← All articlesAll firms17 June 2026 · 6 min read

Building your firm’s AML training log (and why supervisors ask for it)

How Irish firms should build an AML training log that stands up to supervisor inspection, and what to retrain on before the AMLR applies in July 2027.

When an AML supervisor inspects an Irish firm, one of the first things they ask to see is evidence that staff have been trained. Not a verbal assurance that "we covered it at the team meeting" — a record. Who was trained, on what, when, and how you know it landed.

Most firms do train their people. Far fewer can prove it. The training happens, the slides get emailed around, and two years later nobody can say which staff attended or what the session covered. That gap between doing the training and evidencing the training is where inspections go wrong.

There is now a second reason to fix this. From 10 July 2027, Regulation (EU) 2024/1624 (the AMLR) replaces the substantive AML rulebook your firm has been working under — the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 — with a directly applicable EU regulation. A lot of what your staff were trained on will be out of date on that day. Your training log is how you plan, deliver and evidence the retraining that has to happen between now and then.

Why supervisors ask for the log

Staff awareness is one of the few controls a supervisor can test quickly. Policies can be bought off the shelf; a training record shows whether the firm actually operates them. If your front-line staff cannot recognise a red flag or do not know who the MLRO is, everything downstream — customer due diligence, suspicious transaction reporting — fails quietly.

Expect the request whichever supervisor you answer to:

  • Estate agents, letting agents, auctioneers and property management firms — the PSRA
  • Solicitors — the Law Society of Ireland
  • Accountants, auditors and tax advisers in membership of a body — the designated accountancy bodies (Chartered Accountants Ireland, ACCA, CPA Ireland)
  • TCSPs, high-value goods dealers and unaffiliated accountants or tax advisers — the AMLCU (Department of Justice)
  • Credit and financial institutions — the Central Bank of Ireland

Note for TCSPs and other AMLCU-supervised firms: an administrative financial sanctions regime for the AMLCU has been in force since 30 June 2026 (S.I. No. 307 of 2026), so enforcement in that sector is getting teeth before the AMLR even applies.

What a good training log actually records

A training log is not a certificate folder. It is a register your firm maintains continuously. For every training event, capture:

FieldWhat to record
Date and durationWhen the session ran and how long it was
AttendeesNamed individuals — and who was absent, with a follow-up date
Trainer and formatInternal or external; live, e-learning, written briefing
Content coveredTopics, not just a title — keep the materials with the record
AssessmentQuiz score, sign-off, or confirmation of understanding
Next due dateWhen each person's refresher falls due

Two of these do the heavy lifting. Recording absentees turns the log into a management tool rather than a scrapbook — it tells you who still needs the session. And keeping the actual materials alongside the register lets an inspector see the substance, which is what distinguishes real training from a tick-box exercise.

Keep the log for at least five years. The AMLR takes a firm line on record-keeping — retain for five years, then delete — so build both retention and eventual deletion into how you store training records.

Who needs to be on it

Everyone whose work touches clients, money or client records — not just the MLRO. That includes reception and administrative staff who onboard clients, fee earners, negotiators, bookkeepers, and partners or directors. Senior people are the group most often missing from training logs, and the group inspectors most enjoy asking about.

The AMLR also prescribes compliance roles: a board-level compliance manager plus a compliance officer of sufficiently high standing. Whoever holds those roles in your firm needs deeper training than the general staff session — and from 10 July 2027 the compliance officer also becomes responsible for targeted financial sanctions implementation, which is its own training topic.

Train new joiners before they handle client work, and log induction training like everything else.

What to retrain on before July 2027

Your existing CJA 2010-era training does not need to be thrown out — the core skills of recognising suspicion and escalating internally carry over. But the rulebook underneath changes, and your 2026–27 training plan should cover at least:

  • The shift from "designated persons" under the CJA 2010 to "obliged entities" under the AMLR — same firms, new terminology, new source of rules
  • The CDD threshold for occasional transactions dropping to €10,000, with occasional cash transactions of €3,000 or more triggering limited CDD
  • The EU-wide €10,000 cash payment cap for commercial transactions — staff who take payments need to know this cold
  • Beneficial ownership at 25% or more, direct or indirect, harmonised EU-wide — plus your existing RBO duties: obtaining an extract before a new business relationship and reporting discrepancies
  • Enhanced due diligence triggers for high-net-worth relationships (assets of €5m or more handled for a client whose total wealth is €50m or more)
  • STR reporting in Ireland remains dual: to FIU Ireland via the goAML portal and to the Revenue Commissioners via ROS — staff should know the internal escalation route to the MLRO, and the MLRO should know both channels
  • Responding to FIU requests within 5 working days — who in the firm owns that clock

A sensible sequence: a general awareness refresher in late 2026, a focused "what changes under the AMLR" session in early 2027, and role-specific sessions for the compliance officer and anyone handling cash or onboarding. Every one of those goes in the log.

A worked example (hypothetical)

Suppose a three-partner accountancy practice runs a one-hour AMLR-changes briefing in March 2027. The log records the date, the trainer, all eleven attendees by name, the two staff who were out sick and their catch-up date, the slide deck as an attachment, and a five-question quiz result for each attendee. When their designated accountancy body next reviews the firm, the training question takes ninety seconds to answer.

What to do now

  1. Create the register today — a single structured record beats scattered certificates.
  2. Reconstruct what you can of the last two years of training from emails, calendars and CPD records, and log it honestly.
  3. List everyone in scope, including partners, directors and support staff, and note when each person was last trained.
  4. Book a general refresher for late 2026 and an AMLR-changes session for early 2027, and put both in the diary now.
  5. Assign owners: who maintains the log, who chases absentees, who signs off that the compliance officer's training is adequate.
  6. Set a five-year retention rule for training records — and a deletion process to match.

How CompliDesk helps

CompliDesk Ireland includes a training register built for the AMLR from day one — attendance, materials, absentee follow-ups and refresher reminders in one place, ready to hand to an inspector. See what changes under the AMLR or book a demo to see the training log in action.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist