Compliance

Understanding KYC and Identity Providers for Remittance

Identity verification and screening are two different purchases. How the approaches differ, what to ask, why costs overrun, and what makes switching provider possible later.

Two different jobs that get confused

Most operators talk about “KYC providers” as one category. In practice you are buying two distinct things, and conflating them causes both compliance gaps and wasted spend.

Identity verification answers a question at onboarding: is this person who they claim to be? Screening and monitoring answers a question continuously: is this person, or this transaction, something my firm should be concerned about? A provider excellent at the first may not perform the second at all.

The three verification approaches

Document-based verification

The customer photographs an identity document; the service assesses whether it is genuine and, usually with a selfie, whether the person presenting it matches. Strong where documents are the norm and the customer has a smartphone. Weaker where document quality varies or the customer base spans many unusual document types, which drives up manual review.

Database and record checks

The identity is checked against authoritative records rather than an image. Fast and low-friction where good data exists, and it avoids the failure modes of photography entirely. Coverage varies significantly by country, which is precisely why some operators run this as primary in some markets and secondary in others.

Biometric verification

Usually layered on top of document capture as a liveness and matching check. It addresses the specific attack of someone presenting a genuine document that is not theirs.

Screening is a separate control

Sanctions and politically exposed person screening is not the same purchase as identity verification, and it does not stop at onboarding. Lists change, and a customer who was clear in January may not be in June. Your obligations here run continuously.

Screening should cover the relevant lists for your business — for a UK operator that typically means HM Treasury, OFAC, UN and EU as a baseline — and needs to produce an auditable record of what was checked, when, and what was decided. That record is what a supervisor asks for.

What to ask an identity provider

  • What is your coverage for the nationalities my customers actually hold? Not the country list — the document types your specific customer base carries.
  • What proportion of checks go to manual review, for a customer base like mine? This is the number that determines your operational cost and your onboarding drop-off.
  • How is pricing structured? Per check, per successful check, tiered, minimum commitments. Re-verification and repeat attempts can quietly multiply the cost.
  • What evidence do you return, and in what form? You need to store it and produce it later.
  • Do you provide ongoing screening, or only onboarding checks? If only the latter, you need a second arrangement.
  • What happens when a check fails? Retry policy, appeal path and cost.

The cost model most operators get wrong

Identity checks are priced per attempt far more often than per customer. A customer who fails twice and succeeds on the third try may cost three times what you budgeted. In corridors where document quality is variable, that difference is material rather than marginal.

Ask for pricing modelled on realistic first-time pass rates for your customer base, not on a best case. And model the manual review labour separately — that cost is yours, not the provider's.

Onboarding friction is a commercial decision

Every additional verification step reduces fraud and reduces conversion. Setting that balance is a business decision informed by compliance requirements, not a purely technical one. A risk-based approach — lighter checks at low value, stepping up as the relationship grows — is generally expected by supervisors and usually better commercially than treating every customer identically.

What matters is that the approach is documented, applied consistently, and evidenced. An undocumented risk-based approach looks indistinguishable from an inconsistent one.

Changing provider later

Operators do change identity providers, usually because manual review load or cost has grown. Two things make that easier: your historic verification records must remain accessible in your own platform rather than living only in the provider's system, and your platform should treat the provider as a configurable component rather than something hard-wired into the customer journey.

If switching provider would mean a development project, you are locked in more tightly than you may realise. Worth establishing before you sign with either the provider or the software vendor.

How this connects to your platform

Your platform orchestrates the check within the customer journey, records the outcome in an audit trail retained for your regulatory retention period, routes failed and referred cases to a compliance queue a human can work, and runs screening alongside it. The identity provider does the verification; the platform has to make the result usable and defensible.

Frequently Asked Questions

What is the difference between identity verification and sanctions screening?
Identity verification answers whether someone is who they claim to be, usually once at onboarding. Sanctions and PEP screening asks whether that person or transaction is a concern, and continues throughout the relationship because lists change. They are separate controls and most operators need both.
Can I change KYC provider after launch?
Yes, and operators commonly do as volumes and costs change. It is straightforward if your historic verification records live in your own platform rather than only in the provider's system, and if your platform treats the provider as a configurable component rather than hard-wiring it into the customer journey.
Why do KYC costs run higher than budgeted?
Checks are usually priced per attempt rather than per customer, so a customer who fails twice before succeeding can cost three times the assumed amount. In corridors where document quality varies this is material. Ask for pricing modelled on realistic first-time pass rates, and budget manual review labour separately.
Does Remitz perform the identity checks?
No. Verification is performed by your chosen provider under your own agreement, using your credentials. Remitz orchestrates the check within the customer journey, records the outcome in the audit trail, and routes referred cases to a compliance queue your team can work.

Where Remitz fits

Remitz is software. We do not provide banking, payout, KYC, payment gateway or licensing services — you hold each of those relationships directly. What we provide is a white-label platform with production-tested connectors to providers like the ones described above, so connecting the partners you choose is configuration rather than a development project.

Book a 15-minute demo See the integration catalogue
Get Started Today

Ready to Launch Your Remittance Business?

Book a demo and discover how Remitz can power your money transfer operations.