
AMLA Group-Wide RTS Harmonisation: An Analysis of the Blind Spot
A multinational obliged entity onboards the same customer more than once. A person verified by the EU parent undertaking is verified again by the German subsidiary, and again by a branch in a third country — the same passport, the same screening, the same file, re-collected and re-stored inside each entity of the group. That is the operating reality group anti-money laundering functions run under, and the one AMLA's draft group-wide RTS is written on top of.
AMLA's group-wide RTS harmonises how groups apply their AML/CFT framework across subsidiaries — including third-country subsidiaries — but harmonising the policy does not remove the duplication in the customer file. What follows is an AMLA group-wide RTS harmonisation analysis, read from the identity layer up: what the draft RTS on group-wide requirements standardises, and the one duplication it leaves untouched.
The Group-Wide Requirements AMLA Is Codifying
The anti-money laundering authority (AMLA) assumed its powers on 1 July 2025 and develops the regulatory technical standards behind the EU single rulebook (1)(9). The group-wide RTS is one such draft RTS. When AMLA consults on group-wide requirements, it is not writing a new obligation, but setting the minimum shape of one the anti-money laundering regulation already imposes. We covered the opening of that process in our compliance recap on UK wholesale tokenisation and the AMLA RTS. The draft instruments cover group-wide requirements, information sharing among group entities, and the identification of the EU parent undertaking (4)(5).
Under AMLR Article 16 — the group-wide requirements provision — the EU parent undertaking must ensure that internal policies, procedures and controls, and the business-wide risk assessment, apply across all branches and subsidiaries; group-wide policies must be approved by the parent's management body (1)(7). These group-wide requirements reach obliged entities across the financial and non-financial sectors.
AMLR Article 16 and the Parent Undertaking's Duty
Article 16 puts a group-consistent floor on the parent undertaking: one set of internal policies, procedures and controls, one business-wide risk assessment, applied on a group-wide basis. Article 16(4) delegates the group-wide minimum requirements of that floor to AMLA (1). The draft RTS on group-wide requirements is not a new obligation, but the minimum shape of one the anti-money laundering regulation already imposes.
Articles 16(4) and 17(3) are delegation clauses: they let AMLA specify the group-wide requirements without expanding the underlying duty. The business-wide risk assessment stays where AMLR put it — at the parent undertaking, cascading to every subsidiary as a single set of controls the group applies.
Article 17: Additional Measures for Third-Country Subsidiaries
Article 17 addresses branches and subsidiaries that operate in third countries. Where a third country's law does not permit full compliance with EU AML/CFT requirements, the group must implement additional measures so those entities still manage money laundering and terrorist financing risk, and Article 17(3) delegates the RTS on those additional measures (1)(7). The additional measures are the jurisdictional layer stacked on the group-wide floor.
Articles 16 and 17 also reach information sharing. Groups must set the conditions under which information — customer data, suspicious transaction reports — moves between group entities, subject to data protection law (7)(11). Where legal impediments block that sharing in third countries, the additional measures compensate. This is the wedge context for how the same customer identity moves, or fails to move, across the entities of the group.

Reading the Draft RTS as an Onboarding Blueprint
Read the draft RTS not as a policy document but as an onboarding blueprint — trace what the group-wide requirements mean for one multinational obliged entity onboarding one customer across its subsidiaries. The draft RTS scope is threefold: group-wide requirements, information sharing among group entities, and criteria for identifying the EU parent where a third-country head office sits above multiple obliged entities (4)(5). The minimum standards it sets are meant to hold in cross-border situations and when obliged entities operate in third countries.
This is a mid-process standard. The AMLA consultation opened on 16 April 2026; AMLA held a public hearing on 20 May 2026, and set the comment deadline at 15 June 2026, 23:59 CEST (4)(6). Two public consultations ran in parallel — the draft RTS and the accompanying draft guidelines on business-wide risk assessment. AMLA will weigh the consultation feedback when preparing its submission to the European Commission by 30 September 2026 (6). Its stated purpose is that groups obtain a consolidated view of money laundering and terrorist financing risks and adapt their group-wide AML/CFT frameworks accordingly (5).
From the Business-Wide Risk Assessment to the Customer File
The business-wide risk assessment is a group-level instrument. It measures inherent and residual money laundering and terrorist financing risk across the organisation, sized by the entity's size, business model and specific risk exposure, and drives the group's risk-based decisions on a proportionality-based footing (5)(10). The draft guidelines on business-wide risk assessment set out how groups score that risk profile; the goal is a consolidated view of ML/TF risk, not a patchwork of per-entity risk assessments.
But the business-wide risk assessment cascades down to per-customer due diligence run inside each entity. Harmonising the policy standardises the questions every subsidiary asks; it does not deduplicate the answers each subsidiary collects. A proportionate, risk-based framework at group level still resolves into a fresh identity check per obliged entity.
Subsidiary-by-Subsidiary: Where the Duplication Lives
A consolidated group-wide view of ML/TF risk is a reporting and governance consolidation. It does not consolidate the identity-collection event. Each obliged entity in the group runs its own customer due diligence to identify and manage money laundering risk, holds its own copy of the customer's documents, and stores its own PII. For groups spanning the financial sector and the non-financial sector — banks and other financial institutions, plus non-financial sector firms such as auditors and the accounting and audit sector — the same customer becomes a new file in every entity that onboards them. Harmonised requirements establish a common floor, not a common record.
Third-country subsidiaries add a jurisdictional layer: the Article 17 additional measures apply precisely where information sharing between entities is hardest. Two pressures pull against each other: the draft RTS pushes groups to share more customer information for a consolidated risk view, while duplicative re-collection and re-storage of the same natural-person identity multiplies the PII attack surface across every entity — all under data protection law (7)(11). Common ownership does not, in itself, resolve the fragmentation of the record.
The Same Natural Person, Re-Collected Across the Group
Zoom to the natural-person layer. One verified identity holds N business relationships across N entities in the group, which means N document collections and N separate stores. This is the slice this analysis isolates — narrower than the standard's scope, but architecturally fixable. Vendor guidance rarely names it; we set out the mechanics in perpetual KYC: the PII re-pull vendor guides don't mention.
The RTS sets minimum standards for the framework, not a single set of shared identity records. Groups can build one policy, one business-wide risk assessment, one consolidated reporting line — and still re-collect the same passport a dozen times. Harmonised group-wide requirements do not, by themselves, produce a single customer identity.

