Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Can We Actually Pull This Off by 2027?International Bodies & Standards
4 min readFor AML Compliance Officers

Can We Actually Pull This Off by 2027?

During a recent compliance team planning session, a critical question emerged: Are we truly on track for AMLR compliance by July 2027? The team was divided. Some believed they were on schedule, while others hadn't even begun scoping the work. A quick poll revealed that only a third felt confident about their client data readiness. The rest faced a looming deadline with a backlog they couldn't simply hire their way out of.

These aren't abstract policy issues. They're practical gaps that will determine whether your institution can justify its decisions when AMLA or your national supervisor comes calling.

What's Actually Different About AMLR?

You might think you're covered with existing CDD and Beneficial Owner Identification processes, but AMLR changes the game. It's not enough to have policies stating you collect beneficial ownership data. You must demonstrate, on demand, how your data supports every client decision.

AMLR replaces the patchwork of national AML directives with a unified rulebook for all 27 EU member states. It specifies what data to collect, when to apply enhanced due diligence, and which risk factors to consider. Regulatory and implementing technical standards (RTS and ITS) provide the details.

This shift is about moving from policy compliance to decision proofing. If a supervisor asks why you onboarded a client or didn't escalate a relationship, you need to trace your answer back to specific data points, not just point to a procedures manual.

What Does "Data Debt" Mean for Your Team?

Data debt refers to client records that don't meet the new AMLR standard. This includes incomplete UBO chains, outdated addresses, missing documents, or unverifiable risk assessments.

Most institutions hold large volumes of such records, and you can't fix them all by July 2027 just by adding staff. If 20% of your 50,000 corporate client records need remediation, you're looking at 10,000 manual reviews. This isn't just a hiring issue; it's a workflow and data infrastructure challenge.

Institutions that have invested in workflow orchestration and modern data infrastructure will find this transition more manageable. Those that haven't must choose: industrialize data collection now, or face overwhelming client outreach requests in the coming months.

What Does "Industrialize Data Collection" Look Like?

Industrializing data collection means sourcing data from authoritative sources before reaching out to clients.

Start with public registries: corporate registries, beneficial ownership registers, sanctions lists, and adverse media feeds. Then, check your internal data across business lines. Only after exhausting these sources should you contact clients.

A practical approach is building a corporate digital identity (CDI) for each legal entity client. A CDI is a single, continuously updated profile combining verified data and documents from authoritative sources. It provides a complete, current, and traceable record for each client without manual collection every time requirements change.

For example, BNP Paribas has been preparing since mid-2025 by setting up a dedicated governance structure and program team. Their focus is on industrializing collection using public sources, internal data, or external providers rather than defaulting to client outreach.

Are We All Going to Be Asking Clients for the Same Documents?

Yes, and it will be challenging. Many corporate clients bank with multiple institutions. Under AMLR, all these banks must refresh UBO data to the same standard, often across multiple entities within the same group.

Clients will receive overlapping requests for the same beneficial ownership documents from multiple banks, each with slightly different formats and deadlines. This is not only a client experience issue but also a reputational risk if competitors handle it more smoothly.

To address this, coordinate internally to avoid duplicate requests and communicate early with clients about what's coming. Waiting until Q1 2027 to inform clients about updated UBO documentation needs will lead to friction and delays.

Are UBO Requirements Diverging Between the EU and the US?

Yes, they are, creating a challenge for global institutions. Europe is reinforcing its beneficial ownership standards under AMLR, while the US is simplifying its Corporate Transparency Act requirements. This means you can't apply a single global UBO process everywhere.

You'll need parallel workflows: one for the detailed AMLR standard for EU clients and another for the simplified US approach. The operational complexity increases, especially if you're also handling UK clients, where requirements are already stricter than the EU baseline in some areas.

The silver lining is that UK requirements seem to be influencing AMLA's direction, potentially reducing complexity over time.

What Should You Be Doing Right Now?

Here are five steps to take immediately:

Assess data quality and exposure. Audit your client base to identify incomplete, outdated, or missing key data points. Don't wait for deadline pressure.

Industrialize data collection. Determine which data you can source from public or internal sources before reaching out to clients. Build the necessary infrastructure.

Build traceability. Ensure you can explain every decision by linking data points to decisions, not just filing documents.

Coordinate change management early. Align due diligence, relationship management, and compliance teams now to avoid managing change under time pressure.

Rethink the framework. Redesign your CDD process for efficiency and explainability, rather than just layering on new requirements.

Where to Go for More

AMLA will directly supervise about 40 of the largest institutions, with national supervisors overseeing the rest under the same standard. If you're in that top tier, expect direct oversight. If not, your national supervisor will apply the same rulebook.

The regulatory and implementing technical standards (RTS and ITS) contain the details. Read them. They specify exactly what AMLA expects, and they're more specific than high-level summaries.

If you're still in the "we haven't started" camp, start now. July 2027 is just 18 months away, and data remediation at scale takes longer than you think.

Promotional banner for the Penetration Report Template Kit

You Might Also Like