Insights

AMLR Expert Insight: Is eIDAS Now the Default?

A practitioner’s read on Article 7(4) of the draft CDD RTS and why I’ve already lived this shift once before.

There is one line in the draft CDD RTS that quietly rewrites how remote onboarding works. Article 7(4) says that if you verify a customer remotely and you did not use an eIDAS-compliant method, you have to justify why. Read it slowly because that single sentence flips the default.

Today, a selfie plus a document check is just a normal choice, one option among many. Under this rule, the eIDAS-compliant method becomes the assumed standard, and everything else becomes an exception you defend on paper. That is not a tweak. It is a reversal. The default itself moves and once the default moves, every other question follows from it.

I’ll be honest about my lens. I’ve spent my career in compliance across the Gulf; Kuwait, Bahrain, the UAE, selecting verification vendors and owning onboarding risk. And what strikes me about Article 7(4) is that I have already lived this shift once. The EU is now writing into law something the UAE moved toward in practice: stop letting the customer hand you the document, and start pulling identity from the trusted government source.

Why I stopped trusting uploaded IDs

Here’s why.

A man onboarded remotely. Russian national, but he presented himself on a Serbian passport, because his Emirates ID was in Serbian. At the facial-recognition step, the system flagged a mismatch, and I don’t mean he’d gained or lost weight. The photo on the “Emirates ID” he uploaded had been manipulated. The tool caught it on the eyes: the eyes on the selfie did not match the eyes on the ID.

We had set the match threshold at 60%. He reached 55%. If he’d hit 60%, he would have passed. He didn’t, and when we looked closer, the man was sanctioned on his Russian passport. We rejected him and reported the case to the FIU.

Two things came out of that. First, I raised the accuracy threshold from 60% to 80%. Second, and this is the part that matters for eIDAS, we connected to ICP, the government portal, through UAE Pass. Rather than let the client upload an Emirates ID that could be faked, we take the identity from a trusted source and match the biometrics against it.

That is the same instinct behind eIDAS: the assurance should come from a government-backed method, not from whatever the customer chooses to show the camera.

Nobody’s drawn the line yet, so you have to!

The RTS doesn’t define when an eIDAS-compliant solution is “not available” or “cannot reasonably be expected.” People want a bright line. There isn’t one yet, and until there is, this comes back to self-control. As a licensed institution, it is your responsibility to have full confidence in your tools and to document how you got there:

  • Build the ladder. A semi-automated path on the way to full automation, with a manual fallback where you need one.
  • Draw the control. Calculate the risk, assess it, and decide how much you’ll accept.
  • Set it against appetite and tolerance. This I can do; this I cannot, always within the regulator’s requirements, never breaching them.

Until there is clarity and full automation, the honest truth is that your defense is the quality of your reasoning on file. Which raises the obvious question: what does that file actually contain?

There’s no bright line yet so until the regulator draws one, your defence is the quality of your reasoning on file. Write it down as you go, not after the fact.

The exception is biometrics

For me, biometrics is the anchor. If I cannot use the assumed method, the thing I can defend against is the biometric file because I can take it and run the comparison between what exists on the government side and what I captured. OCR of an ID is a fallback; it is not a defense. Biometrics is.

But I’ll name the elephant in the room: the thing you’re supposed to default to isn’t fully there yet, and facial recognition alone can be played.

  • If you lose weight, the camera may not recognise you, that was even an early iPhone problem, which is why they moved to the biometrics of the eye.
  • Dubai airports went further: instead of one smart gate where you look into a camera, you walk past four cameras, each capturing your biometrics; if one recognises you, you’re through.

That’s the direction: richer biometric capture, less reliance on a single document the customer uploads.

OCR of a document is a fallback. Biometrics matched against a trusted government source is a defence. Know the difference, the regulator will.

The wallet isn’t everywhere yet so stress-test, and expect incidents

EUDI Wallets only start rolling out from late 2026, and coverage varies by member state. How do you reconcile “eIDAS as default” with that? Honestly, at real scale, full reconciliation is difficult until an incident forces it. The tools give me comfort on more than 80% of onboarding; the rest, you test in segments when something happens.

That’s why, before I ever choose a tool, I stress-test it, I upload the entire range of scenarios, including the ones that should never happen. “Someone is clean in the morning and sanctioned in the afternoon” sounds impossible.

I have faced it twice.

A man onboarded normally on his Indonesian passport; screened clean, wallet ready, all perfect, around 10am. He held a second passport from North Korea that he wasn’t using. By noon he’d funded his wallet from his bank account; by around 2:30 he’d moved the money out to another account.

