免费
适用于构建、测试和您的首批用户。
- 每月500次完整KYC验证
- 身份、活体、人脸匹配、设备和IP验证
- 200+欺诈信号、黑名单、重复项检测
- Didit网络内可复用KYC
- 工作流构建器、案件管理、SDK
- AI 支持 控制台内 AI 助手、文档和社区支持。
全球3,000多家组织信赖。
AMLR 对您的要求
自 2027 年 7 月 10 日起,欧盟所有受规管实体都将遵循一套统一的客户尽职调查 (CDD) 规则。Didit 负责执行检查并提供证据,您则保留决策权并承担相应责任。
在无代码构建器中,根据您的风险政策选择所需检查项:电子身份或文件验证、活体检测、人脸比对、筛查和问卷调查。您批准政策,工作流将自动执行。
2024年6月19日
欧盟法规 (EU) 2024/1624 在欧盟官方公报上发布。
2024年7月9日
AMLR 生效。但尚未适用于受义务实体。
2025年7月1日
设在法兰克福的反洗钱管理局 (AMLA) 开始运作。
2026年10月1日
AMLA 公布了其关于客户尽职调查的最终技术标准草案,日期为2026年9月30日,并将其提交给欧盟委员会。它们是最终草案,而非法律。
2027年7月10日
该规则对欧盟所有受义务实体具有约束力。对商品交易或服务提供者的现金支付上限10,000欧元也于同日开始实施。
2028年
AMLA 开始直接监管选定的高风险金融机构,首轮上限为40家。
2029年7月10日
AMLR 开始适用于足球经纪人和职业足球俱乐部。
第19条
尽职调查的适用时机
AMLR 要求
对每项新的业务关系以及金额等于或超过10,000欧元的偶发交易进行客户尽职调查。较低的触发金额:资金转账和加密资产服务提供商 (CASP) 为1,000欧元,现金交易为3,000欧元(需识别和验证),赌博交易为2,000欧元。
Didit 提供
通过API或托管链接启动会话,由您自己的触发器控制。交易监控规则可标记金额和模式。
由您负责
决定何时达到阈值以及哪些交易相关联。
第22条
身份识别与验证
AMLR 要求
对每个人(姓名、出生地和出生日期、国籍、地址)和每个法人实体收集一套固定的数据,并全部进行验证。
Didit 提供
支持14,000多种证件类型的文档捕获,电子护照和电子身份证的芯片读取,被动和主动活体检测,人脸比对和非文档查询。
由您负责
当证件缺少数据点(例如地址)时,选择第二个可靠来源。
第22(6)条
电子身份识别途径
AMLR 要求
通过身份证明文件进行验证,或通过eIDAS实质性或高级别保证的电子身份识别和合格信任服务进行验证。
Didit 提供
已上线五种数字身份钱包:MitID、Finnish Trust Network、Smart-ID、Mobile-ID和BankID Sweden。EUDI Wallet即将推出。
由您负责
确认每个方案都符合您所需的保证级别,并记录您何时使用文档途径以及原因,这是AMLA最终草案标准所要求的。
第22(7)条、第24条、第51至55条和第62条
受益所有权
AMLR 要求
识别直接或间接持有25%或以上股份的每个自然人,以及通过其他方式控制实体的任何人。查阅中央登记册并在14个日历日内报告差异(第24条)。
Didit 提供
提供三个层级的公司注册数据(精简版、股东、UBO),对每个所有者或高级职员进行关联身份检查,以及公司和个人筛选。
由您负责
评估通过其他方式进行的控制,查阅中央登记册并报告差异。层级可用性因国家/地区而异。
第25条
资金目的和来源
AMLR 要求
了解业务关系的目的和预期性质,并在必要时了解资金来源。
Didit 提供
提供带有资金来源和关系目的模板的问卷。
由您负责
决定每个风险级别需要多少信息。
第26条
持续监控和更新
AMLR 要求
监控业务关系,并至少每1年更新高风险客户信息,其他客户每5年更新一次,并根据事件触发进行更新。
Didit 提供
每日重新筛选,通过webhook发出警报,并记录每次运行,每人每年$0.07。当需要刷新时,启动新会话。
由您负责
设置每个客户的风险等级和审查日期。
第20(1)(g)条和第42至46条
政治公众人物 (PEP)
AMLR 要求
确定客户或受益所有人是否为PEP、其家庭成员或密切关联人。需获得高级管理层批准,进行财富来源和资金来源检查,并加强监控。风险措施在当事人离职后至少持续12个月。
Didit 提供
涵盖家庭成员和密切关联人的PEP筛选,问卷调查,人工审核和四眼原则批准。
由您负责
高级管理层批准以及您选择的强化措施。
第20(1)(d)条和第26(4)条
制裁筛选
AMLR 要求
对照欧盟目标金融制裁名单检查客户、受益所有人及控制人,并定期重新检查。
Didit 提供
对照1,300多个制裁、PEP和观察名单进行筛选,每日更新,每次检查$0.20。每日重新筛选并持续监控。
由您负责
审查每个匹配项并对已确认的匹配项采取行动。
第26(1)条和第69条
交易和报告
AMLR 要求
根据您掌握的客户信息监控交易,并向金融情报机构 (FIU) 报告可疑情况。
