AMLA’s new standards make customer knowledge a continuing business duty, not an onboarding ritual.
A payment arrives from a company that does not appear on the contract. The customer says it belongs to the same group and asks for immediate delivery. Finance sees cleared funds. Sales sees a completed deal. Compliance sees a question that should have been answered before the warehouse door opened.
This is where customer due diligence becomes real. It is not the moment someone copies a passport or downloads a company extract. It is the moment the commercial story changes and the business must decide whether the new facts still fit.
On 1 October 2026, the Dutch Authority for the Financial Markets reported that the European Anti-Money Laundering Authority, AMLA, had published two Regulatory Technical Standards. They cover customer due diligence and the classification of business relationships, occasional transactions and linked transactions.
AMLA also published group-wide guidelines on risk, policies, procedures, internal controls and governance. Together, these publications place the daily customer file at the centre of a wider European shift.
The legal baseline already exists
The present Dutch baseline remains the Wet ter voorkoming van witwassen en financieren van terrorisme, the Wwft. Article 3 requires institutions within scope to conduct customer due diligence when entering a business relationship. That includes understanding its purpose and intended nature, then monitoring the relationship and its transactions continuously.
The Wwft also sets a general due-diligence trigger for an occasional transaction of at least €15,000. Linked transactions that together reach that amount also count. Payments rarely announce their economic connection. The institution has to recognise the pattern.
AMLA’s standards give more structure to this distinction. When does a one-off transaction become a relationship? When should several payments be read as one pattern? What should monitoring reveal when actual behaviour departs from the activity expected at onboarding?
The two technical standards are with the European Commission for adoption. The group-wide publication is guidance. Firms can still examine their records, authority lines and handovers now. Final wording will not repair fragmented customer data or decisions that disappear into private inboxes.
Documents are not the same as knowledge
Many customer records look complete until someone asks a simple question: who actually paid? The identity document is present. The beneficial owner was recorded. The risk rating has a date. Yet the contract, invoice, bank account and commercial explanation point in different directions.
FIU-Nederland received more than three million unusual transaction reports in 2025 and designated 92,000 transactions as suspicious. In one analysis of third-party payments to Dutch businesses, it designated 2,000 transactions worth €300 million as suspicious.
A third-party payment calls for a clear account of the payer, the source of funds and the commercial explanation. For a small regulated firm, the strongest control is often a simple sequence of facts. Who is the legal customer? Who owns or controls that customer? What activity was expected? Why did another party pay?
The next questions matter just as much. Who reviewed the explanation? Who decided whether work, delivery or withdrawal could continue? A file becomes useful when it preserves that chain of judgement.
When those answers sit across chat messages, personal memory and separate email accounts, the business has no working record. A colleague, auditor or supervisor returning six months later must be able to reconstruct the decision.
Europe changes the scale of the question
The AMLR, AMLD6 and AMLAR package will largely apply from 10 July 2027. The AMLR and AMLAR will apply directly in the Netherlands. AMLD6 requires Dutch implementation through legislation intended to replace the present Wwft.
This is more than a legislative change. Anti-money-laundering control is moving towards a more consistent European language. Groups need a reliable view of risk across entities and countries. A local office cannot rely only on familiarity with a customer when material information sits elsewhere in the group.
Cross-border payment activity gives this added weight. FIU-Nederland reported that 51 percent of unusual transaction reports received in 2025 had no direct Dutch link. For payment service providers, the share was 90 percent, strongly influenced by several internationally active providers.
For payment firms and international platforms, reporting exposure can follow the Dutch-regulated payment structure rather than the nationality of the buyer or seller. The practical question is often not where the parties feel they belong, but where the regulated payment route runs.
The Dutch government aims to implement the European package with limited burden and without extra national obligations where possible. That may reduce duplication. It still leaves firms with the basic work of coherent records, accountable decisions and escalation routes that work under commercial pressure.
Start with the awkward transaction
The most revealing management test is not a wholesale policy rewrite. It is a recent customer relationship in which something changed: payment from an unexpected party, repeated supposedly one-off transactions, or activity that moved beyond the original explanation.
Trace that case from onboarding to the latest payment. Compare the customer named in the contract with the invoice, payment account, beneficial-owner information and internal risk assessment. Then identify who could pause the transaction, request clarification, approve an exception and explain the decision to the customer.
That exercise often exposes more than a compliance weakness. It can reveal poor invoicing, unclear sales authority, weak communication within a group or working-capital pressure created by intervention that comes too late.
Since 1 July 2026, FIU-Nederland can request that an institution does not execute a transaction for up to five working days. A delayed transaction can quickly affect delivery, suppliers and customer trust. The control question therefore belongs to the business itself, not only to the compliance function.
The business in the opening scene still needs to decide whether to release the goods. A thick policy cannot make that decision. A connected record can support it: customer, owner, purpose, payer, payment pattern, review and authority, read as one story.
That is the practical direction of Dutch and European anti-money-laundering control. Customer knowledge has to survive contact with the transaction. If it does not, the weakness is already present, whatever date appears on the next regulation.
If a changed payment exposes gaps in your customer records or decision-making, I can help you assess the case and strengthen the control process.
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- Technische standaarden AMLA
- Autoriteit Financiële Markten - Dutch transition from Wwft to the European framework
- Wettenbank - Existing Dutch due-diligence baseline
- Rijksoverheid - National policy: harmonisation without additional Dutch burden
- Autoriteit Financiële Markten - Supervisory preparation and reporting already embedded in ordinary AFM processes
- FIU-Nederland - Transaction context, third-party payments and the quality of the audit trail
- FIU-Nederland - Wider payment infrastructure and cross-border reporting exposure
- Rijksoverheid - Immediate transaction-interruption power
