The real regulatory shift under the AMLR is not the arrival of new digital identity tools. It runs deeper. Compliance is no longer judged by the presence of documents on file, but by the ability to demonstrate that the identification carried out was relevant, reliable, and proportionate to risk.
In many organisations, the official document still sits at the heart of the KYC process. Yet this model has reached its limits. A document can be authentic, valid, and administratively consistent, and still be used fraudulently. The challenge is therefore no longer only to verify that a document exists, but to understand whether the person acting is genuinely who they claim to be, in the right context, at the right moment.
This is where the risk-based approach the AMLR imposes becomes concrete. A risk-based approach does not require stacking up controls indiscriminately. It requires applying the right level of control to the right risk, and being able to explain that choice afterwards. The document does not disappear, but it stops being the alpha and omega of trust.
Under the AMLR, digital identity verification means proving, with evidence proportionate to risk, that a customer is who they claim to be. The regulation moves the test from whether a valid document was collected to whether the identification was relevant, reliable, and explainable. That is the heart of the shift from declarative compliance to demonstrable compliance.
The European AML framework, set out in Regulation (EU) 2024/1624, moves in this direction. Obligated entities must build their identification processes around a risk-based approach, with an assessment of their verification methods, their technologies, and their compatibility with the new standards. For non face-to-face situations, the AMLR and its associated standards steer institutions toward three main families of acceptable means: national electronic identification, the EU Digital Identity Wallet, and qualified trust services, with a substantial or high level of assurance when verifying the identity of a natural person remotely. This is consistent with the FATF's long-standing risk-based approach, now given sharper operational teeth in the European rulebook.
eIDAS 2.0, Regulation (EU) 2024/1183, should not be presented as a universal silver bullet. For the identification of natural persons, however, it provides a recognised framework for using electronic identification means and trust services with standardised levels of assurance. That changes compliance in two ways.
First, it strengthens the evidentiary quality of identification. An identity verified through an eIDAS means at a substantial or high level of assurance does not rest on the mere reading of a document, but on a chain of trust that is recognised in regulation. Second, it lets identification be embedded in a broader logic of strong authentication and continuity of trust, which is central for financial institutions exposed to post-onboarding impersonation. For the regulatory mechanics behind this, see our explainer on the eIDAS 2.0 regulation.
The most strategic point is not the existence of a wallet or a trust service taken in isolation. The real issue is orchestration: how to combine document verification, biometrics with liveness detection, eIDAS means, strong authentication, and contextual signals into a coherent, manageable journey. What matters is not the addition of controls, but the ability to correlate signals, weigh them according to context, and produce an explainable decision.
This is precisely what makes it possible to reduce false positives, operational overload, and the blind spots left by traditional document-based systems all at once. Identity orchestration is also what turns a one-off check at onboarding into continuous trust across the client lifecycle, rather than a verification that ages the moment it is filed.
Financial institutions do not need to wait until 2027 to act. They should already be mapping their identity verification methods, testing their compatibility with the future AMLR standards, and identifying where their onboarding journeys still rely on a purely document-based logic. They should also draw a clearer distinction between initial verification, continuous authentication, and risk-based reassessment.
The undertaking is therefore not only technological. It is also doctrinal and operational. It is about moving away from a model where compliance means archiving supporting documents, and into a model where compliance means demonstrating why an identity was judged sufficiently reliable: with what level of assurance, on the basis of which signals, and according to what risk logic. That is where compliance that is native rather than bolted on begins.
AMLR and digital identity belong in the same sentence because the regulation reframes identity from a document to be collected into proof to be demonstrated. eIDAS 2.0 gives institutions a recognised way to produce that proof at substantial or high assurance, but the structural advantage comes from orchestration: the ability to correlate signals and explain the decision. The institutions that start mapping and rebuilding now will not simply meet the obligation. They will turn it into an edge in fraud prevention and client experience.
The AMLR requires obligated entities to verify identity through a risk-based approach and to demonstrate that the identification was relevant, reliable, and proportionate to risk. It moves the test from whether a valid document was collected to whether the institution can explain why it trusted a given identity.
No. The document does not disappear, but it stops being the centre of gravity. Under the AMLR, a document is one signal among several, and compliance is judged by the strength and explainability of the overall identification, not by the mere presence of a document on file.
For remote verification of a natural person, the AMLR and its associated standards point to three families of acceptable means: national electronic identification, the EU Digital Identity Wallet, and qualified trust services, used at a substantial or high level of assurance.
eIDAS 2.0 supplies the standardised assurance levels and trust services that the AMLR's risk-based approach can rely on. It raises the evidentiary quality of identification and enables continuity of trust, so the two frameworks are designed to work together rather than in isolation.
They should map current verification methods, test compatibility with the future AMLR standards, identify journeys that still rely purely on documents, and separate initial verification from continuous authentication and risk-based reassessment. Building flexible orchestration now allows a gradual transition rather than a forced rebuild before 2027.
Harmoney offers a cutting-edge digital platform that streamlines intricate onboarding and compliance procedures, featuring automated screening functionalities. Interested in discovering more about our innovative solution? Reach out to us for further details or stay in touch via our newsletter ⬇️.