AMLR and the EUDI Wallet: when you must accept it, and what is left
The duty to accept the EU Digital Identity Wallet sits in eIDAS Article 5f(2), not in the AMLR. Who it binds, the confirmed and computed dates, what a wallet covers of Article 22, and what due diligence still remains.

In short
The AMLR EUDI wallet question has a two-part answer. The duty to accept the EU Digital Identity (EUDI) Wallet sits in Article 5f(2) of the eIDAS Regulation, not in the EU Anti-Money Laundering Regulation (AMLR). It binds larger private firms that must use strong user authentication, 36 months after the wallet implementing acts.[2] Under AMLR Article 22(6) a wallet is one valid means of verifying identity.[1] It does not finish customer due diligence.
- Acceptance deadline, computed: 24 December 2027.
- A wallet covers identity attributes. Beneficial owners, purpose, screening and monitoring remain.[1]
Regulation (EU) 2024/1183, known as eIDAS 2, creates the wallet and says who must accept it.[2] The AMLR, Regulation (EU) 2024/1624, applies from 10 July 2027 and says how an obliged entity verifies a customer.[1] Many pages blend the two and state that the AMLR makes the wallet compulsory from July 2027. Its operative text does not say that.
This guide separates the two duties, marks which dates are computed, and shows what a wallet covers of the Article 22 data set. For the wider regulation, start with AMLR explained.
What the EU Digital Identity Wallet is under eIDAS 2
eIDAS 2 amends Regulation (EU) No 910/2014, the eIDAS Regulation on electronic identification (eID).[2] Its new Article 5a puts the first duty on Member States, not on companies.
Article 5a(1)Regulation (EU) No 910/2014, as amended by Regulation (EU) 2024/1183
"each Member State shall provide at least one European Digital Identity Wallet within 24 months of the date of entry into force of the implementing acts referred to in paragraph 23 of this Article and in Article 5c(6)."
Source: EUR-Lex, Regulation (EU) 2024/1183[2]
Under eIDAS Article 5a(5)(d), wallets must "meet the requirements set out in Article 8 with regard to assurance level high".[2] That level matters for the AMLR, as shown below.
Not yet known
We did not verify the launch status of each national wallet on 2 October 2026. Check each Member State you onboard in.
Where the EUDI wallet acceptance obligation sits: eIDAS Article 5f(2), not the AMLR
The duty of private companies to accept the wallet is one sentence in eIDAS.
Article 5f(2)Regulation (EU) No 910/2014, as amended by Regulation (EU) 2024/1183
"Where private relying parties that provide services, with the exception of microenterprises and small enterprises [...], are required by Union or national law to use strong user authentication for online identification or where strong user authentication for online identification is required by contractual obligation, including in the areas of transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications, those private relying parties shall, no later than 36 months from the date of entry into force of the implementing acts referred to in Article 5a(23) and Article 5c(6) and only upon the voluntary request of the user, also accept European Digital Identity Wallets that are provided in accordance with this Regulation."
Source: EUR-Lex, Regulation (EU) 2024/1183[2]
The AMLR works differently. Article 22(6) says verification is done "through either of the following means", an identity document or electronic identification.[1] The sentence about acceptance is in a recital, which explains the law but is not an operative article.
Recital 66Regulation (EU) 2024/1624
"The electronic identification as set out in that Regulation should be taken into account and accepted by obliged entities for the customer identification process."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
eIDAS
A duty to accept
- Binds larger private relying parties
- Triggered by strong user authentication
- Runs from the wallet implementing acts
Article 5f(2) eIDAS
AMLR
A means of verification
- Binds every obliged entity
- Triggered by customer due diligence
- Applies from 10 July 2027
Article 22(6) AMLR
Two laws, two different duties.[1][2]
Watch out
"From July 2027 every obliged entity must accept the wallet under the AMLR" is not what the operative text says.
