EBA Guidelines on ML/TF Risk Factors (EBA/GL/2024/01)
- Issuing authority
- European Banking Authority (EBA)
- Effective date
- Applies from 30 December 2024
- Scope
- All EU Member States
Key requirements
EU-wide guidance on how to assess money laundering and terrorist financing risk. Tells firms how to spot risk factors in their customers, products, geography and transactions. The big change in this version: new Guideline 21 specifically for crypto-asset service providers sector-specific risk factors for CASPs operating in the EU.
Quick Summary
These guidelines help firms understand how to identify and assess money laundering and terrorist financing risks. They explain what risk factors firms should consider when dealing with customers, products, services, countries, and transactions. The latest version also introduces new guidance specifically for Crypto Asset Service Providers (CASPs).
What is it?
This is a practical handbook for carrying out AML risk assessments. They don't create new legal obligations, but they explain how firms can apply existing AML rules in practice. They also provide examples of higher and lower risk situations to help firms make informed decisions.
Who does it apply to?
- Banks
- Payment institutions
- Electronic money institutions
- Investment firms
- Crypto Asset Service Providers (CASPs)
- Financial institutions subject to EU AML rules
- AML and compliance professionals
- Risk management teams
Why does it matter?
Every firm is expected to understand the risks it faces before deciding how much due diligence to apply. These guidelines help firms take a risk-based approach instead of treating every customer or transaction the same. They also provide clearer expectations for firms offering crypto services.
What should firms do?
- Review how they identify and assess money laundering and terrorist financing risks.
- Update customer risk assessments to reflect the latest EBA guidance.
- Consider customer, product, geographic, and transaction risk factors when applying customer due diligence.
- Review the new guidance if they provide cryptoasset services.
- Update internal AML policies, procedures, and staff training where necessary.
- Monitor future updates to the Guidelines and adjust their risk framework accordingly.
AboutAML Breakdown
Not every customer presents the same level of risk. For example, a customer from a low-risk country with a simple banking relationship may require standard due diligence, while a customer with complex ownership structures or links to higher-risk jurisdictions may require additional checks. The latest version is also important because it introduces dedicated guidance for Crypto Asset Service Providers (CASPs). As crypto continues to grow, the EBA expects firms to understand the specific risks associated with cryptoassets and include those risks in their AML programmes. These guidelines don't replace the law. Instead, they help firms understand how to apply the law in practice, making them one of the most useful AML resources for compliance teams across the EU.
