Skip to main content

8 min read

How to get started on your AMLR gap-analysis

How to get started on your AMLR gap-analysis

On 10 July 2027, the EU’s new anti-money laundering rules will come into force. And if you have already read our previous article about AMLR, you will also know that you do not need to tear down your entire existing compliance setup and start again. But what should you do instead?

An excellent place to start is your gap analysis.

Because although there are still details that need to be clarified through technical standards and guidance, we already know enough to start preparing. And the better you understand your current AML setup, the easier it will be to assess where the upcoming rules will actually have an impact on your business.

Here is a practical template to help you get started with your gap analysis.

What is a gap analysis?

A gap analysis may sound like yet another one of those terms that can quickly make a compliance meeting feel a little heavier, but in practice, it is actually quite simple. It is about comparing two factors:

👉 This is how we work today
👉  This is how we need to be able to work when the new rules come into force.

The purpose is to create an overview – not to find faults for the sake of finding faults. Where do your current processes already meet the upcoming requirements? Where are there areas that need to be adjusted? And where are you still missing information before you can assess what needs to happen?

A good gap analysis gives you a concrete basis for deciding what should be changed, strengthened or implemented towards 2027. And it is important to remember that the result does not necessarily need to be a huge 80-page report.

For many businesses, it will be far more valuable to be left with a precise and clear overview of:

  • which areas are already in place

  • where gaps have been identified

  • which gaps are the most significant

  • what needs to be investigated further

  • and which tasks should be prioritised first.

You do not need to fully implement AMLR yet

Before you begin the analysis itself, it is important to establish one thing: A gap analysis is not the same as a finished implementation plan.

We already know many of the central requirements in AMLR. Among other things, the regulation establishes direct requirements in areas such as KYC procedures, risk-based processes and internal AML/CFT measures. At the same time, however, a number of more detailed requirements are still being developed through AMLA’s technical standards and guidance.

It therefore does not make sense to decide exactly what all your processes should look like in 2027. What does make very good sense, however, is to start asking the questions.

For example:

  • How do we work with this area today?

  • What do we already know about the upcoming requirements?

  • Where could there be a difference between our current practice and AMLR?

  • What do we need to investigate further?

  • What can we already start improving?

That is essentially what a gap analysis should help you with.

Start by mapping your current setup

It can be tempting to open AMLR, start on page 1 and work your way through to a list of all the things that may potentially need to be changed. But before you can find your gaps, you need to know what you are comparing against.

The first step should therefore be to create an overview of how your business actually works with money laundering today. And here, the word actually is important. You should not look at how the process is described in a procedure from 2022, but instead look closely at how employees actually work in practice today.

So start by gathering your current:

  • business-wide risk assessment

  • policies and procedures

  • KYC procedures

  • risk assessment and risk classification models

  • documentation requirements

  • controls and quality processes

  • systems and suppliers

  • ongoing follow-up processes

  • training materials and employee guidance

Once you have the full overview, it becomes easier to begin the analysis itself.

How you can review your business one area at a time

The list above gives you a good idea of how you can approach the gap analysis, one piece at a time. A good way to get started is to divide the work into specific areas and go through them one by one. It may seem cumbersome, but it is much more manageable once you get started.

1. Start with your business risk assessment

Your business-wide risk assessment is a natural place to start.

Ask yourself:

  • What risks have we identified today?

  • Which customer types, products, services, transactions and geographical factors are included in our assessment?

  • Can we explain why we have assessed a risk as high, medium or low?

  • Is the risk assessment up to date in relation to the business we actually operate today?

  • Is there a connection between our risk assessment and the controls we have established?

An important point to remember is that this does not necessarily mean that your entire risk assessment needs to be redone. But AMLR makes it relevant to take a closer look at whether your risk-based approach is sufficiently systematic, documented and connected to the way the business operates in practice.

A possible gap could be:

We have a risk assessment, but it is difficult to see how the risks we have identified actually affect our procedures and controls.

