Biometric
KYC & AMLUpdated September 25, 20264 min

KYC in Moldova: Customer Identification, Verification and Monitoring

How to build an auditable Moldovan KYC file covering the customer, representative, beneficial owner, purpose, risk, PEP and monitoring.

A customer can show a valid identity document and pass Face Match, and the KYC decision is still incomplete. Those checks do not establish who controls a company, whether a representative is authorised, why the product is requested or whether the relationship risk is acceptable. The usual design error is collapsing five separate decisions into one identity_verified field.

Under Moldovan Law No. 308/2017, the file should distinguish the customer's claim, verification from a reliable independent source, beneficial ownership, purpose and risk, and ongoing monitoring. A defensible file shows the sources and the reasoning behind the decision. Copies alone cannot do that.

In brief

  • Identification collects data; verification confirms them against an independent source.

  • Customer, representative and beneficial owner are different roles requiring different evidence.

  • Risk determines the depth of checks, approvals and monitoring.

  • Biometrics can bind a person to a reference and current session, but cannot prove ownership, PEP status or source of funds.

  • KYC continues after onboarding and must react to change events.

Five decisions inside KYC

Decision

Control question

Evidence to retain

Identification

What did the customer declare?

Original values, form and documents

Verification

Which independent source confirmed the data?

Source, timestamp, response and discrepancies

Beneficial owner

Which natural person ultimately owns or controls the customer?

Ownership chain and reasoning

Purpose and risk

Why is the relationship opened and what risk does it carry?

Expected profile, factors and approvals

Monitoring

Does later behaviour match the known profile?

Events, analysis, updates and decisions

OCR transfers fields from an image. It does not itself prove that the document is authentic, the data are current or the presenter owns it. Verification needs a reliable independent source and a retained response.

When due diligence is triggered

NBM AML/CFT guidance links standard measures to establishing a business relationship, specified occasional transactions, ML/TF suspicion and doubts about previously obtained data. For certain occasional payments it describes thresholds above MDL 20,000 through payment-service providers and above MDL 200,000 for one or linked operations. Suspicion overrides a threshold exemption.

Build your CDD triggers on events and risk as well as on amounts.

From a company to the natural person in control

The SPCSB beneficial-owner guide distinguishes direct ownership, indirect ownership, control by other means and a fallback. More than 25% ownership or 25% plus one share is one indicator of ownership, and control can take other forms. Voting rights, appointment powers, contracts and financial influence can change the conclusion.

The file should retain every ownership layer, direct and indirect percentages, control rights, source records, discrepancies and the reason for moving to the next criterion. Treat the customer's own declaration as the starting point of that analysis.

Six KYC decisions in Moldova
Editorial model based on Law No. 308/2017, NBM guidance and the SPCSB guide; sector-specific procedures still apply.legis.md

Risk changes the controls

Simplified, standard and enhanced due diligence differ in more than the length of the form. Each level sets its own evidence quality, approval level and monitoring intensity. Complex ownership, multiple jurisdictions, insufficient information or PEP exposure may require enhanced measures.

For PEPs, NBM guidance describes status detection, relevant sources, senior-management approval, source-of-wealth and source-of-funds work and enhanced monitoring. A name match opens a review. It does not confirm PEP status, and it is no reason to reject the customer automatically.

Biometric.Vision AML Screening can find and recheck candidates in declared PEP, sanctions and other sources. The organisation resolves identity, determines the applicable consequence and records its decision.

Biometrics solve only part of the file

Face Match estimates similarity between the current face and a reference portrait. Liveness checks for signs of a live presentation against the attack types it was tested on. Document verification analyses fields and available document signals. None of them establishes representative authority, beneficial ownership, purpose or source of funds.

Remote onboarding is separately governed by NBM eKYC Regulation No. 281/2024. Your general KYC process and the eKYC session have to connect, and neither replaces the other.

Biometric.Vision Orchestrator can connect document checks, biometrics, screening and manual review. The minimum file retains original and normalised data, the source of every check, person roles, ownership structure, risk rationale, separate module results, exceptions, decision owner and policy version.

Law No. 308/2017 and SPCSB guidance generally provide for retaining CDD documents, copies, correspondence and analysis for five years after the relationship or occasional transaction, subject to applicable extensions. Map that rule to each data class in your retention policy instead of keeping whole sessions by default.

Sources

Starter pack · free

Ready to strengthen your customer checks?

500 checks free every month · no card · no contract · no sales call.

Or message us onTelegramWhatsApp— we reply within 5 minutes

Read also