← All articlesAccountants24 June 2026 · 7 min read

Your AMLR gap analysis, step by step: a guide for small accountancy practices

A practical, step-by-step AMLR gap analysis for small Irish accountancy practices: what to compare against your CJA 2010 file before 10 July 2027.

If you run a small accountancy practice in Ireland, you have almost certainly been a "designated person" under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 for years. You have an AML policy somewhere, a risk assessment that gets dusted off before a monitoring visit, and a partner who acts as MLRO alongside everything else they do.

That file was built for the CJA 2010 world. On 10 July 2027, Regulation (EU) 2024/1624 (the AMLR) starts to apply directly across the EU, and it replaces the substantive rulebook your current documents were written against. The AMLR is a regulation, not a directive, so there is no Irish transposition to wait for on the core obligations — the text on EUR-Lex is the text you will be measured against.

A gap analysis is simply a structured comparison: what does the AMLR require, what does your practice actually have, and what is the difference? Here is how to run one without turning it into a six-month project.

Step 1: Confirm who supervises you, and gather your current file

Before comparing anything, get your baseline in one place. Pull together your current AML policy, your business-wide risk assessment, your client due diligence procedures, your training records, and your MLRO appointment.

Confirm your supervisor while you are at it. If your practice is a member firm of a designated accountancy body — Chartered Accountants Ireland, ACCA or CPA Ireland — that body is your AML competent authority. If you are an unaffiliated accountant or tax adviser, your supervisor is the Anti-Money Laundering Compliance Unit (AMLCU) at the Department of Justice — see amlcompliance.ie.

Note the terminology shift too: Irish law calls you a designated person; the AMLR calls you an "obliged entity". Your refreshed documents should recognise both terms.

Step 2: Compare your CDD thresholds and triggers

This is where most CJA 2010-era procedures date fastest. Check your written procedures against the AMLR positions:

  • The customer due diligence threshold for occasional transactions drops to 10,000 euro, from 15,000 euro.
  • Occasional cash transactions of 3,000 euro or more trigger limited CDD.
  • A directly applicable EU-wide cap of 10,000 euro applies to cash payments for commercial transactions, whether as a single operation or linked operations.

If your procedures still quote the 15,000 euro figure, or say nothing about cash-specific triggers, mark that as a gap. Also check whether your identity-verification procedure recognises eIDAS-aligned electronic identification, which the AMLR explicitly accepts — useful for a small practice onboarding clients remotely.

One thing not to add: Ireland has no threshold transaction reporting regime, so do not import that idea from other jurisdictions. Your reporting obligation remains suspicious transaction reports, dual-filed to FIU Ireland via goAML (fiu-ireland.ie) and to the Revenue Commissioners via ROS (revenue.ie).

Step 3: Review your beneficial ownership procedures

Under the AMLR, a beneficial owner is anyone with 25 per cent or more ownership interest, direct or indirect, harmonised EU-wide. Check three things in your file:

  1. Does your CDD procedure apply the 25 per cent test consistently, including through indirect holdings?
  2. Do you obtain an RBO extract from rbo.gov.ie before entering a new business relationship with a company client, as designated persons have been required to do since April 2021?
  3. Do you compare the extract against what the client tells you, and record how you handled any discrepancy — including reporting it to the Registrar where required?

If your firm has never registered for designated-person access to the RBO (via the BEN3A1 form), that is a gap in itself. Be aware the Commission may later lower the ownership threshold, to 15 per cent or lower, for high-risk sectors by delegated act following a review due by 2029 — worth a note in your procedures so a future update is not a surprise.

Step 4: Check your compliance governance against the prescribed roles

The AMLR prescribes compliance roles rather than leaving structure entirely to the firm: a compliance manager at board level, plus a compliance officer of sufficiently high standing. From 10 July 2027 the compliance officer is also responsible for implementing targeted financial sanctions.

For a small practice this may in reality be one or two named partners, but the designation should be deliberate and documented. Compare that against your current set-up, where one person may informally hold everything. Ask: who is our board-level compliance manager, who is our compliance officer, and is the sanctions responsibility written into the role?

Step 5: Test your risk assessment, records and response times

Three final checks:

  • Business-wide risk assessment. Does it reflect the AMLR's risk factors and your actual client base, or was it last meaningfully updated years ago? A refresh against the new rulebook is a core readiness deliverable.
  • Records. The AMLR requires records to be retained for 5 years and then deleted. Many small practices retain indefinitely "to be safe" — under the new regime, deletion is part of the obligation, so your retention procedure needs an end point, not just a start.
  • FIU requests. Requests from the FIU must be answered within 5 working days, with shorter periods for some categories. Could your practice actually retrieve a client file and respond in that window? If the honest answer depends on which filing cabinet, that is a gap.

What to do now

  1. Assemble your current AML file and confirm your supervisor (designated accountancy body or AMLCU).
  2. Run the threshold comparison: 10,000 euro occasional transactions, 3,000 euro occasional cash, the 10,000 euro cash cap.
  3. Verify your RBO access, extract-before-relationship procedure, and discrepancy-reporting record.
  4. Name your compliance manager and compliance officer in writing, including sanctions responsibility.
  5. Diary a business-wide risk assessment refresh against the AMLR, and fix your retention procedure to 5-years-then-delete.
  6. Confirm your goAML and Revenue ROS registrations are live and the MLRO knows both portals.
  7. Set a review date well before 10 July 2027 — supervisory guidance under Directive (EU) 2024/1640 (AMLD6) and AMLA technical standards are still landing, so build in time to adjust.

None of these steps is difficult in isolation. The risk for a small practice is that no one owns the list, and June 2027 arrives with the gaps still open.

How CompliDesk can help

CompliDesk Ireland is being built for the AMLR from day one — gap analysis, a refreshed business-wide risk assessment, and an AMLR policy pack designed for small practices. Start with our free AMLR readiness checklist and see how your file measures up.

General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

Join the waitlist for CompliDesk Ireland and lock in founding-member pricing.

Join the waitlist