AMLR and digital identity: why financial institutions must move beyond document collection

28 July 2026

The real regulatory shift under the AMLR is not the arrival of new digital identity tools. It runs deeper. Compliance is no longer judged by the presence of documents on file, but by the ability to demonstrate that the identification carried out was relevant, reliable, and proportionate to risk.

Amlr digital identity authentication banner


💡 Key takeaways

  • Under the AMLR, digital identity is judged by demonstrable, risk-based proof, not by the presence of a document on file.
  • For non face-to-face onboarding, the AMLR steers obligated entities toward three acceptable means: national electronic identification, the EU Digital Identity Wallet, and qualified trust services.
  • eIDAS 2.0 raises the evidentiary quality of identification by giving it standardised assurance levels, substantial or high, that are recognised in regulation.
  • The real challenge is orchestration: correlating documents, biometrics, eIDAS means, and contextual signals into one explainable decision.
  • Financial institutions do not need to wait until 2027; mapping verification methods against the new AMLR digital identity standards can start now.

The false comfort of the document

In many organisations, the official document still sits at the heart of the KYC process. Yet this model has reached its limits. A document can be authentic, valid, and administratively consistent, and still be used fraudulently. The challenge is therefore no longer only to verify that a document exists, but to understand whether the person acting is genuinely who they claim to be, in the right context, at the right moment.

This is where the risk-based approach the AMLR imposes becomes concrete. A risk-based approach does not require stacking up controls indiscriminately. It requires applying the right level of control to the right risk, and being able to explain that choice afterwards. The document does not disappear, but it stops being the alpha and omega of trust.

What AMLR digital identity rules actually require

Under the AMLR, digital identity verification means proving, with evidence proportionate to risk, that a customer is who they claim to be. The regulation moves the test from whether a valid document was collected to whether the identification was relevant, reliable, and explainable. That is the heart of the shift from declarative compliance to demonstrable compliance.

The European AML framework, set out in Regulation (EU) 2024/1624, moves in this direction. Obligated entities must build their identification processes around a risk-based approach, with an assessment of their verification methods, their technologies, and their compatibility with the new standards. For non face-to-face situations, the AMLR and its associated standards steer institutions toward three main families of acceptable means: national electronic identification, the EU Digital Identity Wallet, and qualified trust services, with a substantial or high level of assurance when verifying the identity of a natural person remotely. This is consistent with the FATF's long-standing risk-based approach, now given sharper operational teeth in the European rulebook.

What eIDAS 2.0 changes for digital identity proof

eIDAS 2.0, Regulation (EU) 2024/1183, should not be presented as a universal silver bullet. For the identification of natural persons, however, it provides a recognised framework for using electronic identification means and trust services with standardised levels of assurance. That changes compliance in two ways.

First, it strengthens the evidentiary quality of identification. An identity verified through an eIDAS means at a substantial or high level of assurance does not rest on the mere reading of a document, but on a chain of trust that is recognised in regulation. Second, it lets identification be embedded in a broader logic of strong authentication and continuity of trust, which is central for financial institutions exposed to post-onboarding impersonation. For the regulatory mechanics behind this, see our explainer on the eIDAS 2.0 regulation.

Orchestration becomes the real issue

The most strategic point is not the existence of a wallet or a trust service taken in isolation. The real issue is orchestration: how to combine document verification, biometrics with liveness detection, eIDAS means, strong authentication, and contextual signals into a coherent, manageable journey. What matters is not the addition of controls, but the ability to correlate signals, weigh them according to context, and produce an explainable decision.

This is precisely what makes it possible to reduce false positives, operational overload, and the blind spots left by traditional document-based systems all at once. Identity orchestration is also what turns a one-off check at onboarding into continuous trust across the client lifecycle, rather than a verification that ages the moment it is filed.

What institutions must review now

Financial institutions do not need to wait until 2027 to act. They should already be mapping their identity verification methods, testing their compatibility with the future AMLR standards, and identifying where their onboarding journeys still rely on a purely document-based logic. They should also draw a clearer distinction between initial verification, continuous authentication, and risk-based reassessment.

The undertaking is therefore not only technological. It is also doctrinal and operational. It is about moving away from a model where compliance means archiving supporting documents, and into a model where compliance means demonstrating why an identity was judged sufficiently reliable: with what level of assurance, on the basis of which signals, and according to what risk logic. That is where compliance that is native rather than bolted on begins.

Conclusion

AMLR and digital identity belong in the same sentence because the regulation reframes identity from a document to be collected into proof to be demonstrated. eIDAS 2.0 gives institutions a recognised way to produce that proof at substantial or high assurance, but the structural advantage comes from orchestration: the ability to correlate signals and explain the decision. The institutions that start mapping and rebuilding now will not simply meet the obligation. They will turn it into an edge in fraud prevention and client experience.


Frequently asked questions about AMLR and digital identity

What does the AMLR require for digital identity verification?

The AMLR requires obligated entities to verify identity through a risk-based approach and to demonstrate that the identification was relevant, reliable, and proportionate to risk. It moves the test from whether a valid document was collected to whether the institution can explain why it trusted a given identity.

Does the AMLR replace document-based KYC?

No. The document does not disappear, but it stops being the centre of gravity. Under the AMLR, a document is one signal among several, and compliance is judged by the strength and explainability of the overall identification, not by the mere presence of a document on file.

Which identity means are acceptable for non face-to-face onboarding under the AMLR?

For remote verification of a natural person, the AMLR and its associated standards point to three families of acceptable means: national electronic identification, the EU Digital Identity Wallet, and qualified trust services, used at a substantial or high level of assurance.

How does eIDAS 2.0 relate to AMLR digital identity?

eIDAS 2.0 supplies the standardised assurance levels and trust services that the AMLR's risk-based approach can rely on. It raises the evidentiary quality of identification and enables continuity of trust, so the two frameworks are designed to work together rather than in isolation.

What should financial institutions do now to prepare?

They should map current verification methods, test compatibility with the future AMLR standards, identify journeys that still rely purely on documents, and separate initial verification from continuous authentication and risk-based reassessment. Building flexible orchestration now allows a gradual transition rather than a forced rebuild before 2027.

Harmoney offers a cutting-edge digital platform that streamlines intricate onboarding and compliance procedures, featuring automated screening functionalities. Interested in discovering more about our innovative solution? Reach out to us for further details or stay in touch via our newsletter ⬇️.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Latest blog posts