Implications for Group Anti-Money Laundering Functions
For group anti-money laundering functions, the anti-money laundering regulation raises the floor and reduces fragmentation across jurisdictions. Harmonised minimum standards mean a subsidiary in one EU member state and a subsidiary in another apply the same group-wide requirements. The standard also formalises the parent's accountability for every subsidiary's file — including the third-country subsidiaries the European Banking Authority guidance (EBA/GL/2022/05) already required the group compliance officer to monitor (10). That pre-AMLA baseline is codified upward into a single harmonised standard supervisors can hold groups against.
Stakeholder contributions and public-hearing responses from the two public consultations feed AMLA's submission to the European Commission by 30 September 2026, ahead of the AMLR's general application on 10 July 2027 (1)(6). That gap is the planning window: the identity-architecture decision is worth making before the obligation bites in July 2027.
One disambiguation: the FIAU-Malta note that sometimes surfaces here concerns a different RTS package — the risk-assessment methodology under Article 40(2) AMLD and supervisory selection under Article 12(7) AMLAR — not the group-wide RTS (8).

The Identity Layer: One Attestation, Every Subsidiary
Be precise about scope. Verifyo does not offer group-wide transaction monitoring, entity-level KYB, ultimate beneficial owner verification, or full CDD/EDD — those obligations sit outside the natural-person identity-attestation layer entirely. They rest with the obliged entity's own compliance functions and its supervisory reporting, not with an identity attestation.
There is one layer where the RTS and an identity attestation meet: confirming that a natural person is who they claim to be. Every subsidiary that onboards a customer establishes this same fact, and eIDAS 2 lets people present verified attributes across the Union without repeated manual verification (12). A single reusable Zero-Knowledge KYC attestation lets each group entity confirm a customer's verified status without re-collecting and re-storing raw PII. This is the approach we take at Verifyo: Zero-Knowledge KYC means the receiving subsidiary gets a cryptographic proof of compliance status — verified, sanctions-clear, PEP-clear, age-confirmed, document-country known — never a copy of the underlying documents. The per-subsidiary re-onboarding cost falls away at the identity layer.
Portable identity evidence is one control point inside a larger group-wide framework. It does not consolidate the group's monitoring, its entity verification, or its supervisory reporting — those remain obligations on the obliged entity itself, including the ongoing customer due diligence AMLA expects across each business relationship. The identity layer is the narrow, fixable slice; the rest of that framework is not ours to claim.
AMLA's group-wide RTS harmonises the policy a group applies across its subsidiaries. It does not, by itself, deduplicate the identity each subsidiary re-collects. The harmonisation is real and overdue; the duplication it leaves untouched is the part worth engineering out — and the natural-person identity layer is the one part that can actually be fixed.
Sources
- European Parliament & Council. Regulation (EU) 2024/1624 (AMLR — AML/CFT single rulebook), Articles 16 and 17. 31 May 2024. eur-lex.europa.eu/eli/reg/2024/1624
- European Parliament & Council. Regulation (EU) 2024/1620 (AMLAR — establishing the Authority for Anti-Money Laundering). 31 May 2024. eur-lex.europa.eu/eli/reg/2024/1620
- European Parliament & Council. Directive (EU) 2024/1640 (AMLD6), Article 40(2). 31 May 2024. eur-lex.europa.eu/eli/dir/2024/1640
- AMLA. Public consultation — "Consultation on the draft RTS on group-wide minimum requirements and additional measures for subsidiaries and branches in third countries." Opened 16 April 2026. amla.europa.eu
- AMLA. Press release — "AMLA consults on group-wide requirements and business-wide risk assessment." 16 April 2026. amla.europa.eu
- AMLA. News — "AMLA concludes public hearing on draft RTS on group-wide requirements." 20 May 2026. amla.europa.eu
- AMLA. Consultation Paper — "Draft RTS under Articles 16(4) and 17 of Regulation (EU) 2024/1624." Frankfurt am Main, 16 April 2026. amla.europa.eu (consultation paper PDF)
- FIAU (Malta). News — "AMLA publishes Final Report on Draft RTS under Article 40(2) AMLD and Article 12(7) AMLAR." 23 December 2025. fiaumalta.org
- eucrim (Max Planck Institute). News — "AMLA Kicks Off Work." 2025. eucrim.eu
- European Banking Authority. Guidelines on the role and responsibilities of the AML/CFT compliance officer (EBA/GL/2022/05). 14 June 2022. eba.europa.eu (EBA/GL/2022/05 PDF)
- Matheson LLP. Insight — "AMLA opens public consultation on draft RTS on group-wide requirements and third-country measures." 2026. matheson.com
- European Parliament & Council. Regulation (EU) 2024/1183 (eIDAS 2 — European Digital Identity framework). 11 April 2024. eur-lex.europa.eu/eli/reg/2024/1183
Want to learn more?
Explore our other articles and stay up to date with the latest in zero-knowledge KYC and identity verification.
Browse all articles