Blog | 10 mins read

September 29, 2026

The KYC evidence problem: Why banks are moving beyond passports and video

For most of the last two decades, identity verification in KYC relied on a relatively simple premise: collect a passport or national ID, review it, and retain it as evidence. That premise is becoming harder to defend. Generative AI has made it easier to produce synthetic documents and convincing face manipulation, while regulatory expectations increasingly emphasize reliable, independent sources of information.

The replacement cannot be a single technology. Governments are building digital identities and wallets; regulators are defining when those credentials can be relied upon; and banks are expanding the use of non-documentary data, commercial databases, and other independent signals. The result is a transition in which old methods are losing credibility faster than new ones are gaining universal legal and operational acceptance. Banks are therefore living in the gap — triangulating imperfect signals and layering fraud defenses across a fragmented, jurisdiction-by-jurisdiction landscape.

Key takeaways

  • Identity is only part of the corporate KYC challenge, with banks still needing to establish ownership, control, and authority.
  • Digital identity won’t replace KYC overnight as banks navigate uneven technology, regulation, and adoption across markets.
  • AI is weakening traditional identity evidence, making documents and video less reliable as standalone verification methods. The future of KYC is evidence triangulation, combining digital credentials, registries, databases, and non-documentary signals.
  • There will be no single global path to digital KYC, as privacy rules, regulatory requirements, and infrastructure maturity vary by jurisdiction.

Identity verification is only half the corporate KYC problem

Even before the verification step, a bank must first identify beneficial owners, controllers, and authorized representatives, to establish the ownership, control, or authority relationship. Only then can it use an identity credential to validate the individuals.

This becomes more important as access to beneficial ownership information has become more restrictive. In the EU, privacy concerns and the Court of Justice’s 2022 ruling on unrestricted public access to beneficial ownership registers have contributed to a shift away from assuming that ownership information is available through an open public lookup. Newer EU measures are intended to create a more consistent framework for legitimate-interest access, but implementation remains a moving target.

Even in non-EU jurisdictions, access to BO information is being restricted. Another good example is the Philippines, which took all BO information off their General Information Sheets (GIS) and migrated to a new platform called HARBOUR; but as of yet, no access to HARBOUR is provided to covered parties.

This creates an unusual tension: banks face stronger expectations to independently verify beneficial ownership while some of the public sources that once made ownership easier to establish are becoming more restricted.

Digital identity will not solve the discovery problem. It becomes another piece of evidence after the relevant individual has been identified.

The old evidence is breaking down

The problem is particularly acute when verifying the people behind a corporate customer. In this context, identity verification for banks means evidence that beneficial owners and control persons are real people and that they are who they claim to be. Historically, a passport or national ID—sometimes notarized, certified or apostilled—provided much of that evidence.

But cracks have been visible in this model for a while. The Financial Action Task Force’s (FATF) Recommendations 24 and 25, strengthened by its 2023 guidance emphasize adequate, accurate, and up-to-date information and, where appropriate, verification against reliable, independent sources. Challenges remain, however, as layered ownership structures, nominee arrangements, and jurisdictions with weak or inaccessible corporate registries have made document-based verification a genuinely hard problem.

At the same time, the rise of AI-enabled fraud lets bad actors generate convincing identity documents and manipulate live video. The issue is not that documents or video have become useless. It is that a single piece of evidence, even one reviewed by a human, can no longer carry the same weight it once did.

This is where KYC identity verification is changing. Rather than treating a document, selfie, or video call as the answer on its own, banks can use several sources to build a more complete picture of the customer. The same approach also matters for AI fraud in identity verification, where manipulated documents, synthetic identities, and altered video can make a single verification signal less dependable.

Germany shows how quickly the gold standard can become transitional

Germany offers a useful example of how identity-verification methods evolve under pressure. BaFin, Germany’s financial regulator, approved VideoIdent in 2014 and subsequently imposed detailed controls around real-time, uninterrupted identification and human review. For years, it represented a sophisticated answer to remote identity verification in a highly regulated market.

But the technology it was designed around is also the technology modern fraud can attack most directly. Face-swapping, camera injection, and other forms of real-time manipulation challenge the assumption that a live video session necessarily provides strong evidence of identity. German regulators have consequently described VideoIdent as a bridging technology toward more advanced digital identity approaches rather than an end state.

The lesson is broader than Germany: the compliance value of a verification method can change as fraud changes. A process that was once considered highly reliable can become one layer of evidence rather than the final answer.

The EU is building a different kind of evidence

The European Union’s answer is eIDAS 2.0 and the European Digital Identity Wallet. Rather than asking a bank to decide whether a document image is genuine, the model is designed around cryptographically verifiable credentials and attributes that can be presented to a relying party.

For KYC, the significance extends beyond proving a person’s basic identity. The wallet framework can support verified attributes and credentials associated with legal persons and business roles whilst maintaining privacy. In the right implementation, this creates a more direct way to establish both who an individual is and, where authoritative credentials are available, their relationship or authority within a legal entity.

The EU has also put implementation on a defined legal timetable, with member states required to make at least one wallet available to citizens and residents by the end of 2026, and obligated private-sector organizations, including banks, must then be capable of accepting it roughly 12 months later, in late 2027. That distinction matters: implementation is uneven. The existence of a wallet, its technical interoperability and a bank’s legal obligation to accept or rely on a credential are not necessarily the same milestone.

Other markets show why there will not be one global model

Singapore’s national digital identity, Singpass, and consent-based data-sharing service, Myinfo, demonstrate what a mature integration between national identity infrastructure and financial services can look like. Government-held information (across immigration, tax, and pension authorities) can be shared with consent and used by banks in place of repeatedly collecting the same documents. Since Myinfo is considered a reliable, independent source for identity verification, banks don’t need to separately collect ID when it’s used. Myinfo Business extends this same logic to legal entities, retrieving verified company officer and ownership data directly from government sources for corporate onboarding.

Estonia represents an even deeper model: digital identity is embedded into the fabric of public and private services, with more than 90% of Estonians holding a digital ID used from banking to digitally signing documents. The significance is less the ID card itself than the surrounding national infrastructure that makes digital identity usable across everyday transactions.

In the UK, the government has developed GOV.UK One Login and a Digital Verification Services (DVS) framework meant to let certified private providers deliver identity checks that banks, airlines, and others could rely on. However, a more ambitious plan for a mandatory national digital ID was repeatedly narrowed after public pushback, until the program was ultimately abandoned in July 2026. The DVS framework survives, but adoption has been slow as banks may be cautious about transferring identity risk to third parties, particularly where cost, ownership, and fragmented processes remain concerns.

India’s biometric identity number, Aadhaar, shows the other side of the equation. India built digital identity at extraordinary scale and developed multiple remote-verification capabilities around it, such as biometric matches, video-based identification processes, or digital documents. But private-sector access to Aadhaar-based eKYC was constrained following the Supreme Court’s 2018 decision on privacy grounds and later rebuilt on narrower legal terms. The example demonstrates that technical capability does not by itself determine how freely financial institutions can rely on a digital identity—legal and political implications can shift momentum forwards or backwards with similar ease.

The non-documentary path is already here

Government-issued digital identity is not the only way beyond the passport. In the United States, Customer Identification Program rules have long permitted non-documentary methods. Banks can compare information such as name, address, date of birth, and identification numbers against independent sources including credit bureaus and public records.

The model predates today’s AI fraud environment, but its role is changing. Instead of asking whether one document looks genuine, banks can synthesize multiple low-friction signals and look for combinations that do not make sense. As documents and live video become easier to manipulate, this kind of database-driven verification is moving from a fallback approach toward a standing layer of KYC fraud prevention toolkits.

The operating model is triangulation

For banks, the practical response is a broader evidence architecture rather than a replacement of one source with another. Commercial ownership databases, corporate filings, registries accessed under legitimate-interest rules, documentary evidence, non-documentary verification and, increasingly, digital credentials can each contribute a signal.

The objective is to reconcile those signals, identify inconsistencies, and escalate cases where the evidence does not align. A wallet-based attestation may provide a high-confidence identity signal. A registry may establish ownership. A commercial database may corroborate an address or identity history. A document may still provide useful evidence. Layered fraud controls then sit across the process to detect manipulation or anomalous behavior.

For financial institutions, this is the practical shift in KYC evidence verification that helps them decide which combination of evidence provides enough confidence for a particular customer, jurisdiction, and risk level.

The likely direction of travel: Banks are living in the gap

Across the markets we’ve examined, the direction is becoming clearer: the burden of proof is shifting from a single document toward multiple, independent and harder-to-fake signals. Some will be government-issued and cryptographically verifiable. Others will come from commercial data, registries, corporate records, or non-documentary sources.

But the transition is uneven. Digital infrastructure, legal permissions, privacy rules, regulatory expectations, and institutional adoption do not move at the same speed. A system can be technically ready but legally constrained. A framework can be available but slow to gain institutional adoption. A government can narrow or redesign access after privacy or political concerns emerge.

