Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 3, 2026

AMLR identity verification: eID first, documents as the alternative

What Article 22 of the AMLR requires, what AMLA's final draft of 30 September 2026 says about remote onboarding, and how to choose between electronic ID and document verification for each customer.

By DiditUpdated
amlr-identity-verification-eid-document-remote-onboarding-cover.png

In short

AMLR identity verification rests on Article 22 of the EU Anti-Money Laundering Regulation (AMLR): collect a fixed data set, then verify it with an identity document or with electronic identification (eID) at assurance level substantial or high.[1] For remote onboarding, the final draft standards of AMLA, the EU's anti-money laundering authority, dated 30 September 2026, make eID the default and document-based checks an alternative the firm must justify.[2]

  • Document verification stays lawful: it is one of the two means in Article 22(6).[1]
  • The standards are a final draft, not adopted and not law.[4]

Last reviewed: 2 October 2026 · Not legal advice

Most pages on this topic say one of two things: only electronic identification, wallets and qualified signatures will count from 2027, or nothing changes for a document and a face check. Neither matches the texts.

This guide reads Article 22, then the final draft AMLA announced on 1 October 2026, and turns both into a decision flow. The AMLR, Regulation (EU) 2024/1624, applies from 10 July 2027.[1] For the wider picture, start with AMLR explained.

What AMLR identity verification requires: the Article 22 data set

Identifying the customer and verifying that identity is the first customer due diligence (CDD) measure in Article 20(1)(a).[1] Article 22(1) fixes what to collect. The same data set applies to "any person purporting to act on behalf of the customer".[1]

PointNatural person, Article 22(1)(a)Legal entity, Article 22(1)(b)
(i)All names and surnamesLegal form and name
(ii)Place and full date of birthAddress of the registered or official office, the principal place of business if different, and the country of creation
(iii)Nationalities or protection status, and the national identification number where applicableNames of the legal representatives and, where they exist, the registration number, the tax identification number and the Legal Entity Identifier
(iv)Usual place of residence, or a postal address if there is no fixed one, and the tax identification number where there is oneNames of persons holding shares or a directorship in nominee form, with their nominee status

For a company, the final draft adds verification against constitutive documents and public register extracts.[2] Who owns and controls it is a separate duty: see AMLR beneficial ownership.

Watch out

Collected is not verified. AMLA's factsheet says "all the data points in Article 22(1) AMLR used for the identification purposes, need to be verified".[3] A passport rarely shows an address, so the missing data must come "from reliable and independent sources".[2]

The two means of verification in Article 22(6)

Article 22(6)Regulation (EU) 2024/1624

"Obliged entities shall obtain the information, documents and data necessary for the verification of the identity of the customer and of any person purporting to act on their behalf through either of the following means: (a) the submission of an identity document, passport or equivalent and, where relevant, the acquisition of information from reliable and independent sources, whether accessed directly or provided by the customer; (b) the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high' and relevant qualified trust services as set out in that Regulation."

Source: EUR-Lex, Regulation (EU) 2024/1624, Article 22[1]

Point (a), the document. Under the final draft, a document counts when a designated authority issued it and it shows the holder's names, place and date of birth, a number and expiry date, "a facial image and the signature of the document holder" and "security features to ensure authenticity".[2]

Point (b), electronic identification. The draft covers eID means under the eIDAS Regulation "regardless of whether they are notified under Article 9 of that Regulation or not", provided they reach substantial or high, and adds: "This includes European Digital Identity Wallets."[2] Neither text lists which qualified trust services are "relevant".

An eID is enough for the attributes it carries. Where it lacks one, the firm must "obtain and verify the missing attributes through other means".[2] Wallet duties and dates are in AMLR and the EU Digital Identity Wallet and our guide to eIDAS 2 deadlines.

