What AMLR requires at a glance
End-to-end flow
Your backend creates a session, the user completes the workflow, Didit notifies you, and you retrieve the full decision. The onboarding decision stays with your team. Monitoring continues after onboarding.When due diligence applies
Article 19 says when you must apply customer due diligence: when you establish a business relationship; for an occasional transaction of at least EUR 10,000, in one operation or in linked transactions; when there is a suspicion of money laundering or terrorist financing, whatever the amount; and when you doubt identification data you already hold. Lower triggers apply in some sectors: EUR 1,000 for occasional transfers of funds and for CASPs, EUR 3,000 for occasional cash transactions (at least identification and verification), and EUR 2,000 in gambling. A CASP must at least identify and verify the customer for an occasional transaction below EUR 1,000. Didit does not decide whether a trigger applies. You route by transaction type and amount in your own code, then start the workflow that matches.Identify and verify people
Article 22(1) lists the data you must hold on a natural person: all names and surnames, place and full date of birth, nationalities, the national identification number where applicable, the usual place of residence and, where available, the tax identification number. Article 22(6) then names two means of verifying identity: an identity document, passport or equivalent, or electronic identification (eID) that meets the eIDAS assurance levels “substantial” or “high”, together with relevant qualified trust services.Data points against the decision
The decision returned byGET /v3/session/{sessionId}/decision/ carries one entry per identity check in id_verifications[].
The two routes
What the draft technical standards say about remote verification
The regulatory technical standards (RTS) on customer due diligence under Article 28(1) are written by the Anti-Money Laundering Authority (AMLA). AMLA’s final report is dated 30 September 2026 and was announced on 1 October 2026. It is a final draft submitted to the European Commission. It is not adopted and it is not law. The Commission may still change it, and the draft proposes to apply six months after it enters into force. That draft treats the two means in Article 22(6) as the default. Remote verification with a document is an alternative solution for when the person cannot reasonably be expected to present the document face to face and does not have access to qualifying eID (draft Article 7(1)). If you use the alternative, the draft asks you to be able to justify why, and to show your supervisor that the solution has safeguards (draft Article 7(2) and 7(3)). The draft is technology neutral: it names no technique. How the draft safeguards line up with what a Didit session records:metadata when you create it.
Verify businesses and beneficial owners
For a legal entity, Article 22(1)(b) asks for the legal form and name, the registered office address, the legal representatives and, where available, the registration number, tax identification number and Legal Entity Identifier. You must also identify the beneficial owners and take reasonable measures to verify them, so that you understand the ownership and control structure (Article 20(1)(b)). A beneficial owner is a natural person with direct or indirect ownership of “25 % or more” of the shares, voting rights or other ownership interest (Article 52(1)), or who controls the entity through ownership or other means (Articles 51 and 53). Control is assessed in parallel to ownership.- The threshold is yours to set. The AMLR figure is “25 % or more”, not “more than 25 %”. The UBO threshold on the workflow is configurable, so set it to match and review it if your policy is stricter.
- A register is not enough by itself. Article 22(7) requires you to consult the central registers in addition to verifying the beneficial owners. Reporting a discrepancy to the register within 14 calendar days (Article 24) is your step.
- An empty registry result is not proof that a company has no owners. A register may hold no ownership record for a company or a country. If you identify no beneficial owner, Article 22(2) asks you to record that and to identify and verify the senior managing officials instead.
- Registry monitoring is Coming soon. Continuous monitoring of registry changes is not available yet. Until it is, re-run the Business Verification on your refresh schedule.
Screen for sanctions and PEPs
You must verify whether the customer or its beneficial owners are subject to targeted financial sanctions, and whether sanctioned persons control a legal-entity customer or hold more than 50 % of it (Article 20(1)(d)). In AMLR, targeted financial sanctions means EU sanctions. You must also determine whether the customer or a beneficial owner is a politically exposed person (PEP), a family member or a close associate (Article 20(1)(g)). For PEPs, Article 42 adds senior management approval, measures to establish source of wealth and source of funds, and enhanced ongoing monitoring.Confirmed Match or False Positive fires a data.updated webhook and does not change the session decision by itself. Senior management approval for a PEP relationship is your process: route the session to review and record who approved it.
Monitor on an ongoing basis and refresh
Article 26 requires ongoing monitoring of the business relationship and up-to-date customer information. The period between updates must not exceed 1 year for higher-risk customers and 5 years for all other customers (Article 26(2)), and you must also update when the customer’s circumstances change or you learn a relevant fact (Article 26(3)). Sanctions checks must be repeated regularly, and for credit and financial institutions on any new designation (Article 26(4)).status.updated and data.updated events.
