AMLA finalises draft Regulatory Technical Standards on Customer Due Diligence under the EU AML Regulation

written by
Headshot of a man with short hair wearing a suit and tie against a blurred background.
Rory Doyle
Head of Financial Crime Policy
published date
October 6, 2026
reading time
4
min

The EU Anti-Money Laundering Authority (AMLA) has published its final report on the draft Regulatory Technical Standards (RTS) on Customer Due Diligence (CDD) under Article 28(1) of the EU Anti-Money Laundering Regulation (AMLR), as firms prepare for implementation of the EU's new harmonised AML/CFT framework. The standards fill in much of the practical detail firms have been waiting for, covering how customers and beneficial owners should be identified and verified, how firms should understand the purpose and intended nature of a business relationship, and how simplified and enhanced due diligence, Politically Exposed Person (PEP) identification and screening and targeted financial sanctions screening should operate.

For compliance teams, many of the core obligations will be recognisable. The more significant shift is in the level of specificity: where national frameworks often allowed discretion in how standards were met, once adopted, the RTS will set a consistent baseline across the EU. The practical challenge is making it work in day-to-day operations. With the AMLR finalised and the draft RTS now submitted to the European Commission, firms are already confronting three questions: do they have the customer data they need, do their CDD processes actually change when risk changes, and how much work will be needed to bring existing records into line?

Start with the data

The RTS are more specific than many existing national frameworks about the identification information required under standard CDD, including names, addresses, place of birth and nationality. They also go further on the information and sources required to verify beneficial owners and understand ownership and control structures. One notable change from the consultation draft is the treatment of complex ownership structures. AMLA has removed the prescriptive test that could automatically classify certain multi-layer structures as complex, replacing it with a risk-sensitive assessment of factors such as ownership layers, legal arrangements, high-risk jurisdictions and nominee shareholders or directors. The instinctive response may be to add more fields to the onboarding journey, but that is unlikely to be the right starting point.

AMLA is not asking firms to collect the maximum possible amount of information from every customer. Relevant information already held by the firm should be considered, and the extent of CDD information and measures should remain proportionate to the money laundering and terrorist financing risk being addressed. That shifts the focus from collecting more data to understanding the quality of what is already held. Firms need to know what they have, where it came from, whether it has been verified and whether it can support a CDD decision with confidence.

Digital onboarding adds another layer of complexity. The RTS permit electronic identification means and relevant qualified trust services for identity verification. They also allow alternative non-face-to-face verification solutions where the customer cannot reasonably be expected to present their identity document face-to-face and does not have access to qualifying electronic identification means or relevant qualified trust services. These alternatives are subject to safeguards around identity matching, security, data quality and record keeping, and firms must be able to justify their use to their supervisor. Getting those controls right from the outset is considerably easier than retrofitting them to an existing digital journey.

Risk-based CDD must change the process

The treatment of risk is where the RTS become particularly important operationally. A reduced identification dataset may be appropriate in some lower-risk cases, while high-risk relationships require additional information or checks. The principle is familiar, but the RTS now put significantly more pressure on firms to demonstrate that risk genuinely changes what happens during CDD, not just how a customer is categorised. Assigning a risk rating is not the same thing as running a risk-based process.

If most customers still follow essentially the same journey, provide the same information and undergo the same checks, the risk rating has limited operational effect. Under the new framework, firms must be able to vary the information they obtain, the verification they perform, and the due diligence measures they apply as the level and nature of risk changes. That requires infrastructure that responds to the risk decision being made, not simply one that records it.

Where CDD requirements are hard-coded into onboarding journeys or spread across disconnected systems and manual procedures, even a relatively modest regulatory change can become a significant technology programme. A configurable approach gives firms considerably more room to adapt. With Fenergo, client and beneficial-owner data capture, identity verification, risk assessment, screening and due diligence are managed within a single client KYC and onboarding platform, with rules and workflows determining what happens for a particular client and risk profile. That makes it materially easier to demonstrate that risk is changing the process, not just the rating.

Plan for the existing customer book

For established firms, the existing customer base is where implementation effort tends to concentrate. New onboarding is only one part of the challenge. The new framework does not require firms to refresh every existing customer file at once. Existing records are to be brought into line on a risk-sensitive basis, within the applicable customer-information updating periods. The scale of that task may not always be obvious at the outset.

Before starting a broad remediation programme, firms need a clear view of which customers are affected: where required data is missing, where existing evidence no longer meets the standard, and where information already held is sufficient. That assessment can make a material difference to the size of the exercise. Treating the entire customer base as one remediation population creates work that may not be necessary and can lead to avoidable customer outreach, with the reputational and operational costs that brings.

A targeted approach starts by segmenting the data gaps. Firms can identify affected populations, distinguish between different types of issues and prioritise relationships by risk. Fenergo's client KYC and onboarding platform supports this by bringing client information together and applying configurable rules to determine where further information, verification or review is needed. That allows remediation to be scoped and sequenced against actual risk exposure, rather than working through the client book as a single undifferentiated queue.

What this means for firms

AMLA is seeking greater consistency in CDD across the EU while retaining a proportionate, risk-based approach. Firms must therefore meet more consistent standards without forcing every customer through the same process. That will be harder for organisations that rely heavily on manual controls, fragmented customer data or hard-coded workflows. In those environments, each regulatory change can trigger another cycle of customer outreach, remediation and technology redevelopment.

Regulators have long distinguished between firms that comply and firms that can demonstrate compliance. The draft AMLA RTS make expectations more explicit and harmonised. The difference, in practice, comes down to whether a firm's systems can show their working.

AMLA's final draft RTS have been submitted to the European Commission for adoption and may therefore still change. Once adopted and published in the Official Journal of the European Union, they are proposed to apply six months after their entry into force.

‍

About the author
Headshot of a man with short hair wearing a suit and tie against a blurred background.
Rory Doyle
Head of Financial Crime Policy

Rory Doyle, Head of Financial Crime Policy, joined Fenergo in 2017 and brings with him a wealth of subject matter expertise surrounding financial services, hedge funds, anti-money laundering, and financial crime regulations. Rory is also qualified with ACAMS as a Certified Anti-Money Laundering Specialist (CAMS). Additionally, Rory has extensive experience in the financial, legal, and compliance sectors from the likes of Merrill Lynch, Brown Brothers Harriman, and J.P. Morgan.

Share