us

216.73.217.135

    Please complete the information below to download the whitepaper

    By clicking the "Submit" button, you are agreeing 
to the Terms & Conditions and Privacy Policy

    EU AMLR: The Complete EU Compliance Guide for 2027 — guide cover with the AMLR Rulebook held against the EU stars
    Shufti · Regulatory Guide

    EU AMLR: The Complete Guide to 2027 Compliance

    AMLR is final and in force, and most of it applies from 10 July 2027. For compliance teams working across EU markets, the question is not what the Regulation says, it is which of your existing controls it breaks. This guide walks the whole rulebook, separates what changed from what was already there, and cites the article behind every rule.

    Request a demo
    KEY TAKEAWAYS
    • The ownership threshold moved from "more than 25%" to "25% or more." A rule engine testing > 25 is wrong from 10 July 2027; it needs to be >= 25.
    • Ownership and control are now tested independently and in parallel, and control carries no percentage floor at all.
    • Deadlines got harder EU-wide: 28 days to update beneficial-ownership information, 14 days to report a register discrepancy, a hard 1–5 year customer refresh cap.
    • New EU-wide limits arrive: a €10,000 professional cash ceiling, €1,000 CDD trigger for crypto, and threshold reporting on high-value goods.
    • AMLA directly supervises only a small cohort: up to 40 entities at first, from 2028. Most obliged entities keep their existing national supervisor.
    • Football agents and clubs have until 10 July 2029, two years later than everyone else.
    Part IThe Regulation
    Section 01

    What is the EU AMLR?

    The EU Anti-Money Laundering Regulation, AMLR, is the European Union’s directly applicable rulebook for preventing money laundering and terrorist financing in the private sector. It tells banks, financial institutions, crypto-asset businesses and a wide range of professional and non-financial firms how to assess risk, perform customer due diligence, identify beneficial owners, monitor relationships and report suspicious activity.

    AMLR is the core of what the Commission calls the EU AML single rulebook. Where earlier EU law set common principles and left each Member State to write its own version, AMLR sets the obligations directly. National supervisors, financial intelligence units (FIUs), registers and a defined set of national options remain, but the requirements themselves no longer arrive through 27 separate transpositions.

    Most provisions apply from 10 July 2027.1

    Fig 01AMLR at a glanceOverview
    Formal instrumentRegulation (EU) 2024/1624
    Main application date10 July 2027
    Core purposeCommon EU AML/CFT requirements for obliged entities
    Key lifecycle dutiesCDD, KYC/KYB, ownership, screening, monitoring and reporting
    SupervisionPrimarily national with AMLA coordination and selected direct supervision

    Football is the one deferred sector, and it is narrower than it sounds

    Two obliged-entity categories apply from 10 July 2029 rather than 2027: football agents, and professional football clubs.1 2

    Clubs are not in scope for everything they do. They are obliged entities only for four transaction types: transactions with an investor, with a sponsor, with football agents or other intermediaries, and for the purpose of a player’s transfer.3

    Example

    A top-division club selling season tickets to supporters is not acting as an obliged entity. The same club paying commission to an agent on a player transfer is, because that payment falls inside two of the four listed types at once.

    Member States may also exempt clubs entirely or partly, by two separate routes. Top-division clubs qualify where total annual turnover was under EUR 5,000,000 in each of the previous two calendar years. Clubs in any lower division qualify with no turnover threshold at all. Both routes require a documented Member State risk assessment and are optional, not automatic.4

    Preventive law

    AMLR mandates measures that help businesses prevent crimes like money laundering. It does not replace the criminal law used to investigate and prosecute them.

    Referenced in this section
    1 AMLR Art 90 2 AMLR Art 3(3)(n)-(o) 3 AMLR Art 3(3)(o) 4 AMLR Art 5(1)-(3)
    Section 02

    Why was AMLR introduced?

    Earlier EU directives created common principles, but each Member State implemented them through its own national AML regulations: different definitions, thresholds, supervision and operational expectations. A group operating in eight Member States maintained eight interpretations of the same rule.

    The Commission put numbers on that before it drafted AMLR. Its impact assessment for the AML package found most Member States setting the beneficial-ownership register threshold at 25%, with Latvia and Spain at 10%. It also found that national rules for calculating indirect ownership diverged far enough that the same corporate structure could produce different beneficial owners depending on which Member State assessed it.

    AMLR centralises that into one rulebook, directly applicable in every EU country.

    Fig 02What harmonisation deliversSix changes
    Hub network icon
    More harmonisation

    Groups can design a stronger common EU baseline while retaining national overlays

    Category shapes icon
    Expanded scope

    Additional crypto, professional, high-value and other activities expressly covered

    Fact-check list icon
    More detailed CDD

    Identity, ownership, purpose, risk and monitoring operate as one lifecycle

    Account tree ownership icon
    Stronger ownership transparency

    Both ownership and control must be tested, discrepancies addressed

    Update clock icon
    Lifecycle monitoring

    Customer data and expected activity must remain current after onboarding

    Block restriction icon
    Common restrictions

    Limits on anonymous instruments and large professional cash payments

    What harmonisation does not remove

    Direct applicability does not mean every national difference disappears. Member States retain responsibility for supervision, FIU processes, beneficial-ownership registers, sanctions machinery and the areas where AMLR permits national choices. A group operating in several Member States still needs a country overlay on top of the common baseline.

    The overlay is thinner than it was. It is not gone.

    Section 03

    How do AMLR, AMLD6, AMLA and TFR fit together?

    The EU AML package contains four instruments, and each answers a different question.

    Fig 03The EU AML packageFour instruments
    Regulation · (EU) 2024/1624
    AMLR
    What must an obliged entity do?

    Direct private-sector requirements

    Directive · (EU) 2024/1640
    AMLD6
    How must national systems operate?

    FIUs, registers, supervision, enforcement

    Regulation · (EU) 2024/1620
    AMLA
    What does the new authority do?

    Coordination, standards, direct supervision

    Regulation · (EU) 2023/1113Already live
    TFR
    What must accompany transfers?

    Funds and crypto travel-rule information

    AMLRAMLD6
    Instrument type Regulation, directly applicable Directive, requires transposition
    Binds Obliged entities Member States
    Covers CDD, KYC/KYB, beneficial ownership, screening, monitoring, reporting, cash and anonymity limits Registers, FIUs, supervision, cooperation, penalties
    Also called The single rulebook 6AMLD
    Applies / transposed by 10 July 2027 10 July 2027, with earlier deadlines for some articles
    Replaces National AML rulebooks built on Dir (EU) 2015/849 Dir (EU) 2015/849, repealed from 10 July 2027 AMLD6 Art 77

    Two naming traps are worth avoiding. AMLR should not be called “AMLD6”: the regulation carries the direct private-sector obligations, while the directive governs national machinery. And AMLD6 is the instrument informally called 6AMLD. It does not replace “6AMLD”; it repeals Directive (EU) 2015/849, the directive commonly called 4AMLD as amended by 5AMLD.

    AMLD6 also transposes on a staggered schedule rather than a single date. General transposition is 10 July 2027, but Article 74 was due by 10 July 2025, the register-access provisions in Articles 11, 12, 13 and 15 by 10 July 2026, and the real-estate single access point by 10 July 2029.1

    The updated Transfer of Funds Regulation has applied since 30 December 2024. Its payment and crypto travel-rule requirements are already live. They are not postponed until AMLR applies.

    Referenced in this section
    1 AMLD6 Art 78(1)
    Section 04

    What changes under AMLR, and what was already there?

    Most AMLR coverage reads as though every requirement is new. For a firm already running a compliant 5AMLD programme, that is not useful. This section separates the genuinely new obligations from the ones that have simply moved instrument.

    Start with the beneficial-ownership threshold, because it moved twice

    Under the previous regime, the corporate ownership indicator read:

    “A shareholding of 25% plus one share or an ownership interest of more than 25% in the customer held by a natural person shall be an indication of direct ownership.”1

    Under AMLR it reads:

    “direct or indirect ownership of 25% or more of the shares or voting rights or other ownership interest”2

    A natural person holding exactly 25.00% was not caught by the ownership indicator before. They are now.

    Example

    A customer company owned by four natural persons at exactly 25.00% each produced no beneficial owner under the ownership limb of the previous test. From 10 July 2027 it produces four.

    Check your comparison operator

    If any KYB rule engine, screening configuration or onboarding form you run carries a > 25 test, it is wrong from 10 July 2027. It needs to be >= 25. A one-line change, and easy to miss precisely because the headline number did not move.

    The second change sits in the same sentence. The old provision continued: “This applies without prejudice to the right of Member States to decide that a lower percentage may be an indication of ownership or control.” A Member State could unilaterally drop the threshold. Under AMLR it cannot. It may notify the Commission of higher-risk categories, and only the Commission sets a lower category-specific threshold, by delegated act, floored at 15% and in any case below 25%.3

    So the trigger got lower and the ability of 27 Member States to diverge on it was removed. If you built country-by-country UBO threshold logic to handle national variation, you are maintaining machinery AMLR is designed to make unnecessary.

    The rest of the change map

    AreaPreviouslyUnder AMLR
    InstrumentDirective, transposed 27 waysRegulation, directly applicable Art 90
    UBO thresholdMore than 25%, or 25% plus one share25% or more Art 52(1)
    Lowering the thresholdMember State discretionCommission delegated act only, floor 15% Art 52(2)
    Ownership vs controlControl assessed, relationship to ownership left to national practiceControl tested independently of and in parallel to ownership, no percentage floor Art 51 Art 53
    Mixed ownership/control chainsNot addressedArt 54 replaces percentage arithmetic where the two coexist across layers Art 54
    No beneficial owner foundIdentify senior managing officials, keep recordsStatement, justification, full senior-managing-official details, term now defined Art 63(3)-(4)
    Who holds BO informationObliged entity investigatesEntities, owners, chain entities, trustees and nominees carry their own duties Arts 62-67
    BO refreshRisk-based, no EU deadline28 calendar days from change, plus annual verification Art 62(2) Art 63(2)
    Register discrepanciesReport, no EU day countWithout undue delay and in any case within 14 calendar days of detection Art 24(1)
    Customer refreshRisk-based, no EU capHard maximum 1 year under EDD, 5 years otherwise Art 26(2)
    Deferred verificationRisk-basedHard 60-day cap for qualifying low-risk relationships Art 33(1)(a)
    High-net-worth EDDGeneral risk-based approachPrescribed gate at EUR 5m handled and EUR 50m held Art 34(5)
    CashNational limits onlyEU-wide EUR 10,000 ceiling on professional cash payments Art 80(1)
    High-value goodsTraders as obliged entitiesPlus threshold reports to the FIU at EUR 250,000 and EUR 7.5m Art 74
    CryptoPartial coverageCASPs as full obliged entities, EUR 1,000 occasional threshold Art 19(3)
    Crypto anonymityNot addressedAnonymous crypto accounts and anonymity-enhancing features prohibited Art 79(1)
    Bearer sharesNational treatmentConversion or immobilisation by 10 July 2029, cancellation by 10 July 2030 Art 79(3)
    New sectors·Football agents and clubs, crowdfunding, investment migration, wider high-value trading Art 3(3)
    SupervisionNational onlyNational, plus AMLA direct supervision of a selected cohort from 2028 AMLA Art 13

    Fig 04 · the UBO threshold row is the one to flag first internally, it is the single most common implementation miss.

    What did not change

    The risk-based approach survives intact. So does the structure of customer due diligence, the tipping-off prohibition, the duty to report suspicion irrespective of amount, and the principle that simplified due diligence is a calibration rather than an exemption. If you have a working 5AMLD programme you are not starting again. You are tightening deadlines, widening scope, and rebuilding the ownership layer.

    Referenced in this section
    1 Dir 2015/849 Art 3(6)(a)(i) 2 AMLR Art 52(1) 3 AMLR Art 52(2)
    Section 05

    When does AMLR apply?

    AMLR entered into force in 2024, but most operative requirements have a later application date. “In force” and “fully applicable” are not the same thing.1

    Fig 05From entry into force to full application2024 → 2030
    AMLR timeline from entry into force to full application: 9 Jul 2024 AMLR enters into force (twentieth day after OJ publication of 19.6.2024); 30 Dec 2024 TFR applies, travel rule already live; 1 Jul 2025 AMLA Regulation applies, authority stands up; 10 Jul 2025 AMLD6 Art 74 transposition due; 31 Dec 2025 Commission stewardship of AMLA ends; 10 Jul 2026 AMLD6 register-access articles due; 8 May 2026 Art 28 CDD RTS consultation closed, results pending; 3 Sep 2026 Art 26(5) monitoring guidelines close, consultation open; 10 Jul 2027 most AMLR requirements apply, the main operational deadline; 1 Jul 2027 AMLA first selection process commences; 2028 AMLA direct supervision begins, selected entities only; 10 Jul 2029 football provisions apply, bearer-share conversion deadline and AMLD6 real-estate access point due; 10 Jul 2030 unconverted bearer shares cancelled

    One date matters most: 10 July 2027.1 Track final law, draft Level 2 measures (the technical standards and guidelines that sit beneath the Regulation), transitional guidance and national rules as four separate workstreams. They move at different speeds, and collapsing them into one plan is how a programme ends up waiting on a standard it did not need.

    Level 2 status

    AMLA’s regulatory-instruments tracker lists the Article 28 CDD regulatory technical standard (RTS) as draft. Its consultation closed on 8 May 2026 and results are pending. The Article 26(5) ongoing-monitoring consultation remains open until 3 September 2026. Existing EBA instruments identified by AMLA continue to apply until replacement measures take effect. Re-check this status before relying on any Level 2 detail.

    Referenced in this section
    1 AMLR Art 90
    Part IIScope And Reach
    Section 06

    Who is subject to AMLR?

    AMLR applies to obliged entities. Scope can attach to an entire regulated business, or only to specified professional activities and transactions.1

    Fig 06The obliged-entity map15 sectors
    SectorWho is coveredScope note
    Banks and creditBanks, credit institutionsWhole business
    Payments and fintechPayment and e-money institutions, payment initiation and account information providersWhole business
    Investment and insuranceInvestment firms, relevant life and investment insurers and intermediariesWhole business
    CryptoIn-scope crypto-asset service providersWhole business. Authorisation and definitions sit in MiCA
    Lawyers and notariesNotaries, lawyers and other independent legal professionalsOnly for defined activities and transactions
    Accountants and taxAuditors, external accountants, tax advisersOnly for defined activities
    Trust and company servicesTrust or company service providersWhole business
    Real estateEstate agents and defined real-estate professionalsActivity-dependent. Both parties count as customers Art 19(6)(c)
    GamblingProviders of gambling servicesMember States may exempt defined low-risk services Art 4
    High-value and luxury goodsTraders in and intermediaries for precious metals and stones, jewellery, watches, luxury motor vehicles, aircraft and watercraftThreshold and activity-dependent
    Art and cultureArt-market participants, including intermediaries and those storing art in free zonesThreshold-dependent
    CrowdfundingCrowdfunding service providers and intermediariesWhole business
    Investment migrationOperators involved in residence-by-investment schemesActivity-dependent
    Holding companiesCertain non-financial mixed-activity holding companiesStructure-dependent
    FootballFootball agents; professional football clubs for four transaction typesFrom 10 July 2029. Member State exemptions available Art 5

    Not every person working in a listed sector is automatically covered. For legal professionals, goods traders, property businesses and football organisations, the activity and transaction conditions are decisive. Member States may also add sectors or apply defined exemptions, so test the specific activity against the Regulation first and the national overlay second.

    Scoping first

    Confirm which entities, branches and activities are covered before designing controls. A scope error propagates through every downstream decision.

    Referenced in this section
    1 AMLR Art 3
    Section 07

    Does AMLR apply outside the EU?

    AMLR binds the 27 Member States, with EEA relevance. It is not a universal worldwide regime. A non-EU organisation should look for a specific EU nexus rather than assume it is either fully in or fully out.

    Fig 07The non-EU nexus testDecision ladder
    Start · non-EU organisation
    Q1 EU branch, entity or covered establishment? Yes → Assess direct AMLR obligations Branch and establishment duties apply
    No ↓
    Q2 EU obliged subsidiary or EU-headed group? Yes → Map group-wide controls Escalate third-country conflicts
    No ↓
    Q3 Article 67 asset, contract or relationship nexus? Yes → Assess register duties Ownership registration may apply
    No ↓
    Q4 Customer of an EU obliged entity? Yes → Expect CDD and data requests The EU firm’s duties, not yours
    No to all ↓
    No obvious nexus Document the conclusion; revisit on change

    Does AMLR apply to UK businesses?

    For a UK business the position is interpretive rather than a single article. The UK remains under the Money Laundering Regulations 2017. But EU subsidiaries and branches of UK groups are obliged entities in their own right, and AMLR’s group-wide policy obligations reach EU-facing UK parents.1 2 A UK firm asked by an EU counterparty for identity, ownership or source-of-funds information is usually seeing that counterparty’s duties at work, which does not by itself make the UK firm an obliged entity.

    Foreign entities can also acquire a direct register duty under Article 67, triggered by an EU business relationship, EU real estate, defined high-value goods purchases, or an EU public contract.3

    Referenced in this section
    1 AMLR Art 16 2 AMLR Art 17 3 AMLR Art 67(1)
    Part IIIThe Customer Lifecycle
    Section 08

    When is customer due diligence required?

    CDD is required when a business relationship is established, when specified occasional transactions occur, when there is suspicion, and when an obliged entity doubts previously obtained identity information or doubts who it is dealing with.1

    Fig 08When due diligence is triggeredThresholds
    Business relationship · CDD applies when established, no threshold
    €1,000
    Funds transfer, credit/financial institutions excl. CASPs Art 19(2)
    €1,000
    CASP occasional transaction Art 19(3)At least identification and verification below this level
    €2,000
    Gambling, on winnings, stake, or both Art 19(5)
    €3,000
    Cash occasional transaction Art 19(4)At least Art 20(1)(a) measures
    €10,000
    General occasional transaction Art 19(1)(b)

    Suspicion applies regardless of value · doubt about existing information refreshes the measures · exemption: €150 low-risk e-money, supervisor-granted Art 19(7)

    Transactions that appear separate must be treated together when they are linked. Controls should catch structuring across time, channels, accounts and related people.

    Example

    Three cash payments of EUR 1,200 on consecutive days each sit below the EUR 3,000 cash trigger, but aggregate to EUR 3,600 above it. Whether your controls see one customer or three transactions is the whole question.2

    The cash trigger has a carve-out worth knowing: it does not apply where the Member State already operates a cash payment limit of EUR 3,000 or less under Article 80(2) and (3).

    The one exemption most summaries miss

    Supervisors may exempt an obliged entity, fully or partly, from the Article 20(1)(a), (b) and (c) measures for electronic money on proven low risk. All four conditions must be met:3

    The instrument is not reloadable and stores no more than EUR 150
    It is used only for goods or services from the issuer, or within a defined network
    It is not linked to a payment account and cannot be exchanged for cash or crypto-assets
    The issuer monitors transactions sufficiently to detect the unusual

    Note who grants it. This is a supervisor-granted exemption, not one you can assess for yourself.

    Every product carries its own threshold

    Different products and activities trigger different measures, and suspicion overrides every monetary threshold. There is no single “AMLR threshold” to configure.

    Referenced in this section
    1 AMLR Art 19(1)(a)-(f) 2 AMLR Art 19(4) 3 AMLR Art 19(7)(a)-(d)
    Section 09

    What does AMLR customer due diligence include?

    AMLR treats CDD as a continuing process, not a one-time document check. It is also worth keeping three articles distinct, because they are routinely collapsed into one:

    Article 19

    Says when CDD is required

    Article 20

    Says what the measures are

    Article 22

    Says how identity is identified and verified

    Calling Article 22 “the CDD article” is the most common citation error in AMLR commentary, and it will send you to the wrong provision when you need the right one.

    Fig 09The CDD lifecycleNine measures
    The CDD lifecycle, nine measures. Onboarding, run once to establish the relationship: 1 Identify, 2 Verify, 3 Understand purpose, 4 Beneficial owners, 5 Assess risk, 6 Approve. Relationship established. Ongoing, for the life of the relationship: 7 Screen and monitor, 8 Refresh or investigate, 9 Report or exit. Steps 7 to 9 repeat for the life of the relationship, exit via report or offboard.

    The core measures are identifying and verifying the customer, identifying and verifying beneficial owners, assessing the purpose and intended nature of the relationship, and conducting ongoing monitoring.1 2 3

    If CDD cannot be completed

    Do not establish or execute the relationship or transaction, and an existing relationship may need to end. Document the outcome and consider whether the circumstances should be reported to the FIU.4

    Draft Level 2

    The final Article 28 CDD RTS will add detail on required information and evidence. Its consultation is closed but the standard remains draft, so proposed document lists should not yet be presented as the final universal AMLR checklist.5

    Referenced in this section
    1 AMLR Art 20 2 AMLR Art 25 3 AMLR Art 26 4 AMLR Art 21 5 AMLR Art 28(1)
    Section 10

    What are the KYC requirements for individuals?

    “Know your customer” is the operational process for performing CDD on a natural person. It is not a separate AMLR legal regime.

    Fig 10The KYC recordArt 22(1)(a)
    A face captured inside a dashed verification circle, with the extracted Name, Date of Birth and Nationality attributes below
    The required record
    • Full name and any former or alternative names
    • Place and date of birth
    • Nationality or nationalities and legal status
    • Identification or tax number, where applicable
    • Usual residence and required contact information
    • Any representative, and their authority to act

    Verification must use reliable and independent documents, data or information. A successful document check establishes identity attributes. Purpose, occupation, source of funds, PEP exposure and overall risk still need their own evidence.1 2

    Where a person acts for the customer, the firm must identify and verify the representative, identify the customer behind them, and confirm the authority to act. A mandate on file is not the same as evidence that the mandate is current.

    Example

    A power of attorney executed four years ago and presented by a relative establishes that authority was granted once. It does not establish that it was never revoked, and the file should show which of those two things you verified.

    A document check answers one question of four

    A passing document and biometric check answers who this person is. It does not answer why the relationship exists, where the money comes from, or how risky it is.

    Referenced in this section
    1 AMLR Art 22(1)(a) 2 AMLR Art 22(6)
    Section 11

    What are the KYB requirements for businesses?

    “Know your business” applies CDD to legal entities and arrangements: legal existence, authority, ownership, beneficial owners, purpose and risk in one assessment.

    The structural change under AMLR is that the duty is no longer one-sided. Previously the obliged entity investigated and the customer cooperated or did not. AMLR places statutory obligations on the customer entity, its beneficial owners, the entities in its ownership chain, its trustees and its nominees. KYB becomes a two-sided information exchange with deadlines on both sides.

    Fig 11Who owes what under AMLR KYBTwo sides
    Obliged entityInvestigates and verifies
    Customer sideSupplies and self-reports
    Identify and verify the entity Art 22(1)(b)
    Obtain BO information within 28 days of creation, update within 28 days of change, and annually Art 62(2)
    Identify and verify beneficial owners Art 20
    Report to the central register without undue delay, changes within 28 days, verify at minimum annually Art 63(2)
    Report register discrepancies within 14 calendar days of detection Art 24(1)
    Beneficial owners and chain entities must supply what the entity needs Art 63(2)
    Refresh customer information within 1 or 5 years Art 26(2)
    Nominees disclose nominator, nominator’s BOs and their own nominee status Art 66; trustees report within 28 days and verify at least annually Art 64(2)

    The six KYB questions

    QuestionWhat it establishes
    Does the entity legally exist?Official name, legal form, registration and governing law
    Where does it operate?Registered or official office and, if different, principal place of business and country of creation
    Who can act for it?Directors, representatives, mandates and authority
    Who owns it?Direct and indirect ownership through every material layer
    Who controls it?Voting, appointment, contractual or other control
    Why does the relationship exist?Business activity, purpose and expected transactions

    Three data points older KYB models tend to miss

    Article 22(1)(b) sets the legal-entity identification minimum, and three items in it are commonly absent from data models built for 4AMLD:

    Legal Entity Identifier (LEI), where available
    Principal place of business where different from the registered office, plus country of creation
    Names of persons holding shares or a directorship in nominee form, including their status as nominee shareholders or directors1

    Companies, trusts, foundations, partnerships and collective-investment structures need different data models. A standard company checklist will not reliably identify all parties to a trust or similar arrangement.

    Central-register information supports CDD but does not ordinarily replace independent identification and verification.

    When no beneficial owner can be identified

    AMLR is stricter than the old senior-managing-official shortcut. Where all means under Articles 51 to 57 are exhausted, or there is “substantial and justified uncertainty”, the entity keeps records of the actions taken and must supply:2

    A statement that there is no beneficial owner, or that they could not be determined
    A justification of why, and of what the uncertainty consists
    Details of all senior managing officials

    AMLR also defines senior managing officials, which the previous directive did not.

    On the obliged-entity side, where verifying senior managing officials would signal that the firm doubts the ownership picture, it must abstain from that verification and instead record the steps taken and the difficulties encountered.3

    Register discrepancies

    Where CDD information conflicts with beneficial-ownership register data, report to the central registers without undue delay and in any case within 14 calendar days of detection. Defined minor cases let you ask the customer first instead, but not in higher-risk cases.4

    Is “perpetual KYB” required?

    No. “Perpetual KYB” and “perpetual KYC” are industry terms. Neither appears in AMLR, and neither removes the periodic duty.

    The practical position is more demanding than the label suggests. AMLR stacks five clocks:

    • 1. The entity updates its own BO information within 28 days of change, and annually. Art 62(2)
    • 2. The entity reports register changes within 28 days and verifies at minimum annually. Art 63(2)
    • 3. You refresh customer information within 5 years, or 1 year where enhanced measures apply. Art 26(2)
    • 4. You review and update on three specific events, not on a schedule. Art 26(3)
    • 5. You report register discrepancies within 14 days of detection. Art 24(1)

    A five-year refresh cycle cannot detect a change the customer was obliged to register within 28 days, and the discrepancy clock only starts once you have looked. Event-driven KYB is not a legal requirement. It is the practical way to meet the requirements AMLR does impose.

    Example

    A customer entity whose beneficial owner changes in September must update its own record within 28 days and report the change to the register within 28 days. An obliged entity that last refreshed that customer in 2028 is not due to look again until 2033, and the 14-day discrepancy clock does not start until it does.

    Referenced in this section
    1 AMLR Art 22(1)(b)(iv) 2 AMLR Art 63(3)-(4) 3 AMLR Art 22(2) 4 AMLR Art 24(1)-(2)
    Section 12

    Can customers be onboarded remotely?

    Yes. Article 22(6) gives two routes and does not rank them. A proposed ranking exists, but only in draft Level 2, and the final text and the draft must be kept apart.

    Fig 12Two routes, one proposed hierarchyFinal law + draft RTS
    Final law · Article 22(6)
    Either · Art 22(6)(a) Identity document route

    Identity document, passport or equivalent and, where relevant, information from reliable and independent sources

    Or · Art 22(6)(b) Electronic route

    Electronic identification means meeting Reg (EU) No 910/2014 at assurance level substantial or high, and relevant qualified trust services

    Article 22 itself does not rank the two routes

    Draft CDD RTS · Article 7Draft · not yet law
    Primary route Qualifying eID or qualified trust service

    Used first for non-face-to-face verification

    If the primary route is unavailable or cannot reasonably be expected ↓ then

    Conditional fallback Remote document capture with safeguards

    Quality, presenter match, integrity, interruptions, validity and retained evidence, plus a justification to your supervisor

    Status warning

    The priority-and-justification requirement sits in the draft Article 28 CDD RTS. Its consultation has closed, but it is not yet final adopted Level 2 law. Build for it, do not cite it as binding.1

    Example

    An applicant onboarding at 22:00 during an outage of their national eID scheme can be verified under Article 22(6)(a) today, with no justification owed to anyone. Under the draft RTS the same journey would require a recorded reason why the primary route was unavailable. Building that field now costs little, and retrofitting it into a live journey later costs a great deal.

    How eIDAS 2.0 and the EUDI Wallet connect to AMLR

    AMLR never mentions the European Digital Identity Wallet. The connection runs through three instruments, and stating the chain explicitly is the difference between a claim you can defend and one you cannot.

    Fig 13The eIDAS chainFour links
    1 AMLR Art 22(6)(b)

    Accepts electronic identification means at assurance level substantial or high Art 22(6)(b)

    Chain continues to the next instrument
    2 Reg (EU) No 910/2014

    This is eIDAS. AMLR points at it by number.

    Chain continues to the next instrument
    3 Reg (EU) 2024/1183

    Informally eIDAS 2.0. Amends 910/2014 and creates the European Digital Identity Wallet.

