Back

23 July 2026 — Consultation Response

AMLA draft guidelines on business-wide risk assessment

Accountancy Europe has submitted feedback on the EU Anti-Money Laundering Authority’s (AMLA) draft Guidelines on business-wide risk assessment (BWRA) under Article 10(4) of Regulation (EU) 2024/1624.

In its submission, Accountancy Europe supports the objective of establishing common expectations for business-wide risk assessments and recognises the importance of a risk-based approach. However, it does not consider that the draft Guidelines consistently reflect a proportionate approach across the wide range of obliged entities covered by the AMLR, particularly smaller non-financial obliged entities.

Accountancy Europe highlights several key recommendations in its submission, in particular:

Putting proportionality into practice:

Although the draft Guidelines recognise proportionality, the detailed expectations should be applied with sufficient flexibility to reflect the wide range of obliged entities covered by the AMLR.

Accountancy Europe recommends placing greater emphasis on the obliged entity’s risk profile and business model, rather than size alone, when applying proportionality. It also calls for greater clarity on how the risk-based approach should be applied in practice, including how the scope, depth, documentation and frequency of the business-wide risk assessment should vary according to the obliged entity’s ML/TF risk profile.

Making business-wide risk assessments workable:

The expectation to establish and document a detailed business-wide risk assessment methodology is disproportionate for many smaller obliged entities. The draft Guidelines combine detailed lists of matters to be considered with relatively limited practical guidance on how these should be reflected in the business-wide risk assessment, creating a risk of inconsistent implementation.

Accountancy Europe recommends clarifying that a documented methodology should be expected only where justified by the nature, size and complexity of the obliged entity. The Guidelines should more clearly recognise the use of appropriately adapted sectoral templates rather than expecting smaller obliged entities to develop methodologies from first principles.

Risk-based use of information sources:

The draft Guidelines should provide greater clarity on how the proposed sources of information are intended to be applied in practice.

Accountancy Europe recommends clarifying that obliged entities should determine, on a risk-based basis, which information sources are appropriate to their sector, business model and ML/TF risk profile, and that the list of additional information sources is neither cumulative nor intended to create an expectation that every obliged entity monitor all such sources on an ongoing basis.

Supporting effective implementation:

Accountancy Europe recommends that the Guidelines be accompanied by practical guidance to support consistent implementation. Without such guidance, obliged entities and supervisors are likely to develop divergent interpretations, undermining the Guidelines’ objective of promoting harmonised implementation and supervisory convergence.

Accountancy Europe also reiterates that obliged entities should be given sufficient time to prepare for the new requirements through timely publication of Level 2 and Level 3 measures together with appropriate transitional arrangements.