Enterprise Guide to Remediate Existing Customer and Business Files under EU AMLR
From 10 July 2027, one EU rulebook judges every legacy customer file. This guide shows compliance teams how to find CDD gaps, triage existing relationships into five outcomes and close files with decisions another reviewer can reconstruct.
Schedule a DemoThe Existing Book Is Where AMLR Bites First
From 10 July 2027, Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation (AMLR), applies as a directly applicable baseline across the Union. The duties are older than the Regulation; the level of consistency and precision expected across the existing customer book is what changes.
Most enterprises do not hold a blank book. They hold years of identity records, company documents, ownership charts, screening results and risk decisions, spread across systems and created under different national rules. The gap is rarely absence: the firm often cannot show quickly that what it holds is still current, reliable and sufficient for the relationship that exists today.
AMLR does not require every existing customer to be re-onboarded on the same day. It does require the existing book to support current, risk-based and traceable decisions.
What follows is a controlled remediation programme, not a one-day refresh of every old file. Much of the programme runs on comparison and internal evidence, and a file that passes closes without the customer ever being contacted.
A controlled exercise that defines what a complete customer file must show, compares the existing book against that standard, moves the riskiest or most uncertain cases first, updates only what needs work, and keeps enough evidence to reconstruct each decision.
Four Numbers Set the Shape of AMLR Remediation
Four numbers govern the exercise: AMLR applies from 10 July 2027, Article 26 caps the gap between customer-file updates at one year for higher-risk customers and five years for everyone else, and beneficial ownership now starts at 25% or more of shares, voting rights or other ownership interest.
Risk can shorten either update period, never stretch it, and the maximum periods are not default review cycles. Before AMLR, no EU rule set a refresh frequency at all; Ireland’s law, for example, asked firms to monitor as far as risk warranted and set no deadline.
AMLR applies as one directly applicable EU baseline
Maximum gap between file updates for higher-risk customers (Article 26)
Maximum update gap for everyone else; risk shortens, never stretches
Beneficial-ownership threshold under Article 52, replacing more-than-25%
Source: Regulation (EU) 2024/1624, Articles 26, 52 and 90
As at 31 July 2026, the surrounding detail is still moving: the consultation by the EU Anti-Money Laundering Authority (AMLA) on the draft regulatory technical standards (RTS) for customer due diligence (CDD) closed on 8 May 2026, and the consultation on the draft ongoing-monitoring guidelines runs until 3 September 2026. Neither instrument is adopted, and the remediation clock does not wait for either.
8 May 2026: AMLA consultation on the draft CDD RTS closed; instrument still draft
Closed on 3 September 2026: consultation on the draft ongoing-monitoring guidelines has been finished; not adopted as at 09 Sep 2026
10 July 2027: AMLR applies across the EU
Six AMLR Changes Can Reopen Existing Customer Files
Six changes in AMLR can require an existing customer file to be reopened, updated or reassessed: update intervals, event-triggered reviews, individual identification data, business identification data, the beneficial-ownership threshold and its calculation, and politically exposed person (PEP) functions and family members.
AMLR does not make every legacy file defective. Many of the underlying duties existed under the Fourth Anti-Money Laundering Directive (AMLD4), Directive (EU) 2015/849, the pre-AMLR EU baseline, and national rules may already have been stricter or more detailed. The cards below compare each change against that baseline and name the check it triggers across the book.
Customer-File Update Intervals
No EU rule said how often files must be refreshed. Ireland’s law, for example, asked firms to monitor as far as risk warranted and set no deadline.
Article 26 caps the gap between updates at one year for higher-risk customers and five years for everyone else. Risk can shorten either, never stretch them.
Find files already beyond, or approaching, the relevant maximum. Do not treat one or five years as the default for every customer.
Reviews Before the Scheduled Date
Files were reviewed when something known changed, such as a customer’s circumstances. Germany’s law worked the same way; learning a new fact was not a written trigger on its own.
The same occasions stay, and Article 26(3) adds a third trigger in writing: the firm becomes aware of a relevant fact concerning the customer.
Make sure new facts, monitoring findings and verified changes can reopen a file instead of waiting for the next scheduled review.
