Skip to main content
Category: Regulations and Standards

AML Directives

Also known as: AMLD, Anti-Money Laundering Directive, EU Anti-Money Laundering Directive, AML Directive
Simply put

The AML Directives are a series of European Union laws intended to prevent money laundering and the financing of terrorism. They require banks and other regulated businesses to verify who their customers are and to watch for and report suspicious activity. The goal is to create a consistent set of rules across EU member states.

Formal definition

The Anti-Money Laundering Directive (AMLD) refers to a successive series of EU directives that establish customer due diligence (CDD) and Know Your Customer (KYC) obligations aimed at preventing money laundering and terrorist financing. Directive (EU) 2015/849, commonly known as the Fourth Anti-Money Laundering Directive, is one instrument in this lineage, following earlier measures such as Council Directive 91/308/EEC. As directives, these instruments set requirements that EU member states transpose into national law; for example, the Dutch Money Laundering and Terrorist Financing Prevention Act reflects such transposition. AML obligations are intended to help detect and report suspicious activity, including predicate offenses to money laundering and terrorist financing. This framework is distinct from payment card security standards such as PCI DSS; readers should confirm current directive numbering, amendments, and transposition status against the applicable published legislation, as these change over time and vary by jurisdiction.

Why it matters

Money laundering and terrorist financing exploit the financial system to move and disguise illicit funds, and the AML Directives represent the European Union's effort to establish a consistent regulatory baseline across member states rather than leaving each country to act in isolation. For banks and other regulated businesses, these directives translate into concrete customer due diligence (CDD) and Know Your Customer (KYC) obligations that shape how customers are onboarded, monitored, and reported when their activity appears suspicious. Failure to meet these obligations exposes regulated entities to enforcement action under the national laws that transpose the directives.

Because the AMLD is a successive series of directives rather than a single fixed instrument, the practical requirements evolve over time. Directive (EU) 2015/849, the Fourth Anti-Money Laundering Directive, follows earlier measures such as Council Directive 91/308/EEC, which first defined money laundering in this lineage. Compliance teams must therefore track not only the directive text but also how each member state transposes it into national law, since directives set requirements that member states implement domestically. The Dutch Money Laundering and Terrorist Financing Prevention Act is one example of such national transposition.

It is important to distinguish this framework from payment card security standards such as PCI DSS, which govern the protection of cardholder data rather than anti-money-laundering obligations. Confusing the two can lead to gaps: satisfying PCI DSS controls does not address AML duties, and vice versa. Because directive numbering, amendments, and transposition status change over time and vary by jurisdiction, readers should confirm current obligations against the applicable published legislation rather than assuming a fixed requirement set.

Who it's relevant to

Compliance officers
Compliance officers at regulated businesses are responsible for implementing the customer due diligence and KYC obligations that the AML Directives require, and for tracking how those obligations are transposed into the national law of each jurisdiction in which the business operates. They should confirm current directive numbering, amendments, and transposition status against the applicable published legislation, as these change over time.
Banks and other obligated entities
Banks and other regulated businesses subject to AML obligations must verify customer identities, monitor for suspicious activity, and report it in line with the national laws transposing the directives. These duties are separate from payment card security obligations such as PCI DSS and must be addressed on their own terms.
Fraud analysts and monitoring teams
Teams that monitor transactions and account activity support the detection of suspicious activity that AML rules are intended to surface, including predicate offenses to money laundering and terrorist financing. Their monitoring processes contribute to the reporting obligations set by the applicable national legislation, though the specific thresholds and criteria depend on how the directives are transposed in each jurisdiction.
Legal and regulatory teams
Legal teams must interpret how the successive AML Directives — from Council Directive 91/308/EEC through Directive (EU) 2015/849 and later amendments — are reflected in national instruments such as the Dutch Money Laundering and Terrorist Financing Prevention Act. Because transposition and amendments vary by member state and change over time, they should verify obligations against the current published legislation.

Inside AMLD

Anti-Money Laundering (AML) Framework
A body of legal and regulatory obligations intended to detect, deter, and report the movement of illicitly obtained funds through the financial system. AML directives typically require regulated entities to implement risk-based programs rather than a single fixed control.
Customer Due Diligence (CDD)
Processes for identifying and verifying the identity of customers and understanding the nature of their activity. The depth of verification is generally proportionate to assessed risk, with enhanced measures applied to higher-risk relationships.
Know Your Customer (KYC)
Identity verification and onboarding controls that support CDD obligations. KYC is a component of an AML program and is distinct from payment security standards such as PCI DSS, which govern the protection of cardholder data rather than money-laundering controls.
Enhanced Due Diligence (EDD)
Additional scrutiny applied to relationships or transactions presenting elevated money-laundering or terrorist-financing risk, which may include closer monitoring and additional information gathering. The specific triggers and measures depend on the applicable jurisdiction's directive.
Transaction Monitoring and Reporting
Ongoing monitoring intended to identify unusual or suspicious activity, and mechanisms for reporting such activity to the relevant authorities. Reporting obligations, thresholds, and formats vary by jurisdiction and change over time.
Beneficial Ownership Requirements
Obligations to identify the natural persons who ultimately own or control a customer entity. The scope, thresholds, and register requirements differ across jurisdictions and directive versions.
Risk-Based Approach
A principle common to many AML directives requiring entities to assess and prioritize controls according to identified risk, rather than applying uniform measures. This means implementation details and control intensity depend on the entity's own documented risk assessment.

