AMLA's CDD Standards: What Identity Systems Must Deliver
AMLA's consultation on CDD technical standards closed May 8. Final rules go to the EU Commission by July 10. Here's what KYC systems must deliver.

Brussels shut a consultation window on May 8, 2026 that few compliance calendars had even marked. Public comments had been collected by the Anti-Money Laundering Authority on draft Regulatory Technical Standards covering Customer Due Diligence — the text that will lock down, in legally precise terms, the way identity verification has to operate throughout the EU.
Those final standards must reach the European Commission by July 10, 2026. Obliged entities then get until July 10, 2027 to reshape policies, systems, and controls. Member States also face a July 10 cutoff to put AMLD6's beneficial ownership registry rules into national law — two substantial compliance duties sharing one date.
Fourteen months. Comfortable on paper. Not in practice.
The Actual Scope of the AMLA CDD Technical Standards
General principles are not what AMLA's draft RTS on Customer Due Diligence (under Article 28(1) of the AML Regulation) sets out. Operational requirements are specified instead: acceptable documents, which electronic identification means qualify, the risk factors that must push a case from standard into enhanced due diligence, and the circumstances in which simplified CDD is allowed.
Identity verification across the EU financial system, the crypto sector, real estate, the luxury goods market, and every other obliged-entity category under the AMLR will be governed by this technical rulebook.
Three distinct areas sat inside the consultation:
| Area | Legal Basis | What It Governs |
|---|---|---|
| CDD requirements | Art. 28(1) AMLR | Documents, electronic means, verification methods |
| Business relationship monitoring | Art. 19(9) AMLR | Triggers for ongoing review and re-verification |
| Harmonised supervision | Art. 53(10) AMLD6 | Supervisor methodology for assessing CDD compliance |
Those three pillars are the starting point for grasping what identity systems must be capable of from July 2027 onward.
The Three-Tier CDD Framework
Customer due diligence is formalised by the AMLR as a three-tier scheme: standard, simplified, and enhanced. Technical boundary conditions for each tier are defined in the RTS.
Standard CDD
The default customer relationship is where standard CDD applies. Identity documents that obliged entities may collect and rely on when verifying customer identity and beneficial ownership are specified by the RTS.
Which electronic identification means satisfy CDD requirements is also formally established by the RTS. eIDAS-compliant electronic identification — credentials issued through the EU Digital Identity Wallet among them — qualifies for standard CDD under the framework and is treated as equivalent to face-to-face verification for these purposes.
The structural implication is this: an onboarding system that accepts government-issued eIDAS credentials at the same assurance level used for physical documents meets the CDD obligation without extra manual review. One that does not is accumulating technical debt that turns into a compliance liability in 2027.
Simplified CDD
Conditions under which reduced CDD measures may be applied by obliged entities are set out in the draft RTS. Electronic money instruments — prepaid cards and similar products — receive specific provisions, with AMLA naming the risk thresholds beneath which full CDD is not required.
KYC is not waived by simplified CDD. Verification depth is reduced in a calibrated way, and only when documented risk factors sit below defined thresholds. Those thresholds are defined explicitly by the RTS, closing the interpretive grey area that existed under earlier national transpositions of AMLD4 and AMLD5.
Enhanced CDD
Specific risk factors, once present, trigger enhanced CDD. "High risk" is not left undefined by the RTS — the conditions that mandate escalation are enumerated:
- Customers originating from jurisdictions on FATF grey or black lists
- Politically exposed persons (PEPs) together with their associates
- Transactions that involve complex corporate structures or nominee arrangements
- Transaction patterns that look unusual relative to the stated business purpose
- Non-face-to-face onboarding in settings where extra verification is warranted
A concrete technical implication follows for identity systems: verification measures have to be documentably more rigorous. Additional document types, extra liveness checks, source of funds verification, and, in some cases, senior management sign-off are what that means. A proportionality requirement is introduced by the RTS — enhanced measures must match the specific risk factors present rather than applying maximum intensity uniformly.
Where eIDAS 2.0 Intersects
Treatment of electronic identification means is among the most operationally significant parts of the CDD RTS. AMLA's standards plug directly into the eIDAS 2.0 framework and EUDI Wallet rollout schedule at this point.
