AMLR TRAINING COMPLIANCE
AMLR changes what is expected of how organisations work with AML competence and training. Offering AML training and recording that it was completed is no longer enough. Training must be specific, ongoing, adapted to function and activity as well as to the ML/TF risks the business is exposed to — and documented.
For employees who are directly involved in the organisation's compliance with the regulation, there are additional requirements to assess, among other things, individual knowledge, skills and expertise in relation to the risks in the tasks they perform.
In practice this is a shift from only being able to show completed training to working systematically with the relationship between risk, role, competence, training and follow-up.
Training programmes must be adapted to employees' functions or activities and to the money laundering and terrorist financing risks the business is exposed to.
Relevant employees must take part in specific, ongoing training programmes that help them recognise situations that may be linked to money laundering or terrorist financing and understand how to act.
Employees who are directly involved in the organisation's compliance with the regulation must be assessed on, among other things, individual knowledge, skills and expertise. The assessment must be proportionate to the risks in their tasks, take place before the person begins performing those tasks, and be repeated regularly thereafter.
Training programmes must be duly documented. Relevant employees must also be aware of, among other things, the organisation's overall risk assessment and the internal policies, procedures and controls relevant to AML work.
Regulatory reference Regulation (EU) 2024/1624, Articles 12–13
AMLR mainly starts to apply on 10 July 2027.
A practical Training Compliance framework
AMLR sets out the regulatory requirements. The next question is how the organisation translates them into training and competence work that can be governed, followed up and documented.
When those parts connect, AML training becomes part of the organisation's risk and control work rather than just a recurring training activity.
In our analysis of more than 100 supervisory reports we see a recurring pattern. Organisations can often show that AML training was completed. Far fewer can show the coherent governance behind it.
From
Has the employee completed the AML training?
To
That is where Training Compliance becomes more than a completion rate.
There are courses, an LMS, policies and annual activities, but not always a coherent model for how AML competence and training are governed.
AML training therefore needs to be treated as part of the organisation's AML governance, not as a standalone training activity.
A relationship manager, an onboarding specialist, a transaction monitoring analyst and a board member have different tasks and can face entirely different risks. Yet the training model often looks broadly the same: “Everyone completes the annual AML training.”
That is simple to administer, but it does not in itself create a risk-based competence model.
Risk connects to role.
Role connects to competence.
Competence connects to relevant training.
“98% have completed the training.” That is a relevant administrative measure.
But completed training does not in itself show that an employee can identify a suspicious situation, apply internal processes, make the right decision or escalate when needed.
Training completion is not the same as demonstrated competence.
So how can an organisation put the requirements into practice?
The starting point should be the organisation's risk picture, not the course catalogue. Which customers, products, geographies, transactions and activities create exposure? Which regulatory requirements and internal controls exist to manage those risks?
Once the risk picture is clear, it becomes possible to identify which roles and competencies are central to managing it.
Different roles meet different parts of the organisation's risk picture. An onboarding specialist may need to assess ownership structures and beneficial ownership. A relationship manager needs to recognise changes in customer behaviour and understand when something should be escalated. An AML investigator needs deeper competence to analyse suspicious activity.
Training needs therefore have to be connected to both function and risk exposure.
Competence requirements need to be concrete. Not just: “Understand AML.” But for example:
When competence requirements become concrete, it also becomes possible to train and assess them.
Different roles may need different combinations of regulatory knowledge, internal processes, product- and system-specific training, practical cases, scenario practice and reinforcement.
The result is a relevant training path based on role and risk, rather than the same generic training package for the whole organisation.
To create traceability, the organisation needs to be able to follow the logic between risk, role, competence need and training.
Instead of only “Anna completed AML 2026.”
Traceable logic
That makes it possible to explain why a given person or role received a given training and what it is intended to develop.
Completion is one data point. Following up knowledge and competence gives another picture. That can happen through knowledge assessments, scenario results, quality controls, recurring errors, audit observations and development over time.
Does the organisation have the knowledge and competence needed to manage its AML risks?
If assessments, quality controls, incidents or supervision identify a competence gap, the organisation needs to be able to act on it.
Remediation flow
Training then becomes a continuous part of the organisation's control work rather than an activity that ends when the course is completed.
The central change can be summarised by moving the focus from one question to another.
Not only
Have employees completed the AML training?
But
Can you show that the right people hold the right competence for the risks they actually manage — and that you follow up on whether the model works?
That is the difference between administering AML training and working systematically with Training Compliance.
Creating a coherent structure does not have to mean building and administering the whole model manually. amlify.ai helps you connect competence requirements, roles and risks with relevant training, practical application and traceable documentation.
AI-assisted competence mapping helps you identify which AML competencies are needed based on roles, responsibilities and risk exposure.
Each employee is matched with relevant microlearning and scenario practice based on role, responsibility and risk.
Employees build knowledge through short microlearning modules and then practise applying it in realistic AI-driven scenarios via voice or text, with feedback during the session.
Training, results and demonstrated competence are documented and can be followed over time, making the link between role, risk, training and competence clear.