← All articlesAll firms19 June 2026 · 6 min read

Crowdfunding platforms join the obliged-entity list

From 10 July 2027 the EU AMLR brings crowdfunding providers into scope as obliged entities. What Irish platforms need to put in place, and when.

If you run a crowdfunding platform serving Irish or EU users, the ground is about to shift under you. Regulation (EU) 2024/1624 — the AMLR, the EU's new single AML rulebook — applies from 10 July 2027, and it widens the list of businesses covered by AML obligations. Crowdfunding providers are on that list.

For many platforms this is genuinely new territory. Unlike Irish accountants, solicitors and estate agents — who have been "designated persons" under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 for well over a decade — some crowdfunding businesses have never had to build a full AML programme before. Others sit adjacent to payments or investment activity and already carry obligations. Either way, the AMLR sets a common EU-wide standard, and it is directly applicable: no waiting for Irish transposition, no national variations in the core rules.

This post explains what joining the obliged-entity list actually means in practice, and what a sensible preparation timeline looks like from here.

What "obliged entity" means

The AMLR uses the term "obliged entity" for any business within its scope. Irish law has historically used "designated person" — under the CJA 2010 that is the label your compliance documents probably carry today, if you have any. From 10 July 2027, the AMLR's terminology and its substantive obligations take over as the operative rulebook.

The widened scope in the AMLR is deliberate. Alongside crowdfunding providers, it pulls in crypto-asset service providers (aligned with MiCA), traders in high-value and luxury goods above thresholds, mixed financial holding companies, and letting agents for tenancies with monthly rent of 10,000 euro or more. Football clubs and agents follow from 2029. The message from the EU legislator is clear: channels that move or pool money for third parties belong inside the AML perimeter.

Being an obliged entity means, at minimum:

  • carrying out customer due diligence (CDD) — identifying and verifying who you are dealing with
  • maintaining a business-wide risk assessment of the money laundering and terrorist financing risks your platform faces
  • having written internal policies, controls and procedures proportionate to your size and risk
  • appointing prescribed compliance roles (more on this below)
  • monitoring activity and reporting suspicions to the national Financial Intelligence Unit
  • keeping records for five years — and then deleting them

The core obligations, in plain terms

Customer due diligence

The AMLR harmonises when CDD is triggered and what it involves. The general threshold for occasional transactions drops to 10,000 euro (from 15,000 euro under the old framework), and occasional cash transactions of 3,000 euro or more trigger limited CDD. For an ongoing business relationship — which is what most platform accounts are — CDD applies from the outset, regardless of amount.

One helpful modernisation: the AMLR explicitly recognises eIDAS-aligned electronic identification for identity verification. For a digital-first platform, that means remote onboarding with electronic ID checks is a recognised route, not a workaround you have to justify.

Beneficial ownership

Where your users are companies or other legal entities — a business raising funds through your platform, for instance — you must identify the beneficial owners. The AMLR harmonises the test EU-wide at 25 per cent or more ownership interest, direct or indirect. In Ireland, designated persons already have duties around the Register of Beneficial Ownership (rbo.gov.ie), including obtaining an extract before entering a new business relationship and reporting discrepancies between the register and what your own checks reveal. Expect equivalent verification work to be a standing part of onboarding corporate fundraisers.

Compliance roles

The AMLR prescribes a governance structure rather than leaving it to firms to improvise. You will need a compliance manager at board level, plus a compliance officer of sufficiently high standing. From 10 July 2027 the compliance officer is also responsible for implementing targeted financial sanctions. For a small platform, these can be demanding roles to resource — which is exactly why the regulation forces the question early.

Reporting and responsiveness

Suspicious Transaction Reports in Ireland are dual-reported: to FIU Ireland via the goAML portal (fiu-ireland.ie) and to the Revenue Commissioners via ROS. Both registrations take lead time to set up, so do not leave them until 2027. The AMLR also requires obliged entities to answer FIU information requests within five working days — shorter for some categories — which assumes your records are organised enough to retrieve quickly.

Who supervises you, and who is watching them

The AMLR sets the rules; Directive (EU) 2024/1640 (AMLD6) organises national supervision and must be transposed by 10 July 2027. In Ireland, AML supervision of the financial sector — banks, funds, payment firms, insurers, CASPs — sits with the Central Bank of Ireland; other sectors have their own competent authorities, such as the PSRA for property services firms and the AMLCU in the Department of Justice for TCSPs and high-value goods dealers. Watch for confirmation of the supervisory arrangements that will apply to your specific authorisation as transposition lands, and take direction from your supervisor's published guidance.

Above the national layer sits AMLA, the new EU Anti-Money Laundering Authority in Frankfurt, created by Regulation (EU) 2024/1620 and operational since 1 July 2025. AMLA is issuing the technical standards and guidelines that will flesh out how the AMLR is applied — track amla.europa.eu — and it drives consistency in national enforcement. The days of light-touch supervision for newly scoped sectors should not be assumed.

A realistic build order

You have roughly a year. That is enough — if you treat it as a project, not a form-filling exercise in June 2027.

What to do now

  1. Confirm your scope position. Map your activities against the AMLR obliged-entity categories, and note any overlap with existing obligations you already carry.
  2. Draft your business-wide risk assessment. Think about your fundraiser profiles, investor base, geographies, payment channels and product design. Everything else flows from this document.
  3. Design your CDD workflow. Decide how you will identify and verify individuals and corporate users at onboarding, including beneficial-ownership checks and RBO extracts for Irish entities.
  4. Nominate your compliance roles. Identify your board-level compliance manager and your compliance officer, and document the appointments.
  5. Register the reporting plumbing. Get goAML and Revenue ROS registrations moving well ahead of the deadline.
  6. Plan for records. Build five-year retention — and deletion at the end of it — into your data architecture from the start, alongside your GDPR obligations.
  7. Watch the primary sources. The AMLR text is on eur-lex.europa.eu; AMLA standards are landing through 2026 and 2027 at amla.europa.eu.

Where CompliDesk fits

CompliDesk Ireland is being built AMLR-native for exactly this moment: risk assessment, CDD workflows, beneficial-ownership checks and STR preparation in one place, hosted in Ireland. If you are not sure whether your platform is caught, start with our scope checker.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist