Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
AMLR · EU AML Regulation

Meet AMLR customer checks
before 10 July 2027.

The EU Anti-Money Laundering Regulation (AMLR) applies from 10 July 2027. Verify people by electronic ID or by document, find the owners, screen them and keep the evidence, in one workflow. A full know your customer (KYC) check costs $0.33.

Backed by
Y CombinatorRobinhood Ventures
Firecrawl
Slash
Crnogorski Telekom
UCSF Neuroscape
Bit2Me

Trusted by 3,000+ organizations worldwide.

What AMLR asks of you

One EU rulebook.
Five duties.

From 10 July 2027, every obliged entity in the EU will follow one set of customer due diligence (CDD) rules. Didit runs the checks and returns the evidence. You keep the decisions and the liability.

  1. 01Identify and verify each customer (Article 22)
  2. 02Find the beneficial owners (Articles 51 to 62)
  3. 03Screen for sanctions and politically exposed persons (Article 20)
  4. 04Keep watching the relationship (Article 26)
  5. 05Keep the evidence for five years (Article 77)
How it works

From AMLR policy to a verified customer in four steps.

Step 01 / 04

Create the workflow

Pick the checks your risk policy calls for in the no-code builder: electronic ID or document verification, liveness, face match, screening and questionnaires. You approve the policy. The workflow applies it.

Customer due diligence · Six checks

Every AMLR customer check, in one workflow.

Each row answers a group of AMLR articles. Didit runs the check and returns the evidence. Your team keeps the decisions that Article 18 says cannot be outsourced.
01 · Identify and verify

Verify people by electronic ID or by document.

Article 22(6) names two routes: electronic identification under eIDAS, or an identity document. Didit runs both. Five digital ID wallets are live: MitID, Finnish Trust Network, Smart-ID, Mobile-ID and BankID Sweden. The EU Digital Identity (EUDI) Wallet is coming soon. Document checks cover 14,000+ document types, with chip reading, liveness and face match.
See digital ID wallets
02 · Businesses and owners

Find the owners behind every company.

Pull company registry data, including shareholders and ultimate beneficial owners (UBOs) where the registry holds them. AMLR sets the ownership test at 25% or more, with control assessed in parallel (Articles 51 to 53). A register entry alone does not finish verification, so each owner or officer gets a linked identity check and screening.
See Business Verification
03 · Sanctions and PEPs

Screen customers, owners and controllers.

Check each customer and beneficial owner against 1,300+ sanctions, politically exposed person (PEP) and watchlists, refreshed daily. PEP results cover family members and close associates, as Articles 20 and 46 expect. Your reviewer confirms or dismisses each match. Screening costs $0.20 per check.
See AML Screening
04 · Monitoring and refresh

Re-screen every day. Refresh on schedule.

Article 26 caps the gap between updates of customer information at 1 year for higher-risk customers and 5 years for everyone else, with event triggers on top. Didit re-screens approved customers daily, sends an alert by webhook when something changes and records each run, for $0.07 per person per year. You set the refresh dates.
See ongoing monitoring
05 · Transactions and cases

Monitor transactions and work the cases.

Apply real-time rules to fiat and crypto transactions, starting from 11 rule bundles. An alert opens a case with the evidence attached, and Didit prepares the report for your financial intelligence unit (FIU). Under Article 18, you approve the detection criteria and you file the report.
See Transaction Monitoring
06 · Records and evidence

Keep the evidence for five years, then delete it.

Article 77 will require due diligence records for 5 years after the relationship ends, then deletion. Set session retention from 1 month to 10 years and delete on demand. Manual review and four-eyes approval support the human intervention that Article 76(5) requires for automated decisions. Data is stored in the EU by default.
See security and compliance
AMLR timeline

In force since 2024. Applies from 10 July 2027.

AMLR is already law, but it does not bind obliged entities yet. These are the dates to plan around.
  1. 19 June 2024

    Published

    Regulation (EU) 2024/1624 appears in the Official Journal of the EU.

  2. 9 July 2024

    In force

    AMLR enters into force. It does not apply to obliged entities yet.

  3. 1 July 2025

    AMLA starts

    The Anti-Money Laundering Authority (AMLA), based in Frankfurt, starts operations.

  4. 1 October 2026

    Final draft standards

    AMLA announces its final draft technical standards on customer due diligence, dated 30 September 2026, and sends them to the European Commission. They are a final draft, not law.

  5. 10 July 2027

    AMLR applies

    The rules bind obliged entities across the EU. The EUR 10,000 cap on cash payments for people trading in goods or providing services starts on the same day.

  6. 2028

    AMLA direct supervision

    AMLA starts to supervise selected high-risk financial institutions directly, capped at 40 in the first round.

  7. 10 July 2029

    Football

    AMLR starts to apply to football agents and professional football clubs.

Article by article

What AMLR asks, what Didit provides, what stays with you.

Didit supplies checks and evidence. It does not make you compliant, and the obliged entity remains fully liable under Article 18.

Art. 19

When due diligence applies

AMLR asks

Customer due diligence on every new business relationship and on occasional transactions of EUR 10,000 or more. Lower triggers: EUR 1,000 for transfers of funds and for crypto-asset service providers (CASPs), EUR 3,000 in cash (identify and verify), EUR 2,000 in gambling.

Didit provides

Sessions by API or hosted link, started from your own triggers. Transaction monitoring rules that flag amounts and patterns.

Stays with you

Deciding when a threshold is met and which transactions are linked.

Art. 22

Identification and verification

AMLR asks

A fixed set of data for each person (names, place and date of birth, nationalities, address) and for each legal entity, all of it verified.

Didit provides

Document capture for 14,000+ document types, chip reading for e-passports and e-IDs, passive and active liveness, face match and non-document lookup.

Stays with you

Choosing a second reliable source when a document lacks a data point, such as an address.

Art. 22(6)

Electronic identification route

AMLR asks

Verification through an identity document, or through electronic identification at eIDAS assurance level substantial or high and qualified trust services.

Didit provides

Five digital ID wallets live: MitID, Finnish Trust Network, Smart-ID, Mobile-ID and BankID Sweden. EUDI Wallet coming soon.

Stays with you

Confirming that each scheme meets the assurance level you need, and recording why you used the document route when you did, which AMLA’s final draft standards would ask for.

Arts. 22(7), 24, 51 to 55 and 62

Beneficial ownership

AMLR asks

Identify every natural person who holds 25% or more, directly or indirectly, and anyone who controls the entity by other means. Consult the central register and report discrepancies within 14 calendar days (Article 24).

Didit provides

Company registry data in three tiers (Lite, Shareholders, UBOs), a linked identity check for each owner or officer, and company and person screening.

Stays with you

Assessing control by other means, consulting the central register and reporting discrepancies. Tier availability varies by country.

Art. 25

Purpose and source of funds

AMLR asks

Understand the purpose and intended nature of the relationship and, where necessary, the source of funds.

Didit provides

Questionnaires with templates for source of funds and purpose of the relationship.

Stays with you

Deciding how much information each level of risk needs.

Art. 26

Ongoing monitoring and updates

AMLR asks

Monitor the relationship and update customer information at least every 1 year for higher-risk customers and every 5 years for all others, plus event triggers.

Didit provides

Daily re-screening with alerts by webhook and a record of each run, for $0.07 per person per year. New sessions when a refresh is due.

Stays with you

Setting each customer’s risk class and review date.

Arts. 20(1)(g) and 42 to 46

Politically exposed persons (PEPs)

AMLR asks

Determine whether the customer or a beneficial owner is a PEP, a family member or a close associate. Apply senior management approval, source of wealth and source of funds checks and enhanced monitoring. Risk measures continue for at least 12 months after the person leaves office.

Didit provides

PEP screening that covers family members and close associates, questionnaires, manual review and four-eyes approval.

Stays with you

Senior management approval and the enhanced measures you choose.

Arts. 20(1)(d) and 26(4)

Sanctions screening

AMLR asks

Check customers, beneficial owners and controlling persons against EU targeted financial sanctions, and check again regularly.

Didit provides

Screening against 1,300+ sanctions, PEP and watchlists, refreshed daily, for $0.20 per check. Daily re-screening with ongoing monitoring.

Stays with you

Reviewing each match and acting on a confirmed one.

Arts. 26(1) and 69

Transactions and reporting

AMLR asks

Monitor transactions against what you know about the customer, and report suspicions to the financial intelligence unit (FIU).

Didit provides

Real-time rules for fiat and crypto, 11 rule bundles, alerts, case management and report preparation.

Stays with you

Approving the detection criteria and filing the report.

Art. 18

Outsourcing

AMLR asks

Outsourcing is allowed with a written agreement, notification to your supervisor before the provider starts, and regular controls. You remain fully liable.

Didit provides

The checks, the evidence behind each result and exportable records for your controls.

Stays with you

Six tasks that can never be outsourced: approving the business-wide risk assessment, approving policies and controls, deciding the customer’s risk profile, deciding to onboard, reporting to the FIU and approving detection criteria.

Art. 77

Records

AMLR asks

Keep due diligence records, unredacted, for 5 years after the relationship or transaction ends. Then delete the personal data.

Didit provides

Session records with retention you set from 1 month to 10 years, deletion on demand and EU storage by default.

Stays with you

The retention duty itself, and any extension an authority requires.

Art. 76(5)

Human intervention

AMLR asks

Automated decisions to accept or refuse a customer, or to change the level of due diligence, need meaningful human intervention. The customer can ask for an explanation.

Didit provides

Manual review queues, four-eyes approval and the evidence behind every automated result.

Stays with you

The human decision and the explanation to your customer.

Last reviewed: 2 October 2026. Not legal advice. Confirm your obligations with counsel. AMLR applies from 10 July 2027, and AMLA’s technical standards are a final draft dated 30 September 2026, not law.

Integrate

Start a check. Receive the evidence.

Create a session for the customer, then receive a signed webhook when the status changes. Your system keeps the onboarding decision.
POST /v3/session/Start the check
$ curl -X POST https://verification.didit.me/v3/session/ \
  -H "x-api-key: $DIDIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "workflow_id": "YOUR_AMLR_WORKFLOW_UUID",
    "vendor_data": "customer_8412"
  }'
201Created{ "url": "https://verify.didit.me/session/…" }
One session per customer. Your own reference comes back with every result.docs
POST /webhooks/diditYour endpoint
app.post("/webhooks/didit", async (req, res) => {
  const expected = crypto.createHmac("sha256", process.env.DIDIT_WEBHOOK_SECRET)
    .update(req.rawBody).digest();
  const sig = Buffer.from(req.get("X-Signature") ?? "", "hex");
  if (sig.length !== expected.length ||
      !crypto.timingSafeEqual(sig, expected)) return res.sendStatus(401);

  const { event_id, timestamp, webhook_type, vendor_data, status } = req.body;
  const fresh = Math.abs(Date.now() / 1000 - timestamp) <= 300; // signed field
  if (!fresh) return res.sendStatus(401);
  if (webhook_type === "status.updated" || webhook_type === "data.updated") {
    // event_id repeats on retries: store each event once (unique key).
    if (await alreadyStored(event_id)) return res.sendStatus(200);
    await saveEvidence(event_id, vendor_data, req.body);   // your record
    if (status === "In Review") queueForReviewer(vendor_data);
    // "Approved" and "Declined" are results. You decide to onboard.
  }
  res.sendStatus(200);
});
200OKOK
Verify the signature first. A status of In Review goes to your reviewer.docs
Agent-ready integration

Ship AMLR customer checks in one prompt.

