- Australia
- Austria
- Bangladesh
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Croatia
- Cyprus
- Czech Republic
- Denmark
- Egypt
- Estonia
- Eswatini
- Ethiopia
- Finland
- France
- Germany
- Greece
- Haiti
- Hong Kong
- Hungary
- India
- Iraq
- Ireland
- Indonesia
- Italy
- Japan
- Jordan
- Kazakhstan
- Kenya
- Kosovo
- Kuwait
- Latvia
- Lithuania
- Luxembourg
- Malaysia
- Malta
- Mauritius
- Mexico
- Micronesia
- Moldova
- Mongolia
- Montenegro
- Morocco
- Mozambique
- Myanmar
- Namibia
- Nauru
- Nepal
- Nigeria
- Nicaragua
- Niue
- Norway
- Netherlands
- New Zealand
- Oman
- Pakistan
- Palau
- Palestine
- Panama
- Papua New Guinea
- Paraguay
- Peru
- Puerto Rico
- Philippines
- Portugal
- Poland
- Qatar
- Republic of Congo
- Romania
- Russia
- Rwanda
- Samoa
- San Marino
- Senegal
- Serbia
- Seychelles
- Sierra Leone
- Singapore
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- South Sudan
- Spain
- Sri Lanka
- St Kitts and Nevis
- St Maarten
- St Lucia
- Sweden
- Switzerland `
- Syria
- Taiwan
- Tajikistan
- Tanzania
- Thailand
- Timor Leste
- Togo
- Tonga
- Trinidad and Tobago
- Turkey
- Turks and Caicos
- Turkmenistan
- Tunisia
- Tuvalu
- Uganda
- Ukraine
- UK
- USA
- Vietnam
DENMARK KYC, KYB AND AML
Scale Identity Verification and KYC Operations in Denmark
Verify Danish customers and businesses through MitID, NFC, QES, identity documents, biometrics and KYB. Reduce manual review, maintain consistent audit evidence and run one connected workflow designed to support hvidvaskloven today and AMLR from 10 July 2027.
Operational Performance for Denmark KYC
Our Numbers Speak Volumes
99.01%
First-pass
verification rate
< 10 sec
Median
verification time
5+
Danish ID methods
supported
Denmark IDV/KYC Challenges
The Document People Carry Is the One That Cannot Be Read
Denmark has no compulsory national ID card. Only the passport is widely held and NFC readable. The kørekort most people carry has no chip, so onboarding falls back to image capture and manual review.
No CPR Number Means No MitID
MitID is issued only to people with a CPR number. Foreign nationals, recent arrivals and cross-border customers cannot authenticate that way, so firms need a second high-assurance route.
Beneficial Ownership Data Moved Behind a Gate
Public access to the beneficial ownership layer of the CVR closed on 1 September 2025. Obliged entities keep access for customer due diligence, but it now runs through an authenticated route and returns a defined record rather than an open lookup, so KYB teams built around public queries have had to rebuild the step.
Danish Letters Break Global Matching
Æ, Ø and Å become AE, OE and AA in the machine readable zone and in many international databases, so ØSTERGÅRD reads as OESTERGAARD once machine read. Matching that misses the conversion creates false positives.
Regulatory Update
What AMLR Changes for Identity Verification in Denmark
The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Denmark from 10 July 2027, with no transposition period. It sets the due diligence rules that hvidvaskloven and its supervisors will operate under, with AMLA, the new EU-level supervisor, working from Frankfurt.
Timeline
- End of 2026 Member State wallet issuance deadline
- 10 July 2027 AMLR applies, no transposition
- Late 2027 Wallet acceptance duty, eIDAS 2.0 Art. 5f
- 2028 AMLA direct supervision begins
eIDAS Expressly Recognised
Article 22(6)(b) recognises electronic identification means that meet the eIDAS assurance levels substantial or high, together with relevant qualified trust services, as a route for verifying identity remotely. MitID and qualified signing already sit inside that route. Document and biometric checks remain expressly permitted under Article 22(6)(a), and firms should document why their method fits the risk.
The Ownership Test Tightens
AMLR sets the test at 25% or more ownership, or control, which can arise below any threshold, with floors down to 15% possible for higher-risk categories. Danish guidance today treats 25% as an indication rather than a fixed boundary, so the harmonised test gives firms one number to work to.
Existing Customers Get Re-Checked
AMLR expects existing customer records to be brought up to standard on a risk basis, not just new onboarding. Continuous monitoring keeps back-book files current between reviews.
Accountability Stays With You
Article 18 governs outsourcing and keeps the obliged entity fully liable for the tasks a service provider carries out, so vendor evidence and clean audit trails matter more under AMLR.
