
The KYC market has a definition problem.
Every year, regulated financial institutions run procurement processes labelled "KYC solution." They receive proposals from identity verification specialists, document reading platforms, and BPO operators who handle document review at volume. All of these vendors solve real operational problems. None of them deliver a Know Your Customer (KYC) compliance program. The confusion is not semantic: it is a structural gap that regulators are increasingly equipped to identify, and with the Anti-Money Laundering Regulation (AMLR), which applies from July 2027, the cost of that confusion is about to become auditable.
Key takeaways
- "KYC" and "identity verification" are not synonyms. A regulated KYC process has at least eight distinct stages, each carrying its own traceability obligation. Document verification covers the first two. The other six remain entirely unaddressed by an IDV tool.
- IDV specialists stop at identity. Compliance starts after the document is verified. AML screening, risk scoring, Ultimate Beneficial Owner (UBO) graph mapping, Enhanced Due Diligence (EDD), and ongoing monitoring are outside the architectural scope of an identity verification tool, by design.
- BPOs add human bandwidth to the same incomplete process. Manual document review at scale has operational value. It produces no structured audit trail, no configurable risk scoring engine, and no automated periodic review capability.
- KYC is not a linear sequence. It is a continuous, event-driven process. Any new piece of information, a UBO change, an adverse media hit, a transaction anomaly, can reopen any stage at any time. Point tools built for one-time checks cannot handle this. See our views on KYCÂ monitoring.Â
- AMLR 2027 makes every compliance parameter an institutional liability. Regulated entities must document, justify, and own every compliance decision. "Our vendor handled it" is not an auditable answer to a regulator.
- The gap between document verification and KYC orchestration is architectural, not functional. It cannot be closed by adding more point solutions or more headcount. It requires a dedicated orchestration layer built on a compliance system of record.
What does a regulator actually mean by KYC?
The term KYC is used in two distinct ways in the market. The first is colloquial: any process involving a check on who a person is. The second is regulatory: the full set of obligations a supervised institution must fulfill before entering into a business relationship, and throughout the life of that relationship.
Regulators use the second definition. The Financial Action Task Force (FATF) Recommendations, the EU's fifth and sixth Anti-Money Laundering Directives (AMLD5/AMLD6), and the upcoming AMLR describe KYC as a multi-step, continuously maintained compliance process. Financial crime compliance already costs financial institutions $274.1 billion globally (LexisNexis Risk Solutions, 2023). A large share of that cost is driven by fragmented, manual processes built around point tools that cover only the front end of a much larger obligation.
In practice, a compliant KYC / Know Your Business (KYB) program covers eight distinct stages:
- Collection: Gathering identifying information and documentation from the customer or corporate entity
- Identity verification (IDV): Confirming the person is who they claim to be, using certified methods
- UBO mapping: Identifying and verifying the chain of Ultimate Beneficial Ownership (UBO) for legal entities
- AML screening: Checking all parties against sanctions lists, Politically Exposed Person (PEP) registers, and adverse media sources
- Risk scoring: Classifying the customer based on a configurable, institution-owned risk matrix
- Enhanced Due Diligence (EDD): Applying additional scrutiny to higher-risk profiles, triggered automatically on defined conditions
- Compliance decision: Approving or rejecting the relationship, with documented rationale
- Ongoing monitoring and periodic review: Continuously reassessing the risk profile throughout the customer lifecycle
Every one of these stages generates obligations. Specific data must be collected and retained. Decisions must be documented and traceable. Parameters must be configurable and defensible by the institution itself. Document verification handles step 2. Sometimes step 1. The other six are left for someone else to solve.
These eight stages are not a waterfall. This is the most common mistake in how institutions design their compliance programs, and how vendors sell to them. A real KYC program is not a sequence you run once at onboarding. It is a cloud of conditional tasks that responds continuously to new information. A UBO structure change in year three reopens step 3. An adverse media alert reopens step 4 and may trigger step 6. A product change by the institution reopens steps 5 and 7 for entire customer segments. Any tool, or any BPO, built on the assumption that KYC is a linear onboarding process will fail the moment real-world complexity kicks in.
Where do IDV specialists actually stop?
Identity Document Verification (IDV) providers answer one question: is this person who they say they are? They capture a document, extract data, run liveness checks, and return a signal. The best of them are certified: in France, providers operating under the PVID (Prestataire de Vérification d'Identité à Distance) standard carry ANSSI accreditation and satisfy the eIDAS Level of Assurance Substantial requirement. That certification matters. It is also scoped precisely and narrowly to identity.
