Curaçao mandates stricter checks for remote onboarding
Table of contents
- Curaçao Gaming Authority (CGA) has published binding provisions governing how businesses identify and verify customers who are not physically present, in force since August 21, 2026.
- Operators already running remote onboarding solutions must reach full compliance by May 1, 2027.
- The rules were developed with the Central Bank of Curaçao and Sint Maarten and the Financial Intelligence Unit Curaçao, and apply beyond gambling to any service provider covered by the National Ordinance on Identification when Rendering Services (NOIS).
The Curaçao Gaming Authority has published binding requirements for verifying customers who cannot be physically present during onboarding, confirmed in an official announcement stating the Provisions for Identification and Verification without Physical Contact took effect on August 21.
Operators already using a remote onboarding solution have until May 1, 2027 to bring it into full compliance.
Beyond the casino floor
The CGA developed the provisions jointly with the Central Bank of Curaçao and Sint Maarten and the Financial Intelligence Unit Curaçao. The regulator says the private sector, including operators from the online gaming industry, was consulted during drafting.
The rules apply under NOIS, so they reach any service provider handling remote client identification, not only gambling operators. Businesses that do not currently use remote onboarding must meet the requirements before switching one on, closing a gap that would otherwise let new systems launch outside the standard.
The provisions extend a year of expanding AML oversight from the CGA, which has faced its own turbulence since the board’s mass resignation in 2025. Since then, the regulator has published a crypto guideline for B2C licensees and required operators to rewrite their terms and conditions around account management and transparency.
How verification works
The provisions accept passports, identity cards and driving licenses, along with any other document the Minister of Finance designates.
Providers can use document-scanning technology and video verification, but automated systems must confirm the person being checked is physically present, not a photograph, recording or other form of impersonation.
Firms that rely on automated biometric checks must test the technology against internationally recognized standards, keep audit trails, encrypt stored data and put the systems through security testing.
Responsibility for compliance stays with the Curaçao-licensed operator even when identity verification itself is outsourced to a third-party technology vendor. Operators leaning on external KYC providers cannot point to that vendor if checks fall short.
Deadline and penalties
Operators with an existing remote onboarding solution do not have to rebuild it immediately. They can keep it running through the transition period, provided they have started work toward compliance and can show the CGA evidence of that progress on request.
Sanctions for falling short go beyond fines. The CGA can issue administrative or criminal penalties, and in serious cases, revoke a license or pursue imprisonment.
Ireland recently set out a national AML strategy covering gambling and crypto, and Australia is midway through its own AML/CTF overhaul of the wider gambling sector. Curaçao’s timeline sits alongside those efforts, though its rules answer a narrower question: whether an operator can prove, on demand, that the person behind a screen is who they claim to be.
Operators with a remote onboarding solution now have roughly eight months to document their path to compliance, or show the CGA a system already built to the new standard.
Do you have a story worth sharing?
Send it over to our editors!