
CBCS, FIU, and CGA Collaborate to Establish Uniform Standards for Remote Onboarding Under the National Ordinance on Identification When Rendering Services
Curaçao’s primary supervisory authorities, the Central Bank of Curaçao and Sint Maarten (CBCS), the Financial Intelligence Unit (FIU), and the Curaçao Gaming Authority (CGA), have jointly introduced a comprehensive framework governing the identification and verification of natural persons without physical contact. Developed in close collaboration with the private sector, the new provisions fulfill the requirements stipulated under Article 3, paragraph 1 of the National Ordinance on Identification when rendering Services (NOIS).
Designed to ensure a uniform regulatory approach across all supervised sectors, the provisions integrate seamlessly into existing Anti-Money Laundering, Countering the Financing of Terrorism, and Countering Proliferation Financing (AML/CFT/CFP) guidelines. The framework aims to facilitate responsible innovation, allowing service providers to leverage advanced digital technologies while maintaining rigorous risk management standards.
Scope, Validation, and Verification Standards
The provisions apply to all service providers within the scope of the NOIS, excluding money transfer companies, which are prohibited from utilizing non-face-to-face client acquisition. Under the rules, accepted identification documents include valid passports, identity cards, and driver’s licenses issued by competent authorities.
To authenticate client identities remotely, service providers may utilize certified document copies or advanced technological solutions. Approved methods include:
- Advanced Document Validation: Remote detection of laser engraving features, microprinting analysis, and specialized software verification against authentic template databases.
- Biometric and Liveness Verification: Utilizing facial recognition, iris scans, and fingerprints matched against official documents using robust algorithms, supported by liveness detection during unattended sessions or trained personnel during attended video-conferencing.
- Official Database Cross-Checking: Verifying provided credentials directly against official government or reliable public records.
Policies, Pre-Implementation Testing, and Security Mandates
Supervised institutions must establish robust, risk-sensitive policies and procedures prior to deploying remote onboarding solutions. These internal frameworks require comprehensive pre-implementation assessments covering data accuracy, fraud and impersonation risks, ICT vulnerabilities, and end-to-end functionality testing.
Furthermore, technological infrastructure must comply with stringent security standards, featuring end-to-end data encryption, multi-factor authentication, secure audit logging, and regular vulnerability or penetration testing. Cloud-based or outsourced systems must align with recognized international frameworks such as ISO 27001 and provide independent assurance reports like SOC or ISAE 3402 Type 2.
Implementation Timeline and Transitional Provisions
The provisions by the CGA enter into force immediately upon publication. Service providers currently utilizing remote onboarding solutions are granted a transitional period until May 1, 2027, to achieve full compliance, provided they have initiated necessary corrective steps and can demonstrate progress to their respective supervisors upon request. Institutions adopting remote solutions after the publication date must ensure full compliance prior to implementation. Non-compliance constitutes a violation of Article 3 of the NOIS, exposing entities to administrative and criminal sanctions, including financial penalties, license revocation, and imprisonment.