AMLR policy pack & compliance programme
Generate the policies, procedures and controls the AMLR requires, designate the prescribed compliance roles, and keep the whole programme versioned and evidenced.
What the AMLR requires of your compliance programme
Under Regulation (EU) 2024/1624 (the AMLR), every obliged entity must have internal policies, procedures and controls that are proportionate to its business and grounded in its risk assessment — covering customer due diligence, suspicious-transaction reporting, record-keeping, staff training and the compliance function itself. Irish firms have run policies and procedures under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 for years; from 10 July 2027 the AMLR sets the requirements directly, and documents written for the old framework need rebuilding against the new one.
The AMLR is also more prescriptive about who owns compliance. It requires two designated roles — a compliance manager at management-body level and a compliance officer of sufficiently high standing — even in small firms.
Two prescribed roles, clearly separated
The compliance manager
A member of the management body responsible for ensuring the firm’s policies, procedures and controls comply with the AMLR — accountability at the top, not delegated out of sight.
The compliance officer
A person of sufficiently high standing who runs day-to-day compliance — and who, from 10 July 2027, also becomes responsible for implementing targeted financial sanctions.
The CompliDesk policy pack generator
Drafting an AMLR-compliant programme from a blank page is slow, and buying a generic template gives you a document that describes someone else’s firm. CompliDesk generates your policy pack from a structured questionnaire about your business, maps each policy and control to the AMLR’s requirements, and embeds the compliance manager and compliance officer designations. It sits alongside the BWRA generator, so the two documents an inspector reads together are actually built together.
- AMLR-native structure — policies, procedures and controls organised around Regulation (EU) 2024/1624, not a legacy framework.
- Role designation built in — the prescribed compliance roles named, with the designation on record.
- Training log — evidence of who was trained, on what, and when.
- Versioning & audit trail — every revision and approval logged, so the document’s history is inspectable.
- Retention discipline — records kept for the five years the AMLR requires, then deleted.
How the feature works
Build
Answer a structured questionnaire about your firm — sector, services, size, risk profile. CompliDesk generates a policy pack mapped to the AMLR’s internal policies, procedures and controls requirements, aligned with your BWRA.
Adopt
Designate your compliance manager and compliance officer in the pack, then export it for formal approval by the management body — with the sign-off recorded.
Train
Record who was trained, on what, and when in the training log, so the awareness obligation is evidenced rather than assumed.
Maintain
Every revision is versioned with a full audit trail. When guidance shifts or your services change, update the pack and the history shows exactly what changed and when.
Why it matters in Ireland right now
Your policies and controls are the second thing an inspector reads, straight after your BWRA — and Irish supervision is sharpening before the AMLR even applies. An administrative financial sanctions regime for the sectors supervised by the AMLCU at the Department of Justice has been in force since 30 June 2026 (S.I. No. 307 of 2026), and Ireland has published an AML/CFT action plan running through 2027. Whichever supervisor covers your sector — a designated accountancy body, the Law Society, the PSRA or the AMLCU — a programme rebuilt against the AMLR, with the prescribed roles designated and the training evidenced, is what readiness looks like on paper.
Who needs it
Every designated person needs documented policies, procedures and controls. CompliDesk generates them for:
- Accountants & tax advisers
- Solicitors
- Estate & letting agents
- Trust & company service providers
- High-value goods dealers
Good practice for your compliance programme
- Designate the compliance manager and compliance officer by name and record the designation — an unnamed role is an unfilled one.
- Have the management body formally approve the pack, and keep the approval with the document.
- Keep policies consistent with the BWRA — a control your risk assessment doesn’t justify reads as boilerplate.
- Log training as it happens; reconstructing it before an inspection convinces nobody.
- Treat the pack as versioned software, not a PDF: change it deliberately, and keep the history.
Frequently asked questions
Does the AMLR still have a Part A / Part B programme structure?
That split belongs to other regimes — Ireland never had it, and the AMLR doesn’t either. The AMLR requires obliged entities to have internal policies, procedures and controls proportionate to their business and grounded in their risk assessment, covering due diligence, reporting, record-keeping, training and the compliance function. CompliDesk’s pack is generated against that AMLR structure directly.
Who can be the compliance officer — and do we need a compliance manager too?
The AMLR prescribes both roles: a member of the management body responsible for compliance (the compliance manager) and a compliance officer of sufficiently high standing who runs the day-to-day framework. From 10 July 2027 the compliance officer also becomes responsible for implementing targeted financial sanctions. In a small firm the same people may already hold adjacent roles — our guide on appointing the compliance officer and manager covers the practicalities, including how the roles sit alongside the MLRO you already have.
How is this different from buying a policy template?
A template describes a generic firm; a supervisor inspects yours. CompliDesk generates the pack from your answers, ties it to your Business-Wide Risk Assessment, embeds your role designations, and then keeps it alive — versioned, reviewed and evidenced — instead of frozen at the date on the cover.
How often should the policy pack be reviewed?
Review it regularly and whenever something material changes — new services, new client types, or regulatory movement, and 2026–27 brings plenty as AMLA technical standards land and Ireland transposes Directive (EU) 2024/1640. Versioning means each review leaves a trace an inspector can follow.
Replace the binder with a programme you can prove
See the AMLR policy pack, role designation and training log working together — or join the waitlist for free early access before the platform launches ahead of 10 July 2027.