Anti-Money Laundering Authority: What AMLA and National AML Supervisors Do
An anti-money laundering authority is a public body that writes, supervises, and enforces the rules obliged entities must follow to detect and report money laundering and terrorist financing. The job rarely sits with one agency. In most countries it is divided up: a financial intelligence unit (FIU) takes in and analyzes suspicious activity reports, one or more sectoral supervisors examine firms for AML compliance, and law enforcement investigates and prosecutes. For 2026 and beyond, the headline development is the European Union's new Anti-Money Laundering Authority (AMLA), a single EU-level supervisor headquartered in Frankfurt that will eventually take direct supervision of selected high-risk firms.
For compliance teams, the textbook definition of money laundering is beside the point. What you need to know is which authority supervises your business, what they will inspect, and how to stay ready for them. This guide walks through the main AML authorities a regulated firm answers to and what each one actually does.
The European Anti-Money Laundering Authority (AMLA)
The Anti-Money Laundering Authority (AMLA) is a new EU body built to centralize and strengthen anti-money laundering and counter-terrorist-financing supervision across the bloc. EU legislation adopted in 2024, part of a wider AML reform package, established it. Its headquarters sit in Frankfurt, Germany. Through 2024 and 2025, AMLA began standing up its organization, and full operational capacity is expected over the following years.
Why does it exist? For years, AML supervision in the EU has been scattered across national regulators, leaving uneven standards and cross-border gaps that criminals exploited. The European Banking Authority (EBA) previously held a coordinating AML mandate but had limited direct power over individual firms. AMLA closes that gap. It combines direct supervision of the highest-risk cross-border firms with stronger coordination of national supervisors and financial intelligence units.
What AMLA does
AMLA's mandate has two broad dimensions. On the supervisory side, it will directly supervise a group of selected high-risk obliged entities, primarily large financial institutions operating across multiple member states, while overseeing and coordinating the national authorities that supervise everyone else. On the FIU side, it supports cooperation and joint analysis among the EU's financial intelligence units and helps develop common standards for how suspicious activity is reported and shared.
In practice, AMLA will set technical standards and guidelines under the EU's single AML rulebook, run or coordinate inspections, and use its convening power to push consistent expectations across member states. Direct supervision of selected entities is expected to begin from around 2028, according to the EU's published timeline. The years in between go toward building capacity, picking the in-scope firms, and finalizing supervisory methodology. Any new regulator's timeline can slip, so track AMLA's own announcements rather than lean on fixed dates.
Who AMLA supervises
AMLA will not supervise every regulated firm in Europe directly. Its direct remit targets a limited population of selected obliged entities judged to carry the highest cross-border money laundering and terrorist financing risk. The much larger universe of banks, payment firms, crypto-asset service providers, and other obliged entities stays with national competent authorities. Those national supervisors, though, will work under AMLA's coordination, common standards, and oversight. The point is to level the playing field, so a firm operating in several member states meets consistent expectations rather than a patchwork.
National AML authorities and supervisors
Outside the EU's new central structure, most countries run AML supervision through a financial intelligence unit paired with one or more prudential or conduct regulators. Knowing which body does what matters. Each carries different powers, reporting channels, and examination styles.
Financial intelligence units (FIUs)
A financial intelligence unit is the national hub that receives suspicious activity or suspicious transaction reports from obliged entities, analyzes them, and disseminates intelligence to law enforcement and international partners. Your transaction monitoring program feeds the FIU, so how clear and accurate your filings are decides how useful that intelligence ends up being. Many FIUs belong to the Egmont Group, an international network that lets FIUs exchange information across borders.
The United States: FinCEN
In the United States, the Financial Crimes Enforcement Network (FinCEN) is the national FIU and the administrator of the Bank Secrecy Act. It issues regulations, collects Currency Transaction Reports and Suspicious Activity Reports, and sets expectations for AML programs. Functional regulators such as the federal banking agencies examine institutions for compliance. Got US exposure? FinCEN guidance and rulemakings are a primary source of your obligations.
The United Kingdom: the FCA and others
In the United Kingdom, the Financial Conduct Authority (FCA) supervises most financial-sector firms for AML compliance, alongside other supervisors for specific sectors. The FCA expects firms to run a risk-based program, size customer due diligence to the risk at hand, and show that ongoing monitoring actually works. UK firms also file suspicious activity reports to the National Crime Agency, which performs the FIU function.
How supervisors examine firms
Jurisdiction aside, AML supervisors tend to inspect along the same lines. They assess your firm's money laundering risk assessment, test whether customer due diligence and enhanced due diligence are applied consistently, review the calibration and effectiveness of your screening and transaction monitoring, sample alert and case files for quality of decisioning, and check governance, training, and the independence of the compliance function. Fall short and penalties follow, from remediation orders and fines to restrictions on business and, in the worst cases, individual liability for senior managers.
What this means for your compliance program
The spread of AML authorities, and the EU's move toward a single central supervisor, all point one way. Supervisors increasingly want demonstrable, well-documented, technology-enabled controls, not paper policies. A modern program needs three things examiners can see and test. First, screening that reliably catches sanctions, politically exposed persons, and adverse media at onboarding and on an ongoing basis. Second, monitoring that adapts to changing risk and produces explainable alerts. Third, a clear audit trail showing how each alert was reviewed and resolved.
This is where AML screening and monitoring tooling does the heavy lifting. KYC Hub provides exhaustive AML screening against sanctions and watchlists, continuous monitoring with configurable AML alerts, and global adverse media intelligence that surfaces negative news a name-only check would miss. Network intelligence connects related entities and beneficial owners, so hidden risk becomes visible. Risk-based tuning cuts false positives, freeing analysts to work the alerts that matter. Each piece maps directly to what an AML authority will inspect. Run the program well and supervisory readiness comes with it, instead of turning into a separate scramble before an exam.
Show a supervisor consistent customer due diligence, defensible monitoring logic, and a full history of how alerts were handled, and the inspection turns into a chance to demonstrate control rather than a source of risk.



