Five jurisdictions moved in the last twelve months, and two of them moved in opposite directions. A recurring brief on the rule changes that reach the onboarding stack.

Instruments that are in force or have a fixed application date. Proposed measures are excluded from this timeline and flagged separately in the article.
This is a recurring brief. The rule is simple: we name the instrument, the jurisdiction, the date it applies from and the practical consequence for the systems that actually run onboarding. Anything still in consultation is labelled as such, because building to a proposal is how compliance budgets get wasted.
The last twelve months produced an unusual pattern. Two jurisdictions loosened obligations and two tightened them, and in one case the loosening and the tightening happened inside the same regime.
United States: the beneficial ownership registry effectively withdrew
A FinCEN interim final rule published on 26 March 2025 redefined a reporting company under the Corporate Transparency Act to mean only entities formed under foreign law and registered to do business in a US state or tribal jurisdiction. US-formed entities and US persons are exempt, and foreign reporting companies do not report US-person beneficial owners. In May 2026 the Government Accountability Office assessed that the change eliminates more than 99 per cent of entities that previously were required to report.
As of late June 2026 a final rule had been received by the Office of Information and Regulatory Affairs and had not been published, with three federal appellate proceedings held in abeyance pending it. The interim rule therefore remains the operative position.
Systems implication. A federal registry lookup is no longer a viable verification route for US entities. Ownership data has to be gathered under the customer due diligence rule and from state registers. New York's LLC Transparency Act, which took effect on 1 January 2026 and applies to foreign LLCs, is an early example of the state-level patchwork that replaces it.
United States: taxpayer identification numbers may now come from a third party
An order by the OCC, FDIC and NCUA with FinCEN's concurrence, dated 27 June 2025, and a concurring Federal Reserve order of 31 July 2025, permit a bank to obtain a customer's taxpayer identification number from a third-party source such as a credit bureau or a vetted data provider, rather than directly from the customer, provided the bank otherwise complies with the customer identification programme rule.
Systems implication. This is permissive, not mandatory, and it is the first substantive change to CIP data sourcing since 2003. It enables an onboarding flow that never asks for a social security number. It also moves the control burden onto third-party data quality, vendor due diligence and the audit evidence a firm keeps about source reliability.
European Union: one date matters, and it is 10 July 2027
The EU AML package is in force but not yet applicable. Regulation (EU) 2024/1624, the single rulebook, applies directly from 10 July 2027 with no transposition. Directive (EU) 2024/1640 carries the same transposition deadline. The new Anti-Money Laundering Authority, established by Regulation (EU) 2024/1620 and seated in Frankfurt, has been operational since 2025 and will take up direct supervision of a selected group of entities from 1 January 2028, with the first selection window running from July to December 2027.
The content that arrives on that date is specific: an EU-wide cap of EUR 10,000 on cash payments for goods and services, identification required for cash payments of EUR 3,000 or more, full customer due diligence by crypto-asset service providers on occasional transactions at or above EUR 1,000, and an obliged-entity scope extended to crypto firms, crowdfunding platforms, football clubs and agents, investment-migration operators and high-value goods dealers.
Systems implication. Because the single rulebook is a Regulation rather than a Directive, the member-state variation logic that most customer due diligence engines carry has to be replaced with one harmonised ruleset, with the cash and crypto thresholds hard-coded. The date is fixed and the migration is not small.
United Kingdom: verification became mandatory, and enhanced due diligence narrowed
Identity verification at Companies House under the Economic Crime and Corporate Transparency Act became mandatory on 18 November 2025 for anyone incorporating a company or being appointed a director. Existing directors confirm verification with their next annual confirmation statement within a twelve-month transition, and persons with significant control verify within a fourteen-day window whose start date depends on whether they are also a director. Verification runs through GOV.UK One Login or an authorised corporate service provider, and produces a personal code. Companies House estimates six to seven million individuals must verify by mid-November 2026.
Separately, the Money Laundering and Terrorist Financing (Amendment) Regulations 2026 came into force for most purposes on 30 June 2026. Mandatory enhanced due diligence was narrowed to jurisdictions subject to a Financial Action Task Force call to action, currently Iran, North Korea and Myanmar. The enhanced due diligence trigger for complex transactions was narrowed to unusually complex ones. A new risk assessment and mitigation duty applies to pooled client accounts, and euro-denominated thresholds were restated in sterling. Enhanced due diligence for specified crypto-asset activities is delayed to 1 February 2027, and the crypto-asset change-in-control regime to 25 October 2027.
