Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2023-0128 → TA-9-2024-0366
- From
- A-9-2023-0128 Plenary report of 5 Apr 2023
- To
- TA-9-2024-0366 Adopted text of 24 Apr 2024
- Changes
- Not comparable
- Paragraphs
- +9 added · −1 234 removed · 1 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism and amending Regulations (EU) No 1093/2010, (EU) 1094/2010, (EU) 1095/2010
- Title (to)
- Establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 2 of 21: Paragraphs 61–120
Removed(14e) In the context of its supervisory tasks, the Authority should also actively cooperate with competent FIUs and Europol. Where the Authority, in the course of its supervisory and oversight activities, discovers facts, that could be related to money laundering, to a predicate offence or to terrorist financing, it should ensure that the information is promptly made available to the competent FIUs and, where the facts have a cross-border relevance, to Europol within their respective areas of competence.
Removed(15) With the objective of ensuring a more effective and less fragmented protection of the Union’s financial framework, a limited number of the riskiest obliged entities should be directly supervised by the Authority. As ML/TF risks are not proportional to the size of the supervised entities, other criteria should be applied to identify the most risky entities. In particular, two categories should be considered: high-risk cross-border credit and financial institutions with activity in a significant number of Member States, selected periodically; and, in exceptional cases, any entity whose serious, systematic or repeated breaches of applicable requirements are not sufficiently or in a timely manner addressed by its national supervisor. In addition, in order to enhance the prevention of ML/TF and ensure that supervisory practices are aligned across the Union, the Authority shall ensure that it directly supervises at least one entity per Member State. Those entities would fall under the category of ‘selected obliged entities’.
Removed(16) ML/TF supervision should be risk-based. The first category of credit and financial institutions, including crypto-asset service providers, or groups of such institutions should be assessed every three years, based on a combination of objective criteria related to their cross-border presence and activity, and criteria related to their inherent ML/FT risk profile. The Authority should assess those institutions based on residual risk benchmarks in order to better target the riskiest of those obliged entities. In order to ensure that direct supervision by the Authority has added value, only cross-border entities operating in a minimum number of Member States, either through establishments or under the freedom to provide services, should fall within the remit of the Authority.
Removed(17) In order to ensure that only the riskiest obliged entities ▌ are supervised directly at the level of the Union, the assessment of their inherent and residual risk should be harmonised. Currently, there are various national approaches and supervisory authorities use distinct benchmarks for assessment and classification of the inherent and residual ML/TF risk of obliged entities. Using these national methodologies for selection of entities for direct supervision at Union level could lead to a different playing field among them. Therefore, the Authority should be empowered to develop regulatory technical standards laying out ▌harmonised methodologies and benchmarks for categorising ▌inherent ML/TF risk as low, medium, substantial, or high. The Authority should also develop common residual risk benchmarks. Those methodologies should be tailored to particular types of risks and therefore should follow different categories of obliged entities which are financial institutions in accordance with the Regulation of the European Parliament and of the Council on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing [OP please insert the next number for COM(2021)420], as well as crypto-asset service providers. Those methodologies should be sufficiently detailed and should establish specific quantitative and qualitative benchmarks considering at least the risk factors related to types of customers served, products and services offered, and geographical areas, including third country jurisdictions that obliged entities operate in or are related to. Specifically, each assessed obliged entity would have its inherent and residual risk profiles classified in each Member State where it operates in a manner consistent with the classification of any other obliged entity in the Union. The quantitative and qualitative benchmarks would allow such classification to be objective and not dependent on the discretion of a given supervisory authority in a Member State, or the discretion of the Authority.
Removed(18) The final selection criterion should warrant a level playing field among directly supervised obliged entities, and to that end, no discretion should be left to the Authority or supervisory authorities in deciding on the list of obliged entities that should be subject to direct supervision. Therefore, where a given assessed obliged entity operates cross-border and falls within the high risk category in accordance with the harmonised methodology in a minimum number of Member States, it should be deemed a selected obliged entity. ▌
Removed(19) To provide transparency and clarity to the relevant institutions, the Authority should publish a list of the selected obliged entities within one month of commencement of a selection round, after verifying the correspondence of information provided by the financial supervisors to the cross-border activities criteria and the inherent and residual risk methodologies. Therefore it is important that at the beginning of each selection period, the relevant financial supervisors and, if necessary, the obliged entities themselves, provide the Authority with up-to-date statistical information to determine the list of financial institutions eligible for assessment in accordance with the assessment entry criteria relating to their cross-border operations. In this context, the financial supervisors should inform the Authority about the inherent and residual risk category that a financial institution or crypto-asset service provider falls into in their jurisdictions in accordance with the methodologies laid down in the regulatory technical standards. The Authority should then assume the tasks related to direct supervision five months after the publication of the list. That time is needed to appropriately prepare the transfer of supervisory tasks from national to Union level, including the formation of a joint supervisory team, and adopting any relevant working arrangements with the relevant financial supervisors.
