Skip to content
EBA · EU-wide

Simplified due diligence — five measures, one 60-day cap

Fintech Passport
August 20, 2026 · 10-min read
Simplified due diligence — five measures, one 60-day cap

Simplified due diligence is not reduced due diligence — it is a closed list of five specific relaxations, wrapped in four paragraphs of obligation that most firms never read. Article 33 of Regulation (EU) 2024/1624 permits them where, taking into account the risk factors set out in Annexes II and III, the relationship or transaction presents a low degree of risk. Paragraph 1 is the permission; paragraphs 2 to 5 are the price.

1. The five measures

LimbMeasureLimit
(a)Verifying the identity of the customer and the beneficial owner after the business relationship is establishedOnly where the specific lower risk identified justified postponement, and in any case no later than 60 days of the relationship being established
(b)Reducing the frequency of customer identification updatesReduced, not removed
(c)Reducing the amount of information collected to identify the purpose and intended nature of the relationship or occasional transaction, or inferring it from the type of transactions or relationship establishedInference must be from the transaction or relationship type
(d)Reducing the frequency or degree of scrutiny of transactions carried out by the customerReduced, not removed
(e)Any other relevant simplified measure identified by AMLA pursuant to Article 28Only measures AMLA identifies

The measures must be proportionate to the nature and size of the business and to the specific elements of lower risk identified. Then the sentence that governs the whole regime: however, obliged entities must carry out sufficient monitoring of the transactions and business relationship to enable the detection of unusual or suspicious transactions. Frequency and depth may fall under limb (d); sufficiency for detection may not.

2. Which lower-risk factors you may actually rely on

Annex II is a non-exhaustive list of factors and types of evidence of potentially lower risk, in three groups. A determination built on factors nobody recognises is the first thing an inspection unpicks.

  • Customer factors: listed public companies subject to disclosure requirements ensuring adequate transparency of beneficial ownership; public administrations or enterprises; customers resident in lower-risk geographical areas.
  • Product, service, transaction or delivery-channel factors: low-premium life policies; pension policies with no early surrender option that cannot be used as collateral; occupational schemes funded by wage deduction whose rules bar assignment of a member’s interest; products giving defined and limited services to certain customer types to increase access for financial inclusion purposes; and products whose risks are managed by other factors such as purse limits or transparency of ownership — the Annex names certain types of electronic money as the example.
  • Geographical factors — registration, establishment or residence in Member States; third countries with effective AML/CFT systems; third countries credible sources identify as having a low level of corruption or other criminal activity; and third countries which, on credible sources such as mutual evaluations, have requirements consistent with the revised FATF Recommendations and effectively implement them.

3. What has to be in writing (Article 33(2))

Two documentation duties sit in paragraph 2, and neither is met by a policy saying “SDD may be applied to low-risk customers”. Internal procedures established under Article 9 must contain the specific measures of simplified verification to be taken in relation to the different types of customers that present a lower risk — measures mapped to customer types and named in the procedure. And where a firm relies on lower-risk factors beyond the Annex, it must document decisions to take into account additional factors of lower risk.

Practically, the procedure needs a matrix, not a paragraph: customer type on one axis, which of limbs (a) to (d) applies on the other, and a cell for the evidence relied on. A firm that cannot produce it has a permission it cannot use.

4. The 60-day cap and the pre-verification regime

Limb (a) is the only measure with a number attached, and it is absolute: postponed verification must complete no later than 60 days of the relationship being established, and only where the specific lower risk identified justified the postponement.

What most firms miss is paragraph 3, which is not optional. For the purpose of applying limb (a), obliged entities shall adopt risk management procedures with respect to the conditions under which they can provide services or perform transactions for a customer before verification takes place, including by:

  • limiting the amount, number or types of transactions that can be performed; or
  • monitoring transactions to ensure they are in line with the expected norms for the business relationship at hand.

So limb (a) is not “open the account and verify within 60 days” but “open the account under a constrained transaction regime, and verify within 60 days”. A build that grants full functionality on day one and sets a reminder has implemented half of Article 33(3) — and skipped the half that limits loss.

5. Worked example — an e-money product with purse limits

Facts: an e-money institution launches a capped wallet: EUR 150 maximum balance, no cash withdrawal, top-ups only from a verified payment account in the customer’s own name, no outbound transfers to third parties.

Which rules apply: Annex II point (2)(e) recognises products whose risks are managed by other factors such as purse limits, and names certain types of electronic money. Combined with a customer base resident in Member States (point (3)(a)), the low-risk determination is well founded, and limbs (b), (c) and (d) are available.

What the practitioner does: writes the determination down against the named Annex factors rather than against “it is a low-value wallet”, and records which limbs apply to this customer type in the Article 9 procedure. The firm keeps sufficient monitoring for detection — here, rules on top-up velocity and on one funding instrument appearing across unrelated wallets.

Outcome: the product controls that justified the finding — the cap, the funding restriction, the absence of third-party transfers — become compliance-relevant configuration. Change any of them and the determination must be redone.

6. The conditions have to be re-checked (Article 33(4))

Simplified treatment is the one regime that gets less accurate over time by default: the customer was low risk when assessed, and nothing inside a reduced-scrutiny regime is designed to notice when they stop being so. The Regulation closes that gap. Obliged entities must verify on a regular basis that the conditions for the application of simplified due diligence measures continue to exist, at a frequency commensurate with the nature and size of the business and the risks posed by the specific relationship.

