AMLR 2027 / EU AML Single Rulebook

AMLR 2027 Readiness: AML Solutions Built to Meet the Deadline

From 10 July 2027, the EU Anti-Money Laundering Regulation applies directly across all 27 member states, with no transposition period and no national variation. Plenty of firms understand the rules. Fewer have software that can deliver them. Dreamix builds and integrates the AML systems behind AMLR readiness, from KYC and screening through to monitoring and FIU reporting, so they hold up once supervision starts.

Standards and frameworks we work under
AMLR / AMLD6 eIDAS 2 / EUDI Wallet SOC 2 ISO 27001 GDPR PSD2 MiFID II DORA
300+
engineers across regulated-industry domains
20+ years
building software for financial services, insurance and fintech
Synechron group
EU-jurisdiction nearshore delivery from Bulgaria
Dreamix industry awards
Global Award Spring 2025 1 - AMLR 2027 Readiness: AML Solutions Built to Meet the Deadline
FBA2023 04 Tag FINALIST Employer of 2024 3 1 - AMLR 2027 Readiness: AML Solutions Built to Meet the Deadline
FBA2023 04 Tag FINALIST Company of 2024 ICT 2 3 1 - AMLR 2027 Readiness: AML Solutions Built to Meet the Deadline
unnamed 3 1 - AMLR 2027 Readiness: AML Solutions Built to Meet the Deadline
IBA25 Gold Winner - AMLR 2027 Readiness: AML Solutions Built to Meet the Deadline
2026 TITAN Business Awards Status Logo Gold 2 - AMLR 2027 Readiness: AML Solutions Built to Meet the Deadline
Globee - AMLR 2027 Readiness: AML Solutions Built to Meet the Deadline

The AMLR clock is already running

The EU AML package replaced a patchwork of national rules with one directly applicable regulation. There is no transposition period for the AMLR and no country-by-country interpretation. The same rules will become applicable to everyone in scope on the same day.

Key dates

1 July 2025

AMLA, the new Anti-Money Laundering Authority in Frankfurt, became operational.

1 January 2026

The European Banking Authority handed its AML/CFT mandates to AMLA.

10 July 2027

The AMLR applies directly across the EU. The Regulatory Technical Standards (RTS) that sit underneath it carry the same legal weight from the same date.

2028

AMLA begins direct supervision of around 40 high-risk, cross-border institutions.

This is a fixed deadline with no soft launch. If your AML systems are still in procurement or design by early 2027, you are behind. Building the systems, wiring them into what you already run, and testing them properly is going to take time.

AMLR requirements

What AMLR actually asks of your systems

The AMLR reshapes operations and policy, but most of the heavy lifting falls on technology. These are the requirements that turn into engineering work.

Harmonised, auditable CDD and KYC

One rulebook means your onboarding can no longer lean on the country-specific flows stitched together over the years. Customer due diligence has to be consistent and reproducible across every entity you run, with the evidence to back each decision.

Stronger identity verification

Under the AMLR and its RTS, eIDAS-compliant electronic verification counts as equivalent to face-to-face. From late 2027, regulated firms also have to accept EU Digital Identity Wallet presentations. Both are real integration jobs.

Beneficial ownership at the new threshold

UBO identification moves to 25% or more, with tighter verification. Your data model and screening logic need to reflect that.

Ongoing monitoring and perpetual KYC

Point-in-time checks at onboarding will not cut it. Systems have to refresh risk on a schedule and react when something changes, which puts real pressure on data quality and on how cleanly your customer records connect.

Transaction monitoring that holds up

Supervisors increasingly treat static, rule-only monitoring as too weak to catch real risk. Risk-based scoring and AI-assisted detection are the way forward, and they also take work off your analysts by cutting false positives.

Integrated sanctions and PEP screening

The AMLR ties due diligence and sanctions obligations together, so screening cannot keep sitting in its own silo away from onboarding and monitoring.

Audit trails, data lineage and five-year retention

Regulators want to see why a decision was made, with the data trail to prove it, retrievable quickly when they ask.

Reporting to Financial Intelligence Units

Your suspicious activity reporting pipelines have to be dependable and correctly formatted for the harmonised expectations the framework brings.

If your current stack is a mix of legacy systems and bought-in tools that were never designed to work together, this is the gap that AMLR exposes.

Can off-the-shelf AML software get you there?

It helps, though it rarely gets a firm all the way there. Identity and KYC products do their slice well, and so do screening tools. What is left over is the space between them: connecting those tools to core banking, feeding them clean data, building the workflows no product covers, and pulling it together into the single auditable view of a customer that supervisors expect.

That space between the tools is where we work. Rather than sell you another product to bolt on, we build the custom pieces, wire in the tools you have already chosen, and modernise the legacy systems that cannot meet the new standards, so the whole thing runs as one compliant stack.

What we build

What we build for AMLR readiness

Each area below maps to systems we already build and run as an engineering partner for regulated firms and RegTech vendors.

01

01 Onboarding and verification

KYC and KYB workflows, eIDAS and EUDI Wallet integration, sanctions and adverse-media screening, risk-assessment scoring, CDD and EDD flows built to the AMLR's harmonised standard.

02

02 Ongoing financial crime monitoring

Perpetual KYC, payments monitoring and screening, transaction monitoring, SAR generation and FIU reporting pipelines.

03

03 AI and ML for monitoring

Risk-based transaction monitoring and anomaly detection that improves on rule-only systems and cuts false positives, with explainable, auditable outputs.

04

04 The customer risk data layer

Data engineering to consolidate fragmented customer and KYC data into a single, clean, queryable source of truth, with the lineage and audit trails AMLR demands.

05

05 Integrations

Connecting identity providers, screening engines, core banking and your existing vendor tools into one workflow through reliable API integration.

06

06 Legacy modernisation

Rebuilding or re-platforming AML systems that cannot meet RTS-level requirements, without stalling the rest of your roadmap.

Not sure where your stack falls short?

Tell us where you are with AMLR. We will map it to the engineering work that gets you ready.

Book an AMLR readiness assessment

Who we build for

Who we build AMLR-ready systems for

Banks and financial institutions

High obligations, severe cost of failure, and integration complexity across core banking. We build AML systems that connect reliably into the infrastructure you already run.

Fintech and payment platforms

Compliance that has to scale with the business and across jurisdictions, built so growth does not mean re-engineering every time.

Crypto-asset service providers (CASPs). Newly and firmly in scope, with travel-rule and traceability obligations. We build the monitoring and screening to match.

Newly obliged entities

High-value goods, certain professional sectors and others entering AML scope for the first time, who need compliance capability built from the ground up.

RegTech vendors

Companies building AMLR-related products who need extra engineering capacity to add capability without slowing their roadmap.

How we engage

How we work with you on AMLR

Four ways to engage, matched to where your platform is today.

AMLR readiness assessment and remediation

An engineering-led review of your current AML systems against AMLR and the RTS, followed by a clear remediation plan and the team to deliver it. A practical entry point if you are not sure where the gaps are.

Specialist engineering pods

Time-boxed teams for a specific job: a KYC rebuild, AI transaction monitoring, the customer data layer, or FIU reporting.

Product engineering partner

Full ownership of a product or module, from architecture through build, release and support.

Dedicated engineering teams

Long-running teams embedded into your delivery model for multi-year compliance modernisation.

Case studies

Compliance platforms we have built

  • Building an AI Platform for the Compliance Industry

    Our client is a leader in compliance technology solutions for regulated financial firms. As the volume of data compliance teams must monitor keeps growing, they saw an opportunity to use AI to get ahead of it. They partnered with Dreamix to build Encore: a production-grade AI platform that today gives compliance teams access to 100+ […]

  • Streamlining compliance with a comprehensive ARL management tool 

    Navigating regulation has always been a core challenge for companies. For nearly two decades, MCO has been at the forefront of creating solutions to help overcome this hurdle. In the currently growing complexity of the regulatory landscape, the US-based platform recognized a rare opportunity to make compliance more straightforward for their clients.  After joining forces […]

  • Automating Asset-Backed Finance ETL for Insurance Giant 

    Our client, a major insurer managing asset-backed finance portfolios across 20+ banking partners, saw an opportunity to modernize their data consolidation processes. Credit line data arrived in different formats via email from multiple institutions, requiring significant manual processing. They partnered with us to build a comprehensive ETL system that automated data processing, improved accuracy, and […]

Why Dreamix

Why firms choose Dreamix for AML engineering

Regulated-industry engineering

Over a decade building software for financial services, insurance and fintech clients under heavy regulatory scrutiny.

Part of the Synechron group

Dreamix is part of Synechron, a global financial services consultancy with deep regulatory expertise across 21 countries.

EU nearshore delivery

EU jurisdiction, full time-zone overlap with the UK and EMEA, same-day overlap with the US.

Compliance-aware engineering

Practices aligned with the security, audit and traceability standards regulated firms work under, including GDPR-aligned data handling and audit-ready change control.

Low-turnover teams

A 95% employee retention rate, so the team that builds your AML systems is the team that still knows them next year, when the requirements shift again.

Technology stack

The technology we build on

Java and Spring Boot for robust backend services, Angular and React for user-facing applications, microservices for scale, Kafka and Elasticsearch for data-heavy workloads, Python for AI and ML, and cloud-native deployment on AWS and Azure.

Java · Spring Boot · Angular · React · Node.js · Microservices · Kafka · PostgreSQL · Python · Elasticsearch

Development approach

How a build comes together

1

Discovery

We map your AMLR obligations, your current AML systems and your integration landscape.

2

Architecture

Integration design, data model, security architecture and the technology choices that shape the platform.

3

Build

Focused Agile sprints with regular touchpoints, so the work stays visible and adaptable as the RTS detail firms up.

4

Integrate and test

Functional, integration, security and performance testing before anything reaches production.

5

Deploy and support

We stay involved after launch, ready to respond as AMLA guidance and technical standards evolve.

Frequently asked questions about AMLR readiness

The AMLR applies directly across all 27 EU member states from 10 July 2027. The Regulatory Technical Standards underneath it are legally binding from the same date. There is no transposition period and no grace period.

Not necessarily. Some firms need a rebuild, but many need integration, data work and modernisation around the tools they already have. The first step is understanding which parts of your stack meet the new technical standards and which do not. That is what our readiness assessment is for.

The AMLR is the high-level law that sets out what obliged entities must do. The Regulatory Technical Standards fill in the operational detail of how to do it. Both take effect on 10 July 2027 and both are legally binding.

Banks and financial institutions, payment and e-money firms, crypto-asset service providers, and a set of newly obliged entities including certain high-value sectors. If you are unsure whether you fall in scope, it is worth checking early, because the build timeline is tight.

Yes. A large part of AMLR readiness is connecting the tools you have already chosen into one workflow with clean data and a clear audit trail. We build those integrations rather than asking you to start over.

From 2028, AMLA will directly supervise around 40 high-risk, cross-border institutions. Even if you are not on that list, you are still subject to the AMLR and the same technical standards, so the engineering work is the same.

It depends on scope. A focused piece such as a KYC rebuild or a reporting pipeline can be delivered in months. A wider modernisation across multiple systems takes longer and works best in phases. Given the 2027 deadline, earlier starts leave more room to test.

Send us a short brief on where your AML systems stand. We will route it to the engineering lead with the closest domain coverage and come back to you quickly.