AMLD6's UBO Registry Deadline: What July 10 Means for KYC
The EU's AMLD6 beneficial ownership registry rules take effect July 10, 2026. Here's what changes for KYC, CDD, and identity verification teams.

Six weeks now stand between today and July 10, 2026. That is the transposition deadline for AMLD6's beneficial ownership registry provisions — the point at which EU Member States must have national rules in force. Those rules will require obliged entities to query interconnected registers, verify UBO data from more than one source, and document five years of historical ownership. Preparedness is still the exception among compliance teams. A sizable share of firms have not even registered that the deadline exists. Anyone who misses it will sit outside AMLD6 compliance from day one, and enforcement cases from 2024 and 2025 already show that "we did not know" is a defence regulators refuse to accept.
AMLD6's Beneficial Ownership Requirement, Explained
May 2024 is when the EU formally adopted the Sixth Anti-Money Laundering Directive, in parallel with the Anti-Money Laundering Regulation (AMLR). Beneficial ownership rules first introduced under AMLD5 are the provisions this instrument replaces. The underlying idea is unchanged: obliged entities have to identify and verify the beneficial owners of their corporate clients, meaning any natural person who ultimately owns or controls 25% or more of shares, voting rights, or other ownership interests. Depth, geographic reach, and the cross-border character of that verification duty are what have been rewritten.
Pulling a single national register record no longer closes the file under AMLD6. Multi-source verification is now required. Register data must be matched against documents the client supplies, against third-party data sources, and — where it is relevant — against queries to BORIS, the EU's new Beneficial Ownership Registers Interconnection System. A register starts the process. It does not finish it.
AMLA is the EU's new central supervisory authority. Final Customer Due Diligence Regulatory Technical Standards from that body are expected by July 10, 2026, matching the same deadline. What those standards demand of identity systems is set out in our analysis of AMLA's CDD RTS and the bar identity systems now have to meet.
Five Changes That Arrive on July 10, 2026
-
Mandatory 5-year historical ownership data. Current beneficial ownership is not enough on its own. Ownership structures going back five years must also be verified. If a corporate client changed hands in 2022, that history is relevant and has to be documented.
-
Non-EU entities with EU nexus are in scope. EU-incorporated entities were the main focus of AMLD5. AMLD6 pulls offshore and third-country structures into scope whenever they hold EU real estate, hold public contracts, or carry another qualifying nexus with the EU. A Cayman Islands SPV that owns a Paris apartment is now your compliance problem.
-
BORIS goes live. National UBO registers are joined through a central EU platform by the Beneficial Ownership Registers Interconnection System. Cross-border client books will need workflows that query BORIS — and that reconcile gaps between what BORIS returns and what the client discloses.
-
Harmonized legitimate-interest access for journalists and NGOs. A uniform framework now runs across Member States for third-party access to beneficial ownership information. Investigative journalists, civil society organizations, and academic researchers sit at the centre of that access. Public accountability is affected, as are the reputational risk assessments obliged entities run during enhanced due diligence.
-
AMLA publishes CDD RTS by July 2026. Customer Due Diligence Regulatory Technical Standards from AMLA, due by July 10, will set out with legal precision which methods of verifying beneficial ownership are acceptable. Optional guidance this is not. It is the technical rulebook. AMLA's mandate and its direct supervisory powers mean that firms falling below the RTS thresholds face enforcement from the centre, not merely from a national supervisor.
AMLD5 and AMLD6 Compared
| Area | AMLD5 | AMLD6 |
|---|---|---|
| Ownership threshold | 25% | 25% (unchanged) |
| Geographic scope | EU-incorporated entities | EU entities + non-EU entities with EU nexus |
| Register verification | Single national register query | Multi-source; BORIS cross-border queries required |
| Historical data | No mandatory look-back period | 5 years mandatory |
| Cross-border interconnection | Voluntary/bilateral | BORIS — mandatory EU platform |
| Access for journalists/NGOs | Member State discretion | Harmonized EU-wide framework |
| CDD technical standards | Directive-level principles | Binding RTS from AMLA |
| Supervisory authority | National FIUs only | National FIUs + direct AMLA supervision |
The move from AMLD5 to AMLD6 is not a modest tightening of the same rules. Verification, documentation, and cross-checking of beneficial ownership across the Single Market have been structurally redesigned.
