sg

13.215.197.171

Enterprise Guide to Remediate Existing Customer and Business Files under EU AMLR — guide cover
EU AMLR – Existing Customer Files

Enterprise Guide to Remediate Existing Customer and Business Files under EU AMLR

From 10 July 2027, one EU rulebook judges every legacy customer file. This guide shows compliance teams how to find CDD gaps, triage existing relationships into five outcomes and close files with decisions another reviewer can reconstruct.

Schedule a Demo

The Existing Book Is Where AMLR Bites First

From 10 July 2027, Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation (AMLR), applies as a directly applicable baseline across the Union. The duties are older than the Regulation; the level of consistency and precision expected across the existing customer book is what changes.

Most enterprises do not hold a blank book. They hold years of identity records, company documents, ownership charts, screening results and risk decisions, spread across systems and created under different national rules. The gap is rarely absence: the firm often cannot show quickly that what it holds is still current, reliable and sufficient for the relationship that exists today.

Compliance reviewer working through existing customer files
The Point

AMLR does not require every existing customer to be re-onboarded on the same day. It does require the existing book to support current, risk-based and traceable decisions.

What follows is a controlled remediation programme, not a one-day refresh of every old file. Much of the programme runs on comparison and internal evidence, and a file that passes closes without the customer ever being contacted.

Remediation programme

A controlled exercise that defines what a complete customer file must show, compares the existing book against that standard, moves the riskiest or most uncertain cases first, updates only what needs work, and keeps enough evidence to reconstruct each decision.

Four Numbers Set the Shape of AMLR Remediation

Four numbers govern the exercise: AMLR applies from 10 July 2027, Article 26 caps the gap between customer-file updates at one year for higher-risk customers and five years for everyone else, and beneficial ownership now starts at 25% or more of shares, voting rights or other ownership interest.

Risk can shorten either update period, never stretch it, and the maximum periods are not default review cycles. Before AMLR, no EU rule set a refresh frequency at all; Ireland’s law, for example, asked firms to monitor as far as risk warranted and set no deadline.

10 July 2027

AMLR applies as one directly applicable EU baseline

1 year

Maximum gap between file updates for higher-risk customers (Article 26)

5 years

Maximum update gap for everyone else; risk shortens, never stretches

25% or more

Beneficial-ownership threshold under Article 52, replacing more-than-25%

Source: Regulation (EU) 2024/1624, Articles 26, 52 and 90

As at 31 July 2026, the surrounding detail is still moving: the consultation by the EU Anti-Money Laundering Authority (AMLA) on the draft regulatory technical standards (RTS) for customer due diligence (CDD) closed on 8 May 2026, and the consultation on the draft ongoing-monitoring guidelines runs until 3 September 2026. Neither instrument is adopted, and the remediation clock does not wait for either.

8 May 2026: AMLA consultation on the draft CDD RTS closed; instrument still draft

Consultation Open

Closed on 3 September 2026: consultation on the draft ongoing-monitoring guidelines has been finished; not adopted as at 09 Sep 2026

Future Deadline

10 July 2027: AMLR applies across the EU

Six AMLR Changes Can Reopen Existing Customer Files

Six changes in AMLR can require an existing customer file to be reopened, updated or reassessed: update intervals, event-triggered reviews, individual identification data, business identification data, the beneficial-ownership threshold and its calculation, and politically exposed person (PEP) functions and family members.

AMLR does not make every legacy file defective. Many of the underlying duties existed under the Fourth Anti-Money Laundering Directive (AMLD4), Directive (EU) 2015/849, the pre-AMLR EU baseline, and national rules may already have been stricter or more detailed. The cards below compare each change against that baseline and name the check it triggers across the book.

Customer-File Update Intervals

Before AMLR: EU Baseline

No EU rule said how often files must be refreshed. Ireland’s law, for example, asked firms to monitor as far as risk warranted and set no deadline.

From 10 July 2027

Article 26 caps the gap between updates at one year for higher-risk customers and five years for everyone else. Risk can shorten either, never stretch them.

Remediation Check

Find files already beyond, or approaching, the relevant maximum. Do not treat one or five years as the default for every customer.

Reviews Before the Scheduled Date

Before AMLR: EU Baseline

Files were reviewed when something known changed, such as a customer’s circumstances. Germany’s law worked the same way; learning a new fact was not a written trigger on its own.

From 10 July 2027

The same occasions stay, and Article 26(3) adds a third trigger in writing: the firm becomes aware of a relevant fact concerning the customer.

