AMLR 2027

Guidance for your KYC process

or

Day (s)

:

St (n)

:

Minute (s)

:

second(s)

until the application of AMLR.

The Anti-Money Laundering Regulation (AMLR) comes into effect on July 10, 2027. This new EU regulation changes the requirements for customer data, identifying beneficial owners, screening, reviews, and documentation. This page provides key information, resources, and practical guidance to help you prepare for AMLR compliance.

The AMLR Roadmap

What specific preparations must companies have in place before applying the AMLR?

Summer 2026: Understanding the starting point

The AMLR is approaching. For many companies, now is the right time to take a structured look at existing KYC processes, data models, and audit logics.

Autumn 2026: Prioritizing areas of action

Following the initial analysis, the next step is to prioritize the relevant areas for action. Not every process needs to be adapted simultaneously. The crucial point now is to identify the topics that require the greatest professional, technical, or organizational adjustments by July 2027.

End of 2026: Prepare processes and data models

This phase focuses on concrete implementation. Companies should check whether existing systems, data fields, and process logics are sufficiently prepared to efficiently map new requirements.

By July 10, 2026: Complete operational implementation

As the implementation date approaches, the focus should increasingly shift to operational resilience. By this point, it should be clear which processes have been adapted, what data is available, and how operational teams are working with the new requirements.

From 10/07/2026: Apply AMLR requirements

From July 10, 2027, the AMLR will be applied as a matter of principle. From then on, processes must not only be described theoretically, but also be operationally viable.

What AMLR question are you currently working on?

The AMLR introduces new requirements for KYC processes, data models, economic ownership, screening, reviews, and existing customers. Find out which topics are now crucial for your organization and how to prepare for their targeted implementation.

What does AMLR specifically mean for our KYC processes?

Recommended white paper: Becoming AMLR-ready

This white paper provides an overview of key AMLR impacts on KYC processes, data requirements, screening, reviews and documentation.

What data, reviews, and testing logics do we need to examine now?

Recommended white paper: Becoming AMLR-ready

This white paper provides an overview of key AMLR impacts on KYC processes, data requirements, screening, reviews and documentation.

How do we create internal clarity regarding the need for action regarding AMLR?

Recommended white paper: Becoming AMLR-ready

This white paper provides an overview of key AMLR impacts on KYC processes, data requirements, screening, reviews and documentation.

How can beneficial owners be specifically identified and verifiably documented according to the AMLR?

Recommended white paper: Determining beneficial owners according to AMLR

A deep dive into the methodology for determining beneficial ownership, ownership, control, accumulation, and verifiable documentation.

What changes when determining the beneficial owner?

Recommended white paper: Determining beneficial owners according to AMLR

A deep dive into the methodology for determining beneficial ownership, ownership, control, accumulation, and verifiable documentation.

How do the ownership case and control case change when determining the beneficial owner under AMLR?

Recommended white paper: Determining beneficial owners according to AMLR

A deep dive into the methodology for determining beneficial ownership, ownership, control, accumulation, and verifiable documentation.

AMLR in 90 seconds: The most important topics at a glance

In short video chapters, Justus Schrecker, Managing Director and COO of KYCnow, and Anna Krüger, Compliance Officer of KYCnow, explain key AMLR topics. The focus is on data requirements, beneficial ownership, coexistence, and the migration of existing customer data.

Would you like to delve deeper?

In the full webinar, Justus Schrecker and Anna Krüger explain the most important AMLR requirements in detail and show what impact this can have on KYC processes, data models and beneficial owners.

How KYCnow is preparing for AMLR

With the AMLR, the requirements for KYC processes, data quality, and traceability are increasing. Shorter audit cycles, expanded data requirements, and new focuses on beneficial owners are increasing the operational burden for many obligated entities.

KYCnow is specifically preparing for these requirements. The focus is particularly on expanding relevant data models, further developing the determination of beneficial owners, and increasing the automation of KYC processes.

As individual requirements are still being further specified and legally assessed, we continuously monitor regulatory developments and incorporate new findings into our product and process development.

AMLR stamp

Extended data requirements for natural persons

KYCnow expands the available data on natural persons.

The database is continuously being built up so that AMLR-relevant information can be used in a structured way in KYC processes.

Extended data requirements for legal entities

KYCnow expands the available data on the legal entity.

The goal is to provide the information in a complete, structured, and more user-friendly way in the future. The database will be built up gradually.

New requirements for beneficial owners

KYCnow is developing a new method for identifying beneficial owners under AMLR.

The new logic should be tested early on so that customers have enough time for implementation and inventory verification.

