Logo Ondorse
Download brand assets
Solutions

SOLUTIONS

Business verification (KYB)

User verification (KYC)

OVERVIEW

All-in-one KYC/B

PLATFORM

Client onboarding

Case management

AML risk scoring

INTEGRATIONS

App marketplace

Use cases

FOR WHOM

For Ops

For Compliance

For Sales & CSM

Clients
Corporate banking
Credit and financing
Asset management
Insurance and health
PSPs & acquiring
Embedded finance
Platforms and marketplaces
Corporate banking

Manager.One

Tiime

Banque Delubac

iBanFirst

Credit and financing

Hokodo

CGLLS

Finfrog

Mobilize FS

Asset management

French Food Capital

Elvest (Ex-Inter Invest)

Natixis Investment Managers International

Insurance and health

Alan

PSPs & acquiring

SSP

HiPay

PayXpert

Smile & Pay

Embedded finance

Embed

Xpollens

Lemonway

Platforms and marketplaces

Kactus

SeDomicilier.fr

Evaneos

INDUSTRY
Resources

KNOWLEDGE

Blog

Guides

News

PRODUCT

Documentation

Integrations

Product updates

DEVELOPERS

API reference

Recipes

Integration guide

TRUST

Security

Trust center

Live status

SERVICES

CX outsourcing

List tracker

Coverage map

New - CarelineLog In
Get started
Blog

Article

May 12, 2026

Document verification is not a KYC program. It never was.

Aymeric Boëlle
Co-founder & President
5 min read
IN THIS ARTICLE
Example H2

ABOUT AUTHOR

Aymeric Boëlle
President and co-founder of Ondorse. Previously a regulatory lawyer. Tech is an acquired taste.

SHARE ARTICLE

Talk with an expert

The KYC market has a definition problem.

Every year, regulated financial institutions run procurement processes labelled "KYC solution." They receive proposals from identity verification specialists, document reading platforms, and BPO operators who handle document review at volume. All of these vendors solve real operational problems. None of them deliver a Know Your Customer (KYC) compliance program. The confusion is not semantic: it is a structural gap that regulators are increasingly equipped to identify, and with the Anti-Money Laundering Regulation (AMLR), which applies from July 2027, the cost of that confusion is about to become auditable.

Key takeaways

  • "KYC" and "identity verification" are not synonyms. A regulated KYC process has at least eight distinct stages, each carrying its own traceability obligation. Document verification covers the first two. The other six remain entirely unaddressed by an IDV tool.
  • IDV specialists stop at identity. Compliance starts after the document is verified. AML screening, risk scoring, Ultimate Beneficial Owner (UBO) graph mapping, Enhanced Due Diligence (EDD), and ongoing monitoring are outside the architectural scope of an identity verification tool, by design.
  • BPOs add human bandwidth to the same incomplete process. Manual document review at scale has operational value. It produces no structured audit trail, no configurable risk scoring engine, and no automated periodic review capability.
  • KYC is not a linear sequence. It is a continuous, event-driven process. Any new piece of information, a UBO change, an adverse media hit, a transaction anomaly, can reopen any stage at any time. Point tools built for one-time checks cannot handle this. See our views on KYC monitoring. 
  • AMLR 2027 makes every compliance parameter an institutional liability. Regulated entities must document, justify, and own every compliance decision. "Our vendor handled it" is not an auditable answer to a regulator.
  • The gap between document verification and KYC orchestration is architectural, not functional. It cannot be closed by adding more point solutions or more headcount. It requires a dedicated orchestration layer built on a compliance system of record.

What does a regulator actually mean by KYC?

The term KYC is used in two distinct ways in the market. The first is colloquial: any process involving a check on who a person is. The second is regulatory: the full set of obligations a supervised institution must fulfill before entering into a business relationship, and throughout the life of that relationship.

Regulators use the second definition. The Financial Action Task Force (FATF) Recommendations, the EU's fifth and sixth Anti-Money Laundering Directives (AMLD5/AMLD6), and the upcoming AMLR describe KYC as a multi-step, continuously maintained compliance process. Financial crime compliance already costs financial institutions $274.1 billion globally (LexisNexis Risk Solutions, 2023). A large share of that cost is driven by fragmented, manual processes built around point tools that cover only the front end of a much larger obligation.

In practice, a compliant KYC / Know Your Business (KYB) program covers eight distinct stages:

  1. Collection: Gathering identifying information and documentation from the customer or corporate entity
  2. Identity verification (IDV): Confirming the person is who they claim to be, using certified methods
  3. UBO mapping: Identifying and verifying the chain of Ultimate Beneficial Ownership (UBO) for legal entities
  4. AML screening: Checking all parties against sanctions lists, Politically Exposed Person (PEP) registers, and adverse media sources
  5. Risk scoring: Classifying the customer based on a configurable, institution-owned risk matrix
  6. Enhanced Due Diligence (EDD): Applying additional scrutiny to higher-risk profiles, triggered automatically on defined conditions
  7. Compliance decision: Approving or rejecting the relationship, with documented rationale
  8. Ongoing monitoring and periodic review: Continuously reassessing the risk profile throughout the customer lifecycle

Every one of these stages generates obligations. Specific data must be collected and retained. Decisions must be documented and traceable. Parameters must be configurable and defensible by the institution itself. Document verification handles step 2. Sometimes step 1. The other six are left for someone else to solve.

These eight stages are not a waterfall. This is the most common mistake in how institutions design their compliance programs, and how vendors sell to them. A real KYC program is not a sequence you run once at onboarding. It is a cloud of conditional tasks that responds continuously to new information. A UBO structure change in year three reopens step 3. An adverse media alert reopens step 4 and may trigger step 6. A product change by the institution reopens steps 5 and 7 for entire customer segments. Any tool, or any BPO, built on the assumption that KYC is a linear onboarding process will fail the moment real-world complexity kicks in.

Where do IDV specialists actually stop?

Identity Document Verification (IDV) providers answer one question: is this person who they say they are? They capture a document, extract data, run liveness checks, and return a signal. The best of them are certified: in France, providers operating under the PVID (Prestataire de Vérification d'Identité à Distance) standard carry ANSSI accreditation and satisfy the eIDAS Level of Assurance Substantial requirement. That certification matters. It is also scoped precisely and narrowly to identity.

An IDV tool does not know your institution's risk appetite. It cannot apply your risk matrix. It does not screen the verified individual against Office of Foreign Assets Control (OFAC), UN, or EU consolidated lists. It does not map UBO structures. It does not trigger EDD based on a PEP flag or a complex ownership chain. It does not produce a compliance decision. It produces a biometric match score and a document validation result.

The compliance decision that follows that result belongs to your institution. Regulators require you to justify every parameter applied to that decision: which lists were screened, at what matching threshold, who reviewed the flag, what EDD was applied and why. None of that lives inside an IDV tool.

Critically, an IDV tool is built for a single moment in time: the onboarding check. It has no state. It does not know what happened to the customer last month, cannot react to a sanctions list update tonight, and cannot flag that the document it verified two years ago has now expired. This is not a feature gap. It is an architectural choice. IDV tools are designed to answer a one-time question. KYC is a continuous obligation.

When a regulated institution selects an IDV provider and calls it a KYC solution, it has solved for step 2 of 8. The remaining six obligations exist as an unaddressed liability, sitting in email inboxes, spreadsheets, and the individual judgment of compliance officers.

What does a BPO add? And what does it leave broken?

A Business Process Outsourcer (BPO) applied to KYC adds human reviewers to the document verification layer. Analysts read documents, flag anomalies, and route cases to internal compliance teams. This solves a genuine problem: document review at volume is time-consuming, and skilled human judgment catches edge cases that automated systems miss.

It solves exactly that problem. No others.

Here is what structurally breaks when a regulated institution relies on document verification providers, a BPO layer, or a combination of both as its KYC infrastructure:

  • No structured AML screening. Sanctions and PEP checks happen ad hoc, if at all, without a configurable matching threshold or a documented decision trail.
  • No risk scoring engine. Customer risk classification depends on individual analyst judgment, not on a reproducible, auditable matrix owned by the compliance team.
  • No UBO orchestration. Beneficial ownership structures are collected in documents but not modeled, verified against registries, or kept current over time.
  • No automated EDD trigger. High-risk profiles are escalated informally, with no systematic rule governing when EDD is required and what it must contain.
  • No legal events monitoring. Corporate entities change status continuously: insolvency proceedings, liquidations, ownership transfers. A BPO reads documents at a point in time. It does not monitor the live legal state of entities across your portfolio.
  • No discrepancy flagging against official sources. When a customer declares ownership data that contradicts what the official registry holds, an automated platform flags it immediately. Human reviewers working from documents do not have the bandwidth to cross-reference every data point against live registry data at the time of review, let alone on an ongoing basis.
  • No screening hit resolution workflow. When a PEP match or sanctions hit is raised, it must be investigated, validated, documented, and resolved in a traceable way. A BPO handles this through email escalations and notes. That process produces no audit trail a regulator can examine.
  • No audit trail. The history of decisions, flags, and reviews lives across email threads, shared drives, and case notes. It is not exportable, not timestamped at the decision level, and not defensible in a regulatory examination.
  • No periodic review. Customer files are not automatically flagged when documents expire, ownership structures change, or regulatory thresholds are crossed.
  • No scalability. Every increase in volume requires proportional headcount. There is no automation lever to pull.

