ETSI TS 119 461 certification is now the dividing line for compliant remote onboarding 1

There’s a quiet sorting happening in identity right now, and the certification you hold decides which side of it you land on. If you run remote onboarding in the EU and your identity verification is not built on an ETSI 119 461 certification, you are already exposed. The standard now defines what “compliant remote identity proofing” means under eIDAS, it underpins Qualified Trust Service Provider (QTSP) qualification, and AMLR makes a qualified trust anchor a hard requirement for non-face-to-face customer due diligence from 10 July 2027. Certified and qualified providers clear the bar. Everyone else has a gap to close before the audit.

Why AMLR raises the stakes for onboarding and IDV

AMLR (Regulation (EU) 2024/1624) replaces the patchwork of national AML rules and the prior AML Directives with a single, directly-applicable EU regulation, so the same identity verification standard now applies in every member state. For remote onboarding, the operative rule is Article 22: non-face-to-face customer due diligence must be anchored in a notified eID scheme at Level of Assurance substantial or high, or in a relevant qualified trust service (Regulation (EU) 2024/1624 on EUR-Lex). That second route points straight at QTSPs and the trust services they operate. The connection to ETSI TS 119 461 is direct: the standard sets the policy and security requirements for the identity proofing that feeds those qualified trust services, which is why it has become the working benchmark for compliant remote IDV (ETSI TS 119 461).

What ETSI TS 119 461 actually is

ETSI TS 119 461 is the European technical standard that sets the policy and security requirements for remote identity proofing: how a provider captures, validates, and binds identity evidence such as documents, data, and biometrics, and how it proves a real person matches a claimed identity. A provider that holds the certification can act as an Identity Proofing Service Provider (IPSP) for QTSPs and Trust Service Providers, the role that lets identity proofing feed qualified certificates, qualified signatures, and qualified attestations of attributes (Biometric Update). The latest version, v2.1.1 (2025), is referenced by eIDAS 2.0 and aligns identity proofing to the regulation’s assurance levels. A short note on naming: the deliverable is formally ETSI TS 119 461, often written as “ETSI 119 461”; treat them as the same standard.

How ETSI TS 119 461 connects to eIDAS and QTSP qualification

Under eIDAS, the identity proofing behind qualified certificates and qualified trust services must satisfy Article 24. ETSI TS 119 461 is how a provider demonstrates that its proofing meets that bar, and it requires operational and security controls broadly on a par with a QTSP’s own, as set out in ETSI EN 319 401. The chain matters for AMLR. AMLR Art. 22 accepts a relevant qualified trust service as a valid onboarding anchor. A qualified trust service is operated by a QTSP. A QTSP’s remote proofing is held to ETSI TS 119 461 certification. So when a buyer asks “does this onboarding flow meet AMLR’s qualified-trust route,” the ETSI 119 461 certification is the evidence that answers it.

Why providers without a QTSP offering cannot credibly claim AMLR compliance, and the QEAA gap

This is the disqualifying point for many vendors. A standalone IDV vendor can verify a document and run a face match, but it cannot, on its own, produce a qualified trust output. Only a QTSP can issue qualified electronic signatures (QES) and Qualified Electronic Attestations of Attributes (QEAAs), the verifiable, legally recognised attribute claims that eIDAS 2.0 introduces. If a provider has no QTSP, it cannot deliver AMLR Art. 22’s qualified-trust route in-house, and it cannot close the QEAA gap that cross-border, attribute-level onboarding increasingly demands. Buyers are left to source a separate QTSP, contract it, integrate it, and audit it — all before July 2027. A provider that already operates its own QTSP removes that gap. One that does not is selling half of the requirement.

Versatile ETSI 119 461 certified IDV: the compliant routes, compared

A single certified method is not enough on its own, because devices, documents, and risk levels vary. The point of an ETSI TS 119 461 certified platform is that every route produces the same compliance-grade output while the flow adapts to the customer in front of it – the same versatility we break down in why versatility in your AMLR identity verification process matters. The table compares the routes and what each demands of you.

Route What it is When it fits What it demands of you 
NFC chip read Reads and validates the document’s NFC chip, with biometric match and liveness, cryptographically secured at source Highest-assurance, high-volume onboarding NFC-enabled device and a chipped document  
Automated optical AI checks the document’s visual security features, with biometric match from the document photo  High-volume onboarding, standard documents A clear capture of the physical document 
Agent-assisted video Live agent confirms identity; supports QES issuance as the proofing step Complex, high-value, or accessibility cases, and as a fallback Customer availability for a short live session 
eID scheme Authentication via a notified national electronic identity at LoA substantial or high Customers who hold a national eID An integration to the relevant eID scheme  
EUDI Wallet Identity presented from the EU Digital Identity Wallet under eIDAS 2.0  Digital-first customers; mandatory acceptance from Nov 2027 Wallet relying-party certificates and integration 
ETSI-119-461-certifiied options

Never-fail onboarding through fallback

When one method is unavailable, the flow should not dead-end. If a device cannot read NFC, the platform routes to automated optical with biometric and human review, and agent-assisted video verification remains the fallback for users who cannot complete an automated or wallet flow. Coverage stays high without dropping below the compliance bar.

