Autor: Bluem Team

  • Green Mandate erweitert unseren eMandate-Service auf das gesamte SEPA-Gebiet.

    Green Mandate erweitert unseren eMandate-Service auf das gesamte SEPA-Gebiet.

    A digital mandate flow should not stop at the bank selection page

    A digital direct debit journey can run smoothly until the moment a customer selects a bank outside standard eMandate coverage. That is where friction starts. A process that should stay digital suddenly needs a fallback. More explanation, more handling, less consistency. From May 1, Green Mandate is automatically included in our eMandate service to solve exactly that issue.

    What Green Mandate is

    Green Mandate is the additional digital mandate flow within our eMandate service for customers whose bank is not part of the standard eMandate bank selection. In practice, the customer chooses Other bank on the bank selection page and continues through the Green Mandate flow. This makes it possible to complete a digital, legally valid SEPA Direct Debit CORE mandate within the same service. Green Mandate is therefore not a separate product and it does not replace eMandate. It extends the existing eMandate service for CORE mandates where the standard bank-supported route ends.

    Why it is needed

    Our eMandate service already offers a strong digital route for SEPA Direct Debit authorization. The issue is not the service itself, but the fact that support among Dutch banks remains limited. That matters more now than it did before. More customers bank with neobanks or foreign banks, and more merchants serve customers across borders. At the same time, there is no broadly available pan-European equivalent that offers one consistent eMandate flow across the full SEPA area. The result is simple: merchants can offer a smooth digital mandate journey to some customers, but not always to all of them.

    What changes on May 1

    The practical change is straightforward. On the bank selection page, an extra option appears: Other bank. Customers outside the standard eMandate bank set can select it and continue through the Green Mandate flow. For merchants already using our eMandate service, the core setup stays familiar. The service works the same way, but now reaches more customers. That is what makes this launch valuable. It removes a real limitation without introducing a separate service model.

    What this means for merchants

    Green Mandate helps make digital mandate handling more consistent. Instead of one customer staying in a clean digital flow while another falls into an exception process, more customers can now follow the same digital route. That reduces friction at the point of authorization and helps create a smoother journey from onboarding to collection. In practice, that means:

    • fewer fallback situations
    • less operational variation
    • a more consistent customer experience
    • better scalability for direct debit

    Built for how merchants work today

    Customer journeys are no longer limited to a small domestic bank landscape. Businesses grow across borders, customers bank more widely, and digital onboarding is expected to work without interruption. Green Mandate responds to that reality. It builds on the strength of the eMandate service already in place and extends it in a practical way for today’s market.

    Live from May 1

    From May 1, Green Mandate is automatically included in our eMandate service for CORE mandates. That means more customers across the SEPA area can complete a digital, legally valid CORE mandate within one trusted service, even when they bank outside the standard Dutch eMandate set.

  • Die Richtlinien der KSA werden strenger: Können Sie Ihre Sorgfaltspflicht nachweisen?

    Die Richtlinien der KSA werden strenger: Können Sie Ihre Sorgfaltspflicht nachweisen?

    Why this matters now

    The Dutch Gambling Authority, the Kansspelautoriteit, recently published additional guidance on how online gambling licence holders should carry out their duty of care. The documents focus on two difficult areas in practice: personal interviews with players and notifications related to possible registration in Cruks, the Dutch gambling exclusion register.

    That may sound procedural. In practice, it raises a much sharper question for operators:

    If a player shows signs of risk, can you prove that your organisation responded properly?

    Not in general terms. Not with a policy PDF. But with a clear record of what happened, what information was used, what decision was made and why that decision was reasonable at the time.

    That is where many organisations feel the pressure.

    The hard part is not writing the policy

    Most regulated operators already have duty-of-care policies. They know when a player should be contacted. They know when internal escalation may be needed. They know Cruks exists. They know vulnerable players require additional attention.

    The harder part is execution.

    A player hits a behavioural trigger. A customer support agent sees worrying signals. A responsible gaming team needs to decide whether a personal interview is required. A player may be advised to self-exclude. In some cases, the operator may need to assess whether a Cruks notification is appropriate.

    These are not abstract compliance moments. They happen inside real customer journeys, often under time pressure, across different systems and teams.

    The risk is that the decision-making trail becomes scattered. One note in a CRM. One email from support. One affordability check in a separate flow. One compliance decision in a spreadsheet. Six months later, reconstructing the case becomes difficult.

    And if the regulator asks what happened, “we followed our policy” is rarely the strongest answer.

    From intervention to evidence

    The recent KSA guidance does not just remind operators that interventions matter. It also shows that consistency matters.

    • If two similar cases are handled differently, can the operator explain why?
    • If a player was allowed to continue, what evidence supported that decision?
    • If a personal interview was conducted, what was concluded?
    • If a Cruks-related notification was not made, why not?

    These questions are uncomfortable because they sit between compliance, operations and product design. They are not solved by one department.

    A useful duty-of-care process needs at least four things:

    1. Clear triggers: The organisation needs to know which signals require attention. These may include age, deposit behaviour, losses, failed payments, previous interventions or requests to increase limits.
    2. Reliable checks: When extra verification is needed, the operator needs data that is accurate enough to support a decision. That may include identity checks, exclusion checks, affordability checks or source-of-funds information.
    3. A documented decision: The outcome needs to be recorded in a way that can be reviewed later. Not just the result, but the reason behind it.
    4. A customer journey that still works: The process must protect the player without turning every interaction into a slow, confusing manual review.

    That last point is often underestimated. A process can be compliant on paper and still fail in practice if it creates too much friction, too much manual work or too many unclear handovers.

    Affordability checks should not mean asking for everything

    Financial capacity is one of the most sensitive parts of duty of care. Operators need enough information to assess whether continued play is responsible, especially when thresholds or risk triggers are reached. At the same time, customers should not be asked to expose more personal financial data than necessary.

    That is where proportionality becomes important.

    A good affordability process should answer a specific question: is there enough evidence to support the next decision? It should not become an open-ended request for every detail of someone’s financial life.

    Bluem’s BudgetCheck was built around that principle. It supports different types of income documents, including payslips, annual salary statements, bank statements and tax income statements. It also gives the customer a choice in which document to provide, rather than forcing one fixed route for every case.

    That matters because customers differ. A salaried employee may have a payslip. A freelancer may not. A tax income statement may provide a broader view, but some customers will need guidance to retrieve the right document. A one-size-fits-all process creates drop-off and operational exceptions.

    The goal should be simple: collect enough verified information to support a responsible decision, without making the process unnecessarily intrusive.

    The compliance file is becoming part of the product

    For online gambling operators, duty of care can no longer sit outside the customer journey. It has to be part of the product experience.

    • When a player reaches a threshold, the next step should be clear.
    • When additional information is required, the reason should be understandable.
    • When a decision is made, the organisation should be able to show the evidence.
    • When a regulator asks questions later, the case file should not need to be rebuilt manually.

    This is not only about avoiding enforcement risk. It is also about running a better operation. Clearer processes reduce internal uncertainty. Better evidence reduces back-and-forth between teams. A more structured flow helps support teams treat similar cases consistently.

    In other words: good duty-of-care execution is not just a legal safeguard. It is operational discipline.

    What operators should review now

    The KSA’s recent guidance is a useful moment to review how duty of care works in practice. Not in a workshop, but in actual customer cases.

    Start with a few recent examples:

    • A player who reached a deposit or loss threshold.
    • A player who received a responsible gaming intervention.
    • A player who requested a limit increase.
    • A case where Cruks was discussed.
    • A case where affordability evidence was requested.

    Then ask:

    • Can we see why the case was triggered?
    • Can we see which checks were performed?
    • Can we see who made the decision?
    • Can we see what the customer was told?
    • Can we defend the outcome if challenged?

    If those answers are spread across multiple systems or depend on one colleague’s memory, the process is vulnerable.

    Where Bluem fits

    Bluem helps regulated organisations turn checks into workable customer flows. For gambling operators, that can include identity verification, Cruks checks, affordability assessment, source-of-funds support and documented decision flows.

    The point is not to add more friction. The point is to make the right step happen at the right moment, with the evidence stored properly.

    Recent KSA guidance makes one thing clear: duty of care is not only about having the right intentions. Operators need to show their work.

    Want to know whether your duty-of-care process would hold up under review? Bluem can help you map the weak points and design a cleaner flow.

  • Die EUDI Wallet kommt. Sind Sie bereit für das, was vor ihrer Ankunft passiert?

    Die EUDI Wallet kommt. Sind Sie bereit für das, was vor ihrer Ankunft passiert?

    The wallet is moving from policy to implementation

    The European Digital Identity Wallet is no longer just a policy topic. At the eIDAS Summit in Berlin on 28 and 29 April 2026, public and private stakeholders met to discuss EUDI Wallet implementation, pilot lessons and the next steps before wider European rollout.

    For businesses, this matters because identity is not a back-office detail. It affects onboarding, fraud prevention, age checks, contract signing, account creation, customer recovery and access to regulated services.

