Skip to main content
Certyneo

KYC Documents: Electronic Signature for Banking Compliance

The digitalisation of KYC processes is transforming banking and financial practices. Discover how electronic signature secures your Know Your Customer obligations in 2026.

Équipe éditoriale Certyneo12 min read

Équipe éditoriale Certyneo

Writer — Certyneo · About Certyneo

a woman holding a cell phone in her hand

Introduction: why KYC has become a strategic issue

KYC (Know Your Customer) refers to the set of identity verification procedures that a financial institution must implement before entering into a business relationship with a customer. In 2026, European supervisory authorities — ACPR in France, EBA at European level — require increased rigour in the collection, authentication and preservation of KYC documents. Electronic signature emerges as the technological pivot enabling the reconciliation of customer experience fluidity, evidentiary value of documents and regulatory compliance. This guide explains the stakes, legal requirements and best practices for deploying an electronically signed KYC process in the banking and financial sector.

---

KYC fundamentals and its documentary dimension

KYC is built on three fundamental pillars: customer identification, verification of identity and ongoing monitoring of the business relationship. Each of these pillars generates significant documentary flows that must be authenticated, timestamped and preserved in a probative manner.

Documents collected in a KYC process

A typical KYC file comprises:

  • Identity documents: national identity card, passport, residence permit
  • Proof of address: utility bills, bank statements dated less than three months old
  • Documents relating to professional activity: Kbis certificate, articles of association, annual accounts for legal entities
  • Declarative forms: declaration of beneficial owners, certificate of tax residence, FATCA/CRS form
  • Framework agreements: account opening contracts, management mandates, payment service conventions

Each of these documents must be signed, dated and traceable. The question is therefore no longer whether electronic signature has a place in KYC, but rather determining which level of signature is required for each act.

eIDAS signature levels applicable to KYC

The eIDAS regulation (no. 910/2014) distinguishes three levels of electronic signature, with applicability varying depending on the nature of the KYC document:

| Level | KYC Applicability | Requirements | |--------|------------------|----------| | Simple (SES) | Declarative forms with low risk | Link between signatory and document | | Advanced (AES) | Account conventions, standard mandates | Verified identity, integrity guaranteed, optional qualified certificate | | Qualified (QES) | Banking powers, representation mandates, acts of high legal value | Qualified certificate issued by approved eIDAS QTSP |

The advanced electronic signature constitutes the minimum recommended level for the vast majority of banking KYC documents. For electronic signature processes in business subject to enhanced regulatory obligations, qualified signature becomes essential.

---

Digital KYC: regulatory requirements specific to the financial sector

Credit institutions, investment firms and payment service providers are subject to a dense regulatory stack that directly conditions the design of their electronic KYC system.

The 5th Anti-Money Laundering Directive (AMLD5) and its impact on digital KYC

Transposed into French law by ordinance no. 2020-1342 of 4 November 2020, the 5th Anti-Money Laundering Directive (2018/843/EU) opened the door to remote identification by explicitly recognising electronic means of identification notified pursuant to eIDAS. It notably requires:

  • Enhanced verification for high-risk customers (PEPs, third countries at risk)
  • Complete traceability of due diligence carried out
  • Data preservation for five years from the end of the business relationship
  • Obligation to periodically update customer files

The 6th AMLD Directive (2021/1237), whose transposition is expected by the end of 2026, further strengthens these obligations by introducing a European digital identity space (eID) and harmonising watch-lists.

DSP2 and strong authentication: the interface with KYC

The Payment Services Directive DSP2 (2015/2366/EU) imposes strong customer authentication (SCA) for sensitive transactions. In the KYC context, this requirement materialises when:

  • Entering into a remote relationship (100% digital account opening)
  • Signing an amendment modifying the essential characteristics of the account
  • Adding an unusual transfer beneficiary

Strong authentication requires the combination of at least two factors among: knowledge (password), possession (smartphone, token) and inherence (biometrics). This system interfaces naturally with advanced electronic signature, whose issuance process integrates these authentication factors. To understand the subtleties of eIDAS regulation and its evolution towards eIDAS 2.0, a dedicated guide provides all the keys.

EBA recommendations on digital onboarding

The European Banking Authority (EBA) published in 2022 its guidelines on the use of remote identification solutions in the context of KYC (EBA/GL/2022/15). These guidelines clarify the conditions under which an institution may rely on electronic identity verification solutions without physical presence of the customer, in particular:

  • Use of automated document verification technologies (OCR, NFC)
  • Integration of a liveness detection step to prevent deepfake fraud
  • Complete audit trail enabling reconstruction of the entire identification session
  • Substantial or high level of assurance within the meaning of eIDAS for medium or high-risk customers

---

Deploying an electronically signed KYC workflow: architecture and best practices

The implementation of a fully digitalised KYC process requires precise articulation between technical components and regulatory requirements.

Components of an integrated KYC-signature solution

A robust KYC electronic signature system is built on:

  1. Document collection module: secure portal enabling customers to submit supporting documents, with consistency checks (format, legibility, authenticity)
  2. Identity verification engine: OCR coupled with biometric verification to extract and validate data from identity documents
  3. Electronic signature engine: signature certificate issuance, signature application to contractual documents, audit report generation
  4. [Qualified electronic timestamp](/guide/horodatage-electronique): certified time stamp applied to each signed document, guaranteeing the date
  5. Digital safe: preservation of signed documents for the legal duration (minimum 5 years post-business relationship)
  6. Compliance dashboard: real-time monitoring of each customer's KYC status, alerts for files requiring renewal

Management of beneficial owners and delegation chains

The verification of beneficial owners (UBO — Ultimate Beneficial Owners) represents one of the most complex challenges in KYC for legal entities. Institutions must identify any natural person holding, directly or indirectly, more than 25% of capital or voting rights.

This requirement generates signature chains involving multiple signatories (managers, representatives, legal representatives) with different levels of authorisation. Advanced electronic signature enables the management of these multi-signatory workflows with complete traceability of each signature act. The legal value of each electronic signature in these delegation chains must be carefully documented.

KYC renewal: automating periodic updates

AML/CFT (anti-money laundering and counter-terrorist financing) requires a periodic review of customer files according to their risk profile:

  • Low risk: every 5 years
  • Medium risk: every 3 years
  • High risk: annually

Automating these reviews through electronic signature workflows significantly reduces the operational burden on compliance teams. Automatic alerts are triggered as renewal dates approach, and customers are invited to update their documents through a secure digital journey. For institutions already using a signature solution, it may be relevant to assess a migration towards a more integrated platform.

---

Data security and privacy protection in electronic KYC

The processing of KYC data involves some of the most sensitive information: identity data, biometric data, financial information. GDPR compliance is essential.

Personal data processing carried out in the context of KYC is based on two main legal bases within the meaning of Article 6 of the GDPR:

  • Legal obligation (Art. 6.1.c): AML/CFT law requires the collection and verification of identification data
  • Contract performance (Art. 6.1.b): account opening requires customer identification

For biometric data (liveness detection, facial recognition), Article 9 of the GDPR requires a specific legal basis, generally the explicit consent of the customer or an express legal obligation. An impact assessment (DPIA) is mandatory before any deployment of these technologies.

Data minimisation and retention periods

The minimisation principle requires collecting only data strictly necessary for KYC purposes. Original documents may be replaced by extracted data (name, forename, document number, date of validity) once verification has been completed. The maximum retention period for biometric data is 3 years from collection, unless otherwise legally required.

Institutions must also ensure the right to erasure (Art. 17 GDPR), whilst reconciling this with AML/CFT preservation obligations — a legal tension requiring precise document management policy.

Foundational European texts

The legal system governing electronic KYC in France articulates around several overlapping regulatory layers:

eIDAS Regulation no. 910/2014 (EU): establishes the legal framework for electronic signature in the European Union. Article 25 establishes the principle of non-discrimination: an electronic signature cannot be rejected solely on the grounds that it is in electronic form. Articles 26 to 29 define the requirements respectively applicable to advanced and qualified signatures. eIDAS 2.0 revision (Regulation 2024/1183/EU) strengthens these provisions and introduces the European digital identity wallet (EUDIW).

5th Anti-Money Laundering Directive (2018/843/EU) and 6th AMLD: directly condition vigilance and identification obligations. French transposition appears in Articles L.561-1 et seq. of the Monetary and Financial Code, as well as in the order of 6 January 2021 relating to AML/CFT internal controls and systems.

DSP2 Directive (2015/2366/EU) and delegated regulation 2018/389: require strong authentication (SCA) and condition the issuance of payment instruments.

