KYC/KYB under AMLR & RTS: What will really change for banks and PSPs | ALLES LEGAL #128

🎧KYC and KYB are taking centre stage in the new EU AML framework. In this episode of Alles Legal – Fintech-Recht kompakt, Dana Wondra speaks with Sebastian Glaab and Dr Camillo Werdich about how the EU AML package reshapes customer due diligence and why KYC will increasingly become a continuous, risk-based process.

Podcast: https://paymentandbanking.podigee.io/803-alles-legal-128-kyc-kyb-unter-amlr-rts-was-sich-fur-banken-und-psps-wirklich-andert/

From onboarding step to continuous monitoring

In this episode, Dana Wondra (Payment & Banking) speaks with Sebastian Glaab (Annerton) and Dr Camillo Werdich (Sinpex) about the evolving Know Your Customer (KYC) and Know Your Business (KYB) requirements under the EU AML package.

A key takeaway: the regulatory understanding of KYC is shifting. Instead of being treated primarily as a one-off onboarding procedure, regulators increasingly expect institutions to treat KYC as a continuous and risk-based process.

After all, effective anti-money laundering measures ultimately depend on whether firms truly know who they are doing business with.

More data points and stricter expectations

KYC was always intended to be an ongoing process. In practice, however, many institutions relied heavily on periodic reviews, sometimes with several years between updates.
The AMLR and the Regulatory Technical Standards (RTS) now provide much clearer expectations and expand the scope of KYC considerations, including:

  • customer identity
  • beneficial ownership structures
  • authorised representatives
  • sanctions exposure
  • data maintenance and updates
  • documentation and traceability

As a result, KYC is evolving from a compliance checklist into a structured process architecture.

Data quality and “defensibility”

Many organisations still operate systems that were never designed to manage KYC/KYB as a continuous lifecycle process. Data flows are sometimes still handled manually – using spreadsheets, shared folders or scattered documentation.
Under the new regulatory framework, this becomes problematic. Institutions must not only present outcomes but also demonstrate how those outcomes were reached, including:

  • the underlying documentation
  • the steps taken in the process
  • the audit trail behind the decision

This concept is often referred to as “defensibility” – the ability to justify and document compliance decisions during regulatory reviews.

Small data fields, big operational impact

One example discussed in the episode illustrates how seemingly small regulatory changes can create significant operational challenges.
In the future, nationalities must be collected more comprehensively. While this may appear minor, it raises major questions for existing customer data, potentially requiring firms to update records and contact customers again.
Many such additional data points together can quickly evolve into a large-scale transformation project for KYC processes and data management.

Technology helps – responsibility stays in-house

Another key discussion point concerns third-party service providers.
Many institutions rely on external providers for identification and verification processes. However, the new regulatory framework makes one thing very clear:

Responsibility cannot be outsourced.

Technology may accelerate processes and support compliance teams, but risk decisions remain with the regulated entity.

Start with an honest gap analysis

As a practical takeaway, the speakers recommend beginning with a comprehensive gap analysis of existing KYC processes.

Key questions include:

  • What data is currently collected?
  • Where do manual steps still exist?
  • Which documentation is missing?
  • How transparent and auditable are the current processes?

Organisations that still treat KYC primarily as a single onboarding step may find that incremental adjustments are no longer sufficient under the new EU AML regime.
Instead, the focus will increasingly shift to process architecture, data governance and accountability.

About this podcast

Alles Legal – Fintech Recht Kompakt delivers sharp, weekly insights into legal and compliance matters in the world of banking. (in German only)
This podcast is a collaboration between Payment & Banking and PayTechLaw.
Each Wednesday, we unpack the legal developments shaping the financial world – clearly, concisely, and without the legal jargon.
Since 2021, PayTechLaw authors and Annerton attorneys have brought depth and clarity to complex topics.
Whether it’s PSD3, DORA, or FiDA – we provide the legal context you need.
In 20 minutes. No detours.



By continuing, you accept our privacy policy.
You May Also Like
MiCAR trifft PSD2: Warum E-Geld-Token plötzlich doppelt reguliert werden | ALLES LEGAL #138
Read More

MiCAR meets PSD2: Why e-money tokens are suddenly subject to dual regulation | ALLES LEGAL #138

Since the end of the EBA transitional period in March 2026, many crypto-asset service providers have had to assess whether, in addition to MiCAR, they also require a PSD2 or national payment services licence. In this episode, Kemal Ahmedi explains why crypto regulation and payment services law overlap and what this means for business models and licensing strategies.
Read More
AMLA konsultiert Leitlinien zur laufenden Überwachung von Geschäftsbeziehungen – Was auf Verpflichtete zukommt AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect
Read More

AMLA Consults on Guidelines for the Ongoing Monitoring of Business Relationships – What You Should Expect

Continuous monitoring is already one of the core obligations in anti-money laundering compliance today. However, the AMLR elevates this principle to a new level. Obliged entities must not only review individual transactions but continuously analyse and assess the entire business relationship throughout its lifecycle.
Read More
MiCAR erklärt: Was die neue Krypto-Regulierung für Unternehmen verändert | ALLES LEGAL #137 MiCAR explained: How the new crypto regulation is changing the market | ALLES LEGAL #137
Read More

MiCAR explained: How the new crypto regulation is changing the market | ALLES LEGAL #137

With MiCAR, the EU is introducing its first harmonised regulatory framework for crypto-assets. In the latest episode of “Alles Legal – Fintech-Recht kompakt”, Kemal Ahmedi from Annerton explains which companies will require a MiCAR licence, why stablecoins are subject to stricter regulation and how the EU passport could reshape the European crypto market.
Read More