- Australia
- Austria
- Bangladesh
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Croatia
- Cyprus
- Czech Republic
- Egypt
- Estonia
- Eswatini
- Ethiopia
- France
- Germany
- Greece
- Haiti
- Hong Kong
- India
- Iraq
- Ireland
- Indonesia
- Italy
- Japan
- Jordan
- Kazakhstan
- Kenya
- Kosovo
- Kuwait
- Latvia
- Luxembourg
- Malaysia
- Malta
- Mauritius
- Mexico
- Micronesia
- Moldova
- Montenegro
- Morocco
- Mozambique
- Myanmar
- Namibia
- Nauru
- Nepal
- Nigeria
- Nicaragua
- Niue
- Norway
- Netherlands
- New Zealand
- Oman
- Pakistan
- Palau
- Palestine
- Panama
- Papua New Guinea
- Paraguay
- Peru
- Puerto Rico
- Philippines
- Portugal
- Portugal
- Qatar
- Republic of Congo
- Romania
- Russia
- Rwanda
- Samoa
- San Marino
- Senegal
- Serbia
- Seychelles
- Sierra Leone
- Singapore
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- South Sudan
- Spain
- Sri Lanka
- St Kitts and Nevis
- St Maarten
- St Lucia
- Sweden
- Switzerland `
- Syria
- Taiwan
- Tajikistan
- Tanzania
- Thailand
- Timor Leste
- Togo
- Tonga
- Trinidad and Tobago
- Turkey
- Turks and Caicos
- Turkmenistan
- Tunisia
- Tuvalu
- Uganda
- Ukraine
- UK
- Uruguay
- USA
- Uzbekistan
- Vatican City
- Vietnam
- Venezuela
- Vanuatu
CROATIA KYC, KYB AND AML
Scale Identity Verification and KYC Operations in Croatia
Verify Croatian customers and businesses through the eOsobna iskaznica eID, NFC, QES, identity documents, biometrics and KYB. Reduce manual review, maintain consistent audit evidence and run one connected workflow designed to support the ZSPNFT today and AMLR from 10 July 2027.
Operational Performance for Croatia KYC
Our Numbers Speak Volumes
98.80%
First-pass
verification rate
< 10 sec
Median
verification time
5+
Croatian ID methods
supported
Croatia IDV/KYC Challenges
The eID Gap
The eOsobna iskaznica carries eID certificates at the highest eIDAS assurance level, yet many customers never activate them and onboard with photographed documents instead. Manual capture is slower and easier to spoof.
Croatian Names Break Global Matching
Kovačević becomes Kovacevic when diacritics are lost in international databases. Marks such as č, ć, đ, š and ž disappear, digraphs such as dž, lj and nj split or merge, and false positives push files into manual review.
Ownership Is Hard to See Through
Croatian d.o.o. and d.d. structures with holding layers slow UBO identification, and the AMLR test, 25% or more ownership or control, sets what must be traced. Registrar of real owners filings can lag or sit incomplete, which stalls KYB.
Registry Data Is Not Verification
The Sudski registar confirms a company exists, not who controls it or whether they are sanctioned. KYB needs screening layered on top of registry lookups.
Regulatory Update
What AMLR Changes for Identity Verification in Croatia
The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Croatia from 10 July 2027, with no transposition period. It sets due diligence rules applying alongside an amended ZSPNFT. AMLA, the EU supervisor based in Frankfurt, will start direct supervision in 2028.
Timeline
- End of 2026 Member State deadline to issue EUDI Wallets
- 10 July 2027 AMLR applies, no transposition
- Late 2027 eIDAS 2.0 Art 5f wallet acceptance duty
- 2028 AMLA direct supervision begins
eIDAS Routes Recognised in AMLR
Article 22(6) sets two routes, an identity document backed by reliable independent sources, or eIDAS eID at substantial or high assurance with qualified trust services. Both remain valid. The eOsobna iskaznica and QES sit in the eIDAS route, and video identification continues under Article 52 ZSPNFT.