FOR FINANSTILSYNET-SUPERVISED BUSINESSES
Streamline Finanstilsynet-Supervised Onboarding in Denmark
Connect identity verification, QES, Penny Drop and compliance evidence in one configurable workflow for businesses operating within the supervisory remit of Finanstilsynet. Reduce customer drop-off and manual hand-offs while giving compliance teams a consistent, review-ready record of every decision.
1. Verify the customer
Verify identity using the configured route, such as MitID, NFC reading of the Danish passport chip, or document and biometric checks. Finanstilsynet's May 2023 guidance covers MitID as a control source in customer due diligence, and your own risk assessment decides which route applies to which customer.
2. Complete qualified signing
Apply and validate the QES within the same journey, keeping the signed document, verification result and supporting evidence together, so the signed contract and the identity evidence behind it stay in one record.
3. Confirm the payment account
Penny Drop Verification confirms the customer holds the payment account, a supporting control with the evidence kept in the same case record. Danish law does not set out a dedicated qualified-signature-plus-payment-account identification route.
Shufti’s IDV/KYC Solutions for Denmark
KYC Solutions
Clear onboarding for Danish customers under hvidvaskloven, with age and address checked in the same flow as identity, each check completing in seconds.
Explore MoreIdentity Verification
Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ actively processed document types.
.Face Verification
Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.
.Age Verification
Selfie-based age estimation combined with document verification fallback where required for regulated sectors such as licensed gambling under Spillemyndigheden rules and age-restricted online retail.
.Address Verification
Shufti verifies Danish address-bearing documents, including utility invoices, telecom bills and bank statements from major Danish issuers. Proof-of-address checks remain common in regulated onboarding.
.Document Verification
Verification of the Danish passport, kørekort, legitimationskort and residence permit card, including NFC chip reading of the passport and Danish-language extraction that keeps Æ, Ø and Å intact. Remains a permitted route for remote verification under AMLR.
.KYB Solutions
Shufti checks a business as deeply as the people behind it, supporting your risk-based approach. Shufti checks registry records, beneficial ownership and VAT details in real time, then screens UBOs against 4,000+ global watchlists for sanctions and adverse media exposure.
Explore MoreBusiness Verification
Automated validation of CVR records, the eight-digit CVR number, VAT registration and registered management. Reduces manual registry lookups and onboarding delays.
.Enhanced Due Diligence (EDD)
Structured risk profiling for complex ownership chains, cross-border entities and high-risk sectors, supporting the risk-based obligations in hvidvaskloven.
.AML Screening
Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet local reporting obligations.
Explore More
AI Compliance Copilot
Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.
.
Transaction Monitoring
Ongoing transaction monitoring calibrated to Danish financial flows flags anomalies against AML rules, supporting the risk-based controls expected by Finanstilsynet and the reporting Hvidvasksekretariatet receives.
.Supported Verification Methods for Denmark
Every Verification Route Denmark Uses, in One Platform
Shufti supports the full range of remote verification routes used in Denmark, from the EU Digital Identity Wallet and MitID to NFC, document and biometric checks. Each method below shows what is live today and what is ready for the 2027 rollout.
EUDI Wallet
Wallet-ready · from 2027AMLR Article 22(6)(b) recognises eIDAS electronic identification at substantial or high assurance. Denmark launched AltID, its national digital identity wallet, in June 2026 and is bringing it up to the eIDAS 2.0 requirements. Shufti accepts wallet verification as acceptance duties take effect.
Notified eID
LiveeIDAS HighMitID is Denmark’s notified eID at assurance levels substantial and high, used daily through the MitID app, chip, code display and audio code reader. MitID Erhverv covers organisations. Denmark has no separately notified commercial or bank eID, because the public sector and the Danish banks jointly own MitID. Shufti verifies MitID today.
Docless Database (eIDV)
LiveDatabase-driven verification confirms identity in seconds for low-risk onboarding with no document upload, using permitted reference data sources. Shufti escalates to stronger checks as risk rises.
NFC Chip Verification
LiveShufti reads the secure chip in the Danish passport and in residence permit cards issued to non-EU nationals. This is the high-assurance capture route where a chip is present, and it carries real weight in Denmark because the kørekort has no chip to read.
Document and Face Biometric
LivePermitted under AMLR Art. 22(6)(a). Document authentication of the Danish passport, kørekort, legitimationskort and residence permit card, paired with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness to confirm a real, present person.
