Two different jobs that get confused
Most operators talk about “KYC providers” as one category. In practice you are buying two distinct things, and conflating them causes both compliance gaps and wasted spend.
Identity verification answers a question at onboarding: is this person who they claim to be? Screening and monitoring answers a question continuously: is this person, or this transaction, something my firm should be concerned about? A provider excellent at the first may not perform the second at all.
The three verification approaches
Document-based verification
The customer photographs an identity document; the service assesses whether it is genuine and, usually with a selfie, whether the person presenting it matches. Strong where documents are the norm and the customer has a smartphone. Weaker where document quality varies or the customer base spans many unusual document types, which drives up manual review.
Database and record checks
The identity is checked against authoritative records rather than an image. Fast and low-friction where good data exists, and it avoids the failure modes of photography entirely. Coverage varies significantly by country, which is precisely why some operators run this as primary in some markets and secondary in others.
Biometric verification
Usually layered on top of document capture as a liveness and matching check. It addresses the specific attack of someone presenting a genuine document that is not theirs.
Screening is a separate control
Sanctions and politically exposed person screening is not the same purchase as identity verification, and it does not stop at onboarding. Lists change, and a customer who was clear in January may not be in June. Your obligations here run continuously.
Your compliance team should define the applicable sanctions and PEP sources, screening frequency, review process and record retention. Ask the provider to demonstrate coverage and list updates; a generic list of jurisdictions is not a complete compliance policy.
What to ask an identity provider
- What is your coverage for the nationalities my customers actually hold? Not the country list — the document types your specific customer base carries.
- What proportion of checks go to manual review, for a customer base like mine? This is the number that determines your operational cost and your onboarding drop-off.
- How is pricing structured? Per check, per successful check, tiered, minimum commitments. Re-verification and repeat attempts can quietly multiply the cost.
- What evidence do you return, and in what form? You need to store it and produce it later.
- Do you provide ongoing screening, or only onboarding checks? If only the latter, you need a second arrangement.
- What happens when a check fails? Retry policy, appeal path and cost.
The cost model most operators get wrong
Identity checks are priced per attempt far more often than per customer. A customer who fails twice and succeeds on the third try may cost three times what you budgeted. In corridors where document quality is variable, that difference is material rather than marginal.
Ask for pricing modelled on realistic first-time pass rates for your customer base, not on a best case. And model the manual review labour separately — that cost is yours, not the provider's.
Onboarding friction is a commercial decision
Verification design affects customer friction and fraud controls, but an extra step does not automatically make the process safer. Your compliance team must define a proportionate, lawful approach and test it against actual customer and risk profiles.
What matters is that the approach is documented, applied consistently, and evidenced. An undocumented risk-based approach looks indistinguishable from an inconsistent one.
Changing provider later
Operators do change identity providers, usually because manual review load or cost has grown. Two things make that easier: your historic verification records must remain accessible in your own platform rather than living only in the provider's system, and your platform should treat the provider as a configurable component rather than something hard-wired into the customer journey.
A provider change may require development without necessarily creating unacceptable lock-in. Establish API access, export rights, historic evidence access, development costs and transition support before signing.
If you are considering either provider, review the Onfido integration questions or Trulioo connector overview. Confirm the particular checks and services you contract; neither a provider name nor a connector page establishes coverage. Use the integration readiness checklist to prepare your requirements.
How this connects to your platform
Your platform orchestrates the check within the customer journey, records the outcome in an audit trail retained for your regulatory retention period, routes failed and referred cases to a compliance queue a human can work, and runs screening alongside it. The identity provider does the verification; the platform has to make the result usable and defensible.
Frequently Asked Questions
Where Remitz fits
Remitz is software. We do not provide banking, payout, KYC, payment gateway or licensing services — you hold each of those relationships directly. Remitz provides the software and assesses your chosen providers against supported connectors. A compatible connection may reduce development work; API versions, services, configuration, testing and any additional work are agreed in your quotation. Provider fees remain separate.