
- False Positive Rate: under 80% (internal target: 75%)
- Time to Resolution: under 24h (Tier 1+2) | under 5 days (Tier 3)
- Data Freshness: under 24h (Daily Updates from Vendors)
The six main roles:
MLRO (MONEY LAUNDERING REPORTING OFFICER) – 2nd Line
- SAR-Filing Ownership (FIU Liaison without undue delay)
- Alert Escalation Review (High-Priority under 1h)
- Risk Appetite Statement Owner
- Quarterly Board KPI Reporting
- FMA Contact Person (Regulatory Inquiries)
- Independent of 1st Line (Operational)
- Reporting directly to Board/CEO (no intermediate level)
- Onboarding Execution (Low Risk Auto-Approve)
- Alert Triage (under 4h SLA, False Positive Elimination)
- Customer Communication (Document Requests)
- KYC Refresh Initiation (Time-Driven + Event-Driven)
- Alert Investigation (Deep Dive, under 24h SLA)
- EDD Review & Approval (Risk Score over 70 - exemplary)
- Monitoring Rule Optimization (False Positive Reduction)
- Policy Development Support
- Vendor Performance Monitoring (for Outsourcing)
- Tool Integration (Screening, Case Management, eKYC)
- Audit Trail Architecture (Immutable Logs)
- Data Security (Encryption, Access Control, GDPR-Compliance)
- Performance Monitoring (API Latency, Uptime)
- Outsourcing Technical Management (SLA-Monitoring)
- AML/KYC Policy Ownership (Annual Review)
- Training Delivery (Staff + Management)
- Regulatory Change Monitoring (AMLR Updates, FMA/BaFin Guidance)
- Internal Audit Coordination
- Group-wide Policy Coordination (for Corporate Groups)
- Risk Appetite Approval (Annual)
- Quarterly KPI Review (Dashboard)
- Resource Allocation (Budget, Headcount)
- Regulatory Relationship (FMA/BaFin Liaison)
- Group-wide Oversight (for Corporate Groups)
- Approval of significant outsourcing arrangements
According to AMLR Art. 9, additional requirements apply to corporate groups:
1. GROUP-WIDE RISK ASSESSMENT
- Consolidated risk assessment across all group entities
- Consideration of cross-border risks
- Central documentation and reporting
- Uniform AML/KYC policies for all group companies
- Adaptation to local regulatory requirements (higher standard applies)
- Central policy governance with local adaptation rights
- Group MLRO or Group Compliance Officer
- Central reporting to Group Board
- Coordination of SAR-Filing across entities
- Information Sharing within the group (observing Data Protection)
- Uniform Monitoring Rules and Screening Standards
- Central Watchlist Management
- Consolidated KPI Dashboard
- Group-wide Training & Awareness Programme
- Independent AML audits at Group-Level
- Coordination of local audits
- Escalation mechanisms in case of violations
Outsourcing & Reliance
When using external service providers (eKYC, Screening, Case Management), the following requirements must be observed in accordance with AMLR:
1. VENDOR DUE DILIGENCE
- Technical Evaluation (Proof-of-Concept)
- Financial Stability (Annual Financial Statements, Ratings)
- Compliance Posture (ISO 27001, SOC 2, GDPR-Certifications)
- References and Track Record
- Data Processing Agreement (DPA) according to GDPR Art. 28
- Service Level Agreement (SLA) with clear Performance Metrics
- Audit Rights (annual audit right on-site or remote)
- Exit Clauses and Data Migration Plan
- Liability Regulations in case of Data Loss or Compliance Violations
- Full Disclosure of all Sub-Processors
- Review of Sub-Processor Locations (EU vs. Third Country)
- Contractual Commitment of Sub-Processors to the same Standards
- EU-Hosting for KYC-Data (GDPR-compliant)
- Clarification of Data Residency Requirements (e.g. FM-GwG)
- Backup Locations within EU
- Regular Review of the False Positive Rate (Screening)
- API Uptime and Response Time (eKYC under 100ms)
- Quarterly Business Reviews with Vendor
- Escalation Process in case of Performance Problems
- Vendor must enable supervisory audits by FMA/BaFin
- Vendor must provide documentation and logs on request
- Incident Reporting Obligation (Data Breaches, System Failures)
RACI Matrix – Distribution of Roles and Responsibilities
The RACI matrix is a proven governance tool for the clear assignment of responsibilities in regulatorily sensitive processes (e.g. AML, Compliance, Risk Management, Outsourcing).
