AMLA's First Watch List: What the September Milestone Means
AMLA's provisional list of directly supervised entities finalises end-September 2026. Here's who qualifies and what your KYC stack must do.

The number is forty. That is how many financial institutions — banks, payment processors, crypto-asset service providers — will come under the European Anti-Money Laundering Authority's direct supervision from January 1, 2028. And the process of identifying which forty is crossing a critical threshold this week.
AMLA's data collection from national supervisors closed on August 15, 2026. The provisional list of provisionally eligible entities is expected to be finalised by end-September 2026. This is not a distant regulatory horizon. It is a live process, and the entities it will touch are finding out now.
Understanding what AMLA's direct supervision actually entails — and how to determine whether your institution is in scope — is no longer optional contingency planning. It is immediate operational risk management.
Two Tiers of EU AML Supervision
Prior to AMLA, AML supervision in the EU was entirely national. Your AML supervisor was the national FIU or financial regulator in your home member state. That structure created predictable gaps: supervisory quality varied, resource constraints differed, and sophisticated financial crime operations regularly exploited the seams between national frameworks.
AMLA changes this architecture by introducing two tiers:
Indirect supervision — the default for most obliged entities. National competent authorities (NCAs) continue to supervise, but under AMLA's harmonised standards and oversight. AMLA issues guidelines, standards, and peer reviews. NCAs execute.
Direct supervision — applied to a small set of the highest-risk, most cross-border entities. AMLA becomes the primary supervisor, with on-site inspection rights, binding decision authority, and direct sanctioning power.
Most firms will remain under indirect supervision. But for the roughly 40 entities that make the direct supervision list, the relationship with regulators fundamentally changes.
How AMLA Determines Eligibility
The selection methodology is defined by Commission Delegated Regulation. It is not opaque. Eligibility requires satisfying both a cross-border criterion and a risk threshold.
The Cross-Border Criterion
Only credit institutions and financial institutions are eligible for direct supervision. Within that universe, eligibility applies to firms that operate in six or more EU member states. Critically, AMLA's rules define "presence" in a member state to include remote digital activity — not just branches or subsidiaries.
A firm is deemed to have material presence in a member state if it has either:
- More than 20,000 resident customers in that member state, or
- More than €50 million in annual incoming and outgoing transactions for customers resident in that member state
This remote-presence standard matters enormously. A crypto exchange with no physical EU presence beyond a single MiCA licence could still qualify as operating in six member states if its customer distribution is wide enough.
The Risk Threshold
Being eligible is not sufficient. AMLA will select only those eligible entities whose residual AML/CFT risk is classified as high.
The residual risk assessment combines two components:
- Inherent risk score: based on customer base characteristics, products offered, geographies served, and delivery channels used
- Control effectiveness score: how well existing AML/CFT controls mitigate that inherent risk
An entity with high inherent risk but exceptionally robust controls could receive a medium residual risk classification and avoid direct supervision. Conversely, a firm with moderate inherent risk but weak controls may be classified high-residual-risk and included.
This means your AML control quality — including your KYC infrastructure — directly influences whether you appear on AMLA's list.
The Data Behind the List
AMLA published a standardised reporting template and interpretative note that national supervisors used to collect data by August 15. That data covered customer numbers per EU member state, annual transaction volumes per member state, inherent risk scores per entity, and each national supervisor's residual risk classification.
The error correction phase — where AMLA aligns data with national supervisors — is now underway. The provisional list emerges from that process.
The provisional list is not the final list. The formal first selection exercise runs in 2027, beginning with a second data collection in Q1 2027 and concluding between July and December 2027. But the provisional list is the first moment when specific institutions learn they are in scope. A firm that appears on the provisional list has roughly twelve to eighteen months to prepare for direct supervision before it begins.
CASPs and the Absence of a Carve-Out
For crypto-asset service providers authorised under MiCA, the AMLA framework contains an important structural point: there is no de minimis carve-out.
Every CASP authorised under MiCA is classified as a financial institution under the Anti-Money Laundering Regulation (AMLR). Every CASP is therefore an obliged entity under AMLA's rules. Whether a CASP becomes directly supervised depends on whether it meets the cross-border and risk thresholds — but no CASP is categorically excluded from that possibility.
Given that MiCA is explicitly designed to create single-market access across all EU member states, a licensed CASP that actively operates EU-wide faces a structural question: does its customer distribution across member states meet the six-country threshold? For any serious exchange or stablecoin issuer, the answer is likely yes. The risk question is then the operative one.
For more on the post-MiCA enforcement environment, our analysis of what 80% market exit means for crypto KYC sets the context for what regulators are now paying attention to.
What AMLA Direct Supervision Looks Like Operationally
Being directly supervised by AMLA differs from national supervision in ways that matter day-to-day.
| Dimension | National Supervision | AMLA Direct Supervision |
|---|---|---|
| Supervisor | National competent authority | AMLA Joint Supervisory Team |
| Inspection rights | Varies by member state | Harmonised, enforceable EU-wide |
| Binding decisions | National authority | AMLA directly |
| Maximum sanctions | National authority limits | 10% of annual turnover or €10 million |
| Reporting format | National format | AMLA standardised templates |
| Public disclosure | National practice | AMLA can publish enforcement decisions |
Joint Supervisory Teams (JSTs) will be formed for each directly supervised entity, bringing together staff from AMLA and relevant national competent authorities. They will run supervisory programmes that include regular data requests, targeted reviews, and on-site inspections. The first institutions to fall under direct supervision should expect a supervisory programme that is more intensive, more standardised, and more cross-border in scope than anything their national supervisor ran.
KYC Infrastructure Under Direct Supervision
AMLA's approach to KYC requirements is set out in its Customer Due Diligence regulatory technical standards — detailed in our analysis of AMLA's CDD standards and what identity systems must deliver.
Directly supervised entities face these requirements at a higher standard of evidence than indirectly supervised ones. AMLA's Joint Supervisory Team will request documentation, not just attestations. They will test controls, not just review policies.
Key KYC infrastructure requirements for directly supervised entities:
Identity verification at onboarding
- Document authenticity checks using MRZ validation and chip-based verification where available
- Biometric liveness detection meeting ISO/IEC 30107-3 anti-spoofing standards
- Sanctions and PEP screening against consolidated EU lists at onboarding and continuously
Ongoing monitoring
- Automated triggers for customer re-verification on material risk events
- Transaction monitoring calibrated to AMLA typologies guidance
- Audit trails capable of producing a complete customer activity history on demand
Risk classification
- Customer risk scoring incorporating both inherent risk factors and behavioural signals
- Documentation of risk-based decisions to a standard that withstands JST scrutiny
The AMLA ongoing monitoring guidelines provide a detailed breakdown of what Article 26 AMLR requires from monitoring systems.
The common thread across all these requirements is documentation. AMLA's supervisory teams will not take an entity's word for its control effectiveness. They will want to see the data, the decision logic, and the audit trail.
Continuous Compliance Is No Longer Optional
The shift from periodic KYC review to perpetual KYC is already established as a regulatory expectation. For entities under AMLA direct supervision, it is a baseline requirement.
AMLA supervisory teams will assess not just whether controls exist at a point in time, but whether they operate continuously. An onboarding process that meets standards but a monitoring programme that flags nothing is a red flag, not a clean bill of health.
This is where the architecture of your KYC system matters. Static, rules-based monitoring that runs periodic batch processes cannot demonstrate continuous operation to an AMLA inspector. Systems that generate real-time alerts, maintain decision logs, and produce exportable audit trails can.
Joinble's AI Agents are built for this operational model — not one-time verification, but autonomous, continuous identity management that logs every decision and adapts to new risk signals without manual intervention. When a JST requests evidence that your monitoring is working, a system that has been generating structured audit logs every day is a fundamentally different conversation from one that must reconstruct activity retrospectively.
Four Steps to Take Before the Provisional List Finalises
The end of September 2026 is the provisional list deadline. The formal selection completes in late 2027. That is twelve to fifteen months for institutions that may be in scope to prepare.
1. Assess your geographic footprint Map your EU customer base by member state. Count the states where you have either 20,000 customers or €50M in annual transaction volumes. If you operate in six or more, assume eligibility for direct supervision.
2. Commission an AML/CFT risk assessment Your residual risk classification will be based partly on data your national supervisor already holds. A fresh, documented risk assessment using AMLA's inherent risk categories is defensible where an informal one is not.
3. Audit your KYC documentation AMLA supervisors will request documentation that may differ from what your national supervisor accepts. Review your customer due diligence files against AMLA's CDD RTS standards, identify gaps, and close them before the JST arrives.
4. Implement continuous monitoring now The period between the provisional list and formal selection is the window for infrastructure upgrades. Waiting until direct supervision begins to implement continuous monitoring means building under scrutiny rather than before it. The AMLA overview outlines the broader context for why this authority has real enforcement teeth.
FAQ
What is the AMLA provisional list and when will it be published?
The provisional list identifies financial institutions potentially eligible for AMLA direct supervision under the 2027 selection exercise. It is expected to be finalised by end-September 2026, following data collection from national supervisors that closed on August 15.
Which firms are eligible for AMLA direct supervision?
Credit institutions and financial institutions — including MiCA-authorised CASPs — that operate in six or more EU member states and receive a high residual AML/CFT risk classification. Remote digital presence counts toward the six-member-state threshold if customer or transaction volume thresholds are met.
When does AMLA direct supervision actually start?
Direct supervision over the first cohort of selected entities begins on January 1, 2028. The formal selection exercise runs between July and December 2027.
How many entities will be directly supervised?
AMLA will select up to 40 entities or groups in the first selection round.
Can a firm avoid direct supervision by improving its risk classification?
Yes. Selection requires both cross-border eligibility and a high residual risk classification. Strong AML/CFT controls that reduce residual risk to a medium classification can result in exclusion from the initial cohort. This is the strongest operational argument for investing in compliance infrastructure now.
What are the consequences of being directly supervised?
Directly supervised entities are subject to Joint Supervisory Teams, standardised data requests, on-site inspections, binding AMLA decisions, and administrative sanctions of up to 10% of annual turnover or €10 million. There is also the reputational dimension of being publicly identified as a directly supervised entity.
Related Articles

EU AI Act August 2026: What It Means for Your KYC Stack
The EU AI Act's August 2 deadline activates high-risk AI rules. Here is what the biometric verification exemption really means for your KYC compliance stack.

EU Digital Omnibus: What the AI Act Delay Means for KYC
The EU Digital Omnibus entered into force July 27, extending high-risk AI deadlines to December 2027. Here is what it means for your KYC compliance stack.

FATF June 2026 Grey List: Iraq, Bosnia & KYC EDD
FATF added Iraq and Bosnia-Herzegovina to its June 2026 grey list. Here is what compliance teams must update in their KYC programs and EDD workflows.