AMLR software: what to build, what to buy and what it costs
A vendor-neutral buyer's guide to AMLR software: the ten capabilities the regulation implies, what to buy and what to keep, 13 questions for any vendor, red flags in sales claims and a cost model with a worked example.

In short
AMLR software is not one product, and no tool can be certified for the regulation. The EU Anti-Money Laundering Regulation (AMLR) applies from 10 July 2027[1] and implies ten capabilities, from identity verification to audit evidence.
- Buy the commodity checks: document and electronic ID verification, registry data, screening lists.
- Keep your risk logic and the six tasks that can never be outsourced.[1]
- Estimate cost from four volumes: new customers, refreshes, monitored persons and reviewer time.
Search for AMLR compliance software and you get landing pages that promise one product for the whole regulation. In our scan of the results on 2 October 2026, none showed a price, and most vendor pages still described the technical standards as drafts.
This guide maps the regulation to capabilities, separates what is commodity from what is your own risk logic, gives a checklist for choosing an AMLR KYC (Know Your Customer) solution, and ends with a cost model. It is vendor-neutral until its last section.
The capability map AMLR software has to cover
The AMLR, Regulation (EU) 2024/1624, sets duties for obliged entities, the firms it binds. It prescribes no product: it asks that compliance functions have "adequate resources, including staff and technology" (Article 11(3)).[1] Read as a product brief, its customer due diligence (CDD) chapter and the articles around it imply ten capabilities.
| Obligation | Capability | Article |
|---|---|---|
| Verify identity by electronic identification (eID) | Connections to eID schemes at assurance level substantial or high | Art. 22(6)(b); draft RTS Art. 27 |
| Verify identity by document | Authenticity checks, a control that the presenter is the holder, time-stamped evidence | Art. 22(6)(a); draft RTS Arts. 6, 7 |
| Verify businesses and owners | Register data, an ownership tree at 25% or more, identity checks on owners | Arts. 22(1)(b), 22(7), 51, 52 |
| Screen for sanctions and politically exposed persons (PEPs) | Screening of the customer, owners and controllers, re-screening when lists change | Arts. 20(1)(d), 20(1)(g), 26(4); draft RTS Arts. 17, 25 |
| Keep customer information current | A review scheduler by risk class, plus event triggers | Art. 26(2), 26(3) |
| Monitor transactions | Rules, alerts, a record of each assessment | Arts. 26(1), 69(2) |
| Assess and report suspicions | Case management and report preparation for the financial intelligence unit (FIU) | Arts. 69, 77(1)(b) |
| Keep records, then delete | Evidence store, 5-year timers, deletion jobs | Art. 77 |
| Review automated decisions | Review queues, recorded reasons, an explanation the customer can challenge | Art. 76(5) |
| Audit evidence | An exportable per-case trail: inputs, checks, results, reviewer, timestamps | Arts. 20(4), 21(3), 18(5) |
Articles are those of Regulation (EU) 2024/1624.[1] "Draft RTS" is AMLA's final draft of 30 September 2026, not yet adopted.[2]
Article 22(6) names two means of verification: an identity document, or eID at assurance level substantial or high and qualified trust services.[1] AMLA, the EU Anti-Money Laundering Authority, has sent its final draft regulatory technical standards (RTS) on CDD to the Commission.[3] The draft is not adopted and not law. It says eID should be used wherever possible and treats remote document checks as an alternative the firm must justify.[2] A tool with one route covers half the job. See AMLR identity verification and AMLR beneficial ownership.
Buyers forget the last row. The AMLR has no single audit trail article; the duty comes from sentences like this one.
Article 20(4)Regulation (EU) 2024/1624
"Obliged entities shall at all times be able to demonstrate to their supervisors that the measures taken are appropriate in view of the risks of money laundering and terrorist financing that have been identified."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
Build vs buy, capability by capability
The honest split has three parts: commodity checks, engines you buy and rules you write, and tasks that are yours by law.