Individual Identification Data
Every country wrote its own list of personal details. Germany’s law, for example, asked for five basics, name, birth details, nationality and address, and never asked for a tax number.
Article 22 fixes the set for standard CDD: all names and surnames, place and full date of birth, nationality and specified status information, national ID where applicable, usual residence or contact address, and tax ID where available.
Map legacy individual files against the Article 22 fields. Collect only information that is missing, outdated, doubtful or required for the current risk.
Business Identification Data
The EU baseline fixed no single entity data set. What a business file held came from national rules, and lists differed between countries.
Article 22 specifies legal form and name; registered or official office; principal place of business and country of creation; legal representatives; available registration, tax and LEI identifiers; and the names and status of nominee shareholders or directors.
Flag files that cannot evidence the entity’s current legal form, locations, representatives, identifiers or nominee roles.
Beneficial-Ownership Threshold and Calculation
The EU indicator was 25% plus one share, or an ownership interest of more than 25%. Indirect ownership was recognised, but calculation practice could differ.
Article 52 uses 25% or more of shares, voting rights or other ownership interest. Indirect interests are multiplied down each chain, results from different chains are added, and every ownership level is considered.
Rerun structures involving exactly 25% and layered holdings. Test control by other means separately; ownership percentage is not the only route to beneficial ownership.
PEP Functions and Family Members
The EU minimum covered senior national functions. Family members were spouses or equivalent partners, children and their partners, and parents; siblings were not included.
AMLR expressly includes heads of regional and local authorities, municipal groupings and metropolitan regions with at least 50,000 inhabitants. Siblings are added as family members only for heads of State or government, ministers, deputy or assistant ministers, and equivalent EU or third-country functions.
Extend role and relationship screening, but do not label every PEP’s sibling a family member. Apply the sibling rule only to the functions AMLR names.
Directive (EU) 2015/849, Articles 3(6), 3(9)-(10) and 13-14; Regulation (EU) 2024/1624, Articles 2(34)-(35), 22, 26, 52 and 90.
Two of the changes reset data expectations outright. Article 22 fixes the individual data set for standard CDD, down to nationality, status information and identifiers, and specifies the business set from legal form through registration, tax and LEI identifiers to nominee roles. A third review trigger also arrives in writing under Article 26(3): the firm becomes aware of a relevant fact concerning the customer, which lets monitoring findings reopen a file before its scheduled date.
The programme has to keep one distinction visible at all times: final law, draft detail and firm decisions are three different things, and only the first is settled.
Final Law
AMLR applies from 10 July 2027 and Article 26 sets the ongoing-monitoring, update and event-review framework.
Draft Detail
AMLA’s February 2026 CDD RTS and June 2026 ongoing-monitoring guidelines are not yet adopted, as at 31 July 2026.
Firm Decision
Prioritisation, outreach, escalation, quality assurance and case ownership remain part of each firm’s operating model.
AMLA’s draft CDD RTS proposes that information on customers already in a relationship be brought into line on a risk-sensitive basis within the Article 26 periods, with those periods starting when the future delegated regulation applies. Firms should treat that as a planning assumption for building the inventory now, not as a statutory deadline, and never present draft dates as adopted law.
Article 26 also turns file maintenance into a continuing cycle rather than a diary entry.
Monitor the relationship
Check that activity remains consistent with the customer, the relationship purpose and current risk.
Update at risk-based intervals
Maximum one year for higher-risk customers and five years for everyone else; risk may require earlier review.
Reopen when circumstances change
Review the file early when relevant circumstances change, a specified legal-contact duty applies, or the firm learns a relevant new fact (Article 26(3)).
Verify targeted financial sanctions
Check customers and beneficial owners on a separate Article 26(4) cadence.
The maximum periods are caps, not default review cycles.
