KYC Article

KYC has left the era of compliance. Welcome to the era of performance

Most identity verification teams are still measuring the wrong thing. Not because they’re careless, but because the industry was born to satisfy regulators, and the scoreboard never changed: pass rates, audit findings, whether or not you’ll be fined.

Our industry was born under the driver of complying with regulators. That origin story still shapes how most teams measure identity verification: pass rates, audit findings, whether or not you’ll be fined.

I think we are now in a different era – the era of performance. And in truth, it was always here. The regulator had a very specific problem in mind. It’s just that the compliance requirement has masked the actual performance we were expecting behind it.

That performance has always been the same thing: the least possible friction for the honest person, and the maximum possible friction for the fraudster. Everything else is implementation detail.

I discussed this recently on a Payments On Air panel with Chris Ampofo, CIO at Uphold. What follows is what I think the shift means in practice, and what I’d want to know if I were choosing an identity partner today.

Onboarding is not the point. The relationship is

A lot of businesses still look at KYC as an onboarding requirement. A gate you pass once.

The better way to look at it is that you are initiating a relationship, and building a platform where trust can reign. That reframe has two consequences.

First, once you’ve created a safe environment, there are barriers you can remove; costs you can cut much further down the line, because you already know who you’re dealing with.

Second, you have to think about the entire customer lifecycle. Onboarding opens the relationship, but there will be key moments where you want to rebuild trust: a high-risk transaction where you need to be sure you have the right person behind the account, a new device, a new payment method. Trust isn’t established once. It’s maintained.

When trust becomes a strategy and a growth lever rather than a box to tick, the whole conversation changes. I find that genuinely exciting, and I’m seeing it happen across many industries.

See how Uphold verifies customers for the life of the account.

Uphold’s team sat down with PYMNTS to talk through what continuous, lifecycle verification looks like in practice — and why one-time onboarding checks no longer hold. Read the interview 

The most expensive gap in the funnel

The gap between account creation and first funded transaction is where platforms lose the customers they paid the most to acquire.

Chris described the mechanics of it better than I could: a customer moving through multiple layers of checks from multiple providers, each asking for something more. “They can shift away from the screen to go and grab a passport, go and grab a driver’s license. By the time they come back, that screen has timed out, that process has timed out, and at that point you’ve lost them. They’ll shift to somewhere where it’s a lot easier and a lot quicker.”

In a volatile market the window is even narrower. When a bull run brings a rush of new users, verification that takes days means the moment has passed and they’ve gone elsewhere.

Modulating friction is the whole job

The way we model this at Veriff has two inputs.

On one side, the risk level the business faces in that specific flow or use case. On the other, the motivation of the person being verified.

If you’re applying for a loan, your motivation to get through the process is high. You can afford more friction there, and use it to bring a high level of guarantees. But if verification sits on your main acquisition channel, and you’ve spent precious dollars getting people into that funnel, then undue friction actively destroys the acquisition you just paid for. There, you need to be low-friction and smooth for all the traffic.

Chris put the user’s side of it well: consumers don’t mind friction, as long as it’s applied in the right place. Nobody objects to a pause when they link a new bank account. That pause gives an honest person a beat to think – and gives someone whose account has been taken over a chance to stop it.

Fine-tuning between those two dials is the alchemy. Light at the front door, heavier at the moments that warrant it.

Rejecting a good customer is a business problem, not a UX problem

False positives don’t get the airtime that fraud losses do. They should.

When you come from a compliance mindset, you’re addressing the regulator’s concern, and that concern is fraud. So most IDV assessment revolves around false approval rate. But false rejection rate is a big deal, and I hear it more and more on customer calls. One customer told me recently: “It’s 10 times a bigger business concern to reject a good person than to let a fraudster through.”

Consider a large ride-hailing platform with tens or hundreds of thousands of drivers. A false rejection rate that looks like a rounding error puts thousands of people on the phone to your contact center. It looks like friction you can live with — but this friction is almost always creating more friction for the business itself, and it can compound.

So the true performance of an identity provider is the false approval rate combined with the conversion rate they can guarantee. Two sides of the same number. Test for both.

Four questions I’d ask an identity provider

1. What does your architecture look like?

We believe trust is about architecture. Some providers aggregate: they don’t build the technology themselves, they integrate and cherry-pick from third parties depending on geography and use case. Others are more vertically integrated and own more of the stack.

Even a vertically integrated provider has to connect to third parties: wallets and digital identity schemes, for instance, aren’t things you build yourself. At Veriff we integrate with them. But there is a very different mindset between bringing data points into your verification plane and becoming smarter for it, and sending the biometric face of your customer out to a third party you have some control over, but not a lot.

Ask how much control your provider has over the full flow, and where your data goes at each step.

