The long-awaited technical standards on customer due diligence under Article 28(1) of the EU Anti-Money Laundering Regulation (AMLR) are now in their final form. Here is what changes for KYC, remote identification and ongoing monitoring.
If you work in KYC, onboarding or compliance, you have probably been waiting for this document for a long time. At the time of writing, the EU Anti-Money Laundering Authority (AMLA) has published the final report on its draft Regulatory Technical Standards (RTS) on customer due diligence (CDD) under Article 28(1) of Regulation (EU) 2024/1624, the AMLR.
It is one of three sets of standards that AMLA has finalised for the private sector, after several rounds of public consultation. They will now be submitted to the European Commission, adopted as a Commission Delegated Regulation and published in the Official Journal of the European Union. Until that happens they remain formally “draft”, but the substance is stable enough to plan against.
This article covers what the CDD RTS says, which provisions matter most for KYC teams, and why this is the moment to review your onboarding stack.
Why this RTS matters
The AMLR is directly applicable. It replaces the patchwork of national transpositions of the old AML directives with a single rulebook. But a regulation sets principles and leaves gaps: which data points exactly, which documents, which sources, what counts as “reliable and independent”, and when remote verification is acceptable.
The CDD RTS fills those gaps. It harmonises how CDD is applied across Member States and across both financial and non-financial obliged entities, including newer categories such as crowdfunding providers, crypto-asset service providers and mortgage credit intermediaries.
The road to the final text was long:
- the European Commission asked the EBA for advice in 2024
- the EBA delivered its response in late 2025 and in early 2026;
- AMLA took the EBA text as its baseline and adapted it to also work for the non-financial sector;
- AMLA then ran a three-month public consultation, received 325 responses (including Namirial) and held a public hearing with more than 1,600 participants.
The result keeps the EBA’s structure but is more flexible, more principle-based and less checklist-driven.
A risk-based rulebook, not a checklist
The most important message sits in Article 1: the RTS must be applied in line with the risk-based approach. The extent and nature of the information collected must be proportionate to the type and level of risk identified, and simplified due diligence (SDD) is explicitly encouraged in low-risk situations.
Many consultation respondents feared that the long lists of data in the draft would be read as mandatory checklists. AMLA’s answer was to strengthen Article 1 and rewrite several provisions so that the scope of information stays “commensurate” with the risk. AMLA’s accompanying factsheet repeats that the examples on purpose and intended nature are non-exhaustive and not a prescriptive checklist.
For KYC teams, this means more room to design proportionate journeys, and also more responsibility to document why your approach is adequate.
Remote identification, eID and EU Digital Identity Wallets
If you run digital onboarding, Articles 6, 7 and 27 and Annex I deserve the most attention.
eID and qualified trust services come first
Article 22(6) AMLR says identity is verified through (a) an identity document, passport or equivalent, or (b) electronic identification means and relevant qualified trust services under the eIDAS Regulation. Recital 11 of the RTS clarifies the scope of option (b):
- It covers electronic identification (eID) means at “substantial” or “high” assurance level under Implementing Regulation (EU) 2015/1502, whether or not they are notified under eIDAS.
- It expressly includes European Digital Identity Wallets.
- It also covers relevant qualified trust services, such as Namirial as QTSP with Qualified Electronic Signatures (QES) embedded processes.
Article 6(4) adds that these means can also be used face to face, so they are not limited to remote scenarios.
Alternative remote verification is the exception
The consultation showed a recurring worry that the draft created an “eIDAS-first” regime that would sideline existing remote onboarding tools. AMLA’s answer has two parts:
- The Article 22(6) means remain the default. Article 7 alternatives apply only where the customer cannot reasonably present the document in person and has no access to eID or qualified trust services meeting Article 22(6)(b).
- Existing remote onboarding tools can continue to be used, provided they meet the minimum requirements of Article 7.
Those requirements are concrete. Article 7(2) calls for controls to ensure:
- the person presenting the document is its holder,
- integrity and confidentiality of the communication,
- images, video, sound and data of sufficient quality to identify the person unambiguously,
- interruption of the process on technical failures or doubts about identity or process integrity.
