Article
August 28, 2026
Launching in a new European market without rebuilding your compliance framework

You are launching in a new EU market, whether it’s your first market or your next one. You do not need to become an expert in local Know Your Business (KYB) requirements, supervisory expectations, or registry access rules. You need the right compliance framework, correctly configured for that market from day one, so you can launch audit-ready. The regulatory complexity is real, and it is deep. But absorbing it is not your job. It is your compliance infrastructure provider’s job.
Key takeaways
- You do not need to master local compliance rules to launch compliantly. What you need is a partner who has already done that work and translates it into a correctly parameterized workflow before you onboard your first customer.
- “Functionally compliant” and “audit-ready” are not the same thing. Collecting the right documents is necessary but not sufficient. Regulators expect traceable decisions, justified risk thresholds, and documented escalation paths that survive scrutiny long after onboarding happened.
- Country-by-country divergences are deep, not cosmetic. UBO thresholds, document acceptance criteria, EDD trigger conditions, and registry access rules differ materially across EU markets. A workflow compliant in France can fail an audit in Germany or the Netherlands on multiple dimensions (explore further in this article explaining how to avoid country-by-country complexity).
- AMLA 2027 is coming, but national frameworks govern you today. The Anti-Money Laundering Regulation (AMLR) applies from 10 July 2027. Until then, ACPR, BaFin, DNB, and FCA each audit under their own national framework. Waiting for harmonization is not a compliance strategy.
- The compliance configuration problem is operational, not legal. A regulatory memo tells you what the law says. It does not configure your risk matrix, your EDD triggers, or your audit trail. That work requires supervisory expertise, not legal advice.
What does getting this right actually look like?
When a mid-market fintech launches in a new European market with Ondorse, the compliance framework for that market is not built from scratch. It is already mapped. The connections to local company registries are pre-integrated. The identity verification standards required by the local regulator are pre-configured. The Enhanced Due Diligence (EDD) triggers reflect the specific supervisory expectations of the target jurisdiction, not a copy-paste of the domestic setup.
Before the first customer is onboarded, Maël Fasan, Ondorse’s Senior Compliance Consultant, reviews and validates the entire configuration. Maël’s role is not to summarize what the regulation says. It is to translate regulatory intent into the exact workflow configuration, risk matrix parameters, and audit trail architecture that passes scrutiny in each market. He has sat across the table from European regulators. He knows the gap between what the directive requires and what a BaFin or DNB examiner expects to see in a case file.
This is the model that makes compliance a pre-solved problem rather than a post-launch discovery. Below is why that matters, and why the alternative is harder than most expanding fintechs expect.
Why is every EU market its own compliance problem?
The EU’s Anti-Money Laundering Directives (AMLD) were designed as minimum harmonization instruments. Member states transposed them into national law, adding their own interpretations, stricter thresholds, and specific supervisory expectations. The result is that France, Germany, Belgium, the Netherlands, and the UK each operate under a distinct compliance regime, sharing the same vocabulary but diverging sharply on the operational details.
The table below illustrates how five key compliance parameters differ across the markets a mid-market fintech expanding in Europe will typically encounter first.
Each of these parameters needs to be correctly configured in your onboarding workflow before you process your first customer in that market. Not after your first audit finding. The five markets above are the most common first steps for European expansion. Ondorse covers a broader set of jurisdictions, see the full coverage map →
And it is about to get harder. Under the AMLR, the mandatory data set for Ultimate Beneficial Owners (UBOs) expands significantly: date and place of birth, full address including country, all nationalities, ID document number, and personal identification number all become compulsory fields. None of these are typically available in public registries. (consalty, July 2026) Obliged entities will have to collect them directly from the customer. On top of that, if a client is registered in another EU member state, the AMLR requires querying that member state’s own beneficial ownership register, which means either building registry connections in each country or asking the customer to provide the extract themselves. The EU-wide centralized registry platform with a common English interface is not expected to be available before mid-2027. Until then, every cross-border UBO verification is a country-specific operational problem.
What breaks when a fintech configures compliance in a new market from scratch?
Most expanding fintechs approach a new market the same way: assign the project to their Head of Compliance, engage a local law firm for a regulatory memo, then ask their engineering team to adapt the existing workflow. This process has consistent failure modes.
- The regulatory memo describes what the law says, not how the regulator actually audits. There is a gap between the text of the Wwft and what the DNB expects to see in a case file during a supervisory review. That gap is only visible to practitioners with direct supervisory experience.
- Document acceptance rules are not in the law. Whether a Dutch DigiD counts as valid identity verification, whether a German Handelsregister extract downloaded 45 days ago is still current, whether a Bulgarian UBO declaration signed by a local notary satisfies French ACPR standards for a cross-border onboarding: none of this is in the directive. It lives in supervisory guidance, precedent, and institutional knowledge.