Remediation Check

Make sure new facts, monitoring findings and verified changes can reopen a file instead of waiting for the next scheduled review.

Individual Identification Data

Before AMLR: EU Baseline

Every country wrote its own list of personal details. Germany’s law, for example, asked for five basics, name, birth details, nationality and address, and never asked for a tax number.

From 10 July 2027

Article 22 fixes the set for standard CDD: all names and surnames, place and full date of birth, nationality and specified status information, national ID where applicable, usual residence or contact address, and tax ID where available.

Remediation Check

Map legacy individual files against the Article 22 fields. Collect only information that is missing, outdated, doubtful or required for the current risk.

Business Identification Data

Before AMLR: EU Baseline

The EU baseline fixed no single entity data set. What a business file held came from national rules, and lists differed between countries.

From 10 July 2027

Article 22 specifies legal form and name; registered or official office; principal place of business and country of creation; legal representatives; available registration, tax and LEI identifiers; and the names and status of nominee shareholders or directors.

Remediation Check

Flag files that cannot evidence the entity’s current legal form, locations, representatives, identifiers or nominee roles.

Beneficial-Ownership Threshold and Calculation

Before AMLR: EU Baseline

The EU indicator was 25% plus one share, or an ownership interest of more than 25%. Indirect ownership was recognised, but calculation practice could differ.

From 10 July 2027

Article 52 uses 25% or more of shares, voting rights or other ownership interest. Indirect interests are multiplied down each chain, results from different chains are added, and every ownership level is considered.

Remediation Check

Rerun structures involving exactly 25% and layered holdings. Test control by other means separately; ownership percentage is not the only route to beneficial ownership.

PEP Functions and Family Members

Before AMLR: EU Baseline

The EU minimum covered senior national functions. Family members were spouses or equivalent partners, children and their partners, and parents; siblings were not included.

From 10 July 2027

AMLR expressly includes heads of regional and local authorities, municipal groupings and metropolitan regions with at least 50,000 inhabitants. Siblings are added as family members only for heads of State or government, ministers, deputy or assistant ministers, and equivalent EU or third-country functions.

Remediation Check

Extend role and relationship screening, but do not label every PEP’s sibling a family member. Apply the sibling rule only to the functions AMLR names.

Directive (EU) 2015/849, Articles 3(6), 3(9)-(10) and 13-14; Regulation (EU) 2024/1624, Articles 2(34)-(35), 22, 26, 52 and 90.

Two of the changes reset data expectations outright. Article 22 fixes the individual data set for standard CDD, down to nationality, status information and identifiers, and specifies the business set from legal form through registration, tax and LEI identifiers to nominee roles. A third review trigger also arrives in writing under Article 26(3): the firm becomes aware of a relevant fact concerning the customer, which lets monitoring findings reopen a file before its scheduled date.

The programme has to keep one distinction visible at all times: final law, draft detail and firm decisions are three different things, and only the first is settled.

Final Law

AMLR applies from 10 July 2027 and Article 26 sets the ongoing-monitoring, update and event-review framework.

Draft Detail

AMLA’s February 2026 CDD RTS and June 2026 ongoing-monitoring guidelines are not yet adopted, as at 31 July 2026.

Firm Decision

Prioritisation, outreach, escalation, quality assurance and case ownership remain part of each firm’s operating model.

AMLA’s draft CDD RTS proposes that information on customers already in a relationship be brought into line on a risk-sensitive basis within the Article 26 periods, with those periods starting when the future delegated regulation applies. Firms should treat that as a planning assumption for building the inventory now, not as a statutory deadline, and never present draft dates as adopted law.

Article 26 also turns file maintenance into a continuing cycle rather than a diary entry.

1

Monitor the relationship

Check that activity remains consistent with the customer, the relationship purpose and current risk.

2

Update at risk-based intervals

Maximum one year for higher-risk customers and five years for everyone else; risk may require earlier review.

3

Reopen when circumstances change

Review the file early when relevant circumstances change, a specified legal-contact duty applies, or the firm learns a relevant new fact (Article 26(3)).

4

Verify targeted financial sanctions

Check customers and beneficial owners on a separate Article 26(4) cadence.

The maximum periods are caps, not default review cycles.

A Remediated File Connects Verified Facts to the Current Risk Decision

A remediated customer file is a record that connects verified facts to the current risk decision, not a folder full of documents. No firm can find gaps until it defines the file it wants to finish with, and Articles 20, 22, 25 and 26 of AMLR define that target.