It also requires that verified documents and data are valid and up to date, and that records are retained, time-stamped, stored securely and readable for ex post verification. Namirial Onboarding, including its biometric components, is already fully aligned with these requirements and certified against ETSI TS 119 461 v2, the de facto standard for identity proofing, which will soon be published as EN 319 461.
Article 7(3) adds a justification duty: you must be able to explain why a given customer could not be verified through the Article 22(6) means, and demonstrate to your supervisor that the alternative solution complies.
In practice, remote KYC flows should treat eID, EUDI Wallet and QES as the primary path wherever possible, with alternative methods as a documented fallback to cover all the use cases. Teams relying mainly on selfie-plus-document or video identification should map their flows to Article 7 and start collecting evidence of why the fallback was used.
Document authenticity and Annex I
Recital 8 stresses that documents used for identity verification should be checked for authenticity, including whether they have been forged or tampered with. Article 6 defines the minimum content of an “equivalent” document: names, place and date of birth, document number and expiry, facial image, signature and security features. A relaxed set applies to people who cannot hold standard documents, such as refugees and stateless persons.
Annex I lists the minimum attributes that eID means and qualified trust services must be able to provide, based on the person identification data of Implementing Regulation (EU) 2024/2977 for EUDI Wallets.
Identification data: names, birthplace, nationality, address
The RTS standardises what you collect from natural persons and legal entities:
- Names (Art. 2): all names that feature on the identity document or in the eID, including given names and surnames. For legal entities, the legal name plus the trade name where it differs.
- Address (Art. 3): country and city, municipality, town or village as core data points, plus state, postal code, street and building number where they exist. For senior managing officials, the registered office of the legal entity may replace their residential address.
- Place of birth (Art. 4): at least the country, state, city, municipality, town or village, as shown on the document or eID/wallet.
- Nationalities (Art. 5): take reasonable measures to establish whether a person holds more than one nationality. If several are declared, record them and verify at least one.
These flexibilities answer a real operational problem: identity documents across the EU do not present birthplace, middle names or addresses in a uniform way. Passports, for instance, usually carry no residential address. In that case the address must be verified through reliable and independent sources, but you do not need to request extra documents for data already verified through the identity document.
The AMLR requires every data point collected for identification to be verified, and the RTS cannot derogate from that. AMLA said so explicitly when rejecting calls to limit verification to a core subset. The relief comes through SDD: in low-risk situations, Article 18 allows a reduced data set and, for natural persons, no need to collect and verify the address.
Sources, beneficial ownership and purpose of the relationship
Reliable and independent sources (Art. 8). Assess sources on credibility, official status, independence, currency and accuracy, and understand the information whatever its language.
Beneficial ownership (Arts. 10, 11 and 19). Central registers are not enough on their own for verification. Article 10 lists other sources: business, tax, residence and property registers, reputable data providers and certified company documents. In low-risk cases, Article 19 allows different sources for identification and verification. Complex ownership chains fall under a single risk-sensitive provision (Art. 11).
Purpose and intended nature (Arts. 16 and 20). Understand the purpose, expected activity, source of funds and occupation or business, with depth commensurate with the risk. Article 20 sets a minimal baseline for low-risk customers; Articles 21 to 24 describe additional EDD information for high-risk ones, at the firm’s discretion.
Ongoing monitoring, re-identification and screening
This is where many compliance teams will feel the operational impact.
Customer information updates. The AMLR (Art. 26(2)) sets maximum update periods: one year for higher-risk customers, five years for others. Within them, review frequency and depth stay risk-sensitive, with event-driven triggers at the core of your model.
Existing customers. Under Article 28, existing relationships must be brought in line on a risk-sensitive basis within the AMLR periods, counted from the RTS’s entry into force. Start early.
PEP screening (Art. 17). Determine PEP status of the customer, the beneficial owner and, where relevant, the person on whose behalf a transaction is carried out, at onboarding and for existing customers. Re-check without delay when customer data or PEP lists change.