More automation to address increasing testing costs

KYCnow is being further developed to automate increasing testing and update efforts to a greater extent.

The focus is on more efficient data updates, structured testing logics, and better scalability of KYC processes.

Preparing customers for the new AMLR logic

KYCnow helps customers prepare for the new AMLR requirements at an early stage.

This allows for a better assessment of potential impacts on existing customer bases and for timely planning of necessary adjustments.

Always keep an eye on regulatory changes

KYCnow continuously monitors and evaluates legal and data protection-related specifications.

New findings are gradually incorporated into product development, data model and technical implementation.

AMLR in exchange

AMLR preparation raises many specific questions in practice. We want to create space for precisely these questions: for expert analysis, current developments, and the exchange of information on operational implementation topics.

With our AMLR Question of the Month, we regularly address specific practical questions. You can submit your own questions about AMLR, determining beneficial ownership, data requirements, or implementation in KYC processes.

From the submitted questions, we regularly select a topic and prepare it anonymously for this page, our FAQs, webinars or other exchange formats.

Additionally, you will find information here on upcoming events, webinars, recordings and formats in which KYCnow addresses AMLR-relevant topics.

AMLR Question of the Month

AMLR Question of the Month

June 2026: What does coexistence mean in terms of ownership and control?

"Coexistence" describes cases in which ownership and control interact within a shareholding structure. This becomes particularly relevant when a natural person can exert influence over a legal entity not only through shareholding percentages but also through control relationships within the shareholding chain.

For KYC processes, this means that ownership and control structures must not only be examined individually, but also linked together in a traceable manner within more complex chains of ownership. The crucial question is whether and how shareholdings, control rights, and intermediate companies affect the determination of the beneficial owner.

May 2026: What are event-driven audits?

Event-driven reviews are audits triggered by specific events. They can be initiated, for example, when beneficial ownership, shareholding structures, business activities, transaction patterns, or risk factors change. For companies, this means that KYC processes should not only cover periodic audits but also identify relevant events and address them in a traceable manner.

What question are you currently grappling with in your AMLR preparation?

Submit your question here. We regularly review incoming topics and select one AMLR Question of the Month. We address selected questions anonymously on this page or in other formats.

* Required

ClariLab GmbH & Co. KG will use the information you provide in this form to stay in touch with you and to send you updates and marketing information. You can unsubscribe at any time by clicking the link in the footer of our emails. Further information on data protection can be found in our privacy policy.

Events

September 03, 2026, 18:00 p.m. | Frankfurt am Main

KYCnow and friends

Own event

September 15–17, 2026 | Potsdam

24th Annual Conference: Combating Money Laundering

External event

October 29, 2026 | Magdeburg

SCHUFA Industry Meeting: Receivables Management & Debt Collection

External event

November 10, 2026 | Berlin

DigiFin

External event

Understanding AMLR: The most important questions and answers

Which AMLR articles are particularly relevant for KYC processes?

Articles 19 to 46 of the AMLR are particularly relevant for the practical implementation of KYC processes. These include general customer due diligence obligations (Articles 19 et seq.), the identification and verification of customers and beneficial owners (Articles 22 et seq.), the requirements for determining the beneficial owner, including ownership and control structures (Articles 51 et seq.), the ongoing monitoring of business relationships (Article 26), the updating of customer data, and the requirements for simplified and enhanced due diligence (Articles 34 et seq.). For many institutions, this has concrete implications for data models, KYC questionnaires, the identification of beneficial owners, review processes, and the documentation of decisions.

What changes are there regarding customer due diligence obligations?

The AMLR (Additional Productivity and Registration Regulation) specifies the requirements for Customer Due Diligence (CDD) much more precisely than previous regulations. Obligated entities must identify and verify customers, obtain information about the purpose and nature of the business relationship, determine and verify beneficial owners, assess risk factors, and continuously monitor the business relationship. Furthermore, the requirements for documentation, the timeliness of customer data, the traceability of decisions, and the consideration of ownership and control structures are described more precisely. For companies, this may mean that additional data fields are needed, existing KYC (Know Your Customer) and screening processes must be adapted, and review and monitoring processes must be redesigned.

What data can be relevant for legal entities?

For legal entities, additional information may be relevant, including details such as name, legal form, registered office, economic activity, country of incorporation, tax residence, identification numbers, governing bodies, and ownership structure. This also includes information on shareholders, intermediate companies, beneficial owners, and complex ownership structures.

What changes when determining the beneficial owner?