    The wallet promises a cleaner future: citizens and businesses sharing verified identity data digitally, with more control and less repeated document handling.

    That future is attractive. But the transition will not be clean.

    Businesses will need to support old and new identity methods at the same time

    The arrival of the EUDI Wallet does not mean passports, ID cards, bank-based identification and local eID schemes suddenly disappear from onboarding flows.

    Some customers will adopt wallet-based identity quickly. Others will not. Some markets will move faster than others. Some use cases will need qualified credentials. Others will still rely on document scans, bank-based ID, address validation or electronic signatures.

    This is the practical problem for companies: they cannot design for one identity method and assume the market will follow.

    • A Dutch customer may expect iDIN.
    • A Belgian customer may use itsme.
    • A German customer may follow a different route.
    • A Nordic customer may be used to BankID.
    • An international customer may only have a passport or residence document.
    • A high-risk case may still require extra checks.

    That is what onboarding will look like for a while: not one elegant route, but several routes that need to work without confusing the customer.

    The real question is not “will the wallet matter?”

    It will.

    The better question is: can your onboarding process handle change without being rebuilt every time?

    Many organisations have identity flows that grew one exception at a time. A new country was added. Then a new document type. Then a bank-based ID method. Then eSigning. Then AML screening. Then a manual review queue.

    The result works, but only because teams know where the workarounds are.

    That kind of setup becomes fragile when the identity market changes.

    The EUDI Wallet adds another reason to clean this up. Not because every business needs to be wallet-first tomorrow, but because identity orchestration will become more important. Companies will need to route customers through the right method based on country, risk level, document availability, regulatory requirements and customer preference.

    If that routing is hardcoded, slow or heavily manual, onboarding will suffer.

    Good identity flows reduce uncertainty

    A good onboarding flow does not ask every customer to do the same thing. It asks for the right level of assurance for the situation.

    • A low-risk customer may need a simple identity confirmation.
    • A regulated financial product may require stronger KYC.
    • A gambling operator may need age verification and exclusion checks.
    • A lease or financing journey may require identity plus affordability evidence.
    • A contract flow may need an electronic signature that can be defended later.

    The point is not to collect more data by default. The point is to collect the right data, at the right moment, with a clear reason.

    That is where many onboarding flows go wrong. They ask too much too early, or they ask too little and create manual follow-up later. Both hurt conversion. Both create operational cost.

    The wallet may reduce friction, but not all friction

    The EUDI Wallet could remove some of today’s repeated identity work. If a customer can share verified credentials directly, businesses may need fewer document uploads and fewer manual checks.

    But the wallet will not remove every business rule. Companies will still need to decide which credentials are acceptable, how consent is captured, when additional verification is needed, how fraud signals are handled and how the process is documented.

    They will also need fallback routes. A customer without a wallet still needs to onboard. A cross-border customer may not have the expected credential. A document may still need to be verified. A signature may still be required.

    So the practical goal is not to replace the current onboarding flow with “the wallet”. The goal is to build an onboarding process that can use the wallet where it helps, and use other methods where it does not.

    What companies should review before the market shifts

    Businesses do not need to wait for full EUDI Wallet adoption before improving onboarding. In fact, waiting may make the transition harder.

    A useful review starts with five questions:

    1. Which identity methods do we support today? Include document scanning, bank-based ID, eID schemes, address validation and manual review.
    2. Where do customers drop off? Look for steps where users abandon the process, upload the wrong document or need support.
    3. Which checks are truly required? Separate regulatory requirements from habits that became part of the flow over time.
    4. Can we route customers by risk and context? A single fixed process is rarely the best process.
    5. Can we add a new identity method without rebuilding the journey? This is the wallet-readiness test that matters most. If adding a new method requires a long technical project, several manual workarounds and new support scripts, the architecture is probably too rigid.

    Where Bluem fits

    Bluem helps companies build onboarding flows that can handle multiple identity and trust methods in one process. That can include ID document verification, bank-based identification, address validation, eSigning and compliance checks.

    The value is not in pushing every customer through the same path. It is in giving each customer a route that fits the situation while keeping the process manageable for the business.

    That matters now because the identity market is changing. The EUDI Wallet will become part of the landscape, but it will sit alongside existing methods for some time.

    Companies that prepare well will not be the ones that wait for a perfect European identity standard. They will be the ones that make their onboarding flexible enough to support today’s customers and tomorrow’s credentials.

    Want to see where your onboarding flow may become a bottleneck? Bluem can help you review your current identity routes and prepare for wallet-based verification without breaking what already works.

