July 2027, when the EU's AML Regulation applies directly across all member states, sits exactly eighteen months away. Subtract a quarter for vendor selection, a quarter for integration, a quarter for policy rewrites and model validation, and a quarter of parallel running before cut-over, and the comfortable-sounding distance evaporates. AMLA's steady stream of draft technical standards through 2026 keeps sharpening what "ready" means.
What changes in practice
The headline shifts: harmonised customer due-diligence data points that end national interpretation games; beneficial-ownership rules applied uniformly at 25%; obliged-entity status for crypto firms and other newcomers; and a supervisor architecture built to compare institutions across borders. The polite fiction that a national rulebook quirk excuses a weak control does not survive 2027.
Eighteen-month plan, one platform
A calm AMLR programme looks like this: quarter one, map current CDD against the regulation's data points; quarter two, deploy verified identity, UBO resolution and screening as one evidenced pipeline; quarters three and four, encode the risk policy as executable rules and run parallel. WeVerify compresses the middle: KYC, KYB, screening and rule-driven Advanced CDD with LSEG and Moody's data (bring your own licence supported) already operate as that pipeline, emitting the sealed evidence AMLA-era examiners will expect.
