AMLR READINESS
AMLR Compliance: From Obligation To Evidence, On One Platform
AMLR is Regulation (EU) 2024/1624, the EU's single anti-money laundering rulebook. It applies directly from 10 July 2027, replaces the 2015 Directive, and removes the national variation firms have built around. Shufti maps every obligation it creates to a product already in production, and states plainly what remains your decision.
Book a Demo
Trusted by 2,000+ Clients Worldwide
HOW SHUFTI SOLVES IT
Compliant Under The Directives, Exposed Under AMLR
One Rulebook Replaces Twenty-Seven
National discretion is gone and thresholds are set at Union level. A programme built around per-market variation has to be rebuilt around one standard.
Ownership Alone No Longer Identifies the Owner
Control is assessed alongside ownership, and both sets can be beneficial owners at once. Nominees must be flagged and register consultation becomes mandatory.
Review Intervals Become Hard Caps
Higher risk at least annually, everyone else at least every five years. Absolute ceilings, no risk-based exemption, applied across the whole book at once.
Retention Becomes a Deletion Duty
Five years from the end of the relationship, then personal data must be deleted. Holding it longer is not caution, it is a breach.
REQUIREMENT TO CAPABILITY
Use What You Need Without Fragmenting The Evidence
Remote Onboarding With The Proof Built In
The old rules treated signing someone up online as higher risk on its own. AMLR does not, and it accepts an ID document or a national eID as equally valid. Shufti runs both on one integration and records which one each customer used.
The route that needs no national scheme. Verifies identity from documents obtained from a reliable and independent source, the first of the two means Article 22(6) permits.
The second permitted means, where the scheme exists. Electronic identification at assurance level substantial or high. Shufti connects to 40+ national eID schemes worldwide and falls back to documents where coverage is thin.
The second permitted means, where the scheme exists. Electronic identification at assurance level substantial or high. Shufti connects to 40+ national eID schemes worldwide and falls back to documents where coverage is thin.
The attribute a wallet does not guarantee. Usual place of residence is part of the information Article 22(1) requires, established from documentary proof rather than self-declaration.
Authenticity proven, not inferred. Reads the chip and validates its signature against the issuing authority, so the document stands as a reliable and independent source rather than a good photograph.
The document belongs to the person presenting it. Matches the live subject to the document portrait with certified passive liveness, so identity attaches to the customer and not to the credential alone.
See Who Controls, Not Just Who Owns
Holding 25% is no longer the only way to be a beneficial owner. Whoever controls the company counts too, and AMLR wants both checked separately. Shufti resolves the shareholding and the control layer in one request.
Resolves the ownership chain and the control layer in parallel, so both sets of beneficial owners surface from one request.
The entity and its owners in one call. Screens the legal entity and every beneficial owner identified under Article 51, so the corporate record and the person record share one evidence trail.
Two sources, separately evidenced. Source of funds and source of wealth become distinct requirements, with senior management approval recorded before the business relationship is entered into.
Accreditation and identity in one record. Applies customer due diligence measures to the subscribing investor, rather than running suitability and identity in two separate systems.
Nominees do not declare themselves. Surfaces the nominee arrangements and informal agreements between connected parties that Article 53 treats as control via other means.
Never Wait For The Next Review
Every customer now has a deadline for their next review: one year for higher risk, five years for everyone else, with no exceptions. Shufti rescreens continuously, so a sanctions hit does not wait for the review date.
Screening inside the due diligence call. Targeted financial sanctions, politically exposed persons and adverse media in one check, applied when the relationship is entered into and throughout its course.
A designation should not wait for a review. Global and regional lists refreshed continuously, so a listing reaches the customer record without waiting for the next scheduled review.
The associates count as much as the principal. Covers politically exposed persons, family members and persons known to be close associates, using the categories AMLR itself defines.
A name match is not a finding. Media screening resolved to the customer, so an alert tests the obliged entity’s knowledge of the customer rather than a name string.
The interval is a ceiling, not a target. Keeps transactions consistent with the customer’s business activity and risk profile, and enforces the review interval that applies to each risk level.
One Record When The Regulator Asks
Evidence spread across three vendors becomes the audit finding on its own. Shufti keeps every verification in one record, and says plainly which decisions you are not allowed to hand to a vendor at all.
Behaviour tested against the risk profile. Detects transactions inconsistent with the obliged entity’s knowledge of the customer, the customer’s business activity and risk profile.
