AMLR is coming. Are you really ready?

14 September 2026

The AMLR, or Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), is the European Union's single anti-money laundering rulebook, directly applicable in every member state from 10 July 2027. It is the centrepiece of the EU's new anti-money laundering package, and for financial institutions it marks a shift from years of nationally implemented directives to one uniform set of rules. Yet when we polled compliance professionals in our webinar, nearly 70 percent said they were not, or probably not, ready for it.

This article explains what the AMLR changes, and draws on that webinar to show why it will test your compliance architecture, not your team.

Amlr is coming webinar replay

💡 Key takeaways

  • The AMLR (Regulation (EU) 2024/1624) is the EU's first directly applicable AML rulebook, live across the EU from 10 July 2027.
  • It makes customer due diligence more prescriptive, harmonises beneficial ownership at a 25 percent threshold, and sets a single EU cash-payment limit of 10,000 euro.
  • The real question is not whether you are AMLR compliant today, but whether your compliance model can survive tomorrow, financially, operationally, and structurally.
  • AMLR will not break your team. It will expose the architecture, because most compliance frameworks were accumulated over time, not designed as a whole.
  • Sustainable readiness rests on four pillars, automation, orchestration, AI, and traceability, not on adding another tool or another rule.

What is the AMLR?

The AMLR harmonises anti-money laundering and know-your-customer obligations across every member state, standardising how KYC, AML and CDD obligations are applied rather than leaving them to diverge from one country to the next. For financial institutions, the AMLR marks a shift from years of nationally implemented directives to one directly applicable set of rules.

Why the AMLR is a regulation, not a directive

A directive sets objectives that each member state must transpose into national law, which is why AML requirements have historically varied from one country to the next. A regulation is different: it is directly applicable, taking legal effect in the same form across all member states without national transposition. By replacing the patchwork of national rules with one uniform text, the AMLR removes the divergence that left obliged entities operating in several countries facing inconsistent requirements.

It sits alongside two other instruments in the EU AML package:

  • The AMLR (Regulation (EU) 2024/1624): the single rulebook containing the substantive obligations for obliged entities.
  • AMLD6, the sixth Anti-Money Laundering Directive: rules that member states still transpose nationally, covering supervisory organisation, financial intelligence units, and access to information.
  • The Anti-Money Laundering Authority, established by Regulation (EU) 2024/1620: the new EU-level supervisor created to enforce consistent application.

The AMLR timeline: what happens by 10 July 2027

The regulation was adopted in 2024 as part of the wider AML/CFT legislative package. Its main substantive provisions apply from 10 July 2027, giving obliged entities a defined runway to adapt their processes, data models, and systems before the rules take effect. This is not an indefinite horizon: the preparation window is finite, and the operational changes the AMLR requires take time to design and embed.

Two intermediate deadlines matter more than the 2027 date itself. The first has already passed: the first package of regulatory technical standards, including the RTS on customer due diligence measures under Article 28(1) AMLR, was due to the European Commission on 10 July 2026, so the binding shape of the standard is now largely visible in the drafts publicly consulted in the first half of 2026. The second concerns digital identity: Regulation (EU) 2024/1183, eIDAS 2.0, requires Member States to make the European Digital Identity Wallet available by 24 December 2026, with an acceptance obligation for listed private actors, including banks, from 24 December 2027. These timelines overlap: an identification architecture built in 2026 has to work under the AMLR, absorb the EUDI Wallet at an uneven pace across countries, and stay explainable for the entire retention period of the files.

What the AMLR changes for obliged entities

The AMLR introduces several concrete changes that reshape day-to-day compliance operations.

Harmonised customer due diligence

Customer due diligence becomes far more prescriptive. The regulation clarifies and standardises how obliged entities perform customer identification, verification, beneficial-ownership checks, and ongoing monitoring, with more measurable requirements on identity verification. The risk-based approach remains, but it becomes more demanding: every decision must be documented and defensible, showing how, why, and on what basis it was reached, rather than a general assertion that risk was assessed. Our deep dive on what the AMLR changes for customer due diligence walks through this in detail.

Beneficial ownership at 25 percent

The AMLR sets a harmonised threshold for identifying a beneficial owner at 25 percent ownership or control, applied consistently across the EU. It also expands the data set that must be collected and held for each beneficial owner, including full legal names, all nationalities, national identification numbers, dates of birth, residential addresses, and detailed ownership percentages across the ownership chain. Meeting this at scale is where automated UBO verification and register integration earns its place.

An EU-wide cash payment limit

The regulation introduces an EU-wide limit of 10,000 euro on large cash payments for goods and services, and requires customer identification for cash payments from 3,000 euro. This restricts the anonymity that high-value cash transactions can provide and gives supervisors a common baseline rather than differing national ceilings.

Expanded scope

The population of obliged entities widens. The AMLR brings additional sectors into scope, extending AML obligations beyond the institutions traditionally covered so that a broader range of businesses must apply due diligence and reporting duties.

These are the changes with the broadest operational impact, not the whole regulation. The AMLR goes further, from enhanced due diligence to reporting obligations, and the full text on EUR-Lex remains the definitive reference.

