# Corporate KYC: Verifying a Company Client, Its Owners and Its Money

> How banks and licensed firms verify a corporate client: ownership chain and UBO thresholds, documents, risk rating, review intervals and refusal.

Author: Alena Dunaeva — Lawyer, Family Office (https://wiki.private.law/en/authors/dunaeva)
Last modified: 2026-09-28T00:00:00.000Z
Canonical: https://wiki.private.law/en/corporate-kyc
Publisher: wiki.private.law (https://wiki.private.law)
Version: 9d683e1f39a880460b6bdb4bef917e7d3d4400cefad4e9ad0fae2e24a7cf9ab2
Cite as: Corporate KYC: Verifying a Company Client, Its Owners and Its Money. wiki.private.law. https://wiki.private.law/en/corporate-kyc. Version 9d683e1f39a880460b6bdb4bef917e7d3d4400cefad4e9ad0fae2e24a7cf9ab2.
Topics: banking
Jurisdictions: global, eu, uk, usa, singapore, hong-kong, uae, switzerland
Product tags: compliance, banking, bank, company, corp-docs
Semantic tags: compliance, banking, bank, company, corp-docs

---

Corporate KYC is the procedure by which a bank, a licensed payment or crypto firm, a broker, a fund administrator or a trust and company service provider satisfies itself that it knows who a corporate customer is, who ultimately stands behind it, and where the money it will move comes from. The customer here is a legal fiction: a company cannot be looked in the eye, cannot show a passport and does not have a single mind of its own. Everything the institution learns about it is learned from documents it was given, registers it can consult and natural persons it can eventually name. That is the whole difficulty of the discipline, and the reason it has its own body of rules.

Three features set it apart. The first is that the verification never stops at the customer. Identity verification does not close an individual or corporate CDD file: purpose, risk and ongoing monitoring remain relevant. Corporate CDD additionally traces ownership and control to natural persons or records the applicable fallback. The second is that the entity question splits in two: ownership and control require distinct analysis. The applicable legal framework determines how those tests interact; control can exist without ownership. The third is that the money question also splits in two — where the funds in this particular relationship came from, and how the capital behind the customer was accumulated in the first place. A company can document the former convincingly and still fail on the latter.

What the procedure produces is an account of the customer that the institution is prepared to defend to a supervisor: a description of the ownership and control structure, named beneficial owners with verified identities, a stated purpose for the relationship, an expected pattern of transactions against which real ones will be monitored, and a risk rating that determines how deep everything else goes. Onboarding fails far more often because that account does not hang together than because a document is missing. A corporate structure whose beneficial owner appears only when fractions are multiplied, a jurisdiction of incorporation with no visible connection to the business, capital supported by bank statements and nothing else — each of these is a gap in the narrative, and each is treated as such.

The technical rules that follow — thresholds, document lists, review intervals, refusal duties — matter because they are the points at which the institution's judgement becomes checkable. A supervisor cannot audit whether a compliance officer found a client persuasive. It can audit whether the applicable ownership and control tests were performed across every chain, whether the register excerpt was current, whether the file was refreshed within the interval the law allows, and whether a refusal was recorded with its reasons. That is where examinations and enforcement actually land.

## Where the duty comes from

The international baseline is [FATF](https://wiki.private.law/en/fatf) Recommendation 10, which requires financial institutions to identify the customer and verify identity from reliable, independent sources, and then to identify the beneficial owner "and taking reasonable measures to verify the identity of the beneficial owner, such that the financial institution is satisfied that it knows who the beneficial owner is", adding that for legal persons and arrangements this "should include financial institutions understanding the ownership and control structure of the customer". The same Recommendation requires an understanding of the purpose and intended nature of the relationship and ongoing due diligence throughout it. Recommendation 22 carries those duties across to designated non-financial businesses and professions, and it is the reason a company formation agent, a notary handling a share transfer, an accountant managing client money or a trust and company service provider acting as nominee shareholder runs a corporate file of its own rather than relying on whatever a bank did later. The [FATF Recommendations](https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html) are not directly binding on any firm; they bind through national law and through the mutual evaluations that grade how well a country implemented them.

