Curaçao gives existing remote-KYC systems until May 2027 to meet liveness and audit rules
A joint Curaçao framework sets a transition deadline for existing remote-onboarding systems and immediate compliance for technology not yet deployed.
Jump to a section
1 May 2027
Legacy systems get a transition; new identity technology must comply before launch
Curaçao · remote KYC
Evidence behind the story
What we checked
Primary documents
3 checked
Response record
Not requested
Last source check
31 August 2026
Next scheduled review
28 September 2026
Why this matters
Curaçao's licensing reform is often judged by licence counts. These provisions move the test into the operating layer: whether a remote customer can be identified with evidence that survives impersonation, security and audit scrutiny.
Procedural status
Joint provisions in force with transition
New systems must comply before deployment. Existing remote-identification solutions may continue during a documented transition that ends on 1 May 2027.
The current picture
- Existing remote-identification systems in scope may operate during a transition ending 1 May 2027 if demonstrable compliance work is underway.
- New remote-onboarding solutions must comply before implementation; the framework requires controls for liveness, impersonation, security and auditability.
- The provisions apply across service providers covered by Curaçao's identification law, not only to online gambling licensees.
Confirmed by the record
- The Curaçao Gaming Authority, Central Bank and Financial Intelligence Unit announced the joint provisions on 21 August 2026.
- Remote checks may use document scanning, videoconferencing and biometrics, but a video call cannot rely only on visual inspection.
- Unattended systems must use current images or video, liveness detection and sufficiently robust document-verification methods.
- If the evidence is inadequate, the remote process must stop, restart or move to face-to-face identification.
Not established
- The framework does not ban remote onboarding or require every provider to use the same technology vendor.
- The May 2027 transition is not permission to ignore the rules; providers must already be able to demonstrate implementation work.
- The document does not establish that a named gaming operator has failed these controls.
- The provisions are not limited to the gambling industry and expressly exclude money-transfer companies from this specific framework.
Sources for each key claim
Evidence map
Each core claim is paired with the document used to substantiate it. Open the record and check our reading.
Existing remote-identification solutions have until 1 May 2027 for full compliance if implementation work is demonstrable.
New systems must comply before implementation and unattended checks require liveness and robust document validation.
The provisions were jointly established by Curaçao's gaming, central-bank and financial-intelligence authorities.
What changed, and when
21 August 2026
Joint framework takes effect
The CGA, Central Bank and FIU announce final remote-identification provisions.
1 May 2027
Transition ends
Existing solutions must be fully compliant with the provisions.
The deadline applies to systems already in use
Curaçao has given existing remote-identification solutions a defined route to compliance rather than forcing an overnight replacement. Systems already operating when the provisions took effect can continue until 1 May 2027, provided the service provider has begun the necessary work and can demonstrate that progress to a supervisor.
Technology not yet implemented receives no equivalent grace period. A new solution must meet the provisions before it goes live. The distinction prevents the transition from becoming a general delay while recognising that redesigning identity flows, contracts, testing and audit records can take time.
A video call alone is not enough
The framework permits several remote methods, including identity-document scanning, videoconferencing and biometrics. It does not treat the appearance of a document on camera as proof by itself. Videoconferencing must include controls beyond visual inspection, and unattended systems must collect current images or video and test that a live person is present.
Document verification must be robust enough for the risk and supported by a recorded rationale. The provisions point to internationally recognised ISO, IEC and NIST frameworks rather than prescribing one commercial product. This gives providers technical flexibility, but it also requires them to explain why their chosen method is reliable.
The process must fail safely
Remote onboarding is not allowed to drift forward when the evidence is poor. If image quality, document checks or identity comparison do not provide adequate assurance, the process must stop and restart or the customer must be identified face to face. That rule matters because a frictionless journey is not compliant if uncertainty is simply passed downstream.
Before implementation, providers must assess the solution, test end to end and consider impersonation fraud. Ongoing monitoring then has to respond to changes and warning signals. The framework therefore treats identity as a continuing control, not a one-time photograph collected at registration.
Auditability becomes part of customer experience
The provisions require an audit trail, data protection, encryption and safeguards against incorrect acceptance. Cloud and outsourced arrangements do not remove the provider's responsibility. Annual penetration testing is expected for relevant cloud or outsourced systems, alongside monitoring for bias and performance limitations in automated tools.
For gaming licensees, those requirements reach beyond the compliance department. They influence onboarding design, abandonment rates, vendor selection, evidence retention and incident response. A system can be fast and still fail if the provider cannot reconstruct what it checked, which version of a model it used or why an exception was accepted.
This is wider than online gambling
The announcement came through the Curaçao Gaming Authority, but the legal scope covers service providers subject to the National Ordinance on Identification when Rendering Services. The Central Bank of Curaçao and Sint Maarten and FIU Curaçao are joint authors. Money-transfer companies are expressly outside this specific set of provisions.
That broader scope is important for the headline. Curaçao has not introduced a gaming-only biometric mandate, nor has it alleged that every operator's current KYC fails. It has set a common evidential standard for remote identification, with a hard deadline for legacy systems and immediate obligations for new ones.
Enforcement will reveal the practical threshold
The framework explains what a defensible process should contain, but the first inspection or decision will show how supervisors judge proportionality in a real deployment. Liveness quality, document coverage, false acceptance and the handling of failed checks are likely to become the decisive evidence.
Until then, the operational message is clear. Existing systems have a transition, not an exemption. New systems need compliance before launch. Any provider relying on remote identity checks should be able to show not only that a customer passed, but why the result deserved to be trusted.
Response record
This explainer reports a general regulatory framework and makes no allegation about a named operator.
Status: not requested
Sources checked
Announcement of provisions for remote identification
primaryCuraçao Gaming Authority, Central Bank of Curaçao and Sint Maarten, and FIU Curaçao · checked 31 August 2026
Provisions for remote identification
primaryCuraçao Gaming Authority, Central Bank of Curaçao and Sint Maarten, and FIU Curaçao · checked 31 August 2026
Curaçao Gaming Authority
primaryCuraçao Gaming Authority · checked 31 August 2026