This document provides guidelines on the use of remote customer onboarding solutions, in response to the European Union's digital finance strategy. It aims to establish common standards for customer due diligence processes in a digital context, in order to reduce regulatory divergence among member states. The guidelines will come into force six months after publication and will apply from October 2, 2023.
The document "Guidelines on the use of Remote Customer Onboarding Solutions" is a guide published in 2022 by the European Banking Authority (EBA). It concerns the application of anti-money laundering and counter-terrorist financing (AML/CFT) rules in the context of remote customer onboarding by financial institutions. The scope covers innovative technological solutions used for initial remote customer due diligence (CDD), European regulatory requirements, associated risks, and best practices to adopt. The guide is addressed to competent authorities and credit and financial institutions in the European Union. It is based on Directive (EU) 2015/849 and comes into effect on 2 October 2023 (p. 1-12).
The guide responds to the European Commission's request, formulated in its Digital Finance strategy of September 2020, aiming to clarify and harmonize AML/CFT rules applicable to remote customer onboarding in the European Union. This topic is crucial because current regulatory fragmentation hinders innovation and cross-border provision of financial services, while exposing the single market to increased financial crime risks (p. 3-4). The main findings are that supervisory practices and expectations differ among Member States, and current rules lack precision on acceptable technologies and conditions for using remote solutions. The guidelines establish common European standards for robust, risk-adapted initial CDD processes and define the steps institutions must follow to select, assess, implement, and monitor their remote onboarding tools. They emphasize technological neutrality, allowing institutions to freely choose their solutions as long as they meet the requirements. The guide also specifies conditions for using qualified trust services and delegation to third parties, as well as IT security measures to adopt. Recommendations notably include conducting a rigorous prior assessment of solutions, implementing clear internal policies and procedures, continuous monitoring of tools, mandatory use of liveness detection in automated processes without human intervention, and ensuring the quality and integrity of collected data. These guidelines will enter into force on 2 October 2023, with an obligation for competent authorities to notify their compliance by 30 May 2023 (p. 3-23).
Faced with the rise of remote customer onboarding solutions, amplified by the COVID-19 pandemic, the European Commission identified a need for regulatory clarity on AML/CFT rules applicable in this digital context. Directive (EU) 2015/849 did not sufficiently specify acceptable technologies nor conditions for using remote solutions. The EBA, mandated to coordinate the fight against money laundering and terrorist financing in the European financial sector, therefore developed these guidelines to harmonize practices, reduce risks related to fraud and identity theft, and facilitate innovation while ensuring security. The objectives are to define common standards on initial remote CDD processes, criteria for assessing technological solutions, governance, monitoring and risk management requirements, as well as modalities for recourse to third parties and trust services. These guidelines complement other EBA guides on ML/TF risk factors, internal governance, AML/CFT compliance, outsourcing, and IT risk management (p. 4-7).
1. Internal policies and procedures: Institutions must establish clear, risk-adapted policies and procedures describing the onboarding solutions used, use cases, automated steps and those requiring human intervention, controls before the first transaction, as well as staff training. Governance must involve approval by management and supervision by the AML/CFT compliance officer (p. 12-13).
2. Pre-implementation assessment: Before adopting a solution, a comprehensive assessment must be conducted, including verification of completeness and reliability of collected data, analysis of ML/TF, operational and reputational risks, fraud detection and IT security tests, as well as a full process test. Solutions based on certified electronic identification schemes (eIDAS) or qualified trust services are considered to meet certain criteria (p. 13-15).
3. Continuous monitoring: Institutions must regularly monitor the quality and effectiveness of solutions, with periodic and ad hoc reviews triggered by risk changes, detected anomalies, or regulatory developments. Corrective measures must be planned in case of failures, including reassessment of customer relationships, enhanced due diligence, restrictions, or account closure (p. 14-15).
