What KYC requires
Know your customer (KYC) is the set of checks a regulated business carries out to be confident its customers are who they say they are, and to understand the risk they bring. Under the FATF standards, customer due diligence includes:
- identifying the customer and verifying that identity using reliable, independent sources;
- identifying the beneficial owner where the customer is a company or other arrangement;
- understanding the purpose of the relationship;
- ongoing monitoring, keeping information up to date and watching for activity that does not fit.
KYC is risk-based. Lower-risk products can use simplified checks, and higher-risk customers need enhanced ones. Many mobile-money and banking services use tiered KYC: basic verification opens an account with low limits, and fuller verification raises them.
eKYC is KYC done digitally and remotely, often on the customer's phone, instead of in a branch. It must meet the same standard as a branch check, while facing fraud that a person at a counter might have spotted.
How a digital identity check works
A typical eKYC journey has five steps:
- Notice and consent. The customer is told what will be collected, why, and for how long, before anything is captured.
- Document capture. The customer photographs their identity document. Image-quality checks reject blurred, cropped or glare-covered photos early.
- Document checks. Text is read automatically (optical character recognition, OCR), and the data is checked for consistency and expiry. Many passports and identity cards carry a machine-readable zone (MRZ), defined in an international standard (ICAO Doc 9303), with check digits that reveal typing or tampering errors.
- The person. A selfie or short video is compared with the document photo, and liveness checks confirm a real person is present (next lesson).
- Data checks. Where the law allows, details are confirmed against an authoritative source, such as a national population register. In Kenya this is the Integrated Population Registration System (IPRS). The phone number may be confirmed with a one-time passcode.
The results are combined into an outcome: approve, reject, or send to a person for review. A good system records every step, the evidence it used and who made the final decision.
Face matching and liveness
Face matching in eKYC is usually one-to-one verification: is the person in the selfie the same person as on the document? This is different from one-to-many identification, which searches a face against a whole database.
The system produces a similarity score, and a threshold turns it into a match or no match. As with name matching, this is a trade-off. A low threshold lets more impostors through (false matches); a high one rejects more genuine customers (false non-matches).
Liveness detection checks that the camera is seeing a real, present person, not a printed photo, a screen, a mask or a replayed video. These are called presentation attacks, and an international standard (ISO/IEC 30107) sets out how to test defences against them. Checks can be active (asking the person to turn their head or smile) or passive (analysing the image without asking).
Newer threats include deepfakes and injection attacks, where fake video is fed into the app without passing through the camera at all. Defending against them needs checks on the device and the video stream, not only on the face.
Face-matching accuracy can also differ across demographic groups. Independent testing by the US National Institute of Standards and Technology (NIST) has found such differences in many algorithms. Test on the population you actually serve, and give people a human route when the technology fails them.
The fraud eKYC must stop
Remote onboarding attracts particular kinds of fraud:
- Impersonation with a stolen or borrowed identity document.
- Forged or altered documents, including edited photos and details.
- Synthetic identities built from a mix of real and invented details.
- Duplicate identities: one person opening many accounts under different names, often the same face with different documents.
- Mule accounts: genuine people paid or pressured to open accounts that criminals then control.
Defences work in layers: document checks, face matching and liveness, checks against authoritative data, detection of the same face or document appearing in more than one application, and monitoring after the account is open.
Automated checks should support people, not replace them. A sensible design sets hard minimum scores that no setting can lower, sends uncertain cases to a trained reviewer, requires a second reviewer for high-risk decisions, and records the reason for every rejection.
Protecting people's data
eKYC collects some of the most sensitive data there is: identity documents, faces and, often, biometric templates. In Kenya, the Data Protection Act, 2019 treats biometric data as sensitive personal data, which carries stricter conditions. Good practice, and in many cases the law, calls for:
- a lawful basis and clear notice, with consent where it is required, before capture;
- data minimisation: collect only what the check needs;
- retention limits: keep data only as long as the law and the purpose require, then delete it;
- security: encryption, strict access control and a record of who viewed what;
- an impact assessment before processing that is likely to be high risk, which large-scale biometric processing usually is.
People also have rights over automated decisions. Kenya's Act, like many data protection laws, gives people a right not to be subject to decisions based solely on automated processing that significantly affect them, with limited exceptions. For eKYC, that means a real person should be able to review a rejection, and the customer should be told how to challenge it.
Saolix K2M, our eKYC product, is in pre-release. It records the customer's consent before any evidence is accepted, keeps its hard minimum scores in code, and leaves decisions to human reviewers, with a second reviewer for high-risk sessions. See the K2M page for details and the design simulator.
Ten questions
Answer all ten questions, then check your answers. You need 8 out of 10 to pass, and you can try as many times as you like. Your answers, progress and times are kept only in this browser.
Your certificate of completion
Enter your name as you want it to appear, then save the certificate as a PDF. In the print window, choose Save as PDF.
Saolix does not record who takes this course, so it cannot verify these certificates. The certificate confirms completion of a free self-paced course and is not an accredited qualification.