Five years, then deletion is the duty. Records retained for five years after the business relationship ends, then personal data deleted. Holding it longer is a breach unless a competent authority requires otherwise.
Policy changes without an engineering ticket. Compliance teams move thresholds and review intervals themselves, and every change is recorded against the journey.
Evidence assembled, determination retained. Assembles the evidence behind an alert for the reviewer. The determination stays with the compliance officer, which Article 18(3) does not permit an obliged entity to outsource.
Residency answered before procurement asks. Cloud, on-premises, hybrid or offsite with identical capability, so residency and third-party controls are documented up front.
NEW UNDER AMLR
What AMLR Introduces,
And What You Get With Shufti
Remote Onboarding, Without A Risk Penalty
The non-face-to-face higher-risk factor from the 2015 Directive has no counterpart in AMLR, so remote verification runs under the general risk-based approach. Shufti's journeys are remote by design and evidenced end to end.
EID At The Assurance Level The Regulation Names
Electronic identification at level substantial or high is one of two permitted verification routes. Shufti checks against authoritative registries where national coverage supports it, and routes to document verification where it does not.
Qualified Trust Services And QES
Qualified signatures and trust services sit in the same provision as electronic identification. Shufti supports qualified electronic signature inside the verification journey, so declarations and attestations are signed without leaving the flow.
QEAA For The Attributes A Wallet Does Not Carry
Qualified electronic attestations of attributes cover address and other data verifiable against authentic sources from December 2026. They are a separate mechanism from the wallet's core identity dataset, and they are how the gaps in it get filled.
EUDI Wallet, Accepted For What It Carries
Identity attributes presented from a wallet are accepted as presented. Usual place of residence is optional in the wallet's mandatory dataset and mandatory under AMLR, so Shufti obtains it by other means rather than assuming the wallet supplies it.
Live Register Consultation, Now Mandatory
Consulting the central beneficial ownership register becomes a required additional check rather than an alternative to your own verification. Shufti queries 240+ official registries live at every request.
EVERYTHING YOU NEED TO KNOW IN ONE PLACE
Frequently Asked Questions
Regulation (EU) 2024/1624 applies from 10 July 2027, when the 2015 Directive is repealed. Some parts of the package already bind, including the crypto travel rule since December 2024 and register access since July 2026.
AMLR is a regulation and applies directly in every Member State. AMLD6 is a directive covering registers, supervision and national authorities, so it must be transposed. AMLA is the new EU authority in Frankfurt, which writes the technical standards and will directly supervise selected financial institutions.
No. The threshold is 25% or more. The 15% is the maximum depth of a possible future delegated act for specified higher-risk sectors, which the Commission must assess by 10 July 2029. No such act exists.
The obligation comes from eIDAS rather than AMLR, applies from 24 December 2027, and only where strong user authentication is already required, excluding micro and small enterprises, and only when the customer asks to use their wallet. AMLR itself never mentions the Wallet.
Not on its own. The Wallet's mandatory identity data is five attributes and usual place of residence is not one of them, while AMLR requires it. Residence has to be obtained by other means, such as a qualified electronic attestation of attributes or documentary verification.
Yes, and the non-face-to-face higher-risk factor from the 2015 Directive has no counterpart in AMLR. Remote channels fall under the general risk-based approach, though the EBA remote onboarding guidelines remain applicable until AMLA replaces them.
At least annually for higher-risk customers and at least every five years for everyone else. These are absolute ceilings rather than risk-based defaults, and event-driven review applies on top of them.
Verification, screening, monitoring and evidence assembly can be outsourced. Six decisions cannot, including the customer risk profile, the decision to enter a relationship and reporting to the Financial Intelligence Unit. Your supervisor must also be notified before a provider begins.
Five years from the end of the relationship, the occasional transaction or the refusal, after which personal data must be deleted. Extension is possible only case by case at a competent authority's request, capped at five further years.
Not yet. As at late July 2026 no standard had been adopted by the Commission or published in the Official Journal, including the customer due diligence standard whose consultation closed in May 2026. This page describes drafts as drafts.
Evaluate Your Stack Against Every AMLR Obligation
Most firms are compliant under the directives and assume that carries over. Some of it does. Book a review and we will walk your programme against the matrix, obligation by obligation, including the ones that are not ours to solve.