us

216.73.216.226

AMLR CONSULTATION

Know What To Change Before AMLR Applies

Shufti reviews how your identity, KYB, UBO, screening, monitoring and evidence workflows support the EU AMLR. You receive a technical capability and evidence-gap map, recommended assurance routes, a target workflow and a practical implementation roadmap.

AMLR workflow readiness consultation: current workflow review, technical capability map, evidence-gap map, assurance route and target workflow

Trusted By 2,000+ Clients Worldwide

cashew-2gemone-1heroo-1image 299ironFX-1-1penn-1Rokuten-1witzeal-logo 1Noteris-Logo 1cashew-2gemone-1heroo-1image 299ironFX-1-1penn-1Rokuten-1witzeal-logo 1Noteris-Logo 1

AMLR: DATES, THRESHOLDS, ARTICLES

Navigate Through AMLR Regulation with Shufti

AMLR creates a harmonised EU baseline, but every obliged entity still has to translate legal text into working journeys. Which identification route fits each customer. How ownership is established. When a case moves to enhanced due diligence. What evidence a supervisor can actually retrieve.

ITEMKEY FIGURESARTICLEQUALIFICATION
Application date, most provisions10 July 2027Article 90Applies directly across Member States
Application date, Professional football10 July 2029Article 90Clubs and agents, with possible Member State exemptions for lower-risk clubs
General Beneficial Ownership Threshold25% or moreArticle 52Held directly or indirectly. Changed from the previous "more than 25%" formulation
Possible lower Ownership ThresholdTo be determinedArticle 52May be introduced for specified higher-risk categories by delegated act, following a Commission assessment due by 10 July 2029
EU Cash-payment CeilingEUR 10,000Article 80Subject to lower national limits and defined exclusions
Occasional Cash transaction CDD TriggerEUR 3,000Article 19(4)At least identification and verification apply to certain occasional cash transactions.
Verification RoutesTwoArticle 22Document-based, or eIDAS electronic identification at substantial or high assurance. Further specified by AMLA technical standards

ONE ARCHITECTURE, EIGHT STAGES

AMLR Ready Across The Full Compliance Lifecycle

01STAGE
Article 20

Pre-Journey Risk Context

Market, product, customer type and channel determine the starting path before any check runs.

EVIDENCE CAPTURED

Risk inputs, applied thresholds, routing decision and rule version

Journey BuilderRisk Assesment
02STAGE
Article 22

Identity Route

Document and NFC, supported eID, VideoIdent or another route permitted by your policy and applicable requirements.

EVIDENCE CAPTURED

Method used, sources relied on, check results and timestamps

03STAGE
Article 22, 52

Business And Ownership

Verify legal-entity details, map ownership and control through layered structures, then identify and verify the relevant person.

EVIDENCE CAPTURED

Registry sources, ownership calculation, control relationships and verified persons

KYBUBO Verification
04STAGE
Article 22, 26

Screening

Screen customers, businesses and owners against sanctions, PEP and relevant risk data at onboarding and during the relationship.

EVIDENCE CAPTURED

Screening runs, match context, review outcomes and alert history

05STAGE
Articles 20, 34

Due Diligence Path

Apply standard, simplified or enhanced measures based on configured risk, with thresholds owned by your compliance team.

EVIDENCE CAPTURED

Applied measures, evidence collected and the diligence path taken

Due DiligenceRisk Assessment
06STAGE
Customer Decides

Client Compliance Decision

Your authorised compliance team reviews exceptions, higher-risk cases and approval conditions.

EVIDENCE CAPTURED

Reviewer actions, decision, rationale and timestamps

Case ManagementManual Review
07STAGE
Article 26

Ongoing Monitoring

Rescreen, refresh information and monitor activity at a risk-based cadence, with event-driven rechecks between scheduled runs.

EVIDENCE CAPTURED

Refresh events, triggers, rechecks and alert history

08STAGE
Article 22, 52

Evidence Record

Retain sources, decisions, actions and timestamps as one connected history against the same record.

