So, hello everyone and good afternoon. My name is Petra Krizan and I'm a Managing Director of The Blockhouse Technology Limited in Luxembourg. The Blockhouse Technology Limited is a deep tech startup founded in 2018 in Oxford by two Oxford scholars and we develop wallets. We started with developing wallets for digital assets but with the advent of EI 2.0 two years ago we started to develop wallets for digital identities as well. The topic of my today's talk will be onboarding to real-world services.
This is an interesting topic in plans of EODI and verification of EODI credentials and it also needs a closer look from regulatory perspective where we will examine regulatory requirements and we will also examine technical requirements for the onboarding. So not to scare you with this slide but as I assume that most of you are not coming from compliance and don't know a lot about AML and similar terms I would quickly give a run through to these abbreviations because there's a lot of them in my presentation and I decided to kind of divide these terms in three different areas.
First one is compliance and AML, second one is identity and verification and third one is regulations and standards. So let's start with a term called CDD which is customer due diligence and this is basically the obligation you have according to the AML regulation where you need to verify who your customer is before and during having a relationship with this customer.
It's usually done in three different tiers, standard, enhanced and simplified where standard is a requirement for everyone and this requires baseline checks like checking someone's name, date of birth, nationality, ID number and address. And then there's a simplified CDD procedure which is usually done for one of transactions and also for entities which are already under high scrutiny so for example for regulated entities or for publicly listed companies. Here you're dealing with simplified procedures and less of a data set.
And then in case your client is a politically exposed person or PEP this immediately triggers enhanced CDD procedure and enhanced CDD procedure instead of just collecting the basic data set from identification data also requires higher scrutiny meaning that we need to figure out the verified source of funds and wealth for that client and collect additional data to better estimate what's the risk for us as a financial institution or a company working with that client.
And in case we're onboarding a business entity we also need to figure out who are the natural persons standing behind this business entity and those would be beneficial owners and we also need to verify their identity. So from identity and verification we have two terms I would like to explain because I will use them quite a lot during my presentation. First one is level of assurance and this is coming from EIDAS regulation and this is basically saying how reliably the identity was verified or how reliably the identity was issued. So we have three tiers here low, substantial and high.
And from the other set of standards from ETSI standards we have something called LOIP which is level of identity proofing which gives us the information how rigorously was the identity established at the enrollment. There are other abbreviations I will further explain EODI wallet and here are other regulations as well AMLR, EIDAS but I will go into more details further along my presentation. So to give you a big picture not to bore you with the rest of the details if you're not interested, the topic of onboarding is a topic where four different standards and regulations touch upon.
So first one is AMLR regulation, then we have EIDAS 2.0, we have ETSI standards and we have AMLR regulatory technical standards. And for the first time with AMLR and EIDAS 2.0 we have same rules for 27 member countries meaning that with AMLR we have exact same rules for 27 member countries how to onboard clients to financial institutions and all the other sectors which are requiring identity verification and with EIDAS 2.0 again same rules and standards for credentials for digital identity verifiable credentials.
The deadline to be compliant with those regulations is 2027 so for AMLR it's July 2027 and for EIDAS it's December 2027. It's important to mention that in this case the requirements for AMLR regulation are not just for financial services and for financial industry, they are extended to everyone who needs to identify their customers meaning it's extended to real estate agencies, accountant offices and lawyers. And how to be compliant with all of those easiest possible parts by using credentials from digital identity wallet.
So I will now try to quickly explain how it works here and then we're going to run through more detailed explanations later during the presentation. So we will examine a remote onboarding use case where you as a customer want to join a certain digital service, want to be onboarded to a certain digital service. On the portal of that service where this service integrates the verifier component from EUDI ecosystem there is a QR code displayed which is basically a presentation request to ask for certain information from your credential from your wallet.