What Obliged Entities Need in Place Before July 10
Refresh Your CDD Policy and Procedures
AMLD6's expanded scope has to appear in the CDD policy in plain terms. Cover non-EU entities with EU nexus. Record the five-year look-back obligation. Specify how BORIS queries will be folded into onboarding and into periodic review. Leave an AMLD5-era policy unamended and it will be non-compliant from July 10.
Put Multi-Source UBO Verification Workflows in Place
Single-register checks giving way to multi-source verification is the most operationally demanding change. The process now has to include: (a) a query to the relevant national register or to BORIS for cross-border structures, (b) review and reconciliation of ownership documents supplied by the client, and (c) checks against third-party data sources wherever register data is incomplete, stale, or at odds with client disclosures. Where discrepancies exist, they must be escalated and resolved. Ignoring them is not an option.
Identify Non-EU Client Exposure
Client books at many firms have never been audited for non-EU structures that now fall in scope. A systematic review is required. Which corporate clients are incorporated outside the EU? Do any of them hold EU real estate, take part in EU public procurement, or otherwise carry the nexus that triggers AMLD6 duties? Finish that mapping before July 10, not after it.
Train Compliance and Operations Staff
Procedures that nobody executing them understands are worthless. Training needs to cover the five-year look-back, the BORIS query process, how to treat mismatches between register data and client disclosures, and the escalation paths for complex structures. Keep a record of that training. Regulators ask for it.
Assess Your Technology Infrastructure
Does the KYC platform you run today handle BORIS queries? Can it store and surface five years of historical UBO data? Can it flag non-EU structures with EU nexus for enhanced screening? A "not yet" on any of those questions leaves six weeks either to fix the platform or to put in place a documented manual workaround that meets the evidentiary standard.
Why Automation Is No Longer Optional
The operational load AMLD6 creates is substantial. Corporate onboarding that currently runs one register query per entity now has to run multi-source checks, manage historical data, query BORIS for cross-border structures, and document reconciliation decisions. Spread that across a book of hundreds or thousands of corporate clients and the manual workload cannot be sustained at the quality level the rules demand.
That is the problem autonomous AI agents were built to solve. Headcount is not the only way to absorb the extra work. Firms are deploying AI agents that run UBO verification workflows from end to end — querying registers, cross-referencing data sources, flagging discrepancies, and sending only the genuinely ambiguous cases to human reviewers. Beneficial ownership verification that stays consistent, auditable, and scalable, and that does not degrade under volume, is the outcome.
Joinble's AI Agents were designed for this kind of multi-source, multi-step compliance workflow. Replacing compliance judgement is not the aim. The aim is to spend that judgement where it actually matters, instead of burning it on data retrieval and reconciliation that software performs more reliably than people.
Which Firms Are in Scope
AMLD6 covers the full set of obliged entities defined under the AMLR. Immediate operational pressure falls hardest on these sectors:
Banks and credit institutions — UBO verification is already familiar territory. Expanded scope and the multi-source requirement still mean existing processes need revision, not a light refresh.
Crypto-asset service providers (CASPs) — A stacked obligation faces CASPs operating under MiCA. The MiCA travel rule takes effect July 1, 2026, nine days before the AMLD6 UBO deadline. Teams already under strain on MiCA and travel rule compliance will see the AMLD6 duty land at the worst possible moment.
Real estate professionals and agents — Non-EU SPVs and holding structures used to acquire EU real estate sit explicitly in scope under AMLD6. Anyone who previously screened only EU-incorporated buyers now has to apply enhanced scrutiny to offshore structures.
Notaries, lawyers, and accountants — Firms that advise on corporate transactions, trust arrangements, or asset transfers must verify beneficial ownership for the structures they advise on. Professional secrecy carve-outs that AMLD5 allowed are narrower under AMLD6.
Trust and company service providers (TCSPs) — Forming companies, supplying registered office addresses, or acting as nominee directors now carries heightened duties. These entities are often the first point of entry for complex offshore structures.
Penalties Have Weight — and They Are Rising
The enforcement climate of the past 18 months has shifted in a material way. Two precedents show the direction of travel.
Bank of Scotland was fined £160,000 in January 2026 by the UK's Office of Financial Sanctions Implementation for opening and maintaining an account for a sanctioned Russian individual. The case turned on what the bank knew, when it knew it, and whether beneficial ownership checks at onboarding were adequate. Absolute size of the fine was modest. A public enforcement action against a major institution, for a failure that stronger UBO verification would have stopped, is what mattered.
