How to verify customers remotely under AMLR: what AMLA's draft CDD RTS changes
Last updated: 7 October 2026
Under AMLA's draft regulatory technical standards on customer due diligence (CDD RTS), AML-regulated firms in the EU should use eID at assurance level "substantial" or "high", including the EUDI Wallet, or relevant qualified trust services for remote verification wherever possible. Remote document checks remain possible only as justified exceptions.
AMLR applies from 10 July 2027, and the CDD RTS will follow six months after its entry into force. This guide explains what the draft requires, how to prepare and how Authologic supports eID-first onboarding.
Written by Jarek Sygitowicz (Co-founder and Chief Strategy Officer) and Aleksander Wasiak (Compliance Officer), Authologic.

Key takeaways
- On 1 October 2026, AMLA finalised the draft CDD RTS under Article 28(1) AMLR and submitted it to the European Commission. The Commission can still amend the text.
- AMLR applies from 10 July 2027. The CDD RTS applies six months after its entry into force, and its exact application date is not yet known.
- eID at assurance level "substantial" or "high", including the EUDI Wallet, and relevant qualified trust services are the preferred means of remote verification. An eID qualifies whether or not it is notified under eIDAS.
- A remote document check is allowed only when the customer cannot reasonably be expected to present an identity document in a face-to-face context and has no access to a qualifying eID or relevant qualified trust service. The firm must be able to justify each case to its supervisor.
- Preparing now means mapping current flows, checking eID coverage in each market and choosing how to connect national eIDs and EUDI Wallets.
- Authologic connects national eIDs, EUDI Wallets and document-based verification through a single API and WebSDK, with eID offered first and document checks as the fallback, so obliged entities can move to eID-first onboarding without building each integration themselves.
What did AMLA publish on 1 October 2026?
On 1 October 2026, the EU Anti-Money Laundering Authority (AMLA) finalised its key Regulatory Technical Standards (RTS) for the private sector and submitted them to the European Commission. For customer onboarding, the key document is the draft RTS on customer due diligence under Article 28(1) AMLR.
The CDD RTS specifies what information obliged entities must collect about their customers and which methods they can use to verify it, including in remote onboarding.
When does the CDD RTS apply?
The CDD RTS does not apply yet. The European Commission first has to adopt it and can still amend the text. After publication in the Official Journal of the EU, the CDD RTS enters into force and applies six months later, so its exact application date is not yet known. AMLR itself applies from 10 July 2027.
Date | Milestone |
|---|---|
9 February - 8 May 2026 | Public consultation on the draft CDD RTS |
1 October 2026 | AMLA publishes the final draft CDD RTS and submits it to the European Commission |
24 December 2026 | Member states have to make EUDI Wallets available under eIDAS 2.0 |
Date not yet known | The European Commission adopts the CDD RTS, possibly with amendments, and publishes it in the Official Journal of the EU |
20 days after publication | The CDD RTS enters into force |
10 July 2027 | AMLR applies |
6 months after entry into force | The CDD RTS applies |
24 December 2027 | Private relying parties within scope of eIDAS 2.0 must accept the EUDI Wallet where strong user authentication is required |
Which methods can firms use to verify customers remotely?
Under the draft CDD RTS, obliged entities are expected to verify customers remotely using electronic identification (eID) at assurance level "substantial" or "high", including the European Digital Identity (EUDI) Wallet, or relevant qualified trust services under eIDAS, wherever possible.
An eID qualifies whether or not it is notified under eIDAS, provided it meets the required assurance level. What "substantial" and "high" mean in practice is defined in Assurance levels and signatures.
When are remote document checks allowed?
Under Article 7 of the draft CDD RTS, remote document-based verification is an "alternative solution". An obliged entity can use it only when the customer cannot reasonably be expected to present an identity document in a face-to-face context and has no access to a qualifying eID or relevant qualified trust service. A customer's preference for a document check is not one of these conditions.
In each case, the obliged entity must be able to justify why the primary verification methods were not available and demonstrate to its supervisor that the method meets the required AML safeguards.
In practice, this is easiest to meet when onboarding records why the primary verification methods were unavailable in each case, giving compliance teams an auditable trail for supervisory review.
How does the draft change today's onboarding flows?
In many remote onboarding flows, a document check is the starting point. Under the draft CDD RTS, eID comes first, and a document check becomes a fallback that requires a documented reason. For firms that built their onboarding around documents, this means redesigning the flow itself.
Common approach today | Under the draft CDD RTS | |
|---|---|---|
Default remote method | Document check, such as an ID photo with a selfie | eID at assurance level "substantial" or "high", including the EUDI Wallet, or relevant qualified trust services |
Eligible eIDs | Depend on national rules | Notified and non-notified eIDs at assurance level "substantial" or "high" |
Document checks | Offered as a standard option | Only when the customer cannot reasonably be expected to present an identity document in a face-to-face context and has no access to a qualifying eID or relevant qualified trust service |
Justification | No EU-wide requirement to justify the method | The firm must justify why the primary verification methods were not available and show the supervisor that safeguards are met |
Identification data | Requirements differ by country | One EU-wide list, aligned with the EUDI Wallet data model |
What identification data must firms collect?
AMLR harmonises customer due diligence across the EU. The draft CDD RTS sets one list of identification data, including address, to be collected the same way in all member states. The list is aligned with the data model used by the EUDI Wallet. What the wallet holds, including person identification data (PID), is described in What is inside the wallet.