The Ownership Test Tightens
AMLR sets the beneficial-ownership test at 25% or more of ownership or control, so Registar stvarnih vlasnika records and KYB checks trace both.
Existing Customers Get Re-Checked
AMLR expects existing customer records to be brought up to standard on a risk basis, not just new onboarding. Continuous monitoring keeps back-book files current between reviews.
Accountability Stays With You
Article 38 ZSPNFT already keeps due diligence responsibility with you when outsourced, and AMLR Article 18 carries this on, so vendor evidence and clean audit trails matter today.
FOR HNB-SUPERVISED BUSINESSES
Streamline HNB-Supervised Onboarding in Croatia
Connect identity verification, QES, Penny Drop and compliance evidence in one configurable workflow for businesses operating within the Croatian National Bank's supervisory remit. Reduce customer drop-off and manual handovers while giving compliance teams a consistent, review-ready record of every decision.
1. Verify the customer
Verify identity using the configured route, such as the eOsobna iskaznica eID, NFC document reading or document and biometric checks.
2. Complete qualified signing
Apply and validate the QES within the same journey, keeping the signed document, verification result and supporting evidence together.
3. Confirm the payment account
Use Penny Drop Verification to confirm account ownership and strengthen fraud control, keeping the evidence with the QES journey.
Shufti’s IDV/KYC Solutions for Croatia
KYC Solutions
Onboarding designed to support ZSPNFT requirements, with age and address checked in the same flow as identity, each check completing in seconds.
Explore MoreFace Verification
Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.
.Age Verification
Selfie-based age estimation with document verification fallback for age-restricted sectors such as online gaming and e-commerce.
.Bank Account Verification
Confirms a Croatian bank account (HR IBAN) belongs to the customer, returning the registered account holder name for matching against the verified identity.
.Address Verification
Shufti verifies Croatian address-bearing documents, including utility invoices, telecom bills and bank statements from major Croatian issuers. Proof-of-address checks remain common in regulated onboarding.
.Document Verification
Verification of the osobna iskaznica, residence permits and Croatian ePassports, including NFC chip reading and Croatian-language OCR extraction. Remains a permitted route for remote verification under AMLR.
.Identity Verification
Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ actively processed document types.
.KYB Solutions
Shufti checks a business as deeply as it checks the people behind it, using a risk-based ZSPNFT approach. Shufti checks registry records, beneficial ownership and VAT details in real time, then screens UBOs against 3,500+ global watchlists for sanctions and adverse media exposure.
Explore MoreBusiness Verification
Automated validation of Sudski registar data, the MBS registration number, OIB and VAT details, and appointed directors. Reduces manual registry lookups and onboarding delays.
.Enhanced Due Diligence (EDD)
Structured risk profiling for complex ownership chains, cross-border entities and high-risk sectors, supporting Croatia's risk-based AML obligations under the ZSPNFT.
.AML Screening
Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet local reporting obligations.
Explore More
AI Compliance Copilot
Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.
.
Transaction Monitoring
Ongoing transaction monitoring calibrated to Croatian financial flows flags anomalies against AML rules, keeping you aligned with the risk-based controls the HNB and the Anti-Money Laundering Office expect.
.Supported Verification Methods for Croatia
Every Verification Route Croatia Uses, in One Platform
Shufti supports the full range of remote verification routes used in Croatia, from the EUDI Wallet and the eOsobna iskaznica eID to document and biometric checks. Each method below shows what is live today and what is ready for the 2027 rollout.
EUDI Wallet
Wallet-ready · from 2027AMLR Article 22(6) recognises eIDAS eID means, including the EUDI Wallet.
Notified eID
LiveeIDAS HighThe eOsobna iskaznica, the eID function of Croatia's electronic identity card, is the country's notified eID at the highest eIDAS assurance level, used through the NIAS gateway and the Certilia app. Shufti verifies the eOI card today through NFC chip reading and biometric checks.
Docless Database (eIDV)
LiveDatabase-driven verification confirms identity in seconds for low-risk onboarding with no document upload, using permitted reference data sources. Shufti escalates to stronger checks as risk rises.
