Resources

The EU AML Regulation 2027: a plain-language briefing for UK law firms with EU offices

Take a single client. A corporate entity, one shareholder holding exactly 25%. Your London office onboards it and finds no beneficial owner. Your Frankfurt office onboards the same entity, same structure, same day and finds one. Neither office is wrong. The files disagree because the law does.

This is the position facing UK law firms with EU offices from 10 July 2027. On that day, the EU's Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, takes direct effect across all 27 member states. London stays under the UK Money Laundering Regulations 2017. One firm, two rulebooks. For clients with a presence on both sides, both rulebooks apply to the same file.

Most coverage of AMLR reads it as a countdown: a big new regulation, a deadline, get ready. That framing misses the harder problem. AMLR is not obviously stricter than the UK regime. It diverges from it in small, specific ways, and those differences stay invisible until a file is pulled for audit. A one-point gap in a threshold. A country on one list and not the other. A monitoring duty nobody's system was built to meet.

AMLR is a regulation, so there is no softer jurisdiction left

The first thing to understand is what kind of law this is. AMLR is a regulation, not a directive. It applies directly in every member state with no national transposition and no member state discretion on the core obligations. That is the deliberate point of the 2024 package: to close the gaps that opened when AMLD4 and AMLD5 were transposed differently in each country.

The practical consequence for a multi-office firm is blunt. There is no longer a member state with a lighter local implementation to route work through. Every EU office conducting corporate, transactional, real estate, or funds work is an obliged entity from 10 July 2027, supervised by its national bar association. The new EU authority, AMLA, sets the technical standards those supervisors apply but does not directly supervise law firms; its direct supervision is limited to a small group of the highest-risk financial institutions. So the rulebook is uniform, the supervisor is local. However, the national regulators that will apply AMLR have not yet said how they will interpret it. A uniform text does not mean uniform enforcement on day one. One practitioner we spoke to put it well: same game, different referees.

The danger is divergence, not severity

The reason this is hard is not the volume of new rules. It is that a UK-calibrated framework produces the wrong answer in an EU office on specific points, while looking entirely correct.

Beneficial ownership is the cleanest example. UK MLRs capture an individual holding more than 25% (Regulation 5). AMLR captures 25% or more (Article 52).  An individual holding exactly 25% is a beneficial owner in Frankfurt and not in London, which is how the same four-equal-shareholder structure produces different UBO findings in two offices. AMLR also runs a more prescriptive, role-based model for trusts (Article 58): settlor, trustee, protector, beneficiaries and anyone exercising ultimate control, with no percentage test at all. A single trust CDD template applied across both jurisdictions will not hold.

Politically exposed persons (PEPs) is the divergence that is actively widening. The UK has moved toward proportionality: FCA guidance FG25/3, finalised in July 2025, sets a starting presumption that UK domestic PEPs are lower risk than foreign PEPs, and the SRA, which supervises most law firms for AML, reflects the same proportionate direction. AMLR moves the other way. It treats domestic and foreign PEPs identically, sets a minimum 12-month enhanced due diligence period after a person leaves office (Article 45) and defines the PEP population more broadly, capturing heads of regional and local authorities in areas of at least 50,000 inhabitants (Article 2(1)(34)) and adding siblings of heads of state, government and ministers as family members. The same regional official job title may get proportionate treatment in London and mandatory EDD in Frankfurt. Two offices, two correct answers, one individual.

Ongoing monitoring is where the divergence stops being a policy question and becomes an architecture one. AMLR Article 26 attaches monitoring to the business relationship, not the matter. It prohibits monitoring products or service lines in isolation: where a client spans corporate, disputes or real estate work, the monitoring must see all of it as one picture. It requires information held by other group entities about a shared client to be actively used, not merely available. And it requires an intermediate assessment outcome between "close the alert" and "file a report" (Article 26 read with Article 69(2)), which makes a binary file-or-close workflow non-compliant. A firm running matter-level compliance with no aggregated client view cannot meet this by rewriting a policy. It is a systems problem.

The group dimension makes that systems point sharper. AMLR treats a firm and its offices as a single group and imposes group-wide obligations: a duty to share information relevant to CDD and risk management, including beneficial ownership detail and suspicions, across group entities where it bears on the assessment of a shared client (Article 16), subject to confidentiality and data-protection guardrails on what is shared. It also expects a consolidated, group-level risk assessment rather than a set of siloed per-office ones. Whether a UK head office is itself directly caught by these provisions is still subject to pending AMLA guidance, and the position may turn on where the group is domiciled. But the operational direction is already clear: an ownership change flagged in Frankfurt has to be usable by the monitoring function in Paris, and no firm running office-level systems with no shared client view meets that on day one. 

Those are three. There are more, and they matter: CDD triggers drop to EUR 10,000 for occasional transactions with a EUR 3,000 cash identification trigger (Article 19); sanctions screening moves inside CDD as a documented step rather than a parallel check (Articles 9 and 20); enhanced due diligence becomes non-substitutable once triggered, with new high-value thresholds at EUR 5 million in personalised services and EUR 50 million in total assets (Article 34). And AMLR carries obligations with no UK equivalent at all: a EUR 10,000 cash payment ceiling, lower in some states (France and Spain sit near EUR 1,000) under Article 80; a prohibition on new bearer shares with existing ones to be converted or immobilised by 10 July 2029 (Article 79); discrepancy reporting to beneficial ownership registers within 14 days (Article 24); and integrity assessments for compliance staff (Article 13).

The choice every firm has to make 

Faced with two rulebooks on one file, a firm has a strategic decision, not just a compliance task. It can calibrate one global process to the higher standard and accept over-compliance in London on some points. It can run two genuinely separate standards, which is legally precise but demands jurisdiction-specific system configuration, training and governance across every EU office. Or it can phase: the higher-standard process as an interim while it builds toward the accurate dual model.

Each path has a different cost and a different deliverability by July 2027. What none of them tolerates is drift, where relationship ownership across offices decides which regime applies by accident rather than design.

Waiting for the final text is the understandable instinct and the risky one

The natural response and the one many firms and their advisers are taking is to wait for the final regulatory technical standards before changing anything. It is a defensible position for the settings that a policy update can fix later. It is a dangerous one for the items that cannot be retrofitted at speed: cross-matter client aggregation, jurisdiction-specific rule configuration, CDD record-age tracking, re-screening triggered by list changes rather than the calendar. Those are build decisions. Starting them in 2027 is starting too late.

The regulation is fixed. The date is fixed. What is still moving is the detail beneath them, and the firms that treat the architecture as a 2026 project rather than a 2027 one are the firms that will not be remediating live files after the deadline.

That client, the one with a single 25% shareholder, is still sitting in two offices' systems, correctly onboarded twice, with two different answers on file. We have set out the full divergence map, the client-journey friction points and the three architecture models in a longer companion piece. It is the practical next step for closing that gap before an auditor finds it and for anyone who has read this far and recognised their own firm in it.


About First AML

First AML comes from the perspective of both a technology provider, but also as compliance professionals. Prior to releasing, First AML’s all-in-one AML workflow platform, we processed over 2,000,000 AML cases ourselves. Understanding the acute problem that faces firms these days as they try to scale their own AML, is in our DNA.

That's why First AML now powers thousands of compliance experts around the globe to reduce the time and cost burden of complex and international entity KYC. First AML stands out as a leading solution for organisations with complex or international onboarding needs. It provides streamlined collaboration and ensures uniformity in all AML practices.

Keen to find out more? Book a demo today!

Related