Imagine it is 2027: A customer opens an account with your bank entirely digitally, without paper and without visiting a branch. Their identity is confirmed within seconds via the EU Digital Identity Wallet, required attributes such as residence and a digitally attested proof of income are checked automatically, and the contract is completed with an electronic signature.
This is exactly what eIDAS 2.0 will make possible, and banks are under pressure to act: Banks that integrate wallet-based processes early not only secure regulatory compliance, but also gain speed, efficiency and customer satisfaction.
Many banks say today: 'We already have VideoIdent, PostIdent or eID, that is enough.' Unfortunately, that is not the case. These methods will remain in place, but eIDAS 2.0 introduces the EUDI Wallet as a new, Europe-wide standardised source of verified identity attributes, and banks will be required to accept it.
This article shows in practical terms how banks need to prepare in 2026/2027, which processes are particularly affected and what opportunities this creates for operational excellence and digital competitiveness.
What to Expect in This Article:
- Fundamentals: What Are eIDAS 2.0 and the EUDI Wallet?
- Business Case Comparison: Account Opening Today vs. Wallet-Based (2027)
- Why eIDAS 2.0 Is Forcing Banks to Prepare Now
- What Is Changing in Practice? The Most Important eIDAS 2.0 Changes for Banks
- Rethinking Account Opening: Digital, Fast and Wallet-Based
- Roadmap 2026-2027: Four Phases to Becoming a Wallet-Ready Bank
- Policy Mapping for SES/AES/QES by Risk Level
- Wallet Integration into Identification & Attribute Verification
- Technical Requirements & Interfaces
- Audit Logs & Preservation of Evidentiary Value for Wallet-Based Data
- Defining Pilot Processes: Where Banks Should Start in 2026
- Compliance & Risk: What Legal, Data Protection and MaRisk Teams Need to Consider
- Organisation & Governance: RACI for the Wallet Project
- Practical Check: The Wallet in Everyday Banking
- KPI Set: What Banks Should Measure
- Risks & Pitfalls and How Banks Can Avoid Them
- Summary & Recommendations for Banks
- FAQ: Frequently Asked Questions About eIDAS 2.0 & the Wallet
Planning 2025-2027
2025: Analysis of regulatory requirements and initial process reviews. Development of technical interfaces and piloting in selected branches or processes.
2026: Extended testing, employee training and preparation for full integration.
2027: Mandatory start of wallet acceptance across all relevant banking processes.
The critical period is not 2027, but 2025-2026. Banks that start pilots and integration now will experience the 2027 wallet acceptance obligation not as a risk, but as an opportunity to scale.
Fundamentals: What Are eIDAS 2.0 and the EUDI Wallet?
eIDAS 2.0 and the EUDI Wallet create a common EU framework for digital identities, electronic signatures and verified attribute attestations. This enables banks to verify identity, residence or representation rights digitally across borders in a legally robust, standardised way without paper-based evidence.
What Is eIDAS '1.0'?
eIDAS (Regulation (EU) No 910/2014) is the EU legal framework for electronic identification and trust services that has applied since 2016. It primarily governs how electronic signatures, seals and timestamps are legally recognised and how national eID systems can be used across borders. It does not yet provide a single EU-wide wallet solution.
What Is eIDAS 2.0?
eIDAS 2.0 is the revised EU regulation on electronic identification and trust services. It defines how citizens and businesses will be able to identify themselves digitally, sign and provide evidence in the near future, within a binding legal framework for all Member States.
Key eIDAS 2.0 Points for Banks:
What Is the EUDI Wallet in Simple Terms?
The EUDI Wallet (European Digital Identity Wallet) can be understood as a state-recognised digital identity app. Users can store their identity data (PID) and verified credentials in it, such as proof of residence or a driving licence, and potentially also proof of income or company information in the future, and selectively share them when needed.
Key Features of the EUDI Wallet:
- Wallet as a trusted container for identity and attributes
- Users decide which data they share with which bank (selective disclosure)
- Digital credentials are cryptographically protected and verifiable
- Use of the wallet is voluntary, but acceptance by banks is mandatory
Contrast: Manual identification = copies, manual checks and media breaks. Wallet-based identification = verified attributes in real time, with an audit trail.
How Does the Wallet Work in Practice?
The EUDI Wallet can be described as a simple process chain:
- Issuance: Public authorities or trust service providers issue digital credentials, such as identity, residence or representation rights, as signed credentials.
- Storage: Users store these credentials in their wallet.
- Sharing: When opening an account or applying for a loan, users choose which attributes they share with the bank.
- Validation: The bank automatically verifies the signatures and trust status of the credentials.
- Use: Verified attributes flow into KYC, credit decisions and signature processes.
Many people ask: Is the wallet just 'another app'?
No. The wallet can become the central source for standardised, digitally verifiable credentials instead of fragmented individual documents sent by email, submitted through forms and then checked manually. Wallet attributes form the basis for end-to-end onboarding processes that can be largely automated.
