Reference🧭 Global overviewsIntermediate⏱ 22 min read

🪪 Digital identity and payments

Aadhaar and e-KYC in India, BankID and MitID in the Nordics, itsme, Smart-ID, the eIDAS 2 wallet, Singpass, and ConnectID: how the identity layer shapes account opening, strong authentication, and payment acceptance

Three functions that are constantly confused

In the payment chain, identity covers everything an institution does to establish who its customer is, confirm that the account holder is the one acting, and check a specific fact about them. These steps happen at three different points, each governed by different law, carrying different risk, and served by different providers. Identifying a customer at account opening falls under anti-money laundering rules. Authenticating the account holder during a transaction falls under payment security. Verifying an attribute falls under a third regime, whether the check is on age, on address, or on the payee name for a credit transfer. A single national scheme often handles all three, but that does not make them interchangeable.

FunctionQuestion it answersApplicable regimeWhat happens if it fails
Identification (KYC/CDD)Who is this person, and is their identity genuine?National AML law, FATF RecommendationsAccount refused, or opened in breach of the rules and sanctioned by the regulator
Authentication (SCA)Is the person acting really the account holder?Payment security rules (PSD2 in the EEA, scheme rules, central bank requirements)Transaction declined, or fraud liability shifted
Attribute verificationIs this specific attribute correct?Sector-specific law: age, residence, authority to act, name–account matchIllegal sale, misdirected transfer, unenforceable mandate
SignatureIs this person making a legally binding commitment?Trust services law (eIDAS in the EU, national equivalents elsewhere)Contract, direct debit mandate, or consent open to challenge
The three uses of identity in the payment chain

The cost of this confusion shows up at integration. A national ID chosen because it “does KYC” may not provide qualified signatures at all, which forces the institution to redo all its direct debit mandates. A successful authentication is not an age check either: the first confirms the account holder, the second verifies one attribute of their civil status. Identity providers charge per service, and the contract defines exactly what they attest to.

🔑
Identity is on the critical path, not an add-on
In parts of the world, you cannot accept payments without first connecting to the local identity system. Without it, customers cannot enroll in a wallet, sign up for a subscription, or open a merchant account. Sweden, Norway, Denmark, the three Baltic states, and Belgium all work this way. India does too, in a different form. Getting a contract signed with the identity provider often takes longer than the technical integration. That connection therefore drives the go-live date, so it belongs at the start of the project plan, not the end.

Aadhaar: e-KYC for a billion people

Aadhaar is a 12-digit identifier issued by the Unique Identification Authority of India (UIDAI). It is backed by biometric and demographic data and governed by the 2016 Aadhaar Act. India treats it as public infrastructure, just like a payment rail. A licensed institution queries UIDAI online and gets a response. The registry covers almost the entire adult population, and cumulative authentications since launch run into the hundreds of billions, a scale no other system comes close to.

1.45B
Aadhaar numbers issued since launch
UIDAI, Aadhaar dashboard, accessed August 2026
182.9B
cumulative Aadhaar authentications
UIDAI, Aadhaar dashboard, accessed August 2026
25.7B
cumulative e-KYC transactions
UIDAI, Aadhaar dashboard, accessed August 2026
24.4M
biometric devices registered with UIDAI
UIDAI, Aadhaar dashboard, accessed August 2026
Opening an account with Aadhaar e-KYC and a one-time passcode
Customer
Enters their Aadhaar number and gives explicit consent
Consent is timestamped and stored. Without it, the request is unlawful
Institution (KUA)
Sends the request under its license
Only an authorized entity can query UIDAI. Access requires a license and a contract, not just an API key
UIDAI
Sends a one-time passcode to the registered mobile number
This flow uses no biometric factor. The mobile number on record in the registry is what counts
UIDAI
Returns signed demographic data
Name, date of birth, address, and photo, in a digitally signed response. The institution does not need to collect any paper documents
Institution
Opens a limited-access account
The account stays capped until full due diligence is completed. The RBI sets the limits

The Reserve Bank of India’s Master Direction on Know Your Customer, issued on February 25, 2016, and updated on August 14, 2025, spells out exactly what e-KYC allows. An account opened with a one-time passcode alone remains capped: its aggregate balance cannot exceed ₹1 lakh, and total credits in a year cannot exceed ₹2 lakh. If full due diligence is not completed within a year, the account can no longer be used. The customer must also declare that they have not opened any other account this way.

The Video-based Customer Identification Process (V-CIP) is a remote identification procedure carried out through a video interview. The RBI standardized it so these limits can be lifted without a branch visit. Its requirements are more prescriptive than in most jurisdictions. The infrastructure must be hosted on the institution’s own premises, on a secure network, with end-to-end encryption between the customer’s device and the hosting site. The video recording carries GPS coordinates and a timestamp. Liveness and spoofing detection are mandatory, and the setup must pass penetration tests by auditors empaneled by CERT-In.

⚠️
Identity as a payment rail: the AePS example
The Aadhaar Enabled Payment System, run by NPCI since 2011, lets customers withdraw cash, make deposits, or pay with a fingerprint at a banking correspondent. No card or phone is needed. The account debited is the one the customer has linked to their Aadhaar number, which may not be their main account, and the account holder may not even know it. In response to identity fraud, the RBI issued the Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint Operators directions (RBI/2025-26/63) on June 27, 2025, in effect since January 1, 2026. When biometrics are the only factor in a payment, the weak point shifts to the operator capturing them.

An Aadhaar number also works as a payment address. NPCI’s National Automated Clearing House, through the Aadhaar Payment Bridge System, delivers direct benefit transfers to hundreds of millions of recipients. Recipients are identified by their Aadhaar number instead of an account number, so the identity registry acts as a routing directory to the linked bank. No advanced economy has replicated this setup at anything like the same scale.

BankID and MitID: identity issued by banks

In the Nordic model, the national electronic ID is issued by banks and then used by both government and the private sector. That is the reverse of the usual sequence elsewhere, where the government rolls out an electronic ID and banks connect to it later. Residents use the same credential to file their taxes, sign a lease, approve a transfer, and enroll in a wallet. A new entrant in these markets cannot open a single customer account until it has integrated with it.

FrameworkCountryOperatorSinceGovernance
BankIDSwedenFinansiell ID-Teknik BID AB2003Fully private, owned by the banks
BankID NorgeNorwayStø AS2004Owned by Norwegian banks. The same company owns BankAxept
MitIDDenmarkDigitaliseringsstyrelsen / Finans Danmark2021Joint public-private ownership. Replaced NemID; operated by Nets, then taken over by IN Groupe
Finnish Trust NetworkFinlandBank and telecom providers, supervised by Traficom2017Regulated market of providers and brokers, under Act 617/2009
Nordic digital identities and their operators

Who owns these systems determines how well they align with domestic payment rails and how exposed they are to a change of ownership. In Norway, Stø AS owns both BankID and the domestic card scheme BankAxept, so identity and card acceptance share the same bank owners. That explains why the country’s resilience arrangements hang together so well. In Denmark, public co-ownership of MitID keeps identity out of reach of any infrastructure sale, whereas Dankort followed Nets all the way to Nexi. In Sweden, identity remains fully private, and reliance on a single provider is now a matter of public debate.

ℹ️
Why the Riksbank wants a state-issued digital ID
In its Betalningsrapport 2026 (payments report), the Riksbank welcomes the prospect of a public electronic ID that can be used for payments. Sweden has no e-ID at the highest assurance level, and reliance on a single provider is seen as a resilience weakness. Design of the state ID has been assigned to the Polismyndigheten (Swedish Police Authority), working with the Digg agency. The outcome matters directly to any company that onboards Swedish customers using BankID alone.

The Finnish Trust Network, set up in Finland in 2017 under the supervision of Traficom, creates a market for electronic identification rather than a single system. Banks and mobile operators issue the credentials, and brokers aggregate them and resell access to online services under a standard contract. A merchant that signs with one broker reaches every bank in the country through that single connection. The previous protocol, TUPAS, has been obsolete since September 30, 2019. Any integration documentation that still mentions it has not been updated in six years.

itsme, Smart-ID, and iDIN: three consortium models

An identity consortium is a joint venture of banks, often telecom operators, and sometimes the government, that runs a national electronic ID. Several European markets have chosen this middle ground between a state-issued ID and a purely bank-issued one. The three cases below share that structure but differ in who is liable for the attestation and which legal regime applies.

🇧🇪
itsme, Belgium, 2017
Run by Belgian Mobile ID SA/NV, a consortium founded by Belfius, BNP Paribas Fortis, ING, KBC, Orange Belgium, Proximus, and Telenet. The Belgian government has owned about 20% through SFPI/FPIM since 2021. Users enroll with a bank account or an ID card. It covers authentication, transaction confirmation, and electronic signatures. itsme says it is available at more than 1,000 companies and platforms (itsme, accessed August 2026).
🇪🇪
Smart-ID, Baltic states, 2016
Run by SK ID Solutions AS on Cybernetica’s SplitKey platform. The private key is split between the device and the server, and neither half can sign on its own. Certified as a qualified signature creation device by TÜV Informationstechnik GmbH on October 31, 2018. About 100 million transactions a month across the region in 2025.
🇳🇱
iDIN, Netherlands, 2016
Run by Currence, which also owns Incassomachtigen, the SEPA direct debit mandate signed with bank authentication. The service reuses the customer’s online banking credentials to identify them and verify attributes, especially age. Its scope is narrower than the other two, and it does not claim to replace the ID card.

Smart-ID’s SplitKey architecture splits the signing key between the user’s device and the operator’s server. The PIN is not stored anywhere. It unlocks the device’s share locally, and that share alone cannot produce a signature. The server holds the other share and activates it only when the first one is presented. Compromising one side alone yields nothing usable. That property is what earned the system qualified signature status without any dedicated hardware on the user’s side.

⚠️
Recognized does not mean notified
An electronic ID can produce qualified signatures under eIDAS and count as a strong authentication factor while not being one of the identification schemes notified to the European Commission. Smart-ID is a case in point. Estonia’s list of notified schemes includes the ID card, the residence permit card, Digi-ID, e-Residency Digi-ID, Mobile-ID, and the diplomatic card. Notification triggers automatic cross-border recognition, which qualified signature status does not. The two regimes are independent. Mixing them up in a compliance submission gets it rejected.
November 7, 2018
Estonian scheme notified
ID card, residence permit card, Digi-ID, e-Residency Digi-ID, Mobiil-ID, and diplomatic card, notified at assurance level high (OJ 2018/C 401/08).
December 18, 2019
Latvia’s scheme is notified
Notified at assurance levels substantial and high (OJ 2019/C 425/06).
August 21, 2020
Lithuania’s scheme is notified
Lithuanian national ID card (eID/ATK), assurance level high (OJ 2020/C 276/02).
January 2023
Smart-ID overtakes the state’s own tools
In the Estonian state authentication service, Smart-ID overtakes Mobiil-ID and the ID card.
May 2023
3,298,969 active users
Combined figure for the three Baltic states: about 79 million transactions a month. The peak, in March 2023, was 85 million.
April 25, 2025
Finland’s scheme is notified
The Citizen Certificate on the Finnish ID card is notified at assurance level high (OJ C/2025/2448).

eIDAS 2 and the European Digital Identity Wallet

Regulation (EU) 2024/1183 of April 11, 2024, published in the Official Journal on April 30, 2024, amends Regulation (EU) No 910/2014 to establish the European digital identity framework. It requires every member state to provide its residents with at least one European Digital Identity Wallet, built on common specifications. Some private companies will have to accept it. The regulation phases in the transition and sets the deadlines that go with it.

The deadlines run from the regulation’s implementing acts, not from the regulation itself. The first batch was adopted on November 28, 2024, published on December 4, 2024, and entered into force 20 days later. It includes Implementing Regulation (EU) 2024/2979, which covers the wallet’s integrity and core functions. Article 5a(1) then gives member states 24 months to provide a wallet. Article 5f(2) gives the private relying parties it covers 36 months to accept it.

April 11, 2024
Regulation (EU) 2024/1183 adopted
Amends Regulation (EU) No 910/2014. Published in the Official Journal on April 30, 2024; the framework enters into force in May 2024.
November 28, 2024
First batch of implementing acts
Includes Implementing Regulation (EU) 2024/2979 on the wallet’s integrity and core functions. Published on December 4, 2024.
December 24, 2024
Implementing acts enter into force
This is the date that starts the clock for Article 5a and Article 5f, not the date of the base regulation.
24 months later
Member state obligation
Each member state provides at least one European Digital Identity Wallet (Article 5a(1)).
36 months later
Private relying party obligation
The private companies covered must accept the wallet (Article 5f(2)). Banks and financial services are among them wherever the law requires strong user authentication.

Six large-scale pilot consortia are testing the specifications ahead of the deadline: POTENTIAL, NOBID, DC4EU, EWC, APTITUDE, and WEBUILD. They are funded by European Commission grants. Payments are among the use cases being tested, along with travel, education, driver’s licenses, public services, banking, telecoms, signatures, and organizational identities. What these pilots deliver will set the attestation formats actually implemented, which the regulation leaves open.

TopicBeforeWith the European wallet
Proof of identity at account openingScanned ID, document verification, or a national ID not recognized across bordersElectronic attestation of attributes presented by the holder, legally valid across the EU
Geographic reachOne contract per country with the local identity providerCommon specifications, and a single integration designed to work in all 27 member states
Data disclosureThe full identity record passes through the verification providerSelective disclosure: the wallet attests the requested attribute without revealing anything else
Relying party statusBilateral contract, no public registrationRelying parties must register and declare the attributes they request
What the wallet changes for a payments company
⚠️
The wallet does not replace anything
A common reading is that the European wallet will replace existing national IDs. The regulation says no such thing. BankID, MitID, itsme, and Smart-ID remain in service, banks keep requiring them, and users keep using them out of habit. The wallet adds an interoperable option, and some companies are required to accept it. A user flow that swaps the local ID for the wallet would lose conversions in countries where that local ID has become the everyday way to sign in.

Singapore, Australia, Canada, Nigeria, and Latin America

Outside Europe and India, the identity systems that payments rely on fall into four groups. The first is state-issued identity exposed through APIs, with Singapore as the textbook case. The second is an identity broker tied to payment rails, the Australian and Canadian model. The third is a biometric bank identifier mandated by the central bank, the Nigerian model. The fourth reuses a tax or civil ID number as the key to opening an account, a very common practice in Latin America. None of these models carries over unchanged from one market to another.

🇸🇬
Singpass and Myinfo, Singapore
State-issued identity available to government agencies and businesses. Singpass reports more than 4.2 million app users and more than 41 million transactions a month. More than 2,700 services are connected, and more than 800 government agencies and businesses use it (Singpass, page updated July 16, 2026). Myinfo pre-fills account opening forms with data the government has already verified.
🇦🇺
ConnectID, Australia
An identity broker run by Australian Payments Plus, formed in 2022 through the merger of eftpos, BPAY, and NPP Australia, and accredited by the Australian government as an identity exchange. Users have their data attested by a trusted organization, in practice their bank, and ConnectID itself stores none of the data.
🇨🇦
Interac Verified, Canada
Interac Corp. runs a verification service that reuses the customer’s online banking credentials and adds verification of government-issued documents. It handled 568 million verification transactions in 2024 (Interac Corp.). Canadian government services use its authentication service, Interac Sign-In. It is a rare case of a domestic payment scheme that has become a de facto identity provider.
🇳🇬
BVN and NIN, Nigeria
The Bank Verification Number, run by NIBSS since 2014, is Nigeria’s single biometric banking identifier. A Central Bank of Nigeria circular dated December 1, 2023 (ref. PSM/DIR/PUB/CIR/001/053), made the BVN and the NIN (National Identification Number) mandatory on all accounts and wallets. It required electronic revalidation by January 31, 2024, and ordered a freeze on debits from noncompliant accounts.

In Latin America, account opening usually relies on the civil ID number residents already have. In Chile, a CuentaRUT account can be opened just by showing a national ID number, with no income requirement. BancoEstado has offered it since 2006, and it reported 15.5 million customers at its 20th anniversary. In Costa Rica, the central bank’s SINPE handles settlement, transfers, direct debits, check clearing, and digital identity services under one roof. The same combination of roles shows up outside the region in Bahrain, where BENEFIT runs the national switch, the Electronic Fund Transfer System, the credit bureau, and the country’s e-KYC.

ℹ️
South Korea: ending a monopoly does not open up the checkout flow
The monopoly held by the 공인인증서 public certificate ended with the amended Digital Signature Act, which took effect on December 10, 2020. Opening up the market legally did not change the checkout flow itself. Identity verification usually relies on a phone number registered in Korea and linked to a resident registration number, which in practice shuts out nonresident buyers. Without an alternative verification path, a checkout aimed at international customers loses every buyer without a Korean identity.

Account opening: registry, document, liveness

Remote identity verification has to prove two separate things. The first is that the person claimed exists and that their civil status data is accurate. The second is that this same person is actually in front of the camera at the time of the request. Existence is checked by querying a registry or reading a document. Presence can only be established by a liveness check. A system that covers only one of the two leaves the attack vector for the other wide open.

MethodWhat it provesWhat it does not proveWhere it dominates
Registry lookup (Aadhaar, BVN, Singpass, Myinfo)That the data matches an official recordThat the applicant is the registered person, if the only factor is a code sent by SMSIndia, Nigeria, Singapore, Bahrain
Reuse of online banking credentials (BankID, itsme, iDIN, ConnectID, Interac Verified)That the bank has already completed due diligence and vouches for itThat the bank’s due diligence meets the relying party’s regulatory requirementsNordic countries, Belgium, the Netherlands, Australia, Canada
Document verification and liveness detectionThat the document is genuine and the person is physically presentThat the document was not obtained fraudulently in the first placeAnywhere there is no registry to query
Three remote verification methods and what they prove

Liveness detection covers the techniques used to confirm that a captured face belongs to a person who is physically present. It has to deal with two very different attack vectors that a standard video capture cannot tell apart. A presentation attack holds a screen, a photo, or a mask up to the lens, and it can be caught through image analysis. An injection attack replaces the camera feed with synthetic video before it reaches the sensor. No image analysis can catch it, because the feed that arrives is perfectly clean. Detecting it requires an integrity attestation for the device and the channel. Many products sold as “anti-deepfake” only cover the first vector.

🔑
Tiered KYC, and why it exists everywhere
Almost every financial inclusion regime is built on tiers. A tier 1 account opens with a minimal ID and comes with very low balance and transaction limits, while higher tiers require full due diligence. The same approach appears in African mobile money and underpins Colombia’s depósitos de bajo monto (low-value deposit accounts), with Daviplata as the prototype. It is also the basis for the RBI’s limits on OTP-based e-KYC. An onboarding flow designed without tiers leaves only two options: shut out half the market or open noncompliant accounts.

The last hurdle in multi-country projects is making due diligence portable across borders. No due diligence record is automatically valid across a border. A customer verified in Nigeria with their BVN is not verified in Ghana, and a Swedish customer authenticated with BankID is not identified in Denmark. The European wallet is built precisely to make this portable within the EU, which is what sets it apart from earlier systems. Everywhere else, verification has to be redone in each jurisdiction, at a cost.

Strong authentication built on national identity

Strong authentication is defined the same way everywhere: at least two independent factors drawn from knowledge, possession, and inherence. In the European Economic Area, the rule comes from Article 97 of PSD2 and Delegated Regulation (EU) 2018/389. Where a trusted national electronic ID exists, banks do not build a second system. They delegate SCA to that ID. The customer then uses the same app to log in to the tax portal and to approve a payment.

