2022-11-24
Added · Updated
Payment initiation service providers (PISPs) must perform customer due diligence under the Anti-Money Laundering and Anti-Terrorist Financing Act to prevent misuse for money laundering and terrorist financing. Simplified due diligence is the standard approach, requiring identification and verification using at least two independent and reliable sources, such as bank API data or Trade Register extracts. PISPs must also establish the purpose of the business relationship, verify customer representatives, identify ultimate beneficial owners, and conduct politically exposed person reviews based on risk factors.
Q&A
Read aloud
Question:
Do the customer due diligence (CDD) requirements apply to payment initiation service providers (PISPs)?
Published: 24 November 2022
On 1 March 2021, the European Banking Authority (EBA) published the final revised Guidelines on money laundering and terrorist financing (ML/TF) risk factors . The EBA has included new ML/TF risk factors. We have amended these Q&As on the basis of the revised Guidelines.
Answer:
Account information service providers (PISPs) must perform customer 1 due diligence to prevent their services from being used for money laundering and terrorist financing. These service providers fall under the Anti-Money Laundering and Anti-Terrorist Financing Act (Wet ter voorkoming van witwassen en financieren van terrorisme – Wwft) pursuant to Section 1a(1) of that act.
Simplified CDD is the standard approach for PISPs, given the low risk inherent in their services. A PISP must take into account all data available to it for which customers have given their explicit consent. The CDD must be documented in customer files and comprise at least the following elements:
Customer identification
A PISP must identify its customers on the basis of Section 3(2) under a of the Wwft. There is no prescribed format for identifying customers. This information can also be used for screening customers against relevant sanctions lists. If a PISP has a business relationship with a customer that offers a payment service user (PSU) the opportunity to use the relevant PISP's to initiate a single or one-off transaction, the PSU does not qualify as the PISP's customer.
Customer identity verification
A PISP must verify its customers’ identity on the basis of Article 3(2) under a of the Wwft. A risk-based approach can be taken to verification. We consider it necessary for a PISP to make use of at least two independent and reliable sources. This could include (personal) data taken from the bank API, as well as information from an extract from the Trade Register of the Chamber of Commerce (a certified copy or obtained via an API from the Chamber of Commerce), or a passport scan.
Purpose and intended nature of the business relationship
Pursuant to Section 3(2) under c of the Wwft, a PISP must establish the purpose and intended nature of the business relationship. When the PISP has identified risk factors for a customer, it must further investigate the purpose and intended nature of the business relationship and the transactions conducted during the relationship. The purpose of this is to monitor whether the customer's behaviour is consistent with these statements. In the absence of such risk factors, the PISP can apply simplified CDD and assume the purpose and nature of the business relationship.
Review of customer representative
When a natural person states they are acting as a representative of a customer, a PISP must also determine whether this person is authorised to do so. For legal entities, the representatives are often the board members. When a natural person claims to indirectly represent a legal person (whereby the legal person is the customer), the chain of representative authority must be determined. An extract from the Trade Register of the Chamber of Commerce may for example be used for this purpose. When this authorisation has been established, the customer is then the subject of the CDD measures set out in Section 3 of the Wwft. The natural person acting as representative must also be identified and their identity verified. Verification must occur by means of two independent and reliable sources. An extract from the Trade Register of the Chamber of Commerce may for example be used for this purpose, combined with a second source, such as personal data obtained from the bank API.
Identifying ultimate beneficial owners (UBOs)
A PISP must carry out CDD which enables it to identify the customer's ultimate beneficial owner (UBO). A PISP must also take all necessary and reasonable measures to verify the identity. There is no prescribed format for identifying customers, but this can for example be done through a UBO declaration or an organisation diagram. In the case of simplified CCD, a UBO's identity can be verified using a risk-based approach, based on various types of sources, but this must not result in the UBO's identity not being verified.
Review of politically exposed persons (PEPs)
Pursuant to Section 8(5) of the Wwft, a PISP must have adequate risk management systems in place with risk-based procedures to determine whether a customer or UBO is a politically exposed person (PEP). In practice, this must result in a PISP conducting a PEP review at the start of the business relationship, or at a suitable point after the start of the business relationship, for example when certain risk factors increase or when a time limit has expired. External sources or tools can be used for this purpose.
[1]Section 1(1) of the Wwft defines a customer as the natural or legal person with which a business relationship is entered into or on whose behalf a transaction is conducted.
Transaction monitoring requirements for payment initiation services (service 7)
Transaction monitoring requirements for account information services (service 8)
Due diligence requirements for account information services (service 8)
Discover related articles
Q&A
Integrity & sanctions
Payment institutions
Share:
Share on LinkedIn
Share on X
Share on Facebook
Share via Email
Interesting articles
De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’
25 June 2026
News item supervision
In the third edition of ‘Integrity Supervision in Focus’ (ISF), we share the key insights from our integrity supervision.
Read more De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’
News item supervision
25 June 2026
DNB email on technical adjustments
25 June 2026
News item supervision
This week, you may receive an email from De Nederlandsche Bank (DNB). This email concerns technical adjustments required to continue corresponding with DNB by email.
Read more DNB email on technical adjustments
News item supervision
25 June 2026
Update FATF-warning lists June 2026
23 June 2026
News item supervision
FATF released an update of its ‘grey’ and ‘black’ lists.
Read more Update FATF-warning lists June 2026
News item supervision
23 June 2026
Banks and payment institutions are actively combating payment fraud but could adopt a more targeted approach
03 June 2026
News item supervision
Payment fraud has a significant impact on society. We therefore consider the management of external payment fraud to be an important topic, as secure and reliable payment systems are central to our public mandate, as emphasised in our Payments Strategy 2026-2028.
Read more Banks and payment institutions are actively combating payment fraud but could adopt a more targeted approach
News item supervision
03 June 2026
Necessary cookies
To ensure the proper operation of the website, De Nederlandsche Bank (DNB) uses functional cookies and analytics cookies, and has taken measures to ensure that these cookies have little or no impact on the privacy of website users.
Optional cookies
Some pages include embedded content from external websites. These websites may use proprietary (tracking) cookies. This allows third parties to track visitor statistics, show personalised content and display targeted ads, for example.
You can make your choice about allowing these optional cookies both when you first visit the website and when you navigate to a page with embedded content.