Didit 提供
针对法币和加密货币的实时规则,11 个规则包,警报,案件管理和报告准备。
由您负责
批准检测标准并提交报告。
第 18 条
外包
AMLR 要求
允许外包,但需签订书面协议,在服务提供商开始前通知您的主管,并进行定期控制。您仍需承担全部责任。
Didit 提供
检查、每个结果背后的证据以及可导出用于您控制的记录。
由您负责
六项绝不能外包的任务:批准全业务风险评估、批准政策和控制措施、决定客户的风险状况、决定客户入驻、向金融情报机构报告以及批准检测标准。
第 77 条
记录
AMLR 要求
在关系或交易结束后,将未经编辑的尽职调查记录保存 5 年。然后删除个人数据。
Didit 提供
会话记录,保留期限可设置为 1 个月至 10 年,可按需删除,默认存储在欧盟。
由您负责
保留义务本身,以及当局要求的任何延期。
第 76(5) 条
人工干预
AMLR 要求
接受或拒绝客户,或更改尽职调查级别的自动化决策,需要有意义的人工干预。客户可以要求解释。
Didit 提供
人工审核队列、四眼原则批准以及每个自动化结果背后的证据。
由您负责
人工决策以及对客户的解释。
最后审阅日期:2026 年 10 月 2 日。非法律建议。请咨询律师确认您的义务。AMLR 将于 2027 年 7 月 10 日生效,AMLA 的技术标准最终草案日期为 2026 年 9 月 30 日,尚未成为法律。
$ curl -X POST https://verification.didit.me/v3/session/ \
-H "x-api-key: $DIDIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"workflow_id": "YOUR_AMLR_WORKFLOW_UUID",
"vendor_data": "customer_8412"
}'{ "url": "https://verify.didit.me/session/…" }app.post("/webhooks/didit", async (req, res) => {
const expected = crypto.createHmac("sha256", process.env.DIDIT_WEBHOOK_SECRET)
.update(req.rawBody).digest();
const sig = Buffer.from(req.get("X-Signature") ?? "", "hex");
if (sig.length !== expected.length ||
!crypto.timingSafeEqual(sig, expected)) return res.sendStatus(401);
const { event_id, timestamp, webhook_type, vendor_data, status } = req.body;
const fresh = Math.abs(Date.now() / 1000 - timestamp) <= 300; // signed field
if (!fresh) return res.sendStatus(401);
if (webhook_type === "status.updated" || webhook_type === "data.updated") {
// event_id repeats on retries: store each event once (unique key).
if (await alreadyStored(event_id)) return res.sendStatus(200);
await saveEvidence(event_id, vendor_data, req.body); // your record
if (status === "In Review") queueForReviewer(vendor_data);
// "Approved" and "Declined" are results. You decide to onboard.
}
res.sendStatus(200);
});OK# Integrate Didit for AMLR customer due diligence
Integrate Didit into <my_stack> to run the customer checks that the EU
Anti-Money Laundering Regulation (AMLR, Regulation (EU) 2024/1624) will
require from 10 July 2027. Didit supplies the checks and the evidence. The
obliged entity keeps every decision and stays fully liable (Article 18).
This prompt is not legal advice.
## What stays with the obliged entity (never automate these away)
Article 18(3) lists six tasks that cannot be outsourced:
- proposing and approving the business-wide risk assessment
- approving internal policies, procedures and controls
- deciding the risk profile of a customer
- deciding to enter a business relationship or carry out a transaction
- reporting to the financial intelligence unit (FIU)
- approving the criteria for detecting suspicious transactions
Build the integration so that a named person takes each of these decisions.
Article 76(5) also requires meaningful human intervention on automated
decisions to accept or refuse a customer.
## Published prices used below
- Full KYC (know your customer) check: $0.33
- AML (anti-money laundering) screening: $0.20 per check
- Ongoing AML monitoring: $0.07 per person per year
For every other module, read https://didit.me/pricing. Do not invent a price.
## 1. Create the applications and the workflow
Create an account at https://business.didit.me. Live and sandbox are separate
applications. Sandbox outcomes are simulated. Store the application keys and
workflow UUIDs in server-side configuration. Never expose a key to a browser.
Build the workflow in the Console, or with
POST https://verification.didit.me/v3/workflows/.
Map the checks to the regulation:
- Identification and verification (Article 22): either a digital ID wallet
(the electronic identification route of Article 22(6)(b)) or ID
Verification with chip reading, liveness and face match (the document
route of Article 22(6)(a)). Which route a customer takes is the obliged
entity's policy. Record the route and the reason in your own system.
- Sanctions and PEP (politically exposed person) screening (Article 20):
add AML Screening.
- Purpose and source of funds (Article 25): add a Questionnaire.
- Companies and beneficial owners (Articles 51 to 62): use a KYB (know your
business) workflow and start a linked identity session for each owner.
The AMLR ownership test is 25% or more, with control assessed in parallel.
Registry tiers vary by country, and a register alone is not sufficient
verification.
Publish the draft. Existing sessions keep the workflow version they started
with.
## 2. Create a session for each customer
curl -X POST https://verification.didit.me/v3/session/ \
-H "x-api-key: <application-key>" \
-H "Content-Type: application/json" \
-d '{
"workflow_id": "<workflow-uuid>",
"vendor_data": "<your-customer-id>"
}'
The response contains "url". Redirect the customer to it, or embed the hosted
flow. vendor_data is your own stable reference and is returned on session
events. Within one application only one unfinished session can exist per
(workflow_id, vendor_data) pair.
## 3. Receive authenticated results
Register a webhook destination for status.updated and data.updated and store
its secret_shared_key on the server.
Verify before reading a result or changing a customer's data:
- X-Signature-V2: HMAC-SHA256 over recursively sorted, compact JSON with
Unicode preserved. This header does not sign raw bytes.
- X-Signature: HMAC-SHA256 over the exact raw request bytes, captured before
any JSON middleware.
- Check the signature format and length before a constant-time comparison.
- Validate X-Timestamp and reject a difference greater than 300 seconds.
Require it to match the timestamp in the authenticated payload. The header
is not signed, so a header checked alone can be replaced on a replay.
- Make processing idempotent before any side effect: a retry reuses the same
event_id, so key on event_id and skip an event you have already stored.
Durably queue the work before acknowledging.
Session statuses: Approved, Declined, In Review, In Progress, Not Started,
Abandoned, Expired, Kyc Expired, Resubmitted, Awaiting User.
- "Approved" and "Declined" are verification results, not onboarding
decisions. Store the result, then let the obliged entity's own process
decide.
- "In Review" goes to a human reviewer.
For reconciliation read
GET https://verification.didit.me/v3/session/{sessionId}/decision/.
## 4. Keep watching (Article 26)
Enable ongoing AML monitoring for approved customers. Didit re-screens daily
and re-screens fire the usual status.updated and data.updated events.
Store a risk class and a next review date for each customer in your own
system. Article 26(2) caps the interval between updates of customer
information at 1 year for higher-risk customers and 5 years for all others,
with event triggers on top. When a review is due, create a new session.
## 5. Keep the record (Article 77)
Records are kept for 5 years from the end of the business relationship, the
occasional transaction or the refusal, and personal data is then deleted
unless another law or an authority requires otherwise.
- Set retention in Business Console -> App Settings -> Data (1 month to 10
years). The clock that matters starts when the relationship ends, so either
size the window for that or export the evidence into the obliged entity's
own archive.
- Delete a session on demand with
DELETE https://verification.didit.me/v3/session/{session_id}/delete/.
Store the session id, the status, the workflow version, the route used and
the name of the person who took the onboarding decision.
## 6. Verify the integration
1. In the sandbox application, run one customer through the wallet route and
one through the document route. Confirm both write the same record shape.
2. Send a webhook with a wrong signature and confirm it is rejected with 401.
3. Confirm an "In Review" result reaches a reviewer and that no code path
onboards a customer without a recorded human decision.
4. Confirm sandbox and live traffic use separate applications.
Docs: https://docs.didit.me/getting-started/amlr-compliance适用于构建、测试和您的首批用户。
25+ 模块,价格公开透明。自动享受批量折扣。
适用于大批量和受监管项目。
使用量增长时自动享受批量折扣——无需谈判,无需销售电话。
Didit 是身份验证和欺诈防护的基础设施,是我们自己构建产品时梦寐以求的平台:开放、灵活、对开发者友好,能真正融入您的技术栈,而不是一个需要您围绕其进行集成的黑盒。
一个 API 即可覆盖个人验证(KYC,了解您的客户)、企业验证(KYB,了解您的业务)、加密钱包筛选(KYT,了解您的交易)以及实时交易监控。我们的技术栈旨在实现:
底层支持:14,000 多种文档类型,支持 48 种以上语言,1,000 多个数据源,每次会话提供 200 多个欺诈信号。Didit 基础设施通过每次会话动态学习,并日益优化。
AMLR 是欧盟反洗钱条例 Regulation (EU) 2024/1624:一套直接适用于欧盟所有受义务实体的客户尽职调查、受益所有权、报告和记录保存的规则。
重要日期:
在 2027 年 7 月 10 日之前,转换早期指令的国家法律仍然适用。由于 AMLR 是一项法规,它无需国家转换,尽管成员国保留了一些选项,例如更低的现金限额。
Didit 帮助您满足客户检查要求。一次完整的了解您的客户 (KYC) 检查费用为 $0.33,制裁和政治公众人物 (PEP) 筛选每次检查费用为 $0.20。
最后审阅时间:2026 年 10 月 2 日。这不是法律建议。请咨询律师确认。
它们是 2024 年一揽子计划的三个组成部分:
一个陷阱:Directive (EU) 2018/1673,关于通过刑法打击洗钱的指令,是另一项法案。在重要时请注明编号。
AMLA 不会认证或批准供应商,AMLR 也不创建供应商许可证。Didit 提供检查和证据,例如对 14,000 多种文档类型的身份验证以及对 1,300 多个列表的筛选。您自己的计划才是监管机构评估的对象。
第 3 条列出了它们。主要群体包括:
成员国可以豁免一些赌博服务和一些风险被证明较低的足球俱乐部。