For legal persons, FATF's [Interpretive Note to Recommendation 10, paragraph 5(b)(i)](https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/fatf-recommendations-2012.pdf), uses a cascade: controlling ownership; other control where ownership does not resolve beneficial ownership; then the relevant senior managing official as a CDD fallback, not a finding that the official is the actual beneficial owner. Footnote 39 makes these sequential measures, and footnote 40 gives 25 % only as an example. This is not the AMLR's independently applied ownership-and-control test.

As at 26 September 2026, the European Union has adopted [Regulation (EU) 2024/1624](https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng), the AMLR, whose general application starts on 10 July 2027 — from 10 July 2029 for football agents and professional football clubs. Until then the operative framework remains national law implementing [Directive (EU) 2015/849](https://eur-lex.europa.eu/eli/dir/2015/849/oj/eng) as amended, in the form each member state transposed it, which is why the same group answers materially different questionnaires in two EU countries today. [Directive (EU) 2024/1640](https://eur-lex.europa.eu/eli/dir/2024/1640/oj/eng) carries the institutional half of the package — registers, supervision, financial intelligence units — and must be transposed by 10 July 2027, with the register provisions of Articles 11 to 13 and 15 due a year earlier and Article 18 not until 10 July 2029. What that shift does to corporate onboarding specifically is set out in the [EU AML package](https://wiki.private.law/en/eu-aml-package).

Unless another instrument is named, the numbered articles below refer to AMLR and describe its framework from 10 July 2027. They must not be read as already applicable EU-wide thresholds or deadlines; current requirements must be checked under the relevant national law.

Two further layers carry no legislative force and still govern practice. The Basel Committee's guidelines on [sound management of ML/FT risks](https://www.bis.org/bcbs/publ/d505.htm) (January 2014, last revised July 2020) require a bank to operate a customer acceptance policy that identifies the types of customer likely to pose a higher risk (paragraph 32), to apply due diligence "not only to customers but also to persons acting on their behalf and beneficial owners" (paragraph 35), to base the extent of ongoing monitoring on risk, and to set specific policies on the frequency of monitoring and of CDD updates for customers it has identified as higher risk (paragraphs 45 and 48). The [Wolfsberg Group](https://wolfsberg-group.org/news/cbddq-publication/) supplies the market's standard form: the Correspondent Banking Due Diligence Questionnaire for bank-to-bank relationships, and the shorter Financial Crime Compliance Questionnaire, which the Group issued because its original questionnaire "has been used in multiple other customer type due diligence scenarios", while expressly declining to prescribe for which customer types either form should be used. Both open with the entity and its ownership before turning to the AML, sanctions and anti-bribery programme, and a bank's own corporate pack is usually built from the same blocks; the questions and what a bank reads into the answers are set out in [Wolfsberg questionnaires](https://wiki.private.law/en/wolfsberg-questionnaires).

## What is collected on the entity itself

From 10 July 2027, AMLR Article 22(1)(b) will fix the minimum identification set for a legal entity: legal form and name; the address of the registered or official office and, if different, the principal place of business, together with the country of creation; the names of the legal representatives and, where available, the registration number, the tax identification number and the Legal Entity Identifier; and the names of any persons holding shares or a directorship in nominee form, with their status as nominees stated. A trustee of an express trust supplies instead basic information on the arrangement, the trustees' address of residence, the place from which the arrangement is administered and the powers that bind it — and, importantly, only the assets to be managed in the context of this relationship need be identified, not the whole trust fund.

Verification of the entity's own existence and standing runs on registers. From 10 July 2027, AMLR Article 23(4) will require an obliged entity, whenever it enters a new relationship with a legal entity or a trustee subject to beneficial-ownership registration, to collect valid proof of registration or a recently issued excerpt of the register confirming that the registration is valid. For the natural persons in the file — representatives, authorised signatories, beneficial owners — Article 22(6) allows either an identity document or passport plus information from reliable independent sources, or electronic identification meeting the eIDAS assurance levels "substantial" or "high". Beneficial owners may additionally be verified from reliable sources including public registers other than the central registers, and Article 22(7) then requires the institution to verify beneficial-ownership information by consulting the central registers as well. Where those registers stand today, and what "legitimate interest" access has done to them, is covered in [UBO registers](https://wiki.private.law/en/ubo-registers).

Current verification timing follows the applicable national implementation of Directive 2015/849. In the AMLR framework from 10 July 2027, verification normally precedes the relationship (Article 23(1)); an account may be opened earlier only with safeguards preventing transactions until the required verification is complete (Article 23(3)). Article 33(1)(a) will permit a risk-justified deferral in lower-risk cases, subject to its 60-day ceiling.

## Ownership and control: where 25 % is the line, and where it is not

From 10 July 2027, under AMLR Article 51 the beneficial owners of a legal entity are the natural persons who have, directly or indirectly, an ownership interest in it, or who control it, directly or indirectly, through ownership interest or via other means. Article 52(1) puts a number on the first limb: an ownership interest means direct or indirect ownership of 25 % or more of the shares or voting rights or other ownership interest, including rights to a share of profits, other internal resources or the liquidation balance. Indirect ownership is calculated by multiplying the holdings through each chain of intermediate entities and adding the results of the different chains together, and every shareholding at every level must be taken into account. The current Directive (EU) 2015/849 Article 3(6) formulation is different — "a shareholding of 25 % plus one share or an ownership interest of more than 25 %" is an *indication* of ownership, with member states free to set a lower percentage — and the change from an indication to a defined threshold is a change that the AMLR will introduce.

> ⚠️ **25 % is not a safe harbour.** Under the AMLR framework from 10 July 2027, Article 51 states that control via other means "shall be identified independently of and in parallel to the existence of an ownership interest or control through ownership interest". A person holding nothing can be a beneficial owner through veto rights, the power to appoint or remove a majority of the board, control over profit distribution, a shareholders' agreement, a family relationship or a nominee arrangement (Article 53(3) and (4)). A structure engineered so that every holder sits at 24.9 % has not removed its beneficial owners; it has moved the question from arithmetic to evidence, which is a harder question to answer well.

The AMLR framework also provides for lower thresholds. Article 52(2) directs the Commission, by 10 July 2029, to assess categories of corporate entities exposed to higher ML/TF risk and, where a lower threshold is appropriate, to set one by delegated act — at a maximum of 15 %, or otherwise at some figure below 25 %. In that framework from 10 July 2027, "control through ownership interest" is defined at 50 % plus one of the shares or voting rights (Article 53(2)(c)), and the sanctions limb of the check runs on its own arithmetic: Article 20(1)(d) requires the institution to verify whether persons subject to targeted financial sanctions control the entity or hold more than 50 % of its proprietary rights or a majority interest, individually or collectively. How that test is operated in practice is the subject of [sanctions screening](https://wiki.private.law/en/sanctions-screening).

> ⚙️ **Non-linear structures under AMLR from 10 July 2027.** Where ownership interest and control coexist at different layers of the same chain, Article 54 shifts the answer: the beneficial owners become the natural persons who control the entities holding a direct ownership interest in the customer, and the natural persons with an ownership interest in the entity that controls the customer. Where a trust, a foundation or a similar arrangement sits in the chain, Article 55 looks through it and the beneficial owners of the customer are the beneficial owners of that arrangement — for a foundation, under Article 57, the founders, the members of the management body in its management and supervisory functions, and the beneficiaries. This is why a two-page shareholder certificate is rarely the end of the exercise.

Under AMLR from 10 July 2027, where no natural person can be identified after all possible means are exhausted, or where there is doubt about those identified, Article 22(2) requires the institution to record that no beneficial owner was identified and to identify and verify all natural persons holding senior managing official positions instead — and to abstain from that verification where it would tip the customer off, recording the steps taken instead. The fallback therefore comes with its own paper trail, and a supervisor reads that trail before it reads the name. Nominee arrangements are addressed head-on: nominee shareholders and directors must be named as such under Article 22(1)(b)(iv), and formal or informal nominee arrangements count as control via other means. The practical consequences of that for holding structures are set out in [beneficial ownership and nominee structures](https://wiki.private.law/en/beneficial-ownership-nominee).