Qualified Electronic Signature
LiveSection 11(1)(2) of hvidvaskloven requires identity data to be checked against a reliable and independent source, and names electronic identification means and trust services as examples. Shufti runs eIDAS-qualified signing through Evrotrust, an EU qualified trust service provider, producing PAdES-LTV signatures. For Danish signers the signing identity check runs through MitID.
Independent Validation
Shufti's Recognition Across Independent Evaluations

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Top Vendor for Product Execution in the Liminal Index for KYC 2026
View Report
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader in G2 Fall 2026 reports
Read MoreEvidence-Ready Checks Across People & Businesses
Verifications with robust evidentiary support
Individual Documents We Verify
Shufti supports 20+ Danish document types.
View All Supported DocumentsDanish Passport (Dansk pas)
Denmark’s highest-assurance identity document, applied for and issued through the municipalities. Biometric and ICAO-compliant, with a chip Shufti reads over NFC. It is the only widely held Danish document that supports chip-based capture.
Danish Driving Licence (Kørekort)
EU-format card issued through borgerservice, with the driving licence register (Kørekortregisteret) held by Rigspolitiet. The photo ID most Danes carry day to day and accepted in Danish onboarding, verified through document and biometric checks because it carries no chip.
Municipal Identification Card (Legitimationskort)
Voluntary photo ID issued by the municipality where the holder is registered, available from age 15 under Lov nr. 236 af 15. marts 2017 om udstedelse af legitimationskort. Carries full name, CPR number and nationality, and is accepted domestically where a passport or licence is unavailable.
Health Insurance Card (Sundhedskort)
The yellow card issued to every CPR-registered resident by the municipality. It carries no photograph, so Shufti treats it as supporting evidence in lower-risk checks rather than as primary photo identification.
Residence Permit Card (Opholdskort)
Biometric card carrying a photograph, a machine-readable zone and a chip, issued to non-EU and non-EEA nationals by the Danish Immigration Service and SIRI. Accepted by Danish institutions for identity verification of foreign residents during onboarding.
EU/EEA National Identity Card
National identity cards from other EU and EEA states, accepted in Denmark under free movement rules and valid for identity verification under Danish AML obligations. Verified against ICAO standards with document, biometric and chip-based checks where a chip is present.
Entity Identity
CVR Registration Certificate (Registreringsbevis)
Issued by Erhvervsstyrelsen. Confirms legal name, the eight-digit CVR number, incorporation date, company type, registered address and legal status for KYB.
Articles of Association (Vedtægter)
The founding document of a Danish company, filed electronically with Erhvervsstyrelsen. Used to confirm the company’s constitution and its ownership structure.
Serviceattest Certificate
Official certificate from Erhvervsstyrelsen confirming a company’s current legal standing. Commonly requested for cross-border KYB verification.
Tax Identity
CVR / VAT Registration Certificate
For most Danish entities the eight-digit CVR number is also the SE number used for VAT, prefixed with DK for cross-border use. VAT registration is administered by Skattestyrelsen.
Annual Accounts (Årsrapport)
Statutory financial statements filed with Erhvervsstyrelsen and publicly accessible through the CVR portal. Used in KYB financial due diligence.
Ownership & Control (UBO)
Beneficial Ownership Register (UBO-register) in the CVR
Danish beneficial ownership data sits inside the CVR and is held by Erhvervsstyrelsen. Public access closed on 1 September 2025, and obliged entities now retrieve a defined record through an authenticated route while performing customer due diligence. Shufti runs the AMLR test at 25% or more, or control.
This data may be used only for customer due diligence, and passing it on is punishable by fine.
Shareholder Register (Ejerbog)
The register of capital owners kept by the company itself under the Danish Companies Act. Shufti uses it to map shareholdings and identify the people behind a Danish company, alongside the separate public register of legal owners, which records holdings from 5% upward.
Languages We Cover
Danish document language handling
Native Danish parsing keeps Æ, Ø and Å intact across the passport, kørekort, legitimationskort and CVR records, so checks stay accurate against official sources.
Name matching and diacritic controls
Matching handles the ICAO conversion of Æ, Ø and Å into AE, OE and AA, so ØSTERGÅRD on the document page and OESTERGAARD in the machine readable zone resolve to one person instead of two.
Evidence consistency across verification steps
Cross-document consistency checks reconcile names and identifiers across the passport, CPR data, CVR records and screening output in one consolidated case record.
GOVERNANCE & CONTROLS
Audit-Ready Decisions, Lower Operational Drag
Fewer avoidable re-submissions
Capture tuned to Danish document formats and to NFC reading of the passport chip cuts avoidable re-submissions and manual review.
