One more year until AMLR: What's important now

July 16, 2026

EU flag

The AMLR will be implemented starting on July 10, 2027.

For banks and other obliged entities, this marks the beginning of a new phase in the European fight against money laundering and terrorist financing. The new EU Anti-Money Laundering Regulation changes the requirements for customer data, the identification of beneficial owners, screening, reviews, and documentation.

The remaining time should therefore not be seen as a purely observational phase. Now it's about examining the initial situation, prioritizing areas for action, and preparing for operational implementation.

At a glance:

Deadline: July 10, 2027
Affected areas: KYC processes, identification of beneficial owners, PEP and sanctions checks, risk models, ongoing monitoring, outsourcing and internal controls
Current focus: Review processes, identify data gaps, prioritize areas for action

The AMLR timetable until July 2027

The following roadmap divides AMLR preparation into five successive phases. It helps companies to analyze their adaptation needs step by step, prioritize measures effectively, and complete operational implementation in a timely manner.

Summer 2026: Understanding the starting point

For many companies, now is the right time to take a structured look at existing KYC processes, data structures and audit logics.

Important questions are:

    • Which processes are affected by the AMLR?
    • Where is structured or up-to-date customer data lacking?
    • Which systems, interfaces, and service providers need to be adapted?
    • What special manual processes exist?

The goal is a reliable gap analysis at the professional, technical and organizational levels.

Autumn 2026: Prioritizing areas of action

After the initial analysis, the next step is to prioritize the relevant areas for action. Not every process needs to be adapted simultaneously.

Particularly relevant are often:

    • the identification of beneficial owners,
    • KYC data and identification processes,
    • PEP and screening processes,
    • Customer risk models,
    • Outsourcing,
    • Group-wide AML standards.

The key is to identify the issues that will require the greatest professional, technical, or organizational adjustments by July 2027.

The supervisory authority also points out that, among other things, the identification of beneficial owners, the PEP definition and outsourcing requirements will change.

End of 2026: Prepare processes and data structures

This phase marks the beginning of concrete implementation. Companies should examine whether existing systems, data fields, and process logics are adequately prepared to efficiently map new requirements.

This can mean, in particular:

    • adapting KYC workflows
    • to introduce additional data fields
    • Updating risk models
    • Redefining control and approval processes
    • to review outsourcing models
    • Prepare existing customer analyses
    • To revise the logic for determining beneficial owners

Collaboration between compliance, operations, IT, data protection and internal audit is particularly important.

By July 2027: Complete operational implementation

The closer the start of the application gets, the more the focus should be on operational resilience.

By then, it should be clear:

    • Which processes were adapted?
    • What data is available?
    • Which existing customers need to be reassessed?
    • Are employees adequately trained?
    • Do the controls and escalation procedures work?
    • Have the systems and interfaces been tested?
    • Can decisions be documented in a comprehensible manner?

Testing and quality assurance should not begin just before the deadline. Particularly complex customer structures, PEP hits, missing data, and increased risk cases should be simulated early on.

From July 10, 2027: Apply AMLR requirements

The new requirements must work in practice from July 10, 2027.

Companies must be able to prove that:

    • Data is complete, up-to-date, and traceable.
    • Decisions are made and documented consistently.
    • Controls function effectively,
    • Deviations are identified and escalated,
    • Employees can confidently handle the requirements.

Conclusion: Start now in a structured manner

The countdown is on. Companies that analyze their initial situation early on can prioritize areas of action and avoid unnecessary time pressure.

The AMLR should not only be viewed as a regulatory obligation. It also offers the opportunity to simplify KYC processes, improve data quality, and make control structures more resilient in the long term.

Further information and an AMLR readiness check can be found on our topic page:

Sophie Karl