    Chain continues to the next instrument
    4 Wallets at assurance level high

    Meet Article 8 requirements Reg 2024/1183 Art 5a(4)(d), satisfying the AMLR condition by reference

    Each Member State must provide at least one Wallet within 24 months of the relevant implementing acts entering into force.2 The Regulation sets no calendar date, so treat any specific month you see quoted as derived from implementing-act timing rather than from the Regulation itself.

    Three things the Wallet does not do. It does not create a hierarchy in Article 22(6), which remains route-neutral in final law. It does not remove the obliged entity’s decision on whether the supplied attributes and assurance level meet the CDD requirement. And it answers who, not why: purpose, beneficial ownership and source of funds still need their own evidence.3 4 5

    If Wallets must be “high”, what sits at “substantial”?

    A fair question, and the answer matters more than it first appears. AMLR accepts electronic identification means at substantial or high. Wallets must be high. So what populates the substantial tier?

    Notified national eID schemes. eIDAS 2.0 adds the Wallet; it does not abolish notification. Article 8(3) of Regulation (EU) No 910/2014, as amended, still sets minimum technical specifications for assurance levels low, substantial and high, and Article 9 still requires the Commission to publish the list of notified electronic identification schemes in the Official Journal and to publish amendments within one month.6

    The substantial tier is therefore the existing installed base: national identity schemes, bank-identity schemes and equivalent means already notified by Member States and already listed.

    The electronic route is available now

    Article 22(6)(b) does not wait for Wallet rollout. A notified scheme already on the Official Journal list, assessed at substantial or high, satisfies the electronic route today. Wallets widen coverage and raise the assurance floor. They do not open a route that was previously closed.

    There is a filter here that is easy to miss. Notified schemes span three levels of assurance. AMLR accepts only two of them.

    Fig 14The assurance-level filterThree tiers
    Low Notified schemes exist at this level Not accepted
    Substantial Notified national eID schemes Accepted
    High Notified schemes at high, and all EUDI Wallets Reg 2024/1183 Art 5a(4)(d) Accepted

    Operational note: check the Official Journal list of notified schemes and exclude anything notified at low before accepting it as an Art 22(6)(b) route.

    Does a substantial-level eID need supplementing?

    Not as a matter of Article 22(6)(b). Substantial is accepted on its own terms, and there is no obligation to top it up.

    Whether you choose to add measures is a risk question, governed by the ordinary rule that the extent and intensity of due diligence must reflect the customer, geography, product, transaction and delivery channel. A firm may reasonably decide that for a higher-risk customer a substantial-level eID alone is not enough, and layer additional verification on top. That decision is made under Articles 20 and 34, and it is documented and justified the same way any other risk-based calibration is.7 8

    Qualified trust services

    Qualified trust services are the second limb of Article 22(6)(b) and are not interchangeable with electronic identification means. The three that matter for identity work are the qualified electronic signature (QES), the qualified electronic seal and the qualified electronic timestamp.

    Fig 15Three qualified trust servicesQES · seal · timestamp
    Qualified signature

    Links a person to signed data

    Qualified seal

    Supports the origin and integrity of legal-person data

    Qualified timestamp

    Establishes that data existed at a particular time

    None of them replaces purpose, beneficial-ownership or source-of-funds checks. Check qualified status against the national trusted list or the EU Trusted List Browser rather than a supplier’s own description.

    Where video identification sits

    AMLR does not name video identification as a distinct route. It falls under Article 22(6)(a) as a means of obtaining information from reliable and independent sources, which means it is governed by the general verification standard rather than by a bespoke rule. Several Member States operate detailed national video-identification requirements today, and the EBA Remote Customer Onboarding Guidelines remain relevant transitional guidance until AMLA’s replacement measures take effect.

    Under the draft CDD RTS, remote capture routes of any kind would become a conditional fallback requiring justification. That status is draft.

    What to keep configurable

    If you are building a remote onboarding flow now, keep the following adjustable so the final RTS text can be applied without re-architecting the journey:

    Which route is attempted first, and why
    The recorded justification when a fallback is used
    Accepted assurance levels per product and risk tier
    Capture-quality and presenter-match thresholds
    Interruption and retry handling
    Evidence retained for supervisory review
    Referenced in this section
    1 AMLR Art 28(1) 2 Reg 2024/1183 Art 5a(1) 3 AMLR Art 20 4 AMLR Art 25 5 AMLR Arts 51-55 6 910/2014 Arts 8(3), 9 7 AMLR Art 20 8 AMLR Art 34
    Section 13

    How does risk affect due diligence?

    The extent and intensity of CDD must reflect risk, considering the customer, geography, product, transaction and delivery channel together.1 2

    Fig 16Three depths of due diligenceRisk-based
    SimplifiedStandardEnhanced
    Simplified
    Demonstrably lower riskArt 33

    Adjust timing, extent or intensity, never skip CDD.

    Standard
    Normal riskArt 20

    Complete the core measures at risk-sensitive depth, with evidence for each.

    Enhanced
    Higher risk or prescribedArt 34

    Additional evidence, senior approval, source-of-funds or wealth checks, transaction limits, closer monitoring.

    Where verification is deferred for a qualifying low-risk relationship, it must be completed no later than 60 days after the relationship is established, and only where the specific lower risk identified justifies the postponement. Interim risk-management procedures are required in the meantime, such as limiting the amount, number or type of transactions.3 4

    Example

    A qualifying low-risk relationship opened on 1 March with verification deferred and transaction limits applied must be fully verified by 30 April. On day 61 that file is not a backlog item, it is a breach.

    Simplified due diligence must not be applied at all where there are doubts about veracity, where the lower-risk factors are no longer present, where monitoring excludes a lower-risk scenario, or where there is suspicion of money laundering, terrorist financing or sanctions evasion.5

    Source of funds

    Where the money used in this relationship or transaction came from.

    Source of wealth

    How the customer’s or beneficial owner’s overall wealth was accumulated.

    A numerical risk score can support consistency, but you have to be able to explain the rating, any material override, and the controls that follow from it.

    Referenced in this section
    1 AMLR Art 20 2 AMLR Annexes II-III 3 AMLR Art 33(1)(a) 4 AMLR Art 33(3) 5 AMLR Art 33(5)
    Section 14

    What screening does AMLR require?

    “Screening” is several controls with different legal purposes and different consequences.

    Fig 17Four screening controlsDifferent consequences
    High-risk countries Arts 29-31 Art 35

    Customer, ownership, operations and fund flows. Apply the prescribed enhanced measures or countermeasures.

    Adverse information

    Reliable reputation information. Reassess risk, investigate the facts, consider whether suspicion exists.

    Targeted financial sanctions Art 20(1)(d) Art 26(4)

    Customers, beneficial owners and relevant controllers. Validate matches, hand confirmed exposure to the sanctions process.

    Politically exposed persons Arts 42-46

    PEPs, family members and known close associates. Senior approval, source-of-funds and wealth measures, enhanced monitoring.

    AMLR’s sanctions-risk controls do not replace the separate legal duty to freeze assets and avoid making funds available under applicable restrictive measures.1 2 PEP status indicates higher risk. It is not evidence of wrongdoing.3

    Adverse media

    “Adverse media screening” is not a standalone statutory duty under that name. Reliable public-source information can still affect customer risk, enhanced due diligence, ongoing review and suspicion assessment. Automated matches are not facts: identity resolution and human evaluation of source quality, recency and relevance come first.

    Screening runs at onboarding, on list changes, on customer or ownership changes, at relevant transaction points, and on periodic or event-driven review. Your governance has to cover data quality, transliteration, fuzzy matching, ownership and control, alert priority, false positives, escalation and testing.

    Referenced in this section
    1 AMLR Art 20(1)(d) 2 AMLR Art 26(4) 3 AMLR Arts 42-46
    Section 15

    What does ongoing monitoring involve?

    Article 26 requires firms to scrutinise transactions and activity, keep customer information current, and check that behaviour stays consistent with the customer’s purpose and risk profile.1 It contains four distinct duties, and they run on different clocks.

    Fig 18The four monitoring clocksArticle 26
    Update · max 1 yearArt 26(2)(a)
    Customers under Section 4 enhanced due diligence
    Update · max 5 yearsArt 26(2)(b)
    All other customers
    Review on 3 eventsArt 26(3)
    Circumstance change · annual BO/DAC review duty · new relevant fact
    Sanctions verificationArt 26(4)
    Regularly, and on any new designation for credit/financial institutions

    The one-year and five-year figures are maximum intervals for updating customer information, not review targets. Three named events override the calendar, and sanctions verification runs regardless of either.

    Two precision points that matter when you build the schedule. First, Article 26(2) governs updates of customer information; the word “review” belongs to Article 26(3), which is a different duty with a different trigger.2 3 Second, the one-year band is scoped to customers under Section 4 enhanced measures, not to every customer your internal model rates as higher risk. A customer can carry a high internal score without Section 4 applying, and that customer sits on the five-year clock.4

    Fig 19Two duties that run in parallelArticle 26
    Duty 1Customer information
    Duty 2Transactions and activity
    Keep identity, ownership and purpose current
    Detect unusual patterns and behaviour
    Respond to changes and risk events
    Investigate alerts in context
    Update within 1 year under Section 4 measures
    Examine source of funds where necessary
    Update within 5 years otherwise
    Decide whether activity should be reported

    Automated monitoring needs scenario ownership, reliable data, calibration, validation and controlled case closure. Manual monitoring needs defined populations, frequency, trained reviewers and evidence. Neither model should rest on unexplained backlogs or blanket alert closure.

    What reads as a broken control

    Alerts closed in volume, with no recorded reasoning, are read as a control that is not working, whatever the closure rate says.

    Referenced in this section
    1 AMLR Art 26(1) 2 AMLR Art 26(2) 3 AMLR Art 26(3) 4 AMLR Art 26(2)(a)
    Part IVOwnership And Higher Risk
    Section 16

    How is beneficial ownership determined?

    A beneficial owner is the natural person who ultimately owns or controls a legal entity or arrangement. AMLR runs two tests, and they are parallel rather than sequential.

    The general corporate indicator is 25% or more of the shares, voting rights or other ownership interest, including rights to a share of profits, other internal resources or liquidation balance, held directly or indirectly.1

    Control is assessed “independently of and in parallel to” the existence of an ownership interest.2 Control through ownership interest means 50% plus one.3 Control via other means carries no percentage floor at all: a majority of voting rights whether or not shared by persons acting in concert, the right to appoint or remove a majority of the board, relevant veto or decision rights attached to shares, decisions on profit distribution or asset shifts, and formal or informal agreements including relationships between family members and nominee arrangements.4

    Fig 20Resolving the beneficial ownerThree tests
    Map direct and indirect ownership through every layer
    Test 1 Ownership · natural person holds 25% or more, directly or indirectly? Yes → Identify and verify that person Independent evidence, not registry data alone
    No ↓
    Test 2 Control · through voting, board, contract or dominant influence? Yes → Identify and verify that person Independent evidence, not registry data alone
    No ↓
    Test 3 Exhaustion · every identification means exhausted and documented? Yes → Record senior managing officials Statutory fallback, last resort

    No at Test 3 · continue mapping, do not default to a director

    The senior-managing-official fallback is not permission to call a director the UBO because a database found nothing. It requires exhausted investigation and documented uncertainty.

    Indirect ownership, and the case where arithmetic does not work

    Indirect ownership is calculated by multiplying holdings through each chain and adding the chains together. All shareholdings at every level count.1

    But that arithmetic is expressly disapplied where Article 54 applies. Where a multi-layered structure has ownership interest and control coexisting at different layers of a chain, the beneficial owners become the natural persons controlling the entities that hold a direct ownership interest, and the natural persons with an ownership interest in the entity that controls the corporate entity.5

    Example

    A natural person holds 40% of a holding company, and that holding company holds 60% of the customer. Multiplying gives 24%, and a rule engine that stops there reports no beneficial owner. But 60% is control through ownership interest, so Article 54 applies in place of the arithmetic, and the person holding 40% of the entity that controls the customer is a beneficial owner.1 3 6

    Fig 21Layered ownershipTwo structures
    PURE OWNERSHIP CHAIN · ARITHMETIC WORKS
    Natural person at the top of the chain Natural person
    Ownership flows down to the next layer 40% OWNERSHIP
    Intermediate holding company Holding Co
    Ownership flows down to the next layer 40% OWNERSHIP
    Customer entity Customer 16% TOTAL · NO BENEFICIAL OWNER
    OWNERSHIP + CONTROL COEXIST · ART 54 APPLIES
    Natural person identified as the beneficial owner Natural person BENEFICIAL OWNER
    Ownership flows down to the next layer 40% OWNERSHIP
    Holding company that controls the customer Holding Co CONTROLS THE CUSTOMER
    Control passes down to the customer 60% = CONTROL ART 53(2)(C)
    Customer entity under assessment Customer ENTITY OF FOCUS

    Left: no single layer reaches control, so multiply-and-add resolves the answer. Right: 60% at the middle layer is control through ownership, so Article 54 substitutes for the arithmetic and the 40% holder becomes a beneficial owner of the customer.

    Where a legal arrangement or an Article 57 entity sits in the chain, the beneficial owners are the beneficial owners of that arrangement or entity.7

    Trusts and complex structures

    Trusts and similar arrangements need function-based identification. Relevant persons can include settlors, trustees, protectors, beneficiaries or classes of beneficiaries, and any person exercising ultimate control. A company-shaped checklist will miss several of these roles entirely.8

    For a complex structure, map each ownership layer, calculate indirect interests, identify the natural persons behind intermediate entities, examine nominee arrangements, and understand the commercial rationale. A structure whose only apparent purpose is to obscure ownership is itself a risk indicator.

    Ownership deadlines to build into the operating model

    DeadlineDuty
    28 calendar daysEntity obtains BO information after creation Art 62(2)
    Promptly, 28 days maxEntity updates its own BO information after any change Art 62(2)
    Undue delay, 28 days maxReport a change to the central register Art 63(2) Art 64(2) Art 67(5)
    At minimum annuallyEntity verifies it holds up-to-date BO information Art 63(2)
    At least annuallyTrustee verifies the wider information set held Art 64(2)
    Undue delay, 14 days maxObliged entity reports a register discrepancy after detection Art 24(1)
    5 yearsRetention of specified ownership records after cessation Art 63(6) Art 64(1)

    Note that the initial register report differs by entity type. A legal entity reports “without undue delay after its creation” with no 28-day cap. A trustee reports without undue delay and in any case within 28 calendar days.9 10

    Registry data is an input

    A register entry supports the assessment. It is not, on its own, independent verification of who ultimately owns or controls the customer.

    Referenced in this section
    1 AMLR Art 52(1) 2 AMLR Art 51 3 AMLR Art 53(2)(c) 4 AMLR Art 53(3)-(4) 5 AMLR Art 54 6 AMLR Art 54(b) 7 AMLR Art 55 8 AMLR Arts 58-60
    Section 17

    Which situations require specific enhanced measures?

    Some relationships require prescribed enhanced due diligence in addition to the general customer-risk assessment.1

    SituationWhat is required
    High-risk third countryAdditional customer, ownership, purpose, funds, wealth, approval and monitoring measures Arts 29-31 Art 35
    Correspondent bankingRespondent ownership, reputation, supervision, controls and responsibilities Art 36
    Correspondent crypto relationshipsEquivalent measures for CASP correspondent relationships Art 37
    Shell institutionProhibited relationship; guard against indirect access Art 39
    Self-hosted crypto addressOwnership or control, transfer risk and proportionate mitigation Art 40
    Residence-by-investment applicantFunds, wealth, PEP exposure, intermediaries and structure Art 41
    PEP or former PEPSenior approval, source-of-wealth and funds evidence, enhanced monitoring Arts 42-46
    Life or investment insuranceBeneficiary identity, ownership and PEP exposure Art 44 Art 47
    Higher-risk high-net-worth servicePrescribed gate, see below Art 34(5)

    Former PEPs

    Mitigating measures continue until the risk no longer exists, and “in any case for not less than 12 months following the time when the individual ceased to be entrusted with a prominent public function”. The clock runs from the person leaving the function, not from your last review. The duty is to apply one or more of the Article 34(4) measures, not the full PEP regime. It applies equally to a new customer who formerly held such a function.2

    The prescribed high-net-worth gate

    Fig 22The high-net-worth gateAll conditions required
    €5M in assets handled through personalised services
    plus
    €50M in total financial, investable or real-estate assets, excluding the customer’s private residence
    plus
    Higher risk the business relationship is identified as higher-risk

    All three elements required · applies only to credit/financial institutions and TCSPs

    Then: prescribed EDD applies, in addition to Art 34(4) measures

    The Regulation contains no annual qualifier: the trigger is the value of assets handled through personalised services, not an annual flow. The duty binds only credit institutions, financial institutions and trust or company service providers, not obliged entities generally.3

    Below any one of the three elements, the prescribed rule does not bite and the general risk-based approach applies.

    Example

    A customer holding EUR 60,000,000 in total assets but running only EUR 2,000,000 through personalised services fails the first limb. The prescribed gate does not apply, and the relationship is assessed under the general risk-based approach like any other.3

    Referenced in this section
    1 AMLR Art 34 2 AMLR Art 45(1)-(3) 3 AMLR Art 34(5)
    Section 18

    How does AMLR apply to crypto-assets?

    Crypto-asset service providers operate AMLR and the Transfer of Funds Regulation together. One customer, one transfer, two rulebooks. A third and a fourth instrument sit alongside them, and keeping the four apart is the single most useful thing a crypto compliance team can do with AMLR.

    Fig 23Four instruments, one operationAttribution map
    AMLR Lifecycle
    • CDD at €1,000 occasional Art 19(3)
    • Self-hosted address risk mitigation Art 40
    • Anonymity prohibitions Art 79
    • Correspondent CASP relationships Art 37
    TFR · 2023/1113 Transfers
    • Originator and beneficiary information
    • Transfer-message completeness
    • Missing-information handling
    • Travel-rule records · live since 30 Dec 2024
    MiCA · 2023/1114 Authorisation and definitions
    • What a CASP is, and who may operate as one MiCA Art 59
    • Applies since 30 December 2024.
    • No preventive AML/CFT duties sit here.
    AMLD6 National machinery
    • Beneficial-ownership registers
    • FIU powers, supervisory architecture, and the penalty regime for AMLR breaches. AMLD6 Art 55
    • General transposition 10 July 2027.

    Attributing a rule to the wrong instrument is the most common error in crypto AML commentary.

    What AMLR does and does not prohibit

    Self-hosted addresses are not banned. CASPs must identify and assess the money laundering and terrorist financing risk of transfers to or from a self-hosted address, then apply mitigating measures commensurate with that risk. One or more of:1

    Risk-based identification and verification of the originator or beneficiary, or their beneficial owner
    Additional information on the origin and destination of the crypto-assets
    Enhanced ongoing monitoring of transactions with a self-hosted address
    Any other measure that mitigates the risk

    There is no fixed threshold in this article.

    The “verify who controls the wallet above EUR 1,000” rule that circulates in summaries is the Transfer of Funds Regulation, not AMLR.

