Structuring KYC profiles for the AMLA single rulebook: Level 2 RTS requirements

Structuring KYC profiles for the AMLA single rulebook: Level 2 RTS requirements

The AML Regulation's Level 2 technical standards specify the data points that KYC profiles must capture for customer due diligence and UBO identification. Moving from loose national implementations to a standardised EU data schema requires a concrete audit of what your onboarding pipeline collects, validates, and retains.

13 min read

This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for advice specific to your situation.

  • The operative change is instrument-level, not just content-level. The AML Regulation (Regulation (EU) 2024/1624) is directly applicable from July 2027. The customer due diligence data points it requires, and that AMLA's Level 2 RTS will specify in detail, are not transposed through national law. They apply identically in every member state. KYC profiles built against national AML law schemas must be audited against the EU-level specification.
  • AMLA holds a substantial number of Level 2 mandates under the AML Regulation. The mandates most directly relevant to KYC data architecture cover: the information to be collected during standard and enhanced customer due diligence; the data points required to identify and verify a beneficial owner or UBO; the minimum content of business relationship monitoring procedures; and the technical standards for data exchange between obliged entities and Financial Intelligence Units. Each mandate produces a separate RTS or ITS with its own publication date.
  • The UBO data schema is where national divergence has been most material. Under successive AML directives, member states specified different data points for UBO identification, different thresholds for the ownership or control test, and different verification standards. The AML Regulation fixes the 25 percent threshold directly and empowers AMLA to specify the data fields required at EU level. Firms that have calibrated UBO collection to a specific national implementation will find gaps in some areas and redundancy in others.
  • The Level 2 mandates are on a staggered timeline relative to the July 2027 application date. Consultations on the most directly relevant RTS, including the CDD data schema (Article 28) and linked transactions thresholds (Article 19(9)), closed in 2026. Firms that wait for final RTS before beginning schema design are compressing their implementation window unnecessarily. AMLA's consultation papers and draft RTS are the relevant tracking target from now.

Why Level 2 matters more than the regulation text for KYC design

The AML Regulation (Regulation (EU) 2024/1624) tells compliance teams that customer due diligence is required, what the trigger conditions are, and what the broad categories of information to be collected include. It does not tell them the exact data fields a KYC profile must contain, the format in which UBO information must be held, or the technical standards for how that information must be exchanged with Financial Intelligence Units or accessed by AMLA's supervisory function.

That level of specification is where the Level 2 regulatory technical standards come in, and for the compliance teams and engineers responsible for building or procuring KYC systems, the Level 2 instruments are more important than the regulation text itself for the purpose of schema design.

This is not unique to the AML framework. It is the structural feature of EU financial regulation that makes tracking the full legislative pipeline, from regulation through to RTS, a precondition for compliance readiness rather than an optional refinement. For the mechanics of how RTS mandates work and why they arrive on a separate timeline from the headline regulation, see what are regulatory technical standards and why do they matter more than the regulation itself.

For the AML Regulation specifically, AMLA holds a substantial number of Level 2 mandates. The mandates most directly relevant to KYC data architecture and UBO schema design are the focus of this article.

The mandate architecture: which RTS govern KYC data

The AML Regulation distributes its Level 2 mandates between AMLA and the European Commission. AMLA develops the technical standards, and the Commission adopts them as delegated or implementing regulations. The result is that the operative CDD data schema will live in a set of instruments with their own CELEX identifiers, distinct from the AML Regulation itself.

The mandates with direct KYC schema implications fall into four clusters.

Standard customer due diligence data points. Article 20 of the AML Regulation requires obliged entities to collect specific customer information during standard CDD. AMLA is mandated under Article 28 to develop RTS specifying the minimum information to be collected and verified for natural persons, legal entities, and legal arrangements. This RTS will define the floor for what a compliant standard CDD profile must contain, across all member states, from July 2027.

Enhanced due diligence data requirements. Articles 34 through 46 of the AML Regulation address enhanced due diligence triggers and the specific measures that must be applied, with Articles 29 through 31 establishing the third-country risk identification framework that feeds into EDD obligations. AMLA is mandated to develop RTS specifying additional information to be collected in EDD contexts, including high-risk third country relationships, complex ownership structures, and specific product risk categories. The EDD data schema is an extension of, not a replacement for, the standard CDD schema, and both must be designed together.

Beneficial ownership identification and verification. Article 28 of the AML Regulation mandates AMLA to develop RTS specifying the information to be collected for customer due diligence, including UBO identification and verification data points. The discrepancy reporting obligation, requiring obliged entities to flag inconsistencies between their UBO records and information held in beneficial ownership registers, is set out in Article 24. These two provisions together define the UBO data collection and governance requirements.

FIU data exchange standards. AMLA holds mandates relating to the technical standards for data exchange between obliged entities and Financial Intelligence Units, including the format and content of suspicious transaction reports and the data points that must accompany them. These mandates are slightly downstream from the KYC schema question but are directly relevant to how KYC-derived data flows out of the obliged entity to public authorities.

The UBO schema: what the AML Regulation establishes directly and what Level 2 will add

The AML Regulation makes several determinations about UBO identification that apply directly, without waiting for Level 2 RTS.

The 25 percent ownership or control threshold for natural persons is fixed in Article 52(1) of the regulation text. The threshold is set at EU level and cannot be unilaterally raised by member states; where the Commission determines by delegated act that specific higher-risk categories warrant a lower threshold, that determination is made at EU level, not by individual member states acting alone. This resolves one of the most significant divergences under the directive framework, where member states applied different ownership thresholds and some required identification of all persons in the control chain regardless of percentage.

The definition of control, which covers both direct and indirect ownership and a range of non-ownership control mechanisms including the right to appoint or remove a majority of the management body, is also set at EU level in the regulation text. Control through legal arrangements, including express trusts and functionally equivalent structures, is addressed specifically in Article 58(1), with the regulation requiring identification of settlors, trustees, protectors, beneficiaries, and any other natural person exercising effective control.

What the Level 2 RTS will add is the specific data fields that must be collected and retained to document the identification and verification of each UBO. The categories that AMLA's draft RTS are expected to address include:

Identity data. Full legal name, date of birth, nationality, country of residence, and national identification number or document reference. The RTS will likely specify acceptable verification documents by category of natural person and by risk level, resolving the current national divergence in what constitutes adequate verification evidence.

Ownership and control data. The specific mechanism through which the UBO meets the threshold: direct shareholding percentage, indirect shareholding percentage with the intermediate entity chain identified, or the specific control mechanism where ownership is not the basis. The regulation requires obliged entities to document the ownership or control structure in a form that allows the pathway to the UBO to be followed, not just to record the UBO's name against a percentage figure.

Verification source and date. The document or source used to verify each data point, and the date on which verification was performed. This is relevant both to the ongoing monitoring obligation and to the discrepancy-reporting requirement under Article 24, which requires obliged entities to flag inconsistencies between their own UBO records and the information held in beneficial ownership registers.

Senior managing official fallback documentation. Where a legal entity cannot, after exhausting all means, identify a natural person who meets the UBO threshold, Articles 22(2) and 63(3)–(4) of the regulation allow the senior managing official to be recorded as the beneficial owner. The conditions for applying this fallback, and what must be documented to demonstrate that the threshold person could not be identified, are expected to be specified in the RTS.

What national divergence looked like and where the gaps will be

Understanding where the EU data schema differs from national implementations requires looking at specific member states. The divergences under the directive framework were not random; they followed from deliberate national policy choices and from the discretion that the directive instrument left to member states.

Germany. The German implementation under the Geldwäschegesetz applied a 25 percent threshold consistent with 4AMLD but also required identification of persons who exercise control through other means in considerable detail, with a multi-tier ownership chain documentation requirement that was more granular than many other member states demanded. German-calibrated KYC profiles may already contain much of what the AMLA RTS will require for ownership chain documentation, but the specific field structure and format may need adjustment.

Ireland. The Irish implementation included specific provisions for the identification of beneficial owners of trusts that went beyond the 4AMLD minimum. Firms authorised in Ireland with significant trust customer exposure may find that their UBO data schema for legal arrangements is already relatively detailed, but the format of the records may not match what the AMLA RTS will specify.

Luxembourg and the Netherlands. Both jurisdictions have large funds industries with complex UBO identification challenges arising from multi-layer fund structures. National supervisory guidance in both jurisdictions addressed specific fund structure scenarios. The AMLA RTS will need to address equivalent scenarios at EU level, and the national guidance provides a useful indicator of where the complexity lies, even if the EU-level resolution may differ.

Jurisdictions with historically lighter implementation. Several member states applied the directive's UBO requirements with less granularity in practice, accepting verification evidence that larger member state NCAs would have considered insufficient, and not requiring ownership chain documentation beyond the UBO layer. Firms primarily supervised in those jurisdictions face the most material upward revision when the AMLA RTS establish the EU-level floor.

The direction of travel for KYC data schema design is toward the more granular end of what currently exists in national implementations, not toward an average. AMLA's mandate is to set the minimum that applies everywhere, and the political and supervisory expectation is that minimum is meaningful.

Onboarding pipeline audit: the practical schema review

The schema review that compliance teams need to undertake before the Level 2 RTS are finalised has two components: a gap analysis against the AML Regulation's directly applicable requirements, and a readiness assessment for the additional data points the Level 2 RTS are expected to specify.

The gap analysis starts with the regulation text. For each category of customer, the regulation specifies what must be collected and verified at standard CDD level. Mapping the current onboarding pipeline against those categories identifies fields that are currently not collected, fields that are collected but not verified to the standard the regulation will require, and fields that are collected in a format that may not satisfy the Level 2 technical standards when they arrive.

The readiness assessment is more speculative but not uninformed. AMLA has published its Level 2 mandate pipeline and indicative timelines. Several member states have already implemented requirements that go beyond the 4AMLD minimum in ways that anticipate what the EU-level standard is likely to require. The EBA's existing guidelines on customer due diligence, developed under the 4AMLD framework and still technically in force pending replacement by AMLA guidance, provide additional signal on the direction of the Level 2 specifications.

The specific onboarding pipeline components that most commonly require modification in preparation for the new schema are:

Ownership chain capture. Many onboarding platforms capture the UBO at the top of the ownership chain but do not document the intermediate entities between the customer and the UBO. The AML Regulation's ownership chain documentation requirement means the platform needs to support multi-level entity graph capture, not just a UBO field.

Verification evidence storage. The AML Regulation's ongoing monitoring and discrepancy reporting obligations both require that the verification evidence used at onboarding is retained in a form that allows it to be reviewed at any subsequent point. Platforms that capture verification outcomes without storing the underlying evidence documents, or that store them outside the KYC profile in a way that makes retrieval difficult, need to address this before the compliance date.

Senior managing official fallback logging. The conditions under which the senior managing official fallback applies are specific, and applying it without documenting why the threshold person could not be identified creates a supervisory vulnerability. The onboarding platform needs to support a structured record of the steps taken to identify a UBO before the fallback is applied.

PEP status and Commission PEP list integration. The AML Regulation replaces the patchwork of national PEP lists with a single consolidated list assembled and published by the Commission in the Official Journal, with AMLA making it available on its website. Systems that currently use national PEP list lookups need to be updated to reference the EU-level list when it is published, and the integration point needs to be designed to support updates when the Commission revises the list.

The discrepancy reporting obligation and its data architecture implications

One of the more operationally consequential provisions in the AML Regulation for KYC data architecture is the discrepancy reporting requirement set out in Article 24. Obliged entities must report discrepancies between the UBO information they hold following customer due diligence and the information contained in national beneficial ownership registers to the authority responsible for maintaining the register.

This obligation has two data architecture implications that are distinct from the core KYC schema question.

First, the onboarding pipeline must have access to beneficial ownership register data at the point of customer due diligence, not just at the point of a reactive check. This means a data feed or API integration with each relevant national register, and the pipeline must be capable of performing a structured comparison between register data and the UBO data collected from the customer.

Second, the discrepancy reporting process must generate a structured output in a format specified by the relevant authority. The AMLA Level 2 mandates include technical standards for discrepancy reporting format, which means the comparison and reporting function will eventually be governed by a technical standard rather than left to each obliged entity to design.

For firms operating across multiple member states, the discrepancy reporting obligation is complicated by the fact that beneficial ownership registers remain national. The quality, completeness, and accessibility of register data varies significantly across member states. Some registers provide real-time API access; others require manual searches. Some contain data that is current and accurate; others have known gaps. The AMLA framework addresses this by improving inter-register data sharing over time, but the near-term compliance environment requires firms to work with registers as they currently exist.

Timeline management: what to track before July 2027

AMLA's work programme for Level 2 instruments is the primary tracking target for firms building toward the July 2027 compliance date. The staggered delivery timeline for the mandates means that some instruments will arrive with meaningful lead time and others will arrive close to the application date.

The practical tracking framework has three components.

AMLA consultation papers are the earliest signal of what the final RTS will require. AMLA publishes consultation papers before submitting draft RTS to the Commission, and industry responses to those consultations sometimes shift the final requirements in material ways. Consultations on key instruments, including the CDD data schema under Article 28 and the linked transactions thresholds under Article 19(9), had already closed by mid-2026. Firms that engage with consultations, or at minimum monitor the consultation papers and responses, have the best available picture of what the schema will require before it is final.

The Commission's endorsement timeline adds additional lead time compression. After AMLA submits a final draft RTS, the Commission has a statutory period to decide whether to endorse it and may request amendments. The published RTS, available in EUR-Lex with its own CELEX number, is the final binding text, and building to consultation paper drafts rather than final RTS carries the risk of a late revision requiring rework.

The existing EBA guidelines on customer due diligence, published under 4AMLD mandates, remain in force pending replacement by AMLA instruments. They are not the future standard, but they reflect a supervisory expectation that has been applied across multiple jurisdictions and is likely to inform the AMLA RTS content. Firms whose current programmes already meet the EBA guidelines are better positioned for the transition than those whose programmes fall short of that level.

Forseti monitors AMLA's Level 2 mandate pipeline continuously, including consultation papers, draft RTS, and Commission endorsement decisions, anchored to verified official sources. Start for free.

For the broader shift from directive-based national AML law to the directly applicable EU single rulebook, see the EU AML single rulebook: what uniform enforcement means for fintechs. For the geographic risk classification obligations that sit alongside the customer-level CDD schema, see EU AML high-risk third countries: the maintenance burden compliance teams underestimate.

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.