AMLR identity verification: eID first, documents as the alternative
What Article 22 of the AMLR requires, what AMLA's final draft of 30 September 2026 says about remote onboarding, and how to choose between electronic ID and document verification for each customer.

In short
AMLR identity verification rests on Article 22 of the EU Anti-Money Laundering Regulation (AMLR): collect a fixed data set, then verify it with an identity document or with electronic identification (eID) at assurance level substantial or high.[1] For remote onboarding, the final draft standards of AMLA, the EU's anti-money laundering authority, dated 30 September 2026, make eID the default and document-based checks an alternative the firm must justify.[2]
- Document verification stays lawful: it is one of the two means in Article 22(6).[1]
- The standards are a final draft, not adopted and not law.[4]
Most pages on this topic say one of two things: only electronic identification, wallets and qualified signatures will count from 2027, or nothing changes for a document and a face check. Neither matches the texts.
This guide reads Article 22, then the final draft AMLA announced on 1 October 2026, and turns both into a decision flow. The AMLR, Regulation (EU) 2024/1624, applies from 10 July 2027.[1] For the wider picture, start with AMLR explained.
What AMLR identity verification requires: the Article 22 data set
Identifying the customer and verifying that identity is the first customer due diligence (CDD) measure in Article 20(1)(a).[1] Article 22(1) fixes what to collect. The same data set applies to "any person purporting to act on behalf of the customer".[1]
| Point | Natural person, Article 22(1)(a) | Legal entity, Article 22(1)(b) |
|---|---|---|
| (i) | All names and surnames | Legal form and name |
| (ii) | Place and full date of birth | Address of the registered or official office, the principal place of business if different, and the country of creation |
| (iii) | Nationalities or protection status, and the national identification number where applicable | Names of the legal representatives and, where they exist, the registration number, the tax identification number and the Legal Entity Identifier |
| (iv) | Usual place of residence, or a postal address if there is no fixed one, and the tax identification number where there is one | Names of persons holding shares or a directorship in nominee form, with their nominee status |
For a company, the final draft adds verification against constitutive documents and public register extracts.[2] Who owns and controls it is a separate duty: see AMLR beneficial ownership.
Watch out
Collected is not verified. AMLA's factsheet says "all the data points in Article 22(1) AMLR used for the identification purposes, need to be verified".[3] A passport rarely shows an address, so the missing data must come "from reliable and independent sources".[2]
The two means of verification in Article 22(6)
Article 22(6)Regulation (EU) 2024/1624
"Obliged entities shall obtain the information, documents and data necessary for the verification of the identity of the customer and of any person purporting to act on their behalf through either of the following means: (a) the submission of an identity document, passport or equivalent and, where relevant, the acquisition of information from reliable and independent sources, whether accessed directly or provided by the customer; (b) the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels 'substantial' or 'high' and relevant qualified trust services as set out in that Regulation."
Point (a), the document. Under the final draft, a document counts when a designated authority issued it and it shows the holder's names, place and date of birth, a number and expiry date, "a facial image and the signature of the document holder" and "security features to ensure authenticity".[2]
Point (b), electronic identification. The draft covers eID means under the eIDAS Regulation "regardless of whether they are notified under Article 9 of that Regulation or not", provided they reach substantial or high, and adds: "This includes European Digital Identity Wallets."[2] Neither text lists which qualified trust services are "relevant".
An eID is enough for the attributes it carries. Where it lacks one, the firm must "obtain and verify the missing attributes through other means".[2] Wallet duties and dates are in AMLR and the EU Digital Identity Wallet and our guide to eIDAS 2 deadlines.
Note
Recital 66 says eID "should be taken into account and accepted by obliged entities".[1] That is a recital. The operative rule is Article 22(6), which says "through either of the following means".[1]
What AMLA's final draft says about AMLR remote onboarding
The AMLR has no article on video identification, selfie matching or liveness.[1] Remote verification is detailed in the regulatory technical standards (RTS) under Article 28(1). AMLA's final report is dated 30 September 2026 and was announced the next day: "The final draft standards have now been submitted to the European Commission."[4] The full set is covered in AMLA's final customer due diligence standards.