Common questions

Answers to the questions practitioners most commonly ask about AMLD.

Are the AML Directives part of PCI DSS or the other PCI standards?
No. The AML Directives are anti-money laundering legal frameworks and are separate from PCI DSS and the related PCI standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, and PCI 3DS. PCI DSS governs the protection of cardholder data and the systems that handle it, and it does not define AML obligations. An organization can be PCI DSS compliant and still have distinct, independent AML responsibilities, and vice versa. Confirm which framework governs a given control rather than assuming the two overlap.
Does complying with the AML Directives mean my fraud controls are covered too?
Not necessarily. Anti-money laundering and fraud prevention address different, though sometimes related, risks. AML frameworks focus on detecting and reporting the movement of illicit funds, while fraud controls target activity such as card-present and card-not-present fraud, account takeover, first-party or friendly fraud, chargeback fraud, and synthetic identity fraud. Meeting AML obligations is intended to address money laundering risk and may support some fraud monitoring, but it does not by itself provide comprehensive fraud coverage. The specific obligations depend on the applicable law, region, and the entity's role.
How do I determine which of my organization's activities fall under the AML Directives?
Scope depends on the applicable jurisdiction, the entity type, and the services provided, and it varies by region. Because the requirements and their interpretation differ across implementations and change over time, confirm applicability against the current legal text and any competent-authority guidance for your jurisdiction rather than assuming a fixed scope. Where an activity's status is unclear, obtain qualified legal or compliance advice specific to your operations.
How should AML controls coordinate with the way I handle cardholder data under PCI DSS?
AML and PCI DSS obligations can apply to the same systems but govern different concerns, so coordinate them without conflating them. When AML processes require retaining or reviewing transaction records, ensure any cardholder data involved is still handled under PCI DSS controls, and distinguish cardholder data such as the PAN, cardholder name, expiration date, and service code from sensitive authentication data such as full track data, CAV2/CVC2/CVV2/CID, and PINs or PIN blocks, which must not be stored after authorization even when encrypted. Techniques such as tokenization, encryption, truncation, masking, and hashing affect data protection and scope differently depending on implementation and validation, so evaluate their use in both AML and PCI DSS contexts.
Where do the AML Directives sit relative to the payment authentication controls we already use?
AML obligations operate independently of transaction authentication controls such as EMV chip authentication, 3-D Secure, strong customer authentication, and multi-factor authentication. Those controls address different risks at different points in a transaction and are not a substitute for AML monitoring and reporting. Treat AML processes as a separate control layer, and do not assume that any single authentication control satisfies AML requirements or eliminates the underlying risk.
What should I keep in mind about the limitations of AML monitoring tools?
Detection-based AML monitoring involves trade-offs between false positives and false negatives, so tuning and ongoing review are important. Overly broad rules may generate excessive alerts and operational burden, while narrow rules may miss activity that should be investigated. These tools are intended to help identify and support the reporting of suspicious activity, not to guarantee detection. Document your methodology and validate it against the applicable legal requirements, recognizing that specific thresholds, expectations, and figures depend on jurisdiction, period, and source.

Common misconceptions

AML directives and PCI DSS are part of the same compliance regime, so meeting one satisfies the other.
AML directives address money-laundering and terrorist-financing controls, while PCI DSS is a separate standard governing the protection of cardholder data and sensitive authentication data. They have different scopes, governing bodies, and objectives, and compliance with one does not establish compliance with the other.
AML directives are a single, uniform global rulebook with fixed requirements.
AML obligations are set through directives and laws that vary by jurisdiction and change over time. Specific thresholds, reporting formats, beneficial ownership rules, and due diligence expectations differ by region and version, so practitioners should confirm requirements against the currently applicable law rather than assuming a fixed set of rules.
Completing customer verification at onboarding fully satisfies AML obligations.
Onboarding KYC is only one component. Many directives also expect ongoing monitoring, periodic review proportionate to risk, and suspicious activity reporting, so AML compliance is intended to be continuous rather than a one-time check.

Best practices

Adopt a documented risk-based approach that maps controls to assessed customer, product, and geographic risk, and apply enhanced due diligence where higher risk is identified.
Confirm applicable AML obligations against the current, jurisdiction-specific directive or law rather than assuming fixed thresholds, reporting formats, or beneficial ownership rules.
Keep AML programs organizationally and functionally distinct from payment security compliance efforts such as PCI DSS, while coordinating where data and processes overlap.
Maintain ongoing transaction monitoring and periodic customer review proportionate to risk, rather than relying solely on onboarding verification.
Establish clear procedures for identifying and reporting suspicious activity to the relevant authorities, and keep those procedures aligned with current reporting requirements.
Retain records of due diligence decisions, beneficial ownership determinations, and monitoring outcomes to support audit, review, and regulatory examination.