Remote onboarding of new customers: New rules starting in July 2027
A year might seem like a long time, but it’s not much for rebuilding processes for remote identification and verification of customers’ identity for anti–money-laundering purposes. In 2027, institutions will face two related reforms. First, the AMLR (Regulation (EU) 2024/1624) will begin to apply directly, along with the regulatory technical standards for due diligence of customers. Second, 2027 will be a key year for application of the changes under eIDAS 2.0 (Regulation (EU) 2024/1183), implementing the European Digital Identity Wallet (EUDIW). What will change for obliged entities?
An end to the patchwork of national regimes: Uniform rules under the AMLR and eIDAS 2.0
The “hard law” currently in force at the EU and national levels does not set clear, specific requirements for the process of remote identification and verification of customers under the AML regime. This gap is filled by instruments of soft law, but their substance and scope can differ greatly depending on the regulatory status of the obliged entity—even within a single jurisdiction.
In Poland, institutions subject to oversight by the Polish Financial Supervision Authority (KNF) must, for example, take into account guidance for onboarding of customers issued by the European Banking Authority, as well as positions issued by KNF.
For other obliged entities in Poland, such as notaries, tax advisers, accounting firms and real estate brokers, EBA and KNF guidelines are generally not binding, and communiqués from the General Inspector of Financial Information (GIIF) remain the touchstone.
This leads to a situation where the process of forming relations with new customers without the physical presence of the parties (i.e. remote onboarding) is subject to various requirements depending on which entity is doing the onboarding, and in which jurisdiction.
The AMLR and the regulatory technical standards (RTS) issued under the AMLR will change this logic, because they are directly applied acts of EU law. Starting next year, the conditions for admissibility of methods of remote onboarding will be imposed by hard law, not soft guidelines, and will generally be the same for all obliged entities.
The RTS drafted by the EU’s Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) pursuant to Art. 28(1) AMLR, involving measures for customer due diligence (CDD), cover both financial institutions and non-financial obliged entities—a major qualitative change from the existing model, under which the EBA CDD guidelines were addressed solely to the financial sector. Meanwhile, eIDAS 2.0 introduces the EUDIW, a new identification tool which obliged entities will have to accept in certain instances. Below we touch on the key changes in both of these areas.
Remote onboarding—eIDAS takes priority
The manner in which an obliged entity can verify its customers’ identity for AML purposes will follow directly from Art. 22(6)–(7) AMLR. In turn, the draft RTS clarify the specific conditions for such verification, separately for remote and in-person tracks.
In remote scenarios, the draft RTS introduce a distinct hierarchy.
The methods of first resort will be:
- Electronic means of identification meeting the eIDAS requirements for a mid (“substantial”) or “high” assurance level
- Qualified trust services within the meaning of eIDAS.
Other verification methods, such as via video or electronic identification means not meeting the eIDAS requirements for substantial or high assurance levels, will be a fallback option, but only upon fulfilment of the conditions set in the draft RTS. This is a major change from the current state, because now obliged entities are vested with a great amount of discretion in selecting their methods of remote identification and are not limited solely to the measures provided under eIDAS.
The priority for eIDAS methods stirred controversy at the stage of the EBA consultations on the draft RTS. Market participants argued that obliged entities should not be forced to use eIDAS solutions if other methods also comply with the EBA guidelines. The EBA recognised the soundness of these remarks, but pointed out that broader flexibility cannot be introduced without amending the AMLR itself, as Art. 22(6)(b) AMLR expressly and exclusively refers to measures provided in eIDAS in the context of verifying customers’ identity.
The AMLA adopted the draft RTS without significant changes in this respect, clearly sharing the EBA’s view that introducing a parallel identification track based on non-eIDAS methods, pursuant to a delegated act, would depart too radically from the actual wording of the AMLR.
Thus it is key to determine:
- When it is permissible to use alternative methods, and
- Under what conditions.
On the first point, the draft RTS provide that an alternative may be used if the method of first choice is “not available” or “cannot reasonably be expected to be provided.” But the draft does not explain what “cannot reasonably be expected” means in this context.
The key in this respect is set forth in Art. 7(4) of the draft RTS, stating that obliged entities using remote solutions shall be able to demonstrate to their competent authority that the remote verification solutions they use comply with this article, and why the customer could not be verified through means of electronic identification or qualified trust services because those means were not available or could not reasonably be expected to be provided. Thus the burden of proof rests on the institution. In practice this means that the onboarding track must be designed so that the obliged entity is in a position to demonstrate to the regulator that the conditions for use of alternative methods were met with respect to the given customer (or group of customers).
The detailed technical requirements for the conditions under which alternative methods may be used are set forth in Art. 7(3) of the draft RTS. First and foremost, the alternative solution must use “reliable and independent information sources.” In addition, it must provide six specific safeguards:
- Controls to ensure that the natural person presenting the customer’s identity document is the person pictured in the document
- Integrity of communications
- Confidentiality of communications
- Sufficient quality of images, video and/or data so that the person is unambiguously recognisable
- Automatic termination of the identification process in the event of technical shortcomings or any doubts regarding the identity of the person
- Retention of copies of the verified documents, time-stamped, in a format allowing for ex-post verification.
