AMLR TRAINING COMPLIANCE

What does AMLR mean for Training Compliance?

AMLR changes what is expected of how organisations work with AML competence and training. Offering AML training and recording that it was completed is no longer enough. Training must be specific, ongoing, adapted to function and activity as well as to the ML/TF risks the business is exposed to — and documented.

For employees who are directly involved in the organisation's compliance with the regulation, there are additional requirements to assess, among other things, individual knowledge, skills and expertise in relation to the risks in the tasks they perform.

In practice this is a shift from only being able to show completed training to working systematically with the relationship between risk, role, competence, training and follow-up.

What does AMLR require?

01

Role- and risk-based training

Training programmes must be adapted to employees' functions or activities and to the money laundering and terrorist financing risks the business is exposed to.

02

Specific and ongoing training

Relevant employees must take part in specific, ongoing training programmes that help them recognise situations that may be linked to money laundering or terrorist financing and understand how to act.

03

Assessment of competence

Employees who are directly involved in the organisation's compliance with the regulation must be assessed on, among other things, individual knowledge, skills and expertise. The assessment must be proportionate to the risks in their tasks, take place before the person begins performing those tasks, and be repeated regularly thereafter.

04

Documentation

Training programmes must be duly documented. Relevant employees must also be aware of, among other things, the organisation's overall risk assessment and the internal policies, procedures and controls relevant to AML work.

Regulatory reference Regulation (EU) 2024/1624, Articles 12–13

AMLR mainly starts to apply on 10 July 2027.

A practical Training Compliance framework

Training Compliance is a full chain.

AMLR sets out the regulatory requirements. The next question is how the organisation translates them into training and competence work that can be governed, followed up and documented.

  1. 01
    Risk
  2. 02
    Role
  3. 03
    Competence
  4. 04
    Training
  5. 05
    Evidence
  6. 06
    Measurement
  7. 07
    Remediation
  • Which risks does the business face?
  • Which roles handle them?
  • What do those people need to be able to do?
  • Which training builds that competence?
  • How are results documented and followed up?
  • And what happens when a competence gap is identified?

When those parts connect, AML training becomes part of the organisation's risk and control work rather than just a recurring training activity.

Most organisations train their employees. That is rarely where the problem lies.

In our analysis of more than 100 supervisory reports we see a recurring pattern. Organisations can often show that AML training was completed. Far fewer can show the coherent governance behind it.

From

Has the employee completed the AML training?

To

  • Why did this role receive this particular training?
  • Which risk is the training intended to address?
  • How do you know the person has the right competence?
  • How do you follow up on whether the training works?
  • What do you do when you identify a competence gap?

That is where Training Compliance becomes more than a completion rate.

Three problems come up again and again.

01

Training lacks clear governance

There are courses, an LMS, policies and annual activities, but not always a coherent model for how AML competence and training are governed.

  • Who owns the training programme?
  • Who decides what different roles need to know?
  • How does the risk assessment influence training needs?
  • When should content change?
  • How are results followed up?
  • And who is responsible for making sure identified gaps are actually addressed?

AML training therefore needs to be treated as part of the organisation's AML governance, not as a standalone training activity.

02

The same training is given to too many

A relationship manager, an onboarding specialist, a transaction monitoring analyst and a board member have different tasks and can face entirely different risks. Yet the training model often looks broadly the same: “Everyone completes the annual AML training.”

That is simple to administer, but it does not in itself create a risk-based competence model.

Risk connects to role.

Role connects to competence.

Competence connects to relevant training.

03

Completed training is used as proof of competence

“98% have completed the training.” That is a relevant administrative measure.

But completed training does not in itself show that an employee can identify a suspicious situation, apply internal processes, make the right decision or escalate when needed.

Training completion is not the same as demonstrated competence.

From risk to documented competence.

So how can an organisation put the requirements into practice?

01
RISK

Which risks does the organisation need to manage?

The starting point should be the organisation's risk picture, not the course catalogue. Which customers, products, geographies, transactions and activities create exposure? Which regulatory requirements and internal controls exist to manage those risks?

Once the risk picture is clear, it becomes possible to identify which roles and competencies are central to managing it.

02
ROLE

Which roles meet the risks?

Different roles meet different parts of the organisation's risk picture. An onboarding specialist may need to assess ownership structures and beneficial ownership. A relationship manager needs to recognise changes in customer behaviour and understand when something should be escalated. An AML investigator needs deeper competence to analyse suspicious activity.

Training needs therefore have to be connected to both function and risk exposure.

03
COMPETENCE

What does the person actually need to be able to do?

Competence requirements need to be concrete. Not just: “Understand AML.” But for example:

  • “Be able to identify the beneficial owner in a complex ownership structure.”
  • “Be able to determine when enhanced due diligence is required.”
  • “Be able to identify unusual customer behaviour and escalate according to the organisation's process.”

When competence requirements become concrete, it also becomes possible to train and assess them.

04
TRAINING

Which training builds the right competence?

Different roles may need different combinations of regulatory knowledge, internal processes, product- and system-specific training, practical cases, scenario practice and reinforcement.

The result is a relevant training path based on role and risk, rather than the same generic training package for the whole organisation.

05
EVIDENCE

Can you show why the person received that particular training?

To create traceability, the organisation needs to be able to follow the logic between risk, role, competence need and training.

Instead of only “Anna completed AML 2026.”

Traceable logic

Roleactivityriskcompetence requirementtrainingresult

That makes it possible to explain why a given person or role received a given training and what it is intended to develop.

06
MEASUREMENT

How do you follow up on whether the training works?

Completion is one data point. Following up knowledge and competence gives another picture. That can happen through knowledge assessments, scenario results, quality controls, recurring errors, audit observations and development over time.

Does the organisation have the knowledge and competence needed to manage its AML risks?

07
REMEDIATION

What happens when you find a competence gap?

If assessments, quality controls, incidents or supervision identify a competence gap, the organisation needs to be able to act on it.

Remediation flow

Gap identifiedaffected rolestargeted trainingnew assessmentdocumented result

Training then becomes a continuous part of the organisation's control work rather than an activity that ends when the course is completed.

From completed training to documented competence.

The central change can be summarised by moving the focus from one question to another.

Not only

Have employees completed the AML training?

But

Can you show that the right people hold the right competence for the risks they actually manage — and that you follow up on whether the model works?

That is the difference between administering AML training and working systematically with Training Compliance.

amlify.ai makes the chain manageable.

Creating a coherent structure does not have to mean building and administering the whole model manually. amlify.ai helps you connect competence requirements, roles and risks with relevant training, practical application and traceable documentation.

01

MAP

AI-assisted competence mapping helps you identify which AML competencies are needed based on roles, responsibilities and risk exposure.

02

MATCH

Each employee is matched with relevant microlearning and scenario practice based on role, responsibility and risk.

03

TRAIN

Employees build knowledge through short microlearning modules and then practise applying it in realistic AI-driven scenarios via voice or text, with feedback during the session.

04

PROVE

Training, results and demonstrated competence are documented and can be followed over time, making the link between role, risk, training and competence clear.

Book a demo

Regulatory references

  • Regulation (EU) 2024/1624 (AMLR), Articles 12–13
  • Relevant EBA AML/CFT guidance