The Fourthline Team
Are You Ready for AMLR? A Self-Assessment for Compliance Teams
Are You Ready for AMLR? A Self-Assessment for Compliance Teams
According to PwC's 2026 EMEA AML Survey of 531 financial institutions, fewer than 1 in 3 EU institutions expect to be ready by the July 2027 deadline. Beyond that, it states that fewer than 30% have even completed a detailed impact assessment.
In our experience, this is not because compliance teams aren't working hard. On the contrary. It's because as the first EU-wide AML standard applied across Europe, AMLR is still difficult to prepare for.
If you haven't gotten started yet with what AMLR requires, begin by reading How to Prepare for AMLA Compliance: What Financial Institutions Must Do Before 2027. This article is for teams who are already in the preparation phase and want to assess where they actually stand.
1. Do you know exactly what AMLR requires of you?
AMLR obligations depend on the markets you operate in, the products you offer, and the customer segments you serve. A neobank that only works with retail customers in Germany faces different requirements than a payment institution serving SMEs across five EU markets.
Here are some specific questions to consider:
Have you mapped your specific AMLR obligations against your current product and market segments? This needs to be done product by product, market by market.
Do you know which customer segments will require enhanced due diligence? This includes (among others) Politically Exposed Persons, high-risk third country relationships, and business relationships involving assets over €5 million.
AMLR has three approved methods of remote onboarding: Qualified Electronic Signatures, eID, and the EUDI Wallet. Is at least one of these, part of your current or future verification flows?
2. Is your risk categorisation granular enough?
This may be the area where the largest gap exists between what has been standard practices up until now, and what AMLR requires.
AMLR demands significantly more granular risk categorisation than most institutions currently apply. What does this mean? For one thing, it is no longer sufficient to assign a customer a high, medium, or low risk rating. Instead, institutions will need to document what risk decision was reached, how (what data was used, what criteria were applied), and what outcome was executed upon.
Ask yourself:
If a regulator were to ask you how a risk decision was made (not just what it was) can you provide a legitimate audit trail? In practice, this means documenting what data you used, the criteria you applied, and how the call was made.
Is your organisation aligned around risk appetite across all functions? Technology, compliance, and business teams often operate to different standards without realising it.
3. Are your vendors as prepared as you are?
Vendors are often the weakest link in compliance preparation. Institutions focus intensely on internal readiness and assume their vendors are compliant — or don’t think it’s their problem.
But under AMLR, your entire compliance infrastructure needs to meet the standards, including your identity verification provider, transaction monitoring system, CDD tooling, and screening vendors. Simply put: a compliant institution built using non-compliant components is not truly compliant at all.
Consider these questions:
Have you formally assessed every third-party vendor against AMLR requirements? Transaction monitoring, CDD, screening, and identity verification all need to meet the standard. A compliant institution built on non-compliant infrastructure is not compliant.
Use your IDV provider as a litmus test. Can they demonstrate AMLR-approved remote onboarding methods, a tamper-evident audit trail, and a unified record of the full onboarding journey? If the answer is unclear, that's your answer.
At Fourthline, we submitted a formal response to the EBA consultation on AMLR's remote onboarding requirements. We have built our entire product roadmap around the three approved methods. We recognise that institutions cannot afford to wait for their vendors to catch up.
4. Have you stress-tested your audit trails?
In many ways, audit trails are the heart of compliance, and they are where AMLR readiness really becomes visible. The regulation stipulates that audit trails be complete, unaltered, and that they clearly show not just which decisions were made and the outcome, but how they were made.
In our experience, the most common source of audit trail gaps is not inadequate technology. It is the disconnection between identity verification and contract signing at the point of onboarding. When these steps are owned by different teams and built on different systems, the audit trail has to be reconstructed rather than retrieved. That distinction matters enormously when a regulator asks for a specific record.
Given this, consider:
Can you retrieve a complete, unaltered record of all customers’ onboarding journey on demand?
Are your identity verification and contract signing steps captured in a single, unified audit trail?
Are records retained for a minimum of five years from the end of a customer relationship, or from the date a relationship was refused, as required under AMLR Article 77?
Are those records stored securely, protected from alteration or deletion?
5. Do you have a realistic roadmap to July 2027?
Now that you hopefully have all the questions above answered in the affirmative, it’s time to consider your roadmap.
As the saying goes: time flies, particularly when it comes to meeting conspicuous regulatory deadlines! But in all seriousness, July 2027 isn't as far off as it sounds. When you factor in procurement timelines, new vendor onboarding, integration, testing, and regulatory approval, there’s plenty to get done before the deadline.
Based on our own experience, a typical integration runs to between 16 and 20 weeks from contract signature to go-live, with a total project timeline of up to 33 weeks, particularly when you include requirement gathering and post-launch monitoring.
Of course, timelines vary depending on scope and complexity, but this is a solid parameter to use to think through your timelines.
Ask yourself:
Have you completed a detailed impact assessment, or a specific mapping of what needs to change across systems, processes, and vendors?
Does your roadmap account for the full timeline, built backwards from July 2027?
Under AMLR Articles 9 and 11, internal policies must be approved by the Management Board, with a designated Compliance Manager accountable for implementation. Provided you have a roadmap ready, has it been approved by the right people?
The opportunity in the preparation gap
Of course, all this preparation seems like a lot to manage. But in our experience, there’s a huge upside to doing all this legwork that sits apart from meeting the standards.
AMLR presents a real opportunity to consolidate your fragmented infrastructure, modernise your entire compliance architecture, streamline your auditing tools, and to build systems that are more modern and secure.
There’s a financial upside, too. A Forrester study commissioned by Fourthline found that institutions using a unified, end-to-end compliance infrastructure achieve a 75–95% reduction in the cost of compliance. That's a clear argument for using AMLR as the chance to stop patching and start building properly.
The bottom line is that you shouldn’t wait. Preparing now will pay dividends in the long run, both with regulators and for your own bottom line.
Prepare for AMLR with Fourthline
Fourthline is one of Europe’s most trusted KYC, AML, and Authentication solutions for regulated financial institutions. We support all three AMLR-approved remote onboarding methods — Qualified Electronic Signatures, eID, and EUDI Wallet — and our systems generate a single, unified audit trail across every step of the customer journey. Every decision is logged automatically, retained securely, and retrievable on demand, giving compliance teams the evidence layer they need to demonstrate readiness when AMLA supervision begins.
FAQs
What are the penalties for non-compliance with AMLR?
Under AMLR, national competent authorities and AMLA have the power to issue binding decisions, impose administrative fines, and apply periodic penalty payments to institutions that fail to meet their obligations. For the highest-risk institutions under direct AMLA supervision, sanctions can also include temporary restrictions on business activity and the removal of senior management. Note that penalties are not reserved for institutions that actively breach the rules. They also apply to institutions that cannot demonstrate compliance.
Does AMLR apply to existing customers or only new ones?
AMLR applies to both, but the timelines differ. Customer relationships established after 10 July 2027 must comply with AMLR requirements from day one, while existing customer relationships have a transitional remediation period. However, even for older relationships, institutions must demonstrate a structured, risk-based plan for bringing these into compliance, prioritising the highest-risk customers first.
According to PwC's 2026 EMEA AML Survey of 531 financial institutions, fewer than 1 in 3 EU institutions expect to be ready by the July 2027 deadline. Beyond that, it states that fewer than 30% have even completed a detailed impact assessment.
In our experience, this is not because compliance teams aren't working hard. On the contrary. It's because as the first EU-wide AML standard applied across Europe, AMLR is still difficult to prepare for.
If you haven't gotten started yet with what AMLR requires, begin by reading How to Prepare for AMLA Compliance: What Financial Institutions Must Do Before 2027. This article is for teams who are already in the preparation phase and want to assess where they actually stand.
1. Do you know exactly what AMLR requires of you?
AMLR obligations depend on the markets you operate in, the products you offer, and the customer segments you serve. A neobank that only works with retail customers in Germany faces different requirements than a payment institution serving SMEs across five EU markets.
Here are some specific questions to consider:
Have you mapped your specific AMLR obligations against your current product and market segments? This needs to be done product by product, market by market.
Do you know which customer segments will require enhanced due diligence? This includes (among others) Politically Exposed Persons, high-risk third country relationships, and business relationships involving assets over €5 million.
AMLR has three approved methods of remote onboarding: Qualified Electronic Signatures, eID, and the EUDI Wallet. Is at least one of these, part of your current or future verification flows?
2. Is your risk categorisation granular enough?
This may be the area where the largest gap exists between what has been standard practices up until now, and what AMLR requires.
AMLR demands significantly more granular risk categorisation than most institutions currently apply. What does this mean? For one thing, it is no longer sufficient to assign a customer a high, medium, or low risk rating. Instead, institutions will need to document what risk decision was reached, how (what data was used, what criteria were applied), and what outcome was executed upon.
Ask yourself:
If a regulator were to ask you how a risk decision was made (not just what it was) can you provide a legitimate audit trail? In practice, this means documenting what data you used, the criteria you applied, and how the call was made.
Is your organisation aligned around risk appetite across all functions? Technology, compliance, and business teams often operate to different standards without realising it.
3. Are your vendors as prepared as you are?
Vendors are often the weakest link in compliance preparation. Institutions focus intensely on internal readiness and assume their vendors are compliant — or don’t think it’s their problem.
