Remote onboarding Ireland — CJA 2010 section 33
Six EU markets tell you how to identify a customer remotely. Ireland tells you what the result has to be and leaves the method to you — which is harder, not easier. There is no Irish video-identification annex, no pre-authorised procedure and no supervisory circular prescribing a flow. Section 33 of the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 is written in terms of outcomes, the Central Bank treats remote onboarding as a risk factor rather than a permitted procedure, and the operational detail arrives from the European Banking Authority. This piece sets out what section 33 actually requires, what the 2021 amendment changed, where the supervisor’s expectations sit, and three worked cases.
1. Ireland’s model: no prescribed procedure
Across the EU, four regulatory models for remote identification recur: a pre-authorised procedure approved by the financial intelligence unit; equivalence filled by supervisory circular; a procedure prescribed in an annex and scripted step by step; and a combination of measures drawn from a closed list.
Ireland fits none of them. The statute is technology-neutral: it states what verification has to achieve and what quality of source it must rest on, and stops there. No instrument names an acceptable remote procedure, and none forbids one. That is a fifth model — call it outcome-based — and it moves the burden. In a prescribed-procedure market you demonstrate conformity with the script. In Ireland you demonstrate that your own method was reasonable, which is a judgement you document rather than a box you tick.
2. What section 33 requires
Section 33 of the CJA 2010 carries both limbs of the obligation: when the measures must be applied and what they consist of.
On timing, section 33(1) requires a designated person to apply the measures prior to establishing a business relationship, prior to an occasional transaction or service, prior to any service where there are reasonable grounds to suspect money laundering or terrorist financing or to doubt the veracity or adequacy of documents, at any time the customer’s relevant circumstances have changed, and at any time another enactment or rule of law obliges the firm to contact the customer to review beneficial-ownership information.
On substance, section 33(2) requires identifying the customer and verifying identity on the basis of documents — whether or not in electronic form — or information that the designated person has reasonable grounds to believe can be relied upon to confirm the identity. Three things follow, each with a build consequence.
- Electronic form is expressly in scope. A document does not have to be physical to be a document. The statute settled that point rather than leaving it to guidance.
- “Or information” is a second, independent route. Verification need not rest on a document at all, provided the information source is one the firm has reasonable grounds to rely on. This is what makes register lookups, trust-service assertions and authoritative data sources available in Ireland without a separate permission.
- “Reasonable grounds to believe” is the test you must evidence. The assessment of the source, not just the output for one customer, is the record a supervisor asks for.
3. What the 2021 amendment changed
The Criminal Justice (Money Laundering and Terrorist Financing) (Amendment) Act 2021 made two changes that matter for a remote flow.
First, it broadened the sources of information that may be used to identify and verify a customer to explicitly include information from relevant trust services as specified in the eIDAS Regulation, Regulation (EU) No 910/2014. The Central Bank’s guidance records the change in those terms and adds that records evidencing identity may be retained in paper or electronic format. That is the clearest statutory signal available that trust-service evidence is an accepted input rather than a tolerated one.
Second, it added an express recording duty in the beneficial-ownership limb. Where the beneficial owner is a senior managing official, the designated person must take the necessary measures to verify that person’s identity and must keep records of the actions taken, including any difficulties encountered in the verification process. That converts an awkward verification attempt from an embarrassment into a required artefact. Remote flows generate them constantly — a document that would not read, a liveness check that failed twice, a customer who abandoned and returned — and the instinct to keep only the successful final attempt is what the provision cuts against.
4. The supervisor’s expectation: channel risk
The Central Bank of Ireland’s Anti-Money Laundering and Countering the Financing of Terrorism Guidelines for the Financial Sector — published 6 September 2019, revised 23 June 2021 — do not prescribe a remote procedure. They locate remote onboarding inside the risk assessment, under channel and distribution risk, and ask a specific set of questions.
| Question the guidelines pose | What it means for a remote build |
|---|---|
| Is the customer physically present for identification? | The starting classification. Remote onboarding is a risk factor to be assessed, not a mode to be permitted. |
| Has the customer deliberately avoided face-to-face contact other than for convenience or incapacity? | Distinguishes a customer using your only channel from one avoiding a channel that exists. In a digital-only firm the answer is structural: document it once, at business level. |
| Does the firm use reliable forms of non-face-to-face CDD? | The reliability assessment of the method itself — the firm-level judgement section 33(2) presupposes. |
| What steps has the firm taken to prevent impersonation or identity fraud? | The control question. It is asked about the outcome, not about a particular technology. |
The guidelines also expect firms applying a risk-based approach to maintain their own lists of documents they will accept in satisfaction of the identification and verification obligation, in accordance with sections 33 to 39, and to keep those lists under review in light of evolving processes, new technology and external factors. In a prescribed-procedure market that list is given to you; here you write it, own it, and have to show when it was last reviewed.
5. Where the operational detail comes from
The gap between an outcome-based statute and a buildable specification is filled by the EBA Guidelines on the use of remote customer onboarding solutions, EBA/GL/2022/15, applicable from 2 October 2023. They bind credit and financial institutions within the scope of the anti-money-laundering directive — payment and e-money institutions as squarely as banks — and they are themselves technology-neutral, setting out what any method must demonstrate.
The relationship between the three sources is worth stating explicitly, because teams keep looking for an Irish instrument that does not exist:
- Section 33 of the CJA 2010 gives the obligation and the standard of the source.
- The Central Bank guidelines give the risk-assessment questions the firm must answer and the documentation expectations around them.
- EBA/GL/2022/15 gives the pre-implementation assessment, the policy content, the ongoing monitoring duty and the document-authenticity and identity-matching expectations a build can be tested against.
Treated as one stack, that is a complete specification. Treated as three searches for “the Irish rule”, it produces the conclusion that Ireland has no requirements — the wrong answer, and an expensive one.
6. Section 33(5) to (8): the open-but-frozen account
Ireland answers explicitly the question most remote flows run into: can the relationship start before verification finishes?
Section 33(5) allows a firm to identify and verify a customer during the establishment of a business relationship where it believes there is no real risk of money laundering or terrorist financing. Section 33(6) then closes the door that subsection appears to open: the account may be opened before CDD is complete, but transactions may not be carried out by or on behalf of the customer or beneficial owner until it is. Section 33(8)(a) prohibits providing any service or carrying out any transaction while required documentation or information remains outstanding, and section 33(8)(b) requires the firm to take separate and distinct action to discontinue the business relationship in those circumstances.
The design that follows is specific: an Irish remote flow can create an account record in a pending state, but cannot let a payment in or out of it. The Central Bank’s guidance adds the corollaries — set a defined timeframe for completing verification, short enough that the customer can still be contacted and funds still returned to source; notify the customer during onboarding of the circumstances that would end the relationship; and implement a process that returns funds directly to the source they came from, taking care not to appear to legitimise them. Where CDD is not forthcoming, consider whether the circumstances themselves give rise to a reportable suspicion.
7. Three worked cases
Case one — reusing a passported flow. A group authorised elsewhere in the EU runs a video-identification flow built to a national annex in another market and plans to serve Irish customers on the same build. Rule: nothing in Irish law requires that annex, and nothing forbids it; section 33(2) asks whether the firm has reasonable grounds to believe the source can be relied upon, and the Central Bank asks what steps prevent impersonation. What the practitioner does: keeps the flow and writes the missing artefact — an Irish-facing assessment of why the method is reliable for the Irish customer population, which documents it accepts and how impersonation risk is addressed, cross-referenced to the EBA pre-implementation assessment. Outcome: one build, two evidence packs.
Case two — verification stalls after opening. A customer is onboarded under section 33(5) with verification outstanding, then stops responding. Forty days later the customer attempts an inbound transfer. Rule: section 33(6) prohibits transactions until CDD is complete; section 33(8)(a) prohibits providing the service while information remains outstanding; section 33(8)(b) requires distinct action to discontinue. What the practitioner does: confirms the pending state blocks the credit rather than holding it in suspense, triggers the internal timeframe that should already have expired, returns the funds to source, discontinues the relationship as a separate documented act, and assesses whether the pattern warrants a suspicious transaction report. Outcome: the common error — letting the account drift open and unverified because no transaction had yet been attempted — is avoided.
Case three — the acceptable-document list nobody owns. An Irish e-money institution is asked during an inspection for the list of documents it accepts for remote verification, and produces a screen from its onboarding system configuration. Rule: the Central Bank expects firms applying a risk-based approach to maintain their own list, in accordance with sections 33 to 39, and to keep it under review as processes, technology and external factors evolve. What the practitioner does: lifts the list into a governed document with an owner, a date, a review cycle and a recorded rationale per document type, each linked to the jurisdictions it is accepted for. Outcome: changes to the list become visible decisions rather than configuration drift.
8. What to do, today
- Stop looking for an Irish procedure. Make “Ireland is outcome-based” the opening line of the remote-onboarding section of your policy.
- Write the reliability assessment of each verification source, at firm level, against the section 33(2) standard. That is the document Ireland asks for and prescriptive markets do not.
- Own the acceptable-document list as a governed artefact with a named owner and a review date.
- Record failed and difficult verification attempts, not only successful ones, in line with the 2021 recording duty.
- Test that a pending account genuinely cannot transact, in the system rather than on paper, and that the verification timeframe actually fires.
- Map your build to EBA/GL/2022/15 clause by clause, keeping the pre-implementation assessment with the version of the flow it assessed. Regulation (EU) 2024/1624 converges the substantive CDD obligations across the EU, so that evidence is an input to the transition rather than work that will be discarded.
9. Questions people actually ask
Is remote onboarding allowed in Ireland?
Yes. Section 33(2) of the CJA 2010 permits verification on the basis of documents, whether or not in electronic form, or information the firm has reasonable grounds to believe can be relied upon. There is no requirement of physical presence.
Is there an Irish video-identification procedure to follow?
No. Ireland has no prescribed remote identification procedure, no pre-authorisation requirement and no annexed script. The statute is outcome-based and the supervisor treats remote onboarding as a channel risk factor.
Can we open an account before verification is complete?
Section 33(5) allows identification and verification during the establishment of the relationship where the firm believes there is no real risk of money laundering or terrorist financing. Section 33(6) prohibits transactions until CDD is complete, and section 33(8) requires the firm to stop providing services and to discontinue the relationship if the information remains outstanding.
Do the EBA remote onboarding guidelines apply in Ireland?
Yes. EBA/GL/2022/15 has applied since 2 October 2023 to credit and financial institutions within the scope of the anti-money-laundering directive, which includes payment and e-money institutions.
Can we rely on eIDAS trust services to verify identity?
The 2021 amendment broadened the sources that may be used to identify and verify a customer to explicitly include information from relevant trust services as specified in the eIDAS Regulation, and records may be kept in paper or electronic form.
Who decides which documents we accept?
You do. The Central Bank expects firms applying a risk-based approach to maintain their own lists of acceptable documents in accordance with sections 33 to 39 of the CJA 2010, and to keep those lists under review.
What do we have to record when a verification goes wrong?
Where the beneficial owner is a senior managing official, the 2021 Act requires records of the actions taken to verify identity including any difficulties encountered. Extending that discipline across the flow is good practice, because the difficulties are what a supervisor cannot reconstruct later.
Related: Remote onboarding compared — six EU markets · EBA remote customer onboarding guidelines · Risk Evaluation Questionnaire — Ireland’s AML return