The File Must ShowIndividual CustomerBusiness Customer
IdentityNames, date and place of birth, nationality and residence or contact information, with suitable verification evidence.Legal name, form, registration and tax identifiers where available, registered office, principal place of business and country of creation.
People connected to the relationshipAny authorised person or other person on whose behalf or for whose benefit activity is conducted.Legal representatives, authorised persons, directors where relevant, beneficial owners and anyone exercising control by other means.
Purpose and expected activityWhy the relationship exists, expected use and activity, and occupation where relevant.Business activity, economic rationale, expected products, activity and flows, with source and destination of funds where necessary.
Risk and screeningCurrent risk assessment, PEP status, targeted financial-sanctions checks and other screening required by policy.Entity and connected-party risk, ownership complexity, geography, PEP and targeted financial-sanctions exposure, plus relevant screening.
Decision evidenceReason for review, information used, reviewer, outcome and next review point.Ownership rationale, verification sources, unresolved issues, approvals, outcome and next review point.

For an individual, the file establishes identity, relevant residence information, the purpose of the relationship, expected activity, screening results and current risk. A business file follows the same logic and must also explain the legal entity, its authorised representatives, and its ownership and control.

Regulation (EU) 2024/1624, Articles 20, 22, 25 and 26.

Registration Evidence Is Not Ownership Evidence

Business remediation is usually heavier because a current certificate of incorporation does not, by itself, show who ultimately owns or controls the customer. Current register information establishes legal existence and supports the ownership review; the firm must still test that the recorded ownership and control picture is complete, plausible and consistent with other evidence.

Where no beneficial owner can be identified after all possible means have been exhausted, AMLR requires that outcome and the steps taken to be recorded. The senior-managing-official route is not a shortcut around an incomplete ownership assessment.

The Exactly-25% Catch

The threshold is now 25% or more, where the pre-AMLR baseline said more than 25%. A holder sitting at exactly 25% counts today, and may be absent from a file built under the old wording.

Every business file reaches a point where its ownership information is rechecked, either on its review cycle or sooner when an event pulls it forward. What that recheck means varies, and it rarely means rebuild: where the owners on file still match the registers and nothing signals a change, the firm confirms and records, and reconstruction is reserved for structures that are old, incomplete or contradicted. Every business review still re-runs the threshold test and the separate control-by-other-means check.

The Completion Test. Could another trained reviewer open the file and understand what was checked, what changed, how risk was assessed, who made the decision and when the relationship must next be reviewed? If not, the file is not finished.

Turn Existing Customer Data Into Remediation-Ready Evidence

AMLR remediation runs on reliable identity, business, ownership and screening evidence. See how Shufti turns your existing book into evidence a reviewer can trace.

Book a Demo

Five Outcomes Triage the Book Before Any Customer Hears From You

Assessment starts with the book, not with outreach. Outreach that comes first creates unnecessary friction and usually produces a poor estimate of the work, because the firm already holds much of what it needs to grade each file.

An inventory per relationship brings together customer type, current risk level, last completed review, available identity or entity evidence, ownership information, screening status, known trigger events, open alerts and unresolved exceptions. The book is then compared, file by file, with the target standard from the previous section.

That comparison should separate a real information gap from a storage or retrieval problem. A reliable fact already held may still be usable; a document may be present yet no longer prove the current position; a record may be current yet lack the reasoning that connects it to the risk decision. Each file then takes exactly one of five outcomes.

1

Current

No customer contact

Information and evidence remain sufficient for the present risk.

Confirm the review and retain the record.

2

Confirm or Reuse

Reliable information exists, but its current relevance must be checked.

Confirm through internal or reliable independent sources.

3

Update

A defined field, document or screening result is outdated.

Refresh only the affected information.

4

Investigate

Material evidence is missing, inconsistent or cannot be validated.

Obtain further evidence and resolve the conflict.

5

Escalate

Risk has increased, CDD cannot be completed, or the case may require EDD, restriction, exit or reporting consideration.

Route to the authorised decision-maker.

Quotable

Where every field is present, supported and undisturbed by doubt, the file takes outcome 1, Current, and the customer never hears from you.

The first outcome keeps the exercise honest, and files earn it by comparison, not by assumption. For individuals the comparison is concrete because Article 22 fixes the data set down to names, birth details, nationality, identifiers and addresses. Files missing defined fields, common wherever onboarding ran under an older national regime, take outcome 3, Update, and join the queue.

Triage is also what contains the cost. Outcomes 1 and 2 close from internal records and reliable independent sources, so outreach effort concentrates on the files that genuinely need customer input, and the programme stays smaller than the book it covers.