## Source of funds against source of wealth

The two questions are routinely conflated and are not the same. Source of funds asks where the money entering this relationship came from — which account, from which counterparty, on what contract. Source of wealth asks how the capital behind the customer and its beneficial owners was accumulated over time: a business sold, dividends from an operating group, an inheritance, a property disposal, salary and bonus over a career. In the framework applying from 10 July 2027, AMLR Article 34(4)(c) lists additional information "on the source of funds, and source of wealth of the customer and of the beneficial owners" among the enhanced measures, and Article 34(2) requires the origin and destination of funds and the purpose of a transaction to be examined whenever the transaction is complex, unusually large, conducted in an unusual pattern or without apparent economic or lawful purpose. Article 26(1) folds the same question into ongoing monitoring, which must be consistent with what the institution knows about the origin and destination of funds. What documents actually carry each of the two, and how they are assembled for a corporate group, is the subject of [source of funds and source of wealth](https://wiki.private.law/en/source-of-funds).

> 🍓 **A corporate file is judged as an account, not as a checklist.** The documents exist to support one claim — that the institution knows who stands behind this company and why the money moves the way it does. Where the ownership chain, the jurisdiction of incorporation, the stated business and the expected flows explain each other, a thin pack is usually enough. Where they do not, no volume of certificates repairs it, and the file is refused or escalated on exactly that ground.

## Depth of check by client type

The table illustrates the AMLR framework from 10 July 2027. Under Articles 20(2) and 34, each customer's risk must be assessed individually: a potential higher-risk factor is not an automatic EDD decision. Specific mandatory cases remain separate. The stated update ceilings depend on the resulting classification; before that date, national rules and the institution's risk-based policy govern.

| Client type | Depth of check | Entity documents | People and ownership | Money | AMLR update ceiling from 10 July 2027 |
| --- | --- | --- | --- | --- | --- |
| Domestic operating company, simple ownership, low-risk sector | Standard; simplified measures possible | Register excerpt, constitutional documents | Beneficial owners, directors and signatories; simplification does not remove the ownership inquiry | Purpose and expected flows | Up to 5 years |
| Cross-border trading company | Standard, with structure and geography examined | Register excerpt per layer, LEI or TIN where available | Full chain to natural persons, both limbs of Art. 51 | Source of funds; counterparties and corridors | Up to 5 years; sooner on triggers |
| Holding company or personal asset-holding vehicle | Risk-based; personal asset holding is a potential higher-risk factor, not an automatic EDD trigger | As above plus evidence of activity or its absence | Chain, control via other means, nominees named | Source of funds; source of wealth where required by the assessed risk or a specific rule | 1 year for higher-risk customers subject to EDD; otherwise 5 years, with earlier trigger reviews |
| Trust, foundation or similar arrangement in the chain | Look-through under Arts. 55 and 57; EDD where higher risk or a specific requirement is established | Deed or statutes, trustee identification, administration place | Relevant parties by structure: settlor, trustees, protector, beneficiaries and controllers for trusts; foundation roles under Art. 57 | Funding history of the arrangement | 1 year for higher-risk customers subject to EDD; otherwise 5 years, with earlier trigger reviews |
| PEP link, sanctions nexus or high-risk third country | Apply the relevant PEP or high-risk-country measures; assess sanctions prohibitions separately | As above, with register currency checked | PEP status of customer, beneficial owners and associates | Source of funds and wealth documented, not declared | 1 year for higher-risk customers subject to EDD; otherwise 5 years, with earlier trigger reviews |
| Crypto business, cash-intensive or complex-structure sector | Risk-based; check licensing and governance; EDD where higher risk or a specific requirement is established | Licence or registration, group structure | Chain plus the customer's own customers where relevant | Flow of funds and counterparty exposure | 1 year for higher-risk customers subject to EDD; otherwise 5 years, with earlier trigger reviews |
| Regulated financial institution as customer | Specific EDD for in-scope third-country correspondent relationships; otherwise risk-based | Licence, group data, CBDDQ or FCCQ | Ownership, governance, compliance programme | Products, volumes, downstream clearing | 1 year for higher-risk customers subject to EDD; otherwise 5 years, with earlier trigger reviews |

From 10 July 2027, AMLR Article 26(2) will cap intervals at one year for higher-risk customers subject to enhanced measures and five years for other customers. These are outer limits; risk or new information can require an earlier update. They are not a universal EU schedule already applicable in September 2026.

## Risk rating and what triggers enhanced due diligence

For the AMLR framework from 10 July 2027, Annex III lists factors of potentially higher risk, to be assessed under Articles 20 and 34; their presence alone does not automatically determine the rating or require the same enhanced measures. Among them: legal persons or arrangements that are personal asset-holding vehicles; corporate entities with nominee shareholders or bearer shares; cash-intensive businesses; an ownership structure that "appears unusual or excessively complex given the nature of the company's business"; and a customer that is a legal entity created in a jurisdiction where it has no real economic activity, substantial economic presence or apparent economic rationale — together with any customer owned, directly or indirectly, by such an entity. On the product side, private banking, products favouring anonymity, payments received from unknown or unassociated third parties and transactions in oil, arms, precious metals and stones, tobacco and cultural artefacts are relevant to the assessment. Geographically, the list runs to third countries under increased FATF monitoring, countries identified as lacking effective AML/CFT systems or as having significant corruption, and countries subject to Union or UN sanctions, embargoes or similar measures.

Specific mandatory cases must be separated from general risk indicators. The following AMLR provisions apply from 10 July 2027; the EBA guidance mentioned below has its own application date. Where a beneficial owner or a controlling person is a politically exposed person, senior management approval, source-of-wealth documentation and enhanced monitoring become mandatory rather than discretionary; the definitions, the family-and-associates perimeter and the practice of removing the status are set out in [politically exposed persons](https://wiki.private.law/en/pep). AMLR Articles 29 to 31 contain different country mechanisms: Article 29 requires the Article 34(4) measures for the specified relationships and transactions, while Articles 30 and 31 can require the particular measures selected in the relevant delegated act.

In the current framework, the country trigger is the EU list of high-risk third countries in Delegated Regulation (EU) 2016/1675. [Commission Delegated Regulation (EU) 2026/46](https://eur-lex.europa.eu/eli/reg_del/2026/46/oj/eng) of 3 December 2025, in force since 29 January 2026, added to that list a new category for countries whose FATF membership has been suspended, with the Russian Federation as its only entry. For relationships and transactions involving a listed country, [Article 18a of Directive (EU) 2015/849](https://eur-lex.europa.eu/eli/dir/2018/843/oj/eng) makes enhanced measures mandatory: additional information on the customer, the beneficial owners and the intended nature of the relationship, the source of funds and source of wealth, the reasons for the transactions, senior management approval and enhanced monitoring. From 10 July 2027 that role passes to AMLR Article 29. Sanctions prohibitions run on a separate track, and no AML risk assessment displaces them.

Where the customer provides crypto-asset services without being authorised under MiCA, the [EBA guidelines amending EBA/GL/2021/02](https://www.eba.europa.eu/sites/default/files/2024-01/a3e89f4f-fbf3-4bd6-9e07-35f3243555b3/Final%20Amending%20%20Guidelines%20on%20MLTF%20Risk%20Factors.pdf) of 16 January 2024, [applicable from 30 December 2024](https://www.eba.europa.eu/publications-and-media/press-releases/eba-issues-guidance-crypto-asset-service-providers), expect a bank to assess the risk before the relationship starts and, at a minimum, to run due diligence on senior management as well as on the beneficial owners, to establish whether the customer is licensed and whether its services fall within that licence, and to understand how far it applies due diligence to its own clients (Guidelines 9.20 and 9.21). A crypto-asset service provider that is itself the obliged entity is expected, for its own higher-risk customers, to verify identity "on the basis of more than one reliable and independent source" (Guideline 21.12). The transfer-data side of the same business is covered by the [travel rule](https://wiki.private.law/en/travel-rule).

A separate AMLR rule from 10 July 2027 combines a higher-risk relationship with asset thresholds; wealth alone does not activate it. Article 34(5) attaches additional measures where a higher-risk relationship involves handling assets of at least EUR 5 000 000 through personalised services for a customer whose total assets, excluding a private residence, are at least EUR 50 000 000: specific procedures for the risks of personalised service, additional source-of-funds information, and management of conflicts of interest between the customer and the staff responsible for compliance on that customer.

