- Can remote onboarding be carried out in compliance with AML/CFT regulations?
- Yes. Remote onboarding is permitted provided that additional due diligence measures are implemented (art. L561-10 of the Monetary and Financial Code and associated regulatory provisions). Certyneo enables the file to be signed with strong identification (dual-channel OTP) and qualified timestamping that traces each step.
- Does electronic signature replace the identity verification required by article L561-5?
- No, it complements it. Article L561-5 requires verifying identity on a reliable document; electronic signature does not replace this documentary verification, but it timestamps the document collection, authenticates the customer via OTP and seals the file with an enforceable audit trail.
- How to prove the ongoing due diligence required by article L561-6?
- Article L561-6 requires updating customer knowledge throughout the relationship. Certyneo preserves each signed version of the file with its audit trail, which makes it possible to demonstrate to ACPR the dates and content of each due diligence update.
- How long must the KYC file be kept?
- Five years from the end of the business relationship (art. L561-12 of the Monetary and Financial Code). Certyneo automatically archives the signed file and its eIDAS audit trail, accessible in one click for any ACPR inspection.
- Is the audit trail enforceable against ACPR and usable for a TRACFIN declaration?
- Yes. The Certyneo audit trail (identity verified by OTP, qualified timestamp, SHA-256 hash) documents each AML/KYC diligence. It is exportable as a certified PDF, enforceable against ACPR to demonstrate compliance of the customer onboarding device, and usable to support a suspicious activity report to TRACFIN.
- What is the role of the Banque de France and the ACPR in KYC supervision?
- The Banque de France does not perform KYC on behalf of institutions: the ACPR, an authority attached to the Banque de France, supervises the compliance of banks' and insurers' KYC and AML frameworks and sanctions breaches. The Banque de France also manages the files consulted during onboarding (FICP, FCC), and TRACFIN receives suspicious-activity reports. A KYC file signed electronically, with a timestamped audit trail, makes it much easier to demonstrate compliance during an inspection.