- Australia
- Austria
- Bangladesh
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Croatia
- Cyprus
- Czech Republic
- Denmark
- Egypt
- Estonia
- Eswatini
- Ethiopia
- Finland
- France
- Germany
- Greece
- Haiti
- Hong Kong
- Hungary
- India
- Iraq
- Ireland
- Indonesia
- Italy
- Japan
- Jordan
- Kazakhstan
- Kenya
- Kosovo
- Kuwait
- Latvia
- Lithuania
- Luxembourg
- Malaysia
- Malta
- Mauritius
- Mexico
- Micronesia
- Moldova
- Mongolia
- Montenegro
- Morocco
- Mozambique
- Myanmar
- Namibia
- Nauru
- Nepal
- Nigeria
- Nicaragua
- Niue
- Norway
- Netherlands
- New Zealand
- Oman
- Pakistan
- Palau
- Palestine
- Panama
- Papua New Guinea
- Paraguay
- Peru
- Puerto Rico
- Philippines
- Portugal
- Poland
- Qatar
- Republic of Congo
- Romania
- Russia
- Rwanda
- Samoa
- San Marino
- Senegal
- Serbia
- Seychelles
- Sierra Leone
- Singapore
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- South Sudan
- Spain
- Sri Lanka
- St Kitts and Nevis
- St Maarten
- St Lucia
- Sweden
- Switzerland `
- Syria
- Taiwan
- Tajikistan
- Tanzania
- Thailand
- Timor Leste
- Togo
- Tonga
- Trinidad and Tobago
- Turkey
- Turks and Caicos
- Turkmenistan
- Tunisia
- Tuvalu
- Uganda
- Ukraine
- UK
- USA
- Vietnam
ITALY KYC, KYB AND AML
Scale Identity Verification and KYC Operations in Italy
Verify Italian customers and businesses through the CIE, SPID, NFC, QES, identity documents, biometrics and KYB. Reduce manual review, maintain consistent audit evidence and run one connected workflow designed to support the D.Lgs. 231/2007 framework today and AMLR from 10 July 2027.
Operational Performance for Italy KYC
Our Numbers Speak Volumes
99.08%
First-Pass
Verification Rate
< 10 sec
Median
Verification Time
5+
Italian ID Methods
Supported
Italy IDV/KYC Challenges
Two eIDs, One Paper Cut-Off
Italy runs two notified eIDs, SPID and the CIE, while the paper identity card lost travel validity on 3 August 2026 and keeps only limited domestic use until 31 January 2027. Flows that do not handle the mix fall back to manual uploads that are slower and easier to spoof.
Italian Names Break Global Matching
Accented letters such as à, è and ò, the apostrophe in names like D'Angelo, and regional and compound surnames trigger false positives and manual review spikes when diacritics are stripped in international databases.
Ownership Has Been Hard to See Through
The Registro dei titolari effettivi stays suspended pending the Consiglio di Stato, though the CJEU upheld it with conditions on 21 May 2026. Layered holdings behind an S.r.l. or S.p.A. still slow UBO checks.
Registry Data Is Not Verification
The Registro delle Imprese confirms a company exists, not who controls it or whether they are sanctioned. KYB needs screening layered on top of registry lookups.
Regulatory Update
What AMLR Changes for Identity Verification in Italy
The EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly in Italy from 10 July 2027, with no transposition period. D.Lgs. 231/2007 is being amended to sit beside it. AMLA in Frankfurt directly supervises selected entities from 2028.
Timeline
- End of 2026 Member State EUDI Wallet issuance deadline
- 10 July 2027 AMLR applies, no transposition
- Dec 2027 EUDI Wallet acceptance, eIDAS 2.0 Art 5f
- 2028 AMLA direct supervision begins
eIDAS Is Expressly Recognised
Article 22(6) allows two routes, an ID document backed by reliable, independent sources, or eIDAS eID at level substantial or high with qualified trust services. Both are valid. The CIE and SPID sit in the eIDAS route. Document your route and why.
The Ownership Test Tightens
AMLR moves the ownership test from over 25% to 25% or more, assessed with control, so a UBO can sit below any line. The Commission may lower it, floored at 15%.
Existing Customers Get Re-Checked
AMLR expects existing customer records to be brought up to standard on a risk basis, not just new onboarding. Continuous monitoring keeps back-book files current between reviews.
Accountability Stays With You
Article 18 keeps customer due diligence accountable with the obliged entity even when verification is outsourced, so vendor evidence and clean audit trails matter more under AMLR.