A large book needs a living queue, not one fixed campaign list. Priority rises where a trigger event has occurred, the customer is higher risk, the gap is material, the evidence is old or unreliable, ownership or control has changed, sanctions exposure may exist, activity no longer fits the profile, or the next required review is approaching.

Trigger event occurred Higher-risk customer Material gap Old or unreliable evidence Ownership or control changed Possible sanctions exposure Activity no longer fits profile Next review approaching
Front of Queue EscalateInvestigateUpdateConfirm or reuse Back

Current: outside the active queue

A living queue, re-ranked as facts arrive, not one fixed campaign list.

Practical Rule. Do not contact every customer. Contact the customer when the required information cannot be confirmed, reused or obtained from an appropriate source, or when the firm needs the customer to explain a change or inconsistency.

One Eight-Step Process Remediate Individual and Business Files

One controlled process should remediate both individual and business files. The two paths contain different evidence, and splitting them into separate operating models makes ownership, escalation and quality assurance harder to control.

Its sequence runs from a recorded reason to a reconstructable decision. Steps three and four carry the outreach discipline: the firm checks what it can confirm or reuse from internal records, recent checks and official registers before asking the customer for anything, then collects only what is missing, outdated or doubtful, recording each attempt.

STEP 1

Open the case

Record why it exists: scheduled review, trigger event, missing-data assessment, monitoring alert, sanctions or PEP development, or a quality finding.

STEP 2

Identify the exact gap

State the problem area: identity, legal existence, authority, ownership, purpose, expected activity, screening, risk or completion evidence.

STEP 3

Confirm or reuse first

Review internal records, recent checks, official registers and other suitable sources before asking the customer.

STEP 4

Collect only what is missing

Request only the missing, outdated or doubtful items; explain what is needed, why, and the response route; record each attempt.

STEP 5

Verify people and entity

Individual: identity and relevant personal information. Business: legal existence, authority, ownership, control and beneficial owners.

IndividualBusiness
STEP 6

Refresh screening and risk

PEP status, targeted financial sanctions, adverse information and other required screening; compare expected activity with what was observed.

STEP 7

Make the relationship decision

Confirm or update, apply EDD, obtain senior approval, restrict activity, escalate for exit, or consider suspicion under the reporting process.

STEP 8

Record and return to monitoring

Store evidence, reasoning, approvals, completion date and next review point; close only when the decision can be reconstructed.

One process for individual and business files; only the evidence at step 5 differs.

Two Hard Rules Protect the Programme

Silence and contradiction are the two situations that test the programme’s integrity, and neither can be closed by a system default. Non-response is never a decision by itself, conflicting evidence is never averaged into a clean field, and both routes end in a recorded human decision.

1

Rule 1: Non-Response

Documented Outreach, Risk Review and Escalation
  • Record every contact attempt and check what suitable sources can supply instead.
  • Weigh the customer’s risk and the materiality of the missing information, then follow the firm’s escalation rules.
  • Where the gap prevents completing the Article 20(1) CDD measures, Article 21 requires refraining from transactions or new relationships; for an existing relationship, terminating it and considering a suspicion report, subject to the Regulation’s specific exceptions and alternatives.
  • Technology should not decide that outcome.
2

Rule 2: Conflicting Evidence

Resolve or Escalate Before the File Closes
  • Identify the conflict and obtain a more reliable source or explanation.
  • Determine what the difference changes: identity, authority, ownership, purpose or risk.
  • Record how it was resolved.
  • Route differences with the central beneficial-ownership register through Article 24’s discrepancy process, including its limited correction route for specified minor or outdated entries.

A Worked Example: An Ownership Change at Northbridge ICT

Northbridge ICT is a hypothetical medium-risk business customer. Monitoring identifies a registry update: a new shareholder now holds 30% and one director has left, while the file still shows the old ownership chart and names the departed director as an authorised representative.

Hypothetical Example
1

Open an event-driven review and record the registry change as the trigger.

2

Obtain current entity and representation information; reconstruct the ownership chain.

3

Identify and verify the new beneficial owner; confirm who is authorised to act.

4

Screen the entity, the new owner and relevant connected parties; resolve any matches.

5

Compare revised ownership, geography and expected activity with the existing risk assessment.

6

Record the decision, any approval, the updated risk rating and the next review date.

Verified, no material adverse information, activity still fits: update and continue

Ownership unclear or risk higher: enhanced review or escalation

The trigger starts the review; it does not predetermine the outcome. A verified new owner, no material adverse information and activity that still matches the relationship mean the firm updates the file and continues. Ownership that stays unclear, or a change that raises the risk, moves the case to enhanced review or escalation.

