Blog – Future Processing
Home Blog IT News Why your factoring onboarding process won’t hold up to a 2027 audit 
IT News

Why your factoring onboarding process won’t hold up to a 2027 audit 

Non-bank factoring companies have been onboarding clients under AML/KYC obligations for years. Procedures exist, consultants keep them current, analysts follow them. The compliance program works in the sense that clients get onboarded, the team knows what to do, and regulatory incidents are rare. What July 2027 tests is something different: not whether the process ran, but whether it can be demonstrated. A supervisor applying harmonised EU standards does not ask "do you have procedures?" - they ask "show me what happened in this case."
Share on:

Table of contents

Share on:

Key takeaways

  • Non-bank factors are named explicitly in the new EU AML regulation as obliged entities from 10 July 2027. Not by analogy to banks: by name. 

  • AMLR is qualitatively different from every directive before it: one regulation, no national transposition, a new supervisory authority harmonising standards across all 27 member states. The approach based entirely on PDF instructions & e-mail no longer holds as regulators will expect a structured, retrievable compliance record for every client, not a reconstruction from email chains after the fact. 

  • A digitally enabled onboarding process turns future rule changes into configuration updates, not procedure rewrites. Building that architecture based on automation with human judgment at decision points takes time. Firms decide now, or under emergency conditions. 

What onboarding looks like without an integrated platform and why it works

Most non-bank factors run client onboarding the same way they have for a decade. A client portal or email thread collects documents. Compliance, credit, and legal each work through their own steps. An experienced analyst drives coordination. When that person is available and knows the process, clients get onboarded efficiently. When they are on leave, or have just joined, or are handling a few submissions at once, the process slows or stalls. 

Adapting to regulatory change follows the same pattern. A new AML directive means a new procedure in Word, an updated checklist, an email to the relevant people explaining what changed. Compliance consultants keep the documents current, an effective arrangement that many firms rely on. The problem is not whether the procedure is current. It is whether its application is verifiable. 

Can your firm confirm today that every analyst in every client file over the past twelve months applied the same version of the UBO verification checklist? That question, not “do we have the right procedures,” but “can we prove what was applied in this specific case,” is what determines audit risk from 2027 onward. 

What AMLR actually requires - and why this is not "another directive"

In July 2027, non-bank factoring companies across Europe become obliged entities under a new legal framework, not by analogy to banking, not through national interpretation, but by name. Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation (AMLR), defines “financial institution” by reference to CRD IV Annex I, which explicitly lists “factoring, with or without recourse”. The regulation applies from 10 July 2027, directly, across all 27 EU member states. 

This matters differently from the directives that came before. AMLD4, AMLD5, and AMLD6 were each transposed into national law. Every member state produced its own version, with its own supervisor and its own tolerance for how compliance looked in practice. AMLR is a regulation: identical across all EU member states, applicable without national adaptation, with no space for local interpretation. 

From January 2028, AMLA (the Anti-Money Laundering Authority, headquartered in Frankfurt) begins harmonising supervisory standards across every member state. The largest cross-border institutions fall under direct AMLA supervision; all others come under indirect supervision, with national supervisors required to apply AMLA’s harmonised standards. A supervisor applying those standards will not accept “this is how we do it here” as an explanation. They will accept a documented process with a retrievable record. 

Two additional deadlines converge in the same 18-month window. By December 2027, financial institutions must be capable of accepting the EUDI Wallet, the EU’s digital identity credential, as a valid method for KYC verification of beneficial owners. For a firm that has been active for a decade, that is an operational challenge larger than new onboardings, carrying the same auditability requirement. 

Enhancing the architecture of an application that enables over 20 million invoices to be processed each day

Read the case study

Why updating the checklist won't be enough this time

The standard response to a new AML directive is to update the procedure and brief the team. This has worked for two rounds of directives. It will not work for what AMLR now requires. 

A new checklist is the correct starting point. The problem is that it does not change how the analyst documents what they found, what decision they made, or what rule they applied. A consultant can update the procedure document effectively. No one can confirm the update was applied in every specific case in a verifiable way. 

When a supervisor pulls a client file from three months ago, the question is: show me what happened here. Documentation in email threads, assembled after the fact, does not satisfy a supervisor applying harmonised EU standards. The 5-year data retention requirement under AMLR is not a filing obligation; it is the assumption that a structured record exists and can be produced. 

AMLR, and AMLA supervisory operations all converge on the same process requirement: not a procedure that describes what should happen, but a system that records what did. 

