Arachne+ is the European Commission’s corporate data-mining and risk-scoring tool designed to help detect and prevent fraud, conflicts of interest, and irregularities affecting the EU budget.
It builds on the existing Arachne (legacy system) by enhancing how data is collected, analysed, and used. The tool supports EU institutions, Member States, and implementing partners in identifying higher-risk projects, beneficiaries, contracts, and contractors, enabling more targeted and efficient controls.
From the next Multiannual Financial Framework (2028–2034), Member States will be required to provide data to Arachne+. This obligation concerns making relevant operational data related to EU-funded programmes available, enabling the tool to perform consistent and effective risk analysis across all funds and management modes. The mandatory use of the tool will be reassessed following an assessment of the readiness with respect to key criteria: interoperability, risk indicators, data protection and artificial intelligence.
Arachne+ supports risk-based decision-making; it does not make automatic decisions. The tool is planned to be released in its full version by the end of 2027.
What’s new in Arachne+?
Arachne+ will improve the legacy system by:
- Covering all EU funds and management modes (shared, direct and indirect)
- Simplifying risk analysis through a reduced and more targeted set of indicators
- Enhancing usability with a more streamlined and user-friendly approach
- Ensuring strong data protection safeguards, under the supervision of the European Data Protection Supervisor (EDPS)
Between 28 April and 30 June 2026, Arachne+ gradually replaced the legacy Arachne system, with the objective of becoming, by the end of 2027, the Commission's single corporate tool for fraud-risk analysis across EU funding programmes.
Key features
- Risk-based decision support: identifies anomalies in procurement, eligibility, reputational risk, and fund concentration
- Smart data integration: combines structured and unstructured data from multiple sources
- AI-ready design: prepared for future integration of artificial intelligence
- Interoperability-first approach: enables cooperation with national and EU systems (e.g. EDES, IMS)
- Secure and compliant: aligned with EU data protection and security standards
Key benefits
Arachne+ helps national authorities and EU institutions to:
- Comply with regulatory requirements on risk-based management
- Improve the targeting of audits and controls
- Reduce administrative burden through automation and data integration
- Access a centralised, cross-programme risk analysis tool
- Strengthen fraud prevention through better use of data
- Benefit from a system fully maintained by the European Commission
How does Arachne+ work?
Arachne+ combines data from multiple sources:
1. Operational data
Provided by EU institutions and the Member States, including:
- Information on beneficiaries, contractors, and project partners
- Contract data and financial flows
- Data on beneficial ownership
2. External data
Provided by specialised sources such as:
- Orbis (company ownership, financial data, corporate structures)
- World Compliance (sanctions lists, politically exposed persons, adverse media)
The system applies predefined risk rules to generate a risk score for an entity or a project.
Data protection and safeguards
Arachne+ operates under a robust EU legal and data protection framework.
- It is designed only as a support to decision-making, not to automate decisions
- There is no automatic decision
- It is developed in cooperation with the Data Protection Officer (DPO) and the European Data Protection Supervisor (EDPS)
- It complies with the applicable EU data protection rules (Regulation (EU) 2018/1725)
- Only relevant and necessary data is processed, including identification and contact details of individuals and entities involved in EU-funded activities and financial and contractual information
How is the risk calculated?
Operational data is provided by the EU institutions and the Member States. This data is enriched with information from an external provider, Moody’s Analytics. This provider gives access to Orbis and World Compliance to identify patterns and risks.
Arachne+ applies a series of pre-defined risk indicators to generate a risk score for each project, contract, beneficiary or entity. The tool is designed to support risk-based decision-making, not to trigger automatic decisions.
What kind of information is processed?
Arachne+ processes information from two main sources:
1. From national authorities and EU services
- Beneficiaries, contractors, project partners: name, date of birth, VAT number, address, turnover, roles
- Contractors, sub-contractors, project partners, service providers, consortium members: name, address, VAT number
- Key experts for service contracts: name, date of birth
- Data on final beneficial owner data (FBO) of beneficiaries, contractors and subcontractors: name, date of birth
- Contract details and financial flows
2. From external data sources:
- Orbis: company ownership, financials, structure, ultimate beneficial owners (UBO)
- World Compliance: PEP profiles, sanctions list, enforcement actions, adverse media
What is the legal basis?
The legal basis for Arachne+ is set out in:
- Article 36(6) of the Financial Regulation (Regulation (EU, Euratom) 2024/2509 of the European Parliament and of the Council of 23 September 2024 on the financial rules applicable to the general budget of the Union (recast)), which foresees the establishment of a corporate IT tool for data-mining and risk-scoring in all management modes
- Articles 310, 317 and 325 of the Treaty on the Functioning of the European Union (TFEU), which oblige the Commission and the Member States to counter fraud and any illegal activity affecting the EU’s financial interests
- These provisions ensure Arachne+ operates under a solid and future-proof legal framework, balancing transparency, effectiveness, and fundamental rights, including the protection of personal data. It establishes that by the end of 2027, the Commission shall present an Assessment of the Readiness covering:
- Interoperability with relevant IT systems and databases
- Targeted and proportionate risk indicators
- Use of artificial intelligence
- Compliance with EU data protection rules, in line with Regulation (EU) 2018/1725
In addition, the Joint Declaration of 7 December 2023 by the European Parliament, the Council, and the Commission, which states that the use of Arachne+ will be reassessed based on the readiness of the tool by the end of 2027.
Summary
| Current Arachne | Arachne+ | |
| Scope | Shared management, and some RRF funds | All funds, all management mode |
| Risk indicators | 107 | Reduced, targeted 78 risk indicators |
| Interoperability | Limited | Scalable |
| Providing data | Voluntary | Mandatory as from 2028 |
| Use | Voluntary | Voluntary* |
*Use of Arachne+ will be reassessed in 2028 based on the four readiness criteria outlined above.