Reusable identity lets a person verify once and reuse that credential elsewhere. Reusable KYC is the same model named from the compliance side. Reuse changes how identity data reaches you, not how much of it you must collect.
The European Union has set a deadline for reusable identity. Under Regulation (EU) 2024/1183, every Member State must give its citizens a digital identity wallet by the end of 2026. Businesses that are legally required to verify who their customers are will then have to accept that wallet as proof of identity.
Most verification systems were never built for this. Today, a single customer has to open his/her wallet, then a card, then a lending product, and upload the same passport three times, because each product runs its own onboarding from scratch. Every repeat gives that customer another reason to give up and leave. This is where reusable identity or KYC comes in handy.
This guide explains what reusable identity is, what regulators accept, and which parts of the sales pitch do not hold up.
What is a reusable identity?
Reusable identity is a verified identity credential that a person proves once and then reuses at other services, without repeating the full check each time. The first verification works the way any verification works today, with a document check, a facial biometric and a liveness test.
Now, instead of the result sitting only in one company’s records, it is issued to the customer as a cryptographically signed credential they hold and can present again later for more verifications. This saves customers from having to prove their identity over and over again.
Reusable identity and reusable KYC mean the same thing
Reusable KYC is the same idea named from the compliance side of the desk. Reusable identity describes the credential itself, and reusable KYC describes the regulated process that credential shortens.
The reusable KYC meaning does not change between vendors, even though the labels do. If one provider sells reusable KYC and another sells reusable digital identity, ask each of them the same questions about architecture because both offer the same product under different names.
Who does what: issuer, holder and verifier
Every reusable identity system assigns three roles, whatever the vendor calls them.
- Issuer: The organisation that runs the first verification and signs the credential. Usually a government body or an identity verification provider.
- Holder: The person who keeps the credential, normally in a wallet app on their phone, and chooses when to present it.
- Verifier: The business that receives the credential, confirms the signature is intact, and checks that the person presenting it is the person it was issued to.
That last check matters more than it first appears. A valid signature proves the credential has not been altered since it was issued. It proves nothing about who is holding the phone right now. This is why businesses running higher-risk checks add a live biometric on top of the signature check.
How does reusable identity verification work?
Reusable identity verification runs in three stages, one full check followed by an issuance step and then repeated lighter reuse. It’s designed this way to minimize expense and ensure every later check reads the result that was first generated instead of rebuilding it.
Here’s the sequence to give you and idea of how it looks like:
Step 1: The first full verification
The opening check carries all the weight. The customer submits a government-issued document, the provider runs document verification against the document’s security features, and a liveness test confirms a real person is present rather than a photo, a screen replay or a deepfake. Every later reuse inherits whatever quality this first check produced, so a weak opening check produces a credential that travels widely and is wrong everywhere it goes.
Step 2: The credential is issued to the wallet
Once the identity is confirmed, the result is cryptographically signed and issued to the customer’s wallet. That signature is what makes the credential tamper-evident. Change any field in it and the signature stops validating, which is how a business can trust a credential it did not create itself.
Step 3: Reusing the credential elsewhere
The customer presents the credential at the next business that accepts it, and that business validates the signature instead of collecting documents again. Lower-risk checks can run on the credential by itself. Higher-risk ones add a liveness test, which ties the credential to the person presenting it at that moment.

What is the difference between reusable KYC and traditional KYC?
The difference is how the identity data reaches you and how long that takes. Traditional KYC rebuilds the customer file from scratch at every business the person deals with, while reusable KYC builds that file once and confirms it again at each reuse. The table sets the two side by side, including the two things reuse does not change.
| Comparison | Traditional KYC | Reusable KYC |
| When verification happens | In full, at every business | Once, then confirmed again at each reuse |
| What the customer submits | Documents and a biometric, every time | A credential they already hold, plus a liveness check |
| Typical onboarding time | Minutes, including capture and review | Seconds, when the credential is accepted |
| Identity data the business must collect | The full data set required by law | The same data set, delivered as a signed credential |
| Who answers to the regulator | The business doing the verifying | Still the business accepting the credential |
| Most common failure | Customers abandon document capture | Credentials that are out of date or poor quality |
The fourth and fifth rows are the ones vendor material tends to skip. Reuse changes how the data reaches you and how fast, but you still collect the same information, and you still answer to your regulator for the decision you made.
Is reusable KYC legally valid for AML compliance?
Reusable KYC is legally valid for anti-money laundering compliance wherever local law follows the international framework for relying on a third party. Regulators treat a reused credential as exactly that, one business relying on a check somebody else performed, and that permission comes with conditions attached. The two sections below cover the conditions and the regulations that now support the model directly.
What FATF Recommendation 17 requires
The Financial Action Task Force (FATF) allows a business to rely on a third party for customer due diligence, and then closes off the obvious loophole. In the FATF Recommendations as updated in October 2025, Recommendation 17 states that “the ultimate responsibility for CDD measures remains with the financial institution relying on the third party.” Accepting someone else’s verification does not pass on the consequences of a bad one.
Four conditions attach to that reliance.
- Get the due diligence information immediately: The relying business must obtain the necessary customer due diligence information at the point it relies on the credential.
- Secure access to the underlying records: Copies of the identification data and supporting documentation must be available from the third party on request, without delay.
- Check the third party is supervised: The relying business must satisfy itself that the third party is regulated, supervised or monitored, and has due diligence and record-keeping measures in place.
- Account for country risk: The country the third party operates in forms part of that assessment.
Keep in mind that a reusable credential with no auditable trail behind it creates work for your compliance team rather than saving it.
What regulations support reusable digital identity?
Several frameworks now support reusable digital identity directly rather than merely permitting it.
- eIDAS 2.0 in the European Union: Regulation (EU) 2024/1183 entered into force on 20 May 2024 and requires Member States to provide EU Digital Identity Wallets to citizens by the end of 2026. Businesses that are legally required to identify their customers will have to accept the wallet for authentication. Our explainer on how eIDAS 2 reshapes identity verification covers what that means in practice.
- National schemes already running: Singapore’s Singpass gives residents access to over 2,000 services from more than 700 government agencies and businesses using one verified identity. It is the clearest evidence that people will use a single credential widely once enough organisations accept it.
- Reusable identity standards: Credentials only travel between systems that agree on how to read them. Two open specifications do that work, Decentralised Identifiers (DIDs) and Verifiable Credentials, both published as W3C Recommendations. Without shared reusable identity standards, each scheme becomes its own island and the portability that justified the model disappears.
How is user consent handled in reusable KYC?
Consent in reusable KYC controls who the customer shares the credential with. It is not the legal basis for the anti-money laundering checks themselves, and treating it as though it were creates real exposure. A regulated business verifies customers because the law requires it, so its legal basis under the General Data Protection Regulation (GDPR) is legal obligation, not consent.
The difference matters in practice. The European Data Protection Board’s Guidelines 05/2020 on consent, adopted on 4 May 2020, state that consent “should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller.” A customer who cannot open an account unless they agree is not giving consent freely in the way those guidelines mean.
Reusable KYC does not reduce the data you have to collect
Reusable identity is usually sold as a privacy improvement, and that claim only holds up outside regulated onboarding. Selective disclosure works well for age checks, where a service needs to know whether someone is over a threshold and nothing more. Regulated financial onboarding is a different problem, because the business has a legal duty to know exactly who its customer is.
The regulation says so directly. FATF Recommendation 17 requires the relying business to obtain the customer due diligence information at the point of reliance, so the name, the date of birth and the supporting evidence still change hands. A digital identity wallet changes how that data travels and who controls its release, whereas the amount an AML-regulated business has to collect stays the same.
How do you implement reusable KYC on your platform?
Implementation starts with a scope decision that many buyers make without noticing, and the two options carry very different risks. How far you let reuse travel decides your integration work, where your data boundary sits, and how much third-party reliance you take on under AML rules. Settle that question before anyone writes integration code, because changing the answer later means rebuilding the consent and audit layers underneath it.
Closed-loop reuse or a shared KYC framework
A closed-loop model reuses a verified identity inside one company’s own boundary, across its products, subsidiaries and partner network. A shared KYC framework, on the other hand, extends reuse between unrelated businesses, so a credential issued by one bank is accepted by another.
Closed-loop reuse is the faster path to build, you control both ends, and the data stays inside your boundary. Where the reuse happens between entities in the same group covered by a group-wide AML programme, FATF allows a simpler treatment than full third-party reliance. Reuse across a partner network is not the same thing, because a partner is still a third party and all four conditions above apply in full.
A shared KYC framework delivers more value than either and brings the heaviest compliance load, including a supervision check on every issuer whose credentials you accept.
What to build before you turn reuse on
Four things need to be in place before the first credential is reused.
- A strong first verification: Every later reuse inherits the quality of that first check, so weak verification spreads rather than staying contained.
- A binding step at reuse: A signature check confirms the credential, not the person holding it, so add a liveness test for anything above low risk.
- A recorded consent and audit trail: Log which attributes were released, who received them, and when.
- A fallback path: When reuse fails, the customer needs to land in standard verification rather than a dead end, or you lose the conversion gain on exactly the cases that were already difficult.
What still slows reusable identity adoption?
Three obstacles account for most stalled programmes, and none of them is a flaw in the model itself. Each one is a coordination problem rather than a technical one, which is why they are taking longer to clear than the technology did to build.
- Fragmented standards: Credentials only travel between systems that agree on the same specifications. Where competing schemes pick different ones, they rebuild the silos reuse was meant to remove.
- Customer understanding: People need to know how to secure a wallet and what they are handing over when they approve a request. A holder who approves everything by reflex loses the control the model was built to give them.
- Readiness across the market: Reuse needs issuers, wallet providers and verifiers live at the same time. A credential nobody accepts is worth nothing to the person holding it.
How Shufti handles reusable identity for returning users
If a customer already verified with you to open a wallet, asking for the same passport again when they apply for a card is a drop-off you caused yourself. That repeat capture is where returning-customer onboarding leaks, and it is avoidable.
Shufti’s Fast ID is built for that specific moment. A returning customer re-verifies by selecting their own masked identity profile and passing a facial liveness check, which returns a decision in under five seconds, around half the time a full repeat check would take. Reuse stays inside your own subsidiary and partner network rather than a shared external graph, so verified data never leaves your boundary. Any session Fast ID cannot confirm moves automatically into standard verification, so onboarding does not stall on the cases it cannot handle.
Frequently Asked Questions
What is reusable KYC?
Reusable KYC is a model where a customer completes Know Your Customer checks once and the verified result is reused at other services instead of being rebuilt. Reusable KYC, reusable identity and portable identity verification all describe the same approach.
Is reusable KYC legally compliant for AML?
Yes, under third-party reliance rules. FATF Recommendation 17 permits reliance but keeps ultimate responsibility for due diligence with the business relying on the third party. You must obtain the due diligence information immediately, secure access to the underlying records, and confirm the issuer is supervised.
