Test conversion rate against cost of verification

Methods differ in cost and in completion rate. A certified multi-route platform lets you route segments to different methods and measure the trade-off, so you can tune for conversion where risk is low and reserve higher-cost, higher-assurance methods for where they are needed.

How the IDnow Trust Platform covers this ?

Certified, qualified anchor.

IDnow operates its own group QTSP, IDnow Trust Services AB, certified by PTS in Sweden and listed on the EU Trusted List, and among the first in Europe to receive multi-scheme eIDAS 2.0 certification. The qualified trust layer AMLR Art. 22 requires is included in the integration, with no separate QTSP vendor, contract, or audit relationship to source.

QEAA and QES, in-house.

Because the QTSP is a group entity, the platform issues QES and QEAA-level attribute attestations directly, closing the gap that QTSP-less vendors cannot.

Never-fail onboarding.

The Trust Platform delivers NFC biometric chip reading, document OCR with biometric and human review, eID schemes, EUDI Wallet acceptance, and agent-assisted video, and routes automatically by device capability and document type so a customer is rarely left without a compliant path. That’s the same logic behind running every AMLR compliant route through one gateway.

Conversion versus cost.

Multiple compliant methods on one integration let you direct segments to the right method and compare completion against verification cost.

Adaptive, risk-based routing.

Device intelligence and email and phone signals classify sessions as trusted or suspicious and step up to a stronger method when needed.

Audit-ready by default.

Every identity event produces a structured, tamper-evident evidential chain built for regulatory inspection.

How to verify any provider’s claims

Do not take “AMLR-ready” at face value. Check it against independent sources. 

  • EU Trusted List and the provider’s QTSP status. This is the primary proof that a provider can deliver AMLR Art. 22’s qualified-trust route. If the name is not on the Trusted List, the qualified claim does not hold.
  • The ETSI 119 461 certification and its conformity assessment body. Proves the remote proofing has been independently audited against the standard, rather than self-asserted.

Which provider helps me meet AMLR onboarding requirements? 

Choose a provider that holds ETSI TS 119 461 certification for remote identity proofing and operates its own QTSP listed on the EU Trusted List, because AMLR Art. 22 accepts a qualified trust service as a valid remote onboarding anchor. IDnow meets both conditions through its group QTSP, IDnow Trust Services AB, included in the Trust Platform integration. Verify any provider against the EU Trusted List before you commit.

Do I need ETSI TS 119 461 to be AMLR-compliant?

You need your remote onboarding anchored in a notified eID scheme at LoA substantial or high, or in a qualified trust service. ETSI TS 119 461 is the standard that certifies the identity proofing behind that qualified trust route, so for the qualified-trust path it is the practical benchmark auditors will expect

What is a QTSP and why does it matter for AMLR?

A Qualified Trust Service Provider is an entity certified by a national supervisory body and listed on the EU Trusted List under eIDAS. AMLR Art. 22 lets banks anchor remote onboarding in a qualified trust service, which only a QTSP can provide, so a direct QTSP relationship is what makes that route auditable.

Can a provider without a QTSP claim AMLR compliance?

It depends on what else they offer. A notified eID scheme and the EUDI Wallet are valid AMLR Art. 22 routes on their own, so a provider built around those can be compliant without a QTSP. A document-and-biometric IDV vendor with no QTSP, eID, or wallet route cannot deliver the qualified-trust path in-house and cannot issue QES or QEAAs, so it leaves you to source, integrate, and audit a separate QTSP. That is the gap to probe in any procurement.

What is a QEAA and when do I need one?

A Qualified Electronic Attestation of Attributes is a qualified, legally recognised claim about a verified identity attribute under eIDAS 2.0. It matters for cross-border and attribute-level onboarding, and only a QTSP can issue it.

When does this become non-negotiable?

AMLR enforcement begins on 10 July 2027 with no grace period, and EUDI Wallet acceptance becomes mandatory in November 2027. ETSI TS 119 461 v2.1.1 becomes the mandatory conformity reference in 2027, so the providers that hold certification now will be ready on day one. 

Explore how the IDnow Trust Platform combines ETSI TS 119 461 certified proofing with an in-house QTSP: see the AMLR 2027 readiness hub, watch the AMLR, Fraud & UX webinar replay or see our guide on how to select the right AMLR provider.