Skip to content
EBA · EU-wide

Timing of verification — AMLR Article 23 explained

Fintech Passport
August 20, 2026 · 9-min read
Timing of verification — AMLR Article 23 explained

“Verify before you onboard” is the rule, and Regulation (EU) 2024/1624 provides three structured exits from it. Article 23 of the AMLR sets the default — verification of the customer, the beneficial owner and certain other persons takes place before the establishment of a business relationship or the carrying out of an occasional transaction — and then allows completion during establishment, an account-opening derogation for credit and financial institutions, and postponement in lower-risk cases, which Article 33 caps at 60 days. A fourth paragraph adds a proof-of-registration duty for legal entities that most onboarding flows have not yet built. The Regulation applies from 10 July 2027; until then the national transpositions of Article 14 of Directive (EU) 2015/849 govern.

1. The default, and who it covers

Article 23(1) requires verification of three populations before the relationship starts or the occasional transaction is carried out: the customer, the beneficial owner, and the persons in Article 20(1), points (h) and (i) — natural persons on whose behalf or for whose benefit a transaction is conducted, and any person purporting to act on behalf of the customer, whose authority must also be verified. The third group is where flows leak: an authorised signatory added after onboarding, or a director operating a business account, is a person who must be verified under the same timing rule.

Article 23(1) also carries a sector-specific rule: for real estate agents, verification is carried out after an offer is accepted by the seller or lessor, and in all cases before any funds or property are transferred. It does not apply to payment firms but shows how the legislator anchors timing to the moment value moves.

The means of verification are set elsewhere. Article 22(6) allows either an identity document, passport or equivalent — with information from reliable and independent sources where relevant — or electronic identification means meeting Regulation (EU) No 910/2014 at assurance level substantial or high. Article 22(7) lets beneficial owners be verified either the same way or by reasonable measures using the customer and reliable sources, and in addition requires a check against the central beneficial ownership registers.

2. The three exits, side by side

The structure only becomes clear when the routes are compared. They have different triggers, different conditions and different end points, and a firm that blends them into one “pending KYC” status cannot show which one it relied on.

RouteProvisionConditionEnd point
Completion during establishmentArt. 23(2)Necessary not to interrupt normal business and little ML/TF risk“As soon as practicable after initial contact”
Account opened, capability blockedArt. 23(3)Credit or financial institution only; adequate safeguards that no transaction is carried out by or for the customerUntil full compliance with Art. 20(1)(a) and (b)
Postponement in lower-risk casesArt. 23(1) second sentence + Art. 33(1)(a)Low risk under Annexes II and III and the specific lower risk justifies postponementNo later than 60 days after the relationship is established

Only the third route allows the customer to transact before verification. Article 23(3) is the opposite: the account exists, but nothing moves. Article 23(2) sits between them — it concerns completing verification while the relationship is being established, under a standard rather than a fixed period.

3. Completion during establishment — Article 23(2)

Verification of the customer and the beneficial owner may be completed during the establishment of the relationship where two conditions hold together: it is necessary so as not to interrupt the normal conduct of business, and there is little risk of money laundering or terrorist financing. The procedures must then be completed as soon as practicable after initial contact.

“As soon as practicable” is assessed after the fact, on the facts. A firm relying on it should set an internal limit, measure performance against it, and treat breaches as exceptions with an owner. The necessity condition also needs a reason that holds up: a product where the customer expects to fund an account the same day may meet it; a product where nothing happens until the customer completes onboarding does not need the derogation at all.

4. The account-opening derogation — Article 23(3)

A credit institution or financial institution may open an account, including one permitting transactions in transferable securities, as may be required by a customer, provided adequate safeguards ensure that no transaction is carried out by the customer or on its behalf until full compliance with Article 20(1), points (a) and (b) — identifying and verifying the customer, and identifying the beneficial owners and taking reasonable measures to verify them. That second limb matters: for a business customer, the account stays frozen until the ownership work is done, not just the company check.

The control therefore moves from account creation to account capability.

StateWhat can happenControl
Account createdThe record and IBAN existPermitted under Art. 23(3)
Verification pendingNo transaction by or for the customerAn account state enforced by the ledger and the payment rails, not a banner
Verification completeFull capability releasedA state transition with a recorded trigger and timestamp

The standard failure is an incoming credit. If the IBAN is live, a third party can pay into it; the safeguard must decide what happens to those funds — held, returned, or credited but frozen — and that decision belongs in the procedure before launch, not in an incident review afterwards.

5. Postponement and the 60-day cap — Article 33

The second sentence of Article 23(1) disapplies the default in lower-risk situations under the simplified due diligence section, provided the lower risk justifies postponement. Article 33(1)(a) turns that into a measure with a hard ceiling: verification after the relationship is established, in any case no later than 60 days from its establishment. Directive (EU) 2015/849 contained no such cap; firms whose current postponement windows were designed under national law should check them against 60 days now.

