Financial institutions have become good at answering one question: is this person who they claim to be? Now, AMLR requires them to ask further questions, but the answers may not come from the same place as before.
Why AMLR creates an attribute challenge
The Anti-Money Laundering Regulation (AMLR) extends the obligations that financial institutions face under the existing AML framework. Among other changes, it requires the collection and verification of specific attributes — data points such as place of birth, nationality, and occupation — during customer due diligence.
These attributes are not new. What is new is the expectation that they be verified, not merely declared. A customer can tell you their date of birth. A QEAA can confirm it from a trusted source.
The gap lies in the infrastructure. Most existing identity verification processes are built around document checks and biometric matching. They are designed to confirm who someone is, not to extract and attest structured attributes about them. AMLR requires both, and the second part is harder than the first.
What changes in onboarding
The practical impact on onboarding is a shift from single-question to multi-question flows. Today, most financial institutions ask: can we verify this person’s identity? AMLR asks that and more.
Financial institutions designing for AMLR compliance need to ask three questions of their current onboarding flow:
1. Which attributes do we currently collect, and from what source?
2. Are those sources sufficient to meet the verification standard AMLR requires?
3. If not, where can a verified attribute come from, and how does it enter our systems?
How QEAA fits into customer due diligence
A Qualified Electronic Attestation of Attributes (QEAA) is a credential issued by a qualified trust service provider under eIDAS 2.0. It attests to one or more attributes about a person — such as their address, nationality, or tax identification number — with a legal and technical assurance level that mirrors that of a qualified electronic signature.
“The value of a QEAA is the trust chain behind the credential: the source, the proofing process, the issuance and the status over time.”
Sebastian Elfors, CSO at IDnow Trust Services
In a financial-services journey, the QEAA enters the process at the point where an attribute needs to be verified:
1. The customer presents a QEAA during onboarding, either from an EUDI Wallet or through a provider-hosted flow.
2. The financial institution’s system verifies the credential’s signature and issuer status against the EU Trust List.
3. The verified attribute is extracted and stored in line with data minimisation requirements.
4. The audit log records the provenance — who issued it, when, and under what assurance level.
This replaces a document scan and manual data entry with a machine-readable, cryptographically verifiable record.
What financial institutions can use QEAAs for
The scope extends beyond identity. Financial institutions can use QEAAs to verify:
- Proof of address for account opening and periodic review
- Nationality and country of residence for sanctions screening and tax reporting
- Professional status or accreditation for investment eligibility checks
- Age for age-restricted products
- Tax identification numbers for CRS and FATCA obligations
Each of these has previously required either self-declaration or a document upload followed by manual verification. A QEAA transforms each one into a structured, signed, reusable data point.
How to prepare
Preparation for QEAA-based attribute verification involves four steps:
1. Map your attribute gaps. Identify which attributes AMLR requires you to verify, which you currently collect, and which are currently self-declared or document-based without machine-readable verification.
2. Define your acceptance criteria. Decide which trust service providers and credential types you will accept. This is a policy and procurement decision as much as a technical one.
3. Build the verification flow. Integrate credential presentation and signature verification into your onboarding and periodic review processes. This includes handling fallback paths for customers who do not yet have a QEAA.
4. Update your records and audit trail. Ensure your CDD system can record attribute provenance — not just the attribute value, but its source, assurance level, and timestamp.
How IDnow can help
IDnow is a qualified trust service provider under eIDAS 2.0 and issues QEAAs through its Trust Services offering. For financial institutions, this means:
- QEAAs issued under a regulated, audited process with a traceable trust chain
- Integration with existing IDnow identity verification flows, so attribute attestation can follow identity verification in a single customer journey
- Support for EUDI Wallet presentation and provider-hosted flows, so customers can participate regardless of their current level of digital access
- Compliance documentation and audit logs designed to meet AML supervisory expectations
“The fallback path is part of the compliant journey. Customers will arrive with different documents, eIDs and levels of digital access, so resilience has to be designed into the flow.”
Sebastian Elfors, CSO at IDnow Trust Services
Map your AMLR attribute gaps — one platform for both.
Frequently asked questions
Do customers need an EUDI Wallet?
No. Depending on the implementation, a QEAA can be delivered through an organisation’s existing onboarding flow. It can also be issued to or presented through an EUDI Wallet where supported.
Is a QEAA the same as an electronic ID?
No. An electronic ID establishes identity through a recognised identification scheme. A QEAA attests to a specific attribute, such as an address or tax identification number. The two can work together.
Does a QEAA replace KYC?
No. A QEAA can support KYC evidence, but the financial institution remains responsible for customer due diligence, risk assessment, screening, monitoring and other applicable controls.
Want to read more about QEAA?
- The Credential Is the New Passport
- IDnow Develops QEAA to Close the AMLR Attribute Gap
- IDnow Receives Certification to Issue QEAAs

Nikita Rybová
Customer & Product Marketing Manager at IDnow
Nikita Rybova is a Customer & Product Marketing Manager with 8+ years in tech, SaaS and e-commerce. At IDnow, she specializes in customer and product marketing, turning the complexities of identity verification into compelling narratives that drive growth.
Connect with Nikita on LinkedIn