Cleaner audit trails
Structured logs aligned to the record-keeping duties in hvidvaskloven and to goAML reporting keep every onboarding decision audit-ready.
Better name matching outcomes
Matching handles Æ, Ø and Å and their AE, OE and AA equivalents, reducing false positives on Danish names and the manual review they create.
One workflow, one back office
KYC, KYB and AML screening are consolidated in one operational case view, so one back office team works on every customer file.
National eID-first flow design
MitID-first onboarding with a passport and NFC fallback reflects Denmark’s national identity ecosystem and the way customers actually verify.
Continuous Compliance
Compliance that does not stop at onboarding
AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.
Surface Changes as it happens
DetectPerpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.
Step up when the signal fires
VerifyWhen a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.
Keep the file audit-ready
ComplyEvery check and decision is logged to the record-keeping standards in hvidvaskloven, so the file is organised and retrievable for internal audit and supervisory review.
Perpetual KYC
pKYCKeeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready.
Perpetual KYB
pKYBMonitors the CVR and its beneficial ownership layer for shareholding and control changes, so a shift past 25% ownership, or in control, is caught between reviews.
Built To Fit Denmark’s Compliance Landscape
Finanstilsynet (Danish Financial Supervisory Authority)
Supervises banks, mortgage credit institutions, investment firms, insurers, payment and e-money institutions and crypto-asset service providers for AML. Shufti aligns customer due diligence workflows to hvidvaskloven with structured identity evidence, risk classification logs and ongoing monitoring controls.
Erhvervsstyrelsen (Danish Business Authority)
Maintains the CVR and its beneficial ownership layer, and supervises auditors, estate agents, tax advisers, company service providers and art dealers for AML. Shufti uses CVR data for KYB entity verification and ownership checks.
Spillemyndigheden (Danish Gambling Authority)
Licenses gambling operators and supervises them under hvidvaskloven. Shufti supports KYC, age verification and AML screening for licensed operators.
Hvidvasksekretariatet (Danish Financial Intelligence Unit)
Denmark’s FIU sits within the National Unit for Special Crime and receives suspicious activity reports through goAML. Decision audit trails, structured risk indicators and escalation logs support report documentation.
Skattestyrelsen (Danish Tax Agency)
Administers Danish tax law, VAT registration and business tax identifiers. Shufti corroborates CVR and VAT numbers during KYB.
AMLA (EU Anti-Money Laundering Authority)
The new EU-level supervisor works from Frankfurt and began operating in 2025. It starts direct supervision of selected high-risk cross-border entities from 2028 and shapes technical standards under AMLR.
Deployment Option
Cloud in EU regions, or on-premise deployment, keeps Danish customer data in-region and supports GDPR accountability.
Regulatory Alignment
Aligned with the customer due diligence, beneficial ownership and record-keeping duties in hvidvaskloven, with GDPR principles, and with the AMLR rules that apply in Denmark from 10 July 2027.
Retention Controls
Hvidvaskloven Section 30, and AMLR Article 77 from 10 July 2027, set a five-year minimum for identity, control and transaction records, from the end of the business relationship or an occasional transaction. Personal data must then be deleted unless other law requires longer, so retention settings need to enforce both ends. Shufti provides configurable purge settings.
Encryption & Security
Encryption in transit and at rest, with access controls and audit logging, supports Article 32 GDPR, under our ISO 27001 certification and SOC 2 Type II attestation.
Scope of Our Role
Shufti acts as a data processor and provides verification technology, not legal or regulatory advice. Customer due diligence and the choice of verification method remain with the obliged entity, documented in its own risk assessment.
Biometric Processing
The controller sets the lawful basis. Biometric identification engages Article 9 GDPR, and human review is available in the workflow.
Data and Privacy Controls in Denmark
Denmark AML Sources That Strengthen Decisions
We screen against 215+ sanction regimes, 4,000+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Denmark and globally. A few of them are:
Finanstilsynet (Danish Financial Supervisory Authority)
Hvidvasksekretariatet (Money Laundering Secretariat, FIU-Denmark)
Erhvervsstyrelsen (Danish Business Authority)
Spillemyndigheden (Danish Gambling Authority)
Advokatsamfundet (Danish Bar and Law Society)
Skattestyrelsen (Danish Tax Agency)
Toldstyrelsen (Danish Customs Agency)
Politiets Efterretningstjeneste (Danish Security and Intelligence Service, PET)
Erhvervsministeriet (Ministry of Industry, Business and Financial Affairs)
Udenrigsministeriet (Ministry of Foreign Affairs of Denmark)
Financial Action Task Force (FATF)
EU Consolidated Financial Sanctions List
UN Security Council Consolidated List
European Banking Authority (EBA)
EU Authority for Anti-Money Laundering (AMLA)
European Commission, DG FISMA
Egmont Group of Financial Intelligence Units
Europol, European Financial and Economic Crime Centre (EFECC)
SEE SHUFTI IN YOUR DENMARK WORKFLOW
Turn Danish Verification Requirements into a Smoother Customer Journey
Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for compliance review.