NFC Chip Verification
LiveShufti reads the secure chip in the Osobna iskaznica, the biometric residence permit and the Croatian ePassport. This is the high-assurance capture route where eID activation is still low.
Document and Face Biometric
LivePermitted by AMLR Article 22(6)(a). Document authentication of the osobna iskaznica, residence permit and ePassport, paired with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness to confirm a real, present person.
Video Identification
LiveArticle 52 of the ZSPNFT permits video-electronic identification, and the remote onboarding Pravilnik (NN 9/2024) sets the minimum conditions, allowing delegation to a third party under its Article 13. A guided real-time video session checks security features live, with a face match and liveness check.
Qualified Electronic Signature
LiveQualified electronic signatures carry the legal effect of handwritten signatures under eIDAS Article 25. Shufti runs eIDAS-qualified signing powered by Evrotrust, an EU qualified trust service provider, producing PAdES-LTV signatures. For Croatia the signing identity check runs through NFC and face biometrics.
Independent Validation
Shufti's Recognition Across Independent Evaluations

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader across four G2 Summer 2026 reports
View ReportEvidence-Ready Checks Across People & Businesses
Verifications with robust evidentiary support
Individual Documents We Verify
Shufti verifies 6+ core Croatian ID documents.
View All Supported DocumentsOsobna iskaznica (Croatian National Identity Card)
Croatia's electronic identity card and the country's notified eID at the highest eIDAS assurance level. It carries a chip with biometrics and OIB data, and its fields appear in Croatian and English.
Hrvatska putovnica (Croatian Passport)
Biometric, ICAO-compliant passport issued by the Ministry of the Interior through police administrations. The data page appears in Croatian, English and French, and the chip supports NFC checks.
Vozačka dozvola (Croatian Driving Licence)
Polycarbonate EU-format card issued by the Ministry of the Interior. Used as a supporting identity document in KYC workflows and verified for authenticity through document checks.
Tax Residency Certificate
Issued by the Tax Administration to confirm residency status and tax obligations in Croatia. It confirms tax residency for compliance-driven KYC workflows.
Visa or Residency Permit
Travel or residence authorisation issued by Croatian authorities. It verifies the legal status of foreign and non-resident customers during onboarding.
Entity Identity
Trade Register Excerpt
Official extract from the Sudski registar establishing legal existence, the MBS registration number and the organisational structure of a Croatian entity.
Certificate of Incorporation
Court-issued validation of legal formation. It carries the unique MBS identifier that KYB workflows use to confirm business registration.
Business Registration Number (MBS)
Court-assigned identifier unique to each legal entity in the Sudski registar. It supports registry cross-reference and business verification.
Tax Identity
OIB (Tax Identification Number)
Eleven-digit identifier issued by the Tax Administration. With the HR prefix it forms the VAT number, so one check supports both tax and VAT verification.
VAT Registration Certificate
Official confirmation of VAT-registered status. It validates legal entity standing and tax compliance for cross-border assessment.
Ownership & Control (UBO)
Beneficial Ownership Register Extract
Official extract from the Registar stvarnih vlasnika kept by FINA. Shufti checks control data against it, with the AMLR ownership test applied at 25% or more.
Shareholder Documentation
Board resolutions and share certificates confirming equity ownership and voting control. Shufti uses them to trace ownership chains through multi-tier structures.
Languages We Cover
Croatian script and diacritics
Shufti handles Gaj's Latin alphabet with the marks č, ć, đ, š and ž and the digraphs dž, lj and nj, so name matching stays accurate across documents.
Bilingual field recognition
The osobna iskaznica and passport carry dual-language fields. Shufti matches names across language variants without manual intervention.
Evidence consistency verification
Cross-references names, addresses and dates across documents and catches character-mark variations common in multi-document KYC workflows.
Governance & Controls
Audit-Ready Decisions, Lower Operational Drag
Fewer avoidable re-submissions
Optimised capture for Croatian ID formats and the NFC-enabled Osobna iskaznica cuts avoidable re-submissions and manual review.
