Remote onboarding for foreign customers: proving identity with legal value without a national eID
When a regulated firm opens an account with a customer who lives in the same country, the identity step is usually straightforward: a national eID does the heavy lifting. The picture changes the moment the person on the other side of the screen is a French national, a German company director, or an entrepreneur based outside the EU. Those national schemes simply do not exist for them, and remote onboarding for foreign customers turns into a real bottleneck for any bank, payment institution, or fintech that grows across borders. To be clear from the outset: this is about customer due diligence under anti-money-laundering rules, not about welcoming a new employee into a company.
European law does provide equivalent routes. An EU citizen can be recognized through their own notified eID under eIDAS. A customer from outside the EU can be identified with an identity document plus certified video identification. So the useful question is not "can I do this without a national eID", but "which identity assurance level does my risk profile and my sector actually require". Get that criterion right and a cross-border onboarding holds up, both operationally and in legal terms. As covered in our KYC compliance stack for fintech, identity is only one layer, but it is the layer where most remote programmes either hold up or fall apart.
This insight is part of our guide: KYC compliance stack for fintech
What remote identification for foreign customers means. It is the procedure by which a regulated entity recognizes a customer who is not physically present and who holds no national eID from the firm's own country, relying instead on the equivalent instruments set out in EU law: a notified eID issued by another member state, or a video identification session that checks the authenticity of the document and biometrically matches the face to it. The EBA Guidelines on remote customer onboarding (EBA/GL/2022/15, applicable from 2 October 2022) define the technical and organizational requirements: verifying that the document is genuine, confirming that the face matches the document, and putting controls in place against manipulation and forgery. The underlying legal foundation for recognizing electronic identity across borders is the eIDAS Regulation (EU) 910/2014, reinforced by the anti-money-laundering obligations of Regulation (EU) 2024/1624 (AMLR), including the requirement to retain evidence for at least ten years after the relationship ends.
The identity assurance levels of remote identification
The choice of method comes down to the identity assurance level it delivers. The eIDAS Regulation (EU) 910/2014 sets three tiers: low, substantial, and high, mapped onto levels 2, 3, and 4 of ISO/IEC 29115. The higher the level, the stricter the identity proofing and the stronger the binding between the real person and the identity they claim. For any relationship that carries meaningful money-laundering risk, plain OCR of a document rarely clears the bar: you need at least the substantial level.
| Assurance level | Typical method | What it guarantees | Recommended use |
|---|---|---|---|
| Low | Document OCR, basic selfie | Reduces the risk of obviously fake identities, without a strong person-to-document binding | Low-risk services, reduced thresholds, pre-checks |
| Substantial | Certified video identification, document plus liveness and biometric face match | Substantially reduces the risk of identity misuse or tampering | Banking and financial relationships, standard due diligence |
| High | Notified eID with strong binding to a state identity | The highest tier, equivalent to face-to-face recognition | High-risk relationships, public services, signing of significant deeds |
The three assurance levels, in ascending order. First, the low level: identity confirmed through light automated checks, suitable only where residual risk is limited. Second, the substantial level: identity verified online through certified video identification, document authenticity checks, and biometric verification with liveness, which confirms that a real person is genuinely present. Third, the high level: identity anchored to a state-notified eID, carrying the strongest guarantee. For standard anti-money-laundering due diligence, the practical benchmark is the substantial level, while low-level methods belong to reduced thresholds or a first filtering stage. This gradation restates the three assurance levels of the eIDAS Regulation (EU) 910/2014, mapped onto ISO/IEC 29115. Relying on OCR alone leaves a firm exposed to documented threats such as deepfake attacks on bank onboarding, which defeat the weakest visual checks.
Notified eID under eIDAS 1.0 for EU citizens
For a customer who is a citizen of another member state, the cleanest route is the notified eID of their own country. The eIDAS Regulation (EU) 910/2014 requires mutual recognition: a scheme notified to the European Commission must be accepted by the other member states for access to online public services. Notified schemes include Spain's DNIe, Germany's Personalausweis, Estonia's e-ID, and Belgium's itsme, and the exchange runs through national eIDAS nodes that bridge the service provider and the foreign scheme.
A notified eID from another EU member state is valid across the Union. Yes: the principle of mutual recognition set out in eIDAS Regulation (EU) 910/2014 obliges every member state to accept the electronic identity schemes notified by the others. Technically the exchange runs through the national eIDAS nodes, which act as a bridge between the service provider and the foreign scheme. A German customer therefore authenticates with their own national instrument, and the receiving firm gets identity attributes verified at source, carrying the assurance level declared by the scheme. This enables fully compliant remote identity verification that leans on an identity already issued by the customer's state of residence. Mutual recognition has been mandatory since 29 September 2018 for notified schemes, and no member state may refuse an electronic identity whose level equals or exceeds the one required for the service.
eIDAS 2.0 and the European Digital Identity Wallet (November 2026)
The framework is shifting with eIDAS 2.0, Regulation (EU) 2024/1183, which introduces the European Digital Identity Wallet. By November 2026 every member state must offer citizens a national wallet interoperable across the whole EU. The benefit for online identity verification is twofold: a single instrument available to every EU citizen, and selective disclosure of attributes, which lets a customer share only the data strictly needed, in line with data-minimization principles. Anyone designing a customer-recognition flow today should build toward this, much as they should factor in eIDAS 2.0 and the qualified electronic seal on the certification side.
Fallback for non-EU customers
A customer from outside the EU holds neither a national eID nor a notified scheme. The workable path is passport plus certified video identification: checking that the document is authentic, biometrically comparing the face to the document photo, and a liveness check that confirms a real person is in front of the camera. That is the substantial level, and it carries most of cross-border onboarding. A robust biometric comparison is decisive against synthetic identity fraud, which rose 378% in Europe over the past year according to industry figures, and it has to be paired with certification of the session so the result keeps its evidentiary value over time.
Choosing the method by sector and risk level
The practical rule is to match the method to the risk of the relationship and the constraints of the sector: a high-risk account calls for at least the substantial level with certified video identification, while a reduced-threshold service can start from lighter checks, provided residual risk stays under control. The table gives a working orientation.
| Sector | Recommended minimum level | Prevailing method | Risk note |
|---|---|---|---|
| Banks | Substantial / High | Notified eID or certified video identification | Enhanced due diligence for higher-risk relationships |
| Fintech and payments | Substantial | Video identification with document plus liveness | High cross-border volumes, strong fraud exposure |
| Insurance | Substantial | Video identification or eID | Material for life products and high-premium contracts |
| Telco | Low / Substantial | OCR with biometric check for SIM activation | Obligation to identify the subscriber |
| B2B and professional services | Substantial | Notified eID of the legal representative | Beneficial-ownership checks also required |
For fintechs and payment processors onboarding non-EU customers, TrueScreen produces certified, tamper-evident proof of the recognition session. That is what separates, years later, a check that was performed from a check that can be demonstrated, as shown in our work on video identification for customer due diligence.
Certifying onboarding with legal value: the role of TrueScreen
A compliant method solves half the problem. The other half is being able to show, if a session is ever challenged or inspected, that it unfolded exactly as declared. This is where TrueScreen comes in: it certifies the whole video identification session with forensic methodology, covering the substantial level and integrating a third-party QTSP's qualified seal and timestamp via API.
Remote onboarding with legal value. TrueScreen certifies the entire video identification session with forensic methodology, covering the substantial level and integrating a third-party QTSP's qualified seal and timestamp via API. Every document gathered during due diligence is captured and sealed at the moment of acquisition, with a digital signature, an eIDAS-compliant qualified timestamp, and forensic metadata such as GPS coordinates, device identifier, and cryptographic hash. Identity can be verified through an OTP SMS-authenticated digital signature or through biometric video verification with liveness, in line with the EBA Guidelines on remote onboarding. The result is certified, tamper-evident proof of the recognition session that supports the record-retention obligations under the AMLR. Given that the average annual cost of KYC operations exceeds 72 million dollars per institution, having defensible evidence cuts the risk of rework and disputes.
One clarification on scope: TrueScreen is not a QTSP or a certificate authority. It integrates the qualified seal of a third-party QTSP and adds certified capture at source, the piece often missing from a typical KYC compliance stack for fintech. The same logic extends to signing the deeds tied to the relationship, where the advanced electronic signature under eIDAS applies, and the flow can be embedded through the platform API.

