KYC verification process: does strict compliance hurt growth?
We have all been there. You tap "Sign Up" on a slick neobank app, the onboarding flow loads, and then — the wall. A passport photo. A selfie with a chin tilt. A proof of address that has to be less than three months old.
Jocelyn Davenport·Updated: July 23, 2026·12 min read

By the second upload, you are already looking for the close button. That moment, multiplied by millions of would-be customers, is the silent tax that strict KYC compliance imposes on the fintech industry.
The uncomfortable truth is that we have built a verification layer designed to catch bad actors, and it is catching perfectly good customers instead. Roughly 40 to 60 percent of users abandon onboarding flows that are manual or poorly designed. Push the verification past three minutes and the abandonment rate climbs to about 70 percent. A Signicat survey found that 63 percent of European consumers have walked away from a financial sign-up because the verification step felt like a chore. This is not a fringe frustration. It is the default behavior of a frustrated majority.
Yet none of those numbers would matter if regulators were not standing on the other side of the desk. In 2024, global regulators handed out roughly $3.2 billion in AML and KYC fines to banks alone. Over 60 percent of fintechs have been fined for missing KYC checks while trying to onboard customers too quickly — and those fines often exceed $250,000 per incident. So fintechs are caught in a tightening vise: slow down to verify, lose the customer; speed up to keep the customer, pay the regulator.
The question for the industry is no longer whether KYC matters. It does, and quite obviously. The question is how to engineer a verification flow that respects the user's cognitive budget without giving compliance the short end of the stick.
The hardest part of compliance is not the regulation. It is the moment a person decides your app is not worth the effort.
The Hidden Cost of Friction: Why Users Abandon Onboarding
Friction in onboarding is not a minor UX problem. It is a conversion problem with regulatory teeth. Behavioral economics gives us a clean way to see why. Each additional step, each re-upload, each awkward camera instruction adds a small unit of cognitive load. Load does not scale linearly — it compounds. By the time we ask a user to tilt their head, then confirm their address, then retake a blurry document, the total effort has crossed what behavioral researchers call the "too much" threshold. At that point, the rational economic decision is to walk away, and we do.
The data backs this up with uncomfortable precision. Users who are asked to re-upload an identity document are three times more likely to abandon the process than those who sail through the first time. That single stat should haunt every product manager who treats verification as an afterthought. We are not losing users because we asked for a passport. We are losing them because we asked twice.
What is striking is how patient consumers claim to be in surveys versus how impatient they actually are at the moment of action. They will nod along when asked whether they accept verification as a concept, and the very same people are the ones closing the tab the moment the flow crosses the three-minute mark or asks for a third input. The gap between stated preference and revealed behavior is where fintechs bleed pipeline.
There is also a demographic dimension we tend to underplay. Younger users have lower tolerance for legacy verification patterns because they read them as incompetence. Older users sometimes have lower tolerance still, because the same patterns confuse them. The verification flow that frustrates an eighteen-year-old in Berlin is often the same flow that confuses a sixty-two-year-old in Lyon, and they leave for opposite reasons.
Regulatory Stakes: The $3.2 Billion Price of Non-Compliance
It would be tempting to read the drop-off numbers and conclude that the answer is to lighten up on verification. The regulatory numbers suggest otherwise. In 2024, regulators imposed about $3.2 billion in AML and KYC fines on banks. The financial penalties are only the visible surface. Below it sit consent decrees, license reviews, and the very real possibility of being shut out of correspondent banking.
The cost of getting KYC wrong is not a single quarterly line item. It is an ongoing operational expense that the average financial institution now shoulders at roughly $72.9 million per year, according to industry estimates. That figure covers labor, vendor contracts, remediation work, audit overhead, and the perpetual tuning of monitoring systems. When a fintech decides to automate or skip a check, it is making a calculated bet against a fine distribution that has, by every recent measure, been trending upward.