Electronic identification means that satisfy certain attributes are treated as valid for CDD under the draft RTS. Technical requirements those means must fulfil — assurance levels, cryptographic properties, issuer trust — are defined so they can be accepted for standard and enhanced due diligence.
A direct implementation dependency follows: delay eIDAS 2.0 relying party registration and the compliance capability you build will already be technically outdated once the AMLR RTS enters force. Two regulatory clocks — EUDI Wallet deployment by December 2026 and AMLR RTS application from July 2027 — meet within seven months of each other.
Identity systems built around document capture alone will, as a practical matter, need fundamental re-architecture if they are to satisfy eIDAS 2.0 and the AMLR CDD standards at the same time.
Reach Beyond Banks and Payment Firms
Compared with earlier AML directives, the AMLR widens the obliged-entity category substantially. Banks and payment institutions are not the only ones covered by the CDD RTS; the full roster of regulated sectors is in scope:
- Crypto-asset service providers (CASPs) under MiCA
- Real estate agents and property managers
- Luxury goods dealers above transaction thresholds
- Accountants, auditors, tax advisors
- Trust and company service providers
- High-value goods dealers and auctioneers
CASPs already working through the MiCA licensing cutoff of July 1, 2026 pick up a second layer of technical obligation from the CDD RTS twelve months later. MiCA-compliant KYC flows will have to be audited against the AMLR CDD standards before July 2027 — and gaps will show up at many firms.
Real estate professionals face an entirely new compliance domain in the AMLR CDD standards. Lighter-touch AML requirements have historically applied to the sector. That changes categorically under the AMLR. What identity verification for property transactions must include, which document types are acceptable, and what ongoing monitoring business relationships require are all specified by the RTS. Luxury goods traders and other newly obliged sectors confront the same challenge — a full account of who is affected and what they must put in place is in AMLR 2027: New KYC Rules for Real Estate, Luxury & Football.
What Has to Be in Place Before July 2027
Between RTS publication (July 2026) and the application date (July 2027) sit 14 months, which can look like enough runway. It is not, for two reasons.
The RTS is not the only deliverable, first of all. Approximately 26 technical standards, implementing standards, and guidelines are being published by AMLA in 2026 alone. Interpretation, gap analysis, system adaptation, and documentation are required for each. Sequential work through that backlog means the last item finishes as the first compliance deadline arrives.
The technical changes required are not configuration updates, second. They involve:
- Aligning document acceptance logic with the RTS-defined acceptable document types
- Building or integrating eIDAS-compliant electronic identification verification
- Putting risk-factor detection in place so CDD level can be determined automatically
- Adding documented enhanced CDD workflows that include approval chains
- Refreshing ongoing monitoring triggers against the RTS-defined business relationship review conditions
- Producing audit-ready records that meet the RTS documentation requirements
| Action | When |
|---|---|
| Gap analysis: current KYC system vs. AMLR CDD RTS | Now — Q2 2026 |
| Begin eIDAS 2.0 relying party registration | Q2–Q3 2026 |
| Implement risk-factor-based CDD level logic | Q3 2026 |
| Complete enhanced CDD workflow architecture | Q4 2026 |
| Full testing and documentation review | Q1 2027 |
| AMLR CDD RTS application date | July 10, 2027 |
How AI Agents Shift the Equation
Analysts reviewing cases, applying judgement to CDD levels, and documenting decisions after the fact — that manual compliance model cannot scale to the volume and complexity the AMLR CDD RTS demands. Dynamic, documented, risk-proportionate decisions are required at onboarding and across the life of the business relationship.
A structural advantage sits exactly there for agentic KYC systems. Continuously scoring customer risk factors against RTS-defined triggers, an AI agent can pick the right CDD level in real time, apply the matching verification measures, record the decision with an audit trail, and re-evaluate once the risk profile shifts.
Read carefully, the AMLR CDD RTS describes a continuous intelligence problem — not a one-off document collection exercise. Verification has to stay ongoing, the risk assessment has to be refreshed, and documentation has to be contemporaneous. Agents run that workflow systematically; human-led processes run it at significant cost and inconsistency.
