Brief conclusion
In the case of low risk, the relief is smaller than many expected. AMLA has expressly not created any additional relief beyond Art. 33 AMLR. In the case of increased risk, on the other hand, the draft is significantly more specific, particularly regarding the proof of Source of funds and origin of assets. The actual change therefore lies less in the reduction than in the documentation.
Why simplified due diligence measures are not a waiver
Recital 78 of the AMLR clarifies that simplified due diligence measures do not constitute an exemption from regular due diligence. They represent a reduced scope of verification that must cover all elements of the standard procedure. This assessment runs through the entire draft.
AMLA examined in the consultation paper whether relaxations going beyond Article 33 AMLR would be possible. The result is clear: additional measures would have effectively created exemptions and thus exceeded the mandate. Article 33 AMLR itself already contains a bundle of relaxations, such as the possibility of postponing the verification by up to 60 days or reducing the scope of information regarding the purpose and intended nature of the business relationship.
In practice, this means: anyone who was hoping for generous new relaxations will not find them in Level 2 legislation.
What must be assessed as a minimum in the event of low risk
The draft defines a minimum standard that roughly corresponds to the information content of a passport.
For natural persons:
- all first and last names
- Place of birth
- Date of birth
- Nationalities or statelessness, refugee status or subsidiary protection status
For legal entities and other organizations with legal capacity:
- the legal form
- the registered name and a trade name differing therefrom
- the registered office address
- where available, the registration number, the tax identification number or the Legal Entity Identifier
These requirements also apply to persons purporting to act on behalf of the customer, as well as to persons on whose behalf or for whose benefit a transaction is carried out.
The two-source principle regarding the beneficial owner
A detail with significant practical effect concerns the verification of the beneficial owner in low-risk cases. For identification purposes, a single source from a catalog is sufficient: the central register or company or business register, information provided by the customer including already existing information, or publicly available information from a reliable, independent open source.
However, for verification, another source must be used that has not already been used for identification. Information provided by the customer or publicly available information is permitted for this purpose.
Anyone who currently relies equally on the excerpt from the Register of Beneficial Owners (WiEReG) for both identification and verification of the beneficial owner must adapt this process. Even in low-risk cases, the draft requires two independent sources of information.
Reduced update frequency with conditions
Art. 33 para. 1 lit. b AMLR permits a lower update frequency. The draft ties this to the monitoring of the business relationship. The obliged entity must ensure that the circumstances relevant to the assessment have not changed, that no event triggering an update has occurred, and that no suspicious or unusual transactions have been detected that would be inconsistent with a low-risk relationship.
The reduced frequency is therefore not automatic, but rather the result of ongoing monitoring. In any case, the update obligations pursuant to Art. 26 para. 2 lit. b AMLR remain in place.
Collective accounts as sector-specific relief
The draft contains a targeted relief for credit institutions that open an account on which the account holder manages funds of their own clients. Among other things, the prerequisite is that the account holder is themselves a regulated entity subject to effective supervision, that they provide the required information immediately upon request, that the risk of the business relationship is low, and that the credit institution is convinced of the account holder's robust, risk-sensitive due diligence measures.
The distinction is important: according to the recitals, payment accounts for payment institutions or electronic money institutions are not covered. Such constellations are considered correspondent banking relationships within the meaning of the AMLR.
This provision is of direct interest to Austrian lawyers in connection with escrow accounts.
What is additionally required in the event of an increased risk
Article 34(4) AMLR lists four categories of additional measures.
Additional information on the customer and beneficial owner
The information must make it possible to verify the authenticity and correctness of the available details, to evaluate the reputation, or to comprehensively identify and assess the risks, including known close connections.
Additional information on the intended nature of the business relationship
This is about plausibility. The obliged entity must be able to assess whether the use of funds corresponds to the declared nature of the business relationship and the risk profile, and whether the expected number, size, type, volume, and frequency of transactions match the declared business activity, source of funds, or source of wealth. The draft explicitly mentions information on key customers, contracts, and business partners for this purpose.
Source of funds and source of wealth
This is the most practically complex point. The draft requires information that convinces the obligated party that funds and assets originate from lawful activities and lists a catalog of suitable evidence:
- Proof of income such as tax returns, recent pay stubs, or other official proof of income
- audited financial statements, investment documentation, credit line and loan agreements
- for properties public deeds or extracts from the land register or population registry
- Documents relating to inheritances, gifts, and settlements, as well as confirmations from certified independent professionals or authorities
- Purchase agreements or written sales confirmations
- Information from reliable asset or public registers
- authentic information from reputable media publications or from reputable commercial providers
- other information from independent and reliable sources with a high degree of certainty
The catalog is not to be understood as cumulative. One or more items are sufficient, provided the objective of persuasion is achieved. The crucial factor is the traceability of the chain.
Reasons for the transaction and consistency
The obliged entity must be able to assess whether the stated reason is credible and consistent with the customer knowledge, whether the totality of the transactions matches the activity carried out and the turnover, and whether increased risks involving parties including intermediaries need to be clarified.
The principle against double collection
One point that facilitates implementation: according to the recitals, obligated entities should first check whether the required information is already available, for example from the investment profile, the mandate relationship, or an order acceptance procedure, and if applicable, also from other obligated entities within the same group. Only if this information is not sufficient should additional information be obtained.
This is an order for internal data use, not a blank check. The available information must be suitable for the respective audit purpose.
Practical consequences
The supposedly simpler side of the scale creates a need for adjustments regarding the two-source principle and the justification of reduced update cycles. The demanding side creates a need for documentation.
Obligated entities should therefore check three things:
- Risk classification. The low-risk classification must be robustly documented because it justifies relief measures.
- Source map. For each audit procedure, it should be defined which source it bears and whether it meets the criteria of reliability and independence.
- Catalog of evidence for EDD. For the typical case constellations of one's own practice, it should be defined in advance which evidence is considered sufficient.
Your next step
The classification of a business relationship as low or high risk determines the effort and liability involved. The certified anti-money laundering attorneys at ATB.LAW assist in designing risk-based due diligence processes, defining catalogs of evidence, and handling documentation for regulatory authorities.
Write to us: Anela Blöch (bloech@atb.lawRoman Taudestaudes@atb.law)
FAQ:
Does the RTS bring new reliefs for low risk?
No. AMLA stated in the consultation paper that no additional measures beyond the simplifications of Art. 33 AMLR were identified without exceeding the mandate.
May the review be postponed in the event of low risk?
Art. 33 AMLR provides for the possibility of postponing the review by up to 60 days. This relief arises from the regulation itself.
Is the WiEReG extract sufficient for low risk?
For the identification of the beneficial owner, a register search may be sufficient. For verification, the draft requires another source that has not already been used for identification.
What documents are accepted as proof of source of funds in cases of elevated risk?
The draft lists, among other things, tax returns, pay slips, audited financial statements, loan agreements, land register extracts, documents relating to inheritances and gifts, purchase agreements, and information from reliable registers.
Does the relief for collective accounts also apply to lawyers' trust accounts?
The draft focuses on credit institutions that open an account in which the account holder manages funds belonging to their clients, and makes this subject to several cumulative requirements. Application to specific fiduciary account constellations is to be assessed on a case-by-case basis.
Do I need to re-collect information that I already have?
No. The recitals explicitly require examining first whether existing information serves the purpose before comparable data is collected again.