Skip to main content

AMLR and the data imperative

Turning compliance data into strategic capability

This article was written in collaboration with SAS.

Deloitte
• Marit Hoegen, Partner - MHoegen@deloitte.nl
• Mitchell Verstraate, Senior Manager - mverstraate@deloitte.nl
• Robby Philips, Senior Manager - rphilips@deloitte.nl

SAS
• Olaf Passchier, PhD, CFE, BNL Customer Advisor for Fraud,
Compliance and Public Security
- olaf.passchier@sas.com

AMLR is a data-equity test. Make Data Readiness your strategic response

The Regulation (EU) 2024/1624, or Anti-Money Laundering Regulation (hereinafter AMLR) is more than a deadline; it is a structural test of data equity across the financial ecosystem. From 10 July 2027, the Anti-Money Laundering Authority (AMLA) will centralise supervision and through the AMLR insist on machine-readable, harmonised data, near-real-time screening and group-wide reporting. For first and second line teams this is not simply a matter of updating policies: it is an architectural mandate. The question for Obliged entities is straightforward:

Will data be treated as a strategic asset or will it continue to be accepted as a recurring liability?

Fragmented Know-your-customer (hereinafter KYC) data is an immediate AML compliance risk, where unknown risks make proficient mitigation impossible. Across the whole financial system, including newly obliged entities, customer information resides in scattered silos: CRM systems, core banking ledgers, insurance platforms, commercial units, PDFs and spreadsheets.

The same customer appears in different forms for example; “John Smith” in retail banking, “J. Smith” in insurance, and “John. S.” in commercial dealings. These trivial variations break reliable entity matching, generate false positives, impede automation and obliterate auditability. The immediate effects are familiar: manual reconciliation, repeated remediation and weak audit trails, resulting in infrequent and weak batches which are unable to show which data, list or algorithms inform decisions.

Regulatory momentum makes this problem unavoidable. Key AMLR provisions with supporting Regulatory Technical Standards (hereinafter RTS), Implementing Technical Standards (hereinafter ITS) and Guidelines enhances the role of data as a core compliance requirement:

AMLA will perform an initial, impactful selection of entities for direct supervision using a harmonised set of data points that obliged entities must provide; these same data points are essential inputs for the entity‑wide (business‑wide) risk assessment. Although AMLA is expected to pick a limited amount of entities for direct supervision, national supervisors will use the same data points for risk‑based supervision under the new European AML/CFT framework. Accordingly, all obliged entities should be prepared to report on these comprehensive metrics.

Requires parent undertakings to establish centralised governance and implement harmonized information-sharing policies across all group entities for AML/CFT compliance. (AMLR Article 16; Draft RTS on group-wide requirements, Articles 3 & 4).

Draft RTS specify the information to be collected for standard, simplified, and enhanced due diligence, including minimum data requirements and standardized attributes for electronic identification means. (AMLR Article 28; Draft RTS on CDD, Annex I).

Obliged entities must identify and verify customer identity and beneficial owners, and verify whether they are subject to targeted financial sanctions. (AMLR Article 20).

Credit institutions and financial institutions must re-screen customers and beneficial owners upon any new sanctions designation to ensure ongoing compliance. (AMLR Article 26(4)).

AMLA must develop ITS specifying the format for reporting suspicions to Financial Intelligence Units (hereinafter FIU) to harmonise reporting across the Union. (AMLR Article 69(3)).

Permits members of partnerships for information sharing to exchange customer intelligence and risk assessments where strictly necessary for AML/CFT compliance, subject to supervisory verification and strict safeguards. (AMLR Article 75).

The cost of inaction

Together, these articles demand machine-readable, high-quality, harmonised data and a technology uplift to support near-real-time, auditable processes. The legal direction is clear: if your data cannot be read, verified and exchanged in standardised formats, you will struggle to demonstrate compliance.

The consequences of inaction are both immediate and strategic. Persisting with manual patchwork and occasional remediation locks firms into a permanently higher cost base: repeated reconciliations, consultant engagement and firefighting absorb budget that should fund long-term resilience and business transformation. This is not mere accounting; it skews investment decisions and shrinks future capacity for innovation.

Failure to achieve the proposed data readiness approach also becomes a commercial handicap. Inability to verify identity promptly or to complete defensible due diligence will slow or block onboarding, prolong decision times and drive clients towards competitors with cleaner, faster processes. Onboarding friction is not just a customer experience issue; it is a revenue and market-share issue.

More troubling is the systemic impact. If many institutions cannot re-screen portfolios quickly or share intelligence securely, supervisory measures lose precision and typologies go undetected. AMLR aims to create a cohesive, data-driven defence; without Data Readiness, the regulation risks amplifying unevenness across the sector and concentrating, rather than dispersing, risk

Treating Data Readiness as an optional optimisation is a strategic mistake. Organisations that act early will lower operating costs, preserve business agility and be the institutions trusted in a fair, data-driven financial ecosystem. While those that delay will face escalating costs, constrained business and a diminished role in the collective AML defence.