    Anonymity is where AMLR does prohibit. Credit institutions, financial institutions and CASPs are prohibited from keeping anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes or anonymous crypto-asset accounts, as well as any account otherwise allowing the anonymisation of the account holder or the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins.2

    What the privacy-coin provision actually says

    Article 79(1) prohibits obliged entities from keeping accounts that enable anonymisation, including through anonymity-enhancing coins. It does not criminalise privacy coins, ban self-custody, or outlaw non-custodial software. “AMLR bans privacy coins” is a misreading of an account-level prohibition.

    Existing anonymous accounts, passbooks, safe-deposit boxes and crypto-asset accounts must be subject to CDD before they are used in any way.2

    Analytics is not identity

    Blockchain analytics supports risk assessment but is not an infallible identity source. Attribution confidence, chain coverage, clustering assumptions, privacy features and false positives all need governance.

    Referenced in this section
    1 AMLR Art 40(1) 2 AMLR Art 79(1)
    Part VReporting, Data And Limits
    Section 19

    When must suspicious activity be reported?

    An obliged entity must report without delay to its national FIU when it knows, suspects or has reasonable grounds to suspect that funds or activity are connected to criminal conduct or terrorist financing. The duty applies irrespective of amount and can cover attempted transactions.1

    Fig 24From anomaly to reportFIU reporting
    Unusual fact or activity
    Flow continues downward
    Internal assessment Preserve facts, transactions, ownership context and reasons
    Flow continues downward
    Suspicion threshold met?
    No ↓ Yes ↓
    Document and keep monitoring Escalate if the picture changes
    Report promptly to the FIU Without delay, any amount Art 69
    Flow continues downward
    Refrain where required Three-working-day rule if no FIU instruction Art 71
    No tipping off Never reveal that a report has been or will be made Art 73

    Your internal assessment should preserve the relevant facts, transactions, ownership context, explanations, and the reason for the conclusion. Staff do not need to prove the underlying crime before escalating a concern, and a policy that implies otherwise suppresses reporting.

    The tipping-off constraint has to be designed into customer-facing scripts, complaint handling, account-closure messaging and automated notifications, not bolted on afterwards.2

    National filing portals and procedures remain important even as AMLA develops a common reporting-format standard. Firms operating in several Member States should treat filing mechanics as a per-country workstream.

    Attempts count

    A transaction that never completed can still require a report. The duty attaches to suspicion, not to settlement.

    Referenced in this section
    1 AMLR Art 69 2 AMLR Art 73
    Section 20

    What must be reported on high-value goods?

    Alongside suspicion-based reporting, AMLR introduces a threshold-based reporting duty that has nothing to do with suspicion. It is easy to miss because it sits at the end of the reporting chapter.

    Persons trading in high-value goods must report to the FIU all transactions involving the sale of the following goods when those goods are acquired for non-commercial purposes:1

    Fig 25High-value goods reporting thresholdsNon-commercial only
    €250,000
    Motor vehicles
    €7.5M
    Watercraft
    €7.5M
    Aircraft

    Second reporting population: credit and financial institutions servicing these purchases report too Art 74(2) ·

    timing set by the FIU, not AMLR Art 74(3)

    Two points that summaries routinely drop. The duty is not limited to the trader: credit institutions and financial institutions that provide services in relation to the purchase or transfer of ownership of these goods also report the transactions they carry out for their customers.2 And there is no fixed EU deadline: reporting is carried out “within the deadlines imposed by the FIU”.3

    The commercial-purpose condition does real work. A dealership buying stock is outside paragraph 1.
    A private buyer at or above the threshold is inside it.

    Example

    A dealer acquiring three vehicles at EUR 300,000 each for resale reports nothing under this article. A private buyer acquiring one of those same vehicles at EUR 300,000 triggers the report.

    These same thresholds also appear in Article 67 as one of the triggers that pull a foreign legal entity or arrangement into an EU central register.4

    Referenced in this section
    1 AMLR Art 74(1) 2 AMLR Art 74(2) 3 AMLR Art 74(3) 4 AMLR Art 67(1)(c)
    Section 21

    When can AML information be shared?

    AMLR permits defined information sharing within groups and through qualifying information-sharing partnerships, with a clear AML/CFT purpose, restricted access, security, governance and data-protection safeguards.1 2

    Fig 26Four decisions you must still make yourselfNever delegated
    A customer risk conclusion
    Refusing or terminating a relationship
    Suspending a transaction
    Your own FIU reporting decision

    Each of those decisions has to rest on the obliged entity’s own assessment. Shared intelligence can direct attention, prompt a review or corroborate a finding, but the accountable decision stays with the firm that makes it.

    The tipping-off prohibition still applies. Information that would disclose that a suspicious-activity report exists, or that an FIU analysis is under way, can be shared only where a specific legal exception permits it. Partnership design should assume that constraint from the start.3

    Governance to put in place first

    A defined AML/CFT purpose, a lawful basis, role-restricted access, logging, retention limits, security controls, an assessment of accuracy and provenance, and a documented escalation route for disputes or corrections.

    Corroborate, do not delegate

    Sharing improves what you can see. It transfers nothing: not the decision, not the accountability, not the reporting duty.

    Referenced in this section
    1 AMLR Art 75 2 AMLR Art 16 3 AMLR Art 73
    Section 22

    How does AMLR interact with GDPR, AI and recordkeeping?

    AMLR provides a legal framework for necessary AML/CFT data processing. It does not remove GDPR principles.1

    PrincipleWhat it means in practice
    Purpose limitationDo not repurpose AML data for unrelated commercial activity
    Data minimisationCollect the attributes needed for the legal and risk outcome
    AccuracySeparate official facts, credible reporting, allegations and automated inference
    Sensitive-data protectionRestrict special-category and criminal-offence data
    Human interventionGive reviewers evidence and authority to change automated outcomes
    SecurityLimit access, log activity and protect reporting confidentiality

    Automation can extract documents, triage alerts, score risk and identify patterns. It does not transfer accountability to the model or the provider. Where meaningful human intervention is required, the reviewer must understand the evidence and be able to alter the decision. An approval click alone is not enough.

    Record keeping requirements

    Fig 27The retention clockArt 77(3)
    Relationship activeEnd
    Required, from termination / transaction / refusal5 years
    Competent-authority decision, case-by-caseUp to 5 more

    The clock runs from termination of the business relationship, the occasional transaction, or a refusal to enter a relationship or carry out a transaction. The extension is a competent authority's case-by-case decision, not a blanket Member State option, and only where necessary for ML/TF prevention, detection, investigation or prosecution.2 A separate transitional Member State option exists for legal proceedings pending on 10 July 2027.3

    Personal data must be deleted on expiry of the five-year period, without prejudice to retention periods set by other Union or national law compliant with GDPR.2

    Your records should be able to reconstruct what was known, which sources were used, how ownership and risk were assessed, who approved the outcome, and what monitoring or reporting action followed.

    Referenced in this section
    1 AMLR Art 76 2 AMLR Art 77(3) 3 AMLR Art 77(4)
    Section 23

    What anonymity and cash restrictions does AMLR introduce?

    AMLR prohibits anonymous instruments and puts an EU-wide ceiling on professional cash payments.

    Prohibited or restricted instruments

    Anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes and anonymous crypto-asset accounts, plus any account allowing anonymisation or increased obfuscation of transactions.1 Acquirers must not accept payments made with anonymous prepaid cards issued in third countries, subject to any RTS adopted under Article 28.2

    Bearer shares now carry dates

    Companies are prohibited from issuing bearer shares. Existing bearer shares must be converted into registered shares, immobilised, or deposited with a financial institution by 10 July 2029. Where that does not happen, all voting rights and rights to distribution are automatically suspended until conversion, immobilisation or deposit. Shares still not dealt with by 10 July 2030 are cancelled, reducing share capital accordingly. Listed companies and shares issued as intermediated securities are carved out. Bearer share warrants that are not in intermediated form are prohibited.3

    The cash ceiling

    Fig 28The Article 80 cash ceilingEUR 10,000
    Professional cash payments · goods and services, single or linked operations
    €0
    €3,000 Cash ID+V threshold Art 19(4)
    €10,000 Article 80 ceiling Art 80(1)
    MS may go lower after ECB consultation; pre-existing lower limits continue Art 80(2)-(3) Not the CDD threshold

    Suspicion overrides any value

    The cash ceiling is not the CDD threshold. A EUR 3,000 cash transaction can trigger identification and verification even though it sits below the payment ceiling, and suspicion triggers CDD and reporting at any value.

    There are two carve-outs, not one:4

    Payments between natural persons not acting in a professional capacity
    Payments or deposits at the premises of credit institutions, e-money issuers and payment service providers; above the limit these must be reported to the FIU

    If you operate across Member States you need a country matrix covering lower national limits, exclusions, linked payments, mixed payment methods and refund controls.

    Referenced in this section
    1 AMLR Art 79(1) 2 AMLR Art 79(2) 3 AMLR Art 79(3) 4 AMLR Art 80(4)
    Part VIGovernance And Consequences
    Section 24

    What compliance framework does AMLR require?

    AMLR requires a risk-based and proportionate programme. A smaller obliged entity may use simpler controls than a cross-border bank, but it must still achieve the required outcomes and prove that the controls work.1

    Fig 29The compliance framework loopSix elements
    01Management oversight
    02Business-wide risk assessment
    03Policies and controls
    04Customer lifecycle
    05Monitoring and reporting
    06Testing and assurance
    Risk-based · proportionate Outcomes you can prove

    The business-wide risk assessment should reflect actual customers, geographies, products, services, transactions, delivery channels and technology, and connect identified risk to control design and investment rather than read as a generic description of the sector.2

    The compliance officer and the management body

    AMLR separates responsibility rather than leaving it to organisational preference. The management body carries overall accountability. A member of the management body is designated as the compliance manager responsible for implementation. A compliance officer runs day-to-day compliance, reports to the management body, and must have the standing, resources and access to discharge the role.3

    Training and employee integrity

    Staff must be made aware of the requirements that apply to their role, with training proportionate to the risks and to what the person actually does. Employee integrity measures and protected internal reporting routes are part of the framework, not optional additions.4

    Group-wide policies

    Groups apply group-wide policies, procedures and controls, including information sharing for AML/CFT purposes within the group. Where a third country’s law prevents implementation, the conflict must be escalated and additional measures applied.5

    Outsourcing and reliance are not the same thing

    Fig 30Outsourcing vs relianceTwo routes
    Route 1Outsourcing Art 18
    Route 2Reliance Arts 48-50
    A provider may perform permitted tasks, but the obliged entity remains accountable and keeps the decisions reserved to it.
    Under defined conditions, CDD performed by another obliged entity may be used. Responsibility remains, and the information and evidence must be available.

    Neither route transfers accountability. In both cases the obliged entity has to produce the underlying information and evidence on request, and demonstrate that the arrangement was assessed, documented and monitored. Contractual language alone is not a control.

    Proportionality applies to the build, the outcome is fixed

    Proportionality governs how a control is built, never whether the outcome is achieved. A small firm may run simpler processes, but it still has to evidence them.

    Referenced in this section
    1 AMLR Arts 9-18 2 AMLR Art 10 3 AMLR Art 11 4 AMLR Arts 12-14 5 AMLR Arts 16-17
    Section 25

    Who supervises AMLR, and what does AMLA do?

    AMLA is the most misunderstood part of the package. The short answer is that for most obliged entities, the supervisor on 10 July 2027 is the same national authority as today.

    The Anti-Money Laundering Authority was created by Regulation (EU) 2024/1620, which applies from 1 July 2025. The Commission was responsible for its establishment and initial operation until 31 December 2025.1 2

    Fig 31Who supervises whomA few dozen, not thousands
    AMLA direct supervision

    Credit and financial institutions and groups whose residual risk profile is classified high. Art 13(1)

    Up to 40 in the first selection round Art 106(2) ; a number greater than 40 may be agreed subsequently. Art 13(2)

    First selection commences by 1 July 2027, concludes within six months, direct supervision begins six months after the list is published. Art 13(4)

    National supervisors

    Everyone else. Powers, resources, risk-based supervision, colleges and cooperation sit in AMLD6. AMLD6 Arts 37-52

    This is where almost every obliged entity in the EU sits on 10 July 2027: the directly supervised cohort is a few dozen entities out of many thousands.

    For everyone outside the selected cohort, AMLA still matters, but indirectly. It writes regulatory and implementing technical standards, issues guidelines, oversees national supervisors and supports FIU cooperation. The Article 28 CDD RTS and the Article 26(5) monitoring guidelines are AMLA products, and they will shape day-to-day practice far more than direct supervision will.

    The 40 figure is a first-round floor

    AMLA is not permanently capped at 40 entities. Article 13(2) allows a specific different number greater than 40 to be agreed with supervisors. The hard 40 applies only to the first selection process under Article 106(2).

    Referenced in this section
    1 AMLA Reg Art 108 2 AMLA Reg Art 107
    Section 26

    What are the penalties for non-compliance?

    Penalties sit in two instruments, and neither of them is AMLR.

    AMLR Article 68 is not the penalty article

    AMLR Article 68 is titled “Penalties” but covers Chapter IV, beneficial ownership transparency, only. It delegates to Member States and contains no monetary figure. Citing it for the EUR 10 million number is wrong.

    Tier 1, national penalties for most obliged entities

    AMLD6 requires Member States to make pecuniary sanctions available for serious, repeated or systematic breaches of AMLR Chapter II (internal policies), Chapter III (customer due diligence), Chapter V (reporting) and Article 77 (record retention), and for non-compliance with administrative measures.1

    Fig 32Three penalty tiers, two instrumentsMinimum maxima
    Tier 1Obliged entities generally
    At least twice the benefit derived from the breach where determinable, or at least EUR 1,000,000, whichever is higher AMLD6 Art 55(2)
    Tier 2Credit & financial institutions
    Legal persons: at least EUR 10,000,000 or 10% of total annual turnover, whichever is higher. Natural persons: at least EUR 5,000,000 AMLD6 Art 55(3)
    Tier 3AMLA direct supervision
    Basic amounts by breach category, capped at 10% of turnover for CDD/group-policy/reporting breaches, or EUR 10,000,000 for other breaches AMLA Art 22(6)-(7)

    Minimum maxima · floors on the ceiling each Member State must provide, not the sanction a firm will face

    Three qualifications travel with the headline number. AMLD6 says “maximum pecuniary sanctions of at least”, which makes it a floor on the ceiling. The EUR 10 million and 10% tier applies only to credit and financial institutions; every other obliged entity sits on the EUR 1 million tier. And Member States may empower authorities to exceed these amounts, while ability to pay must be taken into account.2

    Tier 3 is structured differently, and the difference matters

    For entities under AMLA direct supervision the structure is not “EUR 10 million or 10%, whichever is higher”. AMLA sets a basic amount within ranges that vary by breach type and by whether the breach spans one Member State or several, adjusts it using aggravating and mitigating coefficients, and then applies one of two separate caps depending on the breach category.3

    Writing the two regimes as though they share a formula is the most common error in AMLR penalty commentary.

    Periodic penalty payments

    Less discussed, and operationally sharper. Where an obliged entity fails to comply with certain administrative measures within the deadline, supervisors may impose periodic penalty payments until it does. They are capped at 3% of average daily turnover for legal persons, or 2% of average daily income for natural persons. They run for no more than six months, extendable once by a further six months.4

    A sanction is a single event. A periodic penalty payment accrues daily until the control is fixed.

    Referenced in this section
    1 AMLD6 Art 55(1) 2 AMLD6 Art 55(4)-(5) 3 AMLA Reg Art 22(3)-(7) 4 AMLD6 Art 57
    Section 27

    How should organisations prepare for AMLR?

    National supervisors remain responsible for most obliged entities. AMLA will coordinate the EU system and directly supervise only a selected group of higher-risk cross-border financial entities, with preparations for the 2027 selection exercise under way and direct supervision expected from 2028.

    Fig 33Eight readiness workstreamsWhere to start
    01ScopeEntity, branch, service and national-overlay register
    02RequirementsArticle-to-control inventory with accountable owners
    03RiskUpdated business-wide risk assessment
    04Customer dataRemediated identity, ownership and stale records
    05OnboardingFuture-state CDD, KYC/KYB and remote process
    06Lifecycle controlsValidated screening, monitoring and reporting
    07GovernanceUpdated roles, outsourcing, reliance, training, assurance
    08Regulatory changeLevel 2 tracker and controlled implementation plan

    Those four are the fastest way in. The full readiness checklist runs the same method across eight domains and 35 checks.

    A gap analysis is the practical starting point, and it is more specific than a generic readiness assessment. Four questions produce most of the findings:

    Does any rule, form or engine still test beneficial ownership at > 25% rather than >= 25%? Art 52(1)
    Can you evidence the date on which each customer’s information was last updated, and does any population exceed the one-year or five-year cap? Art 26(2)
    Do your KYB records capture LEI, principal place of business and nominee status? Art 22(1)(b)
    Can you produce, for any customer, the reasoning behind a closed alert and the person who closed it?

    Where the work concentrates, by sector

    Credit and financial institutions verify sanctions on any new designation, not only at review points, and sit on the penalty band of EUR 10,000,000 or 10% of total annual turnover. Art 26(4) AMLD6 Art 55(3) A few dozen will also fall into AMLA’s directly supervised cohort. AMLA Art 13
    Crypto-asset service providers are the only sector running two rulebooks on different clocks. TFR travel-rule duties have applied since 30 December 2024. AMLR then adds the EUR 1,000 occasional-transaction trigger, self-hosted address risk mitigation, correspondent duties and the anonymity prohibitions from 10 July 2027. Art 19(3) Art 40 Art 37 Art 79
    Trust and company service providers sit inside the Article 34(5) high-net-worth gate alongside credit and financial institutions, and are the sector most exposed to the rebuilt ownership layer in Articles 51 to 55. Art 34(5) Arts 51-55
    Estate agents and real-estate professionals should note that both parties to the transaction count as customers. Art 19(6)(c) That doubles the due-diligence population on every deal.
    Traders in high-value goods acquire a reporting duty they have not had before: threshold reports to the FIU at EUR 250,000 for motor vehicles and EUR 7,500,000 for watercraft and aircraft, on non-commercial acquisitions only, plus the EUR 10,000 cash ceiling. Art 74(1) Art 80(1)
    Football agents and clubs have two extra years, to 10 July 2029. Art 90 Clubs should establish whether a Member State exemption applies before building anything. Art 5
    Start with what the final text already settles

    Scope analysis, governance, data remediation, ownership logic, architecture and testing can proceed now. Keep draft-dependent details configurable and give them a final-text review before closing implementation.

    The platform

    Where Shufti fits the AMLR lifecycle

    AMLR does not split neatly into products. It runs as one lifecycle: identify, verify, establish ownership, assess risk, screen, monitor, refresh, report. Shufti is a glocal platform that runs that full compliance lifecycle, from sign-up and onboarding through authentication and monitoring to remediation, across 240+ countries and territories and 10,000+ document types actively verified each month.

    For remote onboarding it supports both Article 22(6) routes, and it is prepared to accept European Digital Identity Wallet attributes as EUDI Wallets become available. Its single-selfie passive liveness is assessed at iBeta PAD Level 3 under ISO/IEC 30107-3 on both iOS and Android, returning 0% APCER and 0% BPCER. Shufti was the first European company to achieve that conformance.