Separate draft guidelines were published by AMLA on 3 June 2026, addressing specifically how ongoing monitoring and transaction monitoring must be structured under Article 26 of the AMLR. Those requirements sit alongside the CDD RTS — the operational checklist is in AMLA's ongoing monitoring guidelines: what KYC systems must do.
KYC 3.0 architectures — organised around continuous, contextual, intelligence-driven verification — already line up with the AMLR CDD RTS design. Stacks organised around static document capture at onboarding will need a fundamental rethink before July 2027.
Joinble's AI Agents are built to run precisely this kind of dynamic, risk-calibrated compliance workflow — CDD level set by real-time risk signals rather than a manual questionnaire filled in at sign-up.
A Working Calendar for Compliance Teams
May 8 closed the CDD RTS consultation. Stakeholder feedback is now being processed by AMLA, which submits the final standards to the European Commission by July 10, 2026. The Commission reviews and adopts the standards. Application begins on July 10, 2027.
July 2027 is the visible milestone. The real deadline is now — because the systems, integrations, and workflows that must exist by July 2027 take 12 to 18 months to build and validate.
Treat this as a 2027 problem and Q1 2027 brings an uncomfortable reality: six months remain to implement changes that need 18.
A further pressure point sits between the AMLA deadline and the AMLR application date: the EU AI Act's high-risk AI provisions take effect on August 2, 2026 — three weeks after AMLA submits its final CDD standards. KYC systems that include AI-driven risk scoring or fraud detection will have both frameworks active at once inside the same quarter.
FAQ
What is the AMLA CDD RTS and why does it matter?
Exactly how obliged entities must verify customer identity across the EU is specified by the AMLA Regulatory Technical Standard on Customer Due Diligence. Acceptable documents, qualifying electronic identification means, and the conditions for standard, simplified, and enhanced due diligence are defined there. This is not guidance — it is binding technical law, applicable from July 10, 2027.
When do the final CDD technical standards get published?
The final draft RTS must be submitted by AMLA to the European Commission by July 10, 2026. Once the Commission adopts them, the standards apply from July 10, 2027. Twelve months are available for firms to implement the required changes from final publication.
Who does the AMLR CDD RTS apply to?
Every obliged entity under the AMLR: banks, payment institutions, e-money institutions, crypto-asset service providers (CASPs), real estate agents, luxury goods dealers, accountants, auditors, trust and company service providers, and others. The net is significantly broader than previous AML directives.
How does eIDAS 2.0 relate to the CDD technical standards?
eIDAS-compliant electronic identification means are formally recognised by the AMLA CDD RTS as valid for customer due diligence. Credentials issued through the EU Digital Identity Wallet will qualify for both standard and enhanced CDD where they meet the technical attributes defined in the RTS. A compliance gap awaits businesses that have not integrated eIDAS-compliant verification by July 2027.
How does simplified CDD differ from standard CDD under the RTS?
Reduced verification measures are allowed under simplified CDD when documented risk factors fall below defined thresholds. Those thresholds are specified explicitly by the RTS — including conditions for electronic money instruments. General risk-based discretion is not what this is: the conditions for simplified CDD must be met and documented, and ongoing monitoring continues even under simplified measures.
How can AI agents help meet the AMLR CDD requirements?
Customer risk factors can be evaluated by AI agents against AMLR-defined triggers in real time, the appropriate CDD level determined, the matching verification measures applied, the decision recorded with a complete audit trail, and the assessment updated when risk indicators change. Continuous, documented, proportionate compliance of the kind the AMLR CDD RTS requires is exactly this workflow — and the kind that manual processes cannot deliver at scale.
Related Articles

AMLA Ongoing Monitoring: What KYC Systems Must Do
AMLA's draft ongoing monitoring guidelines, published June 3, redefine KYC obligations under Article 26 AMLR. Here's your compliance checklist.

AMLA Is Watching: EU's New AML Authority
The EU's new Anti-Money Laundering Authority is now actively supervising crypto firms. Here's what CASPs must do before the July 2026 deadline.

Fraud Rings Now Recycle Identities Across KYC Systems
Shufti's September 2026 report exposes how organised fraud rings share devices, IP addresses, and forged identities to defeat KYC at scale.