Skip to main content
Certyneo

KYC Documents: Electronic Signature for Banking Compliance

The digitalization of KYC processes is transforming banking and financial practices. Discover how electronic signature secures your Know Your Customer obligations in 2026.

Équipe éditoriale Certyneo12 min read

Équipe éditoriale Certyneo

Writer — Certyneo · About Certyneo

a woman holding a cell phone in her hand

Introduction: Why KYC Has Become a Strategic Issue

KYC (Know Your Customer) refers to the set of identity verification procedures that a financial institution must implement before entering into a business relationship with a customer. In 2026, European supervisory authorities — the ACPR in France, the EBA at European level — demand increased rigor in the collection, authentication, and preservation of KYC documents. Electronic signature emerges as the technological pivot enabling the reconciliation of fluidity in customer experience, probative value of documents, and regulatory compliance. This guide explains the issues, legal requirements, and best practices for deploying an electronically signed KYC process in the banking and financial sector.

---

KYC Fundamentals and Its Documentary Dimension

KYC rests on three fundamental pillars: customer identification, verification of identity, and continuous monitoring of the business relationship. Each of these pillars generates significant documentary flows that must be authenticated, time-stamped, and preserved in a probative manner.

Documents Collected in a KYC Process

A typical KYC file includes:

  • Identity documents: national identity card, passport, residence permit
  • Proof of residence: utility bills, bank statements dating less than three months
  • Documents relating to professional activity: corporate registration certificate, bylaws, annual accounts for legal entities
  • Declarative forms: beneficial ownership declaration, tax residence certificate, FATCA/CRS form
  • Framework agreements: account opening contracts, management mandates, payment service conventions

Each of these documents must be signed, dated, and traceable. The question is therefore no longer whether electronic signature has a place in KYC, but rather determining which signature level applies to each act.

The eIDAS Signature Levels Applicable to KYC

The eIDAS regulation (No. 910/2014) distinguishes three levels of electronic signature, whose relevance varies depending on the nature of the KYC document:

| Level | KYC Applicability | Requirements | |--------|------------------|----------| | Simple (SES) | Low-risk declarative forms | Link between signer and document | | Advanced (AES) | Account conventions, standard mandates | Verified identity, integrity guaranteed, qualified certificate optional | | Qualified (QES) | Banking powers, representation mandates, high legal value acts | Qualified certificate issued by approved PSCO under eIDAS |

The advanced electronic signature constitutes the minimum recommended level for the vast majority of banking KYC documents. For electronic signature processes in enterprises subject to enhanced regulatory obligations, qualified signature becomes essential.

---

Digital KYC: Regulatory Requirements Specific to the Financial Sector

Credit institutions, investment firms, and payment service providers are subject to a dense regulatory framework that directly conditions the design of their electronic KYC system.

The 5th Anti-Money Laundering Directive (AMLD5) and Its Impact on Digital KYC

Transposed into French law by ordinance No. 2020-1342 of November 4, 2020, the 5th anti-money laundering directive (2018/843/EU) paved the way for remote identification by explicitly recognizing electronic identification means notified under eIDAS. It requires in particular:

  • Enhanced verification for high-risk customers (PEPs, third countries at risk)
  • Complete traceability of diligence performed
  • Data preservation for five years from the end of the business relationship
  • The obligation to periodically update customer files

The 6th directive AMLD (2021/1237), whose transposition is expected before the end of 2026, further strengthens these obligations with the introduction of a European digital identity space (eID) and harmonization of surveillance lists.

DSP2 and Strong Authentication: Interface with KYC

The Payment Services Directive DSP2 (2015/2366/EU) imposes strong customer authentication (SCA) for sensitive operations. In the KYC context, this requirement materializes when:

  • Entering into a remote relationship (100% digital account opening)
  • Signing an amendment modifying essential account characteristics
  • Adding a beneficiary of non-habitual transfer

Strong authentication requires the combination of at least two factors among: knowledge (password), possession (smartphone, token), and inherence (biometrics). This system articulates naturally with advanced electronic signature, whose issuance process integrates these authentication factors. To understand the subtleties of the eIDAS regulation and its evolution toward eIDAS 2.0, a dedicated guide provides you with all the keys.