An online payment authenticated with a national ID
Buyer
Confirms their cart and picks a payment method
No merchant or PSP password is entered at this point
PSP
Triggers authentication with the issuer
Depends on the rail: 3-D Secure for cards, a redirect to the bank’s interface for payment initiation
Issuer
Delegates authentication to the identity provider
BankID, MitID, itsme, or Smart-ID depending on the country. The customer switches to the app they already use for everything
Identity provider
Authenticates and signs the transaction details
The amount and the payee appear in the identity app. That is dynamic linking
Issuer
Receives the proof and authorizes
Fraud liability shifts according to the rail’s rules. The authentication proof is kept for dispute handling

Dynamic linking ties the authentication proof to the amount and the payee of the transaction in progress. Strong authentication for a payment therefore proves two things: that the account holder is present, and exactly what transaction they are approving. A system that only shows a generic login confirmation screen, without the amount, does not meet this requirement. The Nordic and Baltic electronic IDs display the transaction details in the app, which makes them usable for payments as is.

⚠️
Delegating SCA means delegating your uptime
When payment authentication depends on a single national identity provider, an outage at that provider stops online payments across the whole country. There is no fallback, because the customer has no other factor and the merchant has no workaround. This has two operational consequences. The identity contract must include a clear availability commitment and an incident reporting channel. And monitoring must separate authentication failures caused by the customer from those caused by the provider. Otherwise, an outage looks like a drop in conversion.

Payee verification applies the same identity requirement to the recipient of the funds. In the euro area, Regulation (EU) 2024/886 has required it for euro credit transfers since October 9, 2025. The name the payer enters is checked against the actual holder of the receiving account, and the payer is warned before confirming. The mechanism is a tool against credit transfer fraud, not an AML requirement. It shifts the identity question from the customer to the recipient of the funds.

What breaks, and what to negotiate

Identity integration projects fail for a handful of reasons, which recur from one market to the next in a fairly consistent order. They are rarely technical. Most of the problems come from the license the applicant needs, the contract terms, and the exact scope of what the provider attests to.

SymptomRoot causeWhat should have been done
The project slips by several months before the first requestAccess to the identity provider requires an authorization or a license, not an API keyTreat getting the identity contract as a critical-path dependency from the scoping stage
Direct debit mandates are challengedThe system used authenticates but does not produce a signature valid under local lawCheck authentication, signature, and the assurance level separately
Conversion collapses in one countryThe flow requires a national ID that nonresidents do not haveOffer foreign buyers an alternative, document-based path
An outage looks like a performance dropAuthentication failures do not distinguish a customer decline from a provider outageLog failure causes by code, and track provider uptime separately
The compliance submission is rejectedRecognized, qualified, and notified schemes are confusedGet the provider to state in writing the exact legal regime of each service you sign up for
An account is opened but cannot be usedThe light onboarding flow opens a capped account with no path to the next tierDesign the upgrade path to full due diligence at the same time as the entry tier
Recurring failures in multi-country identity projects
  • Map the identity layer before the payment rail. You can switch rails, but not the national identity provider.
  • Separate the four services in the contract: identification, authentication, attribute verification, and signature. They are priced separately, and the provider’s liability differs for each.
  • Use an identity broker when several providers coexist in a country (Finland, Australia), unless your volume justifies direct integrations.
  • Require dynamic linking from any system used to authenticate a payment: the amount and the payee must appear in the identity app.
  • Treat liveness detection as two problems: presentation attacks in front of the lens, and feed injection before the camera. The second requires a device integrity attestation.
  • Track the eIDAS 2 timeline by implementing act, not by the date of the base regulation. The implementing acts start the 24- and 36-month clocks.
  • Never assume due diligence carries across borders unless a specific regime says so. A customer verified in one country is just a prospect in the next.
🔑
The question to ask every identity provider
Two clauses define what an identity contract actually covers: exactly what is being attested, and what liability the provider bears if that attestation turns out to be false. The provider’s answer on both must be in writing, with amounts and limits. A provider that attests a data match is not attesting an identity, because the match covers declared fields, not the person presenting them. Nor does login authentication amount to payment consent, since it is not tied to the amount or the payee. Issuing a qualified signature makes the provider liable under the trust services regime. The price difference between these three services is far smaller than the cost of getting the classification wrong.