October 2026 Summaries
11 posts from Didit
Filter
Month:
Year:
Post Summaries
Back to Blog
From 10 July 2027, the EU Anti-Money Laundering Regulation (AMLR) will classify most crypto-asset service providers (CASPs) as financial institutions, requiring them to conduct customer due diligence, monitor relationships, retain records, and prevent anonymous crypto-asset accounts. CASPs must identify and verify customers even for occasional transactions below EUR 1,000, while transactions of EUR 1,000 or more trigger fuller due-diligence requirements such as beneficial-owner checks, risk assessment, sanctions screening, and ongoing monitoring. The regulation does not generally ban privacy-oriented crypto-assets or self-hosted wallets for individuals, but prohibits providers from maintaining accounts that enable customer or transaction anonymisation, including through anonymity-enhancing coins. Transfers involving self-hosted addresses remain permitted but require risk assessment and mitigating measures under the AMLR, while the already applicable Transfer of Funds Regulation requires ownership or control checks for such transfers above EUR 1,000. MiCA supplies the definition of a CASP, the AMLR establishes anti-money-laundering obligations, and the Transfer of Funds Regulation governs transfer-related information requirements. From 2028, the Anti-Money Laundering Authority may directly supervise a limited number of high-risk, cross-border CASPs, while most will remain overseen by national authorities.
Oct 03, 2026
2,960 words in the original blog post.
Under the EU Anti-Money Laundering Regulation (AMLR), applicable from 10 July 2027, a beneficial owner of a corporate entity is a natural person who directly or indirectly holds 25% or more of its shares, voting rights, profit rights, or other ownership interests, or who exercises control through ownership or other means. Ownership and control tests must be assessed independently and in parallel, meaning a person with less than 25% may still qualify through rights such as appointing a board majority, veto powers, decision rights, agreements, family relationships, or nominee arrangements. Indirect interests are calculated by multiplying holdings through each ownership chain and adding interests across multiple chains, although more complex structures involving control may require additional analysis under Article 54. As of 2 October 2026, no delegated act had lowered the general 25% threshold to 15% for higher-risk entities. Obliged entities must identify and verify beneficial owners, understand the full ownership and control structure, consult central beneficial ownership registers in addition to conducting independent verification, screen relevant parties for sanctions and politically exposed person status, and report material register discrepancies within 14 calendar days. If no beneficial owner can be identified after all reasonable efforts, firms must document this outcome and identify and verify every senior managing official. Trusts, foundations, and similar arrangements follow separate AMLR provisions, while outsourced verification providers may support compliance work but cannot assume the obliged entity’s responsibility for risk assessment or onboarding decisions.
Oct 03, 2026
2,932 words in the original blog post.
Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation (AMLR), will apply directly across all EU Member States from 10 July 2027, replacing the prior directive-based framework for business-facing anti-money-laundering requirements, while football agents and professional clubs will be covered from 2029. It establishes harmonized rules on customer due diligence, identity verification, beneficial ownership, sanctions screening, recordkeeping, cash-payment limits, outsourcing, and human oversight of automated onboarding decisions for banks, crypto-asset service providers, legal and accounting professionals, real-estate intermediaries, gambling firms, luxury-goods traders, and other obliged entities. AMLD6 separately requires Member States to implement supervisory, registry, and penalty provisions, including minimum maximum sanctions for serious breaches, while the Frankfurt-based AMLA will develop technical standards and directly supervise a limited group of high-risk financial institutions beginning in 2028 without replacing national supervisors. As of 2 October 2026, AMLA had submitted final drafts of several technical standards to the European Commission, but these drafts were not yet legally binding. The regulation retains a 25% beneficial-ownership threshold, caps certain professional cash transactions at EUR 10,000, permits justified remote identity verification, and maintains that firms remain fully liable for outsourced compliance activities.
Oct 03, 2026
2,929 words in the original blog post.
EU rules distinguish between the European Digital Identity (EUDI) Wallet acceptance obligation under eIDAS 2 and customer identity verification requirements under the Anti-Money Laundering Regulation (AMLR). eIDAS Article 5f(2) requires larger private service providers that are subject to strong online authentication requirements to accept compliant wallets at a user’s request, while exempting micro and small enterprises; based on the first implementing act’s entry into force, the text calculates this deadline as 24 December 2027. The AMLR, applicable from 10 July 2027, treats electronic identification at substantial or high assurance as one permitted method of identity verification, with EUDI Wallets meeting the high-assurance threshold, but it does not itself impose the broader wallet-acceptance duty in its operative provisions. A wallet can verify personal identity attributes that it contains, though firms must obtain missing information through other means and still complete separate due-diligence tasks such as identifying beneficial owners, assessing relationship purpose and risk, conducting sanctions and politically exposed person screening, and monitoring customers over time. Identity documents remain a valid alternative verification route, including for remote onboarding with appropriate safeguards, while proposed AMLA technical standards support the use of qualifying national eID schemes and wallets but were not yet legally binding at the time described.
Oct 03, 2026
2,894 words in the original blog post.
EU Anti-Money Laundering Regulation (AMLR) Article 22, applicable from 10 July 2027, requires firms to collect and verify prescribed identity data for customers and their representatives using either identity documents supplemented where needed by reliable independent sources, or qualifying electronic identification and trust services at substantial or high assurance levels. AMLA’s 30 September 2026 final draft technical standards, which are not yet adopted or legally binding, present eID as the preferred remote-onboarding route while allowing document-based remote verification only where a customer cannot reasonably use in-person document submission or qualifying eID, subject to case-specific justification and safeguards such as holder controls, secure communications, adequate image or video quality, process termination when doubts arise, and secure time-stamped records. The text emphasizes that neither the AMLR nor the draft specifically mandates video calls, liveness detection, biometrics, selfies, or NFC chip reading, although liveness appears in existing EBA remote-onboarding guidelines whose status after July 2027 remains uncertain. It also notes that identity verification is only one part of customer due diligence, which additionally includes beneficial ownership, purpose, sanctions, and ongoing-monitoring checks, and promotes Didit as a provider supporting both digital-ID and document-based workflows.
Oct 03, 2026
2,873 words in the original blog post.
Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation (AMLR), will apply directly across Member States from 10 July 2027, with football agents and professional clubs covered from 10 July 2029, replacing national rules derived from the current directive after the transition period. It applies to credit and financial institutions, including crypto-asset service providers, and specified professionals and traders such as lawyers, estate agents, gambling operators, crowdfunding platforms, and high-value-goods dealers, while a EUR 10,000 cash-payment cap broadly applies even to businesses that are not obliged entities. All covered organisations must implement risk-based controls including documented risk assessments, approved policies, compliance roles, customer due diligence, beneficial-ownership checks, sanctions and politically exposed person screening, transaction monitoring, FIU reporting, record retention, staff training, and outsourced-provider oversight. Sector-specific rules establish different thresholds and duties, including EUR 1,000 for certain payment and crypto transfers, EUR 2,000 for gambling transactions, EUR 3,000 for cash identification, and EUR 10,000 for general occasional transactions, alongside tailored requirements for areas such as virtual IBANs, self-hosted crypto wallets, real estate, and high-value assets. Draft technical standards from the EU Anti-Money Laundering Authority may add detail but are not yet law, and although software can support verification, screening, monitoring, and evidence collection, firms remain responsible for risk decisions, customer acceptance, FIU reporting, and compliance liability.
Oct 03, 2026
2,908 words in the original blog post.
From 10 July 2027, the EU Anti-Money Laundering Regulation will cap cash payments in trade at EUR 10,000, requiring businesses that sell goods or provide services not to accept or make larger cash payments, including through linked instalments. The ceiling does not apply to non-professional payments between private individuals or to deposits and payments made at banks and payment providers, although large bank deposits may be reported to financial intelligence units. Member States may retain or introduce lower national cash limits, meaning businesses must follow whichever applicable threshold is lower. Separately, EUR 3,000 is not a payment cap but a customer-identification threshold for AMLR “obliged entities,” such as certain high-value-goods traders, which must verify a customer’s identity before occasional cash transactions at or above that amount and retain relevant records for five years. Businesses covered by the rules may face national penalties for breaches, while the regulation’s treatment of linked transactions prevents customers from avoiding limits by dividing a single purchase into smaller cash payments.
Oct 03, 2026
2,986 words in the original blog post.
AMLA submitted final draft regulatory technical standards on customer due diligence, business relationships and group-wide requirements to the European Commission on 1 October 2026, but the drafts are not yet legally binding and may be amended before Commission adoption and Official Journal publication. While the AMLR itself will apply from 10 July 2027, the proposed CDD standard would generally apply six months after entering into force, with football agents and professional football clubs deferred until July 2029. The draft maintains identity documents and qualified electronic identification at substantial or high assurance levels as the default verification methods, allowing remote document-based onboarding only when those methods are unavailable and requiring firms to justify its use and retain evidence. It requires verification of all required customer data, supplemental sources for missing information and beneficial ownership checks, risk-sensitive PEP monitoring, sanctions screening at onboarding and after relevant changes, and remediation of existing customer files within one year for higher-risk clients and five years for others. AMLA rejected calls to extend refresh intervals, adopt broadly risk-based sanctions screening, reduce required verification data, or expand simplified due diligence, while other guidance on risk assessment, ongoing monitoring, reporting, outsourcing and related issues remains pending.
Oct 03, 2026
2,939 words in the original blog post.
The EU Anti-Money Laundering Regulation (AMLR), which applies from 10 July 2027, does not prescribe or certify a single compliance product but requires obliged entities to maintain adequate staff, technology, controls, and evidence across identity verification, beneficial-ownership checks, sanctions and PEP screening, customer updates, transaction monitoring, suspicious-activity reporting, record retention, human review of automated decisions, and audit trails. The text distinguishes commodity services that firms can buy, such as document and electronic-ID verification, registry data, and screening lists, from risk models, monitoring criteria, onboarding decisions, and FIU reporting responsibilities that remain with the regulated firm, which also retains legal liability for outsourced work. It advises buyers to support both high-assurance eID and document-based verification, retain reasons and timestamps for verification choices, provide meaningful human intervention in automated decisions, and assess vendors’ data locations, pricing, retention controls, exportability, screening triggers, review tooling, and exit arrangements. Cost estimates should account for new customers, periodic refreshes, monitored individuals, and manual-review time, while vendor claims of AMLR certification, full liability transfer, or complete due diligence through a single wallet check are characterized as unsupported. The text notes that AMLA’s customer-due-diligence technical standards were still final drafts as of October 2026, then presents Didit as an example provider for verification, screening, monitoring, and workflow capabilities while emphasizing that customers retain compliance decisions and liability.
Oct 03, 2026
2,851 words in the original blog post.
Under the EU Anti-Money Laundering Regulation (AMLR), which applies from 10 July 2027, Article 18 permits obliged entities to outsource certain compliance tasks to qualified service providers but requires prior notification to supervisors, written agreements, regular oversight, and continued full liability by the firm. Six functions cannot be outsourced: approving the business-wide risk assessment, internal policies and controls, customer risk profiles, onboarding or transaction decisions, suspicious activity reporting to financial intelligence units, and transaction-monitoring criteria. The regulation distinguishes outsourcing from reliance on another obliged entity, which is limited to selected due-diligence elements, and from use of software, databases, or screening tools where the firm itself performs the regulatory task. Automated KYC and identity-verification services remain a regulatory grey area, particularly where provider systems make substantive verification determinations. Outsourcing is restricted for providers established in certain high-risk third countries, while firms must ensure supervisors can trace compliance and retain access to evidence and records. AMLA is expected to issue outsourcing guidelines by the regulation’s start date, but no draft guidance was publicly available as of 2 October 2026, leaving firms to document their own classifications and controls in the interim.
Oct 03, 2026
2,888 words in the original blog post.
Didit will introduce a new credit-based pricing model on November 1, 2026, replacing its current allowance of 500 free monthly checks for limited features with $10 in monthly credit usable across identity verification, business checks, transaction monitoring, and other services. The company says the change reflects its expansion from ID and face verification into fraud detection, crypto compliance, company verification, government databases, digital ID wallets, and planned AI agents. Users may remain on a no-fee Free plan with no minimum commitment, paying list prices after using their monthly credit, while Growth and Scale plans cost $99 and $299 per month and include $115 and $350 in credit respectively, along with 4% or 10% discounts, expanded team access, support, and selected tools. Identity Verification and Transaction Monitoring & Travel Rule will have separate plan selections but share a single account, team, invoice, and credit balance, with top-up funds valid for 12 months while free and plan credit resets monthly. The announced pricing retains list prices for full ID checks and watchlist screening, keeps the sandbox free and unlimited, and adds forthcoming AI agents for paid plans to automate case reviews and recovery of incomplete verification sessions.
Oct 02, 2026
1,819 words in the original blog post.