Skip links

EU Digital Identity Wallets: Where do banks fit?

EUDI Wallet - Where do Banks Fit

The EUDI Wallet will be available as an app. But it is more than that: the larger change is the regulated ecosystem behind it: wallet providers, identity and attestation issuers, registrars, and Relying Parties (RP) must all work together.

By December 24, 2026, every EU Member State must provide at least one EUDI Wallet. From then on, organisations like the banks can use the wallets as so called ‘Relying Party’ to identify their customers during onboarding, let them log in to their services, digitally sign documents, or use further attestations (e.g., a proof of age to obtain reliable information about the wallet owner). For this, they must register and specify their planned use of the EUDI Wallet with a registrar in the country where they are established. Moreover, by December 24, 2027, private relying parties which have to offer strong user authentication (including those in banking and financial services), and very large online platforms must also accept wallets for customers’ authentication.

Here is what banks and PSPs need to know about the EUDI Wallet ecosystem, who are legally required to participate in it.

The EUDI Wallet ecosystem

The European Digital Identity Framework (Regulation (EU) 2024/1183) establishes a multi-wallet framework interoperable across the EU states. Four operational roles are central to identification and attribute sharing:

  • Wallet providers: Every member state has to provide its citizens with an EUDI wallet. However, wallets can also be provided by independent private participants.
  • Person identification data (PID) providers: They issue and revoke the identity data at the wallet’s core and bind it to the user’s wallet app. The European Commission maintains a list of PID providers.
  • Attestation providers: They issue additional verified attributes and could be Qualified Trust Service Providers (QTSP), public sector bodies, or even private organizations, depending on the type and trust level of the electronic attestations of attributes (EAA).
  • Relying parties and intermediaries: They are entitled to request and receive Personal Identification Documents (PIDs) / attributes from a wallet for providing a service. Thus, a PSP becomes an RP by accepting the wallet for SCA, onboarding etc. For facilitating wallet access, “intermediaries”, like Banfico, are permitted to act on behalf of the RP, thereby simplifying the process for them.

EUDI Wallet Ecosystem

In this ecosystem, banks and PSPs can have several roles at the same time:

  • Relying party
  • Financial attribute attestation issuer
  • Partner to a qualified trust service provider
  • Wallet provider (recognised by a member state and certified)

Each role comes with registration, certificate-validation and lifecycle requirements. A missing or outdated trust record can interrupt a wallet journey and create a compliance issue.

eIDAS 2.0 – Requirements for banks and PSPs

Two requirements will shape bank and PSP programmes:

  1. Registration enables access: The implementing act of Regulation (EU) 2025/848, adopted under the revised eIDAS framework being applied by 24 December 2026, defines the requirements for the registration of EUDI Wallet relying parties. A relying party registers where it is established, records its intended EUDI Wallet use and defines the data it plans to request. This allows then to obtain the required technical certificates for wallet access.
  2. Trust status changes over time: New participants will appear and registrations / certificates can be updated, suspended, or revoked. Registers of certified-wallet- and PID-providers, credential issuers, and qualified trust service providers are maintained per member state and aggregated at EU level in List of Trusted Lists (LoTL). Monitoring must continue after go-live.

The impact

Connecting to this ecosystem affects governance and architecture. Two areas deserve early attention:

  • Customer use case implementation
    • KYC/KYB Onboarding: Customers instantly verify their identity by scanning their EUDI Wallet, eliminating document uploads and video calls.
    • Strong Customer Authentication (SCA): A verified wallet identity enables secure authentication across mobile, internet, and open banking, supporting an SCA-compliant authentication journey.
    • Payment Authorisation: Customers review and sign the exact payment details in their wallet before approval, supporting PSD2 dynamic linking and full transaction transparency.
  • Data governance: Requesting additional attributes from the wallet in a customer journey may require a registration update.
  • Cross-border trust operations: Ensuring interoperability by accepting foreign wallets relies on a deep integration into the EU trust infrastructure.

Banks should map their legal entities, intended use, and requested attributes now, then decide whether a shared integration layer should handle wallet protocols, certificates, trust data and relying-party workflows.

Next steps?

Before the 2027 acceptance deadline, banks and PSPs should have answers for the following questions:

  • Who must register, where and for which use?
  • Which attributes and issuers meet each use case?
  • Whether an intermediary like Banfico sits in the path?

The same infrastructure can support multiple roles. A bank may also issue financial attestations, such as proof of account ownership or regular income, under the relevant trust model. It may also seek to provide a certified EUDI wallet itself. Both choices require separate legal, certification and operating-model work.

Prepare for the EUDI Wallet ecosystem: Schedule a free gap analysis with Banfico experts

Preparation starts with a clear map of legal entities, customer journeys, intended use, requested attributes, and trust sources. That map shows where registration, integration and ongoing monitoring are required.

Schedule a session using the button below.

Schedule now