Who must accept the wallet, and from when
Article 5f(2) is a list of conditions. All of them must be met.[2]
| Condition | What Article 5f(2) says |
|---|---|
| Who | Private relying parties that provide services, in banking and financial services among other areas. |
| Who is exempt | Microenterprises and small enterprises. |
| Trigger | Union law, national law or a contract requires "strong user authentication for online identification". |
| Whose choice | "only upon the voluntary request of the user". The customer decides whether to present a wallet. |
| Deadline | "no later than 36 months" from the entry into force of the implementing acts. |
- 24 December 2024Clock startsThe first wallet implementing regulations enter into force.[4]
- 30 September 2026AMLA draftFinal draft standards count wallets as qualifying eID. Not law.[3]
- 24 December 2026Wallets dueComputed: 24 months for Member States.[2]
- 10 July 2027AMLR appliesArticle 22(6) binds obliged entities.[1]
- 24 December 2027AcceptanceComputed: 36 months under Article 5f(2).[2]
The two December deadlines are computed.
Only the starting point is confirmed in a legal text. Commission Implementing Regulation (EU) 2024/2977, one of the first wallet implementing acts, was published in the Official Journal on 4 December 2024 and entered into force on the twentieth day after: 24 December 2024.[4]
We count from the entry into force of that act: 24 months gives 24 December 2026 for Member States, and 36 months gives 24 December 2027 for private acceptance.[2] Both days are our computation and rest on that starting point. The Commission gives only the year: it says the framework "mandates Member States to provide EU Digital Identity (eID) Wallets to citizens by the end of 2026".[5] No primary source we read prints the second day.
Not yet known
On 2 October 2026 the texts do not settle whether customer due diligence onboarding counts as "strong user authentication for online identification" for a given obliged entity. Take advice on this point.
See also our guide to eIDAS 2 deadlines.
How the EUDI Wallet maps to AMLR Article 22(6) and the assurance levels
In Article 22(6), point (a) is the identity document and point (b) the electronic route.
Article 22(6)(b)Regulation (EU) 2024/1624
"the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high' and relevant qualified trust services as set out in that Regulation."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
The floor is substantial. Wallets must meet assurance level high, so they clear it.[2]
AMLA, the EU's Anti-Money Laundering Authority, says so directly in its final draft regulatory technical standards (RTS) on customer due diligence (CDD), dated 30 September 2026. Qualifying eID "includes European Digital Identity Wallets", and eID means and qualified trust services "should be used wherever possible".[3]
That draft is not law. AMLA submitted it to the Commission, and its provisions "will only become definitive upon publication in the Official Journal".[6][7] See AMLA's final customer due diligence standards.
Recital 66 of the AMLR adds that the use of eID "can reduce, where appropriate risk mitigation measures are in place, the risk level to standard or even low".[1]
What a wallet gives you toward the Article 22 data points
Article 22(1)(a) fixes the data to collect on a natural person.[1] AMLA's factsheet says all of those data points must be verified, not only collected.[7] Annex I of the final draft maps them to wallet attributes, based on Implementing Regulation (EU) 2024/2977.[3]
| Article 22(1)(a) data point | Attribute in draft Annex I |
|---|---|
| All names and surnames | family_name, given_name |
| Place and full date of birth | birth_place, birth_date |
| Nationalities | nationality |
| Usual place of residence | The resident address fields |
| National identification number, where applicable | Personal administrative number, where applicable |
Data points of Article 22(1)(a) and the attributes listed in the draft.[1][3]
Two rules in the draft set the limits:
- Enough for what it carries. Where verification uses an Article 22(6)(b) means, "no additional data points need to be obtained and verified through additional information".[3]
- Gaps are yours to fill. Where the eID lacks a required attribute, "the obliged entity shall take steps to obtain and verify the missing attributes through other means".[3]
So map what each presentation returns against Article 22(1), field by field, as set out in AMLR identity verification.
Why a wallet alone does not finish due diligence
Identifying the customer is the first measure in Article 20(1).[1] The other measures are separate duties, and a wallet presentation leaves them untouched.
| Due diligence measure | AMLR article | Covered by a wallet |
|---|---|---|
| Identify and verify the customer | 20(1)(a), 22 | Yes, for the attributes it carries |
| Beneficial owners and the ownership structure | 20(1)(b) | No |
| Purpose of the relationship; source of funds where necessary | 20(1)(c), 25 | No |
| Targeted financial sanctions check | 20(1)(d) | No |
| Politically exposed person (PEP) status | 20(1)(g) | No |
| Customer risk rating | 20(2) | No. The decision on the risk profile cannot be outsourced (Article 18(3)(c)) |
| Ongoing monitoring | 20(1)(f), 26 | No |
| Person acting for the customer | 20(1)(i) | Their identity, yes. Their authority to act, no |
The measures of Article 20(1) and what a wallet presentation settles.[1]
See AMLR beneficial ownership for the 25% rule and ongoing monitoring under Article 26 for the refresh periods.
National eID schemes that already exist
The wallet is not the only electronic route. Article 22(6)(b) speaks of electronic identification means in general.[1] AMLA's final draft covers eID means "regardless of whether they are notified under Article 9 of that Regulation or not, as long as they comply with the requirements of either 'substantial' or 'high' assurance levels [...]".[3]
On that reading, a national scheme at substantial or high can carry the electronic route before any wallet arrives. Article 22(1) attributes it lacks must be obtained and verified "through other means".[3]
Watch out
Neither the AMLR nor the final draft lists which qualified trust services are "relevant". Ask each scheme for its assurance level in writing.
What to do for customers without a wallet
Some customers will have no wallet and no qualifying eID. The AMLR keeps the identity document as the other means in Article 22(6)(a).[1]
Remote document checks are the alternative route in AMLA's final draft. Draft Article 7(1) opens it where a person "cannot reasonably be expected to submit the identity document, passport or equivalent in a face-to-face context and does not have access to electronic identification means and relevant qualified trust services".[3] Two conditions follow:
- Safeguards. Controls that the person presenting the document is its holder, and time-stamped copies.[3]
- Justification. Firms "shall be able to justify why the customer could not be verified through the methods referred to in Article 22(6)".[3]
The draft adds that firms "may continue using existing remote onboarding tools that meet those requirements".[3] How supervisors will treat a customer who holds a wallet and declines to use it was open on 2 October 2026.
1Offer the electronic route first
A wallet or a national eID at substantial or high.
The customer can use a qualifying wallet or eID
Verify with the wallet
Map the attributes to Article 22(1). Obtain missing ones by other means.
Verify with a document
In person, or remotely with safeguards. Record why this route was used.
2Run the rest of due diligence
Beneficial owners, purpose, sanctions and PEP screening, risk rating.
3Decide and keep the records
The onboarding decision stays with the obliged entity.
4Monitor the relationship
Refresh customer information within the Article 26 periods.
Wallet-first onboarding with a document fallback.[1][3]
How Didit helps with wallets and the rest of due diligence
Didit runs the electronic route, the document route and the other checks in one workflow. The AMLR solution page maps each check to its article, and the AMLR guide in the docs shows the setup.
Wallets today. Five digital ID wallets are in production: MitID (Denmark), the Finnish Trust Network, Smart-ID (Estonia, Latvia, Lithuania, Belgium), Mobile-ID (Estonia, Lithuania) and BankID Sweden. Support for the EU Digital Identity (EUDI) Wallet is coming soon; it is not in production today. Confirm with counsel which schemes reach the assurance level you need.
The fallback. Customers without a wallet go to document verification with chip reading, liveness and face match, in the same workflow.
The rest of due diligence. AML screening against 1,300+ sanctions, PEP and watchlists costs $0.20 per check, and ongoing monitoring re-screens daily for $0.07 per person per year. Business verification links identity checks to each owner or officer, and questionnaires carry templates for source of funds and purpose. A full Know Your Customer (KYC) check costs $0.33 and you can start free. See pricing.