A practical path to Data Readiness

Our view is that the pragmatic solution to fragmented KYC is found by setting up an organised capability for data readiness, where the right data is available, in the right quality and format, precisely when AML/ CTF processes require it. This is not a one-off project but an operating model that turns a dispersed set of records into consistent, auditable, reusable assets. In effect, the proposed data readiness approach makes the “John Smith” problem disappear by converting inconsistent strings into canonical, attributable records.

The proposed data readiness approach dissolves fragmentation in the following ways:

Consolidate names, dates of birth, addresses, beneficial owner records, identifiers and transaction metadata into discrete, standardised fields rather than a free format. A single source of truth is established for matching and reporting.

Combine a mix of rule‑based and similarity‑based matching to consolidate name variants (J. Smith, John. S.) into a unified profile, while retaining provenance and versioning.

Move from periodic batch processes to continuous watchlist ingestion and event triggers so re-screening and alerts happen in near-real time, consistent with Article 26 of the AMLR.

Ensure systems can export CDD and STR formats aligned with AMLA RTS/ITS and the standardisation ambitions of Article 69 of the AMLR, eliminating ad hoc conversions that break provenance.

Deploy PET to allow secure, privacy-preserving private-to-private sharing and analytics in line with Article 75, reducing legal friction for collaboration.

Treat rules, watchlists and business logic as versioned artefacts so deployments are auditable, repeatable and transparent, meeting supervisory expectations under Article 16.

Transitioning to Data Readiness need not be paralysis-inducing. Start with a focused assessment of data availability at the item level, establish a canonical model for critical attributes, and deploy entity resolution on a high-risk segment to prove the approach. 

Embed PET where sharing is required and govern rules as code to maintain reproducibility. These are practical, deliverable steps that move firms from costly remediation cycles to a scalable, auditable operating model. AMLR’s timeline is uncompromising and its expectations are structural. 

 
Technical Implementation: Unified Platform Approach to Data Readiness

Achieving Data Equity requires a data and technology platform capable of consolidating fragmented KYC data into machine-readable, standardised formats in the different ways discussed above.

Platforms that integrates their modules for Anti-Money Laundering, Customer Due Diligence and Real-Time Watchlist screening, such as SAS Viya for Financial Crime demonstrates how this consolidation can be achieved at scale within a single governed environment. Machine-readable data export functionality ensures CDD and STR outputs align with AMLA Regulated Technical Standards removing ad hoc conversions that compromise auditability. Real-Time screening and event-driven rescreening replace batch processes, meeting Article 26’s near-real-time requirements. Integrated data sharing capabilities, supported by advanced analytics and network intelligence, enable secure and documented intelligence exchange between institutions under Article 75 safeguards.

By treating data quality, entity resolution and regulatory reporting as integrated functions rather than separate point solutions. Organisations transition from costly remediation cycles to scalable, auditable operations. That satisfy AMLR’s structural demands for harmonised, machine-readable data and transparent decision trails, as is also applicable in other data domains in financial institutions.

By automating entity resolution and maintaining perpetual KYC through integrated CDD and EDD workflows, compliance teams can accelerate customer onboarding while simultaneously reducing false positives and improving decision quality, directly addressing the speed-versus-accuracy trade-off that has long constrained KYC operations.

This unified approach transforms KYC from a fragmented, periodic process into a continuous, data-driven capability that adapts to evolving risk profiles and regulatory expectations.

AMLR Readiness Roundtable: Key Insights from the Sector

We recently brought together representatives from more than 20 different organisations to address some of the sector’s most pressing AMLR challenges. The energy and insights shared were insightful– bringing together peers from banking, payments, insurance and other industries to find common challenges and approaches proved invaluable. 

Three Key Takeaways 

  1. Changing your data landscape and developing a clear IT roadmap are ‘no regrets’ moves Regardless of regulatory specifics, investing in data quality and modernising your technology infrastructure will deliver immediate compliance and operational benefits. 
  2. AMLR makes data equity a joint compliance imperative — The Regulation and its RTS/ITS demand machine‑readable, harmonised KYC, near‑real‑time screening and group‑wide exchange, so without canonical data models, provenance and auditable outputs firms face immediate compliance failures, escalating remediation costs and a commercial disadvantage. 
  3. Adopt a unified, platform led operating model and govern as code — Consolidating KYC into canonical fields, deploying hybrid entity resolution, event driven screening, machine readable CDD/STR exports and PET enabled private to private sharing will cut false positives, speed onboarding and create the auditable, scalable capability AMLR requires.

This article was written in collaboration with SAS.

Deloitte
• Marit Hoegen, Partner - MHoegen@deloitte.nl
• Mitchell Verstraate, Senior Manager - mverstraate@deloitte.nl
• Robby Philips, Senior Manager - rphilips@deloitte.nl

SAS
• Olaf Passchier, PhD, CFE, BNL Customer Advisor for Fraud,
Compliance and Public Security
- olaf.passchier@sas.com

Did you find this useful?

Thanks for your feedback