Country-specific guidance Current

Verifying an identity document came from a reliable, independent source

Collecting a document and verifying it are two different steps under the EU standard.

The EU's customer due diligence standard doesn't stop at collecting a document; it expects that document to be verified. This guide sets out what that verification step actually involves. It is general information, not legal or compliance advice.

Action plan

1 Know the EU's two-part verification standard A document is one part of the standard; independent corroboration or a qualifying digital check is the other.

The EU's Anti-Money Laundering Regulation sets out two ways to verify a customer's identity: submission of an identity document, passport, or equivalent, combined where relevant with information acquired from reliable and independent sources, whether accessed directly or provided by the customer; or use of an electronic identification means meeting a substantial or high assurance level under the EU's electronic identification framework.

  • Treat document plus independent-source corroboration as one complete verification route
  • Treat a qualifying substantial or high assurance electronic identification means as the other
  • Don't treat a document alone, with no corroboration and no qualifying digital check, as verification

Done when: Each identity document was verified through one of the Regulation's two recognised routes, not accepted on its own

EUR-Lex: EU Anti-Money Laundering Regulation (EU) 2024/1624, Article 22(6)
2 Treat a bare copy of a document as insufficient on its own The independent-source element is what turns a copy into genuine verification.

A scanned or photographed copy of a document, without any independent corroboration, does not by itself satisfy the reliable-and-independent-source element of the standard. Where you're not using a qualifying electronic identification means, plan for a genuine independent-source check, whether that's a reliable database check, a certified copy process, or another mechanism that doesn't rely on the document alone.

  • Don't rely on an uncorroborated scanned or photographed copy as complete verification
  • Use a genuine independent-source check where you're not using a qualifying electronic identification means
  • Record which independent source was used for each verification

Done when: Every document-based verification includes a genuine, recorded independent-source element

3 Verify before the business relationship starts, and check your national timeline Timing matters as much as method, and this standard's own EU-wide start date isn't immediate.

The Regulation requires verification of the customer's and beneficial owner's identity to take place before the establishment of a business relationship or the carrying out of an occasional transaction, subject to limited lower-risk exceptions. This specific EU-wide text becomes directly applicable from 10 July 2027; before that date, your member state's currently transposed law governs the equivalent timing requirement.

  • Complete verification before the business relationship starts, or before an occasional transaction, wherever the standard applies
  • Check any lower-risk exception your firm relies on against the Regulation's own text
  • Confirm your currently applicable national timing requirement until the 2027 EU-wide date

Done when: Verification was completed before the relevant relationship or transaction began, consistent with the applicable national or EU-wide timing rule

See requesting identity documents from an individual client