无论属于哪个类别,客户检查的形式都是相同的,Didit 在一个工作流程中运行它们:对 220 多个国家和地区的身份检查,以及对每个所有者的身份检查进行业务验证。
如果您不确定自己是否在范围内,请咨询律师。这不是法律建议。
是的,根据现有文本,但这不是首选。
法规规定。 第 22(6) 条规定了两种身份验证方式:身份证明文件,或具有 eIDAS 保证级别“实质性”或“高”的电子身份识别,并使用合格的信任服务。AMLR 未提及任何具体技术。“自拍”、“活体检测”和“生物识别”等词语并未出现在其中。
标准草案规定。 AMLA 于 2026 年 9 月 30 日发布的最终技术标准草案将电子身份识别视为默认的远程途径。远程基于文件的验证是那些无法合理地亲自出示文件且无法获得合格电子身份识别的客户的替代方案。您必须能够证明使用它的合理性并提供保障措施。AMLA 还表示,公司可以继续使用符合这些要求的现有远程入职工具。这是一份已提交给欧盟委员会的最终草案。它不是法律。
Didit 的作用。 Didit 支持这两种途径:五个数字身份钱包已投入生产,并提供带芯片读取、活体检测和人脸匹配的文档验证。
尚未。AMLA 于 2026 年 9 月 30 日完成了客户尽职调查的最终草案监管技术标准 (RTS),并于 2026 年 10 月 1 日公布。它们已提交给欧盟委员会。
以下三点需要注意:
AMLR 本身已确定:它将从 2027 年 7 月 10 日起适用。
现在该怎么做:根据法规进行构建,并保持工作流程易于更改。在 Didit 的无代码构建器中,您可以添加或删除检查,或将客户从文档途径转移到数字身份钱包,而无需重新部署。每个会话都会记录其运行的工作流程版本,因此您可以显示适用的规则。
AMLR 没有这样规定。接受义务在于 eIDAS 法规,而不在 AMLR 中。
钱包也不能完成尽职调查。受益所有权、目的、制裁和政治公众人物筛选以及监控仍然存在。
Didit 目前:五个数字身份钱包已投入生产:MitID(丹麦)、Finnish Trust Network、Smart-ID(爱沙尼亚、拉脱维亚、立陶宛、比利时)、Mobile-ID(爱沙尼亚、立陶宛)和BankID Sweden。EUDI 钱包即将推出。 文档验证涵盖没有钱包的客户。
25% 或以上。 第 52(1) 条规定,所有权测试为直接或间接持有 25% 或以上的股份、投票权或其他所有权权益。措辞是 25% 或以上,而不是超过 25%。
经常被忽略的三点:
如果未找到受益所有人,您应记录下来并验证高级管理人员。必须查阅中央登记册,但这本身不足够,差异应在 14 个日历日内报告。
Didit 的业务验证提供三层公司注册数据(精简版、股东、受益所有人),并将身份检查链接到每个所有者或高级职员。可用层级因国家/地区而异。
第 26(2) 条规定了客户信息更新的最大间隔时间:
这些是上限,而非目标。第 26(3) 条补充了事件触发条件:客户情况发生变化、当年有法律义务联系客户,或您知晓相关事实。AMLA 表示这些期限不能通过技术标准延长。
制裁是独立的。第 26(4) 条要求您定期检查客户和受益所有人是否受到定向金融制裁。信贷和金融机构还必须检查任何新的指定。
Didit 如何提供帮助:
您决定每个客户的风险等级和审查日期。Didit 不会为您做出此决定。
第 18 条允许受义务实体在满足特定条件(包括书面协议、在服务提供商开始前通知您的监管机构以及定期控制)的情况下将任务外包给服务提供商。您对外包任务负全部责任。
六项任务绝不能外包(第 18(3) 条):
Didit 可以为您运行的任务包括:身份和文件检查、数字身份钱包验证、注册表查询和所有者检查、制裁和政治公众人物筛选、每日重新筛选、根据您批准的规则进行交易监控以及报告准备。
第 47 条补充说,使用第三方软件或筛选服务,如果由您自己的员工执行要求,则不属于外包。您的设置属于哪一方是律师需要考虑的问题。AMLA 的外包指南预计将于 2027 年 7 月 10 日发布。
五年。 第 77 条要求您在业务关系结束、偶发交易或拒绝入职后 5 年内保留客户尽职调查记录、交易记录和可疑评估。记录不得进行修订。5 年期满后,个人数据必须删除,除非适用其他法律或当局在特定情况下要求再延长 5 年。
此义务由您承担。服务提供商可以存储记录,但义务不会转移。
Didit 的处理方式:
请注意:5 年期限从关系结束时开始计算,而不是从检查运行时开始。请根据此点设置保留窗口,或将记录导出到您自己的存档中。
您按次检查付费,价格公开透明:
业务验证、数字身份钱包和交易监控也按使用量计费。请参阅定价了解所有模块的详细信息。
上线流程简短:
集成只需一个 API 调用和一个 webhook。上线所需时间取决于您自己的政策和审批,这些根据第 18 条规定由您保留。
通过 business.didit.me 免费开始,或通过联系页面与我们联系。