AMLA RTS Open Source monitoring active

Consultation on the draft Regulatory Technical Standards on cross-border information exchange between Financial Intelligence Units

AML Agent page published: . Page updated: .

AMLA is consulting on draft Regulatory Technical Standards under Article 31(3) of Directive (EU) 2024/1640. The draft specifies how Financial Intelligence Units should determine whether a report of suspicions submitted under Article 69(1) of Regulation (EU) 2024/1624 concerns another Member State and should be transmitted as a cross-border report or cross-border dissemination.

The proposal introduces harmonised, structured and largely automatable selection criteria, supported by FIU.net and its matching functionality. It distinguishes the responsibility of the transmitting FIU to identify cross-border connections from the responsibility of the receiving FIU to assess whether a cross-border dissemination is relevant. The rules are principally directed at FIUs and do not impose direct obligations on private companies, although they may affect how information submitted by obliged entities is routed and analysed across the EU.

Key takeaways

  • The draft distinguishes cross-border reports (XBRs) from cross-border disseminations (XBDs) and establishes separate selection criteria for each.
  • For XBRs, the receiving Member State would generally be identified from the customer’s residence or place of business, with specified fallback criteria.
  • For XBDs, transmission would be triggered by qualifying links involving a primary subject, an associated financial asset or a full positive FIU.net matching hit.
  • A primary subject includes a reported victim or alleged perpetrator, an account holder, or a subject with a financial ranking of at least 3 under Annex I.
  • An XBD based on a person or legal entity would require minimum identifying information before it could be transmitted.
  • The transmitting FIU would apply the selection criteria, while the receiving FIU would assess relevance using its domestic risk framework and potentially an FIU.net scorecard.
  • The draft coordinates cases where the same suspicion report results in both an XBR and one or more XBDs.
  • The draft proposes application from 10 July 2027 and implementation and use of the FIU.net Ma³tch functionality by FIUs by 10 July 2028.

What changed

Article 31(1) of Directive (EU) 2024/1640 already requires an FIU that receives a report of suspicions concerning another Member State to promptly forward the report or the relevant information to that Member State’s FIU. The draft RTS would specify the previously undefined relevance and selection criteria used to determine when that obligation is triggered and where the information should be sent.

The proposal replaces reliance on heterogeneous national practices and operational discretion with harmonised criteria based primarily on structured data. It formally distinguishes a cross-border report, or XBR, from a cross-border dissemination, or XBD, and establishes different routing rules for each.

For XBRs, customer location is the primary criterion, followed by ordered fallback criteria such as nationality, country of birth, registered office or country of creation. For XBDs, the draft introduces tiered criteria covering natural persons, legal persons, associated financial assets and full positive FIU.net matching hits. It also requires certain minimum identifying data to be available before an XBD is sent.

The proposal allocates the initial selection decision to the transmitting FIU but leaves the assessment of an XBD’s actual relevance to the receiving FIU. Receiving FIUs may use risk scorecards reflecting national risks, transaction values, predicate offences, indicators, negative open-source intelligence, sanctions links and ongoing investigations.

Why it may matter

If adopted substantially as drafted, the RTS would materially affect how FIUs identify, route, prioritise and follow up on suspicious activity with links to more than one EU Member State. Common selection criteria could reduce inconsistent national approaches and information gaps, while the minimum-data requirements and relevance assessment are intended to limit unnecessary sharing of personal data.

The proposal is also operationally significant because it relies on structured data and automation within FIU.net. FIUs may need to update routing logic, data mappings, matching processes, risk scorecards, case-management workflows and arrangements for requesting complete information after an XBD is assessed as relevant.

The RTS does not itself impose direct obligations on private companies. Nevertheless, banks, payment institutions, electronic money institutions, crypto-asset service providers and other obliged entities should monitor it alongside the related reporting-format standards under Article 69(3) AMLR. The quality and structure of information provided in a report of suspicions may affect whether the report is automatically identified as cross-border and transmitted to another FIU.

Who may be affected

Banks and credit institutionsCrypto-asset service providersPSPs and EMIsInvestment firmsInsurersDNFBPsGroups and branchesLegal and compliance advisersFinancial Intelligence UnitsSupervisory authoritiesOther affected stakeholders

Financial Intelligence Units are the principal affected authorities. The draft would affect transmitting and receiving FIUs, including their operational analysts, legal teams, data-protection specialists, FIU.net administrators, technology teams and staff responsible for international cooperation.

AMLA and national public authorities involved in FIU cooperation may also be affected through the operation of FIU.net, development of the proposed scorecard mechanism and implementation of the Ma³tch functionality. Supervisory authorities may need to understand how reports from supervised obliged entities are subsequently routed and used across borders.

Obliged entities are not subject to direct requirements under this draft RTS. However, banks, payment service providers, electronic money institutions, crypto-asset service providers, investment firms, insurers, DNFBPs and cross-border groups may be indirectly affected because their reports of suspicions provide the structured information used by FIUs to apply the proposed criteria. Legal and compliance advisers may therefore need to consider the RTS together with the related AMLR reporting-format requirements.

The proposal is particularly relevant where an obliged entity operates across borders, provides services into another Member State, or submits reports involving customers, subjects, accounts or financial assets connected with multiple Member States.

Practical considerations

  • FIUs should map the proposed XBR and XBD criteria against their existing cross-border routing rules and identify implementation gaps.
  • FIUs should test whether customer residence, place of business and the specified fallback data can be extracted reliably from structured suspicion reports.
  • XBD workflows should verify that the required minimum identifying information is available before information is transmitted.
  • FIUs should assess how primary subjects and the Annex I financial ranking would be calculated consistently and automatically.
  • Receiving FIUs should consider how national risk assessments and operational priorities would be reflected in an XBD risk scorecard.
  • Technology teams should assess the required FIU.net integration, automated routing and Ma³tch functionality.
  • Operational procedures should address simultaneous XBR and XBD transmissions and preserve the FIU receiving the XBR as the relevant coordination point.
  • FIUs should involve data-protection and information-security specialists when assessing automated matching and cross-border transmission controls.
  • Obliged entities should monitor the related Article 69(3) AMLR reporting-format standards but should not treat this consultation draft as creating a new reporting duty.
  • Interested stakeholders should consider responding on proportionality, the allocation of relevance assessment to receiving FIUs and the proposed definition of a primary subject.
  • The final report and adopted Commission Delegated Regulation should be checked for changes to the criteria, application date and Ma³tch deadline.

These considerations support professional review and do not constitute legal advice.

AMLD 31(3)Article 31(3) of Directive (EU) 2024/1640Directive (EU) 2024/1640Article 31(1), third subparagraph, of Directive (EU) 2024/1640Article 30(4) of Directive (EU) 2024/1640Article 31(2) of Directive (EU) 2024/1640Article 69(1), first subparagraph, point (a), of Regulation (EU) 2024/1624Article 69(3) of Regulation (EU) 2024/1624Article 22(1)(a)(iv) and Article 22(1)(b)(ii) of Regulation (EU) 2024/1624

Official sources