Not every client is high risk, and the rulebook does not pretend otherwise. Both the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 and Regulation (EU) 2024/1624 (the AMLR) are built on a risk-based approach: you do more where the risk is higher, and you are allowed to do less where the risk is genuinely lower.
That second half is where firms get into trouble. "Simplified due diligence" is one of the most misunderstood ideas in AML compliance. Some firms treat it as permission to skip checks altogether. Others are so nervous of it that they run full enhanced-style diligence on every client, which is expensive and unnecessary. This post explains what simplified measures actually are, when the AMLR allows them, and how to apply them in a way that will stand up when your supervisor reads the file.
What simplified due diligence actually means
Simplified due diligence is not an exemption from customer due diligence. It is a lighter application of the same core obligations. You still have to know who your client is, verify that identity, understand who ultimately owns or controls them, and understand the purpose of the relationship.
What changes is the intensity. In lower-risk situations, firms typically adjust the extent, timing or frequency of their measures rather than the existence of them. In practice that tends to mean things like less intensive ongoing monitoring, longer intervals between file reviews, or accepting a narrower set of information about the purpose of the relationship where it is obvious from context.
The precise boundaries of what is acceptable under the AMLR will be sharpened by AMLA, the EU's new anti-money laundering authority. AMLA submitted its first batch of draft technical standards to the European Commission around 10 July 2026, and those drafts are now awaiting adoption. Until the final standards land, treat detailed prescriptions you see elsewhere with caution and follow updates at amla.europa.eu.
When are lighter checks allowed?
The short answer: only where you have identified a lower degree of risk, and only where nothing points the other way.
That assessment has two layers:
- Your business-wide risk assessment. If you want to treat a category of clients or services as lower risk, your BWRA should say so, and say why. A simplified approach that contradicts your own risk assessment is indefensible.
- The individual client. Even within a lower-risk category, each client must actually fit the pattern. A client type that is usually low risk stops being low risk the moment an unusual feature appears.
A hypothetical example: a small accountancy practice preparing annual accounts for a long-established local trading company, owned by two named directors it has met in person, paid by bank transfer from an Irish account, is plainly at the lower end of the risk spectrum. The same practice forming a new company for a non-resident client it has never met is not, even though the fee might be smaller.
When simplified measures are never appropriate
There are hard stops. Lighter checks are off the table where:
- You suspect money laundering or terrorist financing, however low the apparent risk category. Suspicion always overrides classification, and your Suspicious Transaction Report obligations to FIU Ireland and Revenue apply regardless.
- Enhanced due diligence is triggered - for example, involvement of a high-risk third country, a politically exposed person, or a high-net-worth relationship where you handle assets of 5 million euro or more for a client whose total wealth is 50 million euro or more.
- The client, structure or transaction simply does not match the low-risk profile you assigned it.
Simplified due diligence also does not switch off your other duties. You still need to identify beneficial owners against the AMLR's harmonised 25 per cent threshold, obtain an RBO extract before entering a new business relationship with a corporate client, report any discrepancies you find, and screen against sanctions lists. None of those obligations scale down with risk rating.
How do you justify simplified measures on file?
This is the part inspectors actually look at. A simplified approach is defensible only if the file shows the reasoning. For each client where you apply lighter measures, the record should answer three questions:
- What risk category did you assign, and why? A one-line note tying the client to a low-risk category in your BWRA is far better than a bare "low" in a spreadsheet column.
- What measures did you actually apply? Simplified is still something. Record the identification, verification and beneficial-ownership steps you took.
- What would change your mind? Your procedures should state the events that bump a client out of simplified treatment - a new service line, an unusual payment, a change of ownership - so monitoring has something concrete to catch.
A file that shows a considered decision to do less is a sign of a mature programme. A file that shows nothing was done, with no reasoning, looks like neglect - even if the client really was low risk.
What changes between now and July 2027?
From 10 July 2027 the AMLR applies directly in Ireland and replaces the substantive CDD rulebook in the CJA 2010. If your current procedures describe simplified due diligence by reference to old thresholds or old lists of low-risk categories, they will need a refresh. Two things to build into that refresh:
- Align your risk categories and thresholds with the AMLR, including the 10,000 euro occasional-transaction trigger and the 3,000 euro occasional-cash trigger.
- Leave room for AMLA's technical standards and guidelines. Where the fine detail is still pending, say so in your procedures and diarise a review for when the standards are adopted.
What to do now
- Check whether your current procedures define when simplified measures apply, or whether staff are improvising.
- Cross-check every simplified category against your business-wide risk assessment - and update the BWRA if they do not match.
- Sample five recent low-risk files and ask whether the reasoning for lighter checks is written down anywhere.
- Confirm your simplified approach never skips beneficial-ownership checks, RBO extracts or sanctions screening.
- List the triggers that move a client out of simplified treatment, and make sure monitoring can detect them.
- Diarise a procedures review for when AMLA's technical standards are adopted.
Where CompliDesk fits
CompliDesk Ireland bakes risk-rating and the matching level of due diligence into one onboarding flow, so the file always shows why lighter checks were justified. For a practical view of what a complete client file should contain, see the CDD file checklist.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.