Copy this prompt into your coding agent and describe your stack. It covers the workflow, the session call, the signed webhook, screening, monitoring and retention. Your compliance team keeps the decisions.
didit-integration-prompt.md
# Integrate Didit for AMLR customer due diligence

Integrate Didit into <my_stack> to run the customer checks that the EU
Anti-Money Laundering Regulation (AMLR, Regulation (EU) 2024/1624) will
require from 10 July 2027. Didit supplies the checks and the evidence. The
obliged entity keeps every decision and stays fully liable (Article 18).
This prompt is not legal advice.

## What stays with the obliged entity (never automate these away)
Article 18(3) lists six tasks that cannot be outsourced:
- proposing and approving the business-wide risk assessment
- approving internal policies, procedures and controls
- deciding the risk profile of a customer
- deciding to enter a business relationship or carry out a transaction
- reporting to the financial intelligence unit (FIU)
- approving the criteria for detecting suspicious transactions
Build the integration so that a named person takes each of these decisions.
Article 76(5) also requires meaningful human intervention on automated
decisions to accept or refuse a customer.

## Published prices used below
- Full KYC (know your customer) check: $0.33
- AML (anti-money laundering) screening: $0.20 per check
- Ongoing AML monitoring: $0.07 per person per year
For every other module, read https://didit.me/pricing. Do not invent a price.

## 1. Create the applications and the workflow
Create an account at https://business.didit.me. Live and sandbox are separate
applications. Sandbox outcomes are simulated. Store the application keys and
workflow UUIDs in server-side configuration. Never expose a key to a browser.

Build the workflow in the Console, or with
POST https://verification.didit.me/v3/workflows/.
Map the checks to the regulation:
- Identification and verification (Article 22): either a digital ID wallet
  (the electronic identification route of Article 22(6)(b)) or ID
  Verification with chip reading, liveness and face match (the document
  route of Article 22(6)(a)). Which route a customer takes is the obliged
  entity's policy. Record the route and the reason in your own system.
- Sanctions and PEP (politically exposed person) screening (Article 20):
  add AML Screening.
- Purpose and source of funds (Article 25): add a Questionnaire.
- Companies and beneficial owners (Articles 51 to 62): use a KYB (know your
  business) workflow and start a linked identity session for each owner.
  The AMLR ownership test is 25% or more, with control assessed in parallel.
  Registry tiers vary by country, and a register alone is not sufficient
  verification.
Publish the draft. Existing sessions keep the workflow version they started
with.

## 2. Create a session for each customer

  curl -X POST https://verification.didit.me/v3/session/ \
    -H "x-api-key: <application-key>" \
    -H "Content-Type: application/json" \
    -d '{
      "workflow_id": "<workflow-uuid>",
      "vendor_data": "<your-customer-id>"
    }'

The response contains "url". Redirect the customer to it, or embed the hosted
flow. vendor_data is your own stable reference and is returned on session
events. Within one application only one unfinished session can exist per
(workflow_id, vendor_data) pair.

## 3. Receive authenticated results
Register a webhook destination for status.updated and data.updated and store
its secret_shared_key on the server.
Verify before reading a result or changing a customer's data:
- X-Signature-V2: HMAC-SHA256 over recursively sorted, compact JSON with
  Unicode preserved. This header does not sign raw bytes.
- X-Signature: HMAC-SHA256 over the exact raw request bytes, captured before
  any JSON middleware.
- Check the signature format and length before a constant-time comparison.
- Validate X-Timestamp and reject a difference greater than 300 seconds.
  Require it to match the timestamp in the authenticated payload. The header
  is not signed, so a header checked alone can be replaced on a replay.
- Make processing idempotent before any side effect: a retry reuses the same
  event_id, so key on event_id and skip an event you have already stored.
  Durably queue the work before acknowledging.

Session statuses: Approved, Declined, In Review, In Progress, Not Started,
Abandoned, Expired, Kyc Expired, Resubmitted, Awaiting User.
- "Approved" and "Declined" are verification results, not onboarding
  decisions. Store the result, then let the obliged entity's own process
  decide.
- "In Review" goes to a human reviewer.
For reconciliation read
GET https://verification.didit.me/v3/session/{sessionId}/decision/.

## 4. Keep watching (Article 26)
Enable ongoing AML monitoring for approved customers. Didit re-screens daily
and re-screens fire the usual status.updated and data.updated events.
Store a risk class and a next review date for each customer in your own
system. Article 26(2) caps the interval between updates of customer
information at 1 year for higher-risk customers and 5 years for all others,
with event triggers on top. When a review is due, create a new session.

## 5. Keep the record (Article 77)
Records are kept for 5 years from the end of the business relationship, the
occasional transaction or the refusal, and personal data is then deleted
unless another law or an authority requires otherwise.
- Set retention in Business Console -> App Settings -> Data (1 month to 10
  years). The clock that matters starts when the relationship ends, so either
  size the window for that or export the evidence into the obliged entity's
  own archive.
- Delete a session on demand with
  DELETE https://verification.didit.me/v3/session/{session_id}/delete/.
Store the session id, the status, the workflow version, the route used and
the name of the person who took the onboarding decision.

## 6. Verify the integration
1. In the sandbox application, run one customer through the wallet route and
   one through the document route. Confirm both write the same record shape.
2. Send a webhook with a wrong signature and confirm it is rejected with 401.
3. Confirm an "In Review" result reaches a reviewer and that no code path
   onboards a customer without a recorded human decision.
4. Confirm sandbox and live traffic use separate applications.

Docs: https://docs.didit.me/getting-started/amlr-compliance
Compliant by design

Open a new country in one click. We do the hard work.

We open the local subsidiaries, secure the licenses, run the penetration tests, earn the certifications, and align with every new regulation. To ship verifications in a new country, flip a toggle. 220+ countries live, audited and pen-tested every quarter, the only identity provider an EU member-state government has formally called safer than in-person verification.
Read the security & compliance dossier
SOC 2 · Type II — AICPA · 2026
SOC 2 · Type I — AICPA · 2026
ISO/IEC 27001 — Information security · 2026
EU financial sandbox — Tesoro · SEPBLAC · BdE
FIDO Alliance — Associate member · 2026
iBeta Level 1 PAD — NIST / NIAP · 2026
GDPR — EU 2016/679
HIPAA — 45 CFR §160 · §164
DORA — EU 2022/2554
MiCA — EU 2023/1114
EBA remote onboarding — EBA/GL/2022/15
AMLD6 · eIDAS 2.0 — EU-aligned by design
Jugendschutz geprüft — FSM · JMStV §4(2) · 2026

Proof numbers

Proof numbers
  • 3,000+
    Companies in production
  • 220+
    Countries and territories covered
  • 1,300+
    Sanctions, PEP and watchlists
  • 14,000+
    Document types supported
Three tiers, one price list

Start free. Pay as you go. Scale to Enterprise.

500 free verifications every month, forever. Then pay only when a module runs. Custom contracts, data residency, and service level agreements (SLAs) on Enterprise.

Free

$0/ month · no card

For building, testing, and your first users.

Everything you need to start:
  • 500 full KYC verifications every month
  • ID, liveness, face match, device & IP
  • 200+ fraud signals, blocklist, duplicates
  • Reusable KYC across the Didit network
  • Workflow builder, case management, SDKs
  • AI support In-console AI agent, docs, and community.
Most popular

Pay as you go

$0.33per full KYC

25+ modules, publicly priced. Automatic volume discounts.

Everything in Free, plus:
  • AML screening and monitoring from $0.07
  • Business registry pricing by country and data tier
  • Transaction monitoring at $0.02 each
  • Wallet screening at $0.15 per check
  • White-label flow under your own brand
  • AI support In-console AI agent, docs, and community.

Enterprise

Customannual contract

For large volumes and regulated programs.

Everything in Pay as you go, plus:
  • Annual contracts, committed-volume pricing
  • Custom legal terms and a 99.99% uptime SLA
  • Data residency, retention, security review
  • Manual reviewers on demand
  • Reseller and white-label terms
  • Priority human support 24/7 shared Slack channel, named success manager.

Volume discounts apply automatically as usage grows — no negotiation, no sales call.

FAQ

AMLR questions, answered

Last reviewed: 2 October 2026. Not legal advice. Confirm your obligations with counsel. AMLR applies from 10 July 2027, and AMLA’s technical standards are a final draft dated 30 September 2026, not law.
What is Didit?

Didit is infrastructure for identity and fraud, the platform we wished existed when we were building products ourselves: open, flexible, and developer-friendly, so it works as a real part of your stack instead of a black box you integrate around.

One API covers verifying people (KYC, know your customer), verifying businesses (KYB, know your business), screening crypto wallets (KYT, know your transaction), and monitoring transactions in real time, on a stack built to be:

  • Fast, sub-2-second p99 on every session
  • Reliable, in production with 3,000+ companies across 220+ countries
  • Secure, SOC 2 Type 1 & Type 2, ISO 27001, GDPR-native, and formally attested by Spain's financial regulator as safer than verifying someone in person

The footprint underneath: 14,000+ document types in 48+ languages, 1,000+ data sources, and 200+ fraud signals on every session. The Didit infrastructure dynamically learns from every session and gets better every day.

What is AMLR, in one sentence, and when does it apply?

AMLR is Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation: one directly applicable set of rules on customer due diligence, beneficial ownership, reporting and record keeping for every obliged entity in the EU.

The dates that matter:

  • 19 June 2024: published in the Official Journal
  • 9 July 2024: entered into force
  • 10 July 2027: applies to obliged entities (Article 90)
  • 10 July 2029: applies to football agents and professional football clubs

Until 10 July 2027, the national laws that transpose the earlier directives still apply. Because AMLR is a regulation, it needs no national transposition, although Member States keep some options, such as lower cash limits.

Didit helps you meet the customer checks. A full know your customer (KYC) check costs $0.33, and sanctions and politically exposed person (PEP) screening costs $0.20 per check.

Last reviewed: 2 October 2026. This is not legal advice. Confirm with counsel.

What is the difference between AMLR, AMLD6 and AMLA?

They are three parts of the same 2024 package:

  • AMLR, Regulation (EU) 2024/1624: the rules for businesses. It applies directly from 10 July 2027.
  • AMLD6, Directive (EU) 2024/1640: addressed to Member States. It covers supervisors, financial intelligence units (FIUs), registers and penalties, and must be transposed by 10 July 2027.
  • AMLA, the Anti-Money Laundering Authority, created by Regulation (EU) 2024/1620 and based in Frankfurt. It drafts the technical standards and, from 2028, directly supervises a selected group of high-risk financial institutions, capped at 40 in the first round.

One trap: Directive (EU) 2018/1673, on combating money laundering by criminal law, is a different act. Give the number when it matters.

AMLA does not certify or approve vendors, and AMLR creates no vendor licence. Didit supplies the checks and the evidence, for example identity verification across 14,000+ document types and screening against 1,300+ lists. Your own programme is what a supervisor assesses.

Who is an obliged entity under AMLR?

