AMLA sent its final draft CDD RTS to the Commission on 1 October 2026. ID documents and eID stay the default; remote tools need a reason, and PEP rules tighten.
Table of contents
AMLA's final draft CDD RTS, sent to the European Commission on 1 October 2026, keep identity documents and eIDAS electronic identification as the default ways to verify a customer. Other remote verification tools stay lawful, but only as a fallback the firm must justify. It becomes law only once adopted and published in the Official Journal.
- On 1 October 2026 AMLA submitted three final draft standards to the Commission, including the CDD RTS under Article 28(1) of the AML Regulation (AMLR).
- Verification runs through an identity document or eIDAS electronic identification at assurance level substantial or high, which includes European Digital Identity Wallets.
- Other remote tools may be used only where neither route is available. The firm must justify each case and meet five safeguards, including keeping time-stamped copies.
- PEP status must be rechecked without delay when the EU list of prominent public functions changes.
- The standard is proposed to apply six months after it enters into force (10 July 2029 for football agents and clubs). The AMLR applies from 10 July 2027.
What did AMLA publish on 1 October 2026?
On 1 October 2026 AMLA published three final draft regulatory technical standards for the private sector and submitted them to the European Commission. The most consequential is the CDD RTS under Article 28(1) AMLR, which fixes what information firms collect, how they verify it, and which remote methods count.
The AMLA press release covers three standards: customer due diligence under Article 28(1), business relationships and linked transactions under Article 19(9), and group-wide requirements under Articles 16(4) and 17(3). All are proposed to apply six months after entry into force, or from 10 July 2029 for football agents and professional football clubs.
The final report, dated 30 September 2026, builds on European Banking Authority advice and a consultation that drew 325 responses.
AMLA says it revised the text to make clear that "the measures in Article 22(6) AMLR are still the default option".
How does the CDD RTS treat remote onboarding?
The CDD RTS recognises two default verification routes and one fallback. Firms verify a natural person with an identity document or with eIDAS electronic identification. Article 7 names no technology, but in practice unattended selfie, video and document-capture flows are its likeliest home, available only when the customer cannot present a document in person and has no qualifying eID.
The two routes come from Article 22(6) AMLR. Point (a) is the submission of an identity document, passport or equivalent. Point (b) is electronic identification meeting eIDAS assurance level substantial or high, or relevant qualified trust services. Recital 11 of the draft says the eID route covers means whether or not they are notified, and expressly includes European Digital Identity Wallets. Article 6(4) adds that eID may also be used face to face.
Article 7 is the fallback. Where a person cannot reasonably be expected to show a document in person and lacks qualifying eID, firms verify the document through "alternative solutions". Those solutions must use reliable and independent sources and meet five safeguards. There must be controls that the person presenting the document is its holder. The communication must keep its integrity and confidentiality. Images, video, sound and data must be captured at a quality that makes the person unambiguously identifiable. The process must stop on technical failures, connection drops or any doubt about identity or integrity. Finally, verified documents must be valid and up to date, with copies retained, time-stamped and stored securely for later checks.
Article 7(3) then requires the firm to justify why the customer could not be verified through either Article 22(6) route, and to show its supervisor that the tool complies. Recital 11 softens the landing: firms "may continue using existing remote onboarding tools" that meet these requirements, and may show compliance through recognised technical standards.
Annex I lists the attributes an eID must provide, such as family_name and birth_place, based on Implementing Regulation (EU) 2024/2977 for EUDI Wallets. Where an attribute is missing, Article 27(2) requires the firm to verify it by other means.
How does it compare with the EBA remote onboarding guidelines?