Cleaner audit trails
Structured logs aligned to ZSPNFT record retention and Anti-Money Laundering Office reporting obligations keep every onboarding decision audit-ready.
Better name matching outcomes
Matching handles Croatian diacritics and digraphs, so variants such as Kovačević and Kovacevic resolve correctly and false positives stay low.
One workflow, one back office
KYC, KYB and AML screening are consolidated in one operational case view across the Sudski registar, the Registar stvarnih vlasnika and screening outcomes.
National ID-first flow design
Osobna iskaznica-first onboarding reflects Croatia's national identity ecosystem and the way customers actually verify.
Continuous Compliance
Compliance that does not stop at onboarding
AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.
Surface Changes as it happens
DetectPerpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.
Step up when the signal fires
VerifyWhen a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.
Keep the file audit-ready
ComplyEvery check and decision is logged to ZSPNFT record-keeping standards, so the file is organised and retrievable for internal audit and supervisory review.
Perpetual KYC
pKYCKeeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready.
Perpetual KYB
pKYBMonitors the Registar stvarnih vlasnika and Sudski registar for shareholding and control changes, so a shift past the 25% or a change in control is caught between reviews.
Built To Fit Croatia’s Compliance Landscape
Croatian National Bank (HNB)
Supervises credit institutions, credit unions, payment institutions and electronic-money institutions for AML/CFT. Shufti provides structured KYC records that HNB-supervised firms can hold as evidence.
Croatian Financial Services Supervisory Agency (HANFA)
Supervises capital markets, investment funds, insurance, leasing and relevant crypto-asset activities. Shufti supplies onboarding and screening evidence within HANFA's remit.
Financial Inspectorate (Ministry of Finance)
Conducts AML/CFT supervision of designated non-bank financial and professional sectors within its remit. Shufti supports the documentation these obliged entities need.
Anti-Money Laundering Office (AMLO)
Croatia's Financial Intelligence Unit receives and analyses suspicious transaction reports from obliged entities. Shufti documentation supports STR case preparation.
Tax Administration (Porezna uprava)
Administers the OIB system and supervises games-of-chance operators under the ZSPNFT. Shufti cross-references OIB records to validate entity status.
Ministry of Foreign and European Affairs (MVEP)
Coordinates information on EU and UN restrictive measures and their Croatian implementation. Shufti integrates EU sanctions lists to support screening in Croatia.
AMLA (EU Anti-Money Laundering Authority)
The new EU-level supervisor has been established in Frankfurt since July 2025. Begins direct supervision of selected high-risk cross-border entities from 2028 and shapes technical standards under AMLR.
Deployment Option
Cloud deployment in EU regions, or on-premise where residency requirements are stricter, keeps Croatian customer data in-region and supports GDPR accountability.
Regulatory Alignment
Aligned with ZSPNFT due diligence obligations, UBO verification and recordkeeping duties, as well as GDPR principles and AMLR requirements applying from July 2027.
Retention Controls
ZSPNFT (NN 108/17, 39/19, 151/22) records are kept ten years under Article 79, then deleted once retention periods expire, as the Law requires.
Encryption & Security
Encryption in transit and at rest, with access controls and audit logging, supports Article 32 GDPR, backed by ISO 27001 certification and SOC 2 Type II attestation.
Scope of Our Role
Shufti acts as a data processor and provides verification technology, not legal or regulatory advice. Responsibility for customer due diligence and for the choice of verification method remains with the obliged entity, documented in its own risk assessment.
