Skip to content
Ver.iDhttps://ver.id/articles/blog/2025-03-12-afm-report
All articles

Article

Digital customer identification: what the AFM report means

The European wallet affects your whole customer journey. What information do you request, what do you check, and how do you keep your service accessible?

Editorial illustration by Ver.iD: a wallet can supply evidence. Assessing the application and carrying out the remaining customer due diligence are still necessary.

For a financial services provider, digital identity starts with a practical question: how do you establish who your customer is without repeatedly putting them through the same process? A wallet can play a part. Its value depends on deciding which evidence you need and how you will use it.

On 11 March 2025, the Dutch Authority for the Financial Markets (AFM) published an exploration of the European Digital Identity Wallet. It identifies opportunities alongside fraud, privacy and digital exclusion concerns. Read the AFM announcement.

Look at the whole customer journey

The AFM report illustrates a loan application: identification, sharing authenticated source data and signing could take place through the wallet. It examines the European wallet; it does not give blanket approval to existing identity apps.

Our practical interpretation is to consider these steps together. Successful identification does little for the customer if they then have to supply the same information again, or an employee has to retype it.

Consider an application requiring evidence of identity and income. First map each piece of information to the decision it supports. Then establish which sources you accept, how recent the evidence must be and who reviews exceptions. You can then make an informed choice about the wallet's role in that application.

Connect identity assurance with customer onboarding

Several rules and guidelines inform customer onboarding. Each serves a different purpose:

  • EBA: designing remote onboarding. The EBA guidelines call for a risk-sensitive assessment of solutions' adequacy and reliability. They are technology-neutral and do not favour one identification tool.
  • FATF: confidence in digital identification. The Guidance on Digital Identity connects assurance levels with customer due diligence. Technology, architecture and governance are assessed against risk. This is international guidance, not a separate EU regulation.
  • AMLR: customer due diligence requirements. Article 22(6) includes electronic identification at assurance level substantial or high and relevant qualified trust services as a verification option. The AMLR generally applies from 10 July 2027. Identity verification is one part of due diligence.
  • eIDAS 2.0: accepting the European wallet. Article 5f(2) provides for acceptance obligations for certain private service providers required to use strong authentication for online identification, including financial institutions. Micro and small enterprises are exempt. Customers retain the choice to use the wallet.

A suitable implementation therefore requires an assessment of your service, customers and obligations. A technical connection alone does not answer those questions.

Make the acceptance decision explicit

When designing a wallet journey, we recommend separating three decisions:

  • What evidence do you request? Describe the information needed at this step. Distinguish what is necessary from what you collect out of habit.
  • When do you accept it? Define suitable issuers and sources, the checks required and when evidence is too old or insufficient.
  • What happens next? Decide what enters the customer record, who handles exceptions and how the application proceeds.

This gives product, compliance and engineering teams a shared application to work through. A successful technical check becomes useful when the decision it supports is clear.

Test the journey without a wallet too

Deliberately include customers who do not have a suitable wallet, information that is missing and sharing attempts that fail. Can the customer continue? Does an employee know how to help? Does the customer understand why you need particular information?

Include these situations in your design and acceptance criteria. That makes a trial more useful than a demonstration of a successful data transfer.

Start with one defined application

Our recommendation is to choose one customer journey and document how it works today. For example, measure how many applications need extra explanation or manual review. Then trial the same application with a wallet and compare the results. This makes assumptions about simplicity and usability testable.

Want to work through this for your organisation? Discuss your customer journey with Ver.iD. For the technical side, read about verifying digital credentials.