By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: iProovPublished August 4, 2026

TL;DR: New EU anti-money laundering rules will make eID-based onboarding the default and push financial institutions toward stronger identity proofing, with the draft RTS shaping customer due diligence and digital onboarding requirements ahead of a July 2027 effective date, according to iProov. The real governance issue is not just compliance timing, but whether identity stacks can resist deepfakes and injection attacks without creating an assurance gap at onboarding.


At a glance

What this is: This is a policy and identity-verification analysis of the EU anti-money laundering package, with a key finding that onboarding will shift toward eIDAS-based assurance and stronger resistance to deepfake and injection attacks.

Why it matters: It matters because IAM, KYC, and fraud teams will need to align onboarding assurance, risk scoring, and regulatory evidence before current document and selfie checks become inadequate.

By the numbers:

  • In 2026, iProov Threat Intelligence reported a 1,151% increase in injection attacks targeted at iOS systems, a platform previously considered secure due to Apple’s closed–loop ecosystem.
  • A single bad actor opened 46 bank accounts with ABM AMRO, using stolen identity information and deepfakes to bypass the ID + Selfie identity controls.

👉 Read iProov's analysis of the EU AML rules and eIDAS onboarding changes


Context

The EU anti-money laundering package is a shift in identity governance as much as a regulatory update, because it changes how institutions must establish trust at onboarding. For IAM, KYC, and fraud teams, the core problem is no longer whether identity checks exist, but whether they are strong enough to withstand synthetic identities, deepfakes, and injection attacks.

The article frames eIDAS-compliant verification as the default route for remote onboarding, with physical documents and video-based checks becoming fallback methods that must be justified. That raises the bar for assurance, evidence, and certification discipline across financial institutions, crypto businesses, and other regulated onboarding flows.


Key questions

Q: How should financial institutions govern remote onboarding under the new EU AML rules?

A: They should treat onboarding as an assurance and evidence problem, not just a verification step. Each flow needs a defined assurance threshold, a documented fallback path, and proof that the selected method can satisfy eIDAS-aligned expectations. The key is to connect KYC policy, fraud controls, and IAM governance before the regulatory deadline arrives.

Q: Why do deepfakes and injection attacks change KYC risk models?

A: Because they let criminals create identities that look legitimate at the point of onboarding and then scale them across multiple accounts. Deepfakes challenge human review, while injection attacks can bypass the camera path altogether. That means risk models must account for adversarial capture integrity, not just the quality of the identity documents presented.

Q: What do teams get wrong about eIDAS-based onboarding?

A: The most common mistake is assuming that compliance with an identity method automatically means the entire onboarding process is ready. In reality, assurance level, certification status, fallback justification, and audit evidence all have to line up. If any one of those pieces is missing, the control may be operationally useful but still fail governance review.

Q: Who is accountable when AML controls fail?

A: Accountability should be explicit across the three lines of defence. Business teams own day-to-day execution, compliance owns policy and challenge, and audit independently tests whether controls work. If every function can point to another group when a failure occurs, the programme has no real accountability model.


Technical breakdown

eIDAS assurance and the new onboarding baseline

The draft rules make eID the primary mechanism for remote identity verification, tied to eIDAS levels of assurance. In practice, that means onboarding decisions will increasingly depend on whether an identity proofing method can demonstrate Substantial or High assurance, rather than simply whether it is convenient for the user. This moves the control point upstream into the verification step itself, where regulators can challenge the evidentiary basis for accepting an identity claim. The operational consequence is that assurance level becomes a governance decision, not just a product feature.

Practical implication: Treat eIDAS assurance as a policy control and map each onboarding path to a required assurance threshold.

Why deepfakes and injection attacks change identity proofing

Presentation attacks manipulate the human-facing part of the check, such as a fake document or a mask shown to a camera. Injection attacks are more severe because they bypass the camera path and insert synthetic images or video directly into the stream, often through virtual cameras or virtualized environments. That changes the defender’s problem from spotting a fake face to proving the integrity of the capture session itself. As AI-generated media becomes cheaper and more convincing, weak identity proofing becomes a fraud-enablement layer rather than a control.

Practical implication: Prioritise controls that verify capture integrity, not just face matching or document image quality.

Certification timing is now part of compliance risk

The article highlights a practical gap between regulation timing and implementation cycles. Certification for identity verification solutions can take months, which means choosing tools that are not yet aligned to required assurance levels can create a future noncompliance problem before the deadline even arrives. The issue is less about feature parity than about whether the organisation can produce auditable evidence that the chosen onboarding method meets the expected standard at the point of use. This is a classic governance lag problem, where procurement decisions precede regulatory readiness.

Practical implication: Build certification status into procurement and transition planning so onboarding controls do not drift ahead of compliance evidence.


Threat narrative

Attacker objective: The attacker seeks to convert false identity claims into trusted financial accounts that can be used for laundering, evasion, and other regulated abuse.

  1. Entry occurs when attackers use stolen identity data, synthetic identities, or deepfakes to enter remote onboarding flows as apparently legitimate applicants.
  2. Escalation happens when weak verification controls allow the attacker to open multiple accounts or bypass identity assurance gates across institutions.
  3. Impact is realised when fraudulent accounts are used for money laundering, terrorist financing, and sanctions evasion at scale.
  • MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
  • Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity proofing is becoming a regulated assurance problem, not a UX choice. The draft EU AML package shifts onboarding away from document-first convenience toward assurance levels that supervisors can inspect and compare. That changes the governance question from whether a flow is smooth to whether it can withstand adversarial identity fabrication. Practitioners should treat onboarding assurance as a control objective with evidence, not a design preference.