Removed(20) To ensure legal certainty and a level playing field among selected entities, any selected entity should remain under direct supervision of the Authority for at least three years, even if since the moment of selection and in the course of the three years it ceases to meet any of the cross-border activity or risk-related criteria due to e.g. potential consolidation, expansion or re-allocation of activities carried out via establishments or freedom to provide services. The Authority should also ensure that sufficient time is allocated to preparation by the obliged entities and their supervisory authorities to the transfer of supervision from national to Union level. Therefore, each subsequent selection should commence six months before the end-date of the three year period of supervision of the previously selected entities.
Removed(21) The relevant actors involved in the application of the AML/CFT framework should cooperate with each other in accordance with the duty of sincere cooperation enshrined in the Treaties. In order to ensure that the AML supervisory system composed of the Authority and supervisory authorities functions as an integrated mechanism, and that jurisdiction-specific risks and local supervisory expertise are duly taken into account and well utilised, direct supervision of selected obliged entities should take place in the form of joint supervisory teams. These teams should be led by a staff member of the Authority coordinating all supervisory activities of the team. ▌ The Authority should be in charge of establishment and composition of the joint supervisory team, and each local supervisor involved in the supervision of the selected obliged entity should ensure that a sufficient number of its staff members are appointed to the team, taking into account the risk profile of the selected entity in its jurisdiction as well as its overall volume of activity.
Removed(22) To ensure that the Authority can fulfil its supervisory obligations in an efficient manner with regard to selected obliged entities, the Authority should be able to obtain any internal documents and information necessary for the exercise of its tasks and for that purpose have general investigation powers afforded to all supervisory authorities under national administrative law.
Removed(23) The Authority should have the power to require actions, internal to the entity, to enhance the compliance of obliged entities with the AML/CFT framework, including reinforcement of internal procedures and changes in the governance structure, going as far as removal of members of the management body, without prejudice to the powers of other relevant supervisory authorities of the same selected entity. Following relevant findings related to non-compliance or partial compliance with applicable requirements by the obliged entity, it should be able to impose specific measures or procedures for particular clients or categories of clients who pose high risks. On-site inspections should be a regular feature of such supervision. If a specific type of on-site inspection requires an authorisation by the national judicial authority, such authorisation should be applied for by the Authority.
Removed(24) The Authority should have a full range of supervisory powers in relation to directly supervised entities in order to ensure compliance with applicable requirements. These powers should apply in cases where the selected entity does not meet its requirements, in cases where certain requirements are not likely to be met, as well as in cases where internal processes and controls are not appropriate to ensure sound management of selected obliged entity’s ML/FT risks. The exercise of these powers could be done by means of binding decisions addressed to selected individual obliged entities, as well as by means of recommendations.
Removed(25) In addition to supervisory powers and in order to ensure compliance, in cases of serious, repeated or systematic breaches of directly applicable requirements, the Authority should be able to impose administrative pecuniary sanctions and other measures on the selected obliged entities. Those measures should be defined in regulatory technical standards by means of indicators to classify the level of gravity of the breaches and the criteria to be taken into account when setting the level of administrative pecuniary sanctions and other measures. Such sanctions should be proportionate and dissuasive, should have both punitive and deterrent effect, and should comply with the principle of ne bis in idem. The maximum amounts of pecuniary sanctions should be in line with those established by [please insert reference – 6th Anti-Money Laundering Directive] and available to all supervisory authorities across the Union. The basic amounts of these sanctions should be determined within the limits established by the AML/CFT framework, taking into account the nature of the requirements that have been breached. In order for the Authority to take aggravating or mitigating factors adequately into account, adjustments to the relevant basic amount should be possible. With the objective to achieve a timely change of the damaging business practice, the Executive Board of the Authority should be empowered to impose periodic penalty payments to compel the relevant legal or natural person to cease the relevant conduct. With the aim to heighten awareness of all obliged entities, by encouraging them to adopt business practices in line with the AML/CFT framework, the sanctions and penalties should be disclosed. The Court of Justice should have jurisdiction to review the legality of decisions adopted by the Authority, the Council and the Commission, in accordance with Article 263 TFEU, as well as for determining their non-contractual liability.
Removed(26) In order for the Authority and financial supervisors to communicate swiftly and efficiently within AML/CFT supervisory system and to enable more coherent decision-making processes, it is necessary to have specific arrangements for communication within that system.
Removed(27) For non-selected obliged entities, the AML/CFT supervision is to remain primarily at national level, with national competent authorities retaining full responsibility and accountability for direct supervision. The Authority should be granted adequate indirect supervisory powers to ensure that supervisory actions at national level are consistent and of a high quality across the Union. Therefore, it should carry out assessments of the state of supervisory convergence and publish reports with its findings. It should be empowered to issue guidelines and recommendations, addressed to both obliged entities as well as supervisory authorities, and should request the relevant authorities to take follow-up measures on their application with a view to ensuring harmonised and high level supervisory practices across the Union.