Under the AMLR, the 25% threshold is an important starting point for identifying beneficial owners. A further new aspect is the requirement to examine more closely which direct and indirect shareholdings, voting rights, or other ownership interests can be attributed to a natural person.Furthermore, a mere shareholding is not sufficient. Control, special control rights, and the interplay of ownership and control can also lead to a natural person being classified as the beneficial owner.

This increases the demands on data quality, audit logic and documentation for KYC processes, especially in the case of complex shareholding and group structures.

What does AMLR mean for existing customers?

The AMLR (Additional Management and Monitoring Regulation) affects not only new customers but also existing business relationships. Obligated companies must review whether the information they hold for existing customers complies with the new regulatory requirements. This may require, in particular, additional information on ownership and control structures, a re-identification of the beneficial owner, adjusted risk assessments, and updated screening and monitoring processes. Furthermore, existing customer files should be reviewed and, if necessary, supplemented as part of regular reviews. Particularly high-risk business relationships should be prioritized when preparing and updating customer data.

Glossary

Click on a letter to display the matching terms.

A

Adverse Media

Negative media reports or public information that can be taken into account as part of the risk assessment and screening process.

accumulation

Aggregation of relevant shareholdings across multiple chains of ownership. This can be relevant when determining the beneficial owner.

AMLA

European Anti-Money Laundering and Counter-Terrorist Financing Agency. Its purpose is to support the more uniform application of European AML regulations.

AMLAR

Anti-Money Laundering Authority Regulation. Regulation establishing AMLA as the European authority for combating money laundering.

AMLD

Anti-Money Laundering Directive. The AMLD is the EU's anti-money laundering directive and part of the European AML package. Unlike the AMLR, it must be transposed into national law by the member states.

AML package

European legislative package to strengthen and harmonize money laundering prevention. It includes, among other things, AMLR, AMLD and AMLAR.

AMLR

Anti-Money Laundering Regulation. The AMLR is the new EU anti-money laundering regulation and applies directly in all EU member states. It will generally be applied from July 10, 2027.

B

Existing customers

Existing business relationships, whose data, risk classifications, audit logics and review processes must be considered as part of AMLR preparation.

Existing customer migration

Structured transfer of existing customer data, risk classifications and audit logics to new AMLR requirements.

shareholding structure

Presentation of direct and indirect interests in a legal entity. It is central for examining ownership, control, and beneficial ownership.

C

temporary contracts

Customer Due Diligence. Customer due diligence obligations for identifying, reviewing, risk assessment and ongoing monitoring of customer relationships.

Control

The ability to exert significant influence over a legal entity, for example through voting rights, control rights, agreements or other means of influence.

Customer Risk Assessment

Assessment of the risk of a customer relationship. It influences the scope, depth, and frequency of the due diligence obligations to be applied.

D

Data requirements

Requirements for the structured collection, timeliness and traceability of relevant customer, company and owner data.

Data model

A structure in which KYC-relevant information is captured, stored, and processed. AMLR may require adjustments to existing data models.

Data quality

Completeness, timeliness, structurability and reliability of data used for KYC checks.

Documentation

Traceable recording of audit results, data sources, decisions and justifications in the KYC process.

E

Ownership participation

Direct or indirect participation in a legal entity. This can be relevant for determining the beneficial owner.

Determining the beneficial owner

Examination to determine which natural person can exert significant influence over a legal entity through ownership, control, or a combination of both.

Event-driven Review

Event-driven review of a business relationship, for example in the event of changes in ownership structure, risk profile, transaction patterns or relevant customer data.

F

false Positive

A screening hit that, upon review, is not confirmed as an actual risk hit.

Fatf

International organization that develops standards to combat money laundering and terrorist financing.

financial crime

A general term for financial crime, including money laundering, terrorist financing, fraud, and sanctions violations.

G

Money laundering prevention

Measures to prevent, detect and report money laundering and terrorist financing.

business relationship

Long-term customer relationships where customer due diligence obligations, ongoing monitoring and update obligations become relevant.

GwG

German Money Laundering Act. It contains national regulations for money laundering prevention.

H

High-risk customer

A high-risk client where enhanced due diligence and shorter review cycles may be relevant.

High-risk country

Country with an increased risk in the context of money laundering, terrorist financing or inadequate AML/CFT controls.

I

identification

Identification of relevant information about customers, beneficial owners, legal representatives or acting persons.

identity check

Verification of the collected identity data using appropriate documents, procedures or trusted sources.

Indirect participation

A stake that is not held directly, but through one or more intermediate companies.

Intermediate Beneficiary Owner

Intermediate company or relevant unit within a chain of ownership that can be considered in the context of structural reviews and sanctions screening.