Certain general requirements may also arise under the AMLR itself or other types of provisions. For example, under Art. 76(5) AMLR, decisions by automated systems (including AI) must be “subject to meaningful human intervention,” and the customer must be entitled to an explanation of the decision and to challenge the decision.
Turning again to the preferred methods for remote identification of the customer, i.e. eIDAS methods, there are two more issues that should be noted.
First, neither the AMLR nor the draft RTS require that the means of electronic identification used in remote onboarding were issued under a notified electronic identification scheme within the meaning of Art. 9 eIDAS. Under the draft RTS, notified measures are not privileged in any way. Nonetheless, the current EBA and KNF guidelines award special preferences only to notified schemes: an institution using a measure with a “substantial” or “high” assurance level, issued under a notified scheme, may for example regard certain requirements with respect to pre-implementation assessment of the remote onboarding solution as being fulfilled.
In Poland, this status is held by only two means: the trusted profile (profil zaufany) for the “substantial” assurance level and the personal profile (profil osobisty) for the “high” assurance level. By contrast, the commonly used mid-level means, mObywatel, is not issued under a notified scheme and does not enjoy these preferences. Under the draft RTS, this difference would no longer be relevant: they require only fulfilment of a substantial or high level of assurance, without the requirement of notification, which will potentially equate the position of the mObywatel system with that of the trusted profile or personal profile.
But we must make an important reservation at this point. The EBA guidance on remote onboarding, as well as the analogous position of KNF, will not automatically expire as of the date when the AMLR begins to be applied. Under Art. 54(5) of Regulation (EU) 2024/1620 (establishing the AMLA), guidelines and recommendations by European and national regulators and financial intelligence units shall remain in force until they are superseded by guidelines and recommendations issued by the AMLA. Thus it cannot be ruled out that for some time, financial institutions will have to comply simultaneously with directly applicable RTS as well as still-current EBA guidance, although solutions apparently of equal weight under the RTS will carry differing compliance burdens in light of the guidance from the EBA and national regulators.
Second, the draft RTS establish a minimum set of attributes which must be possessed by electronic means of identification and qualified trust services for purposes of meeting the AMLR requirements for identification and verification of customers and beneficial owners. The problem is that many available qualified trust services and means of electronic identification do not contain the full set of required attributes (e.g. concerning the person’s place of residence or habitual abode). In this respect, Art. 32 of the draft RTS provides that the missing attributes must be obtained and verified through other means in line with Art. 22(6) AMLR. Apparently, this means that obtaining and verification of the missing identification data must also be conducted using the preferred methods, and alternative methods can be used only if the preferred methods are not available or cannot reasonably be expected to be presented by the client.
EUDIW—what will it mean for obliged entities?
The European Digital Identity Wallet is an electronic identification means introduced by eIDAS 2.0 which enables the user to selectively provide identifying data and to certify attributes to public and private entities either online or, in certain situations, offline (i.e. in the physical presence of the parties). The main aim of the EUDIW is to ensure the cross-border interoperability of electronic identification means within the EU, while ensuring that the user maintains full control over the scope of the disclosed data. An EUDIW will be issuable to both natural persons and legal persons. Every EU member state is required to make at least one digital identity wallet available by 24 December 2026. Work is currently underway on national implementation in Poland. The mObywatel app will not become the Polish digital identity wallet, but will continue to function as a separate tool.
The introduction of EUDIW raises three practical questions for obliged entities:
- Will the EUDIW suffice as a method of first choice in light of the draft RTS?
- Will obliged entities have to accept the digital identity wallets used by their customers?
- Will obliged entities be able to base their remote onboarding processes solely on this method?
Not all of these questions have obvious answers.
Can EUDIW be the method of first choice under the draft RTS?
The EUDIW is an electronic identification means issued in an identification system with a high level of assurance. Thus, at first glance, from the perspective of the draft RTS it would seem to fall into the first-choice category for remote scenarios. But the reality is more nuanced. The possibility of using a digital identity wallet as the first-choice option varies depending on the nature and scope of the information that can be obtained from the wallet. eIDAS 2.0 provides for two categories of information that can be obtained from the EUDIW in particular for purposes of remote onboarding of customers. These are “person identification data” and “electronic attestation of attributes.”
Person identification data. Commission Implementing Regulation (EU) 2024/2977, issued pursuant to eIDAS 2.0, distinguishes between two categories of person identification data: mandatory data and optional data. Mandatory data includes, for example, a person’s name, date of birth, and citizenship. However, the catalogue of mandatory data does not completely overlap with the minimum set of attributes required by the draft RTS with respect to electronic identification means and qualified trust services used for purpose of remote verification of identity. For example, the draft RTS require them to contain address details. By contrast, in the EUDIW these have the status of optional data, which means that not every EUDIW will ensure the storage and accessibility of these data. The draft Polish law introducing the EUDIW does provide for a catalogue of data broader than the EU minimum, but in its present form it also omits data on the place of residence or habitual abode. Consequently, at least at the current stage, the bundle of identifying data from the EUDIW itself may not fully suffice for conducting the remote onboarding procedure, and the missing attributes will have to be made up using other methods complying with Art. 22(6) AMLR.