EVIDENCE CAPTURED

The full connected decision chain, retrievable by customer or business record

Audit TrailEvidence Exports

READINESS ROADMAP

A Phased Roadmap to AMLR Readiness by 10 July 2027

Foundation & Gap Identification

  • Confirm which obliged-entity category applies and which workflows it touches
  • Map identity, KYB, UBO, screening and monitoring journeys against the regulation
  • Establish where evidence exists, where it is thin, and where it cannot be retrieved

Implementation & Remediation

  • Configure identification so both permitted routes run on one integration
  • Retrofit records to the mandatory data set and recalculate ownership at 25% or more
  • Move refresh from a fixed calendar to risk-based and event-driven triggers

Final Validation & Assurance

  • Run the target journey alongside the current one and compare outcomes
  • Test evidence retrieval the way a supervisor would request it
  • Re-check configuration against AMLA technical standards as they are adopted

CLEAR ACCOUNTABILITY

AMLR Compliance: Technology, Controls and Organisational Responsibility

SHUFTI SUPPORTS

  • Reviewing the technical workflow and evidence architecture
  • Recommending assurance routes and integration design
  • Configuring identity, KYB, screening, monitoring and escalation workflows
  • Providing verification results, alerts and audit records
  • Supporting solution design, testing and implementation

YOUR ORGANISATION RETAINS

  • Determining obliged entity status and legal interpretation
  • Setting AML/CFT policies, risk appetite and methodology
  • Approving customers and higher-risk relationships
  • Investigating alerts and deciding whether to report suspicion
  • Maintaining Governance, Training, Internal Controls And Regulator Engagement
Shufti

Client Compliance
Decision

SECTOR IMPACT

The AMLR Rulebook Changes Different Workflows

AMLR Art 3(1) · Art 20–22

Banking

WHAT CHANGES

Financial institutions have always been covered, but the rules were written into national law and each country read them differently. AMLR applies directly, so the checks you run in Germany and the checks you run in Ireland become the same checks.

WHAT SHUFTI DOES

Set your risk rules once and they apply in every market. ID, KYB, UBO and screening run in one place, and every check is saved.

AMLR Art 3(2) · Art 33

Payments & Fintech

WHAT CHANGES

Simplified due diligence used to come with national options, and many onboarding flows were built on them. Those options go. Simplified checks now have to be justified by your own risk assessment, not by a local exemption.

WHAT SHUFTI DOES

Build one onboarding journey instead of one per country. When you apply lighter checks, the risk score that justified it is recorded.

AMLR Art 3(2) · Art 34

Forex & Trading

WHAT CHANGES

For higher-risk clients you need to establish where the money came from and where the client’s wealth came from. These are two separate questions, and both need evidence you can show a supervisor.

WHAT SHUFTI DOES

Higher-risk clients are flagged automatically. Source-of-funds and source-of-wealth documents are collected and stored in the same file as the ID check.

AMLR Art 3 · Art 40

Crypto & Digital Assets

WHAT CHANGES

Coverage widens from exchanges and custodial wallets to the full MiCA population. Anonymous accounts are prohibited, and transfers to self-hosted wallets have to be risk-assessed and mitigated rather than simply blocked or ignored.

WHAT SHUFTI DOES

Onboarding, screening and transaction monitoring run on one system. Wallet activity is linked to the verified person behind it.

AMLR Art 3 · Art 19

Gaming

WHAT CHANGES

Due diligence is triggered at a defined transaction threshold rather than left to each market. Member States can exempt some gambling services, but never casinos and never services provided mainly online.

WHAT SHUFTI DOES

Age and ID checks at first deposit, done in seconds. Players are rescreened automatically for as long as the account stays open.

AMLR Art 3(3)(h)

Crowdfunding

WHAT CHANGES

Crowdfunding platforms and intermediaries become obliged entities for the first time. Both sides of the platform count, so the business raising money and the person funding it each need checking.

WHAT SHUFTI DOES

Verify investors and businesses in the same flow. UBO checks are included, so you do not need a second provider for the company side.

AMLR Art 3(3) · letting

High-Value Property Letting

WHAT CHANGES

Letting agents come into scope where the monthly rent reaches €10,000. Sales agents were already covered; lettings were not. For most agencies this is a compliance function that does not exist yet.

WHAT SHUFTI DOES

Check the tenant’s ID and the landlord’s ownership before the tenancy starts. Both are saved against the letting.

