KYC & AML Compliance in Italy (2026): Customer Due Diligence for Digital Finance
Italian digital-finance teams need customer due diligence that joins identity, ownership, purpose, risk, review, and audit evidence in one accountable file.
Italian digital-finance teams need customer due diligence that joins identity, ownership, purpose, risk, review, and audit evidence in one accountable file.
Direct answer: A regulated digital-finance team in Italy must apply customer due diligence in line with its AML/CFT obligations, including a risk-based understanding of the customer and relationship, ongoing review, escalation, suspicious-operation reporting where required, and retrievable records. A digital journey can speed collection, but it cannot remove the need for an accountable case decision.
As of 23 July 2026. This guide is an operational overview, not legal advice.
VOVE ID helps Italian payments and fintech teams connect identity evidence with review actions and an auditable case record. The breakdown happens when a customer looks complete at onboarding but the team cannot explain the identity, ownership, and risk reasoning behind the decision.
This is exactly where customer due diligence stalls.
Regulatory map: set the Italian control perimeter first
Italy's AML/CFT framework is anchored in Legislative Decree No. 231 of 21 November 2007, as amended. For intermediaries within the Bank of Italy's remit, the Bank's customer-due-diligence provisions specify an operational framework for adequate verification of customers. The Bank of Italy's 2019 provisions are a primary supervisory reference.
The perimeter is not identical for every digital-finance model. A bank, payment institution, electronic-money institution, financial intermediary, agent, or service provider can have different obligations, outsourcing arrangements, and supervisory touchpoints. Teams should determine their actual role before they treat a product journey as a complete compliance design.
The Bank of Italy's AML FAQs also make the risk-based point explicit: a firm sets the timing and frequency of data updates in its AML policies according to the customer's risk profile, and must update information when it is no longer current. The published FAQ is useful for translating ongoing review into operating practice.
For the underlying operating model, see our KYC Requirements Explained 2026.
Customer due diligence: make the relationship visible, not merely collected
Customer due diligence is not a checklist of uploads. It is the process by which a team gathers and assesses the information needed to understand a customer and the business relationship, including the relevant identity, ownership, purpose, and risk context.
For a digital customer journey, the critical question is what happens when the evidence does not line up. An individual's document, a company's ownership chain, its anticipated use of the service, and a review outcome need to meet in one case. If they remain in separate tools, a completed journey can still create an incomplete control file.
The EBA's remote customer-onboarding guidelines apply to credit and financial institutions within AMLD scope and have been in force since 2 October 2023. They set out common steps for safe and effective remote onboarding under applicable AML/CFT and data-protection rules. The EBA's final guidance should inform a firm's own risk-based control design.
A realistic failure: a digital merchant is onboarded without a joined-up ownership record
An Italian payments platform receives an application from an online merchant with sales across several EU markets.
- Identity evidence for the authorized representative
- Company documents and stated beneficial-owner details
- A description of expected payment activity
- A screening outcome that requires review

Then the file breaks apart. The identity result sits in the verification service, the ownership explanation is saved as a PDF, and the analyst records the exception decision in a spreadsheet. The merchant begins processing payments.
Later, the ownership information changes and transaction behavior no longer fits the original purpose. The team cannot tell which ownership structure was accepted, what risk factors the analyst considered, or whether the original exception was resolved with enough evidence.
This is not a document-collection failure. It is a customer-file failure.
Ongoing review and suspicious operations: design the escalation chain before an alert
The relationship does not freeze after onboarding. Italian teams need a defined way to notice when relevant information or activity changes, collect additional facts, apply decision rights, and preserve the rationale for the outcome.
The UIF's current guidance states that suspicious-operation reports are submitted electronically through the Infostat-UIF portal after registration and authorization. It also identifies the 18 December 2025 instructions made under Legislative Decree 231/2007 for the content and submission of reports. UIF's SOS reporting page is the operational reference.
Teams should not wait for an alert to determine who owns the review. A potential match, a changing ownership structure, or activity that does not fit the stated purpose must create a documented task with clear escalation, evidence, and decision paths. This means one thing: monitoring is useful only when it feeds a controlled case process.
The EU AML Regulation, Regulation (EU) 2024/1624, is scheduled to apply from 10 July 2027 to most obliged entities. Article 90 gives teams a near-term reason to test whether their controls and records can support a more harmonised EU framework.
For the underlying operating model, see our AML Requirements Explained 2026.
Records and privacy: retain an explainable record, not a loose archive
Digital finance creates a large volume of sensitive evidence. Teams need access controls, logged actions, clear retention and deletion policies, and a way to preserve relevant facts when a case needs review. Those controls should align with the firm's legal obligations, data-protection responsibilities, and operational policies.
The test is practical. A compliance reviewer should be able to reconstruct why a relationship was accepted, restricted, escalated, or declined without searching across personal drives, vendor exports, and chat messages. If the rationale cannot be recovered, the customer file has not done its job.
How VOVE ID fits: connect evidence to an accountable workflow
VOVE ID supports identity verification, biometric liveness, face matching, AML screening, KYB, and transaction monitoring. It supports 2,000+ document types across 200+ countries and can help surface document-template inconsistencies, invalid MRZ checksums, barcode or QR inconsistencies, and image manipulation.
VOVE ID does not determine an Italian firm's risk appetite, legal obligations, or suspicious-operation reporting decision. It helps teams collect evidence, route exceptions, and retain a case record that is useful in operations and review.
Practical Italy KYC and AML checklist
Governance
- Confirm the firm's AML/CFT perimeter, supervisor, and accountable decision owner.
- Maintain documented risk policies for customer, product, geography, and channel risk.
- Define approval rights for ownership complexity, exceptions, and elevated-risk cases.
Customer due diligence
- Join identity, beneficial-owner, relationship-purpose, and risk evidence in one file.
- Define what reviewers must record when evidence conflicts or needs follow-up.
- Test remote-onboarding controls against the EBA guidance and the firm's own risk assessment.
Monitoring and reporting
- Set customer-review triggers for ownership, activity, and risk-profile changes.
- Preserve the facts, review actions, and decision rationale for each escalation.
- Maintain a tested electronic reporting route to UIF where a report is required.
Records and privacy
- Restrict customer and ownership evidence by role.
- Define retention, deletion, and legal-hold controls with appropriate advice.
- Test whether a completed case can be reconstructed without manual searching.
FAQ
What should a digital-finance CDD file contain? It should connect the evidence used to identify the customer and relevant owners, the purpose and risk assessment, review actions, exceptions, monitoring triggers, and the final relationship decision.
Does a completed remote check finish due diligence? No. A remote check is one input. The firm still needs a risk-based assessment, controlled exception handling, ongoing review, and an accountable file.
How are suspicious-operation reports submitted in Italy? UIF states that reports are transmitted electronically through the Infostat-UIF portal after the reporter is registered and authorized. Firms should validate their exact reporting procedure with current requirements.
When should customer information be updated? The timing should reflect the customer's risk profile and the firm's AML policies. Information should also be updated when the firm identifies that it is no longer current.
Conclusion
KYC and AML compliance in Italy is not a task of collecting more documents. It is the discipline of building and maintaining an explainable customer relationship record.
Digital-finance teams need identity, ownership, risk, review, monitoring, and audit evidence to stay connected as the relationship changes. Collection, verification, review, and case management are one workflow.
Want to see how VOVE ID supports a country-aware identity and compliance workflow?
This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. KYC/KYB/AML requirements may vary depending on jurisdiction, industry, and specific business circumstances. For up-to-date and binding compliance obligations, readers should refer to the relevant regulatory authorities or consult qualified professionals.