AMLD6 for Fintechs: What Actually Changes in 2026 and How to Prepare

From 22 predicate offences to corporate liability up to 5% of global turnover — a plain-English breakdown of AMLD6 obligations and what they mean for your engineering team.

AMLD6 for Fintechs: What Actually Changes in 2026 and How to Prepare

The Sixth Anti-Money Laundering Directive (AMLD6, Directive (EU) 2024/XXXX) entered into force on 7 January 2025. Member states have until 7 January 2027 to transpose it into national law. That means the clock is running and your legal team needs to be working now.

This post cuts through the jargon. Here's what actually changes, what's harder to comply with, and what your engineering team needs to build.


What Is AMLD6?

AMLD6 is the sixth iteration of the EU's anti-money laundering directive framework. It replaces AMLD5 (2018/843) and does three things that matter for fintech operators:

1. **Criminalizes new and expanded predicate offences** — making it easier to prosecute money laundering
2. **Tightens corporate liability** — making it a criminal matter for your company, not just individuals
3. **Updates the Travel Rule** — expanding its scope to more crypto asset transfers

It also paves the way for the AMLA Regulation (2024/... on the establishment of the EU Anti-Money Laundering Authority), which creates a new supranational supervisor for high-risk entities from 2027.


The Predicate Offence Expansion: 22 Offences Now

AMLD6 Art. 3 lists **22 predicate offences** — the underlying crimes that create money laundering liability. The key changes from AMLD5:

**What's new or expanded:**

**What this means in practice:** Your transaction monitoring system needs to flag transactions linked to any of these 22 categories. For crypto operators, the cybercrime and insider trading expansions are the most operationally significant.


Corporate Liability: Up to 5% of Global Turnover

This is the change that gets board attention.

AMLD6 Art. 6 introduces **direct corporate criminal liability** for money laundering — not just for individuals. If a director, officer, or employee commits a money laundering offence "for the benefit of" the legal entity, the entity itself is criminally liable.

The penalties:

| Threshold | Fine |
|---|---|
| Minimum floor | €5,000,000 |
| Maximum for serious offences | Up to **5% of total worldwide annual turnover** (or €40,000,000, whichever is higher) |

For a fintech with €50M annual revenue, that's a potential **€2.5M fine**. For a company with €200M revenue, it's €10M.

This makes D&O insurance coverage review urgent. Your insurance broker needs to know about the corporate liability provisions. Many existing policies don't cover administrative sanctions arising from criminal proceedings.


The Travel Rule — More Transfers, More Data

The Travel Rule (AMLD6 Art. 5, building on AMLD4's Art. 8) requires financial institutions and CASPs to collect, transmit, and retain originator and beneficiary information for transfers.

**What's changing:**

Crypto asset transfer threshold drops to **€0**

Under the AMLD5 implementation, many member states applied the Travel Rule only above €1,000. AMLD6 removes this threshold for crypto asset transfers — every single on-chain transaction between two CASPs (or a CASP and a bank) must carry originator and beneficiary information.

The beneficiary data must be stored

Both originator and beneficiary data must be retained for **5 years** after the transaction. Your database schema needs to accommodate this, and your data retention policy must reflect it.

Cross-border transfers to high-risk third countries

If you're sending a transfer to a wallet associated with a high-risk third country (the EU maintains a list), you need enhanced due diligence and — critically — **prior approval** from your MLRO before initiating the transfer.


UBO Registers — Stricter Verification

AMLD6 Art. 31 updates the Ultimate Beneficial Owner register requirements:

**For fintech operators onboarding business clients:** Your KYB process must now include tracing ownership chains down to the 15% level. This requires a structured ownership diagram, not just a company registration number.