Systems implication. Two jobs, in opposite directions. Entity onboarding gains a new, checkable artefact in the Companies House personal code and verification date, which is usable as a risk signal. Screening engines need their high-risk country lists and complex-transaction rules re-scoped, and the effect there is to reduce alert volume rather than add to it, which is rare enough to be worth planning for deliberately.
India: the CKYCR record became the authority
The Reserve Bank of India replaced the 2016 KYC Master Direction with ten sector-specific Directions on 28 November 2025, as part of a wider consolidation exercise. Amendment Directions dated 29 December 2025 added an explanation to paragraph 65: the regulated entity that last uploads or updates a KYC record in the Central KYC Records Registry is responsible for verifying identity and address, and entities downloading a current, compliant record need not re-verify.
Earlier, three circulars dated 12 June 2025 amended periodic updation. Low-risk customers have until one year from the KYC due date or 30 June 2026, whichever is later, and at least three advance intimations must be sent before the due date, at least one of them by letter.
Systems implication. A genuine reduction in duplicate work, purchased with a liability. Suppressing re-verification on a fresh CKYCR download only works if the upload was accurate, which makes upload quality a control rather than an administrative step. Periodic updation engines now need the three-intimation trail, including a physical letter, held as auditable evidence.
Proposed, not law
Two items are worth watching and neither should be built to yet. FinCEN issued a notice of proposed rulemaking on anti-money laundering and countering the financing of terrorism programmes, published on 10 April 2026 with comments closed on 9 June 2026, signalling a move toward effectiveness-based rather than checklist programmes. Separately, FinCEN delayed the investment adviser AML rule by two years, to 1 January 2028.
On the India and DPDP question. We have not published a claim about how KYC record retention interacts with the Digital Personal Data Protection Act, because we could not find a dated instrument from the RBI or MeitY that reconciles the two. The tension is real: retention duties under the Prevention of Money Laundering Act sit against DPDP purpose limitation and erasure rights. We would rather name the open question than fill it. If you have a citation, write to us.
This is reporting on regulation as it stood at the date of publication. It is not legal or compliance advice, and obligations differ by jurisdiction and change. Take qualified advice on your own circumstances.
References
Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.
FinCEN, Beneficial Ownership Information Reporting Requirement Revision and Deadline Extension, published 26 March 2025. https://www.federalregister.gov/documents/2025/03/26/2025-05199/beneficial-ownership-information-reporting-requirement-revision-and-deadline-extension
US Government Accountability Office, Assessment of the revised reporting scope, May 2026. https://www.gao.gov/products/gao-26-107967
OCC, FDIC, NCUA and FinCEN, Order on customer identification programme taxpayer identification numbers, 27 June 2025. https://ncua.gov/files/press-releases-news/fincen-order-customer-identification-program.pdf
European Union, Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering. https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng
Anti-Money Laundering Authority, AMLA, official site. https://www.amla.europa.eu/index_en
Companies House, Identity verification rollout from 18 November 2025, published 5 August 2025. https://www.gov.uk/government/news/companies-house-confirms-identity-verification-rollout-from-18-november-2025
UK Government, The Money Laundering and Terrorist Financing (Amendment) Regulations 2026. https://www.legislation.gov.uk/ukdsi/2026/9780348281743
ICAEW, Parliament approves AML reform package, July 2026. https://www.icaew.com/regulation/regulatory-news/regulatory-news-2026-07/parliament-approves-aml-reform-package
Reserve Bank of India, Master Directions index, including the Commercial Banks (Know Your Customer) Directions, 2025. https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13141
FinCEN, Anti-Money Laundering and Countering the Financing of Terrorism Programs, proposed rule, published 10 April 2026. https://www.federalregister.gov/documents/2026/04/10/2026-07033/anti-money-laundering-and-countering-the-financing-of-terrorism-programs
How we work. This article was researched and written by the Financy editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@financyhub.com and tell us what and why.
Filed under RegTech & Compliance · Get The Weekly Brief
