Solutions

Industries

Markets

Partnerships

Resources

Get in touch

Chris van Straeten, Co-founder and Chief Risk Officer at Fourthline

Beyond Video-Ident: Germany’s Shift to Digital Identity and What Banks Need to Do Next

Beyond Video-Ident: Germany’s Shift to Digital Identity and What Banks Need to Do Next

How eID, qualified trust services, the EUDI Wallet and AMLR are reshaping German customer onboarding.

Germany has followed a distinctive path in digital identity verification. While several European countries have seen widespread adoption of national digital identity solutions, active use of Germany’s eID has developed more gradually.

This was partly due to regulatory and market choices that allowed Germany’s remote KYC infrastructure to develop around Video-Ident — a form of identity verification whose role is likely to become more limited as the new Anti-Money Laundering Regulation shifts the market toward high-assurance electronic identification.

But practical readiness remains a challenge. According to Bitkom research published in April 2026, only 18% of Germans have the online identification function of their identity card activated and know the associated PIN. A further 21% have activated the function but do not know, or no longer know, their PIN. This distinction matters for onboarding: possessing an eID-capable identity document is not the same as being able to use eID immediately.

But perhaps the more interesting question than whether eID will become mainstream is how to use it to build something effective, secure and compliant.

At Fourthline, we've helped millions of German customers through digital onboarding flows. The question we hear most from financial institutions right now is not whether to adopt eID, but how to do it well — without creating a new single point of failure in conversion, customer experience or risk management. Here, I’ll walk you through how we got to where we are, and what to consider as you’re building or updating your own architecture for this complex market.

A short history of customer onboarding in Germany

Germany has historically moved more cautiously than many European peers in digital identity. This has as much to do with the country’s history and values as with its infrastructure and regulatory priorities. Germany has traditionally placed strong emphasis on privacy and data protection, which has also shaped expectations around digital identity and the sharing of personal data. As a result, opening a bank account was, until relatively recently, still often done in person or by post.

The story of modern onboarding in Germany includes BaFin’s early framework for video identification. Video-Ident subsequently became a widely adopted identity verification method among German financial institutions. While Video-Ident solved a genuine remote-onboarding problem, it is operationally intensive and can be materially more expensive than automated chip-based alternatives.

From a fraud-prevention perspective, the fundamental difference is the source of assurance. Traditional Video-Ident relies primarily on a trained agent visually inspecting the identity document and its optical security features over a live video connection, although modern providers may supplement this with automated document analysis, facial matching and other fraud controls. These controls can provide meaningful assurance, but where the document’s electronic chip is not cryptographically read and authenticated, they do not provide the same cryptographic proof of document authenticity and integrity as chip-based eID verification.

BaFin itself has described Video-Ident as a "bridge technology" — reflecting the broader direction toward higher-assurance digital identity methods.

AMLR, together with AMLA’s current draft technical standards, points to a fundamental change in the role of Video-Ident. AMLR applies from 10 July 2027, and AMLA’s latest draft technical standards on customer due diligence propose a clear hierarchy for remote verification: institutions would first use eIDAS-compliant electronic identification at assurance level “substantial” or “high”, or a relevant qualified trust service. Let’s look more closely at what that means for German onboarding.

AMLR and eID

AMLR applies from 10 July 2027. As an EU Regulation, it will create a directly applicable and more harmonised AML/CFT rulebook across Member States. German legislation, BaFin guidance and supervisory practice will nevertheless continue to matter where the European framework leaves room for national rules or supervisory interpretation.

The Regulation gives a central role to electronic identification means and relevant trust services under eIDAS. In practice, notified eID schemes, qualified trust services where applicable, and ultimately the EUDI Wallet will become increasingly important building blocks for remote identification.

Traditional document-based remote verification, including methods such as Video-Ident, does not disappear entirely under AMLA’s current draft RTS. Instead, it becomes a fallback: it may be used where the preferred eIDAS-based electronic identification solution is not available or cannot reasonably be expected to be provided. Institutions using such an alternative remote solution would need to demonstrate compliance with the applicable requirements and justify why the customer could not be verified using the preferred electronic route. The RTS is still draft, so the final technical standard may change, but the regulatory direction is now much clearer.

Again, from a risk perspective, this goes beyond managing regulatory responsibilities. The German online ID function combines a cryptographically protected credential with PIN authentication, providing a strong identity signal and digitally verified identity attributes.

