Regulated-Admin · Authority guide

6AMLD vs 5AMLD: What Changed for Onboarding Teams

5AMLD, 6AMLD, and the 2024 AML package all touch onboarding — but not the way most teams think. A cited, plain-language guide to what each one actually changed for KYC/KYB.

The three-way naming problem nobody warns you about

If your onboarding team is confused about "5AMLD vs 6AMLD," that is not a knowledge gap — it is a labelling problem baked into EU law. There are, in practice, three things people mean when they say "6AMLD," and only one of them is what your onboarding workflow will be judged against in 2027.

Getting this straight matters, because an examiner will not accept "we followed 6AMLD" if you cannot say which one. Here is the clean version.

  • 5AMLD — Directive (EU) 2018/843. The directive that pulled crypto into the AML perimeter. Transposition deadline 10 January 2020.
  • 6AMLD (the real one) — Directive (EU) 2018/1673, "on combating money laundering by criminal law." Transposition deadline 3 December 2020. This is a criminal-law directive, not an onboarding-procedure directive — and that distinction is the whole point.
  • "AMLD6" (the 2024 one) — Directive (EU) 2024/1640, part of the 2024 AML package. Different instrument, different number, transposition largely by 10 July 2027. This is the one that actually rewrites onboarding.

Below is what each changed, and — more usefully — what it changed for the people running KYC and KYB intake.

What 5AMLD (2018/843) changed for onboarding

5AMLD is the directive most onboarding teams have actually built against. It amended the Fourth Anti-Money Laundering Directive (Directive (EU) 2015/849) and did three things that show up directly in intake work:

  1. It made crypto an obliged sector. Article 1(1)(c) of 2018/843 amended Article 2(1) of 2015/849 to add providers of exchange services between virtual and fiat currencies and custodian wallet providers to the list of obliged entities, with matching definitions inserted into Article 3(18)–(19). In plain terms: crypto exchanges and wallet custodians now owe the same customer due diligence (CDD) any bank owes.
  2. It tightened enhanced due diligence for high-risk third countries. 5AMLD inserted a prescriptive EDD checklist (Article 18a of 2015/849) for business relationships involving high-risk third countries — additional information on the customer, source of funds, and senior-management sign-off before onboarding.
  3. It widened beneficial-ownership transparency, moving UBO registers toward public access and interconnection — which changed what an onboarding analyst is expected to verify and evidence for corporate customers.

The onboarding takeaway: 5AMLD is procedural. It expanded who must run CDD and what an EDD file has to contain. If your intake process produces thin files, 5AMLD is where the gap first becomes visible.

What 6AMLD (2018/1673) changed — and why onboarding teams still feel it

The genuine 6AMLD is easy to under-read because it is aimed at prosecutors, not intake analysts. It harmonised money laundering as a crime across the EU. The provisions that change the risk calculus of onboarding:

  • 22 predicate offences. Article 2 of 2018/1673 defines a common list of 22 categories of predicate offence — including cybercrime and environmental crime — so the underlying crimes that trigger laundering are the same in every member state.
  • Self-laundering and facilitation are in scope. Article 3 covers self-laundering, and Article 4 criminalises aiding, abetting and inciting. An institution's staff who help a launderer onboard are inside the frame, not adjacent to it.
  • Legal persons can be liable. Articles 7–8 extend liability to legal persons for offences committed for their benefit due to a lack of supervision or control.
  • Tougher penalties. Article 5 sets the maximum term of imprisonment at at least four years, up from the previous one-year floor.

The onboarding takeaway: 6AMLD did not add a KYC form field. It raised the stakes of getting onboarding wrong. A weak, unevidenced onboarding decision is no longer just a supervisory finding — it is the front edge of potential corporate criminal exposure for a control failure. That is precisely why "why did you accept this account?" needs a defensible, reconstructable answer, not a risk score.

The part everyone conflates: the 2024 AML package (the real onboarding overhaul)

When a 2026-era vendor says "get ready for 6AMLD," they almost always mean the 2024 AML package, which is a different animal from 2018/1673:

  • AMLR — Regulation (EU) 2024/1624. A single, directly applicable EU rulebook that harmonises CDD, EDD, beneficial ownership, and PEP handling across all 27 member states. It applies from 10 July 2027. Because it is a regulation, there is no national transposition to hide behind — the same onboarding rules apply everywhere.
  • AMLD6 — Directive (EU) 2024/1640. Covers beneficial-ownership registers, financial intelligence units, and supervision; transposed largely by 10 July 2027.
  • AMLA — Regulation (EU) 2024/1620. Created the EU Anti-Money Laundering Authority, seated in Frankfurt and operational since 1 July 2025, with direct supervision of selected high-risk cross-border institutions.

This is the package that will actually standardise what a compliant onboarding file looks like — and it removes the "our jurisdiction interprets it differently" defence. Teams that treat onboarding evidence as reconstructable, cited, and human-signed now are building for the 2027 baseline instead of retrofitting to it.

Side-by-side

5AMLD — 2018/843 6AMLD — 2018/1673 2024 package — 2024/1624 + /1640 + /1620
Type Directive (procedure) Directive (criminal law) Regulation + Directive + Authority
Deadline 10 Jan 2020 3 Dec 2020 Applies / transposed 10 Jul 2027
Onboarding effect Crypto in scope; EDD checklist; UBO transparency Raises criminal stakes of a bad decision Single CDD/EDD/PEP rulebook, EU-wide
The one-liner Who must do CDD, and what the file holds What it costs to get onboarding wrong One standard everyone is measured against

What onboarding teams should do about it now

You do not need to wait for July 2027 to act on the direction of travel. Three moves pay off under all three regimes:

  1. Make every onboarding decision reconstructable. Tie each material conclusion to the specific obligation it satisfies (CDD under Article 13 of 2015/849, EDD under Articles 18/18a, PEP handling under Articles 20–22) and to the evidence that supports it.
  2. Keep a named human in the loop. Given 6AMLD's legal-person liability, decision support with human sign-off ages far better than opaque decision replacement.
  3. Standardise the file now. The AMLR single rulebook rewards teams whose onboarding packets already look the same across jurisdictions and reviewers.

That is the design principle behind Regulated-Admin: evidence in, cited decision out, human-approved, reconstructable later. It maps onboarding decisions to the exact CDD, EDD, PEP, and sanctions obligations above, so the file answers "why did you accept this account?" before anyone asks.

Want to see a cited onboarding packet mapped to your own worst-case counterparty type? That is exactly what a design-partner pilot is for — first 500 onboards at EUR 30 each, human sign-off built in.

Request a pilot →

Sources (checkable)

Related: Why audit-grade citations beat black-box scores →