Overview
ISO 5158:2023 - "Mobile financial services - Customer identification guidelines" provides a practical framework for customer identification in mobile financial services (MFS) and eKYC. The standard defines a multi-dimensional identity assurance level (AL) model for identifying natural persons via mobile channels, sets out evaluation criteria for those assurance dimensions, and addresses key security and privacy considerations relevant to MFS enrolment and lifecycle management. Annexes illustrate application of ALs with (e)KYC case studies and mobile-device security capabilities.
Key technical topics and requirements
- General framework for MFS identification
- Defines a contextual identity built from verifiable attributes (biometrics, NPI, email, geolocation, etc.) sufficient for MFS use.
- Clarifies the steps of mobile identification: attribute/evidence submission, validation, verification of linkage and willingness, and enrolment.
- Multi-dimensional Assurance Levels (AL)
- AL dimensions covered: AL_U (uniqueness), AL_E (existence/identity evidence), AL_P (presence), AL_W (willingness), AL_R (reachability).
- The standard provides evaluation criteria for each AL dimension and for identity evidence used in MFS contexts.
- Identity evidence and identity information authorities
- Guidance on assessing identity evidence issued by identity information providers (IIP) and identity information authorities (IIA).
- Recommends use of natural person identifier (NPI) records (ISO 24366) when selecting attributes.
- Security and privacy considerations
- Personal data protection, biometric vulnerabilities and privacy risks, and device-side security (trusted execution, secure elements) are addressed.
- Annexes detail mobile device security capabilities and practical (e)KYC use cases.
Practical applications and who uses this standard
- Mobile financial services providers (MFSPs) - commercial banks, digital-wallet operators, and third-party payment service providers use ISO 5158 to design compliant eKYC flows and risk-based onboarding.
- Identity solution vendors & integrators - to align mobile identity proofs, biometric checks, and device attestations with accepted assurance criteria.
- Compliance, AML and risk teams - for mapping local KYC/AML requirements to ALs and selecting appropriate identity evidence.
- Regulators and policy makers - to harmonize remote identification expectations across jurisdictions and support financial inclusion initiatives.
Related standards
- ISO 12812-1 (Core banking - Mobile financial services)
- ISO/IEC 24760-1 (Identity management terminology & concepts)
- ISO 24366 (Natural person identifier) - referenced guidance
- ISO/IEC TS 29003 and NIST SP 800-63A are cited for identity proofing and IAL concepts
ISO 5158:2023 is a practical reference for implementing secure, privacy-aware mobile customer identification and for mapping eKYC practices to clear assurance levels in MFS environments.