Platform
Solutions
Resources
Company
Resources
Solutions

Customer onboarding: identity verification, KYB and onboarding risk score

Customer onboarding is the moment an institution proves it knows a person or company and measures their risk. TruvaLI consolidates identity verification, ultimate beneficial owner (UBO) analysis, and onboarding risk signals into a single flow, recording them alongside the decision justification.

Customer onboarding is the process of verifying the identity of a person or company, assessing their risk, and deciding whether to enter into a business relationship. For obliged parties, onboarding is not just a form-filling step: who was onboarded, with what information, and for what reason must be auditable later.

Which onboarding requirements apply to which sector is explained on the customer onboarding page. This page explains the tools TruvaLI uses to meet those requirements.

How is identity verified?

In remote identity verification, a single check is not considered sufficient. Multiple layers work together to verify one another.

LayerWhat it does
Document readingFields are extracted from ID, passport, or driver's license images using OCR, and the MRZ line is parsed separately
Chip reading with NFCFor chipped IDs and passports, data is read directly from the document's chip: unlike image processing, it cannot be spoofed with a copied document
Liveness and face matchingThe presence of a live person is verified, and their face is matched against the photo on the document
Video callWhere regulations require human verification, the call is recorded and linked to the decision as evidence
List screeningThe individual is screened against sanctions, PEP, and adverse media lists

Cross-verifying the document, chip, and face prevents onboarding decisions from relying on a single image. Details are on the video KYC page.

Who is onboarded for corporate customers?

Onboarding a company means onboarding the natural person behind that company. The ownership structure is resolved layer by layer down to the ultimate beneficial owner (UBO), with every step of the path recorded. Every natural person identified in the ownership chain also undergoes sanctions and PEP screening.

Authorized signatures, representation authority, and the company's line of business are part of the onboarding decision: a mismatch between declared activity and subsequent transaction behavior is one of the first things monitoring looks for. Details are on the KYB and UBO verification page.

What signals are analyzed during onboarding?

An identity may be valid, yet the customer can still be risky. At the moment of onboarding, only a few data points are available, but they reveal more than expected.

Email address. The address provider is matched against lists of trusted, disposable, and privacy-focused providers to generate a trust score. Then, the address itself is analyzed: does it contain the person's first name, last name, date of birth, or initials? Finally, a fuzzy search is run against other addresses in the system; this reveals clusters of highly similar or sequentially numbered addresses.

IP address. The address is resolved using geolocation data, and ownership information and rDNS records are read. This determines whether the address is a proxy, a VPN, or a residential service provider. Whether other users share the same IP is also factored in: a cluster of accounts opened from a single address is a pattern that goes unnoticed when viewed individually.

These two signals alone do not reject anyone. They feed into the onboarding score, and applications exceeding the threshold are routed to human review.

How is the onboarding decision made?

Onboarding is not just about staying below a single threshold. Collected signals are converted into a score; this score is interpreted according to the institution's own rule set, leading to one of three outcomes: approval, request for additional information, or rejection. Where simplified due diligence can be applied, fewer documents are requested; high risk triggers enhanced due diligence.

Which threshold triggers which outcome is the institution's own decision and is written as a rule. The rule engine is where these rules are written; the impact of a new threshold on real applications is tested first using rule simulation.

The work does not end when onboarding is complete

Risk at the moment of onboarding is not static across the customer lifecycle. Transactions inconsistent with declared activity, a new sanctions record, or a device shared with another account emerge post-onboarding. The onboarding record is therefore the starting point of monitoring, not the end. Read more on the ongoing monitoring page.

Decision and evidence

Every onboarding decision is recorded with its justification: which document was read, which list was screened, what score was generated, and who approved it. Document images, call recordings, and screening results remain linked to the decision. Segregation of duties and audit trails are explained on the maker-checker, authorization and audit trail page, while deployments where data does not leave the institution are covered on the on-premise deployment page.

Common questions

Which methods are used for remote identity verification?
OCR and MRZ reading from document images, chip reading via NFC for chipped documents, liveness testing, face matching, and video calls where required by regulations. The layers verify one another; a single check is never the sole basis for onboarding.
Why is NFC reading particularly important?
Data read from the chip comes directly from the document itself. While checks based on image processing can be fooled by a high-quality copy, chip reading cannot be spoofed.
How is the ultimate beneficial owner (UBO) identified for corporate customers?
The ownership structure is resolved layer by layer down to the natural person. Every natural person identified in the chain also undergoes sanctions and PEP screening, with every step of the path recorded.
How is the email address scored?
The provider is matched against lists of trusted, disposable, and privacy-focused providers. The address is checked to see if it contains the person's first name, last name, date of birth, or initials, and a fuzzy search is run against similar or sequentially numbered addresses in the system.
What is extracted from the IP address?
By analyzing geolocation, ownership information, and rDNS records, the system determines whether the address is a proxy, VPN, or residential service provider. Finding other accounts using the same IP is a separate risk signal.
Can simplified due diligence be applied?
Yes. Where risk is low and regulations permit, fewer documents are requested; high risk triggers enhanced due diligence. Which threshold leads to which outcome is defined by the institution's own rules.
Who makes the onboarding decision?
Applications that exceed the score threshold are routed to human review. Decisions are recorded with their justification, subject to segregation of duties, and written to the audit trail.
Where are the documents collected during onboarding stored?
On the institution's own infrastructure in an on-premise deployment. Document images, call recordings, and screening results remain linked to the decision and can be presented as evidence later.

Related