English
English

Blogpost // Financial Services

EUDI-Wallet

Blogpost // Financial Services

EUDI-Wallet

Regulatory Pressure and Strategic Opportunities for Banks

Download PDF

Our 3 Key Take-away's

After a long ramp-up phase, momentum around the EUDI Wallet is gaining steam - the regulator is already requiring banks to accept the EUDI Wallet as an equivalent means of authentication by December 24, 2027.

Since no distinction is made based on use cases and 3-D Secure, for example, is also affected, the MFA architecture of most banks will likely require extensive adjustments

The EUDI Wallet should be viewed not only as a regulatory requirement, but also as an enabler for new use cases -such as more efficient processes, improved user experience, or risk reduction through digital employee IDs, for example.

1 Background

With the adoption of the Europe-wide regulation establishing the European Digital Identity Wallet (EUDI Wallet), the European Union has created a key building block for a unified digital identity. This is based on the reform of the eIDAS Regulation (EU) No. 910/2014, the revision of which (“eIDAS 2.0”) was politically finalized in 2024. The goal is to provide all EU citizens with an interoperable digital identity solution that can be used for both public and private services by 2026 at latest. Implementation is taking place in stages: Following the political agreement in 2024, technical standardization will be carried out through the European Digital Identity Toolbox, while member states simultaneously adopt national implementation laws. In Germany, this was implemented through amendments to the “Vertrauensdienstegesetz” (VDG) and accompanying provisions in the “Onlinezugangsgesetz“ (OZG), while Austria made corresponding additions to the “E-Government Gesetz” (E-GovG). Member states are required to make the wallet available by 2026, followed by mandatory acceptance by regulated private providers. Since January 2026, for example, a corresponding sandbox has also been available in Germany, allowing third parties to technically implement and test EUDI wallet use cases.

Fig. 1: Timeline of the EUDI wallet

This results in a specific obligation for banks: According to Articles 6a and 12b of the revised eIDAS Regulation, so-called “relying parties” - which explicitly include regulated financial institutions - are required to accept the EUDI wallet as a means of authentication and identification if users wish to use it. This obligation takes effect on December 24, 2027. In addition, Article 11 requires Member States to ensure that private service providers with a high level of trust can technically integrate this means of identification and actually accept it. For banks, this effectively places the EUDI wallet on an equal footing with existing and strong customer authentication procedures.

Fig. 2: Example User Journey

The consequences of not being compliant are significant. Article 24c of the eIDAS Regulation stipulates that Member States must implement effective, proportionate, and dissuasive sanctions. These are structurally modeled after other EU digital regulations, such as the General Data Protection Regulation (GDPR), and may include substantial fines. National supervisory authorities - such as BaFin in Germany or the FMA in Austria - will be authorized to penalize violations. In addition to financial penalties, regulatory measures such as restrictions on business operations or reputational damage may also be imposed. Given the increasing integration with other regulations in the payments sector, it is also reasonable to assume that violations may have indirect implications for licensing requirements and capital requirements.

2 Complication

Despite the seemingly clear regulatory requirements, the specific details of implementation remain highly complex. The law deliberately limits itself to mandating the acceptance of the EUDI wallet without defining specific use cases. This leaves considerable room for interpretation within financial institutions. While current discussions in industry working groups primarily focus on obvious use cases such as customer onboarding, logging into online banking, or authorizing transfers, this perspective falls short. In reality, a wide variety of other authentication scenarios exist within banks. These include, among others, card payments in online retail, the authorization of securities transactions in brokerage, and identity verification in customer service. These processes have evolved over time and are often implemented as technically decoupled systems. Although user interaction in the front end often appears similar, the back-end systems differ significantly. Factors such as multi-tenancy, varying account holder structures, and -specific logging and audit requirements further increase the complexity. A particularly striking example is the 3-D Secure procedure for card payments. Here, strong customer authentication is typically not initiated directly by the bank, but rather via a so-called Access Control Server (ACS), which is often operated outside the bank’s actual IT infrastructure. Integrating the EUDI wallet into this process would require not only adjustments on the part of the banks but also changes to the 3-D Secure protocol itself. However, this protocol is standardized by EMVCo , an international consortium over which individual banks have no direct influence. In addition, the customer journey on the merchant side would also need to be adapted. This results in a dependence on external parties, which puts further pressure on the already ambitious timeline. Overall, this means that adjustments cannot be made in isolation within individual systems but must be orchestrated across domain boundaries. At the same time, the regulatory interpretation has not yet been conclusively clarified, and some technical standards are still under development. However, waiting for final specifications would significantly shorten the time remaining until mandatory implementation and increase the risk of a delayed or incomplete implementation.