For banks operating across jurisdictions, that means there is no single global switch from documents to digital identity. Instead, institutions must manage different levels of maturity and different rules about which evidence can be used, when, and for what purpose.

The KYC evidence model is changing — but the gap is here to stay

The future of KYC is unlikely to be document-free. It is more likely to be evidence-driven. As AI makes traditional evidence less dependable and governments build stronger digital identity infrastructure, banks will increasingly combine documentary, non-documentary, registry, and digital credentials to establish confidence in the customer.

The EU is putting a legal timetable behind that shift. Germany shows how quickly video-based identification can move from leading-edge solution to transitional technology. Singapore and Estonia demonstrate what mature digital identity infrastructure can enable. The UK and India show how legal, political, and institutional considerations can reshape technically capable systems.

Until those pieces converge more consistently, triangulation will remain the operating reality: identify the people behind the entity, establish their relationship to it, corroborate their identities through independent sources, and layer fraud defenses around the process. That is not simply a temporary workaround while digital IDs arrive. For a global banking system operating across different regulatory and technological environments, it may be the enduring KYC model.

Frequently Asked Questions

What is the eIDAS 2.0 deadline for the EUDI Wallet?

Under the current EU framework, Member States are required to make European Digital Identity Wallets available by the end of 2026. Relevant private-sector organizations will then have acceptance obligations by the end of 2027 where the regulation applies. For banks, the important point is that wallet availability and mandatory acceptance are separate milestones.

What must financial institutions do to accept EUDI Wallet credentials?

Financial institutions that fall within the applicable eIDAS 2.0 requirements need to prepare their systems and processes to receive and validate wallet-based credentials. Operationally, that means understanding which wallet credentials can be accepted, integrating the relevant technical interfaces, validating the credentials and attributes presented, maintaining appropriate records, and fitting wallet-based identity into existing KYC and authentication controls. The wallet should become another trusted evidence source within the process rather than a reason to remove every other control.

What should a bank actually do operationally in the meantime?

Banks do not need to wait for the EUDI Wallet rollout before changing their KYC operating model. They can strengthen existing KYC identity verification by combining documentary and non-documentary sources, improving exception handling, checking independent data sources, and adding stronger fraud controls around documents, video, and digital onboarding. They can also map where EUDI Wallet credentials could eventually fit into onboarding, authentication, ongoing KYC, and re-KYC workflows.

Will digital identity replace traditional KYC documents?

Not necessarily. Digital identity can reduce the need to rely on documents in some situations, particularly where a credential comes from a trusted and authoritative source. But the wider KYC process still needs to establish ownership, control, authority, and other relevant customer information. The likely direction is a combination of digital credentials, documents, registries, commercial databases, and non-documentary evidence rather than a complete move to document-free KYC.

What are non-documentary methods of KYC verification?

Non-documentary methods verify identity using information from sources other than an identity document. Depending on the jurisdiction and the institution’s permitted controls, this can include information such as name, address, date of birth, identification numbers, credit bureau data, public records, corporate databases, and other independent sources. The value of non-documentary KYC verification is that it gives banks another way to corroborate identity and identify inconsistencies rather than relying on one document alone.

Featured insights

contact pinContact Us

Safe harbour

The presentations, videos, and other Investor Day materials have been prepared for informational purposes only. Certain statements contained in these materials may constitute forward-looking statements regarding eClerx's business outlook, growth strategy, market opportunities, client demand, operational priorities, technology and AI-led initiatives, investment plans and anticipated financial and operating performance.

These forward-looking statements are based on management's current expectations, assumptions and estimates and are subject to known and unknown risks and uncertainties that could cause actual results to differ materially from those expressed or implied. Such risks and uncertainties include, but are not limited to: changes in global economic and business conditions, customer spending patterns, competitive pressures, technological developments including evolving regulations relating to AI, data privacy and data protection, cybersecurity threats, talent availability and retention, currency fluctuations, geopolitical developments and other factors that may affect the Company's business, clients and operating performance.

Forward-looking statements are made only as of the date of the relevant Investor Day materials and should not be relied upon as indicators or guarantees of future performance. The Company undertakes no obligation to publicly update, revise or supplement any forward-looking statement to reflect subsequent events or circumstances, except as required by applicable law.

By clicking ‘Accept’ or accessing these Investor Day materials, you acknowledge that you have read and understood this Safe Harbour Statement.