Guide · Readiness

Your 12-month AMLR readiness plan (to 10 July 2027)

On 10 July 2027, Regulation (EU) 2024/1624 replaces the substantive AML framework Irish firms have worked under since 2010. Twelve months is enough time to get ready without heroics — if you sequence the work. Here is a quarter-by-quarter plan a small firm can actually run.

In brief

Work in four quarterly phases: gap analysis first, then a BWRA refresh, then policies and the two prescribed compliance roles, then training and end-to-end systems checks — finishing before the AMLR applies on 10 July 2027. Enforcement is already sharpening: the AMLCU’s administrative financial sanctions regime has been in force since 30 June 2026 under S.I. No. 307 of 2026.

The clock

Why start now rather than in 2027?

Two reasons. First, the AMLR applies directly — there is no Irish transposition to wait for, and no grace period after 10 July 2027. Second, the enforcement environment is tightening ahead of the deadline, not after it: the AMLCU can now impose administrative financial sanctions under S.I. No. 307 of 2026, in force since 30 June 2026, and Ireland’s National Risk Assessment and 30-point AML/CFT Action Plan, launched on 18 June 2026, signal a more active supervisory cycle. A firm that leaves the work to spring 2027 will be rebuilding its risk assessment, rewriting policies and training staff in the same overloaded quarter.

What are the key dates?

18 June 2026 — already passed

Ireland launched its National Risk Assessment and a 30-point AML/CFT Action Plan. Both are inputs your refreshed BWRA should cite.

30 June 2026 — already in force

The administrative financial sanctions regime for the AMLCU came into force under S.I. No. 307 of 2026. For AMLCU-supervised firms — TCSPs, high-value goods dealers, unaffiliated accountants — enforcement has teeth now, a year before the AMLR applies.

Through 2026–27 — pending

AMLA’s technical standards and guidelines, which fill in much of the AMLR’s practical detail, are pending Commission adoption. Track amla.europa.eu and be ready to adjust policies when they land.

10 July 2027 — the application date

Regulation (EU) 2024/1624 applies directly across the EU. Your policies, thresholds, roles and risk assessment must be operating under the new framework from this date. (Football clubs and agents follow from 10 July 2029.)

The plan

What should each quarter deliver?

Each phase builds on the last: you cannot write policies before the BWRA tells you what they must cover, and you cannot train staff on procedures that do not exist yet. Sequence beats speed.

  1. 1
    Quarter 1 · to October 2026

    Gap analysis

    • Map your current CJA 2010 programme against the AMLR: CDD thresholds, beneficial-ownership procedures, record-keeping, reporting, internal controls.
    • Confirm your registrations are live: goAML, Revenue ROS and RBO designated-person access (form BEN3A1).
    • List the gaps with an owner and a target quarter for each. This list is the rest of the plan.
  2. 2
    Quarter 2 · to January 2027

    BWRA refresh

    • Rebuild your Business-Wide Risk Assessment against the AMLR, using the EU high-risk third-country list and Ireland’s June 2026 National Risk Assessment as inputs.
    • Derive your client risk-rating model from the refreshed BWRA so onboarding decisions trace back to it.
    • Have the document approved at board level and diarise its next review.
  3. 3
    Quarter 3 · to April 2027

    Policies and roles

    • Rewrite policies, procedures and controls to the AMLR: the €10,000 occasional-transaction CDD threshold, the €3,000 occasional-cash trigger, the €10,000 cash cap, and five-year retain-then-delete record-keeping.
    • Designate the two prescribed roles: a board-level compliance manager and a compliance officer of sufficiently high standing. From 10 July 2027 the compliance officer also takes responsibility for implementing targeted financial sanctions.
    • Update engagement letters, onboarding forms and client communications where thresholds or requirements change.
  4. 4
    Quarter 4 · to 10 July 2027

    Training and systems

    • Train all relevant staff on the new framework and record who was trained, on what, and when.
    • Prove the workflows end to end: a new client through CDD, screening and the RBO check; a test STR built and both submission routes confirmed; an FIU information request answered from your records within five working days.
    • Hold the final weeks as buffer — check for late AMLA standards and supervisor guidance, and fix what the dry runs surfaced.
Staying current

What is still moving while you plan?

The AMLR text is fixed, but two layers around it are not. AMLA’s technical standards and guidelines — which will settle much of the practical detail on due diligence and internal controls — are pending Commission adoption; check amla.europa.eu as part of each quarterly review. And Ireland’s transposition of Directive (EU) 2024/1640, the institutional layer covering supervisors and registers, continues through 2027. Neither is a reason to wait: the four phases above hold regardless of what the standards add. Build the plan on what is certain, and leave the fourth quarter’s buffer for what is not. Start with the deepest single piece of work — the BWRA refresh — as early as your gap analysis allows.

Twelve months, one system

Run the whole plan inside CompliDesk

BWRA generator, AMLR policy pack, role designations, training log and milestone reminders — so the quarter-by-quarter plan runs itself instead of living in a spreadsheet.