Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · July 28, 2026

Remote eKYC: Methods, Risks, and Compliance

A definition-first guide to electronic KYC: remote identity evidence, digital onboarding, fraud controls, regulatory expectations, evaluation criteria, and implementation pitfalls.

By DiditUpdated
ekyc-remote-verification-methods-risks-compliance.png

eKYC, or electronic Know Your Customer, is the delivery of customer identification and due diligence through digital channels. It allows an organization to collect identity information, validate evidence, verify that the applicant is linked to it, screen for relevant risk, and record a decision without requiring every customer to visit a branch or office.

The “electronic” part describes the channel, not a lighter obligation. A remote flow still needs a policy for reliable evidence, fraud resistance, exceptions, human review, privacy, recordkeeping, and ongoing customer due diligence. Replacing a desk with an app changes the attack surface and operating model; it does not turn one selfie or database response into complete KYC.

This guide focuses on the remote-onboarding branch of the broader KYC lifecycle: how electronic evidence is collected, tested, bound to an applicant, and operated when the customer is not physically present.

Key takeaways

  • eKYC is digital KYC, not a single technology. Documents, NFC chips, authoritative databases, digital credentials, biometrics, and attended video can all support a remote decision.
  • Assurance depends on the whole system. Evidence strength, validation, applicant binding, capture integrity, policy, and exception handling matter more than whether the journey is labeled “automated.”
  • Remote onboarding creates distinct threats. Presentation attacks, injected media, emulators, stolen identity data, synthetic identities, account farms, and manipulated documents need separate controls.
  • Risk should determine the path. Lower-risk applicants may complete a short flow, while uncertainty or higher risk can trigger more evidence, an active challenge, or trained review.
  • The organization remains accountable. A provider supplies evidence and technical results; the regulated or relying organization owns the legal analysis, acceptance policy, records, and ongoing monitoring.

What does eKYC mean?

eKYC means conducting the identity and customer-due-diligence portions of KYC through an electronic journey. The applicant might use a phone, browser, kiosk, reusable digital identity, or assisted video channel. The organization may combine several kinds of evidence rather than force every person through the same document-and-selfie sequence.

The Financial Action Task Force guidance on digital identity is technology-neutral. It asks regulated entities to understand a digital identity system’s assurance level, architecture, and governance, then decide whether it is sufficiently reliable and independent for the relevant customer-due-diligence risk.

This makes eKYC an operating model rather than a product category with one fixed definition. In one market, an authoritative database match plus a bound phone may be acceptable for a limited account. In another, the policy may require a government document, chip verification, liveness, face comparison, and screening before any relationship begins.

eKYC, KYC, digital identity, and authentication compared

TermQuestion it answersTypical momentBoundary to preserve
KYCDo we know and understand this customer well enough for the relationship?Onboarding and continuing reviewBroader than identity evidence
eKYCCan the KYC evidence and decision be completed through electronic channels?Remote onboarding and refreshA channel, not a separate legal objective
Identity proofingDoes the claimed real-world identity exist, and is the applicant linked to it?Enrollment, recovery, or step-upDoes not by itself assess customer risk
Digital identityWhat digital representation, credential, or account refers to the subject?Enrollment and later useQuality depends on how it was issued and maintained
AuthenticationDoes the current user control the authenticator bound to an account?Login or transaction authorizationDoes not prove how the account was originally established
AML screeningDoes the customer appear in relevant sanctions, PEP, or other risk data?Onboarding and rescreeningA possible match is not automatically a confirmed match

These concepts work together. eKYC can establish a customer record and bind an authenticator. Authentication can then protect later access. Anti-money-laundering controls can use the verified customer profile to interpret screening and behavior. Treating them as one score hides which conclusion is actually supported.

How does an eKYC process work?

1. Define the policy and assurance target

Start with the protected relationship or action. Specify the jurisdictions, customer types, products, risk factors, accepted evidence, prohibited cases, escalation rules, retention periods, and decision owners. An account with limited functionality may not need the same evidence as account recovery or access to a regulated financial product.

The policy should also define what happens when the preferred method is unavailable. A person may not own a compatible phone, have a readable chip, possess the default document, or be able to complete a biometric action. An alternate path is part of the control.

2. Collect the minimum identifying data

Collect the attributes needed to resolve the customer and meet the applicable purpose. This can include legal name, date of birth, address, nationality, government identifier, or contact information. More data does not automatically produce more assurance. Every field should have a reason, protection, retention rule, and deletion path.

3. Resolve the identity

Resolution determines whether the supplied attributes identify one person in the relevant population. The NIST SP 800-63A-4 identity-proofing model separates resolution, validation, and verification. That separation is useful well beyond US federal services because it prevents a database hit from being mistaken for proof that the applicant owns the record.

4. Validate evidence and attributes

Validation tests whether the evidence is authentic, accurate, current, and acceptable. A document path can inspect expiry, layout, printed fields, machine-readable data, security features, signs of alteration, and issuer information. An NFC path can read signed chip data where supported. A database path can corroborate attributes against an authoritative or credible source.

Return specific evidence and reason codes. “Expired evidence,” “unsupported evidence,” “field mismatch,” and “suspected manipulation” require different customer guidance and operational actions.

