- Australia
- Austria
- Bangladesh
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Croatia
- Cyprus
- Czech Republic
- Egypt
- Estonia
- Eswatini
- Ethiopia
- France
- Germany
- Greece
- Haiti
- Hong Kong
- Hungary
- India
- Iraq
- Ireland
- Indonesia
- Italy
- Japan
- Jordan
- Kazakhstan
- Kenya
- Kosovo
- Kuwait
- Latvia
- Luxembourg
- Malaysia
- Malta
- Mauritius
- Mexico
- Micronesia
- Moldova
- Montenegro
- Morocco
- Mozambique
- Myanmar
- Namibia
- Nauru
- Nepal
- Nigeria
- Nicaragua
- Niue
- Norway
- Netherlands
- New Zealand
- Oman
- Pakistan
- Palau
- Palestine
- Panama
- Papua New Guinea
- Paraguay
- Peru
- Puerto Rico
- Philippines
- Portugal
- Poland
- Qatar
- Republic of Congo
- Romania
- Russia
- Rwanda
- Samoa
- San Marino
- Senegal
- Serbia
- Seychelles
- Sierra Leone
- Singapore
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- South Sudan
- Spain
- Sri Lanka
- St Kitts and Nevis
- St Maarten
- St Lucia
- Sweden
- Switzerland `
- Syria
- Taiwan
- Tajikistan
- Tanzania
- Thailand
- Timor Leste
- Togo
- Tonga
- Trinidad and Tobago
- Turkey
- Turks and Caicos
- Turkmenistan
- Tunisia
- Tuvalu
- Uganda
- Ukraine
- UK
- Uruguay
- USA
- Uzbekistan
- Vatican City
- Vietnam
- Venezuela
- Vanuatu
ROMANIA KYC, KYB AND AML
Scale Identity Verification and KYC Operations in Romania
Verify Romanian customers and businesses through ROeID, the electronic identity card, video identification, QES, biometrics and KYB. Reduce manual review, keep consistent audit evidence and run one workflow designed to support Legea 129/2019 and AMLR from 10 July 2027.
Operational Performance for Romania KYC
Our Numbers Speak Volumes
99.73%
First-pass
verification rate
< 10 sec
Median
verification time
5+
Romanian ID methods
supported
Romania IDV/KYC Challenges
Most Wallets Still Hold a Chipless Card
The carte electronică de identitate entered phased issue 20 March 2025, the chipless carte de identitate simplă 20 May 2025. One flow must read the chip or fall back cleanly.
The Video Route Has a Short Document List
The ADR video identification norms accept the carte de identitate and the pașaport, and nothing else for private firms. The permis de ședere sits outside that list, so foreign residents need a different route.
Romanian Names Reach Screening in Several Spellings
The letters ș and ț carry a comma below, legacy systems store the cedilla forms ş and ţ, and the machine-readable zone strips both. Unicode says the two forms should be treated as equivalent.
One Country, Three Beneficial Ownership Registers
Article 19(5) of Legea 129/2019 puts companies at ONRC, associations and foundations at the Ministry of Justice and fiducii at ANAF. Article 19(10) says you cannot rely on a register alone.
Regulatory Update
What AMLR Changes for Identity Verification in Romania
The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Romania from 10 July 2027, with no transposition period. It sets the due diligence rules that Legea 129/2019 will operate under, with AMLA, the new EU-level supervisor, established in Frankfurt.
Timeline
- End of 2026 (EU) Member States must provide at least one EU Digital Identity Wallet
- End of 2026 (RO) Romania targets its own wallet, with the electronic identity card as the enrolment anchor
- 10 July 2027 AMLR applies, no transposition
- 24 December 2027 Private relying parties using strong user authentication, excluding micro and small firms, must accept wallets on request. eIDAS 2.0 Article 5f(2)
- 2028 AMLA direct supervision begins
eIDAS Becomes a Named Route
Article 22(6)(b) lets obliged entities verify identity with electronic identification means at the eIDAS substantial or high levels and relevant qualified trust services. Romania notified ROeID at substantial, so that route already exists alongside the other means Article 22(6) allows.