## Periodic review and what resets the clock

Ongoing monitoring is a duty in its own right. In the AMLR framework from 10 July 2027, Article 26(1) will require transactions to be tested against what the institution knows of the customer, its business activity and its risk profile; where a relationship spans several products, the due diligence must cover all of them; and where other entities in the same group serve the same customer, information from those relationships must be taken into account. Beyond the one-year and five-year caps, Article 26(3) requires a review whenever there is a change in the customer's relevant circumstances, whenever the institution has a legal obligation during the calendar year to contact the customer to review beneficial-ownership information or to comply with Directive 2011/16/EU on administrative cooperation in taxation, and whenever it becomes aware of a relevant fact about the customer. The tax-cooperation limb is what synchronises the AML file with the tax-status file; the forms and classifications on that side are covered in [FATCA and CRS self-certification](https://wiki.private.law/en/fatca-crs-self-certification).

Sanctions screening runs on a separate clock. From 10 July 2027, AMLR Article 26(4) will require regular verification against the Article 20(1)(d) test at a frequency commensurate with exposure, and for credit and financial institutions it must also be repeated upon any new designation. Article 27 adds a record-keeping duty for the window between a UN financial sanction being made public and the corresponding Union measure taking effect.

A discrepancy between what the customer says and what the register holds travels beyond the two of them. From 10 July 2027, the AMLR will oblige the institution to report discrepancies with beneficial-ownership registers, and the practical sequence — what is logged, within what period, how the customer is invited to correct the entry, how a decision not to report a minor mismatch is recorded — belongs to the register regime rather than to the onboarding file.

## Refusal, exit and de-risking

> ⚠️ **AMLR refusal duties from 10 July 2027.** Where an obliged entity cannot complete the measures in Article 20(1), Article 21(1) requires it to refrain from carrying out the transaction or establishing the relationship, to terminate an existing relationship, and to consider reporting a suspicious transaction to the financial intelligence unit. Termination does not require the disposal of the customer's assets where the institution has a duty to protect them, and for life insurance the alternative is to withhold performance until the measures are complete. Article 21(3) then requires the decision, the supporting documents and the justification to be recorded — and the record-keeping duty applies expressly to refusals, terminations and alternative measures.

Wholesale exit from categories of customer is the opposite failure, and the package treats it as one. Article 21(4) directs AMLA and the European Banking Authority to issue joint guidelines by 10 July 2027 on the measures institutions may take to comply with AML/CFT rules when implementing Directive 2014/92/EU on access to payment accounts, "including in relation to business relationships that are most affected by de-risking practices". In other words, a firm that closes an entire class of corporate accounts to avoid the analysis is answerable for that too. What a closure looks like from the customer's side, and what can be done about it, is set out in [bank account closure](https://wiki.private.law/en/bank-account-closure).

## Why corporate applications are refused

The recurring reasons are narrower than applicants expect, and almost all of them are failures of the account rather than of paperwork.

- The ownership chain does not resolve. Layers exist whose purpose nobody explains, or the AMLR multiplication rule applying from 10 July 2027 under Article 52(1) would identify a beneficial owner the customer denies having.
- The jurisdiction of incorporation has no relationship to the business, a potential higher-risk factor reflected in the AMLR's Annex III point (1)(h) for its framework from 10 July 2027 — an entity created where it has no real economic activity or apparent economic rationale.
- Control is not disclosed. A shareholders' agreement, a veto right or a nominee arrangement emerges from a document the institution obtained itself rather than from the customer's answers, and the file loses credibility on everything else.
- Where source-of-wealth evidence is required, it is asserted rather than evidenced. Bank statements show that money exists; they do not show how it was accumulated.
- The expected flows and the stated business diverge. A consultancy projecting high-volume third-party settlement is describing a different business from the one on its application.
- A sanctions nexus above the 50 % or control test appears in the chain, or a designated person is found at a layer the applicant did not map.
- The register excerpt is stale, the entity is not in good standing, or beneficial-ownership data was never filed where filing is compulsory.
Refusals of the last kind are repairable in weeks. The first three usually are not, because what they require is a change to the structure rather than a change to the file. Where the structure is being designed rather than defended, the operator-side machinery that will be examining it — the roles, policies, systems and audit trail behind every one of these decisions — is described in the [compliance stack](https://wiki.private.law/en/compliance-stack), and the individual-client counterpart of this page is [AML/KYC for private clients](https://wiki.private.law/en/aml-kyc-private-client).