Buy
Commodity checks
- Document and eID verification
- Registry and screening data
Articles 20 and 22
Configure
Bought engine, your rules
- Customer risk scoring
- Transaction monitoring criteria
Article 18(4)
Keep
Yours by law
- The onboarding decision
- The report to the FIU
Article 18(3)
Article 18(3) lists six tasks that "shall not be outsourced under any circumstances": proposing and approving the business-wide risk assessment, approving internal policies, deciding the customer's risk profile, deciding to enter the relationship, reporting to the FIU (outside a narrow same-group exception), and approving the criteria that detect suspicious transactions.[1] Whatever you buy, the liability does not move.
Article 18(2)Regulation (EU) 2024/1624
"The obliged entity shall remain fully liable for any action, whether an act of commission or omission, connected to the outsourced tasks that are carried out by service providers."
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
| Capability | Verdict | Why |
|---|---|---|
| Document checks | Buy | Commodity. The cost is keeping up with document types and attack methods. |
| eID connections | Buy | One integration per national scheme. |
| Company register data | Buy | Many national sources of uneven quality. |
| Sanctions and PEP data | Buy the data, own the thresholds | How close a match must be is your risk appetite. |
| Risk scoring | Buy an engine, write the model | The tool proposes. The risk profile decision is yours (Art. 18(3)(c)). |
| Transaction monitoring | Buy an engine, approve the criteria | Approval of the criteria cannot be outsourced (Art. 18(3)(f)). |
| Cases and reports | Buy or build | A tool can draft the report. Filing it is yours (Art. 18(3)(e)). |
| Onboarding decision | Keep | Reserved to you (Art. 18(3)(d)), with human intervention when automated (Art. 76(5)). |
Article references are to the AMLR.[1] The verdicts are our view, not a legal classification.
Whether a purchase counts as outsourcing at all is a separate question. Recital 47 says that "the use or acquisition of third-party software or the access to databases or screening services by the obliged entity, are not considered to be outsourcing".[1] Where a provider performs the requirement itself, Article 18 attaches: notice to the supervisor before the provider starts, a written agreement and regular controls.[1] Where that line falls for an automated verification service is not yet known on 2 October 2026: AMLA's outsourcing guidelines are due by 10 July 2027.[1] See AMLR Article 18 outsourcing.
A reference architecture for remote onboarding
Each step writes to the evidence store.
1Detect the trigger
A new relationship, or a transaction at an Article 19 threshold.
2Collect the data set
Article 22(1) data. For a company, add owners at 25% or more.
Can the customer use an eID at substantial or high
Verify with eID
Collect any attribute that is missing.
Verify with a document
Record why, and keep time-stamped copies.
3Screen
Sanctions and PEP checks on the customer, owners and controllers.
4Score and decide
The tool proposes a risk rating. A person at your firm decides.
5Monitor and refresh
Re-screen when lists change. Review after 1 or 5 years at most.
6Store, then delete
Keep the evidence for 5 years after the relationship ends.
Article numbers refer to the AMLR.[1] The eID-first branch follows AMLA's final draft RTS, which is not yet adopted.[2]
Step 4 meets a legal limit. A firm may adopt decisions from automated processes, including AI systems, on this condition.[1]
Article 76(5)(b)Regulation (EU) 2024/1624
"any decision to enter or refuse to enter into or maintain a business relationship with a customer [...] is subject to meaningful human intervention to ensure the accuracy and appropriateness of such a decision"
Source: EUR-Lex, Regulation (EU) 2024/1624[1]
The same rule covers decisions to carry out a transaction or to change the extent of due diligence, and the customer may obtain an explanation and challenge the decision.[1] The tool needs a review queue, not only a score.
Thirteen questions to ask any vendor
The list also works for an internal build. For the duties by sector, see the AMLR checklist by obliged entity.
- List the eID schemes in production per country, with the assurance level of each.[1]
- Show both routes in one flow, with the reason for the document route recorded per case.[2]
- Explain how a missing attribute is collected when an eID or a passport carries no address.[2]
- State where data is stored, and where you and each sub-processor are established. Article 18(6) restricts providers in the third countries identified under Articles 29 to 31, not every non-EU provider.[1]
- Provide the outsourcing documents: written agreement, method description, change notices, control reports.[1]
- Confirm the flow follows our policies and procedures, not your defaults.[1]
- Send the full price list before any call: per check, per monitored person, minimums.
- Export one complete case file in a readable format.
- Set retention to 5 years from the end of the relationship or the refusal, then deletion.[1]
- Demonstrate the human review tooling: queues, a second approver, recorded reasons.
- Say what triggers a re-screen, and how soon after a sanctions list changes.[1][2]
- Give us a sandbox so we can time the integration ourselves.
- Describe the exit: every record exported, so our retention duty survives the contract.
What AMLR compliance software costs: a model you can run
With per-check pricing, annual cost follows four volumes.
| Cost line | Annual volume | Legal driver |
|---|---|---|
| Onboarding | New customers (N): one verification and one screening each | Arts. 19, 20, 22 |
| Refresh | Higher-risk customers (H) plus a fifth of all others (S / 5) | Art. 26(2) |
| Ongoing screening | Monitored persons (M): customers, beneficial owners, controllers | Art. 26(4) |
| Human review | Alerts and manual reviews, times the minutes each takes | Art. 76(5) |
Two cautions. The intervals of 1 year for higher-risk customers and 5 years for all others are maximums, and an update is also due when circumstances change, so S / 5 is a floor.[1] And Article 26 asks for updated information, not a new identity check each time. Budgeting one check per refresh gives an upper bound. Background: ongoing monitoring under Article 26.
Example
A firm has 20,000 customers, 10% of them higher risk, and onboards 5,000 new ones a year. Onboarding: 5,000 verifications and 5,000 screenings. Refresh: 2,000 higher-risk reviews plus 18,000 / 5 = 3,600 others, so 5,600. Ongoing screening: 25,000 persons. Multiply each volume by its unit price, add reviewer time, and ask every vendor to price the same volumes in writing.
Red flags in vendor claims
Each claim fails against the text.
| Claim | What the texts say |
|---|---|
| "Certified for the AMLR" or "AMLA approved" | A provider's duties "arise only from the contract"; the AMLR creates no certification for tools.[1] AMLA "does not issue any documents or certificates" to companies.[4] |
| "Only these methods are compliant" | Article 22(6) names two means.[1] Under the final draft, firms "may continue using existing remote onboarding tools" that meet its safeguards. It names no technique: no liveness, chip reading or video.[2] |
| "The standards are still in consultation" | Out of date. The consultation closed on 8 May 2026; the final report is dated 30 September 2026.[2] The opposite claim fails too: the Commission has not adopted them.[3] |
| "We take on your liability" | The obliged entity "shall remain fully liable" (Art. 18(2)).[1] |
| "A wallet check finishes due diligence" | eID covers identity. Ownership, screening and monitoring remain (Art. 20(1)).[1] |
AMLA proposes that the standards apply six months after their entry into force,[3] so no start date exists yet. More in AMLA's final CDD standards and AMLR and the EUDI Wallet.
How Didit helps you cover the map
Didit supplies the bought half of the map in one workflow, priced per check. The AMLR solution page maps each check to its article, and the AMLR guide in the docs shows the setup.
Checks. Identity verification runs by document, with chip reading, liveness and face match, or by digital ID wallet: MitID, the Finnish Trust Network, Smart-ID, Mobile-ID and BankID Sweden are in production. EU Digital Identity (EUDI) Wallet support is coming soon. Business verification returns registry data and links an identity check to each owner. Anti-money laundering (AML) screening covers 1,300+ sanctions, PEP and watchlists refreshed daily, and ongoing monitoring re-screens daily. Transaction monitoring runs real-time rules and prepares the FIU report, which you file.
Controls. A no-code workflow builder carries your policy, with manual review and four-eyes approval. Session records keep the retention you set, from 1 month to 10 years, in the EU by default. See security and compliance.
Cost. Three public prices cover the example above: a full KYC check at $0.33, AML screening at $0.20 and ongoing monitoring at $0.07 per person per year.
| Line | Volume | Unit price | Per year |
|---|---|---|---|
| Onboarding KYC checks | 5,000 | $0.33 | $1,650 |
| Onboarding AML screening | 5,000 | $0.20 | $1,000 |
| Refresh KYC checks, upper bound | 5,600 | $0.33 | $1,848 |
| Ongoing monitoring | 25,000 | $0.07 | $1,750 |
| Total | $6,248 |
That excludes business verification, transaction monitoring and your review time. Every other price is on the pricing page, and you can start free.