Beyond these operational failures, there is a structural regulatory problem that is often overlooked: when compliance data is scattered across a BPO's case management system, an IDV vendor's portal, a screening tool's weekly export, and a CRM, the institution cannot present a coherent, unified view of any single customer to a regulator. Risk is not assessed by looking at individual data points in isolation. It is assessed by reading the coherence of signals across a client's full history. Regulators are beginning to sanction not just bad individual compliance decisions, but the structural impossibility of having that coherent view when there is no central system to hold it. A fragmented compliance stack is itself a supervisory risk.

Why does AMLR 2027 turn this gap into an urgent problem?

Bruna Szego, Chair of the EU's Anti-Money Laundering Authority (AMLA), was direct about the cause of the problem the regulation is designed to fix:

“

In the past, fragmented rules and oversight and uneven enforcement created cracks in our system, cracks that criminals were quick to exploit.

Bruna Szego Chair of AMLA Read the full speech â†’

The AMLR (EU Regulation 2024/1624), applicable from July 2027, is the EU's structural response. For regulated institutions, the parallel obligation is clear: a fragmented compliance stack produces the same cracks, on the operational side.

The AMLR does not introduce new obligations so much as it removes ambiguity from existing ones and makes them directly enforceable across all EU member states (European Parliament, 2024). Three provisions land directly on the gap described above.

Traceability of compliance parameters. Every screening parameter applied to a customer file, including the lists consulted, the matching thresholds used, and the alerts reviewed, must be documented and attributable to the institution. Delegating those parameters to a vendor configuration the institution does not control is not compliant.

Significantly tightened customer identification requirements. The AMLR substantially narrows the conditions under which Simplified Due Diligence (SDD) applies, making customer identification near-universal in practice. Institutions that have relied on broad low-risk exemptions to defer or reduce onboarding controls will need to revisit their programs. Volume will increase. Institutions without an automated IDV path embedded inside an orchestrated compliance flow will absorb that volume manually.

Beneficial ownership verification. The AMLR sharpens UBO verification requirements. Multi-level ownership structures must be verified, not just declared. This is a process that requires registry access, a data model capable of representing complex structures, and a traceable decision for each level of the ownership chain. It is not a document reading task.

Each of these requirements points to the same structural conclusion: regulated institutions need a compliance orchestration layer, not a collection of point tools.

What does KYC system of record actually look like in production?

The shift becomes concrete in production. Across French regulated institutions that have replaced fragmented compliance stacks with a dedicated orchestration layer, onboarding time drops from an average of 1.5 days to under 30 minutes for business onboarding. Time spent by compliance teams on KYB operations falls by 58%. Automation rates reach 85% or above, with the remaining 15% routed to human reviewers for genuinely complex cases, because there will always be decisions where human judgment is required and where no automation should substitute for it (Ondorse, 2026).

“

Before Ondorse, balancing a seamless customer experience with regulatory compliance was a constant challenge. Every new regulatory requirement added complexity to our onboarding process.

Hadjer Bouzid Senior Compliance Manager at Smile & Pay

The orchestration platform holds the compliance decision layer: the risk matrix, the screening configuration, the EDD trigger rules, the audit trail, the periodic review schedule. Point tools feed data into it. Every decision, automated or human, is traceable, timestamped, and exportable on demand. This is what regulators examine. Not whether documents were collected, but whether the institution can demonstrate a structured, reproducible, configurable compliance process for every customer in its portfolio, at any point in time.

So what should a compliance team actually ask when evaluating KYC vendors?

The right question is not "Does this vendor do KYC?" Every vendor in the market will answer yes. The right questions are organized around the six functional domains a real compliance operations platform must cover:

Customer interface and onboarding

  • Does the platform support adaptive onboarding that adjusts data and document requirements based on entity type, jurisdiction, and risk level, without IT involvement?
  • Can the portal be reopened at any point in the customer lifecycle to request additional information or run a KYC refresh?

AML and entity controls

  • Does the platform cross-reference declared data against official registries and flag discrepancies automatically?
  • Does it map complete shareholding structures, including multi-level UBO chains, and trace beneficial ownership to ultimate natural persons?
  • Does it monitor legal events, including insolvency proceedings and ownership changes, on an ongoing basis?

AML screening

  • Which lists are screened (OFAC, EU, UN, domestic), at what matching threshold, and who configures those parameters?
  • Does the platform provide a documented, auditable screening hit resolution workflow, inside the platform, not via email?
  • Does it alert automatically when an existing customer or related party newly appears on a PEP list or sanctions database?

