Curaçao: May 2027 Deadline For Remote KYC Compliance

Curaçao has introduced a new remote identification framework that gives operators already using digital onboarding until May 1, 2027 to reach full compliance.

The Curaçao Gaming Authority, Central Bank of Curaçao and Sint Maarten and Financial Intelligence Unit developed the rules under the National Ordinance on Identification when rendering Services. They apply across sectors covered by the ordinance, not only online gambling.


Good to Know

  • Existing remote onboarding systems must comply by May 1, 2027.
  • New systems cannot launch until they meet the requirements.
  • Operators remain responsible for compliance even when they outsource KYC technology.

Curaçao Puts More Controls Around Remote KYC

The biggest change is practical. Curaçao no longer relies mainly on certified identity document copies for customers who are not physically present.

Providers can now use remote technology, including document scanning, videoconferencing and biometric verification, but each method needs documented controls and testing.

Accepted identity documents include a passport, identity card, driving licence or another document designated by the Minister of Finance. The same framework also covers directors, representatives, controllers, proxy holders and ultimate beneficiaries linked to corporate customers.

Automated systems must capture evidence during the check, verify that the person is live and link that person to the identity document. Human assisted checks require trained staff and escalation procedures.

If a system cannot reach a reliable result because of poor evidence or technical failure, the onboarding process must stop, restart or switch to a face to face check.

Testing Starts Before A Tool Goes Live

Operators now need a formal assessment before introducing or materially changing a remote onboarding solution.

That review must cover data quality, fraud and impersonation risks, IT and legal exposure, mitigating controls and end to end testing. Operators must also be able to show supervisors what they tested and why the solution fits the risk profile of the customers, products and jurisdictions involved.

Ongoing monitoring is also required. Reviews must consider data accuracy, system reliability and changing AML risks, with extra checks triggered by events such as rising fraud attempts, audit findings or regulatory changes.

Technology controls include encrypted data, detailed audit trails, access logs, biometric accuracy testing and regular security reviews. Cloud based or outsourced systems must undergo independent penetration testing every year.

The rules make outsourcing less of a shortcut. A gaming operator can use an external KYC vendor, but the operator still has to demonstrate that the system complies with Curaçao requirements.

May 2027 Deadline Applies To Existing Systems

Providers without a remote onboarding system must meet the rules before launching one.

Those already using a solution can continue operating it during the transition, but only if they have started the compliance work and can prove that to their supervisor. Full compliance is required from May 1, 2027.

Failure to comply can lead to administrative or criminal sanctions, including fines, penalties, licence revocation and imprisonment. Curaçao online gaming licence conditions also allow the CGA to impose administrative measures where licensees fail to maintain required customer verification and AML procedures.

The new framework sits within a wider Curaçao AML and licensing overhaul following the National Ordinance on Games of Chance and newer CGA rules covering areas such as responsible gaming, disputes and compliance controls.

The post Curaçao: May 2027 Deadline For Remote KYC Compliance appeared first on iGaming.org.