There is a second regulatory development banks should prepare for in parallel: mandatory acceptance of the EUDI Wallet in the circumstances specified by the revised eIDAS framework.

Under the revised eIDAS framework, relevant private relying parties — including financial-services providers in the circumstances specified by Article 5f — will also need to prepare for EUDI Wallet acceptance. Rather than treating German eID and the EUDI Wallet as two unrelated projects, institutions should build an identity layer capable of consuming different high-assurance credentials without rebuilding the onboarding journey each time the ecosystem changes.

Building an architecture for tomorrow’s customer

So, the regulatory direction is clear, as is the technological evolution. What's less clear is the gap between all of this and where German customers actually are. Surveys measure eID activation, readiness and active use differently, but the practical issue is consistent: possessing an eID-capable credential does not necessarily mean a customer can complete an eID journey immediately.

This creates a paradox. Financial institutions need to build for a future where eID and reusable digital credentials become the norm while serving a population that isn't fully eID-ready today. Customers are making their way there unevenly and at different speeds. This is what makes onboarding architecture decisions so consequential.

A meaningful share of your customers will be able to use eID immediately. Many won't. Your onboarding architecture has to serve all of them without frustrating customers who fall into the gaps. That means not assuming "German" equals "eID-eligible" and vice versa. It also means treating a forgotten PIN, an NFC failure, an unsupported device or an interrupted hand-off as expected states in the journey rather than exceptional errors.

What an eID-first architecture should look like

An eID-first architecture should not be eID-only. A robust design starts by determining which high-assurance credential the customer can actually use. Where German eID is available and the customer is ready, it can be the preferred path. Where it is not, the journey should move seamlessly to another compliant identification route, with the fallback selected on the basis of regulation, product risk, customer eligibility and device capability.

The German eID journey itself has practical dependencies: an activated credential, a known PIN, the required eID software or embedded equivalent, and an NFC-capable smartphone or card reader. These details matter because "eligible for eID" and "able to complete eID now" are not the same thing.

This is where orchestration matters. The customer should not need to understand the regulatory taxonomy of eID, document verification, liveness, QES or Wallet credentials. The institution does.

Questions to ask yourself before July 2027

With the regulatory direction becoming clear, the work is now to test internal systems and planned integrations against both the future regulatory model and today's customer reality. Here are some questions to ask.

Is your eID flow embedded, or does it redirect? Every hand-off creates a potential conversion break. An embedded or tightly integrated experience can reduce friction, but the design still needs to respect the security requirements of the German eID ecosystem. The objective is a coherent customer experience without weakening the underlying assurance.

Does your fallback architecture handle the transition well? Under AMLA’s current draft RTS, fallback is not merely a conversion feature; it becomes part of the regulatory logic of remote identification. A significant share of customers will still encounter practical friction: no eligible credential, an unknown or forgotten PIN, NFC or device failure, or an interrupted hand-off. Your architecture should identify these states quickly and route the customer to an appropriate compliant alternative, while retaining the evidence needed to explain why the preferred electronic route could not be used.

Are you accounting for your full eID-eligible population? This one is important: Germany's eID ecosystem is not limited to German nationals. The notified German eID scheme also covers electronic residence permits and the eID card for Union and EEA citizens. Financial institutions should therefore determine eID eligibility based on the credential a customer holds, rather than nationality alone.  Looking beyond Germany, AMLR and the revised eIDAS framework are moving Europe toward a more interoperable identity ecosystem. But this does not mean that every national eID automatically has to be accepted by every financial institution across the EU. Cross-border use depends, among other things, on whether the eID scheme is notified under eIDAS, the required assurance level, technical interoperability and access conditions. The EUDI Wallet will take this a significant step further by creating a common framework for cross-border digital identity that relevant financial institutions will be required to support under the conditions set out in eIDAS.

What does your risk model require, beyond eID? Do not assume that every data element stored on an identity document is available to a private relying party through the online eID function. Biometric data on the physical credential is subject to access restrictions. If your risk framework requires an additional biometric or liveness signal, that needs to be provided by the surrounding onboarding flow rather than assumed to come from the eID transaction itself.

Are you just building for onboarding, or for the entire customer relationship? High-assurance digital credentials can also be valuable for re-authentication, sensitive account changes, account recovery and elements of periodic or event-driven re-KYC.

Where do qualified trust services and QES fit? eID is not the only high-assurance route under AMLR. The Regulation also recognises relevant qualified trust services under eIDAS as a means of supporting customer identity verification. This is particularly important where an appropriate electronic identification method is not available to the customer.

Relevant qualified trust services, which may include QES-based solutions where appropriate, can therefore play a broader role than simply signing a contract. In a QES journey, the identity proofing required by the Qualified Trust Service Provider (QTSP) may form part of the wider high-assurance onboarding architecture, subject to the requirements that will be further specified under the AMLR technical standards.

In practical terms, the market is likely to organise around three principal high-assurance routes: notified national eIDs, EUDI Wallets, and relevant qualified trust services, including QES-based solutions where appropriate. These routes are not interchangeable in practice.

By the end of 2027, relevant regulated institutions will need to be ready to accept an EUDI Wallet when a customer presents one, in the circumstances specified by the revised eIDAS framework. But acceptance capability does not guarantee that customers will have a Wallet. Rollout and adoption will vary across Member States, while national eID coverage and customer readiness will also remain uneven. An institution can therefore support both routes and still encounter customers who cannot use either.

QES can fill that operational gap. A QES journey does not depend on the customer already holding a national eID or EUDI Wallet and can be deployed across the EU through qualified trust-service infrastructure. Subject to customer eligibility, QTSP coverage and the final AMLR technical standards, QES can therefore provide a scalable pan-European high-assurance route. For institutions seeking one dependable cross-border method during the transition, it should be considered a preferred route alongside the required development of eID and Wallet acceptance. The broader architecture should still orchestrate all three routes and retain an appropriate fallback for customers who cannot use them.

Is your provider positioned for what comes after eID? The real test is not whether a provider can connect one German eID flow. It is whether the architecture can support national eIDs, relevant qualified trust services, EUDI Wallet credentials and robust fallback methods through one governed orchestration layer — without repeatedly rebuilding the onboarding stack.

The strategic takeaway

Germany is not moving from Video-Ident to one new universal method overnight. But the regulatory hierarchy is changing: eIDAS-based electronic identification is moving toward the default remote route, while traditional document-based methods such as Video-Ident are positioned as conditional alternatives under AMLA’s current draft technical standards. The transition will be uneven, and that is precisely why flexibility matters.

For risk leaders, the objective should be straightforward: use an identity method that provides the required level of assurance for the customer, product and risk; preserve a compliant alternative where the preferred electronic route cannot be used; and make the transition between methods almost invisible to the customer. The institutions best positioned for 2027 and beyond will be those that can absorb the next identity method without redesigning the customer journey every time.

How eID, qualified trust services, the EUDI Wallet and AMLR are reshaping German customer onboarding.

Germany has followed a distinctive path in digital identity verification. While several European countries have seen widespread adoption of national digital identity solutions, active use of Germany’s eID has developed more gradually.

This was partly due to regulatory and market choices that allowed Germany’s remote KYC infrastructure to develop around Video-Ident — a form of identity verification whose role is likely to become more limited as the new Anti-Money Laundering Regulation shifts the market toward high-assurance electronic identification.

But practical readiness remains a challenge. According to Bitkom research published in April 2026, only 18% of Germans have the online identification function of their identity card activated and know the associated PIN. A further 21% have activated the function but do not know, or no longer know, their PIN. This distinction matters for onboarding: possessing an eID-capable identity document is not the same as being able to use eID immediately.

But perhaps the more interesting question than whether eID will become mainstream is how to use it to build something effective, secure and compliant.

At Fourthline, we've helped millions of German customers through digital onboarding flows. The question we hear most from financial institutions right now is not whether to adopt eID, but how to do it well — without creating a new single point of failure in conversion, customer experience or risk management. Here, I’ll walk you through how we got to where we are, and what to consider as you’re building or updating your own architecture for this complex market.

A short history of customer onboarding in Germany

Germany has historically moved more cautiously than many European peers in digital identity. This has as much to do with the country’s history and values as with its infrastructure and regulatory priorities. Germany has traditionally placed strong emphasis on privacy and data protection, which has also shaped expectations around digital identity and the sharing of personal data. As a result, opening a bank account was, until relatively recently, still often done in person or by post.

The story of modern onboarding in Germany includes BaFin’s early framework for video identification. Video-Ident subsequently became a widely adopted identity verification method among German financial institutions. While Video-Ident solved a genuine remote-onboarding problem, it is operationally intensive and can be materially more expensive than automated chip-based alternatives.

From a fraud-prevention perspective, the fundamental difference is the source of assurance. Traditional Video-Ident relies primarily on a trained agent visually inspecting the identity document and its optical security features over a live video connection, although modern providers may supplement this with automated document analysis, facial matching and other fraud controls. These controls can provide meaningful assurance, but where the document’s electronic chip is not cryptographically read and authenticated, they do not provide the same cryptographic proof of document authenticity and integrity as chip-based eID verification.

BaFin itself has described Video-Ident as a "bridge technology" — reflecting the broader direction toward higher-assurance digital identity methods.

AMLR, together with AMLA’s current draft technical standards, points to a fundamental change in the role of Video-Ident. AMLR applies from 10 July 2027, and AMLA’s latest draft technical standards on customer due diligence propose a clear hierarchy for remote verification: institutions would first use eIDAS-compliant electronic identification at assurance level “substantial” or “high”, or a relevant qualified trust service. Let’s look more closely at what that means for German onboarding.

AMLR and eID

AMLR applies from 10 July 2027. As an EU Regulation, it will create a directly applicable and more harmonised AML/CFT rulebook across Member States. German legislation, BaFin guidance and supervisory practice will nevertheless continue to matter where the European framework leaves room for national rules or supervisory interpretation.

The Regulation gives a central role to electronic identification means and relevant trust services under eIDAS. In practice, notified eID schemes, qualified trust services where applicable, and ultimately the EUDI Wallet will become increasingly important building blocks for remote identification.

Traditional document-based remote verification, including methods such as Video-Ident, does not disappear entirely under AMLA’s current draft RTS. Instead, it becomes a fallback: it may be used where the preferred eIDAS-based electronic identification solution is not available or cannot reasonably be expected to be provided. Institutions using such an alternative remote solution would need to demonstrate compliance with the applicable requirements and justify why the customer could not be verified using the preferred electronic route. The RTS is still draft, so the final technical standard may change, but the regulatory direction is now much clearer.

Again, from a risk perspective, this goes beyond managing regulatory responsibilities. The German online ID function combines a cryptographically protected credential with PIN authentication, providing a strong identity signal and digitally verified identity attributes.

There is a second regulatory development banks should prepare for in parallel: mandatory acceptance of the EUDI Wallet in the circumstances specified by the revised eIDAS framework.

Under the revised eIDAS framework, relevant private relying parties — including financial-services providers in the circumstances specified by Article 5f — will also need to prepare for EUDI Wallet acceptance. Rather than treating German eID and the EUDI Wallet as two unrelated projects, institutions should build an identity layer capable of consuming different high-assurance credentials without rebuilding the onboarding journey each time the ecosystem changes.

Building an architecture for tomorrow’s customer

So, the regulatory direction is clear, as is the technological evolution. What's less clear is the gap between all of this and where German customers actually are. Surveys measure eID activation, readiness and active use differently, but the practical issue is consistent: possessing an eID-capable credential does not necessarily mean a customer can complete an eID journey immediately.

This creates a paradox. Financial institutions need to build for a future where eID and reusable digital credentials become the norm while serving a population that isn't fully eID-ready today. Customers are making their way there unevenly and at different speeds. This is what makes onboarding architecture decisions so consequential.

A meaningful share of your customers will be able to use eID immediately. Many won't. Your onboarding architecture has to serve all of them without frustrating customers who fall into the gaps. That means not assuming "German" equals "eID-eligible" and vice versa. It also means treating a forgotten PIN, an NFC failure, an unsupported device or an interrupted hand-off as expected states in the journey rather than exceptional errors.

What an eID-first architecture should look like

An eID-first architecture should not be eID-only. A robust design starts by determining which high-assurance credential the customer can actually use. Where German eID is available and the customer is ready, it can be the preferred path. Where it is not, the journey should move seamlessly to another compliant identification route, with the fallback selected on the basis of regulation, product risk, customer eligibility and device capability.

The German eID journey itself has practical dependencies: an activated credential, a known PIN, the required eID software or embedded equivalent, and an NFC-capable smartphone or card reader. These details matter because "eligible for eID" and "able to complete eID now" are not the same thing.

This is where orchestration matters. The customer should not need to understand the regulatory taxonomy of eID, document verification, liveness, QES or Wallet credentials. The institution does.

Questions to ask yourself before July 2027

With the regulatory direction becoming clear, the work is now to test internal systems and planned integrations against both the future regulatory model and today's customer reality. Here are some questions to ask.

Is your eID flow embedded, or does it redirect? Every hand-off creates a potential conversion break. An embedded or tightly integrated experience can reduce friction, but the design still needs to respect the security requirements of the German eID ecosystem. The objective is a coherent customer experience without weakening the underlying assurance.

