EU AMLR 2027: What Businesses Need to Prepare for
July 2027 may sound comfortably far away, but for businesses that need to identify customers, assess risk, and prove they are meeting Anti-Money Laundering (AML) requirements, it isn’t.
On July 10, 2027, a major update to the European Union’s Anti-Money Laundering framework will take effect.
Regulation (EU) 2024/1624, better known as the Anti-Money Laundering Regulation (AMLR), will become directly applicable across the EU. At the same time, EU Member States will generally need to transpose the 6th Anti-Money Laundering Directive (AMLD6) into their national laws.
The goal of AMLD6 is to make anti-money laundering and counter-terrorist financing requirements more consistent across Europe.
For businesses, however, this change isn’t just another regulatory deadline to add to the compliance calendar. The new framework redefines how you:
- verify customers,
- assess their risk,
- can clearly prove what you did and why.
Here’s what’s changing and how Ondato is preparing for it.
1. Digital identity is moving closer to the center of customer verification
One of the clearest changes is the growing role of trusted electronic identification.
Under AMLR, businesses will be able to use electronic identification methods that meet the requirements of the EU’s eIDAS framework at a “substantial” or “high” assurance level, as well as relevant qualified trust services, for identity verification.
At the same time, Europe is rolling out another important piece of its digital identity infrastructure: the European Digital Identity Wallet (EUDI).
The EUDI Wallet is part of a broader shift in how people will prove their identity online.
This means that instead of relying only on traditional identity documents, businesses will be able to verify customers using trusted digital identity tools. And the EUDI Wallet is one of them.
For businesses that onboard customers across Europe, this change matters a lot because they will need to introduce identity verification processes that can work with the digital identity methods regulators recognize (such as eIDAS-compliant electronic IDs and relevant qualified trust services) without creating unnecessary friction for customers.
What Ondato is doing
We’re preparing for this in two parallel ways.
First, Ondato is integrating European Digital Identity Wallets into its identity verification processes.
The web version became available on October 1, 2026, and it will be followed by full integration, including availability through the app, by the end of Q4 2026.
Second, we’re developing a qualified trust service provider route aligned with the relevant eIDAS requirements.
That process is already underway, with the required conformity assessment audit planned for completion by the end of 2026.
Our overall goal is to ensure that when the regulatory framework changes, the identity tools you use with Ondato will already be moving in the same direction.
2. A risk score alone won’t tell the whole story
When it comes to risk-based compliance, under AMLR, the expectation becomes more explicit.
Businesses covered by the AMLR rules must assess the money laundering and terrorist financing risks associated with their customers and apply Customer Due Diligence (CDD) measures that match those risks.
And another important part – you need to be able to show why those CDD measures were appropriate.
Let’s illustrate that with an example. 👉 Imagine a customer is classified as high risk. A regulator may not only want to know what the final classification was, but they may also need to understand:
- Which risk factors were considered?
- What information affected the final risk score?
- Why did those risk factors lead to that result?
- What happened next?
In other words, customer risk assessment becomes less about producing a label and more about creating a clear, traceable decision-making process.
What Ondato is doing
Ondato is strengthening its risk scoring capabilities to help businesses structure customer risk assessments more clearly.
A dedicated risk-scoring solution is being developed to support defined risk factors and preserve evidence of how the resulting risk assessment was derived.
That not only gives you a final risk category but also helps create the audit trail behind it. And that trail is becoming increasingly important.
3. Stronger requirements for compliance evidence
There’s a theme running through many of the upcoming AML changes – evidence.
Businesses already perform identity verification, AML screening, and customer risk assessments. The new framework places greater importance on being able to demonstrate those processes to supervisors.
That means keeping clear records of questions such as:
- What was checked?
- When was it checked?
- What was the result?
- Which information was considered?
- How did you reach the final compliance decision?
This may sound like recordkeeping, but it has a much bigger effect on your day-to-day compliance.
A process that works perfectly but leaves behind an unclear trail becomes difficult to defend later. A process that produces structured, accessible evidence makes audits and supervisory reviews much easier to navigate.
What Ondato is doing
We’re strengthening the evidence available across Ondato’s compliance processes, with a particular focus on making verification and risk assessment results clear, traceable, and suitable for audit purposes.
Our identity verification solution is being enhanced with additional anti-fraud measures, while our existing services continue to provide records showing which checks were performed and their outcomes.
At the same time, our advanced risk scoring capabilities are being built to provide clear evidence of the factors used in an assessment and the resulting risk classification.
The goal is to help our customers give a confident ‘Yes’ answer if someone asks them to explain a compliance decision (months or years later): “Can you reconstruct what happened?”
“We’re not waiting for July 2027 to start adapting. The work is already underway across digital identity, risk assessment, anti-fraud measures, and compliance evidence. Our focus is on translating the new requirements into practical product changes early, so our customers have the tools and time they need to prepare, rather than having to react when the deadline arrives,” commented Ondato’s Chief Information Security & Product Compliance Officer, Dmitrij Olifer.
Why start preparing before July 2027?
The answer is simple – because regulatory deadlines rarely affect just one setting or one workflow. It’s a cascading sequence.
- Changes to identity verification can affect onboarding.
- Changes to risk assessment can affect compliance rules and review processes.
- Stronger evidence requirements can affect what data you retain and how your teams access it.
Waiting until the regulation applies means trying to review all of those moving parts at once.
The better approach is to use the time before July 10, 2027 to understand what will need to change and make those changes gradually.
For Ondato, that work has already started.
Our current roadmap includes:
- By October 1, 2026: EUDI Wallet is available on the web.
- By the end of Q4 2026: full EUDI Wallet integration (including app) is available.
- By the end of 2026: the conformity assessment audit, required as part of our qualified trust service provider route, is completed.
- Ahead of July 10, 2027: continued improvements to identity verification, anti-fraud measures, risk scoring, and the evidence available through Ondato’s compliance processes.
The bigger shift: compliance needs to be explainable
The July 2027 framework brings a lot of detailed requirements. But for businesses, one idea is especially useful to keep in mind – compliance is becoming more demonstrable.
It’s not enough to identify a customer. You need reliable ways to show how the identity was verified.
It’s not enough to place someone in a risk category. You need to show what justified that decision.
It’s not enough to run a compliance process. You need evidence that makes the process understandable later — to your own team, auditors, or supervisors.
That is why Ondato is focusing on its preparations. We’re building toward the new requirements now so that, as the EU moves toward more standardized AML rules and trusted digital identity, our customers can move with it.
July 2027 is the deadline. But the preparations and the groundwork are already underway.
*We’ll continue sharing relevant regulatory developments and Ondato product updates as the new framework gets closer.