Go to main content
Certyneo

KYC Documents: Electronic Signature for Banking Compliance in 2026

The digitalization of KYC processes is transforming banking and financial practices. Discover how electronic signature secures your Know Your Customer obligations in 2026.

Équipe finance Certyneo12 min read

Équipe finance Certyneo

Writer — Certyneo · About Certyneo

a woman holding a cell phone in her hand

Introduction: Why KYC Has Become a Strategic Issue

KYC (Know Your Customer) refers to the set of identity verification procedures that a financial institution must implement before entering into a business relationship with a customer. In 2026, European supervisory authorities — ACPR in France, EBA at European level — require increased rigor in the collection, authentication and retention of KYC documents. Electronic signature has become the technological pivot enabling the reconciliation of customer experience fluidity, probative value of documents and regulatory compliance. This guide explains the issues, legal requirements and best practices for deploying an electronically signed KYC process in the banking and financial sector.

---

The Fundamentals of KYC and Its Documentary Dimension

KYC rests on three fundamental pillars: customer identification, verification of their identity, and continuous monitoring of the business relationship. Each of these pillars generates significant documentary flows that must be authenticated, timestamped and retained in a probative manner.

Documents Collected in a KYC Process

A typical KYC file includes:

  • Identity documents: national identity card, passport, residence permit
  • Proof of address: utility bills, bank statements dating from less than three months
  • Documents relating to professional activity: Kbis, articles of association, annual accounts for legal entities
  • Declaratory forms: declaration of beneficial owners, tax residence certificate, FATCA/CRS form
  • Framework agreements: account opening contracts, management mandates, payment service agreements

Each of these documents must be signed, dated and traceable. The question is therefore no longer whether electronic signature has a place in KYC, but rather determining which signature level is required for each act.

eIDAS Signature Levels Applicable to KYC

Regulation eIDAS (No. 910/2014) distinguishes three levels of electronic signature, the relevance of which varies depending on the nature of the KYC document:

| Level | KYC Applicability | Requirements | |--------|------------------|----------| | Simple (SES) | Low-risk declaratory forms | Link between signatory and document | | Advanced (AES) | Account agreements, standard mandates | Verified identity, guaranteed integrity, optional qualified certificate | | Qualified (QES) | Banking powers, representation mandates, high-value legal acts | Qualified certificate issued by approved eIDAS PSCO |

Advanced electronic signature constitutes the minimum recommended level for the vast majority of banking KYC documents. For electronic signature processes in enterprises subject to enhanced regulatory obligations, qualified signature becomes essential.

---

Digital KYC: Regulatory Requirements Specific to the Financial Sector

Credit institutions, investment firms and payment service providers are subject to a dense regulatory framework that directly conditions the design of their electronic KYC system.

The 5th Anti-Money Laundering Directive (AMLD5) and Its Impact on Digital KYC

Transposed into French law by ordinance n°2020-1342 of November 4, 2020, the 5th anti-money laundering directive (2018/843/EU) opened the way to remote identification by explicitly recognizing electronic identification means notified under eIDAS. It notably imposes:

  • Enhanced verification for high-risk customers (PEPs, third countries at risk)
  • Complete traceability of due diligence performed
  • Data retention for five years from the end of the business relationship
  • Obligation for periodic updates of customer files

The 6th directive AMLD (2021/1237), with transposition expected before the end of 2026, further strengthens these obligations with the introduction of a European digital identity space (eID) and harmonization of watchlists.

DSP2 and Strong Authentication: The Interface with KYC

The Payment Services Directive DSP2 (2015/2366/EU) imposes strong customer authentication (SCA) for sensitive operations. In the KYC context, this requirement materializes when:

  • Entering into a remote relationship (100% digital account opening)
  • Signing an amendment modifying essential account characteristics
  • Adding a beneficiary of an unusual transfer

Strong authentication requires the combination of at least two factors among: knowledge (password), possession (smartphone, token) and inherence (biometrics). This system naturally articulates with advanced electronic signature, whose issuance process integrates these authentication factors. To understand the subtleties of the eIDAS regulation and its evolution towards eIDAS 2.0, a dedicated guide provides you with all the keys.

