Join the list (opens in a new tab)

Why You Need to Get Ready for AMLR and SCA Before July 2027

If you do business in Europe and conduct identity or anti-money laundering (AML) checks on your customers, from July 2027 your organization will likely need to accept digital credentials as proof of identity verification.

AMLR (opens in a new tab) and eIDAS 2 (opens in a new tab) are European regulations with looming deadlines that will reshape how people share data about themselves. This is not only creating a shift in Europe. It is creating ripple effects across the pond in the US, sparking an urgent global movement towards digital credentials.

Like passkeys have slowly gotten rid of the password, credentials will slowly replace the document upload. Like GDPR reframed how everyone thought about data protection, eIDAS 2 will reframe how everyone shares data about themselves, with consent and privacy at the core.

This matters because it creates a new norm: cryptographically signed data that cannot be altered without detection, shared lawfully by people as part of everyday life. That means less fraud and a better experience for the customer.

In October, EQUS is releasing the private beta for its Developer Toolkit, allowing companies to accept and issue these credentials, people to hold them, and AI agents to present them on their behalf. Most companies are either not aware of this deadline or not ready for it, so we are providing the infrastructure to get ready.

Why Early Adoption of eIDAS 2 and AMLR Is Your Best Business Decision

The regulations are the reason to act now. These are the reasons to be glad you did.

  • ⏱️Onboarding in seconds, not minutes. No passport photo, no selfie, no retyping. The customer taps once and verified data arrives already signed by the issuer. Fewer drop-offs, less manual review.
  • ♻️Verify once, reuse repeatedly. A document check costs money every time it runs. A credential is verified once and presented as many times as needed until it expires or is revoked.
  • 📜Fraud moves to firmer ground. Forged documents and deepfake selfies attack the moment a picture becomes trusted data. With a credential, nobody has to judge whether an image looks real. The verifier checks who issued the data, whether it was altered, and whether it is still valid.
  • ✅Less data, less liability. Ask for "over 18" and receive exactly that, not a date of birth. Smaller GDPR footprint, smaller breach surface, simpler answers for supervisors.
  • 📦One integration, many uses. AML identification, strong customer authentication, age verification, employee onboarding, and powers of attorney all run on the same wallet and the same verification code. Build once against the standards, reuse across use cases and jurisdictions.

The European Commission calls the acceptance mandate a "catalyst for broad deployment." The legal minimum is narrow. The infrastructure it forces into existence is general-purpose.

Three Deadlines You Need to be Ready for, Starting Now

An October 2026 through December 2027 timeline

1. December 24, 2026. Every EU member state must offer a free EUDI Wallet to its citizens. National registers of relying parties (the businesses that request and check credentials) open the same day.

2. July 10, 2027. AMLR applies directly across the EU. For remote customer identification it points to a notified national eID, a EUDI Wallet, or a qualified trust service.

3. December 24, 2027. Under eIDAS 2 Article 5f, regulated businesses that must use strong user authentication have to accept the EUDI Wallet whenever a customer chooses it. This is where the Strong Customer Authentication (SCA) regime and the wallet regime meet.

The legal framework has been in force since May 2024 and integration estimates run to twelve to eighteen months. The decisions that determine day-one compliance are being made today. The deadline is non-negotiable. The business benefits? Those are the reason to move fast now.

What is AMLR and SCA

Here’s a summary of what you need to know about AMLR and SCA.

  • AMLR changes how obliged entities (companies legally required to conduct identity and AML checks in Europe) identify and verify customers, and which methods count.
  • eIDAS 2 builds the European Digital Identity framework: the EUDI Wallet, the trust lists, qualified trust services, and the rules for relying on all of them.
  • Strong Customer Authentication (SCA) governs how customers authenticate for payments and account access, and from December 2027 carries its own wallet acceptance obligation for relying parties in specified sectors.

These three changes build on different laws that complement each other. Each builds a different layer, moving towards a trusted digital world for people, organizations and AI agents. We will go through each of them in more detail.

AMLR: one rulebook instead of 27

Until now, EU anti-money laundering rules came as directives that each member state implemented differently. AMLR (Regulation (EU) 2024/1624) replaces that patchwork with a single regulation that applies directly everywhere. The rules now say which identification methods are acceptable instead of leaving each national regulator to decide, and a single new supervisor, the Anti-Money Laundering Authority (AMLA) in Frankfurt, coordinates enforcement across the EU.

The change that matters most for system design is that a customer check stops being a one-time event. Under AMLR you keep watching the relationship after onboarding. You refresh what you know about the customer on a schedule set by their risk level, and you keep a record of every identity decision, and when you made it, that a supervisor can inspect and nobody can quietly alter. New customers onboarded from July 10, 2027 must go through the new process from day one. Existing customers are moved onto it as their periodic reviews come around.

The three compliant identification routes to create the best business outcomes

AMLR does not define its own identity technology. For remote verification, Article 22(6) points to the eIDAS framework, and in practice that means three routes.

1. Notified eID schemes at eIDAS assurance level substantial or high: France Identité (opens in a new tab), Germany's nPA (opens in a new tab), Sweden's BankID (opens in a new tab), Belgium's itsme (opens in a new tab), and more than 20 others, now interoperable across borders.

2. The EUDI Wallet, holding government-verified Person Identification Data (PID) plus additional attestations, with selective disclosure built in. Twenty-seven national wallets is the start; accredited private wallets will sit alongside them.

3. Qualified trust services from providers on national trusted lists. A Qualified Electronic Signature (QES) (opens in a new tab) is issued only after verified identification. A Qualified Electronic Attestation of Attributes (QEAA) (opens in a new tab) is a signed credential asserting specific facts with a legal presumption of accuracy.

The only hard acceptance mandate is the EUDI Wallet one under eIDAS 2 Article 5f, and it binds relying parties in the listed sectors rather than every obliged entity. Wallet use is voluntary for the customer, and adoption will take time, so a compliant flow keeps all three routes open with Qualified Trust Service Provider (QTSP) backed identity proofing as the fallback.

From verifying documents to verifying data

The deepest shift is in what gets checked, and it is a progression from what happens today to what happens next:

  • Today: does this document image look authentic, unaltered, and presented by its holder?
  • Tomorrow: who issued this data, has it been altered, is it still valid, and do I trust the issuer?

The object of verification moves from the picture to the signature.

Flow diagram: a wallet credential meets EU AMLR identification and eIDAS 2 strong authentication.

The KYC file changes accordingly. It no longer needs to be an archive of scans. It needs to show what data was received, from whom, when, and with what result. A credential verification log answers all four in one record.

Two things a credential does not do. It does not tell you whether a customer is a politically exposed person, on a sanctions list, or where their funds come from; those checks remain. And it does not automatically cover everything AMLR requires: residential address, national ID number, and tax ID are in scope but not consistently in the PID data set. That is the attribute gap, and QEAAs are how it gets filled. The question for a compliance team is not "did the customer use a wallet?" but "does the data we received match what Article 22 requires?"

SCA: eIDAS 2 meets payments

Strong Customer Authentication has applied in European payments since PSD2 (opens in a new tab): two independent factors, dynamically linked to the transaction. eIDAS 2 does not replace it. It adds an acceptance obligation. From December 24, 2027, private relying parties in banking and payments, telecommunications, energy, transport, health, education, and very large online platforms must accept the EUDI Wallet wherever law or contract requires strong user authentication online. Point-of-sale and ATM are outside it, and microenterprises and small enterprises are exempt.

The wallet is built for SCA: device-bound key for possession, biometric or PIN for inherence or knowledge, transaction-bound presentation for dynamic linking. The payments rulebook itself moves from PSD2 to the Payment Services Regulation by 2027, and industry taskforces are still mapping wallet authentication onto the technical standards. Expect more guidance.

Two rules that change how you design, not just what you build

Most of the regulation is about which methods are acceptable and when. Two provisions go further: they change the shape of a compliant onboarding flow, so they are worth settling before anyone writes code.

Relying party registration. Before requesting wallet data, a business registers in its member state, declaring its purpose and the exact attributes it will request. The wallet checks each request against that declared scope and warns the user if a request exceeds it. Data minimization stops being a policy and becomes a checkable constraint.

Free qualified signatures. Every wallet holder can create a QES free of charge for non-professional use. Contracts, mandates, and consents can be signed in the same flow as identification.

What preparation looks like

  • Map each customer journey against the minimum data AMLR requires and what the wallet provides. Identify what fills the gap.
  • Register as a relying party and define the declared scope carefully.
  • Write a wallet acceptance policy: which attestations, which issuers, how validated, how recorded.
  • Integrate ARF-conformant verification that accepts any member state's wallet.
  • Keep every route open so no single method is a single point of failure.

And avoid the bare-minimum trap: a "Use EUDI Wallet" button in front of a flow that still demands a form, a document upload, and a selfie. The value is in receiving exactly the trusted data a journey needs and redesigning the journey around it.

Who is Affected

The short answer is: more organizations than most people expect. AMLR reaches well beyond banks, eIDAS 2 reaches well beyond finance, and the age and eligibility rules reach consumer platforms that have never run a KYC process. If your business falls into any of the groups below, the deadlines above apply to you, and the preparation steps are the same whichever group you are in.

1. Obliged entities under AMLR. Banks, payment and e-money institutions, insurers, investment firms, crypto-asset service providers, auditors, accountants, tax advisors, notaries and lawyers in financial transactions, estate agents, high-value goods dealers, and gambling operators. The obligation attaches to any institution with European operations. A US bank with a Frankfurt branch is an obliged entity for its European business.

2. Relying parties under eIDAS 2 SCA. Every medium or large business in the Article 5f sectors that must use strong authentication online. One estimate puts the number of European businesses needing to comply by end 2027 at around 100,000.

3. Everyone verifying age or eligibility. The EU age-proof scheme runs on EUDI Wallets from December 2026 and UK under-16 requirements follow in December 2027. Gambling, adult content, alcohol, tobacco, and social platforms all face the same question.

The rest of the world. Mobile driver's licenses on the ISO 18013-5 standard are live or in progress in more than 21 US states, and that is one of the two formats the EUDI Wallet uses. The forcing function is European. The technology is global.

Where does EQUS fit

At EQUS, we’ve leveraged our team’s deep technical expertise and years of working in the credentialing sector to bring European businesses, fintechs, and regulated companies a solution so they can prepare early.

Strip away the article numbers and every affected business is left with two infrastructure problems:

1. Accepting credentials. Receive a presentation, verify it against the issuer's trust anchor, check revocation, apply the attributes, record the outcome.

2. Issuing credentials. Turn a completed verification into a reusable signed attestation so the customer is never verified from scratch twice.

The EQUS Developer Toolkit does both, and gives you the building blocks to get ready for AMLR and SCA well ahead of the deadlines, including:

1. Accepting. OpenID4VP presentation requests, verification of SD-JWT VC and ISO 18013-5 mdoc (the two supported EU formats), revocation via IETF Token Status Lists, issuer trust via did:web and X.509 chains. Request only the attributes you need, receive a selectively disclosed presentation from any conformant wallet, get a structured result with a signed audit record.

2. Issuing. OpenID4VCI issuance. Complete an identity verification once and issue the customer a credential they present back for re-authentication or to other relying parties who trust you. Ongoing due diligence becomes a credential refresh. A change of address becomes a single attribute presentation.

3. Holding. EQUS Wallet, a mobile non-custodial wallet, puts credentials in customers' hands before national wallets reach mass adoption and serves customers outside the EU who will never hold one.

4. Delegating trust to your AI agent. Once a credential represents trusted identity and attributes, an authorized agent can present it too. EQUS X plans to allow AI agents to present credentials and authorize payments within delegated limits, through AP2 and Verifiable Intent, answering the same questions SCA asks of a person: who is acting, and what are they allowed to do.

5. The qualified layer. The Developer Toolkit is infrastructure, not a QTSP. Following the beta, EQUS is working with regulated banking partners in Europe and the US to bring qualified and bank-issued credentials onto the platform.

6. Open standards, open source. The EQUS Credentials SDK (opens in a new tab) is Apache 2.0. Nothing in the stack depends on a proprietary format or a single wallet vendor, which matters when the requirement is to accept 27 national wallets and an unknown number of private ones.

Getting Ahead of AMLR and eIDAS 2 Isn't Just Compliance, It's a Cheat Code to Better Business Outcomes

Early movers across Europe that prepare early will gain speed, security, and get a competitive advantage. The regulations were coming anyway, so make them work for you.

July 2027 is the deadline for identification. December 2027 is the deadline for authentication. The more important change is the one those dates accelerate: credentials do not just replace the document upload. They let every business receive identity and attribute data that is signed at source, carried by the person, and checked by machine, and issue that data as readily as they consume it.

Your competitors will scramble in 2027, while you'll have better business outcomes because you prepared in 2026. EQUS has given you the playbook to succeed and get ready for AMLRand eIDAS 2.

The EQUS Developer Toolkit private beta opens in October. If you are getting ready, we would like to talk.

Make sure your AI answers to you

Get started