Article 3 lists them. The main groups:

  • Credit institutions and financial institutions, which include investment firms, life insurers, currency exchange offices and crypto-asset service providers (CASPs)
  • Auditors, external accountants and tax advisors, plus notaries and lawyers for certain transactions
  • Trust or company service providers and estate agents, including lettings from EUR 10,000 a month
  • Traders in precious metals and stones and in high-value goods, such as jewellery and watches above EUR 10,000
  • Gambling providers, crowdfunding service providers, credit intermediaries and investment migration operators
  • Football agents and professional football clubs, from 10 July 2029

Member States can exempt some gambling services and some football clubs where the risk is proven to be low.

Whatever the category, the customer checks have the same shape, and Didit runs them in one workflow: identity checks in 220+ countries and territories, and business verification with an identity check for each owner.

If you are not sure whether you are in scope, ask counsel. This is not legal advice.

Is remote onboarding with a document and a selfie still allowed?

Yes, on the texts as they stand, but it is not the first choice.

What the regulation says. Article 22(6) names two ways to verify identity: an identity document, or electronic identification at eIDAS assurance level substantial or high, with qualified trust services. AMLR names no technique. The words “selfie”, “liveness” and “biometric” do not appear in it.

What the draft standards say. AMLA’s final draft technical standards, dated 30 September 2026, treat electronic ID as the default remote route. Remote document-based verification is an alternative for customers who cannot reasonably present the document in person and have no access to a qualifying electronic ID. You must be able to justify using it and show safeguards. AMLA also says firms may keep using existing remote onboarding tools that meet those requirements. This is a final draft sent to the European Commission. It is not law.

Where Didit fits. Didit runs both routes: five digital ID wallets live in production, and document verification with chip reading, liveness and face match.

Are AMLA’s technical standards final, and when do they apply?

Not yet. AMLA finished its final draft regulatory technical standards (RTS) on customer due diligence on 30 September 2026 and announced them on 1 October 2026. They have been sent to the European Commission.

Three things follow:

  • They are not law. They bind only after the Commission adopts them and they are published in the Official Journal, and the Commission may still amend them.
  • There is no calendar date. The draft proposes that the standards apply six months after they enter into force, so the start date depends on adoption.
  • Guidelines are still open. AMLA consulted on its guidelines on ongoing monitoring and on business-wide risk assessment in 2026. They are not final.

AMLR itself is fixed: it applies from 10 July 2027.

What to do now: build to the regulation and keep the workflow easy to change. In Didit’s no-code builder you can add or remove a check, or move customers from the document route to a digital ID wallet, without a redeploy. Each session records the workflow version it ran on, so you can show which rules applied.

Do we have to accept the EU Digital Identity Wallet?

AMLR does not say so. The acceptance duty sits in the eIDAS Regulation, not in AMLR.

  • eIDAS, Article 5f(2). Private companies that must use strong user authentication for online identification will have to accept the EU Digital Identity (EUDI) Wallet when the user asks, no later than 36 months after the wallet implementing acts entered into force. Micro and small enterprises are exempt.
  • AMLR, Article 22(6). Electronic identification at assurance level substantial or high is one of the two ways to verify identity. AMLA’s final draft standards (30 September 2026, not law) say it should be used wherever possible and confirm that EUDI Wallets qualify.

A wallet does not finish due diligence either. Beneficial ownership, purpose, sanctions and PEP screening, and monitoring remain.

Didit today: five digital ID wallets are live in production: MitID (Denmark), Finnish Trust Network, Smart-ID (Estonia, Latvia, Lithuania, Belgium), Mobile-ID (Estonia, Lithuania) and BankID Sweden. The EUDI Wallet is coming soon. Document verification covers customers who have no wallet.

Is the beneficial ownership threshold 25% or 15%?

25% or more. Article 52(1) sets the ownership test at 25% or more of the shares, voting rights or other ownership interest, held directly or indirectly. The wording is 25% or more, not more than 25%.

Three points that are often missed:

  • Indirect ownership is calculated. You multiply the stakes down each chain and add the chains together.
  • Control is tested in parallel. A person can be a beneficial owner through control by other means, such as the right to appoint most of the board, whatever their stake (Articles 51 and 53).
  • 15% is only a possibility. Article 52(2) lets the Commission set a lower threshold, at most 15%, for higher-risk categories of entities. No such act exists.

