# EBA/GL/2022/15 (remote customer onboarding): EBA/GL/2022/15 Guidelines on the use of Remote Customer Onboarding Solutions under Article 13(1) of Directive (EU) 2015/849

Source: https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding
Last updated: Oct 5, 2026

EBA/GL/2022/15, the EBA's Guidelines on the use of Remote Customer Onboarding Solutions, were published on 22 November 2022 and have applied since 2 October 2023. They set out the steps credit and financial institutions must take when choosing and running remote tools to meet their customer due diligence obligations under Article 13(1)(a)-(c) of the AML directive (Directive (EU) 2015/849). The Guidelines are technology-neutral and do not name artificial intelligence, but they reach AI-based identity verification: they require a pre-implementation assessment, ongoing monitoring, strong and reliable algorithms for biometric matching and liveness detection in unattended onboarding, and specific controls when the process is outsourced to a provider. A bank that uses a vendor for selfie, document or video verification should treat these Guidelines as the supervisory baseline until the EU AML Regulation's own rules apply from 10 July 2027.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) |
| Type | Guidance |
| Status | In force |
| Published | Nov 22, 2022 |
| Effective | Oct 2, 2023 |
| Applies to | Credit and financial institutions as defined in Article 3(1) and 3(2) of Directive (EU) 2015/849 (the AML directive) that onboard customers remotely, and their competent authorities; applies to banks directly |
| Official text | https://www.eba.europa.eu/sites/default/files/document_library/Publications/Guidelines/2022/EBA-GL-2022-15%20GL%20on%20remote%20customer%20onboarding/1043884/Guidelines%20on%20the%20use%20of%20Remote%20Customer%20Onboarding%20Solutions.pdf |

## Key points

- Date and status: published 22 November 2022 as the EBA final report; apply from 2 October 2023. Issued under Article 16 of Regulation (EU) No 1093/2010, so competent authorities must say whether they comply or intend to comply.
- Scope: steps institutions take when adopting or reviewing solutions to comply with Article 13(1) points (a), (b) and (c) of Directive (EU) 2015/849 when onboarding new customers remotely, and when relying on third parties under Chapter I, Section 4 of that directive.
- Governance and policies (paragraphs 9-12): written policies and procedures for remote onboarding, with management body approval of the policy and the ability to demonstrate it to the competent authority.
- Pre-implementation assessment (paragraphs 13-16): assess adequacy, completeness and accuracy of data, impact on ML/TF, operational, reputational and legal risks, test for impersonation fraud and ICT security risks, and run end-to-end testing before use.
- Ongoing monitoring (paragraphs 18-22): regular and ad hoc reviews of the quality and accuracy of data collected, with defined triggers and remedial actions; also applies to fully automated solutions.
- Identity matching and liveness (paragraphs 38-41): where biometric data is used, ensure it is sufficiently unique, use 'strong and reliable algorithms' for matching, apply additional controls when confidence is insufficient, and in unattended onboarding perform liveness detection and match photographs or video to the document image.
- Document checks (paragraphs 33-37): where OCR or MRZ features read documents automatically, the institution must ensure that they capture information accurately and consistently.
- Outsourcing and third parties (paragraphs 46-49): decide in policy which functions are performed by the institution, third parties or outsourced providers; for outsourced CDD, apply the EBA outsourcing guidelines, monitor the provider through reporting, visits or testing, and keep control of stored customer data.
- ICT and security (paragraphs 50-53): manage ICT and security risk of the onboarding process, including where outsourced to group entities, using secure channels and cryptographic protocols and, for multi-purpose devices, a secure execution environment.

## What changed for banks

Before the Guidelines, the AML directive did not say what was acceptable in a remote setting, and supervisory expectations differed across Member States. EBA/GL/2022/15 set a common EU standard for remote identity verification, including for biometric and automated tools, so banks buying AI-enabled identity checks must show they assessed, tested and monitor the tool. They remain the reference until the AML Regulation (EU) 2024/1624, which applies from 10 July 2027, and the technical standards and AMLA guidelines it calls for take over; No replacement or repeal had been identified as of 5 October 2026.

