Join our Newsletter — 33% off our NHI Course

Why do EUDI wallet pilots matter for customer due diligence?

They test whether verified identity data can be reused for onboarding without losing assurance or auditability. That matters because customer due diligence depends on trusted evidence, not just convenience, and regulated firms still need to prove how identity was established and accepted.

Why EUDI wallet pilots matter for onboarding and due diligence

eudi wallet pilots are important because they show whether a relying party can accept verified identity evidence from a wallet and reuse it in onboarding without weakening assurance, auditability, or control over the original proofing step. That is directly relevant to customer due diligence, where firms need more than speed, they need evidence they can defend to auditors and regulators.

The practical question is not whether a wallet can present data, but whether the firm can trust the source, understand the assurance level behind it, and preserve enough provenance to show how the identity was established. A pilot is where those assumptions get tested against real onboarding journeys, policy checks, and exception handling.

What pilots test that ordinary digital onboarding does not

Standard digital onboarding often optimises for form completion and identity match. EUDI wallet pilots test a narrower and harder question: can the organisation rely on verifiable credentials, selective disclosure, and reuse of identity attributes while still meeting customer due diligence expectations? That means checking whether evidence remains meaningful when it moves from the identity issuer to the relying party.

For regulated firms, this matters because customer due diligence is not satisfied by convenience alone. The control objective is to accept identity evidence only if it remains traceable, current enough for the use case, and tied to a defined trust framework. A wallet pilot exposes where process design, legal acceptance, or technical interoperability breaks down before the firm scales it.

Pilots also reveal whether onboarding logic can distinguish between identity proofing, attribute verification, and downstream risk screening. Those are related but not interchangeable steps. If they are collapsed into one experience, the firm may lose clarity about what was verified, by whom, and under what policy.

Why the evidentiary chain matters for regulated onboarding

Customer due diligence depends on evidence that can survive review, challenge, and retention. In practice, that means the firm should be able to show the credential source, the disclosure received, the acceptance decision, and the basis for any fallback checks. If the wallet introduces reusable identity data, the control question becomes whether the firm can still reconstruct the chain of trust later.

That is why wallet pilots matter even before broad production adoption. They expose whether the onboarding workflow can preserve assurance metadata, handle revocation or expiry cleanly, and support consistent treatment across product lines. The most useful pilots are the ones that test audit evidence, not just user experience.

They also force a decision on what the firm will accept as strong enough evidence for different customer types and risk tiers. A low-risk journey may tolerate more reuse, while higher-risk onboarding may still require supplementary verification. The pilot outcome helps define where reuse is safe and where manual review remains necessary.

Risk and Threat Considerations

EUDI wallet pilots create a concentrated test of trust, because a weak acceptance model can make identity reuse look stronger than it really is. If the relying party cannot validate the issuer, the credential state, and the provenance trail, onboarding may become easier to complete but harder to defend after the fact.

Failure mechanism: Weak issuer trust, poor credential verification, or incomplete audit capture can let reused identity data enter onboarding with less assurance than the firm believes it has, especially when disclosure is selective or workflows vary across channels.

Impact: The firm can accept the wrong customer, miss a mismatch between the asserted identity and the actual evidence, or fail an audit because it cannot prove how due diligence was performed and accepted.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) CDD onboarding needs verified identity establishment before access or account creation.
AU-2 — Event Logging Pilot onboarding must retain evidence of what identity data was accepted and why.
IA-5 — Authenticator Management Reusable wallet credentials still need lifecycle and validity controls to remain trustworthy.
Recommendation — Require verified identity before provisioning customer access or accounts. Log credential receipt, verification decisions, and exception handling for auditability. Validate credential lifecycle, expiry, and revocation before relying on reused identity data.
NIST SP 800-63 IAL2 — Identity Assurance Level 2 Wallet pilots are about reusing identity evidence while preserving sufficient assurance.
AAL2 — Authenticator Assurance Level 2 Pilots often depend on whether the presentation and verification method is strong enough for onboarding.
FAL2 — Federation Assurance Level 2 Cross-party identity reuse depends on the trust and assertion quality of the wallet flow.
Recommendation — Map wallet acceptance to the required identity assurance level before reuse. Use phishing-resistant authenticators where wallet-based onboarding depends on strong proofing. Validate federation assurance before accepting wallet-supplied identity assertions.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Wallet pilots change onboarding risk decisions, acceptance criteria, and evidence expectations.
PR.AA-05 — Identity Management, Authentication and Access Control The pilot tests whether identity evidence can be accepted and governed in onboarding.
Recommendation — Define risk thresholds for when wallet-based evidence may replace or supplement manual checks. Bind wallet acceptance to explicit identity and access control rules.

Practitioner Guidance

What to verify: Treat the pilot as a control test, not a product demo. Verify that the relying party can record the issuer, the credential type, the disclosed attributes, the acceptance decision, and any fallback checks in a form suitable for audit and investigation.

Decision rule: If the wallet flow cannot preserve evidentiary provenance end to end, use it only as an input to onboarding, not as a replacement for due diligence evidence. If it can preserve provenance, define which customer segments and risk tiers may rely on it first.

What practitioners underestimate: The hardest part is often not technical presentation, it is policy translation. Teams must align legal acceptance, operational review, and system logging so that reused identity data still answers the question, “What did we know at the time, and why did we accept it?”

Practitioner takeaway: The real value of EUDI wallet pilots is evidentiary, they prove whether reusable identity can reduce friction without breaking the chain of trust that customer due diligence depends on.