This is a good example of an area where the work can already add value – even before all the upcoming details have been fully specified.

2. Look at your policies, procedures and controls

Most businesses already have AML policies and procedures. The question is not only whether they exist, but also whether they actually reflect reality.

You can ask yourself:

  • Do our written procedures match the way employees work?

  • Are roles and responsibilities clearly assigned?

  • Do employees know where to find the procedures?

  • Do we have controls that show whether the procedures are being followed?

  • Can we document how we follow up on identified deficiencies?

A possible gap here could be:

We have good written procedures, but we do not have a fixed process for checking whether they are actually being followed.

That is exactly the type of difference a gap analysis can help to highlight.

3. Review your KYC procedure

KYC is one of the areas where the upcoming EU rules will be particularly important and therefore also an obvious area where we can expect to see some changes. This makes it an obvious place to review the entire process, from onboarding to ongoing follow-up.

Ask yourself:

  • When do we collect KYC information?

  • What information do we collect?

  • How do we identify and verify the customer?

  • How do we identify beneficial owners and relevant persons exercising control?

  • How do we document our assessments?

  • When and how do we update the customer’s information?

  • What happens if we cannot obtain the necessary information?

AMLR establishes direct requirements for KYC measures in connection with, among other things, establishing business relationships, while AMLA is continuing to work on more detailed standards for how the KYC requirements should be applied in practice.

So this is a good area to be concrete about already, without necessarily locking all future processes into place.

A possible gap could be:

We collect the necessary information, but our documentation does not always make it clear why we considered the KYC procedure to be sufficient.

4. Examine your risk classification

How do you actually assess the risk of an individual customer? And, just as importantly: Can you explain why? Here, you can review, among other things:

  • which risk factors you use

  • how the factors are weighted

  • how the overall risk assessment is determined

  • whether employees can deviate from the model

  • how any deviations are documented

  • how the risk classification affects the subsequent handling of the customer.

A possible gap could be:

We have a risk model, but there is no clear connection between the customer’s risk level and the way we work with the customer afterwards.

5. Take a closer look at beneficial owners, PEPs and screening

For many businesses, this area is already a standard part of the KYC procedure, but a gap analysis should not only examine whether screening is carried out. It should also look at how the business deals with the results.

For example, ask:

  • How do we identify beneficial owners?

  • How do we handle complex ownership structures?

  • How do we handle missing or conflicting information?

  • When do we carry out PEP and sanctions screening?

  • What do we do when a screening produces a possible match?

  • How do we document our assessment?

Here, it is important to look at the entire process and not just whether someone presses a “screen” button.

6. Review ongoing monitoring and follow-up

A business may have a good onboarding process but have a gap in its ongoing follow-up and monitoring of changes in its customer relationships. It goes without saying that this process needs to be in place so that you always have an accurate picture of the risk profile of your existing customers.

So ask:

  • When do we review existing customers?

  • What triggers an update?

  • How do we identify changes in the customer’s circumstances?

  • Do we have different intervals depending on the customer’s risk?

  • How do we document ongoing follow-up?

AMLA has already started work on more detailed guidance on ongoing monitoring of business relationships. This is therefore a good example of an area where businesses can map their current practices now and continuously compare them with the upcoming clarifications.

7. Look at how you handle unusual circumstances

A gap analysis should also cover the processes that come into play when something does not look as it should. This includes, among other things:

  • identification of unusual circumstances

  • internal investigations

  • escalation

  • documentation

  • decisions on whether to report.

Ask yourself: If an employee notices something unusual tomorrow, do they know exactly what needs to happen? And if the answer is “it depends on who you ask”, you may already have identified an area worth looking into more closely.

8. Test your documentation

Documentation can quickly become the slightly boring part of compliance work that you just want to get over with, but try asking yourself this question: If an employee, an auditor or a supervisory authority looks at a case, can they understand what we have done – and why?