5. Verify the applicant’s link to the identity

Verification connects the person in the journey to the validated evidence. A remote document flow may compare a live facial capture with the portrait on the document. A digital credential may use cryptographic proof of control. An attended flow may involve a trained agent following a defined procedure.

Document validation, liveness, face matching, and capture integrity answer different questions. Passing one should not silently imply that all four passed.

6. Screen and risk-rate the customer

Where required, screen the customer and related people against relevant sanctions, politically exposed person, adverse-media, or other risk sources. Combine screening evidence with geography, product, purpose, customer type, ownership, and other policy factors.

Name matching is probabilistic. Preserve source data and match context, distinguish candidate from confirmed matches, and route ambiguity according to risk rather than declining every similar name.

7. Decide and preserve the record

Map evidence into explicit outcomes such as approved, retry, step-up, manual review, or declined. Store the policy and workflow version, evidence references, structured results, timestamps, reviewer actions, and decision rationale needed for audit, appeal, and later refresh.

The backend—not the browser redirect—should control customer state. Verify the final result through an authenticated server-to-server path and make retries idempotent so a delayed event cannot create duplicate customers or contradictory decisions.

8. Monitor and refresh

eKYC does not end at account opening. Documents expire, sanctions information changes, accounts are recovered, ownership changes, and behavior can diverge from the expected profile. Define periodic and event-driven refresh triggers, then preserve the relationship between the new evidence and the original record.

Evidence methods used in eKYC

MethodWhat it can supportStrengthsImportant limitations
Document optical captureAttribute collection and document validationBroad availability and familiar user journeyImages can be altered, replayed, poorly captured, or unsupported
NFC chip readingSigned document data and higher-confidence portrait extractionCan verify chip signatures and reduce reliance on pixelsRequires compatible documents, devices, and implementation
Authoritative database checkAttribute corroborationNo physical document may be neededCoverage, freshness, matching logic, and lawful access vary
Biometric face comparisonLink applicant capture to a reference portraitDirect holder-binding evidenceAccuracy depends on reference, quality, threshold, and population
Liveness or PADEvidence of a live presentation at captureHelps against defined replay and presentation attacksDoes not automatically stop injected media or prove identity
Digital credentialCryptographically presented identity attributesCan minimize repeated document captureTrust depends on issuer, assurance, status, wallet, and verifier policy
Attended videoAgent-guided evidence and exception handlingCan support complex or uncertain casesRequires training, consistency, secure tooling, and quality controls

No method is universally best. A good architecture allows policy to combine evidence and change the path without rebuilding the entire application.

Regulatory and standards expectations

FATF: reliability, independence, and risk

FATF Recommendation 10 establishes the customer-due-diligence foundation. Its digital identity guidance does not approve technologies by label. It asks the relying organization to understand assurance and determine whether the system is reliable and independent in light of money-laundering and terrorist-financing risk.

EBA: a governed remote process

The European Banking Authority remote-onboarding guidelines set expectations for credit and financial institutions using remote customer onboarding. They cover policies, solution assessment, information collection, document authenticity, biometric and non-biometric methods, reliance on third parties, ICT security, and ongoing oversight. A purchased component still needs governance and testing inside the institution’s control framework.

European Union AML rules: CDD remains the objective

Regulation (EU) 2024/1624 provides for identity documents, reliable independent sources, and qualifying electronic identification means as routes for verification. It also retains the wider CDD duties: identify the customer and beneficial owner, understand the relationship, check relevant financial-sanctions exposure, and monitor the relationship.

NIST: proofing is a series of distinct controls

NIST separates identity resolution, evidence validation, applicant verification, enrollment, fraud management, privacy, and redress. Its remote-proofing requirements also distinguish presentation attacks from digital injection and forged-media threats. Even when an organization is not bound by NIST, the model is a practical way to write testable requirements.

The main eKYC fraud threats

Stolen genuine evidence

A criminal can possess a real person’s document images and personal data. Document authenticity alone does not prove the current applicant is the rightful holder.

Altered or fabricated documents

Text, portraits, machine-readable data, or layouts can be modified. Validation should compare independent fields and security evidence rather than trust a visually convincing front image.

Presentation attacks

Printed photos, screen replays, masks, and other artefacts target the expected camera. Presentation attack detection and capture guidance can add evidence at this boundary.

Injection attacks

Virtual cameras, emulators, modified applications, hooks, and manipulated requests can insert forged media after or around the physical sensor. NIST SP 800-63A-4 requires remote proofing systems in its scope to increase confidence in genuine sensor capture and analyze media for modification; biometric comparison alone is not sufficient.

Synthetic and composite identities

Real and fabricated attributes can be assembled into an identity that does not correspond to one genuine person. Cross-session device, contact, evidence, velocity, and relationship signals can reveal patterns that a single document decision misses.

Account farms and automated enrollment

Scripts can create many attempts, exploit retries, or test stolen data at scale. Rate limits, attempt binding, resource controls, velocity analysis, and review queues should be designed before launch.

