2022-11-24
Added · Updated
Account information service providers (AISPs) must perform customer due diligence on end users (account holders) under the Anti-Money Laundering and Anti-Terrorist Financing Act. This obligation applies when the AISP enters into a business relationship with the account holder, which typically occurs when consent to access accounts is granted for a specific period rather than for a single transaction. Consequently, AISPs must verify the identity of both the direct customer and the account holder in scenarios involving third-party data collection.
Q&A
Read aloud
Question:
Are account information service providers (AISPs, Service 8) required to perform customer due diligence on end users (account holders) of the service?
Published: 24 November 2022
Answer:
Yes. Account information service providers (AISPs, Service 8) are required by law to perform customer due diligence on the payment service user (PSU): the account holder who is the end user of the service. The aim is to prevent the AISP from being used for money laundering or terrorist financing purposes 1 .
Customer due diligence: customer identification and verification
Under Section 3 of the Anti-Money Laundering and Anti-Terrorist Financing Act (Wet ter voorkoming van witwassen en financiering van terrorisme – Wwft), AISPs must perform customer due diligence of all customers 2 with which they enter into a business relationship 3 .
The most common situation is that the PSU enters into a direct relationship with the AISP. In another situation, the AISP collects information on an account holder's account on behalf of a third party.
For example:
Account holder A applies for a mortgage loan from credit provider B, who wants access to A's accounts to assess the application. B then engages the services of AISP C, who needs A's consent to deliver the required information to B.
In this example, AISP C has two customer within the meaning of the Wwft:
Natural person or legal entity B, with whom it enters into a business relationship, and Natural person or legal entity A (the PSU), who gives consent to a transaction. Whether A also enters into a business relationship with C depends on the type of consent that A gives to C. If C is given consent for downloading a single transaction overview, this is considered a one-off transaction that does not qualify as a business relationship. However, if C is given consent to access A's accounts more than once, this does qualify as a business relationship, which means C must perform customer due diligence on both B and A.
Since the end user/account holder usually gives consent for a specific period (e.g. 90 days), in practice this means that a business relationship usually exists.
This means the AISP must also perform customer due diligence on account holders if it only collects “raw” payment data from account holders on behalf of a non-licensed party that compiles these data into overviews for the account holder.
1 The inherent risk of money laundering or terrorist financing through AISPs is low. The customer due diligence requirements for account information services (service 8) are therefore lower. More information
2 The customer is the natural or legal person with whom a business relationship is entered into or who has a transaction effected (Section 1(1) of the Wwft). A transaction is defined as follows: “An act or a combination of acts performed by or on behalf of a customer of which the institution has taken note in the provision of its services to that customer (Section 1(1), under b, of the Wwft)”. Providing an account overview also qualifies as a transaction.
3 A business relationship is a professional or commercial relationship between an institution and a natural person, legal entity or partnership firm, which is related to the professional activities of the institution and is expected to continue for a certain period from the moment the relationship is entered into. (Section 1(1), under b, of the Wwft).
Discover related articles
Q&A
Integrity & sanctions
Payment institutions
Share:
Share on LinkedIn
Share on X
Share on Facebook
Share via Email
Interesting articles
De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’
25 June 2026
News item supervision
In the third edition of ‘Integrity Supervision in Focus’ (ISF), we share the key insights from our integrity supervision.
Read more De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’
News item supervision
25 June 2026
DNB email on technical adjustments
25 June 2026
News item supervision
This week, you may receive an email from De Nederlandsche Bank (DNB). This email concerns technical adjustments required to continue corresponding with DNB by email.
Read more DNB email on technical adjustments
News item supervision
25 June 2026
Update FATF-warning lists June 2026
23 June 2026
News item supervision
FATF released an update of its ‘grey’ and ‘black’ lists.
Read more Update FATF-warning lists June 2026
News item supervision
23 June 2026
Banks and payment institutions are actively combating payment fraud but could adopt a more targeted approach
03 June 2026
News item supervision
Payment fraud has a significant impact on society. We therefore consider the management of external payment fraud to be an important topic, as secure and reliable payment systems are central to our public mandate, as emphasised in our Payments Strategy 2026-2028.
Read more Banks and payment institutions are actively combating payment fraud but could adopt a more targeted approach
News item supervision
03 June 2026
Necessary cookies
To ensure the proper operation of the website, De Nederlandsche Bank (DNB) uses functional cookies and analytics cookies, and has taken measures to ensure that these cookies have little or no impact on the privacy of website users.
Optional cookies
Some pages include embedded content from external websites. These websites may use proprietary (tracking) cookies. This allows third parties to track visitor statistics, show personalised content and display targeted ads, for example.
You can make your choice about allowing these optional cookies both when you first visit the website and when you navigate to a page with embedded content.