Consultation on the draft ITS on the format for reporting suspicions and providing transaction records
AML Agent page published: . Page updated: .
AMLA consulted on draft Implementing Technical Standards under Article 69(3) of Regulation (EU) 2024/1624. The consultation closed on 20 September 2026. The proposal specifies the formats that obliged entities would use to report suspicions under Article 69(1)(a) AMLR and that credit and financial institutions would use to provide transaction records requested by Financial Intelligence Units under Article 69(1)(b).
The proposed framework combines a common set of EU data points with templates adapted to different types of obliged entities and reported activity. Data points may be mandatory, technically required, mandatory if available, optional, dependent or required by an individual FIU. Reports would generally be submitted electronically in a machine-readable format through FIU reporting platforms.
For transaction records, the draft provides separate templates covering banking and payment activities, money remittance, crypto-asset services and correspondent services. The proposal is intended to improve reporting consistency, data quality and cross-border FIU analysis, while retaining limited flexibility for national requirements and sector-specific information.
Key takeaways
- The draft ITS would create a more standardised EU framework for reports of suspicions and transaction records submitted to Financial Intelligence Units.
- All obliged entities would use reporting templates adapted to their activity and the nature of the suspicion being reported.
- The framework distinguishes mandatory, technically required, mandatory-if-available, optional, dependent and FIU-required data points.
- A missing technically required data point could prevent a report of suspicions from passing the FIU platform’s validation checks.
- Reports of suspicions would generally be transmitted electronically in a machine-readable format, although the ITS does not prescribe one EU-wide technical language or file format.
- Credit and financial institutions would use activity-specific transaction-record templates covering banking, money remittance, crypto-assets and correspondent services.
- The interpretative note provides technical specifications and reporting guidance but expressly does not create or replace legally binding requirements.
- The final application and implementation dates remain undetermined, with the draft proposing a phased assessment and technical-implementation process.
What changed
Current suspicion-reporting formats and transaction-record requirements differ significantly between Member States and FIUs. Cross-border obliged entities may therefore need different reporting structures for different jurisdictions, while FIUs receive information with inconsistent terminology, granularity and technical formats.
The draft ITS introduces a common core set of defined data points, supplemented by limited sector-specific and FIU-required information. Instead of one universal template, the proposal uses templates adapted to the reporting entity’s activity and the type of suspicion. This is intended to avoid requiring non-financial obliged entities to provide financial-sector information that they would not ordinarily hold.
The proposal also formalises different treatments for individual data points. Some would be systematically mandatory; technically required data could prevent submission if absent; mandatory-if-available data would be required only where held; optional data could be provided where relevant; dependent data would arise only when a specified condition is met; and FIU-required data could reflect justified national requirements.
Reports of suspicions would generally be submitted electronically in machine-readable form through FIU platforms. Transaction records requested from credit and financial institutions would also be machine-readable and would follow activity-specific templates.
The draft adds formal data-quality requirements, a phased implementation process, periodic review of the annexed data points and a mechanism allowing FIUs to introduce temporary data points in response to urgent events, emerging risks or legal changes.
Why it may matter
This proposal may require significant changes to the reporting processes, data models and technology used by obliged entities and FIUs. Firms may need to map existing reporting fields against the new templates, identify data gaps, revise internal escalation and report-preparation procedures, build validation controls, train staff and update connections with national FIU portals.
Cross-border financial groups may benefit over time from greater consistency between Member States. However, the preferred approach still allows limited FIU-required and national data points, meaning that complete uniformity is not guaranteed. Groups should therefore distinguish the proposed common core from any additional national requirements.
The proposal is particularly significant for non-financial obliged entities and newly regulated sectors. AMLA has chosen sector-adapted templates rather than imposing a large, finance-centred template on every reporting entity. This may improve usability, but firms will still need to determine which fields are mandatory, applicable or available for their particular business and report.
Credit institutions, financial institutions, payment firms, money-remittance providers and crypto-asset service providers face an additional impact from the proposed transaction-record templates. They may need to extract complete, consistent and machine-readable transaction data within the deadlines imposed by an FIU.
Because reports contain personal, financial and potentially criminal-allegation data, implementation will also require careful attention to data minimisation, purpose limitation, information security, accuracy and access controls.
Who may be affected
All obliged entities within the scope of Article 3 of Regulation (EU) 2024/1624 may be affected by the proposed formats for reporting suspicions. This includes banks, credit institutions, payment and electronic money institutions, investment firms, insurers, crypto-asset service providers and the broad range of non-financial obliged entities.
The non-financial population includes auditors, accountants, tax advisers, notaries and legal professionals when acting within the regulated activities, trust and company service providers, estate agents, gambling providers, traders and intermediaries in relevant high-value or cultural goods, crowdfunding providers, credit intermediaries, investment migration operators and other entities included by the AMLR or national law. Football agents and professional football clubs enter the AMLR framework on the later timetable specified in Article 90 AMLR.
Credit and financial institutions are additionally affected by the proposed templates for providing transaction records. The templates cover banking and payment activities, money-remittance services, crypto-asset services and correspondent services.
Financial Intelligence Units would need to assess the core data set, perform gap analyses, adapt national reporting and analytical platforms, establish validation and data-quality controls and participate in the AMLA-coordinated review process.
Compliance officers, money-laundering reporting officers, legal teams, operations teams, data owners, technology teams, privacy specialists, reporting-platform providers and external advisers may all be involved in implementation. Third-country groups with EU-regulated subsidiaries or branches should assess the requirements applicable to those EU entities.
Practical considerations
- Map every existing suspicion-reporting field against the applicable Annex I template and record any missing or differently defined data.
- Identify the correct sector-specific template for each regulated activity carried out by the organisation.
- Classify each data point as technically required, mandatory, mandatory if available, optional, dependent or FIU-required.
- Document data ownership, source systems, availability, quality and permissible use for every reportable data point.
- Assess whether internal reporting systems can generate machine-readable reports and satisfy FIU validation, consistency and plausibility checks.
- Entities generating reports through internal systems should evaluate the integration work required; entities relying on FIU portals should assess how the revised forms affect manual reporting workflows.
- Credit and financial institutions should separately map the transaction-record templates for banking, payments, money remittance, crypto-assets and correspondent services.
- Review procedures for providing supporting documents and ensure that attachments do not introduce unnecessary or irrelevant personal data.
- Plan for the reporting language required by each competent FIU and any remaining FIU-specific or national data points.
- Update governance, staff training, report-review controls and technical testing plans once the final data set and implementation timetable are known.
- Build change-management processes capable of handling the four-year review cycle and urgent temporary data points introduced by FIUs.
These considerations support professional review and do not constitute legal advice.