Picture the scenario. Your MLRO opens an information request from FIU Ireland relating to a client file your firm last touched eighteen months ago. The identity documents are in a scanned folder somewhere. The beneficial-ownership notes are in a Word document on a former staff member's drive. The transaction records are split between your practice management system and an email thread.
Today, pulling that together in a hurry is stressful. From 10 July 2027, it becomes a hard regulatory deadline. Under Regulation (EU) 2024/1624 (the AMLR), obliged entities must answer FIU requests for information within 5 working days — and for some categories of request the window is shorter still.
If your firm's client records live in filing cabinets, shared drives and inboxes, that clock should worry you. Here is what is changing, and how to get ahead of it.
Who FIU Ireland is, and why it contacts firms
FIU Ireland is the State's Financial Intelligence Unit, sitting within An Garda Síochána. It is the body that receives Suspicious Transaction Reports (STRs) from designated persons through the goAML portal at fiu-ireland.ie.
Remember that Ireland operates dual reporting for STRs: reports go to FIU Ireland via goAML and to the Revenue Commissioners via ROS, where the goAML-generated XML upload is accepted. Your MLRO needs to be registered on both systems. (There is no threshold transaction reporting regime in Ireland — STRs are the reporting obligation that matters for most firms.)
An STR is often the start of a conversation, not the end of one. Once intelligence is in the system, the FIU may come back to firms for more: the underlying customer due diligence file, transaction detail, beneficial-ownership information, correspondence. That is where the new deadline bites.
What the AMLR changes on 10 July 2027
Irish firms have been designated persons under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 for more than fifteen years, and cooperating with the FIU is nothing new. What changes is the framework and the precision of the obligation.
The EU's new AML package has two instruments to keep straight here:
- Regulation (EU) 2024/1624 (AMLR) — the directly applicable single rulebook for firms. It sets the obligations you must meet, including answering FIU information requests within 5 working days (shorter for some categories). No Irish transposition is needed; it applies to your firm automatically from 10 July 2027.
- Directive (EU) 2024/1640 (AMLD6) — the institutional layer, covering national FIU powers and supervision, which Ireland transposes into national law.
The practical upshot: a uniform, EU-wide response deadline sits directly on your firm, in the same instrument that sets your due diligence and record-keeping duties. A request that arrives on a Tuesday must generally be answered by the following Tuesday. Bank holidays help a little; disorganised records do not.
Why 5 working days is harder than it sounds
Five working days feels generous until you map what a real response involves:
- Someone must see the request promptly. If it lands while your MLRO is on annual leave and nobody else monitors the mailbox or goAML account, you may lose two of your five days before work even starts.
- You must locate the client file — identification documents, verification evidence, beneficial-ownership records, risk assessment, ongoing monitoring notes.
- You must locate the transaction detail, which in many small firms lives in a different system from the CDD file.
- Someone senior must review what goes out, check it actually answers what was asked, and ensure nothing about the response tips off the client.
- You must send it through the right channel and keep evidence of what you provided and when.
For a firm with clean, centralised, digital records, that is a half-day of work. For a firm where each partner keeps files their own way, it can genuinely take longer than the deadline allows — especially if the file is old. And note that the AMLR's record-keeping rule is retain for 5 years, then delete: your retrieval process needs to work across that whole retention window.
Ownership: this lands on your prescribed compliance roles
The AMLR requires obliged entities to designate a compliance manager at board level and a compliance officer of sufficiently high standing. In most Irish firms these duties will sit with, or alongside, the person currently acting as MLRO.
FIU responsiveness is a natural test of whether those roles are real or nominal. A named officer with no deputy, no documented procedure and no authority to pull files from colleagues will struggle to hit a 5-working-day deadline. Build the response process into the role descriptions now, including:
- who receives and triages FIU correspondence, and who covers absences
- who has authority to access every client file in the firm without waiting for a partner's permission
- who signs off the outgoing response
- where the audit trail of the request and response is stored
A hypothetical worked example
Suppose — purely hypothetically — a two-partner practice in Galway filed an STR in 2027 about an unusual client payment. Months later, a request for the full CDD file arrives.
A prepared firm's timeline looks like this: Day 1, the request is logged and assigned. Day 2, the file — held in one system, with identification evidence, the beneficial-ownership record and the client risk rating attached — is exported and reviewed by the compliance officer. Day 3, the response goes out, and the request, response and dates are recorded. Two days to spare.
An unprepared firm's timeline: Day 2, the request is noticed. Days 3–4 are spent hunting for a scanned passport and reconstructing beneficial-ownership notes from emails. Day 5 is a scramble, and the response is late, incomplete, or both — in front of the one body you least want to look chaotic to.
What to do now
- Register and verify access. Confirm your MLRO's goAML registration with FIU Ireland and your Revenue ROS access for STR reporting are current, and that login details are not held by one person alone.
- Nominate and deputise. Decide who will hold the AMLR's compliance manager and compliance officer roles, and name a deputy for FIU correspondence.
- Write a one-page response procedure. Receipt, triage, file retrieval, senior review, dispatch, record. Include the 5-working-day deadline explicitly.
- Centralise client files. Get CDD evidence, beneficial-ownership records and risk assessments for each client into one retrievable place — not spread across drives and inboxes.
- Run a fire drill. Pick a random client file from two years ago and time how long it takes to assemble a complete response pack. If it takes more than a day, fix what slowed you down.
- Check retention. Make sure records are kept for the full 5-year period — and deleted after it — so old files are neither missing nor lingering.
Where CompliDesk fits
CompliDesk Ireland is built for the AMLR from day one: every client's CDD evidence, beneficial-ownership records and STR history in one place, retrievable in minutes rather than days. See what the AMLR changes for Irish firms, or run the fire drill on your own files first — we think you'll see the point quickly.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.