That is a scheduled obligation, not a duty to react — and the cadence is itself a risk-based decision the firm must be able to explain: one interval for a capped wallet, another for a corporate customer treated as low risk because it is listed.

7. Five situations where you must stop (Article 33(5))

Paragraph 5 lists the circumstances in which obliged entities shall refrain from applying simplified due diligence measures. These are not risk-appetite settings; they are mandatory exits.

TriggerWhat it means operationally
Doubts as to the veracity of information provided by the customer or beneficial owner at the identification stage, or detected inconsistencies in itA data-quality flag raised at onboarding is a regime change, not a queue item
The factors indicating a lower risk are no longer presentRequires the factors to have been recorded individually in the first place
Monitoring of the customer’s transactions and the information collected exclude a lower-risk scenarioMonitoring output must be able to write back to the customer’s regime
There is a suspicion of money laundering or terrorist financingSuspicion ends simplified treatment before and independently of any filing decision
There is a suspicion that the customer, or a person acting for them, is attempting to circumvent or evade targeted financial sanctionsSanctions-evasion signals must reach the CDD regime, not only the screening team

The common engineering requirement across all five is a write path from detection back into the customer record. In most builds the arrows point one way only: the risk rating configures monitoring, and monitoring never reconfigures the rating.

8. Worked example — an inconsistency at identification

Facts: a customer onboards to the capped wallet above. The name on the funding instrument differs from the name given at registration by more than a transliteration; the check records a mismatch but the account opens because the product is on the simplified path.

Which rules apply: Article 33(5), first limb. Detected inconsistencies in the information provided at the identification stage require the firm to refrain from applying simplified measures — the relationship moves to standard due diligence immediately, whatever the product’s classification says. If the firm then cannot comply with Article 20(1) at all, Article 21 applies: refrain, terminate, and consider reporting to the FIU under Article 69.

What the practitioner does: makes the mismatch a hard gate on the simplified path rather than an alert. The same logic governs the 60-day clock under limb (a): the expiry needs a defined consequence, and Article 21 supplies it.

Outcome: the customer leaves the simplified population on day one rather than in a later file review. Two nuances of Article 21 matter before terminating: it does not prohibit the receipt of funds due to the obliged entity, and where the firm has a duty to protect the customer’s assets, termination does not require their disposal.

9. Limb (e), and what is still missing

“Any other relevant simplified due diligence measure” is not open-ended. It means measures identified by AMLA pursuant to Article 28, which mandates regulatory technical standards on the information necessary for customer due diligence. Article 28(1)(b) covers the type of simplified measures permitted in situations of lower risk under Article 33(1), including measures for specific categories of obliged entity and for particular products, having regard to the Union-level risk assessment the Commission conducts under Article 7 of Directive (EU) 2024/1640. AMLA was required to submit the draft standards to the Commission by 10 July 2026.

Until they are in force, limb (e) has no content a firm can rely on, and the minimum requirements in situations of lower risk under Article 28(1)(a) are also still to be set. Build on limbs (a) to (d), and expect the standards to land on the Article 9 procedure rather than on the code.

One point for the policy: simplified due diligence is a permission, not an obligation — Article 33 says entities may apply the measures. Where the cost of two regimes, a review cadence and five mandatory exits exceeds the saving, running full measures for everyone is legitimate and far simpler to evidence.

FAQ

How long can verification be postponed under simplified due diligence?

No later than 60 days after the business relationship is established, and only where the specific lower risk identified justified the postponement.

Can a customer transact freely during those 60 days?

No. Article 33(3) requires risk management procedures governing what the customer may do before verification — limiting the amount, number or types of transactions, or monitoring them against the expected norms for the relationship.

Can monitoring be switched off for low-risk customers?

No. Frequency or degree of scrutiny may be reduced under limb (d), but sufficient monitoring must remain to enable detection of unusual or suspicious transactions.

Which lower-risk factors can be relied on?

Those in Annex II, which is non-exhaustive: customer, product and channel, and geographical factors — the product group including financial-inclusion products and products whose risk is managed by purse limits or ownership transparency, with certain electronic money named as the example. Additional factors may be used, but the decision must be documented.

When must simplified treatment stop?

In the five Article 33(5) situations: doubts or detected inconsistencies in identification information; lower-risk factors no longer present; monitoring excluding a lower-risk scenario; suspicion of money laundering or terrorist financing; and suspicion of attempted circumvention or evasion of targeted financial sanctions.

Is there a duty to re-check that simplified treatment is still appropriate?

Yes. Article 33(4) requires regular verification that the conditions continue to exist, at a frequency commensurate with the nature and size of the business and the risks of the specific relationship.

Can we design our own simplified measures?

Only within the list. Limb (e) covers measures identified by AMLA under Article 28 — standards AMLA was to submit to the Commission by 10 July 2026 — not measures a firm devises for itself.

What to do, today

  • MLRO: check the Article 9 procedure names specific simplified measures per lower-risk customer type. A general permission is not compliance with Article 33(2).
  • Product owner: where a product opens before verification, write down the pre-verification limits and confirm the platform enforces them, not guidance.
  • Engineer: build the write path from monitoring and screening back to the due diligence regime. All five Article 33(5) triggers depend on it.
  • Compliance officer: set and justify the Article 33(4) cadence per customer type, and give the 60-day expiry a defined consequence under Article 21.

Related: Enhanced due diligence · Timing of verification · Inability to complete customer due diligence · The customer risk profile

Related reads.