Why fintechs can’t afford to get remote verification wrong


This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.


In the early days of financial products and services, verifying a customer’s identity was straightforward. Face-to-face meetings, physical documents, and personal relationships formed the basis of most client onboarding. As technology advanced, especially with the rise of fintechs and digital banking, these traditional methods became impractical.

The digital age demanded faster, more efficient ways to onboard customers, leading to the adoption of electronic verification methods. But, as businesses moved online, so did criminals. Fraudsters adapted quickly, exploiting weak identity checks and loopholes in remote verification systems. Over the years, regulatory bodies have tightened their requirements, emphasising the need for digital identity verification processes to combat financial crime.

For fintech companies, getting remote customer verification wrong could mean losing consumer trust, facing hefty fines, and damaging their reputation beyond repair.

How identity verification has changed

Traditionally, identity verification relied heavily on face-to-face interactions and physical documentation. Verifying a customer’s identity meant collecting copies of driving licences, passports, and utility bills, then manually reviewing them and checking them against a database. It was frustratingly slow, clunky, and often prone to human error. 

Now, firms in the UK are expected to balance seamless customer experiences with comprehensive risk controls, all while keeping up with changing Financial Conduct Authority (FCA) expectations and global Anti-Money Laundering (AML) standards.

The shift towards digital onboarding accelerated with the pandemic, but even before then, firms were looking for ways to speed up verification while maintaining AML compliance. The problem? Fraudsters were evolving just as quickly, and the regulatory environment was tightening. 

In recent years, deepfake technology (where AI is used to manipulate or generate highly realistic but fake images and videos), synthetic identities (a combination of fabricated credentials where the implied identity is not associated with a real person), and stolen personal data have made it easier than ever for bad actors to slip through weak verification processes. That’s why fintechs need systems that don’t just verify customer legitimacy but actively assess risk.

The risk of inadequate verification

Failing to verify customers properly is a direct threat to AML compliance, hard-earned reputation, and business success for regulated firms. The FCA and other regulatory bodies have made it clear that weak customer due diligence (CDD) and verification processes won’t be tolerated. 

Despite such clear expectations, some firms continue to rely on outdated or ineffective verification methods when onboarding customers. Others take a ‘tick-box’ approach, assuming that basic identity checks will suffice. But as recent enforcement actions have shown, firms that cut corners, rely on outdated verification methods or fail to identify high-risk individuals face penalties, reputational damage, and potential restrictions on their operations.

A notable example is Starling Bank, a UK-based neobank that experienced rapid growth between 2016 and 2023. Despite its astonishing success, the FCA uncovered significant deficiencies in Starling’s client screening controls, describing them as “shockingly lax”.  

This negligence allowed the bank to open accounts for over 49,000 high-risk customers, leading to a fine of more than £28 million. The FCA’s final notice highlighted issues with the bank’s AML policies and processes, senior management oversight, and internal communication regarding compliance. 

The case was and absolutely should be a wakeup call for regulated firms and fintechs alike, reminding them of the importance of comprehensive identity verification and screening processes, and the potential repercussions of neglecting them. 

How criminals exploit weak verification processes

Firms that don’t implement rigorous verification measures provide an easy entry point for financial criminals to infiltrate the financial system. Fraudsters use stolen or synthetic identities to open accounts, move illicit funds, and evade detection. These types of fraudsters are often well-versed in identifying and bypassing verification protocols that fail to keep up with evolving risks. What’s more, the rise of AI-powered deepfake technology has made it even easier for bad actors to bypass weak identity verification processes. 

Fraudsters now have the ability to manipulate digital assets (whether that’s photos, videos, or audio) making it even harder to distinguish between genuine and fabricated identities. This is where compliance teams often feel the strain as traditional identity verification processes just aren’t enough to keep up.

Beyond direct criminal activity, inadequate verification can create a snowball effect. Once bad actors realise a firm’s defences are weak, they will exploit it repeatedly, making it even harder to tell real customers from fraudulent ones. 

How to get remote verification right

Getting remote verification right means integrating technology, risk assessment, and regulatory compliance in a way that is seamless for customers but stringent enough to deter bad actors.

Relying solely on document scans or selfies is no longer enough. Combining biometrics and facial recognition, document verification, and liveness detection to confirm customer identities significantly reduces the risk of fraud. What’s more, a technology-first approach enables customers to complete verification remotely, using any device, thereby enhancing user experience while maintaining stringent security standards.

Regulated fintechs need to verify not just the identity of an individual but also their legitimacy. This means checking that documents are genuine, confirming that the person presenting them is real, and ensuring that their details match provided ID documents and external data sources. 

But, not all customers present the same level of threat, and a one-size-fits-all approach can either introduce unnecessary friction or leave gaps that fraudsters can exploit. The key is to apply a risk-based approach, using verification methods that combine onboarding checks with thorough data cross-referencing to strengthen security and deliver peace of mind. 

Cross-referencing information against watchlists, adverse media, and other datasets strengthens the process and helps flag high-risk individuals for further investigation before they gain access to financial services.

Remember that verification is not a one-time event – customer profiles can change, and new risks can emerge post-onboarding. Continuous monitoring ensures that any unusual activity, such as a change of address or an individual becoming sanctioned or politically exposed, is flagged, and reverification can be triggered when needed.

What does the future hold for remote customer verification? 

As compliance expectations grow, fintech firms will need to invest in verification technologies that not only meet today’s standards but can adapt to future challenges. Automated solutions are increasingly central to this, reducing manual effort, improving accuracy, and allowing firms to scale their compliance operations efficiently.
At the same time, regulators will continue to tighten requirements. In the UK, the Economic Crime and Corporate Transparency Act, alongside ever-evolving FCA guidance, indicates that compliance expectations will only increase in the coming years. Firms that proactively strengthen their verification processes now, rather than waiting for regulatory pressure, will be better prepared for the future and in a stronger position for long-term, sustainable growth.

More great articles from our opinions section

Andrew Doyle, CEO, NorthRow
Andrew Doyle

Andrew Doyle is the CEO of Anti-Money Laundering compliance software, NorthRow. He has written for TechFinitive under its Opinions section.