Who Plays Which Role in the Wallet Ecosystem?
For banks to use the EUDI Wallet effectively, the roles within the ecosystem need to be understood.
Key Roles at a Glance:
- Member State / Wallet Provider: Provides or authorises the wallet and defines security and certification requirements.
- Trust Service Providers (e.g. QTSPs): Issue qualified certificates, signatures and electronic attestations of attributes, for example identity, company data and specific credentials.
- Bank as a Relying Party: Uses wallet data for account opening, KYC (Know Your Customer), lending processes and signature journeys. Verifies credentials and manages attribute requirements.
- Business Department: defines which attributes are required for which banking processes.
- Head of Compliance: assesses wallet attributes, KYC rules and signature levels.
- IT Governance: is responsible for wallet connectivity, interfaces, certificates and security testing.
- Internal Audit: checks whether wallet-based processes, audit trails and preservation of evidentiary value comply with MaRisk/BAIT requirements.
Key Point: Wallet integration → focuses on identity and attribute verification. Practical observation: audit-trail transparency → strengthens compliance and evidentiary value.
eIDAS 2.0 / Wallet Readiness Check
From Regulatory Obligation to a Roadmap with CIR Impact
We make your core processes, including accounts, lending and service, wallet-ready from a business, technical and regulatory perspective. Within 4-6 weeks, you receive a clear, actionable roadmap from eIDAS 2.0 to productive use of the EUDI Wallet, including a business case and defined responsibilities.
Our Preconfigured Readiness Analysis Includes:
- Assessment of core processes (accounts, lending, service) with wallet touchpoints
- Risk & signature mapping (SES/AES/QES) for each process
- High-level target architecture: Wallet ↔ Paperfly ↔ core banking system/DMS/KYC
- Concrete 2026/2027 roadmap with priorities & quick wins
- Business case (CIR/OPEX effects) and proposed RACI for business departments, IT and compliance
Business Case Comparison: Account Opening Today vs. Wallet-Based (2027)
Wallet-based identities not only reduce identification costs, but also shift the entire process structure towards Straight-Through Processing. The effects directly impact the KPIs that CFOs and executive boards prioritise in digitalisation and CIR (Cost-Income Ratio) discussions.
Account Opening with a Traditional KYC Journey vs. Wallet-Integrated Account Opening
| KPI | Today | With Wallet (2026 / 2027) |
Effect |
|---|---|---|---|
| Turnaround Time | 1-3 days (including document checks, follow-up questions and approvals) | 15-60 minutes (PID + automated attribute verification + digital decision) | -70 bis -90 % |
| Manual Effort per Case (Bank) | 15-25 minutes | 3-8 minutes | -55 bis -80 % |
| First-Time-Right (FTR), without follow-up questions or corrections | 65–80 % | 90–98 % | +15 bis +30 pp |
| Error / Follow-Up Question Rate | 20–30 % | 2–8 % | -70 bis -90 % |
| OPEX per Account Opening | 18–35 € | 7–15 € | -40 bis -60 % |
| Drop-Off Rate | 20–40 % | 5–15 % | -15 bis -25 pp |
Measurement framework: period: 6-12 months · population: digital retail customer account openings · method: before/after comparison (matching) · scope: end-to-end process including document/attribute verification, follow-up questions and approvals · data sources: wallet/PID logs, KYC system, core banking system, DMS/audit trail · reporting: monthly (median, P90, FTR, error rate).
Why eIDAS 2.0 Is Forcing Banks to Prepare Now
Brief Answer: From 2026/2027, eIDAS 2.0 will require banks to accept EU-wide digital identities via wallets. As a result, account opening, lending processes and signature journeys must become technically wallet-ready.
Attributes such as identity, residence, representation rights or attested proof of income are validated digitally, making processes faster, more verifiable and audit-proof.
The regulatory timeline through the end of 2026 and beginning of 2027 requires banks to make technical and organisational adjustments at an early stage.
Risk of Starting Late: Starting late means implementing the wallet only shortly before the acceptance obligation at the end of 2027. Banks that take this approach compress project work, process design, testing and training into a narrow time window, while other banks may already have implemented their workflows.
If banks start pilots in 2026, they can spread effort and risk over several years, learn from real volumes and refine policies, RACI structures and IT interfaces step by step. Executive boards and CFOs benefit because the dual-cost phase becomes a management lever with measurable effects on Time-to-Yes, First-Time-Right and OPEX, rather than a purely regulatory project without business impact.
At Its Core, the EUDI Framework (Regulation (EU) 2024/1183 + Implementing Acts) Provides:
Wallet AvailabilityMember States must provide at least one EUDI Wallet within 24 months of the Implementing Acts entering into force. The Implementing Acts entered into force at the end of 2024, which effectively places the deadline at the end of 2026.
Acceptance Obligation (Private Relying Parties Such as Banks)Private service providers in regulated sectors that are required to use strong customer authentication (SCA), including the banking and financial sector, must accept EUDI Wallet credentials within 36 months of the Implementing Acts if customers wish to use them. In practice, this means by the end of 2027.
