Skip to main content
Certyneo

KYC Documents: Electronic Signature for Banking Compliance in 2026

KYC process digitalisation is transforming banking and financial practices. Discover how electronic signature secures your Know Your Customer obligations in 2026.

Équipe éditoriale Certyneo12 min read

Équipe éditoriale Certyneo

Editor — Certyneo · About Certyneo

a woman holding a cell phone in her hand

Introduction: Why KYC Has Become a Strategic Priority

KYC (Know Your Customer) refers to the set of identity verification procedures that a financial institution must implement before entering into a business relationship with a customer. In 2026, European supervisory authorities — ACPR in France, EBA at the European level — require increased rigour in the collection, authentication and retention of KYC documents. Electronic signature has become the technological pivot enabling reconciliation of fluidity of the customer experience, probative value of documents and regulatory compliance. This guide explains the stakes, legal requirements and best practices for deploying an electronically signed KYC process in the banking and financial sector.

---

KYC Fundamentals and Its Documentary Dimension

KYC rests on three fundamental pillars: client identification, verification of identity and ongoing surveillance of the business relationship. Each of these pillars generates significant documentary flows that must be authenticated, timestamped and retained in a probative manner.

Documents Collected in a KYC Process

A typical KYC file comprises:

  • Identity documents: national identity card, passport, residence permit
  • Proof of residence: energy bills, bank statements less than three months old
  • Documents relating to professional activity: business registration certificate (Kbis), articles of association, annual accounts for legal entities
  • Declaration forms: beneficial ownership declaration, tax residence certificate, FATCA/CRS form
  • Master agreements: account opening contracts, management mandates, payment service conventions

Each of these documents must be signed, dated and traceable. The question is therefore no longer whether electronic signature has a place in KYC, but rather to determine what signature level is required for each act.

eIDAS Signature Levels Applicable to KYC

The eIDAS regulation (No. 910/2014) distinguishes three levels of electronic signature, whose relevance varies depending on the nature of the KYC document:

| Level | KYC Applicability | Requirements | |-------|------------------|--------------| | Simple (SES) | Low-risk declaration forms | Link between signatory and document | | Advanced (AES) | Account conventions, standard mandates | Verified identity, integrity guaranteed, qualified certificate optional | | Qualified (QES) | Banking powers, representation mandates, high-value legal acts | Qualified certificate issued by approved eIDAS PSCO |

Advanced electronic signature constitutes the minimum recommended level for the vast majority of banking KYC documents. For electronic signature processes in business subject to enhanced regulatory obligations, qualified signature becomes essential.

---

Digital KYC: Regulatory Requirements Specific to the Financial Sector

Credit institutions, investment firms and payment service providers are subject to a dense regulatory framework that directly conditions the design of their electronic KYC system.

The 5th Anti-Money Laundering Directive (AMLD5) and Its Impact on Digital KYC

Transposed into French law by ordinance No. 2020-1342 of 4 November 2020, the 5th anti-money laundering directive (2018/843/EU) paved the way for remote identification by explicitly recognising electronic identification means notified under eIDAS. It notably imposes:

  • Enhanced verification for high-risk customers (PEPs, high-risk third countries)
  • Complete traceability of diligence performed
  • Data retention for five years from the end of the business relationship
  • Obligation to periodically update client files

The 6th directive AMLD (2021/1237), whose transposition is expected before the end of 2026, further strengthens these obligations by introducing a European digital identity space (eID) and harmonising watchlists.

DSP2 and Strong Authentication: The Interface with KYC

The Payment Services Directive DSP2 (2015/2366/EU) imposes strong customer authentication (SCA) for sensitive transactions. In the KYC context, this requirement materialises during:

  • Entry into remote relationship (100% digital account opening)
  • Signing an amendment modifying essential account characteristics
  • Adding a non-habitual transfer beneficiary

Strong authentication requires the combination of at least two factors among: knowledge (password), possession (smartphone, token) and inherence (biometrics). This system articulates naturally with advanced electronic signature, whose issuance process incorporates these authentication factors. To understand the subtleties of the eIDAS regulation and its developments towards eIDAS 2.0, a dedicated guide provides you with all the keys.