A File Is Finished When Another Reviewer Can Reconstruct the Decision

Completion is the point at which current evidence supports a current decision and the record explains how that decision was reached. The date on which the last document arrived proves nothing on its own.

Reconstruction rests on the closure record, and it has eight parts.

01

Why the review began

02

What the firm already held

03

What was missing, outdated or inconsistent

04

Which information was confirmed, reused or collected

05

Which verification and screening checks were performed

06

How the risk view changed

07

Who decided and approved the outcome

08

When the relationship will next be reviewed

Eight entries that let a second reviewer reconstruct the decision.

Stale FileRemediated File
ElementStale FileRemediated File
Identity or entity informationOld information with no current assessmentCurrent evidence, or a recorded basis for confirming that existing evidence remains suitable
Ownership and controlOwnership chart without verification or control rationaleBeneficial owners and verification sources recorded; control understood
ScreeningResult saved without match resolutionResult, reviewer outcome and effect on risk recorded
Risk decisionRisk score with no explanationRisk factors, judgement, approval and resulting classification connected
ClosureNo future review pointCompletion date, next review date and monitoring route recorded

Once closed, the file returns to periodic review, event-trigger monitoring, transaction or activity monitoring where applicable, PEP and sanctions screening, exception management and quality assurance. Remediation clears a known gap. Ongoing monitoring is what stops the file becoming stale again.

What to Fix Before Scaling

A good pilot can still fail at full volume if nobody has decided who owns the queue, who can approve higher-risk outcomes, what non-response means, or what evidence closes a case. Nine building blocks belong in place before large-scale outreach, from a single customer-file standard and one inventory of relationships through named case owners and decision rights to completion criteria, quality assurance and management reporting.

Customer-file standard One inventory of existing relationships Trigger and prioritisation rules Named case owners Decision rights Escalation routes Completion criteria Quality assurance Management reporting

Settle these before any large-scale outreach begins.

Firms should test the process on six representative files before scaling it across the full book. The pilot should show where data cannot be retrieved, which checks can be reused, where hand-offs stall and where a final decision cannot be reconstructed. A fault found on six files costs little; the same fault found mid-campaign does not.

A straightforward individual

Proves the happy path closes cleanly

An expired document

Tests targeted refresh without full re-onboarding

A higher-risk customer

Tests EDD routing and senior approval

A business with layered ownership

Tests chain calculation and control checks

A non-responsive customer

Tests outreach records and escalation rules

A case with conflicting evidence

Tests resolution before closure

Shufti Supplies the Evidence; the Firm Makes the Decision

Verification, screening and registry outputs support remediation decisions; the obliged entity makes them. AMLR draws that line itself: the entity stays liable for outsourced tasks, and specified decisions, including the customer risk profile, entry into a relationship and suspicious-activity reporting, cannot be outsourced to any provider.

Shufti is a Glocal Platform built for the full compliance lifecycle, from sign-up, onboarding and authentication through monitoring to remediation, across every industry, region and use case. In a remediation programme it sits at the evidence layer, and the division of labour is explicit.

ActivityShufti Can SupportThe Obliged Entity Remains Responsible For
Identity refreshDocument, biometric, NFC and electronic identity checks, configured for the required journey.Deciding when re-verification is necessary and if the evidence is sufficient for the risk.
Business remediationEntity verification, director and beneficial-owner identification, ownership mapping and connected-party checks.Understanding ownership and control, resolving discrepancies and deciding if the relationship is acceptable.
ScreeningPEP, sanctions, watchlist and adverse-media screening for individuals, entities and relevant connected parties.Reviewing potential matches, assessing relevance and deciding how findings affect risk.
Ongoing controlsContinuous screening and monitoring signals that can identify changes after onboarding.Defining triggers, thresholds, investigation standards and escalation routes.
EvidenceVerification results, screening outputs and traceable records from the checks performed.Maintaining the complete CDD record, reasoning, approvals and retention controls.
Final outcomeDecision-support information and workflow inputs.Assigning the risk profile and deciding to approve, restrict, report, continue or exit. These decisions cannot be outsourced.

One Bulk Pass Shows Where the Book Has Drifted

Much of the evidence work runs in bulk. Shufti can re-screen an existing book against PEP, sanctions, watchlist and adverse-media data through AML screening built for batch re-checks, monitor it for status changes, and refresh business and beneficial-owner information from registry sources where coverage allows through business verification and ownership mapping, with results returned per customer and evidence attached.