FOR BUSINESSES SUPERVISED BY BANCA D'ITALIA
Streamline Banca d'Italia-Supervised Onboarding in Italy
Connect IDV, QES, Penny Drop and compliance evidence in one workflow for firms under Banca d'Italia's remit, built around Article 19 of D.Lgs. 231/2007 and Banca d'Italia's adeguata verifica provisions (2019, as amended). Cut drop-off and hand-offs with a review-ready record of every decision.
Verify the Customer
Verify identity using the configured route, such as the CIE or SPID, NFC document reading or document and biometric checks.
Complete Qualified Signing
Apply and validate the QES within the same journey, keeping the signed document, verification result and supporting evidence together. For Italy the signing identity check runs through the CIE or SPID.
Confirm the Payment Account
Use Penny Drop Verification to confirm account ownership as a supporting control, and keep that evidence with the rest of the onboarding record.
Shufti's IDV/KYC Solutions for Italy
KYC Solutions
Built to support the KYC obligations that apply where you operate. Shufti verifies age and address in the same flow as identity checks, with each check completing in under 5 seconds.
Explore MoreFace Verification
Face verification binds the live person to the document with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness, stopping spoofs, masks and deepfakes.
.Age Verification
Selfie-based age estimation and document-based age checks, set to your sector's rules. Italy's AGCOM double-anonymity regime for adult sites needs its own design.
.Bank Account Verification
Confirms an Italian bank account (IT IBAN) belongs to the customer, returning the registered account holder name for matching against the verified identity.
.Address Verification
Shufti verifies Italian address-bearing documents, including utility invoices, telecom bills and bank statements from major Italian issuers. Proof-of-address checks remain common in regulated onboarding.
.Document Verification
Shufti verifies Italian identity documents, including the CIE electronic ID card and passport, with the CIE as the primary route for new onboarding. NFC chip reading and Italian-language OCR extraction are built in. Remains a permitted route under AMLR.
.Identity Verification
Shufti confirms every customer is real and present, not a spoofed or synthetic identity. Biometric face matching and liveness detection run against 10,000+ actively processed document types.
.KYB Solutions
Every business you onboard is obligated to undergo the same scrutiny as the people behind it. Shufti checks registry records, beneficial ownership, and VAT details in real time, then screens UBOs against 4,000+ global watchlists for sanctions and adverse media exposure.
Explore MoreBusiness Verification
Automated validation of Registro delle Imprese data, the visura camerale, Partita IVA and Codice Fiscale, and appointed directors. Reduces manual registry lookups and onboarding delays.
.Enhanced Due Diligence (EDD)
Structured risk profiling for complex ownership chains, cross-border entities and high-risk sectors, supporting Italy's risk-based AML obligations under D.Lgs. 231/2007.
.AML Screening
Shufti screens customers and transactions in 240+ countries and territories, flagging sanctions, PEP, and adverse media matches as they happen. Ongoing monitoring surfaces suspicious activity in time to meet local reporting obligations.
Explore More
AI Compliance Copilot
Helps compliance teams review verification and AML data, investigate alerts, and understand the reasoning behind risk signals. It brings relevant case information together to support faster, more consistent compliance decisions.
.
Transaction Monitoring
Ongoing transaction monitoring calibrated to Italian financial flows flags anomalies against AML rules, supporting the risk-based controls Banca d'Italia and the UIF expect.
.Supported Verification Methods for Italy
Every Verification Route Italy Uses, in One Platform
Shufti supports the full range of remote verification routes used in Italy, from the EUDI Wallet and the CIE and SPID to document and biometric checks. Each method below shows what is live today and what is ready for the 2027 rollout.
EUDI Wallet
Wallet-ready · from 2027AMLR Article 22(6) expressly recognises eIDAS eIDs, including the EUDI Wallet. Italy is rolling out its wallet as IT-Wallet through the IO app under the eIDAS 2.0 rollout. Shufti is built to accept wallet-based verification as the Italian wallet goes live.
Notified eID
LiveeIDAS notifiedThe CIE is Italy's notified eID, up to eIDAS level high, via the CieID app. SPID is Italy's notified public digital identity, run by private providers like PosteID at levels low to high. Shufti verifies both today.
Docless Database (eIDV)
LiveDatabase-driven verification confirms identity in seconds for low-risk onboarding with no document upload, using permitted reference data sources. Shufti escalates to stronger checks as risk rises.
NFC Chip Verification
LiveShufti reads the secure chip in the CIE, the permesso di soggiorno residence permit and the Italian ePassport. This is the high-assurance capture route where eID activation is still ramping.
Document and Face Biometric
LivePermitted by AMLR Article 22(6)(a). Document authentication of the CIE, permesso di soggiorno and ePassport, paired with iBeta Level 3 Conformance to ISO/IEC 30107-3 liveness to confirm a real, present person.
Qualified Electronic Signature
LiveA qualified electronic signature is a qualified trust service AMLR recognises for remote verification. Shufti runs eIDAS-qualified signing powered by Evrotrust, an EU qualified trust service provider, producing PAdES-LTV signatures. Italy is a notified-eID country, so the signing identity check runs through the CIE or SPID.
Independent Validation
Shufti's Recognition Across Independent Evaluations

Ranked Exceptional in the Liminal Index 2026 for age estimation
View Report
Differentiated by Gartner on document diversity and country coverage
Read more
Certified at iBeta Level 3 PAD with 0% APCER
Read Blog
Broadest global reach in the 2025 KuppingerCole Extended IDV report
Download Report
Ranked Top 5 in the DHS RIVR 2025 for identity validation
Read Blog
Top Vendor for Product Execution in the Liminal Index for KYC 2026
View Report
Ranked Exceptional for age verification by Liminal Index 2026
View Report
Recognised as a Leader in G2 Fall 2026 reports
Read MoreEvidence-Ready Checks Across People & Businesses
Verifications with robust evidentiary support
Individual Documents We Verify
Shufti verifies more than 15+ individual Italian documents.
View All Supported DocumentsCarta d'Identità Elettronica (CIE)
Primary ID for most people onboarding in Italy. The card carries OCR-readable fields, a contactless chip, residence address and fiscal code, which makes it strong for identity and consistency checks.
Carta d'Identità Cartacea
Seen in older books. Invalid for travel or new contracts from 3 August 2026. Unexpired cards keep limited domestic use, incl. banking, to 31 January 2027.
Passaporto Elettronico Italiano
Primary fallback for cross-border users, AIRE users and cases where no CIE is available. Italy issues biometric e-passports with a chip containing biographic data, photo and fingerprints.
Permesso di Soggiorno Elettronico
Core identity and residency evidence for many non-EU nationals. The electronic permit is card-based and stores biographic and biometric data for identity checks and immigration status handling.
Patente di Guida Italiana
Equivalent to the ID card under Article 35 of DPR 445/2000 and accepted for SPID enrolment. Useful as supporting evidence with stronger primary data.
Entity Identity
Visura Camerale / Certificato Camerale
Official registry extract used to confirm company name, legal form, registered office, status and registration details from the Registro delle Imprese.
Statuto, Bilanci and Fascicolo d'Impresa
Used to evidence legal constitution, governance, filed accounts and corporate history where a fuller KYB packet is needed.
INI-PEC / Registry Profile
Useful for confirming the registered digital domicile and cross-checking official company identity data held in the chamber system.
Tax Identity
Partita IVA
Used to confirm VAT registration status, holder name and activity dates, including active, suspended or ceased status.
Codice Fiscale
Used to confirm the validity and exact correspondence between the tax code and the legal denomination of a non-natural person.
VIES Status
Useful for cross-border EU onboarding where intra-Community VAT authorisation needs to be confirmed.
Ownership & Control (UBO)
Director And Legal Representative Evidence
Pulled from visure, certificates and Telemaco records to identify who can bind the company and who currently manages it.
Shareholder Evidence
Registry records, shareholder lists, deeds or corporate papers for ownership, plus control where ownership alone does not name the UBO.
Signed UBO Declaration and Ownership Chart
Register access is suspended pending the Consiglio di Stato, though the CJEU upheld it with conditions on 21 May 2026. Firms use ownership proof, declarations and company records.
Languages We Cover
Document Text Handling
Italian onboarding is mainly Latin-script, but CIE, tax and identity records must still handle long names, OCR fields, chip-era layouts and machine-readable elements cleanly.
Name Matching Controls
Shufti can handle apostrophes, particles and spacing shifts such as D'Angelo, D Angelo and De Luca, plus foreign passport transliterations, while keeping the original extracted value visible for review.
Evidence Consistency
Italian journeys should reconcile user identity across document, selfie and supporting-evidence steps while handling codice fiscale omocodia and related tax-code edge cases without forcing false mismatches.
Governance & Controls
Audit-Ready Decisions, Lower Operational Drag
Fewer Avoidable Re-submissions
Optimised capture for Italian ID formats and the NFC-enabled CIE cuts avoidable re-submissions and manual review.
Cleaner Audit Trails
Structured logs aligned to D.Lgs. 231/2007 record retention and UIF reporting obligations keep every onboarding decision audit-ready.
Better Name Matching Outcomes
Matching handles accents, apostrophes and compound surnames common in Italy, reducing false positives and manual review.
