← Back to blog

The Role of Customer Verification in Currency Business

August 18, 2026
The Role of Customer Verification in Currency Business

Customer verification exists to do three things: stop dirty cash from being laundered through your exchange counter, create an identity record that survives an audit, and feed your monitoring systems the data they need to catch trouble in real time. Get those three right and everything else, the paperwork, the training, the software, falls into place around them.

If you run or supervise a currency exchange office, here's what to fix this quarter. First, hardcode threshold-based identification into your workflow: Lithuanian law requires customer identification once a cash exchange crosses €6,000 in a single or linked transaction, with heightened obligations at €15,000, under the Law on the Prevention of Money Laundering and Terrorist Financing. Second, if you accept non-face-to-face customers, your remote ID method needs to hit eIDAS high or substantial assurance, not a screenshot of a passport emailed in. Third, configure automated alerts for structured or linked transactions before you need them, not after the Bank of Lithuania asks why you didn't catch a pattern.

  • Set exchange thresholds and linked-transaction logic directly into your point-of-sale or compliance software.
  • Confirm your remote identification vendor meets eIDAS-qualified or equivalent assurance levels.
  • Build automated flags for repeat small-value exchanges from the same customer, ID, or device.

Quick fact: under the AML law, transactions at or above the higher threshold trigger additional identification and monitoring duties on top of the lower threshold baseline. Platforms like CURREXCHANGER are built to encode both thresholds into the transaction flow automatically.

Key Takeaways

Customer verification works because it converts a legal obligation into an operational habit: identify every customer above threshold, monitor transactions continuously, and document every decision in a way a supervisor can review months later.

PointDetails
Three core dutiesIdentify customers above statutory thresholds, monitor transaction patterns, and document every check.
Know your thresholdsIdentification is required above €6,000; additional monitoring and identification duties apply from €15,000.
Remote ID must meet assurance standardsNon-face-to-face verification needs eIDAS-qualified or equivalent high/substantial assurance methods.
Automate linked-transaction detectionStructuring shows up as repeated small transactions, which manual review often misses.
Retention and reporting have deadlinesRecords must be kept for the statutory period, and suspicious activity must reach FCIS without undue delay.
Software can operationalize compliancePlatforms like Currexchanger automate thresholds, document checks, and audit logging across multi-branch networks.

Table of Contents

Why Customer Verification Is the Backbone of Currency Exchange Risk Management

Currency exchange has a structural weakness other financial businesses don't share: it converts cash into cash, instantly, with no intermediary bank slowing things down. That's exactly why it's a preferred laundering channel. Verification isn't a compliance checkbox here, it's the control that stops someone from walking in with low-denomination notes from an illicit source and walking out with high-value, easily transportable currency.

Poor verification doesn't just expose you to a single bad transaction. It compounds. A customer who successfully splits a €20,000 exchange into four €5,000 visits across two weeks has learned your thresholds don't work, and they'll come back. Left unchecked, that pattern (known as structuring) creates cross-border cash flight risk and puts your license on the supervisor's radar. Regulatory guidance across jurisdictions treats non-face-to-face interactions as inherently higher risk, and the same logic applies to any pattern that looks engineered to dodge a threshold.

Structuring rarely looks dramatic. It looks like a regular customer, slightly too regular, showing up with amounts that always land just under your reporting trigger.

That single rule catches most amateur structuring attempts before they escalate.*

Lithuanian law sets clear triggers for when identification becomes mandatory, and the obligation doesn't disappear just because a customer splits a transaction into pieces. Identity checks are required for occasional cash exchanges once the amount exceeds the statutory threshold, and that includes linked transactions carried out by the same person over time, per the AML law's identification provisions.

Two figures matter most. At €6,000, you must identify the customer using a reliable, independent source (government ID, verified through a database or document check). At €15,000, additional identification and monitoring obligations kick in, which usually means gathering source-of-funds information and applying closer scrutiny to the transaction pattern. Articles 9 through 15 and Article 24 of the AML law lay out the full customer due diligence framework, including when simplified or enhanced measures apply.

The obligation to identify a customer doesn't reset because a transaction was split across visits. Linked transactions are assessed cumulatively, not individually.

Practical checklist for what your front desk needs to capture and when:

  • Government-issued photo ID with a verifiable document number for any exchange above €6,000.
  • Source-of-funds documentation once cumulative exchanges reach €15,000.
  • Escalation to enhanced due diligence for PEPs, high-risk jurisdictions, or inconsistent ID data.
  • Suspicious activity reports filed to the Financial Crime Investigation Service (FCIS) without undue delay once a suspicion arises, not at month-end.

Quick fact: the €15,000 threshold isn't a separate, unrelated rule, it's the point where identification obligations from the €6,000 trigger expand into fuller due diligence and monitoring.

Building a Risk-Based Verification Framework for Your Exchange Office

A risk-based approach means the verification you apply scales with the danger the transaction actually presents, not a flat rule applied to every customer regardless of context. That means combining four inputs: customer profile, transaction size and frequency, channel (walk-in versus remote), and geographic exposure.

A simple matrix helps operationalize this. Low-risk customers making small, infrequent, in-person exchanges can usually go through simplified due diligence (SDD). Mid-tier customers approaching your reporting thresholds need standard CDD. Anyone flagged for PEP status, high-risk jurisdiction ties, or unusual transaction patterns moves to enhanced due diligence (EDD) regardless of transaction size.

Risk SignalVerification LevelExample Trigger
Small, infrequent, in-person exchangeSimplified due diligenceUnder €6,000, no linked history
Standard exchange near thresholdCustomer due diligence€6,000–€15,000, first-time customer
High-risk profile or patternEnhanced due diligencePEP status, structuring pattern, high-risk jurisdiction

Red flags that should trigger automatic escalation, drawn from practical guidance for money-service businesses on designing CDD/EDD trigger scenarios, include repeat transactions just under your threshold, ID documents with mismatched or inconsistent data, and customers unable to give a coherent explanation for the source of large cash sums. Encode these as automated rules rather than relying on a teller's memory. A busy counter on a Friday afternoon isn't where you want pattern recognition to depend on human recall.

Quick fact: the €6,000 and €15,000 thresholds from Lithuanian law form the backbone of any tiering matrix, but frequency and jurisdiction risk should push a customer into a higher tier even below those numbers.

Building a Risk-Based Verification Framework for Your Exchange Office — overview diagram

Operational Controls and Technology That Make Verification Auditable

Verification only holds up under supervisory review if it produces a record someone can check later. That means combining reliable ID capture, live transaction monitoring, and logs that can't be quietly edited after the fact.

The concrete controls worth investing in:

  • OCR-based document verification to catch altered or expired IDs at intake.
  • Liveness and biometric checks for remote onboarding, reducing the risk of stolen-identity fraud.
  • PEP and sanctions screening run automatically against every new customer, not just flagged ones.
  • Bank-account-link verification for first-time electronic payments, confirming the payer matches the account holder.
  • Automated threshold alerts that fire the moment linked transactions approach €6,000 or €15,000.
ControlWhat It CatchesTypical Data Retained
OCR document verificationAltered, expired, or forged IDsScanned document, verification timestamp
Biometric/liveness checkStolen or borrowed identityMatch score, session recording
PEP/sanctions screeningPolitically exposed or sanctioned individualsScreening result, screening date
Linked-transaction alertsStructuring across visitsTransaction history, alert log

Compliance has to run inside daily operations, not alongside them, so verification produces records supervisors can actually pull up and review.

A platform like CURREXCHANGER maps these controls directly into the transaction workflow: document capture happens at the point of sale, PEP screening runs through API integrations with third-party providers, and every check is logged automatically rather than typed up after the fact. That's the difference between compliance that exists on paper and compliance a regulator can verify in five minutes. For a deeper look at how monitoring rules catch these patterns, see this overview of transaction monitoring system types.

Who Owns Verification: Governance, Training, and Internal Audit

Every exchange office needs one person whose job title includes actual accountability for AML compliance, usually an MLRO (Money Laundering Reporting Officer) or a designated responsible manager. The Bank of Lithuania's registration requirements require notification when that manager changes, which tells you how seriously supervisors treat the role.

RolePrimary Responsibility
Front-line staffCapture ID documents, flag unusual behavior at the counter
Compliance officer / MLROReview alerts, decide on EDD escalation, file SARs
Operations managerMaintain audit logs, ensure retention policy compliance
Senior managementApprove risk appetite, review periodic audit findings

Training needs two layers: onboarding for new hires covering ID checks and red-flag recognition, and periodic refreshers (annual, at minimum) covering updated typologies and regulatory changes. Internal audits should run at least twice a year, checking a sample of transactions against the documentation trail and confirming alerts were actually reviewed, not just generated and ignored.

Non-Face-to-Face Identification: What Meets Lithuanian Standards

Remote identification is permitted, but only when the method delivers assurance comparable to checking a passport in person. Lithuanian AML guidance accepts eIDAS-qualified electronic signatures and video calls with confirmed facial identity matching as meeting that bar.

Remote onboarding isn't inherently risky. Remote onboarding without a documented assurance level is where the trouble starts.

Acceptable methods worth building into your process:

  • eIDAS-qualified electronic signatures, which carry a legal presumption of reliability across the EU.
  • Video identification sessions with real-time face matching against a submitted ID document.
  • Verified digital identity schemes recognized under national or EU frameworks.
  • First-payment verification from an account already held in the customer's name at a regulated bank.

For remote sessions specifically, record the interaction, retain evidence the document was checked live rather than uploaded separately, and apply enhanced monitoring to the resulting transaction for a defined period. E-signing platforms have published detailed breakdowns of how identity verification works within qualified electronic signature flows, which is useful background if you're evaluating vendors. The Bank of Lithuania's own FAQ on prevention of money laundering addresses several practical questions on acceptable remote sources directly.

Enhanced Due Diligence: Triggers and a Step-by-Step Process

EDD isn't optional once specific risk factors appear: PEP status, ownership structures that obscure the real beneficial owner, ties to a high-risk jurisdiction, or transactions crossing your reporting thresholds. When any of these show up, the process should run the same way every time.

  1. Identify the trigger (PEP hit, jurisdiction flag, threshold breach, or inconsistent data).
  2. Gather additional documentation: proof of address, source-of-funds statements, corporate ownership records if applicable.
  3. Verify the source of funds independently rather than accepting the customer's explanation at face value.
  4. Escalate the file to the MLRO for a documented decision.
  5. File a suspicious activity report with FCIS if the review confirms grounds for suspicion.

Evidence worth collecting during EDD includes recent bank statements, notarized identity documents for cross-border customers, corporate registry extracts showing beneficial ownership, and a written explanation of the transaction's business purpose. Retain this file for the full statutory period, since a supervisor reviewing a case months later needs the same trail you had on day one.

Data Protection: Keeping Verification Records GDPR-Compliant

AML retention obligations and GDPR don't conflict, but they do require careful handling. Identity data collected for verification has a lawful basis under AML law, which satisfies GDPR's lawfulness requirement, but that doesn't excuse you from minimization, access controls, or encryption.

Required controls include encryption for stored documents, detailed access logs showing who viewed a customer file and when, and multi-factor authentication for any staff account with access to identity data. Once the statutory retention window closes and no active investigation exists, records should be anonymized or deleted, not retained indefinitely on the assumption that more data is always safer.

Six Steps to Strengthen Verification This Week

  1. Set exchange thresholds in your software. Done looks like: €6,000 and €15,000 triggers fire automatically without manual entry.
  2. Enable linked-transaction alerts. Done looks like: the system flags cumulative exchanges from the same customer across visits, not just single transactions.
  3. Adopt an eIDAS-capable remote ID method. Done looks like: your vendor documentation confirms high or substantial assurance level.
  4. Log and store verification evidence centrally. Done looks like: every ID check has a timestamped, retrievable record tied to the transaction.
  5. Train front-line staff on red flags. Done looks like: staff can name three structuring indicators without checking a manual.
  6. Schedule an internal audit. Done looks like: a calendar date is set, with a defined sample size and reviewer assigned.

If resources are tight, prioritize the threshold alerts and the audit log. Those two controls catch the most risk and are the first things a supervisor will ask to see.

What Changed When We Took Verification Seriously

Fewer suspicious transactions slip through when verification runs on rules instead of memory. Automating the linked-transaction check was the single change that mattered most. Before, catching a customer splitting exchanges across three visits depended on a teller happening to recognize a face. After, the system flagged it on the second visit, every time.

Operator's hands near dark office screen with alert glow

The lesson worth passing on: audit trails matter more than most operators expect until the day a supervisor actually requests one. A verification process that only lives in a teller's judgment produces nothing to show an auditor. A verification process built into software produces a timestamped record for every decision. If you're prioritizing one change, make it automated threshold and linked-transaction alerts, everything else in a strong compliance program builds on that foundation.

How Currexchanger Turns Verification Rules Into Daily Practice

Every control covered above, threshold alerts, document capture, PEP screening, audit logs, has to live somewhere operational, not just in a policy document. Currexchanger is built specifically for currency exchange operators who need those controls running automatically across every branch, not managed manually at each counter.

Currexchanger

The platform maps directly onto the checklist in this article: automated €6,000 and €15,000 threshold alerts, document verification integrated with third-party AML/KYC providers, PEP and sanctions screening built into onboarding, and immutable activity logs that give supervisors exactly the audit trail they'll ask for. Role-based permissions mean your MLRO sees escalations while front-line staff see only what they need for intake. Reporting functions generate the summaries a regulator or internal auditor expects without someone manually compiling spreadsheets. If you want to see how real-time liquidity and transaction data feed into these compliance workflows, the guide on tracking liquidity across currencies walks through the reporting side in more depth.

If your current setup relies on manual checks and disconnected spreadsheets, request a demo of Currexchanger and see how the platform handles threshold alerts and audit logging for a network your size.

Primary Sources for Operators and Supervisors

This article provides general regulatory information and does not substitute for advice from a qualified compliance professional or the Bank of Lithuania directly. Confirm current thresholds and procedural requirements with the primary legal sources before relying on them operationally.

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Sources

FAQ

What triggers mandatory customer identification in currency exchange?

Identification is required once a cash exchange exceeds €6,000 in a single transaction or in linked transactions, with heightened obligations applying at €15,000 under Lithuanian AML law.

Yes, provided the method delivers high or substantial assurance, such as eIDAS-qualified electronic signatures or video identification with confirmed facial matching.

What is the difference between CDD, EDD, and SDD?

CDD is standard identity verification applied to most customers, EDD adds extra scrutiny for high-risk factors like PEP status, and SDD applies reduced measures for genuinely low-risk, low-value transactions.

How long must verification records be kept?

Records must be retained for the statutory AML retention period, with encryption and access controls in place throughout, and anonymized or deleted once that period ends without an open investigation.

Can software help operators meet these verification requirements?

Yes. Platforms like Currexchanger automate threshold alerts, document verification, PEP screening, and audit logging so compliance evidence is generated as part of the transaction rather than reconstructed afterward.