Are you ready for July 2027? A 32-question SCA & AMLR readiness checklist
Last updated: July 2026
Two EU regulations will reshape identity verification within 6 months of each other. The Anti-Money Laundering Regulation (AMLR, Regulation (EU) 2024/1624) applies directly across all Member States from July 10, 2027. The obligation for private relying parties to accept the EUDI Wallet under eIDAS 2.0 (Regulation (EU) 2024/1183) follows on December 24, 2027.
Most companies treat them as 2 separate compliance projects.
That is a mistake - and an expensive one.
The SCA & AMLR Readiness Checklist is a free 32-question self-assessment that tests whether an organisation is ready for both deadlines: AMLR customer due diligence from July 10, 2027, and mandatory EUDI Wallet acceptance under eIDAS 2.0 from December 24, 2027. It covers 7 sections - from scope and timelines to SCA architecture, wallet acceptance, CDD and audit trail - with a scoring guide that turns the answers into next steps.

What is the SCA & AMLR Readiness Checklist?
The checklist turns both regimes into one practical self-assessment. Each question offers 3 answers - Yes, In progress, No - and the scoring section turns the result into next steps. It is written for compliance officers and product owners; no legal background required.
Key takeaways
- AMLR applies from July 10, 2027 - directly, with no national transposition.
- Private relying parties in mandated sectors must accept the EUDI Wallet wherever SCA is legally required from December 24, 2027.
- By December 24, 2026, every Member State must provide at least one EUDI Wallet. Adoption has already started: Denmark's AltID is live.
- SCA will be governed mainly by the Payment Services Regulation (PSR) combined with eIDAS 2.0, not by PSD2.
- Both regimes converge on the same capability: accepting many identity methods, at defined assurance levels, with evidence. That is one infrastructure project, not two.
AMLR vs eIDAS 2.0: why one checklist covers both regulations
Because the deadlines land in the same year and the requirements land on the same systems.
AMLR | eIDAS 2.0 | |
|---|---|---|
Full name | Regulation (EU) 2024/1624 - the EU's single AML rulebook | Regulation (EU) 2024/1183 - the European Digital Identity framework |
What it governs | Customer due diligence (CDD), AML/CFT obligations | Digital identity, EUDI Wallet, trust services |
Key date | July 10, 2027 - applies directly, no national transposition | December 24, 2027 - wallet acceptance obligation (formal wallet availability deadline: December 24, 2026) |
Who it applies to | Obliged entities - including newly in-scope crypto-asset service providers, crowdfunding platforms and traders in high-value goods | Private relying parties in the Art. 5f sectoral catalog: banking, financial services, telecom, insurance, healthcare, education, energy, transport and others |
Core identity obligation | Verify name, date of birth, nationality and address against reliable, independent sources (Article 22) | Accept the EUDI Wallet wherever Strong Customer Authentication is legally required |
SCA framework | n/a | PSR combined with eIDAS 2.0, replacing PSD2 (transition expected by 2028) |
Supervision | AMLA - operational since July 2025, direct supervision of selected institutions from 2028 | National supervisory bodies and relying party registers per Member State |
AMLR Article 22 defines what customer due diligence must verify - name, date of birth, nationality, address - and requires verification against reliable, independent sources. Article 22(6) explicitly recognises digital pathways: eID schemes under eIDAS at substantial or high assurance, the EUDI Wallet, and qualified trust services (QES, QEAA).
eIDAS 2.0, in turn, obliges relying parties in the Art. 5f sectoral catalog - banking, financial services, telecom, insurance, healthcare, education, energy, transport and others - to accept the EUDI Wallet wherever SCA is required.
Read those two together and the conclusion is hard to avoid: the infrastructure you build for wallet acceptance is the same infrastructure that satisfies AMLR's verification pathways. Companies that run these as parallel projects will pay for the same plumbing twice.
What has changed since our March 2026 analysis?
