What is AMLR? A guide to the EU's new Anti-Money Laundering Regulation
For as long as most compliance professionals have worked in European financial services, anti-money laundering rules have come from directives. Each EU member state transposed those directives into national law differently, so requirements and effective dates varied by country.
That’s ending with the EU Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624. Unlike directives, EU regulations apply directly and identically across all 27 member states, with no national transposition required. AMLR takes effect on 10 July 2027, and when it does, it will replace the current directive-based approach with one harmonized rulebook.
AMLR anchors a broader EU AML package adopted in 2024. The package also includes AMLD6, which covers areas that member states must implement at the national level, such as beneficial ownership registers and supervision. As part of the same reforms, the EU established the Anti-Money Laundering Authority (AMLA). Based in Frankfurt, the new authority began operating in July 2025 and will directly supervise around 40 of the highest-risk cross-border financial groups starting in 2028.
What is AMLR?
| Official name | Regulation (EU) 2024/1624, the Anti-Money Laundering Regulation (AMLR) |
| Applies from | 10 July 2027 (10 July 2029 for professional football clubs and agents) |
| What it replaces | National rulebooks built on successive AML directives |
| Who it covers | “Obliged entities,” including banks, payment and e-money institutions, crypto-asset service providers, investment firms, insurers, and designated non-financial businesses |
| Headline changes | One directly applicable EU rulebook, an EU-wide €10,000 cash payment cap, CDD on occasional transactions of €10,000 or more, a harmonized 25% beneficial-ownership threshold, and a new EU supervisor (AMLA) |
Who does AMLR apply to?
AMLR applies to a broad set of financial institutions and non-financial businesses, which the regulation calls “obliged entities.” These include:
Credit institutions and banks
Payment institutions and e-money institutions
Crypto-asset service providers (CASPs)
Investment firms and insurance companies
Trust and company service providers
Real estate agents, auditors, accountants, and other designated non-financial businesses
Member states can extend AMLR to additional high-risk sectors, so the exact scope may vary slightly by market even under a harmonized regulation.
What does AMLR require for identity verification?
AMLR’s customer due diligence (CDD) obligations span several sections of the regulation. Understanding how they relate to each other is foundational for everything else.
Article 22 sets out what obliged entities must collect and verify for natural persons: full name, date of birth, place of birth, nationality, and residential address. Obliged entities must check these attributes against authoritative sources, such as government-issued documents or electronic identification schemes, rather than relying solely on customer-provided information.
Articles 6 and 7 of the RTS on customer due diligence set what must be verified but not exactly how verification must work, especially during remote onboarding. The standards are expected to address document-based verification and checks such as liveness detection and anti-spoofing measures.
Article 28 extends the same verification standards to ultimate beneficial owners (UBOs) of corporate entities, leveraging central beneficial ownership registers where they exist.
Finally, Articles 9 and 10 connect these identity verification requirements to a broader AML program that also covers transaction monitoring, sanctions screening, and suspicious activity reporting.
How does AMLR’s risk-based CDD work?
AMLR organizes CDD into three tiers based on customer risk:
| Tier | When it applies | What's required |
|---|---|---|
| Simplified due diligence (SDD) | Low-risk cases only, as strictly defined by regulation | Reduced verification measures where low risk is demonstrable |
| Standard CDD | Default for most customers and relationships | Full collection and verification of Article 22 attributes |
| Enhanced due diligence (EDD) | High-risk customers and regions, PEPs, complex ownership structures | Additional scrutiny, source of funds/wealth checks, senior management approval |
Across all three tiers, AMLR sets out what must be verified but leaves the how flexible, as long as the approach is proportionate to the risk.
How do AMLR and eIDAS 2.0 fit together?
One of the more foundational things to understand about AMLR is that it’s explicitly designed to work alongside the EU’s evolving digital identity framework, eIDAS 2.0, and the EU Digital Identity (EUDI) Wallet. eIDAS 2.0 establishes assurance levels (Low, Substantial, and High) that classify how reliably a digital identity has been verified.
Article 22 permits electronic identification methods recognized under eIDAS 2.0, including:
Government-issued eID schemes at Substantial or High assurance
NFC chip verification of ICAO-compliant documents
EUDI Wallet credentials carrying Person Identification Data at High assurance, once available
Under the eIDAS 2.0 timeline, all member states must make at least one EUDI Wallet available to citizens within 24 months after the implementing acts take effect, a deadline anticipated for late 2026. Regulated financial services entities must accept EUDI Wallet credentials as valid identification within 36 months after the acts take effect, a deadline anticipated for late 2027.
In short, AMLR sets the identity verification requirements, while eIDAS 2.0 defines the assurance levels for the electronic identification methods that can meet them.
Does AMLR apply to companies outside of the EU?
AMLR isn’t just a concern for companies headquartered in Europe, as it applies where regulated activity happens, not where a company is incorporated. This means a US fintech onboarding customers through an EU entity, a global platform serving EU users through an authorized crypto-asset service provider, or any group with a qualifying EU branch or subsidiary will generally need AMLR-grade due diligence for that European footprint.
Non-EU companies also face AMLR indirectly. Obliged entities must apply group-wide policies, so a European bank’s standards flow down to the partners and providers it works with, and counterparties increasingly expect AMLR-level verification as a condition of doing business in the region.
If you’re operating globally, the question is rarely whether AMLR applies to some part of your organization. In practice, it comes down to which legal entities fall within scope and whether to apply one EU-grade verification standard globally or run separate processes by market. Either way, get counsel involved early.
Where does AMLR implementation stand today?
As of August 2026, AMLR is still set to take effect on 10 July 2027. But the detailed technical standards that tell firms exactly how to operationalize the regulation, referred to as Level 2 measures, are still taking shape.
AMLA consulted on draft CDD technical standards through May 8, 2026, with final drafts originally due to the European Commission by July 10, 2026 ahead of next year’s go-live. Other guidance and rules are also taking shape ahead of the 2027 go-live, including:
AMLA guidelines on customer due diligence, transaction monitoring, and ongoing monitoring
European Commission delegated acts setting out more detailed rules for sanctions screening
AMLA Regulatory Technical Standards (RTS) specifying when the CDD threshold for occasional transactions should drop below €10,000 in higher-risk scenarios
Draft guidelines on ongoing monitoring are now out for consultation until September 3, 2026. One piece is running past the original July 10, 2026 target: the technical standards on CDD thresholds for occasional transactions, now expected in September 2026.
None of this is unusual. In EU rulemaking, detailed technical standards typically follow the regulation. The core requirements are already in the text of AMLR: what must be verified, how risk is tiered, and where eIDAS 2.0 fits. What’s still coming will fill in the implementation specifics.
Dates to keep in mind
3 September 2026: consultation feedback deadline for AMLA’s draft ongoing monitoring guidelines
September 2026: expected delivery window for outstanding RTS on CDD thresholds for occasional transactions
10 July 2027: AMLR becomes directly applicable across the EU
How Persona helps regulated entities prepare for AMLR
While AMLR doesn’t apply until July 2027, you don’t need to wait for every technical standard to be finalized to start preparing. If you map your verification and onboarding flows against Articles 6, 7, and 22, identify where your risk tiering needs to evolve, and build systems flexible enough to add eID and EUDI Wallet methods as they become available, you won’t need to rebuild from scratch.
That’s where Persona can help. Persona can help you collect and verify the attributes your AMLR program calls for against the sources you configure. Persona verifies passports and driver’s licenses from all 27 EU member states, plus national ID cards where they’re issued. It also checks the attributes AMLR cares about against authoritative sources — including NFC chip verification — and is participating in the EUDI Wallet pilots in France and Germany, so you can add wallet methods to the flows you build now as they become available. If you’re mapping your onboarding flows against AMLR ahead of 2027, our team can walk you through what that looks like in practice.
The information provided is not intended to constitute legal advice; all information provided is for general informational purposes only and may not constitute the most up-to-date information. Any links to other third-party websites are only for the convenience of the reader.
FAQs
When does AMLR take effect?
Toggle description visibility
AMLR applies across all 27 EU member states starting 10 July 2027. Because it’s a regulation, it takes effect directly, with no national transposition. One sector has more time: professional football clubs and agents come into scope on 10 July 2029.
What’s the difference between AMLR and the AML directives (AMLD)?
Toggle description visibility
AML directives had to be transposed into national law, which produced diverging rulebooks across member states. AMLR applies directly and identically everywhere. The newest directive, AMLD6, runs alongside AMLR and covers the pieces that stay national, like supervisors, financial intelligence units, and beneficial ownership registers.
Does AMLR replace KYC?
Toggle description visibility
No, AMLR doesn’t replace KYC. AMLR tightens the customer due diligence component of KYC: what must be verified, against which sources, and when enhanced measures apply. Firms with strong KYC and AML foundations simply need to adapt their programs, not start over.
What is AMLA?
Toggle description visibility
The Anti-Money Laundering Authority (AMLA) is the EU’s new AML supervisor. Based in Frankfurt since July 2025, it writes the technical standards and guidelines that put AMLR into practice. Starting in 2028, it will also directly supervise around 40 of the highest-risk cross-border financial groups.
Does AMLR apply to companies outside the EU?
Toggle description visibility
If you have EU entities, branches, or in-scope regulated activity, AMLR applies to that European footprint regardless of where you're headquartered. Non-EU groups also encounter AMLR through the group-wide policies of the European institutions they work with.
What should compliance teams do before the technical standards are final?
Toggle description visibility
Compliance teams should map onboarding and verification flows against Article 22’s required attributes, review how customers are tiered across the three CDD levels, and build verification that can add eID and EUDI Wallet methods as they roll out. The remaining Level 2 detail will refine implementation, not change its direction.
