AMLA's October release on AMLR standards (RTS): What changes for compliance teams

This article is part of our AMLR 2027 series.

—

On 1 October 2026, AMLA finalised three regulatory technical standards (RTS) under AMLR and sent them to the European Commission.

For most compliance teams, the one that matters most is the standard on customer due diligence, which sets out what you need to collect and verify about your customers, and when.

These are the main takeaways from the update that most compliance teams will want to check against their current processes.

1. Ongoing due diligence: when the update periods start for existing customers

AMLR sets maximum periods for updating customer information: 1 year for higher-risk customers and 5 years for all others (Art. 26(2) AMLR).

For customers you already have when the standard enters into force, you bring their information in line with the new requirements within those same periods, prioritising by risk.

The periods start on the date the standard enters into force, so you can plan the review of your existing customer base around that date (Art. 28 and recital 26 RTS).

2. Identity verification: ID in person or electronic ID as the main methods

The standard names two main ways to verify a person's identity: an identity document presented in person, or electronic identification at the eIDAS "substantial" or "high" assurance level, which includes the EU Digital Identity Wallet (Art. 6 RTS; Art. 22(6) AMLR).

AMLA says electronic identification should be used wherever possible. You can use another remote method only when the customer can't reasonably show their ID in person and has no access to electronic ID, and you need to be able to explain to your supervisor why that was the case (Art. 7 RTS).

3. Beneficial ownership: information on each company in the ownership chain

For each company between your customer and its beneficial owners, you record its legal form, the country it is registered in, any nominee shareholders or directors, and its share of ownership and voting rights (Art. 11 RTS).

You still need to check the central beneficial ownership register, but you can't rely on it alone (Art. 22(7) AMLR). (More on UBO mapping under AMLR.)

4. Onboarding: expected transaction activity and source of funds

You need to understand the purpose of each business relationship and, where necessary, collect information on it. AMLA's list of what this can include names the expected number, size, volume, type and frequency of transactions (Art. 16 RTS).

Source and destination of funds are collected where the customer's risk calls for it, and the level of detail should match that risk. The expected activity you record at onboarding is also what you can later compare the customer's actual transactions against.

5. Sanctions screening: when you need to screen

You screen every customer and their beneficial owners when you onboard them, when a sanctions list changes, and when their details change, for example a new name, address, nationality or beneficial owner.

On top of that, you screen on a regular basis, at a frequency that reflects your exposure to sanctions risk (Art. 25 RTS).

Extra: business relationships and linked transactions (a separate standard)

Alongside the customer due diligence standard, AMLA finalised a separate standard on business relationships, occasional and linked transactions. It sets out when one-off transactions add up to a business relationship. If a customer has ongoing access to your services, for example through an account, that points to a business relationship.

For currency exchange, money remittance and crypto exchange or transfer services, three or more transactions within 12 months also count, and transactions within one month are assessed together when checking whether they are linked (Art. 2 and 3, business relationships RTS). AMLA didn’t introduce any new lower thresholds, so the existing AMLR thresholds stay as they are.


—

Timing: when the standards apply

The standards apply six months after they enter into force, which happens 20 days after they are published in the Official Journal (Art. 29 RTS). AMLR itself applies from 10 July 2027, so the date for the standards depends on how quickly the Commission adopts them.


These standards are final, but not yet adopted. Next, the European Commission decides whether to adopt them, and once they are published in the Official Journal, the clock starts towards the date they apply.

AMLA has not yet finalised its guidelines on ongoing monitoring and business-wide risk assessment. For a broader overview, read our summary of the main changes AMLR introduces.

If you want to go through what this means for your compliance processes, get in touch.

—

More in the AMLR 2027 series

—

This article is published by Bits Technology, a compliance platform for regulated financial companies in Europe.