Curaçao sets May 2027 deadline for remote-onboarding controls
Curaçao’s Gaming Authority has imposed mandatory NOIS controls for remote identification, giving existing onboarding systems until 1 May 2027 to comply.

Existing users of remote customer-onboarding solutions have until 1 May 2027 to bring those systems into line with Curaçao’s remote-identification provisions. A provider that has not yet deployed remote onboarding must comply before putting a solution into use.
The Provisions for Identification and Verification Without Physical Contact say they enter into force on publication. It records that the Central Bank of Curaçao and Sint Maarten, the Financial Intelligence Unit and the Curaçao Gaming Authority drafted the provisions under Article 3(1) of the NOIS. The instrument’s stated posture is therefore a set of supervisory provisions under Article 3(1) of the NOIS, with effect from publication.
The provisions apply to service providers within the NOIS scope, except money transfer companies, which cannot have non-face-to-face clients. During the transition, an existing solution may continue only if the provider has begun the steps needed for compliance and can demonstrate them to its supervisor on request. The transition is therefore conditional: it does not give an existing solution an unconditional right to remain in use until the deadline.
Verification controls
The remote process must establish identity from internationally recognised, independently sourced documents and validate copies through an appropriately sourced verification and authentication process. For unattended onboarding, providers must capture clear photographs or video during the verification session, perform active or passive liveness detection and use strong, reliable algorithms to match the person with the official document.
If the evidence is too poor or the result is ambiguous, the process must stop and restart or move to face-to-face verification. Attended onboarding must use reliable image and audio systems and staff trained in AML/CFT/CFP rules, security risks and deception techniques. Remote verification tasks may be performed only by authorised personnel with adequate knowledge, skills and training.
Policies must distinguish automated steps from those requiring human intervention and cover staff induction and regular training. Together, those controls identify the evidence, decision point and authorised person involved in the verification process without adding a separate approval route.
Assessment and monitoring
Before introducing or materially changing a solution, providers must assess data completeness and accuracy, source reliability, money-laundering, operational, technology, reputational and legal risks, fraud and impersonation risk, and end-to-end performance. That assessment belongs before launch or material change; ongoing review addresses how the solution performs after it is operating.
Providers must monitor the solution’s quality, completeness, accuracy and reliability, set the scope and frequency of reviews, define event-driven triggers and document remediation when deficiencies arise. The technology controls include audit trails, secure evidence storage, encryption, privacy and security testing, access logging and vulnerability scanning.
For an existing solution, the operative sequence is to begin and evidence the compliance steps during the transition, keep the system within the stated controls and complete alignment by 1 May 2027. A new solution must meet the provisions before use. The published provisions identify no later filing, consultation or implementation event beyond the 1 May 2027 deadline.
Permanent link to this Atlas analysis
Related Atlas analysis
Continue with coverage connected by market, topic and operating context.
- CyprusEU AML standards put three control owners on noticeAMLA’s draft Regulatory Technical Standards would standardise customer checks, transaction classification and group-wide controls after Commission adoption and publication.
- BrazilCVM/SRE Circular 4/2026 redraws Brazil’s automatic-offering application routeBrazil’s securities regulator has replaced three automatic-registration applications and added mandatory review and issuer-status fields, with implementation completed by 24 August.
- SeychellesSeychelles tightens trustee disclosure and register dutiesSeychelles’s Trusts (Amendment) Act 2026 protects good-faith AML/CFT disclosures while requiring trustees to maintain accurate register information from publication.
Continue with Atlas
Move from this development into the relevant research, comparison and workflow.
- Gambling compliance software guideSee the research, monitoring, ownership and evidence a useful platform should connect.
- Atlas vs VixioCompare gambling research, change monitoring, workflow, technical work and evidence.
- Monitoring and alertsFollow a relevant change from detection through accountable implementation.