- Workflow configuration lags legal advice. Engineering teams receive compliance requirements weeks after the legal memo and translate them imperfectly. The result is a workflow that approximates the compliance intent without matching the regulatory expectation.
- Risk matrices are copied from the domestic market. Sector risk weights, country risk scores, and EDD thresholds calibrated for a French or British portfolio do not transfer to a Belgian or German one without recalibration.
- AMLR creates counter-intuitive traps that no legal memo will flag. Under the incoming AMLR, low-risk verification scenarios are paradoxically stricter than standard CDD obligations in some configurations. The German Handelsregister is an accepted verification source under standard CDD, but not under the low-risk path. (consalty, July 2026) A compliance team relying on a regulatory memo will not catch this. A practitioner who has stress-tested the rules will.
- Audit trail is an afterthought. The first time a fintech realizes its audit trail does not document why a specific customer was auto-approved is usually during a regulatory review, not during configuration.
What does “audit-ready” actually mean, market by market?
Being audit-ready is not a state you achieve once before launch. It is an architecture decision.
For the ACPR in France, audit-readiness means: every decision (approve, escalate, reject) is logged with the rule set version that produced it, the risk score is justified against the fintech’s own risk classification document, and the EDD case file documents who made the final decision and on what basis.
For the BaFin in Germany, it means: the Transparenzregister query is logged even when it returns no result, the VideoIdent session is retained and retrievable, and the risk matrix explicitly addresses the sectors flagged in BaFin’s sectoral risk assessments.
For the DNB in the Netherlands, it means: the UBO graph is complete and cross-referenced against the Dutch UBO register, every deviation from standard Customer Due Diligence (CDD) is documented, and the workflow produces a case file that a DNB examiner can read without asking follow-up questions.
These requirements are not written in a single document. They are assembled from circulars, supervisory Q&As, enforcement decisions, and direct engagement with regulators. This is exactly the institutional knowledge Maël brings to every new market configuration on Ondorse’s platform.
Does AMLA 2027 change this calculation?
Not yet, and not as much as you might hope.
AMLA became operational on 1 July 2025 : Based in Frankfurt, it will directly supervise approximately 40 of the highest-risk EU obliged entities from 2028. For the remaining thousands of regulated fintechs, its immediate impact is indirect: it coordinates national supervisors, drafts Regulatory Technical Standards (RTS) that will define AMLR implementation, and raises the audit bar across member states.
The AMLR itself applies from 10 July 2027 : It is a directly binding regulation, meaning no national transposition step, and the same CDD rules and UBO verification standards will apply uniformly across the EU for the first time. That is genuinely significant.
But three realities prevent this from being a reason to wait:
- RTSs are still being published. The operational detail of AMLR implementation lives in RTSs that AMLA is drafting through 2026 and into 2027. (AML RightSource, 2026) Fintechs that defer configuration until the final RTS package is complete will not be ready by July 2027.
- AMLD6 still requires national transposition. The sixth Anti-Money Laundering Directive governs beneficial ownership registers and national supervisory structures. Country-level divergences in registry access, UBO register quality, and supervisory expectations persist through and beyond 2027.
- National supervisors remain primary until 2028. AMLA’s direct supervisory powers do not activate until 2028. Until then, every fintech’s primary regulatory relationship is with its national supervisor, under the national framework.
The AMLA transition period is not a compliance holiday. Fintechs that configure correct, audit-ready workflows per market today will be AMLR-ready by July 2027 without a redevelopment sprint. Those who wait will not.
How Ondorse absorbs this complexity so you do not have to
The architecture Ondorse has designed for multi-market deployments handles both the current fragmented reality and the coming AMLA harmonization. One contract, one platform, N countries. AML governance is centralized. Country-level configuration, language, document types, regulatory thresholds, registry connections, operates as a scoped override on top of the global framework, not as a separate logic stack.
‍
In practice, this means:
- A new European market does not require rebuilding the compliance layer from scratch.
- Each country configuration is validated by Maël against the local supervisory expectation before activation.
- When AMLA RTSs are published, the platform absorbs the changes. No client redevelopment required.
- New countries are activable within 2 weeks of request, with the compliance framework pre-mapped. The markets currently available on Ondorse's platform are listed on our global coverage map. New jurisdictions are added on request, with compliance configurations validated before activation.
A regulated payment institution launched in three EU markets, France, Belgium, and Bulgaria, under a single Ondorse contract. Each country's compliance configuration, document types, UBO verification rules, language settings, and EDD triggers, was pre-mapped and validated by Ondorse's compliance team before the first customer was onboarded. The institution's Head of Compliance did not write a single local regulatory requirement. Their IT department did not write a single line of code.
If you are planning a European market expansion and want to understand what audit-ready looks like for your specific regulatory context, the conversation starts here.
‍
Discover our latest guide
Everything you need to know about this subject
Heading
Subtextt
.jpeg)
%202%201.png)