But under AMLR, your entire compliance infrastructure needs to meet the standards, including your identity verification provider, transaction monitoring system, CDD tooling, and screening vendors. Simply put: a compliant institution built using non-compliant components is not truly compliant at all.
Consider these questions:
Have you formally assessed every third-party vendor against AMLR requirements? Transaction monitoring, CDD, screening, and identity verification all need to meet the standard. A compliant institution built on non-compliant infrastructure is not compliant.
Use your IDV provider as a litmus test. Can they demonstrate AMLR-approved remote onboarding methods, a tamper-evident audit trail, and a unified record of the full onboarding journey? If the answer is unclear, that's your answer.
At Fourthline, we submitted a formal response to the EBA consultation on AMLR's remote onboarding requirements. We have built our entire product roadmap around the three approved methods. We recognise that institutions cannot afford to wait for their vendors to catch up.
4. Have you stress-tested your audit trails?
In many ways, audit trails are the heart of compliance, and they are where AMLR readiness really becomes visible. The regulation stipulates that audit trails be complete, unaltered, and that they clearly show not just which decisions were made and the outcome, but how they were made.
In our experience, the most common source of audit trail gaps is not inadequate technology. It is the disconnection between identity verification and contract signing at the point of onboarding. When these steps are owned by different teams and built on different systems, the audit trail has to be reconstructed rather than retrieved. That distinction matters enormously when a regulator asks for a specific record.
Given this, consider:
Can you retrieve a complete, unaltered record of all customers’ onboarding journey on demand?
Are your identity verification and contract signing steps captured in a single, unified audit trail?
Are records retained for a minimum of five years from the end of a customer relationship, or from the date a relationship was refused, as required under AMLR Article 77?
Are those records stored securely, protected from alteration or deletion?
5. Do you have a realistic roadmap to July 2027?
Now that you hopefully have all the questions above answered in the affirmative, it’s time to consider your roadmap.
As the saying goes: time flies, particularly when it comes to meeting conspicuous regulatory deadlines! But in all seriousness, July 2027 isn't as far off as it sounds. When you factor in procurement timelines, new vendor onboarding, integration, testing, and regulatory approval, there’s plenty to get done before the deadline.
Based on our own experience, a typical integration runs to between 16 and 20 weeks from contract signature to go-live, with a total project timeline of up to 33 weeks, particularly when you include requirement gathering and post-launch monitoring.
Of course, timelines vary depending on scope and complexity, but this is a solid parameter to use to think through your timelines.
Ask yourself:
Have you completed a detailed impact assessment, or a specific mapping of what needs to change across systems, processes, and vendors?
Does your roadmap account for the full timeline, built backwards from July 2027?
Under AMLR Articles 9 and 11, internal policies must be approved by the Management Board, with a designated Compliance Manager accountable for implementation. Provided you have a roadmap ready, has it been approved by the right people?
The opportunity in the preparation gap
Of course, all this preparation seems like a lot to manage. But in our experience, there’s a huge upside to doing all this legwork that sits apart from meeting the standards.
AMLR presents a real opportunity to consolidate your fragmented infrastructure, modernise your entire compliance architecture, streamline your auditing tools, and to build systems that are more modern and secure.
There’s a financial upside, too. A Forrester study commissioned by Fourthline found that institutions using a unified, end-to-end compliance infrastructure achieve a 75–95% reduction in the cost of compliance. That's a clear argument for using AMLR as the chance to stop patching and start building properly.
The bottom line is that you shouldn’t wait. Preparing now will pay dividends in the long run, both with regulators and for your own bottom line.
Prepare for AMLR with Fourthline
Fourthline is one of Europe’s most trusted KYC, AML, and Authentication solutions for regulated financial institutions. We support all three AMLR-approved remote onboarding methods — Qualified Electronic Signatures, eID, and EUDI Wallet — and our systems generate a single, unified audit trail across every step of the customer journey. Every decision is logged automatically, retained securely, and retrievable on demand, giving compliance teams the evidence layer they need to demonstrate readiness when AMLA supervision begins.
FAQs
What are the penalties for non-compliance with AMLR?
Under AMLR, national competent authorities and AMLA have the power to issue binding decisions, impose administrative fines, and apply periodic penalty payments to institutions that fail to meet their obligations. For the highest-risk institutions under direct AMLA supervision, sanctions can also include temporary restrictions on business activity and the removal of senior management. Note that penalties are not reserved for institutions that actively breach the rules. They also apply to institutions that cannot demonstrate compliance.
Does AMLR apply to existing customers or only new ones?
AMLR applies to both, but the timelines differ. Customer relationships established after 10 July 2027 must comply with AMLR requirements from day one, while existing customer relationships have a transitional remediation period. However, even for older relationships, institutions must demonstrate a structured, risk-based plan for bringing these into compliance, prioritising the highest-risk customers first.
Solutions
Solutions
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.