Subscribe to the Non-Human & AI Identity Journal
Home FAQ Governance, Ownership & Risk How should financial institutions govern remote onboarding under…
Governance, Ownership & Risk

How should financial institutions govern remote onboarding under the new EU AML rules?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 11, 2026 Domain: Governance, Ownership & Risk

They should treat onboarding as an assurance and evidence problem, not just a verification step. Each flow needs a defined assurance threshold, a documented fallback path, and proof that the selected method can satisfy eIDAS-aligned expectations. The key is to connect KYC policy, fraud controls, and IAM governance before the regulatory deadline arrives.

Why This Matters for Security Teams

Remote onboarding under the EU AML rules is no longer just a customer experience problem. It is a control-design problem that sits at the intersection of fraud, identity proofing, audit evidence, and regulator-ready decisioning. Financial institutions need to show not only that a person was checked, but that the chosen onboarding method met an appropriate assurance threshold for the product, channel, and risk profile.

That changes the governance burden. FATF guidance on AML and KYC expectations makes clear that firms must apply risk-based customer due diligence, while identity assurance guidance from NIST SP 800-63 Digital Identity Guidelines helps frame how proofing strength, authentication, and binding evidence should be evaluated. For institutions already managing NHI and automation risk, the lesson is familiar: governance fails when the evidence trail is fragmented across teams, tools, and policy owners. NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives shows why auditability and lifecycle control matter when identity decisions must survive scrutiny.

In practice, many security teams encounter weak onboarding evidence only after a disputed account, fraud event, or regulator query has already forced reconstruction of the full decision path.

How It Works in Practice

Effective governance starts by classifying onboarding flows into assurance tiers. A low-risk account may allow remote document verification with liveness checks, while higher-risk customers or higher-value products may require stronger evidence, step-up controls, or a fallback to supervised review. The important point is that the institution should define what evidence is acceptable before the event, not after a reviewer has already approved the case.

Best practice is to connect three layers of control: KYC policy, fraud detection, and identity governance. KYC defines the regulatory purpose and minimum evidence. Fraud controls look for device anomalies, document tampering, synthetic identities, and repeated attempts. IAM governance ensures that access, approvals, and overrides are tied to named roles with traceable accountability. This is where a policy-as-code approach can help. Current guidance suggests that assurance decisions should be evaluated against documented rules, but there is no universal standard for exactly how every institution should express those rules.

  • Define assurance thresholds by customer type, channel, geography, and product risk.
  • Require a documented fallback path when automated proofing fails or confidence is insufficient.
  • Store the evidence package, reviewer action, and policy version used for the decision.
  • Test whether vendors and internal controls can support eIDAS-aligned expectations for identity assurance.
  • Review rejected, escalated, and overridden cases for pattern detection and control drift.

Operationally, this is where NHIMG’s Top 10 NHI Issues is relevant as a reminder that identity governance fails when lifecycle, visibility, and offboarding are treated as afterthoughts. The same pattern appears in remote onboarding when evidence is scattered and policy exceptions are not centrally governed. These controls tend to break down in high-volume onboarding operations that rely on multiple vendors, because evidence quality, reviewer consistency, and audit retention can diverge across channels.

Common Variations and Edge Cases

Tighter onboarding controls often increase friction, manual review load, and abandonment risk, so institutions must balance fraud reduction against customer conversion and operational capacity. That tradeoff is especially visible in cross-border onboarding, where document types, local identity schemes, and privacy rules can vary materially.

There are also edge cases where the standard answer becomes less stable. For example, a fully automated flow may be acceptable for one customer segment but not another. A simplified journey may be defensible for low-value products, yet the same process may fail under higher-risk scenarios if the institution cannot demonstrate proportionate assurance. Best practice is evolving around how much human review is enough, and current guidance suggests institutions should keep the fallback path explicit rather than assuming automation will always be sufficient.

Institutions should also be careful not to treat vendor attestation as the same thing as regulatory proof. A platform can support onboarding, but the firm remains responsible for the control outcome, the evidence trail, and the decision to accept residual risk. NHIMG’s Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is useful here because it highlights a broader governance truth: identity controls fail when lifecycle transitions and revocation paths are not built in from the start. For AML onboarding, that same discipline applies when customer evidence is incomplete, inconsistent, or later challenged.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNRemote onboarding needs accountable governance, evidence, and decision traceability.
NIST SP 800-63IAL/AALAssurance levels map directly to identity proofing strength and authentication confidence.
NIST CSF 2.0PR.AC-1Identity and access governance supports controlled onboarding and reviewer accountability.
OWASP Non-Human Identity Top 10NHI-07Evidence gaps and unmanaged exceptions mirror weak identity lifecycle governance.
CSA MAESTROG5Agentic workflows need policy, audit, and escalation paths for high-risk decisions.

Use tiered controls and human escalation for onboarding flows that exceed automation confidence.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org