9 Key Points

Previously, I explained the key points of “Developing a Digital Identity Solution for Use by the Financial Sector Based Around eIDAS Trust Services (Developing a Digital Identity Solution for Use by the Financial Sector Based Around eIDAS Trust Services).” The 9 key points were as follows.

Of these key points, the “CDD Exchange Framework” particularly caught my interest. The following is an overview.

The “CDD Exchange Framework” in This Document

A CDD1 exchange framework is a system or arrangement designed to facilitate the secure and efficient exchange of customer due diligence (CDD) data among financial institutions and potentially other entities, while ensuring compliance with applicable regulatory requirements.

Types of CDD Exchange Framework

The document envisages 3 types of CDD exchange framework.

  1. Bilateral Agreements: Each participant concludes a separate agreement with every other participant for exchanging CDD data. Because numerous customized agreements are required, this method can be lengthy and complex.
  2. Scheme Model: A more integrated approach in which a central scheme defines common guidelines and standards for CDD data exchange. The scheme standardizes processes, handles allocation of liability, and establishes pricing provisions, similarly to models used by payment schemes such as VISA and Mastercard.
  3. KYC Utility Model: Under this model, a central KYC utility manages CDD data on behalf of participating financial institutions and acts as the counterparty for every data exchange. The utility handles processing and outsourcing of CDD data, simplifying compliance and operational efficiency for member institutions, but is not well suited to promoting broader portability of CDD data outside the utility.

Key Framework Considerations

The document also identifies the following 3 key considerations for a framework.

  1. Governance: Effective governance is critical to ensuring trust, transparency, and fairness among participants. This includes establishing clear participation criteria, preventing conflicts of interest, and creating processes for adopting rules and ensuring fee transparency.
  2. Economic Sustainability: The framework must provide a sustainable economic model, ensuring that service providers are appropriately compensated and that clear financial incentives for participation exist.
  3. Allocation of Liability: Clear rules for allocating liability must be established to manage risks associated with inaccurate or fraudulent data. Liability may be strict, negligence-based, or a combination of both, and must be clearly understood and agreed upon by all parties.

Practical Implementation in Europe

Need for Standardization

The document also identifies challenges for practical implementation.

  • The framework requires extensive standardization efforts, particularly for attributes beyond core identity data.

Efforts to standardize customer due diligence (CDD) data attributes beyond core identity data include:

  1. Use of EDIWs: European Digital Identity Wallets (EDIWs) will play an important role in standardizing the range of electronic attributes and improving interoperability of CDD data throughout the EU financial sector.
  2. Harmonization Efforts: Under the proposed AMLR, the future AML authority will have the power to specify lists of attributes required for standard, simplified, and enhanced CDD processes, with the aim of harmonizing CDD data attributes across the EU.
  3. Industry Initiatives: Various KYC-sharing initiatives, such as the INVIDEM initiative in the Nordic region and Belgium’s KUBE project, are working to standardize CDD data attributes to facilitate smoother CDD data exchange.

Taken together, these efforts aim to streamline the handling of both core identity data and additional status- or risk-related attributes needed for comprehensive due diligence in the financial sector. I would also like to investigate INVIDEM and KUBE further.

Financial Institutions as CDD Data Custodians

The document also notes that financial institutions may act as CDD data custodians, providing verified, attested attributes through European Digital Identity Wallets (EDIWs) and orchestrating multi-party utility models to manage broader CDD processes.

The role of a CDD data custodian is multifaceted and can be summarized as follows:

  1. Data Segregation: A CDD data custodian must segregate customers’ CDD data from its own data to prevent commingling.
  2. Data Security: It must ensure that CDD data is maintained securely and protected against loss, theft, or compromise.
  3. Data Integrity and Consent: The custodian is responsible for keeping CDD data current, maintaining its integrity, and ensuring that it is used only for purposes to which the data owner has consented.
  4. Verification and Reliability of Sources: It must verify that CDD data comes from reliable and independent sources. This includes responsibility for continuously monitoring and verifying the data in accordance with AML/CFT requirements.
  5. Transfer Protocols: A CDD data custodian must not transfer data to a third party without the data owner’s explicit consent and must comply with the GDPR and banking-secrecy rules.
  6. Operational Responsibilities: These obligations include exercising care when selecting sub-custodians, avoiding conflicts of interest, and ensuring that customers can exercise their rights over their data.

Together, these roles broadly ensure that custodians manage CDD data responsibly, comply with regulatory requirements, and maintain data integrity and security.

The document states that by considering these models and aspects, financial institutions can better handle the complexities involved in CDD data exchange while ensuring regulatory compliance and operational efficiency.

Data Transfer Protocols

This document was issued on September 2021, as many as 3 years ago. I was interested in what protocols were being considered at that stage. On examination, however, it appears that the discussion was not yet mature: the protocols are mentioned only briefly under the responsibilities of CDD data custodians and only in the context of overall data security and control mechanisms. Even at that stage, however, consideration distinguished offline proximity communications from other communications.

  1. NFC and Bluetooth (BLE): These protocols are used for secure electronic data exchange, particularly in offline scenarios where an Internet connection is unavailable (for example, point-of-sale payments).
  2. General Secure Communications: Although specific references to other protocols are not detailed, secure communications using SSL/TLS protocols compliant with X509-standard certificates suggest the underlying secure data-exchange mechanism.

This is broadly the same as EDIW-related work at the time, suggesting that the two efforts were closely coordinated.

In the next installment of the EU AMLR series, I would like to examine the AML package adopted by the European Commission on May 30.

Footnotes

  1. Customer Due Diligence