How to evaluate an eKYC service

Assurance and regulatory fit

Ask which evidence strengths, identity-proofing models, jurisdictions, customer types, and regulated use cases are supported. Map every independent test or certification to the exact component, version, mode, threshold, and attack scope.

Coverage quality

Build a matrix for the countries, documents, scripts, databases, devices, and languages your customers actually use. “Global coverage” is not enough. Measure unsupported evidence, extraction quality, completion, retry, and review by segment.

Fraud resistance

Request an attack-by-attack map for document manipulation, replays, masks, morphs, generated media, injection, emulator use, repeated identities, and automated attempts. Review false-positive and false-negative behavior at the intended operating threshold.

Decision and review operations

Inspect evidence views, reason codes, policy versioning, queues, permissions, reviewer actions, audit logs, retry controls, and appeals. Automation is useful only if exceptions remain understandable and governable.

Developer reliability

Test API authentication, idempotency, signed events, event ordering, retries, reconciliation, status transitions, timeouts, versioning, rate limits, sandbox cases, and environment separation. Simulate a completed user flow whose webhook arrives late or more than once.

Privacy, security, and inclusion

Map collection, purpose, consent where applicable, access, encryption, region, retention, deletion, and subprocessor handling for every attribute and biometric artefact. Measure outcomes by device and relevant population, then provide accessible recovery and alternative evidence paths.

Common eKYC implementation mistakes

Buying a document check and calling it KYC

A genuine document can belong to another person, while an accurately identified person may still require screening and risk assessment. Keep evidence, identity, customer risk, and eligibility separate.

Forcing one flow on every applicant

A uniform path can create excessive burden for low-risk customers and insufficient evidence for higher-risk ones. Use bounded, documented branches with explicit step-up criteria.

Trusting an automation percentage

A high automated-decision rate can conceal weak thresholds, unsupported populations, or an overloaded retry path. Measure security, completion, review, and downstream outcomes together.

Ignoring the fallback

If the only fallback is support staff making undocumented exceptions, the weakest path will define the system. Design alternate evidence, manual review, redress, and recovery with the same care as the default.

Treating vendor output as the final legal decision

The provider does not know the full customer relationship, product exposure, legal basis, or risk appetite. Keep policy and customer-state ownership in the relying organization.

An eKYC deployment checklist

Before launch, confirm that:

  • the protected relationship, jurisdictions, and assurance target are documented;
  • accepted evidence and independent sources are mapped to customer and risk type;
  • resolution, validation, verification, screening, and eligibility remain distinct;
  • presentation, injection, stolen-evidence, and automated-attempt threats are tested;
  • the backend verifies final outcomes and processes duplicate events safely;
  • retry, step-up, review, appeal, and alternative paths have clear owners;
  • privacy purpose, retention, access, residency, and deletion are defined;
  • production-like devices, networks, documents, and populations are included in testing;
  • policy, model, workflow, and reviewer actions are versioned for audit;
  • refresh and ongoing-monitoring triggers are connected to the customer record.

Using Didit for an eKYC workflow

Didit lets teams compose ID Verification, Liveness Detection, Device and IP Analysis, and other checks through the Workflow Orchestrator. The published full KYC bundle is $0.33 for ID Verification, Passive Liveness, Face Match, and IP Analysis, with 500 free verifications per month.

Teams can review module-level rates on the pricing page. These controls supply evidence for a remote journey; the organization still owns its customer-due-diligence policy, legal interpretation, exceptions, and monitoring.

Frequently asked questions

What does eKYC stand for?

eKYC stands for electronic Know Your Customer. It is the use of electronic channels and evidence to conduct customer identification and related due diligence remotely.

Is eKYC the same as online identity verification?

Identity verification is a core part of eKYC, but eKYC can also include customer-risk assessment, screening, decision records, exceptions, and ongoing refresh. The terms are often used interchangeably in product searches, but their operating scope differs.

Does eKYC always require a selfie and identity document?

No. The acceptable evidence depends on jurisdiction, risk, policy, and assurance. Some flows can use authoritative databases, digital credentials, NFC-enabled documents, attended video, or combinations of evidence.

Can eKYC be fully automated?

Many low-risk cases can be automated, but a defensible program needs a path for uncertainty, unsupported evidence, accessibility, potential matches, and appeals. “Fully automated” should not mean “no governed exception process.”

Is remote eKYC less secure than in-person verification?

Not inherently. Security depends on evidence strength, capture integrity, fraud controls, process design, and testing. Remote and in-person methods have different threats and should be evaluated against the required assurance.

How are eKYC and AML related?

eKYC creates and verifies the customer identity and initial risk record. Anti-money-laundering controls use that context for screening, monitoring, investigations, and reporting throughout the relationship.

How often should eKYC be repeated?

There is no universal schedule. Use applicable legal requirements and a documented risk model, with event-driven refresh when identity data, evidence validity, sanctions exposure, ownership, behavior, or account control changes materially.

Primary references

Good eKYC preserves the logic of customer due diligence while changing the channel. Define the required assurance, collect proportionate evidence, protect the capture path, keep exceptions governable, and connect the onboarding decision to the continuing customer relationship.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page
Remote eKYC: Methods, Risks, and Compliance