The Ownership Test Tightens
AMLR sets the test at 25% or more under Article 52. Article 4 of Legea 129/2019 works from more than 25%, so the line moves. Control must also be assessed and can arise below it.
Existing Customers Get Re-Checked
AMLR expects existing customer records brought up to standard on a risk basis, not just new onboarding. Article 14 of Legea 129/2019 already says the same.
Accountability Stays With You
AMLR Article 18 keeps due diligence accountable with the obliged entity even when verification is outsourced. Article 18(5) of Legea 129/2019 already says the same.
FOR BNR-SUPERVISED BUSINESSES
Streamline BNR-Supervised Onboarding in Romania
Article 27(1) of Legea 129/2019 gives the Banca Națională a României exclusive AML supervision of credit, payment and e-money institutions, listed non-bank institutions, and crypto-asset providers that are also credit or e-money institutions. Connect identity verification, QES and evidence in one workflow.
1. Verify the customer
Verify identity using the configured route, such as ROeID, NFC chip reading of the identity card, video identification or document checks.
2. Complete qualified signing
Apply and validate the QES within the same journey, keeping the signed document, verification result and supporting evidence together.
3. Confirm the account (optional)
Penny Drop confirms account ownership. Romanian law has no combined signature-and-account route, so it sits beside identification, not in it.
Shufti’s IDV/KYC Solutions for Romania
KYC Solutions
Clear onboarding for Romanian customers under Legea 129/2019, with age and address checked in the same flow as identity, each check completing in seconds.
Explore MoreIdentity Verification
Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ actively processed document types.
.Face Verification
Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.
.Age Verification
Selfie-based age estimation with document verification fallback where higher assurance is required, cross-checked against the CNP on the carte de identitate.
.Address Verification
Shufti verifies Romanian address-bearing documents, including utility invoices, telecom bills and bank statements from Romanian providers, matching the address to the customer record in the same flow.
.Document Verification
Verification of the carte de identitate, the Romanian pașaport, the permis de ședere and the permis de conducere, with NFC chip reading where a chip exists.
.KYB Solutions
Shufti checks businesses as closely as their owners, supporting the risk-based approach Legea 129/2019 requires. It verifies Registrul Comerțului data, beneficial ownership and VAT details in real time, then screens UBOs against 4,000+ watchlists for sanctions and adverse media.
Explore MoreBusiness Verification
Automated validation of ONRC Registrul Comerțului records, the CUI, the RO-prefixed VAT number and representatives entitled to bind the entity.
.Enhanced Due Diligence (EDD)
Structured risk profiling for complex ownership chains, cross-border entities and higher-risk sectors, aligned with the enhanced measures Legea 129/2019 expects.
.AML Screening
Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP, and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet local reporting obligations.
Explore More
AI Compliance Copilot
Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.
.
Transaction Monitoring
Transaction monitoring calibrated to Romanian financial flows flags anomalies against AML rules, keeping you aligned with BNR expectations and ready to report to the ONPCSB.
.Supported Verification Methods for Romania
Every Verification Route Romania Uses, in One Platform
Shufti supports the full range of remote verification routes used in Romania, from ROeID and NFC chip reading to ADR-recognised video identification and document checks. Each method below shows what is live today and what is ready for the 2027 rollout.
EUDI Wallet
Wallet-ready · from 2027AMLR Article 22(6)(b) points to eIDAS electronic identification means at substantial or high levels. Romania is building its wallet under the eIDAS 2.0 rollout. Shufti is built to accept wallet verification as it goes live.
Notified eID
LiveeIDAS SubstantialRomania notified the Romanian eID scheme, whose eID means is ROeID, at assurance level substantial. Operated by the ADR, it runs as an everyday mobile app. No bank-operated notified scheme sits alongside it, and Shufti verifies it today.
Docless Database eIDV
LiveAn invisible background check against Romanian government, telecom, credit and utility data confirms identity in seconds for low-risk onboarding, with no document upload. Shufti escalates to stronger checks as risk rises.
NFC Chip Verification
LiveShufti reads the secure chip in the carte electronică de identitate, the permis de ședere and the Romanian passport. The card chip holds the facial image and fingerprints.
Document and Face Biometric
LiveThe lawful fallback route under AMLR. Document authentication of the carte de identitate, the Romanian pașaport and the permis de ședere, with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness.
Video Identification
Via ADR-approved providerDecision 564/2021 of the Autoritatea pentru Digitalizarea României sets the norms for remote video identification. Only a provider holding an ADR aviz, or an EU provider meeting Article 4 of those norms, may run the route. Shufti supplies document, chip and biometric checks alongside your approved provider.
Qualified Electronic Signature
LiveLegea 214/2024 governs electronic signatures and trust services, with the ADR as supervisory body. Shufti runs eIDAS-qualified signing powered by Evrotrust, an EU qualified trust service provider, producing PAdES-LTV signatures. For Romania the signing identity check runs through NFC and face biometrics.
Independent Validation
Shufti's Recognition Across Independent Evaluations

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader across four G2 Summer 2026 reports
View ReportEvidence-Ready Checks Across People & Businesses
Verifications with robust evidentiary support
Individual Documents We Verify
Shufti verifies 10 + Romanian document types.
View All Supported DocumentsCarte de Identitate (Romanian Identity Card)
Primary identity document for Romanian citizens under OUG 97/2005. It carries the CNP, and the electronic version adds a chip under Regulation (EU) 2019/1157.
Pașaport (Romanian Passport)
Romanian electronic passport issued under Legea 248/2005. Its contactless chip holds the facial image, so Shufti reads the chip rather than the printed page.
Permis de Conducere (Romanian Driver's Licence)
EU-format photocard licence issued by the DRPCIV under OUG 195/2002, supporting name and date of birth checks but not the ADR video route.
Entity Identity
Certificat de Înregistrare (Certificate of Incorporation)
ONRC registration certificate confirming entry in the Registrul Comerțului, the company's legal existence, its registered name and the CUI identifier.
Certificat Constatator (Registration Certificate)
ONRC attestation of current standing, covering the registered office, share capital, activity codes and the people entitled to represent that company.
Tax Identity
CUI (Cod Unic de Înregistrare)
Unique registration code assigned at incorporation and used as the fiscal identification code for Trade-Register companies. It links registry, tax and screening records to one entity during KYB.
Certificat de Înregistrare în Scopuri de TVA (VAT Registration Certificate)
Evidence that a business is registered for VAT with ANAF. Shufti checks its current standing against the ANAF VAT register and the RO-prefixed number.
Ownership & Control (UBO)
Declarația Privind Beneficiarul Real (Beneficial Ownership Declaration)
Filed under Article 56 of Legea 129/2019 at incorporation and within 15 days of any later change. It feeds the Registrul beneficiarilor reali held by ONRC.
UBO Information Requirements
The data Legea 129/2019 expects on a beneficial owner, covering the name, date of birth, CNP, document details, citizenship and how control is exercised.
Languages We Cover
Document Text Handling
Romanian identity documents carry the diacritics ă, â, î, ș and ț, and the machine-readable zone stores the same name without them. Shufti extracts both forms.
Name Matching Controls
Legacy systems hold ş and ţ with a cedilla where modern Romanian uses ș and ț with a comma, so one surname reaches screening in two encodings. Matching treats both as equivalent.
Evidence Consistency
Identity data is linked across document checks, face verification and screening outputs in one case record, so an ONPCSB request is answered from a single file.
Governance & Controls
Audit-Ready Decisions, Lower Operational Drag
Fewer avoidable re-submissions
Capture tuned to the carte de identitate designs in circulation, plus NFC chip reading, cuts re-uploads and manual review.
Cleaner audit trails
Structured logs aligned to the five-year Article 21 retention rule and ONPCSB reporting keep decisions ready for inspection.
Better name matching outcomes
Matching treats the comma-below and cedilla forms of s and t as equivalent, reducing false positives and manual review on Romanian records.
One workflow, one back office
KYC, KYB and AML screening are consolidated in one operational case view, so one back office team works on every customer file.
National ID-first flow design
Flows lead with the carte de identitate for residents, then fall back to the permis de ședere and home-country documents for everyone else.
Continuous Compliance
Compliance that does not stop at onboarding
AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.
Surface Changes as it happens
DetectPerpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.
Step up when the signal fires
VerifyWhen a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.
Keep the file audit-ready
ComplyEvery check and decision is logged to the record-keeping standard in Article 21 of Legea 129/2019, so the file is ready for the BNR, the ONPCSB and AMLA.
Perpetual KYC
pKYCKeeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready.
Perpetual KYB
pKYBMonitors Registrul Comerțului and Registrul beneficiarilor reali filings, so a shift past 25%, or a change in control below it, is caught in good time.
Built To Fit Romania's Compliance Landscape
Banca Națională a României (BNR)
Romania’s central bank. Article 27(1) of Legea 129/2019 gives it exclusive AML supervision of credit, payment, electronic money and listed non-bank financial institutions, and of crypto-asset providers that are also credit or e-money institutions. Shufti aligns identity evidence to those rules.
Autoritatea de Supraveghere Financiară (ASF)
Holds exclusive AML powers under Article 28 of Legea 129/2019 over capital markets, insurance and private pensions, and over the firms seeking crypto authorisation at Article 28(1)(b). Shufti supports it with entity and UBO verification.
Oficiul Național de Prevenire și Combatere a Spălării Banilor (ONPCSB)
Romania’s financial intelligence unit, which also supervises every reporting entity not covered by the BNR, the ASF or the ONJN. Decision audit trails and escalation logs support suspicious transaction reporting.
Autoritatea Națională pentru Protecția Consumatorilor (ANPC)
Consumer protection and market surveillance authority. It is a market conduct regulator rather than an AML supervisor, and Shufti supports fair, reviewable onboarding decisions and clear consumer-facing verification steps.
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Romania’s data protection authority, enforcing the GDPR and Legea 190/2018. Data minimisation, lawful-basis processing and EU-region hosting keep Romanian personal data handling defensible when identity evidence is retained for AML purposes.
Oficiul Național al Registrului Comerțului (ONRC)
Keeps the Registrul Comerțului and the Registrul beneficiarilor reali, open to obliged entities free of charge since Legea 86/2025. Shufti flags divergences for reporting under Article 19(7¹).
Agenția Națională de Administrare Fiscală (ANAF)
Romania’s tax administration. It runs the VAT register and the beneficial ownership register for fiducii, reached through Spațiul Privat Virtual on proof of legitimate interest. Shufti attaches CUI and VAT evidence to company files.
AMLA (EU Anti-Money Laundering Authority)
The new EU-level supervisor has been established in Frankfurt since July 2025. It begins direct supervision of selected high-risk cross-border entities from 2028 and shapes technical standards under AMLR.
Deployment Option
Cloud in EU regions, or on-premise, keeps Romanian customer data in-region and supports GDPR accountability and the expectations of Romanian supervisors.
Regulatory Alignment
Aligned with the due diligence, beneficial ownership and record-keeping duties in Legea 129/2019, with Legea 190/2018 for GDPR, and with AMLR from 10 July 2027. Shufti provides verification technology as a data processor, not legal or regulatory advice. The lawful basis is set by the controller, biometric data used for unique identification engages Article 9 GDPR, and human review is available. Customer due diligence and the choice of verification method remain with the obliged entity.
Retention Controls
Article 21 of Legea 129/2019 sets a five-year retention period from the end of the relationship or the occasional transaction. Authorities may extend it by up to five more years, and personal data is deleted at expiry. AMLR Article 77 applies the same rule from 10 July 2027.
Encryption & Security
Encryption in transit and at rest, with access controls and audit logging, meets Article 32 GDPR and ISO 27001 and SOC 2 Type II security expectations for Romanian data.
Data and Privacy Controls in Romania
Romania AML Sources That Strengthen Decisions
We screen against 215+ sanction regimes, 4,000+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Romania and globally. A few of them are:
Oficiul Național de Prevenire și Combatere a Spălării Banilor (ONPCSB)
Banca Națională a României (BNR)
Autoritatea de Supraveghere Financiară (ASF)
Ministerul Finanțelor
Oficiul Național al Registrului Comerțului (ONRC)
Agenția Națională de Administrare Fiscală (ANAF)
Autoritatea pentru Digitalizarea României (ADR)
Poliția Română, Direcția de Investigare a Criminalității Economice
Autoritatea Vamală Română
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Financial Action Task Force (FATF)
MONEYVAL (Council of Europe)
EU Consolidated Financial Sanctions List
UN Security Council Consolidated List
European Banking Authority (EBA)
EU Authority for Anti-Money Laundering (AMLA)
SEE SHUFTI IN YOUR ROMANIA WORKFLOW
Turn Romania Verification Requirements into a Smoother Customer Journey
Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for compliance review.
Frequently Asked Questions
Which identity documents can be used for KYC in Romania?
Customers can use the carte de identitate, including the electronic version, along with the Romanian pașaport and the permis de ședere for foreign residents. The permis de conducere sits alongside them as supporting evidence. Shufti supports document, eID, NFC, video and biometric verification in one workflow.
How does Shufti support BNR-supervised businesses in Romania?
Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. Article 27(1) of Legea 129/2019 sets the BNR’s exclusive AML remit over credit, payment and electronic money institutions. Those firms get standardised records and clearer evidence for supervisory review.
What documents are required for KYB in Romania?
Typically the ONRC certificat de înregistrare and a current certificat constatator, the CUI, VAT registration evidence and the beneficial ownership declaration behind the Registrul beneficiarilor reali entry. Shufti verifies these in real time and screens the UBOs against sanctions and PEP lists.
How are Romanian names and diacritics handled in screening?
Romanian uses ă, â, î, ș and ț, and the machine-readable zone stores the name without them, so one person reaches screening in two spellings. Many legacy systems also hold ş and ţ with a cedilla. Matching treats those forms as equivalent, as the Unicode Standard advises.
How long must AML records be retained in Romania?
Five years. Article 21 of Legea 129/2019 requires customer due diligence records and transaction evidence to be kept for five years from the day the relationship ends or the occasional transaction is carried out. Authorities may extend that by up to five more years, and personal data is deleted at expiry unless another law requires it kept.
Is EU-region data hosting available for Romanian customer data?
Yes. Shufti offers EU-based cloud regions, so Romanian customer data stays in-region in line with the GDPR as implemented by Legea 190/2018 and enforced by the ANSPDCP. On-premise deployment is available where residency requirements are stricter.
What changes for Romania under AMLR from July 2027?
AMLR applies directly, so no Romanian transposition law is needed. Article 22(6)(b) points to eIDAS electronic identification means and qualified trust services, document plus biometric checks stay a lawful route, and the beneficial ownership test moves to 25% or more under Article 52. Romania’s tighter cash limits are preserved by Article 80(3).
Is ROeID an eIDAS-notified electronic identity for Romania?
Yes. Romania notified the Romanian eID scheme, whose eID means is ROeID, at assurance level substantial, published in the Official Journal on 9 September 2024. It is operated by the Autoritatea pentru Digitalizarea României, runs as an everyday mobile app and is accepted on Ghișeul.ro. No bank-operated scheme sits alongside it.
Is remote video identification allowed in Romania?
Yes. Decision 564/2021 of the President of the Autoritatea pentru Digitalizarea României approves the norms for remote identification by video means, published in Monitorul Oficial nr. 1119 of 24 November 2021. The norms cover attended and unattended flows, set document and liveness checks, require a one-time code or time-limited link as a second factor, and limit private firms to the carte de identitate and the pașaport.
When will the EU Digital Identity Wallet be usable for onboarding in Romania?
Under eIDAS 2.0, member states target wallet availability from the end of 2026, and private relying parties that use strong customer authentication accept wallets after that. Romania is building its wallet under that rollout. Shufti is built to accept wallet-based verification as it goes live, so onboarding flows will not need to be rebuilt.
Let’s Build Trust Into Your Business
1B+Verifications Processed
240+Regions Actively Processed
99.7%Accuracy Rate
Samer Al Tamimi
CEO of Safwa Bank
“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”
Trusted. Compliant. Certified
Explore Shufti For Your Business
Get a personalised demo from our experts.
PROVEN PLAYBOOKS
Explore Practical KYC & AML Resources
10 July, 2026
Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet
A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.
Product Guide





