Publicité
ERP IMPLEMENTATION
🇫🇷 Lire en français

UBO, AMLD6 and KYC in Your ERP: What European Businesses Must Automate Before 2027

AMLD6, AMLR 2024 and AMLA: what AML obligations apply to your ERP? UBO registers, supplier KYC, sanctions screening and approval workflows — practical guide 2026.

UBO, AMLD6 and KYC in Your ERP: What European Businesses Must Automate Before 2027

Your ERP records every vendor creation, every bank transfer, every transaction. What it does not do by default: check whether that new trading partner appears on an OFAC sanctions list or whether its ultimate beneficial owner is a politically exposed person (PEP) under investigation. That automation gap exposes you to fines of up to 10% of your annual turnover — and personal liability for directors.

The EU’s 2024 AML legislative package — comprising the AMLR regulation (EU Regulation 2024/1624) and the Sixth Anti-Money Laundering Directive AMLD6 (EU Directive 2024/1640) — applies from 10 July 2027 across all Member States. The deadline is not far off. For sectors newly brought into scope — crypto-assets, crowdfunding, real estate, luxury goods dealers — the compliance project starts now.

This guide is aimed at CFOs, CIOs, Compliance Directors and AML Officers at SMEs and mid-market companies operating in sectors subject to AML/CFT (Anti-Money Laundering and Counter-Financing of Terrorism) obligations. It explains what the regulatory framework requires and how your ERP can — and should — automate those controls.


The 2024 AML Package: AMLR, AMLD6 and AMLA — Three Texts, One Logic

What are AMLR and AMLD6?

The regulatory architecture rests on two complementary texts adopted in 2024:

  • AMLR (EU Regulation 2024/1624) — a directly applicable regulation across all Member States with no national transposition required. It forms the AML/CFT single rulebook, defining due diligence obligations, KYC requirements, risk management, and documentation standards. Application date: 10 July 2027.
  • AMLD6 (EU Directive 2024/1640) — a directive that Member States must transpose before 10 July 2027. It revises the rules governing Financial Intelligence Units (FIUs), supervisory arrangements, and harmonises the definition of ultimate beneficial owner (UBO) with a threshold set at 25% or more of voting rights or capital (versus “more than 25%” under the previous directive — a shareholder at exactly 25% is now included).

Which businesses are newly in scope?

AMLR significantly expands the perimeter of “obliged entities” compared to previous directives. Newly included categories include:

  • Crypto-asset service providers (CASPs) — any exchange or custody platform within scope of MiCA
  • Crowdfunding service providers
  • Dealers in precious metals, precious stones, and high-value goods (>€10,000 in cash transactions)
  • Operators of residence or citizenship by investment programmes
  • Professional football clubs and sports agents (for transfers > €2 million)
  • Mixed non-financial holding companies supervising obliged entities

Traditional actors — credit institutions, insurers, estate agents, notaries, accountants, business lawyers — remain in scope with strengthened requirements.

AMLA: Europe’s New AML Supervisory Authority

AMLA (Authority for Anti-Money Laundering and Countering the Financing of Terrorism) opened its doors in Frankfurt on 1 July 2025. It serves as the supra-national supervision pillar: coordinating national authorities (including the FCA, BaFin, AMF, and others), publishing technical standards (23 regulatory technical standards expected before July 2026), and — ultimately — directly supervising up to 40 high-risk cross-border financial entities. Selection is scheduled for 2027, with direct supervision taking effect in January 2028 (AMLA operational calendar).


The UBO Register: Obligations and ERP Integration

What is a UBO and Why Must You Declare One?

A UBO (Ultimate Beneficial Owner) is the natural person who ultimately owns or controls a legal entity. Under AMLD6, the threshold is 25% or more of shares, voting rights, or interests — including through indirect structures or chains of control.

Every company incorporated in the EU must identify its UBOs and register them in the national beneficial ownership register. In the UK, this is managed by Companies House under the People with Significant Control (PSC) register. In Germany, the register is maintained by the Bundesanzeiger. In Ireland, by the Companies Registration Office (CRO). Across the EU, each Member State maintains its own national register.

Interconnection of National UBO Registers

Since October 2023, national UBO registers have been interconnected via BRIS (Business Registers Interconnection System), pursuant to EU Directive 2018/843. A compliance officer in the Netherlands can now query the UBO register of a German, Polish, or Spanish counterparty through a single access point.

AMLD6 strengthens this interconnection: obliged entities will be required to query registers when entering into a business relationship with a new counterparty.

How ERPs Can Access and Validate UBO Data

The most advanced solutions offer direct API integration:

  • EU registries: aggregators such as Creditreform or Creditsafe consolidate UBO data from multiple European registers via a unified API.
  • UK: Companies House provides a free REST API for PSC (Person with Significant Control) data, directly queryable from your ERP vendor onboarding flow.
  • Workflow impact: at vendor creation in the ERP, a rule can automatically trigger a UBO registry lookup, compare the result with information declared by the vendor, and flag any discrepancy to the Compliance Officer before the third party is validated.

Supplier KYC and Screening in Your ERP: Automating Due Diligence

Third-Party Verification at Onboarding: Sanctions Lists, PEPs and Adverse Media

Supplier and partner KYC rests on three verification layers:

  1. Sanctions list screening: checking the third party and its directors/UBOs against OFAC (US Treasury), EU (Regulation 269/2014 and successors), UN, and UK OFSI lists. A listed party must be immediately blocked — any transaction constitutes a violation subject to criminal penalties.
  2. PEP verification (Politically Exposed Persons): individuals who hold or have held senior public office (ministers, parliamentarians, senior executives of state-owned enterprises, senior judiciary). Any business relationship with a PEP or their close associates requires enhanced due diligence.
  3. Adverse media: monitoring media sources for negative mentions (convictions, legal proceedings, alleged fraud) linked to the third party or its directors.

API-Connectable Screening Solutions

Several market solutions offer APIs that connect directly to major ERP platforms:

  • ComplyAdvantage: real-time screening, AI-driven adverse media, covering 200+ sanctions lists. API-first, 3,000+ clients globally.
  • Dow Jones Risk & Compliance: proprietary data on sanctions lists, PEPs, and high-risk companies. Premium positioning, strong in banking and insurance sectors.
  • LSEG World-Check (formerly Refinitiv): one of the most comprehensive databases on the market, with a cloud-native API (World-Check On Demand, launched 2025). Integration available with SAP, Oracle, and Dynamics 365.
  • LexisNexis Risk Solutions: combined identity verification and AML data, strong across continental Europe and North America.

Supplier Approval Workflow in the ERP

The standard process recommended by compliance teams follows five steps:

  1. Third-party creation request: the business user enters vendor data into the ERP
  2. Automated screening: the ERP calls the screening API; response within 2–5 seconds with a risk score (green / amber / red)
  3. Green result: vendor automatically approved, record created, UBO registered, timestamped audit trail generated
  4. Amber result: manual validation required by the Compliance Officer within a defined processing window (48–72 hours)
  5. Red result: immediate block, escalation to management and legal, no transactions permitted until the vendor is approved or rejected

The audit trail for each decision — including manual approvals — must be stored immutably within the ERP. This is what regulators examine first during an inspection.


Native ERP Module Capabilities

SAP GRC — Business Partner Screening

For SAP S/4HANA clients, the SAP GRC (Governance, Risk & Compliance) module includes Business Partner Screening functionality that queries global sanctions lists directly from third-party management transactions (BP). Screening can be triggered at creation, on modification, or periodically (automatic rescreening of the master data).

SAP GRC integrates with third-party data providers (Dow Jones, World-Check) via certified connectors, centralising results in the Business Partner record with a full audit trail.

Oracle Financial Services and Dynamics 365

Oracle Financial Services AML is designed primarily for financial institutions (banks, insurers). For industrial or service companies on Oracle Fusion, third-party connectors are required.

Microsoft Dynamics 365 has an ISV (Independent Software Vendor) ecosystem for KYC integration — notably Neterium for sanctions screening and Encompass for digital KYC.

Sage, Unit4, IFS and Odoo: Third-Party Connectors Required

Mid-market ERP platforms — including Sage X3, Unit4, IFS, and Odoo — have no native AML/CFT module. Compliance requires API connectors to the specialist solutions listed above, integrated into the vendor creation and modification workflow. Several system integrators offer pre-configured accelerators for Odoo (ComplyAdvantage + Odoo) and Sage X3 (World-Check API + Sage).


Practical Action Plan for Obliged Entities

Auditing Your Existing Vendor Base: Where to Start

Before automating the future, audit the past. Your existing third-party master data likely contains vendors that have never been screened. Start by prioritising:

  • Vendors domiciled in high-risk third countries (FATF list of jurisdictions under monitoring: Myanmar, Haiti, Democratic Republic of Congo, Yemen, and others)
  • Transactions exceeding €10,000 in cash or near-cash equivalents
  • Vendors of professional services (consultants, intermediaries, commercial agents)
  • Third parties with relationships spanning more than five years without reassessment

Configuring Risk-Based Due Diligence Rules in the ERP

The risk-based approach is at the heart of AMLR. Not all third parties need to be treated identically. Configure differentiated due diligence levels in your ERP:

LevelProfileERP Measures
StandardEU vendor with no risk factorSanctions list screening + UBO at creation
EnhancedPEP, high-risk third country, transaction > €50kExtended screening + adverse media + compliance validation + annual review
SimplifiedRegulated EU credit institution, listed entityMinimal screening, triennial update

Documentation and Audit Trail: What Regulators Inspect

An AML/FIU inspection consistently focuses on three questions:

  1. Do you have documented procedures? — a formalised AML/CFT policy, approved by management, accessible to teams
  2. Is the procedure applied? — an ERP audit trail for each screening performed (date, result, decision)
  3. Are incidents traced? — amber/red alerts, manual approvals, decision rationales stored

Every decision must be archived for a minimum of five years (AMLR, Article 77) from the end of the business relationship.


Timeline and Penalties: What Changes Before 10 July 2027

MilestoneEvent
July 2025AMLA operational in Frankfurt — first technical standards published
10 July 2026AMLA publishes 23 technical standards (RTS/ITS) — ERP configurations can be aligned
10 July 2027AMLR directly applicable; AMLD6 transposed across all Member States
January 2028AMLA direct supervision takes effect over the 40 selected financial entities

Penalties for non-compliance (AMLAR, Article 22): up to €10 million or 10% of total annual consolidated turnover (whichever is higher) for serious, repeated or systematic violations. Criminal penalties may apply additionally under national law.

By way of reference, BNP Paribas was fined USD 8.9 billion in 2014 in the United States for OFAC sanctions violations — an extreme case, but one that illustrates what is at stake for institutions handling international flows. Non-financial European companies face exposure at a lower scale, though one that is growing as national supervisory authorities expand their audit programmes.


To go further on embedding compliance in your ERP, read our GRC in ERP guide and our article on anti-corruption compliance automation. If access security to your ERP is a complementary angle, our Zero Trust and IAM guide covers entitlement controls.