+SECTION 1 General provisions
---+Article 19 Application of customer due diligence measures
---+Article 20 Customer due diligence measures
---+Article 21 Inability to comply with the requirement to apply customer due diligence measures
---+Article 22 Identification and verification of the identity of customers and beneficial owners
---+Article 23 Timing of the verification of the customer and beneficial owner identity
---+Article 24 Reporting of discrepancies with information contained in beneficial ownership registers
---+Article 25 Identification of the purpose and intended nature of a business relationship or occasional transaction
---+Article 26 Ongoing monitoring of the business relationship and monitoring of transactions performed by customers
---+Article 27 Temporary measures for customers subject to UN financial sanctions
---+Article 28 Regulatory technical standards on the information necessary for the performance of customer due diligence
|
SECTION 1 General provisions
SECTION 1 General provisions
1. Overview
| Summary |
Regulation |
|
Article 19 Application of customer due diligence measures
|
Article 19
Application of customer due diligence measures
1. Obliged entities shall apply customer due diligence measures in any of the following circumstances:
|
(a)
|
when establishing a business relationship;
|
|
(b)
|
when carrying out an occasional transaction of a value of at least EUR 10 000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions, or a lower value laid down pursuant to paragraph 9;
|
|
(c)
|
when participating in the creation of a legal entity, the setting up of a legal arrangement or, for the obliged entities referred to in Article 3, points (3) (a), (b) or (c), in the transfer of ownership of a legal entity, irrespective of the value of the transaction;
|
|
(d)
|
when there is a suspicion of money laundering or terrorist financing, regardless of any derogation, exemption or threshold;
|
|
(e)
|
when there are doubts about the veracity or adequacy of previously obtained customer identification data;
|
|
(f)
|
when there are doubts as to whether the person they interact with is the customer or person authorised to act on behalf of the customer.
|
2. In addition to the circumstances referred to in paragraph 1, credit institutions and financial institutions, with the exception of crypto-asset service providers, shall apply customer due diligence measures when initiating or executing an occasional transaction that constitutes a transfer of funds as defined in Article 3, point (9), of Regulation (EU) 2023/1113, that amounts to a value of at least EUR 1 000, or the equivalent in national currency, whether that transaction is carried out in a single operation or through linked transactions.
3. By way of derogation from paragraph 1, point (b), crypto-asset service providers shall:
|
(a)
|
apply customer due diligence measures when carrying out an occasional transaction that amounts to a value of at least EUR 1 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions;
|
|
(b)
|
apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction where the value is below EUR 1 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.
|
4. By way of derogation from paragraph 1, point (b), obliged entities shall apply at least customer due diligence measures referred to in Article 20(1), point (a), when carrying out an occasional transaction in cash amounting to a value of at least EUR 3 000, or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.
The first subparagraph of this paragraph shall not apply where Member States have in place, pursuant to Article 80(2) and (3), a limit to large cash payments of EUR 3 000 or less, or the equivalent in national currency, except in the cases covered by paragraph 4, point (b) of that Article.
5. In addition to the circumstances referred to in paragraph 1, providers of gambling services shall apply customer due diligence measures upon the collection of winnings, the wagering of a stake, or both, when carrying out transactions amounting to at least EUR 2 000 or the equivalent in national currency, whether the transaction is carried out in a single operation or through linked transactions.
6. For the purposes of this Chapter, obliged entities shall consider as their customers the following persons:
|
(a)
|
in the case of obliged entities as referred to in Article 3, points (3) (e), (f) and (i) and persons trading in high value goods as referred to in Article 3, point (3) (j), in addition to their direct customer, the supplier of goods;
|
|
(b)
|
in the case of notaries, lawyers and other independent legal professionals intermediating a transaction and to the extent that they are the only notary or lawyer or other independent legal professional intermediating that transaction, both parties to the transaction;
|
|
(c)
|
in the case of real estate agents, both parties to the transaction;
|
|
(d)
|
in relation to payment initiation services carried out by payment initiation service providers, the merchant;
|
|
(e)
|
in relation to crowdfunding service providers and crowdfunding intermediaries, the natural or legal person both seeking funding and providing funding through the crowdfunding platform.