Does your fallback architecture handle the transition well? Under AMLA’s current draft RTS, fallback is not merely a conversion feature; it becomes part of the regulatory logic of remote identification. A significant share of customers will still encounter practical friction: no eligible credential, an unknown or forgotten PIN, NFC or device failure, or an interrupted hand-off. Your architecture should identify these states quickly and route the customer to an appropriate compliant alternative, while retaining the evidence needed to explain why the preferred electronic route could not be used.

Are you accounting for your full eID-eligible population? This one is important: Germany's eID ecosystem is not limited to German nationals. The notified German eID scheme also covers electronic residence permits and the eID card for Union and EEA citizens. Financial institutions should therefore determine eID eligibility based on the credential a customer holds, rather than nationality alone.  Looking beyond Germany, AMLR and the revised eIDAS framework are moving Europe toward a more interoperable identity ecosystem. But this does not mean that every national eID automatically has to be accepted by every financial institution across the EU. Cross-border use depends, among other things, on whether the eID scheme is notified under eIDAS, the required assurance level, technical interoperability and access conditions. The EUDI Wallet will take this a significant step further by creating a common framework for cross-border digital identity that relevant financial institutions will be required to support under the conditions set out in eIDAS.

What does your risk model require, beyond eID? Do not assume that every data element stored on an identity document is available to a private relying party through the online eID function. Biometric data on the physical credential is subject to access restrictions. If your risk framework requires an additional biometric or liveness signal, that needs to be provided by the surrounding onboarding flow rather than assumed to come from the eID transaction itself.

Are you just building for onboarding, or for the entire customer relationship? High-assurance digital credentials can also be valuable for re-authentication, sensitive account changes, account recovery and elements of periodic or event-driven re-KYC.

Where do qualified trust services and QES fit? eID is not the only high-assurance route under AMLR. The Regulation also recognises relevant qualified trust services under eIDAS as a means of supporting customer identity verification. This is particularly important where an appropriate electronic identification method is not available to the customer.

Relevant qualified trust services, which may include QES-based solutions where appropriate, can therefore play a broader role than simply signing a contract. In a QES journey, the identity proofing required by the Qualified Trust Service Provider (QTSP) may form part of the wider high-assurance onboarding architecture, subject to the requirements that will be further specified under the AMLR technical standards.

In practical terms, the market is likely to organise around three principal high-assurance routes: notified national eIDs, EUDI Wallets, and relevant qualified trust services, including QES-based solutions where appropriate. These routes are not interchangeable in practice.

By the end of 2027, relevant regulated institutions will need to be ready to accept an EUDI Wallet when a customer presents one, in the circumstances specified by the revised eIDAS framework. But acceptance capability does not guarantee that customers will have a Wallet. Rollout and adoption will vary across Member States, while national eID coverage and customer readiness will also remain uneven. An institution can therefore support both routes and still encounter customers who cannot use either.

QES can fill that operational gap. A QES journey does not depend on the customer already holding a national eID or EUDI Wallet and can be deployed across the EU through qualified trust-service infrastructure. Subject to customer eligibility, QTSP coverage and the final AMLR technical standards, QES can therefore provide a scalable pan-European high-assurance route. For institutions seeking one dependable cross-border method during the transition, it should be considered a preferred route alongside the required development of eID and Wallet acceptance. The broader architecture should still orchestrate all three routes and retain an appropriate fallback for customers who cannot use them.

Is your provider positioned for what comes after eID? The real test is not whether a provider can connect one German eID flow. It is whether the architecture can support national eIDs, relevant qualified trust services, EUDI Wallet credentials and robust fallback methods through one governed orchestration layer — without repeatedly rebuilding the onboarding stack.

The strategic takeaway

Germany is not moving from Video-Ident to one new universal method overnight. But the regulatory hierarchy is changing: eIDAS-based electronic identification is moving toward the default remote route, while traditional document-based methods such as Video-Ident are positioned as conditional alternatives under AMLA’s current draft technical standards. The transition will be uneven, and that is precisely why flexibility matters.

For risk leaders, the objective should be straightforward: use an identity method that provides the required level of assurance for the customer, product and risk; preserve a compliant alternative where the preferred electronic route cannot be used; and make the transition between methods almost invisible to the customer. The institutions best positioned for 2027 and beyond will be those that can absorb the next identity method without redesigning the customer journey every time.

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.