Solutions

Industries

Markets

Partnerships

Resources

Get in touch

Luigi Pardey, Security Engineer at Fourthline

ETSI: The standard that quietly rewrote your verification workflow

ETSI: The standard that quietly rewrote your verification workflow

At Fourthline, we spend a lot of time reading through and applying regulations and standards that most people may never read. We do this so the products we build keep people safe and keep the companies using them stay on the right side of the rules.  

When a business partner financial institution says “customer onboarding,” I immediately think of ETSI TS 119 461. This is the technical standard that sets how identity proofing is done: confirming that a person is who they claim to be. Yet until recently, nothing apart from eIDAS has obliged anyone to follow it. In fact, outside of trust service circles, it gets almost no attention. 

AMLR is straightening that out. The regulation enters into force on 10 July 2027, and the technical standards that specify how you verify identities in this ecosystem become binding on the same day. If you work for an obliged entity, onboarding as you know it is about to change. 

Here, we’ll explore how ETSI TS 119 461 works and what it means for your organisation. 

The AMLR connection 

AMLR Article 22(6) sets out two ways obliged entities can verify a customer's identity: identity documents or verifications that follow the requirements of eIDAS. The former naturally links to ETSI TS 119 461: it is the standard that governs this type of identification. The latter covers notified national eID schemes (insofar as they provide a “Substantial” level of assurance according to eIDAS), the EUDI Wallet, and qualified electronic signatures (QES).  

The AMLA Regulatory Technical Standard (RTS) on customer due diligence,  (currently in draft form) puts eIDAS methods as the clear preference for verifications conducted on a non-face-to-face basis. Capturing an identity document remotely is allowed where the eIDAS route is not available (or cannot reasonably be expected to be provided) but it must be strongly demonstrated to regulatory authorities on a case-by-case basis. The draft then attaches conditions to that fallback that bear many similarities to the requirements of ETSI TS 119 461 V2.1.1. 

The draft RTS stipulates that the level of due diligence  (Standard, Enhanced, or Simplified) dictates which attributes the obliged entity is required to collect from the customer. Obliged entities set the level of due diligence that needs to be performed on an onboarding customer based on money laundering or terrorism financing risk factors. 

An electronic identification method or qualified trust service has to carry the attributes listed for standard and enhanced due diligence, with a lighter set where simplified due diligence applies. If the eIDAS-compliant proofing factor does not provide the required attributes based on the level of customer due diligence conducted, the obliged entity must still obtain these attributes through other methods that still satisfy AMLR. For most financial institutions, that means using an identity document and a biometric sample. 

AMLR never names ETSI TS 119 461 directly, but the eIDAS route resolves to it. The amended regulation sets the identity verification requirement, and Commission Implementing Regulation (EU) 2025/1566 makes V2.1.1 the reference standard for conformity assessment, from 19 August 2027. So the more the draft RTS pushes obliged entities toward eIDAS, the more of your onboarding rests on this understated standard. 

Preparing for the future 

ETSI TS 119 461, changes what identity proofing service providers must build to support AMLR requirements. Here are some important aspects to be aware of, especially if you are an obliged entity or if you build identity proofing products.  

Identity proofing levels  

The standard defines two levels of identity proofing: “Baseline,” which had been the goalpost in previous years, and “Extended,” which is required for anything involving high-assurance trust services, such as qualified certificates or EUDI Wallet attribute attestations.  

Notably, for institutions that use identity documents for remote onboarding, the “Extended” level changes what your flow may look like. Fully manual attended and unattended flows can now only reach the “Baseline” level. “Extended” requires automated analysis, presentation and injection attack detection tested at the higher level, and a risk assessment that assumes attackers with high attack potential. 

Injection attack detection  

In recent years, identity proofing has been vulnerable to more sophisticated types of fraud, often involving deepfakes. Industry standards have evolved to combat these trends.  

Injection attack detection involves developing comprehensive measures to detect (and prevent) fraud — specifically, attempts to introduce artificial or replayed biometrics into an identity proofing flow. Identity proofing service providers must prove their protection is effective by obtaining a certificate of conformity; namely CEN TS 18099. At the same time, the protections must not reduce the quality of the product for legitimate users, and the service provider should set (and meet) low target rates for falsely classifying a legitimate identity verification as an injection attack. 

Practice statements 

The practice statement is the documentation for all these details. It must include the use cases it claims compliance for by reference to specific clauses (down to the specific flows and document types). Providers are also required to document the False Acceptance Rate and False Rejection Rates of the solution in this statement. This is the document that tells you how a provider performs under pressure, not just how it is designed to perform.  

Any two providers can both claim ETSI compliance and still offer very distinct solutions with different quality targets. It’s worth paying attention to the details, to make sure they align with your expectations. 

What all this means for your onboarding strategy 

Here is where the standard moves from compliance to operations. Indeed, how you verify identity today may very well determine how much work lies ahead. 

Physical documents are not going anywhere. The regulations and standards support digitalisation in the European Union, making high-assurance digital means the path of least resistance, operationally speaking.  

What obliged entities need now is a remote onboarding setup already as close to optimal as the market allows. This includes unattended, chip-read documents ahead of camera capture of physical identity documents, and a compliant provider behind whichever of those you still run. Stay ready to accept a notified eID or the EUDI Wallet as soon as these are implemented. (Read more about EUDI Wallet implementation here.)  

Human review is where organisations may experience real operating costs. A remote attended session with an agent deciding the outcome in real time still requires automated support and advanced attack protections. And on the unattended side, when physical documents are used, a solution that cannot reliably match the biometric to the document needs to involve a human agent. In both cases, the economics likely don’t make sense. 

My advice is to look at onboarding volumes. Do they run unattended or on physical documents? Could they run unattended on an NFC-read or notified eID in the markets where those exist?  

In practice, document-based and electronic routes will run in parallel for years, and electronic methods will become available at different times across different markets. That places real demands on your onboarding partner, to manage both modes simultaneously, and to absorb new electronic methods as and when they arrive. 

The role of your identity proofing provider 

Now is the time to assess whether your providers are compliant, because if they aren’t, this will have implications for your business. Here are a few questions to ask your providers.  

AMLR doesn't explicitly mandate that your provider holds certification against ETSI TS 119 461 V2.1.1. However, s certified providers independently assessed against the very standard that underpins eIDAS-compliant identity proofing, which gives you a measurable basis for trust. So, the first question to ask is: have they been independently assessed, and can they show you the certification? 

The second question is about scope: can your provider cover the document types, modes of operation, and eIDAS-compliant identity means that support your business needs and the distribution of your customer base? The practice statement should help you answer these questions and compare providers. Review the provider’s FAR and FRR targets. Ask how they were set and what methodology was used. Then, compare these against your organisation's risk appetite.  

Getting provider selection right now will save a difficult conversation later. The organisations that move on this early will be in a stronger position when the AMLA RTS on CDD is finalised and regulators begin asking questions. 

Map your exposure with Fourthline 

This is exactly the kind of transition we work through with regulated businesses every day at Fourthline. If you’re trying to figure out what ETSI TS 119 461 V2.1.1 means for your onboarding architecture, vendor contracts, or obligations under AMLR, we're here to help. 

At Fourthline, we spend a lot of time reading through and applying regulations and standards that most people may never read. We do this so the products we build keep people safe and keep the companies using them stay on the right side of the rules.  

When a business partner financial institution says “customer onboarding,” I immediately think of ETSI TS 119 461. This is the technical standard that sets how identity proofing is done: confirming that a person is who they claim to be. Yet until recently, nothing apart from eIDAS has obliged anyone to follow it. In fact, outside of trust service circles, it gets almost no attention. 

AMLR is straightening that out. The regulation enters into force on 10 July 2027, and the technical standards that specify how you verify identities in this ecosystem become binding on the same day. If you work for an obliged entity, onboarding as you know it is about to change. 

Here, we’ll explore how ETSI TS 119 461 works and what it means for your organisation. 

The AMLR connection 

AMLR Article 22(6) sets out two ways obliged entities can verify a customer's identity: identity documents or verifications that follow the requirements of eIDAS. The former naturally links to ETSI TS 119 461: it is the standard that governs this type of identification. The latter covers notified national eID schemes (insofar as they provide a “Substantial” level of assurance according to eIDAS), the EUDI Wallet, and qualified electronic signatures (QES).  

The AMLA Regulatory Technical Standard (RTS) on customer due diligence,  (currently in draft form) puts eIDAS methods as the clear preference for verifications conducted on a non-face-to-face basis. Capturing an identity document remotely is allowed where the eIDAS route is not available (or cannot reasonably be expected to be provided) but it must be strongly demonstrated to regulatory authorities on a case-by-case basis. The draft then attaches conditions to that fallback that bear many similarities to the requirements of ETSI TS 119 461 V2.1.1. 

The draft RTS stipulates that the level of due diligence  (Standard, Enhanced, or Simplified) dictates which attributes the obliged entity is required to collect from the customer. Obliged entities set the level of due diligence that needs to be performed on an onboarding customer based on money laundering or terrorism financing risk factors. 

An electronic identification method or qualified trust service has to carry the attributes listed for standard and enhanced due diligence, with a lighter set where simplified due diligence applies. If the eIDAS-compliant proofing factor does not provide the required attributes based on the level of customer due diligence conducted, the obliged entity must still obtain these attributes through other methods that still satisfy AMLR. For most financial institutions, that means using an identity document and a biometric sample. 