## Use cases it governs

- [AML / KYC](https://www.bankingnewsai.com/ai-regulation/by-use-case#aml-kyc)
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Data & privacy](https://www.bankingnewsai.com/ai-regulation/by-use-case#data-privacy)
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)

## What does EBA/GL/2022/15 require of banks that onboard customers remotely, including with AI-based tools?

EBA/GL/2022/15 requires a bank that onboards customers remotely to set written policies approved at management level, assess any remote solution before use, monitor it continuously, and verify identity with controls proportionate to the ML/TF and fraud risk. For biometric and automated verification it expects strong and reliable matching algorithms, liveness detection in unattended journeys, reproducible document checks and escalation to a face-to-face check when evidence quality is poor. If a provider runs the process, the bank keeps the CDD responsibility, applies the EBA outsourcing guidelines and monitors the provider. The Guidelines have applied since 2 October 2023 and do not mention AI explicitly, but they are the standard supervisors apply to AI-enabled identity verification.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Paragraphs 9-12 — Policies, procedures and governance | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | Maintain written remote onboarding policies and procedures, approved by the management body and demonstrable to the competent authority. | Applies from 2 Oct 2023 | [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) |
| Paragraphs 13-16 — Pre-implementation assessment | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | Before adopting a solution, assess data adequacy, ML/TF and operational risks, impersonation fraud and ICT security risks, and carry out end-to-end testing. | Applies from 2 Oct 2023 | [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) |
| Paragraphs 18-22 — Ongoing monitoring | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | Review the quality, completeness and accuracy of onboarding data regularly and on defined triggers, including for fully automated solutions, and set remedial actions. | Applies from 2 Oct 2023 | [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) |
| Paragraph 39 — Biometric data | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | Ensure biometric data is sufficiently unique to link to one person and use strong and reliable algorithms to match the data from the document to the customer. | Applies from 2 Oct 2023 | [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) |
| Paragraph 41 — Unattended onboarding | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | Ensure image quality and timing, perform liveness detection, and use strong and reliable algorithms to match the live photograph or video to the identity document. | Applies from 2 Oct 2023 | [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) |
| Paragraph 40 — Insufficient evidence | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | Interrupt and restart the process, or redirect to face-to-face verification, when evidence quality prevents reliable remote checks. | Applies from 2 Oct 2023 | [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) |
| Paragraphs 46-49 — Third parties and outsourcing | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | Allocate functions between the institution and providers in policy, apply the EBA outsourcing guidelines, and monitor the provider and data it stores. | Applies from 2 Oct 2023 | [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) |
| Paragraphs 50-53 — ICT and security risk | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | Manage ICT and security risks of the onboarding process, use secure channels and cryptographic protocols, and secure the customer-side software environment. | Applies from 2 Oct 2023 | [EBA/GL/2022/15 (remote customer onboarding)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding) |

The Guidelines were requested by the European Commission to address divergent national supervisory expectations on remote customer due diligence. They are addressed to the AML directive's obliged entities, so they apply to banks, payment institutions and other financial institutions across the EU, and they leave the choice of technology to the institution provided the stated conditions are met.

They connect with the wider EU rulebook in three ways. DORA applies to the ICT dependency on the verification provider, including the register of information and the Article 30 contract terms. The EU AI Act classifies certain remote biometric identification as high-risk, while biometric verification that only confirms that a person is who they claim to be is carved out of that category; a bank should check each tool against the AI Act separately. And the AML Regulation (EU) 2024/1624, which applies from 10 July 2027, will move the underlying customer due diligence rules from a directive to a directly applicable regulation.

The EBA gives no guidance that banks may use an AI vendor's certification as a substitute for their own assessment: the institution must be able to demonstrate to its competent authority that the solution is adequate, reliable and remains so.

### What this means in practice

- Document a pre-implementation assessment for every remote onboarding tool, including impersonation-fraud and deepfake testing, before go-live.
- Obtain from the vendor the liveness and matching performance data needed to show the algorithms are strong and reliable, and re-test after model updates.
- Set monitoring triggers (for example rising fraud rates or false rejections) that force an ad hoc review, and keep a fallback to face-to-face verification.
- Treat the vendor as an ICT third-party provider: register it, apply the contract terms and plan an exit, in line with DORA.
- Track the AML Regulation (applies from 10 July 2027) and AMLA technical standards for changes to remote identification rules.

