My bookmarksSign up free

Regulation (EU) 2024/1620 SECTION 2 — AML/CFT supervisory system

Article 7–Article 11 · 5 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Cooperation within the AML/CFT supervisory system

Article 7

1.   The Authority shall be responsible for the effective and consistent functioning of the AML/CFT supervisory system. 2.   The Authority and the supervisory authorities shall be subject to a duty of cooperation in good faith, and to an obligation to exchange information for AML/CFT purposes in accordance with this Regulation, Regulation (EU) 2023/1113, Regulation (EU) 2024/1624 and Directive (EU) 2024/1640. 3.   At the request of the Authority, supervisory authorities shall provide the Authority with all information concerning obliged entities that remain directly supervised at national level which is necessary for the fulfilment of Authority’s tasks pursuant to Article 5(1), (3) and (4), where the supervisory authorities have legal access to such information. 4.   Supervisory authorities shall assist the Authority in identifying and taking into account the specificities of their respective national legal frameworks, in particular where the Authority is applying national legislation transposing Union law as referred to in Article 1(2).

AML/CFT supervisory methodology

Article 8

1.   In cooperation with the supervisory authorities, the Authority shall develop and maintain an up-to-date and harmonised AML/CFT supervisory methodology detailing the risk-based approach to supervision of obliged entities in the Union. That methodology shall comprise guidelines, recommendations, opinions and other measures and instruments as appropriate, including in particular regulatory and implementing technical standards, on the basis of the empowerments laid down in the acts referred to in Article 1(2). 2.   When developing the supervisory methodology, the Authority shall distinguish between obliged entities, including on the basis of their activities and the type and nature of the ML/TF risks to which they are exposed. The supervisory methodology shall be risk-based and contain at least the following elements: (a) benchmarks and a methodology for classification of obliged entities into risk categories on the basis of their residual risk profile, separately for each category of obliged entities; (b) approaches to supervisory review of ML/TF risk self-assessments of obliged entities; (c) approaches to supervisory review of obliged entities’ internal policies and procedures, including their customer due diligence policies and procedures, in line with a risk-based approach to the prevention of ML/TF; (d) approaches to supervisory evaluation of risk factors inherent in, or related to, customers, business relationships, transactions and delivery channels of obliged entities, as well as geographical risk factors. 3.   The Authority shall develop structured questionnaires and other online or offline tools to be used by the Authority and supervisors for the purposes of requesting, collecting, compiling and analysing data and information from obliged entities, including the data to be relied upon in application of the elements of the supervisory methodology listed in paragraph 2. The tools developed by the Authority shall ensure the collection of objective and comparable AML/CFT-related data and information from obliged entities and enable an efficient and speedy exchange of information between supervisors and the Authority. The Authority shall endeavour to develop those tools as soon as the supervisory methodology is applicable across the entire AML/CFT supervisory system. 4.   The supervisory methodology shall reflect high supervisory standards at Union level and shall build on relevant international standards and guidance. The Authority shall periodically review and update its supervisory methodology, taking into account the evolution of risks affecting the internal market, including risks and threats identified by national law enforcement authorities and FIUs. The supervisory methodology shall, to the extent possible, take into account best practices and guidance developed by international standard setters.

Thematic reviews

Article 9

1.   No later than 1 December each year, supervisory authorities shall provide information to the Authority on supervisory reviews which they intend to carry out, on a thematic basis, during the following year or supervisory term and which aim to assess ML/TF risks or a specific aspect of such risks to which multiple obliged entities are exposed at the same time. The following information shall be provided: (a) the scope of each planned thematic review in terms of category and number of obliged entities included and the subject matter of the review; (b) the timeframe of each planned thematic review; (c) the planned types, nature and frequency of supervisory activities to be performed in relation to each thematic review, including any on-site inspections or other types of direct interaction with obliged entities, where applicable. 2.   By the end of each year, the Chair of the Authority shall present to the General Board in supervisory composition as referred to in Article 57(2) a consolidated planning of the thematic reviews that supervisory authorities intend to carry out during the following year. 3.   Where the scope and Union-wide relevance of thematic reviews justify coordination at Union level, they shall be carried out jointly by the relevant supervisory authorities and shall be coordinated by the Authority. The Executive Board may propose joint thematic reviews based on the available analyses of threats, vulnerabilities and risks in the internal market. The General Board in supervisory composition shall draw up a list of joint thematic reviews. The General Board in supervisory composition shall draw up a report relating to the conduct, subject matter and outcome of each joint thematic review. The Authority shall publish that report on its website. 4.   The Authority shall coordinate the activities of the supervisory authorities and facilitate the planning and execution of the joint thematic reviews referred to in paragraph 3. Any direct interaction with obliged entities other than the selected obliged entities in the context of any thematic review shall remain under the exclusive responsibility of the supervisory authority responsible for supervision of those obliged entities and shall not be construed as a transfer of tasks and powers related to those entities within the AML/CFT supervisory system. 5.   Where planned thematic reviews at national level are not subject to a coordinated approach at the level of the Union, the Authority shall, jointly with the supervisory authorities, explore the need for and the possibility of aligning or synchronising the timeframe of those thematic reviews, and shall facilitate information exchange and mutual assistance between supervisory authorities carrying out those thematic reviews. The Authority shall also facilitate any activities that the relevant supervisory authorities may wish to carry out jointly or in a similar manner in the context of their respective thematic reviews. 6.   The Authority shall ensure that the outcomes and conclusions of the thematic reviews conducted at national level by several supervisory authorities are shared with all supervisory authorities, with the exception of confidential information pertaining to individual obliged entities. Such sharing of information shall include any common conclusions resulting from exchanges of information or from joint or coordinated activities involving several supervisory authorities.