A Remediated File Connects Verified Facts to the Current Risk Decision
A remediated customer file is a record that connects verified facts to the current risk decision, not a folder full of documents. No firm can find gaps until it defines the file it wants to finish with, and Articles 20, 22, 25 and 26 of AMLR define that target.
| The File Must Show | Individual Customer | Business Customer |
|---|---|---|
| Identity | Names, date and place of birth, nationality and residence or contact information, with suitable verification evidence. | Legal name, form, registration and tax identifiers where available, registered office, principal place of business and country of creation. |
| People connected to the relationship | Any authorised person or other person on whose behalf or for whose benefit activity is conducted. | Legal representatives, authorised persons, directors where relevant, beneficial owners and anyone exercising control by other means. |
| Purpose and expected activity | Why the relationship exists, expected use and activity, and occupation where relevant. | Business activity, economic rationale, expected products, activity and flows, with source and destination of funds where necessary. |
| Risk and screening | Current risk assessment, PEP status, targeted financial-sanctions checks and other screening required by policy. | Entity and connected-party risk, ownership complexity, geography, PEP and targeted financial-sanctions exposure, plus relevant screening. |
| Decision evidence | Reason for review, information used, reviewer, outcome and next review point. | Ownership rationale, verification sources, unresolved issues, approvals, outcome and next review point. |
For an individual, the file establishes identity, relevant residence information, the purpose of the relationship, expected activity, screening results and current risk. A business file follows the same logic and must also explain the legal entity, its authorised representatives, and its ownership and control.
Regulation (EU) 2024/1624, Articles 20, 22, 25 and 26.
Registration Evidence Is Not Ownership Evidence
Business remediation is usually heavier because a current certificate of incorporation does not, by itself, show who ultimately owns or controls the customer. Current register information establishes legal existence and supports the ownership review; the firm must still test that the recorded ownership and control picture is complete, plausible and consistent with other evidence.
Where no beneficial owner can be identified after all possible means have been exhausted, AMLR requires that outcome and the steps taken to be recorded. The senior-managing-official route is not a shortcut around an incomplete ownership assessment.
The threshold is now 25% or more, where the pre-AMLR baseline said more than 25%. A holder sitting at exactly 25% counts today, and may be absent from a file built under the old wording.
Every business file reaches a point where its ownership information is rechecked, either on its review cycle or sooner when an event pulls it forward. What that recheck means varies, and it rarely means rebuild: where the owners on file still match the registers and nothing signals a change, the firm confirms and records, and reconstruction is reserved for structures that are old, incomplete or contradicted. Every business review still re-runs the threshold test and the separate control-by-other-means check.
The Completion Test. Could another trained reviewer open the file and understand what was checked, what changed, how risk was assessed, who made the decision and when the relationship must next be reviewed? If not, the file is not finished.
Turn Existing Customer Data Into Remediation-Ready Evidence
AMLR remediation runs on reliable identity, business, ownership and screening evidence. See how Shufti turns your existing book into evidence a reviewer can trace.
Book a DemoFive Outcomes Triage the Book Before Any Customer Hears From You
Assessment starts with the book, not with outreach. Outreach that comes first creates unnecessary friction and usually produces a poor estimate of the work, because the firm already holds much of what it needs to grade each file.
An inventory per relationship brings together customer type, current risk level, last completed review, available identity or entity evidence, ownership information, screening status, known trigger events, open alerts and unresolved exceptions. The book is then compared, file by file, with the target standard from the previous section.
That comparison should separate a real information gap from a storage or retrieval problem. A reliable fact already held may still be usable; a document may be present yet no longer prove the current position; a record may be current yet lack the reasoning that connects it to the risk decision. Each file then takes exactly one of five outcomes.
Current
No customer contactInformation and evidence remain sufficient for the present risk.
Confirm the review and retain the record.
Confirm or Reuse
Reliable information exists, but its current relevance must be checked.
Confirm through internal or reliable independent sources.
Update
A defined field, document or screening result is outdated.
Refresh only the affected information.
Investigate
Material evidence is missing, inconsistent or cannot be validated.
Obtain further evidence and resolve the conflict.
Escalate
Risk has increased, CDD cannot be completed, or the case may require EDD, restriction, exit or reporting consideration.
Route to the authorised decision-maker.
Where every field is present, supported and undisturbed by doubt, the file takes outcome 1, Current, and the customer never hears from you.
