TL;DR
- eKYC is a market term, not a single regulatory category anywhere.
- The compliance obligation stays the same; only the evidence and method change.
- India defines e-KYC, Digital KYC and V-CIP as three separate legal methods.
- EU regulators govern remote onboarding solutions without using the word eKYC.
- Stacked verification steps, not weak technology, are why programmes underperform.
The term eKYC can be confusing for some businesses, as no regulator uses it, yet almost every vendor in the market seems to offer a product or service for it.
Regulators refer to it with different names. The European Banking Authority, for example, referred to it as “remote customer onboarding solutions” in Guidelines EBA/GL/2022/15,, which applied from 2 October 2023.
These guidelines were put in place because the existing AML rules at the time did not make it clear as to what was permitted and what was not when a customer was onboarded through an app.
This shows that the label you put on a series of processes doesn’t explain what you need as a business to comply with regulations in the regions/countires you operate in.
This guide covers what eKYC means, how the process runs, what evidence it uses, where regulators accept it, and why most programmes return less than what the vendors promised.
What is eKYC?
eKYC, short for electronic Know Your Customer, is the practice of completing customer identity checks remotely through digital channels rather than in person. A complete flow establishes who someone claims to be, tests whether the evidence they present is genuine, confirms that a real person is present at the point of capture, and screens them against sanctions and watchlists before returning a decision.
The market uses eKYC, e-KYC, e kyc and electronic KYC interchangeably, and all four mean the same thing in ordinary vendor usage. Digital KYC is usually treated as a fifth synonym, which is safe in conversation and unsafe in a compliance policy, for reasons the regulatory section below sets out.
Two adjacent phrases are worth pinning down. eKYC verification refers to the check itself, the moment a flow tests evidence and returns a result, rather than to the wider programme that governs it. eKYC online describes the same check by its channel, and that distinction earns its keep only where a regulator treats an unattended web or app journey differently from an assisted one, which several do. Scope is worth settling as well, because eKYC covers natural persons, while the equivalent checks on a company and its beneficial owners fall under Know Your Business and follow a different evidence trail entirely.
What eKYC is not is a separate obligation. KYC duties come from anti-money laundering law, and those duties are indifferent to channel. A regulated firm must identify its customer, verify that identity against a source independent of the customer, understand the purpose of the relationship, and keep monitoring it. eKYC changes how a firm discharges those duties and how quickly, but it does not add to them or subtract from them. Any eKYC meaning that implies a lighter standard for online customers is wrong.
Two consequences follow. A firm cannot buy compliance as a product, because the obligation sits with the firm and not with its vendor. And an eKYC flow that satisfies one regulator can fail another while using identical technology, because what varies is the set of conditions attached to each permitted method.
eKYC vs Traditional KYC: What Changes and What Does Not
The obligation is identical in both cases, and the difference lies entirely in what counts as acceptable evidence and who or what examines it. Compare the two against the obligation rather than against a feature list, and the boundary becomes clear.
| What the law requires | Traditional KYC | eKYC |
| Identify the customer | Details taken on a paper form at a counter | Details captured in an app, often pre-filled from an authoritative source |
| Verify identity from an independent source | Staff inspect an original document | Document forensics, an authoritative database check, or an eID authentication |
| Confirm the person presenting is the person identified | Staff compare the face to the photo | Face match against the document or source image, plus liveness testing |
| Screen against sanctions and PEP lists | Manual or batch lookup after opening | Screening inside the same decision, before approval |
| Keep an auditable record | Paper file, retrievable on request | Timestamped evidence package with every check, score and reason |
| Monitor the relationship afterwards | Periodic review, often calendar-driven | Event-triggered re-verification alongside periodic review |
Three things are worth drawing out of that table. Verification moves from human judgement to a documented test, which is an improvement in consistency and a new dependency on the quality of the test.
The screening step moves inside the decision rather than trailing it, which is where much of the compliance gain sits. And the record stops being a folder and becomes evidence a supervisor can interrogate line by line, which cuts both ways for the firm producing it.
In reality, very few firms run either model. Most businesses use an electronic flow with an assisted or in-branch route that is retained for exceptions, for high-value relationships, or for markets where regulators demand a human analyst in the review.
The comparison above therefore describes two methods, and which one you should use depends on which customer you’re checking
How Does the eKYC Process Work, and How Long Does It Take?
A well-built eKYC process is a routing decision before it is a sequence of steps. The platform decides which path a given applicant should take, runs only the checks that path requires, and escalates when a signal warrants it. Four questions describe it better than a fixed pipeline does, and they map far more closely to how these systems are actually configured.
Which Path the Applicant Takes
The first decision is whether the applicant needs to produce a document at all. Where a country has usable authoritative data or a national digital identity, the flow can confirm name, date of birth and address against a trusted source, or ask the applicant to authenticate with a credential they already hold. Where neither exists, the flow falls back to document capture.
Proving the Evidence is Genuine
Whatever evidence arrives, the next question is whether it is real. For a document that means optical character recognition to read the fields, machine-readable-zone parsing and checksum validation, security feature inspection, and tamper detection across fonts, layers and photo edges. Where the document carries a chip, the flow can read it directly and compare the signed data against the printed page. For an authoritative data check the equivalent question is which source answered and what that source is actually authoritative about, since a credit file and a civil register carry different weight.
Binding the Person to the Evidence
Genuine evidence proves nothing about who is holding it, so the flow has to tie the applicant to the record. A face match compares a live capture against the photo on the document or the image returned by the source. Liveness testing then establishes that the capture came from a present human rather than a printed photograph, a screen replay, a mask or a generated video. Without that second test a face match is trivially defeated by anyone holding a stolen document and a picture of its owner.
The Decision, The Record, and The Honest Answer on Duration
The flow ends in one of three states, which are approval, refusal, or referral to a human reviewer, with an evidence package attached in every case. Duration follows from the path rather than from the vendor, which is why any single number quoted for eKYC is misleading.
Shufti publishes response times under three seconds for a database or eID check and decisions under fifteen seconds for a document check on its identity methods, both figures Shufti-reported. A referral to manual review, by contrast, is measured in hours or days because a person has to look at it. The useful metric is therefore not average speed but the share of applicants who never receive an automated decision at all.
One further property of the record pays off commercially. Because the evidence package is structured rather than filed, a later trigger such as an expired document, a change of address or a suspicious transaction can reopen the existing file instead of starting a fresh onboarding, which keeps the cost of ongoing due diligence well below the cost of the original check. Programmes that treat eKYC as a one-off gate forfeit that advantage and end up re-onboarding customers they have already verified once.
What Documents and Data Does eKYC use, and What does each one Prove?
eKYC draws on five families of evidence, and the practical skill in designing a flow is knowing what each family settles and what it leaves open. Most weak programmes over-rely on one family and assume it answers questions it cannot.
| Evidence | What it is | What it proves | What it does not prove |
| Authoritative data | Civil registers, electoral rolls, credit files, utility records | That the claimed identity exists and the details match a trusted record | That the person supplying the details is that identity |
| Identity document | Passport, national ID card, driving licence, residence permit | That a genuine, unexpired credential exists for that identity | That the presenter is its rightful holder |
| Chip read (NFC) | Cryptographically signed data on an ePassport or eID | That the document was issued by the stated authority and is unaltered | Anything about who is holding the phone |
| Biometric capture | Selfie or short video, face matched and liveness tested | That a present, live human matches the identity evidence | That the identity itself was genuine to begin with |
| Device and behavioural signals | IP, geolocation, device fingerprint, typing and form behaviour | That the session looks consistent with a real applicant | Identity, on its own, in any jurisdiction |
The pattern in the right-hand column is the argument for combining families rather than buying the strongest single check. A document proves the credential, a biometric proves the presenter, an authoritative source proves the record, and a chip proves the issuer. No one of them closes the loop, which is why the eIDV and document paths are usually layered with a biometric rather than run alone.
Sequence matters as much as combination. A flow that runs the cheapest and least intrusive family first, then escalates only on a weak or missing result, costs less and converts better than one that runs everything in parallel on everyone. An authoritative data check that resolves cleanly can make a document upload unnecessary, whereas the reverse order asks every applicant for a document and then adds the data check on top of it.

Is eKYC Legally Accepted for Regulated Onboarding?
Yes, in every major regulated market, but not under that name and never unconditionally. Regulators authorise specific methods subject to specific conditions, and the conditions are where multi-market programmes come unstuck.
The European Union Regulates the Solution, not the Label
EBA/GL/2022/15 sets out what a credit or financial institution must do before adopting a remote onboarding solution and while running it, covering the pre-implementation assessment, the controls, and the ongoing checks on whether the solution still works. Nowhere does it grant blanket permission for a product category called eKYC. The forthcoming single rulebook tightens this further, since Regulation (EU) 2024/1624 applies from 10 July 2027 and is directly applicable, which removes the national variations that currently let one flow pass in one member state and fail in another.