Targeted financial sanctions (Art. 25). Screen customers, beneficial owners and controlling persons, in original and transliterated form, including aliases, trade names and wallet addresses. Re-screen at onboarding and whenever lists or customer data change. Unlike other checks, this is not risk-based.
Screening can be automated, manual or a combination, provided it is effective for your size, risks and complexity. Manual checks are not a lower standard.
Data and lists: integration is no longer optional
Read together, these provisions point in one direction. Without integrated, continuously updated data, it is hard to comply efficiently with:
- PEP determination triggered by changes in customer data or by updates to PEP lists;
- sanctions re-screening on list changes and on customer data changes;
- verification of beneficial owners against registers, data providers and other sources;
- risk-based re-identification and event-driven reviews;
- record retention that supports ex post checks of remote verification.
Even for firms that choose manual checks, connecting sanctions, PEP and adverse-media lists, registers and data providers to the KYC workflow is now close to unavoidable. The RTS turns this into a design requirement for your onboarding architecture.
Source, timeline and next steps
Download the Final Report and the AMLA press release.
- The RTS enters into force on the twentieth day after its publication in the Official Journal.
- It applies six months after entry into force, except for obliged entities under Article 3(3)(n) and (o) AMLR, for which it applies from 10 July 2029.
- The AMLR itself applies from 10 July 2027.
At the time of writing, the text remains subject to the Commission’s review until adoption.
A practical checklist
- Map your onboarding journeys to Article 22(6): which customers can go through eID, EUDI Wallet or qualified trust services?
- Document the fallback logic for alternative remote verification and check each Article 7 safeguard.
- Revisit your data model against Articles 2 to 5 and Annex I.
- Calibrate your risk scoring to drive SDD, EDD, review frequency and event triggers.
- Plan remediation of existing customers within the one-year and five-year limits.
- Review your screening architecture for PEP and sanctions, including aliases, trade names and wallet addresses.
Why Namirial Onboarding is aligned with the new requirements
The CDD RTS rewards platforms that combine flexibility with evidence: multiple verification methods, risk-based orchestration and integrated data. This is how Namirial Onboarding (NOB) maps to the new rulebook.
Qualified trust services at scale. Namirial is the largest qualified trust service provider (QTSP) in Europe. Our onboarding processes are enriched with the qualified electronic signature (QES), and already support millions of transactions with regulated customers. This is the kind of Article 22(6)(b) assurance the RTS places at the top of the verification hierarchy.
EUDI Wallet readiness and interoperability. Namirial is at the forefront on digital identity wallets. Our Wallet Gateway, integrated in NOB, is designed to give customers maximum interoperability across wallets and credential types, so they can accept eID and EUDI Wallet-based identification without rebuilding their onboarding every time the ecosystem evolves. We are already taking part in the sandboxes in France, Germany, Italy and Danemark, which means our approach is being tested against real national implementations. NOB also captures the structured attributes described in Annex I.
Alternative remote verification with safeguards. Where Article 7 applies, NOB supports remote identification with document authenticity checks, liveness and holder-matching controls, secure time-stamped retention and audit trails, which are the elements supervisors will expect to see demonstrated and already audited in alignment with the identity proofing standard ETSI TS 119 461 v2.
Risk-based orchestration. NOB lets institutions configure journeys by risk profile, from reduced SDD data sets to EDD, in line with the proportionality principle of Article 1 and the SDD provisions of Articles 18 to 20.
Integrated screening and data enrichment. NOB connects to PEP, sanctions and other data sources, so list updates and customer data changes can trigger re-screening and review, which is what Articles 17 and 25 now demand.
Auditability. Retained evidence, decision logs and configurable regulatory settings help you demonstrate compliance to supervisors, a recurring theme from Article 7(3) to Article 15(2).
The RTS does not ask for more data for its own sake. It asks for the right data, from the right sources, verified through the right means, with a clear risk rationale. A platform that treats eID, wallets, qualified signatures, remote verification, screening and monitoring as parts of one risk-driven workflow is well placed for that.
Want to discuss how the CDD RTS affects your KYC journeys? Get in touch with the Namirial team.







