[codicts-css-switcher id=”346″]

Global Law Experts Logo
kyc onboarding israel

KYC & Onboarding in Israel (2026): Practical Guide for Fintechs, Psps & Banks

By Global Law Experts
– posted 2 hours ago

Last updated: September 2026

Who this guide is for: This guide explains the legal requirements, supervisory expectations and practical implementation steps for compliant KYC and onboarding in Israel in 2026, aimed at compliance managers, in‑house counsel and fintech/PSP operations teams.

KYC onboarding Israel is entering a decisive phase in 2026, as supervisors sharpen their emphasis on risk‑based due diligence, electronic identity verification and end‑to‑end automation. For banks, payment service providers (PSPs) and fintechs operating in the Israeli market, the practical challenge is no longer whether to digitise Know Your Customer (KYC) processes, but how to do so while satisfying the Prohibition on Money Laundering Law and evolving supervisory expectations. This article distils two decades of hands‑on banking‑compliance experience into a working playbook: statutory framework, risk‑based matrices, customer due diligence (CDD) steps, eKYC method comparison, automation patterns, onboarding checklists and refresh schedules. Read it as an operational manual rather than an abstract legal survey.

Why 2026 is a pivotal year for KYC in Israel

TL;DR: Israeli supervisors continue to emphasise a risk‑based approach, broaden acceptance of electronic KYC (eKYC) and encourage automation across banks, PSPs and fintechs. The direction of travel mirrors international standards set by the Financial Action Task Force (FATF), whose guidance on digital identity and the risk‑based approach (RBA) increasingly frames how Israeli obligations are interpreted in practice.

Several forces converge in 2026. First, the maturation of the fintech and payments sector has produced a wave of digitally native firms that cannot rely on branch‑based, face‑to‑face onboarding. Second, Israeli supervisors expect a proportionate, risk‑sensitive model, meaning resources should concentrate where money‑laundering and terrorist‑financing risk is highest. Third, RegTech tooling has matured to the point where sanctions screening, adverse‑media checks and identity verification can be orchestrated through APIs in seconds. For compliance leaders, the message is clear: a well‑designed KYC onboarding Israel programme is now a competitive differentiator as much as a legal obligation.

Core KYC and legal framework in Israel: statutes and regulators

Any KYC onboarding Israel programme must be built on the correct statutory foundations. The cornerstone is the Prohibition on Money Laundering Law, 5760‑2000, together with the orders and regulations issued under it for specific categories of financial institution. These instruments establish the core obligations: to identify and verify customers, to conduct ongoing due diligence, to retain records, and to report suspicious activity. The Prohibition on Terrorist Financing Law, 5765‑2005, complements this framework on the counter‑terrorist‑financing side.

Key statutes and regulator expectations

The legal and supervisory architecture involves several bodies, each with a defined remit:

  • Bank of Israel, Banking Supervision Department. As the supervisor of banks, the Banking Supervision Department issues the directives and supervisory expectations that shape how banks implement AML/CTF (anti‑money‑laundering / counter‑terrorist‑financing) controls, including KYC and CDD.
  • Capital Market, Insurance and Savings Authority. This authority supervises a range of non‑bank financial service providers, including certain payment and financial‑services providers licensed under the Supervision of Financial Services (Regulated Financial Services) Law, and its rules affect their onboarding and monitoring standards. Firms should confirm the current licensing and supervisory allocation applicable to their activity, as the framework governing payment and financial‑asset service providers has continued to evolve.
  • Israel Securities Authority (ISA). Where capital‑market intermediaries fall within ISA supervision, its rules affect onboarding standards and ongoing monitoring for those regulated populations.
  • Israel Money Laundering and Terror Financing Prohibition Authority (IMPA). IMPA is the country’s financial intelligence unit, receiving and analysing reports filed under the Prohibition on Money Laundering Law.
  • The Prohibition on Money Laundering Law framework. This is the primary statutory source of CDD, recordkeeping and reporting obligations, supplemented by sector‑specific orders.

Because Israeli obligations are frequently interpreted against international benchmarks, FATF standards on the risk‑based approach and digital identity are essential reading. They provide the analytical vocabulary, customer risk, product risk, channel risk, geographic risk, that supervisors expect firms to apply.

