RegRally Insights: AML/CTF Regulation, September 2026

RegRally Insights: AML/CTF Regulation, September 2026

The countdown to direct EU-level anti-money laundering and counter-terrorist financing (AML/CTF) supervision has started. The European Banking Authority (EBA) and the new Anti-Money Laundering Authority (AMLA) are preparing the data collection that will decide which institutions AMLA supervises directly from 2028. At national level, the Bank of Lithuania is asking a simpler question: does the AML framework work in practice, from geographic risk to suspicious transaction reporting and sanctions screening.

The September edition of RegRally covers what matters most to financial institutions, payment and electronic money institutions, crypto-asset service providers (CASPs) and other obliged entities in Lithuania and across the EU.

This month at a glance

  • Lithuania: the Bank of Lithuania’s letter, based on 2025 supervisory data and 10 AML/CTF inspections, flags formally assessed geographic risk, missing authorisation checks under the Markets in Crypto-Assets Regulation (MiCAR), weak enhanced due diligence, disproportionately low suspicious transaction reporting and incomplete sanctions screening. The Council of Europe’s MONEYVAL 6th evaluation round starts in October 2026, and the EU AML package applies in full from 10 July 2027.
  • AMLA direct supervision: the EBA published a draft data model and taxonomy for the 2027 eligibility data collection, the basis for AMLA’s first selection of institutions for direct supervision. The reference date is 31 December 2026. Payment institutions and electronic money institutions fall within the reporting population.
  • Cross-border payments: AMLA is surveying electronic money institutions (EMIs) and payment service providers (PSPs) on Central Contact Points until 15 September 2026, feeding future technical standards under Article 41(2) of the Anti-Money Laundering Directive (AMLD). Crypto-asset service providers are not in scope.
  • Isle of Man: the Isle of Man Financial Services Authority (FSA) published a year-one progress report on its two-year supervisory engagement programme covering AML, countering the financing of terrorism and countering proliferation financing (AML/CFT/CPF), and set out its priorities for 2026/27. Legislative reviews touch virtual asset service providers (VASPs) and the Travel Rule, and a questionnaire on foreign politically exposed persons (PEPs) is coming.

Bank of Lithuania warns financial market participants about recurring ML/TF deficiencies

Date: 20 August 2026 | Source: Lietuvos bankas 
Link

What happened?

The Bank of Lithuania sent a letter to the heads of financial market participants on money laundering and terrorist financing (ML/TF) risks and prevention requirements. It is based on 2025 supervisory data and 10 AML/CTF inspections.

The letter flags several risk areas:

  • geographic risk assessed too formally, based on declared residence only rather than actual activity and payment flows
  • higher-risk activities (crypto-assets, gambling, remittance), where licences must be verified in official registers, including MiCAR authorisation now that the transitional period ended on 1 July 2026
  • agents and distributors, where responsibility remains with the financial market participant
  • cash operations, virtual IBANs (vIBANs) and Travel Rule compliance

Deficiencies found during inspections:

  • business-wide risk assessments that do not match the actual risk profile
  • weak enhanced due diligence
  • transaction monitoring not tailored to the business
  • incomplete sanctions screening, with no sanctions risk assessment

Suspicious transaction report (STR) numbers remain disproportionately low or nil in most sectors. The Bank of Lithuania also reminded firms of the cash reporting duty: linked cash operations reaching EUR 15,000 must be reported to the Financial Crime Investigation Service (FNTT) within 7 business days.

On sanctions, circumvention continues via the Commonwealth of Independent States (CIS) and third countries, and EU packages now reach third-country banks and crypto platforms. Not being established in Russia or Belarus is no evidence of low risk. The Council of Europe’s MONEYVAL 6th evaluation round runs from October 2026 to May 2028, and the EU AML package applies in full from 10 July 2027.

Why does it matter for businesses?

The letter is effectively an inspection roadmap. The flagged areas are where 2025 inspections actually found breaches, and the same areas will get attention in the run-up to the MONEYVAL evaluation starting in October 2026.

Two compliance triggers already apply. The MiCAR transitional period ended on 1 July 2026, so servicing crypto clients without MiCAR authorisation is now a live exposure. And the EUR 15,000 cash reporting duty carries a hard 7-business-day deadline.

Low or nil STR volumes are treated as a warning sign in themselves. Firms should be able to justify their reporting levels against their scale and risk profile.

Recommended actions

Lithuanian financial market participants should:

  • re-do geographic risk assessments based on actual activity and payment flows
  • screen the crypto client book for clients without MiCAR authorisation
  • review STR volumes against the firm’s scale and risk profile and be able to justify them
  • complete the sanctions risk assessment and extend screening to ownership and the intermediary chain
  • remediate known deficiencies before expanding activities
  • start the EU AML package gap analysis against the 10 July 2027 application date

EBA publishes draft reporting framework for AMLA’s 2027 eligibility data collection

Date: 4 August 2026 | Source: European Banking Authority (EBA)
Link

What happened?

The EBA published, as part of release 4.4 of its reporting framework, a public working draft of the data model and taxonomy that will support the 2027 eligibility data collection underpinning AMLA’s first selection of financial institutions for direct supervision.

The data will be gathered in early 2027 from all obliged entities provisionally identified as eligible in 2026, to confirm whether they still meet the criteria as of the 31 December 2026 reference date.

