DocbyteFacebookPixel
Deutsch

AMLR Compliance, Article 77 Record Retention and EUDI Wallet Onboarding

The EU Anti-Money Laundering Regulation creates one directly applicable EU framework for AML record retention. From 10 July 2027, obliged entities will need to demonstrate a five-year retention period, controlled deletion and a record-keeping process that stands up to supervisory review. AMLR also recognises the European Digital Identity Wallet for customer onboarding, which changes the evidence that needs to be retained over time.

Record-keeping becomes a regulated control.

Qualified preservation and evidential archiving from a Qualified Trust Service Provider listed on the EU Trusted List.

Visual showing AMLR Article 77 retention triggers, five-year retention, deletion and case-by-case extension

Why AMLR matters for the archive

AMLR removes much of the national variation that shaped AML record retention under earlier directives. Article 77 sets a single baseline across Member States. For cross-border obliged entities, that means one common retention logic, one deletion discipline and one supervisory benchmark from 10 July 2027.

The effect on archiving is direct. Records must be retained for the right period, retrieved when competent authorities ask for them and deleted when the legal basis ends. That is no longer only a policy question. It has to be supported by the archive design, the retention configuration and the audit trail.

The Article 77 retention rules

Image for AMLR Article 77 retention rules
Icon for AMLR Article 77 retention clock

The five-year clock.

Article 77(3) AMLR sets a uniform five-year retention period commencing on the earliest of:

  • The date the business relationship ends
  • The date an occasional transaction is carried out
  • The date the obliged entity refuses to enter into a business relationship or carry out an occasional transaction
Icon for AMLR pending proceedings retention

The pending proceedings rule.

Where legal proceedings are pending on 10 July 2027 and an obliged entity holds relevant information or documents, those records may be retained for five years from that date. Member States may allow or require a further five-year retention where necessity and proportionality are established.

Icon for AMLR personal data deletion

The deletion obligation.

At the end of five years, personal data must be deleted, without prejudice to retention obligations under other EU legal acts or national law that complies with GDPR. Indefinite AML retention is not permitted.

Icon for AMLR retained records integrity

The integrity rule.

Records retained under Article 77 need to remain authentic, intact and usable across the retention period.

Icon for AMLR retention extension rules

The case-by-case extension.

Competent authorities may require further retention beyond the five-year period, but only on a case-by-case basis and only where necessary for the prevention, detection, investigation or prosecution of money laundering or terrorist financing. The further extension cannot exceed five years. Total maximum retention is therefore ten years.

Icon for AMLR Article 77 derogation

The reference derogation.

Article 77(2) allows obliged entities to retain a reference to documents rather than copies in defined cases, but only if they document in their internal procedures (a) which categories of information are retained as a reference, and (b) the procedures for retrieving the information when requested by competent authorities. The derogation is conditional, documented and auditable.

What records must be retained

Article 77(1) AMLR sets out an exhaustive list of documents and information subject to retention. The list covers:

Icon for AMLR customer due diligence records

Customer due diligence records

Copies of documents and information obtained in the performance of customer due diligence under Chapter III AMLR, including information obtained through electronic identification means.

Icon for AMLR risk assessment records

Risk assessment records

Records of assessments undertaken pursuant to Article 69(2), including assessments that did not result in a suspicious transaction report. Internal AML assessments that never reach the FIU are still subject to retention and supervisory review.

Icon for AMLR transaction records retention

Transaction records

The supporting evidence and records of transactions, consisting of original documents or admissible copies, that are necessary to identify transactions.

Icon for AMLR business relationship records

Business relationship records

Files and correspondence relating to business relationships and to occasional transactions covered by AMLR.

Icon for AMLR information-sharing partnership records

Information-sharing partnership records

Where obliged entities participate in information-sharing partnerships under Chapter VI AMLR, copies of documents and information obtained through those partnerships.

Icon for AMLR suspicious activity records

Suspicious activity records

Reports made to the FIU and the
supporting documentation that
justified them.

The list is exhaustive. Obliged entities should therefore avoid narrowing the scope through local interpretation. The archive needs to support these record classes consistently.

The EUDI Wallet dimension and what it means for preservation

There is a second change behind this. AMLR Article 22 sets explicit expectations for remote customer due diligence and recognises the European Digital Identity Wallet (EUDIW) and Qualified Electronic Attestations of Attributes (QEAAs) as valid identification mechanisms.

Under eIDAS 2.0, the acceptance obligation for relying parties under Article 5 septies(2) becomes operative on 24 December 2027, six months after AMLR applies. From that date, regulated entities, including financial institutions, must accept the EUDI Wallet for identification and authentication in defined use cases.

This changes the nature of the onboarding record. Instead of only storing document copies, organisations may need to preserve signed wallet presentations, attribute attestations, timestamps, assurance context and revocation status as they existed at the time of identification.

Image for AMLR EUDI Wallet evidence preservation

Why this matters for the archive

That evidence package needs to remain valid and verifiable for the full five-year retention period required by Article 77, and potentially up to ten years under case-by-case extensions. Wallet-based onboarding evidence depends on cryptographic artefacts that are themselves subject to certificate expiry, algorithm change and changes in revocation infrastructure. Without active preservation, evidence can lose verifiability before the retention period ends.

For many organisations, storage will not be enough.

The archive should support:

Long-term validation of wallet presentations

The signature on a wallet presentation depends on certificates and trust chains that may expire or be retired. Long-term validation requires that the verification context at the time of onboarding is preserved alongside the presentation itself.

Qualified Electronic Attestation of Attributes preservation

QEAAs issued under eIDAS 2.0 carry their own validity windows. Preserving them with their issuance context allows obliged entities to demonstrate, years later, that the identity was verified at the right assurance level by a qualified issuer.

The QTSP-backed preservation route

Long-term preservation of qualified evidence can itself be delivered as a regulated trust service. Docbyte is listed on the EU Trusted List as a Qualified Trust Service Provider for Qualified Preservation of Qualified Electronic Signatures and Qualified Electronic Seals under eIDAS Articles 34 and 40. Where wallet-based onboarding evidence needs to remain verifiable over time, a QTSP-backed preservation route is worth considering.

For obliged entities, the record-keeping decision is now tied more closely to the onboarding decision. The preservation approach determines whether CDD evidence remains technically verifiable and evidentially useful in 2032 or 2037.

What AMLR expects from the archive

AMLR is not an archiving regulation in the narrow sense, but Article 77 makes record-keeping a control that supervisors can test.

Icon for AMLR Article 77 retention discipline

Retention discipline by record class

Different records start their five-year clock on different events. The archive must apply retention rules per record type and per relationship, not as a single global retention policy.

Icon for AMLR audit-grade deletion controls

Audit-grade deletion

When a retention period expires, deletion must happen reliably and demonstrably. Supervisors will test that personal data is actually deleted, not merely flagged. Audit logs must show what was deleted, when and on whose authority.

Icon for AMLR case-by-case legal hold

Legal hold under case-by-case extensions

When a competent authority extends retention, the archive must support a documented hold that survives normal expiry. The hold must be auditable and reversible when the extension ends.

Icon for AMLR record integrity retention

Integrity across the retention period

Records must remain authentic, intact and retrievable. Format obsolescence, system migrations and certificate decay must not erode evidential value.

Icon for AMLR supervisor record retrieval

Retrievability for supervisors

Records must be presentable to competent authorities on request, in a form that makes it possible to reconstruct the customer’s identity, activity and risk decisions at the time of the original event.

AMLR Reference Derogation Traceability

Reference derogation traceability

Where references are retained instead of copies, the retrieval procedure must work reliably under supervisory pressure, often years after the original event. The archive must support both modes.

Icon for AMLR wallet evidence verifiability

Wallet evidence verifiability

As EUDIW and QEAAs become primary identification means, the archive should preserve cryptographic onboarding evidence in a form that remains verifiable over the full retention period. Long-term validation, evidence records and augmentation become highly relevant.

Icon for AMLR cross-border archive consistency

Cross-border consistency

Cross-border obliged entities will be supervised against a single AMLR standard. The archive must apply the same rules across all jurisdictions in scope.

How Docbyte Vault supports AMLR readiness

Docbyte Vault is a preservation platform aligned with the OAIS reference model and ETSI standards for long-term archiving. Docbyte is listed on the EU Trusted List as a Qualified Trust Service Provider for Qualified Preservation of Qualified Electronic Signatures and Qualified Electronic Seals under eIDAS Articles 34 and 40.

Configurable retention by record class

Vault Admin manages retention policies per record type, with start-date triggers configurable to match Article 77 events such as relationship end, transaction date and refusal date. Multiple retention policies can run in parallel for the same customer.

01

Audit-grade deletion

Records are deleted on schedule with full audit logs. Deletion events are attributable and verifiable.

02

Legal hold with full traceability

Vault supports legal holds that override scheduled deletion. The hold has its own audit trail, including who applied it, on what authority and when it was lifted.

03

Integrity over time

Records are preserved with fixity checks, time-stamps and evidence records aligned with ETSI TS 119 511 and 119 512. Integrity can be maintained as cryptographic algorithms evolve.

04

Authentic preservation

Vault preserves records in their authentic form. Where derived copies are created for other purposes, the original can be preserved alongside them.

05

Reference and copy modes

Vault supports both full-copy preservation and reference-based retrieval. Where the reference derogation in Article 77(2) is used, retrieval procedures can be defined and tested.

06

Long-term validation for wallet evidence

Vault preserves the verification context for EUDI Wallet presentations and QEAAs, and applies evidence records, time-stamps and augmentation in line with ETSI TS 119 511. Evidence renewal workflows for cryptographic change are already operational in production.

07

Qualified preservation backed by QTSP status

For organisations that need a QTSP-backed route for wallet-based onboarding evidence, Docbyte can combine long-term validation and evidence renewal with its Qualified Preservation status.