Mutual assistance in the AML/CFT supervisory system

Article 10

1.   The Authority may, as appropriate, develop: (a) new practical instruments and convergence tools to promote common supervisory approaches and best practices; (b) practical tools and methods for mutual assistance following: (i) specific requests from supervisory authorities; (ii) referral of disagreements between supervisory authorities on the measures to be taken jointly by several supervisory authorities in relation to an obliged entity. 2.   The Authority shall facilitate and encourage at least the following activities: (a) sectoral and cross-sectoral training programmes, including with respect to technological innovation; (b) exchanges of staff and the use of secondment schemes, twinning and short-term visits; (c) exchanges of supervisory best practices between supervisory authorities where one authority has developed expertise in a specific area of AML/CFT supervisory practices. 3.   Each supervisory authority may submit a request for mutual assistance related to its supervisory tasks to the Authority, specifying the type of assistance it seeks from the staff of the Authority, the staff of one or more supervisory authorities, or a combination thereof. If the request concerns activities that relate to the supervision of specific obliged entities, the requesting supervisory authority shall transmit to the Authority the information and data necessary for the provision of assistance. The Authority shall keep and regularly update the information on specific areas of expertise and on the capacities of supervisory authorities to provide mutual assistance related to their supervisory tasks. 4.   Where the Authority is requested to provide assistance for the performance of specific supervisory tasks at national level in relation to obliged entities other than selected obliged entities, the requesting supervisory authority shall detail, in its request, the tasks for which support is sought. The assistance shall not be construed as the transfer, from the requesting supervisory authority to the Authority, of supervisory tasks, powers, or accountability for the supervision of obliged entities other than selected obliged entities. 5.   Where the Authority is of the opinion that the request is appropriate and feasible, it shall make every effort to provide the requested assistance, including by mobilising its own human resources as well as by ensuring that supervisory authorities mobilise resources on a voluntary basis. 6.   By the end of each year, the Chair of the Authority shall inform the General Board in supervisory composition of the human resources that the Authority will allocate to providing the assistance requested under paragraph 3 of this Article during the following year. Where the availability of human resources changes due to the performance of any of the tasks referred to in Article 5(2), (3) and (4), the Chair of the Authority shall inform the General Board in supervisory composition thereof. 7.   Any interaction between the staff of the Authority and the obliged entity shall remain under the exclusive responsibility of the supervisory authority responsible for the supervision of that entity. Such interaction shall not be construed as a transfer of tasks or powers related to individual obliged entities within the AML/CFT supervisory system.

