Two different jobs that get confused
Most operators talk about “KYC providers” as one category. In practice you are buying two distinct things, and conflating them causes both compliance gaps and wasted spend.
Identity verification answers a question at onboarding: is this person who they claim to be? Screening and monitoring answers a question continuously: is this person, or this transaction, something my firm should be concerned about? A provider excellent at the first may not perform the second at all.
The three verification approaches
Document-based verification
The customer photographs an identity document; the service assesses whether it is genuine and, usually with a selfie, whether the person presenting it matches. Strong where documents are the norm and the customer has a smartphone. Weaker where document quality varies or the customer base spans many unusual document types, which drives up manual review.
Database and record checks
The identity is checked against authoritative records rather than an image. Fast and low-friction where good data exists, and it avoids the failure modes of photography entirely. Coverage varies significantly by country, which is precisely why some operators run this as primary in some markets and secondary in others.
Biometric verification
Usually layered on top of document capture as a liveness and matching check. It addresses the specific attack of someone presenting a genuine document that is not theirs.
Screening is a separate control
Sanctions and politically exposed person screening is not the same purchase as identity verification, and it does not stop at onboarding. Lists change, and a customer who was clear in January may not be in June. Your obligations here run continuously.
Screening should cover the relevant lists for your business — for a UK operator that typically means HM Treasury, OFAC, UN and EU as a baseline — and needs to produce an auditable record of what was checked, when, and what was decided. That record is what a supervisor asks for.
What to ask an identity provider
- What is your coverage for the nationalities my customers actually hold? Not the country list — the document types your specific customer base carries.
- What proportion of checks go to manual review, for a customer base like mine? This is the number that determines your operational cost and your onboarding drop-off.
- How is pricing structured? Per check, per successful check, tiered, minimum commitments. Re-verification and repeat attempts can quietly multiply the cost.
- What evidence do you return, and in what form? You need to store it and produce it later.
- Do you provide ongoing screening, or only onboarding checks? If only the latter, you need a second arrangement.
- What happens when a check fails? Retry policy, appeal path and cost.
The cost model most operators get wrong
Identity checks are priced per attempt far more often than per customer. A customer who fails twice and succeeds on the third try may cost three times what you budgeted. In corridors where document quality is variable, that difference is material rather than marginal.
Ask for pricing modelled on realistic first-time pass rates for your customer base, not on a best case. And model the manual review labour separately — that cost is yours, not the provider's.
Onboarding friction is a commercial decision
Every additional verification step reduces fraud and reduces conversion. Setting that balance is a business decision informed by compliance requirements, not a purely technical one. A risk-based approach — lighter checks at low value, stepping up as the relationship grows — is generally expected by supervisors and usually better commercially than treating every customer identically.
What matters is that the approach is documented, applied consistently, and evidenced. An undocumented risk-based approach looks indistinguishable from an inconsistent one.
Changing provider later
Operators do change identity providers, usually because manual review load or cost has grown. Two things make that easier: your historic verification records must remain accessible in your own platform rather than living only in the provider's system, and your platform should treat the provider as a configurable component rather than something hard-wired into the customer journey.
If switching provider would mean a development project, you are locked in more tightly than you may realise. Worth establishing before you sign with either the provider or the software vendor.
How this connects to your platform
Your platform orchestrates the check within the customer journey, records the outcome in an audit trail retained for your regulatory retention period, routes failed and referred cases to a compliance queue a human can work, and runs screening alongside it. The identity provider does the verification; the platform has to make the result usable and defensible.
Frequently Asked Questions
Where Remitz fits
Remitz is software. We do not provide banking, payout, KYC, payment gateway or licensing services — you hold each of those relationships directly. What we provide is a white-label platform with production-tested connectors to providers like the ones described above, so connecting the partners you choose is configuration rather than a development project.