08

Inspector-ready access

Vault Explorer provides controlled, time-bound access for inspectors and auditors without exposing operational systems. Every access is logged.

09

Cross-border consistency

A single Vault deployment can serve obliged entities across multiple jurisdictions with consistent AMLR-aligned policies.

10

Who this matters to

For banks and financial institutions

AMLR replaces the AMLD national transpositions many financial institutions have built around. Internal record-keeping policies, archive configurations and deletion procedures need to be reviewed against Article 77 well before 10 July 2027. Wallet acceptance follows from 24 December 2027. Vault provides a preservation layer for the controls AMLR formalises and the longer-term evidential preservation that EUDIW introduces.

For insurance carriers

Many insurance products fall within the scope of AMLR through life insurance, investment-linked insurance and certain general insurance use cases. Customer due diligence records, claims-related risk assessments and beneficial ownership data all attract Article 77 retention.

For accountants, auditors and tax advisors

AMLR applies directly across the accountancy profession. Smaller firms that previously relied on national rules for AML record-keeping will face a uniform EU standard.

For real estate, legal and other obliged sectors

Real estate agents, notaries, lawyers handling specific transactions, gambling operators and other non-financial obliged entities are also in scope. AMLR turns AML record-keeping from a national interpretation exercise into a directly applicable standard.

For crypto-asset service providers

AMLR explicitly extends AML obligations to CASPs. Customer due diligence, transaction records and travel-rule data all need to be retained under Article 77.

For data protection officers

Article 77 sets a hard ceiling on AML retention and a mandatory deletion at the five-year point. That intersects directly with GDPR data minimisation.

For digital identity and onboarding teams

EUDI Wallet acceptance becomes mandatory for relying parties from 24 December 2027. Onboarding evidence will shift from document copies towards cryptographic presentations, attribute attestations and verification contexts. The archive that stores this evidence needs to keep it verifiable for the full Article 77 retention period. Vault combines long-term validation, evidence records, augmentation and a QTSP-backed preservation route for organisations that need stronger evidential assurance over time.

Related customer proof

EDR Credit Services: Intelligent document processing for financial workflows

EDR Credit Services uses Docbyte to automate document classification, extraction and anonymisation for high-volume financial workflows. The case shows how regulated financial document processes can be made auditable and efficient at the same time.

FEDERALE Insurance: Self-learning classification at scale

FEDERALE Insurance uses Docbyte for centralised, classified document handling across departments. The case demonstrates how compliance and customer service can be served by the same infrastructure.

Frequently asked questions

AMLR entered into force on 9 July 2024 and applies from 10 July 2027. From that date, Article 77 record-retention rules apply uniformly across the EU and replace national transpositions of previous AML directives. Preparation should start well before that date, especially for cross-border obliged entities that need to align records held under different national rules.

AMLR Article 22 recognises the European Digital Identity Wallet and Qualified Electronic Attestations of Attributes as valid means of customer due diligence in remote onboarding. Under eIDAS 2.0 Article 5 septies(2), regulated entities, including financial institutions, must accept the EUDI Wallet for identification in defined scenarios from 24 December 2027.

For the archive, this means CDD records will increasingly include cryptographic wallet evidence rather than only document copies. That points to long-term validation, evidence records, augmentation and, in some cases, a QTSP-backed qualified preservation route for stronger long-term evidential assurance.

AMLR maintains and extends the obliged entities list from previous AML directives. It includes credit institutions, financial institutions, insurance companies for certain products, investment firms, payment service providers, crypto-asset service providers, gambling operators, accountants, auditors, tax advisors, notaries, lawyers in specific transactions, real estate agents, traders in high-value goods above defined thresholds, and others. Article 3 AMLR sets out the full list.

Article 77(3) sets a uniform five-year retention. The five-year clock starts on the earliest of: termination of the business relationship, the date of an occasional transaction, or the date the obliged entity refuses to enter a relationship or carry out a transaction. At the end of five years, personal data must be deleted unless another Union or national law specifies otherwise. Competent authorities may require further retention case-by-case, up to a total maximum of ten years.

Article 77(2) allows certain documents and information to be retained as references rather than copies, provided the obliged entity has documented in its internal procedures (a) the categories of information for which references are kept, and (b) the procedures to retrieve the information for competent authorities upon request. The reference derogation does not relieve the obligation to produce the actual records when requested.

AMLR retention is purpose-bound to AML/CFT and capped at five years, extendable case-by-case to ten years. GDPR requires data minimisation and storage limitation. Article 77 deletion at the five-year point operationalises storage limitation in the AML context. Where retention beyond five years is required by other Union or national law, that secondary basis must itself comply with GDPR.

Prepare your archive for 10 July 2027

Article 77 AMLR applies from 10 July 2027. EUDI Wallet acceptance follows on 24 December 2027. If your current archive was designed mainly for storage and retrieval, this is the moment to test whether it also supports deletion discipline, supervisory retrieval and long-term verifiability of onboarding evidence.