  • Identitätsbetrug im Jahr 2026: Warum die jüngsten Nachrichten auf eine komplexere Bedrohung hinweisen

    Identitätsbetrug im Jahr 2026: Warum die jüngsten Nachrichten auf eine komplexere Bedrohung hinweisen

    Identity Fraud in 2026 Feels Different Now

    Identity fraud is no longer just about a fake ID or a stolen password. It is becoming easier to build and harder to contain. Stolen data, AI-generated impersonation, deepfakes, and account takeover now fit together in ways that make fraud both more accessible and more convincing.

    That change is happening at both ends of the market. At the low end, the tools are cheaper, simpler, and easier to access. At the high end, the fraud is more polished, more targeted, and harder to spot. The result is a threat that feels different from a few years ago: broader, more reusable, and more personal.

    The numbers already show the shift. More than 444,000 cases were recorded to the UK National Fraud Database in 2025, the highest annual total on record. Nearly three quarters of those cases, 72%, were linked to identity fraud and facility takeover. Identity fraud remained the single biggest category.

    Fraud rarely ends with the first move

    Identity fraud and account takeover used to sound like different problems. They now look much closer together. The same stolen details can be reused to support a fake application, impersonate a real person, unlock an existing account, or make a scam look convincing enough to work.

    That is why the impact keeps getting heavier. More of a person’s identity now sits inside systems that decide whether they are trusted, recognised, approved, or allowed through. When that identity is misused, the damage does not stop at one failed check. It can spread into finances, access, reputation, and daily security.

    Put simply, fraud now moves. Data gets exposed or stolen. That data supports impersonation. Impersonation opens the door to account takeover or further deception. From there, the same cycle can repeat.

    AI is lowering the barrier to identity fraud

    The worrying part is that technological advances are giving more people access to tools that make identity fraud easier to commit. Public fraud reporting now reflects that change. Generative tools are helping criminals create convincing impersonations, synthetic identities, and fake documentation at greater speed and scale. AI-enhanced fraud is also making fraud more sophisticated and, in some cases, more profitable than older methods.

    The important point is not that AI has invented a brand-new crime. It has made familiar tactics easier to run. Persuasive messages are easier to produce. Fake supporting material is easier to generate. More versions of the same scam can be launched at once.

    In practice, that means something simpler and worse: more people can run more convincing fraud. The challenge is no longer only whether someone has enough stolen information to pose as another person. It is whether they can make that lie look consistent across documents, messages, calls, and account activity.

    Deepfakes have moved into the centre of the story

    Deepfakes are no longer a side topic in fraud. They are becoming part of the same toolkit. Deepfake technology is increasingly associated with fraud, identity abuse, and more advanced forms of deception. It also raises the risk of document fraud becoming harder to detect.

    Deepfakes are taking centre stage for good reason. They do not just create security risks. They also make identity abuse more personal when someone’s face, voice, or likeness is used against them.

    That makes remote trust harder. A fake claim backed by a realistic voice clip, image, or video is more persuasive than a crude scam on its own. The real weakness is not one image or one clip. It is when too much trust rests on a narrow check instead of the wider process around it.

    Stolen data still does most of the work

    For all the attention on AI and deepfakes, stolen data still sits underneath much of this. That helps explain why identity fraud keeps showing up in different forms. A leak, breach, or compromised dataset is often not the end of the problem. It is the beginning of what can be done with that information next. Once personal data is stolen, sold, or reused, it can support impersonation, account takeover, fake applications, and further fraud.

    Put together, the pattern is hard to miss. Stolen data provides the base. AI improves the impersonation. Deepfakes strengthen the illusion. Account takeover turns that into direct abuse. Each part makes the next one easier.

    What feels different now

    The biggest change is not just that fraud is rising. It is that fraud is becoming easier to assemble. Identity fraud, facility takeover, stolen-data abuse, AI-driven impersonation, and deepfake-enabled deception now overlap much more than they used to.

    That is why older ways of describing identity fraud feel too narrow. It is no longer enough to ask whether one ID image or one credential is real. The harder question is whether the whole picture makes sense: the identity claim, the data behind it, the behaviour around it, and the context in which it appears.

    That is also why this topic no longer feels like a niche issue in verification alone. Identity fraud now sits inside a much larger security problem.

    Conclusion

    Identity fraud in 2026 is more than a verification problem. It can disrupt finances, damage reputations, and undermine a person’s sense of security.

    What feels different now is not one new tactic. It is the way multiple tactics fit together. Stolen data, scalable impersonation, deepfakes, and account takeover now reinforce each other. That is what makes identity fraud harder to catch, easier to repeat, and more serious for the people caught up in it.

    At Bluem, we help organisations deal with this shift by combining identity verification, payment data and compliance checks into one flow. Instead of relying on a single moment of verification, our solutions support continuous insight into who you are doing business with. This allows businesses to detect risk earlier, reduce fraud exposure and keep processes efficient without adding unnecessary friction for legitimate customers.

  • Wo die lokale digitale Identität endet: Wie okID grenzüberschreitende IDV unterstützt

    Wo die lokale digitale Identität endet: Wie okID grenzüberschreitende IDV unterstützt

    Where Local Digital ID Ends: How okID Supports Cross-Border Identity Verification

    Local digital identity has transformed onboarding. In markets with mature national identity infrastructure, resident verification can be fast, familiar, and highly trusted. Singapore is a clear example: Singpass serves around 5 million users, supports more than 2,700 services across 800 government agencies and businesses, and processes more than 41 million transactions each month. Myinfo adds another layer by enabling reuse of verified personal data in digital journeys. That strength does not make local digital identity universal. National identity rails are typically built for a defined population, within a specific legal and domestic service framework. Singpass registration, for example, is designed for Singapore Citizens, Permanent Residents, and FIN holders. In other words, these systems work best when the user already sits inside the local identity ecosystem. This is where document-based identity verification becomes relevant. The strongest model is often not local digital identity or document verification, but local digital identity plus a broader assurance layer. Local rails can handle the users they were built for, while a broader verification solution can support cases that fall outside that domestic framework.

    Local identity rails are powerful, but they are local by design

    The limitation of local digital identity is not quality. It is scope. In South Korea, the official mobile identity ecosystem shows how strong a national framework can become inside one market. Government-supported mobile credentials include domestic identity documents and mobile residence cards for registered foreign residents. That works well for people already inside the Korean administrative system, but it also shows that access depends on local registration and local credentials rather than functioning as a universal onboarding rail for every international prospect. Japan follows a similar logic. The My Number system is tied to the resident record, and JPKI provides the trust layer for online authentication and electronic signatures in both public and private services. That gives Japan a strong national identity foundation, but practical onboarding still depends on the specific use case, the integration model, and the user’s resident status. For internationally active organisations, that creates a recurring gap. National digital identity works well when a user is already eligible for the domestic scheme. It becomes less complete when onboarding involves a foreign passport, a non-resident applicant, an international customer base, or a flow that requires stronger evidence than a standard domestic login can provide.

    Where the gaps appear in practice

    The first gap is non-resident onboarding. A domestic digital identity method may work perfectly for resident users, but that does not automatically help with expats, international applicants, foreign customers, or users who do not qualify for the local scheme. In Singapore, for instance, Singpass eligibility is clearly linked to resident status categories. The second gap is foreign-document coverage. A national eID can authenticate local users, but many onboarding journeys still need to process passports, residence permits, visas, and other foreign documents. That is especially relevant for organisations serving multiple countries through one onboarding flow rather than building separate identity journeys market by market. The third gap is assurance. In some journeys, the requirement is not only authentication, but stronger evidence against fraud, impersonation, or manipulated documents. This is particularly relevant in higher-risk onboarding, regulated sectors, and flows where auditability matters.

    Why okID fits around local digital identity

    okID makes the most sense when positioned around local rails, not against them. It is not strongest as a replacement for every national identity scheme. It is strongest as the layer that supports broader coverage and additional assurance where local digital identity no longer fits the case. Bluem positions okID as a document-based identity verification solution for digital onboarding, with capabilities such as document checks and liveness detection. That makes it relevant in flows where the user does not have access to the local digital identity method, where foreign documents must be verified, or where extra verification is needed on top of an existing domestic login flow. In practical terms, that leads to a stronger hybrid model. Local digital identity can remain the preferred route for eligible resident users. It is often the fastest and most trusted option in domestic flows. okID can then support the users and scenarios that sit outside those rails: non-residents, foreign document holders, cross-border customers, and higher-assurance onboarding journeys. That combination is often more realistic than trying to force one method to solve every use case.

    A stronger model for international onboarding

    For many organisations, the key challenge is no longer proving that local digital identity is valuable. That is already clear. The real challenge is maintaining smooth onboarding when the user, the document set, or the risk profile falls outside the comfort zone of national rails. That is where okID adds practical value. It extends identity verification beyond resident-only ecosystems, supports document-based verification for international users, and adds an assurance layer where stronger checks are required. Used that way, it does not compete with local digital identity at its strongest point. It fills the space around it, where onboarding becomes more international, more fragmented, and more risk-sensitive. The result is a more flexible identity strategy: local digital ID where it fits, and broader document-based verification where it does not.

