KYC Documents: Electronic Signature for Banking Compliance in 2026
KYC process digitalisation is transforming banking and financial practices. Discover how electronic signature secures your Know Your Customer obligations in 2026.
Équipe éditoriale Certyneo
Writer — Certyneo · About Certyneo

Introduction: Why KYC has become a strategic priority
KYC (Know Your Customer) refers to the set of identity verification procedures that a financial institution must implement before entering into a business relationship with a customer. In 2026, European supervisory authorities — ACPR in France, EBA at the European level — require increased rigour in the collection, authentication and preservation of KYC documents. Electronic signature has become the technological pivot enabling the reconciliation of customer experience fluidity, evidential value of documents and regulatory compliance. This guide explains the stakes, legal requirements and best practices for implementing an electronically signed KYC process in the banking and financial sector.
---
KYC fundamentals and its documentary dimension
KYC rests on three fundamental pillars: customer identification, verification of their identity and continuous monitoring of the business relationship. Each of these pillars generates significant document flows that must be authenticated, time-stamped and retained in a probative manner.
Documents collected in a KYC process
A typical KYC file comprises:
- Identity documents: national identity card, passport, residence permit
- Proof of address: utility bills, bank statements dated less than three months ago
- Documents relating to professional activity: company registry extract (Kbis), articles of association, annual accounts for legal entities
- Declarative forms: declaration of beneficial owners, tax residency certificate, FATCA/CRS form
- Framework agreements: account opening contracts, management mandates, payment service agreements
Each of these documents must be signed, dated and traceable. The question is therefore no longer whether electronic signature has a place in KYC, but rather determining which level of signature is required for each act.
eIDAS signature levels applicable to KYC
The eIDAS regulation (n°910/2014) distinguishes three levels of electronic signature, whose relevance varies according to the nature of the KYC document:
| Level | KYC Applicability | Requirements | |--------|------------------|----------| | Simple (SES) | Low-risk declarative forms | Link between signatory and document | | Advanced (AES) | Account agreements, standard mandates | Verified identity, guaranteed integrity, optional qualified certificate | | Qualified (QES) | Banking powers, representation mandates, high legal value acts | Qualified certificate issued by accredited PSCO |
Advanced electronic signature constitutes the minimum recommended level for the vast majority of banking KYC documents. For electronic signature processes in business subject to enhanced regulatory obligations, qualified signature becomes essential.
---
Digital KYC: specific regulatory requirements for the financial sector
Credit institutions, investment firms and payment service providers are subject to a dense regulatory framework that directly conditions the design of their electronic KYC system.
The 5th Anti-Money Laundering Directive (AMLD5) and its impact on digital KYC
Transposed into French law by Ordinance No. 2020-1342 of 4 November 2020, the 5th Anti-Money Laundering Directive (2018/843/EU) opened the way to remote identification by explicitly recognising electronic identification means notified under eIDAS. It notably imposes:
- Enhanced verification for high-risk customers (PEPs, high-risk third countries)
- Complete traceability of due diligence carried out
- Data retention for five years from the end of the business relationship
- Obligation for periodic updates to customer files
The 6th AMLD Directive (2021/1237), whose transposition is expected before end of 2026, further strengthens these obligations with the introduction of a European digital identity space (eID) and harmonisation of watchlists.
DSP2 and strong authentication: the interface with KYC
The Payment Services Directive DSP2 (2015/2366/EU) imposes strong customer authentication (SCA) for sensitive operations. In the KYC context, this requirement materialises during:
- Entry into a remote business relationship (100% digital account opening)
- Signing of an amendment modifying the essential characteristics of the account
- Addition of an unusual payment recipient
Strong authentication requires the combination of at least two factors from: knowledge (password), possession (smartphone, token) and inherence (biometrics). This system naturally articulates with advanced electronic signature, whose issuance process incorporates these authentication factors. To understand the subtleties of the eIDAS regulation and its developments towards eIDAS 2.0, a dedicated guide provides you with all the keys.
EBA recommendations on digital onboarding
The European Banking Authority (EBA) published in 2022 its guidelines on the use of remote identification solutions in the context of KYC (EBA/GL/2022/15). These guidelines specify the conditions under which an institution can rely on electronic identity verification solutions without the customer's physical presence, particularly:
- Use of automated document verification technologies (OCR, NFC)
- Integration of a liveness detection step to prevent deepfake fraud
- Complete audit trail enabling full reconstruction of the identification session
- Substantial or high level of confidence under eIDAS for medium or high-risk customers
---
Implementing an electronically signed KYC workflow: architecture and best practices
Implementing an entirely digitalised KYC process requires precise articulation between technical components and regulatory requirements.