Then when you scan this request then your wallet finds appropriate credential with correct attributes and claims and then you get to choose whether you want to share those attributes and claims from your credential and when this is shared automatically the CDD record is populated and you're compliant with AML article 22. All of this happens in a matter of seconds with cryptographic verification.
There's no manual checks, no agents, no forms, no risk of deep fakes and if the credential was issued with high level of assurance this can cover both standard and enhanced customer due diligence in one flow. Back to the regulations. So we can quickly examine which regulation or standard requires what.
So it's not a single regulation as I already mentioned it's four different documents and of course the first one is anti-money laundering regulation which is setting the rules for anti-money laundering processes and the KYC or Know Your Customer procedure is a part of the AML regulation and it's defined there and this basically defines what must be verified and by whom.
The second one is EIDAS 2.0 which basically gives an infrastructure to provide credentials with level of assurance high which are user controlled, cryptographically secured and reusable and the last two are not regulations but those are standards where extended ETSI standard from February 2025 defines exactly how onboarding procedures must work in face to face and remote scenarios and the last one is AMLA draft regulatory technical standards where the consultations closed couple of days ago and this basically translates the requirements from AML regulation into operational CDD requirements and it exactly specifies what must be collected and verified to onboard the customer.
And couple of notes about the wallet I'm sure that most of you already are familiar with the UDI wallets but just for the case of completeness UDI wallet is something what was proposed by EIDAS 2.0 regulation actually two years ago the regulation came into force May 2024 and it requires for all 27 member countries of European Union to provide at least one wallet for its citizens and customers by the end of 2026.
Functional features of this wallet are as follows on this slide, the credentials and the wallet is user controlled so me and you we can all manage our credentials and there's no central database which is required for it. The credentials are cryptographically secured and signed by the issuing authority.
We can have a higher level of privacy preserving with these credentials compared to physical credentials where we can omit the fields we want to share with certain services so only the information which is actually required gets shared which is according to the data minimization principles or GDPR. As I mentioned those are cross-border interoperable credentials which work all across 27 EU member countries and they are issued and can be issued under high assurance and they are reusable meaning once you get the credential you can use it to onboard to various different services.
And to the most difficult part what are the rules for the onboarding so this is something what is specified in ETSI requirements. Of course that standard defines face-to-face requirements as well but as remote is more complex and requires more attention there are three different options how you can be compliant with this standard. So in order to onboard your customers remotely you can either choose live agent video call, you can onboard them by using automated video system or you can onboard them by using EIDAS 2.0 credentials.
So for a live video call you can imagine that has to be attended video call where you take your documents, your passport, you're having a chat with a live agent and then you show your passport from all of the angles, disclose some information from the document and afterwards you send a scanned copy or an image of this document. The second one is automated video system this already exists and we already have those put in place but with this standard we have some new requirements. So no photos or scans of documents are required anymore.
The required documents are the only documents which have a chip and the data needs to be read from that chip. And there are also specific requirements on the quality of the video stream which is used for automated face biometrics binding. And with EIDAS credentials you don't have any video and you don't have any images and basically they're issued at a level of assurance high. They automatically cover both simplified standard and enhanced customer due diligence where two previous cases only cover simplified and standard customer due diligence.
So just to give you a little bit of an overview why EIDAS credentials are probably the best choice when deciding on how to have remote onboarding procedures. It wouldn't be a presentation if I wouldn't mention AI I guess but I'm mentioning AI in a completely different light here because in terms of fraud, identity fraud, AI is a huge risk. Why?
Because if you're using traditional methods for remote onboarding which require video streaming or photos and the liveness check, there's always a risk of deep fakes, there's always a risk of different attacks like presentation attacks, photo, video replay, mask attacks and those systems require presentation attack detection. And what is also important to stress is that those detection system needs to be lab certified by the end of 2026.
