RegRally Insights: AML/CTF Regulation, September 2026

RegRally Insights: AML/CTF Regulation, September 2026

The countdown to direct EU-level anti-money laundering and counter-terrorist financing (AML/CTF) supervision has started. The European Banking Authority (EBA) and the new Anti-Money Laundering Authority (AMLA) are preparing the data collection that will decide which institutions AMLA supervises directly from 2028. At national level, the Bank of Lithuania had an active August: a letter on money laundering and terrorist financing risks, an interim restriction on an electronic money institution under inspection, and the first results of the Verification of Payee service.

The September edition of RegRally covers what matters most to financial institutions, payment and electronic money institutions, crypto-asset service providers (CASPs) and other obliged entities in Lithuania and across the EU.

This month at a glance

  • Lithuania: the Bank of Lithuania’s letter, based on 2025 supervisory data and 10 AML/CTF inspections, flags formally assessed geographic risk, the need to verify authorization under the Markets in Crypto-Assets Regulation (MiCAR), weak enhanced due diligence, disproportionately low suspicious transaction reporting and incomplete sanctions screening. The Council of Europe’s MONEYVAL 6th evaluation round starts in October 2026, and the EU AML package applies in full from 10 July 2027.
  • Lithuania enforcement: the Bank of Lithuania temporarily prohibited the electronic money institution Lux International Payment System from providing financial services to new and existing customers while an inspection is ongoing, citing suspected serious deficiencies and possible AML/CTF breaches. The restriction was authorized by the Regional Administrative Court.
  • Payment fraud: the Bank of Lithuania published the first results of the Verification of Payee (VoP) service, based on a survey of seven banks, two central credit unions and five electronic money institutions. VoP is seen as a useful additional measure against payment fraud, and monitoring continues.
  • AMLA direct supervision: the EBA published a draft data model and taxonomy for the 2027 eligibility data collection, the basis for AMLA’s first selection of institutions for direct supervision. The reference date is 31 December 2026. Payment institutions and electronic money institutions fall within the reporting population.
  • Cross-border payments: AMLA surveyed electronic money institutions (EMIs) and payment service providers (PSPs) on Central Contact Points until 15 September 2026, feeding future technical standards under Article 41(2) of the Anti-Money Laundering Directive (AMLD). Crypto-asset service providers are not in scope.
  • Isle of Man: the Isle of Man Financial Services Authority (FSA) published a year-one progress report on its two-year supervisory engagement program covering AML, countering the financing of terrorism and countering proliferation financing (AML/CFT/CPF), and set out its priorities for 2026/27. Legislative reviews touch virtual asset service providers (VASPs) and the Travel Rule, and a questionnaire on foreign politically exposed persons (PEPs) is coming.

Bank of Lithuania warns financial market participants about ML/TF deficiencies

Date: 20 August 2026 | Source: Lietuvos bankas (Bank of Lithuania), Financial Market Supervision Department
Link

What happened?

The Bank of Lithuania sent a letter to the heads of financial market participants on money laundering and terrorist financing (ML/TF) risks and prevention requirements. It is based on 2025 supervisory data and 10 AML/CTF inspections.

The letter flags several risk areas:

  • geographic risk assessed too formally, based on declared residence only rather than actual activity and payment flows
  • higher-risk activities (crypto-assets, gambling, remittance), where licenses must be verified in official registers, including MiCAR authorization now that the transitional period ended on 1 July 2026
  • agents and distributors, where responsibility remains with the financial market participant
  • cash operations, virtual IBANs (vIBANs) and Travel Rule compliance

Deficiencies found during inspections:

  • business-wide risk assessments that do not match the actual risk profile
  • weak enhanced due diligence
  • transaction monitoring not tailored to the business
  • incomplete sanctions screening, with no sanctions risk assessment

Suspicious transaction report (STR) numbers remain disproportionately low or nil in most sectors. The Bank of Lithuania also reminded firms of the cash reporting duty: linked cash operations reaching EUR 15,000 must be reported to the Financial Crime Investigation Service (FNTT) within 7 business days.

On sanctions, circumvention continues via the Commonwealth of Independent States (CIS) and third countries, and EU packages now reach third-country banks and crypto platforms. Not being established in Russia or Belarus is no evidence of low risk. The Council of Europe’s MONEYVAL 6th evaluation round runs from October 2026 to May 2028, and the EU AML package applies in full from 10 July 2027.

Why does it matter for businesses?

The flagged areas are where 2025 inspections actually found breaches, and the MONEYVAL evaluation starts in October 2026.

Two duties already apply. The MiCAR transitional period ended on 1 July 2026, so crypto-asset business clients must be checked for MiCAR authorization in the official register. And the EUR 15,000 cash reporting duty carries a 7-business-day deadline.

STR volumes should be reviewed against the firm’s scale and risk profile, and firms should be able to justify them.

Recommended actions

Lithuanian financial market participants should:

  • re-do geographic risk assessments based on actual activity and payment flows
  • screen the crypto client book for clients without MiCAR authorization
  • review STR volumes against the firm’s scale and risk profile and be able to justify them
  • complete the sanctions risk assessment and extend screening to ownership and the intermediary chain
  • remediate known deficiencies before expanding activities
  • start the EU AML package gap analysis against the 10 July 2027 application date

Bank of Lithuania temporarily prohibits EMI Lux International Payment System from providing services during inspection

Date: 4 August 2026 | Source: Lietuvos bankas (Bank of Lithuania)
Link

What happened?

The Bank of Lithuania temporarily prohibited the electronic money institution UAB “Lux International Payment System” from providing financial services to both new and existing customers while an inspection is ongoing.

The measure was imposed because the Bank of Lithuania had grounds to suspect serious deficiencies and possible breaches of AML/CTF and other regulatory requirements. The restriction was authorized by the Regional Administrative Court.

Why does it matter for businesses?

The case shows that the supervisor does not need a completed inspection to act. Where suspected deficiencies are serious, the supervisor can impose an interim restriction before the inspection is completed, with court authorization.

For other institutions, the practical lesson is that material AML/CTF weaknesses should be escalated and remediated promptly, and management should be able to demonstrate control over identified deficiencies.

Recommended actions

Financial institutions should:

  • treat the case as a supervisory benchmark demonstrating the Bank of Lithuania’s willingness to impose interim restrictions before completion of an inspection where serious deficiencies are suspected
  • ensure material AML/CTF weaknesses are escalated and remediated promptly
  • ensure management can demonstrate effective control over identified regulatory deficiencies

Bank of Lithuania publishes first results of the Verification of Payee service

Date: 13 August 2026 | Source: Lietuvos bankas (Bank of Lithuania)
Link

What happened?

The Bank of Lithuania published the first assessment of the implementation of the Verification of Payee (VoP) service, based on a survey covering seven banks, two central credit unions and five electronic money institutions.

The initial results indicate that VoP is considered a useful additional measure for reducing payment fraud, particularly by alerting customers to discrepancies between the beneficiary name and account details before a payment is executed.

The Bank of Lithuania nevertheless emphasised that further data and experience are required to assess its effectiveness. It intends to continue monitoring both financial institutions’ and consumers’ experience with the service.

Why does it matter for businesses?

VoP has moved from go-live to supervisory review. Expectations will now be shaped by implementation data, so how a firm handles match results today is what gets benchmarked tomorrow.

The key question is whether VoP outcomes are integrated into the firm’s fraud prevention and monitoring framework, rather than only shown to the customer as a warning.

Recommended actions

Payment service providers should:

  • review VoP implementation, including the handling of match, no-match and close-match results and customer warnings
  • assess whether VoP outcomes are appropriately integrated into the firm’s fraud prevention and monitoring framework
  • monitor further Bank of Lithuania communications as supervisory expectations develop based on implementation experience

EBA publishes draft reporting framework for AMLA’s 2027 eligibility data collection

Date: 4 August 2026 | Source: European Banking Authority (EBA)
Link

What happened?

The EBA published, as part of release 4.4 of its reporting framework, a public working draft of the data model and taxonomy that will support the 2027 eligibility data collection underpinning AMLA’s first selection of financial institutions for direct supervision.

The data will be gathered in early 2027 from all obliged entities provisionally identified as eligible in 2026, to confirm whether they still meet the criteria as of the 31 December 2026 reference date.

Credit and financial institutions fall within the population that must report, including payment institutions and electronic money institutions. Feedback on the draft could be submitted through the EBA feedback form until 24 August 2026, and the draft should be read alongside the templates AMLA published for the 2026 eligibility-criteria data collection.

Why does it matter for businesses?

Selection for direct AMLA supervision from 2028 will be based on this data. The 31 December 2026 reference date means the position that determines eligibility is being fixed now, not when the data is collected in 2027.

Payment institutions and electronic money institutions are explicitly within the reporting population. Firms that have not mapped their internal data against the draft model may only discover gaps once the collection exercise is already under way.

Recommended actions

Firms should:

  • assess whether they are within scope of the eligibility data collection and begin mapping the required data against the draft model and taxonomy
  • review the draft reporting templates alongside the templates AMLA published for the 2026 eligibility-criteria data collection
  • plan governance and resourcing for possible selection for AMLA direct supervision from 2028, using 31 December 2026 as the reference date

AMLA surveyed EMIs and payment service providers on Central Contact Points

Date: 6 August 2026 | Source: Anti-Money Laundering Authority (AMLA)
Link

What happened?

AMLA launched a survey on Central Contact Points (CCPs), inviting electronic money institutions and payment service providers to share their experience of the current CCP framework under Article 45(9) of the AMLD and Delegated Regulation (EU) 2018/1108.

The survey supports AMLA’s preparatory work on forthcoming regulatory technical standards (RTS) under Article 41(2) of the AMLD. The standards will address when a host Member State may require the appointment of a CCP and what functions the CCP should perform.

AMLA ran a parallel survey for national competent authorities. It also confirmed that crypto-asset service providers are not in scope, as the previous CCP framework did not apply to them. The survey closed on 15 September 2026, and AMLA will publish a report on the main findings.

Why does it matter for businesses?

For EMIs and payment service providers operating cross-border through agents or distributors, CCP requirements shape host-Member-State compliance obligations. The future technical standards will harmonize when a host state may require a CCP and what functions it performs.

Practical implementation challenges reported in the survey are likely to shape the future harmonized standards.

Recommended actions

EMIs and PSPs operating cross-border through agents or distributors should:

  • review their host-Member-State CCP arrangements
  • capture practical implementation challenges now, as they are likely to shape the future harmonized RTS
  • monitor the follow-up report and the eventual Article 41(2) technical standards

Isle of Man FSA publishes year-one progress report on AML/CFT supervisory priorities

Date: 19 August 2026 | Source: Isle of Man Financial Services Authority (FSA)
Link

What happened?

The Isle of Man FSA published a year-one progress report on its two-year AML/CFT/CPF supervisory engagement program. It sets out the risk-based work delivered during 2025/26 and the priorities for 2026/27.

The report covers topical thematic reviews (sanctions, terrorist financing, proliferation financing, business risk assessments, reporting and registers), sectoral reviews (estate agents, moneylenders) and legislative reviews touching Virtual Asset Service Providers (VASPs) and the Travel Rule.

Findings feed into the AML/CFT Handbook, sectoral guidance, the Island’s National Risk Assessment and preparations for the MONEYVAL mutual evaluation. The Authority also signalled a forthcoming questionnaire on foreign PEPs.

Why does it matter for businesses?

For firms within scope, the stated priorities show where the FSA’s thematic and sectoral reviews will land during 2026/27. The legislative reviews confirm continued attention to VASPs and the Travel Rule.

Recommended actions

Firms within scope should:

  • review the FSA’s stated supervisory priorities and benchmark their AML/CFT/CPF frameworks against the thematic and sectoral focus areas
  • confirm Travel Rule readiness ahead of continued legislative attention (VASPs and firms handling transfers)
  • anticipate thematic reviews and the PEP questionnaire, and evidence remediation of known gaps

What businesses should take from this month’s developments

The Bank of Lithuania’s letter makes the expectation explicit: risk assessments, due diligence, monitoring, reporting and sanctions screening must reflect how the business actually operates, not just how it is documented.

The Lux International Payment System case shows the other side of the same expectation. Where serious deficiencies are suspected, the supervisor is prepared to stop business before the inspection ends.

At EU level, the AMLA era is arriving on two tracks. The 2027 eligibility data collection, with 31 December 2026 as the reference date, will determine which institutions face direct AMLA supervision from 2028. The Central Contact Point survey shows AMLA building the technical rules for cross-border payment and e-money business.

MONEYVAL starts in October 2026 and the EU AML package applies in full from 10 July 2027. The deadlines are set.


Need assistance?

ECOVIS ProventusLaw advises financial institutions, fintechs, CASPs and other obliged entities on AML/CTF compliance, including:

  • AML/CTF regulatory assessments and gap analysis
  • business-wide ML/TF risk assessments
  • AML policies, internal controls and procedures
  • customer due diligence and enhanced due diligence frameworks
  • transaction monitoring and suspicious transaction reporting
  • AML governance, MLRO responsibilities and employee training
  • CASP and virtual asset AML/CTF requirements
  • regulatory inspections and remediation of identified deficiencies.

If your organization is preparing for increased AMLA or national supervisory scrutiny, our team can help assess whether your AML framework works in practice and is ready for regulatory review.

Related news

Knowledge without experience is of little use. Therefore we are proud of having our own valuable experience to share with you.

Contact person

+370 5 212 40 84

[email protected]

Inga Karulaitytė

Lawyer, Attorney at law, Partner, Head of Banking and Finance & FinTech, CAMS

Contact person

+370 5 212 40 84

[email protected]

    Newsletter SubscriptionGet in touch