Note

Recital 66 says eID "should be taken into account and accepted by obliged entities".[1] That is a recital. The operative rule is Article 22(6), which says "through either of the following means".[1]

What AMLA's final draft says about AMLR remote onboarding

The AMLR has no article on video identification, selfie matching or liveness.[1] Remote verification is detailed in the regulatory technical standards (RTS) under Article 28(1). AMLA's final report is dated 30 September 2026 and was announced the next day: "The final draft standards have now been submitted to the European Commission."[4] The full set is covered in AMLA's final customer due diligence standards.

  1. 30 September 2026Final draftAMLA dates its final report.
  2. 1 October 2026AnnouncedAMLA says the draft is with the Commission.
  3. No date yetAdoptionBinding only once in the Official Journal.
  4. 10 July 2027AMLR appliesArticle 22 binds obliged entities.

Where the standards stand on 2 October 2026.[1][2][4]

Status

Everything in this section is a final draft, not adopted and not law. AMLA's factsheet: the RTS "remain subject to review and potential amendments by the European Commission".[3] Article numbers are those of the 30 September 2026 text; earlier drafts differ.[2]

Draft Article 6(3) gives three ways to proceed: obtain the document "or a verified copy thereof", use electronic identification or qualified trust services, or "act in accordance with Article 7".[2] Article 7 is the gateway for remote document checks.

Article 7(1)AMLA final draft RTS, 30 September 2026

"where a natural person cannot reasonably be expected to submit the identity document, passport or equivalent in a face-to-face context and does not have access to electronic identification means and relevant qualified trust services that meet the requirements stipulated by Article 22(6), point (b), of Regulation (EU) 2024/1624, obliged entities shall verify the natural person's identity through their identity document, passport or equivalent using alternative solutions that meet the conditions set out in this Article."

Source: AMLA, Final Report, draft RTS under Article 28(1) AMLR[2]

Both conditions must hold. The alternative solution must then carry five safeguards.

SafeguardWording of draft Article 7(2)
(a) Holder"controls are in place to ensure that the natural person presenting the customer's identity document, passport or equivalent is the document holder"
(b) Channel"the integrity and confidentiality of the communication through the solution are ensured"
(c) QualityImages, video, sound and data are "of sufficient quality that the natural person is unambiguously identifiable"
(d) AbortThe process stops on "technical shortcomings or unexpected connection interruptions" or on doubts about identity
(e) Records"copies are retained, time-stamped and stored securely by the obliged entity"

Safeguards for alternative solutions in the final draft.[2]

Article 7(3)AMLA final draft RTS, 30 September 2026

"Obliged entities using alternative solutions shall be able to justify why the customer could not be verified through the methods referred to in Article 22(6) of Regulation (EU) 2024/1624 and demonstrate to their supervisor that the alternative solutions used comply with the requirements of this Article."

Source: AMLA, Final Report, draft RTS under Article 28(1) AMLR[2]

Recital 11 gives the order of preference. Electronic identification and qualified trust services "should be used wherever possible". Alternative solutions "should only be used on a case-by-case basis", and in those cases firms "may continue using existing remote onboarding tools that meet those requirements".[2] AMLA's reply to respondents: "the measures in Article 22(6) AMLR are still the default option".[2]

Document verification under AMLR: what the "eID only" claim gets wrong

Many vendor pages claim the AMLR allows three methods only: national eID, the wallet and qualified trust services. The texts say otherwise, in both directions.

ClaimWhat the texts say
Only eID, wallets or qualified signatures countArticle 22(6)(a) names the submission of an identity document as one of two means.[1] The draft keeps document-based remote solutions as an alternative.[2]
A document and a face check equal eIDNo. The draft allows them only when neither Article 22(6) means can be used, with a duty to justify.[2]
Liveness, chip reading or a video call is requiredThe AMLR has no article on video identification, selfie matching, liveness or biometrics.[1] The draft names no technique. It asks for "controls".[2]
A named certification is mandatoryThe only technical standard the draft names is Document 9303 of the International Civil Aviation Organization, for document security features.[2]

Document verification remains lawful. Remote document verification is no longer a free choice next to eID: under the draft it serves customers who cannot use the two default means, and the firm must show why.

