The EU Anti-Money Laundering package, adopted in May 2024, is not a theoretical reform.
It is a direct response to supervisory failures observed over recent years among fast-growing, digital-first institutions.
The message from regulators is now explicit:
digital-first does not mean AML-light.
With the introduction of the Anti-Money Laundering Regulation (AMLR), directly applicable across all EU Member States:
— AML requirements are fully harmonised
— the risk-based approach applies regardless of automated or remote onboarding
— outsourcing AML does not transfer accountability away from management
👉 In practice, neobanks are assessed like banks, based on their actual risk exposure.
A concrete example: N26
— customer growth cap imposed by BaFin in 2021
— restriction maintained for almost three years
— partially lifted only in April 2024, after significant AML remediation
👉 Growth was not constrained by capital or liquidity — but by AML capacity.
This supervisory logic is now embedded into EU-wide law.
Regulatory arbitrage between traditional banks and digital players is rapidly disappearing.
For neobanks, the real challenge is execution at scale:
— aligning customer acquisition speed with AML scalability
— operating automated controls that are explainable, auditable and supervisor-ready
— embedding AML upstream, in product design and governance
AML is no longer just a control function.
It is becoming a structural growth constraint — and a key credibility differentiator.
The question is no longer how fast a neobank can grow,
but how fast it can grow while continuously demonstrating effective AML control.

Très juste. La nouvelle réglementation AML européenne consacre une réalité : pour les neobanks, la croissance dépend désormais de leur capacité à démontrer des contrôles AML solides et scalables. Ce n’est plus un sujet de business model, mais de gouvernance et d’exécution opérationnelle. Les acteurs capables d’intégrer l’AML au cœur du produit seront les seuls à pouvoir croître durablement.
Interessant