4. Acquisition and verification of information: Collected data must be up-to-date, legible, and sufficient to clearly identify the customer, with enhanced controls to counter risks related to location or VPN use. For legal entities, legal existence, legal representatives, and beneficial owners must be verified. Reproduced identity documents must be checked for authenticity, integrity, and quality, with automatic and manual controls, and the possibility to use data contained in electronic identity card chips (p. 16-19).
5. Authenticity controls: Solutions must allow verification of the correspondence between visible data, provided documents, and, where applicable, biometric data. Liveness detection is mandatory in automated processes without human intervention to prevent impersonation fraud. In processes with human interaction, the employee must be trained to detect suspicious behavior and use interview guides. Complementary measures such as verification of the first payment or sending random codes can enhance reliability (p. 19-21).
6. Use of third parties and outsourcing: Institutions must clearly define functions entrusted to third parties, ensure these comply with AML/CFT requirements, and maintain continuous control via reports, audits, or visits. Customer data stored by providers must be limited, secured, and accessible only to authorized persons (p. 21-22).
7. IT risk and security management: Solutions must use secure communication channels, robust cryptographic protocols, and offer a secure access point based on qualified certificates. Multi-use devices must guarantee a secure environment for software execution and data collection (p. 22-23).
8. Use of trust services and national identifications: Institutions may use qualified trust services or nationally recognized electronic identification processes, provided they assess their compliance with guideline requirements and implement specific measures to mitigate risks of impersonation, non-compliant identity, or fraud related to lost or stolen documents (p. 23-24).
9. Governance and proportionality: Governance of remote onboarding solutions is essential to cover all risks, including those related to internal management. Considering assessments already performed under the eIDAS regulation avoids redundancies and reduces administrative burden, while maintaining the final responsibility of financial institutions (p. 24-27).
10. Liveness detection: Liveness detection is mandatory only in automated situations without human interaction, as it significantly increases verification reliability. This requirement is proportionate and technology-neutral (p. 27-28).
11. Public consultation: The guide was submitted to public consultation, which allowed adjustment of certain points, notably the limited scope to new customers, clarification of policy and procedure requirements, integration of ETSI TS 119 461 standards, biometric data management, and confirmation that non-eIDAS solutions are possible under conditions (p. 29-43).
Established facts:
- Current regulatory fragmentation harms innovation and exposes to ML/TF risks.
- Demand for remote onboarding has strongly increased, notably following the pandemic.
- Technological solutions must be rigorously assessed before adoption.
- Liveness detection is a key element for automated processes without human intervention.
- Institutions must maintain continuous monitoring and corrective measures.
Hypotheses:
- Use of qualified trust services or recognized electronic identifications reduces certain risks.
- Adapted governance measures limit risks related to solution management.
Interpretations:
- Technological neutrality fosters innovation while ensuring compliance.
- Proportionality in requirements, notably regarding eIDAS solutions, is necessary to avoid excessive burdens.
Uncertainties:
- Rapid technological evolution may require future adaptations of the guidelines.
- The concrete impact on reducing fraud and ML/TF risks remains to be measured after implementation.
The EBA recommends competent authorities and financial institutions adopt these guidelines to harmonize remote customer onboarding practices in the EU. Institutions must:
- Implement clear internal policies and procedures, validated by management and supervised by the AML/CFT compliance officer.
- Conduct a rigorous prior assessment of technological solutions before implementation.
- Ensure continuous monitoring of solution quality, security, and compliance.
- Integrate liveness detection in automated processes without human intervention.
- Verify authenticity and integrity of collected documents and data.
- Rigorously manage relationships with third parties and outsourced providers.
- Use secure channels and protocols for communication and data collection.
- Assess and apply specific measures when using trust services or national identifications.
- Consider assessments performed under the eIDAS regulation to lighten requirements when relevant.
These guidelines will enter into force on 2 October 2023, with an obligation for authorities to notify their compliance by 30 May 2023, thus ensuring better coherence and security in remote customer onboarding within the European single market.
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.