Removed(27a) The Authority should lead in ensuring a consistent functioning of colleges of supervisors for non-selected obliged entities operating in several Member States, taking account of the systemic risk posed by financial institutions, and should, where appropriate, convene a meeting of a college. The Authority should also have a role in legally binding mediation to resolve disputes between financial supervisors upon their request and, where necessary, to take supervisory decisions directly applicable to the institution concerned. Prudential supervisors including the European Central Bank, the European Supervisory Authorities and, where necessary, FIUs, should actively engage in such colleges, using them as forums for discussion and to exchange relevant information.
Removed(28) Certain obliged entities in the financial sector that do not meet the requirements for regular selection might still have a high residual risk profile from the money laundering and terrorism financing perspective, or might take on, change or expand activities that entail high risk, not mitigated with a commensurate level of internal controls, thus leading to serious, repeated or systematic breaches of its AML/CFT requirements. If there are indications of possible serious, repeated or systematic breaches of applicable AML/CFT requirements, they may be a sign of gross negligence on part of the obliged entity. The supervisory authority should ▐be able to adequately respond to any possible breaches and prevent the risks from materialising and leading to gross negligence of AML/CFT requirements. However, in certain cases a national level response might not be sufficient or timely, especially when there are indications that serious, repeated or systematic breaches at the level of the entity have already occurred. In those cases, the Authority should ▐request the local supervisor to take specific measures to remedy the situation, including requesting to issue financial sanctions or other coercive measures. To prevent money laundering and terrorism risks from materialising, the deadline for action at national level should be sufficiently short.
Removed(28a) In the case of possible serious, repeated or systematic breaches, the Authority should be notified where the situation of any non-selected obliged entity with regard to its compliance with applicable requirements and its exposure to money laundering and terrorism financing risks deteriorates rapidly and significantly, especially where such deterioration could lead to significant harm to the reputation of several Member States or of the Union as a whole.
Removed(29) The Authority should have the opportunity to request a transfer of supervisory tasks and powers relating to a specific obliged entity on its own initiative in case of inaction or failure to follow its instructions within the provided deadline. Since the transfer of tasks and powers over an obliged entity without the specific request of the financial supervisor to the Authority would require a discretionary decision on the part of the Authority, the Authority should address a specific request to that end to the Commission. In order for the Commission to be able to take a decision coherent with the framework of the tasks allocated to the Authority within the AML/CFT framework, the request of the Authority should enclose an appropriate justification, and should indicate a precise duration of the reallocation of tasks and powers towards the Authority. The timeframe for the reallocation of powers should correspond to the time the Authority requires to deal with the risks at entity level, and should not exceed three years. The Commission should adopt a decision transferring powers and tasks for supervising the entity to the Authority swiftly, and in any case without undue delay. That decision should be communicated to the European Parliament and to the Council.
Removed(29a) In specific cases, upon the request of a financial supervisor, the Authority should assess whether it is necessary to exercise direct supervision in accordance with this Regulation in respect of non-selected obliged entities in order to ensure the consistent application of high supervisory standards. Member States could set out specific arrangements regarding the delegation of responsibilities that are required to be complied with before their competent authorities enter into such delegation agreements, and could limit the scope of delegation to that which is necessary for the effective supervision of cross-border financial market participants or groups. The financial supervisor’s request should be accompanied by a report indicating the supervisory history and risk profile of the relevant non-selected obliged entity. In cases where the Authority does not agree with the financial supervisor’s request, it should consult with that financial supervisor prior to its final assessment as to whether AML/CFT supervision by the Authority of the non-selected obliged entity is necessary. If the Authority agrees with the financial supervisor’s request, the Authority should take over the relevant tasks and powers related to direct supervision of the non-selected obliged entity from the financial supervisor concerned to the Authority. That decision should also be communicated to the European Parliament and to the Council.
Removed(29b) The Authority should play an important role in the settlement of disagreements between financial supervisors in cross-border situations in relation to this Regulation, by assisting financial supervisors in reaching an agreement. Such assistance should occur at the request of one or more of the financial supervisors concerned, where on the basis of objective reasons, disagreement can be determined between financial supervisors. The financial supervisors concerned should notify the Authority without undue delay that an agreement has not been reached.
Removed(29c) The Executive Board should assess whether the Authority is able to act at the request of the financial supervisors concerned. The Authority should set a time limit for conciliation between the financial supervisors, taking into account any relevant time periods specified in Union law and the complexity and urgency of the matter. At that stage the Authority should act as a mediator. In cases where financial supervisors concerned fail to reach an agreement during the conciliation phase, the Authority should be able to take a decision requiring those supervisors to take specific action, or to refrain from certain action, in order to settle the matter, and to ensure compliance with Union law. The decision of the Authority should be binding on the financial supervisors concerned. The Authority’s decision should be able to require financial supervisors to revoke or amend a decision that they have adopted or to make use of the powers which they have under the relevant Union law. The Authority should notify the financial supervisors concerned of the conclusion of the procedure. The Chair of the Authority should set out the nature and type of disagreements between financial supervisors, the agreements reached and the decisions taken to settle such disagreements in the annual report of the Authority.
Removed(30) In order to improve supervisory practices in the non-financial sector, the Authority should carry out peer reviews of supervisory authorities in the non-financial sector, including public authorities overseeing self-regulatory bodies (SRBs), and publish reports with its findings; those could be accompanied by guidelines or recommendations addressed to the relevant public authorities, including public authorities overseeing SRBs. When performing those peer reviews, the Authority should not duplicate existing assessments and should take into account all relevant information. SRBs should be able to participate in peer reviews▌.
Removed(30a) Cooperation between national supervisors is essential to ensure a common supervisory approach across the Union. To be effective, it is also essential for that cooperation to be leveraged to the greatest extent possible. Accordingly, it is appropriate to mandate the Authority to decide whether it is necessary to set up AML/CFT supervisory colleges with respect to non-financial sector obliged entities that operate under the freedom to provide services or of establishment in several Member States and that have a significant annual EU-wide turnover. In addition, the Authority should facilitate the functioning of AML/CFT supervisory colleges and contribute to the convergence of supervisory practices and the promotion of high supervisory standards.
Removed(31) With the objective to increase the efficiency of the implementation of AML/CFT measures also in the non-financial sector, the Authority should also be able to investigate possible breaches or incorrect application of Union law by supervisory authorities in that sector, including public authorities overseeing SRBs. The national oversight authority should be able to request a derogation to that rule when there is a risk of interference with the independence of the judiciary.
Removed(31a) Taking into account the cross-border nature of money laundering and terrorist financing, coordination and cooperation between FIUs are extremely important. In order to improve such coordination and cooperation, and, in particular, to ensure that subjects of the FIU´s interest in other Member States are identified, along with their proceeds, and funds, the Authority and FIUs should constitute the FIU Support and Coordination Mechanism. Its aim should be preventing, detecting and effectively combating money laundering and terrorism financing in the internal market, facilitating cooperation among FIUs, supporting and, in some cases, initiating joint analyses in order to bring together all relevant information, identifying trends and factors relevant in assessing the risks of money laundering and terrorist financing at national and Union level, as well as exchanging views on cooperation-related issues such as effective cooperation among FIUs and between FIUs and third-country financial intelligence units. To that end, Europol, Eurojust and EPPO should have liaison officers based in the Authority´s premises in order to ensure a smooth cooperation.
Removed(31b) The Authority should support FIUs in relation to the following tasks: to support, coordinate and, where necessary, direct joint analyses to be performed with the relevant FIUs as well as to develop methods and procedures to coordinate and facilitate their planning, organisation and conduct; to support cooperation among FIUs, particularly by developing best practices, methods and formats; to develop expert knowledge on detection analysis and dissemination methods; to develop criteria for the identification of cross-border cases that FIUs are required to share; to prepare indicators, formats and contents for the detection and reporting of STRs and other disclosures received by FIUs; to follow the management, maintenance and update of FIU.net and the development of IT and artificial intelligence tools for secure information sharing; to follow the work of international and European fora on FIU-related matters. In performing those tasks, the Authority should have dedicated human, financial and IT resources, and should guarantee their independence from the supervisory functions provided for in Chapter II, Sections 2 to 6.
Removed(32) In order to analyse suspicious activity affecting multiple jurisdictions, the relevant FIUs that received linked reports should be able to efficiently conduct joint analyses of cases of common interest. To this end, the Authority should be able to initiate, propose, coordinate and support with all appropriate means the joint analyses of cross-border suspicious transactions or activities, as well as to adopt internal procedures on the methods and criteria for the selection and prioritisation of cases relevant for joint analyses. The relevant FIUs should participate in the conduct of the joint analysis. Exceptionally, an FIU could decline to participate in the conduct of the joint analysis by duly explaining and justifying it to the Authority in writing. The Authority should provide such explanations and justifications to the other FIUs involved without delay.
