The Challenge
On November 22, the Court of Justice of the European Union invalidated AMLD5's requirement for public access to beneficial ownership registers, ruling it violated fundamental privacy rights under the Charter of Fundamental Rights of the European Union. Within days, Luxembourg, Germany, Austria, the Netherlands, Belgium, and Cyprus suspended public access to their registers.
If you're an AML compliance officer at a financial institution, you've just lost a verification tool you relied on for customer due diligence. While the registers were never perfect, they provided a baseline check when onboarding corporate customers or investigating suspicious ownership structures. Now you're operating with one less data source in an environment where regulators still expect you to identify beneficial owners accurately.
The immediate compliance question isn't philosophical. It's operational: How do you maintain the quality of your beneficial owner identification process when a mandated public resource disappears overnight?
Operational Constraints
The CJEU's decision focused on proportionality. While beneficial ownership transparency aims to combat money laundering and terrorist financing, unrestricted public access created "serious interference" with privacy and data protection rights. The directive didn't limit who could access the data or for what purpose, nor did it require any justification for access requests.
For compliance teams, this creates asymmetric pressure. Your regulatory obligations under AMLD5 haven't changed. You're still required to identify beneficial owners holding 25% or more of shares or voting rights (or exercising control through other means). You're still expected to verify that information using reliable, independent sources. However, the EU member states that suspended public access haven't provided alternative mechanisms for obliged entities like banks and payment companies.
The political environment adds uncertainty. Co-rapporteurs Luděk Niedermayer and Paul Tang called the suspensions "unjustified" and warned that limiting access for competent authorities and obliged entities would increase the risk of money laundering. The European Commission stated it's analyzing what amendments are needed but hasn't proposed a timeline beyond the mid-March 2023 vote on AMLD6 in the ECON and LIBE Committees.
You're caught between a court decision protecting privacy, suspended registers, unchanged compliance obligations, and legislators who won't finalize revisions for months.
Adapting Your Approach
Compliance officers at institutions operating across multiple EU jurisdictions had to make rapid decisions without regulatory guidance. The practical response broke into three workstreams.
First, teams mapped their current beneficial owner verification procedures to identify where they relied on public register checks. Some institutions used the registers as a primary source during onboarding. Others used them as a secondary verification layer or for periodic reviews. The critical question: Can you still meet your customer due diligence obligations using remaining data sources?
Second, institutions evaluated alternative data sources. Commercial registries that compile beneficial ownership data from multiple jurisdictions became more valuable, though they now face the same access restrictions for EU data. Corporate registry filings, shareholder agreements, and direct customer attestations gained more weight in the verification process. Some teams increased their use of adverse media screening to flag ownership structures that appeared in investigative journalism or enforcement actions.
Third, compliance teams revised their risk assessment frameworks. If you can't verify beneficial ownership as thoroughly as before, do you need to adjust risk ratings for certain customer segments? Some institutions applied enhanced due diligence more broadly to corporate customers from affected jurisdictions, particularly for complex ownership structures or customers in higher-risk sectors.
The European Commission and Parliament co-rapporteurs signaled they're working toward amendments that would preserve access for competent authorities and obliged entities while restricting general public access. But that's a policy discussion, not an operational solution for your current caseload.
Results and Implications
The suspensions revealed how much compliance processes had integrated public register access as a routine step. Institutions that built automated workflows pulling data from public APIs had to disable those checks. Manual review times increased because analysts needed to gather verification documents directly from customers or use more expensive commercial data sources.
The operational impact varied by institution size and sophistication. Larger banks with established relationships often had detailed beneficial ownership documentation already on file from account opening. Fintechs and payment companies with streamlined digital onboarding faced harder choices because they'd designed lighter-touch verification processes that assumed public register availability.
No institution could quantify how much the suspensions degraded their beneficial owner identification accuracy. You can measure process changes (more manual reviews, longer onboarding times, higher data costs), but you can't measure what you're missing. That's the uncomfortable reality: your false negative rate for beneficial ownership may have increased, and you won't know until a law enforcement inquiry or regulatory exam exposes a gap.
The mid-March 2023 committee vote on AMLD6 will clarify the legislative direction, but inter-institutional negotiations aren't expected until Q2 2023. Even after AMLD6 passes, member states will need time to implement revised access controls.
Lessons Learned
With hindsight, compliance teams wish they'd stress-tested their beneficial owner verification procedures against the loss of public registers earlier. The CJEU ruling wasn't entirely unpredictable. Privacy advocates had challenged the proportionality of unrestricted public access since AMLD5's implementation. Building verification processes that assumed permanent public access created a single point of failure.
Institutions that maintained robust document collection practices during onboarding weathered the suspensions better. If you're already requiring corporate customers to provide certified ownership documentation, shareholder registers, and trust deeds, losing the public register is an inconvenience, not a crisis. If you'd shifted toward minimal documentation plus a quick public register check, you're now rebuilding verification procedures under time pressure.
The lesson extends beyond beneficial ownership registers. Any compliance process that depends heavily on a single external data source carries execution risk. Regulatory requirements change. Court decisions reinterpret directives. Data providers get acquired or shut down. Your verification framework should assume you'll lose access to any given source and still meet your obligations.
Action Steps for Your Team
First, audit your beneficial owner verification procedures now. Document every data source you use, categorize them as primary or secondary, and identify which customer segments or risk categories depend most heavily on each source. If you lost access to any single source tomorrow, could you still verify beneficial ownership to the standard your regulator expects?
Second, don't wait for AMLD6's final text to adjust your approach. The court's reasoning is clear: unrestricted public access is disproportionate. Even after amendments pass, expect more restrictive access controls. Plan for a future where you need to demonstrate a legitimate interest or register as an obliged entity to query beneficial ownership data. Build those authentication and justification steps into your procedures now.
Third, strengthen your direct documentation requirements. The most reliable beneficial ownership information comes from the customer, supported by certified corporate documents. Public registers were always meant to supplement, not replace, your own due diligence. If the suspensions forced you to collect more documentation from customers, keep that practice even if public access returns.
Finally, engage with your industry association and regulators about access for obliged entities. The co-rapporteurs explicitly stated they're looking for ways to provide access to competent authorities and obliged entities while restricting general public access. Your regulator needs to understand what data you need, in what format, and under what access controls you can still meet your obligations. That feedback shapes the amendments that will govern your work for the next several years.
The suspensions exposed a dependency that many compliance programs didn't realize they'd built. Use this disruption to build more resilient verification procedures that can withstand the next court decision or regulatory shift.



