In brief
On 23 August 2026, the Central Bank of Egypt (CBE) issued a circular to banks setting out the rules governing the services of the digital financial identity system for the electronic identification and verification of bank customers within the Arab Republic of Egypt ("Rules"). The Rules establish a CBE-approved Digital Financial Identity (DFI) system that enables retail customers to create a digital financial identity and to be identified and verified electronically ("eKYC"), to obtain banking products and services and update their data and documents remotely. The Rules constitute a significant step towards enabling secure remote onboarding in Egypt and will facilitate the growth of digital banking services in the Egyptian market.
Key takeaways
- The Rules apply to all banks operating in Egypt, licensed entities that may join the approved system, and CBE-authorised banking agents, and set the minimum requirements to provide DFI services.
- The services covered include the electronic identification, verification and updating of customer data; the electronic authentication of banking transactions, payment orders and transfer orders and acceptance of their terms and conditions; and the sharing of the digital financial identity through the approved system.
- The DFI system is a single, CBE-approved platform through which each retail customer is given one unique digital financial identity used for eKYC and electronic authentication. The platform is created and operated by the Digital Financial Identity Company (Haweya) ("Haweya"), which provides and operates the approved system from within Egypt, issues the technical connection rules, and securely connects with trusted entities (such as the Civil Status Authority) to obtain citizens' data, in each case subject to the CBE approval.
- The participating bank remains primarily responsible for identifying and verifying its customers in line with the Anti-Money Laundering and Combating the Financing of Terrorism Unit ("AML/CFT Unit") procedures. The Rules set out the minimum compliance requirements applicable to all entities addressed, namely participating banks, CBE-authorised banking agents, and Haweya.
- Banking agent's role, where identification and verification are made available through them, must be confined to cases that the approved system cannot process automatically (such as a strong similarity in data or biometric features, for example twins).
- Haweya must ensure a single unique digital financial identity per customer and provide identification, electronic authentication, negative-list screening and DFI-sharing services, while retaining electronic records within Egypt. It must support liveness detection and the reading of national ID and official documents, establish an information security committee, and conduct penetration testing together with vulnerability and third-party risk assessments with 24/7 monitoring, in each case subject to CBE oversight.
- The Rules apply without prejudice to the CBE's existing regulations and instructions and to the identification and verification procedures to be issued by the AML/CFT Unit.
Implications for market participants
- The Rules will enable banks to onboard and verify customers remotely and to update the data of existing customers, reducing reliance on physical branches and supporting the development of new digital products and services.
- Participating banks should align their onboarding, governance, cybersecurity, outsourcing, fraud and data-protection frameworks with the Rules and prepare the documentation required to obtain CBE approval, both to join the system and prior to the launch of the service.
- Banking agents will operate within a tightly defined, exception-based role, requiring banks to put in place appropriate contractual, operational and control arrangements over agent activity, while Haweya acts as the operator of the approved platform.
Explore More Insight