  • Ein Wort von unserem CTO: Wo endet die Automatisierung?

    Ein Wort von unserem CTO: Wo endet die Automatisierung?

    In this opinion piece, our CTO Aviël Ossi shares his perspective on the evolving impact of AI on business. He introduces a parabolic model of AI adoption and reflects on where automation creates value and where human judgment remains essential.

    The Parabolic Rise of AI Disruption

    I believe the disruptive impact of AI follows a parabolic curve. In the early phase of this curve, companies signal to the market that shareholder value will increase through AI automation, often accompanied by layoffs. For example, when Jack Dorsey’s Block laid off a large portion of its workforce, the market responded positively, and the share price rose with 20%. Moves like this suggest that investors initially reward companies for reducing costs through automation. In this first phase of the parabola, executives, especially in companies struggling with growth or under pressure to meet investor expectations may attempt to “ride the AI wave” to deliver quick financial results. This is particularly relevant for firms with multiple funding rounds, high burn rates, or unfavourable profit-to-loss ratios (Uber, Airbnb, etc.). In the short term, such strategies may indeed boost share prices and improve key performance indicators.

    However, when this strategy no longer produces results, we reach the top of the parabola. Growth stagnates, share prices stop growing, and customer satisfaction suffers. Companies that rely heavily on automation and workforce reductions may find they can no longer outperform their competitors. Therefore, when things go wrong and consumer interest declines or when the company begins to lose its competitive edge over others, despite automation, who is held accountable? And more importantly, who pays for those mistakes?

    The Erosion of the Company “Soul”

    There are several possible drivers of this shift. One is the erosion of a company’s “soul”: the loss of human knowledge, internal systemic relationships, connection with customers, and touch with the market. Markets do not deal with binaries and absolutes – markets are fluid, and dependant on chance, not only in objective perspectives but also subjective perspectives. At this stage, stakeholders may begin to value companies not only for financial performance but also for the employment they create and the societal role they play and impact they have.

    Another potential inflection point is a decline in innovative capacity. Over-automation can lead to rigid, binary decision-making shaped by strict algorithms and regulatory constraints, whereas human judgment can interpret rules flexibly and creatively to achieve better outcomes. Not following the rules versus following them to varying degrees.

    Additionally, consumers may grow fatigued by automated interactions. A lack of human engagement could push them toward competitors that emphasize experience, support, and genuine human connection. Or from a principal point of view, always defer the highly automated competitor over the companies with human touch.

    The Normalization Phase

    The normalization phase follows. In this stage, companies recognize that AI is most effective as a supportive tool rather than a full replacement for human ingenuity, creativity, judgment, and initiative. Instead of continued workforce reductions, organizations may begin reinvesting in human capital to complement AI systems and fill the gaps automation cannot address.

    Where Automation Ends

    While AI is rapidly improving, automating development workflows, fixing bugs autonomously, analysing interfaces, and is increasingly operating without supervision, the central question remains whether this constitutes true creativity or merely advanced task execution. Automation can optimize, iterate, and even self-correct, but it does not yet display the human ability to sense opportunity, navigate ambiguity, respond to shifting dynamics, or inject vision into a situation. Just as a company can lose its “soul” when its driving force departs, organizations that over-automate risk eroding the human intuition, contextual awareness, and subjective judgment that allow them to recognize market openings and create differentiated value. AI will undoubtedly become more autonomous and more affordable, and those who ignore it risk irrelevance. Yet in the long run, the advantage will not belong to those who automate the most, but to those who know exactly where automation stops, and where human coherence, courage, and creative instinct must take over.

  • Online-Identifizierung: Trends, Regulierung und was kommt als nächstes?

    Online-Identifizierung: Trends, Regulierung und was kommt als nächstes?

    Online identification has become core infrastructure for digital onboarding. It is no longer just a compliance step. It defines how businesses manage risk, prevent fraud and build trust with customers.

    Several structural developments are shaping the future of digital identity verification.

    AI-Driven ID Scanning Becomes the Standard
    Artificial intelligence now powers modern ID scanning systems.
    AI-based OCR reads document data automatically. MRZ recognition verifies machine-readable zones. Fraud detection models identify document manipulation and inconsistencies in real time.
    Advanced ID scanning solutions can recognize thousands of document types across more than 200 countries and support dozens of languages. Automation reduces manual review and increases onboarding speed.

    Read more about Bluem’s ID scanning and identity verification solutions here:

    https://www.bluem.nl/en/oplossingen/identity/ok-id

    The next phase of development focuses on explainable AI. Under the EU AI Act, identity verification systems will fall into regulated categories requiring transparency and human oversight. Automation will continue, but governance will tighten.

