A broker launches into three markets, verification works cleanly in two, and in the third half the applicants fail at the document step. The documents are genuine. The vendor's model has thin training data for that national identity card, the cheap phone cameras common in that market produce images it rejects, and there is no local database check to fall back on. The compliance framework is fine. The onboarding funnel is broken.
Coverage is four different things
Vendors publish a country count, which is close to meaningless on its own. What matters is four separate capabilities, and a provider can be strong in one and absent in another for the same country.
| Capability | What it means | Where it breaks |
|---|---|---|
| Document capture | Reading and authenticating the national ID types actually issued in that country | Older document versions, regional variants, handwritten entries |
| Biometric matching | Liveness detection and face match against the document portrait | Low-end cameras, poor lighting, spoofing resistance under pressure |
| Data source checks | Verification against a government or credit database rather than a photo | Many countries have no accessible source, so document checks are the only route |
| Screening data | Sanctions, politically exposed persons and adverse media lists | Name transliteration, local-language sources, refresh frequency |
The screening row deserves separate attention because it fails quietly. A sanctions list is only as useful as its matching logic against names transliterated from a non-Latin script, and adverse media coverage in local-language press is uneven. A vendor that returns no hits for a market may have excellent data or almost none, and the two look identical from your dashboard. The mechanics of this sit alongside sanctions screening basics, and the practical test is to ask what sources are used for that market and how often they refresh.
Coverage and risk are not the same axis
Good coverage in a country does not mean the country is a comfortable place to take clients from. Jurisdictions identified by the Financial Action Task Force as having strategic deficiencies attract enhanced due diligence expectations from your own supervisor and from your banking partners, regardless of how well a vendor reads the local passport. The downstream effect on payments is real, as set out in the impact of FATF listings. A firm can verify a client perfectly and still be unable to bank the relationship.
This is why the vendor decision has to follow the risk policy rather than lead it. Decide which markets you accept, at what risk tier, with what enhanced measures, and then buy verification that serves that list. Firms that buy the broadest vendor first and write the policy afterwards end up onboarding clients they cannot process payments for, which is worse than rejecting them at the start.
Verification obligations, acceptable evidence and reliance on third parties differ by jurisdiction, and a supervisor can reject an approach a vendor markets as compliant. This describes mechanisms only and is not legal or compliance advice. Take advice from counsel and confirm requirements with your own supervisor.
Reliance, records and data residency
Outsourcing the check does not outsource the obligation. In most regimes the regulated firm remains responsible for the customer due diligence even where a vendor performs it, which has three consequences. You need the underlying evidence, not a pass or fail flag, because a supervisor may ask to see what the decision was based on. You need it retained for the period the local rules require, which is often longer than a vendor contract. And you need it to survive a vendor change, so an export path is a procurement question rather than an afterthought.
Data residency is the other constraint that decides shortlists. Identity documents and biometric templates are sensitive personal data, and biometrics carry heightened treatment in several regimes. Where processing happens, where it is stored, and on what basis it moves across borders all matter, especially for European clients where the obligations described in GDPR for trading firms apply to your vendor chain as well as to you.
Choosing without guessing
Run a pilot on your real client mix before committing. Measure pass rate at first attempt, not overall, because a client who has to retry three times is largely a client you lost. Measure time to decision and the share sent to manual review, because manual review is a staffing cost you inherit. Ask specifically about the document types your target markets issue, and check what happens on failure: whether the flow offers a second document type, a fallback route or a dead end.
Build the fallback deliberately. Every automated system rejects legitimate people, and a manual review path with trained staff and a documented standard is not a weakness in the design, it is the part that keeps the funnel honest. Where the checks sit inside your onboarding rather than beside it, the operational load drops, which is why verification status belongs in the same client record as everything else, a point we make in KYC providers compared. Coverage numbers sell the contract. Pass rates on your own applicants tell you whether you bought the right one.
"Ask a vendor for pass rates by country on your own client mix, not the global average. The average always looks fine and the average is never who is standing at your door."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- Country counts hide four separate capabilities: document capture, biometrics, database checks and screening data.
- Screening gaps fail silently, so ask which sources cover a market, how names are matched across scripts and how often data refreshes.
- Verifying a client is not the same as being able to bank them, so let the risk policy pick the markets and the vendor serve that list.
- Reliance does not transfer the obligation: keep the underlying evidence, retain it for the local period and make sure it exports.
Frequently Asked Questions
Why do pass rates differ so much between countries with the same vendor?
Because document types, camera quality and available data sources differ. A vendor may have deep training data for one country's identity card and thin data for another's, and many countries have no accessible government database to check against, leaving the document image as the only route. Test on your own client mix rather than trusting a global average.
Does using a KYC vendor transfer the compliance obligation?
Generally no. In most regimes the regulated firm remains responsible for customer due diligence even when a third party performs the checks, which is why you need the underlying evidence rather than a pass flag, retention for the period local rules require, and an export path if you change provider.
Is good vendor coverage a reason to open a market?
No. Verification capability and jurisdiction risk are separate questions. Markets identified as having strategic deficiencies in their anti money laundering regimes attract enhanced due diligence and can create problems with banking and payment partners even when identity checks pass cleanly.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.