The CDD RTS is stricter than the EBA remote onboarding guidelines that apply today. Those guidelines treat remote onboarding as an ordinary channel with controls. The CDD RTS treats document-based remote tools as an exception that needs a recorded reason.
| Point of comparison | EBA guidelines EBA/GL/2022/15 | AMLA final draft CDD RTS |
|---|---|---|
| Legal form | Guidelines under the old directive regime | Commission delegated regulation, directly applicable |
| Who is covered | Credit and financial institutions | All obliged entities, financial and non-financial |
| Status of remote document tools | A normal onboarding channel | Fallback when neither Article 22(6) route works |
| Reason needed to use a remote tool | No | Yes, under Article 7(3) |
| Liveness and holder checks | Liveness detection for unattended solutions | Controls that the presenter is the document holder |
| Evidence retention | Time-stamped, securely stored images, video and data (paragraph 26) | Same requirement, now binding (Article 7(2)(e)) |
The EBA text, applied from 2 October 2023, told institutions using unattended solutions to "perform liveness detection verifications". The CDD RTS asks for holder controls without naming a technique. The bigger change is legal form: a delegated regulation binds every obliged entity directly.
When will the CDD RTS apply?
The CDD RTS is a submitted draft, not law. It applies only after the Commission adopts it, Parliament and the Council do not object, and it is published in the Official Journal. AMLA proposes application six months after entry into force. Applying by the AMLR's 10 July 2027 start needs entry into force by 10 January 2027.
Under Article 49 of the AMLA Regulation, the Commission has three months to decide whether to adopt, and may amend the draft. Article 51 gives Parliament and the Council three months to object, extendable by three more. Draft Article 29 sets entry into force 20 days after publication.
| Step | Date or period | Source |
|---|---|---|
| AMLA public consultation | 9 February to 8 May 2026 | AMLA final report |
| Statutory deadline for the draft | 10 July 2026 | AMLR Article 28(1) |
| Submitted to the Commission | 1 October 2026 | AMLA press release |
| AMLR applies | 10 July 2027 | AMLR Article 90 |
| CDD RTS applies | Six months after entry into force | Draft Article 29 |
| CDD RTS and AMLR apply to football agents and clubs | 10 July 2029 | Draft Article 29, AMLR Article 90 |
For existing customers, draft Article 28 and recital 26 say records must be brought into line within the AMLR Article 26(2) update periods, counted from the standard's entry into force. That means one year for higher risk customers and five years for everyone else.
What does the CDD RTS change for your obligations?
The CDD RTS adds three hard rules. PEP status must be rechecked without delay when the Article 43(5) list of prominent public functions changes. Sanctions screening covers names in the original or Latin alphabet, plus listed aliases and wallet addresses. Every Article 7 remote check needs a recorded justification. Identification and ownership data also get firmer rules.
Identification data (CDD). Firms collect every name on the document, including given names and surnames. Place of birth is at least the country, state, city, town or village as shown. Firms take reasonable measures to find other nationalities and verify at least one (Articles 2 to 5).
Simplified due diligence (SDD). In low-risk cases, Article 18 sets a minimum: names, place and date of birth, and nationality. For natural persons no address is required, a point the AMLA factsheet confirms. AMLA's report says it found no further simplification possible without creating exemptions from the AMLR.
Beneficial ownership. Under Article 22(7) AMLR, central registers must be consulted alongside other verification, never instead of it. Article 10 gives examples of verification sources, from business and tax registers to credit agencies and group entities. Article 11 sets the data to obtain on each intermediate layer of a UBO structure, including nominee directors.
PEP screening. Article 17 requires a PEP check before onboarding, risk-based rechecks, and rechecks without delay when customer data or the Article 43(5) list changes. Tools may be automated, manual or both. See our PEP glossary entry.
Targeted financial sanctions. Article 25 covers customers, beneficial owners and controlling persons. Screening runs at onboarding, on every list change, on changes to customer data, and without undue delay after UN listings are published.
Record-keeping. For Article 7 fallback tools, copies of images, video, sound and data must be retained, time-stamped and readable for later verification. That sits on top of AMLR Article 77, which keeps CDD records for five years after the relationship ends. Article 77(2) lets firms keep references instead of copies if the data can be produced immediately and cannot be altered.
What is still uncertain about the CDD RTS?