    Stronger Biometric Verification

    Biometric controls are evolving quickly.
    Selfie comparison alone is no longer sufficient. Liveness detection, face match algorithms and injection attack protection are becoming standard features.
    As generative AI tools improve, deepfake identity fraud will increase. This drives demand for multi-layer biometric verification.
    Solutions that combine ID scanning, biometric face capture and liveness detection provide stronger protection while maintaining high onboarding conversion.

    Learn more about Bluem’s Identity & eSign services and biometric add-ons such as Face Match and Liveness Detection:

    eIDAS 2.0 and Digital Identity Wallets

    A major regulatory shift in Europe is the introduction of eIDAS 2.0 and the European Digital Identity Wallet.
    Member states must provide citizens with interoperable digital identity solutions. Businesses will need to accept wallet-based identification and higher-assurance electronic signatures.
    This creates hybrid onboarding environments where document-based identification and wallet-based verification coexist.
    Organizations should ensure their identity infrastructure supports Advanced and Qualified Electronic Signatures where required.

    Reference: European Commission on eIDAS 2.0
    https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation

    Convergence of Identification and Compliance

    Identification no longer operates in isolation.
    Modern onboarding integrates:

    • ID document verification
    • Biometric validation
    • AML and sanctions screening
    • Address verification
    • Digitale Signatur

    Regulators expect structured audit trails and traceability. Identity verification results must feed directly into compliance decision engines.
    For sectors such as fintech, iGaming, leasing and financial services, identification, compliance and affordability checks are increasingly connected.

    Data Sovereignty Changes Infrastructure Decisions

    Data sovereignty is one of the most important developments in digital identity.
    Governments are tightening rules on where personal and biometric data can be stored and processed. GDPR already limits international data transfers. Additional national requirements are emerging across Europe and globally.

    Organizations must evaluate:

    • Where identity data is hosted
    • Which cloud providers are used
    • How cross-border onboarding flows are structured

    Failure to align with data residency requirements can create regulatory exposure.
    Data sovereignty is not only a legal issue. It influences vendor selection, system architecture and expansion strategy.

    Privacy and Attribute-Based Identity

    Another emerging trend is selective disclosure of identity attributes.
    Instead of sharing full identity documents, systems may confirm specific attributes such as age or residency status. Digital identity wallets support this model.
    Identity verification is moving toward more granular, privacy-aware models.

    This aligns with GDPR principles of data minimization and purpose limitation.

    Reference: GDPR overview
    https://gdpr.eu

    What to Expect

    In the coming years, expect:

    • More AI-driven automation
    • Higher biometric assurance standards
    • Broader adoption of digital identity wallets
    • Stricter data sovereignty requirements
    • Increased regulatory scrutiny

    Online identification will become more structured, more regulated and more integrated into national digital strategies.
    Organizations that treat identification as core digital infrastructure will be better positioned for growth and compliance.
    If you are reviewing your onboarding setup or exploring secure ID scanning, biometric verification or digital signing solutions, now is the time to evaluate whether your current infrastructure is ready for the next regulatory phase.

    Kontaktieren Sie uns to discover how Bluem can help you.

  • Wie die Überprüfung des IBAN-Namens dazu beiträgt, Ihre Lieferantendatenbank zu reinigen und zu pflegen

    Wie die Überprüfung des IBAN-Namens dazu beiträgt, Ihre Lieferantendatenbank zu reinigen und zu pflegen

    Supplier databases tend to grow organically over time. New suppliers are added, details are changed, and information is copied between systems. As a result, data quality slowly deteriorates. Incorrect or outdated bank details are one of the most common causes of failed payments and urgent payment corrections.

    The IBAN Name Check offers a practical and scalable way to improve supplier data quality without large scale migration projects. By validating the IBAN and account holder name at the moment supplier details are entered or updated, errors are detected immediately. This shifts control from the payment run to the data entry phase.

    For finance teams, this means fewer surprises during payment execution. Payments are less likely to bounce or be misdirected, reducing the need for manual investigation and recovery. Bank fees and operational costs decrease, while internal confidence in payment data increases.

    The real value becomes visible in organisations with large supplier volumes. Even a small reduction in failed payments can lead to significant savings over time. IBAN-Name Check turns supplier onboarding into a preventive control rather than a reactive process.

    The most effective approach is simple and consistent. Validate supplier bank details once when they are first entered, and revalidate when changes are made. This keeps the supplier database accurate by design and reduces dependency on periodic clean-up exercises.

