If your firm onboards clients, counterparties or candidates in another country, the first thing that breaks is identity verification. That is true for a law firm acting on a cross-border matter, a financial adviser taking on a non-resident client, and a recruiter placing someone in another EU state. The fix that AMLR points to is specific: stop improvising, and start using a regulated trust service provider with eIDAS-recognised methods. That shift is not only a compliance step. It is the architecture that gives you a real system of record.
The trap: firms think they are buying a one-time identity check. What they actually need is the record that a regulated check produces as a by-product. The verification and the record are the same act. Do it properly once, and the audit trail already exists.
Across cross-border onboarding, two inadequate methods dominate, and neither produces a defensible, reproducible record:
Both methods collapse hardest across borders, where a foreign document, an unfamiliar national ID, or the absence of a domestic eID exposes how thin the underlying process really is.
The core instruction in the AMLR is to move customer due diligence onto regulated, eIDAS-recognised electronic identification, and to maintain identity as a logged, time-stamped, auditable dataset rather than a folder of copies (see Articles 19–28). Article 22 sets out the identification data required, and the regulation favours electronic identification performed to an eIDAS assurance level. For a cross-border firm, the practical translation is: use a trust service provider whose methods are recognised across the EU, so the same standard applies whether your client is in Stockholm, Vilnius or Valletta. For what the regulation requires more broadly, see our guide to what AMLR actually requires from small firms before July 2027.
The failure mode is shared, but its shape changes by sector. Law firms hit it on cross-border matters where a foreign counterparty must be identified to the same standard as a domestic client, and the firm has no method that travels, so it falls back to emailed copies and hopes. Financial advisers hit it when a non-resident client cannot be verified to the assurance level their own supervisor expects, leaving the adviser to choose between turning the client away and onboarding on a weaker basis they cannot defend later. Recruiters and HR consultants placing candidates across borders hit it on identity and right-to-work evidence: a black-box selfie check that satisfies nobody, generating a pile of foreign ID scans that is pure data-protection liability the moment the placement closes.
In every case the instinct is to treat the cross-border instance as an exception requiring a special workaround. AMLR's logic is the opposite: adopt one regulated, eIDAS-recognised method that works identically everywhere, and the cross-border case stops being special. The same verification that handles a local client handles a foreign one, to the same standard, with the same record.
There is a second cost beyond compliance, and it compounds quietly. An emailed ID copy or a one-off black-box check is single-use by design. The next time that same client signs an engagement letter, the firm verifies them again. More often it does not, and simply trusts the email address. Either way the firm has paid for a verification it cannot bank. Across a client relationship that spans years and dozens of interactions, that is enormous wasted effort and a steadily growing pile of duplicated personal data, every copy of which is its own liability under data-protection law.
A regulated identity, established once to an eIDAS assurance level, is reusable. The client proves who they are a single time, and every later action, whether a signature, a shared document or a fresh KYC declaration, draws on that established identity rather than starting over. The cross-border case makes the contrast vivid, because re-verifying a foreign client by email a second and third time is precisely where firms feel the friction. But the saving applies to every client, foreign or domestic.
This is the point most onboarding tools miss. When identity is established through a regulated trust service, the output is not just a yes/no result. It is a verification event with a timestamp, an assurance level, and a verified identity attached. That event is the foundation of a system of record. Every later interaction, from a signed engagement letter to a KYC declaration to a document shared with that client, can be tied back to a verified identity rather than to an email address.
| Email copies / black-box check | Regulated TSP + eIDAS method | |
|---|---|---|
| Assurance level | Undefined | Defined and externally audited |
| Cross-border consistency | Varies per country | Same standard EU-wide |
| Reproducible for an audit | No | Yes, logged verification event |
| Reusable for later interactions | No | Yes, identity can be reused |
| Produces a system of record | No | Yes, as a by-product |
For a firm onboarding across borders, the working setup has three properties:
This is precisely how Trust Circle is designed to work: a client anywhere in the EU verifies once through ZealiD's regulated identity app, and that verified identity then anchors every share and signature in the workspace. It is backed by ZealiD's status as a Qualified Trust Service Provider on the EU Trusted List, so the system of record your supervisor will eventually ask for is built as you work, not reconstructed under pressure. For the standard behind the signatures, see our explainer on what a qualified electronic signature actually is.