A subtle dynamic deserves attention here. Regulators are not just fining institutions for missing checks. They are also publicly naming them, which means the reputational cost now exceeds the financial cost for many consumer-facing brands. A $300,000 penalty is survivable. A headline that says your neobank let synthetic identities through is not. We have watched this trade-off play out repeatedly: the fintech that built a beautiful onboarding funnel, then quietly patched it after a consent order, then never quite recovered its growth curve.
Compliance is the price you pay for being allowed to operate. The fine is what you pay when you try to operate without it.
The pace of enforcement is also accelerating, even as user expectations rise. The same year we saw record AML fines, we saw consumer abandonment metrics at record highs. Both trajectories are happening at once, because the underlying volume of digital onboarding is exploding. More accounts mean more KYC work, more opportunities for failure, and more users bouncing at the friction.
Operational Bottlenecks in Manual Identity Verification
Manual KYC, in its traditional form, looks something like this. A user uploads a document. An analyst reviews it. The analyst cross-references names against sanction lists, politically exposed person databases, and adverse media. A decision is made, sometimes in minutes, sometimes in days. Each step is defensible in isolation. Together, they form a process that was designed before any of us carried a passport in our pocket.
The bottleneck is not the analyst's diligence. The bottleneck is that this pipeline was built for a world where financial accounts were opened in branches, not on phones. We inherited the workflow and then strapped a mobile camera to it, expecting the result to feel modern. It does not.
Consider the human hours involved. Even a moderately efficient compliance team spends the bulk of its time not on the suspicious cases, but on the long tail of mostly-clean verifications that still require an analyst's eyes. That is operational gravity. It pulls experienced reviewers away from the cases where their judgment actually matters, and it inflates the per-customer cost. Multiply that across thousands or millions of onboarding events, and the economics of manual verification start to look less like a compliance choice and more like a labor problem.
We can also see the effect on the user side. Manual flows almost always include some form of "we will get back to you" delay. Even when the delay is hours, it changes the psychological state of the applicant. They were excited about the product. Now they are wondering if the company is real. The activation moment — that narrow window when intent converts into commitment — closes quietly, and no funnel dashboard notices.
| Approach | Typical Onboarding Time | Drop-off Risk | Compliance Confidence |
|---|---|---|---|
| Manual document review with analyst | Hours to days | High (40-60%) | High but expensive |
| Semi-automated checks with human fallback | 3-10 minutes | Moderate | High |
| Fully automated, biometric-led | Under 90 seconds | Lowest | High when paired with monitoring |
The middle column is doing a lot of work in that table. Drop-off is not a binary. It is a probability distribution shaped by timing, repetition, and the perceived competence of the interface. The research on document re-uploads gives us a concrete anchor: a second attempt is associated with roughly three times the abandonment of a clean first pass. Every extra field we add is a small bet against conversion.
Engineering a Seamless Flow: The Role of Passive Liveness
The most interesting shift in the last two years is the move from active liveness detection to passive liveness. In the old model, users were asked to blink, smile, or turn their head. Each instruction was a tiny invitation to fail. A user with a tremor, a user filming in dim light, a user wearing glasses — all of them got bounced into a retry loop that contributed to the three-times-higher abandonment rate we already see on re-uploads.
Passive liveness flips the script. Instead of asking the user to perform, the system reads signals from a short video capture: micro-expressions, texture analysis, depth cues, and device metadata. The user holds the phone up. That is it. The check completes in under two seconds, compared to the eight to twelve seconds an active flow typically eats up.
The behavioral implications are larger than the technical ones. Six seconds is the difference between a friction event and a moment of delight. Under two seconds is essentially invisible, which is exactly what good compliance should feel like to a customer who has nothing to hide. We are watching an industry shift from "prove you are real" toward "we already know you are real, here is the question."
