AMLR CONSULTATION
Know What To Change Before AMLR Applies
Shufti reviews how your identity, KYB, UBO, screening, monitoring and evidence workflows support the EU AMLR. You receive a technical capability and evidence-gap map, recommended assurance routes, a target workflow and a practical implementation roadmap.
Trusted By 2,000+ Clients Worldwide










AMLR: DATES, THRESHOLDS, ARTICLES
Navigate Through AMLR Regulation with Shufti
AMLR creates a harmonised EU baseline, but every obliged entity still has to translate legal text into working journeys. Which identification route fits each customer. How ownership is established. When a case moves to enhanced due diligence. What evidence a supervisor can actually retrieve.
| ITEM | KEY FIGURES | ARTICLE | QUALIFICATION |
|---|---|---|---|
| Application date, most provisions | 10 July 2027 | Article 90 | Applies directly across Member States |
| Application date, Professional football | 10 July 2029 | Article 90 | Clubs and agents, with possible Member State exemptions for lower-risk clubs |
| General Beneficial Ownership Threshold | 25% or more | Article 52 | Held directly or indirectly. Changed from the previous "more than 25%" formulation |
| Possible lower Ownership Threshold | To be determined | Article 52 | May be introduced for specified higher-risk categories by delegated act, following a Commission assessment due by 10 July 2029 |
| EU Cash-payment Ceiling | EUR 10,000 | Article 80 | Subject to lower national limits and defined exclusions |
| Occasional Cash transaction CDD Trigger | EUR 3,000 | Article 19(4) | At least identification and verification apply to certain occasional cash transactions. |
| Verification Routes | Two | Article 22 | Document-based, or eIDAS electronic identification at substantial or high assurance. Further specified by AMLA technical standards |
ONE ARCHITECTURE, EIGHT STAGES
AMLR Ready Across The Full Compliance Lifecycle
READINESS ROADMAP
A Phased Roadmap to AMLR Readiness by 10 July 2027
Foundation & Gap Identification
- Confirm which obliged-entity category applies and which workflows it touches
- Map identity, KYB, UBO, screening and monitoring journeys against the regulation
- Establish where evidence exists, where it is thin, and where it cannot be retrieved
Implementation & Remediation
- Configure identification so both permitted routes run on one integration
- Retrofit records to the mandatory data set and recalculate ownership at 25% or more
- Move refresh from a fixed calendar to risk-based and event-driven triggers
Final Validation & Assurance
- Run the target journey alongside the current one and compare outcomes
- Test evidence retrieval the way a supervisor would request it
- Re-check configuration against AMLA technical standards as they are adopted
CLEAR ACCOUNTABILITY
AMLR Compliance: Technology, Controls and Organisational Responsibility
SHUFTI SUPPORTS
- Reviewing the technical workflow and evidence architecture
- Recommending assurance routes and integration design
- Configuring identity, KYB, screening, monitoring and escalation workflows
- Providing verification results, alerts and audit records
- Supporting solution design, testing and implementation
YOUR ORGANISATION RETAINS
- Determining obliged entity status and legal interpretation
- Setting AML/CFT policies, risk appetite and methodology
- Approving customers and higher-risk relationships
- Investigating alerts and deciding whether to report suspicion
- Maintaining Governance, Training, Internal Controls And Regulator Engagement
Client Compliance
Decision
SECTOR IMPACT
The AMLR Rulebook Changes Different Workflows
Banking
WHAT CHANGES
Financial institutions have always been covered, but the rules were written into national law and each country read them differently. AMLR applies directly, so the checks you run in Germany and the checks you run in Ireland become the same checks.
WHAT SHUFTI DOES
Set your risk rules once and they apply in every market. ID, KYB, UBO and screening run in one place, and every check is saved.
Payments & Fintech
WHAT CHANGES
Simplified due diligence used to come with national options, and many onboarding flows were built on them. Those options go. Simplified checks now have to be justified by your own risk assessment, not by a local exemption.
WHAT SHUFTI DOES
Build one onboarding journey instead of one per country. When you apply lighter checks, the risk score that justified it is recorded.
Forex & Trading
WHAT CHANGES
For higher-risk clients you need to establish where the money came from and where the client’s wealth came from. These are two separate questions, and both need evidence you can show a supervisor.
WHAT SHUFTI DOES
Higher-risk clients are flagged automatically. Source-of-funds and source-of-wealth documents are collected and stored in the same file as the ID check.
Crypto & Digital Assets
WHAT CHANGES
Coverage widens from exchanges and custodial wallets to the full MiCA population. Anonymous accounts are prohibited, and transfers to self-hosted wallets have to be risk-assessed and mitigated rather than simply blocked or ignored.
WHAT SHUFTI DOES
Onboarding, screening and transaction monitoring run on one system. Wallet activity is linked to the verified person behind it.
Gaming
WHAT CHANGES
Due diligence is triggered at a defined transaction threshold rather than left to each market. Member States can exempt some gambling services, but never casinos and never services provided mainly online.
