Skip to main content
Didit Raises $2M and Joins Y Combinator (W26)
Didit
Asia-Pacific

Identity verification
built for Malaysia Flag of Malaysia

MyKad and Malaysian e-Passport on one session, cross-checked against the JPN national registry and credit-bureau header data — $0.33 full KYC, 500 free every month.

Backed by
Y Combinator
GBTC Finance
Bondex
Crnogorski Telekom
UCSF Neuroscape
Shiply
Adelantos

Trusted by 2,000+ organizations worldwide.

Country brief

How identity verification works in Malaysia.

The fraud surface and the frameworks an engineering or compliance lead needs before scoping an integration.
Fraud landscape
Three pressures shape Malaysian identity fraud: deepfake injection against the BNM-mandated e-KYC flows on mobile banking and DAX onboarding, organised forgery of legacy MyKad and MyPR cards in the migrant-worker remittance corridors, and synthetic-identity mule farming against DuitNow-connected wallets. Didit scores 200+ real-time fraud signals on every session — face morph, replay, injection, document tampering, device intelligence, IP geolocation.
Compliance frameworks
  • AMLA 2001 (Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act)
  • PDPA 2010 (Personal Data Protection Act)
  • BNM e-KYC Policy Document (2020)
  • SC Guidelines on Recognized Markets (Digital Asset Exchanges)
  • Capital Markets and Services Act 2007
  • FATF 40 recommendations
Regulators

Who supervises identity verification in Malaysia.

These are the supervisors a Malaysia verification flow has to answer to. One Didit hosted flow + one audit log covers every one of them — no separate integration per agency.
  • BNM

    Bank Negara Malaysia — central bank and prudential supervisor for banks, EMIs and approved-payment-system operators. Issues the e-KYC Policy Document (2020) binding on every reporting institution.

  • SC

    Securities Commission Malaysia — securities and digital-asset supervisor. Registers Digital Asset Exchanges (DAX) and Initial Exchange Offering operators under the Capital Markets and Services Act 2007.

  • FIED

    Financial Intelligence and Enforcement Department within Bank Negara Malaysia — Malaysia's Financial Intelligence Unit. Receives Suspicious Transaction Reports under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA 2001).

  • JPDP

    Jabatan Perlindungan Data Peribadi — enforces the Personal Data Protection Act 2010 (PDPA 2010) and the 2024 amendments. Governs how identity-verification data is collected, processed and stored.

  • JPN

    Jabatan Pendaftaran Negara — civil-registry authority within the Ministry of Home Affairs. Issues every MyKad, MyKid and MyPR and operates the authoritative-source database for identity verification.

Verification flow · One API

Four modules. One verification.

ID, biometric, AML, and a Malaysia database cross-check — composed on one workflow, billed per success, returned in one report.
01 · ID

Capture and read the ID.

Captured on any phone — auto-classified, OCR-parsed, and template-verified.

  • MyKad (the current chip card), MyKid (minors), MyPR (permanent residents), Malaysian Passport with the chip read on the NFC channel, and JPJ Driver's Licence.
  • Returns the full name, 12-digit IC number, date of birth, sex, race, religion, and address.
Read the docs
Stage 01Capture and read the ID
  • MyKad — 12-digit IC number
  • MyKid · MyPR
  • Malaysian Passport — NFC chip read
02 · Biometric

Match the face. Prove it's a real person..

Selfie confirmed live and matched against the ID portrait.

  • Duplicate check: 1:N face search across existing users. Free.
  • Active liveness ($0.15) for elevated-risk flows — user turns or blinks.
Read the docs
Stage 02Match the face. Prove it's a real person.
  • Selfie on any phone or laptop camera
  • Mobile-handoff QR when the user starts on desktop
03 · AML

Screen for sanctions, PEPs, and adverse media.

Didit screens the user's name against the global pool of 1,300+ sanctions, Politically Exposed Persons (PEP), and adverse-media lists, plus every Malaysian regulatory watchlist (Ministry of Home Affairs Sanction List, SC AOB Sanctions, BNM warnings, Dewan Rakyat PEP register, LFSA-ALERT, MACC).

Severity-scored. Ongoing monitoring ($0.07/user/yr) re-checks daily and fires a webhook on new hits.

Read the docs
Stage 03Screen for sanctions, PEPs, and adverse media

Screen for sanctions, PEPs, and adverse media — see the docs for the full module surface.

04 · Registry

Cross-check against the JPN national registry.

Cross-checked against the authoritative civil registry.

  • The Malaysia National ID check (mys_national_id, $0.16, >75% coverage) is the JPN government-sourced authoritative lookup — name, date of birth, 12-digit IC and optional address + phone are verified against the citizen-records source.
  • The Malaysia Credit Bureau check (mys_credit_bureau, $0.71, >55% coverage) cross-checks against credit-header data — useful for fintech credit underwriting and BNM-licensed digital-bank onboarding.
Read the docs
Stage 04Cross-check against the JPN national registry

Cross-check against the JPN national registry — see the docs for the full module surface.

Documents covered

Every Malaysia document Didit accepts.

One row per accepted credential — flag, document name, document type. Live from the Didit Business Console.
Compliant by design

Open a new country in one click. We do the hard work.

We open the local subsidiaries, secure the licenses, run the penetration tests, earn the certifications, and align with every new regulation. To ship verifications in a new country, flip a toggle. 220+ countries live, audited and pen-tested every quarter — the only identity provider an EU member-state government has formally called safer than in-person verification.
Read the security & compliance dossier
EU financial sandbox
Tesoro · SEPBLAC · BdE
ISO/IEC 27001
Information security · 2026
SOC 2 · Type I
AICPA · 2026
iBeta Level 1 PAD
NIST / NIAP · 2026
GDPR
EU 2016/679
DORA
EU 2022/2554
MiCA
EU 2023/1114
AMLD6 · eIDAS 2.0
EU-aligned by design
FAQ

Common questions about Malaysia.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page