Credit and financial institutions fall within the population that must report, including payment institutions and electronic money institutions. Feedback on the draft could be submitted through the EBA feedback form until 24 August 2026, and the draft should be read alongside the templates AMLA published for the 2026 eligibility-criteria data collection.

Why does it matter for businesses?

Selection for direct AMLA supervision from 2028 will be based on this data. The 31 December 2026 reference date means the position that determines eligibility is being fixed now, not when the data is collected in 2027.

Payment institutions and electronic money institutions are explicitly within the reporting population. Firms that have not mapped their internal data against the draft model may only discover gaps once the collection exercise is already under way.

Recommended actions

Firms should:

  • assess whether they are within scope of the eligibility data collection and begin mapping the required data against the draft model and taxonomy
  • review the draft reporting templates alongside the templates AMLA published for the 2026 eligibility-criteria data collection
  • plan governance and resourcing for possible selection for AMLA direct supervision from 2028, using 31 December 2026 as the reference date

AMLA surveys EMIs and payment service providers on Central Contact Points

Date: 6 August 2026 | Source: Anti-Money Laundering Authority (AMLA)
Link

What happened?

AMLA launched a survey on Central Contact Points (CCPs), inviting electronic money institutions and payment service providers to share their experience of the current CCP framework under Article 45(9) of the AMLD and Delegated Regulation (EU) 2018/1108.

The survey supports AMLA’s preparatory work on forthcoming regulatory technical standards (RTS) under Article 41(2) of the AMLD. The standards will address when a host Member State may require the appointment of a CCP and what functions the CCP should perform.

AMLA is running a parallel survey for national competent authorities. It also confirms that crypto-asset service providers are not in scope, as the previous CCP framework did not apply to them. The survey remains open until 15 September 2026, after which AMLA will publish a report on the main findings.

Why does it matter for businesses?

For EMIs and payment service providers operating cross-border through agents or distributors, CCP requirements shape host-Member-State compliance obligations. The future technical standards will harmonise when a host state may require a CCP and what functions it performs.

The survey is the practical way to shape those standards. Problems reported now will likely influence how the harmonised rules are drafted.

Recommended actions

EMIs and PSPs operating cross-border through agents or distributors should:

  • review their host-Member-State CCP arrangements and respond to the survey before 15 September 2026
  • capture practical implementation challenges now, as they are likely to shape the future harmonised RTS
  • monitor the follow-up report and the eventual Article 41(2) technical standards

Isle of Man FSA publishes year-one progress report on AML/CFT supervisory priorities

Date: 19 August 2026 | Source: Isle of Man Financial Services Authority (FSA)
Link

What happened?

The Isle of Man FSA published a year-one progress report on its two-year AML/CFT/CPF supervisory engagement programme. It sets out the risk-based work delivered during 2025/26 and the priorities for 2026/27.

The report covers topical thematic reviews (sanctions, terrorist financing, proliferation financing, business risk assessments, reporting and registers), sectoral reviews (estate agents, moneylenders) and legislative reviews touching Virtual Asset Service Providers (VASPs) and the Travel Rule.

Findings feed into the AML/CFT Handbook, sectoral guidance, the Island’s National Risk Assessment and preparations for the MONEYVAL mutual evaluation. The Authority also signalled a forthcoming questionnaire on foreign PEPs.

Why does it matter for businesses?

For firms within scope, the stated priorities show where the FSA’s thematic and sectoral reviews will land during 2026/27. The legislative reviews confirm continued attention to VASPs and the Travel Rule.

Recommended actions

Firms within scope should:

  • review the FSA’s stated supervisory priorities and benchmark their AML/CFT/CPF frameworks against the thematic and sectoral focus areas
  • confirm Travel Rule readiness ahead of continued legislative attention (VASPs and firms handling transfers)
  • anticipate thematic reviews and the PEP questionnaire, and evidence remediation of known gaps

What businesses should take from this month’s developments

The Bank of Lithuania’s letter makes the expectation explicit: risk assessments, due diligence, monitoring, reporting and sanctions screening must reflect how the business actually operates, not just how it is documented.

At EU level, the AMLA era is arriving on two tracks. The 2027 eligibility data collection, with 31 December 2026 as the reference date, will determine which institutions face direct AMLA supervision from 2028. The Central Contact Point survey shows AMLA building the technical rules for cross-border payment and e-money business.

With MONEYVAL starting in October 2026 and the EU AML package applying in full from 10 July 2027, the remediation window is now clearly defined.


Need assistance?

ECOVIS ProventusLaw advises financial institutions, fintechs, CASPs and other obliged entities on AML/CTF compliance, including:

  • AML/CTF regulatory assessments and gap analysis;
  • business-wide ML/TF risk assessments;
  • AML policies, internal controls and procedures;
  • customer due diligence and enhanced due diligence frameworks;
  • transaction monitoring and suspicious transaction reporting;
  • AML governance, MLRO responsibilities and employee training;
  • CASP and virtual asset AML/CTF requirements;
  • regulatory inspections and remediation of identified deficiencies.

If your organisation is preparing for increased AMLA or national supervisory scrutiny, our team can help assess whether your AML framework is not only documented but operationally effective and ready for regulatory review.

Related news

Knowledge without experience is of little use. Therefore we are proud of having our own valuable experience to share with you.

Contact person

+370 5 212 40 84

[email protected]

Inga Karulaitytė

Lawyer, Attorney at law, Partner, Head of Banking and Finance & FinTech, CAMS

Contact person

+370 5 212 40 84

[email protected]

    Newsletter SubscriptionGet in touch