If your firm still verifies identity by taking a certified copy of a passport and a utility bill, you are not alone. Most Irish designated persons built their customer due diligence (CDD) processes under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, and for many small practices those processes are still paper-first.
From 10 July 2027, Regulation (EU) 2024/1624 (AMLR) replaces the substantive AML rulebook you work under today. One change that has had less attention than the new thresholds is this: the AMLR explicitly recognises eIDAS-aligned electronic identification as a way to verify identity. With the European Digital Identity (EUDI) wallet on the horizon, that recognition matters for how you design your verification process now, not just in 2027.
This post explains what that recognition does and does not mean, and how to prepare without betting your compliance programme on technology that is still rolling out.
eIDAS and the EUDI wallet in plain English
eIDAS is the EU's legal framework for electronic identification and trust services. In broad terms, it sets the rules under which an electronic proof of identity issued or recognised in one member state can be relied on across the EU, with defined assurance levels.
The EUDI wallet is the next step: a digital identity wallet that people will hold on their own device and use to prove who they are to businesses and public bodies. It is not yet part of everyday Irish practice, and the rollout timeline across member states is still settling. Treat it as a direction of travel, not something your clients will hand you tomorrow.
The important point for AML purposes is that the AMLR was written with this world in mind. Where the CJA 2010 regime left firms and supervisors to work out how comfortable they were with electronic verification, the new single rulebook names eIDAS-aligned electronic identification as a recognised route to verifying identity.
What the AMLR actually changes for identity verification
Three practical consequences follow from that recognition.
First, electronic verification stops being a grey area. Under the AMLR, a verification process built on eIDAS-aligned electronic identification is a recognised method, applied directly and uniformly across all 27 member states because the AMLR is a regulation, not a directive requiring national transposition. You will not be relying on a national gloss or a supervisor's tolerance.
Second, you will need it more often. The AMLR lowers the CDD threshold for occasional transactions to 10,000 euro (from 15,000 euro), and occasional cash transactions of 3,000 euro or more trigger limited CDD. More transactions crossing the CDD line means more identity checks, and manual certification does not scale well. Firms that can verify a client electronically in minutes will feel the new thresholds far less than firms couriering certified copies.
Third, it changes the conversation with your verification vendor. If you already use an electronic identity verification tool, the question to ask is how it aligns with eIDAS and what its roadmap is for accepting EUDI wallet credentials when they arrive. If you verify manually today, the AMLR gives you a solid legal footing to move to an electronic process as part of your wider AMLR readiness work.
What does not change
Electronic identification is a verification method. It is not a substitute for the rest of CDD, and it does not shrink your obligations.
- You still take a risk-based approach. A clean identity check on a high-risk client does not remove the need for enhanced due diligence where the AMLR requires it, including the new enhanced measures for high-net-worth relationships (assets of 5 million euro or more handled for a client whose total wealth is 50 million euro or more).
- You still verify beneficial ownership. For corporate clients, identifying beneficial owners at the harmonised 25 per cent threshold, obtaining an RBO extract from rbo.gov.ie before entering a new business relationship, and reporting discrepancies are separate duties. A wallet proves the person in front of you; it does not map an ownership chain.
- You still keep records, and you must delete them. The AMLR requires records to be retained for 5 years and then deleted. Electronic verification produces evidence automatically, which helps, but your systems need retention and deletion built in either way.
- Your supervisor does not change because your tooling does. The PSRA for property services providers, the Law Society of Ireland for solicitors, the designated accountancy bodies (Chartered Accountants Ireland, ACCA, CPA Ireland) for their members, the AMLCU for TCSPs and high-value goods dealers, and the Central Bank of Ireland for financial firms will each expect your verification method, whatever it is, to be documented in your policies and reflected in your business-wide risk assessment.
A hypothetical worked example
Purely hypothetically: imagine a two-partner accountancy practice in Galway taking on a new company client in August 2027. Today, that firm might collect certified passport copies from two directors by post, which takes a fortnight. Under an AMLR-ready process, the directors complete an eIDAS-aligned electronic verification from their phones the same day. The firm separately identifies the beneficial owners at the 25 per cent threshold, obtains its RBO extract, compares it against what the client disclosed, and records the outcome. The identity step got faster; the beneficial-ownership and risk-assessment steps stayed exactly as demanding. That is the realistic shape of the change.
Questions to put to your verification provider
- Is your identity verification aligned with the eIDAS framework, and at what assurance level?
- What is your roadmap for accepting EUDI wallet credentials as member state wallets go live?
- Where is verification data stored, and does that satisfy your GDPR obligations as a controller?
- Can the tool evidence each check well enough to show your supervisor, and support 5-year retention followed by deletion?
If a vendor cannot answer these clearly, that is useful information before 10 July 2027, not after.
What to do now
- Map how your firm verifies identity today, client type by client type, and note which steps are manual.
- Read the primary text: Regulation (EU) 2024/1624 on EUR-Lex, alongside Directive (EU) 2024/1640 (AMLD6) for the institutional side.
- Ask your current or prospective verification vendor the questions above and record the answers.
- Update your draft AMLR policies so the verification method, including any electronic route, is written down and approved by your compliance manager and compliance officer.
- Check your record-keeping can actually deliver retain-5-years-then-delete for verification evidence.
- Watch AMLA for technical standards and guidance that will firm up the detail through 2026 and 2027.
How CompliDesk fits in
CompliDesk Ireland is being built AMLR-native, with electronic identity verification in the client onboarding flow and eIDAS/EUDI wallet support on the roadmap as the framework rolls out. If you want to see where your current CDD process stands against the new rulebook, start with the AMLR explainer.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.