If your firm provides trust or company services in Ireland, you have probably filed the EU's new AML rulebook under "2027 problems." Understandable: Regulation (EU) 2024/1624 (AMLR) does not apply until 10 July 2027.
But for TCSPs there is an earlier date to worry about. An administrative financial sanctions regime for the Anti-Money Laundering Compliance Unit (AMLCU) — your AML supervisor within the Department of Justice — came into force on 30 June 2026 (S.I. No. 307 of 2026). In other words, enforcement in your sector got sharper teeth roughly a year before the substantive rules change, while the current rulebook — the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 — is still in force.
This post explains who the AMLCU supervises, what an administrative sanctions regime changes in practice, and how to use the next twelve months so that the same preparation covers both dates.
Who the AMLCU supervises
Ireland splits AML supervision of "designated persons" by sector. The Central Bank of Ireland covers banks, funds, payment firms, insurers and CASPs. The Law Society of Ireland covers solicitors. The designated accountancy bodies — Chartered Accountants Ireland, ACCA and CPA Ireland among them — cover their member firms.
The AMLCU, part of the Department of Justice, supervises the rest, including:
- Trust or company service providers (TCSPs)
- High-value goods dealers
- Accountants and tax advisers who are not members of a designated accountancy body
If your firm forms companies, acts as or arranges nominee directors or shareholders, provides registered office or business addresses, or acts as or arranges trustees, you are a TCSP and the AMLCU is your competent authority. Its guidance and registration material is published at amlcompliance.ie.
What "administrative sanctions" actually changes
Under the CJA 2010 as TCSPs have known it, the AMLCU's practical toolkit has centred on registration, inspections, directions and, at the serious end, criminal prosecution. Criminal proceedings are a heavy, slow instrument, and supervisors everywhere use them sparingly.
An administrative sanctions regime changes the economics of enforcement. It gives a supervisor a way to penalise compliance failures directly — without a criminal trial — which typically means action can be taken faster, more often, and for a wider range of breaches, including the unglamorous ones: an out-of-date business risk assessment, missing CDD records, no evidence of staff training, no documented policies and procedures.
Two things follow for your firm:
- The gap between "we'd fail an inspection" and "we get penalised" narrows. Housekeeping failures that might previously have drawn a warning or a follow-up letter sit squarely in the territory administrative regimes are built for.
- Paper compliance gets tested. A Word document written years ago and never reviewed is exactly what an inspection with sanction powers behind it is designed to expose.
We will not speculate here about penalty levels or how the regime will be applied — watch the AMLCU's own publications for the detail as it lands. The strategic point stands regardless: Ireland has published an AML/CFT Action Plan for 2026–2027, and the direction of travel is more enforcement capability in your sector, sooner.
Why this collides with the AMLR timeline
Here is the awkward sequencing for TCSPs:
| Date | What happens |
|---|---|
| 30 June 2026 | AMLCU administrative sanctions regime in force (S.I. No. 307 of 2026) — stronger enforcement of the current CJA 2010 obligations |
| 10 July 2027 | Regulation (EU) 2024/1624 (AMLR) applies directly — the substantive rulebook changes |
So the obligations you will be inspected against in the next twelve months are the existing ones, but the rulebook you must be ready for in July 2027 is new. The temptation is to treat these as two separate projects. They are not. The AMLR is an evolution of the same framework: risk assessment, CDD, beneficial ownership, reporting, internal controls. A firm that gets its current-law house in order now is most of the way to AMLR readiness — and the reverse is also true.
Headline AMLR changes that matter for TCSPs specifically:
- Terminology shifts from "designated person" (Irish law) to "obliged entity" (AMLR).
- CDD for occasional transactions triggers at €10,000, down from €15,000, with limited CDD for occasional cash transactions of €3,000 or more.
- A directly applicable €10,000 cash cap on commercial payments (single or linked operations).
- Harmonised beneficial ownership at 25% or more, direct or indirect — core territory for any firm structuring companies and trusts. The Commission may set a lower threshold (15% or lower) for high-risk sectors by delegated act after a review due by 2029.
- Prescribed compliance roles: a board-level compliance manager plus a compliance officer of sufficiently high standing, with the compliance officer also responsible for targeted financial sanctions implementation from 10 July 2027.
- FIU requests answered within 5 working days (shorter for some categories).
- Records kept for 5 years, then deleted — retention and deletion, not retention alone.
The current obligations to get right first
Because the next inspection cycle will test CJA 2010 compliance, start there. In practice that means being able to evidence:
- A current, documented business risk assessment that reflects your actual services and client base
- Policies and procedures that match what your firm actually does — not a template nobody has read
- CDD files for every client: identity verification, beneficial ownership, and the rationale for the risk rating applied
- RBO checks: since 2021, designated persons must obtain a Register of Beneficial Ownership extract before entering a new business relationship, and must report discrepancies between the register and what they find. Designated-person access is arranged via the BEN3A1 form at rbo.gov.ie
- STR arrangements: Ireland dual-reports suspicious transactions — to FIU Ireland via the goAML portal (fiu-ireland.ie) and to the Revenue Commissioners via ROS. Confirm your MLRO is registered on both
- Training records showing who was trained, on what, and when
If any of those bullets made you wince, that is your gap list.
What to do now
- Confirm your firm's registration position with the AMLCU and subscribe to updates at amlcompliance.ie so you see the sanctions regime detail when it is published.
- Run an honest gap review against the CJA 2010 obligations listed above — assume an inspector reads every file.
- Refresh your business risk assessment and date it. An undated or ancient risk assessment is the fastest credibility loss in any inspection.
- Check your RBO access and your goAML and ROS registrations before you need them, not during an inspection or when a suspicion arises.
- Designate your future AMLR compliance roles now — decide who will act as board-level compliance manager and who as compliance officer, so the July 2027 requirement is a formality.
- Plan one remediation programme covering both dates: fix current-law gaps first, and upgrade thresholds, cash-cap controls and retention practices to AMLR standards as you go.
How CompliDesk can help
CompliDesk Ireland is being built AMLR-native for exactly this sequencing: one programme that stands up to supervision under the CJA 2010 today and rolls forward to Regulation (EU) 2024/1624 without a rewrite. Start with our free AMLR readiness checklist to see where your firm stands.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.