Curaçao regulators set binding rules for remote customer onboarding
Curaçao Regulators Set Binding Rules for Remote Customer Onboarding
New Binding Rules for Remote Customer Onboarding
Operators that do not yet use a remote onboarding tool must comply with new standards before launching one. Those already running a solution have until 1 May 2027 to meet the requirements. Until the National Ordinance on Identification when Rendering Services (NOIS) was amended in May 2024, Curaçao accepted only one way to verify the identity of a customer who was not physically present: a certified copy of an identity document.
On 21 August 2026, the Curaçao Gaming Authority (CGA), the Central Bank of Curaçao and Sint Maarten (CBCS), and the Financial Intelligence Unit Curaçao (FIU) jointly enacted provisions that now govern how remote identification and verification must be carried out.
Key Provisions at a Glance
What the Provisions Cover
The Provisions for Identification and Verification without Physical Contact implement Article 3, paragraph 1 of the NOIS. This article requires supervisory authorities to set rules for identifying natural persons who are not physically present. The provisions apply to all service providers under the scope of the NOIS identity verification rules—not only gaming licensees—and form part of the existing anti-money laundering (AML), counter-terrorist financing (CTF), and counter-proliferation financing framework.
Identity Verification Requirements
Identity must be established using one of the following documents:
- A valid driving licence
- An identity card
- A passport
- Another document designated by the Minister of Finance
The same rules apply to controllers, proxy-holders, directors, representatives, and ultimate beneficial owners of corporate clients.
Validation and Verification Processes
How Validation Works
Certification remains an acceptable method to validate a document. This can be done either through a certified copy or extract from the civil registry, or by sending the document electronically and following up with a certified copy within two weeks.
Providers may instead use technology such as:
- Laser-engraving detection
- ID-scanning software
- Videoconferencing (video checks must go beyond a simple visual inspection of the document)
Verification Links the Document to the Person
Verification then links the validated document to the person appearing on screen. For unattended solutions, the system must:
- Capture images at the time of the check
- Run liveness detection
- Use algorithms benchmarked against internationally recognised standards (e.g., ISO, IEC, or NIST frameworks)
Attended solutions require trained staff and a defined escalation process. If the evidence is too poor to produce a clear result, onboarding must be stopped and either restarted or moved to a face-to-face check.
Testing, Monitoring, and Compliance
Pre-Implementation Testing
The paperwork comes first. No tool may go live until the provider has:
- Assessed the solution
- Tested it end-to-end
- Probed it for impersonation fraud
- Documented the entire process
Supervisors can request to see these results at any time.
Ongoing Monitoring
Monitoring must continue after launch. Unscheduled reviews are required when:
- Risk exposure shifts
- An audit finds a fault
- Fraud attempts appear to rise
- The law changes
From a technical standpoint, the provisions demand:
- A time-stamped audit trail
- Encrypted data
- Biometric systems tested for bias
- Annual penetration testing (if the system is cloud-based or outsourced)
Deadlines and Penalties
Providers that do not yet use a remote onboarding solution must comply before implementing one. Those already running a solution have until 1 May 2027 to achieve full compliance. In the meantime, they may keep their existing setup provided they have started the work and can demonstrate it upon request.
Non-compliance will trigger administrative and criminal sanctions, including:
- Fines and penalties
- Licence revocation
- Imprisonment
The announcement closes by urging operators to act now rather than wait for the deadline: “All operators are encouraged to review the provisions carefully, take note of the applicable requirements, and take the necessary steps to ensure that their procedures, controls and systems are aligned accordingly.”
Why It Matters for Operators
The immediate work is largely documentary. Most operators already run a KYC vendor. However, far fewer will have:
- A written pre-implementation assessment
- A defined monitoring cadence
- An evidence trail that a supervisor can inspect
Outsourcing does not shift this burden—the provider, not the vendor, must demonstrate compliance.
The provisions apply a uniform approach across all sectors under supervision. This means gaming licensees and institutions overseen by the CBCS now work to the same onboarding standard. The rules follow the National Ordinance on Games of Chance, which took effect on 24 December 2024, and sit alongside the CGA’s other guidance issued since, including its rules on alternative dispute resolution.
Related guides
- $24M Florida Slots Case: Owner Seeks Dismissal of RICO and Money Laundering Charges
- ADM Authorises Setka Cup Betting: BETER Gains Access to Italy’s Regulated Market
- ANJL: Ban on Licensed Online Casinos Could Double Brazil’s Illegal Gambling Market
- ASA Maintains Strict Gambling Ad Control: A Comprehensive Guide to Two New Rulings
- ASA upholds complaint against Midnite over AI-generated character in TikTok ad