What a structured onboarding workflow looks like

The architecture that meets this requirement is not novel. It is the systematic application of automation and structured data capture to a process that currently depends on human judgment and email coordination. Not every firm needs to implement all of it. The right scope depends on scale, volume, and where the current process carries the most compliance risk.

Before the file reaches a person: completeness is checked automatically. When a client submits documents within the onboarding procedure, an automated check validates completeness before any analyst opens the file: are all required documents for this entity type present, is the AR aging within the required period, are formats compatible? An incomplete submission gets specific feedback within minutes. Document requirements live in a configurable instruction. When requirements change, the system enforces the update automatically. Compliance no longer depends on every analyst having read and applied the latest version.

Data extraction – the analyst verifies judgment, not information. Structured data is extracted automatically from the client’s submitted documents: registration data, the beneficial ownership chain above the applicable threshold, financial data. The analyst receives prepared, structured output rather than a stack of PDFs to work through. When a regulatory change shifts the UBO threshold, for example, one parameter in the extraction instruction changes.

Beneficial owner verification through external registries. Extracted UBO data goes automatically to a PEP and sanctions database and to the relevant national UBO register. The EU is interconnecting national registers through the BORIS system. The result comes back structured: confirmed, discrepancy, or PEP match. This is an API call, not an analyst task.

Routing to the right path by rule, not by availability. The assembled case file routes automatically to the appropriate path: standard CDD to a first-line analyst; a client from a high-risk jurisdiction to a senior compliance analyst; a high-net-worth individual to a mandatory EDD path. Routing rules are configurable. Changing an EDD trigger does not require a process re-design.

The human decision with a record that holds. The analyst reviews a prepared case: extracted data, screening results, flags. They make a judgment and document it with reasoning. Under AMLR, this documentation is a requirement. The audit record contains what was extracted, what rules were applied, what the analyst decided and why. Retention: five years. If a supervisor requests the documentation, it is retrieved, not reconstructed.

What changes in 2027 - and what stays the same

The most visible difference is in how regulatory changes land.

When the EU Commission adds a new country to the high-risk third-country list, something that happens several times a year, the PDF-and-email workflow responds: the consultant updates the procedure, the team gets an email. The adaptation is done in a day. The problem arrives three months later, when a supervisor pulls a client file onboarded the week after the update: the client’s UBO is from that country. Was EDD conducted? The answer is somewhere in the analyst’s notes. Or it isn’t. In a structured workflow, the high-risk country list in the agent’s configuration is updated, routing rules automatically trigger EDD for every subsequent case, and the case file records what rule was applied and when. The same logic applies to new EDD triggers and UBO threshold changes

The scope of what to automate varies with the firm. Some factors will build end-to-end; others will focus on specific bottlenecks (completeness checking, UBO extraction, sanctions screening) while keeping human-driven steps elsewhere. The right starting point is not a system architecture decision. It is an honest assessment of where your current process would fail an audit: where records are missing, where rules are applied inconsistently, where decisions are not retrievable. Automation investment there delivers the fastest return on compliance risk. A smaller factor can achieve the same auditability standard as a larger one with a narrower scope, provided the scope covers the right steps. What does not vary is the requirement itself. Every factor named under AMLR needs to be able to produce a structured, retrievable compliance record, regardless of how much of the process is automated.

The hard part is not building a system that handles today’s requirements. It is building one that handles the next round, and the one after that. AML/KYC regulations change frequently. Each change is manageable in isolation; the accumulation is what drives costly rebuilds. Getting the architecture right from the start (modular, configurable, with compliance logic separated from core process flow) is what determines whether future regulatory updates are configuration tasks or re-engineering projects. A vendor with domain knowledge of factoring compliance and experience building AI-driven workflows makes the most material difference here: not in the technology, but in the design decisions that make it durable.

The window

A non-bank factor can update its procedures, keep its compliance program current, and onboard clients in July 2027 without a technical problem. Demonstrating what happened in each case is a different task.

An implementation project of this kind, from decision through vendor selection, implementation, testing, and go-live, takes nine to twelve months. Firms that decide now have time for a measured implementation before July 2027. Firms that decide in Q1 2027 will be implementing under emergency conditions, parallel to procedure updates, against a supervisor’s deadline.

Factors building this architecture now are not just buying readiness for 2027. They are buying a different unit of adaptation for every subsequent round. The next round is already on AMLA’s calendar.

AI Readiness Assessment

Gain a clear view of how prepared your data is to support and scale AI initiatives in your organisation.

Value we delivered

$
27
bn

in assets processed through a scalable finance platform built to support the company's growth.

Let’s talk

Contact us and transform your business with our comprehensive services.