Removed(32a) The joint analyses should be triggered with the aim of establishing cross-border links between suspicious transactions and underlying possible criminal activity in order to prevent and combat money laundering and terrorist financing. When conducting the analyses, the Authority and FIUs should disseminate their results as well as additional information to the competent authorities, including, where relevant, Europol, where there are grounds to suspect money laundering, associated predicate offences or financing of terrorism. The FIU delegates of the FIUs participating in the joint analysis should be granted access, directly or indirectly, to all data pertaining to the subject-matter of the joint analysis and should be able to process those data for the purposes of conducting the joint analysis in accordance with the applicable data protection rules, in particular in respect of receiving and analysing suspicious transactions and other information in accordance with Article 17 [please insert reference to the proposal for 6th Anti-Money Laundering Directive - COM/2021/423 final]. Upon the explicit consent of the FIUs participating in the joint analyses, the staff of the Authority supporting the conduct of joint analyses should be able to receive and process the necessary data pertaining to the analysed cases. With the aim of facilitating cooperation with Europol, where relevant, Europol should be able to take part in the joint analysis, subject to the agreement of participating FIUs, when such joint analysis is requested by an FIU. Europol should be given access to a part or all of the data with the explicit consent of the participating FIUs and Europol data should be processed in accordance with [please insert reference to Regulation 2016/794 (Recast)].
Removed(33) In order to improve the effectiveness of the joint analyses, the Authority should be able to establish and review the methods, procedures and the conduct of the joint analyses, with the aim of determining the lessons learnt and of improving and promoting these analyses. The feedback on the joint analysis should enable the authority to issue conclusions and recommendations which would ultimately lead to the regular refinement and improvement of the methods and procedures for the conduct of joint analyses.
Removed(34) In order to facilitate and improve cooperation between FIUs and the Authority, including for the purposes of conducting joint analyses, the FIUs should be able to delegate one staff member per FIU to the Authority ▌. The national FIU delegates should support the Authority’s staff in carrying out all the tasks relating to FIUs, including the conduct of joint analyses and the preparation of threat assessments and strategic analyses of money laundering and terrorist financing threats, risks and methods. In that regard, delegating FIUs should facilitate the exercise of the functions of the relevant FIU delegates and refrain from any action or policy that could adversely affect their career or status in the national system. In particular, FIUs should provide the relevant FIU delegates with the resources and equipment necessary for the exercise of their functions, ensuring that they are fully integrated in the delegating FIU and remain able to receive and analyse suspicious transactions and other information in accordance with Article 17 [please insert reference – proposal for 6th Anti-Money Laundering Directive - COM/2021/423 final]. Apart from the joint analyses, the Authority should encourage and facilitate various forms of mutual assistance between FIUs, including training and staff exchanges in order to improve capacity building and enable the exchange of knowledge and good practices amongst FIUs. The Authority should also facilitate the development or procurement of IT tools and services to enhance its analysis capabilities and those of the FIUs, for example on blockchain analysis and on commercially-held data, where appropriate.
Removed(35) The Authority should manage, host, and maintain FIU.net, the dedicated IT system allowing FIUs to cooperate and exchange information amongst each other and, where appropriate, with their counterparts from third countries and third parties. The Authority should ▌keep the system up-to-date, taking into account the needs expressed by the FIUs. To this end, the Authority should, in consultation with the European Data Protection Supervisor, ensure that at all times the most advanced available state-of-the-art technology, including blockchain-based solutions, is used for the development of the FIU.net▌.
Removed(36) In order to establish consistent, efficient and effective supervisory and FIU-related practices and ensure common, uniform and coherent application of Union law, the Authority should be able to issue guidelines and recommendations addressed to all or category of obliged entities and all or a category of supervisory authorities and FIUs. The guidelines and recommendations could be issued pursuant to a specific empowerment in the applicable Union acts, or on the own initiative of the Authority, where there is a need to strengthen the AML/CFT framework at Union level.
Removed(36a) In order to improve FIU´s practices, the Authority should carry out peer reviews and publish reports setting out its findings. Those reports could be accompanied by guidelines or recommendations addressed to the relevant FIUs. FIUs should be able to participate in peer reviews on a case-by-case basis. The Authority should lay down detailed rules on the confidentiality of its exchanges with FIUs and other relevant actors in the context of peer reviews, including of its results.
Removed(36b) The Authority should be responsible for the effective and consistent supervision of obliged entities and competent authorities relating to the implementation and enforcement of targeted financial sanctions and act as a central contact point ensuring outreach and seemless communication with obliged entities for the purpose of improving compliance. In that regard, the Authority should monitor the implementation and enforcement of targeted financial sanctions across Member States, supporting competent authorities in their efforts to apply targeted financial sanctions, including by acting as a central contact point for competent authorities for sharing information on designated persons, their assets and controlled legal entities. The Authority should furthermore provide guidance and assistance in the application of targeted financial sanctions.
Removed(36c) An inconsistent enforcement of restrictive measures undermines the Union's ability to speak with one voice. It is therefore paramount that restrictive Union measures are fully implemented and that any violation of those measures does not provide any benefit. It is also necessary to ensure that the assets of individuals and entities that violate the restrictive measures can be effectively confiscated in the future. The Authority can play an important role in that regard. The Authority should also cooperate with Asset Recovery Offices in Member States and contribute towards attaining the goals set in [please insert reference –Proposal for a Directive on asset recovery and confiscation, COM(2022) 245 final].
Removed(36d) The Authority should specify the format to be used to request, collect or exchange information with the purpose of enhancing the comparability of the information and ensuring the efficiency of reporting.
Removed(37) The establishment of a solid governance structure within the Authority is essential for ensuring effective exercise of the tasks granted to the Authority, and for an efficient and objective decision-making process. Due to the complexity and variety of the tasks conferred on the Authority in both the supervision and FIU areas, the decisions cannot be taken by a single governing body, as is often the case in decentralised agencies. Whereas certain types of decisions, such as decisions on adoption of common instruments, need to be taken by representatives of appropriate authorities or FIUs, and respect voting rules of the TFEU, certain other decisions, such as the decisions towards individual selected obliged entities, or individual authorities, require a smaller decision-making body, whose members should be subject to appropriate accountability arrangements. Therefore, the Authority should comprise a General Board, and an Executive Board composed of five full-time independent members and of the Chair of the Authority.
Removed(38) In order to ensure the relevant expertise, the General Board should have two compositions. For all the decisions on the adoption of acts of general application such as the regulatory and implementing technical standards, guidelines, recommendations, and opinions relating to FIUs, it should be composed of the heads of FIUs of Member States (‘General Board in FIU composition’). For the same types of acts related to direct or indirect supervision of financial and non-financial obliged entities, it should be composed of the heads of AML/CFT supervisors which are public authorities (‘General Board in supervisory composition’). All parties represented in the General Board should make efforts to limit the turnover of their representatives, in order to ensure continuity of the Board's work. All parties should aim to achieve a balanced representation between men and women on the General Board.
Removed(39) For a smooth decision making process, the tasks should be clearly divided: the General Board in FIU composition should decide on the relevant measures for FIUs, the General Board in supervisory composition should decide on delegated acts, guidelines and similar measures for obliged entities. The General Board in supervisory composition should also be able to provide its opinion and advice to the Executive Board on all draft decisions towards individual selected obliged entities proposed by the Joint Supervisory Teams. In absence of such opinion or advice, the decisions should be taken by the Executive Board. Whenever the Executive Board deviates from the advice provided by the General Board in supervisory composition in the final decision, it should explain the reasons thereof in writing.
Removed(40) For the purposes of voting and taking decisions, each Member State should have one voting representative. Therefore, the heads of public authorities should appoint a permanent representative as the voting member of the General Board in supervisory composition. Alternatively, depending on the subject-matter of the decision or agenda of a given General board meeting, public authorities of a Member State may decide on an ad-hoc representative. The practical arrangements related to decision-making and voting by the General Board members in supervisory composition should be laid down in the Rules of Procedure of the General Board, to be developed by the Authority.
Removed(41) The Chair of the Authority should chair the General Board meetings and have a right to vote when decisions are taken by simple majority. The Commission should be a non-voting member on the General Board. To establish good cooperation with other relevant institutions, the General Board should also be able to admit other non-voting observers, such as a representative of the Single Supervisory Mechanism and of each of the three European Supervisory Authorities (EBA, EIOPA and ESMA) for the General Board in its Supervisory Composition and Europol, the EPPO and Eurojust for the General Board in its FIU composition, where matters that fall under their respective mandates are discussed or decided upon. To allow a smooth decision making process, decisions of the General Board should be taken by a simple majority, except for decisions concerning draft regulatory and implementing technical standards, guidelines and recommendations which should be taken by a qualified majority of Member State representatives in accordance with voting rules of the TFEU.
Removed(42) The governing body of the Authority should be the Executive Board composed of the Chair of the Authority and of five full time members, appointed by the European Parliament and the Council based on the shortlist of qualified candidates drawn up by the Commission. With the aim of ensuring a speedy and efficient decision making process, the Executive Board should be in charge of planning and execution of all the tasks of the Authority except where specific decisions are explicitly allocated to the General Board. In order to ensure objectivity and appropriate rapidity of the decision-making process in the area of direct supervision of the selected obliged entities, the Executive Board should take all binding decisions addressed to selected obliged entities. In addition, together with a representative of the Commission the Executive Board should be collectively responsible for the administrative and budgetary decisions of the Authority. ▌
Removed(43) To allow for swift decisions, all decisions of the Executive Board, including the decision where the Commission has a right to vote, should be taken by simple majority, with the Chair holding a casting vote in case of a tied vote. ▌
Removed(44) To ensure the independent functioning of the Authority the five Members of the Executive Board and the Chair of the Authority should act independently and in the interest of the Union as a whole. They should behave, both during and after their term of office, with integrity and discretion as regards the acceptance of certain appointments or benefits. To avoid giving any impression that a Member of the Executive Board might use its position as a Member of the Executive Board of the Authority to get a high-ranking appointment in the private sector after his term of office and to prevent any post-public employment conflicts of interests, a cooling-off period for the five Members of the Executive Board, including the Chair of the Authority, should be introduced.