Frequently Asked Questions
Which identity documents can be used for onboarding in Denmark?
Danish customers can be onboarded with the Danish passport, the kørekort, the legitimationskort and the residence permit card, and national identity cards and passports from other EU and EEA states are also accepted. The sundhedskort carries no photograph, so it works as supporting evidence rather than as primary photo identification. Shufti supports document, eID, NFC and biometric verification within one configurable workflow.
Is MitID enough on its own to verify a customer in Denmark?
Often, yes. Finanstilsynet guidance says MitID can in many cases stand alone as the control source for establishing identity where enhanced customer due diligence does not apply, including for remote customers, on the firm’s own assessment of the individual relationship. That guidance covers the identity control step only, so every other due diligence element still applies, and high-risk customers still need more. Shufti runs MitID as the primary route and escalates to NFC, document and biometric checks where your risk policy requires it.
How do you verify a Danish customer who does not have a CPR number?
Customers without a CPR number cannot hold MitID, so verification runs through the document route instead. Shufti reads the chip in a passport or residence permit card over NFC where one is present, authenticates the document, and binds the live person to it with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness. The same case record captures the evidence, so the file looks identical to a MitID file at review time.
How does Shufti support Finanstilsynet-supervised businesses in Denmark?
Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. This helps businesses within the supervisory remit of Finanstilsynet reduce manual hand-offs, standardise compliance records and prepare clearer evidence for internal audit and applicable supervisory review.
What documents are required for KYB in Denmark, and where does beneficial ownership data come from?
KYB in Denmark typically requires a CVR registration certificate, the eight-digit CVR number, VAT registration details, articles of association and beneficial ownership data held in the CVR. Public access to the beneficial ownership layer closed on 1 September 2025, so obliged entities now retrieve a defined record through an authenticated route while performing customer due diligence. Shufti verifies the registry data in real time and screens the UBOs behind it against sanctions and PEP lists.
How are Danish name variants handled in screening?
Matching accounts for the ICAO conversion of Æ, Ø and Å into AE, OE and AA, so a name printed as ØSTERGÅRD on the document page and encoded as OESTERGAARD in the machine readable zone resolves to one person. That keeps false positives on Danish names low and cuts the manual review they would otherwise create.
How long must AML records be retained under hvidvaskloven?
Under Section 30, identity, control and transaction records are kept for at least five years, from the end of the business relationship or an occasional transaction. Danish law then requires personal data to be deleted unless other legislation requires longer retention, so retention settings need to enforce both ends.
Is EU-region data hosting available for Danish customer data?
Yes, Shufti offers EU-based cloud regions, so Danish customer data stays in-region in line with GDPR and the Danish Data Protection Act. On-premise deployment is available where residency requirements are stricter.
What changes for Denmark under AMLR from 10 July 2027?
AMLR applies directly, so no Danish transposition law is needed. It puts eIDAS-conformant electronic identification and qualified trust services at the centre of remote verification and keeps document plus biometric checks available, so most firms are treating eIDAS routes as the default and documenting why they use anything else. It also sets the beneficial ownership test at 25% or more. Hvidvaskloven and its supervisors continue to operate, now under the harmonised EU rulebook.
When will the EU Digital Identity Wallet be usable for onboarding in Denmark?
Denmark launched AltID, its national digital identity wallet, in June 2026. Organisations can register with Digitaliseringsstyrelsen as a relying party to receive credentials, with a narrower route available for age proofs alone. Under eIDAS 2.0, Member States must issue wallets by end-2026, and Article 5f requires firms using strong customer authentication, banks included, to accept them from late 2027. Shufti is built to accept wallet-based verification as relying-party acceptance takes effect, so onboarding flows will not need to be rebuilt.
Let’s Build Trust Into Your Business
1B+Verifications Processed
240+Regions Actively Processed
99.7%Accuracy Rate
Samer Al Tamimi
CEO of Safwa Bank
“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”
Trusted. Compliant. Certified
Explore Shufti For Your Business
Get a personalised demo from our experts.
PROVEN PLAYBOOKS
Explore Practical KYC & AML Resources
10 July, 2026
Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet
A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.
Product Guide





