Introduction
For most of the past decade, outsourcing identity verification and Know Your Customer (KYC) processes has been treated by European obliged entities as a tactical convenience, something to fall back on when internal capacity ran short, or when a particular onboarding flow proved too costly to build in-house. As the European Union enters the most significant overhaul of its anti-money laundering and digital identity framework in a generation, that mindset has become outdated. Between now and 2027, outsourcing will shift from being one option among several to being the rational default for the majority of obliged entities.
This article sets out why. The argument rests on three pillars: the scale and pace of the regulatory transformation now under way, the explicit legitimisation of outsourcing under the new Anti-Money Laundering Regulation, and the economics of building and maintaining a compliant onboarding stack in an environment where the rules themselves are still being written.
A regulatory landscape in transition
The European compliance perimeter is being redrawn by several interlocking instruments that take effect over a short window.
The Anti-Money Laundering Regulation (Regulation (EU) 2024/1624, “AMLR”) will apply directly across all Member States from July 2027, replacing the fragmented, directive-based approach with a single rulebook for customer due diligence (CDD). It is accompanied by the Sixth Anti-Money Laundering Directive (AMLD6), which Member States must transpose by the same date, and by the new European Anti-Money Laundering Authority (AMLA), which will directly supervise a first cohort of systemically important institutions and set the supervisory benchmark for everyone else.
In parallel, the revised eIDAS Regulation (Regulation (EU) 2024/1183, “eIDAS 2.0”) requires every Member State to make available at least one European Digital Identity Wallet (EUDI Wallet) by the end of 2026, with the obligation to accept these wallets extending to regulated private entities (banks, telecommunications operators, and utilities among them) over the course of 2027. Under the AMLR and its draft Regulatory Technical Standards, eIDAS-compliant electronic identification and Qualified Electronic Attestations of Attributes (QEAA) are recognised as equivalent to face-to-face verification, and onboarding systems are expected to integrate with the EUDI Wallet at the “High” assurance level.
The practical consequence is unambiguous. Every obliged entity in the Union will, before 2027, have to re-architect its onboarding to support risk-based, context-driven identification (Article 22 AMLR), to accept the EUDI Wallet and qualified attestations, and to operate continuous, perpetual KYC with prescribed review intervals. This is not a configuration change. It is a structural redesign of the identity layer.
Article 18 AMLR: outsourcing moves from grey area to regulated default
The most important development for the outsourcing question is that the AMLR removes the ambiguity that previously surrounded it. Article 18 of the Regulation is the first EU-level provision to comprehensively govern the outsourcing of AML/CFT tasks across all obliged entities, and it gives outsourcing an explicit green light, subject to clear conditions.
Two of those conditions deserve emphasis, because they are precisely what makes outsourcing a safe default rather than a risk. First, the supervisor must be notified before the service provider begins performing the outsourced task; outsourcing without prior notification is itself a breach, independent of the quality of the work. Second, when a provider performs an outsourced AML/CFT task, it is legally regarded as part of the obliged entity for that task, yet responsibility, risk ownership, and decision-making can never be transferred. They remain with the obliged entity.
Far from being a deterrent, this allocation of responsibility is the feature that makes outsourcing the responsible choice. The obliged entity retains full control over strategy, risk appetite, and the final compliance decision, while delegating the operational and technical execution (document verification, biometric checks, liveness detection, wallet integration) to a specialist. The entity outsources the work, not the accountability. That is exactly the division of labour a well-governed institution should want.
Why building in-house is the wrong default
Against this backdrop, the case for building and maintaining the identity stack internally has weakened considerably.
The economics are unfavourable from the outset. An in-house build commits significant fixed engineering and operational cost before verification volume is high enough to justify it, and that cost recurs indefinitely through maintenance, security patching, and annual compliance audits. For all but the largest institutions, this is the most expensive path precisely when budgets are most uncertain.
The pace of regulatory change compounds the problem. The Regulatory Technical Standards that will give the AMLR operational detail are still under consultation, and the identification methods deemed acceptable (nationally notified eID, the EUDI Wallet, qualified attestations, biometric flows) will continue to evolve. A system built to today's understanding will require continual rework simply to remain compliant.
The architectural complexity is also significant and increasingly specialised. Integrating the EUDI Wallet at the “High” assurance level, accepting qualified attestations, and orchestrating risk-based onboarding are non-trivial engineering tasks. Where biometric face matching or liveness detection is involved, the system falls within the scope of the AI Act's rules on remote biometric identification; the handling of identity data engages the full weight of the GDPR; and the issuance of qualified attestations requires the involvement of a Qualified Trust Service Provider (QTSP), a heavy certification regime that few institutions will pursue for themselves. Each of these is a distinct discipline, and maintaining all of them in-house is a poor use of an institution's engineering capacity.
Why outsourcing is the go-to option
Specialist providers exist precisely to absorb this complexity. An identity-first provider can deliver a strong verification front end while integrating the certified back-end issuance of established QTSPs, so that the obliged entity gains both robust onboarding and qualified attestation without becoming a trust service provider itself. The provider carries the product-level burden of GDPR and AI Act compliance for its verification components, keeps pace with the evolving Technical Standards as part of its core business, and offers the modular, adaptive onboarding orchestration that Article 22's risk-based approach demands.
This is the decisive point. The future of EU onboarding is not a single fixed flow but an adaptive architecture capable of handling everything from a simple proof of identity to a complex, multi-attribute verification, drawing on wallets, qualified attestations, and traditional methods as the risk profile dictates. That kind of orchestration is most efficiently delivered by a specialist whose entire product is built around it, and most expensively reinvented by an obliged entity for whom identity is one function among many.
Outsourcing the right way
Treating outsourcing as the default does not mean treating it casually. The same Article 18 framework that legitimises outsourcing also prescribes how to do it correctly, and obliged entities should approach it as a governed process:
- Notify the supervisor before the provider begins the outsourced task.
- Retain accountability and decision-making internally; document the rationale for the chosen identification flows so that they can be justified to the competent authority as proportionate and compliant.
- Conduct genuine vendor due diligence, recognising that the provider is treated as part of the obliged entity for the outsourced task.
- Put a Data Processing Agreement in place under the GDPR, with the provider acting as processor.
- Confirm the provider's coverage of AI Act obligations for biometric components and its integration with a QTSP for any qualified issuance.
Handled this way, outsourcing is not a shortcut around compliance. It is a structured means of achieving compliance faster, more cheaply, and with greater resilience than an in-house build can offer.
Conclusion
The convergence of the AMLR, AMLA, eIDAS 2.0, and the EUDI Wallet has turned the identity layer into a moving target that every EU obliged entity must hit by 2027. In that environment, the relevant question is no longer whether outsourcing is permissible (Article 18 settles that) but whether building and maintaining a compliant onboarding stack internally is a defensible use of scarce resources. For most institutions, it is not. Outsourcing, conducted under proper governance, is the strategic default: it delivers the architecture the new framework demands, keeps responsibility where the law requires it, and frees the obliged entity to focus on the decisions that genuinely cannot be delegated.
Disclaimer: This article is for general information only and does not constitute legal advice. Specific outsourcing and data-processing arrangements should be reviewed with qualified AML and data-protection counsel.