Inside a KYC Identity Verification Pipeline

Know Your Customer (KYC) checks are how banks, exchanges, and fintechs confirm you are who you claim to be. Step through the six stages below.

Drag to orbit, scroll to zoom, tap a station
Stage 1 of 6

Document Capture

~30-90s
typical automated verification time
80-95%
straight-through approval on clean documents
5+ yrs
record retention required by most AML regimes
2-5%
of global GDP estimated laundered annually (UNODC)

Why regulators require KYC

KYC is not optional for regulated firms. Anti-money-laundering (AML) frameworks such as the FATF Recommendations, the U.S. Bank Secrecy Act, and the EU Anti-Money-Laundering Directives require institutions to verify customer identity before providing financial services.

FATF R.10BSA / CDD RuleEU AMLD 5/6ISO 30107-3 (PAD)

The privacy tradeoff

Verification means handing over documents and biometrics, and that data becomes a target. A single KYC provider breach can leak passports and face images for millions of users, and unlike passwords, a face cannot be rotated.

Risk-based verification tiers

Regulators expect proportionality: the depth of verification should match the risk of the product and the customer. Most institutions implement three tiers.

Verification also is not a one-time event: transaction monitoring and periodic re-screening continue for the life of the account, which is why the audit trail from stage six matters.

Key terms in 20 seconds

Where verification fails in practice

Understanding failure modes explains why the pipeline has six stages instead of one. Each stage exists because attackers defeated a simpler design.

No single stage is reliable alone; the pipeline works because an attacker must beat every stage at once, while a legitimate user passes each one in seconds.

Enjoy this tool? Build your own with Super