AMLR Art 3(3) · goods

High-Value Goods

WHAT CHANGES

Traders whose regular business involves precious metals, stones or defined high-value goods are covered, alongside an EU-wide €10,000 cash limit and reporting on items such as vehicles, watercraft and aircraft.

WHAT SHUFTI DOES

Verify a buyer at the counter in seconds with Fast ID. Sanctions and PEP checks run before you take payment.

AMLR Art 3(3) · cultural goods

Cultural Goods

WHAT CHANGES

Dealers and intermediaries are covered from €10,000, and linked transactions count towards that figure. Activity through free zones and customs warehouses is included rather than excluded.

WHAT SHUFTI DOES

Verify buyer and seller, check company ownership, run screening. Linked transactions are stored together under one record.

AMLR Art 3(3) · Art 34

Investment Migration

WHAT CHANGES

Operators arranging residence or citizenship by investment are named in the regulation. Their applicants carry a minimum set of enhanced checks by default, rather than only when something looks unusual.

WHAT SHUFTI DOES

Every applicant gets enhanced checks by default: ID, source of funds, screening. The decision and what it was based on are saved.

AMLR Art 3(2) · credit intermediaries

Non-Bank Credit

WHAT CHANGES

Mortgage and consumer credit intermediaries become obliged entities in their own right. You can no longer rely on the lender behind the deal to have done the checks.

WHAT SHUFTI DOES

Run borrower and business checks in your own flow. You hold the evidence, not the lender.

ASSESS, DESIGN, IMPLEMENT

One Team From Current-State Review To Production

Both Identification Routes On One Integration

Article 22 permits document-based verification supported by reliable and independent sources, or eIDAS electronic identification at substantial or high assurance. Shufti operates document, NFC, biometric, electronic identification and agent-assisted routes through one integration, and records which route was used for each customer.

Deployment And Residency Options

Cloud, private-cloud and on-premise deployment where available for the product and target region, which matters for DORA-covered entities assessing concentration and exit risk. Security, privacy and biometric-testing credentials are provided during vendor due diligence.

One Record, Retrieved Not Reconstructed

Identity, business, screening, monitoring and reviewer evidence link to a single customer or business record, so the decision chain is retrieved on request rather than assembled after the fact.

Your Policy In A Configuration Layer

Rules, thresholds, evidence requirements and escalation paths are exposed as configuration, so your compliance team changes policy without a rebuild of every market journey.

EVERYTHING YOU NEED TO KNOW IN ONE PLACE

Frequently Asked Questions

A review of your current identity, KYB, UBO, screening, monitoring and evidence workflows, followed by a technical capability map, an evidence-gap map, recommended assurance routes, a target workflow design and a phased implementation roadmap.

Neither. It is a technical and workflow assessment. Determining obliged entity status, interpreting the Regulation and setting AML/CFT policy remain with your organisation and its advisers.

No. Article 22 provides two routes: an identity document, passport or equivalent supported where relevant by reliable and independent sources, or eIDAS electronic identification at substantial or high assurance with relevant qualified trust services. These are alternatives, not a hierarchy. Some commentary implies electronic identification is mandatory. It is not. Future AMLA technical standards will further specify acceptable sources and attributes, so build route flexibility rather than forcing every customer through one method.

A fixed annual cycle is not what the Regulation asks for. AMLR requires ongoing monitoring of the business relationship and requires customer documents, data and information to be kept up to date, with the frequency and depth of review driven by risk and material events rather than a single calendar date.

Not currently. The general threshold is 25% or more, held directly or indirectly. A lower threshold may be introduced for specified higher-risk categories through delegated acts, following a Commission assessment due by 10 July 2029. No lower threshold is scheduled, so keep thresholds configurable rather than hard-coded.

Yes. The review spans individual identity journeys, legal-entity verification, ownership and control mapping, screening of both populations, and the monitoring and evidence layers that sit across them.

Your compliance team. Shufti provides verification results, screening alerts, risk context and the audit record. Approving a customer, accepting a higher-risk relationship and deciding whether to report suspicion remain yours.

You receive the capability map, evidence-gap map, target workflow and roadmap. If you proceed, the same team supports configuration, testing and rollout through to production.

Know What To Change Before 10 July 2027

Bring your current identity, KYB, screening, monitoring and evidence setup. Shufti maps the technical gaps, recommends the target journey and defines a practical route to implementation.