The United Kingdom Now Ties Acceptance to Certification
Under regulation 28 of the Money Laundering Regulations 2017, a firm must verify identity from a source independent of the person being verified, and electronic checks can meet that test. On 26 February 2026 HM Treasury and the Department for Science, Innovation and Technology published joint guidance explaining how the UK digital verification services trust framework interacts with those Regulations, confirming that a service certified against the framework and listed on the DVS Register can be treated as a reliable and independent source offering an appropriate level of anti-impersonation assurance. For procurement teams that changes the question from whether electronic verification is allowed to whether the chosen provider carries the certification.
India Defines Three Separate Methods, and They are not Synonyms
India popularised the term, and it is the clearest illustration of why that specific vocabulary matters. The Reserve Bank of India’s FAQs on the Master Direction on KYC, updated 9 June 2025, treat e-KYC authentication, the Digital KYC Process and the Video based Customer Identification Process as three distinct routes with different standing.
- e-KYC authentication means Aadhaar OTP or biometric authentication.
- The Digital KYC Process, defined separately in the Master Direction, requires an authorised officer of the regulated entity to capture a live photograph together with the latitude and longitude of the location, so despite its name it is not an unattended remote flow at all.
- V-CIP is a live, consent-based audio-visual interaction treated as equivalent to face-to-face. The clearest signal of the hierarchy is that V-CIP may be used to convert an account already opened non-face-to-face through Aadhaar OTP based e-KYC, which tells you the OTP route alone carries limits the video route does not.
| Jurisdiction | Instrument | Position | Date |
| EU | EBA/GL/2022/15 | Remote onboarding solutions permitted subject to assessment and controls | Applied 2 October 2023 |
| EU | Regulation (EU) 2024/1624 | Single rulebook, directly applicable, replaces national variation | Applies 10 July 2027 |
| UK | MLRs 2017 reg. 28 plus HMT and DSIT guidance | Electronic verification accepted; certified and registered DVS treated as a reliable independent source | Guidance 26 February 2026 |
| US | 31 CFR 1020.220 | Customer Identification Programme permits documentary or non-documentary verification | In force |
| India | RBI Master Direction on KYC | e-KYC authentication, Digital KYC and V-CIP are separate methods with different permissions | FAQs updated 9 June 2025 |
What this Means for a Multi-Market Flow
One fixed flow shipped to every market will either over-comply or under-comply, and both are expensive. Over-compliance costs completed applications in the markets where a lighter method was permitted. Under-compliance costs a finding when a supervisor asks which method was used and under what conditions.
For anyone comparing eKYC solutions, that shifts the shortlist criteria away from headline coverage counts and towards configurability. The questions that actually separate platforms are whether a flow can differ by market without a second integration, whether the conditions attached to each permitted method can be expressed in the routing itself, and whether the evidence package names the method used so a supervisor can see which permission the firm claimed. Coverage breadth still matters, but it is the easiest claim on the list to verify and the least likely to be the binding constraint.
Is eKYC Secure Against Fraud and Deepfakes?
A current eKYC flow with independently tested liveness is materially harder to defeat than a counter clerk comparing a face to a photograph, but security is a property of the configuration rather than of the category. Two things decide it.
What Liveness Testing Actually Covers
Presentation attack detection is tested against ISO/IEC 30107-3, and iBeta publishes conformance results by level. Shufti holds iBeta Level 3 conformance under that standard for passive single-selfie liveness. The important limitation is that presentation attack testing measures artefacts presented to a camera, such as a printed photo, a screen replay or a mask. Attacks injected directly into the video stream, which bypass the camera altogether, sit outside that standard and are assessed separately. A vendor’s PAD result is therefore necessary evidence and not sufficient evidence, and buyers should ask which standard, which level, which lab and which date.
The reason that gap is widening is that an injected attack needs no physical artefact at all. Rather than holding a screen up to a camera, the attacker feeds a generated video stream straight into the capture layer through a virtual camera or a modified client, so nothing is ever presented to a lens for a presentation test to catch. Defence of that layer depends on capture integrity and device attestation rather than image analysis, which is why the two results are reported separately.
Why Hardening one Layer Moves the Attack Rather than Ending it
Fraud adapts to whatever control is strongest. Gadsden describes the sequence in Shufti’s own attack traffic as a balloon that pops out elsewhere when squeezed, with AI-generated faces on documents giving way to face swaps on stolen documents, and then, as deepfake defences improved, a swing back towards real human actors and money mules recruited to onboard with their genuine faces. That last pattern defeats liveness completely, because the face is live and the document is real. Detection depends instead on device signals, behavioural patterns, repeated details across accounts and AML screening, rather than on a better selfie test. Any answer to whether eKYC is secure that stops at deepfake detection has answered only the layer that is currently well defended.