What Is Changing in Practice? The Most Important eIDAS 2.0 Changes for Banks
With eIDAS 2.0, the introduction of the EUDI Wallet and new rules on person identification data (PID) require banks to fundamentally rethink their identification and signature processes.
Statt bisheriger papierbasierter oder lokaler digitaler Verfahren liefert die Wallet standardisierte, attributbasierte Nachweise (z. B. Name, Geburtsdatum, Wohnsitz).
Rethinking Account Opening: Digital, Fast and Wallet-Based
The introduction of the EUDI Wallet fundamentally digitalises account opening. Banks must accept wallet attributes for personal identification and KYC/GWG checks.
This Means: Customers can provide their identity, proof of residence or other required attributes directly via the wallet.
Wallet Power for Account Opening & KYC/GWG
| Step in the Account Opening Process | Wallet Relevance | Benefit / Impact | Implementation Tips |
|---|---|---|---|
| Identity Verification (PID) | Automated retrieval of person identification data from the wallet | Reduced manual checks, faster verification | API integration: Wallet → KYC system, real-time validation |
| Attribute Verification (Residence, Date of Birth) | Wallet provides certified attributes | Compliant and paperless | Integrate attributes directly into the CRM/KYC system and automate risk classification |
| GWG/AML Check | Wallet attributes for risk profiling & screening | Reduction of money laundering & fraud risks | Automated screening checks using wallet data, with audit trail storage |
| Digital Signature (QES/AES/SES) | QES for account opening agreements | Legally robust digital signing | Implement the signature workflow in the core banking or contract management system |
Business impact: when uploaded evidence is no longer required, the effect goes beyond First-Time-Right. OPEX benefits increase in two ways: fewer follow-up questions + faster validation = lower personnel costs and less rework.
From Application to Payout: The Wallet in the Lending Workflow
The integration of the EUDI Wallet into lending processes will become a key competitive factor for banks from 2026/2027. Wallet-based identity and attribute credentials make it possible to automate creditworthiness checks. PID attributes (person identification data), proof of income, company data or creditworthiness information can be retrieved directly from the wallet.
This Reduces Manual Document Review, accelerates the lending onboarding process and at the same time increases compliance assurance with regard to KYC (Know Your Customer), the German Anti-Money Laundering Act (GwG) and AML (Anti-Money Laundering) requirements.
How the EUDI Wallet Changes Credit Assessments
| Process Step | Traditional | With EUDI Wallet | Benefit / Impact |
|---|---|---|---|
| Identity Verification: Customer / Company | Manual Review | PID & verified attributes from the wallet | Time savings, fewer errors, automatic documentation |
| Creditworthiness Check / Income | Paper documents, manual review of bank statements | Wallet attributes for income/financial data | Faster checks, higher data quality |
| Company Verification (Turnover, Shareholders) | Commercial register extract, manual validation | Digital attestations from the wallet | Automation, compliant processing |
| Signing of Loan Agreements | In person or PDF scan with signature | QES / AES / SES via the wallet | Legally robust, digital, auditable |
| KYC/GWG Check | Manual, across multiple systems | Automatic wallet-based validation | Lower risk, end-to-end audit trail |
Roadmap 2026-2027: Four Phases to Becoming a Wallet-Ready Bank
The introduction of the EUDI Wallet requires banks to align their processes, systems and governance structures strategically with wallet integration. A structured roadmap for the coming months helps banks meet regulatory requirements on time while maximising operational value and customer experience.
The Roadmap Is Divided into Four Phases, which build on one another: analysis & policy mapping, piloting & system integration, rollout & process optimisation, and monitoring & scaling. Each phase addresses specific topics such as KYC/GWG integration, signature types, interfaces to core banking systems/DMS and audit-trail compliance.
From Pilot to Full Rollout: The Roadmap to a Wallet-Ready Bank
Phase 1: Start: Risk analysis & signature mapping for all banking processes
Phase 2: Pilot: Make account opening or a lending process wallet-ready
Phase 3: Rollout: Extend wallet integration to additional services after a successful pilot
Phase 4: Monitor & Optimise: KPI measurement and continuous process improvement
Fast Implementation Instead of a Major Project: Paperfly as a Wallet-Ready Process Layer
Paperfly provides wallet-ready workflows as prebuilt components. Business departments can configure account opening, lending journeys or service processes, while technical integration is handled through standard APIs. This keeps implementation business-driven, with IT informed but not overloaded.
Wallet & eIDAS 2.0 do not affect only identification methods, but complete end-to-end processes.
This Is Exactly Where Paperfly Fits:
- Orchestration layer between the wallet, KYC system, core banking system, DMS and signature service.
- Workflow engine that translates PID and attribute data from the wallet into concrete process steps, including logic, STP (Straight-Through Processing) and fallback scenarios.
- Audit trail & preservation of evidentiary value as standard functionality: a key requirement for MaRisk/BAIT and internal audit.
- Signature hub for SES/AES/QES, including risk-based mapping by process.
Paperfly therefore acts as the missing link between new wallet standards and your existing customer processes.
Preparation Step 1: Policy Mapping for SES/AES/QES by Risk Level
Business Department: initiates the process & assesses risk classes. The eIDAS 2.0 regulation requires banks to reassess signature classes and assign their electronic signatures, SES, AES and QES, on a risk-based basis. This particularly affects sensitive banking processes such as account opening, credit approvals, powers of attorney and card approvals.
Wallet integration not only enables existing signatures to be represented digitally, but also allows the signature class to be selected efficiently and transparently according to process risk and the required regulatory level of assurance.
Banks Need to Consider the Following Aspects:
- Define Process Risk: assessment based on regulatory risk, including GwG, credit risk, payments and legal acts
- Assign Signature Types: SES (simple), AES (advanced), QES (qualified)
- Assess Wallet Integration: use of wallet-based QES for high-risk processes
Matrix: Risk Class ↔ Signature Type ↔ Wallet Integration
| Banking Process | Risk Level | Recommended Signature | Wallet Integration Possible? |
|---|---|---|---|
| Account Opening | Medium | QES | Yes, attribute verification + optional QES |
| Account Opening (Private Deposits > €100,000) | High | QES | Yes, direct wallet-based QES possible |
| Credit Approval (Retail) | High | QES | Yes, document verification via wallet attributes |
| Credit Approval (Business) | Very High | QES | Yes, including powers of attorney + attribute credentials |
| Card Approval / Limit Change | Medium | AES | Yes, attributes such as identity and residence, relevant for AML |
| Powers of Attorney / Contract Changes | High | QES | Yes, use wallet attributes requiring signatures |
| Service Changes | Low | SES | Yes, document verification via wallet attributes |
Business impact: choosing the appropriate signature level prevents over-securing processes. Every unnecessary QES requirement extends processing times and can increase costs per case by up to 300%. Correct classification saves both time and licence costs.
Preparation Step 2: Wallet Integration into Identification & Attribute Verification
The introduction of the EUDI Wallet under eIDAS 2.0 enables banks to process person identification data (PID) and attribute-based credentials digitally and automatically.
The Wallet Provides Verified Information on Residence, Income, Identity and Other Credentials, which can be integrated directly into banking processes such as KYC, credit assessment or contract signing. This reduces manual checks, increases efficiency and minimises compliance risks.
Benefits of Wallet Integration at a Glance:
Preparation Step 3: Technical Requirements & Interfaces
IT Governance: is responsible for interfaces & certificates. The introduction of the EUDI Wallet requires clear technical preparation by banks: APIs and interfaces to existing systems must be implemented in a standardised manner to ensure smooth KYC, lending and contract-signing processes.
Technical Check: What Wallet Interfaces Really Need to Deliver
Preparation Step 4: Audit Logs & Preservation of Evidentiary Value for Wallet-Based Data
Internal Audit: ensures preservation of evidentiary value in the bank's internal audit trail. Integrating the EUDI Wallet into banking processes not only delivers efficiency gains, but also requires complete traceability of all data movements.
For Banks, This Means:
- Wallet-Based Identity and Attribute Data must be documented with timestamps in the bank's systems and archived in compliance with GoBD/MaRisk requirements. The bank must not rely on this information still being available from the wallet at a later date.
- Under Section 8 of the German Anti-Money Laundering Act (GwG) , all KYC data must be retained for at least five years and, in many cases due to German banking supervisory requirements under MaRisk, for up to ten years.
- Internal Bank Audit Trails enable traceability of customer actions, approvals and attribute validations, which is essential for internal audit, compliance and regulatory reviews.
- Business Impact: Audit-ready audit trails reduce audit costs and help avoid follow-up questions from supervisors (MaRisk effect).
Banks should therefore not only store audit logs, but actively analyse them in order to identify risks early and optimise processes.
Preparation Step 5: Define Pilot Processes: Where Banks Should Start in 2026
With the introduction of the EUDI Wallet, banks face the challenge of implementing wallet-based processes gradually and with low risk. Pilots help test technical interfaces, process integration and customer acceptance in practice.
The Most Important Criteria for Selecting Suitable Pilot Processes:
- Usage Frequency: Frequently used processes generate reliable data more quickly.
- Process Maturity: Mature processes are easier to automate and digitalise.
- Risk & Compliance: Pilot processes should have manageable regulatory complexity in order to minimise errors.
- ROI Potential: Prioritise processes with high efficiency gains or significant reductions in manual steps.
Top Pilots for 2026: Effort vs. Benefit
| Pilot Process | Effort (Technology & Integration) | Benefit (Efficiency & Compliance) | Quick-Win Potential | Description / Objective |
|---|---|---|---|---|
| KYC with Wallet | Medium | High | High | Automated identification of new customers using wallet attributes, reducing manual KYC steps |
| Address Change via Wallet Attribute | Low | Medium | High | Customers can confirm changes digitally; the bank reduces manual checks |
| Loan Document Review → Ready for Signature | High | High | Medium | Review and approval of loan documents via wallet + QES; faster credit decision process |
| Service Changes / Account Management | Medium | Medium | Medium | Wallet-gestützte Änderungen von Kontoinformationen, z. B. Telefonnummer, E-Mail |
| Business Customer Onboarding | High | High | Low | More complex KYC processes for corporate customers, including attributes for managing directors and shareholders |
With Paperfly, Large Parts of the Project Effort Are Eliminated: All top pilot processes, including KYC, address changes and loan document review, are available as ready-to-use reference journeys.
Preparation Step 6: Compliance & Risk - What Legal, Data Protection & MaRisk Teams Need to Consider
Compliance: assesses wallet attributes & signature levels. The introduction of the EUDI Wallet brings not only technical challenges for banks, but above all legal, regulatory and data protection responsibilities.
Key Compliance Challenges and Opportunities:
- Wallet Acceptance Obligation: Banks are required to support wallet users, which requires adjustments to KYC, GwG and lending processes.
- Data Protection & GDPR: Storage of only the minimum required attributes, attribute encryption and time-limited processing must be ensured.
- MaRisk & BAIT Compliance: For banks operating in Germany, wallet-supported processes must also be integrated into risk management, internal control systems and audit trails in line with German banking supervisory requirements such as MaRisk and BAIT, particularly for high-volume KYC or lending processes.
Data minimisation here means taking only the required attributes from the wallet. For banks operating in Germany, national retention and governance requirements such as GoB, the German Anti-Money Laundering Act (GwG) and MaRisk remain applicable alongside the EU-wide eIDAS 2.0 and GDPR framework.
MaRisk/BAIT Implications
The introduction of the EUDI Wallet under eIDAS 2.0 brings not only technical but also national supervisory requirements for banks. For banks operating in Germany, MaRisk, the German Minimum Requirements for Risk Management, and BAIT, the German Supervisory Requirements for IT in Financial Institutions, must be taken into account alongside the EU-wide eIDAS 2.0 framework when integrating the wallet.
Banks operating in Germany must ensure that wallet-supported processes, such as KYC, signatures and attribute verification, are embedded in their risk and IT governance in line with applicable German supervisory requirements.
Wallet as a Trusted Ecosystem: Security, Responsibility and Certification
The EUDI Wallet is not just another digital touchpoint, but part of a trusted identity ecosystem that requires clear responsibilities, traceability and high security and compliance standards.
- Banks must also assign responsibilities clearly during integration: Who is responsible for wallet connectivity, who manages the requested and verified attributes, and who ensures that signatures are used and logged correctly?
- Zudem fordert eIDAS 2.0 eine vertrauenswürdige Zertifizierung der Wallet-Provider, which is relevant from a security and liability perspective, particularly with regard to qualified electronic attestations.
Implications & Risks under MaRisk / BAIT
| Area | Potential Challenge | Measures / Recommendation |
|---|---|---|
| Risk Management (MaRisk) | New operational risks arising from wallet authentication and attribute verification | Integrate wallet risks into the internal control system (ICS) |
| IT Security (BAIT) | Connection to external wallets as a potential attack vector | Encrypted API connections and regular security reviews |
| Responsibilities | Unclear ownership of wallet-related actions | Roll out a RACI matrix for wallet roles across compliance, IT and business departments |
| Audit & Traceability | Wallet transactions must be logged in an audit-proof manner | Implement audit trails and log attribute changes comprehensively |
| Regulatory Certification | Not all wallet providers meet qualified trust requirements | Use only certified wallet service providers and review contracts |
| Data Protection | Speicherung sensibler Attribute (z. B. Wohnsitz, Einkommen) | GDPR-compliant attribute processing, data minimisation and purpose limitation |
GDPR-Compliant Attribute Storage and Data Minimisation in Wallet Processes
Under the GDPR, personal data such as identity attributes, proof of residence or income information must only be collected and processed to the extent required for the relevant process.
Banks Should Ensure That Identity and Attribute Data Obtained from the Wallet are stored and archived in their own systems in a traceable, secure and audit-proof manner.
Preparation Step 7: Organisation & Governance: RACI for the Wallet Project
Introducing the EUDI Wallet into banking processes requires clear organisational responsibilities to ensure compliance, security and efficiency. A RACI model helps assign roles and responsibilities precisely.
Who is Responsible (R) for carrying out individual process steps, who is Accountable (A) for ultimate responsibility, who is Consulted (C) as a subject-matter expert, and who needs to be kept Informed (I).
RACI Matrix: Roles & Responsibilities in Wallet Integration
| Process / Task | Business Department | Compliance | Internal Audit |
|---|---|---|---|
| Wallet Integration into Account Opening | R | A | I |
| Wallet Integration into Account Opening | R | A | I |
| Attribute Verification & Validation | C | R | I |
| Implementation of QES/AES/SES | C | R | I |
| Audit Trail & Reporting | I | R | A |
| Security & Certification Review | I | C | R |
| Workflow Automation (Paperfly Interfaces) | R | C | I |
Notes:
R = Responsible: wer die Aufgabe ausführt
A = Accountable: wer die Endverantwortung trägt
C = Consulted: wer fachlich einbezogen wird
I = Informed: wer informiert werden muss
Compliance: assesses wallet attributes & signature levels (SES/AES/QES).
IT-Governance: is responsible for API authentication & ARF interfaces.
Fachbereich: starts the onboarding process & determines risk classifications.
Practical Check: The Wallet in Everyday Banking
By 2027, the EUDI Wallet will become a central component of digital banking processes. Banks can use the wallet not only to identify customers, but also to validate attributes, enable digital signatures and automate processes.
Account Opening 2027: PID + Attribute + QES
Account opening in 2027 will be strongly shaped by the EUDI Wallet. Banks can use the wallet to integrate Person Identification Data (PID), required attributes such as residence or income, and qualified electronic signatures directly into the process.
„Lea W., 32, opens a current account in 2027: open wallet → share identity attribute → provide income information → sign with QES → account active.“
Customers benefit from fully digital onboarding, while banks reduce error rates and meet regulatory requirements efficiently.
Key Functions for Wallet-Based Account Opening:
- PID Verification: The wallet provides verified identity data directly to the bank, including name, date of birth and unique identifiers.
- Attribute-Based Credentials: Relevant attributes such as residence, income or document status are verified automatically.
- QES Integration: Contracts or account-opening documents are signed electronically and become legally valid immediately.
- Audit Trail: All steps, including data retrieval, validation and signature, are logged in a traceable manner.
- Integration into Banking Workflows: Wallet data flows directly into KYC and GwG checks as well as internal CRM systems.
In Practice, a Large Part of the Implementation Effort Is Eliminated:
Paperfly already provides wallet, KYC and signature logic as standard workflows, so banks only need to configure attribute checks and signature levels rather than program them.
Loan Application: Digital Documents + Wallet Identification
With the integration of the EUDI Wallet, lending onboarding in 2027 will become a fully digital and legally compliant process. Banks can access verified attributes from the wallet, such as income, and carry out the required KYC checks automatically.
„Daniel B., 51, applies for an online loan in 2027: wallet approval for income and residence → creditworthiness check → QES → payout.“
At the same time, all contract documents can be signed with qualified electronic signatures in a legally valid manner without exchanging paper documents.
Key Components of Wallet-Based Lending Onboarding:
- Digital Identification: PID and relevant attributes are retrieved directly from the wallet.
- Attribute-Based Credit Assessment: Residence, income, creditworthiness and company data, for business loans, are validated automatically.
- Electronic Signatures: for loan applications and contracts are integrated directly into the workflow.
- Audit & Traceability: Attribute requests, validation and signatures are recorded in the audit trail.
- Integration into Banking Processes: Credit assessment, risk evaluation and contract approval run seamlessly and digitally.
The required validation and signature logic is already preconfigured in Paperfly, including PID validation, attribute mapping and QES workflows.
Service Changes: Address Change in Just 60 Seconds
Changing an address via the EUDI Wallet will become a fully digital banking process in 2027. Customers will no longer need to submit their new details on paper or visit a branch. Instead, relevant attribute information will be retrieved directly from the wallet.
„Tariq K., 29, changes his registered address directly via a wallet attribute in 2027: approval → validation → confirmation without upload.“
By combining Identity Verification (IDV), attribute verification and digital signatures, address changes can be completed in under a minute while meeting all regulatory requirements.
Benefits at a Glance:
- Speed: Address change in approximately 60 seconds
- Compliance: Fully logged, GDPR-compliant, including an audit trail
- Security: Wallet-based identity and digital signatures
- Process Integration: Automated integration into core banking, CRM and DMS/archive systems
KPI Set: What Banks Should Measure
With the introduction of the EUDI Wallet and eIDAS 2.0, banks face the challenge of not only digitalising processes but also optimising them in measurable ways. A clearly defined KPI set enables continuous monitoring of efficiency.
Key KPIs for Wallet-Based Banking Processes:
| Process Area | KPI | Calculation / Source | Target 2026-2027 |
|---|---|---|---|
| Account Opening | Turnaround Time | Time from application to activation | < 60 min. |
| First-Time-Right | % without errors / rework | ≥ 95 % | |
| Wallet Adoption Rate | % of customers using the wallet | ≥ 70 % | |
| Lending Processes | Attribute Validation Rate | Successful verification of all PID/attributes | ≥ 98 % |
| QES Success Rate | Successful signature processing | ≥ 99 % | |
| Service Changes | Turnaround Time | Time from request to completion | < 5 Min |
| Error Rate | % of processes corrected manually | < 2 % | Error Rate |
What Does This Mean for the Executive Board & CFO in Practice?