AMLR never names ETSI TS 119 461 directly, but the eIDAS route resolves to it. The amended regulation sets the identity verification requirement, and Commission Implementing Regulation (EU) 2025/1566 makes V2.1.1 the reference standard for conformity assessment, from 19 August 2027. So the more the draft RTS pushes obliged entities toward eIDAS, the more of your onboarding rests on this understated standard. 

Preparing for the future 

ETSI TS 119 461, changes what identity proofing service providers must build to support AMLR requirements. Here are some important aspects to be aware of, especially if you are an obliged entity or if you build identity proofing products.  

Identity proofing levels  

The standard defines two levels of identity proofing: “Baseline,” which had been the goalpost in previous years, and “Extended,” which is required for anything involving high-assurance trust services, such as qualified certificates or EUDI Wallet attribute attestations.  

Notably, for institutions that use identity documents for remote onboarding, the “Extended” level changes what your flow may look like. Fully manual attended and unattended flows can now only reach the “Baseline” level. “Extended” requires automated analysis, presentation and injection attack detection tested at the higher level, and a risk assessment that assumes attackers with high attack potential. 

Injection attack detection  

In recent years, identity proofing has been vulnerable to more sophisticated types of fraud, often involving deepfakes. Industry standards have evolved to combat these trends.  

Injection attack detection involves developing comprehensive measures to detect (and prevent) fraud — specifically, attempts to introduce artificial or replayed biometrics into an identity proofing flow. Identity proofing service providers must prove their protection is effective by obtaining a certificate of conformity; namely CEN TS 18099. At the same time, the protections must not reduce the quality of the product for legitimate users, and the service provider should set (and meet) low target rates for falsely classifying a legitimate identity verification as an injection attack. 

Practice statements 

The practice statement is the documentation for all these details. It must include the use cases it claims compliance for by reference to specific clauses (down to the specific flows and document types). Providers are also required to document the False Acceptance Rate and False Rejection Rates of the solution in this statement. This is the document that tells you how a provider performs under pressure, not just how it is designed to perform.  

Any two providers can both claim ETSI compliance and still offer very distinct solutions with different quality targets. It’s worth paying attention to the details, to make sure they align with your expectations. 

What all this means for your onboarding strategy 

Here is where the standard moves from compliance to operations. Indeed, how you verify identity today may very well determine how much work lies ahead. 

Physical documents are not going anywhere. The regulations and standards support digitalisation in the European Union, making high-assurance digital means the path of least resistance, operationally speaking.  

What obliged entities need now is a remote onboarding setup already as close to optimal as the market allows. This includes unattended, chip-read documents ahead of camera capture of physical identity documents, and a compliant provider behind whichever of those you still run. Stay ready to accept a notified eID or the EUDI Wallet as soon as these are implemented. (Read more about EUDI Wallet implementation here.)  

Human review is where organisations may experience real operating costs. A remote attended session with an agent deciding the outcome in real time still requires automated support and advanced attack protections. And on the unattended side, when physical documents are used, a solution that cannot reliably match the biometric to the document needs to involve a human agent. In both cases, the economics likely don’t make sense. 

My advice is to look at onboarding volumes. Do they run unattended or on physical documents? Could they run unattended on an NFC-read or notified eID in the markets where those exist?  

In practice, document-based and electronic routes will run in parallel for years, and electronic methods will become available at different times across different markets. That places real demands on your onboarding partner, to manage both modes simultaneously, and to absorb new electronic methods as and when they arrive. 

The role of your identity proofing provider 

Now is the time to assess whether your providers are compliant, because if they aren’t, this will have implications for your business. Here are a few questions to ask your providers.  

AMLR doesn't explicitly mandate that your provider holds certification against ETSI TS 119 461 V2.1.1. However, s certified providers independently assessed against the very standard that underpins eIDAS-compliant identity proofing, which gives you a measurable basis for trust. So, the first question to ask is: have they been independently assessed, and can they show you the certification? 

The second question is about scope: can your provider cover the document types, modes of operation, and eIDAS-compliant identity means that support your business needs and the distribution of your customer base? The practice statement should help you answer these questions and compare providers. Review the provider’s FAR and FRR targets. Ask how they were set and what methodology was used. Then, compare these against your organisation's risk appetite.  

Getting provider selection right now will save a difficult conversation later. The organisations that move on this early will be in a stronger position when the AMLA RTS on CDD is finalised and regulators begin asking questions. 

Map your exposure with Fourthline 

This is exactly the kind of transition we work through with regulated businesses every day at Fourthline. If you’re trying to figure out what ETSI TS 119 461 V2.1.1 means for your onboarding architecture, vendor contracts, or obligations under AMLR, we're here to help. 

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.