Then the call came: this man is sanctioned. I was surprised; he’d onboarded two hours earlier. We checked our systems, and we were right. At onboarding, he was clean. At 2pm, OFAC added him to the list.

That is the whole argument for continuous, near-real-time screening. My rule to vendors:

  • A name added to OFAC, the UN, a local or a central-bank list must reflect in your list within four hours – six at the outside.
  • After six hours, I started getting questions from the Central Bank.
  • Onboarding clean is not the end of the job. It is the start of monitoring.

Cleaning onboarding is not the finish line. A customer can be cleaned at 10am and sanctioned by 2pm which is why screening has to be continuous, not a one-time gate.

The part of the stack that strains most: UBOs

If you ask me which part of a remote onboarding stack will struggle hardest to clear this bar, it isn’t the individual. It’s the corporate, specifically the ultimate beneficial owners.

Onboarding exists to serve the risk assessment, and for corporations the most critical, most sophisticated part is identifying the UBOs. It’s also where everyone still struggles:

  • People don’t want to share UBO information. You ask to verify the UBO and you’re told you can’t…. “their ID is confidential.”
  • If it’s confidential, the UBO will never sit for facial recognition.
  • So you fall back to manual: a document that could be expired, improper, or fake.
  • And at the end of it, you still don’t truly know the UBO.

That is the gap the whole framework is trying to close and the one that will take the longest.

The individual is the easy part. The real strain is the corporate, proving who actually owns the company. That’s the gap that will take the longest to close.

Same rule, different paperwork

For a firm onboarding across several member states, does the burden-shift push toward a single standard or a per-country patchwork? Both, in different layers and yes, it’s messy. The UBO as a concept is a worldwide standard; the fundamental is one, everywhere. But each country has its own

regulations and its own documentation: here the national ID, there the passport, elsewhere a license. Standardise on the UBO logic; expect the paperwork to differ country by country.

The mistake I keep seeing

The one thing compliance teams are getting wrong on the eIDAS angle is mapping. They upload a document and fail to map it to the person’s actual role and responsibility if it’s a corporate, or to the person’s activity if it’s an individual.

The document is not the point. What the person is, and does, is the point.

What your board remembers

Most boards won’t read the RTS detail, and they don’t need to. What they need to understand is the regulatory landscape and the risk of not following it. My approach has always been to frame the risk of non-compliance; the implications, the enforcement, the punishment, because it’s tone from the top. I give them the risk landscape, show how it could affect the whole organisation, and bring the remediation plan and the controls I need approved.

That is the sentence a board remembers: not the article number; the risk of ignoring it.

Beyond 2027: the exception route stays open

Will the exception narrow further, or stay open? I think it stays open because the technology changes every day. Today we have eKYC. Tomorrow, KYC could be simpler: maybe we won’t need document verification at all, and we’ll rely on biometrics and facial recognition, with a verbal, voice-recognised consent instead of a signature. If the voice is verified and the consent is his, that’s the same person taking full responsibility. It would need legal change but that’s the future: leaning further into digital to make onboarding more efficient, not less.

What I’d tell any firm

  • The default has moved. eIDAS is the assumption, everything else is an exception you document.
  • Your defense is biometrics matched against a trusted government source, plus the quality of your reasoning on file.
  • Stress-test tools against the one-in-a-million case before you buy including “clean in the morning, sanctioned by afternoon.”
  • Near-real-time sanctions screening (four hours) and continuous monitoring are non-negotiable. UBOs are where you’ll struggle most.
  • Treat technology risk as a core part of your risk assessment and always keep a fallback until the technology stabilises.

Because that’s where the whole thing really sits. Onboarding, KYC, EDD, AML, it changes every day, driven by the risk of financial crime and, increasingly, by technology risk itself. Keep a proper way to control and mitigate: be ready to step back to the normal way, or push forward to a more sophisticated one, until the technology stabilises. Doing it the proper way is the whole job.

A closing note from Sherif

The default has moved, but the job hasn’t changed: know who you’re dealing with, and be able to prove how you know. eIDAS is the assumption now, everything else is an exception you defend on paper, with biometrics and the quality of your reasoning behind it.

Keep a fallback. Stress-test for the impossible. Never treat onboarding as the finish line. Do it the proper way, that is the whole job.

Sherif Afifi
Partner, Head of Compliance
https://www.linkedin.com/in/sherif-afifi-aml-compliance-expert/

Scroll to Top