Skip to content

Preparing customer due diligence for the EU AML Regulation

The EU AML Regulation applies directly from 10 July 2027 and replaces national CDD rules with one text. Build to the Regulation now: its data list, verification routes, 25% ownership test and refresh ceilings are fixed, while AMLA's detailed CDD standards were still in draft as of September 2026.

Charles Archibong

, Co-founder

· 6 min read

Headline "CDD under the EU AML Regulation" beside an illustration of a calendar page with one date highlighted, on a warm cream gradient.

Key takeaways

  • The EU AML Regulation (EU) 2024/1624 applies from 10 July 2027, directly, in every Member State.
  • Article 22 fixes a minimum identification data list, including every nationality and a national ID number.
  • Customer information must be refreshed at least every year for higher-risk customers and every five years for others.
  • AMLA's CDD technical standards were due by 10 July 2026 and were still marked consultation closed on 4 September 2026.

The EU AML Regulation, Regulation (EU) 2024/1624 (opens in a new tab), applies from 10 July 2027 and is directly applicable in every Member State (Article 90). For customer due diligence (CDD) that means one text instead of 27 national versions: a fixed minimum list of identification data, two defined routes for verifying identity, a 25% beneficial ownership test that counts indirect holdings, and hard ceilings on how long customer information can go without an update.

Firms should build to the Regulation now rather than wait for the detail. The Regulation told the new EU authority, AMLA, to deliver draft CDD technical standards by 10 July 2026 (Article 28(1)). As of AMLA's own regulatory instruments page, last updated 4 September 2026, those standards were marked "consultation closed", with no final report published. The draft shows the direction; the Regulation's text is what is certain.

Requirements differ by jurisdiction and by firm type, and this article is general information, not legal advice.

What is fixed in the Regulation itself?

Four parts of the Regulation change day-to-day CDD, and none of them depends on AMLA's standards being finished.

A minimum data list for every customer

Article 22(1) lists what you must obtain to identify a natural person: all names and surnames, place and full date of birth, nationalities (plural, or statelessness and refugee or subsidiary protection status where applicable), the national identification number where applicable, and the usual place of residence. For a legal entity it lists legal form and name, registered address and principal place of business, country of creation, legal representatives, and, where available, the registration number, tax identification number and Legal Entity Identifier.

Two items catch teams out. Many onboarding forms ask for one nationality; the Regulation says nationalities. And many flows never capture a national identification number when the customer verifies with a passport.

Two routes to verify identity

Article 22(6) gives two ways to obtain what you need to verify a customer:

  1. An identity document, passport or equivalent, plus information from reliable and independent sources where relevant.

  2. Electronic identification that meets the eIDAS Regulation (EU) No 910/2014 at assurance level "substantial" or "high", and relevant qualified trust services.

Beneficial owners: 25%, counted through the chain

Article 52(1) sets the ownership test at 25% or more of shares, voting rights or other ownership interest, "direct or indirect". Indirect ownership is calculated by multiplying the holdings through each chain and adding the chains together. Article 22(7) requires you to verify beneficial owners and, in addition, to consult the central beneficial ownership registers.

Where nobody qualifies after you have exhausted all means, Article 22(2) says you record that no beneficial owner was identified, then identify and verify all the senior managing officials.

Refresh ceilings

Article 26(2) says the period between updates of customer information depends on risk and must not exceed 1 year for higher-risk customers under enhanced due diligence and 5 years for everyone else. Article 26(3) adds event triggers: a change in the customer's circumstances, or a relevant fact you become aware of.

Where do AMLA's CDD standards stand?

AMLA consulted on the draft regulatory technical standards (RTS) on CDD from 9 February 2026 to 8 May 2026 (opens in a new tab), building on a draft the European Banking Authority published on 30 October 2025. The consultation page says "Results will follow." The regulatory instruments page (opens in a new tab) still listed the CDD RTS as "Consultation closed" on 4 September 2026. Re-check both before relying on any detail below.

The consultation paper (opens in a new tab) matters most for firms that onboard remotely. Draft Article 7 says that, for non-face-to-face verification, firms use eIDAS electronic identification at substantial or high. Only where that "is not available, or cannot reasonably be expected to be provided" may they use a remote solution, and that solution must include safeguards such as:

  • controls to ensure the person presenting the document is the person in its picture;

  • images, video and data captured in a readable format with enough quality to recognise the person unambiguously;

  • stopping the process when there are technical problems or doubts about identity;

  • copies retained, time-stamped and stored so they can be checked after the event.

The draft also expects firms to be able to justify to their supervisor why a customer could not be verified by eID. And draft recital 25 says the 1 and 5 year refresh periods should start for existing customers only from when the delegated regulation applies, which, if it survives, spreads the first refresh wave rather than making the whole book due in July 2027.

Treat all of this as a draft until AMLA submits a final version and the Commission adopts it.

What should you do before July 2027?

Work through the gaps that the Regulation creates regardless of how the RTS ends up. A practical sequence:

  1. Map your data fields against Article 22(1). Take one individual customer file and one company file and mark each required item as held, derivable or missing. Missing nationalities and national ID numbers are the usual gaps.

  2. Decide your verification route per channel. If you onboard in markets where eIDAS eID is widely held, plan how you will accept it. If you rely on document and selfie flows, document why eID is not available for that population, since the draft RTS expects that justification.

  3. Check your remote flow against the draft safeguards. Can you show the face matched the document or an authoritative record? Is capture live and good enough to recognise the person? Do you keep time-stamped evidence you can replay for a supervisor?

  4. Recalculate beneficial ownership for layered structures. Multiply through each chain and add the chains. A person holding 60% of a company that holds 40% of your customer has an indirect interest of 24%, below the line on that chain alone; if the same person also holds 5% directly, the total is 29% and they are a beneficial owner.

  5. Write down your "no beneficial owner found" procedure. Record the finding, then identify and verify the senior managing officials.

  6. Build a refresh calendar. Tag every customer with a risk rating and a next-review date that never exceeds 1 or 5 years, plus event triggers for changes you learn about.

A worked example for step 6: a payment institution with 40,000 customers rated higher risk on 2,000 of them needs a process that can refresh those 2,000 at least annually. If the process today is a manual email campaign, that is the gap to close first.

How Myaza Trust helps with the parts it covers

Business Verification discovers directors, shareholders and beneficial owners from company registries, reconciles them with the list the applicant gives, and flags people the register lists but the applicant left out. The ownership threshold is configurable and defaults to 25% outside Nigeria, which matches Article 52's figure. Corporate shareholders are never treated as beneficial owners, and the person applying completes their own identity verification and is checked against the named officers. Following ownership into a corporate shareholder's own register (look-through) is opt-in and off by default, so check how you will handle indirect holdings. See the key people documentation.

For individuals, Identity Verification combines document capture, selfie with active liveness and, in supported markets, a check against the government record. Watchlist screening runs at onboarding and again on a risk-based schedule. We do not currently describe eIDAS electronic identification support, so firms that want the Article 22(6)(b) route need to plan for it separately.

The decision rule

Build to the Regulation's text now, because it is final and directly applicable from 10 July 2027. Keep a short list of RTS-dependent choices (remote verification safeguards, refresh start dates for existing customers) and revisit them when AMLA publishes its final draft. Member States also have until 10 July 2027 to transpose the accompanying Directive (EU) 2024/1640 under its Article 78 (opens in a new tab), so watch your national supervisor's guidance alongside the EU texts.

Sources

Charles Archibong

About the author

Charles Archibong

Co-founder

Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.

Build your product.We'll handle the rest.

Identity and compliance, end to end, built to global standards, priced for founders.

EU AML Regulation: preparing CDD before July 2027 · Myaza Trust