Most small Irish firms never read national AML documents, on the reasonable theory that they are written for banks, departments and supervisors. This one deserves an exception. On 18 June 2026, Ireland launched its National Risk Assessment of money laundering and terrorist financing, together with a 30-point AML/CFT Action Plan — and the timing is the message. With the EU's AML Regulation (the AMLR, Regulation (EU) 2024/1624) applying from 10 July 2027, Ireland is publicly sharpening its assessment of where risk sits and what will be done about it in the run-up. If you are a designated person — an accountancy practice, a solicitors' firm, an estate agency, a TCSP — this national exercise reaches your firm in very practical ways.
What is a National Risk Assessment, and why should a small firm care?
A National Risk Assessment (NRA) is the state's structured evaluation of where money-laundering and terrorist-financing risks concentrate across the economy — which sectors, products, channels and threats matter most in the Irish context. It exists because the whole AML framework is risk-based, and a risk-based system needs a shared, national picture of risk to calibrate against.
Here is why that reaches you: your own business-wide risk assessment is not supposed to be written in a vacuum. Firm-level risk assessments are expected to take account of risk identified at national and EU level. When the national picture is refreshed, the honest question for every firm is whether its own risk assessment still reflects the environment it operates in — or reflects the environment as it looked when the document was last touched. A business-wide risk assessment that predates the June 2026 NRA and never engages with it is easy for a supervisor to challenge.
What does the 30-point Action Plan signal?
We will not summarise findings the plan and NRA speak for themselves on — read the source documents rather than second-hand paraphrases, and be wary of anyone quoting statistics from them without a citation. But the existence and shape of a 30-point action plan, launched a year and a month before the AMLR applies, signals three things clearly:
- Enforcement is tightening before 2027, not after it. The clearest concrete example: the AMLCU — supervisor of TCSPs, high-value goods dealers and unaffiliated accountants and tax advisers — now has an administrative financial sanctions regime in force, since 30 June 2026, under S.I. No. 307 of 2026. Teeth arrived before the new rulebook did.
- Supervisors will align their attention with the national picture. Sector supervisors — the Central Bank, the Law Society, the designated accountancy bodies, the PSRA, the AMLCU — calibrate their supervisory focus against national risk findings. Where the NRA points, inspections tend to follow.
- Ireland is positioning for the AMLR transition. The AMLR arrives as a directly applicable EU regulation on 10 July 2027, with AMLA in Frankfurt driving supervisory convergence across the EU. A national action plan spanning the transition period is Ireland getting its house in order for that world.
How should you actually use the NRA in your firm?
Not by filing it. A practical, proportionate approach for a small firm looks like this:
- Read the parts that touch you. Start with the executive summary, then the sections covering your sector and the services you provide. This is an hour or two, not a week.
- Map findings to your business-wide risk assessment. For each relevant national finding, note where your own assessment addresses it — or does not. The gaps are your update list.
- Update, date and record. Revise your risk assessment where warranted, and record explicitly that the review considered the 2026 NRA. That single line of provenance is worth a lot in an inspection, because it evidences a living risk process rather than a static document.
- Push the changes downstream. A risk assessment update that changes nothing in client risk-rating, CDD depth or monitoring priorities has not really happened. If the national picture elevates a risk your firm is exposed to, your client-facing controls should show it.
A purely hypothetical example: a two-partner accountancy practice reads the NRA sections relevant to professional services, concludes that two of its service lines deserve a higher inherent-risk score, re-rates the handful of affected clients, and minutes the exercise. Total effort: a day. Inspection value: the difference between a programme that responds to its environment and one that does not.
Where does this fit in the road to 10 July 2027?
Think of the sequence: the NRA and Action Plan land in June 2026; the AMLCU's sanctions powers are in force from 30 June 2026; AMLA's technical standards work is progressing — AMLA submitted its draft technical standards to the European Commission around 10 July 2026, with Commission adoption still awaited — and the AMLR itself applies from 10 July 2027. Each step raises the cost of a stale compliance programme. The firms that treat 2026 as the preparation year, using the NRA refresh as the natural trigger to refresh their own documents, will meet the AMLR with a current risk assessment and updated controls. The firms that wait will be rewriting everything at once, against a deadline, under sharper supervision.
What to do now
- Get the NRA and Action Plan from official sources and read the sections relevant to your sector.
- Diarise a business-wide risk assessment review that explicitly considers the 2026 NRA, and minute it.
- Update client risk ratings, CDD depth and monitoring priorities wherever the review changes your view.
- If you are AMLCU-supervised, treat the sanctions regime in force since 30 June 2026 as your urgency benchmark.
- Fold this into your AMLR preparation timeline, so one refresh serves both purposes.
Where CompliDesk fits
CompliDesk Ireland keeps your business-wide risk assessment a living document — versioned, dated, and linked to the client ratings and controls that flow from it — so a national refresh becomes an afternoon's update, not a rewrite. For the full 2027 picture, start with our AMLR explainer.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.