EUDI Wallet & AMLR: Securing Verifiable Credentials
The portable Verifiable Credential (VC) is no longer a concept. High-net-worth individuals (HNWIs) investors and regular retail banking customers can be verified once, onboarded across multiple products in minutes, with the same cryptographically-bound credential.
But what about the document behind the credential? This is a question that’s not being asked loudly enough. The U.S. Treasury’s March 2026 report to Congress calls verifiable credentials “a potential pathway to mitigate identity fraud and other sources of identity-related illicit finance risk.” And they are right. Especially about the ‘potential’ part.
An identity insurance policy for the EUDI Wallet & Verifiable Credential economy
Verifiable credential models work like this:
- An issuer creates and cryptographically signs the credential once, including document check, biometric match and liveness test.
- The user stores it in a digital wallet, together with their other credentials.
- A bank, employer or other third party, uses cryptographic keys to instantly verify the credential’s authenticity. No need to contact a central database.
The result is cryptographically bound and issued to the holder. The holder presents it downstream; no re-verification needed. Onboarding speed goes up, friction goes down and data exposure shrinks. But we see a weak point at the moment of issuance.
If a manipulated synthetic document passes the initial check, the credential issued against it may be cryptographically perfect. It is also fraudulent. And it travels. To product A, fund B and institution C. Basically, it can go to every relying party in the network. Yes, verified once, but incorrectly.
Digital identity wallet risks: probabilistic models vs. deterministic data
This specific attack is not hypothetical. We have shown in a previous article that document fraud at enrollment can include real document numbers, but with substituted photographs, ML-assisted morph attacks that defeat automated facial comparison, and template-injected security features that replicate the visual appearance of genuine documents.
These typologies are active, documented, and evolving fast. Roughly 4% of digital identity checks at enrollment were flagged as fraudulent in 2025. EU and UK rates were even higher. And according to this article in SQ Magazine, in roughly 8% of digital onboarding verification, fraud attempts were detected.
Credential portability based on deterministic data and authentic ID documents can reduce enrollment fraud risk. But a tampered document or unreliable probabilistic model at the heart of digital ID wallet initiatives, will scale ID fraud, rather than reducing it.
Digital-native does not automatically mean digital-only
Now, we know that one of the more persistent assumptions is that younger customers want every interaction to be fully remote. That idea is becoming outdated. Digital-native customers may prefer mobile-first journeys for routine tasks, but Gartner sees a significant rise in preference for human reassurance and in-person contact when the moment carries financial or personal consequence.
That matters here. Opening a bank account, establishing a new financial commitment or handing over the keys to one’s identity is not a low-stakes interaction. For some customers, especially those who grew up in the post-Covid period, a well-designed in-person verification step is not an inconvenience. It is a signal that the institution takes risk, identity and trust seriously.
Meeting AMLR, eIDAS 2.0, and IAL compliance standards at issuance
The EU Anti-Money Laundering Regulation (AMLR), which applies directly across Member States, sets the CDD standard at customer onboarding. Institutions must identify customers using reliable, independent source documents, data, or information. The burden is on the institution accepting the identity claim. A verifiable credential presented by a customer is a claim. Under AMLR, the institution accepting it must be able to demonstrate that the source document was genuine.
“We received a cryptographically signed credential” is not an audit-defensible answer.
The EUDI Wallet Architecture Reference Framework, developed under eIDAS 2.0, defines the requirements for high-assurance credential issuance across the EU. Member State wallet pilots are running through 2026, with mandatory relying-party acceptance timelines into 2027. The framework specifies that credentials issued at high assurance require identity proofing against authoritative document sources. The regulation assumes the issuance step is rigorous, but does not guarantee it.
In the United States, NIST SP 800-63A-4, published in final form in July 2025, strengthened the enrollment fraud requirements for credential service providers at Identity assurance levels (IAL) 2 and (IAL) 3. The updated guidelines introduce programmatic fraud management requirements specifically designed to address fraudulent document presentation at the enrollment step.
The standards do not assume a document is genuine because a credential was issued. They require that the issuance process itself is defensible in audits.
The pattern across these legislations is remarkably consistent. The credential is downstream, and the document check is the evidentiary foundation. Get it wrong, and the credential inherits the error, and distributes it at scale. With all potential impact on customers, financial health and reputation.
Closing the audit gap with primary-source identity proofing data
A document examiner, whether human or automated, can only check what they can compare against. If the reference library does not include the latest security feature specifications for a Ghanaian passport updated six months ago, or the new Dutch residence permit released last quarter, the comparison is imprecise. The check passes and the fraud is enrolled.
This is not a failure of biometrics or liveness detection. Those tools do what they are designed to do: confirm that the person presenting the document is alive and matches the document photo. But they cannot confirm that the document itself is genuine. That requires a different layer. A reference layer.
Keesing has maintained the world’s earliest primary-source document reference database. Our DocumentChecker ID and banknote reference database is updated continuously through direct relationships with more than 200 issuing authorities, manufacturers, governments, border agencies, and forensic laboratories with operational ties to INTERPOL, Europol and the FBI’s forensic document laboratory.
DocumentChecker is seen as a best of breed solution, with 70,000 high-quality images across 250 countries and territories, featuring full-color HD, infrared and UV scans that allow high-quality zooming, highlight security features like holograms and microprint and comes with an MRZ decoder. Moreover, our lifelong relations with issuing authorities uniquely ensure that our database is always updated immediately upon newly issued security specifications, instead of when secondary aggregators notice the change.
This is what audit-defensible issuance means. Not a liveness check that passed. Not a credential that is cryptographically valid. A document verification event that a compliance examiner, a regulator, or a court can trace to a primary source with extremely well-documented provenance.
ID infrastructure needs a premium insurance policy
The credential economy is building an infrastructure that carries valuable and very personal transactions. But it needs a robust foundation to stand on with confidence. The distinction matters when the credential is presented to a compliance examiner, a sanctions screening system, or a court that asks: where does this identity claim actually come from? Keesing provides the reference layer that makes credential issuance audit-defensible.
We are part of IN Groupe, which published an interesting white paper on digital identity in May 2026. Drawing on a proprietary analysis of 210 countries, their central finding was clear:
The 30% of countries that have deployed digital ID successfully share a common pattern. They treat it as economic and social infrastructure, embedded in everyday life.
One of IN Groupe‘s operational principles is building trust at the core. Keesing was built on exactly this principle. Not on processing transactions faster, but on making the identity claim at the start of the transaction accurate and hold up under scrutiny. With primary-source reference data with real-time updates, validated by our questioned document experts team, and backed by an audit trail that satisfies the evidentiary standard of any jurisdiction the credential reaches.
Many financial institutions, such as the Dutch National Bank (and 20+ other central banks), US-based JP MorganChase (and 8 other top-20 US banks), online payments provider Paysafe, and over 96% of all physical bank branches in the Nordics, work with our solutions. Not just as a direct competitor to more probability-based remote onboarding suppliers, but often also as an ‘Intel Inside’ ID Intelligence Layer in these mobile onboarding apps; a premium insurance policy for the 8% of onboardings where fraud is attempted.
The million-dollar question before accepting a credential
The portable credential model is a genuine improvement. Faster onboarding. Less repeated document collection. Reduced centralised data exposure. These are real benefits for institutions, and for the people they serve.
But before accepting a verifiable credential, there is one question worth asking every issuer: what did you check the document against?