EBA Recommendations on Digital Onboarding

The European Banking Authority (EBA) published its guidelines in 2022 on the use of remote identification solutions in the context of KYC (EBA/GL/2022/15). These guidelines clarify the conditions under which an institution may rely on electronic identity verification solutions without the physical presence of the customer, notably:

  • Use of automated document verification technologies (OCR, NFC)
  • Integration of a liveness detection step to prevent deepfake fraud
  • Complete audit trail enabling reconstitution of the entire identification session
  • Level of confidence substantial or high under eIDAS for customers with medium or high risk

---

Deploying an Electronically Signed KYC Workflow: Architecture and Best Practices

Implementing a fully digitalised KYC process requires precise articulation between technical components and regulatory requirements.

Components of an Integrated KYC-Signature Solution

A robust KYC electronic signature system is based on:

  1. Documentary collection module: secure portal allowing the customer to upload supporting documents, with consistency control (format, legibility, authenticity)
  2. Identity verification engine: OCR coupled with biometric verification to extract and check data from the identity document
  3. Electronic signature engine: signature certificate issuance, signature application to contractual documents, audit report generation
  4. [Qualified electronic timestamping](/guide/horodatage-electronique): certified timestamp affixed to each signed document, guaranteeing the certain date
  5. Digital safe: retention of signed documents for the legal duration (5 years minimum post-business relationship)
  6. Compliance dashboard: real-time monitoring of each customer's KYC status, alerts on files to be renewed

Management of Beneficial Owners and Delegation Chains

Verification of beneficial owners (UBO — Ultimate Beneficial Owners) represents one of the most complex challenges in KYC for legal entities. Institutions must identify any natural person holding, directly or indirectly, more than 25% of capital or voting rights.

This requirement generates signature chains involving multiple signatories (directors, authorised representatives, legal representatives) with different authorisation levels. Advanced electronic signature enables management of these multi-signatory workflows with complete traceability of each signing act. The legal value of each electronic signature in these delegation chains must be carefully documented.

KYC Renewal: Automating Periodic Updates

AML/CFT (anti-money laundering and countering the financing of terrorism) imposes a periodic review of client files according to their risk profile:

  • Low risk: every 5 years
  • Medium risk: every 3 years
  • High risk: annually

Automating these reviews via electronic signature workflows significantly reduces the operational burden on compliance teams. Automated alerts are triggered as deadlines approach, and the customer is invited to update documents via a secure digital pathway. For institutions already having a signature solution, it may be worthwhile to evaluate a switch to a more integrated platform.

---

Data Security and Privacy Protection in Electronic KYC

Processing KYC data involves some of the most sensitive information: identity data, biometric data, wealth information. GDPR compliance is particularly acute.

Personal data processing undertaken in the context of KYC rests on two main legal bases under Article 6 of the GDPR:

  • Legal obligation (Art. 6.1.c): AML/CFT law requires collection and verification of identification data
  • Contract performance (Art. 6.1.b): account opening requires customer identification

For biometric data (liveness detection, facial recognition), Article 9 of the GDPR imposes a specific legal basis, generally explicit consent from the customer or an express legal obligation. A Data Protection Impact Assessment (DPIA) is mandatory before any deployment of these technologies.

Data Minimisation and Retention Periods

The minimisation principle requires collection only of data strictly necessary for the KYC purpose. Original documents can be replaced by extracted data (name, forename, document number, expiry date) once verification has been performed. The maximum retention period for biometric data is 3 years from collection, unless otherwise required by law.

Institutions must also ensure the right to erasure (Art. 17 GDPR), whilst reconciling this with AML/CFT retention obligations — a legal tension requiring a precise document management policy.

Founding European Texts

The legal framework governing electronic KYC in France is articulated around several superimposed regulatory layers:

Regulation eIDAS No. 910/2014 (EU): establishes the legal framework for electronic signature in the European Union. Article 25 poses the principle of non-discrimination: an electronic signature cannot be rejected on the sole ground that it is in electronic form. Articles 26 to 29 define the requirements respectively applicable to advanced and qualified signatures. The eIDAS 2.0 revision (Regulation 2024/1183/EU) strengthens these provisions and introduces the European digital identity wallet (EUDIW).

5th anti-money laundering directive (2018/843/EU) and 6th AMLD directive: directly condition vigilance and identification obligations. French transposition appears in Articles L.561-1 et seq. of the Monetary and Financial Code, as well as in the Order of 6 January 2021 relating to AML/CFT internal control systems.

DSP2 Directive (2015/2366/EU) and delegated regulation 2018/389: impose strong authentication (SCA) and condition the issuance of payment instruments.

