SEPBLAC video-identification — remote onboarding in Spain
Spain does not let you invent your own remote onboarding flow — it lets you use one SEPBLAC has already authorised. Article 21 of the Regulation of Ley 10/2010 sets out four ways to open a business relationship with a customer who is not physically present, and only one of them is open-ended: procedures previously authorised by SEPBLAC. Two such authorisations are in force — videoconference and video-identification — and each carries a detailed list of minimum specifications that read like an inspection checklist, because that is what they become. This is the procedure, not the technology: what you may do, what you must record, and what invalidates the whole file.
1. The four routes into a remote relationship
Article 21(1) of Real Decreto 304/2014 permits obliged subjects to establish relationships or execute transactions by telephone, electronic or telematic means with customers who are not physically present, provided one of four circumstances applies. They are alternatives, not a hierarchy.
| Route | What it requires | Practical use |
|---|---|---|
| (a) Electronic signature | Identity established in accordance with the applicable electronic-signature rules | Needs an existing qualified certificate; low retail volume |
| (b) Certified copy | A copy of the Article 6 identity document issued by a fedatario público | Corporate files; too slow for app onboarding |
| (c) First payment test | The first inbound payment comes from an account in the same customer’s name at an entity domiciled in Spain, the EU or an equivalent third country | Common as a secondary control; funding must precede activity |
| (d) Authorised procedure | Another secure remote identification procedure previously authorised by SEPBLAC | Carries app-based onboarding at scale |
Route (d) carries the volume, and it is deliberately closed-ended. You cannot design a proprietary flow and self-certify it as “secure”: you either operate inside an authorisation SEPBLAC has already published, or you are outside Article 21 altogether.
2. The one-month rule that closes every remote file
Whichever route you use, Article 21(1) ends with a duty frequently missed in product design: in every case, within one month of establishing the non-face-to-face relationship, the obliged subject must obtain from these customers a copy of the documents necessary to apply due diligence.
That is a calendar obligation attached to the relationship, not to the identification event. A remote flow therefore needs a follow-up mechanism, an ageing report and a defined consequence when the month expires — typically restriction rather than closure, decided in advance and written into the manual. Firms that treat the video session as the end of the file discover this at the external examination.
3. What SEPBLAC has authorised — and what has lapsed
Three authorisations have been issued under Article 21(1)(d). Two remain the operative basis today; the third has been wound down, which matters because older internal manuals still cite it.
| Procedure | Signed | Effective from | Status |
|---|---|---|---|
| Inter-entity account-ownership confirmation within the national electronic clearing system | 22 May 2015 | 1 June 2015 | No longer available. SEPBLAC published notices ending its validity, the closing one dated 26 April 2023 |
| Non-face-to-face identification by videoconference | 12 February 2016 | 1 March 2016 | In force |
| Video-identification (unassisted) | 11 May 2017 | 1 June 2017 | In force |
That lapsed procedure was narrower than firms remember: one entity asked another — with which it knew the customer had a relationship — to confirm the customer’s identification data, only between participants in a specific clearing subsystem, with no movement of funds. SEPBLAC stated expressly that it satisfied only the formal identification obligation, leaving every other due-diligence, reporting, record-keeping and internal-control duty untouched. If your manual still lists it, it needs removing.
4. Videoconference: the assisted route
The 2016 authorisation covers procedures in which a trained operator conducts a live session with the customer. Its minimum specifications are the baseline the later authorisation builds on:
- usable only for customers holding the reliable identification documents listed in Article 6 of the Regulation — the DNI for Spanish nationals; for foreign nationals the residence card, foreigner identity card, passport or, for EU/EEA citizens, the official identity document issued by their home authorities;
- the obliged subject must implement the technical requirements establishing the document’s authenticity, validity and integrity and the correspondence between holder and customer;
- the customer must visibly display both the front and the reverse of the document during the session;
- the session must be recorded with date and time and retained under Article 25 of Ley 10/2010, with the customer’s express consent to the procedure and the recording, before or during it;
- a photograph or snapshot of both sides of the document must be obtained and retained, of a quality and sharpness permitting use in investigations or analysis;
- the process may not be completed where there are indications of falsity or manipulation, indications that the holder is not the customer, or transmission conditions preventing or hindering verification of either.
The last item is drafted as a prohibition on completion, not a risk factor to weigh: there is no “proceed with enhanced monitoring” option once one of those three conditions is present.
5. Video-identification: the unassisted route, and its extra cautions
The 2017 authorisation exists because firms wanted to remove the live operator. SEPBLAC’s reasoning is explicit: omitting the online interaction between prospective customer and agent, and replacing it with a subsequent review of the recording, carries higher risks that must be adequately mitigated — hence additional cautions on top of the videoconference baseline. Those additions decide whether an implementation is compliant:
- the process must be performed by the customer from a single device;
- images and sound must be transmitted to the obliged subject immediately, in digital format, unaltered and live — streaming — with immediate recording allowing sequential replay;
- files pre-recorded by the customer or by anyone outside the obliged subject are not admissible;
- each recording must be specifically and individually reviewed before any transaction is executed, with compliance documented for each recording;
- the snapshot of the document must meet investigation-grade quality, and mere frame captures from the video-identification process are expressly not valid for this purpose;
- measures must secure the customer’s privacy, the security of the transmission, and the authenticity and integrity of the recording.
Facts: an EMI launches Spanish onboarding with an unassisted video flow. The customer records a short liveness sequence on the app; the file uploads once complete; compliance samples 5% of files weekly against a checklist; document images are extracted from the best frames of the video.
What the rule says: three separate breaches. Upload-on-completion is not live transmission with immediate recording, and a locally captured file is close to the pre-recorded material the authorisation excludes. Sampling at 5% is not the required specific and individual review of every recording before transactions. And frame captures are expressly excluded as the retained document image.
What the practitioner does: moves capture to a streamed session recorded server-side; makes the individual review a blocking step in the account lifecycle so no transaction executes before it is completed and documented; and adds a separate document-capture step producing a still of both sides at investigation-grade quality. The journey is barely longer, but the review moves from a quality sample to a per-file control gate — which is what the authorisation requires and what the external examination tests.
6. Before you go live: risk analysis, documented testing, trained staff
Both authorisations impose three gates, and both apply prior to effective implementation of the procedure.
First, the specific risk analysis required by Article 32.2 of the Regulation. Article 32 requires internal-control procedures to rest on a documented analysis identifying and evaluating risk by customer type, geography, product, service, transaction and distribution channel; paragraph 2 requires review whenever a significant change could affect the risk profile and makes a specific documented analysis mandatory in defined situations. A new remote channel is one.
Second, the firm must document the procedure and test its effectiveness, recording the results in writing — and the authorisations state that implementation shall not proceed if the test results do not evidence effectiveness. That is a go/no-go gate with a written artefact, not a pilot report.
Third, the processes must be managed by staff with specific training consistent with the functions performed, evidenced under Article 39 of the Regulation, which requires an annual AML/CFT training plan.
7. The evidence file: recording, snapshot, retention
Retention runs to Article 25 of Ley 10/2010: documentation formalising compliance is kept for ten years and then deleted, and five years after the end of the business relationship or the occasional transaction it is accessible only to the firm’s internal control bodies, including technical prevention units, and where applicable to those handling its legal defence.
That access restriction has a design consequence that is easy to miss: a remote-onboarding archive cannot sit in a general operations folder that onboarding, fraud and support teams can browse for its whole life. Access has to narrow at the five-year mark, which means the retention system must be keyed to the relationship end date, not the file creation date — and must then delete at the ten-year point rather than holding indefinitely.
8. Screening before the first transaction
Both authorisations carry the same sequenced instruction: prior to the execution of any transaction, the obliged subject must verify that the customer is not subject to international financial sanctions or countermeasures, in the terms of Article 42 of Ley 10/2010.
