Skip to main content
Category: Regulations and Standards

Anti-Money Laundering Directive

Also known as: AMLD, AML Directive, EU AML Directive, AMLDs, 6AMLD
Simply put

The Anti-Money Laundering Directive (AMLD) is a series of European Union laws intended to combat money laundering and terrorist financing. Rather than a single law, it is a succession of directives that set out requirements such as customer due diligence (CDD) and Know Your Customer (KYC) checks for regulated businesses. The aim is to create a more consistent regulatory environment across EU member states, though directives generally require transposition into each country's national law.

Formal definition

The AMLDs are a series of EU directives that, since 1991, have formed the basis of European anti-money-laundering (AML) and counter-terrorist-financing (CFT) policy, establishing customer due diligence (CDD), KYC, and related obligations for obliged entities. As directives, they set objectives that member states transpose into national legislation, which can produce variation in implementation across jurisdictions. Practitioners should note important terminological ambiguity: the criminal-law measure Directive (EU) 2018/1673 is commonly called the 6th AMLD (6AMLD), while a separate preventive-law instrument, Directive (EU) 2024/1640, is also branded by some commentators as AMLD6 or AMLD7. This 2024 directive is part of the broader EU AML/CFT legislative package adopted on 30 May 2024, which also includes the directly applicable AML Regulation (Regulation (EU) 2024/1624, 'AMLR') and the regulation establishing the AML Authority (Regulation (EU) 2024/1620, 'AMLA'), with much of the package beginning to apply from July 2027. Because the labeling of successive instruments varies by source and the legal landscape is shifting, readers should confirm the specific instrument, its number, and its applicable dates against the official published texts rather than relying on the AMLD number alone. AMLD requirements are distinct from payment-card security standards such as PCI DSS and govern AML/CFT obligations rather than cardholder data protection.

Why it matters

The AMLD framework matters because it sets the baseline for how regulated businesses across the European Union identify their customers, assess risk, and detect and report suspected money laundering and terrorist financing. For any organization touching payments, financial services, or other regulated activity within the EU, obligations such as customer due diligence (CDD) and Know Your Customer (KYC) flow directly from these directives as transposed into national law. Because directives set objectives that member states implement through their own legislation, the practical requirements can vary by jurisdiction, and compliance teams operating across multiple EU markets must account for those local differences rather than assuming a single uniform rule.

The legal landscape is currently shifting in ways that make precise tracking of instruments essential. Since 1991, a succession of AMLDs has formed the basis of European AML and counter-terrorist-financing (CFT) policy. More recently, the EU adopted a broader AML/CFT legislative package on 30 May 2024, which includes the directly applicable AML Regulation (Regulation (EU) 2024/1624, 'AMLR'), the regulation establishing the AML Authority (Regulation (EU) 2024/1620, 'AMLA'), and Directive (EU) 2024/1640. Much of this package is scheduled to begin applying from July 2027. Organizations relying on their understanding of earlier directives should plan for these changes rather than treating the pre-2024 framework as static.

A further reason for care is terminological ambiguity that can cause real confusion in compliance documentation. The criminal-law measure Directive (EU) 2018/1673 is commonly called the 6th AMLD (6AMLD), while the separate preventive-law Directive (EU) 2024/1640 is also branded AMLD6 or AMLD7 by some commentators. Because the same 'AMLD number' can refer to different legal instruments depending on the source, practitioners should confirm the specific directive, its number, and its applicable dates against the official published texts rather than relying on the label alone. It is also worth noting that AMLD obligations are distinct from payment-card security standards such as PCI DSS: the AMLDs govern AML/CFT duties, not the protection of cardholder data.

Who it's relevant to

Compliance officers and AML/CFT teams
Compliance functions in EU-regulated businesses rely on the AMLDs to define CDD, KYC, and monitoring obligations. They must track how directives are transposed into applicable national law and prepare for the 2024 AML/CFT package, including the directly applicable AMLR and the establishment of AMLA, much of which begins to apply from July 2027. Given the terminological overlap between the 2018/1673 criminal-law directive and the 2024/1640 preventive directive, these teams should cite specific instruments rather than AMLD numbers alone.
Payment processors and financial institutions operating in the EU
Organizations providing regulated financial and payment services in the EU are obliged entities under the AMLD framework and must implement customer due diligence and related controls as required by national transpositions. They should note that these AML/CFT obligations are separate from payment-card security standards such as PCI DSS, which govern cardholder data protection rather than money-laundering controls.
Fraud and risk analysts
Analysts assessing customer and transaction risk use KYC and CDD outputs shaped by AMLD requirements as inputs to their risk models. Because the underlying obligations vary across member states and are being reshaped by the 2024 package, analysts should confirm which instrument and which national implementation apply to a given jurisdiction and period.
Legal and regulatory affairs professionals
Legal teams interpreting AML/CFT obligations must distinguish between the succession of directives since 1991, the criminal-law Directive (EU) 2018/1673 commonly called 6AMLD, and the 2024 package instruments (Regulation (EU) 2024/1624, Regulation (EU) 2024/1620, and Directive (EU) 2024/1640). Because labeling varies by source and the landscape is shifting, they should validate instrument numbers and applicable dates against official published texts.

