Compliance operations guide

EU AMLR 2027 readiness: customer due diligence and KYC

Plan policy changes, customer-file reviews and evidence checks without confusing operational support with legal advice.

AMLR 2027 readiness means preparing for the EU Anti-Money Laundering Regulation (AMLR), generally applicable from 10 July 2027. Review legal scope, customer information, monitoring and outsourcing controls. Actigy BPO provides nearshore business process outsourcing (BPO) support for client-approved file reviews and remediation. Compliance owners retain legal interpretation, risk policy and customer decisions.

Scope: An operational planning guide for EU compliance teams, not legal advice or a compliance opinion. Read the linked law with your legal adviser.

Key takeaways

Actigy BPO separates operational preparation from the legal assessment of your obligations.

  • General AMLR application starts on 10 July 2027; specified football-sector entities have a later date.
  • AMLA direct supervision of selected firms starts in 2028, not for every firm in 2027.
  • Risk-based reviews include relevant changes between scheduled updates.
  • Every Actigy BPO engagement starts with a process audit and a paid pilot.
  • Actigy BPO works in the client's tools, with access limited to the systems the client approves.

Customer due diligence (CDD) and know your customer (KYC) work need clear populations, evidence and decision owners. A readiness project is not complete just because a task list is closed. A reviewer must be able to trace the approved rule to the file checks and unresolved exceptions.

AMLR 2027: what changes for KYC?

Actigy BPO can turn approved KYC rules into file queues, checks and reports. AMLR sets directly applicable rules for covered EU firms. Local laws still matter. First confirm which rules apply, then find the records and processes that need work. A provider's checklist is not legal approval.

Article 90 of Regulation (EU) 2024/1624 sets general application from 10 July 2027. The specified football agents and professional football clubs enter from 10 July 2029. Confirm whether your entity and activities fall within scope rather than applying either date without that check.

Compare your approved target policy with the evidence you hold today. A missing address, unclear owner and overdue review need different actions. Group those gaps before you size a team or set a due date.

EU AML package explained: AMLR, AMLD6 and AMLA

Actigy BPO uses the EU AML package to frame approved work, not as a provider credential. AMLR sets covered firms' duties; AMLD6 addresses national mechanisms. AMLA is the authority. Split legal work, system changes and file checks by owner. These roles do not share a single deadline.

EU AML package roles summarized by Actigy BPO
Instrument or bodyRolePlanning consequence
AMLR, Regulation 2024/1624Directly applicable rules for covered entities.Map applicable duties to policy and evidence.
AMLD6, Directive 2024/1640National prevention mechanisms, supervision and financial intelligence arrangements.Track relevant national implementation with legal counsel.
AMLA, established by Regulation 2024/1620EU authority coordinating supervision and financial intelligence work.Separate authority milestones from your operational deadlines.

In this package, AMLD6 means Directive (EU) 2024/1640, also called 6AMLD. It is not the earlier criminal-law Directive 2018/1673. AMLR does not replace every national anti-money laundering (AML) rule. Your legal register needs both EU instruments and relevant local requirements.

What are AMLR customer due diligence requirements?

Actigy BPO prepares evidence under the client's approved CDD policy. AMLR Article 20 covers customer and beneficial-owner checks, the relationship's purpose and monitoring. The legal owner maps those rules to the firm. Operators use approved fields and checks. A set of documents alone does not prove that all duties are met.

Use Article 20 to anchor the legal review. Article 34 addresses enhanced due diligence (EDD) for specified higher-risk cases. The client determines the applicable measures and approves decisions. Operators prepare evidence; they do not create a risk policy.

Beneficial ownership and source conflicts

Actigy BPO records ownership evidence and gaps in the client's case system. Trace each claim to its source and date. An ownership chart without supporting records leaves a gap. Conflicting registers, customer statements or identity records need a named reviewer. Do not invent a missing owner or assume a blank field means no control.

A review pack separates facts, open questions and client decisions. Record the policy version used for the check. If a rule changes, find the files it affects. Do not repeat work before the client confirms the change.

Refresh intervals and existing customer files

Actigy BPO prepares review schedules from client-approved risk tiers and triggers. Article 26 sets update ceilings of 1 year for specified higher-risk customers and 5 years for others. Relevant changes also require review. Those ceilings are not permission to wait when a trigger occurs.

Do not infer that every file needs a full review on the same day. The compliance owner checks current records against the duties and approves the plan. Split files with known gaps from those due for routine review. Record why each group takes priority.

Actigy BPO can run KYC refresh and periodic review for ongoing work. Use KYC remediation for a defined repair population. Both queues need named decision owners. A successful backlog project does not solve recurring reviews if new due files keep arriving without capacity.

Track customer response, missing sources and client-held decisions separately. An operator can finish a request without obtaining acceptable evidence. Closing the task does not resolve that gap. Reopened files need their original history and current next action.

An Actigy BPO readiness work plan

Actigy BPO scopes file work after the client confirms the legal rules and target policy. The steps below create outputs you can check. A process provider is not a legal adviser. Give each stage an owner and an acceptance rule. Record open issues before the next stage starts.

