Logo Ondorse
Download brand assets
Solutions

SOLUTIONS

Business verification (KYB)

User verification (KYC)

OVERVIEW

All-in-one KYC/B

PLATFORM

Client onboarding

Case management

AML risk scoring

INTEGRATIONS

App marketplace

Use cases

FOR WHOM

For Ops

For Compliance

For Sales & CSM

Clients
Corporate banking
Credit and financing
Asset management
Insurance and health
PSPs & acquiring
Embedded finance
Platforms and marketplaces
Corporate banking

Manager.One

Tiime

Banque Delubac

iBanFirst

Credit and financing

Hokodo

CGLLS

Finfrog

Mobilize FS

Asset management

French Food Capital

Elvest (Ex-Inter Invest)

Natixis Investment Managers International

Insurance and health

Alan

PSPs & acquiring

SSP

HiPay

PayXpert

Smile & Pay

Embedded finance

Embed

Xpollens

Lemonway

Platforms and marketplaces

Kactus

SeDomicilier.fr

Evaneos

INDUSTRY
Resources

KNOWLEDGE

Blog

Guides

News

PRODUCT

Documentation

Integrations

Product updates

DEVELOPERS

API reference

Recipes

Integration guide

TRUST

Security

Trust center

Live status

SERVICES

CX outsourcing

List tracker

Coverage map

New - CarelineLog In
Get started
Blog

Article

August 28, 2026

Launching in a new European market without rebuilding your compliance framework

Aymeric Boëlle
Co-founder & President
5 min read
IN THIS ARTICLE
Example H2

ABOUT AUTHOR

Aymeric Boëlle
President and co-founder of Ondorse. Previously a regulatory lawyer. Tech is an acquired taste.

SHARE ARTICLE

Talk with an expert

You are launching in a new EU market, whether it’s your first market or your next one. You do not need to become an expert in local Know Your Business (KYB) requirements, supervisory expectations, or registry access rules. You need the right compliance framework, correctly configured for that market from day one, so you can launch audit-ready. The regulatory complexity is real, and it is deep. But absorbing it is not your job. It is your compliance infrastructure provider’s job.

Key takeaways

  • You do not need to master local compliance rules to launch compliantly. What you need is a partner who has already done that work and translates it into a correctly parameterized workflow before you onboard your first customer.
  • “Functionally compliant” and “audit-ready” are not the same thing. Collecting the right documents is necessary but not sufficient. Regulators expect traceable decisions, justified risk thresholds, and documented escalation paths that survive scrutiny long after onboarding happened.
  • Country-by-country divergences are deep, not cosmetic. UBO thresholds, document acceptance criteria, EDD trigger conditions, and registry access rules differ materially across EU markets. A workflow compliant in France can fail an audit in Germany or the Netherlands on multiple dimensions (explore further in this article explaining how to avoid country-by-country complexity).
  • AMLA 2027 is coming, but national frameworks govern you today. The Anti-Money Laundering Regulation (AMLR) applies from 10 July 2027. Until then, ACPR, BaFin, DNB, and FCA each audit under their own national framework. Waiting for harmonization is not a compliance strategy.
  • The compliance configuration problem is operational, not legal. A regulatory memo tells you what the law says. It does not configure your risk matrix, your EDD triggers, or your audit trail. That work requires supervisory expertise, not legal advice.

What does getting this right actually look like?

When a mid-market fintech launches in a new European market with Ondorse, the compliance framework for that market is not built from scratch. It is already mapped. The connections to local company registries are pre-integrated. The identity verification standards required by the local regulator are pre-configured. The Enhanced Due Diligence (EDD) triggers reflect the specific supervisory expectations of the target jurisdiction, not a copy-paste of the domestic setup.

Before the first customer is onboarded, Maël Fasan, Ondorse’s Senior Compliance Consultant, reviews and validates the entire configuration. Maël’s role is not to summarize what the regulation says. It is to translate regulatory intent into the exact workflow configuration, risk matrix parameters, and audit trail architecture that passes scrutiny in each market. He has sat across the table from European regulators. He knows the gap between what the directive requires and what a BaFin or DNB examiner expects to see in a case file.