French civil law and evidentiary value

Article 1366 of the Civil Code provides that electronic writings have the same evidentiary force as writings on paper, provided that its author can be duly identified and that it is established and preserved under conditions such as to guarantee its integrity. Article 1367 recognises electronic signature when it consists of the use of a reliable process of identification guaranteeing its link with the act to which it attaches.

Decree no. 2017-1416 clarifies the conditions under which electronic signature is presumed reliable, in particular by cross-reference to eIDAS requirements for qualified signature.

ETSI technical standards

The standards ETSI EN 319 132 (XAdES, CAdES and PAdES formats) define the standards for electronic signature format. In the KYC context, the PAdES format (PDF Advanced Electronic Signatures) is preferred as it embeds the signature directly in the PDF file, ensuring consistency between the visual document and its cryptographic signature.

The standard ETSI EN 319 401 governs the general requirements applicable to trust service providers (TSPs), which include qualified electronic signature providers. In France, ANSSI supervises these providers and publishes the national trust list (TL-FR).

A non-compliant KYC system exposes the institution to significant sanctions: ACPR may impose disciplinary sanctions (warning, censure, temporary ban from operating) and financial penalties of up to €100 million or 10% of net annual turnover. The MiCA Directive (2023/1114/EU) extends these obligations to crypto-asset service providers (PSAN/PSCA) from 2024 onwards, further extending the scope of KYC to be monitored.

Use cases: electronic KYC in practice

Scenario 1 — Online banking and 100% digital onboarding

A European neobank processing around 15,000 new account openings per month seeks to reduce its KYC process abandonment rate, then estimated at 34% due to friction from postal document submission. The bank deploys an entirely digital journey: the prospect captures their identity document via mobile (NFC verification of the security chip), performs a liveness selfie, then electronically signs the account convention and beneficial owner declaration via advanced signature compliant with eIDAS.

Results observed after 6 months of deployment: the KYC abandonment rate drops to 11% (a reduction of 67%), average account opening time falls from 5 working days to less than 20 minutes, and the unit cost of KYC file processing decreases by 58%. The automatically generated audit trail enables the bank to respond to ACPR justification requests within 4 hours during inspections.

Scenario 2 — Asset management company and investor KYC

An asset management company managing approximately €2.8 billion in assets for around 1,200 institutional and particularly wealthy private clients (UHNWI) must annually renew KYC files for its high-risk customers. Traditionally carried out by postal submission and manuscript signature, this process mobilised 3 full-time equivalents for 6 weeks each year.

Following deployment of a qualified electronic signature KYC solution (QES) for management mandates and banking powers, combined with advanced signature for update questionnaires, the company reduces the duration of the annual renewal process from 6 weeks to 8 working days. The rate of return of complete files before deadline rises from 71% to 96%, virtually eliminating regulatory blocking situations. The timestamped traceability of each signature also enables the firm to precisely justify the update date before the regulator.

Scenario 3 — Specialist credit institution and business KYC

A specialist institution in SME financing processes around 800 credit files per year, each requiring the collection and signature of 12 to 18 KYC documents (articles of association, Kbis, certified accounts, beneficial owner declaration, credit agreement, personal guarantees). The multiplicity of signatories (manager, co-borrowing spouse, joint guarantor) complicated workflows and extended implementation timescales.

The institution deploys multi-signatory signature workflows with customisable signature order: the manager signs first, automatically triggering the co-borrower's invitation, then the guarantor. Each signatory is authenticated via reinforced SMS OTP and document identity verification. The average time to complete a KYC file reduces from 18 days to 4 working days, enabling significant acceleration of financing implementation timescales and improved customer satisfaction (NPS increase of 22 points in the SME segment).

Conclusion

The convergence between KYC requirements in the financial sector and the capabilities of electronic signature draws a new standard in 2026 for onboarding and banking compliance management. Whether initial customer identification, verification of beneficial owners of complex structures or periodic renewal of files, electronic signature — advanced or qualified depending on stakes — provides the evidentiary rigour that regulators demand, whilst enhancing customer experience.

The legal framework is stabilised: eIDAS, AML/CFT, DSP2 and GDPR form a coherent foundation on which institutions can rely to digitalise their processes with confidence.

Certyneo offers an eIDAS-compliant, integrated and auditable electronic signature solution specially adapted to the constraints of financial actors. Discover our pricing and start your free trial to transform your KYC workflows today.

Try Certyneo for free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Take action

Sign a KYC file / online account opening

Sign this document online with an eIDAS-compliant electronic signature.

Sign now

Go deeper into this topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.