- 30 September 2026Final draftAMLA dates its final report.
- 1 October 2026AnnouncedAMLA says the draft is with the Commission.
- No date yetAdoptionBinding only once in the Official Journal.
- 10 July 2027AMLR appliesArticle 22 binds obliged entities.
Where the standards stand on 2 October 2026.[1][2][4]
Status
Everything in this section is a final draft, not adopted and not law. AMLA's factsheet: the RTS "remain subject to review and potential amendments by the European Commission".[3] Article numbers are those of the 30 September 2026 text; earlier drafts differ.[2]
Draft Article 6(3) gives three ways to proceed: obtain the document "or a verified copy thereof", use electronic identification or qualified trust services, or "act in accordance with Article 7".[2] Article 7 is the gateway for remote document checks.
Article 7(1)AMLA final draft RTS, 30 September 2026
"where a natural person cannot reasonably be expected to submit the identity document, passport or equivalent in a face-to-face context and does not have access to electronic identification means and relevant qualified trust services that meet the requirements stipulated by Article 22(6), point (b), of Regulation (EU) 2024/1624, obliged entities shall verify the natural person's identity through their identity document, passport or equivalent using alternative solutions that meet the conditions set out in this Article."
Source: AMLA, Final Report, draft RTS under Article 28(1) AMLR[2]
Both conditions must hold. The alternative solution must then carry five safeguards.
| Safeguard | Wording of draft Article 7(2) |
|---|---|
| (a) Holder | "controls are in place to ensure that the natural person presenting the customer's identity document, passport or equivalent is the document holder" |
| (b) Channel | "the integrity and confidentiality of the communication through the solution are ensured" |
| (c) Quality | Images, video, sound and data are "of sufficient quality that the natural person is unambiguously identifiable" |
| (d) Abort | The process stops on "technical shortcomings or unexpected connection interruptions" or on doubts about identity |
| (e) Records | "copies are retained, time-stamped and stored securely by the obliged entity" |
Safeguards for alternative solutions in the final draft.[2]
Article 7(3)AMLA final draft RTS, 30 September 2026
"Obliged entities using alternative solutions shall be able to justify why the customer could not be verified through the methods referred to in Article 22(6) of Regulation (EU) 2024/1624 and demonstrate to their supervisor that the alternative solutions used comply with the requirements of this Article."
Source: AMLA, Final Report, draft RTS under Article 28(1) AMLR[2]
Recital 11 gives the order of preference. Electronic identification and qualified trust services "should be used wherever possible". Alternative solutions "should only be used on a case-by-case basis", and in those cases firms "may continue using existing remote onboarding tools that meet those requirements".[2] AMLA's reply to respondents: "the measures in Article 22(6) AMLR are still the default option".[2]
Document verification under AMLR: what the "eID only" claim gets wrong
Many vendor pages claim the AMLR allows three methods only: national eID, the wallet and qualified trust services. The texts say otherwise, in both directions.
| Claim | What the texts say |
|---|---|
| Only eID, wallets or qualified signatures count | Article 22(6)(a) names the submission of an identity document as one of two means.[1] The draft keeps document-based remote solutions as an alternative.[2] |
| A document and a face check equal eID | No. The draft allows them only when neither Article 22(6) means can be used, with a duty to justify.[2] |
| Liveness, chip reading or a video call is required | The AMLR has no article on video identification, selfie matching, liveness or biometrics.[1] The draft names no technique. It asks for "controls".[2] |
| A named certification is mandatory | The only technical standard the draft names is Document 9303 of the International Civil Aviation Organization, for document security features.[2] |
Document verification remains lawful. Remote document verification is no longer a free choice next to eID: under the draft it serves customers who cannot use the two default means, and the firm must show why.
Not yet known
On 2 October 2026, neither the draft nor the factsheet says how strictly supervisors will read "does not have access to", for example for a customer who holds an eID but declines to use it. Nor is it known whether the Commission will keep Article 7 unchanged.
Which verification route for which customer: a decision flow
The route follows what the customer can use, not what the firm prefers.
1Collect the Article 22(1) data
The fixed data set for a person or a legal entity.
Which Article 22(6) means can this customer use
Verify with electronic identification
Substantial or high. Get missing attributes by other means.
Verify the document face to face
The original or a verified copy, checked for authenticity.
Use an alternative remote solution
With the five safeguards. Record why neither means was possible.
2Keep the evidence
Time-stamped, readable, ready for your supervisor.
3Continue due diligence
Beneficial owners, purpose and sanctions checks.
Route selection under Article 22(6) AMLR and Articles 6 and 7 of the final draft.[1][2]
Default
Electronic identification
- Evidence: the eID result and its attributes
- Coverage: customers with an eID at substantial or high
- Justification: none specific to the route
Article 22(6)(b) AMLR
Default, in person
Document, face to face
- Evidence: the document or a verified copy
- Coverage: customers who can attend in person
- Justification: none specific to the route
Article 22(6)(a) AMLR
Alternative, remote
Document-based remote solution
- Evidence: document, holder control and time-stamped record
- Coverage: customers who can use neither default
- Justification: required, case by case
Article 7, AMLA final draft
Whatever the route, firms must "at all times be able to demonstrate to their supervisors that the measures taken are appropriate".[1] On the alternative route that means recording, per customer, why neither Article 22(6) means was possible.
What the EBA remote onboarding guidelines add, and their status after July 2027
The technical detail sits in another text: the European Banking Authority (EBA) guidelines EBA/GL/2022/15, applicable since 2 October 2023 to credit and financial institutions under the current directive.[5] They say what the draft leaves open:
- Unattended solutions should "perform liveness detection verifications" (paragraph 41).[5]
- The criteria are deemed met where a notified eID at substantial or high, or a relevant qualified trust service, is used (paragraph 45).[5]
Status after 10 July 2027
Not settled. The AMLA Regulation keeps EBA guidelines applicable "until such time as the new guidelines and recommendations issued by the Authority on the same subject start to apply",[6] and AMLA's tracker lists these guidelines among them.[7] Yet the directive they rest on is repealed from 10 July 2027,[8] and the draft does not mention them by name.[2] On 2 October 2026 no primary source says whether they stay, lapse or pass to AMLA.
How Didit helps with both AMLR identity verification routes
Didit runs the electronic route and the document route in one workflow, so each customer takes the route they can use. The AMLR solution page maps each check to its article, and the AMLR guide in the docs shows the setup.
Electronic route. Five digital ID wallets are in production: MitID (Denmark), the Finnish Trust Network, Smart-ID (Estonia, Latvia, Lithuania, Belgium), Mobile-ID (Estonia, Lithuania) and BankID Sweden. Support for the EU Digital Identity (EUDI) Wallet is coming soon. Confirm with counsel which schemes reach the assurance level you need.
Document route. Document capture runs with chip reading over near-field communication (NFC), liveness and face match. These map to the holder control in draft Article 7(2)(a). The draft does not name them, and choosing them is your decision.
Didit was tested in Spain's financial regulatory sandbox, supervised by CNMV with SEPBLAC taking part; the conclusions were published by the Spanish Treasury in February 2026. An independent legal opinion by finReg360, dated 28 April 2026, finds the tool meets the EBA remote onboarding guidelines (EBA/GL/2022/15). It is a legal opinion, not a regulator ruling.
A full Know Your Customer (KYC) check costs $0.33 and you can start free. See pricing.