J

legal entity

A legally independent organization, for example a GmbH (limited liability company), AG (stock corporation), or comparable legal form. For legal entities, structured company, representation, and ownership data become relevant under the AMLR (Agency for Commercial Register and Organizational Data).

K

Coexistence of control and ownership participation

The parallel existence of different audit methodologies. In the AMLR context, this means that ownership, control, and combination cases must be considered together.

Control structure

A description of which persons or entities can exercise control over a legal person.

Customer due diligence obligations

Obligations to identify, examine, assess risks, continuously monitor and document customer relationships.

KYC

Know Your Customer (KYC). Process for identifying, vetting, risk-assessing, and continuously monitoring customers.

KYC process

The entire process from customer registration through identification, data verification, screening and risk assessment to reviews and ongoing monitoring.

L

Ongoing monitoring

Continuous monitoring of a business relationship, including transactions, customer data, risk profile and relevant events.

List screening

Matching customers, beneficial owners or other relevant persons against risk, PEP or sanctions lists.

M

Migration

Transfer of existing data, processes, or test logics into a new target model.

Monitoring

Ongoing monitoring of customer relationships, risk factors, transactions, or relevant changes.

N

traceability

Ability to transparently document and later review KYC decisions, data sources, audit steps and results.

Name Screening

Checking names against relevant lists, for example sanctions lists, PEP lists or other risk lists.

Natural person

A human being as a legal entity, for example a customer, legal representative, senior managing official or beneficial owner.

O

Onboarding

Onboarding a new customer into a business relationship, including identification, due diligence, risk assessment, screening, and documentation.

Outreach

Contacting customers to obtain, update, or clarify relevant information and documents.

Ownership

Ownership relationship in a legal entity, which can exist directly or indirectly.

P

PEP

Politically exposed person. Individuals with prominent public functions, as well as certain close associates, may trigger increased due diligence obligations.

PEP screening

Assessment of whether a customer, beneficial owner or relevant person should be classified as a politically exposed person.

Test logic

Technical rule according to which KYC-relevant data, structures or risks are assessed.

Q

Quality Control

Checking whether KYC data, decisions and documentation are complete, consistent and traceable.

qTSP

Qualified Trust Service Provider. A qualified trust service provider that can be relevant in digital identification and verification processes.

R

Regular Review

Periodic review of existing customer relationships and customer data.

Review cycle

Period after which a customer relationship or KYC record is re-verified.

Risk-based approach

The principle that the scope and depth of KYC measures are aligned with the risk of the respective business relationship.

Risk classification

Classification of a customer relationship according to risk factors relevant for due diligence, reviews and monitoring.

RTS

Regulatory Technical Standards. Technical standards that further specify individual requirements of the AMLR.

S

Sanction screening

Screening of customers, beneficial owners and relevant structures against sanctions lists.

Screening

Matching individuals, companies or structures against relevant risk and sanction sources.

Senior Managing Official

A manager who may become relevant if no beneficial owner can be identified or if doubts remain.

Due diligence obligations

Regulatory obligations for the identification, auditing, risk assessment, monitoring and documentation of customer relationships.

T

transparency register

Register for recording beneficial owners of companies and certain legal arrangements.

Hit processing

Examination and evaluation of a screening hit to determine whether an actual risk hit exists.

U

Discrepancy report

Report if the determined information differs from registry information or other relevant data sources.

Company data

Structured information on legal entities, for example name, legal form, registered office, identification numbers, representative bodies and ownership structure.

Corporate structure

Presentation of shareholdings, intermediate companies, control relationships and relevant units within a corporate group.

V

suspicious transaction report

Report to the relevant authority if there is suspicion of money laundering or terrorist financing.

Obligated

Companies or individuals who must comply with anti-money laundering obligations.

Enhanced due diligence obligations

Extended testing and monitoring measures in cases of increased risk, for example with high-risk customers or certain risk constellations.

Completeness check

Analysis to determine whether relevant KYC data is complete or whether further clarification or processing is required.

W

Watchlist

List of individuals, companies, or organizations that are screened as part of screening processes.

Beneficial owner

Natural person who ultimately owns or controls a legal entity.

Economic ownership

Ownership or control through which a natural person can exert significant influence over a legal person.

Z

Purpose and nature of the business relationship

Information about why a business relationship is being established and how it is expected to be used.

Intermediate company

Company within a chain of ownership through which indirect ownership or control relationships may exist.

No terms stored.

There are currently no glossary terms associated with this letter.

join Appointments
and get to know KYCnow

Prepare your KYC processes for AMLR. We'll show you how KYCnow can support you with data, verification processes, and operational implementation.