EU AML Directive customer due diligence rules
Published · By Stonewake · Export finance · Project finance · Commercial real estate
EU AML directive customer due diligence rules are set primarily in Directive (EU) 2015/849, as amended by Directive (EU) 2018/843. Obliged entities must identify and verify the customer, identify and verify the UBO, obtain information on the purpose and intended nature of the relationship, and conduct ongoing monitoring on a risk-sensitive basis.
Core EU AML directive customer due diligence measures
Article 13 of Directive (EU) 2015/849 defines the customer due diligence measures. They comprise: identifying the customer and verifying identity from reliable and independent documents, data or information; identifying the beneficial owner and taking reasonable measures to verify that person's identity, including understanding ownership and control of legal persons and arrangements; assessing and, as appropriate, obtaining information on the purpose and intended nature of the business relationship; and conducting ongoing monitoring, including scrutiny of transactions for consistency with knowledge of the customer, business and risk profile, and keeping documents and data up to date.
Directive (EU) 2018/843 amended Article 13(1)(a) so that verification sources expressly include, where available, electronic identification means, relevant trust services under Regulation (EU) No 910/2014, or other secure remote or electronic identification processes regulated, recognised, approved or accepted by relevant national authorities. When performing identity measures, obliged entities must also verify that any person purporting to act on behalf of the customer is authorised and must identify and verify that person.
Article 13(2) requires Member States to ensure that obliged entities apply each of those requirements, while allowing the extent of measures to be determined on a risk-sensitive basis. Obliged entities must be able to demonstrate to competent authorities that the measures are appropriate to identified money laundering and terrorist financing risks.
Beneficial ownership threshold in the directive
Article 3 defines beneficial owner as any natural person who ultimately owns or controls the customer and/or the natural person on whose behalf a transaction or activity is conducted. For corporate entities, a shareholding of 25 percent plus one share, or an ownership interest of more than 25 percent, held by a natural person is an indication of direct ownership.
The same percentages held through corporate entities under the control of the same natural person(s) indicate indirect ownership. Member States may set a lower percentage as an indication of ownership or control. Where no beneficial owner is identified under those tests, or there is doubt, senior managing officials may be treated as the beneficial owner for identification purposes, with records of the actions taken.
That directive definition is the institutional basis for UBO identification in EU AML law. Complementary identifiers such as the LEI appear in market infrastructure and reporting regimes; they do not replace beneficial owner verification under Article 13.
Enhanced due diligence and high-risk third countries
Article 18, as amended, requires enhanced customer due diligence in the cases referred to in Articles 18a to 24 and in other higher-risk cases identified by Member States or obliged entities. Obliged entities must examine, as far as reasonably possible, the background and purpose of complex transactions, unusually large transactions, transactions conducted in an unusual pattern, or transactions that lack an apparent economic or lawful purpose, and must increase monitoring of the business relationship.
Directive (EU) 2018/843 strengthened the treatment of business relationships and transactions involving high-risk third countries identified by the Commission, requiring enhanced measures to manage and mitigate those risks. Recitals to that amending directive state that divergent national approaches to high-risk third countries created weak spots and that electronic identification means should be recognised within customer due diligence.
When CDD applies and how far it extends
Directive 2015/849 requires customer due diligence when establishing a business relationship, when carrying out occasional transactions above specified thresholds, when there is suspicion of money laundering or terrorist financing, and when doubts arise about previously obtained identification data. The extent of measures is risk-sensitive, but each of the Article 13 components remains required. Simplified due diligence is available only where lower risk is justified under the directive's conditions; it does not mean omitting beneficial owner identification where the directive still requires it.
For legal-entity customers typical of export and project finance, understanding ownership and control includes intermediate holding companies and trust or foundation layers. Where the beneficial owner identified is a senior managing official because no ownership-based beneficial owner was found, Directive 2018/843 requires reasonable measures to verify that official's identity and records of difficulties encountered. Ongoing monitoring must test whether transaction patterns remain consistent with the stated purpose of the relationship, including source of funds where necessary.
Institutional reform after 2015/849
Directive (EU) 2024/1640 of 31 May 2024 sets Member State mechanisms for preventing use of the financial system for money laundering or terrorist financing, amends Directive (EU) 2019/1937, and amends and repeals Directive (EU) 2015/849 as part of the wider Union AML package. Recitals emphasise strengthened beneficial ownership transparency and access for obliged entities when they apply customer due diligence measures. Central registers and access rules in that directive support, rather than replace, the Article 13 verification duty. Until national transposition and the parallel AML Regulation framework are fully in force, Article 13 of Directive 2015/849 as amended remains the operative statement of EU AML directive customer due diligence content for many desks.
In the United Kingdom, Money Laundering Regulations implement parallel customer due diligence, beneficial owner and enhanced due diligence duties for businesses in scope, including identity verification and ongoing monitoring, as summarised in HMRC guidance on responsibilities under those regulations. That guidance describes CDD as identifying the customer, verifying identity from official documents and reliable sources, identifying beneficial owners, and applying enhanced measures for politically exposed persons, high-risk third countries and other higher-risk situations.
Sanctions screening and adverse media screening sit alongside CDD as risk controls; they are not substitutes for Article 13 identity and beneficial owner measures. EU AML directive customer due diligence rules therefore remain a four-part institutional duty: customer identity, beneficial owner, purpose, and ongoing monitoring, escalated where risk factors in the directive so require.