Removed(45) The Chair of the Authority should be appointed based on objective criteria by the Council after approval by the European Parliament. He or she should represent the Authority externally and should report on the execution of Authority’s tasks.
Removed(46) The Executive Director of the Authority should be appointed ▌based on objective criteria by the Executive Board after approval by the European Parliament. The Executive Director of the Authority should be a senior administrative official of the Authority, in charge of the day-to-day management of the Authority, and responsible for budget administration, procurement, and recruitment and staffing.
Removed(47) To protect effectively the rights of parties concerned, for reasons of procedural economy and to reduce the burden on the Court of Justice of the European Union, the Authority should provide natural and legal persons with the possibility to request an appeal of decisions taken under the powers related to direct supervision and conferred on the Authority by this Regulation and addressed to them, or which are of direct and individual concern to them. The independence and objectivity of the decisions taken by the Administrative Board of Appeal should be, among others, ensured by its composition of five independent and suitably qualified persons. Decisions of the Administrative Board of Appeal should be in turn appealable before the Court of Justice of the European Union.
Removed(48) It is necessary to provide the Authority with the requisite human and financial resources so that it can fulfil its objectives, tasks and responsibilities under this Regulation. In order to ensure that the Authority can respond flexibly to human resource needs, it is in particular appropriate that it has autonomy regarding the recruitment of contract agents. To guarantee the proper functioning of the Authority, funding should be provided , depending on the tasks and functions, by a combination of fees levied on certain obliged entities and a contribution from the Union budget▌. The budget of the Authority should be part of the Union budget. The contribution from the Union budget is to be decided by the Budgetary Authority through the budgetary procedure. To that end, the Authority should submit to the Commission a statement of estimates. It should also adopt financial rules after consulting the Commission.
Removed(49) To ensure that the Authority can also fulfil its tasks as direct and indirect supervisor of obliged entities, an adequate mechanism for the determination and the collection of the fees should be introduced. As regards the fees levied on selected obliged entities and certain non-selected obliged entities, the methodology for their calculation and the process of collection of fees should be developed in a delegated act of the Commission. The methodology should be based on the risk of the directly and indirectly supervised entities as well as their turnover or revenue. The methodology established should ensure sufficient and stable revenue for the Authority, ensuring the predictability of the contribution from the Union budget, in order to enable the Authority to carry out its duties.
Removed(50) The rules on establishment and implementation of the budget of the Authority, as well as the presentation of annual accounts of the Authority, should follow the provisions of Commission Delegated Regulation (EU) 2019/715 as regards cooperation with the European Public Prosecutor’s Office and the effectiveness of the European Anti-Fraud Office investigations.
Removed(51) In order to prevent and effectively combat internal fraud, corruption or any other illegal activity within the Authority, it should be subject to Regulation (EU, Euratom) No 883/2013 as regards cooperation with the European Public Prosecutor’s Office and the effectiveness of the European Anti-Fraud Office investigations. The Authority should accede to Interinstitutional Agreement concerning internal investigations by OLAF, which should be able, to carry out on-the-spot checks within the area of its competence.
Removed(52) As stated in the Cybersecurity Strategy for the European Union, it is essential to ensure a high level of cyber resilience in all EU institutions, bodies and agencies due to the increasingly hostile threat environment. The Executive Director must thus ensure appropriate IT risk management, a strong internal IT governance and sufficient IT security funding. The Authority shall work closely with the Computer Emergency Response Team of the European Union Institutions, Bodies and Agencies and report major incidents with 24 hours to CERT EU as well as to the Commission.
Removed(53) The Authority should be accountable to both the European Parliament and the Council for the execution of its tasks and implementation of this Regulation. The Chair of the Authority should present a respective report to the European Parliament, the Council and the Commission on a yearly basis.
Removed(54) The staff of the Authority should be composed of temporary agents, contractual agents and seconded national experts as well as national delegates placed at the disposition of the Authority by Union FIUs. The Authority, in agreement with the Commission, should adopt the relevant implementing measures in accordance with the arrangements provided for in Article 110 of the Staff Regulations.
Removed(55) To ensure that confidential information is treated accordingly, all members of the governing bodies of the Authority, all staff of the Authority, including seconded staff and staff placed at the disposition of the Authority, as well as any persons carrying out tasks for the Authority on a contractual basis, should be subject to obligation of professional secrecy, including any confidentiality restrictions and obligations stemming from the relevant provisions of Union legislation, and related to the specific tasks of the Authority. However, confidentiality and professional secrecy obligations should not prevent the Authority from cooperating with, exchanging or disclosing information to other relevant national or Union authorities or bodies, where it is necessary for the performance of their respective tasks and where such cooperation and exchange of information obligations are envisaged in Union law.
Removed(56) Without prejudice to the confidentiality obligations that apply to the Authority’s staff and representatives in accordance with the relevant provisions in Union law, the Authority should be subject to Regulation (EC) No 1049/2001 of the European Parliament and of the Council. In line with the confidentiality and professional secrecy restrictions related to supervisory and FIU support and coordination tasks of the Authority, such access should not be extended to confidential information handled by the staff of the Authority. In particular, any operational data or information related to such operational data of the Authority and of the EU FIUs that is in the possession of the Authority due to carrying out the tasks and activities related to support and coordination of FIUs should be deemed as confidential. With regard to supervisory tasks, access to information or data of the Authority, the financial supervisors, or the obliged entities obtained in the process of carrying out the tasks and activities related to direct supervision should in principle also be treated as confidential and not subject to any disclosure. However, confidential information listed that relates to a supervisory procedure can be fully or partially disclosed to the obliged entities which are parties to such supervisory procedure, subject to the legitimate interest of legal and natural persons other than the relevant party, in the protection of their business secrets.
Removed(57) Without prejudice to any specific language arrangements that could be adopted within AML supervisory system and with selected obliged entities, Council Regulation No 1 should apply to the Authority and any translation services which may be required for the functioning of the Authority should be provided by the Translation Centre for the Bodies of the European Union.
Removed(58) Without prejudice to the obligations of the Member States and their authorities, the processing of personal data on the basis of this Regulation for the purposes of the prevention of money laundering and terrorist financing should be considered necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Authority under Article 5(1)(a) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and Article 6(1)(b) of Regulation (EU) 2016/679 of the European Parliament and of the Council, or when necessary for complying with a legal obligation to which the controller is subject pursuant to Article 5(1)(b) of Regulation (EU) 2018/1725 or Article 6(1)(c) of Regulation (EU) 2016/679. When developing any instruments or taking any decisions that may have an impact on the protection of personal data, the Authority should consult with the European Data Protection Board established by Regulation (EU) 2016/679 and with the European Data Protection Supervisor established by Regulation (EU) 2018/1725 to avoid duplication.
Removed(58a) The Authority should put in place effective and reliable mechanisms to encourage the reporting of potential and actual breaches of Regulation [please insert reference to Funds Transfer Regulation] or Regulation [please insert reference – proposal for Anti-Money Laundering Regulation - COM/2021/420 final] by obliged entities or potential and actual breaches of [please insert reference – proposal for 6th Anti-Money Laundering Directive - COM/2021/423 final] by obliged entities, supervisory authorities, FIUs or authorities competent for the implementation of targeted financial sanctions. For that purpose, the Authority should ensure a high level of protection of the persons reporting those breaches, at least equivalent to the level of protection of persons reporting breaches of Union law provided by Directive (EU) 2019/1937.
Removed(58b) Member States should ensure that individuals, including employees and representatives of the obliged entity, supervisory authorities, FIUs or authorities competent for the implementation of targeted financial sanctions, who report to the Authority actual or potential breaches of Regulation [please insert reference to Funds Transfer Regulation], Regulation [please insert reference – proposal for Anti-Money Laundering Regulation - COM/2021/420final] or breaches of [please insert reference – proposal for 6thAnti-Money Laundering Directive - COM/2021/423 final], are legally protected from being exposed to threats, retaliatory or hostile action, and in particular from adverse or discriminatory employment actions. Member States should also ensure that individuals who are exposed to threats, hostile actions, or adverse or discriminatory employment actions for reporting to the Authority actual or potential breaches of Regulation [please insert reference to Funds Transfer Regulation], Regulation [please insert reference – proposal for Anti-Money Laundering Regulation - COM/2021/420final] or breaches of [please insert reference – proposal for 6th Anti-Money Laundering Directive -COM/2021/423 final], are entitled to present a complaint in a safe manner to the respective competent authorities. Without prejudice to the confidentiality of information gathered by FIUs, Member States should ensure that such individuals have the right to an effective remedy to safeguard their rights in accordance with applicable Union law. In accordance with Article 23 of the Directive (EU) 2019/1937 of the European Parliament and of the Council, Member States should also provide for proportionate and dissuasive penalties applicable to reporting persons where it is established that those persons knowingly reported or publicly disclosed false information.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0128/compare/TA-9-2024-0366?all=1&part=2
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 27 September 2026
Cite as
European Parliament (2024). “Changes between A-9-2023-0128 and TA-9-2024-0366”. Text, 24 April 2024. from A-9-2023-0128, to TA-9-2024-0366. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0128/compare/TA-9-2024-0366?all=1&part=2 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-24,
author = {{European Parliament}},
title = {{Changes between A-9-2023-0128 and TA-9-2024-0366}},
year = {2024},
date = {2024-04-24},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0128/compare/TA-9-2024-0366?all=1&part=2}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0128/compare/TA-9-2024-0366?all=1&part=2},
urldate = {2026-09-27},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2023-0128, to TA-9-2024-0366. Data: European Parliament Open Data (CC BY 4.0)}
}