Curaçao has imposed new rules for remote customer identification and verification, giving operators already using digital onboarding until 1 May 2027 to bring their systems into line. The framework allows document scanning, videoconferencing and biometric checks, but only if firms can show that the technology is controlled, tested and monitored for money-laundering risk.
The Provisions for Identification and Verification without Physical Contact took effect on 21 August and were developed by the Curaçao Gaming Authority, the Central Bank of Curaçao and Sint Maarten, and the Financial Intelligence Unit Curaçao under the National Ordinance on Identification when rendering Services. They apply across the sectors covered by that ordinance, not just online gambling, although gaming firms are likely to be among the most affected.
The rules are strict about how a remote check must work. Operators must be able to establish identity from recognised documents, validate copies, verify that the customer is physically present and link that person to the document. Where the process cannot reach a reliable result because the evidence is poor or the technology fails, the onboarding must stop, restart or move to an in-person check.
Firms introducing a new remote onboarding solution must comply before going live. Those already using one may continue during the transition only if they have begun the compliance work and can demonstrate that to a supervisor on request. The obligations are not limited to gaming licences: the provisions bind service providers within the NOIS scope, though money transfer companies are excluded from having non-face-to-face clients.
The framework also requires a formal pre-launch assessment of any new or materially changed solution. That assessment must consider data quality, fraud and impersonation risk, operational and legal exposure, mitigating controls and end-to-end testing, and companies must be able to show what they tested and why the system fits their customer, product and jurisdictional risk profile.
Once a system is in use, ongoing monitoring is mandatory. Reviews must cover data accuracy, reliability and changing AML risk, with extra checks triggered by events such as higher fraud attempts, audit findings or regulatory change. Technology controls must include encrypted data, detailed audit trails, access logs, biometric accuracy testing and regular security reviews, while cloud-based or outsourced systems need annual independent penetration testing.
The burden does not move to the vendor if a company outsources verification. The operator remains responsible for demonstrating compliance, and failure to do so can lead to administrative or criminal sanctions, including fines, licence revocation and imprisonment.



