AI Regulation Tracker · EBA · Guidance

What does EBA/GL/2022/15 (remote customer onboarding) say about AI in banking?

Published Nov 22, 2022 · Last reviewed Oct 5, 2026

EBA/GL/2022/15, the EBA's Guidelines on the use of Remote Customer Onboarding Solutions, were published on 22 November 2022 and have applied since 2 October 2023. They set out the steps credit and financial institutions must take when choosing and running remote tools to meet their customer due diligence obligations under Article 13(1)(a)-(c) of the AML directive (Directive (EU) 2015/849). The Guidelines are technology-neutral and do not name artificial intelligence, but they reach AI-based identity verification: they require a pre-implementation assessment, ongoing monitoring, strong and reliable algorithms for biometric matching and liveness detection in unattended onboarding, and specific controls when the process is outsourced to a provider. A bank that uses a vendor for selfie, document or video verification should treat these Guidelines as the supervisory baseline until the EU AML Regulation's own rules apply from 10 July 2027.

OFFICIAL TEXT: eba.europa.eu ↗ · IN FORCE · EBA

DocumentEBA/GL/2022/15 (remote customer onboarding) — EBA/GL/2022/15 Guidelines on the use of Remote Customer Onboarding Solutions under Article 13(1) of Directive (EU) 2015/849
Issued byEuropean Banking Authority
TypeGuidance
StatusIn force
PublishedNov 22, 2022
EffectiveOct 2, 2023
Applies toCredit and financial institutions as defined in Article 3(1) and 3(2) of Directive (EU) 2015/849 (the AML directive) that onboard customers remotely, and their competent authorities; applies to banks directly
Official sourceeba.europa.eu ↗
Use casesAML / KYC · Fraud detection · Third-party & vendor AI · Data & privacy · Cybersecurity

What are the key points of EBA/GL/2022/15 (remote customer onboarding)?

  • Date and status: published 22 November 2022 as the EBA final report; apply from 2 October 2023. Issued under Article 16 of Regulation (EU) No 1093/2010, so competent authorities must say whether they comply or intend to comply.
  • Scope: steps institutions take when adopting or reviewing solutions to comply with Article 13(1) points (a), (b) and (c) of Directive (EU) 2015/849 when onboarding new customers remotely, and when relying on third parties under Chapter I, Section 4 of that directive.
  • Governance and policies (paragraphs 9-12): written policies and procedures for remote onboarding, with management body approval of the policy and the ability to demonstrate it to the competent authority.
  • Pre-implementation assessment (paragraphs 13-16): assess adequacy, completeness and accuracy of data, impact on ML/TF, operational, reputational and legal risks, test for impersonation fraud and ICT security risks, and run end-to-end testing before use.
  • Ongoing monitoring (paragraphs 18-22): regular and ad hoc reviews of the quality and accuracy of data collected, with defined triggers and remedial actions; also applies to fully automated solutions.
  • Identity matching and liveness (paragraphs 38-41): where biometric data is used, ensure it is sufficiently unique, use 'strong and reliable algorithms' for matching, apply additional controls when confidence is insufficient, and in unattended onboarding perform liveness detection and match photographs or video to the document image.
  • Document checks (paragraphs 33-37): where OCR or MRZ features read documents automatically, the institution must ensure that they capture information accurately and consistently.
  • Outsourcing and third parties (paragraphs 46-49): decide in policy which functions are performed by the institution, third parties or outsourced providers; for outsourced CDD, apply the EBA outsourcing guidelines, monitor the provider through reporting, visits or testing, and keep control of stored customer data.
  • ICT and security (paragraphs 50-53): manage ICT and security risk of the onboarding process, including where outsourced to group entities, using secure channels and cryptographic protocols and, for multi-purpose devices, a secure execution environment.

What did EBA/GL/2022/15 (remote customer onboarding) change for banks?

Before the Guidelines, the AML directive did not say what was acceptable in a remote setting, and supervisory expectations differed across Member States. EBA/GL/2022/15 set a common EU standard for remote identity verification, including for biometric and automated tools, so banks buying AI-enabled identity checks must show they assessed, tested and monitor the tool. They remain the reference until the AML Regulation (EU) 2024/1624, which applies from 10 July 2027, and the technical standards and AMLA guidelines it calls for take over; No replacement or repeal had been identified as of 5 October 2026.

What does EBA/GL/2022/15 require of banks that onboard customers remotely, including with AI-based tools?

EBA/GL/2022/15 requires a bank that onboards customers remotely to set written policies approved at management level, assess any remote solution before use, monitor it continuously, and verify identity with controls proportionate to the ML/TF and fraud risk. For biometric and automated verification it expects strong and reliable matching algorithms, liveness detection in unattended journeys, reproducible document checks and escalation to a face-to-face check when evidence quality is poor. If a provider runs the process, the bank keeps the CDD responsibility, applies the EBA outsourcing guidelines and monitors the provider. The Guidelines have applied since 2 October 2023 and do not mention AI explicitly, but they are the standard supervisors apply to AI-enabled identity verification.