Read alongside the requirement that each recording be individually reviewed before any transaction, that produces two blocking controls between a completed session and a customer’s first payment. Both belong in the account state machine rather than in a procedure document, or the first transaction will occasionally beat them.
9. Outsourcing — and what the external expert must say
Execution of both procedures may be outsourced, with the obliged subject retaining full responsibility. The video-identification authorisation goes further and defines the perimeter: references to obliged subjects in it include persons or entities acting under the direction of an obliged subject by virtue of a contractual relationship. Every specification therefore lands on the provider as if it were you, which is the right way to draft the schedule to the contract.
The second consequence is the audit. The external expert report under Article 28 of Ley 10/2010 must expressly address the adequacy and operational effectiveness of the procedure. Article 28 requires internal control measures and bodies to be examined annually by an external expert, with results in a written report describing the measures, assessing their operational effectiveness and proposing corrections; in the two following years that report may be replaced by a follow-up report confined to the adequacy of remediation, and the report goes to the board within a maximum of three months of issue.
Facts: a firm contracts a provider to run video-identification end to end and relies on the provider’s own annual assurance report.
What the rule says: outsourcing does not move the Article 28 duty. The firm’s own external expert report must pronounce expressly on the adequacy and operational effectiveness of the procedure as operated, including by the provider.
What the practitioner does: writes audit-access and evidence-production into the provider contract, gives the external expert the per-recording review documentation and the pre-implementation test results, and puts the report to the board inside the three-month window with the video procedure as a named scope item.
FAQ
Do we need SEPBLAC to approve our specific implementation?
No — both authorisations state that specific procedures established under them need no new authorisation. On inspection you must show that the implementation sits inside every minimum specification and that the pre-implementation risk analysis, testing and training evidence exists.
Can we identify a company by video-identification?
The video routes address the natural person in front of the camera. A legal person is identified under Article 6 of the Regulation on public documents evidencing existence, name, legal form, address, directors, articles and tax number — with a provincial Mercantile Register certification admissible — and the representative is identified separately.
Is the first-payment route in Article 21(1)(c) enough on its own?
It is one of the four alternative circumstances, so yes as a route into the relationship — but it is narrow. The first inbound payment must come from an account in the same customer’s name at an entity domiciled in Spain, the EU or an equivalent third country, and the one-month document duty still applies.
What invalidates a video-identification process?
Two situations, stated as invalidity rather than as risk: indications of falsity or manipulation of the identity document or of a lack of correspondence between the document holder and the customer; and transmission conditions that prevent or hinder verification of the document’s authenticity and integrity and of that correspondence.
Can we keep the identity-document image as a still taken from the video?
Not for video-identification. The authorisation requires a photograph or snapshot of both sides of a quality and sharpness permitting use in investigations or analysis, and states that a mere capture of frames from the video-identification process is not valid for that purpose.
Does the customer have to consent to being recorded?
Yes, expressly, and to the retention of the recording — before or during the process. Both authorisations also state that they are without prejudice to other legal duties, in particular tax, conduct and disclosure, consumer protection and personal data protection.
What to do, today
- Compliance officers: map the live flow line by line against the authorisation covering it and treat any specification you cannot evidence as a finding. Single-device, live-streaming and no-pre-recorded-file are where app implementations most often drift.
- Heads of onboarding: confirm the per-recording review is a blocking state in the account lifecycle, not a downstream sample, and that sanctions screening sits before the first transaction.
- Operations: check that a still of both sides is captured separately at investigation-grade quality and that nothing in the pipeline is silently substituting video frames.
- Product: build the one-month document-collection tail and its expiry consequence into the account states before launch.
- MLROs: retrieve the pre-implementation risk analysis and written test results for each procedure in use — they cannot credibly be created retrospectively, and the external expert report must speak to the procedure expressly.
Related: What is SEPBLAC · EBA remote customer onboarding guidelines · The SEPBLAC representative and Modelo F22 · EMI licence in Spain · BaFin video identification — remote onboarding in Germany · Remote onboarding compared across the EU