Not yet known

On 2 October 2026, neither the draft nor the factsheet says how strictly supervisors will read "does not have access to", for example for a customer who holds an eID but declines to use it. Nor is it known whether the Commission will keep Article 7 unchanged.

Which verification route for which customer: a decision flow

The route follows what the customer can use, not what the firm prefers.

1Collect the Article 22(1) data

The fixed data set for a person or a legal entity.

Which Article 22(6) means can this customer use

eID or trust service

Verify with electronic identification

Substantial or high. Get missing attributes by other means.

Document in person

Verify the document face to face

The original or a verified copy, checked for authenticity.

Neither

Use an alternative remote solution

With the five safeguards. Record why neither means was possible.

2Keep the evidence

Time-stamped, readable, ready for your supervisor.

3Continue due diligence

Beneficial owners, purpose and sanctions checks.

Route selection under Article 22(6) AMLR and Articles 6 and 7 of the final draft.[1][2]

Default

Electronic identification

  • Evidence: the eID result and its attributes
  • Coverage: customers with an eID at substantial or high
  • Justification: none specific to the route

Article 22(6)(b) AMLR

Default, in person

Document, face to face

  • Evidence: the document or a verified copy
  • Coverage: customers who can attend in person
  • Justification: none specific to the route

Article 22(6)(a) AMLR

Alternative, remote

Document-based remote solution

  • Evidence: document, holder control and time-stamped record
  • Coverage: customers who can use neither default
  • Justification: required, case by case

Article 7, AMLA final draft

Whatever the route, firms must "at all times be able to demonstrate to their supervisors that the measures taken are appropriate".[1] On the alternative route that means recording, per customer, why neither Article 22(6) means was possible.

What the EBA remote onboarding guidelines add, and their status after July 2027

The technical detail sits in another text: the European Banking Authority (EBA) guidelines EBA/GL/2022/15, applicable since 2 October 2023 to credit and financial institutions under the current directive.[5] They say what the draft leaves open:

  • Unattended solutions should "perform liveness detection verifications" (paragraph 41).[5]
  • The criteria are deemed met where a notified eID at substantial or high, or a relevant qualified trust service, is used (paragraph 45).[5]

Status after 10 July 2027

Not settled. The AMLA Regulation keeps EBA guidelines applicable "until such time as the new guidelines and recommendations issued by the Authority on the same subject start to apply",[6] and AMLA's tracker lists these guidelines among them.[7] Yet the directive they rest on is repealed from 10 July 2027,[8] and the draft does not mention them by name.[2] On 2 October 2026 no primary source says whether they stay, lapse or pass to AMLA.

How Didit helps with both AMLR identity verification routes

Didit runs the electronic route and the document route in one workflow, so each customer takes the route they can use. The AMLR solution page maps each check to its article, and the AMLR guide in the docs shows the setup.

Electronic route. Five digital ID wallets are in production: MitID (Denmark), the Finnish Trust Network, Smart-ID (Estonia, Latvia, Lithuania, Belgium), Mobile-ID (Estonia, Lithuania) and BankID Sweden. Support for the EU Digital Identity (EUDI) Wallet is coming soon. Confirm with counsel which schemes reach the assurance level you need.

Document route. Document capture runs with chip reading over near-field communication (NFC), liveness and face match. These map to the holder control in draft Article 7(2)(a). The draft does not name them, and choosing them is your decision.

Didit was tested in Spain's financial regulatory sandbox, supervised by CNMV with SEPBLAC taking part; the conclusions were published by the Spanish Treasury in February 2026. An independent legal opinion by finReg360, dated 28 April 2026, finds the tool meets the EBA remote onboarding guidelines (EBA/GL/2022/15). It is a legal opinion, not a regulator ruling.

