EBA 2025 Opinion and Report on ML/TF risks affecting the EU financial sector
AML Agent page published: . Page updated: .
On 28 July 2025, the European Banking Authority published its fifth biennial Opinion on money laundering and terrorist financing risks affecting the EU financial sector, together with a detailed supporting report. Issued under Article 6(5) of Directive (EU) 2015/849, the Opinion is addressed to European co-legislators and AML/CFT competent authorities and is intended to inform risk-based supervision and the European Commission’s supranational risk assessment.
The assessment draws on information covering January 2022 to December 2024, including responses from 52 competent authorities across 29 EU and EEA countries, submissions to the EBA’s EuReCA database, supervisory reviews, peer reviews and work undertaken through AML/CFT supervisory colleges.
The EBA identifies a complex risk environment shaped by FinTech growth, poorly governed use of regulatory technology, increasing crypto-asset activity, AI-enabled fraud, terrorist financing, restrictive-measures compliance and persistent customer due diligence weaknesses. Risk trends differ materially by sector: controls and residual-risk outcomes improved in several established sectors, while payment institutions, life insurance undertakings and crypto-asset service providers showed increasing residual-risk concerns.
The Opinion is an authoritative risk and supervisory-policy assessment, but it is not legislation, binding guidance or a new compliance standard. Following the transfer of the EBA’s AML/CFT functions to AMLA on 1 January 2026, it remains an important pre-AMLA baseline for financial-sector risk assessments and future supervisory developments.
Key takeaways
- The document is the EBA’s fifth biennial ML/TF risk Opinion and is supported by data and supervisory evidence covering 2022–2024.
- Approximately 69% of competent authorities considered ML/TF risk associated with FinTech to have remained high or increased.
- EuReCA data identified 277 material weaknesses involving RegTech technologies, systems or tools among reported financial institutions during 2023 and 2024.
- The number of crypto-asset service providers licensed or registered under the then-applicable framework increased 2.5-fold to 2,525 by the end of 2024; this historical figure is not a count of CASPs authorised under MiCA.
- Terrorist-financing risk remained broadly stable but insufficiently addressed, including weaknesses in distinct TF risk assessments and transaction-monitoring scenarios.
- Customer due diligence remained the dominant source of AML/CFT breaches, accounting for 61% of breaches across the sectors assessed.
- The complexity of restrictive measures increased compliance risk, with weaknesses in governance, screening, record-keeping, list updates and alert handling.
- Residual-risk outcomes improved in several established sectors but deteriorated in payment institutions, life insurance undertakings and crypto-asset service providers.
What changed
The 2025 Opinion replaces the EBA’s 2023 Opinion as its latest biennial EU financial-sector ML/TF risk assessment. It updates the evidence base using data from 2022–2024 and gives substantially greater attention to technology-enabled business models, compliance tools and criminal methods.
The EBA identifies the pace of FinTech growth as a material concern where customer acquisition, cross-border expansion or outsourcing is not matched by appropriate AML/CFT governance, expertise and operational capacity. Particular risks arise from white-labelling arrangements, virtual IBANs and increasing interconnection between traditional financial institutions and innovative providers.
RegTech is treated as both an opportunity and a source of risk. The report identifies insufficient vendor oversight, automated controls used without adequate safeguards, weak testing, limited explainability, poor calibration and shortages of relevant in-house expertise.
Crypto-asset risks remain high. The EBA records rapid growth in provider numbers and transaction activity, alongside deficiencies in customer and beneficial-owner verification, business-wide and customer risk assessment, senior-management integrity and governance. It also identifies increasing connections between CASPs, payment institutions, e-money institutions and other financial services.
The assessment gives increased prominence to AI-enabled fraud, deepfakes, remote-onboarding attacks, instant payments, payment-card infrastructure and the use of stablecoins in terrorist financing and other illicit activity. It also highlights continuing shortcomings involving PEPs, corruption, sanctions implementation, transaction monitoring and suspicious-transaction reporting.
Supervisory engagement increased over the assessment period. Off-site reviews rose by approximately 41% between 2022 and 2024, while on-site inspections remained an important tool for higher-risk sectors and activities.
Why it may matter
The Opinion provides an authoritative evidence base that financial institutions and advisers can consider when maintaining business-wide and customer-level ML/TF risk assessments. Its findings may also indicate areas likely to attract supervisory scrutiny, particularly where firms rely on innovative technology, cross-border delivery models or outsourced compliance functions.
The report reinforces that purchasing or deploying RegTech does not transfer responsibility for compliance. Institutions remain responsible for governance, data quality, model and system calibration, explainability, validation, alert handling, staffing and oversight of third-party providers.
Payment institutions, e-money institutions and CASPs may face particular scrutiny because the report identifies elevated inherent or residual risks, rapid market growth and uneven maturity of AML/CFT systems and controls. Traditional institutions should also assess spillover risks arising from acquisitions, partnerships, outsourcing and exposure to these sectors.
The findings on terrorist financing caution against treating sanctions-list screening as a complete TF control. The EBA distinguishes the detection of terrorist financing from compliance with targeted financial sanctions and identifies weaknesses in TF-specific risk assessments and monitoring scenarios.
The report should be treated as a risk and supervisory reference rather than a source of new legal duties. Institution-specific action should remain proportionate to the firm’s activities, customers, delivery channels, geographical exposure and applicable legal obligations.
Who may be affected
The Opinion is relevant across the financial sectors examined by the EBA, although its findings and risk ratings vary by sector and should not be applied indiscriminately.
Credit institutions—including neobanks and institutions acquiring or partnering with FinTech businesses—may be affected by the findings on technology governance, customer due diligence, transaction monitoring, remote onboarding and cross-sector spillover risk.
Payment institutions and e-money institutions are particularly relevant because of their exposure to cross-border services, agent or partner arrangements, virtual IBANs, instant payments, card infrastructure, outsourcing and technology-enabled delivery models.
CASPs, issuers of e-money tokens and financial institutions exposed to crypto-assets should consider the findings on customer and beneficial-owner identification, self-hosted wallets, crypto-to-fiat services, governance, authorisation and terrorist-financing risk.
The assessment also covers investment firms, collective investment undertakings, fund managers, credit providers, bureaux de change, life insurance undertakings and life insurance intermediaries. Supervisors and policymakers are the Opinion’s principal institutional addressees.
The report concerns the EU financial sector. It should not be presented as a risk assessment of non-financial obliged entities or DNFBPs.
Practical considerations
- Compare the report’s findings with the institution’s current business-wide ML/TF risk assessment and document whether each material risk is applicable.
- Review whether product and service risk assessments address FinTech models, white labelling, virtual IBANs, instant payments, crypto-assets and other technology-enabled delivery channels where relevant.
- Assess RegTech governance, including vendor due diligence, data quality, testing, calibration, explainability, change control, performance monitoring and accountable internal ownership.
- Confirm that growth, acquisitions and cross-border expansion are supported by sufficient AML/CFT staffing, expertise, governance and alert-handling capacity.
- Test the effectiveness—not merely the existence—of customer identification, beneficial-owner verification, customer risk rating, ongoing monitoring and transaction-monitoring controls.
- Assess terrorist-financing risk separately from money-laundering risk and avoid relying solely on targeted-financial-sanctions screening as a TF control.
- Review remote-onboarding and fraud controls against deepfakes, falsified documents, account takeover, money-mule activity and other AI-enabled threats.
- Evaluate direct and indirect exposure to CASPs, stablecoins, self-hosted wallets and crypto-to-fiat services, including exposure arising through groups, customers or outsourced arrangements.
- Review restrictive-measures governance, screening thresholds, list-update frequency, record-keeping, alert escalation and responsibility for freezing or rejecting transactions.
- Compare internal sector and customer risk ratings with the EBA’s findings and retain documented reasons for material differences.
- Monitor AMLA publications for successor risk assessments or guidance and update the analysis when the 2025 EBA baseline is overtaken.
These considerations support professional review and do not constitute legal advice.