Electronic attestation of attributes. The EUDIW not only stores and makes identification data accessible, but also allows the user to retain, store and manage electronic attestations of attributes. Under eIDAS, “attribute” is defined as a “characteristic, quality, right or permission of a natural or legal person or of an object” which can be attested in electronic form—for example, a person’s address, age, professional qualifications, or licences.
Here the situation is particularly complicated, because three categories of attestation of attributes may be linked with an EUDIW, depending on the entity issuing them:
- An electronic attestation of attributes issued by a non-qualified trust service provider
- A “qualified electronic attestation of attributes,” issued by a qualified trust service provider
- An “electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic source,” which, under Art. 45f(2) eIDAS, should “meet a level of reliability and trustworthiness equivalent to qualified trust service providers.”
From the perspective of the draft RTS, this division has important consequences. Among the three foregoing categories, only a qualified electronic attestation of attributes—as a qualified trust service—constitutes a first-choice method. In turn, a non-qualified attestation of attributes would constitute at best an alternative method. The situation of an electronic attestation of attributes issued by or on behalf of a public sector body responsible for an authentic sources is more complex: eIDAS 2.0 requires of them a level of reliability and trustworthiness equivalent to qualified trust service providers, but formally they are not qualified providers—and it follows from this that the attestations they issue do not constitute qualified trust services within the meaning of the draft RTS. This raises the question of how supervisory authorities and financial intelligence units will approach such attestations, and also whether there is a justification under the draft RTS for differentiating between these two categories of attestations, since, under eIDAS itself, they have an equivalent level of reliability.
In short, due to the optional nature of some of the identification data accessible in an EUDIW, which are required by the draft RTS, as well as the differentiated status of electronic attestations of attributes, it should not automatically be assumed that an EUDIW will in every instance constitute a fully self-sufficient method of first choice for the purpose of remote onboarding of customers under the draft RTS.
Will obliged entities have to accept an EUDIW?
Here as well, the answer is not entirely clear. Under Art. 5f(2) eIDAS, entities required by law or contract to use strong user authentication for online identification will be required to accept an EUDIW. This group does not fully overlap with the scope of obliged entities under the AMLR. Entities such as notaries, tax advisers, accounting firms and real estate brokers typically have no duty to use strong user authentication within the meaning of eIDAS—and from this perspective, based on eIDAS they are not required to accept an EUDIW at the user’s request. However, other obliged entities (e.g. banks and payment institutions) will in practice be required to accept an EUDIW starting from December 2027.
Significantly, those institutions that do decide to accept an EUDIW will first have to register as “relying parties.” Registration will require, among other things, a precise indication of what data the institution will demand from the wallet users—a relying party will not be allowed to demand that a wallet user provide data beyond this list without first updating the relying party’s registration. Thus obliged entities will need to precisely define, at the stage of planning the onboarding tack using the EUDIW, what data they will require from customers, and frame their registration application accordingly.
Can an institution base onboarding solely on an EUDIW?
Here the answer is clear. Under Art. 5a(15) eIDAS, use of a wallet is voluntary, and no entity can make possession of a wallet a condition for accessing a service. This means that an institution that decides to accept the EUDIW cannot also require that their customers use the EUDIW—but must also maintain other authentication paths alongside the EUDIW. Thus, the EUDIW can be one of the available onboarding channels, but not the only one.
Summary
The AMLR and the draft regulatory technical standards introduce a major qualitative change in the field of remote authentication of customers’ identity. For the first time, the rules for the permissibility of particular authentication methods will be provided under directly applicable EU law, and not under “soft law” instruments. At the basic level at least, the rules will be uniform for all obliged entities, regardless of their regulatory status or jurisdiction. Methods based on eIDAS have obtained the status of the method of first choice, and the use of other solutions, such as video authentication, will require demonstration to the supervisory authority that use of the preferred method was not available or could not reasonably be expected to be provided in the given instance.
Meanwhile, entry into force of the European Digital Identity Wallet adds another element to this picture which obliged entities will have to factor into their processes. Basically, the EUDIW falls within the track of preferred authentication methods, but its practical usefulness will depend on the scope of data accessible in the specific instance. Institutions deciding to accept the EUDIW will have to remember that for customers, use of the wallet is voluntary, and other onboarding tracks will also have to remain available.
The regulations discussed above are entering into force in stages, but July 2027 remains the key date for obliged entities. It’s essential to plan well in advance for the adjustments to institutions’ customer onboarding processes, to bring them into compliance with the new requirements.
Joanna Werner, attorney-at-law, Banking & Project Finance practice, New Technologies practice, Wardyński & Partners