Docless verification in APAC, without losing genuine users
What it is, where APAC supports it today, what regulators permit, and how to move low-risk users to a Non-Doc check without adding friction. A practitioner guide for compliance, product, and onboarding teams.
Schedule a DemoOverview
Why first-pass success decides the outcome
Across APAC, the first verification attempt is where onboarding is won or lost. A document that fails to capture cleanly, a format the scanner does not recognise, a user who abandons mid-flow, each is a genuine customer delayed or lost, and a cost your operations team absorbs downstream.
First-pass success sets conversion, the speed to a compliant account, and the operational load your teams carry. The guide shows where identity can be confirmed without a document, and where regulators permit it.
The onboarding challenge across APAC
Volume and velocity
APAC onboarding moves at scale and speed. Verification has to keep pace without queuing genuine users behind manual review.
Pass rate pressure
Document capture fails often on the first attempt across the region’s many ID formats, and every failure is a lost or delayed account.
One-size-fits-all verification
A single document flow ignores that many APAC users can be confirmed against trusted data with no upload at all.
The markets that grow fastest are the ones where low-risk users never have to reach for a document.
How Docless Identity Verification works, three methods
Three escalating levels of Non-Doc assurance. Each confirms identity without a document upload, with an automatic fallback when a match is not returned.
Passive
Checks identity data invisibly against trusted government, bank, and bureau sources. The user submits nothing to scan.
Active
The user authenticates through a bank or government eID login, returning a verified record direct from the source.
Biometrically Enriched
Adds a live facial match against the source record for the strongest Non-Doc assurance available.
The regulatory picture across key APAC markets
Regulatory positions across APAC change often. The positions below reflect primary-source research current to June 2026. Confirm the current position with local counsel before relying on any market-specific claim for regulated onboarding.
| Market | Regulator | Key instrument | What it permits |
|---|---|---|---|
Singapore | MAS | MAS Notice 626; Myinfo via Singpass | Non-face-to-face CDD accepted with Myinfo as a reliable source. |
India | RBI / UIDAI | Master Direction – KYC (rev. 28 Nov 2025) | Aadhaar e-KYC is the principal electronic route; UIDAI consent required. |
Vietnam | State Bank of Vietnam | VNeID mandate (from Jan 2026) | Biometric match against the national population database is mandatory. |
Indonesia | OJK / Bank Indonesia | POJK e-KYC; Dukcapil | Electronic CDD against Dukcapil population data is permitted. |
Malaysia | Bank Negara Malaysia | e-KYC Policy Document | Remote onboarding via approved e-KYC with biometric and liveness. |
Philippines | BSP | PhilSys; BSP Circular | PhilSys-based eKYC permitted for non-face-to-face onboarding. |
Thailand | BOT / AMLO | NDID framework | Digital ID via NDID accepted at defined identity assurance levels. |
Japan | FSA / NPA | APA; Hon-nin Kakunin (eKYC ‘wa’) | Online selfie-plus-ID method permitted; My Number use expanding. |
South Korea | FSC / FSS | Non-face-to-face verification guidelines | Multi-factor non-face-to-face verification permitted. |
Hong Kong | HKMA | Remote onboarding guidance | Non-face-to-face account opening permitted with safeguards. |
Taiwan | FSC | Digital onboarding rules | eKYC permitted; Citizen Digital Certificate accepted. |
Australia | AUSTRAC | AML/CTF Act; safe harbour (DVS) | Electronic verification against reliable data sources permitted. |
New Zealand | DIA / RBNZ | AML/CFT Act; amended IVCOP | Electronic identity verification permitted; RealMe accepted. |
Bangladesh | Bangladesh Bank | e-KYC Guideline | NID-based e-KYC with biometric verification permitted. |
Pakistan | State Bank of Pakistan | Digital onboarding framework; NADRA | NADRA Verisys and biometric verification permitted. |
Sri Lanka | CBSL / FIU | Electronic KYC rules | Electronic KYC permitted under an evolving framework. |
Currency note: where a market operates multiple instruments, the principal route for regulated onboarding is shown. Positions current to June 2026 — confirm with local counsel before relying on any market-specific claim.
Permitted source types
| Source type | What it confirms | Where it applies |
|---|---|---|
| National eID scheme | Government-issued digital identity authenticated at source. | Singpass (SG), Aadhaar (IN), NDID (TH) |
| Government population registry | Direct check against the national civil registry. | Dukcapil (ID), VNeID (VN) |
| Bank-based eID | Identity confirmed through a verified banking credential. | BankID, OneID, regional bank rails |
| Credit bureau & data sources | Cross-reference against bureau and 270+ trusted data sources. | Across 95+ countries |
| Mobile & utility data | Confirmation against MNO and registered service records. | Selected emerging markets |
| Document + biometric (fallback) | OCR, NFC chip read, and PAD Level 2 face match. | 240+ countries & territories |
A Risk-Routing Model
A risk-routing model
Route each user by risk. Low-risk users clear through a Non-Doc check; standard and high risk go to document verification. A fallback path means a failed Non-Doc check never turns a genuine user away.
Identity request initiated
Jurisdiction Rules & Product Type
Frictionless verification for trusted signals
PassiveDocument verification as fallback
Coverage & Performance
Shufti’s APAC coverage, through one integration
Shufti runs Non-Doc and document verification across the same APAC markets through one integration, with AML screening alongside both. Passive eIDV covers 85+ countries and connects to 270+ data sources, including government registries, credit bureaus, and eID schemes such as BankID, Singpass, and OneID. Document verification supports 240+ countries and territories, with OCR, NFC chip reading where the document supports it, and biometric face matching at iBeta PAD Level 3.
AML, data residency, and getting started
AML screening alongside
Run sanctions, PEP, and adverse-media screening on the same identity, in the same flow. One configuration covers verification and AML together, so a compliant account is reached in a single pass.
Data residency
In-region processing and storage options meet local residency requirements across APAC, so data stays where the regulator expects it while you onboard through one integration.
One region. Infinite compliance requirements. Solved.
Don’t let regional verification hurdles slow down your expansion. Learn how top-tier platforms use a single orchestration layer to verify users across multiple APAC markets in seconds.
Book a DemoFrequently Asked Questions
Yes. The check matches the user’s name, date of birth, and national ID number directly against authoritative sources such as government registries, so the same compliance obligation is met without a document upload.
In most markets covered in this guide, yes. Singapore accepts Myinfo, the Philippines recognises the PhilSys ID, and Australia permits checks against reliable electronic data, though positions change often, so confirm the current rules with local counsel.
Passive matches the user’s details against trusted databases in the background, Active asks the user to log in through an eID such as Singpass, and Biometrically Enriched adds a facial match against the photo held in the government registry. Assurance rises with each method.
No. The flow steps the user up to an Active eID login or document verification automatically, so a legitimate user who fails a background data match still completes onboarding in the same session.
Checks run against government-grade records, and the Biometrically Enriched method adds a facial match with single or dual source cross-referencing to catch stolen and synthetic identities. Higher risk users can still be routed to document verification.
Yes. The verified identity is screened against sanctions lists, PEP registers, and adverse media in the same flow, whichever verification route the user takes, with no separate integration needed.
For businesses already on Shufti, none, since it is switched on as a configuration change in Journey Builder. New businesses can book a scoping call with Shufti’s APAC team to map the right routes before any integration work begins.







































