Is July 10, 2027, marked in your calendar? It’s not your anniversary or your best friend’s birthday. It’s the day in which 27 national AML rulebooks combine into one.
On this date, the EU’s Anti-Money Laundering Regulation (AMLR) becomes directly applicable across every Member State – no national transposition, no local carve-outs, no waiting for your regulator to publish its interpretation.
If your onboarding flow was built for the directive era, you have less than a year to rebuild it for the regulation era.
Here are the five things every compliance, product, and onboarding leader needs to understand and what to do about each one.
1. It’s a regulation, not a directive and that single word changes everything
For three decades, EU anti-money laundering rules arrived as directives: frameworks each Member State transposed into national law on its own timeline, with its own interpretations. The result is patchy. For example, a fintech company with business in both Spain and Germany onboards customers via two different CDD processes, tracks two sets of thresholds, and answers to two supervisors reading two separate rulebooks.
AMLR ends that. As a regulation, it applies word-for-word in every Member State from day one. Same customer identification standards, same thresholds, same documentation requirements from Lisbon to Helsinki.
What this means for you: The upside is real: one compliance framework can finally serve your whole EU footprint. The catch is that “we follow local guidance” stops being a defensible position. If your controls were tuned to the most lenient national interpretation you operate under, the harmonized standard is likely tighter than what you’re running today.
Do this now: Map your current onboarding requirements country by country and flag every place where you rely on a national exemption or lighter local rule. Those are your gaps.
2. You may be an “Obliged Entity” without knowing it
Banks, payment institutions, and investment firms already know they’re covered. But AMLR redraws the perimeter, and some of the new verticals on the list are surprising:
- Crypto-asset service providers (CASPs) now fully obliged entities under the same regulation as banks, with CDD required for occasional transactions from €1,000
- Crowdfunding platforms – including those outside existing EU crowdfunding rules
- Traders in luxury goods: jewellery, watches, art, high-end vehicles, yachts and aircraft
- Professional football clubs and agents – a first for EU AML law
- Non-EU companies serving EU customers – geography doesn’t exempt you; your customer base pulls you in
What this means for you: If you’re in one of these sectors, you’re not adapting an existing AML program ,you’re building one, and July 2027 is fast approaching.
If you sell to these sectors, an entire new market of first-time obliged entities is about to go shopping for compliance infrastructure.
Do this now: Confirm your classification with counsel early. “We didn’t think it applied to us” has never once worked as a defense.
3. CDD gets teeth: 15% ownership, €10,000 in cash, no wiggle room
AMLR doesn’t just harmonize customer due diligence. It hardens it. Three numbers tell the story:
15%. The beneficial ownership threshold stays at 25% as the general rule but drops to 15% for entities in higher-risk sectors. This means unwrapping ownership structures further than before and if a customer sits three shell companies deep, you’re expected to keep digging until you reach a human being. Verification against reliable, independent sources becomes the explicit standard, not a best practice.
€10,000. An EU-wide cap on cash payments, with Member States free to go lower. High-value goods traders, take note: this is aimed squarely at you.
Every customer, evidenced. AMLR is prescriptive about how identity is established and verified which data points, which documents, and what evidence trail you keep. Regulators won’t ask whether you verified a customer. They’ll ask you to show them: the checks you ran, the sources you validated against, and the decision logic you applied.
Do this now: Audit your evidence trail. If a supervisor asked you today to reconstruct why you onboarded a specific customer eighteen months ago the document checks, the screening results, the risk score could you produce it in hours, or weeks?
4. Electronic ID goes from nice-to-have to expected default
The quiet revolution inside AMLR explicitly aligns customer identification with the eIDAS 2.0 framework notified electronic IDs, Qualified Trust Services, and the European Digital Identity Wallet.
The message is blunt: the EU expects identity verification to be electronic, verifiable, and consistent. Manual document review a human squinting at a scanned ID doesn’t just scale poorly. Under AMLR’s evidence standards, paper-first onboarding will look increasingly indefensible: slower, more error-prone, and harder to audit than the electronic methods the regulation openly favors.
This lands at the worst possible moment for manual processes, because the documents themselves can no longer be trusted at face value. AI-generated forgeries and deepfake-driven onboarding attacks have industrialized. The question is no longer “does this document look real?” it’s “can my verification stack detect a synthetic identity that was built to pass human review?”
Do this now: Assess your verification stack against three capabilities: automated document authenticity analysis, biometric liveness with deepfake and injection-attack detection, and readiness to accept EU Digital Identity Wallet credentials when your customers start presenting them.
5. AMLA isn’t a new acronym. It’s a new boss.
Until now, AML supervision was national: 27 authorities, 27 enforcement styles, 27 sets of priorities. AMLR pairs the single rulebook with a single supervisor to match the Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt.
AMLA will directly supervise the highest-risk cross-border financial institutions, coordinate national supervisors everywhere else, and critically issue the binding technical standards that translate AMLR’s articles into operational detail. The first waves of those standards are already arriving, and they will keep landing between now and 2027, each one narrowing the room for interpretation.
What this means for you: Compliance stops being a set-and-forget project and becomes a moving target you track quarterly. The firms that treat AMLA’s technical standards as a release calendar reviewing each drop and adjusting will be ready in July 2027. The firms that wait for a final, settled rulebook will discover there’s no such thing.
Do this now: Assign clear ownership for tracking AMLA publications, and build regulatory-change review into your quarterly compliance cycle rather than your annual one.
July 2027 is sooner than you think
Strip out procurement cycles, integration work, testing, and staff training, and July 2027 is effectively two or three budget quarters away. The firms that will cross the deadline comfortably are the ones treating AMLR as a 2026 project with a 2027 deadline not a 2027 problem.
The directive era rewarded firms that adapted to each market. The regulation era rewards firms that get it right once with verification that’s automated, evidenced, and consistent everywhere.
AU10TIX helps the world’s leading financial institutions, CASPs, and platforms automate identity verification with full audit trails built for the regulation era. Book a demo today.