|
7. Supervisors may, directly or in cooperation with other authorities in that Member State, exempt obliged entities from applying, in full or in part, the customer due diligence measures referred to in Article 20(1), points (a), (b) and (c), with respect to electronic money on the basis of the proven low risk posed by the nature of the product, where all of the following risk-mitigating conditions are met:
|
(a)
|
the payment instrument is not reloadable, and the amount stored electronically does not exceed EUR 150 or the equivalent in national currency;
|
|
(b)
|
the payment instrument is used exclusively to purchase goods or services provided by the issuer, or within a network of service providers;
|
|
(c)
|
the payment instrument is not linked to a payment account and it does not permit any stored amount to be exchanged for cash or for crypto-assets;
|
|
(d)
|
the issuer carries out sufficient monitoring of the transactions or business relationship to enable the detection of unusual or suspicious transactions.
|
8. Providers of gambling services may fulfil their obligation to apply customer due diligence measures referred to in Article 20(1), point (a), by identifying the customer and verifying the customer’s identity upon entry to the casino or other physical gambling premises, provided that they have systems in place that enable them to attribute transactions to specific customers.
9. By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify:
|
(a)
|
the obliged entities, sectors or transactions that are associated with higher money laundering and terrorist financing risk and to which a value lower than the value set out in paragraph 1, point (b), applies;
|
|
(b)
|
the related occasional transaction values;
|
|
(c)
|
the criteria to be taken into account for identifying occasional transactions and business relationships;
|
|
(d)
|
the criteria to identify linked transactions.
|
When developing the draft regulatory technical standards referred to in the first subparagraph, AMLA shall take due account of the inherent levels of risks of the business models of the different types of obliged entities and of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640.
10. Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraph 9 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.
|
|
Article 20 Customer due diligence measures
|
Article 20
Customer due diligence measures
1. For the purpose of conducting customer due diligence, obliged entities shall apply all of the following measures:
|
(a)
|
identifying the customer and verifying the customer’s identity;
|
|
(b)
|
identifying the beneficial owners and taking reasonable measures to verify their identity so that the obliged entity is satisfied that it knows who the beneficial owner is and that it understands the ownership and control structure of the customer;
|
|
(c)
|
assessing and, as appropriate, obtaining information on and understanding the purpose and intended nature of the business relationship or the occasional transactions;
|
|
(d)
|
verifying whether the customer or the beneficial owners are subject to targeted financial sanctions, and, in the case of a customer or party to a legal arrangement who is a legal entity, whether natural or legal persons subject to targeted financial sanctions control the legal entity or have more than 50 % of the proprietary rights of that legal entity or majority interest in it, whether individually or collectively;
|
|
(e)
|
assessing and, as appropriate, obtaining information on the nature of the customers’ business, including, in the case of undertakings, whether they carry out activities, or of their employment or occupation;
|
|
(f)
|
conducting ongoing monitoring of the business relationship including scrutiny of transactions undertaken throughout the course of the business relationship to ensure that the transactions being conducted are consistent with the obliged entity’s knowledge of the customer, the business and risk profile, including where necessary the source of funds;
|
|
(g)
|
determining whether the customer, the beneficial owner of the customer and, where relevant, the person on whose behalf or for the benefit of whom a transaction or activity is being carried out is a politically exposed person, a family member or person known to be a close associate;
|
|
(h)
|
where a transaction or activity is being conducted on behalf of or for the benefit of natural persons other than the customer, identifying and verifying the identity of those natural persons;
|
|
(i)
|
verifying that any person purporting to act on behalf of the customer is so authorised and identify and verify their identity.
|
2. Obliged entities shall determine the extent of the measures referred to in paragraph 1 on the basis of an individual analysis of the risks of money laundering and terrorist financing having regard to the specific characteristics of the client and of the business relationship or occasional transaction, and taking into account the business-wide risk assessment by the obliged entity pursuant to Article 10 and the money laundering and terrorist financing variables set out in Annex I as well as the risk factors set out in Annexes II and III.
Where obliged entities identify an increased risk of money laundering or terrorist financing they shall apply enhanced due diligence measures pursuant to Section 4 of this Chapter. Where situations of lower risk are identified, obliged entities may apply simplified due diligence measures pursuant to Section 3 of this Chapter.
3. By 10 July 2026, AMLA shall issue guidelines on the risk variables and risk factors to be taken into account by obliged entities when entering into business relationships or carrying out occasional transactions.
4. Obliged entities shall at all times be able to demonstrate to their supervisors that the measures taken are appropriate in view of the risks of money laundering and terrorist financing that have been identified.
|
|
Article 21 Inability to comply with the requirement to apply customer due diligence measures
|
Article 21
Inability to comply with the requirement to apply customer due diligence measures
1. Where an obliged entity is unable to comply with the requirement to apply customer due diligence measures laid down in Article 20(1), it shall refrain from carrying out a transaction or establishing a business relationship, and shall terminate the business relationship and consider reporting a suspicious transaction to the FIU in relation to the customer in accordance with Article 69.
The termination of a business relationship pursuant to the first subparagraph of this paragraph shall not prohibit the receipt of funds as defined in Article 4, point (25), of Directive (EU) 2015/2366 due to the obliged entity.
Where an obliged entity has a duty to protect its customer’s assets, the termination of the business relationship shall not be understood as requiring the disposal of the assets of the customer.
In the case of life insurance contracts, obliged entities shall, where necessary as an alternative measure to terminating the business relationship, refrain from performing transactions for the customer, including payouts to beneficiaries, until the customer due diligence measures laid down in Article 20(1) are complied with.
2. Paragraph 1 shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors, to the extent that those persons ascertain the legal position of their client, or perform the task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings.
The first subparagraph shall not apply when the obliged entities referred to therein:
|
(a)
|
take part in money laundering, its predicate offences or terrorist financing;
|
|
(b)
|
provide legal advice for the purposes of money laundering, its predicate offences or terrorist financing; or
|
|
(c)
|
know that the client is seeking legal advice for the purposes of money laundering, its predicate offences or terrorist financing; knowledge or purpose may be inferred from objective factual circumstances.
|
3. Obliged entities shall keep record of the actions taken in order to comply with the requirement to apply customer due diligence measures, including records of the decisions taken and the relevant supporting documents and justifications. Documents, data or information held by the obliged entity shall be updated whenever the customer due diligence is reviewed pursuant to Article 26.
The obligation to keep records provided for in the first subparagraph of this paragraph shall also apply to situations where obliged entities refuse to enter into a business relationship, terminate a business relationship or apply alternative measures pursuant to paragraph 1.
4. By 10 July 2027, AMLA shall issue joint guidelines with the European Banking Authority on the measures that may be taken by credit institutions and financial institutions to ensure compliance with AML/CFT rules when implementing the requirements of Directive 2014/92/EU, including in relation to business relationships that are most affected by de-risking practices.
|
|
Article 22 Identification and verification of the identity of customers and beneficial owners
|
Article 22
Identification and verification of the identity of customers and beneficial owners
1. With the exception of cases of lower risk to which measures under Section 3 apply and irrespective of the application of additional measures in cases of higher risk under Section 4 obliged entities shall obtain at least the following information in order to identify the customer, any person purporting to act on behalf of the customer, and the natural persons on whose behalf or for the benefit of whom a transaction or activity is being conducted:
|
(a)
|
for a natural person:
|
(i)
|
all names and surnames;
|
|
(ii)
|
place and full date of birth;
|
|
(iii)
|
nationalities, or statelessness and refugee or subsidiary protection status where applicable, and the national identification number, where applicable;
|
|
(iv)
|
the usual place of residence or, if there is no fixed residential address with legitimate residence in the Union, the postal address at which the natural person can be reached and, where available the tax identification number;
|
|
|
(b)
|
for a legal entity:
|
(i)
|
legal form and name of the legal entity;
|
|
(ii)
|
address of the registered or official office and, if different, the principal place of business, and the country of creation;
|
|
(iii)
|
the names of the legal representatives of the legal entity as well as, where available, the registration number, the tax identification number and the Legal Entity Identifier;
|
|
(iv)
|
the names of persons holding shares or a directorship position in nominee form, including reference to their status as nominee shareholders or directors.
|
|
|
(c)
|
for a trustee of an express trust or a person holding an equivalent position in a similar legal arrangement:
|
(i)
|
basic information on the legal arrangement; however, with regard to the assets held in the legal arrangement or managed through it, only the assets that are to be managed in the context of the business relationship or occasional transaction shall be identified;
|
|
(ii)
|
the address of residence of the trustees or persons holding an equivalent position in a similar legal arrangement and, if different, the place from where the express trust or similar legal arrangement is administered, the powers that regulate and bind the legal arrangement, as well as, where available, the tax identification number and the Legal Entity Identifier;
|
|
|
(d)
|
for other organisations that have legal capacity under national law:
|
(i)
|
name, address of the registered office or equivalent;
|
|
(ii)
|
names of the persons empowered to represent the organisation as well as, where applicable, legal form, tax identification number, registration number, Legal Entity Identifier and deeds of association or equivalent.
|
|
2. For the purposes of identifying the beneficial owner of a legal entity or of a legal arrangement, obliged entities shall collect the information referred to in Article 62(1), second subparagraph, point (a).
Where, after having exhausted all possible means of identification, no natural persons are identified as beneficial owners, or where there are doubts that the persons identified are the beneficial owners, obliged entities shall record that no beneficial owner was identified and identify all the natural persons holding the positions of senior managing officials in the legal entity and shall verify their identity.
Where the performance of identity verification referred to in the second subparagraph may tip off the customer that the obliged entity has doubts regarding the beneficial ownership of the legal entity, the obliged entity shall abstain from verifying the senior managing officials’ identity, and shall instead record the steps taken to ascertain the identity of the beneficial owners and senior managing officials. Obliged entities shall keep records of the actions taken as well as of the difficulties encountered during the identification process, which led to resorting to the identification of a senior managing official.
3. Credit institutions and financial institutions shall obtain information to identify and verify the identity of the natural or legal persons using any virtual IBAN they issue, and the associated bank or payment account.
The credit institution or financial institution servicing the bank or payment account to which a virtual IBAN issued by another credit institution or financial institution redirects payments, shall ensure that it can obtain from the institution issuing the virtual IBAN the information identifying and verifying the identity of the natural person using that virtual IBAN without delay and in any case within 5 working days of it requesting that information.
4. In the case of beneficiaries of trusts or similar legal entities or arrangements that are designated by particular characteristics or class, an obliged entity shall obtain sufficient information concerning the beneficiary so that it will be able to establish the identity of the beneficiary at the time of the payout or at the time of the exercise by the beneficiary of its vested rights.
5. In the case of discretionary trusts, an obliged entity shall obtain sufficient information concerning the objects of a power and default takers to enable it to establish the identity of the beneficiary at the time of the exercise by the trustees of their power of discretion, or at the time that the default takers become the beneficiaries due to the trustees’ failure to exercise their power of discretion.
6. Obliged entities shall obtain the information, documents and data necessary for the verification of the identity of the customer and of any person purporting to act on their behalf through either of the following means:
|
(a)
|
the submission of an identity document, passport or equivalent and, where relevant, the acquisition of information from reliable and independent sources, whether accessed directly or provided by the customer;
|
|
(b)
|
the use of electronic identification means which meet the requirements of Regulation (EU) No 910/2014 with regard to the assurance levels ‘substantial’ or ‘high’ and relevant qualified trust services as set out in that Regulation.
|
7. Obliged entities shall verify the identity of the beneficial owner and, where relevant, the persons on whose behalf or for the benefit of whom a transaction or activity is being carried out in either of the following ways:
|
(a)
|
in accordance with paragraph 6;
|
|
(b)
|
by taking reasonable measures to obtain the necessary information, documents and data from the customer or other reliable sources, including public registers other than the central registers.
|
Obliged entities shall determine the extent of the information to be consulted, having regard to the risks posed by the occasional transaction or the business relationship and the beneficial owner, including risks relating to the ownership structure.
In addition to the means of verification set out in the first subparagraph of this paragraph, obliged entities shall verify the information on the beneficial owners by consulting the central registers.
|
|
Article 23 Timing of the verification of the customer and beneficial owner identity
|
Article 23
Timing of the verification of the customer and beneficial owner identity
1. Verification of the identity of the customer, the beneficial owner, and of any persons pursuant to Article 20(1), points (h) and (i), shall take place before the establishment of a business relationship or the carrying out of an occasional transaction. Such obligation shall not apply to situations of lower risk under Section 3 of this Chapter, provided that the lower risk justifies postponement of such verification.
For real estate agents, the verification referred to in the first subparagraph shall be carried out after an offer is accepted by the seller or lessor, and in all cases before any funds or property are transferred.
2. By way of derogation from paragraph 1, verification of the identity of the customer and of the beneficial owner may be completed during the establishment of a business relationship if necessary so as not to interrupt the normal conduct of business and where there is little risk of money laundering or terrorist financing. In such situations, those procedures shall be completed as soon as practicable after initial contact.
3. By way of derogation from paragraph 1 of this Article, a credit institution or financial institution may open an account, including accounts that permit transactions in transferable securities, as may be required by a customer provided that there are adequate safeguards in place to ensure that transactions are not carried out by the customer or on its behalf until full compliance with the customer due diligence measures laid down in Article 20(1), points (a) and (b), is obtained.
4. Whenever entering into a new business relationship with a legal entity or the trustee of an express trust or the person holding an equivalent position in a similar legal arrangement referred to in Articles 51, 57, 58, 61 and 67 and subject to the registration of beneficial ownership information pursuant to Article 10 of Directive (EU) 2024/1640, obliged entities shall collect valid proof of registration or a recently issued excerpt of the register confirming validity of registration.
|
|
Article 24 Reporting of discrepancies with information contained in beneficial ownership registers
|
Article 24
Reporting of discrepancies with information contained in beneficial ownership registers
1. Obliged entities shall report to the central registers any discrepancies they find between the information available in the central registers and the information they collect pursuant to Article 20(1), point (b), and Article 22(7).
The discrepancies referred to in the first subparagraph shall be reported without undue delay and, in any case, within 14 calendar days of their detection. When reporting such discrepancies, obliged entities shall accompany their reports with information they have obtained indicating the discrepancy and whom they consider to be the beneficial owners and, where applicable, the nominee shareholders and nominee directors to be and why.
2. By way of derogation from paragraph 1, obliged entities may refrain from reporting discrepancies to the central register and may instead request additional information from the customers where the discrepancies identified:
|
(a)
|
are limited to typographical errors, different ways of transliteration, or minor inaccuracies that do not affect the identification of the beneficial owners or their position; or
|
|
(b)
|
are a result of outdated data, but the beneficial owners are known to the obliged entity from another reliable source and there are no grounds for suspicion that there is an intention to conceal any information.
|
Where an obliged entity concludes that the beneficial ownership information in the central register is incorrect, it shall invite the customer to submit the correct information to the central register pursuant to Articles 63, 64 and 67 without undue delay, and, in any case, within 14 calendar days.
This paragraph shall not apply to cases of higher risk to which measures under Section 4 of this Chapter apply.
3. Where a customer has not submitted the correct information within the deadline referred to in paragraph 2, second subparagraph, the obliged entity shall report the discrepancy to the central register in accordance with paragraph 1, second subparagraph.
4. This Article shall not apply to notaries, lawyers, other independent legal professionals, auditors, external accountants and tax advisors in relation to information they receive from, or obtain on, a client, in the course of ascertaining the legal position of that client, or performing their task of defending or representing that client in, or concerning, judicial proceedings, including providing advice on instituting or avoiding such proceedings, regardless of whether such information is received or obtained before, during or after such proceedings.
However, the requirements of this Article shall apply when the obliged entities referred to in the first subparagraph of this paragraph provide legal advice in any of the situations covered by Article 21(2), second subparagraph.
|
|
Article 25 Identification of the purpose and intended nature of a business relationship or occasional transaction
|
Article 25
Identification of the purpose and intended nature of a business relationship or occasional transaction
Before entering into a business relationship or performing an occasional transaction, an obliged entity shall assure itself that it understands its purpose and intended nature. To that end, the obliged entity shall obtain, where necessary, information on:
|
(a)
|
the purpose and economic rationale of the occasional transaction or business relationship;
|
|
(b)
|
the estimated amount of the envisaged activities;
|
|
(d)
|
the destination of funds;
|
|
(e)
|
the business activity or the occupation of the customer.
|
For the purposes of the first paragraph, point (a), of this Article, obliged entities covered by Article 74 shall collect information in order to determine whether the intended use of high value goods referred to in that Article is for commercial or non-commercial purposes.
|
|
Article 26 Ongoing monitoring of the business relationship and monitoring of transactions performed by customers
|
Article 26
Ongoing monitoring of the business relationship and monitoring of transactions performed by customers
1. Obliged entities shall conduct ongoing monitoring of business relationships, including transactions undertaken by the customer throughout the course of a business relationship, to ensure that those transactions are consistent with the obliged entity’s knowledge of the customer, the customer’s business activity and risk profile, and where necessary, with the information about the origin and destination of the funds and to detect those transactions that shall be made subject to a more thorough assessment pursuant to Article 69(2).
Where business relationships cover more than one product or service, obliged entities shall ensure that the customer due diligence measures cover all those products and services.
Where obliged entities belonging to a group have business relationships with customers that are also the customers of other entities within that group, whether obliged entities or undertakings not subject to AML/CFT requirements, they shall take into account information relating to those other business relationships for the purposes of monitoring the business relationship with their customers.
2. In the context of the ongoing monitoring referred to in paragraph 1, obliged entities shall ensure that the relevant documents, data or information of the customer are kept up to date.
The period between updates of customer information pursuant to the first subparagraph shall be dependent on the risk posed by the business relationship and shall not in any case exceed:
|
(a)
|
for higher risk customers to which measures under Section 4 of this Chapter apply, 1 year;
|
|
(b)
|
for all other customers, 5 years.
|
3. In addition to the requirements set out in paragraph 2, obliged entities shall review and, where relevant, update the customer information where:
|
(a)
|
there is a change in the relevant circumstances of a customer;
|
|
(b)
|
the obliged entity has a legal obligation in the course of the relevant calendar year to contact the customer for the purpose of reviewing any relevant information relating to the beneficial owners or to comply with Council Directive 2011/16/EU (42);
|
|
(c)
|
they become aware of a relevant fact which pertains to the customer.
|
4. In addition to the ongoing monitoring referred to in paragraph 1 of this Article, obliged entities shall regularly verify whether the conditions laid down in Article 20(1), point (d), are met. The frequency of that verification shall be commensurate with the exposure of the obliged entity and the business relationship to risks of non-implementation and evasion of targeted financial sanctions.
For credit institutions and financial institutions, the verification referred to in the first subparagraph shall also be carried out upon any new designation in relation to targeted financial sanctions.
The requirements of this paragraph shall not replace the obligation to apply targeted financial sanctions or stricter requirements under other Union legal acts or under national law on the verification of the client base against lists of targeted financial sanctions.
5. By 10 July 2026, AMLA shall issue guidelines on ongoing monitoring of a business relationship and on the monitoring of the transactions carried out in the context of such relationship.
|
|
Article 27 Temporary measures for customers subject to UN financial sanctions
|
Article 27
Temporary measures for customers subject to UN financial sanctions
1. In respect of customers that are subject to UN financial sanctions or that are controlled by natural or legal persons or entities subject to UN financial sanctions, or in which natural or legal persons or entities that are subject to UN financial sanctions have more than 50 % of the proprietary rights or majority interest, whether individually or collectively, obliged entities shall keep records of:
|
(a)
|
the funds or other assets that they manage for the customer at the time when UN financial sanctions are made public;
|
|
(b)
|
the transactions attempted by the customer;
|
|
(c)
|
the transactions carried out for the customer.
|
2. Obliged entities shall apply this Article between the time that UN financial sanctions are made public and the time of application of the relevant targeted financial sanctions in the Union.
|
|
Article 28 Regulatory technical standards on the information necessary for the performance of customer due diligence
|
Article 28
Regulatory technical standards on the information necessary for the performance of customer due diligence
1. By 10 July 2026, AMLA shall develop draft regulatory technical standards and submit them to the Commission for adoption. Those draft regulatory technical standards shall specify:
|
(a)
|
the requirements that apply to obliged entities pursuant to Article 20 and the information to be collected for the purpose of performing standard, simplified and enhanced due diligence pursuant to Articles 22 and 25 and Articles 33(1) and 34(4), including minimum requirements in situations of lower risk;
|
|
(b)
|
the type of simplified due diligence measures which obliged entities may apply in situations of lower risk pursuant to Article 33(1) of this Regulation, including measures applicable to specific categories of obliged entities and products or services, having regard to the results of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640;
|
|
(c)
|
the risk factors associated with features of electronic money instruments that should be taken into account by supervisors when determining the extent of the exemption under Article 19(7);
|
|
(d)
|
the reliable and independent sources of information that may be used to verify the identification data of natural or legal persons for the purposes of Article 22(6) and (7);
|
|
(e)
|
the list of attributes which electronic identification means and relevant qualified trust services referred to in Article 22(6), point (b), must feature in order to fulfil the requirements of Article 20(1), points (a) and (b), in the case of standard, simplified and enhanced due diligence.
|
2. The requirements and measures referred to in paragraph 1, points (a) and (b), shall be based on the following criteria:
|
(a)
|
the inherent risk involved in the service provided;
|
|
(b)
|
the risks associated with categories of customers;
|
|
(c)
|
the nature, amount and recurrence of the transaction;
|
|
(d)
|
the channels used for conducting the business relationship or the occasional transaction.
|
3. AMLA shall review regularly the regulatory technical standards and, if necessary, prepare and submit to the Commission the draft for updating those standards in order, inter alia, to take account of innovation and technological developments.
4. Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in paragraphs 1 and 3 of this Article in accordance with Articles 49 to 52 of Regulation (EU) 2024/1620.
|
1.1 References
1.2 Identified Requirements
1.3 Related Standards
2. Identified Requirements
Requirements
| Source |
Requirement |
3. Related Standards
Standards
| Source |
Requirement |
|