News
EU
news image Published on : 28/09/2026

18 EU states miss beneficial-ownership access deadline — AML programmes now run on a split map

Executive summary.

  • It has been reported that on 25 September 2026, the European Commission sent letters of formal notice to 18 Member States that had not declared full transposition of the AMLD6 rules on who may see company and trust beneficial-ownership registers.

  • The deadline was 10 July 2026. The letters initiate an infringement process; they are not a court finding and carry no fine.

  • Governments have two months to reply.

  • For firms, the practical problem is immediate:

    • Customer due diligence still cannot rest on the register alone, access already differs from country to country, and

    • From 10 November 2026, registrars are supposed to decide legitimate-interest requests within 12 working days.

  • Treat the list as a warning that official UBO data is incomplete and uneven — not as proof that any given national register is closed.

Brussels has opened infringement proceedings against 18 Member States for failing to fully transpose EU rules on access to beneficial ownership registers — a gap that leaves firms running AML programmes on an uneven, legally incomplete map.

  • On 25 September 2026, the European Commission sent letters of formal notice to

    • Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Estonia,

    • Finland, France, Germany, Greece, Lithuania, Luxembourg,

    • The Netherlands, Poland, Portugal, Romania and Spain.

  • The Commission’s position is that these countries had not fully transposed the relevant provisions by the deadline of 10 July 2026.

  • The articles in issue are those that govern access to central beneficial ownership registers for competent authorities, self-regulatory bodies, obliged entities, and persons who can show a legitimate interest in preventing money laundering, predicate offences and terrorist financing (Articles 11, 12, 13 and 15 of Directive (EU) 2024/1640, the Sixth Anti-Money Laundering Directive).

  • A letter of formal notice is the first step in an infringement procedure.

  • It is not a court finding that EU law has been breached, and it does not impose a fine. Governments have two months to reply, complete any missing measures, and notify the Commission.

  • If the Commission is not satisfied, it can issue a reasoned opinion and, later, refer the case to the Court of Justice. A Member State may have already enacted some of the rules yet still be in the package because it has not notified a complete set of national measures for the specified articles. That distinction matters: the legal text on the ground and the Commission’s notification file can diverge.

  • The 10 July 2026 deadline was the date by which Member States were required to put the access architecture in place.

  • From 10 November 2026, registers are supposed to verify a legitimate-interest applicant and respond within 12 working days (extendable by 12 days in a surge of requests). Successful applicants should receive a certificate valid for three years, with subsequent requests answered within seven days. Those operational clocks now sit atop an incomplete national notification.

What this means for AML risk, not just the Brussels process

The risk for firms is operational and supervisory, not that the Commission will fine a bank for a Member State’s failure to notify.

  • Registers cannot be treated as a complete control. Under the AML package, obliged entities must collect beneficial ownership information themselves and report any discrepancies to the register. They must not rely exclusively on the register to discharge customer due diligence. Where a national register is late, incomplete, restricted, or only available after a slow legitimate-interest process, the residual risk sits with the firm. Supervisors will still expect a defensible source mix: company documents, group structures, reliable commercial data, and documented attempts to use the official register.

  • Access is already fragmented, and this package freezes that fragmentation in public view. After the 2022 Court of Justice ruling that struck down unrestricted public access, Member States rebuilt access on a “legitimate interest” model. In practice, the gates differ: some registers are closed to the public and slow for journalists and NGOs; some restrict electronic access; some have passed the 2026 amendments, while others have not notified them. Cross-border groups therefore cannot run a single “EU UBO lookup” standard. A German bank onboarding a Spanish holding company, a Dutch fund using a Luxembourg SPV, or a UK/EEA firm using BORIS still faces country-by-country rules, fees, identity checks and delays.

  • The November 2026 response deadlines will expose capacity problems. If 18 countries have not even notified full transposition, it is not safe to assume that every registrar will meet the 12-working-day decisions from mid-November. Firms that have built onboarding SLAs around register extracts should treat those SLAs as at risk in the listed jurisdictions.

  • Legitimate-interest access is a second-order risk for the AML industry itself. AML product providers, investigative journalists, civil-society organisations and counterparties to transactions are among the categories the Directive treats as having a presumed or demonstrable legitimate interest. Delayed or inconsistent national rules mean delayed intelligence for NGOs and delayed product features for vendors — which in turn affects the quality of third-party data that banks buy.

  • Notification failure is not the same as an empty statute book. Malta, for example, brought Legal Notice 184 of 2026 into force on the July deadline and rewrote access tiers. Other listed states may have similar domestic texts that the Commission has not yet accepted as a complete notification. Compliance teams should map actual national law and portal access, not only the infringement list. Treating every named country as “no register access” would be wrong; treating the list as “access is reliable and harmonised” would also be wrong.

  • The larger AML package still arrives in 2027. The AML Regulation (the single rulebook) applies from 10 July 2027. AMLA will supervise selected firms directly. Beneficial-ownership definition, discrepancy reporting, and group-wide controls will be set out in directly applicable EU law, even if some national register procedures remain messy. Firms that wait for every Member State to close its infringement file before tightening BO collection will be late for the Regulation.

What should compliance functions do now

  • Document, for each of the 18 jurisdictions, whether the national register is live for obliged entities, what identification and fees apply, typical turnaround, and whether legitimate-interest certificates exist.

  • Record failed or delayed register queries as part of the CDD file. Do not close high-risk files on the assumption that a missing extract is the register’s problem rather than the firm’s.

  • Escalate to legal and public-affairs teams when a group entity needs access that the local portal still refuses.

  • Watch the two-month reply window (roughly late November 2026): reasoned opinions would be the next public signal that a state is not closing the gap.

  • The Commission’s language is that the gradual implementation of AMLD6 is “essential” to close weaknesses in the Union’s financial system. Until notification is complete and registers actually respond within the statutory timeframes, firms must prove they know who owns the customer.

Primary sources to verify

 

EU

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.  

Archived News

To find our older articles, please click here.

View archive