Remote onboarding compared — six EU markets
Six markets, four fundamentally different regulatory models — and one onboarding flow cannot satisfy all of them without being built to the union of their requirements. Remote onboarding is the clearest example of an area where EU-level harmonisation has not reached the operational layer. The customer due diligence obligations are converging under Regulation (EU) 2024/1624; the question of how you may identify someone at a distance is still answered nationally, and the answers are structurally incompatible.
1. The four models
| Model | Market | How compliance is established |
|---|---|---|
| Pre-authorised procedure | Spain | The procedure must have been previously authorised by the financial intelligence unit. Two authorisations are in force — videoconference and video-identification — each with a list of minimum specifications |
| Equivalence, filled by circular | Germany | The statute permits any procedure of equivalent security to in-person document examination; the supervisor’s circular states what equivalence requires |
| Prescribed procedure in an annex | Italy | Either a document-plus-corroboration route with a policy-naming duty, or an annexed video-identification procedure scripting the session |
| Combination of listed measures | France | At least two of six listed measures, one of which is a nationally certified remote identity verification service |
| Risk compensation | Luxembourg | Specific measures to compensate the potentially higher risk, from an indicative list, judged against the firm’s risk analysis |
| Policy-led | Netherlands | Institutions must have policies for remote onboarding solutions, taking the EBA guidelines into account; no prescriptive national procedure |
2. What is common across all six
Four requirements recur, and building to them satisfies the intersection everywhere:
- A valid, official identity document, shown front and back, with the data legible.
- A recording or retained evidence of the identification, with consent obtained.
- Trained staff operating or reviewing the process, with training evidenced.
- An independent corroborating element — a first payment from an account in the customer’s name, a certification by another regulated institution, or a check against an independent source. This one appears in some form in every market in the table.
The first-payment measure is the most portable of these. It appears in the Spanish Article 21(1)(c) route, among the French six, among the Luxembourg four, and as a named example of Italian corroboration. A firm that builds it once has a measure it can rely on in four of the six markets.
3. Where they genuinely conflict
Three differences cannot be resolved by building to the strictest standard, because they are structural rather than incremental:
- Unassisted versus assisted. Spain authorises an unassisted video-identification procedure with a per-recording review before any transaction. The Italian annexed procedure is built around an operator who states their identity and conducts a script. A single fully automated flow does not satisfy the Italian route.
- Provider certification versus procedure conformity. France’s certified-provider route places assurance on the provider; Spain places every specification on the obliged entity. Selecting a certified provider does less work in Spain than in France.
- Counting versus judging. France requires at least two measures; Luxembourg requires measures adequate to compensate the risk. A firm meeting the French count may still need to justify adequacy in Luxembourg, and a firm with a strong Luxembourg risk analysis may still be short of two measures in France.
4. Building one flow for several markets
Facts: an e-money institution licensed in one Member State passports into all six and wants a single onboarding journey.
What the analysis produces: a common core — assisted or reviewable video capture with server-side recording, a still image of both sides of the document at investigation-grade quality, trained operators, and a first payment from an account in the customer’s name — plus market-specific overlays. Spain adds the per-recording individual review before any transaction and the one-month document-collection tail. Italy adds the eleven-step script and the policy naming of corroboration mechanisms. France adds the second measure and the record of which elements each measure verified. Germany adds the three-security-feature check, the machine-readable zone checksum and the one-time number.
What the practitioner does: builds the core once, treats the overlays as configuration rather than as separate products, and — critically — maintains a single mapping document showing, per market, which requirement each control satisfies. That mapping is the artefact that makes six supervisory conversations tractable, and it is the thing most multi-market firms do not have.
One planning note. The AMLR applies from 10 July 2027 and harmonises the customer due diligence obligations themselves, but the national rules on remote identification technique sit in national law and supervisory guidance that the Regulation does not displace wholesale. Expect the overlays to persist past that date, and expect AMLA guidelines to become the reference point where national texts are silent.
FAQ
Can one onboarding flow serve the whole EU?
A common core can, with market-specific overlays. The models differ structurally — pre-authorisation, equivalence, prescribed procedure, combination, risk compensation and policy-led — so a single undifferentiated flow will fall short somewhere.
Which single measure is most portable?
Requiring the first payment from an account in the customer’s own name at a regulated institution. It appears in the Spanish, French, Luxembourg and Italian frameworks in some form.
Will the AMLR harmonise this?
It harmonises the due diligence obligations from 10 July 2027. The technical rules on how identification may be performed remotely sit in national law and supervisory guidance, so the national overlays should be expected to persist.


