Skip to content

April 21, 2026

EU AML regulation 2027: what proof of address do you actually need?

The EU's single rulebook for anti-money laundering applies from 10 July 2027. For the first time, proof of address requirements will be harmonized across all 27 member states under one directly applicable regulation. No more interpreting different national transpositions. No more wondering whether a German utility bill meets French CDD standards.

This article breaks down what the new regulation says about address verification, what actually changes compared to the current directive-based framework, and what compliance teams should be doing now to prepare.

What is the EU AML regulation?

The EU Anti-Money Laundering Regulation, officially Regulation (EU) 2024/1624, was adopted on 31 May 2024. It entered into force on 9 July 2024 and will apply in full from 10 July 2027.

The critical distinction is in the instrument type. Previous EU anti-money laundering rules came as directives (AMLD4, AMLD5, AMLD6), which had to be transposed into national law by each member state. This meant 27 different national implementations, each with its own interpretation of what "adequate" customer due diligence looked like. One country might require two forms of address verification, another might accept a self-declaration, and a third might have no explicit address requirement at all.

The AMLR is a regulation. It applies directly in every member state without national transposition. One set of rules, one interpretation, one standard. This is the most significant structural change in EU anti-money laundering law in two decades.

Alongside the regulation, the EU has established the Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt. AMLA will begin operations with AML mandates transferring from January 2026, and will start directly supervising the 40 highest-risk cross-border financial entities from 2028.

What AMLR says about proof of address

Article 22(1)(a) of the regulation requires obliged entities to identify their customers and verify their identity. For natural persons, this includes collecting the customer's "usual place of residence." This is not optional; residence is a mandatory identification element under the new framework.

Article 22(3) specifies that verification must use "reliable and independent sources, including electronic identification means and relevant trust services." The language is deliberately outcome-based. The regulation does not provide a prescriptive list of acceptable documents. Instead, it sets a standard: whatever you use to verify an address must be reliable and independent of the customer.

This matters because it gives obliged entities flexibility in how they verify addresses while holding them to a clear standard of evidence. A utility bill from a major provider is reliable and independent. A self-declared address on a signup form is not.

For practical guidance on what documents meet the "reliable and independent" standard, the EBA's guidelines on customer due diligence (EBA/GL/2022/02) remain the primary reference. These guidelines explicitly list the following as acceptable address verification sources:

These document types remain fully valid under the AMLR. If your current process accepts these documents and validates them properly, the core of your verification workflow does not need to change.

What's actually new (compared to AMLD5)

The AMLR replaces the patchwork of national AMLD implementations with a single set of rules. Here is what changes in practice:

Area AMLD4/5/6 (current) AMLR (from July 2027)
Legal instrument Directive (national transposition) Regulation (directly applicable)
CDD threshold EUR 15,000 EUR 10,000
Beneficial ownership >25% ownership ≥25% ownership
Cash payment cap Varied by country EUR 10,000 EU-wide
Obliged entities Banks, insurers, PSPs, etc. Expanded: crypto, crowdfunding, football clubs
Verification approach Document-based primary eIDs preferred, documents as fallback
Supervision National authorities only AMLA + national authorities

Several of these changes have direct implications for address verification. The lower CDD threshold of EUR 10,000 means more transactions will trigger full customer due diligence, including address verification. The shift in beneficial ownership from "more than 25%" to "25% or more" is subtle but catches an additional set of entities. And the EU-wide cash payment cap eliminates the patchwork of national limits (some countries had no cap at all) that made cross-border compliance inconsistent.

The expanded list of obliged entities is perhaps the most impactful change for proof of address verification volumes. Crypto-asset service providers, crowdfunding platforms, and others that previously operated in regulatory grey areas will now need full CDD processes, including address verification.

eIDs, digital wallets, and the future of address verification

The AMLR places notable emphasis on electronic identification. Article 22 explicitly encourages the use of eIDAS electronic identification means and the forthcoming EU Digital Identity Wallet (EUDI Wallet) for customer verification. In the regulation's framework, electronic identification is the preferred method, with traditional document-based verification positioned as a valid fallback.