Inside AMLD

Anti-Money Laundering Directive (AMLD)
A series of European Union directives establishing preventive measures against money laundering and terrorist financing. As directives, AMLD instruments require transposition into each EU member state's national law, meaning specific obligations and enforcement can vary by jurisdiction and by the date of national implementation.
4AMLD and 5AMLD
Directive (EU) 2015/849 (4AMLD) and its amending Directive (EU) 2018/843 (5AMLD) form the core preventive framework preceding the 2024 package. They address customer due diligence, beneficial ownership registers, risk-based approaches, and (via 5AMLD) extended scope to areas such as virtual currency service providers. Confirm the exact transposed obligations against the current national implementing law rather than the directive text alone.
6AMLD (Directive (EU) 2018/1673)
A criminal-law directive that harmonizes the definition of money laundering as a criminal offence and related sanctions across member states. It is commonly branded '6AMLD' but is distinct from the preventive AMLD line; it focuses on criminalization rather than on the customer due diligence and reporting obligations that firms operationalize under the preventive directives.
2024 EU AML/CFT legislative package
A set of instruments adopted 30 May 2024 that reshapes the framework after 4AMLD–5AMLD. It includes Regulation (EU) 2024/1624 (the single AML Rulebook, 'AMLR'), Regulation (EU) 2024/1620 establishing the EU Anti-Money Laundering Authority ('AMLA'), and Directive (EU) 2024/1640 (a preventive directive sometimes branded 'AMLD6' or 'AMLD7' by different commentators). Much of this package begins applying from July 2027; verify exact application dates and transitional arrangements against the published instruments.
Regulation vs. Directive distinction
The 2024 package moves substantial content into a directly applicable Regulation (AMLR), whereas earlier AML measures were directives requiring national transposition. This affects how uniformly rules apply across member states and reduces some divergence that arises when directives are implemented differently.
Customer due diligence (CDD) and beneficial ownership
Core obligations across the preventive AMLD framework include identifying and verifying customers, applying enhanced due diligence in higher-risk situations, and maintaining beneficial ownership information. The precise thresholds, register access rules, and scope have shifted across 4AMLD, 5AMLD, and the 2024 package.

Common questions

Answers to the questions practitioners most commonly ask about AMLD.