Central AML/CFT database

Article 11

1.   The Authority shall establish and keep up to date a central database of information pursuant to this Article. The Authority shall make the information available to supervisory authorities, non-AML/CFT authorities, other national authorities and bodies competent for ensuring compliance with Directive 2008/48/EC of the European Parliament and of the Council  ( 28 ) , Directive 2009/110/EC of the European Parliament and of the Council  ( 29 ) , Directive 2009/138/EC of the European Parliament and of the Council  ( 30 ) , Directive 2014/17/EU of the European Parliament and of the Council  ( 31 ) , Regulation (EU) No 537/2014 of the European Parliament and of the Council  ( 32 ) , Directive 2014/56/EU of the European Parliament and of the Council  ( 33 ) , Directive 2014/65/EU of the European Parliament and of the Council  ( 34 ) or Directive (EU) 2015/2366 of the European Parliament and of the Council  ( 35 ) , and to the European Supervisory Authorities, namely, the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA) and the European Insurance and Occupational Pensions Authority (EIOPA) (collectively, ‘the ESAs’), on a need-to-know and confidential basis, where it is necessary for the fulfilment of their tasks. The Authority shall also analyse the collected information and may share the results of its analysis on its own initiative with supervisory authorities, where to do so would facilitate their supervisory activities, and, where relevant, with obliged entities. 2.   The supervisory authorities shall transmit to the Authority at least the following information, including the data related to individual obliged entities, so that the Authority enters that information into the database: (a) a list of all supervisory authorities and self-regulatory bodies in their Member State entrusted with the supervision of obliged entities, including information about their mandate, tasks and powers and, where applicable, the identification of the leading supervisor or coordination mechanism; (b) statistical information about the categories and the number of supervised obliged entities per category in their Member State and basic information about the risk profile of those entities; (c) the administrative measures applied and pecuniary sanctions imposed in the course of supervision of individual obliged entities in response to breaches of AML/CFT requirements, accompanied by: (i) the grounds for applying the administrative measure or imposing the pecuniary sanction, such as the nature of the breach; (ii) related information on the supervisory activities and outcomes which led to the administrative measure being applied or the pecuniary sanction being imposed; (d) any advice or opinion related to ML/TF risks provided to other authorities in relation to authorisation procedures, withdrawal of authorisation procedures, and ‘fit and proper’ assessments of shareholders or members of the management body of individual obliged entities; (e) the outcomes of their assessments of the inherent and residual risk profiles of all credit institutions and financial institutions that meet the criteria set out in Article 12(1); (f) the outcomes and reports of thematic reviews and other horizontal supervisory actions with regard to high-risk areas or activities; (g) information regarding the supervisory activities they performed over the past calendar year, gathered pursuant to Article 40(5) of Directive (EU) 2024/1640; (h) statistical information about staffing and other resources of supervisors and supervisory authorities. The information provided pursuant to the first subparagraph shall not include references to specific suspicions reported pursuant to Article 69 of Regulation (EU) 2024/1624. The Authority shall also enter into the database the information stemming from its activities in the area of direct supervision which corresponds to the categories of information listed in the first subparagraph, as well as the outcomes of the risk assessment process carried out by the Authority pursuant to Article 12. 3.   The Authority may request supervisory authorities to provide other information in addition to that referred to in paragraph 2. The supervisory authorities shall update any provided information as soon as the update is necessary or at the Authority’s request. 4.   The Authority shall enter into the database any data or information relevant for the purposes of AML/CFT supervisory activities which is provided by non-AML/CFT authorities, other national authorities and bodies competent for ensuring compliance with the requirements of Directive 2008/48/EC, Directive 2009/110/EC, Directive 2009/138/EC, Directive 2014/17/EU, Regulation (EU) No 537/2014, Directive 2014/56/EU, Directive 2014/65/EU or Directive (EU) 2015/2366, or by the ESAs. The information referred to in the first subparagraph shall include instances where the authorities and bodies referred to in that subparagraph have reasonable grounds to suspect that ML/TF is being attempted or committed or that an increased risk thereof exists in connection with an obliged entity, and where such reasonable grounds arose in the context of the exercise of their respective tasks. The database shall also include relevant information which authorities or bodies supervising credit institutions in accordance with Directive 2013/36/EU of the European Parliament and of the Council  ( 36 ) , including the ECB when acting in accordance with Regulation (EU) No 1024/2013, have obtained, in the context of ongoing supervision, including information on business model assessments, assessments of governance arrangements, authorisation procedures, assessments of acquisitions of qualifying holdings, ‘fit and proper’ assessments and procedures related to the withdrawal of licences. 5.   The authorities and bodies referred to in paragraph 1, second subparagraph, may address to the Authority a reasoned request for information collected pursuant to this Article, if that information is necessary for their supervisory activities. The Authority shall assess those requests and provide the information requested on a need-to-know and confidential basis and in a timely manner. The Authority shall inform the authority or body that has initially provided the requested information of the identity of the requesting authority or body, the identity of any obliged entity concerned, the reason for the information request as well as whether the information has been provided to the requesting authority or body. Where the Authority decides not to provide the requested information, it shall provide a reasoned justification for that decision. 6.   The Authority shall develop draft regulatory technical standards specifying: (a) the procedure, formats and timelines for the transmission of information pursuant to paragraphs 2 and 3; (b) the scope and level of detail of the information to be transmitted, taking into account relevant distinctions between obliged entities, such as their risk profile; (c) the scope and level of detail of the information to be transmitted in relation to obliged entities in the non-financial sector; (d) the type of information the disclosure of which by the Authority, pursuant to a reasoned request or at its own initiative, requires the prior consent of the supervisory authority that originated it; (e) which level of materiality a breach needs to have in order for a supervisory authority to be obliged to transmit information on the breach pursuant to paragraph 2, point (c); (f) the conditions under which the Authority may request additional information pursuant to paragraph 3; (g) the types of additional information to be transmitted to the Authority pursuant to paragraph 3. The Authority shall submit those draft regulatory technical standards to the Commission by 27 December 2025. The Commission is empowered to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph in accordance with Article 49 of this Regulation. 7.   Personal data collected in accordance with this Article may be kept in an identifiable form for a period of up to 10 years after the date of collection of the data by the Authority, at the end of which those data shall be deleted. Based on a regular assessment of their necessity, personal data may be deleted before the expiry of that period on a case-by-case basis.

Back to Regulation (EU) 2024/1620 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next