KYC

KYC With EUDI Wallets: What Actually Changes at Onboarding, Step by Step

Blog Owner

Muhammad Ahmad

Growth Hacker at Hovi
Big Thumb

From 10 July 2027 the Anti-Money Laundering Regulation ties customer due diligence to eIDAS methods, and wallet-based identification becomes one of the accepted routes. For the identity verification step, that removes the document scan, the selfie and the liveness check. It removes almost nothing else. This is a step-by-step walk through a remote onboarding flow, showing which parts change, which parts stay exactly where they are, and where teams get the boundary wrong.

The onboarding flow you have today

A typical remote onboarding runs something like this.

The customer photographs an identity document. Your provider checks the document for authenticity, security features, tampering and known forgery patterns. The customer takes a selfie. A biometric engine matches the face to the document photo and runs a liveness check to confirm a real person is present rather than a printed photo, a screen or a deepfake. Data is extracted from the document by OCR or read from the chip. Then screening runs against sanctions, politically exposed person and adverse media lists. A risk score is assigned. Records are kept. Monitoring continues for the life of the relationship.

The first half is where the document handling, the biometric processing and the abandonment risk sit.

The same flow with a wallet presentation

Now the customer has a wallet unit issued by their member state, holding Person Identification Data.

Your service sends a presentation request. The wallet shows the customer what you are asking for and why. The customer approves. You receive the attributes, cryptographically signed, traceable to the issuing member state, at level of assurance high.

Then screening runs. A risk score is assigned. Records are kept. Monitoring continues.

The second half is identical. The first half collapses into one exchange.

Step by step: what changes

Document capture disappears. There is no photograph of a passport or ID card, so there is no image quality problem, no glare, no cropping failure, and no document your provider does not support.

Document authenticity checking disappears. You are not assessing whether a document is genuine. The member state already did that when it issued the credential, and the signature proves the credential came from them and has not been altered.

Liveness and face match disappear from your flow. Commission Implementing Regulation (EU) 2024/2977 requires PID providers to verify the identity of the wallet user before issuing Person Identification Data, and that enrolment must meet the high assurance level set out in Commission Implementing Regulation (EU) 2015/1502. In practice that means document checks, facial biometrics, fraud detection and deepfake detection, performed once at issuance. You inherit the result rather than repeating it.

Data extraction disappears. Attributes arrive as structured, machine-readable data. No OCR, no correction step, no transcription errors in a name with diacritics.

You stop collecting what you do not need. Selective disclosure means you can request date of birth without receiving a full document, or an over-18 assertion without receiving a date of birth. Less data received is less data to secure, less to retain and less to breach.

Repeat verification gets cheaper. The same customer returning to a second service presents the same credential. This is the reusable KYC and KYB model, and it is where the economics change most.

What does not change

This is the part worth reading twice, because the identity step is one step in a compliance obligation with many.

Screening. Sanctions, politically exposed persons and adverse media checks are unaffected. A wallet tells you who someone is. It tells you nothing about whether they appear on a list.

Risk assessment. Customer risk rating, simplified or enhanced due diligence decisions, and the documented reasoning behind them all remain your obligation.

Beneficial ownership. For corporate customers, identifying and verifying ultimate beneficial owners is a separate exercise. Person Identification Data for a director does not discharge it.

Source of funds and source of wealth. Untouched.

Record keeping and auditability. You still have to evidence what you checked, when, and on what basis. The evidence changes shape, from stored document images to signed presentations and verification results, but the obligation is identical.

Ongoing monitoring. Data ageing, periodic review and re-identification triggers all continue.

The other onboarding routes. Wallet acceptance is mandatory for regulated sectors, but not every customer will have a wallet. You still need document-based verification and eID paths alongside it, for years.

Your exposure to issuance quality. This is the trade-off worth understanding. A signed credential proves the member state issued it and that nobody altered it. It does not independently prove the document presented at enrolment was genuine. The regulation sets a high bar for that enrolment, and the French and German cyber security agencies have published joint guidance on remote identity proofing for wallet onboarding. But you are relying on someone else's check rather than performing your own, which is a different risk position, not the absence of one.

Two boundaries worth getting right

The wallet is an identity step, not an onboarding solution. It replaces one component. Removing a screening provider because you added wallet support would leave a gap that no wallet fills.

The checks still have to form one record. Identity verification at 09:42 and screening at 11:17, sitting in separate systems, is harder to defend to a supervisor than one continuous flow with one audit trail. The wallet changes where the identity data comes from. It does not let the pieces drift apart.

What you have to build before any of this works

Wallet-based onboarding is not something you switch on. Four things sit in front of it.

Registration. You register as a relying party with the registrar in the member state where your business is established. No register has opened yet anywhere in the EU. We covered what registration involves in what a business needs before it can verify wallet credentials.

An access certificate. Issued only to registered relying parties, by a certificate authority authorised by your own member state.

A declared scope and intended use. Every attribute you intend to request, declared before you request any of them, per intended use. Onboarding and ongoing authentication are separate declarations.

A verification flow that handles more than one scheme. Formats and protocols are harmonised, but national attributes, trust lists and timing differ. We set out what varies and what does not in 27 member states, 27 wallets.

All four can be prepared now. None of them require a register to be open, and the flow you build against a government sandbox today is the flow you run in production later, because the formats do not change.

How Hovi helps

Hovi works across the Nordics and Baltics, and already operates inside two of the ecosystems moving fastest.   

In the France Identité EUDI ecosystem and the German EUDI Wallet Deutschland sandbox, we can help you integrate and verify against these test wallets. You can build user onboarding and KYC identity verification flows using Person Identification Data and age verification credentials, and issue Electronic Attestation of Attributes credentials into wallet units across the full credential lifecycle.

We presented live in Paris at the France Identité event EUDIW Unfold #3, running verification demos with the France Identité digital wallet, built on the Hovi platform. Watch the full demo.

We also tested against ETSI TS 119 472-1 at the ETSI EAA Plugtests, covering SD-JWT VC and ISO/IEC 18013-5 across several government and private wallet providers.

Hovi gives you the orchestration layer to integrate with EUDI schemes and build your use cases at scale and connect with all 27 member state EUDI Wallets  Talk to us about your EUDI Wallet Integration Strategy.