The AMLA published draft RTS on several AML/CFT topics | verification of the identity

The Authority for Countering Money Laundering and Financing of Terrorism (AMLA) on 1 October published the press release on three draft regulatory technical standards (RTS) that they finalised and sent to the European Commission.

The topics are:

  • Business relationships and occasional transactions: how companies and professionals should distinguish between the two, and how to identify linked transactions, so that customer due diligence thresholds are applied consistently.
  • Customer due diligence: the information companies and professionals must collect and verify, including proportionate measures for lower-risk situations, non-face-to-face verification, electronic identification, and screening of politically exposed persons (PEPs), their family members and close associates.
  • Group-wide arrangements: minimum requirements for effective group-wide AML/CFT arrangements, including governance, risk management, internal controls and secure information sharing.

For members of the public the customer due diligence (‘CDD’) rules applied by companies with AML/CFT tasks like banks, the ‘OEs’, are of particular importance.

Verification of the identity
One of the elements of the RTS on CDD is verificaton by the OE of the identity of natural persons. Article 6 of the draft-RTS specifies which document may be used to verify the identity of a natural person, the main rule of paragraph 1 is:

1. For the purposes of verifying the identity of the natural person in accordance with Article 20(1), Article 22(6), point (a), and Article 22(7), point (a), of Regulation (EU) 2024/1624, the obliged entity shall use an identity document(s), passport(s) or equivalent document. A document shall be considered equivalent to an identity document or passport if it is issued by a designated authority in accordance with applicable the law and contains the following information:

(a) first name(s) (given name(s)) and surname(s) (family name(s)) and the place and date of birth of the document holder;
(b) the document’s number and date of expiration;
(c) a facial image and the signature of the document holder;
(d) security features to ensure authenticity.

Paragraph 4 specifically states that the EUDI wallet (the European identification wallet based on eIDAS) may also be used (marked by me):

4. Electronic identification means and relevant qualified trust services, as described in Article 22(6), point (b), of Regulation (EU) 2024/1624, shall be permitted to verify the identity of the natural person also in a face-to-face context.

Although the AMLA states that the EUDI wallet is not mandatory, it is likely that OEs will require their customers to identify with an EUDI wallet and will otherwise refuse to do business with them.

As far as I could see at a first glance, the AMLA makes no mention of the scope and nature of the data that OEs are permitted to record – such as biometric data (which may be derived from the secure element of the identity document) – nor of the period for which this data may be retained. These data could be used to commit identity fraud. Perhaps recording data is a matter for other secondary legislation.

It remains to be seen whether the verification of identity carried out as part of this CDD is secure.

If we are to ensure that the EUDI wallet remains a voluntary option, legislation is needed to oblige OEs to accept traditional identity verification at all times.

Onbekend's avatar

About Ellen Timmer

Weblog: https://ellentimmer.com/ ||| Microblog: https://mastodon.nl/@ellent ||| Motto: goede bedoelingen rechtvaardigen geen slechte regels
Dit bericht werd geplaatst in English - posts in English on this blog, Europa, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce en getagd met , , , , , , , , . Maak de permalink favoriet.

Plaats een reactie