Digital identity & remote CDD

How eIDAS 2.0, EUDI Wallets, and the AML Single Rulebook converge on remote customer identification — documents, timeline, and MLRO decision points.

eIDAS 2.0 and the AML Single Rulebook converge on remote customer identification. AMLR Art. 22(6)(b) requires obliged entities to accept substantial or high assurance electronic identification — including EUDI Wallet credentials — while AMLA drafts the operational detail in the Art. 28(1) CDD RTS. This guide maps the timeline, consultable documents, and MLRO decision points without duplicating a full eIDAS package.

AML-impact only. eIDAS governs digital identity across the EU economy. Here we focus on CDD, remote onboarding, and vendor due diligence — cross-link to AI Act & AML classification when biometric verification is involved.

Convergence timeline

Key dates where eIDAS wallet rollout meets AMLR CDD obligations.

20 May 2024

Passed

eIDAS 2.0 (Reg. 2024/1183) in force

eidas

European Digital Identity Framework applies — Member States begin wallet programmes; obliged entities should track wallet rollout in their markets.

24 December 2024

Passed

First wallet implementing acts in force

eidas

Core implementing regulations on wallet integrity, PID/EAAs, protocols, and certification enter into force — starts the 24-month clock for national wallet availability.

10 July 2026

Passed

AMLA Art. 28(1) CDD RTS deadline

aml

Draft RTS on CDD information requirements (consultation closed May 2026) should specify remote verification, eIDAS attributes, and reliable sources under Art. 22(6)–(7).

31 December 2026

154d left

Member State wallet availability (target)

eidas

Each Member State must offer at least one compliant EUDI Wallet within 24 months of the first implementing acts — practical remote ID option for EU-resident customers.

10 July 2027

345d left

AMLR Single Rulebook application

aml

Harmonised CDD under AMLR Arts. 20–22 applies directly — Art. 22(6)(b) requires acceptance of substantial/high eIDAS identification where used.

24 December 2027

512d left

Wallet acceptance obligations (indicative)

eidas

Certain public bodies and regulated private-sector relying parties must accept EUDI Wallets within 36 months of the first implementing acts — widens customer access to wallet-based ID.

Primary AMLA mandate

Customer due diligence — information requirements

The information obliged entities must collect and verify for standard, simplified and enhanced CDD, including sectoral adjustments.

Consultation closed · draftingPassed

Consultable documents

Level 1 eIDAS, implementing acts, EC toolbox, and AML hooks — curated for onboarding and MLRO teams.

AML Package hooks

AML Package hooks

AMLR Art. 22 — Identification and verification

Core CDD identification duties — Art. 22(6)(b) explicitly allows verification via substantial/high eIDAS electronic identification and qualified trust services.

AML relevance

Your primary Level 1 hook — remote onboarding policy must accommodate eIDAS means where customers can present them.

Open document

AML Package hooks

Draft RTS — Customer due diligence information requirements (Art. 28(1))

AMLA consultation (closed May 2026) on CDD fields, remote verification, and attributes required from eIDAS means and trust services.

AML relevance

Will operationalise Art. 22(6)–(7) — define minimum data, reliable sources, and non-face-to-face mitigations across the Single Rulebook.

Open document

AML Package hooks

AMLA mandate — Reliance on other obliged entities (Art. 50)

Future guidelines on relying on another obliged entity's CDD — including remote identification chains and allocation of responsibility.

AML relevance

Successor to EBA remote onboarding guidance — governs when you can rely on a partner's wallet-based or remote CDD.

View on AML Map →

eIDAS Level 1

eIDAS Level 1

Regulation (EU) 2024/1183 — European Digital Identity Framework

Amends eIDAS to establish the EUDI Wallet ecosystem — Member State issuance, cross-border recognition, and relying-party obligations.

AML relevance

Sets the legal basis for wallet-based identification that AMLR Art. 22(6)(b) cross-references via Regulation (EU) No 910/2014 assurance levels.

Open document

eIDAS Level 1

Regulation (EU) No 910/2014 (eIDAS) — as amended

Electronic identification assurance levels (substantial, high) and qualified trust services — the direct legal hook in AMLR Art. 22(6)(b).

AML relevance

Obliged entities must accept electronic identification means meeting substantial or high assurance when customers use them for identity verification.

