Compliance

Simplified and enhanced due diligence measures under the AMLR

The AMLA Draft in Detail

The risk-based approach is the backbone of anti-money laundering. It determines where resources are deployed. The draft AMLA technical regulatory standards on Article 28(1) of Regulation (EU) 2024/1624 define the extent to which obliged entities may reduce measures in cases of low risk and what additional information must be collected in cases of high risk. This article examines both ends of the scale.

Simplified and enhanced due diligence measures under the AMLR

Table of Contents

Brief conclusion

In the case of low risk, the relief is smaller than many expected. AMLA has expressly not created any additional relief beyond Art. 33 AMLR. In the case of increased risk, on the other hand, the draft is significantly more specific, particularly regarding the proof of Source of funds and origin of assets. The actual change therefore lies less in the reduction than in the documentation.

Why simplified due diligence measures are not a waiver

Recital 78 of the AMLR clarifies that simplified due diligence measures do not constitute an exemption from regular due diligence. They represent a reduced scope of verification that must cover all elements of the standard procedure. This assessment runs through the entire draft.

AMLA examined in the consultation paper whether relaxations going beyond Article 33 AMLR would be possible. The result is clear: additional measures would have effectively created exemptions and thus exceeded the mandate. Article 33 AMLR itself already contains a bundle of relaxations, such as the possibility of postponing the verification by up to 60 days or reducing the scope of information regarding the purpose and intended nature of the business relationship.

In practice, this means: anyone who was hoping for generous new relaxations will not find them in Level 2 legislation.

What must be assessed as a minimum in the event of low risk

The draft defines a minimum standard that roughly corresponds to the information content of a passport.

For natural persons:

  • all first and last names
  • Place of birth
  • Date of birth
  • Nationalities or statelessness, refugee status or subsidiary protection status

For legal entities and other organizations with legal capacity:

  • the legal form
  • the registered name and a trade name differing therefrom
  • the registered office address
  • where available, the registration number, the tax identification number or the Legal Entity Identifier

These requirements also apply to persons purporting to act on behalf of the customer, as well as to persons on whose behalf or for whose benefit a transaction is carried out.

The two-source principle regarding the beneficial owner

A detail with significant practical effect concerns the verification of the beneficial owner in low-risk cases. For identification purposes, a single source from a catalog is sufficient: the central register or company or business register, information provided by the customer including already existing information, or publicly available information from a reliable, independent open source.

However, for verification, another source must be used that has not already been used for identification. Information provided by the customer or publicly available information is permitted for this purpose.

Anyone who currently relies equally on the excerpt from the Register of Beneficial Owners (WiEReG) for both identification and verification of the beneficial owner must adapt this process. Even in low-risk cases, the draft requires two independent sources of information.

Reduced update frequency with conditions

Art. 33 para. 1 lit. b AMLR permits a lower update frequency. The draft ties this to the monitoring of the business relationship. The obliged entity must ensure that the circumstances relevant to the assessment have not changed, that no event triggering an update has occurred, and that no suspicious or unusual transactions have been detected that would be inconsistent with a low-risk relationship.

The reduced frequency is therefore not automatic, but rather the result of ongoing monitoring. In any case, the update obligations pursuant to Art. 26 para. 2 lit. b AMLR remain in place.

Collective accounts as sector-specific relief

The draft contains a targeted relief for credit institutions that open an account on which the account holder manages funds of their own clients. Among other things, the prerequisite is that the account holder is themselves a regulated entity subject to effective supervision, that they provide the required information immediately upon request, that the risk of the business relationship is low, and that the credit institution is convinced of the account holder's robust, risk-sensitive due diligence measures.

The distinction is important: according to the recitals, payment accounts for payment institutions or electronic money institutions are not covered. Such constellations are considered correspondent banking relationships within the meaning of the AMLR.

This provision is of direct interest to Austrian lawyers in connection with escrow accounts.

What is additionally required in the event of an increased risk

Article 34(4) AMLR lists four categories of additional measures.

Additional information on the customer and beneficial owner

The information must make it possible to verify the authenticity and correctness of the available details, to evaluate the reputation, or to comprehensively identify and assess the risks, including known close connections.

Additional information on the intended nature of the business relationship

This is about plausibility. The obliged entity must be able to assess whether the use of funds corresponds to the declared nature of the business relationship and the risk profile, and whether the expected number, size, type, volume, and frequency of transactions match the declared business activity, source of funds, or source of wealth. The draft explicitly mentions information on key customers, contracts, and business partners for this purpose.

Source of funds and source of wealth

This is the most practically complex point. The draft requires information that convinces the obligated party that funds and assets originate from lawful activities and lists a catalog of suitable evidence:

  • Proof of income such as tax returns, recent pay stubs, or other official proof of income
  • audited financial statements, investment documentation, credit line and loan agreements
  • for properties public deeds or extracts from the land register or population registry
  • Documents relating to inheritances, gifts, and settlements, as well as confirmations from certified independent professionals or authorities
  • Purchase agreements or written sales confirmations
  • Information from reliable asset or public registers
  • authentic information from reputable media publications or from reputable commercial providers
  • other information from independent and reliable sources with a high degree of certainty

The catalog is not to be understood as cumulative. One or more items are sufficient, provided the objective of persuasion is achieved. The crucial factor is the traceability of the chain.

Reasons for the transaction and consistency

The obliged entity must be able to assess whether the stated reason is credible and consistent with the customer knowledge, whether the totality of the transactions matches the activity carried out and the turnover, and whether increased risks involving parties including intermediaries need to be clarified.

The principle against double collection

One point that facilitates implementation: according to the recitals, obligated entities should first check whether the required information is already available, for example from the investment profile, the mandate relationship, or an order acceptance procedure, and if applicable, also from other obligated entities within the same group. Only if this information is not sufficient should additional information be obtained.

This is an order for internal data use, not a blank check. The available information must be suitable for the respective audit purpose.

Practical consequences

The supposedly simpler side of the scale creates a need for adjustments regarding the two-source principle and the justification of reduced update cycles. The demanding side creates a need for documentation.

Obligated entities should therefore check three things:

  1. Risk classification. The low-risk classification must be robustly documented because it justifies relief measures.
  2. Source map. For each audit procedure, it should be defined which source it bears and whether it meets the criteria of reliability and independence.
  3. Catalog of evidence for EDD. For the typical case constellations of one's own practice, it should be defined in advance which evidence is considered sufficient.

Your next step

The classification of a business relationship as low or high risk determines the effort and liability involved. The certified anti-money laundering attorneys at ATB.LAW assist in designing risk-based due diligence processes, defining catalogs of evidence, and handling documentation for regulatory authorities.

Write to us: Anela Blöch (bloech@atb.lawRoman Taudestaudes@atb.law)

 


FAQ:


Does the RTS bring new reliefs for low risk?

No. AMLA stated in the consultation paper that no additional measures beyond the simplifications of Art. 33 AMLR were identified without exceeding the mandate.


May the review be postponed in the event of low risk?

Art. 33 AMLR provides for the possibility of postponing the review by up to 60 days. This relief arises from the regulation itself.


Is the WiEReG extract sufficient for low risk?

For the identification of the beneficial owner, a register search may be sufficient. For verification, the draft requires another source that has not already been used for identification.


What documents are accepted as proof of source of funds in cases of elevated risk?

The draft lists, among other things, tax returns, pay slips, audited financial statements, loan agreements, land register extracts, documents relating to inheritances and gifts, purchase agreements, and information from reliable registers.


Does the relief for collective accounts also apply to lawyers' trust accounts?

The draft focuses on credit institutions that open an account in which the account holder manages funds belonging to their clients, and makes this subject to several cumulative requirements. Application to specific fiduciary account constellations is to be assessed on a case-by-case basis.


Do I need to re-collect information that I already have?

No. The recitals explicitly require examining first whether existing information serves the purpose before comparable data is collected again.

More articles

NIS2 in Austria: Is your company prepared?

The NIS2 countdown is ticking: Starting October 1, 2026, affected companies must comply with the core requirements of the NISG 2026. Which obligations must now be implemented, why cybersecurity is becoming a management responsibility, and why managing directors and board members must be trained in good time.
Picture of Anela Blöch
Anela Blöch
PEP and sanctions screening according to the draft AMLA

PEP and sanctions screening according to the draft AMLA

Automated testing is becoming the rule
Picture of Anela Blöch
Anela Blöch
AMLA RTS on Anti-Money Laundering Due Diligence Obligations

AMLA RTS on Anti-Money Laundering Due Diligence Obligations

What will face obliged entities from 2027 onwards
Picture of Anela Blöch
Anela Blöch