SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Shufti launches EU AMLR compliance service for firms

Shufti launches EU AMLR compliance service for firms

Wed, 9th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Shufti has launched a compliance preparation service for firms affected by the European Union's Anti-Money Laundering Regulation, aimed at obliged entities across the EU.

The offering centres on a single platform that maps the regulation's requirements to customer onboarding, identity checks, business verification, monitoring and remediation.

The regulation will introduce a single anti-money laundering and counter-terrorist financing rulebook across all 27 EU member states, replacing national regimes that have varied by country. It covers banks, payment and e-money institutions, fintech groups, digital-asset service providers, crowdfunding platforms and some high-value-goods traders, and extends to certain non-EU firms operating within its scope.

At the heart of the changes is a sharper focus on evidence. Firms will be expected not only to check customers and beneficial owners, but also to show supervisors that those controls are effective and that records remain current on a risk basis.

Rulebook shift

Shufti has aligned its product set with the main compliance steps created by the regulation. These include remote identity verification, business verification, ongoing checks on ultimate beneficial ownership, sanctions and politically exposed persons screening, behavioural monitoring, enhanced due diligence and audit trails.

Identity verification is a central issue under the new framework. According to Shufti, Article 22 requires firms to use reliable and independent sources, while draft technical standards under Article 28(1) point to eIDAS-grade verification as a reference point for customer due diligence and enhanced due diligence.

The company also pointed to the planned introduction of EU Digital Identity Wallets under eIDAS 2.0. These wallets are expected to become available from late 2026, with obliged entities required to accept them as the rollout advances from 2027.

Another major operational issue is the treatment of existing customers. Under Article 26, firms must keep records up to date on a risk basis, while Articles 51 and 52 require them to identify beneficial owners with holdings of 25% or more.

That could prove especially difficult in know-your-business checks, where ownership and management structures can change over time. In practice, verification of companies and their beneficial owners may need to become a continuing process rather than a one-off check at onboarding.

Single platform

Shufti's system combines remote onboarding with identity document reading, NFC chip checks, face matching and passive liveness testing. It also includes qualified electronic signatures in the same workflow, allowing a user to move from identity verification to signing within a single process recognised across the EU and EEA under eIDAS.

The platform also records each verification in a time-stamped chain of custody. That record can then be exported for use by auditors and regulators.

For business verification, Shufti checks companies against official registries and identifies ultimate beneficial owners. It also continuously re-screens entities, directors and ownership structures across more than 100 business registries, flagging significant changes without requiring full re-onboarding.

The screening element covers watchlists, sanctions regimes, politically exposed persons and adverse media. Shufti also links alerts to a verified identity and uses online, transactional and behavioural signals to detect changes in customer risk.

The regulation also raises questions about outsourcing. While Article 18 permits firms to outsource anti-money laundering tasks, responsibility and liability remain with the obliged entity. Companies must therefore oversee providers and sub-providers and be able to demonstrate effective controls.

That point is relevant to vendors competing in the compliance software market, where many providers assemble tools from several third parties. Shufti says its technology is built in-house and offered through a single API, giving clients one provider across the full compliance process.

Advisory push

Alongside the technology platform, the company is offering consultancy support and a managed Money Laundering Reporting Officer service for firms without internal compliance teams. The service covers areas including back-book remediation and ongoing monitoring.

Shufti describes itself as an identity verification and financial crime prevention platform serving more than 2,000 enterprise customers worldwide. Its system verifies users across more than 240 countries and regions and processes more than 10,000 document types in more than 150 languages.

The company framed the new service around the shift from fragmented national compliance structures to a single EU-wide regime. "The AMLR raises the standard of proof, not just the rules. Firms must show a supervisor that their verification is sound, that customer records remain current, and that monitoring is continuous. We built Shufti as one owned platform across the customer lifecycle, so firms can meet that standard with a single, accountable provider, and demonstrate it," said Shahid Hanif, Chief Executive Officer, Shufti.