Digital Identity eIDAS
What Cross-Border Onboarding Actually Requires for Identity
If your firm onboards clients, counterparties or candidates in another country, the first thing that breaks is identity verification. That is true for a law firm acting on a cross-border matter, a financial adviser taking on a non-resident client, and a recruiter placing someone in another EU state. The fix that AMLR points to is specific: stop improvising, and start using a regulated trust service provider with eIDAS-recognised methods. That shift is not only a compliance step. It is the architecture that gives you a real system of record.
Key Takeaways: Identity in Cross-Border Onboarding
- Emailed ID copies and uncertified "black-box" selfie checks fail for the same reason: neither produces a defensible, reproducible record.
- AMLR moves customer due diligence onto regulated, eIDAS-recognised electronic identification, held as a logged, time-stamped dataset rather than a folder of copies.
- One method recognised EU-wide removes the need for a country-by-country workaround, so the cross-border case stops being special.
- A one-off check is single-use by design; a regulated identity established once can be reused for every later signature, share and declaration.
- Trust Circle anchors every share and signature to an identity verified through ZealiD's regulated app, so the system of record is built as you work.
The trap: firms think they are buying a one-time identity check. What they actually need is the record that a regulated check produces as a by-product. The verification and the record are the same act. Do it properly once, and the audit trail already exists.
What Breaks First Today
Across cross-border onboarding, two inadequate methods dominate, and neither produces a defensible, reproducible record:
- Emailing copies of ID documents. A photographed passport in an inbox proves nothing about who sent it, whether it is genuine, or whether the person is who they claim. It also scatters sensitive personal data across mailboxes you cannot fully control.
- An unlisted, uncertified "black-box" check. A simple selfie-versus-ID-card best-effort service may feel modern, but if it is not a certified, regulated method, you cannot point to an assurance level, and you cannot reproduce the verification event for a supervisor. One firm using exactly this kind of app acknowledged it was better than scanning IDs through a signing tool, but saw significant room for improvement, because it left them unable to reuse or rely on the identity afterwards.
Both methods collapse hardest across borders, where a foreign document, an unfamiliar national ID, or the absence of a domestic eID exposes how thin the underlying process really is.
What AMLR Actually Dictates
The core instruction in the AMLR is to move customer due diligence onto regulated, eIDAS-recognised electronic identification, and to maintain identity as a logged, time-stamped, auditable dataset rather than a folder of copies (see Articles 19–28). Article 22 sets out the identification data required, and the regulation favours electronic identification performed to an eIDAS assurance level. For a cross-border firm, the practical translation is: use a trust service provider whose methods are recognised across the EU, so the same standard applies whether your client is in Stockholm, Vilnius or Valletta. For what the regulation requires more broadly, see our guide to what AMLR actually requires from small firms before July 2027.
How This Breaks Differently Across the Three Audiences
The failure mode is shared, but its shape changes by sector. Law firms hit it on cross-border matters where a foreign counterparty must be identified to the same standard as a domestic client, and the firm has no method that travels, so it falls back to emailed copies and hopes. Financial advisers hit it when a non-resident client cannot be verified to the assurance level their own supervisor expects, leaving the adviser to choose between turning the client away and onboarding on a weaker basis they cannot defend later. Recruiters and HR consultants placing candidates across borders hit it on identity and right-to-work evidence: a black-box selfie check that satisfies nobody, generating a pile of foreign ID scans that is pure data-protection liability the moment the placement closes.
In every case the instinct is to treat the cross-border instance as an exception requiring a special workaround. AMLR's logic is the opposite: adopt one regulated, eIDAS-recognised method that works identically everywhere, and the cross-border case stops being special. The same verification that handles a local client handles a foreign one, to the same standard, with the same record.
The Hidden Cost: A Check You Cannot Reuse
There is a second cost beyond compliance, and it compounds quietly. An emailed ID copy or a one-off black-box check is single-use by design. The next time that same client signs an engagement letter, the firm verifies them again. More often it does not, and simply trusts the email address. Either way the firm has paid for a verification it cannot bank. Across a client relationship that spans years and dozens of interactions, that is enormous wasted effort and a steadily growing pile of duplicated personal data, every copy of which is its own liability under data-protection law.
A regulated identity, established once to an eIDAS assurance level, is reusable. The client proves who they are a single time, and every later action, whether a signature, a shared document or a fresh KYC declaration, draws on that established identity rather than starting over. The cross-border case makes the contrast vivid, because re-verifying a foreign client by email a second and third time is precisely where firms feel the friction. But the saving applies to every client, foreign or domestic.
Why This Is an Architecture Decision, Not a Checkbox
This is the point most onboarding tools miss. When identity is established through a regulated trust service, the output is not just a yes/no result. It is a verification event with a timestamp, an assurance level, and a verified identity attached. That event is the foundation of a system of record. Every later interaction, from a signed engagement letter to a KYC declaration to a document shared with that client, can be tied back to a verified identity rather than to an email address.
| Email copies / black-box check | Regulated TSP + eIDAS method | |
|---|---|---|
| Assurance level | Undefined | Defined and externally audited |
| Cross-border consistency | Varies per country | Same standard EU-wide |
| Reproducible for an audit | No | Yes, logged verification event |
| Reusable for later interactions | No | Yes, identity can be reused |
| Produces a system of record | No | Yes, as a by-product |
What Good Looks Like
For a firm onboarding across borders, the working setup has three properties:
- Identity established once, to an eIDAS assurance level, through a regulated provider recognised across the EU.
- That identity reusable, so the client does not re-prove themselves at every step, and you do not re-collect their data.
- Every subsequent action anchored to that verified identity, building the record automatically.
This is precisely how Trust Circle is designed to work: a client anywhere in the EU verifies once through ZealiD's regulated identity app, and that verified identity then anchors every share and signature in the workspace. It is backed by ZealiD's status as a Qualified Trust Service Provider on the EU Trusted List, so the system of record your supervisor will eventually ask for is built as you work, not reconstructed under pressure. For the standard behind the signatures, see our explainer on what a qualified electronic signature actually is.
References
- Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, Articles 19–28 and 22. European Union, 2024. eur-lex.europa.eu
- Regulation (EU) No 910/2014 (eIDAS), on electronic identification assurance levels. European Union, 2014. eur-lex.europa.eu
- EU Trusted List of qualified trust service providers. European Commission. esignature.ec.europa.eu