Why Most eKYC Programmes Underperform
Almost every disappointing eKYC deployment fails commercially rather than technically. The checks work, the fraud numbers improve, and the conversion gain that justified the investment never arrives.
Layers Get Stacked Instead of Routed
Gadsden’s account of the pattern is blunt, describing businesses that put seven verification layers in front of every applicant, lose somewhere between five and ten per cent at each one, and end up turning away roughly half their customers. The arithmetic is unforgiving and it is also entirely self-inflicted, because the same seven controls applied selectively cost a fraction of that. A layer that runs on every applicant is a tax on the genuine majority to catch a small minority, and the fix is to make each layer conditional on a signal rather than mandatory.
The pattern persists because each layer is added by a different team solving a real problem, and none of those teams owns the cumulative completion rate. Fraud adds a check after an incident, compliance adds one after an audit finding, product adds a consent step, and no single owner measures what the whole stack costs end to end.
One Flow that Gets Shipped to Every Market
A flow that is tuned for a market with strong authoritative data performs badly in markets where data is thin, and a flow built around document capture wastes the advantage in markets where a national digital identity would resolve the check in seconds. If you treat the flow as a single global artefac, it won’t work really well.
Friction Lands in the Wrong Places
Andrei Sribny of the AML Certification Center makes the point that conversion loss does not come from stronger controls, it comes from applying them in the wrong places, and that risk-weighted conversion rather than raw conversion is the number worth managing. Read alongside the layering problem, that reframes the whole friction debate. The question is not how much friction a flow contains but whether the friction is sitting where the risk is. A flow that steps up on a high-value first deposit and clears a low-value one quickly has more total friction than a uniform flow and loses fewer good customers.
Where Shufti Fits in eKYC Routing
If your onboarding funnel leaks and nobody can say which step is responsible, the problem is usually that every applicant walks the same path regardless of what the earlier steps returned. Shufti’s Journey Builder is the routing layer that addresses this. A journey is a connected graph rather than a fixed sequence, and condition nodes read the result of any completed step to send each applicant down the appropriate branch, so low-risk applicants clear on lighter checks while higher-risk profiles route into deeper verification or human review. Every fork carries a catch-all branch, which means no applicant is left unhandled. Teams compose journeys in the back office without engineering work, test them against a dry-run preview that runs the same logic as the live engine, and only deploy once validation passes.
Frequently Asked Questions
What is eKYC?
eKYC, or electronic Know Your Customer, is the completion of regulated identity checks remotely through digital channels instead of in person. A full flow verifies identity evidence, matches and liveness-tests the applicant's face, screens against sanctions and watchlists, and returns a decision with an audit record.
How does eKYC work?
An eKYC flow routes the applicant, either to an authoritative data or eID check where available, or to document capture. It then confirms the evidence is genuine, binds the applicant to it through face match and liveness testing, screens for sanctions exposure, and returns an approval, refusal or referral.
What is the difference between eKYC and traditional KYC?
The legal obligation is the same. Traditional KYC discharges it through in-person inspection of original documents by staff. eKYC discharges it through document forensics, authoritative data or eID authentication, biometric matching and liveness testing, with screening inside the same decision and a timestamped evidence record.
Is eKYC legally accepted for regulated onboarding?
Yes, across all major regulated markets, though not as a category called eKYC. Regulators authorise particular methods under particular conditions, so acceptance depends on which method you use and where. The EU, UK, US and India each set different conditions, and a single global flow rarely satisfies all of them.
What documents and data does eKYC use?
Passports, national ID cards, driving licences and residence permits are the common documents, often with an NFC chip read where available. Flows also use authoritative data such as civil registers and credit files, national eID credentials, biometric selfies, and device and behavioural signals.
How long does eKYC take?
Duration depends on the path rather than the provider. Shufti reports database and eID checks returning in under three seconds and document decisions in under fifteen. Anyone referred to a human reviewer waits hours or days, so automated decision rate matters more than average speed.
Is eKYC secure against fraud and deepfakes?
Independently tested liveness detection defeats printed photos, screen replays, masks and generated video, and iBeta publishes conformance results against ISO/IEC 30107-3 by level. Injected attacks that bypass the camera are assessed separately. Recruited human accomplices defeat liveness entirely, so device, behavioural and screening layers remain necessary.
















