Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

EU AML onboarding rules: are your identity checks ready for 2027?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: New EU anti-money laundering rules will make eID-based onboarding the default and push financial institutions toward stronger identity proofing, with the draft RTS shaping customer due diligence and digital onboarding requirements ahead of a July 2027 effective date, according to iProov. The real governance issue is not just compliance timing, but whether identity stacks can resist deepfakes and injection attacks without creating an assurance gap at onboarding.

NHIMG editorial — based on content published by iProov: EU anti-money laundering rules and eIDAS-compliant onboarding

By the numbers:

  • In 2026, iProov Threat Intelligence reported a 1,151% increase in injection attacks targeted at iOS systems, a platform previously considered secure due to Apple’s closed–loop ecosystem.
  • A single bad actor opened 46 bank accounts with ABM AMRO, using stolen identity information and deepfakes to bypass the ID + Selfie identity controls.

Questions worth separating out

Q: How should financial institutions govern remote onboarding under the new EU AML rules?

A: They should treat onboarding as an assurance and evidence problem, not just a verification step.

Q: Why do deepfakes and injection attacks change KYC risk models?

A: Because they let criminals create identities that look legitimate at the point of onboarding and then scale them across multiple accounts.

Q: What do teams get wrong about eIDAS-based onboarding?

A: The most common mistake is assuming that compliance with an identity method automatically means the entire onboarding process is ready.

Practitioner guidance

  • Map onboarding paths to assurance levels Document which customer flows require eID LoA High, which can use Substantial, and which fallback methods need supervisor justification.
  • Test for injection attack resilience Evaluate whether identity proofing controls validate capture integrity and stream authenticity, not only document image quality or face similarity.
  • Align certification with procurement timelines Require evidence of certification status before selecting identity verification methods that will be used after July 2027.

What's in the full article

iProov's full blog covers the operational detail this post intentionally leaves for the source:

  • A breakdown of eIDAS High and Substantial certification positioning for remote onboarding flows
  • Specific guidance on presentation attack detection and injection attack detection testing
  • The article’s view of how AMLR RTS drafts affect regulated onboarding design choices
  • Implementation context for financial institutions deciding whether to keep or retire fallback identity paths

👉 Read iProov's analysis of the EU AML rules and eIDAS onboarding changes →

EU AML onboarding rules: are your identity checks ready for 2027?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Identity proofing is becoming a regulated assurance problem, not a UX choice. The draft EU AML package shifts onboarding away from document-first convenience toward assurance levels that supervisors can inspect and compare. That changes the governance question from whether a flow is smooth to whether it can withstand adversarial identity fabrication. Practitioners should treat onboarding assurance as a control objective with evidence, not a design preference.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: Who is accountable when AML controls fail?

A: Accountability should be explicit across the three lines of defence. Business teams own day-to-day execution, compliance owns policy and challenge, and audit independently tests whether controls work. If every function can point to another group when a failure occurs, the programme has no real accountability model.

👉 Read our full editorial: EU AML rules tighten identity verification for digital onboarding



   
ReplyQuote
Share: