Back to News
Educational Content

AMLR and Digital Identity

AMLR and Digital Identity

Collecting the document was the easy part.

For years, identity verification in real estate has often started—and sometimes almost ended—with a familiar request:

“Please send us a copy of your passport or ID card.”

The document gets uploaded. The name matches. The expiry date is checked. A copy is placed in the AML dossier.

But there is an obvious problem:

A genuine identity document does not necessarily mean that the person presenting it is the person to whom it belongs.

A passport can be perfectly authentic and still be used fraudulently.

As the EU moves toward the new Anti-Money Laundering Regulation (AMLR), applicable from 10 July 2027, real estate professionals should think beyond collecting identity documents and toward demonstrable identity verification.

And there is no good reason to wait until 2027 to start.

AMLR separates identification from verification

This distinction is fundamental.

Under Article 20 AMLR, Customer Due Diligence requires obliged entities to identify the customer and verify the customer's identity. AMLR also requires them to be able to demonstrate to supervisors that the measures they applied were appropriate to the identified risks. EUR-Lex

These are not the same thing.

Identification asks:

Who does this person claim to be?

Verification asks:

What reliable evidence gives us sufficient confidence that this person really is who they claim to be?

Uploading a passport helps answer the first question.

A proper verification process needs to answer the second.

AMLR explicitly recognises digital identity

Article 22 AMLR provides two principal routes for verification.

Identity can be verified using an identity document, passport or equivalent, supplemented where relevant by information from reliable and independent sources.

But AMLR also expressly recognises electronic identification means meeting the requirements of the EU's eIDAS framework at assurance level “substantial” or “high”, together with relevant qualified trust services. EUR-Lex

That matters enormously for real estate.

Customers are increasingly remote.

A buyer in Stockholm purchases in Spain.

A seller living in Belgium sells a property in France.

A corporate buyer's UBO may live in another Member State—or outside the EU altogether.

Remote onboarding is no longer exceptional.

It is normal real-estate business.

A scanned passport is not digital identity verification

This distinction is important.

Receiving a PDF or photograph of a passport electronically does not, by itself, make the verification digital.

The real question is the reliability of the verification process.

Consider:

Customer A

uploads a photograph of a passport.

The agency stores it.

Done.

Now compare that with:

Customer B

provides identity information through an appropriate verification process.

The process establishes the identity evidence used, verifies relevant information, records when verification occurred and retains the evidence needed to demonstrate the result.

Both agencies may possess a passport image.

But their ability to demonstrate why they considered the identity sufficiently verified can be very different.

This is where AMLR changes the conversation

AMLR Article 20(4) contains a deceptively important requirement:

Obliged entities must be able at all times to demonstrate to their supervisors that the measures taken are appropriate in view of the identified ML/TF risks. EUR-Lex

That changes the compliance question from:

“Do we have an ID?”

to:

“How did we verify this identity, what evidence did we rely upon, and was that method appropriate for the risk?”

That is a much stronger compliance position.

Remote onboarding needs an evidence trail

For a real estate business, a digital identity process should therefore leave a structured record.

Not merely:

Passport.pdf ✓

But something closer to:

Identity declared

↓

Identification information collected

↓

Verification method recorded

↓

Evidence/source used

↓

Verification result

↓

Date and responsible process/person

↓

Risk assessment

↓

CDD decision

↓

Ongoing monitoring

That final element matters too.

Identity is not necessarily a one-time event.

Because customers do not remain static

Imagine that a customer is correctly verified today.

Six months later:

  • the customer provides different identification information;

  • an authorised representative changes;

  • corporate ownership changes;

  • a new UBO appears;

  • documents expire;

  • information becomes inconsistent;

  • circumstances affecting the customer's risk profile change.

AML compliance cannot simply say:

“KYC completed six months ago ✓.”

AMLR requires ongoing monitoring of business relationships and requires CDD information to be kept relevant. The Regulation makes CDD part of a continuing risk-based process rather than a one-off document collection exercise. EUR-Lex

So the better question becomes:

Do we still have reasonable confidence in the customer information on which our compliance decision is based?

Real estate has another important AMLR rule

AMLR gives real-estate agents a specific timing requirement.

For real-estate agents, identity verification is to take place after an offer has been accepted by the seller or lessor and, in all cases, before funds or property are transferred. EUR-Lex

That means identity verification cannot simply be an administrative exercise completed whenever convenient after the transaction.

It needs to sit at the correct point in the transaction workflow.

And AMLR also treats both parties to a real-estate transaction as customers for CDD purposes.

The implication for real-estate technology is significant.

Identity verification should be connected to the transaction dossier, not sit somewhere isolated in a generic CRM contact record.

Digital identity is still only one part of CDD

There is another trap here.

Replacing manual passport uploads with sophisticated digital identity verification does not make a business AML compliant.

Identity verification is one component.

A real-estate AML process can also involve:

  • Business-Wide Risk Assessment

  • KYC

  • UBO identification and verification

  • PEP assessment

  • Targeted financial sanctions controls

  • Customer risk assessment

  • Purpose and intended nature of the relationship or transaction

  • CDD / EDD

  • Know Your Transaction

  • Source of Funds where required

  • Source of Wealth where required

  • Ongoing monitoring

  • Suspicious transaction reporting

  • Training

  • Record keeping

  • Demonstrable decisions and audit trails

That is why a sophisticated identity-verification provider is still not an AML compliance system.

It solves an important piece of the puzzle.

Not the whole puzzle.

AMLA is making the details more concrete

This development is still continuing.

AMLA has been developing Regulatory Technical Standards under Article 28 AMLR specifying how CDD should be performed in practice, including the information and documents that obliged entities should collect.

AMLA's 2026 consultation explicitly addresses how obliged entities should verify customer identity and conduct ongoing monitoring in a risk-sensitive and proportionate way, with the standards intended to work across both financial and non-financial sectors. AML/CTF Authority

That is another reason why real-estate businesses should not design their future AML process around a folder full of document uploads.

The direction is clear: structured, risk-based and demonstrable CDD.

Why (not) wait until 2027?

This may be the most important point.

Customer identification and verification are not new obligations introduced by AMLR.

Real-estate professionals are already subject to AML requirements under today's legal framework.

AMLR changes and harmonises the framework, but the fundamental need to know and verify your customer already exists.

So why continue with a weak process for another nine months simply because AMLR applies from July 2027?

A better approach is to start moving now from:

document collection to identity verification

and ultimately to: demonstrable Customer Due Diligence.

Where Immosurance fits

This is precisely the distinction Immosurance is designed around.

The objective is not simply:

“Upload ID.”

It is to incorporate identity into a wider AML compliance workflow:

Identify → Verify → Screen → Assess Risk → CDD/EDD → Assess Transaction → Monitor → Document → Demonstrate

Identity evidence therefore becomes part of the customer's and transaction's AML dossier, together with the reasoning, checks, decisions and evidence surrounding it.

Because when a supervisor eventually asks:

“How did you establish that this customer was properly identified and verified?”

the answer should not be:

“There is a passport somewhere in the file.”

It should be:

“Here is exactly how we established it.”

AMLR takes us beyond document collection.

And real estate businesses don't need to wait until 10 July 2027 to get there.

Immosurance — Compliance built for Real Estate.

Early Birds 2026

SPECIAL 2026 CONDITIONS

Exceptional conditions are available for early adopters in 2026 and change in 2027. Secure your preferred pricing today.