Curaçao Tightens Standards for Remote Player ID Verification

publisher-admin Aug 31, 2026
Featured news image

Curaçao has put new binding requirements into effect for service providers that verify customers without meeting them in person, establishing detailed standards for remote identification procedures across businesses covered by the country’s identification legislation.

The provisions became effective on August 21, 2026. Companies that already use remote verification technology have been granted a transition period, with full compliance required by May 1, 2027.

The Curaçao Gaming Authority (CGA), Central Bank of Curaçao and Sint Maarten (CBCS) and Financial Intelligence Unit Curaçao (FIU) jointly developed the requirements under Article 3 paragraph 1 of the National Ordinance on Identification when rendering Services (NOIS).

The framework forms part of Curaçao’s existing requirements concerning anti-money laundering, counter-terrorist financing and counter-proliferation financing. It applies to service providers that fall under NOIS, although money transfer businesses remain outside the remote verification provisions because they cannot accept customers on a non-face-to-face basis.

Accepted Methods for Confirming Customer Identity

Service providers can verify an individual by using a valid passport, driving licence, identity card or another identification document designated by the Minister of Finance.

Similar identification obligations apply when businesses need to establish the identities of people connected with legal entities. These can include directors, controllers, representatives, proxy-holders and ultimate beneficiaries.

Certified documentation continues to qualify as an approved method of validation. A provider may rely on a certified identity document or an extract from a civil registry. When a customer initially submits documentation electronically, however, the provider must receive a certified copy within two weeks.

The rules also allow companies to use technological tools during remote onboarding. Permitted techniques include specialised identification-document scanning, checks of security features and biometric comparison. Providers may also use videoconferencing.

A video verification session cannot consist solely of an employee visually inspecting the customer’s identification document. Companies must carry out additional controls when the customer’s risk profile makes further verification necessary.

Automated systems face additional requirements when no employee participates directly in the identification process. Providers using these systems must obtain images or video during the verification session and apply liveness detection.

The technology must compare the person undergoing verification with the image contained in the relevant official identification document. When the collected material does not provide sufficient or reliable evidence, the provider must begin the verification process again or require an in-person procedure.

Verification Technology Requires Formal Assessment

Companies also have responsibilities before they introduce remote verification technology into their operations.

Under the provisions, providers “must assess a remote verification solution before introducing it” or before making a material change to an existing system.

The assessment must cover the quality of the information used by the system and the reliability of its underlying sources. Companies must also consider risks involving fraud and impersonation, together with operational, technological, legal and reputational risks associated with the verification process.

Providers must complete end-to-end testing of their systems and be prepared to demonstrate the results of their assessments to supervisors when requested.

Internal procedures must clearly identify which stages operate automatically and which stages involve employee participation. Staff members responsible for attended remote verification procedures must also receive suitable training for their role.

Responsibilities continue after the technology enters operation. Service providers must monitor remote verification systems on an ongoing basis and review whether changes affect their reliability.

These reviews must account for developments such as changes in risk exposure, technical weaknesses and increased attempts at fraud. Regulatory changes must also form part of the monitoring process. When a provider identifies deficiencies that could undermine the reliability of its system, it must document the measures used to address them.

Existing Providers Receive Transition Period

The technical requirements extend to the way providers protect and retain verification information. Systems must maintain audit trails and provide secure storage for collected evidence. Encryption and privacy safeguards must also form part of the controls.

Companies using biometric verification must test their technology for bias and assess false acceptance and false rejection rates.

Providers that rely on cloud-based technology or outsourced verification services face further security obligations. Those systems must undergo independent security and penetration testing every year.

A provider introducing remote verification for the first time must meet the new requirements before putting the system into use.

Companies with existing systems may continue operating them during the transitional period, provided they have already started the necessary compliance work and can show supervisors that they are making progress toward meeting the requirements.

The final compliance date is May 1, 2027. Providers that fail to satisfy the provisions can face administrative or criminal enforcement. Available sanctions include fines and penalties, while more serious consequences can include licence revocation or imprisonment.

Source:

Curaçao Tightens Player Verification Rules, LCB.org, August 29, 2026