EU AML Regulations 2027

Verification under AMLR, Regulation (EU) 2024/1624 vs UK MLR2017

What UK law firms need to know

[Updated September 2026]

Verification comparisons for UK law firms with EU offices

The EU rules are more prescriptive about both how identity can be verified and what information must be captured. The UK allows a broader risk-based mix of reliable and independent sources, while the AMLR sets a more defined documentary route and requires electronic identification to meet eIDAS “substantial” or “high” assurance.

The AMLR also prescribes a wider individual and entity dataset, requires the relevant beneficial ownership register to be consulted and will be supplemented by further RTS on acceptable verification sources and electronic-ID attributes.

Ref:
UK: MLRs 2017, Reg 28; LSAG guidance; UK DVS framework
EU: Regulation (EU) 2024/1624, Arts 20, 22–23, 28; eIDAS Regulation (EU) No 910/2014

Read more about UK MLRs vs EU AMLR

Frequently asked questions

Does the AMLR change how much we can rely on registry data for beneficial owners?

Yes. The relevant central beneficial owner register must be consulted as part of verification, but it does not replace the wider requirement to verify the beneficial owner using reliable sources. Firms therefore need to distinguish between the register check and the underlying verification evidence.

What evidence will we need to show that the verification method used was valid for each jurisdiction?

The audit trail increasingly needs to show which verification route was used, what source or provider supported it, which jurisdictional standard applied and what evidence was retained. This becomes particularly important where UK and EU offices use different documentary or digital assurance routes.

What will we need to know about our digital ID providers that we may not ask today?

Firms will need to understand which assurance framework the provider meets, in which jurisdictions and whether its EU service satisfies eIDAS “substantial” or “high” assurance.

What will we need to change in our verification workflow from day one?

At minimum, firms will need to route verification by jurisdiction, ensure EU matters use permitted documentary or eIDAS-compliant digital methods, capture the additional AMLR identity fields and make the beneficial owner register check a required verification step.

How can I check that our EU identity provider meet the required eIDAS assurance level, and what technical standards or conformity assessment, including ETSI TS 119 461 where relevant, would support that claim?

The key standard for KYC is ETSI TS 119 461. It sets detailed requirements for how an identity-proofing service should work, including:

  • collection and validation of identity attributes and evidence;
  • checking documents for authenticity;
  • binding the person to the identity evidence;
  • attended and unattended remote identity proofing;
  • use of eID means security, record-keeping and auditability of the verification process.

The latest published version is ETSI TS 119 461 V2.1.1 (February 2025). It is now being developed into EN 319 461, with a stable draft produced in July 2026.

eIDAS and AMLR - a hierarchy 

AMLR
Says what level of electronic identification is acceptable for CDD

eIDAS
Provides the EU legal framework and assurance levels

ETSI standards
Provide detailed technical requirements for how identity-proofing services can meet parts of that framework.

Additional resources

EU level

Cross-border legal profession