    However, preventive validation at entry level should be complemented by a periodic review of the full supplier database. An annual database check helps organisations identify outdated bank details, inactive suppliers, duplicate records and inconsistencies that may have accumulated over time. This is particularly relevant in preparation for year-end closing and financial reporting, where the accuracy of creditor data directly impacts the reliability of the financial statements.

    In addition, periodic verification supports broader compliance efforts. While an IBAN Name-Check confirms whether the IBAN and account holder name match at the time of validation, organisations should also ensure that supplier data remains aligned with internal AML policies, fraud prevention controls and, where applicable, sanctions screening procedures. A structured annual review strengthens governance and reduces operational and compliance risks.

    The IBAN Name-Check enables companies to perform this validation in real time, directly within their onboarding or payment processes. The solution verifies whether the IBAN and account holder name match and provides clear feedback that can be automatically processed in your systems. Integration is available via API or dashboard, allowing organizations to implement a preventive control without disrupting existing workflows.

    Learn more about the IBAN Name check

  • Überprüfung des IBAN-Namens in Europa und seine Bedeutung für Ihre Zahlungen

    Überprüfung des IBAN-Namens in Europa und seine Bedeutung für Ihre Zahlungen

    IBAN name check, also referred to as verification of payee, is steadily becoming a standard component of European payment flows. What started as a local initiative in a small number of countries is now expanding across the entire SEPA region. For organisations that send or receive payments on a daily basis, this development directly affects fraud prevention, operational efficiency and regulatory readiness.

    In practical terms, IBAN name check verifies whether the name of the account holder matches the IBAN before a payment is executed. Historically, banks validated the structure of the IBAN but did not actively compare it with the beneficiary name. This gap has led to payment errors, invoice redirection fraud and costly manual recovery processes. IBAN name check closes this gap by adding an extra layer of validation at the moment it matters most.

    European coverage is being rolled out in phases. Some countries already support real time name matching with clear match or mismatch responses. Other countries provide partial confirmations or delayed responses, while a small number are still preparing their infrastructure. This means businesses must design payment and onboarding flows that can cope with differences between countries without creating friction for users or internal teams.

    The broader European roadmap is clear. Verification of payee is closely linked to the instant payments regulation and will become widely available across Europe. Organisations that integrate IBAN name check now are not only reducing payment risk today, but also avoiding rushed system changes later when adoption becomes mandatory.

    From a commercial perspective, the benefits are immediate. Fewer failed payments reduce support costs and bank fees. Cleaner payment data improves reconciliation and reporting. Over time, IBAN name check becomes a foundation for scalable, high quality payment operations rather than a standalone fraud control.

    Would you like to receive more info on the IBAN-name check?

    Contact our sales team

  • Warum fragmentierte Onboarding-Prozesse Ihre Conversion-Rate reduzieren

    Warum fragmentierte Onboarding-Prozesse Ihre Conversion-Rate reduzieren

    Every additional step in an onboarding flow increases the likelihood of drop off. Users expect a smooth and predictable experience, especially when they are asked to share personal or financial information. When identity checks, payment setup and compliance are handled by separate tools, the journey quickly becomes fragmented.

    This fragmentation forces users to switch contexts, repeat information or wait for manual follow-ups. Each interruption introduces friction and uncertainty, which directly impacts completion rates. What often starts as a necessary control quickly becomes a barrier to conversion.

    Fragmented onboarding also creates challenges behind the scenes. Connecting multiple vendors for identity verification, IBAN validation, mandates and compliance checks increases technical complexity. Errors become harder to trace, data is spread across systems and user journeys are difficult to analyse and optimise. As a result, support teams spend more time resolving issues that originate from disconnected processes.

    A unified onboarding flow addresses these challenges by keeping users in one consistent journey. Identity verification, IBAN name check, digital mandates and compliance screening are applied in the background and only surface when something requires attention. This reduces friction for genuine users while maintaining control over risk and regulatory requirements.

    Bluem enables this approach by bringing identity, payments and compliance together in a single onboarding flow. Services such as identity verification, IBAN name check, Emandates und compliance checks are designed to work together, not as isolated steps. This allows organisations to onboard customers faster without compromising security or data quality.

    From a commercial perspective, the impact is clear. A unified Bluem onboarding flow leads to higher conversion rates, faster activation and lower operational costs. Fragmented onboarding often hides its true cost in lost sign-ups, delayed payments and inefficient manual processes.

    The most effective onboarding strategies combine security, compliance and usability into one integrated experience.

    👉 Learn more about how Bluem helps streamline onboarding on our onboarding page