In our March 2026 analysis, How eIDAS 2.0 affects private relying parties and SCA, we made one point that has aged well: readiness will ultimately depend on technical implementation, not policy declarations.
4 months later, the implementation picture is sharper:
- The AMLA consultation on the Customer Due Diligence Regulatory Technical Standards closed on May 8, 2026. The final draft is due to the European Commission by July 10, 2026 - exactly one year before AMLR applies.
- Denmark shipped AltID, one of Europe's first live EUDI Wallets, ahead of the legal deadline.
- More Member States will follow before December 2026 - our analysis of how European markets are scaling in 2026 shows the trajectory, and Italy's eID paradox shows where bottlenecks remain. Every wallet launched now is a wallet your users may present to you 12 months later.
The window between "the rules are final" and "the rules apply" is closing to roughly a year. That is the window the checklist is built for.
How should organisations prepare for Strong Customer Authentication under eIDAS 2.0?
Preparation starts from the assumption that PSD2 will not be the framework you comply with. By 2027, SCA will be governed mainly by the Payment Services Regulation combined with eIDAS 2.0, which adds a new acceptance channel: wallet-based authentication with mandatory dynamic linking wherever SCA is legally required.
In practice that means three workstreams: confirming whether your sector falls under the Art. 5f catalog, testing whether your SCA flows can consume a wallet credential in remote scenarios, and verifying that authentication events leave the evidence trail AMLR supervisors will ask for. Section 3 of the checklist covers all three.
What does the SCA & AMLR Readiness Checklist cover?
The checklist has 32 questions across 7 sections. Each question offers three answers - Yes, In progress, No - and the scoring section turns the result into next steps. Each question in the PDF also carries a short "why this matters" note explaining the regulatory stake behind it.
Section 1 | Scope: do these rules apply to you at all?
Covers the Art. 5f sectoral catalog, private relying party status, registration duties, and AMLR's widened obliged-entity list - including newly in-scope categories such as crypto-asset service providers, crowdfunding platforms and traders in high-value goods.
# | Question |
|---|---|
1.1 | Taking into account relevant sectoral regulations, have you determined whether your organisation falls within the Art. 5f sectoral catalog of eIDAS 2.0 (banking, financial services, telecom, insurance, healthcare, education, energy, transport, and others)? |
1.2 | Have you assessed whether your organisation qualifies as a "private relying party" - a natural or legal person relying on electronic identification or trust services? |
1.3 | Do you know in which Member State(s) you must register as a relying party, and have you defined the purpose and data scope for that registration? |
1.4 | Have you confirmed whether your organisation is an "obliged entity" under AMLR - including newly in-scope categories such as crypto-asset service providers, crowdfunding platforms and traders in high-value goods? |
1.5 | If you operate in multiple EU markets, have you mapped which national requirements survive alongside the harmonised rulebook? |
Section 2 | Timeline: where are you against the deadlines?
Whether your roadmap accounts for the 3 hard dates: December 24, 2026 (wallet availability), July 10, 2027 (AMLR), December 24, 2027 (wallet acceptance) - and whether budget and engineering capacity are allocated for 2026, not 2027.
# | Question |
|---|---|
2.1 | Does your compliance roadmap account for December 24, 2026 - the date each Member State must provide at least one EUDI Wallet? |
2.2 | Does it account for December 24, 2027 - the date private relying parties in mandated sectors must accept the EUDI Wallet where SCA is required? |
2.3 | Does it account for July 10, 2027 - the date AMLR applies directly across all Member States? |
2.4 | Are you tracking wallets and eID schemes launching ahead of the deadlines? |
2.5 | Have you allocated budget and engineering capacity for identity infrastructure changes in 2026, not 2027? |
Section 3 | SCA architecture readiness (PSR + eIDAS 2.0)
PSR replaces PSD2 as the main SCA framework. The questions test wallet-based SCA in remote flows, mandatory dynamic linking, secure credential storage, and cross-application authentication on mobile.