3 Solution Approach and Call-to-action

Against this backdrop, a structured and cross-organizational approach is absolutely essential. The implementation of the EUDI Wallet should not be viewed as an isolated IT or security project. A fragmented implementation carries the risk of inconsistencies, redundant solutions, or critical gaps in the coverage of individual use cases. Instead, it is recommended to establish a central task force that brings together representatives from all relevant areas - IT, business units, compliance, payment processing, and sales. The goal of this task force should be to first conduct a comprehensive business analysis of all authentication use cases and systematically translate these into technical requirements. On this basis, dependencies and potential synergies can be identified early on, enabling prioritized and efficient implementation planning. The actual implementation can then take place decentrally within the respective organizational units, such as in existing tribes or domain structures. However, central coordination is crucial, particularly with regard to end-to-end testing, regulatory alignment, and consistent user experiences. Without such coordination, there is a risk that different solutions will emerge in parallel that are not interoperable or only partially meet regulatory requirements. Banks should also assess the extent to which they can still contribute to the specific design and interpretation of the law. For example, they could participate in relevant working groups regarding the adaptation of the 3-D Secure protocol. In parallel with regulatory implementation, banks should evaluate the strategic potential of the EUDI wallet. The wallet not only offers a new form of authentication but also enables innovative use cases in the field of digital identities. A concrete example would be a digital employee ID card that provides customers with a verifiable identity of bank employees: The draft Payment Services Regulation (PSR) under PSD3 explicitly states that payment service providers will be held more accountable if fraud occurs through the misuse of their identity. In essence, this means that payment service providers can be held liable if they have not implemented adequate measures to prevent “impersonation fraud” (see draft PSR, Article 59 on liability for unauthorized transactions and cases of fraud). To minimize such risks for banks, a bank employee could digitally verify their identity - regardless of the communication channel - using an ID based on the EUDI wallet. The customer could verify this ID using a feature that could be integrated into, for example, a mobile banking app. Banks, in turn, could require customers in their terms and conditions to use this feature when interacting with employees in remote banking transactions; failure to comply would result in a corresponding shift in liability, thereby reducing the bank’s exposure to risk. Against this backdrop, the EUDI wallet should not be viewed solely as a regulatory burden. Rather, it opens up the opportunity to modernize security architecture while simultaneously improving the user experience. Banks that invest early in a strategically aligned implementation can not only minimize regulatory risks but also secure competitive advantages.

4 Conclusion

The introduction of the EUDI wallet marks a profound shift in Europe’s digital identity landscape. For banks, this means a mandatory transformation of existing authentication processes under considerable time pressure. The complexity of implementation is often underestimated, particularly due to the multitude of affected use cases and the reliance on external standards. A proactive, coordinated approach is therefore crucial. Banks should use the time remaining to initiate a structured implementation while simultaneously tapping into strategic opportunities. The EUDI wallet is not only a regulatory requirement but also a catalyst for innovation in security and customer experience.


Sources

European Commission. “Regulation (EU) No 910/2014 (eIDAS) and its revision (eIDAS 2.0).” European Commission. 2024. https://digital-strategy.ec.europa.eu/en/policies/eidas-Regulation

European Commission. “European Digital Identity Framework (EUDI Wallet).” European Commission. 2024. https://digital-strategy.ec.europa.eu/en /policies/european-digital-identity

Proposal for a Regulation on payment services in the internal market (PSR). European Commission. 2023. https://finance.ec.europa.eu/publications/proposal-regulation-payment-services_en

BaFin. “Aufsicht über Zahlungsdienste und regulatorische Anforderungen.” Bundesanstalt für Finanzdienstleistungsaufsicht. https://www.bafin.de

FMA Austria. “Regulatory framework for digital identity and payment services.” Finanzmarktaufsicht Österreich. https://www.fma.gv.at

About the author(s)

3d avatar

Advisor

Dominik Siebert

+10 years of in-depth consulting experience in the financial industry in complex transformation projects, from strategic conceptualisation to implementation management. Special focus on digital payment solutions.

3d avatar

Managing Partner

Fabian Meyer

Over 15 years of experience in top management consulting for IT strategies, payments and technical implementation, with a particular focus on the financial services industry.

3d avatar

3d avatar

Managing Partner

Fabian Meyer

Over 15 years of experience in top management consulting for IT strategies, payments and technical implementation, with a particular focus on the financial services industry.

Meet Amaranth

Is increasing tech complexity a challenge?

Let's discuss how we can help your organization navigate complexity and achieve lasting success.

Meet Amaranth

Is increasing tech complexity a challenge?

Let's discuss how we can help your organization navigate complexity and achieve lasting success.

Meet Amaranth

Is increasing tech complexity a challenge?

Let's discuss how we can help your organization navigate complexity and achieve lasting success.