Anti-money laundering policies across the European Union are moving ever closer to harmonization with the introduction of the AMLR. But what exactly will change under the new regulation? Which organizations fall within its scope, and how much time do they have to prepare for compliance? This article answers these questions and more.
Why the AMLR Exists: From Fragmented Directives to a Single EU Rulebook
Anti-money laundering legislation is not new to the European Union. The first such directive was published in 1991 and, as of 2026, we are following a combination of AMLD 4, 5, and 6.
These directives were meant to standardize anti-money laundering measures in member states and ensure the safety of the financial sector.
Nevertheless, directives leave more up to local governments to finalize, implement, and supervise, which in turn has resulted in a fragmented legal landscape, leading to the occasional lapse in compliance or inconsistencies between member states.
Now, the introduction of a unified AMLR will cover the gaps and harmonize AML compliance in the EU. As a regulation, it applies directly to all member states, reducing national deviations.

When does the AMLR come into effect?
The deadline for AMLR compliance is July 10, 2027. All organizations that fall within the regulation’s scope must have ensured that their products and workflows adhere to the new standard by that deadline.
New Supervision: Meet the AMLA
The Regulation will be under the supervision of the Anti-Money Laundering Authority (AMLA). It is a central supervisory authority that will closely cooperate with national supervisors.
Thanks to the central authority of the AMLA, there will be increased scrutiny and consistent enforcement across countries.
As a result, compliance teams will likely see improvements in the form of:
- tighter expectations
- fewer “local interpretation” arguments
- more pressure for evidence-based controls.
Who Is Affected by the AMLR?
The Anti-Money Laundering Regulation applies to a number of regulated sectors, as well as industries with high-value transactions. The list includes, among others:
Traditional regulated financial services
Companies providing financial services that have thus far been within the scope of the AML Directives will be subject to the AMLR:
- Banks
- Payment institutions
- Fintechs
- Insurance companies
- Investment services
Crypto platforms and digital trading services
Crypto exchanges and digital platforms for financial trading are explicitly mentioned in the new regime.
Luxury sectors and other designated non-financial businesses
High-value and luxury sectors with high transaction values are also included. This category includes not only upscale retailers, but also organizations such as football clubs and gambling platforms, for example.
Moreover, legal practitioners, real estate companies, and trust service providers also fall within the scope of the AMLR.
Non-EU companies doing business in the EU
Despite the AMLR being a European regulation, it also affects foreign entities, insofar as they do business in the EU. This ensures that funds flowing in and out of the bloc are doing so in compliance with the new anti-money laundering standards.
AMLR KYC Requirements in Practice
So, what would a company’s KYC process looks like once the AML Regulation comes into effect? Here are some of most important changes.
Information on a need-to-know basis
The organization must perform a thorough identity verification of each user. Nevertheless, not every single attribute is collected during the process. There will be clear specifications as to what attributes collected must be verified.
When identifying natural persons, the required attributes include:
- Name
- Date and place of birth
- Nationality
- Identification number
- Address information
More importantly, there is new guidance on how customer data is kept up to date. For high-risk persons, you need to update data every year. For persons you haven’t deemed to present much risk, it is sufficient to update customer data once every five-year period.
Onboarding routes under the AMLR
With the AMLR into effect, organizations still have a choice in how they construct their KYC and onboarding flows. The more outdated ID document checks are still an option, but there is a clear preference for eIDAS-first processes, facilitated by qualified trust services and the upcoming EUDI wallet.
Method 1: Electronic identification (preferred)
Qualified trust services as defined in the eIDAS Regulation, especially electronic identification, take the center stage in the AMLR era. Since these services are already designed and audited according to the highest standards in the EU, they are compliant by default, creating the least amount of friction and leaving no compliance gaps.
Businesses in the banking sector are already aware that the EBA recommends eIDAS trust services as the primary direction.
The EUDI Wallet, once it becomes widely available to EU citizens, will also fit in this category, since the methods of attribute collection and attestation with the Wallet are also eIDAS-compatible.
Method 2: Identity-document-based identification (fallback)
As a back-up flow, organizations may still retain processes that identify customers via identity document checks. This route is especially useful in scenarios where citizens do not have the EUDI wallet (as it will not be mandatory) or until interoperability between member states is fully ensured.
Nevertheless, ID document verification is widely seen as a less secure method and is expected to gradually fall out of favor.
In countries that already have a high degree of digitalization, e.g. the Netherlands, Belgium, Denmark, Norway, asking for an identity document instead of eID may even have reputational harm, as citizens are more likely to suspect fraud.
ETSI 119 461 identity proofing
ETSI 119 461 continues to be the preferred basis for identity proofing across methods (video, NFC read, eIDAS scenarios). Aligning your processes with this standard enables certification and reduces the risk of regulators hitting you with unexpected requirements during audits.
