AMLA May Miss the Next Københavns Andelskasse

AMLA may miss the next KBH

AMLA May Miss the Next Københavns Andelskasse

Why AMLA's selection criteria need a fraud-infrastructure test

AMLA’s direct supervision is one of the central innovations of the EU’s new AML/CFT framework. From 2028, AMLA will directly supervise a limited group of high-risk financial-sector obliged entities. The objective is sound: fragmented national supervision should be complemented by a Union-level supervisor with a cross-border perspective.

The problem lies in the selection architecture.

AMLA’s ordinary selection model is designed to identify large, complex, high-risk financial institutions or groups with a significant EU footprint. That is appropriate for major cross-border banking groups. It is much less suitable for the institutions that frequently enable online investment fraud, cyber-enabled fraud and transaction laundering: small banks, payment institutions, EMIs, merchant acquirers, technical processors, crypto ramps and other specialised payment gatekeepers.

These entities may be small in institutional terms but systemically important for fraud.

The legal selection test

The AMLA Regulation does not give AMLA ordinary direct supervisory competence over all risky financial-sector obliged entities. It creates a narrow selection mechanism.

The first filter is geographic eligibility. Under Article 12 AMLAR, AMLA periodically assesses credit institutions, financial institutions and groups of such institutions only where they operate, whether through establishments or under the freedom to provide services, in at least six Member States, including the home Member State.

The second filter is risk classification. The inherent and residual ML/TF risk profiles of eligible entities are classified as low, medium, substantial or high. Under Article 13 AMLAR, only entities whose residual risk profile is classified as high qualify as selected obliged entities for ordinary direct AMLA supervision.

The third filter is numerical capacity. AMLA’s first ordinary selection is aimed at a limited population of selected obliged entities. Where more than 40 entities qualify, AMLA may limit the list under the mechanism in Article 13 AMLAR.

The draft RTS under Article 12(7) AMLAR operationalise the geographic eligibility test for activities carried out under the freedom to provide services. Activity in another Member State is considered material where either the number of customers resident in that Member State exceeded 20,000 as of 31 December of the previous year, or the total annual amount of incoming and outgoing transactions generated by those customers in the previous year exceeded EUR 50 million.

The timing is equally important. The first selection process must start by 1 July 2027 and be completed within six months, thereafter, AMLA’s selection of directly supervised entities is to be repeated every three years. This periodic model may be adequate for large, stable banking groups, but it is poorly suited to fast-moving fraud infrastructure AMLA then publishes the list of selected obliged entities without undue delay, and direct supervision starts six months after publication. Direct supervision is therefore expected to begin in 2028, but not necessarily on 1 January 2028.

The methodology therefore relies on four filters: geographic reach, customer or value-based materiality, residual ML/TF risk classification and a periodic selection cycle based largely on historical data.

That is coherent as an administrative selection model for large, stable, cross-border institutions. It is weaker as a fraud-infrastructure detection model.

The first blind spot: harm does not follow the legal footprint

The six-Member-State threshold measures the legal and commercial footprint of the institution. It does not necessarily measure the cross-border footprint of the harm.

A small bank in one Member State can receive funds from victims across the Union through shell companies, intermediaries or high-risk merchants. A merchant acquirer may have a narrow legal footprint while processing payments from consumers in many Member States. An EMI may not have a large customer base in six Member States but may provide critical accounts or payment access to fraud-linked networks.

In such cases, the supervised entity may look local. The victims, transactions and laundering routes are not.

This distinction matters. Online fraud infrastructure is often built around access points: accounts, merchant IDs, virtual IBANs, acquiring relationships, crypto ramps and payment flows. The institution that enables the fraud may not be the largest institution in the chain. It may simply be the weakest gatekeeper.

Københavns Andelskasse as the warning case

Københavns Andelskasse was a small cooperative bank based in Copenhagen, Denmark when scammers took over the bank and used it for big-style cross-border money laundering (read our report here and here). The misuse of the small bank illustrates the category of risk that AMLA may miss.

It was not a large pan-European banking group. It was not a natural candidate for a selection model centred on operations in at least six Member States. Yet it became associated with serious money-laundering concerns and cross-border financial-crime relevance.

That is the warning. A bank does not need to be large to become dangerous. It needs to provide useful access to the financial system.

If an institution of this kind fails the six-Member-State eligibility test, it remains primarily under national supervision. That is precisely the level at which many European AML failures have occurred.

Deutsche Handelsbank and the high-risk PSP problem

The same structural issue arises with specialised payment banks, PSPs, EMIs and acquirers.

Many entities identified by EFRI in online investment-fraud cases would likely not be selected for direct AMLA supervision under the ordinary criteria. They may be too small, too local or too specialised. Yet their role in the fraud ecosystem may be central.

This is the specific defect in the current model: it assumes that the most relevant AML risks can be identified through institutional scale, geographic presence and residual risk scoring. In payment fraud, that assumption is incomplete.

A high-risk PSP may generate enormous consumer harm without satisfying the ordinary selection criteria. The aggregate victim damage can reach hundreds of millions or billions while the institutional footprint remains modest.

For this category, AMLA needs a special rule.

The missing criterion: cross-border transaction intensity

The draft RTS contain data points on transactions and transaction value. They also use EUR 50 million in incoming and outgoing transactions as one materiality threshold for freedom-to-provide-services activity. But the ordinary eligibility test does not use the number and pattern of cross-border consumer transactions as an independent fraud-risk trigger.

