Loading
Financial services

Take applications online, with identity checks built in

Applications arrive as PDFs and identity documents arrive as phone photographs attached to e-mail. Someone eyeballs a passport against a form. When the regulator asks how a decision was reached, the evidence is scattered across a mailbox and the identity check was a person's judgement with nothing behind it.

Take finance applications online, with KYC built in.

You are probably here because

  • Identity documents arrive as photographs attached to e-mail, and stay there.
  • A member of staff compares a passport image to a form and forms a view.
  • Applications are part-completed and abandoned, and nobody knows at which question.
  • Evidence for a decision has to be reconstructed from several mailboxes.
  • Nobody tracks when a verification stops being valid and needs redoing.
  • Re-keying application data into another system is a daily job.
  • You are storing copies of identity documents you would rather not hold at all.

What is actually going wrong

The compliance risk is obvious once stated: identity document images sitting in a mailbox are among the most sensitive data you could hold, they are held in the least controlled place you have, and holding them is not actually necessary for the check you needed.

The quieter problem is that a human comparison of a document to a form produces a decision with no evidence behind it. It might have been a good decision. There is nothing on file establishing that it was, which is precisely what a regulator or an insurer will ask for — not whether you checked, but what the check consisted of and what it returned.

And commercially, a long form with an e-mail step in the middle loses applicants. Every handoff is an opportunity to stop, and because the abandonment is invisible, nobody knows whether the loss is at question three or question thirty.

What we build

A staged application form with save-and-resume, so a long application can be finished later rather than abandoned, and conditional fields so applicants only see what applies to them. Because it is staged, you can see where people stop.

Identity verification is wired into the flow rather than bolted onto the end. The applicant photographs their passport, driving licence or national identity card and normally takes a selfie, which is matched against the document. The check runs through Onfido or Stripe Identity in the provider's own flow, so document images never pass through your application and you are not storing them. The result comes back against the applicant's record.

From there, underwriting rules route the application, an authorisation step records who signed it off, and each check type carries a validity period so a fact that stops being true expires and is asked again. A result from an unknown or disabled provider, or one without a valid signature, is refused rather than trusted — the check fails closed, which is the only safe default.

How it goes together

  1. 01

    Build the application as stages, not a wall

    A multi-stage form with conditional sections and save-and-resume. Applicants see only what applies to them, can stop and come back, and because each stage is a recorded step you find out where abandonment actually happens.

    Built from
    FormsConditional form builderWorkflows
  2. 02

    Verify identity inside the flow

    Document and biometric checks run through the provider's own flow at the point in the application where they belong. The applicant photographs a passport, licence or ID card and takes a selfie; the images go to the provider, not to you.

    Built from
    User verificationID document checksOnfido & Stripe Identity
  3. 03

    Decide what happens with each result

    A pass can proceed automatically or be held for a manual review queue with the evidence shown alongside the decision. Sign-in itself can be gated on a required check. An unsigned or unrecognised result is refused rather than treated as a pass.

    Built from
    Manual review queueGate sign-in on a checkFails closed
  4. 04

    Route and authorise the application

    Underwriting rules send applications down the right path by value, product or risk, and an electronic authorisation step records the sign-off — who, when, and against what the record contained at that moment.

    Built from
    WorkflowsElectronic authorisationAuditing
  5. 05

    Handle expiry and re-verification

    Each check type has a validity period, so verification is a fact with a lifespan rather than a permanent tick. Scheduled tasks ask again before it lapses instead of after someone notices.

    Built from
    Validity & re-verificationScheduled tasksE-mail templates

The platform features doing the work

Nothing here is written specially for this use case — it is the same platform every ActiveManage application is built from. The full feature list is on the platform page.

FeatureWhat it doesWhy it matters here
ID document checksThe applicant photographs a passport, driving licence or national identity card and normally takes a selfie, matched against the document.Replaces a member of staff forming a view about a photograph with a check that produces a recorded result.
Onfido & Stripe IdentityChecks run in the provider's own flow, so document images never pass through your application.You get the assurance without becoming the custodian of a pile of passport photographs.
Validity & re-verificationEach check type carries a validity period, after which the user is asked again.Verification is a fact that expires. Treating it as permanent is how files quietly become non-compliant.
Manual review queueA provider pass can be held for an administrator to confirm, with the evidence shown alongside.Keeps a human in the loop where your risk appetite requires one, without making the human the whole control.
Fails closedA result from an unknown or disabled provider, or without a valid signature, is refused rather than trusted.The correct default, and not a universal one. A verification system that fails open is worse than none, because it is believed.
Multi-stage forms & auditingStaged forms with save-and-resume and conditional fields, over a full change history.Fewer abandoned applications, and a complete record of how each decision was reached.

What you end up with

  • Passport, licence or ID card checked automatically with biometric matching
  • Document images never pass through or rest in your system
  • Expiry and re-verification handled per check type
  • Unverified or unsigned results refused, not trusted
  • Sign-off recorded against the record as it stood at the time
  • Save-and-resume, so long applications get finished

Whether this is for you

A good fit when

  • Lenders, brokers, insurers and financial services taking applications from the public.
  • Any regulated onboarding where identity has to be established and evidenced.
  • Age-restricted services needing a threshold confirmed without storing the document.
  • Organisations currently receiving identity documents by e-mail, which is most of them.

Probably not, if

  • A short enquiry form where identity does not matter. Verification adds cost and friction; only apply it where the risk justifies it.
  • Organisations wanting to run identity checks themselves without a provider. Document and biometric verification is specialist, and building it in-house would be a poor decision.
  • Anyone wanting the platform to make the lending decision. It routes, records and evidences — the underwriting judgement stays yours.

How a project like this runs

First

The application form and the verification step, end to end, against a provider sandbox. Getting the identity flow right early matters because it shapes everything around it.

Then

Underwriting routing, the review queue, authorisation, expiry handling and whatever the application has to hand off to afterwards.

Handover

Questions, routing rules and validity periods are configuration — which matters, because regulatory requirements change more often than software budgets.

Questions we get asked

Do we end up storing copies of passports?

No, and that is much of the point. The check runs in Onfido's or Stripe Identity's own flow, so document images never pass through your application. You hold the result and the evidence of the check, not the document.

Which documents can be checked?

Passports, driving licences and national identity cards, normally with a selfie matched against the document.

What happens if a check is inconclusive?

It goes to a manual review queue where an administrator sees the evidence alongside the decision. You choose which outcomes route there rather than accepting a provider's default.

How do we handle checks that expire?

Each check type carries a validity period, so the platform knows when a verification has lapsed and can ask again — and can gate access on a required check where that is appropriate.

Can it decide applications automatically?

It can route them automatically on your rules, and record the authorisation when a person signs off. Whether any decision is fully automated is your call and your regulatory responsibility — the platform will not make that choice for you.

Sound like your week?

Tell us what you are trying to fix and we will tell you whether this is the right shape for it — including when it is not.