Who must comply: banks, PSPs, fintechs and financial‑service providers

The obligation to perform KYC and CDD extends across the regulated financial ecosystem. Banks sit at the most heavily supervised end. Payment service providers and financial‑service providers are squarely within scope, as are fintechs offering regulated payment, lending or credit services. Providers dealing in crypto and other financial assets are also treated as supervised entities where their activity falls within the regulatory perimeter and licensing requirements. The practical consequence is that any firm onboarding customers into a financial relationship in Israel should assume it carries CDD, monitoring, recordkeeping and reporting duties, and should confirm its exact supervisory home and licensing status before launch.

Effective customer due diligence in Israel begins with correctly identifying which regulator governs your activity, because that determines the precise standard you must meet.

Risk‑based KYC in Israel: building a practical matrix for fintechs and PSPs

A risk‑based KYC Israel programme allocates due‑diligence intensity according to the money‑laundering and terrorist‑financing risk each customer presents. Rather than treating every applicant identically, the firm scores risk, sets thresholds, and applies simplified, standard or enhanced measures accordingly. This is both a regulatory expectation and an operational necessity: it lets low‑risk customers onboard with minimal friction while concentrating scrutiny where it matters.

Risk factors and scoring

A robust matrix evaluates at least four dimensions:

  • Customer risk. Nature of the customer (individual vs. corporate), politically exposed person (PEP) status, adverse media, complexity of ownership, and prior conduct.
  • Product and service risk. Some products, cross‑border transfers, high‑value payments, anonymous‑style instruments, carry inherently greater risk than others.
  • Channel risk. Non‑face‑to‑face and fully digital onboarding raises impersonation and synthetic‑identity risk, requiring stronger verification controls.
  • Geographic risk. Exposure to higher‑risk jurisdictions, sanctions nexus, or counterparties in territories with weak AML regimes.

Each factor is scored and weighted to produce an overall tier. The example below illustrates a simplified matrix a PSP might adopt:

Risk tier Illustrative profile Due‑diligence level Approval authority
Low Domestic individual, low‑value wallet, verified government ID, no adverse flags Simplified / standard CDD Automated / analyst
Medium Domestic SME, moderate transaction volumes, straightforward ownership Standard CDD + periodic review Senior analyst
High PEP nexus, complex cross‑border structure, higher‑risk geography, or high transaction values Enhanced due diligence (EDD) MLRO / compliance committee

Governance and documentation

A risk matrix is only defensible if it is governed. Document the methodology, the weightings, and the rationale for each threshold. Assign clear ownership, typically the Money Laundering Reporting Officer (MLRO) or head of compliance, and require periodic model review. Every EDD trigger, every override of an automated decision, and every high‑risk approval should leave an audit trail. Supervisors will expect to see that the matrix is not static: it must be recalibrated as new typologies, sanctions developments and product changes emerge. For fintech KYC Israel programmes in particular, the ability to demonstrate disciplined model governance is often the difference between a smooth supervisory review and a remediation order.

Customer due diligence steps: individuals and corporates (UBO)

Customer due diligence in Israel splits into two broad tracks, individuals and corporates, with distinct evidence requirements and verification methods. Both tracks must incorporate sanctions and PEP screening at onboarding and on an ongoing basis.

Individual onboarding checklist

For a natural person, the standard onboarding sequence is:

  1. Collect identity data. Full name, date of birth, national identity or passport number, and residential address.
  2. Verify identity. Confirm the identity document is genuine and belongs to the applicant, using document authentication and, for digital channels, biometric or liveness checks.
  3. Screen against sanctions and PEP lists. Run the verified identity against applicable sanctions lists, PEP databases and adverse‑media sources.
  4. Assess purpose and nature of the relationship. Understand why the account is being opened and the expected activity profile.
  5. Assign a risk tier. Feed the collected data into the risk matrix to determine simplified, standard or enhanced measures.

Corporate onboarding and UBO steps

Corporate KYC is materially more demanding because the firm must look through the legal entity to the humans who ultimately own or control it, the ultimate beneficial owners (UBOs). A defensible corporate onboarding process runs as follows:

  1. Verify the legal entity. Obtain the certificate of incorporation, current registry extract, articles of association and evidence of good standing.
  2. Map the ownership chain. Trace ownership and control through each layer of the structure until natural persons are identified, documenting each intermediate entity.
  3. Identify the UBOs. Establish which individuals hold ownership or control above the applicable threshold set out in the relevant order, and verify their identities to the same standard as individual customers.
  4. Verify authorised signatories. Confirm the identity and authority of the individuals acting on behalf of the entity.
  5. Screen the entity and all UBOs. Apply sanctions, PEP and adverse‑media screening to the corporate, its directors, signatories and beneficial owners.
  6. Corroborate with independent sources. Use third‑party corporate registries and reliable data providers to cross‑check declared ownership against public records.

