Swisscom Trust Services - Trust Blog

A Boost for QES-Based Identification – Germany Simplifies Onboarding in the EU

Written by Peter Amrhyn | 7/24/26 2:52 PM

Qualified electronic signatures (QES) are already a highly reliable way to identify individuals online. Before a QES can be issued, the user must first be identified unambiguously and beyond a doubt; the process itself is subject to the strict requirements of the eIDAS Regulation and is regularly audited. In theory, this makes QES an obvious solution for secure digital onboarding. In regulated industries such as the financial sector, however, Germany has so far required an additional step. This is because, under the current anti-money laundering (AML) framework, member states had leeway to implement the customer due diligence requirements under anti-money laundering law in different ways. As a result, national onboarding requirements varied. The new European Anti-Money Laundering Regulation (AMLR) is intended to reduce this fragmentation in the future.

Until now, the German Anti-Money Laundering Act (GwG) permitted identification via a qualified electronic signature only if it was supplemented by a direct reference transfer from a bank account held in the name of the signatory. This additional requirement is now set to be eliminated under the German Digital Identities Act (DIdG), which is currently going through the parliamentary process and, according to the federal government, is scheduled to take effect this year—in time for the planned launch of the EUDI wallet on January 2, 2027.

Here is what the change would look like in practice:

 
In the case of identity verification using a qualified electronic signature pursuant to sentence 1, number 3, the obligated party must validate the qualified electronic signature in accordance with Article 32(1) of Regulation (EU) No. 910/2014. In this case, the obligated party must also ensure that a transaction is made directly from a payment account as defined in Section 1(17) of the Payment Services Supervision Act, which is held in the name of the contracting party, in the case of an obligated party under § 2(1), first sentence, item 1 or item 3, or in the case of a credit institution established in a
1. another Member State of the European Union,
2. a State party to the Agreement on the European Economic Area, or
3. a third country in which the credit institution is subject to due diligence and record-keeping obligations that correspond to those outlined in Directive (EU) 2015/849 and compliance with which is supervised in a manner consistent with Chapter IV, Section 2 of Directive (EU) 2015/849.

Germany is aligning its requirements with the standard practice in many EU member states

The planned simplification of QES-based identification in Germany is not merely a national adjustment. It offers a glimpse into the future direction of customer onboarding in Europe. With the new EU Anti-Money Laundering Regulation (AMLR), which will apply directly in all Member States as of July 10, 2027, the EU is moving away from a patchwork of local identification rules toward a more harmonized, digitally oriented approach to customer due diligence under anti-money laundering law.

In practice, this means that obligated entities such as banks, fintechs, and other regulated financial service providers will increasingly rely on identification methods that are secure, interoperable, and verifiable across borders. The future AML framework points to three key pathways: national electronic identification systems (eIDs), the European Digital Identity Wallet (EUDI Wallet), and qualified trust services under eIDAS, including qualified electronic signatures.

  1. National eID solutions will remain a key pillar. Many EU member states already operate government-backed electronic identity systems that can provide a high level of trust when recognized under eIDAS. For customers, this could mean using an existing national eID to verify their identity when opening an account or accessing a regulated financial service. For financial institutions, the advantage is clear: the identity attributes come from a trusted source and can be verified in a structured and repeatable manner.

  2. The European Digital Identity Wallet, or EUDI Wallet, is expected to add another layer to this ecosystem. Once available, it will enable citizens and residents to store and share verified identity data and credentials in a controlled digital environment. For AML onboarding, this could make cross-border identification more convenient: Instead of repeatedly scanning documents or going through country-specific processes, customers could provide verified attributes from their wallet to a regulated provider.

  3. Qualified trust services represent the third approach. Under eIDAS, qualified trust services offer a high level of legal and technical security for digital transactions. Qualified electronic signatures deserve special attention here. A QES is not simply an electronic signature in the everyday sense. It is created using a qualified signature creation device and is based on a qualified certificate issued by a qualified trust service provider. As a result, it enjoys strong legal standing throughout the EU and can support both identity verification and the integrity of the signed transaction.

For financial institutions, QES is therefore becoming a very attractive option in their onboarding toolkit. It combines customer convenience with a recognized trust framework, is well-suited for remote and cross-border processes, and creates evidence that can be documented and retained. For customers, this could mean fewer media breaks, fewer manual checks, and fewer country-specific detours during onboarding. For the market, this opens the prospect of a more standardized European model for digital identification.

Germany may be one of the first markets to simplify QES-based identification in the financial sector, but it will not remain an exception. Through the synergy of AMLR, eIDAS 2.0, and the EUDI Wallet, qualified electronic signatures are becoming part of the broader European shift from fragmented AML onboarding toward trustworthy, digital, and interoperable identity verification.

Would you like to learn more about electronic signatures, the technology behind them, and their different levels of trust? Then take a look here: In this free guide, we've compiled the most important information for you. Of course, Swisscom Trust Services supports you in integrating QES into various business processes—both in Switzerland and in the EU.

More on PSD3 and PSR:

AMLR isn't the only new European regulation expected to take effect next year. It's part of the broader context of PSD3 and PSR. We've put together an overview of these new regulations and show how companies can start preparing now. Download the free white paper now.