What AMLR Actually Requires from Small Firms Before July 2027
If you run a small law firm, accounting practice, or financial advisory and you think the EU's new Anti-Money Laundering Regulation (AMLR) is a problem for banks, you are the audience this article is written for. From 10 July 2027, the AMLR applies directly and identically in every EU Member State, and it names lawyers, accountants, tax advisers, notaries and financial institutions as obliged entities.
The honest position across these groups is uneven: most law firms currently do the minimum or nothing, small financial advisers know they are in scope but underinvest, and HR and recruiting consultants are generally out of scope altogether — a distinction worth getting right before you spend money solving the wrong problem.
Key Takeaways: AMLR Compliance for Small Firms
- AMLR applies directly from 10 July 2027 to law firms, accountants, tax advisers, notaries and financial institutions — but generally not to HR and recruiting consultants.
- AMLR reframes customer due diligence as a time-stamped, auditable verification event, not a filed copy of an ID document.
- Article 22 sets a verification standard, not just a data-collection list — and it favours electronic identification to an eIDAS-recognised assurance level.
- AMLA's technical standards are due through 2026, which makes this year, not the 2027 deadline, the right time to act.
- Trust Circle turns each verification and signing event into a logged, reproducible record backed by ZealiD's status as a Qualified Trust Service Provider.
The single biggest change: AMLR stops treating identity verification as collecting a copy of an ID and filing it. It reframes customer due diligence as a time-stamped, auditable verification event you must be able to reproduce on demand. A scanned passport in an inbox does not meet that standard — and after July 2027, "we had a copy somewhere" is not a defence.
Does AMLR Apply to My Firm at All?
It depends entirely on what you do, not how big you are. The regulation lists obliged entities by activity, and the audiences reading this fall differently:
| Firm type | In scope under AMLR? | What this means in practice |
|---|---|---|
| Law firms | Yes, for in-scope work | Conveyancing, company formation, managing client money, trust and company services and similar all trigger CDD obligations. Pure litigation may not. Most firms do some in-scope work. |
| Accounting / tax advisers | Yes | Auditors, external accountants and tax advisers are named obliged entities. Small size is not an exemption. |
| Financial advisers | Yes | Financial institutions and most regulated advisory activity are squarely in scope, including smaller independent firms. |
| HR / recruiting consultants | Generally no | Recruitment and HR consultancy is not an AML-obliged activity. Your identity and data obligations come from elsewhere, not from AMLR. |
That last row matters because it is the most common misconception we hear. HR and recruiting firms either assume AMLR sweeps them in (it usually does not) or assume that because AMLR does not apply, identity verification is optional (it is not — right-to-work checks, candidate data protection and fraud prevention still demand verified identity). If you are an HR consultant, your driver is GDPR's security-of-processing duty (Article 32) and employment-law identity checks, not anti-money-laundering law. Solve that problem on its own terms.
What "Doing the Minimum" Will No Longer Cover
Under the directives AMLR replaces, customer due diligence was widely interpreted as a document-collection exercise: get a copy of the ID, take proof of address, file it, glance at it once a year. AMLR closes that door. Articles 19 to 28 establish CDD as a maintained dataset governed by explicit trigger logic, data-age rules and failure handling. Identity data must be tied to a specific, logged verification event with a timestamp. Triggers for re-verification must be defined in advance. Stale data creates a re-identification obligation.
In plain terms: the regulator no longer wants your filing cabinet. It wants proof of how, when and to what assurance level you established who someone is — and proof that someone signed what they signed. A photographed ID card emailed by a client cannot produce any of that.
The Article Practitioners Keep Misreading
The reference that gets underestimated is Article 22. Firms read it as a list of data points to collect — name, date of birth, document number, the Legal Entity Identifier where a company has one — and stop there. What they miss is that the same article sets the standard for how identity is verified, and that AMLR explicitly favours electronic identification carried out to an eIDAS-recognised standard. The collection list is the easy part. The verification standard is the part that quietly forces a change of method.
Why "We Do the Minimum" Is a Specific Risk, Not a Posture
Among law firms the most common stance is not defiance but drift: a box was ticked years ago, a template engagement letter mentions identity checks, and nobody has revisited it. The problem is that AMLR's standard is reproducibility, and a drifted process cannot be reproduced. When a supervisor asks how a particular client was verified in March, the firm needs to show the method, the assurance level and the timestamp — not a recollection that someone probably took a copy of a passport. The minimum, as currently practised, produces none of that.
Small financial advisers face a subtler trap. They know they are obliged entities, but they treat AML tooling as an overhead to be deferred, reasoning that their client base is low-risk and familiar. AMLR removes that discretion: simplified due diligence is confined to genuinely low-risk, documented scenarios, and the assessment itself must be evidenced. "I know my clients" is not a risk assessment a supervisor can read.
What This Costs the Firm That Waits
In conversations with professional-services firms, the pattern is consistent: the cost is not the fine, it is the scramble. One partner described the current process bluntly — asking a senior client to photograph an ID card and email it is embarrassing, and it produces nothing a supervisor would accept as a verification event. Firms discover during an audit, not before it, that years of "compliant on paper" onboarding leaves no reproducible trail, and that reconstructing it after the fact is impossible because the underlying events were never logged.
The firms that fare worst are the financial advisers who knew they were in scope and chose to underinvest, and the law firms that did nothing on the assumption that AML is somebody else's regime. AMLA, the new EU supervisor headquartered in Frankfurt, has been operational since July 2025, and most of its detailed technical standards and guidelines are due through 2026 — which makes 2026, not 2027, the year to act. A firm that waits until the application date to choose a method will be implementing a new onboarding process at the exact moment it is first expected to have one working. The cheaper path is to change the method now, while there is no deadline pressure, and let two years of clean records accumulate before anyone asks to see them.
What to Do Before July 2027
A small firm does not need an enterprise compliance department. It needs four things in place:
- A verification method that produces a logged, timestamped event — not a filed document.
- Identity established to an eIDAS-recognised assurance level, so the standard is defensible by reference to law rather than to your own best effort.
- A single place where the verification record and any signed declarations live, retrievable on demand.
- A clear internal rule for when re-verification is triggered, written down before a supervisor asks.
This is the operational gap Trust Circle is built to close: client identity is established once through a regulated EU identity app and reused, and every signing or KYC declaration becomes a verification event with a record behind it. That capability rests on ZealiD's status as a Qualified Trust Service Provider on the EU Trusted List, which means the assurance level is audited and externally verifiable, not asserted. For the underlying signature standard, see our explainer on what a qualified electronic signature actually is.
References
- Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, Articles 19–28 and 22. European Union, 2024. eur-lex.europa.eu
- Regulation (EU) No 910/2014 (eIDAS) on electronic identification and trust services. European Union, 2014. eur-lex.europa.eu
- Regulation (EU) 2016/679 (GDPR), Article 32 (security of processing). European Union, 2016. eur-lex.europa.eu