The first outcome keeps the exercise honest, and files earn it by comparison, not by assumption. For individuals the comparison is concrete because Article 22 fixes the data set down to names, birth details, nationality, identifiers and addresses. Files missing defined fields, common wherever onboarding ran under an older national regime, take outcome 3, Update, and join the queue.
Triage is also what contains the cost. Outcomes 1 and 2 close from internal records and reliable independent sources, so outreach effort concentrates on the files that genuinely need customer input, and the programme stays smaller than the book it covers.
A large book needs a living queue, not one fixed campaign list. Priority rises where a trigger event has occurred, the customer is higher risk, the gap is material, the evidence is old or unreliable, ownership or control has changed, sanctions exposure may exist, activity no longer fits the profile, or the next required review is approaching.
Current: outside the active queue
A living queue, re-ranked as facts arrive, not one fixed campaign list.
Practical Rule. Do not contact every customer. Contact the customer when the required information cannot be confirmed, reused or obtained from an appropriate source, or when the firm needs the customer to explain a change or inconsistency.
One Eight-Step Process Remediate Individual and Business Files
One controlled process should remediate both individual and business files. The two paths contain different evidence, and splitting them into separate operating models makes ownership, escalation and quality assurance harder to control.
Its sequence runs from a recorded reason to a reconstructable decision. Steps three and four carry the outreach discipline: the firm checks what it can confirm or reuse from internal records, recent checks and official registers before asking the customer for anything, then collects only what is missing, outdated or doubtful, recording each attempt.
Open the case
Record why it exists: scheduled review, trigger event, missing-data assessment, monitoring alert, sanctions or PEP development, or a quality finding.
Identify the exact gap
State the problem area: identity, legal existence, authority, ownership, purpose, expected activity, screening, risk or completion evidence.
Confirm or reuse first
Review internal records, recent checks, official registers and other suitable sources before asking the customer.
Collect only what is missing
Request only the missing, outdated or doubtful items; explain what is needed, why, and the response route; record each attempt.
Verify people and entity
Individual: identity and relevant personal information. Business: legal existence, authority, ownership, control and beneficial owners.
Refresh screening and risk
PEP status, targeted financial sanctions, adverse information and other required screening; compare expected activity with what was observed.
Make the relationship decision
Confirm or update, apply EDD, obtain senior approval, restrict activity, escalate for exit, or consider suspicion under the reporting process.
Record and return to monitoring
Store evidence, reasoning, approvals, completion date and next review point; close only when the decision can be reconstructed.
One process for individual and business files; only the evidence at step 5 differs.
Two Hard Rules Protect the Programme
Silence and contradiction are the two situations that test the programme’s integrity, and neither can be closed by a system default. Non-response is never a decision by itself, conflicting evidence is never averaged into a clean field, and both routes end in a recorded human decision.
Rule 1: Non-Response
- Record every contact attempt and check what suitable sources can supply instead.
- Weigh the customer’s risk and the materiality of the missing information, then follow the firm’s escalation rules.
- Where the gap prevents completing the Article 20(1) CDD measures, Article 21 requires refraining from transactions or new relationships; for an existing relationship, terminating it and considering a suspicion report, subject to the Regulation’s specific exceptions and alternatives.
- Technology should not decide that outcome.
Rule 2: Conflicting Evidence
- Identify the conflict and obtain a more reliable source or explanation.
- Determine what the difference changes: identity, authority, ownership, purpose or risk.
- Record how it was resolved.
- Route differences with the central beneficial-ownership register through Article 24’s discrepancy process, including its limited correction route for specified minor or outdated entries.
A Worked Example: An Ownership Change at Northbridge ICT
Northbridge ICT is a hypothetical medium-risk business customer. Monitoring identifies a registry update: a new shareholder now holds 30% and one director has left, while the file still shows the old ownership chart and names the departed director as an authorised representative.
Hypothetical ExampleOpen an event-driven review and record the registry change as the trigger.
Obtain current entity and representation information; reconstruct the ownership chain.
Identify and verify the new beneficial owner; confirm who is authorised to act.
Screen the entity, the new owner and relevant connected parties; resolve any matches.
Compare revised ownership, geography and expected activity with the existing risk assessment.
Record the decision, any approval, the updated risk rating and the next review date.
Verified, no material adverse information, activity still fits: update and continue
Ownership unclear or risk higher: enhanced review or escalation
The trigger starts the review; it does not predetermine the outcome. A verified new owner, no material adverse information and activity that still matches the relationship mean the firm updates the file and continues. Ownership that stays unclear, or a change that raises the risk, moves the case to enhanced review or escalation.
A File Is Finished When Another Reviewer Can Reconstruct the Decision
Completion is the point at which current evidence supports a current decision and the record explains how that decision was reached. The date on which the last document arrived proves nothing on its own.
Reconstruction rests on the closure record, and it has eight parts.
Why the review began
What the firm already held
What was missing, outdated or inconsistent
Which information was confirmed, reused or collected
Which verification and screening checks were performed
How the risk view changed
Who decided and approved the outcome
When the relationship will next be reviewed
Eight entries that let a second reviewer reconstruct the decision.
| Element | Stale File | Remediated File |
|---|---|---|
| Identity or entity information | Old information with no current assessment | Current evidence, or a recorded basis for confirming that existing evidence remains suitable |
| Ownership and control | Ownership chart without verification or control rationale | Beneficial owners and verification sources recorded; control understood |
| Screening | Result saved without match resolution | Result, reviewer outcome and effect on risk recorded |
| Risk decision | Risk score with no explanation | Risk factors, judgement, approval and resulting classification connected |
| Closure | No future review point | Completion date, next review date and monitoring route recorded |
Once closed, the file returns to periodic review, event-trigger monitoring, transaction or activity monitoring where applicable, PEP and sanctions screening, exception management and quality assurance. Remediation clears a known gap. Ongoing monitoring is what stops the file becoming stale again.
What to Fix Before Scaling
A good pilot can still fail at full volume if nobody has decided who owns the queue, who can approve higher-risk outcomes, what non-response means, or what evidence closes a case. Nine building blocks belong in place before large-scale outreach, from a single customer-file standard and one inventory of relationships through named case owners and decision rights to completion criteria, quality assurance and management reporting.
Settle these before any large-scale outreach begins.
Firms should test the process on six representative files before scaling it across the full book. The pilot should show where data cannot be retrieved, which checks can be reused, where hand-offs stall and where a final decision cannot be reconstructed. A fault found on six files costs little; the same fault found mid-campaign does not.
A straightforward individual
Proves the happy path closes cleanly
An expired document
Tests targeted refresh without full re-onboarding
A higher-risk customer
Tests EDD routing and senior approval
A business with layered ownership
Tests chain calculation and control checks
A non-responsive customer
Tests outreach records and escalation rules
A case with conflicting evidence
Tests resolution before closure
Shufti Supplies the Evidence; the Firm Makes the Decision
Verification, screening and registry outputs support remediation decisions; the obliged entity makes them. AMLR draws that line itself: the entity stays liable for outsourced tasks, and specified decisions, including the customer risk profile, entry into a relationship and suspicious-activity reporting, cannot be outsourced to any provider.
Shufti is a Glocal Platform built for the full compliance lifecycle, from sign-up, onboarding and authentication through monitoring to remediation, across every industry, region and use case. In a remediation programme it sits at the evidence layer, and the division of labour is explicit.
| Activity | Shufti Can Support | The Obliged Entity Remains Responsible For |
|---|---|---|
| Identity refresh | Document, biometric, NFC and electronic identity checks, configured for the required journey. | Deciding when re-verification is necessary and if the evidence is sufficient for the risk. |
| Business remediation | Entity verification, director and beneficial-owner identification, ownership mapping and connected-party checks. | Understanding ownership and control, resolving discrepancies and deciding if the relationship is acceptable. |
| Screening | PEP, sanctions, watchlist and adverse-media screening for individuals, entities and relevant connected parties. | Reviewing potential matches, assessing relevance and deciding how findings affect risk. |
| Ongoing controls | Continuous screening and monitoring signals that can identify changes after onboarding. | Defining triggers, thresholds, investigation standards and escalation routes. |
| Evidence | Verification results, screening outputs and traceable records from the checks performed. | Maintaining the complete CDD record, reasoning, approvals and retention controls. |
| Final outcome | Decision-support information and workflow inputs. | Assigning the risk profile and deciding to approve, restrict, report, continue or exit. These decisions cannot be outsourced. |
One Bulk Pass Shows Where the Book Has Drifted
Much of the evidence work runs in bulk. Shufti can re-screen an existing book against PEP, sanctions, watchlist and adverse-media data through AML screening built for batch re-checks, monitor it for status changes, and refresh business and beneficial-owner information from registry sources where coverage allows through business verification and ownership mapping, with results returned per customer and evidence attached.
One pass surfaces stale screening, new matches and ownership that no longer matches the file, without a single email to a customer. Identity re-verification still needs the customer to complete a check, through electronic identity verification against government registries or a document and biometric journey, which is one more reason to reserve outreach for files nothing else can close. Each result returns attached to the customer record as evidence, which is the shape the closure record needs.
No provider can see inside a firm’s own records, so the field-by-field comparison runs on the firm’s systems, with the bulk results feeding it as the freshest evidence. The firm builds the list. Shufti fills in what the world outside its records says about each file.
Technology cannot make a firm AMLR-compliant. The working question is different: can the operating model use verification, registry, screening and monitoring outputs to reach consistent human decisions across the existing book, and show the evidence later? Teams that prefer to build and price a stack without a sales conversation can configure a plan directly at any tier, and deployment references are available on request.
Firms should test the final Regulation and adopted AMLA instruments against their own activities, risk assessment, customer base and national supervisory expectations. Shufti provides technology, not legal or regulatory advice.
Prepare Your Existing Customer Book for AMLR
AMLR readiness starts with knowing where your current files stand. Walk through the evidence gaps and the remediation workflow with the Shufti team.
Book an AMLR Readiness SessionFrequently asked questions (FAQs)
No; AMLR requires the existing book to support current, risk-based and traceable decisions, not same-day re-onboarding. Firms meet that through a controlled remediation programme that compares each file against the target standard, and a file whose every field is present and supported closes as Current with no customer contact at all.
AMLR, Regulation (EU) 2024/1624, applies from 10 July 2027 as a directly applicable baseline across the EU. Many underlying duties already existed under the Fourth Anti-Money Laundering Directive; what changes for existing files is the consistency and precision expected, including fixed data fields and capped update intervals. Legacy files are not exempt; they are the main place the new precision shows.
Article 26 caps the gap between updates at one year for higher-risk customers and five years for everyone else, and risk can shorten either period but never stretch it. The caps are maximums, not default review cycles. A review also reopens early when circumstances change or the firm becomes aware of a relevant fact concerning the customer.
Article 52 sets beneficial ownership at 25% or more of shares, voting rights or other ownership interest, where the pre-AMLR baseline said more than 25%. A holder at exactly 25% therefore counts today and may be missing from files built under the old wording. Indirect interests are multiplied down each chain and added across chains, and control by other means is a separate, mandatory check.
Non-response is a fact to assess, not a decision in itself. The firm records its attempts, checks other appropriate sources, and weighs the customer’s risk and the materiality of the missing information. Where the gap prevents completing the Article 20(1) CDD measures, Article 21 requires refraining from transactions or new relationships and, for an existing relationship, terminating it and considering a suspicion report, subject to the Regulation’s specific exceptions and alternatives.
Remediation tasks can be supported by a provider; the decisions cannot be outsourced. A provider can supply verification, screening and registry evidence across the whole book, but AMLR keeps the obliged entity liable for outsourced tasks and prohibits outsourcing specified decisions, including the customer risk profile, entry into a relationship and suspicious-activity reporting. The workable split is evidence from the provider, with decisions and records owned by the firm.
No adopted instrument sets that start date. The draft CDD RTS proposes bringing existing-customer information into line on a risk-sensitive basis within the Article 26 periods, with those periods starting when the future delegated regulation applies. As at 31 July 2026 that instrument remains draft, so firms should plan with it without presenting its dates as statutory deadlines.
























