Ask an Irish firm about its AML training and you often get one of two answers. Either "we did a webinar a while back" or "our people know the clients, they'd spot anything odd". Neither survives contact with an inspector, because training is one of the first things every supervisor checks - and one of the easiest obligations to evidence properly if you set it up right.
Training is not an add-on to your AML programme. It is the mechanism that turns your policies from documents into behaviour. Under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 firms must train relevant staff, and under the AMLR - Regulation (EU) 2024/1624, applying from 10 July 2027 - training remains a core internal control that your compliance framework has to deliver and document. Here is how to do it in a way that actually works for a small Irish firm.
Who actually needs AML training?
More people than most firms assume. The realistic list:
- Client-facing staff - anyone who onboards clients, handles transactions or could encounter a red flag. In an estate agency that includes negotiators; in a practice it includes bookkeepers and support staff who process payments.
- Senior management and principals. They approve the risk assessment, own the culture and, under the AMLR's prescribed roles, one of them serves as the board-level compliance manager. Supervisors increasingly expect evidence that leadership was trained, not just the front line.
- Your compliance officer and MLRO, who need deeper, role-specific training - on reporting through goAML and Revenue's ROS, on the RBO duties, and from 10 July 2027 on targeted financial sanctions, which the AMLR puts squarely on the compliance officer.
- New joiners, before they touch client work, not at the next annual session months later.
A useful test: if a person could plausibly be the first to see something suspicious, they need to know what suspicion looks like and where to send it.
How often is often enough?
Irish law does not prescribe a fixed interval, and the AMLR keeps training risk-based rather than calendar-based. In practice, a defensible rhythm for a small firm looks like this:
- Induction training for every new relevant hire, before client contact.
- A refresher at least annually for everyone in scope. Annual is the norm supervisors are used to seeing; longer gaps invite questions.
- Event-driven training whenever something material changes: a new service line, a new client market, updated red-flag typologies, or a change in the rules.
That last category is about to matter a great deal. Between now and 10 July 2027, every Irish firm needs at least one substantial AMLR transition session covering the new thresholds - 10,000 euro for occasional transactions, 3,000 euro for occasional cash, the 10,000 euro cash cap - plus the harmonised beneficial-ownership rules and the new compliance roles. Ireland's National Risk Assessment and 30-point AML/CFT Action Plan, launched on 18 June 2026, are also natural inputs: your training should reflect the risks identified for your sector.
What should the training cover?
Generic slide decks are the weakest form of training. Content should be anchored in your firm's own risk assessment and procedures:
- The red flags your staff will actually meet - conveyancing funding patterns for a solicitor, tenant and landlord risks for an agent, company-formation risks for an accountant.
- Your CDD procedure, including when enhanced measures kick in and who approves them.
- The escalation route: how a staff member raises a concern with the MLRO, and the strict prohibition on tipping off.
- Beneficial ownership and your RBO workflow.
- Sanctions screening basics, ahead of the compliance officer's formal sanctions duty from July 2027.
- What happens after escalation - enough for staff to trust the process, without sharing details of actual reports.
Short and specific beats long and generic. Forty-five focused minutes on your own procedures is worth more than a half-day of abstract law.
How do you prove it happened?
This is where firms lose marks despite having done the work. An inspector cannot see the webinar you ran in 2024; they can only see the log. A training record that stands up shows, for each session:
- the date and duration;
- who delivered it and what materials were used - keep the slides or a content outline;
- an attendance list with names and roles, and a record of who missed it and when they were caught up;
- some evidence of understanding - a short quiz, a signed acknowledgement, or documented Q&A;
- for new joiners, the induction date relative to their start date.
Keep the log centrally, not in individual inboxes, and retain it in line with your record-keeping framework - under the AMLR that means a five-year retention-then-deletion discipline like everything else.
What to do now
- List everyone in your firm who could plausibly encounter a red flag - that is your training population.
- Check when each of them last received documented AML training; anyone over a year is due.
- Build or repair your training log using the fields above, and backfill what you can honestly evidence.
- Plan your AMLR transition session for well before 10 July 2027, covering the new thresholds and roles.
- Give your compliance officer dedicated preparation for the targeted financial sanctions duty arriving in July 2027.
- Add training to induction so no new joiner touches client work untrained.
Where CompliDesk fits
CompliDesk Ireland includes a built-in training log - sessions, attendees, materials and acknowledgements in one place - as part of an AMLR-ready compliance programme priced for small Irish firms. See what is included on the pricing page.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.