Remote onboarding and Irish KYC/CDD
Remote identity technology supports customer due diligence; it does not replace the firm's responsibility to identify and verify customers and beneficial owners, understand risk, maintain records and respond when evidence is inadequate.
Central Bank guidance describes risk-based CDD and does not prescribe one definitive list of documentation that satisfies every case. Firms must apply the applicable Irish legal and supervisory framework to their own business.
For: Irish regulated-firm compliance, MLRO, fraud, operations and product teams. This is independent information, not legal, compliance or security advice.
Separate the obligations
- Identify the customer and relevant beneficial owner or representative.
- Verify identity using reliable evidence or information appropriate to risk.
- Understand purpose, nature and risk of the relationship.
- Apply enhanced measures where required.
- Maintain ongoing monitoring and current records.
Technology control map
Document and NFC checks may validate evidence; face comparison or account control may verify ownership; data sources may confirm attributes; fraud signals may detect anomalies; manual review handles exceptions. The firm must explain how the combination meets its policy and risk decision.
Remote-specific risks
- Stolen or manipulated evidence and synthetic identities.
- Deepfake, replay and digital injection.
- Coaching, coercion or mule onboarding.
- Unsupported foreign documents and false rejection.
- Weak recovery after a strong initial check.
- Over-retention of documents and biometric material.
Governance record
Connect requirements, method design, vendor evidence, DPIA, fraud testing, thresholds, manual review, ongoing monitoring and board/management risk ownership. Obtain professional advice for the firm's specific regulatory position.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- Central Bank of Ireland AML/CFT guidance
- NIST SP 800-63A-4 identity proofing
- ENISA Remote Identity Proofing: Attacks and Countermeasures
- General Data Protection Regulation
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing