FATF-数字身份监管指引(英文)-2020.3-107页_4mb
报告摘要
Summary of FATF Guidance on Digital Identity
Core Content
This document provides FATF Guidance on Digital Identity, focusing on how digital identity (ID) systems can be used to meet Customer Due Diligence (CDD) requirements under FATF Recommendation 10. The guidance aims to help governments, regulated entities, and digital ID service providers understand and implement digital ID systems in a way that supports AML/CFT compliance, financial inclusion, and risk-based approaches.
Main Viewpoints
- Digital ID systems are becoming increasingly important in the context of growing digital financial transactions, which are expected to reach 726 billion transactions annually by 2020 and 60% of global GDP by 2022.
- The FATF promotes a technology-neutral approach, meaning no preference is given to specific types of digital ID systems.
- Digital ID assurance frameworks and standards (such as NIST and eIDAS) are critical for evaluating the reliability and independence of digital ID systems for AML/CFT purposes.
- Risk-based approaches are essential in determining whether a digital ID system is suitable for CDD, depending on the assurance levels of the system and the associated ML/TF risks.
Key Information
Digital ID Terminology and Key Features
- Digital ID systems involve identity proofing and enrolment, binding, and authentication.
- Identity proofing involves obtaining and verifying identity attributes (e.g., name, date of birth, ID number).
- Binding links the individual to the issued credentials or authenticators.
- Authentication confirms that the individual is the one in possession of the credentials.
FATF CDD Requirements
- The FATF requires reliable, independent source documents, data, or information for customer identification and verification.
- In the context of digital ID systems, this means the system must have adequate technology, governance, and procedures to ensure appropriate levels of confidence in its reliability and independence.
Benefits of Digital ID Systems
- Digital ID systems can enhance financial inclusion by enabling individuals to prove their identity remotely.
- They offer improved customer experience, cost reduction, and increased efficiency for regulated entities.
- These systems can support ongoing due diligence, transaction monitoring, and risk management.
Risks of Digital ID Systems
- Risks include cybersecurity threats, identity theft, and large-scale fraud.
- These risks are more significant in digital ID systems due to the potential scale of attacks and cybersecurity vulnerabilities.
- Poorly designed or unsecured digital ID systems can compromise personal identifiable information (PII) and undermine AML/CFT efforts.
Recommendations
For Government Authorities
- Develop clear guidelines or regulations allowing the risk-based use of digital ID systems.
- Assess and revise existing CDD regulations to accommodate digital ID systems.
- Adopt flexible, performance-based criteria for identity proofing and authentication.
- Establish integrated policies that combine digital ID, AML/CFT, anti-fraud, and risk management activities.
- Support multi-stakeholder approaches to understand and mitigate risks in the digital ID ecosystem.
- Enhance dialogue and cooperation with private sector stakeholders, including through regulatory sandboxes.
- Audit and certify digital ID systems against transparent assurance frameworks.
- Promote harmonisation of digital ID standards and frameworks to ensure a common understanding of what constitutes a reliable, independent system.
- Provide transparent information about the digital ID system's assurance levels and how it works.
For Regulated Entities
- Understand the components of digital ID systems, especially identity proofing and authentication.
- Take an informed, risk-based approach to using digital ID systems for CDD, ensuring that the assurance levels are appropriate for the ML/TF risks involved.
- Consider using lower assurance level systems for simplified due diligence in low-risk scenarios.
- Review and revise internal policies that classify non-face-to-face transactions as high risk.
- Use anti-fraud and cybersecurity processes to support digital ID verification and ongoing due diligence.
- Ensure access to underlying identity information for compliance with AML/CFT record-keeping requirements.
For Digital ID Service Providers
- Understand AML/CFT requirements and related regulations, including record-keeping obligations.
- Seek assurance testing and certification from the government or an approved expert body.
- Participate in regulatory sandboxes or other testing mechanisms to evaluate assurance levels.
- Provide transparent information about the system's assurance levels, including federation and interoperability.
Conclusion
The FATF Guidance on Digital Identity outlines a risk-based framework for the use of digital ID systems in customer identification and verification, and ongoing due diligence. It highlights the importance of assurance levels, technical standards, and collaboration between public and private sectors to ensure AML/CFT compliance and financial inclusion. The guidance is non-binding but provides clarification and support for implementing digital ID systems in a secure and effective manner.
试读结束,高清完整版pdf/doc/ppt,请点下载