AMLR changes the level of detail, consistency and organisation
For a real estate agent, AMLR changes the level of detail, consistency and organisation expected in the AML process—not simply the number of documents collected from a customer. It moves core obligations from nationally implemented directives into a directly applicable EU rulebook, generally applying from 10 July 2027. How much an agency must change will depend on its existing national requirements and how thoroughly it already follows them. AML Authority
The important distinction is between genuinely new or more specific rules and existing obligations that AMLR carries forward and makes more explicit.
1. AML was already much more than checking an identity document
Under Directive (EU) 2015/849, as amended, the framework already requires business risk assessment, internal policies and controls, customer and beneficial-owner identification, understanding the business relationship, ongoing monitoring, enhanced checks for higher risks, suspicious-transaction reporting, training and record retention. Source-of-funds enquiries already form part of the framework where necessary. EUR-Lex
Consequently, “we collect a passport and run a PEP check” was not a complete AML process under the directives either. The distinction is not “documents before, proper compliance after”; it is the introduction of more harmonised and specific requirements for how the compliance system operates.
2. The concrete changes to an agency’s procedures
The following separates the legal change from its practical implementation.
Process | What AMLR specifies or changes | Practical implementation for a real estate agency |
Assessing the agency’s own risks | Article 10 expressly includes sanctions-evasion risks and assessment before new markets, services or technologies. Data Consilium | Build a compliance review into business changes. For example, before launching remote onboarding or targeting a new overseas market, assess the risks and decide which additional controls the agency needs. |
Deciding whose identity to check—and when | Articles 19(6)(c) and 23(1) expressly cover both transaction parties; verification follows offer acceptance and must precede any funds or property transfer. | Design a buyer-and-seller workflow, not merely a file for the party paying the commission. Introduce a verification checkpoint before the first relevant funds transfer—not just before the final deed. This timing rule concerns verification; it is not a reason to postpone risk assessment or ignore concerns earlier. |
Identifying company owners and controllers | Article 52 uses 25% or more, rather than the previous EU ownership indicator of more than 25%; ownership and control are assessed in parallel. | Update ownership questionnaires and calculation rules. A company with four individuals each owning exactly 25% illustrates why the wording matters. Also examine control arrangements rather than stopping at a shareholder percentage. |
Updating customer information | Article 26 sets maximum update intervals: one year for higher-risk customers, five years for others, alongside relevant-change reviews. | Add review dates and event triggers to ongoing customer relationships. A different purchasing company, a new owner or a changed funding arrangement should prompt reassessment. These are not instructions to keep monitoring every former buyer indefinitely after the relationship has ended. |
Assigning management responsibility | Article 11 specifies compliance responsibilities and at least annual management reporting; proportionate combination of roles remains possible. | Specify who runs the process, who handles concerns, who receives the compliance report and who follows up weaknesses. A small agency can use a proportionate structure rather than copying a bank’s compliance department. |
Testing whether the system works | Article 9 expressly requires independent testing, with an external-expert alternative where no independent internal audit function exists. | Arrange independent examination of actual files and controls. Test whether required checks happened at the right time, exceptions were addressed and weaknesses were corrected—not merely whether a written policy exists. |
Using software, consultants or outsourced services | Article 18 reserves core decisions, including customer-risk classification and business acceptance, to the obliged entity. | Use providers to support information collection, screening and analysis, but retain ownership of the agency’s decisions. Configure the workflow so the agency can explain its outcome rather than relying solely on a vendor’s “passed” result. |
On audits specifically: the current directive already provides for independent audit where appropriate to the business’s size and nature. AMLR makes the testing requirement more explicit. However, Article 9 does not itself impose a universal annual external-audit schedule. Independent testing, the annual management report and a supervisory inspection are different things. EUR-Lex
3. Customer onboarding becomes more standardised—but remains risk-based
AMLR’s supporting framework specifies customer information and verification requirements more closely. AMLA’s customer-due-diligence material addresses matters such as names, birth details, addresses, legal-entity information, reliable sources and alternatives for remote identity verification. It also explains that beneficial-ownership register information alone is not sufficient for verification. AML Authority
A practical implementation would be to separate three things in each file:
Information collected: what the customer or another source says.
Verification performed: how the agency established that the information was reliable.
Assessment reached: what the information means for the customer’s risk and the transaction.
For example, a passport image is an input. The record of how identity was verified is a separate part of the process. The decision about whether the proposed purchase fits the customer’s profile is another.
This does not mean that every customer must submit an identical, extensive document pack. AMLA’s CDD work emphasises proportionate, risk-based measures and avoiding unnecessary duplication where adequate information is already available. AML Authority
There is also an implementation distinction to preserve: AMLA’s 30 September 2026 final report contains draft technical standards for submission to the Commission for adoption. A final AMLA draft is not, by itself, an adopted Commission regulation.
4. The transaction needs an explanation—not just an identified buyer
This is particularly important for real estate, but it is not an entirely new obligation. The current directive already requires scrutiny of transactions against the customer’s profile and, where necessary, the source of funds. EUR-Lex
AMLA’s real-estate analysis identifies issues that agents are positioned to notice: anomalies in the buyer’s profile, funding, nominees, ownership arrangements and pricing. It also distinguishes agents’ role from the roles played by notaries and other professionals in a transaction. AML Authority
Consider this hypothetical example:
An individual agrees to buy an apartment. Shortly before the deposit is due, a newly introduced company becomes the purchaser, and an unrelated person proposes to send the money.
A useful agency workflow would reopen the file rather than treat the earlier identity check as the end of the exercise. It would establish the new purchaser’s ownership, clarify the payer’s connection to the transaction, examine the explanation and supporting evidence, reassess the risk, and record the resulting decision or escalation.
The operational lesson is that the customer file and the transaction file must stay connected. A verified identity does not, on its own, explain a changed purchasing structure or an unexpected payment.
5. The business-wide risk assessment must drive the working procedures
A business-wide risk assessment—often called a BWRA—is about the agency itself: its services, customer base, locations, transaction patterns and ways of doing business. It is different from assessing one buyer or one sale.
AMLA’s draft BWRA guidelines propose a structured sequence: understand the business, identify its inherent risks, assess the quality of its controls and assess the remaining risks. These are draft guidelines, but they show how the authority is developing the common framework. AML Authority
For an agency, the useful implementation is to connect the assessment to actual operating choices. For example:
Business exposure: many customers are onboarded remotely and some purchases involve layered corporate ownership.
Procedure: define acceptable remote-verification methods, an ownership-investigation process and escalation criteria.
Control test: examine a sample of those files to see whether staff followed the process and resolved missing information.
That connection is more useful than maintaining a risk-assessment document that has no effect on how staff handle a sale.
6. What this means for an agency preparing now
I would organise the preparation around two connected workflows:
At business level:
Risk assessment → policies and responsibilities → training → management reporting → independent testing → correction of weaknesses.
At transaction level:
Identify the relevant parties → gather and verify information → assess the transaction and funding → resolve concerns and make the agency’s decision → review relevant changes → retain the evidence.
These are practical operating models, not prescribed statutory forms. The preparation task is to compare the agency’s existing process against the new requirements and identify precisely where its forms, responsibilities, timing, systems and controls need adjustment.
National requirements still matter. AMLA states that non-financial businesses, including real estate professionals, will continue to be supervised at national level, while the EU framework seeks more consistent rules and supervisory approaches. AML Authority
The central difference is therefore not “more KYC”. It is aligning the agency’s entire AML operation with a common, more detailed framework—particularly who is checked, when verification happens, how ownership is established, when information is reviewed, who owns decisions and how the controls are tested.