“

The gap I see most often is not between what the regulation requires and what teams do. It is between what teams do and what they can prove they did. Every regulator I have worked with, ACPR, BaFin, DNB, wants the same thing: a case file they can read without asking a single follow-up question. That is the bar. Most onboarding workflows are not built to that standard.

Maël Fasan Senior Compliance Consultant at Ondorse

This is the model that makes compliance a pre-solved problem rather than a post-launch discovery. Below is why that matters, and why the alternative is harder than most expanding fintechs expect.

Why is every EU market its own compliance problem?

The EU’s Anti-Money Laundering Directives (AMLD) were designed as minimum harmonization instruments. Member states transposed them into national law, adding their own interpretations, stricter thresholds, and specific supervisory expectations. The result is that France, Germany, Belgium, the Netherlands, and the UK each operate under a distinct compliance regime, sharing the same vocabulary but diverging sharply on the operational details.

The table below illustrates how five key compliance parameters differ across the markets a mid-market fintech expanding in Europe will typically encounter first.

Parameter France (ACPR) Germany (BaFin) Netherlands (DNB) Belgium (NBB) UK (FCA)
UBO threshold 25% 25% (+ beneficial control) 25% 25% (+ UBO register cross-check mandatory) 25% (PSC register)
UBO register access RBE, public, free Transparenzregister, requires proof of legitimate interest UBO register, public UBO register, public Companies House PSC, public, real-time API
Identity verification standard PVID-certified (ANSSI), eIDAS LoA Substantial VideoIdent or eIDAS, BaFin circular 03/2017 eIDAS, DNB guidance on remote onboarding eIDAS, NBB AML circular 2021 DIATF (UK DCMS), FCA guidance
EDD trigger (example) PEP, high-risk third country, complex UBO structure PEP, specific sectors (real estate, crypto), cash-intensive High-risk jurisdiction, missing UBO data, adverse media PEP, non-EU group structure, specific product types PEP, high-risk country (FATF grey list), unusual transaction patterns
Key regulatory reference Code Monétaire et Financier, ACPR guidelines GwG (Geldwäschegesetz), BaFin circulars Wwft (Wet ter voorkoming van witwassen), DNB guidelines Loi du 18 septembre 2017, NBB circulars POCA 2002, MLR 2017, FCA Financial Crime Guide

Each of these parameters needs to be correctly configured in your onboarding workflow before you process your first customer in that market. Not after your first audit finding. The five markets above are the most common first steps for European expansion. Ondorse covers a broader set of jurisdictions, see the full coverage map →

And it is about to get harder. Under the AMLR, the mandatory data set for Ultimate Beneficial Owners (UBOs) expands significantly: date and place of birth, full address including country, all nationalities, ID document number, and personal identification number all become compulsory fields. None of these are typically available in public registries. (consalty, July 2026) Obliged entities will have to collect them directly from the customer. On top of that, if a client is registered in another EU member state, the AMLR requires querying that member state’s own beneficial ownership register, which means either building registry connections in each country or asking the customer to provide the extract themselves. The EU-wide centralized registry platform with a common English interface is not expected to be available before mid-2027. Until then, every cross-border UBO verification is a country-specific operational problem.

What breaks when a fintech configures compliance in a new market from scratch?

Most expanding fintechs approach a new market the same way: assign the project to their Head of Compliance, engage a local law firm for a regulatory memo, then ask their engineering team to adapt the existing workflow. This process has consistent failure modes.

