Skip to content
Regulatory regime guide

AML, financial crime, DORA and operational resilience

Anti-money-laundering, financial-crime controls and the Digital Operational Resilience Act.

Scope
European Union. Illustrative overview, so verify against current national requirements.
Last reviewed
2026-07-18

Direct answer

AML/CTF and DORA are cross-cutting: nearly every EU financial authorisation depends on a credible financial-crime framework and, increasingly, demonstrable ICT and operational resilience. With the new AML package and AMLA, and DORA now in force, these are core parts of any application, not an afterthought.

Who this applies to

  • All regulated financial institutions and applicants
  • Payment, e-money, investment, crypto and crowdfunding firms
  • ICT third-party providers to financial entities

Regulated activities

  • Customer due diligence, monitoring and sanctions screening
  • Business-wide AML/CTF risk assessment and governance
  • ICT risk management, incident reporting and resilience testing (DORA)
  • Third-party ICT and critical-provider oversight

Routes to market

Embedded in authorisation

Build AML and DORA evidence as part of the application, not after.

Remediation programme

Close gaps identified in readiness review before submission or supervision.

Capital and substance

  • MLRO / compliance function with local substance and independence.
  • ICT governance, register of information and resilience testing.
  • Incident-reporting and third-party risk management.

Authorisation stages

  1. 1

    Risk assessment

    Complete business-wide AML and ICT risk assessments.

  2. 2

    Framework build

    Implement controls, policies and monitoring.

  3. 3

    Evidence

    Prepare regulator-ready documentation and testing results.

  4. 4

    Ongoing supervision

    Maintain reporting and resilience over time.

Where applications commonly fail

  • Treating AML and DORA as documentation exercises rather than operating capability
  • Weak sanctions screening and transaction monitoring
  • Incomplete register of information and third-party oversight

Frequently asked questions

Increasingly yes. Supervisors expect demonstrable ICT risk management and operational resilience as part of authorisation and ongoing supervision.

Official regulatory sources

Verified external references. Always confirm against the current official text.

RenIQ provides regulatory strategy and programme delivery. It is not a law firm and this content is illustrative guidance, not legal advice. Regime details are summaries that may change, so always verify against current rules and official sources, and take formal advice before acting.

Planning a AML & DORA application?

Book an intro call to pressure-test your route, timeline and evidence plan with a senior practitioner.