This is a meaningful shift in regulatory posture. Previous directives were largely silent on electronic verification methods, leaving it to national regulators to decide whether and how digital tools could be used. The AMLR actively promotes them.

But there is a significant gap between regulatory ambition and operational reality. The EUDI Wallet is not yet available in most member states. The rollout is gradual, with pilot programs still running in several countries and full availability expected only by late 2027 or 2028. Even once available, adoption among end users will take time. Not every customer will have a wallet, and not every wallet will contain verified address data.

Document-based verification is explicitly preserved as a valid verification method under the regulation. The text makes clear that where electronic identification is not available or not practical, obliged entities may continue to rely on documents from reliable, independent sources.

The practical reality for most companies is clear: document-based address verification will remain the primary method for years to come, especially for international customers, customers in member states with slower wallet rollouts, and customers from outside the EU entirely. The regulation permits this. What it does not permit is unverified self-declarations.

Looking further ahead, AMLA is expected to publish regulatory technical standards (RTS) under Article 22 that may establish minimum technical requirements for both electronic and document-based verification. These RTS will add specificity but are unlikely to eliminate document-based verification as an accepted method.

Who needs to comply (expanded obliged entities)

The AMLR significantly expands the list of entities that must perform customer due diligence, including address verification. All existing obliged entities remain covered:

The regulation adds several new categories of obliged entities:

If you provide compliance infrastructure to any of these verticals, your customers will need AMLR-compliant address verification. If you are one of these entities, you need it yourself. The transition window is narrowing.

Practical steps to prepare before July 2027

Fourteen months is not a lot of time for compliance infrastructure changes, especially when regulatory technical standards are still being finalized. Here is what you can do now.

Audit your current CDD process. Map out exactly how you verify residential addresses today. What documents do you accept? What recency rules do you apply? How do you handle mismatches? Is every decision based on a reliable, independent source, or are some addresses accepted on the basis of self-declaration? If your current process relies on customers typing their address into a form without verification, that will not meet the AMLR standard.

Stop accepting unverified addresses. If you currently accept self-reported addresses without documentary or electronic verification, start requiring verification now. The AMLR makes this mandatory, but it is also good practice under existing KYC requirements. There is no reason to wait.

Ensure multi-language coverage. The AMLR applies across 27 member states with 24 official languages. If a Bulgarian customer submits a utility bill in Bulgarian, you need to be able to verify it just as reliably as a German utility bill in German. Rejecting documents because your team cannot read the language is both a compliance risk and a customer experience failure.

Build a proper audit trail. For every address verification, record what document was submitted, what data was extracted, what the expected address was, the match result, confidence scores, and the decision made. Include timestamps. Retain these records for the period required by your national regulator (typically 5 years after the business relationship ends). AMLA supervisors will expect this level of documentation.

Monitor AMLA's RTS publications. The regulatory technical standards under Article 22 will add specificity to verification requirements. Subscribe to AMLA's public consultations and monitor the Official Journal for final publications. These RTS may introduce minimum match thresholds, document freshness requirements, or technical standards for electronic verification.

Consider automated verification. Manual document review does not scale across 24 languages and 27 national document formats. Automated verification handles volume, ensures consistency, and produces the audit trails that supervisors expect. This is what trusqo is built for.

Key dates to watch

The bottom line

The shift from directive to regulation is the biggest structural change in EU anti-money laundering law since the framework was created. Address verification moves from a patchwork of national interpretations to a single, enforceable standard. The documents that compliance teams have always relied on (utility bills, bank statements, government correspondence) remain valid. But the bar for how you verify them, how you document the process, and how consistently you apply your rules is going up.

July 2027 is 14 months away. The entities that will be ready are the ones that start now.

From signup to first verification in under an hour.

No contracts, no minimums, cancel any time. Every plan includes the full API, dashboard, and webhooks.

cURL
curl -X POST https://app.trusqo.com/api/verify \
  -H "X-API-Key: poa_live_..." \
  -F "[email protected]" \
  -F "name=John Doe" \
  -F "address=123 Main St"