Due diligence and registers
Remote client identification: what Lithuanian AML law allows with a qualified signature
Lithuanian anti-money-laundering law allows a client to be identified without being physically present when they sign with a qualified electronic signature. Why it works, what evidence has to be kept, and what the method does not cover.
When a client can be identified without being present
The Law on the Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania requires obliged entities to identify a client before entering into a business relationship. Obliged entities are not only banks: the duty also falls on attorneys, notaries, accounting service providers, real estate intermediaries, virtual currency operators and others.
The Law deals separately with the case where the client is not physically present during identification. Article 11 lists the methods by which remote identification is permitted at all. One of them is a qualified electronic signature.
In practice the question is rarely whether this is allowed. The question is almost always a different one: how, two years later, do you show a supervisory authority that identification actually took place.
Why a qualified signature works for identification
A qualified electronic signature rests on a qualified certificate, and a qualified trust service provider may issue such a certificate only after identifying the person. That is done in physical presence or by an equivalent method under eIDAS Regulation (EU) No 910/2014, and the provider itself is supervised and listed on the EU trusted list.
So a qualified signature is not merely an electronic consent. The certificate names the person and their personal code, and the signature is a statement by a supervised provider about who signed. The identification work was already done by the provider when the certificate was issued.
The concept should not be diluted: only a qualified signature qualifies. A scanned image of a signature, a picture at the bottom of a document, a confirmation click, or an email signature block does not meet the requirement.
- The Lithuanian national ID card - a qualified certificate on the chip, which also works contactlessly over NFC.
- Mobile-ID - a qualified certificate on the SIM card.
- A Smart-ID account at the qualified level.
- A USB token or smart card holding a qualified certificate.
The signature alone is not enough: keep the evidence
The most common mistake is to file the signed document away and treat the duty as discharged. The duty is not only to identify, but to be able to show later how identification was carried out. That calls for verifiable data, not a recollection.
One technical detail is worth knowing in advance: a signature without a timestamp and without validation data becomes impossible to check as time passes. Certificates expire, certification authorities rotate their keys, and after a few years there may be nowhere left to confirm that the signing certificate was valid at the time. Keep the signature at a long-term level, or keep it together with a verification report.
- The signed document in its original format, not a printout or a screenshot.
- The verification result: who signed, with which certificate, who issued it, and when the document was signed.
- The personal code named in the certificate, and how it connects to the role the person is acting in.
- A qualified timestamp and validation data, so the signature can still be checked years later.
Identity and role are two different questions
A qualified signature answers the question of who this person is. It does not answer the question of whether this person may act on behalf of this company.
Where the client is a legal entity, the Law requires both the authority of the representative and the beneficial owner to be established. So a check that is useful in practice has two parts: the qualified signature identifies the person, and the registers show whether that same person holds the position claimed - Manager, shareholder or beneficial owner.
Put the two together and you get a statement that can be verified: the personal code in the certificate matches the register entry for that role. As long as the parts are kept separately, a gap remains, because one person may sign while another holds the position.
What the method does not cover
Remote identification by qualified signature settles the identity question. It does not replace the whole know-your-client procedure.
- It does not cover sanctions and politically exposed person screening, which is a separate duty.
- It does not cover risk assessment, source of funds, or ongoing monitoring of the business relationship.
- It does not work for people who hold no qualified signature recognised in Lithuania; another method provided for in the Law is then needed.
- It does not replace enhanced identification where the Law requires it because of higher risk.
What it looks like in practice
The order matters: first establish what the registers say, and only then invite the person to sign. Otherwise you can end up with a faultless signature for a role the person does not hold.
- Establish who, according to the registers, holds the role the person is claiming: Manager, shareholder or beneficial owner.
- Prepare a document that states clearly what the person confirms by signing it.
- Invite the person to sign it with a qualified electronic signature.
- Check the signature and compare the personal code in the certificate with the register entry.
- Keep the document, the signature verification result and the register answers together in one place.
How Tvarka does it
The Tvarka identity verification package performs exactly these steps and returns a single ASiC-E container: the signed document, the register answers as received, the signature verification result, and an attorney confirmation that the person named in the certificate matches the register entry for the stated role.
There are no video calls, no selfies and no biometric data in the process. Identity is proven by a qualified signature the person already holds, so there are no facial images to process and no need to work out whether a photograph of a document is genuine.
You pay only for the result: if nobody in the registers holds the stated position, if the person does not sign, or if the identity does not match, no package is produced and no fee applies.
Frequently asked questions
Is a qualified signature the same as meeting face to face?
In the eyes of the Law it is a self-standing method of remote identification, not a substitute for a meeting. It works because the identity of the person was already established by a qualified trust service provider when the certificate was issued.
Do Smart-ID and Mobile-ID qualify?
Yes, when the signature is at the qualified level. What matters is not the name of the app but whether the signature is qualified, and that is visible in the verification result.
Do I have to keep a copy of an identity document?
With this method identity is established from the data in the qualified certificate rather than from a photograph of a document, so no image of an identity document is needed. What is kept is the data that allows the signature and the person named in the certificate to be checked.
How is this different from a video call?
Video identification checks an identity document and a facial image, so biometric data and recordings are processed. With a qualified signature none of that is needed, and the evidence can be checked technically with any signature verification tool.
Is it enough that the client simply signed the contract?
Not always. If you want to rely on a signature as evidence of identification, it has to be clear what the person confirmed by signing, and the verification result has to be preserved. That is why a separate document is used rather than any signature you happen to hold.
What about clients from other countries?
Qualified signatures from other EU Member States are recognised across the Union under eIDAS. If a person holds no qualified signature, identity has to be established by another method provided for in the Law.
Sources
- Law on the Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania (consolidated text, in Lithuanian) Checked: 2026-08-14
- EUR-Lex: eIDAS Regulation (EU) No 910/2014 (consolidated) Checked: 2026-06-12
- Tvarka Due diligence: public product page Checked: 2026-06-12
- Centre of Registers (Registrų centras): public Register of Legal Entities search Checked: 2026-06-12
- Centre of Registers: ordering JADIS shareholder extracts and lists Checked: 2026-06-12
- Centre of Registers: JANGIS beneficial ownership filings Checked: 2026-06-12