  1. Confirm legal scope. Assign applicability, local rules and technical standards to your compliance and legal owners.
  2. Map policy gaps. Record the current rule, approved change and affected workflow.
  3. Size the population. Count files by risk tier, due date and known evidence gap.
  4. Prepare instructions. Agree required fields, outreach, checks and escalation paths.
  5. Test a pilot. Review a defined sample before committing capacity to the full queue.
  6. Resolve exceptions. Assign missing records, policy questions and risk decisions to named owners.
  7. Retain evidence. Record accepted packs, returned work, approvals and the next review schedule.
Actigy BPO preparation tasks and retained client decisions
WorkstreamActigy BPO operational supportClient owner and evidence
Policy mappingDocument the approved process and task boundaries.Compliance approves interpretation and procedure.
Customer recordsCheck agreed fields, request documents and prepare packs.Reviewer resolves disputed evidence and risk changes.
Monitoring queueReview agreed alerts and record escalation reasons.Compliance owns thresholds and final actions.
Quality checksCheck work against accepted examples and log defects.Client approves acceptance rules and changes.
Progress reportingSeparate due, prepared, returned and blocked files.Program owner accepts completion and remaining risks.

Capacity, review quality and handover evidence

Actigy BPO tests effort and quality on a defined pilot group. Include simple and complex files, not just easy cases. Split time spent on file checks from time spent waiting for a reply or decision. Plan for new reviews as well as the old backlog.

Quality assurance (QA) checks work against accepted examples and agreed samples. Define the count behind each measure. Report prepared packs, first-review acceptance, returns and the age of open issues. No single files-per-day target fits every risk mix or ownership structure.

Actigy BPO retains the evidence trail in approved client systems. A handover pack identifies the file, policy version, sources, preparer, checker and pending decisions. Use KYC outsourcing for broader onboarding and review capacity. Use AML outsourcing for agreed alert review and case preparation.

Before adding work, compare the pilot with the full queue. A sample of complete files does not test the effort to find missing ownership records. State that limit in the plan. Test the untried work type before you set its staffing level.

What Actigy BPO does not decide

Actigy BPO prepares work under the client's policy; the client retains legal accountability and regulated decisions. AMLR Article 18 addresses outsourcing controls, supervisory notification and reserved tasks. Your legal and compliance owners must assess the arrangement before operations begin.

The team never acts as your money laundering reporting officer (MLRO). Customer risk ratings, acceptance and exits remain with authorized client staff. Suspicious activity report (SAR) and suspicious transaction report (STR) decisions and filings also remain with the client. A completed provider checklist is not a regulatory approval.

Actigy BPO delivers from teams in Bulgaria, Romania, Poland and Ukraine. Ukraine is outside the EU. The written scope names work locations, roles, subprocessors and any transfer terms. Agree access, retention and record return in the data-processing terms; do not infer data residency from headquarters.

What starts with AMLA supervision in 2028?

The EU Anti-Money Laundering Authority (AMLA) starts direct supervision of selected financial firms in 2028. Actigy BPO distinguishes that milestone from AMLR's general application in 2027. AMLA is based in Frankfurt and began operations in summer 2025. National supervisors continue to matter; not every firm moves to direct EU supervision.

AMLA's official timeline explains the sequence. Its selection update identifies the first selection cycle in 2027. Ask your supervisory contact about firm-specific reporting. Do not assume that a vendor or ordinary compliance team belongs in the selected group.

AMLR 2027 readiness FAQ

Actigy BPO answers operational planning questions; your legal adviser confirms obligations for your entity.

When does the EU AMLR apply?

AMLR generally applies from 10 July 2027, with the specified football-sector exception in Article 90. Actigy BPO uses that date as planning context, not as a promise of compliance by a deadline. The legal owner confirms scope and any relevant national requirements.

Existing obligations remain relevant before application. Build the transition around approved policy changes, file evidence and accountable reviewers rather than waiting for the general date to begin preparation.

What is AMLA?

AMLA is the EU authority for anti-money laundering and countering the financing of terrorism. Actigy BPO provides operational support, not AMLA supervision or regulatory approval. The authority is based in Frankfurt and coordinates work with national bodies. Direct supervision of selected financial firms starts in 2028.

Check the authority's official timeline and your supervisory contact for the relevant reporting process. Do not confuse the authority with the separate AMLR legal instrument.

What changes for customer due diligence under AMLR?

Actigy BPO supports the operational review of customer files against client-approved requirements. AMLR harmonizes covered duties, including identity and beneficial-owner checks, relationship information and monitoring. Your legal owner determines which policy and system changes apply.

Translate the approved requirements into fields, source checks, review triggers and retained decisions. A document upload alone is not a completed CDD assessment. Keep unresolved gaps and the decision owner visible in the file history.

Do firms need to refresh existing customer files?

Actigy BPO can review existing files against the client's approved risk-based schedule and identified gaps. The correct population depends on current evidence, triggers and applicable duties. A general application date does not establish a universal instruction to reverify every file on one day.

Have the compliance owner approve the population and priority rules. Separate historical remediation from recurring reviews, then record customer non-response and client-held decisions rather than treating incomplete files as finished.

Is this guide legal advice?

Actigy BPO publishes this guide for operational planning, not legal advice. A qualified legal adviser and your compliance team must interpret the rules for your entity, activities and location. The linked primary sources take precedence over a summary.

Review later technical standards and supervisory guidance before changing policy. The service prepares files and reports under approved instructions; it does not certify readiness, replace legal review or transfer regulated decisions to an external operator.

Sources and next steps

Actigy BPO checked the linked EU law and authority material on October 5, 2026. The editorial standards explain source handling and corrections. Regulations, adopted standards and firm-specific supervisory instructions require separate legal review.

To scope operations, provide aggregate file counts, risk groups, due dates and known gaps. Do not send customer identity records in an initial enquiry. Agree the approved work and secure access before transferring case evidence.

Page updates

Actigy BPO published this guide on October 5, 2026, with review responsibilities, evidence checks and linked regulatory sources.