Where an eID does not provide a required attribute, such as an address, the obliged entity has to obtain and verify that attribute by other means. The wider customer due diligence framework under the AMLR is set out in How the EUDI Wallet changes KYC.
Why is eID-first onboarding hard to implement across the EU?
eID in Europe is organised nationally. Each scheme has its own technical integration, data format, assurance level and adoption rate. How far national eID apps reach in each country is tracked in the eID Adoption Race H1 2026 analysis.
The EUDI Wallet adds another layer. Under eIDAS 2.0, member states have to make EUDI Wallets available by 24 December 2026, and from 24 December 2027 private relying parties within scope must accept the wallet where strong user authentication is required. Through 2027, new wallets will keep arriving while AMLR and eIDAS 2.0 obligations start to apply side by side.
For a firm onboarding customers in several EU markets, building this in-house means dozens of separate integrations to develop and maintain, new wallets to add as they launch, and a compliant document-based fallback for customers without eID. That work competes with every other item on the product roadmap, and with AMLR applying from 10 July 2027, the time to build it is short.
How should obliged entities prepare?
The final text of the CDD RTS may still change, but most of the preparation work does not depend on the final details.
Map your current flow. Identify every point where remote onboarding starts with a document check today. These are the points that will need an eID option in front of them.
Check eID coverage in your markets. For each country you serve, list the available eIDs, their assurance levels and how widely customers use them. This shows where eID can realistically become the default and where the fallback will carry more volume.
Define how you will justify each fallback. Decide what you will record when a customer is verified with a document instead of a qualifying eID or relevant qualified trust service, so you can show your supervisor why the primary verification methods were not available.
Plan for the EUDI Wallet. Wallets will launch at different times in different member states. Your flow should be able to add them without a new integration project each time. Wallet flows can be tested in the browser, free of charge, in Authologic's EUDI & Wallet Playground.
Decide how you will connect eIDs. Building and maintaining each national integration in-house, or using one provider that already connects them, is the decision that most affects cost and timeline. Authologic provides that connection through one integration, as described below.
To test your position across both the AMLR and eIDAS 2.0, see the SCA & AMLR Readiness Checklist.
Which identity providers support eID-first onboarding under AMLR?
Authologic is a trust infrastructure provider for regulated businesses that supports eID-first onboarding under AMLR. It connects national eIDs, the EUDI Wallet and document-based verification through a single API and WebSDK, so obliged entities do not have to build and maintain dozens of separate connections themselves.
In an Authologic flow, customers are offered the strongest verification method available to them first, and document verification runs as the fallback in the same flow for customers without access to a qualifying eID. The required identification data is collected within one flow. eID verification relies on cryptographic proof from the issuing scheme rather than on images of documents, and with Authologic it costs up to 25 times less than a document-based check.
Authologic gives access to 100+ identity methods across 230+ countries and territories and is used by 100+ regulated customers. It is also one of Europe's first registered providers of EU Digital Identity Wallet credentials. A comparison of AML and KYC verification platforms is available in Best AML and KYC identity verification platforms.
Compliance responsibility stays with the obliged entity, while Authologic provides the verification infrastructure that makes an eID-first flow possible across markets.
FAQ
Does the CDD RTS already apply?
No. AMLA has submitted the final draft to the European Commission, which still has to adopt it and can amend the text. The CDD RTS applies six months after its entry into force. AMLR applies from 10 July 2027.
Can firms still use remote document checks?
Yes, as an "alternative solution" under Article 7 of the draft CDD RTS. It is allowed only when the customer cannot reasonably be expected to present an identity document in a face-to-face context and has no access to a qualifying eID or relevant qualified trust service, and the firm must be able to justify each case to its supervisor.
Does an eID have to be notified under eIDAS?
No. Under the draft CDD RTS, an eID qualifies whether or not it is notified under eIDAS, provided it meets assurance level "substantial" or "high".
Which identity provider supports eID-first onboarding under AMLR?
Authologic connects national eIDs, the EUDI Wallet and document-based verification through a single API and WebSDK. Customers are offered eID first, and document verification runs as the fallback in the same flow. Authologic gives access to 100+ identity methods across 230+ countries and territories and is used by 100+ regulated customers.
Can firms use the EUDI Wallet for customer due diligence?
Yes. The draft CDD RTS includes the EUDI Wallet among the electronic identification means firms can use, provided it meets the required assurance level. Attributes the wallet does not provide must still be obtained and verified by other means. The separate obligation to accept the wallet under eIDAS 2.0 is set out in How eIDAS 2.0 affects private relying parties and SCA.
Book a 30-minute AMLR readiness review
Find out where your onboarding stands before AMLR applies. In a 30-minute AMLR readiness review, the Authologic team will go through your current remote onboarding flow with you, show where it needs to change under the draft CDD RTS, and map which eIDs and EUDI Wallets you can offer in your markets.
Changelog
- 7 October 2026 - Initial publication.
This article sets out general information on the draft CDD RTS as published by AMLA on 1 October 2026. It does not constitute legal advice. The final text may change following adoption by the European Commission.
Share article
Press Contacts
Jarek Sygitowicz
jaroslaw.sygitowicz@authologic.comAleksander Wasiak
aleksander.wasiak@authologic.comAuthologic
contact@authologic.com