And of course it's an ongoing arms race against AI systems which are becoming more and more sophisticated and then detection systems need to become more and more sophisticated as well and follow this. On the other hand, we have EIDAS 2.0 credentials where the authentication is cryptographic. Since there's no video, there's no possibility of deep fakes, replay attacks or injection attacks. There's no presentation attack detection required. There's no lab certifications required for those systems. Why? Because risk here shifts to the issuance procedure.
So if the identity was verified and if the credential was issued at the level of assurance high at the moment of the wallet provisioning, the relying party, the party which actually has to verify you is inheriting this assurance from the credential. And also always the most important thing, the economics. So live agents video call onboarding procedures usually cost around 70 to 100 euros per customer. This is the data which I got from a couple of providers in Luxembourg. This is how much they pay for an attended call.
The second one, automated video systems, currently they're cheaper but having in mind that they will have to be lab certified by the end of 2026 and having all of the detection systems put in place to countermeasure the possibility of attacks with AI or deep fakes, the price will for sure rise to 3 to, let's say, 8 euros, while EIDAS is, of course, the cheapest one because we are running only cryptographic verification and checks.
And back to the flow, I did explain it in the beginning, but now I will try to explain it in more detail so you have a better understanding of what's actually happening behind. If you remember, we're scanning a QR code, we're scanning a presentation request, wallet finds the appropriate credential to share with this service and to share required attributes or claims.
In the moment when we're sharing this, what is actually happening behind, when we get this presentation request, when the appropriate credential was found, customer needs to review whether he wants to share those fields and data from the credential with the service. Once this is done, a verifiable presentation is created from the original credential in the wallet, and in that moment, Verify needs to run six independent checks. First of all, it needs to resolve holder binding and replay protection.
Second, it needs to verify the signature on the credential itself, whether this is correct or it's issued by the correct authority. It needs to resolve the chain of trust, furthermore, it needs to verify whether the credential has been expired, revoked, or suspended. It needs to verify whether the credential itself, it's according to original presentation definition and related to a specific credential format, as it can be SDJVT or MSRMDAC credential, it needs to run specific format checks.
Once all of this is done, then you're actually verified, and then the data from your credential can be accepted. And at this moment, your customer due diligence record is auto-populated, and if it's determined that you are simple or standard CDD client, then you can be onboarded to the service. In case you need to undergo extended CDD, in that case, we will ask you more questions and we can also use reusable, verifiable credentials for that. What is important to say here is that if you remember all of those six steps, you don't have to do six steps alone.
So this is why we built a verifier, which can handle the hard parts of resolution of cryptographic methods here. So you don't have to do it, you can just integrate the service. If you want to onboard your customers under minutes, and you want to have a full or full compliant eIDAS 2.0 and AML onboarding solution, you don't need to have a cryptographic expertise because we are here because we've already built that for you. And we are also resolving trust and status lists for you automatically. And what do you need to do now in order to be compliant?
If you're having onboarding procedures, you need to audit your current onboarding standards against the new regulations and standards. As it's mandatory for everyone who's undertaking identity verification to integrate eUDI wallet credentials by December 2027 by eIDAS 2.0 regulation, you also need to plan and prepare for eUDI wallet acceptance. If you're using video onboarding, you need to check with your provider whether they have a lab certification roadmap and whether they have detection for the attacks.
And my advice, consider eIDAS 2.0 credentials as your default path because of the reasons I've mentioned earlier, risks are lower and price is lower. And just to conclude, this is not just a compliance infrastructure. This is also an opportunity, and it's not just a compliance moment where you tick the box and say, OK, cool, we're compliant with these regulations. It's also an opportunity to change your onboarding flows for the better, where you have better access to the data with higher level of assurance.
And secondly, it's better for your customers because they finally get streamlined onboarding procedures. They're not stuck in a loop because they have to scan their documents. And it's more convenient for everyone. And traditional onboarding costs are, of course, rising. And as I mentioned, it's an arms race against AI. And in case you have any questions, I'm done with my presentation. So please shoot.