Components of an integrated KYC-signature solution
A robust KYC electronic signature system is based on:
- Document collection module: secure portal enabling customers to upload supporting documents, with consistency checks (format, readability, authenticity)
- Identity verification engine: OCR coupled with biometric verification to extract and verify identity document data
- Electronic signature engine: signature certificate issuance, signature application to contractual documents, audit report generation
- [Qualified electronic time-stamping](/guide/horodatage-electronique): certified time stamp applied to each signed document, guaranteeing date certainty
- Digital safe: retention of signed documents for the legal duration (5 years minimum post-business relationship)
- Compliance dashboard: real-time tracking of KYC status for each customer, alerts on files requiring renewal
Management of beneficial owners and delegation chains
Verification of beneficial owners (UBO — Ultimate Beneficial Owners) represents one of the most complex KYC challenges for legal entities. Institutions must identify any natural person holding, directly or indirectly, more than 25% of capital or voting rights.
This requirement generates signature chains involving multiple signatories (managers, mandatories, legal representatives) with different authorisation levels. Advanced electronic signature enables management of these multi-signatory workflows with complete traceability of each signature act. The legal value of each electronic signature in these delegation chains must be carefully documented.
KYC renewal: automating periodic updates
AML-CFT (anti-money laundering and counter-terrorist financing) requirements impose periodic review of customer files according to their risk profile:
- Low risk: every 5 years
- Medium risk: every 3 years
- High risk: annually
Automating these reviews through electronic signature workflows significantly reduces the operational burden on compliance teams. Automatic alerts are triggered as deadlines approach, and customers are invited to update their documents via a secure digital journey. For institutions already having a signature solution, it may be relevant to evaluate switching to a more integrated platform.
---
Data security and privacy protection in electronic KYC
Processing KYC data involves some of the most sensitive information: identity data, biometric data, patrimonial information. GDPR compliance is essential with particular acuity.
GDPR and KYC: applicable legal bases
Personal data processing undertaken within the framework of KYC rests on two main legal bases under Article 6 of the GDPR:
- Legal obligation (art. 6.1.c): AML-CFT imposes collection and verification of identification data
- Contract performance (art. 6.1.b): account opening requires customer identification
For biometric data (liveness detection, facial recognition), Article 9 of the GDPR imposes a specific legal basis, generally the explicit consent of the customer or an express legal obligation. An impact assessment (DPIA) is mandatory before any deployment of these technologies.
Data minimisation and retention periods
The minimisation principle requires collecting only data strictly necessary for the KYC purpose. Original documents can be replaced by extracted data (name, surname, document number, validity date) once verification has been performed. The maximum retention period for biometric data is 3 years from collection, unless legally otherwise required.
Institutions must also ensure the right to erasure (art. 17 GDPR), while reconciling it with AML-CFT retention obligations — a legal tension requiring precise document management policy.
Legal framework applicable to KYC and electronic signature
Founding European texts
The legal system governing electronic KYC in France is structured around several superimposed regulatory layers:
eIDAS Regulation n°910/2014 (EU): establishes the legal framework for electronic signature in the European Union. Article 25 sets the principle of non-discrimination: an electronic signature cannot be rejected solely on the ground that it is in electronic form. Articles 26 to 29 define the requirements respectively applicable to advanced and qualified signatures. The eIDAS 2.0 revision (Regulation 2024/1183/EU) strengthens these provisions and introduces the European Digital Identity Wallet (EUDIW).
5th Anti-Money Laundering Directive (2018/843/EU) and 6th AMLD: directly condition due diligence and identification obligations. The French transposition appears in Articles L.561-1 et seq. of the Monetary and Financial Code, as well as in the Decree of 6 January 2021 relating to the AML-CFT system and internal control.
DSP2 Directive (2015/2366/EU) and Delegated Regulation 2018/389: impose strong authentication (SCA) and condition the issuance of payment instruments.
French civil law and evidentiary value
Article 1366 of the French Civil Code provides that an electronic writing has the same probative force as writing on paper support, provided that its author can be duly identified and that it is established and retained under conditions such as to guarantee its integrity. Article 1367 recognises electronic signature when it consists of the use of a reliable identification process guaranteeing its link with the act to which it attaches.
Decree No. 2017-1416 specifies the conditions under which electronic signature is presumed reliable, notably by reference to eIDAS requirements for qualified signature.
ETSI technical standards
The standards ETSI EN 319 132 (XAdES, CAdES and PAdES formats) define electronic signature format standards. In the KYC context, the PAdES format (PDF Advanced Electronic Signatures) is preferred as it integrates the signature directly into the PDF file, ensuring consistency between the visual document and its cryptographic signature.
