Biometric
KYC & AMLUpdated September 25, 20267 min

KYC in Azerbaijan: a decision map for remote bank onboarding

How banks can separate CDD, authority, beneficial ownership, video identification, authentication, risk and monitoring in Azerbaijan.

A customer can pass Face Match and liveness and still fail KYC. Biometrics can provide evidence that a live presenter resembles a portrait from an accepted source. They do not establish a representative's authority, reveal who ultimately controls a company, explain source of funds or show that nobody is coaching the customer off camera.

In Azerbaijan the distinction has direct consequences. The Central Bank's Regulations on opening, maintaining and closing bank accounts set category-specific routes for remote account opening, which combine video calls or recordings, public information systems, strengthened authentication and electronic signatures. Alongside them, the current AML/CFT Law No. 781-VIQ requires customer due diligence before and throughout the relationship.

In brief

  • KYC is a chain of decisions about identity, authority, ownership, purpose, risk and later behaviour.

  • Under the account rules, a video recording and an interactive video call are separate controls, and one cannot stand in for the other.

  • A document image and a check against an authorised public information system count as different evidence.

  • Strengthened authentication requires independent elements from different factor categories.

  • The audit file keeps sources, discrepancies, rule versions and the owner of each decision alongside the approved status.

KYC begins with control questions, not the camera

Article 4 of Law No. 781-VIQ triggers CDD by events as well as by the relationship. It applies when a relationship begins and in specified one-off transaction, transfer, virtual-asset, suspicion and data-quality scenarios. So KYC cannot live on a registration screen that the customer sees once.

Control object

Question to answer

Why one document is insufficient

Customer

Who is entering the relationship?

A document can be false, misused or out of date

Representative

May this person bind the customer?

Identity does not prove the scope of authority

Legal entity

Does it exist and who manages it?

Registration does not show the full control chain

Beneficial owner

Which natural person ultimately owns or controls it?

A named shareholder may not be the effective controller

Purpose and risk

Why is the product needed and what review depth follows?

A product name does not describe expected activity

Monitoring

Does later behaviour still fit the profile?

Correct data ages and risk changes

Keep the resulting data objects separate. A single customer_verified = true field erases the difference between identity, authority, ownership and risk acceptance.

Beneficial ownership is a reasoned path to a natural person

Article 4.7 of the AML/CFT Law sets a sequence: identify the natural person with the relevant qualifying holding, then the person exercising control by other means and, if those routes do not identify anyone, the natural person managing the entity. The qualifying-holding threshold comes from the applicable sector legislation, so do not swap in a convenient percentage from another jurisdiction.

A reproducible file retains the direct and indirect ownership map, registers and corporate documents used, calculated interests at each layer, non-ownership control indicators, the reason for moving to the next test and the rule edition. The result then feeds risk assessment and PEP or sanctions analysis.

Remote account opening starts with customer classification

Evidence path for remote KYC in Azerbaijan
Editorial map based on Section 5 and Appendix 6 of the Central Bank account regulations. It separates evidence and decisions; it is not a legal determination for a specific product.cbar.az

The regulations allow an account to be opened without the customer and a bank employee being physically together, but they set no single universal path. They restrict some non-resident legal-entity and representative scenarios and tie remote opening to obtaining the required documents from public information systems.

For a new customer, route selection depends on residence, legal form and status. Certain entities and non-resident individuals use a strengthened electronic signature with a video call. A resident individual can use the provided strengthened-signature or strengthened-authentication route with a video call. Existing customers opening another account have a separate route in which a video recording may be used, while the bank can require a call where the recording is considered risky.

For the product, this means an asynchronous recording cannot quietly replace an interactive call for every first-time applicant. Classify the customer before you choose the biometric scenario.

Four evidence objects inside video identification

The account rules describe face-to-document comparison, document and data checks through public information systems and liveness measures in the video-identification process. They solve different problems:

  • Face Match estimates similarity between the current image and the chosen reference portrait;

  • Liveness evaluates whether the presentation has properties expected from a live capture within the tested attack scope;

  • Document Verification analyses the submitted document and extracted fields;

  • the public-source query independently confirms the relevant data.

High facial similarity says nothing about whether the reference document is authentic. A passed liveness check does not show that the customer is acting of their own free will, and a matching face does not establish a director's powers or the source of funds.

Appendix 6 of the account regulations also requires the employee to assess dialogue and behaviour and to consider social engineering, third-party pressure and other fraud methods. A remote flow therefore needs a human escalation route that carries the session context along with the score.

Strengthened authentication is not any two checks

Clause 5.7 of the account regulations uses two or more independent elements from knowledge, possession and inherence categories. A password belongs to knowledge, a registered device or one-time code to possession, and a face or fingerprint to inherence. Compromise of one element should not compromise the other.

Two questionnaire answers still belong to one category. An SMS code and a face capture on the same compromised device call for a threat analysis, and counting them as two factors misses the point. The architecture has to account for account takeover, session substitution, replay, deepfake and coercion.

Risk determines what additional evidence is proportionate

Articles 4.4–4.5 and 4.11–4.13 of Law No. 781-VIQ connect purpose, customer profile and ongoing activity with risk and source of funds. Higher-risk relationships require enhanced measures. The law also provides specific treatment for politically exposed persons, relevant relatives and close associates.

Biometric.Vision AML Screening can return candidate matches from the stated sanctions, PEP and other sources and support repeat monitoring. The bank then resolves identity, role, policy effect and residual risk, because a candidate match decides nothing on its own.

A useful risk record answers four questions: which fact changed the rating, which additional evidence addresses that fact, who may approve the residual risk, and which later event starts a new review.

Five failure modes to test before launch

Recording substituted for a call. New and existing customers get the same convenient flow, although the rules set different controls for them.

Only the document image is checked. The flow treats OCR and image features as confirmation and skips the required public-source step.

All checks collapse into one status. Document, face, liveness, authority, ownership and screening become approved, so partial failure and manual exception cannot be explained.

Dependent checks are counted as independent factors. The interface counts steps but not factor category, compromise path or independence.

KYC ends when the account opens. A new owner, manager, activity pattern or PEP status never triggers a refresh of the profile and risk rating.

The output is an evidence file, not a conversion event

Biometric.Vision Orchestrator can connect available document, face, liveness and AML-screening modules with versioned routing. Integration with a public source, a video-call system and manual review has to be confirmed for each specific project. The bank remains responsible for the legal decision.

The minimum file contains customer category and route basis, original data and source, separate technical results, authentication factors and their independence, representative authority, beneficial-ownership reasoning, purpose and risk, PEP/sanctions resolution, escalation reasons, final approver, policy version and later monitoring events.

Article 6 of the AML/CFT Law provides retention rules for transaction information and CDD materials, with a minimum period and possible extension by the relevant authority. Design retention by evidence class and trigger instead of setting one expiry timer for the entire session.

A reviewer who opens the file should see who was identified and from which sources, what uncertainty remained, who accepted it, and why later behaviour was judged consistent with the relationship.

Sources

Starter pack · free

Ready to strengthen your customer checks?

500 checks free every month · no card · no contract · no sales call.

Or message us onTelegramWhatsApp— we reply within 5 minutes

Read also