Where the ownership chain is opaque, involves nominee arrangements, or spans higher‑risk jurisdictions, the corporate should be escalated to enhanced due diligence. UBO verification is one of the most heavily scrutinised elements of any KYC onboarding Israel review, and gaps here are a common finding in enforcement.

KYC for mobile‑first customers

Neo‑banks and payment apps onboard customers who will never visit a branch. For these mobile‑first flows, the verification burden shifts to technology: document capture with optical character recognition (OCR), liveness detection to defeat spoofing, and device and behavioural signals to detect fraud. The compliance objective remains identical, reliable identification and verification, but the controls must compensate for the absence of physical interaction. This is where eKYC becomes central rather than optional.

eKYC in Israel: methods, reliability and supervisory expectations

eKYC Israel adoption has accelerated as supervisors, influenced by FATF digital‑identity guidance, increasingly accept that remote verification can be as reliable as traditional face‑to‑face checks when properly implemented. The key is that the eKYC method must be appropriate to the risk, resistant to fraud, and supported by an audit trail. Firms should not treat eKYC as a single technology but as a stack of complementary controls, and should confirm the current position of their supervisor on remote onboarding for their category.

When eKYC is appropriate

eKYC is well suited to standard and lower‑risk individual onboarding at scale. For higher‑risk customers, cross‑border applicants, or complex corporate structures, firms typically layer additional controls or fall back to manual review. Supervisory expectation is that the firm can justify, in writing, why the chosen eKYC method is adequate for the risk tier it serves.

Comparison of eKYC methods

The table below compares the principal eKYC methods used in the Israeli market so teams can match method to use case:

Method Typical accuracy / fraud resilience User friction Compliance pros / cons Typical use case
Government ID API / registry check Very high, authoritative source data Low Strong evidentiary value; availability and access constraints may apply Domestic individual onboarding at scale
ID document OCR + database verification High when combined with database cross‑check Low–medium Fast and scalable; vulnerable to sophisticated forgeries if used alone Digital individual and SME onboarding
Liveness + biometric High, defeats photo and replay attacks Medium Strong anti‑impersonation; raises privacy and consent considerations Mobile‑first neo‑bank and wallet onboarding
Database and PEP / sanctions screening High for screening; not identity proof alone Low (background) Essential AML control; must be paired with identity verification All customers, at onboarding and ongoing
Video‑KYC with manual review Very high, human adjudication High Strong for complex/high‑risk cases; costly and slow at scale High‑risk individuals, complex corporates, EDD

eKYC anti‑fraud controls

Whatever method is chosen, layer defences against synthetic identity and impersonation fraud: liveness detection, document authentication (checking security features, not just readability), device fingerprinting, and cross‑referencing against previously seen data. Retain the artefacts, captured images, verification results, timestamps, as part of the KYC file so the decision can be reconstructed during audit. For any KYC onboarding Israel implementation, the anti‑fraud layer is frequently where the real supervisory scrutiny lands, because it demonstrates whether the eKYC control is genuinely reliable or merely convenient.

KYC automation and RegTech integration patterns

KYC automation transforms onboarding from a manual, error‑prone process into a governed, auditable workflow. The goal is not to remove human judgement but to reserve it for the cases that genuinely require it, while systems handle collection, verification, screening and record‑keeping.

Automation architecture options

A mature architecture typically centres on an orchestration layer that coordinates multiple specialist services:

  • Identity verification service. Document OCR, liveness and database checks return a verification result.
  • Screening service. API‑based sanctions, PEP and adverse‑media screening runs at onboarding and continuously thereafter.
  • Risk‑scoring engine. The orchestration layer feeds verified data into the risk matrix and assigns a tier.
  • Case‑management and workflow. Anything that fails automated checks or scores high risk is routed to a compliance analyst or the MLRO for review.
  • Audit and data‑retention store. Every decision, artefact and screening result is retained with reliable timestamps to satisfy recordkeeping obligations.

The typical data flow runs: applicant submits data → identity verified → screening executed → risk scored → auto‑approve, auto‑refer, or auto‑decline → record written to the audit store. High‑risk or failed cases branch to manual review with an SLA (service‑level agreement) attached. This pattern keeps low‑risk onboarding near‑instant while ensuring nothing bypasses the required controls.

Vendor checklist and contracts

Selecting eKYC and screening vendors is a legal exercise as much as a technical one. Assess candidates against both dimensions:

  • Coverage and data quality. Does the vendor cover the identity documents, sanctions lists and PEP data relevant to your customer base?
  • Accuracy and fraud resilience. Request performance metrics and evidence of anti‑spoofing controls.
  • Integration and orchestration fit. API quality, latency, and the ability to sit within your orchestration layer.
  • Data protection and residency. How and where personal data is processed and stored, and what contractual safeguards apply under the Protection of Privacy Law and its regulations.
  • Audit and evidence. Can the vendor supply the artefacts and logs you need to reconstruct a decision for a supervisor?
  • Contractual allocation of liability. Clear terms on accuracy, service levels, breach notification and sub‑processor use.

Because outsourcing verification does not outsource responsibility, the firm remains accountable for the compliance outcome. Contracts should reflect that reality with robust audit rights and clear obligations.

Onboarding checklist and sample workflows: bank, PSP, neo‑bank

Different institution types calibrate onboarding differently. The controls are the same; the intensity and automation level differ.

The onboarding checklist

  • Identify the customer and collect required data fields.
  • Verify identity using method appropriate to the risk tier.
  • Screen against sanctions, PEP and adverse‑media sources.
  • Establish beneficial ownership for corporates and verify UBOs.
  • Assess and record the risk tier using the risk matrix.
  • Apply EDD where triggered, with senior approval.
  • Document the decision and retain all artefacts.
  • Set the monitoring and refresh cadence for the relationship.

Workflow examples

  • Bank, high touch. Comprehensive documentary CDD, layered verification, senior sign‑off for higher‑risk relationships, and structured periodic review. Manual review triggers are conservative.
  • PSP, medium. Largely automated onboarding for standard customers, with a case‑management queue for referrals. Screening runs continuously; medium‑risk customers face periodic re‑verification.
  • Neo‑bank, digital, low friction with enhanced monitoring. Fully digital eKYC with liveness and document checks, near‑instant approval for low‑risk applicants, and compensating enhanced transaction monitoring to catch risk that a light‑touch onboarding might miss.

In every model, define explicit manual‑review triggers, screening hits, verification failures, high‑risk scores, and attach an SLA so referrals are cleared promptly rather than becoming a backlog. A clean, well‑documented onboarding checklist is the operational heart of any KYC onboarding Israel programme.

CDD refresh schedules, monitoring and EDD triggers

KYC is not a one‑off event. Ongoing due diligence, periodic refresh plus continuous monitoring, keeps the customer picture current and detects changes that alter risk. The AML CDD Israel obligations extend across the entire life of the relationship, not merely its start.

Examples of triggers and refresh cadence

Firms typically calibrate refresh frequency to risk tier. A common policy standard applies periodic refresh for lower‑risk customers, more frequent review for medium‑risk, and ongoing or annual review for high‑risk relationships:

Risk tier Illustrative refresh cadence Monitoring intensity
Low Periodic (longest interval) Baseline automated monitoring
Medium Shorter periodic interval Enhanced automated monitoring
High Ongoing / annual review Close, often manual, monitoring

Regardless of scheduled cadence, event‑driven triggers should force an immediate review. Typical EDD triggers include:

  • A new PEP or sanctions match, or a change in a customer’s status.
  • Transaction behaviour inconsistent with the expected profile.
  • A sanctions list update that touches an existing customer or counterparty.
  • Adverse media or a material change in beneficial ownership.
  • Suspicious activity identified through monitoring.

Suspicious‑activity reporting basics

Where monitoring or review surfaces suspicion of money laundering or terrorist financing, the firm must file the reports required under the Prohibition on Money Laundering Law and the applicable order to the Israel Money Laundering and Terror Financing Prohibition Authority (IMPA). Israeli reporting duties include both mandatory reports (for example, certain thresholds and unusual activity) and irregular‑activity reports based on suspicion; firms should confirm the categories applicable to their supervised sector. Timeliness matters, and firms should have a defined internal escalation path from analyst to MLRO to filing. Recordkeeping obligations require that KYC files and supporting evidence be retained for the statutory period so they remain available for supervisory review and investigation.

Practical compliance and programme governance tips

Technology and process are necessary but not sufficient. A defensible KYC onboarding Israel programme also depends on governance, people and evidence.

Training and escalation

Front‑line and compliance staff must understand the risk matrix, the red flags and the escalation path. Regular, role‑specific training keeps the programme effective as typologies evolve. Escalation routes should be unambiguous: analysts know when to refer, referrals reach the MLRO promptly, and high‑risk decisions carry senior accountability. Where lawyers are involved in reviewing onboarding or advising on complex cases, the professional conduct standards of the Israel Bar Association apply to that involvement.