Article 33(3) adds the condition that makes postponement auditable: risk management procedures on what the customer can do before verification, including limiting the amount, number or types of transactions or monitoring that activity matches expected norms. Article 33(5) then lists situations where SDD must stop — doubts about the veracity of information, the lower-risk factors no longer present, monitoring that excludes a lower-risk scenario, suspicion of ML/TF, or suspicion of attempts to evade targeted financial sanctions. Any of those, during the 60 days, ends the postponement.

Separately, Article 19(7) allows supervisors to exempt certain e-money products from Article 20(1)(a)–(c) entirely — non-reloadable, stored value up to EUR 150, used only for the issuer’s or a network’s goods and services, not linked to a payment account, no cash or crypto redemption, with sufficient monitoring. That is an exemption, not a timing rule, and it applies only where the supervisor has granted it.

6. Proof of registration for legal entities — Article 23(4)

When entering into a new relationship with a legal entity, or with the trustee of an express trust or an equivalent arrangement, that must register beneficial ownership under Article 10 of Directive (EU) 2024/1640, the obliged entity must collect valid proof of registration or a recently issued excerpt of the register confirming the registration is valid. The duty sits in the timing article, so it is part of onboarding, not a later remediation step.

Operationally this is a document to store, not just a lookup to perform. A screenshot of a search result is weak evidence; an extract or confirmation issued by the register is better. It also feeds the discrepancy duty — see the article on register discrepancies.

7. Three scenarios

Scenario one — the consumer e-money wallet. Facts: an EMI wants customers to top up a wallet immediately and complete video identification within days. Rule: Article 23(3) does not help — it forbids transactions. The firm needs Article 23(1) with Article 33(1)(a): a documented lower-risk population. What the officer does: records why the product is lower risk under Annexes II and III, sets load and spend caps under Article 33(3), sets a verification deadline well inside 60 days, and defines the Article 33(5) triggers that end postponement. Outcome: a defensible postponement with a hard stop, and Article 21 applies on day 60 if verification has failed.

Scenario two — the SME business account. Facts: a PI issues an IBAN on application so the customer can share payment details, but ownership verification of a two-layer holding structure is still open. Rule: Article 23(3) — account open, no transactions until Article 20(1)(a) and (b) are complete; Article 23(4) — proof of registration collected. What the officer does: confirms the account state blocks outgoing and incoming movements, sets the treatment for unexpected credits, and stores the register extract. Outcome: the IBAN is live, the money is not.

Scenario three — the added signatory. Facts: six months after onboarding, a business customer adds a finance manager with payment rights. Rule: Article 20(1)(i) and the Article 23(1) timing — the person purporting to act must be verified, with authority checked, before acting. What the officer does: routes user-addition through the same verification gate as onboarding. Outcome: no unverified operator on a verified account.

Article 22 sets what is identified and how it is verified; Article 21 governs what happens when CDD under Article 20(1) cannot be completed — refrain, terminate, and consider a report under Article 69, with records kept of the decision under Article 21(3). The Article 23 routes buy time; they do not change the outcome if verification fails. A postponement route without a defined failure path produces accounts that sit unverified indefinitely, because nothing forces the Article 21 decision.

Article 21(1) also says termination does not prevent receipt of funds due to the obliged entity, and where the firm must protect customer assets, termination does not require disposing of them — relevant for safeguarded e-money balances on a failed-verification account.

FAQ

When does Article 23 AMLR apply?

From 10 July 2027. Until then, national rules transposing Article 14 of Directive (EU) 2015/849 apply; they contain equivalent before-the-relationship, during-establishment and account-opening provisions, but no 60-day cap.

Can we open an account before verification is complete?

Yes, under Article 23(3), if adequate safeguards ensure no transaction is carried out by or for the customer until the customer and beneficial owners are identified and verified as Article 20(1)(a) and (b) require.

Can a customer transact before verification?

Only under the lower-risk route: Article 23(1) with Article 33(1)(a), where the specific lower risk justifies postponement, with limits under Article 33(3), and verification no later than 60 days after the relationship starts.

What does “as soon as practicable” mean?

It is a standard, not a fixed period. Set an internal limit for Article 23(2) cases and be able to evidence performance against it.

Do we need the UBO register extract for every business customer?

Article 23(4) requires proof of registration or a recent register excerpt for new relationships with legal entities and trustees subject to beneficial ownership registration under Article 10 of Directive (EU) 2024/1640.

What if verification never completes?

Article 21 applies: refrain from the transaction or relationship, terminate it, consider a suspicious transaction report under Article 69, and record the decision.

What to do, today

  • Map every onboarding flow to one of the three routes and record which one it relies on.
  • Check any postponement window against the 60-day cap in Article 33(1)(a).
  • Test that a “pending” account cannot send or receive funds, including incoming credits from third parties.
  • Add proof-of-registration capture for legal-entity customers to onboarding.
  • Route added signatories and representatives through the same verification gate.

Related: When due diligence cannot be completed · Simplified due diligence · EBA remote onboarding guidelines

Related reads.