For executive management, eIDAS 2.0 and the EUDI Wallet are strategic levers for efficiency, risk and profitability:
- Mandatory, Not Optional: By 2026/2027, banks must be able to accept wallet-based identities. The question is not whether, but how early you align your processes and systems and what competitive advantage you gain from starting early.
- Direct Impact on CIR & OPEX: Wallet-based onboarding, lending journeys and service processes reduce manual processing, error rates and turnaround times.
- More Controllable Risks: Consistent policy mappings, clear RACI structures and audit-proof audit trails reduce liability risks and discussions with supervisors, internal audit and external auditors.
- Standardised Scalability: Banks that make 2-3 core processes wallet-ready now and measure them properly can roll out the setup to additional products, segments and channels in 2026/2027 without starting from scratch each time.
- Clear Decision Framework: For the executive board, it ultimately comes down to three decisions:
- Timeline: When should wallet processes go live?
- Focus: Which 2-3 core processes offer the greatest leverage?
- Governance: Who holds business responsibility for policy, KPIs and rollout?
This positions eIDAS 2.0 at executive-board level not as another regulatory topic, but as an investment in more efficient, scalable and audit-proof core processes.
Risks & Pitfalls and How Banks Can Avoid Them
Integrating the EUDI Wallet into banking processes creates major efficiency and security gains, but also introduces new risks.
User Adoption
The introduction of the EUDI Wallet into banking processes depends not only on regulatory compliance, but critically on user adoption. Even technically flawless implementations can fail if customers or employees do not understand or accept the wallet.
Fallback Scenarios (Without a Wallet)
Even though the EUDI Wallet will become mandatory to accept for many banking processes, banks must maintain fallback solutions. Not all customers will immediately have or want to use a wallet, and technical outages may also require an alternative route.
Key Points for Fallback Scenarios:
- Traditional Identification: In the German market, established fallback methods include PostIdent, VideoIdent, the German eID online ID function and branch-based identification, alongside identity cards, passports or existing digital ID providers.
- Manual Attribute Verification: Document review by bank employees or digital upload portals as a substitute for wallet-based attribute credentials.
- Signature Alternatives: SES/AES/QES via existing signature platforms if wallet-based QES is not available.
Fraud Scenarios & Attribute Manipulation
As adoption of the EUDI Wallet increases, banks also face growing requirements to manage fraud and manipulation risks proactively. Critical scenarios arise particularly when attributes are transmitted and validated.
Common Fraud Risks:
- Phishing and Fake Wallet Requests: Attackers may attempt to intercept wallet attributes or manipulate transactions.
- Unauthorised Push Payments (APPs): Manipulation of payment instructions via compromised wallet apps.
- Identity Misuse: Combining PID attributes from different sources to gain unauthorised access.
- Manipulation of Attribute Values: False information about residence, income or authorisations.
Summary & Recommendations for Banks
The introduction of eIDAS 2.0 and the EUDI Wallet gives banks the opportunity to turn a regulatory obligation into genuine operational strength. The goal is not simply to change processes, but to follow a clear roadmap across 2026-2027, progressing step by step from understanding and technology to scaling and measurability.
Wallet Pilot for Account/Securities Account Opening (Live in ≤ 8 Weeks)
The Economically Relevant Entry Point into Wallet Processes: We implement a production-ready wallet pilot for account or securities account opening with you, with a clear focus on economic value and a measurable impact on your Cost-Income Ratio. The pilot shows business departments and the executive board how wallet attributes affect processing time, error rates, drop-off rates and OPEX per application in practice.
Our Standard Pilot Delivers Out of the Box:
- Preconfigured, wallet-ready account/securities account opening journey (retail current account / securities account)
- Retrieval of wallet PID and relevant KYC attributes, for example address, basic income information and employment status
- Attribute verification using clear rule sets for First-Time-Right, risk classes and KYC
- Automatic provision of the appropriate signature level, QES, for account and securities account agreements
- Complete, audit-proof audit trail across all steps, including KYC, attributes and signatures
- Optional: KPI setup for Time-to-Yes, First-Time-Right, drop-off rate and OPEX per account/securities account
Target: Pilot go-live within ≤ 8 weeks, with robust figures for CIR impact, scaling to additional products and a well-founded executive-board decision paper.
FAQ: Frequently Asked Questions About eIDAS 2.0 & the Wallet
1. Do Banks Have to Accept the Wallet from 2026/2027?
Yes, from 2026/2027 banks are required to accept the EUDI Wallet as an official source of identity, particularly for KYC processes, account opening and digital signatures. It will therefore become a standardised form of identity evidence within the EU.
Jeder Mitgliedstaat muss bis Dezember 2026 mindestens eine EUDI-Wallet bereitstellen. Ab Ende 2027 beginnt die Pflicht zur Akzeptanz für regulierte relying parties (inkl. Banking/Financial Services).
2. What Data Does the Wallet Provide for KYC?
The wallet provides basic data such as first and last name, date of birth and nationality, as well as optional additional attributes such as address or identity credentials that banks can use for legally required KYC checks.