One Workflow, One Back Office
KYC, KYB and AML screening are consolidated in one operational case view, so one back office team works on every customer file.
National ID-First Flow Design
Start onboarding with the CIE electronic ID or passport as the primary route, with residence permits or driving licences accepted as supplementary evidence.
Continuous Compliance
Compliance that does not stop at onboarding
AMLR treats customer due diligence as a continuing obligation. Perpetual monitoring keeps the customer picture current between reviews, so risk is caught when it appears, not at the next annual check.
Surface Changes as it happens
DetectPerpetual monitoring flags risk when it appears, not at the next annual review. Behavioural biometrics, background fraud signals, and ongoing sanctions and PEP screening watch every active relationship.
Step up when the signal fires
VerifyWhen a signal fires, re-verification confirms the person or the ownership change using the same live methods above, so a flag turns into a resolved decision.
Keep the file audit-ready
ComplyEvery check and decision is logged to D.Lgs. 231/2007 record-keeping standards, so the file is organised and retrievable for internal audit and supervisory review.
Perpetual KYC
pKYCKeeps individual customer risk current with behavioural biometrics, background fraud signals and ongoing AML screening, so back-book records stay standard-ready.
Perpetual KYB
pKYBMonitors the Registro delle Imprese for shareholding and control changes, and the Registro dei titolari effettivi once access resumes, so a holding reaching 25% or a control change is caught between reviews.
Built To Fit Italy's Compliance Landscape
Banca d'Italia
Oversees AML controls for supervised financial firms. Shufti helps structure CDD evidence, decision reasons and retained records for supervisory review.
UIF
Receives and analyses suspicious transaction reports in Italy. Shufti helps teams keep escalation notes, screening results and case evidence ready for reporting and follow-up.
CONSOB
Regulates securities and investment-market participants. Shufti helps retain reviewable onboarding, screening and decision evidence for investment-sector controls.
IVASS
Regulates insurers and insurance intermediaries. Shufti supports customer due diligence, enhanced review paths and retained audit history for higher-risk cases.
MEF / Comitato di Sicurezza Finanziaria
Coordinates Italy’s financial sanctions framework. Shufti helps screen customers, businesses and controllers, with time-stamped match and escalation records.
Ministero dell’Interno
Relevant to the Italian document ecosystem, including the CIE, passports and residence permits. Shufti supports document checks, selfie verification and fallback logic across the main official identity routes.
AgID / SPID Ecosystem
Oversees Italy’s digital identity framework. Shufti supports document checks, selfie verification and step-up controls where stronger assurance is needed.
Agenzia delle Entrate
Operationally important for Partita IVA and Codice Fiscale validation in Italian KYB and tax-identity controls.
Registro delle Imprese / Camere di Commercio
Holds Italy’s official company registry. Shufti helps build KYB workflows around registry data, director details and ownership evidence.
Garante per la Protezione dei Dati Personali
Enforces Italy’s privacy regime alongside the GDPR. Shufti supports controlled access, retention and review processes for identity and compliance data.
AMLA (EU Anti-Money Laundering Authority)
The new EU-level supervisor has been established in Frankfurt since July 2025. Begins direct supervision of selected high-risk cross-border entities from 2028 and shapes technical standards under AMLR.
Deployment Choice
Cloud in EU regions, or on-premise, keeps Italian customer data in-region and supports GDPR accountability.
Regulatory Alignment
Aligned with D.Lgs. 231/2007 due diligence obligations, UBO verification and record-keeping duties, as well as GDPR principles and AMLR requirements applying from July 2027.
Retention Controls
Ten years after a relationship ends (Art. 31 D.Lgs. 231/2007). AMLR Art. 77 sets five years from 10 July 2027, extendable case by case. Italy is undecided.
Encryption & Security
Encryption in transit and at rest, with access controls and audit logging, supports Article 32 GDPR obligations, under our ISO 27001 certification.
Lawful Basis and Biometrics
The controller sets the lawful basis for processing. Biometric data used for unique identification engages Article 9 GDPR, and human review is available in the workflow.
AI Act Position
AI Act Article 50 transparency duties apply from 2 August 2026, and Annex III high-risk duties from 2 December 2027 (Regulation (EU) 2026/1744). Human review is available.
Roles and Responsibilities
Shufti is a data processor providing verification technology, not legal advice. CDD and the choice of method stay with the obliged entity, set out in its risk assessment.