## Q/A

### Is corporate KYC just individual KYC applied to more people?

No. It adds two tests that have no individual analogue: reconstructing the ownership and control structure until natural persons are reached, and verifying the entity's own legal existence and standing from a register. The individual checks inside a corporate file are the endpoints of those tests, not their substance.

### If every shareholder holds less than 25 %, does the company have no beneficial owner?

That fact alone does not answer the question. Under the AMLR framework from 10 July 2027, the 25 % figure in AMLR Article 52(1) covers only ownership interest; control via other means is identified independently and in parallel under Article 51. Where neither limb produces a natural person after all possible means are exhausted, Article 22(2) requires the institution to record that fact and to identify and verify the senior managing officials instead.

### How is indirect ownership calculated through several companies?

Under AMLR from 10 July 2027, by multiplying the shares or voting rights held by the intermediate entities along each chain, then adding together the results from the various chains. All shareholdings at every level are taken into account. Where ownership interest and control coexist at different layers of one chain, Article 54 replaces the multiplication with its own rule. Before then, the applicable national ownership and control rules must be checked.

### How often will the file have to be refreshed?

From 10 July 2027, AMLR Article 26(2) will require no more than one year between updates for higher-risk customers subject to enhanced measures, and no more than five years for other customers. These are outer limits, not fixed schedules: relevant changes, required contact about beneficial ownership or tax cooperation, and new relevant information trigger an earlier review. Until then, check the applicable national requirements.

### Can an account be opened before the checks are finished?

The current answer depends on the applicable national implementation of Directive 2015/849. Under AMLR from 10 July 2027, verification must normally precede the relationship. A credit or financial institution may open an account earlier under Article 23(3) only where safeguards prevent any transaction until customer and beneficial-owner identification are complete. In genuinely low-risk cases simplified due diligence may postpone verification, but never beyond 60 days.

### What does the institution have to do when it cannot complete the checks?

Under AMLR from 10 July 2027: refrain from the transaction, decline or terminate the relationship, consider a suspicious transaction report, and record the decision with its supporting documents and justification. Article 21 frames all of that as an obligation, and the record-keeping requirement reaches the refusal itself. Current refusal and reporting duties remain governed by applicable national law.

### Does a company get the Wolfsberg questionnaire?

The CBDDQ is built for correspondent banking. The Wolfsberg Group issued the shorter Financial Crime Compliance Questionnaire because its original form was being used for many other customer types, but it deliberately leaves the choice of form to the bank. A regulated financial institution as customer may well receive the FCCQ; an ordinary trading or holding company usually meets the bank's own corporate pack. The ground covered overlaps: entity and ownership first, then the AML, sanctions and anti-bribery programme, products and geography.

---

## Factual claims

- As at 26 September 2026, the European Union has adopted Regulation (EU) 2024/1624, the AMLR, whose general application starts on 10 July 2027 — from 10 July 2029 for football agents and professional football clubs.
- The table illustrates the AMLR framework from 10 July 2027. Under Articles 20(2) and 34, each customer's risk must be assessed individually: a potential higher-risk factor is not an automatic EDD decision.
- From 10 July 2027, AMLR Article 26(2) will cap intervals at one year for higher-risk customers subject to enhanced measures and five years for other customers.
- For the AMLR framework from 10 July 2027, Annex III lists factors of potentially higher risk, to be assessed under Articles 20 and 34; their presence alone does not automatically determine the rating or require the same enhanced measures.
- A separate AMLR rule from 10 July 2027 combines a higher-risk relationship with asset thresholds; wealth alone does not activate it.

---

Source: wiki.private.law — the private.law legal knowledge base. When quoting, cite the canonical page URL.
Consultation with a lawyer: https://t.me/private_law_bot
