Remote identification in Belgium: Article 27
Belgium is the one market in this series where the statute itself names electronic identification as a way to verify identity — and then says almost nothing about how the session must look. There is no video-identification annex, no circular scripting an operator’s steps, no pre-authorised procedure. Article 27 of the Law of 18 September 2017 gives obliged entities a closed list of three source types they may confront identification data against, and makes the depth of that confrontation a function of the individual risk assessment. For a payments firm onboarding Belgian customers remotely the consequence is unusual: the easiest market in which to run a fully unassisted flow, and one of the harder ones in which to evidence that the flow was enough.
1. The framework, and who supervises it
Belgian anti-money-laundering law was rewritten by the Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the limitation of the use of cash. For payment and electronic money institutions it is supplemented by the Regulation of the National Bank of Belgium of 21 November 2017, approved by Royal Decree of 10 December 2017 and published in the Moniteur belge of 22 December 2017. The NBB is the AML supervisor for these firms; suspicious transactions go to the financial intelligence unit, not to the NBB.
Three articles carry the whole remote-onboarding question:
| Article | What it governs | Why it matters remotely |
|---|---|---|
| Art. 26 | Which data you must collect | The minimum set your capture screen must produce |
| Art. 27 | What you may verify it against, and how deeply | Three source types, plus the risk-graded depth rule |
| Arts. 30–31 | When verification must be complete | Whether money may move before it finishes |
2. What Article 26 makes you collect
Article 26, § 1 sets the standard: collect information that distinguishes the person from any other «de façon suffisamment certaine», taking account of the risk level under Article 19, § 2. Paragraph 2 names the minimum set.
- Natural person — surname, first name, place and date of birth and, as far as possible, address.
- Legal person — corporate name, registered office, the list of directors, and the provisions governing the power to bind the entity.
- Trust or similar legal arrangement — its name, the natural- or legal-person data above for trustees, settlors and any protectors, and the provisions governing the power to bind it.
Two qualifiers bite remotely: address is required «dans la mesure du possible», and for a beneficial owner so are date and place of birth — concessions worth encoding in the product.
3. Article 27 — the three permitted source types
Article 27, § 1 — in the wording inserted by the Law of 20 July 2020, in force since 15 August 2020 — requires entities to confront all or part of the Article 26 data against:
- 1° one or more documents probants or reliable and independent sources of information able to confirm the data;
- 2° where applicable, information obtained by using electronic identification means offered or approved within the service d’authentification in accordance with Articles 9 and 10 of the Law of 18 July 2017 on electronic identification, confirming the identity of persons online;
- 3° where applicable, information obtained via the relevant trust services provided for by Regulation (EU) No 910/2014.
The closing sentence is the one most easily lost: in doing so, entities must take account of the risk level identified in accordance with Article 19, § 2, first paragraph. The list says what you may use; the risk assessment says how much of it you need.
Route 2° points at the Belgian Federal Authentication Service, the state gateway for identification and authentication to public services, which also hosts the Belgian eIDAS node. Belgium has notified schemes built on it under Article 7 of Regulation (EU) No 910/2014 at level of assurance «high» — the eID-card scheme, and a mobile scheme whose notification was published in the Official Journal on 18 December 2019. That is the structural point: Belgium wrote a nationally notified, high-assurance electronic identification route into the AML statute itself rather than leaving firms to argue eIDAS equivalence from first principles.
Route 3° is broader and is often the one a cross-border firm actually uses: qualified trust services under eIDAS are available from providers established anywhere in the EU and appear on the EU trusted list. A Belgian customer verified through a qualified certificate issued in another Member State is verified under 3°, not under a foreign analogue of 2°.
4. The depth dial: §§ 2, 3 and 4
Article 27 then grades how much of the collected data must actually be verified.
| Paragraph | Trigger | What is required |
|---|---|---|
| § 2 | Default | Verify all data collected under Article 26, § 2 |
| § 3 | Risk assessed low | May reduce the number of items verified — what remains must still give sufficient certainty |
| § 4 | Risk assessed high | Verify everything, and satisfy yourself with heightened attention that the sources give a high degree of certainty |
Read together with § 1, this is a two-axis control, and most firms build only one axis: which sources they use. The second axis is how many data items you confront and how confident the confrontation must make you. A Belgian file that records the source but not the risk grade justifying the number of items verified is missing half the evidence Article 27 asks for.
5. The National Register route in Article 28
Article 28 is easy to misread as a fourth route, and it is not open to every firm. On the sole request of an obliged entity listed in Article 5, § 1, and solely to verify the identity of natural-person customers and their agents who are not present when they are identified, to verify beneficial owners and to update identification data, professional associations designated by the King may use the national register number, access data in the National Register of natural persons and copy what they consult. The obliged entity may then use and process what it receives.
So the statute contemplates an authoritative population-register check for the remote case, but mediated through a designated association rather than running firm to register. For a foreign payment institution it is usually unavailable, and verification rests on Article 27, § 1, 1° and 3°.
6. When verification must be finished
Article 30 sets the default: identification and verification are satisfied before entering the business relationship or executing the occasional transaction, and for an agent before that agent exercises the power to bind.
Article 31 is the derogation, drafted narrowly. An obliged entity may verify identity during the business relationship only in particular circumstances that its internal procedures list exhaustively, only where it is necessary not to interrupt the conduct of business, and only if both conditions are met:
- the individual risk assessment under Article 19, § 2 shows the relationship presents a low ML/TF risk; and
- verification is performed, in accordance with Article 27, «dans les plus brefs délais» after first contact with the customer.