EBA Recommendations on Digital Onboarding

The European Banking Authority (EBA) published in 2022 its guidelines on the use of remote identification solutions in the context of KYC (EBA/GL/2022/15). These guidelines specify the conditions under which an institution can rely on electronic identity verification solutions without the physical presence of the customer, in particular:

  • Use of automated document verification technologies (OCR, NFC)
  • Integration of a liveness detection step to prevent deepfake fraud
  • Complete audit trail allowing reconstitution of the entire identification session
  • Level of confidence substantial or high under eIDAS for medium or high-risk customers

---

Deploying an Electronically Signed KYC Workflow: Architecture and Best Practices

Implementing a fully digitalized KYC process requires precise articulation between technical components and regulatory requirements.

Components of an Integrated KYC-Signature Solution

A robust KYC electronic signature system is based on:

  1. Document collection module: secure portal allowing customers to upload supporting documents, with consistency checks (format, readability, authenticity)
  2. Identity verification engine: OCR coupled with biometric verification to extract and verify identity document data
  3. Electronic signature engine: signature certificate issuance, signature application to contractual documents, audit report generation
  4. [Qualified electronic timestamping](/guide/horodatage-electronique): certified timestamp applied to each signed document, guaranteeing the date of certainty
  5. Digital safe: retention of signed documents for the legal duration (minimum 5 years post-business relationship)
  6. Compliance dashboard: real-time monitoring of each customer's KYC status, alerts on files to be renewed

Management of Beneficial Owners and Delegation Chains

Verification of beneficial owners (UBO — Ultimate Beneficial Owners) represents one of the most complex challenges of KYC for legal entities. Institutions must identify any natural person holding, directly or indirectly, more than 25% of capital or voting rights.

This requirement generates signature chains involving multiple signatories (managers, agents, legal representatives) with different authorization levels. Advanced electronic signature enables the management of these multi-signatory workflows with complete traceability of each signing act. The legal value of each electronic signature in these delegation chains must be carefully documented.

KYC Renewal: Automating Periodic Updates

Anti-money laundering and counter-terrorist financing (AML-CFT) regulations require a periodic review of customer files according to their risk profile:

  • Low risk: every 5 years
  • Medium risk: every 3 years
  • High risk: annually

Automating these reviews through electronic signature workflows significantly reduces the operational burden on compliance teams. Automatic alerts are triggered as due dates approach, and customers are invited to update their documents via a secure digital process. For institutions already having a signature solution, it may be appropriate to evaluate a switch to a more integrated platform.

---

Data Security and Privacy Protection in Electronic KYC

The processing of KYC data involves some of the most sensitive information: identity data, biometric data, wealth information. GDPR compliance is imperative with particular acuity.

Personal data processing carried out in the context of KYC is based on two main legal bases under Article 6 of the GDPR:

  • Legal obligation (Art. 6.1.c): AML-CFT regulations require the collection and verification of identification data
  • Contract performance (Art. 6.1.b): account opening requires customer identification

For biometric data (liveness detection, facial recognition), Article 9 of the GDPR requires a specific legal basis, generally the explicit consent of the customer or an express legal obligation. An impact assessment (DPIA) is mandatory before any deployment of these technologies.

Data Minimization and Retention Periods

The minimization principle requires collecting only data strictly necessary for the KYC purpose. Original documents can be replaced by extracted data (name, surname, document number, validity date) once verification has been performed. The maximum retention period for biometric data is 3 years from collection, unless otherwise required by law.

Institutions must also ensure the right to erasure (Art. 17 GDPR), while reconciling it with AML-CFT retention obligations — a legal tension that requires precise document management policy.

Founding European Texts

The legal system governing electronic KYC in France is structured around several superimposed regulatory layers:

Regulation eIDAS No. 910/2014 (EU): establishes the legal framework for electronic signature in the European Union. Article 25 establishes the principle of non-discrimination: an electronic signature cannot be rejected solely on the grounds that it is in electronic form. Articles 26 to 29 define the requirements respectively applicable to advanced and qualified signatures. The eIDAS 2.0 revision (Regulation 2024/1183/EU) strengthens these provisions and introduces the European digital identity wallet (EUDIW).

5th anti-money laundering directive (2018/843/EU) and 6th AMLD directive: directly condition due diligence and identification obligations. The French transposition appears in Articles L.561-1 et seq. of the Monetary and Financial Code, as well as in the order of January 6, 2021 relating to the AML-CFT internal control system.

DSP2 directive (2015/2366/EU) and delegated regulation 2018/389: impose strong authentication (SCA) and condition the issuance of payment instruments.

French Civil Law and Probative Value

Article 1366 of the French Civil Code provides that electronic writing has the same probative force as writing on paper, subject to the author being duly identified and being established and retained in conditions that guarantee its integrity. Article 1367 recognizes electronic signature when it consists in the use of a reliable identification process guaranteeing its link with the act to which it attaches.