  • The regulatory memo describes what the law says, not how the regulator actually audits. There is a gap between the text of the Wwft and what the DNB expects to see in a case file during a supervisory review. That gap is only visible to practitioners with direct supervisory experience.
  • Document acceptance rules are not in the law. Whether a Dutch DigiD counts as valid identity verification, whether a German Handelsregister extract downloaded 45 days ago is still current, whether a Bulgarian UBO declaration signed by a local notary satisfies French ACPR standards for a cross-border onboarding: none of this is in the directive. It lives in supervisory guidance, precedent, and institutional knowledge.
  • Workflow configuration lags legal advice. Engineering teams receive compliance requirements weeks after the legal memo and translate them imperfectly. The result is a workflow that approximates the compliance intent without matching the regulatory expectation.
  • Risk matrices are copied from the domestic market. Sector risk weights, country risk scores, and EDD thresholds calibrated for a French or British portfolio do not transfer to a Belgian or German one without recalibration.
  • AMLR creates counter-intuitive traps that no legal memo will flag. Under the incoming AMLR, low-risk verification scenarios are paradoxically stricter than standard CDD obligations in some configurations. The German Handelsregister is an accepted verification source under standard CDD, but not under the low-risk path. (consalty, July 2026) A compliance team relying on a regulatory memo will not catch this. A practitioner who has stress-tested the rules will.
  • Audit trail is an afterthought. The first time a fintech realizes its audit trail does not document why a specific customer was auto-approved is usually during a regulatory review, not during configuration.

What does “audit-ready” actually mean, market by market?

Being audit-ready is not a state you achieve once before launch. It is an architecture decision.

For the ACPR in France, audit-readiness means: every decision (approve, escalate, reject) is logged with the rule set version that produced it, the risk score is justified against the fintech’s own risk classification document, and the EDD case file documents who made the final decision and on what basis.

For the BaFin in Germany, it means: the Transparenzregister query is logged even when it returns no result, the VideoIdent session is retained and retrievable, and the risk matrix explicitly addresses the sectors flagged in BaFin’s sectoral risk assessments.

For the DNB in the Netherlands, it means: the UBO graph is complete and cross-referenced against the Dutch UBO register, every deviation from standard Customer Due Diligence (CDD) is documented, and the workflow produces a case file that a DNB examiner can read without asking follow-up questions.

These requirements are not written in a single document. They are assembled from circulars, supervisory Q&As, enforcement decisions, and direct engagement with regulators. This is exactly the institutional knowledge Maël brings to every new market configuration on Ondorse’s platform.

Does AMLA 2027 change this calculation?

Not yet, and not as much as you might hope.

AMLA became operational on 1 July 2025 : Based in Frankfurt, it will directly supervise approximately 40 of the highest-risk EU obliged entities from 2028. For the remaining thousands of regulated fintechs, its immediate impact is indirect: it coordinates national supervisors, drafts Regulatory Technical Standards (RTS) that will define AMLR implementation, and raises the audit bar across member states.

The AMLR itself applies from 10 July 2027 : It is a directly binding regulation, meaning no national transposition step, and the same CDD rules and UBO verification standards will apply uniformly across the EU for the first time. That is genuinely significant.

But three realities prevent this from being a reason to wait:

  1. RTSs are still being published. The operational detail of AMLR implementation lives in RTSs that AMLA is drafting through 2026 and into 2027. (AML RightSource, 2026) Fintechs that defer configuration until the final RTS package is complete will not be ready by July 2027.
  2. AMLD6 still requires national transposition. The sixth Anti-Money Laundering Directive governs beneficial ownership registers and national supervisory structures. Country-level divergences in registry access, UBO register quality, and supervisory expectations persist through and beyond 2027.
  3. National supervisors remain primary until 2028. AMLA’s direct supervisory powers do not activate until 2028. Until then, every fintech’s primary regulatory relationship is with its national supervisor, under the national framework.

The AMLA transition period is not a compliance holiday. Fintechs that configure correct, audit-ready workflows per market today will be AMLR-ready by July 2027 without a redevelopment sprint. Those who wait will not.

How Ondorse absorbs this complexity so you do not have to

The architecture Ondorse has designed for multi-market deployments handles both the current fragmented reality and the coming AMLA harmonization. One contract, one platform, N countries. AML governance is centralized. Country-level configuration, language, document types, regulatory thresholds, registry connections, operates as a scoped override on top of the global framework, not as a separate logic stack.