2. How do you learn, and from what data?

Detection quality depends on how fast you learn, and that depends on data. Quality first, and quantity as always with modern machine learning – but what you really want is coverage. A wide distribution.

Fraudsters are not only innovative, they’re extremely collaborative. There are Fraud-as-a-Service platforms where you can create an account and learn how to bypass checks on specific platforms. When you use a shared verification platform, you start playing the same game: the more industries on the same platform, the faster we learn, and the faster those learnings propagate across industries and customers.

3. Do you support global expansion, or just operate globally?

This is a crucial difference. Local providers can give you higher accuracy in their own market. But stitching together many of them leaves you with two bad options: dumb everything down to an abstraction so you can compare performance apples to apples, or get the most from each local player and live in integration and vendor hell.

Worse, it makes your own performance unknowable. The hardest thing in this business, and people don’t always realize it, is knowing your own performance. With two providers in two geographies, you can never compare them, so you can never tell which one is letting you down.

And global coverage isn’t optional even for single-market businesses. You may operate only in the US, but the people onboarding hold documents from everywhere.

3. How will you handle documents while everything else fragments?

There is a balkanization of identification means underway: digital ID, biometric registries, and documents all coexisting. Fraud always follows the path of least resistance, and documents remain the space where the most creativity gets applied to tampering and fabrication.

We’ll be verifying documents for a long time yet, until the world settles on a set of digital identities that work for everyone. That means fraud will keep concentrating on that vector, and it means computer vision and deepfake detection on the document itself still carry a lot of the load.

Will “verify once, trade everywhere” ever be universal?

Honestly? This is the golden grail, and I don’t know if it can be pulled off. Let me take the three obvious routes in turn.

Interoperable standards. Europe is working towards eIDAS 2, which suggests the first version didn’t fully meet the requirement, and it wouldn’t be crazy to imagine an eIDAS 3. In the US, where you’d expect interoperability within one country, the explosion of state-level standards is remarkable. So I wouldn’t bank on interoperability.

One universal wallet. We don’t all carry the same phone. We won’t all carry the same wallet.

Reusable identities generated by businesses that already verify at scale. Technically plausible. The obstacle is that even within one industry, companies have very different trust requirements — and identity verification is only a slice of a much bigger trust assessment that includes PEP and sanctions screening, adverse media, and AML checks. What one company considers a reusable verification, another won’t.

If I’m honest, the more digital identity schemes being operated in the world, the more fragmentation we see right now.

I do think there’s a middle ground coming: eIDAS may give us enough to work with in Europe, and some token-based schemes may carry enough of a trust definition for businesses to align to. But it’s far from clear how we crack it. Which means the practical move today is to build the unified identity record inside your own ecosystem and partner network rather than waiting for the industry to converge.

The compliance stack, in one place

None of this removes the obligations. It changes how you deliver them.

  • Customer identification programs give a firm a reasonable belief that it knows who its customer is. In the US these stem from Section 326 of the USA PATRIOT Act, implemented through Bank Secrecy Act regulations: a written program, four identifying data points for each individual customer (name, date of birth, address, identification number), risk-based verification procedures, record-keeping, procedures to compare customers against any designated government list, and customer notices.
  • Customer due diligence evaluates the risk of the relationship using the customer, sanctions lists, and public and private data sources — at simplified, standard, or enhanced level. Matching that level to the customer is the compliance version of friction modulation.
  • Ongoing monitoring keeps accounts, transactions, and risk profiles under review in real time. This is what lets you keep the front door light, because scrutiny can be applied later and precisely.
  • KYB applies the same discipline to corporate accounts: company vitals, ownership structure, ultimate beneficial owners, then AML/KYC checks on those owners.
  • eKYC and mobile KYC are how all of the above gets delivered now; digitally, in the flow, with mobile signals adding a layer of authentication rather than a layer of friction.

Two things to take away

Be clear on the risk level you’re facing, and make sure the level of friction matches the situation. It’s all friction modulation.

And if the goal is trust as a growth lever, understand what underpins that trust; specifically the architecture and the data flow that let you make a confident decision. That’s the part that’s easy to skip and expensive to get wrong.

At Veriff, that’s the principle we build on: technology built and owned in-house, from biometrics to OCR, which removes the need for third-party black boxes in your verification flow. 12,500+ document specimens across 230+ countries and territories, an average decision in 6 seconds, and one accountable partner for the full stack.

If you’d like to see what that looks like in your funnel, book a demo.

Take the next step

  1. Stay ahead of fraud trends. Subscribe to our newsletter for the latest research, data, and industry insights.
  2. See Veriff in action. Try the Identity Verification live demo and experience exactly what your users see.
  3. Talk to our team. Book a personalized demo and get answers to your specific questions.

Subscribe for insights

CTA form illustration

Start building with Veriff for free

Your journey toward faster, more accurate identity verification starts here.