Then the hard stop that governs product design. Where an entity in Article 5, § 1, 4° to 22° — where payment and e-money institutions sit — uses this derogation on opening an account, no transfer, withdrawal or remittance of funds or securities may be made from that account, by the customer or on their behalf, before identity has been verified. Article 33 closes the loop: where the obligations cannot be satisfied in time, the entity may not establish the relationship or carry out the transaction, and must terminate an existing one.
7. Three worked cases
Case A — an EU e-money institution passporting in with one unassisted flow
Facts. A firm licensed in another Member State runs a document-capture-plus-liveness journey built for a prescriptive market, and passports into Belgium.
Which rule applies. Article 27, § 1, 1°: the flow verifies against a document probant plus an independent source. Nothing requires an operator, a script or a recorded session.
What the practitioner does. Keeps the flow and adds two artefacts rather than a Belgian product: a written mapping from each Article 26, § 2 data item to the control that verifies it, and a rule routing a high-graded customer into the § 4 treatment, with the grade recorded. The overlay is evidential, not technical.
Case B — the corporate customer whose directors cannot be verified remotely
Facts. A Belgian company onboards through a self-service business journey. The legal representative completes identification; two of the four directors named in the constitutional documents are non-residents and complete nothing.
Which rule applies. Article 26, § 2, 2° requires the list of directors and the power-to-bind provisions as collection. Article 27, § 2 then requires verification of that data, subject to the § 3 reduction where risk is low.
What the practitioner does. Separates the two obligations. The director list comes from the constitutive documents and the public register; the power-to-bind provisions are recorded. Verification effort concentrates on the person actually binding the company and the beneficial owners. If the relationship is graded low risk, the § 3 reduction is invoked explicitly and in writing, naming which items were not verified and why the remainder still gives sufficient certainty. An unwritten reduction is indistinguishable from an omission when the supervisor reads the file two years later.
Case C — the account opened on Friday evening
Facts. A low-risk retail customer completes registration, but the document check returns an inconclusive result at 19:00. Commercial pressure is to open the account and resolve on Monday.
Which rule applies. Article 31, and only if internal procedures already list this circumstance. If not, Article 30 governs.
What the practitioner does. Two things, in order. Confirms that “inconclusive automated document check on a customer graded low risk” is an enumerated circumstance in the procedure — if it is not, the account does not open. Then applies the Article 31 restriction at the ledger level: inbound credits allowed, all outbound transfers, withdrawals and remittances blocked until verification completes. The control that fails audits is the one built as a review queue rather than a payment-level block.
8. How Belgium sits against the other markets
The national models divide by where the requirement is placed. Belgium adds a seventh shape: a closed statutory list of source types with a risk-graded verification depth, and no technique-level prescription at all.
| Market | Model | What a supervisor reads first |
|---|---|---|
| Belgium | Statutory source list, risk-graded depth | Risk grade and item-by-item verification |
| Spain | Pre-authorised procedure | Conformity to the specifications |
| Italy | Prescribed procedure in an annex | The scripted session |
| France | Combination of listed measures | Two measures, and what each verified |
| Germany | Equivalence, filled by circular | Security-feature and checksum checks |
| Netherlands | Policy-led | The policy and reliability assessment |
| Luxembourg | Risk compensation | The compensating measures |
The consequence runs against intuition: a flow built to the Spanish or Italian standard clears Article 27 on the technique axis but not automatically on the evidence axis, because the Belgian file must show the risk grade and the item-by-item decision a prescriptive market never asks you to articulate. Looking forward, Regulation (EU) 2024/1624 harmonises the due diligence obligations from 10 July 2027 and the European Digital Identity Wallet adds a further route — neither displaces this architecture, because Article 27’s dependence on the Article 19 risk assessment is the structure the EU package builds on.
9. FAQ
Does Belgium require video identification for remote onboarding?
No. The Law of 18 September 2017 prescribes no video-identification procedure. Article 27, § 1 lists the source types that identification data may be confronted against; how the session is conducted is left to the obliged entity, subject to the risk-graded depth requirement.
Can a foreign electronic identification means be used for a Belgian customer?
Yes, through Article 27, § 1, 3° — the relevant trust services under Regulation (EU) No 910/2014, which is not limited to Belgian providers. Route 2° concerns means offered or approved within the Belgian federal authentication service under Articles 9 and 10 of the Law of 18 July 2017.
May an account be opened before verification is complete?
Only under Article 31: the circumstance must be listed exhaustively in internal procedures, the relationship assessed as low risk, and verification must follow in the shortest possible time. For payment and e-money institutions, no transfer, withdrawal or remittance may be made from the account until verification is complete.
How much of the collected data must actually be verified?
All of it by default under Article 27, § 2. The number of items may be reduced where the individual risk assessment shows low risk (§ 3), provided sufficient certainty remains; where risk is high, everything is verified and the sources must give a high degree of certainty (§ 4). The National Bank of Belgium supervises this for payment and e-money institutions.
10. What to do, today
- Map every Article 26, § 2 data item to the control that verifies it, per customer type. That mapping is the Belgian evidence pack.
- Record the risk grade with each verification decision, and make the § 3 reduction an explicit written act.
- Enumerate the Article 31 circumstances exhaustively in the internal procedure, and implement its restriction as a payment-engine block, not a review flag.
- Re-read the corporate journey against Article 26, § 2, 2°: director list and power-to-bind provisions are collection obligations in their own right.
Related: Remote onboarding compared across the EU · The Netherlands — Wwft remote identification · France — R. 561-5-2 · Reporting suspicions in Belgium · The NBB periodic AML questionnaire