3. Does the Wallet Replace Existing Identification Methods?
Partly. If customers use the wallet and provide the required attributes, it can replace VideoIdent, eID, PostIdent or physical documents in digital processes. Because use of the wallet remains voluntary, banks will still need fallback methods. It is not a mandatory alternative for all offline processes.
4. Which Signatures Will a Bank Really Need in Future?
With eIDAS 2.0 and the EUDI Wallet, the three-tier signature model remains in place: simple (SES), advanced (AES) and qualified electronic signatures (QES). SES or AES are usually sufficient for service and standard processes. A QES is mandatory whenever a transaction is legally subject to a written-form requirement, for example in the case of consumer loans or certain powers of attorney. In addition, a bank may decide within its risk management framework to require a QES for specific high-risk decisions.
Risk-Based Signature Mapping in Practice:
- If process risk is low, for example standard service or simple contract information → SES.
- If personal-data risks, liability or GwG-related considerations increase → AES.
- If written form, the highest evidentiary value or strict legal consequences apply → QES.
Boundary condition: QES is suitable for clearly defined high-risk and high-value cases, not indiscriminately for all contracts, otherwise costs and turnaround times increase unnecessarily.
5. What Happens If Customers Do Not Have a Wallet?
Banks must continue to offer established identification methods. These include VideoIdent, eID (online ID function), PostIdent, branch-based identification and physical identity documents. The wallet is voluntary for customers, so a complete fallback remains necessary until wallet use is widely established. In brief, the wallet is an additional standardised source of identity, not a replacement for all existing methods.
6. Is the eIDAS 2.0 Wallet (EUDI Wallet) Simply an App?
Yes. The eIDAS 2.0 Wallet, usually referred to as the EUDI Wallet, is a state-recognised smartphone app in which citizens can securely store their digital identity and verified credentials, for example identity data, driving licence or certificates, and share them when needed. Each EU Member State must provide at least one certified EUDI Wallet for its citizens by the end of 2026.
7. Will Use of the EUDI Wallet Be Mandatory for Citizens?
No. Use of the EUDI Wallet will not be mandatory for individuals. The wallet is an option, not an obligation: citizens can use it voluntarily to store and manage their digital identity documents and credentials centrally. For banks, this means they need wallet-ready processes, but also a clearly defined fallback for customers without a wallet.
8. Who Is Developing the Wallet for Germany?
In Germany, the Federal Ministry of the Interior (BMI) is responsible for the state EUDI Wallet. Its design and implementation involve German institutions and organisations including SPRIND, the Federal Agency for Disruptive Innovation, BSI, the Federal Office for Information Security, Bundesdruckerei and Fraunhofer AISEC. Private wallets may also be approved in Germany, but must meet the same EU-wide eIDAS 2.0 and ARF requirements.
Mini Glossary for eIDAS 2.0 Preparation
eIDAS 2.0: EU regulatory framework for digital identities and trust services, including signatures, seals and timestamps, as well as the framework for the EUDI Wallet and new obligations for relying parties.
EUDI-Wallet (European Digital Identity Wallet): State-recognised wallet in which users store identity data and digital credentials and selectively share them with third parties.
PID (Person Identification Data): Person Identification Data provided via the wallet and cryptographically verifiable, for example name, date of birth and unique identifiers.
Attribute / Attribute Credential: Verifizierbare Eigenschaft einer Person/Organisation (z. B. Wohnsitz, Vertretungsrecht, Einkommen) als digitaler Nachweis statt Papierbeleg.
Credential (Digital Credential): Signierter digitaler Nachweis (z. B. ein Attribut), der maschinell geprüft werden kann (Authentizität, Integrität, Aussteller).
Relying Party (Bank): Entity that accepts and validates wallet data and integrates it into processes such as KYC and contract conclusion, including evidence management and audit.
Wallet Provider: Provider or operator of the wallet, either state-provided or authorised, including security and certification requirements.
QTSP (Qualified Trust Service Provider): Qualified Trust Service Provider that, among other things, issues QES or enables qualified trust services.
KYC (Know Your Customer): Identity and customer due-diligence checks, for example identification, sanctions/PEP screening and risk profiling, as part of onboarding and ongoing customer management.
SCA (Strong Customer Authentication): Strong Customer Authentication in the PSD2 context; relevant because regulated processes require robust authentication and wallet interactions connect to these requirements.
Audit-Trail: Audit-proof logging of process steps, including data retrieval, validation, decisions and signatures, with timestamps and status information.
Preservation of Evidentiary Value: Ensuring that digital credentials and signatures remain verifiable over the long term through traceability, integrity and archiving.
STP (Straight-Through Processing): End-to-end automated processing without manual rework; the target operating model for wallet-based onboarding.
FTR (First-Time-Right): Share of cases completed first time without follow-up questions or corrections, a key KPI for OPEX.
CIR / OPEX: Cost-Income Ratio / operating expenditure, management metrics influenced by shorter turnaround times and reduced rework.