One pass surfaces stale screening, new matches and ownership that no longer matches the file, without a single email to a customer. Identity re-verification still needs the customer to complete a check, through electronic identity verification against government registries or a document and biometric journey, which is one more reason to reserve outreach for files nothing else can close. Each result returns attached to the customer record as evidence, which is the shape the closure record needs.

240+ countries and territories 10,000+ actively processed document types 150+ languages ISO 27001 SOC 2 Type II GDPR-compliant iBeta Level 3 Conformance to ISO/IEC 30107-3

No provider can see inside a firm’s own records, so the field-by-field comparison runs on the firm’s systems, with the bulk results feeding it as the freshest evidence. The firm builds the list. Shufti fills in what the world outside its records says about each file.

Technology cannot make a firm AMLR-compliant. The working question is different: can the operating model use verification, registry, screening and monitoring outputs to reach consistent human decisions across the existing book, and show the evidence later? Teams that prefer to build and price a stack without a sales conversation can configure a plan directly at any tier, and deployment references are available on request.

Firms should test the final Regulation and adopted AMLA instruments against their own activities, risk assessment, customer base and national supervisory expectations. Shufti provides technology, not legal or regulatory advice.

Prepare Your Existing Customer Book for AMLR

AMLR readiness starts with knowing where your current files stand. Walk through the evidence gaps and the remediation workflow with the Shufti team.

Book an AMLR Readiness Session
Enterprise Guide to Remediate Existing Customer and Business Files under EU AMLR — guide cover
Guide page — industry recognition 2025-2026
Guide page — table of contents
Guide page — how to find and remediate AMLR gaps in existing customer files
Previous
01 - 04
Next

Certifications

Independently audited and certified for enterprise-grade security and data protection.

  • GDPR Compliant
  • GDPR Fundamentals
  • ISO 27001 Certified
  • CCPA
  • iBeta Level 3 ISO 30107-3 Compliant
  • PCI DSS Compliant
  • Shufti SOC 2 Type 2 Compliant

    search_cross_mobile

    Please complete the information below 
to download the whitepaper

    By clicking the "Submit" button, you are agreeing 
to the Terms & Conditions and Privacy Policy

    Frequently asked questions (FAQs)

    No; AMLR requires the existing book to support current, risk-based and traceable decisions, not same-day re-onboarding. Firms meet that through a controlled remediation programme that compares each file against the target standard, and a file whose every field is present and supported closes as Current with no customer contact at all.

    Was this content helpful?

    AMLR, Regulation (EU) 2024/1624, applies from 10 July 2027 as a directly applicable baseline across the EU. Many underlying duties already existed under the Fourth Anti-Money Laundering Directive; what changes for existing files is the consistency and precision expected, including fixed data fields and capped update intervals. Legacy files are not exempt; they are the main place the new precision shows.

    Was this content helpful?

    Article 26 caps the gap between updates at one year for higher-risk customers and five years for everyone else, and risk can shorten either period but never stretch it. The caps are maximums, not default review cycles. A review also reopens early when circumstances change or the firm becomes aware of a relevant fact concerning the customer.

    Was this content helpful?

    Article 52 sets beneficial ownership at 25% or more of shares, voting rights or other ownership interest, where the pre-AMLR baseline said more than 25%. A holder at exactly 25% therefore counts today and may be missing from files built under the old wording. Indirect interests are multiplied down each chain and added across chains, and control by other means is a separate, mandatory check.

    Was this content helpful?

    Non-response is a fact to assess, not a decision in itself. The firm records its attempts, checks other appropriate sources, and weighs the customer’s risk and the materiality of the missing information. Where the gap prevents completing the Article 20(1) CDD measures, Article 21 requires refraining from transactions or new relationships and, for an existing relationship, terminating it and considering a suspicion report, subject to the Regulation’s specific exceptions and alternatives.

    Was this content helpful?

    Remediation tasks can be supported by a provider; the decisions cannot be outsourced. A provider can supply verification, screening and registry evidence across the whole book, but AMLR keeps the obliged entity liable for outsourced tasks and prohibits outsourcing specified decisions, including the customer risk profile, entry into a relationship and suspicious-activity reporting. The workable split is evidence from the provider, with decisions and records owned by the firm.

    Was this content helpful?

    No adopted instrument sets that start date. The draft CDD RTS proposes bringing existing-customer information into line on a risk-sensitive basis within the Article 26 periods, with those periods starting when the future delegated regulation applies. As at 31 July 2026 that instrument remains draft, so firms should plan with it without presenting its dates as statutory deadlines.