If no beneficial owner is found, you record that and verify the senior managing officials instead. The central register must be consulted, but it is not enough on its own, and discrepancies are reported within 14 calendar days.

Didit’s Business Verification returns company registry data in three tiers (Lite, Shareholders, UBOs) and links an identity check to each owner or officer. Tier availability varies by country.

How often must customer information be refreshed?

Article 26(2) sets maximum intervals between updates of customer information:

  • 1 year for higher-risk customers
  • 5 years for all other customers

These are ceilings, not targets. Article 26(3) adds event triggers: a change in the customer’s circumstances, a legal duty to contact the customer during the year, or a relevant fact you become aware of. AMLA has said these periods cannot be extended through technical standards.

Sanctions are separate. Article 26(4) asks you to check regularly whether customers and beneficial owners are subject to targeted financial sanctions. Credit and financial institutions must also check on any new designation.

How Didit helps:

  • Ongoing monitoring re-screens approved customers daily against 1,300+ lists, sends an alert by webhook when something changes and records each run, for $0.07 per person per year.
  • Refresh sessions re-run the identity checks on the schedule your policy sets.

You decide each customer’s risk class and review date. Didit does not make that decision for you.

What can we outsource to Didit under Article 18, and what stays with us?

Article 18 lets obliged entities outsource tasks to service providers on conditions that include a written agreement, notification to your supervisor before the provider starts, and regular controls. You remain fully liable for the outsourced tasks.

Six tasks can never be outsourced (Article 18(3)):

  • Proposing and approving the business-wide risk assessment
  • Approving internal policies, procedures and controls
  • Deciding the customer’s risk profile
  • Deciding to enter a business relationship or carry out a transaction
  • Reporting to the financial intelligence unit (FIU)
  • Approving the criteria for detecting suspicious transactions

What Didit can run for you: identity and document checks, digital ID wallet verification, registry look-ups and owner checks, sanctions and PEP screening, daily re-screening, transaction monitoring against rules you approved, and report preparation.

Recital 47 adds that using third-party software or screening services, where your own staff perform the requirement, is not outsourcing. Which side of that line your setup falls on is a question for counsel. AMLA’s outsourcing guidelines are due by 10 July 2027.

How long must records be kept, and how does Didit handle retention and deletion?

Five years. Article 77 will require you to keep customer due diligence records, transaction records and suspicion assessments for 5 years from the end of the business relationship, the occasional transaction or the refusal to onboard. Records must not be redacted. When the 5 years end, personal data must be deleted, unless another law applies or an authority asks for up to 5 more years in a specific case.

The duty is yours. A provider can store the records, but the obligation does not move.

How Didit handles it:

  • Retention you set, from 1 month to 10 years, so session records can match the 5-year rule
  • Deletion on demand, in the console or by API
  • EU storage by default, with in-country processing on Enterprise
  • Human review: manual review and four-eyes approval support the meaningful human intervention that Article 76(5) requires for automated decisions

One caution: the 5 years start when the relationship ends, not when the check ran. Set the retention window with that in mind, or export the records into your own archive.

What does it cost, and how fast can we go live?

You pay per check, at published prices:

  • $0.33 for a full know your customer (KYC) check
  • $0.20 per sanctions and PEP screening check
  • $0.07 per person per year for ongoing monitoring

Business verification, digital ID wallets and transaction monitoring are priced per use too. See pricing for every module.

Going live is a short path:

  • Create an account and build the workflow in the no-code builder
  • Test it in a sandbox application
  • Create sessions by API, or share a hosted link
  • Receive results by signed webhook

The integration is one API call and one webhook. How long the rollout takes depends on your own policies and approvals, which stay with you under Article 18.

Start free at business.didit.me, or talk to us through the contact page.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page