RuleAuthorityWhat it requiresApplies
Paragraphs 9-12 — Policies, procedures and governanceEBAMaintain written remote onboarding policies and procedures, approved by the management body and demonstrable to the competent authority.Applies from 2 Oct 2023
Paragraphs 13-16 — Pre-implementation assessmentEBABefore adopting a solution, assess data adequacy, ML/TF and operational risks, impersonation fraud and ICT security risks, and carry out end-to-end testing.Applies from 2 Oct 2023
Paragraphs 18-22 — Ongoing monitoringEBAReview the quality, completeness and accuracy of onboarding data regularly and on defined triggers, including for fully automated solutions, and set remedial actions.Applies from 2 Oct 2023
Paragraph 39 — Biometric dataEBAEnsure biometric data is sufficiently unique to link to one person and use strong and reliable algorithms to match the data from the document to the customer.Applies from 2 Oct 2023
Paragraph 41 — Unattended onboardingEBAEnsure image quality and timing, perform liveness detection, and use strong and reliable algorithms to match the live photograph or video to the identity document.Applies from 2 Oct 2023
Paragraph 40 — Insufficient evidenceEBAInterrupt and restart the process, or redirect to face-to-face verification, when evidence quality prevents reliable remote checks.Applies from 2 Oct 2023
Paragraphs 46-49 — Third parties and outsourcingEBAAllocate functions between the institution and providers in policy, apply the EBA outsourcing guidelines, and monitor the provider and data it stores.Applies from 2 Oct 2023
Paragraphs 50-53 — ICT and security riskEBAManage ICT and security risks of the onboarding process, use secure channels and cryptographic protocols, and secure the customer-side software environment.Applies from 2 Oct 2023

The Guidelines were requested by the European Commission to address divergent national supervisory expectations on remote customer due diligence. They are addressed to the AML directive's obliged entities, so they apply to banks, payment institutions and other financial institutions across the EU, and they leave the choice of technology to the institution provided the stated conditions are met.

They connect with the wider EU rulebook in three ways. DORA applies to the ICT dependency on the verification provider, including the register of information and the Article 30 contract terms. The EU AI Act classifies certain remote biometric identification as high-risk, while biometric verification that only confirms that a person is who they claim to be is carved out of that category; a bank should check each tool against the AI Act separately. And the AML Regulation (EU) 2024/1624, which applies from 10 July 2027, will move the underlying customer due diligence rules from a directive to a directly applicable regulation.

The EBA gives no guidance that banks may use an AI vendor's certification as a substitute for their own assessment: the institution must be able to demonstrate to its competent authority that the solution is adequate, reliable and remains so.

WHAT THIS MEANS IN PRACTICE

  • Document a pre-implementation assessment for every remote onboarding tool, including impersonation-fraud and deepfake testing, before go-live.
  • Obtain from the vendor the liveness and matching performance data needed to show the algorithms are strong and reliable, and re-test after model updates.
  • Set monitoring triggers (for example rising fraud rates or false rejections) that force an ad hoc review, and keep a fallback to face-to-face verification.
  • Treat the vendor as an ICT third-party provider: register it, apply the contract terms and plan an exit, in line with DORA.
  • Track the AML Regulation (applies from 10 July 2027) and AMLA technical standards for changes to remote identification rules.

Do the EBA remote onboarding guidelines apply to banks?

Yes. They are addressed to competent authorities and to credit and financial institutions as defined in Article 3(1) and 3(2) of the AML directive, which includes banks. They are guidelines, not law, but competent authorities must notify the EBA whether they comply, and supervisors use them to assess customer due diligence.

When did EBA/GL/2022/15 take effect?

The EBA published the final Guidelines on 22 November 2022 and they apply from 2 October 2023.

Do the EBA guidelines allow AI-based facial recognition for onboarding?

They are technology-neutral and do not name AI, but they allow biometric verification where the data is sufficiently unique to link to one person, strong and reliable algorithms are used, liveness detection is applied in unattended journeys and additional controls apply where confidence is low. The institution must also test the solution before use and monitor it afterwards.

Can a bank outsource remote onboarding to a vendor?

Yes, but the institution stays responsible for customer due diligence. Paragraphs 46-49 require the policy to say what the vendor does, require the institution to apply the EBA outsourcing guidelines and monitor the vendor, and require control over customer data held by the provider; DORA's third-party rules apply on top.

What will replace the EBA remote onboarding guidelines?

Regulation (EU) 2024/1624 (the AML Regulation) applies from 10 July 2027 and mandates AMLA technical standards and guidelines on customer due diligence, including remote identification. No repeal of EBA/GL/2022/15 had been identified as of 5 October 2026, so it remains the operative text.

DateDocumentStatus
Jul 31, 2026ESA Statement on ICT risks from frontier AI models (JC 2026 25) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI modelsIn force
Nov 21, 2025EBA factsheet: AI Act implications for the EU banking and payments sector — AI Act: implications for the EU banking and payments sectorFinal
Nov 21, 2025EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384) — Outcome of EBA's AI Act mapping exercise — letter to DG FISMA and DG CNECTFinal
Oct 1, 2025EBA Work Programme 2026 — EBA Work Programme 2026 — AI Act implementation and digital-finance prioritiesIn force
Sep 25, 2025EBA report: Rising application of AI in EU banking and payments (Sep 2025) — Rising application of AI in EU banking and payments sectorFinal
Aug 4, 2023EBA follow-up report on machine learning for IRB models (EBA/REP/2023/28) — Machine Learning for IRB Models — Follow-up report from the consultation on the Discussion paper on machine learning for IRB modelsFinal

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning