Free Demo
  • Linkedin
  • Twitter
  • Youtube

Connect with a Daon solutions expert

Let us know how we can assist you

  • Product/Solution Information
  • Product Demonstration
  • Request for Proposal
  • Partnership Opportunities

See why many of the world’s strongest brands chose Daon to help them build lasting trust with their customers.

EU AML Reform and the Future of Customer Onboarding Across Europe

by Laura Flood 
September 17, 2026

The EU’s new Anti-Money Laundering Regulation creates a single harmonised rulebook replacing fragmented national directives, with full application from July 2027. Customer onboarding will shift from document-and-selfie checks toward eIDAS-compliant digital credentials and trusted identity frameworks, with traditional document verification increasingly treated as a fallback rather than the default.



 

The European Union is implementing its most significant reform of the anti-money laundering (AML) framework in decades. A single AML rulebook, a new EU Anti-Money Laundering Authority (AMLA) and harmonised customer due diligence requirements will change how organisations across the European Economic Area (EEA) approach compliance.

Many of the new rules will not apply fully until July 2027, but the direction is already clear. Identity verification is moving away from fragmented national approaches towards a more consistent, digital-first model based on trusted identity frameworks.

Organisations responsible for AML and Know Your Customer (KYC) compliance should now assess what is changing and how their customer onboarding processes may need to evolve.

The EU Single AML Rulebook

Historically, European AML requirements have been implemented through directives, giving individual Member States considerable flexibility in how they adopted and enforced the rules.

The new Anti-Money Laundering Regulation (AMLR), which entered into force on 9 July 2024, changes this approach. Unlike a directive, the AMLR applies directly across the EU and creates one harmonised set of requirements for organisations subject to AML obligations.

The aim is to reduce national variation, improve regulatory consistency, and simplify compliance for organisations operating across multiple jurisdictions.

For financial institutions and other regulated entities, this should lead to more standardised onboarding, due diligence, and verification processes across Europe.

More Organisations Will Be Affected

The AMLR expands the range of organisations subject to AML obligations.

Alongside banks and other financial institutions, the new framework covers:

  • Crypto-asset service providers (CASPs)
  • Crowdfunding service providers
  • Traders in high-value goods
  • Auditors, accountants and tax advisers
  • Trust and company service providers
  • Estate agents
  • Gambling service providers
  • Professional football clubs and agents (from 2029)

This expanded scope reflects the EU’s response to money laundering risks across a wider range of sectors.

AMLA and Centralised European Supervision

The reform also creates the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA).

Based in Frankfurt and operational since 2025, AMLA is intended to support consistent implementation of AML requirements across Europe. It will also directly supervise selected high-risk financial institutions that operate across borders.

For regulated firms, stronger central oversight should support more consistent interpretation and enforcement of AML requirements, reducing uncertainty caused by different national approaches.

More Prescriptive Customer Due Diligence

The new framework introduces harmonised customer due diligence (CDD) requirements across the EU from July 2027.

Although the detailed Regulatory Technical Standards are still being finalised, organisations should prepare for:

  • More prescriptive onboarding requirements
  • Greater consistency in verification procedures
  • Enhanced evidence collection and retention requirements
  • Better auditability and record keeping

The clear direction is towards greater standardisation and compliance that can be demonstrated through evidence.

Identity Verification and Trusted Digital Credentials

One of the most significant changes for customer onboarding concerns how identity will be verified.

The future EU model gives greater weight to trusted digital identity frameworks and reduces reliance on document-based verification alone.

The emerging requirements point towards:

  • Stronger identity assurance requirements
  • Improved audit trails
  • Enhanced fraud resistance
  • Greater use of technology in verification processes
  • Alignment with the broader eIDAS digital identity framework

Organisations will need to move toward trusted electronic identity mechanisms while moving away from manual reviews or document-and-selfie checks.

eIDAS and the European Digital Identity Wallet

For remote onboarding, eIDAS-compliant electronic identification is emerging as the preferred approach.

Two main verification routes are expected to play a central role.

1. High-Assurance Electronic Identification (eID)

Verification may be performed using:

  • Existing national electronic identity schemes
  • European Digital Identity (EUDI) Wallet credentials
  • Other eIDAS-compliant electronic identification methods that provide substantial or high assurance

These methods provide a standardised and trusted approach to customer identification across Europe.

2. Qualified Trust Services

Organisations may also use Qualified Trust Services (QTS), including:

  • Qualified Electronic Signatures (QES)
  • Other qualified trust services recognised under eIDAS

These services provide a high degree of legal certainty and regulatory confidence and can support higher-assurance digital onboarding.

Document-Based Verification as a Fallback

Traditional identity verification methods, such as checking a passport or driver’s licence alongside a selfie, are not disappearing. Their role is, however, changing.

Under the emerging framework, document-based verification is increasingly treated as a secondary option where:

  • No suitable eID solution is available
  • No Qualified Trust Service is available
  • It would be unreasonable to expect the customer to use a digital identity credential

When using document-based processes, organisations may need to explain why they were necessary and show how they achieved an appropriate level of assurance.

This changes the basis on which identity is established.

The emphasis is moving from:

“I saw a passport and a selfie.”

to

“I verified the individual’s identity through trusted credentials and corroborated information from reliable sources.”

The Role of Independent Data Sources

Where document-based verification remains necessary, organisations are expected to strengthen their controls by supplementing documents with:

  • Reliable independent data sources
  • Authoritative databases
  • Trusted registries and external records

Verification therefore becomes less dependent on a single credential and more reliant on corroborating identity information through trusted sources and frameworks.

Customer Refresh and Remediation Programmes

The reforms apply to more than the onboarding of new customers.

Many organisations may need to review existing customer records against future regulatory standards. This could lead to large-scale remediation and customer refresh programmes, particularly for higher-risk customers or those onboarded through legacy processes.

Firms should begin assessing:

  • Existing customer record quality
  • Gaps in verification evidence
  • The scalability of re-verification processes
  • Their ability to accept digital identity credentials in future

Preparing for July 2027

The new EU AML framework moves customer identification and verification away from fragmented national practices and towards a harmonised European approach.

From July 2027, organisations subject to AML obligations will operate under a framework that gives greater weight to trusted digital credentials, harmonised verification standards, auditability, and stronger identity assurance.

Regulated organisations will need to adapt their onboarding journeys, prepare for identity ecosystems such as the EUDI Wallet, use trusted identity services, and balance compliance requirements with the customer experience.

The transition is already underway. Organisations that assess their systems and processes now will be better prepared to deliver secure, compliant and low-friction customer onboarding under the new European AML framework.