Meaning of the Roles (Legend):
- R – Responsible (Responsible for Implementation)
- A – Accountable (Overall Responsibility)
- C – Consulted (Involved)
- I – Informed (Informed)
| Process / Activity | MLRO | 1st Line | 2nd Line | IT | Compliance | Board |
|---|---|---|---|---|---|---|
| Annual Risk Assessment | A | C | R | C | R | I |
| Group-wide Risk Assessment | Group MLRO: A | Local MLROs: R | – | – | Group Compliance: R | Group Board: I |
| Onboarding Approval (Low Risk < 30) | A (Escalation) | R | C | I | I | – |
| EDD Approval (High Risk > 70) | A | I | C | I | R | I |
| Alert Triage (SLA < 4h) | I | R | A (Escalation) | – | I | – |
| SAR Filing (without undue delay) | A / R | I | C | – | C | I |
| Vendor Selection (Outsourcing) | C | I | C | R | A | A (Approval) |
| Quarterly KPI Review (Board Reporting) | R | C | C | C | C | A |
Interpretation from a Governance and Compliance Perspective:
- MLRO (Money Laundering Reporting Officer)
- 1st Line of Defense
- 2nd Line of Defense / Compliance Function
- IT Function
- Board / Management
Regulatory Added Value of the RACI Structure
A clearly defined RACI matrix supports:
- clear supervisory audits (FMA, BaFin, ECB)
- Proof of functional separation (Segregation of Duties)
- Fulfillment of requirements from AMLD, MiCA, DORA and ISO 37301 Compliance Management Systems
- Reduction of operational risks and liability risks for management and MLRO
The 6th EU Money Laundering Directive (6AMLD, 2024/1640) significantly expands criminal liability:
1. EXPANDED UNDERSTANDING OF MONEY LAUNDERING
- 22 predicate offenses (instead of previously variable national lists)
- Including Tax Crimes
- Self-Laundering (perpetrator launders own proceeds) is punishable
- Aiding and Abetting and Attempt are punishable
- Companies can be prosecuted
- Sanctions: Fines, Business Bans, License Revocation
- Requirement: Act was committed by a manager OR lack of supervision enabled the act
- Management Liability in case of intentional or grossly negligent breach of duty
- Directors & Officers can be personally prosecuted
- Relevant Positions: Board, CEO, CFO, MLRO, Compliance Officer
- At least 4 years imprisonment for serious money laundering
- In aggravating circumstances (organized crime): up to 8 years
- Fines: up to 10% of worldwide annual turnover or EUR 5 million
- Warning the customer about SAR-Filing: Criminal Offense (§ 41 FM-GwG)
- Obstruction of Investigations: Criminal Offense
- Destruction of Evidence: Criminal Offense
- Well-documented CDD/EDD Processes
- Traceable Risk Assessments
- Timely SAR-Filing (without undue delay)
- Complete Audit Trails
- Regular Employee Training
- Independent AML Audits
KPI Dashboard – The 10 Most Important AML and Compliance Metrics
Note: The following KPIs serve as best-practice examples for internal control. The specific design depends on the business model, risk profile, product scope and regulatory status of the institution.
