Draft ‘RTS on CDD’ – Identification and verification of the identity of the client and beneficial owners

Regulatory & Compliance Financial Services

By: Anael Rosalen, Marco Gagliardi

In May 2026, we reported on the start of the implementation of the European Council’s AML package in Liechtenstein (Implementation of the EU AML package in Liechtenstein – Repeal of the SPG and enactment of the new GwG). As is well known, the implementing regulatory technical standards (RTS), which are particularly relevant in practice, have not yet been finalised but have been and are still being worked on in consultation procedures. This article examines the draft ‘RTS on CDD’ (Regulatory Technical Standard on Customer Due Diligence), in particular its provisions on establishing and verifying the identity of the customer and the beneficial owners.
Contents

Context1


1This is a greatly simplified overview, intended to provide a quick initial understanding of the subject matter. Each institution should determine the relevance and the specific need for action on a case-by-case basis.

 

RTS on CDD

As the RTS are still at the draft stage, further changes are still possible. The following section highlights what are likely to be the most significant changes compared with the current legal situation regarding obligations relating to customer identification and the identification of beneficial owners.

Level of detail required for the data to be collected: 

The required level of detail for the data to be collected has been slightly increased. For example, in the case of natural persons, all first names and surnames (previously: first name and surname), as well as the place of birth, must be recorded; for legal entities, both the registered name and the trading name (previously: name or company name) must be recorded. 

Requirements for an ‘equivalent’ identity document: 

An explicit list of criteria has been introduced to determine whether an identity document is considered equivalent to an identity card or passport. These include, amongst other things, details of the period of validity or security features to ensure authenticity. 

The same applies to the requirements for an identification document in cases where the customer is unable to present a suitable identity document.

Ownership/control structures and complex structures:

Those subject to due diligence obligations must take risk-based measures to ensure a comprehensive understanding of their customers’ ownership and control structures. In this context, the classification of a customer relationship as a complex structure is also relevant, as this influences the overall risk rating of the relationship and the scope of the due diligence obligations to be fulfilled. A legal definition of a complex structure has now been introduced. Such a structure may exist where there are three or more layers between the customer and the beneficial owner, as well as at least two of other defined criteria (e.g. involvement of nominee shareholders, foundations, trusts or similar entities, etc.) are met.

Identification of beneficial owners of legal entities, trusts and foundations:

The identification of beneficial owners essentially follows the already familiar and established provisions. Accordingly, there should generally be no major differences in practice. Nevertheless, there may be variations on specific points, for example, in the calculation or determination of (in)direct ownership control or other forms of control. 

One new development is the special provisions relating to discretionary trusts, where trustees may exercise a certain degree of discretion in selecting beneficiaries, but may also choose not to do so. In such cases, additional information must be collected and further monitoring obligations may arise, for example, as to whether discretion has been exercised or not, or whether it is still possible to exercise discretion at all.

Register extracts for verifying information on beneficial owners:

It is mandatory to search central registers for beneficial owners; however, this alone does not constitute an appropriate measure for verifying the identity of beneficial owners. The RTS therefore specify appropriate additional measures, such as searching other public registers or obtaining information from the client and from third-party sources.

Beneficiaries of foundations: 

Article 60 of the AML Regulation provides for specific treatment of discretionary beneficiaries of trusts. It is currently unclear whether a similar approach might be introduced. However, given the functional similarity between trusts and foundations, this is in principle conceivable.

 

Timetable

As a directly applicable regulation, the AML Regulation is expected to replace the SPG on 10 July 2027. The associated RTS will therefore also come into force on that date. 

There is currently no clear information regarding the publication of the final versions of the RTS. Nevertheless, given the current draft of the ‘RTS on CDD’, it can be assumed that the provisions are largely final. 

 

Impact on market participants 

Although the fundamental requirements and principles for institutions and individuals subject to anti-money laundering legislation will not be comprehensively altered, there are in some instances minor or even significant deviations from the familiar requirements.

Given the scope and complexity of the new regulatory framework, affected institutions should carry out a detailed analysis of their current anti-money laundering arrangements at an early stage in order to assess their options and any necessary action.

If you have any questions regarding the AML package or other financial market law issues, the Regulatory & Compliance Financial Services team will be happy to assist you. We look forward to hearing from you.