    Was this content helpful?
    n-img-roi-cross

    Form submitted successfully!

    Thank you for your interest — your report is loading now.

    AMLR Is One Baseline Across 27 Markets. See what it means in each country you operate in.

      Let’s Tailor Your Journey

      Which products would you like to check out?

      VideoIdent

      Address Verification

      eIDV (Docless)

      KYB

      AML Screening

      Deepfake Detection

      Face and ID Verification

      Age Verification

      Others

      What is your expected yearly verification volume?

      1 to 1,000

      1,001 to 5,000

      5,001 to 20,000

      20,001 to 50,000

      50,001 to 100,000

      100,001 to 1,000,000

      1,000,000+

      Valid Invalid number

      By clicking Submit, you accept our Privacy Policy and consent to marketing communications.

      report

      iGaming Fraud Report 2026 | Fraud Detection & Bonus Abuse Trends

      igaming-fraud-report-ftr-img
      report

      Forex Fraud Report 2026 | Identity Fraud Trends in Forex

      forex-fraud-identity-fraud-report-2026-ftr-img
      Product Guide

      Risk-Aligned Transaction Monitoring Process to Reduce Alerts

      Product Guide

      Crypto Compliance Maturity Model | Free Self-Assessment

      Crypto Compliance Maturity Model
      Product Guide

      Qualified Electronic Signature: EU & EEA Country Guide | Shufti

      report

      Identity Fraud Report 2026 | Shufti

      Identity Fraud Report 2026
      Product Guide

      Guide to Docless Identity Verification in the US and Canada

      Docless Identity Verification Us Canada
      Product Guide

      AMLR Readiness Checklist: 2027 Gap Assessment | Shufti

      Amlr Readiness Checklist
      Product Guide

      Shufti’s 2026 Context Gap in AML Risk Assessment

      The Context Gap In Aml Risk Assessment
      Product Guide

      Customizable KYC Solution for KYC Product Owners

      Customizable Kyc Solution For Kyc Product Owners
      Product Guide

      Docless KYC Verification in APAC to Onboard More Genuine Users

      Cover of the Shufti guide to docless KYC verification in APAC
      Product Guide

      EU AMLR Guide 2027: Requirements, Scope, Deadlines | Shufti

      Eu Amlr Compliance Guide
      Product Guide

      APAC Child Safety Age Verification Regulations

      APAC Child Safety Age Verification Regulations
      Product Guide

      Docless Identity Verification in the Middle East

      docless-identity-verification-middle-east
      Product Guide

      The Future of Docless Verification in Europe

      Onboard already verified users with Docless Verification in Europe
      Product Guide

      Cyprus 2026 KYC Operators Guide to Improve First Pass Rate

      Cyprus 2026 KYC Operators Guide to Improve First Pass Rate
      Product Guide

      Philippines KYC & Account-Owner Verification Playbook | Shufti

      Philippines KYC & Account-Owner Verification Playbook | Shufti
      Product Guide

      Digital Lending KYC Guide for Mexico: INE/IFE, CURP, RFC, Liveness and AML Controls

      Digital Lending KYC Guide for Mexico: INE/IFE, CURP, RFC, Liveness and AML Controls
      Product Guide

      CySEC Forex KYC Compliance Handbook 2026 | Shufti

      CySEC Forex KYC Compliance Handbook 2026 | Shufti
      Product Guide

      Singapore KYC & AML Compliance Guide 2026 | Shufti

      Singapore KYC & AML Compliance Guide 2026 | Shufti
      Product Guide

      Mexico 2026 KYC Handbook to Improve First Pass Rate

      Mexico 2026 KYC Handbook to Improve First Pass Rate
      Product Guide

      Where Can Identity Data Legally Live? 2026 Guide | Shufti

      Where Can Identity Data Legally Live? 2026 Guide | Shufti
      Product Guide

      Shufti Deepfake Fraud Index Report: Deepfake Fraud Set to Surge 495% in 2026

      Shufti Deepfake Fraud Index Report: Deepfake Fraud Set to Surge 495% in 2026
      Whitepaper