Several points remain open: the final text, the start date, the meaning of the fallback test, and how much evidence firms must store. The sharpest is timing: unless Parliament and the Council waive their objection window, the AMLR will apply before the CDD RTS that details it.
The text can still change. The Commission may adopt the draft in part or with amendments, so avoid hard-coding details it may revise.
A start-date gap is likely. Entry into force by 10 January 2027 means publication by about 21 December 2026, possible only if Parliament and the Council waive their objection window early under AMLA Regulation Article 51(2). Otherwise the AMLR applies before the detail on how to meet it.
The fallback test is undefined. Article 7 applies where a person "cannot reasonably be expected" to present a document in person and lacks qualifying eID. The draft gives no list of qualifying situations. For a digital-only bank, the first question is whether a remote-only model meets that limb; if it does, the test turns on whether each customer has qualifying eID. Expect supervisors to read this differently until AMLA issues guidance.
EUDI Wallet readiness varies. The default route assumes customers can present eID at substantial or high assurance. Article 27(2) makes the firm fill any attribute a wallet lacks, so firms serving several markets will run a mixed model.
Retention collides with minimisation. Article 7(2)(e) turns the EBA's time-stamped retention of images and video into binding law for every Article 7 flow. Central stores of ID images are exactly what recent breaches have exposed, from the Times Car breach to IDScan. AMLA says it engaged the European Data Protection Supervisor, but the draft leaves security design to firms.
Simplified due diligence is still thin. On 2 October 2026 AMLA invited stakeholders to roundtables in Frankfurt between 9 November and 2 December 2026, with expressions of interest due by 18 October.
How should compliance teams respond?
Run a gap analysis against the final draft, not the February consultation text, which is no longer the baseline. Map every onboarding path to an Article 22(6) route or an Article 7 fallback, then fix data fields, screening triggers and evidence storage.
First, classify each onboarding flow. Document checks in a branch and eID at substantial or high assurance sit under Article 22(6). A copy attested as matching the original also falls under point (a) (Article 6(3), recital 10). Remote selfie and document capture otherwise sits under Article 7 unless anchored to qualifying eID. For each Article 7 flow, write down the conditions that trigger it and build a per-customer justification record.
Second, test eID acceptance. List the eID means and EUDI Wallets your customers hold, and check that your stack can read the Annex I attributes and flag missing ones. See our EUDI Wallet guide.
Third, update screening rules. Add a trigger to recheck PEP status when the prominent public functions list changes, and confirm your sanctions engine handles original scripts, transliteration and wallet addresses. Read it with the AMLA ongoing monitoring consultation.
Fourth, review where verification evidence lives: a full copy or an Article 77(2) reference model, and who holds the keys.
Zyphe reads the NFC chip of passports and ID cards to ICAO 9303 and runs two-step liveness. After verification, documents and biometrics are encrypted into a vault split across a decentralised network of thousands of nodes, unlockable only with a key held by the user or by your firm, so there is no central store of customer PII. If you are mapping your onboarding flows to the CDD RTS, see how our KYC software and AML screening fit, or book a demo.
The bottom line
Remote onboarding survives the CDD RTS, but documents and qualifying eID are the default and everything else needs a reason on file. Teams that classify their flows, prepare for wallets and rethink where verification evidence sits will not have to rebuild twice.
Cited sources
- AMLA press release: AMLA finalises key standards for the private sector, 1 October 2026
- AMLA final report: draft RTS under Article 28(1) of Regulation (EU) 2024/1624, 30 September 2026
- AMLA factsheet on the RTS on customer due diligence under Article 28(1) AMLR
- Regulation (EU) 2024/1624, the AML Regulation, Articles 22, 26, 28, 77 and 90
- Regulation (EU) 2024/1620 establishing AMLA, Articles 49 and 51
- EBA Guidelines on the use of remote customer onboarding solutions, EBA/GL/2022/15
- AMLA invitation to sectoral roundtables on simplified customer due diligence, 2 October 2026
- Commission Implementing Regulation (EU) 2024/2977 on person identification data for EUDI Wallets
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.