Schedule the 1-year and 5-year refresh in your own system
The refresh clock depends on the risk class you assign, and that decision cannot be outsourced. Didit does not hold your risk class and does not schedule the periodic refresh for you.Store the risk class and the last update date
vendor_data you send to Didit.Run a scheduled job
Create a new session
POST /v3/session/ with the same vendor_data and your refresh workflow, then send the customer the url.React to events as well
"Kyc Expired", a monitoring webhook that moves a session to "In Review", and a change the customer reports as triggers for an earlier update.Purpose and source of funds
Before you enter a business relationship or carry out an occasional transaction, Article 25 asks you to understand its purpose and intended nature. Where necessary, you obtain information on the purpose and economic rationale, the estimated amount of activity, the source of funds, the destination of funds, and the customer’s business activity or occupation. “Where necessary” means the extent is risk-based. Enhanced due diligence can add source of wealth (Article 34(4)).Monitor transactions and report
Ongoing monitoring covers the transactions carried out during the relationship, so that they stay consistent with what you know about the customer (Article 26(1)). When you know, suspect or have reasonable grounds to suspect that funds are the proceeds of criminal activity or related to terrorist financing, you report to your Financial Intelligence Unit (FIU) under Article 69.- You approve the detection criteria. Approving the criteria for detecting suspicious or unusual transactions cannot be outsourced (Article 18(3)(f)). Review each rule you install and record that approval in your own policies.
- You file the report. Didit prepares the report files from the case. It does not submit anything to an FIU. Filing is done by your compliance officer through your FIU’s channel.
Keep records, then delete
Article 77 is your record-keeping duty. You keep the documents and information obtained for customer due diligence, the records of your suspicion assessments and the transaction records for 5 years. The period starts when the business relationship ends, when the occasional transaction is carried out, or when you refuse to enter the relationship (Article 77(3)). When the 5 years expire, you delete the personal data, unless another law applies or an authority asks you to keep specific records longer. The clock starts from an event in your system: the end of the relationship. Didit does not know that date, so the retention you configure and the deletions you request are your decisions.Pick a retention window that cannot end early
Record the end of the relationship
Delete when the period expires
DELETE /v3/session/{sessionId}/delete/ for each session of that customer. Deletion is irreversible and media URLs stop resolving.Human review of automated decisions
Article 76(5) lets you adopt decisions that result from automated processes, including profiling and AI systems, on three conditions. The data is limited to due diligence data. Any decision to enter, refuse or maintain a business relationship, to carry out or refuse an occasional transaction, or to change the extent of due diligence is subject to meaningful human intervention. And the customer can obtain an explanation of the decision and challenge it."Approved" or "Declined" is the result of the checks you configured. It is an input to your decision to onboard, which Article 18(3) keeps with you. Decide with your counsel where a person has to intervene, then build that step into the workflow and into your own back office.
Outsourcing
Article 18 lets you outsource tasks that result from AMLR to a service provider. It sets conditions: you notify your supervisor before the provider starts (Article 18(1)), you remain fully liable for the outsourced tasks (Article 18(2)), and you lay down the conditions in a written agreement and run regular controls on the provider (Article 18(4)). The regulation also says that using third-party software, or accessing databases or screening services, where you perform the requirement yourself, is not outsourcing (recital 47). Which side your use of Didit falls on depends on how you use it. AMLA guidelines on outsourcing are due by 10 July 2027. Six tasks cannot be outsourced under any circumstances (Article 18(3)). They stay with you:- The proposal and approval of your business-wide risk assessment.
- The approval of your internal policies, procedures and controls.
- The decision on the risk profile to attribute to the customer.
- The decision to enter into a business relationship or carry out an occasional transaction.
- Reporting suspicious activity and threshold-based reports to the FIU.
- The approval of the criteria for detecting suspicious or unusual transactions and activities.
Reference workflow
A starting point for an onboarding workflow for natural persons. Adapt it to your risk assessment.Create the workflow
Choose the identity methods per country
Bind the document to the person
Cover the address
Screen and monitor
Ask for purpose and source of funds
Subscribe to webhooks
status.updated and data.updated. See Webhooks.Publish and copy the workflow ID
workflow_id when you create sessions.201 Created):
url. When the session reaches a decision, Didit sends a status.updated webhook. An excerpt:
event_id, and match status as an exact, case-sensitive string. The values are listed in Verification statuses. Then read the full decision with GET /v3/session/{sessionId}/decision/ and hand it to the person or the process that makes your onboarding decision.
Timeline
FAQ
When does AMLR apply?
When does AMLR apply?
What is the difference between AMLR, AMLD6 and AMLA?
What is the difference between AMLR, AMLD6 and AMLA?
Is remote verification with an identity document still allowed?
Is remote verification with an identity document still allowed?
Are the technical standards final?
Are the technical standards final?
Do I have to accept the EUDI Wallet, and does Didit support it?
Do I have to accept the EUDI Wallet, and does Didit support it?
Is the beneficial ownership threshold 25% or 15%?
Is the beneficial ownership threshold 25% or 15%?
How do I implement the 1-year and 5-year refresh?
How do I implement the 1-year and 5-year refresh?
POST /v3/session/ and the same vendor_data. Add event triggers: a "Kyc Expired" status, a monitoring webhook, or a change the customer reports. The 1-year and 5-year figures in Article 26(2) are maximum periods.What can I outsource?
What can I outsource?
How do I set retention for the 5-year rule?
How do I set retention for the 5-year rule?
DELETE /v3/session/{sessionId}/delete/ when your period expires. Export audit logs and screening history if your records policy relies on them.Does using Didit make me compliant with AMLR?
Does using Didit make me compliant with AMLR?