
The company-wide risk assessment under the AML Regulation
The AML Regulation restructures the requirements for risk assessment. This article explains the obligations that will apply in the future.

The AML Regulation (AMLR) redefines the AML compliance requirements for obliged entities. In our series, we present the new updates and discuss the implications for obliged entities.
Changes Introduced by the AMLR
The AMLR comprehensively reorganises "customer due diligence" (formerly: customer due diligence obligations). In the AMLR, Articles 19 et seq. AMLR regulate the principles of due diligence. Due to the nature of the legal act (regulation), the specifications apply directly to obliged entities, without the need for transposition into German law.
As has been the case to date, the AMLR also distinguishes between three tiers of due diligence obligations:
Regular due diligence measures (Art. 20 AMLR)
Simplified due diligence measures (Section 3/ Art. 33 AMLR) and
Enhanced due diligence measures (Section 4/ Art. 34 AMLR)
Obliged entities determine which due diligence measures apply in each case based on an individual customer risk assessment (Art. 20 (2) sub-para. 1 AMLR). The specifications of the risk factors per customer or occasional transaction, which must be included when determining the respective risk, are defined by the AMLA in guidelines, which will be published by 10 July 2026 (Art. 20 (3) AMLR).
The RTS on CDD
Despite the already much more granular specifications of the AMLR, the provisions are specified in detail by delegated acts (Level 2 measures). To this end, the AMLR provides that the Commission adopts technical standards (Regulatory Technical Standards - RTS and Implementing Technical Standards - ITS). Relevant for CDD are the RTS on Customer Due Diligence under Article 28(1) of Regulation (EU) 2024/1624 (RTS CDD). The RTS CDD specify the requirements of Articles 20-27 AMLR.
The draft RTS were developed by the EBA and are transmitted by the AMLA to the Commission. Compared to the current legal situation, the following points stand out:
Identity Details
The identity details to be collected are much more comprehensive than under the current legal situation. For example, the following must also be recorded:
all nationalities (although no proof of this information is required),
trading names (if different from the registered company),
the tax identification number.
Procedures for Distance Verification of Identity
Substantial changes arise compared to the procedures currently permitted under Section 13 GwG in conjunction with the BaFin interpretation and application notes and circulars. Thus, the RTS initially only recognise eIDAS-compliant procedures as permissible procedures (Art. 7 of the RTS CDD).
💡
eIDAS-compliant procedures include, for example:
- the German national identity card with enabled online function as an eID
- Qualified electronic signatures,
- the European Digital Identity (EUDI) Wallet
The video identification process, which is particularly widespread in Germany, is not one of the eIDAS-certified procedures. The procedure is therefore unlikely to be permitted for verifying identity details from the date on which the AMLR applies to obliged entities (July 2027). During the consultation phase, however, obliged entities lobbied for a transition phase in order to be able to identify via video identification at least on a temporary basis even after July 2027, until eIDAS-compliant procedures are implemented.
Procedures for Verifying Beneficial Owner Information
Art. 10 RTS CDD defines the permissible means for verifying beneficial owner information. In contrast to the previous German legal situation, electricity or gas bills as well as information from commercial database providers are, for example, also permissible procedures.
Determining PEP Status
Regarding the identification of whether the customer or a beneficial owner is a politically exposed person (PEP), the RTS CDD clarify that the determination of PEP status does not apply to the entire business relationship, but must be reviewed regularly. In the EBA's view, occasions for such a review include, for example, the holding of elections. In addition, the information must be reviewed periodically.
Enhanced Due Diligence Obligations
Section 6 (Art. 25 et seq. RTS CDD) specifies the additional information that obliged entities must collect in the event of higher risk. For the first time, the RTS CSS also mention info on the customer's reputation, which means that Adverse Media Screening is likely to count as a standard procedure, at least in the case of high risk. Information to be collected additionally may also include information on customer and contractual relationships of particular relevance to the customer (Art. 26 (1) RTS CDD).
Sanctions Status
For the first time, the AMLR includes the obligation to screen customers and occasional transactions for violations of EU targeted restrictive measures. Articles 29-30 RTS CDD determine,
which persons are to be screened for potential sanction links, and
which procedures are approved for screening.
Automated screening by comparison against sanction lists is the standard from which obliged entities can only deviate in exceptional cases if automated screening is disproportionate.
Art. 30 RTS CDD also defines when the screening must be repeated (see Art. 30 (c) RTS CDD).
Handling of Legacy Data
A point that is relevant for obliged entities and was addressed correspondingly often during the consultation concerns the handling of legacy data. The EBA had already announced that it would include a grandfathering rule. The AMLA has followed suit. Accordingly, the RTS CDD provide for a compromise regulation in Art. 33:
In cases where the customer has entered into a business relationship before the publication date of this Regulation, the documents, data and information relating to those customers shall be brought in line with the requirements of this Regulation and of Regulation (EU) 2024/1624 on a risk-sensitive basis, but in all cases not later than within the periods set out in Article 26(2) of Regulation (EU) 2024/1624.
As a result, customer data must then be updated based on the risk profile and as part of the periodic update (high-risk customers: within one year, for all other customers: after a maximum of five years).
Outlook
The consultation phase expired on 8 May 2026. The AMLA is now reviewing the statements and will adjust the drafts if necessary before transmitting the final draft RTS to the Commission. The Commission will then adopt the RTS as a delegated regulation. By 10 July 2027 at the latest (when the AMLR applies to obliged entities), customer data must then be collected in accordance with the new standard.