Didit provides
- Verification by digital ID wallet or by document
- Chip reading, liveness and face match
- A session record for every check, with retention you configure
Stays with you
- The route each customer takes, and its justification
- The risk assessment and the onboarding decision
- The liability: you "shall remain fully liable"[1]
Run both AMLR routes in one workflow
Set up digital ID wallets and document verification side by side, and pay per check.
Key takeaways
- Article 22(6) AMLR gives two means of verification: an identity document, or eID at substantial or high and qualified trust services.
- AMLA's final draft of 30 September 2026 keeps remote document checks as a justified alternative with five safeguards.
- The draft is not adopted and not law.
- Neither text names liveness, selfies, video calls or chip reading.
Frequently asked questions
Is document verification still compliant under the AMLR?
Yes. Article 22(6)(a) names the submission of an identity document as one of the two means of verification.[1] For remote onboarding, AMLA's final draft treats document-based solutions as an alternative for customers who cannot attend in person and have no qualifying eID, with a duty to justify.[2]
What does AMLR Article 22 require?
A fixed data set and its verification. For a person: names, place and date of birth, nationalities and place of residence. For a legal entity: legal form and name, registered office, legal representatives and nominee holders.[1] AMLA's factsheet says all these data points must be verified.[3]
Is one method of identity verification preferred over the others?
In AMLA's final draft, yes. Electronic identification and qualified trust services "should be used wherever possible", and alternative remote solutions are for case-by-case use.[2] The regulation itself says "either of the following means".[1]
Will video identification be banned from July 2027?
Neither text bans it or names it. The AMLR has no article on video identification.[1] The draft says firms "may continue using existing remote onboarding tools that meet those requirements" where the alternative route is open.[2]
Does the AMLR require liveness detection, NFC chip reading or biometrics?
No. The regulation has no article on selfie matching, liveness or biometrics.[1] The final draft names no technique and requires "controls" that the presenter is the document holder.[2] Liveness detection appears in the EBA guidelines.[5]
Are AMLA's customer due diligence standards already law?
No. AMLA sent its final draft to the Commission.[4] The Commission may amend it, and it becomes definitive only on publication in the Official Journal.[3] It would apply six months after entry into force, so no calendar date is fixed.[2]
Does an eID check finish customer due diligence?
No. An eID settles identity for the attributes it carries, and missing attributes must be verified by other means.[2] The other measures in Article 20(1) still apply: beneficial owners, purpose, sanctions checks and ongoing monitoring.[1]
Do the EBA remote onboarding guidelines still apply after July 2027?
Not settled on 2 October 2026. The AMLA Regulation keeps EBA guidelines applicable until AMLA instruments on the same subject apply,[6] and AMLA's tracker lists these guidelines among them.[7] No primary source says what happens once the current directive is repealed.[8]
Sources
- Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
- Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
- Factsheet on the RTS under Article 28(1) AMLR, AMLA, September 2026.
- AMLA finalises key standards for the private sector, AMLA press release, 1 October 2026.
- Guidelines on the use of remote customer onboarding solutions, EBA/GL/2022/15, European Banking Authority.
- Regulation (EU) 2024/1620 (AMLA Regulation), EUR-Lex, Article 54(5).
- Regulatory instruments tracker, AMLA, last update 30 September 2026.
- Directive (EU) 2024/1640 (AMLD6), EUR-Lex, Article 77.
The article by article map of requirements and checks is on the AMLR solution page.
Build your AMLR onboarding flow
Configure the verification routes your risk assessment calls for and keep the evidence behind every customer.
Related articles
- The EU's EUR 10,000 cash limit from July 2027: who it binds
- AMLR software: what to build, what to buy and what it costs
- AMLR and the EUDI Wallet: when you must accept it, and what is left
- AMLR for crypto: what crypto-asset service providers must verify
- AMLR checklist by obliged entity, with the article behind every line
- AMLR beneficial ownership: the 25% rule, control and worked examples