WHAT SHUFTI DOES
Age and ID checks at first deposit, done in seconds. Players are rescreened automatically for as long as the account stays open.
Crowdfunding
WHAT CHANGES
Crowdfunding platforms and intermediaries become obliged entities for the first time. Both sides of the platform count, so the business raising money and the person funding it each need checking.
WHAT SHUFTI DOES
Verify investors and businesses in the same flow. UBO checks are included, so you do not need a second provider for the company side.
High-Value Property Letting
WHAT CHANGES
Letting agents come into scope where the monthly rent reaches €10,000. Sales agents were already covered; lettings were not. For most agencies this is a compliance function that does not exist yet.
WHAT SHUFTI DOES
Check the tenant’s ID and the landlord’s ownership before the tenancy starts. Both are saved against the letting.
High-Value Goods
WHAT CHANGES
Traders whose regular business involves precious metals, stones or defined high-value goods are covered, alongside an EU-wide €10,000 cash limit and reporting on items such as vehicles, watercraft and aircraft.
WHAT SHUFTI DOES
Verify a buyer at the counter in seconds with Fast ID. Sanctions and PEP checks run before you take payment.
Cultural Goods
WHAT CHANGES
Dealers and intermediaries are covered from €10,000, and linked transactions count towards that figure. Activity through free zones and customs warehouses is included rather than excluded.
WHAT SHUFTI DOES
Verify buyer and seller, check company ownership, run screening. Linked transactions are stored together under one record.
Investment Migration
WHAT CHANGES
Operators arranging residence or citizenship by investment are named in the regulation. Their applicants carry a minimum set of enhanced checks by default, rather than only when something looks unusual.
WHAT SHUFTI DOES
Every applicant gets enhanced checks by default: ID, source of funds, screening. The decision and what it was based on are saved.
Non-Bank Credit
WHAT CHANGES
Mortgage and consumer credit intermediaries become obliged entities in their own right. You can no longer rely on the lender behind the deal to have done the checks.
WHAT SHUFTI DOES
Run borrower and business checks in your own flow. You hold the evidence, not the lender.
ASSESS, DESIGN, IMPLEMENT
One Team From Current-State Review To Production
Both Identification Routes On One Integration
Article 22 permits document-based verification supported by reliable and independent sources, or eIDAS electronic identification at substantial or high assurance. Shufti operates document, NFC, biometric, electronic identification and agent-assisted routes through one integration, and records which route was used for each customer.
Deployment And Residency Options
Cloud, private-cloud and on-premise deployment where available for the product and target region, which matters for DORA-covered entities assessing concentration and exit risk. Security, privacy and biometric-testing credentials are provided during vendor due diligence.
One Record, Retrieved Not Reconstructed
Identity, business, screening, monitoring and reviewer evidence link to a single customer or business record, so the decision chain is retrieved on request rather than assembled after the fact.
Your Policy In A Configuration Layer
Rules, thresholds, evidence requirements and escalation paths are exposed as configuration, so your compliance team changes policy without a rebuild of every market journey.
EVERYTHING YOU NEED TO KNOW IN ONE PLACE
Frequently Asked Questions
A review of your current identity, KYB, UBO, screening, monitoring and evidence workflows, followed by a technical capability map, an evidence-gap map, recommended assurance routes, a target workflow design and a phased implementation roadmap.
Neither. It is a technical and workflow assessment. Determining obliged entity status, interpreting the Regulation and setting AML/CFT policy remain with your organisation and its advisers.
No. Article 22 provides two routes: an identity document, passport or equivalent supported where relevant by reliable and independent sources, or eIDAS electronic identification at substantial or high assurance with relevant qualified trust services. These are alternatives, not a hierarchy. Some commentary implies electronic identification is mandatory. It is not. Future AMLA technical standards will further specify acceptable sources and attributes, so build route flexibility rather than forcing every customer through one method.
A fixed annual cycle is not what the Regulation asks for. AMLR requires ongoing monitoring of the business relationship and requires customer documents, data and information to be kept up to date, with the frequency and depth of review driven by risk and material events rather than a single calendar date.
Not currently. The general threshold is 25% or more, held directly or indirectly. A lower threshold may be introduced for specified higher-risk categories through delegated acts, following a Commission assessment due by 10 July 2029. No lower threshold is scheduled, so keep thresholds configurable rather than hard-coded.
Yes. The review spans individual identity journeys, legal-entity verification, ownership and control mapping, screening of both populations, and the monitoring and evidence layers that sit across them.
Your compliance team. Shufti provides verification results, screening alerts, risk context and the audit record. Approving a customer, accepting a higher-risk relationship and deciding whether to report suspicion remain yours.
You receive the capability map, evidence-gap map, target workflow and roadmap. If you proceed, the same team supports configuration, testing and rollout through to production.
Know What To Change Before 10 July 2027
Bring your current identity, KYB, screening, monitoring and evidence setup. Shufti maps the technical gaps, recommends the target journey and defines a practical route to implementation.