Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 3, 2026

AMLR and the EUDI Wallet: when you must accept it, and what is left

The duty to accept the EU Digital Identity Wallet sits in eIDAS Article 5f(2), not in the AMLR. Who it binds, the confirmed and computed dates, what a wallet covers of Article 22, and what due diligence still remains.

By DiditUpdated
amlr-eudi-wallet-acceptance-cover.png

In short

The AMLR EUDI wallet question has a two-part answer. The duty to accept the EU Digital Identity (EUDI) Wallet sits in Article 5f(2) of the eIDAS Regulation, not in the EU Anti-Money Laundering Regulation (AMLR). It binds larger private firms that must use strong user authentication, 36 months after the wallet implementing acts.[2] Under AMLR Article 22(6) a wallet is one valid means of verifying identity.[1] It does not finish customer due diligence.

  • Acceptance deadline, computed: 24 December 2027.
  • A wallet covers identity attributes. Beneficial owners, purpose, screening and monitoring remain.[1]

Last reviewed: 2 October 2026 · Not legal advice

Regulation (EU) 2024/1183, known as eIDAS 2, creates the wallet and says who must accept it.[2] The AMLR, Regulation (EU) 2024/1624, applies from 10 July 2027 and says how an obliged entity verifies a customer.[1] Many pages blend the two and state that the AMLR makes the wallet compulsory from July 2027. Its operative text does not say that.

This guide separates the two duties, marks which dates are computed, and shows what a wallet covers of the Article 22 data set. For the wider regulation, start with AMLR explained.

What the EU Digital Identity Wallet is under eIDAS 2

eIDAS 2 amends Regulation (EU) No 910/2014, the eIDAS Regulation on electronic identification (eID).[2] Its new Article 5a puts the first duty on Member States, not on companies.

Article 5a(1)Regulation (EU) No 910/2014, as amended by Regulation (EU) 2024/1183

"each Member State shall provide at least one European Digital Identity Wallet within 24 months of the date of entry into force of the implementing acts referred to in paragraph 23 of this Article and in Article 5c(6)."

Source: EUR-Lex, Regulation (EU) 2024/1183[2]

Under eIDAS Article 5a(5)(d), wallets must "meet the requirements set out in Article 8 with regard to assurance level high".[2] That level matters for the AMLR, as shown below.

Not yet known

We did not verify the launch status of each national wallet on 2 October 2026. Check each Member State you onboard in.

Where the EUDI wallet acceptance obligation sits: eIDAS Article 5f(2), not the AMLR

The duty of private companies to accept the wallet is one sentence in eIDAS.

Article 5f(2)Regulation (EU) No 910/2014, as amended by Regulation (EU) 2024/1183

"Where private relying parties that provide services, with the exception of microenterprises and small enterprises [...], are required by Union or national law to use strong user authentication for online identification or where strong user authentication for online identification is required by contractual obligation, including in the areas of transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications, those private relying parties shall, no later than 36 months from the date of entry into force of the implementing acts referred to in Article 5a(23) and Article 5c(6) and only upon the voluntary request of the user, also accept European Digital Identity Wallets that are provided in accordance with this Regulation."

Source: EUR-Lex, Regulation (EU) 2024/1183[2]

The AMLR works differently. Article 22(6) says verification is done "through either of the following means", an identity document or electronic identification.[1] The sentence about acceptance is in a recital, which explains the law but is not an operative article.

Recital 66Regulation (EU) 2024/1624

"The electronic identification as set out in that Regulation should be taken into account and accepted by obliged entities for the customer identification process."

Source: EUR-Lex, Regulation (EU) 2024/1624[1]

eIDAS

A duty to accept

  • Binds larger private relying parties
  • Triggered by strong user authentication
  • Runs from the wallet implementing acts

Article 5f(2) eIDAS

AMLR

A means of verification

  • Binds every obliged entity
  • Triggered by customer due diligence
  • Applies from 10 July 2027

Article 22(6) AMLR

Two laws, two different duties.[1][2]

Watch out

"From July 2027 every obliged entity must accept the wallet under the AMLR" is not what the operative text says.

Who must accept the wallet, and from when

Article 5f(2) is a list of conditions. All of them must be met.[2]

ConditionWhat Article 5f(2) says
WhoPrivate relying parties that provide services, in banking and financial services among other areas.
Who is exemptMicroenterprises and small enterprises.
TriggerUnion law, national law or a contract requires "strong user authentication for online identification".
Whose choice"only upon the voluntary request of the user". The customer decides whether to present a wallet.
Deadline"no later than 36 months" from the entry into force of the implementing acts.
  1. 24 December 2024Clock startsThe first wallet implementing regulations enter into force.[4]
  2. 30 September 2026AMLA draftFinal draft standards count wallets as qualifying eID. Not law.[3]
  3. 24 December 2026Wallets dueComputed: 24 months for Member States.[2]
  4. 10 July 2027AMLR appliesArticle 22(6) binds obliged entities.[1]
  5. 24 December 2027AcceptanceComputed: 36 months under Article 5f(2).[2]

The two December deadlines are computed.

Only the starting point is confirmed in a legal text. Commission Implementing Regulation (EU) 2024/2977, one of the first wallet implementing acts, was published in the Official Journal on 4 December 2024 and entered into force on the twentieth day after: 24 December 2024.[4]

We count from the entry into force of that act: 24 months gives 24 December 2026 for Member States, and 36 months gives 24 December 2027 for private acceptance.[2] Both days are our computation and rest on that starting point. The Commission gives only the year: it says the framework "mandates Member States to provide EU Digital Identity (eID) Wallets to citizens by the end of 2026".[5] No primary source we read prints the second day.

Not yet known

On 2 October 2026 the texts do not settle whether customer due diligence onboarding counts as "strong user authentication for online identification" for a given obliged entity. Take advice on this point.

See also our guide to eIDAS 2 deadlines.

How the EUDI Wallet maps to AMLR Article 22(6) and the assurance levels

In Article 22(6), point (a) is the identity document and point (b) the electronic route.

Article 22(6)(b)Regulation (EU) 2024/1624

"the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high' and relevant qualified trust services as set out in that Regulation."

Source: EUR-Lex, Regulation (EU) 2024/1624[1]

The floor is substantial. Wallets must meet assurance level high, so they clear it.[2]

AMLA, the EU's Anti-Money Laundering Authority, says so directly in its final draft regulatory technical standards (RTS) on customer due diligence (CDD), dated 30 September 2026. Qualifying eID "includes European Digital Identity Wallets", and eID means and qualified trust services "should be used wherever possible".[3]

That draft is not law. AMLA submitted it to the Commission, and its provisions "will only become definitive upon publication in the Official Journal".[6][7] See AMLA's final customer due diligence standards.

Recital 66 of the AMLR adds that the use of eID "can reduce, where appropriate risk mitigation measures are in place, the risk level to standard or even low".[1]

What a wallet gives you toward the Article 22 data points

Article 22(1)(a) fixes the data to collect on a natural person.[1] AMLA's factsheet says all of those data points must be verified, not only collected.[7] Annex I of the final draft maps them to wallet attributes, based on Implementing Regulation (EU) 2024/2977.[3]

Article 22(1)(a) data pointAttribute in draft Annex I
All names and surnamesfamily_name, given_name
Place and full date of birthbirth_place, birth_date
Nationalitiesnationality
Usual place of residenceThe resident address fields
National identification number, where applicablePersonal administrative number, where applicable

Data points of Article 22(1)(a) and the attributes listed in the draft.[1][3]

Two rules in the draft set the limits:

  • Enough for what it carries. Where verification uses an Article 22(6)(b) means, "no additional data points need to be obtained and verified through additional information".[3]
  • Gaps are yours to fill. Where the eID lacks a required attribute, "the obliged entity shall take steps to obtain and verify the missing attributes through other means".[3]

So map what each presentation returns against Article 22(1), field by field, as set out in AMLR identity verification.

Why a wallet alone does not finish due diligence

Identifying the customer is the first measure in Article 20(1).[1] The other measures are separate duties, and a wallet presentation leaves them untouched.

Due diligence measureAMLR articleCovered by a wallet
Identify and verify the customer20(1)(a), 22Yes, for the attributes it carries
Beneficial owners and the ownership structure20(1)(b)No
Purpose of the relationship; source of funds where necessary20(1)(c), 25No
Targeted financial sanctions check20(1)(d)No
Politically exposed person (PEP) status20(1)(g)No
Customer risk rating20(2)No. The decision on the risk profile cannot be outsourced (Article 18(3)(c))
Ongoing monitoring20(1)(f), 26No
Person acting for the customer20(1)(i)Their identity, yes. Their authority to act, no

The measures of Article 20(1) and what a wallet presentation settles.[1]

See AMLR beneficial ownership for the 25% rule and ongoing monitoring under Article 26 for the refresh periods.

National eID schemes that already exist

The wallet is not the only electronic route. Article 22(6)(b) speaks of electronic identification means in general.[1] AMLA's final draft covers eID means "regardless of whether they are notified under Article 9 of that Regulation or not, as long as they comply with the requirements of either 'substantial' or 'high' assurance levels [...]".[3]

On that reading, a national scheme at substantial or high can carry the electronic route before any wallet arrives. Article 22(1) attributes it lacks must be obtained and verified "through other means".[3]

Watch out

Neither the AMLR nor the final draft lists which qualified trust services are "relevant". Ask each scheme for its assurance level in writing.

What to do for customers without a wallet

Some customers will have no wallet and no qualifying eID. The AMLR keeps the identity document as the other means in Article 22(6)(a).[1]

Remote document checks are the alternative route in AMLA's final draft. Draft Article 7(1) opens it where a person "cannot reasonably be expected to submit the identity document, passport or equivalent in a face-to-face context and does not have access to electronic identification means and relevant qualified trust services".[3] Two conditions follow:

  • Safeguards. Controls that the person presenting the document is its holder, and time-stamped copies.[3]
  • Justification. Firms "shall be able to justify why the customer could not be verified through the methods referred to in Article 22(6)".[3]

The draft adds that firms "may continue using existing remote onboarding tools that meet those requirements".[3] How supervisors will treat a customer who holds a wallet and declines to use it was open on 2 October 2026.

1Offer the electronic route first

A wallet or a national eID at substantial or high.

The customer can use a qualifying wallet or eID

Yes

Verify with the wallet

Map the attributes to Article 22(1). Obtain missing ones by other means.

No

Verify with a document

In person, or remotely with safeguards. Record why this route was used.

2Run the rest of due diligence

Beneficial owners, purpose, sanctions and PEP screening, risk rating.

3Decide and keep the records

The onboarding decision stays with the obliged entity.

4Monitor the relationship

Refresh customer information within the Article 26 periods.

Wallet-first onboarding with a document fallback.[1][3]

How Didit helps with wallets and the rest of due diligence

Didit runs the electronic route, the document route and the other checks in one workflow. The AMLR solution page maps each check to its article, and the AMLR guide in the docs shows the setup.

Wallets today. Five digital ID wallets are in production: MitID (Denmark), the Finnish Trust Network, Smart-ID (Estonia, Latvia, Lithuania, Belgium), Mobile-ID (Estonia, Lithuania) and BankID Sweden. Support for the EU Digital Identity (EUDI) Wallet is coming soon; it is not in production today. Confirm with counsel which schemes reach the assurance level you need.

The fallback. Customers without a wallet go to document verification with chip reading, liveness and face match, in the same workflow.

The rest of due diligence. AML screening against 1,300+ sanctions, PEP and watchlists costs $0.20 per check, and ongoing monitoring re-screens daily for $0.07 per person per year. Business verification links identity checks to each owner or officer, and questionnaires carry templates for source of funds and purpose. A full Know Your Customer (KYC) check costs $0.33 and you can start free. See pricing.

Didit provides

  • Verification by digital ID wallet, with documents as the fallback
  • Sanctions and PEP screening, re-screened daily
  • Questionnaires, business verification and a record of every check

Stays with you

  • The route each customer takes, and its justification
  • The customer risk profile and the onboarding decision
  • The liability: you "shall remain fully liable"[1]

Put wallets and documents in one onboarding flow

Offer a digital ID wallet first, fall back to document verification, and run screening in the same workflow.

Start freeTalk to us

Key takeaways

  • The duty to accept the wallet is in eIDAS Article 5f(2). In the AMLR, acceptance of eID appears only in recital 66.
  • Computed dates: wallets due by 24 December 2026, private acceptance by 24 December 2027.
  • A wallet covers identity attributes. Beneficial ownership, purpose, source of funds, screening, risk rating and monitoring remain.
  • The identity document stays as the other means of verification.

Frequently asked questions

Does the AMLR require obliged entities to accept the EU Digital Identity Wallet?

Not in its operative text. Article 22(6) lists electronic identification as one of two means of verification, and only recital 66 says eID "should be taken into account and accepted".[1] The duty to accept the wallet is in Article 5f(2) of the eIDAS Regulation, with its own conditions.[2]

From what date must private companies accept the wallet?

No later than 36 months after the entry into force of the wallet implementing acts.[2] The first of those acts entered into force on 24 December 2024, which gives 24 December 2027.[4] That day is our computation, not a date printed in the Regulation.

Which companies fall outside the wallet acceptance duty?

Microenterprises and small enterprises are excluded. The duty also applies only where Union law, national law or a contract requires strong user authentication for online identification, and only when the user asks to use a wallet.[2]

Does a wallet check complete customer due diligence?

No. A wallet verifies the identity attributes it carries. Article 20(1) also requires beneficial owner identification, the purpose of the relationship, a sanctions check, politically exposed person status and ongoing monitoring.[1] Attributes the wallet lacks must be obtained and verified by other means, under AMLA's final draft.[3]

Do national eID schemes count, or only the EU wallet?

Under AMLA's final draft, national schemes count if they reach substantial or high, "regardless of whether they are notified under Article 9" of the eIDAS Regulation.[3] The draft is dated 30 September 2026 and is not yet law.[6]

Can we still verify customers with an identity document once wallets arrive?

Yes. The identity document is one of the two means in Article 22(6).[1] For remote onboarding, AMLA's final draft keeps document checks for customers who cannot attend in person and have no qualifying eID, and the firm must justify the choice.[3]

Does onboarding count as strong user authentication for online identification?

That was not settled on 2 October 2026. Article 5f(2) is triggered by a legal or contractual requirement to use strong user authentication for online identification.[2] The texts do not say whether customer due diligence onboarding meets that test. Take advice before you rely on either reading.

How long must we keep the data from a wallet verification?

Five years. Article 77 covers documents and information obtained in customer due diligence, "including information obtained through electronic identification means", for 5 years from the end of the relationship or the occasional transaction. After that, personal data must be deleted.[1]

Sources

  1. Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
  2. Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 (eIDAS 2), EUR-Lex.
  3. Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
  4. Commission Implementing Regulation (EU) 2024/2977, EUR-Lex, Official Journal of 4 December 2024.
  5. European Digital Identity Regulation, policy page, European Commission.
  6. AMLA finalises key standards for the private sector, AMLA press release, 1 October 2026.
  7. Factsheet on the RTS under Article 28(1) AMLR, AMLA, September 2026.

A wallet shortens one step of due diligence. The other steps, and the decisions, stay where the AMLR puts them. The full map of requirements and checks is on the AMLR solution page.

Build the rest of due diligence around the wallet

Configure identity checks, screening, questionnaires and monitoring, and keep the evidence of each one.

Start freeTalk to us

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page