Didit provides
- Identity checks by digital ID wallet or by document
- Business verification, screening and daily re-screening
- The monitoring engine and report preparation
- A session record for every check
Stays with you
- The risk assessment and the policies
- The risk profile and the onboarding decision
- The monitoring criteria and the report to the FIU
- The liability: you "shall remain fully liable"[1]
Price your own AMLR volumes
Set up both verification routes, screening and monitoring in one workflow, and pay per check.
Key takeaways
- The AMLR implies ten capabilities, and no tool can be certified for it.
- Buy the commodity checks. Keep the risk model, the detection criteria and the decisions.
- A tool needs both routes: eID, and document verification with a recorded reason.
- AMLA's CDD standards are a final draft: neither in consultation nor law.
Frequently asked questions
Do I need new software to comply with the AMLR?
The AMLR requires outcomes, not a product. Article 11(3) asks for adequate resources, including staff and technology. Your current tooling is enough if it covers both verification routes, screening, the refresh schedule and the evidence trail.
Can software be certified for the AMLR?
No. The AMLR creates no certification, licence or approval for vendors or tools, and AMLA states that it does not issue certificates to companies. Compliance is a property of the obliged entity's programme, not of a product.
Is buying KYC software outsourcing under Article 18?
It depends on who performs the requirement. Recital 47 says that using third-party software, databases or screening services is not outsourcing when the obliged entity performs the requirement itself. Where the provider performs it, Article 18 applies. Where an automated verification service falls is not settled; AMLA's outsourcing guidelines are due by 10 July 2027.
Does my vendor need to offer electronic ID, or is document verification enough?
Plan for both. Article 22(6) accepts an identity document, or electronic identification at assurance level substantial or high. AMLA's final draft standards of 30 September 2026, not yet adopted, say electronic identification should be used wherever possible and treat remote document verification as an alternative the firm must justify.
How much does AMLR software cost per year?
Multiply four volumes by their unit prices: new customers, refreshes (every higher-risk customer plus at least a fifth of the others), persons under ongoing screening, and reviewer time. In this article's example, 20,000 customers plus 5,000 new ones a year mean 5,000 onboarding checks, 5,600 refreshes and 25,000 monitored persons.
Should I wait for AMLA's technical standards before choosing a tool?
No. The AMLR applies from 10 July 2027. The CDD standards are a final draft that AMLA sent to the Commission, proposed to apply six months after their entry into force, so their start date is not yet known. Choose tooling that covers both verification routes.
Can onboarding decisions be fully automated under the AMLR?
Not fully. Article 76(5) allows decisions from automated processes and AI systems, provided that any decision to accept, refuse or end a relationship is subject to meaningful human intervention. The decision to onboard also cannot be outsourced.
How long must KYC records be kept, and where?
For 5 years from the end of the business relationship, the occasional transaction or the refusal. Then personal data must be deleted, unless another law applies or an authority extends the period by up to 5 more years. The AMLR does not say where records must sit, but supervisors must be able to retrace your compliance.
Sources
- Regulation (EU) 2024/1624 (AMLR), EUR-Lex, Official Journal of 19 June 2024.
- Final Report, draft RTS under Article 28(1) AMLR, AMLA, 30 September 2026.
- AMLA finalises key standards for the private sector, AMLA press release, 1 October 2026.
- Frequently asked questions, AMLA.
The article by article map is on the AMLR solution page. Confirm your reading with counsel.
Build the bought half of your AMLR stack
Configure the checks your risk assessment calls for and keep the evidence of each one.
Related articles
- The EU's EUR 10,000 cash limit from July 2027: who it binds
- AMLR identity verification: eID first, documents as the alternative
- AMLR and the EUDI Wallet: when you must accept it, and what is left
- AMLR for crypto: what crypto-asset service providers must verify
- AMLR checklist by obliged entity, with the article behind every line
- AMLR beneficial ownership: the 25% rule, control and worked examples