Data and Privacy Controls in Italy
Italy AML Sources That Strengthen Decisions
We screen against 215+ sanction regimes, 4,000+ watchlists, 100,000+ adverse-media sources, and 6M+ PEPs across Italy and globally. A few of them are:
UIF, Unità di Informazione Finanziaria per l'Italia
Banca d'Italia
CONSOB (Commissione Nazionale per le Società e la Borsa)
IVASS (Istituto per la Vigilanza sulle Assicurazioni)
MEF, Comitato di Sicurezza Finanziaria
Guardia di Finanza
Direzione Investigativa Antimafia (DIA)
Registro Imprese (Italian Business Register)
Garante per la protezione dei dati personali
FATF
EU Consolidated Financial Sanctions List
UN Security Council Consolidated List
European Banking Authority (EBA)
EU AMLA (Anti-Money Laundering Authority)
SEE SHUFTI IN YOUR ITALY WORKFLOW
Turn Italian Verification Requirements into a Smoother Customer Journey
Share your customer types, risk rules and current onboarding process. A Shufti specialist will show you how to connect identity verification, KYB, QES, Penny Drop and ongoing monitoring, reducing operational hand-offs while keeping decision evidence organised for compliance review.
Frequently Asked Questions
Is the CIE sufficient for D.Lgs. 231 onboarding?
Yes. The Carta d'Identità Elettronica is the primary identity document for Italian citizens and is Italy's notified eID at the highest eIDAS assurance level. Shufti reads the CIE chip directly and pairs it with a biometric check for high-assurance onboarding.
Can EU nationals onboard with their national ID card?
Yes. EU and EEA national identity cards are recognised for Italian onboarding under the EU AML framework, and AMLR keeps them valid from July 2027. Shufti verifies them with document, biometric and chip-based checks in one flow.
Does Italy use goAML?
No. Italy's Financial Intelligence Unit, the UIF, receives suspicious transaction reports through its own INFOSTAT-UIF portal, not goAML. Shufti structures verification and screening evidence so those reports can be filed without a manual scramble.
What documents are required for KYB in Italy?
Typically a visura camerale from the Registro delle Imprese, the Partita IVA and Codice Fiscale, and beneficial ownership details from a signed UBO declaration and ownership chart while access to the Registro dei titolari effettivi is suspended. Shufti verifies the registry data in real time and screens the UBOs behind them against sanctions and PEP lists.
How are Italian name variants handled in screening?
Matching accounts for accents, apostrophes in names such as D'Angelo, and compound or regional surnames, so Italian names resolve correctly and false positives stay low.
How long must AML records be retained in Italy?
Ten years after the relationship ends under Article 31 of D.Lgs. 231/2007. From 10 July 2027 AMLR Article 77 sets five years, extendable case by case, and Italy is undecided. Shufti logs evidence for the applicable period.
Is EU-region data hosting available?
Yes. Shufti offers EU-based cloud regions, so Italian customer data stays in-region in line with GDPR. On-premise deployment is available where residency requirements are stricter.
What changes for Italy under AMLR from July 2027?
AMLR applies directly, so no Italian transposition law is needed. It permits two routes, document-based and eIDAS-based, so notified eIDs, the EUDI Wallet and qualified trust services sit alongside document and biometric checks, and sets the UBO test at 25% or more, assessed with control.
Will QES alone satisfy identity verification under AMLR?
A qualified electronic signature is a qualified trust service AMLR recognises for remote verification. Shufti runs QES flows that work under D.Lgs. 231/2007 today and carry over when AMLR applies, with the signing identity check running through the CIE or SPID.
How does Shufti support businesses supervised by Banca d'Italia?
Shufti connects identity verification, KYB, AML screening, QES, account verification and decision evidence in one configurable workflow. This helps businesses within Banca d'Italia's supervisory remit reduce manual hand-offs, standardise compliance records and prepare clearer evidence for internal audit and applicable supervisory review.
Let’s Build Trust Into Your Business
1B+Verifications Processed
240+Regions Actively Processed
99.7%Accuracy Rate
Samer Al Tamimi
CEO of Safwa Bank
“We take our client’s privacy very seriously and always look for new innovative solutions to ensure a safe banking experience. Working with Shufti feels like a breath of fresh air, as their 100% in-house tech keeps our customer’s data free from vulnerabilities and fully safe and protected.”
Trusted. Compliant. Certified
Explore Shufti For Your Business
Get a personalised demo from our experts.
PROVEN PLAYBOOKS
Explore Practical KYC & AML Resources
10 July, 2026
Identity Verification in Europe: eIDAS 2.0 & EUDI Wallet
A practitioner's guide to verifying identity in Europe, covering eIDAS 2.0, the EUDI Wallet, docless eIDV and how to choose an eID provider for onboarding in the EU.
Product Guide