Open document

Implementing acts

Implementing acts

Commission implementing regulations (Dec 2024 package)

First legally binding technical rules — wallet integrity, person identification data, electronic attestations of attributes, protocols, certification.

AML relevance

Defines what wallet-presented attributes and trust marks mean in practice for CDD evidence — watch AMLA RTS alignment on required attributes.

Open document

EC toolbox & ARF

EC toolbox & ARF

EC — European Digital Identity (EUDI) Regulation hub

Commission overview of wallet rollout, Cooperation Group, and implementation support for Member States and market participants.

AML relevance

Track national wallet pilots and acceptance timelines — affects when remote onboarding can rely on wallet credentials in your jurisdictions.

Open document

EC toolbox & ARF

EC — EUDI Wallet Toolbox process

Common Union Toolbox — Architecture and Reference Framework, reference implementation, and harmonised standards for wallet ecosystems.

AML relevance

Technical context for vendor due diligence on wallet integrations and qualified trust service providers used in KYC flows.

Open document

EC toolbox & ARF

EUDI Wallet Architecture and Reference Framework (ARF)

Living technical blueprint for issuers, wallets, and relying parties — informative, not a substitute for implementing acts.

AML relevance

Use when assessing onboarding vendors claiming EUDI compatibility — understand PID, attestations, and verifier responsibilities.

Open document

EBA predecessor

EBA predecessor

EBA/GL/2022/15 — Remote customer onboarding solutions

Current EU standard for non-face-to-face identification — pre-implementation assessment, data reliability, and risk-sensitive policies.

AML relevance

Applies until AMLA Art. 50 guidelines replace it — baseline for remote KYC governance during the transition to wallet-heavy onboarding.

Open document

eIDAS assurance levels

AMLR Art. 22(6)(b) references substantial and high assurance — not low.

Substantial assurance

Meets AMLR Art. 22(6)(b) threshold for electronic identification means — suitable for standard remote CDD where risk assessment supports it.

High assurance

Stronger eIDAS assurance — useful for higher-risk relationships or where supervisors expect enhanced remote verification evidence.

MLRO decision guide

Common remote identification scenarios as eIDAS wallets roll out alongside the Single Rulebook.

Customer presents EUDI Wallet credentials

EU-resident customer offers person identification data or attestations via a Member State wallet meeting substantial or high assurance.

  • Accept eIDAS means under Art. 22(6)(b) — do not insist on paper ID where electronic means suffice.
  • Map wallet attributes to Art. 22(1) fields; obtain any gaps via reliable independent sources.
  • Record assurance level, trust service provider, and verification timestamp in the CDD file.
  • Apply relationship-level risk (Art. 20) — wallet ID does not automatically justify SDD for higher-risk profiles.

No wallet or eIDAS means available

Customer cannot use EUDI Wallet (non-EU resident, wallet not yet live in Member State, or prefers traditional documents).

  • Fall back to Art. 22(6)(a) — identity document plus reliable independent sources.
  • Follow EBA/GL/2022/15 for non-face-to-face flows until AMLA Art. 50 guidelines land.
  • Document why eIDAS means were unavailable — AMLR recitals expect alternative paths where ID is not accessible.
  • Re-assess when national wallets launch in your customer jurisdictions.

Third-party remote onboarding vendor

You outsource or buy SaaS for video KYC, document capture, or wallet verification integration.

  • Obliged entity retains full AML/CFT responsibility — vendor contract must cover Art. 22 verification standards.
  • Pre-implementation assessment per EBA/GL/2022/15 before go-live.
  • If vendor uses biometric matching, run parallel AI Act classification (Annex III §1 high-risk).
  • Track draft Art. 28(1) RTS for harmonised attribute lists and reliable-source rules.

Relying on another obliged entity's remote CDD

Partner bank, EMI, or introducer performed wallet-based or remote identification that you rely on.

  • Current EBA reliance principles apply until AMLA Art. 50 guidelines.
  • Confirm partner's assurance level, data freshness, and scope of verification.
  • Define escalation when wallet attributes do not cover beneficial ownership (Art. 22(2)).

EBA predecessor (until AMLA Art. 50)

EBA/GL/2022/15Guidelines on the use of remote customer onboarding solutions

Common EU standards for non-face-to-face identification and verification — pre-implementation assessment of onboarding tools, data reliability, and risk-sensitive policies under the AMLD.

EBA → AMLA migration view →

Related AML mandates

Also see