Decree No. 2017-1416 specifies the conditions under which electronic signature is presumed reliable, in particular by referral to eIDAS requirements for qualified signature.

ETSI Technical Standards

The standards ETSI EN 319 132 (XAdES, CAdES and PAdES formats) define the standards for electronic signature format. In the KYC context, the PAdES format (PDF Advanced Electronic Signatures) is preferred because it integrates the signature directly into the PDF file, ensuring consistency between the visual document and its cryptographic signature.

The standard ETSI EN 319 401 governs the general requirements applicable to trust service providers (TSPs), including electronic signature providers. In France, ANSSI supervises these providers and publishes the national trust list (TL-FR).

A non-compliant KYC system exposes the institution to significant penalties: ACPR can impose disciplinary sanctions (warning, reprimand, temporary prohibition from operating) and financial penalties reaching 100 million euros or 10% of annual net turnover. The MiCA directive (2023/1114/EU) extends these obligations to crypto-asset service providers (PSAN/PSCA) from 2024 onwards, further strengthening the KYC scope to monitor.

Use Cases: Electronic KYC in Practice

Scenario 1 — Online Bank and 100% Digital Onboarding

A European neobank processing around 15,000 new account openings per month seeks to reduce its KYC process abandonment rate, then estimated at 34% due to friction related to postal document submission. The bank deploys a fully digital journey: the prospect captures their identity document via mobile (NFC verification of the secure title chip), performs a liveness selfie, then electronically signs the account agreement and beneficial owner declaration via an eIDAS-compliant advanced signature.

Results observed after 6 months of deployment: KYC abandonment rate drops to 11% (a 67% reduction), average account opening time drops from 5 business days to under 20 minutes, and the unit cost of KYC file processing decreases by 58%. The automatically generated audit trail allows responses to ACPR requests for justification within less than 4 hours during inspections.

Scenario 2 — Asset Management Company and Investor KYC

An asset management company managing approximately 2.8 billion euros in assets on behalf of 1,200 institutional and high-net-worth individual clients (UHNWI) must renew KYC files annually for high-risk customers. Traditionally carried out by postal submission and manuscript signature, this process required 3 full-time equivalents for 6 weeks each year.

After deploying a qualified electronic KYC signature solution (QES) for management mandates and banking powers, combined with advanced signature for update questionnaires, the company reduces the annual renewal process duration from 6 weeks to 8 business days. The rate of complete file returns before deadline increases from 71% to 96%, virtually eliminating regulatory blocking situations. The timestamped traceability of each signature further allows precise justification of the update date to the regulator.

Scenario 3 — Specialized Credit Institution and Business KYC

A specialized SME financing institution processes around 800 credit files per year, each requiring the collection and signature of 12 to 18 KYC documents (articles of association, Kbis, certified accounts, beneficial owner declaration, credit agreement, personal guarantees). The multiplicity of signatories (manager, co-borrowing spouse, joint and several guarantor) complicated workflows and lengthened implementation timelines.

The institution deploys multi-signatory signature workflows with configurable signature order: the manager signs first, automatically triggers the co-borrower's invitation, then the guarantor's. Each signatory is authenticated by reinforced SMS OTP and documentary identity verification. The average time to complete a full KYC file drops from 18 days to 4 business days, enabling significant acceleration of financing implementation timelines and improved customer satisfaction (NPS up 22 points on the SME segment).

Conclusion

The convergence between KYC requirements in the financial sector and the capabilities of electronic signature outlines in 2026 a new standard for onboarding and banking compliance management. Whether it is the initial identification of an individual customer, verification of beneficial owners of a complex structure or periodic renewal of files, electronic signature — advanced or qualified depending on the stakes — brings the probative rigor that regulators demand, while streamlining the customer experience.

The legal framework is stabilized: eIDAS, AML-CFT, DSP2 and GDPR form a coherent foundation on which institutions can rely to digitalize their processes with full security.

Certyneo offers an eIDAS-compliant electronic signature solution, integrated and auditable, specially adapted to the constraints of financial actors. Discover our pricing and start your free trial to transform your KYC workflows starting today.

Try Certyneo for free

Send your first signature envelope in under 5 minutes. 5 free envelopes per month, no credit card required.

Take action

Sign a KYC file / online account opening

Sign this document online with an eIDAS-compliant electronic signature.

Sign now

Go deeper on the topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.