Compliance · Financial services
e-KYC, rigorous by design.
Remote customer identification and anti-money-laundering controls for banks, non-bank lenders and fintechs — National Bank of Moldova rules under Law 308/2017, National Bank of Romania rules under Law 129/2019, and the EU AML framework they both transpose.
- 3jurisdictions: Moldova, Romania, EU
- 5 yrsrecord retention
- 2027EU AML Regulation applies
Electronic Know Your Customer and Anti-Money-Laundering compliance — Moldova, Romania and the EU
Know Your Customer is the front door of anti-money-laundering. Before a bank, lender, payment institution or crypto provider opens a relationship it must establish who the customer is, who ultimately owns them, and whether the relationship carries money-laundering or terrorist-financing risk. e-KYC does this remotely — from a phone camera and a government ID — without weakening the checks.
The obligations come from the same EU source and land in each market through national law. In the EU: the AML directives (2015/849 as amended), the AML Regulation (EU) 2024/1624 that applies directly from July 2027, and the EBA guidelines on remote customer onboarding. In Romania: Law 129/2019 and the National Bank of Romania regulations for credit and non-bank financial institutions, with the ONPCSB as the financial-intelligence unit. In Moldova: Law 308/2017, supervised by the National Bank of Moldova — for banks and, since July 2023, non-bank credit organisations — with suspicious activity reported to the SPCSB.
A compliant e-KYC flow is a chain: capture and authenticate the identity document, prove the person is live and matches it, screen against sanctions and PEP lists, score the risk, collect beneficial-ownership data for companies, then keep monitoring and keep every decision auditable for five years. The chain is the same in Chișinău, Bucharest and Berlin; what changes is the supervisor, the reporting channel and the accepted identity schemes. We built exactly this chain for eCredit's digital lending platform in Moldova.
What the framework demands
The obligations an auditor or supervisor will test, in plain language.
Customer identification and verification
Capture a government ID, authenticate it — OCR, MRZ checksums, NFC chip read where available, security-feature checks — and verify the applicant against it with liveness detection and biometric face match. Video identification and eIDAS-notified electronic identities are accepted routes in the EU and Romania.
Risk-based customer due diligence
Classify each customer as low, standard or high risk from product, geography, delivery channel and profile, and apply simplified, standard or enhanced due diligence accordingly.
Sanctions, PEP and adverse-media screening
Screen at onboarding and continuously against UN, EU and national lists and against politically-exposed-person data, with a documented process for handling hits.
Beneficial ownership
For legal entities, identify and verify the natural persons holding 25% or more, or otherwise exercising control, and reconcile them against the trade register and the beneficial-ownership register where one exists.
Record keeping — five years
Retain identity documents, verification results, screening evidence and transaction records for at least five years after the relationship ends, tamper-evident and retrievable for the supervisor.
Ongoing transaction monitoring
Rules and behavioural analytics that flag unusual patterns, with a case-management workflow for review and escalation.
Suspicious-activity reporting
Report suspicious transactions and activities to the financial-intelligence unit — the ONPCSB in Romania, the SPCSB in Moldova, the national FIU elsewhere in the EU — within the statutory deadlines, without tipping off the customer.
Governance, training and independent audit
A designated compliance officer, board-approved policies, staff training and periodic independent testing of the AML programme.
The cost of getting it wrong
- Supervisory sanctions from the National Bank of Romania or the National Bank of Moldova, from fines to restrictions on the licence
- Personal administrative liability for managers and the compliance officer
- Frozen correspondent-banking and payment relationships when partners lose confidence in your controls
- Fraud losses from synthetic and stolen identities that a weak onboarding flow lets through
From gap to evidence
Assessment, remediation, documentation and audit support — run as one programme.
- 01
Regulatory mapping and gap review
We map the rules that apply to each market you operate in — Law 129/2019 and BNR regulations in Romania, Law 308/2017 and NBM regulations in Moldova, the AML Regulation and EBA guidelines in the EU — to your products and channels, and score the current flow against them.
- 02
e-KYC flow design
We design the remote journey — document capture, authenticity checks, liveness and face match, data extraction, risk scoring and fallbacks — balancing conversion against control, with per-country identity schemes where they differ.
- 03
Integration and engineering
We integrate identity-verification, sanctions/PEP and registry APIs into your core system, with a case-management back office and audit-grade logging.
- 04
Monitoring and reporting
We implement transaction-monitoring rules, alert triage and FIU reporting workflows for the ONPCSB, the SPCSB or your national unit, tuned to your customer base.
- 05
Policies, training and audit readiness
We deliver the AML/CFT policy set, train staff and prepare the evidence pack for BNR or NBM inspections and independent audits.
Deliverables
- Regulatory gap assessment per market: Romania (Law 129/2019, BNR), Moldova (Law 308/2017, NBM), EU (AMLR, EBA guidelines)
- End-to-end e-KYC flow specification and risk-scoring model
- Integrated identity verification, liveness, sanctions/PEP screening and registry checks
- Case-management back office with full audit trail and five-year retention
- Transaction-monitoring rules and suspicious-activity reporting workflow
- AML/CFT policies, procedures and staff training
- Inspection-ready evidence pack
Questions we hear most
Is fully remote onboarding allowed for regulated lenders?
Yes, in all three jurisdictions, provided the remote identification meets the applicable rules: Law 129/2019 and National Bank of Romania regulations in Romania, Law 308/2017 and National Bank of Moldova regulations in Moldova, and the EBA remote-onboarding guidelines across the EU — reliable document authentication, liveness, risk assessment and full records. That is the flow we built for eCredit.
We operate in both Romania and Moldova. Do we need two programmes?
One programme, two supervisors. Both laws transpose the same EU directives, so due diligence, screening, monitoring and retention are designed once. What differs is the identity schemes you accept, the reporting channel (ONPCSB versus SPCSB) and the supervisor who inspects you (BNR versus NBM); we handle those as market-specific configuration.
Which lists do we have to screen against?
At minimum the UN Security Council and EU sanctions lists, the national lists maintained under each AML law, and politically-exposed-person data; most institutions add OFAC and adverse media. Screening has to be repeated for the life of the relationship, not only at onboarding.
How long do we keep KYC records?
At least five years after the business relationship ends or the occasional transaction is completed, and longer if the supervisor or a court asks. Records must show what was checked, when, by whom and what decision was taken.
Does this cover the new EU AML Regulation?
Yes. We design against the directives in force today and track Regulation (EU) 2024/1624, which applies directly in every member state — Romania included — from July 2027, and the EBA remote-onboarding guidelines, so EU-facing clients are ready when the regulation applies.
Often pursued together
Ready to Transform Your Business?
Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.