If you run an Irish accountancy practice, you have almost certainly been a "designated person" under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 for years. You have an AML policy somewhere, a risk assessment that gets dusted off before a monitoring visit, and a partner who acts as MLRO alongside everything else.
On 10 July 2027, the ground shifts. Regulation (EU) 2024/1624 (AMLR) — a directly applicable EU regulation, with no Irish transposition needed for its substantive rules — replaces the rulebook your current programme was written for. Alongside it, Directive (EU) 2024/1640 (AMLD6) reshapes the supervisory and institutional layer, and the new EU Anti-Money Laundering Authority (AMLA) is already producing technical standards and guidance.
The practical consequence: a policy pack written for the CJA 2010 world will be out of date on day one. This checklist walks through what a small or mid-sized practice should review, in roughly the order it makes sense to tackle it.
1. Confirm who supervises you — and that your registrations are current
Nothing in your file matters if the basics are wrong.
- If your practice is affiliated to a professional body, your AML supervisor is your designated accountancy body — Chartered Accountants Ireland, ACCA or CPA Ireland, among others.
- If you are an unaffiliated accountant or tax adviser, your supervisor is the Anti-Money Laundering Compliance Unit (AMLCU) at the Department of Justice.
- Check your MLRO is registered with FIU Ireland on the goAML portal (fiu-ireland.ie). Suspicious Transaction Reports in Ireland are dual-reported: to FIU Ireland via goAML and to the Revenue Commissioners via ROS. Your firm needs to be set up on both before it ever needs to file.
- Check your firm has designated-person access to the Register of Beneficial Ownership (rbo.gov.ie), obtained via the BEN3A1 form. Post-CJEU, access is tiered, and designated persons use the restricted tier.
One thing you do not need to worry about: Ireland has no threshold transaction reporting regime. Reporting here is suspicion-based.
2. Refresh your business-wide risk assessment against the AMLR
Your existing firm-wide risk assessment was almost certainly structured around the CJA 2010 and the guidance built on the old directives. Under the AMLR, the risk assessment remains the foundation of everything else — but the inputs change. When you refresh it, work through:
- Your client base against the AMLR's obliged-entity categories and terminology (Irish law says "designated persons"; the AMLR says "obliged entities" — expect supervisors and guidance to use both for a while).
- Services that touch the new thresholds: occasional transactions, cash handling, and any clients who might fall within the enhanced due diligence rules for high-net-worth relationships.
- Whether any clients are themselves newly in scope — for example, crypto-asset service providers or traders in high-value goods — because that changes the risk profile of acting for them.
Treat the refreshed assessment as the document that justifies every other choice in your programme — that is how supervisors will read it.
3. Rework your CDD thresholds and procedures
This is where most of the redrafting effort sits. Headline changes under the AMLR:
| Area | Current practice under CJA 2010 era rules | From 10 July 2027 (AMLR) |
|---|---|---|
| Occasional transactions | CDD from €15,000 | CDD from €10,000 |
| Occasional cash transactions | No separate lower trigger | Limited CDD from €3,000 |
| Cash payments | No EU-wide cap | €10,000 cap on commercial cash payments, single or linked |
| Beneficial ownership | 25% plus one share in practice | Harmonised at 25% or more, direct or indirect |
A few points worth flagging to staff early:
- The €10,000 cash cap applies to commercial transactions across the EU and is directly applicable. Clients who take large cash payments — and some of yours will — need to know before 2027, and your engagement risk assessments should reflect it.
- Enhanced due diligence applies to high-net-worth relationships involving assets of €5 million or more handled for a client whose total wealth is €50 million or more. AMLA guidance on the €50 million test is due by 10 July 2027, so keep that section of your procedures marked for review.
- The beneficial ownership threshold is harmonised at 25% or more, but the European Commission may later lower it to as little as 15% for high-risk sectors by delegated act, following a review due by 2029. Draft your procedures so the number is easy to change.
4. Tighten your RBO workflow
Since April 2021, designated persons must obtain an RBO extract before entering a new business relationship with a company, and must report discrepancies between the register and what their own CDD finds. Many practices do this inconsistently. Before 2027:
- Build the RBO extract into your new-client onboarding as a mandatory step, not an afterthought. Extracts cost a few euro each and there is no API — this is a manual, evidenced process.
- Record the comparison between the extract and the beneficial ownership information the client gives you, and document the decision on whether a discrepancy exists.
- Remember Ireland has three beneficial ownership registers: the RBO for companies, CRBOT for trusts (via Revenue) and the Central Bank of Ireland register for ICAVs and similar vehicles. Know which one applies before you search.
5. Assign the prescribed compliance roles
The AMLR prescribes two roles: a compliance manager at board (or equivalent management) level, and a compliance officer of sufficiently high standing. In a small practice these conversations are awkward — the same two or three people do everything — but the designations need to be made, minuted and reflected in your policies. Note also that from 10 July 2027 the compliance officer becomes responsible for implementing targeted financial sanctions, so sanctions screening moves formally into that role's remit.
6. Records, retention and response times
Two operational points to build into procedures now:
- Records must be retained for 5 years and then deleted. Retention without deletion is no longer a safe default — your file management needs an end date, not just a start date.
- Requests from the FIU must be answered within 5 working days (shorter for some categories). If your client files are scattered across email, paper and a shared drive, a five-day clock is uncomfortable. Centralising CDD evidence is the fix.
What to do now
- Verify your supervisor relationship and confirm goAML, ROS and RBO registrations are live.
- Diarise a business-wide risk assessment refresh for late 2026, once more AMLA standards have landed.
- Redraft CDD procedures around the €10,000 and €3,000 triggers and the €10,000 cash cap.
- Make the RBO extract and discrepancy check a mandatory onboarding step.
- Designate your compliance manager and compliance officer, and minute it.
- Map your record retention to the 5-year keep-then-delete rule.
- Brief staff and clients on the cash cap well before July 2027.
Getting AMLR-ready with CompliDesk
CompliDesk Ireland is being built for the AMLR from day one — policy packs, a business-wide risk assessment generator and RBO workflows designed around Regulation (EU) 2024/1624 rather than retrofitted from the old rules. Download the full AMLR readiness checklist to work through with your team.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.