Solutions

Industries

Markets

Partnerships

Resources

Get in touch

What is AMLR?

What is AMLR?

The Anti-Money Laundering Regulation (AMLR) is a new EU law that establishes a single framework across all 27 EU member states for fighting money laundering and terrorist financing. It goes into full effect on 10 July 2027

Unlike its predecessors, the Anti-Money Laundering Directives (AMLDs), AMLR applies across the entire EU, helping to close gaps and inconsistencies that led to confusion, extra burdens on companies operating across borders, and opened loopholes that criminals could exploit.  

What AMLR is replacing

Before AMLR, each country was responsible for coming up with their own approach to fighting financial crime. This created substantial variations across jurisdictions: different verification standards, different reporting thresholds, different interpretations of what constitutes appropriate Customer Due Diligence (CDD). 

The AMLR puts an end to this. As a regulation rather than a directive, it is binding in its entirety. This means that a bank onboarding customers in Germany will operate under identical AML requirements in France or Spain. This simplifies compliance for financial institutions over the long term. Enforcement is the responsibility of a new EU body (the Anti-Money Laundering Authority), marking the first time the EU has had a dedicated central authority for AML supervision. 

Learn more about AMLA, and its regulatory technical standards here.    

Understanding AMLR requirements 

The AMLR strengthens the core obligations of AMLD, while adding new requirements to the list. Here is a broad list of the requirements: 

Customer Due Diligence (CDD) 

Before any business relationship can begin, institutions must verify a customer’s identity as a first step. Then, they need to continue to verify their details throughout the entire relationship. AMLR sets the standard for how this verification should occur. 

For remote identification specifically, the AMLR singles out eIDAS-compliant methods: national eID schemes, Qualified Electronic Signatures (QES), and the EU Digital Identity (EUDI) Wallet. Document-based remote onboarding remains valid too, but approaches like Video-Ident are likely to become documented exceptions rather than defaults. 

Where risk is high, for example with Politically Exposed Persons (PEPs) or customers from higher-risk jurisdictions, Enhanced Due Diligence (EDD) applies. Where risk is demonstrably low, Simplified Due Diligence (SDD) is permissible. 

Transaction Monitoring

Because compliance doesn't stop once a customer is onboarded, financial institutions must continuously monitor transactions for signs of suspicious activity. When something doesn't look right, such as a high-volume transaction or one initiated from a different country, companies are now required to file a Suspicious Activity Report (SAR) with the relevant authorities. 

Audit trails 

According to AMLR, institutions must retain customer records and transaction data for a minimum of five years, measured from the end of the business relationship or the date of a one-off transaction. This ensures that a clear audit trail exists should it ever be needed by regulators or law enforcement. 

Beneficial ownership 

One of the areas where criminals have historically been able to circumvent legal obstacles is through creating complex corporate structures; entities designed to obscure who ultimately owns or controls a business. To prevent this, AMLR tightens the rules on beneficial ownership significantly, requiring institutions to identify and verify the benefial owners of any legal entity they work with. 

Who is subject to AMLR 

The AMLR applies to a broad range of obliged entities (organisations that are required to comply with AMLR). These include:  

  • Banks 

  • Payment institutions and electronic money institutions 

  • Investment firms and asset managers 

  • Crypto-asset service providers (CASPs) 

  • Insurance companies 

  • Auditors, accountants, and tax advisors 

  • Real estate agents and notaries 

  • Trust and company service providers 

What AMLR means for remote onboarding 

For financial institutions, AMLR's requirements around remote customer identification represent one of the most operationally significant changes in recent years.  

Under AMLR Article 22, eIDAS-compliant methods become the preferred path for remote customer identification. Here are the three methods that are prioritised:  

  1. National eID: Notified under eIDAS at substantial or high assurance level (e.g. German eID) 

  2. Qualified Electronic Signature (QES): The only method currently available at scale across all EU member states 

  3. EUDI Wallet: Available from member states by late 2026; mandatory acceptance for designated relying parties by December 2027 

Institutions that continue to rely on Video-Ident need to formally document and justify that decision to supervisors.  

AMLR compliance with Fourthline 

Fourthline's platform supports all three AMLR-compliant identification methods, QES, national eID, and EUDI Wallet, within a single orchestration layer. As Europe's leading QES provider and a certified Qualified Trust Service Provider (QTSP), holding ISO/IEC 27001:2022 certification and official BVA authorisation as a German eID service provider, Fourthline is built to help financial institutions meet AMLR requirements without rebuilding their onboarding stack from scratch. 

FAQs 

What is the difference between AMLR and the Anti-Money Laundering Directives (AMLDs)? 

The AMLDs were directives. They set goals for the bloc, but required each EU member state to interpret and transpose them into national law, resulting in confusion and loopholes. The AMLR is a broadly applicable regulation, meaning it applies directly and uniformly across all 27 member states without national transposition. This eliminates the inconsistencies that have allowed for compliance gaps and blind spots that enabled financial crime. 

Does AMLR mean we have to stop using Video-Ident? 

Not immediately, but it does change its status. Under AMLR, eIDAS-compliant methods (national eID, QES, and the EUDI Wallet) become the preferred remote identification path from July 2027. Video-Ident and other non-eIDAS methods are not currently prohibited, but institutions using them for customers who could use eIDAS-compliant alternatives may need to formally justify that decision.  

What is the difference between AMLR and RTS? 

The AMLR (Anti-Money Laundering Regulation) establishes the high-level obligations: what financial institutions must do, who is subject to the rules, and what outcomes must be achieved. The RTS (Regulatory Technical Standards) sit on a tier beneath that. They are effectively the detailed implementation rules that specify how institutions should comply. This includes which identity verification methods are acceptable, what CDD data must be collected, and how ongoing monitoring should be conducted. Both take effect on July 10, 2027 and are legally binding. 


 

The Anti-Money Laundering Regulation (AMLR) is a new EU law that establishes a single framework across all 27 EU member states for fighting money laundering and terrorist financing. It goes into full effect on 10 July 2027

Unlike its predecessors, the Anti-Money Laundering Directives (AMLDs), AMLR applies across the entire EU, helping to close gaps and inconsistencies that led to confusion, extra burdens on companies operating across borders, and opened loopholes that criminals could exploit.  

What AMLR is replacing

Before AMLR, each country was responsible for coming up with their own approach to fighting financial crime. This created substantial variations across jurisdictions: different verification standards, different reporting thresholds, different interpretations of what constitutes appropriate Customer Due Diligence (CDD). 

The AMLR puts an end to this. As a regulation rather than a directive, it is binding in its entirety. This means that a bank onboarding customers in Germany will operate under identical AML requirements in France or Spain. This simplifies compliance for financial institutions over the long term. Enforcement is the responsibility of a new EU body (the Anti-Money Laundering Authority), marking the first time the EU has had a dedicated central authority for AML supervision. 

Learn more about AMLA, and its regulatory technical standards here.    

Understanding AMLR requirements 

The AMLR strengthens the core obligations of AMLD, while adding new requirements to the list. Here is a broad list of the requirements: 

Customer Due Diligence (CDD) 

Before any business relationship can begin, institutions must verify a customer’s identity as a first step. Then, they need to continue to verify their details throughout the entire relationship. AMLR sets the standard for how this verification should occur. 

For remote identification specifically, the AMLR singles out eIDAS-compliant methods: national eID schemes, Qualified Electronic Signatures (QES), and the EU Digital Identity (EUDI) Wallet. Document-based remote onboarding remains valid too, but approaches like Video-Ident are likely to become documented exceptions rather than defaults. 