# | Question |
|---|---|
3.1 | Have you mapped which of your authentication flows will fall under PSR instead of PSD2? |
3.2 | Can your architecture support wallet-based SCA in remote scenarios, such as account access and electronic payment initiation? |
3.3 | Does your SCA design support mandatory dynamic linking under PSR? |
3.4 | Can you meet PSR requirements for secure credential storage? |
3.5 | Can you support cross-application authentication flows in mobile environments - from wallet app to your app and back? |
3.6 | Have you confirmed which flows are out of scope, such as in-person point-of-sale and ATM transactions? |
3.7 | Will users be able to choose between the wallet and your existing SCA methods, with the wallet option available wherever SCA is legally required? |
Section 4 | Wallet acceptance readiness
A minimum of 27 national wallets, issued by governments and accredited private entities, all of which you must be able to verify, authenticate against, and request data from - with selective disclosure and data minimisation built in. 1 integration is a pilot; 27+ is an orchestration problem. For a deeper wallet-specific assessment, see the EUDI Wallet Readiness Checklist by Authologic.
# | Question |
|---|---|
4.1 | Do you have a strategy for acceptance and interoperability testing of a minimum of 27 national EUDI Wallets? |
4.2 | Can your systems verify the authenticity and validity of a presented wallet using the common protocols and interfaces? |
4.3 | Can you authenticate yourself to the wallet as a registered relying party? |
4.4 | Are your data requests limited to what is necessary and proportionate, including support for selective disclosure? |
4.5 | Do you have a plan for wallet acceptance beyond your home market? |
4.6 | Have you decided between building integrations in-house and using an orchestration layer, and modelled the maintenance cost of each? |
Section 5 | AMLR / CDD readiness
Article 22 data points, recognised verification pathways, the CDD RTS timeline, new thresholds (EUR 10,000 for occasional transactions, down from EUR 15,000), and AMLR's exhaustive catalog of enhanced due diligence triggers.
# | Question |
|---|---|
5.1 | Have you mapped your current KYC flows against AMLR Article 22 - verification of name, date of birth, nationality and address against reliable, independent sources? |
5.2 | Can your onboarding support the verification pathways AMLR explicitly recognises: traditional identity documents, eID schemes under eIDAS at substantial or high assurance, the EUDI Wallet, or qualified trust services (QES, QEAA)? |
5.3 | Are you tracking the Customer Due Diligence Regulatory Technical Standards - EBA draft handed to AMLA, AMLA consultation closed May 8, 2026, final draft due to the European Commission by July 10, 2026? |
5.4 | Do your CDD thresholds match AMLR - EUR 10,000 for occasional transactions, EUR 3,000 and above for occasional cash transactions, and limited CDD below EUR 1,000 for crypto-asset transfers? |
5.5 | Are your enhanced due diligence triggers aligned with AMLR - PEPs, high-risk third countries, business relationships involving assets of EUR 5 million or more, and customers with net worth above EUR 50 million? |
5.6 | Are you prepared for supervision under AMLA, including the five-working-day deadline for responding to Financial Intelligence Unit requests? |
Section 6 | Evidence, monitoring and audit trail
CDD as a living record, automated ongoing monitoring under Article 25, and the question supervisors will actually ask: which verification method, at which assurance level, was used for which customer?
# | Question |
|---|---|
6.1 | Can your systems maintain CDD data as a living record, with defined refresh triggers and re-verification logic? |
6.2 | Does your monitoring meet AMLR's expectation of automated ongoing monitoring, rather than periodic sample checks? |
6.3 | Can you produce an audit trail showing which verification method, at which assurance level, was used for which customer? |
The sections map to the 2 regimes like this - and the overlap is the point:
| Features | AMLR | eIDAS 2.0 + PSR |
|---|---|---|
| Scope | ||
| Timeline | ||
| SCA architecture | ||
| Wallet acceptance | ||
| AMLR / CDD | ||
| Evidence and audit trail |
Half the checklist serves both regulations at once. That is the convergence argument in one table: scope, timeline and audit trail are shared infrastructure, not per-regulation work.
