The European Banking Authority has published a clear assessment of money laundering and terrorist financing (ML/TF) risks in its latest report (EBA/Op/2025/10). For FinTech companies, including EMIs and Payment Institutions operating in the Netherlands and across the EU, this Opinion provides both a reality check and a guide for improving compliance systems.
The FinTech challenge: Growth vs compliance
The Opinion’s most important finding should concern every FinTech executive: 70% of competent authorities report high or rising ML/TF risks in the financial sector, with weak AML/CFT controls and poor governance being the main problems. The EBA clearly states that firms appear to focus on growth over compliance—a common issue in the FinTech space where getting to market quickly often conflicts with regulatory requirements.
This is especially relevant for EMIs and PSPs, where business models based on high transaction volumes and fast customer onboarding can create serious compliance gaps. The pressure to grow quickly while keeping operations lean has clearly gotten the attention of supervisors across Europe.
Technology: Solution or problem?
The Opinion shows a worrying contradiction in regulatory technology use. While RegTech promises better compliance capabilities, over half of serious compliance failures reported to the EBA’s database involved incorrect use of RegTech tools. This finding challenges the industry’s belief that technology solutions automatically improve compliance results.
For companies that have invested heavily in automated compliance systems, this should lead to serious questions about implementation quality, staff training, and ongoing oversight. Technology without proper human oversight and expertise appears to be creating new problems rather than solving existing ones.
Crypto assets: Still high-risk
The 2.5-fold increase in authorised crypto-asset service providers between 2022 and 2024 shows the sector’s rapid growth, but the EBA still considers crypto assets as high-risk. Many CASPs continue to lack effective AML/CFT systems, with some trying to avoid regulatory oversight completely.
For FinTech companies expanding into crypto services or partnering with CASPs, stronger due diligence and monitoring systems are essential. The ongoing MiCAR implementation adds another layer of complexity that needs careful handling.
AI and changing criminal methods
Perhaps most concerning is the EBA’s observation that criminals are increasingly using AI to automate laundering schemes, forge documents, and avoid detection. Financial institutions are struggling to keep up with these advanced threats, showing a critical competition between compliance technology and criminal innovation.
Practical recommendations for FinTech companies
Based on this Opinion, I recommend Fintech companies take the following steps:
1. Combine strong professionals with RegTech tools Don’t assume your automated systems work perfectly on their own. Review your RegTech tools regularly, focusing on configuration accuracy and alert quality. Most importantly, invest in skilled compliance personnel who can provide proper oversight of automated systems and understand their outputs. Technology and human expertise must work together—one cannot replace the other.
2. Balance growth and compliance properly Create clear governance frameworks that prevent compliance from being sacrificed for growth targets. Include compliance metrics as key performance indicators alongside traditional business metrics. Make compliance part of your business strategy, not an afterthought.
3. Prepare for AI threats Develop monitoring capabilities that can identify AI-generated fraud attempts and forged documents. Think about how criminals might exploit your specific business model using AI tools. This is an ongoing challenge that requires continuous attention.
Looking forward
The Opinion shows that 2025 is an important year for AML/CFT compliance in the EU. With AMLA taking over standalone AML/CFT powers from the EBA by year-end and new Guidelines coming into effect, FinTech companies face a period of significant regulatory change.
The message is clear: sustainable growth in the FinTech space requires mature compliance frameworks that can develop with both regulatory expectations and criminal innovation. Companies that continue to treat compliance as an afterthought are taking serious risks.
For EMIs and PSPs, the path forward involves treating compliance as a competitive advantage rather than just a regulatory burden. In an increasingly complex risk environment, strong AML/CFT capabilities will become a key differentiator for long-term business success.
For specific compliance guidance tailored to your business model, professional legal advice should be sought.
Would you like to discuss this further, get in touch Bauke through our contact page.