
On 10 July 2027, Regulation (EU) 2024/1624 replaces the fourth Anti-Money Laundering Directive with a single directly applicable rulebook. Most of the coverage of that change concerns beneficial ownership thresholds, the new authority, and the extension of the regime to new sectors.
One provision inside it changes what a customer-facing employee is allowed to write, and it has attracted almost no attention.
Article 73 restates the tipping-off prohibition. Read against Article 39 of the current directive, the categories of person bound are the same: obliged entities and their directors, officers and employees. What changes is the fact that may not be disclosed, and the change moves the prohibition to an earlier point in the process.
Article 39 of Directive (EU) 2015/849 covers two things. Disclosing that a suspicious transaction report has been, is being, or will be transmitted. And disclosing that a money laundering or terrorist financing analysis is being, or may be, carried out.
Both of those attach to something that has already happened inside the compliance function. A report exists, or an analysis has begun. Firms have built their customer communication standards around that boundary, usually without stating it explicitly. Wording is treated as sensitive once a matter has been escalated to the MLRO, and treated as ordinary before that point.
Article 73(1) covers three things. The transmission of information under Articles 69 and 70. An analysis being or possibly being carried out. And, as a separate limb, the fact that transactions or activities are being or have been assessed under Article 69.
That third limb is the change. Assessment is what happens before anything is escalated, reported, or analysed. It is the first-line review of an alert, the second look at a payment, the question a supervisor asks about an unusual pattern. Under the directive that activity produces no covered fact until it turns into something more. Under the Regulation, the assessment itself is the covered fact.
The practical consequence follows from arithmetic rather than from law.
In any firm of size, the number of transactions assessed in a year is very much larger than the number reported. Alerts are reviewed and closed. Payments are looked at and released. Questions are asked and answered internally. Most of that activity ends with a decision that nothing further is required, and under the current regime almost none of it leaves a customer-facing trace that the prohibition reaches.
From 10 July 2027, every one of those reviews is a fact that cannot be disclosed to the customer. The population of protected facts grows by a factor that depends on your alert-to-report ratio, and in most firms that ratio is large.
The people newly exposed are the ones furthest from the compliance function. An agent explaining a two-day payment delay that was resolved by a first-line reviewer is now explaining something covered by the prohibition. Under the directive, that same explanation would often have been outside it, because no report and no analysis existed.
A specific and common pattern becomes unsafe, and it is worth naming because it is currently taught as good practice.
Many firms distinguish, in their customer communication standards, between matters that have been escalated and matters that have not. Agents are given latitude to be more explanatory about an ordinary check, and instructed to fall back to a formula once something has gone to the MLRO. The reasoning is sound under the current rule, because the covered fact does not exist until escalation.
That distinction stops being safe when the assessment itself is covered. Worse, the distinction reproduces the consistency problem in a new place: if agents explain ordinary checks in detail and become formulaic about assessed ones, the change in register is itself informative.
The wording that survives the change is wording that is the same for every case, whatever stage it has reached.
Two parts of the article are worth knowing because they answer the objections that come up whenever this is discussed internally.
Dissuasion is not disclosure. Article 73(6) makes clear that attempting to dissuade a client from engaging in illegal activity does not constitute disclosure within the meaning of the prohibition. Firms that have avoided intervening for fear of tipping off have a clearer basis to act.
Internal and inter-firm sharing is provided for. Paragraphs 2 to 5 permit disclosure to competent authorities and investigating bodies, sharing within a group and with third-country branches and subsidiaries under group-wide policies, sharing across professional networks under common ownership or compliance control, and sharing between obliged entities involved in the same transaction, subject to professional secrecy and data protection obligations. Escalating internally and sharing appropriately with a counterpart institution are provided for by the article rather than prohibited by it.
The prohibition is aimed at the customer and at third parties. It is worth saying that plainly inside a firm, because the common failure is over-application to internal escalation and under-application to the sentence that actually goes to the customer.
| Situation | Under the directive | From 10 July 2027 |
|---|---|---|
| Alert reviewed by first line and closed, no escalation | Generally no covered fact | The assessment is a covered fact |
| Payment held, released after a second look | Generally no covered fact | The assessment is a covered fact |
| Matter escalated, analysis under way | Covered | Covered |
| Report transmitted to the FIU | Covered | Covered |
| Telling a client to stop doing something unlawful | Treated cautiously by many firms | Expressly outside the prohibition |
The first two rows are where the work is. They describe the ordinary operating volume of a financial crime function, and they are the cases your front line currently handles with the most latitude.
One procedural point changes the planning horizon. Because this is a regulation rather than a directive, it applies directly in every member state from the same date. There is no national implementation act to wait for, no local variation to interpret, and no period during which the position differs across your European entities.
Firms accustomed to the directive rhythm have generally planned against national transposition dates, which arrive at different times and give a natural sequencing to multi-country rollouts. That sequencing is not available here.
The United Kingdom is outside the Regulation, and section 333A of the Proceeds of Crime Act 2002 is unaffected by it. The UK prohibition continues to attach to disclosing that a report has been made and to disclosing that an investigation is being considered or carried out.
Two situations still bring UK firms into contact with the change. A UK group with EU subsidiaries or branches will have entities directly in scope, and running two customer communication standards across one group is a poor outcome. And a UK firm serving EU customers through an EU entity is applying the Regulation to those relationships whatever the position at home.
The practical answer for most groups is to write to the stricter standard once. The wording that satisfies Article 73 also satisfies section 333A, and the reverse is not reliably true.
A change of this kind fails in a predictable way. The policy is updated, the training is delivered, and the wording in the templates converges. Then somebody replies outside a template, at speed, to a customer who has asked three times, and writes the sentence the standard was designed to prevent.
Our pre-send check works on that gap. It reads the draft in Outlook or Gmail and flags a disclosing construction while the sentence is still open, which is the last moment the answer can change. It does not decide whether to file, it does not read your case management system, and it is no substitute for agreeing the standard in the first place.
We have written the standard itself into a free ten-page pack: four moments, twenty-two wording pairs each with the reasoning behind it, and a printable desk card. Get the SAR-safe wording pack.
Put 10 July 2027 in the compliance plan with a specific line item for customer communication wording, separate from the beneficial ownership and registration work that will dominate the programme. The change is small in the text and large in the operating population it reaches, which is the combination that produces surprises. For the wording itself, see our guide to what you can tell a customer after filing a report.
See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.
See VerbaPulse in action →