Data and Privacy Controls in Croatia
Croatia AML Sources That Strengthen Decisions
We screen against 215+ sanction regimes, 3,500+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Croatia and globally. A few of them are:
Ministry of Finance - Anti-Money Laundering Office
Croatian National Bank - HNB
Croatian Financial Services Supervisory Agency - HANFA
Ministry of Finance - Financial Inspectorate
Ministry of Finance - Tax Administration
Ministry of Finance - Customs Administration
General Police Directorate - Croatian Police
State Attorney's Office of the Republic of Croatia - DORH
Office for the Suppression of Corruption and Organised Crime - USKOK
Ministry of Foreign and European Affairs - Restrictive Measures
Council of Europe MONEYVAL
Financial Action Task Force - FATF
Egmont Group of Financial Intelligence Units
EU Anti-Money Laundering Authority- AMLA
European Commission - DG FISMA Financial Crime
EU Consolidated Financial Sanctions List
UN Security Council Consolidated List
SEE SHUFTI IN YOUR CROATIA WORKFLOW
Turn Croatian Verification Requirements into a Smoother Customer Journey
Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for compliance review.
Frequently Asked Questions
Which identity documents can be used for onboarding in Croatia?
Customers can use the osobna iskaznica, including its eID and NFC capabilities, the Croatian biometric passport and residence permits. A driving licence can support the file, and eligible EU and EEA documents can be accepted where requirements are met. Shufti supports document, eID, NFC and biometric verification within one configurable workflow.
How does Shufti support HNB-supervised businesses in Croatia?
Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. This helps businesses within the Croatian National Bank's supervisory remit reduce manual hand-offs, standardise compliance records and prepare clearer evidence for internal audit and applicable supervisory review.
What documents are required for KYB in Croatia?
Typically a Trade Register Excerpt from the Sudski registar, the MBS registration number, OIB and VAT registration details, shareholder documentation and a beneficial ownership extract from the Registar stvarnih vlasnika. Shufti verifies these in real time and screens the UBOs behind them against sanctions and PEP lists.
How are Croatian name variants handled in screening?
Matching accounts for Croatian diacritics such as č, ć, đ, š and ž and the digraphs dž, lj and nj, so variants such as Kovačević and Kovacevic resolve correctly and false positives on Croatian names stay low.
How long must AML records be retained in Croatia?
Under Article 79 of the ZSPNFT, records are kept ten years from the end of the relationship or transaction, then deleted. From 10 July 2027, AMLR Article 77 sets a five-year baseline.
Is EU-region data hosting available for Croatian data?
Yes. Shufti offers EU-based cloud regions, so Croatian customer data stays in-region in line with GDPR. On-premise deployment is available where residency requirements are stricter.
What changes for Croatia under AMLR from July 2027?
It sets out two permitted routes, document-based and eIDAS-based, recognising notified eIDs, the EUDI Wallet and qualified trust services alongside document and biometric checks, and sets the beneficial ownership test at 25% or more, assessed with control.
How do QES and account verification work together in Croatia?
Qualified electronic signatures carry the legal effect of handwritten signatures under eIDAS, which applies directly in Croatia. Where a workflow calls for it, Shufti connects QES, Penny Drop account verification and supporting evidence in one journey, supporting fraud and account-ownership control.
When will the EUDI Wallet be usable for onboarding in Croatia?
Under eIDAS 2.0, member states must issue wallets by the end of 2026, and from late 2027 Article 5f requires firms using strong user authentication to accept them. Croatia is preparing its wallet under this rollout. Shufti is built to accept wallet-based verification as the Croatian wallet goes live, so onboarding flows will not need to be rebuilt.
Can we keep using video identification in Croatia after July 2027?
Where national rules permit it, yes. Video-electronic identification continues under Article 52 of the ZSPNFT and the remote onboarding Pravilnik (NN 9/2024), with a documented justification for the method choice. Shufti supports eIDAS routes and video, so firms can shift the mix over time without changing platforms.
Let’s Build Trust Into Your Business
1B+Verifications Processed
240+Regions Actively Processed
99.7%Accuracy Rate
Samer Al Tamimi
CEO of Safwa Bank
“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”
Trusted. Compliant. Certified
Explore Shufti For Your Business
Get a personalised demo from our experts.
PROVEN PLAYBOOKS
Explore Practical KYC & AML Resources
10 July, 2026
Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet
A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.
Product Guide