French Civil Law and Probative Value

Article 1366 of the Civil Code provides that an electronic document has the same probative force as a document on paper support, provided that its author can be duly identified and that it is drawn up and retained in conditions of a nature to guarantee its integrity. Article 1367 recognises electronic signature when it consists of the use of a reliable identification process guaranteeing its connection to the act to which it is attached.

Decree No. 2017-1416 clarifies the conditions under which electronic signature is presumed reliable, notably by referral to eIDAS requirements for qualified signature.

ETSI Technical Standards

The standards ETSI EN 319 132 (XAdES, CAdES and PAdES formats) define standards for electronic signature formats. In the KYC context, the PAdES format (PDF Advanced Electronic Signatures) is preferred because it integrates the signature directly into the PDF file, ensuring consistency between the visual document and its cryptographic signature.

The standard ETSI EN 319 401 frames general requirements applicable to trust service providers (TSP), including electronic signature providers. In France, ANSSI supervises these providers and publishes the national trust list (TL-FR).

A non-compliant KYC system exposes the institution to significant sanctions: the ACPR may impose disciplinary sanctions (warning, reprimand, temporary prohibition from practising) and financial penalties of up to 100 million euros or 10% of net annual turnover. The MiCA directive (2023/1114/EU) extends these obligations to crypto-asset service providers (CASP/CSSP) from 2024, further broadening the scope of KYC to monitor.

Use Cases: Electronic KYC in Practice

Scenario 1 — Online Bank and 100% Digital Onboarding

A European neobank processing approximately 15,000 new account openings per month seeks to reduce its KYC process abandonment rate, then estimated at 34% due to friction caused by postal document submission. The bank deploys a fully digital pathway: the prospect captures their identity document via mobile (NFC verification of the secure title chip), performs a liveness selfie, then electronically signs the account convention and beneficial ownership declaration via an eIDAS-compliant advanced signature.

Results observed after 6 months of deployment: the KYC abandonment rate drops to 11% (a 67% reduction), the average account opening time falls from 5 working days to less than 20 minutes, and the unit cost of processing a KYC file decreases by 58%. The automatically generated audit trail enables response to ACPR justification requests during inspections in less than 4 hours.

Scenario 2 — Asset Management Company and Investor KYC

An asset management company managing approximately €2.8 billion in assets for approximately 1,200 institutional and high-net-worth individual clients (UHNWI) must annually renew KYC files for its high-risk customers. Traditionally carried out by postal submission and manuscript signature, this process involved 3 full-time equivalents for 6 weeks annually.

After deploying a qualified electronic signature (QES) KYC solution for management mandates and banking powers, combined with advanced signature for update questionnaires, the company reduces the annual renewal process duration from 6 weeks to 8 working days. The rate of complete file returns before deadline increases from 71% to 96%, nearly eliminating regulatory blocking situations. The timestamped traceability of each signature enables precise justification of the update date to the regulator.

Scenario 3 — Specialised Credit Institution and Enterprise KYC

A specialised institution financing SMEs processes approximately 800 credit applications per year, each requiring collection and signature of 12 to 18 KYC documents (articles, Kbis, certified accounts, beneficial owners declaration, credit convention, personal guarantees). The multiplicity of signatories (director, co-borrowing spouse, guarantor) complicated workflows and prolonged implementation timelines.

The institution deploys multi-signatory signature workflows with parameterisable signing order: the director signs first, automatically triggers the co-borrower's invitation, then the guarantor's. Each signatory is authenticated by reinforced SMS OTP and documentary identity verification. The average time to complete a full KYC file drops from 18 days to 4 working days, enabling significantly faster financing implementation and improved customer satisfaction (NPS up 22 points in the SME segment).

Conclusion

The convergence between KYC requirements in the financial sector and electronic signature capabilities defines in 2026 a new standard for onboarding and banking compliance management. Whether it is the initial identification of an individual customer, verification of beneficial owners of a complex structure or periodic renewal of files, electronic signature — advanced or qualified depending on stakes — provides the probative rigour that regulators demand, whilst streamlining customer experience.

The legal framework is stable: eIDAS, AML/CFT, DSP2 and GDPR form a coherent foundation on which institutions can rely to digitalise their processes with confidence.

Certyneo offers an eIDAS-compliant, integrated and auditable electronic signature solution, specially adapted to the constraints of financial actors. Discover our pricing and start your free trial to transform your KYC workflows today.

Try Certyneo for free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Take action

Sign a KYC file / online account opening

Sign this document online with an eIDAS-compliant electronic signature.

Sign now

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.