      KYC Compliance and Identity Fraud Challenge Across APAC

      KYC Compliance and Identity Fraud Challenge Across APAC
      Product Guide

      Brazil Bets KYC Playbook for .bet.br Operators 2026 | Shufti

      Brazil Bets KYC Playbook for .bet.br Operators 2026 | Shufti
      Product Guide

      Malta iGaming KYC & AML Readiness Guide 2026| Shufti

      Malta iGaming KYC & AML Readiness Guide 2026| Shufti
      Product Guide

      Brazil 2026 KYC Playbook to Improve First Pass Rate

      Brazil 2026 KYC Playbook to Improve First Pass Rate
      Product Guide

      Malta 2026 KYC Playbook to Improve First Pass Rate

      Malta 2026 KYC Playbook to Improve First Pass Rate
      Whitepaper

      The Deepfake Detection Gap

      The Deepfake Detection Gap
      Product Guide

      Choosing the Right Identity Verification Vendor for the Forex Sector

      Choosing the Right Identity Verification Vendor for the Forex Sector
      Product Guide

      A Comprehensive Guide to Address Verification in Complex Markets

      A Comprehensive Guide To Address Verification In Complex M
      Whitepaper

      Beyond Benchmark Accuracy: Making Deepfake Detection Work for IDV Systems

      Beyond Benchmark Accuracy: Making Deepfake Detection Work for IDV Systems
      Product Guide

      Human – Assisted Video KYC for Regulated Businesses:

      Human – Assisted Video KYC for Regulated Businesses:
      Whitepaper

      Re-Thinking RegTech for KYC Compliance

      Re-Thinking RegTech for KYC Compliance
      Product Guide

      Enterprise Guide to Choose Right Identity Verification Solution

      Enterprise Guide to Choose Right Identity Verification Solution
      report

      Global Age-Verification Laws 2025 Snapshot

      Global Age-Verification Laws 2025 Snapshot
      Whitepaper

      The Backbone of Global Trust

      The Backbone of Global Trust
      report

      State of Global AML Compliance 2025

      State of Global AML Compliance 2025
      Product Guide

      Strategic ID Verification Vendor for Crypto Industry

      Strategic ID Verification Vendor for Crypto Industry
      report

      Market Positioning and Commercial Assessment Results Presentation

      Market Positioning and Commercial Assessment Results Presentation
      Whitepaper

      Preventing Account Takeover Fraud with Multilayered Defense

      Preventing Account Takeover Fraud with Multilayered Defense
      Whitepaper

      The Critical 1% Closing Systemic Gaps In Global Identity Verification

      The Critical 1% Closing Systemic Gaps In Global Identity Verification
      Whitepaper

      Outsmarting the Deepfake Threat to Identity Trust

      Outsmarting the Deepfake Threat to Identity Trust
      Product Guide

      Scale Without Borders

      Scale Without Borders
      report

      Streamlining Identity Verification: How Shufti Secure Capture Enhances Accuracy and Trust

      Streamlining Identity Verification: How Shufti Secure Capture Enhances Accuracy and Trust
      report

      Top 10 Most Difficult Countries for Identity Verification

      Top 10 Most Difficult Countries for Identity Verification
      Whitepaper

      Shufti’s iGaming White Paper 2023

      Shufti’s iGaming White Paper 2023
      report

      Shufti Identity Fraud Report 2022

      Shufti Identity Fraud Report 2022
      report

      Shufti Fraud Report 2021

      Shufti Fraud Report 2021
      report

      Holiday Season – The Prime Time for ID Thieves and Financial Criminals

      Holiday Season – The Prime Time for ID Thieves and Financial Criminals
      report

      Shufti Completes 4 Years of Fighting ID Fraud

      Shufti Completes 4 Years of Fighting ID Fraud
      Product Guide

      On-premises Identity Verification for the Banking Sector

      On-premises Identity Verification for the Banking Sector
      Whitepaper

      Shrinking the Space for Travel Industry Scams with Biometric Verification

      Shrinking the Space for Travel Industry Scams with Biometric Verification
      Product Guide

      Global Gambling Compliance: Regulations, Age Checks & Financial Safety

      Global Gambling Compliance: Regulations, Age Checks & Financial Safety
      report

      A comprehensive guide to KYC and AML compliance in Canada

      A comprehensive guide to KYC and AML compliance in Canada
      n-img-roi-cross

      Form submitted successfully!

      Thank you for your interest — your report is loading now.

      Take the next steps to better security.

      Contact us

      Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

      Contact us

      Get the Shufti newsletter

      Stay ahead of the curve with fresh takes on the latest identity innovations.

        Take the next steps to better security.

        Contact us

        Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

        Contact us

        Request demo

        Get free access to our platform and try our products today.

        Get started

        Pitch a piece and get a verified byline in the Media room.

        Partnership Inquiries?
        Email us at [email protected]

        iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
        Copyright © 2026 Shufti. All rights reserved.