Risk scoring and decision

  • Is the risk scoring engine configurable by the compliance team without IT dependency?
  • Who holds the compliance decision layer: the vendor or the institution?

Audit and reporting

  • Can the full audit trail, including every decision, parameter, and reviewer action, be exported to a regulator on request?
  • Is every decision timestamped and traceable to a named parameter and a named individual?

Ongoing monitoring and periodic review

  • What happens at periodic review time, at scale, without adding headcount?
  • When the risk profile of a customer changes mid-lifecycle, which system owns that event and routes it correctly?

An IDV specialist answers none of these questions. A BPO answers some of them, informally, with human labor, and without a traceable output. A compliance orchestration platform is built to answer all of them.

To help your team structure this evaluation, Ondorse has published a free RFP template covering the full functional scope of a compliance operations platform, ready to send to vendors.

Ondorse is built as a compliance orchestration platform and the system of record for KYC data. Identity verification is handled by certified partners, including PVID-accredited providers for French-regulated institutions. The orchestration layer, covering risk scoring, AML screening, UBO mapping, EDD workflows, audit trail, and periodic review, sits inside the platform and is configurable directly by the compliance team, without IT involvement. Ondorse is not a router connecting existing point solutions. It is the system of record where compliance data lives in its proper context: organized around risk, not around commercial interactions. That distinction is what makes AI, automation, and third-party checks meaningful, because without a structured, risk-centered view of each customer, there is no context for any of those tools to operate in.

To see how the platform handles the full compliance cycle, visit ondorse.co/solutions. For further reading on how to structure your vendor evaluation, see How to choose the right compliance operations software.

Discover our latest guide

Everything you need to know about this subject

Read GuideRead Guide

Heading

Subtextt

Try it yourself

ABOUT AUTHOR

President and co-founder of Ondorse. Previously a regulatory lawyer. Tech is an acquired taste.

SHARE ARTICLE

Talk with an expert

Short description

Similar articles

Your KYB onboarding is clean. Your periodic review is a liability.

Most regulated fintechs invest heavily in onboarding, and almost nothing in what comes after. Periodic KYB reviews are where regulatory exposure actually lives: 63% of ACPR grievances in 2023 targeted ongoing vigilance failures, not Day 1 processes. This article breaks down why the standard email-and-spreadsheet review cycle fails under scrutiny, what a risk-based, automated review process looks like in practice, and how compliance teams can close the gap without adding headcount.
Insights

Read article

eIDAS 2: The great digital identity revolution is (finally) here

eIDAS 2 isn't just another EU regulation, it's a fundamental shift in how identity is verified across Europe. With digital identity wallets set to go live by end of 2026, compliance and onboarding teams need to start preparing now. Here's what it means for your KYC workflows, your AML/CFT procedures, and the future of KYB.
Insights

Read article

KYC/KYB remediation best practices for compliance and ops teams

Remediation projects are one of the toughest challenges compliance teams face. But remediation is also an opportunity. With the right strategy, you can clean up your data, improve risk management, and strengthen your compliance framework for the future.
Insights

Read article

Ready to take the manual work out of KYC/B?

Unlock the power of automation
Easy setup that takes just a few days
Friendly human support based in Europe
Book a call
Subscribe to our newsletter

The latest information and tips on business onboarding, KYB, compliance, risk management

By submitting your information above, you hereby consent to Ondorse’s use of your information for sales and marketing purposes, and you otherwise agree with the use, storage and handling of your data by Ondorse in accordance with Ondorse’s Privacy Policy.
Logo Ondorse

Powering KYC/KYB
for modern operations.

Contact us
Eng
Fra
Get an AI summary of Ondorse:
Resources
BlogGuidesSuccess storiesAPI referenceProduct documentationIntegrationsProduct updatesSecurityOfficial documentsNews
KYC
KYC softwareKYC workflowKYC workflow builderKYC orchestrationKYC API integrationKYB verificationCustomer onboarding softwareAccount opening fraud prevention
COMPLIANCE
Compliance softwareKYC/AML platformAML case managementCustomer risk assessmentOngoing monitoring
SOLUTION
Client onboardingCase managementAML risk scoringApp marketplaceScan libraryRemediation libraryAll-in-one KYC/B
GET STARTED
Contact usLogin
USE CASES
For compliance teamsFor operations teams
COMPANY
TeamCareers
Ondorse.co ISOMark_27001-2022Ondorse.co Prescient SOC2 Type 2 Badge
Logo LinkedInLogo Twitter
Ondorse © 2026
Privacy PolicyTerms & ConditionsCookie Policy