Operational KPI Overview
| KPI | Current | Previous Period | Target Value | Status |
|---|---|---|---|---|
| Alert Volume (Monthly Average) | 1.247 | 1.113 | < 1,500 | ✓ |
| Alert Closure Rate (SLA < 48h) | 96 % | 94 % | ≥ 95% | ✓ |
| False Positive Rate | 82 % | 85 % | < 80% (optimal: 75%) | ⚠ |
| SARs Filed (FIU Reports) | 17 | 14 | Trend Monitoring | – |
| SAR Filing Timeliness | 100 % | 100 % | Legally: 100% | ✓ |
| EDD Coverage (% Customer Base) | 14 % | 13 % | 10–15% | ✓ |
| Average Risk Score | 42 / 100 | 41 / 100 | < 50 | ✓ |
| KYC Refresh On-Time | 98 % | 96 % | > 95% | ✓ |
| Screening Hit Rate | 0,43 % | 0,48 % | < 0.5% | ✓ |
| Onboarding Reject Rate | 2,1 % | 1,9 % | < 3% | ✓ |
Regulatory Classification of Selected KPIs
SAR Filing Timeliness:
- Legal Obligation: immediate notification without undue delay
- Best Practice according to Supervisory Practice (e.g. FMA):
- KPI Target: 100% Compliance without exception
- Typical Intervals (Example):
- Low Risk: 24 months
- Medium Risk: 12 Months
- High Risk: 6 Months
- AMLR requires: risk-based approach, no rigid deadline logic.
- Alert Volume: +12% MoM
- False Positives: 82%
- SARs Filed: +3 compared to previous quarter
- EDD Coverage stable at 14%
Management Action Items
- Reduce False Positive Rate
- Continue to monitor Alert Volume
- Ensure SAR Timeliness
Common Errors: The 15 Biggest Risks
❌ 1. Risk Appetite Missing → Arbitrary decisions, no governance, AMLR violation
❌ 2. Manual Screening → Does not scale, high false positive rate, inefficient
❌ 3. No UBO Data → FIU-SAR rejection, incomplete due diligence, AMLR violation
❌ 4. Event-Driven Monitoring Missing → Sleeping Risks (Behavioral Changes undetected)
❌ 5. Alert Backlog over 7 Days → FMA criticism, compliance risk, potential sanctions
❌ 6. No Audit Trail → Untraceable, audit findings guaranteed, AMLR violation
❌ 7. PEP Name-Screening Only → Incomplete (RCA = Relatives & Close Associates missing), FATF non-compliance
❌ 8. Source of Funds Ignored → High-Risk Customers accepted without plausibility, ML risk
❌ 9. Staff Training Missing → Liability (employees do not recognize SAR-worthy cases), 6AMLD risk
❌ 10. No Escalation Processes → MLRO Blindspot (alerts get stuck in 1st line), SAR delay
❌ 11. KPI Only Internal → Board not informed, no strategic control, governance gap
❌ 12. False Positive over 90% → Inefficiency, high operational costs, staff burnout, missed true positives
❌ 13. Crypto without Travel Rule → TFR non-compliance (VASP-to-VASP Transfers over EUR 1,000)
❌ 14. Onboarding SLA over 5 Days → Customer Churn, Competitive Disadvantage
❌ 15. No Vendor Due Diligence for Outsourcing → AMLR violation, GDPR risk, potential data breaches
"What to do next?" – The 3-Stage Rollout
STAGE 1: BLUEPRINT ASSESSMENT (1 week)
- Day 1-2: Download Kit Review (Checklist, Templates)
- Day 3-4: Gap Analysis (Actual vs. AMLR/6AMLD/FM-GwG)
- Day 5: Prioritization (Quick Wins vs. Long-Term)
- Output: Gap Report + Prioritized Backlog
- Week 1: Scope Definition (1 Product, e.g., SEPA Payments)
- Week 2: Process Design (Onboarding Flow + Decision Matrix)
- Week 3: Tool Selection with Vendor Due Diligence (eKYC, Screening, Case Management)
- Week 4: Full Process Test (10 Onboardings + 5 Alerts)
- Output: Pilot Report + Lessons Learned + Go/No-Go Decision
- Week 1-4: Tool Integration (API, Webhooks, Audit Logs) + Outsourcing Agreements
- Week 5-8: Process Automation (Rules, Workflows, Thresholds)
- Week 9-10: Staff Training (1st Line, 2nd Line, MLRO) incl. 6AMLD Liability
- Week 11: Soft Launch (20% Customer Base)
- Week 12: Full Rollout + KPI Dashboard Go-Live
- Output: Production-Ready System + Board KPI Report + Group-wide Rollout (if applicable)
Q1: When do I have to implement AMLR? A: Directly applicable from 2027-07-10. No transposition necessary (EU regulation).