Does the AMLD directly bind banks and payment firms, or does it require national implementation first?
An EU Directive, including the AMLDs, is not directly applicable in the same way a Regulation is. Directives set out results that Member States must achieve but leave the form and method to national legislatures, so obligations reach obliged entities through transposing national law. This means requirements can vary in detail and timing across jurisdictions. Note that the 2024 EU AML/CFT package changes this dynamic: it includes a directly applicable Regulation (EU) 2024/1624 (the AML Regulation, or AMLR) alongside a directive (Directive (EU) 2024/1640), so parts of the future framework will apply uniformly without national transposition once they begin applying.
Is the '6AMLD' the final and most current step in EU anti-money laundering law?
No, and the labelling here is a common source of confusion. Directive (EU) 2018/1673, frequently called 6AMLD, focuses on the criminal-law harmonisation of money laundering offences and is distinct from the earlier preventive directives (such as 4AMLD and 5AMLD). Separately, the EU adopted a new AML/CFT legislative package on 30 May 2024, comprising Regulation (EU) 2024/1624 (AMLR), Regulation (EU) 2024/1620 establishing the AML Authority (AMLA), and Directive (EU) 2024/1640 (a preventive directive that various commentators brand as the new '6AMLD' or 'AMLD6/AMLD7'). Because different sources apply the same numbering to different instruments, you should identify legislation by its full citation rather than by its informal number. Much of the 2024 package begins applying from July 2027; readers should confirm exact application dates against the official texts.
How should a compliance team track which AML rules currently apply given the coexisting instruments?
Map obligations to specific legal citations rather than informal directive numbers. Distinguish the criminal-law instrument (2018/1673) from the preventive framework built on 4AMLD/5AMLD and, going forward, the 2024 package (AMLR, AMLA Regulation, and Directive (EU) 2024/1640). Track each Member State's transposing legislation for directive-based obligations, and monitor the phased application timeline for the 2024 instruments. Confirm effective dates and requirement wording against the official published texts, since informal branding and secondary summaries can differ.
What is the practical distinction between an AMLD obligation and an obligation under the 2024 AMLR for implementation planning?
For directive-based obligations, the operative rules your firm follows are the national transposing measures, so implementation should reference the relevant Member State law and may vary by jurisdiction. For obligations under Regulation (EU) 2024/1624 (AMLR), the Regulation is intended to apply directly and more uniformly once its application dates are reached, reducing divergence across Member States. Planning should therefore separate rules that flow through national law from those that apply directly, and account for the future transition to the 2024 framework rather than assuming a single static rulebook.
How does the establishment of AMLA affect a firm's supervisory relationships?
Regulation (EU) 2024/1620 establishes the AML Authority (AMLA) as part of the 2024 package. Firms should treat the supervisory architecture as evolving: existing national competent authorities and national transposition of directives continue to govern current obligations, while AMLA's role is being introduced under the new framework with its own application timeline. Implementation planning should confirm the scope, powers, and start dates of AMLA against the official texts rather than assuming immediate change to existing supervisory arrangements.
When aligning AML controls with payment security programmes, is AMLD compliance the same as PCI DSS compliance?
No. The AMLDs and the 2024 EU AML/CFT package address anti-money laundering and counter-terrorist-financing obligations, such as customer due diligence, beneficial ownership, and suspicious activity reporting, and are enforced through EU and national law. PCI DSS is a separate payment-industry standard governing the protection of cardholder data and is not an AML instrument. A firm may be subject to both, but satisfying one does not satisfy the other, and controls, scope, and validation should be assessed independently against each applicable framework.

Common misconceptions

The AML framework stopped evolving with the '6th Anti-Money Laundering Directive.'
The reference to '6AMLD' typically means the criminal-law Directive (EU) 2018/1673, but the framework did not stop there. The 2024 EU AML/CFT package (AMLR, the AMLA Regulation, and Directive (EU) 2024/1640) was adopted on 30 May 2024, with much of it applying from July 2027. Practitioners should track the newer instruments, not assume the directive line ended at '6AMLD.'
'6AMLD' unambiguously refers to a single directive.
The label is used inconsistently. Directive (EU) 2018/1673 (criminal-law harmonization) is commonly called 6AMLD, while the 2024 preventive directive (Directive (EU) 2024/1640) is also branded 'AMLD6' or 'AMLD7' by different commentators. Because these instruments differ in purpose and scope, cite the specific directive number rather than relying on the informal 'nth AMLD' shorthand.
AMLD compliance and PCI DSS compliance are the same or interchangeable programs.
AMLD instruments govern anti-money-laundering and counter-terrorist-financing obligations under EU law, while PCI DSS governs the protection of cardholder data. They address different risks, are set by different bodies, and are validated separately. Meeting one does not satisfy the other.

Best practices

Cite the specific legal instrument by number (for example Directive (EU) 2015/849, Directive (EU) 2018/843, Directive (EU) 2018/1673, or the 2024 instruments AMLR/AMLA Regulation/Directive (EU) 2024/1640) rather than the informal 'nth AMLD' shorthand, since the numbering is used inconsistently.
Track the 2024 EU AML/CFT package and its application timeline, noting that much of it begins applying from July 2027, and confirm exact application and transposition dates against the published instruments rather than assuming a fixed date.
Distinguish directly applicable Regulations (such as AMLR) from directives requiring national transposition, and verify obligations against the relevant member state's implementing law where a directive applies.
Do not treat the criminal-law directive (2018/1673) as covering the same ground as the preventive directives; map criminalization requirements separately from customer due diligence and reporting obligations.
Keep AML/CFT compliance efforts distinct from payment-data security programs like PCI DSS, coordinating them where data overlaps but validating each against its own governing standard.
Review beneficial ownership, customer due diligence, and enhanced due diligence obligations against the current framework whenever the legislative package changes, rather than relying on prior directive versions.