AMLR, Regulation (EU) 2024/1624, applies directly from 10 July 2027. In Sweden, the Swedish AML Act (2017:630) applies until then. AMLR sets out what customer due diligence (CDD) must cover. AMLA must propose technical standards on how. See What is AMLA?
This article covers two drafts:
- The draft RTS on CDD under Article 28(1) AMLR, dated "Frankfurt am Main – 9 February 2026"
- The draft RTS on business relationships and transactions under Article 19(9) AMLR, dated "Frankfurt am Main – 09/02/2026"
Are the standards adopted?
No. Both are drafts that AMLA put out for public consultation. The consultation opened on 9 February 2026 and closed on 8 May 2026. AMLA's consultation page says the consultation is closed and "Results will follow."
The next steps are:
- AMLA considers the feedback and submits final draft standards to the Commission.
- The Commission normally decides within three months. It may adopt the draft in full, in part or with amendments (Article 49 of Regulation (EU) 2024/1620).
- The standard is adopted as a delegated regulation and then applies directly in every Member State.
The draft RTS on CDD builds on the EBA's draft of 30 October 2025, adapted for the non-financial sector. It leaves the date of application open. The draft on business relationships proposes 10 July 2027.
Everything below is a proposal. Where we cite AMLR, that is adopted law.
What data must you collect on a natural person?
Article 22(1)(a) AMLR sets the minimum: all names and surnames, place and full date of birth, nationalities and usual place of residence. The draft adds detail:
- Names: all names and surnames on the identity document (Article 2).
- Address: the country (full name or ISO 3166 code), the city, and where available the postal code, street, building and apartment number (Article 3).
- Place of birth: at least the country. If the identity document shows more, collect that too (Article 4).
- Nationality: all nationalities, or statelessness and refugee or subsidiary protection status (Article 5).
According to the recitals, verifying one nationality is sufficient where a person declares several in good faith.
What data must you collect on a legal person?
Article 22(1)(b) AMLR requires, among other things, the legal form, name, registered office address and the names of legal representatives. Under the draft, you must also obtain the trade name where it differs from the registered name (Article 2).
Ownership and control structure
Where the structure contains more than one legal entity or arrangement, you must obtain a description of it, including intermediate entities (Article 11). You must be satisfied that the description is credible, that there is an economic, legal or other rationale behind the structure, and that you understand how it affects the risk.
Under Article 12, a structure is complex if there are three or more layers between the customer and the beneficial owner and more than one of the following applies:
- there is a legal arrangement or a foundation in any layer
- the customer or any entity in the layers is registered outside the EU
- there are nominee shareholders or nominee directors
- the structure obscures ownership with no legitimate economic rationale
You may then need additional information, such as an organigram.
Beneficial owner
According to the recitals, consulting the central beneficial ownership register is "necessary but not sufficient" for verification. Article 10 requires at least one further measure. This can be other public registers, such as residence or land registers, or information from the customer and other sources. See beneficial ownership.
If no beneficial owner can be identified, you collect the same information on the senior managing officials. You may use the company's registered office address instead of their residential address (Article 13).
How must identity be verified?
Article 22(6) AMLR allows two methods: an identity document, passport or equivalent, or electronic identification under the eIDAS Regulation at assurance level substantial or high. The draft details both.
What counts as an equivalent document?
Under Article 6(1), the document must meet all of these conditions:
- issued by a state or public authority
- contains all names and surnames and the date of birth
- contains an expiry date and a document number
- contains a facial image and the holder's signature
- has security features to ensure authenticity
Lighter requirements apply where a person cannot provide such a document for a legitimate reason, such as statelessness (Article 6(2)). Documents must always be checked for authenticity (Article 6(3)).
Remote verification
Article 7 of the draft makes electronic identification the first choice for non-face-to-face verification. You must use electronic identification means at assurance level substantial or high, or qualified trust services.
Other remote solutions, such as an uploaded identity document with a face match, may be used only where electronic identification is not available or cannot reasonably be expected. The solution must, among other things:
- check that the person presenting the document is the person in the picture
- stop the process on technical failures or doubts about identity
- keep time-stamped copies so the check can be verified afterwards
You must be able to show your supervisor that the solution meets the requirements, and justify why electronic identification was not used. In Sweden today, Chapter 3, Section 7 of the Swedish AML Act allows both electronic identification and other secure remote identification processes.
Annex I to the draft lists the attributes the electronic identification must carry. If an attribute is missing, you must obtain and verify it by other means (Article 32(3)).
What does the draft say about simplified due diligence?
Article 33(1) AMLR already lists the simplified measures, such as delaying verification by up to 60 days and updating customer data less often. AMLA states that it found no further simplifications it could propose without creating exemptions from AMLR.
Instead, the draft sets a minimum for low-risk situations:
| Area | Minimum in low-risk situations |
|---|---|
| Natural person (Art. 20) | All names, place of birth, date of birth, nationalities |
| Legal person (Art. 20) | Legal form, registered and trade name, registered office address, registration or tax number or LEI where available |
| Beneficial owner (Art. 21) | Identify from one source: the register, the customer or a reliable open source. Verify with one of the other two |
| Updates (Art. 23) | Less frequent updates require monitoring that nothing has changed. Data must still be updated within five years |
| Purpose (Art. 24) | Intended use, estimated value and, where necessary, source of funds |
The glossary explains simplified due diligence.
What does the draft say about enhanced due diligence?
Article 34(4) AMLR lists enhanced measures, including more information on the customer, the relationship and the source of funds and wealth. The draft (Articles 25 to 28) sets out what that information must allow, such as assessing the customer's reputation and whether transactions match the declared business.
For source of funds and source of wealth, Article 27 gives examples of evidence:
- tax declarations, pay slips or other official income statements
- audited accounts, investment documentation and loan agreements
- contracts of sale, inheritance and gift documentation
- information from reliable registers or reputable media
The evidence must satisfy you that the funds derive from lawful activities. See customer risk assessment.
What do the drafts say about screening and existing customers?
PEPs: You must determine whether the customer or beneficial owner is a PEP before the relationship starts, and then at a risk-based frequency (Article 19). Automated tools are required, unless your size or business justifies manual checks only. See PEP screening.
Sanctions: Screen at onboarding, when sanctions designations change and when customer data changes significantly (Article 30). See sanctions screening.
Existing customers: Data on customers onboarded before the standard is published must be brought into line on a risk-sensitive basis, and at the latest within the AMLR periods of one and five years (Article 33 of the draft). Work out your dates with the review interval tool.
What does the draft say about business relationships?
The draft under Article 19(9) AMLR sets criteria for business relationships and linked transactions. It applies, among others, to auditors, external accountants and tax advisers, lawyers and other independent legal professionals, trust or company service providers and real estate agents (Article 3(3)(a) to (d) and (l) AMLR). They must at least consider whether services are provided at different intervals and whether different services are provided (Article 2(2)). Both point towards a business relationship.
AMLA does not propose any new lower thresholds for occasional transactions. The draft can affect whether a customer needs ongoing monitoring.
One customer file
AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. Read more about the platform.