IMPORTANT: Preparation in 2026 is strongly recommended!
- Q1 2026: Gap Assessment (2 weeks)
- Q2-Q3 2026: Tool Selection + Process Design (8-12 weeks)
- Q4 2026: Pilot + Staff Training (4-8 weeks)
- Q1 2027: Full Rollout + FMA Readiness
Q2: Which tools are mandatory? A: No specific tools are prescribed. AMLR and MiCA do not require vendor selection. Tool selection is risk-based based on the business model and risk profile.
Examples (no recommendation):
- eKYC: e.g., Jumio, Onfido, Sumsub, IDnow
- Screening: e.g., WorldCheck (Refinitiv), Dow Jones Risk & Compliance, ComplyAdvantage
- Case Management: e.g., Actimize (NICE), SAS AML, FICO
Q3: How often KYC Refresh? A: Exemplary cycles based on RBA and market standard:
- Low Risk: 24 months
- Medium-High Risk: 12 months
- PEP: 6 months
You must define and document the specific cycles based on your company-wide risk assessment.
Q4: SAR Deadline FIU? A: Legal obligation: Without undue delay (cf. FM-GwG §41, GwG §43). "Without undue delay" means immediate reporting from the time of knowledge by MLRO.
FMA practice (indicative): Ideally on the same day, at the latest within a few working days according to FMA guidelines.
Internal SLA: 5 working days from MLRO decision can serve as an internal control benchmark, but does not replace the legal immediate obligation.
Target: 100% Compliance with legal reporting deadline.
Q5: Who is MLRO? A: Designated Person according to AMLR requirements:
- Independent of 1st Line (Customer Operations)
- Board access and direct reporting line to CEO/Board
- FIU-Liaison
- No dual role with operational business activities
- Adequate resources and powers
- Reporting not to COO/CFO, but directly to the Board
- EU-Hosting (GDPR Art. 44-50) or adequate level of protection in third country
- Data Processing Agreement (DPA) according to GDPR Art. 28
- Audit rights contractually secured (on-site or remote)
- Sub-Processors fully declared and verified
- Backup & Disaster Recovery documented and tested
- Exit strategy and data migration plan available
- FM-GwG/GwG Data Residency Requirements observed
Additionally:
- Wallet Screening (Mixing Services, High-Risk Exchanges, Tornado Cash)
- MiCA Compliance from 2024-12-30
- Enhanced Monitoring for Crypto-Ramps (Example: over EUR 10,000/day → Source of Funds)
- EDD for High-Value Crypto (Example: over EUR 50,000 single transaction)
- Actual analysis against AMLR/6AMLD/FM-GwG
- Identification of compliance gaps
- Prioritized Roadmap with Quick Wins
- Process Design for 1 product line
- Tool Evaluation and Vendor Due Diligence
- Full Process Test (10 Onboardings + 5 Alerts)
- Go/No-Go Recommendation
- Below 75% = excellent (requires ML models + continuous rule-tuning)
- Over 90% = inefficient (rule optimization urgently needed, high costs, staff burnout)
Q10: Can KYC Refresh be automated? A: Yes, largely automatable:
- Time-Driven Trigger (24M/12M/6M - exemplary cycles)
- Automatic e-mail with update link (eKYC Re-Verification)
- Customer Self-Service Portal for Document Upload
- Workflow-Engine for Status-Tracking
- EDD cases (MLRO review required)
- Screening Hits (PEP/Sanctions)
