Reviewed October 1, 2026EBA guideline in force

EBA remote customer onboarding: make digital CDD risk-sensitive, testable, and reviewable.

The European Banking Authority's Guidelines on the use of remote customer onboarding solutions are final and in force, with an application date of 2 October 2023. They establish a common supervisory baseline for safe and effective remote customer due diligence across credit and financial institutions in scope of the Anti-Money Laundering Directive.

The guidelines are technology neutral. The control objective is not to deploy a particular biometric, video, eID, or document-verification product; it is to demonstrate that the institution's policy, process, chosen solution, security, oversight, records, and risk response work together effectively.

Current baseline

Remote onboarding is still customer due diligence—just performed without physical co-presence.

The EBA guidelines provide common standards for the development and implementation of sound, risk-sensitive initial customer due diligence policies and processes in remote onboarding. They apply to credit and financial institutions within the scope of the AML Directive framework.

The implementation question is therefore broader than whether an identity-verification product can recognize a document or face. Institutions should be able to explain the end-to-end control environment: what information is collected, how identity is verified, how risk changes the workflow, what evidence is retained, when automated results are rejected or escalated, and how the process is monitored after launch.

Policy and risk

Define where remote onboarding is permitted and how risk changes the process.

Remote onboarding policy

Document the customer types, products, jurisdictions, channels, identity methods, fallback paths, evidence, approvals, and escalation conditions for remote onboarding. Keep the policy tied to the institution's broader AML/CFT risk framework.

Risk-sensitive CDD

Define how customer, product, geography, delivery channel, fraud, identity, and other relevant risk indicators change verification depth, manual review, enhanced due diligence, or refusal.

Accountability

Name the owners for AML/CFT policy, onboarding operations, product, technology, security, privacy/data protection, vendor oversight, model or rules changes, quality assurance, and incident response.

Change control

Require review when the onboarding flow, verification provider, data source, identity method, device requirements, decision logic, customer population, or fraud pattern changes materially.

Identity evidence

Verify that the person and evidence presented are sufficiently trustworthy for the risk.

A remote process should make the identity-verification chain reviewable. Record what evidence is accepted, what attributes are captured, how authenticity/integrity are assessed, what data sources are used, how inconsistencies are handled, and which conditions trigger additional verification or human review.

Where the institution uses documents, electronic identification, video, biometrics, device signals, databases, or third-party identity services, define the role each signal plays in the decision. Avoid treating one technology as proof by itself when the overall risk model requires corroboration.

Build explicit failure paths for unreadable documents, mismatched attributes, suspected manipulation, repeated attempts, unsupported identity evidence, poor capture quality, unusual device/network behaviour, or other conditions that reduce confidence.

Tool assurance

Assess the onboarding solution before relying on its output.

Adequacy and reliability

Define acceptance criteria for the remote onboarding solution and test whether it performs reliably for the intended customer population, evidence types, channels, devices, and operating conditions.

Security

Protect the onboarding channel, exchanged data, credentials, session state, APIs, administrative interfaces, logs, and evidence stores. Monitor for tampering, replay, account abuse, automation, and unauthorized access.

Operational monitoring

Track verification failures, manual-review rates, suspected fraud, repeated attempts, provider outages, latency, customer abandonment, exceptions, false acceptance/false rejection indicators where measurable, and material control changes.

Fallback and continuity

Define what happens when the remote onboarding technology is unavailable, inconclusive, or unsuitable for the customer. Alternative processes should preserve CDD quality rather than bypass it.

Third-party onboarding services

Outsourcing technology does not outsource institutional accountability.

When a vendor supplies document verification, identity proofing, video, biometric, orchestration, data, or related onboarding capability, preserve enough oversight to understand how the service supports your CDD obligations.

Evaluate service scope, security, availability, evidence access, change notification, incident handling, data processing, subcontractors, quality controls, assurance results, performance metrics, and exit/transition arrangements. Define what changes the vendor can make without prior review and what evidence the institution requires after significant changes.

Make sure the institution can reconstruct a customer onboarding decision later even if the third-party service or contract changes.

Assurance trail

Build evidence that a supervisor or independent reviewer can follow end to end.

Control areaEvidence to retain or generate
Policy and risk assessmentApproved remote-onboarding policy, AML/CFT risk assessment, scope, risk tiers, decision rules, exceptions.
Customer flowJourney diagrams, accepted evidence, fallback/manual-review triggers, denial/escalation logic.
Solution assuranceSelection criteria, testing results, configuration baseline, known limitations, change records, validation.
Identity decisionCaptured attributes/evidence, verification outcomes, inconsistencies, manual decisions, reviewer identity.
Security and privacyData flows, access controls, encryption/security configuration, retention rules, incidents, security testing.
Third partiesDue diligence, contract requirements, service metrics, incidents, assurance evidence, change notices, exit plan.
MonitoringFraud trends, failure/review rates, exceptions, complaints, control issues, audit findings, corrective actions.
Implementation sequence

Move from applicability to tested operation.

1. Confirm applicability

Identify the legal entity, customer/product scope, national competent authority context, and related AML/CFT/data-protection requirements that govern the onboarding process.

2. Map the current journey

Document every system, person, evidence source, third party, decision, manual handoff, failure path, data store, and downstream KYC/monitoring dependency.

3. Assess control gaps

Compare current policy, risk logic, identity evidence, solution assurance, security, outsourcing, record keeping, monitoring, and exception handling to the EBA guideline outcomes.

4. Test realistic cases

Exercise low- and high-risk customers, poor-quality evidence, mismatches, suspected fraud, unavailable providers, manual escalation, customer abandonment, and onboarding-channel outages.

5. Verify evidence quality

Sample completed cases and confirm that an independent reviewer can reproduce why the customer was accepted, escalated, rejected, or subjected to additional due diligence.

6. Monitor change

Track EBA guidance, national implementation, AML/CFT framework changes, provider changes, fraud patterns, and material changes to the onboarding solution or customer population.

Primary sources

Use the EBA's current guideline page as the source of truth.

This guide supports control design and evidence planning; it is not legal advice. Confirm current EU and national AML/CFT requirements, supervisory expectations, data-protection requirements, and institution-specific obligations before relying on a particular control interpretation.

Continue learning

Related guides after EBA Remote Customer Onboarding

Follow the next implementation topic without returning to search.

Put this guide to work

Turn EBA Remote Customer Onboarding Guidelines: AML/CFT Implementation | Zeph Tech into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.