An IDV tool does not know your institution's risk appetite. It cannot apply your risk matrix. It does not screen the verified individual against Office of Foreign Assets Control (OFAC), UN, or EU consolidated lists. It does not map UBO structures. It does not trigger EDD based on a PEP flag or a complex ownership chain. It does not produce a compliance decision. It produces a biometric match score and a document validation result.
The compliance decision that follows that result belongs to your institution. Regulators require you to justify every parameter applied to that decision: which lists were screened, at what matching threshold, who reviewed the flag, what EDD was applied and why. None of that lives inside an IDV tool.
Critically, an IDV tool is built for a single moment in time: the onboarding check. It has no state. It does not know what happened to the customer last month, cannot react to a sanctions list update tonight, and cannot flag that the document it verified two years ago has now expired. This is not a feature gap. It is an architectural choice. IDV tools are designed to answer a one-time question. KYC is a continuous obligation.
When a regulated institution selects an IDV provider and calls it a KYC solution, it has solved for step 2 of 8. The remaining six obligations exist as an unaddressed liability, sitting in email inboxes, spreadsheets, and the individual judgment of compliance officers.
What does a BPO add? And what does it leave broken?
A Business Process Outsourcer (BPO) applied to KYC adds human reviewers to the document verification layer. Analysts read documents, flag anomalies, and route cases to internal compliance teams. This solves a genuine problem: document review at volume is time-consuming, and skilled human judgment catches edge cases that automated systems miss.
It solves exactly that problem. No others.
Here is what structurally breaks when a regulated institution relies on document verification providers, a BPO layer, or a combination of both as its KYC infrastructure:
- No structured AML screening. Sanctions and PEP checks happen ad hoc, if at all, without a configurable matching threshold or a documented decision trail.
- No risk scoring engine. Customer risk classification depends on individual analyst judgment, not on a reproducible, auditable matrix owned by the compliance team.
- No UBO orchestration. Beneficial ownership structures are collected in documents but not modeled, verified against registries, or kept current over time.
- No automated EDD trigger. High-risk profiles are escalated informally, with no systematic rule governing when EDD is required and what it must contain.
- No legal events monitoring. Corporate entities change status continuously: insolvency proceedings, liquidations, ownership transfers. A BPO reads documents at a point in time. It does not monitor the live legal state of entities across your portfolio.
- No discrepancy flagging against official sources. When a customer declares ownership data that contradicts what the official registry holds, an automated platform flags it immediately. Human reviewers working from documents do not have the bandwidth to cross-reference every data point against live registry data at the time of review, let alone on an ongoing basis.
- No screening hit resolution workflow. When a PEP match or sanctions hit is raised, it must be investigated, validated, documented, and resolved in a traceable way. A BPO handles this through email escalations and notes. That process produces no audit trail a regulator can examine.
- No audit trail. The history of decisions, flags, and reviews lives across email threads, shared drives, and case notes. It is not exportable, not timestamped at the decision level, and not defensible in a regulatory examination.
- No periodic review. Customer files are not automatically flagged when documents expire, ownership structures change, or regulatory thresholds are crossed.
- No scalability. Every increase in volume requires proportional headcount. There is no automation lever to pull.
Beyond these operational failures, there is a structural regulatory problem that is often overlooked: when compliance data is scattered across a BPO's case management system, an IDV vendor's portal, a screening tool's weekly export, and a CRM, the institution cannot present a coherent, unified view of any single customer to a regulator. Risk is not assessed by looking at individual data points in isolation. It is assessed by reading the coherence of signals across a client's full history. Regulators are beginning to sanction not just bad individual compliance decisions, but the structural impossibility of having that coherent view when there is no central system to hold it. A fragmented compliance stack is itself a supervisory risk.
Why does AMLR 2027 turn this gap into an urgent problem?
Bruna Szego, Chair of the EU's Anti-Money Laundering Authority (AMLA), was direct about the cause of the problem the regulation is designed to fix:
The AMLR (EU Regulation 2024/1624), applicable from July 2027, is the EU's structural response. For regulated institutions, the parallel obligation is clear: a fragmented compliance stack produces the same cracks, on the operational side.
The AMLR does not introduce new obligations so much as it removes ambiguity from existing ones and makes them directly enforceable across all EU member states (European Parliament, 2024). Three provisions land directly on the gap described above.
Traceability of compliance parameters. Every screening parameter applied to a customer file, including the lists consulted, the matching thresholds used, and the alerts reviewed, must be documented and attributable to the institution. Delegating those parameters to a vendor configuration the institution does not control is not compliant.