A full Know Your Customer (KYC) check costs $0.33 and you can start free. See pricing.

Didit provides

  • Verification by digital ID wallet or by document
  • Chip reading, liveness and face match
  • A session record for every check, with retention you configure

Stays with you

  • The route each customer takes, and its justification
  • The risk assessment and the onboarding decision
  • The liability: you "shall remain fully liable"[1]

Run both AMLR routes in one workflow

Set up digital ID wallets and document verification side by side, and pay per check.

Start freeTalk to us

Key takeaways

  • Article 22(6) AMLR gives two means of verification: an identity document, or eID at substantial or high and qualified trust services.
  • AMLA's final draft of 30 September 2026 keeps remote document checks as a justified alternative with five safeguards.
  • The draft is not adopted and not law.
  • Neither text names liveness, selfies, video calls or chip reading.

Frequently asked questions

Is document verification still compliant under the AMLR?

Yes. Article 22(6)(a) names the submission of an identity document as one of the two means of verification.[1] For remote onboarding, AMLA's final draft treats document-based solutions as an alternative for customers who cannot attend in person and have no qualifying eID, with a duty to justify.[2]

What does AMLR Article 22 require?

A fixed data set and its verification. For a person: names, place and date of birth, nationalities and place of residence. For a legal entity: legal form and name, registered office, legal representatives and nominee holders.[1] AMLA's factsheet says all these data points must be verified.[3]

Is one method of identity verification preferred over the others?

In AMLA's final draft, yes. Electronic identification and qualified trust services "should be used wherever possible", and alternative remote solutions are for case-by-case use.[2] The regulation itself says "either of the following means".[1]

Will video identification be banned from July 2027?

Neither text bans it or names it. The AMLR has no article on video identification.[1] The draft says firms "may continue using existing remote onboarding tools that meet those requirements" where the alternative route is open.[2]

Does the AMLR require liveness detection, NFC chip reading or biometrics?

No. The regulation has no article on selfie matching, liveness or biometrics.[1] The final draft names no technique and requires "controls" that the presenter is the document holder.[2] Liveness detection appears in the EBA guidelines.[5]

Are AMLA's customer due diligence standards already law?

No. AMLA sent its final draft to the Commission.[4] The Commission may amend it, and it becomes definitive only on publication in the Official Journal.[3] It would apply six months after entry into force, so no calendar date is fixed.[2]

Does an eID check finish customer due diligence?

No. An eID settles identity for the attributes it carries, and missing attributes must be verified by other means.[2] The other measures in Article 20(1) still apply: beneficial owners, purpose, sanctions checks and ongoing monitoring.[1]

Do the EBA remote onboarding guidelines still apply after July 2027?

Not settled on 2 October 2026. The AMLA Regulation keeps EBA guidelines applicable until AMLA instruments on the same subject apply,[6] and AMLA's tracker lists these guidelines among them.[7] No primary source says what happens once the current directive is repealed.[8]

Sources

  1. Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
  2. Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
  3. Factsheet on the RTS under Article 28(1) AMLR, AMLA, September 2026.
  4. AMLA finalises key standards for the private sector, AMLA press release, 1 October 2026.
  5. Guidelines on the use of remote customer onboarding solutions, EBA/GL/2022/15, European Banking Authority.
  6. Regulation (EU) 2024/1620 (AMLA Regulation), EUR-Lex, Article 54(5).
  7. Regulatory instruments tracker, AMLA, last update 30 September 2026.
  8. Directive (EU) 2024/1640 (AMLD6), EUR-Lex, Article 77.

The article by article map of requirements and checks is on the AMLR solution page.

Build your AMLR onboarding flow

Configure the verification routes your risk assessment calls for and keep the evidence behind every customer.

Start freeTalk to us

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page
AMLR identity verification: eID first, documents second