KPIs to report to the board

Boards and senior management should see meaningful compliance metrics, not just volumes. Useful indicators include onboarding pass and referral rates, average time‑to‑decision, screening alert volumes and false‑positive rates, EDD case counts, refresh backlog, and reporting statistics. These KPIs demonstrate that the programme is functioning, help identify bottlenecks, and provide the evidence supervisors expect when they ask whether the board genuinely oversees AML risk. Maintain audit‑readiness continuously: documented policies, retained artefacts, and a clear record of decisions turn a supervisory visit from a crisis into a routine confirmation that controls work.

Conclusion and recommended next steps

Getting KYC onboarding Israel right in 2026 means aligning legal obligations under the Prohibition on Money Laundering Law with a genuinely risk‑based, technology‑enabled operating model. Start by confirming your supervisory home and documenting your statutory obligations. Build and govern a risk matrix. Define separate individual and corporate CDD flows with rigorous UBO discovery. Select eKYC and screening vendors against both technical and legal criteria, and orchestrate them through an automation layer with a full audit trail. Then set refresh cadences and event‑driven EDD triggers, and prove the whole system with board‑level KPIs. A practical pilot, one customer segment, one automated flow, one governed decision log, is the fastest route to a scalable, defensible programme.

For tailored advisory or a compliance review of your KYC onboarding Israel implementation, readers can consult a qualified Israeli compliance practitioner. Firms wishing to explore support can review the Compliance Lawyer, Israel and In‑House Compliance Officer, Israel resources, or the author’s GLE profile.

This article is for general information only and does not constitute legal advice. Firms should consult qualified counsel for advice on their specific circumstances.

Compliance Officer Reviewing Kyc Onboarding Checklist For Israel Fintech

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Idan Levy at MITIGATE Compliance & Risk Management, a member of the Global Law Experts network.

Sources

  1. Bank of Israel
  2. Knesset
  3. Israel Securities Authority (ISA)
  4. Israel Money Laundering and Terror Financing Prohibition Authority (IMPA)
  5. Financial Action Task Force (FATF)
  6. Israel Bar Association

FAQs

What are the minimum KYC documents required for individual customers in Israel?
At minimum, firms collect and verify the customer’s full name, date of birth, national identity or passport number and address, supported by a valid government‑issued identity document. Verification must confirm both that the document is genuine and that it belongs to the applicant, and the customer must be screened against sanctions and PEP lists. The precise required particulars are set out in the order applicable to the firm’s supervised sector.
Firms verify the legal entity, then trace the ownership and control chain through each layer until natural persons are identified. Those ultimate beneficial owners are verified and screened against sanctions, PEP and adverse‑media sources, with declared ownership corroborated against independent corporate registries. The applicable ownership/control threshold is set out in the relevant order under the Prohibition on Money Laundering Law.
eKYC is increasingly accepted for standard and lower‑risk onboarding, consistent with FATF digital‑identity guidance, provided the method is reliable, fraud‑resistant and auditable and is permitted for the firm’s supervised category. For higher‑risk customers, cross‑border applicants or complex corporates, firms typically layer additional controls or fall back to manual review, and must be able to justify why the chosen method suits the risk. Firms should confirm their supervisor’s current position on remote onboarding.
Common EDD triggers include a PEP or sanctions match, transaction behaviour inconsistent with the expected profile, a relevant sanctions list update, adverse media, a material change in beneficial ownership, or suspicious activity detected through monitoring. High‑risk tiers assigned by the risk matrix also require EDD with senior approval.
Refresh cadence is calibrated to risk. A common policy standard applies the longest periodic interval to low‑risk customers, a shorter interval to medium‑risk, and ongoing or annual review to high‑risk relationships. Event‑driven triggers override the schedule and force immediate review whenever risk materially changes.
KYC files, verification artefacts and supporting evidence must be retained for the statutory period specified in the order applicable to the firm’s sector, so they remain available for supervisory review and investigation. Firms should confirm the exact retention period applicable to their supervised category and ensure records are stored in a retrievable, auditable form.
Where a firm forms a suspicion of money laundering or terrorist financing, or where a mandatory reporting threshold is met, it must file the applicable report to the Israel Money Laundering and Terror Financing Prohibition Authority (IMPA) in line with the relevant order. Firms should maintain a clear internal escalation path from analyst to MLRO to timely filing.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

KYC & Onboarding in Israel (2026): Practical Guide for Fintechs, Psps & Banks

Send welcome message

Custom Message