What makes this change architecturally interesting is that it does not weaken compliance. Passive liveness is, on most third-party benchmarks, harder to spoof than active liveness, because it does not announce which signal it is testing for. A fraudster trying to game a blink prompt knows what to do. A fraudster trying to game a model that evaluates forty signals at once does not. So we get a rare win: better security, shorter flow, less cognitive load.
A few practical notes worth flagging. Passive liveness is not a magic word. The quality of implementation varies enormously across vendors, and most production deployments still rely on document verification alongside the biometric step. The net effect is a substantial drop in abandonment, but only when the document legibility step is also well engineered. The trap we keep seeing is vendors treating biometrics as a silver bullet while leaving a clunky document upload in place. The customer does not experience biometrics and documents as separate steps. They experience the whole flow as one wall.
Good verification is invisible. Bad verification is the only thing the customer remembers about your product.
Strategic Trade-offs: Scaling Fintech Without Compromising Security
Here is the part the marketing decks skip. There is a point at which optimization becomes a defense mechanism. Every percentage point of drop-off recovered is also a percentage point of protection against competitors, fraud rings, and regulatory scrutiny. A slick flow does not just win customers. It filters them, because sophisticated fraud operations are also allergic to friction.
The corollary is that any fast onboarding must be paired with strong post-onboarding monitoring. This is where transaction monitoring systems, sanctions screening refreshes, and behavioral analytics earn their keep. We sign the customer quickly, then watch how they actually behave. The risk does not go away — it migrates.
A practical framework that has held up well across several fintechs we have watched closely looks something like this:
- Begin with a layered identity stack: document verification, passive liveness, and device intelligence, all queried in parallel within the first ten seconds of the flow.
- Apply risk-based scoring in real time, not in a batch job that runs overnight. The customer experience we are designing is the customer's experience now.
- Reserve human review for cases where the model is uncertain, not for clean cases the model already cleared. Analysts are expensive. Use them where their judgment moves the needle.
- Refresh KYC on a schedule tied to risk tier, not on a flat calendar. A low-risk savings customer and a high-value remittance sender should not face the same review cadence.
- Treat re-prompting as a last resort, not a default. Document re-uploads are associated with three times the abandonment of a clean first pass, so even one retry is rarely a small cost.
Each of these choices reflects a quiet inversion of how KYC used to be structured. The legacy mental model was: verify exhaustively at the door, then mostly forget the customer. The current model is: verify quickly at the door, then watch continuously, then re-verify when the signals change.
The cost picture changes too. Manual-heavy stacks dominated by analyst labor tend to scale linearly with customer growth. Automated stacks scale sub-linearly because the marginal cost of an additional verification approaches the cost of an API call. That is why the average annual KYC and AML operational spend sits around $72.9 million per institution — so much of it is still going to the parts of the pipeline that could be automated but have not been. The fintechs that move first on automation capture both lower operating costs and higher conversion rates. The fintechs that lag pay both premiums.
There is also a trust dimension we tend to handle badly. We frame KYC as a thing we do to customers. That framing leaks into the design, and the customer feels it. A better framing is that verification is a thing we do for customers — proof that the platform they are handing their data to takes its obligations seriously. When the design makes that visible, even subtly, the friction feels purposeful rather than punitive. We do not see many fintechs get this right yet.
Where This Leaves Us
Strict KYC does hurt growth — when strict means slow, repetitive, and indifferent to the user. Modern KYC, automated and behavior-aware, behaves differently. It still catches the bad cases, still satisfies regulators, but it stops punishing the good ones for the sin of having limited patience.
The industry is converging on a few useful beliefs. Verification is a product surface, not a back-office function. Time to clear is a compliance metric, not just a UX one. Drop-off during onboarding is a risk indicator, not just a marketing problem. Once you accept those framings, the engineering choices become clearer.
What we are really building is not a faster check. We are building the moment when a person decides that this fintech is the one they will trust with their money. Most of those moments are lost in plain sight, inside a verification flow nobody bothered to design.