Verification under AMLR, Regulation (EU) 2024/1624 vs UK MLR2017
What UK law firms need to know
[Updated September 2026]
Verification comparisons for UK law firms with EU offices
The EU rules are more prescriptive about both how identity can be verified and what information must be captured. The UK allows a broader risk-based mix of reliable and independent sources, while the AMLR sets a more defined documentary route and requires electronic identification to meet eIDAS “substantial” or “high” assurance.
The AMLR also prescribes a wider individual and entity dataset, requires the relevant beneficial ownership register to be consulted and will be supplemented by further RTS on acceptable verification sources and electronic-ID attributes.
Ref:
UK: MLRs 2017, Reg 28; LSAG guidance; UK DVS framework
EU: Regulation (EU) 2024/1624, Arts 20, 22–23, 28; eIDAS Regulation (EU) No 910/2014
UK MLRs
EU AMLR
Operational implication
Document-based
Flexible, risk-based approach. LSAG recognises originals, copies on a risk-sensitive basis, electronic verification and other reliable independent sources. In practice certified or notarised documents with proof of address documents are also acceptable.
Customer identity is verified using an identity document, passport or equivalent, plus reliable and independent information where relevant.
Document-based verification workflows may need different permitted evidence options by jurisdiction, with broader source flexibility in the UK and a more defined passport / ID / equivalent route in the EU.
Electronic methods
Permitted where the source is reliable, secure from fraud / misuse and provides appropriate assurance that the person is who they claim to be. UK DVS providers are also recognised.
Electronic verification must use an eIDAS electronic identification means at “substantial” or “high” assurance, or relevant qualified trust services. “Low” assurance is not enough for this route.
eIDV providers may need to support different assurance frameworks by jurisdiction, with UK DVS recognition for UK checks and eIDAS substantial / high assurance for EU checks.
Individual verification data
No prescribed statutory dataset in the legislation but LSAG expects identification of name, date of birth and current address for individuals.
Prescribes all names, place and full date of birth, nationality / status, residential address, national ID number (where applicable) and tax identification number / TIN (where available.)
Client data capture tools /onboarding forms may need additional EU identity fields, particularly place of birth, nationality, national ID and tax identifiers.
Entity verification data
Requires core company information including name, registration number, registered office, principal place of business, legal form / governing law and senior management.
Requires legal form and name, registered / official office and principal place of business (if different), country of creation, names of legal representatives, registration number, tax identification number and legal entity identifier (where available), and names of nominee shareholders / directors with reference to their nominee status.
KYB data capture tools and workflows may need additional EU fields, particularly for legal representatives, tax identification numbers and legal entity identifiers as well as nominee shareholder / director status.
Beneficial owners
Must be independently identified and verified; Companies House / PSC register information cannot be relied on solely for this purpose.
Must be verified using reliable sources and the relevant central beneficial owner register must also be consulted.
EU beneficial owner verification workflows need a mandatory relevant register-check step alongside the wider verification evidence. Digital identity data providers may also need to extend to relevant registers.
Digital assurance
More risk-based. Electronic verification must provide an appropriate level of assurance against impersonation/fraud; certified services on the GOV.UK DVS Register are expressly recognised as a reliable and independent source.
The EU prescribes that electronic ID must meet eIDAS “substantial” or “high” assurance
Digital-ID providers may need to support different assurance standards by jurisdiction.
Further standards
UK requirements are defined by MLRs, LSAG guidance and the UK DVS framework.
Acceptable verification sources and electronic-ID attributes are still to be defined. eIDAS technical standards increasingly reference ETSI TS 119 461 for identity proofing, including remote onboarding to EU Digital Identity Wallets.
eIDV providers may need to evidence both regulatory assurance and underlying technical conformity, including ETSI standards where relevant
Read more about UK MLRs vs EU AMLR
Frequently asked questions
Does the AMLR change how much we can rely on registry data for beneficial owners?
Yes. The relevant central beneficial owner register must be consulted as part of verification, but it does not replace the wider requirement to verify the beneficial owner using reliable sources. Firms therefore need to distinguish between the register check and the underlying verification evidence.
What evidence will we need to show that the verification method used was valid for each jurisdiction?
The audit trail increasingly needs to show which verification route was used, what source or provider supported it, which jurisdictional standard applied and what evidence was retained. This becomes particularly important where UK and EU offices use different documentary or digital assurance routes.
What will we need to know about our digital ID providers that we may not ask today?
Firms will need to understand which assurance framework the provider meets, in which jurisdictions and whether its EU service satisfies eIDAS “substantial” or “high” assurance.
What will we need to change in our verification workflow from day one?
At minimum, firms will need to route verification by jurisdiction, ensure EU matters use permitted documentary or eIDAS-compliant digital methods, capture the additional AMLR identity fields and make the beneficial owner register check a required verification step.
How can I check that our EU identity provider meet the required eIDAS assurance level, and what technical standards or conformity assessment, including ETSI TS 119 461 where relevant, would support that claim?
The key standard for KYC is ETSI TS 119 461. It sets detailed requirements for how an identity-proofing service should work, including:
- collection and validation of identity attributes and evidence;
- checking documents for authenticity;
- binding the person to the identity evidence;
- attended and unattended remote identity proofing;
- use of eID means security, record-keeping and auditability of the verification process.
The latest published version is ETSI TS 119 461 V2.1.1 (February 2025). It is now being developed into EN 319 461, with a stable draft produced in July 2026.
eIDAS and AMLR - a hierarchy
AMLR
Says what level of electronic identification is acceptable for CDD
eIDAS
Provides the EU legal framework and assurance levels
ETSI standards
Provide detailed technical requirements for how identity-proofing services can meet parts of that framework.
Additional resources
Bar associations for common jurisdictions
Belgium
- Orde van Vlaamse Balies – witwaspreventie (Flemish bars)
- AVOCATS.BE – anti-blanchiment (French/German-speaking bars, OBFG).
Belgium has no single national bar, so both apply depending on the bar of registration.
France
Conseil National des Barreaux – LBC-FT,
Germany
Italy
Consiglio Nazionale Forense – Antiriciclaggio.
Luxembourg
Ordre des Avocats du Barreau de Luxembourg – LBC-FT.
Netherlands
Nederlandse Orde van Advocaten – Wwft.
Spain
Abogacía Española – Prevención del Blanqueo de Capitales (OPBA).
EU level
- AMLA: regulatory instruments – tracks every guideline and technical standard as it's finalised
- AMLA: public consultations – draft guidance open for comment
- EUR-Lex: Anti-Money Laundering Regulation (AMLR) – the regulation itself
- EUR-Lex: sixth Anti-Money Laundering Directive (AMLD6) – the directive Member States transpose
Cross-border legal profession
- CCBE: anti-money laundering – guidance written for lawyers specifically, bridging UK and EU frameworks