Remote onboarding in France — pick two of six
France does not authorise a remote onboarding procedure and does not test it for equivalence. It requires you to stack measures — at least two of them. Article R561-5-2 of the Code monétaire et financier sets out a list of additional measures that apply where the standard, face-to-face verification cannot be carried out, and obliges the firm to apply at least two. That is a structurally different model from Spain’s authorisation regime or Germany’s equivalence test, and it changes what a compliant French onboarding flow looks like.
1. The six measures
| # | Measure | Note |
|---|---|---|
| 1 | Obtain a copy of an identity document of the kind referred to in the primary identification article | The baseline; rarely sufficient alone, and never sufficient by itself here |
| 2 | Measures requiring an independent third party to verify or certify copies of official documents | Certification, not merely collection |
| 3 | Require the first payment to be made through an account opened in the customer’s name with an entity established in an EU or EEA state, or an equivalent third country | Constrains product design: funding must precede activity |
| 4 | Obtain directly a confirmation of the customer’s identity from a qualified third party | A confirmation received directly, not relayed by the customer |
| 5 | Use an identity-verification service certified by the French cybersecurity agency to a substantial level | The PVID route — see below |
| 6 | Collect an advanced or qualified electronic signature, or use qualified electronic registered delivery from a trust service provider | Anchored in the EU trust-services framework |
2. The PVID route, and why it is distinctive
Measure 5 points at a national certification scheme for remote identity verification providers — prestataires de vérification d’identité à distance, PVID — whose reference framework was published by the French cybersecurity agency on 1 March 2021. It is the closest thing in the French system to the Spanish model of a pre-authorised procedure, but the certification attaches to the provider rather than to the obliged entity’s procedure.
That distinction has a practical consequence. In Spain, a firm operating inside a SEPBLAC authorisation is responsible for meeting every specification itself. In France, selecting a certified provider discharges one of the two required measures on the strength of the provider’s certification — but the firm still has to choose and evidence a second measure, and it still bears the outcome.
3. Designing a French flow
Because the requirement is combinatorial, the design question is which pair to run rather than which procedure to adopt. Three pairings recur, with different trade-offs:
- Certified verification (5) plus first payment (3). Strong on identity assurance and adds an independent banking-system check, at the cost of requiring inbound funding before the relationship is usable.
- Certified verification (5) plus qualified electronic signature (6). Fully digital and fast; both measures depend on the customer already holding or being able to obtain credentials.
- Document copy (1) plus third-party certification (2) or direct confirmation (4). The traditional route; slowest, and the one most exposed to document-quality problems.
Facts: a payment institution passporting into France launches app onboarding using a certified remote identity verification provider, and treats that as sufficient.
What the rule says: the certified service is measure 5. Article R561-5-2 requires at least two of the listed measures, so a single measure — however strong, and however well certified — does not meet the article.
What the practitioner does: adds a second measure that verifies something the first does not. The first-payment route is the usual choice because it introduces an independent check from outside the identity stack, and because it is verifiable from the firm’s own transaction data rather than from a provider’s attestation.
4. Recording the choice
The article requires documentation of the measures implemented to be retained under the applicable retention rules. In practice the file should show, per customer or per clearly defined population: which two measures were applied, the evidence produced by each, and which identification elements each one verified — because that last point is what demonstrates the combination was adequate rather than merely numerous.
Firms should also read the ACPR’s guidelines on identification, verification of identity and customer knowledge alongside the article. They set out the supervisor’s expectations on how the measures are applied in practice, which is where a control that satisfies the text can still fall short of the expectation.
FAQ
Is one certified identity provider enough?
No. Article R561-5-2 requires at least two of the listed measures. A certified remote identity verification service is one of them.
Does France authorise specific procedures like Spain?
No. France certifies remote identity verification providers through the PVID scheme and otherwise requires a combination of listed measures. There is no equivalent of a procedure-level authorisation.
Can the first payment come from anywhere?
It must come from an account opened in the customer’s name with an entity established in an EU or EEA state, or in an equivalent third country.
Related: Remote onboarding compared across the EU · Remote onboarding in Spain · EBA remote onboarding guidelines