    Identity Verification

    The Art 22(6)(a) route, and the compliant fallback where a primary electronic route is unavailable. Document and biometric checks against reliable, independent sources

    KYC

    The Art 22(1)(a) attribute set, including place of birth, national identification number and tax identification number where available

    KYB

    Art 22(1)(b) entity data, UBO mapping across Arts 51 to 55, and the register-discrepancy duty in Art 24

    AML Screening

    Sanctions, PEP and adverse-information screening with human-review workflows for identity resolution and escalation

    Ongoing Monitoring

    The four Art 26 clocks, including event-driven refresh and the Art 26(4) sanctions verification duty

    eIDV

    Electronic identity verification where a notified eID scheme is available at substantial or high

    Explore each capability: Identity Verification · KYC · KYB · AML Screening · Ongoing Monitoring · eIDV

    AMLR’s real test is whether identity, ownership, screening, monitoring and reporting behave as one connected record. Where those functions sit with separate suppliers, officers reconcile them by hand, and the context needed to resolve an alert arrives late or not at all.

    One lifecycle, one record

    AMLR’s real test is whether identity, ownership, screening, monitoring and reporting behave as one connected record. The verified identity captured at onboarding should be the same record that screening, monitoring and reporting rely on for the life of the relationship.

    One glocal platform. The full compliance lifecycle, from sign-up to remediation. Every industry, every region, every use case.

    References

    Key legal and regulatory sources

    Scope of this guide

    This guide provides general regulatory information, not legal advice. Final AMLA measures, Member State rules, sector legislation and applicable sanctions should be assessed for the organisation’s own circumstances. Draft Level 2 measures are identified as draft throughout and should be re-checked against the adopted text before implementation is closed.

    Last reviewed 28 July 2026.

    © 2026 Shufti Ltd. All rights reserved. Registered in England and Wales, company number 11039567.

    EU AMLR: The Complete Guide to 2027 Compliance — cover EU AMLR guide — page EU AMLR guide — page EU AMLR guide — page
    Previous
    01 - 04
    Next

    Certifications

    Independently audited and certified for enterprise-grade security and data protection.

    • GDPR
    • GDPR Fundamentals
    • ISO 27001 Certified
    • CCPA
    • iBeta Level 1 — ISO 30107-3 Compliant
    • iBeta Level 2 — ISO 30107-3 Compliant
    • PCI DSS Compliant
    • Shufti SOC 2 Type 2 Compliant

    Frequently asked questions (FAQs)

    Start with scope: confirm which entities, branches and activities are covered, then inventory each obligation against a named control owner. Risk assessment, customer data remediation, onboarding, lifecycle controls, governance and a Level 2 tracker follow from there.

    Four questions produce most of the findings: does any rule engine still test beneficial ownership at > 25% rather than >= 25%, can you evidence when each customer’s information was last updated, do your KYB records capture LEI, principal place of business and nominee status, and can you produce the reasoning behind any closed alert.

    Scope analysis, governance, data remediation, ownership logic, architecture and testing can all proceed now. Keep draft-dependent details configurable and give them a final-text review before closing implementation.

    Shufti’s AMLR readiness checklist maps the Regulation’s obligations to the controls each one requires, so the gap analysis can be worked against a single list rather than against the Regulation itself.

      search_cross_mobile

      Please complete the information below 
to download the whitepaper

      By clicking the "Submit" button, you are agreeing 
to the Terms & Conditions and Privacy Policy

      n-img-roi-cross

      Form submitted successfully!

      Thank you for your interest — your report is loading now.

      Get the full guide

      Download the AMLR guide as a PDF

      The same 27 sections, all 33 figures and the full sources list, laid out for reference and internal sharing.

      • Share it with legal, product and engineering in one document
      • Every draft Level 2 measure flagged as draft
      • Updated 28 July 2026

        Let’s Tailor Your Journey

        Which products would you like to check out?

        VideoIdent

        Address Verification

        eIDV (Docless)

        KYB

        AML Screening

        Deepfake Detection

        Face and ID Verification

        Age Verification

        Others

        What is your expected yearly verification volume?

        1 to 1,000

        1,001 to 5,000

        5,001 to 20,000

        20,001 to 50,000

        50,001 to 100,000

        100,001 to 1,000,000

        1,000,000+

        Valid Invalid number

        By clicking Submit, you accept our Privacy Policy and consent to marketing communications.

        Product Guide

        APAC Child Safety Age Verification Regulations

        apac-child-safety-age-verification-regulations-ftr-img
        Product Guide

        Docless Identity Verification in the Middle East

        docless-identity-verification-middle-east
        Product Guide

        The Future of Docless Verification in Europe

        docless-identity-verification-europe=ftr-img
        Product Guide

        Cyprus 2026 KYC Operators Guide to Improve First Pass Rate

        Cyprus KYC Pass Rate Guide Ftr Img
        Product Guide

        Philippines KYC & Account-Owner Verification Playbook | Shufti

        philippines-account-owner-verification-ftr-image
        Product Guide

        Digital Lending KYC Guide for Mexico: INE/IFE, CURP, RFC, Liveness and AML Controls

        Mexico Digital Lending KYC Ftr Img
        Product Guide

        CySEC Forex KYC Compliance Handbook 2026 | Shufti

        Cysec Forex KYC Compliance Feature Image
        Product Guide

        Singapore KYC & AML Compliance Guide 2026 | Shufti

        Webinar banner for Redefining AML Decisioning The Future is Contextual Screening
        Product Guide

        Mexico 2026 KYC Handbook to Improve First Pass Rate

        Mexico 2026 KYC Pass Rate Handbook Featured Image
        Product Guide

        Where Can Identity Data Legally Live? 2026 Guide | Shufti

        Data Residency Guide Feature Image
        Product Guide

        Shufti Deepfake Fraud Index Report: Deepfake Fraud Set to Surge 495% in 2026

        Deepfake Identity Fraud Index Report 2026 Featured Image
        Whitepaper

        KYC Compliance and Identity Fraud Challenge Across APAC

        Product Guide

        Brazil Bets KYC Playbook for .bet.br Operators 2026 | Shufti

        Venn diagram showing overlap of Fraud and AML with operator liability
        Product Guide

        Malta iGaming KYC & AML Readiness Guide 2026| Shufti

        Globe topped with Malta landmark buildings and a Malta flag label
        Product Guide

        Brazil 2026 KYC Playbook to Improve First Pass Rate

        Featured Image
        Product Guide

        Malta 2026 KYC Playbook to Improve First Pass Rate

        Malta 2026 KYC Playbook To Improve First Pass Rate Feature Image
        Whitepaper

        The Deepfake Detection Gap

        Product Guide

        Choosing the Right Identity Verification Vendor for the Forex Sector

        Forex Guide Feature Image
        Product Guide

        A Comprehensive Guide to Address Verification in Complex Markets

        A comprehensive guide to address
        Whitepaper

        Beyond Benchmark Accuracy: Making Deepfake Detection Work for IDV Systems

        Sphere Cover Whitepaper
        Product Guide

        Human – Assisted Video KYC for Regulated Businesses:

        Video KYC Guide
        Whitepaper

        Re-Thinking RegTech for KYC Compliance

        Product Guide

        Enterprise Guide to Choose Right Identity Verification Solution

        Guide Feature Image
        report

        Global Age-Verification Laws 2025 Snapshot

        Global Age
        Whitepaper

        The Backbone of Global Trust

        The Backbone of global trust
        report

        State of Global AML Compliance 2025

        AML Laws Insight Image
        Product Guide

        Strategic ID Verification Vendor for Crypto Industry

        Feature Image Buyers Guide
        report

        Market Positioning and Commercial Assessment Results Presentation

        Report Market
        Whitepaper

        Preventing Account Takeover Fraud with Multilayered Defense

        Preventing Account Takeover
        Whitepaper

        The Critical 1% Closing Systemic Gaps In Global Identity Verification

        Shifti Whitepaper 1 Percent
        report

        Outsmarting the Deepfake Threat to Identity Trust

        n-img-outstand
        Product Guide

        Scale Without Borders

        n-img-scale-without
        report

        Streamlining Identity Verification: How Shufti Secure Capture Enhances Accuracy and Trust

        new report feature iamge
        report

        Top 10 Most Difficult Countries for Identity Verification

        n-img-report-top-10
        Whitepaper

        KYC & AML IN THE MENA Region White Paper 2023

        Whitepaper

        Shufti’s iGaming White Paper 2023

        report

        Shufti Identity Fraud Report 2022

        Frame 953
        report

        Shufti Fraud Report 2021

        Frame 953 (1)
        report

        Holiday Season – The Prime Time for ID Thieves and Financial Criminals

        Frame 996
        report

        Shufti Completes 4 Years of Fighting ID Fraud

        Frame 997
        report

        On-premises Identity Verification for the Banking Sector

        Frame 998
        report

        Shrinking the Space for Travel Industry Scams with Biometric Verification

        Frame 999
        Whitepaper

        Global Gambling Compliance: Regulations, Age Checks & Financial Safety

        Frame 1000
        report

        A comprehensive guide to KYC and AML compliance in Canada

        Frame 1001
        n-img-roi-cross

        Form submitted successfully!

        Thank you for your interest — your report is loading now.

        Take the next steps to better security.

        Contact us

        Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

        Contact us

        Get the Shufti newsletter

        Stay ahead of the curve with fresh takes on the latest identity innovations.

          Take the next steps to better security.

          Contact us

          Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

          Contact us

          Request demo

          Get free access to our platform and try our products today.

          Get started

          Pitch a piece and get a verified byline in the Media room.

          Partnership Inquiries?
          Email us at [email protected]

          iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
          Copyright © 2026 Shufti. All rights reserved.