- Complex Corporate Structures (UBO Updates)
6AMLD (criminal law):
- At least 4 years imprisonment for serious money laundering
- In aggravating circumstances: up to 8 years
- Management Liability (personal liability of Board, CEO, CFO, MLRO, Compliance Officer)
- Liability of legal entities (company as a whole)
- Tipping-Off: Criminal offense (warning the customer about SAR)
- License withdrawal possible (FMA/BaFin)
- Reputational Damage
- Business prohibitions
- First-time implementation (AMLR/6AMLD compliance)
- Complex business models (Crypto, Cross-Border, Group)
- FMA/BaFin-Audit Preparation
- Tool Selection (RFP Management with Vendor Due Diligence)
- Group-wide Harmonization (multiple entities)
- Outsourcing Arrangements (Contract Review, SLA Design)
- Standard models (SEPA Payments, Low-Risk)
- Small customer base (under 10,000 customers)
- No group structure
- Available internal compliance resources
BONUS DOCUMENTS (NEW):
About NEXORA:
NEXORA Unternehmensberatung GmbH, Vienna: Specialized in compliance, RegTech and digital processes for FinTechs, CASPs and Payments in the DACH region. From Risk Assessment to Go-Live – with practical Blueprints, Templates and Hands-On Support.
Our Expertise:
- AML/KYC Compliance (AMLR, 6AMLD, FM-GwG, GwG)
- MiCA & DORA Implementation
- RegTech Tool Selection & Integration
- Process Optimization & Automation
- Group-wide Compliance Harmonization
- Vendor Due Diligence & Outsourcing Management
- Risk-based Approach (AMLR/EBA-compliant)
- Practice-oriented Templates (immediately usable)
- No Vendor-Kickbacks (neutral advice)
- Fixed-Scope Offers (Cost Transparency)
Requirements vary depending on:
- Business model (Payments, Lending, Crypto, FX)
- Jurisdiction (Austria, Germany, other EU countries)
- Risk profile (customer segment, transaction volume, product portfolio)
- Group structure (standalone vs. multi-entity)
- Outsourcing arrangements (inhouse vs. external service providers)
Individual advice from qualified lawyers or compliance experts is recommended, especially for:
- First-time licensing (FMA/BaFin, incl. PSD2/EMI/MiCA licensing)
- Complex cross-border structures
- Group-wide compliance frameworks
- Supervisory audits (FMA/BaFin audits)
Sources & Links
EU Legal Acts:
- AMLR (EU) 2024/1624 – Directly applicable from 2027-07-10
- 6AMLD (EU) 2024/1640 – Transposition by 2027-07-10
- EU Money Transfer Regulation (TFR) – Travel Rule for Crypto
- MiCA (EU) 2023/1114 – Markets in Crypto-Assets Regulation
- EBA Guidelines on ML/TF Risk Factors (EBA/GL/2021/02)
- EBA Guidelines on Customer Due Diligence (EBA/GL/2022/XX)
- FATF Recommendations (40 Recommendations + Interpretive Notes)
- FATF Public Statements (High-Risk & Non-Cooperative Jurisdictions, quarterly updates)
- FMA Hinweise zu AML (Austrian Financial Market Authority)
- BaFin Merkblätter zu GwG (German Federal Financial Supervisory Authority)
- FM-GwG (Austrian Financial Market Money Laundering Act)
- GwG (German Money Laundering Act)
- EU High-Risk 3rd Countries (Delegated Regulation Updates) 14. GDPR (EU) 2016/679 – Data Protection Regulation
Need a consultation?
Book a free initial consultation with the NEXORA team.