The European Business Wallet: What It Is, What It Is Not, and What Changes for KYB

Blog Owner

Omer Shafiq

CEO at Hovi
Big Thumb

A company opening a branch in another Member State still sends documents. A certificate of incorporation, a notarised copy, a certified translation, a board resolution proving that the person signing is allowed to sign. Someone at the other end reads them and decides whether to believe them.

European Business Wallets are designed to end that. Instead of sending a document about your company, you present a credential issued by the authority that holds the fact.

That is a real change, and it is worth understanding precisely, because the claims made for it are broader than what the regulation actually does. It will not replace your KYB obligations. It changes the evidence you use to meet them.

Where the file actually stands

The Commission proposed the regulation on 19 November 2025, as part of its Digital Package.

The Council adopted its negotiating position on 9 June 2026 at the Telecommunications Council. Germany and Spain both filed written reservations while supporting the compromise text, Germany pressing on security requirements for wallet providers serving high-assurance public applications.

The European Parliament's Committee on Industry, Research and Energy adopted its position on 10 September 2026, by 64 votes to seven with four abstentions, and voted 65 to nine to open negotiations. The rapporteur is Eero Heinäluoma. Once that decision is announced in plenary, trilogues can begin.

So the file is at the start of interinstitutional negotiation, not the end of it. The Council has said it wants political agreement before the end of 2026, following a request from EU leaders in March 2026. Treat that as an intention rather than a date.

What they are

Five capabilities sit at the centre of the proposal.

Proving who your company is, and checking others. A single digital identity for a legal entity, recognised across all 27 Member States.

Holding verified company facts. Licences, permits, certificates and registrations arrive as electronic attestations of attributes issued by authoritative sources, rather than as documents you scan and forward.

Signing, sealing and timestamping. With legal effect across the Union.

Delegation. Proving that a named person may act for the company, and binding their action to the entity. This is the link between a person's wallet and a company's.

A legally recognised channel. A qualified electronic registered delivery service, giving proof of sender, proof of delivery and proof of integrity, so a notification sent through it counts everywhere.

Underneath, the architecture reuses the European Digital Identity Framework, alongside existing infrastructure such as the Once Only Technical System and the Business Registers Interconnection System.

What they are not

Four corrections, because each one is widely stated the wrong way round.

They are not mandatory for businesses. The obligations fall on public sector bodies, which must accept the wallets for identification, signing, document submission and notifications. Companies choose whether to adopt them. Adoption is expected to be market-driven.

They are not a register or a database. Nothing is centralised. A wallet holds attestations issued by authentic sources, and the company presents them. A European Digital Directory supports discoverability, but the data stays with the issuer and the holder.

They are not the same thing as the wallets being issued to citizens. EUDI Wallets under Regulation (EU) 2024/1183 belong to natural persons. European Business Wallets belong to legal entities and come from a separate proposed regulation. They are designed to interoperate, which is the point of the delegation feature, but they are not one product.

They are not law yet. Nothing in the current text is final until negotiations conclude. The timelines below come from the proposal as it stands.

On timing, public sector bodies get 24 months after entry into force to accept the core functions, with a longer transitional period for the communication channel. Since the regulation has not been adopted, the clock has not started.

What changes for KYB

Here is the part that matters for anyone onboarding business customers.

Most of the effort in KYB today goes into collecting and checking documents. Proof of incorporation. Proof of registered address. Proof that the individual in front of you can bind the company. Across borders this gets worse, because the document arrives in another language, under another legal form, from a registry your team has never seen.

European Business Wallets attack exactly that layer. The company presents attestations issued by its own national register or licensing authority. You verify cryptographically rather than by reading. Representation authority arrives as a credential rather than as a board minute.

Cross-border onboarding is where the gain concentrates. A company in one Member State can present facts from its home registry in a form a counterparty in another Member State can check without knowing anything about that registry.

Delegation is the underrated part. Knowing that a company exists is the easy half of KYB. Knowing that the person signing is authorised to sign is the half that generates the phone calls.

What does not change for KYB

Now the limit, and it is a hard one.

The Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, applies from 10 July 2027. It sets one rulebook across all 27 Member States for customer due diligence, beneficial ownership and reporting. Nothing in the business wallet proposal amends it.

So these obligations survive intact. You still identify and verify beneficial owners. You still screen for sanctions and politically exposed persons. You still assess risk, and apply enhanced measures where the risk is higher. You still monitor the relationship on an ongoing basis. You still report discrepancies against beneficial ownership registers.

A verified attestation of incorporation is good evidence for one element of due diligence. It says nothing about who ultimately owns the company, where the funds come from, or whether the relationship looks different in six months.

The honest summary: onboarding gets faster, and compliance does not get lighter. Treat the wallet as a better source of evidence, not as a substitute for judgement.

Two dates are worth putting side by side. AMLR applies from 10 July 2027. The business wallet regulation has not been agreed, and public sector acceptance arrives two years after whatever entry into force ends up being. Your AML programme will be rebuilt before wallets are widely usable, which means the sequencing question is whether your KYB stack can accept credential-based evidence later without being rebuilt twice.

The problem nobody has solved

Adoption depends on wallets that contain something.

The risk repeatedly raised by people building this is the empty wallet: companies holding a wallet with no usable attestations in it, because the registries and licensing bodies that hold the underlying facts have not started issuing.

Work through the WE BUILD large-scale pilot, which covers business, supply chain and payments, has identified more than 50 distinct attestations across 13 use cases. Which of those get issued, by whom, and when, determines whether any of this is useful in practice.

That is worth watching more closely than the legislative timetable. A regulation that passes on schedule and produces empty wallets changes nothing.

It is not a reason to wait, though. Whichever attestations arrive first, and whichever authority issues them, they arrive in the formats and protocols already specified for EUDI Wallets. A verification layer built now does not need rebuilding when the contents change.

What a business should do now

Work out which side of the transaction you are on. If you onboard business customers, you are a verifier and the question is whether your KYB flow can consume credentials. If you hold licences and registrations, you are a holder and the question is whether your authorities plan to issue them.

Separate your AML programme from your wallet planning. AMLR has a fixed date. The business wallet regulation does not. Planning them as one project will put a hard deadline at the mercy of a soft one.

Map your document collection to attestations. For each thing you currently ask a business customer to send, identify which authority holds that fact. That map is what tells you how much of your onboarding a wallet could actually remove.

Build the verification capability once. European Business Wallets are designed to reuse the formats and protocols already specified for EUDI Wallets. A verifier built properly for one should be most of the way to the other. We covered what that involves in our beginner's guide to EU Digital Identity Wallets.

How Hovi helps

Hovi works across the Nordics and Baltics, and operates inside two of the ecosystems moving fastest.

Hovi Business Wallets let an organisation receive, manage and prove credentials, and sign with its wallet, in the cloud or on-premises. Issuance runs through Hovi Connect. Both are built on the EUDI standards that European Business Wallets are set to build on.

Moreover, Hovi is also part of the France Identité EUDI ecosystem and the German EUDI Wallet Deutschland sandbox, we can help you build and verify against real test wallets today, using Person Identification Data and age verification credentials, and issue Electronic Attestation of Attributes credentials into wallet units across the full credential lifecycle.

Want to explore business wallets and use-cases around them, schedule a meeting with us.

‍