The AMLA Regulation — 2027 and Beyond

The EU's new Anti-Money Laundering Authority (AMLA) starts supervising high-risk entities from Q3 2027. "High-risk" includes:

For smaller fintechs, direct AMLA supervision is not immediate — but the indirect effects are:

**What to do:** Treat the AMLA standards as the floor for your compliance program. Start aligning your policies and procedures with anticipated AMLA guidance on transaction monitoring thresholds, risk scoring methodologies, and SAR filing formats.


SAR Filing Under AMLD6 — What Changes

The suspicious activity report (SAR) framework remains substantially similar, but with two important changes:

1. Tipping-off offences strengthened

If you file a SAR and then disclose to the subject that you've filed — including during the client relationship — the tipping-off offence carries a maximum penalty of **4 years imprisonment** (up from 2 years under AMLD5).

Train your front-line staff on this. The client asking "why was my transfer held?" is a tipping-off risk.

2. No-Refusal regime for SARs above €10,000

When you file a SAR and the FIU issues a freezing instruction on a transaction above €10,000, you cannot complete that transaction without FIU authorization — even if the client pushes back or threatens to close the account.

This creates a business continuity risk. If a high-value client demands you release funds and you have a pending FIU freeze, you need legal cover. Document everything.


Engineering Implementation Guide

Here's what your engineering team needs to build or update to achieve AMLD6 readiness:

1. Transaction Monitoring Rules — Update Your Typology Matrix

**Engineering note:** Store your typology matrix as a versioned JSON schema with source citations (FIU guidance documents, FATF recommendations). When a regulator asks "why did you flag this?", your answer should reference your typology matrix version and the regulatory source that triggered the rule.

2. Travel Rule Compliance — Full Implementation

3. UBO Verification Pipeline

4. SAR Drafting System


AMLD6 vs AMLD5: The Core Differences

| Obligation | AMLD5 (2018) | AMLD6 (2025) |
|---|---|---|
| Predicate offences | ~11 listed | 22 listed |
| Corporate liability | Administrative only | **Criminal, up to 5% turnover** |
| UBO threshold | 25% ownership | 15% ownership |
| Travel Rule crypto threshold | €1,000 (varies by state) | **€0 — all transfers** |
| Tipping-off penalty | 2 years imprisonment | **4 years imprisonment** |
| AMLA supervision | None | Supranational body from 2027 |


Your AMLD6 Readiness Checklist

1. **Board briefing** — ensure directors understand corporate liability exposure
2. **AML manual update** — incorporate 22 predicate offences, new Travel Rule thresholds, tipping-off rules
3. **Transaction monitoring update** — add new typologies for crypto predicate offences
4. **Travel Rule engineering** — implement IVMS101 for all transfers, remove €1,000 floor
5. **UBO threshold review** — update KYB process to 15% ownership tracing
6. **SAR filing system** — verify FIU portal integration, update tipping-off training
7. **D&O insurance review** — confirm corporate criminal liability coverage
8. **Discrepancy reporting procedure** — implement the 14-day reporting workflow
9. **Data retention audit** — verify all required fields are retained for 5 years
10. **MLRO sign-off** — compliance officer must formally review and approve the updated AML program


Arkē's Role in Your AMLD6 Compliance

| AMLD6 Obligation | Arkē Coverage |
|---|---|
| Transaction monitoring | AML typology detection across batched CSV/JSON |
| Predicate offence indicators | Adverse media screening + sanctions/PEP checks |
| SAR drafting | FIU-format draft generation |
| Travel Rule wallet screening | Counterparty screening before transfer initiation |
| Ongoing risk scoring | Real-time risk scores 0–100, updated per transaction |


*This post is for informational purposes and does not constitute legal advice. Member state transposition timelines vary. Consult a qualified AML compliance specialist for your specific situation.*

*→ [Explore Arkē Pricing →](/pricing)*

Get AMLD6-ready in 48 hours

Arkē screens counterparties, monitors transactions for AML typologies, and drafts FIU-format SARs — in one platform.

See Pricing →
← Back to All Posts Try Arkē Screen Counterparty