Compliance management software in the European Union has to work across borders by default. A firm in Cyprus onboarding a customer in Greece with a parent in Malta and a director in Romania needs registry coverage, language handling and beneficial ownership resolution in four jurisdictions, each with its own access rules and data quality.
The regulatory floor is also rising. The EU AML Package moves the core rules into a directly applicable regulation supervised by the Anti-Money Laundering Authority, narrowing national discretion. In parallel, DORA sets operational resilience requirements on financial entities and their ICT providers, and MiCA brings crypto-asset service providers into scope. Software chosen now should already be able to evidence all three.
The EU rulebook your software has to carry
- The EU AML Package — a single rulebook applying directly across member states, with AMLA supervising selected high-risk obliged entities and coordinating national supervisors.
- Customer due diligence and enhanced due diligence for PEPs, complex ownership structures and high-risk third countries.
- Beneficial ownership identification, with access to national UBO registers restricted to legitimate interest following the CJEU's 2022 judgment.
- EU consolidated sanctions screening, plus asset freeze reporting to national competent authorities.
- GDPR — lawful basis, data minimisation, retention limits and subject rights over screening and profiling data.
- DORA — ICT risk management, incident reporting and third-party provider oversight for in-scope financial entities.
- MiCA — authorisation, travel-rule and monitoring obligations for crypto-asset service providers.
Cross-border KYB realities
| Challenge | What it looks like in practice | What good software does |
|---|---|---|
| Fragmented registers | 27 national registers, different schemas and languages | Normalises entities to one schema with source attribution |
| UBO access | Legitimate-interest gating varies by member state | Records the access basis and falls back to corroborating sources |
| Language | Filings in national languages | Machine translation plus original document retention |
| Latency | Filing frequency differs widely | Timestamps every data point so staleness is visible |
| Divergent lists | EU, UK and OFAC designations differ | Screens all applicable regimes in one pass |
What EU buyers should test in a demo
- Onboard a multi-jurisdiction group and inspect how the UBO chain is resolved and where each data point came from.
- Ask which member-state registers are primary-source connected and which are scraped or manually sourced.
- Review the GDPR position: hosting region, sub-processors, retention configuration and how a subject access request is served.
- Confirm DORA-relevant artefacts exist — incident reporting support, exit plans and a register of information entry.
- Test alert handling in a language other than English, including transliterated name matching.
How Infocredit Group supports EU firms
Infocredit Group has operated from Cyprus since 1972 and covers Cyprus, Malta, Greece, Hungary, Romania and the wider EU alongside the UK, North America, the Gulf and Africa. ComplianceSuite runs EU KYB and KYC onboarding, consolidated sanctions and PEP screening, adverse media and continuous monitoring. RISQO scores counterparties and suppliers across ten risk dimensions, and API4ALL lets EU firms search companies and order Credit, KYB and Structure reports directly inside their existing systems.
Frequently asked questions
How does the EU AML Package change compliance software requirements?
The package replaces much of the directive-based patchwork with a directly applicable regulation and creates AMLA as a central supervisor. Software must apply a single harmonised rulebook consistently across member states, evidence customer due diligence to that standard, and produce reporting that both national authorities and AMLA can review.
Can one platform handle KYB across all EU member states?
A capable platform normalises data from national business registers and beneficial ownership registers into a single schema with source attribution and timestamps. Coverage depth still varies by country, so ask a vendor which registers are primary-source connected rather than accepting a coverage map at face value.
How does GDPR affect sanctions and PEP screening?
Screening processes personal data, so it needs a lawful basis — usually a legal obligation or legitimate interests — plus data minimisation, defined retention, transparency, and a process for handling access and rectification requests. Discounted alerts must be retained proportionately as evidence rather than kept indefinitely by default.
Does DORA apply to compliance software vendors?
DORA applies directly to in-scope financial entities and reaches their ICT third-party providers through contractual and oversight requirements. If your compliance platform supports a critical or important function, it belongs in your register of information with the associated contractual terms and exit plan.
Is the EU consolidated sanctions list enough?
Only if your exposure is purely EU. Most firms with international customers, correspondent relationships or USD clearing also screen the UK Sanctions List and OFAC designations, because the three regimes have diverged.
Compliance insights, straight to your inbox
Monthly analysis on AML, screening and risk technology from the teams behind ComplianceSuite, RISQO and API4ALL. No spam — unsubscribe anytime.
