Tuesday, 18 March 2025

Information sharing in the context of the new EU AML Regulation

After a (rather long) absence from the editorial scene, I return with a relevant topic in the field of international efforts to combat money laundering, terrorist financing, and the proliferation of weapons of mass destruction. Especially since I ”owed” an article to my friends at Casino Inside.

by Daniel Staicu, AML/CFT expert

Daniel Staicu

In the landscape of discussions in Romania, this topic has often been treated superficially, despite being a fundamental pillar in the mechanisms for preventing and combating financial crimes. Information sharing takes place both at the national level, between competent authorities, and internationally, between financial intelligence units (FIUs). Why did I choose this topic? The recent adoption of the new EU AML legislative package, published in the summer of 2024, has marked a significant paradigm shift in this field. But let’s start from the beginning.

 

The role of the Financial Intelligence Unit

At the core of the information-sharing system is the Financial Intelligence Unit (FIU), known in Romania as the National Office for Preventing and Combating Money Laundering, which acts as a hub. It collects and analyzes data received from obligated entities in accordance with existing legislation and transmits it to competent authorities, both nationally (supervisory bodies, law enforcement agencies, etc.) and internationally to other FIUs.

Under previous regulations, information sharing between reporting entities was only permitted within the same corporate group, in line with AMLD 4/5 directives. However, for the first time, the new EU AML legislative package introduces the possibility of information exchange between distinct private entities.

 

Information sharing in the private sector 

For this exchange of information to be possible, strict conditions must be met. The central sine qua non element is the existence of an information-sharing partnership, defined as a mechanism that allows the transfer and processing of data between obligated entities and, where applicable, competent authorities, either nationally or cross-border.

This mechanism is not a formal organization but rather a collaborative framework that ensures compliance with legal requirements. Participating entities must (i) Notify the relevant supervisory authorities, (ii) Assess the impact on personal data protection, in accordance with GDPR, in consultation with the national data protection authority and (iii)Ensure compliance with European and national regulations.

This implies a set of guarantees regarding the legality of information exchange, its purpose, and the protection of personal data.

 

Benefits and limitations of information sharing

An essential observation here is that an information-sharing partnership can be established between different categories of reporting entities, as defined by EU AMLD or national anti-money laundering laws. It is not mandatory for a partnership to exist only between banks, for example, or between gambling service providers.

Another crucial point is that these partnerships can be formed at the national, regional, international, or global level. In fact, cross-sectoral and cross-border collaborations are not only possible but, in my opinion, highly desirable to enhance the efficiency of anti-money laundering efforts.

Imagine gambling service providers exchanging information with financial institutions regarding clients suspected of money laundering—or vice versa. Using a well-known phrase, this would be a win-win situation.

Furthermore, private institutions will only exchange information when it is strictly necessary to fulfill AML/CFT obligations, ensuring compliance with fundamental rights and judicial safeguards, as stated above. This is a logical consequence of the fact that the regulation is an AML-related act.

 

The scope of information sharing

Information exchange is limited to clients who: exhibit behaviors or transactions associated with a higher risk of money laundering, predicate offenses, or terrorist financing, as identified in EU and national risk assessments, are located in third countries with strategic AML/CFT deficiencies, virtual asset service providers (VASPs), shell financial institutions, holders of golden visas, politically exposed persons (PEPs), their relatives, or known associates, require additional due diligence from obligated entities to determine if they pose a higher risk of money laundering or terrorist financing. Thus, only high-risk clients from an AML/CFT perspective fall under this scope.

EU AML Regulation

Additionally, the types of information that can be exchanged are clearly regulated. These include client identification details, the purpose and nature of the business relationship or transaction, the source of wealth and funds, transaction details, risk factors associated with the client, risk analysis conducted by the reporting entity, information held under record-keeping obligations, suspicious activity reports (SARs) submitted to FIUs.

Although at first glance this mechanism may seem restrictive—given the use of terms such as “only,” “limited,” and “strictly necessary” in the regulation—it actually represents a major step forward compared to previous regulations. Or, to put it more precisely, compared to the lack of previous provisions, where information sharing between FIUs was mainly governed by the Egmont Charter and the Egmont Group Principles for Information Exchange.

Additionally, we must consider the new European Anti-Money Laundering Authority (AMLA) and its growing need for information to effectively fulfill its responsibilities.

 

Best Practices at the European Level

Although the new EU regulation is relatively recent, several initiatives have already demonstrated the effectiveness of private-sector information sharing:

  • Europol Financial Intelligence Public-Private Partnership (EFIPPP) – Established in 2017, this was the first transnational AML/CFT information-sharing mechanism between Europol, FIUs, and private financial institutions. During my tenure as head of the Moldovan FIU, I had the honor of facilitating the inclusion of Moldova’s Financial Intelligence Unit in this initiative.
  • National Crime Agency Public-Private Partnership (UK) – A collaboration between the UK’s National Crime Agency (NCA) and seven British banks, evolving from a 2021–2022 pilot project that initially included only two banks and the NCA.
  • Fintell Alliance NL (Netherlands) – A partnership between the Dutch FIU and the country’s four largest banks (ABN AMRO, ING, Rabobank, and Volksbank), which cooperate directly within a dedicated framework.

 

Conclusions 

This article does not aim to provide an exhaustive analysis of Article 75 of AMLR, but rather to highlight the opportunities introduced by this new regulation for industry professionals.

When built on solid foundations—with well-defined policies and procedures, as required by the regulation—these information-sharing partnerships can significantly enhance AML/CFT efforts, reduce the risk exposure of reporting entities, and support authorities in safeguarding the integrity of the financial system at both national and EU levels.

Finally, while implementing these partnerships requires resource allocation and may put additional budgetary pressure on obligated entities, the long-term benefits—including avoiding severe AML penalties and enhancing financial security—make it a worthwhile and strategic investment.

 





Author: Editor

Share This Post On

Submit a Comment

Your email address will not be published. Required fields are marked *