Who should use the checklist?
The SCA & AMLR Readiness Checklist is written for compliance officers and product owners. No legal background required - and if the terminology is new, start with our EUDI & eIDAS 2.0 glossary. It applies to any organisation that:
- operates in a sector listed in Art. 5f of eIDAS 2.0, or
- qualifies as an obliged entity under AMLR - including categories entering scope for the first time, or
- relies on electronic identification or trust services anywhere in its user flows, which makes it a relying party whether it realises it or not.
Many companies hold relying party status without knowing it - a login flow or an e-signature integration is enough.
How do you read your checklist score?
Result | What it means | What to do next |
|---|---|---|
Mostly YES | You are ahead of the market. | Close the gaps marked In progress. Pressure-test wallet integrations against the RTS and implementing acts as they are finalised. |
MIXED | You have started, but 2027 readiness is not secured. | Prioritise Sections 3 and 5 - SCA architecture and CDD remediation have the longest lead times. Set milestones for Q4 2026. |
Mostly NO | This is a 2026 priority, not a 2027 one. | Confirm scope first (Section 1), then build a roadmap backwards from July 10, 2027 - the earlier hard deadline. |
The question behind all 32 questions: build or buy?
Most of the checklist reduces to one capability: accepting many identity methods, at defined assurance levels, with evidence. That is an orchestration problem, not a series of one-off integrations.
Build or buy, the architectural question is the same: can you add the next wallet, eID scheme or attestation type without rebuilding your stack?
FAQ
Is the SCA & AMLR Readiness Checklist free?
Yes - the PDF is a direct download with no signup, form, or email gate.
When does AMLR apply?
AMLR (Regulation (EU) 2024/1624) applies from July 10, 2027, directly in all EU Member States, with no national transposition required.
When must companies accept the EUDI Wallet?
Private relying parties in the sectors listed in Art. 5f of eIDAS 2.0 must accept the EUDI Wallet from December 24, 2027, wherever Strong Customer Authentication is legally required.
Does the EUDI Wallet obligation cover in-person payments?
No - the EUDI Wallet acceptance obligation applies to remote scenarios only. In-person point-of-sale and ATM transactions are out of scope, and existing SCA methods remain applicable there.
Will PSD2 still govern SCA in 2027?
No - by 2027, SCA will be governed mainly by the Payment Services Regulation (PSR) in combination with eIDAS 2.0, not by PSD2.
How many EUDI Wallets will companies need to accept?
Companies should prepare for a minimum of 27 national EUDI Wallets - each Member State must provide at least one, and both governments and accredited private entities can issue them. Users may present any of them cross-border.
Do users have to use the EUDI Wallet?
No - users remain free to choose their authentication method. The obligation sits with the relying party: the wallet option must be available wherever SCA is legally required.
How is this different from the EUDI Wallet Readiness Checklist?
The EUDI Wallet Readiness Checklist is a 20-question assessment focused specifically on wallet acceptance - strategy, customer experience, integration, orchestration and fallback. The SCA & AMLR Readiness Checklist is broader: 32 questions covering both AMLR customer due diligence and eIDAS 2.0 wallet acceptance, including SCA architecture under PSR. Use both together: this one to map the full 2027 obligation, the EUDI checklist for the deeper wallet-specific dive.
Is the SCA & AMLR Readiness Checklist legal advice?
No - the checklist is a self-assessment tool for a high-level analysis by compliance officers and product owners, reflecting the regulatory state of play in July 2026.
Changelog
- July 30, 2026 - Full 32-question checklist published on page.
- July 29, 2026 - Initial publication (32 questions, 7 sections, scoring guide).
Share article
Press Contacts
Dominika Cepek
dominika.cepek@authologic.comAuthologic
contact@authologic.com