More than $3 billion in penalties was agreed by TD Bank in 2024 after a US Department of Justice investigation into systemic AML control failures. The DOJ found that hundreds of millions of dollars in suspicious transactions had been processed over years — activity that adequate beneficial ownership checks and ongoing monitoring would have flagged far earlier. Scale of the failure, and size of the penalty, is what regulators do when systemic weaknesses go unaddressed.
EU enforcement is travelling the same road. AMLA now holds direct supervisory authority over the largest obliged entities. Pair that with the harmonized penalty framework under the AMLR and the fragmented, uneven enforcement of the AMLD5 years is coming to an end.
A Six-Week Sequence of Practical Steps
Time is short, so order of work matters. A sequenced action plan:
- Week 1–2: Audit the current UBO verification process against AMLD6 requirements. Name the gaps: scope gaps (non-EU entities not currently reviewed), process gaps (a single register query with no multi-source check), and data gaps (no historical ownership records).
- Week 2–3: Update the CDD policy and procedures. Obtain legal sign-off. Make sure the policy states the five-year look-back, BORIS query duties, and the non-EU nexus expansion in explicit terms.
- Week 3–4: Map the existing client portfolio for non-EU structures with EU nexus. Flag those clients for enhanced review. That cohort carries the highest risk of retroactive enforcement.
- Week 4–5: Implement or configure multi-source verification workflows. Where the current platform cannot support this, document the compensating controls that will be used until the platform is upgraded.
- Week 5–6: Train the relevant staff. Document the training. Run a parallel test of the new process on a sample of new onboardings before the deadline arrives.
Six weeks is enough to reach a defensible compliance posture if work starts now. It is not enough to invent a perfect process from nothing. Concentrate on the gaps that carry the highest enforcement risk: non-EU entities with EU nexus, clients with complex or layered ownership structures, and any file whose current records would not survive a regulatory audit.
FAQ
Does the 25% beneficial ownership threshold change under AMLD6? No. The threshold remains at 25% of shares, voting rights, or other ownership interests, consistent with AMLD5 and the FATF standard. What changes is how that ownership must be verified, documented, and cross-checked — not the threshold itself. Note, however, that the forthcoming AMLR changes this boundary condition from "more than 25%" to "25% or more" — a subtle but operationally significant distinction that affects every KYB rule engine in the EU. See our analysis of how the AMLR's UBO threshold change affects KYB processes in 2027.
What is BORIS and do obliged entities query it directly? BORIS (Beneficial Ownership Registers Interconnection System) is the EU's central platform linking national UBO registers. Direct API access by every firm is not the expected path. Access for obliged entities is expected to run through competent authorities and designated access points. Cross-border UBO checks must now take BORIS data into account, and mismatches between BORIS and other sources must be resolved rather than ignored. That is the operational implication that matters.
Our clients are all EU-incorporated. Does AMLD6 still affect us? Yes. Multi-source verification, the five-year historical data duty, and the AMLA CDD RTS apply whether clients are incorporated inside the EU or outside it. The non-EU nexus expansion adds scope. Enhanced verification requirements still apply to every corporate client.
When do we need to be compliant — July 10, 2026, or July 10, 2027? July 10, 2026 is the Member State transposition deadline, the date by which national rules implementing AMLD6's UBO provisions must be in force. Obliged entities must comply with those national rules from that date. July 10, 2027 attaches to the implementation period for AMLA's CDD RTS, which gives firms 12 months after RTS publication to adapt their systems. The two calendars are separate. They also overlap.
If AMLA publishes the CDD RTS on July 10, does that mean we have a year to comply? Publication of the CDD RTS starts a 12-month implementation period for the technical standards. AMLD6 itself — UBO registry obligations included — applies from the Member State transposition date of July 10, 2026. The RTS implementation window is not a reason to postpone beneficial ownership verification improvements that AMLD6 already requires. Each deadline serves a different purpose. They cannot be treated as one.
Related Articles

DORA and KYC: Identity Vendors Are Now ICT Third Parties
DORA's ICT third-party rules apply to KYC vendors from 2025. Here's what financial firms must audit, contract, and monitor to stay compliant in 2026.

SR 26-2: The Governance Gap in AI-Powered KYC
The Fed's new model risk guidance explicitly excludes generative and agentic AI. For banks using AI in KYC, that gap is now a compliance liability.

KYB Under AMLR: The UBO Threshold Trap of 2027
44% of KYB processes will fail the EU AMLR's new UBO threshold rules from July 2027. Here's how to audit your beneficial ownership verification now.