## FAQ

### Do the EBA remote onboarding guidelines apply to banks?

Yes. They are addressed to competent authorities and to credit and financial institutions as defined in Article 3(1) and 3(2) of the AML directive, which includes banks. They are guidelines, not law, but competent authorities must notify the EBA whether they comply, and supervisors use them to assess customer due diligence.

### When did EBA/GL/2022/15 take effect?

The EBA published the final Guidelines on 22 November 2022 and they apply from 2 October 2023.

### Do the EBA guidelines allow AI-based facial recognition for onboarding?

They are technology-neutral and do not name AI, but they allow biometric verification where the data is sufficiently unique to link to one person, strong and reliable algorithms are used, liveness detection is applied in unattended journeys and additional controls apply where confidence is low. The institution must also test the solution before use and monitor it afterwards.

### Can a bank outsource remote onboarding to a vendor?

Yes, but the institution stays responsible for customer due diligence. Paragraphs 46-49 require the policy to say what the vendor does, require the institution to apply the EBA outsourcing guidelines and monitor the vendor, and require control over customer data held by the provider; DORA's third-party rules apply on top.

### What will replace the EBA remote onboarding guidelines?

Regulation (EU) 2024/1624 (the AML Regulation) applies from 10 July 2027 and mandates AMLA technical standards and guidelines on customer due diligence, including remote identification. No repeal of EBA/GL/2022/15 had been identified as of 5 October 2026, so it remains the operative text.

## Related documents

- [ESA Statement on ICT risks from frontier AI models (JC 2026 25)](https://www.bankingnewsai.com/ai-regulation/documents/esas-jc-2026-25-frontier-ai-statement) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models (Jul 31, 2026)
- [EBA factsheet: AI Act implications for the EU banking and payments sector](https://www.bankingnewsai.com/ai-regulation/documents/eba-ai-act-factsheet-2025) — AI Act: implications for the EU banking and payments sector (Nov 21, 2025)
- [EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384)](https://www.bankingnewsai.com/ai-regulation/documents/eba-2025-d-5384-ai-act-mapping-letter) — Outcome of EBA's AI Act mapping exercise — letter to DG FISMA and DG CNECT (Nov 21, 2025)
- [EBA Work Programme 2026](https://www.bankingnewsai.com/ai-regulation/documents/eba-work-programme-2026) — EBA Work Programme 2026 — AI Act implementation and digital-finance priorities (Oct 1, 2025)
- [EBA report: Rising application of AI in EU banking and payments (Sep 2025)](https://www.bankingnewsai.com/ai-regulation/documents/eba-ai-adoption-report-2025) — Rising application of AI in EU banking and payments sector (Sep 25, 2025)
- [EBA follow-up report on machine learning for IRB models (EBA/REP/2023/28)](https://www.bankingnewsai.com/ai-regulation/documents/eba-rep-2023-28-ml-irb-follow-up) — Machine Learning for IRB Models — Follow-up report from the consultation on the Discussion paper on machine learning for IRB models (Aug 4, 2023)
- [EBA discussion paper on machine learning for IRB models](https://www.bankingnewsai.com/ai-regulation/documents/eba-ml-irb-discussion-paper-2021) — Discussion Paper on machine learning for IRB models (Nov 11, 2021)
- [EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06)](https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2020-06-loan-origination-monitoring) — Guidelines on loan origination and monitoring (May 29, 2020)

Last reviewed Oct 5, 2026. Cite the official text (https://www.eba.europa.eu/sites/default/files/document_library/Publications/Guidelines/2022/EBA-GL-2022-15%20GL%20on%20remote%20customer%20onboarding/1043884/Guidelines%20on%20the%20use%20of%20Remote%20Customer%20Onboarding%20Solutions.pdf) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/eba-gl-2022-15-remote-customer-onboarding
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