Didit provides
- Verification by digital ID wallet, with documents as the fallback
- Sanctions and PEP screening, re-screened daily
- Questionnaires, business verification and a record of every check
Stays with you
- The route each customer takes, and its justification
- The customer risk profile and the onboarding decision
- The liability: you "shall remain fully liable"[1]
Put wallets and documents in one onboarding flow
Offer a digital ID wallet first, fall back to document verification, and run screening in the same workflow.
Key takeaways
- The duty to accept the wallet is in eIDAS Article 5f(2). In the AMLR, acceptance of eID appears only in recital 66.
- Computed dates: wallets due by 24 December 2026, private acceptance by 24 December 2027.
- A wallet covers identity attributes. Beneficial ownership, purpose, source of funds, screening, risk rating and monitoring remain.
- The identity document stays as the other means of verification.
Frequently asked questions
Does the AMLR require obliged entities to accept the EU Digital Identity Wallet?
Not in its operative text. Article 22(6) lists electronic identification as one of two means of verification, and only recital 66 says eID "should be taken into account and accepted".[1] The duty to accept the wallet is in Article 5f(2) of the eIDAS Regulation, with its own conditions.[2]
From what date must private companies accept the wallet?
No later than 36 months after the entry into force of the wallet implementing acts.[2] The first of those acts entered into force on 24 December 2024, which gives 24 December 2027.[4] That day is our computation, not a date printed in the Regulation.
Which companies fall outside the wallet acceptance duty?
Microenterprises and small enterprises are excluded. The duty also applies only where Union law, national law or a contract requires strong user authentication for online identification, and only when the user asks to use a wallet.[2]
Does a wallet check complete customer due diligence?
No. A wallet verifies the identity attributes it carries. Article 20(1) also requires beneficial owner identification, the purpose of the relationship, a sanctions check, politically exposed person status and ongoing monitoring.[1] Attributes the wallet lacks must be obtained and verified by other means, under AMLA's final draft.[3]
Do national eID schemes count, or only the EU wallet?
Under AMLA's final draft, national schemes count if they reach substantial or high, "regardless of whether they are notified under Article 9" of the eIDAS Regulation.[3] The draft is dated 30 September 2026 and is not yet law.[6]
Can we still verify customers with an identity document once wallets arrive?
Yes. The identity document is one of the two means in Article 22(6).[1] For remote onboarding, AMLA's final draft keeps document checks for customers who cannot attend in person and have no qualifying eID, and the firm must justify the choice.[3]
Does onboarding count as strong user authentication for online identification?
That was not settled on 2 October 2026. Article 5f(2) is triggered by a legal or contractual requirement to use strong user authentication for online identification.[2] The texts do not say whether customer due diligence onboarding meets that test. Take advice before you rely on either reading.
How long must we keep the data from a wallet verification?
Five years. Article 77 covers documents and information obtained in customer due diligence, "including information obtained through electronic identification means", for 5 years from the end of the relationship or the occasional transaction. After that, personal data must be deleted.[1]
Sources
- Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
- Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 (eIDAS 2), EUR-Lex.
- Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
- Commission Implementing Regulation (EU) 2024/2977, EUR-Lex, Official Journal of 4 December 2024.
- European Digital Identity Regulation, policy page, European Commission.
- AMLA finalises key standards for the private sector, AMLA press release, 1 October 2026.
- Factsheet on the RTS under Article 28(1) AMLR, AMLA, September 2026.
A wallet shortens one step of due diligence. The other steps, and the decisions, stay where the AMLR puts them. The full map of requirements and checks is on the AMLR solution page.
Build the rest of due diligence around the wallet
Configure identity checks, screening, questionnaires and monitoring, and keep the evidence of each one.
Related articles
- The EU's EUR 10,000 cash limit from July 2027: who it binds
- AMLR software: what to build, what to buy and what it costs
- AMLR identity verification: eID first, documents as the alternative
- AMLR for crypto: what crypto-asset service providers must verify
- AMLR checklist by obliged entity, with the article behind every line
- AMLR beneficial ownership: the 25% rule, control and worked examples