Significantly tightened customer identification requirements. The AMLR substantially narrows the conditions under which Simplified Due Diligence (SDD) applies, making customer identification near-universal in practice. Institutions that have relied on broad low-risk exemptions to defer or reduce onboarding controls will need to revisit their programs. Volume will increase. Institutions without an automated IDV path embedded inside an orchestrated compliance flow will absorb that volume manually.
Beneficial ownership verification. The AMLR sharpens UBO verification requirements. Multi-level ownership structures must be verified, not just declared. This is a process that requires registry access, a data model capable of representing complex structures, and a traceable decision for each level of the ownership chain. It is not a document reading task.
Each of these requirements points to the same structural conclusion: regulated institutions need a compliance orchestration layer, not a collection of point tools.
What does KYC system of record actually look like in production?
The shift becomes concrete in production. Across French regulated institutions that have replaced fragmented compliance stacks with a dedicated orchestration layer, onboarding time drops from an average of 1.5 days to under 30 minutes for business onboarding. Time spent by compliance teams on KYB operations falls by 58%. Automation rates reach 85% or above, with the remaining 15% routed to human reviewers for genuinely complex cases, because there will always be decisions where human judgment is required and where no automation should substitute for it (Ondorse, 2026).
The orchestration platform holds the compliance decision layer: the risk matrix, the screening configuration, the EDD trigger rules, the audit trail, the periodic review schedule. Point tools feed data into it. Every decision, automated or human, is traceable, timestamped, and exportable on demand. This is what regulators examine. Not whether documents were collected, but whether the institution can demonstrate a structured, reproducible, configurable compliance process for every customer in its portfolio, at any point in time.
So what should a compliance team actually ask when evaluating KYC vendors?
The right question is not "Does this vendor do KYC?" Every vendor in the market will answer yes. The right questions are organized around the six functional domains a real compliance operations platform must cover:
Customer interface and onboarding
- Does the platform support adaptive onboarding that adjusts data and document requirements based on entity type, jurisdiction, and risk level, without IT involvement?
- Can the portal be reopened at any point in the customer lifecycle to request additional information or run a KYC refresh?
AML and entity controls
- Does the platform cross-reference declared data against official registries and flag discrepancies automatically?
- Does it map complete shareholding structures, including multi-level UBO chains, and trace beneficial ownership to ultimate natural persons?
- Does it monitor legal events, including insolvency proceedings and ownership changes, on an ongoing basis?
AML screening
- Which lists are screened (OFAC, EU, UN, domestic), at what matching threshold, and who configures those parameters?
- Does the platform provide a documented, auditable screening hit resolution workflow, inside the platform, not via email?
- Does it alert automatically when an existing customer or related party newly appears on a PEP list or sanctions database?
Risk scoring and decision
- Is the risk scoring engine configurable by the compliance team without IT dependency?
- Who holds the compliance decision layer: the vendor or the institution?
Audit and reporting
- Can the full audit trail, including every decision, parameter, and reviewer action, be exported to a regulator on request?
- Is every decision timestamped and traceable to a named parameter and a named individual?
Ongoing monitoring and periodic review
- What happens at periodic review time, at scale, without adding headcount?
- When the risk profile of a customer changes mid-lifecycle, which system owns that event and routes it correctly?
An IDV specialist answers none of these questions. A BPO answers some of them, informally, with human labor, and without a traceable output. A compliance orchestration platform is built to answer all of them.
To help your team structure this evaluation, Ondorse has published a free RFP template covering the full functional scope of a compliance operations platform, ready to send to vendors.
Ondorse is built as a compliance orchestration platform and the system of record for KYC data. Identity verification is handled by certified partners, including PVID-accredited providers for French-regulated institutions. The orchestration layer, covering risk scoring, AML screening, UBO mapping, EDD workflows, audit trail, and periodic review, sits inside the platform and is configurable directly by the compliance team, without IT involvement. Ondorse is not a router connecting existing point solutions. It is the system of record where compliance data lives in its proper context: organized around risk, not around commercial interactions. That distinction is what makes AI, automation, and third-party checks meaningful, because without a structured, risk-centered view of each customer, there is no context for any of those tools to operate in.
To see how the platform handles the full compliance cycle, visit ondorse.co/solutions. For further reading on how to structure your vendor evaluation, see How to choose the right compliance operations software.
Discover our latest guide
Everything you need to know about this subject
Heading
Subtextt
.jpeg)


