The RTS on Customer Due Diligence (CDD), stemming from EU Regulation 2024/1624 (AMLR), constitutes one of the key mandates given its crucial role in laying down the requirements and information to be collected for the purposes of standard, simplified and enhanced due diligence; as well as in specifying the electronic identification means required for the identification and verification of the customer and of the beneficial owners.
Against this background, the EACB appreciated the opportunity provided by AMLA to submit its feedback to the Consultation on the RTS on CDD.
Some of the main messages emerging from the response include the following:
- A key overarching consideration is the need to ensure that the RTS fully preserves the risk-based approach embedded in the AMLR, ensuring that requirements remain proportionate and do not become overly prescriptive, while maintaining the ability of obliged entities to apply measures tailored to the actual level of risk.
- In relation to the design of due diligence requirements, concern is raised that the draft RTS does not ensure a sufficient and meaningful differentiation between standard CDD and simplified due diligence, which risks limiting the practical usability of SDD and effectively reducing its value as a proportionate tool for low-risk situations.
- From a proportionality and efficiency perspective, it is considered that the draft RTS may in some areas lead to duplication or overextension of CDD obligations, particularly where intermediaries already perform robust AML/CFT controls, thereby generating limited additional risk mitigation while increasing complexity and cost (Articles 17, 22).
- A further area of concern relates to the need to safeguard technological neutrality and practical implementability, as the RTS must remain fully aligned with current market readiness. In particular, concerns arise in relation to electronic identification solutions (Article 7), where certain provisions introduce an “eIDAS-first” approach. By prioritising eIDAS-compliant means or requiring justification for the use of alternative verification methods, the draft risks creating a de facto hierarchy of solutions not envisaged under the AMLR.
- Closely linked to the need for a proportionate implementation of the framework, it is important to reaffirm the principle of consistency with data protection requirements, ensuring that the RTS do not lead to unnecessary or excessive collection of personal data relating to customers, beneficial owners, or related individuals.
- Finally, it is considered essential that the RTS remain fully consistent with the overall AML framework and do not introduce interpretations or requirements that could extend the scope of obligations beyond what is foreseen in the Level 1 text.