Where risk is high, for example with Politically Exposed Persons (PEPs) or customers from higher-risk jurisdictions, Enhanced Due Diligence (EDD) applies. Where risk is demonstrably low, Simplified Due Diligence (SDD) is permissible. 

Transaction Monitoring

Because compliance doesn't stop once a customer is onboarded, financial institutions must continuously monitor transactions for signs of suspicious activity. When something doesn't look right, such as a high-volume transaction or one initiated from a different country, companies are now required to file a Suspicious Activity Report (SAR) with the relevant authorities. 

Audit trails 

According to AMLR, institutions must retain customer records and transaction data for a minimum of five years, measured from the end of the business relationship or the date of a one-off transaction. This ensures that a clear audit trail exists should it ever be needed by regulators or law enforcement. 

Beneficial ownership 

One of the areas where criminals have historically been able to circumvent legal obstacles is through creating complex corporate structures; entities designed to obscure who ultimately owns or controls a business. To prevent this, AMLR tightens the rules on beneficial ownership significantly, requiring institutions to identify and verify the benefial owners of any legal entity they work with. 

Who is subject to AMLR 

The AMLR applies to a broad range of obliged entities (organisations that are required to comply with AMLR). These include:  

  • Banks 

  • Payment institutions and electronic money institutions 

  • Investment firms and asset managers 

  • Crypto-asset service providers (CASPs) 

  • Insurance companies 

  • Auditors, accountants, and tax advisors 

  • Real estate agents and notaries 

  • Trust and company service providers 

What AMLR means for remote onboarding 

For financial institutions, AMLR's requirements around remote customer identification represent one of the most operationally significant changes in recent years.  

Under AMLR Article 22, eIDAS-compliant methods become the preferred path for remote customer identification. Here are the three methods that are prioritised:  

  1. National eID: Notified under eIDAS at substantial or high assurance level (e.g. German eID) 

  2. Qualified Electronic Signature (QES): The only method currently available at scale across all EU member states 

  3. EUDI Wallet: Available from member states by late 2026; mandatory acceptance for designated relying parties by December 2027 

Institutions that continue to rely on Video-Ident need to formally document and justify that decision to supervisors.  

AMLR compliance with Fourthline 

Fourthline's platform supports all three AMLR-compliant identification methods, QES, national eID, and EUDI Wallet, within a single orchestration layer. As Europe's leading QES provider and a certified Qualified Trust Service Provider (QTSP), holding ISO/IEC 27001:2022 certification and official BVA authorisation as a German eID service provider, Fourthline is built to help financial institutions meet AMLR requirements without rebuilding their onboarding stack from scratch. 

FAQs 

What is the difference between AMLR and the Anti-Money Laundering Directives (AMLDs)? 

The AMLDs were directives. They set goals for the bloc, but required each EU member state to interpret and transpose them into national law, resulting in confusion and loopholes. The AMLR is a broadly applicable regulation, meaning it applies directly and uniformly across all 27 member states without national transposition. This eliminates the inconsistencies that have allowed for compliance gaps and blind spots that enabled financial crime. 

Does AMLR mean we have to stop using Video-Ident? 

Not immediately, but it does change its status. Under AMLR, eIDAS-compliant methods (national eID, QES, and the EUDI Wallet) become the preferred remote identification path from July 2027. Video-Ident and other non-eIDAS methods are not currently prohibited, but institutions using them for customers who could use eIDAS-compliant alternatives may need to formally justify that decision.  

What is the difference between AMLR and RTS? 

The AMLR (Anti-Money Laundering Regulation) establishes the high-level obligations: what financial institutions must do, who is subject to the rules, and what outcomes must be achieved. The RTS (Regulatory Technical Standards) sit on a tier beneath that. They are effectively the detailed implementation rules that specify how institutions should comply. This includes which identity verification methods are acceptable, what CDD data must be collected, and how ongoing monitoring should be conducted. Both take effect on July 10, 2027 and are legally binding. 


 

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.