← All posts
Thought Leadership

The tipping-off prohibition moves earlier in 2027

September 30, 2026 · 8 min read

On 10 July 2027, Regulation (EU) 2024/1624 replaces the fourth Anti-Money Laundering Directive with a single directly applicable rulebook. Most of the coverage of that change concerns beneficial ownership thresholds, the new authority, and the extension of the regime to new sectors.

One provision inside it changes what a customer-facing employee is allowed to write, and it has attracted almost no attention.

Article 73 restates the tipping-off prohibition. Read against Article 39 of the current directive, the categories of person bound are the same: obliged entities and their directors, officers and employees. What changes is the fact that may not be disclosed, and the change moves the prohibition to an earlier point in the process.

What the current prohibition attaches to

Article 39 of Directive (EU) 2015/849 covers two things. Disclosing that a suspicious transaction report has been, is being, or will be transmitted. And disclosing that a money laundering or terrorist financing analysis is being, or may be, carried out.

Both of those attach to something that has already happened inside the compliance function. A report exists, or an analysis has begun. Firms have built their customer communication standards around that boundary, usually without stating it explicitly. Wording is treated as sensitive once a matter has been escalated to the MLRO, and treated as ordinary before that point.

What Article 73 adds

Article 73(1) covers three things. The transmission of information under Articles 69 and 70. An analysis being or possibly being carried out. And, as a separate limb, the fact that transactions or activities are being or have been assessed under Article 69.

That third limb is the change. Assessment is what happens before anything is escalated, reported, or analysed. It is the first-line review of an alert, the second look at a payment, the question a supervisor asks about an unusual pattern. Under the directive that activity produces no covered fact until it turns into something more. Under the Regulation, the assessment itself is the covered fact.

Why that reaches further than it sounds

The practical consequence follows from arithmetic rather than from law.

In any firm of size, the number of transactions assessed in a year is very much larger than the number reported. Alerts are reviewed and closed. Payments are looked at and released. Questions are asked and answered internally. Most of that activity ends with a decision that nothing further is required, and under the current regime almost none of it leaves a customer-facing trace that the prohibition reaches.

From 10 July 2027, every one of those reviews is a fact that cannot be disclosed to the customer. The population of protected facts grows by a factor that depends on your alert-to-report ratio, and in most firms that ratio is large.

The people newly exposed are the ones furthest from the compliance function. An agent explaining a two-day payment delay that was resolved by a first-line reviewer is now explaining something covered by the prohibition. Under the directive, that same explanation would often have been outside it, because no report and no analysis existed.

The wording that stops working

A specific and common pattern becomes unsafe, and it is worth naming because it is currently taught as good practice.

Many firms distinguish, in their customer communication standards, between matters that have been escalated and matters that have not. Agents are given latitude to be more explanatory about an ordinary check, and instructed to fall back to a formula once something has gone to the MLRO. The reasoning is sound under the current rule, because the covered fact does not exist until escalation.

That distinction stops being safe when the assessment itself is covered. Worse, the distinction reproduces the consistency problem in a new place: if agents explain ordinary checks in detail and become formulaic about assessed ones, the change in register is itself informative.

The wording that survives the change is wording that is the same for every case, whatever stage it has reached.

What Article 73 permits

Two parts of the article are worth knowing because they answer the objections that come up whenever this is discussed internally.

Dissuasion is not disclosure. Article 73(6) makes clear that attempting to dissuade a client from engaging in illegal activity does not constitute disclosure within the meaning of the prohibition. Firms that have avoided intervening for fear of tipping off have a clearer basis to act.

Internal and inter-firm sharing is provided for. Paragraphs 2 to 5 permit disclosure to competent authorities and investigating bodies, sharing within a group and with third-country branches and subsidiaries under group-wide policies, sharing across professional networks under common ownership or compliance control, and sharing between obliged entities involved in the same transaction, subject to professional secrecy and data protection obligations. Escalating internally and sharing appropriately with a counterpart institution are provided for by the article rather than prohibited by it.

The prohibition is aimed at the customer and at third parties. It is worth saying that plainly inside a firm, because the common failure is over-application to internal escalation and under-application to the sentence that actually goes to the customer.

Today and 2027, side by side

Situation Under the directive From 10 July 2027
Alert reviewed by first line and closed, no escalation Generally no covered fact The assessment is a covered fact
Payment held, released after a second look Generally no covered fact The assessment is a covered fact
Matter escalated, analysis under way Covered Covered
Report transmitted to the FIU Covered Covered
Telling a client to stop doing something unlawful Treated cautiously by many firms Expressly outside the prohibition

The first two rows are where the work is. They describe the ordinary operating volume of a financial crime function, and they are the cases your front line currently handles with the most latitude.

No transposition window

One procedural point changes the planning horizon. Because this is a regulation rather than a directive, it applies directly in every member state from the same date. There is no national implementation act to wait for, no local variation to interpret, and no period during which the position differs across your European entities.

Firms accustomed to the directive rhythm have generally planned against national transposition dates, which arrive at different times and give a natural sequencing to multi-country rollouts. That sequencing is not available here.

The UK position

The United Kingdom is outside the Regulation, and section 333A of the Proceeds of Crime Act 2002 is unaffected by it. The UK prohibition continues to attach to disclosing that a report has been made and to disclosing that an investigation is being considered or carried out.

Two situations still bring UK firms into contact with the change. A UK group with EU subsidiaries or branches will have entities directly in scope, and running two customer communication standards across one group is a poor outcome. And a UK firm serving EU customers through an EU entity is applying the Regulation to those relationships whatever the position at home.

The practical answer for most groups is to write to the stricter standard once. The wording that satisfies Article 73 also satisfies section 333A, and the reverse is not reliably true.

What to do in the next ten months

  1. Find the wording that depends on the escalation boundary. Search your response templates, macros and knowledge base for language that treats an ordinary check differently from an escalated matter. That is the language that has to converge.
  2. Decide the single standard now. One formula for delay, one for closure, one for document requests, applied whatever stage the case has reached. This removes the consistency signal at the same time as it prepares for the Regulation.
  3. Tell the front line what changed and why. The people writing these sentences are not lawyers, and “a review is now a protected fact” is a sentence they can hold and apply.
  4. Write down the dissuasion position. Article 73(6) resolves a question many firms have been cautious about, and the caution outlives the rule unless somebody records the change.
  5. Audit a real sample. Take fifty delay replies and fifty closure letters from the last quarter and mark them against the standard you have just agreed. The gap you find is the size of the job.

Where a pre-send check fits

A change of this kind fails in a predictable way. The policy is updated, the training is delivered, and the wording in the templates converges. Then somebody replies outside a template, at speed, to a customer who has asked three times, and writes the sentence the standard was designed to prevent.

Our pre-send check works on that gap. It reads the draft in Outlook or Gmail and flags a disclosing construction while the sentence is still open, which is the last moment the answer can change. It does not decide whether to file, it does not read your case management system, and it is no substitute for agreeing the standard in the first place.

We have written the standard itself into a free ten-page pack: four moments, twenty-two wording pairs each with the reasoning behind it, and a printable desk card. Get the SAR-safe wording pack.

The takeaway

Put 10 July 2027 in the compliance plan with a specific line item for customer communication wording, separate from the beneficial ownership and registration work that will dominate the programme. The change is small in the text and large in the operating population it reaches, which is the combination that produces surprises. For the wording itself, see our guide to what you can tell a customer after filing a report.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← The control you believe is working