Look at the documentation for, among other things:

  • KYC procedures

  • reasons for risk assessments

  • handling of deviations

  • investigations of unusual circumstances

  • decisions and approvals

  • follow-up on deficiencies.

A possible gap could be:

We carry out the assessments, but the reasons are often in employees’ heads or in an email somewhere in the inbox.

And this is an important assessment to make. Because a process that is carried out but cannot be explained or documented can be difficult to prove afterwards. And as we keep saying when it comes to supervision: if it is not documented, it did not happen!

9. Do not forget your employees

Even the best procedure has limited value if employees do not know how to use it. This is where it is important to have internal training and education under control – and not just once during onboarding, but continuously throughout their employment.

So review:

  • how new employees are introduced to AML work

  • how existing employees are kept up to date

  • whether the training is relevant to their specific tasks

  • how the business ensures that the procedures are actually understood.

A possible gap here could be:

We inform relevant employees about our AML procedures during their onboarding, but we have no established process for continuously updating or checking their knowledge.

10. Look at systems, data and suppliers

For many businesses, AML work is not all in one place. Customer data may be stored in one place, while screening is handled somewhere else. Documentation may be saved in some shared folders, while individual customer risk assessments are stored on individual employees’ private drives.

It can quickly become messy to establish the state of your overall AML efforts, so it is worth using the gap analysis to investigate:

  • where your AML data comes from and whether the data is accessible (to all relevant employees) when they need it

  • whether there are duplicate records or manual processes

  • how suppliers support your work

  • whether you have the necessary controls around your systems and suppliers.

Prioritise your gaps and create an action plan

A gap analysis can quickly become overwhelming if all identified gaps are given the same priority. It is rare for everything to have the same priority, and some areas will require greater changes in relation to AMLR, while others may be solved with a minor adjustment to your existing procedure.

And then there are some things you will not yet be able to assess because more specific guidance is still missing.

For example, you can gather the gaps you identify in a simple overview:

 Area  Current status  Identified gap  Risk  Next step
Risk assessment Partially in place Lack of connection between risks and controls High Review and update
KYC In place Need to follow upcoming clarifications Medium Await and follow developments
Documentation Partially in place Assessments are not documented consistently High Establish a common standard
Training In place Materials need updating Low Plan update

 

It does not need to be more complicated than that, because the most important thing is that the analysis helps you answer:

✅ what you know

❌ what you are missing

👉 what you now need to do.

In this way, your gap analysis ends up becoming a prioritised action plan for the work ahead rather than just a checklist of tasks. In addition to the above, a plan could also include concrete recommendations, a prioritised implementation plan, as well as proposed responsibilities and deadlines.

You do not need to know all the answers to get started

Here is perhaps the most important point in the entire process towards July 2027:

A gap analysis should not give you a finished answer sheet for how your business should work on 10 July 2027. It should help you understand where you are today.

AMLA is still working on a number of technical standards and guidance, and some of the practical details will therefore continue to be clarified towards 2027. AMLA’s work includes standards and guidance intended to create greater consistency and clarity in the practical application of the new regulatory framework.

The best approach is therefore to create a strong starting point where you map your current processes, identify the areas where there may already be a difference, and prioritise the biggest risks. And then, of course, you can adjust continuously as new information becomes available.

10 July 2027 may still seem like a long way off, but a good gap analysis does not need to wait until next summer. You can start it with one simple question: Do we actually know exactly how we work with AML today?

How to get started on your AMLR gap-analysis

15 min read

How to get started on your AMLR gap-analysis

On 10 July 2027, the EU’s new anti-money laundering rules will come into force. And if you have already read our previous article about AMLR, you...

Læs Artiklen
What does Nature of intended business relationship actually mean?

6 min read

What does Nature of intended business relationship actually mean?

"You almost feel like saying: just speak plain English."

Læs Artiklen
How to start internal training on AML and combating the financing of terrorism

3 min read

How to start internal training on AML and combating the financing of terrorism

Training is a crucial part of every organisation's efforts to combat money laundering and terrorist financing.

Læs Artiklen