The European AML/CFT framework is entering a new phase. From 10 July 2027, the EU Anti-Money Laundering Regulation (AMLR) will apply to most obliged entities across Member States, introducing a more harmonised set of AML/CFT requirements. In Malta, the EU term “obliged entities” broadly corresponds to persons currently referred to as “subject persons”, although the scope is not identical.
For Maltese obliged entities, the impact will extend across several core areas, including governance, customer due diligence, beneficial ownership, risk assessment, onboarding, internal controls and, where relevant, group-wide arrangements. With the July 2027 application date approaching, the practical implementation window is becoming shorter. Obliged entities that have not yet assessed the impact of the new framework may find themselves having to update policies, revise governance structures, remediate customer files, amend systems and train staff within a compressed timeframe.
A More Harmonised European Standard
The new framework is intended to reduce differences in how AML/CFT obligations are interpreted and applied across Member States. Obliged entities will therefore increasingly need to assess their compliance arrangements against a common European standard, rather than relying solely on existing national practices.The regulatory detail is also becoming clearer. On 1 October 2026, AMLA finalised three sets of draft Regulatory Technical Standards covering customer due diligence, the identification of business relationships, occasional and linked transactions, and group-wide AML/CFT arrangements. The final drafts have now been submitted to the European Commission for adoption. The direction of the new requirements is already sufficiently clear for obliged entities to begin assessing their impact. Waiting for every technical detail to be finalised risks compressing the time available to address gaps that may require changes to systems, processes or existing customer files.
Governance and Accountability Will Require Attention
One of the more significant developments concerns governance. The AMLR requires obliged entities to designate a member of the management body as the compliance manager, placing formal responsibility for AML/CFT compliance at management-body level. The compliance manager will be responsible for ensuring that internal policies, procedures and controls are consistent with the entity’s risk exposure and are effectively implemented, and that sufficient human and material resources are allocated to the compliance function.The Regulation also requires the appointment of a compliance officer responsible for the policies, procedures and controls involved in the day-to-day operation of the AML/CFT framework, acting as a contact point for competent authorities and reporting suspicious transactions to the FIU. For Maltese obliged entities, this function largely aligns with responsibilities currently associated with the MLRO. Where the nature of the business, its risks and complexity, and its size justify it, the compliance manager and compliance officer functions may be performed by the same individual.
For many obliged entities, the issue will therefore go beyond whether these functions already exist in practice. The key question will be whether responsibilities are clearly allocated, properly documented and supported by adequate authority, reporting lines and resources.
Beneficial Ownership and CDD Could Drive Remediation
Beneficial ownership is another area where the new framework may have a significant operational impact. Under the AMLR, an ownership interest is established through direct or indirect ownership of 25% or more of shares, voting rights or other ownership interests. This differs from the familiar “more than 25%” threshold, meaning that ownership of exactly 25% will fall within scope. The Regulation also introduces more detailed rules for calculating indirect ownership and requires control to be assessed alongside ownership.Customer due diligence is also becoming more standardised and more detailed. The emerging requirements address the information that must be collected and verified, non-face-to-face verification, electronic identification and the application of CDD measures according to risk. Depending on the business model, implementation could affect onboarding procedures, customer data requirements, systems, external providers and existing customer files.
The Risk Is No Longer Only Regulatory
The greatest risk in delaying preparation is increasingly operational. Gaps identified now can still be prioritised and addressed through a controlled remediation programme. Gaps identified in the final months will compete for the same resources as system changes, customer outreach, policy revisions, governance changes, staff training and ongoing business requirements.For organisations with substantial customer portfolios, remediation can quickly become resource intensive. Reviewing large numbers of files, obtaining updated beneficial ownership information or modifying onboarding processes takes time, particularly where customers do not respond promptly or complex structures require further analysis.
The regulatory environment is also becoming more demanding. The new EU framework provides for significant sanctions in cases involving serious, repeated or systematic breaches of key AML/CFT obligations. This further increases the importance of being able to demonstrate that gaps have been identified, assessed and addressed in a timely manner.
How BDO Malta Can Help
The question for boards, partners, MLROs and compliance teams should therefore be straightforward: if your AML/CFT framework were assessed against the incoming requirements today, where would the gaps be?BDO Malta’s AML/CFT 2027 Readiness & Gap Assessment is designed to answer that question. The assessment reviews the areas most likely to be affected by the new framework, including governance, compliance manager and MLRO/compliance officer arrangements, business-wide risk assessments, AML/CFT policies and procedures, customer due diligence, onboarding and verification processes and, where relevant, group-wide controls.
The outcome is a practical report identifying where the existing framework is already aligned, where changes are required and which actions should be prioritised ahead of July 2027. Where relevant, this can be supported by targeted AML/CFT training to help boards, management, MLROs and relevant staff understand the new requirements, their responsibilities and the practical changes required within the organisation. For obliged entities that have not yet assessed their readiness, the remaining period should be treated as an implementation window, as 10 July 2027 is the date by which the framework needs to be ready and embedded across the organisation. It should not be the date preparation begins.