The Role of eIDAS Trust Services in AMLR KYC
When it comes to the involvement of eIDAS-defined services in KYC processes that are AMLR-compliant, organizations need to consider the use of notified eIDs/electronic identification, qualified electronic signatures (QES), and qualified electronic attestation of attributes (QEAA).
eID
For the purposes of AMLR compliance, the KYC process must rely on electronic identification with an either substantial or high level of assurance. Note that Evrotrust’s own notified eID scheme covers these levels. At the LOAs, the identification is deemed more than reliable.
QES during onboarding
In many instances, QES can be used as an onboarding/identification method, not only for signing. After all, the issuance of the qualified certificate that enables qualified eSigning already verified the identity of the user. Each signing with QES requires confirmation, usually a biometric check, which ensures only the legal owner of the eSignature can use it.
With the wide coverage of QTSPs in Europe, as well as the upcoming EUDI Wallet (which includes a free QES for citizens), most people have easy access to qualified eSignatures, even in countries that do not yet have a national eID app.
For instance, with solutions such as Evrotrust’s mobile app, the issuance of a QES certificate takes only about 2 minutes and happens fully remotely, without waiting for a video operator. As a result, Evrotrust’s remote QES is highly accessible and may be a suitable means of identification for many. Evrotrust is also a notified eID scheme, fully aligned with eIDAS.
Ready to integrate eIDAS qualified trust services in your business? Reach out to Evrotrust’s expert team to discover how our solutions can meet your compliance needs.
Qualified Electronic Attestation of Attributes
QEAA is a trust service where an organization requests only the attributes it needs from the user, without getting ahold of all of their personal data.
For instance, an online casino or an online liquor shop needs to confirm the user is at least 18 years old. They can verify the ‘age’ attribute without having access to the user’s national PIN/social security number, their address, or other details that are not necessary for the transaction.
Moreover, when the EUDI Wallet becomes available, if one organization has already gone through the KYC process with a user, it can issue an attestation that other organizations can re-use when they need one or more of these attributes without doing KYC from scratch.

AMLR Challenges and How To Overcome Them
Naturally, with the new regulation and the transition towards heavier reliance on eIDAS services, there are a few possible areas where businesses may have difficulties at first. These include scattered attributes, issues with interoperability, and uneven adoption, among others.
Missing attributes
Depending on how the service is set up, it is possible that identification may have to look for certain attributes in different places.
For example, if one form of eID relies on extracting personal data via the NFC chip in a person’s passport of ID card, it may be missing some attributes, such as current address (since that may not be part of the ID document).
To go around such attribute gaps, the ideal KYC process may ask the user to do a combination of methods to make sure all necessary attributes are accounted for.
EUDI Wallet interoperability
Although the European Commission has set out the requirement that all member states’ digital identity wallets will be interoperable, it is possible to run into technical issues here and there. Considering each Wallet is its own app, with its own code, even when built according to the same standard, some miscommunication may still occur, especially in the early stages of wallet rollout.
Institutions need to be ready to accept every EU member state’s wallet and actively prepare for the complexity that supporting 27+ wallets entails.
Uneven adoption
Digital IDs and the EUDI Wallet remain voluntary for citizens. Thus, adoption rates may vary from one member state to another. While the AMLR is a strong motivator to increase digitalization, organizations need to anticipate some users’ reluctance to use eIDs and maintain reliable fallback methods just in case.
Combinations of ID document scans and liveness checks may continue to serve citizens who are not using digital identity wallets.
Conclusion
The new Anti-Money Laundering Regulation and the eIDAS organization are already familiar with mutually reinforce one another. The AMLR enhances KYC standards, pushing for greater adoption of eIDAS trust services such as notified eID schemes, electronic identification, QES, and the upcoming EUDI Wallet.
Member states where eID adoption is already high, and where the Wallet is expected to fit in seamlessly, may be better prepared for AMLR compliance. Those that lack behind may need longer for adoption rates to rise – businesses from such member states might need to combine attribute collection methods to ensure compliance.
Frequently Asked Questions
What is the EU AML Regulation?
The AMLR is a new, unified regulation on anti-money laundering that will replace the existing AML directives. It comes into effect in July 2027 and applies to all EU member states.
What happens to document scans and liveness checks?
Document-based identification as part of the KYC process remains as a fallback under the AMLR, especially if aligned with ETSI 119 461 identity proofing.
What about Switzerland and non-EU users?
The AMLR is EU law and does not apply to Switzerland itself. However, identifying non-EU persons would still require EU businesses and institutions to adhere to the AMLR.
If the user cannot use an eID or a digital identity wallet, document-based identification or QES can be used. Passports may be the most preferred identity document in these flows.
What does “government-grade assurance” mean?
The term refers to notified eIDs and EUDI wallets on trusted lists, which are intended to be accepted across Europe. These government-backed schemes provide stronger legal certainty and are less likely to be rejected by supervisors than purely private schemes.