That is a material omission.

Fraud risk is often visible in transaction patterns before it is visible in institutional size. A payment institution processing thousands of small or medium-sized cross-border payments from consumers to high-risk merchants may pose a greater fraud-infrastructure risk than a larger institution with more conventional activity.

The following indicators should therefore matter independently:

the number of cross-border consumer transactions;

the number of Member States from which victim funds originate;

the number of consumer complaints or victim reports from multiple Member States;

the number of chargebacks, fraud claims or rejected transactions;

the concentration of transactions involving high-risk merchants, shell companies or nominee structures;

the use of virtual IBANs, reissued IBANs or layered payment structures;

the number of law-enforcement requests, FIU-related signals and adverse-media references;

and the speed with which transaction volumes grow after onboarding high-risk merchants or intermediaries.

A selection model that focuses on institutional footprint may miss transaction-intensive fraud gateways. AMLA should therefore measure not only where the institution operates, but what its transactions reveal.

The second blind spot: static reference dates and backward-looking data

The ordinary AMLA selection process is periodic and substantially backward-looking.

For the freedom-to-provide-services materiality test, customer numbers are measured as of 31 December of the previous year, and transaction value is measured over the previous year. For the first selection cycle, this points to 31 December 2026 customer data and 2026 transaction-volume data.

That is a serious limitation for fraud-infrastructure detection.

Fraud networks do not develop in three-year supervisory cycles. They move quickly. They test banks, PSPs, acquirers and EMIs until they find weak access points. Once a permissive financial institution is identified, victim funds can be processed at scale within months. A gatekeeper that looked immaterial on 31 December 2026 may become central to a cross-border fraud network during 2027.

A point-in-time customer threshold and a previous-year transaction threshold may therefore miss precisely the institutions that become dangerous after the reference date.

The model should be supplemented by a rolling-period and event-driven risk mechanism. AMLA should be able to act on rapid transaction growth, sudden increases in cross-border consumer payments, victim complaints from several Member States, abnormal chargebacks, law-enforcement requests, FIU-related signals, adverse media and links to high-risk merchants or shell-company networks arising after the reference date.

This weakness is particularly acute in the first selection cycle. The draft RTS provide that two important data points will not be used for the first selection process: the number of customers with high-risk activities and the number of customers whose CDD data is not yet aligned with Article 20 AMLR. Those are precisely the indicators that may reveal weak onboarding, deficient customer due diligence and high-risk payment activity.

Fraud risk is dynamic. AMLA’s ordinary selection model is not.

Existing exceptional transfer powers are not enough

The AMLA Regulation does contain exceptional transfer mechanisms. A national financial supervisor may request AMLA to assume direct supervision of a non-selected entity in exceptional circumstances. AMLA may also, where there are indications of serious, repeated or systematic breaches and insufficient national supervisory action, request a Commission decision temporarily transferring direct supervision to AMLA.

These mechanisms are important. But they do not fully solve the problem.

First, they are reactive. They are triggered by heightened risk, compliance failures, serious breaches or ineffective national action. Second, one route depends on a national supervisor requesting the transfer. Third, AMLA’s own route requires procedural escalation and a Commission decision.

That architecture is not equivalent to a dynamic fraud-infrastructure trigger.

The relevant question is not only whether an institution has already been proven to breach AML/CFT requirements systematically. The question is whether credible external signals show that the institution has become a cross-border fraud gateway and requires immediate Union-level scrutiny before the harm becomes irreversible.

What AMLA should add

AMLA should introduce a specific high-risk PSP and fraud-gatekeeper escalation mechanism.

This mechanism should apply to non-selected financial-sector obliged entities that do not meet the ordinary size or six-Member-State criteria but present credible indicators of cross-border fraud-infrastructure risk.

The trigger should not be institutional size. It should be operational relevance to cross-border financial crime.

Relevant triggers should include transaction-intensity indicators, victim reports from several Member States, law-enforcement requests, FIU-related signals, adverse media, abnormal chargeback levels, high-risk merchant portfolios, rapid transaction growth, shell-company concentrations, virtual IBAN usage and repeated links to online investment fraud, pig-butchering scams or other consumer-fraud typologies.

Once triggered, AMLA should be able to require information from national supervisors, open an enhanced supervisory review, coordinate joint inspections, issue binding recommendations and, where necessary, initiate the temporary transfer procedure.

This would not replace national supervision. It would correct its most dangerous failure mode: treating a formally local institution as local even when its harm is cross-border.

Conclusion: AMLA must follow the transactions

AMLA is necessary. But direct supervision must not become limited to the largest and most visible institutions.

Financial-crime ecosystems do not organise themselves around supervisory eligibility criteria. They use whatever access point works: a small bank, a permissive EMI, a payment processor, a merchant acquirer, a crypto ramp, a local account provider or a specialised payment institution ignored by national authorities.

The next Københavns Andelskasse or Deutsche Handelsbank may not look like a pan-European financial group. It may look small, local and technically insignificant.

But for victims, it may be the institution that made the fraud possible.

AMLA’s credibility will therefore depend not only on which 40 entities it selects in its ordinary cycle, but on whether it can identify smaller institutions that function as cross-border fraud infrastructure in practice.

The missing question is not only: in how many Member States does the institution operate?

The missing question is: how many cross-border fraud transactions did it enable and how quickly can AMLA act before the damage becomes irreversible?

More about this topic.