The ETSI EN 319 401 standard frames general requirements applicable to trust service providers (TSP), which include qualified electronic signature providers. In France, ANSSI supervises these providers and publishes the national trust list (TL-FR).
Legal risks in case of non-compliance
A non-compliant KYC system exposes the institution to significant sanctions: ACPR can pronounce disciplinary sanctions (warning, censure, temporary prohibition of exercise) and pecuniary sanctions that can reach 100 million euros or 10% of net annual turnover. The MiCA Directive (2023/1114/EU) extends these obligations to crypto-asset service providers (PSAN/PSCA) from 2024, further strengthening the KYC scope to monitor.
Use scenarios: electronic KYC in practice
Scenario 1 — Online bank and 100% digital onboarding
A European online banking startup processing approximately 15,000 new account openings per month seeks to reduce its KYC process abandonment rate, then estimated at 34% due to friction linked to postal document submission. The bank deploys a fully digital journey: the prospect captures their identity document via mobile (NFC verification of the security chip of the secure document), performs a liveness selfie, then electronically signs the account agreement and beneficial owner declaration via an eIDAS-compliant advanced signature.
Results observed after 6 months of deployment: KYC abandonment rate drops to 11% (a 67% reduction), average account opening time falls from 5 business days to less than 20 minutes, and the unit cost of processing a KYC file decreases by 58%. The automatically generated audit trail enables response in less than 4 hours to ACPR justification requests during inspections.
Scenario 2 — Asset management company and investor KYC
An asset management company managing approximately 2.8 billion euros in assets for 1,200 institutional and particularly high-net-worth individual clients (UHNWI) must renew KYC files annually for high-risk customers. Traditionally carried out by postal submission and handwritten signature, this process mobilised 3 full-time equivalents for 6 weeks each year.
After deploying a qualified electronic signature KYC solution (QES) for management mandates and banking powers, combined with advanced signature for update questionnaires, the company reduces the annual renewal process duration from 6 weeks to 8 business days. The return rate of complete files before deadline rises from 71% to 96%, virtually eliminating regulatory blocking situations. The time-stamped traceability of each signature allows precise justification of update date to the regulator.
Scenario 3 — Specialised credit institution and business KYC
A specialised credit institution financing SMEs processes approximately 800 loan files annually, each requiring the collection and signature of 12 to 18 KYC documents (articles of association, company registry extract, certified accounts, beneficial owner declaration, credit agreement, personal guarantees). The multiplicity of signatories (manager, co-borrowing spouse, joint guarantor) complicated workflows and prolonged implementation times.
The institution deploys multi-signatory signature workflows with configurable signing order: the manager signs first, automatically triggers the co-borrower invitation, then the guarantor. Each signatory is authenticated by reinforced SMS OTP and document identity verification. The average time to complete a KYC file drops from 18 days to 4 business days, significantly accelerating financing implementation timelines and improving customer satisfaction (NPS increase of 22 points in the SME segment).
Conclusion
The convergence between KYC requirements in the financial sector and the capabilities of electronic signature draws in 2026 a new standard for onboarding and banking compliance management. Whether initial identification of an individual customer, verification of beneficial owners of a complex structure or periodic renewal of files, electronic signature — advanced or qualified depending on stakes — provides the probative rigour that regulators require, whilst enhancing customer experience fluidity.
The legal framework is stabilised: eIDAS, AML-CFT, DSP2 and GDPR form a coherent foundation upon which institutions can rely to digitalise their processes with complete security.
Certyneo proposes an eIDAS-compliant electronic signature solution, integrated and auditable, specially adapted to the constraints of financial actors. Discover our pricing and start your free trial to transform your KYC workflows today.
Try Certyneo for free
Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.
Take action
Sign a KYC file / get in touch online
Sign this document online with an eIDAS-compliant electronic signature.
Dive deeper
Our comprehensive guides to master electronic signatures.
Recommended articles
Deepen your knowledge with these articles related to the topic.

Electronic Signature for Mortgage Loans in 2026
Electronic signature is profoundly transforming the real estate credit sector. Discover the required levels, legal obligations, and concrete benefits for banks and borrowers.

Electronic Signature in Finance: Compliance 2026
The financial sector faces increasing regulatory requirements for electronic signatures. Discover how to reconcile operational efficiency with eIDAS, DORA and GDPR compliance in 2026.

ISO Certification for Electronic Signature: 2026 Guide
ISO 27001, eIDAS, ETSI… certifications from electronic signature service providers have become an essential selection criterion. Discover how to compare them effectively.