EBA Recommendations on Digital Onboarding

The European Banking Authority (EBA) published in 2022 its guidelines on the use of remote identification solutions as part of KYC (EBA/GL/2022/15). These guidelines specify the conditions under which an institution can rely on electronic identity verification solutions without physical presence of the customer, in particular:

  • Use of automated document verification technologies (OCR, NFC)
  • Integration of a liveness detection step to prevent deepfake fraud
  • Complete audit trail enabling the full reconstruction of the identification session
  • Confidence level of substantial or high under eIDAS for customers with medium or high risk

---

Deploying an Electronically Signed KYC Workflow: Architecture and Best Practices

The implementation of a fully digitalized KYC process requires precise articulation between technical components and regulatory requirements.

Components of an Integrated KYC-Signature Solution

A robust KYC electronic signature system relies on:

  1. Document collection module: secure portal allowing customers to submit their supporting documents, with coherence control (format, readability, authenticity)
  2. Identity verification engine: OCR coupled with biometric verification to extract and verify identity document data
  3. Electronic signature engine: signature certificate issuance, signature application to contractual documents, audit report generation
  4. [Qualified electronic time-stamping](/guide/horodatage-electronique): certified time-stamp applied to each signed document, guaranteeing the date of certainty
  5. Digital safe: preservation of signed documents for the legal duration (5 years minimum post-business relationship)
  6. Compliance dashboard: real-time tracking of each customer's KYC status, alerts on files needing renewal

Management of Beneficial Owners and Delegation Chains

The verification of beneficial owners (UBO — Ultimate Beneficial Owners) represents one of the most complex challenges of KYC for legal entities. Institutions must identify any natural person holding, directly or indirectly, more than 25% of capital or voting rights.

This requirement generates signature chains involving multiple signers (executives, proxies, legal representatives) with different authorization levels. Advanced electronic signature enables the management of these multi-signer workflows with complete traceability of each signature act. The legal value of each electronic signature in these delegation chains must be carefully documented.

KYC Renewal: Automating Periodic Updates

AML-FT (anti-money laundering and terrorist financing) requires periodic review of customer files according to their risk profile:

  • Low risk: every 5 years
  • Medium risk: every 3 years
  • High risk: annually

Automating these reviews through electronic signature workflows significantly reduces the operational burden on compliance teams. Automatic alerts are triggered as renewal dates approach, and the customer is invited to update their documents via a secured digital pathway. For institutions already with a signature solution, it may be relevant to evaluate a switch to a more integrated platform.

---

Data Security and Privacy Protection in Electronic KYC

The processing of KYC data involves some of the most sensitive information: identity data, biometric data, property information. GDPR compliance is essential with particular acuity.

Personal data processing carried out in the context of KYC is based on two main legal bases under Article 6 of the GDPR:

  • Legal obligation (art. 6.1.c): AML-FT law requires the collection and verification of identification data
  • Contract performance (art. 6.1.b): account opening requires customer identification

For biometric data (liveness detection, facial recognition), Article 9 of the GDPR requires a specific legal basis, generally explicit customer consent or express legal obligation. An impact assessment (DPIA) is mandatory before any deployment of these technologies.

Data Minimization and Retention Periods

The minimization principle requires collecting only data strictly necessary for the KYC purpose. Original documents may be replaced by extracted data (name, surname, document number, expiration date) once verification has been performed. The maximum retention period for biometric data is 3 years from collection, except where otherwise legally required.

Institutions must also ensure the right to be forgotten (art. 17 GDPR), while reconciling it with AML-FT preservation obligations — a legal tension requiring precise document management policy.

Founding European Texts

The legal system regulating electronic KYC in France is articulated around several superimposed regulatory layers:

eIDAS Regulation No. 910/2014 (EU): establishes the legal framework for electronic signature in the European Union. Article 25 sets the principle of non-discrimination: an electronic signature cannot be rejected solely because it is in electronic form. Articles 26 to 29 define the requirements respectively applicable to advanced and qualified signatures. The eIDAS 2.0 revision (regulation 2024/1183/EU) strengthens these provisions and introduces the European digital identity wallet (EUDIW).

5th anti-money laundering directive (2018/843/EU) and 6th AMLD directive: directly condition vigilance and identification obligations. French transposition is found in Articles L.561-1 and following of the Monetary and Financial Code, as well as in the order of January 6, 2021 relating to the AML-FT internal control system and device.

DSP2 directive (2015/2366/EU) and delegated regulation 2018/389: impose strong authentication (SCA) and condition the issuance of payment instruments.

French Civil Law and Probative Value

Article 1366 of the Civil Code provides that electronic writing has the same probative force as writing on paper, provided that its author can be properly identified and that it is established and preserved under conditions designed to guarantee its integrity. Article 1367 recognizes electronic signature when it consists of the use of a reliable identification process guaranteeing its link to the act to which it attaches.