‍

“

Ondorse is not a compliance tool layered on top of your existing stack. It is the system of record for your compliance data - the single place where every decision, every document, every risk score, and every escalation is logged, versioned, and auditable.

Florent Robert CEO and co-founder of Ondorse

In practice, this means:

  • A new European market does not require rebuilding the compliance layer from scratch.
  • Each country configuration is validated by MaĂ«l against the local supervisory expectation before activation.
  • When AMLA RTSs are published, the platform absorbs the changes. No client redevelopment required.
  • New countries are activable within 2 weeks of request, with the compliance framework pre-mapped. The markets currently available on Ondorse's platform are listed on our global coverage map. New jurisdictions are added on request, with compliance configurations validated before activation.

A regulated payment institution launched in three EU markets, France, Belgium, and Bulgaria, under a single Ondorse contract. Each country's compliance configuration, document types, UBO verification rules, language settings, and EDD triggers, was pre-mapped and validated by Ondorse's compliance team before the first customer was onboarded. The institution's Head of Compliance did not write a single local regulatory requirement. Their IT department did not write a single line of code.

If you are planning a European market expansion and want to understand what audit-ready looks like for your specific regulatory context, the conversation starts here.

‍

Discover our latest guide

Everything you need to know about this subject

Read GuideRead Guide

Heading

Subtextt

Try it yourself

ABOUT AUTHOR

President and co-founder of Ondorse. Previously a regulatory lawyer. Tech is an acquired taste.

SHARE ARTICLE

Talk with an expert

Short description

Similar articles

A morning with France's former PM and the ACPR's Vice-President

On June 30th, Ondorse hosted an off-the-record breakfast with France's former Prime Minister Bernard Cazeneuve and Jean-Paul Faugère, Vice-President of the ACPR. The topic: what the regulator's recent sanctions actually mean for compliance teams. We can't tell you what was said. But you can be in the room next time.
Insights

Read article

Scaling KYB compliance across Europe: How to avoid country-by-country complexity

Multi-country KYB complexity is architectural, not regulatory. Here's how to fix the build before it becomes unmanageable.
Insights

Read article

Document verification is not a KYC program. It never was.

Regulated institutions run KYC RFPs and receive proposals from IDV vendors and BPOs. Both solve real problems. Neither delivers a KYC compliance program. Here is why the confusion is structural, and what it costs under AMLR 2027.
Insights

Read article

Ready to take the manual work out of KYC/B?

Unlock the power of automation
Easy setup that takes just a few days
Friendly human support based in Europe
Book a call
Subscribe to our newsletter

The latest information and tips on business onboarding, KYB, compliance, risk management

By submitting your information above, you hereby consent to Ondorse’s use of your information for sales and marketing purposes, and you otherwise agree with the use, storage and handling of your data by Ondorse in accordance with Ondorse’s Privacy Policy.
Logo Ondorse

Powering KYC/KYB
for modern operations.

Contact us
Eng
Fra
Get an AI summary of Ondorse:
Resources
BlogGuidesSuccess storiesAPI referenceProduct documentationIntegrationsProduct updatesSecurityOfficial documentsNews
KYC
KYC softwareKYC workflowKYC workflow builderKYC orchestrationKYC API integrationKYB verificationCustomer onboarding softwareAccount opening fraud prevention
COMPLIANCE
Compliance softwareKYC/AML platformAML case managementCustomer risk assessmentOngoing monitoring
SOLUTION
Client onboardingCase managementAML risk scoringApp marketplaceScan libraryRemediation libraryAll-in-one KYC/B
GET STARTED
Contact usLogin
USE CASES
For compliance teamsFor operations teams
COMPANY
TeamCareers
Ondorse.co ISOMark_27001-2022Ondorse.co Prescient SOC2 Type 2 Badge
Logo LinkedInLogo Twitter
Ondorse © 2026
Privacy PolicyTerms & ConditionsCookie Policy