Newsroom ·

EBA finalises reporting framework 4.3 for third-country branches and AMLA data collection

regulatoryaml

What happened

On 9 July 2026 the European Banking Authority (EBA) published the final technical package for version 4.3 of its reporting framework. The package introduces two new reporting streams:

  • supervisory reporting for third-country branches (TCBs) under Article 48l(1) of the Capital Requirements Directive (CRD VI), with a first reference date of 31 March 2027;
  • an AMLA risk assessment data collection that supports the identification of obliged entities falling under the direct supervision of the Anti-Money Laundering Authority (AMLA). Its first reference date is 31 December 2026, but it will be reported using the future framework version 4.4.

The package contains the full set of standard specifications: the data point model (DPM), XBRL taxonomies, validation rules, and a new Glossary Usage Exploration file intended to make the semantic model easier to navigate.

Finansinspektionen (FI) issued a brief notice on 13 July confirming the publication. FI stresses that version 4.3 is published purely to allow firms to begin preparations and will not be used for reporting to FI. Actual reporting under the AMLA framework will be delivered through version 4.4, which will contain the submissions due during 2027. FI will publish the corresponding submission dates in its reporting portal Fidac.

Differences in detail

EBA’s press release is technically dense, covering validation rules, feedback processes, and a possible hotfix at end-September. It targets EU institutions and software vendors that build reporting solutions on the EBA taxonomies.

FI’s note is short and operationally focused on what matters for Swedish firms. It adds the crucial local precision that AMLA reporting will eventually use version 4.4, not 4.3, and that the 4.3 taxonomy is only a preparatory artefact. The two authorities agree on the modules and the high-level timetable, but the difference lies in how much implementation guidance is provided at the national level.

Relevance for Swedish reporting entities

The TCB reporting module is unlikely to directly affect Sigill’s core customer base of Swedish payment institutions, e-money institutions and registered payment service providers, as these firms are not third-country branches.

The AMLA risk assessment data collection is more significant. It introduces a new, centralised AML reporting strand that will ultimately require a broad set of obliged entities – including payment and e-money institutions – to supply data to AMLA. While no immediate reporting obligation arises for Swedish firms, the direction of travel is clear. Institutions should monitor FI’s upcoming version 4.4 specifications and the related Fidac instructions so they can plan the necessary data preparation.

Sigill already handles FI’s national aml return for payment institutions and e-money institutions. Once FI adopts the AMLA data collection under a future reporting framework, Sigill will incorporate the new data points into its service, ensuring firms can meet the new requirements without a separate reporting exercise.

What happens next

There is no filing obligation today for TCB or AMLA reporting under version 4.3 in Sweden. Firms should look out for FI’s release of version 4.4 and any related consultations. Sigill will assess the final DPM and taxonomy changes as they become applicable for FI reporting, keeping its COREP OF, FINREP and national return services aligned.

Sources: EBA publishes final technical package for reporting framework 4.3 · Finansinspektionen: EBA publicerar nytt paket för rapportering