Decree No. 2017-1416 specifies the conditions under which electronic signature is presumed reliable, in particular by reference to eIDAS requirements for qualified signature.

ETSI Technical Standards

The ETSI EN 319 132 standards (XAdES, CAdES, and PAdES formats) define electronic signature format standards. In the KYC context, the PAdES format (PDF Advanced Electronic Signatures) is preferred because it integrates the signature directly into the PDF file, ensuring consistency between the visual document and its cryptographic signature.

The ETSI EN 319 401 standard frames general requirements applicable to trust service providers (TSPs), including electronic signature providers. In France, ANSSI ensures the supervision of these providers and publishes the national trust list (TL-FR).

A non-compliant KYC system exposes the institution to significant penalties: the ACPR can impose disciplinary sanctions (warning, reprimand, temporary prohibition from operating) and pecuniary sanctions reaching 100 million euros or 10% of annual net turnover. The MiCA directive (2023/1114/EU) extends these obligations to crypto-asset service providers (PSAN/PSCA) from 2024 onward, further strengthening the KYC perimeter to monitor.

Use Cases: Electronic KYC in Practice

Scenario 1 — Online Bank and 100% Digital Onboarding

A European neobank processing approximately 15,000 new account openings per month seeks to reduce its KYC process abandonment rate, then estimated at 34% due to friction from postal document submission. The bank deploys an entirely digital pathway: the prospect captures their identity document via mobile (NFC verification of the secure title chip), performs a liveness selfie, then electronically signs the account convention and beneficial ownership declaration via an eIDAS-compliant advanced signature.

Results observed after 6 months of deployment: the KYC abandonment rate drops to 11% (a 67% reduction), the average account opening time falls from 5 business days to less than 20 minutes, and the unit cost of processing a KYC file decreases by 58%. The automatically generated audit trail enables response to ACPR justification requests during controls in less than 4 hours.

Scenario 2 — Asset Management Company and Investor KYC

An asset management firm managing approximately 2.8 billion euros in assets for 1,200 institutional clients and high-net-worth individuals (UHNWIs) must renew KYC files for its high-risk clients annually. Traditionally performed through postal submission and handwritten signature, this process mobilized 3 full-time equivalents for 6 weeks each year.

After deploying an electronic KYC signature solution with qualified signature (QES) for management mandates and banking powers, combined with advanced signature for update questionnaires, the firm reduces the annual renewal process from 6 weeks to 8 business days. The rate of complete file returns before deadline rises from 71% to 96%, virtually eliminating blocking regulatory situations. The time-stamped traceability of each signature enables precise justification of the update date before the regulator.

Scenario 3 — Specialized Credit Institution and Business KYC

A specialized SME financing institution processes approximately 800 loan files per year, each requiring collection and signature of 12 to 18 KYC documents (bylaws, corporate registration certificate, certified accounts, beneficial ownership declaration, loan agreement, personal guarantees). The multiplicity of signers (executive, co-borrowing spouse, joint guarantor) complicated workflows and lengthened implementation timelines.

The institution deploys multi-signer signature workflows with configurable signing order: the executive signs first, automatically triggers the co-borrower invitation, then the guarantor. Each signer is authenticated via reinforced SMS OTP and document identity verification. The average KYC file completion time drops from 18 days to 4 business days, enabling significant acceleration of financing implementation timelines and improved customer satisfaction (NPS increased by 22 points on the SME segment).

Conclusion

The convergence between KYC requirements in the financial sector and the capabilities of electronic signature outlines in 2026 a new standard for onboarding and banking compliance management. Whether initial customer identification, verification of beneficial owners of a complex structure, or periodic renewal of files, electronic signature — advanced or qualified depending on stakes — brings the probative rigor that regulators demand, while streamlining the customer experience.

The legal framework is stabilized: eIDAS, AML-FT, DSP2, and GDPR form a coherent foundation on which institutions can rely to digitalize their processes securely.

Certyneo offers an eIDAS-compliant electronic signature solution, integrated and auditable, specially adapted to the constraints of financial actors. Discover our pricing and start your free trial to transform your KYC workflows today.

Try Certyneo for Free

Send your first signature envelope in less than 5 minutes. 5 free envelopes per month, no credit card required.

Take action

Sign a KYC file / online account opening

Sign this document online with an eIDAS-compliant electronic signature.

Sign now

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.