Trainee Identity Verification for CPF Funding: The New Obligation Under France's 2026 Anti-Fraud Law
A trainee enrolls in your course through Mon Compte Formation, draws on their CPF rights, and then a completely different person shows up on the first day — or nobody shows up at all, with the session still billed against an identity that never set foot in your premises or on your platform. This is exactly the kind of fraud targeted by the new identity verification requirement introduced by Law No. 2026-534 of 25 June 2026 on combating social and tax fraud. For a training provider, this isn’t a common-sense recommendation: it is now a condition for the funding itself to be released.
What the law actually says
Law No. 2026-534, enacted on 25 June 2026 and published in the Official Journal on 26 June 2026, entered into force on 27 June 2026 for most of its provisions — except those left to an implementing decree or whose entry into force is expressly deferred. Among its measures concerning vocational training, one now requires any provider drawing on CPF funds to verify the trainee’s identity at two distinct moments: at enrollment, and again on the first effective day of training.
This double check is not incidental. It responds to a fraud pattern identified as recurring by control services: an enrollment made under a borrowed or stolen identity, followed by the actual course being attended by someone else entirely, or by no one. Verifying identity only once, at enrollment, is no longer enough to shut down this kind of scheme — hence the requirement for a second checkpoint when the course actually starts.
The same law also introduces a mirror-image mechanism on the control side: it authorizes agents responsible for monitoring training providers to use a cover identity to test, under real conditions, the enrollment and tracking procedures of courses delivered remotely or with online enrollment. The message is consistent: lawmakers now expect providers to be able to demonstrate, with evidence, who is actually following their CPF-funded courses.
Two checkpoints, not one
In practice, the obligation breaks down into two sequences your enrollment process needs to cover:
- At enrollment, before the order is validated on Mon Compte Formation: the identity declared by the account holder must be confirmed through a traceable means, not just a checked box or an account number entered on a form.
- On the first effective day of training, whether delivered in person or remotely: a second check must establish that the person actually starting the course is indeed the one who enrolled, with the same level of traceability.
Without these two documented confirmations, the Caisse des Dépôts will not release payment for the session — a mechanism that echoes the logic already in place for missing the certification exam, where funding is now conditioned on specific milestones along the course, rather than being paid out on the strength of the initial enrollment alone.
Which verification methods: caution is warranted
Early legal analyses published after the law was enacted mention several technical routes for meeting this requirement: electronic identification, certified facial recognition, or a certified biometric device. These remain interpretations put forward by training-law practitioners, though, not an official, definitive list. The precise technical arrangements — which solutions are recognized, what level of assurance is required, what proof format has to be kept — depend on an implementing decree and, most likely, on specifications the Caisse des Dépôts will publish itself, along the same lines as what already exists for listing courses on EDOF.
In practice, for a small or mid-size provider, two habits limit the risk while waiting for this clarification:
- Don’t rush into a commercial tool marketed as “anti-fraud law compliant” before confirming that the solution actually matches the requirements of the forthcoming decree.
- Start documenting now, even simply, every identification step you already carry out — a time-stamped copy of an ID document at enrollment, a sign-in sheet with a visual check on day one — to have a solid base to build on once the technical framework is clarified.
The consequences of a breach
The absence of a documented identity check has a double effect, both financial and regulatory. On one side, it mechanically blocks payment from the Caisse des Dépôts, with the cash-flow strain that can cause if the problem is only spotted after the session ends. On the other, it exposes the provider to the new administrative fine regime introduced by the same law: a breach found can lead to an administrative fine issued directly by the authorities, with no prior criminal proceedings, on a scale mentioned at up to €4,000 per breach, increased by 50% for repeat offenses within the year.
A repeated, uncorrected breach can also feed into a CPF quality control review by the Caisse des Dépôts, with a risk that the whole set of sessions concerned — not just the single file under review — gets reclassified as a service-delivery anomaly.
What research says about authentication in remote training
Strong learner authentication isn’t a uniquely French concern: it has been an active research topic since the rise of distance training. A study by Alexandra Okada, Denise Whitelock, Wayne Holmes and Chris Edwards, “e-Authentication for online assessment: A mixed-method study”, published in 2019 in the British Journal of Educational Technology, analyzed feedback from 328 students who used an adaptive, trust-based authentication system (“TeSLA”) during online assessments. The authors found broadly positive acceptance of these systems among learners, provided the verification stays proportionate and is clearly explained — a useful lesson for a training provider that now has to build an identity check into its enrollment process without turning it into a deterrent for trainees acting in good faith.
How to prepare now
- Map your current enrollment process to identify where the two expected checkpoints naturally fit: CPF order validation and the actual start of training.
- Formalize a written procedure describing who checks what, at which moment, and how the proof is kept — a point that directly overlaps with the documents expected in a Qualiopi audit.
- Don’t over-invest in a technical solution before the implementing decree and the Caisse des Dépôts specifications are published.
- Add this file to your regulatory monitoring, alongside the other parts of the anti-fraud law, as part of the legal monitoring required under Indicator 23 of the Qualiopi framework.
- Link this check to the enrollment evidence already expected under Indicator 16 on certification exam enrollment, to avoid running separate paper trails for the same process.
Take action
Properly documenting trainee enrollment and follow-up is part of the evidence base expected by both the Caisse des Dépôts and a Qualiopi auditor. The Complete Kit Certif (€297, 14-day guarantee) provides the evidence tables and the regulatory-monitoring template to structure this documentation across all 32 indicators of the framework. If you’re just starting your training organization, the ebook Create Your Training Organization in 30 Days (€67) sets the right foundations from day one, and the Complete Pack (€347) bundles both resources.
Frequently asked questions
+Which training providers are affected by this identity verification requirement?
Any training provider that draws on CPF (personal training account) funds to finance all or part of a course, regardless of size or legal status. The measure specifically targets enrollments made through Mon Compte Formation; it does not, as such, apply to OPCO-funded courses or to contracts signed directly with an individual outside the CPF system.
+What happens if I don't verify a CPF trainee's identity?
Without a documented identity confirmation at enrollment and on the first day, the Caisse des Dépôts will not release payment for the session. On top of that, the provider is exposed to the administrative fine regime introduced by the same law, which can reach €4,000 per breach found, increased by 50% for repeat offenses.
+Which verification methods are accepted?
Early legal analyses published after the law was enacted mention electronic identification, certified facial recognition, or a certified biometric device. The precise list of recognized solutions and their technical requirements, however, still depend on an implementing decree and on specifications the Caisse des Dépôts is expected to publish — better not to invest in a tool before that official confirmation arrives.
+Does this replace the identity checks some providers were already doing?
No, it generalizes and formalizes them, adding a traceability requirement. A provider that already informally asked for an ID at enrollment now has to document that check at two specific moments — enrollment and the first day of training — and be able to justify it to the Caisse des Dépôts.