How AMLA supervises under the AMLR

The Anti-Money Laundering Authority (AMLA) is the new EU-level body created to give the single rulebook consistent teeth. AMLA will directly supervise a selection of the highest-risk cross-border financial institutions and will coordinate national supervisors to ensure the AMLR is applied uniformly rather than interpreted differently from one country to the next. We looked at how it will operate in our note on the AMLA regulation and technical standardisation. For obliged entities, this means integrated European supervision with less local flexibility, and a higher premium on standardised, defensible processes.

Understanding the AMLR is the first step; translating it into an operating model that can withstand integrated European supervision is the harder one.

What "documented and defensible" concretely requires

Three articles of the AMLR make this concrete rather than aspirational.

  1. Article 20(4) says it directly: obliged entities must "at all times be able to demonstrate to their supervisors that the measures taken are appropriate in view of the risks... that have been identified." That is the demonstrability requirement in the text itself, not an interpretation of it.
  2. Article 22 sets out what has to be collected and verified for customers and beneficial owners, and it accepts electronic identification meeting eIDAS assurance levels, "substantial" or "high", as an alternative to a physical document, provided the reliability is equivalent and demonstrated. Choosing between methods is not a neutral administrative detail: the choice has to fit the customer's risk profile, and that fit has to be explainable.
  3. Article 24 adds a check specific to beneficial ownership: if an entity's own verification conflicts with what a national register shows, the discrepancy has to be reported within 14 calendar days, not filed away. The register is a reference point to check against, not the end of the analysis.

A simple test cuts through the abstraction. Take a file accepted eighteen months ago and check whether these six questions can be answered without reconstruction:

  1. What signals grounded the decision to accept this identity?
  2. What weight was given to each, and why?
  3. What risk level was assigned, on what criteria?
  4. What, since then, should have triggered a reassessment?
  5. Who made the call, under what rule?
  6. Where is that trace kept, and in what form?

If answering means reopening several tools and rebuilding a timeline by hand, the framework is documented, not demonstrable. That gap, between documented and demonstrable, is what the rest of this piece is really about.

Why AMLR readiness is an architecture problem

The conversations we have with compliance managers across Europe share a common thread. The effort is there. The talent is there. And yet the system keeps getting more expensive, more manual, more fragile. Alert volumes rise. Onboarding timelines stretch. Audit preparation feels like a crisis every time.

Frank Verhaest, Partnership Director at Harmoney, opened the webinar with a reframe that resonated throughout the session:

"They work hard. They do their job well. The problem is not the effort. The problem is the architecture."
Frank Verhaest Brand & ecosystem director

Most compliance frameworks were not designed. They were accumulated. A system added after an audit. A new layer after a regulation. Another tool after a fine. Each decision made sense at the time. The result is an architecture built in layers, never designed as a whole.

AMLR will not break your team. It will expose the architecture.

Five bottlenecks. One closed loop.

The webinar introduced the FAILS framework, five structural bottlenecks that prevent sustainable compliance progress:

  1. Fragmentation.
  2. Alerts.
  3. Invisibility.
  4. Lag.
  5. Saturation.

Each one is real. Together, they form a cycle that local fixes cannot break. More rules generate more alerts. More alerts drive more manual processing. More manual processing creates fatigue. Fatigue increases the risk of missing real threats. Real threats prompt more rules. And the loop continues. Adding another tool or another rule does not break this cycle. It adds weight to a system that is already bending.

The question worth sitting with

The real question compliance leaders need to ask is not "are we AMLR compliant today?" Most organisations are, at least partially.

The question is: can our model survive tomorrow?

Financially. Operationally. Structurally. AMLR raises the bar on traceability, risk-based decision-making, and consistent documentation in ways that a fragmented architecture will struggle to meet. Not because of a lack of will, but because of how the system was built.

Frequently asked questions

When does the AMLR come into effect?

Regulation (EU) 2024/1624 is directly applicable across all Member States from 10 July 2027, with no national transposition needed. AMLA's direct supervision of a selection of entities begins in 2028.

Does the AMLR allow electronic identification instead of physical documents?

Yes. Article 22(6) accepts electronic identification meeting eIDAS assurance levels, "substantial" or "high", alongside traditional documents, provided the reliability is equivalent and demonstrated.

Is the beneficial ownership register enough to prove a customer's control structure?

No. Article 24 treats register information as a starting point for verification, not sufficient proof on its own. The obligated entity remains responsible for verifying that it matches the actual control structure.

What does "demonstrable compliance" actually mean under the AMLR?

It rests on four properties: being able to reconstruct why an identity was judged trustworthy years later, explicit proportionality so a given level of vigilance can be justified against a given risk profile, consistency between written policy and day-to-day practice, and continuity, since identification does not stop at onboarding.

Do we need to change tools to comply with the AMLR?

No specific technology is prescribed. The regulation sets an outcome: reliable, risk-proportionate, demonstrable identification. The useful question isn't which tools to replace, but whether the tools already in place produce a traceable, explainable decision.

AMLR asks whether an identity can be demonstrated as reliable, and kept reliable. Our white paper, written with ShareID, Trustfull and ID Protect, shows what that takes in practice. Download From document verification to mastering identity entities free for the full analysis, including worked cases in insurance and in auto credit and leasing. ⬇️

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Latest blogs