Most people have signed something digitally. Very few have signed with a Qualified Electronic Signature, and the difference matters enormously in regulated industries. Fourthline operates exclusively at the highest level of assurance: QES. The only signature type that is AMLR-compliant for remote customer verification.
When a customer ticks a box or types their name in a document, that is an electronic signature. It is quick and easy. It also tells you almost nothing about who actually did it, and if it is ever challenged, the burden of proof falls on you.
A Qualified Electronic Signature is different. Before one can be created, the person signing must have their identity verified to a legally defined standard - certified by a Qualified Trust Service Provider (QTSP) that is regulated under EU law. The signature is then cryptographically bound to that verified identity. It cannot be forged, replicated, or credibly denied.
Under EU law, a QES carries the same legal weight as a handwritten signature in every member state. More importantly for regulated businesses: if someone disputes a QES, they bear the burden of proving it was not them. That reversal matters when you are dealing with loan agreements, account openings, and compliance obligations that need to stand up to regulatory scrutiny.
QES is also the only signature type that satisfies AMLR's preferred methods for remote customer verification from July 2027. It is not the only way to be compliant, but it is the most robust, the most future-proof, and when implemented well, the fastest and least friction-heavy for your customer.
SES: Simple Electronic Signature
A tick, typed name, or image. No identity check. No legal equivalence to a handwritten signature.
AES: Advanced Electronic Signature
Uniquely linked to the signer. Some identity verification, but not certified to a legal standard.
QES: Qualified Electronic Signature
Identity verified to the highest legal standard by a certified QTSP. Legally equivalent to a handwritten signature across the EU. Non-repudiable.
Two regulations and a technical standard changed simultaneously: eIDAS 2.0, AMLR, and ETSI v2. Most companies are treating them as separate deadlines. They are not. They were designed to work together as one coordinated shift in how identity verification works across Europe.
IN FORCE NOW
✓ eIDAS 2.0
MAY 2024
The infrastructure is here. Every EU citizen will have access to a government-issued digital identity wallet and will be able to use it to create a QES. Identity liability shifts from businesses to governments when customers use official credentials. The system is already being deployed.
○ AMLR
JULY 10, 2027
One AML rulebook replaces 27 national frameworks. For remote customer verification, eIDAS-compliant methods (QES, notified eIDs, and the EUDI Wallet) become the preferred methods. Video identification is demoted to a fallback: still permitted, but only where preferred methods cannot be provided, and you must document why every time you use it.
○ ETSI v2
AUGUST 2027
Updated technical standards for QES identity proofing become mandatory. Providers must be certified against AI-powered attacks; deepfakes, injection attacks, presentation attacks. Only certified providers can deliver compliant QES after this date.
Why QES is more fraud-resistant
Deepfakes convincing enough to fool video calls now exist commercially and are being used in fraud operations targeting onboarding flows across Europe. QES identity proofing must meet ETSI standards specifically designed to detect synthetic identities and AI-generated images. The deepfake that passes a video call cannot pass a QES identity check.
Why QES provides a better experience for your customer
A 30 minute wait to be connected to an operator is not the experience customers expect when opening an account in 2026. QES is fully digital, available at any hour, and completed in one uninterrupted flow. No waiting room, no booking screen, no business hours restriction. The customer is done before they have time to reconsider.
Your customer has photographed their ID, completed a liveness check, and read the agreements. This is when most qualified signing flows send them an SMS code and wait. That's the worst possible place to introduce a dependency. The code doesn't arrive. They're roaming, or on a train, or the number on file is old. They switch apps to find it and don't come back. Every one of those is a customer you'd already paid to acquire, lost at the final step, and a support ticket on top.
Our QES flow does not require a SMS code. As a QTSP, we link authentication directly to the identity verification. The signature is bound to the check that just happened, not to a phone number.
No failed or delayed messages
No dependency on mobile signal or roaming
No SIM-swap exposure
No support tickets about codes that never came
No per-message cost at scale
WHY FOURTHLINE
ID Verification + QES
The customer proves who they are and signs in a single journey. Full identity verification followed immediately by a qualified electronic signature. This is the core AMLR-compliant onboarding flow for customers without an existing eID.
Preferred method under AMLR Article 22
eID + QES
For customers who have a national eID or EUDI Wallet, the identity step uses their existing government-issued credential. QES is then issued on top. Faster for the customer, less friction, fully compliant. No additional integration needed when the EUDI Wallet arrives.
Works with EUDI Wallet



