Skip to main content
The Signicat Blog
AMLR guide cover graphic featuring a compliance document and security shield with EU stars, titled "From regulation to operational readiness".

AMLR 2027 guide: from regulation to operational readiness

With the EU Anti-Money Laundering Regulation (AMLR) set to become fully applicable from 10 July 2027, the landscape of financial crime prevention is undergoing its most significant change in years. For organisations across Europe, the time to move from understanding the regulation to ensuring operational readiness is now. 

The AMLR replaces a patchwork of national laws with a single, directly applicable rulebook for the entire Union. This shift presents both a critical compliance challenge and a clear incentive for organisations to modernise their customer onboarding and identification processes. 

How will customer identification change under the AMLR? 

A core focus of the AMLR is harmonising how organisations verify customer identity. The regulation explicitly recognises electronic identification methods under the EU’s eIDAS framework and signals a clear shift towards electronic identification for customer onboarding. The guide explores the two main approaches recognised under Article 22 of the AMLR: 

  1. Document-based identification: This involves using official documents like passports and national ID cards, enhanced with technologies such as NFC-based verification, face matching, and liveness detection. 
  2. Electronic identification and trust services: This approach relies on notified electronic identification schemes (eIDs), Qualified Electronic Signatures (QES), and, in the future, the European Digital Identity Wallet (EUDI Wallet). 

What are the key differences between the old and new frameworks? 

The transition from fragmented directives to a single rulebook introduces several crucial changes that compliance teams must prepare for: 

Regulatory framework: 

  • Before 2027: A fragmented system where national laws were based on EU directives. 
  • From 10 July 2027: A single EU Regulation that applies directly and uniformly across all member states. 

Customer identification: 

  • Before 2027: Inconsistent KYC and identity verification rules that varied between countries. 
  • From 10 July 2027: Harmonised standards for customer identification, with a clear preference for secure electronic methods. 

Supervisory oversight: 

  • Before 2027: Supervision was handled exclusively by national supervisory authorities. 
  • From 10 July 2027: Oversight will be strengthened through the new European Anti-Money Laundering Authority (AMLA), which will coordinate supervision across the EU and directly supervise selected high-risk institutions. 

Why is a multi-layered approach to identity still necessary? 

While the AMLR creates a single rulebook, the adoption of digital identity solutions still varies significantly across Europe. This creates an operational challenge for businesses operating in multiple markets. 
As Bob Hulsebosch, Compliance Officer at Signicat, states in the guide: 

"There isn't a single perfect identification solution yet. Organisations will need to combine several methods, because adoption of electronic identities still varies widely across Europe." 

To prepare, organisations must develop agile onboarding systems capable of supporting multiple identification methods to ensure a compliant customer journey across all markets.