Presentation attack detection is no longer enough when injection attacks scale faster than remediation. Presentation attacks still matter, but they are increasingly overshadowed by attacks that bypass the camera path entirely and manipulate the capture stream. That creates a distinct governance gap because traditional selfie-based controls assume the camera sees the truth. Practitioners need to recognise that capture integrity and stream trust are now first-class identity requirements.

eIDAS-aligned onboarding will expose certification debt in existing identity stacks. The article makes clear that certification cycles can outlast regulatory timelines, which means many organisations are already carrying hidden compliance debt. When onboarding controls are not certified to the relevant assurance level, the organisation may have a process that works operationally but fails administratively. Practitioners should assume that procurement, legal, and IAM timelines are now tightly coupled.

Named concept: onboarding assurance gap. The gap appears when institutions accept identity claims using controls that cannot prove resistance to modern spoofing and injection methods. That is not merely a technical weakness, it is a governance mismatch between the evidence regulators expect and the proof the control can actually provide. Practitioners should test every remote onboarding path against that gap before the 2027 deadline.

The AML package will force tighter alignment between KYC, fraud, and IAM governance. Identity proofing can no longer sit in a separate operational silo while fraud teams react after account opening. The control environment now has to connect assurance level, risk scoring, and regulatory evidence in one lifecycle. Practitioners should expect onboarding governance to move closer to identity risk management than to pure verification tooling.

From our research:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • From our research: 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • That is why lifecycle discipline matters alongside onboarding assurance, and the NHI Lifecycle Management Guide is the right next resource for teams aligning governance to access change and revocation.

What this signals

Onboarding assurance gap: regulated identity proofing is converging with fraud and IAM governance, so teams should expect stronger evidence requirements across customer onboarding workflows. When assurance levels, certification status, and fallback justification are not aligned, the organisation may still pass operations tests but fail supervisory scrutiny.

The more persistent risk is governance lag. An institution can meet a functional onboarding need today and still carry compliance debt into the 2027 effective date if the chosen verification method cannot demonstrate resistance to modern spoofing and injection threats. Teams should prioritise method readiness, not just vendor capability claims.

For identity programmes that already manage secrets, privileged accounts, and lifecycle controls, this is a reminder that verification is only the first control point. The downstream challenge is to ensure that onboarding evidence, risk scoring, and revocation governance can be audited together across the customer identity lifecycle.


For practitioners

  • Map onboarding paths to assurance levels Document which customer flows require eID LoA High, which can use Substantial, and which fallback methods need supervisor justification. This creates a defensible control matrix for regulated onboarding.
  • Test for injection attack resilience Evaluate whether identity proofing controls validate capture integrity and stream authenticity, not only document image quality or face similarity. Include virtual camera and virtualised environment scenarios in testing.
  • Align certification with procurement timelines Require evidence of certification status before selecting identity verification methods that will be used after July 2027. Build transition plans for any control that is not already aligned to the required assurance standard.
  • Separate presentation and injection defenses Do not treat presentation attack detection as sufficient coverage for remote onboarding. Track both attack classes explicitly and retire flows that rely on legacy selfie checks alone.

Key takeaways

  • The EU AML package turns remote onboarding into an assurance-led governance problem, not a simple identity check.
  • Deepfakes and injection attacks expose the weakness of document-plus-selfie flows that cannot prove capture integrity.
  • Teams need to align assurance levels, certification timing, and audit evidence before the 2027 deadline creates compliance debt.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63ARemote identity proofing and onboarding assurance are central to the article.
NIST CSF 2.0PR.AC-7The post is about identity verification and access trust establishment.
NIST SP 800-53 Rev 5IA-2Identity verification and authentication controls underpin regulated onboarding.
ISO/IEC 27001:2022A.5.17Identity information and authentication controls are directly relevant to onboarding governance.
GDPRArt.32Identity proofing and onboarding systems process personal data and need protection measures.

Align onboarding verification methods with IA-2 and document assurance thresholds for each customer path.


Key terms

  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • eIDAS 2.0 High Level of Confidence: A formal assurance level used in European digital identity verification to indicate that a process meets high trust requirements for identifying people or businesses. In practice, it means the verification method must be specific, auditable, and suitable for regulated use cases where evidence matters.
  • Injection attack: An attack that inserts synthetic or manipulated data directly into the verification flow rather than fooling the sensor itself. For identity programmes, this is a control-path problem, because the attacker may bypass the visible presentation layer and exploit the software decision point.
  • Presentation Attack: A presentation attack is an attempt to fool a biometric system with a fake face, replayed video, mask, or other synthetic artefact. In practice, the control fails when it measures resemblance alone, because the attacker’s objective is to pass as the real user without actually being that person.

What's in the full article

iProov's full blog covers the operational detail this post intentionally leaves for the source:

  • A breakdown of eIDAS High and Substantial certification positioning for remote onboarding flows
  • Specific guidance on presentation attack detection and injection attack detection testing
  • The article’s view of how AMLR RTS drafts affect regulated onboarding design choices
  • Implementation context for financial institutions deciding whether to keep or retire fallback identity paths

👉 iProov's full post covers the draft RTS, anti-spoofing detail, and certification implications for regulated onboarding.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org